{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,13]],"date-time":"2026-05-13T15:08:59Z","timestamp":1778684939482,"version":"3.51.4"},"reference-count":14,"publisher":"MDPI AG","issue":"3","license":[{"start":{"date-parts":[[2026,5,13]],"date-time":"2026-05-13T00:00:00Z","timestamp":1778630400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Cryptography"],"abstract":"<jats:p>A cryptographic hash function should dissipate patterns, such that highly related inputs are transformed into unrelated outputs. This property, known as diffusion, has been effectively measured on SHA-256 via the Strict Avalanche Criterion (SAC) throughout the 64 rounds of compression. Additionally, variants of SHA-256 with individual sub-functions removed have previously been tested. In this study, the previous work is expanded; all combinations of the seven SHA-256 sub-functions are tested for SAC, throughout the 64 rounds of compression. The threshold as to whether a variant passes the SAC is calculated with the Bonferroni Method, which results in a relaxed threshold as compared to previous measures. The SAC of each sub-function variant is compared with the SAC of variants with shared sub-functions. The sub-functions \u03a31, Integer Addition, Choose, and Message Scheduler are found to consistently contribute to SAC at the earliest rounds, throughout all combinations.<\/jats:p>","DOI":"10.3390\/cryptography10030032","type":"journal-article","created":{"date-parts":[[2026,5,13]],"date-time":"2026-05-13T12:46:55Z","timestamp":1778676415000},"page":"32","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Relaxation of Strict Avalanche Criterion on All SHA-256 Sub-Function Combinations"],"prefix":"10.3390","volume":"10","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-8676-4524","authenticated-orcid":false,"given":"Riley","family":"Vaughn","sequence":"first","affiliation":[{"name":"Department of Electrical Engineering and Computer Science, University of Wyoming, Laramie, WY 82071, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9409-8245","authenticated-orcid":false,"given":"Mike","family":"Borowczak","sequence":"additional","affiliation":[{"name":"Department of Electrical and Computer Engineering, University of Central Florida, Orlando, FL 32816, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2026,5,13]]},"reference":[{"key":"ref_1","unstructured":"Handschuh, H., and Gilbert, H. (2009). The Evaluation Report of SHA-256 Crypt Analysis Hash Function. 2009 International Conference on Communication Software and Networks, IEEE."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"656","DOI":"10.1002\/j.1538-7305.1949.tb00928.x","article-title":"Communication theory of secrecy systems","volume":"28","author":"Shannon","year":"1949","journal-title":"Bell Syst. Tech. J."},{"key":"ref_3","unstructured":"(2002). Secure Hash Standard (Standard No. FIPS Pub 180-2)."},{"key":"ref_4","unstructured":"(2015). Secure Hash Standard (Standard No. FIPS Pub 180-4)."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Vaughn, R., and Borowczak, M. (2024). Strict Avalanche Criterion of SHA-256 and Sub-Function-Removed Variants. Cryptography, 8.","DOI":"10.3390\/cryptography8030040"},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"747","DOI":"10.1109\/TC.1979.1675242","article-title":"Structured Design of Substitution-Permutation Encryption Networks","volume":"10","author":"Kam","year":"1979","journal-title":"IEEE Trans. Comput."},{"key":"ref_7","unstructured":"Webster, A.F., and Tavares, S.E. (1985). On the design of S-Boxes. Advances in Cryptology\u2014CRYPTO \u201985 Proceedings. CRYPTO 1985, Springer. LNCS."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Wasserman, L. (2004). All of Statistics: A Concise Course in Statistical Inference, Springer. Springer Texts in Statistics.","DOI":"10.1007\/978-0-387-21736-9"},{"key":"ref_9","unstructured":"(2015). SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions (Standard No. Federal Information Processing Standards Publication FIPS 202)."},{"key":"ref_10","unstructured":"Rescorla, E. (2026, May 07). The Transport Layer Security (TLS) Protocol Version 1.3. Available online: https:\/\/datatracker.ietf.org\/doc\/html\/rfc8446."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Yoshida, H., and Biryukov, A. (2005). Analysis of a SHA-256 Variant. Selected Areas in Cryptography. SAC 2005. Lecture Notes in Computer Science, Springer.","DOI":"10.1007\/11693383_17"},{"key":"ref_12","unstructured":"Vaughn, R. (2026, May 07). Available online: https:\/\/github.com\/RileyVaughn\/Sha256-SAC."},{"key":"ref_13","unstructured":"Go Authors (2026, May 04). crypto\/sha256. Available online: https:\/\/pkg.go.dev\/crypto\/sha256."},{"key":"ref_14","unstructured":"National Institute of Standards and Technology (2026, May 07). The Secure Hash Algorithm Validation System (SHAVS), Available online: https:\/\/csrc.nist.gov\/csrc\/media\/projects\/cryptographic-algorithm-validation-program\/documents\/shs\/shavs.pdf."}],"container-title":["Cryptography"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2410-387X\/10\/3\/32\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,13]],"date-time":"2026-05-13T14:12:03Z","timestamp":1778681523000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2410-387X\/10\/3\/32"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,13]]},"references-count":14,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2026,6]]}},"alternative-id":["cryptography10030032"],"URL":"https:\/\/doi.org\/10.3390\/cryptography10030032","relation":{},"ISSN":["2410-387X"],"issn-type":[{"value":"2410-387X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,5,13]]}}}