Skip to main content

sha256_compress_2x_seq

Function sha256_compress_2x_seq 

Source
pub fn sha256_compress_2x_seq(
    builder: &CircuitBuilder,
    state_in: State,
    blocks: [[Wire; 16]; 2],
) -> State
Expand description

Two sequential SHA-256 block compressions evaluated in one parallel core.

The second block’s compression takes the first block’s output state as its input state. Both run as the two 32-bit lanes of a single parallel compression:

    high lane [32:64]:  S1 = compress(input state, first block)
    low  lane [0:32] :  S2 = compress(S1,          second block)

So two chained blocks cost one compression instead of two.

The two lanes run concurrently, yet the low lane needs the high lane’s output as its input. A hint breaks this dependency by precomputing S1 off-circuit. The hinted S1 seeds the low lane’s input and is constrained two ways, so it cannot lie:

  • its high half must equal the real input state (the first compression’s input).
  • its low half must equal the first compression’s in-circuit output.

§Arguments

  • state_in: 8-word input state for the first compression, value in the low 32 bits of each.
  • blocks: two 16-word message blocks; blocks[0] feeds the first, blocks[1] the second.

§Preconditions

  • Every input wire holds a valid 32-bit value in its low 32 bits.
  • High halves need not be empty.
    • A block word’s high half is masked off.
    • A state word’s is discarded by the shift that lifts it into the high lane.

§Returns

8 wires, each packing both output states:

  • low 32 bits: the second compression’s output.
  • high 32 bits: the first compression’s output.