diff --git a/docs/analysis/cryptanalysis/report-mixer-3.md b/docs/analysis/cryptanalysis/report-mixer-3.md index 2a992fde..ebd186c8 100644 --- a/docs/analysis/cryptanalysis/report-mixer-3.md +++ b/docs/analysis/cryptanalysis/report-mixer-3.md @@ -24,13 +24,13 @@ Plant rule: a tool is trusted once it has fired on a known-failed shape. Which s | Q | Method | Known-failed shape | Gate | Result (numbers) | Status | |---|---|---|---|---|---| -| Q1 | exhaustive round-0 line-index census, all 2^32 t, k = 0..8 | k = 0 (the init: one bin holds 2^32, fired on both days) | chi-square z within 6, no empty bin | day 20729: uniform at k = 1 (z -1.13), 2 (-0.68), 3 (-0.39), 4 (-0.47), 5 (-1.47), 6 (-0.30); day 20733 uniform at k = 1 (z -0.71); k = 7, 8 and day 20733 k = 2..8 running under the lock | PASS to k = 6 (BOUND: the index histogram is uniform from k = 1), RUNNING | -| Q2 | single-bit avalanche, random states, 2^24 (and 2^27) states | `one` at k = 8 (fired: 1959 holes); `weak` fires at k = 1 only, not at k = 8 (see Q2) | no cell beyond 6 sigma | day 20729 k = 1: 354 holes, 129,726 cells beyond 6 sigma, worst p = 1.000; day 20733 k = 1: 266 holes, 136,797 cells; day 20729 k = 2 at 2^24: 0 holes, 0 cells beyond 6 sigma, worst z -4.74 (band 0.0015); k = 3: 0 and 0, worst z -5.28; k = 4..8 and the 2^27 rows running | FINDING at k = 1, PASS at k = 2 (margin: 1 of 8 on random states) | -| Q2b | t-bit avalanche on the round-0 input (32 bits in), 2^24 (and 2^28) states | k = 0 (the init alone, fired: 12,439 holes) | no cell beyond 6 sigma | k = 1: 0 holes, 218 cells beyond 6 sigma, worst p = 0.7427 (t bit 31 to state bit 53), 18 line-index cells beyond 6 sigma. k = 2..8 at 2^24: 0 cells beyond 6 sigma, worst z 3.7 to 4.7 (the maximum of 16,384 normals is about 4.1); k = 2 at 2^28 states: 0 cells beyond 6 sigma, worst z -4.30, band 0.00018 | FINDING at k = 1, PASS from k = 2 (margin: 1 of 8) | +| Q1 | exhaustive round-0 line-index census, all 2^32 t, k = 0..8 | k = 0 (the init: one bin holds 2^32, fired on both days) | chi-square z within 6, no empty bin | day 20729: uniform at k = 1 (z -1.13), 2 (-0.68), 3 (-0.39), 4 (-0.47), 5 (-1.47), 6 (-0.30), 7 (-1.04); day 20733 uniform at k = 1 (z -0.71); k = 8 and day 20733 k = 2..8 running under the lock | PASS to k = 7 (BOUND: the index histogram is uniform from k = 1), RUNNING | +| Q2 | single-bit avalanche, random states, 2^24 (and 2^27) states | `one` at k = 8 (fired: 1959 holes); `weak` fires at k = 1 only, not at k = 8 (see Q2) | no cell beyond 6 sigma | day 20729 k = 1: 354 holes, 129,726 cells beyond 6 sigma, worst p = 1.000; day 20733 k = 1: 266 holes, 136,797 cells; day 20729 k = 2 at 2^24: 0 holes, 0 cells beyond 6 sigma, worst z -4.74 (band 0.0015); k = 3: 0 and 0, worst z -5.28; day 20733 k = 2: 0 and 0, worst z -4.59; k = 4..8 and the 2^27 rows running | FINDING at k = 1, PASS at k = 2 on both days (margin: 1 of 8 on random states) | +| Q2b | t-bit avalanche on the round-0 input (32 bits in), 2^24 (and 2^28) states | k = 0 (the init alone, fired: 12,439 holes) | no cell beyond 6 sigma | k = 1: 0 holes, 218 cells beyond 6 sigma, worst p = 0.7427 (t bit 31 to state bit 53), 18 line-index cells beyond 6 sigma. k = 2..8 at 2^24: 0 cells beyond 6 sigma, worst z 3.7 to 4.7 (the maximum of 16,384 normals is about 4.1); k = 2 and 3 at 2^28 states: 0 cells beyond 6 sigma, worst z -4.30 and 4.76, band 0.00018; k = 4 at 2^28 running | FINDING at k = 1, PASS from k = 2 (margin: 1 of 8) | | Q3 | differential multiplicity, 576 low-weight input differences, 2^20 pairs each | `nomul` at k = 1 (fired: 17,289 deterministic output bits at 4,096 pairs) | no multiplicity 4 or more, no deterministic bit | k = 1: 695 deterministic output bits over the 576 differences (max 35 in one difference) on day 20729, 537 (max 40) on 20733; k = 2..7: 0 deterministic bits, max multiplicity 1, no pair with 2 zero words, both days; k = 8 running | FINDING at k = 1 (deterministic bits), PASS from k = 2 | | Q4 | single-bit linear correlations, random states, 2^26 samples | k = 0 (the identity, fired: c = 1.0 on the diagonal) | no cell beyond 6 sigma (band 0.00073) | day 20729 k = 1..7 and day 20733 k = 1..8: worst c between 0.00055 and 0.00062 (z 4.5 to 5.1; the expected maximum of 262,144 normals is 4.8), 0 cells beyond 6 sigma on every row; day 20729 k = 8 running | PASS from k = 1 (BOUND) | -| Q4b | t-bit linear correlations on the round-0 input, 2^26 samples | k = 0 (fired: c = 1.0, t bit 0 to s[8] bit 0) | no cell beyond 6 sigma | k = 1..8: worst c 0.00048 to 0.00059 (z 3.9 to 4.9 over 16,384 cells), 0 cells beyond 6 sigma | PASS from k = 1 (BOUND) | -| Q5 | rotational-XOR, rotations 1, 8, 16, 2^22 samples | `weak0` at k = 1 (fired: 740 zero-difference words of 2^20 at r = 1, 245 at r = 16) | no zero-difference word above 2 of N, no repeated difference above 3 | day 20729, k = 1, 2, 3, 4 at 2^22 samples: 0 zero-difference words at every rotation (random expects about 0.001), most frequent per-word difference multiplicity 3 (the birthday expectation at 2^22 draws of 32 bits) | PASS from k = 1 (BOUND: the XOR constants and the odd multiply kill the rotational property inside one application) | +| Q4b | t-bit linear correlations on the round-0 input, 2^26 samples | k = 0 (fired: c = 1.0, t bit 0 to s[8] bit 0) | no cell beyond 6 sigma | both days, k = 1..8: worst c 0.00046 to 0.00059 (z 3.7 to 4.9 over 16,384 cells), 0 cells beyond 6 sigma | PASS from k = 1 (BOUND) | +| Q5 | rotational-XOR, rotations 1, 8, 16, 2^22 samples | `weak0` at k = 1 (fired: 740 zero-difference words of 2^20 at r = 1, 245 at r = 16) | no zero-difference word above 2 of N, no repeated difference above 3 | both days, k = 1, 2, 3, 4 at 2^22 samples: 0 zero-difference words at every rotation (random expects about 0.001), most frequent per-word difference multiplicity 3 (the birthday expectation at 2^22 draws of 32 bits) | PASS from k = 1 (BOUND: the XOR constants and the odd multiply kill the rotational property inside one application) | | Q6 | SAT (CaDiCaL) on the round-0 input: find t with a given 22-bit index after k applications | k = 1 solved and verified | solve inside one hour per k, time against the honest 2^10 x k x 130 ops | k = 1: SATISFIABLE in 137 s wall (loaded box); model t = 0x49880000 verifies to the target 0x20eb79. Honest: 2^10 trials of one application is under a millisecond. The solver is already slower than brute force at k = 1 | PASS at k = 1 (BOUND); k = 2..4 RUNNING | | Q7 | days: 20733 on every row, 8 fixed day indices on Q1 and Q2 | as above | as above | day 20733 rows land below | RUNNING | | GPU | any GPU row | n/a | n/a | no GPU on either box | BLOCKED | @@ -54,6 +54,7 @@ Command (build-1), per k: `adv-mixer-3 index --day 20729 --apps k --threads 64`. | 20729 | 4 | -0.47 | 0 | 857 | 1190 | 1.07 | -0.25 | pending | uniform | | 20729 | 5 | -1.47 | 0 | 872 | 1202 | 0.99 | -0.11 | pending | uniform | | 20729 | 6 | -0.30 | 0 | 867 | 1185 | 0.01 | -1.62 | pending | uniform | +| 20729 | 7 | -1.04 | 0 | 862 | 1191 | -0.45 | -0.88 | pending | uniform | | 20733 | 0 | 6.2e12 | 4194303 | 0 | 2^32 | 7.8e11 | 2.4e10 | n/a | NON-UNIFORM (plant) | | 20733 | 1 | -0.71 | 0 | 863 | 1202 | 0.11 | -0.60 | pending | uniform | @@ -79,6 +80,7 @@ run at k = 1 fired it too: 14,364 holes). The `one` plant is the firing check of | 20729 | 2 | 2^24 | 0 | 0 | in 322 (word 10) to out 373 (word 11) | 0.49942 (z -4.74) | 0 | inside the band | | 20729 | 3 | 2^24 | 0 | 0 | in 370 (word 11) to out 88 (word 2) | 0.49936 (z -5.28) | 0 | inside | | 20733 | 1 | 2^24 | 266 | 136,797 | in 30 (word 0) to out 32 (word 1) | 1.0000 | pending | DISTINGUISHED | +| 20733 | 2 | 2^24 | 0 | 0 | in 260 (word 8) to out 450 (word 14) | 0.49944 (z -4.59) | 0 | inside | Reading: one application on a random 512-bit state leaves 354 deterministic cells (an input bit that always or never flips a given output bit) and 129,726 of 262,144 cells beyond 6 sigma; 7,930 of the 11,264 cells that @@ -102,6 +104,7 @@ Logs: sac0-20729-k.log. Plant k = 0 (the init alone) fired: 12,439 holes of 1 | 20729 | 7 | 2^24 | 0 | 0 | t bit 6 to bit 390 | 0.49943 (z -4.69) | 0 | inside | | 20729 | 8 | 2^24 | 0 | 0 | t bit 13 to bit 9 | 0.49947 (z -4.33) | 0 | inside | | 20729 | 2 | 2^28 | 0 | 0 | t bit 8 to bit 352 | 0.49987 (z -4.30) | 0 | inside (band 0.00018) | +| 20729 | 3 | 2^28 | 0 | 0 | t bit 26 to bit 97 | 0.50015 (z 4.76) | 0 | inside (band 0.00018) | Why k = 1 has deterministic cells and k = 2 has none (read from the code, `memhard::qr` and `mixer`): a difference whose lowest set bit is at position j keeps that lowest bit through an XOR with a constant, through a @@ -183,6 +186,14 @@ of t, y = the state after the init and k applications). Plant k = 0 fired: c = 1 | 20729 | 6 | -0.00048 | -3.97 | 0 | | 20729 | 7 | 0.00058 | 4.76 | 0 | | 20729 | 8 | -0.00051 | -4.15 | 0 | +| 20733 | 1 | 0.00047 | 3.82 | 0 | +| 20733 | 2 | 0.00056 | 4.60 | 0 | +| 20733 | 3 | 0.00051 | 4.19 | 0 | +| 20733 | 4 | 0.00052 | 4.25 | 0 | +| 20733 | 5 | 0.00049 | 4.02 | 0 | +| 20733 | 6 | -0.00050 | -4.08 | 0 | +| 20733 | 7 | -0.00046 | -3.74 | 0 | +| 20733 | 8 | -0.00058 | -4.75 | 0 | Reading: no t bit has a linear correlation with any state bit after one application, at a band of 0.00073. The 24 percent avalanche bias of Q2b at k = 1 is a differential effect (a flipped t bit flips a state bit with @@ -191,7 +202,7 @@ probability 0.74), not a linear one. ## Q5: rotational-XOR Command (build-1): `adv-mixer-3 rx --day 20729 --apps k --start 8 --samples 2^22`. Plant `weak0` (MUL 1, RC 0, -ROT 16, round key 0: a constant-free ARX round) at k = 1 fired: at r = 1, 740 of 2^20 samples had a zero +ROT 16, round key 0: a constant-free ARX round) at k = 1 fired on both days (day 20733: 739, 222): at r = 1, 740 of 2^20 samples had a zero rotational-XOR difference in one word and the difference 0x00000001 repeated 784 times; at r = 16, 245 zero differences. Real day: @@ -201,6 +212,7 @@ differences. Real day: | 20729 | 2 | 2^22 | 0 / 0 / 0 | 3 / 3 / 3 | no RX property | | 20729 | 3 | 2^22 | 0 / 0 / 0 | 3 / 3 / 3 | no RX property | | 20729 | 4 | 2^22 | 0 / 0 / 0 | 3 / 3 / 3 | no RX property | +| 20733 | 1 to 4 | 2^22 | 0 / 0 / 0 on every row | 3 / 3 / 3 on every row | no RX property | Reading: rotational-XOR cryptanalysis needs the constants to be rotation-friendly; here every word is XORed with a drawn 32-bit constant plus the round key and then multiplied by a drawn odd constant before the ARX layer, so