adv-mixer: Q1 deepening rows (linrel 16 days x 3 K, lineindex K1-3, CNF model); sweeps running
Internal adversarial pass, not an independent review. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
parent
1662a76082
commit
d10eee9f34
1 changed files with 63 additions and 0 deletions
|
|
@ -132,6 +132,69 @@ above does not depend on the choice. Reconciling the median is handed to adv-mix
|
|||
1.17x FPGA-datapath gain the chip model does not credit as hash rate (the chip is bound by the 8 cache reads and
|
||||
the fixed op count, not by one day's multiply-adder count), and a weak day is a public calendar.
|
||||
|
||||
## Q1 deepening (from 20:4x BST): more days, all key pairs, exact relations, the address bits, a SAT model
|
||||
|
||||
Main's re-scope asked for the probes at full 32-bit width over more days and more rk pairs, a SAT model of two
|
||||
keyed applications for an algebraic relation, and a relation search in the s[0] line-index bits. Binary sha256
|
||||
bbfab24075923083f0c9c8c4372a6dd22257c245bac75ba6fadbd60ab64ec803 (frozen-identical tree, same bytes on both
|
||||
boxes). Queue files tools/attack/adv-mixer/queue/11..14, claimed in /srv/builds/_adv/mixer/claims. Logs under
|
||||
/srv/builds/_adv-adv-mixer/logs on each box, copied into docs/analysis/cryptanalysis/logs/adv-mixer when done.
|
||||
|
||||
### Exact affine-relation search at full width (linrel), queue 14, box 2
|
||||
|
||||
Command: `attack-adv-mixer linrel --day 20729 --apps K --samples 8192 --days 16` for K in 1, 2, 8. Each sample
|
||||
is a GF(2) row over 1025 columns (512 input bits, 512 output bits, the constant). Rank 1025 means no exact
|
||||
affine relation a.x XOR b.y = c exists between the input and output bits of K applications; a chance survivor
|
||||
has odds 2^-(8192-1025) = 2^-7167.
|
||||
|
||||
| Applications K | Days (20729 to 20744) | Rank | Kernel dimension | Reading |
|
||||
|---|---|---|---|---|
|
||||
| 1 | 16 of 16 | 1025 | 0 | no affine relation after one application |
|
||||
| 2 | 16 of 16 | 1025 | 0 | no affine relation after two |
|
||||
| 8 | 16 of 16 | 1025 | 0 | no affine relation across the full between-reads block |
|
||||
|
||||
This is the decidable algebraic probe the brief's "algebraic form" question needs: at full width with the real
|
||||
day constants there is no linear or affine structure a chip could use to batch or predict the 8 applications.
|
||||
|
||||
### The line-index bits of s[0] (lineindex), queue 13, box 1
|
||||
|
||||
Command: `attack-adv-mixer lineindex --day 20729 --apps K --states 1000000 --threads 44`. The 22 address bits
|
||||
(s[0] AND 2^22-1) against each of the 512 input bits; band 8 sigma = 0.004 at 1e6 states.
|
||||
|
||||
| K | Mean address-bit flip | Holes / 11264 | Strong cells / 11264 | Worst cell | Verdict |
|
||||
|---|---|---|---|---|---|
|
||||
| 1 | 0.4275 | 70 | 6904 | 1000 sigma | FINDING: address bits predictable after one application |
|
||||
| 2 | 0.500007 | 0 | 0 | 3.9 sigma | clean |
|
||||
| 3 | clean | 0 | 0 | inside band | clean |
|
||||
| 4 | running | | | | RUNNING |
|
||||
|
||||
Reading for the chip: the line index a read depends on is not predictable before the second of the 8
|
||||
applications completes, so a prefetch cannot hide more than 1 of the 8 applications behind the memory latency.
|
||||
The address-restricted exact relation search (linrel --addr, 8 days, K = 1 and 2) is in the same queue file and
|
||||
lands here.
|
||||
|
||||
### Fold probes over 1024 days and all 71 adjacent key pairs (fold-sweep), queue 11, box 1
|
||||
|
||||
Command: `attack-adv-mixer fold-sweep --day 20729 --days 1024 --trials 20000 --threads 44`: probes (a) and
|
||||
(c) on every adjacent application pair (i, i+1) for i in 0..70 and probe (b) on the full block, per day.
|
||||
RUNNING; the row lands here.
|
||||
|
||||
### Integral degree test over 32 days (integral), queue 12, box 2
|
||||
|
||||
Command: `attack-adv-mixer integral --day 20729 --apps K --dmax 16 --placements 2000 --days 32` for K = 1, 2.
|
||||
RUNNING; the row lands here.
|
||||
|
||||
### SAT model of two keyed applications (cnf), queue 14 then a solve on box 2
|
||||
|
||||
Command: `attack-adv-mixer cnf --day 20729 --out .../adv-mixer-commute-20729.cnf`. Bit-exact Tseitin encoding
|
||||
of M(M(x,rk1),rk2) and M(M(x,rk2),rk1) on a shared 512-variable input with the two outputs constrained equal:
|
||||
105,652 variables, 361,188 clauses, 6.8 MB. SAT = a state on which the two key orders commute; UNSAT = a proof
|
||||
over all 2^512 states that fold probe (c) holds exactly. No solver reaches the box from crates.io (HTTP 403), so
|
||||
the harness marks the solve BLOCKED; the sibling lane adv-mixer-3 has cadical 3.0.1 built from source on box 2,
|
||||
and that binary is running on this instance under a one-hour cap at nice 10 (log sat-commute-20729.log).
|
||||
RUNNING; the row lands here. A timeout is the honest expected outcome: the instance is a preimage-shaped search
|
||||
on a 2^512 space, and a plain timeout is a bound on solver reach, not evidence either way.
|
||||
|
||||
## Confirmation across the stale and frozen trees
|
||||
|
||||
The branch was first cut from stale master 3f0afcd5. Its igneum-pow differed from the frozen object in six
|
||||
|
|
|
|||
Loading…
Reference in a new issue