From d10eee9f349eb9730b4edbd36b30a1faf348cedc Mon Sep 17 00:00:00 2001 From: igneum-labs <337424239+igneum-labs@users.noreply.github.com> Date: Wed, 7 Oct 2026 18:52:16 +0000 Subject: [PATCH] adv-mixer: Q1 deepening rows (linrel 16 days x 3 K, lineindex K1-3, CNF model); sweeps running Internal adversarial pass, not an independent review. Co-Authored-By: Claude Fable 5.1 --- docs/analysis/cryptanalysis/report-mixer.md | 63 +++++++++++++++++++++ 1 file changed, 63 insertions(+) diff --git a/docs/analysis/cryptanalysis/report-mixer.md b/docs/analysis/cryptanalysis/report-mixer.md index 0bdf1d567..c5279e1ef 100644 --- a/docs/analysis/cryptanalysis/report-mixer.md +++ b/docs/analysis/cryptanalysis/report-mixer.md @@ -132,6 +132,69 @@ above does not depend on the choice. Reconciling the median is handed to adv-mix 1.17x FPGA-datapath gain the chip model does not credit as hash rate (the chip is bound by the 8 cache reads and the fixed op count, not by one day's multiply-adder count), and a weak day is a public calendar. +## Q1 deepening (from 20:4x BST): more days, all key pairs, exact relations, the address bits, a SAT model + +Main's re-scope asked for the probes at full 32-bit width over more days and more rk pairs, a SAT model of two +keyed applications for an algebraic relation, and a relation search in the s[0] line-index bits. Binary sha256 +bbfab24075923083f0c9c8c4372a6dd22257c245bac75ba6fadbd60ab64ec803 (frozen-identical tree, same bytes on both +boxes). Queue files tools/attack/adv-mixer/queue/11..14, claimed in /srv/builds/_adv/mixer/claims. Logs under +/srv/builds/_adv-adv-mixer/logs on each box, copied into docs/analysis/cryptanalysis/logs/adv-mixer when done. + +### Exact affine-relation search at full width (linrel), queue 14, box 2 + +Command: `attack-adv-mixer linrel --day 20729 --apps K --samples 8192 --days 16` for K in 1, 2, 8. Each sample +is a GF(2) row over 1025 columns (512 input bits, 512 output bits, the constant). Rank 1025 means no exact +affine relation a.x XOR b.y = c exists between the input and output bits of K applications; a chance survivor +has odds 2^-(8192-1025) = 2^-7167. + +| Applications K | Days (20729 to 20744) | Rank | Kernel dimension | Reading | +|---|---|---|---|---| +| 1 | 16 of 16 | 1025 | 0 | no affine relation after one application | +| 2 | 16 of 16 | 1025 | 0 | no affine relation after two | +| 8 | 16 of 16 | 1025 | 0 | no affine relation across the full between-reads block | + +This is the decidable algebraic probe the brief's "algebraic form" question needs: at full width with the real +day constants there is no linear or affine structure a chip could use to batch or predict the 8 applications. + +### The line-index bits of s[0] (lineindex), queue 13, box 1 + +Command: `attack-adv-mixer lineindex --day 20729 --apps K --states 1000000 --threads 44`. The 22 address bits +(s[0] AND 2^22-1) against each of the 512 input bits; band 8 sigma = 0.004 at 1e6 states. + +| K | Mean address-bit flip | Holes / 11264 | Strong cells / 11264 | Worst cell | Verdict | +|---|---|---|---|---|---| +| 1 | 0.4275 | 70 | 6904 | 1000 sigma | FINDING: address bits predictable after one application | +| 2 | 0.500007 | 0 | 0 | 3.9 sigma | clean | +| 3 | clean | 0 | 0 | inside band | clean | +| 4 | running | | | | RUNNING | + +Reading for the chip: the line index a read depends on is not predictable before the second of the 8 +applications completes, so a prefetch cannot hide more than 1 of the 8 applications behind the memory latency. +The address-restricted exact relation search (linrel --addr, 8 days, K = 1 and 2) is in the same queue file and +lands here. + +### Fold probes over 1024 days and all 71 adjacent key pairs (fold-sweep), queue 11, box 1 + +Command: `attack-adv-mixer fold-sweep --day 20729 --days 1024 --trials 20000 --threads 44`: probes (a) and +(c) on every adjacent application pair (i, i+1) for i in 0..70 and probe (b) on the full block, per day. +RUNNING; the row lands here. + +### Integral degree test over 32 days (integral), queue 12, box 2 + +Command: `attack-adv-mixer integral --day 20729 --apps K --dmax 16 --placements 2000 --days 32` for K = 1, 2. +RUNNING; the row lands here. + +### SAT model of two keyed applications (cnf), queue 14 then a solve on box 2 + +Command: `attack-adv-mixer cnf --day 20729 --out .../adv-mixer-commute-20729.cnf`. Bit-exact Tseitin encoding +of M(M(x,rk1),rk2) and M(M(x,rk2),rk1) on a shared 512-variable input with the two outputs constrained equal: +105,652 variables, 361,188 clauses, 6.8 MB. SAT = a state on which the two key orders commute; UNSAT = a proof +over all 2^512 states that fold probe (c) holds exactly. No solver reaches the box from crates.io (HTTP 403), so +the harness marks the solve BLOCKED; the sibling lane adv-mixer-3 has cadical 3.0.1 built from source on box 2, +and that binary is running on this instance under a one-hour cap at nice 10 (log sat-commute-20729.log). +RUNNING; the row lands here. A timeout is the honest expected outcome: the instance is a preimage-shaped search +on a 2^512 space, and a plain timeout is a bound on solver reach, not evidence either way. + ## Confirmation across the stale and frozen trees The branch was first cut from stale master 3f0afcd5. Its igneum-pow differed from the frozen object in six