Keyed unlock research direction

The user proposes making decryption require trials even with the correct key, with a very small attacker success probability. This is a proposed change of objective from unkeyed hashing to keyed access. No wallet or encryption implementation was changed in this turn.

The earlier approximately 22-quintillion figure describes a birthday threshold for any collision in an ideal 128-bit hash. It does not quantify the chance of guessing a particular wallet key, forging authentication, or decrypting a particular ciphertext. No such resistance has been established for the experimental Refracting Light.

Separate the mechanisms

  1. A secret key determines authorization. A wrong key must not be accepted merely because a random gate passes.

  2. A password-based key derivation function can make every password guess consume time and memory. Argon2id is a documented approach; its memory and pass counts are tunable. It does not create password entropy. RFC 9106.

  3. Authenticated encryption must check whether decryption produced authentic data before using wallet material. A separate vetted encryption design is required; the Refracting Light digest is not encryption.

  4. A probabilistic gate can delay a valid unlock for an experiment. If it accepts a correct-key attempt with probability one in sixteen, the average wait is sixteen independent trials, with no fixed maximum. This is a hypothetical setting, not a measured security level or an implemented feature.

An application-only retry gate can be removed by an attacker who controls a copy of the encrypted file and the software. Enforcing work against offline attack requires the work to be necessary to derive the decryption key, not merely a conditional check before calling decryption. A server or hardware device could enforce an additional policy, but that introduces a distinct trusted component.

Proposed experiment boundary

Compare a deterministic expensive key derivation against an optional probabilistic gate using disposable test secrets. Measure legitimate unlock time and cost per incorrect guess separately. Do not infer attacker resistance from output width, collision counts, a favorable random trial, or the mere presence of a retry loop. A randomly generated 256-bit secret can be a design input; that alone does not validate a custom cipher or provide a post-quantum security proof.

The preferred baseline has predictable work for the legitimate user and expensive guesses for an attacker. A lottery on correct-key use is a separately labelled availability experiment. No real funds, existing wallet files, or actual user keys are part of this research record.