Message encoding and a 64 bit hash

5 October 2026. Current constraint from Michael: no external manifest; any retained recovery information must be incorporated into the message and reversibly handled. Item two is a 64-bit hash. ABS remains deferred.

Item one reversible message encoding

Define E on every bit by E(0)=00 and E(1)=01, reading input bytes most-significant bit first. Two input bytes become four output bytes. Decode by validating each pair’s first bit is zero, then retaining its second bit. For complete byte strings the expansion is self-delimiting through the supplied byte-string length; no separate original-length manifest is needed. Transport framing is still required if multiple messages are concatenated.

This encoding is reversible and unkeyed; it is not encryption. Any later escape residual or other information required for recovery must also be encoded in the message, with an unambiguous format. Calling it salt does not remove its size or make it recoverable from a smaller hash. A conventional salt is an additional input, not an inverse operation. Arbitrary longer messages cannot all be reversibly represented in a self-contained 64-bit output.

Item two a fixed 64 bit fingerprint

Proposed experimental structure:

message bytes -> E(message) -> mixing and finalization -> 8-byte digest

There is no manifest and no random salt in this branch. Identical byte strings produce identical results. If a salt is introduced later, the function will hash the message-and-salt pair, and comparison will require the same salt.

The custom RedTail mixing and finalization are not yet specified. To establish a reproducible comparison control, this record uses SHAKE256, an existing standardized extendable-output function, and asks for eight bytes. This is not a new RedTail cipher or an independently designed hash. SHAKE is specified in NIST FIPS 202.

Exact reference definition:

reference64(m) = SHAKE256(ASCII("RedTail64-reference-v1") || 0x00 || E(m), 64 output bits)

The fixed prefix identifies this experimental use. It is part of the algorithm, not a per-message manifest, random salt, or secret key. E preserves all input distinctions, but doubles the input size without adding entropy. This control obtains its cryptographic mixing from SHAKE256.

Verified example

Input is exactly Hello World, UTF-8, capital H and W, one space, no newline.

  • Original: 11 bytes, 88 bits.

  • Expanded: 22 bytes, 176 bits.

  • Expanded hexadecimal: 10401411145014501455040011151455150414501410.

  • Reference digest: 0a449e6b87a57f70.

  • Output: 8 bytes, 64 bits, displayed as 16 hexadecimal characters.

The expansion was decoded and checked against the input. The digest was calculated using Python hashlib.shake_256 and checked to be eight bytes. The digest itself is not reversible.

Reproduction:

import hashlib

def expand(message):
    out = bytearray()
    for byte in message:
        word = 0
        for bit in range(7, -1, -1):
            word = (word << 2) | ((byte >> bit) & 1)
        out.extend(word.to_bytes(2, 'big'))
    return bytes(out)

def reference64(message):
    prefix = b'RedTail64-reference-v1\x00'
    return hashlib.shake_256(prefix + expand(message)).digest(8)

assert reference64(b'Hello World').hex() == '0a449e6b87a57f70'

Collision implications

There are 2^64 possible outputs. Collisions must exist for a larger input domain. Under an ideal uniform-output model, generic collision search takes on the order of 2^32 evaluations; approximately 1.177 times 2^32 independent samples give a 50 percent collision probability. This is distinct from the roughly 2^64 generic work to target a specified digest under the same ideal model.

The short output therefore does not retain SHA-256’s 128-bit generic collision security. It is a useful research fingerprint size, but does not meet that security target for a SHA-256 replacement. Output width is a separate parameter from internal state size; requesting 64 output bits does not require a 64-bit internal state.

Next comparison: define the proposed custom mixing rule and compare it to this reference using explicit collisions and small-output exhaustive experiments. A shorter-output collision experiment must be labeled as such; it does not constitute a demonstrated collision in the full 64-bit output. No 64-bit collision search was performed for this record.