Refracting Light revision¶
The user requested applying the outward digit methodology to the existing revised Refracting Light hash. The new experiment is versioned as outward-trampoline-v1; the earlier implementation and measurements remain available. This change preserves the sign and offset of each intermediate escape before it enters the bounded mixing state. It does not eliminate collisions in a 64-bit digest or introduce decryption.
Exact construction¶
First create the existing complete RedTail 4+2 record, including its eight-byte original length. Consume every record byte in order, most significant bit first. Set B=16 and define F(z)=z−B for z<=0, otherwise F(z)=z+B−1. Each binary digit becomes F(0)=−16 or F(1)=16.
Initialize x=0 and v=1. For each mapped digit d at zero-based position i:
z = 257*x + 17*v + d*(i+1)
y = F(z)
q, r = divmod(y, 2^32)
v = (65537*v + q + d + i + 1) modulo 2^32
v = ROTL32(v, 13) XOR r
x = r XOR ROTL32(v, (i modulo 31)+1)
Return the 64-bit concatenation x || v, formatted as 16 hexadecimal characters. There is no SHA finalizer, floating point, sampled randomness, secret key, or external recovery manifest. The constants are experimental choices, not established cryptographic parameters.
Signed Euclidean division obeys y=q*2^32+r, including negative y. Thus the quotient and remainder together preserve each intermediate before feedback. The subsequent modular state update is still a compression step: it does not retain a reversible history of those quotients. In particular, invertibility of F does not imply invertibility of the digest.
This version replaces the original per-byte reflection with a per-bit outward mapping and quotient feedback. The comparison therefore measures the entire changed construction, not the isolated effect of F. Inserting a reversible relabelling by itself cannot establish a security advantage.
Verification and measurement scope¶
The test checks the original Hello World hash to confirm that the reference remains unchanged. It verifies signed quotient reconstruction, enumerates all 65,536 two-byte messages, checks the old truncated collision pair, and finds a fresh truncated collision. It measures 4,096 single-input-bit changes across 32 seeded sixteen-byte messages and enumerates 65,536 Hello World nonces.
Hash timing includes RedTail encoding and all bit rounds. Five batches of 1,000 hashes are timed; the reported value is their median per-hash time. Each first-hit search is also timed from nonce zero. Timings describe Python on this machine under its current load, not a hardware-independent cost.
Results¶
Hello World now produces f06230c6897789f9. Median measured time is 195.3 microseconds per hash, approximately 5,121 hashes per second. The previously measured reference was 28.4 microseconds, making this run about 6.9 times slower. This is a comparison of runs, not a simultaneous controlled performance benchmark.
Zero-bit target |
First accepted nonce |
Attempts |
Measured search time |
Accepted hash |
Hits across 65,536 nonces |
|---|---|---|---|---|---|
8 |
184 |
185 |
52.4 ms |
00b57e83322b12f5 |
244 |
10 |
346 |
347 |
98.8 ms |
00348423a73dcb3e |
63 |
12 |
506 |
507 |
144.6 ms |
00067d07d0bf4001 |
15 |
Uniform expected counts are 256, 64, and 16. First-hit attempts are properties of this message and nonce sequence, not expected costs; the early 12-bit hit does not demonstrate a generally faster search. A submitted nonce is checked with one digest computation on the longer nonce-bearing message.
All 65,536 two-byte inputs have distinct full 64-bit digests in this test. The low-16-bit projection has 32,597 colliding pairs versus 33,004 in the old test. That count change is not evidence of cryptographic improvement. Mean output changes were 31.952 bits across the 4,096 single-bit perturbations.
The old pair separates even after truncation:
00 0f -> d235a20e7c01ed60
00 40 -> e0b10c0680010f0f
A newly found pair still collides on the last 16 bits:
00 45 -> 02058ee9719fe5c3
01 5e -> ca186f9f9284e5c3
Their common ending is e5c3; their full digests are distinct. Both cases were verified by the executable census. This directly demonstrates that the outward transformation changes where truncated collisions occur without eliminating them.
Interpretation¶
The complete outward digit sequence can be inverted using the existing outward_digit_clamp.py representation. The final 64-bit digest cannot generally reconstruct that sequence. A cipher would need a separate keyed encryption and authentication design.
Short-output collisions are expected after truncation: for 65,536 inputs and a uniform 16-bit projection, the expected number of colliding pairs is 32,767.5. Separating one old pair does not remove other pairs or establish a stronger hash. No observed 64-bit collisions in this small domain would likewise provide little assurance.
This is a tested implementation of the proposed mapping, with no established preimage, collision, or post-quantum security bound. The runnable specification is refracting_light_trial.py; full results are in outward-trampoline-results.json.