Handoff: Grover test of Refracting Light v3-128

For: ChatGPT (or any assistant) picking up this task later Written: 7 October 2026 Project folder: /Users/premise/Documents/ChatGPT/Ciphers and Chains

Goal

Measure and estimate how Grover’s quantum search affects Refracting Light v3-128 (RL v3):

  1. Preimages: finding a message whose RL v3 output matches a target. Ideal Grover cost ≈ (π/4)·2^(n/2) oracle calls for an n-bit output, so ≈ 2^64 at n = 128.

  2. Mining: proof-of-work search, where Grover gives a quadratic speedup that difficulty adjustment absorbs.

No quantum hardware is available or claimed. Everything is either a simulation at small widths or a resource estimate for full size, and must be labelled as such.

Read first

File

Why

REFRACTING-LIGHT-SPEC.md

the formal spec; §8 is v3 (8 blank finalization steps = v2 over record(M) ‖ 0x00)

refracting_light_v3.py

reference digest() (folded 128) and unfolded() (512)

refracting-light-v3-test-vectors.json

vectors any new code must reproduce

phase3_sat_attacks.py

reuse this: digest_w(m, w) is the width-scaled RL-w (w-bit words, 2w-bit output; equals v3 at w = 64 when RL_VERSION=v3, the default), plus a z3 bit-vector encoding of the step function, a useful template for a reversible circuit

PHASE3-RESULTS.md

all classical results so far (sections A–K); the new results go in a new section

CHAIN-DESIGN.md §2a, §7 (S12, S15)

how RL v3-128 is used: mining, Rad IDs, and half of each single-owner address (RL v3 128 ‖ SHAKE256 128)

Tasks

A. Oracle correctness (classical). For RL-w at w = 2, 3, 4 (output 4, 6, 8 bits), build the oracle f(m) = 1 if digest_w(m, w) == target. Check it against digest_w on every input of the chosen input width.

B. Grover simulation (small widths). Use a numpy statevector simulator (own code, ≤ ~20 qubits) or Qiskit Aer if installed. Input register = n_in qubits (n_in ≥ output bits, e.g. 8–14).

  • The phase oracle may be built from a classically precomputed truth table of digest_w, which is legitimate for measuring iteration counts. Label it “table oracle, not a gate-level circuit”.

  • For each width: count M (the number of preimages of the target), run k = 0…2·k_opt iterations, and record the success probability.

  • Compare the best k with the theory, k_opt ≈ (π/4)·sqrt(N/M), and the peak probability with the theoretical value. Seeded targets, at least 5 targets per width.

  • Pass condition: RL-w behaves like a generic function (Grover gives exactly the generic √ speedup, no more). Any width where far fewer iterations suffice would indicate structure: report it, don’t hide it.

C. Gate-level oracle (stretch). Build a reversible circuit for one RL step at w = 4 (Qiskit or hand-rolled Toffoli/CNOT counting): the constant multiplications (257, 17, 65537), the signed clamp outward, the floor divmod by 2^w, rotations and XORs. Verify it against phase3_sat_attacks.step on all inputs. Report qubits, Toffoli/T-count and depth per step.

D. Resource estimate for full RL v3-128. From C, extrapolate to w = 64:

  • steps per oracle call = 8 × (8 + 6·ceil(len/4)) + 8. For an address preimage over a 44-byte input ("E46-address\0" 12 bytes + 32-byte public key) that is 8 × (8 + 66) + 8 = 600 steps.

  • Grover iterations ≈ (π/4)·2^64 ≈ 1.45 × 10^19, each with 2 oracle calls (compute + uncompute).

  • Give total logical qubits, T-count and depth, and note that parallel Grover on P machines only cuts time to ≈ 2^64/√P.

  • State the address conclusion: the decided address is RL v3 128 ‖ SHAKE256 128. Grover against the whole 256-bit payload costs ≈ 2^128, and the RL half alone ≈ 2^64. Explain why the concatenation is what keeps addresses at ≈ 2^128.

E. Mining. Show how Grover changes proof-of-work: expected classical hashes per block 2^b versus ≈ 2^(b/2) Grover iterations, and why ASERT difficulty adjustment absorbs a quantum miner, at the cost of centralization if only one party has a quantum computer. Plain-language summary only; no simulation needed.

Deliverables (new files only)

  • grover_rl_test.py: tasks A and B (and C if done); seeded; standard library + numpy (+ Qiskit only if already installed).

  • phase3-runs/grover-<timestamp>.json: raw results (widths, N, M, k_opt theory versus measured, peak probabilities, seeds).

  • A new section “L. Grover test” appended to PHASE3-RESULTS.md: a results table, the D estimate and the E summary.

Rules

  1. Tag every claim: PROVEN (maths), MEASURED (with the evidence file), HYPOTHESIS, or ESTIMATE.

  2. No invented results. If something didn’t run, say so. Never describe a simulation as a quantum-hardware run.

  3. Don’t modify existing files except to append section L to PHASE3-RESULTS.md. Don’t touch PEER_REVIEW/, qtl-*-runs/ or existing phase3-runs/ files.

  4. Ask the owner before installing anything (e.g. Qiskit) and before runs longer than about 10 minutes. Use at most 4 CPU workers (the Mac’s fans are an issue).

  5. Project policy: the chain uses no SHA-2. Test code may use any hash as a control, but nothing chain-facing should introduce SHA-256.

  6. Never put passwords or keys in files.

Expected outcome (hypothesis to test, not a result)

RL-w behaves like a generic function under Grover: k_opt matches (π/4)·sqrt(N/M) within simulation precision. At full size, an RL v3-128 preimage needs ≈ 2^64 Grover iterations of a ~600-step reversible oracle, which is why single-owner addresses pair it with SHAKE256-128.