UNC Quantum Time Lock construction

QTL is the user’s nomenclature. With the correct credential, X minutes denotes an intended computational unlock cost. Without it, the desired cost is vastly greater, but no “light-years” attacker estimate has been established. The name does not imply a quantum computer, an expiration time, or a proven time-lock puzzle.

The two Python files

  • unc_qtl_folded.py: the 128-bit Refracting Light output, 32 hexadecimal characters, for local collision hunting. Keep the unfolded file next to it.

  • unc_qtl_unfolded.py: all four internal lanes concatenated, totaling 512 bits or 128 hexadecimal characters, for the user’s collision hunt. It contains the shared implementation and can run alone.

Both compute identical internal rounds. Unfolded means the complete finite internal state before the final fold. It does not mean an unbounded, reversible record of every input or escape. A collision in the unfolded state also collides after folding; the reverse implication does not hold.

The scripts require only Python’s standard library for collision hunting. Hash-only equivalence was checked against the existing Refracting Light v2 implementation on five representative messages. No original hash rounds were changed.

Access construction and current test status

The shared file contains explicit calibrate, keygen, seal, and unlock commands. Following the user’s request to begin access testing, small-work checks passed with generated disposable secrets: correct-key recovery, wrong-key rejection, tampered ciphertext/header rejection, and repeatable password derivation. The five-minute user-password run succeeded. Test Two subsequently demonstrated modified-parameter rejection and successful return to the control, followed by a later control rejection whose credential context is unresolved. See PEER_REVIEW/2026-10-05/E46-TESSERA-QTL-REVIEW.md, exp-2-test-one.md and exp-2-self-check-results.json.

The proposed flow is a password or disposable random 256-bit test key, a fresh 16-byte salt, required Argon2id computation, and AES-256-GCM authenticated encryption/decryption. Key derivation produces 32 bytes. The envelope stores its format, KDF costs and version, credential mode, salt, nonce, intended target minutes, and research view. The header is authenticated as associated data. A fresh 12-byte nonce is generated when sealing. Outputs are created without overwriting existing files and with owner-only file permissions. Authentication must succeed before recovered data is written.

Refracting Light is not substituted for Argon2id or AES. Those are separate established primitives; packaging them alongside the collision experiment does not validate Refracting Light as a KDF or cipher. The folded/unfolded setting controls the research hash output, not the AES key length or password entropy.

Future calibration measures a small fixed number of Argon2id passes and estimates the pass count for the requested X-minute budget. Unlock executes that stored amount of work. It does not wait for a clock, sleep, repeatedly flip a coin, or require a public nonce target. Actual duration depends on the machine and workload. An attacker can have different hardware or use parallel guesses. Holding the final derived decryption key bypasses password derivation.

The prototype limits accepted KDF settings and file sizes to bound resource consumption. These limits are implementation policy, not a security proof. Password quality still matters. A random test-key file is an alternative credential mode, not implemented second-factor authentication. The external secret factor and software-signature policy remain deferred; a public signature alone is not a secret factor.

Access commands require argon2-cffi and cryptography, now installed in the isolated .venv-qtl environment. Imports remain deferred; collision commands do not load them. Installation and small-work checks followed the later user instruction to begin QTL testing.

Sources

The custom file format and surrounding application code are our experimental design, not a separately standardized protocol.

Order of work

  1. Continue collision and structural analysis of the hash, with distinct labels for message collisions and arbitrary-state fold collisions.

  2. Specify reproducible digest vectors, nonce solving, and verification.

  3. Execute exp-2-test-one only when the user proceeds with access testing.

  4. Consider SDK packaging for Python, C++, C#, and Rust after the function and interfaces are stable. No SDK implementation is authorized as part of the present step.

Hash portion results and commands

The continued folded collision hunt tested 22,640 unique messages, combining 20,000 sequential eight-byte inputs with structured and seeded variable-length inputs. It found zero full 128-bit collisions in 21.73 seconds. Results are in exp-1-folded-128-hunt.json. That run preceded addition of the hash/solve/verify CLI commands, so its source fingerprints identify the earlier command interface; the hash rounds are unchanged.

The subsequent hash-only solver found and independently verified nonce 1566 for Hello World with 12 leading zero bits. It tried 1,567 nonces in 2.28 seconds and produced 000b8d571006fbe129af3054dfadbc0a. Nonce zero was separately checked and rejected for that target. Solving a hash target is not QTL unlocking.

Six vectors in refracting-light-test-vectors.json give both output forms, including empty input, leading zeros, binary bytes, and text. Re-folding each recorded 512-bit state reproduces its 128-bit vector. These checks establish consistency on those inputs, not cryptographic strength.

Run only the hash portion:

python3 unc_qtl_folded.py hash --text 'Hello World'
python3 unc_qtl_folded.py solve --text 'Hello World' --zero-bits 12 --max-nonces 10000
python3 unc_qtl_folded.py verify --text 'Hello World' --zero-bits 12 --nonce 1566
python3 unc_qtl_unfolded.py hunt --messages 100000 --message-bytes 8 --random 1000 --progress 10000

The unfolded hunt compares all 128 hexadecimal characters, not a truncated diagnostic. Its 512-bit output is still a bounded state. Both files must be kept together to run the folded entry point. Running hunt, hash, solve, or verify never calls QTL access functions or imports the optional cryptographic dependencies.

Portability notes for later SDK work

Message bytes and nonce bytes are exact. Text uses UTF-8 without normalization. Nonces are eight-byte unsigned big-endian integers appended to message bytes before RedTail encoding. Original length is an eight-byte big-endian integer. GF(256) arithmetic uses polynomial 0x11d and the custom parity rows. Process each record byte from its most significant bit to its least significant bit.

Internal words are unsigned 64-bit values after masking. Intermediate arithmetic before division uses unbounded signed integers. Division must reproduce Python’s Euclidean quotient and nonnegative remainder; C++/C#/Rust signed division defaults must not be assumed equivalent for negative intermediates. Concatenate each lane’s position before velocity, then lanes zero through three. The folded view rotates lanes by 0, 29, 61 and 97 bits before XOR. Implementations must avoid overflow in intermediate arithmetic and match the saved vectors before being considered compatible.