Skip to content

Latest commit

 

History

33 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Parano1d soundness certificate

This standalone repository instantiates the security analysis for a pinned Parano1d production proof profile. Cross-component invariants and security inequalities are evaluated with arbitrary-precision integer or rational arithmetic.

The public claim graph, open research contracts, accepted evidence and contributor record are versioned in research/. The service at noid.network uses this public verification layer but is not part of the certificate or its acceptance boundary.

The analysis inputs and production acceptance correspondence are pinned to Parano1d v1.0.4 commit fedbe6e3c0ddf8b8372546017bb9bc341acb8ab0. The complete standalone snapshot is model/production.toml, and its repository-relative source-symbol and acceptance-path map is docs/parameter-provenance.md. The executable embeds this snapshot and does not import another checkout. A later production revision requires an explicit snapshot and provenance renewal.

The repository pins the same Rust 1.96.0 toolchain used by the source revision.

Results

Security statement Current production result
Target FRI security 128 bits
Provable Block-Tiwari FS-FRI security 127 bits
Block-Tiwari conjectured comparison, reference only 127 bits
Sequential ideal-QROM half-success boundary 64.707407428576 bits
NIST Post-Quantum Cryptography Category Category 1
Dominant Category 1 gate-depth floor 173.273866314232 bits
Margin over the NIST 2^170 reference 3.273866314232 bits
Complete ideal bound at the Category 1 envelope 0.053364140323608411

The provable FS-FRI row is the certified classical lower bound. The conjectured row is shown only to compare against the corresponding literature estimate and is not used by the certificate. The remaining rows concern a different game: acceptance of an invalid terminal State whose recursive ancestry starts at genesis by a quantum adversary.

C1 is the source identifier for the production wide-challenge profile. Its algebraic challenges are elements of GF(2^256), sampled uniformly from a trace-one affine set of cardinality 2^255. In the security statement, Category 1 is the NIST Post-Quantum Cryptography resource target referenced to exhaustive key search against AES-128, including the NIST MAXDEPTH limits. The resource theorem, not the profile name, establishes the assessment.

The fixed Poseidon2b production conclusions are explicit implications:

at T = 2^64:
    Delta_P2b < 0.312471062061564258

at the NIST Post-Quantum Cryptography Category 1 resource envelope:
    Delta_P2b^C1 < 0.446635859676391589

The Category 1 result also states the coherent response-cost premise used to translate oracle queries into logical gates and circuit depth. These conditions are part of the theorem, not omitted implementation notes.

The certificate also instantiates the algebraic cryptanalysis published in ePrint 2026/306. Its headline wide-tensor attack family is structurally outside the production width-four permutation. Appendix A applies to the MDS two-to-one feed-forward compression used by production Merkle trees. For the snapshotted GF(2^128), t=4, x^7, RF=8, RP=58 instance, Theorem 5.1 gives

round skip                 (1, [1, 7])
ideal-degree upper bound   7^73
log2(d_I^2) dedicated algebraic projection   409.873818620410

The final value is the paper's classical dedicated-attack projection with omega=2, derived from an ideal-degree upper bound. The paper concludes that its attacks do not reduce the claimed 128-bit security of the full-round recommended instances. This projection does not evaluate the fixed-Poseidon2b QROM delta, which remains a separate premise of the end-to-end theorem. The exact correspondence and scope are included in the Category 1 proof.

The certificate also instantiates the nonlinear-subspace models from ePrint 2026/1792. It checks the required balancing rank against the exact production internal matrix over GF(2^128), obtaining N_e=0xbe32. The production constraint budget is E_c=2, so the new trail covers four of 58 partial rounds. The smallest attack-cost projection in that comparison is 1022.830074998558 bits under its omega=2 semi-regular Macaulay model. It is weaker than the existing ePrint 2026/306 feed-forward projection and does not change the certificate conclusion. This is an attack-model projection, not a claim of 1022-bit security. The exact calculation and scope are in the August 2026 Poseidon2b review.

The complete derivations are in:

Block-Tiwari comparison

Block and Tiwari define concrete FS-FRI security as the minimum expected classical random-oracle query work over every positive integer query budget. Their published comparison and the production Parano1d row are:

Organization Repository or configuration Target Provable Conjectured
Polygon Plonky2 100 38 99
StarkWare stone-prover 96 54 99
StarkWare SHARP Verifier 96 59 95
dYdX dYdX Protocol 80 52 79
Polygon Miden Miden-VM 96 / 128 45 / 67 96 / 128
Lambda Class lambdaworks 80 / 100 / 128 81 / 99 / 127 81 / 101 / 129
RISC Zero RISC Zero 100 37 99
Matter Labs era-boojum 100 50 99
Parano1d History B25 / B255 128 127 127

Both Parano1d values lie in the exact interval [127, 128). Their whole-bit values are equal because the 256-bit random-oracle collision term controls the minimum expected-work scale in both calculations. The descriptive logarithms of the two exact rational work values are different:

proved lower bound          127.194502224322
conjectured reference only  127.207518749639

See the full calculation for the metric, local RBR premises, exact optimizer and primary sources.

Certification basis

ProductionParameters::load parses the embedded production snapshot and constructs the typed analysis tuple. It validates the full source revision, the independent wallet ledger and geometry values, the HistoryStep and BaseFold query counts, both canonical History PCS profiles, the wide-challenge support, the derived algebraic root bounds, the fixed Poseidon2b profile, both linear matrices and the Merkle compression mode. Construction fails before any security calculation if a required equality or geometry invariant does not hold.

The documents define the security games, identify the applicable published theorems and derive every Parano1d-specific term. Separate Rust types preserve the distinction between the Block-Tiwari, sequential QROM and depth-aware Category 1 statements. Probabilities, optimizer boundaries and resource inequalities are evaluated with arbitrary-size integers and reduced rational numbers. Floating point is confined to descriptive logarithms. Upper bounds are rounded upward and sufficient headroom conditions are rounded downward. Release tests pin the production profile, cover both History classes, exercise optimizer boundaries and compare normative thresholds by exact integer inequalities.

Subject to the fixed Poseidon2b delta and coherent response-cost premises stated in the Category 1 proof, the resulting inequality bounds the success probability of every adversary inside the declared resource envelope by less than one half in the from-genesis invalid-State game.

This repository provides a Category 1 resource assessment for the Parano1d soundness game. It does not claim that NIST reviewed or certified Parano1d.

Theorem dependencies

Layer Evidence
Classical FS-FRI compiler and expected-work definition Block and Tiwari, linked and instantiated in docs/block-tiwari.md
RBR foundation and Reed-Solomon proximity bounds Block et al., Ben-Sasson et al. and Haböck, specialized to both production History classes in the same document
Sequential QROM lifting and adaptive all-root composition Chiesa, Manohar and Spooner together with FRACTAL, specialized in docs/category-one.md
Parallel compressed-oracle transition and collision bounds Chung, Fehr, Huang and Liao, specialized to typed production responses in the Category 1 document
Category 1 reference resources NIST Section 4.A.5, evaluated at every stated MAXDEPTH point
Published classical Poseidon2b cryptanalysis Merz and Rodríguez García, plus Li, Liu and Wang, specialized to the production permutation and compression mode in src/poseidon2b_cryptanalysis.rs
Production correspondence the full revision pin, standalone snapshot and source-symbol map in docs/parameter-provenance.md
Numerical conclusions exact rational arithmetic and release regression tests in this crate

Reproduce

Clone the standalone certificate repository and run the default report:

git clone https://github.com/ignotusnemo/parano1d-soundness.git
cd parano1d-soundness
cargo run --release --locked

To print every reduced rational certificate and optimizer boundary:

cargo run --release --locked -- --exact

To verify snapshot validation, exact arithmetic, optimizer boundaries and all normative result thresholds:

cargo test --release --locked

Source layout

Path Responsibility
model/production.toml source-pinned production input snapshot
docs/parameter-provenance.md exact source revision and symbol map
src/parameters.rs parse and cross-check the embedded snapshot
src/local.rs wallet and History generalized RBR bounds
src/block_tiwari.rs exact classical-ROM expected-work optimizer
src/poseidon2b_cryptanalysis.rs source-pinned specialization of published Poseidon2b algebraic attacks
src/qrom.rs sequential ideal-QROM all-root bound
src/resource.rs depth-aware Category 1 resource calculation
src/exact.rs arbitrary-size rational arithmetic and directed decimals
src/main.rs human-readable and exact certificate output
rust-toolchain.toml pinned compiler and formatter toolchain
research/ public research contracts, submission verifier and evidence ledger

About

Executable soundness analysis for Parano1d production proof parameters, with theorem-backed bounds and reproducible industry-metric comparisons.

Topics

Resources

Stars

5 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages