scieee AI-readable full text Open interactive document viewer

Dual-Torus Architecture in SHA-256: Carry-Field Tomography Reveals Asymmetric Subsystem Design

Davis, Bee Rosa

Abstract

We introduce carry-field tomography, a geometric methodology that treats per-bit carry events in modular addition as a discrete curvature field on the SHA-256 state torus (Z/2^32 Z)^8. By partitioning staged additions into channel-specific subsystems and measuring second-order coherence structure, we discover that SHA-256 implements a dual-clock architecture with fundamentally different mixing characteristics: A-torus (Maj, Sigma_0, registers a,b,c,d): Rigid 8-round correlation length with zero variance—a deterministic metronome providing rapid symmetric diffusion. E-torus (Ch, Sigma_1, registers e,f,g,h): Variable 10-16 round correlation length (mean 12)—a path-dependent carrier providing nonlinear security margin. Bridge (d + T1 -> e'): Transfers A-diffused structure into E-timing, following the E-clock while preserving A-like fingerprint structure. The subsystems are structurally independent (RV coefficient approximately 1.2%) but temporally coupled through the bridge. This asymmetric design explains why the Nikolic-Biryukov 9-step local collision exploits the predictable A-clock, while extended attacks require geometry-guided targeting of trailing registers where the slower E-clock provides residual structure. We propose a Round 20 security horizon where both clocks fully thermalize across all registers, and formulate a BKM-style regularity criterion (the structure persistence integral) bounding viable attack depth. Keywords: SHA-256, cryptanalysis, ARX primitives, differential geometry, discrete curvature, correlation length, hash function security, carry propagation, geometric cryptanalysis.

Full text

Dual-Torus Architecture in SHA-256: Carry-Field Tomography Reveals Asymmetric Subsystem Design Bee Rosa Davis * December 2025 Abstract We present a novel structural analysis of SHA-256 using carry-eld tomography , a methodology that treats per-bit carry events in modular addition as a discrete curvature eld on the state torus (Z/232Z)8 . By partitioning staged additions into channel-specic subsystems and measuring second-order coherence structure, we discover that SHA-256 implements a dual-clock architecture with fundamentally dierent mixing characteristics:  A-torus (Maj, Σ0 , registers a, b, c, d ): Rigid 8-round correlation length with zero variance across message populationsa deterministic metronome providing rapid symmetric diusion.  E-torus (Ch, Σ1 , registers e, f, g, h ): Variable 1016 round correlation length (mean 12)a path-dependent carrier providing nonlinear security margin.  Bridge ( d+T1→e′ ): Transfers A-diused structure into E-timing, following the E-clock (12 rounds) while preserving A-like ngerprint structure. The subsystems are structurally independent (RV coecient 1.2%) but temporally coupled through the bridge. This asymmetric design explains why the Nikoli¢-Biryukov 9step local collision exploits the predictable A-clock, while extended attacks require geometryguided targeting of trailing registers where the slower E-clock provides additional structure. Our methodologydening sector coordinates from spectral coherence of carry patterns, with stratied confound matchingprovides a general framework for geometric cryptanalysis of ARX primitives. Contents 1 Introduction 3 1.1 AGeometricPerspective................................ 3 1.2 MainContributions................................... 3 1.3 RelatedWork...................................... 3 2 Theoretical Framework 4 2.1 TheStateTorus .................................... 4 2.2 Round Update as Nonlinear Map . . . . . . . . . . . . . . . . . . . . . . . . . . . 4 2.3 Carry Events as Discrete Curvature . . . . . . . . . . . . . . . . . . . . . . . . . . 5 2.4 ChannelPartition.................................... 7 2.5 Sector Coordinates from Coherence . . . . . . . . . . . . . . . . . . . . . . . . . . 8 2.6 ConfoundControl.................................... 8 * Principal Adversarial Intelligence Engineer. Electronic mail: [redacted for preprint] 1 3 Experimental Methodology 9 3.1 InstrumentedSHA-256................................. 9 3.2 FingerprintConstruction................................ 9 3.3 Correlation Length Measurement . . . . . . . . . . . . . . . . . . . . . . . . . . . 9 3.4 Cross-Channel Correlation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10 4 Experimental Results 10 4.1 Correlation Length by Channel . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10 4.2 Cross-Channel Independence . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11 4.3 BridgeAnity ..................................... 11 5 The Dual-Torus Architecture 12 5.1 ArchitectureSummary................................. 12 5.2 Functional Interpretation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12 5.3 WhyThisDesignWorks................................ 12 6 Connection to Classical Cryptanalysis 13 6.1 The Nikoli¢-Biryukov Local Collision . . . . . . . . . . . . . . . . . . . . . . . . . 13 6.2 Trailing Register Vulnerability . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14 6.3 TheSecurityHorizon.................................. 14 7 Design Implications 14 7.1 TheNSA'sDesignChoice ............................... 14 7.2 Rotation Constant Selection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15 7.3 Generalization to ARX Primitives . . . . . . . . . . . . . . . . . . . . . . . . . . . 15 8 Conclusion 15 8.1 Practical Implications for Cryptanalysis . . . . . . . . . . . . . . . . . . . . . . . 16 8.2 A BKM-Style Regularity Criterion . . . . . . . . . . . . . . . . . . . . . . . . . . 16 8.3 OpenQuestions..................................... 16 8.4 TheUniedThesis................................... 17 A Notation Reference 18 B Experimental Parameters 18 C SHA-256 Round Function Reference 18 2 1 Introduction The security of cryptographic hash functions rests on their approximation of random oracles functions whose outputs are computationally indistinguishable from uniform random strings. For SHA-256, this property emerges from the avalanche eect : small input changes propagate rapidly through the compression function, destroying exploitable structure. Traditional cryptanalysis evaluates mixing through dierential and linear methods, measuring how input dierences propagate probabilistically. These approaches treat the hash function algebraically, analyzing Boolean equations and their statistical biases. While powerful, they provide no geometric intuition for why certain attacks succeed and others fail. 1.1 A Geometric Perspective We propose a fundamentally dierent approach: carry-eld tomography on the discrete state torus. Rather than asking how do bit dierences propagate? we ask: 1. What is the shape of the carry-eld correlation structure? 2. How does this structure decay across rounds? 3. Do dierent functional subsystems exhibit dierent geometric clocks ? The key insight comes from treating modular addition carries as a discrete analogue of curvature. In Riemannian geometry, curvature measures the failure of parallel transport to preserve vectors around closed loops. In SHA-256, carries measure the failure of XOR (the linear approximation) to match modular addition. High carry activity indicates regions where the linear model breaks downprecisely where cryptographic nonlinearity lives. 1.2 Main Contributions 1. Carry-Field Tomography Framework. We develop a methodology for extracting geometric structure from staged modular additions, dening sector coordinates from secondorder coherence measures with proper confound control. 2. Dual-Clock Architecture Discovery. We empirically demonstrate that SHA-256 contains two weakly-coupled subsystems with dierent correlation timescales: the A-torus (8-round clock) and E-torus (12-round clock). 3. Bridge Characterization. We show that the d+T1 operation acts as a one-way valve, transferring A-structure into E-timing while maintaining structural independence (RV coecient 1.2%). 4. Connection to Classical Cryptanalysis. We explain why the Nikoli¢-Biryukov 9-step local collision succeeds (it exploits the A-clock) and why geometry-guided attacks extend to Round 18 (they target E-clock trailing registers). 1.3 Related Work Dierential Cryptanalysis of SHA-256. Nikoli¢ and Biryukov [1] introduced practical collisions for step-reduced SHA-256 using a 9-step local collision with modular dierences. Sanadhya and Sarkar [2] extended this to 24 steps. Mendel et al. [3] achieved 31-step collisions using extended local collision techniques. Our geometric analysis explains why these attacks plateau: the A-torus thermalizes at 8 rounds, removing exploitable A-structure. 3 Higher-Order Dierential Attacks. Lamberger and Mendel [4] applied higher-order dierentials to SHA-256, achieving distinguishers up to 46 steps. The connection between algebraic degree collapse and our E-clock thermalization merits further investigation. ARX Cryptanalysis. The broader literature on Addition-Rotation-XOR primitives [5] treats carries as the primary source of nonlinearity. Our contribution is to organize this into a channelspecic geometric framework with measurable correlation timescales. Heat Kernel Methods. In our companion work [6], we introduced heat kernel cryptanalysis : treating the SHA-256 state space as a discrete manifold and analyzing diusion via the heat equation ∂tu= ∆u , where ∆ is a graph Laplacian constructed from state transitions. The heat kernel Kt(x, y) = Pke−λktϕk(x)ϕk(y) encodes how probability mass spreads from state x to state y after t rounds. Spectral gaps in the Laplacian eigenvalues λk determine mixing rates. That work identied trailing register vulnerabilities using curvature-weighted variable selection for cube attacks; the present paper explains why those vulnerabilities exist via the dual-clock architecture. Geometric Field Theory. The geometric intuitions in this work draw from a broader program [7] applying dierential geometry to discrete computational systems. The key insight is that nonlinear operations create curvature in the sense that parallel transport (tracking how structures evolve) fails to commute around closed paths. In SHA-256, carries quantify this failure: the dierence between the linear approximation (a⊕b) and the true result (a+bmod 232) measures local curvature. Regions of high carry activity are geometrically curved, while low-carry regions are at. This perspective motivates treating carry statistics as a discrete curvature eld. 2 Theoretical Framework 2.1 The State Torus SHA-256 compression operates on an 8-word internal state: xt= (at, bt, ct, dt, et, ft, gt, ht)∈(Z/232Z)8 (1) This is a nite abelian group. Embedding each word w∈ {0,...,232 −1} into [0,1) by w7→ w/232 gives: (Z/232Z)8 behaves like a discrete sampling of T256 = (R/Z)256 (2) The torus terminology reects periodic boundary conditions induced by modular arithmetic just as angles wrap around at 360◦ , 32-bit words wrap around at 232 . This creates a closed, bounded state space where trajectories cannot escape to innity. The geometry of this space (how far apart two states are, how trajectories curve) underlies our analysis. 2.2 Round Update as Nonlinear Map Let the compression update be written as: xt+1 = Φt(xt, Wt), t = 0,...,63 (3) where Wt is the message schedule word. The update uses Boolean functions Ch , Maj , rotations, and additions mod 232 . 4 Figure 1: The SHA-256 state space as a discrete torus. Each 32-bit word wraps at 232 , inducing periodic boundary conditions analogous to angles wrapping at 360◦ . The state trajectory (red) winds through 64 rounds from initialization (green) to nal hash (red square). The color gradient indicates round progression. This embedding motivates treating SHA-256 compression as a discrete dynamical system on T256 = (Z/232Z)8 . Denition 2.1 (SHA-256 Round Functions) . Σ0(x) = ROTR2(x)⊕ROTR13(x)⊕ROTR22(x) (4) Σ1(x) = ROTR6(x)⊕ROTR11(x)⊕ROTR25(x) (5) Maj(a, b, c) = (a∧b)⊕(a∧c)⊕(b∧c) (6) Ch(e, f, g) = (e∧f)⊕(¬e∧g) (7) Remark 2.2 (Functional Asymmetry) . Maj is symmetric : each input aects the output in 3 of 4 cases. Ch is asymmetric : input e gates between f and g . This functional asymmetry is central to our ndings. 2.3 Carry Events as Discrete Curvature Bitwise XOR is linear over F2 : it satises (a⊕b)⊕c=a⊕(b⊕c) and produces no surprises. A 32-bit modular addition, however, is fundamentally nonlinear due to carry propagation. The relationship can be decomposed as: a+b= (a⊕b) + 2(a∧b) + higher carry interactions (8) The term 2(a∧b) represents positions where both inputs have 1-bits, forcing a carry. Carries encode the failure of the linear (XOR) approximation . In our geometric analogy, this failure 5 Figure 2: Nested subsystems with weak structural coupling. The A-torus (blue, inner) and E-torus (orange, outer) occupy the same state space but operate with dierent correlation timescales. The RV coecient between their Gram matrices is 1.2%essentially noise oor indicating structural independence despite geometric nesting. The combined system's correlation length (8 rounds) is dominated by the A-channel's zero-variance clock, masking the E-channel's longer memory in composite measurements. is curvature: just as a curved surface cannot be attened without distortion, the modular addition cannot be linearized without error. High carry activity indicates regions where the linear model breaks downprecisely where cryptographic nonlinearity lives. Example 2.3 (Curvature Extremes) . Consider adding 0xFFFFFFFF + 0x00000001 . The XOR approximation gives 0xFFFFFFFE , but the true sum is 0x00000000 with a carry-out. This single addition generates 32 carry eventsmaximum curvature. In contrast, 0x00000001 + 0x00000001 = 0x00000002 produces only one carry (at bit 0)minimal curvature. Regions of high carry activity are where SHA-256's nonlinearity concentrates. Denition 2.4 (Carry Mask) . For an addition at operation index u , dene the carry mask: Mu∈ {0,1}32, Mu[b]=1 if there is a carry out of bit b (9) For SHA-256 with 7 staged additions per round, we index: Ft,s,b := Mt,s[b]∈ {0,1} (10) 6 Figure 3: Carry activity as discrete curvature. Gaussian curvature on a torus varies by position: the outer rim (red, positive curvature) corresponds to regions of high carry activity, where the XOR linear approximation fails most severely. The inner rim (blue, negative curvature) corresponds to low-carry regions where modular addition behaves nearly linearly. In SHA-256, high-curvature regions drive faster mixing and quicker thermalization. Color scale: Gaussian curvature K∝ carry density. where t is round index, s∈ {0,...,6} is stage index, and b∈ {0,...,31} is bit lane. 2.4 Channel Partition We partition the 7 staged additions by functional provenance: Table 1: Stage-to-Channel Assignment Stage Operation Channel Rationale 0 h+ Σ1(e) E E-register input 1 +Ch(e, f, g) E E-function 2 +Kt Neutral Constant injection 3 +Wt Neutral Message injection 4 Σ0(a) + Maj(a, b, c) A A-function 5 d+T1 Bridge A → E conduit 6 T1+T2 A A-register update This gives channel denitions: E-channel :{0,1} (11) A-channel :{4,6} (12) Bridge :{5} (13) 7 2.5 Sector Coordinates from Coherence We dene sector coordinates from second-order structure of the carry eld, avoiding the nearconstant statistic trap of rst-order measures. Denition 2.5 (Temporal Spectral Coherence) . Row-normalize centered operation vectors: ˜ Xu,·:= Xu,· ∥Xu,·∥2 (14) where X=F−1µ⊤ is the centered carry eld. Then: GT:= ˜ X˜ X⊤, QT,eig := λmax(GT) N (15) Interpretation: If many operations share a common carry mode, λmax concentrates and QT,eig rises. Denition 2.6 (Spatial Spectral Concentration) . Compute bit-bit covariance: CB:= 1 NX⊤X (16) Let eigenvalues be λ1≥λ2≥ · · · ≥ λ32 ≥0 . Then: Qλ:= PK k=1 λk P32 k=1 λk ,(K= 5) (17) Interpretation: How low-rank the bit-lane correlation geometry is. Denition 2.7 (Wedge Sector Coordinate) . Q∧:= QT,eig ·Qλ (18) This is high only when temporal operation patterns are mode-locked and that locking is expressed through a small set of correlated bit modes. 2.6 Confound Control Message statistics (Hamming weight, word magnitudes) correlate with carry statistics. Without matching, a classier can cheat by exploiting message properties rather than geometric structure. Denition 2.8 (Stratied Tail Matching) . Let ψ(m) be message summary statistics. Dene stratum key: κ(m) := HW(m) ∆hw ,mean(m) ∆mv  (19) where HW(m) is the Hamming weight (number of 1-bits) and mean(m) is the mean word value across the message. Sample HI and LO sectors to have identical distributions over κ . This stratication is essential: messages with more 1-bits naturally produce more carries (since 1 + 1 = 102 generates a carry while 0 + 0 = 0 does not). Without matching on Hamming weight, a naïve classier could achieve spurious accuracy by detecting message statistics rather than cryptographic structure. Stratied matching ensures that any detected signal reects genuine geometric dierences in how SHA-256 processes structurally-equivalent inputs. 8 3 Experimental Methodology 3.1 Instrumented SHA-256 We implement SHA-256 per FIPS 180-4 with state capture at congurable rounds. Each trajectory records:  Input message m∈ {0,1}512 (single block)  Carry masks Ft,s ∈ {0,1}32 for all 7 stages across 64 rounds  Staged intermediate values for verication Implementation validated against all FIPS 180-4 test vectors. 3.2 Fingerprint Construction For a window [r0, r1) and channel stages S , we construct a 39-dimensional ngerprint:  Per-bit carry rates (32 dimensions)  Top-5 eigenvalue ratios of bit-covariance (5 dimensions)  QT,eig (1 dimension)  Mean density (1 dimension) Fingerprints are centered and normalized for cosine similarity comparisons. 3.3 Correlation Length Measurement The correlation length measures how many rounds of SHA-256 processing are required before carry patterns become statistically independent from their initial state. Intuitively, if two ngerprints from rounds r and r+k are correlated, structure from round r persists into round r+k an attacker might exploit this persistence. When correlation drops to zero, the structure has thermalized and earlier structure provides no advantage. Denition 3.1 (Thermalization) . Thermalization is the process by which structured patterns in the state decay to statistical equilibrium, becoming indistinguishable from random. A thermalized subsystem provides no exploitable structure to an attacker. The correlation length ξ measures the thermalization time: after ξ rounds, initial structure has decayed below the noise oor. Remark 3.2 (Security Implication of Correlation Length) . A correlation length of ξ rounds means that structure from round r persists (in a statistically detectable way) until round r+ξ . An attacker can exploit this persistence: if they control input dierences that create favorable structure at round 0, that structure remains useful for ξ rounds. Beyond ξ , the advantage vanishes. Thus, correlation length directly bounds the round-depth of structural attacks . Denition 3.3 (Recurrence Matrix) . For ngerprints ϕW across sliding windows W : S(i, j) = Emsim(ϕWi(m), ϕWj(m)) (20) where similarity is cosine after centering. Denition 3.4 (Correlation Length) . The correlation length ξ is the rst lag where the diagonal decay S(i, i + lag ) falls below threshold (typically 0): ξ:= min{ lag :¯ S diag ( lag )<0} × ∆ step (21) where ∆ step is the window step size in rounds. 9  Round 20 is the security horizon where all structure thermalizes. The methodologysector coordinates from spectral coherence, stratied confound matching, channel-split tomographyprovides a general framework for geometric cryptanalysis of ARX primitives. 8.1 Practical Implications for Cryptanalysis Our ndings have direct implications for attacking reduced-round SHA-256: 1. Target selection : Focus cube/dierential attacks on E-channel trailing registers (g, h) between rounds 1218, where the A-torus has thermalized but the E-torus has not. 2. Attack bounds : The 8-round A-clock provides a hard lower bound on attack complexity A-structure is gone by Round 8 regardless of technique. The variable E-clock (1016 rounds) determines the upper bound E-structure persists longer but eventually thermalizes. 3. Variable selection : Geometry-guided cube attacks should weight input variables that maximize E-channel carry activity in early rounds, as this structure persists longest. 4. Collision search : Local collision techniques should exploit the predictable A-clock for the collision core, then use message freedom to control E-channel evolution through the variable window. The Round 1718 algebraic cli observed in our cube attack experiments corresponds precisely to E-clock thermalization in trailing registers. 8.2 A BKM-Style Regularity Criterion The preceding analysis suggests a formal criterion for structure persistence, analogous to the Beale-Kato-Majda criterion for Navier-Stokes regularity. Denition 8.1 (Structure Persistence Integral) . Let S(r) denote a per-round structure intensity observable (e.g., sector separability or centered carry-eld recurrence at lag 1). Dene the cumulative structure persistence: S(R) = R X r=0 S(r) (23) Conjecture 8.2 (Finite Horizon) . For SHA-256, S(R) saturates by R≈20 : there exists R∗≈ 20 such that S(R∗)≈ S(64) . Beyond R∗ , no additional exploitable structure accumulates. This is the discrete analog of the Beale-Kato-Majda criterion: security (regularity) is preserved because the intensity integral is nite. Just as BKM bounds vorticity to prevent uiddynamical blowup, the structure persistence integral bounds the round depth of viable attacks. 8.3 Open Questions 1. Can the correlation length be predicted analytically from round function specication? 2. Does the E-clock variability correlate with message entropy or structure? 3. Can manifold-based search accelerate practical collision nding? 4. Do other ARX primitives exhibit similar dual-clock architectures? 16 5. Can the structure persistence integral S(R) be computed eciently for arbitrary primitives? The intersection of dierential geometry, spectral analysis, and cryptanalysis represents fertile ground for future research. 8.4 The Unied Thesis The results presented here are instances of a broader mathematical pattern. In all three settings we have studiedRicci/Wilson ow on gauge congurations, vorticity evolution in NavierStokes, and carry-eld dynamics in SHA-256the measurable nonlinearity proxy (plaquette curvature variance, vorticity magnitude, or carry-eld coherence) drives a ow that erases distinguishable structure. The system's topology and coupling constraints determine how that erasure propagates, yielding nite correlation length and channel-dependent transport rather than unbounded persistence. Principle 8.3 (Davis Manifold Principle) . Let (M, Φ) be a discrete or continuous dynamical system with: 1. A nonlinearity proxy κ:M→R≥0 measuring departure from linear behavior 2. A topological constraint τ (linking number, helicity, connectedness) that is approximately conserved 3. A dissipative mechanism D that couples to κ Then the system exhibits bounded structure evolution : there exists a horizon T∗ such that for t>T∗ , the structure intensity S(t)≈0 and no cascade to unbounded values occurs. Corollary 8.4 (Security/Regularity) . Systems satisfying the Davis Manifold Principle cannot exhibit blowup (singularities in PDE, successful attacks in cryptography) beyond the horizon T∗ . For SHA-256, the A-torus provides T∗ A= 8 rounds, the E-torus provides T∗ E= 12 rounds (variable), and the composite horizon is T∗≈20 rounds. The topological constraint is the Hopflink structure between subsystems; the dissipative mechanism is carry-induced diusion. The principle explains why full-round SHA-256 resists attack: by Round 20, all exploitable structure has thermalized. Acknowledgments The author thanks the anonymous collaborators who contributed to the experimental framework and theoretical renements. References [1] I. Nikoli¢ and A. Biryukov. Collisions for step-reduced SHA-256. In Fast Software Encryption (FSE) , LNCS 5086, pages 115. Springer, 2008. [2] S. K. Sanadhya and P. Sarkar. Attacking reduced round SHA-256. In Applied Cryptography and Network Security (ACNS) , LNCS 5037, pages 130143. Springer, 2008. [3] F. Mendel, T. Nad, and M. Schläer. Improving local collisions: New attacks on reduced SHA-256. In Advances in CryptologyEUROCRYPT 2013 , LNCS 7881, pages 262278. Springer, 2013. 17 [4] M. Lamberger and F. Mendel. Higher-order dierential attack on reduced SHA-256. Cryptology ePrint Archive, Report 2011/037, 2011. [5] D. Khovratovich and I. Nikoli¢. Rotational cryptanalysis of ARX. In Fast Software Encryption (FSE) , LNCS 6147, pages 333346. Springer, 2010. [6] B. R. Davis. Heat kernel cryptanalysis of SHA-256: Geometric structure and algebraic exploitation. Preprint, December 2025. [7] B. R. Davis. The eld equations of semantic coherence: A geometric theory of meaning, curvature, and reasoning in transformer architectures. Zenodo, 2025. https://doi.org/ 10.5281/zenodo.17771796 [8] National Institute of Standards and Technology. Secure Hash Standard (SHS) . FIPS PUB 180-4, August 2015. [9] A. Biryukov, M. Lamberger, F. Mendel, and I. Nikoli¢. Second-order dierential collisions for reduced SHA-256. In Advances in CryptologyASIACRYPT 2011 , LNCS 7073, pages 270287. Springer, 2011. [10] S. Indesteege, F. Mendel, B. Preneel, and C. Rechberger. Collisions and other non-random properties for step-reduced SHA-256. In Selected Areas in Cryptography (SAC) , LNCS 5381, pages 276293. Springer, 2009. [11] P. Robert and Y. Escouer. A unifying tool for linear multivariate statistical methods: The RV-coecient. Journal of the Royal Statistical Society: Series C (Applied Statistics) , 25(3):257265, 1976. [12] I. Dinur and A. Shamir. Cube attacks on tweakable black box polynomials. In Advances in CryptologyEUROCRYPT 2009 , LNCS 5479, pages 278299. Springer, 2009. A Notation Reference Symbol Denition (Z/232Z)8 State space (discrete torus) Ft,s,b Carry eld (round t , stage s , bit b ) QT,eig Temporal spectral coherence Qλ Spatial spectral concentration Q∧ Wedge sector coordinate ( QT,eig ·Qλ ) ξ Correlation length (rounds) RV(E, A) RV coecient (structural similarity) Maj,Ch SHA-256 Boolean functions Σ0,Σ1 SHA-256 rotation functions T1, T2 Intermediate values in round function Table 5: Notation reference B Experimental Parameters C SHA-256 Round Function Reference For completeness, the SHA-256 state update: 18 Parameter Value Messages per seed 2000 Seeds {42,123,999} Message size 64 bytes (single block) Sector window [0,12) rounds Readout window [16,28) rounds Sliding window size 8 rounds Sliding window step 2 rounds Tail fraction (HI/LO) 20% Matched samples per group 200 Permutation tests 200 Fingerprint dimension 39 Table 6: Experimental parameters T1=h+ Σ1(e) + Ch(e, f, g) + Kt+Wt (24) T2= Σ0(a) + Maj(a, b, c) (25) (a′, b′, c′, d′, e′, f′, g′, h′)=(T1+T2, a, b, c, d +T1, e, f, g) (26) Stage mapping to operations: 0. h+ Σ1(e) 1. ( stage 0 ) + Ch(e, f, g) 2. ( stage 1 ) + Kt 3. ( stage 2 ) + Wt⇒T1 4. Σ0(a) + Maj(a, b, c)⇒T2 5. d+T1⇒e′ 6. T1+T2⇒a′ 19