A headless, local-first autonomous research platform for SHA-256 cryptanalysis with native CPU execution, Vulkan compute acceleration, SAT/SMT solvers, local LLM/VLM runtimes, tool-restricted autonomous agent orchestration, independent verification, and tamper-evident evidence packages.
Important
No standard full SHA-256 collision demonstrated. Full SHA-256 remains computationally secure and unbroken. All candidate preimages, differential trails, or collision claims are strictly validated by an independent reference verifier prior to acceptance.
Epistemic Trust Model (L0-L5):
- L0: Model Suggestion (Hypothesis)
- L1: Unverified Observation (Visual/Empirical)
- L2: Experiment Output (Solver Raw Result)
- L3: Independently Verified (Arbitrated by IndependentVerifier)
- L4: Reproduced (Locally replicated with identical parameters)
- L5: Cross-Environment Reproduced (Independently validated across platforms)
Neither LLM, VLM, nor agent output is ever treated as cryptographic proof. Only the segregated IndependentVerifier arbitrates truth.
- Standard Full SHA-256 (64 rounds): UNBROKEN. No standard collision or full preimage has ever been discovered or claimed.
- Reduced-Round Demonstrations: Inversions verified on toy/reduced rounds (e.g. 8-round CaDiCaL, 10-round Kissat) for research validation only.
- Classification Non-Negotiables: Reduced-round experiments are never conflated with full SHA-256. Modified or custom-IV experiments are categorized strictly as
SemiFreeStartor rejected. Near-collisions are triage heuristics, not cryptographic breaks.
- Segregated Independent Reference Verifier Engine:
IndependentVerifierno longer shares implementation code withSha256Scalar, eliminating common-mode software failure.- Contains an isolated, self-contained FIPS 180-4 reference engine with independent state, independent round execution, independent padding logic, and independent constant tables.
- Explicit Anti-Clamping Policy:
- Replaced silent input clamping (
std::min(rounds, 64)) with strict, explicit validation in both CLI options and SAT encoders. - Any request with
rounds < 1orrounds > 64throws an explicit invalid argument exception.
- Replaced silent input clamping (
- Comprehensive Layered Test Suite (6 CTest Targets, 100% Pass Rate):
sha-tests(21 tests): Exhaustive primitives, padding boundary sweep (0..130 bytes, 55, 56, 64, 65, 119, 120, 128 bytes), streaming chunked hashing, backend equivalence, exact search partitioning, Tseitin SAT semantics, solver replay, and verifier differential cross-checks.sha-adversarial-tests(8 tests): 1-bit tampering detection, identical input spoofing rejection, artifact hash tampering, custom-IV misclassification prevention, reduced-round conflation rejection, zero-round rejection, over-claimed rounds rejection, and forged metadata override rejection.test-million-a: NIST CAVP long message test (1,000,000'a'characters) verifying both scalar, optimized, and independent verifier backends againstcdc76e5c9914fb9281a1c7e284d73e67f1809a48a497200e046d39ccc7112cd0.test-determinism: Dedicated determinism test verifying bit-for-bit output invariance across repeated runs (runs A, B, C) across all engines, parallel batch hashing, SAT encodings, and differential trails.verifier-kat: NIST Known-Answer Test suite executed via standalonesha-verifier.exe.verifier-negative: Negative guardrail and hostile rejection test suite.
- Hardened Shaders & Pipelines:
- Corrected 32-bit shift in SPIR-V
search.compwhen target zero bits is 0. - Recompiled SPIR-V shaders embedded for Vulkan GPU acceleration.
- Corrected 32-bit shift in SPIR-V
- CI Automation & Deterministic Failure Propagation:
- Hardened all GitHub Actions PowerShell workflows with
$LASTEXITCODEchecks to guarantee failure propagation.
- Hardened all GitHub Actions PowerShell workflows with
| Target Name | Test Count | Description | Status |
|---|---|---|---|
sha-tests |
21 Unit Tests | Primitives, padding sweep, differential, Tseitin SAT, solver replay | PASS |
sha-adversarial-tests |
8 Adversarial Tests | Hostile tamper detection, fake claims, metadata forgery guardrails | PASS |
test-million-a |
1 NIST KAT | NIST 1,000,000 'a' character vector verification |
PASS |
test-determinism |
8 Invariance Tests | Multi-run (A/B/C) determinism for CPU, threads, SAT, verifier | PASS |
verifier-kat |
4 Vectors | Standalone independent FIPS 180-4 reference engine KATs | PASS |
verifier-negative |
3 Hostile Vectors | Negative rejection gates for |
PASS |
verify_evidence.py |
Full Evidence DB | SHA-256 hash manifest verification across all experiment artifacts | PASS |
-
FIPS 180-4 Standard Compliance: Exact reference scalar implementation cross-checked against NIST CAVP test vectors (
sha-verifier test-vectors,sha_tests). - Multicore CPU Backend: Portable unrolled compression path plus scalar reference fallback, validated for identical digests across padding-boundary lengths. Example measured throughput: ~27.18M hashes/sec across 16 threads on AMD Ryzen 7 7735HS.
-
Vulkan GPU Compute Acceleration (optional): SPIR-V compute shaders for batched compression, independently verified against CPU state when a compute device is present. CPU-only builds (
-DSHA256_ENABLE_VULKAN=OFF) work without any Vulkan SDK. - Pluggable SAT/SMT Cryptanalysis (optional, environment-dependent): Tseitin SAT encoding for reduced-round SHA-256 with native-vs-model differential oracle tests. External solvers (CaDiCaL, Kissat, CryptoMiniSat, MiniSat, Z3) are used only when installed; solver claims are always re-verified by the independent verifier.
-
Non-Negotiable Independent Verifier: Cryptographic results are strictly verified by an independent component before entering evidence storage. Enforces distinct inputs (
$M_1 \neq M_2$ ) and exact FIPS padding. -
Immutable Evidence Storage & SQLite DB: Every experiment receives an immutable ID, SHA-256 hashed artifact manifest, and entry in
evidence/knowledge_base.sqlite. Manifests record git commit, environment, solver version, command, seed, timing, and verification status; "executed" and "independently verified" are distinct states. -
ML-Guided Search (research prototype): PyTorch neural ranking prototype trained on synthetic trail features with a reported heuristic baseline (see
ml/models/metrics.json).
pwsh -File scripts/doctor.ps1
pwsh -File scripts/bootstrap.ps1pwsh -File scripts/build.ps1 -Configuration Releasectest --test-dir build -C Release --output-on-failure
# Or run using the test runner script:
pwsh -File scripts/test.ps1 -Configuration Releasepwsh -File scripts/benchmark.ps1pwsh -File scripts/research.ps1 -Rounds 10 -Solver kissat.\build\Release\sha-research.exe statusUsage: sha-research <command> [options]
Core Commands:
doctor Probe environment, hardware, and toolchains
bootstrap Verify/setup dependencies and solvers
build Configure and build framework binaries
test Execute test suite (unit, KAT, differential, verifier)
benchmark Run CPU, Vulkan, and SAT benchmark suite
verify Verify known answer vectors and negative tests
status Display framework status, devices, and solvers
Research & Experimentation:
hypothesis list List active and evaluated research hypotheses
experiment run [r] [s] Execute cryptanalysis experiment with [r] rounds and solver [s]
campaign start Start autonomous research campaign
analyze Analyze solver statistics and differential characteristics
train Train ML search guidance models
report Generate comprehensive markdown reports
├── CMakeLists.txt # Modern CMake build configuration (v2.0.0)
├── CMakePresets.json # Native Windows MSVC & Ninja presets
├── include/sha256_research/ # C++ Public Headers
│ ├── core/ # Word rotations, bitwise functions, FIPS constants
│ ├── sha256/ # Scalar reference implementation with round tracing
│ ├── cpu/ # Portable unrolled batching + CPUID info (no intrinsics)
│ ├── vulkan/ # Vulkan context, SPIR-V pipeline, GPU compute
│ ├── differential/ # Differential trails and bit condition modeling
│ ├── sat/ # Full Tseitin SAT CNF encoder
│ ├── solver/ # Pluggable solver abstraction (CaDiCaL, Kissat, CMS, Z3)
│ ├── verifier/ # Independent verifier and integrity gate
│ ├── storage/ # Immutable runs, artifact SHA-256 manifests
│ └── benchmark/ # Benchmark suite
├── shaders/ # GLSL compute shaders & compiled SPIR-V
│ ├── sha256.comp / .spv # Batched 64-round SHA-256 compute shader
│ ├── differential.comp / .spv# Differential pair evaluation shader
│ └── search.comp / .spv # Nonce and target condition search shader
├── src/ # C++ Implementation sources
│ └── verifier/ # Segregated FIPS 180-4 reference engine
├── tests/ # Automated test suite (KATs, Equivalence, Million 'a')
│ └── adversarial/ # Tamper detection, anti-spoofing, hostile tests
├── verifier/standalone/ # Standalone verifier CLI
├── scripts/ # Automation scripts (doctor, bootstrap, build, test, etc.)
├── tools/ # Python utilities (train.py, analyze.py, report.py, init_db.py)
├── evidence/ # Immutable logs, manifests, and SQLite knowledge base
├── reports/ # Machine-generated build, test, and benchmark reports
└── docs/ # Complete engineering and cryptanalysis documentation
This framework strictly upholds cryptographic integrity:
- The agent is never an authority for cryptographic validity; an independent verifier arbitrates all claims.
- Reduced-round results, semi-free-start collisions, or differential trails are never misrepresented as standard full SHA-256 collisions.
- Failed experiments are preserved as first-class scientific evidence.
- Input constraints are strictly validated and never silently clamped.