proof-aware-crypto-tooling-.../paper
mrwulf ec9f085615 paper v0.5: B6 executed — accountability games + explicit composition theorem (IACR track)
New \S5.4 'Scheme-level games and a composition theorem' (operator
order: third attempt targets an IACR venue):
- Game PB (position binding): two accepting openings of different
  leaves at one (m,n,r) -> explicit B_pb outputs a SHA-256 collision
  in <= 2(ceil(log2 n)+1) hash evaluations (two-transcript top-down
  comparison; 32-byte widths make argument pairs recoverable).
- Lemma (prefix transport): an accepted ConsRec transcript plus an
  accepting opening at m<n0 under the NEW head yields a collision or
  an assembled accepting opening under the OLD head (frontier
  comparison + old-root spine assembly; degenerate power-of-two case
  handled).
- Game HIST (local history binding): pin-rule chains + contradictory
  openings at any two accepted heads -> collision, by transport
  induction + PB. Supplies the multi-step closure at paper level.
- Game FORK: evidence completeness by construction; frame resistance
  reduces to EUF-CMA. Win condition deliberately over canonical
  PAYLOADS, not heads — a second signature on an already-signed
  payload is not an EUF-CMA forgery (SUF/EUF trap caught in the
  self-audit pass before integration).
- Policy separation as a deterministic lemma (per GPT B6's own
  suggestion), formal Definition 3, and Theorem 7: the construction
  is an accountable replay-distribution scheme.
- Fixed-function SHA-256 handled per Rogaway's human-ignorance
  treatment (new citation, arXiv-API/DBLP/Springer-verified: VIETCRYPT,
  LNCS 4341, pp. 211-228, 2006 — note Rogaway's own page carries a
  221- typo): every hash statement is an explicit reduction, the
  scheme-level continuation of the named-extractor discipline.
- Games are non-interactive BECAUSE the operator-adversary holds the
  signing key (no secrets, no oracles) — stated in the section,
  mirroring the deployment's non-interactive verification.
- Honesty anchored: scope remark + new coverage-table row (two-
  transcript comparisons and prefix transport are paper-level, not
  mechanized); Definition 2 re-badged informal with pointer; DGHS
  two-transcript lineage credited in related work.
19 pages, 0 overfull, suite 115 green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 13:31:51 +02:00
..
.gitignore The LTL paper: 4-page arXiv draft, claim-disciplined 2026-07-06 18:14:38 +02:00
ltl-v0.1.pdf paper v2 canonical + versioned hosting; pin-store proposition now true 2026-07-09 18:02:59 +02:00
ltl-v0.1.tex paper v2 canonical + versioned hosting; pin-store proposition now true 2026-07-09 18:02:59 +02:00
ltl-v0.2.pdf paper v0.3: the reinvention — accountable distribution of machine-checked evidence 2026-07-17 09:39:04 +02:00
ltl-v0.2.tex paper v0.3: the reinvention — accountable distribution of machine-checked evidence 2026-07-17 09:39:04 +02:00
ltl.pdf paper v0.5: B6 executed — accountability games + explicit composition theorem (IACR track) 2026-07-17 13:31:51 +02:00
ltl.tex paper v0.5: B6 executed — accountability games + explicit composition theorem (IACR track) 2026-07-17 13:31:51 +02:00
reinvention-outline.md paper: reinvention outline (post second ePrint rejection) 2026-07-16 19:09:29 +02:00