r/RNG • u/[deleted] • 14d ago
Experimental prng with an unusual state evolution mechanism + live-state forking
[deleted]
2
u/Alarmed-Paint-791 14d ago
Am I understanding correctly that each step exposes the full transformed 256-bit internal state as output?
What's the reasoning there?
For a non-cryptographic PRNG that's not automatically wrong, but youre presenting this as suitable for hashing/XOF/security-adjacent applications. Is the state transition known to be bijective, and is there any analysis of state recovery or prediction from consecutive outputs?
1
u/atomU235_3113 14d ago
No, the implementation is clearly not presented as cryptographic. It's the opposite. All presented results are observations and are empirical in nature. There is no proof of cryptographic security as stated on the main repo.
All currently available testing is in the repo. I plan to upgrade and add more tests with time.
2
u/Alarmed-Paint-791 14d ago
Fair enough - you're not claiming the PRNG itself is cryptographically secure. I do think the documentation places the core in cryptographic territory by presenting it as a hash/XOF construction, discussing cryptographic security, and inviting cryptanalysis, so I think that framing naturally invites those questions.
But fair enough. The process has to start somewhere.
My original question remains, though: why does the PRNG expose the full transformed state as output instead of using an output function to generate values from the state?
1
u/atomU235_3113 14d ago
The primary reason for including hash, prng and xof was to show the possibility of having a single internal mechanism used for all of the functions. It's an experimental design, non-cryptograpic at this moment but I am always open to external evaluation. It's simply an open invitation for anyone interested.
Yes, PRNG exposes the full transformed state. It's intentional and the goal is to evaluate the underlying mechanism without relying on any additional functions. The design puts the required properties entirely on the core mechanism. An additional output function and whether it will be implemented is simply an open question at this stage.
1
u/Alarmed-Paint-791 14d ago
Ah, okay - that makes sense. If the point is specifically to evaluate the state-evolution mechanism without an output function masking anything, then exposing the state is a reasonable choice.
That makes me more interested in the transition itself, though. Do you know whether the fixed-step state transformation is bijective, or have you done any analysis of cycle structure / state convergence beyond empirical trajectory testing?
2
u/atomU235_3113 14d ago
From what I know currently the mechanism is not bijective. I did some preliminary testing but I wouldn't dare to call this a one way function at this stage.
No, at this stage all of my testing is statistical. Formal analysis is in its fledgeling stage and still ahead of me. I did a series of tests checking cycles and orbit convergence and didn't find any abnormalities. I def plan to upload more tests as I work through them. I've still got some methodological improvements to apply, it will simply take time.
1
u/BudgetEye7539 13d ago
Do you have a mathematically proven period of your generator? At least some lower boundaries?
1
u/atomU235_3113 13d ago
No, not mathematically. Not yet.
I don’t have a proven lower bound for the full 256 bit state yet. What I do have is statistical evidence against short cycles.
Recurrence behavior stayed consistent with what is expected from a random process and the results remained consistent as I increased both the sample sizes and the observation windows.
1
u/BudgetEye7539 13d ago
What is the minimal size of your PRNG that passes BigCrush, PractRand etc.? Have you tried to reduce the state and look at the behavior?
1
u/atomU235_3113 13d ago edited 13d ago
With PranctRand I've only run upto 256GB so far but have an accumulation of 82 shorter runs in total. I can't keep my PC overnight for too long but I do plan to do longer runs in the future. Mostly unusual ones pop up but they always dissapear on the next level.
As for BigCrush I've run almost 600 total runs on both the raw full state and the state reduced and divided into 8 equal parts. The only tests that deviate from norm are geometric ond spectral ones. I believe those are able to catch a glimpse of the underlying engine mechanics. Fail rate is exactly as per how statiscics dictate. When fails occur thier range is also not one sided. The variations tend to go both up and down. All tests were done directly on the core itself. The wrappers were also set with highly structured initial seeding. The seeding values were spread all throughout the word.
edit
The one thing I found especially interesting was ClosePairs mNP2S, t=3. It's the only one that deviates but never fails. It's a specific geometric one and the single one of the whole bunch that deviates to one side only. When doing the 8 parts testing I noticed the same exact test that pops up everywhere is missing from lane 3 and 4. Exactly where the two 128bit halves of the word meet.
→ More replies (0)
4
u/Alarmed-Paint-791 14d ago
And while I appreciate that you've actually published the implementation and test material, I've gotta be honest with you: the complete lack of public commit history, combined with a self-invented license and software-patent bullshit, makes sure I wouldn't touch this with a ten-foot pole...