Featured Developer Sponsor • Zero-Token Protection
Homomorphic Time-Lock Puzzles & Verifiable Delay Studio
Architect non-interactive cryptographic time capsules with Rivest-Shamir-Wagner (RSW96) sequential squaring.
Simulate trapdoor key generation via Euler's totient φ(N), test in-browser sequential squarings,
and evaluate parallel-resistant unsealing horizons.
RSW96 Construction
Sequential Squaring
Euler Totient Trapdoor
ASIC/GPU Resistant
Sequential computational work T required to unlock
Hidden-order composite group size
Sequential execution hardware speed
Confidential plaintext to lock until time elapsed
Trapdoor Asymmetry Analysis
ASYMMETRY: 1,000,000x SPEEDUP
Creator Time
0.04 ms
via e = 2^T mod φ(N) [O(log T)]
Solver Time
1.02 s
Strictly serial O(T) squaring steps
Parallel Advantage
0.0x (None)
1 core = 1,000,000 GPU cores
Squaring Rate
980,000 / s
Based on 3.6 GHz ALU cycle model
Creator Trapdoor: e ≡ 2T (mod φ(N)) → K = ge mod N
Solver Path: x0 = g, xi+1 = xi2 mod N → xT = K
Payload Ciphertext: CM = M ⊕ H(K)
In-Browser Squaring Solver Execution
Progress: 0.0%
Steps: 0 / 1,000,000
Elapsed: 0.00s
[SYS] Time-Lock Puzzle Generator Ready.
[SYS] Modulus N generated (1024-bit composite).
[SYS] Plaintext payload sealed. Ready for sequential solver benchmark.
Production RSW96 & Wesolowski VDF Implementation
Python 3.11+ / GMP
The Mathematics of RSW96 Time Capsules
Time-lock puzzles bridge number theory with computational physics:
- Hidden Order Groups: When factoring $N = p cdot q$ is intractable, the group order $phi(N)$ is unknown to all parties except the puzzle creator.
- The Trapdoor Shortcut: Knowing $phi(N)$ allows reducing the exponent $2^T$ modulo $phi(N)$. Since $2^T pmod{phi(N)}$ takes $O(log T)$ bit operations via double-and-add, a creator can prepare a 10-year puzzle in under 5 milliseconds.
- Irreducible Sequentiality: Without $phi(N)$, finding $g^{2^T} pmod N$ requires computing each intermediate square $x_{i+1} = x_i^2 pmod N$. Every squaring requires the full 1024-bit or 2048-bit result of the previous operation, making parallel distribution mathematically impossible.
VDF Integration: Wesolowski & Pietrzak Proofs
In decentralized networks (e.g. Ethereum beacon chain randomness, sealed-bid auctions), observers must verify the puzzle solution without repeating the delay:
- Wesolowski Proofs: The solver computes a single group element $pi = g^{lfloor 2^T / ell floor} pmod N$, where $ell$ is a Fiat-Shamir prime challenge $ell = H(g, y, T)$.
- Logarithmic Verification: Any node verifies the equation $pi^ell cdot g^{(2^T mod ell)} equiv y pmod N$ with only a few modular exponentiations ($< 2$ milliseconds).
- Homomorphic Time-Locks (HTLP): Puzzles can be combined homomorphically ($C_1 cdot C_2 pmod N$) such that solving the composite puzzle unlocks the sum of the secret plaintexts without revealing intermediate inputs.
Sponsored Utility
While You're Here
Sponsored Recommendations
Advertisement