Research · Papers · The SHA-256 record and exact synthesis · ML-069

Exact additivity of two-copy block sharing in leader pairs

Consecutive-round Ch and Maj pairs and schedule adder pairs are exactly additive at width 32; block sharing across real pairs yields 0 savings.

ML-069PROVED DEADRECEIPTEDNEGATIVE RESULTThe SHA-256 record and exact synthesis

Published 2026-09-04

For everyone

Plain summary

Hardware designers building hash functions like SHA often try to save gates by sharing logic across consecutive operations. This entry tests whether adjacent operations in SHA leader rounds—the choice function Ch, the majority function Maj, and two-operand addition blocks in the message schedule—can share nonlinear logic to cut circuit cost.

The route is closed. At 32-bit word width, the operations are strictly additive: evaluating two consecutive blocks costs exactly as much as evaluating each one on its own. While sharing logic can save gates on paper when two adders process identical inputs, no two actual leader steps ever share an input bundle. Block sharing across consecutive pairs yields zero savings.

Result

Under the GF(2) XOR-and-inverter graph (XAG) multiplicative cost model, consecutive-round Ch and Maj pairs and real affine-overlap pairs of schedule two-operand adders are strictly additive at width 32. Their nonlinear output quotient ranks equal the sum of their independent ranks. Multiplicative block sharing across real leader pairs yields 0 savings.

Setting and definitions

  • Multiplicative complexity metric: GF(2) XAG (AND-gate count; XOR and inverter gates are free).
  • Target components: 32-bit Ch pairs, 32-bit Maj pairs, and two-operand schedule adder pairs across consecutive rounds of SHA-family leader instances.
  • Operand bundles: Input word tuples fed into T1 calculation instances.

Method

Nonlinear output quotient ranks were computed for consecutive-round Ch pairs, Maj pairs, and affine-overlap schedule adder pairs, then compared against independent baseline constructions. Results and rank checks are logged in RECORD-BLOCKSHARE.md. The register records no further search parameters.

Discussion

Theoretical savings do exist when two constant adders process identical four-operand words: joint synthesis costs 2 AND gates instead of 4 at width two, and 5 instead of 10 at width three. Real leader rounds never instantiate this structure because no two T1 instances share an operand bundle. Because real pairs receive distinct or mismatched operand bundles, their nonlinear quotient ranks match the independent bounds, leaving no room for block-sharing gains.

For everyone — the takeaway

What this means

Hardware designers and circuit optimizers cannot cut AND-gate counts by sharing logic across consecutive rounds or adders in the leader. Because the actual steps never reuse operand bundles, synthesizing each block independently is already optimal.

Register references

  • ML-069
  • RECORD-BLOCKSHARE.md

Every artifact named above is bundled in, or hashed by, this paper's evidence pack below.

Evidence pack

Everything needed to check this entry against its receipts: the register text, a manifest with a SHA-256 hash for every named receipt, and 0 of 1 receipt files bundled (1 KB). Anything not bundled is still hashed in the manifest and lives in the compute-box working trees.

Download evidence.zip

Changelog

Last reviewed 2026-09-04

  • 2026-09-04Published on this site.

Related in this programme