An idea for a "possibility hard" hash function

Words
462
Reading
3 min
Listen
Play
7y

A "hash function" where the pre-image is a "map" to traverse a "global reference number", the reference number is immutable and remains the same for anyone using the function, and is in the size of terabytes, roughly a trillion bit, and in the form of a hash chain of n-bit numbers (256-bit for example. )

Formal definition:

The message (m) is of minimum length n-bit, shorter messages are padded to n-bit. The message (m) maps to block height (x) in a reference number (l), x = m%l. This value (x), recursively, maps to bit d in the message, d = n + x%log2(m), where n is a nonce that is incremented every iteration of the function. The bit d is stored in memory, and the message is bit-shifted d>>1. The bit d is transformed with a XOR operation, d ⊕ (x+m)%2, and the value loaded onto the last bit of message, previously set to 0 by the bit-shift operation. The nonce n is incremented by 1, n += 1. The function is repeated log2(m) times.

To get outputs of fixed size, the output can be split into blocks of fixed size, and the blocks combined with XOR operation.

Tradeoff:

The "reference number", if you take the world economy, will have a state in the petabyte, blockchains are already in terabytes. To attempt to brute force this collusion-resistant and pre-image resistant hash function, an attacker has to 1) store that reference number or 2) continuously access it. They could be validating transactions instead, making a profit that way.

It would add a vulnerability as people would request state to generate their hashes (could do so anonymously, and encrypted), while making brute force harder, and, I could see the hash function being harder to break in other ways. For ordinary people like me and you it would be a few requests, but an attacker would have to make a quindecillion requests to the network storing the state, or store it themselves and those added costs could be better used just validating transactions instead and earning a profit that way.

How could an attacker possibly attack a system that they cannot even keep "in their head" or "see"? Seems impossible.

Economic argument:

The economic argument is, a global ledger is the largest possible shared resource, it has extreme requirements. Compare it with the requirements for digital signatures, they could never match it no matter how advanced they are. If you require an attacker to be able to match the combined economic resource of the network as a whole, and the network is one of the biggest public utilities ever created, I guess you severely limit their ability to attack the network?

You make the ledger the lock that they key has to fit in.