Welcome to the FLT and the dFLT

A Computational Transformation in Cryptography
Peter Lablans

Summary

The Finite Lab-Transform (FLT) is a computational transformation explained as a number theoretical transformation applied to cryptographic computer operations. The FLT transforms the instantiation of a 2-operand computational function while preserving its meta-properties. It modifies the output of cryptographic primitives, such as encryption, hashing and key exchange, while preserving proven security properties. The FLT operates on n-state elements and has a solution space in the order of factorial of n. For n=256 it provides a solution space greater than 10400. Simple (7-state) examples of the FLT are provided. Dynamic FLT (dFLT) is explained. Certain applications of the FLT are protected by US Patents.

A Number Theoretical Model

The FLT as explained herein is a technical invention to design and implement novel computer circuits/operations that may be used in cryptographic machines. One may consider the FLT also a Number Theoretical discovery. It is fairly unusual to discover a fundamental property like the FLT at this stage of Number Theoretical developments. Number Theory goes back for centuries. It is surprising for the FLT to show up now. To be fair, an FLT has no real meaning outside computer implementation and was pretty much useless pre-computers. The FLT was developed by Lablans as a technical solution to modify computer operations, not as a mathematical discovery.

What is the FLT?

The FLT is a transformation of an instantiation of a computer function, such as a modulo-n addition or modulo-n multiplication, modelled as a (2-operand) look-up table. The FLT transforms the function and it effective operation so that the output of the transformed operation is different from the original one. However, the meta-properties of the FLTed operation are identical to the meta-properties of the original operation.

Meta-properties of an operation are those that define for instance finite rings and finite fields in Number Theory or Abstract Algebra. Those properties also apply to computer operations, as they may and commonly are modelled by Algebra. These computational operations are finite by necessity.

A Computational Implementation Does Not Perform Mathematics

Computer machines can be described, according to Dr. Gerrit "Gerry" Blaauw, at three levels:
1) Architecture;
2) Implementation; and
3) Realization.

A famous example is a binary carry ripple adder, described in Boolean logic expressions by Claude Shannon in his MIT Thesis in 1938. While it seems the machine performed arithmetic, it actually performed state switching of electro-mechanical relays.

Thus, what some people call a computer machine performing mathematics or logic, is in fact physical switching. The logic or math is merely a convenient model of what a machine appears to do.

Modulo-n Operations in FLT

For instance an operation may be commutative, so that a+b=b+a. Assume an FLT transforms the modulo-n + operation into an ⊕ operation. The ⊕ operation will also be commutative. Another property as expressed in (a+b)+c=(c+a)+b is that the + operation is associative. The ⊕ operation is also associative: (a⊕ b)⊕c=(c⊕a)⊕b.

Another property is the existence of a neutral element e, so that a+e=a and an inverse a-1 exists so that a+a-1=e, for every element a. We know e to be e=0. Under an FLT of + the ⊕ operation also has a neutral element with the properties a⊕a-1=p for every element a. However, the value of p after an FLT may be not 0.

Similarly a modulo-n multiplication has a zero element z, so that a*z=z for all values of a. In general z=0. Furthermore a neutral element k exists for which a*a-1=k. In general k=1. The inverse a-1 is called the multiplicative inverse of a. The FLT transforms operation * into operator symbol. Operation operator symbol also has a zero-element, which may be element y, so that aoperator symboly=y for all a, but y may not be 0. Furthermore, an element q exists so that aoperator symbola-1=q, but q may not be 1.

The meta-properties stay unchanged in an FLT. The instantaneous values of certain properties may change in the FLT.

n-state invertible inverters

An inverter is a device (or an expression) with an input and an output that modifies the input to an output (or an input state to an output state.) An invertible inverter reverses the modification of the reversible inverter. A common and well known inverter is the binary inverter. The known binary inverter inverts an input state to its reverse state. State 0 is inverted to state 1 and state 1 is inverted to state 0. This binary inverter can be represented as [0 1]→[1 0]. The representation has as benefit that its position (for instance position 0) also represents a state of an input or output. This notation says that state 0 is inverted to 1 and state 1 is inverted to state 0. The binary inverter [0 1] → [0 1] is identity as no modification takes place.

An n-state invertible inverter is described by a sequence of n different n-state elements. The herein provided notation is:
[input sequence] → [output sequence].

For convenience the n states are defined as ranging from state 0 to state (n-1) and all states in between. A 7-state inverter, for instance, has states 0, 1, 2, 3, 4, 5 and 6. For convenience each state of an n-state inverter is provided with an index to indicates its position in the sequence. The identity 7-state inverter is [0 1 2 3 4 5 6] → [0 1 2 3 4 5 6]. Another reversible 7-state inverter is [0 1 2 3 4 5 6] → [1 2 3 4 5 6 0]. This says that input state 0 is modified to state 1; state 1 is modified to state 2, etc. and state 6 is modified to state 0. For reversible n-state inverters each possible state occurs exactly once in the output sequence. The input sequence is always [0 1 2 … (n-1)] and may be dropped. So instead of using [0 1 2 3 4 5 6] → [1 2 3 4 5 6 0], the notation 7-state inverter [1 2 3 4 5 6 0] may be used.

What is a state?

A "state" is an instantiation in an expression, which may represent a physical property or condition. It may be represented as a variable that can have one or 2 or more states. The variable may be symbolic, as in mathematics. The variable may also be a physical property. Such as the "state" of an output of a circuit, or the "state" of a device. Assigning symbolic states such as numbers 0, 1, 2, …, (n-1) is merely for convenience, as physical states do not come in convenient numbers. Many people believe that computers process digits 0 and 1. Physically that is not the case. Computers commonly operate on signals with states LOW and HIGH, of which the values, or range of values, are explained in detailed data-sheets related to computer components.

States are generally represented as discrete values in expressions, while in practice the physical states may cover a range of values, such a voltages. Thus, a state machine may be a device that can be placed in one of 2 or more states. Its operation may be described in an abstract model. In real life, measuring the voltage related to a state with a Volt meter may provide a whole range of conditions.

Reversing n-state inverter

Each invertible n-state inverter invn has a reversing inverter rinvn. The meaning of such a reversing n-state inverter is that applying the reversing inverter rinv after applying invn creates the original starting state. For instance invn(k)=p provides rinvn(p)=k. Or rinvn(invn(i))=i. The above 7-state inverter inv7=[1 2 3 4 5 6 0] has as reversing inverter rinv7=[6 0 1 2 3 4 5].

How many reversible n-state inverters?

There are factorial n or n! reversible n-state inverters, including identity. That means that there are 3! or 1*2*3=6 different 3-state inverters. The number of permutations increases rapidly with n. There are 120 reversible 5-state inverters and over 40,000 reversible 8-state inverters.

How to perform the FLT

The FLT is applied to a dyadic (or 2-operand) operation (such as a modulo-n multiplication) in the following way. Represent the modulo-n operation by symbol operator symbol, which may be a multiplication, an addition, a subtraction or any other dyadic operation. The input operands are a and b and the output is y. The operation operator symbol performs aoperator symbolb=y.

A reversible n-state inverter invn is obtained and its corresponding reversing inverter rinvn is determined.

The FLTed operation is: y=rinvn(invn(a) operator symbolinvn(b)).

The FLTed operation may be represented as: aoperator symbolb=y

The operation operator symbol has all the meta-properties of operator symbol, though ordering of elements as well as zero-element and neutral element may have been modified.

The FLT operation is applied in computer operations and may be represented in the form as shown below.

FLT operation diagram

A Numerical Example

To illustrate the FLT a 7-state example using addition and multiplication modulo-7 will be shown below. One should keep in mind that a symbolic representation like (a+b) mod-7 in terms of a computer operation is identical to a representation by a switching or truth table in computer use.

The applied 7-state inverter is inv7=[2 3 4 0 5 1 6] with reversing inverter rinv7=[3 5 0 1 2 4 6].

The following figure shows the FLT of a modulo-7 addition based on inverter inv7

Modulo-7 addition FLT table

The neutral element (or zero-element) of the modulo-7 addition is 0: (a+0)=a mod-7. The additive inverse a-1 of a is determined so that
a-1+a=0. One can read from the original addition mod-7 table that the additive inverse of 1 is 6; of 2 is 5; of 3 is 4; etc. The FLT as illustrated above leaves the FLTed operation with the same meta-properties as the original operation. Name the FLTed operation operator symbol. The additive zero-element is z, so that aoperator symbolz=a now is 3, as aoperator symbol3=a for all a. This also modifies the additive inverses of operator symbol. The additive inverse of 0 under operator symbol is 4; of 1 is 2; of 3 is 3; of 4 is 0; etc. One can see that operator symbol is commutative, closed and has a zero-element and thus inverses. It is not directly clear that operator symbol is associative. This can easily be checked exhaustively with a computer program. An example (4operator symbol5)operator symbol3=4operator symbol(5operator symbol3) and (3operator symbol4) operator symbol5 are all 6, as one can see from the operator symbol table.

The following figure illustrates the FLT of the modulo-7 multiplication based on inv7

Modulo-7 multiplication FLT table

The zero-element of the multiplication mod-7 is of course 0 (a*0=0 mod-7). The zero-element z of the FLTed operation is 3. Name the FLTed multiplication mod-7 again operator symbol. Then aoperator symbol3=3 for all a as can be seen in the FLTed table. Furthermore, the neutral element e is so that aoperator symbole=a is e=5. This means that the multiplicative inverse of element a under operator symbol has to be determined against:
aoperator symbola-1=5.

Thus the multiplicative inverse of a=0 under operator symbol is 2; of 1 is 4; of 2 is 0; etc. All meta-properties of * mod-7 apply to operator symbol. application of certain dedicated algorithms such as the Extended Euclidean Algorithm (EEA). By applying the correct values of the neutral element one can apply the EEA to determine the correct multiplicative elements of a under operator symbol. For small numbers of n as in modulo-n the multiplicative inverses may be determined from FLTed tables. This becomes impractical for n being very large and the FLTed EEA becomes more convenient.

The above 7-state FLT of a circuit modified in accordance with a 7-state inverter is illustrated in this video of a Matlab realization of the FLT.

Video: Matlab realization of the FLT

Other functions that can be FLTed

As an example, operations modulo-n have been used to illustrate the FLT. This includes modulo-n with n being prime. A Finite Field is created when using addition and multiplication modulo-n with n prime. Other functions can also be FLTed. For instance operations over an extension finite field GF(n=qp) with q being prime can also be FLTed. This is explained for instance in US Patent 10,515,56. The FLT preserves also other properties such as "involution" or self-reversibility.

Also composite operations may be FLTed. For instance, a radix-n addition is a combination of a modulo-n addition or the residue operation and the determination of a transitional element, usually called a carry. One may apply the FLT to both operations. The reversing operation of a radix-n addition is a radix-n subtraction. The reversing operation of an FLTed radix-n addition is an FLTed radix-n subtraction. In that case one FLTs the modulo-n subtraction as well as the function that generates the related modulo-n borrow element.

What the FLT is NOT

The FLT is not a simple random bijection or straight-forward substitution. That is: not every state in the original table is transformed (as a bijection) into a same other state. For instance, state 4 in the 7-state multiplication table is FLTed into state 5, 0, etc. depending on inputs. You can check this in the above example 7-state tables.

Where and Why to Apply the FLT?

The FLT can be applied in computer implemented methods, in error-correction, cryptography and random sequence generators, for instance. One important area of application is in cryptography such as encryption, PKI, authentication and digital signatures. The FLT, with its enormous amount of variation for even relative small values of n, make current cryptographic methods more secure with minimal change. It also allows for lightweight cryptography with small size parameters. See again US Patent 10,515,567.

The underlying idea is to apply proven and hard to attack cryptographic methods, and modify with the FLT one or more of the primitive computer switching functions. This approach is loosely based on the design methods as applied and taught by Dr. Gerrit "Gerry" Blaauw, with Amdahl and Brooks, co-architect of the legendary and impactful IBM System/360.

Blaauw/Brooks distinguish 3 levels of computer design: 1) the architecture (what a user sees); 2) the implementation (the logic design); and 3) the physical realization.

In a loose sense, this approach is followed in creating FLTed cryptographic applications. The data-flow or basic architecture of a cryptographic method such as AES, RSA, DH, SHA-2 and ECC is maintained. However, the logic implementation is modified by FLTing certain switching functions. This renders the methods to be more unpredictable and thus more secure, without modifying the basic structure of a method.

In cryptography one may try increasing security by modifying (and usually increasing) parameters and parameter sizes or by adding random data (nonce). The FLT is a way to modify functions (that were considered to be immutable) without a need to increase size of cryptographic parameters, which can now even made smaller.

How does the FLT work in encryption?

Let’s take the Advanced Encryption Standard (AES) as defined in FIPS-197. AES defines several operational blocks:
- Key Expansion
- SubBytes()
- ShiftRows()
- MixColumns()
- AddRoundKey()

AddRoundKey() is a XORing of the State Array with Round Key Array. These arrays are matrices of 4 by 4 bytes. A byte may be considered a 256-state element. In that context the AddRoundKey() block provides an addition over Finite Field GF(256) of 256-state elements of a 4 by 4 matrix. The FLT modifies the addition over GF(256) in accordance with a reversible 256-state inverter.

There are 256! (factorial of 256) different reversible 256-state inverters. Some of these inverters create the same FLT of the base addition over GF(256). But ultimately, there are at least 10^480 different instantiations of this addition.

Transforming a 256-state function in AddRoundKey() is just one modification without changing the data flow or architecture of AES. One may implement such modification in one round, in some rounds, or in all 14 rounds of AES. One may use a same transformation for rounds and for all blocks in a single file or message. But one may change the FLT also per round, per block, per file, per sign-in, per time period, per location, per packet, per user or for any criterion one wants.

While. as example, AddRoundKey() has been provided, one may apply the FLT also to the more complex MixColumns() which is a combined addition/multiplication over GF(256) being a vector-matrix multiplication. One may apply the FLT also in KeyExpansion and in SubBytes().

In an additional step, one may also FLT modify in AES-GCM, which is the preferred mode of AES, the final step and XORing of the output of AES (which is then the keyword) with the cleartext to generate the ciphertext. One way of doing this is by providing sender and receiver, CIPHER() and INVCIPHER(), with the same set of secret 256-state inverters, like a set of 1 GB worth of 256-state inverters.

The above system may also be applied to ChaCha20, and to systems like hashing such as SHA-256 and to PKI like Diffie-Hellman, RSA and ECC.

The dynamic FLT or dFLT

In many cases communicating parties don’t know each other, and it would be a challenge to exchange securely one or more reversible n-state inverters between parties.

A novel invention, disclosed in U.S. Patent US 12,476,789, addresses the issue of secure exchange of 256-state inverters and dynamic self-propagation. This related to use of secure PKI (Public Key Exchange), for instance using Kyber, to establish a shared PQC secure 256-bit key.

A 256-bit sequence represents a set of 32 bytes, which is not a 256-state reversible inverter, which is a set of 256 bytes. The sequence of 32 bytes is then expanded to a set of 256 bytes. The newly formed 256 bytes set almost certainly will have duplicate bytes.

For that reason, the expanded 256 byte set is also not a 256-state reversible inverter. A novel. shared, computer procedure is applied to deterministically change the 256 byte set with duplicates in a set of 256 bytes without duplicates.

Thus, a unique, shared and secure 256-state reversible inverter has been formed.

Inverter Self-Propagation

In certain cases, it is desirable to use a set of different reversible inverters as discussed above.
It may be undesirable to start a PKI procedure for every new reversible inverter. For that purpose, the self-propagating property of reversible inverters is applied.

For instance, one may name an initial reversible inverter invnbase. And initialize invnew=invnbase. And in Matlab perform: invnew=invnew(invnbase), for instance.

This creates, iteratively, a new inverter, for each iteration. It circumvents the need for creating a new PKI key for each new inverter.

Proof-of-Concept Programs

The aspects of the FLT have been programmed in C, Python and Matlab. These evaluation programs are available for educational, trial and testing and evaluation efforts, only.

They are not to be used for operational cryptographic application. The Intellectual Property is protected by US Patents. Licenses for cryptographic use may be obtained by contacting info@labcyfer.com.

The programs can be downloaded from lcip.in.

Why Use the dFLT? Functional Polymorphism!

The sudden rise of autonomous, AI-driven agent swarms alters the calculus of secure encryption. The core threat vector has changed, and it places polymorphic cryptography and specifically FLT as a foundational breakthrough rather than a mathematical curiosity.

Why AI Agent Swarms Transform FLT's Value

Standard machine cryptography relies heavily on predictable, fixed computer functions (like standard finite field bitwise XOR operations). When human adversaries were the main threat, keeping the algorithm public and the key secret was a perfectly viable paradigm (Kerckhoffs's principle).

However, an AI agent swarm attack changes the paradigm:
1. The Machine-Speed Brute Force Problem: AI agent swarms can coordinate massively parallelized, real-time fuzzing and mathematical analysis of cryptographic targets. Because standard primitives use fixed operational logic, the AI’s objective function is mathematically stable. It knows exactly what an "addition" or "multiplication" looks like in the machine code.

2. The Polymorphic Threat Matrix: AI is already being used to create self-rewriting, metamorphic malware that changes its signature and execution path dynamically to evade detection. To defend against a fluid, polymorphic adversary, the underlying defense architecture cannot remain static.

The FLT Edge: Dynamic "Meta-Property" Preservation
This is exactly why polymorphic cryptography—and specifically the dFLT framework—shifts from "niche" to "essential". Polymorphic transformations, such as the dFLT, introduce an entirely new layer of cryptographic defense: functional polymorphism.

• Instead of just hiding a key, it secretly customizes the underlying cryptographic primitives themselves.
• An AI swarm attacking an FL T-modified system faces an explosion of search space of different functional modifications—exceeding 10400 variants for n=256.
• Because the actual execution behavior of the computer operations becomes unpredictable to an outsider, it actively breaks the mathematical assumptions an attacking AI model uses to find vulnerabilities.

The Finite Lab-Transform (FLT) offers a way to customize the primitive computer switching functions (such as the traditional bitwise XOR or modular additions used in AES-GCM or ChaCha20). It provides exactly the type of "functional polymorphism" and session-level agility needed to disrupt automated, machine-speed attacks, such as by AI agent swarms.

Autonomous AI agent swarm campaigns may and likely will target critical infrastructure and defense systems via machine-speed lateral movement. Static defenses are failing here. Security teams shold be actively looking for ways to implement polymorphic encryption (dynamic, changing execution paths). The dFLT fits in that search.

An article on cybersecurity attacks by AI agents can be found here.

The Inventor

Peter Lablans is the inventor of the FLT. He has a Master's degree in EE. Lablans is a prolific independent researcher and inventor and is the named inventor on over 50 patents.

Publications

A series of publications describe the FLT and/or other computational transformations. A list of these publications is available on this webpage.

The Patents

US Patents related to the FLT include: US 10,650,373; US 10,515,567; US 10,375,252; and US 8,577,026. It is your own responsibility to check if an application of the FLT infringes these or other patents. Additional patent cases are pending.

Does that mean that you cannot apply or test the FLT? That is not the case. You have permission to apply the FLT for testing and educational purposes only and on a single machine only. You have no permission to apply one of our patent protected inventions for commercial and/or operational purposes. That is: no permission is granted to apply the patented inventions in and/or for exchange of data between two or more machines and/or to encrypt/decrypt data for storage on a single machine.

Contact us:

Please visit labcyfer.com for more information. Or contact us at info@labcyfer.com.