CPU timing
- Samples
- 16,384
- Unique values
- 78
- Longest identical run
- 10
- Spread
- 312,800 ns
- Gate
- PASS
Conditioned with SHAKE256. The manifest explicitly states that conditioning does not create entropy.
HUMANBLOOMING · PUBLIC EVIDENCE RELEASE
A conventional-hardware demonstration of ephemeral secret construction, partial-compromise resistance, functional dependency testing, and deliberate destruction of recovery state.
This release documents a completed HumanBlooming Sovereign Physical Root execution performed using conventional commercial hardware and operating-system facilities only. The public package contains the surviving ciphertext, cryptographic commitments, execution manifest, verification scope, SHA-256 inventory and an offline verifier.
The experiment does not attempt to prove universal immunity from attack. It demonstrates something narrower and technically more useful: a protection architecture in which recovery depends on a transient composite state, individual contribution paths are functionally tested, and managed recovery material is deliberately destroyed after successful verification.
7184365c7396799781c22637b8607e82735feb9096de4f6aac0f7e2e4915b78e01
Much of conventional cybersecurity is organized around a persistent problem: create a secret, store it, protect it, control access to it and prevent an adversary from extracting it for as long as the protected information exists.
Sovereign explores a complementary security model.
What if the information required to recover a protected state is designed to have a deliberately finite lifetime?
In this execution, recovery state is constructed from multiple heterogeneous contributions, used to transform and successfully recover the payload, challenged through individual ablations, and then subjected to a burn phase intended to remove the managed material required to reconstruct that state.
After the burn, does sufficient recovery state still exist inside the declared security boundary to reconstruct what was destroyed?
02
This release is intentionally important for what it does not require.
The execution uses mechanisms available on a commercial computing platform: CPU timing observations, host-observed CUDA execution latency, Windows BCryptGenRandom, and a TPM-backed cryptographic operation through the Microsoft Platform Crypto Provider.
No QPU, external QRNG or remote entropy provider is required by this protocol run. HumanBlooming's separately published advanced physical-entropy and quantum-computing work is not used to strengthen the claims of this release.
03
The public execution manifest records a 41-byte pad constructed from four contributions:
P =
SHAKE256(CPU timing observations)
XOR SHAKE256(CUDA latency observations)
XOR Windows BCryptGenRandom
XOR first N bytes of one-use TPM ECDSA-P256 signature
The payload M is transformed as C = M XOR P.
Security requires at least one contribution to remain unknown during capture.
If the ciphertext and some contributions become known while one remaining contribution retains sufficient effective uncertainty and remains unknown, the missing contribution still blocks direct algebraic reconstruction of the composite pad. This does not imply that weak-source entropy can simply be added together; residual security depends on the effective uncertainty of what remains unknown.
04
Conditioned with SHAKE256. The manifest explicitly states that conditioning does not create entropy.
Host-observed CUDA execution latency; not claimed as a certified quasiparticle measurement.
A cryptographic operating-system contribution distinct in implementation origin from the timing channels.
05
| Configuration | Recorded result |
|---|---|
| CPU + GPU + OS + TPM | ROUND-TRIP PASS |
| Without CPU | REJECTED |
| Without GPU | REJECTED |
| Without OS | REJECTED |
| Without TPM | REJECTED |
These tests do not establish an entropy rate. They demonstrate a different property: the recorded execution is functionally dependent on every individual contribution path.
06
CREATE → PRIVATE EXPORT REJECTED → USE → SIGNATURE VERIFIED → DELETE → REOPEN FAILED
TPM public-key SHA-256 fingerprint:
f459ba247bcf0cc1c145af641e21ae2a66b961d8a8ec71f5a80663d51224abb9
The private key and TPM signature are not included in the public package.
07
After successful round-trip and ablation testing, the execution records zeroization of the managed payload, CPU buffer, GPU buffer, operating-system contribution, TPM signature, TPM buffer, final pad and recovered copy.
It also records that raw timing observations, the OS contribution, TPM signature and final pad were not written, and that no recovery command exists.
Ciphertext plus a long-term protected recovery capability.
Ciphertext plus deliberate destruction of the managed recovery capability.
08
3f05540dbecd060b70fdf0c71ba7c85f6401c02e6619abe8fa8198a7b72ca94b
c49f7a9f06b1be4d5cedf7f46c5ed3ea23c1ee648fc9f2d08f03573b84e40515
7b530043dc9677ff590ad06d5797f5c89618c13bacb4c6bb4361b1f2ddfa5d23
f7d70c3c5981442d36d73d6d2c5bd36adf1a13f458cd3f61de1fe8b4993d0ab1
Security note. A public hash of a low-entropy or easily enumerable payload can be used to test candidate plaintexts offline. The confidentiality value of the pre-burn commitment therefore depends on the committed payload not belonging to a practically enumerable candidate space.
09
evidence_level = MANIFEST_AND_CIPHERTEXT
PASS = true
The supplied verifier checks the internal consistency of the released evidence. It does not independently certify hidden runtime events or entropy rate.
10
Complete evidence ZIP SHA-256:
7184365c7396799781c22637b8607e82735feb9096de4f6aac0f7e2e4915b78e
| Artifact | SHA-256 |
|---|---|
| PUBLIC_CLAIMS.md | 747d6e7fa1602481da42f72e7f8a03c0a18ddd1051473618280b990eb34b38b2 |
| PUBLIC_RUN_MANIFEST.json | 9b3d127a3752dce0f006f376fa9604d787cde9efc3ab0b770ef9251af05fd6bc |
| SHA256_PUBLIC_FILES.txt | fdebab0f930aa918d4888af76e82d52ee184dfe030f8af2869f1b72dca9bc421Independent audit calculation; not self-listed in the inventory. |
| SOVEREIGN_CIPHERTEXT.bin | 3f05540dbecd060b70fdf0c71ba7c85f6401c02e6619abe8fa8198a7b72ca94b |
| VERIFICATION_SCOPE.md | 909559f0916279f92f5b31b7212b954f86d3eb91d6da1e2b91ec1f5a541dcac7 |
| verify_public_evidence.py | 674aa7d5433e5bb8e20754942940e194489d8c7557afba415e9e4755dd161188 |
824a749cd50de93a0f6436fa17586f02f968935e0478acc1365ec179f4b08a8311
The original evidence ZIP is physically included beside this HTML page. Download it, calculate its digest and execute the included verifier offline.
sha256sum HUMANBLOOMING_SOVEREIGN_PUBLIC_EVIDENCE_COMPLETE.zip
Expected:
7184365c7396799781c22637b8607e82735feb9096de4f6aac0f7e2e4915b78e
unzip HUMANBLOOMING_SOVEREIGN_PUBLIC_EVIDENCE_COMPLETE.zip
sha256sum -c SHA256_PUBLIC_FILES.txt
python verify_public_evidence.py
12
This release does not claim to prove a certified CPU/GPU entropy or min-entropy rate, formal statistical independence of all contributions, kernel or firmware integrity, DMA resistance, absence of privileged compromise, physical absence of every possible internal copy, a certified quasiparticle measurement, or universal immunity against every possible attack.
These limitations are part of the evidence, not exceptions hidden outside it.
The package provides reproducible public evidence of a recorded local cryptographic burn using four heterogeneous contribution paths, functional dependency testing, managed-state destruction/non-persistence, and a surviving cryptographically committed ciphertext.
13
HumanBlooming does not claim that this release constitutes NIST certification or validation. Terminology and comparison points include:
These references do not transform this experimental release into a standards certification.
14
HumanBlooming's wider research program includes substantially stronger physical-entropy and quantum-computing work. Those results are intentionally separated from this evidence release.
What security architecture can be demonstrated using only mechanisms available on conventional commercial hardware?
The answer presented here is not dependent on QPU access, advanced HumanBlooming physical entropy sources or external quantum infrastructure.
Explore separately published HumanBlooming research and evidence →
References to IBM hardware or IBM Quantum in separate HumanBlooming research describe infrastructure used in those experiments and do not imply certification, validation or endorsement by IBM.
15
Sovereign asks whether different defensive paths can contribute to a common transient state, whether partial disclosure can remain insufficient, whether each path can be functionally challenged before destruction, and whether recovery capability can be given an intentionally finite lifecycle.
The objective is not to make a secret harder to find forever. The objective is to reach a point where the secret required for recovery is no longer intended to exist.
This conventional-hardware release is the public evidence for that experiment.
The public package intentionally excludes the private operator source, plaintext payload, raw CPU/GPU observations, operating-system entropy contribution, TPM signature/private material, final/intermediate pads, and recovery material.
These exclusions are intentional security boundaries. The public verifier validates the evidence that was released; it does not reconstruct deliberately destroyed or withheld secret state.
HumanBlooming · Sovereign Physical Root · Public Evidence Release · Run recorded 2026-09-28 17:34:10 Europe/Madrid.