# Keccak-256 truncated collision (λ = 24)

The requested collision is supplied in [`collision.json`](../collision.json). Hex strings represent decoded bytes, not the UTF-8 bytes of the hexadecimal text.

| Field | Observed value |
| --- | --- |
| inputA | `0x8375360100000000` |
| inputB | `0x7131040200000000` |
| Keccak-256(inputA) | `8851a59bbb9d6231d46ab9566296d3aed4afb5cd4212a1f68a094142b0366868` |
| Keccak-256(inputB) | `8851a59bbb9d27a12c8340ba34a0ac8820e6315e00542945f74d66f4ef53a9b1` |
| Shared first 48 bits (MSB of the serialized digest) | `8851a59bbb9d` |

## Method and attributable evidence

The locally authored [`src/collision.c`](../src/collision.c) enumerated eight-byte little-endian integers starting at zero and stored the first six digest bytes in a hash table. It found counters 20,346,243 and 33,829,233, after 33,829,234 total evaluations. This implementation uses Keccak-f[1600] with 24 rounds, a 136-byte rate, and original Keccak padding with delimiter `0x01`. The permutation and sponge construction are documented by the designers in the [Keccak specifications summary](https://keccak.team/keccak_specs_summary.html) and [Keccak reference, version 3.0](https://keccak.team/files/Keccak-reference-3.0.pdf). The task's λ = 24 determines a 48-bit comparison; the permutation's 24 rounds are a separate parameter.

The separately authored [`src/verify.py`](../src/verify.py) implements a generic Python sponge with explicit two-dimensional lane mapping. It uses only the Python standard library, checks empty-message and `abc` known-answer values, validates the JSON key set and parameters, decodes the inputs, checks their distinctness, and recomputes both complete digests. Its local output was:

```text
digestA: 8851a59bbb9d6231d46ab9566296d3aed4afb5cd4212a1f68a094142b0366868
digestB: 8851a59bbb9d27a12c8340ba34a0ac8820e6315e00542945f74d66f4ef53a9b1
PASS: distinct inputs; identical first 48 bits: 8851a59bbb9d
```

The C program's full digests matched this output byte for byte. It compiled with `gcc -O3 -march=native -Wall -Wextra` without warnings.

## Conclusion and limits

Observed facts: the decoded inputs are distinct, and both local implementations produced the full digests above with identical first six bytes. These checks support the conclusion that the supplied pair meets the requested 48-bit collision condition. The full 256-bit digests differ.

The evidence is attributable to the included source and this local execution. The two implementations were authored in this assignment; their agreement is not independent external review. SIMD verification was not available or run here, so its acceptance remains unobserved. No claim is made that path or byte validation certifies cryptographic behavior.
