Skip to content

Method

A joint design decision without either side handing over its input, with the leaks we found in it

The result

Two organisations reach a joint design decision without either handing over its input, with the leaks found in the published files.

Limit Commitment-based, not zero-knowledge, and in progress; a lossy encoding still gets past every scan.

Sometimes two companies need a joint answer, such as whether a package meets a coupling budget, without either showing the other its design. The record describes a commitment-based exchange that does this, and a sweep for leaks through the files it publishes. The sweep found that published bytes were leaking private values, including through the very text written to explain a leak, and took them down to none in the committed files. The method is explicitly not zero-knowledge, and the work is in progress.

A dotted magenta underline marks a number read straight from a published file when this page was built.

On this page
  1. What it shows
  2. Why it matters
  3. Who should care
  4. The limits, in the record’s words

What it shows

A confidential exchange is only as private as every file it publishes. A design value can leak through a field name, a log line or a rounding, not only through the answer.

The record states the result this way:

The published record says, word for word (an excerpt)

Two organisations reach a joint engineering decision without either handing over the input that answers it, and the leak sweep took 13 of 39 private scalars in the committed artifact down to 0.

In plain words: in the committed files of the exchange, 13 of 39 private values were found leaking, and after the fixes 0 were. A sweep of 19 planted faults was each caught by the check aimed at it.

Why it matters

Companies that design packages together often cannot share their designs. A joint check that keeps each input private, and that has been swept for leaks with the results published, is a starting point for that kind of work.

What is ours, and what is not

Commitments and joint computation over private inputs are established ideas (see the prior art below). What is ours is this exchange for a packaging decision, and the leak sweep with its results.

Who should care

  • Package and chip teams who need a joint check without sharing designs.
  • Reviewers. The record states the leaks it found, and that a lossy encoding still defeats every scan.

The limits, in the record’s words

The published record says, word for word (an excerpt)

Commitment-based signoff, explicitly NOT zero-knowledge — the name is honest. Status is in-progress, not done.

The published record says, word for word (an excerpt)

A lossy 4-significant-figure encoding defeats every scan, disclosed.

In plain words: this is not zero-knowledge, it is work in progress, and a value encoded lossily, to a few significant figures, gets past every scan the sweep runs. The leak counts are for the committed files of this exchange, not a guarantee about any other.

Open source for this step

Tools and datasets we publish for the package step of building a multi-chip package. They are the checkers around this work, not a copy of the result itself.

  • physics-lint: One command that checks a folder of physics models against a fixed set of named physical rules, with findings straight into CI.
  • maxwell-lint: Flags a coupling extractor whose answers no passive set of conductors could produce.
  • sparam-lint: Is your signal-response model physically possible? Five physical laws checked from the command line.
  • interval-core: The interval arithmetic core behind our proofs over whole families of layouts.
  • touchstone-tools: Read, write and convert Touchstone files, the standard text files that record how signals pass through a package's connections, and refuse to write one that cannot be read back.
  • physics-lint-mcp: The physics checks, callable by an AI agent.
  • physics-lint-action: A GitHub Action that fails the build when a model breaks one of a fixed set of named physical rules.
  • Signal-response validity corpus: A labelled corpus of physically invalid signal-response networks, and a scorer that grades any checker against it.
  • screening-ceiling: The screening-ceiling family as an open dataset.

Ask about a result, or check one yourself

Founder: Nick Harris. AI agents do our research and engineering. Each result page says how it was checked: against an outside solver, by an interval-arithmetic proof, by a Lean-checked step, or against our own simulator; these checks ran on our own machines. Who we are · How the work is checked

Every result on this site links to the file it comes from. Acquisition, licensing and partnership enquiries go to one address, nick@chipletos.com, and a person reads it.

Write to us Read the results

Each number links to the file it comes from; every file is listed, with its checksum, on Published files.

When a number is left off

We leave a number off a page, or mark it, when

  • its file has not loaded yet
  • nobody has looked into it yet
  • a search for it found nothing
  • its file holds no value for it
  • its file is missing or altered
  • files disagree on what it describes
  • its sample is too small for the claim
  • two files give different values
  • its file cannot be published
  • it was measured over ninety days ago
  • the question does not apply here
  • the program behind it stopped with an error