Calibrated Large-Scale Search and Elimination Map and Stopping Rules for Undeciphered Pages: Cicada3301 LiberPrimus

Final research report · 22 July 2026

Liber Primus Unsolved Pages

A calibrated search boundary, a negative-results atlas, and a stopping rule

Publication position: this is not a claim that Liber Primus has been solved. It is the final account of what was tested, what was excluded within explicit bounds, what remains anomalous, and why further unguided expansion is no longer justified.

1. Executive conclusion

The research program has reached a defensible stopping point, but not a decryption endpoint. Hundreds of billions of documented configurations and window comparisons were evaluated across bounded families of classical ciphers, generated number-theoretic keystreams, transpositions, autokey constructions, file-derived pads, image and audio surfaces, and structural detectors. No candidate survived the final calibrated acceptance process as coherent plaintext on the unsolved pages.

The strongest final product is therefore not a plaintext announcement. It is a mapped record of negative results: a description of which finite hypothesis families were searched, how detection power was calibrated, where false positives arose, and where the investigation encounters either combinatorial explosion or an information-theoretic wall.

Final verdict Stop unguided brute-force expansion. Preserve the bounded exclusions. Treat the page-54 observations as unresolved candidates. Resume only when genuinely new evidence changes the prior probability of a specific method.

2. Research question and scope

The project asked whether the remaining Liber Primus material could be advanced through reproducible structural analysis and bounded cryptanalytic searches using the locally assembled corpus. The work concentrated on the operationally unsolved page set, with solved material used for calibration, language models, key provenance, and positive controls.

Three questions guided the final phase:

  1. Can a short, motivated program generate the required keystream from primes, totients, Fibonacci-like sequences, book vocabulary, page parameters, or related primitives?
  2. Can known finite cipher families, transpositions, interrupter conventions, or local carrier bytes produce language under calibrated gates?
  3. Does page 54 contain a transferable structural signature that recurs on other unsolved pages?

The answer to all three was negative within the tested definitions. This qualification is essential. A bounded negative result excludes a model family; it does not prove that the ciphertext is a one-time pad, and it does not exclude an unknown external key, an unconstrained key-derivation function, or an unmodeled compound cipher.

3. Principal contributions

Contribution What it establishes Limit
Calibrated exclusion atlasA traceable map of finite cipher, keystream, carrier, and structural search families.Applies only to the implemented parameterizations and gates.
Matched-null disciplineRepeatedly identified attractive candidates as search-size or page-specific artifacts.Some early exploratory generations predated the final standard.
Positive-control recoveryDemonstrated that later instruments could recover known solutions and planted constructions.Power against a modeled family is not power against every possible cipher.
Proof-corpus self-auditRetired circular, dependent, and high-base-rate numerical claims.The correction weakens earlier page-54 language.
Explicit stopping ruleSeparates low-information expansion from evidence-triggered future work.Several branches were stopped by policy, not falsified.

By the project's own conservative accounting, approximately 357.9 billion real-page full-text configurations were evaluated in the generative-keystream program, with at least 599.1 billion documented evaluations or window comparisons when calibrations and null work are included. These figures are an audit trail of computational scope, not proof by volume.

4. Page 54: anomaly, not solution

Page 54 produced two prominent observations under different constructions:

  • CONSUME/add: a period-seven Vigenère-style operation yields four occurrences of NOT and one of YOU after lossy rune-to-display reduction.
  • Ciphertext-autokey lag 6 followed by affine (23, 21): a sparse cluster can be read as WAS / ATE / FOR / NOW / THAT at selected positions.

These paths generate different outputs. Neither yields coherent full-page English, and the autokey-affine output contains no CONSUME beacon. The sparse word cluster is not an externally supplied crib: its words and positional interpretation were developed after inspecting the candidate output. A corpus-wide scan using the same five-word density criterion placed page 54 only fifteenth among 72 eligible pages, with 17 pages reaching the same raw density threshold.

The defensible statement is therefore:

Page 54 contains unusual, reproducible short-word structure under two motivated transforms, but no complete plaintext or single validated cipher path has been recovered.

5. How the research was carried out

The work did not consist of one undifferentiated brute-force run. It developed into a layered search program in which candidate generation, cheap rejection, full-page scoring, structural checks, and page-matched null tests were kept separate. Early exploratory scripts proposed hypotheses; later generations rebuilt the promising ones as calibrated instruments and then applied them uniformly to the unsolved corpus.

5.1 Corpus construction and representations

The canonical transcription was split into 72 non-empty page units. Each rune was represented by its Gematria Primus index from 0 to 28. Separators, punctuation, line breaks, and image-confirmed word boundaries were retained as parallel structural data rather than silently discarded. The final structural sweeps treated 54 page units as operationally unsolved targets, while solved pages and page 54 were used only in declared calibration or diagnostic roles.

Three representations were used for different purposes:

  • Rune-index space: exact modular arithmetic over 29 symbols for encryption and decryption operations.
  • Rune-language space: n-gram models trained from solved material, preserving the runic alphabet.
  • Display space: a lossy 23-symbol Latin reduction used only for readable-word and beacon detectors. Because multiple runes collapse to the same letter, display-space statistics require their own null model.

The original page images were consulted when punctuation or separator placement affected a test. A later audit checked 12,532 within-line gaps, confirming the recorded word dots and period clusters and identifying four omitted apostrophe marks. This prevented language scores from benefiting from invented word boundaries.

5.2 The hypothesis families

FamilyRepresentative operationsHow it was expanded
Classical modular ciphersAll 812 affine maps; Vigenère, Beaufort and reverse subtraction; plaintext and ciphertext autokey; Hill and Quagmire variants.Keys from solved text, Cicada vocabulary, rune names, page labels, and fixed periods.
Periodic and interrupted keysArbitrary non-interrupted periods 2–29, literal-F conventions, skip geometries, and selected reset rules.Coordinate optimization, beam search, and exact enumeration where the mask size remained finite.
TranspositionsReversal, rail and column families, page-derived permutations, and a catalog of 98 canonical transforms.Composed before or after generated streams and affine layers.
Generated keystream programsPrimes, prime−1, Euler totients, Fibonacci and triangular sequences, divisor functions, digit streams, partitions, Carmichael values, and related integer sequences.Offsets, strides, signs, affine wrappers, pairwise products, algebraic depth, page conditioning, segmentation, and transposition.
Crib and vocabulary searchesKnown phrases, internal sliding cribs, 77 mined repeated 12-grams, book vocabulary, and exact prefix or interior matching.Every feasible alignment, arithmetic mode, and selected cipher wrapper.
Carrier-derived padsRaw files, ZIP members, PDF streams, JPEG bytes and pixels, audio containers, PCM samples, and frame bytes.Forward and reverse direction, all offsets, three arithmetic modes, and the established byte-to-rune maps.
Structural testsLine lengths, repeated packets, boundary geometry, dot ornaments, page graphs, equal-pair streams, and page-54 beacons.Corpus-wide base-rate tests and transfer to every unsolved page.

5.3 The generative-keystream program

The largest branch treated a key not as a guessed word but as a short program. A grammar selected one or more mathematically motivated primitive sequences, applied offsets and strides, combined them with addition, subtraction, or multiplication modulo 29, and optionally wrapped the result in an affine map or transposition. Algebraically duplicate generators were normalized in the later exhaustive generations so that raw formula counts did not inflate the reported search space.

Representative generationSearch sizePurpose
Depth ≤2 grammar≈37.4 millionShallow streams, strides, offsets, constants, and pairwise combinations.
Full depth-4 lattice32,310,894 cellsExhaustive canonical grammar rather than sampling.
Depth-5 non-affine families254,152,416 cellsTest whether deeper algebra created a score gradient.
Transposition × depth-310.66 billion real-page configurationsCombine the generated stream with every canonical transposition.
Transposition × depth-4 AT133.20 billionClose the largest canonical transposed branch.
Depth-4 triple full-page search102.27 billionFinal crib-independent test of the principal deep-stream branch.

Across the generative-keystream generations, the conservative sum for real-page full-text hunts is approximately 357.9 billion configurations. When calibration pages, planted controls, global nulls, and matched nulls are included, the documented lower bound exceeds 599.1 billion evaluations or window comparisons.

5.4 The scoring and rejection funnel

Candidate source  →  transform  →  head score  →  full-page score  →  boundary check  →  matched null  →  human reading
  1. Generation and exact arithmetic. A candidate key or transform was produced in rune-index space. Exact crib and beacon searches stayed exact; they did not use a language model.
  2. Head filter. A rune-bigram model cheaply rejected the bulk of configurations. The head length was increased as the search grew so the expected chance maximum remained below the English calibration range.
  3. Full-page scoring. Surviving candidates were evaluated with solved-text rune models, including an order-5 backoff model, and with a separate Latin letter-bigram diagnostic where appropriate.
  4. Boundary gate. If punctuation was expected to survive, words had to fall at image-confirmed separators. This eliminated high-period fits that created fragments only by cutting across real boundaries.
  5. Matched-null confirmation. A real-page survivor was rerun against shuffled versions of the same page through the same search. The project used a confirmatory threshold of p ≤ .01 and required a coherent reading, not merely a high score.

5.5 Positive controls and null models

The principal known-solution anchor was the solved “AN END WITHIN THE DEEP WEB” material, recovered by its established prime-derived stream. Other solved pages and synthetic pages with planted keys tested whether a proposed detector could recover the correct configuration rather than merely rank random text. Later large searches required at least 90% recovery on planted controls or an exact known-page recovery, depending on the instrument.

Random pads and shuffled pages estimated global false-positive rates. When a real page produced a survivor, a page-matched null was preferred because page length and symbol distribution strongly affected extreme scores. This distinction proved important: one short page repeatedly supplied the global maximum across 13 successive search generations, but its advantage persisted after shuffling and every candidate failed its matched-null test.

5.6 Carrier and provenance analysis

Potential pads were not treated as an undifferentiated pile of files. ZIP members, PDFs, primary puzzle assets, later community captures, and post-2014 material were hashed and placed into provenance tiers. Only motivated, historically plausible byte strings were promoted to expensive all-offset scans. Later material could still be tested as an exact local string, but a negative result on it was not presented as evidence about the original 2014 bytes.

For selected carriers, the standard cube used byte modulo 29 and two rejection maps, forward and reverse direction, and add, subtract, and reverse-subtract modes. Literal-F ambiguity was handled with a beam rather than a single hard interpretation. Image work separately examined encoded files, decoded luminance, and selected RGB channels; audio work separated container bytes, sample values, and raw frame bytes. The final gate was applied to every retained beam candidate, not only the top preliminary score.

5.7 How false leads changed the method

Several apparently strong discoveries were later shown to be artifacts. Expanded three-letter vocabularies made random windows look word-rich. Common line lengths were interpreted as cipher parameters until a corpus-wide base-rate audit showed that the same lengths dominated the entire book. Numerical relations multiplied because derived values were repeatedly recombined. Large searches produced page-specific maxima that disappeared under matched nulls.

These failures led to the mature rules used in the final phase: freeze gates before the hunt, calibrate through the complete pipeline, scale the head length with search size, preserve true boundaries, count algebraically distinct generators, and never promote a survivor without a page-matched null and readable output.

6. Result map

ClassFinal statusCorrect interpretation
Short and medium periodic keysCalibrated negative in tested rangesThe enumerated uninterrupted families did not decode the unsolved set.
Generated number-theoretic streamsCore bounded program exhaustedShallow motivated grammars and several deeper canonical families were negative.
Transposition compositionsLarge finite subspaces negativeUnmotivated higher-order products remain infinite in practice.
Local file, image, and audio padsSelected authentic surfaces negativeDefined byte maps, directions, channels, and offsets were tested; arbitrary derived representations were not.
Page-54 signature transferNo accepted transferThe tested p54-like beacons and structures did not recur on the unsolved pages.
External pad or true OTPOpen and potentially undecidable locallyNo local negative result can exclude unavailable external key material.

No reported real-page survivor passed the complete late-stage chain of calibrated gate, matched-null significance, boundary-aware language inspection, and coherent reading. That is the central empirical result.

7. Recalibration and corrections

The project initially described dozens of page-54 numerical relationships as independent proofs. Subsequent audits showed that this language was not sustainable:

  • Common line lengths were mistaken for rare parameter encodings.
  • Derived values were sometimes counted again as confirmations.
  • A large target set made more than half of simple pairwise arithmetic combinations appear meaningful.
  • Several observations were re-expressions of the same event through different lookup tables.

The phrase “74+ independent proofs” is retired. The numerical relationships remain part of the exploratory history, but they are not independent evidence.

The CONSUME significance issue

An early Poisson approximation treated the rendered output as if each trigram were drawn uniformly from 29 display symbols. The actual display reduction contains 23 symbols and is many-to-one: several rune indices render as the same Latin letter. That model therefore understates the chance rate for strings such as NOT.

During finalization, a deterministic 300,000-trial permutation spot-check preserved the page-54 rune multiset and applied the fixed CONSUME/add construction. It observed three trials with at least four NOT occurrences and one trial meeting the broader gate of at least three NOT plus at least one YOU. No trial reproduced the exact observed combination of at least four NOT plus at least one YOU.

This spot-check supports the claim that the fixed observation is unusual, but it does not supply a discovery-adjusted p-value. The original search tested 476 windows, 33 keys, and four modes before escalation, and earlier generations influenced that search surface. A conclusive significance claim would require an end-to-end null that reproduces the complete adaptive discovery procedure. No such p-value is claimed here.

8. Explicit open boundaries

The following remain open. They are boundaries, not evidence that a particular answer lies within them.

  1. Unavailable external material. The hypothesized deep-web resource associated with “AN END” has not been recovered. Academic Tor archives may contain relevant historical content, but access and provenance verification remain external tasks.
  2. Arbitrary KDF constructions. Unbounded salts, iteration counts, contexts, and personalization strings cannot be exhaustively excluded.
  3. Large Hill and compound families. A 3×3 keyspace over 29 symbols and unconstrained cipher compositions remain computationally or methodologically out of reach.
  4. Unknown external pads and true OTP. These are not distinguishable from random text without key material or a sufficiently long crib.
  5. Untested representations. Arbitrary image transforms, audio-domain transforms, bit-plane schemes, and noncanonical byte-to-rune maps remain possible but lack independent motivation.
  6. Deferred internal branches. The full two-program segmented GKP branch was not completed; only a restricted known-key degeneration was tested. The demonstrated-stream plus variable F-skip branch also remains unexecuted.

It is important to distinguish these items from calibrated negatives. “Not searched because the model was too broad or weakly motivated” is not the same as “searched and rejected.”

9. Why stopping is justified

The stopping decision rests on expected information gain, not exhaustion of all mathematical possibilities. Known solved material uses comparatively shallow constructions. As program depth, cipher composition, key derivation, segmentation, and representation choices are multiplied, the search space grows faster than the evidence supporting any specific branch. Flexible searches can manufacture language-like fragments even from shuffled data.

Future work should resume only when at least one of the following occurs:

  • a new authenticated primary artifact becomes available;
  • a coherent known-plaintext span of approximately 25 or more runes is recovered;
  • external archival material can be checked against known hashes or addresses;
  • a specific compound construction gains independent support from the book's physical or textual structure;
  • an independent team reproduces a page-54 anomaly with a discovery-wide null and a preregistered reading rule.

Absent one of these triggers, more computation would mostly expand researcher degrees of freedom rather than increase the probability of a reliable solution.

10. Final assessment

This project did not solve the remaining Liber Primus pages. It did something narrower and still valuable: it converted a large, loosely bounded puzzle hunt into an auditable research boundary. It documented failed families, measured false-positive behavior, found and corrected its own overclaims, and identified the conditions under which further work would again become rational.

The final contribution is best summarized as follows:

Within the explicitly enumerated cipher, keystream, transposition, and carrier families, calibrated searches found no accepted plaintext on the unsolved Liber Primus pages. Page 54 retains reproducible short-word anomalies but is not solved. The rational next move is not broader brute force; it is new evidence.

That is an appropriate endpoint for the present research program and an honest basis for public presentation.

このブログの人気の投稿

Research Using LLMs on cicada3301

Article1 research mainline

Voynich Interim Report