Full text
Dual-Torus Architecture in SHA-256: Carry-Field Tomography Reveals Asymmetric Subsystem Design Bee Rosa Davis * December 2025 Abstract We present a novel structural analysis of SHA-256 using carry-eld tomography , a methodology that treats per-bit carry events in modular addition as a discrete curvature eld on the state torus (Z/232Z)8 . By partitioning staged additions into channel-specic subsystems and measuring second-order coherence structure, we discover that SHA-256 implements a dual-clock architecture with fundamentally dierent mixing characteristics: A-torus (Maj, Σ0 , registers a, b, c, d ): Rigid 8-round correlation length with zero variance across message populationsa deterministic metronome providing rapid symmetric diusion. E-torus (Ch, Σ1 , registers e, f, g, h ): Variable 1016 round correlation length (mean 12)a path-dependent carrier providing nonlinear security margin. Bridge ( d+T1→e′ ): Transfers A-diused structure into E-timing, following the E-clock (12 rounds) while preserving A-like ngerprint structure. The subsystems are structurally independent (RV coecient 1.2%) but temporally coupled through the bridge. This asymmetric design explains why the Nikoli¢-Biryukov 9step local collision exploits the predictable A-clock, while extended attacks require geometryguided targeting of trailing registers where the slower E-clock provides additional structure. Our methodologydening sector coordinates from spectral coherence of carry patterns, with stratied confound matchingprovides a general framework for geometric cryptanalysis of ARX primitives. Contents 1 Introduction 3 1.1 AGeometricPerspective................................ 3 1.2 MainContributions................................... 3 1.3 RelatedWork...................................... 3 2 Theoretical Framework 4 2.1 TheStateTorus .................................... 4 2.2 Round Update as Nonlinear Map . . . . . . . . . . . . . . . . . . . . . . . . . . . 4 2.3 Carry Events as Discrete Curvature . . . . . . . . . . . . . . . . . . . . . . . . . . 5 2.4 ChannelPartition.................................... 7 2.5 Sector Coordinates from Coherence . . . . . . . . . . . . . . . . . . . . . . . . . . 8 2.6 ConfoundControl.................................... 8 * Principal Adversarial Intelligence Engineer. Electronic mail: [redacted for preprint] 1
3 Experimental Methodology 9 3.1 InstrumentedSHA-256................................. 9 3.2 FingerprintConstruction................................ 9 3.3 Correlation Length Measurement . . . . . . . . . . . . . . . . . . . . . . . . . . . 9 3.4 Cross-Channel Correlation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10 4 Experimental Results 10 4.1 Correlation Length by Channel . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10 4.2 Cross-Channel Independence . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11 4.3 BridgeAnity ..................................... 11 5 The Dual-Torus Architecture 12 5.1 ArchitectureSummary................................. 12 5.2 Functional Interpretation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12 5.3 WhyThisDesignWorks................................ 12 6 Connection to Classical Cryptanalysis 13 6.1 The Nikoli¢-Biryukov Local Collision . . . . . . . . . . . . . . . . . . . . . . . . . 13 6.2 Trailing Register Vulnerability . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14 6.3 TheSecurityHorizon.................................. 14 7 Design Implications 14 7.1 TheNSA'sDesignChoice ............................... 14 7.2 Rotation Constant Selection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15 7.3 Generalization to ARX Primitives . . . . . . . . . . . . . . . . . . . . . . . . . . . 15 8 Conclusion 15 8.1 Practical Implications for Cryptanalysis . . . . . . . . . . . . . . . . . . . . . . . 16 8.2 A BKM-Style Regularity Criterion . . . . . . . . . . . . . . . . . . . . . . . . . . 16 8.3 OpenQuestions..................................... 16 8.4 TheUniedThesis................................... 17 A Notation Reference 18 B Experimental Parameters 18 C SHA-256 Round Function Reference 18 2
1 Introduction The security of cryptographic hash functions rests on their approximation of random oracles functions whose outputs are computationally indistinguishable from uniform random strings. For SHA-256, this property emerges from the avalanche eect : small input changes propagate rapidly through the compression function, destroying exploitable structure. Traditional cryptanalysis evaluates mixing through dierential and linear methods, measuring how input dierences propagate probabilistically. These approaches treat the hash function algebraically, analyzing Boolean equations and their statistical biases. While powerful, they provide no geometric intuition for why certain attacks succeed and others fail. 1.1 A Geometric Perspective We propose a fundamentally dierent approach: carry-eld tomography on the discrete state torus. Rather than asking how do bit dierences propagate? we ask: 1. What is the shape of the carry-eld correlation structure? 2. How does this structure decay across rounds? 3. Do dierent functional subsystems exhibit dierent geometric clocks ? The key insight comes from treating modular addition carries as a discrete analogue of curvature. In Riemannian geometry, curvature measures the failure of parallel transport to preserve vectors around closed loops. In SHA-256, carries measure the failure of XOR (the linear approximation) to match modular addition. High carry activity indicates regions where the linear model breaks downprecisely where cryptographic nonlinearity lives. 1.2 Main Contributions 1. Carry-Field Tomography Framework. We develop a methodology for extracting geometric structure from staged modular additions, dening sector coordinates from secondorder coherence measures with proper confound control. 2. Dual-Clock Architecture Discovery. We empirically demonstrate that SHA-256 contains two weakly-coupled subsystems with dierent correlation timescales: the A-torus (8-round clock) and E-torus (12-round clock). 3. Bridge Characterization. We show that the d+T1 operation acts as a one-way valve, transferring A-structure into E-timing while maintaining structural independence (RV coecient 1.2%). 4. Connection to Classical Cryptanalysis. We explain why the Nikoli¢-Biryukov 9-step local collision succeeds (it exploits the A-clock) and why geometry-guided attacks extend to Round 18 (they target E-clock trailing registers). 1.3 Related Work Dierential Cryptanalysis of SHA-256. Nikoli¢ and Biryukov [1] introduced practical collisions for step-reduced SHA-256 using a 9-step local collision with modular dierences. Sanadhya and Sarkar [2] extended this to 24 steps. Mendel et al. [3] achieved 31-step collisions using extended local collision techniques. Our geometric analysis explains why these attacks plateau: the A-torus thermalizes at 8 rounds, removing exploitable A-structure. 3
Higher-Order Dierential Attacks. Lamberger and Mendel [4] applied higher-order dierentials to SHA-256, achieving distinguishers up to 46 steps. The connection between algebraic degree collapse and our E-clock thermalization merits further investigation. ARX Cryptanalysis. The broader literature on Addition-Rotation-XOR primitives [5] treats carries as the primary source of nonlinearity. Our contribution is to organize this into a channelspecic geometric framework with measurable correlation timescales. Heat Kernel Methods. In our companion work [6], we introduced heat kernel cryptanalysis : treating the SHA-256 state space as a discrete manifold and analyzing diusion via the heat equation ∂tu= ∆u , where ∆ is a graph Laplacian constructed from state transitions. The heat kernel Kt(x, y) = Pke−λktϕk(x)ϕk(y) encodes how probability mass spreads from state x to state y after t rounds. Spectral gaps in the Laplacian eigenvalues λk determine mixing rates. That work identied trailing register vulnerabilities using curvature-weighted variable selection for cube attacks; the present paper explains why those vulnerabilities exist via the dual-clock architecture. Geometric Field Theory. The geometric intuitions in this work draw from a broader program [7] applying dierential geometry to discrete computational systems. The key insight is that nonlinear operations create curvature in the sense that parallel transport (tracking how structures evolve) fails to commute around closed paths. In SHA-256, carries quantify this failure: the dierence between the linear approximation (a⊕b) and the true result (a+bmod 232) measures local curvature. Regions of high carry activity are geometrically curved, while low-carry regions are at. This perspective motivates treating carry statistics as a discrete curvature eld. 2 Theoretical Framework 2.1 The State Torus SHA-256 compression operates on an 8-word internal state: xt= (at, bt, ct, dt, et, ft, gt, ht)∈(Z/232Z)8 (1) This is a nite abelian group. Embedding each word w∈ {0,...,232 −1} into [0,1) by w7→ w/232 gives: (Z/232Z)8 behaves like a discrete sampling of T256 = (R/Z)256 (2) The torus terminology reects periodic boundary conditions induced by modular arithmetic just as angles wrap around at 360◦ , 32-bit words wrap around at 232 . This creates a closed, bounded state space where trajectories cannot escape to innity. The geometry of this space (how far apart two states are, how trajectories curve) underlies our analysis. 2.2 Round Update as Nonlinear Map Let the compression update be written as: xt+1 = Φt(xt, Wt), t = 0,...,63 (3) where Wt is the message schedule word. The update uses Boolean functions Ch , Maj , rotations, and additions mod 232 . 4
Figure 1: The SHA-256 state space as a discrete torus. Each 32-bit word wraps at 232 , inducing periodic boundary conditions analogous to angles wrapping at 360◦ . The state trajectory (red) winds through 64 rounds from initialization (green) to nal hash (red square). The color gradient indicates round progression. This embedding motivates treating SHA-256 compression as a discrete dynamical system on T256 = (Z/232Z)8 . Denition 2.1 (SHA-256 Round Functions) . Σ0(x) = ROTR2(x)⊕ROTR13(x)⊕ROTR22(x) (4) Σ1(x) = ROTR6(x)⊕ROTR11(x)⊕ROTR25(x) (5) Maj(a, b, c) = (a∧b)⊕(a∧c)⊕(b∧c) (6) Ch(e, f, g) = (e∧f)⊕(¬e∧g) (7) Remark 2.2 (Functional Asymmetry) . Maj is symmetric : each input aects the output in 3 of 4 cases. Ch is asymmetric : input e gates between f and g . This functional asymmetry is central to our ndings. 2.3 Carry Events as Discrete Curvature Bitwise XOR is linear over F2 : it satises (a⊕b)⊕c=a⊕(b⊕c) and produces no surprises. A 32-bit modular addition, however, is fundamentally nonlinear due to carry propagation. The relationship can be decomposed as: a+b= (a⊕b) + 2(a∧b) + higher carry interactions (8) The term 2(a∧b) represents positions where both inputs have 1-bits, forcing a carry. Carries encode the failure of the linear (XOR) approximation . In our geometric analogy, this failure 5
Figure 2: Nested subsystems with weak structural coupling. The A-torus (blue, inner) and E-torus (orange, outer) occupy the same state space but operate with dierent correlation timescales. The RV coecient between their Gram matrices is 1.2%essentially noise oor indicating structural independence despite geometric nesting. The combined system's correlation length (8 rounds) is dominated by the A-channel's zero-variance clock, masking the E-channel's longer memory in composite measurements. is curvature: just as a curved surface cannot be attened without distortion, the modular addition cannot be linearized without error. High carry activity indicates regions where the linear model breaks downprecisely where cryptographic nonlinearity lives. Example 2.3 (Curvature Extremes) . Consider adding 0xFFFFFFFF + 0x00000001 . The XOR approximation gives 0xFFFFFFFE , but the true sum is 0x00000000 with a carry-out. This single addition generates 32 carry eventsmaximum curvature. In contrast, 0x00000001 + 0x00000001 = 0x00000002 produces only one carry (at bit 0)minimal curvature. Regions of high carry activity are where SHA-256's nonlinearity concentrates. Denition 2.4 (Carry Mask) . For an addition at operation index u , dene the carry mask: Mu∈ {0,1}32, Mu[b]=1 if there is a carry out of bit b (9) For SHA-256 with 7 staged additions per round, we index: Ft,s,b := Mt,s[b]∈ {0,1} (10) 6
Figure 3: Carry activity as discrete curvature. Gaussian curvature on a torus varies by position: the outer rim (red, positive curvature) corresponds to regions of high carry activity, where the XOR linear approximation fails most severely. The inner rim (blue, negative curvature) corresponds to low-carry regions where modular addition behaves nearly linearly. In SHA-256, high-curvature regions drive faster mixing and quicker thermalization. Color scale: Gaussian curvature K∝ carry density. where t is round index, s∈ {0,...,6} is stage index, and b∈ {0,...,31} is bit lane. 2.4 Channel Partition We partition the 7 staged additions by functional provenance: Table 1: Stage-to-Channel Assignment Stage Operation Channel Rationale 0 h+ Σ1(e) E E-register input 1 +Ch(e, f, g) E E-function 2 +Kt Neutral Constant injection 3 +Wt Neutral Message injection 4 Σ0(a) + Maj(a, b, c) A A-function 5 d+T1 Bridge A → E conduit 6 T1+T2 A A-register update This gives channel denitions: E-channel :{0,1} (11) A-channel :{4,6} (12) Bridge :{5} (13) 7
2.5 Sector Coordinates from Coherence We dene sector coordinates from second-order structure of the carry eld, avoiding the nearconstant statistic trap of rst-order measures. Denition 2.5 (Temporal Spectral Coherence) . Row-normalize centered operation vectors: ˜ Xu,·:= Xu,· ∥Xu,·∥2 (14) where X=F−1µ⊤ is the centered carry eld. Then: GT:= ˜ X˜ X⊤, QT,eig := λmax(GT) N (15) Interpretation: If many operations share a common carry mode, λmax concentrates and QT,eig rises. Denition 2.6 (Spatial Spectral Concentration) . Compute bit-bit covariance: CB:= 1 NX⊤X (16) Let eigenvalues be λ1≥λ2≥ · · · ≥ λ32 ≥0 . Then: Qλ:= PK k=1 λk P32 k=1 λk ,(K= 5) (17) Interpretation: How low-rank the bit-lane correlation geometry is. Denition 2.7 (Wedge Sector Coordinate) . Q∧:= QT,eig ·Qλ (18) This is high only when temporal operation patterns are mode-locked and that locking is expressed through a small set of correlated bit modes. 2.6 Confound Control Message statistics (Hamming weight, word magnitudes) correlate with carry statistics. Without matching, a classier can cheat by exploiting message properties rather than geometric structure. Denition 2.8 (Stratied Tail Matching) . Let ψ(m) be message summary statistics. Dene stratum key: κ(m) := HW(m) ∆hw ,mean(m) ∆mv (19) where HW(m) is the Hamming weight (number of 1-bits) and mean(m) is the mean word value across the message. Sample HI and LO sectors to have identical distributions over κ . This stratication is essential: messages with more 1-bits naturally produce more carries (since 1 + 1 = 102 generates a carry while 0 + 0 = 0 does not). Without matching on Hamming weight, a naïve classier could achieve spurious accuracy by detecting message statistics rather than cryptographic structure. Stratied matching ensures that any detected signal reects genuine geometric dierences in how SHA-256 processes structurally-equivalent inputs. 8
3 Experimental Methodology 3.1 Instrumented SHA-256 We implement SHA-256 per FIPS 180-4 with state capture at congurable rounds. Each trajectory records: Input message m∈ {0,1}512 (single block) Carry masks Ft,s ∈ {0,1}32 for all 7 stages across 64 rounds Staged intermediate values for verication Implementation validated against all FIPS 180-4 test vectors. 3.2 Fingerprint Construction For a window [r0, r1) and channel stages S , we construct a 39-dimensional ngerprint: Per-bit carry rates (32 dimensions) Top-5 eigenvalue ratios of bit-covariance (5 dimensions) QT,eig (1 dimension) Mean density (1 dimension) Fingerprints are centered and normalized for cosine similarity comparisons. 3.3 Correlation Length Measurement The correlation length measures how many rounds of SHA-256 processing are required before carry patterns become statistically independent from their initial state. Intuitively, if two ngerprints from rounds r and r+k are correlated, structure from round r persists into round r+k an attacker might exploit this persistence. When correlation drops to zero, the structure has thermalized and earlier structure provides no advantage. Denition 3.1 (Thermalization) . Thermalization is the process by which structured patterns in the state decay to statistical equilibrium, becoming indistinguishable from random. A thermalized subsystem provides no exploitable structure to an attacker. The correlation length ξ measures the thermalization time: after ξ rounds, initial structure has decayed below the noise oor. Remark 3.2 (Security Implication of Correlation Length) . A correlation length of ξ rounds means that structure from round r persists (in a statistically detectable way) until round r+ξ . An attacker can exploit this persistence: if they control input dierences that create favorable structure at round 0, that structure remains useful for ξ rounds. Beyond ξ , the advantage vanishes. Thus, correlation length directly bounds the round-depth of structural attacks . Denition 3.3 (Recurrence Matrix) . For ngerprints ϕW across sliding windows W : S(i, j) = Emsim(ϕWi(m), ϕWj(m)) (20) where similarity is cosine after centering. Denition 3.4 (Correlation Length) . The correlation length ξ is the rst lag where the diagonal decay S(i, i + lag ) falls below threshold (typically 0): ξ:= min{ lag :¯ S diag ( lag )<0} × ∆ step (21) where ∆ step is the window step size in rounds. 9
Round 20 is the security horizon where all structure thermalizes. The methodologysector coordinates from spectral coherence, stratied confound matching, channel-split tomographyprovides a general framework for geometric cryptanalysis of ARX primitives. 8.1 Practical Implications for Cryptanalysis Our ndings have direct implications for attacking reduced-round SHA-256: 1. Target selection : Focus cube/dierential attacks on E-channel trailing registers (g, h) between rounds 1218, where the A-torus has thermalized but the E-torus has not. 2. Attack bounds : The 8-round A-clock provides a hard lower bound on attack complexity A-structure is gone by Round 8 regardless of technique. The variable E-clock (1016 rounds) determines the upper bound E-structure persists longer but eventually thermalizes. 3. Variable selection : Geometry-guided cube attacks should weight input variables that maximize E-channel carry activity in early rounds, as this structure persists longest. 4. Collision search : Local collision techniques should exploit the predictable A-clock for the collision core, then use message freedom to control E-channel evolution through the variable window. The Round 1718 algebraic cli observed in our cube attack experiments corresponds precisely to E-clock thermalization in trailing registers. 8.2 A BKM-Style Regularity Criterion The preceding analysis suggests a formal criterion for structure persistence, analogous to the Beale-Kato-Majda criterion for Navier-Stokes regularity. Denition 8.1 (Structure Persistence Integral) . Let S(r) denote a per-round structure intensity observable (e.g., sector separability or centered carry-eld recurrence at lag 1). Dene the cumulative structure persistence: S(R) = R X r=0 S(r) (23) Conjecture 8.2 (Finite Horizon) . For SHA-256, S(R) saturates by R≈20 : there exists R∗≈ 20 such that S(R∗)≈ S(64) . Beyond R∗ , no additional exploitable structure accumulates. This is the discrete analog of the Beale-Kato-Majda criterion: security (regularity) is preserved because the intensity integral is nite. Just as BKM bounds vorticity to prevent uiddynamical blowup, the structure persistence integral bounds the round depth of viable attacks. 8.3 Open Questions 1. Can the correlation length be predicted analytically from round function specication? 2. Does the E-clock variability correlate with message entropy or structure? 3. Can manifold-based search accelerate practical collision nding? 4. Do other ARX primitives exhibit similar dual-clock architectures? 16
5. Can the structure persistence integral S(R) be computed eciently for arbitrary primitives? The intersection of dierential geometry, spectral analysis, and cryptanalysis represents fertile ground for future research. 8.4 The Unied Thesis The results presented here are instances of a broader mathematical pattern. In all three settings we have studiedRicci/Wilson ow on gauge congurations, vorticity evolution in NavierStokes, and carry-eld dynamics in SHA-256the measurable nonlinearity proxy (plaquette curvature variance, vorticity magnitude, or carry-eld coherence) drives a ow that erases distinguishable structure. The system's topology and coupling constraints determine how that erasure propagates, yielding nite correlation length and channel-dependent transport rather than unbounded persistence. Principle 8.3 (Davis Manifold Principle) . Let (M, Φ) be a discrete or continuous dynamical system with: 1. A nonlinearity proxy κ:M→R≥0 measuring departure from linear behavior 2. A topological constraint τ (linking number, helicity, connectedness) that is approximately conserved 3. A dissipative mechanism D that couples to κ Then the system exhibits bounded structure evolution : there exists a horizon T∗ such that for t>T∗ , the structure intensity S(t)≈0 and no cascade to unbounded values occurs. Corollary 8.4 (Security/Regularity) . Systems satisfying the Davis Manifold Principle cannot exhibit blowup (singularities in PDE, successful attacks in cryptography) beyond the horizon T∗ . For SHA-256, the A-torus provides T∗ A= 8 rounds, the E-torus provides T∗ E= 12 rounds (variable), and the composite horizon is T∗≈20 rounds. The topological constraint is the Hopflink structure between subsystems; the dissipative mechanism is carry-induced diusion. The principle explains why full-round SHA-256 resists attack: by Round 20, all exploitable structure has thermalized. Acknowledgments The author thanks the anonymous collaborators who contributed to the experimental framework and theoretical renements. References [1] I. Nikoli¢ and A. Biryukov. Collisions for step-reduced SHA-256. In Fast Software Encryption (FSE) , LNCS 5086, pages 115. Springer, 2008. [2] S. K. Sanadhya and P. Sarkar. Attacking reduced round SHA-256. In Applied Cryptography and Network Security (ACNS) , LNCS 5037, pages 130143. Springer, 2008. [3] F. Mendel, T. Nad, and M. Schläer. Improving local collisions: New attacks on reduced SHA-256. In Advances in CryptologyEUROCRYPT 2013 , LNCS 7881, pages 262278. Springer, 2013. 17
[4] M. Lamberger and F. Mendel. Higher-order dierential attack on reduced SHA-256. Cryptology ePrint Archive, Report 2011/037, 2011. [5] D. Khovratovich and I. Nikoli¢. Rotational cryptanalysis of ARX. In Fast Software Encryption (FSE) , LNCS 6147, pages 333346. Springer, 2010. [6] B. R. Davis. Heat kernel cryptanalysis of SHA-256: Geometric structure and algebraic exploitation. Preprint, December 2025. [7] B. R. Davis. The eld equations of semantic coherence: A geometric theory of meaning, curvature, and reasoning in transformer architectures. Zenodo, 2025. https://doi.org/ 10.5281/zenodo.17771796 [8] National Institute of Standards and Technology. Secure Hash Standard (SHS) . FIPS PUB 180-4, August 2015. [9] A. Biryukov, M. Lamberger, F. Mendel, and I. Nikoli¢. Second-order dierential collisions for reduced SHA-256. In Advances in CryptologyASIACRYPT 2011 , LNCS 7073, pages 270287. Springer, 2011. [10] S. Indesteege, F. Mendel, B. Preneel, and C. Rechberger. Collisions and other non-random properties for step-reduced SHA-256. In Selected Areas in Cryptography (SAC) , LNCS 5381, pages 276293. Springer, 2009. [11] P. Robert and Y. Escouer. A unifying tool for linear multivariate statistical methods: The RV-coecient. Journal of the Royal Statistical Society: Series C (Applied Statistics) , 25(3):257265, 1976. [12] I. Dinur and A. Shamir. Cube attacks on tweakable black box polynomials. In Advances in CryptologyEUROCRYPT 2009 , LNCS 5479, pages 278299. Springer, 2009. A Notation Reference Symbol Denition (Z/232Z)8 State space (discrete torus) Ft,s,b Carry eld (round t , stage s , bit b ) QT,eig Temporal spectral coherence Qλ Spatial spectral concentration Q∧ Wedge sector coordinate ( QT,eig ·Qλ ) ξ Correlation length (rounds) RV(E, A) RV coecient (structural similarity) Maj,Ch SHA-256 Boolean functions Σ0,Σ1 SHA-256 rotation functions T1, T2 Intermediate values in round function Table 5: Notation reference B Experimental Parameters C SHA-256 Round Function Reference For completeness, the SHA-256 state update: 18
Parameter Value Messages per seed 2000 Seeds {42,123,999} Message size 64 bytes (single block) Sector window [0,12) rounds Readout window [16,28) rounds Sliding window size 8 rounds Sliding window step 2 rounds Tail fraction (HI/LO) 20% Matched samples per group 200 Permutation tests 200 Fingerprint dimension 39 Table 6: Experimental parameters T1=h+ Σ1(e) + Ch(e, f, g) + Kt+Wt (24) T2= Σ0(a) + Maj(a, b, c) (25) (a′, b′, c′, d′, e′, f′, g′, h′)=(T1+T2, a, b, c, d +T1, e, f, g) (26) Stage mapping to operations: 0. h+ Σ1(e) 1. ( stage 0 ) + Ch(e, f, g) 2. ( stage 1 ) + Kt 3. ( stage 2 ) + Wt⇒T1 4. Σ0(a) + Maj(a, b, c)⇒T2 5. d+T1⇒e′ 6. T1+T2⇒a′ 19