## White Paper: CORA - Patterns and Probabilities

### Quantum Computers will not break CORA!

## What is needed to read the encrypted (CORAfied) data?

- **The Encryption package.**  
  - Multiple Use Pads (MUPs) are fast and reusable OTPs which have long been identified as 'perfect encryption'.  
  - CORA's MUPs vary in size. Why give a hacker 'any' information including the length of the encryption key?  
  - Unlike other forms of encryption in which each key is the same size, CORA is probabilistic and varies just about everything including the length of the MUP.  
  - MUPs are more than 1 million bits long; nothing compares to CORA.  
  - 1,000,000+ bit encryption is 10<sup>300,413</sup> times stronger than 2048 bit encryption.  
  - The MUP is dispersed and only exists as a complete key 'in memory'.  
- **The catalog.**  
  - Connects the CORA blocs with the readable data.  
  - Centrally controlled.  
  - CORAfied (encrypted).  
- **The CORA blocs.**  
  - CORA is a distributed solution.  
  - The number of CORA blocs varies.  
  - Each CORA bloc is needed without exception and without corruption.  
  - Each byte in each bloc must be exact; there cannot be any modification what so ever.  
  - Ideally CORA blocs will be dispersed on 'different' devices and/or in the Cloud.  
  - With CORA, the Cloud becomes a value added resource; a corporation (such as a bank) becomes more secure by saving 1 or 2 small, 2 kB CORA blocs to the Cloud, while keeping the rest in their data center.

#### make hacking irrelevant

What are the chances that a hacker will guess which 2, 3, 4... 40 CORA blocs go with one another?

Option 1 - we don't require that the CORA blocs be entered in the proper order. The total number of combinations to test between 2 and 40 CORA blocs is only (and that is with the MUP - which should never happen):

That's right, **1042 - unimaginable**, and that's with **only 200 CORA blocs**.

Option 2 - we require the proper order - then the total # of permutations is **1.68 x 10^90**.

* * *

#### safe from Quantum Computers and makes hacking irrelevant

CORA hacking is irrelevant - YouTube

Tap to unmute

[CORA hacking is irrelevant](https://www.youtube.com/watch?v=Bvs1Uh1L_6s) [CORA Cyber Security Inc](https://www.youtube.com/channel/UC_5Hxu4MaVmP4B_kMf2cAyw)

### Cloud CORA

Cloud CORA, located at CloudCORA.com, is a website that will house CORA's online, cloud-based, storage solution.

How can CORA can be unbreakable when Servers can be breached, and identities stolen?

To understand why CORA is unbreakable, one must clarify (explained below) these different facets of security and how they impact regular commerce at retail outlets, and e-commerce in this global marketplace.

#### Authentication - are you who you say you are? »

#### Your Identity

You know who you are, and generally speaking, anyone who meets you face to face, may recognize you.

What about applying for credit? You provide your name, address, phone number, date of birth, and perhaps other "documents".  
Now this is where it is difficult for honest people to relate... what if someone knows your address, phone number, and your date of birth...  
they can claim to be you... and the person at the store, or bank, won't know the difference.

"Identity theft" uses information about you to trick someone else into believing they are you. Strangely enough, the creditor, bank or business still "looks to you" for the money, which translates into "hurting your credit".

This is why it is important to safeguard **your personal information**.

#### Your Online Identity

When you go to a website, there is no way to "know if it is you"... can't see you, or even take your picture.

How does the Website know if it is you? Should you be allowed to see your information? Should you be allowed to download your file(s)?

This is where **authentication** comes in to play. Authentication is more often referred to as "Sign In", or "Log In".

You provide your user name and password, and if they match up, then you are "assumed" to be "you". There is much work being done in this field of authentication, however,
you should understand that, if someone successfully pretends to be "John Doe" and gets into "a server", **then "John Doe's" data is compromised, but not the rest of **the users of this server**.

#### The Cloud - servers located online, somewhere out there »

#### Servers

There are millions of Servers that are interconnected throughout the Internet. There are more Servers located on internal Networks, that also have a connection to the Internet. Computers have more than 65000 ports, which can be thought of as "doors", since these are the ways in which information gets into and/or out of a computer.

Imagine how difficult it would be to lock, monitor and guard 65000 doors in a house, or mall. If someone Signs in as you, on a server, they violate your data. When someone breaches a server, they violate "much more than just one person's data"!

These are the types of breaches that have been gaining more and more visibility through the media, however, there are many more violations that never make it to the news.

I consider myself a creative and imaginative person, and yet, I cannot imagine how it is possible to guarantee that someone will never break into a "home" again. Nor can I imagine that someone will never break into a "server" again.

What does this mean about the safety of our data, and the confidence with which we can comfortably go online to socialize, do our banking, book our trips and hotel rooms, or purchase products?

So what is the solution?   **CORA**.

Why?   **Unbreakable**.

Authentication

Servers don't see your face. Faceless people ask for their data all the time. Data goes out to faceless people, 24-7, around the globe.

#### CORA - unbreakable data security for the global marketplace

As discussed above The Cloud - servers... one cannot expect that thieves will disappear, nor that they will never again break into a server.

If a thief does breach a server, and steal data, CORA will protect the data so that it is useless to the cyber criminal!

- Unlike traditional, offline thought:  
  - CORA doesn't build bigger, better safes.  
  - CORA doesn't use bigger and bigger Prime Numbers - hoping criminals won't have bigger and faster computers.  
  - CORA doesn't endeavor to become a regulated, governed body that is worthy of your trust (including all of its employees).  
  - It's ok if you don't want to trust goCORA.com, CloudCORA.com, and anyone else... completely - just hold onto your data Key and client Key, and optionally one of the data files.  
- CORA can be unbreakable due to its creative use of Context Ordered Rendering that places indecipherable zeros and ones into different files, that may be stored at different locations.  
- If one file, or two, or more... are stolen, they will remain useless to the cyber criminal, unless every single file, and key, is obtained.

So how could CORA be "broken"?

If an individual user elected to keep all of the files on a single computer, or USB, then should someone steal this computer or USB, they could conceivably have access to the secured data.

For corporations or institutions the only vulnerability would be having someone on the inside who has sufficient permissions to determine where each of these files are located, and then the permission to access them. With proper record keeping and best practices in place, such a criminal would be readily identified and prosecuted. Moreover, such intimate knowledge of the distributed environment should not be entrusted to a single individual.

With CORA, Cloud based data storage will become **the most secure** style of data storage. The number of files will be astronomical meaning that it becomes impossible for a cyber criminal to know where a particular CORA solution is stored in its entirety. Should a particular file be compromised, the system can quickly shut down access to other networks, server farms, or data points that may contain the remaining files.

Cloud CORA - imagine

- each node (dot) represents a server farm  
- each farm contains hundreds of servers  
- each server holds millions of data files  
- the darker the dots, the more servers

> What are the chances that someone might guess (or know) where your 2, 3, 4... or more ... data files are?

> What are the chances that someone might breach, not just one server, but multiple servers "at the same time"?
