Research
Open problems, worked in public.
Each problem carries its formal statement, everything established so far with explicit epistemic tags, and what has been ruled out. Negative results are kept, not hidden.
Hardness of the discrete logarithm
Lower bounds, factor bases, descent and transfers — why, and whether, ECDLP is hard.
- Lower bounds for ECDLP beyond the generic group modelThe scoped free-coordinate no-go result is valid, but the work did not reach the requested full endpoint because the GHS row was closed only by a degenerate genus-one specialization.2026-06-29failed
- Existence of a factor base over prime fieldsPROVED Standard-L/fixed- is impossible and square-root/online-only is nonuniformly trivial; A009 rules out translate probes, while A010 finds a succinct coordinate predicate but no efficient decoder.2026-07-17resolved
- Removing the first-fall-degree heuristicPROVED A007 gives the all-parameter upper bound, while A008 proves the matching strong obstruction: every proper core has , and an infinite family has with .2026-07-23resolved
- Classifying Weil Descent VulnerabilityOnly the scaffold-authorized Frobenius-span/genus fallback was completed for degrees 4, 6, and 8.2026-06-23partial
- A unified theory of transfersA030 makes the A029 evaluator exactly ECDLP-complete, A031 collapses same-characteristic affine endpoints, A032 isolates cross-characteristic conversion, A033--A037 close lift/rebasing/natural/symmetric/trace routes, A038--A039 close single-feature filters, A040 closes fixed-dictionary linear cancellation, A041 closes bounded-degree polynomial feature algebras, A042 closes piecewise polynomial branching, A043 reaches arbitrary rational preprocessing and orientation-free final division, A044--A045 expose logarithmic target mixing, A046--A047 decode labelled and single-coset factors, and A049 proves every exposed polynomial-total-alphabet signed factorization into any polynomial-bit finite abelian target ECDLP-complete by finite-module calibration.2026-07-24active
- The height obstruction to liftingPROVED The literal height lower bound is false, while the dependence/rank-conditioned xedni question remains open.2026-07-14partial
Assumptions & reductions
What the standard assumptions actually buy: reductions, separations, and their limits.
- Completing the Maurer reduction (CDH => DLP)Fifteen research sub-goals are closed; conditional surface-order existence is abundant, but both a uniform smooth-order finder and an explicit curve-equation seed remain open.2026-07-21partial
- Reducing or separating $q$-type assumptionsPROVED A008 replaces A006's raw label count by the maximum affine solution-space dimension of the verified source-label trace at an actual adversary-call prefix and separates every fully-black-box fixed-representation reduction with ; affine derivation DAGs and available factor-base presentations are covered regardless of label count.2026-07-25partial
- Generalizing Cheon's attackThe requested generalization and matching GGM lower bound were not obtained; only the known divisor case and its scaling were reproduced.2026-07-13partial
- Fixed-argument pairing inversionPROVED An elliptic-curve-backed RR/Shoup generic oracle separates easy -ECDLP from FAPI-1; the theorem survived a second adversarial self-verification.2026-07-07resolved
Isogenies & quantum
Endomorphism rings, class-group actions, and the quantum cost of breaking them.
- Unconditional endomorphism-ring equivalencePROVED A003 unconditionally removes D2 from the audited smooth-path proof, but D1, D3, and D4 remain; EMPIRICAL: p<=71 the local Deuring round trip and a five-size toy cost fit are validated without yielding a security-bit loss.2026-07-11partial
- The constant in the quantum attack on class group actionsFailed relative to the formal tasks: no physically calibrated universal constant or unrestricted structured-action query lower bound was obtained.2026-06-30abandoned
- Optimality of ideal-to-isogeny translationEMPIRICAL: 108 near- ideals through 28 bits LLL is exact, while exact constraints raise median norms by 222.64x/168.23x overall and by roughly 2500x in the 28-bit band.2026-07-13partial
- A decision criterion for torsion-point leakageRecorded as failure: the published-template checklist is a useful partial artifact, but the requested universal necessary-and-sufficient criterion was not proved.2026-07-03abandoned
Pairings & exTNFS
Pairing-friendly curves against exTNFS: families, cycles, and rigorous cost models.
- Optimal pairing-friendly families under exTNFSThe transparent cost model, four family generators, bounded search, three target tables, cross-family exact-norm audit, public-code bound audit, and KSS16 ceiling certificate are implemented and tested.2026-07-15complete
- Pairing-friendly curve cyclesEvery 2-cycle degree pair in {3,4,5,6,8,10,12} is globally classified; the 28-bit degree-3-through-12 census remains candidate-complete.2026-07-18partial
- Rigorous complexity for exTNFSFailed to prove an unconditional complexity theorem for exTNFS; the task was terminated at the user's request.2026-07-06abandoned
Curve generation & practice
How curves are chosen, standardized, and hashed to — rigidity in deployment.
- Koblitz's conjecture on prime curve ordersPROVED All twelve scoped algebraic, computational, audit, and literature sub-goals are complete; the CM event is reduced to an explicit simultaneous norm-prime pattern, while the unconditional fixed-curve asymptotic remains Q026.2026-07-20partial
- Small CM discriminant and ECDLP securityMarked as failed at the user's request; validated Sessions 1-3 remain preserved, while the planned Q025 experiment was not implemented.2026-07-11abandoned
- Formalizing curve-generation rigidityP5.3 and SG-01 through SG-11 are resolved; Q014 and Q015 now carry self-contained evidence, derivations, artifacts, scope boundaries, and reopening conditions.2026-07-14resolved
- Universal constant-time hash-to-curveThe toy compile-time family now has complete prime, cubic-extension, and bounded characteristic-two/three pipelines, and one Rust suite has exhaustive assembly/subgroup/timing evidence; universal coverage remains open.2026-07-20partial