Research · Hardness of the discrete logarithm

A unified theory of transfers

active24 sessionsupdated 2026-07-24Paper (PDF · 1.4 MB)

A030 makes the A029 evaluator exactly ECDLP-complete, A031 collapses same-characteristic affine endpoints, A032 isolates cross-characteristic conversion, A033--A037 close lift/rebasing/natural/symmetric/trace routes, A038--A039 close single-feature filters, A040 closes fixed-dictionary linear cancellation, A041 closes bounded-degree polynomial feature algebras, A042 closes piecewise polynomial branching, A043 reaches arbitrary rational preprocessing and orientation-free final division, A044--A045 expose logarithmic target mixing, A046--A047 decode labelled and single-coset factors, and A049 proves every exposed polynomial-total-alphabet signed factorization into any polynomial-bit finite abelian target ECDLP-complete by finite-module calibration.

Setting

Let E/FqE/\mathbb F_q be an elliptic curve and let PE(Fq)P\in E(\mathbb F_q) have prime order rr.

Task

Classify the curves for which there is a polynomial-time computable injective homomorphism from P\langle P\rangle to a group with a subexponential discrete logarithm algorithm.

  • CITED Trace-one elliptic curves over prime fields admit the anomalous-curve reduction of Semaev (1998), Satoh--Araki (1998), and Smart (1999).
  • CITED Prime-order subgroups with small embedding degree admit pairing reductions to finite-field multiplicative groups (Menezes--Okamoto--Vanstone 1993; Frey--Ruck 1994).

The research question is whether a structurally different third transfer exists, or whether a classification can rule one out in a stated class.

Deliverables

  1. A precise definition, including an explicit decision about Weil descent.
  2. End-to-end validated additive and multiplicative transfer demonstrations.
  3. A common structural description of the two known cases.
  4. A candidate-target table with a reason for every inclusion or exclusion.
  5. A restricted classification statement, with its proof or precise gaps.

Scope

All computations use toy parameters under the repository-wide 60-bit ceiling.

Q004 control results and novelty-grade resolution

  • PROVED A025 satisfies the former literal class-group existence checklist. On an infinite trace-zero j=1728j=1728 family, the degree-two pairing character maps through the conductor exact sequence into the ordinary ring class group Pic(Z+pZ[i])\operatorname{Pic}(\mathbb Z+p\mathbb Z[i]).

  • PROVED A projective pairing value 1+ti1+ti maps to the reduced class of (1+t2,2pt,p2)(1+t^2,2pt,p^2), and Gaussian ideal extension converts the target DLP back to the same finite-field torus.

  • PROVED This is a valid class-group transfer but not a structurally new mechanism: it is the known bilinear transfer in an ordinary ring-class presentation.

  • CITED A026's proposed effective conductor-kernel inverse is not new: Hühnlein--Takagi (1999) reduce the class-number-one case to finite-field DLP, and Castagnos--Laguillaumie (2009) give the effective kernel isomorphism for general conductor.

  • PROVED A027 nevertheless proves a source-side theorem for every evaluator, including direct form synthesis. In the source CM field, a target whose conductor is supported on {p,r}\{p,r\} either exposes an explicit Fr\mathbb F_r linearizer or forces trace 22 and embedding degree one.

  • PROVED A028 closes both residuals at once for every explicit imaginary-quadratic order target. The conductor exact sequence gives an exhaustive dichotomy for the order-rr image:

    1. a kernel image is exposed by the classical effective conductor inverse in a tame finite-field torus or a wild additive Fr\mathbb F_r-line;
    2. a nonzero maximal projection has a canonical virtual unit ar=(α)\mathfrak a^r=(\alpha), and a suitable split q1(modr)q\equiv1\pmod r gives the injective character [ [\mathfrak a]\longmapsto \alpha^{(q-1)/r}\bmod\mathfrak q\in\mu_r(\mathbb F_q). ]
  • PROVED Compact relative-generator tracking evaluates the maximal character in polynomial time without expanding the Θ(rlogDK)\Theta(r\log|D_K|)-bit generator.

  • CONDITIONAL: the standing ERH/GRH convention Effective Chebotarev finds a separating qq in expected polynomial time with logq=O(logr+log(logDK+2))\log q=O(\log r+\log(\log|D_K|+2)).

  • PROVED Hence the ordinary quadratic class presentation never supplies an independent third endpoint: every nonzero evaluator, including arbitrary direct form synthesis, post-composes to a finite/local residue character. This does not assert that the source evaluator cannot exist or that its resulting finite-field character is pairing-derived.

  • PROVED SG-30 is unchanged and separate. A028 starts from a supplied explicit target and does not construct a succinct prescribed-order maximal class group from arbitrary rr.

  • PROVED A029 subsequently closes the target-only SG-30 problem unconditionally. For every odd prime rr, [ \mathcal O_r=\mathbb Z+r^2\mathbb Z[i],\qquad \Delta_r=-4r^4, ] and the canonical reduced form [ [r^2,2r,r^2+1] ] has exact class order rr. Its discriminant has 2+4log2r=Θ(logr)2+4\log_2r=\Theta(\log r) bits and lies inside the SG-25 window. This target theorem remains separate from the source evaluator and is the wild additive conductor branch predicted by A028.

  • PROVED A030 sharpens that separation to a complexity equivalence. The class number r(rχ4(r))/2r(r-\chi_{-4}(r))/2 contains exactly one factor of rr, so A029's wild line is the unique Sylow rr-subgroup. A polynomial-time nonzero evaluator into the A029 target exists if and only if source ECDLP is polynomial-time solvable.

  • PROVED A031 gives a new evaluator-independent endpoint theorem. If an arbitrary source homomorphism lands in an affine algebraic group over Fpe\mathbb F_{p^e} with a faithful mm-dimensional representation and em=(logr)O(1)em=(\log r)^{O(1)}, then an order-rr image matrix either:

    1. has r=pr=p, exposes the scalar through its nilpotent part, and Hasse forces the anomalous trace-one case; or
    2. has an eigenvalue of exact order rr in degree at most emem, forcing ordr(p)em\operatorname{ord}_r(p)\le em and the MOV/Frey--Rück regime.

    This requires no rational-map hypothesis and permits disconnected and noncommutative targets.

  • PROVED Combining A028 and A031 yields the A032 trichotomy for every ordinary quadratic class evaluator: it either solves source ECDLP in polynomial time through an additive character, forces the known pairing regime through a same-characteristic multiplicative character, or produces a cross-characteristic converter [ \langle P\rangle\longrightarrow \mu_r(\mathbb F_{\ell^d}),\qquad \ell\ne p. ]

  • PROVED A033 closes the standard lift-and-specialize route to that last converter. Prime-to-pp torsion lifts uniquely through a same-prime nilpotent thickening, but after adjoining an order-rr second fiber the homomorphic sections are indexed by Hom(C,T)Fr\operatorname{Hom}(C,T)\simeq\mathbb F_r; choosing a nonzero section is exactly choosing the missing converter. A canonical/Deuring CM torsion bridge or a torsion bridge on a rational lifted curve requires an explicit number field of degree Ω(r)=2Ω(logr)\Omega(r)=2^{\Omega(\log r)}, by the checked CM and rational torsion-degree theorems.

  • PROVED A034 closes the most direct residue-level reuse of finite-field labels. If HFp×H\subset\mathbb F_p^\times has prime order rr, the least positive representatives of its elements cannot retain a nonzero labelled multiplication table modulo any distinct prime \ell: their positive sum would be divisible by pp\ell while being strictly below rp<prp<p\ell. A target-field multiplicative character is also incompatible with the Ward EDS recurrence. Thus neither a perfectly periodic EDS label nor a genuine same-characteristic character can be turned into the missing converter by canonical scalar reduction.

  • PROVED The coefficientwise extension-field version is also sharply constrained. Reinterpreting the same canonical Fpe\mathbb F_{p^e}-coefficient vectors in characteristic \ell can be nonzero only when <r\ell<r and ordr()e\operatorname{ord}_r(\ell)\le e. This follows by applying the same sum argument to one positive coordinate.

  • PROVED A035 closes the entire base-change-natural finite/local algebraic route. Over Z[1/r]\mathbb Z[1/r], the nonzero character functor Crμr\underline C_r\to\mu_r is the primitive-root torsor [ \operatorname{Spec}\mathbb Z[1/r,T]/(\Phi_r(T)). ] It is finite etale of degree r1r-1, has no integral section, and every finite locally free parameter algebra that trivializes it has rank at least r1=2Ω(logr)r-1=2^{\Omega(\log r)}. Local roots in characteristics pp and \ell merely define the exponent-preserving relation ζpxζx\zeta_p^x\mapsto\zeta_\ell^x; they do not evaluate it from source coordinates.

  • PROVED A036 closes every basis-free or insufficiently oriented bit-level implementation, without assuming that the evaluator is algebraic or rational. If DD is its public target-orientation data in Fd\mathbb F_{\ell^d}, then a nonzero DD-canonical character requires [ \operatorname{ord}r(\ell) \mid|\operatorname{Gal}(\mathbb F{\ell^d}/\mathbb F_\ell)\cdot D|. ] In particular, no F\mathbb F_\ell-rational presentation can work when <r\ell<r. Frobenius-symmetric multiplicative postprocessing also collapses: the norm of the rr-torsion to F\mathbb F_\ell is one whenever ordr()>1\operatorname{ord}_r(\ell)>1.

  • PROVED A037 shows that Frobenius trace does not compress this orientation into a second succinct global bridge. If f=ordr()f=\operatorname{ord}_r(\ell), the corresponding prime Gaussian period has characteristic-zero degree [ m=\frac{r-1}{f},\qquad fm=r-1. ] Hence a polynomial-degree local root field and a polynomial-degree global period field cannot coexist.

  • PROVED A038 closes a fully oriented translation-filter mechanism. For any spectrally full scalar source feature uu, a target-field-linear combination of translates u(Q+kP)u(Q+kP) equal to a nonzero character must use all rr shifts. Even with coefficients in the full oriented target field, one nonzero base-field target coordinate needs at least [ \left\lceil \frac{r-\operatorname{ord}_r(\ell)} {\operatorname{ord}_r(\ell)} \right\rceil+1 ] shifts. This is exponential for every polynomial-degree SG-39 target.

  • PROVED A039 strengthens A038 to a source feature with zz Fourier zeros. If the target has Fourier support hh and the filter uses tt translated probes, then t(z+h)rt(z+h)\ge r. A polynomial-tap character filter therefore requires exponentially many spectral zeros.

  • PROVED A039 also isolates those zeros arithmetically for every nonconstant integer-lifted feature. They occur at nonzero frequencies in characteristic r\ell\ne r only when \ell divides the explicit nonzero resultant Res(Φr,jwjXj)\operatorname{Res}(\Phi_r,\sum_jw_jX^j); the zero-frequency exception is jwj\ell\mid\sum_jw_j.

  • PROVED A040 permits several fixed integer-valued feature channels with arbitrary linear cancellation. In characteristic zero, fewer than r1r-1 rational probe vectors cannot span a primitive character. For a fixed finite dictionary and tap budget tr2t\le r-2, modular failure can occur only at prime divisors of one explicit nonzero product ΔV,t\Delta_{\mathcal V,t} of cyclotomic obstruction resultants.

  • PROVED A041 permits arbitrary polynomial combinations of fixed integer features. If the total-degree-DD evaluation space contains a primitive character, its rational Hilbert rank is the full rr, so [ \binom{m+D}{m}\ge r ] and an explicitly expanded polynomial needs at least r1r-1 monomials. Whenever that evaluation space has smaller rational rank, modular containment forces \ell to divide one explicit nonzero sum-zero annihilator resultant. The unrestricted polynomial algebra contains a character exactly when the joint feature tuple is injective.

  • PROVED A042 permits arbitrary branch partitions with polynomial leaves. Galois saturation and Chebotarev's prime Fourier-minor theorem force every characteristic-zero leaf evaluation code to be full on its branch, hence [ B\binom{m+D}{m}\ge r. ] For integral features and M=(m+Dm)<rM=\binom{m+D}{m}<r, the product of the nonzero annihilator resultants over all (M+1)(M+1)-point subsets gives one explicit ΔU,D\Delta_{U,D}. Outside its prime divisors, the same linear-BB bound holds uniformly over every branch partition and arbitrary extension-field leaf coefficients.

  • PROVED A043 removes any restriction on how the rational source features before a circuit cut are computed. If their interface has dimension ww, a target-oriented Schur suffix of multiplication degree DD has dimension at most (w+D1w1)\binom{w+D-1}{w-1}. For one final quotient p/q=cap/q=c_a, let ee be the projective Galois-orbit size of the denominator evaluation shape. Every leaf code then has dimension at least [ \min\left{|S|,1+\frac{r-1}{e}\right}. ] Hence orientation-free denominators (e=1e=1) do not help, while a uniform BB-leaf model satisfies Mmax{B,e}r1M\max\{B,e\}\ge r-1. Fixed integral denominators also have a partition-uniform weighted subset-resultant obstruction.

  • PROVED A044 answers A043's immediate rank--rank question negatively and sharply in the pure-root subclass. Writing j=tk(j)+a(j)j=tk(j)+a(j), the maximally oriented denominator qj=ζra(j)q_j=\zeta_r^{-a(j)} and numerator pj=ζrtk(j)p_j=\zeta_r^{tk(j)} satisfy pj/qj=ζrjp_j/q_j=\zeta_r^j inside a common rational code of exact dimension [ t+\left\lceil\frac rt\right\rceil-1. ] Taking t=rt=\lceil\sqrt r\rceil gives O(r)O(\sqrt r), so no linear simultaneous-orbit-rank theorem can close target-mixed division. Conversely every pure cyclotomic-monomial pair on ss points has common-envelope dimension MM satisfying s(M+1)2/4s\le\lfloor(M+1)^2/4\rfloor. This is a sharp algebraic escape, not an evaluator: computing its mixed-radix labels from jPjP still requires the missing scalar information.

  • PROVED A045 iterates this escape and proves an exact logarithmic compression theorem. If j=i2iai(j)j=\sum_i2^ia_i(j), then [ f_i(j)=\zeta_r^{2^ia_i(j)},\qquad \prod_i f_i(j)=\zeta_r^j. ] Every fif_i has rational Galois rank two and maximal projective orbit, while all factors lie in one rational code of exact dimension 1+log2r1+\lceil\log_2r\rceil. More generally a mixed-radix family has exact common dimension 1+i(di1)1+\sum_i(d_i-1). This proves that final algebraic rank and factor depth alone cannot close SG-39.

  • PROVED A045 also closes this explicit compression as a source construction: evaluating its exposed factors from jPjP is polynomial-time equivalent to ECDLP, since each factor is either 11 or the public value ζr2i\zeta_r^{2^i} and therefore reveals one scalar bit. This is representation-independent for the named factor registers, but it is not a lower bound for an arbitrary circuit that never exposes them.

  • PROVED A046 removes the digit-specific hypothesis. Suppose arbitrary coordinate-aware subroutines expose gi(jP){ζu:uUi}g_i(jP)\in\{\zeta^u:u\in U_i\} for public exponent alphabets and [ \prod_i g_i(jP)^{\varepsilon_i}=\zeta^{aj+b}. ] Public table lookup recovers every selected exponent and hence j=a1(iεiuib)j=a^{-1}(\sum_i\varepsilon_i u_i-b) in O(iUi)O(\sum_i|U_i|) target operations. Thus every exposed polynomial-total-size public cyclotomic factorization is ECDLP-complete, with no rationality, degree, branch, denominator, source-coordinate, or characteristic assumption on the factor evaluators.

  • PROVED A047 also removes the public alphabet and exponent-label hypotheses. If each exposed factor image ViV_i has polynomial total size and lies in one unknown coset γiμr\gamma_i\mu_r, encode a factor tuple by its signed symbol-incidence row z(j)z(j). The product identity supplies an unknown linear functional [ z(j)\cdot\theta=j. ] For mm random known multiples TsPT_sP, a distribution-free rank-increment lemma gives [ \Pr!\left[z(J)\notin \operatorname{span}{z(T_1),\ldots,z(T_m)}\right] \le\frac{A+1}{m+1}. ] Whenever the challenge row is in the span, applying the same linear combination to the known TsT_s recovers JJ, without target DLP, alphabet enumeration, exponent labels, or coset representatives. Random self-reduction therefore makes every polynomial-AA evaluator of this type a randomized polynomial-time source ECDLP solver.

  • PROVED A049 removes all factor-coset and cyclic-target hypotheses. Let TT be any finite abelian target with public polynomial-bit annihilator NN, and encode every distinct exposed factor value by a signed one-hot row over R=Z/NZR=\mathbb Z/N\mathbb Z. A module-span relation among calibration and challenge rows maps formally to the same relation among haTs+bh^{aT_s+b} and haJ+bh^{aJ+b}, hence recovers JmodrJ\bmod r. For total alphabet AA, [ \Pr[\text{decoding failure}] \le \frac{(A+1)\lceil\log_2N\rceil}{m+1}. ] Thus every exposed polynomial-total-alphabet signed factorization into a polynomial-bit finite abelian target is ECDLP-complete, even when one factor meets many μr\mu_r-cosets or r2Nr^2\mid N. A048's public direct-summand projection is a strict intermediate case; A049 needs no projection.

  • [OPEN] The last converter is the genuine remaining endpoint problem. Generic and rational models are excluded by A007--A013 and standard algebraic lifts by A033; A034 also excludes EDS-preserving and scalar canonical-residue rebasing; A035 excludes all natural common-base finite/local character bridges and dense cyclotomic parameters; A036 additionally proves that full Frobenius orientation is necessary; A037 rules out hiding it through a Gaussian-period trace bridge; A038--A039 exclude all single-feature linear translation filters except the explicitly isolated large-defect resultant-prime cases; A040 also closes every fixed finite multi-feature linear dictionary outside its explicit exceptional primes; A041 closes every fixed bounded-degree or sparse polynomial feature algebra outside its own explicit exceptional primes; A042 closes all piecewise polynomial partitions there as well, with a linear rather than quadratic branch tradeoff; A043 additionally closes arbitrary rational/Boolean preprocessing followed by a bounded Schur suffix and every projectively orientation-free final denominator; A044 proves that a fully target-mixed pure-root denominator has a square-root algebraic escape; A045 iterates it to logarithmic dimension; A046--A047 decode labelled and unknown-single-coset alphabets; and A049 closes every exposed polynomial-total-alphabet signed factorization into any polynomial-bit finite abelian target. No unconditional gate-count lower bound covers every fully oriented exceptional-prime, adaptive, superpolynomial-alphabet, final-only target-mixed or nonseparable nested-division, or extension-coordinate Boolean/bit-mixing program, and no such converter is constructed here. P1.5 is therefore reopened at SG-39 rather than being called unrestrictedly complete.

State in five lines

SG-01--SG-38 are complete at their stated scopes; SG-39 is open. A028 removes the ordinary quadratic class layer, and A029 closes SG-30. A030 proves that evaluation into A029's unique rr-line is exactly polynomial-time ECDLP. A031 proves, for arbitrary evaluators, that every polynomial-dimensional same-characteristic affine endpoint is anomalous or MOV/Frey--Rück. A032 leaves one honest residual: a coordinate-aware cross-characteristic converter Pμr(Fd)\langle P\rangle\to\mu_r(\mathbb F_{\ell^d}), p\ell\ne p. A033 excludes canonical/Hensel/CRT/dense-global torsion lifting as a shortcut, but not a direct bit-level converter. A034 additionally excludes EDS-preserving specialization and canonical scalar rebasing of every prime-field character. A035 closes every base-change-natural finite/local character bridge and every dense finite locally free cyclotomic parameter of polynomial rank. A036 proves that even an arbitrary Boolean/bit evaluator must be supplied target orientation data whose Frobenius orbit is divisible by ordr()\operatorname{ord}_r(\ell); basis-free and symmetric implementations collapse. A037 shows that Frobenius-trace/Gaussian-period compression merely exchanges local degree ff for global degree (r1)/f(r-1)/f. A038 keeps the orientation and proves the first exponential lower bound there: a spectrally full single feature filtered through translated probes needs all rr target-field coefficients, and even one base-field coordinate needs at least (rf)/f+1\lceil(r-f)/f\rceil+1 probes. A039 removes the full-spectrum assumption: tt taps, zz source spectral zeros, and target support hh satisfy t(z+h)rt(z+h)\ge r. A nonconstant integer-lifted feature has holes only at prime divisors of one explicit nonzero cyclotomic resultant. A040 closes arbitrary linear cancellation among a fixed finite integer-valued feature dictionary outside an explicit finite resultant-prime set; its order-1111 fixture proves that the exceptional-prime qualifier is essential. Only an exceptional/adaptive feature choice or a nonlinear converter remained. A041 now closes all bounded-degree or explicitly sparse polynomial combinations generically: their unital evaluation code must have full rank rr, while lower rank can occur only at divisors of another explicit resultant. A042 also closes arbitrary polynomial branch partitions generically and improves the scoped branch tradeoff to B(m+Dm)rB\binom{m+D}{m}\ge r, uniformly over all partitions outside one subset-resultant prime set. Only exceptional/adaptive features, succinct factored arithmetic, divisions, or genuinely encoding-dependent Boolean/carry computation remain.

SG-39 lift barrier

A033 proves three exact statements.

  1. For rpr\ne p, reduction through a nilpotent same-prime thickening is an isomorphism on rr-torsion. Every source point has a unique torsion lift, and uniqueness makes the lift homomorphic.
  2. If a useful order-rr second fiber TT is attached, the homomorphic sections of C×TCC\times T\to C are [ s_\chi(Q)=(Q,\chi(Q)), \qquad\chi\in\operatorname{Hom}(C,T)\simeq\mathbb F_r. ] A nonzero section is exactly the missing cross-characteristic converter. The shears fixing the source projection act simply transitively, so source reduction data does not canonically distinguish one.
  3. A dense explicit common torsion point over a number field has exponential degree in the standard global settings. A CM point of prime order rr has degree at least (r1)/3(r-1)/3 for all sufficiently large rr, and a point of order rr on a rational elliptic curve has degree at least (r1)/2(r-1)/2 for r11r\ge11, r{13,37}r\notin\{13,37\}.

This closes the standard canonical, Deuring, local Hensel, CRT, and dense global torsion bridge templates. Silverman's lifting survey and Huang--Raskind's signature equivalence are explicit prior art for the larger lifting program; call A033 a repository-original synthesis, not a discovery that lifting in general has roadblocks.

SG-39 residue and EDS barrier

A034 proves two further exact exclusions.

  1. Let H=aFp×H=\langle a\rangle\subset\mathbb F_p^\times have prime order rr, and let zj{1,,p1}z_j\in\{1,\ldots,p-1\} represent aja^j. The labelled map ajzjmoda^j\mapsto z_j\bmod\ell cannot be a nonzero homomorphism for a distinct prime \ell. If it were, r1r\mid\ell-1, while [ p\ell\mid\sum_jz_j,\qquad 0<\sum_jz_j<rp<p\ell. ] The same argument covers scalar outputs embedded in an extension field. Applied to each coefficient of a canonical extension-field encoding, it shows that a nonzero coordinatewise rebase must satisfy <r\ell<r and ordr()\operatorname{ord}_r(\ell) no larger than the coordinate dimension.
  2. A target-field multiplicative character cannot satisfy the Ward EDS recurrence. Substituting Wj=ujW_j=u^j at (m,n)=(2,3)(m,n)=(2,3) makes the left side u4u^4 and the right side zero.

Lauter--Stange's point-computable perfectly periodic EDS term is therefore a label, not a transfer. Shipsey--Swart's genuine division-polynomial homomorphism is same-characteristic and pairing/MOV-derived. A034's exact defect-gcd criterion remains a useful falsifier for arbitrary scalar integer labels, but it is not a lower bound for extension-coordinate programs.

SG-39 cyclotomic character-torsor barrier

A035 proves the complete natural finite/local algebraic statement.

  1. Over R=Z[1/r]R=\mathbb Z[1/r], the fiberwise nonzero homomorphisms Crμr\underline C_r\to\mu_r are represented by [ X_r=\operatorname{Spec}R[T]/(\Phi_r(T)). ] This is a finite etale torsor under (Z/rZ)×(\mathbb Z/r\mathbb Z)^\times, of degree r1r-1.
  2. The torsor has no RR-point. Hence Yoneda excludes every parameter-free choice of nonzero character compatible with arbitrary base change.
  3. If a nonzero finite locally free parameter algebra A/RA/R trivializes the torsor, then Q(ζr)ARQ\mathbb Q(\zeta_r)\hookrightarrow A\otimes_R\mathbb Q, so rankRAr1=2Ω(logr)\operatorname{rank}_R A\ge r-1=2^{\Omega(\log r)}.
  4. Over Fq\mathbb F_q, local roots appear in degree ordr(q)\operatorname{ord}_r(q). Choosing roots in the pp- and \ell-fibers only defines ζpxζx\zeta_p^x\mapsto\zeta_\ell^x; evaluating that map from a concrete source encoding is SG-39 itself.

Milne's diagonalizable-group equivalence and cyclotomic facts are classical, and Ganz's standard/logarithmic finite-field representation work is the closest checked complexity predecessor. Call A035 a repository-original SG-39 synthesis and naturality no-go, not a discovery of those ingredients. The dense qualifier is essential: a sparse algebraic circuit may name Φr\Phi_r succinctly, and an arbitrary Boolean circuit need not be natural under base change.

SG-39 Frobenius-orientation barrier

A036 removes algebraicity, rationality, and circuit-shape assumptions from the remaining symmetry statement. Let [ K=\mathbb F_{\ell^d},\qquad \Gamma=\operatorname{Gal}(K/\mathbb F_\ell), ] let DD contain every public target-orientation datum, and let ΓD\Gamma_D be its stabilizer. A map is DD-canonical when every automorphism fixing DD fixes all outputs.

If a DD-canonical map Cμr(K)C\to\mu_r(K) is a nonzero homomorphism, then [ \operatorname{ord}_r(\ell)\mid[\Gamma:\Gamma_D] =|\Gamma\cdot D|. ] Indeed, the image of a source generator has exact order rr, lies in the fixed field KΓDK^{\Gamma_D}, and therefore forces rs1r\mid\ell^s-1, where s=[Γ:ΓD]s=[\Gamma:\Gamma_D]. This proof applies to arbitrary bit programs that are invariant under re-presentations fixing their declared data.

When f=ordr()>1f=\operatorname{ord}_r(\ell)>1, the norm of every ζμr(Ff)\zeta\in\mu_r(\mathbb F_{\ell^f}) to F\mathbb F_\ell is one. Consequently norm and every invariant algebraic character of the restriction-of-scalars torus are trivial on the rr-torsion. Symmetric conjugate aggregation cannot remove the target orientation.

The bound is sharp as a symmetry theorem. Supplying a primitive root ζ\zeta gives public data with orbit exactly ff, and xPζxxP\mapsto\zeta^x is then mathematically canonical. A036 does not evaluate that character. Lange--Winterhof's Boolean interpolation results concern the inverse finite-field logarithm, Satoh's dense interpolation concerns the reverse same-characteristic Verheul map, and Maurer--Raub assume a field homomorphism. The remaining case is exactly a fully oriented polynomial-basis or equivalent coordinate circuit.

SG-39 Gauss-period degree-product barrier

A037 tests the last natural way to remove the orientation required by A036: take the Frobenius trace of a primitive root. Let [ H=\langle\ell\rangle \le(\mathbb Z/r\mathbb Z)^\times,\qquad f=|H|=\operatorname{ord}_r(\ell), ] and put ηH=hHζrh\eta_H=\sum_{h\in H}\zeta_r^h.

Distinct cosets aHaH give distinct complex periods. Indeed, equality of two sums gives a degree-at-most-r1r-1 polynomial relation at ζr\zeta_r; divisibility by Φr=1+X++Xr1\Phi_r=1+X+\cdots+X^{r-1} and the zero constant coefficient force the two exponent sets to agree. Thus [ [\mathbb Q(\eta_H):\mathbb Q] =\frac{r-1}{f},\qquad f[\mathbb Q(\eta_H):\mathbb Q]=r-1. ]

The local extension containing μr\mu_r has degree at least ff. Hence a polynomial-degree local root field forces exponential global period degree, and polynomial global period degree forces exponential local degree. Feisel--von zur Gathen--Shokrollahi and Bernstein supply the classical finite-field and cyclotomic Gauss-period context. A037's repository-original content is the exact SG-39 product and boundary, not the period theory.

This closes trace/Gaussian-period orientation compression but not a circuit that keeps the primitive root fully oriented throughout.

SG-39 translation-filter spectral barrier

A038 keeps a primitive target root ζμr(Ff)\zeta\in\mu_r(\mathbb F_{\ell^f}) fully public, with f=ordr()f=\operatorname{ord}_r(\ell), and tests the direct translated-feature mechanism [ \sum_k A_k u(Q+kP). ] For a source feature u:Z/rZFu:\mathbb Z/r\mathbb Z\to\mathbb F_\ell, write [ \widehat u(s)=\sum_j u(j)\zeta^{-sj}. ] If every u^(s)\widehat u(s) is nonzero, Fourier deconvolution gives two exact lower bounds.

  1. To produce ζaj\zeta^{aj} with coefficients in the full target field, the unique filter is [ A_k=\widehat u(a)^{-1}\zeta^{-ak}. ] Every one of its rr coefficients is nonzero.
  2. To produce one nonzero base-field coordinate, even with coefficients in the full target field, Tr(bζaj)\operatorname{Tr}(b\zeta^{aj}), the filter spectrum is supported on the Frobenius orbit Oa={a,a,,af1}\mathcal O_a=\{a,a\ell,\ldots,a\ell^{f-1}\}. If g(Oa)g(\mathcal O_a) is its longest missing cyclic run, the consecutive-zero Vandermonde argument gives [ |\operatorname{supp} A| \ge g(\mathcal O_a)+1 \ge \left\lceil\frac{r-f}{f}\right\rceil+1. ]

Thus the mechanism is exponential whenever the target degree is polynomial in logr\log r. The identity indicator is always spectrally full, and the order-1111 toy subgroup on y2=x3+x/F43y^2=x^3+x/\mathbb F_{43} has spectrally full reduced xx- and yy-coordinate features.

Kumallagov--Sizikov--Zarubin's 2026 Fourier-descent theorem is the closest checked prior art: it characterizes Frobenius-consistent finite-field spectra and optimal coordinate storage. Irreducible cyclic codes and the BCH consecutive-zero bound are also classical. The repository-original claim is only the SG-39 reduction from a translated elliptic-source feature evaluator to this filter and the resulting exponential probe bound.

A038 does not cover several features combined by multiplication or branching, nor a deliberately spectrally sparse tailored feature. Those are now the exact surviving fully oriented cases.

SG-39 spectral-defect and resultant barrier

A039 quantifies the sparse-feature escape left by A038. For one source feature uu, let zz be the number of cyclic Fourier zeros. If a target function has Fourier-support size hh and a translated filter has tt nonzero taps, then [ t(z+h)\ge r. ] The proof is deconvolution plus the consecutive-zero Vandermonde lemma, so it is valid in every characteristic r\ell\ne r. For a character, h=1h=1; for one trace coordinate, h=f=ordr()h=f=\operatorname{ord}_r(\ell). Hence polynomially many taps require exponentially many source spectral zeros.

For a nonconstant lifted integer feature [ w=(w_0,\ldots,w_{r-1}),\qquad U(X)=\sum_jw_jX^j, ] A039 proves [ R_w=\operatorname{Res}(\Phi_r,U)\ne0. ] The reduction modulo r\ell\ne r has a nonzero-frequency Fourier zero exactly when Rw\ell\mid R_w; its zero frequency vanishes exactly when jwj\ell\mid\sum_jw_j. Thus canonical lifted features are full outside a finite explicit exceptional-prime set. This does not exclude a converter that deliberately selects a divisor and obtains exponentially many holes.

Tao's sharper support-sum uncertainty is over C\mathbb C. Emmrich--Kunis explicitly record that an all-minors Fourier assertion can fail in small finite characteristic even under primitive order. Do not import Tao's bound into SG-39 without the required finite-field hypotheses. A039 uses only the universally valid product/consecutive-zero statement.

At A039 alone, the exact remaining cases were exceptional large-defect primes, several feature channels with spectral cancellation, and nonlinear or branching circuits. A040 closes the generic part of the second case.

SG-39 multi-feature Galois-span barrier

A040 removes the generic multi-feature linear-cancellation escape. Let [ c_a=(\zeta^{aj})_{j\in\mathbb Z/r\mathbb Z}. ] If cac_a lies in the Q(ζ)\mathbb Q(\zeta)-span of rational probe vectors, then their rational span has dimension at least r1r-1. The reason is Galois stability: the span contains all r1r-1 primitive Fourier vectors, which are linearly independent.

For any fixed smaller integral probe span of rational rank d<r1d<r-1, signed maximal minors produce a primitive integral annihilator λ\lambda supported on at most d+1d+1 coordinates. Its cyclotomic resultant [ R_\lambda =\operatorname{Res}!\left( \Phi_r,\sum_j\lambda_jX^j \right) \ne0 ] has the following exact consequence: reduction modulo a target prime r\ell\ne r can span a primitive character only if Rλ\ell\mid R_\lambda. Taking the finite product over all subsets of size at most tr2t\le r-2 proves that every fixed finite integer-valued probe dictionary needs at least r1r-1 probes outside an explicit finite set of target characteristics, even with coefficients in an arbitrary extension field and arbitrary cross-channel cancellation.

The exception is real. For the order-1111 subgroup on y2=x3+x/F43y^2=x^3+x/\mathbb F_{43}, eight translated x/yx/y probes span the primitive character modulo 2323. Their rational rank is eight, and the corresponding nonzero 317-bit resultant is divisible by 2323. Thus A040 is a generic-characteristic theorem, not a characteristic-uniform r1r-1 bound.

Serre supplies the classical rational group-algebra constituent behind the Galois argument. The repository-original content is the SG-39 fixed multi-probe/resultant synthesis. Adaptive exceptional-prime dictionaries, nonlinear multiplication, branching, and raw Boolean circuits remained at the A040 stage; A041 closes the bounded-degree and sparse polynomial part.

SG-39 polynomial feature-algebra barrier

A041 passes from a list of linear probes to every monomial in fixed integer features U=(u1,,um)U=(u_1,\ldots,u_m). Let ED(U)\mathcal E_D(U) be the rational evaluation space of all monomials of total degree at most DD, and let HU(D)H_U(D) be its dimension. The space is unital. If it contains one primitive character after extending scalars to Q(ζr)\mathbb Q(\zeta_r), Galois stability supplies the other r2r-2 nontrivial characters, while the constant vector supplies the last Fourier-basis vector. Hence [ H_U(D)=r,\qquad \binom{m+D}{m}\ge r. ] For two raw integer features this gives [ D\ge \left\lceil\frac{\sqrt{8r+1}-3}{2}\right\rceil, ] and an explicitly expanded polynomial needs at least r1r-1 monomials.

If HU(D)<rH_U(D)<r, an integral annihilator of ED(U)\mathcal E_D(U) has coordinate sum zero, so it is nonconstant and has a nonzero cyclotomic resultant RU,DR_{U,D}. A degree-DD primitive character after reduction modulo r\ell\ne r forces RU,D\ell\mid R_{U,D}. This is the exact generic-characteristic nonlinear obstruction.

The full pointwise polynomial algebra has dimension equal to the number of distinct joint feature tuples. It contains a primitive character if and only if the tuple is injective. Dense interpolation from raw unique coordinates therefore always exists; succinctness is the issue.

The order-1111 lifted x/yx/y fixture has Hilbert profile (1,3,6,10,11)(1,3,6,10,11). Its degree-three rank-ten space has a sum-zero annihilator with a nonzero 204-bit resultant divisible by 2323; degree three contains the character modulo 2323, while nonexceptional 6767 first succeeds in degree four.

Lopez--Soprunov--Villarreal supply the standard evaluation-code and affine Hilbert-function framework. A041's repository claim is only the forward-character Galois saturation, exceptional-resultant, and SG-39 degree/sparsity synthesis. It is not a gate-count lower bound: a factored polynomial-size circuit can hide exponential degree and support.

SG-39 piecewise polynomial character barrier

A042 adds arbitrary branch partitions. On a branch SS, the rational monomial evaluation space containing one primitive character restriction is Galois-stable, so it contains all nontrivial Fourier columns restricted to SS. Chebotarev's prime-order Fourier-minor theorem makes those columns span Q(ζ)S\mathbb Q(\zeta)^S for every proper branch; the constant monomial completes the full branch. Therefore every leaf has full restricted Hilbert rank and [ B\binom{m+D}{m}\ge r. ] For B2B\ge2, explicitly stored monomial counts across the leaves sum to at least rr. A binary predicate tree of depth bb with division-free multiplicative-depth-δ\delta leaves satisfies [ 2^b\binom{m+2^\delta}{m}\ge r, \qquad b+m\delta\ge\log_2r-m. ]

The finite-characteristic theorem is uniform over all partitions. Put M=(m+Dm)<rM=\binom{m+D}{m}<r. For every (M+1)(M+1)-point subset TT, take the nonzero resultant of a sum-zero integral annihilator, and multiply them to obtain ΔU,D0\Delta_{U,D}\ne0. If rΔU,D\ell\nmid r\Delta_{U,D}, no degree-DD leaf can match the character on more than MM points, for any branch partition or extension-field coefficients.

The order-1111 x/yx/y fixture has agreement profile (1,3,6,10)(1,3,6,10) at =331\ell=331, exactly the degree-zero-through-three monomial counts. At exceptional =23\ell=23 it has (1,4,8,11)(1,4,8,11); the degree-one four-point branch has a nonzero 74-bit resultant divisible by 2323 but not 331331.

This is a genuine B2B^2-to-BB improvement only in the forward-character fixed-feature polynomial model. It does not improve the general affine piecewise rational-map theorem from A023. Tao supplies the characteristic-zero minor theorem, and Emmrich--Kunis justify the modular resultant replacement.

SG-39 Galois--Schur cut and projective-denominator barrier

A043 cuts after arbitrary target-independent rational preprocessing. Let the unital interface code have width ww. Its DD-th componentwise Schur power has dimension at most [ \binom{w+D-1}{w-1}. ] If a target-oriented suffix produces a primitive character on a branch SS, Galois saturation and Chebotarev force that Schur power to have dimension S|S|. The interface functions themselves may be outputs of factored arithmetic, divisions, comparisons, bit extraction, carries, or Boolean code.

A043 also permits one final quotient p/q=cap/q=c_a. Let e(q)e(q) be the size of the projective cyclotomic Galois orbit of the denominator evaluation shape. Any rational code containing p,qp,q has dimension at least [ \min\left{|S|,1+\frac{r-1}{e(q)}\right}. ] This is invariant under common target-scalar rescaling. In particular, orientation-free denominators have e(q)=1e(q)=1 and give no escape. For uniform Schur capacity MM, BB leaves, and denominator orbit at most ee, [ M\max{B,e}\ge r-1; ] when e=1e=1, BMrBM\ge r.

For a fixed full-support integral denominator, weighted subset annihilators give a nonzero product of cyclotomic resultants, so the branch theorem is uniform over all partitions outside explicit target primes. On the order-1111 degree-one x/yx/y fixture with q=1+xq=1+x, maximum agreement is three modulo 353353 but five modulo the exceptional prime 2323. The five-point witness has a nonzero 91-bit weighted resultant divisible by 2323 but not 353353.

Randriambololona supplies the standard Schur-power formalism. The repository-original claim is the exact Galois--Schur cut, projective denominator-orbit bound, and weighted resultant combination. This is not a general gate-count theorem. A044 below answers its simultaneous-rank question with a low-rank counterexample; nested target-dependent division and unrestricted Boolean/carry computation remain open.

SG-39 mixed-radix denominator escape

A044 proves that the hoped-for linear simultaneous-rank theorem is false. For j=tk(j)+a(j)j=tk(j)+a(j), set [ q_j=\zeta_r^{-a(j)},\qquad p_j=\zeta_r^{tk(j)}. ] Then pj/qj=ζrjp_j/q_j=\zeta_r^j, the denominator has maximal projective Galois orbit r1r-1, and the exact ranks are [ \rho(q)=t,\qquad \rho(p)=\left\lceil\frac rt\right\rceil,\qquad \dim A_{\min} =t+\left\lceil\frac rt\right\rceil-1. ] Balanced tt gives common dimension O(r)O(\sqrt r).

For any pure-root pair [ q_j=\zeta_r^{u_j},\qquad p_j=\zeta_r^{v_j},\qquad v_j-u_j=aj, ] the exponent pairs form the edges of a simple bipartite graph. Its vertex-indicator code is the minimal common rational envelope. If that code has dimension MM on ss points, then [ s\le\left\lfloor\frac{(M+1)^2}{4}\right\rfloor. ] Thus the square-root scale is sharp for cyclotomic monomial denominators. Banakh--Gavrylkiv supply the closest difference-basis prior art; the exact denominator-code translation is the repository synthesis.

This is not a positive evaluator. The construction explicitly uses a(j)=jmodta(j)=j\bmod t and k(j)=j/tk(j)=\lfloor j/t\rfloor. The next problem is a computational lower bound for producing those labels from an encoded source point, or a genuinely coordinate-computable replacement. A purely algebraic rank argument cannot finish SG-39.

SG-39 binary character factorization

A045 iterates the A044 split. For mixed-radix digits [ j=\sum_iR_ia_i(j),\qquad f_i(j)=\zeta_r^{R_ia_i(j)}, ] the factors multiply to ζrj\zeta_r^j. If did_i digit values occur, their individual ranks and exact common rational-envelope dimension are [ \rho(f_i)=d_i,\qquad \dim A_{\min}=1+\sum_i(d_i-1). ] Every nonconstant factor has maximal projective orbit. The proof identifies the common code with the digit-partition indicator span and shows that its only dependencies are the common all-ones sums.

For binary digits, n=log2rn=\lceil\log_2r\rceil rank-two factors lie in exact common dimension n+1n+1, have balanced target product depth log2n\lceil\log_2n\rceil, and multiply to the full character. This is a logarithmic, not merely square-root, algebraic escape.

It is also exactly source-complete. Each named factor is either 11 or ζr2i\zeta_r^{2^i}; comparing with those two public values recovers the ii-th bit of jj. Hence evaluating all exposed factors from jPjP is polynomial-time equivalent to ECDLP, independently of the concrete source representation. De Bruijn supplies the classical mixed-radix decomposition; the exact cyclotomic code and source-completeness synthesis is the repository claim. Do not seek another final rank invariant: the remaining case must hide the digit tuple, make it nondecodable, or compute the character directly.

SG-39 public-exponent factor decoder

A046 removes the digit-specific decoding assumption. Suppose arbitrary coordinate-aware subroutines expose [ g_i(jP)\in{\zeta^u:u\in U_i},\qquad \prod_i g_i(jP)^{\varepsilon_i}=\zeta^{aj+b}, ] for public exponent alphabets UiU_i. Table lookup gives the unique selected exponents uiu_i, and then [ j=a^{-1}\left(\sum_i\varepsilon_i u_i-b\right)\pmod r. ] The reduction costs O(iUi)O(\sum_i|U_i|) target operations and assumes nothing about how the factor subroutines use coordinates, branching, exceptional primes, denominators, or Boolean/carry code.

Thus every exposed polynomial-total-size public cyclotomic factorization is ECDLP-complete. A044's balanced two-factor alphabet has square-root size, whereas A045's binary total alphabet has size 2log2r2\lceil\log_2r\rceil. The next mechanism must use a superpolynomial or unlabelled alphabet, leave public cyclotomic torsors, or avoid exposing factor registers entirely.

SG-39 calibration-span decoder

A047 removes the public alphabets, exponent labels, and coset representatives. Suppose the same arbitrary coordinate-aware subroutines expose finite images [ V_i=g_i(C)\subseteq\gamma_i\langle h\rangle,\qquad \prod_i g_i(jP)^{\varepsilon_i}=h^j, ] and put A=iViA=\sum_i|V_i|. Give every observed pair (i,v)(i,v) a formal one-hot coordinate and write z(j)FrA+1z(j)\in\mathbb F_r^{A+1} for the signed incidence row. Unknown coset exponents define an unknown vector θ\theta satisfying [ z(j)\cdot\theta=j. ] The decoder never computes θ\theta. It evaluates the tuple at mm known random multiples TsPT_sP, and if z(J)=sλsz(Ts)z(J)=\sum_s\lambda_sz(T_s), returns sλsTs=J\sum_s\lambda_sT_s=J.

Shamir's distribution-free span lemma gives success probability at least [ 1-\frac{A+1}{m+1}. ] Random self-reduction therefore turns every polynomial-total-alphabet exposed factorization of this kind into a randomized polynomial-time ECDLP algorithm, without a target DLP. The order-101101 binary fixture is decoded on all scalars by eight fixed calibration rows and in all 10001000 seeded trials using m=30m=30. Shamir supplies the span lemma; the hidden factor-incidence functional and DLP calibration application are the repository-original synthesis.

This still left multi-coset factors. A048 first removed them in the direct-summand case by the public retraction xxs(s1modr)x\mapsto x^{s(s^{-1}\bmod r)} for an ambient cyclic group of order rsrs, gcd(r,s)=1\gcd(r,s)=1. A049 then removed the retraction and every coset hypothesis.

SG-39 finite-module factor decoder

Let TT be any explicit finite abelian target with public annihilator NN, let hTh\in T have order rr, and suppose exposed finite factor images of total size AA satisfy [ \prod_i g_i(jP)^{\varepsilon_i}=h^{aj+b}. ] Encode their signed one-hot rows over R=Z/NZR=\mathbb Z/N\mathbb Z, including a leading constant coordinate. The formal map sending each symbol to its actual target value is an RR-module homomorphism. Thus any calibration relation [ z(J)=\sum_s\lambda_sz(T_s) ] maps to the same relation among haJ+bh^{aJ+b} and haTs+bh^{aT_s+b}, recovering JmodrJ\bmod r without a target logarithm.

For iid samples in a finite module MM, the next sample enlarges the generated submodule with probability at most log2M/(m+1)\log_2|M|/(m+1): every strict inclusion at least doubles size, and the enlargement probabilities decrease. Hence A049 decoding fails with probability at most [ \frac{(A+1)\lceil\log_2N\rceil}{m+1}. ] With a polynomial upper bound on AA and polynomial logN\log N, random self-reduction gives randomized polynomial-time ECDLP. Composite-modulus linear systems are solved in polynomial bit complexity by Smith/Hermite normal form. This covers arbitrary multi-coset values, noncyclic targets, and r2Nr^2\mid N, with arbitrary coordinate/branch/denominator code inside the named factor subroutines.

The surviving factor/circuit route must have superpolynomial total alphabet, hide all factors in a final-only circuit, or use nonseparable additive/algebraic/Boolean intermediates with no polynomial-alphabet signed product interface.

The new theorem

Let r5r\ge5 be prime and let [ h\in\operatorname{Pic}(\mathcal O_f),\qquad \mathcal O_f=\mathbb Z+f\mathcal O_K, ] have exact order rr. The explicit target interface supplies the fundamental discriminant DKD_K, conductor ff, and factorization of ff.

The conductor exact sequence gives exactly two cases.

  1. If hh maps to the identity in Cl(OK)\operatorname{Cl}(\mathcal O_K), the known effective conductor inverse maps it to a nonzero local component: a split finite-field subgroup, an inert norm-one torus, or a wild additive Fr\mathbb F_r-line.
  2. If its maximal projection hˉ\bar h is nonzero, write ar=(α)\mathfrak a^r=(\alpha). Because the imaginary-quadratic unit group has order dividing six, αK×r\alpha K^{\times r} is the canonical virtual unit attached to hˉ\bar h. For infinitely many split q1(modr)q\equiv1\pmod r, [ \lambda_{\mathfrak q}(\bar h) =\alpha^{(q-1)/r}\bmod\mathfrak q ] is nontrivial and hence injective on hˉ\langle\bar h\rangle.

Binary ideal powering with relative-generator tracking retains α\alpha as an O(logr)O(\log r)-node compact power product. It can be evaluated q\mathfrak q-adically in polynomial time even when individual compact factors have qq-divisible denominators.

Under GRH for the normal Kummer closure, effective Chebotarev gives a Las Vegas expected-polynomial search and [ \log q=O(\log r+\log(\log|D_K|+2)). ]

Q004 consequence

For any nonzero source evaluator [ \phi:\langle P\rangle\to\operatorname{Pic}(\mathcal O_f), \qquad h=\phi(P), ] the target-side character Λh\Lambda_h from A028 satisfies [ \Lambda_h(\phi(xP))=\Lambda_h(h)^x ] in a multiplicative branch, or xΛh(h)x\Lambda_h(h) in the additive branch.

Thus an ordinary imaginary-quadratic class presentation is never an independent third transfer endpoint. If the composite source character is not anomalous or MOV/Frey--Rück, its novelty already lies in a direct source-to-finite-field character; the class layer is removable.

This is a factorization theorem, not a proof that ϕ\phi cannot exist and not a claim that every resulting finite-field character is pairing-derived. It is strictly broader than A024 and A027 because it permits arbitrary coordinate access, lifts, valuations, branches, direct MAKEFORM, external conductor primes, and varying or unrelated maximal quadratic fields.

Prior-art boundary

  • The conductor exact sequence and effective kernel inverse are classical: Hühnlein--Takagi and Castagnos--Laguillaumie.
  • Virtual units and the Kummer pairing are classical class field theory.
  • Compact ideal power products and relative generators are supported by Vollmer and Jacobson--Sawilla--Williams.
  • Effective Frobenius-prime bounds are due to Lagarias--Odlyzko and Bach--Sorenson.
  • The repository-original contribution is the complete effective conductor/maximal synthesis in A028.4 and its evaluator-independent Q004 consequence. Do not claim any ingredient separately as new.
  • A bounded primary-source search through 2026-07-23 found no checked source stating this full prime-order computational dichotomy for imaginary-quadratic Picard targets. This remains an audited novelty claim, not a universal bibliographic proof.

Infinite-family checks

  • A025 supplies an infinite succinct conductor-branch control family. It is pairing-derived and remains labeled as such.
  • A029 supplies the uniform target-only family required by SG-30, for every odd prime rr, without an auxiliary prime or analytic hypothesis.
  • Lim (2016) supplies the rigorous infinitude statement: for every fixed odd prime rr, infinitely many imaginary quadratic fields have a maximal ideal class of exact order rr. A028 gives infinitely many separating primes for every such target. This existence theorem is not a uniform succinct SG-30 constructor.
  • A019 supplies the explicit maximal-branch regression fixture: [ D_r=1-4\cdot2^r,\quad \mathfrak a=(2,\omega),\quad \mathfrak a^r=(\omega). ] Its order discriminant is not proved fundamental for every prime rr, so it is not itself claimed as an infinite maximal-order family. The ten probed cases have nonzero maximal projection, certified by their nontrivial residue character. It is deliberately oversized and does not solve SG-30.
  • code/probe_kummer_class_character.py checks ten primes 3r313\le r\le31, finds a nontrivial character in every case, and recovers every scalar. The permanent output is data/probe_kummer_class_character_full_20260723.csv.
  • The session-12 A028/A031 snapshot had 128 passing tests and a 27-page paper. The current session-21 verification is recorded in LOG.md and supersedes those counts.

Other established boundaries

  • A023 reconciles the rational package with the closest discrete-logarithm interpolation literature. The B2B^2 overlap scale has direct prior art; call the full package a repository-original synthesis.
  • A024 proves C+jlog2(hj+1)log2rC+\sum_j\log_2(h_j+1)\ge\log_2r only in its fixed VFB model.
  • A025 is a correct ordinary ring-class transfer but only a presentation of the known degree-two pairing target.
  • A026's hoped-for effective-kernel novelty was rejected as 1999/2009 prior art.
  • A027 proves the sharper source-CM intrinsic-support consequence: rr-local support gives an Fr\mathbb F_r linearizer, while pp-local support forces trace two and embedding degree one.

Unconditional boundary

Ordinary Chebotarev proves infinitely many separating maximal-branch primes, and evaluation is polynomial once one is supplied. The checked unconditional effective bounds do not prove a uniform polynomial-time short-prime search in logr+logDK\log r+\log|D_K|. Do not erase this caveat.

This is compatible with marking A028's ordinary-class factorization complete under the standing convention: the rigorous Hafner--McCurley class-group target route used there is itself recorded under ERH. It is not a claim that the later unrestricted cross-characteristic SG-39 converter has been constructed or excluded.

SG-30 - solved by A029

For every odd prime rr, take [ \mathcal O_r=\mathbb Z+r^2\mathbb Z[i], \qquad \Delta_r=-4r^4. ] The conductor residue 1+rimodr21+ri\bmod r^2 has exact order rr modulo rational and Gaussian units. Its contracted ideal has raw form [1+r2,2r3,r4][1+r^2,2r^3,r^4], which reduces in two elementary steps to [ [r^2,2r,r^2+1]. ] The output has Θ(logr)\Theta(\log r) bits, lies inside SG-25, and is constructed and certified in deterministic polynomial time. Its subgroup logarithm is the explicit additive map 1+raiamodr1+rai\mapsto a\bmod r.

This is a target-only theorem. It does not provide a source evaluator and is exactly the wild conductor branch exposed by A028.

Files that matter

  • attempts/A028-kummer-residue-factorization.md: closing theorem and proof.
  • attempts/A029-uniform-wild-ring-class-target.md: unconditional SG-30 constructor and certificate.
  • attempts/A030-ring-class-evaluator-completeness.md: equivalence between the A029 evaluator and polynomial-time ECDLP.
  • attempts/A031-same-characteristic-affine-endpoints.md: arbitrary-evaluator matrix theorem collapsing same-characteristic affine targets.
  • attempts/A032-ordinary-class-endpoint-trichotomy.md: exact cross-characteristic residual.
  • attempts/A033-cross-characteristic-lift-barrier.md: unique same-prime lift, second-prime section ambiguity, and dense global degree barrier.
  • attempts/A034-canonical-residue-rebasing-barrier.md: least-residue subgroup-sum theorem, EDS/character incompatibility, and defect criterion.
  • attempts/A035-cyclotomic-character-torsor-barrier.md: exact nonzero character moduli, naturality no-go, and dense cyclotomic rank barrier.
  • attempts/A036-frobenius-orientation-barrier.md: arbitrary-algorithm Frobenius-stabilizer obstruction, norm collapse, and sharp oriented boundary.
  • attempts/A037-gauss-period-degree-product.md: exact local/global Gaussian-period degree product and trace-compression barrier.
  • attempts/A038-translation-filter-spectral-barrier.md: fully oriented single-feature Fourier deconvolution and exponential translated-probe lower bounds.
  • attempts/A039-spectral-defect-resultant-barrier.md: generalized defect/tap product and lifted-feature exceptional-prime criterion.
  • attempts/A040-multifeature-galois-span-barrier.md: rational r1r-1-dimensional Galois-span theorem and fixed-dictionary exceptional-resultant barrier.
  • attempts/A041-polynomial-feature-algebra-barrier.md: unital full-Hilbert rank theorem, nonlinear exceptional-resultant barrier, and exact joint injectivity criterion.
  • attempts/A042-piecewise-polynomial-character-barrier.md: full branch-rank theorem, linear-BB tradeoff, and partition-uniform subset-resultant barrier.
  • attempts/A043-galois-schur-denominator-barrier.md: arbitrary-preprocessing width/depth cut, projective-denominator orbit bound, and fixed-denominator weighted-resultant barrier.
  • attempts/A044-mixed-radix-denominator-escape.md: square-root target-mixed denominator construction and matching pure-root envelope lower bound.
  • attempts/A045-binary-character-factorization.md: exact multidigit envelope, logarithmic binary compression, and exposed-factor ECDLP completeness.
  • attempts/A046-public-exponent-factor-decoder.md: representation-independent decoder for every exposed public cyclotomic factor tuple.
  • attempts/A047-calibration-span-decoder.md: unlabelled cyclotomic-coset factor decoder from known-multiple calibration.
  • attempts/A048-direct-summand-factor-projection.md: exact public retraction and multi-coset projection in the direct-summand case.
  • attempts/A049-finite-module-factor-decoder.md: arbitrary finite-abelian polynomial-alphabet factor decoder over Z/NZ\mathbb Z/N\mathbb Z.
  • attempts/A027-intrinsic-conductor-support.md: source-side refinement.
  • attempts/A026-conductor-kernel-universality.md: prior-art control.
  • attempts/A025-pairing-to-ring-class-transfer.md: pairing control.
  • attempts/A024-valuation-factor-base-model.md: VFB lower bound.
  • attempts/A023-interpolation-prior-art-audit.md: prior-art reconciliation.
  • code/probe_kummer_class_character.py: maximal Kummer regression driver.
  • code/construct_sg30_ring_class_target.py: uniform A029 constructor.
  • code/probe_affine_endpoint_collapse.py: A031 semisimple/unipotent certificate fixtures.
  • code/probe_galois_schur_denominator.py: A043 Schur-capacity, orbit-bound, and exact order-11 fixed-denominator certificates.
  • code/probe_mixed_denominator_grid.py: A044 coefficient-rank, projective-orbit, and incidence-graph certificates.
  • code/probe_multidigit_character_factorization.py: A045 mixed-radix factor-product, exact common-rank, and binary scalar-reconstruction certificates.
  • code/probe_public_exponent_factor_decoder.py: A046 signed-factor exponent-table decoder certificates for A044 and A045.
  • code/probe_calibration_span_decoder.py: A047 incidence-span decoder, deterministic spanning set, and random-calibration certificates.
  • code/probe_direct_summand_factor_projection.py: A048 projector, two-coset factor fixture, and repeated-rr obstruction.
  • code/probe_finite_module_factor_decoder.py: A049 raw multi-coset composite-module decoder certificate.
  • code/probe_lift_section_ambiguity.py: A033 finite section certificate.
  • code/probe_residue_rebasing.py: A034 residue-sum, defect, and Ward certificates.
  • code/probe_character_torsor.py: A035 global/local degree and character torsor certificate.
  • code/probe_frobenius_orientation.py: A036 Frobenius orbit, orientation divisibility, and norm certificate.
  • code/probe_gauss_period_product.py: A037 Frobenius subgroup, coset partition, and degree-product certificate.
  • code/probe_translation_filter.py: A038 orbit-gap, dense-filter, and natural-coordinate spectrum certificates.
  • code/probe_spectral_defect.py: A039 defect/tap, circulant-resultant, and sharp sparse-spectrum certificates.
  • code/probe_multifeature_galois_span.py: A040 rational-rank, cofactor-annihilator, exceptional-prime, and eight-probe certificates.
  • code/probe_polynomial_feature_algebra.py: A041 Hilbert-rank profile, degree-three obstruction, and exceptional/nonexceptional degree certificates.
  • code/probe_piecewise_polynomial_character.py: A042 agreement profiles, branch capacity, and oversized-subset resultant certificates.
  • RATIONAL_TRANSFER_REVIEW.md: authoritative rational theorem wording.
  • NOTES.md, STATE.md, LOG.md: synchronized current status.

What I would tell my replacement

Do not call SG-30 a solution of the source problem. A030 proves the opposite: an evaluator into that target is ECDLP-complete. Preserve A028's GRH boundary and A029's unconditional status. The new substantive theorem is A031, which uses only the order-rr image matrix and no rational-map model. Do not weaken it back to the commutative case. The only ordinary-class endpoint not collapsed by A030--A032 is the cross-characteristic converter in SG-39. A033 says not to retry canonical lifting, CRT, or a dense global torsion field. A034 says not to retry a perfectly periodic EDS as though it were a character, or to reduce a prime-field character's least positive integer representatives modulo a second prime. A035 says not to retry any base-change-natural common cyclotomic character or dense finite global parameter algebra. A036 says not to retry a basis-free construction or a trace/norm/symmetric conjugate aggregate: full target orientation of Frobenius orbit divisible by ordr()\operatorname{ord}_r(\ell) is necessary. A037 further says not to replace that orientation by its Gaussian period: the complementary global degree is (r1)/ordr()(r-1)/\operatorname{ord}_r(\ell). A038 says not to retry one spectrally full source feature with a linear translated filter: that costs exponentially many probes even with the full orientation public. A039 says that a polynomial-tap sparse-spectrum escape needs exponentially many holes and, for a nonconstant integer-lifted feature, an exceptional target prime dividing its cyclotomic resultant. A040 says that a fixed finite integer feature dictionary cannot use linear multi-channel cancellation outside another explicit finite resultant-prime set; the eight-probe order-1111 fixture proves those exceptions can occur. A041 says not to retry a bounded-degree or explicitly sparse polynomial in fixed features: its evaluation code must have full dimension, and a lower rank is possible only at an explicit resultant prime. It also says not to confuse dense interpolation from an injective raw encoding with an efficient evaluator. A042 says ordinary polynomial branching does not evade this: branch count trades only linearly against monomial capacity outside one uniform exceptional set. A043 says arbitrary preprocessing before a rational interface does not help a bounded Schur suffix, and a projectively orientation-free final denominator gives no escape. A044 says not to seek a linear rank--rank completion: a maximally oriented mixed-radix denominator has a sharp square-root common envelope. Its definition reads the unknown scalar's remainder and quotient, so the next theorem must charge computation of those labels rather than only final algebraic rank. A045 strengthens that warning: binary digit factors compress the common envelope to logarithmic dimension, but any implementation exposing them is exactly ECDLP-complete. A046 generalizes this to every exposed public cyclotomic alphabet of polynomial total size. A047 removes the public alphabet, exponent labels, and coset representatives whenever each finite factor image lies in one unknown cyclotomic coset. A048 projects multi-coset factors in the direct-summand case. A049 is now authoritative: formal finite-module calibration closes every exposed signed factor tuple of polynomial total alphabet in any polynomial-bit finite abelian target, even with many cosets, a noncyclic target, or repeated rr-torsion. Do not retry exponent labeling, coset projection, or cofactor arguments. The next theorem must address a superpolynomial alphabet, final-only circuit, or nonseparable additive/algebraic/Boolean interface.

48 attempts27 scripts15 datasets73 references