Research · Hardness of the discrete logarithm
A unified theory of transfers
A030 makes the A029 evaluator exactly ECDLP-complete, A031 collapses same-characteristic affine endpoints, A032 isolates cross-characteristic conversion, A033--A037 close lift/rebasing/natural/symmetric/trace routes, A038--A039 close single-feature filters, A040 closes fixed-dictionary linear cancellation, A041 closes bounded-degree polynomial feature algebras, A042 closes piecewise polynomial branching, A043 reaches arbitrary rational preprocessing and orientation-free final division, A044--A045 expose logarithmic target mixing, A046--A047 decode labelled and single-coset factors, and A049 proves every exposed polynomial-total-alphabet signed factorization into any polynomial-bit finite abelian target ECDLP-complete by finite-module calibration.
Problem
Setting
Let be an elliptic curve and let have prime order .
Task
Classify the curves for which there is a polynomial-time computable injective homomorphism from to a group with a subexponential discrete logarithm algorithm.
- CITED Trace-one elliptic curves over prime fields admit the anomalous-curve reduction of Semaev (1998), Satoh--Araki (1998), and Smart (1999).
- CITED Prime-order subgroups with small embedding degree admit pairing reductions to finite-field multiplicative groups (Menezes--Okamoto--Vanstone 1993; Frey--Ruck 1994).
The research question is whether a structurally different third transfer exists, or whether a classification can rule one out in a stated class.
Deliverables
- A precise definition, including an explicit decision about Weil descent.
- End-to-end validated additive and multiplicative transfer demonstrations.
- A common structural description of the two known cases.
- A candidate-target table with a reason for every inclusion or exclusion.
- A restricted classification statement, with its proof or precise gaps.
Scope
All computations use toy parameters under the repository-wide 60-bit ceiling.
Q004 control results and novelty-grade resolution
PROVED A025 satisfies the former literal class-group existence checklist. On an infinite trace-zero family, the degree-two pairing character maps through the conductor exact sequence into the ordinary ring class group .
PROVED A projective pairing value maps to the reduced class of , and Gaussian ideal extension converts the target DLP back to the same finite-field torus.
PROVED This is a valid class-group transfer but not a structurally new mechanism: it is the known bilinear transfer in an ordinary ring-class presentation.
CITED A026's proposed effective conductor-kernel inverse is not new: Hühnlein--Takagi (1999) reduce the class-number-one case to finite-field DLP, and Castagnos--Laguillaumie (2009) give the effective kernel isomorphism for general conductor.
PROVED A027 nevertheless proves a source-side theorem for every evaluator, including direct form synthesis. In the source CM field, a target whose conductor is supported on either exposes an explicit linearizer or forces trace and embedding degree one.
PROVED A028 closes both residuals at once for every explicit imaginary-quadratic order target. The conductor exact sequence gives an exhaustive dichotomy for the order- image:
- a kernel image is exposed by the classical effective conductor inverse in a tame finite-field torus or a wild additive -line;
- a nonzero maximal projection has a canonical virtual unit , and a suitable split gives the injective character [ [\mathfrak a]\longmapsto \alpha^{(q-1)/r}\bmod\mathfrak q\in\mu_r(\mathbb F_q). ]
PROVED Compact relative-generator tracking evaluates the maximal character in polynomial time without expanding the -bit generator.
CONDITIONAL: the standing ERH/GRH convention Effective Chebotarev finds a separating in expected polynomial time with .
PROVED Hence the ordinary quadratic class presentation never supplies an independent third endpoint: every nonzero evaluator, including arbitrary direct form synthesis, post-composes to a finite/local residue character. This does not assert that the source evaluator cannot exist or that its resulting finite-field character is pairing-derived.
PROVED SG-30 is unchanged and separate. A028 starts from a supplied explicit target and does not construct a succinct prescribed-order maximal class group from arbitrary .
PROVED A029 subsequently closes the target-only SG-30 problem unconditionally. For every odd prime , [ \mathcal O_r=\mathbb Z+r^2\mathbb Z[i],\qquad \Delta_r=-4r^4, ] and the canonical reduced form [ [r^2,2r,r^2+1] ] has exact class order . Its discriminant has bits and lies inside the SG-25 window. This target theorem remains separate from the source evaluator and is the wild additive conductor branch predicted by A028.
PROVED A030 sharpens that separation to a complexity equivalence. The class number contains exactly one factor of , so A029's wild line is the unique Sylow -subgroup. A polynomial-time nonzero evaluator into the A029 target exists if and only if source ECDLP is polynomial-time solvable.
PROVED A031 gives a new evaluator-independent endpoint theorem. If an arbitrary source homomorphism lands in an affine algebraic group over with a faithful -dimensional representation and , then an order- image matrix either:
- has , exposes the scalar through its nilpotent part, and Hasse forces the anomalous trace-one case; or
- has an eigenvalue of exact order in degree at most , forcing and the MOV/Frey--Rück regime.
This requires no rational-map hypothesis and permits disconnected and noncommutative targets.
PROVED Combining A028 and A031 yields the A032 trichotomy for every ordinary quadratic class evaluator: it either solves source ECDLP in polynomial time through an additive character, forces the known pairing regime through a same-characteristic multiplicative character, or produces a cross-characteristic converter [ \langle P\rangle\longrightarrow \mu_r(\mathbb F_{\ell^d}),\qquad \ell\ne p. ]
PROVED A033 closes the standard lift-and-specialize route to that last converter. Prime-to- torsion lifts uniquely through a same-prime nilpotent thickening, but after adjoining an order- second fiber the homomorphic sections are indexed by ; choosing a nonzero section is exactly choosing the missing converter. A canonical/Deuring CM torsion bridge or a torsion bridge on a rational lifted curve requires an explicit number field of degree , by the checked CM and rational torsion-degree theorems.
PROVED A034 closes the most direct residue-level reuse of finite-field labels. If has prime order , the least positive representatives of its elements cannot retain a nonzero labelled multiplication table modulo any distinct prime : their positive sum would be divisible by while being strictly below . A target-field multiplicative character is also incompatible with the Ward EDS recurrence. Thus neither a perfectly periodic EDS label nor a genuine same-characteristic character can be turned into the missing converter by canonical scalar reduction.
PROVED The coefficientwise extension-field version is also sharply constrained. Reinterpreting the same canonical -coefficient vectors in characteristic can be nonzero only when and . This follows by applying the same sum argument to one positive coordinate.
PROVED A035 closes the entire base-change-natural finite/local algebraic route. Over , the nonzero character functor is the primitive-root torsor [ \operatorname{Spec}\mathbb Z[1/r,T]/(\Phi_r(T)). ] It is finite etale of degree , has no integral section, and every finite locally free parameter algebra that trivializes it has rank at least . Local roots in characteristics and merely define the exponent-preserving relation ; they do not evaluate it from source coordinates.
PROVED A036 closes every basis-free or insufficiently oriented bit-level implementation, without assuming that the evaluator is algebraic or rational. If is its public target-orientation data in , then a nonzero -canonical character requires [ \operatorname{ord}r(\ell) \mid|\operatorname{Gal}(\mathbb F{\ell^d}/\mathbb F_\ell)\cdot D|. ] In particular, no -rational presentation can work when . Frobenius-symmetric multiplicative postprocessing also collapses: the norm of the -torsion to is one whenever .
PROVED A037 shows that Frobenius trace does not compress this orientation into a second succinct global bridge. If , the corresponding prime Gaussian period has characteristic-zero degree [ m=\frac{r-1}{f},\qquad fm=r-1. ] Hence a polynomial-degree local root field and a polynomial-degree global period field cannot coexist.
PROVED A038 closes a fully oriented translation-filter mechanism. For any spectrally full scalar source feature , a target-field-linear combination of translates equal to a nonzero character must use all shifts. Even with coefficients in the full oriented target field, one nonzero base-field target coordinate needs at least [ \left\lceil \frac{r-\operatorname{ord}_r(\ell)} {\operatorname{ord}_r(\ell)} \right\rceil+1 ] shifts. This is exponential for every polynomial-degree SG-39 target.
PROVED A039 strengthens A038 to a source feature with Fourier zeros. If the target has Fourier support and the filter uses translated probes, then . A polynomial-tap character filter therefore requires exponentially many spectral zeros.
PROVED A039 also isolates those zeros arithmetically for every nonconstant integer-lifted feature. They occur at nonzero frequencies in characteristic only when divides the explicit nonzero resultant ; the zero-frequency exception is .
PROVED A040 permits several fixed integer-valued feature channels with arbitrary linear cancellation. In characteristic zero, fewer than rational probe vectors cannot span a primitive character. For a fixed finite dictionary and tap budget , modular failure can occur only at prime divisors of one explicit nonzero product of cyclotomic obstruction resultants.
PROVED A041 permits arbitrary polynomial combinations of fixed integer features. If the total-degree- evaluation space contains a primitive character, its rational Hilbert rank is the full , so [ \binom{m+D}{m}\ge r ] and an explicitly expanded polynomial needs at least monomials. Whenever that evaluation space has smaller rational rank, modular containment forces to divide one explicit nonzero sum-zero annihilator resultant. The unrestricted polynomial algebra contains a character exactly when the joint feature tuple is injective.
PROVED A042 permits arbitrary branch partitions with polynomial leaves. Galois saturation and Chebotarev's prime Fourier-minor theorem force every characteristic-zero leaf evaluation code to be full on its branch, hence [ B\binom{m+D}{m}\ge r. ] For integral features and , the product of the nonzero annihilator resultants over all -point subsets gives one explicit . Outside its prime divisors, the same linear- bound holds uniformly over every branch partition and arbitrary extension-field leaf coefficients.
PROVED A043 removes any restriction on how the rational source features before a circuit cut are computed. If their interface has dimension , a target-oriented Schur suffix of multiplication degree has dimension at most . For one final quotient , let be the projective Galois-orbit size of the denominator evaluation shape. Every leaf code then has dimension at least [ \min\left{|S|,1+\frac{r-1}{e}\right}. ] Hence orientation-free denominators () do not help, while a uniform -leaf model satisfies . Fixed integral denominators also have a partition-uniform weighted subset-resultant obstruction.
PROVED A044 answers A043's immediate rank--rank question negatively and sharply in the pure-root subclass. Writing , the maximally oriented denominator and numerator satisfy inside a common rational code of exact dimension [ t+\left\lceil\frac rt\right\rceil-1. ] Taking gives , so no linear simultaneous-orbit-rank theorem can close target-mixed division. Conversely every pure cyclotomic-monomial pair on points has common-envelope dimension satisfying . This is a sharp algebraic escape, not an evaluator: computing its mixed-radix labels from still requires the missing scalar information.
PROVED A045 iterates this escape and proves an exact logarithmic compression theorem. If , then [ f_i(j)=\zeta_r^{2^ia_i(j)},\qquad \prod_i f_i(j)=\zeta_r^j. ] Every has rational Galois rank two and maximal projective orbit, while all factors lie in one rational code of exact dimension . More generally a mixed-radix family has exact common dimension . This proves that final algebraic rank and factor depth alone cannot close SG-39.
PROVED A045 also closes this explicit compression as a source construction: evaluating its exposed factors from is polynomial-time equivalent to ECDLP, since each factor is either or the public value and therefore reveals one scalar bit. This is representation-independent for the named factor registers, but it is not a lower bound for an arbitrary circuit that never exposes them.
PROVED A046 removes the digit-specific hypothesis. Suppose arbitrary coordinate-aware subroutines expose for public exponent alphabets and [ \prod_i g_i(jP)^{\varepsilon_i}=\zeta^{aj+b}. ] Public table lookup recovers every selected exponent and hence in target operations. Thus every exposed polynomial-total-size public cyclotomic factorization is ECDLP-complete, with no rationality, degree, branch, denominator, source-coordinate, or characteristic assumption on the factor evaluators.
PROVED A047 also removes the public alphabet and exponent-label hypotheses. If each exposed factor image has polynomial total size and lies in one unknown coset , encode a factor tuple by its signed symbol-incidence row . The product identity supplies an unknown linear functional [ z(j)\cdot\theta=j. ] For random known multiples , a distribution-free rank-increment lemma gives [ \Pr!\left[z(J)\notin \operatorname{span}{z(T_1),\ldots,z(T_m)}\right] \le\frac{A+1}{m+1}. ] Whenever the challenge row is in the span, applying the same linear combination to the known recovers , without target DLP, alphabet enumeration, exponent labels, or coset representatives. Random self-reduction therefore makes every polynomial- evaluator of this type a randomized polynomial-time source ECDLP solver.
PROVED A049 removes all factor-coset and cyclic-target hypotheses. Let be any finite abelian target with public polynomial-bit annihilator , and encode every distinct exposed factor value by a signed one-hot row over . A module-span relation among calibration and challenge rows maps formally to the same relation among and , hence recovers . For total alphabet , [ \Pr[\text{decoding failure}] \le \frac{(A+1)\lceil\log_2N\rceil}{m+1}. ] Thus every exposed polynomial-total-alphabet signed factorization into a polynomial-bit finite abelian target is ECDLP-complete, even when one factor meets many -cosets or . A048's public direct-summand projection is a strict intermediate case; A049 needs no projection.
[OPEN] The last converter is the genuine remaining endpoint problem. Generic and rational models are excluded by A007--A013 and standard algebraic lifts by A033; A034 also excludes EDS-preserving and scalar canonical-residue rebasing; A035 excludes all natural common-base finite/local character bridges and dense cyclotomic parameters; A036 additionally proves that full Frobenius orientation is necessary; A037 rules out hiding it through a Gaussian-period trace bridge; A038--A039 exclude all single-feature linear translation filters except the explicitly isolated large-defect resultant-prime cases; A040 also closes every fixed finite multi-feature linear dictionary outside its explicit exceptional primes; A041 closes every fixed bounded-degree or sparse polynomial feature algebra outside its own explicit exceptional primes; A042 closes all piecewise polynomial partitions there as well, with a linear rather than quadratic branch tradeoff; A043 additionally closes arbitrary rational/Boolean preprocessing followed by a bounded Schur suffix and every projectively orientation-free final denominator; A044 proves that a fully target-mixed pure-root denominator has a square-root algebraic escape; A045 iterates it to logarithmic dimension; A046--A047 decode labelled and unknown-single-coset alphabets; and A049 closes every exposed polynomial-total-alphabet signed factorization into any polynomial-bit finite abelian target. No unconditional gate-count lower bound covers every fully oriented exceptional-prime, adaptive, superpolynomial-alphabet, final-only target-mixed or nonseparable nested-division, or extension-coordinate Boolean/bit-mixing program, and no such converter is constructed here. P1.5 is therefore reopened at SG-39 rather than being called unrestrictedly complete.
Findings & state of play
State in five lines
SG-01--SG-38 are complete at their stated scopes; SG-39 is open. A028 removes the ordinary quadratic class layer, and A029 closes SG-30. A030 proves that evaluation into A029's unique -line is exactly polynomial-time ECDLP. A031 proves, for arbitrary evaluators, that every polynomial-dimensional same-characteristic affine endpoint is anomalous or MOV/Frey--Rück. A032 leaves one honest residual: a coordinate-aware cross-characteristic converter , . A033 excludes canonical/Hensel/CRT/dense-global torsion lifting as a shortcut, but not a direct bit-level converter. A034 additionally excludes EDS-preserving specialization and canonical scalar rebasing of every prime-field character. A035 closes every base-change-natural finite/local character bridge and every dense finite locally free cyclotomic parameter of polynomial rank. A036 proves that even an arbitrary Boolean/bit evaluator must be supplied target orientation data whose Frobenius orbit is divisible by ; basis-free and symmetric implementations collapse. A037 shows that Frobenius-trace/Gaussian-period compression merely exchanges local degree for global degree . A038 keeps the orientation and proves the first exponential lower bound there: a spectrally full single feature filtered through translated probes needs all target-field coefficients, and even one base-field coordinate needs at least probes. A039 removes the full-spectrum assumption: taps, source spectral zeros, and target support satisfy . A nonconstant integer-lifted feature has holes only at prime divisors of one explicit nonzero cyclotomic resultant. A040 closes arbitrary linear cancellation among a fixed finite integer-valued feature dictionary outside an explicit finite resultant-prime set; its order- fixture proves that the exceptional-prime qualifier is essential. Only an exceptional/adaptive feature choice or a nonlinear converter remained. A041 now closes all bounded-degree or explicitly sparse polynomial combinations generically: their unital evaluation code must have full rank , while lower rank can occur only at divisors of another explicit resultant. A042 also closes arbitrary polynomial branch partitions generically and improves the scoped branch tradeoff to , uniformly over all partitions outside one subset-resultant prime set. Only exceptional/adaptive features, succinct factored arithmetic, divisions, or genuinely encoding-dependent Boolean/carry computation remain.
SG-39 lift barrier
A033 proves three exact statements.
- For , reduction through a nilpotent same-prime thickening is an isomorphism on -torsion. Every source point has a unique torsion lift, and uniqueness makes the lift homomorphic.
- If a useful order- second fiber is attached, the homomorphic sections of are [ s_\chi(Q)=(Q,\chi(Q)), \qquad\chi\in\operatorname{Hom}(C,T)\simeq\mathbb F_r. ] A nonzero section is exactly the missing cross-characteristic converter. The shears fixing the source projection act simply transitively, so source reduction data does not canonically distinguish one.
- A dense explicit common torsion point over a number field has exponential degree in the standard global settings. A CM point of prime order has degree at least for all sufficiently large , and a point of order on a rational elliptic curve has degree at least for , .
This closes the standard canonical, Deuring, local Hensel, CRT, and dense global torsion bridge templates. Silverman's lifting survey and Huang--Raskind's signature equivalence are explicit prior art for the larger lifting program; call A033 a repository-original synthesis, not a discovery that lifting in general has roadblocks.
SG-39 residue and EDS barrier
A034 proves two further exact exclusions.
- Let have prime order , and let represent . The labelled map cannot be a nonzero homomorphism for a distinct prime . If it were, , while [ p\ell\mid\sum_jz_j,\qquad 0<\sum_jz_j<rp<p\ell. ] The same argument covers scalar outputs embedded in an extension field. Applied to each coefficient of a canonical extension-field encoding, it shows that a nonzero coordinatewise rebase must satisfy and no larger than the coordinate dimension.
- A target-field multiplicative character cannot satisfy the Ward EDS recurrence. Substituting at makes the left side and the right side zero.
Lauter--Stange's point-computable perfectly periodic EDS term is therefore a label, not a transfer. Shipsey--Swart's genuine division-polynomial homomorphism is same-characteristic and pairing/MOV-derived. A034's exact defect-gcd criterion remains a useful falsifier for arbitrary scalar integer labels, but it is not a lower bound for extension-coordinate programs.
SG-39 cyclotomic character-torsor barrier
A035 proves the complete natural finite/local algebraic statement.
- Over , the fiberwise nonzero homomorphisms are represented by [ X_r=\operatorname{Spec}R[T]/(\Phi_r(T)). ] This is a finite etale torsor under , of degree .
- The torsor has no -point. Hence Yoneda excludes every parameter-free choice of nonzero character compatible with arbitrary base change.
- If a nonzero finite locally free parameter algebra trivializes the torsor, then , so .
- Over , local roots appear in degree . Choosing roots in the - and -fibers only defines ; evaluating that map from a concrete source encoding is SG-39 itself.
Milne's diagonalizable-group equivalence and cyclotomic facts are classical, and Ganz's standard/logarithmic finite-field representation work is the closest checked complexity predecessor. Call A035 a repository-original SG-39 synthesis and naturality no-go, not a discovery of those ingredients. The dense qualifier is essential: a sparse algebraic circuit may name succinctly, and an arbitrary Boolean circuit need not be natural under base change.
SG-39 Frobenius-orientation barrier
A036 removes algebraicity, rationality, and circuit-shape assumptions from the remaining symmetry statement. Let [ K=\mathbb F_{\ell^d},\qquad \Gamma=\operatorname{Gal}(K/\mathbb F_\ell), ] let contain every public target-orientation datum, and let be its stabilizer. A map is -canonical when every automorphism fixing fixes all outputs.
If a -canonical map is a nonzero homomorphism, then [ \operatorname{ord}_r(\ell)\mid[\Gamma:\Gamma_D] =|\Gamma\cdot D|. ] Indeed, the image of a source generator has exact order , lies in the fixed field , and therefore forces , where . This proof applies to arbitrary bit programs that are invariant under re-presentations fixing their declared data.
When , the norm of every to is one. Consequently norm and every invariant algebraic character of the restriction-of-scalars torus are trivial on the -torsion. Symmetric conjugate aggregation cannot remove the target orientation.
The bound is sharp as a symmetry theorem. Supplying a primitive root gives public data with orbit exactly , and is then mathematically canonical. A036 does not evaluate that character. Lange--Winterhof's Boolean interpolation results concern the inverse finite-field logarithm, Satoh's dense interpolation concerns the reverse same-characteristic Verheul map, and Maurer--Raub assume a field homomorphism. The remaining case is exactly a fully oriented polynomial-basis or equivalent coordinate circuit.
SG-39 Gauss-period degree-product barrier
A037 tests the last natural way to remove the orientation required by A036: take the Frobenius trace of a primitive root. Let [ H=\langle\ell\rangle \le(\mathbb Z/r\mathbb Z)^\times,\qquad f=|H|=\operatorname{ord}_r(\ell), ] and put .
Distinct cosets give distinct complex periods. Indeed, equality of two sums gives a degree-at-most- polynomial relation at ; divisibility by and the zero constant coefficient force the two exponent sets to agree. Thus [ [\mathbb Q(\eta_H):\mathbb Q] =\frac{r-1}{f},\qquad f[\mathbb Q(\eta_H):\mathbb Q]=r-1. ]
The local extension containing has degree at least . Hence a polynomial-degree local root field forces exponential global period degree, and polynomial global period degree forces exponential local degree. Feisel--von zur Gathen--Shokrollahi and Bernstein supply the classical finite-field and cyclotomic Gauss-period context. A037's repository-original content is the exact SG-39 product and boundary, not the period theory.
This closes trace/Gaussian-period orientation compression but not a circuit that keeps the primitive root fully oriented throughout.
SG-39 translation-filter spectral barrier
A038 keeps a primitive target root fully public, with , and tests the direct translated-feature mechanism [ \sum_k A_k u(Q+kP). ] For a source feature , write [ \widehat u(s)=\sum_j u(j)\zeta^{-sj}. ] If every is nonzero, Fourier deconvolution gives two exact lower bounds.
- To produce with coefficients in the full target field, the unique filter is [ A_k=\widehat u(a)^{-1}\zeta^{-ak}. ] Every one of its coefficients is nonzero.
- To produce one nonzero base-field coordinate, even with coefficients in the full target field, , the filter spectrum is supported on the Frobenius orbit . If is its longest missing cyclic run, the consecutive-zero Vandermonde argument gives [ |\operatorname{supp} A| \ge g(\mathcal O_a)+1 \ge \left\lceil\frac{r-f}{f}\right\rceil+1. ]
Thus the mechanism is exponential whenever the target degree is polynomial in . The identity indicator is always spectrally full, and the order- toy subgroup on has spectrally full reduced - and -coordinate features.
Kumallagov--Sizikov--Zarubin's 2026 Fourier-descent theorem is the closest checked prior art: it characterizes Frobenius-consistent finite-field spectra and optimal coordinate storage. Irreducible cyclic codes and the BCH consecutive-zero bound are also classical. The repository-original claim is only the SG-39 reduction from a translated elliptic-source feature evaluator to this filter and the resulting exponential probe bound.
A038 does not cover several features combined by multiplication or branching, nor a deliberately spectrally sparse tailored feature. Those are now the exact surviving fully oriented cases.
SG-39 spectral-defect and resultant barrier
A039 quantifies the sparse-feature escape left by A038. For one source feature , let be the number of cyclic Fourier zeros. If a target function has Fourier-support size and a translated filter has nonzero taps, then [ t(z+h)\ge r. ] The proof is deconvolution plus the consecutive-zero Vandermonde lemma, so it is valid in every characteristic . For a character, ; for one trace coordinate, . Hence polynomially many taps require exponentially many source spectral zeros.
For a nonconstant lifted integer feature [ w=(w_0,\ldots,w_{r-1}),\qquad U(X)=\sum_jw_jX^j, ] A039 proves [ R_w=\operatorname{Res}(\Phi_r,U)\ne0. ] The reduction modulo has a nonzero-frequency Fourier zero exactly when ; its zero frequency vanishes exactly when . Thus canonical lifted features are full outside a finite explicit exceptional-prime set. This does not exclude a converter that deliberately selects a divisor and obtains exponentially many holes.
Tao's sharper support-sum uncertainty is over . Emmrich--Kunis explicitly record that an all-minors Fourier assertion can fail in small finite characteristic even under primitive order. Do not import Tao's bound into SG-39 without the required finite-field hypotheses. A039 uses only the universally valid product/consecutive-zero statement.
At A039 alone, the exact remaining cases were exceptional large-defect primes, several feature channels with spectral cancellation, and nonlinear or branching circuits. A040 closes the generic part of the second case.
SG-39 multi-feature Galois-span barrier
A040 removes the generic multi-feature linear-cancellation escape. Let [ c_a=(\zeta^{aj})_{j\in\mathbb Z/r\mathbb Z}. ] If lies in the -span of rational probe vectors, then their rational span has dimension at least . The reason is Galois stability: the span contains all primitive Fourier vectors, which are linearly independent.
For any fixed smaller integral probe span of rational rank , signed maximal minors produce a primitive integral annihilator supported on at most coordinates. Its cyclotomic resultant [ R_\lambda =\operatorname{Res}!\left( \Phi_r,\sum_j\lambda_jX^j \right) \ne0 ] has the following exact consequence: reduction modulo a target prime can span a primitive character only if . Taking the finite product over all subsets of size at most proves that every fixed finite integer-valued probe dictionary needs at least probes outside an explicit finite set of target characteristics, even with coefficients in an arbitrary extension field and arbitrary cross-channel cancellation.
The exception is real. For the order- subgroup on , eight translated probes span the primitive character modulo . Their rational rank is eight, and the corresponding nonzero 317-bit resultant is divisible by . Thus A040 is a generic-characteristic theorem, not a characteristic-uniform bound.
Serre supplies the classical rational group-algebra constituent behind the Galois argument. The repository-original content is the SG-39 fixed multi-probe/resultant synthesis. Adaptive exceptional-prime dictionaries, nonlinear multiplication, branching, and raw Boolean circuits remained at the A040 stage; A041 closes the bounded-degree and sparse polynomial part.
SG-39 polynomial feature-algebra barrier
A041 passes from a list of linear probes to every monomial in fixed integer features . Let be the rational evaluation space of all monomials of total degree at most , and let be its dimension. The space is unital. If it contains one primitive character after extending scalars to , Galois stability supplies the other nontrivial characters, while the constant vector supplies the last Fourier-basis vector. Hence [ H_U(D)=r,\qquad \binom{m+D}{m}\ge r. ] For two raw integer features this gives [ D\ge \left\lceil\frac{\sqrt{8r+1}-3}{2}\right\rceil, ] and an explicitly expanded polynomial needs at least monomials.
If , an integral annihilator of has coordinate sum zero, so it is nonconstant and has a nonzero cyclotomic resultant . A degree- primitive character after reduction modulo forces . This is the exact generic-characteristic nonlinear obstruction.
The full pointwise polynomial algebra has dimension equal to the number of distinct joint feature tuples. It contains a primitive character if and only if the tuple is injective. Dense interpolation from raw unique coordinates therefore always exists; succinctness is the issue.
The order- lifted fixture has Hilbert profile . Its degree-three rank-ten space has a sum-zero annihilator with a nonzero 204-bit resultant divisible by ; degree three contains the character modulo , while nonexceptional first succeeds in degree four.
Lopez--Soprunov--Villarreal supply the standard evaluation-code and affine Hilbert-function framework. A041's repository claim is only the forward-character Galois saturation, exceptional-resultant, and SG-39 degree/sparsity synthesis. It is not a gate-count lower bound: a factored polynomial-size circuit can hide exponential degree and support.
SG-39 piecewise polynomial character barrier
A042 adds arbitrary branch partitions. On a branch , the rational monomial evaluation space containing one primitive character restriction is Galois-stable, so it contains all nontrivial Fourier columns restricted to . Chebotarev's prime-order Fourier-minor theorem makes those columns span for every proper branch; the constant monomial completes the full branch. Therefore every leaf has full restricted Hilbert rank and [ B\binom{m+D}{m}\ge r. ] For , explicitly stored monomial counts across the leaves sum to at least . A binary predicate tree of depth with division-free multiplicative-depth- leaves satisfies [ 2^b\binom{m+2^\delta}{m}\ge r, \qquad b+m\delta\ge\log_2r-m. ]
The finite-characteristic theorem is uniform over all partitions. Put . For every -point subset , take the nonzero resultant of a sum-zero integral annihilator, and multiply them to obtain . If , no degree- leaf can match the character on more than points, for any branch partition or extension-field coefficients.
The order- fixture has agreement profile at , exactly the degree-zero-through-three monomial counts. At exceptional it has ; the degree-one four-point branch has a nonzero 74-bit resultant divisible by but not .
This is a genuine -to- improvement only in the forward-character fixed-feature polynomial model. It does not improve the general affine piecewise rational-map theorem from A023. Tao supplies the characteristic-zero minor theorem, and Emmrich--Kunis justify the modular resultant replacement.
SG-39 Galois--Schur cut and projective-denominator barrier
A043 cuts after arbitrary target-independent rational preprocessing. Let the unital interface code have width . Its -th componentwise Schur power has dimension at most [ \binom{w+D-1}{w-1}. ] If a target-oriented suffix produces a primitive character on a branch , Galois saturation and Chebotarev force that Schur power to have dimension . The interface functions themselves may be outputs of factored arithmetic, divisions, comparisons, bit extraction, carries, or Boolean code.
A043 also permits one final quotient . Let be the size of the projective cyclotomic Galois orbit of the denominator evaluation shape. Any rational code containing has dimension at least [ \min\left{|S|,1+\frac{r-1}{e(q)}\right}. ] This is invariant under common target-scalar rescaling. In particular, orientation-free denominators have and give no escape. For uniform Schur capacity , leaves, and denominator orbit at most , [ M\max{B,e}\ge r-1; ] when , .
For a fixed full-support integral denominator, weighted subset annihilators give a nonzero product of cyclotomic resultants, so the branch theorem is uniform over all partitions outside explicit target primes. On the order- degree-one fixture with , maximum agreement is three modulo but five modulo the exceptional prime . The five-point witness has a nonzero 91-bit weighted resultant divisible by but not .
Randriambololona supplies the standard Schur-power formalism. The repository-original claim is the exact Galois--Schur cut, projective denominator-orbit bound, and weighted resultant combination. This is not a general gate-count theorem. A044 below answers its simultaneous-rank question with a low-rank counterexample; nested target-dependent division and unrestricted Boolean/carry computation remain open.
SG-39 mixed-radix denominator escape
A044 proves that the hoped-for linear simultaneous-rank theorem is false. For , set [ q_j=\zeta_r^{-a(j)},\qquad p_j=\zeta_r^{tk(j)}. ] Then , the denominator has maximal projective Galois orbit , and the exact ranks are [ \rho(q)=t,\qquad \rho(p)=\left\lceil\frac rt\right\rceil,\qquad \dim A_{\min} =t+\left\lceil\frac rt\right\rceil-1. ] Balanced gives common dimension .
For any pure-root pair [ q_j=\zeta_r^{u_j},\qquad p_j=\zeta_r^{v_j},\qquad v_j-u_j=aj, ] the exponent pairs form the edges of a simple bipartite graph. Its vertex-indicator code is the minimal common rational envelope. If that code has dimension on points, then [ s\le\left\lfloor\frac{(M+1)^2}{4}\right\rfloor. ] Thus the square-root scale is sharp for cyclotomic monomial denominators. Banakh--Gavrylkiv supply the closest difference-basis prior art; the exact denominator-code translation is the repository synthesis.
This is not a positive evaluator. The construction explicitly uses and . The next problem is a computational lower bound for producing those labels from an encoded source point, or a genuinely coordinate-computable replacement. A purely algebraic rank argument cannot finish SG-39.
SG-39 binary character factorization
A045 iterates the A044 split. For mixed-radix digits [ j=\sum_iR_ia_i(j),\qquad f_i(j)=\zeta_r^{R_ia_i(j)}, ] the factors multiply to . If digit values occur, their individual ranks and exact common rational-envelope dimension are [ \rho(f_i)=d_i,\qquad \dim A_{\min}=1+\sum_i(d_i-1). ] Every nonconstant factor has maximal projective orbit. The proof identifies the common code with the digit-partition indicator span and shows that its only dependencies are the common all-ones sums.
For binary digits, rank-two factors lie in exact common dimension , have balanced target product depth , and multiply to the full character. This is a logarithmic, not merely square-root, algebraic escape.
It is also exactly source-complete. Each named factor is either or ; comparing with those two public values recovers the -th bit of . Hence evaluating all exposed factors from is polynomial-time equivalent to ECDLP, independently of the concrete source representation. De Bruijn supplies the classical mixed-radix decomposition; the exact cyclotomic code and source-completeness synthesis is the repository claim. Do not seek another final rank invariant: the remaining case must hide the digit tuple, make it nondecodable, or compute the character directly.
SG-39 public-exponent factor decoder
A046 removes the digit-specific decoding assumption. Suppose arbitrary coordinate-aware subroutines expose [ g_i(jP)\in{\zeta^u:u\in U_i},\qquad \prod_i g_i(jP)^{\varepsilon_i}=\zeta^{aj+b}, ] for public exponent alphabets . Table lookup gives the unique selected exponents , and then [ j=a^{-1}\left(\sum_i\varepsilon_i u_i-b\right)\pmod r. ] The reduction costs target operations and assumes nothing about how the factor subroutines use coordinates, branching, exceptional primes, denominators, or Boolean/carry code.
Thus every exposed polynomial-total-size public cyclotomic factorization is ECDLP-complete. A044's balanced two-factor alphabet has square-root size, whereas A045's binary total alphabet has size . The next mechanism must use a superpolynomial or unlabelled alphabet, leave public cyclotomic torsors, or avoid exposing factor registers entirely.
SG-39 calibration-span decoder
A047 removes the public alphabets, exponent labels, and coset representatives. Suppose the same arbitrary coordinate-aware subroutines expose finite images [ V_i=g_i(C)\subseteq\gamma_i\langle h\rangle,\qquad \prod_i g_i(jP)^{\varepsilon_i}=h^j, ] and put . Give every observed pair a formal one-hot coordinate and write for the signed incidence row. Unknown coset exponents define an unknown vector satisfying [ z(j)\cdot\theta=j. ] The decoder never computes . It evaluates the tuple at known random multiples , and if , returns .
Shamir's distribution-free span lemma gives success probability at least [ 1-\frac{A+1}{m+1}. ] Random self-reduction therefore turns every polynomial-total-alphabet exposed factorization of this kind into a randomized polynomial-time ECDLP algorithm, without a target DLP. The order- binary fixture is decoded on all scalars by eight fixed calibration rows and in all seeded trials using . Shamir supplies the span lemma; the hidden factor-incidence functional and DLP calibration application are the repository-original synthesis.
This still left multi-coset factors. A048 first removed them in the direct-summand case by the public retraction for an ambient cyclic group of order , . A049 then removed the retraction and every coset hypothesis.
SG-39 finite-module factor decoder
Let be any explicit finite abelian target with public annihilator , let have order , and suppose exposed finite factor images of total size satisfy [ \prod_i g_i(jP)^{\varepsilon_i}=h^{aj+b}. ] Encode their signed one-hot rows over , including a leading constant coordinate. The formal map sending each symbol to its actual target value is an -module homomorphism. Thus any calibration relation [ z(J)=\sum_s\lambda_sz(T_s) ] maps to the same relation among and , recovering without a target logarithm.
For iid samples in a finite module , the next sample enlarges the generated submodule with probability at most : every strict inclusion at least doubles size, and the enlargement probabilities decrease. Hence A049 decoding fails with probability at most [ \frac{(A+1)\lceil\log_2N\rceil}{m+1}. ] With a polynomial upper bound on and polynomial , random self-reduction gives randomized polynomial-time ECDLP. Composite-modulus linear systems are solved in polynomial bit complexity by Smith/Hermite normal form. This covers arbitrary multi-coset values, noncyclic targets, and , with arbitrary coordinate/branch/denominator code inside the named factor subroutines.
The surviving factor/circuit route must have superpolynomial total alphabet, hide all factors in a final-only circuit, or use nonseparable additive/algebraic/Boolean intermediates with no polynomial-alphabet signed product interface.
The new theorem
Let be prime and let [ h\in\operatorname{Pic}(\mathcal O_f),\qquad \mathcal O_f=\mathbb Z+f\mathcal O_K, ] have exact order . The explicit target interface supplies the fundamental discriminant , conductor , and factorization of .
The conductor exact sequence gives exactly two cases.
- If maps to the identity in , the known effective conductor inverse maps it to a nonzero local component: a split finite-field subgroup, an inert norm-one torus, or a wild additive -line.
- If its maximal projection is nonzero, write . Because the imaginary-quadratic unit group has order dividing six, is the canonical virtual unit attached to . For infinitely many split , [ \lambda_{\mathfrak q}(\bar h) =\alpha^{(q-1)/r}\bmod\mathfrak q ] is nontrivial and hence injective on .
Binary ideal powering with relative-generator tracking retains as an -node compact power product. It can be evaluated -adically in polynomial time even when individual compact factors have -divisible denominators.
Under GRH for the normal Kummer closure, effective Chebotarev gives a Las Vegas expected-polynomial search and [ \log q=O(\log r+\log(\log|D_K|+2)). ]
Q004 consequence
For any nonzero source evaluator [ \phi:\langle P\rangle\to\operatorname{Pic}(\mathcal O_f), \qquad h=\phi(P), ] the target-side character from A028 satisfies [ \Lambda_h(\phi(xP))=\Lambda_h(h)^x ] in a multiplicative branch, or in the additive branch.
Thus an ordinary imaginary-quadratic class presentation is never an independent third transfer endpoint. If the composite source character is not anomalous or MOV/Frey--Rück, its novelty already lies in a direct source-to-finite-field character; the class layer is removable.
This is a factorization theorem, not a proof that cannot exist and
not a claim that every resulting finite-field character is pairing-derived.
It is strictly broader than A024 and A027 because it permits arbitrary
coordinate access, lifts, valuations, branches, direct MAKEFORM, external
conductor primes, and varying or unrelated maximal quadratic fields.
Prior-art boundary
- The conductor exact sequence and effective kernel inverse are classical: Hühnlein--Takagi and Castagnos--Laguillaumie.
- Virtual units and the Kummer pairing are classical class field theory.
- Compact ideal power products and relative generators are supported by Vollmer and Jacobson--Sawilla--Williams.
- Effective Frobenius-prime bounds are due to Lagarias--Odlyzko and Bach--Sorenson.
- The repository-original contribution is the complete effective conductor/maximal synthesis in A028.4 and its evaluator-independent Q004 consequence. Do not claim any ingredient separately as new.
- A bounded primary-source search through 2026-07-23 found no checked source stating this full prime-order computational dichotomy for imaginary-quadratic Picard targets. This remains an audited novelty claim, not a universal bibliographic proof.
Infinite-family checks
- A025 supplies an infinite succinct conductor-branch control family. It is pairing-derived and remains labeled as such.
- A029 supplies the uniform target-only family required by SG-30, for every odd prime , without an auxiliary prime or analytic hypothesis.
- Lim (2016) supplies the rigorous infinitude statement: for every fixed odd prime , infinitely many imaginary quadratic fields have a maximal ideal class of exact order . A028 gives infinitely many separating primes for every such target. This existence theorem is not a uniform succinct SG-30 constructor.
- A019 supplies the explicit maximal-branch regression fixture: [ D_r=1-4\cdot2^r,\quad \mathfrak a=(2,\omega),\quad \mathfrak a^r=(\omega). ] Its order discriminant is not proved fundamental for every prime , so it is not itself claimed as an infinite maximal-order family. The ten probed cases have nonzero maximal projection, certified by their nontrivial residue character. It is deliberately oversized and does not solve SG-30.
code/probe_kummer_class_character.pychecks ten primes , finds a nontrivial character in every case, and recovers every scalar. The permanent output isdata/probe_kummer_class_character_full_20260723.csv.- The session-12 A028/A031 snapshot had 128 passing tests and a 27-page
paper. The current session-21 verification is recorded in
LOG.mdand supersedes those counts.
Other established boundaries
- A023 reconciles the rational package with the closest discrete-logarithm interpolation literature. The overlap scale has direct prior art; call the full package a repository-original synthesis.
- A024 proves only in its fixed VFB model.
- A025 is a correct ordinary ring-class transfer but only a presentation of the known degree-two pairing target.
- A026's hoped-for effective-kernel novelty was rejected as 1999/2009 prior art.
- A027 proves the sharper source-CM intrinsic-support consequence: -local support gives an linearizer, while -local support forces trace two and embedding degree one.
Unconditional boundary
Ordinary Chebotarev proves infinitely many separating maximal-branch primes, and evaluation is polynomial once one is supplied. The checked unconditional effective bounds do not prove a uniform polynomial-time short-prime search in . Do not erase this caveat.
This is compatible with marking A028's ordinary-class factorization complete under the standing convention: the rigorous Hafner--McCurley class-group target route used there is itself recorded under ERH. It is not a claim that the later unrestricted cross-characteristic SG-39 converter has been constructed or excluded.
SG-30 - solved by A029
For every odd prime , take [ \mathcal O_r=\mathbb Z+r^2\mathbb Z[i], \qquad \Delta_r=-4r^4. ] The conductor residue has exact order modulo rational and Gaussian units. Its contracted ideal has raw form , which reduces in two elementary steps to [ [r^2,2r,r^2+1]. ] The output has bits, lies inside SG-25, and is constructed and certified in deterministic polynomial time. Its subgroup logarithm is the explicit additive map .
This is a target-only theorem. It does not provide a source evaluator and is exactly the wild conductor branch exposed by A028.
Files that matter
attempts/A028-kummer-residue-factorization.md: closing theorem and proof.attempts/A029-uniform-wild-ring-class-target.md: unconditional SG-30 constructor and certificate.attempts/A030-ring-class-evaluator-completeness.md: equivalence between the A029 evaluator and polynomial-time ECDLP.attempts/A031-same-characteristic-affine-endpoints.md: arbitrary-evaluator matrix theorem collapsing same-characteristic affine targets.attempts/A032-ordinary-class-endpoint-trichotomy.md: exact cross-characteristic residual.attempts/A033-cross-characteristic-lift-barrier.md: unique same-prime lift, second-prime section ambiguity, and dense global degree barrier.attempts/A034-canonical-residue-rebasing-barrier.md: least-residue subgroup-sum theorem, EDS/character incompatibility, and defect criterion.attempts/A035-cyclotomic-character-torsor-barrier.md: exact nonzero character moduli, naturality no-go, and dense cyclotomic rank barrier.attempts/A036-frobenius-orientation-barrier.md: arbitrary-algorithm Frobenius-stabilizer obstruction, norm collapse, and sharp oriented boundary.attempts/A037-gauss-period-degree-product.md: exact local/global Gaussian-period degree product and trace-compression barrier.attempts/A038-translation-filter-spectral-barrier.md: fully oriented single-feature Fourier deconvolution and exponential translated-probe lower bounds.attempts/A039-spectral-defect-resultant-barrier.md: generalized defect/tap product and lifted-feature exceptional-prime criterion.attempts/A040-multifeature-galois-span-barrier.md: rational -dimensional Galois-span theorem and fixed-dictionary exceptional-resultant barrier.attempts/A041-polynomial-feature-algebra-barrier.md: unital full-Hilbert rank theorem, nonlinear exceptional-resultant barrier, and exact joint injectivity criterion.attempts/A042-piecewise-polynomial-character-barrier.md: full branch-rank theorem, linear- tradeoff, and partition-uniform subset-resultant barrier.attempts/A043-galois-schur-denominator-barrier.md: arbitrary-preprocessing width/depth cut, projective-denominator orbit bound, and fixed-denominator weighted-resultant barrier.attempts/A044-mixed-radix-denominator-escape.md: square-root target-mixed denominator construction and matching pure-root envelope lower bound.attempts/A045-binary-character-factorization.md: exact multidigit envelope, logarithmic binary compression, and exposed-factor ECDLP completeness.attempts/A046-public-exponent-factor-decoder.md: representation-independent decoder for every exposed public cyclotomic factor tuple.attempts/A047-calibration-span-decoder.md: unlabelled cyclotomic-coset factor decoder from known-multiple calibration.attempts/A048-direct-summand-factor-projection.md: exact public retraction and multi-coset projection in the direct-summand case.attempts/A049-finite-module-factor-decoder.md: arbitrary finite-abelian polynomial-alphabet factor decoder over .attempts/A027-intrinsic-conductor-support.md: source-side refinement.attempts/A026-conductor-kernel-universality.md: prior-art control.attempts/A025-pairing-to-ring-class-transfer.md: pairing control.attempts/A024-valuation-factor-base-model.md: VFB lower bound.attempts/A023-interpolation-prior-art-audit.md: prior-art reconciliation.code/probe_kummer_class_character.py: maximal Kummer regression driver.code/construct_sg30_ring_class_target.py: uniform A029 constructor.code/probe_affine_endpoint_collapse.py: A031 semisimple/unipotent certificate fixtures.code/probe_galois_schur_denominator.py: A043 Schur-capacity, orbit-bound, and exact order-11 fixed-denominator certificates.code/probe_mixed_denominator_grid.py: A044 coefficient-rank, projective-orbit, and incidence-graph certificates.code/probe_multidigit_character_factorization.py: A045 mixed-radix factor-product, exact common-rank, and binary scalar-reconstruction certificates.code/probe_public_exponent_factor_decoder.py: A046 signed-factor exponent-table decoder certificates for A044 and A045.code/probe_calibration_span_decoder.py: A047 incidence-span decoder, deterministic spanning set, and random-calibration certificates.code/probe_direct_summand_factor_projection.py: A048 projector, two-coset factor fixture, and repeated- obstruction.code/probe_finite_module_factor_decoder.py: A049 raw multi-coset composite-module decoder certificate.code/probe_lift_section_ambiguity.py: A033 finite section certificate.code/probe_residue_rebasing.py: A034 residue-sum, defect, and Ward certificates.code/probe_character_torsor.py: A035 global/local degree and character torsor certificate.code/probe_frobenius_orientation.py: A036 Frobenius orbit, orientation divisibility, and norm certificate.code/probe_gauss_period_product.py: A037 Frobenius subgroup, coset partition, and degree-product certificate.code/probe_translation_filter.py: A038 orbit-gap, dense-filter, and natural-coordinate spectrum certificates.code/probe_spectral_defect.py: A039 defect/tap, circulant-resultant, and sharp sparse-spectrum certificates.code/probe_multifeature_galois_span.py: A040 rational-rank, cofactor-annihilator, exceptional-prime, and eight-probe certificates.code/probe_polynomial_feature_algebra.py: A041 Hilbert-rank profile, degree-three obstruction, and exceptional/nonexceptional degree certificates.code/probe_piecewise_polynomial_character.py: A042 agreement profiles, branch capacity, and oversized-subset resultant certificates.RATIONAL_TRANSFER_REVIEW.md: authoritative rational theorem wording.NOTES.md,STATE.md,LOG.md: synchronized current status.
What I would tell my replacement
Do not call SG-30 a solution of the source problem. A030 proves the opposite: an evaluator into that target is ECDLP-complete. Preserve A028's GRH boundary and A029's unconditional status. The new substantive theorem is A031, which uses only the order- image matrix and no rational-map model. Do not weaken it back to the commutative case. The only ordinary-class endpoint not collapsed by A030--A032 is the cross-characteristic converter in SG-39. A033 says not to retry canonical lifting, CRT, or a dense global torsion field. A034 says not to retry a perfectly periodic EDS as though it were a character, or to reduce a prime-field character's least positive integer representatives modulo a second prime. A035 says not to retry any base-change-natural common cyclotomic character or dense finite global parameter algebra. A036 says not to retry a basis-free construction or a trace/norm/symmetric conjugate aggregate: full target orientation of Frobenius orbit divisible by is necessary. A037 further says not to replace that orientation by its Gaussian period: the complementary global degree is . A038 says not to retry one spectrally full source feature with a linear translated filter: that costs exponentially many probes even with the full orientation public. A039 says that a polynomial-tap sparse-spectrum escape needs exponentially many holes and, for a nonconstant integer-lifted feature, an exceptional target prime dividing its cyclotomic resultant. A040 says that a fixed finite integer feature dictionary cannot use linear multi-channel cancellation outside another explicit finite resultant-prime set; the eight-probe order- fixture proves those exceptions can occur. A041 says not to retry a bounded-degree or explicitly sparse polynomial in fixed features: its evaluation code must have full dimension, and a lower rank is possible only at an explicit resultant prime. It also says not to confuse dense interpolation from an injective raw encoding with an efficient evaluator. A042 says ordinary polynomial branching does not evade this: branch count trades only linearly against monomial capacity outside one uniform exceptional set. A043 says arbitrary preprocessing before a rational interface does not help a bounded Schur suffix, and a projectively orientation-free final denominator gives no escape. A044 says not to seek a linear rank--rank completion: a maximally oriented mixed-radix denominator has a sharp square-root common envelope. Its definition reads the unknown scalar's remainder and quotient, so the next theorem must charge computation of those labels rather than only final algebraic rank. A045 strengthens that warning: binary digit factors compress the common envelope to logarithmic dimension, but any implementation exposing them is exactly ECDLP-complete. A046 generalizes this to every exposed public cyclotomic alphabet of polynomial total size. A047 removes the public alphabet, exponent labels, and coset representatives whenever each finite factor image lies in one unknown cyclotomic coset. A048 projects multi-coset factors in the direct-summand case. A049 is now authoritative: formal finite-module calibration closes every exposed signed factor tuple of polynomial total alphabet in any polynomial-bit finite abelian target, even with many cosets, a noncyclic target, or repeated -torsion. Do not retry exponent labeling, coset projection, or cofactor arguments. The next theorem must address a superpolynomial alphabet, final-only circuit, or nonseparable additive/algebraic/Boolean interface.