| Generic-group lower boundR-GENERIC-LOWER-BOUND |
Guardrail |
classical-generic |
P0 |
Retain as a mandatory comparison and scope guard; no new experiment. |
| Baby-step giant-step and Pollard rhoR-GENERIC-BASELINE |
Baseline |
classical-single-target-plain, classical-generic |
P0 |
Use as the benchmark comparator in the evaluation harness. |
| GLV endomorphism accelerationR-GLV |
Constant factor |
classical-single-target-plain |
P0 |
Keep as target structure available to a selected route; do not treat it as a standalone attack. |
| Pohlig-Hellman subgroup reductionR-POHLIG-HELLMAN |
Ruled out for target |
classical-single-target-plain |
P0 |
Retain as a machine-checked elimination certificate. |
| MOV, Frey-Ruck, and Tate/Weil pairing transferR-PAIRING-TRANSFER |
Ruled out for target |
classical-single-target-plain |
P0 |
Keep the target-specific exclusion; defer a full pairing library unless a new route needs it. |
| Smart, Satoh-Araki, and Semaev anomalous-curve liftingR-ANOMALOUS-PADIC |
Ruled out for target |
classical-single-target-plain |
P0 |
Retain the formal exclusion; do not build an elliptic formal-group stack for this target now. |
| Weil descent and GHS-style transferR-WEIL-DESCENT |
Ruled out for target |
classical-single-target-plain |
P1 |
Document as a target-applicability exclusion; no formal stack now. |
| Prime-field index calculusR-PRIME-FIELD-INDEX-CALCULUS |
Open, parked |
classical-single-target-plain |
P1 |
Preserve evidence and prerequisites; wait for explicit route selection before any new experiment. |
| GLV-symmetrized Semaev systemsR-GLV-SEMAEV |
Open, parked |
classical-single-target-plain |
P1 |
Keep GLV-SEMAEV-ITER-001 closed without a solver run. Accept only a materially different phase-preserving mechanism with an exact recovery map, orbit tags, excluded components, a falsifiable full-cost prediction, and an independent validator through TASK-008 before any new decision. |
| Petit-style composed rational mapsR-PETIT-COMPOSED-MAPS |
Open, parked |
classical-single-target-plain |
P2 |
Keep the route parked. TASK-023 through TASK-025 completed the exact chart cover, necessary infinity-stratum filters, and conditional single-affine-chart propagation. TASK-026 then consumed its one external synthetic-toy authorization: all 3000000 trials completed, 911 exact relations were accepted, 907 were affine regular, and all six curve-arm regularity gates passed. REO-2026-07-31-001 records the result. This supports the bounded enabling claim that the named regular locus is usable in the frozen toy construction. Matched orbit/plain controls retained no H_NEW qualifying size, so the GLV-specific explanation is bounded negative and the terminal is CLASSIFY_AS_KNOWN_LOCAL_SIMPLIFICATION. The result is not source-faithful PKC relation generation, rank, solver scaling, recovery, total cost, 256-bit persistence, or an ECDLP improvement. Only formulate and review a source-faithful, non-executable HYP-M16-SOLVER-SLOPE-001 proposal with end-to-end metrics and scaling death criteria. Keep every TASK-026 rerun, production mask sweep, solver, experiment, route rejection, route promotion, cost claim, and exact-target inference closed until a separate dated authorization. Keep the auxiliary-curve cell parked until a primary source supplies a finite family or search domain with a completeness criterion. |
| Elliptic divisibility sequences and division-polynomial re-encodingsR-EDS-DIVISION-POLYNOMIAL |
Open, parked |
classical-single-target-plain |
P2 |
Keep HYP_WARD_EDS_001 parked; finish no additional point-division bridge unless a selected route needs it. |
| Isogeny, endomorphism-ring, and Frobenius transferR-ISOGENY-ENDOMORPHISM-TRANSFER |
Monitor |
classical-single-target-plain |
P3 |
Monitor literature and reuse GLV facts; no build now. |
| Multi-target and reusable-precomputation tradeoffsR-MULTI-TARGET-PRECOMPUTATION |
Conditional inputs |
classical-conditioned |
P1 |
Represent in the evaluation contract; no experiment in this phase. |
| Interval DLP, partial-key knowledge, and auxiliary-power algorithmsR-INTERVAL-AUXILIARY-INPUT |
Conditional inputs |
classical-conditioned |
P2 |
Keep as a scope category for future protocol or leakage analyses. |
| Hidden-number and lattice attacks on biased or reused ECDSA noncesR-HNP-NONCE-LEAKAGE |
Separate threat model |
implementation-leakage |
P1 |
Preserve as a separate security track; no lattice foundation build for the primary objective now. |
| Invalid-curve, twist, fault, and side-channel routesR-PROTOCOL-FAULT-SIDECHANNEL |
Separate threat model |
implementation-leakage |
P1 |
Record scope; do not expand the Lean substrate until a concrete implementation-verification goal exists. |
| Fault-tolerant quantum ECDLPR-QUANTUM-SHOR |
Separate threat model |
fault-tolerant-quantum |
P1 |
Update the registry estimate and monitor primary literature; do not build a quantum Lean stack now. |