Submitted:
23 September 2026
Posted:
24 September 2026
You are already at the latest version
Abstract
We explore the complexity-theoretic scenario in which \(\mathrm{P} = \mathrm{NP}\) but \(\#\mathrm{P} \neq \mathrm{FP}\), and ask what it would imply for the Birch–Swinnerton-Dyer conjecture (BSD) for the congruent number curves \(E_n: y^2 = x^3 - n^2x\). Neither hypothesis of the scenario is known to hold; the aim is to determine rigorously what follows if both do. The link is Tunnell's theorem, which expresses the congruence of \(n\) through the representation counts \(C_n\) and \(D_n\) of \(n\) by the ternary forms \(8x^2 + 2y^2 + 64z^2\) and \(8x^2 + 2y^2 + 16z^2\). We prove four unconditional results. First, for square-free \(n \equiv 2 \pmod 8\) one has \(D_n = 2h(-4n)\), where \(h(-4n)\) is the class number of \(\mathbb{Q}(\sqrt{-n})\), while \(D_n = C_n = 0\) for square-free \(n \equiv 6 \pmod 8\). Second, class numbers of imaginary quadratic orders are computable in \(\mathrm{FP}^{\Sigma_2^{\mathrm{P}}}\), hence in \(\mathrm{FP}\) if \(\mathrm{P} = \mathrm{NP}\). Third, the difference \(C_n - h(-4n)\) is the \(n/2\)-th Fourier coefficient of Tunnell's weight-\(3/2\) cusp form, so that, by Tunnell's \(L\)-value formula and Ono's evaluation of the BSD prediction, BSD for \(E_n\) gives \(C_n = h(-4n) \pm \tau(n/2)\sqrt{|\mathrm{Sha}(E_n)|}\) in rank zero and \(C_n = h(-4n)\) in positive rank. Fourth, any exact counting reduction from \(\#\mathrm{SAT}\) to \(D_n\) would collapse the polynomial hierarchy to \(\Delta_3^{\mathrm{P}}\). Our main theorem combines these facts with the enumerative-counting theorem of Cai and Hemachandra: if \(\mathrm{P} = \mathrm{NP}\) and \(\#\mathrm{P} \neq \mathrm{FP}\), and if (i) \(\#\mathrm{SAT}\) reduces exactly to \(C_n\) on square-free \(n \equiv 2 \pmod 8\) (the Cusp Reduction Conjecture) and (ii) positivity of the rank of \(E_n\) and, in rank zero, the order of the Tate--Shafarevich group of \(E_n\) are polynomial-time computable with an NP oracle (the Sha-Tractability Hypothesis), then BSD fails for infinitely many of the curves \(E_n\); since Rubin's theorems give the finiteness of \(\mathrm{Sha}(E_n)\) and the odd part of the BSD formula whenever \(L(E_n,1) \neq 0\), the failure must lie in the rank statement or in the \(2\)-part of the rank-zero formula. We make explicit that the conclusion is conditional on (i) and (ii), and that, logically, the scenario forces the failure of at least one of BSD, (i) and (ii).
Keywords:
computational complexity
; #P-completeness
; Tunnell’s theorem
; Birch–Swinnerton-Dyer conjecture
; congruent numbers
; Tate–Shafarevich group
; class numbers
; ternary quadratic forms
; P Versus NP
MSC: 11G05; 11G40; 68Q15; 11E20; 11R29; 68Q17
1. Introduction
The P versus NP problem stands as one of the most fundamental open questions in computer science and mathematics [1,2]. Its counting analogue, the question whether , is at least as hard: implies , while the converse implication is not known. It is therefore consistent with present knowledge that
a situation in which every NP search problem is easy but exact counting remains hard. We call (1) the scenario. Neither of its two parts has been proved, and most researchers expect ; the scenario is nevertheless a precise and non-contradictory hypothesis, and this paper asks what it would imply for the Birch–Swinnerton-Dyer conjecture (BSD) [3] for the congruent number curves. The bridge between the two worlds is Tunnell’s theorem [4].
1.1. Background on Complexity Classes
The complexity class #P, introduced by Valiant [5,6], consists of counting problems associated with NP decision problems. Formally, a function belongs to #P if there exist a polynomial-time verifier V and a polynomial p such that
A function f is #P-complete if and every reduces to f. Several notions of reduction are in use: parsimonious reductions ( with polynomial-time computable), many-one counting reductions in the sense of Zankó [7] ( with polynomial-time computable), and polynomial-time Turing reductions. The Cook–Levin reduction shows that #SAT is #P-complete under parsimonious reductions, whereas Valiant’s proof that the permanent is #P-complete uses Turing reductions [5]. Reductions that preserve counts only up to a polynomial factor are not sufficient for exact counting (Remark 7).
The functional class FP consists of functions computable in deterministic polynomial time. Being able to count witnesses lets one decide whether at least one exists, so . The converse is open: even if , the threshold predicate (with k in binary) is PP-complete [8], and PP is not known to collapse to P under . By Toda’s theorem [9], [10]. In terms of decision classes the scenario (1) reads and .
1.2. Background on Congruent Numbers and Tunnell’s Theorem
A positive integer n is called a congruent number if it is the area of a right triangle with rational side lengths [11]. Equivalently, n is congruent if and only if the elliptic curve
has positive rank. Since n is congruent if and only if is congruent for every positive integer k, it suffices to treat square-free n.
Theorem 1
(Tunnell [4]). Let n be an even square-free positive integer.
- 1.
- If n is congruent, then .
- 2.
- Conversely, if the Birch–Swinnerton-Dyer conjecture holds for the elliptic curve , then implies that n is congruent.
The first part is unconditional: Tunnell expressed as a non-zero constant multiple of the square of a Fourier coefficient of a weight- cusp form (see Proposition 3), using the Shimura correspondence [12] and Waldspurger’s theorem [13]; the theorem of Coates and Wiles [14] then shows that positive rank forces . An analogous statement, with two other ternary forms, holds for odd n; we only use the even case.
The congruum construction, dating back to Fibonacci, provides an explicit family of congruent numbers [15]. For integers the number is the common difference of the arithmetic progression of squares , and it is four times the area of the integral right triangle with legs and .
1.3. The Scenario and the Main Theorem
Tunnell’s counts are natural candidates for carrying -hard information, because they are functions of n whose arithmetic is controlled by BSD. We show that the two counts behave very differently. On square-free the count is twice a class number (Proposition 1), and class numbers are computable in polynomial time once (Theorem 5); thus cannot carry -hardness in the scenario, and in general an exact reduction to would collapse the polynomial hierarchy (Theorem 12). The count , by contrast, equals the same class number plus the Fourier coefficient of Tunnell’s cusp form (Lemma 3), and under BSD this coefficient is determined, up to sign, by the order of the Tate–Shafarevich group of (Proposition 4). BSD therefore converts knowledge of into knowledge of up to two candidates, and two candidates are enough to count exactly by the theorem of Cai and Hemachandra [16]. This yields our main result, stated in full as Theorem 8 and Corollary 2:
Main Theorem. Assume and . If the Cusp Reduction Conjecture (Conjecture 6) and the Sha-Tractability Hypothesis (Conjecture 7) hold, then the Birch–Swinnerton-Dyer conjecture fails for infinitely many of the curves with n square-free and , and the failure lies either in the rank statement or in the 2-primary part of the rank-zero formula.
The two additional hypotheses are indispensable to the argument and are not known to hold; we discuss their status in detail (Section 8.1). Logically, the Main Theorem says that the scenario is incompatible with the conjunction of BSD, the Cusp Reduction Conjecture and the Sha-Tractability Hypothesis. The emphasis of this paper is on the consequence for BSD, but we state the alternatives explicitly wherever they matter.
1.4. Main Contributions
- Class numbers in the polynomial hierarchy (Theorem 5). The function lies in , hence in FP under ; consequently so does on even square-free n (Corollary 1).
- The BSD bridge (Section 5). Under BSD for , in rank zero and in positive rank (Proposition 4).
- The Main Theorem (Theorem 8, Corollary 2). In the scenario, the Cusp Reduction Conjecture and the Sha-Tractability Hypothesis force BSD to fail for infinitely many .
- The -route is closed (Section 6). An exact Reduction Conjecture for (Conjecture 9) is false in the scenario (Corollary 3) and in general implies (Theorem 12); its approximate form is vacuous under (Remark 7). This explains why the cusp part, and hence BSD, must enter.
- The descent cascade (Section 7). We state a corrected Solution Density Conjecture, prove the size and termination properties of the descent cascade built on it, and show that the cascade is redundant for exact counting (Proposition 5).
1.5. Organization
Section 2 fixes notation and states the precise form of BSD used. Section 3 develops the arithmetic of and . Section 4 treats counting under complexity assumptions and proves the class-number theorem. Section 5 contains the BSD bridge, the two hypotheses, and the Main Theorem. Section 6 shows that the route through is closed. Section 7 analyses the descent cascade. Section 8 discusses the status of the hypotheses, falsifiability and prior work. Section 9 and Section 10 contain extended proofs and further remarks, and Section 11 concludes. The appendices contain pseudocode and numerical data.
2. Preliminaries
2.1. Notation and Conventions
For a function , we write if there exist constants such that for all sufficiently large n. For an integer m, we denote by its bit length, , where is the absolute value; for a problem instance I, is the size of its encoding. For a positive integer g we write for its square-free kernel, the unique square-free s with for some integer k, for the exponent of 2 in g, for the number of divisors of g, and for the number of distinct prime divisors of g; for square-free g, .
For with we write for the number of -classes of primitive positive definite binary quadratic forms of discriminant ; when is a fundamental discriminant this is the class number of . denotes the Hurwitz class number, which counts all (not necessarily primitive) classes of discriminant , weighted by and for classes of forms equivalent to multiples of and respectively, and which is zero unless [17]. For a fundamental discriminant one has .
We write , and . We use the classes and of the polynomial hierarchy PH; for a class of languages, is the class of functions computable in deterministic polynomial time with an oracle for a language in , and FBQP is the class of functions computable with bounded error in quantum polynomial time.
2.2. The Birch–Swinnerton-Dyer Conjecture for
For an elliptic curve let be the rank of , its Tate–Shafarevich group, its real period (counted with the number of real components), its Tamagawa numbers and its torsion subgroup.
Conjecture 2
(BSD for E). The order of vanishing of at equals ; the group is finite; and if , then
We say that BSD holds for if Conjecture 2 holds for . Only the rank statement and the rank-zero formula are used in this paper; the leading-term formula in positive rank plays no role.
2.3. The Scenario and the Other Assumptions
The hypotheses used by each result are stated in that result. We use:
- P = NP. This implies and, by induction on the levels, ; in particular and .
- The scenario: and .
- BSD for some or all of the curves , as specified in each statement.
- GRH, the generalized Riemann hypothesis, used only in Corollary 4 and in the heuristic analysis of Section 7.
Under , integer factorization is computable in polynomial time: the decision problem “does m have a divisor in ?” is in , and prime factors are then found by binary search. Hence , , and are computable in polynomial time, and so are all NP search problems by self-reducibility. We do not assume that exact counting becomes polynomial-time under ; in the scenario it does not.
2.4. Diophantine Representations
Theorem 3
(Matiyasevich [18]). For every recursively enumerable set there is a polynomial with integer coefficients such that if and only if has a solution .
The theorem, which completes work of Davis, Putnam and Robinson, applies to every language in NP, but it gives no bound on the size of the solutions in terms of , and a single witness of an NP verifier typically corresponds to infinitely many solutions. Whether every NP set admits a Diophantine representation with polynomially bounded solutions is open; for restricted equations such as , solvability in natural numbers is already NP-complete [19].
3. Arithmetic of Tunnell’s Counting Functions
3.1. An Elementary Ceiling
Lemma 1
(Elementary ceiling). For every there is a constant such that and for all . In particular .
Proof.
If , then , so z takes at most values. For fixed z, put ; the pair satisfies , so the number of such pairs is at most , the number of representations of k as a sum of two squares. By Jacobi’s formula , and . Hence . The argument for is identical with in place of , and the final statement follows from . □
3.2. Local Vanishing and the Class-Number Formula
Lemma 2
(Local vanishing). Let n be an even square-free positive integer. If , then ; in particular Tunnell’s identity holds trivially.
Proof.
Write with m odd; means . A representation gives , while or , a contradiction. The same argument applies to . □
For the root number of is , so BSD predicts that all such square-free n are congruent; unconditionally, is congruent for every prime (see [20]). Lemma 2 shows that in this residue class Tunnell’s counts carry no information. The informative even residue class is , and we set
Proposition 1
(Class-number formula). For every ,
where is the class number of . Consequently , , and for Tunnell’s identity is equivalent to .
Proof.
Write , so is odd and square-free. Dividing by 2 shows that , the number of representations of m by . The form has class number one (its genus consists of a single class), and for such forms the Siegel–Weil average collapses to the representation number itself; on this basis Bringmann and Kane proved [17] (Lemma 4.2) that, for every ,
with the constant tabulated in [17] (Appendix B): it equals 2 for , 4 for , 12 for , and 0 in the remaining classes. The proof in [17] is unconditional: both sides are modular forms of weight on an explicit congruence subgroup, and the identity is verified on the number of coefficients prescribed by the valence formula. For our we obtain . Since m is odd, is not a discriminant, so . Since m is odd and square-free, is a fundamental discriminant, and it is smaller than , so . Hence . Dirichlet’s class number formula and the elementary bound give , and gives . The last assertion is immediate. □
The identity has also been confirmed by exhaustive computation for all with and for 1500 random with (Appendix B).
3.3. Tunnell’s Cusp Coefficient
Let
This is the weight- cusp form of level 128 attached by Tunnell to the even congruent number problem [4,11,21].
Lemma 3
(Tunnell’s coefficient). For every odd and ,
In particular, for one has , and for .
Proof.
Write . Gauss’s identities and , both special cases of Jacobi’s triple product identity [22] (Theorem
2.8), multiply to
Replacing q by , multiplying by q, and using , we obtain
Multiplying by , the coefficient of is , the sum running over all with t odd and . Since m is odd, the parity condition on t is automatic. Splitting according to the parity of y: the triples with even are in bijection with representations , i.e., with the representations counted by ; all triples are in bijection with the representations counted by (Proposition 1). Hence . The remaining statements follow from Proposition 1 and Lemma 2. □
Remark 1
(On the modular interpretation). The series and are theta series of positive definite ternary forms, hence modular forms of weight , each an Eisenstein part (given by the Siegel–Weil formula [23] as a product of local densities) plus a cusp part. Proposition 1 and Lemma 3 say that, at , coincides with a genus quantity while is that genus quantity plus the cusp coefficient . Deligne’s theorem [24] (the Ramanujan–Petersson conjecture) concerns integral weight and does not apply here; for weight the best known bounds for cusp-form coefficients at square-free arguments are of the shape with a fixed [25,26], and Duke and Schulze-Pillot [27] showed that a positive definite ternary form represents every sufficiently large square-free integer that it represents locally, apart from finitely many spinor-exceptional square classes, with (ineffectively).
3.4. Congruums and the Supply of Admissible Integers
Lemma 4
(Congruums). Let be integers and . Then is a square-free congruent number, and it is even if and only if is odd. Moreover, the map has infinite fibres: and have the same image for every integer .
Proof.
The triangle with legs and has area , so is congruent, hence so are g and , since congruence is invariant under multiplication by rational squares. Writing gives with , which proves the parity statement. Finally, yields , which has the same square-free kernel as g. □
Remark 2
(Supply). Because the fibres are infinite, counting pairs gives no lower bound on the number of distinct congruent numbers produced; and dividing g by before taking the square-free kernel always produces an odd number, so that construction never reaches . The set has natural density zero in : Smith [28] proved that of square-free are not congruent. Numerically, among the 20260 elements of below , exactly 2455 satisfy (Appendix B). No lower bound on is used in any proof. The complement , which has density one, is where, under BSD, the cusp coefficient of Lemma 3 is non-zero, and it is where Section 5 operates.
4. Counting Under Complexity Assumptions
4.1. Decision Versus Counting
Lemma 5
(Decision versus counting). Assume .
- 1.
- Square-freeness, the computation of , , , , and every predicate in PH are decidable or computable in polynomial time.
- 2.
- The threshold predicate for , with k in binary, is PP-complete; it is not known to be in P under , and in the scenario (1) it is not in P.
- 3.
- Tunnell’s test , and under BSD the predicate , are decidable in polynomial time with one query to a oracle (for ).
- 4.
- and are functions of n.
Proof.
(1) See Section 2. (2) PP-completeness of the threshold predicate is classical [8,10]. If it were in P, every PP language would be in P and hence , which gives (each bit of a value is decidable in ), contradicting the scenario. (3) is polynomial-time computable under by Corollary 1 below; query the oracle for and compare. Square-freeness and are decided by (1), and under BSD Theorem 1 makes the test equivalent to congruence. (4) A witness is a triple of bit length , checked in polynomial time. □
Lemma 6
(Small counts). Assume . Let with verifier V and let q be a polynomial. There is a polynomial-time algorithm that, on input x, either outputs or correctly reports .
Proof.
Let ⪰ be the lexicographic order on . The language is in NP, hence in P. By prefix search one finds the lexicographically least witness , or learns that none exists, in polynomial time. Starting from and replacing u by the successor of the witness just found, at most rounds enumerate all witnesses if there are at most of them, and otherwise exhibit distinct witnesses. □
Proposition 2
(Approximate counting, Stockmeyer). For every and every polynomial q, there is a function with for all x [29]. In particular, under , -approximations of all functions are computable in polynomial time.
Remark 3
(Why approximation does not suffice). Stockmeyer’s algorithm runs in time polynomial in and , so any inverse-polynomial relative error is affordable. What approximation cannot deliver is exactness: when may be as large as , a relative error of leaves exponentially many candidate values. This is why the scenario (1) is consistent with Proposition 2.
Theorem 4
(Enumerative counting, Cai and Hemachandra [16]). Suppose there is a polynomial-time computable function that maps every Boolean formula φ to a list of at most integers, for some fixed , one of which is . Then , and consequently .
The consequence follows from because every bit of a value is decidable in . We shall only need lists of length at most 2.
4.2. Class Numbers in the Polynomial Hierarchy
We use the standard facts [30] that every class of primitive positive definite forms of discriminant contains exactly one reduced form , with , if or , and ; that reduced forms have encoding length ; and that composition followed by reduction, the group operation of the form class group , is computable in time polynomial in . Consequently can be computed by repeated squaring in time polynomial in and in the bit lengths of the exponents. We also use the crude bound
and the polynomial-time computability of Hermite normal forms of integer matrices [31].
Theorem 5
(Class numbers in ). The function , defined for with , lies in . In particular, if , then is computable in deterministic polynomial time.
Proof.
Let , write for the class of the principal form, and put by (2). If the procedure below terminates immediately with the empty generating set and outputs 1.
Step 1: a small generating set. For a list of reduced forms, every element of has the form with . Hence the language
is in , because t never exceeds and all quantified objects have polynomial length. Starting from , we use with prefix search to find a reduced form , append it to S, and repeat until no such f exists. Each step at least doubles by Lagrange’s theorem, so the loop stops after steps with .
Step 2: the relation lattice. Let , , and . Since is surjective, , and . The Hermite normal form basis of is triangular with positive diagonal entries whose product is h and with off-diagonal entries bounded by the diagonal ones; hence all its entries lie in .
Step 3: lattice completion. For a finite list B of integer vectors, membership in the lattice spanned by B is decidable in polynomial time via Hermite normal forms [31]. Hence
is in NP. Starting from , we use with prefix search to find such v, append it to B, and repeat until none exists. Each appended vector strictly enlarges . At most t additions increase the rank. Between two rank increases, while has rank r and spans the rational subspace V, the index is a positive integer bounded by the determinant of , which is at most by Hadamard’s inequality applied to r independent vectors of B; each addition that does not increase the rank replaces this index by a proper divisor. Hence the loop stops after at most additions. Full rank is reached because the vectors are available to the search. When the loop stops, every vector of , in particular every vector of the Hermite normal form basis of , lies in , so . We output , where H is the Hermite normal form basis of ; this equals .
All steps run in time polynomial in with queries to and . Under both languages are in P. □
Corollary 1
(Complexity of ). Let TunnellCount denote the function on even square-free n. Then . In particular, if , then is computable in deterministic polynomial time for every even square-free n.
Proof.
An even square-free n satisfies or . If output 0 (Lemma 2); if output (Proposition 1), computed by Theorem 5. □
By Lemma 3, the same algorithm computes on every , where . All the arithmetic difficulty of Tunnell’s counts is therefore concentrated in the cusp coefficient at non-congruent .
5. The Birch–Swinnerton-Dyer Bridge and the Main Theorem
5.1. Tunnell’s L-Value Formula and Ono’s Evaluation
Proposition 3
(Tunnell, Ono). Let . Then:
- 1.
- , where is an absolute constant; in particular if and only if .
- 2.
- If BSD holds for and , then and .
- 3.
- If BSD holds for and , then , i.e., .
Proof.
With odd and square-free, the curve is , and is the form of [21]. Part (1) is Tunnell’s formula [4] in the normalization of [21] (Eq. (3)). Part (2) is [21] (Eq. (4)), which Ono derives by inserting (1) and the local invariants of (periods, Tamagawa numbers, and ) into the rank-zero formula of Conjecture 2; the result is ; the statement follows from by [14]. Part (3) follows from (1) and the rank statement of Conjecture 2. □
We have checked the analytic content of Proposition 3(2), namely , numerically in PARI/GP for the first 60 elements of and for 25 random elements of below 6000, computing from and via Lemma 3 (Appendix B).
Proposition 4
(The BSD bridge). Let and assume that BSD holds for . Define
Then is a non-negative integer and
Proof.
By Lemma 3, . If , then unconditionally [14], so by Proposition 3(1), and . If , then by BSD, so and Proposition 3(2) gives ; since is an integer and , is a non-negative rational whose square is an integer, hence an integer. □
Proposition 4 is the precise sense in which BSD carries computational content: it expresses the function , up to a sign, through the class number , the elementary quantity , and the algebraic invariants and . Part of this relation is known unconditionally. Since has complex multiplication by , Rubin’s theorems apply: if , then is finite [32], and for every prime p not dividing the number of roots of unity of , i.e., for every odd p, the p-part of the rank-zero formula of Conjecture 2 holds [33]. Hence, when , the odd part of equals the odd part of unconditionally. What BSD adds, and what Proposition 4 needs, is the 2-primary part of the rank-zero formula and the implication .
5.2. The Two Hypotheses
Conjecture 6
(Cusp Reduction Conjecture). There exist functions R, α, β, computable in polynomial time with an NP oracle, such that for every Boolean formula φ: , and are integers, and
Conjecture 6 is a many-one counting reduction in the sense of Zankó [7] from to on . By Lemma 3 and Corollary 1, it is equivalent under to the same statement with replaced by the cusp coefficient , suitably shifted. Unlike its analogue for (Conjecture 9), it is not refuted by the results of Section 6: no algorithm in the polynomial hierarchy is known for .
Conjecture 7
(Sha-Tractability Hypothesis). There is a function S, computable in polynomial time with an NP oracle, such that for every :
with no requirement on in the remaining case ( and infinite).
Conjecture 7 is a statement about the algebraic groups and ; it does not mention L-functions or theta series, and BSD is not assumed in its formulation.
5.3. The Main Theorem
Theorem 8
(Main Theorem). Assume , the Cusp Reduction Conjecture (Conjecture 6) and the Sha-Tractability Hypothesis (Conjecture 7). Assume further that BSD holds for for all but finitely many . Then .
Proof.
Let be the finite set of n for which BSD fails for , and fix the finite table . Under the functions R, , , S are computable in polynomial time (Section 2). Consider the following procedure (Algorithm A1 in Appendix A) on input with v variables:
- Compute , , and .
- If , output the single value read from the table.
- Otherwise compute (Theorem 5), (by factoring m) and . If s is not a perfect square, output the empty list; otherwise let .
- Output the list of those values among and that are integers in .
All steps take polynomial time. We claim that the output list always contains . If this holds by Conjecture 6. If , BSD holds for , so is finite and, by Conjecture 7, with as in Proposition 4 (both when and when ). In particular s is a perfect square and . By Proposition 4, for one choice of sign, and by Conjecture 6, , which is an integer in . Hence is in the list. The list has at most two elements, which is for any , so Theorem 4 applies and yields . □
Corollary 2
(Principal consequence). Assume and . If the Cusp Reduction Conjecture and the Sha-Tractability Hypothesis hold, then the Birch–Swinnerton-Dyer conjecture is false for infinitely many of the curves with n square-free and . More precisely (Remark 4), for infinitely many such n either while , or and the 2-primary part of differs from the BSD prediction.
Proof.
If BSD failed for only finitely many with , Theorem 8 would give , contradicting the hypothesis. □
Remark 4
(Which part of BSD fails). The proof of Theorem 8 uses, for , exactly three consequences of BSD for : that implies ; that is finite when ; and the rank-zero formula in the form of Proposition 3(2). (The implication is unconditional [14].) When , the second consequence and the odd part of the third are theorems of Rubin [32,33] (see the discussion after Proposition 4). Hence, under the hypotheses of Corollary 2, for infinitely many one of the following holds: has rank zero although (so n satisfies Tunnell’s criterion without being congruent); or and the 2-part of differs from the 2-part of . The possibility that is infinite in rank zero with is excluded by [32].
Remark 5
(Logical status). Corollary 2 is a theorem; its hypotheses are not. Stated symmetrically, Theorem 8 shows that the scenario (1) is incompatible with the conjunction of three statements: BSD for almost all with , the Cusp Reduction Conjecture, and the Sha-Tractability Hypothesis. The present paper explores the branch of this trichotomy in which the two computational hypotheses hold, where BSD must fail; the other branches, in which BSD holds and one of the hypotheses fails, are equally compatible with the scenario as far as is presently known. Concretely, under BSD and the Sha-Tractability Hypothesis the value is easy, so all the hardness demanded by the Cusp Reduction Conjecture would have to be carried by the single sign bit of ; Theorem 4 is precisely the statement that one bit per instance cannot carry -hardness unless . Section 8.1 discusses the evidence for each branch.
Remark 6
(Without the scenario). Without the assumption , the proof of Theorem 8 still shows that BSD for almost all with , the Cusp Reduction Conjecture and the Sha-Tractability Hypothesis together give a two-valued enumerator for computable in polynomial time with a oracle. We draw no further conclusion from this, because Theorem 4 is stated in [16] for unrelativized polynomial time.
6. The Route Through Is Closed
This section explains why the Main Theorem must involve and BSD: the analogous route through is closed, in the scenario and in general.
6.1. The Reduction Conjecture for
Conjecture 9
(Reduction Conjecture for ). There exist functions R, α, β, computable in polynomial time with an NP oracle, such that for every Boolean formula φ: , and are integers, and .
Remark 7
(The approximate form is vacuous). A weaker formulation would only require . This does not determine exactly, so it cannot support an exact counting algorithm; moreover, under the information it provides is already available, since by Proposition 2 can be approximated within a factor in polynomial time for every polynomial q. The same remark applies to Conjecture 6.
Remark 8
(Size constraint). By Proposition 1, for , so ; by Lemma 1 the same bound holds for Conjecture 6. For a formula with v variables and satisfying assignments, any valid R must output n of bit length at least .
Remark 9
(The parsimony obstruction). A natural construction pathway runs as follows: (Step 1) encode φ as a Diophantine polynomial Φ via Theorem 3; (Step 2) aggregate Φ into an integer of polynomial bit length; (Step 3) form the congruum , i.e., take , ; (Step 4) set and require , which by Lemma 4 forces odd. Each step is polynomial-time given factorization, but the step that should supply the counting identity is missing. (i) Matiyasevich’s theorem is not parsimonious: the number of integer zeros of Φ is not controlled by and is typically infinite. (ii) Nothing links to the Tunnell count of , which by Proposition 1 is a class number of . (iii) For a positive definite ternary form with one class in its genus, representation numbers at square-free integers are class numbers times explicit local factors [17,23]; for the Tunnell form this is Proposition 1, and Theorem 12 below shows that exact reductions to such counts collapse the polynomial hierarchy. Obstructions (i) and (ii) apply equally to Conjecture 6; obstruction (iii) does not, because has a non-trivial cusp part.
6.2. Single-Query Algorithm and Structural Equivalence
Theorem 10
(Correctness of Algorithm 1). Assume Conjecture 9. Then Algorithm 1 computes in deterministic polynomial time using polynomially many NP-oracle queries and a single query to . If is implemented by the algorithm of Corollary 1, Algorithm 1 runs in ; if , it runs in FP.
| Algorithm 1 CountViaTunnell (conditional on Conjecture 9) |
|
Proof.
Correctness is the identity of Conjecture 9. The running time is that of R, , plus one evaluation of . With Corollary 1 every oracle used is in , and under every oracle is in P. □
Theorem 11
(Structural equivalence). Assume Conjecture 9, and assume in addition that R, α, β are computable in polynomial time without oracle (or assume ). Then if and only if .
Proof.
(Lemma 5(4)). By Theorem 10 with the assumed polynomial-time evaluator, ; every reduces parsimoniously to . □
Corollary 3
(The -route in the scenario). Assume . Then Conjecture 9 implies . Consequently, in the scenario (1), Conjecture 9 is false.
Proof.
By Corollary 1, under ; apply Theorem 11. □
6.3. The No-Go Theorem
Theorem 12
(No-go theorem). If Conjecture 9 holds, then , and consequently .
Proof.
By Theorem 10 with Corollary 1, (the NP oracle used by R, , is subsumed). By parsimonious completeness, , hence . By Toda’s theorem [9], . □
Corollary 4
(Quantum consequence). Assume GRH and Conjecture 9 with R, α, β computable in polynomial time without oracle. Then and .
Proof.
Under GRH, is generated by the classes of prime forms of norm less than [34], which can be listed in polynomial time. Reduced forms give a unique encoding of group elements and the group operation is polynomial-time, so Watrous’s quantum algorithm for the order of a solvable black-box group [35] computes with bounded error in polynomial time. Hence and, by Algorithm 1, . Every PP language is decided by comparing a value with a threshold, so ; conversely [36]. □
The proofs of Theorem 12 and Corollary 3 use neither BSD nor the Solution Density Conjecture of Section 7: every even square-free n has regardless of congruence. This is the reason why, in the scenario, a counting reduction through Tunnell’s theorem can only work through , and why BSD enters through Proposition 4.
7. The Descent Cascade and the Solution Density Conjecture
An earlier form of the framework proposed to compute by a descent cascade: starting from , repeatedly replace the current instance by an element of whose Tunnell count is polynomially smaller. This section states the density hypothesis the cascade needs, proves its size and termination properties, and shows that it is redundant for exact counting.
Conjecture 13
(Solution Density Conjecture). There is a polynomial with the following property. Let N be a size parameter and a budget. For every integer T with there exists with and . Moreover, such an n can be found in deterministic polynomial time in N with a oracle.
Remark 10
(The shape of the conjecture). The upper bound on T is forced by Lemma 1. By Proposition 1, on , and under GRH Littlewood’s bounds [37] give . Hence, under GRH, the existence part of Conjecture 13 follows, for a suitable w, from the gap hypothesis that for every the interval contains an element of , for a suitable absolute constant c (take ). Since has density zero (Remark 2), this is not implied by any known counting result, but it is falsifiable by computation.
Remark 11
(Findability). Membership in requires, under BSD, the test , which uses a query. An existential search over n with a -oracle predicate is of type , and does not relativize to give . The findability clause is therefore an additional hypothesis.
Theorem 14
(Instance size control). Assume Conjectures 9 and 13, and let be the integers produced by Algorithm 2 on input φ, with and . Then: (1) for all j; (2) each transition takes time and queries to ; (3) for all , and .
Proof.
Put . In iteration j the loop condition gives , so and . By induction (Proposition 1); enlarging B by if necessary, . Conjecture 13 furnishes with and , found within the stated resources. Since , , and by Proposition 1; hence . □
Proposition 5
(Redundancy of the cascade). Under Conjectures 9 and 13, Algorithm 2 returns , and its output depends on the oracle answers only through ; line 3 is exactly the query of Algorithm 1. Conjecture 13 plays no role in the correctness or complexity of exact counting.
| Algorithm 2 DescentCascade (conditional, with oracle) |
|
Proof.
By construction , so by telescoping, and the returned value is . □
Remark 12.
The reconstruction factor can be as large as ; the product of factors, each at least , is in general super-polynomial and cannot be recovered from alone. The descent does not trade a large count for a small one.
8. Discussion
8.1. Status of the Hypotheses
The Sha-Tractability Hypothesis. Conjecture 7 asks for two things: to decide whether , and in rank zero to compute . Partial information is accessible: the 2-Selmer group of , which contains and surjects onto , is determined by an explicit matrix of Legendre symbols of the prime factors of n [38], hence is polynomial-time computable under . For the odd part of , and for the rank itself, no algorithm in the polynomial hierarchy is known: a generator of may have height exponential in , so points are not polynomial-size certificates of positive rank, and non-trivial elements of Sha are genus-one curves without rational points, for which no short certificates are known. Conjecture 7 would in particular place the congruent number problem for in without assuming the analytic part of BSD, provided only that is finite whenever : then if and only if .
The Cusp Reduction Conjecture. Conjecture 6 asks for an exact encoding of into the coefficients of Tunnell’s cusp form at the arguments , . By Remark 8 the output n must have at least about bits for formulas with v variables, and by Lemma 3 the relevant quantity is , whose square is proportional to (Proposition 3). No construction is known, and obstructions (i) and (ii) of Remark 9 apply. On the other hand, no algorithm in the polynomial hierarchy is known for , so nothing in the present paper refutes the conjecture, in contrast with Conjecture 9.
BSD. BSD for is supported by extensive numerical evidence [39] and by deep theoretical results [14,28,32,33,40]; in particular, for only the 2-part of the rank-zero formula remains open, and partial results on 2-parts for CM curves are available [41]. The branch of Corollary 2 in which BSD fails is therefore confined to the 2-primary part of or to curves with and rank zero. Corollary 2 shows that, in the scenario, this evidence bears on the two computational hypotheses as much as the hypotheses bear on BSD (Remark 5).
8.2. The Role of Each Assumption
- P = NP makes factorization, NP search, class numbers (Theorem 5) and hence polynomial-time, and turns the NP-oracle functions of Conjectures 6 and 7 into polynomial-time functions.
- is the hypothesis that is contradicted in Theorem 8; it is what makes the failure of BSD a consequence rather than a mere possibility.
- GRH is used only in Corollary 4 and in the analysis of Conjecture 13.
8.3. Falsifiability and Routes to Partial Progress
- Testing Proposition 4. For every for which can be determined algebraically (for instance by descent), the proposition predicts . A single counterexample would disprove BSD for .
- Complexity of Tunnell’s cusp coefficient. Any algorithm in the polynomial hierarchy for on would refute Conjecture 6 unless PH collapses, by the argument of Theorem 12. Conversely, a proof that is -hard under exact reductions would establish Conjecture 6.
- Complexity of Sha. Any proof that deciding for is hard for a class beyond PH would refute Conjecture 7; conversely, polynomial-time certificates for the rank and for the order of would establish it under .
- Gap statistics of . Tabulating for X up to [39] and measuring maximal multiplicative gaps would test the gap hypothesis underlying Conjecture 13.
What this paper is not. We do not claim that , that , or that BSD is false. We prove that, in the scenario (1), BSD fails infinitely often unless the Cusp Reduction Conjecture or the Sha-Tractability Hypothesis fails, and we prove that the route through is closed.
8.4. Toda’s Theorem and the Scenario
Under the polynomial hierarchy equals P, so Toda’s theorem yields no additional information inside the scenario. It becomes informative when is dropped, as in Theorem 12, where it converts into .
8.5. Relationship to Prior Work
Connections between number theory and complexity theory have been explored in many contexts, including the complexity of Diophantine problems [19,42], number-theoretic algorithms [43,44], and class group computation, which is subexponential under GRH [45] and quantum polynomial-time given a generating set [35]. Tunnell’s criterion has been studied computationally on a large scale [39], and Ono [21] used Tunnell’s forms to study the Tate–Shafarevich groups of the congruent number curves. The class-number structure of is an instance of the theory of ternary forms with one class in their genus [17,23]. The enumerative counting theorem of Cai and Hemachandra [16] is the complexity-theoretic tool that converts the two-fold sign ambiguity of Proposition 4 into exact counting. The complexity consequences drawn here appear to be new.
8.6. Comparison with Known Complexity Results
Table 1 summarizes the landscape. The row for on uses there, which is unconditional by Theorem 1(1) and Proposition 1; membership of a given n in is, of course, not assumed to be decidable.
9. Extended Proofs
9.1. Solution Count Tracking
Lemma 7
(Solution count tracking). Let be produced by Algorithm 2 and . Under Conjectures 9 and 13,
and each is a rational number with .
Proof.
The first equality is Conjecture 9, the second is telescoping, and is Theorem 14(3). The window of Conjecture 13 determines only up to a factor , so is not a function of alone, and is not bounded by any fixed polynomial when k grows polynomially. □
9.2. Verification of the Cascade
Lemma 8
(Cascade verification). Assume and BSD. Given with , the statements “” and “” can be verified for all j in deterministic polynomial time with queries to a oracle.
Proof.
For each j: square-freeness and are decided in polynomial time (Lemma 5(1)); is computed in polynomial time (Corollary 1); congruence is decided under BSD by comparing , obtained with one oracle query, with (Proposition 1). The window tests compare polynomial-time computable integers. □
10. Additional Remarks
10.1. Other Families of Twists
Tunnell-type criteria exist for other families of quadratic twists via Waldspurger’s theorem [13]. The mechanism of this paper suggests, without proof in general, the following heuristic: when a criterion compares two theta series, one of whose representation numbers are class numbers (for instance because its genus contains a single class), then on the vanishing locus of the relevant counts are class-number quantities and are easy under , while off that locus they equal a class-number quantity plus a cusp coefficient that BSD ties to . An analogue of Theorem 8 should then hold for each such family.
10.2. Quantum Computation
Factorization is in quantum polynomial time by Shor’s algorithm [46], and [36], so no quantum polynomial-time algorithm for -hard counting is expected. Corollary 4 shows that, under GRH, on even square-free n is computable in quantum polynomial time. No such statement is known for the cusp coefficient .
10.3. Average-Case Complexity
11. Conclusion
We explored the scenario in which but and asked what it implies for the Birch–Swinnerton-Dyer conjecture for the congruent number curves. The analysis rests on four unconditional results: on square-free , Tunnell’s count equals ; class numbers are computable in , hence in FP under ; the count equals plus the -th coefficient of Tunnell’s cusp form ; and exact reductions to collapse the polynomial hierarchy. Through Tunnell’s L-value formula and Ono’s evaluation of the BSD prediction, BSD turns the order of the Tate–Shafarevich group into the value of up to sign, and the theorem of Cai and Hemachandra turns two candidates into an exact count. The principal conclusion is Corollary 2: if and , and if reduces exactly to and is tractable, then BSD fails for infinitely many congruent number curves , in its rank statement or in the 2-part of its rank-zero formula.
The conclusion is only as strong as its two computational hypotheses, and the same theorem can be read as saying that, in the scenario, BSD forces the failure of one of them. The most actionable open questions are therefore: (i) Is Tunnell’s cusp coefficient -hard under exact reductions, or does it lie in the polynomial hierarchy? (ii) Is the rank and the order of computable with polynomial-size certificates? (iii) Does an analogue of the BSD bridge exist for other families of twists with class-number-one Tunnell forms? A resolution of (i) or (ii) would decide which branch of the trichotomy of Remark 5 can occur in the scenario.
Acknowledgments
The author would like to thank Iris, Marilin, Sonia, Yoselin, and Arelis for their support.
Appendix A. Pseudocode Details
Algorithm A1 is the two-candidate enumerator used in the proof of Theorem 8; it is conditional on Conjectures 6 and 7 for its functions R, , , S. Algorithms A2 and A3 are conditional on Conjectures 9 and 13; Algorithm A4 is unconditional given its oracle.
| Algorithm A1 BSDEnumerator (conditional on Conjectures 6 and 7) |
|
| Algorithm A2 ReduceToTunnell (hypothetical) |
|
| Algorithm A3 FindCongruentNumber (conditional, hypothetical) |
|
| Algorithm A4 CountD (via class numbers) |
|
Appendix B. Numerical Data
All values below were computed in exact integer arithmetic by exhaustive enumeration of representations and of reduced binary quadratic forms; the L-values were computed in PARI/GP. For every square-free with (20267 integers) we found (Lemma 2). For every with , and for 1500 random with , we found (Proposition 1), and for every with we checked directly. We checked the product identity for in the proof of Lemma 3 up to , and for all odd . For the first 60 elements of and 25 random elements of below 6000 we checked that the analytic order of Sha, computed as , equals . Over all , (Lemma 1).
Table A1.
The ten smallest with .
| n | |||
|---|---|---|---|
| 34 | 8 | 4 | 4 |
| 138 | 16 | 8 | 8 |
| 154 | 16 | 8 | 8 |
| 194 | 40 | 20 | 20 |
| 210 | 16 | 8 | 8 |
| 226 | 16 | 8 | 8 |
| 330 | 16 | 8 | 8 |
| 386 | 40 | 20 | 20 |
| 410 | 32 | 16 | 16 |
| 426 | 48 | 24 | 24 |
Table A2.
Illustration of Proposition 4 for some : , and is the analytic order of computed from .
| n | a | |||||
|---|---|---|---|---|---|---|
| 2 | 2 | 2 | 1 | 1 | 1 | 1 |
| 10 | 4 | 4 | 2 | 2 | 2 | 1 |
| 26 | 12 | 4 | 6 | 2 | 1 | |
| 82 | 8 | 8 | 4 | 4 | 2 | 4 |
| 146 | 32 | 12 | 16 | 2 | 4 | |
| 178 | 16 | 4 | 8 | 2 | 4 | |
| 218 | 20 | 4 | 10 | 2 | 9 | |
| 482 | 40 | 12 | 20 | 2 | 16 |
References
- Cook, S.A. The complexity of theorem-proving procedures. In Proceedings of the Third Annual ACM Symposium on Theory of Computing; ACM: New York, NY, USA, 1971; pp. 151–158. [Google Scholar] [CrossRef]
- Karp, R.M. Reducibility among Combinatorial Problems. In Complexity of Computer Computations; Miller, R.E., Thatcher, J.W., Bohlinger, J.D., Eds.; Plenum: New York, USA, 1972; pp. 85–103. [Google Scholar] [CrossRef]
- Birch, B.J.; Swinnerton-Dyer, H.P.F. Notes on elliptic curves. II. J. Für Die Reine Und Angew. Math. 1965, 218, 79–108. [Google Scholar] [CrossRef]
- Tunnell, J.B. A classical Diophantine problem and modular forms of weight 3/2. Invent. Math. 1983, 72, 323–334. [Google Scholar] [CrossRef]
- Valiant, L.G. The complexity of computing the permanent. Theor. Comput. Sci. 1979, 8, 189–201. [Google Scholar] [CrossRef]
- Valiant, L.G. The complexity of enumeration and reliability problems. SIAM J. Comput. 1979, 8, 410–421. [Google Scholar] [CrossRef]
- Zankó, V. #P-completeness via many-one reductions. Int. J. Found. Comput. Sci. 1991, 2, 77–82. [Google Scholar] [CrossRef]
- Gill, J. Computational complexity of probabilistic Turing machines. SIAM J. Comput. 1977, 6, 675–695. [Google Scholar] [CrossRef]
- Toda, S. PP is as hard as the polynomial-time hierarchy. SIAM J. Comput. 1991, 20, 865–877. [Google Scholar] [CrossRef]
- Arora, S.; Barak, B. Computational Complexity: A Modern Approach; Cambridge University Press: Cambridge, UK, 2009. [Google Scholar] [CrossRef]
- Koblitz, N. Introduction to Elliptic Curves and Modular Forms, 2nd ed.; Graduate Texts in Mathematics; Springer-Verlag: New York, 1993; Vol. 97. [Google Scholar] [CrossRef]
- Shimura, G. On modular forms of half integral weight. Ann. Math. 1973, 97, 440–481. [Google Scholar] [CrossRef]
- Waldspurger, J.L. Sur les coefficients de Fourier des formes modulaires de poids demi-entier. J. De Mathématiques Pures Et. Appliquées 1981, 60, 375–484. [Google Scholar]
- Coates, J.; Wiles, A. On the conjecture of Birch and Swinnerton-Dyer. Invent. Math. 1977, 39, 223–251. [Google Scholar] [CrossRef]
- Dickson, L.E. History of the Theory of Numbers, Vol. II: Diophantine Analysis; Carnegie Institution of Washington: Washington, D.C., 1920; Publication No. 256. [Google Scholar]
- Cai, J.Y.; Hemachandra, L.A. Enumerative counting is hard. Inf. Comput. 1989, 82, 34–44. [Google Scholar] [CrossRef]
- Bringmann, K.; Kane, B. Class numbers and representations by ternary quadratic forms with congruence conditions. Math. Comput. 2022, 91, 295–329. [Google Scholar] [CrossRef]
- Matiyasevich, Y.V. Enumerable sets are Diophantine. Sov. Math. Dokl. 1970, 11, 354–358, English translation of Dokl. Akad. Nauk SSSR 191 (1970), 279–282. [Google Scholar]
- Manders, K.L.; Adleman, L. NP-complete decision problems for binary quadratics. J. Comput. Syst. Sci. 1978, 16, 168–184. [Google Scholar] [CrossRef]
- Monsky, P. Mock Heegner points and congruent numbers. Math. Z. 1990, 204, 45–67. [Google Scholar] [CrossRef]
- Ono, K. Tate–Shafarevich groups of the congruent number elliptic curves. Acta Arith. 1997, 81, 247–252. [Google Scholar] [CrossRef]
- Andrews, G.E. The Theory of Partitions; Cambridge Mathematical Library, Cambridge University Press: Cambridge, UK, 1998. [Google Scholar] [CrossRef]
- Siegel, C.L. Über die analytische Theorie der quadratischen Formen. Ann. Math. 1935, 36, 527–606. [Google Scholar] [CrossRef]
- Deligne, P. La conjecture de Weil. I. Publ. Mathématiques De l’IHÉS 1974, 43, 273–307. [Google Scholar] [CrossRef]
- Iwaniec, H. Fourier coefficients of modular forms of half-integral weight. Invent. Math. 1987, 87, 385–401. [Google Scholar] [CrossRef]
- Duke, W. Hyperbolic distribution problems and half-integral weight Maass forms. Invent. Math. 1988, 92, 73–90. [Google Scholar] [CrossRef]
- Duke, W.; Schulze-Pillot, R. Representation of integers by positive ternary quadratic forms and equidistribution of lattice points on ellipsoids. Invent. Math. 1990, 99, 49–57. [Google Scholar] [CrossRef]
- Smith, A. 2∞-Selmer groups, 2∞-class groups, and Goldfeld’s conjecture. arXiv 2017, arXiv:1702.02325. [Google Scholar] [CrossRef]
- Stockmeyer, L. On approximation algorithms for #P. SIAM J. Comput. 1985, 14, 849–861. [Google Scholar] [CrossRef]
- Cohen, H. A Course in Computational Algebraic Number Theory; Graduate Texts in Mathematics; Springer-Verlag: Berlin, 1993; Vol. 138. [Google Scholar] [CrossRef]
- Kannan, R.; Bachem, A. Polynomial algorithms for computing the Smith and Hermite normal forms of an integer matrix. SIAM J. Comput. 1979, 8, 499–507. [Google Scholar] [CrossRef]
- Rubin, K. Tate–Shafarevich groups and L-functions of elliptic curves with complex multiplication. Invent. Math. 1987, 89, 527–559. [Google Scholar] [CrossRef]
- Rubin, K. The “main conjectures” of Iwasawa theory for imaginary quadratic fields. Invent. Math. 1991, 103, 25–68. [Google Scholar] [CrossRef]
- Bach, E. Explicit bounds for primality testing and related problems. Math. Comput. 1990, 55, 355–380. [Google Scholar] [CrossRef]
- Watrous, J. Quantum algorithms for solvable groups. In Proceedings of the Thirty-Third Annual ACM Symposium on Theory of Computing; ACM: New York, NY, USA, 2001; pp. 60–67. [Google Scholar] [CrossRef]
- Adleman, L.M.; DeMarrais, J.; Huang, M.D.A. Quantum computability. SIAM J. Comput. 1997, 26, 1524–1540. [Google Scholar] [CrossRef]
- Littlewood, J.E. On the class-number of the corpus P(). Proc. Lond. Math. Soc. 1928, s2-27, 358–372. [Google Scholar] [CrossRef]
- Heath-Brown, D.R. The size of Selmer groups for the congruent number problem, II. In Inventiones Mathematicae; Monsky, P., Ed.; 1994; Volume 118, pp. 331–370. [Google Scholar] [CrossRef]
- Hart, W.B.; Tornaría, G.; Watkins, M. Congruent number theta coefficients to 1012. In Algorithmic Number Theory (ANTS-IX); Lecture Notes in Computer Science; Springer: Berlin, 2010; Vol. 6197, pp. 186–200. [Google Scholar] [CrossRef]
- Bhargava, M.; Skinner, C.; Zhang, W. A majority of elliptic curves over satisfy the Birch and Swinnerton-Dyer conjecture. arXiv 2014, arXiv:1407.1826. [Google Scholar] [CrossRef]
- Coates, J.; Kim, M.; Liang, Z.; Zhao, C. On the 2-part of the Birch–Swinnerton-Dyer conjecture for elliptic curves with complex multiplication. arXiv 2013, arXiv:1303.5218. [Google Scholar] [CrossRef]
- Koiran, P. Hilbert’s Nullstellensatz is in the polynomial hierarchy. J. Complex. 1996, 12, 273–286. [Google Scholar] [CrossRef]
- Adleman, L.M.; Huang, M.D.A. Function field sieve method for discrete logarithms over finite fields. Inf. Comput. 1999, 151, 5–16. [Google Scholar] [CrossRef]
- Simon, D. Computing the rank of elliptic curves over number fields. LMS J. Comput. Math. 2002, 5, 7–17. [Google Scholar] [CrossRef]
- Hafner, J.L.; McCurley, K.S. A rigorous subexponential algorithm for computation of class groups. J. Am. Math. Soc. 1989, 2, 837–850. [Google Scholar] [CrossRef]
- Shor, P.W. Polynomial-time algorithms for prime factorization and discrete logarithms on a quantum computer. SIAM J. Comput. 1997, 26, 1484–1509. [Google Scholar] [CrossRef]
- Goldfeld, D. Conjectures on elliptic curves over quadratic fields. In Number Theory, Carbondale 1979; Lecture Notes in Mathematics; Springer: Berlin, 1979; Vol. 751, pp. 108–118. [Google Scholar] [CrossRef]
Table 1.
Complexity of related problems. “RC” denotes Conjecture 9, “CRC” Conjecture 6, “STH” Conjecture 7. Entries in the last two columns are consequences of the stated hypotheses, not claims about the actual state of affairs.
Table 1.
Complexity of related problems. “RC” denotes Conjecture 9, “CRC” Conjecture 6, “STH” Conjecture 7. Entries in the last two columns are consequences of the stated hypotheses, not claims about the actual state of affairs.
| Problem | Known upper bound | Under P=NP | Under P=NP + BSD + STH |
|---|---|---|---|
| , n even square-free | FP | FP | |
| Class number | FP | FP | |
| , | FP | FP | |
| , | two candidates in FP | ||
| Congruence of (BSD) | P | ||
| #SAT | #P-complete | not known in FP | FP if also CRC |
| Factorization | FP | FP |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the author. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).
Copyright: This open access article is published under a Creative Commons CC BY 4.0 license, which permit the free download, distribution, and reuse, provided that the author and preprint are cited in any reuse.