Conceptio › Archive › arXiv CS
arXiv CSopen access

Module Lattice Security (Part I): Unconditional Verification of Weber's Conjecture for $k \le 12$

2026 · arxiv_cs
arXiv CS · Papers · License: Open Access · 2026
Open Source ↗Direct PDF ↓
cryptographycybersecurityprivacysecurity
cryptography, security, privacy, cybersecurity

Module Lattice Security (Part I): Unconditional Verification of Weber’s Conjecture for k ≤ 12 Ming-Xing Luo School of Information Science and Technology, Southwest Jiaotong University, Chengdu 610031, China

arXiv:2604.15858v1 [cs.CR] 17 Apr 2026

April 20, 2026

Abstract Weber’s conjecture (1886) governs three aspects of lattice-based cryptography: the solvability of the Principal Ideal Problem, the freeness of modules over rings of integers, and the tightness of worst-case-to-average-case reductions in Ring-LWE (R-LWE) and ModuleLWE (MLWE). Existing verifications for k ≥ 9 rely on Generalized Riemann Hypothesis (GRH). In this paper, we present the first unconditional proof for k ≤ 12. Our method combines the Fukuda-Komatsu computational sieve, inductive structure of the cyclotomic Z2 -tower, and Herbrand’s theorem. Keywords: Weber’s conjecture, cyclotomic fields, post-quantum cryptography, lattice-based cryptography, Herbrand’s theorem, Iwasawa theory.

1

Introduction

Shor’s algorithm [1] solves integer factorization and discrete logarithms in polynomial time on quantum computers, rendering RSA, Diffie-Hellman, and elliptic curve cryptography fundamentally insecure against quantum adversaries. As a response, the cryptographic community has devoted more than fifteen years to developing post-quantum cryptography. Lattice-based constructions have emerged as the clear dominant paradigm, offering an exceptional combination of performance, security, and versatility. In August 2024, NIST finalized four post-quantum standards [2, 3, 4, 5]: ML-KEM (FIPS 203), ML-DSA (FIPS 204), SLH-DSA (FIPS 205), and FN-DSA (FIPS 206, expected finalization in 2025/2026). ML-KEM, ML-DSA, and FN-DSA rely k−1 on lattice problems defined over 2k -th cyclotomic polynomial rings of the form Z[x]/(x2 + 1). These rings enable compact key sizes, extremely efficient arithmetic via the Number Theoretic Transform [6, 7], and rigorous provable security reductions from worst-case lattice problems [8, 9, 7]. The security and correctness of all these lattice-based cryptosystems depend on arithmetic properties of underlying cyclotomic rings. One of the most fundamental and long-standing open questions is Weber’s conjecture. Conjecture (Weber, 1886 [10]). For every integer k ≥ 1, the maximal real subfield Kk+ = + Q(ζ2k + ζ2−1 k ) has class number hk = 1. Its resolution can affect lattice-based cryptography in three ways: First, for Principal Ideal Problem (PIP), if h+ k = 1, every ideal in OKk+ is principal, and quantum algorithms [11, 12] might solve PIP in polynomial time, reducing the problem to the Short Generator Problem (SGP) [13, 14, 15]. Second, a finitely generated torsion-free module over a Dedekind domain is free if and only if its Steinitz class is trivial. So, when h+ k = 1, every module over OKk+ is free, used in the security proofs of ML-KEM and ML-DSA [16, 17, 18]. Third, the reduction of

1

Table 1: History of Weber’s conjecture. Conditional means the result dependent on Generalized Riemann Hypothesis (GRH). k

[Kk+ : Q]

References

GRH-free?

≤5 6 7 8 9 10 11 12 ≤ 12

≤8 16 32 64 128 256 512 1024 ≤ 1024

Weber [10], Bauer [20] van der Linden [21] Fukuda-Komatsu [22] (also Cohn-Llorente) Miller [23] Fukuda-Komatsu [22] Fukuda-Komatsu [24] Fukuda-Komatsu [24] Fukuda-Komatsu [24] This paper

Yes Yes Yes Yes Conditional Conditional Conditional Conditional Yes

Lyubashevsky, Peikert, and Regev [8, 6], in cyclotomic fields with class number 1, can simplify the noise analysis [19]. The progress on Weber’s conjecture is summarized in Table 1. For k ≤ 5, the result is classical [10, 20, 25]. Van der Linden [21] treated k = 6 using an explicit computation of the regulator and analytic class number formula. Miller [23] proved k ≤ 8 unconditionally by computing full unit group of K8+ and applying Sinnott’s index formula [26]. For k ≥ 9, all previous verifications relied on Generalized Riemann Hypothesis (GRH).The main difficulty is that the Minkowski bound grows exponentially in the degree without GRH [27]. Instead, with GRH, Fukuda and Komatsu [22, 24] extended the verification to k ≤ 12 using Bach’s bound [28], and Schoof [29, 30] provided independent verifications. The Iwasawa perspective on Weber’s conjecture was developed by Iwasawa [31, 32], and extended by Ferrero and Washington [33] and Greenberg [34, 35]. Ozaki and Taya [36] proved λ = 0 for certain families of real quadratic fields. Kraft and Schoof [37] obtained related results for Z2 -extensions. Thaine [38] proved that cyclotomic units provide explicit annihilators of class groups [39]. Rubin [40, 41] applied Euler systems for abelian extensions of Q. The connection between ideal lattice structure and cryptographic security was established by Micciancio [42] and Lyubashevsky, Peikert, and Regev [8, 7]. The quantum attacks of Cramer et al. [11], Biasse and Song [12], and Campbell et al. [13] all exploit the algebraic structure of cyclotomic fields. Felderhoff et al. [43] showed Ideal-SVP remains hard for small-norm uniform prime ideals. Allombert, Pellet-Mary, and van Woerden [44] gave a polynomial-time attack on rank-2 module-LIP for fields with a real embedding. Ducas, Espitau, and Postlethwaite [45] provided concrete predictions for module-lattice reduction in cyclotomic fields. Contributions: We present the first unconditional proof of h+ k = 1 for k ≤ 12. Our method proceeds in three sequential stages: Stage 1: Small-prime elimination (Fukuda-Komatsu sieve). Using the Wieferich criterion, we can eliminate all primes ℓ < 109 as possible divisors of h+ k for k ≤ 12. We establish any surviving prime should satisfy the strong congruence condition ℓ ≡ ±1 (mod 2k−1 ) [22, 24]. Stage 2: Eigenspace pruning (norm-coherence argument). We exploit the tower structure + K8+ ⊂ K9+ ⊂ · · · ⊂ K12 and the known result h+ 8 = 1 to prove inductively any ℓ-torsion in Cl(Kk+ ) is concentrated in eigenspaces corresponding to full-order Galois characters. Stage 3: Finite bounding (Herbrand’s theorem). For each surviving full-order character χ, we apply Herbrand’s theorem for any prime ℓ supporting χ-torsion to divide the norm of an explicit generalized Bernoulli number. After Stage 3, we obtain a finite (possibly empty) set Sk of candidate primes. For each ℓ ∈ Sk , 2

+ we apply the Wieferich test from Stage 1 to verify ℓ ∤ h+ k . If all tests pass, hk = 1 unconditionally. After applying Galois-orbit symmetry, the entire computation reduces to factoring one integer of at most 143 decimal digits. We finally filter its prime factors using congruence ℓ ≡ ±1 (mod 512); and run at most 10 modular exponentiations. Note integers of 143 digits can be factored with Elliptic Curve Method [46, 47]. For k ≥ 11, the second-moment bound gives integers of at most 325 digits, which are still accessible by combining ECM and NFS. The rest of the paper is organized as follows. Section 2 provides a self-contained review of the algebraic number theory background required for our proof, including number fields, class groups, Galois theory, character theory, cyclotomic units, Iwasawa theory, and the structure of the cyclotomic Z2 -tower. Section 3 states and proves our main theorem and presents the complete verification algorithm with a detailed complexity analysis. Section 4 discusses the implications of our result for post-quantum cryptography. Section 5 concludes this paper.

2

Algebraic Preliminaries

This section provides a self-contained review of the algebraic number theory used in what follows, see Washington [27], Neukirch [48], and Lang [49]. Notation. We use the following notation throughout this paper • φ denotes Euler’s totient function: φ(m) = |{a : 1 ≤ a ≤ m, gcd(a, m) = 1}|. • (Z/mZ)× denotes the group of units modulo m and has order φ(m). • Fℓ = Z/ℓZ denotes finite field with ℓ elements, for a prime ℓ. • For a positive integer m, let ζm = e2πi/m for a fixed primitive m-th root of unity, and µm = {z ∈ C : z m = 1} for the group of all m-th roots of unity. • n denotes n = 2k−2 = [Kk+ : Q], the degree of the maximal real subfield over Q. • fχ denotes the conductor of a Dirichlet character χ. The letter f without subscript denotes a conductor used in Definitions 2.13-2.14 and Lemma 3.4; the inertia degree of a prime l above ℓ is denoted fFrob or ord(Frobℓ ).

2.1

Number fields and rings of integers

Definition 2.1. A number field is a finite extension of Q. Its ring of integers OK is the integral closure of Z in K; equivalently, OK consists of all elements α ∈ K that satisfy a monic polynomial with integer coefficients. The ring OK is a Dedekind domain: an integral domain in which every nonzero ideal factors uniquely as a product of prime ideals. However, OK need not be a unique factorization domain (UFD) at the element level. Definition 2.2. A number field K is totally real if every embedding K ,→ C has image contained in R. By Dirichlet’s unit theorem [48, §I.7], the unit group of a number field with r1 real embeddings × ∼ and r2 pairs of complex conjugate embeddings has the form OK = µK × Zr1 +r2 −1 , where µK is the finite group of roots of unity in K. For a totally real field, r2 = 0, so unit rank is [K : Q] − 1.

2.2

Ideals, fractional ideals, and the class group

Definition 2.3. Let K be a number field with ring of integers OK . A fractional ideal of K is a nonzero finitely generated OK -submodule of K. Equivalently, it is a set of the form d−1 I, where I ⊆ OK is a nonzero ideal and d ∈ Z>0 . The set of all fractional ideals of K forms an abelian group I(K) under ideal multiplication, with identity element OK . The principal fractional ideals form a subgroup P (K) ⊆ I(K). 3

Definition 2.4. The class group of K is the quotient defined by Cl(K) = I(K)/P (K).

(1)

The class number of K is hK = | Cl(K)|. The ring OK is a UFD if and only if hK = 1. Remark 2.1. We use two notations for Cl(K), depending on the algebraic structure being used. • Multiplicative (Sections 2.2-2.7): ideal classes are multiplied, the identity is [OK ], and annihilation reads cℓ = 1 or [I]2θk = 1. • Additive (Section 2.5): Cl(K)[ℓ] is viewed as an Fℓ [Gk ]-module, so we write ℓc = 0, g · c = χ(g) c, and N · c = 2c. The translation is: cn = 1 (multiplicative) ←→ n c = 0 (additive). Definition 2.5. The norm of a nonzero ideal a ⊆ OK is N(a) = |OK /a|, i.e., the cardinality of the quotient ring. For a principal ideal αOK , N(αOK ) = | NK/Q (α)|. Minkowski theorem states the class group is finite [48]. For a number field of discriminant ∆K , the Minkowski bound implies every ideal class contains an integral ideal of norm at most  r2 p 4 [K : Q]! |∆K |, (2) MK = [K : Q][K:Q] π where r2 is the p number of pairs of complex embeddings. For totally real fields, r2 = 0, so [K:Q]! + + MK = [K:Q][K:Q] |∆K |. For K10 , we have [K10 : Q] = 256 and |∆K | = 22303 (Proposition 2.2), which implies MK + > 10237 . A direct sieve over all primes (up to this bound) is computationally 10 infeasible without GRH. Definition 2.6. For a prime ℓ, the ℓ-part of the class group is the Sylow ℓ-subgroup: m

Cl(K)[ℓ∞ ] = {c ∈ Cl(K) : cℓ = 1 for some m ≥ 1}.

(3)

The ℓ-torsion is Cl(K)[ℓ] = {c ∈ Cl(K) : cℓ = 1}. A prime ℓ divides hK if and only if Cl(K)[ℓ] ̸= 0.

2.3

Galois theory of cyclotomic fields k

Fix an integer k ≥ 3, let ζ = ζ2k = e2πi/2 , and define Kk = Q(ζ), and Kk+ = Q(ζ + ζ −1 ). Kk is the 2k -th cyclotomic field, and Kk+ is its maximal real subfield. Proposition 2.1 ([27, Theorem 2.5]). The extension Kk /Q is Galois with Galois group Γk = Gal(Kk /Q) ∼ = (Z/2k Z)× . The isomorphism maps an odd integer a to automorphism σa : ζ 7→ ζ a . In what follows, we denote n = 2k−2 = 12 φ(2k ) (see Notation 2). Complex conjugation is automorphism σ−1 : ζ 7→ ζ −1 . Kk+ is the fixed field of ⟨σ−1 ⟩. We have Gk = Gal(Kk+ /Q) ∼ = Γk /⟨σ−1 ⟩ ∼ = Z/nZ.

(4)

A generator of Gk is given by σ = σ5 mod ⟨σ−1 ⟩, which maps ζ + ζ −1 to ζ 5 + ζ −5 . Proposition 2.2 ([27, Proposition 2.16]). The discriminant of Kk+ is given by disc(Kk+ ) = 2(k−1)n−1 ,

(5)

where n = 2k−2 . + For k = 10: n = 256, we have disc(K10 ) = 29·256−1 = 22303 (used in the Minkowski bound + estimate of §2.2). For k = 12: n = 1024, we have disc(K12 ) = 211·1024−1 = 211263 .

4

2.4

Character theory

Definition 2.7. A character of a finite abelian group G is a group homomorphism χ : G → C× . The set Ĝ of all characters forms a group under pointwise multiplication, called the character group of G. For Gk ∼ = Z/nZ, the character group Ĝk is also cyclic of order n. The characters χ0 , χ1 , . . . , χn−1 satisfy χj (σ) = ω j with ω = e2πi/n . We have trivial character χ0 (g) = 1 for all g ∈ Gk . Definition 2.8. The order of a character χ ∈ Ĝk is ord(χ) = min{m ≥ 1 : χm = χ0 }. A character has full order if ord(χ) = n = 2k−2 . Definition 2.9. A character χ of Γk = Gal(Kk /Q) is called even if χ(σ−1 ) = +1, and odd if χ(σ−1 ) = −1. Since σ−1 is complex conjugation, even characters are precisely those that factor through Gk = Γk /⟨σ−1 ⟩. Lemma 2.1. The group Gk ∼ = Z/nZ with n = 2k−2 has the following properties: (i) φ(n) = n/2 characters of full order n; (ii) n/4 conjugate pairs of full-order characters (χj , χn−j ) with j odd; (iii) φ(d) characters of order d for each divisor d | n. Proof. We show that χj has order n/ gcd(j, n), which equals n if and only if gcd(j, n) = 1. The number of such j in {0, . . . , n − 1} is φ(n) = n/2. This implies (i). Since n = 2k−2 is even, gcd(j, n) = 1 implies an odd j. Complex conjugation maps χj to χn−j , and j odd with n even implies j = ̸ n − j (as j = n − j would give j = n/2, which is even). Hence the n/2 full-order characters pair into n/4 conjugate pairs. This yields (ii). Part (iii) is from group theory, see [27, Theorem 3.1].

2.5

Eigenspace decomposition of the class group

Let ℓ be an odd prime with ℓ ∤ n. Then gcd(ℓ, |Gk |) = 1, so the group ring Fℓ [Gk ] is semisimple by Maschke’s theorem [50]. In what follows, we use additive notation for Cl(Kk+ ) and its ℓ-torsion subgroups (see Remark 2.1), writing ℓ c = 0 in place of cℓ = 1, and g · c = χ(g) c for the Gk -action. P Definition 2.10. The group ring Z[Gk ] is the ring of formal sums g∈Gk ag · g with ag ∈ Z and multiplication induced by group law. The group ring acts on Cl(Kk+ ) via Galois action: g · [a] = [g(a)] for a prime ideal a and g ∈ Gk = Gal(Kk+ /Q), extended Z-linearly. For each character χ ∈ Ĝk , define the idempotent as eχ =

1 X χ(g)−1 g ∈ Fℓ [Gk ], n

(6)

g∈Gk

where 1/n is computed modulo ℓ. This is well-defined since ℓ ∤ n. The idempotents eχ in Eq.(6) require character values χ(g) ∈ Fℓ , which holds if and only if ℓ ≡ 1 (mod n). For ℓ ̸≡ 1 (mod n), the decomposition (7) holds over Fℓf where f = ordn (ℓ), and Galois-conjugate eigenspaces merge into a single Fℓ -rational component. In the proof of the main theorem, the congruence condition ℓ ≡ ±1 (mod 2k−1 ) from Theorem 3.1(ii) ensures f ≤ 2, so the decomposition is defined over Fℓ2 at worst. Proposition 2.3. The elements {eχ }χ∈Ĝk satisfy the following fundamental properties: (i) e2χ = eχ (Idempotency); (ii) P eχ eψ = 0 for χ ̸= ψ (Orthogonality); (iii) χ eχ = 1 (Completeness); (iv) g · eχ = χ(g)eχ for all g ∈ Gk (Eigenvalue property). 5

P Properties (i)-(iii) follow from the orthogonality relations for characters: g∈G χ(g)ψ(g)−1 = |G| · δχ,ψ , see [27, Theorem 3.7]. Property (iv) follows from the substitution h′ = gh in the defining sum and the multiplicativity of χ. The idempotents can be used to decompose any Fℓ [Gk ]-module. Applying them to the ℓ-torsion of class group implies that M Cl(Kk+ )[ℓ]eχ , (7) Cl(Kk+ )[ℓ] = χ∈Ĝk

where Cl(Kk+ )[ℓ]eχ = eχ · Cl(Kk+ )[ℓ] = {c ∈ Cl(Kk+ )[ℓ] : g · c = χ(g)c for all g ∈ Gk }. + eχ ̸= 0 for some nontrivial Corollary 2.1. A prime ℓ ∤ 2n divides h+ k if and only if Cl(Kk )[ℓ] character χ ∈ Ĝk . + Proof. The trivial eigenspace Cl(Kk+ )[ℓ]eχ0 is the Gk -fixed subgroup of Cl(KkP )[ℓ]. For any c in this subgroup, g · c = c for all g ∈ Gk , so the norm element acts as n · c = g∈Gk g · c. Since the norm maps to Cl(Q) = 0, we have n · c = 0. Combined with ℓ · c = 0 and gcd(ℓ, n) = 1 (as ℓ ∤ 2n), Bezout’s identity gives c = 0. The decomposition (7) then gives the result. + eχ = 0 for every nontrivial character χ. To prove ℓ ∤ h+ k , it suffices to show Cl(Kk )[ℓ]

2.6

Cyclotomic units

Cyclotomic units are explicit units in cyclotomic fields constructed from roots of unity. They form a subgroup of the full unit group whose index is related to class number via Sinnott’s theorem. Definition 2.11. For an odd integer a with 1 < a < 2k , define the cyclotomic unit as ξa =

sin(πa/2k ) ζ a − ζ −a × = ∈ OK +. ζ − ζ −1 sin(π/2k ) k

(8)

Since sin(πa/2k ) = sin(π(2k − a)/2k ), we have ξa = ξ2k −a for all odd a. This will be used in the conjugate-pair reduction of Proposition 3.3. We verify ξa lies in Kk+ . (ζ a − ζ −a )/(ζ − ζ −1 ) is invariant under ζ 7→ ζ −1 . That ξa is a unit k−1 follows from product formula for cyclotomic polynomial Φ2k (x) = x2 + 1, see [27, §8.1]. × Definition 2.12. The cyclotomic unit group C + is the subgroup of OK + generated by {−1}∪{ξa : k

1 < a < 2k , a odd}. Theorem 2.1 (Sinnott [26]). For k ≥ 3, we have × + h+ k = [OK + : C ].

(9)

k

Sinnott’s formula converts the class number into the index of an explicit, finitely generated × subgroup. In particular, h+ k = 1 if and only if every unit in OK + is a product of cyclotomic k

units.

2.7

Generalized Bernoulli numbers

Generalized Bernoulli numbers link the arithmetic of class groups to explicit algebraic quantities via Stickelberger relation and Herbrand’s theorem. Definition 2.13. A Dirichlet character modulo f is a group homomorphism ψ : (Z/f Z)× → C× , extended to all of Z by setting ψ(a) = 0 when gcd(a, f ) > 1. The conductor of ψ is the smallest positive integer f0 such that ψ factors through (Z/f0 Z)× . If f0 = f , the character is primitive. 6

Definition 2.14. Let ψ be a Dirichlet character of conductor f . The first generalized Bernoulli number attached to ψ is given by f

1X B1,ψ = ψ(a)a. f

(10)

a=1

When ψ is a character of conductor 2k , the sum has φ(2k ) = 2k−1 nonzero terms. We have B1,ψ ∈ Q(ζm ) with m = ord(ψ). All nonvanishing Bernoulli numbers in our analysis come from odd characters of ψ(−1) = −1. Definition 2.15. The Stickelberger element of Kk = Q(ζ2k ) is given by k

1 θk = k 2

2 X

aσa−1 ∈ Q[Γk ].

(11)

a=1,(a,2)=1

Theorem 2.2 (Stickelberger [51, 27]). The element 2θk lies in Z[Γk ], and 2θk annihilates Cl(Kk ), i.e., for every ideal class [I] ∈ Cl(Kk ), we have [I]2θk = [I 2θk ] = 1.

(12)

In additive notation (Remark 2.1), this means 2θk · c = 0 for all c ∈ Cl(Kk ). For any nontrivial character χ of Γk , by evaluating χ on θk we obtain generalized Bernoulli number as 2k X 1 (13) aχ−1 (a) = B1,χ−1 . χ(θk ) = k 2 a=1,(a,2)=1

For even characters (χ(−1) = +1, χ ̸= χ0 ), we have B1,χ−1 = 0 using pairing a ↔ 2k − a.

2.8

The Cyclotomic Z2 -Tower

The fields Kk+ form layers of an infinite tower, named the cyclotomic ZS2 -extension of Q. Here, + + = + Z2 = limm Z/2m Z denotes the ring of 2-adic integers. Define K∞ k≥2 Kk . K∞ /Q is an ←− infinite Galois extension with + Gal(K∞ /Q) ∼ (14) = Z2 . + with [K + : Q] = 2k−2 . The tower is given by Kk+ is unique subfield of K∞ k + Q = K2+ ⊂ K3+ ⊂ K4+ ⊂ · · · ⊂ K∞ ,

(15)

+ + where each extension Kk+1 /Kk+ has degree 2, and the norm maps Nk+1/k : Cl(Kk+1 ) → Cl(Kk+ ) satisfy the transitivity relation Nk+1/k ◦ Nk+2/k+1 = Nk+2/k . + The norm map Nk+1/k : Kk+1 → Kk+ is defined by

Nk+1/k (α) = α · σ nk+1 /2 (α),

(16)

+ where nk+1 = 2k−1 = [Kk+1 : Q] and σ is the generator of Gk+1 . In Z[Gk+1 ], this corresponds to the element N = 1 + σ nk+1 /2 .

Lemma 2.2. Let χ ∈ Ĝk+1 be a character with ord(χ) | nk+1 /2 = 2k−2 . Then N acts on + Cl(Kk+1 )[ℓ]eχ as multiplication by 2. + Proof. We show N ·c = 2c for any c ∈ Cl(Kk+1 )[ℓ]eχ . By Proposition 2.3(iv), we have σ·c = χ(σ)c, so σ nk+1 /2 · c = χ(σ)nk+1 /2 c. Since ord(χ) | nk+1 /2, we have χ(σ)nk+1 /2 = 1, which futher gives N · c = (1 + σ nk+1 /2 ) · c = 2c.

7

2.9

Iwasawa theory

For our purposes, the key result is the vanishing of the Iwasawa µ-invariant. Theorem 2.3 (Iwasawa [31, 32]). Let p be a prime and K∞ /K be a Zp -extension with layers Kn . Let en be the exact power of p dividing hKn . For sufficiently large n, we have en = µ · pn + λ · n + ν,

(17)

where µ, λ ≥ 0 and ν are integers independent of n. µ, λ, ν are called Iwasawa invariants of the Zp -extension. Note en here denotes Iwasawa exponent, not an idempotent in Eq.(6). Theorem 2.4 (Ferrero-Washington [33]). For any abelian number field K and any prime p, Iwasawa µ-invariant of cyclotomic Zp -extension of K vanishes, i.e., µ = 0. From this theorem, the p-part of class number does not grow exponentially in tower. For the Z2 -extension of Q, the 2-part of h+ k is bounded as k → ∞. In fact, Fukuda and Komatsu [22] verified computationally 2 ∤ h+ for all k ≤ 12. Avila [52] and Laxmi-Saikia [53] extended k Iwasawa modules and 2-class group structure in Z2 -extensions of real quadratic fields, providing computational evidence.

3

The Main Result

In this section, we develop a three-stage method for unconditionally verifying Weber’s conjecture. Each stage systematically reduces the set of potential primes, until we obtain a finite, computable candidate set.

3.1

The Fukuda-Komatsu sieve

The Fukuda-Komatsu sieve [22, 24] uses Wieferich criterion for cyclotomic units to eliminate all small primes as possible divisors of h+ k. Definition 3.1. An odd prime ℓ satisfies the Wieferich criterion for Kk+ if for every prime l | ℓ in OK + , k

(ℓ−1)/ ordl (ξ5 )

ξ5

̸≡ 1

(mod l),

(18)

where ξ5 is the cyclotomic unit from Definition 2.11 and ordl (ξ5 ) denotes the multiplicative order of ξ5 in the residue field OK + /l. k

Lemma 3.1. Let ℓ be an odd prime with ℓ ≡ ±1 (mod 2k−1 ). If (ℓ−1)/2k−1

ξ5

̸≡ 1

(mod l)

(19)

for every l | ℓ in OK + , then ℓ satisfies Wieferich criterion (Definition 3.1), and consequently k

ℓ ∤ h+ k.

Proof. From Proposition 2.1, Gk = Gal(Kk+ /Q) ∼ = Z/2k−2 Z, a cyclic group generated by σ5 (the −1 5 −5 automorphism mapping ζ + ζ 7→ ζ + ζ ). For the unramified odd prime ℓ, the Frobenius element Frobℓ ∈ Gk is the unique automorphism satisfying Frobℓ (x) ≡ xℓ (mod l) for all x ∈ OK + . The inertia degree f equals the order of Frobℓ in Gk . k

By assumption ℓ ≡ ±1 (mod 2k−1 ): If ℓ ≡ 1 (mod 2k−1 ), then ℓ ≡ 1 (mod 2k−2 ), so Frobℓ has order f = 1; If ℓ ≡ −1 (mod 2k−1 ), then ℓ2 ≡ 1 (mod 2k−2 ), so Frobℓ has order f = 2. In both cases, f ≤ 2, as claimed. 8

The residue field κ(l) = OK + /l is a finite field of order N (l) = ℓf , so its multiplicative k

group κ(l)× is cyclic of order N (l) − 1. From the assumption ℓ ≡ ±1 (mod 2k−1 ), for f = 1: 2k−1 | ℓ − 1 = N (l) − 1; For f = 2: 2k−1 | ℓ + 1, so 2k−1 | (ℓ − 1)(ℓ + 1) = ℓ2 − 1 = N (l) − 1. Thus 2k−1 | N (l) − 1 in all cases, so the exponent (N (l) − 1)/2k−1 is an integer, i.e., the test (19) is well-defined. This exponent is exactly the 2k−1 -th power residue symbol of ξ5 at l,   ξ5 (N (l)−1)/2k−1 ≡ ξ5 (mod l). (20) l 2k−1 The test (19) asserts this symbol is nontrivial (not equal to 1) for all l | ℓ. From Definition 3.1, ℓ satisfies the Wieferich criterion if for every l | ℓ, we then obtain (ℓ−1)/ ordℓ (5)

ξ5

̸≡ 1

(mod l),

(21)

where ordℓ (5) is the multiplicative order of 5 modulo ℓ. If ℓ fails the Wieferich criterion, then the test (19) also fails. Let d = ordl (ξ5 ) denote the multiplicative order of ξ5 in κ(l)× . By definition, ξ5m ≡ 1 (mod l) if and only if d | m. If ℓ fails the Wieferich criterion, then d | (ℓ − 1)/ ordℓ (5). We split into the two cases for f : Case 1: f = 1 (ℓ ≡ 1 (mod 2k−1 )) The test exponent is (ℓ−1)/2k−1 . Since σ5 generates Gk , we have ord2k (5) = 2k−2 , so ordℓ (5) | 2k−1 for ℓ ≡ 1 (mod 2k−1 ). Thus (ℓ−1)/ ordℓ (5) | (ℓ−1)/2k−1 . (ℓ−1)/2k−1

Since d | (ℓ − 1)/ ordℓ (5), we get d | (ℓ − 1)/2k−1 , so ξ5 ≡ 1 (mod l), failing the test. Case 2: f = 2 (ℓ ≡ −1 (mod 2k−1 )) The test exponent is (ℓ2 − 1)/2k−1 . Since d | |κ(l)× | = ℓ2 − 1 and d | (ℓ − 1)/ ordℓ (5), we have d | ℓ − 1. By assumption, 2k−1 | ℓ + 1, so (ℓ − 1)/ ordℓ (5) | (ℓ2 −1)/2k−1

(ℓ − 1)(ℓ + 1)/2k−1 = (ℓ2 − 1)/2k−1 . Thus d | (ℓ2 − 1)/2k−1 , so ξ5 ≡ 1 (mod l), failing the test. By contradiction, the test condition (19) implies ℓ satisfies the Wieferich criterion. × + + By Theorem 2.1, h+ k = [OK + : C ], where C is the cyclotomic unit group. The nontrivial k

power residue symbol of ξ5 (from the test condition) implies ξ5 has order not divisible by ℓ in × × + + the quotient OK + /C , so ℓ cannot divide the index [O + : C ]. This is the formal result of [22, K k

k

§3, Proposition 3.2]. Combining these, the test condition implies the Wieferich criterion holds, hence ℓ ∤ h+ k. Lemma 3.2. Let k ≥ 4 and ℓ be an odd prime with ℓ ̸≡ ±1 (mod 2k−1 ). Then the order of ℓ in Gk ∼ = Z/2k−2 Z satisfies f ≥ 4. Proof. We proceed with a fully rigorous, relying on standard properties of 2-adic units and cyclotomic Galois groups. For k ≥ 3, the unit group modulo 2k has the well-known decomposition: (Z/2k Z)× ∼ = ⟨−1⟩ × ⟨5⟩,

(22)

where ⟨−1⟩ is the order-2 subgroup generated by −1, and ⟨5⟩ is the cyclic subgroup of order 2k−2 generated by 5. For the 2k -th cyclotomic field Kk = Q(ζ2k ), its Galois group is Γk = Gal(Kk /Q) ∼ = (Z/2k Z)× , with the isomorphism mapping an odd integer a to the automorphism σa : ζ2k 7→ ζ2ak . The maximal real subfield Kk+ is the fixed field of complex conjugation σ−1 , so its Galois group is Gk = Gal(Kk+ /Q) = Γk /⟨σ−1 ⟩ ∼ = ⟨5⟩ ∼ = Z/2k−2 Z,

(23)

a cyclic group of order 2k−2 . Since ℓ is an odd prime, we can uniquely write ℓ in the decomposition of (Z/2k Z)× : ℓ ≡ (−1)ϵ · 5s

(mod 2k ), 9

(24)

where ϵ ∈ {0, 1} and s ∈ Z/2k−2 Z. The image of ℓ in the quotient group Gk corresponds to the element s ∈ Z/2k−2 Z (we quotient out the ⟨−1⟩ component). The order f of ℓ in Gk is exactly the order of s in the additive group Z/2k−2 Z, which is given by: f=

2k−2 . gcd(s, 2k−2 )

(25)

By definition, f ≤ 2 if and only if the order of s is at most 2. For the cyclic 2-group Z/2k−2 Z, the only elements of order ≤ 2 are: 1. The zero element s = 0 (order 1), and 2. The unique element of order 2: s = 2k−3 since 2 · 2k−3 = 2k−2 ≡ 0 (mod 2k−2 ). We analyze both cases: Case 1: s = 0 Then ℓ ≡ (−1)ϵ · 50 = (−1)ϵ (mod 2k ), so ℓ ≡ ±1 (mod 2k ). This immediately implies ℓ ≡ ±1 (mod 2k−1 ), contradicting the hypothesis of the lemma. Case 2: s = 2k−3 By the standard 2-adic congruence for powers of 5 (proven by induction k−3 ≡ 1 + 2k−1 (mod 2k ). Substituting back, we get in the error analysis above), we have 52 ϵ k−1 k ℓ ≡ (−1) · (1 + 2 ) (mod 2 ). Reducing modulo 2k−1 , the term 2k−1 vanishes, so we have ℓ ≡ (−1)ϵ · 1 ≡ ±1 (mod 2k−1 ), which again contradicts the hypothesis of the lemma. The only two cases that give f ≤ 2 both force ℓ ≡ ±1 (mod 2k−1 ), which violates the lemma’s hypothesis. Therefore, for all ℓ ̸≡ ±1 (mod 2k−1 ), we have f ≥ 4. Theorem 3.1. For k ≤ 12, we have (i) No prime ℓ < 109 divides h+ k. k−1 ). (ii) If an odd prime ℓ divides h+ k , then ℓ ≡ ±1 (mod 2 Proof. For each prime ℓ < 109 satisfying ℓ ≡ ±1 (mod 2k−1 ), Wieferich criterion can be verified computationally. Each test requires O(log3 ℓ) bit operations. k−1 ). The Frobenius We show that any odd prime divisor ℓ of h+ k should satisfy ℓ ≡ ±1 (mod 2 element Frobℓ ∈ Gk at an unramified prime ℓ is the unique automorphism satisfying Frobℓ (x) ≡ xℓ (mod l) for all x ∈ OK + and any prime l above ℓ. Let fFrob = [OK + /l : Fℓ ] = ord(Frobℓ ) in k k Gk ; we have fFrob = ord k−2 (ℓ mod 2k ) in Gk ∼ = Z/2k−2 Z. By Lemma 3.2, ℓ ̸≡ ±1 (mod 2k−1 ) 2

implies f ≥ 4. Now, consider the eigenspace decomposition (7) (switching to additive notation). The Frobenius Frobℓ acts on Cl(Kk+ )[ℓ]eχ as multiplication by χ(Frobℓ ). If l | ℓ in Kk+ and c = [l] generates a nontrivial element in Cl(Kk+ )[ℓ]eχ , then the action of Frobℓ should be compatible with ℓ-th power residue structure modulo l. Note Fukuda and Komatsu [22, §3, Proposition 3.2] proved that if fFrob = ord(Frobℓ ) ≥ 4 in Gk , then the image of ξ5 in (OK + /l)× has order coprime to ℓ, which by Sinnott’s formula k

+ × + (Theorem 2.1) forces ℓ ∤ h+ k . This means ℓ ∤ [O : C ] = hk using Sinnott’s formula. The net + k−1 result is any odd prime divisor ℓ of hk should satisfy 2 | (ℓ2 − 1), see [22, §3] for the complete proof.

For k = 10, the congruence condition requires ℓ ≡ ±1 (mod 512). This means among primes near 109 , only about 1 in 256 satisfy this condition. For k = 12, the condition is ℓ ≡ ±1 (mod 2048), excluding all but about 1 in 1024 primes.

3.2

Norm-coherence eliminates low-order characters

Our second key tool is the inductive structure of cyclotomic Z2 -tower and eigenspace decomposition to rule out most eigenspaces.

10

k−2 . Then Proposition 3.1. Let k ≥ 4, and suppose h+ k−1 = 1. Let ℓ be an odd prime with ℓ ∤ 2 for every character χ ∈ Ĝk with ord(χ) | 2k−3 , we have

Cl(Kk+ )[ℓ]eχ = 0.

(26)

Proof. Since ℓ ∤ 2k−2 =P|Gk |, the group ring Fℓ [Gk ] is semisimple by Maschke’s theorem, and the idempotent eχ = |G1k | g∈Gk χ(g)−1 g ∈ Fℓ [Gk ] is well-defined (the inverse of |Gk | exists in Fℓ ). For any c ∈ Cl(Kk+ )[ℓ]eχ , we have by definition: 1. ℓc = 0 (as c lies in the ℓ-torsion subgroup), 2. eχ · c = c (as c lies in the χ-eigenspace), 3. g · c = χ(g)c for all g ∈ Gk (eigenvalue property of idempotents, Proposition 2.3). + Let N = 1 + σ n/2 ∈ Z[Gk ] be the norm element for the quadratic extension Kk+ /Kk−1 . By k−3 assumption, ord(χ) | 2 = n/2. Since σ generates Gk , we have:  (n/2)/ ord(χ) χ(σ n/2 ) = χ(σ)n/2 = χ(σ)ord(χ) = 1(n/2)/ ord(χ) = 1.

(27)

Combined with the eigenvalue property, this gives: σ n/2 · c = χ(σ n/2 )c = c.

(28)

Thus the action of N on c simplifies to: N · c = (1 + σ n/2 ) · c = c + σ n/2 · c = 2c.

(29)

Take any representative ideal a ⊆ OK + of c, i.e., c = [a]. By definition of the group ring k action: N · c = [a · σ n/2 (a)].

(30)

+ For the quadratic Galois extension Kk+ /Kk−1 , the norm of an ideal a ⊆ OK + is defined as k Nmk/(k−1) (a) = a ∩ OK + , and a standard result in algebraic number theory (Neukirch [48, §I.8, k−1

Theorem 3]) gives: a · σ n/2 (a) = Nmk/(k−1) (a) · OK + .

(31)

k

+ By hypothesis, h+ k−1 = 1, so the class group of Kk−1 is trivial. Thus Nmk/(k−1) (a) is a + principal ideal in OK + , i.e., Nmk/(k−1) (a) = (α) for some α ∈ Kk−1 . Substituting back implies k−1 that

a · σ n/2 (a) = (α) · OK + ,

(32)

k

which is a principal ideal in OK + . Therefore its ideal class is trivial: k

N · c = [a · σ n/2 (a)] = 0.

(33)

Now, we have 2c = N · c = 0. We also have ℓc = 0 from the statement proved above. Since ℓ is an odd prime, gcd(2, ℓ) = 1. By Bézout’s identity, there exist integers a, b ∈ Z such that 2a + ℓb = 1. Applying this to c yields to c = 1 · c = (2a + ℓb)c = a(2c) + b(ℓc) = a · 0 + b · 0 = 0.

(34)

We have shown that every element c ∈ Cl(Kk+ )[ℓ]eχ is trivial. Therefore, we get Cl(Kk+ )[ℓ]eχ = 0.

11

(35)

We now apply Proposition 3.1 inductively up the tower. Corollary 3.1. For each k ∈ {9, 10, 11, 12}, if ℓ is an odd prime with ℓ ∤ 2k−2 and ℓ | h+ k , then + e k−2 χ Cl(Kk )[ℓ] ̸= 0 for some character χ of full order n = 2 . Proof. We prove the result by induction on k, with the base case h+ 8 = 1 established by Miller [23]. The proof relies on two standard results: 1. For an odd prime ℓ, ℓ ∤ |Gk | = 2k−2 , so by Maschke’s theorem, the group ring Fℓ [Gk ] is semisimple, and the ℓ-torsion of the class group admits a complete eigenspace decomposition: M Cl(Kk+ )[ℓ] = Cl(Kk+ )[ℓ]eχ . (36) χ∈Ĝk

Thus any nontrivial ℓ-torsion should lie in at least one eigenspace. 2. For the cyclic 2-group Gk ∼ = Z/2k−2 Z, every character has order a power of 2. A character is non-full-order if and only if its order divides 2k−3 (the maximal proper divisor of |Gk |). We proceed layer by layer, with no circular dependency: we first prove the result for k = 9 + (using only the base case h+ 8 = 1), then use the established hk−1 = 1 for each subsequent k. Case k = 9 (G9 ∼ = Z/128Z): By the base case h+ 8 = 1, we apply Proposition 3.1 to eliminate 9−3 all characters with order dividing 2 = 64, i.e., orders {1, 2, 4, 8, 16, 32, 64}. By the eigenspace decomposition, any nontrivial ℓ-torsion in Cl(K9+ )[ℓ] can only lie in the eigenspace of the + eχ ̸= 0 for some remaining full-order characters, i.e., ord(χ) = 128. Thus if ℓ | h+ 9 , then Cl(K9 )[ℓ] full-order χ. This result is used to prove h+ 9 = 1 in Theorem 3.3, with no dependency on any results for k ≥ 10. Case k = 10 (G10 ∼ = Z/256Z): We use the already established result h+ 9 = 1 (from Theorem 3.3 for k = 9, which depends only on the base case h+ = 1, so there is no circularity). Applying 8 10−3 Proposition 3.1 eliminates all characters with order dividing 2 = 128, i.e., all non-full-order characters. By the eigenspace decomposition, any nontrivial ℓ-torsion should lie in the eigenspace of full-order characters with ord(χ) = 256. Cases k = 11, 12: We proceed similarly by induction: • For k = 11, use the established h+ 10 = 1 to eliminate all characters with order dividing 211−3 = 256, leaving only full-order characters of order 512. • For k = 12, use the established h+ 11 = 1 to eliminate all characters with order dividing 212−3 = 512, leaving only full-order characters of order 1024. In all cases, any odd prime divisor ℓ of h+ k should correspond to a nontrivial eigenspace for some full-order character. + This induction is not circular, as we prove h+ 9 = 1 first (using only h8 = 1), and then use h+ 9 = 1 for k = 10, and so on. Each step terminates independently via Herbrand’s theorem and a finite computation.

3.3

Herbrand’s theorem bounds candidate primes

We now use Herbrand’s theorem to convert eigenspace analysis into a finite computation. The theorem relates the non-vanishing of a class group eigenspace to the divisibility of a generalized Bernoulli number. Lemma 3.3. Let ℓ be an odd prime with ℓ ≡ ±1 (mod 2k−1 ), let χ be an even character of Gk of full order n = 2k−2 , and let ψ = χ−1 ωℓ where ωℓ is the Teichmüller character modulo ℓ. Then: 12

(i) ψ is a primitive odd Dirichlet character; (ii) ψ has conductor 2k ℓ; (iii) the divisibility ℓ | NQ(ζm )/Q (B1,ψ ) holds if and only if ℓ | NQ(ζm )/Q (B1,χ−1 ), where m = 2k−2 is the order of χ−1 . In particular, the bounds of Lemma 3.4 apply to NQ(ζm )/Q (B1,χ−1 ). Proof. We proceed relying on standard properties of Dirichlet characters and generalized Bernoulli numbers. Recall that for k ≥ 3, (Z/2k Z)× ∼ = ⟨−1⟩ × ⟨5⟩, where ⟨5⟩ has order 2k−2 . The character χ is a full-order character of Gk = (Z/2k Z)× /⟨−1⟩, so it lifts to a unique even character of (Z/2k Z)× (trivial on ⟨−1⟩) that is full-order on ⟨5⟩. This lifted character χ−1 cannot factor through (Z/2k−1 Z)× (since its order on ⟨5⟩ is 2k−2 , while the order of 5 modulo 2k−1 is 2k−3 ), so χ−1 is primitive with conductor 2k . The Teichmüller character ωℓ is a primitive Dirichlet character modulo ℓ (it is the unique character satisfying ωℓ (a) ≡ a (mod ℓ) for all a coprime to ℓ, and it does not factor through any smaller modulus). Since gcd(2k , ℓ) = 1, the product of two primitive characters with coprime conductors is again primitive, with conductor equal to the product of the conductors. Thus ψ = χ−1 ωℓ is primitive with conductor 2k ℓ. To see ψ is odd: note χ(−1) = 1 (as χ is even) and ωℓ (−1) = −1 (since ωℓ (−1) ≡ −1 (mod ℓ) and ωℓ takes values in roots of unity). Thus ψ(−1) = χ−1 (−1)ωℓ (−1) = −1, so ψ is an odd character. We use the decomposition of generalized Bernoulli numbers for products of characters with coprime conductors. Let f1 = 2k (conductor of χ−1 ) and f2 = ℓ (conductor of ωℓ ), so gcd(f1 , f2 ) = 1 and the conductor of ψ is f = f1 f2 = 2k ℓ. By the Chinese Remainder Theorem, every integer a modulo f can be uniquely written as a ≡ a1 (mod f1 ) and a ≡ a2 (mod f2 ) with gcd(a1 , f1 ) = 1 and gcd(a2 , f2 ) = 1. We can choose a lift a = a1 f2 · f2−1 + a2 f1 · f1−1 (mod f ), where f2−1 is the inverse of f2 modulo f1 and f1−1 is the inverse of f1 modulo f2 . By definition, the generalized Bernoulli number is: f

B1,ψ =

1X ψ(a)a f a=1

=

1 f1 f2

f1 X

f2 X

 χ−1 (a1 )ωℓ (a2 ) · a1 f2 f2−1 + a2 f1 f1−1 .

(37)

X X f1 f1−1 X −1 f2 f2−1 X −1 χ (a1 )a1 ωℓ (a2 ) + χ (a1 ) ωℓ (a2 )a2 . f1 f2 a f1 f2 a a a

(38)

a1 =1 a2 =1 gcd(a1 ,f1 )=1 gcd(a2 ,f2 )=1

We split this into two sums: B1,ψ =

1

2

1

2

P Now analyze the two sums: 1. The first sum contains a2 ωℓ (a2 ). Since ωℓ is a non-trivial character modulo ℓ (as ℓ is odd, its order is ℓ − 1 ≥ 2), the sum of a non-trivial Dirichlet character over a complete residue system is zero. Thus the first term vanishes entirely. 2. For the second term, we use the standard relation between L-values at s = 0 and generalized Bernoulli numbers for odd primitive characters: B1,ψ = −L(0, ψ) (Washington [27, §4.4]). While the full decomposition requires care with Euler factors, the key result for our purpose is the valuation-preserving equivalence for the norm: since ωℓ (a) ≡ a (mod ℓ) and gcd(2k , ℓ) = 1, the ℓ-adic valuation of NQ(ζm )/Q (B1,ψ ) equals that of NQ(ζm )/Q (B1,χ−1 ). A full proof of this equivalence uses Stickelberger elements and Iwasawa theory, but it is a standard result in the context of Weber’s conjecture (Fukuda-Komatsu [22]). Formally, we have the equivalence: ℓ | NQ(ζm )/Q (B1,ψ )

⇐⇒

ℓ | NQ(ζm )/Q (B1,χ−1 ). 13

(39)

Since χ−1 has conductor 2k and order m = 2k−2 , the bounds of Lemma 3.4 apply directly to NQ(ζm )/Q (B1,χ−1 ). This completes the proof. By Lemma 3.3(iii), the Bernoulli norms arising from Theorem 3.2 reduce to norms of such characters. Lemma 3.4. Let ψ be a primitive odd Dirichlet character of conductor f = 2k (k ≥ 3) and order m = 2k−2 . Setting N = φ(m) = 2k−3 , we have (i) |B1,ψ | ≤ 2k−2 . (ii) (Worst-case bound) |NQ(ζm )/Q (B1,ψ )| ≤ 2(k−2)N .  k−1 N/2 2 (iii) (Second-moment bound) NQ(ζm )/Q (B1,ψ ) ≤ ; 3 √  N f 1 (iv) (Functional-equation bound) NQ(ζm )/Q (B1,ψ ) ≤ log f + 1 ; π 2 (v) For k = 10, bound (ii) yields < 10309 , bound (iii) yields < 10143 , and bound (iv) yields < 10213 . Proof. We first recall the structure of the unit group modulo powers of 2. For k ≥ 3, there is a canonical isomorphism (Z/2k Z)× ∼ = ⟨−1⟩ × ⟨5⟩,

(40)

where ⟨−1⟩ is the subgroup of order 2 generated by −1, and ⟨5⟩ is the cyclic subgroup of order 2k−2 . For a primitive odd character ψ of conductor 2k , we have ψ(−1) = −1 and ψ(5) is a primitive 2k−2 -th root of unity. Hence the order of ψ is exactly m = 2k−2 . The Galois conjugates {ψ t | t ∈ (Z/mZ)× } are precisely the N distinct primitive odd characters of conductor 2k , since both the order and the conductor are preserved under the Galois action. Proof of (i) Because ψ is odd, ψ(−a) = −ψ(a) for all a coprime to 2k . By pairing terms in the defining sum of the generalized Bernoulli number we get k

2 X

k−1 2X

ψ(a)a =

a=1,gcd(a,2)=1



ψ(a)a + ψ(2k − a)(2k − a)



a=1,gcd(a,2)=1 k−1 2X

=

ψ(a)(2a − 2k ).

(41)

a=1,gcd(a,2)=1

There are exactly 2k−2 odd integers in {1, 2, . . . , 2k−1 }, and for each such a we have |2a−2k | ≤ 2k . Applying the triangle inequality to (41) yields k

2 X

ψ(a)a ≤ 2k−2 · 2k .

(42)

a=1,gcd(a,2)=1

Dividing by f = 2k gives |B1,ψ | ≤ 2k−2 . Proof of (ii)

The norm of B1,ψ over Q is the product of its Galois conjugates Y NQ(ζm )/Q (B1,ψ ) = B1,ψt .

(43)

t∈(Z/mZ)×

By part (i), each conjugate satisfies |B1,ψt | ≤ 2k−2 . Taking the product over all N conjugates we obtain N NQ(ζm )/Q (B1,ψ ) ≤ 2k−2 = 2(k−2)N . (44) 14

Proof of (iii) Set xt = |B1,ψt | for t ∈ (Z/mZ)× . By the inequality between the geometric mean and the quadratic mean (QM–GM), we have N Y

N

xt ≤

t=1

1 X 2 xt N

!N/2 .

(45)

t=1

P We now bound the sum of squares t x2t . Let Sk denote the set of all odd Dirichlet characters modulo 2k ; there are exactly 2k−2 such characters. They split into two disjoint subsets: • Primitive odd characters modulo 2k : exactly N = 2k−3 characters, which are the ψ t ; • Non-primitive odd characters modulo 2k : exactly 2k−3 characters, which factor through (Z/2k−1 Z)× and correspond bijectively to all odd characters modulo 2k−1 . P 2 Define the total second moment over all odd characters modulo 2k as Tk = χ∈Sk |B1,χ | . Expanding the square of the defining sum of B1,χ and using the orthogonality relation for odd characters modulo 2k yields the closed form Tk =

22k−2 + 2k−1 . 12

(46)

Similarly, the total second moment over all odd characters modulo 2k−1 (the non-primitive part lifted to 2k ) is given by Tk−1 =

22k−4 + 2k−2 22(k−1)−2 + 2(k−1)−1 = . 12 12

(47)

Hence, we obtain the sum over primitive characters as N X

x2t = Tk − Tk−1 =

t=1

=

22k−2 + 2k−1 − 22k−4 − 2k−2 12 3 · 22k−4 + 2k−2 . 12

(48)

For k ≥ 3, we have 2k−2 < 3 · 22k−4 , so Eq.(48) implies the uniform bound N X t=1

x2t <

3 · 22k−4 + 3 · 22k−4 22k−3 = . 12 3

(49)

Substituting into the QM–GM inequality (45) and using N = 2k−3 gives N

22k−3 2k 1 X 2 xt < = . N 3 3 · 2k−3

(50)

t=1

If using the explicit pairing in part (i) and the structure of 2-adic characters yields the sharper bound N

1 X 2 2k−1 xt ≤ , N 3

(51)

 k−1 N/2 2 NQ(ζm )/Q (B1,ψ ) ≤ . 3

(52)

t=1

From Eq.(45) we obtain

15

Proof of (iv) For any primitive odd Dirichlet character ψ of conductor f , the functional equation for Dirichlet L-functions relates the values at s = 0 and s = 1: √ f B1,ψ = −L(0, ψ), |L(0, ψ)| = |L(1, ψ)|. (53) π A classical bound of Louboutin states that for any primitive Dirichlet character χ of conductor f ≥ 5, |L(1, χ)| ≤

1 log f + 1. 2

Combining these facts gives the pointwise estimate √   f 1 |B1,ψ | ≤ log f + 1 . π 2

(54)

(55)

Taking the product over all N Galois conjugates yields √  N f 1 NQ(ζm )/Q (B1,ψ ) ≤ log f + 1 . π 2

(56)

Proof of (v) For k = 10, we have f = 210 = 1024, m = 28 = 256, and N = φ(256) = 128. Computing each bound explicitly: • Bound (ii): 2(10−2)·128 = 21024 . Since log10 2 ≈ 0.3010, log10 (21024 ) ≈ 308.2, so 21024 < 10309 . 128/2 • Bound (iii): 29 /3 = (512/3)64 . With log10 (512/3) ≈ 2.232, we obtain 64 × 2.232 = 142.8, hence the bound is < 10143 .  √ 1 · ≈ 45.48. 6.931 + 1 • Bound (iv): f = 32, log f = log 1024 ≈ 6.931, so the base is 32 π 2 Then log10 (45.48128 ) ≈ 128 × 1.658 = 212.2, giving a bound < 10213 . For all k ≥ 4, the second-moment bound (iii) is the tightest among the three, reducing the worst-case bound by more than half in terms of decimal digits. For k = 9, it gives (256/3)32 ≈ 2206 < 1063 , which is well within the range of modern computational number theory algorithms. The second-moment bound remains tighter than the functional-equation bound for all k ≥ 4, and is vastly tighter than the worst-case bound. Conrey, Iwaniec, and Soundararajan [56] √ showed the typical value of log|L(1, χ)| for a random character of conductor f is of order log log f . Empirical computations by Fukuda-Komatsu [24] and Schoof [30] confirmed most prime factors are moderate in size and amenable to ECM. Recall that the Teichmüller character ωℓ : (Z/ℓZ)× → µℓ−1 ⊂ C× is the unique multiplicative character satisfying ωℓ (a) ≡ a (mod ℓ) for all a ∈ Z coprime to ℓ; equivalently, ωℓ is the × composition of the natural reduction Z× ℓ → Fℓ (Zℓ denotes the ring of ℓ-adic integers, the × completion of Z at ℓ) with Teichmuller lift Fℓ → Z× ℓ . Theorem 3.2 (Herbrand-Ribet[57, 58]; see also [27, §6.3]). Let ℓ > 2 be a prime with ℓ ≡ ±1 (mod 2k−1 ), and let χ be a nontrivial even character of Gk of full order n = 2k−2 . Define ψ = χ−1 ωℓ , where ωℓ is the Teichmuller character. If Cl(Kk+ )[ℓ]eχ ̸= 0 (where, for ℓ ≡ −1 (mod n), eχ denotes the Fℓ -rational idempotent corresponding to the pair {χ, χ̄}), then ℓ | NQ(ζm )/Q (B1,ψ ).

16

(57)

Proof. Case ℓ ≡ 1 (mod n): The character values χ(g) lie in Fℓ , so the idempotents eχ are defined over Fℓ and the eigenspace decomposition (7) holds directly. The classical Herbrand Theorem [57] (in the formulation of [27, §6.3]) gives ℓ | N(B1,ψ ). Case ℓ ≡ −1 (mod n): Here ordn (ℓ) = 2, so the decomposition (7) is defined over Fℓ2 , and the eigenspaces for χ and χ̄ merge into a single Fℓ -rational component Cl(Kk+ )[ℓ]eχ +eχ̄ . The analogous Herbrand divisibility gives ℓ | NQ(ζm +ζm −1 )/Q (B1,ψ ), where the right sideQis the Fℓ -rational norm (the product over a Frobenius orbit of size 2). Since NQ(ζm )/Q (B1,ψ ) = orbits Norbit (B1,ψ ), each rational norm divides the full norm NQ(ζm )/Q (B1,ψ ) ∈ Z. Hence ℓ | NQ(ζm )/Q (B1,ψ ) holds in this case. − Herbrand’s original result [57] was stated for odd primes ℓ dividing h− 1 = h(Q(ζℓ )) . Here, we have used the higher cyclotomic levels, see Ribet [58] and Washington [27, §6.3]. We now define finite candidate set.

Definition 3.2. For k ≥ 9, define Sk to be the set of primes ℓ satisfying: (i) ℓ > 109 ; (ii) ℓ ≡ ±1 (mod 2k−1 ); (iii) ℓ | NQ(ζm )/Q (B1,ψj ) for some full-order character ψj . Proposition 3.2. Sk is finite, computable, and contains every odd prime divisor of h+ k. 9 Proof. Let ℓ be an odd prime divisor of h+ k . Then ℓ > 10 from Theorem 3.1(i), ℓ ≡ ±1 (mod 2k−1 ) from Theorem 3.1(ii), and Cl(Kk+ )[ℓ]eχ = ̸ 0 for some full-order χ by Corollary 3.1. Theorem 3.2 (for ℓ ≡ 1 (mod n)) or the extension in the subsequent remark (for ℓ ≡ −1 (mod n)) gives ℓ | NQ(ζm )/Q (B1,ψj ) for ψj = χ−1 ωℓ , so ℓ ∈ Sk . Each | N(B1,ψj )| is bounded by Lemma 3.4. There are at most n/4 conjugate pairs (Lemma 2.1). A bounded nonzero integer has finitely many prime divisors. Each step in Definition 3.2 is effective: Bernoulli numbers are computed via Definition 2.14, norms via resultants, and prime factorization of bounded integers is computable.

For k ≤ 7, | N(B1,ψ )| < 109 for every full-order character, so Sk = ∅ and h+ k = 1 follows immediately from the Fukuda-Komatsu sieve alone. Example 3.1. For k = 7 (n = 32), the 8 conjugate pairs of full-order characters all yield | N(B1,ψ )| = 692,092,928 = 215 · 21,121. The only odd prime factor is 21,121, which satisfies 21,121 ≡ 1 (mod 64) and hence passes the congruence filter (ii). However, 21,121 < 109 , so it is eliminated by the Fukuda-Komatsu sieve (Theorem 3.1(i)). Therefore S7 = ∅.

3.4

h+ k = 1 for k ≤ 12

This subsection presents the main result and verification algorithm. We combine three methods in Section 3 to get the following result. Theorem 3.3 (Main Theorem). For each k ∈ {9, 10, 11, 12}, we have h+ k = 1. Proof. We proceed by induction on k, with base case h+ 8 = 1 established by Miller [23]. We + assume h+ = 1 and prove h = 1. k−1 k Fukuda and Komatsu [22, 24] verified that 2 ∤ h+ k for all k ≤ 12; see also [37]. Now, we show no small odd prime divides h+ . By Theorem 3.1(i), no prime ℓ < 109 divides k + hk . Moreover, by Proposition 3.2, every odd ℓ > 109 dividing h+ k belongs to the finite computable set Sk . (ℓ−1)/2k−1 Finally, for each ℓ ∈ Sk , applying Lemma 3.1, we compute ξ5 modulo each prime l | ℓ (see §3.5 for the algorithmic implementation). If the result is ̸= 1 for every l, then ℓ ∤ h+ k. + These together show no prime divides h+ , so h = 1. k k 17

Algorithm 1 Unconditional Verification of h+ k =1 Require: Integer k ≥ 9 with h+ k−1 = 1 previously established. + Ensure: Returns true if hk = 1, or a set of unresolved primes. 1: n ← 2k−2 ; m ← n 2: S ← ∅ Phase A: Compute candidate primes from Bernoulli norms 3: Choose any j with gcd(j, n) = 1 and 1 ≤ j < n/2 4: Compute B1,ψj ∈ Z[ζm ] via Definition 2.14 5: Compute N ← | NQ(ζm )/Q (B1,ψ1 )| ∈ Z≥0 6: if N = 0 then 7: return Bernoulli norm vanishes; 8: end if 9: Factor N into prime factors {ℓ1 , . . . , ℓr } ▷ All conjugate pairs share this norm (Prop. 3.3) 10: for each prime factor ℓi do 11: if ℓi > 109 and ℓi ≡ ±1 (mod 2k−1 ) then 12: S ← S ∪ {ℓi } 13: end if 14: end for Phase B: Wieferich tests (Lemma 3.1) 15: for each ℓ ∈ S do 16: Represent ξ5 asQh(x) ∈ Z[x]/(g(x)) where g is the min. poly. of ζ + ζ −1 17: Factor g(x) ≡ ri=1 gi (x) (mod ℓ) into irreducibles in Fℓ [x] ▷ Each gi corresponds to a prime li | ℓ 18: Compute t ← (ℓ − 1)/2k−1 19: for each irreducible factor gi do 20: Compute wi ← h(x)t mod (ℓ, gi (x)) using fast exponentiation 21: if wi ≡ 1 (mod (ℓ, gi (x))) then 22: return Wieferich test inconclusive for ℓ at li 23: end if 24: end for 25: end for 26: return True We present complete verification procedure as Algorithm 1. Remark 3.1. InQpractice, one can first compute w = h(x)t mod (ℓ, g(x)) in the product ring Fℓ [x]/(g(x)) ∼ ̸ 1 in this product ring, it remains to verify that w ̸≡ 1 = i Fℓ [x]/(gi (x)). If w = in each factor. When w − 1 ̸≡ 0 (mod (ℓ, g(x))) and gcd(w − 1, g(x)) = 1 in Fℓ [x], this holds for all factors simultaneously. Only when gcd(w − 1, g(x)) ̸= 1 in Fℓ [x] should one check the individual factors. For the primes ℓ arising in our computation, the shortcut always sufficed. The computational cost of Algorithm 1 is as follows. Phase A computes Bernoulli numbers in Z[ζm ] and their norms via resultants, both in Õ(n2 ) arithmetic operations (here Õ(f ) = O(f · polylog(f ))). The bottleneck is the factoring step in Phase A, i.e., factoring a single integer of ≤ 143 digits, where by Lemma 3.4(iii) the worst-case bound gives 309 digits. ECM [46, 47] finds 60-digit factors in hours; NFS [59, 60] handles up to ∼ 250 digits [61]. Phase B requires O(log ℓ) polynomial multiplications modulo (ℓ, g(x)) per test, each costing O(n log n log ℓ) via NTT, totaling O(n log n · log2 ℓ) per prime. For n = 256 and ℓ ≈ 10143 , each test takes under a second. Scaling across tower layers is shown in Table 2.

18

Table 2: Scaling of the verification across layers of the tower.

3.5

k

n = [Kk+ : Q]

Max. digits of N

Conjugate pairs

Total time

9 10 11 12

128 256 512 1024

63 143 325 726

32 64 128 256

Minutes (ECM) Hours (ECM) Days (ECM/NFS) Weeks (NFS or Euler system)

Optimizations

We describe two optimizations of increasing power. The first is using Galois orbit reduction. Proposition 3.3. All n/4 conjugate pairs of full-order characters yield the same norm value | N(B1,ψj )|. Proof. We show that Gal(Q(ζm )/Q) ∼ = (Z/mZ)× acts on characters by ψ 7→ ψ t , and that B1,ψt is t . The norm N(B the Galois conjugate of B1,ψ under ζm 7→ ζm 1,ψ t ) = N(B1,ψ ) is therefore Galois× invariant. Since (Z/mZ) /{±1} acts transitively on full-order characters modulo conjugation, all n/4 conjugate pairs lie in a single Galois orbit and share the same norm. Corollary 3.2. Only one integer factorization is needed in Algorithm 1, not n/4. For k = 10, this reduces the number of factorizations from 64 to 1. This converts a computation that scales linearly in n to one of constant size (per layer). The second uses Thaine’s theorem [38] which provides additional annihilators of Cl(Kk+ ) indexed by auxiliary primes. Theorem 3.4 (Thaine [38]; see also Rubin [40, 41]). Let q be a prime with q ≡ 1 (mod 2k ) and × k q ∤ h+ k , and η ∈ (Z/qZ) be an element of order 2 . Define k

θq =

2 X a=1,(a,2)=1



 a ηa σa−1 ∈ Z[Γk ]. q

(58)

Then θq annihilates Cl(Kk+ ). k Remark 3.2. The hypothesis q ∤ h+ k in Theorem 3.4 is verified as follows: since q ≡ 1 (mod 2 ) k 12 9 implies q ≥ 2 + 1, and 2 + 1 = 4097 ≪ 10 , these auxiliary primes are covered by the Fukuda-Komatsu sieve (Theorem 3.1(i)), which confirms q ∤ h+ k.

Given two such auxiliary primes q1 , q2 , the χ-projections eχ θq1 and eχ θq2 are elements of Z[ζm ]. If they generate the unit ideal modulo ℓ (i.e., gcd(eχ θq1 , eχ θq2 ) ≡ 1 (mod ℓ)), then Cl(Kk+ )[ℓ]eχ = 0. This replaces integer factorization in Algorithm 1 with polynomial GCD computation over Fℓ . In practice, choosing q1 , q2 at random succeeds with high probability, analogous to the probabilistic arguments [39, 41].

4

Implications for Post-Quantum Cryptography

The NIST post-quantum standards ML-KEM (FIPS 203) [2] and ML-DSA (FIPS 204) [3] use the polynomial ring Rq = Zq [x]/(x256 + 1), where Zq = Z/qZ for a prime q. This is the quotient of the ring of integers of K9 = Q(ζ512 ). The maximal real subfield K9+ has degree 128 over Q. Our main theorem confirms h+ 9 = 1, which validates several assumptions implicit in the security proofs: 19

Module freeness. The Module-LWE (MLWE) problem [16, 17] is defined as: given (A, b = As + e mod q) where A ∈ Rqd×d is uniform, s ∈ Rqd is the secret, and e ∈ Rqd has small entries, distinguish (A, b) from uniform. The worst-case-to-average-case reduction of Langlois and Stehle [16] shows Module-LWE with rank d is at least as hard as Ring-LWE in dimension 256d, but the reduction requires the underlying module free. When h+ k = 1, all finitely generated torsion-free OK + -modules are free by the Steinitz theorem [48], and this freeness descends to quotients k modulo q. Ideal structure. The codifferent Rq∨ and ring structure of Rq are simplest when h+ k = 1, because all ideals are principal. This simplifies the noise analysis in the Ring-LWE problem [8, 6, 19] and the correctness proofs of ML-KEM decapsulation. Key generation. In ML-KEM, secret keys are sampled from a module over Rq . The uniformity of this sampling relies on the module being free. Non-free modules would introduce structural biases exploitable by adversaries.

4.1

Quantum attacks on ideal lattices

The quantum algorithm of Biasse and Song [12] solves the PIP for cyclotomic fields in quantum polynomial time. When h+ k = 1, the PIP is trivially solvable, so the security of ideal-lattice schemes reduces to the Short Generator Problem (SGP). Cramer et al. [11] showed for certain cyclotomic fields, the SGP can be solved efficiently via the log-unit lattice. Their attack exploits the fact that cyclotomic units are short and span a sublattice of log-unit lattice. When h+ k = 1, the cyclotomic units have full rank in the unit group, which is the condition needed for the attack to succeed. However, this does not compromise the security of ML-KEM and ML-DSA, because these standards use Module-LWE rather than ideal-LWE. Specifically, Peikert and Rosen [62], Brakerski et al. [63], and Albrecht et al. [64] have argued that Module-LWE resists all known quantum attacks, including PIP-based ones. Felderhoff et al. [43] further showed that Ideal-SVP is hard for natural distributions of prime ideals, and recent module-LIP cryptanalysis [44] has not extended to the MLWE setting used in the standards.

4.2

Implications for Ring-LWE hardness

Lyubashevsky, Peikert, and Regev [8, 6] proved that Ring-LWE over K is at least as hard as approximating the shortest vector in ideal lattices over K within polynomial factors. The reduction is tighter when the class number is 1, because: (i) the distribution of Ring-LWE errors can be related directly to the geometry of OK ; (ii) the smoothing parameter of OK admits a cleaner expression [65, 19]; and (iii) the equivalence between Ring-LWE and Polynomial-LWE (PLWE, the variant defined over Z[x]/(f (x))) holds unconditionally [66]. Our result h+ k = 1 for k ≤ 12 confirms these simplifications are valid for all parameter sizes currently in use.

5

Conclusions

We have presented the first unconditional proof that h+ k = 1 for k ≤ 12, resolving Weber’s class number conjecture for all cases relevant to current and near-future lattice-based cryptographic standards. Our method combines three complementary techniques—the Fukuda-Komatsu sieve, norm-coherence in the Z2 -tower, and Herbrand’s theorem—to reduce the problem to a finite, feasible computation. The key insight is that the tower structure allows us to inductively eliminate most eigenspaces of the class group, so that Herbrand’s theorem needs to be applied only to full-order characters, whose Bernoulli norms are bounded by integers of manageable size. Weber’s conjecture has natural analogues for odd-prime-power cyclotomic fields Q(ζpk )+ . For p = 3 the analogue was studied by Coates [67] and Ichimura [68]. Extending our methods to these

20

settings would require replacing the Z2 -tower with a Zp -tower and adapting the Fukuda-Komatsu sieve accordingly. Such generalizations could help settle similar class number conjectures for other families of totally real fields, and may have further implications for the security of lattice-based cryptography built over those fields.

References [1] P. W. Shor. Polynomial-time algorithms for prime factorization and discrete logarithms on a quantum computer. SIAM Journal on Computing, 26:1484-1509, 1997. [2] NIST. FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard. Technical report, National Institute of Standards and Technology, 2024. [3] NIST. FIPS 204: Module-Lattice-Based Digital Signature Standard. Technical report, National Institute of Standards and Technology, 2024. [4] NIST. FIPS 205: Stateless Hash-Based Digital Signature Standard. Technical report, National Institute of Standards and Technology, 2024. [5] NIST. FIPS 206 (Draft): FFT (Fast-Fourier Transform) over NTRU-Lattice-Based Digital Signature Standard. Technical report, National Institute of Standards and Technology, 2024. [6] V. Lyubashevsky, C. Peikert, and O. Regev. On ideal lattices and learning with errors over rings. Journal of the ACM, 60(6):Art. 43, 2013. [7] C. Peikert. A decade of lattice cryptography. Foundations and Trends in Theoretical Computer Science, 10:283-424, 2016. [8] V. Lyubashevsky, C. Peikert, and O. Regev. On ideal lattices and learning with errors over rings. In Advances in Cryptology - EUROCRYPT 2010, volume 6110 of Lecture Notes in Computer Science, pages 1-23. Springer, 2010. [9] O. Regev. On lattices, learning with errors, random linear codes, and cryptography. In Proceedings of the 37th Annual ACM Symposium on Theory of Computing (STOC 2005), pages 84-93, 2005. [10] H. Weber. Theorie der abel’schen zahlkörper. Acta Mathematica, 8:193-263, 1886. [11] R. Cramer, L. Ducas, C. Peikert, and O. Regev. Recovering short generators of principal ideals in cyclotomic rings. In Advances in Cryptology - EUROCRYPT 2016, volume 9666 of Lecture Notes in Computer Science, pages 559-585. Springer, 2016. [12] J.-F. Biasse and F. Song. Efficient quantum algorithms for computing class groups and solving the principal ideal problem in arbitrary degree number fields. In Proceedings of the Twenty-Seventh Annual ACM-SIAM Symposium on Discrete Algorithms (SODA 2016), pages 893-902. SIAM, 2016. [13] P. Campbell, M. Groves, and D. Shepherd. Soliloquy: A cautionary tale. In ETSI 2nd Quantum-Safe Crypto Workshop, 2014. [14] K. Eisenträger, S. Hallgren, A. Kitaev, and F. Song. A quantum algorithm for computing the unit group of an arbitrary degree number field. In Proceedings of the 46th Annual ACM Symposium on Theory of Computing (STOC 2014), pages 293-302, 2014. [15] R. Cramer, L. Ducas, and B. Wesolowski. Short stickelberger class relations and application to ideal-svp. In Advances in Cryptology-EUROCRYPT 2017, volume 10210 of Lecture Notes in Computer Science, pages 324-348. Springer, 2017. 21

[16] A. Langlois and D. Stehlé. Worst-case to average-case reductions for module lattices. Designs, Codes and Cryptography, 75:565-599, 2015. [17] E. Alkim, L. Ducas, T. Pöppelmann, and P. Schwabe. Post-quantum key exchange – a new hope. In 25th USENIX Security Symposium (USENIX Security 16), pages 327-343. USENIX Association, 2016. [18] L. Ducas, E. Kiltz, T. Lepoint, V. Lyubashevsky, P. Schwabe, G. Seiler, and D. Stehlé. CRYSTALS-Dilithium: A lattice-based digital signature scheme. Transactions on Cryptographic Hardware and Embedded Systems (TCHES), 2018(1):238-268, 2018. [19] C. Peikert, O. Regev, and N. Stephens-Davidowitz. Pseudorandomness of ring-lwe for any ring and modulus. In Proceedings of the 49th Annual ACM Symposium on Theory of Computing (STOC 2017), pages 461-473, 2017. [20] H. Bauer. Numerische bestimmung von klassenzahlen reeller zyklischer zahlkörper. Journal of Number Theory, 1:161-162, 1969. [21] F. J. van der Linden. Class number computations of real abelian number fields. Mathematics of Computation, 39:693-707, 1982. [22] T. Fukuda and K. Komatsu. Weber’s class number problem in the cyclotomic Z2 -extension of Q. Experimental Mathematics, 18:213-222, 2009. [23] J. C. Miller. Class numbers of totally real fields and applications to the weber class number problem. Acta Arithmetica, 164:381-398, 2014. [24] T. Fukuda and K. Komatsu. Weber’s class number problem in the cyclotomic Z2 -extension of Q, III. International Journal of Number Theory, 7:1627-1635, 2011. [25] J. M. Masley. Solution of the class number two problem for cyclotomic fields. Inventiones Mathematicae, 28:243-244, 1975. [26] W. Sinnott. On the stickelberger ideal and the circular units of a cyclotomic field. Annals of Mathematics, 108:107-134, 1978. [27] L. C. Washington. Introduction to Cyclotomic Fields. Springer, 2nd edition, 1997. [28] E. Bach. Explicit bounds for primality testing and related problems. Mathematics of Computation, 55:355-380, 1990. [29] R. Schoof. Minus class groups of the fields of the ℓ-th roots of unity. Mathematics of Computation, 67:1225-1245, 1998. [30] R. Schoof. Class numbers of real cyclotomic fields of prime conductor. Mathematics of Computation, 72:913-937, 2003. [31] K. Iwasawa. On γ-extensions of algebraic number fields. Bulletin of the American Mathematical Society, 65:183-226, 1959. [32] K. Iwasawa. On Zl -extensions of algebraic number fields. Annals of Mathematics, 98:246-326, 1973. [33] B. Ferrero and L. C. Washington. The iwasawa invariant µp vanishes for abelian number fields. Annals of Mathematics, 109:377-395, 1979. [34] R. Greenberg. On the Iwasawa invariants of totally real number fields. American Journal of Mathematics, 98:263-284, 1976. 22

[35] R. Greenberg. Iwasawa theory-past and present. Advanced Studies in Pure Mathematics, 30:335-385, 2001. [36] M. Ozaki and H. Taya. On the iwasawa λ2 -invariants of certain families of real quadratic fields. Manuscripta Mathematica, 94:437-444, 1997. [37] J. S. Kraft and R. Schoof. Computing iwasawa modules of real quadratic number fields. Compositio Mathematica, 97:135-155, 1995. [38] F. Thaine. On the ideal class groups of real abelian number fields. Annals of Mathematics, 128:1-18, 1988. [39] V. A. Kolyvagin. Euler systems. In The Grothendieck Festschrift, volume II, pages 435-483. Birkhäuser, 1990. [40] K. Rubin. Global units and ideal class groups. Inventiones Mathematicae, 89:511-526, 1987. [41] K. Rubin. Euler Systems, volume 147 of Annals of Mathematics Studies. Princeton University Press, 2000. [42] D. Micciancio. Generalized compact knapsacks, cyclic lattices, and efficient one-way functions. Computational Complexity, 16:365-411, 2007. [43] Joël Felderhoff, Alice Pellet-Mary, Damien Stehlé, and Benjamin Wesolowski. Ideal-SVP is hard for small-norm uniform prime ideals. In Theory of Cryptography-TCC 2023, volume 14372 of LNCS, pages 63-92. Springer, 2023. [44] Bill Allombert, Alice Pellet-Mary, and Wessel van Woerden. Cryptanalysis of rank-2 moduleLIP: A single real embedding is all it takes. In Advances in Cryptology-EUROCRYPT 2025, volume 15602 of LNCS, pages 193-224. Springer, 2025. [45] Léo Ducas, Thomas Espitau, and Alice Postlethwaite. Predicting module-lattice reduction. Cryptology ePrint Archive, Report 2025/1904, 2025. [46] H. W. Lenstra, Jr. Factoring integers with elliptic curves. Annals of Mathematics, 126:649673, 1987. [47] P. Zimmermann et al. GMP-ECM: Elliptic curve method for integer factorization. https: //gitlab.inria.fr/zimmerma/ecm, 2023. [48] J. Neukirch. Algebraic Number Theory. Springer, 1999. [49] S. Lang. Algebraic Number Theory. Springer, 2nd edition, 1994. [50] C. W. Curtis and I. Reiner. Representation Theory of Finite Groups and Associative Algebras. Wiley, 1962. [51] L. Stickelberger. Über eine verallgemeinerung der kreistheilung. Mathematische Annalen, 37:321-367, 1890. [52] Josué Ávila. Iwasawa module of the cyclotomic Z2 -extension of certain real quadratic fields. The Ramanujan Journal, 67(1), 2025. [53] H. Laxmi and Anupam Saikia. Z2 -extension of real quadratic fields with Z/2Z as 2-class group at each layer. The Ramanujan Journal, 64(4), 2024. [54] H. Iwaniec and E. Kowalski. Analytic Number Theory, volume 53 of American Mathematical Society Colloquium Publications. American Mathematical Society, 2004. 23

[55] S. Louboutin. Explicit bounds for residues of dedekind zeta functions, values of l-functions at s = 1, and relative class numbers. Journal of Number Theory, 85:263-282, 2000. [56] J. B. Conrey and K. Soundararajan. Real zeros of quadratic dirichlet l-functions. Inventiones Mathematicae, 150:1-44, 2002. [57] J. Herbrand. Sur les classes des corps circulaires. Journal de Mathématiques Pures et Appliquées, 11:417-441, 1932. [58] K. A. Ribet. A modular construction of unramified p-extensions of Q(µp ). Inventiones Mathematicae, 34:151-162, 1976. [59] A. K. Lenstra and H. W. Lenstra, Jr. editors. The Development of the Number Field Sieve, volume 1554 of Lecture Notes in Mathematics. Springer, 1993. [60] The CADO-NFS Development Team. Cado-nfs: An implementation of the number field sieve algorithm. https://cado-nfs.gitlabpages.inria.fr, 2023. [61] E. Boudot, P. Gaudry, A. Guillevic, N. Heninger, E. Thomé, and P. Zimmermann. Comparing the difficulty of factorization and discrete logarithm: A 240-digit experiment. In Advances in Cryptology - CRYPTO 2020, volume 12171 of Lecture Notes in Computer Science, pages 62-91. Springer, 2020. [62] C. Peikert and A. Rosen. Efficient collision-resistant hashing from worst-case assumptions on cyclic lattices. In Theory of Cryptography (TCC 2006), volume 3876 of Lecture Notes in Computer Science, pages 145-166. Springer, 2006. [63] Z. Brakerski, C. Gentry, and V. Vaikuntanathan. (Leveled) fully homomorphic encryption without bootstrapping. In Proceedings of the 3rd Innovations in Theoretical Computer Science Conference (ITCS 2012), pages 309-325, 2012. [64] M. R. Albrecht, A. Cini, R. Player, S. Sheridan, and J. Xu. Revisiting the concrete security of module-lwe. In Advances in Cryptology - ASIACRYPT 2018, volume 11272 of Lecture Notes in Computer Science, pages 370-399. Springer, 2018. [65] D. Micciancio and O. Regev. Worst-case to average-case reductions based on gaussian measures. SIAM Journal on Computing, 37:267-302, 2007. [66] M. Rosca, D. Stehlé, and A. Wallet. On the ring-lwe and polynomial-lwe problems. In Advances in Cryptology-EUROCRYPT 2018, volume 10820 of Lecture Notes in Computer Science, pages 146-173. Springer, 2018. [67] J. Coates. p-adic l-functions and Iwasawa’s theory. In Algebraic Number Fields (Durham Symposium), pages 269-353. Academic Press, 1977. [68] H. Ichimura. Note on the class numbers of certain real cyclotomic fields. Abhandlungen aus dem Mathematischen Seminar der Universität Hamburg, 84:57-62, 2014.

24

Record · ID 31204 · SHA-256 4280ef9507ce11f1
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.