Lidli Niederreiter finite fields 1986
PDF · 415 pages · 8.8 MB
Open PDF file
Published textbook, Introduction to Finite Fields and Their Applications by Rudolf Lidl and Harald Niederreiter, a student edition of their 1983 monograph Finite Fields. Chapters cover algebraic foundations, structure of finite fields, polynomials over finite fields, factorization, exponential sums, and linear recurring sequences. Applications include finite geometries, combinatorics, pseudorandom sequences, coding theory, cryptology, and tables of irreducible polynomials. It is a downloaded book, not Phil's own work.
AI-written summary; may contain errors.
Extracted text (machine-read; may contain errors)
Introduction to finite fields
and their applications
RUDOLF LIDL
University of Tasmania, Hobart, Australia
HARALD NIEDERREITER
Austrian Academy of Sciences, Vienna, Austria
Tht rlf/tt of til.,
UnlomUYo/c...Mr.lo:{rt
tt>JWiltt-WI
tJJI_,.of!Jook4
....... ,..,,tdby
Hnvy Ylll/n 15J.I.
n-UftiHntly/wu P"lnUd
fiN/ pwhlizlltd CONIIJww/y
�l:JU
CAMBRIDGE UNIVERSITY PRESS
Cambridge
London New York New Rochelle
Melbourne Sydney
Published by the Press Syndicate of the University of Cambridge
The Pitt Building. Trumpington Street, Cambridge CB2 1RP
32 East 57th Street, New York, NY 10022, USA
10 Stamfor d Road, Oakleigh, Melbourne 3166, Australia
©Cambridge University Press 1986
First published 1986
Printed in Great Britain at the University Press, Cambridge
British Library Cataloguing in Publication Data
Lidl, Rudolf
Introduct ion to finite fields and their
applications.
1. Finite Fields (Algebra)
I. Title 11 Niederreiter, Harald
512'.3 QA247.3
Library of Congress Cataloging in Publication Data
Lid!, Rudolf.
Introduction to finite frelds and their applications.
Bibliography: p.
Includes index.
1. Finite fields (Algebra) I. Niederreiter, Harald,
1944- II. Title.
QA247.3.L54 1985 512'.3 85-9704
ISBN ().521-J07()6.ji
Contents
Preface vii
Chapter 1 Algebraic Foundations 1
1 Groups 2
2 Rings and Fields 11
3 Polynomials 18
4 Field Extensions 30
Exercises 37
Chapter 2 Structure of Finite Fields 43
1 Characterizat ion of Finite Fields 44
2 Roots of Irreducible Polynomials 47
3 Traces, Norms, and Bases 50
4 Roots of Unity and Cyclotomic Polynomials 59
5 Representation of Elements of Finite Fields 62
6 Wedderburn's Theorem 65
Exercises 69
Chapter 3 Polynomials over Finite Fields 74
1 Order of Polynomials and Primitive Polynomials 75
2 Irreducible Polynomials 82
iv Contents
3 Construction of Irreducible Polynomials 87
4 Linearized Polynomials 98
5 Binomials and Trinomials 115
Exercises 122
Chapter 4 Factorization of Polynomials 129
I Factorization over Small Finite Fields 130
2 Factorization over Large Finite Fields 139
3 Calculation of Roots of Polynomials 150
Exercises 159
Chapter 5 Exponential Sums 162
1 Characters 163
2 Gaussian Sums 168
Exercises 181
Chapter 6 Linear Recurring Sequences 185
1 Feedback Shift Registers, Periodicity Properties 186
2 Impulse Response Sequences, Characteristic Polynomial 193
3 Generating Functions 202
4 The Minimal Polynomial 210
5 Families of Linear Recurring Sequences 215
6 Characteri zation of Linear Recurring Sequences 228
7 Distribution Properties of Linear Recurring Sequences 235
Exercises 245
Chapter 7 Theoretical Applications of Finite Fields 251
1 Finite Geometries 252
2 Combinatorics 262
3 Linear Modular Systems 271
4 Pseudorandom Sequences 281
Exercises 294
Chapter 8 Algebraic Coding Theory 299
1 Linear Codes 300
2 Cyclic Codes 311
3 Goppa Codes 325
Exercises 332
Chapter 9 Cryptology 338
1 Background 339
Contents v
2 Stream Ciphers 342
3 Discrete Logarithms 346
4 Further Cryptosystems 360
Exercises 363
Chapter 10 Tables 367
1 Computation in Finite Fields 367
2 Tables of Irreducible Polynomials 377
Bibliography 392
List of Symbols 397
Index 401
To Pamela and Gerlinde
Preface
This book is designed as a textbook edition of our monograph Finite Fields
which appeared in 1983 as Volume 20 of the Encyclopedia of Mathematics and
Its Applications. Several changes have been made in order to tailor the book to
the needs of the student. The historical lmd bibliographical notes at the end of
each chapter and the long bibliography have been.omitted as they are mainly
of interest to researchers. The reader who desires this type of information may
consult the original edition. There are also changes in the text proper, with the
present book having an even stronger emphasis on applications. The
increasingly important role of finite fields in cryptology is reflected by a new
chapter on this topic. There is now a separate chapter on algebraic coding
theory containing material from the original edition together with a new
section on Goppa codes. New material on pseudorandom sequences has also
been added. On the other hand, topics in the original edition that are mainly of
theoretical interest have been omitted. Thus, a large part of the material on
exponential sums and the chapters on equations over finite fields and on
permutation polynomials cannot be found in the present volume.
The theory of finite fields is a branch of modem algebra that has come
to the fore in the last 50 years because of its diverse applications in
combinatorics, coding theory, cryptology, and the mathematical study of
switching circuits, among others. The origins of the subject reach back
into the 17th and I 8th centuries, with such eminent mathematicians as Pierre
de Fermat(!60!-1665), Leonhard Euler (1707-1783), Joseph-Louis Lagrange
(1736-1813), and Adrien-Marie Legendre (1752-1833) contributing to the
structure theory of special finite fields-namely, the so-called finite prime
fields. The eeneral theorv of finite fields mav be said to beltin with the work of
viii Preface
Carl Friedrich Gauss (1777-1855) and Evariste Galois (1811-1832), but it
only became of interest for applied mathematicians in recent decades with the
emergence of discrete mathematics as a serious discipline.
In this book we have aimed at presenting both the classical and the
applications-oriented aspects of the subject. Thus, in addition to what has to
be considered the essential core of the theory, the reader will find results and
techniques that are of importance mainly because of their use in applications.
Because of the vastness of the subject, limitations had to be imposed on the
choice of material. In trying to make the book as self-contained as possible, we
have refrained from discussing results or methods that belong properly to
algebraic geometry or to the theory of algebraic function fields. Applications
are described to the extent to which this can be done without too much
digression. The only noteworthy prerequisite for the book is a background in
linear algebra, on the level of a first course on this topic. A rudimentary
knowledge of analysis is needed in a few passages. Prior exposure to abstract
algebra is certainly helpful, although all the necessary information is
summarized in Chapter I.
Chapter 2 is basic for the rest of the book as it contains the general
structure theory of finite fields as well as the discussion of concepts that are
used throughout the book. Chapter 3 on the theory of polynomials and
Chapter 4 on factorization algorithms for polynomials are closely linked and
should best be studied together. Chapter 5 on exponential sums uses only the
elementary structure theory of finite fields. Chapter 6 on linear recurring
sequences depends mostly on Chapters 2 and 3. Chapters 7, 8, and 9 are
devoted to applications and draw on various material in the previous
chapters. Chapter 10 supplements parts of Chapters 2, 3, and 9. Each chapter
starts with a brief description of its contents, hence it should not be necessary
to give a synopsis of the book here.
In order to enhance the attractiv eness of this book as a textbook, we
have inserted worked-out examples at appropriate points in the text and
included lists of exercises for Chapters 1-9. These exercises range from routine
problems to alternative proofs of key theorems, but contain also material
going beyond what is covered in the text.
With regard to cross-references, we have numbered all items in the
main text consecutively by chapters, regardless of whether they are definitions,
theorems, examples, and so on. Thus, "Definition 2.41" refers to item 41 in
Chapter 2 (which happens to be a definition) and "Remark 6.23" refers to item
23 in Chapter 6 (which happens to be a remark). In the same vein,
"Exercise 5.21" refers to the list of exercises in Chapter 5.
We gratefully acknowledge the help of Mrs. Melanie Barton and Mrs.
Betty Golding who typed the manuscript with great care and efficiency.
R. LIDL
H. NIEDERREITER
Chapter 1
Algebraic Foundations
This introductory chapter contains a survey of s.ome basic algebraic con
cepts that will be employed throughout the book. Elementary algebra uses
the operations of arithmetic such as addition and multiplication, but
replaces particular numbers by symbols and thereby obtains formulas
that, by substitution, provide solutions to specific numerical problems. In
modem algebra the level of abstraction is raised further: instead of dealing
with the familiar operations on real numbers, one treats general operations
-processes of combining two or more elements to yield another element-in
general sets. The aim is to study the common properties of all systems
consisting of sets on which are defined a fixed number of operations
interrelated in some definite way-for instance, sets with two binary
operations behaving like + and · for the real numbers.
Only the most fundamental definitions and properties of algebraic
systems-that is. of sets together with one or more operations on the
set-will be introduced. and the theory will be discussed only to the extent
needed for our special purposes in the study of finite fields later on. We
state some standard results without proof. With regard to sets we adopt the
naive standpoint. We use the following sets of numbers: the set N of natural
numbers, the set Z of integers, the set (I of rational numbers, the set R of
real numbers, and the set C of complex numbers.
2 Algebraic Foundations
I. GROUPS
In the set of all integers the two operations addition and multiplication are
well known. We can generalize the concept of operation to arbitrary sets.
Let S be a set and let S X S denote the set of all ordered pairs ( s, t) with
s E S, t E S. Then a mapping from S X S into S will be called a (binary)
operation on S. Under this definition we require that the image of (s, t) E
S X S must be in S; this is the closure property of an operation. By an
algebraic structure or algebraic system we mean a set S together with one or
more operations on S.
In elementary arithmetic we are provided with two operations,
addition and multiplication, that have associativity as one of their most
important properties. Of the various possible algebraic systems having a
single associative operation, the type known as a group has been by far the
most extensively studied and developed. The theory of groups is one of the
oldest parts of abstract algebra as well as one particularly rich in applica
tions.
1.1. Definition. A group is a set G together with a binary operation • on
G such that the following three properties hold:
1. • is associative; that is, for any a, b, c E G,
a•(b•c)�(a•b)•c.
2. There is an identity (or unity) element e in G such that for all
aEG,
a•e=e• a=a.
3. For each a E G, there exists an inverse element a-1 E G such that
a•a-1=a-1 •a=e.
If the group also satisfies
4. For all a, bEG,
a•b=b•a,
then the group is called abelian (or commutative).
It is easily shown that the identity element e and the inverse element
a-1 of a given element a E G are uniquely determined by the properties
above. Furthermore, (a • b)-1 � b-1 • a-1 for all a, b E G. For simplicity,
we shall frequently use the notation of ordinary multiplication to designate
the operation in the group, writing simply ab instead of a • b. But it must be
emphasized that by doing so we do not assume that the operation actually is
ordinary multiplication. Sometimes it is also convenient to write a + b
instead of a • band -a instead of a-1, but this additive notation is usually
reserved for abelian groups.
I. Groups 3
The associative law guarantees that expressions such as a1a2 ···a.
with a1 E G, 1"' j"' n, are unambiguous, since no matter how we insert
parentheses, the expression will always represent the same element of G. To
indicate the n-fold composite of an element a E G with itself, where n EN,
we shall write
a"=aa···a ( n factors a)
if using multiplicative notation, and we call a• the nth power of a. If using
additive notation for the operation • on G, we write
na=a +a+ ···+a (nsumman dsa).
Following customary notation, we have the following rules:
Multiplicative Notation
a-•-(a-1)"
a"a"'- a"+'"
(a")"'= a""' Additive Notation
(-n}a=n(-a)
na+ma=(n +m)a
m(na)= (mn)a
For n = 0 E Z, one adopts the convention a0 = e in the multiplicative
notation and Oa-0 in the additive notation, where the last "zero" repre
sents the identity element of G.
1.2. Examples
(i) Let G be the set of integers with the operation of addition. The
ordinary sum of two iritegers is a unique integer and the
associativity is a familiar fact. The identity element is 0 (zero),
and the inverse of an integer a is the integer -a. We denote
this group by Z.
(ii) The set consisting of a single element e, with the operation •
defined by e • e = e, forms a group.
(iii) Let G be the set of remainders of all the integers on division by
6-that is, G = {0, 1,2,3,4,5}-and let a • b be the remainder
on division by 6 of the ordinary sum of a and b. The existence
of an identity element and of inverses is again obvious. In this
case, it requires some computation to establish the associativity
of •. This group can be readily generalized by replacing the
integer 6 by any positive integer n. 0
These examples lead to an interesting class of groups in which every
element is a power of some fixed element of the group. If the group
operation is written as addition, we refer to "multiple" instead of "power"
of an element.
1.3. Definition. A multiplicative group G is said to be cyclic if there is an
element a E G such that for any b E G there is some integer j with b = ai.
4 Algebraic Foundations
Such an element a is called a generator of the cyclic group, and we write
G =(a).
It follows at once from the definition that every cyclic group is
commutative. We also note that a cyclic group may very well have more
than one element that is a generator of the group. For instance, in the
additive group Z both I and -I are generators.
With regard to the" additive" group of remainders of the integers on
division by n, the generalization of Example L2(iii), we find that the type of
operation used there leads to an equivalence relation on the set of integers.
In general, a subset R of S X S is called an equivalence relation on a set S if
it has the following three properties:
(a) (s, s) E R for all s E S (reflexivity).
(b) If (s, t) E R, then (I, s) E R (symmetry).
(c) If (s, t), (I, u) E R, then (s, u) E R (transitivity).
The most obvious example of an equivalence relation is that of equality. It is
an important fact that an equivalence relation R on a set S induces a
partition of S -that is, a representation of S as the union of nonempty,
mutually disjoint subsets of S. If we collect all elements of S equivalent to a
fixed s E S, we obtain the equivalence class of s, denoted by
(s] = {1 E S: (s, t) E R}.
The collection of all distinct equivalence classes forms then the desired
partition of S. We note that [s] = [t] precisely if (s, t) E R. Example L2(iii)
suggests the following concept.
1.4. Definition. For arbitrary integers a, b and a positive integer n, we
say that a is congruent to b modulo n, and write a= bmod n, if the
difference a -b is a multiple of n -that is, if a= b + kn for some integer k.
It is easily verified that "congruence modulo n" is an equivalence
relation on the set Z of integers. The relation is obviously reflexive and
symmetric. The transitivity also follows easily: if a= b + kn and b = c +In
for some integers k and/, then a= c+(k + l)n, so that a= bmodn and
b = cmod n together imply a= cmod n.
Consider now the equivalence classes into which the relation of
congruence modulo n partitions the set Z. These will be the sets
[0] = ( ... , -2n,-n,O, n,2n, ... },
[I]=( ... , -2n +I,- n +I, I, n + 1,2n + !, ... },
[ n -I] = ( ... , -n -I, - I, n -I, 2 n -I, 3n -I, ... }.
We may define on the set ([O],[l], ... ,[n -I]} of equivalence classes a binary
I. Groups
operation (which we shall again write as +, although it is certainly not
ordinary addition) by
[a]+[b]�[a+b], (1.1)
where a and bare any elements of the respective sets [a] and [b] and the
sum a +bon the right is the ordinary sum of a and b. In order to show that
we have actually defined an operation- that is, that this operation is well
defined-we must verify that the image element of the pair ([a],[b]) is
uniquely determined by [a] and [b] alone and does not depend in any way
on the representatives a and b. We leave this proof as an exercise. Associa
tivity of the operation in (1.1) follows from the associativity of ordinary
addition. The identity element is [OJ and the inverse of [a] is [-a]. Thus the
elements of the set {[O],[l], ... ,[n -I]} form a group.
1.5. Definition. The group formed by the set {[O],[l], ... ,[n -I]) of equiv
alence classes modulo n with the operation (1.1) is called the group of
integers modulo n and denoted by Z ,.
Z, is actually a cyclic group with the equivalence class [I] as a
generator, and it is a group of order n according to the following definition.
1.6. Definition. A group is called finite (resp. infinite) if it contains
finitely (resp. infinitely) many elements. The number of elements in a finite
group is called its order. We shall write I G I for the order of the finite
group G. '
There is a convenient way of presenting a finite group. A table
displaying the group operation, nowadays referred to as a Cayley table, is
constructed by indexing the rows and the columns of the table by the group
elements. The element appearing in the row indexed by a and the column
indexed by b is then taken to be ab.
1.7. Example. The Cayley table for the group Z 6 is:
+ [ 0] [I] [2] [3] [4] [5]
[0] [0] [I] [2] [3] [4] [5]
[I] [I] [2] [3] [4] [5] [0]
[2] [2] [3] [4] [5] [0] [I]
[3] [3] [4] [5] [OJ [I] [2]
[4] [4] [5] [0] [I] [2] [3]
[5] [5] [ 0] [I] [2] [3] [4] D
A group G contains certain subsets that form groups in their own
right under the operation of G. For instance, the subset {[0],[2],[4]) of Z6 is
easily seen to have this property.
6 Algebraic Foundations
1.8. Definition. A subset H of the group G is a subgroup of G if H is itself
a group with respect to the operation of G. Subgroups of G other than the
trivial subgroups {e) and G itself are called nontrivial subgroups of G.
One verifies at once that for any fixed a in a group G, the set of all
powers of a is a subgroup of G.
1.9. Definition. The subgroup of G consisting of all powers of the ele
ment a of G is called the subgroup generated by a and is denoted by (a).
This subgroup is necessarily cyclic. If (a) is finite, then its order is called
the order of the element a. Otherwise, a is called an element of infinite order.
Thus, a is of finite order k if k is the least positive integer such that
a'� e. Any other integer m with am� e is then a multiple of k. If S is a
nonempty subset of a group G, then the subgroup H of G consisting of all
finite products of powers of elements of Sis called the subgroup generated
by S, denoted by H � (S). If (S) � G, we say that S generates G, or that G
is generated by S.
For a positive element n of the additive group Z of integers, the
subgroup (n) is closely associated with the notion of congruence modulo n,
since a = b mod n if and only if a -b E ( n). Thus the subgroup ( n) defines
an equivalence relation on Z. This situation can be generalized as follows.
1.10. Theorem. If His a subgroup of G, then the relation R H on G
defined by (a, b) E R H if and only if a � bh for some h E H, is an equivalence
relation.
The proof is immediate. The equivalence relation R H is called left
congruence modulo H. Like any equivalence relation, it induces a partition
of G into nonempty, mutually disjoint subsets. These subsets ( �equivalence
classes) are called the left cosets of G modulo H and they are denoted by
aH � (ah: hE H)
(or a+ H �{a+ h: hE H) if G is written additively). where a is a fixed
element of G. Similarly, there is a decomposition of G into right cosets
modulo H, which have the form Ha � {ha: hE H). If G is abelian, then the
distinction between left and right cosets modulo H is unnecessary.
1.11. Example. Let G � Z 12 and let H be the subgroup ([OJ, [3], [6], [9]).
Then the distinct (left) cosets of G modulo H are given by:
[OJ+ H � {[0], [3], [6], [9]},
[I]+ H � {[I], [ 4], [7], [ 10]},
[2]+ H� {[2].[5],[8],[11]}. 0
1.12. Theorem. If His a finit( subgroup of G, then every (left or
right) coset of G modulo H has the sam4 number of elements as H.
I. Groups 7
1.13. Definition. If the subgroup H of G only yields finitely many
distinct left easels of G modulo H, then the number of such easels is called
the index of H in G.
Since the left easels of G modulo H form a partition of G, Theorem
1.12 implies the following important result.
1.14. Theorem. The order of a finite group G is equal to the product
of the order of any subgroup H and the index of H in G. In particular, the
order of H divides the order of G and the order of any element a E G divides
the order of G.
The subgroups and the orders of elements are easy to describe for
cyclic groups. We summarize the relevant facts in the subsequent theorem.
1.15. Theorem
(i) Every subgroup of a cyclic group is cyclic.
(ii) In a finite cyclic group (a) of order m, the element a• generates a
subgroup of order m jgcd(k, m ), where gcd(k, m) denotes the
greatest common divisor of k and m.
(iii) If dis a positive divisor of the order m of a finite cyclic group (a).
then (a) contains one and only one subgroup of index d. For any
positive divisor f of m, (a) contains precisely one subgroup of
order f.
(iv) Let f be a positive divisor of the order·of a finite cyclic group (a).
Then (a) contains '4>(/) elements of order f. Here '4>(/) is Euler's
function and indicates the number of integers n with 1 � n � f
that are relatively prime to f.
(v) A finite cyclic group (a) of order m contains '4>( mj
generators-that is, elements a' such that (a')= (a). The gen
erators are the powers a' with gcd( r, m) = 1.
Proof (i) Let H be a subgroup of the cyclic group (a) with
H"' (e). If a" E H. then a-" E H; hence H contains at least one power of a
with a positive exponent. Let d be the least positive exponent such that
ad E H, and let a' E H. Dividing s by d gives s = qd + r, 0.;; r < d, and
q, r E Z. Thus a'( a-d)• =a' E H, which contradicts the minimality of d,
unless r = 0. Therefore the exponents of all powers of a that belong to Hare
divisible by d, and soH= (ad).
(ii) Put d=gcd(k,m). The order of (a•) is the least positive
integer n such that a'"= e. The latter identity holds if and only if m divides
kn, or equivalently, if and only if mjd divides n. The least positive n with
this property is n = mjd.
(iii) If dis given, then (ad) is a subgroup of order m 1 d, and so of
index d, because of (ii). If (a•) is another subgroup of index d, then its
8 Algebraic Foundations
order is m/d, and sod� gcd(k, m) by (ii). In particular, d divides k, so that
a• E (ad) and (a•) is a subgroup of (ad). But since both groups have the
same order, they are identical. The second part follows immediately because
the subgroups of order f are precisely the subgroups of index m /f.
(iv) Let l(a)l � m and m � df. By (ii), an element a• is of order /if
and only if gcd(k, m) �d. Hence, the number of elements of order fis equal
to the number of integers k with I.; k.; m and gcd(k, m) �d. We may
write k � dh with I.; h .; f, the condition gcd(k, m) � d being now equiva
lent to gcd(h,fl �I. The number of these his equal to of>(/).
(v) The generators of (a) are precisely the elements of order m, so
that the first part is implied by (iv). The second part follows from (ii). D
When comparing the structures of two groups, mappings between the
groups that preserve the operations play an important role.
1.16. Definition. A mappingf: G--> H of the group G into the group His
called a homomorphism of G into H iff preserves the operation of G. That is,
if • and · are the operations of G and H, respectively, then f preserves the
operation of G if for all a, bEG we have f(a•b)�f (a))(b). If, in
addition, f is onto H, then f is called an epimorphism (or homomorphism
"onto") and His a homomorphic image of G. A homomorphism of G into G
is called an endomorphism. Iff is a one-to-one homomorphism of G onto H,
then/ is called an isomorphism and we say that G and Hare isomorphic. An
isomorphism of G onto G is called an automorphism.
Consider, for instance, the mapping f of the additive group Z of the
integers onto the group z" of the integers modulo n, defined by f(a) �[a].
Then
f(a+b)�[a+b]�[a]+[b]�f(a) +f(b) fora,bEZ,
and f is a homomorphism.
Iff: G--> His a homomorphism and e is the identity element in G,
then ee � e implies/( e)f( e)� f( e), so that/( e)� e', the identity element
in H. From aa-1 �ewe getf(a-1) � (/(a))-1 for all a E G.
The automorphisms of a group G are often of particular interest,
partly because they themselves form a group with respect to the usual
composition of mappings, as can be easily verified. Important examples of
automorphisms are the inner automorphisms. For fixed a E G, define f. by
f.(b) � aba-1 forb E G. Then f. is an automorphism of G of the indicated
type, and we get all inner automorphisms of G by letting a run through all
elements of G. The elements band aba-1 are said to be conjugate, and for a
nonempty subsetS of G the set asa-1 � {asa-1: s E S) is called a conjugal<
of S. Thus, the conjugates of S are just the images of S under the various
inner automorphisms of G.
L Groups 9
1.17. Definition. The kernel of the homomorphism/: G � H of the group
G into the group H is the set
kerf� {a E G: f(a) � e'),
where e' is the identity element in H.
1.18. Example. For the homomorphism f: Z � Z" given by /(a)� [a],
kerf consists of all a E Z with [a]� [OJ. Since this condition holds exactly
for all multiples a of n, we have kerf� (n), the subgroup of Z generated
�n. D
It is easily checked that kerf is always a subgroup of G. More
over, kerf has a special property: whenever a E G and bE kerf, then
aba-1 E kerf. This leads to the following concept.
1.19. Definition. The subgroup H of the group G is called a normal
subgroup of G if aha_, E H for all a E G and all hE H.
Every subgroup of an abelian group is normal since we then have
aha-1 = aa-1h = eh =h. We shall state some alternative characterizations of
the property of normality of a subgroup.
1.20. Theorem
(i) The subgroup H of G is normal if and only if H is equal to its
conjugates, or equivalently, if and only if H is invariant under all
the inner automorphisms of G.
(ii) The subgroup H of G is normal if and only if the left coset aH is
equal to the right coset Ha for every a E G.
One important feature of a normal subgroup is the fact that the set
of its (left) cosets can be endowed with a group structure.
1.21. Theorem. If His a normal subgroup of G, then the set of (left)
cosets of G modulo H forms a group with respect to the operation ( aH )( bH) �
(ab)H.
1.22. Definition. For a normal subgroup H of G, the group formed by
the (left) cosets of G modulo H under the operation in Theorem 1.21 is
called the factor group (or quotient group) of G modulo H and denoted by
GjH.
If G/H is finite, then its order is equal to the index of H in G. Thus.
by Theorem 1.14, we get for a finite group G,
IGI IG/HI � jHj·
Each normal subgroup of a group G determines in a natural way a
homomorphism of G and vice versa.
10 Algebraic Foundations
1.23. Theorem (Homomorphism Theorem). Let f: G--+ /(G)= G1
be a homomorphism of a group G onto a group G 1• Then kerf is a normal
subgroup of G, and the group G 1 is isomorphic to the factor group G lker f.
Conversely, if H is any normal subgroup ofG, then the mapping I}: G --+ G I H
defined by I} (a) = aH for a E G is a homomorphism of G onto G I H with
kerl} =H.
We shall now derive a relation known as the class equation for a
finite group, which will be needed in Chapter 2, Section 6.
1.24. Definition. LetS be a nonempty subset of a group G. The normal
izer of Sin G is the set N(S) =(a E G: asa-1 = S).
1.25. Theorem. For any nonempty subsetS of the group G, N(S) is
a subgroup of G and there is a one-to-one correspondence between the left
cosets of G modulo N(S) and the distinct conjugates asa-1 of S.
Proof We have e E N(S), and if a, bE N(S), then a-1 and ab are
also in N(S), so that N(S) is a subgroup of G. Now
asa-1 = bsb-1 = s = a-1bsb-1a = (a-1b)S(a-1b)-1
= a-1b E N(S) =bE aN(S).
Thus, conjugates of S are equal if and only if they are defined by elements
in the same left coset of G modulo N(S), and so the second part of the
theorem is shown. 0
If we collect all elements conjugate to a fixed element a, we obtain a
set called the conjugacy class of a. For certain elements the corresponding
conjugacy class has only one member, and this will happen precisely for the
elements of the center of the group.
1.26. Definition. For any group G, the center of G is defined as the set
C = ( c E G: ac = ca for all a E G).
It is straightforward to check that the center Cis a normal subgroup
of G. Clearly, G is abelian if and only if C =G. A counting argument leads
to the following result.
1.27. Theorem (Class Equation). Let G be a finite group with
center C. Then
k
IGI=ICI+ L n,,
i-1
where each n, is ;;. 2 and a divisor of IGI. In fact, n1, n2, .. .,n, are the
numbers of elements of the distinct conjugacy classes in G containing more than
one member.
2. Rings and Fields II
Proof Since the relation "a is conjugate to b" is an equivalence
relation on G, the distinct conjugacy classes in G form a partition of G.
Thus, IGI is equal to the sum of the numbers of elements of the distinct
conjugacy classes. There are ICI conjugacy classes (corresponding to the
elements of C) containing only one member, whereas n1, n2, ...• nk are
the numbers of elements of the remaining conjugacy classes. This yields the
class equation. To show that each n, divides IGI, it suffices to note that n, is
the number of conjugates of some a E G and so equal to the number of left
cosets of G modulo N((a )) by Theorem 1.25. D
2. RINGS AND FIELDS
In most of the number systems used in elementary arithmetic there are two
distinct binary operations: addition and multiplication. Examples are pro
vided by the integers, the rational numbers, and the real numbers. We now
define a type of algebraic structure known as a ring that shares some of the
basic properties of these number systems.
1.28. Definition. A ring (R, +, ·) is a set R, together with two binary
operations, denoted by + and ·, such that:
I. R is an abelian group with respect to +.
2. ·is associative-that is, (a·h)·c�a·(b·c) for all a,b,cER.
3. The distributive laws hold; that is, for all a, b, c E R we have
a· ( b + c) � a· b + a· c and ( b + c)· a � b ·a + c · a.
We shall useR as a designation for the ring (R, +,·)and stress that
the operations + and · are not necessarily the ordinary operations with
numbers. In following convention, we use 0 (called the zero element) to
denote the identity element of the abelian group R with respect to addition.
and the additive inverse of a is denoted by -a; also, a+ (-b) is abbrevi
ated by a-b. Instead of a· b we will usually write a b. As a consequence of
the definition of a ring one obtains the general property aO � Oa � 0 for all
a E R. This, in turn, implies (-a )b �a(-b)�-ab for all a, bE R.
The most natural example of a ring is perhaps the ring of ordinary
integers. If we examine the properties of this ring, we realize that it has
properties not enjoyed by rings in general. Thus, rings can be further
classified according to the following definitions.
1.29. Definition
(i) A ring is called a ring with identity if the ring has a multiplica
tive identity-that is, if there is an element e such that ae = ea
�a for all aER.
(ii) A ring is called commutative if · is commutative.
12 Algebraic Foundations
(iii) A ring is called an integral domain if it is a commutative ring
with identity e"' 0 in which ab � 0 implies a� 0 orb� 0.
(iv) A ring is called a division ring (or skew field) if the nonzero
elements of R form a group under ·.
(v) A commutative division ring is called a field.
Since our study is devoted to fields, we emphasize again the defini
tion of this concept. In the first place, a field is a set F on which two binary
operations, called addition and multiplication, are defined and which con
tains two distinguished elements 0 and e with 0-=�:-e. Furthermore, F is an
abelian group with respect to addition having 0 as the identity element, and
the elements of F that are "'0 form an abelian group with respect to
multiplication having e as the identity element. The two operations of
addition and multiplication are linked by the distributive law a( b +c)� ab
+ ac. The second distributive law (b + c)a � ba + ca follows automatically
from the commutativity of multiplication. The element 0 is called the zero
element and e is called the multiplicative identity element or simply the
identity. Later on, the identity will usually be denoted by 1.
The property appearing in Definition l.29(iii)-namely, that ab � 0
implies a� 0 or b � 0-is expressed by saying that there are no zero
divisors. In particular, a field has no zero divisors, for if ab � 0 and a"' 0,
then multiplication by a-1 yields b � a-10 � 0.
In order to give an indication of the generality of the concept of ring,
we present some examples.
1.30. Examples
(i) Let R be any abelian group with group operation +. Define
ab � 0 for all a, bE R: then R is a ring.
(ii) The integers form an integral domain, but not a field.
(iii) The even integers form a commutative ring without identity.
(iv) The functions from the real numbers into the real numbers
form a commutative ring with identity under the definitions for
f+ g andfg given by(/+ gXx)� f(x)+ g(x) and (/gXx)�
f(x)g(x) for x E R.
(v) The set of all 2 X 2 matrices with real numbers as entries forms
a noncommutative ring -with identity with respect to matrix
addition and multiplication. 0
We have seen above that a field is, in particular, an integral domain.
The converse is not true in general (see Example 1.30(ii)), but it will hold if
the structures contain only finitely many elements.
1.31. Theorem. Every finite integral domain is a field.
Proof Let the elements of the finite integral domain R be
a1, a2, ... ,an. For a fixed nonzero element a E R, consider the products
...-....-. ...-....-._ nn Th�""�" Mf" cli ... tinct. for if aa, = aa,. then a( a,-a;)= 0, and
2. Rings and Fields 13
since a* 0 we must have a;-a1 = 0, or a;= a1. Thus each element of R is
of the form aa;. in particular, e = aa; for some i with I� i � n, where e
is the identity of R. Since R is commutative, we have also a;a = e, and so a;
is the multiplicative inverse of a. Thus the nonzero elements of R form a
commutative group, and R is a field. 0
1.32. Definition. A subset S of a ring R is called a subring of R provided
S is closed under + and · and forms a ring under these operations.
1.33. Definition. A subset J of a ring R is called an ideal provided J is a
subring of R and for all a EO J and r EO R we have ar EO J and ra EO J.
1.34. Examples
(i) Let R be the field a of rational numbers. Then the set Z of
integers is a subring of 0, but not an ideal since, for example,
I EO Z. J: EO a, but J: ·I� J: � l.
(ii) Let R be a commutative ring, a EO R, and let J � {ra: rEO R),
then J is an ideal.
(iii) Let R be a commutative ring. Then the smallest ideal contain
ing a given element a EO R is the ideal (a)� (ra + na: rEO R.
n EO Z). If R contains an identity. then (a)� {ra: r EO R). D
1.35. Definition. Let R be a commutative ring. An ideal J of R is said to
be principal if there is an a EO R such that J � (a). In this case. J is also
called the principal ideal generated by a.
Since ideals are normal subgroups of the additive group of a ring, it
follows immediately that an ideal J of the ring R defines a partition of R
into disjoint cosets, called residue classes modulo J. The residue class of the
element a of R modulo J will be denoted by [a]� a+ J. since it consists of
all elements of R that are of the form a + c for some cEO J. Elements
a. b EO R are called congruent modulo J, written a"' b mod J. if they are in
the same residue class modulo J, or equivalently. if a-bE J (compare with
Definition 1.4). One can verify that a"' bmod J implies u + r "'b + rmod J.
ar "' br mod J, and ra "' rb mod J for any r E R and na "' nb mod J for any
n E Z. If, in addition, r "'smod J, then a+ r "'b + smod J and ar"'
bsmod J.
It is shown by a straightforward argument that the set of residue
classes of a ring R modulo an ideal J forms a ring with respect to the
operations
(a+ J)+(b+ J) �(a +b)+J,
(a+ J )( b + J) � ab + J. ( 1.2)
(13)
1.36. Definition. The ring of residue classes of the ring R modulo the
ideal J under the operations ( 1.2) and ( 1.3) is called the residue class ring (or
''""'"" ,_;.,,..\ '"'f D ""'"'rl"l'"' 1 '>�rl ;,., riP�I"\tPrl l·nr 'R IT
14 Algebraic Foundations
1.37. Example (The residue class ring Z/(n)). As in the case of groups
(compare with Definition 1.5). we denote the coset or residue class of the
integer a modulo the positive integer n by [a], as well as by a+ ( n ), where
(n) is the principal ideal generated by n. The elements of Z/(n) are
[O]�O+(n). [l]�l+(n), ... ,[n-l]�n-l+(n). D
1.38. Theorem. Z/( p ), the ring of residue classes of the integers
modulo the principal ideal generated by a prime p, is a field.
Proof By Theorem 1.31 it suffices to show that Z/( p) is an
integral domain. Now [I] is an identity of lj(p), and [a][b]�[ab]�[O] if
and only if ab � kp for some integer k. But since p is prime, p divides ab if
and only if p divides at least one of the factors. Therefore, either [a] � [0] or
[ b] � [0], so that Z/( p) contains no zero divisors. D
1.39. Example. Let p�3. Then Z/(p) consists of the elements [0], [I],
and [2]. The operations in this field can be described by operation tables
that are similar to Cayley tables for finite groups (see Example 1.7):
+ [0] [I] [2]
[0] [0] [I] [2]
[I] [1] [2] [OJ
[2] [2] [0] [1] [0] [I] [2]
[0] [0] [0] [0]
[1] [0] [I] [2]
[2] [0] [2] [1] D
The residue class fields Zj(p) are our first examples of finite fields
-that is, of fields that contain only finitely many elements. The general
theory of such fields will be developed later on.
The reader is cautioned not to assume that in the formation of
residue class rings all the properties of the original ring will be preserved in
all cases. For example, the lack of zero divisors is not always preserved, as
may be seen by considering the ring lj(n), where n is a composite integer.
There is an obvious extension from groups to rings of the definition
of a homomorphism. A mapping cp: R -+ S from a ring R into a ring S is
called a homomorphism if for any a, b E R we have
cp(a+b)�cp(a)+cp(b) and cp(ab)�cp(a)cp(b).
Thus a homomorphism cp: R -+ S preserves both operations + and · of R
and induces a homomorphism of the additive group of R into the additive
group of S. The set
kercp �{a E R: cp·(a) � 0 E S)
is called the kernel of cp. Other concepts, such as that of an isomorphism , are
analogous to those in Definition 1.16. The homomorphism theorem for
rings, similar to Theorem 1.23 for groups, runs as follows.
1.40. Theorem (Homomorphism Theorem for Rings). If cp is a
r .,_ --· 1--- _ :_ -·· ;J __ , -� D ---1 (" ;,.
2. Rings and Fields
isomorphic to the factor ring R/kercp. Conversely, if J is an ideal of the·��_ng
R, then the mapping of: R --> R I J defined by of (a) � a + J for a E R is a
homomorphism of R onto R/J with kernel J.
Mappings can be used to transfer a structure from an algebraic
system to a set without structure. For instance, let R be a ring and let cp be a
one-to-one and onto mapping from R to a set S; then by means of cp one
can define a ring structure on S that converts cp into an isomorphism. In
detail, let s1 and s2 be two elements of Sand let r1 and r2 be the elements of
R uniquely determined by cp(r1)�s1 and cp(r2)�s2. Then one defines
s1 + s2 to be cp(r1 + r2) and Sh to be cp(r1r2), and all the desired properties
are satisfied. This structure on S may be called the ring structure induced by
cp. In case R has additional properties, such as being an integral domain or a
field, then these properties are inherited by S. We use this principle in order
to arrive at a more convenient representation for the finite fields Z/( p ).
1.41. Definition. For a prime p, let F, be the set {0,1, ... ,p-I} of
integers and let cp: Z/(p)--> F, be the mapping defined by cp([a]) �a for
a� 0, I, ... ,p-I. Then F ,. endowed with the field structure induced by cp, is
a finite field, called the Galois field of order p.
By what we have said before, the mapping cp: Z/( p)--> F, is then an
isomorphism, so that cp([a] +[b))� cp([a]) + cp([b]) and cp([a][b]) �
cp([a])cp([b]). The finite field IF, has zero element 0, identity I, and its
structure is exactly the structure of Z/( p ). Computing with elements of F,
therefore means ordinary arithmetic of integers with reduction modulo p.
1.42. Examples
(i) Consider Zj(5), isomorphic to IF5 � {0,1,2,3,4}, with the iso-
morphism given by: [0]--> 0, [I]-> I, [2]--> 2, [3]--> 3, [4]--> 4.
The tables for the two operations + and · for elements in IF 5
are as follows:
+ 0 2 3 4 0 2 3 4
0 0 I 2 3 4 0 0 0 0 0 0
I I 2 3 4 0 I 0 I 2 3 4
2 2 3 4 0 I 2 0 2 4 I 3
3 3 4 0 I 2 3 0 3 I 4 2
4 4 0 I 2 3 4 0 4 3 2 I
(ii) An even simpler and more important example is the finite field
F2. The elements of this field of order two are 0 and I, and the
operation tables have the following form:
In this context. the elements 0 and I are called binary elements. D
16 Algebraic Foundations
If b is any nonzero element of the ring Z of integers, then the
additive order of b is infinite; that is, nb = 0 implies n = 0. However, in the
ring Z/( p ), p prime, the additive order of every nonzero element b is p; that
is, pb = 0, and p is the least positive integer for which this holds. It is of
interest to formalize this property.
1.43. Definition, If R is an arbitrary ring and there exists a positive
integer n such that nr = 0 for every r E R, then the least such positive
integer n is called the characteristic of R and R is said to have (positive)
characteristic n. If no such positive integer n exists, R is said to have
characteristic 0.
1.14. Theorem. A ring R * (0} of positive characteristic having an
identity and no zero divisors must have prime characteristic.
Proof Since R contains nonzero elements, R has characteristic
n;;, 2. If n were not prime, we could write n = km with k, mE Z, l < k, m
< n. Then 0 = ne = (km)e = (ke)(me), and this implies that either ke = 0
or me= 0 since R has no zero divisors. It follows that either kr = (ke)r = 0
for all r E R or mr = (me)r = 0 for all r E R, in contradiction to the
definition of the characteristic n. D
1.45. Corollllry. A finite field has prime characteristic.
Proof By Theorem 1.44 it suffices to show that a finite field F has a
positive characteristic. Consider the multiples e,2e, 3e, ... of the identity.
Since F contains only finitely many distinct elements, there exist integers k
and m with 1.; k < m such that ke =me, or (m-k)e = 0, and so F has a
positive characteristic. D
The finite field Z/(p) (or, equivalently, F,) obviously has character
istic p, whereas the ring Z of integers and the field Q of rational numbers
have characteristic 0. We note that in a ring R of characteristic 2 we have
2a =a+ a= 0, hence a=-a for all a E R. A useful property of commuta
tive rings of prime characteristic is the following.
1.46. Theorem. Let R be a commutative ring of prime characteristic
p. Then
(a+b)r "=aP"+bP " and (a-b)' "=aP"_bp"
for a, bE Rand n EN.
Proof We use the fact that
(P)_p(p-l)···(p-i+l) _
i - 1. 2 ..... i = 0 mod p
for all i E Z with 0 < i < p, which follows from <n being an integer and the
observation that the factor p in the numerator cannot be cancelled. Then by
2. Rings and Fields 17
the binomial theorem (see Exercise 1.8),
(a+b)'�a'+(�)aP-1b+ ··· +(p�l)abp-l +b'�aP+b',
and induction on n completes the proof of the first identity. By what we
have shown, we get
a'"� ((a-b)+ b)'" � (a-b)p " +b'",
and the second identity follows. D
Next we will show for the case of commutative rings with identity
which ideals give rise to factor rings that are integral domains or fields. For
this we need some definitions from ring theory.
Let R be a commutative ring with identity. An element a E R is
called a divisor of bE R if there exists c E R such that ac �b. A unit of R is
a divisor of the.id.e.ntity; two elements a, bE R are said to �.Qilllf& if
there is a unit • of R such that a� b<. An element c E R is called a erime
element if it is no uni�nc!_if)_t.!J'!.§.Q..'!.\Y..t!Je u�ULQf.B_an�l_the.assQc;iates of
c as "iliiii"ScifS.-An .. ideal P � R of the ring lLiu:�JJ ed a prime ideal if for
a, b E R we have ab E P only if either a E P or b E P. An ideal M "' R of R
is called a maximal ideal of R if for any ideal J of R the property M <::: J
implies J � R or J � M. Furthermore, R is said to be a principal ideal
domain if R is an integral domain and if every ideal J of R is-principal-that
is, if there is a generating element a for J such that J �(a)� {ra: r E R).
1.47. Theorem. Let R be a commutative ring with identity. Then:
(i) An ideal M of R is a maximal ideal if and only if Rj M is a field.
(ii) An ideal P of R is a prime ideal if and only if Rj Pis an integral
domain.
(iii) Every maximal ideal of R is a prime ideal.
(iv) If R is a principalideal domain, then Rj(c) is afield if and only
if c is a prime element of R.
Proof
(i) Let M be a maximal ideal of R. Then for a'/' M, a E R, the set
J � {ar + m: r E R, mE M) is an ideal of R properly containing
M, and therefore J � R. In particular, ar + m � 1 for some
suitable r E R, mE M, where I denotes the multiplicative iden
tity element of R. In other words, if a+ M"' 0 + M is an
element of Rj M different from the zero element in Rj M, then
it possesses a multiplicative inverse, because (a+ M)(r + M) �
ar + M �(I-m)+ M �I+ M. Therefore, RjM is a field. Con
versely; let Rj M be a field and Jet J � M, J"' M, be an ideal of
R. Then for a E J, a'/' M, the residue class a+ M has a multi-
18 Algebraic Foundations
plicative inverse, so that (a+ MXr + M) =I+ M for some r E
R. This implies ar + m =I for some mE M. Since J is an ideal,
we have I E J and therefore (I) = R c;: J, hence J = R. Thus M is
a maximal ideal of R.
(ii) Let P be a prime ideal of R; then R/P is a commutative ring
with identity I+ P * 0+ P. Let (a+ P)(b + P) = 0+ P, hence
abE P. Since P is a prime ideal, either a E P or bE P; that is,
either a+ P = 0+ P orb+ P = 0+ P. Thus, R/P has no zero
divisors and is therefore an integral domain. The converse
follows immediately by reversing the steps of this proof.
(iii) This follows from (i) and (ii) since every field is an integral
domain.
(iv) Let cER. If cis a unit, then (c)=R and the ring R/(c)
consists only of one element and is no field. If c is neither a unit
nor a prime element, then c has a divisor a E R that is neither a
unit nor an associate of c. We note that a* 0, for if a= 0, then
c = 0 and a would be an associate of c. We can write c = ab with
bE R. Next we claim that a '1-(c). For otherwise a= cd = abd
for some dE R, or a(!-bd) = 0. Since a* 0, this would imply
bd =I, so that d would be a unit, which contradicts the fact that
a is not an associate of c. It follows that (c) c;: (a) c;: R, where all
containments are proper, and so R/(c) cannot be-'a field be
cause of (i). Finally, we are left with the case where c is a prime
element. Then (c)* R since cis no unit. Furthermore, if J :2 (cj
is an ideal of R, then J = (a) for some a E R since R is a
principal ideal domain. It follows that cE (a), and so a is a
divisor of c. Consequentl y, a is either a unit or an associate of c,
so that either J = R or J = (c). This shows that (c) is a maximal
ideal of R. Hence Rj(c) is a field by (i). 0
As an application of this theorem, let us consider the case R = Z. We
note that Z is a principal ideal domain since the additive subgroups of Z are
already generated by a single element because of Theorem 1.15(i). A prime
number p fits the definition of a prime element, and so Theorem 1.47(iv)
yields another proof of the known result that Z/( p) is a field. Conse
quently, ( p) is a maximal ideal and a prime ideal of Z. ·For a composite
integer n. the ideal (n) is not a prime ideal of Z, and so lj(n) is not even
an integral domain. Other applications will follow in the next section when
we consider residue class rings of polynomial rings over fields.
3. POLYNOMIALS
In elementary algebra one regards a polynomial as an expression of the
fnrrn n_ + n_ y + ... + n r" Thf". n.'s ;ne C:Jlled coefficients and are usuallV
3. Polynomials 19
real or complex numbers; x is viewed as a variable: that is, substituting an
arbitrary number a for x, a well-defined number a0 + a1a + · · · + a"a" is
obtained. The arithmetic of polynomials is governed by familiar rules. The
concept of polynomial and the associated operations can be generalized to a
formal algebraic setting in a straightforward manner.
Let R be an arbitrary ring. A polynomial over R is an expression of
the form
n
f(x)� L a ,x'�a0+a1x+ ··· +a.x",
;-o
where n is a nonnegative integer, the coefficients a;. 0 � i � n, are elements
of R, and xis a symbol not belonging toR, called an indeterminate over R.
Whenever it is clear which indeterminate is meant, we can use f as a
designation for the polynomial f(x). We adopt the convention that a term
a,x' with a,� 0 need not be written down. In particular, the polynomial
f(x) above may then also be given in the equivalent formf(x)�a0+a1x
+ ··· +a11x"+Ox"+1+ ··· +Ox"+h,wherehisanypositive integer.When
comparing two polynomia ls/(x) and g(x) over R, it is therefore possible to
assume that they both involve the same powers of x. The polynomials
n n
f(x) � L a,x' and g(x) � L b,x'
i-0 ;-o
over R are considered equal if and only if a,� b1 for 0 .;; i.;; n. We define
the sum of f(x) and g(x) by ·
n
f(x)+g(x)� L (a,+b,)x'.
i-0
To define the product of two polynomials over R, let
and set n m
f(x)� L a,x' and g(x)� L b1xi
;-o ;-o
n+m
f(x)g(x)� L c.x•, wherec. �
k-0 i+ j-k
O<!O;i"!i;II,O"!i; j<,m
It is easily seen that with these operations the set of polynomials over R
forms a ring.
1.48. Definition. The ring formed by the polynomials over R with the
above operations is called the polynomial ring over R and denoted by R[x ].
The zero element of R[x] is the polynomial all of whose coeffi cients
are 0. This polynomi;u is called the zero polynomial and denoted by 0. It
should always be clear from the context whether 0 stands for the zero
element of R or the zero polynomial.
20 Algebraic Foundations
1.49. Definition. Let f(x) = !:7-oa;x; be a polynomial over R that is not
the zero polynomial, so that we can suppose a,"' 0. Then a, is called the
leading coefficient of f(x) and a0 the constant term, while n is called the
degree of f(x), in symbols n = deg(f(x)) = deg(f). By convention, we set
deg(O) =-oo. Polynomials of degree .,;; 0 are called constant polynomials. If
R has the identity I and if the leading coefficient of f(x) is I, then f(x) is
called a monic polynomial.
By computing the leading coefficient of the sum and the product of
two polynomials, one finds the following result.
1.50. Theorem. Let f, g E R[x]. Then
deg(f + g) .,;; max( deg(f ) , deg( g)) ,
deg(fg) .,;; deg(/ ) + deg( g) .
If R is an integral domain, we have
deg(fg) = deg(f ) + deg( g) . ( 1.4)
If one identifies constant polynomials with elements of R, then R can
be viewed as a subring of R[x1. Certain properties of R are inherited by
R[x1. The essential step in the proof of part (iii) of the subsequent theorem
depends on (1.4).
1.51. Theorem. Let R be a ring. Then:
(i) R[x1 is commutative if and only if R is commutative.
(ii) R[x 1 is a ring with identity if and only if R has an identity.
(iii) R[x1 is an integral domain if and only if R is an integral domain.
In the following chapters we will deal almost exclusively with poly
nomials over fields. Let F denote a field (not necessarily finite). The concept
of divisibility, when specialized to the ring F[x1, leads to the following. The
polynomial g E F[x1 divides the polynomial f E F[x1 if there exists a
polynomial h E F[x1 such that f = gh. We also say that g is a divisor off, or
thatfis a multiple of g, or thatfis divisible by g. The units of F[x1 are the
divisors of the constant polynomial I, which are precisely all nonzero
constant polynomials.
As for the ring of integers, there is a division with remainder in
polynomial rings over fields.
1.52. Theorem (Division Algorithm). Let g"' 0 be a polynomial in
F[x1. Then for any f E F[x1 there exist polynomials q, r E F[x1 such that
f = qg + r, where deg(r) < deg(g).
1.53. Example. Consider f(x) = 2x' + x4 + 4x + 3 E F,[x1, g(x) = 3x2 +
I E IF ,[x1. We compute the polynomials q, r E IF ,[x 1 with/= qg + r by using
3. Polynomials
long division:
4x3+ 2x2+2x + I
3x2 + 11 2x5+x4
-2x5 -4 x3
x4 + x3 +4x+3
-x4 -2x2
x' +3x2+4x
-x3 -2x
3x2+2x+3
-3x2 -1
2x+2 21
Thus q(x) � 4x3 +2x2 +2x +I, r(x) � Zx +2, and obviously deg(r) <
deg(g). 0
The fact that F[ x 1 permits a division algorithm implies by a standard
argument that every ideal of F[ x 1 is principal.
1.54. Theorem. F[x1 is a principal ideal domain . In fact, for every
ideal J * (0) of F[ x 1 there exists a uniquely determined monic polynomial
g E F[x1 with J� (g).
Proof F[x1 is an integral domain by Theorem 1.5l(iii). Suppose
J * (0) is an ideal of F[ x 1· Let h ( x) be a nonzero pelynomial of least degree
contained in J, let b be the leading coefficient of h ( x ), and set g( x) �
b-1h(x). Then g E J and g is monic. Iff E J is arbitrary, the division
algorithm yields q, r E F[x1 with f � qg +rand deg(r) < deg(g) � deg(h).
Since J is an ideal, we get/-qg � r E J, and by the definition of h we must
have r � 0. Therefore, f is a multiple of g, and so J � (g). If g1 E F[x1 is
another monic polynomial with J=(g1), then g�c1g1 and g1�c2g with
c" c2 E F[x1. This implies g � c1c2g, hence c1c2 �I, and c1 and c2 are
constant polynomials. Since both g and g1 are monic, it follows that g � g1,
and the uniqueness of g is established. 0
1.55. Theorem. Let /1, •.• J. be polynomials in F[x1 not all of which
are 0. Then there exists a uniquely determined monic polynomial dE F[x1
with the following properties: (i) d divides each Jj. I .;; j .;; n; (ii) any
polynomial c E F[x1 dividing each Jj. I .;; j .;; n, divides d. Moreover, d can be
expressed in the form
d�bd1 + ··· +b.f. withb" ... ,b.EF[x]. (1.5)
Proof The set J consisting of all polynomials of the form cd1
+ · · · + c.f. with c1, ••• ,c. E F[x1 is easily seen to be an ideal of F[x1.
Since not all Jj are 0, we have J * (0), and Theorem 1.54 implies that J � (d)
22 Algebraic Foundations
for some monic polynomial dE F[x]. Property (i) and the representation
( 1.5) follow immediately from the construction of d. Property (ii) follows
from (1.5). If d1 is another monic polynomial in F[x] satisfying (i) and (ii).
then these properties imply that d and d1 are divisible by each other, and. so
(d)� (d1). An application of the uniqueness part of Theorem 1.54 yields
d�d1• D
The monic polynomial d appearing in the theorem above is called the
greatest common divisor of f1 .... ,f.,, in symbols d � gcd(/1, ••• ,f, ). If
gcd(/1, ••• ,f.,) � I, then the polynomials /1 .... ,f., are said to be relatively
prime. They are called pairwise relatively prime if gcd(/1, f)� I for I .;; i < j
.;; n.
The greatest common divisor of two polynomia ls/, g E F[x] can be
computed by the Euclidean algorithm . Suppose . without loss of generality,
that g"' 0 and that g does not divide f. Then we repeatedly use the division
algorithm in the following manner:
g=q2r1+r2
'1 = q3r1 + 'J 0 .;;deg(r1) <deg(g)
0 .;;deg(r2) <deg(r1)
0 .;; deg(r1) < deg(r2)
0 .;; deg(r,) < deg(r,_1)
Here q1 .... ,q,. 1 and r1 ..... r, are polynomials in F[x ]. Since deg(g) is finite,
the procedure must stop after finitely many steps. If the last nonzero
remainder r, has leading coefficient b, then gcd(/, g)� b-1 r,. In order to
find gcd(/1, ••• ,f.,) for n > 2 and nonzero polynomials f1, one first computes
gcd( /1, /2 ), then gcd(gcd( /1, /2 ), /1 ), and so on, by the Euclidean algorithm.
1.56. Example. The Euclidean algorithm applied to
f(x)�2x6+x1+x2+2Ef1[x], g(x)�x4+x2+2xEIF1[x]
yields:
2x6 + x1 + x2 +2 � (2x2 + I)(x4 + x2 +2x)+x +2
x4 + x2 +2x � (x1 + x2 +2x + I)(x +2)+ I
x+2�(x+2)1.
Therefore gcd(/, g) � I and f and g are relatively prime. D
A counterpart to the notion of greatest common divisor is that of
least common multiple. Let /1, ••• ,f., be nonzero polynomials in F[x]. Then
one shows (see Exercise 1.25). that there exists a uniquely determined monic
J. Polynomials 23
polynomial mE F[x] with the following pfoperties: (i) m is a multiple of
eachJj, I.; j.; n; (ii) any polynomial bE F[x] that is a multiple of eachJj.
I.; j.; n, is a multiple of m. The polynomial m is called the least common
multiple of /1 ..... /,, and denoted by m � lcm(/1 .... .f.). For two nonzero
polynomials/, g E F[x] we have
a-1/g � lcm(/, g )gcd(/, g), ( 1.6)
where a is the leading coefficient of fg. This relation conveniently reduces
the calculation of lcm(/. g) to that of gcd(/. g). There is no direct analog of
(1.6) for three or more polynomials. In this case, one uses the identity
lcm(/1, ••• .f.)� lcm(lcm(/1, ••• .f._ 1 ). f.) to compute the least common mul
tiple.
The prime elements of the ring F[x] are usually called irreducible
polynomials. To emphasize this important concept. we give the definition
again for the present context.
1.57. Definition. A polynomial p E F[x] is said to be irreducible over F
(or irreducible in F[x], Or_l!,r ime infujfif p has posiiive'deg ree and n be
with b, c E F[x] implies that either b or cis a constant p�ial.
Briefly stated, a polynomial of positive degree is irreducible over F if
it allows only trivial factorizations. A polynomial in F[x] of positive degree
that is not irreducible over F is called reducible over F. The reducibility or
irreducibility of a given polynomial depends heavily on the field under
consideration. For instance. the polynomial x1-2 E O[x] is irreducible
over the field Q of rational numbers. but x2 -2 � (x +/2)(x -/2) is
reducible over the field of real numbers.
Irreducible polynomials are of fundamental importance for the struc
ture of the ring F[x] since the polynomials in F[x] can be written as
products of irreducible polynomials in an essentially unique manner. For
the proof we need the following result.
1.58. Lemma. If an irreducible polynomial p in F[x] divides a
product /1 • • • fm of polynomials in F[x]. then at/east one of the factors!, is
divisible by p.
Proof Since p divides/1•• ·/, •• we get the identity (/1 +(p))·· · Um+(p))�O+(p) in the factor ring F[x]/(p). Now F[x]/(p) is a field
by Theorem 1.47(iv). and so Jj + ( p) � 0 + ( p) for some j; that is, p divides
f,. D
1.59. Theorem (Unique Factorization in F[x]). Any polynomial
f E F[x] of positive degree can be written in the form
f�ap;• .. ·p>'· (1.7)
where a E F, p1, ••• ,pk are distinct monic irreducible polynomials in F[x], and
e1, ••• ,ek are positive integers. Moreover. this factorization is unique apart
from the order in which the factors occur.
24 Algebraic Foundations
Proof The fact that any nonconstant f E F[x] can be represented
in the form (1.7) is shown by induction on lhe degree of f. The case
deg(f) =I is trivial since any polynomial in F[x] of degree I is irreducible
over F. Now suppose the desired factorization is established for all noncon
stant polynomials in F[x] of degree < n. If deg(f) =nand/ is irreducible
over F, then we are done since we can write f =a( a-1/), where a is the
leading coefficient off and a-if is a monic irreducible polynomial in F[x].
Otherwis e,/ allows a factorizatio n/= gh with I.; deg(g) < n, I.; deg(h) <
n, and g, hE F[x]. By the induction hypothesis, g and h can be factored in
the forrn (1.7), and so f can be factored in this forrn.
To prove uniqueness, suppose f has two factorizations of the form
(1.7), say
(1.8)
By comparing leading coefficien ts, we get a= b. Furthermore, the irreduc
ible polynomial Pi in F[x] divides the right-hand side of (1.8), and so
Lemma 1.58 shows that Pi divides q1 for some j, I.; j.; r. But q1 is also
irreducible in F[x], so that we must have q1 = cpi with a constant poly
nomial c. Since q1 and Pi are both monic, it follows that q1 =Pi· Thus we
can cancel Pi against q1 in (1.8) and continue in the same manner with the
remaining identity. After finitely many steps of this type, we obtain that the
two factorizations are identical apart from the order of the factors. D
We shall refer to ( 1.7) as the canonical factorization of the polynomial
fin F[x]. IfF= 0, there is a method due to Kronecker for finding the
canonical factorization of a polynomial in finitely many steps. This method
is briefly described in Exercise 1.30. For polynomials over finite fields,
factorization algorithms will be discussed in Chapter 4.
A central question about polynomials in F[ x] is to decide whether a
given polynomial is irreducible or reducible over F. For our purposes,
irreducible polynomials over IF, are of particular interest. To determine all
monic irreducible polynomials over F P of fixed degree n, one may first
compute all monic reducible polynomials over f, of degree n and then
eliminate them from the set of monic polynomials in F, [ x] of degree n. If p
or n is large, this method is not feasible, and we will develop more powerful
methods in Chapter 3, Sections 2 and 3.
1.60. Example. Find all irreducible polynomials over F2 of degree 4 (note
that a nonzero polynomial in F2[x] is automatically monic). There are
24 = 16 polynomials in IF2[x] of degree 4. Such a polynomial is reducible
over F 2 if and only if it has a divisor of degree I or 2. Therefore, we
compute all products (a0 + aix + a2x2 + x3Xb0 + x) and (a0 + aix +
x2Xb0+bix+x2) with a1,b1EIF2 and obtain all reducible polynomials
over IF 2 of degree 4. Comparison with the 16 polynomials of degree 4 leaves
3. Polynomials 25
us with the irreducible polynomials /1(x) � x4 + x +I, /2(x) � x4 + x3 +I,
f3(x)�x4+x3+x2+x+liniF2[x]. 0
Since the irreducible polynomials over a field Fare exactly the prime
elements of F[x], the following result, one part of which was already used in
Lemma 1.58, is an immediate consequence of Theorems 1.47(iv) and 1.54.
1.61. Theorem. For f E F[x], the residue class ring F[x]/(f) is a
field if and only iff is irreducible over F.
As a preparation for the next section, we shall take a closer look at
the structure of the residue class ring F[x]/(/), where f is an arbitrary
nonzero polynomial in F[x]. We recall that as a residue class ring F[x]/(/)
consists of residue classes g+(/) (also denoted by [g]) with gEF[x],
where the operations are defined as in ( 1.2) and ( 1.3). Two residue classes
g + ( /) and h + ( /) are identical precisely if g = h mod f-that is, precisely
if g-h is divisible by f. This is equivalent to the requirement that g and h
leave the same remainder after division by f. Each residue class g + (f)
contains a unique representative r E F[x] with deg(r) < deg(/), which is
simply the remainder in the division of g by f. The process of passing from g
to r is called reduction mod f. The uniqueness of r follows from the
observation that if r1 E g + ( /) with deg( r1) < derj /), then r - r1 is divisible
by f and deg(r-r1) < deg(/), which is only possible if r � r1• The distinct
residue classes comprising F[x]/(/) can now be described explicitly;
namely, they are exactly the residue classes r + ( /), where r runs through all
polynomials in F [ x] with deg( r) < deg( /). Thus, i{ F � IF P and deg( /) � n
;;, 0, then the number of elem�nts of FP[x]/(/) is equal to the number of
polynomials in IFP[x] of degree < n, which is p".
1.62, Examples
(i) Let f(x) � x E IF2[x]. The p" � 21 polynomials in IF2[x] of
degree <I determine all residue classes comprising F2[x]/(x),
Thus, F2[x]/(x) consists of the residue classes [0] and [I] and
is isomorphic to F 2.
(ii) Let f(x) � x2 + x +IE IF2[x]. Then F2[x]/(/) has the p" � 22
elements [0], [I], [x], [x + 1]. The operation tables for this
residue class ring are obtained by performing the required
operations with the polynomials determining the residue classes
and by carrying out reduction mod f if necessary:
+
[0]
[ I]
[X]
[x +I] [0]
[0]
[I]
[X 1
[x +I] [I]
[I]
[0]
[X+ I]
[X 1 [X] [x +I]
[X] [x +I]
[x +I] [X]
[0] [ I]
[I] [0]
26
[OJ
[OJ [OJ
[I] [OJ
[x] [OJ
[x+l] [OJ [I]
[OJ
[I]
[x]
[x +I] [X]
[OJ
[X]
[x +I]
[I] Algebraic Foundations
[x +I]
[OJ
[x +I]
[I]
[x]
By inspecting these tables, or from the irreducibility of I over
F2 and Theorem 1.61, it follows that F2[x]/(/) is a field. This
is our first example of a finite field for which the number of
elements is not a prime.
(iii) Let l(x) = x2 + 2 E F 3[x]. Then IF 3[x ]/(/) consists of the p" =
32 residue classes [0], [I], [2]. [x]. [x + 1], [x +2]. [2x]. [2x + 1],
[2x+2]. The operation tables for F3[x]/(f) are again pro
duced by performing polynomial operations and using reduc
tion mod I whenever necessary. Since IF3[x ]/(/) is a commuta
tive ring, we only have to compute the entries on and above the
main diagonal.
+
(OJ
(!]
(2]
[x]
[x +I]
[x +2]
[2x]
(2x +I]
(2x +2]
(OJ
[I]
[2]
[x]
[x +I]
[x +2]
(2x]
(2x +I]
(2x + 2] (OJ (! J (2]
(OJ (I] (2]
(2] (OJ
[I]
(OJ [I] (2]
[OJ (OJ [OJ
[I] [2]
[I] [x]
[x J
[x +I]
[x +2]
[2x]
[x]
[OJ
[x]
[2x J
[I] [x +I]
[x+ I]
[x +2]
[x]
[2x +I]
(2x + 2]
[x +I]
(OJ
[x +I]
[2x +2]
[x +I]
[2x +2] [x +2]
[x + 2]
[x]
[x +I]
[">lx + 2]
[2x J
[2x +I]
[x + 2]
(OJ
[x +2]
[2x +I]
(2x +I]
[OJ
[x +2] [2x]
[2x J
(2x +I]
[2x+2]
[OJ
(!]
[2]
[x]
[2x]
(OJ
[2x]
[x J
(2]
(2x +2]
[x +2]
(!] [2x +I]
[2x +I]
[2x +2]
[2x J
[I]
[2]
(OJ
[x +I]
[x +2]
[2x +I]
(OJ
[2x +I]
[x +2]
[x +2]
[0]
[2x +I]
(2x +I]
[x +2] (2x +2]
[2x + 2]
(2x J
(2x +I]
[2]
(OJ
[I]
[x +2]
[x]
[x +I]
(2x +2]
(OJ
(2x +2]
[x +I]
[2x +2]
[x +I]
(OJ
[x +I]
[OJ
[2x +2]
Note that F3[x]/(/) is not a field (and not even an integral
domain). This is in accordance with Theorem 1.61 since x2 +2
= (x + IXx +2) is reducible over IF3. D
IfF is again an arbitrary field andl(x)E F[x]. then replacement of
the indeterminate x in I( x) by a fixed element of F yields a well-def ined
3. Polynomials 27
element of F. In detail, if f(x) = a0 + a1x + · · · + a,x" E F[x] and bE F,
then replacing x by b we get f(b)=a0+a1b+ ··· +a,b"EF. In any
polynomial identity in F[x] we can substitute a fixed bE F for x and obtain
a valid identity in F (principle of substitution ).
1.63. Definition. An element b E F is called a root (or a zero) of the
polynomia l/ E F[x] if f(b) = 0.
An important connection between roots and divisibility is given by
the following theorem.
1.64. Theorem. An element bE F is a root of the polynomial f E
F[x] if and only if x-b divides f(x).
Proof We use the division algorithm (see Theorem 1.52) to write
f(x) = q(x)(x-b)+ c with q E F[x] and c E F. Substituting b for x, we get
/(b)= c, hence f(x) = q(xXx-b)+ f(b). The theorem follows now from
this identity. D
1.65. Definition. Let bE Fbe a root of the polynom ial/ E F[x]. If k is a
positive integer such that f(x) is divisible by (x-b)', but not by (x-b )k+ 1,
then k is called the multiplicity of b. If k =I, then b is called a simple root (or
a simple zero) off, and if k ;. 2, then b is called a multiple root (or a multiple
zero) of f.
1.66. Theorem. LetfEF[xrwith deg/."'n;.O. Ifb1, ••• ,bmEF
are distinct roots off with multiplicities kp···•km, respectively, then (x
b1)''···(x-bm)'··dividesf(x). Consequentl y,k1+ ··· +km"'n,andfcan
have at most n distinct roots in F.
Proof We note that each polynomial x-bj, 1., j"' m, is irreduc
ible over F, and so (x-bj)k; occurs as a factor in the canonical factoriza
tion of f. Altogether, the factor (x-b1)'' • • • (x-bm)'· appears in the
canonical factorization off and is thus a divisor of f. By comparing degrees,
we get k1 + · · · + km"' n, and m "'k1 + · · · + km "'n shows the last state
ment. 0
1.6'7. Definition. If f(x) = a0 + a1x + a2x2 + · · · + a,x" E F[x], then
the derivative f' off is defined by f' = f'(x) = a1 + 2a2x + · · · + na,x•-l E
F[x].
1.68. Theorem. The element bE F is a multiple root off E F[x] if
and only if it is a root of both f and f'.
There is a relation between the nonexistence of roots and irreducib il
ity. Iff is an irreducible polynomial in F[x] of degree ;. 2, then Theorem
1.64 shows that f has no root in F. The converse holds for polynomials of
degree 2 or 3, but not necessarily for polynomials of higher degree.
28 Algebraic Foundations
1.69. Theorem. The polynomial f E F[x] of degree 2 or 3 is irre
ducible in F[x] if and only iff has no root in F.
Proof The necessity of the condition was already noted. Con
versely, if f has no root in F and were reducible in F[x], we could write
f � gh with g, hE F[x] and 1 � deg(g) � deg(h). But deg(g)+deg(h) �
deg(/)�3. hence deg(g)�l; that is, g(x)=ax+b with a,bEF, a*O.
Then - ba-1 is a root of g, and so a root off in F, a contradiction . 0
1,70. Example. Because of Theorem 1.69, the irreducible polynomials in
IF2[x] of degree 2 or 3 can be obtained by eliminating the polynomials with
roots in IF2 from the set of all polynomials in F2[x] of degree 2 or 3. The
only irreducible polynomial in IF2[x] of degree 2 is f(x) = x' + x + 1, and
the irreducible polynomials in IF 2[ x] of degree 3 are /1 ( x) � x' + x + 1 and
f2(x)�x '+x2+1. 0
In elementary analysis there is a well-known method for constructing
a polynomial with real coefficients which assumes certain assigned values
for given values of the indeterminate. The same method carries over to any
field.
1. 71. Theorem (Lagrange Interpolation Formula ). For n;. 0, let
a0, ... ,a, ben+ 1 distinct elements ofF, and let b0, ... ,b, ben+ 1 arbitrary
elements of F. Then there exists exactly one polynomial f E F[x] of degree
� n such that f( a,) -bJor i -0, .. ., n. This polynomial is given by
" "
t(x)� L b, n (a,-a.)-1(x-a.).
i=O 1< -o /<=tJOi
One can also consider polynomials in several indeterminates. Let R
denote a commutative ring with identity and let x1, ... ,x, be symbols that
will serve as indeterminates. We form the polynomial ring R[xd, then the
polynomial ring R[x10 x2] � R[x1][x2], and so on, until we arrive at
R[x1, ... ,x,]� R[x1, ... ,x,_1][x,]. The elements of R[x1, ... ,x,] are then
expressions of the form
I= f(x x ) ="'a x'' · · · x'• I•"" "' n /..... j\ ···in 1 n
with coefficients a,, .. '· E R, where the summation is extended over finitely
many n-tuples (ip ... ,i,) of nonnegative integers and the convention xJ = 1
(1 � j � n) is observed . Such an expression is called a polynomial in x 1, ••• , x,
over R. Two polynomials f, g E R[x1, ... ,x,] are equal if and only if all
corresponding coefficients are equal. It is tacitly assumed that the inde
terminates x1, ••• ,x" commute with each other, so that, for instance, the
expressions x1x2x3x4 and x4x1x3x2 are identified.
1.72. Definition. Let/ E R[x1, ... ,x,] be given by
3. Polynomials 29
If a,1 ... 1� * 0, then a11 ... ;�X�1 · · · x� � is called a term off and i 1 + · · · +in is the
degree of the term. For I"* 0 one defines the degree of 1. denoted by deg( f),
to be the maximum of the degrees of the terms of f. For I� 0 one sets
deg( f) � -oo. If I� 0 or if all terms of f have the same degree, then I is
called homogeneous.
Any IE R[x1, ••• ,x.] can be written as a finite sum of homogeneous
polynomials. The degrees of polynomials in R[x" ... ,x.] satisfy again the
inequalities in Theorem 1.50, and if R is an integral domain, then (1.4) is
valid and R[x1, ••• ,x.] is an integral domain. If F is a field, then the
polynomials in F[x1, ••• ,x.] of positive degree can again be factored uniquely
into a constant factor and a product of "monic" prime elements (using a
suitable definition of "monic"), but for n ;;. 2 there is no analog of
the division algorithm (in the case of commuting indeterminates) and
F(x1, ••• ,x.] is not a principal ideal domain.
An important special class of polynomials in n indeterminates is that
of symmetric polynomials.
1.73. Definition. A polynomial IE R[x1, ••• ,x.] is called symmetric if
l(x, , ... ,X;)� l(xp ... ,x.) for any permutation ip ... ,i. of the integers
' " 1, ... ,n.
1.74. Example. Let z be an indeterminate over R[x1, ... ,x.], and let
g(z) � (z-x1)(z-x2) • • • (z-x.). Then
with
Thus: g(z)�z"-o1z"-1+o2;"-2+ .... +(-l)"o.
x .. ·x. (k�l,2, ... ,n).
11 lk
ol=xl+x2+ ... +xn,
o2=x1x2+x1x3+ ··· +x1x,+x2x3+ ··· +x2xn+ ··· +xn-lxn,
0n = X1X2 · · · Xn.
As g remains unaltered under any permutation of the X;, all the ok are
symmetric polynomials; they are also homogeneous. The polynomial ok �
o.(x1, ... ,x.) E R[x1, ... ,x.] is called the kth elementary symmetric poly
nomial in the indeterminates x1, •••• x, over R. The adjective "elementary" is
used because of the so-called "fundamental theorem on symmetric poly
nomials," which states that for any symmetric polynomial IE R[x" ... ,x.]
there exists a uniquely determined polynomial hE R[x1, ... ,x.] such that
l(xp ... ,x.,)�h(op .... o.). D
1.75. Theorem (Newton's Formula). Let o" ... ,o. be the elemen-
·········-"-:- --1 .. -��;�1,. :,.. v ...,..,,. ,.. I} "'",/ lot r = H t= 7 n�·u/
30 Algebraic Foundations
s,�s,(x1, ••• ,x.)�x;+···+x!ER[x".,,x.]for k;;.L Then the for
mula
SJ. - Sk.-ICJI + Sk.-2(12 + ... + ( -l)m-ISk-m+ lam-\+ ( -l)m: Sk._m(Jm = Q
holds fork ;;.I, where m � min(k, n).
I. 76, Theorem (Waring's Formula). With 1he same notation as in
Theorem L75, we have
for k > I, where the summation is extended over all n-tuples ( i 1,. , , i") of
nonneg�tive integers with i1 +2i2 + · · · + ni,. = k. The coefficient of a;1ai2• • •
a�" is always an integer.
4. FIELD EXTENSIONS
-Let F be a field. A subset K ofF that is itself a field under the operations of
F will be called a subfield of F, In this context, F is called an extension
(field) of K. If K "' F, we say that K is a proper subfield of F
If K is a subfield of the finite field 'F,, p prime, then K must contain
the elements 0 and I, and so all other elements of F, by the closure of K
under addition. It follows that F, contains no proper subfields. We are thus
led to the following concept,
1.77. Definition. A field containing no proper subfields is called a prime
field.
By the above argumen t, any finite field of order p, p prime, is a
prime field. Another example of a prime field is the field 0 of rational
numbers.
The intersection of any nonempty collection of subfields of a given
field F is again a subfield of F. If we form the intersection of all subfields of
F, we obtain the prime subfield of F It is obviously a prime field.
I. 78. Theorem The prime subfield of a field F is isomorphic to
either FP or Q, according as the characteristic ofF is a prime p or 0.
i.79. Definition. Let K be a subfield of the field F and M any subset of
F Then the field K( M) is defined as the intersection of all sub fields of F
containing both K and M and is called the extension (field) of K obtained
by adjoining the elements in M. For finite M � {81,., ,8.) we write K( M) =
K(81,.,,8.). If Mconsistsof a singleelement 8EF, then L� K(8) is said
to be a simple extension of K and 8 is called a defining element of L over K.
4. Field Extensions 31
Obviously, K ( M) is the smallest sub field of F containing both K and
M. We define now an important type of extension.
1.80. Definition. Let K be a subfield of F and 8 E F. If 8 satisfies
a nontrivial polynomial equation with coefficients in K, that is, if
a.8" + · · · + a18 + a0 � 0 with a, E K not all being 0, then 8 is said to be
algebraic over K. An extension L of K is called algebraic over K (or an
algebraic extension of K) if every element of L is algebraic over K.
Suppose 8 E F is algebraic over K, and consider the set J �
(/ E K[x1: f(8)� O).lt is easily checked that J is an ideal of K[x1, and we
have J"' (0) since 8 is algebraic over K. It follows then from Theorem 1.54
that there exists a uniquely determined monic polynomial g E K[x1 such
that J is equal to the principal ideal (g). It is important to note that ,ti�_
irreducible in K[x]. For, in the first place, g is of positive degree since it has
theroolli; and if g � h1h2 in K[x1 with 1"' deg(h,) < deg(g) (i � 1,2), then
0 � g( 8) � h1(8)h2(8) implies that either h1 or h2 is in J and so divisible by
g, which is impossible.
1.81. Definition. If 8 E F is algebraic over K, ti)en the uniquely de
termined monic polynomial g E K[x1 generating the ideal J� (/ E K[x1:
f( 8) � 0} of K [ x 1 is called the minimal polynomial (or defining polynomial, or
irreducible polynomial) of 8 over K. By the degree of 8 over K we mean the
degree of g.
1.82. Theorem. If 8 E F is algebraic over K, then its minimal
polynomial g over K has the following properties :
(i) g is irreducible in K[x].
(ii) For f E K[x1 we have /(8) � 0 if and only if g divides f.
(iii) g is the monic polynomial in K [ x 1 of least degree having 8 as a
root.
Proof Property (i) was already noted and (ii) follows from the
definition of g. As to (iii), it suffices to note that any monic polynomial in
K[x1 having 8 as a root must be a multiple of g, and so it is either equal tog
or its degree is larger than that of g. D
We note that both the minimal polynomial and the degree of an
algebraic element 8 depend on the field K over which it is considered, so
that one must be careful not to speak of the minimal polynomial or the
degree of 8 without specifying K, unless the latter is amply clear from the
context.
If L is an extension field of K, then L may be viewed as a vector
space over K. For the elements of L ( �"vectors") form, first of all, an
abelian group under addition. Moreover, each "vector" a E L can be
multiplied by a "scalar" r E K so that ra is again in L (here ra is simply the
32 Algebraic Foundations
product of the field elements r and a of L) and the laws for multiplication
by scalars are satisfied : r(a+/3)=ra+rf3, (r+s)a=ra+s a, (rs)a=
r(sa), and Ia =a, where r, s E Kanda, {3 E L.
1.83. Definition. Let L be an extension field of K. If L, considered as a
vector space over K, is finite-dimensional, then L is called a finite extension
of K. The dimension of the vector space L over K is then called the degree
of Lover K, in symbols [L: K].
1.84. Theorem. If L is a finite extension of K and M is a finite
extension of L, then M is a finite extension of K with
[M: K] = [M: L][L: K].
Proof Pul [M: L]=m, [L: K]=n, and let (a1, ••• ,a,} be a basis
of M over L and ( {31, ... , {3,) a basis of L over K. Then every a E M is a
linear combination a= y1a1 + · · · + Ymam with Y; E L for l � i .:::;; m, and
writing each y, in terms of the basis elements {3j we get
a= f:. y,a, = f:. ( t r,j/31) a,= f:. t r,1{3ja,
i=l i�l j-\ 1-1,-1
with coefficients ruE K. If we can show that the mn elements Pja,.
l � i � m, l � j � n, are linearly independent over K, then we are done. So
suppose we have
m "
L: L: s,Aa,=o
i-1 j-1
with coefficients s;1 E K. Then
and from the linear independence of the Cl; over L we infer
"
L s;jf3j = 0 for l � i � m.
J-1
But since the {31 are linearly independent over K, we conclude that all s,j are
0. D
1.85. Theorem. Every finite extension of K is algebraic over K.
Proof Let L be a finite extension of K and put (L: K] = m. For
0 E L, them+ 1 elements 1, 0, ... ,0"' must then be linearly dependent over
K, and so we get a relation a0 + a10 + · · · + amO"' = 0 with a, E Knot all
being 0. This just says that 0 is algebraic over K. D
4. Field Extensions 33
For the study of the structure of a simple extension K(O) of K
obtained by adjoining an algebraic element, let F be an extension of K and
let 0 E F be algebraic over K. It turns out that K( 0) is a finite (and
therefore an algebraic) extension of K.
1.86. Theorem. Let 0 E F be algebraic of degree n over K and let g
be the minimal polynomial of 0 over K. Then:
(i) K(O) is isomorphic to K[xJ!(g).
(ii) [K( 0): K] � n and (I, 0, ... , 0"-1) is a basis of K( 0) over K.
(iii) Every a E K(O) is algebraic over K and its degree over K is a
divisor of n.
Proof (i) Consider the mapping T: K[x] � K(O), defined by •(/)
� f(O) for f E K[x], which is easily seen to be a ring homomorphism. We
have ken�(/ E K[x]: f(O) � 0} �(g) by the definition of the minimal
polynomial. Let S be the image of T; that is, S is the set of polynomial
expressions in 0 with coefficients in K. Then the homomorphism theorem
for rings (see Theorem 1.40) yields that Sis isomorphic to K[x]/(g). But
K [ x ]/(g) is a field by Theorems 1.61 and 1.82(i), and so S is a field. Since
K r;;Sr;;K(IJ) and OES, it follows from the definition of K(O) that
S � K(O), and (i) is thus shown.
(ii) Since S � K(O), any given a E K(O) can be written in the form
a� f(O) for some f E K[x]. By the .division algorithm, f � qg + r with
q,rEK[x] and deg(r)<deg(g)�n. Then a�f(O)�q(O)g(IJ) +r(O)�
r(O), and so a is a linear combination of I, 0, ... ,0"-1 with coefficients inK.
On the other hand, if a0+a11J+ ··· +a,_10"-1�0 for certain a1EK,
then the polynomial h(x)�a0+a1x+ ··· +a,_1x"-1EK[x] has 0 as a
root and is thus a multiple of g by Theorem 1.82(ii). Since deg(h) < n �
deg(g), this is only possible if h � 0-that is, if all a,� 0. Therefore, the
elements I, 0, ... ,0"-1 are linearly independent over K and (ii) follows.
(iii) K(O) is a finite extension of K by (ii), and so a E K(O) is
algebraic over K by Theorem 1.85. Furthermore, K( a) is a subfield of K( 0 ).
If d is the degree of a over K, then (ii) and Theorem 1.84 imply that
n � [K(O): K] � [K(O): K(a)][K(a): K] � [K(O): K(a)]d, hence d di
vides n. D
The elements of the simple algebraic extension K(O) of K are
therefore polynomial expressions in 0. Any element of K(O) can be uniquely
represented in the form a0 + a10 + · · · + a,_10"-1 with a, E K for 0.,;; i.,;;
n-1.
It should be pointed out that Theorem 1.86 operates under the
assumption ,that both K and 0 are embedded in a larger field F. This is
necessary �n "order that algebraic expressions involving 0 make sense. We
now want to construct a simple algebraic extension ab ova-that is, without
34 Algebraic Foundations
reference to a previously given larger field. The clue to this is contained in
part (i) of Theorem 1.86.
1.87. Theorem. Let f E K[x] be irreducible over the field K. Then
there exists a simple algebraic extension of K with a root off as a defining
element.
Proof Consider the residue class ring L = K[x]/(f), which is a
field by Theorem 1.61. The elements of L are the residue classes [ h] = h + (f)
with hE K[x]. For any a E K we can form the residue class [a] determined
by the constant polynomial a, and if a,bEK are distinct, then [a]*[b]
since f has positive degree. The mapping a>-> [a] gives an isomorphism
from K onto a subfield K' of L, so that K' may be identified with K. In
other words, we can view L as an extension of K. For every h(x) =
a0+a1x+ ··· +a..,x"'EK[x] we have [h]=[a0+a1x+ ··· +a..,x"']=
[a0]+[ad[x]+ · ·· +[a..,][x]"'=a0+a1[x]+ · · · +a..,[x]"' by the rules for
operating with residue classes and the identification [a1] = a1• Thus, every
element of L can be written as a polynomial expression in [x] with
coefficients inK. Since any field containing both K and [x] must contain
these polynomial expressions, L is a simple extension of K obtained by
adjoining [x]. If f(x)=b0+b1x+ ··· +b.x", then /([x])=b0+b1[x]
+ · · · + b.[x]" = [b0 + b1x + · · · + b.x"] = [f] = [0], so that [x] is a root of
f and Lis a simple algebraic extension of K. 0
1.88. Example. As an example of the formal process of root adjunction
in Theorem 1.87, consider the prime field F3 and the polynomial f(x)=x2
+ x + 2 E IF3[x], which is irreducible over IF3. Let 8 be a "root" off; that is,
8 is the residue class x +(f) in L = F3[x]/(f). The other root off in Lis
then 28 +2, since /(28 +2) = (28 +2)2 +(28 +2)+2 = 82 + 8 +2 = 0. By
Theorem 1.86(ii), or by the known structure of a residue class field, the
simple algebraic extension L = IF3(8) consists of the nine elements
0,1,2,8,8+1,8+2,28,28+1,28+2. The operation tables for L can be
constructed as in Example 1.62. 0
We observe that in the above example we may adjoin either the root
8 or the root 28 + 2 of f and we would still obtain the same field. This
situation is covered by the following result, which is easily established.
1.89. Theorem. Let a and fJ be two roots of the polynomial f E K [ x]
that is irreducible over K. Then K(a) and K({J) are isomorphic under an
isomorphism mapping a to fJ and keeping the elements of K fixed.
We are now asking for an extension field to which all roots of a given
polynomial belong.
1.90. Definition. Let f E K [ x] be of positive degree and F an extension
field of K. Then f is said to split in F iff can be written as a product of
4. Field Extensions 35
linear factors in F[x ]-that is, if there exist elements a1, a2, ... ,a" E F such
that
f(x)�a(x-a1)(x-a2)···(x-a,),
where a is the leading coefficient of f. The field F is a spliuing field off over
Kif f splits in F and if, moreover, F � K( a1, a2, •.. , a,).
It is clear that a splitting field F off over K is in the following sense
the smallest field containing all the roots off: no proper subfield ofF that
is an extension of K contains all the roots of f. By repeatedly applying the
process used in Theorem 1.87, one obtains the first part of the subsequent
result. The second part is an extension of Theorem 1.89.
1.91. 1"1u!orem (Existence and Uniqueness of Splitting Field). If K
is a field and f any polynomial of positive degree in K[x], then there exists a
sp/iuing field off over K. Any two sp/iuing fields off over K are isomorphic
under an isomorphism which keeps the elements of K fixed and maps roots off
into each other.
Since isomorphic fields may be identified, we can speak of the
splitting field off over K. It is obtained from K by adjoining finitely many
algebraic elements over K, and therefore one can show on the basis of
Theorems 1.84 and 1.86(ii) that the splitting field off over K is a finite
extension of K.
As an illustration of the usefulness of splitting fields, we consider the
question of deciding whether a given polynomial has a multiple root
(compare with Definition 1.65).
1.92. Definition. Let f E K [ x] be a polynomial of degree n ;;, 2 and
suppose that f(x) � a0(x- a1) • • • (x-a,) with a1, ••• ,a, in the splitting
field off over K. Then the discriminant D(f) off is defined by
D(f)�a�"-2 0 (a,-ay.
los;i<}Etn
It is obvious fro!)l.tpe defmition of D(f) thatfhas a multiple root if
and only if D(f) � 0. Aiih'6ug!l D(f) is defined in terms of elements of an
extension of K, it is actually an element of K itself. For small n this can be
seen by direct calculation. For instance, if n � 2 and /( x) � ax 2 + bx + c �
a(x- a1Xx- a2), then D(f) � a2(a1-a2)2 � a2((a1 + a2)2 -4a1a1) �
a2(b2a-2 -4ca-1), hence
D( ax'+ bx +c)� b2 -4ac,
a well-known expression from the theory of quadratic equations. If n � 3
and f(x) �ax'+ bx2 +ex+ d � a(x-a1)(x-a2Xx-a3), then D(f) �
a4(a1-a1)2(a1-a3)3(a2-a3)3, and a more inv.ol�ed computation yields
!-''' ''• '1...,
D( ax' + bx2 + ex+ d)� b2c2-4b3d-4ac3 -21a2d2 + 18abcd. ( 1.9)
36 Algebraic Foundations
In the general case, consider first the polynomial s E K[x1, ••• ,x.] given by
s(x,, ... ,x.)�a6•-' n (x,-xj.
l<i<j<n
Then sis a symmetric polynomial, and by a result in Example 1.74 it can be
written as a polynomial expression in the elementary symmetric polynomi
als o1, ... ,o. -that is, s = h( o1, ... ,o.) for some hE K[x1, ... ,x.]. If f(x) =
a0x" + a,x•-l + · · · +a.= a0(x-a1) • • • (x-a.). then the definition of
the elementary symmetric polynomials (see again Example 1.74) implies that
ok(a1, ... ,a.) � ( -l)•a.a0 1 E K for I .;; k .;; n. Thus,
D(/) �s ( a1 , ... ,a.)� h ( o1 ( a1, ... ,a.), ... ,o.( a1 , ... ,a.))
� h(-a1a01 , ... ,( -l}"a.a01} E K.
Since D(/) E K, it should be possible to calculate D(f) without
having to pass to an extension field of K. This can be done via the notion of
resultant. We note first that if a polynomial f E K[x] is given in the form
f(x) � a0x" + a,x•-l + · · · +a. and we accept the possibility that a0 � 0,
then n need not be the degree of f. We speak of n as the formal degree off;
it is always greater than or equal to deg(/ ).
1.93. Definition. Let f(x) = a0x" + a,x•-l + · · · +a. E K[x] and g(x)
= b0xm + b1xm-l + · · · + bm E K[x] be two polynomials of formal degree
n resp. m with n, m EN. Then the resultant R(f, g) of the two polynomials
is defined by the determinant
ao a, a. 0 0
)·-0 ao a, a. 0 0
R(/,g)� 0 0 ao a, a.
ho b, bm 0 0
) "'�' 0 ho b, bm 0
0 0 ho b, bm
of order m + n.
If deg(f) � n (i.e., if a0 "'0) and /(x) � a0(x-a1) • • • (x-a.) in
the splitting field off over K, then R(f, g) is also given by the formula
•
R(!, g)� a;;' 0 g(a,). ( 1.10)
i-1
In this case, we obviously have R(f, g)� 0 if and only if f and g have a
common root, which is the same as saying that f and g have a common
divisor in K[x] of positive degree.
Exercises 37
Theorem 1.68 suggests a connection between the discriminant D( f)
and the resultant R(f,/'). Let f E K[x] with deg(/) � n;;, 2 and leading
coefficient a0. Then we have, in fact, the identity
(1.11)
where f' is viewed as a polynomial of formal degree n -l. The last remark is
needed since we may have deg( /') < n -I and even f' � 0 in case K has
prime character istic. At any rate, the identity ( 1.11) shows that we can
obtain D(f) by calculating a determinant of order 2n-I with entries inK.
EXERCISES
l.l. Prove that the identity element of a group is uniquely determined.
1.2. For a multiplicative group G, prove that a nonempty subset H of G
is a subgroup of G if and only if a, bE H implies ab-1 E H. If His
finite, then the condition can be replaced by: a, bE H implies
abE H.
1.3. Let a be an element of finite order k in the multiplicative group G.
Show that formE l we have am� e if and only if k divides m.
1.4. FormE I'll, Euler's function .p(m) is defined to be the number of
integers k with ! ,..k ,.. m and.gcd(k,m)�l. Show the following
properties form, n, s E I'll and a prime p:
(a)
4>(p') � p'( 1-il
(b) .P(mn) � .p(m)<j>(n) if gcd(m, n) �I;
(c) .P(m)�m(l-;J ··(l-;,). where m�pf'···p;• is the
prime factor decomposition of m.
1.5. Calculate 4>(490) and 4>(768).
1.6. Use the class equation to show the following: if the order of a finite
group is a prime power p', p prime, s;;, I, then the order of its center
is divisible by p.
1.7. Prove that in a ring R we have (-a)(-b)� ab for all a, bE R.
1.8. Prove that in a commutative ring R the formula
holds for all a, bE R and n E I'll. (Binomial Theorem )
1.9. Let p be a prime number in Z. For all integers a not divisible by p,
show that p divides a p-I-I. (Fermat's Little Theorem)
1.10. Prove that for any prime p we have (p-I)!= -I mod p. (Wilson's
Theorem)
38 Algebraic Foundations
1.11. Prove: if pis a prime, we have ( p 71) = ( -l)imod p for 0 "j"
p-l,jEZ.
1.12. A conjecture of Fermat stated that for all n;. 0 the integer 22" + 1 is
a prime. Euler found to the contrary that 641 divides 232 + 1.
Confirm this by using congruences.
1.13. Prove: if m1, ... ,mk are positive integers that are pairwise relatively
prime-that is, gcd(m,, m) � 1 for 1 "i < j" k -then for any in
tegers a1, ••• ,ak the system of congruences y = a,.mod m,., i = I, 2, ... ,
k, has a simultaneous solution y that is uniquely determined modulo
m � m1 • • • m,. (Chinese Remainder Theorem)
1.14. Solve the system of congruences 5x = 20mod6, 6x = 6mod5, 4x =
5mod77.
1.15. For a commutative ring R of prime characteristic p, show that
(a+ ... +a)'" �a'"+··· +a'" I .f I s
for all a1, ... ,a, E Rand n E 1\1.
1.16. Deduce from Exercise 1.11 that in a commutative ring R of prime
characteristic p we have
p -l
(a-b)'-'� L a1bp-l-J foralla,bER.
j=O
1.17. Let F be a field and f E F[x]. Prove that (g(/(x)) : g E F[x]) is
equal to F [ x] if and only if deg(/) � l.
1.18. Show that p2( x)-xq2( x) � xr2(x) for p, q, r E IRI[x] implies p � q �
r � 0.
1.19. Show that if/, g E F[x], then the principal ideal(/) is contained in
the principal ideal (g) if and only if g divides f.
1.20. Prove: if/, g E F [ x] are relatively prime and not both constant, then
there exist a, bE F[x] such that a/+ bg � 1 and deg(a) < deg(g),
deg( b) < deg( /).
1.21. Let /1, ... ,/.EF[x] with gcd(/1, ... ,/,,)�d, so that f.�dg1 with
g, E F[x] for 1 "i" n. Prove that g1, ••• ,g. are relatively prime.
1.22. Prove that gcd(/1, ... J.) � gcd(gcd(/ 1, ... J._, )./.) for n ;. 3.
1.23. Prove: if/, g, hE F[x], f divides gh, and gcd(/, g)� 1, then f di
vides h.
1.24. Use the Euclidean algorithm to comp11te gcd(/, g) for the polynomi
als f and g with coefficients in the indicated field F:
(a) F� Q, f(x) � x7 +2x' +2x2- x +2, g(x) � x' -2x'- x4 +
x2+2x+3
(b) F� 'f2,f(x) � x7 + 1, g(x) � x' + x3 + x + 1
(c) F�'f2,f(x)�x'+x+l,g(x)�x'+x'+x4+1
(d) F� 'f3, f(x) � x8 +2x' + x3 + x2 + 1, g(x) � 2x6 + x' +2x3
+2x2 +2
Exercises 39
1.25. Let /1, ••• ,/,, be nonzero polynomials in F[x]. By considering the
intersection (/1)n · · · n(/.) of principal ideals, prove the existence
and uniqueness of the monic polynomial mE F[x] with the proper
ties attributed to the least common multiple of /1, ••• .f •.
1.26. Prove ( 1.6).
1.27. If f1, ••• ,f. E F[x] are nonzero polynomials that are pairwise rela
tively prime, show that lcm(/1, ••• ./.)�a-1/1•• ·f ., where a is the
leading coefficient of /1 • • ·f •.
1.28. Prove that !em(/,. ... .f.) � lcm(lcm( /1, •••• f.,_ 1 ), f.,) for n ;;, 3.
1.29. Let f1, ••• ,f. E F[x] be nonzero polynomials. Write the canonical
factorization of each/;. 1 � i � n, in the form
t,. = a;nPe,.(p).
where a, E F, the product is extended over all monic irreducible
polynomials pin F[x], thee,( p) are nonnegative integers, and for
each i we have e,( p) > 0 for only finitely many p. For each p set
m(p)� min(e1(p), ... ,e.(p)) and M(p) � max(e1(p), ... ,e.(p)).
Prove that
gcd(f, .... ,f.) � nprnJp).
lcm(j,, ... ,/,,) � npM(p).
1.30. Kronecker's method for finding .divisors of degree "s of a noncon
stant polynomial / E O[x] proceeds as follows:
(l) By multiplying f by a constant, we can assume f E Z[x].
(2) Choose distinct elements a0, ... ,a, E Z that are not roots of f
and determine all divisors of f( a,) for each i,O" i" s.
(3) For each (s +I)-tuple (b0, .•. .b,) with b1 dividing f(a,) for
O .. i .. s, determine the polynomial gEO[x] with deg(g)"s
and g( a,)� b1 for 0 "i "s (for instance, by the Lagrange
interpolation formula).
(4) Decide which of these polynomials g in (3) are divisors of f.
If deg(/) � n;;. I and s is taken to be the greatest integer "n/2,
then f is irreducible in Q[x] in case the method only yields constant
polynomials as divisors. Otherwise, Kronecker's method yields a
nontrivial factorization. By applying the method again to the factors
and repeating the process, one eventually gets the canonical factoriz
ation of f. Use this procedure to find the canonical factorization of
f(x) �tx' -1x' +2x4-x3 +5x2-'fx -1 E O[x].
1.31. Construct the addition and multiplication table for F2[x]/
(x3 + x2 + x). Determine whether or not this ring is a field.
1.32. Let [x +I] be the residue class of x +I in IF2[x]/(x4 + 1). Find
the residue classes comprising the principal ideal ([x + 1]) in F2[x]/
I ,_4 I 1 \
40 Algebraic Foundations
1.33. Let F be a field and a, b, g E F[x] with g"' 0. Prove that the
congruence af = bmod g has a solution f E F[x] if and only if
gcd( a, g) divides b.
1.34. Solve the congruence (x2 + 1)/(x)= 1 mod(x3 + 1) in �,[x], if poss
ible.
1.35. Solve (x4+x3+x2 +1)/(x)=(x2+l)mod(x3+1) in �1[x], if
possible.
1.36. Prove that R[x]/(x4 + x' + x + 1) cannot be a field, no matter what
the commutative ring R with identity is.
1.37. Prove: given a field F, nonzero polynomials /1, ... ,fk E F[x]that are
pairwise relatively prime, and arbitrary polynomials g1, ... ,gk E F[x ],
then the simultaneous congruences h = g, mod/,, i � 1, 2, ... , k, have a
unique solution hE F[x] modulo f � /1 • • • fk· (Chinese Remainder
Theorem for F[x])
1.38. Evaluate/(3) for f(x) � x214 + 3x152 + 2x47 + 2 E IF5[x].
1.39. Let p be a prime and a0, ... ,a, integers with p not dividing a,. Show
that a0 + a1y + · · · + G11J11 = 0 mod p has at most n different solu
tions y modulo p.
1.40. If p > 2 is a prime, show that there are exactly two elements a E IF,
such that a'� I.
1.41. Show: if/ E Z[x] and/(0)= /(1) = 1 mod2, thenfhas no roots in Z.
1.42. Let p be a prime and f E Z[x]. Show: /(a)= Omod p holds for all
a E Z if and only if/( x) � (x' -x )g(x )+ph( x) with g. h E Z[x ].
1.43. Let p be a prime integer and c an element of the field F. Show that
xP -c is irreducible over F if and only if xl'-c has no root in F.
1.44. Show that for a polynomial/ E F[x] of positive degree the following
conditions are equivalent:
(a) f is irreducible over F;
(b) the principal ideal(/) of F[x] is a maximal ideal;
(c) the principal ideal(/) of F[x] is a prime ideal.
1.45. Show the following properties of the derivative for polynomials in
F[x]:
(a) (/, + · · · + fm)'� /{+ · · · + f�;
(b) (/g)'� f'g + fg';
m
(c) (/,···/"')'� L/1 ·· ·J,_J(J,+l .. ·fm·
i-1
1.46. For f E F[ x] and F of characteristic 0, prove that f' � 0 if and only
iff is a constant polynomial. IfF has prime characteristic p, prove
that/'� 0 if and only if /(x) � g(x') for some g E F[x].
1.47. Prove Theorem 1.68.
1.48. Prove that the nonzero polynomial f E F[x] has a multiple root (in
some extension field of F) if and only iff and/' are not relatively
prime.
1.49. Use the criterion in the previous exercise to determine whether the
Exercises
following polynomials have a multiple root:
(a) f(x)�x4-5x3+6x2+4x-8EO[x]
(b) f(x)�x6+x'+x4+x3+1EF2[x] 41
1.50. The nth derivative /'"' of/ E F[x] is defined recursively as follows:
I f'0'�f.f'"'�(f'"-")' forn;.l. Prove that forf,gEF[x] we have
(/g)'"'� t (�)f"'-"g'''.
'-o
1.51. Let F be a field and k a positive integer such that k < p in case F has
prime chara cteristic p. Prove: bE F is a root off E F(x] of multipl
icity kif and only if I'"( b)� 0 for 0.; i.; k-I and jlk1( b)* 0.
1.52. Show that the Lagrange interpolation formula can also be written in
the form
"
f(x)� t b,(g'(a,))_, g(x)
i=O x-a; withg(x) � n (x-a.).
k-0
1.53. Determine a polynomial f E F,(x] with /(0) � /(1) � /(4) �I and
/(2) � /(3) � 3.
1.54. Determine a polynomial f E Q(x] of degree .; 3 such that /(- I)�
-1./(0) � 3./(1) � 3, and /(2) � 5.
1.55. Express s5(x1, x2, x3, x4) = xf +xi+ xj + x� E IF3[x1, x2, x3, x4J in
terms of the elementary symmetric polynomials o,, o2, o3, o4•
1.56. Prove that a subset K of a field F is a su"bfield if and only if the
following conditions are satisfied:
(a) K contains at least two elements;
(b) ifa,bEK, thena-b EK;
(c) if a, bE K and b * 0, then ab-' E K.
· 1.57. Prove that an extension L of the field K is a finite extension if and
only if L can be obtained from K by adjoining finitely many
algebraic elements over K.
1.58. Prove: if 8 is algebraic over L and L is an algebraic extension of K,
then 8 is algebraic over K. Thus show that if F is an algebraic
extension of L, then F is an algebraic extension of K.
1.59. Prove: if the degree (L: K] is a prime, then the only fields F with
K C:: F C:: L are F� K and F� L.
1.60. Construct the operation tables for the field L � IF3( 8) in Example
1.88.
1.61. Show that f(x) � x4 + x +IE F2[x] is irreducible over IF2. Then
construct the operation tables for the simple extension F2(8), where
8 is a root of f.
1.62. Calculate the discriminant D(f) and decide whether or not f has a
multiple root:
(a) f(x)�2x3-3x2+x+lEO[x]
42 Algebraic Foundations
(b) l(x) = 2x4 + x3 + x2 +2x +2 E IF3[x]
1.63. Deduce ( 1.9) from (I. II).
1.64. Prove that 1. g E K[x] have a common root (in some extension field
of K) if and only if I and g have a common divisor in K [ x] of
positive degree.
1.65. Determine the common roots of the polynomials x7-2x4-x3 + 2
and x5-3x4-x + 3 in O[x].
1.66. Prove: if I and g are as in Definition 1.93, then R(/, g)=
( -l)m"R(g, /).
1.67. Let l,gEK[x] be of positive degree and suppose that l(x)=
a0(x-a1)···(x-a.,), a0*0, and g(x)=b0(x-{31)···(x-/3m),
b0 * 0, in the splitting field of lg over K. Prove that
m " m
where n and m are also taken as the formal degrees of I and g.
respectively.
1.68. Calculate the resultant R(/, g) of the two given polynomials I and g
(with the formal degree equal to the degree) and decide whether or
not I and g have a common root:
(a) l(x)=x3+x+l,g(x)=2x5+x2+2EIF3[x]
(b) l(x) = x4 + x3 +I, g(x) = x4 + x2 + x +IE IF2[x]
1.69. For IE K[x1, ••• ,x.,], n;;. 2. an n-tuple (a1, ••• ,a.,) of elements a,
belonging to some extension L of K may be called a zero of I if
l(a1 •••• ,a.,)=O. Now let l.gEK[x1, ••• ,x.,] with x., actually ap
pearing in I and g. Then I and g can be regarded as polynomials
/(x,) and g(x.,) in K[x1, ••• ,x.,_,][x.,] of positive degree. Their
resultant with respect to x., (with formal degree= degree) is R(j, g)
= R x (/,g), which is a polynomial in x1, ••• ,x.,_1• Show that I and g
have a common zero (aJ····•a n-l•an) if and only if (al•···•an-1) is
a zero of R(/. g).
1.70. Using the result of the previous exercise, determine the common
zeros of the polynomials l(x, y) = x(y2-x)2 + y5 and g(x, y) =
y4 + y3-x2 in O[x, y].
Chapter 2
Structure of Finite Fields
This chapter is of central importance since it contains various fundamental
properties of finite fields and a description of methods for constructing
finite fields.
The field of integers modulo a prime number is, of course, the most
familiar example of a finite field, but many of its properties extend to
arbitrary finite fields. The characterization of finite fields (see Section 1)
shows that every finite field is of prime-power order and that. conversely,
for every prime power there exists a finite field whose number of elements is
exactly that prime power. Furthermore, finite fields with the same number
of elements are isomorphic and may therefore be identified. The next two
sections provide information on roots of irreducible polynomials, leading to
an interpretation of finite fields as splitting fields of irreducible polynomi
als. and on traces, norms, and bases relative to field extensions.
Section 4 treats roots of unity from the viewpoint of general field
theory. which will be needed occasionally in Section 6 as well as in Chapter
5. Section 5 presents different ways of representing the elements of a finite
field. In Section 6 we give two proofs of the famous theorem of Wedderburn
according to which every finite division ring is a field.
Many discussions in this chapter will be followed up. continued, and
partly generalized in later chapters.
44 Structure of Finite Fields
1. CHARACTERIZATION OF FINITE FIELDS
In the previous chapter we have already encountered a basic class of finite
fields-that is, of fields with finitely many elements. For every prime p the
residue class ring Z/( p) forms a finite field with p elements (see Theorem
1.38), which may be identified with the Galois field F, of order p (see
Definition 1.41). The fields IF, play an important role in general field theory
since every field of characteristic p must contain an isomorphic copy of IFP
by Theorem 1.78 and can thus be thought of as an extension of IF,. This
observation, together with the fact that every finite field has prime char
acteristic (see Corollary 1.45), is fundamental for the classification of finite
fields. We first establish a simple necessary condition on the number of
elements of a finite field.
2.1. Lemma. Let F be a finite field containing a su/5field K with q
elements. Then F has q"' elements, where m = [F: K].
Proof F is a vector space over K, and since F is finite, it is
finite-dimensional as a vector space over K. If [F: K] = m, then F has a
basis over K consisting of m elements, say b1, b2, ... ,bm. Thus every element
ofF can be uniquely represented in the form a1b1+a2b2+ ··· +a.,b.,,
where a1, a2, ... ,am E K. Since each a; can have q values, F has exactly qm
elements. D
2.2. Theorem. Let F be a finite field. Then F hasp" elements, where
the prime p is the characteristic of F and n is the degree of F over its prime
subfield.
Proof Since F is finite, its characteristic is a prime p according to
Corollary 1.45. Therefore the prime sub field K ofF is isomorphic to F P by
Theorem 1.78 and thus contains p elements. The rest follows from Lemma
2.1. 0
Starting from the prime fields F,. we can construct other finite fields
by the process of root adjunction described in Chapter I, Section 4. If
f E F ,[x] is an irreducible polynomial over IF, of degree n, then by adjoining
a root of/to F, we get a finite field withp" elements. However, at this stage
it is not clear whether for every positive integer n there exists an irreducible
polynomial in F,[x] of degree n. In order to establish that for every primep
and every n E 1\1 there is a finite field with p" elements, we use an approach
suggested by the following results.
2.3. Lemma. IfF is a finite field with q elements, then every a E F
satisfies a"= a.
Proof The identity a• =a is trivial for a= 0. On the other hand,
the nonzero elements ofF form a group of order q -I under multiplication.
1. Characterization of Finite Fields 45
Thus a•-1 �I for all a E F with a* 0. and multiplication by a yields the
desired result. 0
2.4. Lemma. IfF is a finite field with q elements and K is a subfield
ofF, then the polynomial x'-x in K[x] factors in F[x] as
x•-x� n (x-a)
n E F
and F is a splitting field of x'-x over K.
Proof The polynomial x'-x of degree q has at most q roots in F.
By Lemma 2.3 we know q such roots-namely. all the elements of F. Thus
the given polynomial splits in Fin the indicated manner, and it cannot split
in any smaller field. 0
We are now able to prove the main characterization theorem for
finite fields, the leading idea being contained in Lemma 2.4.
2.5. Theorem (Existence and Uniqueness of Finite Fields). For
every prime p and every positive integer n there exists a finite field with v" 1
. 7,1<c-�tc...,/�
elements. Any finite field with q = p" elements is isomorphic to the splitting
field of x•-x over IF r·
Proof (Existence) For q � p" consider x•-x in FP[x], and let F
be its splitting field over FP. This polynomial has q distinct roots in F since
its derivative is qxq-l -1 =-I in IFP[xJ and so can have no common root
with x•-x (compare with Theorem 1.68). Let.S �{a E F: a•-a� 0).
Then S is a subfield of F since: (i) S contains 0 and I; (ii) a, bE S implies
by Theorem 1.46 that (a-b)'� a•-b' �a-b, and so a-bE S; (iii) for
a, bE Sand b * 0 we have (ab-1 )' � a•b-• = aV 1, and so ah 1 E S. But,
on the other hand, xq·_ x must split inS since S contains all its roots. Thus
F � S, and since S has q elements, F is a finite field with q elements.
(Uniqueness) Let Fbe a finite field with q � p" elements. Then F has
characteristic p by Theorem 2.2 and so contains !' P as a subfie!d. It follows
from Lemma 2.4 that F is a splitting field of x'-x over IFr. Thus the
desired result is a consequence of the uniqueness (up to isomorphisms) of
splitting fields, which was noted in Theorem 1.91. 0
The uniqueness part of Theorem 2.5 provides the justification for
speaking of the finite field (or the Galois field) with q elements, or of the
finite field (or the Galois field) of order q. We shall denote this field by IF,.
where it is of course understood that q is a power of the prime characteristic
p of IF,. The notation GF(q) is also used by many authors.
2.6. Theorem (Subfield Criterion). Let IF, be the finite field with
q = p" elements. Then every subfield ofF q has order pm, where m is a positive
divisor of n. Conversely, if m is a positive divisor of n. then there is exactly one
subfield of IF, with pm elements.
46 Structure of Finite Fields
Proof It is clear that a sub field K of IF, has order p"' for some
positive integer m � n. Lemma 2.1 shows that q = p11 must be a power of p"'.
and so m is necessarily a divisor of n.
Conversely, if m is a positive divisor of n, then p"'-I divides p"-I,
and soxP"'-1-1 divides xp"-1-1 in f,[x]. Consequently, xP"'-x divides
xP"-x=xq-x in IFI'[x]. Thus, every root of xP�'-x is a root of xq-x
and so belongs to IF,. It follows that F, must contain as a subfield a splitting
field of xP"-x over IF,, and as we have seen in the proof of Theorem 2.5,
such a splitting field has order p"'. If there were two distinct subfields of
order p"' in IF q' they would together contain more than p"' roots of xP"'-x
in IF q• an obvious contradiction. 0
The proof of Theorem 2.6 shows that the unique subfield of IF,. of
order pm, where m is a positive divisor of n, consists precisely of the roots of
the polynomial xP"-x E IF,[x] in F, •.
2.7. Example. The subfields of the finite field IF2, can be determined by
listing all positive divisors of 30. The containment relations between these
various subfields are displayed in the following diagram.
"'"' /1� IF26 IF21o IF21� IXtXI
IF22 IF2J F2s
�1/ F,
By Theorem 2.6, the containment relations are equivalent to divisibility
relations among the positive divisors of 30. 0
For a finite field IF, we denote by· IF; the multiplicative group of
nonzero elements ofF,. The following result enunciates a useful property of
this group.
2.8. Theorem. For every finite field IF, the multiplicative group F; of
nonzero elements of IF q is cyclic.
Proof We may assume q > 3. Let h � p;'P2' · · · p;,• be the prime
factor decomposition of the order h � q-I of the group F;. For every i,
I.,;; i.,;; m, the polynomial x•IP, -I has at most h/p1 roots in IF,. Since
h/p, < h, it follows that there are nonzero elements in IF, that are not roots
of this polynomial. Let a, be such an element and set b1 � a�IP>'. We have
bl�j = I, hence the order of h;. is a divisor of p;• and is therefore of the form
p:·,. with 0 � s; � r;. On the other hand,
bP�,-� = ah/p,. * 1 ' ' '
and so the order of b1 is p;•. We claim that the element b � b 1 b2 • · · bm has
order h. Suppose, on the contrary, that the order of b is a proper divisor of h
2. Roots of Irreducible Polynomials 47
and is therefore a divisor of at least one of the m integers h 1 p1, I"' i"' m,
say of hjp1• Then we have
1 = b11/P1 = b71Pib;IPI ... b!IP1.
Now if 2 "'i"' m, then Pr' divides h/pp and hence bt/p, �I. Therefore
b;;,, �I. This implies that the order of b1 must divide h/pp which is
impossible since the order of b1 is Pt'· Thus, f; is a cyclic group with
generator b. 0
2.9. Definition. A generator of the cyclic group F: is called a primitive
element of F •.
It follows from Theorem 1.15(v) that F• contains <t>(q -I) primitive
elements, where <P is Euler's function. The existence of primitive elements
can be used to show a result that implies, in particular, that every finite field
can be thought of as a simple algebraic extension of its prime subfield.
210. Theorem. Let IF• be a finite field and IF, a finite extension field.
Then F, is a simple algebraic extension ofF • and every primitive element ofF,
can serve as a defining element ofF, over IFq.
Proof Let I be a primitive element of IF,. We clearly have IF.(O � F,.
On the other hand, F .(1) contains 0 and all powers of L and so all elements
ofF,. Therefore IF, � IF.(I). I 0
211. Corollory. For every finite field IF • �nd every positive integer
n there exists an irreducible polynomial in IF.[x] of degree n.
Proof Let F, be the extension field of F• of order q•, so that
[F,: F•] � n. By Theorem 2.10 we have IF,� F.(O for some IE IF,. Then the
minimal polynomial of I over IF• is an irreducible polynomial in F.[x] of
degree n, according to Theorems 1.82(i) and 1.86(ii). 0
2. ROOTS OF IRREDUCIBLE POLYNOMIALS
In this section we collect some information about the set of roots of an
irreducible polynomial over a finite field.
2.12 Lemma. Let f E F.[x] be an irreducible polynomial over a
finite field F • and let a be a root off in an extension field of F •. Then for a
polynomial h E F.[x] we have h (a)= 0 if and only iff divides h.
Proof Let a be the leading coefficient off and set g(x) � a-1f(x).
Then g is a monic irreducible polynomial in IF.[x] with g(a) � 0 and so it is
the minimal polynomial of a over F • in the sense of Defirtition 1.81. The rest
follows from Theorem 1.82(ii). 0
48 Structure of Finite Fields
2.13. Lemmt1. Let 1 E IF .[x 1 be an irreducible polynomial over IF • o{
degree m. Then {(x) divides x•"-xi{ and only i{ m divides n.
Proof Suppose {(x) divides x•"-x. Let a be a root of 1 in the
splitting field of 1 over IF •. Then a•" �a, so that a E F /_It follows that
F.(a) is a subfield of IF ••. But since [Fq(a):IF.1,;;m and [IF •• :F.1�n,
Theorem 1.84 shows that m divides n.
Conversely, if m divides n, then Theorem 2.6 implies that f •"
contains f •• as a subfield. If a is a root of 1 in the splitting field of 1 over IF •.
then [F.(a):IF.1�m, and so IFq(a)�F •• _ Consequently, we have aEF •• ,
hence a•" � a, and thus a is a root of x•"-x E F •[ x 1-We infer then from
Lemma 2.12 that{(x) divides x•"-x. 0
� Theorem. /{{is an irreducible polynomial in IF•[x1 o{ degree
m. then {has a roat a in F.·-Furthermore, all the roots o{{ are simple and are
-b h d- -I • •' ··-' {IF gwen � I e m lstmct e ements a, a , a , ... , a o q"'·
Proof Let a be a root of {in the splitting field of 1 over IF.-Then
[IF.(a):F.1�m, hence F•(a)�F •• , and in particular aEF •• _ Next we
show that if {3 E IF q"' is a root of{, then {3 q is also a root of{-Write { ( x) �
amxm + ... + alx +Do with a; E IF q for 0 � i � m. Then, using Lemma 2.3
and Theorem 1.46, we get
1({3•) � amf3qm + '" + a,f3• + ao � a'!.,{3qm + '" + arf3• + ag
� (amr +---+ a,/3 + a0)• � 1(/3)• � 0_
l m-1 Therefore, the elements a, aq, aq , ... , aq are roots of f. It remains to
prove that these elements are distinct. Suppose, on the contrary, that
aq' = aq� for some integers j and k with 0 � j < k � m-1. By raising this
identity to the power qm--k, we get
It follows then from Lemma 2_12 that {(x) divides x•"-'''-x. By Lemma
2.13, this is only possible if m divides m- k + J-But we have 0 < m-k + j
< m, and so we arrive at a contradiction. D
2.15. Corolklry. Let 1 be an irreducible polynomial in f•[x1 o{
degree m_ Then the splitting field o{{ over F • is given by F.·-
�ro�f Th:.?!�ITl_ 2. 14 �ows that 1 splits in F... Furthermore,
IF.(a,a ,a , .. ,,a )-F.(a)-F •• for a root a of { m F ••• where the
second identity is taken from the proof of Theorem 2. 14. 0
216. Corolklry. Any two irreducible polynomials in IF •[x 1 o{ the
same degree have isomorphic splitting fields.
2. Roots of Irreducible Polynomials 49
We introduce a convenient terminology for the elements appearing in
Theorem 2.14, regardless of whether a E IF •• is a root of an irreducible
polynomial in IF•[x] of degree m or not.
2.)7. Definition. Let IF •• be an extension of !' • and let a E IF ••. Then the
elements a, aq. aq1. aq,.,_, are_calkd_tij�jugOies of a wjth respect to IF'q
The conjugates of a E F •• with respect to IF• are distinct if and only if
the minimal polynomial of a over F • has degree m. Otherwise, the degree d
of this minimal polynomial is a proper divisor of m, and then the conjugates
of a with respect to Fq are the distinct elements a,aq, ... ,aqd_,, each
repeated m j d times.
218. Theorem. The conjugates of a E IF; with respect to any sub
field of F q have the .same order ft. the group F;.
Proof Since IF; is a cyclic group by Theorem 2.8, the result follows
from Theorem l.l5(ii) and the fact that every power of the characteristic of
F • is relatively prime to the order q -1 of F;. 0
2.19. Corollary. If a is a primitive element of IF •• then so are all its
conjugate s with respect to any sub field of IF q·
2.20. Example. Let a E IF 16 be a root of f(x) = x4 + x + 1 E IF2[x]. Then
the conjugates of a with respect to F2 are a, a2, a4 ;e a+ 1, and a8 = a2 + 1,
each of them being a primitive element of F 16• The conjugates of a with
respect to F 4 are a and a4 = a+ l. 0
There is an intimate relationship between conjugate elements and
certain automorphisms of a finite field. Let F •• be an extension of IF •. By an
automorphism a of IF •• over F q we mean an automorphism of F •• that fixes
the elements of F •. Thus, in detail, we require that a be a one-to-one
mapping from F •• onto itself with a(a+,B)=a(a)+a(,B) and a(a,B)=
a(a)a(,B) for all a,,B E IF •• and a(a) =a for_�lE�J: •.
211- Theorem. The distinct automorphisms of IF q• over F q are
exactly the mappings "o•"I>"""•"m-l• defined by a/a)=a•1 for a ElF •• and
O.;j.;m-1.
Proof For each a1 and all a,,B E F •• we obviously have a1(a,8)=
a1(a)a/.B)-and also a1(a+ ,8)= a/a)+a1(,B) because of Theorem 1.46, so
that a1 is an endomorphism of F ••. Furthermore, "/a) = 0 if and only if
a:= 0, and so ai is one-to-one. Since IF q'" is a finite set, a1 is an epimorphism
and therefore an automorphism of F ••. Moreover, we have a1(a) =a for all
a E IF • by Lemma 2.3, and so each a1 is an automorphism of F •• over F •.
so Structure of Finite Fields
The mappings a0, a1, ••• , am-1 are distinct since they attain distinct values
for a primitive element of IF,.. . Now suppose that a is an arbitrary automorphism of IF q"' over IF,. Let
{J be a primitive element of IF,. and letl(x)=x"'+a.,_1x"'-1+ ··· +
a0 E F ,[x 1 be its minimal polynomial over F ,. Then
0=CJ(fl"'+a.,_1{J"'-1+ · ·· +a0)
=a(fl)"'+a.,_1CJ((J)"'-1+ · ·· +a0,
so that <1({J) is a root of I in IF, •. It follows from Theorem 2.14 that
<1( {J) = (J<' for some j, 0 "j" m-I. Since " is a homomorph ism, we get
then <1( a)= a•' for all a E F ,.. 0
On the basis of Theorem 2.21 it is evident that the conjugates of
a E IF,. with respect to F • are obtained by applying all automorphisms of
IF•"' over F, to the element a. Til<: _au_IO_II19.!11..hism�()f_.f,.,_over F, form a
gr_o_u_p�i!.IUhe..nperation-being. the...usual _.c.ompnsitinn.__oi.!!lajlpi�gs. The
information provided in Theorem 2.21 shows that this group of auiomor
phisms ofF,. over _F0_is)cycl[�_groupoforder m-ge-neratOd by a!"
3. TRACES, NORMS, AND BASES
In this section we adopt again the viewpoint of regarding a finite extension
F=F,. of the finite field K=F, as a vector space over K (compare with
Chapter I, Section 4). Then F has dimension mover K, and if {a1, ... ,a.,} is
a basis of F over K, each element a E F can be uniquely represented in the
form
a=c1a1+ ··· +cmam withc;EK for l�j�m.
We introduce an important mapping from F to K which will turn out to be
linear.
2.22. Definition. For QE F=F,. and K=IF,, the trace TrF;K(a) of a
over K is defined by
TrF;K(a) =a+ a•+ · · · + "'.·-•
If K is the prime subfield of F, then TrF;K(a) is called the absolute trace of
"' and simply denoted by Tr F( a).
In other words, the trace of a over K is the sum of the conjugates of
a with respect to K. Still another description of the trace may be obtained
as follows. Let IE K [x 1 be the minimal polynomial of a over K; its degree
dis a divisor of m. Then g(x} = l(x)mld E K[x1 is called the characteristic
polynomial of a over K. By Theorem 2.14, the roots of I in F are given by
3. Traces, Norms. and Bases 51
a, a•, ... ,a•'-', and then a remark following Definition 2.17 implies that the
roots of g in F are precisely the conjugates of a with respect to K. Hence
g(x) � xm + am_,xm-l +-.Y·. + ao
� (x-a)(x-a•) ... (x-ar'), (2.1)
• and a comparison of coefficients shows that
TrF/K(a) �-am-I· (2.2)
In particular, TrF;K(a) is always an element of K.
2.23. Theorem. Let K � 'f q and F �IF q"· Then the trace function
Tr F/K satisfies the following properties:
(i) TrF/K(a + fJ) � TrF;K(a)+ TrF;K(fJ) for all a, fJ E F;
(ii) TrF1K(ca)�cTrF/K(a)forallcEK, aEF;
(iii) TrF/K is a linear transform ation from F onto K, where both F
and K are viewed as vector spaces over K;
(iv) TrF;K(a) � mo for all a E K;
(v) TrF;K( a•) � TrF/K( a) for all a E F.
Proof
(i) For a, fJ E F we use Theorem 1.46 to get
TrF;K(a+fJ)�a+fJ+(a+fJ) •+ ··· +(a+fJ) • --'
�a+fJ+a•+fJ•+ : ·· +a•"-'+p• ·-•
� TrF1K(a)+TrF1K(fJ).
(ii) ForcE K we have c•' � c for all};;. 0 by Lemma 2.3. Therefore
we obtain for a E F,
TrF;K(ca)�ca+c•a• + ··· +c•"-'a•·-•
= ca + caq + · · · + caq"'-1
� cTrF;K(a).
(iii) The properties (i) and (ii), together with the fact that TrF/K(a)
E K for all a E F, show that TrF/K is a linear transformation
from F into K. To prove that this mapping is onto, it suffices
then to show the existence of an a E Fwith TrF;K(a) "'0. Now
TrF;K(a)�O if and only if a is a root of the polynomial
x•"-'+ ··· +x•+xEK[x] in F. But since this polynomial
can have at most qm-l roots in F and F has qm elements, we
are done.
(iv) This follows immediately from the definition of the trace
function and Lemma 2.3.
(v) For a E F we have a•" �a by Lemma 2.3, and so TrF;K(a•) �
a•+a•'+ ·· · +a•"�TrF;K(a). 0
52 Structure of Finite Fields
The trace function TrF/K is not only in itself a linear transformation
from F onto K, but serves for a description of all linear transformations
from F into K (or, in an equivalent terminology, of all linear functionals on
F) that has the advantage of being independent of a chosen basis.
2.24. Theorem. Let F be a finite extension of the finite field K, both
considered as vector spaces over K. Then the linear transformations from F
into K are exactly the mappings Lp. fl E F, where Lp( a)� TrF/K(fla) for all
a E F. Furthermore, we have Lp � L'l whenever f3 andy are distinct elements
of F.
Proof Each mapping Lp is a linear transformation from F into K
by Theorem 2.23(iii). For fl, y E F with fl "'y, we have Lp(a)-Ly(a) �
TrF;K(fla)-Tr F/K(ya)�Tr F/K((fl-y)a)"'O for suitable aEF since
TrF/K maps F onto K, and so the mappings Lp and L, are different. If
K � F• and F� IFq"'• then the mappings Lp yield qm different linear transfor
mations from F into K. On the other hand, every linear transformation from
F into K can be obtained by assigning arbitrary elements of K to the m
elements of a given basis ofF over K. Since this can be done in qm different
ways, the mappings Lp already exhaust all possible linear transformati ons
�F�� D
2.25. Theorem. Let F be a finite extension of K �F •. Then for
a E F we have TrF/K(a) � 0 if and only if a� fl•-fl for some fl E F.
Proof The sufficiency of the condition is obvious by Theorem
2.23(v). To prove the necessity, suppose a E F� F q" with Tr F/K( a)� 0 and
let fl be a root of x• - x -a in some extension field of F. Then fl • -fl � a
and
so that fl E F. � (fl•-fl)+(fl•-fl)q+ ... +(fl•-fl)··-·
� (fl•-Ill+ (fJ•'-fl•)+ " + (fJ•"-{J··-·)
�fl•"-fl,
D
In case a chain of extension fields is considered, the composition of
trace functions proceeds according to a very simple rule.
226. Theorem (Transitivity of Trace). Let K be a finite field, let F
be a finite extension of K and E a finite extension of F. Then
Tr E/K (a) � TrF/K (Tr£1F( a)) for all a E E.
3_ Traces. Norms, and Bases 53
Proof LetK�F,, let[F:K]�mand [E:F]�n,sothat[E:K]�
mn by Theorem 1.84. Then for a E E we have
Tr,1K(Tr£1,(a))� mE,Tr£1,(a).'� mE1 ("i'a•1"')''
;-o ,-o 1=o
m-1 11-1
i = 0 j = () m11-1 L a•'�Tr E;K(a). k=O 0
Another interesting function from a finite field to a subfield is
obtained by forming the product of the conjugates of an element of the field
with respect to the subfield.
'
2.27. Definition. For a E F� IF,. and K �IF,, the norm N,1K(a) of a
over K is defined, by
NF/K(a) = a.•a.q• ... ·aq�•--1= a.tq"'-Il/(q-11 .
By comparing the constant terms in (2.1), we see that N,1K(a) can
be read off from the characteristic polynomial g of a over K -namely,
(2.3)
It follows, in particular, that N,1K(a) is.always an element of K.
228. Theorem. Let K � F, and F � F , •. Then the norm function
N F/K satisfies the following properties:
(i) N,1K(aj3) � N,1K(a)N,1K(/3)for all a, P E F;
(ii) NFIK maps F onto K and F* onto K*;
(iii) N,1K(a) �am for all a E K;
(iv) N,1K(a')� N,1K(a)forallaEF.
Proof (i) follows immediately from the definition of the norm. We
have already noted that N,1K maps F into K. Since N,1K( a)� 0 if and only
if a� 0, N,1K maps F* into K*. Property (i) shows that NF/K is a group
homomorphism between these multiplicati ve groups. Since the elements of
the kernel of N,1K are exactly the roots of the polynomial x<q"-IJM-IJ_l
E K[x] in F, the order d of the kernel satisfies d.; (qm -1)/(q -1). By
Theorem 1.23, the image of N,1K has order (qm -1)/d. which is :;. q -1.
Therefore, NF/K maps F* onto K* and so F onto K. Property (iii) follows
from the definition of the norm and the fact that for a E K the conjugates of
a with respect to K are all equal to a. Finally, we have N,1K( a•) �
N F/K(a)' � N F/K (a) because of (i) and N F;K( a) E K, and so (iv) is shown.
0
54 Structure of Finite Fields
229. Theorem (Transitivity of Norm). Let K be a finite field, let F
be a finite extension of K and E a finite extension of F. Then
NE/K(a) � NF;K(NE/F(a)) foral/aE E.
Proof With the same notation as in the proof of Theorem 2.26, we
have for a E E.
NF/K (NE;F( a)) � NF!K ( a1•"'"-l)/\q"'-l))
= ( a(q"'"-�)/(q'"-1) )(qm-1)/(q -I)
0
If (a1, ••• ,am) is a basis of the finite field F over a subfield K, the
question arises as to the calculation of the coefficients c1( a) E K, I .;; j.;; m,
in the unique representation
a� c1(a)a1 + · · · + cm(a)am (2.4)
of an element a E F. We note that c1: a�---+ c/ a) is a linear transform ation
from F into K, and thus, according to Theorem 2.24, there exists a {J1 E F
such that c1(a) � TrF;K({J1a) for all a E F. Putting a� a1, I.;; i.;; m, we see
that TrF1K({J1a,) � 0 for i"' j and I for i � j. Furthermore, ({J1, ••• ,{Jm) is
again a basis of F over K, for if
d1{J1+···+dmflm�O withd1EK forl.;;i.;;m,
then by multiplying by a fixed a1 and applying the trace function TrF!K• one
shows that d1 � 0.
2.30. Definition. Let K be a finite field and F a finite extension of K.
Then two bases (a1, ••• ,a.,) and ({J1, ••• ,{Jm) of Fover K are said to be dual
(or complementary) bases if for I.;; i,j.;; m we have
fori"' j,
fori� j.
In the discussion above we have shown that for any basis ( a1, ••• , am)
ofF over K there exists a dual basis ({J1, ••• ,{Jm). The dual basis is, in fact,
uniquely determined since its definition implies that the coefficients c1( a),
I.;; j.;; m, in (2.4) are given by c/a) � TrF;K({J1a) for all a E F, and by
Theorem 2.24 the element {J1 E F is uniquely determined by the linear
fransformation c1.
2.31. Example. Let a E F, be a root of the irreducible polynomial
x3 + x2 +I in F2[x]. Then (a, a2• I+ a+ a2) is a basis of IF8 over F2• One
checks easily that its uniquely determined dual basis is again (a, a2• I+ a+
a2). Such a basis that is its own dual basis is called a self-dual basis. The
element a5 E IF11 can be uniquely represented in the form a5 = c1a + c2a2 +
3. Traces, Norms, and Bases
I
c3(1 +a+ a2) with c1, c2• c3 E IF2• and the coefficients are given by
c1=Tr• (a·a')=O,
•
c = Tr ( a2 · a') = I 2 F8 •
c3 =Tr.,((l+ a+ a2)a') =I,
so that a'= a2 +(I+ a+ a2 ). ss
0
The number of distinct bases ofF over K is rather large (see Exercise
2.37), but there are two special types of bases of particular importance. The
first is a polynomial basis (l,a,a2, ... ,am-t), made up of the powers of a
defining element a of F over K. The element a is often taken to be a
primitive element of F (compare with Theorem 2. 10). Another type of basis g. s a ormal basis defined by a suit�ble element of F.
Definition. Let K = IF, and F = F , •. Then a basis of F over K of the
a, aq •... , aq"'-1}. consisting of a suitable element a E F and its con
jugates with respect to K, is called a normal basis of F over K.
The basis (a. a2• I + a+ a2) of F8 over F2 discussed in Example 2.31
is a normal basis of F8 over IF2 since I+ a+ a2 = a4. We shall show that a
normal basis exists in the general case as well. The proof depends on two
lemmas, one on a kind of linear independence property of certain group
homomorphisms and one on linear operators.
2.33. Lemma (Artin Lemma). Let¥-1 ..... -r.., be distinct homomor
phisms from a group G into the multiplicative group F* of an arbitrary field F,
and let a 1, ... , am be elements of F that are not all 0. Then for some g E G we
have
Proof We proceed by induction on m. The case m =I being trivial,
we assume that m >I and that the statement is shown for any m-I distinct
homomorphisms. No--: take ¥-1, .... ¥-m and a1, ... ,am as in the lemma. If
a1 = 0, the induction hypothesis immediately yields the desired result. Thus
let a 1 "' 0. Suppose we had
a1¥-1(g)+ ... +am>l-m(g)=O forallgEG. (2.5)
Since ¥-1 "' >1-m• there exists hE G with >i-1(h)"' >1-m(h). Then. replacing g by
hg in (2.5). we get
a1>l-1(h)¥-1(g)+ ... +am>l-m(h).r.,(g)=O forallgEG.
After multiplication by ¥-m (h)-1 we obtain
b,¥-,(g)+ ... +bm-1>1-m-l(g)+am¥-m(g)=O forallgEG,
where b;=a;>l-,(h)>i-.,(h)-1 for l.;i.;m-1. By subtracting this identity
56 Structure of Finite Fields
from (2.5), we arrive at
where c, �a,-b, for 1.;; i.;; m-1. But c1 � a1 -a1,P 1( h Nm(h )-1 * 0, and
we have a contradiction to the induction hypothesis. D
We recall a few concepts and facts from linear algebra. If T is a
linear operator on the finite-dimensional vector space V over the (arbitrary)
field K, then a polynomial f(x) � a,x" + · · · + a1x + a0 E K[x] is said to
annihilate T if a,T" + · · · + a1T + a0/ = 0, where I is the identity operator
and 0 the zero operator on V. The uniquely determined monic polynomial
of least positive degree with this property is called the minimal polynomial
forT. It divides any other polynomial in K[x] annihilating T. In particular,
the minimal polynomial for T divides the characteristic polynomial g(x) for
T (Cayley-Hamilton theorem), which is given by g(x) � det(x/ -T) and is
a monic polynomial of degree equal to the dimension of V. A vector a E Vis
called a cyclic vector for T if the vectors T'a, k � 0, 1, ... , span V. The
following is a standard result from linear algebra.
234. Lemma. Let T be a linear operator on the finite-dimensional
vector space V. Then T has a cyclic vector if and only if the characteristic and
minimal polynomials for T are identical.
235. Theorem (Normal Basis Theorem). For any finite field K and
any finite extension F of K, there exists a normal basis ofF over K.
Proof Let K � F, and F � F ,. with m ;;. 2. From Theorem 2.21 and
the remarks following it, we know that the distinct automorphisms ofF over
K are given byE, a, a2, ... ,am-l, where E is the identity mapping on F,
a(a) �a' for a E F, and a power af refers to the j-fold composition of a
with itself. Because of a(a+,B)�a(a)+a(,B) and a(ca)�a(c)a(a)�
ca(a) for a, ,8 E F and c E K, the mapping a may also be considered as a
linear operator on the vector space F over K. Since am= E, the polynomial
xm-IE K[x] annihilates a. Lemma 2.33, applied to£, a, a2, ..• ,am-I viewed
as endo.morphisms of F*, shows that no nonzero polynomial in K [ x] of
degree less than m annihilates a. Consequently, xm-1 is the minimal
polynomial for the linear operator a. Since the characteristic polynomial for
a is a monic polynomial of degree m that is divisible by the minimal
polynomial for a, it follows that the characteristic polynomial for a is also
given by xm -1. Lemma 2.34 implies then the existence of an element a E F
such that a, a(a), a2(a), ... span F. By dropping repeated elements, we see
that a, a(a), a2(a), ... ,am-1(a) span F and thus form a basis ofF over K.
Since this basis consists of a and its conjut;ates with respect to K, it is a
normal basis of F over K. D
3. Traces, Norms. and Bases 57
An alternative proof of the normal basis theorem will be provided in
Chapter 3. Section 4, by using so-called linearized polynomials.
We introduce an expression that allows us to decide whether a given
set of elements forms a basis of an extension field.
2.36. Definition. Let K be a finite field and Fan extension of K of degree
mover K. Then the discriminant 6.F;K(a1, ... ,am) of the elements a1, ... ,am
E F is defined by the determinant of order m .given by
TrF;K(a1a1) TrF;K(a1a2) TrF;K(a1am)
llF;K(a, .... ,am) � TrF;K(a2a1) Tr F/K ( a2a2) TrF;K(a2am)
TrF;K(amal) Tr F!K (a mal) TrF;K(amam)
It follows from the definition that l1F;K(a1, ... ,a.,) is always an
element of K. The following simple characterization of bases can now be
g�ven.
2.37. Theorem. Let K be a finite field, Fan extension of K of degree
m over K, and a1, ... , am E F. Then { a1, ... , am)· is a basis ofF over K if and
only if l1F;K(a1, ... ,am)"' 0.
Proof Let {a1 .... ,am) be a ba.sis of F over K. We prove that
l1F;K(a1 .... ,a.,)"' 0 by showing that the row veqors of the determinant
defining l1F;K(a1,. ... am) are linearly independent. For suppose that
c1TrF;K(a1a)+ · · · + cmTrF;K(amaj) � 0 for'"" j"" m,
where c1, ... ,c., E K. Then with /3 � c1a1 + .. · + c.,am we get TrF;K(/3a)
� 0 for'"" j"" m. and since a1, ... ,a., span F. it follows that TrF;K({Ja) � 0
for all a E F. However. this is only possible if p � 0, and then c1a1 + · · · +
emam = 0 implies el = ... =em= 0.
Conversely, suppose that l1F;K(a1, .... am)*O and c1a1+ .. ·+
emam = 0 for some e1, ... ,em E K. Then
e1a1aj+ ··· +emamaj=O far l�j�m.
and by applying the trace function we get
c1TrF;K(a1aj)+ ··· +cmTrF;K(ama)�O forl"'j"'m.
But since the row vectors of the determinant defining l1F;K(a1, ... ,am) are
linearly independent, it follows that c1 � • • • �em� 0. Therefore. a1, ... ,a.,
are linearly independent over K. 0
There is another determinant of order m that serves the same
purpose as the discriminant l1F;K(a1 .... ,am). The entries of this determi
nant are, however. elements of the extension field F. For a1, .... am E F. let
58 Structure of Finite Fields
A be them X m rilatrix whose entry in the ith row andjth column is af-1,
where q is the number of elements of K. If AT denotes the transpose of A,
then a simple calculation shows that ATA � B, where B is them X m matrix
whose entry in the ith row and jth column is TrF;K(a1a). By taking
determinants, we obtain
dF/K(a1, ... ,am) � det(A)2
The following result is now implied by Theorem 2.37.
2.18, CoroUary, Let a1, ... ,am E F ••. Then {a1, ... ,am) is a basis of
IF q"' over IF q if and only if
a, a, am
af a� a• m *0.
a(' '
·-' q"'-1 a� a.,
From the criterion above we are led to a relatively simple way of
checking whether a g!ven element gives rise to a normal basis.
219 Th "" IF ( • •' ··-'). lba. . . eorem. z·or a E q"'' a, a , a , ... , a IS a norma SIS
of IF • over IFq if and only if the polynomials xm �I and axm-l +
aqxm�2 + · · · + aq"'-\ + aq"'_'_ in 1Fq ... [x] are relatively prime.
Proof When a1 =a, a2 = aq, ... ,am = aq"' 1, the determinant m
Corollary 2.38 becomes
a a• a• , a"m-\
aqm-\ a• __ , a a•
aq"'-� __ , __ , (2.6) ± a• a a •
a• a •' a• ' a
after a suitable permutation of the rows. Now consider the resultant R(/, g)
of the polynomials f(x) � xm �I and g(x) � axm-l + a•xm-2 + · · · +
afl"'-2x + aq"'-1 of formal degree m resp. m -I, which is given by a_determi
nant of order 2m� I in accordance with Definition 1.93. In this determi
nant, add the (m + l)st column to the first column, the (m +2)nd column to
the second column, and so on, finally adding the (2m� l)st column to the
(m � l)st column. The resulting determinant factorizes into the determinant
of the diagonal matrix of order m � I with entries � I along the main
diagonal and the determinant in (2.6). Therefore, R(/, g) is, apart from the
sign, equal to the determinant in (2.6). The statement of the theorem follows
4. Roots or Unity and Cyclotomic Polynomials 59
then from Corollary 2.38 and the fact that R(f, g)* 0 if and·only iff and g
are relatively pr_ime. D
In connection with the preceding discussion. we mention without
proof the following refinement of the normal basis theorem.
2.40 Theorem. For any finite extension F of a finite field K there
exists a normal basis of F over K that consists of primitive elements of F.
4. ROOTS OF UNITY AND CYCLOTOMIC POLYNOMIAlS
In this section we investigate the splitting field of the polynomial x"-I
over an arbitrary field K. where n is a positive integer. At the same time we
obtain a generalization of the concept of a root of unity. well kno\>n for
complex numbers.
2.41. Definition. Let n be a positive integer. The splitting field of x"-I
over a field K is called the nth cyclotomic field over K and denoted by K1"1.
The roots of x"-1 in K<'11 are called the nth roots of unity over K and the
set of all these roots is denoted by £1"1.
A special case of this general definition is obtained if K is the field of
rational numbers . Then K1"1 is a subfield of the field of complex numbers
and the nth roots of unity have their known geometric interpretation as the
vertices of a regular polygon with n vertices on the unit circle in the complex
plane.
For our purposes. the most important case is that of a finite field K.
The basic properties of roots of unity can, however. be established without
using this restriction. T_he_�tru�ture_2L� -�:.)_.i.S.JJ._�J_e_fJ!!_i�_f:.4 .. �Y the relation of
n tothe characteristic of K.-as th�following theorem shows:Wfien-werefe-r
to the ch3��-cteflsilCP-�f .. k in this discussion. we permit the case p = 0 as
well.
2.42. Theorem. Let n be a positive integer and K a field of char
acteristic p. Then:
(i) If p does not divide n, then £1"1 is a cyclic group of order n with
respect to multiplication in Kl"1.
(ii) lfp divides n, write n = mpe with positive integers m and e and m
not divisible by p. Then K<nl = Klml, £(nl = £<m>. and the roots
of x"-1 in K1"1 are them elements of £lml. each auained with
multiplicity p'.
Proof (i) The case n �I is trivial. For n ;. 2. x" -I and its deriva
tive nx·�-l have no common roots, as nx"-1 only has the root 0 in K1"1.
Therefore. by Theorem 1.68. x" -I cannot have multiple roots, and hence
£1"1 has n elements. Now if I.�E£1" 1, then (��-1)"�1"(71")-1�1. thus
60 Structure or Finite Fields
�1J-l E £1"1. It follows that £l•l is a multiplicative group. Let n �
Pi'P2' · · · p;• be the prime factor decomposition of n. Then one shows by
the same argument as in the proof of Theorem 2.8 that for each i, 1.; i.; t,
there e�ists an element a, E £1•l that is not a root of the polynomial
x"IP, -I, that /J; = a71prr has order pf;, and that £(II) is a cyclic group with
generator {3 � {31 {32 · · · {3,.
(ii) This follows immediately from x"-I� xmp'-I� (xm-I)'' and
�ro. o
2.43. Definition. Let K be a field of characteristic p and n a positive
integer not divisible by p. Then a generator of the cyclic group £l•l is called
a primitive nth root of unity over K.
By Theorem 1.15(v) we know that under the conditions of Definition
2.43there are e�actly cl>(n) different primitive nth roots of unity over K. If�
is one of them, then all primitive nth roots of unity over K are given by�·.
where I.; s.; n and gcd(s, n) �I. The polynomial whose roots are precisely
the primitive nth roots of unity over K is of great interest.
2.44. Definition. Let K be a field of characteristic p, n a positive integer
not divisible by p, and � a primitive nth root of unity over K. Then the
polynomial
Q,(x) � •
n (x-n
,_,
gcd(s,n)-1
is called the nth cyclotomic polynomial over K.
The polynomial Q,(x) is clearly independent of the choice oft The
degree of Q,(x) is cl>(n) and its coefficients obviously belong to the nth
cyclotomic field over K. A simple argument will show that they are actually
contained in the prime subfield of K. We use the product symbol Tidi• to
denote a product e�tended over all positive divisors d of a positive integer n.
245. Theorem. Let K be a field of characteristic p and n a positive
integer not divisible by p. Then:
(i) x"-I� Tid1.Qd(x);
(ii) the coefficients of Q.(x) belong to the prime subfield, of K, and to
Z if the prime sub field of K is the field.of'ational numbers.
Proof (i) Each nth root of unity over K is a primitive dth root of
unity over K for e�actly one positive divisor d of n. In detail, if � is a
primitive nth root of unity over K and �·is an arbitrary nth root of unity
over K, then d � njgcd(s, n); that is, dis the order of�· in E1"l. Since
•
x"-1� n<x-f'),
,_,
4. Roots of Unity and Cyclotomic Polynomials 61
the formula in (i) is obtained by collecting those factors (x-t'J 'for which
t' is a primitive d th root of unity over K.
(ii) This is proved by induction on n. Note that Q.,(x) is a monic
polynomial. For n �I we have Q1(x) �x-I, and the claim is obviously
valid. Now let n >I and suppose the proposition is true for all Qd(x) with
l.;d<n. Then we have by (i), Q,(x)�(x"-1)/f(x), where f(x)�
fl"1,.J., Qd(x). The induction hypothesis implies thatf(x) is a polynomial
with coefficients in the prime subfield of K or in Z in case the characteristic
of K is 0. Using long division with x" -I and the monic polynomial f(x),
we see that the coefficients of Q,(x) belong to the prime sub field of K or to
Z, respectively. D
2.46. Example. Let r be a prime and k E N. Then
since
x,.1c -1 x,.A -I Q,•(x) � Q1(x)Q,(x)· · · Q,•-•(x) x',_, -I
by Theorem 2.45(i). For k �I we simply have Q,(x) �I+ x + x2 + · · · +
xr-1. D
An explicit expression for the .nth cyclotomic polynomial generaliz
ing the formula for Q,•(x) in Example 2.46 will be given in Chapter 3,
Section 2. For applications to finite fields it is useful to know some
properties of cyclotomic fields.
247. Theorem. The cyclotomic field K'"' is a simple algebraic
extension of K. Moreover:
(i) If K � Q, then the cyclotomic polynomial Q, is irreducible over K
and [K1"': K] � cp(n).
(ii) If K � F• with gcd(q, n) �I, then Q,factors into cp(n)/d distinct
monic irreducible polynomials in K[x] of the same degree d, K'"1
is the splitting field of any such irreducible factor over K, and
[K'"1: K] � d, where d is the least positive integer such that
qd =I mod n.
Proof If there exists a primitive nth root of unity t over K, it is
clear that K'"1 � K(t). Otherwise, we have the situation described in
Theorem 2.42(ii), then K'"' � K'm1 and the result follows again. As to the
remaining statements, we prove only (ii), the important case for our pur
poses. Let � be a primitive nth root of unity over F •. Then � E IF •' if and
only if �·· � �. and the latter identity is equivalent to q' = I mod n. The
smallest positive integer for which this holds is k � d, and so� is in F•'• but
62 Structure of Finite Fields
in no proper sub field thereof. Thus the minimal polynomial of � over F q has
degree d, and since� is an arbitrary root of Q •• the desired results follow. D
2.48. Example. Let K�F11 and Q12(x)�x4-x 2+1EIF11[x]. In the
notation of Theorem 2.47(ii) we have d � 2. In detail, Q12(x) factors in the
form Q12(x) � ( x2 + Sx + l)(x2 -Sx + 1), with both factors being irreduci
ble in IF 11 [ x ]. The cyclotomic field K1 121 is equal to IF 121• D
A further connection between cyclotomic fields and finite fields is
given by the following theorem.
2.49. Theorem. The finite field F q is the ( q -I )st cyclotomic field
over any one of its subfields.
Proof The polynomial x•-1 -I splits in IF q since its roots are
exactly all nonzero elements of F q· Obviously, the polynomial cannot split
in any proper subfield of F •• so that IF q is the splitting field of x•-1 -I over
any one of its subfields. D
Since F; is a cyclic group of order q-I by Theorem 2.8, there will
exist, for any positive divisor n of q-I, a cyclic subgroup {1, a, ... , a"-1} of
IF; of order n (see Theorem l.IS(iii)). All elements of this subgroup are nth
roots of unity over any sub field of f q and the generating element a is a
primitive nth root of unity over any sub field of F q·
We conclude this section with a lemma we shall need later on.
2.50. Lemma. If dis a divisor of the positive integer n with I .;; d < n,
then Q.(x) divides (x" -1)/(xd -I) whenever Q.(x) is defined.
Proof From Theorem 2.45(i) we know that Q.(x) divides
x"-l�(xd-l)x"-l.
xd -I
Since dis a proper divisor of n, the polynomials Q.(x) and xd -I have no
common root, hence gcd(Q.(x), xa -I)� I and the proposition is true. D
5. REPRESENTATION OF ELEMENTS OF FINITE FIELDS
In this section we describe three different ways of representing the elements
of a finite field F q with q � p" elements, where p is the characteristic of F q·
The first method is based on principles expounded in Chapter I,
Section 4, and in the present chapter. We note that IF q is a simple algebraic
extension of I' P by Theorem 2.1 0. In fact, iff is an irreducible polynomial in
F,[x] of degree n, thenfhas a root a in F• according to Theorem 2.14, and
so F• � F,(a). Then, by Theorem 1.86, every element of IF• can beuniquely
5_ Representation of Elements of Finite Fields 63
expressed as a polynomial in a over IF r of degree less than n. We may also
view IF9 as the residue class ring F,[x]/(fl.
2.51. Example. To represent the elements of IF9 in this way, we regard F9
as a simple algebraic extension of IF 3 of degree 2, which is obtained by
adjunction of a root a of an irreducible quadratic polynomial over F3, say
/( x) � x2 +IE IF3[x]. Thus/( a)� a2 +I� 0 in F9, and the nine elements
of IF9 are given in the form a0 + a1a with a0, a1 E IF3. In detail, IF9 =
(0, I, 2, a, I + a, 2 + a, 2a, I + 2a, 2 + 2a}. The operation tables for F9 may be
constructed as in Example 1.62, with a playing the role of the residue class
[x]. 0
If we use Theorems 2.47 and 2.49, we get another possibility of
expressing the elements of IF9. Since IF9 is the (q -l)st cyclotomic field over
IF,, we can construct it by finding the decomposition of the (q-!)st
cyclotomic polynomial Q,_, E IF,[x] into irreducible factors in F,[x], which
are all of the same degree. A root of any one of these factors is then a
primitive (q -l)st root of unity over F, and therefore a primitive element of
IF,-Thus, F 9 consists of 0 and appropriate powers of that primitive element.
2.52. Example. To apply this to the construction of F9, we note that
IF,� IFj''. the eighth cyclotomic field over IF3. Now Q8(x) � x4 +IE IF3[x]
by Example 2.46, and
Q8(x)�(x2+x.+2)(x2+2x+2)
is the decomposition of Q8 into irreducible facto�s in IF3[x]. Let!; be a root
of x2 + x + 2; then !; is a primitive eighth root of unity over IF3• Thus, all
nonzero elements of F9 can be expressed as powers of t. and so IF9 =
(0. !;. !;2, 1;3, 1;4, !;', !;', !;7, !;8). We may arrange the nonzero elements of IF9 in
a so-called index table, where we list the elements !;' according to their
exponents i. In order to establish the connection with the representation in
Example 2.51, we observe that x2+x+2EF3[x] has !;�I+a as a root,
where a2 +I� 0 as in Example 2.51. Therefore, the index table for F9 may
be written as follows:
!:' !:'
I I+ a 5 2+2a
2 2a 6 a
3 I +2a 7 2+ a
4 2 8 I
We see that we obtain, of course, the same elements as in Example 2,51, just
in a different order. D
A third possibility of representing the elements of IF 9 is given by
means of matrices. In general, the companion matrix of a monic polynomial
64 Structure of Finite Fields
f(x)�a0+a1x+ ··· +a._1x"-1+x" of positive degree n over a field is
defined to be the n X n matrix
0 0 0· 0 -ao
I 0 0 0 -a,
A� 0 0 0 -a,
0 0 0 -a,_\
It is well known in linear algebra that A satisfies the equationf(A) � 0; that
is, a01+a1A+ ··· +a._1A"-1+A"�O. where I is the nXn identity
matrix.
Thus, if A is the companion matrix of a monic irreducible poly
nomial f over F, of degree n, then /(A)� 0, and therefore A can play the
role of a root of f. The polynomials in A over F P of degree less than n yield a
representation of the elements of IF •.
2.53. Example. As in Example 2.51, let f(x) � x' +IE IF3[x]. The com
panion matrix off is
The field F9 can then be represented in the form F9 � {0, /,2/, A, I+ A,
2/ + A,2A, I +2A,21 +2A}. Explicitly:
/+A�(: �l· �� (6 n 21� (�
i)• 2/+A�(i ;) . 2A� (�
i )· :) . 21+2A� (� �)'
With F9 given in this way, calculations in this finite field are then carried
out by the usual rules of matrix algebra. For instance,
(2/+A)(/+ 2A)�(i �)(i :)�(� 6)�2A. D
In the same way, the method based on the factorization of the
cyclotomic polynomial Q q-1 in IF P [ x] can be adapted to yield a representa
tion of the elements ofF • in terms of matrices.
2.54. Example. As in Example 2.52, let h(x) � x' + x + 2 E F 3[x] be an
irreducible factor of the cyclotomic polynomial Q8 E IF3[x]. The companion
matrix of h is
c� (� i)·
6. Wedderburn"s Theorem
The field IF 9 can then be represented in the form
IF9 � {0, C, C2, C3, C4, C', C', C7, C8}.
Explicitly:
0 � (� � ). c � ( � i ). c'� (i � ).
c'�(� n C' � (� . 0)
2 . C' � (� n
C' � (i : ) . C' � (: �). c' � ( � n
Calculations proceed by the rules of matrix algebra. For instance.
C' +C� (i : )+ ( �
6. WEDDERBURN'S THEOREM 1 i) � (� 2) � C'
0 . 65
D
All results for finite fields are at the same time also true for all finite
division rings by a famous theorem due to Wedderburn. This theorem states
that in a finite ring in which all the field properties except commutativity of
multiplication are assumed (i.e., in a finite division ring), the multiplication
must also be commutative. Basically, the first -proof we present of the
theorem considers a subring of the finite divison ring that is a field and
establishes a numerical relation between the multiplicative group of the field
and the multiplicative group of the whole division ring. Using this relation
and information about cyclotomic polynomials, one obtains a contra
diction- unless the field is all of the division ring. Before we prove
Wedderburn's theorem in detail. we mention some general principles that
will be employed.
Let D be a division ring and F a subring that is a field (later on, we
will express this more briefly by saying that F is a subfield of D). Then D
can be viewed as a (left) vector space over F (compare with the discussion of
the analogou s situation for fields in Chapter I, Section 4). IfF� F q and D is
of finite dimension n over F •• then D has q" elements. We shall write D• for
the multiplicative group of nonzero elements of D.
For a group G and a nonempty subset S of G, we defined the
normalizer N(S) of SinG in Definition 1.24. If Sis a singleton {b), we may
also refer to N({b)) as the normalizer of the element bin G. From Theorem
1This section can be omitted without losing necessary information for the following
chapters.
66 Structure of Finite Fields
1.25 we infer that if G is finite, then the number of elements in the
conjugacy class of b is given by IGI/IN((b})l.
2.55. Theorem (Wedderburn's Theorem}. Every finite division ring
is a field.
First Proof Let D be a finite division ring and let Z � (z E D: zd �
dz for all dE D) be the center of D. We omit the obvious verification that Z
is a field. Thus Z � f • for some prime power q. Now D is a vector space
over Z of finite dimension n, and soD has q" elements. We shall show that
D � Z, or, equivalently, that n � 1.
Let us suppose, on the contrary, that n > 1. Now let a ED and define
N. �(bED: ab � ba). Then N. is a division ring and N. contains Z. Thus
N. has q' elements, where I"' r"' n. We wish to show that r divides n. Since
N; is a subgroup of D*, we know that q'-I divides q" -I. If n � rm + I
with 0"' I< r, then q" -I� q'"'q' -I� q'(q'"' -l)+(q' -I). Now q' -I
divides q"-I and also q'"'-I, thus it follows that q'-I divides q'-1. But
q'-I < q'-I, and so we must have 1 � 0. This implies that r divides n.
We consider now the class equation for the group D* (see Theorem
1.27). The center of D* is z•. which has order q-1. For a E D*, the
normalizer of a in D* is exactly Na*. Therefore, a conjugacy class in D*
containing more than one member has (q" -1)/(q'-I) elements, where r is
a divisor of n with I� r < n. Hence the class equation becomes
k q" -I q"-l�q-1+ L -� .
i-1 qr•-1 (2.7)
where r1, ... ,rk are (not necessarily distinct) divisors of n with I� r; < n for
l ... i ... k.
Now let Q .. be the nth cyclotomic polynomial over the field of
rational numbers. Then Q .. (q) is an integer by Theorem 2.45(ii). Further
more, Lemma 2.50 implies that Q.,( q) divides ( q" -I )/(q'• -I) for I "'i"' k.
We conclude then from (2.7) that Q.,(q} divides q -1. However. this will
lead to a contradiction. By definition, we have
n
Q.,(x) � n (x-i'),
s = 1
gcd(s,n)-1
where the complex number i is a primitive nth root of unity over the field of
rationals. Therefore, as complex numbers,
n n
IQ.(qJI� n lq-i'l> n (q-l);.q-1
s-1 s=l
gcdCs.n)=l gcd(s,n)-1
since n > I and q;. 2. This inequality is incompatible with the statement
6. Wedderburn"s Theorem 67
that Q"(q) divides q -I. Hence we must have n �I and D � Z, and the
theorem is proved. 0
Before we start with the second proof of Wedderburn's theorem, we
establish some preparatory results. Let D be a finite division ring with
center Z, and let F denote a maximal subfield of D; that is, F is a subfield of
D such that the only subfield of D containing F is F itself. Then F is an
extension of Z, for if there were an element z E Z with z fl F, we could
adjoin z to F and obtain a subfield of D properly containing F. From
Theorem 2.10 we know that F� Z(E), where� E F* is a root of a monic
irreducible polynomial / E Z[x].
If we view D as a vector space over F, then for each a E D the
assignment T.( d)� da for dE D defines a linear operator T. on this vector
space. We consider now the linear operator IE· If dis an eigenvector of IE·
then for some A E F* we have d� �Ad. This implies dEd� 1 � A and hence
dF*d-1 � F*, thus d EN( F*), the normalizer of F* in the group D*.
Conversely, if dE N(F*), then d�d-1 �A for some A E F*, and so d is an
eigenvector of IE· This proves the following result.
256. Lemma. An element d ED* is an eigenvector of 7! if and only
if dE N(F*).
Let A be an eigenvalue of 71 with eigenvector d, then dE� Ad. It
follows that 0 � df(�)� /(A)d, hence A must be a root off. If d0 is another
eigenvector corresponding to the eigenvalue A, then d0d-1 Add0 1 �A, and
so the element b = d0d-1 commutes with A anc( consequently, with every
element ofF� Z(A). Let P be the set of all polynomial expressions in b
with coefficients in F. Then it is easily checked that P forms a finite integral
domain, and so P is a finite field by Theorem 1.31. But P contains F, and
thus P � F by the maximality of F. In particular, we have bE F, and since
d0 � bd, we conclude that every eigenspace of 7! has dimension I. We use
now the following result from linear algebra.
2.57. Lemma. Let T be a linear operator on the finite-dimensio nal
vector space V over the field K. Then V has a basis consisting of eigenvectors
of T if and only if the minimal polynomial for T splits in K into distinct monic
linear factors.
Since tal� 0, the polynomial f annihilates the linear operator IE·
Furthermore, f splits in F into distinct monic linear factors by Theorem
2.14. The minimal polynomial for 7! divides/, and so it also splits in Finto
distinct monic linear factors. It follows then from Lemma 2.57 that D has a
basis as a vector space over F consisting of eigenvectors of JE. Since every
eigenspace of 7! has dimension I, the dimension m of D over F is equal to
the number of distinct eigenvalues of IE· Let�� �1• �2 •.•.• Em be the distinct
eigenvalues of 7! and let I� d1, d2, ••• ,dm be corresponding eigenvectors.
68 Structure of Finite Fields
Because N( F*) is closed under multiplication, it follows from Lemma 2.56
that d1dj must correspond to an eigenvalue�,. say, and hence d1d1� � �,d,dj.
Using dj� � �jdj, we obtain d1�j � �,d,, or d1�1di 1 �� •• This shows that for
each i, 1 .;; i.;; m, the mapping that takes �J to d1�1di 1 permutes the
eigenvalues among themselves. Consequently, the coefficients of g(x) �
(x-E1l · · · (x-�ml commute with the eigenvectors dp d,, ... ,dm of r,.
Since the coefficients of g obviously belong to F and thus commute with all
the elements of F, they commute with all the elements of D, since these can
be written as linear combinations of d1, d2, ... ,dm with coefficients in F.
Thus the coefficients of g are elements of the center Z of D. Since g( 0 � 0,
Lemma 2.12 implies that f divides g. On the other hand, we have already
observed that every eigenvalue of T, must be a root off, and so f �g. It
follows that [F: Z] � [Z(�): Z] � deg(/) � rn. Now m is also the dimension
of D over F, and so the argument in the proof of Theorem 1.84 shows that
Dis of dimension m2 over Z. Since the latter dimension is independent ofF,
we conclude that every maximal subfield of D has the same degree over Z.
We state this result in the following equivalent form.
2.58. Lemma. All maximal subfields of D have the same order.
Second Proof of Theorem 2.55. Let D be a finite division ring, and
let Z, F� Z(n and f E Z[x] be as above. Let E be an arbitrary maximal
sub field of D. Then, by Lemma 2.58, E and F have the same order, say q. In
view of Lemma 2.4, both E and F are splitting fields of x•- x over Z. It
follows then from Theorem 1.91 that there exists an isomorphism from F
onto E that keeps the elements of Z fixed. The image� E E* of� under this
isomorphism is therefore a root off in E, and so E � Z( � ). Consider the
linear operator T, on the vector space D over F. Since /( �) � 0, the
polynomial f annihilates T,. But f splits in F, and so there exists a root A E F
off that is an eigenvalue of T,. For a corresponding eigenvector d we have
then d� �Ad, and this implies E* � d-1F*d. Thus, E* is a conjugate of the
subgroup F* of D*.
For an arbitrary c E D*, the set of polynomial expressions in c with
coefficients in Z forms a finite integral domain, and thus a finite field by
Theorem 1.31. Hence, any element of D* is contained in some sub field of D,
and so in some maximal subfield of D. From what we have already shown,
it follows that any element of D* belongs to ,some conjugate of F*. By
Theorem 1.25, the number of distinct conjugates of F* is given by
ID*I/IN(F*)I. and so it is at most ID*I/IF*I. Since each conjugate ofF*
contains the identity element of D*, the union of the conjugates ofF* has at
most
ID*I (IF*I-1)+ 1 � ID*I_ID*I + 1
IF*I IF*I
Exercises 69
elements. This number is less than I D*l except when D* � F*. Hence
D � F, and D is a field. 0
EXERCISES
2.1.
2.2.
2.3.
2.4.
2.5.
2.6.
2.7.
2.8.
2.9.
2.10.
2.11.
2.12.
2.13.
2.14.
2.15.
2.16. Prove that x2 +I is irreducible over F 11 and show directly that
F11[x]/(x2+1) has 121 elements. Prove also that x2+x+4 is
irreducible over !' ll and show that IF 11 [x ]/(x2 + I) is isomorphic to
IF"[x]/(x2 + x +4).
Show that the sum of all elements of a finite field is 0, except for F2.
Let a, b be elements of IF,., n odd. Show that a2 + ab + b2 � 0
implies a � b � 0.
Determine all primitive elements of F 7.
Determine all primitive elements of F 17.
Determine all primitive elements of F9.
Write all elements of IF, as linear combinations of basis elements
over IF5. Then find a primitive element fJ ofF, and determine for
each aE 1Fi5 the least nonnegative integer n such that a= /3".
If the elements of F; are represented as powers of a fixed primitive
element bE F,, then addition in F, is facilitated by the introduction
of Jacobi's logarithm L(n) defined by the equation I+ b" � bL'"'.
where the case b" � -I is excluded. Show that we have then bm + b"
� bm+Lc• -mJ whenever L is d�fined. Construct a table of Jacobi's
logarithm for IF 9 and IF 17.
Prove: for any field F, every finite subgroup of the multiplicative
group F* is cyclic.
Let F be any field. IfF* is cyclic, show that F is finite.
Prove: if F is a finite field, then H U (0} is a subfield of F for every
subgroup H of the multiplicative group F* if and only if the order of
F* is either I or a prime number of the form 2'-I with a prime p.
For every finite field F, ·of characteristic p, show that there exists
exactly one pth root for each element of IF,.
For a finite field IF, with q odd, show that an element a E IF; has a
square root in F , if and only if a<q-IJ/2 � I.
Prove that for given k E I'll the element a E IFf is the k th power
of some element of F, tf and only tf a'•-1/d �I, where d �
gcd(q -I, k).
Prove: every element of F, is the k th power of some element of IF, if
and only if gcd(q -I, k) �I.
Let k be a positive divisor of q-I and a E F, be such that the
equation x�< =a has no solution in IF q· Prove that the same equation
has a solution in IF,. if m is divisible by k, and that the converse
holds for a prime number k.
70 Structure of Finite Fields
2.17. Prove that l(x )• � l(x•) for I E F .[x ].
2.18. Show that any quadratic polynomial in F.[x] splits over F•' into
linear factors.
2.19. Show that for a E IF • and n E I'll the polynomial x•"-x + na is
divisible by x• -x + a over F q·
2.20. Find all automorphisms of a finite field.
2.21. IfF is a field and >¥: F-> F is the mapping defined by'!'( a)� a-1 if
a"" 0, >!'(a)� 0 if a� 0, show that >¥ is an automorphism ofF if and
only if F has at most four elements.
2.22. Prove: if p is a prime and n a positive integer, then n divides
�( p" -1). (Hint: Use Corollary 2.19.)
2.23. Let F• be a finite field of characteristic p. Prove that IEF.[x]
satisfies f'(x) � 0 if and only if I is the pth power of some poly
nomial in IF•[x].
2.24. Let F be a finite extension of the finite field K with [F: K] � m and
let l(x) � xd + bd_1xd-l + · · · + b0 E K[x] be the minimal poly
nomial of a E F over K. Prove that TrF;K(a) �-(mjd)bd-l and
NF/K(a) � ( -!)mbQ'Id.
2.25. Let F be a finite extension of the finite field K and a E F. The
mapping L: p E F...., a{J E F is a linear transformation ofF, consid
ered as a vector space over K. Prove that the characteristic poly
nomial g(x) of a over K is equal to the characteristic polynomial of
the linear transformation L; that is, g( x) � det( xi-L ), where I is
the identity transformation.
2.26. Consider the same situation as in Exercise 2.25. Prove that TrF/K(a)
is equal to the trace of the linear transformation L and that NF;K(a)
� det(L).
2.27. Prove properties (i) and (ii) of Theorem 2.23 by using the interpreta
tion of TrF/K(a) obtained in Exercise 2.26.
2.28. Prove properties (i) and (iii) of Theorem 2.28 by using the interpreta
tion of NF/K(a) obtained in Exercise 2.26.
2.29. Let F be a finite extension of the finite field K of characteristic p.
Prove that TrF;K(a'") � (TrF;K(a))'" for all a E F and n E I'll.
2.30. Give an alternative proof of Theorem 2.25 by viewing F as a vector
space over K and showing by dimension arguments that the kernel of
the linear transformation TrF/K is equal to the range of the linear
operator Lon F defined by L({J) � p•-P for P E F.
2.31. Give an alternative proof of the necessity of the condition in Theo
rem 2.25 by showing that if a E F with TrF ;K(a) � 0, "Y E F with
TrF/K("Y) � -1, and 8j �a+ a• + · · · + a•J-•, then
satisfies p•- p �a. [F,K]
p� L 8j"Y·j-·
j-1
Exercises 71
2.32. Let F be a finite extension of K � F • and a= {J•-fJ for some fJ E F.
Prove that a� r•-y withy E F if and only if fJ-y E K.
2.33. Let F be a finite extension of K �IF •. Prove that for a E F we have
NF/K(a)�l ifandonlyifa�p•-1 forsome{JEF*.
2.34. Prove Lj.-o'x•'-c � nc X-a) for all c E K �IF •• where the product
is extended over all a E F �IF •• with TrF;K(a) �c.
2.35. Prove
for any mE I'll. ( m -I )
x•·-x� n :L x•'-c
cEF, ;-o
2 36. Consider IF •• as a vector space over F • and prove that for every linear
operator L on F •• there exists a uniquely determined m-tuple
(a0, a1, ... ,am_1) of elements of IFq"' such that
2.37. Prove that if the order of basis elements is taken into account, then
the number of different bases of F •• over F • is
2.38. Prove: if (a1, ••• ,am) is a basis of F�F •• over K�IF., then
TrF/K(a;) * 0 for at least one i, I .:S;; i .:S;; m. __
2.39. Prove that there exists a normal basis {.;,a•, ... ,a•·-•} of F�IF ••
over K � IF• with TrF/K(a) �I.
2.40. Let K be a finite field, F � K( a) a finite simple extension of degree
n, and/ E K[x] the minimal polynomial of a over K. Let
f(x) �[J0+fJ,x+ ... +fJ._1x"-1EF[x] and y�f'(a).
x-a
Prove that the dual basis of {l,a, ... ,a"-1} is ({J0y-1,{J1y-1, ••• ,
fJ._,y-').
2.41. Show that there is a self-dual normal basis of F4 over F2, but no
self -dual normal basis of IF 16 over F 2 (see Example 2.31 for the
definition of a self-dual basis).
2.42. Construct a self-dual basis ofF 16 over F2 (see Example 2.31 for the
definition of a self-dual basis).
2.43. Prove that the dual basis of a normal basis of IF •• over IF • is again a
normal basis of F •• over F •.
2.44. Let F be an extension of the finite field K with basis (a1, ••• ,am} over
K. Let {31, ••• ,{Jm E F with {J, � Lj.1bijaj for I .;; i .;; m and bij E K.
Let B be the m X m matrix whose ( i, j) entry is bij. Prove that
tJ.F/K ( {J,, ... ,{Jm) � det( B)'tJ.F/K ( a1, ••• , am).
72 Structure of Finite Fields
2.45. Let K = IF, and F = IF, •. Prove that for a E F we have
( n . I 2 /:,F/K l,a, ... ,am-l)= {a•'-a<)
O.;;i<j�m -1
2.46. Prove that for a E F = F , •. with m;. 2 and K =IF, the discriminant
t,,1K(i,a, ... ,am-l) is equal to the discriminant of the characteris tic
polynomial of a over K.
2.47. Determine the primitive 4th and 8th roots of unity in IF9.
2.48. Determine the primitive 9th roots of unity in F 19•
2.49. Let !: be an nth root of unity over a field K. Prove that I+ I;+
!;2 + · · · + !:"-1 = 0 or n according as !: * 1 or !: = I.
2.50. For n ;. 2 let !;1, ••• , !:, be all the (not necessarily distinct) nth roots of
unity over an arbitrary field K. Prove that 1:; + · · · + 1:: = n for
k = 0 and r; + ... + !:,; = 0 for k = 1. 2, .... n -I.
2.51. For an arbitrary field K and an odd positive integer n, show that
K(2n) = K(n).
2.52. Let K be an arbitrary field. Prove that the cyclotomic field Kldl is a
subfield of K1"' for any positive divisor d of n EN. Determine the
minimal polynomial over K <•l of a root of unity that can serve as a
defining element of K112l over K14l.
2.53. Prove that for p prime the p-I primitive pth roots of unity over Q
are linearly independent over Q and therefore form a basis of O'''
over Q.
2.54. Let K be an arbitrary field and n ;. 2. Prove that the polynomial
xn-l + xn-2 + · · · + x + 1 is irreducible over K only if n is a prime
number.
2.55. Find the least prime p such that x22 + x21 + · · · + x +I is irreduci
ble over F,.
2.56. Find the ten least primes p such that xr' + x•-2 + · · · + x + I IS
irreducible over IF 2.
2.57. Prove the following properties of cyclotomic polynomials over a field
for which the polynomials exist:
(a) Qm,(x) = Qm(x')/Qm(x) if pis prime and mE I'll is not divisi
ble by p;
(b) Qmp(x) = Qm(x') for all mE I'll divisible by the prime p;
(c) Qm,•(x) = Qm,(x''-') if p is a prime and m, kEN are arbi-
trary;
(d) Q2.(x) = Q.(-x) if n;. 3 and n odd;
(e) Q.(O) =I if n;. 2;
(f) Q.(x-• )x•<•l = Q.(x) if n ;. 2;
(g)
Q.(l) = {f if n =I,
if n is a power of the prime p,
if n has at least two distinct prime factors;
E:\cn.:ises
(h) ( 0
-2
Q.(-1}= � if n,;, 2,
if n = 1,
if n is 2 times a power of the prime p,
otherwise. 73
2.58. Give the matrix representation for the elements of F8 using the
irreducible polynomial x3 + x +I over IF2.
2.59. Let I be a primitive element ofF= F 16 with 14 +I+ I= 0. Fork;;, 0
write I' = E�_0a,..,l"' with a,., E IF2, and let M, be the 4 X 4 matrix
whose (i, j) entry is ak+i-l,j-l· Show that the 15 matrices M,,
0" k "14, and the 4 X4 zero matrix form a field (with respect to
addition and matrix multiplication over F2) which is isomorphic to
F. For 0" k "14 prove that TrF(I') =trace of M, =a.,.
Chapter 3
Polynomials over Finite Fields
The theory of polynomials over finite fields is important for investigating
the algebraic structure of finite fields as well as for many applications.
Above all. irreducible polynomi als-the prime elements of the polynomial
ring over a finite field-are indispensable for constructing finite fields and
computing with the elements of a finite field.
Section 1 introduces the notion of the order of a polynomial. An
important fact is the connection between minimal polynomials of primitive
elements (so-called primitive polynomials) and polynomials of the highest
possible order for a given degree. Results about irreducible polynomials
going beyond those discussed in the previous chapters are presented in
Section 2. The next section is devoted to constructive aspects of irreducibil
ity and deals also with the problem of calculating the minimal polynomial
of an element in an extension field.
Certain special types of polynomials are discussed in the last
two sections. Linearized polynomials are singled out by the property that
all the exponents occurring in them are powers of the characteristic. The
remarkable theory of these polynomials enables us. in particular, to give
an alternative proof of the normal basis theorem. Binomials and trinomials
-that is, two-term and three-term polynomials- form another class of
polynomials for which special results of considerable interest can be
established. We remark that another useful collection of polynomials
namely, that of cyclotomic polynomials-was already considered in Chapter
1. Order of Polynomials and Primitive Polynomials 75
2, Section 4, and that some additional information on cyclotomic polynomi
als is contained in Section 2 of the present chapter.
1. ORDER OF POLYNOMIALS AND PRIMITIVE POLYNOMIALS
Besides the degree, there is another important integer attached to a nonzero
polynomial over a finite field, namely its order. The definition of the order
of a polynomial is based on the following result.
3.1. Lemma. Let f E F.[x] be a polynomial of degree m ;.I with
f(O) * 0. Then there exists a positive integer e.;; q'" -I such that f(x) divides
xt' -1.
Proof The residue class ring F .[x ]/(/) contains q'"-I nonzero
residue classes. The q'" residue classes x1 + (/ ), j � 0, I, ... ,q'" -I, are all
nonzero, and so there exist integers rands with 0 .:s;; r < s .:s;; qm-1 such that
x' = x'modf(x). Since x and f(x) are relatively prime, it follows that
x'-'=lmodf(x); thatis,f(x) dividesx'-'-1 andO <s-r.;;q'"-1. 0
Since a nonzero constant polynomial divides x -·I, these polynomi
als can be included in the following definition.
3.2. Definition. Let f E F •[x] be a nonzero polynomial. If f(O)"' 0, then
the least positive integer e for which f( x) divides x' -I is called the order of
f and denoted by ord(/) � ord(f(x )). If /(0) � 0, thenf(x) � x'g(x ), where
h EN and g E F •[x] with g(O)"' 0 are uniquely determined; ord(/) is then
defined to be ord( g).
The order of the polynomial f is sometimes also called the period off
or the exponent of f. The order of an irreducible polynomial f can be
characterized in the following alternative fashion.
3.3. Theorem. Let/ EIF.[x] be an irreducible polynomial over IF• of
degree m and with f(O) * 0. Then ord(/) is equal to the· order of any root off
in the multiplicative group r; ..
Proof According to Corollary 2.15, IFq"' is the splitting field off
over IF •. The roots off have the same order in the group IF;. by Theorem
2.18. Let a E IF;. be any root of f. Then we obtain from Lemma 2.12 that we
have a'� I if and only if f(x) divides x' -I. The result follows now from
the definitions of ord(/) and the order of a in the group IF;.. 0
3.4. Corollary. Iff E IF•[x] is an irreducible polynomial over IF• of
degree m, then ord(/) divides q'" -I.
76 Polynomials over Finite Fields
Proof If f(x) �ex with c E IF;. then ord(/) �I and the result is
trivial. Otherwise, the result follows from Theorem 3.3 and the fact that IF;.
is a group of order q"' -I. 0
For reducible polynomials the result of Corollary 3.4 need not be
valid (see Example 3.10). There is another interpretation of ord(/) based on
associating a square matrix to fin a canonical fashion and considering the
order of this matrix in a certain group of matrices (see Lemma 6.26).
Theorem 3.3 leads to a formula for the number of monic irreduc
ible polynomials of given degree and given order. We use again .P to denote
Euler's function introduced in Theorem l.IS(iv). The following terminology
will be convenient: if n is a positive integer and the integer b is relatively
prime ton, then the least positive integer k for which b'"" I mod n is called
the multiplic ative order of b modulo n.
3.5. Theorem. The number of monic irreducible polynomials in
IFq[x] of degree m and order e is equal to .P(e)jm if e:;, 2 and m is the
multiplicative order of q modulo e, equal to 2 if m � e � I, and equal to 0 in all
other cases. In particular, the degree of an irreducible polynomial in Fq[x] of
order e must be equal to the multiplicative order of q modulo e.
Proof Let f be an irreducible polynomial in IF q[x] with /(0)"' 0.
Then, according to Theorem 3.3, we have ord( f)� e if and only if all roots
off are primitive eth roots of unity over &= q· In other words, we have
ord( f)� e if and only if f divides the cyclotomic polynomial Q_. By
Theorem 2.47(ii), any monic irreducible factor of Q, has the same degree m,
the least positive integer such that qm = I mode, and the number of such
factors is given by .p(e)jm. For m�e�l. we also have to take into
account the monic irreducible polynomial f(x) � x. 0
Values of or d(/) are available in tabulated form, at least for irre
ducible polynomials f (see Chapter 10, Section 2). Since any polynomial of
positive degree can be written as a product of irreducible polynomials, the
computation of orders of polynomials can be achieved if one knows how to
determine the order of a power of an irreducible polynomial and the order
of the product of pairwise relatively prime polynomials, The subsequent
discussion is devoted to these questions.
3.6 Lemma. Let c be a positive integer. Then the polynomial
f E IF 9[x] with /(0) "'0 divides x'-I if and only if ord( /) divides c.
Proof If e � ord(/) divides c. then f(x) divides x' -I and x'-I
divides x' -I, so thatf(x) divides x' -I. Conversely, if /(x) divides x' -I,
we have c � e, so that we can write c =m e+ r with mEN and 0 � r <e.
Since x'-L� (xm• -l)x' +(x' -I), it follows that f(x) divides x' -I,
which is only possible for r � 0. Therefore, e divides c. 0
I. Order of Polynomials and Primitive Polynomials 77
3.7. Corollary. If e1 and e2 are positive integers. then the greatest
common divisor of X .. 1 -I and x"� -I in IFq[x] is xJ -I, where dis the
greatest common divisor of e1 and e'}.
Proof Let /(x) be the (monic) greatest common divisor of x'• - I
and x"1-I. Since xd- I is a common divisor of x"· -I, i = 1,2, it follows
that x• -I divides f(x). On the other hand, /(x) is a common divisor of
x'• -I. i � 1.2. and so Lemma 3.6 implies that ord(/) divides e1 and e2•
Consequently, ord(/) divides d, and hence /(x) divides x d -I by Lemma
3.6. Altogether. we have shown that/(x) � xd -I. D
Since powers of x are factored out in advance when determining the
order of a polynomial. we need not consider powers of the irreducible
polynomials g(x) with g(O) � 0.
3.8. Theorem. Let gE Fq[x] be irreducible over IF• with g(O) "' 0
and ord(g) �e. and let f � g' with a positive integer b. Lett be the smallest
integer with p' � b. where p is the characteris tic ofF •. Then ord(/) � ep'.
Proof Setting c � ord(/) and noting that the divisibility of x'- I
by /(x) implies the divisibility of x'- I by g(x). we obtain that e divides c
by Lemma 3.6. Furthermore. g(x) divides x' -I; therefore, /(x) divides
(x' -I)' and. a fortiori, it divides (x' -J)P' � x'P'-I. Thus according to
Lemma 3.6. c divides ep'. It follows from what we have shown so far that c
is of the form c � ep" with 0..; u..; t.· We note now that x' -I has only
simple roots, since e is not a multiple of p because of Corollary 3.4.
Therefore, all the roots of x•P" -I� (x'-I)P" have multiplicity p". But
g( x )' divides x'P "-I, whence p" � b by comparing multiplicities of roots.
and so u � t. Thus we get u = t and c = ep'. D
3.9. Theorem. Let g1, ••• ,gk. be pairwise relatively prime nonzero
polynomials over F •. and let f� g1 • • • g,. Then ord(/) is equal to the least
common multiple of ord( g1 ) .... ,ord( g, ).
Proof It is easily seen that it suffices to consider the case where
g,(O)"' 0 for I..; i..; k. Set e � ord(/) and e, � ord(g,) for I..; i..; k, and let
c �I em( e 1 ••••• e, ). Then each g;(x ). I ..; i..; k. divides x'•-I, and so g,( x)
divides x'-I. Because of the pairwise relative primality of the polynomials
g1 ..... g,. we obtain that/(x) divides x' -I. An application of Lemma 3.6
shows that e divides c. On the other hand. /(x) divides x' -I, and so each
g;(x). I..; i..; k. divides x' -I. Again by Lemma 3.6. it follows that each e,,
I..; i..; k. divides e. and therefore c divides e. Thus we conclude that e �c.
D
By using the same argumen t as above. one may. in fact. show that
the order of the least common multiple of finitely many nonzero polynomi
als is equal to the least · common multiple of the orders of the polynomials.
78 Polynomials over Finite Fields
3.10. Example. Let us compute the order of f(x)�x10+x9+x3+
x2 +IE IF2[x]. The canonical factorization of f(x) over IF2 is given
by f(x)�(x2+x+l)3(x4+x+l). Since ord(x2+x+l)�3. we get
ord((x2 + x + 1)3) � 12 by Theorem 3.8. Furthermore, ord(x4 + x + 1) � 15_,
and so Theorem 3.9 implies that ord(f) is equal to the least common
multiple of 12 and 15; that is, ord(f) � 60. Note that ord(f) does not
divide 210-I, which shows that Corollary 3.4 need not hold for reducible
polynomials. o
On the basis of the information provided above, one arrives then at
the following general formula for the order of a polynomial. It suffices to
consider polynomials of positive degree and with nonzero constant term.
3.11. Theorem. Let F, be a finite field of characteristic p, and let
f E IF,[x] be a polynomial of positive degree and with /(0) * 0. Let f �
aj,•• · · · jj•, where a E F ,, b1, ••• ,bk E 1'\J, and /1, ... ,fk are distinct monic
irreducible polynomials in F,[x], be the canonical factorization off in F,[x].
Then ord( f) � ep', where e is the least common multiple of ord(/1 ), ••• , ord(/•)
and I is the smallest integer with p' ;;. max( b 1, •.. , b k ).
A method of determining the order of an irreducible polynomial fin
F ,[ x] with /(0) * 0 is based on the observation that the order e off is the
least positive integer such that x' =I modf(x). Furthermore, by Corollary
3.4, e divides qm-I, where m � deg(f). Assuming qm > 2, we start from the
prime factor decomposition
'
qm-1 = n p)'.
j�l
For l .;; j.;;s we calculate the residues of x<•"-ll!P,modf(x). This is
accomplished by multiplying together a suitable combination of the residues
of x, x•, x•', ... ,x•··-• mod f(x). If x<•"-ll!PJ ;�;I modf(x), then e is a mul
tiple of p;. If x<•"'-I)/P; = I mod f(x), then e is not a multiple of P? In the
latter case we check to see whether e is a multiple of pp-1, pp-2, ..• ,p1 by
calculating the residues of
x(q"' -l)/P}, x(q"'-l)/p}, ... , x<q"'-1l/Pjl mod f( x ).
This computation is repeated for each prime factor of qm -I.
A key step in the method above is the factorization of the integer
qm -1. There exist extensive tables for the complete factorization of num
bers of this form, especially for the case q � 2.
We compare now the orders of polynomials obtained from each
other by simple algebraic transformations. The following is a typical exam
ple.
3.12. Definition. Let
f(x)=a11x11+a,_1x11-1+ ··· +a1x+a0E1Fq[x]
1. Order of Polynomials and Primitive Polynomials
with a,"' 0. Then the reciprocal polynomial f* off is defined by
f*(x)�x"f(�)�a0x"+a1x"-1+ ··· +a,_1x+a,.. 79
3.13. Theorem. Lee f be a nonzero polynomial in F,[x] and/* irs
reciprocal polynomial. Then ord(/) � ord(/*).
Proof First consider the case /(0) "' 0. Then the result follows from
the fact that f(x) divides x'- I if and only if /*(x) does. If /(0) � 0, write
/( x) � x'g( x) with h E I'll and g E F ,[x] satisfying g(O)"' 0. Then from what
we have already shown it follows that ord(/) � ord(g) � ord(g*) � ord(/*),
where the last identity is valid since g* � f*. D
There is also a close relationship between the orders of/( x) and
/(-x). Since f(x) � /(-x) for a field of characteristic 2, it suffices to
consider finite fields of odd characteri stic.
3.14. Theorem. For odd q. lee f E IF,[x] be a polynomial of positive
degree wich /(0)"' 0. Lee e and E be che orders of f(x) and /(-x),
respectively. Then E � e if e is a multiple of 4 and E � 2e if e is odd. If e is
twice an odd number, chen E � e /2 if all irreducible factors off have even
order and E = e otherwise.
Proof Since ord(/(x))�e, j(x) divides x2'-1, and so /(-x)
divides (-x )2'-I � x2'-1. Thus E divides 2e by Lemma 3.6. By the same
argument, e divides 2£, and so E can only be 2e, e, or e/2. If e is a
multiple of 4, then both e and E are even. Since f(x) divides x' -1,/(-x)
divides (-x)' -1 � x'-I, and so E divides e. Similarly, e divides E, and
thus it follows that E �e. If e is odd, then/(-x) divides (-x)' -1 �-x'
-I and so x' + 1. But then /(-x) cannot divide x' -1, and so we must
have E � 2e.
In the remaining case we have e � 2h with an odd integer h. Let f
be a power of an irreducible polynomial in f,[x]. Then f(x) divides
(x' -lXx' + 1) and /(x) does not divide x ' -1 since ord(/) � 2h. But
x' -1 and x' + 1 are relatively prime, and this implies that j(x) divides
x' +I. Conseque ntly,/(-x) divides (-x)' +I�-x' +I and sox'-I. It
follows that E � e /2. Note that by Theorem 3.8 the power of an irreducible
polynomial has even order if and only if the irreducible polynomial itself
has even order.
For general f we have a factorization f � g 1 • • ·g., where each g, is a
power of an irreducible polynomial and g1, ... ,gk are pairwise relatively
prime. Furthermore, 2h � lcm(ord(g1 ), ... ,ord(gk)) according to Theorem
3.9. We arrange the g, in such a way that ord(g,) � 2h, for I.;; i.;; m and
ord( g,) � h, for m + 1 .;; i.;; k, where the h, are odd integers with lcm( h 1, ... ,
hk)�h. By what we have already shown, we get ord(g,(-x))�h, for
1.;; i.;; m and ord(g,(-x)) = 2h, form+ I.;; i.;; k. Then Theorem 3.9 yields
E � lcm(h,, ... ,h_,2h_.,, ... ,2h,),
Polynomials over Finite Fields
and so E�h�e /2 if m�k and E�2h�e if m<k. These formulas are
equivalent to those given in the last part of the theorem. D
It follows from Lemma 3.1 and Definition 3.2 that the order of a
polynomial of degree m � I over IF q is at most q"1-I. This bound is attained
for an important class of polynomials-namely, so-called primitive poly
nomials. The definition of a primitive polynomial is based on the notion of
primitive element introduced in Definition 2.9.
3.15. Definition. A polynomial f E IF ,[x] of degree m;;, I is called a
primitive polynomial over F q if it is the minimal polynomial over IF q of a
primitive element of IF q'"·
Thus. a primitive polynomial over F, of degree m may be described
as a monic polynomial that is irreducible over F q and has a root a E IF q"' that
generates the multiplicative group ofF, •. Primitive polynomials can also be
characterized as follows.
3.16. Theorem. A polynomial f EIF,[x] of degree m is a primitive
polynomial over IF,1 if and only iff is monic, f(O)"' 0, and ord(/) � qm-I.
Proof Iff is primitive over IF q• then f is monic and /(0)"' 0. Since f
is irreducible over F q• we get ord( f)� qm-I from Theorem 3.3 and the
fact that f has a primitive element of IF,. as a root.
Conversely, the property ord( f)� qm-I implies that m;;, I. Next,
we claim that f is irreducible over IF,. Suppose f were reducible over IF q·
Then f is either a power of an irreducible polynomial or it can be written as
a product of two relatively prime polynomials of positive degree. In the first
case, we have[� g' with g E Fq[x] irreducible over F,. g(O)"' 0, and b;;, 2.
Then, according to Theorem 3.8, ord( f) is divisible by the characteristic of
IF q• but qm - I is not, a contradiction. In the second case, we have f = g1 g2
with relatively prime monic polynomials g1, g2 E IF q[x] of positive degree m1
and m2, respectively. If e,�ord(g,) for i�I.2, then ord(f)..;;e1e2 by
Theorem 3.9. Furthermore. ei � q'"' -I fori= 1,2 by Lemma 3.1, hence
ord(f)" (qm• -l)(qm' -I)< qm,+m, -I� qm -I,
a contradiction. Therefore, f is irreducible over IF q• and it follows then from
Theorem 3.3 that/is a primitive polynomial over F,. D
We remark that the condition f(O)"' 0 in the theorem above is only
needed to rule out the non-primitive polynomial f(x) � x in case q � 2 and
m = I. Still another characterization of primitive polynomials is based on
the following auxiliary result.
3.17. Lemma. Let f E IF q[x] be a polynomial of positive degree with
/(0)"' 0. Let r he the least positive integer for which x' is congruent mod f( x)
tv some element ofF,. so that x' = amodf(x) with a uniquely determined
1. Order of Polynomials and Primitive Polynomials 81
a E F;. Then ord(/) =hr. where his the order of a in the multiplicative group
IF*
q.
Proof Put e = ord(/). Since x' =I modf(x), we must have e;. r.
Thus we can write e = sr + 1 with s EN and 0 � t < r. Now
( 3 .I)
thus x' = a-'modf(x), and because of the definition of r this is only
possible if t = 0. The congruence (3.1) yields then a'= I modf(x), thus
a'= I, and so s;. h and e;. hr. On the other hand, x•' = a• =I mod f(x),
and so e =hr. D
3.18. Theorem. The monic polynomial f E F,[x] of degree m ;.I is
a primitive polynomial over IF, if and only if( -1)"'/(0) is a primitive element
of IF, and the least positive integer r for which x' is congruent modf(x) to
some element of IF, is r= (qm -1)/(q -I). In case /is primitive over F,. we
have x' = ( -l)m/(O)modf(x).
Proof Iff is primitive over F ,. then f has a root a E IF, •• which is a
primitive element of IF, •. By calculating the norm NF,.;F,(a) both by
Definition 2.27 and by (2.3) and observing that f is the character istic
polynomial of a over IF,. we arrive at the identity
( -l)m /(0) = a'•"-1)/(q-1)_ (3.2)
It follows that the order of ( -l)m/(0) in F; is q -);that is, ( -l)m/(0) is a
primitive element of F ,. Since f is the minimal polynomial of a over IF,. the
identity (3.2) implies that
x<•"-l)/(q-l) = (-I )m /(0) mod /(x ),
and so r .;;(qm-i)j(q-1). But Theorem 3.16 and Lemma 3.17 yield
qm -I= ord(/).;; (q -i)r, thus r = (qm -i)j(q -I).
Conversely, suppose the conditions of the theorem are satisfied. It
follows from r = (qm -1)/(q -I) and Lemma 3.17 that ord(/) is relatively
prime to q. Then Theorem 3.11 shows that f has a factorization of the form
f = /1 • • ·f., where the/, are distinct monic irreducible polynomials over IF,.
If m, � deg(/;), then ord(/,) divides qm, -I for ! .;; i.;; k according to
Corollary 3.4. Now qm,-I divides
d = ( qm' -I) .. · ( qm' -J )/ ( q-J) k-1,
thus ord(/1) divides d for 1 .;; i.;; k. It follows from Lemma 3.6 that /,(x)
divides x" -I for 1 .;; i.;; k, and so f(x) divides x'-!."If k;. 2, then
a contradiction to the definition of r. Thus k =I andfis irreducible over IF,.
82 Polynomials over Finite Field!>
If {3 E F •• is a root of f. then the argument leading to (3.2) shows that
{3'�(-1)"'/(0), and so x'=(-1)"'/(0)mod/(x). Since the order of
(-1)"'/(0) in!'; is q -1, it follows from Lemma 3.17 that ord(/) � q"' -1,
so that/is primitive over F• by Theorem 3.16. D
3.19. Example. Consider the polynomial /(x)�x4+x3+x2+2x+2E
F 3 [ x ]. Since f is irreducible over F 3, one can use the method outlined after
Theorem 3.11 to show that ord( /) � 80 � 34 - 1. Consequently, f is primi
tive over IF3 by Theorem 3.16. We have x40 = 2modf(x) in accordance with
Theorem 3.18. D
2. IRREDUCIBLE POLYNOMIALS
We recall that a polynomial f E F •[x] is irreducible over IF q iff has positive
degree and every factorization of f in IF.(x] must involve a constant
polynomial (see Definition 1.57). Elementary properties of irreducible poly
nomials over F q were discussed in Chapter 2, Section 2.
3.20. Theorem For every finite field IF• and every n E I'll, the prod
uct of all monic irreducible polynomials over F q whose degrees divide n is equal
to xq"-x.
Proof According to Lemma 2.13, the monic irreducible polynomi
als over F q occurring in the canonical factorization of g( x) = xq"- x in
IF•[x] are precisely,those whose degrees divide n, Since g'(x) � -1, Theo
rem 1.68 implies that g has no multiple roots in its splitting field over F , q '
and so each monic irreducible polynom!al over F q whose degree divides n
occurs exactly once in the canonical factorization of gin Fq[x], D
3.21. CoroiJJJry. If N•( d) is the number of monic irreducible poly
nomials in F.[x] of degree d, then
q"� '[,dN.(d) fora/In EN, (33)
din
where the sum is extended over all positive divisors d of n.
Proof The identity (33) follows from Theorem 3,20 by comparing
the degree of g(x) � x•"-x with the total degree of the canonical factoriza
tion ofg(x), D
With a little elementary number theory we can derive from (33) an
explicit formula for the number of monic irreducible polynomials in F.[x]
of fixed degree, We need an arithmetic function, called the Moebius
function, which is defined as follows.
2. Irreducible Polynomials 83
3.22. Definition. The Moebius function p. is the function on I'll defined by
ifn=l,
if 11 is the product of k distinct primes,
if 11 is divisible by the square of a prime.
As in (3.3), we use the summation symbol L:Jin to denote a sum
extended over all positive divisors d of 11 E 1'\1. A similar convention applies
to the product symbol ndi•'
3.23. Lemmo. For 11 E I'll the Moebius function p. satisfies
ifn=!,
ifn >I.
Proof For 11 > I we have to take into account only those positive
divisors d of 11 for which p.(d) * 0-that is, for which d =I or dis a product
of distinct primes. Thus, if p1, p2, ... ,p, are the distinct prime divisors of n,
we get
k
I;p.(d)=p.(ll+ I: p.(p,)+ I: p.(p,,p,,l+ ··· +p.(p,p,···p.J
dl• i-1 l<;i\<i1"k
=1+(7)<-ll+(;)<-Jl'+ ... +(Z)<-1)'
=(1+(-!))'=0.
The case n = I is trivial. D
3.24. Theo,..m (Moebius Inversion Formula)
(i) Additive case: Let h and H be two functions from I'll into an
additively written abelian group G. Then H( n) = L h (d) for a/In E I'll (3 .4)
din
if and only if
h(n)= LP.(�)H(d)= LP.(d)H(�) fora//nEi'\1. (3.5)
din din
(ii) Multiplicative case: Let h and H be two functions from I'll into a
multiplicativel y written abelian group G. Then H(n) = 0h(d) fora/In El'll (3.6)
din
foral/nEN. (3.7)
84 Polynomials over Finite Fields
Proof Assuming (3.4) and using Lemma 3.23, we get
LI'(�)H(d)= Ll'(d)H(�)= Ll'(d) L h(c)
dfn dill dfn cfn/d
= L L !'(d)h(c) = Lh(c) L !'(d)= h(n)
cfn dln/c dln/c
for all n E 1\1. The converse is derived by a similar calculation. The proof of
part (ii) follows immediately from the proof of part (i) if we replace the
sums by products and the multiples by powers. D
3. 25. Theorem. The number N, ( n ) of monic irreducible polynomials
in F q[ x] of degree n is given by
N,(n) =.!. L I'(�) q" =.!. L !'(d) q•ld. n din d n din
Proof We apply the additive case of the Moebius inversion formula
to the group G = l, the additive group of integers. Let h(n) = nN,(n) and
H(n) = q" for all n E 1\1. Then (3.4) is satisfied because of the identity (3.3),
and so (3.5) already gives the desired formula. D
3.26. Example. The number of monic irreducible polynomials in F,[x] of
degree 20 is given by
N,(20) = fo(!'(l)q20 + !'(2)q10 + !'(4)q5 + !'(5)q4 + !'(IO)q2 + !'(20)q)
D
It should be noted that the formula in Theorem 3.25 shows again
that for every finite field IF • and every n E 1\1 there exists an irreducible
polynomial in IF,[x] of degree n (compare with Corollary 2.11). Namely,
using I' (I)= I and !'(d);. -I for all dE 1\1, a crude estimate yields
N(n);..!.(q•-q•-l-qn-2_ ... -q)=.!.(q•-q"-q) >0. • n n q-1
As another application of the Moebius inversion formula, we estab
lish an explicit formula for the nth cyclotomic polynomial Q •.
3.27. Theorem. For a field K of characteristic p and n E 1\1 not
divisible by p, the nth cyclotomic polynomial Q. over K satisfies
Q.(x)= O(x"-1)"'"1"1= O(x•l"-1)"'"1
dfn din
Proof We apply the multiplicative case of the Moebius inversion
formula to the multiplicative group G of nonzero rational functions over K.
Let h(n) = Q.(x) and H(n) = x" -I for all n E 1\1. Then Theorem 2.45(i)
shows that (3.6) is satisfied, and so (3.7) yields the desired result. D
2. Irreducible Polynomials
3.28. Example. For fields Kover which Q12 is defined, we have
Qn(x) = n (x"fd -I)"(di
d\ 12
= (x12 -1)"('1(x6 -1)"(2\x4 -1)"(31(x3 -1)"(41
(x2 -1)"('\x -1)"(121
(x12 -l)(x2 -1) = = x4- x2 +I. (x' -l)(x4 -I) 85
D
The explicit formula in Theorem 3.27 can be used to establish the
basic properties of cyclotomic polynomials (compare with Exercise 3.35).
In Theorem 3.25 we determined the number of monic irreducible
polynomials in F.[xl of fixed degree. We present now a formula for the
product of all monic irreducible polynomials in F .[xI of fixed degree.
3.29. Theorem. The product /( q, n; x) of all monic irreducible poly
nomials in F.[xl of degree n is given by
I(q. n; x) = n (x•'-x)"(n/dl = n (x•""-x)"(dl
din din
Proof It follows from Theorem 3.20 that
x•"-x= nl(q,d;x).
din '
We apply the multiplicative case of the Moebius ;�version formula to the
multiplicative group G of nonzero rational functions over F •• putting
h(n)=I(q,n;x) and H(n)=x•"-x for all nEN, and we obtain the
desired formula. D
3.30. Example. For q = 2, n = 4 we get
/(2,4; X)= (x16-X )"(l)(x4-X )"(2\x2-X )"(4)
x16- x x15-I ---
x4-x x3 -I
= xl2 + x9 + x6 + xJ +I. D
All monic irreducible polynomials in IF • [xI of degree n can be
determined by factoring I(q, n; x). For this purpose it is advantageous to
have /( q, n; x) available in a partially factored form. This is achieved by the
following result.
3.31. Theorem. Let I(q, n;x) be as in Theorem 3.29. Then for n >I
we have
I(q, n; x) = TI Qm(x), (3.8)
m
86 Polynomials over Finite Fields
where the product is extended over all positive divisors m of q• -I for which n
is the multiplicative order of q modulo m, and where Qm(x) is the mth
cyclotomic polynomial over F q·
Proof For n >I let S be the set of elements of F q" that are of
degree n over F q· Then every a E S has a minimal polynomial over IF q of
degree n and is thus a root of J(q, n; x). On the other hand, if {J is a root
of J(q, n; x), then {J is a root of some monic irreducible polynomial in IF•[x]
of degree n, which implies that {J E S. Therefore,
I(q,n;x) � 0 (x-a).
aES
If a E S, then a E IF;., and so the order of a in that multiplicative group is a
divisor of q"-I. We note that y E F;. is an element of a proper subfield F •"
of F•" if and only if y•'� y-that is, if and only if the order of y divides
qd-I. Thus, the order m of an element a of S must be such that n is the
least positive integer with q• =I mod m -that is, such that n is the multi
plicative order of q modulo m. For a positive divisor m of q•-I with this
property, lets., be the set of elements of S of order m. Then Sis the disjoint
union of the subsets sm. so that we can write
I(q,n;x)�O 0 (x-a). m aESm
Now Sm contains exactly all elements of r; .. of order m. In other words, Sm
is the set of primitive mth roots of unity over F q· From the definition of
cyclotomic polynomials (see Definition 2.44), it follows that
n (x-a)�Qm(x),
aES,..
and so (3.8) is established. D
3.32. Example. We determine all (monic) irreducible polynomials in
F2[x] of degree 4. The identity (3.8) yields /(2,4; x) � Q1(x)Q11(x) . By
Theorem 2.47(ii), Q,(x) � x4 + x' + x2 + x +I is irreducible in F2[x]. By
the same theorem, Q11(x) factors into two irreducible polynomials in F2[x]
of degree 4. Since Q1(x+l)�x4+x3+1 is irreducible in IF2[x], this
polynomial must divide Q11(x), and so
Q11(x) �x8+ x1+ x' + x4 + x3 + x+ I= (x4 + x3 + l)(x4 + x+ 1).
Therefore, the irreducible polynomials in IF2[x] of degree 4 are x4 + x' + x2
+x+l,x4+x3+l,andx4+x+l. D
Irreducible polynomials often arise as minimal polynomials of ele
ments of an extension field. Minimal polynomials were introduced in
Definition 1.81 and their fundamental properties established in Theorem
1.82. With special reference to finite fields, we summarize now the most
useful facts about minimal polynomials.
3. Construction of lrreduci�le Polynomi als 87
3.33. Theorem. Let a be an element of the extension field F q• of IF q·
Suppose that the degree of a over !' • is d and that g E F •[ x] is the minimal
polynomial of a over IF q· Then:
(i) g is irreducible over IF • and its degree d divides m.
(ii) A polynomial f E F q[x] satisfies/( a)= 0 if and only if g divides
f.
(iii) Iff is a monic irreducible polynomial in IF•[x] with f(a) = 0,
thenf =g.
(iv) g(x) divides x•'-x and x•"-x.
(v) The roots of g are a,a•, ... ,a•'-', and g is the minimal poly
nomial over IF• of all these elements.
(vi) If a"' 0, then ord(g) is equal to the order of a in the multiplica
tive group F: ....
(vii) g is a primitive polynomial over F • if and only if a is of order
d I . F* q - m q"'·
Proof (i) The first part follows from Theorem 1.82(i) and the
second part from Theorem 1.86.
(ii) This follows from Theorem 1.82(ii).
(iii) This is an immediate consequence of (ii).
(iv) This follows from (i) and Lemma 2.13.
(v) The first part follows from (i) and Theorem 2.14 and the second
part from (iii).
(vi) Since aE F;, and F;, is a subgroup of F; •. the result is
contained in Theorem 3.3.
(vii) If g is primitive over F •• then ord( g) = qd -I, and so a is of
order qd-I in F ;. because of (vi). Conversely, if a is of order qd-I in F;.
and so in F;c�, then a is a primitive element of F qJ, and therefore g is
primitive over F • by Definition 3.15. D
3. CONSTRUCllON OF IRREDUCIBLE POLYNOMIALS
We first describe a general principle of obtaining new irreducible polynomi
als from known ones. It depends on an auxiliary result from number theory.
We recall that if n is a positive integer and the integer b is relatively prime to
n, then the least positive integer k for which b• = I mod n is called the
multiplicative order of b modulo n. We note that this multiplicative order
divides any other positive integer h for which b' =I mod n.
3.34. Lemma_ Let s;;. 2 and e;;. 2 be relatively prime integers and
let m be the multiplicative order of s modulo e. Let 1;;. 2 be an integer whose
prime factors divide e but not (sm-l)je. Assume also that sm =I mod4 if
I= 0 mod4. Then the multiplicative order of s modulo et is equal to mt.
88 Polynomials over Finite Fields
Proof We proceed by induction on the number of prime factors of
t, each counted with its multiplicity. First, lett be a prime number. Writing
d = (sm -l)je, we have sm =I+ de, and so
sm' =(I+ de)'
=l+(:)de+(�)d2e2+ ... +(,�1)d'-1e'-1+d'e'.
In the last expression, each term except the first and the last is divisible by
et because of a property of binomial coefficients noted in the proof of
Theorem 1.46. Furthermore, the last term is divisible by et since t divides e.
Therefore, sm' =I mod et, and so the multiplicative order k of s modulo et
divides mi. Also, s• = I mod et implies s• =I mode, and so k is divisible by
m. Since I is a prime number, k can only be m or mi. If k = m, then
sm =I mod et, hence de= Omod et and I divides d, a contradiction. Thus we
must have k = mt.
Now suppose that I has at least two prime factors and write I= rt0,
where r is a prime factor of I. By what we have already shown, the
multiplicative order of s modulo er is equal to mr. If we can prove that each
prime factor of 10 divides er but not d0 = (sm' -l)jer, then the induction
hypothesis applied to 10 yields that the multiplicative order of s modulo
ert0 = et is equal to mrt0 = mt. Let r0 be a prime factor of 10• Since every
prime factor of t divides e, it is trivial that r0 divides er. We write again
d = (sm-I)/e. We havesm'-I= c(sm -I) with c = sm(,-ll + · · · + sm +I,
thus d0 = c(sm -l)jer = cdjr. Furthermore, since sm =I mode and r
divides e, we get sm=Imodr, and so c=r=Omodr. Thus cjr is an
integer. Since r0 does not divided, it suffices to demonstrate that r0 does not
divide cj r in order to prove that r0 does not divide d0 = cd j r. We note that
sm=Imodr0, and so c=rmodr0• If r0*r, then cjr=lmodr0, thus r0
does not divide cjr. Now let r0=r. Then sm=I+brmodr2 for some
bE Z, hence sm; = (I + br); =I + jbrmod r2 for all j:;. 0, and thus
It follows that ,_, r(r-1) c=r+brL,J=r+br modr2
j-0 2
c r(r-I) -=l+b modr r 2 ·
If r is odd, then cjr =I mod r, so that r0 = r does not divide cjr. In the
remaining case we have r0 = r = 2. Then t = Omod4, and so sm =I mod4 by
hypothesis. Since c=sm +I in this case, we get c= 2mod4, and thus
c I r = c j2 = I mod 2. It follows again that r0 does not divide c j r. D
3.35. Theorem. Let f1 ( x ), /2 ( x ), ... ,f N ( x) be all the distinct monic
irreducible polynomials in IF•[x] of degree m and order e, and lett:;. 2 be an
3. Construction or Irreducible Polynomials 89
integer whose prime factors divide e but not (qm-I)/e. Assume also that
qm = lmod4 ift = Omod4. Thenf1(x')./2(x'), ... JN(x') are all the distinct
monic irreducible polynomials in f•[x] of degree mt and order et.
Proof The condition one implies e;;. 2. According to Theorem 3.5,
monic irreducible polynomials in F•[x] of degree m and order e;;. 2 exist
only if m is the multiplicative order of q modulo e, and then N� cj>(e)/m.
By Lemma 3.34, the multiplicative order of q modulo et is equal to mt, and
since cj>(el)/ml � cj>(e)/m by the formula in Exercise 1.4, part (c), it follows
that the number of monic irreducible polynomials in IF q[ x] of degree ml and
order et is also equal to N. Therefore, it remains to show that each of the
polynomials f;(x'), IE; j E; N, is irreducible in F q[x] and of order et.· Since
the roots of each /;(x) are primitive e th roots of unity over F • by Theorem
3.3, it follows that /;(x) divides the cyclotomic polynomial Q,(x) over f •.
Then /;(x') divides Q,(x'), and repeated use of the property enunciated in
Exercise 2.57, part (b), shows that Q,(x') � Q.,(x). Thus /;(x') divides
Q,.(x). According to Theorem 2.47(ii), the degree of each irreducible factor
of Q.,(x) in f•[x] is equal to the multiplicative order of q modulo et, which
is mi. Since /;(x') has degree ml, it follows thatf;-(x') is irreducible in IF q[x].
Furthermore, since /;-(x') divides Q.,(x ), the order of /;(x') is et. 0
3.36. Example. The irreducible polynomials in F2[x] of degree 4 and
order 15 are x4 + x +I and x4 + x3 +I. Then the irreducible polynomials in
F2[x] of degree 12 and order 45 are x12 + x3 +I and x12 + x9 +I. The
irreducible polynomials in F2[x] of degree 60 and order 225 are x60 + x" +I
and x60 + x45 +I. The irreducible polynomials in F2[x] of degree 100 and
order 375 are x"10 + x2' +I and x"10 + x 75 +I. 0
The case in which t = Omod4 and qm = -lmod4 is not covered in
Theorem 3.35. Here we must have q =-I mod4 and m odd. The result
referring to this case is somewhat more complicated than Theorem 3.35.
3.37. Theorem. Let f1(x), f2(x), ... JN(x) be all the distinct monic
irreducible polynomiaLs in F•[x] of odd degree m and of order e. Let q =
2"u-I, t � 2•v with a, b;;. 2, where u and v are odd and all prime factors oft
divide e but not (qm-I)/e. Let k be the smaller of a and b. Then each of the
polynomials f;(x') factors as a product of 2•-• monic irreducible polynomiaLs
giJ(x) in F•[x] of degree mt2•-•. The 2•-•N polynomials giJ(x) are all the
distinct monic irreducible polynomials in F q[ x] of degree ml21 -k and order et.
Proof If v;;. 3, then Theorem 3.35 implies thatf1(x"), f2(x"), ... ,
fN(x") are all the distinct monic irreducible polynomials in F•[x] of odd
degree mv and of order ev. Thus we will be done once the special case I� 2•
is settled.
Let now t � 2•, and note that as in the proof of Theorem 3.35 we
obtain that m is the multiplicative order of q modulo e, N � cj>( e)/ m, and
90 Polynomials over Finite Fields
eachfj(x') divides Q.,(x). By Theorem 2.47(ii), Q.,(x) factors into distinct
monic irreducible polynomials in F•[x] of degree d, where dis the multi
plicative order of q modulo el. Since q• =I model, we have q• = I mode,
and so m divides d. Consider first the case a;;. b. Then q2m -I=
(qm -l)(qm +I), and the first factor is divisible bye, whereas the second
factor is divisible by I since q = -I mod2" implies q = -I mod I, and thus
qm = ( -l)m"' -I modi. Altogether, we get q2m =I model, and so d can
only be m or 2m. If d = m, then qm =I model, hence qm =I mod I, a
contradiction. Thus d =2m= m2•-• + 1 since k = b in this case.
Now consider the case a< b. We prove by induction on h that
qm2" = 1 +.w2a+hmod2a+h+ 1 for all hEN,
where w is odd. For h =I we get
q'm = (2"u -l)'m (3.9)
2m
=1-2"+1um+ L (2,7')(-1)2m-•2""u"=l+w2"+1mod2"+2
o�2
with w = -um. If (3.9) is shown for some h EN, then
qm2" = 1 + w2a+h + c2a+h+ 1 for some c E Z.
It follows that
and so the proof of (3.9) is complete. Applying (3.9) with h = b-a+ I, we
get qm2h-HI = 1 mod2b+ 1. Furthermore, qm = 1 mode implies qm2b-a+, =
I mode, and so qm2•--.' = I mod L, where L is the least common multiple of
2•+ 1 and e. Now e is even since all prime factors of 1 divide e, but also
e $ Omod4 since qm =I mode and qm =-I mod4. Therefore, L = e2• = el,
and thus qm2'-•" =I model. On the other hand, using (3.9) with h = b-a
we get
qm2o-. =I+ w2• ;t; I mod2b+ 1,
which implies qm2•-· *I model. Consequently, we must have d = m2•-• + 1
-m2•->+ 1 since k =a in this case. Therefore, the formula d = m2•->+ 1 =
ml 21 -• is valid in both cases.
Since Q.,(x) factors into distinct monic irreducible polynomials in
F•[x] of degree ml21-•, each Jj(x') factors into such polynomials. By
comparing degrees, the number of factors is found to be 2• -I Since each
irreducible factor g1;(x) off,(x') divides Q.,(x), each g,)x) is of order el.
The various polynomials g1;(x), I<; i.;; 2•-1, I<; j.; N, are distinct, for
otherwise one such polynomial, say g(x), would dividefj,(x') andfj,(x') for
}1 * }2, and then any root P of g(x) would lead to a common root P' of
Jj,(x) and Jj,(x), a contradiction. By Theorem 3.5, the number of monic
3. Construction of Irreducible Polynomials
irreducible polynomials in IF •[ x 1 of degree mt21-•
.p(et)/mt2'.-• = 2•-•.p(et)/mt = 2•-•.p(e)/m = 2•-•N,
yield all such polynomials. 91
and order et is
and so the g,1(x)
D
We will show how, from a given irreducible polynomial of order e,
all the irreducible polynomials whose orders divide e may be obtained. Since
in all cases g(x) = x will be among the latter polynomials, we only consider
polynomials g with g(O) * 0. Let f be a monic irreducible polynomial in
IF •[ x 1 of degree m and order e and with f(O),. 0. Let a E F •• be a root off,
and for every IE N let g, E IF•[x1 be the minimal polynomial of a' over F •.
Let T=(t,.t2, ••• ,t.) be a set of positive integers such that for each tEN
there exists a uniquely determined i, '"' i"' n, with t = t,q•mod e for some
integer b ;lo 0. Such a set T can, for instance, be constructed as follows. Put
11 =I and, when 11,12, ... ,11_; have been constructed, let t1 be the least
positive integer such that t1 ;;E t,q•mode for 1,. i < j and all integers b ;lo 0.
This procedure stops after fmitely many steps.
With the notation introduced above, we have then the following
general result.
3.38. Theorem. The polynomials g,,, g,,, ... ,g," are all the distinct
monic irreducible polynomials in F•[x1 whose orders divide e and whose
constant terms are nonzero.
Proof Each g,, is monic and irreducible in IF•[x1 by definition and
satisfies g, (0) * 0. Furthermore, since g, has the root a'• whose order in the
group F;.'divides the order of a, it follows from Theorem 3.3 that ord(g,,)
divides e.
Let g be an arbitrary monic irreducible polynomial in F .[x1 of order
d dividing e and with g(O) * 0. If Pis a root of g, then pd =I implies P' -1,
and so P is aneth root of unity over F •. Since a is a primitive eth root of
unity over f •• it follows from Theorem 2.42(i) that P =a' for some tEN.
Then the definition of the set T implies that I"' t,q•mode for some i,
'"' i"' n, and some b ;lo 0. Hence p =a'-(a'•)•', and so P is a root of g,
because of Theorem 2.14. Since g is the minimal polynomial of p over F •' ii
follows from Theorem 3.33(iii) that g = g,,.
It remains to show that the polynomials g,, '"' i"' n, are distinct.
Suppose g,, = g, for i * j. Then a'• and a'' ar� roots of g, , and so
a''= ( a'•)•' for �me b ;lo 0. This implies 11 = t,q•mod e, but sin.;. we also
have t1 = t1q0mode, we obtain a contradiction to the definition of the set T.
D
The minimal polynomial g, of a' E F •• over IF • is usually calculated
by means of the characteristic polynomial !, of a' E F •• over F •. From the
discussion following Definition 2.22 we know that !, = g;, where r = m / k
and k is the degree of g,. Since g, is irreducible in F q[x], k is the
multiplicative order of q modulo d = ord(g,), and dis equal to the order of
92 Polynomials over Finite Fields
a' in the group IF; •• which is ejgcd(t,e) by Theorem 1.15(ii). Therefore d,
and so k and r, can be determined easily.
Several methods are known for calculating /,. One of them is based
on a useful relationship between!, and the given polynomial f.
3.39. Theorem. Let f be a monic irreducible polynomial in F•[x] of
degree m. Let a E F •" be a root off, and /or IE N let/, be the characteristic
polynomial of a' E IF q" over F •. Then
' /,(x') = ( -\)m(<+ I) n /( WjX ),
J-1
where w 1, ••• , w, are the t th roots of unity over IF q counted according to
multiplicity.
Proof Let a= a1, a2, ••. ,am be all the roots off. Then a�, a�, ... ,a�
are the roots of/, counted according to multiplicity. Thus
"'
/,(x') = n (x' -,a:) i-1
"'
= n n (x-a,wj) i-! J-!
"' '
= n n "'A"'1�'x-a,). i-lj-1
A comparison of coefficients in the identity
' x'-1= n (x-w) J-l
shows that
and so I
Ow1=(-1)'+1, j-l
I m f,(x') = ( -l)m(<+l) n n (..,}�IX-a,) j-! i-1
I < = ( -\)m(<+l) n /( Wj�IX) = ( -\)m(<+l) n f(w1x) J-! j-l
since w 1', ... , w,� 1 run exactly through alii th roots of unity over IF q· D
3.40. Example. Consider the irreducible polynomial f(x) = x4 + x +I in
F2[x ]. To calculate /3, we note that the third roots of unity over F2 are I, w,
3. Construction of Irreducible Polynomials
and w2, where w is a root of x2 + x+ I in F4• Then
/3 (x3) = ( -1)16/(x )/( wx )/( w2x)
= (x4 + x + 1)( wx4 + wx + 1)( w2x4 + w2x +I)
=x12+x9+x6+x3+1,
so thatf3(x) = x4 + x3 + x2 + x +I. 93
D
Another method of calculating /, is based on matrix theory. Let
f(x)=xm-am-lxm-l_ ··· -a1x-a0andletA be the companion matrix
off, which is defined to be the m X m matrix
0 0
0
A= 0
0 0 0
0
0
Then f is the characteristic polynomial of A in the sense of linear algebra;
that is, f(x) = det(x/-A) with I being the m X m identity matrix over F q·
For each tEN,/, is the characteristic polynomial of A', the tth power of A.
Thus, by calculating the powers of A one obtains the polynomials f..
3.41. Example. It is of interest to determine which polynomials /, are
irreducible in IF•[x1. From the discussion prior to Theorem 3.39 it follows
immediately that/, is irreducible in F .[x 1 if and only if k = m, that is, if and
only if m is the multiplicative order of q modulo d = ejgcd(t, e). Consider,
for instance, the case q = 2, m = 6, e = 63. Since the multiplicative order of q
modulo a divisor of e must be a divisor of m, the only possibilities for the
multiplicative order apart from m are k =I, 2, 3. Then q•-I= I, 3, 7, and
q•=imodd is only possible when d=l,3,7. Thus/, is reducible in IF2[x1
precisely if gcd(l, 63) = 9, 21, 63. Since it suffices to consider values oft with
I.; t.; 63, it follows that /, is irreducible in IF2[x 1 except when I=
9, 18,21,27,36,42,45, 54,63. D
In practice, irreducible polynomials often arise as minimal polynomi
als of elements in an extension field. If in the discussion above we let f be a
primitive polynomial over F q• so that e = qm -I, then the powers of a run
through all nonzero elements of F ••. Therefore, the methods outlined above
can be used to calculate the minimal polynomial over IF • of each element of
F: ....
A straightforward method of determining minimal polynomials is
the following one. Let 8 be a defining element of F q" over F •• so that
{1,8, ... ,8m-l) is a basis of IF •• over F •. In order to find the minimal
polynomial g of /lEF;. over F •. we express the powers fl0,fl1, ••• ,pm in
94 Polynomials over Finite Fields
terms of the basis elements. Let
m
{31-1= � biJ8J-l for l.;;i.;;m+l.
i-1
We write gin the form g(x) = cmxm + ... + c,x +Co. We want g to be the
monic polynomial of least positive degree with g({3) = 0. The condition
g({3) = cmpm + · · · + c1{3 + c0 = 0 leads to the homogeneous system of
linear equations
m+l
� c1_1biJ=O for l.;;j.;;m
i-1 (3.10)
with unknowns c0,c1, ••• ,cm. Let B be the matrix of coefficients of the
system-that is, B is the (m + l)Xm matrix whose (i, j) entry is b11-and
let r be the rank of B. Then the dimension of the space of solutions of the
system iss= m +I-r, and since !.;; r.;; m, we have I.;; s.;; m. Therefore,
we can prescribe values for s of the unknowns c0,c1, ••. ,cm, and then the
remaining ones are uniquely determined. If s =I, we set em= I, and if s >I,
we set em= cm-1-... = cm-s+2 = 0 and cm-s+l-1.
3.42. Example. Let 8 E IF 64 be a root of the irreducible polynomial x' + x
+I in F2[x]. For {3 = 83 + 84 we have
{3°= I
P' = 83+84
P'= I +8 + 82+ 83
P'= 8+8'+8'
{34= 8 + 82 +84
P'=l +83+84
P'= I +8 + 8' +84
Therefore, the matrix B is given by
I 0 0 0 0
0 0 0 I I
I I I I 0
B= 0 I I I 0
0 I I 0 I
I 0 0 I I
I I I 0 I 0
0
0
0
0
0
0
and its rank is r = 3. Hence s = m + I -r = 4, so that we set c6 = c, = c4 = 0,
c3 -1. The remaining coefficients are determined from (3.10), and this
yields c2 =I, c1 = 0, c0 -1. Consequently, the minimal polynomial of {3 over
F2isg(x)=x3+x2+1. D
Still another method of determining minimal polynomials is based on
Theorem 3.33(v). If we wish to find the minimal polynomial g of {3 E F ••
3. Construction of Irreducible Polynomials 95
over IF •. we calculate the powers {3, {3<, (3•', ... until we find the least
positive integer d for which {3•' � {3. This integer dis the degree of g, and g
itself is given by
g(x)� (x-{3)(x-{3•)· · · (x-(3<'-').
The elements {3, {3 • .... , {3 •'-' are the distinct conjugates of {3 with respect to
IF,. and g is the minimal polynomial over IF • of all these elements.
3.43. Example. We compute the minimal polynomials over IF2 of all
elements of IF 16. Let 0 E IF 16 be a root of the primitive polynomial x4 + x +I
over F2, so that every nonzero element of IF 16 can be written as a power of 8.
We have the following index table for IF 16:
O' 0'
0 I 8 I+ 02 I 0
2 O' 9 0 + 03
3 03 10 I+ 0 + 02
4 I+ 0 II 0+02+0 3
5 0 + 02 12 1+0+0 2+03
6 02 + 03 13 1+02+03
7 I+ 0 + 03 14 I+ 03
The minimal polynomials of the elements {3 ofF 16 over F2 are:
{3�0: g1(x)�x.
{3�1: g2(x)�x+l .
{3 � 0: The distinct conjugates of 0 with respect to F 2 are
0, 02, 04, 08, and the minimal polynomial is
g3(x) � (x-O)(x-O')(x-04)(x-08)
� x4 + x +I.
{3 � 0 3: The distinct conjugates of 0 3 with respect to F 2 are
03, 06,012,024 � 09, and the minimal polynomial is
g4(x) � (x-03)(x- 06)(x- O')(x-012)
= x4 + x3 + x2 + x + I.
{3 � 05: Since {34 � {3, the distinct conjugates of this element with
respect to IF2 are 05, 010, and the minimal polynomial is
g5(x)�(x-05)(x-010)�x2+x+l.
{3 � 07: The distinct conjugates of 07 with respect to F2 are
01,014,028 �on, 056 � 011, and the minimal polynomial is
g,(x) � (X-07 )(x- 0 II )(x-on)( X-014)
= x4 + x3 +I.
96 Polynomials over Finite Fields
These elements, together with their conjugates with respect to F2• exhaust
F 16. 0
An important problem is that of the determination of primitive
polynomials. One approach is based on the fact that the product of all
primitive polynomials over F q of degree m is equal to the cyclotomic
polynomial Q, with e � qm-1 (see Theorem 2.47(ii) and Exercise 3.42).
Therefore, all primitive polynomials over IF q of degree m can be determined
by applying one of the factorization algorithms in Chapter 4 to the
cyclotomic polynomial Q ,.
Another method depends on constructing a primitive element of IF q"'
and then determining the minimal polynomial of this element over F q by the
methods described above. To find a primitive element of F q"' one starts
from the order qm-1 of such an element in the group F;. and factors it in
the form qm -1 � h1 • • • h,. where the positive integers h1 .... ,h, are pair
wise relatively prime. If for each i, I � i � k, one can find an element
a, E IF:-· of order h,, then the product a1• ··"'*has order qm-1 and is thus
a primitive element of F q"'·
3.44. Example. We determine a primitive polynomial over IF3 of degree 4.
Since 34-1 � 16· 5, we first construct two elements of F81 of order 16 and 5,
respectively. The elements of order 16 are the roots of the cyclotomic
polynomial Q16(x) � x8 + 1 E IF3[x]. Since the multiplicative order of 3
modulo 16 is 4, Q16 factors into two monic irreducible polynomials in F3[x]
of degree 4. Now
x8 + 1 = ( x4-1)2- x4
�(x4-l+x 2)(x4-l-x 2),
and so f(x) = x4-x2- 1 is irreducible over F3 and with a root (J off we
have IF81 � IF3(9). Furthermore, fJ is an element of f81 of order 16. To find
an element a of order 5, we write a� a+ bfJ + cfJ2 + dfJ' with a, b, c. dE IF3,
and since we must have a10 = I, we get
1 = a'a = (a+ bfJ' + cfJ18 + dfJ21)( a+ bfJ + cfJ2 + d(J3)
� (a-bfJ + cfJ2-dfJ' )(a+ bfJ + cfJ2 + dfJ')
= (a+ cfJ2 )2-( bfJ + dfJ' )2 � a2 + (2ac-b2 )92 + ( c2-2bd )94-d2fJ6
= a2 + c2-d2 + bd+(c2 + d2- b2 -ac+ bd)fJ'-
A comparison of coefficients yields
a2 + c2-d2 + bd � 1, c2 + d2- b2 -ac + bd = 0.
Setting a= d = 0, we get b2 = c2 = l. Take b = c = 1, and then it is easily
checked that a= (J + 92 has order 5. Therefore, l" = fJa � 92 + 93 has order
80 and is thus a primitive element of F 81. The minimal polynomial g of l"
3. Construction of Irreducible Polynomials 97
over F3 is
g(x) � (x-r)(x-r')(x-r')(x-f27)
� (x -IJ2 -IJ')(x -I+ IJ + IJ2)(x -/}2 + IJ3)(x -1-IJ + IJ2)
= x4 + x3 + x2 -x-1,
and we have thus obtained a primitive polynomial over F3 of degree 4. 0
3.45. Example. We determine a primitive polynomial over F2 of degree 6.
Since 26 -I� 9·7, we first construct two elements of IF6'. of order 9 and 7,
respectively. The multiplicative order of 2 modulo 9 is 6, and so the
cyclotomic polynomial Q9(x) � x' + x' +I is irreducible over F2. A root/}
of Q, has order 9 and IF 64 � F2 ( IJ). An element a E IF;. of order 7 satisfies
a8 =a, thus writing a= L.�_0a;D; with a; E F2, 0 � i � 5, we get
E a,IJ' � ( E a,IJ')8
;-o ;-o
s
� L a,IJ"
i=O
�a +a IJ8 +a IJ1 +a IJ' +a IJ' +a 1}4 0 I 2 3 4 S
� a0 +a,+ a21J + a11J2 + a31J3 + ( a2 +a, )IJ4 + ( a1 + a4 )IJ',
and a comparison of coefficients yields a3 � 0, a,"" a2, a4 � a2 +a,. Choose
a0 �a,� a4 � 0, a,� a,� a,� I, so that a� IJ + IJ2 + IJ' is an element of
order 7. Thus, f � IJa �I+ IJ2 is a primitiVe element of IF64• Then f2 �
'+ IJ4• r' � IJ' + IJ' + IJ\ r• �' + IJ' + IJ'. r' �' + o + IJ'. r' �' + IJ' + IJ'
+ IJ4 + IJ' An application of the method in Example 3.42 yields the
minimal polynomial g(x) = x' + x4 + x' +X+ I of r over F, and thus a
primitive polynomial over F2 of degree 6. 0
If a primitive polynomial g over F • of degree m is known, all other
such primitive polynomials can be obtained by considering a root IJ of g in
IF •m and determirting the mirtimal polynomials over F • of all elements IJ',
where t runs through all positive integers "qm-I that are relatively prime
to qm -I. The calculation of these minimal polynomials is carried out by
the methods described earlier in this section.
It is useful to be able to decide whether an irreducible polynomial
over a finite field remains irreducible over a certain finite extension field.
The following results address themselves to this question.
3.46. Theorem. Let 1 be an irreducible polynomial over r. of degree
nand let kEN. Then f factors into d irreducible polynomials in F •• [x] of the
same degree n I d, where d � gcd( k, n ).
98 Polynomials over Finite Fields
Proof Since the case f(O) � 0 is trivial, we can assume /(0)"" 0. Let
g be an irreducible factor off in f •' [ x ]. If ord( f) � e, then also ord( g) � e
by Theorem 3.3 since the roots of g are also roots of f. By Theorem 3.5 the
multiplicative order of q modulo e is n and the degree of g is equal to the
multiplicative order of q' modulo e. The powers qi, j � 0, !, ... ,considered
modulo e, form a cyclic group of order n. Thus it follows from Theorem
1.15(ii) that the multiplicative order of q' modulo e is n/d , and so the
degreeofgisn/d. 0
3.47. Corollary. An irreducible polynomial over F • of degree n
remains irreducible over IF •' if and only if k and n are relatively prime.
Proof This is an immediate consequence of Theorem 3.46. 0
3.48. Example. Consider the primitive polynomial g(x) � x' + x4 + x3
+ x +I over F2 from Example 3.45 as a polynomial over IF 16• Then, in the
notation of Theorem 3.46, we have n � 6, k � 4, and thus d � 2. Therefore. g
factors in IF 16[x] into two irreducible cubic polynomials. Using the notation
of Example 3.45, let g 1 be the factor that has I � I + 8 2 as a root. The other
roots of g1 must be the conjugates I" and !'"' � 14 with respect to IF 16•
Since these elements are also conjugates with respect to F4, it follows that g1
is actually in F4[x]. Now {3 � 121 is a primitive third root of unity over F2,
and so F4 � (0, I, {3. {32). Furthermore,
g1(x)�(x-n(x-l4)(x-l")
� x' + U + 14 + l")x' +(I'+ 117 + l20)x + 121•
We have 14 �I+ 82 + 85• I"� I+ 85, and so I+ 14 +I"� I. Similarly, we
obtain I'+ 117 + 120 �I, so that g1(x) � x3 + x2 + x + {3. By dividing g by
g 1 we get the second factor and thus the factorization
g( x) � ( x3 + x2 + x + {3 )( x3 + x2 + x + {32)
in F4[x], and hence in IF 16[x]. The two factors of g are primitive polynomi
als over F 4, but not over IF 16. By Corollary 3.47, the polynomial g remains
irreducible over certain other extension fields of F2, such as IF32 and F ,.. 0
4. LINEARIZED POLYNOMIALS
Both in theory and in applications the special class of polynomials to be
introduced below is of importance. A useful feature of these polynomials is
the structure of the set of roots that facilitates the determination of the
roots. Let q. as usual, denote a prime power.
4. Linearized Polynomials
3.49. Definition. A polynomial of the form
•
L(x) � L a,x•'
;-o 99
with coefficients in an extension field F q• of F q is called a q-polynomial over
f ••.
If the value of q is fixed once and for all or is clear from the context,
it is also customary to speak of a linearized polynomial. This terminology
stems from the following property of linearized polynomials. If F is an
arbitrary extension field of F •• and L(x) is a linearized polynomial (i.e., a
q-polynomial) over F ••. then
L(f.l+y)�L(f.J)+L(y) forallf.J,yEF, (3.11)
L(c/3) � cL(/3) for all c E F• and allf.J E F. (3.12)
The identity (3.11) follows immediately from Theorem 1.46 and (3.12)
follows from the fact that c•' � c for c E F • and i ;;. 0. Thus, if F is
considered as a vector space over F •• then the linearized polynomial L(x)
induces a linear operator on F.
The special character of the set of roots of a linearized polynomial is
shown by the following result.
3.50. Theorem. Let L ( x) be a nonzero q-polynomial over f q" and
let the extension field F q' ofF q• contain all the roots of L ( x ). Then each root
of L(x) has the same multiplicity, which is either . .! or a power of q, and the
roots form a linear subspace of Fq'• where IFq' is regarded as a vector space
over IF q·
Proof It follows from (3.11) and (3.12) that any linear combination
of roots with coefficients in F q is again a root, and so the roots of L ( x) form
a linear subspace of IF ••. If
•
L(x)� L a,x•',
;-o
then L'(x) � a0, so that L(x) has only simple roots in case a0 • 0. Other
wise, we have a0 � a1 � • • • = ak-l = 0, but ak * 0 for some k;;. I, and then
L ( ) -;.. q' ;.. ••• q'-( ;.. q<•-"' ··-·) •• X -£.., a;X = £.., a1 X -£.., «; X ,
i-k i-k i-k
which is the q• th power of a linearized polynomial having only
roots. In this case, each root of L ( x) has multiplicity q•. simple
0
There is also a partial converse of Theorem 3.50, which is given by
Theorem 3.52. It depends on a result about certain determinants which
extends Corollary 2.38.
100 Polynomials over Finite Fields
3.51. Lemma. Let {31, (32, ... , (3. be elements ofF ••. Then
(3, M !3( /3(_,
(3, {3!J. p!j'
!3. /3." /Jnq2
(3.13}
and so the determinant is * 0 if and only if {31, (32, ... ,(3. are linearly
independent over F •.
Proof Let D. be the determinant on the left-hand side of (3.13). We
prove (3.13) by induction on n and note that the formula is trivial for n =I
if the empty product on the right-hand side is interpreted as I. Suppose the
formula is shown for some n ;;. I. Consider the polynomial
(3, M /3(-' !3(
(3, {3!J. /Jf-1 (3!J."
D(x} =
!3. /3." {Jnq"-I p:· ·-' x•" X x• x•
By expansion along the last row we get
•-1
D( x} = D.x•" + � a,x•'
;-o
with a, E F ••. for 0.; i.; n -I. Assume first that {31, ... ,(3. are linearly
independent over F •. We have D(/3•) = 0 for !.; k.; n, and since D(x) is
a q-polynomial over F ••.• all linear combinations c1{31 + · · · + c.f3. with
c• E F• for 1.; k.; n are roots of D(x). Thus D(x) has q" distinct roots, so
that we obtain a factorization
D(x} =D. '•· QeF, ( x-.t ck(3k )· (3.14)
If {31, ... ,(3. are linearly dependent over F •. then D.= 0 and r.;_,b•/3• = 0
for some b 1, ... , b. E F •• not all of which are 0. It follows that
" (" )qi
� b•/3%1= � b•/3• =0 forj=O,I, ... ,n,
k -I k -I
and so the first n row vectors in the determinant defining D(x) are linearly
4. Linearized Polynomials 101
dependent over IF •. Thus D(x) � 0, and the identity (3.14) is satisfied in all
cases. Consequently.
D_.1 � D(/3,+1) � D, 0 (/3•+1-t c•/3•)·
c1, .. ,c,.Ef¥ k""'l
and (3.13) is established. D
3.52 Theorem. Let U be a linear subspace ofF ••• considered as a
vector space over IF •. Then for any nonnegative integer k the polynomial
L(x)� 0 (x-p)• •
�EU
is a q-polynomial over IF ••.
Proof Since the q• th pow�r of a q·polynomial over F •" is again
such a polynomial, it suffices to co�sider the case k � 0. Let {/31, ... ,{3.) be a
basis of U over F •. Then the determinant D. on the left-hand side of (3.13)
is * 0 by Lemma 3.51, and so
L(x)� 0 (x-{3)
�EU
by (3.14), which shows already that L(x) is a q-poiynomial over F... o
The properties of linearized polynomials lead to the following method
of determining roots of such polynomials. Let
"
L(x) � L a,x•'
i-0
be a q-polynomial over F ••• and suppose we want to find all roots of L(x)
in the finite extension F of IF ••. As we noted above. the mapping L:
{3EF....,L({3)EF is a linear operator on the vector space F over F •.
Therefore, L can be represented by a matrix over IF •. Specifically, let
{{31, ••• ,/3,) be a basis of Fover IF•, so that every {3 E Fcan be written in the
form
then '
{3 � L c1{31 with c1 E IF • for I "" j "" s;
j=l
'
L(/3)� L c1L(f3J.
J-1
102 Polynomials over Finite Fields
Now let
' L(fl;) � L b;•ll• for I.;; j.;; s,
k-1
where b;• E IF • for I .;; j, k .;; s, and let B be the s x s matrix over f • whose
(j, k) entry is b;•· Then, if
(c1, ... ,c.)B � (d1, ... ,d.),
we have
L(/l) � L d.fl •.
k-1
Therefore, the equation L(/l) = 0 is equivalent to
(c1, ... ,c.)B � (0, ... ,0). (3.15)
This is a homogeneous system of s linear equations for c 1, ••• , c ,. If r is the
rank of the matrix B, then (3.15) has q'-' solution vectors (c1, ... ,c,). Each
solution vector ( c1, ... , c,) yields a root fl � L.j_1c;fl; of L(x) in F. Thus, the
problem of fmding the roots of L(x) in F is reduced to the easier problem
of solving a homogeneous system of linear equations.
353. Example. Consider the linearized polynomial L(x) � x'-x'-ax
E IF9[x], where a is a root of the primitive polynomial x2 +<-I over IF3. In
order to find the roots of L(x) in IF8io we choose the basis {I,!;, !;2, !;3) of IF"
over IF3, where!; is a root of the primitive polynomial x4 + x' + x2-x-I
over F3 (compare with Example 3.44). Because of the orders involved, we
must have a� !;10; withj �I, 3, 5, or 7, and since !;20 + !;10 -I� 0, we can
take a� !;10 �-I+!;+ !;2- !;3• Next, we calculate
and so we get L(i) �-a�l-!;-!;2 + !;3,
L (!;) � !;' -!; ' -a!;� -!; -!;' -!; ' '
L (!;2) � !;18-!;6-a!;2 � -I+ !;3,
L(!;') � !;27-!;'-a!;3 = 1-!;3,
B�( 6 -I
I -I
-I
0
0 -I
-I
0
0 -:)
I .
-I
The system (3.15) has two linearly independent solutions, such as (0,0, I, I)
and (-I, 1,0, 1). All solutions of (3.15) are obtained by forming all linear
combinations of these two vectors with coefficients in F3• The roots of L(x)
in F81 are then 81�0. 82�!;2+!;3, 83�-!;2-!;3, 84�-1+!;+!;3,
4. Linearized Polynomials
8,=1-t-t'. 8,=-l+t+t'-t'.
89= -l+t-r'. 103
8, ='-r-t' + t'. 8, = ,_ r + t'.
0
This method of finding roots can also be applied to a somewh at
more general class of polynomials-namely, affine polynomials.
3.54. Definition. A polynomial of the form A(x) = L(x)-a., where L(x)
is a q-polynomial over F •" and a E IF q•, is called an affine q-po/ynomial over
IF ••.
An element fl E F is a root of A(x) if and only if L(/l) =a. In the
notation of (3.15), the equation L(fl) =a is equivalent to
(3.16)
where a=E�_1d•fl•· The system (3.16) of linear equations is solved for
c1, ... ,c,, and each solution vector (c1, ... ,c,) yields a root fl=Ej.1cifli of
A(x)inF.
The fact that roots are easier to determine for affine polynomials
suggests the following method of finding the roots of an arbitrary polynomial
f( x) over f •" of positive degree in an extension field F of F... First
determine a nonzero affme q-polynomia! A(x) over F •• that is divisible by
f(x)-t hat is, a so-called affine multiple of f(x). Next, obtain all the roots
of A(x) in F by the method described above. Since the roots of f(x) in F
must be among the roots of A(x) in F, it suffices then to calculate f(fl) for
all roots fl of A(x) in Fin order to locate the roots of f(x) in F.
The only point that remains to be settled is how to determine an
affine multiple A(x) of f(x). 1bis can be achieved as follows. Let n �I be
the degree of f(x). Fori= O,l, ... ,n -I, calculate the unique polynomial
r1(x) of degree .; n -I with x•' = r1(x)modf(x). Then determine elements
a, E F ••. not all 0, such that E7�Ja,r,(x) is a constant polynomial. 1bis
involves n - I conditions concerning the vanishing of the coefficients of xi,
I.; j.; n-I, and thus leads to a homogeneous system of n-I linear
equations for then unknowns a0,a1, ••• ,a"_1• Such a system always has a
nontrivial solution. Once a nontrivial solution has been fixed, we have
r.;�Ja,r1(x) =a for some a. E F ••. It follows that
and so n-1 n-1
L a,x•'= L a,r,(x)=amodf(x),
;-o ;-o
·-·
A(x)= L a,x•'-a
;-o
is a nonzero affine q-polynomial over F •• divisible by f(x). It is clear that
we may take A(x) to be a monic polynomial.
104 Polynomials over Finite Fields
3.55. Example. Let f(x) � x4 + O'x' +Ox'+ x + 0 E F4[x], where 0 is a
root of x2 + x+ IE IF2[x]. We want to find the roots of f(x) in F64. We first
determine an affine multiple A(x) of f(x) by using the method described
above with q � 2. Modulo f(x) we have x = x � r0(x), x2 = x2 � r1(x),
x4 = 02x3 +Ox'+ x + 0 � r2(x), x8 =Ox'+ Ox'+ x + 0 � r3(x). The con
dition that o0r0(x) + o1r1(x) + o2r2(x) + o3r3(x) should be a constant
polynomial leads to the system
a0 + a2+ a3 = 0
a1+ Oa2+0a3 �o
02a2 + Oa3 � 0.
We choose a3 �I and then obtain a2 � 02, a1 � 02, a0 � 0. Furthermore,
a� a0r0(x )+ a1r1 (x )+ a2r2(x )+ a3r3( x) � 02,
and so
A(x) � a3x8 + a2x4+ a1x2 + a0x-a� x8+ 02x4+ 02x2 +Ox+ 02
Next, we calculate the roots of A(x) in F64. We have to solve the
equation L(x) � 02 with the 2-polynomial L(x) � x8 + 02x4 + 02x2 +Ox
over F •. Let r be a root of the primitive polynomial x6 +X+ I over IF,.
Then {I, i. i2, i', i4, i'} is a basis of IF64 over F2. Since 0 is a primitive third
root of unity over F2, we can take 0 � i21 �I+ i + i' + i4 + i'. Using
02�0+I�t+i' +i4+i'. we obtain
L (I) r + i' + r• + i'
L(i) r + r' + i'
L(r') i' + i' + r• + i'
L (t') r + i' + r•
L(r•) i'
L(r') t' + i' + r•
Thus the matrix B in (3.16) is given by
0 I 0 I I I
0 I I 0 0 I
B� 0 0 I I I I
0 I 0 I I 0
0 0 0 0 0 I
0 0 I I I 0
From the representation for 02 given above it follows that the vector
(d1, ... ,d,) in (3.16) is equal to (0, 1,0, I, I, 1). The general solution of the
system (3.16) is then
( 1,0,0,0,0,0)+ a1 (0, 1,1, 1,0,0)+ a2 (I, I, 1,0, 1,0) +a,( I, 1,0,0,0, I)
4. Linearized Polyno mials 105
with a1, a,, a3 E F2. Thus the roots of A(x) in IF64 are 1)1 �I, 1)2 �!; + !;5,
11, �!; + 1;2 + !;4,1J4 �I+ 1;2 + 1;4 + 1;5,1)5 �I+!;+ 1;2 + 1;3,1)6 � !:' + !:' + !;5,
11,�1;'+!;4, 1Js�l+!;+!;3+!;4+!;5�8. By calculating f(1J,) for j�
1,2, ... ,8, we find that the roots off(x) in !'64 are 1)3,1)5,1)7,1)8. 0
The method of determining the roots of an affine polynomial shows,
in particular, that these roots form an affine subspace-that is, a translate
of a linear subspace. This can also be deduced from abstract principles,
together with a statement concerning multiplicities.
3.56. Theorem. Let A(x) be an affine q-polynomial over IF ••• of
positive degree and let the extension field IF •• of F •• contain all the roots of
A(x). Then each root of A(x) has the same multiplicity, which is either I or a
power of q, and the roots form an affine subspace ofF q'• where IF •' is regarded
as a vector space over F q·
Proof The result about the multiplicities is shown in the same way
as in the proof of Theorem 3.50. Now let A(x) � L(x)- a, where L(x) is a
q-polynomial over IF•"'• and let fl be a fixed root of A(x). Then y E IF •• is a
root ofA(x) if and only if L(y)�a�L(/l) if and only if L(y-fl)�O if
and only if y E fl + U, where U is the linear subspace ofF •' consisting of the
roots of L(x). Thus the roots of A(x) form an affine subspace of IF... 0
3.57. Theorem. Let T be an affine subspace ofF ••• considered as a
vector space over IF •. Then for any nonnegative int�ger k the polynomial
A(x)� 0 (x-y)•'
yeT
is an affine q-polynomial over F •"'·
Proof Let T � 1J + U, where U is a linear subspace of f ••. Then
L(x)� 0 (x-p)• •
�eu
is a q-polynomial over IF •" according to Theorem 3.52. Furthermore,
• • A(x)� 0 (x-y)• � 0 (x-1J-fl)• �L(x-1J),
yeT {jeU
and L(x -1J) is easily seen to be an affine q-polynomial over IF... 0
The ordinary product of linearized polynomials need not be a
linearized polynomial. However, the composition L1(L2(x)) of two q-poly
nomials L 1 ( x ), L2 ( x) over F •• is again a q-polynomial. Instead of the word
composition (or substitution) we use the phrase "symbolic multiplicat ion."
Thus, we define symbolic multiplication by
L1�x)®L2(x) � L1(L2(x)).
106 Polynomials over Finite Fields
If we consider only q-polynomials over F ,. then a simple investigation
shows that symbolic multiplication is commutative, associative, and distrib
utive (with respect to ordinary addition). In fact, the set of q-polynomials
over IF, forms an integral domain under the operations of symbolic multipli
cation and ordinary addition. The operation of symbolic multiplication can
be related to the conventional arithmetic of polynomials by means of the
following notion.
3.58. Definition. The polynomials
n n
l(x)� L: a.1x1 and L(x)� L: a1x''
; = 0 i=O
over IF,. are called q-associates of each other. More specifically, I( x) is the
conventional q-associate of L(x) and L(x) is the linearized q-associare of
l(x).
3.59. Lemma. Let L 1 ( x) and L2 ( x) be q-polynomials ooer F, with
conventional q-associates 11(x) and 12(x). Then l(x) � 11(x)l2(x) and L(x)
� L1(x)®L2(x) are q-associates of each other.
and Proof The equations
l(x) � L;a,x' � L;bjx1L; c.x• � 11 (x )12 (x)
1 k
L(x) � L;a,x•'� L;bj(L:c.x•')'' � L;bjL;c.x'1.,� L1(x)®L2(x)
j j k j k.
are each true if and only if
a;= L b1ck foreveryi.
j+ k-i D
If L1(x) and L(x) are q-polynomials over F,, we say that L1(x)
symbolically divides L(x) (or that L(x) is symbolically divisible by L1(x)) if
L(x) � L1(x)®L2(x) for some q-polynomial L2(x) over IF,. The following
criterion is then an immediate consequence of Lemma 3.59.
3.60. Corollary. Let L1(x) and L(x) be q-polynomials ooer F, with
conventional q-associates 11(x) and l(x). Then L1(x) symbolically divides
L(x) if and only if 11(x) divides l(x).
3.61. Example. Let L(x) be a q-polynomial over IF, that symbolically
divides x•·-x for some mEN. Then there exists a q-polynomial L1(x)
over F, such that
x'"'-x � L(x )®L1 (x) � L1 (x )®L(x) � L1 (L(x )). (3.17)
4. Linearized Polynomials 107
This can be applied as follows. Let a be a fixed element of F q"· Then the
affine polynomial L(x)-a has at least one root in Fq"' if and only if
L1(a)�O, and if L1(a)�O, then actually all the roots of L(x)-a are in
F ••. For if f3 E F •• is a root of L(x)-a, then L(/3) �a, and substituting x
by {3 in (3.17) yields L1(a)�p•·-p�o. Conversely, suppose L1(a)�O
and let y be a root of L(x)-a in some extension field of IF •• ; then
L(y) �a, and substituting x by yin (3.17) yields y•"-y � L1(a) � 0, so
that y E F ••. The polynomial L1(x) can be calculated by letting l(x) be the
conventional q-associate of L(x), determining 11(x) � (xm -1)/l(x), and
then taking L 1 ( x) to be the linearized q-associate of 11 ( x ). This application
contains Theorem 2.25 as a special case, as one sees easily by choosing
L(x)�x•-x. 0
It is an important fact that although symbolic multiplication and
ordinary multiplication are quite different operations, the divisibility con
cepts for linearized polynomials based on these operations are equivalent. ·/ ..
3.62. Theorem. Let L 1 ( x) and L( x) be q-polynomials over IF q with
conventional q-associates 11 ( x) and I( x ). Then the following properties are
equivalent: (i) L1(x) symbolically divides L(x); (ii) L1(x) divides L(x) in
the ordinary sense; (iii) 11(x) divides l(x).
Proof Since the equivalence of (i) and (iii) has been established in
Corollary 3.60, it suffices to show the equivalence of (i) and (ii). If L1(x)
symbolically divides L( x ), then
L(x) � L1(x)®L2(x) � L2(x)®L1(x") � L,(L1(x))
for some q-polynomial L2(x) over F •. Let
•
L2(x) = L, a;x•',
;-o
then
q q"
L(x)=a0L1(x)+a1L1(x) + ··· +a.L1(x) ,
and so L1(x) divides L(x) in the ordinary sense. Conversely, suppose L1(x)
divides L(x) in the ordinary sense, where we can assume that L1(x) is
nonzero. Using the division algorithm, we write l(x) � k(x)l1(x) +r(x),
where deg(r(x)) < deg(l1(x)), and turning to linearized q-associates we get
in an obvious notation L(x) = K(x)®L1(x) + R(x). By what we have
already shown, L1(x) divides K(x)®L1(x) in the ordinary sense, and so
L1(x) divides R(x) in the ordinary sense. But since deg (R(x)) < deg(L1(x)),
R( x) must be the zero polynomial, and this proves that L 1 ( x) symbolically
divides L( x ). o
This result can be used to establish an interesting relationship
between an irreducible polynomial and the irreducible factors of its lin
earized q-associate.
108 Polynomials over Finite Fields
3.63. Theorem. Let f(x) be irreducible in F,[x] and let F(x) be its
linearized q-associate. Then the degree of every irreducible factor ofF( x )/ x in
f,[x] is equal to ord(/(x)).
Proof Since the case f(O) � 0 is trivial, we can assume f(O) * 0. Put
e � ord(/(x)) and let h(x) E F,[x] be an irreducible factor of F(x)/x of
degree d. Then f(x) divides x' -I, and so by Theorem 3.62 F(x) divides
x•'-x. It follows that h(x) divides x•'-x, hence d divides e by Theorem
3.20. By the division algorithm, we can write x" -I� g(x)f(x)+r(x) with
g(x), r(x) E F,[x] and deg(r(x)) < deg(/(x)). Turning to linearized q-asso
ciates, we get
x•'-x � G(x) ®F(x )+ R(x ),
and since h(x) divides x•·'-x and G(x)®F(x), it follows that h(x) divides
R(x). If r(x) is not the zero polynomial, then r(x) and f(x) are relatively
prime, and so by Theorem 1.55 there exist polynomials s(x ), k(x) E IF,[ x]
with
s(x)r(x)+k(x)f(x) �I.
Turning to linearized q-associates, we get
S(x )®R(x )+ K(x )®F(x) � x.
Since h(x) divides R(x) and F(x), it follows that h(x) divides x, which is
impossible. Thus r(x) is the zero polynomial, so that f(x) divides x" -I,
and therefore e divides d by Lemma 3.6. Altogether, we have shown d �e. 0
We say that a q-polynomial L(x) over F, of degree >I is symboli
cally irreducible over IF, if the only symbolic decompositions L(x) � L1(x)
®L2(x) with q-polynomials L1(x), L2(x) over F, are those for which one of
the factors has degree I. A symbolically irreducible polynomial is always
reducible in the ordinary sense since any linearized polynomial of degree
> I has the nontrivial factor x. By using Lemma 3.59, one shows im
mediately that the q-polynomial L(x) is symbolically irreducible over!', if
and only if its conventional q-associate /(x) is irreducible over F,.
Every q-polynomial L(x) over IF, of degree >I has a symbolic
factorization into symbolically irreducible polynomials over F, and
this factorization is essentially unique, in the sense that all other symbolic
factorizations are obtained by rearranging factors and by multiplying fac
tors by nonzero elements of IF,. Using the correspondence between lin
earized polynomials and their conventional q-associates. one sees that the
symbolic factorization of L(x) is obtained by writing down the canonical
factorization in !' ,[x] of its conventional q-associate /(x) and then turning
to linearized q-associates.
3.64. Example. Consider the 2-polynomial L(x) � x16 + x' + x' + x over
IF2. Its conventional 2-associate /(x) � x4 + x' + x +I has the canonical
4. Linearized Polynomials
factorization l(x) � (x2 + x + l)(x + 1)2 in IF2[x]. Thus,
L(x)�(x4+x2+x)®(x2+x)®(x2+x) 109
is the symbolic factorization of L(x) into symbolically irreducible poly
nomials over IF 2. D
For two or more q-polynomials over IF •• not all of them 0, we may
define their greatest common symbolic divisor to be the monic q-polynomial
over F• of highest degree that symbolically divides all of them. In order to
compare this notion with that of the ordinary greatest common divisor, we
note first that the roots of the greatest common divisor are exactly the
common roots of the given q-polynomials. Since the intersection of linear
subspaces is another linear subspace, it follows that the roots of the greatest
common divisor form a linear subspace of some extension field IF q'"•
considered as a vector space over F •. Furthermore, by applying the first part
of Theorem 3.50 to the given q-polynomials, we conclude that each root of
the greatest common divisor has the same multiplicity, which is either I or a
power of q. Therefore, Theorem 3.52 implies that the greatest common
divisor is a q-polynomial. It follows then from Theorem 3.62 that the
· greatest common divisor and the greatest common symbolic divisor are id enti
cal. An efficient way of calculating the greatest common (symbolic) divisor
of q-polynomials over F • is to consider the conventional q-associates and
determine their greatest common divisor; then the linearized q-associate of
this greatest common divisor is the greatest common (symbolic) divisor of
the given q-polynomials. ·
By Theorem 3.50 the roots of a nonzero q-p;,lynomial over F• form a
vector space over IF •. The roots have the additional property that the qth
power of a root is again a root. A finite-dimensional vector space Mover F q
that is contained in some extension field of IF • and has the property that the
qth power of every element of M is again in Miscalled a q-modulus. On the
basis of this concept we ean establish the following criterion.
3.65. Theorem The monic polynomial L(x) is a q-polynomial over
IF • if and only if each root of L(x) has the same multiplicity, which is either I
or a power of q. and the roots form a q-modulus.
Proof The necessity of the conditions follows from Theorem 3.50
and the remarks above. Conversely. the given conditions and Theorem 3.52
imply that L(x) is a q-polynomial over some extension field of IF •. If M is
the q-modulus consisting of the roots of L ( x ), then
L(x)� n (x-f!)"'
PEM
for some nonnegative integer k. Since M � ({3•: f3 EM}, we obtain
. ' L(x)•� n (x•-[3•)• � n (x•-p)• � L(x•).
{lEM flEM
110
If
then n
L(x)� L a,x•',
;-o
n n Polynomials over Finite Fields
L arx• .. '�L(x)'�L(x•)� L a,x• .. ',
;-o i=O
so that for 0 � i � n we have ar = a; and thus a; E IF q• Therefore, L (X) is a
q-polynomial over !' ,. D
Any q-polynomial over F • of degree q is symbolically irreducible over
IF,. For q-polynomials of degree > q, the notion of q-modulus can be used
to characterize symbolically irreducible polynomials.
3.66. Theorem. The q-polynomial L(x) over IF, of degree > q is
symbolically irreducible over IF • if and only if L ( x) has simple roots and the
q-modulus M consisting of the roots of L(x) contains no q-modulus other than
{0} and M itself.
Proof Suppose L(x) is symbolically irreducible over F,. If L(x)
had multiple roots, then Theorem 3.65 would imply that we could write
L(x) � L1(x)• with a q-polynomial L1(x) over!', of degree >I. But then
L(x) � x•®L1(x), a contradiction to the symbolic irreducibility of L(x).
Thus L(x) has only simple roots. Furthermore, if N is a q-modulus
contained in M, then Theorem 3.65 shows that L2(x)�f1PEN(x-,8) is a
q-polynomial over F,. Since L2(x) divides L(x) in the ordinary sense, it
symbolically divides L(x) by Theorem 3.62. But L(x) is symbolically
irreducible over IF,, and so deg(L2(x)) must be either I or deg(L(x)); that
is, N is either {0} or M.
To prove the sufficiency of the condition, suppose that L(x) � L1(x)
®L2(x) is a symbolic decomposition with q-polynomi als L1(x), L2(x) over
f,. Then L1(x) symbolically divides L(x), and so it divides L(x) in the
ordinary sense by Theorem 3.62. It follows that L 1 ( x) has simple roots and
that the q-modulus N consisting of the roots of L 1 ( x) is contained in M.
Consequen tly, N is either {0} or M, and so deg(L1(x)) is either I or
deg(L(x)). Thus, either L1(x) or L2(x) is of degree I, which means that
L ( x) is symbolically irreducible over !' ,. D
3.67. Definition. Let L(x) be a nonzero q-polynomial over IF, •. A root I
of L ( x) is cal1ed a q-primitive root over IF q"' if it is not a root of any nonzero
q-polynomial over F , •. of lower degree.
This concept may also be viewed as follows. Let g( x) be the minimal
polynomial of!' over F, •. Then!' is a q-primitive root of L(x) over F,. if
4. Linearized Polynomials 111
and only if g(x) divides L(x) and g(x) does not divide any nonzero
q-polynomial over F •• of lower degree.
Given an element I of a finite extension field of IF q"'• one can always
find a nonzero q-polynomial over f q" for which !; is a q-primitive root over
F ••. To see this, we proceed as in the construction of an affine multiple. Let
g(x) be the minimal polynomial of !; over IF ••• let n be the degree of g(x),
and calculate for i� 0, 1, ... ,n the unique polynomial r1(x) of degree" n -1
with x•' = r,(x )mod g(x ). Then determine elements a1 E IF ••• not all 0, such
that E7-o a1r1(x) � 0. This involves n conditions concerning the vanishing of
the coefficients of xi, 0 " j " n -1, and thus leads to a homogeneous
system of n linear equations for the n + I unknowns a0, a1, ... , an. Such a
system always has a nontrivial solution, and with such a solution we get
n n
L(x)� L a,x•'= L a,r,(x)=Omodg(x),
i-0 i-0
so that L(x) is a nonzero q-polynomial over F •• divisible by g(x). By
choosing the a, in such a way that L(x) is monic and of the lowest possible
degree, one finds that !; is a q-primitive root of L(x) over�'··· It is easily
seen that this monic q-polynomial L(x) over F •• of least positive degree
that is divisible by g(x) is uniquely determined; it is called the minimal
q-polynomial of !; over IF ••.
3.68. 17reorem. Let I be an element of a finite extension field ofF q"
and let M( x) be its minimal q-polynomial over F ••. Then a q-polynomial K( x)
over F •• has !; as a root if and only if K(x) � L(x)®M(x) for some
q-polynomial L ( x) over F ••. In particular ,for the case m � 1 this means that
K(x) has!; as a root if and only if K(x) is symbolical ly divisible by M(x).
Proof If K(x) � L(x)®M(x) � L(M(x)), it follows immediately
that K(!;) � 0. Conversely, let
and suppose I
M( X) = L YjXq' withy,� 1
J-0
K( x) � L a.x•' with r >I
h-0
has!; as a root. Puts� r-I and y1 � 0 for j < 0, and consider the following
112 Polynomials over Finite Fields
system of s +I linear equations in the s +I unknowns /J0,{31, ••• .{3,:
Po+ y,<_ ,p, +yl,P, + · · ·
" + y•' " + ... PI 1-1P2
" + q' Ps-I Yt-1 f3s =a,_ 1
f3s = a,.
It is clear that this system has a unique solution involving elements
/J0,/J,, ... ,p, of "'··· With
we get '
L(x)� L P,x•' and R(x)�K(x)-L(M(x))
i = 0
' ' I
� L a,x•'-L P, L yfx•"'
h-0 i-0 J-0
� L a,x•'-E ( t Yt,P,)x•'
h-o h-o ;-o
It follows from the system above that R(x) has degree < q'. But since
R(n � K(n-L(M(nJ � 0, the definition of M(x) implies that R(x) is the
zero polynomial. Therefore, we have K(x) � L(M(x)) � L(x)®M(x). D
We consider now the problem of determining the number NL of
q-primitive roots over " • of a nonzero q-polynomial L(x) over F •. If L(x)
has multiple roots, then by Theorem 3.65 we can write L(x) � L1(x)• with
a q-polynomial L 1 ( x) over F q· Since every root of L( x) is then also a root
of L1(x), we have NL � 0. Thus we can assume that L(x) has only simple
roots. If L(x) has degree I, it is obvious that NL �I. If L(x) has degree
q" >I and is monic (without loss of generality), let
L(x) � L1(x)® · · · ®L1(x) ® · · · ® L,(x)® · · · ®L,(x)
e,
be the symbolic factorization of L(x) with distinct monic symbolically
4. Linearized Polynomials 113
irreducible polynomials L, (x) over IF •. We obtain NL by subtracting from the�
total number q" of roots the number of roots of L(x) that are already rootS
of some nonzero q-polynomial over F • of degree < q". If � is a root of L ( x)
of the latter kind and M(x) is the minimal q-polynomial of � over r •. then
deg(M(x)) < q" and M(x) symbolically divides L(x) by Theorem 3.68. It
follows that M(x) symbolically divides one of the polynomials K,(x),
l .; i .; r, obtained from the symbolic factorization of L ( x) by omitting the
symbolic factor L,(x), in which case K1(0 � 0 by Theorem 3.68. Since
every root of K,(x) is automatically a root of L(x), it follows that NL is q"
minus the number of � that are roots of some K1(x). If q"• is the degree of
L,(x), then the degree, and thus the number of roots, of K1(x) is q"-"•. If
i 1, ••• , i .s are distinct subscripts, then the number of common roots of
K, (x), ... ,K1 (x) is equal to the degree of the greatest common divisor, ' . which is the same as the degree of the greatest common symbolic divisor
(see the discussion following Example 3.64). Using symbolic factorizations,
one finds that this degree is equal to
n-n -··· -n q 'I '•·
Altogether, the inclusion-exclusion principle of combinatorics yields
'
NL=q"-E q"-"s+ E qn-n,-n1� •.• +(-l)'qn-n1-··-n,
i-1 l.,.;i<j<r
�q"(l-q-"•)··· (1-q-"·).
This expression can also be interpreted in a diffe�ent way. Let /(x) be the
conventional q-associate of L ( x). Then
l(x) � /1 (x )'' · .. l,(x)''
is the canonical factorization of /(x) in IF•[x], where /1(x) is the conven
tional q-associate of L,(x). We define an analog of Euler's </>-function (see
Exercise 1.4) for nonzero f E F•[x] by letting 4>•(/(x)) � ��>,(fl denote the
number of polynomials in F•[x] that are of smaller degree than/as well as
relatively prime to f. The following result will then imply the identity
NL � 4>q(l(x)) for the case under consideration.
3.69. Lemma. The function 4> • defined for nonzero polynomials in
IF •[ x] has the following properties:
(i) ��>.(fl = l if deFfJ) � 0;
(ii) 4>•(/g) � 4>•(/)ll>•(g) whenever f and g are relatively prime;
(iii) if deg(/) � n ;;.l, then
��>.(!) � q"(l-q-"·)· .. (1-q-"·).
where the n, are the degrees of the distinct monic irreducible
polynomials appearing in the canonical factorization off in F .[x ].
114 Polynomials over Finite Fields
Proof Property (i) is trivial. For property (ii), let IPq(/) � s and
IPq(g) � t, and let /1, ••• ,/, resp. g1, ..• ,g, be the polynomials counted by
IPq(f) resp. il>q(g). If hEF.[x1 is a polynomial with deg(h)<deg(fg) and
gcd(fg, h)� I, then gcd(f, h)� gcd(g, h)� I, and so h =/,mod/, h =
g1mod g for a unique ordered pair (i, j) with I..; i ,;; s, I..; j..; t. On the
other hand, given an ordered pair (i, j), the Chinese remainder theorem for
F .[x 1 (see Exercise 1.37) shows that there exists a unique hE F .[x 1 with
h=/,mod/ , h=g1modg, and deg(h)<deg(fg). This h satisfies gcd(f,h)
� gcd(g, h)� I, and so gcd(fg, h)� I. Therefore, there is a one-to-one
correspondence between the st ordered pairs (i, j) and the polynomi als
hE IF•[x1 with deg(h) < deg(fg) and gcd(fg, h)� I. Consequently, IP•(fg)
� st � IPq(fliPq(g).
For an irreducible polynomial bin IF•[x1 of degree m and a positive
integer e, we can calculate IPq(b') directly. The polynomials hE �'.[x1 with
deg( h) < deg( b') � em that are not relatively prime to b' are exactly those
divisible by b, and they are thus of the form h � gb with deg(g) <em-m.
Since there are q•m-m different choices for g, we get IPq(b') � q•m-q•m-m
= q'm(l-q-m). Property (iii) follows now from property (ii). D
3.70. Theorem Let L(x) be a nonzero q-polynomial over F• with
conventional q-associate l(x). Then the number NL of q-primitive roots of
L(x) over F • is given by NL � 0 if L(x) has multiple roots and by NL �
IPq(l(x)) if L(x) has simple roots.
Proof This follows from Lemma 3.69 and the discussion preceding
�- D
3. 71. Corollmy. Every nonzero q-polynomial over IF • with srmple
roots has at least one q-primitive root over F q·
Earlier in this section we introduced the notion of a q-modulus. The
results about q-primitive roots can be used to construct a special type of
basis for a q-modulus.
3. 72. Theorem Let M be a q-modulus of di:nensio'!,_",';;. I over F •.
Then there exists an element IE M such that { 1.1•.1• , ... ,1• } is a basis of
Mover IF •.
Proof According to Theorem 3.65, L(x)�npEM(x-P) is a q
polynomial over F •. By Corollary 3.71, L(x) has a q-primitive root I over
F •. Then 1.1•.1•', ... ,1•·-• are elements of M. If these elements were
linearly dependent over F •• then I would be a root of a nonzero q-poly
nomial over F • of degree less than qm � deg( L(x)), a contradiction to the
definition of a q-primitive root of L ( x) over IF •. Therefore, these m elements
are linearly independent over IF •• and so they form a basis of Mover IF q· D
5. Binomials and Trinomials 115
3.73. Theorem. In F •• there exist exactly <l>q(xm -I) elements !;
such that (!;. !;•. !;•', ... , !;•"-') is a basis ofF •" over F q·
Proof . Since IF •• can be viewed as a q-modulus, the argument in the
proof of Theorem 3. 72 applies. Here
L(x)� 0 (x-fJ)=x•"-x
{jEfq'"
by Lemma 2.4, and every q-primitive root of L(x) over IF• yields a basis of
the desired type. On the other hand, if !; E F •• is not a q-primitive root of
L(x) over F <' then!;, !;•, !;•' •... , !;•·-• are linearly dependent over F <' and so
they do not form a basis of IF <C over IF.. Consequently, the number of
!; E IF<" such that (!;, !;•, !;•', ... , !;• -') is a basis of F <" over F • is equal to the
number of q·primitive roots of L(x) over "•· which is given by <l>•(xm -I)
according to Theorem 3. 70. D
This result provides a refinement of the normal basis theorem
(compare with Definition 2.32 and Theorem 2.35). Since each of the
2 ,_I elements!;, !;•, !;• , ... ,!;• generates the same normal basis ofF •" over F <'
the number of different normal bases of IF •" over IF • is given by
(ljm)<l>q(xm -I).
3.74. Example. We calculate the number of different normal bases of F64
over F2. Since 64 � 26, this number is given by i<l>2(x6 -I). From the
canonical factorization
x6 -I� (x + 1)2(x2 + x + 1)2
in F2[x) and Lemma 3.69(iii) it follows that
<1>2(x6 -I)� 26(1-!)(1-i) � 24.
and so there are four different normal bases of IF64 over F2•
5. BINOMIALS AND TRINOMIALS D
A binomial is a polynomial with two nonzero terms, one of them being the
constant term. Irreducible binomials can be characterized explicitly. For this
purpose it suffices to consider nonlinear, monic binomials.
3. 75. Theorem. Let I ;. 2 be an integer and a E F;. Then the bi
nomial x'-a is irreducible in F .[x) if and only if the following two conditions
are satisfied: (i) each prime factor of I divides the order e of a in F;, but not
(q-l)je; (ii) q =I mod4 if t = Omod4.
116 Polynomi als over Finite Fields
Proof Suppose (i) and (ii) are satisfied. Then we note that f(x) �
x-a is an irreducible polynomial in F .[x] of order e, and so f(x') � x'-a
is irreducible in F.[x] by Theorem 3.35.
Suppose (i) is violated. Then there exists a prime factor r of t that
either divides (q -1)/e or does not divide e. In the first case, we have
rs � (q-1)/e for somes E 1\1. The subgroup of IF; consisting of rth powers
has order (q-1)/r � es and thus contains the subgroup of order e of F;
generated by a. In particular, a� b' for some bE F;, and sox'-a� x'•'-b'
has the factor x'•-b. In the remaining case, r divides neither (q -1)/e nor
e, and so r does not divide q -I. Then r1r =I mod(q-I) for some r1 E 1\1,
and thus x'-a= x'1'-a'1' has the factor x'1-a'1•
Suppose (i) is satisfied and (ii) is violated. Then t � 412 for some
12 E 1\1 and q $I mod4. But (i) implies that e is even, and since e divides
q-I, q must be odd. Hence q = 3 mod4. The fact that x'-a is reducible in
F.[x] is then a consequence of Theorem 3.37. This can also be seen directly
as follows. First we note that the information on e and q yields e"' 2mod4.
Moreover, a�/2 =-= -1, and so x'-a= x' + a<t'/2)+ 1 = x' +ad, where d =
(e/2)+ I is even. Now
a• � 4(z-lad12 )'
� 4(z-ladf2) q+ I� 4c• with c � (z-lad/2 )<• + 1)/4 •
and this leads to the decomposition
x'-a= x411 +4c4
= (x2'2 +2cx12 +2c2)(x2'2 -2cx12 +2c2). 0
If q = 3mod4, we can write q in the forrn q � 2Au -I with A;;. 2 and
u odd. Suppose condition (i) in Theorem 3.75 is satisfied and tis divisible by
2A. We write I� Bv with B � 2A-\ and v even. Then k =A in Theorem
3.37, so that with f(x) � x-a the polynomial f(x') � x'-a factors as a
product of B monic irreducible polynomials in F.[x] of degree t/B � v.
These irreducible factors can be determined explicitly. We note that as in
the last part of the proof of Theorem 3.75, d � (e/2)+ I is even. Since
gcd(2B, q-I)� 2, there exists r E 1\1 with 2Br = dmod( q-1). Setting b �
a' E F •• we get then the following canonical factorization.
3. 76. Theorem. With the conditions and the notation introduced
above, let
F(x)� l:' (B-i-l)!B x8-2iEF [x).
;�o i!(B-2i)! •
Then the roots c1, ••• ,c8 of F(x) are all in F •• and in F.[x] we have the
S. Binomials and Trinomials
· canonical factorization
B
x'-a� n (x"-bcjx"l'-b').
j"" 1 117
Proof For a nonzero element y in an extension field of IF q we have
(x-y)(x + y-1) � x2 -/h-I with,B � y-y-1•
Using the statement and the notation of Waring's formula (see Theorem
I. 76), we get
s8(xpx2)�xr+x:
� ( )'' (i1 + i2-I)!B ( )'' ( )'' i..J -1 . 1• 1 a1 x1,x2 a2 x1,x2
i1+2i2-B 11·12·
il, i2 OJ> 0
Bf2 (B-'-J)IB � L (-!)'' (B-'�. )t··t (x1+x2)8-"'(x1x2}''.
;2-o 12 ·12·
Putting x1 = y, x2 =-y-1, we obtain
y"+y-•� �' (-I)'(B-i-l)!B ,8"-"(-l)'�F(,B).
,_0 d(B -2• }!
If c1 is a root of F(x) in some extension field of F q and y1 is such that
Y -yc1�c then y8+yc8�F(c.)�O and so y�8�-I Since q+l� J J J ' J J J ' f •
2Bu with u odd, we get yf+ 1 �-I, hence yf �-y1-1• Then
•-( - -\)q= q_ -q __ -1 -c1 -Y1 y1 Y1 Y1 -Y1 + Y1 -c1,
and so c1 E IF q. Since F( x) is monic, we have
hence
It follows that •
F(x)� 0 (x-c1),
J-1
B
Y28+I� 0 (y'-c1y-I).
J-1 .
Since this identity holds for any element y of any extension field of F q (also
for y � 0), we get the polynomial identity
B
x28+I� 0 (x2-c1x-l).
J -I
118 Polynomials over Finite Fields
By substituting b-1x'l' for x and multiplying by b28, we get a factorization
of x80 + b28 = x' + a28r = x' +ad= x'-a (compare with the final portion
of the proof of Theorem 3.75 for the last step). The resulting factors are
irreducible in IF,[x] because we know already that the canonical factoriza
tion of x'-a involves B irreducible polynomials in F,[x] of degree v (see
the discussion preceding Theorem 3.76). D
3.77. Example. We factor the binomial x24-3 in IF7[x]. Here q = 23-I,
so that A� 3, B � 4, and v � 6. Furthermore, the element a� 3 is of order
e � 6 in Fj, and so condition (i) in Theorem 3.75 is satisfied and Theorem
3.76 can be applied. We have d � 4, and a solution of the congru
ence 8r = 4mod6 is given by r � 2. Therefore, b � a2 = 2. Furthermore,
F(x)�x4+4x2+2 has the roots ±I and ±3 in F7. Thus x24-3�
(x6 -2x3 -4Xx' +2x3 -4)(x6 + x3 -4)(x6-x3 -4) is the canonical fac
torization in F7[x]. D
A trinomial is a polynomial with three nonzero terms, one of them
being the constant term. We first consider trinomials that are also affine
polynomials.
3. 78. Theorem. Let a E F • and let p be the characteristic ofF,. Then
the trinomial x' -x -a i.s irreducible in IF,[ x] if and only if it has no root in
F,.
Proof If /l is a root of x' -x -a in some extension field of F •'
then by the proof of Theorem 3.56 the set of roots of x' -x-a is fl + U,
where U is the set of roots of the linearized polynomial x' -x. But U � IFP'
and so
x'-x-a� n (x-fl-b).
beFP
Suppose now that x'-x-a has a factor g E F,[x] with I,. r-deg(g) < p
and g monic. Then
'
g(x) � n (x -ll-b,)
i-1
for certain b1 E F.-A comparison of the coefficients of x ,_ 1 shows that
rfl + b1 + · · · + b, is an element ofF,. Since r has a multiplicative inverse in
F •' it follows that /l E F ,. Thus we have shown that if x' -x-a factors
non trivially in IF,[ x], then it has a root in F ,. The converse is trivial. D
3, 79. Coro/Jary. With the notation of Theorem 3.78, the trinomial
x'-x-a i.s irreducible in f,[x] if and only ifTr,,(a)"' 0.
Proof By Theorem 2.25, x' -x -a has a root in IF • if and only if
the absolute trace Tr, (a) is 0. The rest follows from Theorem 3.78. D
•
5. Binomials and Trinomials 119
Since forb E IF; the polynomial f(x) is irreducible over IF• if and
only if f(bx) is irreducible over F •• the criteria above hold also for
trinomials of the form b'x'-bx-a.
If we consider more general trinomials of the above type for which
the degree is a higher power of the characteristic, then these criteria need
not be valid any longer. In fact, the following decomposition formula can be
established.
3.80. Theorem. For x•-x-a with a being an element of the
subfield K = F, ofF= F •• we have the decomposition
q/' x•-x-a= n (x'-x-PJ (3.18)
1-1
in IF •[x ], where the Pi are the distinct elements ofF • with TrF;x(P) =a.
Proof For a given pi, let y be a root of x'-x-Pi in some
extension field of F •. Then y'- y = Pi• and also
a= TrF1x(PJ
= TrF;x(Y'-y)
= ( y'-y) + ( y'-y )' + ( y'-y r' + ... + ( y'-y) q/' = y•-y'
so that y is a root of x•-x-a. Since x'-x-p1 has only simple roots,
x'-x-Pi divides x•-x-a. Now the polynomials x'-x-Pi• I"' j"'
qjr, are pairwise relatively prime, and so the polynomial on the right-hand
side of (3.18) divides x•-x-a. A comparison of degrees and of leading
coefficients shows that the two sides of (3.18) are identical. 0
3.81. Example. Consider x9-x -1 in IF9[x]. Viewing F9 as F3(a), where
a is a root of the irreducible polynomial x.'-x-I in IF3[x], we find that
the elements of F 9 with absolute trace equal to 1 are -1, a, 1-a. Thus
(3.18) yields the decomposition
x9-x-I= (x3-x + l)(x3-x-a)(x3-x -1 +a).
Since all three factors are irreducible in F9[x], we have also obtained the
canonical factorization of x9-x -1 in F9[x]. 0
The information about irreducible trinomials can be applied to the
construction of new irreducible polynomials from given ones.
3.82. Theorem. Let f(x) = xm + am_,xm-l + · · · + a0 be an irre
ducible pol ynomial over the finite field IF • of characteristic p and let b E F •.
Then the polynomial f(x'-x-b) is irreducible over F• if and only if the
absolute trace Tr• (mb-am_1) is * 0 .
•
120 Polynomials over Finite Fields
Proof Suppose Tr, (mb-a .. _,)"' 0. Put K = IF• and let F be the
splitting field off over K. lf'a E F is a root off, then, according to Theorem
2.14, all the roots off are given by a, a•, ... ,a•·-' and F = K( a). Further
more, TrF;K(a)= -am-I by (2.2), and using Theorem 2.26 we get
TrF( a+ b)= TrK(TrF;K(a +b))= TrK(-am-J + mb) "'0.
By Corollary 3.79, the trinomial x'-x -(a+ b) is irreducible over F. Thus
[F(,ll): F] = p. where ll is a root of x'-x -(a+ b). It follows from
Theorem 1.84 that
[F(,B): K] = [F(,B): F][F: K] = pm.
Now a= ,llP -il-b, so that a E K(,ll) and K(,ll) = K(a, ,B)= F(,ll). Hence
[ K( ll): K] = pm and the minimal polynomial of 1l over K has degree pm.
But /(il' -,ll -b)= f(a) = 0, and so ll is a root of the monic polyno
mial f(x'-x-b) E K[x] of degree pm. Theorem 3.33(ii) shows that
f(x'-x-b) is the minimal polynomial of ll over K. By Theorem 3.33(i),
f(x'-x-b) is irreducible over K =IF •.
If Tr,(mb-am_1)=0, then x'-x-(a+b) is reducible over F,
and so [F(,ll): F] < p for any root ll of x'-x -(a+ b). The same argu
ments as above show that ll is a root of f(x'-x-b) and that [F(,ll): K] <
pm. hence f(x'-x-b) is reducible over K =F.. D
For certain types of reducible trinomials we can establish the forrn of
the canonical factorization. The hypothesis for this result involves the
irreducibility of a binomial, which can be cbecked by Theorem 3.75.
3.83. Theorem_ Let f(x)=x'-ax-bEF.[x], where r>2 is a
power of the characteristic ofF •' and suppose that the binomial x'-1 -a is
irreducible over F •. Then f(x) is the product of a linear polynomial and an
irreducible polynomial over IF • of degree r -l.
Proof Since f'(x) =-a"' 0, f(x) has only simple roots. If pis the
characteristic of F •' then f(x) is an affine p-polynomial over F •. Hence,
Theorem 3.56 shows that the difference y of two distinct roots of f(x) is a
root of the p-polynomial x'-ax, and so a root of x'-1-a. From r-I > l
and the hypothesis about this binomial, it follows that y is not an element of
F q' and so there exists a root a of f(x) that is not an element of F •. Then
a•"' a is also a root of f(x) and, by what we have already shown, a•-a
is a root of the irreducible polynomial x'-1 -a over IF •' so that
[IF.(a•-a):F.J=r-1. Since F•(a•-a)<;;F.(a), it follows that m#
[IF.< a) :IF .l is a multiple of r -l. On the other hand, a is a root of the
polynomial f(x) of degree r, so that m.; r. Because of r > 2, this is only
possible if m = r-l. Thus the minimal polynomial of a over F • is an
irreducible polynomial over F • of degree r-I that divides f(x ). The result
follows now immediately. D
5. Binomials and Trinomials 121
In the special case of prime fields, one can characterize the primitive
polynomials among trinomials of a certain kind.
3.84. Theorem. For a prime p, the trinomial x' - x -a E IF P [ x J is a
primitive polynomial over F, if and only if a is a primitive element ofF, and
ord(x' -x-I)� (p' -1)/(p -I).
Proof Suppose first that f(x) � x'-x-a is a primitive poly
nomial over F.-Then a must be a primitive element of F, because of
Theorem 3.18. If p is a root of g(x) � x'-x-I in some extension field of
F,. then
0 � ag(p) � a(IJP-P -I)� a•{JP-a{J-a� f(a{J),
and so a� a{J is a root off( x ). Consequently, we have P' "' I for 0 < r <
(pP-1)/(p-1), for otherwise a'IP-1>�1 with O<r(p-l)<p'-1 , a
contradiction to a being a primitive element of IF,,. On the other hand, g(x)
is irreducible over IF, by Corollary 3.79, and so
g(x)�x•-x-1� (x-P)(x-P')·--(x-W "').
A comparison of the constant terms leads to {J1•'-I)Ap-l) �I, hence
ord(x' -x-I)� (p' -l)j(p -I) on account of Theorem 3.3.
Conversely, if the conditions of the theorem are satisfied, then a and
p have orders p-I and ( p'-1)/( p-1), respectively, in the multiplicative
group IF;,. Now
( p'-I)/( p-I) �I+ p + p2 + · --+ pp-1 =I+ I+ I+ · · · +I
= p = I mod( p -I),
so that p-I and (p' -l)j(p -I) are relatively prime. Therefore, a� ap
has order (p -1)-(p' -l)j(p -I);. p' -I in IF;,. Hence a is a primitive
element of IF'_, andf(x) is a primitive polynomial over IF,. 0
3.85. Example. For p�5 we have (p'-l)/(p-1 )�7 81�11·71.
From the proof of Theorem 3.84 it follows that x781 =I mod(x5-x-1),
and since x11 ••d mod(x'-x-I) and x71 ••d mod(x'-x-I), we obtain
ord(x'-x-I)� 781. Now 2 and 3 are primitive elements of F5, and so
x'-x-2 and x'-x-3 are primitive polynomials over F, by Theorem
3.84. 0
For a trinomial x2 + x +a over a finite field F q of odd characteristic,
it is easily seen that it is irreducible over F • if and only if a is not of the
form a � 4-1 -b2, b E F •. Thus, there are exactly ( q -I )/2 choices for
a E IF• that make x2 + x +a irreducible over f •. More generally, the number
of a E f • that make x" + x +a irreducible over IF • is usually asymptotic to
q In, according to the following result.
122 Polynomials over Finite Fields
1.86. Theorem. Let F q be a finite field of characteristic p. For an
integer n;;. 2 such that 2n(n -I) is not divisible by p, let T,(q) denote the
number of a E F q for which the trinomial x" +X+ a is irreducible over F q·
Then there is a constant B,, depending only on n, such that
IT,( q )-;I"' B,q'l'.
We omit the proof, as it depends on an elaborate investigation of
certain Galois groups.
In Definition 1.92 we defined the discriminant of a polynomial. The
following result gives an explicit formula for the discriminant of a trinomial.
1.87. 17Jeonm. The discriminant of the trinomial x" + axk +bE
IF•[x] with n > k ;;.1 is given by
D(x" + axk +b)= ( -1)"<•-l)f'bk-l
. ( nNbN-K-( -J) N (n-k )N-K kKaN)d,
where d = gcd(n, k), N= njd, K = k/d.
EXERCISES
3.1. Determine the order of the polynomial (x2 + x + 1)5(x3 + x +I)
over IF2.
3.2. Determine the order of the polynomial x7-x6 + x4-x2 + x over
F,.
3.3. Determine ord(f) for all monic irreducible polynomia ls/in F3[x] of
degree 3.
3.4. Prove that the polynomial x8 + x 7 + x' + x +I is irreducible over F2
and determine its order.
3.5. Let f E IF•[x] be a polynomial of degree m ;;.I with /(0),., 0 and
suppose that the roots a1, ••• , am off in the splitting field off over F q
are all simple. Prove that ord( /) is equal to the least positive integer
e such that a7 =I for !.; i.; m.
3.6. Prove that ord( Q,) = e for all e for which the cyclotomic polynomial
Q, E F .lx] is defined.
3.7. Let/be irreducible over "• with/(0)'* 0. ForeE 1\1 relatively prime
to q, prove that ord(f) = e if and only iff divides the cyclotomic
polynomial Q ,.
3.8. Let f E F .lx] be as in Exercise 3.5 and let bE 1\1. Find a general
formula showing the relationship between ord( /•) and ord(f).
3.9. Let F q be a finite field of characteristic p, and let f E IF .lx] be a
Exercises 123
3.10.
3.11.
3.12.
3.13.
3.14.
3.15.
3.16.
3.17.
3.18.
3.19.
3.20.
3.21.
3.22.
3.23.
3.24.
3.25.
3.26. polynomial of positive degree withf(O) "'0. Prove that ord(/(x')) =
pord(/(x)).
Let f be an irreducible polynomial in IF •[x I with /(0)"' 0 and
ord(/) = e, and let r be a prime not dividing q. Prove: (i) if r divides
e, then every irreducible factor of f(x') in IF •[x I has order er; (ii) if r
does not divide e, then one irreducible factor of f(x') in IF•[xl has
order e and the other factors have order er.
Deduce from Exercise 3.10 that if f E F •[x I is a polynomial of
positive degree with f(O)"' 0, and if r is a prime not dividing q, then
ord(/(x')) = rord(/(x)).
Prove that the reciprocal polynomial of an irreducible polynomial f
over F • with f(O)"' 0 is again irreducible over IF q·
A nonzero polynomial f E IF q[x I is called self-recipro cal if f = f*.
Prove that iff= gh, where g and h are irreducible in IF •[x I and f is
self-reciprocal, then either (i) h* = ag with a E F;; or (ii) g* = bg,
h* = bh with b = ±I.
Prove: if f. is a self-reciprocal irreducible polynomial m IF •[x I of
degree m > I, then m must be even.
Prove: if f is a self-reciprocal irreducible polynomial in F•[xl of
degree > I and of order e, then every irreducible polynomial in F •[ xI
of degree >I whose order divides e is self-reciprocal.
Show that x6 + x' + x 2 + x + I is a primitive polynomial over IF 2.
Show that x' + x6 + x' + x +I is a primitive polynomial over IF2.
Show that x'-x +I is a primitive polynomial over IF3•
Let/ E IF•[xl be monic of degree m;. I. Prove that/is primitive over
IF • if and only iff is an irreducible factor over F • of the cyclotomic
polynomial Qd E Fq[xl with d = qm -I.
Determine the number of primitive polynomials over F • of degree m.
If m E N is not a prime, prove that not every monic irreducible
polynomial over IF • of degree m can be a primitive polynomial over
F •.
If m is a prime, prove that all monic irreducible polynomials over IF •
of degree m are primitive over IF • if and only if q = 2 and 2m- I is a
prime.
Iff is a primitive polynomial over F q• prove that f(0)-1/* is again
primitive over IF q·
Prove that the only self-reciprocal primitive polynomials are x + I
and x2 + x +I over f2 and x +I over F3 (see Exercise 3.13 for the
definition of a self-reciprocal polynomial).
Prove: if f(x) is irreducible in F •[x 1. then/( ax+ b) is irreducible in
IF•[xl for any a, bE IF• with a"' 0.
Prove that Nq(n),.(ljn)(q" -q) with equality if and only if n is
prime.
124 Polynomials over Finite Fields
3.27. Prove that
N(n)�.!_q"-q (q"l'-1). • n n(q-1)
3.28. Give a detailed proof of the fact that (3.5) implies (3.4).
3.29. Prove that the Moebius function p. satisfies p.(mn) = p.(m)p.(n) for
all m, n E 1\1 with gcd(m, n) =I.
3.30. Prove the identity
� p.(d) __ .p(n)
._, for all n E 1\1.
din d n
3.31. Prove that r.d1,p.(d)<j>(d) = 0 for every even integer n � 2.
3.32. Prove the identity r.d1.1p.(d)l = 2•, where k is the number of distinct
prime factors of n E 1\1.
3.33. Prove that N.(n) is divisible by eq provided that n � 2, e is a divisor
of q -I, and gcd(eq, n)= I.
3.34. Calculate the cyclotomic polynomials Q12 and Q30 from the explicit
formula in Theorem 3.27.
3.35. Establish the properties of cyclotomic polynomials listed in Exercise
2.57, Parts (a)-(f), by using the explicit formula in Theorem 3.27.
3.36. Prove that the cyclotomic polynomial Q, with gcd(n, q) =I is irre
ducible over F • if and only if the multiplicative order of q modulo n
is<j>(n).
3.37. If Q, is irreducible over f2, prove that n must be a prime = ± 3 mod
8 or a power of such a prime. Show also that this condition is not
sufficient.
3.38. Prove that Q15 is reducible over any finite field over which it is
defined.
3.39. Prove that for n E 1\1 there exists an integer b relatively prime to n
whose multiplicative order modulo n is .p( n) if and only if n = I, 2, 4,
p', or 2p', where p is an odd prime andrE 1\1.
3.40. Dirichlet's theorem on primes in arithmetic progressions states that
any arithmetic progression of integers b, b + n, ... ,b + kn, ... with
n E 1\1 and gcd(b, n) =I contains infinitely many primes. Use this
theorem to prove the following: the integers n E 1\1 for which there
exists a finite field F • with gcd(n, q) =I over which the cyclotomic
polynomial Q. is irreducible are exactly given by n =I, 2, 4, p', or
2p', where p is an odd prime andrE 1\1.
3.41. Prove that Q19 and Q27 are two cyclotomic polynomials over F2 of
the same degree that are both irreducible over F 2.
3.42. If e � 2, gcd( e, q) = I, and m is the multiplicative order of q modulo
e, prove that the product of all monic irreducible polynomials in
F.[x] of degree m and order e is equal to the cyclotomic polynomial
Q, over IF q·
Exercises 125
3.43. Find the factorization of x32 -x into irreducible polynomials over
F,.
3.44. Calculate /(2,6; x) from the formula in Theorem 3.29.
3.45. Calculate /(2,6; x) from the formula in Theorem 3.31.
3.46. Prove that
( ) n( ,_, )•(•/d) I q,n;x = xq -1 forn>l. d]•
3.47. Prove that over a finite field of odd order q the polynomial
!(I+ x<q+l)/2 +(1-x)<•+ll/2) is the square of a polynomial.
3.48. Determine all irreducible polynomials in F2[x] of degree 6 and order
21 and then all irreducible polynomials in IF2[x] of degree 294 and
order 1029.
3.49. Determine all monic irreducible polynomials in F3[x] of degree 3
and order 26 and then all monic irreducible polynomials in F3[x] of
degree 6 and order I 04.
3.50. Proceed as in Example 3.41 to determine which polynomials f. are
irreducible in IF•[x] in the case q-5, m � 4, e = 78.
3.51. In the notation of Example 3.41, prove that if tis a prime with t -I
dividing m -1, then f. is irreducible in F2[x].
3.52. Given the irreducible polynomial l(x) � x3-x' + x +I over F3,
calculate 12 and Is by the matrix-theoretic method.
3.53. Calculate 12 and Is in the previous exercise by using the result of
Theorem 3.39.
3.54. Use a root of the primitive polynomial x'-x +I over f3 to repre
sent all elements of IFJ'7 and compute the minimal polynomials over
IF3 of all elements of F27.
3.55. Let 8 E IF64 be a root of the irreducible polynomial x6 + x +I in
F2[x]. Find the minimal polynomial of fJ �I+ 82 + 83 over IF2.
3.56. Let 8 E F64 be a root of the irreducible polynomial x6 + x4 + x3 +
x +I in F2[x]. Find the minimal polynomial of fJ �I+ 8 + 9s over
F,.
3.57. Determine all primitive polynomials over F3 of degree 2.
3.58. Determine all primitive polynomials over F 4 of degree 2.
3.59. Determine a primitive polynomial over F s of degree 3.
3.60. Factor the polynomial g E F3[x] from Example 3.44 in F9[x] to
obtain primitive polynomials over F9.
3.61. Factor the polynomial g E IF2[x] from Example 3.45 in F8[x] to
obtain primitive polynomials over F8.
3.62. Find the roots of the following linearized polynomials in their
splitting fields:
(a) L(x) � x' + x4 + x' + x E IF2[x];
(b) L(x) � x9 + x E IF3[x].
3.63. Find the roots of the following polynomials in the indicated fields by
126 Polynomials over Finite Fields
first determining an affine multiple:
(a) f(x)�x7+x6+x3+x2+1EIF2[x[ in IF32;
(b) f(x)� x4 + 8x3-x2 -(8 + l)x + 1-8 E IF9[x[ in Fm, where 8
is a root of x2-x -1 E IF3[x].
3.64. Prove that for every polynomial f over IF q" of positive degree there
exists a nonzero q-polynomial over F q• that is divisible by f.
3.65. Prove that the greatest common divisor of two or more nonzero
q-polynomials over f •" is again a q-polynomial, but that their least
common multiple need not necessarily be a q-polynomial.
3.66. Determine the greatest common divisor of the following linearized
polynomials:
(a) L1(x)�x64+x16+x8+x4+x2+xEF2[x],
L2(x) � x32 + x' + x2 + x E f2[x];
(b) L1(x)�x243-x81-x9+x3+xEF3[x],
L2(x) � x81 + x EF3[x].
3.67. Determine the symbolic factorizat ion of the following linearized
polynomials into symbolically irreducible polynomials over the given
prime fields:
(a) L(x) � x32 + x16 + x' + x4 + x2 + x E IF2[x];
(b) L(x)�x81-x9-x3-xEIF3[x].
3.68. Prove that the q-polynomial L1(x) over IF •• divides the q-polynomial
L(x) over IF •• if and only if L(x) � L2(x)®L1(x) for some q-poly
nomial L2 ( x) over IF ••.
3.69. Prove that the greatest common divisor of two or more affine
q-polynomials over IF ••• not all of them 0, is again an affine q-poly
nomial.
3.70. If A 1(x) � L 1(x )-a1 and A2(x) � L2(x )-a2 are affine q-polynomi
als over IF •• and A1(x) divides A2(x), prove that the q-polynomial
L1(x) divides the q-polynomial L2(x).
3.71. Let f(x) be irreducible in IF•[x] with f(O) * 0 and let F(x) be its
linearized q-associate. Prove that F(x)/x is irreducible in Fq[x] if
and only if f(x) is a primitive polynomial over F • or a nonzero
constant multiple of such a polynomial.
3.72. Let!; be an element of a finite extension field of IF ••. Prove that a
q-polynomial K(x) over F •• has !; as a root if and only if K(x) is
divisible by the minimal q-polynomial of !; over F ••.
3.73. For a nonzero polynomial f E IF.[x], prove that I:<l>.(g) � q•<&<n,
where the sum is extended over all monic divisors g E IF .I x] of f.
3.74. For a nonzero polynomial [ E F•[x] and g E F q[x] with gcd(f, g)� I,
prove that g• =I mod/, where k � <l>q(f).
3.75. The function llq is defined on the set S of nonzero polynomials f over
F • by p.q{ f) � I if deg(f) � 0, p. .<fl � 0 iff has at least one multiple
root, and /lq(f) � ( -I)• if deg(f) ;.I and f has only simple roots,
where k is the number of irreducible factors in the canonical factori-
Exercises 127
zation off in IF•[xl. Let E denote a sum extended over all monic
divisors g E IF .Jxl of f. Prove the following properties: { 1 ifdeg{!)�o, (a) l:l'.(g) � 0 if deg(/) �I;
·
(b) "•(/g) � "•(/)l'•(g) for all f, g E S with gcd(f, g)= I;
(c) Eq•""<•>"•(//g) � Ill•(/) for all f E S;
(d) if I} is a mapping from S into an additively written abelian
group G with l}(cf)=l}(f) for all ceF; andfES, and if
v(f)=EI}(g) for all /ES, then 1}(/)=EI'q(//g)v(g)=
E"•(g)'l'(//g) for all/ E S.
3. 76. Prove that the number of different normal bases of IF •• over F • is
provided that gcd(m, q) �I and the multiplicative order of q modulo
m is <l>(m).
3.77. Refer to Example 2.31 for the definition of a self-dual basis and
show that there exists a self-dual normal basis of F2• over F2
whenever m is odd. (Hint: Show first that the number of different
normal bases of F2• over F2 is odd whenever m is odd.)
3.78. For a prime r and a E IF •• prove that x'-a is either irreducible in
F•[xl or has a root in IF.. ·
3.79. For an odd primer, an integer n �I, and a E F •• prove that x'"-a is
irreducible in F•[xl if and only if a is not an rth power of an element
of F •.
3.80. Find the canonical factorization of the following binomials over the
given prime fields:
(a) /(x)=x8+1EF3[xl;
(b) f(x) = x27-4 E F 19[x I;
(c) /(x) � x88-10 E IF23[xl.
3.81. Prove that under the conditions of Theorem 3. 76 the roots of the
polynomial F( x) introduced there are simple.
3.82. Prove that the resultant of two binomials x•-a and xm-bin F •[x I
is given by ( -i)"(b•l•-amfd)d with d � gcd(n, m), where nand m
are considered to be the formal degrees of the binomials (compare
with Definition 1.93).
3.83. For a nonzero element b of a prime field IF,, prove that the trinomial
x'-x-b is irreducible in F,.[xl if and only if n is not divisible
by p.
3.84. Prove that any polynomial of the form x•-ax-bE F .Jx I with
a *I has a root in F •.
3.85. Prove: if x'-x-a is irreducible over the field IF • of characteristic p
128 Polynomials over Finite Fields
and p is a root of this trinomial in an extension field of F •• then
x'-x-ap•-1 is irreducible over F•(/3).
3.86. Prove: if l(x)=x"'+a.,_1x"'-1+ ··· +a0 is irreducib le over the
field IF• of characteristic p and bE F • is such that Tr,,(mb-a.,_1) =
0, then l(x'-x-b) is the product of p irreducible polynomials
over F • of degree m.
3.87. If m and p are distinct primes and the multiplicative order of p
modulo m ism-1, prove that Ej_(/(x'-x); is irreducible over IF,.
3.88. Find the canonical factorization of the given polynomial over the
indicated field:
(a) l(x) = x'-ax -1 E F64[x], where a satisfies a3 =a+ 1;
(b) l(x) = x9-ax+ a E IF9[x], where a satisfies a2 =a+ 1.
3.89. Let A(x)=L(x)-aEF.[x] be an affme p-polynomial of degree
r > 2, and suppose the p-polynomial L(x) is such that L(x)/x is
irreducib le over F •. Prove that A(x) is the product of a linear
polynomial and an irreducib le polynomial over F • of degree r-1.
3.90. Prove: the trinomial x" + ax• +bE IF.[x], n > k ;;>l, q even, has
multiple roots if and only if n and k are both even.
3.91. Prove that the degree of every irreducib le factor of x2" + x + 1 in
IF2[x] divides 2n.
3.92. Prove that the degree of every irreducible factor of x'"+ 1 + x + 1 in
IF2[x] divides 3n.
3.93. Recall the notion of a self-reciprocal polynomial defined in Exercise
3.13. Prove that if 1 E F2[x] is a self-reciprocal polynomial of posi
tive degree, then I divides a trinomial in F2[x] only if ord(f) is a
multiple of 3. Prove also that the converse holds if I is irreducible
over F2•
3.94. Prove that for odd dEN the cyclotomic polynomial Qd E F2[x]
divides a trinomial in F2[x] if and only if dis a multiple of 3.
3.95. Let l(x)=x"+ax•+bEIF.(x], n>k;;>l , be a trinomial and let
mE I'll be a multiple of ord(f). Prove thatl(x) divides the trinomial
g(x) = xm-k + b-1x"-k + ab-1•
3.96. Prove that the trinomial x2" + x" + 1 is irreducible over IF2 if and
only if n = 3• for some nonnegative integer k.
3.97. Prove that the trinomial x4" + x" + 1 is irreducible over F if and
only if n = 3•5"' for some nonnegative integers k and m. '<
Chapter 4
Factorization of Polynomial s
Any nonconstant polynomial over a field can be expressed as a product of
irreducible polynomials. In the case of finite fields, some reasonably effi
cient algorithms can be devised for the actual calculation of the irreducible
factors of a given polynomial of positive degree.
The availability of feasible factorization algorith ms for polynomials
over finite fields is important for coding theory and for the study of linear
recurrence relations in finite fields. Beyond the realm of finite fields, there
are various computational problems in algebra and number theory that
depend in one way or another on the factorization of polynomials over
finite fields. We mention the factorization of polynomials over the ring of
integers, the determination of the decomposition of rational primes in
algebraic number fields, the calculation of the Galois group of an equation
over the rationals, and the construction of field extensions.
We shall present several algorithms for the factorization of poly
nomials over finite fields. The decision on the choice of algorithm for a
specific factorization problem usually depends on whether the underlying
finite field is "small" or "large." In Section I we describe those algorithms
that are better adapted to "small" finite fields and in the next section those
that work better for "large" finite fields. Some of these algorithms reduce
the problem of factoring polynomials to that of finding the roots of certain
other polynomial s. Therefore, Section 3 is devoted to the discussion of the
latter problem from the computational viewpoint.
130 Factorization of Polynomials
1. FACTORIZATION OVER SMALL FINITE FIELDS
Any polynomial / E IF•[x1 of positive degree has a canonical factorization in
F .[x1 by Theorem 1.59. For the discussion of factorization algorithms it will
suffice to consider only monic polynomials. Our goal is thus to express a
monic polynomial f E F .[x1 of positive degree in the form
(4.1)
where /1, ••• ./, are distinct monic irreducible polynomials in IF•[x1 and
e1 •••• ,e" are positive integers.
First we simplify our task by showing that the problem can be
reduced to that of factoring a polynomial with no repeated factors, which
means that the exponents e 1, ••• , e k in ( 4.1) are all equal to I (or, equiva
lently, that the polynomial has no multiple roots). To this end, we calculate
d(x) = gcd(!(x),f'(x)),
the greatest common divisor of f( x) and its derivative, by the Euclidean
algorithm.
If d( x) = I, then we know that/( x) has no repeated factors because
of Theorem 1.68. If d(x) = f(x), we must have f'(x) = 0. Hence f(x) =
g( x )', where g( x) is a suitable polynomial in IF •[ x 1 and p is the characteris
tic of F •. If necessary, the reduction process can be continued by applying
the method to g( x ).
If d(x)"" I and d(x) ""f(x), then d(x) is a nontrivial factor off(x)
andf(x)jd(x) has no repeated factors. The factorization off(x) is achieved
by factoring d(x) and/(x)jd(x) separately. In case d(x) still has repeated
factors, further applications of the reduction process will have to be carried
out.
By applying this process sufficiently often, the original problem is
reduced to that of factoring a certain number of polynomials with no
repeated factors. The canonical factorizations of these polynomials lead
directly to the canonical factorization of the original polynomial. Therefore,
we may restrict the attention to polynomials with no repeated factors. The
following theorem is crucial.
4.1. Theon"'- If f E IF •[ x 1 is monic and h E IF •[ x 1 is such that
h• = hmodf, then
f(x) = Il gcd(/(x), h(x)-c). (4.2)
,·eF,
Proof Each greatest common divisor on the right-hand side of (4.2)
divides f(x ). Since the polynomials h( x)-c, c E F •• are pairwise relatively
prime, so are the greatest common divisors with/( x ), and thus the product
of these greatest common divisors divides f(x). On the other hand, f(x)
I. Factorization over Small Finite Fields Ill
divides
h(x)•-h(x)= fl (h(x)-c),
cEFq
and sof(x) divides the right-hand side of (4.2). Thus, the two sides of (4.2)
are monic polynomials that divide each other, and therefore they must be
��- D
In general, ( 4.2) does not yield the complete factorization off since
gcd(f(x), h(x)-c) may be reducible in Fq[x]. If h(x) = cmodf(x) for
some c E F •• then Theorem 4.1 gives a trivial factorization off and therefore
is of no use. However, if h is such that Theorem 4.1 yields a nontrivial
factorization off, we say that h is an !-reducing polynomial. Any h with
h• = h mod f and 0 < deg( h)< deg(f) is obviously /-reducing. In order to
obtain factorization algorithms on the basis of Theorem 4.1, we have to find
methods of constructing /-reducing polynomials. It should be clear at this
stage already that since the factorization provided by ( 4.2) depends on the
calculation of q greatest common divisors, a direct application of this
formula will only be feasible for small finite fields IF q·
The first method of constructing /-reducing polynomials makes use
of the Chinese remainder theorem for polynomials (see Exercise 1.37). Let
us assume that f has no repeated factors, so that f = /1 • • ·f. is a product of
distinct monic irreducible polynomials over r •. If (c1, ••• ,c.) is any k-tuple
of elements of r •. the Chinese remainder theorem implies that there is a
unique h E F•[x] with h(x) = c1mod f,(x) for I .;; i'<, k and deg (h) < deg(f).
The polynomial h ( x) satisfies the condition
h(x)• = c? = c, = h(x )mod.t;(x) for I<. i.;; k,
and therefore
h•=hmodf, deg(h) < deg(/).
On the other hand, if h is a solution of ( 4.3), then the identity
h(x)•-h(x) = fl (h(x)-c)
cEF9 (4.3)
implies that every irreducible factor of f divides one of the polynomi�s
h(x)-c. Thus, �I solutions of (4.3) satisfy h(x)=c,mod.t;(x), i .;;i.;k,
for some k-tuple (c1, ••• ,c.) of elements of IF •. Consequently, there are
exactly q• solutions of (4.3).
We find these solutions by reducing (4.3) to a system of linear
equations. With n = deg(f) we construct the n X n matrix B = (b,j), 0 .;; i,j
.; n -1, by calculating the powers x'•modf(x). Specifically ,let
n-1
x'•= L b,jxjmodf(x) forOc;;i.;;n-1.
j�O (4.4)
132 Factorization of Polynomials
Then h(x) � a0 + a1x + · · · + a._,x•-l E IF•[x] is a solution of (4.3) if and
only if
(a0, a1, ••• ,a._,) B � (a0• a1 , ••• ,a._,).
This follows from the fact that (4.5) holds if and only if
n -I
h(x) � L a,xi
J-0
n-1 n -1
� L L a,b,1x1
J-0 i-0
n -I
= L a,x'•�h(x)•modf(x).
i-0
The system ( 4.5) may be written in the equivalent form
(a0, a1, ••• ,a._,)(B-I)� (0,0, ... ,0), (4.5)
(4.6)
where I is the n X n identity matrix over F q· By the considerations above,
the system (4.6) has q• solutions. Thus, the dimension of the null space of the
matrix B -I is k, the number of distinct monic irreducible factors off, and
the rank of B-I is n -k.
Since the constant polynomial h1(x) �I is always a solution of (4.3),
the vector (1,0, ... ,0) is always a solution of (4.6), as can also be checked
directly. There will exist polynomials h2(x), ... ,h.(x) of degree "'n -]
such that the vectors corresponding to h1(x), h2(x),. .. ,h.(x) form a basis
for the null space of B -I. The polynomials h2(x), ... ,h.(x) have positive
degree and are thus /-reducing.
In this approach, an important role is played by the determination of
the rank r of the matrix B-I. We have r � n -k as noted above, so that
once the rank r is found, we know that the number of distinct monic
irreducible factors off is given by n -r. On the basis of this information we
can then decide when the factorization procedure can be stopped. The rank
of B -I can be determined by using row and column operations to reduce
the matrix to echelon form. However, since we also want to solve the system
(4.6), it is advisable to use only column operations because they leave the
null space invariant. Thus, we are allowed to multiply any column of the
matrix B-I by a nonzero element of F q and to add any multiple of one of
its columns to a different column. The rank r is the number of nonzero
columns in the column echelon form.
Having found r, we form k � n-r. If k �I, we know that f
is irreducible over F q and the procedure terminates. In this case, the
only solutions of (4.3) are the constant polynomials and the null space of
B -I contains only the vectors of the form (c,O, ... ,O) with cEIF •.
If k;. 2, we take the /-reducing basis polynomial h2(x) and ealculate
I. Factorization over Small Finite Fields Ill
gcd(f(x ), h"2(x )-c) for all c E F •. The result will be a nontrivial factoriza
tion of f(x) afforded by (4.2). If the use of h2(x) does not succeed in
splittingf(x) into k factors, we calculate gcd(g(x ), h3(x )-c) for all c E F •
and all nontrivial factors g(x) found so far. lbis procedure is continued
until k factors of f(x) are obtained.
The process described above must eventually yield all the factors.
For if we consider two distinct monic irreducible factors of f(x), say f1(x)
and f2(x), then by the argument following (4.3) there exist elements ci''
ci2 E IF• such that h i(x) = ci1mod f1(x ), h i(x) = ci2mod f2(x) for I "j" k.
Suppose we had ci1 = ci2 for I " j " k. Then, since any solution h ( x) of
(4.3) is a linear combination of h1(x), ... ,hk(x) with coefficients in F•, there
would exist for any such h(x) an element c E F• with h(x) = cmodf1(x),
h ( x) = cmod f2 ( x ). But the argument leading to (4.3) shows, in particular,
that there is a solution h(x) of (4.3) with h(x)=Omodf1(x), h(x)=
I mod f2( x ). This contradiction proves that ci1 * ci2 for some j with I " j" k
(in fact, since h1(x)=l, we will have}> 2). Therefore, hi(x)-ci1 will be
divisible by f1(x), but not by f2(x). Hence any two distinct monic irreduc
ible factors of f(x) will be separated by some hi(x).
This factorization algorithm based on determining /-reducing poly
nomials by solving the system (4.6) is called Berlekamp 's algorithm.
4.2. Example. Factor f(x) = x' + x6 + x4 + x3 + I over IF2 by
Berlekamp's algorithm. Since gcd(f(x ), f'(x )) =I, f(x) has no repeated
factors. We have to compute x'•modf(x) forq = 2 and 0" i" 7. This
yields the following congruences mod f(x):
x0 =I
x2 = x'
x4 = x•
x6 = x'
x' =I +x3+x4 +x'
x10= 1 +x2+xl+x4+xs
x\2= x' +x4+xs+x 6+x1
x14=l+x +xl+x4+xs
Therefore, the 8 X 8 matrix B is given by
I 0 0 0 0 0 0 0
0 0 I 0 0 0 0 0
0 0 0 0 I 0 0 0
B= 0 0 0 0 0 0 I 0
I 0 0 I I 0 I 0
I 0 I I I I 0 0
0 0 I 0 I I I I
I I 0 I I 0 0
134 Factorization of Polynomials
and B -I is given by
0 0 0 0 0 0 0 0
0 I I 0 0 0 0 0
0 0 I 0 I 0 0 0
B-1= 0 0 0 I 0 0 I 0
I 0 0 I 0 0 I 0
I 0 I I I 0 0 0
0 0 I 0 I I 0 I
I I 0 I I I 0 I
The matrix B -I has rank 6, and the two vectors (1,0,0,0,0,0,0,0) and
(0, I, 1,0,0, I, I, I) form a basis of the null space of B-I. The corresponding
polynomials are h1(x) =I and h2(x) = x + x2 + x' + x6 + x7 We calculate
gcd(/(x), h2(x)-c) for c E IF2 by the Euclidean algorithm and obtain
gcd(/(x), h2(x)) = x6 + x' + x4 + x +I, gcd(/(x), h2(x)-l) = x2 + x +I.
The desired canonical factorization is therefore
f(x) = (x6 + x' + x4 + x + i)(x2 + x + 1). D
A second method of obtaining f-reducing polynomials is based on
the explicit construction of a family of polynomials among which at least
one /-reducing polynomial can be found. Let f be again a monic polynomial
of degree n with no repeated factors. Let f = /1 • • ·f. be its canonical
factorization in F.[x] with deg(/ )=nj for l.;j<;k. If N is the least
positive integer with x•• = xmodf(x), then it follows from Theorem 3.20
that N = lcm( n 1, ••• , n• ), and it is also easily seen that N is the degree of the
splitting field F of,! over IF •. �t the polynomial T E F•[x] be given by
T(x)=x+x•+x• + ·· · +x• and define T,(x)=T(x') fori=O,i, ....
The following result guarantees that in the case of interest, namely, when f is
reducible, there are /-reducing polynomials among the T,.
4.3. Theorem . Iff is reducible in F .lx ], then at least one of the
polynomials T;, 1 :::;;;; i:::;;;; n -1, is /-reducing.
Proof It is immediate that any polynomial T, satisfies T,• = T,mod f.
Suppose now that for all T,. I.; i.; n-I, the factorization off afforded by
(4.2) were trivial. This means that there exist elements c1,. •• ,c._1 E F • such
that T,(x) = c1modf(x) for 1.; i.; n -I. With c0 = N, viewed as an ele
ment of IF •• we get T(x') = c,modf(x) for 0 .;i.; n -I. For any
n -1
g(x)= La1x1EF.[x]
i-1
of degree less than n we have then (n-1 ) n-1 n-1
T(g(x)) = T
1�0 a1x1 = 1�0 a1T(x') = 1�0 a1c1modf(x).
I. Factorization over Small Finite Fields
Putting
we obtain n -I
c(g)� L a1c1EF,.
;-o
T( g ( x)) = c ( g )mod .0 ( x) for I " j " k. 135
(4.7)
Since N � lcm(n1, •••• n.), at least one of the integers N/nj, say Njn1, is not
divisible by the characteristic of F q· Let 61 be a root of /1 in the splitting
field F1 of /1 over F •. Because of Theorem 2.23(iii) there exists g1 EIF.[x]
with
TrF/F (g1(61)}�1. ' . (4.8)
Since k ;;. 2 by assumption, we can apply the Chinese remainder theorem to
obtain a polynomial g E IF q[x] of degree < n with
g = g1modfp g = Omod/2.
From (4.8) and (4.9) we deduce that
TrF/F (g(61)) �I, ' .
and Theorems 2.23(iv) and 2.26 imply that
TrF/F,(g(61)) � N/n1• (4.9)
Because of the definitions of the trace and of the element 61, it follows that
T(g(x)) = N/n1modf1(x).
However, the second congruence in (4.9) leads to T(g(x))=Omodf2(x),
and since N/n1 * 0 as an element of "•· we get a contradiction to (4.7).
Therefore, at least one of the T,. I" i" n-I, is /-reducing. 0
4.4. Example. Factor f(x) � x11 + x14 + x13 + x12 + x" + x10 + x9 + x'
+ x1 + x5 + x4 + x +I over IF2. We have gcd(/(x), f'(x)) = x10 + x' +I,
and sof0(x) = f(x)jgcd(f(x),f'(x)) = x1 + x5 + x4 + x +I has no repeated
factors. We factor /0 by finding an fo-reducing polynomial of the type
described above. To this end, we calculate the powers x, x2, x4, •.• mod f0(x)
until we obtain the least positive integer N with x2" = xmod f0(x ). We
simplify the notation by identifying a polynomial "f.7::d a1x1 with the n-tuple
a0a1 • • • a._1 of its coefficients, so that, for instance, f0(x) = IJOOllOL The
calculation of the required powers of xmod f0(x) is facilitated by the
observation that squaring a polynomial a0a1 • • • a6mod /0(x) is the same as
multiplying the vector a0a1 • • ·a, by the 7 x 7 matrix of even powers
136 Factorization of Polynomials
x0, x2, .•• ,x12modf0(x). This matrix is obtained from
x0 =I 0 0 0 0 0 0
x2 =0 0 I 0 0 0 0
x4 =0 0 0 0 I 0 0
x6 =0 0 0 0 0 0
x8 = 0 I 0 0 I
x10 =I 0 I I 0 0
x12 =0 0 0 0
where all the congruences are mod/0(x). Therefore we get mod/0(x):
x=O I 0 0 0 0 0
x2 =0 0 I 0 0 0 0
x4 =0 0 0 0 I 0 0
x8 =0 I 0 0 I I
xl6 =I I 0 I 0 0 0
x32 =I 0 I 0 0 0
x64 =I 0 0 0 0
x\28 = I I I 0 I 0 I
x256 = I 0 0 0 0 I 0
XS\2 =: Q 0 I I 0 0 I
x1024 = 0 0 0 0 0 0
Thus N � 10 and
9
T1( x) � L x2' =I I 0 0 0 I mod/0(x).
j=O
Since T1(x) is not congruent to a constant modf0(x), T1(x) isfo-reducing.
We have
ged(/0(x),T1(x)}�ged(l I 0 0 I I 0 I, I I I 0 0 0 I}
= xs + x4 + x3 + x2 + I'
gcd(/0(x},T1(x}-I}�ged(l I 0 0 I I 0 1,0 I I 0 0 0 I)
= x2 + x +I,
and so
/0 ( x} � ( x' + x4 + x3 + x2 + I)( x2 + x + I).
The second factor is obviously irreducible in f2[x]. Since N � 10 is the least
common multiple of the degrees of the irreducible factors of /0 ( x ), any
nontrivial factorization of the first factor would lead to a value of N
different from 10, so that the first factor is also irreducible in IF2[x].
I. Factorization over Small Finite Fields 137
It remains to factor gcd(/(x), f'(x) )�x10+x8+1 . We have
x10 + x8 +I� (·x' + x4 + 1)2, and by checking whether x' + x4 +I is divisi
ble by one of the irreducible factors of f0(x), we find that x' + x4 +I�
(x' + x + l)(x2 + x + 1), with x' + x +I irreducible in F2[x]. Hence
f( x) � ( x' + x4 + x' + x2 + i)( x' + x + 1)2( x2 + x + 1)3
is the canonical factorization ofj(x) in IF2[x]. 0
It should be noted that, in general, the /-reducing polynomials T, do
not yield the complete factorization off since the T, are not able to separate
those irreducible factors� for which N/n1 is divisible by the characteristic
of IF •. In practice, however, one calculates the first /-reducing T, and then
calculates new T, for each of the resulting factors. In this way, one
eventually obtains the complete factorization of f.
It is, however, possible to construct a related set of polynomials R 1
that are capable of separating all the irreducible factors off at once. We
assume, without loss of generality, that /(0) * 0. Let ord(/(x)) � e, so that
f(x) divides x' -I. Since f has no repeated factors, e and q are relatively
prime by Corollary 3.4 and Theorem 3.9. For each i;;. 0 let m, be the least
positive integer with
Then we define x'•"· = x'modf(x).
Since (4.10) is equivalent to
iqm·=imode, (4.10)
(4.11)
which is in tum equivalent to qm; =I mod( ejgcd(e, i)), it follows that m,
can also be described as the multiplicative order of q moduloej gcd(e, i). A
comparison with the definition of T,(x) shows that
T,(x) = �R,(x)modf(x). m,
It is clear that R7 = R,modjfor all i, so that the R, can be used in (4.2) in
place of h. We prove now the claim about the R, made above.
4.5. Theorem. Let f be monic and reducible in IF .[x] with no repeated
factors, and suppose that f(O) * 0 and ord(f) �e. Then, if all the polynomials
R,, 1,. i"" e-I, are used in (4.2), they will separate all irreducible factors of
f.
Proof Let h(x)�E�.::Ja1x1EF.[x] be a solution of h(x)•=
h(x)mod(x' -1). If we interpret subscrip ts mod e, then h(x) =
E7.::d a,.x'•mod (x' -I) since iq, i � O,l, ... ,e -I, runs through all residues
!38 Factorization of Polynomials
mode as q and e are relatively prime. Since h(x )q = L�.:ci a,.x,.q, we get
e -I e -I
L a,x'• = L a,.x'•mo d(x' -I).
i-0 i-0
By considering the exponents mode, it follows that corresponding coeffi
cients are identical. Thus a,.= a,.q for all i, and so a;= a1q = a;q2 = · · · for
all i. Since m, is the least positive integer for which (4.11) holds, we obtain
h(x)= L a,R,(x)mod(x'-1),
iEJ
where the set J contains exactly one representative from each equivalence
class of residues mode determined by the equivalence relation -which is
defined by i1-i2 if and only if i1 = i2q'mod e for some I;. 0. Thus, for
suitable b, E IF q we have
•-1
h(x)= L b,R,(x)mod(x'-1).
;-o (4.12)
Let now /1 (x) and /2(x) be two distinct monic irreducible factors of f(x ),
and so of x'-I. By the argument leading to (4.3), there is a solution
h(x) E IFq[x] of h(x)• = h(x)mod(x' -I), deg(h(x)) < e, with
h(x) =Omod/1(x), h(x) = lmod/2(x). (4.13)
Since Rf = R,mod f, the argument subsequent to (4.3) shows that there
exist elements cil, c, E Fq with R1(x) = c,1modf1(x), R,(x) = c,modf2(x)
for 0.;; i .;; e-I. If we had cil = c, for 0.;; i.;; e-I, then it would follow
from (4.12) that h(x) = cmodf1(x), h(x) = cmodf2(x) for some c E Fq, a
contradiction to (4.13). Thus cil * c, for some i with 0.;; i.;; e -1, and since
R0(x) =I, we must have i ;.I. Then R,(x)-c,1 will be divisible by f1(x),
but not by /2(x). Hence the use of this R,(x) in (4.2) will separate f1(x)
fromf2(x). D
The argument in the proof of Theorem 4.5 shows, of course, that the
polynomials R1, with i running through the nonzero elements of the set J,
are already separating all irreducible factors of f. However, the determina
tion of the set J depends on knowing the order e, and a direct calculation of
e (i.e., one that does not have recourse to the canonical factorization of f)
will be lengthy in most cases.
This problem does not arise in the special cases f(x) = x' -I
and f(x) = Q,(x), the eth cyclotomic polynomial, since it is trivial that
ord(x' -I)= ord(Q,(x)) =e. The polynomials R, are, in fact, well suited
for factoring these binomials and cyclotomic polynomials.
2. Factorization over Large Finite Fields 139
4.6. Example. We determine the canonical factorization of the cyclo
tmnic polynomial Q,(x) in F3[x]. According to Theorem 3.27 we have
(x" -l)(x2 -I)
Q,(x)� (x26-I)(x4-l)
= x24 _ x22 + x2o _ x1s + x\6 _ x\4 + x\2
- xlo + xs-x6 + x4- x2 +I.
Now R1(x) = x + x3 + x9 + x27 + x81 + x243, and since x26 ==
-I modQ12(x), we_get R 1(x) = OmodQ1 2(x), so that R1 is not Q12-reduc
ing. With R2(x) � x2 + x' + x18 we get
gcd(Q,(x), R2(x)) � x'-x2 +I,
gcd(Q,(x), R2(x)+ I)� x' + x4- x2 +I,
gcd(Q,(x), R2(x)-I) � x12 + x10-x' + x' + x4 + x2 +I� g(x),
say, so that (4.2) yields
Q, ( x) � ( x'-x2 + I)( x' + x4-x2 + I )g( x).
By Theorem 2.47(ii), Q12(x) is the product of four irreducible factors in
F3[x] of degree 6. Thus, it remains to factor g(x). Since R3(x) � x' + x9 +
x21 + x81 + x243 + x129 = OmodQ1 2(x), we next use R4(x) � x4 + x12 + x".
We note that x12 = -x10 + x8 -x6 - x4 -x2 - I mod g(x), x36 ==
- x10mod g(x), and so
R4(x) =x10 + x'-x6 -x2 -I modg(x).
Therefore ,
gcd(g(x), R4(x)) � gcd(g(x), x10 + x'-x'- x2 -1) �I,
gcd(g(x), R4(x)+I) � gcd(g(x),x10 + x'-x' -x2) �x'- x4+ x2 +I,
gcd(g(x), R4(x)-1) � gcd(g(x), x10 + x'-x'-x2 +I)� x6-x4 +I.
Thus,
Q, ( x) � ( x6-x2 + I)( x' + x4- x2 + I)( x'-x4 + x2 + I)( x6 -x4 + I)
is the desired canonical factorization.
2. FACI'ORIZATION OVER LARGE FINITE FIELDS D
If IF 9 is a finite field with a large number q of elements, the practical
implementation of the methods in the previous section will become more
difficult. We may still be able to find an [-reducing polynomial with a
reasonable effort, but a direct application of the basic formula ( 4.2) will be
140 Factorization of Polynomials
problematic since it requires the calculation of q greatest common divisors.
Thus, to make the use of /-reducing polynomials feasible for large finite
fields, it is imperative that we devise ways of reducing the number of
elements c E IF • for which the greatest common divisor in ( 4.2) needs to be
calculated. We note that in the context of factorization we consider q to
be "large" if q is (substantially) bigger than the degree of the polynomial to
be factored.
Letfagain be a monic polynomial in IF,[x] with no repeated factors,
let deg(f) � n, and let k be the number of distinct monic irreducible factors
of f. Suppose that hE F,[x] satisfies h• = hmodf and 0 < deg(h) < n, so
that h is /-reducing. Since the various greatest common divisors in (4.2) are
pairwise relatively prime, it is clear that at most k of these greatest common
divisors will be "' l. The problem is to find an a priori characteriz ation of
those c E IF • for which gcd(/(x ), h (x )-c)"' l.
One such characterizat ion can be obtained by using the theory of
resultants (see Definition 1.93 and the remarks following it). Let
R(f(x),h(x)-c) be the resultant of f(x) and h(x)-c, where the degrees
of the two polynomials are taken as the formal degrees in the definition of
the resultant. Then gcd(/(x),h(x)-c)*l if and only if R(f(x),h(x)-c)
� 0. We are thus led to consider
F(y) � R(/(x), h(x)-y),
which, from the representation of the resultant as a determinant, is seen to
be a polynomial iny of degree.; n. Then we have gcd(/(xJ, h(x)-c)"' 1 if
and only if cis a root of F(y) in F ,.
The polynomial F(y) may be calculated from the definition, which
involves the evaluation of a determinant of order .; 2n- 1 whose entries are
either elements of F • or linear polynomials in y. In many cases it will,
however, be preferable to use the following method. Choose n + 1 distinct
elements c0, c1, •••• c, E F • and calculate the resultants r1 � R(f(x ), h (x )-c,)
for 0 .; i.; n. Then the unique polynomial F( y) of degree .; n with F( c,) � r,
for 0.; i.; n is obtained from the Lagrange interpolation formula (see
Theorem 1.71). This method has the advantage that if any of the r, are 0, we
automatically get roots of the polynomial F(y) in F,. At any rate, the
question of isolating the elements c E IF • with gcd(/(x ), h(x )-c)"' 1 is now
reduced to that of finding the roots of a polynomial in IF,. Computational
methods for dealing with this problem will be discussed in the next section.
4.7. Example. Factor f(x) � x6-3x' + Sx4-9x3 -Sx2 + 6x +7 over
F23. Since gcd(/(x), f'(x)) � l.f(x) has no repeated factors. We proceed by
Berlekamp's algorithm and calculate x231modf(x) for 0.; i.; 5. This yields
2. Factorization over Large Finite Fields 141
the 6 X 6 matrix
I 0 0 0 0 0
5 0 -I 8 -3 -10
B= -10 10 10 0 I -9
0 7 9 -8 10 -II
II 0 -4 7 7 2
-3 0 -10 9 2 -9
and thus B - I is given by
0 0 0 0 0 0
5 -I -I 8 -3 -10
B-I= -10 10 9 0 I -9
0 7 9 -9 10 -II
II 0 -4 7 6 2
-3 0 -10 9 2 -10
Reduction to column echelon form shows that B-I has rank r = 3, so that
I has k = 6-r = 3 distinct monic irreducible factors in IF 23 [X]. A basis for
the null space of B -I is given by the vectors h 1 = (I, 0, 0, 0, 0, 0), h 2 =
(0,4,2, 1,0,0), h3 = (0, -2,9�0, I, 1), which correspond to the polynomials
h1(x)=l, h2(x)=x3+2x2+4x, h3(x)=x5+x4+9x2-2x. We take the
/-reducing polynomial h 2 ( x) and consider
F(y) = R{!(x),h2(x)-y)
I -3 5 -9 -5 6 7 0 0
0 I -3 5 -9 -5 6 7 0
0 0 I -3 5 -9 -5 6 7
I 2 4 -y 0 0 0 0 0
0 2 4 -y 0 0 0 0
0 0 I 2 4 -y 0 0 0
0 0 0 2 4 -y 0 ·o
0 0 0 0 ]• 2 4 -y 0
0 0 0 0 0 2 4 -y
In this case a direct computation of F( y) is feasible, and we obtain
F(y)=y6+4y5+3y4-1y3+IOy2+IIy+1. Since f has three distinct
monic irreducible factors in F23[x], the polynomial F can have at most three
roots in IF 23. By using either the methods to be discussed in the next section
or trial and error, one determines the roots ofF in IF23 to be -3, 2, and 6.
Furthermore,
gcd(/(x ), h2(x )+3) = x -4,
gcd(!(x), h2(x)-2) = x2- x + 7,
gcd(/(x ), h2(x) -6) = x3 + 2x2 +4x-6,
142 Factorization of Polynomials
so that
f(x) � (x -4)(x2-x +7)(x3 + 2x2 +4x -6)
is the canonical factorization of f(x) in F23[x). D
Another method of characterizing the elements c E IF q for which the
greatest common divisors in ( 4.2) need to be calculated is based on the
following considerations. With the notation as above, let C be the set of all
c E F• such that gcd( f(x), h(x)-c)* I. Then (4.2) implies
f(x)� n gcd(!(x),h(x)-c), (4.14)
,ec
and sof(x) divides n,ec(h(x)- c). We introduce the polynomial
G(y)� 0 (y-c).
,e c
Thenf(x) divides G(h(x)) and the polynomial G(y) may be characterized
as follows.
4.8. Theorem. Among all the polynomials g E IF•[y) such that f(x)
divides g(h(x)), the polynomial G(y) is the unique monic polynomial of least
degree.
Proof We have already shown that the monic polynomial G(y) is
such that f(x) divides G(h(x)). It is easily seen that the polynomials
g E F•[y) with f(x) dividing g(h(x)) form a nonzero ideal of F•(y). By
Theorem 1.54, this ideal is a principal ideal generated by a uniquely
determined monic polynomial G0 E F•[y). It follows that G0(y) divides
G(y), and so
Go(y)� 0 (y-c)
c e c1
for some subset C1 of C. Furthermore, f(x) divides G0(h(x)) �
n,.ec,(h(x)-c), and hence
f(x) � n gcd(/(x), h(x)-c).
,.e c1
A comparison with (4.14) shows that C1 �C. Therefore G0(y) � G(y), and
the theorem follows. D
This result is applied in the following manner. Let m be the number
of elements of the set C. Then we write
m
G(y)� n (y-c)� L bjyi
rEC j=O
2. Factorization over Large Finite Fields
wilh coefficienls b1 E IF •. Now f(x) divides G(h(x)). so !hal we have
"' L b1h(x)' = Omodf(x).
J=O 143
Since bm = I, this may be viewed as a nontrivial linear dependence relation
over Fq of !he residues of I, h(x), h(x)2, ..• ,h(x)"'modf(x). Theorem 4.8
says !hal wilh !he normalizalion b., � I !his linear dependence relalion is
unique, and !hal !he residues of l,h(x),h(x)2, ••• ,h(x)"'-1modf(x) are
linearly independenl over IF •. The bound m.; k follows from (4.14).
The polynomial G can !hus be de!ermined by calculaling !he residues
modf(x) of I, h(x), h(x)2, ... unlil we find !he smallesl power of h(x) !hal
is linearly dependenl (over IF•) on its predecess ors. The coefficienls of !his
firs! linear dependence relalion, in !he normalized form, are !he coefficienls
of G. We know !hal we need no! go beyond h(x)k 10 find !his linear
dependepce relalion, and k can be obtained from Berlekamp's algorilhm.
The elemenls of C are now precisely !he rools of !he polynomial G. This
mel hod of reducing !he problem of finding !he elemen Is of C lo !hal of
calculaling !he rools of a polynomial in F q is called !he Zassenhaus algo
rithm.
4.9. Example. Consider again !he polynomial f E F23[x] from Example
4.7. From Berlekamp's algorilhm we oblained k � 3 and !he /-reducin g
polynomial h(x) � x3 + 2x2 + 4x E f,23[x]. We apply !he Zassenhaus
algorilhm in order 10 de!ermine !he elemenls c E.JF23 for which gcd(/(x),
h(x)-c)* I. We have
h(x) = x3 +2x2 +4x modf(x),
h(x)2 = 7x5 +7x4 +2x3 -2x2 -6x -1modf(x),
and so i! is clear !hal h(x)2 is no! linearly dependenl on I and h(x).
Therefore, h(x)3 musl be !he smallesl power of h(x) !hal is linearly
dependenl on ils predecessors . We have
h(x)3 = -llx5 -llx4-x3 -9x2 -5x -2modf(x),
and !he linear dependence relalion is
h(x )3-5h (x )2 + llh (x )-10 = 0 modf(x ).
so !hal G( y) � y3-5 y2 + lly-10. By using eilher !he mel hods lo be
discussed in the next section or trial and error, one determines the roots of
G lo be -3, 2, and 6. The canonical faclorizalion off in F,[x] is !hen
oblained as in !he las! par! of Example 4. 7. 0
A me!hod !hal is conceplually more complica!ed, bu! of greal
!heorelical inleresl, is based on !he use of malrices of polynomials . By a
144 Factori zation of Polynomials
matrix of polynomials we mean here a matrix whose entries are elements of
F •[x].
4.10. Definition. A square matrix of polynomials is called nonsingular if
its determinant is a nonzero polynomial, and it is called unimodular if its
determinant is a nonzero element of IF q·
4.11. Definition. Two square matrices P and Q of polynomials are said to
be equivalent if there exists a unimodular matrix U of polynomials and a
nonsingular matrix E with entries in F• such that P � UQE.
It is easily verified that this notion of equivalence is an equivalence
relation, in the sense that it is reflexive, symmetric, and transitive.
We have seen in Section 1 that there are polynomials h 2, ...• h. E
F•[x] with 0 < deg(h1) < deg(/) for 2.;, i.;, k, which together with h1 � 1
are solutions of h• = h mod f that are linearly independent over F q· Clearly,
the polynomials h 1 may be taken to be monic. The following theorem is
fundamental.
4.12. Theorem. Let f � /1 • • • /,, where f1, ••• ,f, are distinct monic
irreducible polynomials in F q[ x ], and let h 2, ... , h k E IF •[ x] be monic po(v
nomials with O<deg(h1 )<deg(f)for 2.;,i.;,k, which together with h1�1
are solutions of h • = h mod f that are linearly independent over IF q· Then the
diagonal matrix of polynomials
/, 0 0
0 /, 0
D� 0 0 /,
0 0 0
is equivalent to the matrix of polynomials
I 0 0
h, -1 0
A� h, 0 -1
h, 0 0 0
0
0
f.
0
0
0
-1
Proof By the argument following (4.3) we have h1(x) = e11mod /j(x)
with e11 E F• for 1.;, i,j.;, k. Let E be the k X k matrix whose (i, j) entry is
e,J' We show first that E is nonsingular. Otherwise, there would exist
2. Fac10rizalion over Large Finite Fields
elements d 1, ... , d, E F •' not all zero, such that
'
This implies that
' L, die if= 0 for 1 � j -E:; k.
i-1
L d,h, = OmodJ; for l<i: j <i: k,
i-1 t45
and so L.�_,d,h, = 0 mod f. Since deg(h,) < deg(/) for I <i: i <i: k, it follows
that L.7_,d,h, � 0, a contradiction to the linear independence of h, .... ,h,.
Next we note that AE is a nonsingular matrix of polynomials. Thus
we can write D � ( D(AE)-1)AE, so that the theorem is established once
we have shown that U � D(AE)-1 is a unimodular matrix of polynomials.
Let b,j E F q[x) be the (i, j) entry of AE. Then b1j � le1j �I=
Omod.fj 'for l"j-E;;k, and for 2-E;;i.E:;k we have bl1=hie11-eij=
h,-eij = OmodJ; for l<i: j <i: k, so that
Now b,,=Omod.t; for l<i:i,j,.k. (4.15)
_, I (-!)'-' (AE) � det(AE) (B,J,�•.j�' � det(E)I (B,J,�,,J�''
where B,j is the cofactor of the (J, i) entry in AE,_and
-1 (-!)'-' U� D(AE) � det(E)I (/.B,J,�,,j�,.
Since (4.15) implies that B,j = Omod(// /,), it follows that each entry of U is
a polynomial over f q· Furthermore,
det(U) � det(D)
det(AE) t=-L
det( E) '
which is a nonzero element of F q· Thus, U is a unimodular matrix of
polynomials. D
Theorem 4.12 leads to the theoretical possibility of determining the
irreducible factors of I by diagonalizing the matrix A. The number k as well
as the entries h2, ... ,h, in the first column of A can be obtained with
relative ease by Berlekamp's algorithm. The algorithm that achieves the
diagonalization of A is, however, quite complicated.
The diagonalization algorithm is based on the use of the following
elementary operations: (i) permute any pair of rows (columns); (ii) multiply
any row (column) by an element ofF;; (iii) multiply some row (column) by
a monomial (element of Fq) and add the result to any other row (column).
146 Factorization of Polynomials
The elementary row operations may be performed by multiplying the
original matrix from the left by an appropriate unimodular matrix of
polynomials. whereas the elementary column operations may be performed
by multiplying the original matrix from the right by an appropriate nonsin
gular matrix with entries in F •. Therefore, the new matrix obtained by any
of these elementary operations is equivalent to the original matrix.
One can show that A is equivalent to a matrix R of polynomials with
the property that for each row of R the degree of the diagonal entry is
greater than the degrees of the other entries in the row. The matrix R can be
computed from A by performing at most (26 + k -IXk -I) elementary
operations, where 6 � deg( h 2) + · · · + deg( h k ).
We note that the diagonal entries of R can be permuted by carrying
out suitable row and column permutations. We can thus obtain a matrix S
that, in addition to the property of R stated above, satisfies deg(s;;);;. deg(s1)
for I.; i.; j.; k, where the s;; are the diagonal entries of S. By multiplying
the rows of S by appropriate elements ofF;. if necessary, we may assume
that the s;; are monic polynomials. A matrix S of polynomials with all these
properties is called a normalized matrix.
The diagonal entries of the matrix D in Theorem 4.12 may also be
arranged in such a way that deg(/,);;. deg(j;J for !.; i.; j.; k. The result
ing equivalent matrix, which we again call D, is then diagonal and normal
ized. Using the fact that the normalized matrix Sis equivalent to D, one can
then show that deg(s,,) � deg(/,) for I.; i.; k. Thus, one can read off the
degrees of the various irreducible factors of I from the diagonal entries of S.
Furthermore, if dis a positive integer which occurs as the degree of somes",
and if S(d> is the square submatrix of S whose main diagonal contains
exactly all s,, of degree d, then one can prove that the determinant of S(Jl is
equal to the determinant of the corresponding submatrix of D. Thus
det(S("') � gd, where gd is the product of all/, of degree d. In this way we
are led to the partial factorization
I� [Jgd, (4.16)
d
where the product is over all positive integers d that occur as the degree of
some/,.
In summary, we see that the matrix S can be used to obtain the
following information about the distinct monic irreducible factors of f:
the degrees of these factors, the number of these factors of given degree, and
the product of all these factors of given degree. If the /, have distinct
degrees, or, equivalently, if the s,, have distinct degrees, then (4.16) repre
sents already the canonical factorization of I in IF .lx ].
If ( 4.16) is not yet the canonical factorization, then one can proceed
in various ways. An obvious option is the application ofone of the methods
discussed earlier to factor the polynomials gd. One can also continue with
2. Factorization over Large Finite Fields 147
the diagonalization algorithm in order to obtain the diagonal matrix D
equivalent to the normalized matrix S.
For the latter purpose, we assume as above that D is put in
normalized form. In addition to the properties mentioned above, it is then
also true that each of the submatrices s<•> is equivalent to the correspond
ing submatrix D<•> of D. It is therefore sufficient to diagonalize each of the
submatrices s<d> separately. By the equivalence of s<d> and D<d> we have
s<•> � UD<•>£ for some unimodular matrix U of polynomials and some
nonsingular matrix E with entries in F •. We may then write
s<d> � s<d> + s<d>x + · · · + s<d>xd 0 I d '
where the s:•>, D:•>, and U,, 0"' r"' d, 0 .,, "' m, are matrices with entries
in F •' Um * 0, and SJdl � DJd> � I, the identity matrix of appropriate order.
A comparison of the matrix coefficients of the highest powers of x on both
sides of the equation s<•> � UD1d1E yields I� UmiE and m � 0. Thus,
U � U0 � E-1 and hence s<d> � E-1D<•>£.
Comparing the matrix coefficients of like powers of x in the last
identity gives S,ldl = E-1D,Id>£ for 0 .,., "'d. Consequently, s,<dl and D,<dl
have the same characteristic polynomial and eigenvalues, and since D,ldl is
diagonal, its eigenvalues are exactly its diagonal entries. Therefore, the latter
can be determined by finding the roots of the characteristic polynomial of
s:dl, which must all be in IF •. As in the earlier methods, we have thus again
reduced the factorization problem to that of finding the roots of certain
polynomials in IF •.
The partial factorization (4.16) can also be obtained by an entirely
different method. To this end, we extend the definition of gd by letting g1,
i ;.I, be the product of all monic irreducible polynomials in IF.[x] of degree
i that divide f. In particular, g1(x) �I in case f has no irreducible factor in
IF•[x] of degree i. We can thus write
t� flg,
i�l
It is trivial that only those i with i "'deg(f) need to be considered.
We calculate now recursively the polynomials . r0(x), r1(x),... and
F0(x), F1(x), ... as well as d1(x), d2(x), .... We start with
r0(x) � x, F0(x) � f(x),
148 Factorization of Polynomials
and for i ;;. I we use the formulas
r1 (x) = r1_1 ( x) •mod £,_1 (x ), deg( r,) < deg( £,_1 ),
d1(x) � gcd( £,_1 (x ), r1(x )-x ),
F,(x) � £,_1(x )/d,(x ).
The algorithm can be stopped when d1(x) � £,_1(x ).
4.13. Theorem. With the notation above, we have d,(x) � g1(x)for
al/i;.l.
Proof Using the fact that F, divides£,_ 1, a straightforward induc
tion shows that
r1(x) = x•'mod £,_1 (x) for all i;;. I.
We prove now by induction that
F,-1� ngj and d,�g, foralli>l. jtJoi ( 4.17)
(4.18)
For i �I the first identity holds since F0 �f. As to the second identity, we
have
d1 (x) � gcd( F0(x ), r1 (x )-x): gcd(f(x ), x•-x)
by (4.17), and since x•-xis the product of all monic linear polynomials in
F.[x], it follows that d1 is the product of all monic linear polynomials in
F.[x] dividing/, and hence d1 � g1. Now assume that (4.18) is shown for
some i ;;. I. Then
r; � r:-1/d, � r;_ ,;g, � n gj.
j "> i +I ( 4.19)
which proves the first identity in ( 4.18) for i + I. Furthermore,
d,+ 1 (x) � gcd( F,(x ), r1+ 1 (x )-x) � gcd( F,(x ), x•"'-x)
by (4.17). According to Theorem 3.20, x•"'-xis the product of all monic
irreducible polynomials in F.[x] whose degrees divide i+ I. Consequently,
d1 + 1 is the product of all monic irreducible polynomials in F •[ x] that divide
F, and whose degrees divide i + I. It follows then from ( 4.19) that d1+ 1 � g1+ 1.
D
In the algorithm above, the most complicated step from the view
point of calculation is that of obtaining r1 by computing the qth power of
r1 _ 1 mod F, _ 1. A common technique of cutting down the amount of calcula ·
tion somewhat is based on computing first the residues mod F, _ 1 of
r; _ 1, r/:_ 1, r;4_ 1, ••• , r/:_ 1 by repeated squaring and reduction mod F; ___ 1, where
2' is the largest power of 2 that is " q, and then multiplying together an
appropriate combination of these residues mod £,_1 to obtain the residue of
2. Factorization over Large Finite Fields 149
r;'�_1mod£,-_1. For instance, to get the residue of r;�1mod�_1, one would
multiply together the residues of r;1� 1, r;"� .. 1, r;:_1, and r;_1mod �-J·
Instead of working with the repeated squaring technique, we could
employ the matrix B from Berlekamp 's algorithm in Section I to calculate r1
from r1_1• We write n � deg(f) and
n-l
r;-J (x) = E r/:!.�xi,
J-0
and define (s;(O),sp), ... ,s;<n-ll)EF; by the matrix identity
( s;<O)' S;(J)' ... ,sfn-I))= ( r;'f3_)1' r/!._)1• .... r/�11)) B,
where B is the n X n matrix in (4.5). With
n-l
s,(x)= L s1Ulxj
J-0 ( 4.20)
(4.21)
we get then r1_1(x)• = s,(x)modf(x), hence r1_1(x)• = s,(x)mod £;_1(x),
and thus
Therefore. once the matrix B has been calculated, we computer; from r;_1 in
each step by reduction mod £,_1 of the polynomials, obtained from (4.20)
and (4.21).
4.14. Example. We consider f(x)�x6- 3x5+5x4-9x3-5x2+6x+
7EIF23[x] as in Example4.7. Then
I 0 0 0 0 0
5 0 -I 8 -3 -10
B= -10 10 10 0 I -9
0 7 9 -8 10 -II
II 0 -4 7 7 2
-3 0 -10 9 2 -9
We start the algorithm with r0(x) = x, F0(x) = f(x). From (4.20) and (4.21)
we get s1 (x) � -lOx' -3x4 + 8x3 -x2 + 5, and reduction mod F0(x) yields
r1(x) = s1(x). By Theorem 4.13 we have g1(x) � d1(x) = gcd(F0(x),
r1(x)-x) � x -4. Furthermore, F1(x) � F0(x)jd1(x) = x' + x4 + 9x3 +
4x2 + llx +4.
In the second iteration, we use again (4.20) and (4.21) to obtain
s2(x)�5x5-8 x4+9x3-10x 2-ll, and reduction modF1(x) leads to
r2(x)=l0x4+10x3-7 x2-9x-8. By Theorem 4.13 we have g2(x)=
d2(x) = gcd(F1(x), r2(x)-x) = x2 -x + 7. Furthermore, F2(x) =
F1(x)jd2(x) = x' +2x2 +4x -6. But, according to the first part of (4.18),
all irreducible factors of F2(x) have degree;. 3, so that F2(x) itself must be
150 Factorization of Polynomials
irreducible in F23[x] and g3(x) � F2(x). Thus, we arrive at the partial
factorization
f(x) � (x -4)(x2-x +7)(x3 +2x2 +4x -6),
which, in this case, is already the canonical factorization off( x) in F 23 [ x]. D
3. CALCULATION OF ROOTS OF POLYNOMIALS
We have seen in the preceding section that the problem of determining the
canonical factorization of a polynomial can often be reduced to that of
finding the roots of an auxiliary polynomial in a finite field. The calculation
of roots of a polynomial is, of course, a matter of independent interest as
well.
In general. one will be interested in determining the roots of a
polynomial in an extension of the field from which the coefficients are
taken. However, it suffices to consider the situation in which we are asked to
find the roots of a polynomial f E IF q(x] of positive degree in IF •• since a
polynomial over a sub field can always be viewed as a polynomial over F q·
It is clear that every factorization algorithm is, in particular, a
root-finding algorithm since the roots off in F q can be read off from the
linear factors that occur in the canonical factorization off in Fq[x]. Thus,
the algorithms presented in the earlier sections of this chapter can also be
used for the determination of roots. However, these algorithms will often
not be the most efficient procedures for the more specialized task of
calculating roots. Therefore, we shall discuss methods that are better suited
to this particular purpose.
As a first step, one may isolate that part off which contains the roots
of fin IF •. This is achieved by calculating gcd(/(x), x•-x). Since x•-xis
the product of all monic linear polynomials in IF q(x], this greatest common
divisor is the product of all monic linear polynomials over F• dividing[, and
so its roots are precisely the roots off in F q· Therefore, we may assume,
without loss of generality, that the polynomial for which we want to find the
roots in IF q is a product of distinct monic linear polynomials over F q·
A useful method of finding roots of polynomials was already dis
cussed in Chapter 3, Section 4. It is based on the determination of an affine
multiple of the given polynomial. See Example 3.55 for an illustration of
this method.
In order to arrive at other methods, we consider first the case of a
prime field F ,. As we have seen above, it suffices to deal with polynomials
of the form
"
f(x)� n (x-c,),
i=l
3. Calculation of Roots of Polynomials !51
where c 1, ••• , c, are distinct elements of IF P" If p is small, then it is feasible to
determine the roots off by trial and error, that is, by simply calculating
f(O),f(I), ... ,f(p -I).
For large p the following method may be employed. For bE F,,
p odd, we consider
"
f(x-b)� n (x-(b+c,)). i=l
We note that f(x-b) divides x'-x � x(x<P-l)/2 + I)(x<p-l)/2-1). If x is
a factor of f(x-b), then/(-b)� 0 and a root off has been found. If xis
not a factor of f(x-b), then we have
f(x-b)� gcd{f(x-b), x<p-l)/2 + I}gcd(/(x-b), x<p-l)/2-I}.
( 4.22)
The identity (4.22) is now used as follows. We. calculate the residue
mod f(x-b) of x<p-l)/2 -for example, by the repeated squaring technique
discussed after Theorem 4.13. If x<p-l)/2�±Imodf(x-b), then (4.22)
yields a nontrivial partial factorization of f(x-b). Replacing x by x + b,
we get then a nontrivial partial factorization of f(x). In the rather unlikely
case where x<p-l)/2-= ±I mod/(x-b), we try another value of b. Thus, by
using, if necessary, several choices forb, we will find either a root off or a
nontrivial partial factorization of f. Continuing this process, we will eventu
ally obtain all the roots of f. It should be noted that, strictly speaking, this is
not a deterministic, but a probabilistic root-finding algorithm, as it depends
on the random selection of several elements b E F ,.
4.15. Example. Find the roots of f(x) � x6 -?x' + 3x4 -?x' + 4x2-
x-2 E F 17[x] contained in F 17• The roots of f(x) in IF 17 are precisely the
roots of g(x) � gcd(f(x), x11-x) in IF 17. By the Euclidean algorithm we
obtain g(x) � x4 + 6x'-5x2 + ?x-2. To find the roots of g(x ), we use the
algorithm above and first select b � 0. A straightforward calculation yields
x<p-l)/2 � x'-= I mod g(x ), and so this value of b does not afford a nontriv
ial partial factorization of g( x ). Next we choose b � 1. Then g( x -I) � x4
+2x' -3x -2 and x8 = -4x3 -7x2 + 8x -5mod g(x -I), so that b �I
yields a nontrivial partial factorization of g(x-1). We have
gcd( g(x -I), x8 +I}� gcd(x4 +2x' -3x -2, -4x3 -7x2 + 8x -4)
� x2 -?x +4
and
gcd( g(x-I), x8-I}� gcd(x4 +2x'-3x -2,-4x3 -7x2 + 8x -6)
=x2-8x+8,
152 Factorization of Polynomials
hence (4.22) implies
g(x -I)� (x2 -7x +4)(x2 -8x +8),
which leads to the partial factorization
g(x) � (x2 -5x -2)(x2 -6x +I)� g1(x)g2(x),
say. In order to factor g1(x) and g2(x), we try b � 2. We have g1(x -2) �
x2 + 8x-5 and x8 =-8x + 2mod g1(x-2). Furthermore,
gcd( g 1 ( x -2), x 8 + I} � gcd( x 2 + 8x -5, -8x + 3) � x + 6,
and long division yields g 1 ( x -2) � ( x + 6)( x + 2), so that
g1(x)� (x+8)(x+4).
Turning to g2(x), we have g2(x-2) � x2 +7x � x(x + 7), thus -2 is a root
of g2(x) and
g2(x)�(x+2)(x-8).
Combining these factorizations, we get
g(x) � (x + 8)(x +4)(x + 2)(x-8).
Therefore, the roots of g( x ), and thus of/( x ), in F 11 are -8, -4, -2, 8. D
Next we discuss a root-finding algorithm for large finite fields F •
with small characteristic p. As before, it suffices to consider the case where
n
/(x)�n(x-y,)
i-1
with distinct elements y1,. .. , Yn E F q· Let q � pm and define the polynomial
m-1
S(x) � L xP'
J-0
We note that for y E IF• we have S(y) � TrF,(y) E FP' where TrF, is the
absolute trace function (see Definition 2.22). Because of Theorem 2.23(iii),
the equation S( y) � c has pm-1 solutions y E F • for every c E F P' and this
observation leads to the identity
x•-x� n (S(x)-c). (4.23)
CE FP
Sincef(x) divides x•-x, we get
n (S(x)-c)=Omodf(x),
cE FP
and so
f(x)� n gcd(/(x),S(x)-c). (4.24)
CE fp
3. Calculalion of Rools or Polynomials 153
This yields a partial factorization of f(x) that calls for the calculation of p
greatest common divisors. If p is small, this is certainly a feasible method.
It can. however, happen th.at the factorization in (4.24) is
trivial-namely, precisely when S(x) = cmodf(x) for some c E FP" In this
case, other auxiliary polynomials related to S(x) have to be used. Let p be a
defining element of F• over FP, so that {l,{J,{J2, ... ,pm-l) is a basis of F•
over FP. For j � O,l, ... ,m -1 we substitute fJ'x for x in (4.23) and we get
(pi)"x•-pix� 0 (s(P'x)-c).
cEFP
Since ([Jf)• � {J1, we obtain
x•-x�p-, n (s(P1x)-c).
eEFP
This yields the following generalization of (4.24):
f(x)� 0 gcd(f(x),S([Jix)-c) forO,.;j,.;m-1. (4.25)
ceFP
We show now that if n � deg(f);. 2, then there exists at least one j,
0,.; j,.; m-1, for which the partial factorization in (4.25) is nontrivial. For
suppose, on the contrary, that all the partial factorizations in (4.25) are
trivial. Then for eachj, 0,.; j,.; m -1, there exists a c, E IFP with
s(pix) = cj�odf(x) ..
In particular, we get
s(piy,) � s(piy,) � cj for 0,. j .. m -1.
By the linearity of the trace it follows that
Tr.,((y1-y2)1Ji)�o forO,.;j,.;m-1
and
Using the second part of Theorem 2.24, we conclude that y1 -y2 � 0, which
is a contradiction. Thus, for at least one j the partial factorization in (4.25)
is nontrivial.
The defining element p of o=. over FP used in(4.25) is chosen as a
root of a known irreducible polynomial in IFP[x] of degree m. Once a
nontrivial factorization of the form (4.25) has been found, the method is
applied to the nontrivial factors by employing other values of j. The
argument above shows also that all distinct roots of f can eventually be
separated by using all the values of j in (4.25).
154 Factorization of Polynomials
4.16. Example. Consider IF64 = F2(,8), where ,B is a root of the irreducible
polynomial x6 + x + 1 in IF2[x], and let
f( x) = x' + ( ,B' + ,84 + ,83 + ,82 )x' + ( ,B' + ,84 + ,82 + ,B + 1 )x2
+ ( ,84 + ,83 + ,8) X + ,83 + ,8 E IF 64 [X].
Using
x6 = ( ,B' + ,B + 1) x' + ( ,B 4 + ,83 + ,B 2) x 2 + ( ,B' + ,B 3 + ,82 + 1) x
+ ,85 + ,8 4 + ,82 + 1 modf(x),
we get the following congruences mod f(x) by repeated squaring:
X
x'
(/14 + pJ + fj2)x'+
(/l� + /33 +.8lx3+ ({J� + p4 +/12 + P+ l)xl+(Jj4 + pJ +{J)x+ pJ + /1
(/1� + f1 + l)x2 +(/1� + p + l)x+ /1� + /14
( /33 + fl)x2. + f3�x + p4 + pl + p2 + fJ + I
Thus./(x) divides x64-x and so has four distinct roots in !'64• We consider
now S(x) = x + x2 + x4 + x8 + x16 + x32. From the congruences above we
obtain
S(x) = (,85 + ,83 + ,82 + ,B + l)x' + ,B5x2 + (,83 + .B')x
+,83+,82+l modf(x).
and therefore
gcd(/(x ). S(x )) = gcd(/(x ). ( ,B' + ,83 + ,82 + ,B + l)x3 + ,B'x'
+(,83 + ,B')x + ,83 + ,82 + 1)
=x' +(,84 + ,83 + ,82)x2 + (,B' + ,82 + l)x + ,83 + ,82 = g(x)
say, and
gcd(/(x), S(x)-1) = gcd(/(x),(,B' + ,83 + ,82 + ,B + l)x' + ,B'x'
+ (,83 + ,82) X+ ,83 + ,82) =X + ,85•
Then ( 4.24) yields
f(x)=g(x)(x+,B').
To find the roots of g(x), we next use (4.25) withj = 1. We have
S( ,Bx) = ,Bx + .B'x' + ,84x4 + ,B'x' + ,816x16 + ,B32x32
= ,Bx + ,B2x2 + ,84x4 + (,83 + ,82 )x'
+ (,84"+ ,B + l)x16 + (,83 + 1 )x32, (4.26)
3. Calculation of Roots of Polynomials !55
and the congruences above yield
S(/h) = ({32 + l)x' +({3' + f3 + l)x2 + ({35 + {34 + {33 + {32 + f3 + l)x
+ {34 + {32 + f3modf(x ).
Since g(x) divides f(x ), this congruence holds also mod g( x ), and so
S(f3x) = ({32 + l)x' +({33 + f3 + l)x2 +({35 + {34 + {33 + {32 +{3 + l)x
+{3'+{32+{3
= ( {35 + {32 )x2 + {33x + {35 + {33 + f3mod g( x).
Thus,
gcd( g (X), S( {3x)) � gcd( g( X), ( {35 + {32) X 2 + {33 X + f35 + {33 + {3)
�x2 + (f3' + l)x + {34 + {33 + {32 + {3� h(x),
say, and
gcd( g( X), S( {3x)-1) � gcd( g (X), ( {35 + {3 2) X 2 + {33 X + {3 5 + {33 + {3 + 1)
�x +{3' +{32 + 1.
Then (4.25) with}� 1 yields
To find the roots of h(x), we use (4.25) with} �·2. We have
s( f32x) � {32x + f34x2 + f38x4 + {316x8 + f3"x 16 + f364x32
� {32x + {34x2 + ( {33 + {32 )x4 + ( {34 + f3 + 1 )x8
+ ( {33 + 1 )x16 + f3x32,
and a similar calculation as for S(f3x) yields
S( {32 x) = ( {35 + {32 + 1 )x + {35 + {33 + {32 mod h ( x).
Therefore, ( 4.27)
gcd( h (X), S ( {3 2 X)) � gcd( h (X), ( f35 + {3 2 + 1) X + {3 5 + {3' + {3 2)
�x+f3+1
and
gcd( h (X), S( {3 2 X)-1) � gcd ( h (X), ( {35 + {3 2 + 1) X + {35 + {3 J + {3 2 + 1)
�x+f3'+f3,
so that from (4.25) with}� 2 we get
h (X) � (X+ {3 + 1 )(X+ {33 + {3). (4.28)
!56 Factorization of Polynomials
Combining (4.26), (4.27), and (4.28), we arrive at the factorization
/( x) � (x + fJ +I)( x + /l3 + fJ )( x + /l4 + /l2 + I)( x + fl'),
and so the roots ofj(x) are fJ +I, fl3 + fl, fl4 + /l2 +I, and fl5. 0
Finally we consider the root-finding problem for large finite fields F •
with large characteristic p. As we have seen before, it suffices to know how
to treat polynomials of the form
"
f(x)�n(x-y,) i-1
with distinct elements y1, ... ,y. ElF •. To check whether f(x) has this form,
we need only verify the congruence x• = xmod/(x) (compare with the first
part of Example 4.16). We can assume that q is the least power of p for
which this holds. The polynomial /(x) will. of course, be given by its
standard representation
"
f(x) � L a1x1,
j-0
where a1 E IF q for 0 � j � n and an = 1.
It will be our first aim to find a nontrivial factor of f(x ). To exclude
a trivial case. we can assume n ;. 2. Let q � pm and define the polynomials
"
j,(x) � L aJ'xi forO.;; k.;; m -I,
J-0 (4.29)
so that /0(x) � f(x) and each /,(x) is a monic polynomial over IF •.
Furthermore,
/, ( y(') � t o.j' Y/'' � ( t o.1 Y/) ,• � 0
J�O j-0
for 1 � i � n, 0 4; k � m -1, and so
"
/, (X) � n (X-Yr') for 0.;; k.;; m -J. i-1
We calculate now the polynomial
m -1
F(x)�nt,(x). k-0
This is a polynomial over F P since
m-1 n n m-1 n ( 4.30)
F(x) � n n (x-y('} � n n (x-yf') � n F,(x)m;d,,
k=O i-1 i-1 k=-0 i-1
where F,(x) is the minimal polynomial of y, over F, and d, is its degree
(compare with the discussion following Definition 2.22). The F,(x) are
3. Calculation of Roots of Polynomials 157
therefore the irreducible factors of F(x) in F,[x], but certain F,(x) could be
identical. Thus, the canonical factorization of F(x) in F,[x) has the form
F(x) �Gb)· · · G,(x), (4.31)
where the G,(x), I<;;l<;;r, are powers of the distinct F,(x). This canonical
factorization can be obtained by one of the factorization algorithms in
Section 2 of this chapter. Since f(x) � f0(x) divides F(x), it follows from
(4.31) that
f(x) � TI gcd(/(x),G,(x)). (4.32)
t-1
In most cases. (4.32) will provide a nontrivial partial factorization of
f(x). The factorization will be trivial precisely if gcd(/(x), G,(x))�j(x)
for some I, 1.;; I<;; r, which is equivalent tor� I andf(x) dividing F1(x). A
comparison of degrees shows then n � d 1 = m. Furthermore, the roots of
f(x) are then all conjugate with respect to IF,. Thus, by labelling the roots of
f(x) suitably, we can write
y,.=y(' for 1�i�n,with0=b1<b2<··· <bn<m.
We set bn+l = m and
· d� min (b,+1-b,).
I os; i <10: n
It is clear that d.;; mjn. The following two possibilities can occur:
(A) h;+ 1-h; > d for some i, 1 � i � n;
(B) b1+1-b,�dforalli,I.;;i.;;n.
In case (A) we note that the set of roots of f(x) is
{ ., r'' r'·) yf . "Y •.•.• "Y
and the set of roots of fd ( x) is
The condition in (A) implies that these two sets of roots are not identical.
On the other hand, since bi+l-h; = d for some i, 1 � i � n, the two sets of
roots have a common element. Thus, gcd(/(x),/d(x)) "'j(x) and"' I; that
is, gcd(/(x)./d(x)) is a nontrivial factor of j(x). We observe also that in
this case we have d < mjn.
In case (B) a comparison of the sets of roots ofj(x) andfd(x) shows
thatf(x) � fd(x), whereas gcd(/(x).f.(x)) �I for I.;; k <d. Moreover, we
have d�mjn, so that n divides m, and also b,�d(i-I) for l.;;i.;;n.lt
follows that
• .:t1 j- u f I . Yi = yf or � 1 � n,
158 Factorization of Polynomials
hence the y, are exactly all the conjugates of y1 with respect to IF, •.
Consequently, .J(x) is the minimal polynomial of y1 over IF,, and thus
irreducible over F Pd.
Therefore, corresponding to the cases (A) and (B) above we have the
following alternatives:
(A) gcd(f(x),f,(x)) is a nontrivial factor of f(x) for some
k,I.;k<m/n;
(B) gcd(f(x), /,(x)) �I for I.; k < d � mjn EN andf(x) � fa(x)
is the minimal polynomial of y1 over F, •.
In alternative (A) our aim of finding a nontrivial factor of f(x) has
been achieved.
Further work is needed in alternative (B). Let fJ again denote a
defining element of IF, over F ,. Then IF ,•( fJ) �IF,� IF,., and so fJ is of
degree m/d � n over F, •. In particular, we have fJ'"' If,, for I.; j.; n -I.
Now let the coefficients a1 of f(x) be such that a,,* 0 for some j0 with
I :!5; j0 :!5; n -I. Consider
(4.33)
which is a monic polynomial of degree n over IF_,. Since fJ"-''"' IF,, and
a10EIF; •. it_follows that the coefficient of x1' inf(x) is not an element of
IF, •. Thus f(x) is not a polynomial over F,,, and so _the alternative (B)
cannot occur if the procedure above is applied to f(x). Since f(x) �
fl"j( fl-1x ). any nontrivial factor of j(x) yields immediately a nontrivial
factor off ( x ).
It remains to consider the case where alternative (B) is valid and
a1 � 0 for I.; j.; n-I. Then f(x) is the binomial x" + a0 E F,.[x]. Now n
is not a multiple of p, for otherwise we would havef(x) � (x•IP + aS'-')P,
which would contradict the irreducibility of f(x) over IF, •. We set
(4.34)
and then it is easily seen from fJ-1 "' IF ,• that the coefficient of x"-1 in j( x)
is not in IF ,•. Thus, the alternative (B) cannot �ur if the procedure
described above is applied to f(x ). Since f(x) � fl"f( fl-1(x-I)), any non
trivial factor of /(x) yields immediately a nontrivial factor of f(x).
This root-finding algorithm is thus carried out as follows. We first
form the polynomials J,(x) according to (4.29) and then the polynomial
F(x) E IF,[x] according to (4.30). Next, we apply a factorization algorithm
to obtain the canonical factorization (4.31) of F(x) in IF,[x]. This leads to
the partial factorization of f(x) given by (4.32). Should this factorization be
trivial, we calculate gcd(f(x), /,(x)) for I.; k < mjn. If this also does not
produce a nontrivial factor of f(x). we transform f(x) into j(x) by either
(4.34) or (4.33), depending on whether f(x) is a binomial or not. As we have
shown above, an application of the algorithm to/< x) is bound to yield a
Exercises !59
nontrivial factor of /(x) and thus of l(x). Once a nontrivial factor of l(x)
has been found, the procedure is continued with the resulting factors in
place of l(x ), until l(x) is split up completely into linear factors.
EXERCISES
4.1. Factor x12 + x 7 + x5 + x4 + x' + x2 + 1 over F2 by Berlekamp's algo
rithm.
4.2. Factor x7 + x6 + x5-x' + x2-x-1 over F3 by Berlekamp's algo
rithm.
4.3. Let IF4=F2(8) and factor x5+8x4+x3+(1+8)x+8 over F4 by
Berlekamp's algorithm.
4.4. Use Berlekamp's algorithm to prove that x6-x' -x-1 is irreduc
ible in IF3[x].
4.5. Use Berlekamp's algorithm to determine the number of distinct
monic irreducible factors of x4 + 1 in F,(x] for all odd primes p.
4.6. Use the polynomials T; in Section 1 to factor x5 + x4 + 1 over F2.
4.7. Determine the splitting field of x8 + x6 + x5 + x4 + x' + x2 + 1 over
IF,.
4.8. Determine the splitting field of x6-x4-x2-x + 1 over F3.
4.9. Use the polynomials R, in Section 1 to factor the polynomial of
Exercise 4.1 over IF2•
4.10. Find the canonical factorization of x8 + x6 + x4 + x' + 1 in F2[x] by
using the polynomials R, in Section 1. ·.
4.11. Determine the canonical factorization of the cyclotomic polynomial
Q31(x) in IF2(x].
4.12. Factor l(x) = x8 + x' + 1 over F2 and determine ord(f(x)).
4.13. Factorl(x)=x9+x8+x7+x4+x 3+x+l overF2 and determine
ord(f(x)).
4.14. Prove in detail that if I is a nonzero polynomial over a field and
d = gcd(f, /'), then 1/d has no repeated factors. (Note: Count
nonzero constant polynomials among the polynomials with no re
peated factors.)
4.15. Let I be a monic polynomial of positive degree with integer coeffi
cients. Prove that if I has no repeated factors, then there are only
finitely many primes p such that 1. considered as a polynomial over
F,, has repeated factors.
4.16. Determine the number of monic polynomials in IF q[x J of degree n � 1
with no repeated factors.
4.17. Let I be a monic polynomial over "• and let g1, ••• ,g, be nonzero
polynomials over IF • that are pairwise relatively prime. Prove that if I
divides g, · · · g,. then I= n;_, gcd(f, g.J.
4.18. Use Berlekamp's algorithm to prove the following special case of
160 Factorization of Polynomials
Theorem 3.75: the binomialx'- a, where I is a prime divisor of q -1
and a E f;, is irreducible in f .[x 1 if and only if al•-l>l• *I.
4.19. Let/be an irreducible polynomial in IF.[x1 of degree nand define
the n X n matrix B = ( b,J) by (4.4). Prove that the characteristic
polynomial det( xi -B) of B is equal to x" -I.
4.20. Let f = f1 • • • /, be a product of k distinct monic irreducible poly
nomials /1, ... ,/, in IF.(x] of degree n1, ... ,n,, respectively. Put
deg(f) = n = n1 + · · · + n, and define then X n matrix B = (b,) by
(4.4). Prove that the characteristic polynomial det(x/-B) of B is
equal to (x"•-I)··· (x"• -I).
4.21. In the notation of Section I, prove that the polynomials T, do not
separate those irreducible factors.fj of/for which Njnj is divisible by
the characteristic of F q·
4.22. Let f E IF .[x 1 be monic of degree n;, I. Define hE F .[x, y] by
h(x,y)= (y-x)(y-x•)(y-x•')· · · (y-x•"-')-f(y)
and write
h(x,y)=s._1(x)y"-1+ ··· +s1(x)y+s0(x).
Prove that f is irreducible over F • if and only if f divides sj for
O�j�n-1.
4.23. Use the criterion in the preceding exercise to prove that x 7 + x6 +
x' + x2 +I is reducible over !'2.
4.24. Prove that the quadratic polynomialf(x) = x2 + bx +cis irreducible
over F • if and only if f(x) divides x• + x + b.
4.25. Let fbe an irreducible polynomial in IF .[x] of degree m and let h be a
root of/in IF ••. Let g and h be nonzero polynomials in F•(x]. Prove
that h(x)mf(g(x)jh(x)) is irreducible in F.(x] if and only if g(x)
Ah(x) is irreducible in f •• [x].
4.26. Use the method in Example 4.7 to factor x4 +3x3 +4x2 +2x -I
over f 13.
4.27. Use the method in Example 4.7 to factor x3 -6x2 -8x -8 over F19.
4.28. Use the Zassenhaus algorithm to factor x4 + 3x3 + 4x1 + 2x-I over
F n·
4.29. Use the Zassenhaus algorithm to factor x3 -6x2 -8x-8 over IF 19•
4.30. Use the Zassenhaus algorithm to factor x5 + 3x4 + 2x3 -6x2 + 5
over IF 17•
4.31. Factor x4 -7x3 + 4x2 + 2x + 4 over IF 17.
4.32. Factor x4 -3x3 + 4x2-6x-8 over IF 19.
4.33. Prove in detail that equivalence of square matrices of polynomials as
defined by Definition 4.11 is reflexive, symmetric, and transitive.
4.34. Use the method in Example 4.14 to factor x3 -6x2 -8x -8 over
F 19·
Exercises 161
4.35. Use the method in Example 4.14 to factor x' + 3x4 + 2x'-6x2 + 5
over IF 17.
4.36. Use the method in Example 4.14 to obtain a partial factorization of
x1-2x6-4x4 + 3x'-5x2 + 3x + 5 over IF 11 and complete the fac
torization by another method.
4.37. Find the roots of /(x)�x'-x4+2x3 +x2-x-2EIF5[x] con
tained in IF 5.
4.38. Find the roots of f(x) � x' + 6x4 + 2x'-6x2-5x + 5 E f n[x] con
tained in IF 13.
4.39. Prove that all the roots of /(x)�x3+8x2+6x-7EF 19[x] are
contained in F 19 and find them.
4.40. Let IF32 � IF2(/l), where /l is a root of the irreducible polyno
mial x' + x2 +I over F2. Prove that all the roots of f(x) �
x' +(/l4 + ll' + l)x2 + !l'x + /l4 + ll' + /l +IE f32[x] are contained
in IF 32 and find them.
4.41. Let F27 � IF3(/l). where /l is a root of the irreducible polynomial
x'-x +I over IF3. Prove that all the roots of f(x) � x' + x2-
(/l2 -!l + l)x + !l' -IE IF27[x] are contained in F27 and find them.
4.42. Let IF 169 � F "(/l), where /l is a root of the irreducible polynomial
x'-x-1 over F". Find the roots of /(x)�x2+(3/l+l)x+/l+
5 E IF 169[x] contained in F 169.
4.43. If the polynomial f(x-b) in (4.22) is quadratic with constant term
c"' 0, prove that the factorization in ( 4.22) is nontrivial if and only if
cis not the square of an element of IFP"
4.44. Let /l be a defining element ofF� F2., ove[IF2. Prove:
(a) There exists k, 0.; k.; m-I, with TrF(/l•) �I.
(b) For each i � 0, I, ... , m-I there exists an a, E F such that { ll' a2 +a-= ' , ll' + p• ifTrF(/l') � 0,
if TrF(/l') �I.
(c) If y � E;"_01 c,/l', c, E IF2, and TrF(Y) � 0, then the roots of
x2 + x +yare Er=01 ciai and 1 +Ei-01 cia;.
Chapter 5
Exponential Sums
Exponential sums are important tools in number theory for solving prob
lems involving integers-and real numbers in general-that are often
in tractable by other means. Analogous sums can be considered in the
framework of finite fields and tum out to be useful in various applications of
finite fields.
A basic role in setting up exponential sums for finite fields is played
by special group homomorphisms called characters. It is necessary to
distinguish between two types of characters-namely, additive and multi
plicative characters-depending on whether reference is made to the addi
tive or the multiplicative group of the finite field. Exponential sums are
formed by using the values of one or more characters and possibly combin
ing them with weights or with other function values. If we only sum the
values of a single character, we speak of a character sum.
In Section 1 we lay the foundation by first discussing characters of finite
abelian groups and then specializing to finite fields. Explicit formulas for
additive and multiplicative characters of finite fields can be given. Both types
of characters satisfy important orthogonality relations.
Section 2 is devoted to Gaussian sums, which are arguably the most
important types of exponential sums for finite fields as they govern the
transition from the additive to the multiplicative structure and vice versa.
They also appear in many other contexts in algebra and number theory. As an
illustration of their usefulness in number theory, we present a proof of the law
of quadratic reciprocity based on properties of Gaussian sums.
I. Characters 163
Exponential sums with the terms of a linear recurring sequence as
arguments will be treated in Chapter 6, Section 7. Deep investigations on
exponential sums for finite fields have been carried out with the help of
algebraic geometry, leading to the famous results of Wei! and Deligne, but a
presentation of this work would lead far beyond the scope of this book.
I. CHARACTERS
Let G be a finite abelian group (written multiplicatively) of order IGI with
identity element lG. A character X of G is a homomorphism from G into the
multiplicative group U of complex numbers of absolute value !-that is, a
mapping from G into U with x(g1g2) = x(g1)x(g2) for all g10 g2 E G. Since
x(lG) = x(lGJx(lG), we must have x(lG) = l. Furthermore,
(x(g))IGI = x(giGI) = x(lG) = l
for every g E G, so that the values of X are IGith roots of unity. We
note also that x(g)x(g- 1)=x(gg-1)=x(lG)=l, and so x(g-1)=
(X( g))-1 =X (g) for every g E G, where the bar denotes complex conjuga
tion.
Among the characters of G we have the trivial character Xo defined
by Xo( g)= 1 ·for all g E G; all other characters of G are called nontrivial.
With each character x of G there is associated the conjugate .character 5(
defined by )((g)=x(g) for all gEG. Given finitely many characters
x10 ...• x. of G, one can form the product character x1• • • x. by setting
<x�· · · x.)(g) = X1(g) · · · x.(g) for all g E G. If X1 = · · · = x. = x. we
write x" for x1• • • x •. It is obvious that the set G A of characters of G forms
an abelian group under this multiplication of characters. Since the values of
characters of G can only be I Gl th roots of unity, G A is finite.
After briefly considering the special case of il finite cyclic group, we
establish some basic facts about characters.
5.1. Example. Let G be a finite cyclic group of order n, and let g be a
generator of G. For a fixed integer j, 0.;; j.;; n -1, the function
xj(gk) = e2wijk/n, k = 0, l, ... ,n -1,
defines a character of G. On the other hand, if xis any character of G, then
X(g) must be an nth root of unity, say x(g) = e2•;J!" for some), 0.;; j.;;
n -1, and it follows that x = XF Therefore, G A consists exactly of the
characters x0,Xp···•Xn-J· 0
5.2. Theorem. Let H be a subgroup of the finite abelian group G and
let .Y be a character of H. Then .Y can be extended to a character of G; that is,
there exists a character x of G with X( h) = .Y (h) for all h E H.
164 Exponential Sums
Proof We may suppose that His a proper subgroup of G. Choose
a E G with a 'l H. and let H1 be the subgroup of G generated by H and a.
Let m be the least positive integer for which a"' E H. Then every element
g E H1 can be written uniquely in the form g � ajh with 0" j < m and
hE H. Define a function 1/>1 on H1 by .f1(g) � wl.f(h). where w is a fixed
complex number satisfying w"' �If( a"'). To check that 1/>1 is indeed a
character of H1, let g1 � akh1• 0 "k < m, h1 E H. be another element of H1•
If j + k < m, then 1/>1( gg1) � wj+k\f( hh 1) �If 1( g)l/>1( g1 ). If j + k;, m, then
gg1 � aj+k-m(a"'hh 1), and so
If 1 ( ggl) � Wj+k-m\f ( a"'hh1)
� wj+k-m.r( a"') If (hh1) � wJ+k.r( hh 1) � lf1 (g) lf1 ( gl) ·
It is obvious that l/>1(h)�.f(h) for hE H. If H1�G. then we are done.
Otherwise. we can continue the process above until, after finitely many
steps, we obtain an extension of If to G. 0
5.3. Corollary. For any two distinct elements g1, g2 E G there exists
a character X of G with X( g1)"' X( g2 ).
Proof It suffices to show that for h � g1g2 1"' lc there exists a
character x of G with X( h)"' I. This follows, however, from Example 5.1
and Theorem 5.2 by letting H be the cyclic subgroup of G generated by h. 0
5.4. Theorem. If x is a nontrivial character of the finite abelian
group G, then
(5 .I)
If g E G with g"' lc, then
L x(g)�o. (5 .2)
Proof Since xis nontrivial, there exists hE G with X(h)"' I. Then
x(h) L x(g) � L x(hg) � E x(g).
gEG gEG gEG
because if g runs through G, so does hg. Thus we have
(x(h)-I) E x(g)�o.
gEG
which already implies (5.1 ). For the second part, we note that the function g
defined by g(x) � x< g) for X EGA is a character of the finite abelian group
GA. This character is nontrivial since, by Corollary 5.3, there exists x EGA
with x(g) "'x(lcl =I. Therefore from (5.1) applied to the group G \
1. Characters 165
0
5.5. Theorem. The number of characters of a finite abelian group G
is equal to I G[.
Proof This follows from
IG"i= L L x(g)= L L x(g)=iGI,
geG xeG" X eG" gEG
where we used (5.2) in the first identity and (5.1) in the last identity. 0
The statements of Theorems 5.4 and 5.5 can be combined into the
orthogonality relations for characters. Let x and ,Y be characters of G. Then
I -{0
iGT L x(g),Y(g) = I gEG (5 .3)
The first part follows, of course, by applying (5.1) to the character xf; the
second part is trivial.
Furthermore, if g and h are elements of G, then
I -{0 jGf L x(g)x(h) = 1
xeG" for g * h,
forg=h. (5.4)
Here, the first part is obtained from (5.2) applied to the element gh-1,
whereas the second part follows from Theorem 5.5.
Character theory is often used to obtain expressions for the number
of solutions of equations in a finite abelian group G. Let f be an arbitrary
map from the cartesian product G" = G X · · · X G ( n factors) into G.
Then, for fixed h E G, the number N(h) of n-tuples (g1, ••• ,g,) E G" with
/(g1, ••• ,g,) =his given by
I N(h)=IGT L ··· L L x(/(g,, ... ,g.))x(h) (5.5)
g1EG g�EG xeG"
on account of (5.4).
A character x of G may be nontrivial on G, but still annihilate a
whole subgroup H of G, in the sense that x(h) =I for all hE H. The set of
all characters of G annihilating a given subgroup H is called the annihilator
ofHinG".
5.6. Theorem. Let H be a subgroup of the finite abelian group G.
Then theannihilator of·H in G" is a subgroup ofG" of order IGI/IHI.
Proof Let A be the annihilator in question. Then it is obvious from
the defmition that A is a subgroup of G". Let xEA; thenp.(gH)=x (g),
g E G, is a well-defined character of the factor group G/H. Conversely, if p.
166 Exponential Sums
is a character of G/H, then x(g) � l'(gH), g E G, defines a character of G
annihilating H. Distinct elements of A correspond to distinct characters of
G 1 H. Therefore, A is in one-to-one correspondence with the character
group (G/H) ', and so the order of A is equal to the order of (G/H) ',
which is iG/HI � iGI/IHI according to Theorem 5.5. D
In a finite field F • there are two finite abelian groups that are of
significance-namely, the additive group and the multiplicative group of
the field. Therefore, we will have to make an important distinction between
the characters pertaining to these two group structures. In both cases,
explicit formulas for the characters can be given.
Consider first the additive group of F •. Let p be the characteristic of
IF •; then the prime field contained in IF • is F,, which we identify with
Z/( p ). Let Tr: f • --+ F, be the absolute trace function from IF • to F, (see
Definition 2.22). Then the function x 1 defined by
(5.6)
is a character of the additive group of IF •• since for c1, c2 E IF • we have
Tr(c1 + c2) � Tr(c1)+Tr(c2), and so x1(c1 + c2) � x1(c1)x1(c2). Instead of
"character of the additive group of IF •·" we shall henceforth use the term
additive character of IF q· The character x1 in (5.6) will be called the canonical
additive character of F q· All additive characters of F • can be expressed in
terms of x1•
5.7. Theorem. Forb E !'•, the function Xb with Xb(c) � x1(bc) for
all c E IF • is an additive character ofF •• and every additive character of IF • is
obtained in this way.
Proof For c1, c2 E F • we have
x.(c1 + c,) � x1(bc1 + bc2)
� Xl(bc1)xl(bc,) � x.(c1)x.(c,),
and the first part is established. Since Tr maps IF • onto F P by Theorem
2.23(iii), x 1 is a nontrivial character. Therefore, if a, bE IF • with a"' b, then
x.(c) �xl(ac) �xl((a-b)c)"'i Xb(c) X1(bc)
for suitable c E IF •• and sox. and x. are distinct characters. Hence, if b runs
through F •• we get q distinct additive characters x •. On the other hand, F q
has exactly q additive characters by Theorem 5.5. and so the list of additive
characters of F • is already complete. D
By setting b � 0 in Theorem 5.7, we obtain the trivial additive
character Xo• for which x0(c) �I for all c E IF q·
Let E be a finite extension field of F•, let x1 be the canonical
\. Characters 167
additive character ofF •' and let/i, be the canonical additive character of E
defined in analogy with (5.6), where Tr is of course replaced by the absolute
trace function Tr£ from E to IF,. Then x1 and liJ are connected by the
identity
(5.7)
where Tr E/F is the trace function from E to F •. This follows from the
transitivity relation
Tr£(/l) � Tr(Tr£/F,(/l)) for all fl E E,
which was shown in Theorem 2.26.
Characters of the multiplicative group IF; of f • are called multiplica
tive characters of F •. Since F; is a cyclic group of order q -I by Theorem
2.8, its characters can be easily determined.
5.8. Theorem. Let g be a fixed primitive element of F •. For each
j � 0, l, ... ,q -2, the function 1/11 with
1/IJ(g'}�e2•iJk/(q-J) fork�O,l, ... ,q-2
defines a multiplicative choracter of IF •' and every multiplicative character of
F • is obtained in this way.
Proof · This follows immediately from Example 5.1. 0
No matter what g is, the character lj!0 will always represent the trivial
multiplicative character, which satisf1es ljl0(c) �I for all c E F;.
5.9. Corollary. The group of multiplicative characters ofF • is cyclic
of order q-I with identity element 1/10•
Proof Every character .jl1 in Theorem 5.8 with} relatively prime to
q -I is a generator of the group in question. D
5.10. Example. Let q be odd and let � be the real-valued function on F;
with�( c)� I if cis the square of an element ofF; and �(c)= -I otherwise.
Then � is a multiplicative character of IF •. It can also be obtained from the
characters in Theorem 5.8 by setting}� (q -1)/2. The character � annihi
lates the subgroup ofF; consisting of the squares of elements ofF;, and by
Theorem 5.6 it is the only nontrivial character ofF; with this property. This
uniquely determined character � is called the quadratic character of F •. If q
is an odd prime, then forcE F; we have �(c)= ( � ). the Legendre symbol
from elementary number theory. D
The orthogonality relations (5.3) and (5.4), when applied to additive
or multiplicative characters of IF •' yield several fundamental identities. We
consider first the case of additive characters, in which we use the notation
from Theorem 5.7. Then, for additive characters x. and x. we have
!68
In particular, -{0 L x.(c)x.(c) = q
cEF11 for a* b,
fora=b.
L x.(c)=O fora*O.
cEF9
Furthermore, for elements c, dE F • we obtain
I: x.(c)x.(d) = { �
bEF9 for C* d,
for c= d.
For multiplicative characters 1f and T of IF • we have
In particular,
If c, dE IF;, then -{0 L .f(c)T(c) = _1
cEP q
•
L .f(c)=Ofor.f*lfo·
cEF; Exponential Sums
(5.8)
(5.9)
(5.10)
(5.11)
(5.12)
(5.13)
where the sum is extended over all multiplicative characters 1f of IF ••
2. GAUSSIAN SUMS
Let 1f be a multiplicative and x an additive character of IF •• Then the
Gaussian sum G( 1f, x) is defined by
G(.f.x)= I: .f(c)x(c).
cEF;
The absolute value of G( .f, x) can obviously be at most q -1, but is in
general much smaller, as the following theorem shows. We recall that .fo
denotes the trivial multiplicative character and Xo the trivial additive
character of IF ••
5.11. Theorem. Let 1f be a multiplicative and x an additive char
acter of 'f q· Then the Gaussian sum G( .f, x) satisfies {q -1 for.f = lfo• X= Xo•
G(.f,x)= -1 for.f=.f0,X*Xo• 0 for.f * lfo• X= Xo· (5.14)
2. Gaussian Sums !69
If .Y"' .Yo and x ""Xo• then
(5.15)
Proof The first case in (5.14) is trivial, the third case follows from
(5.12), and in the second case we have
G(.Yo.xl= L x(c) = L x(c)-x(O)=-I
cef; cEFq
by (5.9). For .Y"' .Yo and X"' Xo we get
IG(f,x)l'= G(.Y.x) G(.Y.x) ----
= L L >r(cJ x(cl >r(c,Jx(c,J
cef; c1Ef;
In the inner sum we substitute c-1c1 =d. Then,
IG(.Y.x)l'= L L .Y(d)x(c(d-I))
ceF; deF;
= d�./(d{� •• x(c(d -1))-x(O))
= L .Y(d) L x(c(d -I))
def; cef'i
by (5.12). The inner sum has the value q if d =I and the value 0 if d"' I,
according to (5.9). Therefore, iG(f, xJI2 = f(l)q = q. and (5.15) is estab
lished. D
The study of the behavior of Gaussian sums under various transfor
mations of the additive or multiplicative character leads to a number of
useful identities.
5.12 Tloeorem. Gaussian sums for the finite field IF• satisfy the
following properties:
(i) G(f,x •• J=.Y(a) G(f.x.JforaE'!i;,bEF.;
(ii) G(f,)()=.y(-I)G(f.x);
(iii) G(f.xJ=!Y(-IJG(.Y,x):
(iv) G( f, x)G(f, X)= f( -I)q for .Y"" fo, X"" Xo;
(v) G( .Y'. x.J = G( .y, x.,.,) forb E f •. where p is the characteristic
of F• and u( b)= b'.
Proof (i) For cEF• we have x •• (c)=x1(abc)=x.(ac) by the
170 Exponential Sums
definition in Theorem 5.7. Therefore,
G(.Y.x.,)� E ,Y(c)x.,(c) � E ,Y(c)x,(ac).
Now set ac �d. Then
G(.Y.x.,)� E ,Y(a-1d)x,(d)
d EF;
�.y(a-1) E .y(d)x,(d)
d EF;
� ,Y(a) G( .y, x,).
(ii) We have X� Xb for a suitable bE f9 and x(c) �X;(-c)�
x_,(c) for c E IF •. Therefore, by using (i) with a� -I and noting that
,Y(-1)� ±I, we get
G(.Y.x)�G(.J-.x_,)� H-I) G(.Y.x.)�.y(-I)G(.Y.x).
(iii) It follows from (ii) that G(f, x) � f(-I)G(f, x) �
.y(-I)G(,Y,x) .
(iv) By combining (iii) and (5.15), we obtain G(,Y,x)G(f,x)�
.y(-I)G(,Y.x)G(,Y.x) � .y(-I)IG(,Y.x)l2� .y(-l)q.
( v) Since Tr( a) � Tr( aP) for a E !' • by Theorem 2.23(v), we have
x 1 (a)� x 1 ( aP) according to (5.6). Thus, for c E IF • we get x,( c)� x1 (be)�
>;:1(bPcP) � Xa(b)(cP), and SO
G(.Y'.x,)� E .y'(c)x,(c)� E ,Y(c')x.1,)(c').
But c' runs through F; as c runs through IF;, and the desired result follows.
0
5.13. Remark. In connection with the properties above, the value .y( -I)
is of interest. We obviously have .y(-I)�± I. Let m be the order of ,Y; that
is, m is the least positive integer such that .ym = lj-0• Then m divides q-I
since .y•-1 � lj-0• The values of .Yare mth roots of unity; in particular, -I
can only appear as a value of .Y if m is even. If g is a primitive element of IF<'
then ,Y(g) � r. a primitive mth root of unity. If m is even (and so q odd),
then ,Y(-I)� .y(g<<-1112) � j<<-1>12, which is -I precisely if ( q-I )/2 =
mj2mod m, or. equivalently, (q -1)/m =I mod2. Therefore, ,Y( -I)� -I
if and only if m is even and (q -1)/m is odd. In all other cases we have
,Y(-1)�1. 0
Gaussian sums occur in a variety of contexts, for example in the
following. Let .Y be a multiplicative character of IF •; then, using (5.10), we
may write
2. Gaussian Sums
I -�-E x.(c) E .j�(d)x,(d) q be:F deP ' '
for any c E F;. Therefore,
I -1/l(c)�-EG(l/l,x)x(c) forcEF;. q X 171
(5.16)
where the sum is extended over all additive characters x of F •. This may be
thought of as the Fourier expansion of .jl in terms of the additive characters
of F q• with Gaussian sums appearing as Fourier coefficients.
Similarly, if x is an additive character of F •• then, using (5.13), we
may write
I --
x(c) � -1 E x(d)1;1/l(c ) .j�(d) q-def: V-
�-1
-1 Ll/l(c) E f(d)x(d) forcEF;.
q-I} dE F:
Thus we obtain
(5 .17)
where the sum is extended over all multiplicative .characters 1/1 of F q· This
can be interpreted as the Fourier expansion of the restriction of x to IF; in
terms of the multiplicative characters of F •• again with Gaussian sums as
Fourier coefficients. Therefore, Gaussian sums are instrumental in the
transition from the additive to the multiplicative structure (or vice versa) of
a finite field.
Before we establish further properties of Gaussian sums, we develop
a useful general principle. Let ci> be the set of monic polynomials over F •·
and let A be a complex-valued function on ci> which is multiplicative in the
sense that
A(gh) � A(g)A(h) for allg, hE cf>, (5.18)
and which satisfies I A( g) I .; I for all g E ci> and A (I) � I. With ci> k denoting
the subset of ci> containing the polynomials of degree k, consider the power
senes
L(z)� E ( E A(g))zk k-0 ge<P" (5.19)
Since there are qk polynomial s in <l>k, the coefficient of zk is in absolute
value .; q', and so the power series converges absolutely for lz I < q-1
Because of (5.18) and unique factorization in F .[x ], we may write
172 Exponential Sums
L(z)� L, A(g)z•'""
� 0(l+A(/)zd"'fl+A(/')z•"u'l+ ... )
I
� 0{1 + A(/)z•'•"' +A(!)'z'd'&Ul + ... ).
I
where !he product is taken over all monic irreducible polynomials fin F.[x].
I! follows !hal
L(z) � n (I-A(/)zd<&<llr 1
I
Now apply logarithmic differentiation and multiply !he resull by z lo gel
zdlogL(z) � L A(/)deg(J)zd'&<ll dz 1 1-A(f)z•<&<ll
Expansion of (1-A(/)zd<&i!l)-1 into a geometric series leads 10
z dlog L ( z) � LA (f) deg( !)zd"'<fl dz 1
·(l+A(J)z••&<fl+A(J)2z'••&lll+ ... )
� L deg( fl{ A( f) z•'•'" +A(/ )2 z2 dog(fl
I
+A(!)'z'•'•'"+ ... ).
and collecting equal powers of z we obtain
dlogL(z) _ ;'. L , z dz -i.... sz
s-l
with
L, � L, deg(/)A(/)'1.'"".
I (5.20)
( 5 .21)
where !he sum is extended over all monic irreducible polynomials fin F .[x]
wilh deg(/) dividing s.
Now suppose !here exists a positive integer t such !hal
L, A (g) � 0 for all k > t. (5.22)
g E 411<
Then L(z) is a complex polynomial of degree .;; t wilh conslanl term I, so
that we can write
L(z) �(I-w1z)(I-w2z)· ··(I-w,z) (5.23)
2. Gaussian Sums
with complex numbers w1,w2, ... ,w,. It follows that
dlogL(z) z dz
' 00
L wmz L wj1z1
m=l J-0
[ ( [ w.:,+1)zi+l�-[ ( t w:,)z',
j=O m-1 .��1 m�l
and comparison with (5.20) yields
Ls =-wj-w2-· · · -w: for all s >I. 173
(5.24)
As an application of the principle expressed in (5.24), we consider
the following situation. Let x be an additive andY, a multiplicative character
of F •. and let E be a finite extension field of F •. Then x and Y, can be
"lilted" to E by setting x'(/J) � x(TrE;r,(/3)) lor {3 E E and Y,'(/3) �
Y,(NE/F ({3)) lor {3 E E*. From the additivity of the trace and the multi
plicativi'ty of the norm it follows that x' is an additive and Y,' a multipli
cative character of E. The following theorem establishes an important
relationship between the Gaussian sum G( Y,, x) in F • and the Gaussian sum
G( Y,', x') in E.
5.14. Theorem (Davenport-Hasse Theore m). Let x be an additive
andY, a multiplicative character of F •• not both of them trivial. Suppose x and
Y, are lifted to characters x' andY,', respectively, of the finite extension field E
of IF • with [ E: IF .1 � s. Then
G ( �/>', x') � (-I)'-1 G ( 1/>, X)'
Proof It is convenient to extend the definition of Y, by setting
Y, (0) � 0. We use the notation of the discussion leading to (5.24); in
particular, <l> denotes again the set of monic polynomials over F •. We define
A by setting A(l) �I as required, and lor g E <l> of positive degree, say
g(x)�x•- c1x'-1 + · · · +(-I)'c,, we set A( g)� Y,(c,)x(c1). The multi
plicative property (5.18) is then easily checked. For k >I we split up <t>,
according to the values of c1 and c,. Each given pair (c1, c,) occurs q'-2
times in �k• and so
174 Exponential Sums
Since one of x and of is nontrivial, it follows from either (5.9) or (5.12) that
L A (g) � 0 fork> I.
g E cpA
Therefore, (5.22) is satisfied with I� I. Furthermore, <1>1 comprises the linear
polynomials x-c with c E F •. and so
L A(g) � L of(c)x(c) � L of(c)x(c) �G(of,x).
Thus, L(z)�l+G(of,x)z from (5.19), hence w1�-G(of,X) by (5.23).
Now we consider L,, which, by (5.21) and the multiplicativ ity of A, is given
by
L, � L deg( f) A (f) '/d<g(fl
f
� L • deg( f) A (J•Id<s<!l),
f
where the sum is extended over all monic irreducible polynomials fin IF •[ x]
with deg(f) dividing s, and where the asterisk indicates that f(x) � x is
excluded. Each suchfhas deg(f) distinct nonzero roots in E, and each root
{3 off has as its characteristic polynomial over F • the polynomial
!( ),;•••<!>_ ' ,_,+ +( I)' x -x - c1x · · · -cs,
say, where c 1 � Tr EfF ( {3) and c, � N E/F ( {3) by (2.2) and (2.3 ). Therefore, • •
and so A (!•I•••U>) � H c, )x ( c,) � of { NE;F,( f3)) X (Tr E;F,( 13))
� of'(f3)x'(f3),
L, � L*deg(f)A(f 'fd<g(/1)-I;• L of'({3)x'({3). f f fJ E E
/I PI-0
If f runs through the range of summation above, then {3 runs exactly
through all elements of E*. Consequently,
L, � I: of'( f3)x'({3) � G( of', x'),
fl E 1::•
and an application of (5.24) yields
G(of',x') � -( -G(of,x))',
which completes the proof. 0
For certain special characters, the associated Gaussian sums can be
evaluated explicitly. We thereby obtain formulas that go beyond the trivial
2. Gaussian Sum� 175
cases listed in (5.!4). A celebrated formula of this kind holds for the
quadratic character '1 considered in Example 5.!0.
5.15. Theonm. Let F • be a finite field with q � p', where p is an
odd prime and s E I'll. Let '1 be the quadratic character ofF• and let X1 be the
canonical additive character of IF •. Then { ( -l)'-lql/2
G(.,.xl) � ( )'-1. 1/2 -l t'q ifp = l mod4,
ifp=3mod4.
Proof Using Theorem 5.l2(iv) and ii� .,, we obtain G(.,, x1)2 �
'1(-l)q, and since '1(-l)�l for q=lmod4 and '1(-l)�-l for q=
3mod4 by Remark 5.!3, it follows that
ifq=lmod4,
if q = 3mod4. (5.25)
The difficulty of the proof lies in the determination of the correct signs.
We first consider the case s � l. Let V be the set of all complex
valued functions on If;; it is a (p -!)-dimensional vector space over the
complex numbers. A basis for Vis formed by the characteristic functions
f1 ./2, ••• ./,_1 of elements of IF;; that is, �(c)= l if c � j and 0 otherwise,
where j � l, 2, ... ,p-l. From the orthogonality relation (5.ll) it follows
easily that the multiplicative characters .p0, 1f1, .•• ,1f,_2 ofF, described in
Theorem 5.8 also form a basis for V. Let I� e2•'1P, and define a linear
operator T on V by letting Th for h E V be given by
p-1
(Th)(c)� L l"'kh(k) forc�l,2, ... ,p-l.
k= I (5 .26)
Then Theorem 5.l2(i) implies !hat T.p � G(.p, x1lf for every multiplicative
character .p of F p· Since .p � 1/> precisely for the trivial character and the
quadratic character, the matrix Tin the basis 1/>0, 1/>1, ••• ,1f,_1 contains two
diagonal entries-namely, G( 1/>0, X 1) � -l and G( .,, X 1 )-and a collection
of blocks ( o G(,f0.x1l)
G( 1/>, x1)
corresponding to pairs .p, f of conjugate characters that are nontrivial and
nonquadratic. If we compute the determinant of T, then each block contrib
utes
-G(.p, x�)G(f.x1) �-.P( -l)p
176 Exponential Sums
by Theorem 5.12(iv). Thus we obtain
(p -3)/2
det(T) �-G( �. x1)(-p )1.-3'12 0 .j-1( -1). j=!
Now¥-/-1) � lj-j( -1) � ( -1)1, and so (5.27)
(p-3)/2
n >�-}( -1) � ( -1)1+2+ ··+(p-3)/2 � ( -1)'•-IXp-3)/8 (5.28)
j=l
Furthermore, since
it follows from (5.25) that ifp = 1 mod4,
ifp"' 3mod4,
Combining (5.27), (5.28), and (5.29), we get
det(T) � ±( -l)(p-IJ/2;<•-1)'14( -l)(r1Xp-3)/8p<.-2);2
hence (5.29)
(5.30)
Now we compute det(T) utilizing the matrix of T in the basis
/1,/2, ... ./ .-1. From (5.26) we find
det( T) � det( (ri• )1 �J. • �, _1) � det( (rirN-I> )1 <J. • •, _1)
�'1+2+···+\p-lldet(('N-1>) . ) � � l c;;;,kc;;p-1
� det( (!i<<-l> )1 • 1. • •• -I),
which is a V andermonde determinant. Therefore,
det(T) � 0 W-I"').
\ .,;;.m<n.llliOp-1
With 8 = e"ifp we get
det(T)� 0 (82"-82"')
l..,.m<n.,;p-1
2. Gaussian Sums
Since n 6"+m(6•-m-6-<•-ml)
1 -llii:m<n-'IE:;p-1
n ••+m n (2·. w(n-m)) u lSln .
1 -llii:m<n,.. p-1 l<:!iOm<n -��ii:p-1 P
p-I n -I
L (n+m)� L L (n+m)
1 -llii:m<n.lO;p -1 n�2 m=l 177
�_3_((p-2)(p-1)(2p-3) (p-2)(p-!))
2 6 + 2
p(p -I)( p -2)
2
the first product is equal to
6P(p-l)(p-2)/2 � ( _ I)(p -l)(p-l)/2 � ( ( _ I) p -2)'P-1)/l � ( -l)(p -1)/2
Furthermore,
and so A n (2. w(n-m)) 0 = stn > ,
l <:;;;m<n-'IE:;p-1 P ··'
det( T) � (-I)'' -IJ/l i(p-1� p-lJ/lA with A> 0.
Comparison with (5.30) shows that the plus sign always applies in (5.29),
and the theorem is established for s � I.
The general case follows from Theorem 5.14 since the canonical
additive character ofF, is lifted to the canonical additive character of F• by
(5.7) and the quadratic character of IF, is lifted to the quadratic character of
�· 0
Because of (5.14) and Theorem 5.12(i), a formula for G(1J,X) can
also be established for any additive character X of "F 9.
We turn to another special formula for Gaussian sums which applies
to a wider range of multiplicative characters but needs a restriction on the
underlying field. We shall have to use the notion of order of a multiplicative
character as introduced in Remark 5.13.
5.16. Theorem (Stickelberger's Theorem). Let q be a prime power,
let .jl be a nontrivial multiplicative character of IF •' of order m dividing q + I,
and let x1 be the canonical additive character ofF•'· Then,
\18 Exponential Sums
G(.J-.x,)� J q
\-q q+I if m odd or --even,
m
q+I if m even and --odd.
m
Proof We write E � F•' and F� IF •. Let y be a primitive element of
E and set g � y•+ 1 Then g•-• �I, so that g E F; furthermore, g is a
primitive element of F. Every a E £* can be written in the form a� gjyk
with 0 � j < q -I and 0 � k < q +I. Since l}(g) � .j-•+ 1(y) �I, we have
q-2 q
G(.J-, x,) � E E l}(gjy')x,(gjy')
J-Ok-0
q q -2
� E .J-'bl E x,(gjy')
k=O J-0
q
� E .J-'( 1 J E x,(by').
k-0 bEF* (5.31)
If T1 is the canonical additive character ofF, then x1(by') � T1(TrE;F(by'))
by (5.7). Therefore,
E x,(by')� E T1(bTrE;F(y'))
beP beP { -1
= q-I for TrE;F( y') * 0,
for TrE;F( y') � 0,
because of (5.9). Now TrE;F(Y') = y' + y'•, and so
TrE;F( y') � 0 if and only if y•c•-•l � -1. (5.32)
(5.33)
If q is odd, the last condition is equivalent to k � ( q + 1)/2, and then by
(5.32),
E x,(by•) � ( -1
bEF" q-J
Together with (5.31) we get
G(.J-.x,)�-q E
k=O
k*(q+l)/2 q+I for 0 � k < q + I, k * -2-,
a+ I fork�2·
2. Gaussian Sums
q
L .p'( yJ + q.p<•+ ill'( Y l
k=O
�q.p<q+i)/l(y) 179
since .P(y)"' I and .p•+ i(y) �I. Now .p<q+ i1!2(y) �I if (q + 1)/m is even
and -I if ( q + I)/ m is odd, and thus for q odd we have
G(.P.xd�( q
-q .f q +'
1 --even. m
if q +I odd. m (5 .34)
If q is even. then the condition in (5.33) is equivalent to y<lq-i) �I, and the
only k with 0" k < q +I satisfying this property is k � 0. Then by (5.32),
and (5.31) yields { -I L Xi(by')�
bEF"' q-J forl�k�q.
fork� 0,
q q
G(.P.xi) �-L .P'(y)+q-1�-L .P'(y)+q�q.
k-1 k-0
Combined with (5.34), this implies the theorem. D
We show how to use Gaussian sums to establish a classical result of
number theory, namely the law of quadratic reciprocity. We recall from
Example 5.10 that if pis an odd prime and q is the quadratic character off,,
then for c ¢0 modp the Legendre symbol(�) is defined by(�)� q(c).
5.17. Theorem (Law of Quadratic Reciprocity). For any distinct
odd primes p and r we have ( �)(%) � (-l)(p-iX,-i)/4
Proof Let 11 be the quadratic character ofF,, let Xi be the canoni
cal additive character of IF,, and put G � G(11, Xi). Then it follows from
(5.25) that G2 � ( -l)ip-ill'p � jj, and so
( 5.35)
Let R be the ring of algebraic integers: that is, R consists of all complex
numbers that are roots of monic polynomials with integer coefficients. Since
the values of (additive and multiplicative) characters of finite fields are
complex roots of unity, and since every complex root of unity is an
algebraic integer, the values of Gaussian sums are algebraic integers. In
particular. GER. Let (r) be the principal ideal of R generated by r. Then
180 Exponential Sums
the residue class ring R/(r) has characteristic r, and thus an application of
Theorem 1.46 yields
Now G'� ( E �(c)x1(c))' = E �'(c)x](c)mod(r).
cEF; cEF;
by Theorem 5.12(i), and so
G'=�(r)Gmod(r).
Together with (5.35) we get
pt'-1lf2G = � ( r )Gmod( r ),
and multiplication by G leads to
pi,_ 1 l/2 p = � ( r) p mod( r)
because of G2 �ft. Since the numbers on both sides of the congruence
above are, in fact. elements of Z, it follows that
pt'-1112p= �( r )pmod r
as a congruence in Z. But p and rare relatively prime, hence
p<'-1'1' = �( r) mod r.
Now ft� ( -I)Ir1ll2p and p'-1 =I mod r, thus multiplication by p1'-1112
yields
( -1)1' -ll('-1114 = p�'-1)/2�( r) mod r. (5.36)
We have pl'-ll/2 =±I mod r, and the plus sign applies if and only if p is
congruent to a square mod r. Thus,
p''-IJ/2 = ( 7) mod r.
Since �(r) � (�).we get from (5.36)
(-I)'' -1)(,-IJ/4 = ( 7) (�)mod r.
But the integers on both sides of this congruence can only be ±I, and since
r <> 3, the congruence holds only if the two sides are identical. 0
We consider now character sums involving the quadratic character t1 of
� •• q odd, and having a quadratic polynomial in the argument. The following
explicit formula will be needed in Chapter 7, Section 2.
5.18. Theorem. Let f(x) � a2x2 + a1x + a0 E F .lx] with q odd and
a2 * 0. Put d � af -4a0a2 and let � be the quadratic character ofF,. Then
Exercises
"' { -'l(a,)
L. '1(/(c))� ( -1) ( )
cEF<i q 11 a2
Proof Multiplying the sum by '1(4aJ) �I, we get
L 'I(/( c))� 'I( a,) L '1(4alc' +4a1a2c +4a0a2) 181
�'l(a,) L '1{(2a2c+a1)2-d)�'l(a2) L 'l(b2-d).
cEff bEfq
(5.37)
The result for the case d � 0 follows now immediately. For d * 0 we write
I: "(b'-d)�-q+ I: (l+"(b'-d)),
bEf'l bEF9
and since I +'I( b2 -d) is the number of c E IF q with c2 � b2 -d, we obtain
L 'l(b2-d)�-q+S(d), (5.38)
bE f'l
where S( d) is the number of ordered pairs ( b, c) with b, c E IF, and
b2 -c2 =d. To solve this equation, we put b + c = u, b-c = v and note
that the ordered pairs ( b, c) and ( u, v) are in one-to-one correspondence
since q is odd. Thus S(d) is equal to the pumber of ordered pairs (u, v) with
u, v E IF, and uv � d, hence S( d)� q-I. Togethe� with (5.37) and (5.38),
this implies the desired formula. D
EXERCISES
5.1. Let G be a finite abelian group, H a proper subgroup of G, and
g E G, g �H. Prove that there exists a character x of G that
annihilates H, but for which x(g) *I.
5.2. Let H be a subgroup of the finite abelian group G. Prove that the
annihilator A of H in G A is isomorphic to G 1 H and that GAIA is
isomorphic to H.
5.3. Let G be a finite abelian group and mE 1\1. Prove that g E G is an
mth power of an element of G if and only if x(g) �I for all
characters X of G for which xm is trivial.
5.4. Let G1, ••• ,G, be finite abelian groups. Define multiplication of
k-tuples ( g1, ...• g, ), ( h 1, ... ,h,) with g,, h, E G, for I .; i.; k by
( g, .... ,g, )( h,, ... ,h,) � ( g,h,, ... ,g,h, ).
Show that with this operation the set of all such k-tuples forms again
a finite abelian group, the so-called direct product G1® · · · ®G,.
182 Exponential Sums
Then prove that (G1® · · · ®Gk) A is isomorphic to G,' ® · · · ®Gt.
5.5. Use the structure theorem for finite abelian groups, which says in its
simplest form that every such group is isomorphic to a direct product
of finite cyclic groups, to prove that G A is isomorphic to G whenever
G is a finite abelian group.
5.6. For additive characters of f• in the notation of Theorem 5.7, show
that x,x. = Xo+b for all a, bE IF •. Thus prove without reference to
Exercise 5.5 that the group of additive characters of IF q is isomorphic
to the additive group of IF q·
5.7. If x1 is the canonical additive character of the finite field IF• of
characteristicp, prove that x,(c'1)=x1(c) for all cEF• and} EN.
5.8. If .pis a multiplicative character of IF •• of order m, prove that the
restriction of .p to IF q is a multiplicative character of order
mjgcd(m,(q' -1)/(q -I)).
5.9. With the notation of Exercise 5.8, prove that the restriction of .p to F q
is the trivial character if and only if m divides (q' -1)/(q -I).
5.10. Let .p be a multiplicative character of F• and let ,P' be the lifted
character of the extension field F •.. Prove that ,P'(c) = t'(c) for
c E (f:.
5.11. Prove that a multiplicative character T of F •. is equal to a character
,P' lifted from F q if and only if ,•-' is trivial.
5.12. If q =I mod m and .p varies over all multiplicative characters of IF• of
order dividing m, prove that the lifted character .P' of F •. varies over
all multiplicative characters of IF q' of order dividing m.
5 .13. Prove that an additive character x of the finite extension field E of IF q
is equal to a character lifted from F q if and only if X= lib with
bE IF•, where p.1 is the canonical additive character of E.
5.14. Prove forcEF; that
{ q-1
= :(q-1) if cis a primitive element ofF q,
otherwise,
where in the outer sum d runs through all positive divisors of q-I
and in the inner sum .P'"' runs through the <j>(d) multiplicative
characters ofF q of order d. Here p. denotes the Moebius function (see
Definition 3.22) and <P Euler's function (see Theorem 1.15 (iv)).
5.15. Show that �(2) = (-J)l•'-lll', where� is the quadratic character of
e: •. q odd.
5.16. For rEN prove G(.f''.x.l=G(.f.x,1.,). where p(b)=b'' for
bE F q and p is the characteristic of F q·
Exercises 183
5.17. Prove Lx G( 1/1, xl � 0 for all multiplicative characters 1/1 of F •. where
the sum is extended over all additive characters x of F q·
5.18. Prove I:,G(,P.x)�(q-I)x(l) for all additive characters x of IF •.
where the sum is extended over all multiplicative characters 1/1 of f q·
5.19. For the quadratic character � of F q• q � p', p an odd prime, s E I'll,
and an additive character x •. bE F •. in the notation of Theorem 5.7.
prove that
G( �. x.) � � (b)(_ I)'• + ll/2 ;•<P'+2p+ Sl/4ql/'-
5.20. If q is odd and � is the quadratic character of IF q• prove that
G(�. x.)G(�. x.l � �(-ab)q for a, bE IF;.
5.21. Use the law of quadratic reciprocity to evaluate the Legendre sym
bols ( m and ( .!r ).
5.22. Determine all primes p such that ( �3) �I.
5.23. Determine all odd prime powers q such that the quadratic character
� of IF q satisfies � (3) � I.
5.24. Prove that the polynomial x2 +ax+ bE Fq[x], q odd. is irreducible
in F•[x] if and only if �(a2 -4b) �-I.
5.25. Determine whether the polynomial x2 + 12x +41 is irreducible in
1Fm[x].
5.26. Let p and r be distinct odd primes, lets E I'll be such that r' =I mod p,
and let!: be an element of order pin F,�. Fork E Z define
p-1 ck � E ( � )rk' E IF,,.
l'=l p
Prove the following properties: (i) Gk � (% )c,: (ii) c; �
( -l)lP-Ill'p. where the last expression is viewed as an element of
IF,.
5.27. Use the results of Exercise 5.26 to prove the law of quadratic
reciprocity.
5.28. Prove that
L ,P(c+a)f(c+b)�-1
cEF'l
for a, bE IF • with a"' b, where 1/1 is a nontrivial multiplicative char
acter of IF q·
5.29. Let lji be a nontrivial multiplicative character of IF • and let S be a
subset of F q with h elements. Prove that
L I L 1/l(c+alj' �h(q-h).
cEfq aES
5.30. Let X1, X2, X3 be nontrivial multiplicative characters of IF• and let
184
a1, a2 E IF q with a1 =1= a2. Prove that
L I L ;>..,(c+a1);\.2(c+a2);\.3(c+b)l2
bEF, cEF9 { q'-3q
� q2-2q-l if ;1.1;1.2 nontrivial,
if;\.1;\.2 trivial. Exponential Sums
5.31. Let 1/> be a multiplicative character of F • of order m > 1. For a E IF •
prove
L IJ>(ac") � { (q -1)1/>(a)
cEF Q
' if m divides n,
otherwise.
5.32. Prove that L"' �(f(c)) � 0 if q = 3 mod 4, � is the quadratic character
off,, and /Ef.[x] is an odd polynomial-that is, a polynomial with
f(-x) � -f(x).
Chapter 6
Linear Recurring Sequences
Sequences in finite fields whose terms depend in a simple manner on their
predecessors are of importance for a variety of applications. Such sequences
are easy to generate by recursive proced�res, which is certainly an advanta
geous feature from the computational viewpoint, and they also tend to have
useful structural properties. Of particular interest is the case where the terms
depend linearly on a fixed number of predecessors, resulting in a so-called
linear recurring sequence. These sequences are employed, for instance, in
coding theory (see Chapter 8, Section 2), in cryptography (see Chapter 9,
Section 2}, and in several branches of electrical engineering. In these
applications, the underlying field is often taken to be � 2, but the theory can
be developed quite generally for any finite field.
In Section I we show how to implement the generation of linear
recurring sequences on special switching circuits called feedback shift reg
isters. We discuss also some basic periodicity properties of such sequences.
Section 2 introduces the concept of an impulse response sequence, which is
of both practical and theoretical interest. Further relations to periodicity
properties are found in this way, and also througb the use of the so-called
characteristic polynomial of a linear recurring sequence. Another applica
tion of the characteristic polynomial yields explicit formulas for the terms of
a linear recurring sequence. Maximal period sequences are also defined in
this section. These sequences will appear in various applications in later
chapters.
The theory of linear recurring sequences can be approached via
linear algebra. ideal theory, or formal power series. An approach based on
186 Linear Recurring Sequences
the latter is presented in Section 3. This leads to a computation-oriented
way of introducing the minimal polynomial of a linear recurring sequence in
the next section. The minimal polynomial is of crucial importance for the
linear recurring sequence, since the order of the minimal polynomial gives
the least period of the sequence.
In Section 5 we study the collection of all sequences satisfying a
given linear recurrence relation. This information is useful in the discussion
of operations with linear recurring sequences, such as termwise addition and
multiplication for sequences in general finite fields and binary complemen
tation for sequences in F2. We consider also the problem of determining the
various least periods of the sequences generated by a fixed linear recurrence
relation. Section 6 presents some determinantal criteria character izing linear
recurring sequences as well as the Berlekamp-Massey algorithm for the
calculation of minimal polynomials.
Section 7 is devoted to distribution properties of linear recurring
sequences. Exponential sums with linear recurring sequences are the main
tools for studying such properties.
1. FEEDBACK SHIFT REGISTERS, PERIODICITY PROPERTIES
Let k be a positive integer, and let a, a0 ....... ak _ 1 be given elements of a
finite field F •. A sequence s0, s1, ••• of elements of IF, satisfying the relation
sn+k=ak-lsn+k-l+ak_2sn+k-2+ ··· +a0sn+a forn=O,l, ...
(6.1)
is called a (kth-order) linear recurring sequence in F q· The terms s0,
s1 •••• ,sk _1, which determine the rest of the sequence uniquely. are referred
to as the initial values. A relation of the form (6.1) is called a (kth-order)
linear recurrence relation. In the older literature one may also find the term
.. difference equation." We speak of a homogeneous linear recurrence relation
if a= 0; otherwise the linear recurrence relation is inhomogeneous. The
sequence s0• s1 •.•. itself is called a homogeneous, or inhomogeneous, linear
recurring sequence in IF q• respectively.
The generation of linear recurring sequences can be implemented on
a feedback shift register. This is a special kind of electronic switching circuit
handling information in the form of elements of IF •• which are represented
suitably. Four types of devices are used. The first is an adder. which has two
inputs and one output, the output being the sum in IF, of the two inputs.
The second is a constant multiplier, which has one input and yields as the
output the product of the input with a constant element of IF •. The third is a
constant adder, which is analogous to a constant multiplier, but adds a
constant element of !', to the input. The fourth type of device is a delay
1. Feedback Shift Registers, Periodicity Properties 187
element ("flip-flop"), which has one input and one output and is regulated
by an external synchronous clock so that its input at a particular time
appears as its output one unit of time later. We shall not be concerned here
with the physical realization of these devices. The representation of the
components in circuit diagrams is shown in Figure 6.1.
A feedback shift register is built by interconnecting a finite number
of adders, constant multipliers, constant adders, and delay elements along a
closed loop in such a way that two outputs are never connected together.
Actually, for the purpose of generating linear recurring sequences, it suffices
to connect the components in a rather special manner. A. feedback shift
register that generates a linear recurring sequence satisfying (6.1) is shown
in Figure 6.2.
At the outset, each delay element D;, j = 0, I, ... ,k -I, contains the
initial value sF If we think of the arithmetic operations and the transfer
along the wires to be performed instantaneously, then after one time unit
each D; will contains;+ 1• Continuing in this manner, we see that the output
of the feedback shift register is the string of element s0, s1, s2, ... , received
in intervals of one time unit. In most of the applications the desired linear
recurring sequence is homogeneous, in which case the constant adder is not
needed.
6.1. Example. In order to generate a linear recurring sequence in ·fs
satisfying the homogeneous linear recurrence relation
(a) Adder
FIGURE 6.1 s,+6=sn+s+2s,+4+s,+1+3s, (orn=O,I, ... ,
(b) Constant multiplier (c) Constant adder (d) Delay element
for multiplying by o for adding o
The building blocks of feedback shift registers. (a) Adder. (b) Constant multiplier
for multiplying by a. (c) Corn;tant adder for adding a. (d) Delay element.
FIGURE 6.2 The general form of a feedback sbift register.
188 Linear Recurring Sequences
one may use the feedback shift register shown in Figure 6.3. Since a2 � a3 �
0, no connections are necessary at these points. 0
6.2. Example. Consider the homogeneous linear recurrence relation
A feedback shift register corresponding to this linear recurrence relation is
shown in Figure 6.4. Since multiplication by a constant in f2 either
preserves or annihilates elements, the effect of a constant multiplier can be
simulated by a wire connection or a disconnection. Therefore, a feedback
shift register for the generation of binary homogeneous linear recurring
sequences requires only delay elements, adders, and wire connections. D
Let s0, s1, ••• be a kth-order linear recurring sequence in F• satisfying
(6.1). As we have noted, this sequence can be generated by the feedback
shift register in Figure 6.2. If n is a nonnegative integer, then after n time
units the delay element�.}� 0, I, ... ,k-I, will contain s•+j· It is therefore
natural to call the row vector sn = (sn, sn+ 1, •.• ,sn+k _1) the nth state vector
of the linear recurring sequence (or of the feedback shift register). The state
vector s0 = (s0, s1, ••• ,sir. _1) is also referred to as the initial state vector.
It is a characteristic feature of linear recurring sequences in finite
fields that, after a possibly irregular behavior in the beginning, such
sequences are eventually of a periodic nature (or ultimately periodic in the
sense of Definition 6.3 below). Before studying this property in detail, we
introduce some terminology and mention a few general facts about ulti·
mately periodic sequences.
FIGURE 6.3 The feedback shift register for Example 6.1.
Output
FIGURE 6.4 The feedback shift register for Example 6.2.
\. Feedback Shift Registers, Periodicity Properties 189
6.3. Definition. LetS be an arbitrary nonempty set, and let s0, s1, ••• be a
sequence of elements of S. If there exist integers r > 0 and n 0 ;;. 0 such that
s,.+, = s,. for all n � n0, then the sequence is called ultimately periodic and r
is called a period of the sequence. The smallest number among all the
possible periods of an ultimately periodic sequence is called the least period
of the sequence.
6.4. Lemma. Every period of an ultimately periodic sequence is
divisible by the least period.
Proof Let r be an arbitrary period of the ultimately periodic
sequence s0, s1 .... and let r1 be its least period, so that we haves,.+,= s,. for
all n � n0 and s,.+,1 = s,. for all n � n1 with suitable nonnegative integers n0
and n I" If r were not divisible by ri' we could use the division algorithm for
integers to writer� mr1 + 1 with integers m;;. I and 0 < 1 < r1• Then, for all
n;;. max(n0, n1) we get
s,.=s,.+,=s,.+mr1+r=s,.+(m-1)r1+t= ·· · =s,.+t•
and so t is a period of the sequence, which contradicts the definition of the
least period. D
6.5. Definition. An ultimately periodic sequence s0, s1, ... with least
period r is called periodic if s.+, � s. holds for all n � 0, I,. .. .
The following condition, which is sometimes found in the literature,
is equivalent to the definition of a periodic sequence.
6.6. Lemma. The sequence s0, Sp ..• is periodic if and only if there
exists an integer r > 0 such that s,.+, = s,. for all n = 0,1, ....
Proof The necessity of the condition is obvious. Conversely, if the
condition is satisfied, then the sequence is ultimately periodic and has a
least period r1. Therefore, with a suitable n0 we have s,.+,1=s,. for all
n � n0. Now let n be an arbitrary nonnegative integer, and choose an integer
m � n0 with m = nmod r. Then s,.+,, = sm+rt = sm = s,., which shows that the
sequence is periodic in the sense of Definition 6.5. D
If s0, s1, ... is ultimately periodic with least period r, then the least
nonnegative integer n0 such that s,.+, = s,. for all n � n0 is called the
preperiod. The sequence is periodic precisely if the preperiod is 0.
We return now to linear recurring sequences in finite fields and
establish the basic results concerning the periodicity behavior of such
sequences.
6.7. Theanm. Let Fq be any finite field and k any positive integer.
Then every kth-order linear recurring sequence in IF q is ultimately periodic with
least period r satisfying r <; q•, and r.; q•-I if the sequence is homogeneous.
190 Linear Recurring Sequences
Proof We note that there are exactly q' distinct k-tuples of ele
ments of IF q· Therefore, by considering the state vectors sm, 0 � m � qk, of a
given k th-order linear recurring sequence in F q• it follows that s1 = si for
some i and j with 0 � i < j � q". Using the linear recurrence relation and
induction, we arrive at s,+J-i = s, for all n � i, which shows that the linear
recurring sequence itself is ultimately periodic with least period r � j-i �
qk In case the linear recurring sequence is homogeneous and no state vector
is the zero vector, one can go through the same argument, but with qk
replaced by q' -I, to obtain r .;; q' -I. If, however, one of the state vectors
of a homogeneous linear recurring sequence is the zero vector, then all
subsequent state vectors are zero vectors, and so the sequence has least
period r �I .;; q' -I. D
6.8, Example. The first-order linear recurring sequence s0, sl'··· in IF,, p
prime, with s,+ 1 � s, +I for n � 0, I, ... and arbitrary s0 E F, shows that the
upper bound for r in Theorem 6.7 may be attained. If IF• is any finite field
and g is a primitive element of IF • (see Definition 2.9), then the first-order
homogeneous linear recurring sequence s0,s1, •.• in Fq withs,+1=gs, for
n � 0, I, ... and s0 "'0 has least period r � q-I. Therefore, the upper bound
for r in the homogeneous case may also be attained. Later on, we shall show
that in any F • and for any k ;;, I there exist k th-orderhomogeneous linear
recurring sequences with least period r � q'-I (see Theorem 6.33). D
6.9. Example. For a first-order homogeneous linear recurring sequence in
IF •' it is easily seen that the least period divides q-I. However, if k ;;, 2,
then the least period of a k th-order homogeneous linear recurring sequence
need not divide qk-1. Consider, for instance, the sequence s0, s1, ... in IF5
with s0=0. s1=1, and s,+2=s,+1+s,1 for n=O,l, ... , which has least
period 20, as is shown by inspection. D
6.10. Example. A linear recurring sequence in a finite field is ultimately
periodic, but it need not be periodic, as is illustrated by a second-order
linear recurring sequence So, sl,. .. in F q with So* sl and s,+2 = s,+ I for
n �0,!,.... D
An important sufficient condition for the periodicity of a linear
recurring sequence is provided by the following result.
6.11. Theorem. If s0, s1, ... is a linear recurring sequence in a finite
field satisfying the linear recurrence relation (6.1), and if the coefficient a0 in
(6.1) is nonzero, then the sequence s0, s1, ... is periodic.
Proof According to Theorem 6.7, the given linear recurring se
quence is ultimately periodic. If r is its least period and n0 its preperiod,
then s•+• � s, for all ;, ;;, n0. Suppose we had n0;;, I. From (6.1) with
Feedback Shift Regi::.ters, Periodicity Properties 191
n � n0 + r-l and the fact that a0 * 0, we obtain
Using (6.1) with n � n0 -1, we find the same expression for s.,-1, and so
s,0 _1 +r = s,0 _ 1• This is a contradiction to the definition of the preperiod. D
Let s0, s1, ... be a kth-<>rder homogeneous linear recurring sequence
in F q satisfying the linear recurrence relation
s,+k = ak _1s,+k _1 + ak _ 2s11+k _ 2 + · · · + a0s, for n = 0, 1, ... , (6.2)
where a1 E IF • for 0.; j.; k-l. With this linear recurring sequence we
associate the k X k matrix A over F • defined by
0 0 0
0 0
0 0
0 0 0 0
0
0 (6.3)
If k � l, then A is understood to be the 1 X 1 matdx (a0). We note that the
matrix A depends only on the linear recurrence relation satisfied by the
gtven sequence.
6.12. Lemma. If s0, s1, .•. is a homogeneous linear recurring se
quence in F q satisfying (6.2) and A is the matrix in (6.3) associated with it,
then for the state vectors of the sequence we have
s. � s0A" for n � 0, l, ... . (6.4)
Proof Since s, = (s,, s,+ 1, ••• ,s,+k _d. one checks easily that
s.+ 1 � s.A for all n;. 0, so that (6.4) follows by induction. D
We note that the set of all nonsingular k X k matrices over F q forms
a finite group under matrix multiplication, called the general linear group
GL(k,F.).
6.13. Theorem. If s0, s1, .•. is a kth-order homogeneous linear recur
ring sequence in IF q satisfying (6.2) with a0 * 0, then the least period of the
sequence divides the order of the associated matrix A from (6.3) in the general
linear group GL(k,IF.).
192 Linear Recurring Sequences
Proof We have det A� (-I)'-1a0 "'0, so that A is indeed an
element of GL(k,Fq). If m is the order of A in GL(k,IFq), then from Lemma
6.12 we obtain sn+m=s0An+m=s0A11=S11 for all n�O. and somis a
period of the linear recurring sequence. The rest follows from Lemma 6.4. D
We remark that the above argument, together with Lemma 6.6, yields
an alternative proof for Theorem 6.11 in the homogeneous case. From
Theorem 6.13 it follows, in particular, that the least period of the sequence
s0,s1, ••• divides the order of GL(k,F.), which is known to be q<•'-kl!Z
(q -1Xq1-l) · · · (q' -I).
Let now s0, s1, ••• be a kth-order inhomogeneous linear recurring
sequence in IF q satisfying (6.1 ). By using (6.1) with n replaced by n + I and
subtracting from the resulting identity the original form of (6.1) we obtain
sn+k+1=bksn+k+b.t.:_1sn+k-l + ·· · +b0s11 forn=O,l, ... , (6.5)
where b0�-a0, b1�ar1-a1 for j�1,2, ... ,k-1, and b,�a,_,+l.
Therefore, the sequence s0,s,, ... can be interpreted as a (k + l)st-order
homogeneous linear recurring sequence in F q· Consequently, results on
homogeneous linear recurring sequences yield information for the inhomo
geneous case as well.
An alternative approach to the inhomogeneous case proceeds as
follows. Let s0, s 1,... be a k th-order inhomogeneous linear recurring se
quence in IF• satisfying (6.1), and consider the (k + I)X(k +I) matrix C
over IF q defined by
0 0 0 a
0 0 0 0 ao
0 0 0 a,
c� 0 0 0 a,
0 0 0 ak-1
If k �I, take
We introduce modified state vectors by setting
s�=(l,s11,S11+t•···•.fn+k-l) forn=O,l, ....
Then it is easily seen that s�+ 1 = s�C for all n � 0, and so s� = sQC11 for all
n:;, 0 by induction. If a0 "'0 in (6.1), then det C � ( -l)'-1a0 "'0, so that
the matrix Cis an element of GL(k +I. F.). One shows then as in the proof
of Theorem 6.13 that the least period of s0, s1, ... divides the order of C in
GL(k + I.F.).
2. Impulse Response Sequences, Characteristic Polynomial
2. IMPULSE RESPONSE SEQUENCES, CHARACfERISTIC
POLYNOMIAL 193
Among all the homogeneous linear recurring sequences in F q satisfying a
given kth-order linear recurrence relation such as (6.2), we can single out
one that yields the maximal value for the least period in this class of
sequences. This is the impulse response sequence d0, d1,. .. determined
uniquely by its initial values d0 � • · • � dk-2 � 0, dk-l �I (d0 �I if k �I)
and the linear recurrence relation
6.14. Example. Consider the linear recurrence relation
sn+s=sn+l+s", n=O,l, ... ,in!F2.
The impulse response sequence d0, d1, ••• corresponding to it is given by the
string of binary digits
OOOOIOOOIIOOIOIOIIIIIOOOOI···
of least period 21. A feedback shift register generating this sequence is
shown in Figure 6.5. We can think of this sequence as being obtained by
starting with the state in which each delay element is "empty" (i.e., contains
0) and then sending the "impulse" I into the rightmost delay element. This
explains the term "impulse response sequence." 0
6.15. Lemma. Let d0, d�o··· be the impulse response sequence in F•
satisfying (6.6), and let A be the matrix in (6.3). Then two state vectors dm and
d, are identical if and only if Am� A".
Proof The sufficiency follows from Lemma 6.12. Conversely, sup
pose that dm � d,. From the linear recurrence relation (6.6) we obtain then
dm+t � d,+, for alii;. 0. By Lemma 6.12 we get d,Am � d,A" for alii;. 0.
But since the vectors d0, d1, .•• , dk _1 obviously form a basis for the k-dimen
sional vector space IF; over F q• we conclude that Am = A". 0
6.16. Theore,_ The least period of a homogeneous linear recurring
sequence in F q divides the least period of the corresponding impulse response
sequence.
FIGURE 6.5 The feedback shift register for Example 6.14.
194 Linear Recurring Sequences
Proof Let s0, s1, .•• be a homogeneous linear recurring sequence in
IF • satisfying (6.2), let d0, d1, ••• be the corresponding impulse response
sequence, and let A be the matrix in (6.3). If r is the least period of
d0, d1, ••• and n0 the preperiod, then d,+, � d, for all n;. n0. It follows
from Lemma 6.15 that A"+'= A" for all n;;;;.n0, and so s,+,=s, for all
n;. n0 by Lemma 6.12. Therefore, r is a period of s0, s1, ••• , and an
application of Lemma 6.4 completes the proof. 0
6.17. Theorem. If d0, d1, ••• is a kth-order impulse response se
quence in F • satisfying (6.6) with a0 * 0 and A is the matrix in (6.3) associated
with it, then the least period of the sequence is equal to the order of A in the
genera/linear group GL(k,IF.).
Proof If r is the least period of d0, d1, ••• , then r divides the order
of A according to the Theorem 6.13. On the other hand, we have d, � d 0 by
Theorem 6. 11, and so Lemma 6. 15 yields A'� A0, which implies already the
desired result. 0
6.18. Example. For the linear recurrence relation s,+5 = s,.+ 1 + s,,
n � 0,1, ... , in F2 considered in Example 6.14 we have seen that the least
period of the corresponding impulse response sequence is equal to 21, which
is the same as the order of the matrix
0 0
1 0
A� 0 1
0 0
0 0 0 0
0 0
0 0
1 0
0 I
I
0
0
0
in GL(S,IF2). If the initial state vector of a linear recurring sequence in IF2
satisfying the given linear recurrence relation is equal to one of the 21
different state vectors appearing in the impulse response sequence, then the
least period is again 21 (since such a sequence is just a shifted impulse
response sequence). If we choose the initial state vector (1,1,1,0,1), we get
the string of binary digits I I 1 0 1 0 0 I I I 0 I··· of least period 7, and
the same least period results from any one of the 7 different state vectors of
this sequence in the role of the initial state vector. If the initial state vector is
( 1, I, 0, I, I), then we obtain the string of binary digits I 1 0 1 I 0 I 1 · · · of
least period 3, and the same least period results if any one of the 3 different
state vectors of this sequence is taken as the initial state vector. The initial
state vector (0,0,0,0,0) produces a sequence of least period I. We have now
exhausted all 32 possibilities for initial state vectors. 0
6.19. Theorem. Let s0, s1, ••• be a kth-order homogeneous linear
recurring sequence in F q with preperiod n0. If there exist k state vectors
S'"1,S'"2, ..• ,s'"" with m1 � n0 (1 � j � k) that are linearly independent over IF q•
2. Impulse RespOnse Sequences, Characteristic Polynomial 195
then both s0, s1, ••• and its corresponding impulse response sequence are
periodic and they have the same least period.
Proof Let r be the least period of s0, s1, ••• • For l.; j.; k we have
•m·A'�sm+,�sm· by using Lemma 6.12, and so A' is the k Xk identity ' ' ' matrix over IF q· Thus we get sr = s0Ar = s0, which shows that s0, s1, ••• is
periodic. Similarly, if d. denotes the nth state vector of the impulse response
sequence, then d, � d0A' � d0, and an application of Theorem 6.16 com
pletes the proof. D
6.20. Example. The condition m,;. n0 in Theorem 6.19 is needed since
there are k th-order homogeneous linear recurring sequences that are not
periodic but contain k linearly independent state vectors. Let d0, d1, ••• be
the second-order impulse response sequence in F q with dn+l = dn+ 1 for
n � 0, 1, .... The terms of this sequence are 0, l, l, l, .... Clearly, the state
vectors d0 and d1 are linearly independent over f q' but the sequence is not
periodic (note that n0 � l in this case). The converse of Theorem 6.19 is not
true. Consider the third-order linear recurring sequence s0, s 1, .•. in f 2 with
s,.+3�s. for n�O,l, ... and s0�(l,l,O). Then both s0,s1, ••• and its
corresponding impulse response sequence are periodic with least period 3,
but any three state vectors of s0, s1, ..• are linearly dependent over F2. D
Let s0, s1, ••• be a kth-order homogeneous linear recurring sequence
in F q satisfying the linear recurrence relation
sn+k=ak-lsn+k-l+ak-zSn+k-z+ ··· +a0�n forn=O,l, ... , (6.7)
where a1 E F • for 0 .; j .; k -l. The polynomial
f(x)�x'-a x'-1-a x'-2-···-a EF [x) k-1 k-2 0 q
is called the characteristic polynomial of the linear recurring sequence. It
depends, of course, only on the linear recurrence relation (6.7). If A is the
matrix in (6.3), then it is easily seen that f(x) is identical with the
characteristic polynomial of A in the sense of linear algebra�that is,
f(x) � det(xi-A) with I being the k X k identity matrix over F •. On the
other hand, the matrix A may be thought of as the companion matrix of the
monic polynomial f( x ).
As a first application of the characteristic polynomial, we show how
the terms of a linear recurring sequence may be represented explicitly in an
important special case.
6.21. Theore"'-Let s0, s1, ... be a kth-order homogeneous linear
recurring sequence in IF • with characteristic polynomial f(x ). If the roots
a1, ••• ,a, of f(x) are all distinct, then
k
s.� L f3,aj forn�O,l, ... ,
j-1 (6.8)
196 Linear Recurring Sequences
where {31, ••• ,{3, are elements that are uniquely determined by the initial values of the sequence and belong to the splitting field of f(x) over IF •.
Proof The constants {31, ••• ,{3, can be determined from the system
of linear equations
k
L cx.jf31 � s., n � 0, l, ... , k-I.
j -I
Since the determinant of this system is a Vandermonde determinant, which
is nonzero by the condition on a1, ••• ,a,, the elements /31, ••• , {3, are uniquely
determined and belong to the splitting field F.(a1, ••• ,a,) off(x) over IF•,
as is seen from Cramer's rule. To prove the identity (6.8) for all n ;;. 0, it
suffices now to check whether the elements on the right-hand side of (6.8),
with these specific values for {31, ••• ,{3,, satisfy the linear recurrence relation
(6. 7). But
k k k
� {Ja"+'-a � f3a•+k-l_a � f3a•+k-l_ l.....jj k-11.....)} k-21.....}}
j-1 j-1 j-1
k
L f3J(a1)aj�O
j=l
for all n ;;. 0, and the proof is complete. k ... -ao L f3;aj
J-1
0
6.22. Example. Consider the linear recurring sequence s0,s1, ••• in F2
with s0 = s1 = 1 and s,1+2 = s,+ 1 + s, for n = 0, 1, .... The characteristic
polynomial isf(x) �x2-x-lEF2[x]. If IF4�1F2(a), then the roots of
f(x) are a1 �a and a2 � l +a. Using the given initial values, we obtain
{31 + {32 � l and {31a + {32(1 +a)� l, hence {31 �a and {32 � l +a. By Theo
rem 6.21 it follows that s. � a•+ 1 + (l + a)"+ 1 for all n ;;. 0. Since {33 � l for
every nonzero {3 E F 4, we deduce that s,+ 3 = s, for all n � 0, which is in
accordance with the fact that the least period of the sequence is 3. 0
6.23. Remark. A formula similar to (6.8) is valid if the multiplicity of
each root off( x) is at most the charact eristic p of IF •. In detail, let a1, •••• am
be the distinct roots of f(x), and suppose that each a,, i � l,2, ... ,m, has
multiplicity e,.;; p and that e, � l if a,� 0. Then we have
m s. � L P, ( n) a7 for n � 0, l, ... ,
;-1
where each P,, i � l,2, ... ,m, is a polynomial of degree less than e, whose
coefficients are uniquely determined by the initial values of the sequence
and belong to the splitting field of f(x) over F •. The integer n is of course
identified in the usual way with an element ofF •. The reader familiar with
differential equations will observe a certain analogy with the general solu-
2. Impulse RespOnse Sequences. Characteristic Polynomial 197
tion of a homogeneous linear differential equation with constant coeffi
cients. 0
In case the characteristic polynomial is irreducible, the elements of
the linear recurring sequence can be represented in terms of a suitable trace
function (see Definition 2.22 and Theorem 2.23 for the definition and basic
properties of trace functions).
6.24. Theorem. Let s0, s1,... be a kth-order homogeneous linear
recurring sequence in K = IF q whose characteristic polynomial f( x) is irreduc
ible over K. Let a be a root off( x) in the extension field F � f •'" Then there
exists a uniquely determined 8 E F such that
s.�TrF;K(8a") forn�O.l, ....
Proof Since {l,a, ... ,a•-1) constitutes a basis of Fover K, we can
define a uniquely determined linear mapping L from F into K by setting
L(a")�s. for n�O,l, ... ,k-1. By Theorem 2.24 there exists a uniquely
determined 8 E F such that L(y) � TrF;K(8y) for all "Y E F. In particular,
we have
s.�TrF;K(8a") forn=O,l, ... ,k-1.
It remains to. show that the elements TrF;K(8a"), n =0, 1, ... , form a
homogeneous linear recurring sequence with characteristic polynomial f(x).
But if f(x)=x•-a._,x•-1-•·· -a0EK[x], then using properties of
the trace function we get
TrF1K(8a•+•)-a._1TrF;K(8a•+k-l)-· ·· -a0TrF;K(8a")
-Tr (8an+k_a 8a"+k-1-···-a8an) -F/K k -I 0
� TrF;K(8a"f(a)) � 0
for all n ;;, 0. 0
Further relations between linear recurring sequences and their char
acteristic polynomials can be found on the basis of the following polynomial
identity.
6.25. Theorem. Let s0, s1, ... be a kth-order homogeneous linear
recurring sequence in F q that satisfies the linear recurrence relation (6.7) and is
periodic with period r. Let f(x) be the characteristic polynomial of the
sequence. Then the identity
f(x)s(x)� (1-x')h(x) (6.9)
holds with
198 Linear Recurring Sequences
and
k-1 k-1-j
h(x)= l: l: a1+J+Is,x1EFq[x].
J-O ;�o
where we set ak = -1. (6.10)
Proof We compare the coefficients on both sides of (6.9). For
0 .;; 1 .;; k + r-I, let c, (resp. d,) be the coefficient of x' on the left-hand
side (resp. right-hand side) of (6.9). Since f(x) =-E7_0a1x1, we have
c,=- l: a,.s,_1_1 forO::e;;t ::e;;k+r-1.
O<.i<:k.O<j<.r-1 i+ J-t (6.11)
We note also that the linear recurrence relation (6.7) may be written in the
form
k
l: a;sn+i = 0 for all n � 0.
;-o (6.12)
We distinguish now four cases. If k <;; I<;; r -I, then by (6.11) and (6.12),
k
c,=-l: a,.s,_1_1+;=0=d,.
;-o
Ift<;;r-1 and t<k, then by (6.11), (6.12), and the periodicity of the given
sequence,
k
c,=-l: a;sr-1-r+i= l: a;sr-1-t+i
;-o ;-r+l
k k-1- r
l: a,.s1_1_1= l: a1+1+1s,.=d,.
i-r+l ;-o
If 1;. rand 1;. k, then by (6.11),
c=' i-t-r+! k-1-t+r
a;5r-l-t+i=-l: ai+t-r+ls;=d,.
;-o
If r <;;I< k, then by (6.11) and the periodicity of the given sequence,
c=' '
l:
i-t-r+l
k-1-t+r
l:
i-, ,_J
alsr-1-r+i =-l: ai+r-r+ lsi
;-o
k-!-t+r
l:
;-o
k-1-r k-!-t+r
l: ai+t+lsi+,-L ai+r-r+lsl i-0 ;-o
k-1-r k-1-t+r
l: ai+r+ls;-l: ai+t-r+ts;=d,.
i-0 i-0 D
2. Impulse Response Sequences, Characteristic Polyrlomial 199
In Lemma 3.1 we have seen that for any polynomial f(x)EIFq[x)
with /(0)"' 0 there exists a positive integer e such that f(x) divides x'-l.
This gave rise to the definition of the order off (see Definition 3.2). We give
the following interpretation of ord( fl.
6.26. Lemma. Let
I( ) k k-I k-2 IF [ 1 x =x -ak_1x -ak_2x -··· -a0E q x
with k ;.I and a0"' 0. Then ord(f(x)) is equal to the order of the matrix A
from (6.3) in the genera/linear group GL(k,IFq).
Proof Since A is the companion matrix of f(x ), the polynomial
f(x) is, in tum, the minimal polynomial of A. Consequently, if I is the k X k
identity matrix over F q• then we have A�= I for some positive integer e if
and only if f(x) divides x' -I. The result follows now from the definitions
of the order of f(x) and the order of A. D
6.27. Theorem. Let s0,s1, ..• be a homogeneous linear recurring
sequence in Fq with characteristic polynomial f(x)E Fq[x]. Then the least
period of the sequence divides ord(f(x)), and the least period of the corre
sponding impulse response sequence is equal to ord(f(x )). If f(O)"' 0, then
both sequences are periodic.
Proof If f(O)"' 0, then in ti1e light of Lemma 6.26 the result is
essentially a restatement of Theorems 6.13 and 6.17. In this case, the
periodicity property follows from Theorem 6.11. If f(O) � 0, then we write
f(x) � x"g(x) as in Definition 3.2 and set t, � sn+h for n � 0, l, .... Then
t0,t1, ••• is a homogeneous linear recurring sequence with characteristic
polynomial g(x), provided that deg(g(x)) > 0. Its least period is the same as
that of the sequence s0, s 1, .... Therefore, by what we have already shown,
the least period of s0,s1, ... divides ord(g(x))�ord(f(x)). The desired
result concerning the impulse response sequence follows in a similar way. If
g(x) is constant, the theorem is trivial. D
We remark that for /(0)"' 0 the least period of the impulse response
sequence may also be obtained from the identity (6.9) in the following way.
For the impulse response sequence with characteri stic polynomialf(x), the
polynomial h(x) in (6.10) is given by h(x) � -l. Therefore, if r is the least
period of the impulse response sequence, then f(x) divides x' -I by (6.9)
and so r;;. ord(/(x)). On the other hand, r must divide ord(/(x)) by the
first part of Theorem 6.27, and so r � ord(f(x)).
6.28. Theorem. Let s0, s1, .•• be a homogeneous linear recurring
sequence in IF q with nonzero initial state vector, and suppose the characteristic
polynomial f(x) E F q[x) is irreducible over IF q and satisfies f(O)"' 0. Then the
sequence is periodic with least period equal to ord(/( x )).
200 Linear Recurring Sequences
Proof The sequence is periodic and its least period r divides
ord(/(x)) by Theorem 6.27. On the other hand, it follows from (6.9) that
f(x) divides (x' -l)h(x). Since s(x), and therefore h(x), is a nonzero
polynomial and since deg(h(x)) < deg(/(x)), the irreducibility of /(x)
implies that f(x) divides x'-I, and so r;. ord(/(x)). D
Now we present a different proof of Corollary 3.4, which we restate
for convenience.
6.29. Theorem. Let f(x) E IF•[x] be irreducible over �"• with
deg(/(x)) = k. Then ord(/(x)) divides q' -I.
Proof We may assume without loss of generality that /(0) * 0 and
that f(x) is monic. We take a homogeneous linear recurring sequence in F •
that hasf(x) as its characteristic polynomial and has a nonzero initial state
vector. According to Theorem 6.28, this sequence is periodic with least
period ord(/(x)), so that altogether ord(/(x)) different state vectors appear
in it. If ord(/(x)) is less than q'-I, the total number of nonzero k-tuples
of elements of r •. we can choose such a k-tuple that does not appear as a
state vector in the sequence above and use it as an initial state vector for
another homogeneous linear recurring sequence in F • with characteristic
polynomial f(x). None of the ord(/(x)) different state vectors of the second
sequence is equal to a state vector of the first sequence, for otherwise the
two sequences would be identical from some points onwards and the initial
state vector of the second sequence would eventually appear as a state
vector in the first sequence-a contradiction. By continuing to generate
linear recurring sequences of the type above, we arrive at a partition of the
set of q'-I nonzero k-tuples of elements of F• into subsets of cardinality
ord(/(x)), and the conclusion of the theorem follows. D
6.30. Example. Consider the linear recurrence relation s,+6 = s,+4 + s,+2
+ s,+ 1 + s,, n = 0, I, ... , in F2. The corresponding characteristic polynomial
is/(x)=x6-x4-x 2-x-IEF 2[x]. The polynomial /(x) is irreducible
over F2• Furthermore, /(x) divides x21- I and no polynomial x'- I with
0 < e < 21, so that ord(/(x)) = 21. The impulse response sequence corre
sponding to the linear recurrence relation is given by the string of binary
digits
000001010010011001011000001···
of least period 21, as it should be. If (0, 0, 0, 0, I, I) is taken as the initial state
vector, we arrive at the string of binary digits
00001111011010101 1101000011 ...
of least period 21, and if (0,0,0, 1,0,0) is taken as the initial state vector, we
2. Impulse Response Sequences, Characteristic Polynomial 201
obtain the string of binary digits
.000 I 000 I I 0 I I Ill I 00 II I 000 I 00 · · ·
of least period 21. Each one of the nonzero sextuples of elements of F2
appears as a state vector in exactly one of the three sequences. Any other
nonzero initial state vector will produce a shifted version of one of the three
sequences, which is again a sequence of least period 21. 0
6.31. Example. If /(x) E IF.[x] with deg(f(x)) � k is reducible, then
ord(/(x)) need not divide q' -I. Consider f(x) � x' + x +IE IF2[x]. Then
f(x) is reducible since
x'+x+I�(x3+x2+I}(x2+x+l).
It follows, for instance, from Theorem 6.27 and Example 6.14 that
ord(/(x)) � 21, and this is not a divisor of 2' -I� 31. 0
Linear recurring sequences whose least periods are very large are of
particular importance in applications. We know from Theorem 6.7 that for
a k th-order homogeneous linear recurring sequence in IF q the least period
can be at most q' -I. In order to generate such sequences for which the
least period is actually equal to q' -I, we have to use the notion of a
primitive polynomial (see Definition 3.15).
6.32. Definition. A homogeneous linear recurring sequence in f • whose
characteristic polynomial is a primitive polynomial over IF • and which has a
nonzero initial state vector is called a maximal period sequence in IF q·
6.33. Theorem. Every kth-order maximal period sequence in IF q is
periodic and its least period is equal to the largest possible value for the least
period of any kth-order homogeneous linear recurring sequence in F q-namely,
q'-I.
Proof The fact that the sequence is periodic and that the least
period is q' -I is a consequence of Theorem 6.28 and Theorem 3.16. The
remaining assertion follows from Theorem 6. 7. 0
6.34. Example. The linear recurrence relation s,+1=sn+4+sn+3+s,+2
+ s", n � 0, I, ... , in F 2 considered in Example 6.2 has the polynomial
/(x) � x1-x4-x'-x2 -IE F2[x] as its characteristic polynomial. Since
/(x) is a primitive polynomial over F2, any sequence with nonzero initial
state vector arising from this linear recurrence relation is a maximal period
sequence in IF2. If we choose one particular nonzero initial state vector, then
the resulting sequence s0, s1,. .. has least period 27 -I� 127 according to
Theorem 6.33. Therefore, all possible nonzero vectors of IFI appear as state
vectors in this sequence. Any other maximal period sequence arising from
the given linear recurrence relation is just a shifted version of the sequence
s0,s1,.... 0
202 Linear Recurring Sequences
3. GENERATING FUNCTIONS
So far, our approach to linear recurring sequences has employed only linear
algebra, polynomial algebra, and the theory of finite fields. By using the
algebraic apparatus of formal power series, other remarkable facts about
linear recurring sequences can be established.
Given an arbitrary sequence s0, s1, ..• of elements of IF q' we associate
with it its generating function, which is a purely formal expression of the
type
"' G(x)=so+slx+s2x2+ ... +s,,x"+ ... = L snx"
n-O (6.13)
with an indeterminate x. The underlying idea is that in G(x) we have
"stored" all the terms of the sequence in the correct order, so that G ( x)
should somehow reflect the properties of the sequence. The name "generat
ing function" is, strictly speaking, a misnomer since we do not consider
G(x) in any way as a function, but just as a formal object (in an obvious
analogy, polynomials are essentially formal ob jects not to be confused with
functions). The term is carried over from the case of real or complex
sequences, where it may often turn out that the series analogous to the one
in (6.13) is convergent after substitution of a real or complex number x0 for
x, thus enabling us to attach a meaning to G(x0). In our present situation,
the question of the convergence or divergence of the expression in (6.13) is
moot, since we think of G ( x) as being nothing but a hieroglyph for the
sequence s0, s1, ....
In general, an object of the type
B(x)�b0+b1x+b2x2+ ··· +h .. x"+
with b0, b1, ... being a sequence of elements of IF •. is called a formal power
series (over F.). In this context, the terms b0, b1, ... of the sequence are also
called the coefficients of the formal power series. The adjective "formal"
refers again to the idea that the convergence or divergence (whatever that
may mean) of these expressions is irrelevant for their study. Two such
formal power series
00
B(x) � L b.,x" and
,,-o
over IF• are considered identical if b, � c, for all n � 0,1, .... The set of all
formal power series over IF q is then in an obvious one-to-one correspondence
with the set of all sequences of elements of IF •. Thus, it seems as if we have
not gained anything from the transition to formal power series (save a
conceptual complication). The raison d 'etre of these objects is the fact that
we can endow the set of all formal power series over IF q with a rich and
3. Generating Functions 203
interesting algebraic structure in a fairly natural way. This will be discussed
in the sequel.
We note first that we may think of a polynomial
p(x) �Po+ p1x + · · · + p,x' E F.(x]
as a formal power series over IF • by identifying it with
P(x) �Po+ p1x + · · · + p,x' +O·x>+1 +0·x'+2 + · · ·.
We introduce now the algebraic operations of addition and multiplication
for formal power series in such a way that they extend the corresponding
operations for polynomials. In detail, if
"' 00
B(x)� L b.x• and C(x)� L c.x•
•-0 .�o
are two formal power series over IF q• we define their sum to be the formal
power series
00
B(x)+C(x)� L (b.+c.)x"
n=O
and their product to be the formal power series
n
B(x)C(x)� L d.x•, whered.� L b,c._, forn�O,l, ....
n=O k=O
If B(x) and C(x) are both polynomials over F •. .then the operations above
obviously coincide with polynomial addition and multiplication, respec
tively. It should be observed at this point that the substitution principle,
which is so useful in polynomial algebra, is not valid for formal power
series, the simple reason being that the expression B(a) with a E IF• and
B(x) a formal power series over IF• may be meaningless. This is. of course,
the price we have to pay for disregarding convergence questions.
6.35. Example. Let
and
"'
C(x)�l+x+x2+ ··· +x"+ L l·x"
·-0
be formal power series over IF 3• Then
"'
B(x)+C(x)�x+2x2+x3+ ··· +x"+ ··· � L d.x•
n-0
with d0 � 0, d1 �I, d2 � 2, and d.� I for n;;. 3, and
B(x)C(x) �2+2x+O·x2+0·x3+ ··· �2+2x. 0
204 Linear Recurring Sequences
Addition of formal power series over IF q is clearly associative and
commutative. The formal power series 0 = L�_00 ·xn serves as an identity
element for addition, and if B(x) � f.':'�ob.x" is an arbitrary formal power
series over F 9, then it has the additive inverse L':�o(-bn)xn, denoted by
-B(x). As usual, we shall write B(x)-C(x) instead of B(x)+(- C(x)).
Evidently, multiplication of formal power series over !F q is commuta
tive,and theformalpowerseries 1=1+0·x+O ·x2+ ··· +0·x'1+ ···acts
as a multiplicative identity. Multiplication is associative, for if
"' 00 "'
B(x)� L b.x", C(x) � L c.x", and D(x) � L d.x",
"-0 n=O n-O
then ( B(x)C(x))D(x) and B(x)(C(x)D(x)) are both identical with
where L(n) is the set of all ordered triples (i, j, k) of nonnegative integers
with i + j + k = n. Furthermore, the distributive law is satisfied since
B(x)(C(x)+ D(x)) � ,,t (.t b,(c. _,+d._,) )x"
f: ( t b,c._,+ t b,d._,)x•
n-O k-0 k-0
f: ( t b,c,_,)x"+ f: ( t b,d._,)x"
n=O k-0 n-O k-0
� B(x )C(x )+ B(x) D(x ).
Altogether, we have shown that the set of all formal power series
over IFq, furnished with this addition and multiplication, is a commutative
ring with identity, called the ring of formal power series over f, and denoted
by F,[[xll· The polynomial ring IF0[xl is contained as a subring in IF0[[xll·
We collect and extend the information on IF q[[x II in the following theorem.
6.36. Theorem. The ring f ,[[x II of formal power series over IF q is an
integral domain containing IF q[x I as a subring.
Proof It remains to verify that IF0[[x]] has no zero divisors-that is,
that a product in l' q[[x II can only be zero if one of the factors is zero.
Suppose, on th� contrary, that we have B( x )C( x) � 0 with
00 00
B(x) � L b.x" "'0 and C(x) � L c,x" "'0 in IF,[[xl].
n=O •-0
Let k be the least nonnegative integer for which b, "'0. and let m be the
3. Generati ng Functions 205
least nonnegative integer for which em* 0. Then the coefficient of xk+m in
B(x)C(x) is bkc., * 0, which contradicts B(x)C(x) � 0. D
It will be important for the applications to linear recurring sequences
to find those B(x) E IF .Ux]] that possess a multiplicative inverse-that is,
for which there exists a C(x) E IF•[[x]] with B(x)C(x) � l. These formal
power series can, in fact, be characterized easily.
6.37. 111eorem. The formal power series
00
B(x)� I: b,x"EF.[[x]]
•-0
has a multiplicative inverse if and only if b0 * 0.
Proof If
""
C(x)� I: c,x"EIF.[[x]]
.-o
is such that B(x)C(x) � 1, then the following infinite system of equations
must be satisfied:
b0c0� 1
b0c1 + b1c0�0
b0c2 + b1c1 + b2c0 �o
. . .
bocn+blcn-1+ ... +bnco=O
From the first equation we conclude that necessarily b0 * 0. However, if this
condition is satisfied, then c0 is uniquely determined by the first equation.
Passing to the second equation, we see that c1 is then uniquely determined.
In general, the coefficients c0, c1, ••• can be computed recursively from the
first equation and the recurrence relation
"
cn=-b0-1 L bkcn-k rorn=t,2, ....
k =I
The resulting formal power series C(x) is then a multiplicative inverse of
B(x). D
If a multiplicative inverse of B(x) E IF.[[x]] exists, then it is, of
course. uniquely determined . We use the notation 1/B(x) for it. A product
A(x)(l/B(x)) with A(x) E F•[[x]] will usually be written in the form
A(x)/B(x). Since F.[[x]] is an integral domain, the familiar rules for
operating with fra ctions hold. The multiplicative inverse of B(x) or an
expression A(x)/B(x) can be computed by the algorithm in the proof of
206 Linear Recurring Sequences
Theorem 6.37. Long division also provides an effective means for accom
plishing such computations .
638. Example. Let B(x)�3+x+x 2, considered as a formal power
series over IF,. Then B(x) has a multiplicative inverse by Theorem 6.37. We
compute 1/B(x) by long division:
2+ x +4x2 +2x4 + · · ·
3+x+x'II+O·x + O·x2 + O·x3+0·x4+0·x'+O·x6+ · · ·
-l-2x -2x2
Thus we get 3x + 3x2 + O·x'
-3x -x2 x3
2x2 +
2x2
3+ x + x2 2 + x + 4x 2 + 2x4 + · · · .
6.39. Example. We compute A(x)/B(x) in F2[[x]], where
00
A(x)�I+x+x 2+x3+ ··· � L l·x"
n-O 0
and B(x) �I+ x + x'- Using long division, dropping the terms with zero
coefficients, and recalling that I � -I in F 2, we get:
l+x2+x3+x1+ ···
l+x+x�l+x +x2+x3+x4 +x5+x6+x7+x8+x9+x10+ ···
Therefore, I+ x + x3
x2 +x4 +xs
x2+x3 +xs
x3+x4 +x6
x3+x4 +x6
1 +X+ X2 + x3 + · · · ..:._c..:.:-'....:.:...-'....:.:...-.:-'--- � I + X 2 + X' + X 7 + .... 1 +X+ X3 0
3. Generating Functions 207
In order to apply the theory of formal power series, we consider now
a k th-order homogeneous linear recurring sequence s0, s1, ••• in F q satisfying
the linear recurrence relation (6.7) and define its reciprocal characteristic
polynomial to be
f*(x)�l-a,_1x-a,_2x2-••• -a0x'EF.[x]. (6.14)
The characteristic polynomial j(x) and the reciprocal characteristic poly
nomial are related by f*(x) � x'f(l/x). The following basic identity can
then be shown for the generating function of the given sequence.
6.40. Theorem. Let s0, s1,... be a kth-order homogeneous linear
recurring sequence in f q satisfying the linear recurrence relation (6.7),_ let
f*(x) E F .[x] be its reciprocal characteristic polynomial, and let G(x) E IF .nx ]]
be its generating function in (6.13). Then the identity
holds with G(x)�g(x) (6.15) f*(x)
k -I j
g(x) �-L L a1+k_1s1x1 EIF.[x],
j-0 i-0 (6.16)
where we set a,� -l. Conversely, if g(x) is any polynomial over IF• with
deg(g(x)) < k and if f*(x) E F.[x] is given by (6.14), then the formal power
series G(x) E F.[[x]] defined by (6.15) is" the generating function of a kth-order
homogeneous linear recurring sequence in F q satisfYing the linear recurrence
relation (6.7).
Proof We have
f*(x)G(x) �-( E a,_.,x")( E s.,x")
n-O n-O
'f,' ( t a,+k-js,)x'-E ( t a,+k-js,)xj
j-0 1-0 J=k i=j-k
�g(x)-E ( E a,s1_,+1)xl (6.17)
j-k. j-0
Thus, if the sequence s0, s1, ... satisfies (6.7), then f*(x)G(x) � g(x) be
cause of (6.12). Since f*(x) has a multiplicative inverse in F•[[x]] by
Theorem 6.37, the identity (6.15) follows. Conversely, we infer from (6.17)
that f*(x )G( x) is equal to a polynomial of degree less than k only if
k
L a1sj-k+i = 0 for all}> k.
j-0
208 Linear Recurring Sequences
But these identities just express the fact that the sequence s0,s1, ... of
coefficients of -G ( x) satisfies the linear recurrence relation (6.7). D
One may summarize the theorem above by saying that the k th-order
homogeneous linear recurring sequences with reciprocal characteristic poly
nomial /*( x) are in one-to-one correspondence with the fractions
g(x)//*(x) with deg(g(x)) < k. The identity (6.15) can be used to compute
the terms of a linear recurring sequence by long division.
6.41. Example. Consider the linear recurrence relation
Its reciprocal characteristic polynomial is
/*(x) � 1-x-x3-x4 �I+ x + x3 + x4 EIF2[x].
If the initial state vector is (1,1,0,1), then the polynomial g(x) in (6.16)
turns out to be g(x) �I+ x2 Therefore. the generating function G(x) of
the sequence can be obtained from the following long division:
+x +x3+x4+x6+ · · ·
l+x+x3+x41 +x2
The result is 1 +x +x3+x4
x +x2+x3+x4
x +x2 +x4+ x5
x4+ x5+x6+x1
x4+ xs +x7+xs
) I + x2 3 4 6 G(x �-----:--- c�l+x+x +x +x + ...
1+x+x 3+x4 '
which corresponds to the string of binary digits I 1 0 11 0 I · · · of least
period 3. The impulse response sequence associated with the given linear
recurrence relation can be obtained by observing that g(x) = x3 in this case,
so that an appropriate long division yields
which corresponds to the string of binary digits 000 Ill 000 1 II · · · of
least period 6. D
3. Generating Functions 209
On the basis of the identity (6.15), we present now an alternative
proof of Theorem 6.25. Since the sequence s0, s1, ••• is periodic with period
r, its generating function G(x) can be written in the form
G(x)�(s +sx+···+s x'-')(l+x'+x''+···)�s*(x) o 1 r-1 I-x'
with s*( x) = s0 + s1 x + · · · + s, _ 1x'- 1• On the other hand, using the nota
tion of Theorem 6.40 we have G(x) � g(x)/f*(x) by (6.15). By equating
these expressions for G(x), we arrive at the polynomial identity f*(x)s*(x)
� (l-x')g(x). If f(x) and s(x) are as in (6.9), then
f( x) s( x) � x'J•( ±) x'-1s*( ±) � ( x'-l) x' -'g( ±),
and a comparison of (6.10) and (6.16) shows that
x'-'g(±) �-h(x). (6.18)
which implies already (6.9).
As another application of (6.15) we derive a general formula for the
terms of a linear recurring sequence. Let s0, s1, ... be a kth-order homogeneous
linear recurring sequence in IF, with characteristic polynomialf(x) E f, [ x]. Let
e0 be the multiplicity of 0 as a root of f(x), where we can have e0 � 0, and let
a1, ... , am be the distinct nonzero roots of f(x) with multiplicities e1, ••• , em,
respectively. For the reciprocal characteristic polynomial we obtain then
Since deg(f*(x)) � k-e0, we get from (6.15)
g(x) .,-1 , b(x) G(x) = f*(x) = J. t,x + f*(x)
with t,E IF, and deg(b(x)) < k-e0. Partial fraction decomposition yields
b(x) m "-1 {JiJ
f*(x) = 1�1 J�O (I -a,x)i+ 1'
where the {JIJ belong to the splitting field of f(x) over IF,. Now
and so I
(I -a ,x)i+ 1 f (n: j)a;x",
n-O ]
Q) 00 m e;-1 n+j •o-1 ( ( ) )
G(x) = .�o s,x" = J. t,x' + .�o J, J. j fJ;;ai x".
210 Linear Recurring Sequences
Comparison of coefficien ts yields
m "-'(n+j)
s, = t, + L L . fiijrt: 1=1 j=O ) for n = 0, 1, ... ,
where tn = 0 for n � e0• This is the desired formula. If e0 � 1 and ei � p for
1 � i � m, where p is the characteristic of f q' then it is easily seen that this
formula is equivalent to the one given in Remark 6.23.
4. THE MINIMAL POLYNOMIAL
Although we have not yet pointed it out. it is evident that a linear recurring
sequence satisfies many other linear recurrence relations apart from the one
by which it is defined. For instance, if the sequence s0, s1 .... is periodic with
period r, it satisfies the linear recurrence relations s,.,+,.=sn (n =0.1, ... ),
511+2,. = sn (n = 0,1, ... ), and so on. The most extreme case is represented by
the sequence 0,0,0, ... , which satisfies any homogeneous linear recurrence
relation. The following theorem describes the relationship between the
various linear recurrence relations valid for a given homogeneous linear
recurring sequence.
6.42. Theorem. Let s0• s1, ••• be a homogeneous linear recurring
sequence in IF q· Then there exists a uniquely determined monic polynomial
m(x) E IF,[x 1 having the following property: a monic polynomial f(x) E F ,[x 1
of positive degree is a characteristic polynomial of s0, s1,. .. if and only if m(x)
divides f(x).
Proof Let f0(x) E F,[x1 be the characteristic polynomial of a
homogeneous linear recurrence relation satisfied by the sequence, and let
h0(x) E IF,[x1 be the polynomial in (6.10) determined by f0(x) and the
sequence. If d(x) is the (monic) greatest common divisor of f0(x) and
h0(x), then we can write f0(x) = m{x)d(x) and h0(.<) � b(x)d(x) with
m(x), h(x) E IF,[x]. We shall prove that m(x) is the desired polynomial.
Clearly, m(x) is monic. Now let f(x) E IF,[x) be an arbitrary characteristic
polynomial of the given sequence, and let h(x) E F,[x1 be the polynomial in
(6.10) determined by f(x) and the sequence. By applying Theorem 6.40, we
obtain that the generating function G(x) of the sequence satisfies
G(x) = g0(x) = g(x) fo*(x) r(x)
with g0(x) and g(x) determined by (6.16). Therefore g(x)fo*(x) =
g0(x)f*(x), and using (6.18) we arrive at
h (x )f0( x) = -xd<r.<f<x)>-'g( ±) xd<g(f,(xllf.,O ( ±)
4. The Minimal Polynomial 2tt
� -xd<g(f,(xll-I go ( �) xd<&lfl•llj• ( �) � ho (X)/( X).
After division by d(x) we have h(x)m(x) � b(x)f(x), and since m(x) and
b(x) are relatively prime, it follows that m(x) dividesf(x).
Now suppose that f(x) E IF•[x] is a monic polynomial of positive
degree that is divisible by m(x), say f(x) � m(x)c(x) with c(x) E IF•[x].
Passing to reciprocal polynomials, we getf*(x) � m*(x)c*(x) in an obvious
notation. We also have h0(x)m(x) � b(x)f0(x), so that, using the relation
(6.18), we obtain
go( X) m*( X) � -Xdog(f,(x))-lho ( � )xdeg(m(x))m ( �)
� -xd<g(m(x))-lb ( �) x•<&lfol•))to ( �).
Since deg(b(x)) < deg(m(x)), the product of the first two factors on the
right-hand side (negative sign included) is a polynomial a(x) E F .lx ].
Therefore, we have g0(x)m*(x) � a(x)frj(x). It follows then from Theorem
6.40 that the generating function G(x) of the sequence satisfies
Since G(x) � go(x) � � � a(x)c•(x) � a(x)c*(x)
f0*(x) m*(x) m*(x)c*(x) f*(x)
deg(a(x )c•(x )) � deg( a(x )) +deg( c•(x ))
< deg( m ( x)) + deg( c ( x)) � deg(/ ( x)),
the second part of Theorem 6.40 shows that f(x) is a characteristic
polynomial of the sequence. It is clear that there can only be one poly
nomial m(x) with the indicated properties. D
The uniquely determined polynomial m ( x) over F • associated with
the sequence s0, s1 .... according to Theorem 6.42 is called the minimal
polynomial of the sequence. If s, � 0 for all n ;;. 0, the minimal polynomial is
equal to the constant polynomial I. For all other homogeneous linear
recurring sequences, m(x) is a monic polynomial with deg(m(x)) > 0 that
is. in fact, the characteristic polynomial of the linear recurrence relation of
least possible order satisfied by the sequence. Another method of calculating
the minimal polynomial will be introduced in Section 6.
6A3. Example. Let s0, s1 .... be the linear recurring sequence in IF2 with
sn+4=sn+J+sn+l+sn, n=O,l, ... ,
and initial state vector (1, 1,0, I). To find the minimal polynomial, we
proceed as in the proof of Theorem 6.42. We may take f0(x) � x4-x3-
x-l�x 4+x3+x+lEIF 2[x]. Then by (6.10) the polynomial h0(x) is
212 Lin�ar Recurring Sequences
given by h0(x) � x3 + x. The greatest common divisor off0(x) and h0(x) is
d(x) � x2 + 1, and so the minimal polynomial of the sequence is m(x) �
f0(x)/d(x) � x2 + x + 1. One checks easily that the sequence satisfies the
linear recurrence relation
Sn+2=sn+l+sn, n=O,I, ... ,
as it should according to the general theory. We note that ord(m(x)) � 3,
which is identical with the least period of the sequence (compare with
Example 6.41). We shall see in Theorem 6.44 below that this is true m
p�. D
The minimal polynomial plays a decisive role in the determination of
the least period of a linear recurring sequence. This is shown by the
following result.
6.44. Theorem. Let s0, sp··· be a homogeneous linear recurring
sequence in IF• with minimal polynomial m(x) E F.[x]. Then the least period of
the sequence is equal to ord( m ( x )).
Proof If r is the least period of the sequence and n0 its preperiod,
then we have sn+r = sn for all n � n0. Therefore. the sequence satisfies the
homogeneous linear recurrence relation
sn+na+r = sn+no for n = 0, I, ....
Then, according to Theorem 6.42, m(x) divides x"o+r-x"0 = x"0(Xr-1),
so that m(x) is of the form m(x) � x•g(x) with h.;;; n0 and g(x) E F.[x],
where g(O) * 0 and g( x) divides x'-1. It follows from the definition of the
order of a polynomial that ord(m(x)) � ord(g(x)).;;; r. On the other hand, r
divides ord(m(x)) by Theorem 6.27, and so r � ord(m(x)). D
6.45. Example. Let s0, s1, ... be the linear recurring sequence in IF2 with
s.+s �s.+1 +s •. n � 0, 1, ... , and initial state vector (1, l, 1,0, 1). Following
the method in the proof of Theorem 6.42, we take /0( x) � x5 -x -1 �
x5 + x + 1 E IF2[x] and get h0(x) � x4 + x3 + x2 from (6.10), Then d(x) �
x2 + x + 1, and so the minimal polynomial m(x) of the sequence is given by
m(x) � f0(x )/d(x) � x3 + x2 + 1. We have ord(m(x)) � 7, and so Theorem
6.44 implies that the least period of the sequence is 7 (compare with
Example 6.18). D
The argument in the example above shows how to find the least
period of a linear recurring sequence without evaluating its terms. The
method is particularly effective if a table of orders of polynomials is
available. Since such tables usually incorporate only irreducible polynomials
(see Chapter 10, Section 2), the results in Theorems 3.8 and 3.9 may have to
be used to find the order of a given polynomial (compare with Example
3.10).
4. The Minimal Polynomial '213
6.46. Example. The method in Example 6.45 can also be applied Jo
inhomogeneous linear recurring sequences. Let s0• s 1, ••• be such a seqUeil'ce.
in rF2 with
sn+4=s,+3+sn+1+s11+l forn=O.I, ...
and initial state vector (1, 1,0, 1). According to (6.5), the sequence is also
given by the homogeneous linear recurrence relation sn+ 5 = sn+J + S11 + 1 + S11,
n � 0, 1, ... , with initial state vector (1, 1.0.1,0). Proceeding as in Example
6.45, we find that the characteristic polynomial
f(x) � x5 +x' +x' +I� (x + l)'(x' + x +I) E IF2[x]
IS m the present case identical with the minimal polynomial m(x) of the
sequence. Since ord(( x + I)')� 4 by Theorem 3.8 and ord( x2 + x + I)� 3,
it follows from Theorem 3.9 that ord(m(x)) � 12. Therefore, the sequence
s0, s1 .... is periodic with least period 12. D
6.47. Example. Consider the linear recurring sequence s0,s1, ... in F2
with
S11+4=sn+2+sn+l forn=O,I, ...
and initial state vector (1,0, 1,0). Then
f(x) �x4 +x2 +x �x(x' + x + 1) E F2[x]
Is a characteristic polynomial of the sequence, and since neither x nor
x3 + x +I is a characteristic polynomial .. we have m(x) = x4 + x2 + x. The
sequence is not periodic,. but ultimately perio\lic with least period
ord(m(x))�7. D
6.48. Theorem. Let s0, s1, ••• be a homogeneous linear recurring
sequence in rF q and let b be a positive integer. Then the minimal polynomial
m1(x) of the shifted sequence s., sb+ 1, ... divides the minimal polynomial
m( x) of the original sequence. If s0, s1, ... is periodic, then m 1( x) � m( x ).
Proof To prove the first assertion, it suffices to show because of
Theorem 6.42 that every homogeneous linear recurrence relation satisfied by
the original sequence is also satisfied by the shifted sequence. But this is
immediately evident. For the second part, let
s,+b+l.:=ak-lsn+b+lt-1+ ... +aosn+b• n=O,I, ... ,
be a homogeneous linear recurrence relation satisfied by the shifted se
quence. Let r be a period of s0, s1, ••• , so that sn+r = s, for all n � 0, and
choose an integer c with cr �b. Then, by using the linear recurrence relation
with n replaced by n + cr-band invoking the periodicity property, we find
that
sn+�.:=a�,:_1s"+�t:-l+ ··· +a0s" foralln>O,
that is, that the sequence s0, s1, ... satisfies the same linear recurrence
relation as the shifted sequence. By applying again Theorem 6.42, we
conclude that m.l xl � mt x\. n
214 Linear Recurring Sequences
6.49. Example. Let s0,s1, .•. be the linear recurring sequence in f2 con
sidered in Example 6.47. Its minimal polynomial is x4 + x2 + x, whereas the
minimal polynomial of the shifted sequence s1, s2, ... is x3 + x +I, which is
a proper divisor of x4 + x2 + x. This example shows that the second
assertion in Theorem 6.48 need not hold if s0, s1, ••• is only ultimately
periodic. but not periodic. D
6.50. Theorem. Let f(x) E IF ,[x] be monic and irreducible over IF,.
and let s0• s1 •... be a homogeneous linear recurring sequence in IFq not all of
whose terms are 0. If the sequence has f(x) as a characteristic polynomial,
then the minimal polynomial of the sequence is equal to f(x ).
Proof Since the minimal polynomial m ( x) of the sequence divides
f(x) according to Theorem 6.42, the irreduci bility off(x) implies that either
m(x) �I or m(x) � f(x). But m(x) �I holds only for the sequence all of
whose terms are 0, and so the result follows. D
There is a general criterion for deciding whether the characteristic
polynomial of the linear recurrence relation defining a given linear recurring
sequence is already the minimal polynomial of the sequence.
6.51. Theorem. Let s0,s1, ... be a sequence in IF, satisfying a kth
order homogeneous linear recurrence relation with characteristic polynomial
f(x) E F,[x]. Then f(x) is the minimal polynomial of the sequence if and only
1/ the state vectors s0• s1, ..• , sk _1 are linearly i':'dependent over f q·
Proof Suppose f(x) is the minimal polynomial of the sequence. If
s0• s1, ...• sk _ 1 were linearly dependent over F q• we would have b0s0 + b1s1
+ · · · + b,_1s,_1 �Owithcoefficientsb0,b1, ... ,b,_1 E!'9not all of which
are zero. Multiplying from the right by powers of the matrix A in (6.3)
associated with the given linear recurrence relation yields
b0sn+b1sn+1+ ··· +blr._1sn+k-1=0 forn=O,l, ....
because of (6.4). In particular, we obtain
b0s_n+b1sn+1+ ··· +bk_1sn+k-1=0forn=O,l, ....
If b; � 0 for I� j � k -I, it follows that s, � 0 for all n;,. 0, a contradiction
to the fact that the minimal polynomial f(x) of the sequence has positive
degree. In the remaining case, let};,. I be the largest index with b1 * 0. Then
it follows that the sequence s0,s1, ... satisfies a jth-order homogeneous
linear recurrence relation with}< k. which again contradicts the assumption
that f(x) is the minimal polynomial. Therefore we have shown that
s0, s1, •.. ,sk _ 1 are linearly independent over IF q·
Conversely, suppose that s0, s1, ..• , sk _1 are linearly independent
over F •. Since s0 * 0, the minimal polynomial has positive degree. If f(x)
were not the minimal polynomial, the sequence s0,s1, ..• would satisfy an
5. Families of Linear Recurring Sequen(;es
mth-order homogeneous linear recurrence relation with 1 � m < k, say
sn+m=am-lsn+m-l+ ··· +a0s11 forn=O,l, ... 215
with coefficients from IF q· But this would imply sm =am _1sm _1 + · · · +
a0s0, a contradiction to the given linear independence property. D
6.52. CoroUary. If s0• s 1,... is an impulse response sequence for
some homogeneous linear recurrence relation in F q• then its minimal poly
nomial is equal to the characteristic polynomial of that linear recurrence
relation.
Proof
independence
quence. This follows from Theorem 6.51 since the required linear
property is obviously satisfied for an impulse response se
D
5. FAMILIES OF LINEAR RECURRING SEQUENCES
Letf(x)EF.[x] be a monic polynomial of positive degree. We denote the
set of all homogeneous linear recurring sequences in IF q with characteristic
polynomial f(x) by S(/(x)). In other words, S(/(x)) consists of all
sequences in F q satisfying the homogeneous linear recurrence relation
determined by f(x). If deg(/(x)) � k, then S(/(x)) contains exactly q•
sequences, corresponding to the qk diff�rent choices for initial state vectors.
The set S(/(x)) may be considered as avector space over IF• if
operations for sequences are defined termwise. In detail. if o is the sequence
s0, s1 •••• and., the sequence t0,t1, ... in f q' then the sumo+., is taken to be
the sequence s0 + t 0• s 1 + 11, .... Furthermore, if c E F q• then co is defined as
the sequence cs0, cs1 •••• • It is seen immediately from the recurrence relation
that S(/( x)) is closed under this addition and scalar multiplication. The
required axioms are easily checked. and so S(/(x)) is indeed a vector space
over IF •. The role of the zero vector is played by the zero sequence, all of
whose terms are 0. Since S(/(x)) has q• elements, the dimension of the
vector space is k. We obtain k linearly independent elements of S(/(x)) by
choosing k linearly independent k-tuples y1, .... y. of elements of IF• and
considering the sequences o1, .... o. belonging to S(/(x)), where each o1,
l .;; j.;; k, has y1 as its initial state vector. A natural choice for y1, .... y, is to
take the standard basis vectors
e1 � (l.O ..... O),e2 � (0, l, ... ,O). .... e, � (0, ... ,0,1).
Another possibility that is often advantageous is to consider the impulse
response sequence d0• d1, ... belonging to S(/( x)) and to choose for y1, ... ,y,
the state vectors d0, ... ,dk _1 of this impulse response sequence.
In the following discussion, we shall explore the relationship between
the various sets S(/( x )).
216 Linear Recurring Sequences
6.53. Theorem. Let f(x) and g(x) be two nonconstant monic poly·
nomials over F •. Then S(/(x)) is a subset of S(g(x)) if and only if f(x)
divides g(x ).
Proof Suppose S(/(x)) is contained in S(g(x)). Consider the
impulse response sequence belonging to S(/(x )). This sequence has f( x) as
its minimal polynomial because of Corollary 6.52. By hypothesis, the
sequence belongs also to S( g(x )). Therefore. according to Theorem 6.42, its
minimal polynomial f(x) divides g(x). Conversely, if f(x) divides g(x) and
s0, ·' 1, ••• is any sequence belonging to S(/(x )), then the minimal poly
nomial m(x) of the sequence divides f(x) by Theorem 6.42. Consequently,
m(x) divides g(x), and so another application of Theorem 6.42 shows that
the sequence s0,s1, ••• belongs to S(g(x)). Therefore, S(/(x)) is a subset of
S(g(x)). D
6.54. Theorem. Let f1 ( x ), ... ,f, ( x) be nonconstant monic polynomi
als over IF •. If f1(x), ... ,f,(x) are relatively prime, then the intersection
s(/,(x))n ·· · ns(/,(x))
consists only of the zero sequence. If f1(x), ... ,f,(x) have a (monic) greatest
common divisor d(x) of positive degree, then
S(/,(x))n · · · n s(/,(x)) � S(d(x)).
Proof The minimal polynomial m(x) of a sequence in the intersec
tion must divide f1(x), ... ,f,(x). In the case of relative primality, m(x) is
necessarily the constant polynomial I; but only the zero sequence has this
minimal polynomial. In the second case, we conclude that m(x) divides
d(x), and then Theorem 6.42 implies that S(/1(x))n ·· · ns(/,(x)) is
contained in S(d(x)). The fact that S(d(x)) is a subset of S(/1(x))n · · · n
S( f,(x)) follows immediately from Theorem 6.53. D
We define S(/(x))+ S(g(x)) to be the set of all sequences a+ T with
a E S(/(x)) and T E S(g(x)). This definition can, of course, be extended to
any finite number of such sets.
6.55. Theorem. Let f1 ( x ), ... J, ( x) be nonconstant monic polynomi
als over F q· Then
S(/1(x))+ ·· · +S(/,(x))�S(c(x)),
where c(x) is the (monic) least common multiple of f1 (x ), ... ,f,(x ).
Proof It suffices to consider the case h � 2 since the general case
follows easily by induction. We note first that, according to Theorem 6.53,
each sequence belonging to S(/1(x)) or to S(/2(x)) belongs to S(c(x)), and
since the latter is a vector space, it follows that S(/1(x))+ S(/2(x)) is
contained in S(c(x)). We compare now the dimensions of these vector
5. Families of Linear Recurring Sequences 217
spaces over F •. Writing V1 � S(/1(x)) and V2 � S(/2(x)) and letting d(x)
be the (monic) greatest common divisor of f1(x) and f2(x), we get
dim(V, + V2) � dim(V1)+dim(V2)-dim(V1 n V2)
� deg{!1 (x )) +deg{!2 ( x)) -deg( d( x )) ,
where we have applied Theorem 6.54. But c(x)� f1(x)f2(x)jd(x), and so
dim(V1 + V2) � deg(c(x)) � dim{S(c(x))).
Therefore, the linear subspace S(/1(x))+ S(/2(x)) has the same dimension
as the vector spaceS( c(x )), and so S(/1(x ))+ S(/2(x)) � S( c(x )). D
In the special case where f( x) and g( x) are relatively prime noncon
stant monic polynomials over F q• we will have
S{f(x )g(x )) � S(/(x )) + S(g(x )) .
Since, in this case, Theorem 6.54 shows that S(f(x ))n S(g(x)) consists only
of the zero sequence, S(f(x)g(x) ) is (in the language of linear algebra) the
direct sum of the linear subspaces S(/(x)) and S(g(x)). In other words,
every sequence o E S(/(x)g(x)) can be expressed uniquely in the form
o � o1 + o2 with o1 E S(/(x)) and o2 E S(g(x)).
Let us recall that S(/(x)) is a vector space over F• whose dimension
is equal to the degree off(x). This vector space has an interesting additional
property: if the sequence s0, s1, ... belongs to S(f(x )), then for every integer
b>O the shifted sequence sb,sb+1,.:. again belongs to S(/(x)). This
follows, of course, immediately from the linear""' recurrence relation. We
express this property by saying that S(/(x)) is closed under shifts of
sequences. Taken together, the properties listed here characterize the sets
S(f(x)) completely.
6.56. Theorem. Let E be a set of sequences in IF q· Then E � S(f(x ))
for some monic polynomial f( x) E IF .I x] of positive degree if and only if E is a
vector space over F q of positive finite dimension (under the usual addition and
scalar multiplication of sequences) which is closed under shifts of sequences.
Proof We have already noted above that these conditions are
necessary. To establish the converse, consider an arbitrary sequence o E E
that is not the zero sequence. If s0, s1, ••• are the terms of o and b;. 0 is an
integer, we denote by o<•l the shifted sequence sb, sb+ 1, .... By hypothesis,
the sequences o<01,o01,o(21, ... all belong to E. But Eisa finite set, and so
there exist nonnegative integers i < j with o"l � o<i1. It follows that the
original sequence a satisfies the homogeneous linear recurrence relation
s.+1�s.+;• n�O,l, .... According to Theorem 6.42, the sequence o has
then a minimal polynomial m.(x) E F•[x] of positive degree k, say. The
state vectors s0,s1, ... ,s •. 1 of the sequence o are thus lineasly independent
over F• by virtue of Theorem 6.51. Consequently, the sequences
218 Linear Recurring Sequences
a'0', a''' .... ,a''-" are linearly independent elements of S(m.(x)) and
hence form a basis for S(m.(x)). Since a'0'.a(l' .... ,a''-'' belong to the
vector space E, it follows that S(m.(x)) is a linear subspace of E. Letting
E* denote the set E with the zero sequence deleted and carrying out the
argument above for every a E E*, we arrive at the statement that the finite
sum E.E pS(m.(x) ) of vector spaces is a linear subspace of E. On the
other hand, it is trivial that E is contained in E.EPS(m.(x)), and so
E =E. E pS(m.(x) ). By invoking Theorem 6.55, we get
E = L, S(m.(x)) = S(/(x)),
where f(x) is the least common multiple of all the polynomials m.(x) with
a running through E*. 0
It follows from Theorem 6.55 that the sum of two or more homoge
neous linear recurring sequences in f q is again a homogeneous linear
recurring sequence. A characteristic polynomial of the sum sequence is also
obtained from this theorem. In important special cases, the minimal poly
nomial and the least period of the sum sequence can be determined directly
on the basis of the corresponding information for the original sequences.
6.57. Theorem. For each i = I, 2, ... , h, let a, be a homogeneous
linear recurring sequence in F • with minimal polynomial m 1 ( x) E IF •[ x ]. If the
polynomials m1(x), ... ,m,(x) are pairwise relatively prime, then the minimal
polynomial of the sum a1 + · · · +a, is equal to the product m1(x) · · · m,(x).
Proof It suffices to consider the case h = 2 since the general case
follows then by induction. If m1(x) or m2(x) is the constant polynomial I,
the result is trivial. Similarly, if the minimal polynomial m(x) E IF'_[x] of
a1 + a2 is the constant polynomial 1. we obtain a trivial case. Therefore, we
assume that the polynomials m1(x), m2(x), and m(x) have positive degrees.
Since
a1 '\-a2 E S( m1(x ))+ S( m2(x )) = S(m1 (x )m2(x ))
on account of Theorem 6.55, it follows that m(x) divides m1(x)m2(x).
Now suppose that the terms of. a1 are s0, s1, ... , that those of a2 are
10, 11, ... , and that
Then
sn+k+t,.+�c.=a�c.-l(sn+k-l+t,.+k-1)+ ... +ao(s"+t") forn=O.l, ....
If we set
Un=Sn+k-ak-\Sn+k-1-... -aos,.
=-tn+k+ak-lln+k-l+ ··· +a0t11 forn=O,l, ...
5. Families of Linear Recurring Sequences 219
and recall that S(m1(x)) and S(m2(x)) are vector spaces over IF• closed
under shifts of sequences (see Theorem 6.56), then we can conclude that the
sequence u0, u1, ••• belongs to both S(m1(x)) and S(m2(x)) and is thus the
zero sequence, according to Theorem 6.54. But this shows that both m1(x)
and m2(x) divide m(x), hence m1(x)m2(x) divides m(x), and so m(x) =
m1(x)m2(x). D
If the minimal polynomials m1(x), ... ,m,(x) of the individual se
quences o1, ... ,oh are not pairwise relatively prime, then the special nature of
the sequences o1, ... ,oh has to be taken into account in order to determine
the minimal polynomial of the sum sequence a = a 1 + · · · + a,. The most
feasible method is based on the use of generating functions. Suppose that
for i=l,2, ... ,h the generating function of a, is G,(x)EIF.[[x]]. Then the
generating function of a is given by G(x) = G1(x)+ · · · + G,(x). By Theo
rem 6.40, each G,(x) can be written as a fraction with, for instance, the
reciprocal polynomial of m,(x) as denominator. We add these fractions,
reduce the resulting fraction to lowest terms. and combine the second part
of Theorem 6.40 and the method in the proof of Theorem 6.42 to find the
minimal polynomial of a. This technique yields also an alternative proof for
Theorem 6.57.
6.58. Example. Let a 1 be the impulse response sequence in F 2 belonging
to S(x4 + x3 + x +I) and a2 the impulse response sequence in IF2 belonging
to S(x' + x4 + 1). Then, according .to Corollary 6.52, the corres ponding
minimal polynomials are
m1(x}=x4+x3 +x+ I= (x2 +x+ l}(x+ 1)2 EF2[x]
and
m 2 ( x) = x' + x4 +I = (x2 + x + I}( x3 + x + I) E F2 [ x ].
Using Theorem 6.40, the generating function G(x) of the sum sequence
a= o1 + o2 turns out to be
x3 x4 G (X ) = + ----cc----:---:-- -;:---
(x2+x+l}(x+l}2 (x2+x+l}(x3+x2+1}
x'
2 . (x3+x2+1}(x+l}
By the second part of Theorem 6.40, the reciprocal polynomial f0(x) =
(x3 + x + l)(x + 1)2 of the denominator is a characteristic polynomial of a.
According to (6.18}, the associated polynomial h0(x) is given by h0(x)=
-x4(1jx)3 =-x. Since f0(x) and h0(x} are relatively prime, the method
220 Linear Recurring Sequences
in the proof of Theorem 6.42 yields the minimal polynomial
rn (X) � ( X3 +X + 1 )(X+ 1 )2
foro. We note that rn(x) is a proper divisor of the least common multiple of
. m1(x) and m2(x), which is
(x2+x+1 )(x+1)2(x3+x+1 ). 0
From the information about the minimal polynomial contained in
Theorem 6.57, one can immediately deduce a useful result concerning the
least period of a sum sequence.
6.59. Theorem. For each i � 1,2, ... ,h, let o, be a homogeneous
linear recurring sequence in IF • with minimal polynomial m, ( x) E IF, [x] and
least period r,. If the polynomials m1(x), ... ,m,(x) are pairwise relatively
prime, then the least period of the sum o1 + · · · + o, is equal to the least
common multiple of r1, ••• ,r,.
Proof We consider only the case h � 2, the general result following
by induction. If r is the least period of o1 + o2, then r � ord(m1(x)m2(x))
by Theorems 6.44 and 6.57. An application of Theorem 3.9 shows that r is
the least common multiple of ord(m1(x)) and ord(m2(x)), and so of r1 and
�- 0
6.60. Example. Let the sequences o1 and o2 be as in Example 6.58. Then
the least periods of o1 and o2 are r1 � ord(m1(x)) � 6 and r2 � ord(m2(x))
� 21, respectively. The least period r of o1 + o2 is r � ord(m(x)) � 14. In
these computations of orders we use, of course, Theorem 3.9. The arguments
above have been carried out without having evaluated the terms of the
sequences involved. In this special case we may, of course, compare the
results with explicit computations of the least periods:
o,: 00011100011100011100011100···
�: 00001111101010011000100001 ... least period r 1 = 6
least period r2 = 21
o1 +o2: 00010011110110000100111101·· · leastperiod r�l4
Notice that r is a proper divisor of the least common multiple of r1 and r2. 0
6.61. Theorem. For each i � 1, 2, ... , h, let o, be an ultimately peri
odic sequence in IF q with least period r;. If r1, ••• ,r11 are painvise relatively
prime, then the least period of the sum o1 + · · · + o, is equal to the product
,1 ... 'n.·
Proof It suffices to consider the case h � 2 since the general case
follows then by induction. It is obvious that r1r2 is a period of o1 + o2, so
that the least period r of o1 + o2 divides r1r2• Therefore, r is of the form
5. Families of Linear Recurring Sequences 221
r � d1d2 with d1 and d2 being positive divisors of r1 and r2, respectively. In
particular, d1r2 is a period of a1 + a2• Consequently, if the terms of a1 are
s0,s1, ... and those ofa2 aret0,t1, ... , then we have
for all sufficiently large n. But t,+a,,, � t, for all sufficiently large n, and so
sn+d1r1 = S11 for all sufficiently large n. Therefore, r1 divides d1r2, and since r1
and r2 are relatively prime, r1 divides d1, which implies d1 � r1• Similarly,
one shows that d2 � r2. D
In the finite field IF 2, there is an interesting operation on sequences
called binary complementation. If a is a sequence in F2, then its binary
complement, denoted by ii, is obtained by replacing each digit 0 in a by I
and each digit I in a by 0. Binary complementation is, in fact, a special case
of addition of sequences since the binary complement ii of a arises by
adding to a the sequence all of whose terms are I. Therefore. if a is a
homogeneous linear recurring sequence, then ii is one as well. Clearly, the
least period of ii is the same as that of a. The minimal polynomial of ii can
be obtained from that of a in an easy manner.
6.62. Theorem. Let a be a homogeneous linear recurring sequence in
IF2 with binary complement ii. Write the minimal polynomial m(x) E F2[x] of
a in the form m(x) � (x + I)'m1(x) with an integer h;;. 0 and m1(x) E IF2[x]
satisfying m1(1) �I. Then the minimal polynomial m(x) of ii is given by
m(x)�(x+l)m(x) ifh�O. m(x)�m1(x) ifh�I, and m(x)�m(x) if
h >I. .
Proof Let < be the sequence in IF 2 all of whose terms are I. Since
ii � a + < and the minimal polynomial of < is x + I, the case h � 0 is settled
by invoking Theorem 6.57. If h ;;. I, then ii � a + < E S( m ( x)) because of
Theorem 6.55, and So m(x) divides m(x). If m(x) is the constant poly
nomial 1, then ii is necessarily the zero sequence and a = E, and the theorem
holds. Therefore, we assume from now on that m(x) is of positive degree.
We get a � ii + < E S( m( x )( x + I)) because of Theorems 6.53 and 6.55, thus
m(x) divides m(xXx + 1), and so for h;;. I we have either m(x) � m(x) or
m(x) � (x + l)'-1m1(x). If h >I, it follows that a� ii + <E S(m(x)), which
yields m(x) � m(x). If h �I, let the terms of a be s0, s1, ••• and let
m1(x)�x•+a._1x•-1+ ··· +a0
be of positive degree, the excluded case being trivial. We set
Since the sequence s0, s 1,... has m ( x) � ( x + I )m 1 ( x) as a characteristic
polynomial, it follows easily that u,+ 1 � u, for all n;;. 0. Therefore, u, � u0
for all n;;. 0, and we must have u0 �I, for otherwise m 1 ( x) would be a
222 Linear Recurring Sequences
characteristic polynomial of a. Consequently,
sn+k+l=a�c._1sn+k-l+ ··· +a0s,1 foralln�O.
Sincem1(l)=l+a,_1+ ··· +a0=1, we obtain
s,+,+i=a,_,(s,+k-l+i)+ ·· · +a0(s,+i) foralln�O,
and this means that m 1 ( x) is a characteristic polynomial of ii. Thus,
m(x)=m1(x)inthecasewhereh=l. D
We recall that S(/(x)) denotes the set of all homogeneous linear
recurring sequences in F q with characteristic polynomial /( x ), where/( x) E
IF•[x] is a monic polynomial of positive degree. We want to determine the
positive integers that appear as least periods of sequences from S(/(x)), and
also,for how many sequences from S(/(x)) such a positive integer is attained
as a least period.
The polynomial f(x) can be written in the form f(x) = x'g(x),
where h � 0 is an integer and g(x) E F q[x] with g(O) * 0. The case in which
g(x) is a constant polynomial can be dealt with immediately, since then
every sequence from S(/(x)) has least period I. If h �I and g(x) is of
positive degree, then, by the discussion following Theorem 6.55, every
sequence a E S(/(x)) can be expressed uniquely in the form a= a1 + a2
with a1 E S(x') and a2 E S(g(x)). Apart from finitely many initial terms,
all terms of a 1 are zero. so that the least period of a is equal to the least
period of a2. Furthermore, a given sequence a2 E S(g(x)) leads to q'
different sequences from S(f(x)) by adding to it all the q' sequences from
S(x'). Consequently, if r1, •••• r, are the least periods of sequences
from S(g(x)) and N1 ...• ,N, are the corresponding numbers of sequences
from S( g( x)) having these least periods, then, for I .; i .; t, there are exactly
q'N; sequences belonging to S(f(x)) with least period.r,, and no other least
periods occur among the sequences from S(f(x)).
We may assume from now on that h = 0-that is, that /(0) * 0.
Suppose first that/( x) is irreducible over F q· Then, according to Theorems
6.44 and 6.50, every sequence from S(f(x)) with nonzero initial state vector
has least period ord(/(x)). Therefore, one sequence from S(f(x)) has least
period I and q•'i\J(x)) -I sequences from S(/(x)) have least period
ord(/(x)).
Next, we consider the case that f(x) is a power of an irreducible
polynomial. Thus, let/(x) = g(x)• with g(x) E F•[x] monic and irreducible
over F q and b � 2 an integer. The minimal polynomial of any sequence from
S(f(x)) with nonzero initial state vector is then of the form g(x)' with
I .; c .; b. According to Theorem 6.53, we have
S(g(x)) <;; s(g(x)2) <;; · .. <;; S(f(x)).
Therefore, if deg(g(x)) = k, then there are q'-I sequences from S(/(x))
5. Families of Linear Recurring Sequences 223
with minimal polynomial g(x), q2'-q' sequences from S(f(x)) with
minimal polynomial g(x)2, and, in general, for c � 1,2, ... ,b there are
q''-q(<-llk sequences from S(f(x)) with minimal polynomial g(x)'. By
combining this information with Theorems 3.8 and 6.44, we arrive at the
following result.
6.63. Theorem. Let f(x) � g(x )• with g(x) E IF .lx] monic and irre
ducible over IF •• g(O)*O, deg(g(x))�k, ord(g(x))�e, and b a positive
integer. Lett be the smallest integer with p';. b, where pis the characteristic of
IF •. Then S(f(x)) contains the following numbers of sequences with the
following least periods: one sequence with least period I, q'-I sequences with
least period e, and for b � 2, qkpl-qkpi-t sequences with least period ep1
(j � 1,2, ... ,t -I) and q••-q'''-' sequences with least period ep'.
In the case of an arbitrary monic polynomial f(x) E F•[x] of positive
degree with f(O) * 0, we start from the canonical factorization
•
f(x)� ng,(x)\
i-1
where the g, ( x) are distinct monic irreducible polynomials over F • and the
b, are positive integers. It follows then from Theorem 6.55 that
In fact, every sequence from S(f(x)) is obtained exactly once by forming all
possible sums a1 + · · · + a• with a, E S(g,(x)••) for 1.;; i.;; h. Since the
least periods attained by sequences from S(g,(x)••) are known from Theo
rem 6.63, the analogous information about S(f(x)) can thus be deduced
from Theorem 6.59.
6.64. Example. Let
f( x) � ( x2 +X +I )2( x4 + x' +I) E IF2 [X].
According to Theorem 6.63, S((x2 + x + 1)2) contains one sequence with
least period I, 3 sequences with least period 3, and 12 sequences with least
period 6, whereas S(x4 + x' +I) contains one sequence with least period I
and 15 sequences with least period 15. Therefore, by forming all possible
sums of sequences from S((x2+x+l)') and S(x4+x'+I) and using
Theorem 6.59, we conclude that S(f(x)) contains one sequence with least
period I, 3 sequences with least period 3, 12 sequences with least period 6,
60 sequences with least period 15, and 180 sequences with least period 30. D
We have already investigated the behavior of linear recurring se
quences under term wise addition. A similar theory can be developed for the
224 Linear Recurring Sequences
operation of termwise multiplication, although it presents greater difficul
ties. If a is the sequence of elements s0,s1, ... of IF• and Tis the sequence of
elements t0, t 1,. •• off q' then the product sequence aT has terms s0t0, s1t1, ••. •
Analogously, one defines the product of any finite number of sequences. Let
S be the vector space over IF q consisting of all sequences of elements of F ••
under the usual addition and scalar multiplication of sequences. For non
constant monic polynomials f1(x), ... ,f,(x) over IF•, let S(/1(x)) · · ·
S(f,(x)) be the subspace of S spanned by all products o1• ··a, with
o, E S(/;(x)), 1.;; i.;; h. The following result is basic.
6.65. Theorem. If /1(x), ... ,f,(x) are nonconstant monic polynomi
als over IF•, then there exists a nonconstant monic polynomial g(x) E IFq[x]
such that
S(/1(x))· · · S(/,(x)) � S(g(x)).
Proof Set E � S(f1(x)) · · · S(f,(x)). Since each S(f,(x)), 1.;; i.;; h,
contains a sequence with initial term 1, the vector space E contains a
nonzero sequence. Furthermore, E is spanned by finitely many sequences
and thus finite-dimensional. From the fact that each S(/;(x)), 1.;; i .;; h, is
closed under shifts of sequences it follows that E has the same property, and
then the argument is complete by Theorem 6.56. D
6.66. Corollary. The product of finitely many linear recurring se
quences in IF q is again a linear recurring sequence in IF q·
Proof By the remarks following (6.5), the given linear recurring
sequences can be taken to be homogeneous. The result is then implicit in
Theorem 6.65. D
The explicit determination of the polynomial g(x) in Theorem 6.65
is, in general, not easy. There is, however, a special case that allows a
simpler treatment of the problem.
For nonconstant polynomials f1(x), ... ,f,(x) over F •. we define
/1 ( x) V · · · V /, ( x) to be the monic polynomial whose roots are the distinct
elements of the form a1 • • • "•, where each a, is a root of /;( x) in the
splitting field of /1(x)· · ·/,(x) over F •. Since the conjugates (over IF•) of
such a product a1 • • • "• are again elements of this form, it follows that
f1(x)V · · · V /,(x) is a polynomial over F •.
6.67. Theorem. For each i � 1,2, ... ,h, let /;(x) be a nonconstant
monic polynomial over F q without multiple roots. Then we have
S(/1 (X))··· S(f,( X))� S(/1 (x) V · · · V /,(x )).
We need a preparatory lemma and some notation for the proof of
this result. For a finite extension field F of F q• let SF be the vector space
5. Families of Linear Recurring Sequences 225
over F consisting of all sequences of elements ofF, under termwise addition
and scalar multiplication of sequences. Thus, in particular, SF � S. By the
• product V1 • • • V, of h subspaces V 1, ... , V, of SF we mean the subspace of
SF spanned by all products a 1 • • • a11 with a; E v,., 1 -E;;: i -E;;: h. For a noncon
stant monic polynomial f(x) E F[x], let SF(f(x)) be the vector space over
F consisting of all homogeneous linear recurring sequences in F with
characteristic polynomial f( x ).
6.68. Lemma. Let F be a finite extension field of F ,. and let
f1(x), ... ,f,(x) be nonconstant monic polynomials over IF,. Then,
S(/1 (x )) ... s(f,(x )) � s n (SF(!\ (x )) ... SF(fh (x ))).
Proof Clearly, the vector space on the left-hand side is contained
in the vector space on the rigbt-hand side. To show the converse, we note
first that each S(/1(x)), I .;; i .;; h, spans SF(/,(x)) over F. Therefore,
S(/1(x)) · · · S(f,(x)) spans SF(/1(x)) · · · SF(f,(x)) over F. Let p1, ... ,pm
be a basis of S(/1 ( x)) · · · S(f, ( x)) over IF,. and let w 1, ... , w k be a basis of F
over IF, with w1 ElF,. Then any aESF(/1(x))·· ·SF(f,(x)) can be written
in the form
k m
a= L L C;jW;P1•
i-1 j-1
where the coefficients c1j are in IF,. Let the terms of the sequence pj,
I .;; j.;; m, be the elements r10, r11, ... of IF,. If now a E S, then for the terms
s,, n�O,I, ... , of awe get
Since the coefficient of each w1 is in F,. it follows from the definition of
w 1, ••• • wk. that Lj� 1c;/'jn = 0 for 2 -E;;: i -E;;: k and all n. Consequen tly,
a= L cl,wlp1ES(/1(x)) .. ·S(/,(x))
j-1
and the proof is complete. D
Proof of Theorem 6.67. Let F be the splitting field of f1 ( x) · · · f, ( x) over
IF,. For I .;; i.;; h, let a1 run througb the roots of /,(x). Then by Theorem
6.55,
.,
We note that we have the distributive law V1(V, + V3) � V1V2 + V1V, for
subs paces V1• V2, V3 of SF, which is shown by observing that the left-hand
226 Linear Recurring Sequences
vector space is contained in the right-hand vector space (by the distributive
law for sequences) and that V1V2 c::: V1(V2 + V3) and V1V, c::: V1(V2 + V3)
imply V1V2 + V1V, c::: V1(V2 + V3). On the basis of the distributive law, it
follows that
s,(!,(x)J· · · s,(!,(x)) � E s,(x-a,)· .. s,(x-a,).
It is easy to check directly that
s,(x-a,)· .. SF(x-a,)� s,(x-a,· .. a,).
and so
llr:l> ... ,a,
�s,(/,(x)V · · · v f.(x))
by Theorem 6.55. The result of Theorem 6.67 follows now from Lemma
U& D
Theorem 6.67 shows, in particular, how to find a characteristic
polynomial for the product of homogeneous linear recurring sequences. at
least in the special case considered there. For this purpose, an alternative
argument may be based on Theorem 6.21. It suffices to carry out the details
for the product of two homogeneous linear recurring sequences. Let the
sequence s0, s1, ... belong to S(/(x)) and let 10,11, ... belong to S(g(x)). If
f(x) has only the simple roots a1, •••• a, and g(x) has only the simple roots
{31, ••• ,{J.,. then by (6.8),
'
s, = L bia; and
i-1 m
I � ... C·"" n 1.... ;PJ
j=l forn�O.I, ... ,
where the coefficients b, and c1 belong to a finite extension field of IF q· If
y1 ••••• y, are the distinct values of the products aJ31, 1 .-:e;; i .:e;; k. 1 .-:e;; j .:e;; m,
then
k m u.�s.t.� L L b,c1(aA)"� L d1y," forn�O.l, ... ,
i-1 J-1 i-1
with suitable coefficients d1, ••• ,d, in a finite extension field of F •. Now let
h(x)�f(x)Vg(x)�x'-a,_,x'-1-··· -a0EIF.[x].
Then for n � 0, I, ... we have
u,+,-a,_lun+r-\-... -GoUrr = L d/y;"h ( Y;):::: 0,
i-1
and so the product sequence u0, u1, ... has h(x) as a characteristic poly
nomial.
5. Families of linear Recurring Sequences 227
6.69. Example. Consider the sequence 0, 1,0, 1, ... in IF2 with the least
period 2 and minimal polynomial (x-1)2• If we multiply this sequence with
itself, we get back the same sequence. On the other hand, (x -1)2 V(x -1)2
� x - I, which is not a characteristic polynomial of the product sequence.
Therefore, the identity in Theorem 6.67 may cease to hold if some of the
polynomialsf ,(x) are allowed to have multiple roots. 0
There is an analog of Theorem 6.61 for multiplication of sequences.
For obvious reasons, sequences for which all but finitely many terms are
zero have to be excluded from consideration.
6.70. Theorem. For each i = 1,2, ... ,h, let a; be an ultimately peri
odic sequence in F q with infinitely many nonzero terms and with least period r;.
If r1, ... ,r, are pairwise relatively prime, then the least period of the product
a1 · · · ah is equal to r1 · · · rh.
Proof We consider only the case h � 2 since the general case
follows then by induction. As in the proof of Theorem 6.61 one shows that
the least period r of a1a2 must be of the form r � d1d2 with d1 and d2 being
positive divisors of r1 and r2, respectively. In particular, d1r2 is a period of
a1a2. Thus, if the terms of a1 are s0, s1, ••. and those of a2 are t0, t1, •.. , then
we have
for all sufficiently large n. Since there exists an integer b with t. * 0 for all
sufficiently large n = bmod r2, it follows that s•+d,,, � s. for all such n. Now
fix a sufficiently large n; by the Chinese remainder theorem, we can choose
an integer m � n with m = nmod r1 and m = bmod r2. Then
and so d1r2 is a period of a1• Therefore, r1 divides d1r2• and since r1 and r2
are relatively prime, r1 divides d1, which implies d1 � r1• Similarly, one
shows that d2 � r2. 0
Multiplication of sequences can be used to describe the relation
between homogeneous linear recurring sequences belonging to characteri stic
polynomials that are powers of each other. The case in which one of the
characteristic polynomials is linear has to be considered first.
6.71. Lemma. If c is a nonzero element of IF • and k is a positive
integer, then
s((x-c)•)�S(x-c)S((x-1)•).
Proof Let the sequences0, s1, ... belong to S(x-c), and lett0.t" ...
228 Linear Recurring Sequences
belong to S((x -I)'). Then s., =c"s0 for n = 0, !, ... and
'
L (7)(-I)'-'t,+1=0 forn=O,l, ....
i-0
It follows that
for n =0, !, .... and so
k
L (k)(-c)'-'x'=(x-c)'
i-0 I
is a characteristic polynomial of the product sequence s0t0, s1t1, ••• • Conse
quently, the vector space S( x -c )S(( x-I)') is a subspace of S(( x -c)').
Since c * 0, the first vector space has dimension k over IF q and is thus equal
to S((x-c)'), which has the same dimension over F.. 0
6.72. Theorem. Let f(x) E IF•[x] be a nonconstant monic poly
nomial with f(O) * 0 and without multiple roots, and let k be a positive integer.
Then,
S(f(x)') = S(f(x))S((x -I)').
Proof Let F be the splitting field of f(x) over F •. Then, with a
running through the roots of /(x), we get
a
by Theorem 6.55. Using Lemma 6.71 and the distributive law shown in the
proof of Theorem 6.67, we obtain
s,(J(x)') = LS,((x -l)')s,(x-a)= s,((x -I)')LS,(x-a)
a a
where we applied Theorem 6.55 in the last step. The desired result follows
now from Lemma 6.68. 0
6. CHARACfERIZATION OF LINEAR RECURRING SEQUENCES
It is an important problem to decide whether a given sequence of elements
of F q is a linear recurring sequence or not. From the theoretical point of
6. Characterization of Linear Recurring Sequences 229
view, the question can be settled immediately since the linear recurring
sequences in F • are precisely the ultimately periodic sequences. However, the
periods of a linear recurring sequence (even of one of moderately low order)
can be extremely long, so that in practice it may not be feasible to determine
the nature of the sequence on the basis of this criterion. Alternative ways of
characterizing linear recurring sequences employ techniques from linear
algebra.
Let s0, s1, ••• be an arbitrary sequence of elements ofF,. For integers
n;:.,. 0 and r ;a,. I, we introduce the Hankel determinants
s. sn+ 1 sn+r-1
D'rl= s,+ I sn+2 s,+,
•
sn+r-1 s,+, sn+2r-2
It will transpire that linear recurring sequences can be characterized in
terms of the vanishing of sufficiently many of these Hankel determinants.
6.73. LemnuJ. Let s0, s1, ••• be an arbitrary sequence in F,, and let
n;:.,. 0 and r;:.,. 1 be integers. Then D�'> = D�'+ I)= 0 implies D��>1 = 0.
Proof For m>O define the vector sm=(sm,sm+l•···•sm+r-l).
From D�')=O it follows that the vectors s,,s,+1, ... ,s,+,-l are linearly
dependent over IF,. If s.+ 1, ...• s.+,-l· are already linearly dependent over
F q' we immediately get D��l1 = 0. Otherwise, s, is a linear combination of
s,+1, ... ,s,+r-l· Set s�=(sm,sm+l•···•sm+r) for m;-.,.0. Then the vectors
s�.s�+ 1, ••• , s�+r· being the row vectors of the vanishing determinant D�'+ 1l,
are linearly dependent over IF q· If s�.s�+ 1, ••• ,s�+r-l are already linearly
dependent over IF<' then an application of the linear transformation
L 1: ( a0• a1, ••• ,a,) E F ;+ 1 ..,. ( a1, ... ,a,) E IF;
shows that sn+l•s,+2, ... ,s,+, are linearly dependent over Fq, and so
D,��)1 = 0. Otherwise, s:+, is a linear combination of s�, s�+ 1, ... , s�+r-1, and
by an application of the linear transformation
L2: (a0, ... ,a,_1, a,) E IF;+ 1 � (a0, .•. ,a,_1) E F;
we obtain that s,+, is a linear combination of s,, s,+ 1, ••• , s,+r-l· But in the
case under consideration s, is a linear combination of s,+ 1, ... ,s,+r-l• so
that the row vectors sn+l•···•s,+r-l•s,+, of D��� are linearly dependent
over IF q• which implies D��� = 0. 0
6.74. Theorem. The sequence s0, s1, ... in F q is a linear recurring
sequence if and only if there exists a positive integer r such that D?' � 0 for all
but finitely many n;;. 0.
230 Linear Recurring Sequences
Proof Suppose s0, s1, ... satisfies a kth-order homogeneous linear
recurrence relation. For any fixed n;;. 0, consider the determinant D�k+ ''·
Because of the linear recurrence relation, the (k + l)st row of D�k+ '' is a
linear combination of the first k rows, and so D�k+ '' = 0. The inhomoge
neous case reduces to the homogeneous case by (6.5).
To show sufficiency, let k +I be the least positive integer such that
v�•+ '' = 0 for all but finitely many n;;. 0. If k +I= I, then we are do�e,
and so we may assume k ;;.I. There is an integer m;;. 0 with D�k+ '' � 0 for
all n;;. m. If we had D�:' = 0 for some n0;;. m, then v�•> = 0 for all n;;. n0
by Lemma 6.73, which contradicts the definition of k +I. Therefore,
D�"> * 0 for all n � m. Setting s,. = (s,., s,.+ 1, ••• ,s,.+k), we note that for
n �m the vectors s,.,s,.+1, ... ,s,.+k• being the row vectors of D�k+n, are
linearly dependent over F q· Since D�k) * 0, the vectors s,.,s,.+ 1, ... ,s,.+k-t
are linearly independent over F •• and so s,H is a linear combination of
s,.,s,.+1, ... ,s11+k-l·lt follows then by induction that each s,. with n �m is a
linear combination of sm, sm+ I• •.. ,sm+k-1" The latter are k vectors in F:+ I'
therefore there exists a nonzero vector (a0, a1, ••. ,a.) E r;+ 1 with
a0s,.+a1s,.+1+ ··· +aksrt+k=O form�n�m+k-1.
This implies
or
Thus, the sequence s0, s1,. .. satisfies a homogeneous linear recurrence
relation of order at most m + k. 0
6.75. Theorem. The sequence s0, s1, ... in F• is a homogeneous
linear recurring sequence with minimal polynomial of degree k if and only if
DJ" = 0 for all r;;. k + I and k + I is the least positive integer for which this
holds.
Proof If a given linear recurring sequence is the zero sequence, the
necessity of the condition is clear. Otherwise, we have k;;. I, and D6" = 0
for all r ;;. k + I follows since the ( k + I )st row of DJ '' is a linear combina·
tion of the first k rows. Moreover, we get DJ•> * 0 from Theorem 6.51, and
so the necessity of the condition is shown in all cases.
Conversely, suppose the condition on the Hankel determinants is
satisfied. By 11sing Lemma 6.73 and induction on n, one establishes that
D�'1 = 0 for all r;;. k + I and all n;;. 0. In particular, vJ• + n = 0 for all
n;;. 0, and so s0, s1, ... is a linear recurring sequence by Theorem 6.74. If its
minimal polynomial has degree d, then, by what we have already shown in
6. Characterization of Linear Recurring Sequences 231
the first part, we know that DJ'' � 0 for all r ;, d + I and that d + I is the
least positive integer for which this holds. It follows that d � k. 0
We note that if a homogeneous linear recurring sequence is known to
have a minimal polynomial of degree k;, I, then the minimal polynomial is
determined by the first 2k terms of the sequence. To see this, write down the
equations (6.2) for n � 0, I, ... ,k-I, thereby obtaining a system of k linear
equations for the unknown coefficients a0, a1, ... , a._, of the minimal
polynomial. The determinant of this system is DJ•l, which is * 0 by
Theorem 6.51. Therefore, the system can be solved uniquely.
An important question is that of the actual computation of the
minimal polynomial of a given homogeneous linear recurring sequence. To
be sure, a method of finding the minimal polynomial was already presented
in the course of the proof of Theorem 6.42. This method depends on the
prior knowledge of a characteristic polynomial of the sequence and on the
determination of a greatest common divisor in F.[x]. We shall now discuss
a recursive algorithm (called Berlekamp-Massey algorithm) which produces
the minimal polynomial after finitely many steps, provided we know an
upper bound for the degree of the minimal polynomial.
Let s0, s1, ... be a sequence of elements of F• with generating
function G(x) � I:�_0s.x•. For j � 0, I, ... we define polynomials g/x) and
h1(x) over IF•, integers m1, and elements b1 of F• as follows. Initially, we set
g0(x)=!, h0(x)�x, and m0�0. (6.19)
Then we proceed recursively by letting b1 be the coefficient of x' in
g/x)G(x) and setting:
g1+1(x) � g1(x)-bh(x),
{-ml m -j+I-mj+l if b1 * 0 and mi;, 0,
otherwise,
if bj * 0 and mj � 0,
otherwise. (6.20)
If s0, s1, ... is a homogeneous linear recurring sequence with a minimal
polynomial of degree k, then it turns out that g,.(x) is equal to the
reciprocal minimal polynomial. Thus, the minimal polynomial m(x) itself is
given by m(x)�x•g,.(!jx). If it is only known that the minimal poly
nomial is of degree ,;;. k, then set r � l k +!-!m,.J, where lY J denotes
the greatest integer ,;;. y, and the minimal polynomial m(x) is given by
m(x) � x'g,.(!jx). In both cases, it is seen immediately from the algorithm
that m(x) depends only on the 2k terms s0,s1, ... ,s,._1 of the sequence.
232 Linear Recurring Sequences
Therefore, one may replace the generating function G ( x) in the algorithm
by the polynomial
2k -I G,._,(x)� L s,x".
•-0
6.76. Example. The first 8 terms of a homogeneous linear recurring
sequence in F, of order ,.4 are given by 0,2,1,0,1,2,1,0. To find the
minimal polynomial, we use the Berlekamp-Massey algorithm with
G7(x) � 2x + x' + x4 +2x' + x6Ef3[x]
in place of G ( x ). The computation is summarized in the following table.
j sjlx) h1(x) mf bj
0 X 0 0
I x' I 2
2 I+ x2 2x -I I
3 I+ x + x2 2x2 0 0
4 I+ x + x2 2x3 I 2
5 I+ x + x2 +2x3 2x +2x2 +2x1 -I 2
6 I+ x1 2x2 +2x1 +2x4 0 I
7 l+x2+2x1+x4 x+x4 0 I
8 I +2x + x2 +2x1 0
Then, r = l4+ -!-1m,J � 4, and so m(x) � x4 +2x3 + x' +2x. The homo
geneous linear recurrence relation of least order satisfied by the sequence is
therefores11+4=S11+1+2s,+2+s,+1 forn=O,l,.... 0
6.77. Example. Find the homogeneous linear recurring sequence in f2 of
least order whose first 8 terms are 1,1,0,0,1,0,1,1. We use the Berlekamp
Massey algorithm with G1(x)�l+x +x4+x6+x 7Ef2[x] in place of
G(x). The computation is summarized in the following table.
j gj(x) hjCx) mf bj
0 X 0 I
I I+ X X 0 0
2 l+x x' I I
3 1 + x + x2 x + x2 -I I
4 I x2 + x3 0 I
5 l+x2+x3 X 0 0
6 l+x2+x1 x' I 0
7 l+x2+x1 x' 2 0
8 l+x2+x3 3
6. Characterization of Linear Recurring Sequences 233
Then, r � [4+ i -im,J � 3, and so m(x) � x3 + x + 1. Therefore, the given
terms form the initial segment of a homogeneous linear recurring sequence
s0, s1, ••• satisfying sn+ 3 = sn+ 1 + S17 for n = 0, I, ... , and no such sequence of
lower order with these initial terms exists. D
We shall now prove, in general, that the Berlekamp"Massey algorithm
yields the minimal polynomial after the indicated number of steps. To this
end, we define auxiliary polynomials u1( x) and v1( x) over IF q recursively by
setting
u0(x)�O and v0(x)�-l,
and then for j � 0, 1, ... ,
u1+ 1(x) � u1(x)-h1v1(x),
-{h1-1xu1(x) ifb1*0andm1;;,0, v1+1(x)-( ) xv1 x otherwise.
We claim that for each};;, 0 we have (6.21)
(6.22)
deg(g1(x)) d(J+ 1-mJ) and deg(h,(x)) d(i+2+m1).
(6.23)
This is obvious for j � 0 because of the initial conditions in (6.19), and
assuming the inequalities to be shown for some j;;, 0, we get from (6.20) in
the case where bj '* 0 and m j � 0,
deg( g;+ 1 (x)).;; max( deg( g1(x) ),deg(h 1( x)))
.;; Hi +2+ m1) � H j +2-m1+ 1 ).
Otherwise,
deg(g;+1(x)) <>Hi+ 1-m1) � Hi+2-m1+ 1).
The same distinction of cases proves the second inequality in (6.23). A
similar inductive argument shows that for each}� 0 we have
The auxiliary polynomials u1(x) and v/x) are related to the polynomials
g1(x) and h1(x) occurring in the algorithm by means of the following
congruences, valid foi each j � 0:
g;(x )G(x) = u1(x )+ b1ximod xJ+ 1,
h1(x )G( x) = v1 (x) + x'mod xf+ 1• (6.25)
(6.26)
Both (6.25) and (6.26) are true for j � 0 because of (6.19), (6.21), and the
.-l�f:-:.:�- �f 1.. A_, .• _; __ •L-• L-•L --- -----·- --� 1----- L ---_1_ ---- -"-
234 Linear Recurring Sequences
j � 0, we get
g1+ 1 (x )G(x) � s;( x)G(x )-b1h1(x )G(x)
== u1( x )+ b1x1 + c1+ 1xi+ 1-b1( v1(x )+xi+ d1+ 1xi+ 1)
==u-(x)+e-xi+1modxi+2
rt-l ; + 1
with suitable coefficients cJ+l•dJ+I•eJ+!EIFq. Since \m,\�). as is seen
easily by induction, we have deg(u1+ 1(x)).; j from (6.24). Therefore, e + 1 is "+ 1 J the coeHicient of x1 in g;+1(x)G(x), and so eJ+I =b)+ I· The induction
step for (6.26) is carried out similarly.
Next, one establishes by a straightforward induction argument that
h1(x)u1(x)-g1(x)v1(x)�x1 foreachj;.O. (6.27)
Now let s(x) and u(x) be polynomials over F• with s(x)G(x)�u(x) and
s(O) �I. Then by (6.26),
h1( x) u(x )-s(x) v1(x) � s(x )( h1(x )G( x)-v1(x ))
= s(x)xi �xi mod xi+ 1,
and so for some �(x) E f•[x] we have
h1(x)u(x)-s(x)v,(x) � x'�(x) with �(0) �I. (6.28)
Similarly, one uses (6.25) to show that there exists lj(x) E IF'q(x] with
g1(x)u(x)-s(x)u1(x) � xilj(x). (6.29)
Now suppose the minimal polynomial m(x) of the given homoge
neous linear recurring sequence satisfies deg(m(x)).; k, and let s(x) be the
reciprocal minimal polynomial. Then s(O) �I and deg(s(x)).; k, and from
(6.15) we know that there exists u(x) E F•[x] with s(x)G(x) � u(x) and
deg(u(x)).; deg(m(x))-1.; k -I. Consider (6.28) with)� 2k. Using (6.23)
and (6.24), we obtain
deg( h2k(x )u(x )) .; 1{2k +2+ m,. )+ k -l � 2k + ):m2k
and
deg(s(x) v,. (x )) .; k + J:(2k + m2k) � 2k + ):m2k,
and so
deg(h2k (x) u(x )-s(x) v2k(x)).; 2k + ):m2k.
On the other hand,
deg( h2k( x )u(x)-s(x) v,.( x )) � deg(x,.u,.(x l) ;;> 2k,
and these inequalities are only compatible if m2k ;;> 0. Using again (6.23)
and (6.24), one verifies that deg(g2k(x)u(x)) and deg(s(x)u2k(x)) are both
7. Distribution Properties of Linear Recurring Sequences 235
.;; 2k-J:-J:m,k, hence (6.29) shows that
deg( x2kV,k(x )) = deg(g2k(x) u(x) -s(x )u,k (x )) < 2k.
But this is only possible if V,.(x) is the zero polynomial. Consequently,
(6.29) yields g,.( x )u(x) = s(x )u2k(x), and multiplying (6.28) for j = 2k by
g2k(x) leads to
h2k(x )g2k (x) u(x)-s(x )g2k(x) v,. (x)
= s(x )( h2k(x) "'* (x)-g,.(x) v2k (x )) = x2kU2k(x )g2k (x ).
Together with (6.27), we get s(x)=U2k(x)g,.(x), which implies u(x)=
U2k(x)u,.(x). Since s(x) is the reciprocal minimal polynomial, it follows
from the second part of Theorem 6.40 that s(x) and u(x) are relatively
prime. Because of this fact, U,.(x) must be a constant polynomial, and
since U,.(O) =I by (6.28), we actually have U2k(x) =I. Therefore s(x) =
g,.(x), and as a by-product we obtain u(x) = u,k(x). If deg(m(x)) = k,
then
m(x)=xks(�)=xkg2k(�).
as we claimed earlier. If deg(m(x)) = t .;; k, then we have s(x) = g2,(x),
u(x) = u2,(x), and m2,;,. 0. Clearly, max(deg(s(x)), l +deg(u(x))).;; t, and
the second part of Theorem 6.40 implies that
t = max( deg( s ( x)), I + deg( u ( x))).
It follows then from (6.23) and (6.24) that
t = max(deg(g2,(x)), I +deg( u2,(x))).;; t + J: -1m2,
and so m2, = 0 or I. Furthermore, we note that g;(x) = s(x) and b1 = 0 for
all j;,. 2t, so that m; = m2, + j-2t for all j;,. 2t by the definition of m ;·
Settingj=2k, we obtain t=k+-im2,--im2k, and since m2,=0 or 1, we
conclude that
Therefore,
m(x)=x's(�) =x'g2k(� ).
in accordance with our claim.
7. DISTRIBUTION PROPERTIES OF LINEAR
RECURRING SEQUENCES
We are interested in the number of occurrences of a given element of Fq in
either the full period or parts of the period of a linear recurring sequence in
236 Linear Recurring Sequences
f q· In order to provide general information on this question, we first carry
out a detailed study of exponential sums that involve linear recurring
sequences. It will then become apparent that in the case of linear recurring
sequences for which the least period is large, the elements of the underlying
finite field appear about equally often in the full period and also in large
segments of the full period.
Let s0, s1, •.. be a kth-order linear recurring sequence in F q satisfying
(6.1), let r be its least period and n0 its preperiod, so that s.,+, = s., for
n � n0. With this sequence we associate a positive integer R in the following
way. Consider the impulse response sequence d0, d1, ... satisfying (6.6), let
r1 be its least period and n1 its preperiod; then we set R = r1 + n1• Of course,
R depends only on the linear recurrence relation (6.1) and not on the
specific form of the sequence. If s0, s11 .•• is a homogeneous linear recurring
sequence with characteristic polynomial f(x) E F .Ix ], then r1 = ord(f(x )),
and if in additionf(O)"' 0, then R = ord(f(x)), as implied by Theorem 6.27.
By the same theorem, r divides r1 and r � R in the homogeneous case.
In the exponential sums to be considered, we use additive characters
of IF q as discussed in Chapter 5 and weights defined in terms of the function
e(t) = e2"'' for real t.
6.78. Theorem. Let s0, s1, ... be a kth-order linear recurring se
quence in IF• with least period rand preperiod n0, and let R be the positive
integer introduced above. Let x be a nontrivial additive character of IF q· Then
for every integer h we have \d,-1 (h l\ 1/2 "�" x(s,)e -f-._ ( �) qk/2
In particular, we have for all u > n0•
\":��1x(s,)\._ (�('q•/2 forallu'3n0• (6.30)
(6.31)
Proof By changing the initial state vector from s0 to s •. which does
not affect the upper bound in (6.30), we may assume, without loss of
generality, that the sequence s0, s1, ... is periodic and that u = 0. For a
column vectorb=(b0,b1, ... ,b,_1)T in F: and an integer h. we set
o(b; h)= o(b0, b1, ... ,b,_1; h)
Since the general term of this sum has period r as a function of n, we can
write
7. Distribution Properties of Linear Recurring Sequences
Using the linear recurrence relation (6.1), we get
lo(b; h )I� I' I:' x( bos .. + I+ b,s.,+2 + ... + b,_,s,+k-1 +-b,_,aos ..
n-O 237
+bk-1a1sll+l+ ··· +bk-lak-lsn+k-1 +bk-la)e(hrn)l
�1 't' x(b,_,aos .. +(bo+b,_,a,)s .. +, + ...
n-O
+(b,_, +b,_,a,_,)s.,+k-J)e( hrn ll
� lo(b,_1a0, b0 + b,_1a1, ... ,b,_2 + b,_,a,_1; h )I.
This identity can be written in the form
I o (b; h )I � I o ( Ab; h )I.
where A is the matrix in (6.3). It follows by induction that
lo(b;h)l�lo(Ajb;h)l forallj;>O. (6.32)
Let d be the column vector d � (l,O, ... ,O)T in IF:. and let d0,d1, .•. be the
state vectors of the impulse response sequence d0, d" ... satisfying (6.6).
Then we claim that two state vectors dm and d, are identical if and only if
A"'d � A"d. For if dm �d.,, then Amd � A"d follows from Lemma 6.15. On
the other hand, if Amd � A"d, then· Am+jd � A"+jd. and so Am( Ajd) �
A"(Ajd), for allj;>O. But since the vectors d, Ad,A2d, ... ,A'-'d form a
basis for the vector space F; over IF q• we get A'"= A'', which implies d'" = d,
by Lemma 6.15.
The distinct vectors in the sequence d0,d1, ... are exactly given by
d0,d1, ... ,d._1. Therefore, by what we have just shown, the distinct vectors
among d, Ad, A2d, ... are exactly given by d, Ad, ... ,A•-'d. Using (6.32), we
get
R-I
Rla(d;h)l2� L lo(Ajd;h)I2.;;Lio(b;h)l2• (6.33)
j=O b
where the last sum is taken over all column vectors bin F;. Now
Llo(b; h)l2 � Lo(b; h) o(b; h)
b b
'-I
L L x(bo(sm -s.,)+b,(sm+J-s .. +,)
bo,b1, .,b�_1Ef" m,n=O
+ ... +b,_,(sm+k-1-s.,+k-l))e( h(m,-n))
� 'I;' e( h(mr-n)) (6.34)
m,n-0
238 Linear Recurring Sequences
IJo,bl> .. ,bk_1Ef01
·x(bk-l(sm+k-l-s•+k-l))
� 'i:_l e(h(m,-nl)( L x(bo(sm-sJ))···
m,n�O boEF11
We note that for c E F, we have
L x(hc) � { 0
hEF.., q if C* 0,
if c�o.
according to (5.9). Therefore, in the last expression in (6.34) one only gets a
contribution from those ordered pairs (m, n) for which simultaneously
s'" = s", ... ,sm+k-1 = sn-+k-t· But since 0 � m, n � r-I, this is only possible
form� n. It follows that
Llo(b; h)\2 � rq•.
b
By combining this with (6.33), we arrive at
\o(d; h)\ "i ( � t' qk/2,
which proves (6.30). The inequality (6.31) results from (6.30) by setting
h�O. o
6.79. Remark. Let x be a nontrivial additive character of IF, and let 1/> be
an arhitrary multiplicative character ofF q· Then the Gaussian sum
G(l/>.x)� L ,P(c)x(c)
can be considered as a special case of the sum in (6.30). To see this, let g be
a primitive element of IF q and introduce the first-order linear recurring
sequence s0,s1, .•. in !Fq with s0=1 and sn+1=gsn for n=O,l, .... Then
r � R � q -I and n0 � 0. We note that ,P(g) � e(h/r) for some integer h.
Thus we can write
r -I r-I
G( 1/>. x) � .�/( g" )I/> ( g") � .�/(s. )e ( h;).
If .p is nontrivial, then in this special case both sides of (6.30) are identical
according to (5.15). 0
The sums in Theorem 6.78 are extended over a full period of the
given linear recurring sequence. An estimate for character sums over seg-
7. Di�tribution Properties of Linear Recurring Sequences 239
ments of the period can be deduced from this result. We need the following
auxiliary inequality.
6.80. Lemma. For any positive integers r and N we have
·-I�N-I (h")l 2 2 L L e _I}_ <-rlogr+-5r+N.
h�o J=O r '"
Proof The inequality is trivial for r � l. For r ;. 2 we have
IN-I (hjll le(hNir}-11 1 1�0 e --;-� ldhlr}-11 .;;; sinwllhlrll
� esc wll � II for l .;;; h .;;; r -l, (6.35)
where 11111 denotes the absolute distance from the real number t to the
nearest integer. It follows that
•-I N-1 (h") •-1 llhll [•/2J h
h�O 1�0 e ; .;;; h�l cscw -; + N.;;; 2 h�l csc7 + N.
By comparing sums with integrals, we obtain
l•/2J wh " 1'12J wh " · · Jl•/2J wx L esc-= esc-+ L esc-� esc-+ csc-dx
h-1 r r h=2 r r I r
" r J•/2 �esc-+-csctdt r '1T wjr
w r w w r 2r �esc-+ -logcot- .;;; esc-+ -log-. r w 2r r w w (6.36)
For r ;. 6 we have ("I r)-1 sin(" 1 r) ;. ( "16)-1 sin(" 16 ), hence sin(" I r) ;.
31r. This implies
and so 1'12J wh l (l l ") L esc-.;;; -rlogr + ---log-r
11-1 r '" 3 '" 2 for r � 6.
l•/2J wh l 1 L csc-<-rlogr+-r r " 5 forr�6. h=l
This inequality is easily checked for r � 3, 4, and 5, so that (6.35) holds for
r;. 3 in view of (6.36). For r � 2 the inequality (6.35) is shown by inspec
tioo. 0
240 Linear Recurring Sequences
6.81. Theorem. Let s0, s1,... be a kth-order linear recurring se
quence in F,, and let r, n0, and R be as in Theorem 6.78. Then, for any
nontrivial additive character x of IF q we have 1-+N-l I 1/2 (2 2 N) "�" x(s,) <(�) q'12 ;logr+5+-;-foru�n0andl"'N,.J.
Proof We start from the identity •+N-l •+,-1 N-l 1 ,_, (h(n-u-j)) L x(s,)� L x(s..) L-; L e r for 1,. N,. r,
n=u n�u 1-0 h-0
which is valid since the sum over j is 1 for u .:s;:; n .:s;:; u + N-1 and 0 for
u + N � n � u + r -l. Rearranging terms, we get
d N-I
l '-I ( N-I ( _ h ( U + ) ) ) ("+'-I ( hn ) ) L x(s,)�-; L L e r 1 L x(s,)e--;-,
n=u h-0 ,�o n-u
and so by (6.30),
[ x(s.l ,. -[ [ e [ x(s.Je -I u+ N- 1 I 1 '-' IN-I ( _ h ( u + j) ) I"+'-1 ( hn ) I
11-u 'h=O ;-o ' 11=u '
,. .!. (!...) 112 q'12 '"[' IN [' e ( hj) I·
r R h-0 J-0 r
An application of Lemma 6.80 yields the desired inequality. D
It should be noted that the inequalities in Theorems 6.78 and 6.81
are only of interest if the least period r of s0, s1, ••• is sufficiently large. For
small r, these results are actually weaker than the trivial estimate
I ": f 1 x ( s.) 1,. N for 1 ,. N ,. r.
In order to obtain nontrivial statements. r should be somewhat larger than
qk/2_
Let s0, s1 •. :. be a linear recurring sequence in IFq with least period r
and preperiod n0. For b E F, we denote by Z( b) the number of n, n0,. n ,.
n0 + r -1, with s., �b. Therefore Z(b) is the number of occurrences of bin
a full period of the linear recurring sequence.
If s0• s1 •••• is a kth-order maximal period sequence, then Z(b) can
be determined explicitly. We have r � q'-1 and n0 � 0 according to
Theorem 6.33, and so the state vectors s0,s1 ••.• ,s,_1 of the sequence run
exactly through all nonzero vectors in IF:. Consequently, Z(b) is equal to
the number of nonzero vectors in F: that have b as a first coordinate.
Elementary counting arguments show then that Z(b) � q,_, forb"' 0 and
7. Distribution Proptrties of Linear Recurring Sequences 241
Z(O) � qk-J-I. Therefore, up to a slight aberration for the zero element,
the elements of f • occur equally often in a full period of a maximal period
sequence.
In the general case, one cannot expect such an equitable distribution
of elements. One may, however, estimate the deviation between the actual
number of occurrences and the ideal number rjq. If r is sufficiently large,
then this deviation is comparatively small.
6.82. Theorem. Let s0, s1, ••• be a kth-order linear recurring se
quence in F• with least period r, and let R be as in Theorem 6.78. Then, for
any b E IF • we have
Proof For given bE F •• let the real-valued function �. on F • be
defined by �.(b)� I and �.(c)� 0 for c"' b. Because of (5.10), the function
�. can be represented in the form
I �. (c) � -LX ( c -b) for all c E IF q, q X
where the sum is extended over all additive characters x of IF •. It follows
that
n0+r-l n0+r-l 1 ..
Z(b)� L �.(s.)� L -[x(s,-b)
n-n0 n-no q x
I no+ r-I
�-[x(b) L x(s,). q X n-n0
By separating the contribution from the trivial additive character of F • and
using an asterisk to indicate the deletion of this character from the range of
summation, we get
I n0+r-l
Z(b)-��-[*x(b) L x(s,). q q X n =no
Thus, by using (6.31), we obtain
1 n0+r-l IZ(b)-��.;-[* L x(s,) q q X n = n0
since there are q-I nontrivial additive characters of IF q· D
6.83. Corollmy. Let s0, sJ>··· be a homogeneous linear recurring
242 Linear Recurring Sequences
sequence in IF • with least period r whose minimal polynomial m ( x) E IF .I x] has
degree k;. I and satisfies m(O) * 0. Then, for every bE IF• we have
Proof We haver� ord(m(x)) according to Theorem 6.44. Further
more, R � ord(m(x)) by a remark preceding Theorem 6.78, and Theorem
6.82 yields the desired result. 0
If the linear recurring sequence has an irreducible minimal poly
nomial, then an alternative method based on Gaussian sums leads to
somewhat better estimates. In the subsequent proof, we shall use the
formulas for Gaussian sums in Theorem 5.11.
6.84. Theorem. Let s0, s1, ... be a homogeneous linear recurring
sequence in IF • with least period r. Suppose the minimal polynomial m ( x) of
the sequence is irreducible over F •• has degree k, and satisfies m(O) * 0. Let h
be the least common multiple of r and q -I. Then,
and Z(O)- .,.; 1------q I I (q'-'-l)rl ( l)(r r ) , 2 q'-I q h q'-I
Z(b)---.,.; ----+-=-ql/2 q<k/2)-l forb#'O. I q'-'r I ( r r h r ) q'-1 h q'-1 h (6.37)
(6.38)
Proof Set K � IF•, and let F be the splitting field of m(x) over K.
Let a be a fixed root of m ( x) in F; then a* 0 because of m (0) * 0. By
Theorem 6.24, there exists 0 E F such that
s, � TrF;K(Oa") for n � 0, !,.... (6.39)
We clearly have 0 * 0. Let X' be the canonical additive character of K. Then,
for any given bE K, the character relation (5.9) yields I { I -L X'( c( b-s,)) � 0 q CE K ifsn=b,
if s, -=1:-b,
and so, together with (6.39),
l r-I Z(b) �-L L "A'(bc)X'(TrF;K(-cOa")). q n=OcEK
If A denotes the canonical additive character of F, then X' and A are related
by "A'(TrF;K( /3 )) � X(/3) for all /3 E F (see (5.7)). Therefore,
7. Distribution Properties of Linear Recurring Sequences
Now by (5.17), Z(b) �_I_ LA'( be) 'i_:1 X(cOa") q cEK n=O
1 r-I
�!:+- L A'(bc) L X(cOa"). q q cEK• n-0
X(p)�-,- 1-L;G(,f.X).y(fl) forfJEF*,
q -I ,_ 243
(6.40)
where the sum is extended over all multiplicative characters .Y of F. For
c E K* it follows that
, -1 , - 1
L X(cOa")�-,-1-L L;G(f,X),Y(cO a")
11'"'0 q-1,.=0-.t-
1 , - 1
�-,-L:.Y (cO)G(f,X) L ,Y(a)".
q-11/- n=O
The inner sum in the last expression is a finite geometric series that vanishes
if ,Y( a)"' I. because of ,Y( a)'� ,Y( a')� ,Y(l) �I. Therefore. we only have to
sum over the set J of those characters .Y for which .Y (a) � I, and so
'-I
L X(cOa") � +-L ,Y(cO)G(f. X).
n-0 q-11/-E} ...
Substituting this in (6.40), we get
Z(b)�!:+ ( ; ) L: A'(bc) L: ,Y(cO)G(f.X) q q q -J ,EK" "E)
�!:+ ( : ) L ,Y(O)G(f,X) L ,Y(c)A'(bc). q q q -1 1¥ E j c E K*
If we consider the restriction .Y' of .Y to K*. then the inner sum may be
viewed as a Gaussian sum inK with an additive character A/,(c) �A'( be) for
cE K. Thus,
Z(b)�!:+ ( : ) L ,Y(O)G(f,X)G( ,Y',A/,). (6.41) q q q -j "E)
Now let b � 0. Then A/, is the trivial additive character of K, and so
the Gaussian sum G( Y,.', �b) vanishes unless Y,.' is trivial, in which case
G( ,Y'. A/,)� q-I. Consequently, it suffices to extend the sum in (6.41) over
the set A of characters .Y for which .Y (a) � I and ,Y' is trivial, so that
( r (q-l)r >:' (--) zo)�-+ (' ) L..>i-(O)G,Y,A.
q q q -J "EA
244 Linear Recurring Sequences
The trivial multiplicativ e character contributes -1 to the sum, hence we get
Z(O)-(q'�'-l)r � (q�l)r L\1-(0)G(f.X), q -1 q(q -1) o/EA
where the asterisk indicates that the trivial multiplica tive character is deleted
from the range of summation. Since� is nontrivial, we have I G( f, X) I � q'l'·
for every nontrivial .f, and so
IZ(O)-(q'-'-l)rl._ (q-l)r (IAI-l)q'l'- (6.42) q'-1 q(q'-1)
Let H be the smallest subgroup ofF* containing a and K*. The element a
has order r in the cyclic group F*, therefore IHI � h, the least common
multiple of rand q -1. Furthermore, we have .f E A if and only if .f(fJ) � 1
for all fJ E H. In other words, A is the annihilator of H in ( F*) A (see p.
165), and so
IAI� IF*I � q'-1
IHI h (6.43)
by Theorem 5.6. The inequality (6.37) follows now from (6.42) and (6.43).
For b * 0, we go back to (6.41) and note first that the additive
character�/, is then nontrivial. Therefore, the trivial multiplicative character
contributes 1 to the sum in (6.41), so that we can write
qk-1, , • -Z(b)--,-�
( k ) L ,P(O)G(,P.X)G(,P'.��). q-1 qq-l;,u
Now G(.f', �/,) = -1 if,P' is trivial and IG(.f', �/,)I= q'l' if ,P' is nontrivial,
which implies
IZ( b)-q'-'r 1---'-(lA I-1 + (111-IA I) q'i') q(k!'l-l. q'-1 q'-1
Since J is the annihilator in ( F*) A of the subgroup of F* generated b)l a, we
have 111 � (q' -1)/r by Theorem 5.6. This is combined with (6.43) to
complete the proof of (6.38). 0
One can also obtain results about the distribution of elements in
parts of the period. Let s0, s 1, ••• be an arbitrary linear recurring sequence in
IF• with least period r and preperiod n0. For bEIFq, for N0;>n0 and
1._ N ._ r, let Z(b; N0, N) be the number of n, N0 ._ n ._ N0 + N -1, with
sn =b.
6.85. Theorem. Let s0, s1, ... be a kth-order linear recurring se
quence in F q with least period rand preperiod n0, and let R be as in Theorem
6. 78. Then, for any b E IF q we have
Exercises 245
lz(b; N0, N)-�I.; ( 1-� )( � (2 q•l'( ;logr+ � + �)
for N0? n0 and I� N � r.
Proof Proceeding as in the proof of Theorem 6.82 and using the
same notation as there, we arrive at the identity
N I * N0+N-l
Z(b;N0,N)--�-L:x(b) L: x(s.).
q qX n-N0
On the basis of Theorem 6.81 we obtain then
I Nl I • N,+N-1
Z(b;N0,N)-- .;-L: L: x(s,)
q qX n=N0
.; (I -�) ( � ) 112 q•12 (;log r + � + �),
since there are q-I nontrivial additive characters ofF q· 0
The method in the proof of Theorem 6.84 can also be adapted to
produce results on the distribution of elements in parts of the period
(compare with Exercises 6.69, 6.70, and 6.71).
EXERCISES
6.1. Design a feedback shift register implementing the linear recurrence
relation sn+5 = sn+4-sn+J-sn+ I+ Sn, n = 0, I, ... , in IF].
6.2. Design a feedback shift register implementing the linear recurrence
relation sn+? = 3sn+S -2sn+ 4 + sn+J +2sn +I, n = 0,1, ... , in F7.
6.3. Let r be a period of the ultimately periodic sequence s0, s1, ••• and let
n0 be the least nonnegative integer such that sn+r = sn for all n? n0.
Prove that n0 is equal to the preperiod of the sequence.
6.4. Determine the order of the matrix
A� [ � 0
0
I
0 0
0
0
I
in the general linear group GL(4,F3). -:)
-I
6.5. Obtain the results of Example 6.18 by the methods of Section 5.
6.6. Use (6.8) to give an explicit formula for the terms of the lin
ear recurring sequence in f3 with s0 = s1 =I, s2 = 0, and sn+J =
-sn+l +s11 forn=O,l, ....
6.7. Use the result in Remark 6.23 to give an explicit formula for the
246 Linear Recurring Sequences
terms of the linear recurring sequence in IF4 with s0 = s1 = s2 = 0,
s3=1, and sn+4=asn+3 +sn+1+as11 for n=O,l, ... , where a is a
primitive element of IF 4.
6.8. Prove that the terms s. given by the formula in Remark 6.23 satisfy
the homogeneous linear recurrence relation with characteristic poly
nomialf(x).
6.9. Prove the result in Remark 6.23 for the case where e,..; 2 for
i = 1,2, ... ,m and e; =I if a;=O.
6.10. Represent the elements of the linear recurring sequence in F2 with
s0=0, s1=s2=1, and sn+3=sn+2+s11 for n=O,l, ... in terms of a
suitable trace function.
6.11. Prove Lemma 6.26 by using linear recurring sequences.
6.12. Determine the least period of the impulse response sequence in IF2
satisfying the linear recurrence relation sn+? = sn+6 + sn+S + sn+ 1 + S11
for n = 0, 1, ....
6.13. Calculate the least period of the impulse response sequence associ
ated with the linear recurrence relations,,+ 10 = S11+1 + s,.+2 + sn+ 1 +
S11 in F2.
6.14. Prove Theorem 6.27 by using generating functions.
6.15. Find a linear recurring sequence of least order m IF2 whose least
period is 21.
6.16. Find a linear recurring sequence of least order m IF2 whose least
period is 24.
6.17. Let r be the least period of the Fibonacci sequence in !F.-that is, of
the sequence with s0 = 0, s 1 = I, and sn+ 2 = s,.+ 1 + s,. for n = 0, I, ....
Let p be the characteristic of F q· Prove that r � 20 if p � 5, that r
divides p-1 if p = ± 1 modS, and that r divides p2-1 in all other
cases.
6.18. Construct a maximal period sequence in IF 3 of least period 80.
6.19. An (m, k) de Bruijn sequence is a finite sequence s0, s1, ••• ,sN-! with
N � m' terms from a set of m elements such that the k-tuples
(sn.sn+l•···•sn+Jr-d, n=O.l, .... N-1, with subscripts considered
modulo N are all different. Prove that if d0, d1, ••• is a kth-order
impulse response sequence and maximal period sequence in F q• then
s0�0,s. �d._1 for l..;n..;q'-1 yields a (q,k) de Bruijn se
quence.
6.20. Construct a (2, 5) de Bruijn sequence.
6.21. Let B(x) � 2-x + x3 E IF7[x]. Calculate the first six nonzero terms
of the formal power series 1/B(x).
6.22. Let
00
A(x)�-1-x+x2, B(x)� L (-l)"x"EF3[[x]]. n�O
Exercises 247
Calculate the first five nonzero terms of the formal power series
A(x)/B(x).
6.23. Consider the linear recurring sequence in IF3 with s0 = s1 = s2 =I,
s3=s4= -1, and sn+5=sn+4 +sn+2-sn+1+sn for n=O,l, ....
Represent the generating function of the sequence in the form (6.15).
6.24. Calculate the first eight terms of the impulse response sequence
associated with the linear recurrence relation sn+5 = sn+J + sn+2 + sn
in IF 2 by long division.
6.25. Let s0, s1 •••• be a homogeneous linear recurring sequence in F q·
Prove that the set of all polynomials /(x) � akxk + · · · + a1x + a0
E IF q[x] such that aksn+k + · · · + a1sn+ 1 + a0s, = 0 for n = 0, I, ...
forms an ideal of Fq(x]. Thus show the existence of a uniquely
determined minimal polynomial of the sequence.
6.26. Consider the linear recurring sequence in IF2 with s0 = s3 = s4 = s5 =
s6=0, sl=s2=s7=1. and sn+8=sn+7+sn+6+sn+5+s, for n=
0. I, .... Use the method in the proof of Theorem 6.42 to determine
the minimal polynomial of the sequence.
6.27. Consider the linear recurring sequence in IF5 with s0 = s1 = s2 =I,
s3=-l, and s,+4=3sn +2-sn+l+sn for n=O,I, .... Use the
method in the proof of Theorem 6.42 to determine the minimal
polynomial of the sequence.
6.28. Prove that a homogeneous linear recurring sequence in a finite field
is periodic if and only if its minimal polynomial rn(x) satisfies
m(O)"' 0.
6.29. Given a homogeneous linear recurring sequence in a finite field with
minimal polynomial m ( x ), prove that the preperiod of the sequence
is equal to the multiplicity of 0 as a root of m(x).
6.30. Prove Corollary 6.52 by using the construction of the minimal
polynomial in the proof of Theorem 6.42.
6.31. Use the criterion in Theorem 6.51 to determine the minimal
polynomial of the linear recurring sequence in F2 with sn+6 = sn+J +
sn+2+s"+1+sn for n=O, 1, ... and initial state vector (1, 1, 1,
0, 0, 1).
6.32. Find the least period of the linear recurring sequence in Exercise
6.26.
6.33. Find the least period of the linear recurring sequence m Exercise
6.27.
6.34. Find the least period of the linear recurring sequence in IF 2
with s0 = s1 = s2 = s6 = s7 = 0, s3 = s4 = s5 = s8 = 1, and sn+9 =
sn+7 +sn+4 +s,+l +sn for n = 0, 1, ....
6.35. Find the least period of the linear recurring sequence in F3. with
So= s1 = 1, sl = s3 = 0, s4 =-I, and Sn+5 = sn+4-s,.+-J + sn+2 + sn
for n � 0, I, ....
6.36. Find the least period of the linear recurring sequence in IF 3 with
248
6.37.
6.38.
6.39.
6.40.
6.41.
6.42.
6.43.
6.44.
6.45.
6.46.
6.47. Linear Recurring Sequences
S11+4=sn+3+sn+2-s"-l for n=O.I, ... and initial state vector
(0, -1.1,0).
Prove that a k th-order linear recurring sequence s0, s1, ... in IF q has
least period q• exactly in the following cases:
(a) k=l,qprime,s.+1=s.+aforn=O.I, ... withaEIF;;
(b) k = 2, q = 2, s.+, = s. +I for n = 0.1. ... .
Given a homogeneous linear recurring sequence in F q with a noncon
stant minimal polynomial m(x) E IFq[x] whose roots are nonzero and
simple, prove that the least period of the sequence is equal to the
least positive integer r such that a'= I for all roots a of m (x).
Prove: if the homogeneous linear recurring sequence o in F q has
minimal polynomial f(x) E IF q[x] with deg(f(x)) = n;;. I, then every
sequence in S(f(x)) can be expressed uniquely as a linear combina
tion of o = o<01 and the shifted sequences o<ll, o(2\ ... ,o<n-l) with
coefficients in F q·
Let f1(x), ... ,f.(x) be nonconstan t monic polynomials over Fq that
are pairwise relatively prime. Prove that S(f1(x) · · · f,(x)) is the
direct sum of the linear subs paces S(/1 (x )), ... , S(f.(x)).
Let s0, sl' ... be a homogeneous linear recurring sequence in K = F q
with characteristic polynomial f(x) = f1(x) · · · f,(x ), where the [,(x)
are distinct monic irreducible polynomials over K. Fori= l, ... ,r, let
a, be a fixed root of [;(x) in its splitting field F; over K. Prove that
there exist uniquely determined elements 81 E F1, ••• ,8, E F, such that
s. = TrF,;K(81al)+ · · · +TrF,;K(8,.a�) for n = 0, 1, ....
With the notation of Exercise 6.41, prove that the sequence s0, s1, •••
has f( x) as its minimal polynomial if and only if 81"' 0 for I .;. i .;. r.
Thus show that the number of sequences in S(f(x)) that havef(x)
as minimal polynomial is given by (q••-l)···(q•'-1), where
k,=deg([;(x)) for I.;.i.;.r.
Let a1 and a2 be the impulse response sequences in F2 associated with
the linear recurrence relations sn+6 = sn+J + S11(n = 0,1, ... ) and sn+J
= s. + 1 + s.(n = 0, I, ... ), respectiv ely. Find the least period of a1 + a2.
Let o1 be the linear recurring sequence in 0:3 with sn+J = sn+l
s.+ 1 -s. for n = 0, I, ... and initial state vector (0, I, 0), and let a2 be
the linear recurring sequence in F3 with sn+S =-sn+J-sn+l + sn for
n = 0, 1, ... and initial state vector (1, I, 1.0, 1). Use the method of
Example 6.58 to determine the minimal polynomial of the sum
sequence o1 + o2•
Find the least period of the sum sequence in Exercise 6.44.
Given a homogeneo us linear recurring sequence in IF2 with minimal
polynomial x6 + x' + x4 +IE F2[x], determine the minimal poly
nomial of its binary complement.
Let f(x) = x' + x1 + x4 + x' + x2 + x +IE F2[x]. Determine the
lea.'>t nericxh of .'>eauences from S( (( x n and the numher of .'>e-
Exercises 249
quences attaining each possible least period.
6.48. Let l(x) � (x + I)'(x3 -x +I) E F3[x]. Determine the least periods
of sequences from S(/(x)) and the number of sequences attaining
each possible least period.
6.49. Let I( x) � x5 -2x4-x2-I E F5[x ]. Determine the least periods of
sequences from S(/(x)) and the number of sequences attaining each
possible least period.
6.50. Find a monic polynomi al g(x) E F3[x] such that
S(x + I) S(x2 + x-I) S(x2 -x -I) � S( g( x)).
6.51. Find a monic polynomi al g(x) E F2[x] such that
S(x2+x+l)S(x5+x4+l)�S(g(x)).
6.52. For odd q determine a monic g(x) E IF,[x] for which
s((x-1)2)S((x-1)2) � S(g(x)).
What is the situation for even q?
6.53. Prove that I V(gh)�(f V g)(/ V h) for nonconstant polynomials
1. g, hE IF,[x], provided the two factors on. the right-hand side are
relatively prime.
6.54. Consider the impulse response sequence in F2 associated with the
linear recurrence relation 511+4 = sn+Z + 511, n = 0, I, ... , and the lin-
ear recurring sequence in F2 witl;l 511+4 = S11, n = 0,1, ... , and initial
state vector (0, I, I, 1). Use these sequences to show that there is no
analog of Theorem 6.59 for multiplication of sequences.
6.55. For r EN and IE IF ,[x] with deg(/) > 0, let o,(/) be the sum of the
r th powers of the distinct roots of f. Prove that o,(f V g)�
o,(/)o,(g) for nonconstant polynomials f, g E IF,[x], provided that
the number of distinct roots of I V g is equal to the product of the
numbers of distinct roots of I and g, respectively.
6.56. Let s0, s1, ... be an arbitrary sequence in IF,, and let n;;. 0 and r;;. I
be integers. Prove that if both Hankel determinants D�:l2 and D�r+l>
are 0, then also D�:l1 = 0.
6.57. Prove that the sequence s0, s1, ... in F9 is a homogeneous linear
recurring sequence with minimal polynomial of degree k if and only
if D�k+ 11 � 0 for all n;;. 0 and k +I is the least positive integer for
which this holds.
6.58. Give a complete proof for the second inequality in (6.23).
6.59. Prove the inequalities in (6.24).
6.60. Give a complete proof for (6.26).
6.61. Prove (6.27).
6.62. The first 10 terms of a homogeneous linear recurring sequence in F2
of order.,; 5 are given by 0,1,1,0,0.0,0,1, I. I. Determine its minimal
polynomial by the Berlekamp-Massey algorithm.
6.63. The first R te.rm� nf ;'! hnmnoP_nPnno;: linf"�r rPrnrrina o.:f"rmPnr•P in � _.,.(
250 Linear Recurring Sequences
order .;; 4 are given by 2, I, 0, I, -2, 0, -2, - I. Determine its minimal
polynomial by the Berlekamp-Massey algorithm.
6.64. The first I 0 terms of a homogeneous linear recurring sequence in IF 3
of order .;; 5 are given by I, -1,0, -l,O,O,O,O, 1,0. Determine its
minimal polynomial by the Berlekamp-Massey algorithm.
6.65. Find the homogeneous linear recurring sequence in F 5 of least order
whose first 10 terms are 2,0, -I, -2,0,0, -2,2, -I, -2.
6.66. Suppose the conditions of Theorem 6.78 hold and assume in addition
that the characteristic polynomial f(x) of the sequence s0,s1, ...
satisfies /(0)"' 0. Establish the following improvement of (6.31):
I" I \(s.,)l.;; (; (' ( q'-r) 112 for all u > 0.
(Hint: Note that b � 0 can be excluded in (6.33).)
6.67. Suppose the conditions of Theorem 6.84 hold, let r be a multiple of
(q'-1)/(q-1) and let (q'-I)jrand k be relatively prime. Prove
that Z(O) � (qk-l -l)r/(q' -I).
6.68. Suppose the conditions of Theorem 6.84 hold, let q be odd and
h � (q' -1)/2. Prove that equality holds in (6.37).
6.69. Let Z(b: N0, N) be as in Theorem 6.85. Under the conditions of
Theorem 6.84 and using the notation in the proof of this theorem,
show that
Z(b;N0,N)
N Z(b) I �-; + q(q'-1)
7 >f ( O)G( f, X)G( >f', A/,) >f (a) N;; :)-=. i ( aY'
lj.(a),... I
6.70. Deduce from the result of Exercise 6.69 that
IZ(O:No,N)-(qk-l_I)NI.;; (1--'-)(N _ _!!_)q'l'
q'-I q h q'-I
+q''l'>-1(2log-h-+• ).
1T q-1 h
where '• � 0 for h � q-I and '• � � for h > q-I.
6. 71. Deduce from the result of Exercise 6.69 that
I k-IN I ( 2 2 N( h r) ) Z(b;N0,N)-�'-I.;; ;Iogr+s+ h; q"-1>12
+(N _ _!!_)q''l'>-1 h q' -I
for h * n
Chapter 7
Theoretical Applications of Finite Fields
Finite fields play a fundamental role in some of the most fascinating
applications of modern algebra to the real world. These applications occur in
the general area of data communic 8tion, a vital cOncern in our information
society. Technological breakthroughs like space and satellite communications
and mundane matters like guarding the privacy of information in data banks
all depend in one way or another on the use of finite fields. Because of the
importance of these applications to communication and information theory,
we will present them in greater detail in the following chapters. Chapter 8
discusses applications of finite fields to coding theory, the science of reliable
transmission of messages, and Chapter 9 deals with applications to cryp
tology, the art of enciphering and deciphering secret messages.
This chapter is devoted to applications of finite fields within mathema
tics. These applications are indeed numerous, so we can only offer a selection
of possible topics. Section I contains some results on the use of finite fields in
affine and projective geometry and illustrates in particular their role in the
construction of projective planes with a finite number of points and lines.
Section 2 on com binatorics demonstrates the variety of applications of finite
fields to this subject and points out their usefulness in problems of design of
statistical experiments.
In Section 3 we give the definition of a linear modular system and show
how finite fields are involved in this theory. A system is regarded as a structure
into which something (matter, energy, or information) may be put at certain
"'
252 Theoretical Applications of Finite Fields
times and that itself puts out something at certain times. For instance, we may
visualize a system as an electrical circuit whose input is a voltage signal and
whose output is a current reading. Or we may think of a system as a network of
switching elements whose input is an on/off setting of a number of input
switches and whose output is the on/off pattern of an array of lights.
Some applications of finite fields to the simulation of randomness are
discussed in Section 4. In particular, we show how certain linear recurring
sequences can be used to simulate random sequences of bits. In numerical
analysis one often has to simulate random sequences of real numbers; it is
perhaps surprising that linear recurring sequences in finite fields can also be
instrumental in this task.
We emphasize that the applications are only described to give
examples for the use of various properties of finite fields. Therefore, the
examples contain rather the algebraic and combinatorial aspects, without
regard to their practical application or indeed other usefulness. For in
stance, we are not going to discuss the analysis of experimental design or the
analysis or synthesis of linear modular systems, nor do we explain geometric
properties that are not directly connected with finite fields.
l. FINITE GEOMETRIES
In this section we describe the use of finite fields in geometric problems. A
projective plane consists of a set of points and a set of lines together with an
incidence relation that allows us to state for every point and for every line
either that the point is on the line or is not on the line. In order to have a proper
definition, certain axioms have to be satisfied.
7.1. Definition. A projective plane is defined as a set of elements, called
points, together with distinguished sets of points, called lines, as well as a
relation/, called incidence, between points and lines subject to the following
conditions:
(i) every pair of distinct lines is incident with a unique point (i.e.,
to every pair of distinct lines there is one point contained in
both lines, called their intersection);
(ii) every pair of distinct points is incident with a unique line (i.e.,
to eVery pair of distinct points there is exactly one line which
contains both points);
(iii) there exist four points such that no three of them are incident
with a single line (i.e., there exist four points such that no three
of them are on the same line).
It follows that each line contains at least three points and that
through each point there must be at least three lines. If the set of points is
finite, we speak of a finite projective plane. From the three axioms above one
1. Finite Geometries 253
deduces that (iii) holds also with the concepts of "point" and "line"
interchanged. This establishes a principle of duality between points and lines,
from which one can derive the following result.
7.2. Theorem. Let IT be a finite projective plane. Then:
(i) there is an integer m;;,. 2 such that every point (line) of rr is
incident with exactly m + I lines (points) of IT;
(ii) IT contains exact(v m2 + m +I points (lines).
7.3. Example. The simplest finite projective plane is that with m = 2;
there are precisely three lines through each point and three points on each
line. Altogether there are 7 points and 7 lines in the plane. This projective
plane is called the Fano plane and it may be illustrated as shown in Figure
7.1. The points are A, B, C. D, E, F, and G and the lines are ADC, AGE,
AFB, CGF, CEB, DGB, and DEF. Since straightness is not a meaningful
concept in a finite plane, the subset DEF is a line in the finite projective
pi�. D
The integer m in Theorem 7.2 is called the order of the finite
projective plane. We will see that finite projective planes of order m exist for
every integer m of the form m = p", where p is a prime. It is known that
there is no plane for m = 6, but it is not known whether a plane exists for
m = I 0. Many planes have been found for m = 9, but no plane has yet been
found for which m is not a power of a prime. . .
In ordinary analytic geometry we represent points of the plane as
ordered pairs (x, y) of real numbers and lines are sets of pointS that satisfy
real equations of the form ax+ by+ c = 0 with a and b not both 0. Now the
field of real numbers can be replaced by any other field, in particular a
finite field. This type of geometry is known as affine geometry (or euclidean
geometry) and leads to the concept of an affine plane.
7.4. Definition. An affine plane is a triple ('3', e. I) consisting of a set '3'
of points. a set e of lines, and an incidence relation I such that:
c
A 8
FIGURE 7.1 The Fano plane.
254 Theoretical Applications of Finite Fields
(i) every pair of distinct points is incident with a unique line;
(ii) every point p E §' not on a line L E e lies on a unique line
ME C which does not intersect L;
(iii) there exist four points such that no three of them are incident
with a single line.
The proof of the following theorem is straightforward.
7.5. Theorem. Let K be any f�eld. Let !!!' denote the set of ordered
pairs (x. y) with x. y E K. and let e consist of those subsets L of Gj' which
satisfy linear equations, i.e .. LEe if for some a, b, c E K with (a, b)"' (0,0)
we have L � {( x, y) : ax + by + c � 0). A point P E 6J' is incident with a line
LEe if and only if PEL. Then (6j', C, I) is an affine plane, denoted by
AG(2,K).
It can be shown readily that if IKI � m, then each line of AG(2. K)
contains exactly m points. We can construct a projective plane from
AG(2, K) by adding a line to it (and, conversely, we can obtain an affine
plane from any projective plane by deleting one line and all the points on
it).
We change the notation in AG(2, K) and rename all the points as
(x. y, 1), that is, (x. y. z) with z � 1. and use the equation ax+ by+ cz � 0
with (a, b)"' (0.0) as the equation of a line. Now add the set of points
L00 � {(l.O,O)}u((x,I,O): x E K)
to 9 to form a new set 9' � "!' U L00• The points of L00 can be represented
by the equation z � 0 and so can be interpreted as a line. Let this new line
L00 be added to C to form the set e·� C U(L00). With the natural extended
notion of incidence, it can be verified that ('3'', e·. !')satisfies all the axioms
for a projective plane.
7.6. Theorem. Let AG(2, K) � (0', C, I) and let
9'� 9 U{(l,O,O)}U{(x, 1,0): x E K) � 6J' U L00,
e·� C U{L00),
and let the extended incidence relation be denoted by I'. Then ('3'', C', /') is a
projective plane. denoted by PG(2. K ) .
7.7. Example. The plane PG(2, �1)-that is, the projective plane over
the field �2 -has seven points: (0.0, I), (1,0, I), (0, I, I), and (1.1.1) with
z "'0 and the three distinct points on the line z � 0, namely, (1,0,0), (0, 1,0),
and (1, 1,0). It can be verified that PG(2.1F2) also contains seven lines and
that this projective plane is the Fano plane of Example 7.3. 0
In constructing PG(2, K ), every line of AG(2. K) must meet the new
line L00, so there will be an additional point on each line; also Lr:T,) contains
1. Finite Geometries 255
0
p
B,
FIGURE 7.2 Desargues's theorem.
m + I points if K contains m elements. Since for every prime power
m � p" � q there are finite fields F ,, we have the following theorem.
7.8. Theorem. For every prime power q � p", p prime, nE N,
there exists a finite projective plane of order q-namely, PG(2, F .J.
The additional line L00 added to an affine plane to obtain a projec
tive plane is sometimes called the line at infinity. If two lines intersect on
L00, they are called parallel.
Next we present without proof two interesting theorems, which hold
in all projective planes that can be .represented analytically in terms of
fields. Two triangles ll.A1B1C1 and ll.A2B2C2 are said to be in perspective
from a point 0 if the lines A1A2, B1 82, and C1C2 pass through 0. Points on
the same line are said to be collinear.
7.9. Theorem (Desargues's Theorem). Ifll.A1B1C1 andll.A2B2C2
are in perspective from 0, then the intersections of the lines A1 81 and A2 82, of
A1C1 and A2C2, and of B1C1 and B2C2, are collinear.
The theorem is illustrated in Figure 7.2; the intersections of corre
sponding lines are P, Q, and Rand are collinear.
7.10. Theorem (Theorem of Pappus). If A1, 81, C1 are points of a
line and A2, 82, C2 are points of another line in the same plane, and if A1B2
and A2B1 intersect in P, A1C2 and A2C1 intersect in Q, and B1C2 and B2C1
intersect in R, then P, Q. and Rare collinear.
The theorem is illustrated in Figure 7.3. Both theorems play an
important role in projective geometry. If Desargues's theorem holds in some
projective plane, then coordinates can be defined in terms of elements from
a division ring. Here we define a point as an ordered triple (x0, x1, x2) of
three homogeneous coordinates, where the x,. are elements of a division ring
R, not all of them simultaneously 0. The triples (ax0, ax1, ax2), 0"' a E R,
256 Theoretical Applications of Finite Fields
FIGURE 7.3 The theorem of Pappus.
shall denote the same point. Thus each point is represented in m -I ways if
!RI � m, and because there are m3 -I possible triples of coordinates, the
total number of different points is
( m3 -I)/( m -I) � m2 + m +I.
A line is defined as the set of all those points whose coordinates satisfy an
equation of the form x0 + a1x1 + a1x2 = 0, or of the form x1 + a2x1 = 0, or
of the form x2 = 0, where a; E R. There are m2 + m +I such lines in the
plane and it is straightforward to show that the points and lines thus
defined satisfy the axioms of a finite projective plane.
From Theorem 2.55-that is, Wedderburn's theorem-we know that
any finite division ring is a field, a finite field F •. In that case the equation
of any line can be written as a0x0 + a1x1 + a2x1 = 0, where the a; are not
simultaneously 0, a"d (aa0)x0 +(aa1)x1 +(aa2)x2 � 0 with a E F; is the
same line. The line connecting the points (y0,y1,y 2) and (z0,z1,z 2) may
then also be defined as the set of all points with coordinates
where a and b are in IF •' not both equal to 0. There are q2-I such triples,
and since simultaneous multiplication of a and b by the same nonzero
element produces the same point, they yield q +I different points.
In PG(2.1F .• ) Desargues's theorem and its converse hold, and the
proof relies on commutativity of multiplication in IF q· In general, Desargues's
theorem and its converse do not both apply if the coordinatizing ring does
not have commutativity of multiplication. Thus Wedderburn's theorem
plays an important role in this context.
A projective plane in which Desargues's theorem holds is called
Desarguesian; o.therwise it is called non-Desarguesi an. Desarguesian planes
of order m exist only if m is the power of a prime, and up to isomorphism
there exists only one Desarguesian plane for any given prime power m = p".
1. Finite Geometries 257
A finite Desarguesian plane can always be coordinatized by a finite field.
Since such fields exist only when the order is a prime power, a projective
plane with exactly m +I points on each line, m not a prime power, will have
to be non-Desarguesian. It is not known whether such planes for m not a
prime power exist. If it can be proved that up to isomorphism there exists
only one finite projective plane of order m, and if m is a prime power, then
this plane must be Desarguesian. This is the case form� 2, 3, 4, 5, 7, and 8.
For m prime, only Desarguesian planes are known. But it has been shown
that for all prime powers m � p", n:;, 2, except for 4 and 8, there exist
non-Desarguesian planes of order m.
The theorem of Pappus implies the theorem of Desargues. If the
theorem of Pappus holds in some projective plane, then the multiplication
in the coordinatizing ring is necessarily commutative. The theorem of
Pappus holds in PG(2, F q) for any prime power q. A finite Desarguesian
plane also satisfies the theorem of Pappus.
A remarkable distinction between the properties of a PG(2,F,) with
q even and a PG(2,1F,) with q odd is given in the following theorem.
7.11. Theorem. The diagonal points of a complete quadrangle in
PG (2,1F,) are collinear if and only if q is even.
Proof We assume, without loss of generality, that the vertices of
the quadrangle are (1,0,0), (0,1,0), (0,0, 1), and (1, !,!). Its six sides are
x2 = 0, x1 = 0, x1 � x2 = 0, x0 = 0, x0 � x2 = 0, and x0 � x1 = 0, while the
three diagonal points are (1, 1,0), (1.0, 1), and (0,1,1). The line through the
first two points contains all points with coordinates (a+ b, a, b), where
(a, b)* (0,0), and the third point is one of these if and only if a� band
a+ b � 0. In a finite field IF, this is only possible if the characteristic is 2. D
The latter case is illustrated in Example 7.3. Let the vertices of the
complete quadrangle be C, D, E, G. In this case, the diagonal points are
A, F, B, and they are collinear.
We introduce now concepts analogous to those with which we are
familiar in analytic geometry, and we restrict ourselves to Desarguesian
planes, coordinatized by a finite field F ,.
Let the equations of two distinct lines be
a01x0 + a11x1 + a21x2 = 0,
aooxo+a12xl+anx2=0. (7.1)
Let the point of intersection of these two lines be P. All lines through P
form a pencil and each line in this pencil has an equation of the form
( ra01 + sa02)x0 + (ra11 + sa12)x1.+ ( ra21 + sa22 )x2 � 0,
where r, s E IF, are not both 0. There are q + I lines in the pencil: the two
lines (7.1) given above corresponding to s � 0 and r � 0, respectively, and
258 Theoretical Applications of Finite Fields
those corresponding to q-I different ratios rs-1 with r"' 0 and s "'0. Let
another pencil through a point Q"' P be given by
(rb01 + sb02)x0 + (rbl! + sb12)x1 + (rb21 + sb22)x2 = 0.
A projective correspondence between the lines of the two pencils is defined
by letting a line of the first, given by a pair ( r, s ), correspond to the line of
the second pencil that belongs to the same pair. Two corresponding lines
meet in a unique point, except when the line PQ corresponds to itself, and
the coordinates of all the points satisfy the equation
(a01x0 + al!x1 + a21x2)(b02x0 + b12x1 + b22x2)
-(a01x0 + a12x1 + a22x2)(b01x0 + bl!x1 + b21x2) = 0, (7.2)
obtained by eliminating r and s from the equations of the two pencils.
7.12. Definition. The set of points whose coordinates satisfy equation
(7.2) is called a conic. If the line PQ corresponds to itself under the
correspondence above, then the conic is called degenerate. It consists then of
the 2q + l points of two intersecting lines. A nondegenerate conic consists of
the q + I points of intersection of corresponding lines. A line that has
precisely one point in common with a conic is called a tangent of it; a line
that has two points in common is a secant.
The equation of a nondegenerate conic is quadratic, therefore it
cannot have more than two points in common with any line. Take one point
of a nondegenerate conic and connect it by lines to the other q points. Then
the resulting lines are secants and the remaining one of the q + l lines
through that point must be a tangent.
The q + I points of a nondegenerate conic thus have the property
that no three of them are collinear. It can be shown that any set of q +I
points in a PG(2,F.), q odd, such that no three of them are collinear is a
nondegenerate conic.
The following theorem, which we prove only in part, exhibits a
difference between conics in Desarguesian planes of odd and of even order.
7.13. Theorem. (i) In a Desarguesian plane of odd order there pass
two or no tangents of a nondegenerate conic through a point not on the conic.
(ii) In a Desarguesian plane of even order all the tangents of a
nondegen erate conic meet in a single point.
Proof We prove (ii) as an example of how properties of finite fields
are used in the theory of finite projective planes. Assume without loss of
generality that three points on a nondegenerate conic in a plane of even
order are A(l,O,O), B(O,l,O), C(O,O, I) and that the tangents through these
three points are, respectively, x1-k0x2 = 0, x2-k1x0 = 0, x0-k2x1 = 0.
Let P(t0, 11, I 2) be another point of the conic. None of the t, can be 0,
1. Finite Geometries 259
because then P would be on a line through two of the points A. B, and C,
contradicting the fact that no three points of the conic are collinear.
Therefore we can write x1-t1121x2=0 for PA, x2-121Q1x0=0 for PB,
and x0-t0t[1x1 � 0 for PC.
Consider the equation for the line PA. As we choose for P the
various points of the conic, leaving out A, B, and C, the ratio 11121 runs
through the elements of f q apart from 0 and k0. Since
n (x-c)�x'-1-1,
cEF;
the product of all nonzero elements of F• is ( -I)•. Thus, multiplying the
product of the q-2 values t 1t2 1 assumes by k", we obtain ( -I)q �I, since
q is even. We have
where the product extends over all points of the conic except A, B, and C.
Multiplying the three products above we get k0k1k2 �I. Therefore the
points(!, k0k1, k1), (k2, I, k1k2), and (k0k2, k0, I) are identical. The three
tangents at A, B, and C pass through this point; and because these points
were arbitrary. any three tangents meet in the same point. D
Analogs of the concept of a projective plane can be defined for
dimensions higber than 2.
7.14. Definition. A projective space, or a projective geometry, or an m
space is a set of points, together with distinguished sets of points, called
lines, subject to the following conditions:
(i) There is a unique line through any pair of distinct points.
(ii) A line that intersects two lines of a triangle intersects the third
line as well.
(iii) Every line contains at least three points.
(iv) Define a k-space as follows. A 0-space is a point. If A0, ... ,Ak
are points not all in the same (k -I)-space, then all points
collinear with A0 and any point in the (k-I)-space defined by
A1, ... ,Ak form a k-space. Thus a line is a !-space, and all the
other spaces are defined recursively. Axiom (iv) demands: If
k < m, then not all points considered are in the same k-space.
(v) There exists no (m +I)-space in the set of points considered.
We say that an m-space has m dimensions, and if we refer to a
k-space as a subspace of a projective space of higber dimension, we call it a
k-flat. An ( m -1)-flat in a projective space of m dimensions is called
a hyperplane. A 2-space is a projective plane in the sense of Definition 7.1.
It can be proved that in any 2-flat in a projective space of at least three
260 Theoretical Applications of Finite Fields
dimensions the theorem of Desargues (Theorem 7.9) is always valid.
Desargues's theorem can only fail to be true in projective planes that cannot
be embedded in a projective space of at least three dimensions.
A projective space containing only finitely many points is called a
finite projective space (or finite projective geometry, or finite m-;pace ). In
analogy with PG(2,F.), we can construct the finite m-space PG(m,f.).
Define a point as an ordered (m +!)-tuple (x0, x1, •••• x.,), where the
coordinates x, E f • are not simultaneously 0. The (m + !)-tuples
(ax0,axp····axm) with aEf; define the same point. There are therefore
(q"'+ 1 -l)/(q -l) points in PG(m,F.).
A k-flat in PG(m,F,) is the set of all those points whose coordinates
satisfy m-k linearly independent homogeneous linear equations
with coefficients a,1 E IF,. Alternatively, a k-flat consists of all those points
with coordinates
with the a, E F• not simultaneously 0 and the k + l given points
( Xoo, ···,X om),.·· • (xkO• · · · ,xkm)
being linearly independent; that is, the matrix
has rank k + l. The number of points in a k-flat is (qk+ 1 -1)/(q -1); there
are q + l points on a line and q2 + q + l on a plane. That PG(m,IF•)
satisfies the five axioms for an m-space is easily verified.
We know that in f •"" all powers of a primitive element a can be
represented as polynomials in a of degree at most m with coefficients in IF q·
If
a;=ama'"+ ··· +a0,
we may consider a; as representing a point in PG(m,IFq) with coordinates
(a0, ... ,a,J. Two powers a',ai represeiJ,t the same point if and only if
a;= a a' for some a E F;-that is, if and only if
i= imod(a"'+1-!)/(a-l).
1. Finite Geometries 261
A k-flat S through k +I linearly independent points represented by a'' .... ,
a;k will contain all points represented by L�_0a,a;•, a, E F q not simulta
neously O. For each h = O,l, ... ,v -I with v = (qm+l -1)/(q -I), the points
L�-o a,ai,+lr, a, E F q not simultaneously 0, form k-flats, and we denote the
k-flat with given h by s •. We haveS,= S0 = S because a" E F •. Letj be the
least positive integer for which S, = S. Then from s., = S for all n EN it
follows that j divides v, say v = tj. We call j the cycle of S.
If a"' is a point of the k-flat S, then so are the points with exponents
d0,d0+ j, ... ,d0+(1-l)j,
because s.; = S for n = 0,1, ... ,1-1. Further points on S can be wntten
with the following exponents of a:
dl, dl + j . ... ,dl +(1-l)j
d._ \'du-1 + j, ... ,d•-1 +(I- l)j,
where d,,-d,, is not divisible by j for r1 "'r2. The number of all these
distinct points is tu = ( qk+ 1 -I)/( q-I).
If tj=(qm+l_l)/(q-1) and lu=(qk+1-l) (q-1) are relatively
prime, then r =I, j = v, and all k-flats have cycle v. This is the case for
k = m -I, and for k = I when m is even.
7.15. Example. Consider PG(3,F2) with 15 points, 35 lines, 15 planes,
and qm+ 1 = 16. Using a root a E IF 16 of the primitive polynomial x4 + x +I
over IF2, we can establish a correspondence between the powers of a and the
points of PG(3,1F2). We obtain:
A(O.O,O,l) .. · a3
B(O,O,l,O) · · · a2
C(O,O,l,l) ···a'
D(O,l,O,O) · · · a1
£(0.1,0,1) ···a'
The plane F(O,l,l,O) · · · a5
G(O.l,l, I)··· a11
H(l,O,O,O) · · · a0
/(1,0,0,1) ··· a14
J(I,O, 1,0) ···a' K(l,O,l,l) · · · a13
L(l,l,O,O) · · · a4
M(l,l,O,l) · · · a7
N(l,l,l,O) · · · a10
0(1,1,1,1) · · · a12
S=S0={a0a0+a1a1+a2a2· a0,a1,a2EIF2notall 0}
is the same as the plane x3 = 0. It contains the points B, D, F, H, J, L, and
N. It has cycle 15, as has any other hyperplane. The plane
S1 = {a0a1 + a1a2 + a2a3: a0,a1, a2 EF2 not all 0}
is the same as the plane x0 = 0 and contains the points A, B, C, D, £, F.
and G; and so on. The line
{a0a3 + a,a8: a0, a, E F, not bothO},
262 Theoretical Applications of Finite Fields
that is, the line AJK, has cycle 5, the lines ABC and ADE both have cycle
15, and this accounts for all the 5 + 15 + 15 � 35 lines. D
A finite affine (or euclidean) geometry, denoted by AG(m,F,), is the
set of flats that remain when a hyperplane with all its flats is removed from
PG( m, IF ,J. Those flats that were removed are called flats at infinity. Those
remaining flats that intersect in a flat at infinity are called parallel. It is
convenient to consider the excluded hyperplane as the one whose equation
is x., � 0. Then we may fix x., for all points in A G(m, f ,) at I, and consider
only the remaining coordinates as those of a point in AG(m,IF,). Since there
are q"' + · · · + q +I points in PG(m,f,), and the q"'-1 + · · · + q +I
points of a hyperplane were removed, there remain q"' points inAG(m,IF, ).
A k-flat within AG(m,F,) contains all those q' points that satisfy a
system of equations of the form
a;0x0+ ··· +a;,m-IXm- l+a;m=O, i=l, ... ,m-k,
where the coefficient matrix has rank m -k. In particular, a hyperplane is
defined by
OoXo + ... + am-IXm -1 +Om= Q,
where a0, ... ,am-l are not all 0. If a0, ... ,am-l are kept constant and am
runs through all elements of F ,. then we obtain a pencil of parallel
hyperplanes.
2. COMBINATORICS
In this section we describe some of the useful aspects of finite fields in
combinatorics.
There is a close connection between finite geometries and designs.
The designs we wish to consider consist of two nonempty sets of objects,
with an incidence relation between objects of different sets. For instance,
the objects may be points and lines, with a given point lying or not lying on
a given line. The terminology that is normally used in this area has its origin
in the applications in statistics, in connection with the design of experi
ments. The two types of objects are called varieties (in early applications
these were plants or fertilizers) and blocks. The number of varieties will, as a
rule, be denoted by v, and the number of blocks by b.
A design for which every block is incident with the same number k of
varieties and every variety is incident with the same number r of blocks is
called a tactical configuration. Clearly
vr � bk. (7.3)
If v � b, and hence r � k, the tactical configuration is called symmetric. For
instance, the points and lines of a PG(2,F,) form a symmetric tactical
2. Combinatorics 263
configuration with v � b � q2 + q + I and r � k � q + I. The property of a
finite projective plane that every pair of distinct points is incident with a
unique line may serve to motivate the following definition.
7.16. Definition. A tactical configuration is called a balanced incomplete
block design (BIBD), or (v, k, A.) block design, if v;;. k;;. 2 and every pair of
distinct varieties is incident with the same number A. of blocks.
If for a fixed variety a1 we count in two ways all the ordered pairs
(a2, B) with a variety a2"' a1 and a block B incident with a1, a2, we obtain
the identity
r(k-l)�A.(v-1) (7.4)
for any (v, k, A.) block design. Thus, the parameters band r of a BIBD are
determined by v, k, and A. because of (7.3) and (7.4).
7.17, Example. Let the set of varieties be {0, 1,2,3,4,5,6) and let the
blocks be the subsets {0, 1,3), (1,2,4), {2,3,5), {3,4,6), {4,5,0), (5,6, 1), and
{6, 0, 2), with the obvious incidence relation between varieties and blocks.
This is a symmetric BIBD with v � b � 7, r � k � 3, and A.� I. It is
equivalent to the Fano plane in Example 7.3. A BIBD with k � 3 and ). = 1
is called a Steiner triple system. D
7.18, Example, More generally, a BIBD is obtained by taking the points
of a projective geometry PG(m,IFq) or of an affine geometry AG(m,F•) as
varieties and its t-flats for some fixed 1, l,.t.< m, as blocks. In the
projective case, the parameters of the resulting BIBD are as follows:
v� qm+l -I t+ I m-t+i I t m-t+i 1
b�nq. -' r�nq. - ' q-1 i=l q'-1 i-1 q'-1
qt+l_l t-l qm-t+i -I k� .A.�n • q-1 i-1 q' -I
where the last product is interpreted to be 1 if I � I. The BIBD is symmetric
in case t � m -1-that is, if the blocks are the hyperplanes of PG(m,IFq).
In the affine case, the parameters of the resulting BIBD are as follows:
t m-t+i _I t m-t+i _I
b � qm-• n q . ' r � n q . '
i-I q'-I j- I q' -I
t-l qm-t+i -I k � q' A� n .:!___........:.. •
i-1 q;-1 .
with the same convention for t �I as above. Such a BIBD is never
symmetri c. D
A tactical configuration can be described by its incidence matrix.
264 Theoretical Applications of Finite Fields
This is a matrix A of v rows and b columns, where the rows correspond to
the varieties and the columns to the blocks. We number the varieties and
blocks, and if the ith variety is incident with the jth block, we define the
(i, j) entry of A to be the integer I, otherwise 0. The sum of entries in any
row is r and that in any column is k.
If A is the incidence matrix of a ( v, k, A) block design, then the inner
product of two different rows of A is A. Thus, if AT denotes the transpose of
A, then
r A A
A r A
A A r � (r-A)l +AJ,
where I is the v X v identity matrix and J is the v X v matrix with all entries
equal to I. We compute the determinant of AAT by subtracting the first
column from the others and then adding to the first row the sum of the
others. The result is
rk 0
A r-A
0
0 0
0
r-A
0 0
0
0
� rk ( r-A) v- 1,
r-A
where we have used (7.4). If v � k, the design is trivial, since each block is
incident with all v varieties. If v > k, then r >A. by (7.4), and so AAT is of
rank v. The matrix A cannot have smaller rank, hence we obtain
b� v. (7.5)
By (7.3), we must also have r ;>. k.
For a symmetric ( v, k, A) block design we haver� k, hence AJ � JA,
and so A commutes with (r-A)/+ AJ� AAT Since A is nonsingular if
v > k, we get ATA � AAT � (r-A)/+ AJ. It follows that any two distinct
blocks have exactly A varieties in common. This holds trivially if v � k.
We have seen that the conditions (7.3) and (7.4), and furthermore
(7.5) in the nontrivial case, are necessary for the existence of a BIBD with
parameters v, b, r, k, A. These conditions are, however, not sufficient for the
existence of such a design. For instance, a BIBD with v � b � 43, r � k � 7,
and A � I is known to be impossible.
The varieties and blocks of a symmetric ( v, k, A) block design with
k ;>. 3 and A � I satisfy the conditions for points and lines of a finite
projective plane. The converse is also true. Thus, the concepts of a symmetric
( v, k, I) block design with k ;>. 3 and of a finite projective plane are equivalent.
Consider the BIBD in Examnle 7.17 and interoret the varieties
2. Combinatorics 265
0, 1,2,3,4,S,6 as integers modulo 7. Each block of this design has the
property that the differences between its distinct elements yield all nonzero
residues modulo 7. This suggests the following definition.
7.19. Definition. A set D � {d1, ••• ,d,) of k;, 2 distinct residues modulo
v is called a ( v, k, .\) difference set if for every d ;�; 0 mod v there are exactly
,\ ordered pairs ( d,, d) with d,, dj ED such that d,-dj = dmod v.
The following results provide a connection between difference sets,
designs, and finite projective planes.
7.20, Theorem. Let {d1, ••• ,d,) be a (v, k, .\)difference set. Then
with all residues modulo v as varieties, the blocks
B, � {d1 + t, ... ,d, + 1), I� 0, l, ... ,v -I,
form a symmetric ( v, k, .\) block design under the obvious incidence relation.
Proof A residue a modulo v occurs exactly in the blocks with
subscripts a-d1, ••• ,a-dk modulo v, thus every variety is incident with the
same number k of blocks. For a pair of distinct residues a, c modulo v, we
have a, c E B, if and only if a= d, + t mod v and c = dj + t mod v for some
d,, dJ" Consequently, a-c = d, -djmod v, and conversely, for every solu
tion ( d,, d) of the last congruence, both a and c occur in the block with
subscript a-d, modulo v. By hypothesis, there are exactly ,\ solutions
(d,, d) of this congruence , and so all the conditions for a symmetric
( v, k, ,\) block design are satisfied. D
7.21. Corollary. Let {d1, ••• ,d,) be a (v,k,l) difference set with
k ;, 3. Then the residues modulo v and the blocks B,, t � 0, I, ... , v-I, from
Theorem 1.20 satisfy the conditions for points and lines of a finite projective
plane of order k -I.
Proof This follows from Theorem 7.20 and the observation above
that symmetric (v, k, I) block designs with k;, 3 are finite projective planes.
D
It follows from Theorem 7.20 and (7.4) that the parameters v, k, A
of a difference set are linked by the identity k(k-I)�.\( v -1). This can
also be seen directly from the definition of a difference set.
7.22. Example. The set (0, 1,2,4,S,8, 10) of residues modulo IS is a
(IS, 7,3) difference set. The blocks
B,� {t,t+ l,t+2,t+4,t +S,t +8,1 + 10), t�O,l, ... , 14,
form a symmetric (IS, 7, 3) block design according to Theorem 7.20. The
blocks of this design can be interpreted as the IS planes of the projective
geometry PG(3.F2), with the IS residues representing the points. Each plane
is a Fano nlane pr,(2.F .. )_ The lines of the hlock R can he nhtaineci hv
266 Theoretical Applications of Finite Fields
cyclically permuting the points of the line
L, � B, n 8,_4 � {t, t +I, t +4)
in the plane B, according to the permu ta lion
r-r+1 -r+2-t+4-r+5-r+I O-r+8-r.
For instance, the lines in the plane 80 � (0, 1,2,4,5, 10,8) are
(0, 1.4}, (1.2,5). (2,4, 10}, (4,5,8), (5, 10,0}, (10,8, 1}, (8,0,2}. D
Examples of difference sets can be obtained from finite projective
geometries. As in the discussion preceding Example 7.15, we identify points
of PG(m,f•) with powers of a, where a is a primitive element of IF ••.• , and
the exponents of a are considered modulo v � (qm+l -1)/(q -I). LetS be
any hyperplane of PG(m,F.). Then S has cycle v, and so the hyperplanes
s. � a•s, h � 0, I, ... , v-I, are distinct. These are already all hyperplanes of
PG(m,F .), since v is also the total number of hyperplanes. Thus, the
following is the complete list of hyperplanes of PG(m,f.), with the points
contained in them indicated by the corresponding exponents of a:
S0 d1 d2 d,
S1 d1 +I d2 +I d, +I
Here k � ( qm-I)/( q-I), the number of points in a hyperplane. If we look
for those rows that contain a particular value, say 0, then we obtain the k
hyperplanes through a0• These k rows are given by:
d,-d, d,-d,
d,-d, d,-d,
Any point "'a0 appears in as many of those k hyperplanes as there are
hyperplanes through two distinct points-that is, 'A� (qm-l -1)/(q -I) of
them-so that the off-diagonal entries repeat each nonzero residue modulo
v precisely A times. Hence (d1, ... ,d,) is a (v,k,'h) difference set. We
summarize this result as follows.
7.23. Theorem. The points in any hyperplane of PG(m,IF•) de
termine a ( v, k, A) difference set with parameters
qm+ 1 _I qm _ 1 qm-1 _ 1
v� q-1 . k�-q---,-, 'A� q-1
7.24. Example. Consider the hyperplane x1 � 0 of PG(3,1F2) in Example
7.15. It contains the points A, B, C, H, I, J, K. and so the corresponding
2 Combinatorics 267
exponents of a yield the ( 15, 7, 3) difference set {0, 2, 3, 6, 8, 13, 14). D
Another branch of combinatorics in which finite fields are useful is
the theory of orthogonal latin squares.
7.25. Definition. An array
a" a" a,"
a, a, aln
L �(a,)�
a", a"' a""
is called a latin square of order n if each row and each column contains
every element of a set of n elements exactly once. Two latin squares (a,.)
and (b,j) of order n are said to be orthogonal if the n2 ordered pairs (a,,, b,j)
are all different.
7.26. Theorem. A latin square of order n exists for every positive
integer n.
Proof Consider(a,.)witha,j=i+ jmodn.l�a,j�n. Thena,j=
a,.k implies i + j = i + kmod n. and so}= kmod n, which means }= k since
I.; i, j, k.; n. Similarly, a,j � a,j implies i � k. Thus the elements of each
row and each column are distinct. D
Orthogonal latin squares were first studied �y Euler. He conjectured
that there did not exist pairs of orthogonal latin squares of order n if n is
twice an odd integer. This was disproved in 1959 by the construction of a
pair of orthogonal latin squares of order 22. It is now known that the values of
n for which there exists a pair of orthogonal latin squares of order n are
precisely all n > 2 with n # 6.
For some values of n, more than two latin squares of order n exist
that are mutually orthogonal (i.e., orthogonal in pairs). We shall show that if
n = q. a prime power, then there exist q-I mutually orthogonal latin
squares of order q, by using the existence of finite fields of order q.
7.27. Theorem.
Then the arrays Let a0�0,a1,a2, ... ,a._, be the elements of IF •.
ao a, aq-1
aka1 aka1 + a1 aka1 + aq-l
L,� aka2 aka2 + al akal + aq-1 k � l, ... ,q-1,
akaq-1 akaq-l + a1 akaq-1 + aq-1
form a set of q-I mutually orthogonal latin squares of order q.
268 Theoretical Applications of Finite Fields
Proof Each Lk is clearly a latin square. Let aLk, = ak.a;_1 + a1_1 be
the (i, j) entry of L,. Fork* m, suppose
Then
and so (a��) a�'?'l) � (a<kl aCml) for some 1 :!>: i 1. g h "'q I) ' I} gh I gh ""<:: 1 1 1 ""<:: "
Since ak*-am, it follows that a;_1=a g_1, ah_1=a1_1, hence i=g,j=h.
Thus the ordered pairs of correspond ing entries from L, and Lm are all
different, and soL, and Lm are orthogonal . 0
7.28. Example. A set of four mutually orthogonal latin squares of order 5
is given below, using the construction in Theorem 7.27:
L, L2
0 l 2 3 4 0 l 2 3 4
l 2 3 4 0 2 3 4 0 l
2 3 4 0 l 4 0 l 2 3
3 4 0 l 2 l 2 3 4 0
4 0 l 2 3 3 4 0 l 2
L, L•
0 l 2 3 4 0 l 2 3 4
3 4 0 l 2 4 0 l 2 3
l 2 3 4 0 3 4 0 l 2 0
4 0 l 2 3 2 3 4 0 l
2 3 4 0 l l 2 3 4 0
The following result, which also yields information for the case
where the order n of the latin squares is not a prime power, is proved in the
same way as Theorem 7.27. Note that Theorem 7.29 shows, in particular, the
existence of a pair of orthogonal latin squares of order n for any n > 1 with
n¢2 mod 4.
7.29. Theorem. Let q 1, ... , q, be prime powers and let
0t�l = 0 0ln alil 0u1 0 • I • 2 •· · · • q,-l
be the elements of 'f.,. Define the s-tuples
b,�(ai'1 .... ,ai'1) forO<>.k<>.r� min (q,-1). l"i"J
and let b,+1, ••• ,b,_1 with n = q1 • • • qs be the remaining s-tuples that can be
formed by taking in the ith coordinate an element off •• These s-tuples are
2. Combinatorics 269
added and multiplied by adding and multiplying their coordinates. Then the
arrays
bo bl bn-1
b,bl b,bl +bl b,bl + b,_l
L, � b,b, b,b, + bl b,b,+b,_l k = l, ... ,r,
bkb,l_l b,b,_l + bl bkbn-l+bn-1
form a set of r mutually orthogonal latin squares of order n.
Tactical configurations and latin squares are of use in the design of
statistical experiments. For example, suppose that n varieties of wheat are to
be compared as to their mean yield on a certain type of soil. At our disposal
is a rectangular field subdivided into n2 plots. However, even if we are
careful in the selection of our field, differences in soil fertility will occur on
it. Thus, if all the plots of the first row are occupied by the first variety, it
may very well be that the first row is of high fertility and we might obtain a
high yield for the first variety although it is not superior to the other
varieties. We shall be less likely to vitiate our comparisons if we set every
variety once in every row and once in every column. In other words, the
varieties should be planted on the n2 plots in such a way that a latin square
of order n is formed.
It is often desirable to test at the same time other factors influencing
the yield. For instance, we might want to apply n different fertilizers and
evaluate their effectiveness. We will then arrange fertilizers and varieties on
the n2 plots in such a way that both the arrangement of fertilizers and the
arrangement of varieties form a latin square of order n, and such that every
fertilizer is applied exactly once to every variety. Thus, in the language of
combinatorics, the latin squares of fertilizer and variety arrangements
should be orthogonal. Similar applications exist for balanced incomplete
block designs.
As another example for a combinatorial concept allowing applica
tions of finite fields, we introduce so-called Hadamard matrices. These
matrices are useful in coding theory, in communication theory, and physics
because of Hadamard transforms, and also in problems of determination of
weights, resistances, voltages, and so on.
7.30. Definition. A Hadamard matrix H11 is an n X n matrix with integer
entries ±I that satisfies
HnH} =n/.
Since H,-1 � (ljn)H,T, we also have H,TH, � nl. Thus, any two
distinct rows and any two distinct columns of Hn are orthogonal. The
270 Theoretical Applications of Finite Fields
determinant of a Hadamard matrix attains a bound due to Hadamard. We
have det(H,H,T) � n". and so ldet(H,)I � n"l'. while Hadamard's result
states that ldet(M)I "n"l' for any real n X n matrix M with entries of
absolute value �I.
Changing the signs of rows or columns leaves the defining property
unaltered. so we may assume that H11 is normalized -that is, that all entries
in the first row and first column are +I. It is easily seen that the order n of
a Hadamard matrix (a1) can only be I. 2. or a multiple of 4. For we have
" "
j=l j=l
for n ;;. 3 and every term in the first sum is either 0 or 4, hence the result
follows. It is conjectured that a Hadamard matrix H, exists for all those n.
7.31. Example. Hadamard matrices of the lowest orders are:
H.� I 1 I I
-:I H1 �(I), H, � (: -:). -I I 0 I -I -1 .
-I -I I
We describe now a construction method for Hadamard matrices
using finite fields.
7.32. Theorem. Let a1, ... ,a, be the elements ofF,, q=3mod4,
and let � be the quadratic character of 'f ,. Then the matrix
-I b, b, b,,
b, -I b" b,,
H� b, b" -I b,,
b,, b,, b,, -I
with b,1 � �( a1-a,) for 1 � i, j � q. i * j, is a Hadamard matrix of order
q+l.
Proof Since all entries are ±I, it suffices to show that the inner
product of any two distinct rows is 0. The inner product of the first row
with the (i + l)st row, I" i" q, is
1+(-1)+ �>iJ� L �(a1-a,)� L �(c)�O
J""l J*l cEF;
by (5.12). The inner product of the (i + l)st row with the (k + l)st row,
I� i < k � q, is
3. Linear Modular Systems
1-bki-btk + L bi,bk1
j <#<I, k
�1-�(a,-a,)-�(a,-a,)+ L �(a1-a,h(a1-a,)
j""' i,k
�1-[1+�(-l)h(a,-a,)+ I: �((c-a,)(c-a,))�o.
cEFq 271
since �(-I)� -I for q"' 3 mod4 by Remark 5.13 and the last sum is -I
by Theorem 5.18. D
If H" is a Hadamard matrix of order n, then
( H" H")
H11 -H,
is one of order 2n. Therefore, Hadamard matrices of orders 2'(q +I) with
h;;. 0 and prime powers q"' 3mod4 can be obtained in this manner. By
starting from the Hadamard matrix H1 in Example 7.31, one can also obtain
Hadamard matrices of orders 2', h;;. 0.
3. LINEAR MODULAR SYSTEMS
System theory is a discipline that aims at providing a common abstract basis
and unified conceptual framework for studying the behavior of various
types and forms of systems. It is a collection of methods as well as special
techniques and algorithms for dealing with problems in system analysis,
synthesis, identification, optimization, and other areas. It is mainly the
mathematica l structure of a system that is of interest to a system theorist,
and not its physical form or area of applications, or whether a system is
electrical, mechanic al, economic, biological, chemical, and so on. What
matters to the theorist is whether it is linear or nonlinear, discrete-time or
continuous-time, deterministic or stochastic, discrete-state or continuous
state, and so on.
In the introduction to this chapter we gave an informal description
of systems. We present now a rigorous definition of finite-state systems,
which provide an idealized model for a large number of physical devices
and phenomena. Ideas and techniques developed for finite-state systems
have also been found useful in such diverse problems as the investigation of
human nervous activity, the analysis of English syntax, and the design of
digital computers.
7.33. Definition. A (complete, deterministic) finite-state system GJ1L is de
fined by the following:
(I) A finite, nonempty set U�{a1,a2, ... ,a,), called the input
272 Theoretical Applications of Finite Fields
alphabet of GJlL. An element of U is called an input symbol.
(2) A finite, nonempty set Y � (/J1, p,, ... ,/3.), called the output
alphabet of G)]L. An element of Y is called an output symbol.
(3) A finite, nonempty set S � ( a1, a2, ... , a,}, called the state set of
GJlL. An el ement of S is called a state.
(4) A next-state function f that maps the set of all ordered pairs
(a1, aj) into S.
(S) An output function g that maps the set of all ordered pairs
(a,aj) into Y.
A finite-state system G)1L can be interpreted as a device whose input,
output, and state at time I are denoted by u(t), y(t), and s(t), respectively,
where these variables are defined for integers t only and assume values
taken from U, Y, and S, respectively. Given the state and input of GJ1L at
time 1, f specifies the state at time I+ 1 and g the output at time 1:
s(t + 1) � f(s(t), u(t)).
y(t) � g(s(t), u(t)).
Linear modular systems constitute a special class of finite-state
systems, where the input and output alphabets and the state set carry the
structure of a vector space over a finite field F • and the next-state and
output functions are linear. Linear modular systems have found wide
applications in computer control circuitry, implementation of error-correct
ing codes, random number generation , and other digital tasks.
7.34. Definition. A linear modular system ( LMS) G)1L of order n over F • is
defined by the following:
(I) A k-dimensional vector space U over IF,. called input space of
GJlL, the el ements of which are called inputs and are written as
column vectors.
(2) An m-dimensional vector space Y over F •' called output space of
GJlL, the el ements of which are called outputs and are written as
column vectors.
(3) Ann-dimensional vector spaceS over IF,, called state space of
GJlL, the elements of which are called states and are written as
column vectors.
(4) Four characterizing matrices over F q:
A= (a;),p:n' B= (b;Jnxk'
The matrix A is called the characteristic matrix of G)1L.
3. Linear Modular Systems 273
(5) A rule relating the state at time 1 + l and output at time 1 to the
state and input at time 1:
s(t + l) � As(t)+ Bu(t),
y(t) �cs(t)+Du(t).
An LMS over IF • can be simulated by a switching circuit incorporat
ing adders, constant multipliers, and delay elements (compare with Chapter
6, Section I). It is convenient here to use adders summing also more than
two field el ements. Thus, an adder has two or more inputs
111 (I), u2 ( t), ... ,u,( I) E IFq
and a single output
y1(t)�u1(t)+u2(t)+ ··· +u,(t).
A constant multiplier with a constant a E F • has a single input u1 ( 1) E F • and
a single output y1(t) � au1(t). A delay element has a single input u1(t) E IF•
and a single output y1(t) � u1(t -l). Symbolically, these components are
represented as shown in Figure 7.4.
We describe now how we can obtain a realization of an LMS �as a
circuit simulating the operations of�:
l. Draw k input terminals labelled "•·····"k• m output terminals
labelled y" ... ,ym, and n delay elements, .. where the output of the
ith delay element iss,� s,( t) and its input iss;� s1( 1 + l).
2. Insert an adder in front of each output terminal y, and each
delay el ement.
3. The inputs to the adder associated with the i th delay element are
the si' each applied via a constant multiplier with constant a;1,
l .,; i, j.,; n, and the ui' each applied via a constant multiplier
with constant h;J' I" j" k.
Adder u2(1)
: : + y1(t)=u1(t)+u2(t)+···+u,(l) u1(t)�
Ur(t)
Constant Multiplier u1(1)� y1(t)=ou1(1)
Delay Element
FIGURE7.4 The building blocks of linear modular systems.
274 Theoretical Applications of Finite Fields
4. The inputs to the adder associated with the output terminal y1,
I � i � m, are the si' each applied via a constant multiplier with
constant c1J, I� j � n, and the ui, each applied via a constant
multiplier with constant d,i, I .;; j.;; k.
If we define
u(t) �
u, (y') (s' , y(t)� : , s(t)� : ,
Ym s" •('+')� [:;)
then the operation of the circuit represented in Figure 7.5 is precisely that
described in Definition 7.34(5).
7.35. Example. Let the characterizing matrices of a fourth-order LMS
over F3 be:
A� I� 2 0 0 �I. 0 2 I B� c� (� 0 2 6)' v�(n. I I 0 2 0
0 I I
Then its realization as a circuit is shown in Figure 7.6. D
���----------------------------------
�j-:��--------------------------,r--
u,----�------------------------�----
dij
�I
+ J!;
Ym
C;j
�I
�;
fJ
s,
FIGURE 7.5 The realization of an LMS as a switching circuit
3. Linear Modular Systems 275
u,-.�-------------------------------------------------,
---+ -- --��-1-1 ----,_+- --+- ---+_.-+-+ ----,_,_ __ r-t--s,
__ _. __________ +-�----��--+--- -+--�r-+----+-+---+� >--s,
--------------��----------._ __ _. __ ��t----t-4---+----s,
----------------�----------------------._ __ _. ____ _. ____ 5,
FIGURE 7.6 The switching circuit for Example 7.3�.
Conversely, we can describe an arbitrary switching circuit with a
finite number of adders, constant multipliers, and delay elements over IF q as
an LMS over IF• as follows (provided every closed loop contains at least one
delay element):
I. Locate in the given circuit all delay elements and all external
input and output terminals, and label them as in Figure 7.5.
2. Trace the paths from sj to s; and compute the product of the
multiplier constants encountered along each path and add the
products. Let a ij denote this sum.
3. Let b1j denote the correspond ing sum for the paths from u1 to
s;. cij for the paths from sJ toY;· d;j for the paths from u1 toY;·
Then the circuit is the realization of an LMS over F q with characterizing
matrices A, B, C, D.
The states and the outputs of an LMS depend on the initial state s(O)
and the sequence of inputs u(t), I= 0,1, .... The dependence on these data
can be expressed explicitly.
7.36. 17teorem (General Response Formula). For an LMS with
characterizing matrices A, B, C, D we have:
1-1
li) s(t)=A's(O)+ L A'-'-1Bu(i) fort=l,2, ... ,
;-o
(ii) y(t)=CA's(O)+ L H(t-i)u(i) fort=O,l, ... ,
i-0
276 Theoretical Applications of Finite Fields
where
if I� 0,
if I " I.
Proof (i) Let 1 � 0 in Definition 7.34(5), then
s( I) � As(O) + Bu(O),
which proves (i) for 1 � 1. Assume (i) is true for some 1" I, then
( 1-1 ) s(1 +I)� A A's(O)+ 1�0 A'_1_1Bu(i) + Bu(1)
proves (i) for 1 + 1. �A'•'s(O)+ L A'-'Bu(i)
i=O
(ii) By (i) and Definition 7.34(5) we have
y(1) �c(A's(O)+ 'f.' A'-1-1Bu(i))+Du(1)
.-o
�CA's(O)+ L H(l-i)u(i),
;-o
where H(l-i) � CA'_,_,B when 1-i" I and H(1-i) � D when 1-i � 0.
D
By Theorem 7.36(ii) we can decompose the output of an LMS into
two components, the free component
y( I )1= � CA's(O)
obtained in case u( 1) � 0 for all I " 0, and the forced component
y(l)ro""' � L H(l-i)u(i) i-0
obtained by setting s(O) � 0. Given any input sequence u( 1 ), 1 � 0, I, ... , and
an initial state s(O), these two components can be found separately and then
added up.
In the remainder of this section we study the states of an LMS in the
input-free case-that is, when 11(1) � 0 for all I" 0. Some simple graph-
3. Linear Modular Systems 277
theoretic language will be useful. Given an LMS GJ1L of order 11 over IF • with
characteristic matrix A, the state graph of GJ!L, or of A, is an oriented graph
with q" vertices, one for each possible state of GJ!L. An arrow points from
state s1 to state s2 if and only if s2 � As1• In this case we say that s1 leads to
s2. A path of length r in a state graph is a sequence of r arrows b1,b2, ... ,b,
and r+l vertices v1,v2, ... ,vr+l such that b; points from V; to V;+b i=
1,2, ... ,r. If the v1 are distinct except v,+1 � v1, the path is called a cycle of
length r. If v1 is the only vertex leading to v1 + 1, i � I, 2, ... , r -I, and the
only vertex leading to v 1 is v, then the cycle is called a pure cycle. For
example, a pure cycle of length 8 is given as shown in Figure 7.7.
The order of a given state s is the least positive integer t such that
A's � s. Thus, the order of s is the length of the cycle which inciudes s. In
the following, let A be nonsingu lar-that is, det(A) "'0. It is clear that in
this case the corresponding state graph consists of pure cycles only. The
order of the characteristic matrix A is the least positive integer 1 such that
A'� I, the n X n identity matrix.
7.37. Lemma. If 11 , ••• , t x are the orders of the possible states of an
LMS with nonsingular characteristic matrix A, then the order of A is
lcm(t1, ... ,1x ).
Proof Let 1 be the order of A and t' � lcm(t1, ... ,1x ). Since A 's � s
for every s, t must be a multiple oft'. Also, (A'"-/)s � 0 for all s, hence
A'"� I. Thus t';. t, and therefore 1 � t'. D
7.38. Lemma. If A has the form
A� ( �� ;,)
with square matrices A1 and A2, and (:) and ( :1) are two states, partitioned
according to the partition of A, with orders 11 and t2, respectively, then the
orderofs�(::) is lcm(t1,t2).
Proof This follows immediately from the fact that A'(::)� ( ::) if
and only if A\s1 � s1 and A�s2 � s2. D
FIGURE 7.7 A pure cycle of length 8.
278 Theoretical Applications of Finite Fields
Let GJlt be an LMS with nonsingular characteristic matrix A. Up to
isomorphisms (i.e., one-to-one and onto mappings T such that T(s1) leads to
T(s2) whenever s1 leads to s2) the state graph of GJlt is characteri zed by the
formal sum
which indicates that n1 is the number of cycles of length 11. E is called the
cycle sum of GJlt, or of A, and each ordered pair (n1, t,) is called a cycle term.
Cycle terms are assumed to commute with respect to +, and we observe the
convention ( n', t) + (n", t) � (n' + n", 1).
Consider a matrix A of the form
with square matrices A1 and A2, and suppose the state graph of A1 has n1
cycles of length 11, i�l ,2. Hence there are n111 states of the form(�) of
order 11, and n212 states of the form ( :,) of order 12. By Lemma 7.38 the
state graph of A must contain n1n21112 states of order lcm(11, 12) and hence
n 1n21,t,/lcm( 11, 12) � n1 n2 gcd( t,. 12)
cycles of length lcm(t1, 12).
The product of two cycle terms is the cycle term defined by
(n1, 11)·(n2, 12) � (n1n2 gcd(11, 12), lcm(11, 12)).
The product of two cycle sums is defined as the formal sum of all possible
products of cycle terms from the two given cycle sums. In other words, the
product is calculated by the distributive law.
7.39. Theorem If
A� ( �� �,)
and the cycle sums of A, and A2 are E, and E2, respectively, then the cycle sum
of A is E1E2•
Our aim is to give a procedure for computin g the cycle sum of an
LMS over IF• with nonsingular character istic matrix A. We need some basic
facts about matrices. The characteristic polynomial of a square matrix M
over F• is defined by det(x/-M). The minimal polynomial m(x) of M is
the monic polynomial over F• of least degree such that m(M) � 0, the zero
matrix. For a monic polynomial
g(x)�x*+a,_,x*-'+ ··· +a,x+a0
3. Linear Modular Systems 279
over F q• its companion matrix is given by
0 0 0 0 -ao
0 0 0 -a,
M(g(x)) � 0 0 0 -a,
0 0 0 -ak-1
Then g(x) is the characteristic polynomial and the minimal polynomial of
M(g(x)).
Let M be a square matrix over IF q with the monic elementary divisors
g,(x), ... ,g,(x). Then the product g1(x) · · · gw(x) is equal to the character
istic polynomial of M, and M is similar to
M*= M(g,(x)) 0
0 M(g,(x))
0 0 0
0
M(g,(x))
that is, M = p-l M*P for some nonsingular matrix P over g: q· The matrix
M* is called the rational canonical form of M and the submatrices M(g,(x))
are called the elementary blocks of M*.
Now let the nonsingular matrix A be the characteristic matrix of an
LMS over IF q· For the purpose of computing its cycle sum, A can be
replaced by a similar matrix. Thus, we consider the rational canonical form
A• of A. Extending Theorem 7.39 by induction, we obtain the following. Let
g1(x), ... ,g,.(x) be the monic elementary divisors of A and let I:, be the
cycle sum of the companion matrix M(g,(x)); then the cycle sum L of A•,
and so of A, is given by
Let the characteristic polynomial f(x) of A have the canonical
factorization
'
j(x) � n pj(x)'l,
j-1
where the P/ x) are distinct monic irreducible polynomials over IF q· Then
the elementary divisors of A are of the form
( ),,, ( )''' ( )''' pi X , pi X , ... ,pi X I, j=l,2, ... ,r,
where
280 Theoretical Applications of Finite Fields
The minimal polynomial of A is equal to
m(x) � n P,(x)'''.
j=!
It remains to consider the question of determining the cycle sum of a
typical elementary block M(g,(x)) of A*, where g,(x) is of the form p(x)'
for some monic irreducible factor p(x) of f(x). The following result
provides the required information.
7.40. Theorem. Let p(x) be a monic irreducible polynomial over F•
of degree d and lett, � ord( p(x)'). Then the cycle sum of M(p(x)') is given
by
. ( q'-I ) . ( q'"- q" ) . . ( q'" _ q<•-'>" ) (1,1)+-t-,-,t,+ t, ,t,+···+ t, ,t,.
In summary, we obtain the following procedure for determining the
cycle sum of an LMS GJlt over IF• with nonsingular characteristic matrix A:
Cl. Find the elementary divisors of A, say g1(x), ... ,gw(x).
C2. Let g,(x) � f,(x)m', where /;(x) is monic and irreducible over
F •. Find the orders ti'' � ord(/,(x)).
C3. Evaluate the orders tl'1�ord(/;(x)') for i�l,2, ... ,w and
h�I,2, ... ,m, by the formula tl''�t}'1p'•, where pis the
characteristic of F • and c, is the least integer such that p'•;;,. h
(see Theorem 3.8).
C4. Determine the cycle sum [,of M(g,(x)) for i�l,2, ... ,w
according to Theorem 7.40.
C5. The cycle sum L of GJlt is given by L � L 1 L 2 · · • L ...
7.41. Example. Let the characteristic matrix of an LMS GJlt over F2 be
given as
Here 0 0
I 0
A� 0 I
0 0
0 0 I 0
I 0
I 0
0 0
0 I 0
0
0
I
I
g1(x)�x'+x2+x+I� (x+I)3, f1(x)�x+I, m1�3,
g2(x)�x2+x+I , f2(x)�x2+x+I . m2�1.
Steps C2 and C3 yield ti" �I. tl" � 2. tl11 � 4, ti21 � 3. Hence by Theorem
4. Pseudorandom Sequences
7.40,
and so L I� (1, 1)+(1, 1)+(1,2)+(1,4) � (2, 1)+(1,2)+ (1,4),
I:,� (1, 1)+(1,3),
L � L I L2 � [(2, 1) + (1 ,2)+ (1' 4)][(1' 1) + (1 ,3)]
� (2, 1)+ (1 ,2) + (2,3)+ (1 ,4)+ (1,6) + (1' 12). 281
Thus the state graph of 'JlL consists of two cycles of length 1, one cycle of
length 2, two cycles of length 3, and one cycle each of length 4, 6, and 12. 0
From C5 it follows that the state orders realizable by 'J1L are given by
lcm(t<l) 1(2) /(w)) h 1 ' h1 '• • •' h.,
for every combination of integers h1, ••• ,h...,, 0 .:s;; h; .:s;; m;. If one wishes to
compute all possible state orders realizable by 'JJL, without computing its
cycle sum, one uses the following theorem.
7.42. Theorem. Let 'JlL be an LMS with nonsingular characteristic
matrix A. Let the canonical factorization .of the minimal polynomial of A be
m (X) � pI (X) b, · · · p, (X) b,
and let tlj 1 � ord( P/ x )' ). Then the state orders realizable by 'JlL are given by
all the integers of the form
4. PSEUDORANDOM SEQUENCES
The notion of a random sequence of events is basic in probability theory and
statistics. Let us take a standard model for the description of this notion.
Consider an experiment in which an unbiased coin is flipped repeatedly. Mark
down 0 for heads and 1 for tails. The result of this experiment is then a
sequence of binary digits (or bits in the parlance of computer science) which
will display typieal features of randomness. For instance, the relative
frequency of each bit will approach !in the long run, and the relative frequency
of two successive O's (or of two successive l's) will approach± in the long run.
More generally, for any given block of m bits the relative frequency of this
block among all the blocks of m successive bits in the sequence will approach
282 Theoretical Applications of Finite Fields
rm in the long run. In short, the sequence can be expected to have all the
statistical properties satisfied by a sequence of independent random variables
which attain each value 0 and I with probability t.
Flipping coins is thus not just an idle pastime, but can serve as a
method for generating random sequences of bits. Since there is no guarantee
that our coin is truly unbiased, the generated sequence should be subjected to
tests for randomness. For instance, we may check the statistical quantities
mentioned above-namely, the relative frequency of each bit (distribution test)
and the relative frequency ofblocks of bits (serial test). Another popular test for
randomness is the correlation test, which is based on the calculation of the
correlation coejf JCients
N-1
CN(h) = L (-!)'·-··+> (7.6)
n=O
of the given sequence s0, s,, ... of bits for positive integers N and h. The
correlation coefficient CN(h) can be interpreted as follows: write the shifted
sequence sh, s"+ 1, ... underneath the original sequence and count the agree
ments and disagreements among the first N corresponding terms; then CN(h) is
equal to the number of agreements minus the number of disagreements. For a
random sequence of bits CN(h) should be relatively small compared to N.
Random sequences of bits are used frequently for simulation purposes,
for various applications in electrical engineering, and also in cryptography (see
Chapter 9, Section 2). In practice, the generation of such sequences by coin
flipping or similar physical means is problematic. First of all, the practical
applications require long strings of bits, and the physical generation of all
those bits may simply take too long. Furthermore, it is an established
principle that scientific calculations have to be reproducible and verifiable,
and this means that all the bits used in a calculation must be stored for later
recall. This may tie up a lot of the computer's memory capacity. In many
applications it is therefore preferable to work with sequences of bits that can be
generated directly in the computer. Since the computer only responds to
deterministic programs, the resulting sequences will not be random. However,
we can try to generate deterministic sequences of bits that pass various tests for
randomness. Such deterministic sequences are called pseudorandom sequences
of bits.
A commonly employed method of generating pseudorandom se
quences of bits is based on the use of suitable linear recurrence relations in the
finite field IF1. The sequences that one generates are the maximal period
sequences introduced in Chapter 6. We will show that-with certain
qualifications-maximal period sequences in IF2 pass the tests for randomness
described above-namely, the distribution test, the serial test, and the
correlation test. Since there is no extra effort involved, we will establish the
relevant facts for maximal period sequences in an arbitrary finite field IF,. We
are thus dealing with pseudorandom sequences of elements of IF,.
4. Pseudorandom Sequences 283
We recall from Chapter 6 that a kth-order maximal period sequence in
IF q is a sequence s0, s1, ... of elements of IF q generated by a linear recurrence
relation
Sn+k=ak-1sn+k-1 +···+a0S11 for n=O,l, ... , (7.7)
for which the characteristic polynomial x" -a"_ 1 x"-1 -· · · -a0 is a primitive
polynomial over �, and not all initial values s0, .•. , s, _1 are 0. A kth-order
maximal period sequence is periodic with least period r = q'-I (see
Theorem 6.33). A requirement we have to impose is that r be very large, say at
least as large as the total number of pseudorandom elements ofF, to be used in
the specific application. In this way the periodicity of the sequence-which is a
distinctly nonrandom feature-will not come into play. With this proviso we
will now investigate the performance of maximal period sequences under tests
for randomness. The distribution test and the serial test can be treated
simultaneously. For b = (b1, ... , bm)E�; let Z(b) be the number of n,
0 � n � r-1, such that S11+1_1 = b1 for 1 � i � rn. The case m = 1 corresponds
to the distribution test and was already dealt with on p. 240. The case of an
m ;;, 2 corresponds to the serial test for blocks of length m. The following
result shows that Z(b) is close to the ideal number rq-m provided that m is
not too large.
7.43. Theorem. Ifl"i;; m,;; k and bE�;, then for any kth-order maximal
period sequence in IF q we have
_ {q"-m...: I forb= 0, Z(b)-•-m fi b ·o q or # .
Proof. Since r=q"-1, the state vectors s0, s1, ... ,s,_1 of the se
quence run exactly through all nonzero vectors in �;.Therefore Z(b) is equal
to the number of nonzero vectors SEf: that have b as the m-tuple of their
first m coordinates. For b # 0 we can have all possible combinations of
elements off, in the remaining k-m coordinates of s, so that Z(b) = q•-m.
For b = 0 we have to exclude the possibility that all the remaining k-m
coordinates of s are 0, hence Z(b) = q'-m-I.
Theorem 6.85 shows that parts of the period of a maximal period
sequence also perform well under the distribution test. We now turn to the
correlation test for a maximal period sequence s0, s1, ... in IF q· We first extend
the definition of correlation coefficients in (7.6) to the general case. Let x be a
fixed nontrivial additive character off, (compare with Chapter 5, Section I)
and set
N-1
CN(h) = L x(s.-s.+.l (7.8)
11=0
for positive integers N and h. For q = 2 this definition reduces to (7.6) since
284 Theoretical Applications of Finite Fields
there is only one nontrivial additive character of �2 and it is given by
x(O) =I, x(l) = -I. In the case N = r we can give explicit formulas for the
correlation coefficients.
7.44. Theorem. For any maximal period sequence in �. with least
period r we have
if h = 0 mod r,
if h ¢0 mod r.
Proof. If h = 0 mod r, then s, = s,+, for all n;. 0 and the result follows
immediately from (7.8). If h ¢ 0 mod r, then u,-s, +h• n = 0, I, ... , defines
a sequence satisfying the same linear recurrence relation as s0,s1, .... By
Lemma 6.4. u0, u 1, ... cannot be the zero sequence, and so it is again a maximal
period sequence in� •. Applying Theorem 7.43 with m =I to this sequence, we
get
r-1 r-1
C,(h)= L x(s,-s,+>)= L x(u,)=(q'-1-l)x(O)+q'-1 L x(b)
n=O n=O bE�:
=-l+q'-1 LX(b)=-1,
where we used (5.9) in the last step. D
7.45. Example. Consider the linear recurring sequence s0,s1 , ... in �2 with
s,+5 = 511+2 + 511 for n = 0, 1,... and initial values s0 = s2 = s4 = 1,
s1 = s3 = 0. Since x5-x2- 1 is a primitive polynomial over IF2, this sequence
is a maximal period sequence in �2 with least period r = 25-I= 31. Write
down the 31 bits making up the period of the sequence and underneath the
first 31 terms of the sequence shifted by h = 3 terms to the left:
I 0 I 0 I 0 0 0 0 I 0 0 I 0 I I 0 0 I I I I I 0 0 0 I I 0 I
0 I 0 0 0 0 I 0 0 I 0 I I 0 0 I I I I I 0 0 0 I I 0 I I I 0
The number of agreements of corresponding terms is 15, the number of
disagreements is 16, hence C31(3) = 15- 16 =-I, in accordance with
Theorem 7.44.1fwe consider the pairs (s,s,+ 1), n = 0, I, ... , 30, then there are
7 of type (0,0) and 8 each of type (0, 1), (1,0), and (I, 1), in accordance with
Theorem 7.43. D
For N < r we can give bounds for the correlation coefficients CN(h), and
in the trivial case h = 0 mod r we have an explicit formula.
7.46. Theorem. For any kth-order maximal period sequence in �.and
I ,;;, N < r = q'-1 we have
4. Pseudorandom Sequences
and
ICN(h)l«/12 -logr+-+- if h¢0modr. (2 2 N)
" 5 r 285
Proof We proceed as in the proof of Theorem 7.44. If h = 0 mod r,
then Un = Sn-Sn+h = 0 for all n � 0 and SO
N-1
CN(h) = L x(u,) = N.
n=O
lfh¢0modr, then u0, u1, ... is a kth-order maximal period sequence in�.
and so
by Theorem 6.81, since n0 = 0 and R = r in this case. 0
If we take every second term of a random sequence of elements ofiFq, we
would expect that the resulting subsequence has again randomness properties.
More generally, the property of being a random sequence should be invariant
under the operations of decimation defined as follows. If CJ is a given sequence
s0,s1,s2, ... of elements of Fq and d� 1 and h"?-0 are integers, then the
decimated sequence �hl has the terms sh, sh+tJ• sh+U• .... In other words, �hl is
obtained by taking every dth term of CJ, starting from s,. The following result
shows that the property of being a maximal period sequence in �.is invariant
under many decimations. This can be viewed as further evidence that maximal
period sequences are good candidates for pseudorandom sequences.
7.47. Theorem. Let CJ be a given kth-order maximal period sequence
in � •. Then CJI'' is a kth-order maximal period sequence in �.if and only if
gcd (d, q'-1) = 1, and CJI'' is a maximal period sequence in �,satisfying the same
linear recurrence relation as CI(or, equivalentl y, CJI'' is a shifted version of CI) if
and only if d = qimod (q'-1) for some j with 0 .;,j,;, k-1.
Proof. Denote the terms of CJ and CJI'' by s, and u, respectively. The
minimal polynomial of CJ is a primitive polynomial f(x) over K =�.of degree
k. If� is a fixed root of f(x) in F =� ••• then� is a primitive element ofF (see
Definition 3.15). By Theorem 6.24 there is a unique OEF* such that
s, = Tr,1K(OIX") for all n;;. 0.
It follows that
u, = s .. ,, = Tr,1"(fl(ct')') for all n;;. 0,
where fJ = O�EF*. Let f,(x) be the minimal polynomial of ex' over K. Then the
calculation in the proof of Theorem 6.24 shows that �•> is a linear recurring
sequence with characteristic polynomial f,(x). Ifgcd(d, q'-1) = 1, then ex' is a
286 Theoretical Applications of Finite Fields
primitive element ofF, and so f4(x) is a primitive polynomial over K of degree
k. Since f3 # 0, not all u, are 0, thus ul"' is a kth-order maximal period sequence
in f,. If gcd(d,q" -1) > 1, then rl is not a primitive element ofF, and sou<,'>
cannot be a kth-order maximal period sequence in f ,. The first part of the
theorem is thus shown.
Furthermore, u�hl is a maximal period sequence in [F4 satisfying the
same linear recurrence relation as u if and only if f4(x) = f(x). By Theorem
2.14, this identity holds if and only if rl = a."1, hence d = qj mod (q'-1), for
some j with 0 .;; j .;; k-1. Since the state vectors of u run through all nonzero
vectors in IF:. the maximal period sequences in IF4 satisfying the same linear
recurrence relation as u are exactly the shifted versions of u. D
Maximal period sequences possess a universality property, in the sense
that a much larger class oflinear recurring sequences can be derived from them
by applying decimations.
7.48. Theorem. Let u be a given kth-order maximal period sequence
in IF4. Then every linear recurring sequence in iF4 having an irreducible minimal
polynomial g(x) with g(O) # 0 and deg(g(x)) dividing k can be obtained from u
by applying a suitable decimation.
Proof. If the terms of u are denoted by s, then as in the proof of
Theorem 7.47 we have
s, = Tr,1K(O�') for all n;. 0,
where a: is a primitive element ofF= IF q-'<• OEF*, and K = IF4. Let u0, Up ... be a
linear recurring sequence in f, with irreducible minimal polynomial g(x),
where g(O) # 0 and m = deg(g(x)) divides k. Then g(x) has a root yEE = f,-,
and y # 0 since g(O) # 0. Furthermore, E is a subfield ofF by Theorem 2.6. It
follows that there exists an integer d;. l such that y = rl. By Theorem 6.24 we
have
u, = Tr,1K(f3y') for all n;. 0,
where f3 E E*. Let liEF* be such that Tr,1,(<5) = {3, and choose an integer h;. 0
with /i0-1 =�•. Then by the transitivity of the trace (see Theorem 2.26) we
have
sh+,, = Tr,1K(e�"+"'l = Tr,1K(Iiy') = TrEIK(Tr,1 ,(1iy'))
= Tr,1K(/3y') = u,
for all n � 0, and so the sequence u0, u1, ... is equal to the decimated sequence
�- 0
The condition g(O) # 0 in Theorem 7.48 rules out the case g(x) = x in
which the sequence has the form c, 0, 0, ... with cEf:. Such a sequence has
preperiod l, and thus it cannot be derived from u by a decimation since
every decimated sequence u�h) is periodic.
4. Pseudorandom Sequences 287
In the special case d = 1 we write u�l = <f'l, which is the sequence
obtained by shifting u by h terms. Maximal period sequences can be
characterized in terms of a structural property of the set of all shifted
sequences. We use again the termwise operations for sequences introduced in
Chapter 6, Section 5.
7.49. Theorem. If u is a nonzero periodic sequence of elements of'F,,
then the shifted sequences <f'l,h = 0, 1, ... , together with the zero sequence form a
vector space over F q under termwise operations for sequences if and only if u is a
maximal period sequence in F q·
Proof. If u is a kth-order maximal period sequence in 'f,, then the
initial state vectors of the sequences u<•l, h = 0, 1, ... , q'� 2, and of the zero
sequence run exactly through all vectors in 'f:. From this it follows easily that
these sequences form a vector space over f,. Note also that any shifted
sequence <f'l, h;;. 0, is identical to one with 0..; h..; q' � 2.
Conversely, if u is a nonzero periodic sequence of elements of 'f, with
least period r, then the distinct shifted sequences are u = u<0l, u<•l, ... , .,-(•-•l. If
these together with the zero sequence form a vector space V over 'f ,, then Vis
closed under shifts of sequences, and so Theorem 6.56 shows that V = S(.f(x))
for some monic polynomial f(x)e'f,[x] of degree k;;. 1. Counting the number
of elements of Vin two different ways we get r +I= q', hence u is a kth-order
linear recurring sequence in 'f, with least period r = q'� 1. In particular, the
state vectors of u run through all nonzero vectors in 'f:, and so some u<•l is the
impulse response sequence with characteristic polynomial f(x). Theorem 6.27
implies that ord (f(x)) = r = q'� 1. If we had f(O) = 0, then a0 = 0 in (7.7) and
the sequence in S(f(x)) with initial values 1, 0, ... , 0 has all subsequent terms
equal to 0; but this nonperiodic sequence cannot belong to V, a contradiction.
Thus f(O) ,< 0, and so f(x) is a primitive polynomial over 'f, by Theorem 3.16.
Consequently, u is a maximal period sequence in 'f,. D
7.50. Example. Let u be the linear recurring sequence s0,s1, ... in 'f2
withsn+4= sn+l + sn for n =0,1, ... and initial values s0 =s1 =s2 =0, s3 = 1.
Since x• � x � 1 is a primitive polynomial over 'f2, u is a maximal period
sequence in 'f2 with least period r = 24 � 1 = 15. The 15 bits making up the
period of u are
000 10011 0101 111.
As an illustration of Theorem 7.48 we derive all the linear recurring sequences in
'f2 having an irreducible minimal polynomial g(x) ,< x with deg(g(x)) = 1 or 2
by applying a suitable decimation to u. The constant sequence 1, 1, 1, .. .
( = u\'l) has minimal polynomial x� 1, and the periodic sequences 0, 1, 1, .. .
( = u�'l), 1, 0, 1, ... ( = u�'l), and 1, 1, 0, ... ( = u�6l) with least period 3 represent
all the linear recurring sequences in 'f 2 with minimal polynomial x2 � x � 1. As
an illustration of Theorem 7.49 we note that u + u"l must be either a shifted
288 Theoretical Applications of Finite Fields
version of a or the zero sequence, and in fact a+ at3l = a04'. On the other
hand, if t is the linear recurring sequence t0,t1, ..• in IF2 with t,+4 =
t,+3 + t, + 1 + t,+ 1 + t, for n = 0, 1, ... and initial values t0 = t 1 = t 2 = 0, t3 = 1,
then r is the periodic sequence 0, 0, 0, I, I, ... with least period 5 and r + r''' is
neither a shifted version oft nor the zero sequence. This is again in accordance
with Theorem 7.49 since r is not a maximal period sequence in f2. 0
For many simulation purposes, and especially for applications in
numerical analysis, one needs random sequences of real numbers. These
numbers should all belong to a given interval on the real line, which for
simplicity we may take to be the interval [0, 1]. The generation of a random
sequence of numbers in [0, I] can again be described by a statistical
experiment. Pick a number from [0, I] at random, where the probability that
the number belongs to a specific subinterval of [0, I] should be equal to the
length of the subinterval. Repeat this procedure indefinitely, with each
selection being statistically independent of all the previous ones. Since we are
using here a special probability distribution giving equal likelihood to
subintervals of the same length, one often speaks of the resulting sequence as a
sequence of unifonn random numbers. The notion of a sequence of uniform
random numbers is an idealized concept, and in practice one works with a
deterministic analog called a sequence of uniform pseudorandom numbers. Such
a sequence is generated by a deterministic method and should pass various
tests for randomness. The advantages of such a sequence are similar to those of
a pseudorandom sequence of bits described earlier.
Maximal period sequences in finite fields can be used to generate
sequences of uniform pseudorandom numbers. Let �,be a finite prime field
that is, pis prime-and let s0, s,. ... be a kth-order maximal period sequence in
�,.In the following we view the terms s, of the sequence as integers with 0.;; s,
< p. The integers s, have to be transformed into numbers in [0,1]. One
method of doing this is the normalization method, in which one chooses p to be
a large prime and normalizes s, by setting
s,
w, �-E[O, I] for all n;;, 0. p
Then w0, wl·· .. is taken as a sequence of uniform pseudorandom numbers.
Clearly, this sequence is periodic with least period r � p'-I. Since the
sequence w0, w1, ... differs from the sequence s0, s1, ... only by a constant
factor, the statistical properties of the two sequences will essentially be the
same. Thus it suffices to refer to our earlier discussion of statistical properties
of maximal period sequences.
A second method of transforming the integers s, into numbers in [0, I]
is the digital (or Tausworthe) method. Here we let p be a small prime and we
choose an integer m � 1. Then we set
m
"' -' w, = L. Smn+t-lP
i=l for all n ;;, 0, (7.9)
4. Pseudorandom Sequences 289
and we use w0, w1, ... as a sequence of uniform pseudorandom numbers. The
formula (7.9) means that the sequence s0, s1, ... is split up into blocks oflength
m, and each block is interpreted as the digital representation in the base p of a
number in [0, 1]. In practice one usually works with the prime p = 2, since this
facilitates the calculation of the terms s, by the relation (7. 7) and since in this
case we get the numbers w, in their binary representation which is well suited
for computer calculations.
7.51. Lemma. The sequence w0, w1, ... of numbers defined by (7.9) is
periodic with least period
p' -1 r---'--�-gcd(m, p'-1)"
Proof Since mr is a multiple of p'- 1 and thus a period of the
maximal period sequence s0,s1, ... , we have
m m "' _, "' _, w,.+,= LJ Smn+i-1+'"'P = LJ Smn+i-1P = w,.
i= 1 j= 1 for all n�O.
Therefore w0, w1, ... is periodic with period r. Now let u be an arbitrary period
of this sequence. Then w,.+u = w,. for all n � 0, hence
m m
L Smn+l-1+muP-1= L Smn+l-1P-i for all n �0.
i= 1 i= 1
The uniqueness of digital represent ations implies that
Smn+i- 1+mu=smn+l-1 for l<.i�m and all n�O.
Now mn + i-1 runs through all nonnegative integers ifi and n run through all
integers with 1 � i � m and n � 0, thus
s,.+mu = s,. for all n � 0.
This means that mu is a period of the sequence s0, s 1, ... , and so p' -1 divides
mu. It follows that r divides u, and therefore r is the least period of the sequence
w0, w1,.... 0
In order to make the least period of the sequence w0, w 1, ... as large as
possible, we will choose the block length min such a way that gcd(m,p'-1)
= 1. The least period of the sequence is then equal top'-1 by Lemma 7.51. If
we want to make this least period large for p = 2, then k should not be chosen
too small. We note also that ifm > k, then the last m-k digits of any w, depend
on the first k digits on account of the relation (7.7). Therefore we impose the
condition m .;; k in order to prevent such obvious dependencies.
An important test for randomness for a sequence w0, w1, ... of uniform
pseudorandom numbers is the uniformity test. We start from the observation
that in the ideal case of a sequence x0, x1, ... of uniform random numbers the
290 Theoretical Applications of Finite Fields
probability that the inequality x,.; tis satisfied for a given tE [0, 1] is equal to
t. We compare this with the elementary probability PN(t) that the inequality
W11 �tis satisfied among the first N terms of the given sequence w0, w1,. .. -
that is, PN(t) is N-1 times the number of n, 0.; n < N, with w,.; t. The largest
deviation
(7.1 0)
O'"t<Stl
between these two probabilities provides a way of measuring the extent to
which w0,w1, ... differs from a sequence of uniform random numbers. For a
"good" sequence of uniform pseudorandom numbers the value of DN should
be small for large N. When applying the uniformity test to a periodic sequence
w0, w 1, •.. with least period r, it suffices to consider the case 1 :s; N � r since the
behavior of the sequence repeats itself beyond the period.
7.52. Theorem. If m.; k and gcd(m, p'-!) = 1, then the sequence
w0, w1,... of uniform pseudorandom numbers generated by (7.9) satisfies
D,=p-m with r=pk-l.
Proof Theleast period ofw0, w1, ... isr = p' -1 by Lemma 7.51. The
sequence of m-tuples
sn = (s,l, sn+ 1• ... ,Sn+m-1 ), n = 0, I, ... '
also has least period r; in other words, s, just depends on the residue class of
n modulo r. From gcd(m, r) = 1 it follows then that the finite sequence
smn• n = 0, 1, ... , r-I, is a rearrangement of the finite sequence sn, n = 0,
1, ... ,1·-l. In particular, for any bE{0,1, ... ,p-l}m the number of n,
0 � n � r-I, with smn = b is the same as the number of n, 0 � n � r-1, with
s, =b. The latter number is given by Theorem 7.43. Together with (7.9) this
yields the following information: the number of n, 0.; n.; r-1, with
W11 = 0 is equal to pk-m-I, and for any rational number cp-m with
cElL, I � c < p'", the number of n, 0 � n � r-1, with W11 = cp-"' is equal to
pk-m; this exhausts all possible values of W11• For a ElL, 0 �a< p"', consider a
real t with ap-m.;t<(a+ 1)p-m. Then
and so
Now 1 P,(t) = -(pk-m-1 + ap'-m), r
a+ 1 1 0< ---t�-p"' p'"
4. Pseudorandom Sequences
and
hence
Since 0 1-(a+ l)p-m 1-p-m
.;; 't .;;,! p- p-I p"-1 I
_. __ ,:: _ p'" pk.- I -...;:; pm'
and P,(l) = I, it follows from (7.10) that D, = p -m. 291
0
Theorem 7.52 shows that if m is chosen sufficiently large, then the
sequence w0, w1, ... passes the uniformity test when considered over the full
period. For parts of the period-that is, for I .;; N < r-we can establish an
upper bound for the quantity DN in (7.10). Let w0, w1, ... be a sequence of
elements of [0, I] whose terms are given by finite digital representations
m
W-' cn-i n-01 "-L. wP p ' -, ' ... ' 1=1 (7.11)
where the digits w�" belong to the set {0, I, .... p-I} and m is independent
of n. For h EZ we define e,(h) = e(h/p), where e(t) is the complex exponential
function used in Chapter 6, Section 7:
7.53. Lemma. Let w0,w1, ... be a sequence of elements of [0, I]
given by (7.11) and let N be a positive integer. Let B be a constant such that
for any h1, ••• , hmE{O, I, ... , p-I} that are not all 0 we have
II N-1 I -" e (h wC11 + .. · + h w1"1) "' B
NL.p ln mn-...;:; n=o
Then the quantity DN in (7.10) satisfies
I (2 7) DN .;; - + Bm -Iogp +-. p" " 5
Proof For 0.;; t <I let
00
r = L tjp-i 1=1 (7.12)
be the digital representation oft in the base p, with t, E {0, I, ... , p-I} for all
i;;. I and the usual condition that t1 <p-I for infinitely many i. Then we have
w,�t if and only if w�11=t1, ... ,w�-11=ti-l• w�0<t1 for some i with
1 � i � m-1 (for i = I the condition reduces to w�u < t d or w:/ 1 =
t1, ... ,w:;"-11=tm-I• w�m)�l111• Thus, if we put u1=ti-I for l�i�m-1
292 Theoretical Applic- .ttions of Finite Fields
and um = tm and interpret empty sums to be equal to 0, then
1 m u; N-1 PN(t)= N ,f:1 1f:0 Jo d,,(w;1')· .. (d,,_,(w�-1')diw�'),
where d/w) = 1 for j = w and d1(w) = 0 for j # w with j, wE{O, 1, ... , p -1).
Now
and so tp-1
d/w) =-L e,(h(w-j)), Ph=O
·e,(-h1t1-···- h1_1t1_1-h1j).
Separating the contribution from the choice h1 = · · · = h1 = 0 in the inner sum
and denoting by an asterisk the deletion of the corresponding term, we get
Using m U· + 1 m 1 p-1 PN(t)= L -'
-,-+ L--; L e,(-h1t1-···-h,_1t1_1)
i=l P i"'lP hJ ••••• h;=O
1 N-1 u;
·-L e (h w1" + · · · + h.w"') L e (-hJ) N n=O p 1 n I n j=O p .
I f: U; � 1 -t I ,; _!,.
i=l p p
and the condition (7.12), we obtain
IPN(t)-tl,; _!,. + B t � I;_ It e,(hJ)I p 1-1 p hJ ..... hj-0 J-0
1 m 1 p-1 I .. I ,;Pm+B,f:1pr ,,, .. �,�o ;f:o e,(hj).
=.,+-L L L e,(hj). 1 B m p-11 "' I p p i=l h=O )=0
By Lemma 6.80 we have
and so L L e,(hj) <-plogp+-p+u1+1 ,;-plogp+-p, ,-1 I .. I 2 2 2 7
h=Oj=O 1t 5 7t 5
IPN(t)-tl,; _1_ + Bm(�logp + �) pm 7t 5 for 0,; t < 1.
Since PN(1) = 1, the desired result follows. D
4. Pseudorandom Sequences 293
7.54. Theorem. Let m .;; k and gcd(m, p' -!) � I, and let w0, w1, ... be
the sequence of uniform pseudorandom numbers generated by (1.9). Then for
I ,;; N < r � p'-l the quantity DN in (7.10) satisfies
I mp'l2 (2 2 N)(2 7) DN.;;-+ ---logr+-+--logp+-5 . pmNn 5rn
Proof The bound for DN is obtained from Lemma 7.53 by determin
ing a suitable constant B such that (7.12) holds. If thew. are given by (7.9), then
we have w�il = sm��+i-1 for 1 � i � m and all n � 0. Thus
We note that for any hEZ we have e,(h) � x1(h), where X1 is the canonical
additive character of�, (see Chapter 5, Section I) and on the right-hand side
we identify h with the corresponding element of �,-namely, with the
residue class of h modulo p. If we now identify all h, and s. with the
corresponding elements of IF" and define
then we can write m
V11 = L hism��+i-1 ElF" for all n;;,. 0,
1=1
tN-1 lN-1
-'<:' e (h w"1 + · · · + h w<ml) �-L X (v ). (7.13) N PI �0 l' 1 PI m PI N n = 0 1 PI
Since s0, st> ... is a kth-order maximal period sequence inK= IF P' we get.as in
the proof of Theorem 7.47
s. � Tr,1x(Ga") for all n � 0,
where a is a primitive element ofF��,.. and e EF*. Suppose h1, ... , hm E �,are
not all 0. Then
v. � ,t1 h, TrF/K(e�•+ i-1) � TrF/K ( e ,t1 h,am•+i-1) � TrF/x(f3y")
for all n � 0, where
m
P=O L h,.ai-1 and y=a"'.
i= 1
Since m .;; k and {I, a, a2, ... , a•-1} is a basis of F over K, we have {3 of 0.
Furthermore, the condition gcd(m,p'-I)� I implies that y is a primitive
element of F. Theorem 6.24 and its proof show then that v0, v1, ... is a kth
order maximal period sequence in K. Thus
11 N-1 I p''2(2 2 N) -I x1(v.l <--logr+-+- for N .�o N n 5 r ! .;;N<r (7.14)
294 Theoretical Applications of Finite Fields
by Theorem 6.81, since n0 � 0 and R � r in this case. Taking into account
(7.13), we can therefore use the expression on the right-hand side of(7.14) as a
possible value of B in condition (7.12). The rest follows from Lemma 7.53.
D
In the proof of Theorem 7.52 we have obtained the exact distribution of
values in the least period of the sequence w0, w1, ... generated by (7.9), under
the conditions rn.;; k and gcd(m,p'-1) � 1. With these hypotheses we can
show an analogous result for higher dimensions d as long as d .;; k(rn. For
such a d we consider the d-tuples
w,.=(W,11W11+1, ...• w,.+d-tlE[0,1]d ·for O�n�r -1,
where r = pk-1 is the least period of the sequence w0, w1, .... Each w,. is ad
tuple of the form
(7.15)
with cJE7L and 0 � cj < pm for 1 � j �d. Consider also the sequence of rnd
tuples
which has again least period r. The same argument as in the proof of
Theorem 7.52 shows that for any bE{O, 1, ... ,p-1 }'""the number ofn, 0.;; n .;; r
-1, with sm,. = b is the same as the number ofn, 0 � n � r-1, with S11 =b. The
latter number can be obtained from Theorem 7.43 since the condition on d
yields rnd.;; k. In this way we arrive at the following result: the number of n,
0 � n � r-1, with w,. = 0 is equal to pk-md-1, and for any c-=/=-0 of the form
(7.15) the number of n, 0.;; n .;; r-1, with w. �cis equal to p'-m'. Thus the d
tuples w. show a very regular distribution behavior. The study of the
distribution of the w. amounts to performing an analog of the serial test for
random sequences of bits described earlier in this section. We can therefore say
that a sequence w0, w1, ... of uniform pseudorandom numbers generated by
(7.9) passes the serial test for dimensions d.;; k(rn, at least when it is considered
over the full period. Results for parts of the period can be obtained by an
extension of the method in the proof of Theorem 7.54.
EXERCISES
7.1. List the points and lines of PG(2,F3). Draw a diagram showing all
the intersections. Enumerate the points on LIXJ and the families of
parallel lines in AG(2,1F3).
7.2. In PG(2, F4) consider the quadrangle A(l, 1, 1 + fl), B(O, 1, fl),
C(l, l,fl), D(l, 1 + fl,fl), where fl is a primitive element of F4. Find
its diagonal points and verify that they are collinear.
7.3. There are six points in PG(2,1F4), no three of which are collinear.
Exercises 295
Four of them are the points A, B, C, D of Exercise 7.2. Find the
other two points.
7.4. Find the equation of the conic consisting of the points A, B, C, D of
Exercise 7.2 and E(l, I + {J, I + {J), determine all its tangents and
the point where they meet.
7.5. Show that for a nondegenerate conic in PG(2,f5) the tangents do
not all meet in the same point.
7.6. Prove: if L is a set of points of PG(2,1F .l such that every line of
PG(2,1F•) contains a point of L, then ILl;. q +I with equality if and
only if L is a line.
7.7. Prove that among any m + 3 points of a finite projective plane of
order m one can find three collinear ones.
7.8. Determine the number of points, lines, planes, and hyperplanes of
PG( 4,1F 3 ). How many planes are there through a given line?
7.9. In PG(4,1F3) determine the 3-flats through the plane given by
(1,0,0,0,0), (0,0,1,0,0), and (0,0,0,0, 1).
7.10. Prove that the number of k-flats of PG(m,IF .), I"' k < m, or also
within a fixed m-flat of a projective geometry over IF q of higher
dimension, is equal to
(qm+l_J)(qm-l)···(qm-k+\_1)
(qk+ I -J)(qk -J)· • • (q -I)
7.11. Show that the following system of blocks forms a BIBD and evaluate
the parameters v, b, r, k, and A:
(1,2,3) (1,4,7) (1,5,9) (1,6,8)
�.�� ��� ��n ���
(7,8,9) (3,6,9) (3,4,8) (3,5.n
7.12. Solve the following special case of the Kirkman Schoolgirl Problem.
A schoolmistress takes 9 girls for a daily walk, the girls arranged in
rows of 3 girls. Plan the walk for 4 consecutive days so that no girl
walks with any of her classmates in any triplet more than once.
7.13. In a school of b boys, t athletics teams of k boys each are formed in
such a way that every boy plays on the same number of teams. Also,
the arrangement is such that each pair of boys plays together the
same number of times. On how many teams does a boy play and how
often do two boys play on the same team?
7.14. Prove: if vis even for a symmetric ( v, k, A) block design, then k-A
is a square.
7.15. Verify that (0,1,2,3,5,7,12,13,16) is a difference set of residues
modulo 19. Determine the parameters v, k, and A.
7.16. Show that (0,4,5, ?)'is a difference set of residues modulo 13 which
yields PG(2,1F 3 ).
296 Theoretical Applications of Finite Fields
7.17. Prove the following generalization of Theorem 7.20. Let
{d,, ... ,d,.}, i�l, ... ,s,
7.18.
7.19.
7.20.
7.21.
7.22.
7.23.
7.24.
7.25.
7.26.
7.27.
7.28.
7.29.
7.30. be a system of (v, k, A) difference sets. Then with all residues
modulo v as varieties, the vs blocks
(d, + t, ... ,d,k + 1}, t � 0, l, ... ,v -I and i � l, ... ,s,
form a (v,k,As) block design.
Let L(*> � (a)J1), where a)J' = i + jkmod9, 0 .;; a),•' < 9 for I.;; i, j
.;; 9. Which of the arrays L(kl, k � 1,2, ... ,8, are latin squares? Are
L (ll and L (SI orthogonal?
A latin square of order n is said to be in normalized form if the first
row and the first column are both the ordered set (1,2, ... ,n}. How
many normalized latin squares of each order n .;; 4 are there?
Let L be a latin square of order m with entries in (I, 2, ... , m} and M
a latin square of order n with entries in (1,2, ... ,n). From Land M
construct a latin square of order mn with entries in {1,2, .. .,m}X
(1,2,. .. ,n}.
Construct three mutually orthogonal latin squares of order 4.
Prove that for n;. 2 there can be at most n-I mutually orthogonal
latin squares of order n.
A magic square of order n consists of the integers I to n2 arranged in
an n -X n array such that the sums of entries in rows, columns, and
diagonals are all the same. Let A� (a,) and B � (b1j) be two
orthogonal latin squares of order n with entries in (0, l, .. .,n -I}
such that the sum of entries in each of the diagonals of A and B is
n(n -1)/2. Show that M � (na,1 + b11 +I) is a magic square of order
n. Construct a magic square of order 4 from two orthogonal latin
squares obtained in Exercise 7.21.
Determine Hadamard matrices of orders 8 and 12.
If Hm and H. are Hadamard matrices, show that there exists a
Hadamard matrix Hm,·
Show that from a normalized Hadamard matrix of order 41, t ;. 2,
one can construct a symmetric (4r -1,2t-l, t-I) block design.
Prove that the state graph of an LMS over IF • with non singular
characteristic matrix consists of pure cycles only.
Prove that the state graphs of similar characteristic matrices over IF q
are isomorphic. (Note: Two matrices A, B over IF• are similar if there
exists a nonsingular matrix P over F q such that B �PAP-'.)
Suppose the characteristic matrix A of an LMS � over IF2 has the
minimal polynomial (x + l)'(x' + x + 1)3. What are the state orders
realizable by �?
Determine the orders of all states in the LMS �of Example 7.41.
Exercises 297
7.31.
7.32.
7.33.
7.34. Suppose the characteristic matrix A of an LMS 0R over IF, is
nonderoga tory; that is, its minimal polynomial is equal to its char
acteristic polynomial. Let the minimal polynomial of A be of the
form p(x )', where p(x) is a monic irreducible polynomial over IF • of
degree d. Without using Theorem 7.40, prove that the cycle sum of
GJn. is given by the expression in that theorem.
Calculate the cycle sum of the LMS GJn. over F 3 given in Example
7.35.
Prove Theorem 7.42.
Let s0,s1, ... be a kth-order maximal period sequence in IF, and let N
= d(q' -1)/(q-I) for some positive integer d. If ZN(O) denotes the
number of n, 0,;; n,;; N-I, such that s, = 0, prove that
d(q'-1-1)
ZN(O) = .
q-1
7.35. Let s0• s,. ... be a kth-order maximal period sequenee in IF,. For
I ,;;m ,;;k, I ,;; N <r=</-1, and b=(b1, ... ,bm)EIF; let ZN(b) be the
number of n, 0 � n � N-1, such that sn+i-I = bi for 1 � i � m. Prove
that
IZ.,(b)-Nq-ml ,;;(l-q-m)q'12 -logr+-+-. (2 2 N)
n 5 r
7.36. Let s0, s1, ... be a periodic sequence of elements of IF, with least period r.
For fixed cEIF, we say that a run of c of length m;;, I occurs if s, #' c,
s,+i = c for 1 � i � m, and s,+m+ 1 '# c for some n with 0 � n � r-1.
Prove that for a kth-order maximal period sequence in IF, with r = </
-I ;;, 2 exactly the following runs occur. For I ,;; m ,;; k -2 and any
cEIF, there are (q-1)2</-m-2 runs of c oflength m. The number of runs
of c of length k-1 is q -1 for c = 0 and q -2 for c #' 0. There is no run
of 0 of length k, and there is one run of c of length k for every c #' 0. No
runs of length > k can occur.
7.37. Prove: If u is a periodic sequence with period r, then the decimated
sequence rrl" has period rfgcd(d, r). Use a suitable decimation of the
sequence u in Example 7.50 to show that this result does not hold in
general if "period'" is replaced by "least period".
7.38. Prove the following converse of Theorem 7.48: any decimated sequence
of a kth-order maximal period sequence in lF q is either the zero sequence
or a linear recurring sequence in lFq having an irreducible minimal
polynomial g{x) with g(O) #' 0 and deg(g(x)) dividing k.
7.39. Let u be a given kth-order maximal period sequence in IF,. Prove that
every kth-order maximal period sequence in IF, is equal to a shifted
version of cr�0' for some d.
7.40. Let u be a nonzero periodic sequence of elements of1F2 with least period
298 Theoretical Applications of Finite Fields
r. Prove that if for every h with I ,s; h ,s; r-I the sequence u + u''' is a
shifted version of u. then u is a maximal period sequence in IF2•
7.41. Prove that for any maximal period sequence in�. there exists a shifted
version u of the sequence such that u�0l =a.
7.42. Let s0, s1, ... be a kth-order maximal period sequence in the finite prime
field IF P and view the terms sn oft he sequence as integers with 0:::;;; sn < p.
For positive integers m and d define
m
"' -i Wn = L. Sdn+i-lP
i= 1 for n = 0, I, ....
Prove that if gcd(d, p'-I)= I, then the sequence w0, w1, ... is periodic
with least period p'-I.
Chapter 8
Algebraic Coding Theory
One of the major applications of finite fields is coding theory. This theory has
its origin in a famous theorem of Shannon that guarantees the existence of
codes that can transmit information .at rates close to the capacity of a
communication channel with an arbitrarily small. probability of error. One
purpose of algebraic coding theory-the theory of error-correcting and error
detecting codes-is to devise methods for the construction of such codes.
During the last two decades more and more abstract algebraic tools such as
the theory of finite fields and the theory of polynomials over finite fields have
influenced coding. In particular, the description of redundant codes by
polynomials over IF, is a milestone in this development. The fact that one can
use shift registers for coding and decoding establishes a connection with linear
recurring sequences. In our discussion of algebraic coding theory we do not
consider any of the problems of the implementation or technical realization of
the codes. We restrict ourselves to the study of basic properties of block codes
and the description of some interesting classes of block codes.
Section I contains some background on algebraic coding theory and
discusses the important class of linear codes in which encoding is performed by
a linear transformation. A particularly interesting type of linear code is a cyclic
code-that is, a linear code invariant under cyclic shifts. Our study of cyclic
codes in Section 2 includes a description of what is possibly the most widely
known family of codes, the BCH codes named after Bose, Ray-Chaudh uri, and
Hocquenghem. BCH codes can be implemented easily and permit a fast
decoding algorithm. The Goppa codes discussed in Section 3 can be viewed as
299
300 Algebraic Coding Theory
generalized BCH codes. Goppa codes allow a much wider choice of
parameters than BCH codes, but can still be decoded efficiently. If the
decoding algorithm for Goppa codes is specialized to BCH codes, one obtains
a second way of decoding BCH codes.
1. LINEAR CODES
The problem of the communication of informati on-in particular the
coding and decoding of information for the reliable transmission over a
"noisy" channel-is of great importance today. Typically, one has to
transmit a message which consists of a finite string of symbols that are
elements of some finite alphabet. For instance, if this alphabet consists
simply of 0 and I, the message can be described as a binary number.
Generally the alphabet is assumed to be a finite field. Now the transmission
of finite strings of elements of the alphabet over a communication
channel need not be perfect in the sense that each bit of information is
transmitted unaltered over this channel. As there is no ideal channel without
"noise," the receiver of the transmitted message may obtain distorted
information and may make errors in interpreting the transmitted signal.
One of the main problems of coding theory is to make the errors,
which occur for instance because of noisy channels, extremely improbable.
The methods to improve the reliability of transmission depend on properties
of finite fields.
A basic idea in algebraic coding theory is to transmit redundant
information together with the message one wants to communicate; that is,
one extends the string of message symbols to a longer string in a systematic
manner.
A simple model of a communication system is shown in Figure 8.1.
We assume that the symbols of the message and of the coded message are
elements of the same finite field IF •. Coding means to encode a block of k
message symbols a1a2 · • • ak., a; E IF q• into a code word c1c2 ···en of n
symbols cj E F,1, where n > k. We regard the code word as an n-dimensional
row vector c in F;. Thus fin Figure 8.1 is a function from IF: in to IF;, called
a coding scheme. and g: IF; -+ IF; is a decoding scheme.
Message Coded Message
a c
Decoded Message g
a c+e
FIGURE 8.1 A communication system. ,...----''-----, ..--
+-------"Noise ..
'-----,--__J --
1. Linear Codes 301
A simple type of coding scheme arises when each block a1a2 ···a, of
message symbols is encoded into a code word of the form
where the first k symbols are the original message symbols and the addi
tional n -k symbols in F., are control symbols. Such coding schemes are
often presented in the following way. Let H be a given (n-k)X n matrix
with entries in F q that is of the special form
where A is an (n-k)X k matrix and I._, is the identity matrix of order
n-k. The control symbols ck+ 1 .... ,c. can then be calculated from the
system of equations
HcT �o
for code words c. The equations of this system are called parity-check
equations.
8.1. Example. Let H be the following 3X7 matrix over F2:
Then the control symbols can be calculated by· solving HcT � 0. given
cl' c2• cJ• c4:
c, �o
�o
+ c7� 0
The control symbols c5• c6, c1 can be expressed as
cs=cl +c3+c4
c6=c1+c2 +c4
c7=c1 + c2+ cJ
Thus the coding scheme in this case is the linear map from 1Ft into rFi given
by
D
In general, we use the following terminology in connection with
coding schemes that are given by linear maps.
302 Algebraic Coding Theory
8.2. Definition. Let H be an (n-k)Xn matrix of rank n-k with entries
in IFq. The set C of all n-dimensional vectors c E F; such that HcT = 0 is
called a linear ( n. k) code over I',; n is called the length and k the dimension
of the code. The elements of Care called code words (or code vectors), the
matrix His a parity-check matrix of C. If q � 2, Cis called a binary code. If
II is of the form (A, 1, ..• ). then Cis called a systematic code.
We note that the set C of solutions of the system HcT � 0 of linear
equations is a subspace of dimension k of the vector space F;. Since the
code words form an additive group. Cis also called a group code. Moreov er,
C can be regarded as the null space of the rna trix H.
8.3. Example (Purity-Check Code). Let q � 2 and let the given message
be a1 • • • ak, then the coding scheme/is defined by
where h; =a; fori= I. ... ,k and
Hence it follows that the sum of digits of any code word b, .. ·bk+ 1 is 0. If
the sum of digits of the received word is I, then the receiver knows that a
rransmission error must have occurred. Let n = k + I. then this code is a
binary linear ( n, n -I) code with parity-check matrix H � (II · · · I). D
8.4. Example (Repetition Code). In a repetition code each code word
consists of only one message symbol a1 and n-I control symbols c2 =
··=en all equal to a1: that is. a1 is repeated n -I times. This is a linear
(n, I) code with parity-check matrix H � ( -1, /,_1). D
The parity-check equations HcT � 0 with H �(A, I,_,) imply
where a= a1 ••• ak is the message and c = c1• ··en is the code word. This leads
to the following definition.
8.5. Definition. The k X n matrix G � U •. -AT) is called the canonical
generator matrix of a linear (n, k) code with parity-check matrix H �
(A,l,_k).
From HcT � 0 and c � aG it follows that Hand G are related by
(8.1)
The code C is equal to the row space of the canonical generator matrix G.
More generally, any k x n matrix G whose row space is equal to C is called
1. Linear Codes 303
a generator matrix of C. A genera tor rna trix G of C can be used for encoding
namely, a message a is encoded by c =aGE C.
8.6. Example. The canonical genera tor rna trix for the code defined by H
in Example 8.1 is given by
G =I� 0 0 0 I I l I· I 0 0 0 I D 0 I 0 I 0
0 0 I I I
8. 7. Definition. If c is a code word and y is the received word after
communication through a "noisy" channel, then e = y-c = e 1 • • • en 1s
called the error word or the error vector.
8.8. Definition. Let x,y be two vectors in F;. Then:
(i) the Hamming distance d(x,y) between x andy is the number of
coordinates in which x and y differ;
(ii) the (Hamming) weight w(x) of x is the number of nonzero
coordinates of x.
Thus d(x,y) gives the number of errors if x is the transmitted code
word and y is the received word. It follows immediately that w(x) = d(x,O)
and d(x.y) = w(x-y). The proof of the following lemma is left as an
exercise.
8.9. Lemma. The Hamming distance is a metric on n:;; that is, for
all x,y,z E F�' we have:
(i) d(x, y) = 0 if and only if x = y;
(ii) d(x,y) = d(y,x);
(iii) d(x,z).;; d(x.y)+ d(y,z).
In decoding received words y, one usually tries to find the code word
c such that w(y-c) is as small as possible, that is, one assumes that it is
more likely that few errors have occurred rather than many. Thus in
decoding we are looking for a code word c that is closest to y according to
the Hamming distance. This rule is called nearest neighbor decoding.
8.10. Definition. For I EN a code c <;: r; is called t-error-correcting if for
any y E IF; there is at most one c E C such that d(y,c) .;;r.
If c E C is transmitted and at most t errors occur, then we have
d(y, c).;; 1 for the received word y. If C is t-error-corr ecting, then for all
other code words z"' c we have d(y,z) > 1, which means that cis closest toy
and nearest neighbor decoding gives the correct result. Therefore, one aim
in coding theory is to construct codes with code words "far apart." On the
other hand, one tries to transmit as much information as possible. To
reconcile these two aims is one of the problems of coding.
304
8.11. Definition. The number
de� min d(u,v) � min w(c)
U,"EC O""cEC
·-·
is called the minimum distance of the linear code C. Algebraic Coding Theory
8.12. Theorem. A code C with minimum distance de can correct up
to 1 errors if de ;> 21 +I.
Proof A ball B,(x) of radius t and center x E F; consists of all
vectors y E F; such that d(x,y).; t. The nearest neighbor decoding rule
ensures that each received word with 1 or fewer errors must be in a ball of
radius 1 and center the transmitted code word. To correct/ errors, the balls
with code words x as centers must not overlap. If u E B,(x) and u E B,(y).
x,y E C, x '* y, then
d(x,y) .; d(x,u)+ d(u,y).; 21.
a contradiction to de� 2t +I. D
8.13. Example. The code of Example 8.1 has minimum distance de � 3
and therefore can correct one error. 0
The following lemma is often useful in determining the minimum
distance of a code.
8.14. Lemma. A linear code C with parity-check matrix H has
minimum distance de� s + 1 if and only if any s columns of H are linearly
independent.
Proof Assume there are s linearly dependent columns of H, then
HcT � 0 and w(c).; s for suitable c E C, c"' 0. hence de.; s. Similarly, if
any s columns of H are linearly independent. then there is no c E C, c "'0,
of weight .;; s, hence de;> s +I. D
Next we describe a simple decoding algorithm for linear codes. Let C
be a linear (n, k) code over F •. The vector space F;;c consists of all cosets
a+C�(a+c:cEC} with aEIF;. Each coset contains qk vectors and IF;
can be regarded as being partitioned into cosets of C -namely,
where a<0> � 0 and s � q•-k -l. A received vector y must be in one of the
cosets, say in aCil +C. If the code word c was transmitted, then the error is
given by e � y-c � aUl + z E aU>+ C for suitable z E C. This leads to the
following decoding scheme.
8.15. Decoding of Linear Codes. All possible error vectors e of a received
1. Linear Codes 305
vector y are the vectors in the coset of y. The most likely error vector is the
vector e with minimum weight in the coset of y. Thus we decode y as
x = y-e.
The implementation of this procedure can be facilitated by the
coset-leader algorithm for error correction of linear codes.
8.16. Definition. Let C � o:; be a linear (n, k) code and let F;;c be the
factor space. An element of minimum weight in a coset a+ C is called a
coset leader of a+ C. If several vectors in a+ C have minimum weight, we
choose one of them as coset leader.
Let a11 1, ..• , a<•> be the coset leaders of the cosets * C and let c<'l = 0,
c'21, .•. ,c1•'• be all code words in C. Consider the following array:
c<l) c<2>
aOl +c(ll a<ll +c<2)
column of
coset leaders c(q' l } row of code words
a<'> +c<•'1 l
; remaining cosets
a<sl +c<q*>
If a word y = a<'l +c"1 is received, then the decoder decides that the errore
is the corresponding coset leader a<". and decodes y as the code word
x = y-e = cli1; that is, y is decoded as the code word in the column of y.
The coset of y can be determined by evaluating the so-called syndrome of y.
8.17. Definition. Let H be the parity-check matrix of a linear (n, k) code
C. Then the vector S(y) = Hy T of length n-k is called the syndrome of y.
8.18. Theorem. For y,z Eo:; we have:
(i) S(y) = 0 if and only if y E C;
(ii) S(y) = S(z) if and only if y+ C = z +C.
Proof (i) follows immediately from the definition of C in terms of
H. For (ii) note that S(y) = S(z) if and only if Hy T = HzT if and only if
H(y-z)T = 0 if and only if y-z E C if and only if y + C = z +C. D
If e = y-c, c E C, y E f;, then
S(y) = S(c+e) = S(c)+ S(e) = S(e) (8. 2)
and y and e are in the same coset. The coset leader of that coset also has the
same syndrome. We have the following decoding algorith m.
8.19. Coset-Leader Algorithm. Let C � F; be a linear ( n. k) code and let
306 Algebraic Coding Theory
y be the received vector. To correct errors in y, calculate S(y) and find the
coset leader, say e, with syndrome equal to S(y). Then decode y as x � y-e.
Here xis the code word with minimum distance toy.
8.20. Example. Let C be a binary linear (4,2) code with generator matrix
G and parity-check matrix H:
G � (� 0 n H� (� 1 n 1 0
The corresponding array of cosets is:
message row 00 10 01 11
code words 0000 1010 0111 1101 m
1000 0010 1111 0101 (�)
other cosets 0100 1110 0011 1001 ( : )
0001 1011 0110 1100 m ..____..__-� coset syndromes
leaders
If y � 1110 is received, we could look where in the array y occurs. But for
large arrays this is very time consuming. Therefore we find S(y)
first-namely. S(y) � Hy T � (:)-and decide that the error is equal to the
coset leader 0100 that also has syndrome (:).The original code word was
most likely the word 1010 and the original message was 10. 0
In large linear codes it is practically impossible to find coset leaders
with minimum weight: for example, a linear (50,20) code over F2 has some
109 cosets. Therefore it is necessary to construct special codes in order to
overcome such difficulties. First we note the following.
8.21. Theorem. In a binary linear (n, k) code with parity-check
matrix H the syndrome is the sum of those columns of H that correspond to
positions where errors have occurred.
Proof Let y E IF;' be the received vector, y � x+e, x E C; then
from (8.2) we have S(y) � HeT. Let i1, i2, .•• be the error coordinates in e,
say e � 0 · · · 0 1. 0 · · · 0 1. 0 · · · then S(y) � h + h + · · · where h. denotes IJ 12 ! /1 11 > I
the i th column of H. 0
If all columns of H are different, then a single error in the ith
1. Linear Codes 307
posii!On of the transmitted word yields S(y) � h1, thus one error can be
corrected. To simplify the process of error location, the following class of
codes is useful.
8.22. Definition. A binary code C.., of length n � 2"' -I, m ;;. 2, with an
m X (2"'-I) parity-check matrix His called a binary Hamming code if the
columns of H are the binary representations of the integers I, 2, ... , 2"' -I.
m-1. 8.23. Lemma. Cm is a 1-error-correcting code of dimension 2m-
Proof By definition of the parity-check matrix H of C..,, the rank of
H is m. Also, any two columns of H are linearly independent. Since H
contains with any two of its columns also their sum, the minimum distance
of C.., equals 3 by Lemma 8.14. Thus C.., is !-error-correcting by Theorem
8.11 D
8.24. Example. Let C3 be the (7,4) Hamming code with parity-check
matrix
H� (� 0 0 I I I ll· I I 0 0 I
0 I 0 I 0
If the syndrome of a received wordy is, say, S(y) �(I 0 l)T, then we
know that an error must have occurre<! in the fifth position, since I 0 I is the
binary representation of 5. o
Hamming codes can also be defined in the non binary case- that is,
over arbitrary finite fields F.. Here the parity-check matrix H is an
m X(q"' -1)/(q -I) matrix that has pairwise linearly independent col
umns. Such a matrix defines a linear ((q"' -1)/(q -I), (q"' -1)/(q -I)
-m) code of minimum distance 3.
Next we describe some relationships between the length n of code
words, the number k of information or message symbols, and the minimum
distance d c of a linear code over IF q·
8.25. Theorem (Hamming Bound). Let C be a t-error-correcting
code over F • of length n with M code words. Then
M(I+(7)(q-l)+ ··· +(�)(q-IJ').;q".
Proof There are (; )( q -I)"' vectors with n coordinates in F • of
weight m. The balls of radius I centered at the code words are all pairwise
disjoint and each of the M balls contains
1+(7)(q-l)+ ... +(;)(q-1)'
vectors of all the q11 vectors in F;. D
308 Algebraic Coding Theory
8.26. Theorem (Plotkin Bound). For a linear (n, k) code Cover F,
of minimum distance d c we have
d nq*-'(q-1) c� k · q -l
Proof Let l..; i...; n be such that C contains a code word with
nonzero i th component. Let D be the subspace of C consisting of all code
words with i th component zero. In C I D there are q elements which
correspond to q choices for the ith component of a code word. Thus
I Ci/IDI =I C/DI implies IDI = q*-1• By counting along the components,
the sum of the weights of the code words in C is then seen to be
...; nq*-'(q -1). The minimum distance de of the code is the minimum
nonzero weight and therefore must satisfy the inequality given in the
theorem since the total number of code words of nonzero weight is q* -l. 0
8.27. Theorem (Gilbert-Varshamov Bound). There exists a linear
(n, k) code over Fq with minimum distance� d whenever
d-2
q"-*> L (n�l)(q-l)'.
'� 0
Proof We prove this theorem by constructing an ( n -k) X n
parity-check matrix H for such a code. We choose the first column of Has
any nonzero (n-k)-tuple over IF,. The second column is any (n-k)-tuple
over IF, that is not a scalar multiple of the first column. In general, suppose
j-l columns have been chosen so that any d-l of them are linearly
independent. There are at most
dt'(j-l)(q-1)'
i-0 I
vectors obtained by linear combinations of d-2 or fewer of these j -1
columns. If the inequality of the theorem holds, then it will be possible to
choose a jth column that is linearly independent of any d -2 of the first
j-1 columns. The construction can be carried out in such a way that H has
rank n-k. The resulting code has minimum distance � d by Lemma 8.14.
0
We define the dual code of a given linear code C by means of the
following concepts. Let u=(u1, ... ,u,), v=(v1, ..• ,v,)EF;, then u·v=
u1v1 + · · · + u,v, denotes the dot product of u and v. If u·v = 0, then u and
v are called orthogonal.
8.28. Definition. Let C be a linear (n, k) code over F,. Then its dual (or
orthogonal) code C" is defined as
C" ={uEIF;:u·v=O forallvEC}.
The code Cis a k-dimensional subspace of F;. the dimension of C"
1. Linear Codes 309
is n-k. C � is a linear (n, n-k) code. It is easy to show that C � has
generator matrix H if C has parity-check matrix H and that C � has
parity-check matrix G if C has generator matrix G.
Considerable information on a code is obtained from the weight
enumeration. For instance, to determine decoding error probabilities or in
certain decoding algorithms it is important to know the distribution of the
weights of code words. There is a fundamental connection between the
weight distribution of a linear code and of its dual code. This will be derived
in the following theorem.
8.29. Definition. Let A; denote the number of code words c E C of weight
i, 0 " i " n. Then the polynomial
•
A(x,y)= I: A;x;y•-;
;�o
in the indeterminates x andy over the complex numbers is called the weight
enumerator of C.
We shall need characters of finite fields, as discussed in Chapter 5.
8.30. Definition. Let x be a nontrivial additive character of f • and let v · u
denote the dot product of v,u E F;. We define for fixed v E F; the mapping
x,:IF;-->c by
x,(u)=x(v·u) foruEIF;.
If Vis a vector space over C and fa mapping from F; into V, then we
define g1: F;--> V by
g1(u)= I: .x,(u)f(v) foruEF;.
Y eF;
8.31. Lemma. Let E be a subspace ofF;, E � its orthogonal comple
ment, f:F; --> V a mapping from IF; into a vector space V ooer C and x a
nontrivial additive character ofF q· Then
L g1(u)=IEI L f(v).
uE E
Proof
I: g,(u) = I: I: x,(u)f(v) = I: I: x(v·u)f(v)
UE£ UE£YE f; YEF;uE£
=lEi L f(v)+ L L L x(c)f(v).
YE£.1 yf£;£.1cEfqy�:-=£c
For fixed v 'f. E �, u E E,... v·u is a nontrivial linear functional onE, thus
L g1(u)=IEI L f(v)+@l L !(•) L x(c)=IEI L f(v),
UE£ \'E£.1 q yf£:£.1 cEfq yE£.1
by using (5.9). D
310 Algebraic Coding Theory
We apply this lemma with V as the space of polynomials in two
indeterminates x and y over C and the mapping f defined as f(v) =
xw(•lyn-w(•l, where w(v) denotes the weight of v E rF;.
8.32. Theorem (MacWilliams Identity). Let C be a linear (n, k)
code over IF • and C " irs dual code. If A ( x. y) is the weight enumerator of C
and A" ( x, y) is the weight enumerator of C ". then
A" (x, y) = q-'A(y -x,y +(q-l)x).
Proof Let f:F; --+C[x, y] be as given above, then the weight
enumerator of C .1 is
A"(x.y)= L f(v).
'E CJ.
Let g1 be as in Definition 8.30 and for v E F q define { I if v * 0, lvl= 0 ifv=O.
For u = (u1,. .. ,un) E IF; we have
g,(u) = L x(v·u)x•C•>y•-•<•>
¥ Ef;
L x(u1v1 + ... + u,v,)xlvtl+ ··+lv�ly(l-lvtll+···+{l-lv�l)
v1 •.•• V11Efq
"
E n [x(u,v,Jx'""y'-'"·']
v1 •••• v�Efql-1
"
= n E [x(u,vJx1"1y'-1"1].
i-1 oEf'l
For u, = 0 we have x(u,v) = x(O) =I, hence the corresponding factor in the
product is ( q-l)x + y. For u, * 0 the corresponding factor is
y+x E x(vJ=y-x.
v Ef;
Therefore.
g1(u) = (y-x)"'"'(y +(q-l)x)"-"'"1•
Lemma 8.31 implies
ICIA"(x.y)=ICI L /(v)= L g1(u)=A(y-x.y+(q-l)x).
¥EC_j_ uEC
Finally, I Ci = q• by hypothesis. 0
8.33. Corollary. Let x = z and y =I in the weight enumerators
A ( x. y) and A" ( x. y) and denote the resulting polynomials by A( z) and
2. Cyclic Codes 311
A" ( z ). respectively. Then the Mac Williams identity can be wrillen in the form
A"(z)�q-k(I+(q-l)z)"A( ;-z) )· I+ q-1 z
8.34. Example. Let C,, be the binary Hamming code of length n � 2"' -I
and dimension n-mover IF2. The dual code C,;t has as its generator matrix
the parity-check matrix H of C,,. which consists of all nonzero column
vectors of length m over IF 2. Cm.l. consists of the zero vector and 2m - 1
vectors of weight 2m-I. Thus the weight enumerator of Cm.l. IS
y" +(2"' -l)x2·-'y'·-•-1.
By Theorem 8.32 the weight enumerator for C.., is given by
A(x. y) � n � 1 [(y + x)" + n(y-x )'"+'112(y + x)'"-111'].
Let A(z)�A(z,l)-that is, A(z)�L:;_0A,z'-then one can verify that
A(z) satisfies the differential equation
dA(z) " (l-z2)� +(I +nz)A(z) �(I+ z)
with initial condition A(O) � A0 �I. This is equivalent to
iA,� c� I )-A,_1-(n-i+2)A,_2 fori� 2,3, ... ,n
with initial conditions A0 �I. A1 � 0. D
2. CYCLIC CODES
Cyclic codes are a special class of linear codes that can be implemented
fairly simply and whose mathematical structure is reasonably well known.
8.35. Definition. A linear. ( n, k) code C over IF q is called cyclic if
( a0, a, .... ,a,_,) E C implies (a,_,, a0, ... ,a,_,) E C.
From now on we impose the restriction gcd(n, q) �I and let (x"-I)
be the ideal generated by x"-IE F q[x ]. Then all elements ofF .[x ]/(x" -I)
can be represented by polynomials of degree less than n and clearly this
residue class ring is isomorphic to IF; as a vector space over IF q· An
isomorphism is given by
Because of this isomorphism, we denote the elements of F•[x]/(x" -I)
either as polynomials of degree < n modulo x" -I or as vectors or words
over F •. We introduce multiplication of polynomials modulo x" -I in the
312 Algebraic Coding Theory
usual way; that is, iff E IF,[x]/(x" -I), g1, g2 E IF0[x], then g1g2 �/means
that g1g2 = fmod(x"-1).
A cyclic (n, k) code C can be obtained by multiplying each message
of k coordinates (identified with a polynomial of degree < k) by a fixed
polynomial g(x) of degree n-k with g(x) a divisor of x" -I. The poly
nomials g(x ), xg(x ), ... , x'-1g(x) correspond to code words of C. A gener
ator matrix of C is given by
go g, gn-k 0 0 0
0 go g, gn-k 0 0
G�
0 0 0 0 go g, gn-k
where g(x) � g0 + g1x + · · · + g,_,x"-'. The rows of G are obviously
linearly independent and rank (G)� k, the dimension of C. If
h(x) � (x" -1)/g(x) � h0 + h1x + · · · + h,x'.
then we see that the matrix
0 0 0 h, h,_, ho
0 0 0 h, h,_, ho 0
H�
h, h,_, ho 0 0
is a parity-check matrix for C. The code with generator matrix His the dual
code of C, which is again cyclic.
Since we are using' the terminologies of vectors (a0, a1, ••• ,a,_1) and
polynomials a0 + a1x + · · · + a11_1x"-1 over IFq synonymously, we can
interpret Cas a subset of the factor ring IF,[x]/(x" -I).
8.36. Theorem. The linear code C is cyclic if and only if C is an
ideal ofiF,[x]/(x" -I).
Proof If Cis an ideal and (a0, a1, .•. ,a.,_1) E C, then also
x(a0+a1x+ ··· +a11_1x"-1)=(a11_1,a0, •.• ,a11_2)EC.
Conversely, if (a0,a1, •.. ,a,1_1)EC implies (a,_1,a0, ..• ,a11_2)EC, then
for every a(x) E C we have xa(x) E C, hence also x2a(x) E C. x3a(x) E C,
and so on. Therefore also b(x)a(x) E C for any polynomial b(x); that is, C
is an ideal. D
Every ideal of IF,[x]/(x" -I) is principal; in particular, every non
zero ideal C is generated by the monic polynomial of lowest degree in the
ideal, say g( x ). where g( x) divides x" -I.
2. Cyclic Codes 311
8.37. Definition. Let C � (g(x)) be a cyclic code. Then g(x) is cafled the·
generator polynomial of C and h(x) � (x" - I )/g( x) is called the parlty"chee�
polynomial of C.
Let x" -I� /1(x)/2(x)· · ·/..,(x) be the decomposition of x" -I
in to monic irreducible factors over IF q· Since we assume gcd( n, q) � I, there
are no multiple factors. If /;(x) is irreducible over IF•, then (/;(x)) is a
maximal ideal and the cyclic code generated by /;(x) is called a maximal
<yclic code. The code generated by (x" -1)//;(x) is called an irreducible
cyclic code. We can find all cyclic codes of length n over Fq by factoring
x"-1 as above and taking any of the 2m-2 nontrivial monic factors of
x" -1 as a genera tor polynomial.
If h(x) is the parity-check polynomial of a cyclic code C S:::
IF.[x]/(x"-1) and v(x)EF9[x]/(x"-l), then v(x)EC if and only if
v(x)h(x) = Omod(x"-1). A message polynomial a(x) � a0 + a1x + · · · +
a,_,xk-l is encoded by C into w(x) � a(x)g(x), where g(x) is the genera
tor polynomial of C. If we divide the received polynomial v(x) by g(x), and
if there is a nonzero remainder, we know that an error occurs. The canonical
generator matrix of C can be obtained as follows. Let deg((g(x)) �
n-k. Then there are unique polynomials aj(x) and r1(x) with deg(r/x)) <
n -k such that
X1 � a i (X) g (X)+ 1j (X).
Consequently, x' -r,(x) is a code polynomial, and so is gj(x) �
x'(x' -r,(x)) considered modulo x" -I. The .. polynomials g1(x), j �
n-k, ... ,n -I, are linearly independent and form the canonical generator
matrix
(1,,-R),
where I, is the k x k identity matrix and R is the k x ( n-k) matrix whose
i th row is the vector of coefficients of rn-k-1 +;(x ).
8.38. Example. Let n � 7, q � 2. Then
x' -I� (x + I)(x3 + x + I)(x3 + x2 +I).
Thus g(x) � x3 + x2 +I generates a cyclic (7,4) code with parity-check
polynomial h( x) � x4 + x3 + x2 + I. The correspon ding canonical generator
matrix and parity-check matrix is, respectively,
I 0 0 0 I 0 �I. G� 0 1 0 0 I 1
0 0 1 0 I 1
0 0 0 1 0 1
H� ( f 1 0 1 0 �). 1 1 0 1 D
0 1 0 0
314 Algebraic Coding Theory
We recall from Chapter 6 that iff E f•[x] is a polynomial of the
form
/(x)�/0+ /,x+ ··· + /,x', fo*O,f,�l.
then the solutions of the linear recurrence relation
k
L �a,+1�0. i�O.I. ....
j�O
are periodic of period n. The set of then-tuples of the first n terms of each
possible solution, considered as polynomials modulo x" -I, is the ideal
generated by g(x) in IFq[x]/(x" -I), where g(x) is the reciprocal poly
nomial of (x" -1)//(x) of degree n-k. Thus linear recurrence relations can
be used to generate code words of cyclic codes, and this generation process can
be implemented on feedback shift registers.
8.39. Example. Let /(x) � x' + x +I, a factor of x7 -I over IF,. The
associated linear recurrence relation is a;+J +a;+ 1 +a;= 0, which gives rise
to a (7,3) cyclic code, which encodes Ill, say, as Ill 00 I 0. The generator
polynomial is the reciprocal polynomial of (x7 -1)//(x); that is, g(x) �
x4 + x3 + x2 + 1. 0
Cyclic codes can also be described by prescribing certain roots of all
code polynomials in a suitable extension field of IF q· The requirement that
all code polynomials are multiples of g(x), a generator polynomial, simply
means that they are all 0 at the roots of g(x ). Let a1, ... , a, be elements of a
finite extension field of IF q and p,( x) be the minimal polynomial of a, over
IF q for i � I, 2, ... ,s. Let n EN be such that a; � 1, i � I, 2, ... ,s, and define
g(x)�lcm(p1(x), ... ,p,(x)). Thus g(x) divides x"-1. If C<:::IF; is the
cyclic code with generator polynomial g(x), then we have v(x) E C if and
only if v (a) � 0, i � I, 2, ... , s. As an example of the concurrence of the
description of a cyclic code by a generator polynomial or by roots of code
polynomials we prove the following result, which uses the concept of
equivalence of codes in Exercise 8.10.
8.40. Theonm. The binary cyclic code of length n �2m-I for
which the generator polynomial is the minimal polynomial over IF 2 of a
primitive element of!F2• is equivalent to the binary (n, n-m) Hamming code.
Proof Let a denote a primitive element of IF2• and let
p(x)�(x-a)(x-a2)···(x-a1"-')
be the minimal polynomial of a over IF 2. We now consider the cyclic code C
generated by p(x). We construct an m X (2m-1) matrix H for which thejth
column is (c0, c1, .• ,em-JlT if
m-l
al-l= L c1a1, j=l,2 .... ,2m-l,
i = 0
2 Cyclic Codes 315
where c, E F2. If a� (a0, a1,. .. ,a,_1) and a(x) � a0 + a1x + · · · +
a, _1x"-1EF2(x], then the vector HaT corresponds to the element a(a)
expressed in the basis (1, a,. .. ,a'"-1). Consequently, HaT� 0 holds exactly
when p(x) divides a(x), so H is a parity-check matrix of C. Since the
columns of H are a permutation of the binary representations of the
numbers 1, 2, .. ., 2'" � 1, the proof is complete. D
8.41. Example. The polynomial x4 + x +I is primitive over F2 and thus
has a primitive element a of IF 16 as a root. If we use vector notation for the
15 elements ai E Fi6• j � 0, I, ... , 14, expressed in the basis (I, a, a2, a3) and
we form a 4 X 15 matrix with these vectors as columns, then we get the
parity-check matrix of a code equivalent to the (15, 11) Hamming code. A
message (a0, a1, .. .,a10) is encoded into a code polynomial
w(x) � a(x)(x4 +x + 1),
where a(x} � a0 + a1x + · · · + a10x10 Now suppose the received poly
nomial contains one error: that is. w(x)+ x�-1 is received when w(x) is
transmitted. Then the syndrome is w( a)+ ae-1 = ae-1 and the decoder is
led to the conclusion that there is an error in thee th position.· D
8.42. Theorem. Let C � F.(x]/(x" � 1} by a cyclic code with gener
ator polynomial g and let a1,. .. , a,_. be the roots of g. Then f E IF .lx ]/(x" � 1)
is a code polynomial if and only if the coefficient vector (/0, ••• ,f,_ 1) of/ is in
the null space of the matrix
a, a' I . ·a�-I
H� (8.3)
an-k a�-k ,_, a,,-k
Proof Let/(x)�/0+/1x+ ··· +f,_1x"-1; then/(a,}�/0+/1a,
+ · · · + /,,_1a�-l = 0 for I� i � n-k, that is,
(I, a,, ... ,a;-\ )(/0,/1, ..• ,f,_1)T � 0 for I .;;, i.;;, n � k,
if and only if H(/0,f1, ..• ,f,_1)T �o. D
We recall from Section I that for error correction we have to
determine the syndrome of the received wordy. In the case of cyclic codes,
the syndrome, which is a column vector of length n � k, can often be
replaced by a simpler entity serving the same purpose. For instance, let a
be a primitive nth root of unity in IF q" and let the generator polynomial g be
the minimal polynomial of a over IF •. Since g divides f E IF•[x]/(x" �I) if
and only if f(a) � 0, it suffices to replace the matrix H in (8.3) by
H �(I a a2
The.o the role of the syndrome is played by S(y) � Hy T, and S(y) � y( a)
since v�(v,.,v, .. .,v .. _,) can be regarded as a oolvnomial vlx) with
316 Algebraic Coding Theory
coefficientsy,. In the following we use the notation w for a transmitted word
and v for a received word, and we write w(x) and v(x), respectively, for the
corresponding polynomials. Suppose eUl(x) � xr 1 with 1 .;; j.;; n is an
error polynomial with a single error, and let v = w+ eCJl be the received
word. Then
v( a)� w( a)+ eUl( a)� e(}l( a)� a;-I
e'11(a) is called the error-location number. S(v) � af-l indicates the error
uniquely, since e'''( a)* eU1( a) for I.; i.; n with i * j.
Before describing a general class of cyclic codes and their decoding,
we consider a special example to motivate the theory.
'
8.43. Example. Let a E IF 16 be a root of x4 + x +I E f2[x ], then a and a3
have the minimal polynomials m'''(x) � x4 + x +I and m0'(x) � x4 + x'
+ x2 + x +I over IF2, respective ly. Both m'"(x) and m'''(x) are divisors of
x"-I. Hence we can define a binary cyclic code C with generator poly
nomial g � m'"m"'· Since g divides f E IF2[x]/(x" -I) if and only if
f( a)�/( a')� 0, it suffices to replace the matrix H in (8.3) by
H � (: :, :: :�: ) .
We shall show (see Theorem 8.45 and Example 8.47) that the minimum
distance of C is � 5, therefore C can correct up to 2 errors. C is a cyclic
( 15, 7) code. Let
14 14
sl = L v,.ai and SJ = L V;a]i
i=O ,-o
be the components of S(v) � Hv T Then v E C if and only if S(v) � Hv T � 0
if and only if S1 � S3 � 0. If we use binary notation to represent elements of
IF 16, then H attains the form
I 0 0 0 I 0 0 I I 0 0 I I
0 I 0 0 I I 0 I 0 I I 0 0
0 0 I 0 0 I I 0 I 0 I I I 0
H� 0 0 0 I 0 0 I I 0 I 0 I I I I
I 0 0 0 I I 0 0 0 I I 0 0. 0 I
0 0 0 I I 0 0 0 I I 0 0 0 I I
0 0 I 0 I 0 0 I 0 I 0 0 I 0 I
0 I I I I 0 I I I I 0 I I I
The columns of Hare calculated as follows: the first four entries of the first
column are the coefficients in I�l·a0+0·a1+0·a2 +O·a'. the first four
entries of the second column are the coefficients in a= 0· a0 + 1 · a1 + 0 · a2
+ 0 · a3, and so on: the last four entries of the first column are the
coefficients in I �I· a0 + 0 ·a' + 0 · a2 + 0 ·a', the last four entries of the
2. Cyclic Codes 317
second column are the coefficients in a3 = 0 · a0 + 0 · a1 + 0 · a2 + 1 · a3, and
so on. We use a4 +a+ 1 = 0 in the calculations.
Suppose the received vector v = ( v0, ...• v 14) has at most two errors;
for example, e(x) = X01 + xu2 with 0 � a1, a1 � 14, a1 * a1. Then we have
Let 111 = 0:01, 112 = a0l be the error-location numbers, then
s, � �, + �,. s, � �l + ��.
therefore
hence
1 + s,�,-' +(Si + s,s,-')�1' � o.
If two errors occurred, then 11]1 and 1121 are roots of the polynomial
s(x)�l+S1x+(Si+S3S!')x2 (8.4)
If only one error occurred, then S1 ��,and S3 � �l. hence S/ + S3 � 0: that
IS,
s(x) �I+ S1x. (8.5)
If no error occurred. then S 1 � S3 � 0 and the correct code word w has been
received.
To summarize, we first evaluate the syndrome S(v) � Hv T of the
received vector v, then determine s(x) and find the errors via the roots of
s( x ). The polynomial in (8.5) has a root in F 10 whenever S1 ""0. If s( x) in
(8.4) has no roots in F"' then we know that the error e(x) has more than
two error locations and therefore cannot be corrected by the given (15, 7)
code.
More specifically, suppose
v�IOOIIIOOOOOOOOO
is the received word. Then S(v) � ( �:) is given by
For the polynomial s(x) in (8.4) we obtain
s(x) �I +(a2 + a3)x + [1 +a+ a2 + a3 +(I+ a2)(a2 + a3)-']x2
� I + ( a2 + a3) X + (I + a + a3) x 2
We determine the roots of s(x) by trial and error and find a and a7 as roots.
Hence we have 11]1 =a, 1121 = a7, thus 111 = a14, 112 = a8. Therefore, we
318 Algebraic Coding Theory
know that errors must have occurred in the positions corresponding to x8
and x14, that is, in the 9th and 15th position of v. The transmitted code
word must have been
w �I 00 I I I 00 I 00000 I.
The code word w is decoded by dividing the corresponding polynomial by
the generator polynomial g. This gives I+ x3 + x5 + x6 with remainder 0.
Hence the original message was I 00 I 0 I I. D
8.44. Definition. Let b be a nonnegative integer and let a E IF •" be a
primitive nth root of unity, where m is the multiplicative order of q modulo
n. A BCH code over F• of length nand designed distanced, 2.;; d .;; n, is a
cyclic code defined by the roots
of the generator polynomial.
If mU1(x) denotes the minimal polynomial of a' over F •. then the
generator polynomial g(x) of a BCH code is of the form
g(x) � lcm(m1•1(x), mib+ii(x), ... ,m'•+d-li(x)).
Some special cases of the general Definition 8.44 are also important. If
b �I, the corresponding BCH codes are called narrow-sense BCH codes. If
n � qm-I, the BCH codes are called primitive. If n � q-I, a BCH code of
length n over F• is called a Reed-Solomon code.
8.45. Theorem. The minimum distance of a BCH code of designed
distance dis at least d.
Proof The BCH code is contained in the null space of the matrix
a• a'• 0:(11-l)b
ab+l al<b+ IJ o:<n-l}(b+ I)
H�
a.b+d-1 o:l(b+d-2) o:<n-l)(b+d-2)
We show that any d-I columns of this matrix are linearly independent.
Take the determinant of any d-I distinct columns of H, then we obtain
abi1 abi1 Q.biJ_ 1
a<b+ Ili1 a<b+ JJi2 a<b+ IJio�-1
a<b+d-2Ji1 a<b+d-2)12 0:(b+d-2)iJ-I
2. Cyclic Codes
a'•
=ab(i1+i2+···+iJ_1J n (ai1_ai")*0.
1110k<j .;;cJ-l
Therefore the minimum distance of the code is at least d. 319
D
8.4<i. Example. Let m'n(x) � x4 + x +I be the minimal polynomial over
F1 of a primitive element a E F 16. We represent the powers a;, 0 :s;;; i :s;;; 14, as
linear combinations of I, a, a2, a3 and thus obtain a parity-check matrix H
of a code equivalent to the (15, II) Hamming code:
H� �� 0 0 0 I 0 0 I I 0 0 I I �I I 0 0 I I 0 I 0 I I I I 0
0 I 0 0 I I 0 I 0 I I I I
0 0 I 0 0 I I 0 I 0 I I I
�(I a a' a' a• a' a• a' a• a' aw a'' a" a" a\4).
This code can also be regarded as a narrow-sense BCH code of designed
distanced� 3 over f2 (note that a2 is also a root of m'''(x)). Its minimum
distance is also 3, and it can therefore correct one error. In order to decode
a received vector v E IF)', we have to find the syndrome Hv T For this cyclic
(15,11) code the syndrome is given as v(a) in the basis {I, a, a2, a3). It is
obtained by dividing v(x) by m'''(x), say v(x) � a(x)m">(x)+ r(x) with
deg(r(x)) < 4, for then o(a) � r(a); that is, the components of the syn
drome are equal to the coefficients of r(x).
For instance, let
v�OIOIIOOOIOIIIOI,
then r(x) �I+ x, hence
HvT�(IIOO)T�l+a.
Next we have to find the error e with weigbt w(e).; I and having the same
syndrome. Thus we must determine the exponent j, 0.; j.; 14, such that
ai � Hv T In our numerical example j � 4, thus in the received vector v the
fifth position is in error and the transmitted word was
w�OIOIOOOOIOIIIOI. D
8-47. Example. Let q � 2, n � 15, and d � 4. Then x4 + x +I is irreduc
ible over IF2 and its roots are primitive elements ofF 16• If a is such a root,
then a1 is a root, and a3 is then a root of x4 + x3 + x 2 + x + 1. Thus a
320 Algebraic Coding Theory
narrow-sense BCH code with d � 4 is generated by
g(x) � (x4 +x + I)(x4 +x3 +x2 +x + 1).
This is also a generator for a BCH code with d � 5, since a4 is a root of
x4+x+l. The dimension ofthiscodeis 15-deg(g(x))�7. This code was
considered in greater detail in Example 8.43. D
BCH codes are very powerful since for any positive integer d we can
construct a BCH code of minimum distance ;;, d. To find a BCH code for a
larger minimum distance, we have to increase the length n _and hence
increase the number m -that is, the degree of IF,. over IF,. A BCH code of
designed distance d ;;, 2t + I will correct t or fewer errors, but at the same
time, in order to achieve the desired minimum distance, we musf use code
words of great length.
We describe now a general decoding algorithm for BCH codes. Let us
denote by w(x), v(x), and e(x) the transmitted code polynomial, the
received polynomial, and the error polynomial, respectively, so that v(x) �
w(x)+ e(x ). First we have to obtain the syndrome of v,
where S(v) � Hv T � (S,, s,+ I• ... ,Sb+d-2) T'
S, � v ( a1) � w ( al) + e ( al) � e ( a1) for b .; j.; b + d -2.
If r � t errors occur, then
e(x) � L c,x"•.
i-1
where a 1, .... a, are distinct elements of {0, 1,. .. , n -I). The elements 1), � a"•
E IF q"' are called error-location numbers. the elements c; E IF; are called error
values. Thus we obtain for the syndrome of v,
s,�e(al)� L C,1); forb.;j.; b+d-2.
i-1
Because of the computatio nal rules in IF q"' we have
( ' )' ' ' S' � "' C1)J � "' c'1J'" � "' C1J'" � S ) £... I I £... I I £... I I jq•
i=l t=l i=l (8.6)
The unknown quantities are the pairs ( 11,. c;). i = 1. ... ,r, the coordinates S1
of the syndrome S(v) are known since they can be calculated from the
received vector v. In the binary case any error is completely characterized by
the lJ; alone. since in this case all ci are I.
In the next stage of the decoding algorithm we determine the
2. Cyclic Codes 321
coefficients a1 defined by the polynomial identity
'
0(7,-x)� L (-l)'a,_,x1
i= l i=O
=ar-ar--lx+ ... +(-l)raoXr.
Thus o0 =I and o1 .... ,or are the elementary symmetric polynomials in
11t····•11r· Substituting 11i for x gives
(-I)'a,_+(-l)'-1a,_1,,+ ··· +(-l)a1,;-1+,;�o fori�I, ... ,r.
Multiplying by c111( and summing these equations fori� I, ... ,r yields
(-f)' a,� + (-I)'-1 a,_ 1S1+ 1 + · · · + (-I) a1S1+,-1 + s,+, � 0
forj�b,b+l .... ,b+r-1.
8.#J. Lemma. The system of equations
L;c,,f ��. j�b,b+l, ... ,b+r-1,
,-1
in the "nknowns c, is solvable if the 11, are distinct elements of IF; ....
Proof The determinant of the system is
"�
b+l ,,
� ,�,� · · . ,� n ( ,, -,, J * o. o
l'(;i<J'(;r
yfr+r-1
8.49. Lemma. The system of equations
(-I)'a,�+(-I)'-1a,_1S1+1+ ··· +(-l)a1S1+<_1+S,+,�o.
j � b, b + 1, ... ,b + r-I,
in the unknowns ( -1)1a1, i � 1,2, ... ,r, is solvable uniquely if and only if r
errors occur.
Proof The matrix of the system can be decomposed as follows:
s. sb+l sb+r-l
sb+l sb+2 sb+r
�VDVT,
sb+r-1 sb+r sb+2r-2
322
where
'h
v�
,_,
,,
and
C11Jt
0
D�
0 'lz
,_,
,,
0
Cz1J�
0 ,_,
,,
0
0 Algebraic Coding Theory
The matrix of the given system of equations is nonsingular if and only if V
and D are nonsingular. V as a Vandermonde matrix is nonsingular if and
only if the"'' i � l, ... ,r, are distinct and Dis nonsingular if and only if all
the Tl; and C; are nonzero. Both condi tions are satisfied if and only if r errors
occur. 0
We introduce the error-locator polynomial that is closely related to the
considerations above:
i-0
where the a, are as above. The roots of s(x) are '1\'. '12' .... ,TJ;'-In order
to find these roots, we can use a search method due to Chien. First we want
to know if an-I is an error-location number-that is, if a= a-tn-IJ is a root
of s(x). To test this we form
-a1a + a2a2 + · · · + (-I)' a,.a'.
If this is equal to -I, then an-I is an error-location number since then
s(a) � 0. More generally, a•-m is tested form� 1,2, ... ,n in the same way.
In the binary case, the discovery of error locations is equivalent to correct
ing errors. We summarize the BCH decoding algorithm, writing now ,, for
(-l)'a,.
8.50. BCH Decoding. Suppose at most 1 errors occur in transmitting a
code word w, using a BCH code of designed distance d;. 21 + I.
Step 1. Determine the syndrome of the received word •,
S(•) � (s •. s.+, .... sb+a-,)T.
2. Cyclic Codes
Let
Sj= Lc;1J/, b�j�b+d- 2.
i-1 323
Step 2. Determine the maximum number r.;; t such that the system
of equations
Sj+r+Sj+r-1T1+ ··· +Sj'Tr=O, b�j�b+r-1,
in the 'T; has a nonsingular coefficient matrix, thus obtaining
the number r of errors that have occurred. Then set up the
error-locator polynomial
,
s(xl � n (1-�,xl � L v'.
i-1 i-0
Find the coefficients T' from the sj.
Step 3. Solve s(x)� 0 by substituting the powers of a into s(x).
Thus find the error-location numbers �� (Chien search).
Step 4. Introduce the �� in the first r equations of Step l to
determine the error values c;. Then find the transmitted
word w from w(x) � v(x)-e(x).
8.51. Remark. We note that the difficult step in this algorithm is Step 2.
There are various methods to perform this step, one possibility is to use the
Berlekamp-Massey algorithm of Chapter 6 to· determine the unknown
coefficients -r; in the linear recurrence relation for the Sj. D
8.52. Example, Consider a BCH code with designed distance d � 5 that
is able to correct any single or double error. In this case, let b � l, n �IS,
q � 2. If mU>(x) denotes the minimal polynomial of a' over IF2, where the
primitive element a E F 16 is a root of x4 + x + l, then
mn'(x) � m'''(x) � m'.,(x) � m"'(x) � l + x + x4,
m"'(x) � m"'(x) � m'12'(x) � m'9'(x) � l + x + x2 + x3 + x4
Therefore a generator polynomial of the BCH code will be
g(x) � mn'(x)m"'(x) � l + x4 + x6 + x1 + x8.
The code is a ( 15, 7) code, with parity-check polynomial
h(x) � (x" -1)/g(x) � l + x4 + x6 + x1.
We take the vectors corresponding to
g(x ), xg( x), x2g(x), x3g(x ), x4g( x), x'g( x), x6g( x)
324 Algebraic Coding Theory
as the basis of the (I 5, 7) BCH code and obtain the generator matrix
I 0 0 0 I 0 I I I 0 0
0 I 0 0 0 I 0 I I I 0
0 0 I 0 0 0 I 0 I I I
G� 0 0 0 I 0 0 0 I 0 I I
0 0 0 0 I 0 0 0 I 0 I
0 0 0 0 0 I 0 0 0 I 0
0 0 0 0 0 0 I 0 0 0 I
Suppose now that the received word v is
or as a polynomial. I 0 0 I 0 0 I I 0 0 0 0 I 0 0,
v(x) �I+ x3 + x' + x1 + x12 0 0
0 0
0 0
I 0
I I
I I
0 I
We calculate the syndrome according to Step I, using (8.6)
work:
sl�e(a)�v(a)�l.
S2 � e(a2) � v(a') �I,
S3 � e(a3) � v(a3) � a4,
S4 � e ( a4) � v ( a4) � I. 0 0
0 0
0 0
0 0
0 0
I 0
I I
to simplify the
The largest possible system of linear equations in the unknowns 1, (Step 2) is
then of the form
or s,11 + S11, � s,.
S3T1 + S2-r2 = S4•
Tl+T2=a4,
a4T1+T2=1.
This system clearly has a nonsingular coeff icient matrix. Therefore two
errors must have occurred-that is, r = 2. We solve this system of equations
and obtain 11 �I, 12 �a. Substituting these values into s(x) and recalling
To= I gives
s(x)�l+x +ax2
As roots in IF 16 we find 71]1 = o:&, 1Ji-1 = cl', hence 711 = a1, 112 = a9. There
fore, we know that errors ml1St have occurred in positions 8 and 10 of the
code word. We correct these errors in the received polynomial and obtain
w( X) � V (X)-e (X)
�(l+x3+x'+x'+x12)-(x1+x9)
=l+x3+x6+x9+x12.
3. Gappa Codes 325
The corresponding code word is
I 0 0 I 0 0 I 0 0 I 0 0 I 0 0.
The initi�l message can be recovered by dividing the corrected polynomial
-that is, the transmitted code polynomial w(x)-by g(x). This gives
w(x)/g(x) �I+ x' + x4,
which yields the corresponding message word I 00 II 00. D
3. GOPPA CODES
We generalize the narrow�sense BCH codes introduced in Section 2 to obtain
an important class of linear codes which still allow an efficient decoding
algorithm and which are also useful for applications in cryptography (see
Chapter 9, Section 4). These codes meet the Gilbert-Varshamov bound in
Theorem 8.27 at least asymptotically. To motivate the definition of this class
of codes, we first go back to narrow-sense BCH codes and present another
characterization of their code words.
We recall that narrow-sense BCH codes correspond to the special
case b = 1 of Definition 8.44. A narrow-sense BCH code over � 4 of length n
and designed distance d is thus the cyclic code defmed by the roots a,
a:2, ... ,�-I of the generator polynomial, where a:EG=4 ... is a primitive nth root
of unity. We characterize the code words of this code by using an identity
in the polynomial ring � .-[x].
8.53. Lemma. (c0,c1, ... ,c11_J)EIF; is a code word of the narrow-sense
BCH code over�, defined by the roots a, a2, ... , a•-I oft he generator polynomial
if and only if
11-1 xd-1 -a:-i<d-1) "'C·"'l(d-1) 0 L. ,....
I . t=o x-a: (8.7)
Pmof. By definition, (c0, c 1, ... , c,._1) is a code word of the given code if
and only if
•-1
L c1rrY=O for 1 �j�d-1. i=O
On the other hand, we have
11-1 . xd-1_CJ:-1Cd-1l
L CiCJ:i(d-1) i i=O X-CJ: 11-1 d-2 " l(d-1)" -i(d-2-j) J L. Cit>: L. a: X i=O }=0
= ''t' ("'t1 c,ai!)xi-1,
)=I f=O
and so (c 0, c 1, ... , c, _dis a code word if and only if the identity (8. 7) holds. 0
This result provides the motivation for the following definition of
Goooa codes over L
326 Algebraic Coding Theory
8.54. Definition. Let g(x) be a polynomial of degree t, I .;; t < n, over an
extension F,-off,, and let L= {y0, y1, ... ,y,_1) be a set ofn distinct elements
of�,-such that g(y1) # 0 for 0 .;; i.;; n-I. The Goppa code r(L, g) over f, with
Goppa polynomial g(x) is the set of all (c0, c1, ... , c,_1)E�; such that the identity
0 (8.8)
holds in the polynomial ring f ,-[x]. If g(x) is irreducible over F,-, then r(L, g)
is called an irreducible Goppa code.
8.55. Example. If g(x) = x'-1 and L= (a-': i = 0, I, ... , n-1}, where aEf ,
is a primitive nth root of unity, then r(L,g) is a narrow-sense BCH code over f,
of length n and designed distance d. 0
It is clear that r(L,g) is a linear code, since the condition (8.8) defines a
subspace of the vector space f;. We want to find a matrix such that the
intersection of its null space with f; is equal to r(L,g). If
then
g(x)-g(y)
x-y '
g(x)= L gy.i,
J-o
Putting h,=g(y,)-1 for O.;;i.;;n-1, it follows that (c0,c, ... ,c,_1)Ef;
satisfies (8.8) if and only if
,-1( ' )
L h, L g/1/_1_' c, = 0 for 0.;; s .;; t-I.
i=O J-s+l
Therefore r(L,g) is the intersection ofF; with the null space of the matrix
ho�:, h,_1g,
h0(g,_1 +g,yo) h,_1(g,_1 +g,y,_1)
Since g, # 0, we can use row operations to transform this into the matrix ( g(y0)-1 ... g(y,_1)-1 l
H= g(yo):-1Yo ··· g(y,-1):-1Y•-1 ,
g( )-1 •-1 g( )-1.;-1 Yo Yo Yn-l ln-1 (8.9)
for which the intersection of its null space with f; is again r(L,g). The entries of
Hare elements off,-. Each element of�.-has a unique representation in a
fixed basis off,- over f ,. A matrix H' with ent!jesin f, having r(L,g) as its null
3. Gappa Codes 327
space can thus be obtained by replacing each entry of H by the column vector
over f, of length m that we get from the coefficients in that representation.
8.56. Theorem. The dimension of the Goppa code r(L, g) is at least
n -mt and its minimum distance is at least t + 1.
Proof. The matrix H' described above is an mt x n matrix with entries
in F,. Since r(L,g) is the null space of H', the dimension of r(L,g) is at least
n-mt. For the second part consider the determinant of any t distinct columns
of the matrix H in (8.9). After taking out obvious constant factors, such a
determinant reduces to a Vandermonde determinant which is nonzero in
view of the condition that the elements y0, y1, ... , y,_1 are distinct. Therefore
any t columns of H are linearly independent, and so the minimum distance
of r(L, g) is at least t + I. 0
In most applications one works with binary Goppa codes-that is,
Goppa codes over f2. In this case the following improvement on the lower
bound of the minimum distance can be obtained.
8.57. Theorem. For a binary Goppa code whose Goppa polynomial has
no multiple roots, the minimum distance is at least 2t + I.
Proof. If(c0,c1, ... ,c,_1)Ef; is a code word of weight w>O in the
binary Goppa code r(L, g), then c,, � c,, � · · · � c,w � 1 with 0 ,;;; i 1 < i2 < · · ·
< iw,;;; n-1 and all other c, � 0. If L� {y0,y1, .•. ,y,_1},; f2m, define
From (8.8) we obtain w
f(x) = IT (x-Y.,)EF2m[X].
}=l
0 � f(x) 'i:1 c;g{y,)-1 g(x)-g(y,) i=o x-yi
"' w
� L: g(y,r 1(g(x)-g(y,)) IT (x-y,,J.
j=l h=l •• J
Considering the last polynomial modulo g(x), we get
w w
0=- L IT (x-y,,)= -f'(x)modg(x),
j=lh=l hti
and so g(x) divides the derivative f'(x). Since we are working in characteristic
2, f'(x) contains only even powers and is thus the square of a polynomial in
F2m[x]. Now g(x) has no multiple roots by hypothesis, hence it follows that
g(x)2 divides f'(x). Consequently,
w-1 ;;. deg (f'(x));;. 2t,
and so any nonzero code word. has weight at least 2t + I. 0
328 Algebraic Coding Theory
8.58. Example. We describe the binary irreducible Goppa code i(L,g) with
Goppa polynomial g(x) = x' + x +I and L= �. = {0, I, a, ... ,a6), where a is a
primitive element of�. satisfying a3 +a+ I= 0. From Theorems 8.56 and
8.57 we get the following inf ormation on the parameters of this code: length
n = 8, dimension k � n-mt = 2, and minimum distance d � 2t + 1 = 5.
Furthermore, l(L,g) is the intersection of�; with the null space of the matrix
H-(g(0)-1 g(W1 g(a•)-1 ) -g(0)-10 g(l)-11 g(a6)-1a6
=G I a' a• a' a a
,.) I a' a• a' a' a• o'
obtained from (8.9). Using the basis {l,a,a2) of�. over
corresponding binary matrix
I I 0 0 0 0 0 0
0 0 0 0
H'= 0 0 0 0
0 I I
0 0 I 0 0
0 0 0 0 �,. we get the
having l(L,g) as its null space. Since H' has rank 6, we have k = 2, and H' is a
parity-check matrix of l{L,g). The linear (8,2) code i(L,g) consists of the
following four code words:
0 0 0 0 0 0 0 0, 0 0 I I I I I I,
I I 0 0 I 0 I I, I I I I 0 I 0 0.
Thus it has minimum distance d = 5. A generator matrix of this code is
G = (I I 0 0 I 0 I I)· 00111111 0
We discuss now a decoding algorithm for Goppa codes. We note that
if this algorithm is applied in the special case of a narrow-sense BCH code,
then it yields an algorithm that is different from the BCH decoding algorithm
described in Section 2. Let l{L,g) be a Goppa code over �.with Goppa
polynomial g(x) of degree t;;. 2. We suppose for simplicity that Lc; �:m
that is, y, # 0 for 0.;; i.;; n-I. By Example 8.55, this condition is in particular
satisfied for narrow-sense BCH codes. It follows from Theorems 8.12 and
8.56 that l(L,g) can correct up to Lt/2J errors. To correct errors, we take
the received word v and the matrix H in (8.9) and calculate the syndrome
S(v)=HvT =(S0,S1, ... ,S,_1)T (8.10)
If S(v) = 0, then vis a code word and no error correction is needed. If S(v) # 0,
we assume that r errors have occurred, where I .;; r.;; Lt/2J. Let the distinct
3, Goppa Codes 329
elements a1, ••• ,a, of {0, l, ... ,n -I) denote the error locations and Jet
c1, ... , c,EIF; be the corresponding error values. We define the error-location
numbers 1]1='}'411E1Fqm for 1 �i�r.
Decoding means determining the pairs (�,, c1), I .;; i.;; r, given the compo
nents S1, 0 <;;j.;; t-I, of the syndrome. From (8.10) we get
'
S1= L: c,g(�,)-1'11 for O<;;j<;;t-1. /= 1
With these S1 we set up the syndrome polynomial
<-1
f(x) = L S1xi j=O
Furthermore, we need the error-locator polynomial
'
s(x) = TI (I-q1x) i= 1
and the error-evaluator polynomial
' '
u(x) = L: c,g(qr 1 TI (I -,,,x). 1=1 h=1 h'fi
As usual, an empty product is identified with the constant I. We note that u(x)
and s(x) are relatively prime since
'
u(�,-1)=c,g(�,)-1 TI (1-�,�,-1)#0 for l <;;i <;;r. (8.11) h=1 h 'fi
8.59. Lemma. The congruence
u(x): s(x)f(x) mod x'
holds in the ring of polynomials over f,-.
Proof. Since s(O) = I, s(x) has a multiplicative inverse in the ring
f,-[[x]] of formal power series over f,-by Theorem 6.37. Then
u(x) = f c,g(qr 1 s(x) 1=11-q,x ' � L c,g(q,) -1 L qfxl i= 1 j=O
JJ,t1 c,g(•Tr 1'1i)x1 = f(x) + x'B(x)
for some B(x)Ef,-[[x]], and so
u(x) = s(x)f(x) + x'B1(x)
for some B1(x)Ef,m[[x]]. A comparison of terms of sufficiently large degrees
330 Algebraic Coding Theory
shows that B1(x) is actually a polynomial, and this yields the desired
congruence. 0
The congruence in Lemma 8.59 can be solved by using the Euclidean
algorithm (see p. 22) with the polynomials r _1(x) = x' and r0(x) = f(x). This
algorithm yields
r, _ 1 (x) = q>+ 1 (x)r,(x) + r, + 1 (x), deg(r, + 1 (x)) < deg(r,(x)),
forh=O, l, ... ,s-1,
r,_1(x) = q,.1(x)r,(x).
We define recursively the polynomials
z_1(x)=0, z0(x}= 1,
z,(x) = z,_2(x)-q,(x)z,_1(x) for h = 1, 2, ... , s.
The following properties are shown by straightforward induction:
r,(x):z,(x)f(x)modx' for h= -1,0, ... ,s, (8.12)
deg(z,(x))=t-deg(r,_1(x)) for h=0,1, ... ,s. (8.13)
The polynomials s(x) and u(x) are now determined by the following result.
8.60. Lemma. The error-locator polynomial s(x) and the e"or
evaluator polynomial u(x) are given by
s(x) = z,(o)-1 z,(x),
u(x) = z,(o)-1r,(x),
where b is the least index such that deg(r,(x)) < t/2.
Proo( We have deg(s(x)) = r and deg(u(x)),; r-1. If d(x) =
gcd(x', f(x)), then d(x) divides u(x) by Lemma 8.59 and so deg(r,(x)) =
deg(d(x)),; deg(u(x)). It follows that there exists an index h, 0,; h,; s, such
that
deg(r,(x)),; deg(u(x)), deg(r,_1(x));;. deg(u(x)) + 1.
From (8.13) we obtain
deg(z"(x)) = t-deg(r"_1(x)),; t-deg(u(x))-1.
Lemma 8.59 and (8.12) yield
hence u(x) = s(x)f(x) mod x', r1,(x) = z,(x)f(x) mod x',
u(x)z,(x) = r,(x)s(x) modx'.
The polynomial on the left-hand side has degree,; t-1, and the one on the
right-hand side has degree,; deg(u(x)) + r,; 2r-1,; 2Lt/2J-1,; t-1. Thus
we have in fact the identity
u(x)z,(x) = r,(x)s(x). (8.14)
3. Goppa Codes 331
Consequently, u(x) divides r,(x)s(x), and since u(x) and s(x) are relatively prime,
u(x) divides r,(x). But 0.; deg(r,(x)).; deg(u(x)), hence u(x) = f3r1,(x) for some
/JE�: ... It follows then from (8.14) that .•(x) = fJz,(x), and from s(O) =I we get
fJ = z,(0)-1• It remains to show that h =b. Since deg(r,(x)) = deg(u(x)) < t/2,
it is clear that h ;;. b. If we had h > b, then
deg (r, _ 1 (x)) .; deg (r,(x)) < t/2,
and so by (8.13),
Lt/2J ;;. deg (s(x)) = deg (z,(x)) = t -deg (r, _ 1 (x)) > t/2,
a contradiction. 0
We may summarize this decoding algorithm for Goppa codes in the
following way.
8.61. Decoding of Goppa Codes. Suppose at most Lt/2J errors occur in
transmitting a code word w, using a Goppa code l(L, g) over �, with Goppa
polynomial of degree t;;. 2 and Lr;; �: ...
Step 1. Determine the syndrome
S(v) = (S0, S1, ... , S,_1)T
of the received word v by (8.10) and set up the syndrome polynomial
r-1
f(x) = L S;xi.
j=O
If f(x) = 0, no errors have occurred, so w = v.
If f(x) # 0, proceed to Step 2.
Step 2. Carry out the Euclidean algorithm with r _1(x) = x' and r0(x) = f(x)
and stop as soon as deg(r,(x)) < t/2. Put
s(x) = z,(0)-1 z,(x), u(x) = z,(0)-1r,(x).
Step 3. Determine the error-location numbers �� as the multiplicative
inverses of the roots of s(x).
Step 4. Determine the error values c, from (8.11)-that is,
'
c,= u(�,-1)g(�,) IT (1-�,�,-1)-1.
h=l
h1i
Subtract c, from the component of vindicated by the error-location
number �� to obtain the transmitted word w.
8.62. Example. We solve the decoding problem in Example 8.52 by the
decoding algorithm for Goppa codes. According to Example 8.55, the narrow
sense BCH code in Example 8.52 is equal to the binary Goppa code l(L, g)
with g{x) = x4 and L= {y0, y, ... , y14}, where y1 =IX_, for 0.; i.; 14 and IZE� 16
332 Algebraic Coding Theory
is a root of x4 + x + I. Let the received word • be
I 0 0 I 0 0 I I 0 0 0 0 I 0 0.
Using the 4 x 15 matrix H obtained from (8.9), we get the syndrome
S(•)�H•' �(S0,S1,S2,S3)7
with
S0=1, S1=o:4, S2=1, S3=1.
This leads to the syndrome polynomial
f(x) � x3 + x2 + a4x + I.
Now carry out the Euclidean algorithm with r _1(x) � x4 and r0(x) � f(x) and
stop as soon as deg(r,(x)) < 2. This yields
x4 � (x + i)(x3 + x2 + a4x +I)+ (ax'+ ax+ 1),
x3 + x2 + a4x +I� a14x(ax2 +ax+ I)+ (a9x + 1).
Thus b � 2 and s(x) � z2(0)-1 z2(x). Since q1(x) � x + I and q2(x) � a14x, we
calculate recursively
z_ 1(x) = 0, z0(x) =I,
z1 (x) � z_ 1(x)-q1(x)z0(x) = x + I,
z,(x) = z0(x)-q2(x)z1(x) = a14x2 + a14x +I.
Therefore
s(x) = a14x2 + a14x + I.
The roots of s(x) are a7 and a9, hence �1 = a-1 = y1 and �2 = a-• = y9. It
follows that the errors have occurred in positions 8 and 10 of the transmitted
code word. By observing that for a binary code the corresponding error values
can only be c1 = c2 = I, or by a direct calculation of c1 and c2 from the formula
in Step 4 of 8.61 with u(x) = z2(0)-1r2(x) = a9x +I, we find the transmitted
code word
I 0 0 I 0 0 I 0 0 I 0 0 I 0 0
in accordance with the result in Example 8.52. 0
EXERCISES
8.1. Determine all code-words, the minimum distance, and a parity-check
matrix of the binary linear (5, 3) code that is defined by the generator
matrix
G= (� 1
0
0 0
1
0 0
0
1 ! ) .
Exercises 333
8.2. Prove: a linear code can detect s or fewer errors if and only if its
minimum distance is � s + I.
8.3. Prove that the Hamming distance is a metric on IF;.
8.4. Let H be a parity-check matrix of a linear code. Prove that the code
has minimum distance d if and only if any d-l columns of H are
linearly independent and there exist d linearly dependent columns.
8.5. If a linear (n, k) code has minimum distanced, prove that n-k + l
;. d (Singleton bound).
8.6. Let G1 and G2 be generator matrices for a linear (n1, k) code and
(n2,k) code with minimum distance d1 and d2, respectively. Show
that the linear codes with generator matrices (�I O ) and (G1, G2) G,
are (n1 +n2,2k) codes and (n1 +n2,k) codes, respectively, with
minimum distances min(d1, d2) and d;. d1 + d1, respectively.
8.7. Prove: given k and d, then for a binary linear (n, k) code to have
minimum distanced= d0 we must have
n>do+dl + ... +dk-1•
where d,+1 � l(d, + l)/2J fori� 0, l, ... ,k -2. Here lxJ denotes
the largest integer :s;,; x.
8.8. A code C �IF; is called perfect if for some integer t the balls B,(c) of
radius t centered at code words care pairv.;i_se disjoint and "fill" the
space F; -that is,
U B,(c) � F;.
<EC
Prove that in the binary case all Hamming codes and all repetition
codes of odd length are perfect codes.
8.9. Using the definition of Exercise 8.8, prove that all Hamming codes
over IF q are perfect.
8.10. Two linear (n, k) codes C1 and C2 over IF• are called equivalent if the
code words of C1 can be obtained from the code words of C2 by
applying a fixed perm utation to the coordinate places of all words in
C2• Let G be a generator matrix for a linear code C. Show that any
permutation of the rows of G or any permutation of the columns of
G gives a generator matrix of a linear code which is equivalent to C.
8.11. Use the definition of equivalent codes in Exercise 8.10 to show that
the binary linear codes with generator matrices
I
I
0
respectively. are equivalent. 0
l
0 I
I
0
334 Algebraic Coding Theory
8.12. Let C be a linear (n, k) code. Prove that the dimension of C" is
n-k.
8.13. Prove that ( C " ) " � C for any linear code C.
8.14. Prove ( C1 + C2)" � C/ n C," for any linear codes C1, C2 over IF, of
the same length.
8.15. If C is the binary (n, l) repetition code, prove that C" is the
( n, n -l) parity-check code.
8.16. Determine a generator matrix and all code words of the (7,3) code
which is dual to the binary Hamming code C3.
8.17. Determine the dual code C" to the code given in Exercise 8.1. Find
the table of cosets of IFi modulo C ",determine the coset leaders and
syndromes. If y � 01001 is a received word, which message was
probably sent?
8.18. Apply Theorem 8.32 to the binary linear code C � {000,0 ll, 10 l, I 10};
that is, find its dual code, determine the weight enumerators, and
verify the MacWilliams identity.
8.19. Let C be a binary linear (n, k) code with weight enumerator
and let "
A(x, y) � L A,x'y"-'
j = 0
n
A"(x,y)� L A,"xy-•
i-0
be the weight enumerator of the dual code C ". Show the following
identity for r � 0, l, ... :
where t i'A,� t (-l)'A/ t t!S(r,t)z•-t:::;).
1-0 1-0 r-0
S(r.t)�J, t (-l)'-'(1)}'
I. J-0 }
is a Stirling number of the second kind and the binomial coefficient ( �) is defined to be 0 whenever h > m or h < 0. Write down the
identity for r � 0, l, and 2.
8.20. Let n � ( qm - l )/(q-l) and fJ a primitive nth root of unity in F ,.,
m;, 2. Prove that the null space of the matrix H � (l fJ {J2 • · ·
{J" -I) is a code over IF, with minimum distance at least 3 if and only
ifgcd(m,q-l)�l.
8.2!. Let a be a primitive element of F9 with minimal polynomial x2-x-l
over IF3. Find a generator polynomial for a BCH code of length 8
and dimension 4 over F 3. Determine the minimum distance of this
code.
Exercises 335
8.22. Find a generator polynomial for a BCH code of dimension 12 and
designed distance d � 5 over IF 2.
8.23. Determine the dimension of a 5-error-correcting BCH code over IF 3
of length 80.
8.24. Find the generator polynomial for a 3-error-correcting binary BCH
code of length 15 by using the primitive element a of F 16 with
a4 = a3 +I.
8.25. Determine a generator polynomial g for a (31,31-deg(g)) binary
BCH code with designed distance d � 9.
8.26. Let m and t be any two positive integers. Show that there exists a
binary BCH code of length 2m -I which corrects all combinations of
t or fewer errors using not more than mt control symbols.
8.27. Describe a Reed-Solomon (15, 13) code over IF 16 by determining its
generator polynomial and the number of errors it will correct.
8.28. Prove that the minimum distance of a Reed-Solomon code with
generator polynomial
is equal to d. d-l
g(x)�O(x-a')
i=l
8.29. Determine if the dual of an arbitrary BCH code is a BCH code. Is
the dual of an arbitrary Reed-Solomon code a Reed-Solomon code?
8.30. Find the error locations in Example 8.43, given that the syndrome of
a received vector is (10010110?. Find a generator matrix for this
code.
8.31. Let a binary 2-error-corr ecting BCH code of length 31 be defined by
the root a of x5 + x2 + 1 in IF_'2· Suppose the received word has the
syndrome (I I I 00 I I I 0 I )T Find the error polynomial.
8.32. Let a be a primitive element of I' 16 with a4 �a+ I, and let g(x) �
x10 + x8 + x5 + x4 + x2 + x +I be the generator polynomial of a
binary (15, 5) BCH code. Suppose the word v � 000 I 0 I I 00 I 000 I I
is received. Determine the corrected code word and the message
word.
8.33. A code Cis called reversible if (a0,a1, ••• ,a,_1)EC implies
(a, 1 •••• ,a1.a0)EC. (a) Prove that a cyclic code C�(g(x)) is
reversible if and only if with each root of g(x) also the reciprocal
value of that root is a root of g(x). (b) Prove that any cyclic code
over F q of length n is reversible if -I is a power of q modulo n.
8.34. Given a cyclic (n, k) code, a linear (n-m, k-m) code is obtained
by omitting the last m rows and columns in the generator matrix of
the cyclic code described prior to Theorem 8.36. Show that the
resulting code is in general not cyclic. but that it has at least the same
minimum distance as the original code. (Note: Such an (n- m,
k-m) code is called a shortened cyclic code.)
336 Algebraic Coding Theory
8.35. Let !(L,g) be a Goppa code over �. with L� {l•0,)'1, ...• y,_1} <::: � •• ".
Prove that (c0, c1, ... ,c,_1)E�; is a code word ofl(L,g) if and only if the
congruence
'-1
I _c'-=0 modg(x) i=ox-yi
holds, where 1/(x-y,) is interpreted as the multiplicative inverse of
x-y, in the residue class ring �,m[x]/(g).
8.36. Let !(L,g) be a Goppa code over �. whose Goppa polynomial of
degree t has t distinct roots p 1, ... , p, in a suitable extension of�,-, and
let L� { y0, y1, ... , y, _1} <::: � ,-. Prove that !(L, g) is the intersection of
�;with the null space of the t x n matrix whose entry in thejth row and
ith column is ({3i-y1_ tl-1 for 1 �j � t, 1 � i � n.
8.37. Prove that the minimum distance of a binary irreducible Goppa code
with Goppa polynomial of degree t is at least 2t + I.
8.38. Determine the dimension of the binary Goppa code l(L,g) with
L� �!6, g(x) � x2 + x + �3, and� a primitive element of �16.
8.39. Determine the dimension of the binary Goppa code 1(L, g) with
L� f 16 and g(x) � x3 + x + I. Find also a generator matrix for this
code.
8.40. Determine the transmitted code word in Exercise 8.32 by the algorithm
in Section 3.
8.41. Determine the transmitted code word m Example 8.43 by the
algorithm in Section 3.
8.42. Determine the transmitted code word m Example 8.46 by the
algorithm in Section 3.
8.43. Let r _1(x) and r0(x) be two nonzero polynomials over a field F with
deg(r _1(x));;. deg(r0(x)). The Euclidean algorithm yields
r,_1(x) � q,+ 1(x)r,(x) + r,+ 1(x), deg(r>+ 1(x)) < deg(r,(x)),
forh=0,1, ... ,s-1,
r,_ 1 (x) � q,. 1 (x)r ,(x).
Define recursively the polynomials
z_1(x) � 0, z0(x) �I,
z,(x) � z,_ 2(x)-q,(x)z,_1(x) for h � I, 2, ... , s.
Prove the following properties:
(a) r,(x)=z,(x)r0(x) modr_1(x) for h�-I,O, ... ,s;
(b) z,(x)r,_1(x)-z,_1(x)r,(x) � (-l)'r _1(x) for h � 0, 1, ... ,s;
(c) deg(z,(x)) � deg(r _1(x))-deg(r,_1(x)) for h � 0, l, ... ,s.
8.44. An alternant code A over �, is defined as follows. Let h 1, ... , h, be
arbitrary elements of [F: m aHd let 0:1, ... , O:n be distinct elements of [F q"'·
Fix an integer t with 1 � t < n. Then A consists of all vectors in [F: that
are in the null space of the t x n matrix
Exercises 337
hl h, h,
hlet.l h2a2 h,a,
h1ai h2et.� h,a;
h r-1 1a1 h t-1 ,�, h,�-1
Show that any Goppa code is an alternant code. Prove that the
dimension of A is at least n-mt and that its minimum distance is at least
t +I.
Chapter 9
Cryptology
In this chapter we consider some aspects of cryptology that have received
considerable attention over the last few years. Cryptology is concerned with
the designing and the breaking of systems for the communication of secret
information. Such •ystems are called cryptosystems or cipher systems or
ciphers. The designing aspect is called cryptography, the breaking is referred to
as cryptanalysis. The rapid development of computers, the electronic
transmission of information, and the advent of electronic transfer of funds all
contributed to the evolution of cryptology from a government monopoly that
deals with military and diplomatic communications to a major concern of
business. The concepts have changed from conventional (private-key) cryp
tosystems to public-key cryptosystems that provide privacy and authenticity
in communication via transfer of messages. Cryptology as a science is in its
infancy since it is still searching for appropriate criteria for security and
measures of complexity of cryptosystems.
Conventional cryptosystems date back to the ancient Spartans and
Romans. One elementary cipher, the Caesar cipher, was used by Julius Caesar
and consists of a single key K = 3 such that a message M is transformed into
M + 3 modulo 26, where the integers 0, I, ... , 25 represent the letters A, B, ... ,
Z of the alphabet. An obvious generalization of this cipher leads to the sub
stitution ciphers often named after de Vigenere, a French cryptographer of the
16th century. Mechanical cipher devices based on such cryptosystems started
to appear in the 19th century and were widely used in both World Wars.
338
1. Background 339
Significant advances in cryptanalysis, for instance the breaking of the German
ENIGMA cipher in World War II, have led to the necessity of developing
more sophisticated cryptosystems, some of which will be described in this
chapter.
In Section I a general background on cryptology is given and the
distinction between conventional and public-key cryptosystems is discussed.
The most secure cryptosystem is the one-time pad in which a random string of
bits is added modulo 2 to a binary message. Since this requires very long keys,
one has come up with the notion of a stream cipher in which a shorter key
generates long strings of bits. This concept is studied in more detail in
Section 2.
Some very recent developments in cryptography are based on the use of
discrete exponentiation in finite fields. A scrutiny of these cipher systems from
the viewpoint of the cryptanalyst leads to a study of the inverse function-that
is, the index or discrete logarithm in finite fields. In particular, it becomes
necessary to analyze the computational complexity of the discrete logarithm.
Various applications of discrete exponentiation and discrete logarithms to
cryptology and several algorithms for the calculation of discrete logarithms
are presented in Section 3. Two more cryptosystems, one based on Goppa
codes and one on polynomial interpolation in finite fields, are discussed in
Section 4.
I. BACKGROUND
Cryptosystems are designed to transform plaintext messages into ciphertexts.
The particular transformations applied at any given time are controlled by the
key of the cryptosystem used at that time. In conventional cryptosystems this
key is supposed to be known to both the legitimate sender and the legitimate
receiver, but not to the attacker (or cryptanalyst) who wants to break the
cryptosystem.
The general structure of a cryptosystem can be described as follows. The
main ingredients are an enciphering scheme E (for encryption), a deciphering
schemeD (for decryption), a key K, the plaintext message (or simply plaintext
or message) M, and the ciphertext C. Given a plaintext message Manda key K,
the enciphering scheme produces the ciphertext C = EK(M) which is trans
mitted. The deciphering scheme recovers M by DK(C) = M. One basic
requirement is that EK be injective-that is, EK should transform distinct
messages into distinct ciphertexts. In this notation the parameter K remains
fixed for a considerable number of messages. If only one key K is involved, the
system is called a conventional (or single-key) cryptosystem.
An attacker is assumed to have full knowledge of the general form of
the enciphering and deciphering schemes, has access to a number of plaintext
ciphertext pairs produced by the cryptosystem, and has additiona l inform-
340 Cryptology
FIGURE 9.1 A cryptosystem.
ation such as language statistics (letter frequencies and so on) and an idea
about the general context of the communication. The attacker does not
know the key K and has the task to produce the best estimate M' of M.
Breaking a system means determining the key K.
As most current data are stored, transmitted, and processed in binary
form, cryptosystems over the binary alphabet f2 = {0,1} are of particular
importance, but other alphabets such as IF, are also possible. Thus both
plaintext and ciphertext are often given in the form of a string ofO's and 1's (or
bits). If the plaintext string is broken into blocks of fixed length and then
enciphered on a block-by-block basis, the correspondi;1g scheme is called
a block cipher. In this chapter-as in this whole book-we are mainly
interested in material directly connected with finite fields, and accordingly we
will be concentrating on certain types of cryptosystems. However, we mention
one of the commercially widely used block ciphers, the DES (Data Encryption
Standard), which is the official system adopted by the National Bureau of
Standards of the United States and used by most U.S. Federal Departments. It
is a cryptosystem with 64-bit data blocks and a 64-bit key; 56 bits of the key are
true key bits, the remaining 8 bits are used for error detection.
The main disadvantage of conventional cryptosystems is that they
require the advance establishment of a secret (or private) key between every
pair of correspondents. This makes proper management of the keys a crucial
problem for the security of the system. Key management is increasingly
difficult if a large number of correspondents are involved in a communication
system, because then it will be even harder to ensure key secrecy. In 1976 Diffie
and Hellman suggested how to overcome some of these problems by
introducing public-key cryptosystems. Public-key cryptosystems ensure that
subscribers who have never met or communicated before could have instant
secure communication. In general terms, each subscriber places an encipher
ing procedure E into a public directory to be used by other subscribers while
keeping secret his corresponding deciphering procedure D. These procedures,
applied to message M or ciphertext C, must have the following properties:
(i) If C = E(M), then M = D(C); hence
D(E(M)} = M for each M.
(ii) E and D must be fast and easy to apply.
(iii) E can be made public without revealing D-that is, deriving D from E
must be computationally infeasible.
For instance, if A wants to send a message M to B, he looks up B's public
1. Background 341
enciphering method £8 and transmits C = £8(M) toBin the open. Only B can
decipher C, since only B knows the secret deciphering method D8 to apply to
c.
Privacy or security of messages is not the only problem area in
cryptology. It is also important that the correspondents or subscribers can be
authenticated. For example, A has to be able to convince B that it is really
from A the message came. The log-on procedure on computers is also an
obvious example of authentication. The problem area of authentication or of
digital signatures is increasingly important as computer networks, electronic
mail, and similar communication systems grow. Digital signature features can
be attained by public-key cryptosystems if we add a fourth property:
(iv) D can be applied to every M, and if S = D(M), then M = E(S); hence
E(D(M)) = M for each M.
With this property, subscriber A can sign his message to B by first forming his
message-dependent signatureS= D ,(M) and then computing C = £8(S). Only
B can recover S by applying the secret deciphering method D8 to C. Then B
computesE,(S) =EA(DA(M)) =M, by using A's public enciphering method EA.
Now B can be satisfied that M came from A since no other person would have
used A's secret deciphering method D, to compute S= D,(M).
Public-key cryptosystems can be implemented by using trapdoor one
way functions. A function f is said to be one-way iff is easy to compute and
invertible, but it is computationally infeaSible to compute the inverse function
f -1 from a complete description of f. A function f is trapdoor one-way iff-1
is easy to compute once certain private trapdoor information is known, but
without this information f would be one-way. An example of a trapdoor one
way function is contained in the RSA cryptosystem (see Section 3); it is based
on exponentiation and the difficulty of factorization of integers. Another
trapdoor one-way function is based on the difficulty of the general decoding
problem for linear error-correcting codes (see the Goppa-code cryptosystem
in Section 4).
A major problem area in cryptology is to find appropriate criteria for
the complexity of a cryptosystem that will replace the present unsatisfactory
method of "certifying" a cryptosystem as secure through heuristics or
concentrated man/com puter years of efforts rather than rigorous proof.
Computational complexity theory seems to offer a suitable framework for
doing that, since there one can classify problems as "hard". A problem is said
to belong to the class P (for polynomial time) if there exists a deterministic
algorithm that will solve every instance of the problem in a running time
bounded by some polynomial in the number of bits needed for the binary
representation of the problem parameters. Problems that can be solved in
polynomial time by a nondeterministic algorithm-that is, by an algorithm in
Which random choices are allowed in each step-make up the class NP (for
342 Cryptology
nondeterministic polynomial time). Clearly, P is a subclass of NP. It is a
fundamental open question of complexity theory whether P = NP. Particular
ly interesting problems in the class NP from the viewpoint of complexity
theory are the NP-complete problems, which have the property that if any one
problem of the NP-complete class is found to be in P, then all ofNP belongs to
P. Examples of NP-complete problems are the graph coloring problem, the
traveling salesman problem, and the knapsack packing problem.
The security of public-key cryptosystems is based on the comput
ational infeasibility of performing certain tasks-su ch as factoring integers,
decoding linear codes, or finding discrete logarithms in finite fields-with the
best algorithms and the best hardware publicly available. Of course, there may
be secret advances in software or hardware we do not know about.
2. STREAM CIPHERS
The simplest and most secure of all cryptosystems is the one-time pad. Suppose
the message is given as a string of bits-that is, of elements of �2. Then a long
random string of bits is formed; this is the key which is known to sender and
receiver. The sender adds this key to the message, using addition in �2. At the
receiving end the key is again added in �2 to the enciphered message to recover
the original message. The key string must be at least as long as the message
string and is used only once. This is a perfect, unbreakable cipher since all the
different key strings and all possible messages are equally likely. The major
disadvantage of this cryptosystem is that it requires as much key as there is
data to be sent. So it is restricted to sending only important messages.
In a stream cipher one uses a much smaller key as the seed to produce
longer key strings-or even infinite key sequences-which are then added to
the message string. One possibility is to use feedback shift registers where
certain initial values suffice to produce infinite linear recu�ring sequences in IF 2
(compare with Chapter 6, Section 1). Before we consider a specific crypto
system, we list some general properties a stream cipher should have:
(i) The number of possible keys must be large enough so that an exhaustive
search for the key is not feasible.
(ii) The infinite sequences must have a guaranteed minimum length for their
periods which exceeds the length of the message strings.
(iii) The ciphertext must appear to be random.
There are a number of properties a random sequence ofbits should satisfy. We
refer to Chapter 7, Section 4, for more details.
On first glance it would seem that certain homogeneous linear
recurring sequences CJ in �2 are good candidates for key sequences. We know
from Theorem 6.33 that if the characteristic polynomial of CJ is primitive over
�2 of degree k and CJ is not the zero sequence, then CJ has least period 2•-1,
which can be made arbitrarily large ask varies. There are many such primitive
2. Stream Ciphers 343
polynomials available, namely </>(2' -1)/k. These maximal period sequences "
(see Definition 6.32) of least period 2'-1 satisfy the basic randomness
requirements imposed on sequences, as we have shown in Chapter 7,
Section 4. Nevertheless, linear recurring sequences are not suitable for
constructing secure cryptosystems, since it follows from the discussion on
p. 231 that if we know that such a sequence has a characteristic polynomial
of degree ,;; k, then any 2k consecutive terms determine a characteristic
polynomial and thus the entire sequence. In spite of the proven insecurity of
this cryptosystem, it is quite popular, perhaps because the large periods 2'-1
create an illusion of strength.
Because of this weakness of linear recurring sequences, we have to
consider pseudorandom generators of higher complexity. One possibility is to
increase complexity by appropriately combining linear recurring sequences.
We shall only describe one such approach, namely the construction of
multiplexed sequences which may be used as building blocks in a cryptosystem
in the category of stream ciphers. Here a multiplexer, which is a many-input
one-output system, is used to produce a multiplexed sequence from two given
linear recurring sequences. The construction can be carried out over any finite
prime field f,.
9.1. Definition. A multiplexed sequence u0, u1, ... in !F P is constructed as
follows:
(i) Let s0, s,,. .. be a kth-order and t0,t,,. .. an mth-order maximal period
sequence in !F P" . _
(ii) Choose an integer h in the range I ,;; h ,;; k such that p' ,;; m if h < k and
p' -I ,;; m if h � k.
(iii) Choose integers j,, ··· ,j, with 0 .;;j, <j1 < ··· <j,,;; k-I.
For n = 0, 1, ···consider the h-tuple (sn+ j1, • • ·, sn+ i,) of elements of !F P and
interpret it as the digital representation in the base p of an integer b.EI,,
where
I,�{O,I,···,p'-1)
I,�{l,2,···,p'-1) if h <k,
if h �k.
(iv) Choose an injective mapping 1/1 from I, into {0, I, ··· ,m -I).
(v) With these choices of h ,j1, ••• ,j,, and 1/1 we set
un = t11+tJt(b.,l for n = 0, 1, ....
Some comments on this definition are in order. We note that, if h < k,
then all elements of f� appear among the h-tuples (s.+ 1,, · · ·, '•+ ;.) as n
varies from 0 to p'-2, and so b. runs exactly through the values in I,. If
h � k, then necessarily j1 � i-1 for I ,;; i,;; k, and the k-tuples (s., · · ·, '•+k-1)
are just the state vectors of the sequence s0, s1, ···;the fact that b. runs exactly
through the values in I, follows therefore from Theorem 7.43. We note also
344 Cryptology
that the existence of an injection 1/1 in (iv) is guaranteed by the condition on min
(ii). The definition in (v) says that we obtain the multiplexed sequence by
scrambling the terms of the sequence t0, t 1, ···in a way that is controlled by the
sequence s0, s1• ···.
9.2. Example. Let p�2, and let s0,s1,··· and t0,t1,··· be the maximal
period sequences in IF2 with
forn=O,l,···,
for n � 0, I, · · ·,
and initial state vectors (1, 0, 0) and (I, 0, 0, 0), respectively. The first sequence
has least period 7 and the terms in the period are
0 0 0 I.
The second sequence has least period 15 and the terms in the period are
0 0 0 0 0 0 0.
Now choose h � 2, j1 � 0, j2 �I, and define the injective mapping 1/1 from
(0, I, 2, 3} into itself by
1/J(O) �I, 1/1(1) � 2, 1/1(2) � 3, 1/1(3) � 0.
The sequence b0, b1, · · · of integers in Definition 9.1(iii) has least period 7 and
the terms in the period are
2 0 2 3 3.
Consequently, the first few terms of the multiplexed sequence u0, u 1, ... are
0 0 0 0 0 0 0 0···.
The diagrammatic representation of the two feedback shift registers and the
multiplexer is given in Fig. 9.2. The delay elements of the first feedback shift
register are labeled by A0, A1, A2 and those of the second feedback shift
register are labeled by B0, B1, B2, B3. D
A, A, A,
Multiplexer
Output u11
FIGURE 9.2 The switching circuit for Example 9.2.
2. Stream Ciphers 345
9.3. Theorem. The multiplexed seque11ce u0, u1, ··· is periodic and its
least period divides lcm(p'- 1, pm-1).
Proof Put r � lcm(p'- 1, p'"-1). Since r is a multiple of the period
p"-1 ofs0,s1, .. ·,wehave
and so b, � b,+, for all 11;;. 0. Since r is a multiple of the period pm-1 of
t0, t1, · .. ,we obtain
for all n ;;. 0. The rest follows from Lemmas 6.4 and 6.6. D
The following property of certain decimations of multiplexed se·
quences can be applied to obtain further information on the least period. We
use again the notation for decimations introduced in Chapter 7, Section 4-
that is, if a is a sequence with terms s0, s1, ···,then the decimated sequence af.jl
is obtained by taking every dth term of o, starting from s,.
9.4. Lemma. If v denotes the multiplexed sequence u0, u1, · · · and r
denotes the sequence t0, t,, ... in Definition 9.l(i), then
for i � 0, 1, .. ·,
where d � p'-1 and j(i) = i + lji(b,).
Proof The terms of v�l are the elements u·���+i• n = 0, 1, ···. Since
d � p'-1 is the least period of the sequence s0, s1, ··· in Definition 9.1(i), we
have b,d+, � b, by the construction in Definition 9.1(iii), and so
for all n ;;. 0, which is the desired result. D
9.5. Lemma. For any integers a;;. 2, k;;. 1, and m;;. 1 we have
gcd(a'- 1, am-l)�a"d(k .m)_[.
Proof If b � gcd (k, m), then it is clear that a'-1 divides
c � gcd («'-1, am-1). Now write k � dm + e with integers d;;. 0 and 0;;;; e
<m. Then
a'-1 � (a'm-1)a' +(a'-1),
and soc divides a'-1. Continuing this process in analogy with the Euclidean
algorithm for k and m, we find that c divides a' -1, hence c � a'-1. D
9.6. Theorem. Ifgcd (k, m) � 1, then the least period of the multiplexed
sequence u0, u1, ···is a multiple of ( pm-1)/(p-1).
Proof We apply Lemma 9.4 with i � 0. Then vl01 � r�1 with d = p'-1
and j = j(O). Put K = � P and F = � P m. Since r is an mth-order maximal period
sequence in K, it follows from Theorem 6.24 that there exists a primitive
PlPTnPnt rt nf J<' �nrl � IJc::. J<'* Clllf'h th�t
346 Cryptology
The terms w, oft�) are thus given by
w, = t,<+ J = Tr,1K(y{3") for n = 0, I,···, (9.1)
where fJ = a'EF* andy= GaJEF* By Theorem 1.15(ii), the order of fJ in the
multiplicative group F* is
gcd(p'-l,pm-1) pm-1
p-1'
where we used Lemma 9.5 and the hypothesis gcd (k, m) = I in the last.step. Let
f(x) be the minimal polynomial of fJ over K. Then it follows from (9.1) and the
calculation in the proof of Theorem 6.24 that f(x) is a characteristic
polynomial of the linear recurring sequence tY'. We claim that <Y' is not the
zero sequence. We have
m I � �pm-1
p-l r . (9.2)
Furthermore, the elements yfJ", 0.;; n < (pm-1)/(p-1), are (pm-l)f(p-I)
distinct elements ofF*. Since there are just pm-1-l elements �EF* with
Tr,1��) = 0 by Theorem 2.23(iii), it follows from (9.1) and (9.2) that
w, = TrF/K(yfJ") # 0 for some n. Thus, indeed, t�' is not the zero sequence, and
since f(x) is irreducible over K by Theorem 3.33(i), the least period of t�1 is
equal to ord (f(x)) = (pm-1)/(p-I) according to Theorems 6.28 and 3.3. Ifr is
the least period of u0,u1, .•. , then r is a period of the decimated sequence
vl0' = t�>, and so Lemma 6.4 shows that r is divisible by (pm-l)f(p-1). D
It can be proved that if p = 2, gcd (k, m) = I, and m > I, then the least
period of the multiplexed sequence u0, u1, ... is equal to (2'-!)(2m-1). For
instance, the least period of the multiplexed sequence in Example 9.2 is equal
to (23-1)(24-I)= 105.
As to the application of multiplexed sequences in stream ciphers, it
appears that such sequences may be quite complex, but further research will be
needed in order to establish that their complexity is sufficiently high.
3. DISCRETE LOGARITHMS
Let b be a primitive element of�. and let a be a nonzero element of� •. Then
the index of a with respect to the base b is the uniquely determined integer
r, 0.;; r < q-I, for which a= b'. We use the notation r = ind,(a), or simply
r = ind (a) if b is kept fixed. The index of a is also called the discrete logarithm of
a. The discrete exponential function exp,(r) = exp (r) = b' and the discrete
logarithm form a pair of inverse functions of each other; compare also with
Chapter 10, Section I. Their use for cryptography depends on the apparent
one-way nature of the discrete exponential function: it is easy to compute, but
appears hard to invert.
3. Discrete Logarithms 347
The discrete exponential function exp (r) = b' in 0', can be calculated for
1 ,; r < q-1 by an analog of the repeated squaring technique discussed after
Theorem 4.13, which is often called the square and multiply technique in the
present context. In detail, we first compute the elements b, b2, b4, · · ·, b2' by
repeated squaring, where 2' is the largest power of 2 that is ,; r. Then b' is
obtained by multiplying together an appropriate combination of these
elements. For instance, to get b21 one would multiply together the elements b,
b2, b8, and b16 A simple analysis shows that the calculation of b' requires at
most 2Llog2 qj multiplications in 0',, where log2 denotes the real logarithm to
the base 2.
Until recently, the inverse problem of computing discrete logarithms in
0', was believed to be much harder, since for one of the best algorithms
available then the required number of arithmetic operations in D', was of the
order of magnitude q11'-If q is sufficiently large, say q > 2100, exponentiation
in 0', might justly have been regarded as a one-way function. However, great
progress has recently been achieved in the computation of discrete logarithms,
which makes it necessary to construct cryptosystems based on discrete
exponentiation in a careful manner in order to protect them against attacks by
these recent algorithms. We now describe some cryptographic applications of
discrete exponentiation and then present some discrete logarithm algorithms.
9.7. Example. The following is a cryptosystem for message transmission in
0',. Let M, K, and C denote the plaintext message, the key, and the ciphertext,
respectively, where M, CED'i, K is ·an integer with 1,; K,; q-2 and
gcd (K, q -1) = 1, and q is a large prime power. The last condition on K makes
it possible to solve the congruence
KD = 1 mod(q-1)
for the integer D. We encipher by computing
C=MK
and decipher by
CD=M. (9.3)
(9.4)
(9.5)
Both operations are easily performed. To find the key, however, is as hard as
finding discrete logarithms since (9.4) is equivalent to
K ind(M) = ind(C)mod(q -1). (9.6)
Even if we know a plaintext-ciphertext pair M and C, computing K can be
expected to be difficult for large q. From (9.6) we see that M must be a primitive
element of 0', so that M and C determine K uniquely. We also observe that
there is a wide choice for the key K since for q > 2 there are </>(q -1) integers K
that satisfy 1;,; K,; q -2 andgcd( K,q-1) = l.Primesoftheformq = 2p+ I,
p also a prime, are the most promising values of q to use in order to get a secure
348 Cryptology
system. For primes q we may view M and Cas integers with 1 .; M, C.; q-1,
and then (9.4) and (9.5) are replaced by the congruences
C=MKmodq, CD=Mmodq. 0
The cryptosystem in Example 9.7 can be made into a new system by
replacing congruences modulo a large prime q by congruences modulo a
product n of two large primes p and q. Such a cryptosystem was proposed by
Rivest, Shamir, and Adleman and is now known as the RSA cryptosystem.
Instead of using (9.3), we now find D from
KD = 1 mod tj>(n) (9.7)
in this generalized system, where we assume gcd(K, tf>(n)) =I. The security of
the RSA cryptosystem is based on keeping the factors of n secret and depends
on the difficulty of factoring large integers into primes. Normally n would be a
product of two primes with approximately 100 decimal digits each. At present,
the factorization of arbitrary integers is computationally feasible only if they
have at most about 70 decimal digits. The RSA cryptosystem is an example of a
public-key cryptosystem with public keys K and n that do not compromise
the secret deciphering key D. Only by knowing the factors of nit is possible
to solve (9.7) for D.
Of special interest in Example 9. 7 is the finite field � 2�, where 2m-1 is
a large Mersenne prime, because with this choice all the keys K with
1 .; K.; 2m-2 can be used. The field with 2127 elements attracted particular
attention. It is generated by the primitive trinomial x127 + x + I over �2 and is
used to implement a cryptosystem with discrete exponentiation. This parti
cular system has recently been shown to be totally insecure; compare also with
the discussion following Example 9.13.
9.8. Example. An application of discrete exponentiation to computer sys
tems is the following. In such systems users' passwords are stored in specially
protected files so that only authorized users have access to them. This can be
achieved by utilizing discrete exponentiation as a candidate for a one-way
functionf by creating a public file of pairs (i.f(p;)), where i denotes the user's
log-on name and p, is the user's password. 0
9.9. Example. Discrete exponentiation can be used to create a well-known
key-exchange system, the Diffie-Hellman scheme. Suppose users A and B wish
to communicate by using a standard high-speed cryptosystem such as DES,
but they do not have a common key. They choose random integers h and k,
respectively, where 2 .; h, k.; q -2. Let b be a primitive element of�,. Then A
sends b' to B, while B transmits b' to A. Both take b"' as their common key,
which can be computed by A as (b')' and by Bas (b'}'. It is an unsolved problem
to generate b" from knowledge of b' and b' only, without computing either h
or k. The public-key cryptosystems that are known today have the disadvan-
3. Discrete Logarithms 349
tage that they are rather slow. Therefore their main use is for the distribution of
keys for conventional cryptosystems. 0
9.10. Example. Consider the following conventional system for message
transmission. User A wishes to send a message m-regarded as a nonzero
element of the publicly known field �,-to user B. Then A chooses a
random integer h, where 1.;; h.;; q-1 and gcd(h, q-1) � 1, and transmits
x = m11 to B. User B chooses a random integer k, where 1 � k � q -1 and
gcd(k, q-1) � 1, and sends y = x' � m" to A. Now A forms z = y"", where
hh' = 1 mod(q-!),and sends zto B. Then B only has to compute z'" to recover
m, where kk" = 1 mod(q- 1), since
This three-pass procedure between A and B is also known as the no-key
algorithm, where users A and B keep their own respective key pairs (h, h') and
(k, k') secret. 0
9.11. Example. Consider the following public-key cryptosystem for message
transmission. Let b be a primitive element of [F4, where q and b are known
publicly. Let A's public key be the element b'E�., where h is kept secret by
A. If B wants to send a message mE�: to A, then B selects a random integer
k, 1 .;; k.;; q-2, and transmits the pair (b', mh") to A. Since A knows h, he
can compute b" � (b')' and so recover m. This cryptosystem could be broken
by computing h or k with an efficient discrete logarithm algorithm. 0
9.12. Example. The following is a digital signature scheme using discrete
exponentiation. If user A wishes to attach a digital signature to a message m
with 1 .;; m.;; p-1, he publishes a prime p, a primitive element b of �,
identified with an integer, and an integer c, 1 � c � p-1, obtained from a
secret random integer h such that c = b' mod p. To sign m, A provides a pair
(r, s) of integers with 1.;; r.;; p-1, 0.;; s.;; p-1, such that
The integer r is generated from a random integer k with gcd (k,p-1) = 1 by
computing r = b' mod p. Then s has to satisfy
bm = b"rbk:J = bhr+ks mod p,
which is equivalent to
m = hr + ksmod(p- 1).
The unique solutions of this congruence is easily obtained by A since he knows
h, r, and k. If an attacker could compute h from c by using a discrete logarithm
algorithm, this digital signature scheme would be insecure. 0
Before we describe several discrete logarithm algorithms for � 4, we
350 Cryptology
make a few general observations. As above, we repeatedly use the fact that
arithmetic in the exponents is done modulo q-1 since b'-1 � b0 � 1 for any
primitive element b off,. In the case of a prime field�, it is often convenient to
identify elements of�. with integers, so that identities in f, are also written as
congruences modulo p.
Next we observe that it is not difficult to find the discrete logarithms of
arbitrary elements of �: under the assumption that discrete logarithms are
"easy" to calculate (or known) for a relatively small portion of all the elements
of �:. For suppose it is easy to compute ind,(a) � ind(a) for a set E of
e(q-1) special elements aE�:, where 0 < e <I. If a given a0E�: is not in E,
take a uniform random sample t1 from {0, 1, ···,q -2} anddefinea1 � a0b''.if
a1 EE, so that ind(a,) is easy to compute, then
ind(a0) = ind(a1)-t1 mod(q-1).
Otherwise, take independent and uniform random samples t2, t3, ··· from
{0, I,···, q-2} until ana,= a0b'' inEisfound. Thenind(a0 )can be calculated by
subtraction. Note that the probability that all the elements a0, a1, · · ·, a, are
outside of E is (1-ef+ 1, which rapidly becomes small.
As an illustration consider the case of a prime field f ,. If the discrete
logarithms in�, of the first n primes 2 = p1 < · · · < P. <pare known and if an
integer a satisfies
then "
a= TIPJ'modp,
J= 1
"
ind(a) = I e1ind(p)mod(p -I).
J= 1
Integers which factor completely into small primes are called "smooth". In the
case described here it is easy to compute ind(a) if a is smooth and the values
ind(p1) are known. The set of smooth integers is then an example of a set E from
above. The density of smooth integers is crucial in the analysis of several
discrete logarithm algorithms.
We first present the Silver-Pohlig-Hellman algorithm for computing
discrete logarithms in f,. The main point to be made here is to show that if
q-1 factors into small primes, then the discrete logarithms can be cal
culated rather efficiently, and so cryptosystems based on discrete exponenti
ation in IFq are insecure for such q. Let
be the prime factor decomposition of q-1, where p1 < p2 < · · · < p, are the
distinct prime factors. We wish to find the valuer= ind,(a) such that a= b',
where b is a primitive element of� •. The value of r will be determined modulo
3. Discrete Logarithms 351
p/' fori= I, 2, · · ·, k and the results will then be combined by the Chinese Re
mainder Theorem for integers (see Exercise 1.13) to obtain r modulo
q-I, which completely determines r since 0..; r < q-I. Suppose
e;-1
r = L s1p{ mod pf' j=O
In order to determine s0 we form
a(q-1)/pj = b(q-1)rfp; = cf = qo, (9.8)
where ci = bC4 -l)/PJ is a primitive pith root of unity in [F 4. Therefore there are
only p, possible values for a'•-"'" corresponding to s0 = 0, I,··· ,p1-I. The
resulting value uniquely determines s0. The next digit s1 in (9.8) is obtained
by letting
Then eJ-1
where r1 = L s1p{. j-1
uniquely determines s1. This method is continued to find all the s1 in (9.8). It
can be shown that this algorithm has a running time of order at most
pt12(log q)2, where Pt is the largest prime factor of q -I. Therefore the
algorithm is most efficient if q-I only has small prime factors.
9.13. Example. Let q = 17, then b = 3 is a primitive element of�17• We wish to
find r = ind,(a) for a= -2 by the Silver-Pohlig-Hellman algorithm.
Sinceq-I = 2\ we only have to work with theprimefactorp1 = 2. We calculate
c1 = b<4-1112 = -1. Write
Now r=s0+s1·2+s2·2 2+s3·23 with s1=0 or I.
a<•-1>12 = (-2)' =I= C"\',
and so s0 = 0. Then d = ab0 = -2 and
d(q-1)f4 = ( -2)4 = -I= C"\',
and so s1 =I. Then e = ab-2 = -4 and
e<•-1>1' =( -4}' =-I= c1',
and so s2 =I. Now f = ab-6 =I, hence a= b6, and so ind3( -2) = 6. 0
The fact that the Silver-Pohlig-Hellman algorithm is less efficient if
q-I has a large prime factor has led to the idea that fields �2• be employed,
where 2"-I is a Mersenne prime. Such fields are also easy to implement. At
the time of this writing 29 Mersenne primes are known, the largest one being
352 Cryptology
2132049-I, but the case of2127-I is of particular interest since the field with
2127 elements has been used in practical hardware implementations. Unfortu
nately, the resulting cryptosystem is completely unsafe since the discrete
logarithm algorithms given below can be carried out rapidly. If one uses f 1• for
a cryptosystem based on discrete exponentiation� an attacker would need
access to a modern supercomputer in order to break a system based on such
finite fields for n ;. 400. Within the next ten years it is recommended to choose
n � 800 or even n � 2000 if one wishes to take into account developments in
large special-purpose machines or improvements of algorithms. Another
disadvantage of fields f 1• for cryptographic applications is that there are few
fields of this type, in the sense that there is only one field of order 2", but there
are many prime fields f, of comparable order since there are many primes p
with 2'-1 < p < 2'. This also lessens the security of a cryptosystem. For large
primes p it appears that fields of the form f P" do not offer increased security
over fields f ,. If we take a system whose main objective is key exchange and
which is based on discrete exponentiation in f ,, such as the Diffie-Hellman
scheme in Example 9.9, and compare it with a public-key cryptosystem like
RSA, then the former seems preferable since one can use keys that are about
half as long for the same level of security.
We now discuss another discrete logarithm algorithm for f ,, the index
calculus algorithm, one variant of which is due to Blake, Fuji-Hara, Mullin,
and Vanstone. This algorithm works best for q = 2', but it can also be carried
out for q = p" with p prime and n;. 2. Let f, with q = p" be defined by the
irreducible polynomialf(x) over f, of degree n. Since f, is isomorphic to the
residue class ring f,[x]/(f), all elements off, can be uniquely represented as
polynomials over f, of degree < n, with the arithmetic being polynomial
arithmetic modulof(x); compare with Chapter 1, Section 3. This identification
will be used throughout the rest of this section. Suppose b(x) is a primitive
element off,. The algorithm to find the discrete logarithm ind(a(x)) to the base
b(x) of an arbitrary nonzero element a(x) off, consists of two stages.
In the initial stage we compute the discrete logarithms to the base b(x)
of all elements of a chosen subset V off,. The set V usually consists of all the
monic irreducible polynomials over lF P of degree� m, where the integer
m < n is determined according to certain probability computations described
later. We suppose that ind(d) is known for all dEf;. This is trivially satisfied
for p = 2 since the only possibility is d = I and then ind(d) = ind(l) = 0. For
p > 2 we use the observation that b = b(x)<•-<Jitp-IJ is a primitive element off,
and
q-1 indbt,,(d) = --1 ind,(d) for all dEf;.
p-
For small values of p, ind,(d) can be obtained by direct calculation. For large
p we may use, for instance, the Silver-Pohlig-Hellman algorithm to compute
these discrete logarithms.
3. Discrete Logarithms 353
9.I4 Index-Calculus Algorithm: Initial Stage. Choose a random integer,
t, I.;; t.;; q-2, and form the polynomial c(x)E�,[x] determined by
c(x) = b(x)' mod f(x), deg(c(x)) < n.
Then factor c(x) into irreducible polynomials over � •• using techniques of
Chapter 4 if necessary. If all the monic irreducible factors are elements of V, so
that
c(x) � d IT v(x)'"'''
"'v
with dE�; is the canonical factorization in �,[x], then
t=ind(d)+ L: e,(c)ind(v(x))mod(q- 1).
"'v
As soon as we obtain more than I VI independent congruences of this type, we
expect that the corresponding system in the unknowns ind(v(x)), VE V, will
determine these discrete logarithms uniquely modulo q-I for all vE V.
The initial stage depends on the possibility to factor c(x) in the way
stated above and to obtain sufficiently many independent congruences. This
stage is independent of a(x) and can be used for other computations in� •. The
second stage of the algorithm is based on the principles described in the
discussion following Example 9.12. In the earlier illustration the set E of
elements with easily computable discrete logarithms was formed by the
smooth integers. The role of the smooth integers is now played by those
polynomials over �, all of whose irreducible factors are elements of V -that
is, all of whose irreducible factors have degree.;; m. Note that the discrete
logarithms of the elements of V are known from the precomputation in the
initial stage. These discrete logarithms serve thus as a data base for the second
stage of the algorithm, and as mentioned earlier this data base should also
include the discrete logarithms of all elements of�;.
9.15. Index-Calculus Algorithm: Second Stage. To compute ind(a(x)) to the
base b(x). choose a random integer t, 0.;; t.;; q-2, and form the polynomial
adx)E�,[x] determined by
a1(x) = a(x)b(x)' mod f(x), deg(a 1(x)) < n.
Then factor a1(x) into irreducible polynomials over� •• using techniques of
Chapter 4 if necessary. If all the monic irreducible factors are elements of V,
so that
a1(x) � d IT v(x)'"1"'1
,.v
with dE�; is the canonical factorization in�,[ x ], then ind (a(x) )is determined by
ind(a(x))=ind(d)+ L: e,(a1)ind(v(x))-tmod(q-! ).
"'v
354 Cryptology
If a1 (x) does not have the desired type of factorization, choose other values oft
until this type of factorization is obtained.
For the analysis of both stages of the algorithm it is important to study
the probability P(n, m) that a nonzero polynomial over f, of degree < n has all
its irreducible factors in � ,[x] of degree:;;; m. We have
1 n-1 P(n,m)�- ,-L N(k,m), p -I k=O
where N(k, m) is the number of polynomials over �,of degree k that have all
their irreducible factors in f,[x] of degree:;;; m. A recurrence relation for
evaluating N(k,m) is given in Exercise 9.14. For p � 2 this leads after lengthy
calculations to the formula
(m)"''·m),/m
P(n, m) � A(n, m) n ,
where A(n,m) and B(n,m) tend to I for n--+ oo and n11100:;;; m:;;; n991100 Thus
we will need roughly (n)'lm
P(n, m)-1 "" ;;; (9.9)
choices of integers t before the second stage of the algorithm can find the discrete
logarithm of a(x). It is clear that m cannot be chosen too small, for
otherwise the running time of the second stage would be exorbitantly long. On
the other hand, if m is chosen too large, then the initial stage will require a very
long running time. Thus one has to find a middle ground between these two
extremes. For instance, in the important special case p � 2 and n � 127 the
choice m = 17 is recommended; then 16510 discrete logarithms have to be
precomputed in the initial stage since there are that many irreducible
polynomials over �2 of degree:;;; 17.
9.16. Example. To illustrate how the initial stage is carried out, we consider
� 64 defined by f(x) = x6 + x + I Ef2[x]. Since f(x) is a primitive polynomial
over F2, we can take b(x) = x as a primitive element of �64. Suppose the
maximum degree m of irreducible polynomials in the set Vis 2. So we have to
find the discrete logarithms of x, x +I, and x2 + x +I to the base x. Oearly
ind(x) = I. Now we choose integers t with I :;;; t:;;; 62. A good choice is t = 6,
since then
c(x) = x6 = x +I modf(x),
hence ind(x + I) = 6. Another good choice is t = 32, since
x64 = x = x6 +I= (x3 + 1)2 modf(x)
implies
c(x) = x32 = x3 + I= (x + l)(x2 + x +I) modf(x).
3. Discrete Logarithms
This yields
32 = ind(x + I) + ind(x2 + x + I) = 6 + ind(x2 + x + I) mod 63,
hence ind(x2 + x + I) = 26. 355
D
9.17. Example. To demonstrate a simple case for the second stage, let IF64
again be defined by f(x) = x6 + x + I ElF 2[x] and let b(x) = x. Suppose m = 2,
so that the discrete logarithms of the elements of V are known from Example
9.16. These values constitute our data base. We wish to find the discrete
logarithm of a(x) = x4 + x3 + x2 + x + I to the base x. We form
a1(x) = a(x)x' modf(x)
with a suitable t. The choice t = 2 yields
a1(x) = a(x)x2 = x5 + x4 + x3 + x2 + x +I= (x2 + x + 1)2(x +I) modf(x),
hence all the irreducible factors are in V. Therefore
ind(a(x)) = 2 ind(x2 + x + I) + ind(x + I)-2
= 2·26 + 6-2 = 56mod63,
and so ind(x4 + x3 + x2 + x + I) =56. 0
The second stage of the index-calculus algorithm can be speeded up by
using the Euclidean algorithm. Consider again the nonzero polynomial
a1(x)EIF,[x] determined by
.·
a1(x) = a(x)b(x)' mod f(x), deg(a1 (x)) < n. (9.1 0)
The method in 9.15 is successful only if a1(x) has all its irreducible factors in
IF,[x] of degree ,;;m. The main idea is to replace this now by the following
condition: there exist nonzero polynomials w1(x) and w2(x) over IF, with
w,(x)a1(x) = w1(x) mod f(x) (9.11)
and deg(wJx)),;; n/2 for i = I, 2 such that each w�x) has all its irreducible
factors in IF,[ x] of degree ,;; m. If such polynomials w,(x) can be found, then
their canonical factorization in IF,[x] is of the form
w1(x) = d, n v(x)•·<w<> for i =I, 2 (9.12)
�v
with d,EIF;.It follows then from (9.10) and (9.11) that the discrete logarithm of
a(x) is determined by
ind(a(x)) = ind(d1d2 1) + L (e,(w1)-e.,(w2))ind(v(x))- t mod(q -I).
�y
(9.13)
Polynomials w1 (x) and w2(x) satisfying(9.11) and the degree restriction
above can be calculated by an application of the Euclidean algorithm that is
356 Cryptology
similar to the procedure for decoding Goppa codes (see Chapter 8, Section 3).
In detail, we use the Euclidean algorithm with the polynomials r _1 (x) = f(x)
and r0(x) = a1(x). This yields
r, -l (x) = q,. 1 (x)r,(x) + r,. 1 (x), deg(r,. 1 (x)) < deg(r,(x)),
for h=O,l, ... ,s-1,
r,_1 (x) = q,. 1 (x)r,(x).
Since 0,;; deg(a1(x)) < n = deg(f(x)) and f(x) is irreducible over �,,we have
gcd(f(x), a1(x)) =I and so deg(r,(x)) = 0. Consequently, there exists a least
index j, 0 ,;;j,;; s, such that deg(r,{x)) ,;; n/2. Now calculate recursively the
polynomials
z_ 1 (x) = 0, z0(x) = I,
z,(x)=z,_2(x)-q,(x)z,_1(x) for h= 1,2, ... ,j.
By the generalizations of(8.12) and (8.13)shown in Exercises 8.43(a) and 8.43(c)
we have
zj(x)a1(x) = rj(x) modf(x)
and
deg(zj(x)) = deg(f(x)) -deg(r;_1(x)) = n-deg(r;_1(x)).
From the minimality ofj we get deg(r;_1(x)) > n/2, and so deg(z;(x)) < n/2. It
follows that w1(x) = rj(x) and w2(x) = zj(x) are polynomials satisfying (9.11)
and deg(w1(x)} ,;; n/'1., deg(w2(x)) < n/2. Moreover, w1(x) and w2(x) can be
calculated very quickly.
The condition about the irreducible factors ofw1(x} and w2(x) cannot
be guaranteed by the algorithm above. However, we may heuristically
estimate the probability that both w1(x) and w2(x) have the desired type of
factorization in (9.12). Let P(n, m) again denote the probability that a nonzero
polynomial over �,of degree< n has all its irreducible factors in �,[x] of
degree,;; m. If we make the reasonable assumption that w1(x) and w2(x) behave
like independently chosen random polynomials of degree < Ln/2J + I, then
the probability that w1(x) and w2(x) have all their irreducible factors in �,[x]
of degree ,;; m will be approximately P(Ln/2J + I, m)2• Usingthe approxim ation
(9.9) in the case p = 2, we obtain that we will now need roughly
choices of integers tin the second stage of the algorithm. This is a saving by a
factor of approximately 2 -•tm over the corresponding expression in (9.9). Thus
we can expect that this version of the second stage of the index-calculus
algorithm will be significantly faster than the earlier one. We summarize this
3. Discrete Logarithms 357
method as follows, assuming again that we already have a data base
containing the discrete logarithms of all elements of �; and of all elements of
the set V consistin g of the monic irreducible polynomials over �. of
degree� m.
9.18. Index-Calculus Algorithm: Improved Version of Second Stage. To
compute ind(a(x)) to the base b(x), choose a random integer t, 0.;; t.;; q-2,
and form the polynomial a1(x)E�,[x] determined by
a1(x) = a(x)b(x)'modf(x), deg(a1(x)) < n.
Then carry out the Euclidean algorithm with r _1(x) = f(x) and r0(x) = a1(x)
and stop as soon as deg(ri(x)) .;; n/2. Put w1 (x) = r1(x) and w2(x) = z/x) and
factor these polynomials into irreducible polynomials over � ,, using techni
ques of Chapter 4 if necessary. If all the monic irreducible factors are elements
of V, so that w1 (x) and w2(x) are of the form (9.12), then ind(a(x)) is determined
by (9.13). If this condition on the monic irreducible factors ofw1 (x) and w2(x) is
not satisfied, choose other values oft until this condition holds.
In the case p = 2 further improvements on the construction of the data
base and on the speeding up of the second stage of the index-calculus
algorithm were recently achieved by Coppersmith.
9.19. Example. We give a simple illustration of the algorithm in 9.18.
Consider the finite field f32, so that p = 2 and n = 5. Let IF32 be defined by the
primitive polynomial f(x) = x' + x2 +I over �2. Then we can take b(x) = x
as a primitive element of IF 32. We wish to find the discrete logarithm of
a(x) = x3 + x + I to the base x. Suppose the data base consists of the discrete
logarithms of all irreducib le polynomials over �2 of degree .;; 2:
ind(x)=l, ind(x+l )=l8, ind(x2+x+l) =ll.
Choose the integer t = 0, so that a1 (x) = a(x), and carry out the Euclidean
algorithm with r _1 (x) = x' + x2 + I and r 0(x) = x3 + x + I. This yields
x' + x2 + I = (x2 + I )(x3 + x + I) + x.
Since r.(x) = x satisfies deg(r1(x)) .;; n/2, we can already stop. Thus
w1 (x) = r1 (x) = x and w2(x) = z1 (x) = x2 + I = (x + I )2 It follows then from
(9.13) that
ind(x3 + x +I) =ind(x)-2ind(x +I)= 1-2·18= 27mod 31,
and so ind(x3 + x +I)= 27. 0
These discrete logarithm algorithms have diminished the security of
cryptosystems based on discrete exponentiation. It is therefore of interest to
design cryptosystems that use similar principles, but employ more complex
operations than discrete exponentiation. This is carried out in the recent
proposal of FSR cryptosystems by Niederreiter, where FSR stands for
358 Cryptology
"feedback shift register". In these cryptosystems, discrete exponentiation is
replaced by the operation of decimation for linear recurring sequences in finite
fields (compare with Chapter 7, Section 4). The ciphertexts are strings of
consecutive terms of linear recurring sequences that are obtained by
decimation from message-dependent linear recurring sequences. The cry
ptanalysis amounts to inferring the value ofthe integer k from the knowledge
of the polynomials J(x) = Tii�1(x- �1) and J,(x) = ru�,(x-"' over � ••
where both factorizations are in the splitting fields ofthe polynomials over� •.
This problem is more difficult than determining discrete logarithms.
We now describe a public-key cryptosystem in which discrete logarithms
are used for encryption. This cryptosystem due to Chor and Rivest is of the
knapsack type -that is, it is based on the difficulty of recovering the summands
from the value of their sum. The following auxiliary result is crucial.
9.20. Lemma. Let p be a prime and n;;. 2 an integer. Then there exist
integers a0, a1, ..•• ap-t with 1 � ai� p" -2/or 0 � i � p-1 such that for any
two distinct vectors (h0, h1, •.• , h,_1) and (k0, k1, ... , k,_1) with nonnegative
integral coordinates satisfying
we have p-1
L h,< n and
i=O (9.14)
Proof. Consider the finite field f 4 with q = p" and identify it as before
with the residue class ring f,[x]/(f), where f(x) is an irreducible polynomial
over �, of degree n. Relative to a fixed primitive element of � 4 set
a, = ind (x -i) for i = 0, I, ... , p -I.
Each a, satisfies I ,;;; a,,;;; q-2. Now suppose (h0, h1, •.• , h,_1) and
(k0, k1, •.. , kP_1) are two vectors with nonnegative integral coordinates
satisfying (9.14) and
Then
and so p-1 p-1
L h,a, = L k,a, mod (q-I).
1=0 i=O (p-1 ) (p-1 )
ind Il (x-i)'' = ind ,IJ (x-i)'' mod (q-I),
p-1 p-1 TI (x -iJ'' = TI (x -i)'' mod f(x).
i=O i=O
Now (9.14) shows that on each side we have a polynomial over�. of degree
< n, hence p-1 p-1
TI (x -i)'' = TI (x -i)''. i=O i=O
3. Discrete Logarithms 359
Unique factorization in f ,[x] implies h1 = k;for 0.;; i.;; p-I, and the desired
result is established. D
The cryptosystem is implemented as follows. Take a publicly known
finite field �.with q = p", p prime, n;;. 2, in which discrete logarithms can be
efficiently computed. Choose a random irreducible polynomial f(x) over f, of
degree nand a random primitive element b(x) of� •. Relative to the base b(x)
compute
a,= ind (x-i) for i = 0, I, ... , p-I
as in the proof of Lemma 9.20. Scramble the a, by selecting a random
permutation 1/J of {0, !, ... ,p-!}and putting
ci = ao;-(i) for i = 0, 1, ... ,p -1.
Then publish c0, c1, ... , c,_1 as the public key and keep f(x), b(x), and 1/J secret.
With this cryptosystem we can encipher binary messages M =
m0m1 ..• m,_1 of length p for which the number N of I 's is less than n. In
detail, let m1, = ... = m1 = I and all other m, = 0. Then encipher M as the
N integer E(M) with 0 .;; E(M) .;; p"-2 and
E(M) = c,, + · ·· + c1 mod(p" -I).
N
It follows from Lemma 9.20 that distinct messages are enciphered as distinct
ciphertexts.
To decipher the ciphertext s 0" E(M), we calculate the uniquely
determined polynomial g(x)E � ,[x] with deg(g(x)) .< n and
g(x) = b(x)'modf(x).
From the definition of the c, and a, we obtain
g(x) = b(x)"• + ··· +"• = (x-!/J(i1)) ... (x-1/J(iN))mod f(x).
Since N < n = deg(f(x)), we have
g(x) = (x-1/J(i,))· · · (x-1/J(iN)).
Therefore 1/J(i,), ... , 1/J(iN) can be determined as the roots ofg(x) in�,, which are
obtained either by successive substitution of elements of�, or by one of the
root-finding algorithms in Chapter 4, Section 3. By applying the inverse
permutation of ljl, we recover the positions i1, •.. , i,. where the original
message M has the bit I.
9.21. Example. We illustrate the procedure with an example involving
small parameters. Let p = 5 and n = 3, so that we are working in the finite field
�125. Choose f(x) = x3 + x2 + 2, which is a primitive polynomial over�,.
Therefore b(x) =xis a primitive element of �125. The part of Table A in
Chapter 10 pertaining to f125 = GF(53) refers precisely to this situation. Thus
we can read off the values of the a, from this table. This yields
a0 =I, a1 = 84, a2 = 80, a3 = 99, a4 = 29.
360
Let the permutation t/1 of {0, 1, 2, 3, 4) be given by
so that t/J(O) = 2, t/1(1) = 4, t/1(2) = 1, t/1{3) = 0, t/1(4) = 3,
c0 = 80, c1 = 29, c2 = 84, c3 = 1, c4 = 99.
If we wish to encipher the binary message M = 10100, then
E(M) = c0 + c2 = 80 + 84 mod 124,
and so E(M) = 40. To decipher s = 40, we calculate
g(x) = x40 =x' + 2x + 2mod(x3 + x2 +2)
from Table A, hence
g(x) = x2 + 2x + 2 = (x-l)(x-2). Cryptology
Therefore N = 2, tjl(i,) = 1, and t/J(i2) = 2, yielding i1 = 2 and i2 = 0, and we
recover the original message M. D
4. FURTHER CRYPTOSYSTEMS
We first describe a public-key cryptosystem that is based on binary irreducible
Goppa codes (see Chapter 8, Section 3). This cryptosystem falls into the
category of block ciphers. We recall from Theorems 8.56 and 8.57 that for any
irreducible polynomial g{x) over �2� of degree t and any integer n, where 2.;;; t
< n.;;; 2m, there exists a binary irreducible Goppa code i{L,g) oflength nand
dimension k � n-mt that is capable of correcting any pattern oft or fewer
errors. All one has to do is to choose Las a subset of �2� of cardinality n.
We note also that Goppa codes allow a fast decoding algorithm discussed
in Chapter 8, Section 3.
The Goppa-code cryptosystem is set up as follows. We choose integers t
and n with 2 � t < n � 2'" and then randomly select a monic irreducible
polynomial g(x) over �2� of degree t. This is easy to do since the probability
that a monic polynomial over IF 2m of degree tis irreducible is
-m< 1 '<;" (t) md 1 N 2�(t)2 =2m, L..Jl -d 2 "='-t dlt t
according to Theorem 3.25. The irreducibility of a randomly chosen poly
nomial may be tested by applying one of the factorization algorithms in
Chapter 4 to it. We consider now a t-error-correct ing binary irreducible
Goppa code l(L, g) of length n and dimension k;;. n -mt. This code has a
binary (n-k) x n parity-check matrix H. From H we can derive a binary k x n
generator matrix G of i(L,g); compare with Chapter 8, Sections 1 and 3. This
generator matrix is scrambled by selecting at random a binary invertible k x k
matrix Sand ann x n permutation matrix P-that is, a matrix obtained from
4. Further Cryptosystems 361
the identity matrix by exchanging rows-and forming the new generator
matrix G'�SGP.
This k x n matrix G' generates a binary linear code with the same length,
dimension, and minimum distance as the Goppa code r(L,g). The matrices
G, S, and P are kept secret, whereas G' is made public. Let z denote a random
binary vector of length n and weight.;; t chosen by the sender. Then the
cryptosystem is implemented as follows.
9.22. Goppa-Code Cryptosystem.
Enciphering: The plaintext data, given as k-bit blocks x, are enciphered as
vectors y � xG' + z.
-'
Deciphering: On receipt ofy we compute y' � yP , which will be at a Hamming
distance at most t from the code word xSG of the Goppa code r(L,g).
Decoding y' gives the corresponding message x' � xS, and the plaintext is
recovered by computing x = x'S-1.
9.23. Example. We present an example with very small parameters to
demonstrate the procedure. However, the cryptosystem in this example does of
course not offer any security. We choose m � 3, n � 8, t � 2, and use the Goppa
code of dimension k � 2 in Example 8.58, with G being the generator matrix
given there. Furthermore , let
I .0 0 0 0 0 0 0
0 0 1 0 Q. 0 0 0
0 1 0 0 0 0 0 0
s�G 1) P�r1� 0 0 0 1 0 0 0 0
1 ' 0 0 0 0 1 0 0 0
0 0 0 0 0 0 0
0 0 0 0 0 1 0 0
0 0 0 0 0 0 0 1
Then the public key is
G'�SGP�G 0 1 0 I 0 D· 0 1 1 1
Let z � 1 0 0 0 0 0 0 0 Then the plaintext x � 0 I, say, is
enciphered as y � I I 0 1 I 1 I I. On receipt of y the authorized receiver
computes y' � yP-1 � 1 0 I I 1 1 I l and decodes this to the code word
0 0 I 1111 I with corresponding message x' � 0 1. The plaintext is recovered
as x � x·s-1 � 0 I. In this example decoding is performed merely as nearest
neighbor decoding-that is, by comparing the received word y' with the
nearest code word of Example 8.58 relative to the Hamming distance. For
large parameters this approach will be infeasible, but then the efficient
decoding algorithm for Goppa codes can do the job for us. D
362 Cryptology
In order to break this cryptosystem, an attacker would have to
determine G from G' or he might try to recover x from y without knowing G.
To find G seems to be a hopeless task ifn and tare large enough, since there are
so many possibilities for G, S, and P. If the attacker wants to find xfrom y, this
amounts to decoding a random looking linear (n, k) code in the presence of up
to t errors. Such an attack is expected to be infeasible for large enough code
parameters, since the general decoding problem for linear codes has been
shown to be NP-complete. For example, ifm = 10, n = 210 = 1024, and t =50,
then there will be about 10149 possible Goppa polynomials and a gigantic
number of choices for Sand P. The dimension of the code will be at least 524
and will make brute-force attacks based on comparisons ofy with code words
or based on coset leaders impossible. This cryptosystem is not suitable for use
in authentication, but its fast communication rate makes it attractive for data
communication.
We now discuss another scheme for the communication of secret
information. Suppose the secret is some data D-for instance, the key for a
cryptosystem or a bank safe combination. Then D is divided into n pieces
D1, ... ,D, in such a way that for some k < n:
(i) knowledge of any k or more pieces D, makes computing D easy;
(ii) knowledge of any k-I or fewer pieces D, makes determining D
impossible because of insufficient information.
Such a scheme is called a (k, n) threshold scheme. It can be helpful in a variety of
situations. For instance, if n = 2k-I, the original data D can be recovered
even when Ln/2J = k-I of the n pieces D, are destroyed or lost, but an
opponent cannot reconstruct D even when security breaches expose k-1 of
the remaining k pieces. Other advantages are that a hierarchical scheme is
possible where the number of pieces D1 given to each user is proportional to the
user's importance. Threshold schemes are well suited to situations where a
group of mutually suspicious individuals with conflicting interests must
cooperate. By choosing the parameters nand k properly, any sufficiently large
majority can be given the authority to take some action, while any sufficiently
large minority can be given the power to block it.
We describe a (k, n) threshold scheme that was originated by Shamir
and by Blakley for f, and f2m, respectively. First we identify D with an element
of a suitable finite field f ,. The pieces D, are derived-in a way to be
specified-from a random polynomial
f(x) = a,_1x'-1 + · · · + a1x + a0Ef,[x]
of degree k-1 whose constant term a0 is D. Here q is a prime power
larger than n and the number of possibilities for D. If one knows the
polynomial f(x), then it is easy to computeD by D = f(O). The pieces D, are
obtained by evaluating f(x) at n distinct elements c1, ••• ,c,Ef,-that is, D,
= f(c,) fori= 1, 2, ... , n. These c, could be elements of�, which do not have to
Exercises 363
be secret; they could be user identifiers. Since any k pairs (c,, D,) uniquely
determine a polynomial of degree .;; k-1, the polynomial f(x) and therefore
the secret data D can be reconstructed from k pieces, but not from fewer pieces.
If the k pieces are denoted by D,,, ... , D,,, then f(x) can be computed by the
Lagrange interpolation formula in Theorem 1.71, which yields
k '
f(x) = L D,, TI (c,.-c,r 1(x-c,J
s"" 1 t = 1
"'
9.24. Example. Let q = 8, n = 3, and k = 2. Suppose we know that
D1=/(1)=a+a 2,
D2 = f(a) =a,
where a E IF 8 is a root of x3 + x + 1. Then f(x) can be reconstructed as follows:
f(x) =(a+ a2)(1-a)-1(x- a)+ a( a-W1(x-1)
= a(x + a) + ( 1 + a + a 2)(x + 1)
=(1 +a2)x + 1 +a.
Therefore the secret data is D = f(O) = 1 +a. 0
EXERCISES
9.1. Let s0, s1, ... and t0, t1, ... be the impulse response sequences with
characteristic polynomial x4 + x + 1 and x' + x2 + 1 over IF2, respec
tively. Let h = 2, j, = 0, j, = 1, and Jjl: {0, 1, 2, 3}--+ {0, 1, 2, 3, 4} be
defined by Jjl(l) = i + I. Find the first 16 terms of the resulting
multiplexed sequence.
9.2. If x15 + x' + x 7 + x2 + 1 and x16 + x15 + x4 + x + 1 are characteristic
polynomials oftwo maximal period sequences in f2, respectively, what
can you say about the least period of a multiplexed sequence based on
these two sequences?
9.3. Suppose we know that a feedback shift register with 5 delay elements
has been used to construct a binary sequence s0, s1, ... and that the
first 10 values of s, are 0, 1, 0, 1, 0, 1, 1, 1, 0, 1. Find a characteristic
polynomial of the sequence and determine the first 20 terms of the
sequence.
9.4. In the notation of Definition 9.1, let s0, s1, ... be a kth-order maximal
period sequence in IF2 with k > 1 and let 1 .;; h < k. For n = 0, I, ... let
P�n), i=O, 1, ... ,2'-1, be the 2' Boolean monomials formed by
taking all2' possible products of the terms s.+1,. ... ,s•+J•· Let< be
a maximal period sequence in F2 with terms t0, t1, ... and minimal
polynomial g(x)EF2[x], and let u0, u1, ••• be the resulting multiplexed
364
sequence. Prove that
lh-1
u,= I Pi(n)t,+N(iJ for n=O,l, ... ,
i=O Cryptology
where the integers N(O), N(l), ... , N(2"-I) are completely determined
by 1/1(0), 1/1(1), ... , 1/1(2"-1). Moreover, prove that the 2" shifted
sequences r<N<<JJ, i = 0, I, ... , 2"-I, are linearly independent in the
vector space S(g(x)) over IF 2 defined on p. 215.
9.5. In the proof of Theorem 9.6 it is shown that if r is an mth-order
maximal period sequence in the finite prime field f •• then the decimated
sequence r:f with d = p' -I and gcd(k, m) = I has least period (pm - I)/
(p-1). Prove more generally that if r is an mth-order linear recurring
sequence in an arbitrary finite field f, with least period rand irreducible
minimal polynomial, then for j;;. 0 and d;;. I we have:
(a) the decimated sequence rYl is either the zero sequence or it has least
period rfgcd(d, r);
(b) if gcd(d, r):;;; rq1-m, then rYJ has least period r/gcd(d, r).
9.6. How many possible enciphering keys K are there in the cryptosystem
in Example 9.7 if q = 1987?
9.7. Letp = 47, q =59, andK =!57 be parameters of an RSA cryptosystem.
Find the deciphering parameter D.
9.8. Let q = p = 13 and b = 2. Demonstr ate by a numerical example how
each of the schemes in Examples 9.9, 9.10, 9.11, and 9.12 works.
9.9. Show that in the public-key cryptosystem in Example 9.11 it is not
advisable to use the same value of k for enciphering more than one
message block.
9.10. Use the Silver-Pohlig-Hellman algorithm for q = 73 and b = 5 to find
the discrete logarithm of a= 7.
9.11. In Example 9.16let m = 3. Find the discrete logarithms to the base x for
all polynomials in V.
9.12. Refer to Example 9.17 and find the discrete logarithm of a(x) = x4 + x3
+x2 +I to the base x.
9.13. Suppose IF32 is defined by f(x) = x' + x2 +I over IF2 and a data base
for the second stage of the index-calculus algorithm is given as in
Example 9.19, so that m = 2. Compute the discrete logarithm of
a(x) = x4 + x + I to the base x. Repeat the calculation under the
assumption that m = I.
9.14. For an arbitrary finite field f ,let N(k, m) be the number of polynomials
over IF, of degree k all of whose irreducible factors in IF,[x] are of
degree :;;; m. Define N(k, 0) = q -I if k = 0, N(k, 0) = 0 if k # 0, and
N(k, m) = 0 if k < 0 and m;;. 0. Let N ,(n) be the number of monic
irreducible polynomials over IF, of degree n (see Theorem 3.25). For
k, m � 1 prove the recurrence
m (i+N,(n)-1) N(k, m) = J, '�' N(k-in, n-I) i .
Exercises 365
9.15. Let r _1(x) and r0(x) be two nonzero polynomials over a field F with
deg(r _1(x));;. 1eg(r0(x)) and d(x) = gcd(r _1(x), r0(x)), and let k be an
integer with deg(d(x)) .;; k < deg(r _1(x)). In the notation of Exercise
8.43, prove that there exists a unique index j, 0 .;;j.;; s, such that
deg(rix)).;; k and deg(z/x)).;; deg(r _1(x))-k-I.
9.16. In several cryptosystems over f, involving discrete exponentiation it
is necessary to generate enciphering keys e and deciphering keys d
with e, dElL and ed =I mod(q-1). Show that such keys can be
generated in the following way. Let ab =I mod(q-1), where a has
the largest possible multiplicat ive order N modulo q-I, and let r be
randomly chosen from {0, I, ... , N-I). Then e = a'mod(q-I) and
d = b' mod(q- I) are multiplicativ e inverses of each other modulo
q-I.
9.17. Prove that a polynomial xm + xm-l + ... +X+ I is irreducible over F2
and its roots o:2;, i = 0, 1, ... , m-1, form a normal basis ofiF2 ... over IF2 if
and only if m + I is prime and 2 is a primitive element off m+ 1. (Note:
Such all-one polynomials permit an attractive impleme ntation of
discrete exponentiation in a normal basis of f2rn over �2.)
9.18. Let b be a primitive element of the finite prime field f ,, p > 2, and let
aE f;. Prove that ind,(a) is determined as an element of f, by the
formula
p-2
ind,(a) =-1 + L (b-i -i)-1ai
j=l
(Hint: Use the Lagrange Interpolation Formula in Theorem 1.71.)
9.19. Prove that the formula in Exercise 9.18 reduces to
p-2
ind,(a) = L (I-bi)-1al
j= 1
provided that a# I. (Note: The formulas for discrete logarithms in
Exercises 9.18 and 9.19 are of theoretical interest, but useless for
computational purposes.)
9.20. Let f(x) be an irreducible polynomial over f, of degree nand let g(x) be
an arbitrary polynomial over f ,. Prove that the degree of any nonzero
divisor of .f(g(x)) in f,[x] is a multiple of n. (Note: This property is
useful in the initial stage of the index-calculus algorithm.)
9.21. Let p, n, f(x), and >/! be as in Example 9.21 and choose the primi
tive element b(x) = 4x2 + 3 of f 125. Encipher the binary message
M = 01010 and then decipher it again.
9.22. Prove that Lemma 9.20 holds also if p is a prime power.
9.23. Show by a counterexample that Lemma 9.20 does not hold in general if
(9.14) is replaced by the condition that Lf:Jh,.;; nand If;Jk1.;; n.
(Hint: Consider n = 2 and p = 2 or 3.)
9.24. In Example 9.23 use as the matrix P the matrix obtained from the
366 Cryptology
identity matrix by exchanging rows one and eight, let
s = (: �)
and z = I I 0 0 0 0 0 0. Encipher the plaintext x = 0 I with the
Goppa-code cryptosystem and decipher the result by using nearest
neighbor decoding and Example 8.58.
9.25. Explain why the Goppa-code cryptosystem cannot be used for digital
signatures.
9.26. Let k = 3 and n = 5 be the parameters of a threshold scheme based on
f8 as in Example 9.24. Suppose the following pairs (c,,DJ are known:
(I, 0), (IX, 0), (1X2, I +IX). Reconstruct the polynomial f(x) over f 8 and
thus find the secret data D.
9.27. A threshold scheme is given by the parameters q = 17, n = 5, and k = 3.
Suppose f(i) = 8,f(2) = 7, and f(3) = 10 are three known pairs (c1, D1).
Find the secret D.
9.28. Show how discrete exponentiation can be used in a threshold scheme.
Also design a scheme in which n;;. 2 mutually suspicious users are all
needed to encipher a common secret (for instance, a classified
document), but each individual user should be able to gain access to the
secret (read the document) and decipher individually.
9.29. A cryptosystem due to L. S. Hill is based on linear transformations of
the residue class ring R. = Z/(n). The plaintext is represented as a k
tuple in R�, enciphering is a nonsingular linear transformation and
deciphering is its inverse.
(a) Suppose n = 29, k = 2, and the linear transformation is P 4
AP(mod 29), where PERl, and
A= G !).
Encipher the message "CRYPTOGRAPHY IS FUN." under the
assumption that the letters A to Z are denoted by 0 to 25, a period
by 26, a comma by 27, and a blank space by 28.
(b) This cryptosystem can also be based on linear transformations of
f,. Let q = 27, k = 3, choose a nonsingular 3 x 3 matrix with entries
in f27 and encipher the message "CIPHER", where A= 0, B = IX0,
C = cx1, ... for a primitive element ct of f27.
(c) Let A be an m x m matrix with integer entries, let b, xEZm, and let n
be a positive integer. Prove that Ax= b mod n has a unique
solution x modulo n (where a congruence between vectors is
interpreted coordinatewise) if and only if gcd(det(A), n) = I. Find a
similar condition for the existence of a unique solution of the
equation Ax= b over IFq.
Chapter 10
Tables
In this chapter we collect tables that facilitate the computation in finite
fields and tables of irreducible and primiiive polynomials. The description
of these tables is given in Sections I and 2, respectively.
1. COMPUTATION IN FINITE FIELDS
Multiplication and division of nonzero elements of F q can be performed
using a notion analogous to logarithms. We speak of the index or discrete
logarithm. If b is a primitive element of [Fq• then for any aErF: there exists a
unique integer r with 0.;; r < q � 1 such. that a= b'. We write r = ind,(u), or
simply r = ind(a) if b is kept fixed. The index function satisfies the following
basic rules:
ind(ac) = ind(a)+ind(c)mod(q -I).
ind( ac-1) = ind( a) -ind( c) mod( q-I).
The inverse function of the index function. corresponding to taking anti
logarithms, is denoted by exp, or simply exp, and we have:
exp(r)=b', exp(ind( a))=a, ind(exp(r))=r.
Given a table of the ind and exp function, it is easy to carry out addition.
subtraction, multiplication, and division in IF q· Addition and subtraction are
367
368 Tables
performed by using the vector space structure of f 11 over its prime sub field
IFP, multipl ication and division are performed by using the rules for the
index function and the exp and ind table to co,nvert from one notation to
the other. Table A provides a complete list of the nonzero elements and
their indices for the finite fields l'q with q composite and q.; 128. In the exp
column the parentheses and commas. of the vector notation for the following
element of I' 9 with q � p" have been dropped:
a=(a1, •••• a11) =a1bn-l+a2bn-2+ ···+a,. O�a;<p.
In Table A we use GF(p') to denote the finite field with p" elements.
10.1. Example. As an example for the use of Table A we calculate
[(b+ 1)+(2b+2)b](b+2)-1+b
in the field 1'9. Working with the portion of the table pertaining to this field.
we get
ind((2b + 2)b) = ind(2b + 2) +ind(b) = 3+ I= 4mod8,
(2b +2)b � exp(4) � 2.
Thus. (b + 1)+(2b +2)b �band
ind([{ b + I)+ (2b + 2) b ]( b + 2)-1) = ind( b)-ind( b + 2) = I-6 = 3 mod 8.
[(b +I)+ (2b +2)b](b +2)-1 � cxp(3) � 2b +2.
The final result is (2 b + 2) + b � 2. 0
Table B affords another possibility of doing arithmetic in finite
fields. In the first two columns it provides a table of Jacobi's logarithm L( n)
for the fields F2, with 2.; k.; 6 (compare with Exercise 2.8). The symbol
n � s means that L(n) = s with respect to a fixed primitive element b. In
characteristic 2 the value L(O) is undefined. The elements b" are multiplied
in the obvious way and added according to the rule
given in Exercise 2.8. The symbol "+" preceding the value of n indicates
that b" is a primitive element.
10.2. Example. We use Table B to calculate
( b6 + b25 + b44 )(I+ b35) . 1 + b28
in the field IF64• We have b6 + b25 = b6+1-(19l = b40 and b40 + h44 = b40+l.(4J =
b12. Since l+b35=b1·C351=b31• we get
(b6 + b25 + b44 )(I+ b35) -I� b12b-31 � b41.
Furthe rmore, since the argument of the function L and the exponent of h
are considered modulo 63, we obtain b41 + b18 = b41 +L<-131 = h41 +L(SOJ =
1. Computation in Finite Fields 369
b101 = b38, which is the final result and happens to be a primitive element of
�-D
The remainder of Table B provides information about minimal and
characteristic polynomials and about dual bases. We take the lines
+ 20 -+ 26[ I 0000 I] 26 6 49 29 9 46: 19
21-+42[101011] [11]
from the table for IF64 over IF2 as illustrations. The symbol [a1 a2 • · · aml
indicates that xm + a1x'"-1 + a2xm-2 + · · · +am is the characteristic poly
nomial of the element with respect to the given field extension. Thus,
x' + x' +I is the characteristic polynomial of b20 over IF2 and x' + x' + x3
+ x +I is that of b21 over IF2. If b" is a defining element of the extension,
then the set of integers between the characteri stic polynomial and the colon
describes the dual basis of the polynomial basis determined by b". If b" is
not a defining element, then the minimal polynomial of b" with respect to
the given extension is listed in the bracket notation explained above. For
instance, b20 is a defining element of F64 over IF2 and the dual basis of the
polynomial basis {1, b20, b40, b60, b80, b100) is {b26, b6, b49, b 29, b1, b46}. On
the other hand, b21 is not a defining element of IF 64 over F 2 and the minimal
polynomial of b21 over IF2 is x2 + x +I, so that b21 E F 4• If b" is not only a
defining element. but also determines a normal basis of the given extension,
then the integer after the colon describes the element determining the dual
normal basis. For instance, b20 determines ihe normal _]?asis
{ b'o • ( b'o )', ( b'o )', ( b'o )', ( b20) 16 • ( b'o )")
of F64 over IF2, and its dual basis is given by
{ bl'. ( bl')'. ( bl')'. ( b")'. ( bl')l'. ( b\9 l").
Elements in subfields except IF2 are denoted in the table by capital letters
whose meaning becomes clear upon inspection of the data for minimal
polynomials. For example, in the table for F 64 the letter X stands for
b21 E IF4 and D stands for b21 E F8.
370 Tables
TABLE A
exp ind exp ind exp ind exp ind
GF(22) GF(25) GF(26) GF(27)
01 0 00011 14 101110 27 0000110 8
10 I 00110 15 Ill \01 28 0001100 9
II 2 01100 16 0\1011 29 0011000 \0
11000 17 1\01\0 30 0110000 II
GF(23) 11001 18 001101 31 1100000 12
i\011 19 011010 32 1000011 13
001 0 il\11 20 \\0\00 33 0000101 14
010 I lOIII 21 001001 34 0001010 15
100 2 00111 22 010010 35 00\0\00 16
\0\ 3 01110 23 100100 36 0101000 17
Ill 4 11100 24 101001 37 \010000 18
Oil 5 10001 25 110011 38 0100011 \9
110 6 0\011 26 000111 39 1000110 20
\OliO 27 001110 40
GF(24) 00\01 28 011100 41 0001111 21
010\0 29 0011110 22
0001 0 10100 30 111000 42 0111100 23
0010 I 010001 43 1111000 24
0100 2 GF(26) 1000\0 44 11100\1 25
1000 3 100101 45 1100\0\ 26
\00\ 4 000001 0 \0\011 46 1001001 27
1011 5 000010 110111 47 0010001 28
\Ill 6 000100 2 001111 48 0100010 29
0111 7 00\000 3 011110 49 1000100 30
1110 8 0\0000 4 \11\00 50 000\011 31
0101 9 \00000 5 0\\00\ 51 0010110 32
1010 10 \00001 6 110010 52 0101100 33
I \01 II 100011 7 000101 53 1011000 34
0011 12 100111 8 0010\0 54 0\10011 35
0110 13 10\111 9 010\00 55 1100110 36
1100 14 \l\111 10 101000 56 1001111 37
0\\111 II 110001 57 0011101 38
GF(25) \\\110 12 000011 58 Oil 1010 39
011\01 \3 0001\0 59 II 10100 40
0000\ 0 1110\0 14 001100 60 110\0\\ 41
000\0 I 010\01 15 011000 61
00\00 2 101010 16 110000 62 \0\0101 42
01000 3 110\01 17 0101001 43
10000 4 001011 18 GF(27) 1010010 44
01001 5 0101\0 \9 0100111 45
10010 6 10\100 20 0000001 0 1001110 46
01101 7 0000010 I 0011111 47
11010 8 111001 21 0000100 2 0111110 48
II 101 9 010011 22 0001000 3 1111100 49
10011 10 1001\0 23 0010000 4 Ill \011 50
01111 11 101101 24 0100000 5 1110101 51
11110 12 \11011 25 1000000 6 I \01001 52
10101 \3 010111 26 0000011 7 1010001 53
1. Computation in Finite Fields
exp
GF(23)
0\0000\
1000010
0000\11
000\\\0
0011100
0\11000
1110000
11000\\
100010\
000100\
00\0010
0\00\00
100\000
00100\\
01001\0
\001100
0011011
01\0\10
1101100
\011011 ind
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
01\0\01 74
11010\0 75
\0\0\11 76
0\01\01 77
\011010 78
0\\0\\1 79
1101110 80
\OII\11 81
0\\l\0\ 82
111\0\0 8)
1110111 84
\\0\\0\ 85
\0\\00\ 86
01\000\ 87
1100010 88
1000111 89
0001101 90
00\\010 91
0110\00 92
I \01000 9]
\010011 94
010010\ 95
1001010 96
0010111 97
01011\0 98
1011100 99
0\\\0\\ 100 exp ind
GF(23)
II \0110 \01
I \01111 102
\011\01 103
0\\\00\ \04
1110010 \05
1100111 \06
\001101 107
00\\00\ 108
0\\00\0 \09
1100\00 110
1001011 ill
00\0\0\ 112
01010\0 Ill
1010100 114
0\0\0\\ 115
10\01\0 116
0\0\\11 117
\0111\0 118
Ollllll 119
1111110 120
llllill 121
ll\1101 122
l\1\00\ \2)
1110001 124
1100001 125
1000001 126
GF(l2)
01 0
10 I
21 2
22 J
02 4
20 5
12 6
II 7
GF(l3)
001 0
0\0 I
I 00 2
102 J
122 4
022 5
220 6
\0\ 7 e:xp ind
GF(l3)
112
222
121
012
120
002
020
200
201
211
Oil
110
202
221
Ill
212
021
210 8
9
10
II
12
\)
14
15
16
17
18
19
20
21
22
23
24
25
GF(l'l
0001
00\0
0\00
1000
2001
\012
2121
2212
0122
1220
1201
lOll
2111
2112
2122
2222
0222
2220
0202
2020
1202
1021
22\l
0112
1120
0201
20\0 0
2
J
4
5
6
7
8
9
10
II
12
\)
14
15
16
17
18
19
20
21
22
23
24
25
26 371
exp ind
GF(l'l
1102
0021
0210
2100
2002
1022
2221
0212
2120
2202
0022
0220
2200
0002
0020
0200
2000
1002
2021
1212
1121
0211
2110
2102
2022
1222
1221
1211
ill\
Oil\
1110
0\01
10\0
2101
2012
1122
0221
2210
0102
\020
2201
0012
0120
1200
1001
2011
1112
0121 27
28
29
30
31
32
))
34
35
]6
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
]72
TABLE A (Cont.)
exp ind
1210 75
1101 76
0011 77
0\\0 78
1100 79
GF(52\
01 0
10
43 2
42 3
32 4
44 5
02 6
20 7
31 8
]4 9
14 10
33 II
04 12
40 13
12 \4
13 15
23 \6
II 17
OJ 18
30 \9
24 20
21 21
41 22
22 23
GF(53)
00\
010
100
403
\]2
223
OJ I
3\0
304
244
241
211
411 0
I
2
3
4
5
6
7
8
9
10
II
12 exp ind
GF(53)
212
421
312
324
444
042
420
302
224
041 13
14
15
16
17
18
19
20
21
22
410 23
202 24
32\ 25
4\4 26
242 27
221 28
Oil 29
110 30
003 31
030 32
300 ]]
204 ]4
341 35
114 36
043 37
430 38
402 ]9
122 40
123 41
Ill 42
233 43
Ill 44
2\J 45
431
412
222
021
2\0
40\
112
023
230
101
4\3
232
121
Ill
Oll 46
47
48
49
50
51
52
53
54
55
56
57
58
59
60 exp ind
GF(53)
llO
004
040
400
102
423
332
024
240
201
311
3\4
344
144
343
134
243
231
Ill
Oil
IJO
203
331
0\4
140
303
234
141
3\ J
334
044
440
002
020
200 6\
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
8\
82
83
84
85
86
87
88
89
90
91
92
93
94
95
JOI 96
214 97
441 98
0\2 99
120 100
\OJ 101
4]] \02
432 \OJ
422 104
322 105
424 106
342 107
124 108 Tables
exp ind
GF(53)
143 \09
333 110
034 Ill
340 112
\04 Ill
443 114
032 115
320 116
404 117
142 118
323 119
434 120
442 121
022 122
220 \2]
GF(72)
01 0
10
64 2
53 3
56 4
\6 5
54 6
66 7
03 8
JO 9
45 10
12 II
\4 12
34
15
44
02
20
51
36
35
25
31
55
06
60
13 \3
14
15
16
17
18
\9
20
21
22
2]
24
25
26
L Computation in Finite Fields 373
exp ind exp ind exp ind exp ind
GF(12) GF(l\2) GF(\12) GF(I\2)
24 27 07 12 JO 49 06 84
21 28 70 IJ 60 85
61 29 46 14 52 86
25 15 81 50 89 87
23 30 38 16 4' 51 I • 88
II 3 I 51 17 65 52 94 89
04 32 79 18 '2 53
40 33 26 19 37 54 63 90
32 34 41 55 R2 91
65 35 48 20 85 56 5' 92
63 36 45 21 R' 57 59 93
43 ]7 15 22 2' 58 49 94
62 38 44 23 88 59 55 95
33 39 05 24 09 96
50 25 o• 60 90 97
05 40 69 26 •o 61 23 98
50 41 32 27 17 62 18 99
26 42 'I 28 64 63
41 43 27 29 92 64 74 100
42 44 43 65 86 101
52 45 58 30 '5 66 9' 102
46 46 39 ]\ 67 67 \] 103
22 47 61 32 12 68 24 104
62 33 14 69 28 105
72 34 68 106
GF(\121 66 35 34 70 22 107
02 36 II 71 08 108
01 0 20 37 04 72 80 \09
\0 I 98 38 40 73
'4 2 '3 39 75 74
57 3 96 75 3' 110
29 4 47 40 83 76 71 Ill
78 5 35 4\ 6' 77 56 112
16 6 21 42 42 78 19 113
54 7 'R 43 95 79 84 114
'9 8 97 44 7' 115
'7 9 93 45 73 80 36 116
53 46 76 81 3\ 117
87 10 99 47 '6 82 9\ 118
.. II 03 48 77 83 33 119
The symbol • denotes the element 10 in F 11•
374
TABLE B
over IF 2
o� • [OIJ 111
+1�2[ 11]20:1
+2�1 [11]10:2 0 �'[Ill] [I]
+I�S [101]43S:I
+2�3[ 101]163:2
+3�2 [011]063:
+4�6 [101]2S6:4
+ S �I [011]0 3 S:
+6 � 4 [011]0 s 6:-
over f2 over F 4
o� • [0001] [I] [01] [I]
+I� 4[0011]14 2 I 0: - [IX] 4 0: !
+2� 8[0011]13 4 2 0: - [I Y] 8 0: 2
3 � 14 [1111]14 10 I 2: II [YI] 2 S:l3
+4� I [0011]11 8 4 0: -[IX] I 0: 4
s � 10 [0101] [II] [OY] [X]
6�13[1111]13 s 24: 7 [XI] 4 10:11
+7� 9 [1001]9 2 10 I: 6 [XX]8 10:12
+8� 2 [0011] 7 I 8 0: - [IY] 2 0: 8
9� 7 [Ill I] 7 s 8 1:13 [XI] I 10:14
10� s [0101] [II] [OX]
+II� 12 [1001]12 I S 8: 3 [YY]4
12�11 [llll]IIIO 48:14 [Yl] 8
+13� 6[1001]6 8 10 4: 9 [XX]2
+14- 3 [1001]3 4 s 2:12 [YY]I
F, over F2
0 • [10011] [I]
+I �19 [10111]16 3 6 S 17: I
+2� 7[10111] 1 61210 3:2
+3�11 [01001]0 282S 6 3:
+4�14 [10111]2·122420 6: 4
+S�29[01111]4 28 s 14 9:
+6�22[01001]0 2S 19 12 6:
+ 7 � 2 [00101]27 20 17 10 3: -
+8�28[10111]4 2417 912: 8
+ 9 �IS [01111] I 7 9 19 10: -
+10�2 7[ 01111]8 2SI02818:
+II� 3 [11101]2312 7 6 3:1S
+12�13[01001]0 19 72412:
+ 13 � 12 [11101]30 1728 2412:29
+ 14 � 4 [00101]23 9 3 20 6: -
+IS� 9 [11011]2620 S 1910:11 [Y]
S: 6
S: 7
10: 3
S: 9 Tables
I. Computation in Finite Fields
over F2
+16�25[10111]8 17 318 24:16
+17�21[01001]0 1428 3 17:
+18�30[01111]2 1418 7 20:
+19� 1 [00101]291024 5 17:-
+20�23[01111]16192025 5:
+21�17 [11101]27 619 3 17:23
+22 � 6 [11101]15 2414 12 6:30
+23 � 20 [11011]13 1018 25 5:21
+24�26[01001]0 71 417 24:
+ 25 � 16 [00101]30 5 12 18 24: -
+26�24[11101]29 32517 24:27
+27�10 [11011]22 5 928 18:26
+28 � 8 [00101]15 18 6 9 12: -
+29� 5 [11011]111820 14 9:13
+30�18[11011]21 910 7 20:22
over f2
0-'[010101] [I]
+ 1-R [101101]44 43 58 54 53 45: -
+ 2 -16 [101101]25 23 53 45 43 27:
3-53 [010111]60 47 46 43 3 0:
+ 4-32 [101101]50 46 43 27 23 54:
+ 5-38 [100001]38 33 28 23 18 43:52
6-43 [010111]57 312923 6 0:
7-62 [001001] 42 35 28 0 56 49:
+ 8-I [101101]37 29 23 54 4<> 45:
9-45 [010001] [101]
+ 10-13 [100001]13 3 56 46 36 23:41
+11-5 1[110011]3714 3553648:11
12-23 [010111]51 62 58 46 12 0: -
+IJ-10[100111]10 759463323:17
14-61 [001001]21 7 56 0 49 35: -
15-44 [110101]51 36 46 31 47 3:15
+ 16- 2 [101101]11 58 46 45 29 27: -
+ 17-41 [100001]41 24 7 53 36 58:13
18-27 [010001] [101]
+ 19-34 [100111]34 49 62 43 24 53:20
+20-26 [100001]26 6 49 29 9 46:19
21-42 [101011] [II]
+22-39[110011]1128 647 933:22
+23 -12 [000011]40 29 6 46 23 0: -
24-46 [010111]39 61 53 29 24 0: -
+25-30 [110011]44 49 24 62 36 6:25 over f4
[Ill] [I]
[XXX]47 54 27: 8
[YYY]31 45 54:16
[OYI] 0 6 -3: -
[XXX]62 27 45:32
[XYY]23 56 49:
[OXI] 0 12 6: -
[00 X] 0 56 49:
[YYY]61 54 27: I
[101] 36 27 45: 9
[ YXX]46 49 35:
[Xi Y]55 48 24:25
[OYI] 0 24 12: -
[XYX]43 49 35: -
[OOY] 0 49 35: -
[YO I] 18 3 33:57
[XXX]59 45 54: 2
[XYY]53 14 28: -
[101] 9 54 27:18
[ XYX]58 28 56: -
[XYY]29 35 7: -
[XYI] [X]
[ Yl X]47 33 48:50
[IXY]31 24 12:58
[OXI] 0 48 24: -
[YIX]62 6 3:11 375
over IF11
[01] [I]
[lA] 8 0: I
[18]16 0: 2
[FD]42 18:39
[IC] 32 0: 4
[CF] 4 27:59
[D£]21 36:15
[£1] 2 9:25
[lA] I 0: 8
[08] [A]
[AD] 8 54:55
[AC]16 54:56
[EF]42 9:30
[A£]32 54:58
[FI] 4 18:50
[CA]21 27: 6
[18] 2 0:16
[AD] I 54:62
[OC] [8]
[ 8F] 8 45:46
[8£]16 45:47
[II] 42 0:21
[8A]32 45:49
[£8] 4 9:41
[FD]21 18:60
[AC] 2 54: 7
376
TABLE 8 (Cont.)
over f 2
+ 26 � 20 [100!11]20 14 55 29 3 46ol4
27�18 [000!01] [Oil]
28-59 [001001]42 \4 49 0 35 7o
+ 29-48 [000011]34 53 24 58 29 Oo
30-25 [110!01]39 9 29 62 31 6o30
+31�35 [011011]25 2961 02456o
+ 32- 4 [101!01]22 53 29 27 58 54o -
33-58 [010111]30 55 23 53 33 Oo -
+34 -19 [100001]19 48 \4 43 9 5U6
35-31 [001001]2\ 49 14 028 56o-
36-54 [0\0001] [!01]
+37�57 [\\0011]50 7 33 59\8 24o37
+38-5 [100!11] 5 35 6123 48 4NO
39-22 [\10101]57 \8 23 47 55 33o39
+40-52 [100001]52 12 35 58 !8 29o38
+41-17 [100111]1756 3\5312 58ol0
42-21 [10101\] [II]
+43-6 [000011]20 46 3 23 43 Oo -
+44-15 [110011]22 5612 3\ \8 3o44
45- 9 [00 0\01] [Oil]
+46-24 [000011]17 58 12 29 46 Oo
+47-49 [01\0l\]44 46 62 0 12 28o
4H - 29 [010\11]15 59 43 58 48 Oo
49 - 47 [001001]42 56 7 0 14 28o
+50-60[\\00II]25 354H6\ 912o50
51-11 [110\0\]60 9 43 55 59 48o5\
+52�40[\00II\]402H2758 629o 5
+53-3 [000011]10 23 33 43 53 Oo
54 � 36 [000\01] [01 \]
+55-56 [01101 1]22 23 31 0 6 14o
56-55 [001001]21 28 35 0 7 \4o -
57- 37 [110\01]30 36 53 59 61 24o57
+58-33 [000011] 5 43 48 53 58 Oo
+59-28 [Ol!Oll]\\ 43 47 0 l 7o-
60 - 50 [\10\01]15 \8 58 6\ 62 IHO
+61 � \4 [011011]37 53 55 0 33 35o
+62� 7 [0\\01 1]50 58 59 0 48 49o-over f4
[ YXY]23 35 7o
[Oil] o 54 n
[OOX] 0 35 7o
[\XY]61 JJ 48A3
[XOI] 36 6 loll
[I!X]46 28 56o
[ YYY]55 27 45o 4
[OX\] 0 3 33o
[ YXX]43 28 56o
[OOY] 0 28 56o
[101] \8 45 54o36
[Y\X[59 24 12o44
[ YXYJ53 56 49o -
jXOij 9 33 48o60
[YXXJ58 7 14o -
[ YXY[29 14 28o -
[YXIJ [Yj
[\YXJ47 12 6o29
[XI Yjl I J 33o37
[Oil] 0 27 45o
[IYX[ 62 48 24o53
[1\Yj 23 \428o
[OY\j 0 33 48o -
[OOX[ 0 14 28o -
[X!Yj61 12 6o22
[ Y01j 36 48 24o30
[XYXj46 7 !4o -
[\XYJ55 6 3o46
[011[ 0 45 54o
[1\Xj 43 7 \4o
[OOYJ 0 7 14o -
[XOI] 18 24 12o\5
[\YX] 59 3 3U3
[1\Yj 53 35 7o-
[YO!] 9 12 6o39
[l!X]58 4935o
[i\Y]29 56 49o -Tables
over F8
[BF] I 45o53
[OE] [D]
I Dl] 8 36o37
[DA]\6 36o38
[AB]42 54o\2
[ DD]J2 36o40
[JCI 4 om
[EF]21 9o51
[BE] 24Hl
[D1j I 36o44
[OA] [C]
[CB] 8 27o28
[CD]\6 27o29
[BC]42 45o 3
[CF]32 27o31
[A E] 4 54o23
[I\] 21 Oo42
IDA] 2 36o52
[CB] I 27o35
[OD] [F]
[FC] 8 18oi9
[FF]\6 !SolO
[D£]42 36o57
[Fij 32 1U2
[BA] 4 45o\4
[AB]ll 54oll
[CD] 2 27A3
[FC] 1 18o26
[OF] [Ej
[EE] 8 9o10
[El] 16 9o\1
[CA]42 27o48
[EB[l2 9o\3
[DD]436o 5
[BC]2\ 45o24
[EF] 2 18o34
[E£] I 9o\7
2. Tables of Irreducible Polynomials
2. TABLES OF IRREDUCIBLE POLYNOMIALS 377
Table C lists all monic irreducible polynomials of degree n over prime fields
F1 for small values of n and p. The extent of the table may be summarized
as follows: p � 2 and n � ll, p � 3 and n � 7, p � 5 and n � 5, p � 7 and
n :s:;: 4. The polynomial a0x�'� + a1xn-l + · · · +an is abbreviated in the form
a0 a1 ···a. with a0 � l. The left-hand column, headed by the value of n.
lists all monic irreducible polynomials I for the degree n and the modulus p
concerned . The right-hand column, headed by e, contains the corresponding
value of ord(/ ).
Table D lists one primitive polynomial over IF2 for each degree
n � 100. In this table only the degrees of the separate terms in the poly
nomial are given; thus 6 l 0 stands for x6 + x + l.
Table E lists all primitive polynomials x2 + a1x + a2 of degree 2 over
IFr for ll � p � 31. For smaller primes all quadratic primitive polynomials
can be obtained from Table C by locating the polynomials I over IFP with
ord(/) � p2 -1.
Table F lists one primitive polynomial of degree n over IF, for all
values of n;;. 2 andp withp <50 andp" < 109• The polynomial x" + a1x"-1
+ a2x�'�- 2 + · · · +an is listed in the form a1 a2 ···an.
378 Tables
TABLE C
lrredu�ible Polynomials for the Modulus 2
n-1 e 10111001 127 I 0000110 II 511 1111100011 511
10111111 127 I 000 I 0000 I 511 1111101001 511
10 I 11000001 127 1000101101 511 lllllll OII 511
II I 11001011 127 1000110011 511
11010011 127 1001001011 73 n-10 e
n=2 e 11010101 127 1001011001 511
11100101 127 100101 1111 511 1000000 1001 1023
Ill 3 11101111 127 1001100101 73 1000000 1111 341
11110001 127 1001101001 511 100000 11011 1023
n�3 e 11110111 127 1001101111 511 100000 11101 341
IIIIIIOI 127 1001110111 511 I 0000 I 00 II I 1023
lOll 7 1001111101 511 I 0000 I 0 I 10 I 1023
1101 7 n=8 e 10 I 0000 I I I 511 I 0000 110 10 I 93
lP<\QljiO) I 1010010101 511 10001000 111 341
n-4 e '• 51 1010011001 73 10001010011 341
100011101 255 1010100011 511 10001100011 341
10011 15 100101011 255 1010100101 511 10001100101 1023
11001 15 100101 101 255 1010101111 511 10001101111 1023
IIIII 5 100111001 17 10101101 11 511 10010000001 1023
100 llllll 85 1010111101 511 10010001011 1023
n-5 e 101001101 255 1011001 111 511 1001001 1001 341
101011111 255 1011010001 511 10010101001 33
100101 31 101100011 255 101101 1011 511 IOOIOIOIIII 341
101001 31 101100101 255 1011110101 511 10011000101 1023
lOIII! 31 101101001 255 1011111001 511 10011001001 341
!lOIII 31 IO!.UOOOI 255 1100000001 73 10011010111 1023
111011 31 (10111011\ 85 1100010011 511 10011100111 1023
111101 31 101111011 85 1100010101 511 10011101101 341
I I 0000 II I 255 1100011111 511 10011110011 1023
n�6 e 110001011 85 1100100011 511 10011111111 1023
110001101 255 1100110001 511 10 I 0000 10 II 93
1000011 63 110011111 51 1100111011 511 10 I 0000 110 I 1023
1001001 9 110100011 85 1101001001 73 10100011001 1023
1010111 21 110101001 255 1101001111 511 10100011111 341
1011011 63 110110001 51 1101011011 511 10100100011 1023
I I 0000 I 63 110111101 85 II 0 I 10000 I 511 101001 10001 1023
1100111 63 I I I 0000 I I 255 1101101011 511 101001 11101 1023
1101101 63 111001111 255 1101101101 511 10101000011 1023
1110011 63 111010111 17 1101110011 511 101010101 11 1023
1110101 21 111011101 85 1101111111 511 10 I 0 II 0000 I 93
111100111 255 I II 0000 10 I 511 10101100111 341
,, = 7 e 111110011 51 1110001111 511 10101101011 1023
111110101 255 I I 10 I 0000 I 73 10 II 0000 10 I 1023
100000 11 127 IIIIIIOOI 85 1110110101 511 10110001111 1023
10001001 127 1110111001 511 10110010111 1023
10001111 127 n-9 e 1111000111 511 10110011011 341
10010001 127 1111001011 511 10110100001 1023
10011101 127 10000000 11 73 1111001101 511 10110101 011 341
101001 11 127 I 0000 I 000 I 5!1 1111010101 511 101101 11001 341
10101011 127 1000010 II I 73 1111011001 511 10111000001 341
2. Tables of Irreducible Polynomials 379
Irreducible Pol ynomials for the Modulus 2
10111000111 1023 11111011011 1023 100111100101 2047 101111101101 2047
10111100101 1023 11111101011 341 100111101111 89 11000000 1011 2047
10111110111 1023 11111110011 1023 100111110111 2047 11000000 1101 2047
10111111011 1023 11111111001 1023 10 I 00000000 I 2047 110000011001 2047
11000010011 1023 11111111111 II 101000000 111 2047 110000011111 2047
11000010101 1023 101000010011 2047 110000110001 89
110001000 11 33 n=!! e 10100001010 I 2047 110001010111 2047
11000100101 1023 101000101001 2047 110001100001 2047
11000110001 341 I 00000000 10 I 2047 101001001001 2047 110001101011 2047
11000110111 1023 1000000 10111 2047 101001100001 2047 110001110011 2047
11001000011 1023 100000 101011 2047 101001101101 2047 110001110101 23
11001001 111 1023 100000 101101 2047 101001111001 2047 110010000101 2047
11001010001 341 100001000 111 2047 101001111111 2047 IIOOIOOOHlol 2047
11001011011 1023 100001100011 2047 1010 I 0000101 2047 1100100101 11 2047
11001111001 1023 100001100101 2047 10101001 0001 2047 1100100110 11 2047
11001111111 1023 10000 1110001 2047 1010100 11101 2047 110010011101 2047
11010000101 93 10000 1111011 2047 101010100 111 2047 110010110011 2047
11010001001 1023 10001000 1101 :!047 101010101011 2047 110010111111 2047
110101001 11 93 100010010101 2047 1010101 10011 2047 110011000111 2047
11010101101 341 100010011111 2047 101010110101 2047 110011001 101 2047
11010110101 1023 1000 10101001 2047 101011010101 2047 110011010011 2047
11010111111 341 100010110001 2047 101011011111 2047 110011010101 2047
11011000001 1023 100011000011 89 101011100011 23 110011100011 2047
11011001 101 341 100011001111 2047 101011101001 2047 110011101001 2047
11011010011 1023 100011010001 2047 101011101111 2047 110011110111 2047
11011011111 1023 1000 11100001 2047 101011110001 1047 1101000000 11 2047
11011110111 341 100011100111 2047 101011111011 2047 110100001111 2047
11011111101 1023 100011101011 2047 1011000000 11 2047 110100011101 2047
11100001111 341 100011110101 2047 101100001001 2047 1101001001 11 2047
11100010001 341 100100001101 2047 101100010001 2047 110100101101 2047
11100010111 1023 100100010011 2047 101100110011 2047 110101000001 2047
11100011101 1023 100100100101 2047 101100111111 2047 110101000111 2047
11100100001 1023 100100101001 2047 101101000001 2047 110101010101 2047
11100101011 93 1001001101 11 89 101101001011 2047 11010101 1001 2047
11100110101 341 1001001 11011 2047 101101011001 2047 110101100011 2047
11100111001 1023 1001001 11101 2047 101101011111 2047 110101101 111 2047
11101000111 1023 100101000101 2047 101101100101 2047 110101110001 2047
11101001101 1023 100101001001 2047 1011011 01111 2047 110110010011 2047
11101010101 1023 10010101 0001 2047 101101111101 2047 110110011111 2047
11101011001 1023 10010101 1011 2047 101110000111 2047 110110101001 2047
11101100011 1023 100101110011 2047 101110001011 2047 110110111011 2047
11101111011 341 100101110101 2047 101110010011 2047 110110111101 2047
11101111101 1023 1001011111ll 2047 101110010101 2047 110111001001 2047
11110000001 341 100110000011 2047 101110101111 2047 110111010111 2047
11110000111 341 100110001111 2047 101110110111 2047 110111011011 2047
11110001101 1023 10011010101 1 2047 101110111101 2047 110111100001 2047
11110010011 1023 100110101101 2047 10ll11 001001 2047 1101ll100111 2047
11110101001 341 100110111001 2047 101111011011 2047 110111110101 2047
11110110001 1023 100111000111 2047 101111011101 2047 110111111111 89
11111000101 341 100111011001 2047 101111100111 2047 111000000 101 2047
380 Tables
TABLE C (Cont.)
Irreducible Polynomials for the Modulur 2
111000011101 2047 111001111011 2047 111011111001 2047 111110010001 2047
111000100001 2047 1110011111 01 2047 111100001011 2047 111110010111 2047
111000100111 2047 111010000001 2047 111100011001 2047 111110011011 2047
111000101011 2047 11101001001 1 2047 111100110001 2047 111110100111 2047
111000110011 2047 111010011111 2047 111100110111 2047 111110101101 2047
111000111001 2047 111010100011 2047 111101011101 2047 111110110101 2047
111001000111 2047 111010111011 2047 111101101011 2047 111111001101 2047
111001001011 2047 111011001001 89 111101101101 2047 111111010011 2047
111001010101 2047 111011001111 2047 111101110101 2047 111111100101 2047
111001011111 2047 111011011 101 2047 111101111001 89 1111111 01001 2047
111001110001 2047 111011110011 2047 111110000011 2047 111111111 011 89
Irreducible Polynomials for the Modulus 3
n =I ' 12101 40 120001 242 1011022 728 1111112 728
12112 80 120011 242 1011122 728 1111222 728
10 I 12121 10 120022 121 1012001 182 1112011 91
II 2 12212 80 120202 121 1012012 728 1112201 182
12 I 120212 121 1012021 364 1112222 728
n-5 ' 120221 242 1012112 728 1120102 728
n-2 e 121012 121 1020001 52 1120121 91
100021 242 121111 242 1020101 52 1120222 728
101 4 100022 121 121112 121 1020112 728 1121012 728
112 8 100112 121 121222 121 1020122 728 1121102 728
122 8 100211 242 122002 121 1021021 364 1121122 104
101011 242 122021 242 1021102 56 1121212 728
n�3 e 101012 121 122101 242 1021112 728 1121221 364
101102 121 122102 121 10 21121 91 1122001 91
1021 26 101122 121 122201 22 1022011 364 1122002 104
1022 13 101201 242 122212 121 1022102 56 1122122 104
1102 13 101221 242 1022111 182 1122202 728
1112 13 102101 242 n=6 ' 1022122 728 1122221 364
1121 26 102112 121 1100002 728 1200002 728
1201 26 102122 II 1000012 728 1100012 56 1200022 56
1211 26 102202 121 1000022 728 1100111 364 1200121 364
1222 13 102211 242 1000111 364 1101002 728 1201001 364
102221 22 1000121 364 1101011 28 1201111 182
n=4 ' 110002 121 1000201 52 1101101 364 1201121 182
110012 121 1001012 728 1101112 728 1201201 364
10012 80 110021 242 1001021 364 1101212 728 1201202 728
10022 80 110101 242 1001101 91 1102001 364 1202002 728
10102 16 110111 242 1001122 104 1102111 91 1202021 28
lOIII 40 110122 121 1001221 182 1102121 91 1202101 364
10121 40 111011 242 1002011 364 1102201 364 1202122 728
10202 16 111121 242 1002022 728 1102202 728 1202222 728
11002 80 111211 242 1002101 182 1110001 364 1210001 364
11021 20 111212 121 1002112 104 1110011 364 1210021 364
11101 40 112001 242 1002211 91 1110122 728 1210112 728
IIIII 5 112022 121 1010201 52 1110202 728 1210202 728
11122 80 112102 II 1010212 728 1110221 182 1210211 91
11222 80 112111 242 1010222 728 1111012 728 1211021 182
12002 80 112201 242 1011001 91 1111021 182 1211201 91
12011 20 112202 121 101101 1 364 1111111 7 1211212 728
2. Tables of Irreducible Polynomials 381
Irreducible Polynomials for the Modulus 3
1212011 91 10022021 2186 102020 12 1093 11021122 1093 11201222 1093
12\2022 728 10022101 2186 10210001 2186 11021201 2186 11202002 1093
1212121 14 10022212 1093 10210121 2186 11021212 1093 11202121 2186
1212122 728 10100011 2186 10210202 1093 11022101 2186 11202211 2186
1212212 728 10100012 1093 10211101 2186 11022122 1093 11202212 1093
1220102 728 10100102 1093 10211111 2186 11022211 2186 11210002 1093
1220111 182 10100122 1093 10211122 1093 11022221 2186 11210011 2186
12202\2 728 l0100201 2186 10211221 2186 11100002 1093 11210021 2186
1221001 182 10100221 2186 10212011 2186 11100022 1093 11210101 2186
1221002 104 10101101 2186 10212022 1093 11100121 2186 11211001 2186
1221 I 12 104 10101112 1093 10212101 2186 11100212 1093 11211022 1093
1221202 728 10101202 1093 10212112 1093 11101012 1093 11211122 1093
1221211 364 10l01211 2186 10212212 1093 11101022 1093 11211212 1093
1222022 728 10102102 1093 10220002 1093 11101102 1093 11211221 2186
1222102 728 10102201 2186 10220101 2186 ll!Ollll 2186 11212012 1093
1222112 104 10110022 1093 10220222 1093 11101121 2186 11212112 1093
1222211 364 10110101 2186 10221122 1093 11102002 1093 11212202 1093
1222222 728 l0ll0211 2186 10221202 1093 11102111 2186 11220001 2186
10111001 2186 10221212 !093 11102222 1093 11220112 1093
n-7 e 10111102 1093 10221221 2186 11110001 2186 11220211 2186
10111121 2186 10222012 1093 11110012 1093 11221022 1093
10000102 1093 10111201 2186 10222021 2186 11110111 2186 11221102 1093
10000121 2186 10112002 1093 10222111 2186 11110112 1093 11221112 1093
10000201 2186 10112012 1093 10222202 1093 11110211 2186 11221121 2186
10000222 1093 10112021 2186 102222 11 2186 11110222 1093 11222011 2186
10001011 2186 101121 11 2186 11000101 2186 Iilli (Jj I 2186 11222102 1093
10001012 1093 10112122 1093 11000222 1093 11111021 2186 11222122 1093
10001102 1093 10120021 2186 11001022 1093 11111201 2186 11222201 2186
10001111 2186 10120112 1093 11001112 1093 11111222 1093 11222221 2186
10001201 2186 10120202 1093 11001211 2186 11112011 2186 12000121 2186
10001212 1093 10121002 1093 11002012 1093 11112221 2186 12000202 1093
10002112 1093 10121102 1093 11002022 1093 11120102 1093 12001021 2186
10002122 1093 10121201 2186 11002121 2186 11120111 2186 12001112 1093
100022 11 2186 10121222 1093 11002202 1093 11120122 1093 12001211 2186
10002221 2186 10122001 2186 110!0001 2186 11120212 1093 12002011 2186
1001012 2 1093 10122011 2186 11010022 !093 11120221 2186 12002021 2186
10010222 1093 10122022 1093 11010121 2186 11121001 2186 12002101 2186
10011002 1093 10122212 1093 11010221 2186 11121101 2186 12002222 1093
10011101 2186 10122221 2186 110!1111 2186 11121202 1093 12010021 2186
10011211 2186 10200001 2186 11011202 !093 11122021 2186 120100 22 1093
10012001 2186 10200002 1093 11012002 !093 11122112 1093 1201010 2 1093
10012022 1093 10200101 2186 11012102 1093 11122201 2186 12010121 2186
10012111 2186 10200112 1093 11012212 1093 11122222 1093 12010201 2186
10012202 1093 10200202 1093 11020021 2186 11200201 2186 12010211 2186
10020121 2186 10200211 2186 11020022 1093 11200202 1093 12011102 1093
10020221 2186 10201021 2186 11020102 1093 11201012 1093 12011111 2186
10021001 2186 10201022 1093 11020112 1093 11201021 2186 12011212 1093
10021112 1093 10201121 2186 11020201 2186 11201101 2186 12011221 2186
10021202 1093 10201222 1093 11020222 1093 11201111 2186 12012112 1093
10022002 1093 102020 11 2186 11021111 2186 11201221 2186 12012122 1093
382 Tables
TABLE C (Cont.)
Irreducible Polynomials for the Modulus 3
12012202 1093 12101201 2186 12112211 2186 12201121 2186 12212122 1093
12012221 2186 12101212 1093 12120002 1093 12201122 1093 12212201 2186
12020002 1093 12101222 1093 12120011 2186 12201202 1093 12212221 2186
12020021 2186 12102001 2186 12120lli 1093 12201212 1093 12220001 2186
12020122 1093 12102121 2186 12120121 2186 12202001 2186 12220012 1093
12020222 1093 12102212 1093 12120211 2186 12202111 2186 12220022 1093
12021101 2186 12110111 2186 12120212 1093 12202112 1093 12220202 1093
12021212 1093 12110122 1093 12121012 1093 12202222 1093 12221002 1093
12022001 2186 12110201 2186 12121022 1093 12210002 1093 12221021 2186
12022111 2186 12110212 1093 12121102 1093 12210112 1093 12221111 2186
12022201 2186 12110221 2186 12121121 2186 12210211 2186 12221122 1093
12100001 2186 12111002 1093 12122012 1093 12211021 2186 12221221 2186
12100021 2186 12111101 2186 12122122 1093 12211201 2186 12222011 2186
121001 11 2186 12111202 1093 12200101 2186 12211211 2186 12222101 2186
12100222 1093 12112022 1093 12200102 1093 12211222 1093 12222211 2186
1210101 1 2186 12112102 1093 12201011 2186 12212012 1093
12101021 2186 12112121 2186 12201022 1093 1221210 2 1093
Irreducible Polynomials for the Modulus 5
n-l ' !Ill 124 n-4 ' 11013 624 12022 624 13102 208
1114 )I 11023 624 12033 624 13121 52
10 I Ill I 62 10002 16 11024 104 12042 624 13124 312
II 2 1134 )I 10003 16 11032 624 12102 208 llll I 26
12 4 1141 62 10014 312 11041 52 12121 13 !Jill 624
13 4 1143 124 10024 312 11042 624 12123 624 13201 78
14 I 1201 62 10034 312 11101 78 12131 52 13203 624
1203 124 10044 312 11113 624 12134 312 13232 624
n=2 e 1213 124 10102 48 11114 312 12201 39 13234 312
1214 31 lOIII 78 11124 104 12203 624 13241 !56
102 8 1222 124 10122 624 11133 208 12211 !56 13302 624
!OJ 8 1223 124 10123 624 11142 208 12222 624 Ill 14 104
Ill ) 1242 124 10132 624 11202 624 12224 312 13322 624
112 24 1244 l I 10133 624 11212 624 12302 624 13323 208
123 24 1302 124 10141 39 11213 208 12311 39 13334 312
124 12 1304 31 1020) 48 11221 !56 12312 208 13341 78
Ill 24 13 II 62 10221 39 11222 208 12324 312 13342 208
134 12 1312 124 10223 208 11234 104 12332 624 13401 !56
141 6 1322 124 10231 78 11244 312 12333 208 13413 208
142 24 1323 124 10233 208 IIJOI !56 12344 104 13423 624
1341 62 10303 48 Ill OJ 624 12401 !56 13424 312
n-) e 1343 124 lOlli !56 11321 39 12414 104 13432 208
1403 124 IOJIJ 208 11342 624 12422 208 13444 104
101 I 62 1404 )I 10341 !56 \\l44 312 12433 624 14004 312
1014 J I 1411 62 10343 208 11402 208 12434 312 14011 52
1021 62 1412 124 10402 48 11411 13 12443 208 14012 624
1024 31 1431 62 10412 624 11414 312 13004 312 14022 624
1032 124 1434 31 10413 624 11441 52 13012 624 14033 624
1033 124 1442 124 10421 !56 11443 624 13023 624 14034 104
1042 124 1444 )I 10431 !56 12004 312 IJOJI 13 14043 624
1043 124 10442 624 12013 624 13032 624 14101 39
1101 62 10443 624 12014 104 13043 624 14112 208
1102 1)_4 11004 "' J?n?l " """" 1M J.i1?1 '"'
2. Tables of Irreducible Polynomials 383
Irreducible Polynomials for the Modulus 5
14134 104 101033 284 103014 781 110123 3124 112034 781 114014 781
14143 624 101103 3124 103022 3124 110131 1562 112104 781 114024 781
14144 312 101104 781 103023 3124 110142 3124 112113 3124 114033 3124
14202 624 101141 1562 103101 1562 110144 781 1121JJ 3124 114044 781
14214 311 101142 3124 103104 781 110202 284 112142 3124 114102 3124
14224 104 101203 3124 103111 1562 110213 3124 112143 284 114132 3124
14231 156 101204 781 103112 3124 110232 3124 112201 1562 114141 1562
14232 208 101212 3124 103143 3124 110243 3124 112212 3124 114201 1562
14242 624 101213 284 103144 71 110244 781 112214 781 114204 71
14243 208 101301 1562 103211 1562 110301 1562 112234 781 114233 3124
14301 156 101302 3124 103212 3124 110303 3124 112241 1562 114242 3124
14303 624 101312 284 103221 1562 110322 3124 112243 3124 114314 781
14312 624 101313 3124 103223 3124 11033 I 1562 112301 1562 114321 1562
14314 312 101401 1562 103232 '3124 110333 3124 112311 1562 114322 3114
14331 78 101402 3124 103233 3124 110343 3124 112313 3124 11433 I 1562
14402 208 101443 3124 103313 3124 110403 3124 112314 781 114343 3124
14411 52 101444 781 103314 781 110411 1562 112323 3124 114401 1562
1441] 624 ·102001 1562 103322 3124 110421 1562 112334 71 114403 3124
14441 26 102004 781 103324 781 110432 3124 112342 3124 114424 781
14444 312 102012 3124 103332 3124 110441 1562 112422 3124 114431 22
102013 3124 103333 3124 110442 3124 112433 3124 114434 781
n-5 e 102021 1562 103401 1562 110444 781 112441 1562 114442 3124
102024 781 103404 781 111003 284 113002 3124 120003 3124
100041 1562 102112 3124 103413 3124 111013 3124 113004 781 120013 3124
100042 3124 102114 781 103414 781 111021 1562 113034 781 120042 3124
100043 3124 102121 1562 103441 142 111022 3124 113044 781 120104 71
100044 781 102122 3124 103442 3124 111024 781 113103 3124 120111 1562
100102 3124 102131 1562 104021 1562 111032 3124 IIlii I 1562 120134 781
100114 781 102134 781 104024 781 111044 781 113134 781 120141 1562
100124 71 102202 3124 104031 142 111102 3124 113142 284 120143 3124
100132 3124 102203 3124 104034 71 111114 781 Ill 143 3124 120201 1562
100143 3124 102211 1562 104101 1562 111123 3124 113211 1562 120212 312 4
100201 1562 102213 3124 104103 3124 111212 44 113222 3124 120222 3124
100212 3124 102242 284 104111 142 111224 781 113224 71 120234 781
100222 284 102244 781 104114 781 111231 1562 113231 1562 120242 3124
100231 1562 102302 3124 104202 3124 111234 781 113241 1562 120243 3124
100244 781 102303 3124 104204 781 111301 1562 113243 284 120244 781
100304 781 102312 3124 104241 1562 111311 1562 IIJJ04 781 120321 1562
100313 3124 102314 781 104243 3124 111312 3124 113312 3124 120332 3124
100323 284 102341 1562 104301 1562 111324 71 113321 1562 120343 3124
100334 781 102343 284 104303 3124 111334 781 IIJJ23 3124 120344 781
100341 1562 102411 1562 104342 3124 111401 142 113324 781 120401 1562
100403 3124 102413 3124 104344 781 111404 781 113332 3124 120402 3124
100411 1562 102423 3124 104402 3124 111423 3124 IIJJ42 3124 120424 781
100421 142 102424 781 104404 781 111431 1562 113412 3124 120431 1562
100433 3124 102431 1562 104411 1562 111433 3124 113422 3124 120432 3124
100442 3124 102434 781 104414 71 111442 3124 113434 781 120441 1562
101022 3124 103002 3124 110004 781 112012 3124 114001 1562 121002 3124
101023 3124 103003 3124 110014 781 112023 3124 114011 1562 121012 3124
101032 284 103011 1562 110041 1562 112032 3124 114012 3124 121013 3124
184 Tables
TABLE C (Cont.)
Irreducible Polynomials for the Modulus 5
121014 781 12l0l4 781 llOIOl 3124 I 12042 3124 114022 1124 141021 3124
121021 1124 121102 3124 110104 181 132102 3124 ll402l 1124 141024 781
12101 I 1562 12llll ] 124 I 10121 1562 112111 1562 ll40ll 1562 1410ll ]\24
121041 1124 121114 781 I lO Ill 1124 112122 1124 114042 ] 124 141041 1562
121102 1124 \2] \3] 3124 110134 181 132121 ]124 134103 3124 141101 1562
12!!03 284 123141 1562 130144 781 112124 781 134111 1562 141104 71
1211 l I 1562 123142 3124 I 10224 781 I 32� l I 1562 134111 1124 141122 ] 124
121144 181 121224 781 1302ll 1124 112141 1562 1]4122 284 1411 l2 3124
121201 1562 123211 1562 110241 1562 132204 781 I 34132 ] 124 141\]4 781
121202 3124 123242 ]\24 130242 3124 ll221l 3124 134201 1562 141143 3124
121221 ]\24 12ll03 3124 ll0l04 781 I l22l2 3124 114212 ]\24 141204 781
121212 44 12ll II 1562 IJOl I l 1124 132241 142 134224 781 14121 l 1124
1212ll 3124 12llll 1562 I l0l2l 3124 132244 781 I 14302 ll24 141214 781
121244 781 12ll41 142 IJOJJI 1562 132111 1562 I l430l 284 141221 142
121104 781 123144 181 ll0l41 1562 132121 1562 134324 781 14121 I 1562
121ll4 781 121402 1124 130342 3124 ll2ll2 1124 134313 ]\24 14ll I l 44
121142 1124 123411 1562 130341 3124 132413 3124 I 34334 m 14ll21 I 562
121411 ]\24 123412 3124 110401 142 132421 1562 114]41 1562 141ll I 1562
121422 3124 12l41l 3124 110414 781 I 32422 284 134411 22 141334 781
121424 781 123421 1562 130411 1562 1324]] ]\24 !34422 ]\24 141403 1124
121432 1124 123433 284 110442 1124 132443 1124 1344]2 3124 141411 1562
121441 1562 123444 781 110444 781 132444 71 1344]] 3124 \41422 3124
122001 3124 124001 142 lliOOJ 1124 IJJOII 1562 140001 1562 14201J 1124
122004 781 124011 1562 13 lOll 1562 133024 781 140011 1562 142022 1124
1220ll 1124 124022 3124 131012 3124 lll031 1562 140044 781 142031 1562
122043 1124 124023 1124 ll lOll 1124 IJJOJ2 1124 140102 ]124 l420ll 3124
122112 3124 124024 781 111022 1124 Ill IOl 3124 140114 781 142123 3124
122121 284 1240.34 781 1]1014 781 Ill 112 1124 140124 781 142132 ]\24
122124 781 124041 ]124 131042 3124 Ill Ill ]\24 1401 ll 1124 142144 781
122132 3124 124114 II ll 1112 3124 ]]] 114 781 140141 1562 142204 7RI
122141 142 124\23 ]124 ll 1121 1562 113124 781 140141 ]124 142211 1562
122142 3124 124\32 3124 llll2l ]\24 13lll2 284 140144 781 142212 ]\24
122214 781 12413] 1124 I l II ll 3124 IJJ141 1562 140202 3124 142214 781
122224 781 124202 284 ll 1144 781 133202 ]\24 140204 781 142222 1124
1222ll 3124 124203 3124 ll 1201 1562 133214 181 140223 3124 142231 142
122101 1562 124221 1562 I l 121 I 1562 lll2l4 781 140232 3124 142243 3124
122312 3124 124231 1562 ll124l 3124 13]241 1562 140214 781 142104 781
122333 3124 124232 3124 ll130l 3124 lll244 71 140242 3124 142111 1562
122341 1562 124244 781 131104 781 llll21 1562 140l0l 284 142313 3124
122344 71 124104 781 I l 1122 l 124 lllll4 781 140]12 ll24 142331 1562
122401 1124 124113 3124 Ill 3]2 3124 133343 3124 140133 3124 142142 3124
122414 781 124321 1562 llllll 44 lll40l 1124 140141 1562 142144 781
122421 1562 124402 1124 ll I 141 1562 lll411 1562 140142 l 124 142401 1562
122422 1124 124412 3124 1]1402 284 1]3412 ]124 140422 1124 142412 3124
122423 3124 124414 781 ll140l 3124 lll4l2 1124 140434 781 1424]2 3124
122434 781 124423 284 131434 781 lll443 l 124 140441 1562 142442 284
122444 781 124433 1124 131441 1562 I ll444 781 140441 1124 142443 ]124
121014 781 130002 3124 132001 1562 I 14004 71 141002 284 141001 1562
121021 1562 1)0012 ]124 1)2002 3124 114014 781 1410!2 3124 143001 3124
12l0ll 1124 ll004l 3124 132032 l 124 114021 I 562 141021 1562 14l0ll 1562
2. Tables of Irreducible Polynomials
143041
143113
14312l
143131
143201
143213
143221
143222
"=I
10
11
12
13
14
15
16
n=2
101
102
104
ill
114
116
122
123
125
131
135
136
141
145
146
152
153
155
163
164
166
n=3
1002
1003
1004
1005
lOll
. "" 1562
3\24
3124
1562
1562
3124
1562
3124
'
1
2
6
3
6
3
1
e
4
12
12
48
24
16
24
48
48
8
48
16
8
48
16
24
48
48
48
24
16
e
18
9
18
9
114
--143224
143233
143243
143314
143321
143323
143334
143342
1021
1026
1032
1035
1041
1046
1052
1055
1062
1065
1101
1103
1112
1115
1124
1126
ill 1
1135
1143
1146
1151
1152
1153
1154
1163
1165
1201
1203
1214
1216
1223
1226
1233
1235
1242
1245
1251
1255
1261
1262
1263
. �' . Irreducible Polynomials for the Modulus 5
781 143344 781 144013 3124 144131
3124 143402 3124 144014 781 144134
3124 143414 781 144021 1562 144143
781 143431 1562 144032 3124 144211
142 143442 3124 144041 1562 144223
3124 143443 284 144102 3124 144224
781 144004 781 144104 781 144234
284 144011 1562 144121 1562 144242
Irreducible Polynomials for the Modulus 7
38
19
342
171
114
57
342
171
342
171
114
171
342
171
342
57
38
171
171
57
114
342
171
342
171
171
38
171
342
57
l7l
57
171
171
342
171
114
171
114
342
171
. .. 1304
1306
llll
1314
1322
1325
llll
ll34
1335
ll36
1341
1343
1352
1354
1362
1366
1401
1403
14ll
1416
1422
1425
1431
1432
1433
1434
1444
1446
1453
1455
1461
1465
1504
1506
1511
1513
1521
1524
1532
1534
1542
. - -342
57
38
342
342
171
171
342
171
19
38
171
342
342
342
57
114
171
171
19
342
171
38
342
171
342
342
19
171
171
114
171
342
19
114
171
114
342
342
342
342
-1552 342 10135
1556 57 10145
1563 171 10151
1564 342 10161
1565 171 10162
1566 57 10203
1604 342 10205
1606 57 10 211
1612 342 10214
1615 171 10224
1621 114 10236
1623 171 10246
1632 342 10254
1636 19 10261
1641 114 16264
1644 342 10305
1653 171 10306
1654 342 10316
1655 171 10322
1656 57 10326
1662 342 10333
1664 342 10334
10335
n=4 e 10343
10344
10011 400 10345
10012 1200 10352
10014 1200 10356
10023 480 10366
10025 480 10405
10026 160 10406
10053 480 10412
10055 480 10414
10056 160 10422
10061 400 10433
10062 1200 10443
10064 1200 10452
10103 96 10462
10106 32 10464
lOlli 400 10503
10112 600 10505 385
1562 144301 142
11 144304 781
3124 144332 3124
1562 144343 3124
3124 144403 3124
781 144433 3124
781 144444 781
3124
2400 10524 1200
2400 10525 2400
200 10531 80
400 10533 2400
600 10536 800
96 10541 80
96 10543 2400
200 10546 800
1200 10554 1200
600 10555 2400
800 10565 2400
800 10603 96
600 10606 32
200 10613 2400
1200 10621 400
96 10623 2400
32 10632 240
800 10635 2400
1200 10636 800
800 10642 240
2400 10645 2400
240 10646 800
2400 10651 400
2400 10653 2400
240 10663 2400
2400 11001 400
1200 11003 480
800 llOll 2400
800 11026 800
96 11031 400
32 11042 75
1200 11054 300
600 11056 800
600 11062 1200
2400 11063 2400
2400 11101 400
600 I i lOJ 2400
1200 11105 2400
600 11111 5
96 11112 1200
96 11124 75
386 Tables
TABLE C (C011t.l
Irreducible Polyllomials for the Modulus 7
11136 800 11556 800 12266 800 12665 480 13432 1200 14125 2400
11141 400 11562 1200 12303 2400 13004 1200 13434 1200 14132 1200
11152 1200 11566 160 12304 240 13005 480 13436 800 14145 2400
11153 2400 11602 240 12311 200 ll011 400 13441 20 14156 800
11161 100 11605 2400 12323 2400 13015 2400 13443 2400 14165 2400
11163 480 11614 600 12325 2400 13022 300 13445 2400 14204 1200
11166 800 11625 2400 12332 120 13023 2400 ll455 2400 14205 2400
11201 200 11626 800 12345 480 13031 50 13456 800 14206 800
11204 600 11631 40 12346 800 13044 1200 IJ465 2400 14211 400
11213 2400 11643 2400 12351 100 13053 2400 13501 80 14214 15
11223 2400 11646 160 12354 600 13065 2400 13506 800 14222 75
11225 2400 11652 600 12356 800 13103 2400 13512 600 14232 240
11232 60 11653 2400 12361 200 13106 800 13513 2400 142JJ 2400
11233 2400 11654 300 12363 2400 13115 2400 13516 800 14244 1200
11236 800 11664 600 12365 2400 13126 800 13521 200 14251 400
11241 400 11665 2400 12402 1200 13135 2400 13522 300 14255 2400
11244 1200 11666 800 12403 2400 13142 1200 13525 2400 14263 2400
11245 2400 12002 1200 12406 800 13151 400 13533 480 14264 300
11252 240 12006 160 12412 15 13155 2400 13535 2400 14265 480
11254 300 12016 800 12414 1200 13161 400 13544 120 14302 1200
11266 160 12025 2400 12421 25 13166 160 13553 2400 14314 ISO
11321 200 12032 1200 12431 80 13204 1200 13556 800 14325 2400
11323 2400 12044 75 12435 2400 13205 2400 13562 600 14335 2400
11324 ISO 12051 100 12442 1200 13206 800 13611 40 14341 25
IIlli 400 12055 2400 12454 1200 13213 2400 13612 1200 14346 800
11332 300 12064 1200 12456 800 13214 300 13616 800 14353 2400
11334 600 12066 800 12462 300 13215 480 13623 480 14354 1200
11351 200 12101 200 12465 2400 13221 400 13624 600 14361 400
11355 2400 12102 600 12466 160 13225 2400 13626 800 14363 480
11356 160 12116 800 12521 so 13234 1200 13641 100 14402 600
11362 120 12123 2400 12522 600 13242 240 13642 600 14404 600
11364 1200 12126 800 12526 800 13243 2400 13644 1200 14415 2400
11365 2400 12134 60 12531 200 13252 ISO 13652 75 14425 2400
11405 2400 12135 2400 12532 1200 13261 400 13654 600 14426 800
11406 800 12136 800 12534 300 13264 30 13655 2400 14431 20
11412 1200 12141 400 12552 600 13302 1200 14004 1200 144JJ 2400
11415 480 12142 1200 12553 2400 13311 400 14005 480 14435 2400
11422 1200 12143 2400 12555 480 13313 480 14015 2400 14442 1200
11423 2400 12151 100 12561 400 13323 2400 14023 2400 14444 1200
11434 1200 12154 240 12563 2400 13324 1200 14034 1200 14446 800
11443 2400 12165 480 12564 120 IJJ31 50 14041 25 14451 80
11455 2400 12203 2400 12601 400 13336 800 14052 300 14452 300
11463 2400 12205 2400 12612 150 13345 2400 14053 2400 14463 480
11504 1200 12213 480 12626 800 ll355 2400 14061 400 14SOI 80
11511 so 12214 1200 12636 800 lll64 75 14065 2400 14506 800
11523 2400 12224 1200 12643 2400 13402 600 14103 2400 14512 600
11533 2400 12226 800 12644 75 13404 600 14106 800 14523 2400
11542 75 12231 400 12652 1200 13413 480 14111 400 14526 800
11545 2400 12246 800 12655 2400 13421 80 14116 160 14534 120
11551 400 12253 2400 12664 1200 13422 300 14121 400 14543 480
2. Tables of Irreducible Polynomials 387
Irreducible Polynomials for !he Modulus 7
14545 2400 l5l2\ 100 15353 2400 15622 1200 16204 600 16453 2400
14551 200 15124 240 15355 2400 15625 2400 16216 160 16462 1200
14552 300 15131 400 15361 200 15633 2400 16222 240 16465 480
14555 2400 15132 1200 15402 1200 15634 150 16224 300 16504 1200
14562 600 15133 2400 15403 2400 15646 800 16231 400 16512 1200
14563 2400 15144 60 15406 800 15656 800 16234 1200 16516 160
14566 800 15145 2400 15412 300 15662 75 16235 2400 16521 400
14622 !50 15146 800 15415 2400 16001 400 16242 60 16526 800
14624 600 15153 2400 15416 160 16003 480 16243 2400 16532 150
14625 2400 15156 800 15424 1200 16012 1200 16246 800 16535 2400
14631 100 15166 800 15426 800 16013 2400 16253 2400 16543 2400
14632 600 15203 2400 15432 1200 16024 300 16255 2400 16553 2400
14634 1200 15205 2400 15441 80 16026 800 16263 2400 16561 25
14653 480 15216 800 15445 2400 16032 !50 16312 120 16602 240
14654 600 15223 2400 15451 50 16041 400 16314 1200 16605 2400
14656 800 15236 800 15462 30 16056 800 16315 2400 16614 600
14661 40 15241 400 15464 1200 16063 2400 16321 200 16615 2400
14662 1200 15254 1200 15511 400 l6l0l 400 16325 2400 16616 800
14666 800 15256 800 15513 2400 16103 2400 16>26 160 16622 600
15002 1200 15263 480 15514 120 16105 2400 16341 400 16623 2400
15006 160 15264 1200 15522 600 l6lll 100 16342 300 16624 300
15014 1200 15303 2400 15523 2400 l6lll 480 16344 600 16633 2400
15016 800 15304 240 15525 480 l6ll6 800 16351 200 16636 160
15021 100 15311 200 15541 200 16122 1200 16353 2400 16641 40
15025 2400 15313 2400 15542 1200 16123 2400 16)54 75 16655 2400
15034 !50 15315 2400 15544 300 l6l3l 400 16405 2400 16656 800
15042 1200 15321 100 15551 25 16144 240 16406 800 16664 600
15055 2400 15324 600 15552 600 16146 800 16413 2400
15066 800 15326 800 15556 800 16154 150 16425 2400
l5l0l 200 15335 480 15601 400 l6l6l lO 16433 2400
15102 600 15336 800 15614 1200 16162 1200 16444 1200
15115 480 15342 120 15615 480 16201 200 16452 1200
388 Tables
TABLE D
I 0 51 6 3 0
2 I 0 52 3 0
3 I 0 53 6 2 I 0
4 I 0 54 6 5 4 3 2 0
5 2 0 55 6 2 I 0
6 I 0 56 7 4 2 0
7 I 0 57 5 3 2 0
8 4 3 2 0 58 6 5 I 0
9 4 0 59 6 5 4 3 0
10 3 0 60 I 0
II 2 0 61 5 2 I 0
12 6 4 0 62 6 5 3 0
13 4 3 0 63 I 0
14 5 3 0 64 4 3 o·
15 I 0 65 4 3 0
16 5 3 2 0 66 8 6 5 3 2 0
17 3 0 67 5 2 I 0
18 5 2 0 68 7 5 I 0
19 5 2 0 69 6 5 2 0
20 3 0 70 5 3 I 0
21 2 0 71 5 3 I 0
22 I 0 72 6 4 3 2 0
23 5 0 73 4 3 2 0
24 4 3 0 74 7 4 3 0
25 3 0 75 6 3 I 0
26 6 2 0 76 5 4 2 0
27 5 2 0 77 6 5 2 0
28 3 0 78 7 2 I 0
29 2 0 79 4 3 2 0
30 6 4 0 80 7 5 3 2 0
31 3 0 81 4 0
32 7 5 3 2 0 82 8 7 6 4 0
33 6 4 I 0 83 7 4 2 0
34 7 6 5 2 0 84 8 7 5 3 0
35 2 0 85 8 2 I 0
36 6 5 4 2 0 86 6 5 2 0
37 5 4 3 2 0 87 7 5 I 0
38 6 5 I 0 88 8 5 4 3 0
39 4 0 89 6 5 3 0
40 5 4 3 0 90 5 3 2 0
41 3 0 91 7 6 5 3 2 0
42 5 4 3 2 0 92 6 5 2 0
43 6 4 3 0 93 2 0
44 6 5 2 0 94 6 5 I 0
45 4 3 I 0 95 6 5 4 2 0
46 8 5 3 2 0 96 7 6 4 3 2 0
47 5 0 97 6 0
48 7 5 4 2 0 98 7 4 3 2 0
49 6 5 4 0 99 7 5 4 0
50 4 3 2 0 100 8 7 2 0
2. Tables of Irreducible Polynomials 389
TABLE E
p-11 n-2 q-121 120�2'·3·5 �(120)/2 � 16
a, a, a, a, a, a, a, a,
4 2 2 6 I 7 ) 8
5 2 3 6 4 7 3 8
6 2 8 6 7 7 8 8
7 2 9 6 lO 7 lO 8
p-13 n=2 q -169 168-23·3·7 �( 168)/2-24
a, a, a, a, a, a, a, a,
I 2 2 6 2 7 4 II
4 2 3 6 3 7 5 ll
6 2 4 6 6 7 6 ll
7 2 9 6 7 7 7 ll
9 2 10 6 10 7 8 II
12 2 II 6 II 7 9 II
p-17 n-2 q � 289 288""'25·32 �(288)/2 - 48
a, a, a, a, a, a, a, a,
I 3 2 6 I 10 2 12
6 3 6 6 3 10 3 12
7 3 8 6 4 10 5 12
10 3 9 6 13 10 12 12
II 3 II 6 14 10 14 12
16 3 15 6 16 10 15 12
3 5 I 7 2 II 4 14
5 5 4 7 7 II 6 14
8 5 5 7 8 II 7 14
9 5 12 7 9 II lO 14 .
12 5 13 7 lO II II 14
14 5 16 7 15 II 13 14
p -19 n=2 q-361 360 -23·32·5 �(360)/2 � 48
a, a, a, a, a, a, a, a,
I 2 10 3 3 13 II 14
4 2 II 3 4 13 12 14
7 2 12 3 6 13 13 14
8 2 18 3 9 13 18 14
II 2 2 10 10 ll 4 15
12 2 4 10 13 13 5 15
15 2 6 10 15 13 6 15
18 2 9 lO 16 13 9 15
I 3 10 lO I 14 10 15
7 3 13 lO 6 14 13 15
8 3 15 10 7 14 14 15
9 3 17 10 8 14 15 15
p-23 n-2 q-529 528-24·3· II �(528)/2-80
a, a, a, a, a, a, a, a, a, a,
2 5 2 10 I 14 3 17 4 20
4 5 3 10 3 14 4 17 7 20
5 5 6 10 5 14 6 17 8 20
8 5 10 10 10 14 II 17 10 20
15 5 13 10 13 14 12 17 13 20
18 5 17 10 18 14 17 17 15 20
390 Tables
TABLE E (Cont.)
p-23 n-2 q� 529 528-24·3·11 �(528)/2 -80
a, a, a, a, a, a, a, a, a, a,
19 5 20 10 20 14 19 17 16 20
21 5 21 10 22 14 20 17 19 20
I 7 3 II 5 15 I 19 5 21
2 7 7 II 9 15 2 19 6 21
4 7 8 II 10 15 7 19 7 21
9 7 9 II II 15 II 19 9 21
14 7 14 II 12 15 12 19 14 21
19 7 15 II 13 15 16 19 16 21
21 7 16 II 14 15 21 19 17 21
22 7 20 II 18 15 22 19 18 21
p-29 n-2 q�841 840-21·3·5·7 �(840)/2 -96
a, a, a, a, a, a, a, a, a, a, a, a,
5 2 I 8 6 II 7 15 2 19 5 26
7 2 7 8 9 II 9 15 4 19 6 26
II 2 10 8 10 II II 15 7 19 8 26
14 2 14 8 II II 12 15 8 19 12 26
15 2 15 8 18 II 17 15 21 19 17 26
18 2 19 8 19 II 18 15 22 19 21 26
22 2 22 8 20 II 20 15 25 19 23 26
24 2 28 8 23 II 22 15 27 19 24 26
I 3 3 10 I 14 4 18 3 21 2 27
2 3 5 10 3 14 8 18 4 21 3 27
9 3 9 10 8 14 13 18 6 21 6 27
14 3 10 10 13 14 14 18 12 21 13 27
15 3 19 10 16 14 15 18 17 21 16 27
20 3 20 10 21 14 16 18 23 21 23 27
27 3 24 10 26 14 21 18 25 21 26 27
28 3 26 10 28 14 25 18 26 21 27 27
p-31 n-2 q""' 961 960-26·3·5 �(960)/2 -128
a, a, a, a, a, a, a, a, a, a, a, a, a, a, a, a,
2 3 2 II I 12 I 13 I 17 2 21 22 I 24
5 3 3 II 3 12 4 13 2 17 5 21 4 22 3 24
6 3 4 II 4 12 6 13 3 17 7 21 5 22 4 24
7 3 5 II 10 12 8 13 6 17 8 21 7 22 5 24
8 3 6 II II 12 9 13 7 17 II 21 9 22 7 24
10 3 9 II 12 12 10 13 8 17 12 21 10 22 8 24
14 3 II II 14 12 12 13 9 17 13 21 14 22 12 24
15 3 15 II 15 12 13 '13 II 17 15 21 15 22 13 24
16 3 16 II 16 12 18 13 20 17 16 21 16 22 18 24
17 3 20 II 17 12 19 13 22 17 18 21 17 22 19 24
21 3 22 II 19 12 21 13 23 17 19 21 21 22 23 24
23 3 25 II 20 12 22 13 24 17 20 21 22 22 24 24
24 3 26 II 21 12 23 13 25 17 23 21 24 22 26 24
25 3 27 II 27 12 25 13 28 17 24 21 26 22 27 24
26 3 28 II 28 12 27 13 29 17 26 21 27 22 28 24
29 3 29 II 30 12 30 13 30 17 29 21 30 22 30 24
2. Tables of Irreducible Polynomials 391
TABLE F
p" a1a2a3 · · . "· p" ala2a3 . . . a, p" a1a2 · · · a,_1a,
2 II 5' 12 192 I 2
2' 101 5' 102 193 10 16
2' 1001 5' 101J 194 100 2
2' 01001 5' 00102 19' 0001 16
2' 100001 5' 100002 196 00001 3
2' 0000011 5' 1000002 197 010000 9
2' 11000011 5' 00101003
2' 000100001 5' 011000003 232 I 7
2" 001000000 1 5" 101000000 3 233 10 16
2" 0100000000 I 5" 10000000002 234 001 II
2" 110000010001 5" 0000 I 00 I 0003 23' 1000 18
2" 110010000000 I 236 1 0000 7
2" 11000000000 10 I
2" I 0000000000000 I 7' 13 292 I 3
2" 10100000000 I 0001 7' 112 29' 01 18
2" 0010000000000000 I 7' 1103 294 100 2
2" 0000001 0000000000 I 7' 10004 29' 0100 26
2" 1100 I 0000000000000 I 7' 110003 296 00001 3
2" 001000000000000000 I 7' 0100004
2" 01000000000000000 I 7' 1000000 3
2" 10000000000000001 7' 100001002 3 12 I 12
2" 0000 I 000000000000000 I 7" 110000000 3 3 13 01 28
2" II 0000 I 0000000000000001 31' 100 lJ
2" 001000000000000000 1 3 I' 0100 20
2" 110001000000000000000 I 112 17 316 10000 12
2" 11001000000000000000 1 113 105
2" 001000000000000000 1 114 0012
2" 01000000000000000 1 11' Oli09 372 I 5
11' 100017 37' 10 24
11' 1000005 374 001 2
11' 000 10012 37' 0001 32
3' 12
3' 201
3' 1002 IJ' I 2 412 I 12
3' 10101 IJ' 10 7 413 01 35
3' 100002 IJ' 101 2 414 001 17
3' 1010001 13' 0101 II 41' 1000 35
3' 00100002 13' 10100 6
J' 010100001 13' 001000 6 432 I 3
3" 101000000 2 13' 0110000 2 433 0140
3" 100000 I 000 I 434 001 20
3" 1000 I 0000002 43' 100040
3" I 00000 I 00000 I 172 I 3
3" I 000000000000 2 173 01 14
3" 1000000000 1000 I 17' 100 5 472 I 13
3" 000000 1000000002 17' 1000 14 473 10 42
3" I 0000000 I 0000000 I 17' 10000 3 474 100 5
3" I 00000000000 I 00002 17' 000100 14 47' 0001 42
BIBLIOGRAPHY
Note. We Jist only textbooks suggested for further reading and some basic research
articles. A more detailed bibliography can be found in:
Lidl, R., and Niederreiter, H.: Finite Fields, Encyclopedia of Math. and Its Appl.,
voL 20, Addison- Wesley, Reading, Mass., 1983; now published by Cambridge
University Press.
Chapter 1
Books on Abstract Algebra:
Birkhoff, G., and MacLane, S.: A Survey of Modern Algebra. 4th ed., Macmillan,
New York, 1977.
Fraleigh, J. B.: A First CoW'se in Abstract Algebra. Addison-Wesley, Reading,
Mass., 1982.
Herstein, I. N.: Topics in Algebra. 2nd ed., Xerox College Publ., Lexington, Mass.,
1975.
Lang, S.: Algebra, Addison-Wesley, Reading, Mass., 1971.
ROOei, L.: Algebra, Pergamon Press, London, 1967.
van der Wae:rden, B. L.: Algebra, vol. 1, 7th ed., Springer-Verlag, Berlin, 1966.
Books on Applied Algebra:
Birkholf, G., and Bartee, T. C.: Modern Applied Algebra. McGraw-Hill, New York,
1970.
Dornholf, L L, and Hohn, F. E.: Applied Modern Algebra. Macmillan, New York,
1978.
Lid!, R., and Pilz, G.: Applied Abstract Algebra, Springer-Verlag, New York, 1984.
392
Bibliography
Chapter 2
Dickson, L. E.: linear Groups with an Exposition of the Galois Field Theory,
Teubner, Leipzig, 1901; Dover, New York, 1958.
Herstein, I. N.: Noncommutative Rings, Carus Math. Monographs, no. 15, Math.
Assoc. of America, Washington, D.C., 1968.
Hoffman, K., and Kunze, R.: Linear Algebra, 2nd ed., Prentice-Hall, Englewood
Cliffs, N.J., 1971.
Jacobson, N.: Uctures in Abstract Algebra, vol. 3: Theory of Fields and Galois
Theory, Springer-Verlag, New York, 1980; originally published by Van
Nostrand, New York, 1964.
Chapter 3
Albert, A. A.: Fundamen tal Concepts of Higher Algebra, Univ. of Chicago Press,
Chicago, 1956.
Berlekamp, E.R.: Algebraic Coding Theory, McGraw-Hill, New York, 1968.
MacWilliams, F. 1., and Sloane, N.J. A.: The Theory of Error-Correcting Codes,
North-Holland, Amsterdam, 1977.
Ore, 0.: On a special class of polynomials, Trans. Amer. Math. Soc. 35, 559-584
(1933); Errata, ibid. 36, 275 (1934).
Ore, 0.: Contributions to the theory of finite fields, Trans. Amer. Math. Soc. 36,
243-274 (1934).
Chapter 4 393
Berlekarnp, E. R.: Algebraic Coding Theory, McGraw-Hill, New York, 1968.
Berlekamp, E. R.: Factoring polynomials over large finite fields, Math. Comp. 24,
713-735 (1970).
Cantor, D. G., and Zassenhaus. H.: A new algorithm for factoring polynomials
over finite fields, Math. Comp. 36. 587-592 (1981).
Knuth, D.E.: The Art of Computer Programming, vol. 2: Seminumerical Algorithms,
2nd ed., Addison-Wesley, Reading, Mass., 1981.
McEliece, R. 1.: Factorization of polynomials over finite fields, Math. Comp. 23,
861-867 (1969).
Rabin, M. 0.: Probabilistic algorithms in finite fields, SIAM J. Computing 9, 273-
280 (1980).
Zassenhaus, H.: On Hensel factorization I, J. Number Theory I, 291-311 (1969).
Chapter S
Hasse, H.: Vorlesungen Uber Zahlentheorie, 2nd ed., Springer-Verlag, Berlin, 1964.
Ireland, K., and Rosen, M.: A Classical Introduction to Modern Number Theory,
Springer-Verlag, New York, 1982.
394 Bibliography
Chapter 6
Berlekamp, E. R.: Algebraic Coding Theory, McGraw-Hill, New York, 1968.
Fillmore, J. P., and Marx, M.L.: Linear recursive sequences, SIAM Rev. 10, 342-
353 (1968).
Golomb, S. W.: Shift Register Sequences, Aegean Park Press, Laguna Hills, Cal.,
1982.
Massey, J. L.: Shift-register synthesis and BCH decoding, IEEE Trans. Information
Theory 15, 122-127 (1969).
Niederreiter , H.: On the cycle structure of linear recurring sequences, Math. Scand.
38, 53-77 (1976).
Zierler, N.: Linear recurring sequences, J. Soc. Jndust. Appl. Math. 7, 31-48 (1959).
Chapter 7
Finite Geometries:
Albert, A.A., and Sandler, R.: An Introduction to Finite Projective Planes, Holt,
Rinehart and Winston, New York, 1968.
Dembowski, P.: Finite Geometries, 2nd ed., Springer-Verlag, Berlin, 1977.
Hirschfeld, J. W. P.: Projective Geometries over Finite Fields, Clarendon Press,
Oxford, 1979.
Hughes, D. R., and Piper, F. C.: Projective Planes, Springer-Verlag, New York,
1973.
Combinatorics:
Beth, T., Jungnickel, D., and Lenz., H.: Design Theory., Bibliographisches
Jnstitut, Mannheim, 1985.
Brualdi, R. A.: Introductory Combinatorics, North-Holland, Amsterdam, 1977.
Denes, J., and Keedwell, A. D.: Latin Squares and Their Applications, Academic
Press, New York, 1974.
Hall, M., Jr.: Combinatorial Theory, Blaisdell, Waltham, Mass., 1967.
Raghavarao, D.: Constructions and Combinatorial Problems in Design of
Experiments, Wiley, New York, 1971.
Ryser, H. J.: Combinatorial Mathematics, Carus Math. Monographs, no. 14, Math.
Assoc. of America, New York, 1963.
Storer, T.: Cyclotomy and Difference Sets, Markham, Chicago, 1967.
Linear Modular Systems:
Arbib, M.A., Falb, P. L., and Kalman, R. E.: Topics in Mathematical System
Theory, McGraw-Hill, New York, 1968.
DornhofT, L. L., and Hohn, F. E.: Applied Modern Algebra, Macmillan, New York,
1978.
Zadeh, L. A., and Polak, E.: System Theory, McGraw-Hill, New York, 1969.
Pseudorandom Sequences:
Golomb, S. W.: Shift Register Sequences, Aegean Park Press, Laguna Hills, Cal.,
1982.
Knuth, D. E.: The Art of Computer Programming, vol. 2: Seminumerical Algorithms,
2nd ed., Addison-Wesley, Reading, Mass., 1981.
Niederreiter, H.: The performance of k-step pseudorandom number generators
Bibliography 395
under the uniformity test, SIAM J. Sci. Statist. Computing 5, 798-810 (1984).
Niederreiter, H.: Distribution properties of feedback shift register sequences,
Problems of Control and In formation Theory, to appear.
Tausworthe, R. C.: Random numbers generated by linear recurrence modulo two,
Math. Comp. 19, 201-209 (1965).
Zierler, N.: Linear recurring sequences, J. Soc. Indust. Appl. Math. 1, 31--48 (1959).
Chapter 8
Berlekamp, E.R.: Algebraic Coding Theory, McGraw-Hill, New York, 1968.
Blake, I. F., and Mullin, R. C.: The Mathematical Theory of Coding, Academic
Press, New York, 1975.
MacWilliams, F. J., and Sloane, N. J. A.: The Theory of Error-Correcting Codes,
North-Holland, Amsterdam, 1977.
McEliece, R. J.: The Theory of Information and Coding, Encyclopedia of Math. and
Its Appl., vol. 3, Addison-Wesley, Reading, Mass., 1977; now published by
Cambridge University Press.
Peterson, W. W., and Weldon, E. J., Jr.: Error-Correcting Codes, 2nd ed., M.I.T.
Press, Cambridge, Mass., 1972.
Pless, V.: Introduction to the -Theory of Error-Correcting Codes, Wiley, New York,
1982.
van Lint, J. H.: Introduction to Coding Theory, Springer-Verlag, New York, 1982.
Chapter 9
Books:
Beker, H., and Piper, F.: Cipher Systems. The Protection of Communications,
Northwood Books, London, 1982.
Denning, D. E. R.: Cryptography and Data Security, Addison-Wesley, Reading,
Mass., 1983.
Kahn, D.: The Codebreakers, Weidenfeld & Nicholson, London, 1967.
Konheim, A. G.: Cryptography. A Primer, Wiley, New York, 1981.
Meyer, C. H., and Matyas, S.M.: Cryptography. A New Dimension in Computer
Data Security, Wiley, New York, 1982.
Articles:
Blake, I. F., Fu ji-Hara, R., Mullin, R. C., and Vanstone , S.A.: Computing
logarithms in finite fields of characteristic two, SIAM J. Algebraic Discrete
Methods 5, 276--285 (1984).
Chor, B., and Rivest, R. L.: A knapsack type public key cryptosystem based on
arithmetic in finite fields, Proc. CRYPTO '84, to appear.
Coppersmith, D.: Fast evaluation of logarithms in fields of characteristic two,
IEEE 'Irans. Information Theory 30, 587-594 (1984).
Diffie, W., and Hellman, M. E.: New directions in cryptography, IEEE Trans.
Information Theory 22, 644-{;54 (1976).
ElGamal, T.: A public key cryptosystem and a signature scheme based on discrete
logarithms, IEEE Trans. Information Theory, to appear.
Jennings, S. M.: Multiplexed sequences: Some properties of the minimum
polynomial, Cryptography (T. Beth, ed.). Lecture Notes in Computer Science,
396 Bibliography
vol. 149, pp. 189-206, Springer-Verlag, Berlin, 1983.
Lempel, A.: Cryptology in transition, ACM Computing Surveys 11, 285-303 (1979).
McEliece, R. J.: A public-key cryptosystem based on algebraic coding theory, DSN
Progress Report 42-44, Jet Propulsion Lab., Pasadena, Cal., 1978.
Niederreiter, H.: A public. key cryptosystem based on shift register sequences, Proc.
EUROCRYPT '85, to appear
Odlyzko, A. M.: Discrete logarithms in finite fields and their cryptographic
significance, Proc. EUROCRYPT ·s4, to appear.
Pohlig, S. C., and Hellman, M. E.: An improved algorithm for computing
logarithms Over GF(p) and its cryptographic significance, IEEE Trans.
Information Theory 24, 106-110 (1978).
Rivest, R. L., Shamir, A., and Adleman, L.: A method for obtaining digital
signatures and public-key cryptosystems, Comm. ACM 21, 120-126 (1978).
Chapter 10
Alanen, J. D., and Knuth, D. E.: Tables of finite fields, Sankhyii Ser. A 26, 305-328
(1964).
Church, R.: Tables of irreducible polynomials for the first four prime moduli, Ann.
of Math. (2) 36, 198-209 (1935).
Conway, J. H.: A tabulation of some information concerning finite fields,
Computers in Mathematical Research (R. F. Churchhouse and J.-C. Herz,
eds.), pp.37-50, North-Holland, Amsterdam, 1968.
Marsh, R. W.: Table of Irreducible Polynomials over GF(2) through Degree 19,
Office of Techn. Serv., U.S. Dept. of Commerce, Washington, D.C., 1957.
Stahnke, W.: Primitive binary polynomials, Math. Camp. 27, 977-980 (1973).
Watson, E. J.: Primitive polynomials (mod 2), Math. Camp. 16, 368-369 (1962).
List of Symbols
Note. Symbols that appear only in a restricted context are not listed. Wherever
appropriate, a page reference is given.
N
z
Q
R
<C
S1 x · · · x s,
S" the set of natural numbers (=positive integers)
the set of integers
the set of rational numbers
the set of real numbers
the set of complex numbers
the set of all n-tuples (s1, ... , s,.) with s1ESi for 1 � i � n
the set of all n-tuples (s 1, ... , s.) with s,E S for I .;;; i .;;; n
lSI
[s] the cardinality (=number of elements) of the finite set S
the equivalence class of s, 4
Z the complex conjugate of z
I z I the absolute value of z
log z the natural logarithm of z
e(t) ehit for tE�
ltJ the greatest integer .;;; IE�
max(k1, ... ,k.) the maximum ofk1, ..• ,k.
min (k 1, ..• , k.) the minimum of k1, ••• , k.
gcd (k 1, .•• , k.) the greatest common divisor of k 1, .•. , k.
lcm (k 1, ..• , k.) the least common multiple of k 1, ••• , k.
(k,.) binomial coefficient
397
398
a= bmodn
¢(n)
p.(n)
(�)
AT
det (A)
Tr(A)
rank (A)
n(r) '
dim(V)
IGI
(a)
aH
G/H
N(S)
kerf
(a)
[a], a+j
a= bmodJ
R/1
ll.,
ll./(n)
GL(k, �,)
R[x]
R[x1, ... ,x11]
deg(f)
D(f)
ord (f)
!'
!*
R(f,g)
gcd(f,, ... ,f,) a congruent to b modulo n, 4
Euler's function of n, 7
Moebius function of n, 83
Legendre symbol, 167
the transpose of the matrix A
the determinant of the matrix A
the trace of the matrix A
the rank of the matrix A
Hankel determinant, 229
the dimension of the vector space V
the order of the finite group G, 5
the cyclic group generated by a, 4, 6 List of Symbols
the left coset of the group element a modulo the subgroup H,
6
the factor group of the group G modulo the normal
subgroup H, 9
the normalizer of the nonempty subset S of a group, 10
the kernel of the homomorphism f, 9, 14
the principal ideal generated by a, 13
the residue class of the ring element a modulo the ideal J, 13
congruence of ring elements a, b modulo the ideal J, 13
the residue class ring of the ring R modulo the ideal J, 13
the group of integers modulo n, 5
the ring of integers modulo n, 14
the general linear group of nonsingular k x k matrices over
� •• 191
the polynomial ring over the ring R, 19
the ring of polynomials over the ring R in n indeterminates,
28
the degree of the polynomial f, 20, 29
the discriminant of the polynomial f, 35
the order of the polynomial f, 75
the derivative of the polynomial f, 27
the reciprocal polynomial of f, 79
the resultant of the polynomials f and g, 36
the greatest common divisor of the polynomials /1, ..• ,fn,
22
lcm(f1, ... ,f,) the least common multiple of the polynomials f1, •.. ,f,, 23
f1(x)v · · · v j,(x) 224
List of Symbols
Q,(x)
ak(xl, ... ,xn)
K(M)
[L :K]
K''l
E'>
� •• GF(q)
�:
Tr,1x(�)
Tr.(�)
N,,K(�)
AF/K(�,. · · · • �m)
ind,(a)
exp,(r)
N,(d)
I(q,n; x)
<I> ,(f)
�,[[x]]
S(f(x))
(j
X
Xo
X!
1/Jo
�
G(l/l.xl
AG(2,K)
PG(2, K)
AG(m, �,)
PG(m, �,) 399
symbolic multiplication of linearized polynomials L1(x) and
L,(x), 105
the nth cyclotomic polynomial, 60
the kth elementary symmetric polynomial in n indetermi
nates, 29
the extension of K obtained by adjoining M, 30
the degree of the field L over K, 32
the nth cyclotomic field over K, 59
the set of nth roots of unity over K, 59
the finite field of order q, 45
the multiplicative group of nonzero elements of � ,, 46
the trace of �EF over K, 50
the absolute trace of �EF, 50
the norm of �EF over K, 53
the discriminant of et1, ... , a.mEF over K, 57
the index (or discrete logarithm) of a with respect to the base
b, 346
the discrete exponential function to the base b, 346
the number of monic irreducible polynomials in � ,[x] of
degree d, 82
the product of all monic irreducible polynomials in � ,[x] of
degree n, 85
the number of polynomials in �,[x] whose degree is less than
deg(/) and which are relatively prime to /E�,[x], 113
the ring of formal power series over � ,. 204
the set of all homogeneous linear recurring sequences in �,
with character istic polynomial f(x), 215
sequence obtained by decimation of the sequence <1, 285
sequence obtained by shifting the sequence <1, 287
the set of characters of the finite abelian group G, 163
the conjugate of the character x. 163
the trivial additive character of � ,. 166
the canonical additive character of � •. 166
the trivial multiplicative character of � •• 167
the quadractic character of �. (q odd), 167
Gaussian sum, 168
the affine plane over the field K, 254
the projective plane over the field K, 254
affine geometry over � ,, 262
projective geometry over � ,, 260
400
d(x, y)
w(x)
de
c•
S(y)
f(L,g)
D the Hamming distance between x andy, 303
the Hamming weight of x, 303 List of Symbols
the minimum distance of the linear code C, 304
the dual code of G, 308
the syndrome of y, 305
Goppa code, 326
end of proof, end of example, end of remark
Index
adder. 186, 187, 273
affine geometry, 262, 263
affine multiple, 103
affine plane • .253-255
affine polynomial. 103, 105, 126. 128
see also q-polyno mial(s)
affine subspace, 105
algebraic structure, 2
algebraic system, l. 2
alternant code, 336, 337
annihilating polynomial, 56
annihilator. 165, 181
Artin lemma, 55
q-associate. 106-108
canonical factorization of, 108
conventional. \06
linearized, 106. 126
authentication, 341
automorphism, 8, 49, 50, 70
inner, 8
balanced incomplete block design, 263-265 ,
269, 295, 296
basis. 50, 54-59, 71. 114. 115
complementary, 54
dual, see dual basis
normal, see normal basis
polynom ial, 55
self-dual. 54, 71
BCH code, 299, 3!8-326, 335
narrow-sense, 318. 325. 326
primitive, 318
Berlekamp-Mas�y algorithm, 23\-235 , 323 Berlekamp's algorithm, 130-134, 140
BIBD, see balanced incomplete block design
binary complementation, 221
binary operation, 2
associative, 2
closure property of, 2
binomial. 115-118. 127. 160
binomial theorem:. 37
bits. 281, 340
block cipher, 340
block design, see balanced incomplete block
design
Caesar cipher, 338
canonical factorization, 24
of q-associate, 108
see also factorization
Cayley-Hamilton theorem. 56
Cayley table, 5
center
of division ring. 66
of group, 10
character, 163-16 8
additive, 166
annihilating. 165
canonical additive, 166
conjugate, 163
lifting of. 173, 182
multiplicative, 167
nontrivial, 163
orthogonality relations. 165, 167, 168
product, 163
quadratic, 167
401
402
trivial, 163
trivial additive, 166
trivial multiplicative, 167
character group, 163, 182
characteristic, 16
characteristic matrix, 272
characteristic polynomial
of element, 50, 70, 91-93, 369,374-376
for linear operator, 56
of matrix, see matrix
reciprocal, 207
of sequence, see linear recurring
sequenc(s)
characterizing matrices, 272
character sum, 162. 180, 181,236-240, 250
Chien search, 322, 323
Chinese remainder theorem, 38, 40
cipher, 338
block, 340
Caesar, 338
stream, 342
substitution. 338
,fee also cryptosystem
cipher system, 338
see alro cryptosystem
ciphertext, 339
class equation, 10, 66
code, 300, 301
alternant, 336, 337
BCH. see BCH code
binary, 302
cyclic, see cyclic code
dimension of, 302
dual, see dual code
equivalent, 333
Gappa, see Gappa code
Hamming, see Hamming code
length of, 302
linear, 302-3ll. 333,334
minimum distance of, see minimum
distance
orthogonal. see dual code
parity--check, 302, 334
perfect, 333
Reed-Soloman. 318, 335
repetition, 302, 333, 334
reversible, 335
systematic, 302
code polynomi al. 313-315
code vector, 302
code word. 300-302
coding scheme, 300, 301
coefficient, 19, 28. 202
leading. 20
collinear points, 255
companion matrix, 63, 64, 93, 195, 279
complete quadrangle, 257
component
forced, 276 free, 276
congruence, 4, 6, 13
left. 6
conic, 258
degenerate, 258
nondegenerate, 258
tangent of, 258
conjugacy class, 10
conjugate, 49, 50
of set, 8
constant adder, 186, 187
constant multiplier, 186, 187. 273
constant term, 20
control symbol, 30 I Index
conventional cryptosystem, 338-340, 349
correlation coefficient. 282-285
correlation test, 282
coset. 6, 7
left, 6
right, 6
coset leader. 305
coset�leader algorithm, 305. 306
cryptanalysis, 338
cryptography, 338
cryptology, 338
cryptosystem, 338-340
conventional. 338-340, 349
DES. 340
FSR, 357. 358
Goppa-code, 360-362
Hill, 366
knapsack-type, 358-360
public-key, 340, 341
RSA, 348
single-key, 339
cycle, 277
length of. 277
pure, 277
cycle sum. 278-281
cycle term, 278
cyclic code, 311-325
irreducible, 313
maximal, 313
shortened, 335
cyclic group, see group
cyclic vector, 56
cyclotomic field, 59, 6l. 62, 72
cyclotomic polynomial, 60-62. 64, 66, 72,
73. 84-86. 96, 97, 124. 128, 138. 139
Davenport-Hasse theorem, 173
de Bruijn sequence. 246
decimated sequence, 285-287, 297, 298, 345,
364
decimation. 285-287, 297, 298, 345, 358, 364
deciphering scheme, 339
decoding algorithm
for BCH code, 320-325, 328, 331, 332
for Gappa code, 328-332
Index
for linear code, 304-306
decoding scheme. 300
degree
of algebraic elemen t, 31
of extension, 32
formal. 36
of polynomial. 20. 29
delay elemen t, 186, 187, 273
derivative, 27, 40, 41, 70
Desarguesian plane. 256-259
· Desargues's theorem. 255-257, 260
DES cryptosystem. 340
design, 262
design of experiments, 269
diagonalization algorithm, 145-147
difference equation. see linear recurrence
relation
difference set. 265-267. 296
Diffie-Hellman scheme, 348
digital method, 288
digital signature. 341, 349
discrete exponential function. 346-349, 367
discrete logarithm, 346. 347, 358, 359, 365,
367
discrete logarithm algorithm, 349-357
discriminant
of elernen ts, 57, 58, 71, 72
of polynomial, 35-37. 122
distribution test, 282. 283
distributive laws, 11, 12
divison algorithm, 20
divison ring. 12, 65-69
divisor, 17
dot product, 308
dual basis. 54, 71, 369, 374-376
dual code, 308-311,334.335
element
algebraic. 31
associate. 17
binary. 15
conjugate. 8
defining. 30
identity, 2
inverse, 2
multiple of, 3
order of, 6, 7
power of, 3, 69, 181
prime. 17
primitive. see primitive element
unity. 2
zero. II
enciphering scheme. 339
endomorphism, 8
epimorphism, 8
equivalence class. 4
equivalence relation. 4
error-correcting code. 303
see also code error-evaluator polynomial. 329, 330
error-location number. 316, 320. 329
error-locator polynomial, 322. 329, 330
error value. 320, 329
error vector. 303
error word, 303 403
Euclideiln algorithm, 22. 38, 330, 336, 355,
356
Euler's function, 7, 37
exponential sum. 162-184, 236-240, 250
exponent of polynomial. see order
extension (field), 30-35
algebraic, 31
degree of. 32
finite, 32
simple, 30, 33, 34
factor group, 9
factorization
of integers, 78
of polynomials. 23, 24, 29, 39, 97, 98, 108,
116-118, 120, 129-150
symbolic. 108, 109
factor ring. 13
Fano plane, 253, 254, 263
feedback shift register. 186-188, 193, 314
Fermat's little theorem. 37
Fibonacci sequence, 246
field, 12
cyclotomic. see cyclotomic field
finite. see finite field
prime, 30
see also extension (field), splitting field
finite affine geometry. 262, 263
finite euclidean geometry. 262
finite field, 15, 45
automorphism, 49, 50, 70
characterization of, 43-47
computation in, 367-369
definition, 14
existence and uniqueness, 45
multiplicative group of, 46, 47, 69
finite-state system, 271, 272
k-flat(s), 259-262, 295
cycle of, 261
at infinity. 262
parallel. 262
flip-flop, .ree delay element
formal power series, 202
ring of, 204
Fourier coefficient, 171
Fourier expansion. 171
FSR cryptosystem, 357, 358
fundamental theorem on symmetric
polynomials. 29
Galois field. 15. 45
see also finite field
404
Gaussian sum, 168-180. 182, 183, 238,
242-244. 250
general linear group, 191. 192
general response formula, 275, 276
generating function, 202. 20 7-209. 219
generator, 4
generator matrix, 303. 312. 333
canonical, 302. 303, 313
generator polynomial, 313
Gilbert-V arsharnov bound, 308, 325
Gappa code, 326-332, 336, 337, 360, 361
irreduci ble, 326, 336, 360
Goppa-code cryptosystern, 360-362
Gappa polynomial, 326
group, 2
abelian, 2
commutative, 2
cyclic, 3, 7, 163
finite, 5
general linear, 191, 192
infinite, 5
of integers modulo n, 5
order of, 5, 7
group code, 302
Hadamard matrix, 269-271, 296
normalized, 270, 296
Hamming bound, 307
Hamming code, 307, 311, 314, 315, 333
binary, 307,311,314,315,333
Hamming distance, 303
Hamming weight. 303
Hankel determ inant, 229-231, 249
Hill cryptosystem, 366
homomorphism. 8, 14
homomorphism theorem
for groups. lO
for rings, 14,15
hyperplane, 259, 262, 266
ideal, 13
maximal, 17
prime, 17
principal, 13
identity element, 2
impulse response sequence , 193-195, 199,
215
incidence matrix, 263, 264
incidence relation, 252-254. 262
indeterminate, 19
index-calculus algorithm, 352-357
index function. 346, 367
.�ee also discrete logarithm
index of subgroup, 7
index table, 63, 368, 370-373
initial state vector, 188
initial value, 186
input alphabet, 271, 272 input space, 272
input symbol. 272
integral domain, 12
interpolation, 28, 4l. 363
inverse element, 2 Index
irreducible polynomial, 23-25, 28, 31, 47,
48, 75, 76.82-91,97,98, 115, 118-128.
160. 183, 377-387
\somorphism. 8, 14
Jacobi's logarithm, 69, 368, 374-376
kernel of homomorphism
group. 9
ring. 14
key. JJ9, 340
key-exchange system, 348
knapsac k-type cryptosystem, 358-360
Kronecker's method, 39
Lagrange interpolation formula, 28, 41, 363
Latin square(s), 267-269, 296
mutually orthogonal, 267-269, 296
normalized. 296
orthogonal. 267-269, 296
law of quadratic reciprocity, 179, 183
Legendre symbol. 167, 179
line(s)
at infinity, 255
pllrallel, 255
linearized polynomial, 98-114, 126--128
see also q-associate, q-polynomial(s)
linear modular system, 272-28 1, 296, 297
characteristic matrix, 272
characterizing matrices, 272
order, 272
linear recurrence relation, 186, 314
characteristic polynomial, 195-20 1,
207-211,214,215.226-228
homogeneous, 186
inhomogeneous, 186
order. 186
linear recurring sequence(s), 186
addition, 215, 218-221
binary complementat ion, 221
characteristic polynomial, 195-201,
207-21 1,214,215,226-228
characteriz ation, 228-23 1
decimation, see decimation
distribution properties, 235-245, 250
families of, 215-228
homogeneous, 186
inhomogeneous, 186
least period, 189-195, 199, 200, 212, 213,
220-22 3,227,247,248
minimal polynomial, 211-215,218-223,
230-235. 247-249
multiplication, 224-228
Index
order, 186
reciprocal characteristic polynomial. 207
scalar multiplication, 215
LM S, see linear modular system
MacWilliams identity. 310, 311
magic square. 296
matrix
associated with sequence, 191-195, 199
characteristic polynomial of. 93, 160. 278.
279
elementary block of, 279, 280
Hadamard, see Hadamard matrix
minimal polynomial of, 278-280
rational canonical form of, 279
matrix of polynomials. 143-147
diagonalization. 145-147
equivalence. 144
nonsingular, 144
normalized. 146
unimodular, 144
maximal ideal, 17
maximal period sequence, 201, 240, 241.
246. 282-288. 297, 298. 343
Mersenne prime, 348, 351. 352
message symbol, 300. 301
minimal polynomial
of element, 31. 86, 87,91-97,369,
374-376
for linear operator. 56
of matrix. 278-280
of sequence, see linear recurring
sequence(s)
minimum distance, 304. 308, 318, 319. 327.
328. 333-337
q-modulus, 109. 110, 114
Moebius function, 83, 124
Moebius inversion formula. 83. 84
multiplexed sequence, 343-346, 363. 364
multiplexer, 343
nearest neighbor decoding, 303
Newton's formula, 29, 30
next-state function, 272
no-key algorithm, 349
non-Desarguesian plane, 256, 257
norm, 53. 54, 70. 71
transitivity of, 54
normal basis. 55-59, 71, 115, 127, 365, 369,
374-376
self-dual. 71, 127
normal basis theorem. 56, 57, 59, 115
normalization method, 288
normalizer, 10
NP-complete problem, 342, 362
one-time pad, 342
one-way function. 341 operation .. fee Binary operation
order
of character, 170. 182
of element. 6, 7
of group, 5, 7
of linear modular system. 272
of linear recurrence relation. I 86
of linear recurring sequence. 186
multiplicative mod n, 76, 87 405
of polynomial. 75-82, 122. 123, 199-201,
212. 377-387
of projective plane, 253-257
of state, 277, 278. 281
orthogonal code, see dual code
orthogonality relations. 165, 167, 168
orthogonal vectors, 308
output alphabet. 272
output function, 272
output space, 272
output symbol, 272
Pappus theorem, 255-257
parity-check code, 302, 334
parity-check equation. 301
parity-check matrix, 302
parity-check polynomial. 313
partition, 4
pencil, 257, 258, 262
period of polynomial, .�ee order
period of sequence, 189-191
least, 189 (see also linear recurring
Sl!quence(s))
permuta tion matrix·, "360, 361
plaintext, 339
plaintext message, 339
Plotkin bound. 308
polynomia l(s), 19. 28
affine. see affine polynomial
affine multiple of, 103
canonical factorization of. 24
characteristic, see characteristic
polynomial
constant. 20
cyclotomic. see cyclotomic polynomial
defining. 31
degree of, 20, 29
derivative of, 27, 40, 41, 70
discriminant of, .�ee discriminant
division of. 20, 21
elementary symmetric, 29
exponent of, see order
factorization of, l"ee factorization
formal degree of, 36
greatest common divisor of. 22, 38, 39,
109
homogeneous. 29
irreducible. see irreducible polynomial
least common multiple of. 22, 23, 39
406
linearized. see linearized polynomial
matrix of. see matrix of polynomials
minimal, see minimal polynomial
monic, 20
order of, see order
pairwise relatively prime. 22
period of, see order
primitive. see primitive polynomial
product of.l9
reciprocal, 79, 123
reciprocal characteristic, 207
reducible. 23
/-reducing. 131-13 7
relatively prime, 22
resultant of, see resultant
root of, .fee root(s)
self-recip rocal, 123. 128
splitting of. 34, 35
sum of, 19
symme tric. 29
zero. 19
q-polynomial(s), 99, 101-103, 106 -114. 126
affine, 103, 105, 126. 128
greatest common symbolic divisor of. 109
minimal. 111-113.126
symbolically irreducible, 108, llO
symbolic division of, 106, 107
symbolic multiplication of, 105, 106
Jee also q-associate , linearized polynomial
polynomial basis, 55
polynomial ring. 19, 28, 204
preperiod of sequence. 189, 245. 247
prime element. 17
prime field, 30
prime ideal, 17
primitive element. 47, 49, 59, 63. 80, 96, 97.
182. 368
primitive polynomial, 80-82, 87, 96-98, 121.
123. 377. 388-391
q-primitive root, 110-114
principal ideal. 13
principal ideal domain. 17
principle of substitution, 27
probabilistic root-finding algorithm, 151
projective correspondence. 258
projective geometry •. �ee projective space
projective plane, 252-259. 262-26 5, 295
Desarguesian. 256-259
finite, 252-259, 262-265, 295
non-Desarguesian. 256, 257
order of, 253-257
projective space. 259-263, 266, 295
finite. 260---263, 266, 295
pseudorandom sequence of bits, 282
public-key cryptosystem. 340, 341
quadratic reciprocity. see law of quadratic
reciprocity quotient group, 9
random sequence
of bits, 281, 282, 342
of real numbers. 288
rational canonical form of matrix. 279
reducible polynomial, 23
/-reducing polynomi al, 131-137
reduction mod/, 25
Reed-Solomon code, 318, 335
reflexivity of relation, 4 Index
repeated squaring technique, 148, 149, 151,
347
repetition code, 302, 333, 334
residue class, 13
residue class ring. 13, 25
resultant, 36. 37. 42, 127, 140
ring. 11-17
of algebraic integers, 179
characteristic of. 16
commutative, II
of formal power series, 204
with identity, II
of polynomials. see polynomial ring
root(s), 27, 28. 34-36, 150-159, 161
of affine polynomial. 103-105, 107
of irreducibie polynomial. 48
of linearized polynomial, 99, 101-103
multiple, 27, 35, 40
multiplicity of. 27. 41
q-primitive, 110-114
simple, 27
root adjunction. 33-35
root-finding algorithm. 101-10 5, 150-159
probabilistic. 151
root of unity. 59-62. 72
primitive, 60---62. 72
RSA cryptosystem, 348
Run. 297
secant. 258
sequence
decimated, see decimated sequence
impulse response, .5ee impulse response
sequence
least period of. 189
maximal period. see maximal period
sequence
multiplexed , 343-346, 363, 364
periodic, !89, 247
period of, 189-191
preperiod of. 189, 245. 247
pseudorandom, 282
random, .,ee random sequence
shifted, 287, 288, 297, 298
ultimately periodic, 189
of uniform pseudorandom numbers,
288-294
Index
of uniform random numbers, 288
zero, 215
see also linear recurring sequence(s)
serial test, 282, 294
Shannon's theorem, 299
shifted sequence, 287, 288. 297, 298
Silver-Pohlig-Hellman algorithm. 350-352
single-key cryptosystem, 339
Singleton bound, 333
skew field. see division ring
smooth integer. 350
m-space, see projective space
splitting field, 35, 48, 134
existence and uniqueness, 35
square and multiply technique, 347
state. 272. 273
order of, 277. 278, 281
state graph, 277, 278, 296
path in, 277
state set, 272
state space, 272
state vector. 188, 191, 193-195, 214, 215
initial. 188
modified. 192
Steiner triple system. 263
Stickelberger's theorem, 177-179
stream ciphe,r, 342
subfield, 30
criterion for, 45, 46
maximal, 67, 68
prime, 30
proper, 30
subgroup, 6
generated by c;:lement, 6
generated by subset, 6
index of, 7
nontrivial, 6
normal. 9
trivial, 6
subring, 13
substitution cipher, 338
symmetric polynomial, 29 elementary, 29
symmetry of relation, 4
syndrome, 305, 306, 315
syndrome polynomial, 329
tactical configuration, 262. 263
symmetric, 262
tangent, 258
Tausworthe method, 288
term of polynomial, 29
test for randomness, 282, 288, 289
theorem of Pappus, 255-257
threshold scheme, 362, 363
trace, 50-53, 70, 71
absolute, 50
transitivity of, 52, 53
transitivity of relation, 4
trapdoor one-way function, 341
trinomial, 118-122, 127, 128 407
irreducible, 118, 119, 121, 122, 127, 128
primitive. 121
uniformity test, 289. 290
uniform pseudorandom numbers, 288-294
uniform random numbers, 288
unique factorization, 23, 24, 29
unit, 17
unity element, 2
Waring's formula, 30
Wedderburn's theorem, 65-69, 256
weight. JOJ
weight enumerator, 309-311, 334
Wilson's theorem, 37
Zassenhaus algorithm, 142, 143
zero divisor, 12
zero element, 11
zero of polynomial, 27, 42
see also root(s)
zero polynomial, 19
zero sequence, 215