Phil Lucht Math & Physics Archive
Home / Math and Physics Files / Math / Math Book Downloads

Lidli Niederreiter finite fields 1986

PDF · 415 pages · 8.8 MB
Open PDF file

Published textbook, Introduction to Finite Fields and Their Applications by Rudolf Lidl and Harald Niederreiter, a student edition of their 1983 monograph Finite Fields. Chapters cover algebraic foundations, structure of finite fields, polynomials over finite fields, factorization, exponential sums, and linear recurring sequences. Applications include finite geometries, combinatorics, pseudorandom sequences, coding theory, cryptology, and tables of irreducible polynomials. It is a downloaded book, not Phil's own work.

AI-written summary; may contain errors.

Extracted text (machine-read; may contain errors)
Introduction to finite fields and their applications RUDOLF LIDL University of Tasmania, Hobart, Australia HARALD NIEDERREITER Austrian Academy of Sciences, Vienna, Austria Tht rlf/tt of til., UnlomUYo/c...Mr.lo:{rt tt>JWiltt-WI tJJI_,.of!Jook4 ....... ,..,,tdby Hnvy Ylll/n 15J.I. n-UftiHntly/wu P"lnUd fiN/ pwhlizlltd CONIIJww/y �l:JU CAMBRIDGE UNIVERSITY PRESS Cambridge London New York New Rochelle Melbourne Sydney Published by the Press Syndicate of the University of Cambridge The Pitt Building. Trumpington Street, Cambridge CB2 1RP 32 East 57th Street, New York, NY 10022, USA 10 Stamfor d Road, Oakleigh, Melbourne 3166, Australia ©Cambridge University Press 1986 First published 1986 Printed in Great Britain at the University Press, Cambridge British Library Cataloguing in Publication Data Lidl, Rudolf Introduct ion to finite fields and their applications. 1. Finite Fields (Algebra) I. Title 11 Niederreiter, Harald 512'.3 QA247.3 Library of Congress Cataloging in Publication Data Lid!, Rudolf. Introduction to finite frelds and their applications. Bibliography: p. Includes index. 1. Finite fields (Algebra) I. Niederreiter, Harald, 1944- II. Title. QA247.3.L54 1985 512'.3 85-9704 ISBN ().521-J07()6.ji Contents Preface vii Chapter 1 Algebraic Foundations 1 1 Groups 2 2 Rings and Fields 11 3 Polynomials 18 4 Field Extensions 30 Exercises 37 Chapter 2 Structure of Finite Fields 43 1 Characterizat ion of Finite Fields 44 2 Roots of Irreducible Polynomials 47 3 Traces, Norms, and Bases 50 4 Roots of Unity and Cyclotomic Polynomials 59 5 Representation of Elements of Finite Fields 62 6 Wedderburn's Theorem 65 Exercises 69 Chapter 3 Polynomials over Finite Fields 74 1 Order of Polynomials and Primitive Polynomials 75 2 Irreducible Polynomials 82 iv Contents 3 Construction of Irreducible Polynomials 87 4 Linearized Polynomials 98 5 Binomials and Trinomials 115 Exercises 122 Chapter 4 Factorization of Polynomials 129 I Factorization over Small Finite Fields 130 2 Factorization over Large Finite Fields 139 3 Calculation of Roots of Polynomials 150 Exercises 159 Chapter 5 Exponential Sums 162 1 Characters 163 2 Gaussian Sums 168 Exercises 181 Chapter 6 Linear Recurring Sequences 185 1 Feedback Shift Registers, Periodicity Properties 186 2 Impulse Response Sequences, Characteristic Polynomial 193 3 Generating Functions 202 4 The Minimal Polynomial 210 5 Families of Linear Recurring Sequences 215 6 Characteri zation of Linear Recurring Sequences 228 7 Distribution Properties of Linear Recurring Sequences 235 Exercises 245 Chapter 7 Theoretical Applications of Finite Fields 251 1 Finite Geometries 252 2 Combinatorics 262 3 Linear Modular Systems 271 4 Pseudorandom Sequences 281 Exercises 294 Chapter 8 Algebraic Coding Theory 299 1 Linear Codes 300 2 Cyclic Codes 311 3 Goppa Codes 325 Exercises 332 Chapter 9 Cryptology 338 1 Background 339 Contents v 2 Stream Ciphers 342 3 Discrete Logarithms 346 4 Further Cryptosystems 360 Exercises 363 Chapter 10 Tables 367 1 Computation in Finite Fields 367 2 Tables of Irreducible Polynomials 377 Bibliography 392 List of Symbols 397 Index 401 To Pamela and Gerlinde Preface This book is designed as a textbook edition of our monograph Finite Fields which appeared in 1983 as Volume 20 of the Encyclopedia of Mathematics and Its Applications. Several changes have been made in order to tailor the book to the needs of the student. The historical lmd bibliographical notes at the end of each chapter and the long bibliography have been.omitted as they are mainly of interest to researchers. The reader who desires this type of information may consult the original edition. There are also changes in the text proper, with the present book having an even stronger emphasis on applications. The increasingly important role of finite fields in cryptology is reflected by a new chapter on this topic. There is now a separate chapter on algebraic coding theory containing material from the original edition together with a new section on Goppa codes. New material on pseudorandom sequences has also been added. On the other hand, topics in the original edition that are mainly of theoretical interest have been omitted. Thus, a large part of the material on exponential sums and the chapters on equations over finite fields and on permutation polynomials cannot be found in the present volume. The theory of finite fields is a branch of modem algebra that has come to the fore in the last 50 years because of its diverse applications in combinatorics, coding theory, cryptology, and the mathematical study of switching circuits, among others. The origins of the subject reach back into the 17th and I 8th centuries, with such eminent mathematicians as Pierre de Fermat(!60!-1665), Leonhard Euler (1707-1783), Joseph-Louis Lagrange (1736-1813), and Adrien-Marie Legendre (1752-1833) contributing to the structure theory of special finite fields-namely, the so-called finite prime fields. The eeneral theorv of finite fields mav be said to beltin with the work of viii Preface Carl Friedrich Gauss (1777-1855) and Evariste Galois (1811-1832), but it only became of interest for applied mathematicians in recent decades with the emergence of discrete mathematics as a serious discipline. In this book we have aimed at presenting both the classical and the applications-oriented aspects of the subject. Thus, in addition to what has to be considered the essential core of the theory, the reader will find results and techniques that are of importance mainly because of their use in applications. Because of the vastness of the subject, limitations had to be imposed on the choice of material. In trying to make the book as self-contained as possible, we have refrained from discussing results or methods that belong properly to algebraic geometry or to the theory of algebraic function fields. Applications are described to the extent to which this can be done without too much digression. The only noteworthy prerequisite for the book is a background in linear algebra, on the level of a first course on this topic. A rudimentary knowledge of analysis is needed in a few passages. Prior exposure to abstract algebra is certainly helpful, although all the necessary information is summarized in Chapter I. Chapter 2 is basic for the rest of the book as it contains the general structure theory of finite fields as well as the discussion of concepts that are used throughout the book. Chapter 3 on the theory of polynomials and Chapter 4 on factorization algorithms for polynomials are closely linked and should best be studied together. Chapter 5 on exponential sums uses only the elementary structure theory of finite fields. Chapter 6 on linear recurring sequences depends mostly on Chapters 2 and 3. Chapters 7, 8, and 9 are devoted to applications and draw on various material in the previous chapters. Chapter 10 supplements parts of Chapters 2, 3, and 9. Each chapter starts with a brief description of its contents, hence it should not be necessary to give a synopsis of the book here. In order to enhance the attractiv eness of this book as a textbook, we have inserted worked-out examples at appropriate points in the text and included lists of exercises for Chapters 1-9. These exercises range from routine problems to alternative proofs of key theorems, but contain also material going beyond what is covered in the text. With regard to cross-references, we have numbered all items in the main text consecutively by chapters, regardless of whether they are definitions, theorems, examples, and so on. Thus, "Definition 2.41" refers to item 41 in Chapter 2 (which happens to be a definition) and "Remark 6.23" refers to item 23 in Chapter 6 (which happens to be a remark). In the same vein, "Exercise 5.21" refers to the list of exercises in Chapter 5. We gratefully acknowledge the help of Mrs. Melanie Barton and Mrs. Betty Golding who typed the manuscript with great care and efficiency. R. LIDL H. NIEDERREITER Chapter 1 Algebraic Foundations This introductory chapter contains a survey of s.ome basic algebraic con­ cepts that will be employed throughout the book. Elementary algebra uses the operations of arithmetic such as addition and multiplication, but replaces particular numbers by symbols and thereby obtains formulas that, by substitution, provide solutions to specific numerical problems. In modem algebra the level of abstraction is raised further: instead of dealing with the familiar operations on real numbers, one treats general operations -processes of combining two or more elements to yield another element-in general sets. The aim is to study the common properties of all systems consisting of sets on which are defined a fixed number of operations interrelated in some definite way-for instance, sets with two binary operations behaving like + and · for the real numbers. Only the most fundamental definitions and properties of algebraic systems-that is. of sets together with one or more operations on the set-will be introduced. and the theory will be discussed only to the extent needed for our special purposes in the study of finite fields later on. We state some standard results without proof. With regard to sets we adopt the naive standpoint. We use the following sets of numbers: the set N of natural numbers, the set Z of integers, the set (I of rational numbers, the set R of real numbers, and the set C of complex numbers. 2 Algebraic Foundations I. GROUPS In the set of all integers the two operations addition and multiplication are well known. We can generalize the concept of operation to arbitrary sets. Let S be a set and let S X S denote the set of all ordered pairs ( s, t) with s E S, t E S. Then a mapping from S X S into S will be called a (binary) operation on S. Under this definition we require that the image of (s, t) E S X S must be in S; this is the closure property of an operation. By an algebraic structure or algebraic system we mean a set S together with one or more operations on S. In elementary arithmetic we are provided with two operations, addition and multiplication, that have associativity as one of their most important properties. Of the various possible algebraic systems having a single associative operation, the type known as a group has been by far the most extensively studied and developed. The theory of groups is one of the oldest parts of abstract algebra as well as one particularly rich in applica­ tions. 1.1. Definition. A group is a set G together with a binary operation • on G such that the following three properties hold: 1. • is associative; that is, for any a, b, c E G, a•(b•c)�(a•b)•c. 2. There is an identity (or unity) element e in G such that for all aEG, a•e=e• a=a. 3. For each a E G, there exists an inverse element a-1 E G such that a•a-1=a-1 •a=e. If the group also satisfies 4. For all a, bEG, a•b=b•a, then the group is called abelian (or commutative). It is easily shown that the identity element e and the inverse element a-1 of a given element a E G are uniquely determined by the properties above. Furthermore, (a • b)-1 � b-1 • a-1 for all a, b E G. For simplicity, we shall frequently use the notation of ordinary multiplication to designate the operation in the group, writing simply ab instead of a • b. But it must be emphasized that by doing so we do not assume that the operation actually is ordinary multiplication. Sometimes it is also convenient to write a + b instead of a • band -a instead of a-1, but this additive notation is usually reserved for abelian groups. I. Groups 3 The associative law guarantees that expressions such as a1a2 ···a. with a1 E G, 1"' j"' n, are unambiguous, since no matter how we insert parentheses, the expression will always represent the same element of G. To indicate the n-fold composite of an element a E G with itself, where n EN, we shall write a"=aa···a ( n factors a) if using multiplicative notation, and we call a• the nth power of a. If using additive notation for the operation • on G, we write na=a +a+ ···+a (nsumman dsa). Following customary notation, we have the following rules: Multiplicative Notation a-•-(a-1)" a"a"'- a"+'" (a")"'= a""' Additive Notation (-n}a=n(-a) na+ma=(n +m)a m(na)= (mn)a For n = 0 E Z, one adopts the convention a0 = e in the multiplicative notation and Oa-0 in the additive notation, where the last "zero" repre­ sents the identity element of G. 1.2. Examples (i) Let G be the set of integers with the operation of addition. The ordinary sum of two iritegers is a unique integer and the associativity is a familiar fact. The identity element is 0 (zero), and the inverse of an integer a is the integer -a. We denote this group by Z. (ii) The set consisting of a single element e, with the operation • defined by e • e = e, forms a group. (iii) Let G be the set of remainders of all the integers on division by 6-that is, G = {0, 1,2,3,4,5}-and let a • b be the remainder on division by 6 of the ordinary sum of a and b. The existence of an identity element and of inverses is again obvious. In this case, it requires some computation to establish the associativity of •. This group can be readily generalized by replacing the integer 6 by any positive integer n. 0 These examples lead to an interesting class of groups in which every element is a power of some fixed element of the group. If the group operation is written as addition, we refer to "multiple" instead of "power" of an element. 1.3. Definition. A multiplicative group G is said to be cyclic if there is an element a E G such that for any b E G there is some integer j with b = ai. 4 Algebraic Foundations Such an element a is called a generator of the cyclic group, and we write G =(a). It follows at once from the definition that every cyclic group is commutative. We also note that a cyclic group may very well have more than one element that is a generator of the group. For instance, in the additive group Z both I and -I are generators. With regard to the" additive" group of remainders of the integers on division by n, the generalization of Example L2(iii), we find that the type of operation used there leads to an equivalence relation on the set of integers. In general, a subset R of S X S is called an equivalence relation on a set S if it has the following three properties: (a) (s, s) E R for all s E S (reflexivity). (b) If (s, t) E R, then (I, s) E R (symmetry). (c) If (s, t), (I, u) E R, then (s, u) E R (transitivity). The most obvious example of an equivalence relation is that of equality. It is an important fact that an equivalence relation R on a set S induces a partition of S -that is, a representation of S as the union of nonempty, mutually disjoint subsets of S. If we collect all elements of S equivalent to a fixed s E S, we obtain the equivalence class of s, denoted by (s] = {1 E S: (s, t) E R}. The collection of all distinct equivalence classes forms then the desired partition of S. We note that [s] = [t] precisely if (s, t) E R. Example L2(iii) suggests the following concept. 1.4. Definition. For arbitrary integers a, b and a positive integer n, we say that a is congruent to b modulo n, and write a= bmod n, if the difference a -b is a multiple of n -that is, if a= b + kn for some integer k. It is easily verified that "congruence modulo n" is an equivalence relation on the set Z of integers. The relation is obviously reflexive and symmetric. The transitivity also follows easily: if a= b + kn and b = c +In for some integers k and/, then a= c+(k + l)n, so that a= bmodn and b = cmod n together imply a= cmod n. Consider now the equivalence classes into which the relation of congruence modulo n partitions the set Z. These will be the sets [0] = ( ... , -2n,-n,O, n,2n, ... }, [I]=( ... , -2n +I,- n +I, I, n + 1,2n + !, ... }, [ n -I] = ( ... , -n -I, - I, n -I, 2 n -I, 3n -I, ... }. We may define on the set ([O],[l], ... ,[n -I]} of equivalence classes a binary I. Groups operation (which we shall again write as +, although it is certainly not ordinary addition) by [a]+[b]�[a+b], (1.1) where a and bare any elements of the respective sets [a] and [b] and the sum a +bon the right is the ordinary sum of a and b. In order to show that we have actually defined an operation- that is, that this operation is well defined-we must verify that the image element of the pair ([a],[b]) is uniquely determined by [a] and [b] alone and does not depend in any way on the representatives a and b. We leave this proof as an exercise. Associa­ tivity of the operation in (1.1) follows from the associativity of ordinary addition. The identity element is [OJ and the inverse of [a] is [-a]. Thus the elements of the set {[O],[l], ... ,[n -I]} form a group. 1.5. Definition. The group formed by the set {[O],[l], ... ,[n -I]) of equiv­ alence classes modulo n with the operation (1.1) is called the group of integers modulo n and denoted by Z ,. Z, is actually a cyclic group with the equivalence class [I] as a generator, and it is a group of order n according to the following definition. 1.6. Definition. A group is called finite (resp. infinite) if it contains finitely (resp. infinitely) many elements. The number of elements in a finite group is called its order. We shall write I G I for the order of the finite group G. ' There is a convenient way of presenting a finite group. A table displaying the group operation, nowadays referred to as a Cayley table, is constructed by indexing the rows and the columns of the table by the group elements. The element appearing in the row indexed by a and the column indexed by b is then taken to be ab. 1.7. Example. The Cayley table for the group Z 6 is: + [ 0] [I] [2] [3] [4] [5] [0] [0] [I] [2] [3] [4] [5] [I] [I] [2] [3] [4] [5] [0] [2] [2] [3] [4] [5] [0] [I] [3] [3] [4] [5] [OJ [I] [2] [4] [4] [5] [0] [I] [2] [3] [5] [5] [ 0] [I] [2] [3] [4] D A group G contains certain subsets that form groups in their own right under the operation of G. For instance, the subset {[0],[2],[4]) of Z6 is easily seen to have this property. 6 Algebraic Foundations 1.8. Definition. A subset H of the group G is a subgroup of G if H is itself a group with respect to the operation of G. Subgroups of G other than the trivial subgroups {e) and G itself are called nontrivial subgroups of G. One verifies at once that for any fixed a in a group G, the set of all powers of a is a subgroup of G. 1.9. Definition. The subgroup of G consisting of all powers of the ele­ ment a of G is called the subgroup generated by a and is denoted by (a). This subgroup is necessarily cyclic. If (a) is finite, then its order is called the order of the element a. Otherwise, a is called an element of infinite order. Thus, a is of finite order k if k is the least positive integer such that a'� e. Any other integer m with am� e is then a multiple of k. If S is a nonempty subset of a group G, then the subgroup H of G consisting of all finite products of powers of elements of Sis called the subgroup generated by S, denoted by H � (S). If (S) � G, we say that S generates G, or that G is generated by S. For a positive element n of the additive group Z of integers, the subgroup (n) is closely associated with the notion of congruence modulo n, since a = b mod n if and only if a -b E ( n). Thus the subgroup ( n) defines an equivalence relation on Z. This situation can be generalized as follows. 1.10. Theorem. If His a subgroup of G, then the relation R H on G defined by (a, b) E R H if and only if a � bh for some h E H, is an equivalence relation. The proof is immediate. The equivalence relation R H is called left congruence modulo H. Like any equivalence relation, it induces a partition of G into nonempty, mutually disjoint subsets. These subsets ( �equivalence classes) are called the left cosets of G modulo H and they are denoted by aH � (ah: hE H) (or a+ H �{a+ h: hE H) if G is written additively). where a is a fixed element of G. Similarly, there is a decomposition of G into right cosets modulo H, which have the form Ha � {ha: hE H). If G is abelian, then the distinction between left and right cosets modulo H is unnecessary. 1.11. Example. Let G � Z 12 and let H be the subgroup ([OJ, [3], [6], [9]). Then the distinct (left) cosets of G modulo H are given by: [OJ+ H � {[0], [3], [6], [9]}, [I]+ H � {[I], [ 4], [7], [ 10]}, [2]+ H� {[2].[5],[8],[11]}. 0 1.12. Theorem. If His a finit( subgroup of G, then every (left or right) coset of G modulo H has the sam4 number of elements as H. I. Groups 7 1.13. Definition. If the subgroup H of G only yields finitely many distinct left easels of G modulo H, then the number of such easels is called the index of H in G. Since the left easels of G modulo H form a partition of G, Theorem 1.12 implies the following important result. 1.14. Theorem. The order of a finite group G is equal to the product of the order of any subgroup H and the index of H in G. In particular, the order of H divides the order of G and the order of any element a E G divides the order of G. The subgroups and the orders of elements are easy to describe for cyclic groups. We summarize the relevant facts in the subsequent theorem. 1.15. Theorem (i) Every subgroup of a cyclic group is cyclic. (ii) In a finite cyclic group (a) of order m, the element a• generates a subgroup of order m jgcd(k, m ), where gcd(k, m) denotes the greatest common divisor of k and m. (iii) If dis a positive divisor of the order m of a finite cyclic group (a). then (a) contains one and only one subgroup of index d. For any positive divisor f of m, (a) contains precisely one subgroup of order f. (iv) Let f be a positive divisor of the order·of a finite cyclic group (a). Then (a) contains '4>(/) elements of order f. Here '4>(/) is Euler's function and indicates the number of integers n with 1 � n � f that are relatively prime to f. (v) A finite cyclic group (a) of order m contains '4>( mj generators-that is, elements a' such that (a')= (a). The gen­ erators are the powers a' with gcd( r, m) = 1. Proof (i) Let H be a subgroup of the cyclic group (a) with H"' (e). If a" E H. then a-" E H; hence H contains at least one power of a with a positive exponent. Let d be the least positive exponent such that ad E H, and let a' E H. Dividing s by d gives s = qd + r, 0.;; r < d, and q, r E Z. Thus a'( a-d)• =a' E H, which contradicts the minimality of d, unless r = 0. Therefore the exponents of all powers of a that belong to Hare divisible by d, and soH= (ad). (ii) Put d=gcd(k,m). The order of (a•) is the least positive integer n such that a'"= e. The latter identity holds if and only if m divides kn, or equivalently, if and only if mjd divides n. The least positive n with this property is n = mjd. (iii) If dis given, then (ad) is a subgroup of order m 1 d, and so of index d, because of (ii). If (a•) is another subgroup of index d, then its 8 Algebraic Foundations order is m/d, and sod� gcd(k, m) by (ii). In particular, d divides k, so that a• E (ad) and (a•) is a subgroup of (ad). But since both groups have the same order, they are identical. The second part follows immediately because the subgroups of order f are precisely the subgroups of index m /f. (iv) Let l(a)l � m and m � df. By (ii), an element a• is of order /if and only if gcd(k, m) �d. Hence, the number of elements of order fis equal to the number of integers k with I.; k.; m and gcd(k, m) �d. We may write k � dh with I.; h .; f, the condition gcd(k, m) � d being now equiva­ lent to gcd(h,fl �I. The number of these his equal to of>(/). (v) The generators of (a) are precisely the elements of order m, so that the first part is implied by (iv). The second part follows from (ii). D When comparing the structures of two groups, mappings between the groups that preserve the operations play an important role. 1.16. Definition. A mappingf: G--> H of the group G into the group His called a homomorphism of G into H iff preserves the operation of G. That is, if • and · are the operations of G and H, respectively, then f preserves the operation of G if for all a, bEG we have f(a•b)�f (a))(b). If, in addition, f is onto H, then f is called an epimorphism (or homomorphism "onto") and His a homomorphic image of G. A homomorphism of G into G is called an endomorphism. Iff is a one-to-one homomorphism of G onto H, then/ is called an isomorphism and we say that G and Hare isomorphic. An isomorphism of G onto G is called an automorphism. Consider, for instance, the mapping f of the additive group Z of the integers onto the group z" of the integers modulo n, defined by f(a) �[a]. Then f(a+b)�[a+b]�[a]+[b]�f(a) +f(b) fora,bEZ, and f is a homomorphism. Iff: G--> His a homomorphism and e is the identity element in G, then ee � e implies/( e)f( e)� f( e), so that/( e)� e', the identity element in H. From aa-1 �ewe getf(a-1) � (/(a))-1 for all a E G. The automorphisms of a group G are often of particular interest, partly because they themselves form a group with respect to the usual composition of mappings, as can be easily verified. Important examples of automorphisms are the inner automorphisms. For fixed a E G, define f. by f.(b) � aba-1 forb E G. Then f. is an automorphism of G of the indicated type, and we get all inner automorphisms of G by letting a run through all elements of G. The elements band aba-1 are said to be conjugate, and for a nonempty subsetS of G the set asa-1 � {asa-1: s E S) is called a conjugal< of S. Thus, the conjugates of S are just the images of S under the various inner automorphisms of G. L Groups 9 1.17. Definition. The kernel of the homomorphism/: G � H of the group G into the group H is the set kerf� {a E G: f(a) � e'), where e' is the identity element in H. 1.18. Example. For the homomorphism f: Z � Z" given by /(a)� [a], kerf consists of all a E Z with [a]� [OJ. Since this condition holds exactly for all multiples a of n, we have kerf� (n), the subgroup of Z generated �n. D It is easily checked that kerf is always a subgroup of G. More­ over, kerf has a special property: whenever a E G and bE kerf, then aba-1 E kerf. This leads to the following concept. 1.19. Definition. The subgroup H of the group G is called a normal subgroup of G if aha_, E H for all a E G and all hE H. Every subgroup of an abelian group is normal since we then have aha-1 = aa-1h = eh =h. We shall state some alternative characterizations of the property of normality of a subgroup. 1.20. Theorem (i) The subgroup H of G is normal if and only if H is equal to its conjugates, or equivalently, if and only if H is invariant under all the inner automorphisms of G. (ii) The subgroup H of G is normal if and only if the left coset aH is equal to the right coset Ha for every a E G. One important feature of a normal subgroup is the fact that the set of its (left) cosets can be endowed with a group structure. 1.21. Theorem. If His a normal subgroup of G, then the set of (left) cosets of G modulo H forms a group with respect to the operation ( aH )( bH) � (ab)H. 1.22. Definition. For a normal subgroup H of G, the group formed by the (left) cosets of G modulo H under the operation in Theorem 1.21 is called the factor group (or quotient group) of G modulo H and denoted by GjH. If G/H is finite, then its order is equal to the index of H in G. Thus. by Theorem 1.14, we get for a finite group G, IGI IG/HI � jHj· Each normal subgroup of a group G determines in a natural way a homomorphism of G and vice versa. 10 Algebraic Foundations 1.23. Theorem (Homomorphism Theorem). Let f: G--+ /(G)= G1 be a homomorphism of a group G onto a group G 1• Then kerf is a normal subgroup of G, and the group G 1 is isomorphic to the factor group G lker f. Conversely, if H is any normal subgroup ofG, then the mapping I}: G --+ G I H defined by I} (a) = aH for a E G is a homomorphism of G onto G I H with kerl} =H. We shall now derive a relation known as the class equation for a finite group, which will be needed in Chapter 2, Section 6. 1.24. Definition. LetS be a nonempty subset of a group G. The normal­ izer of Sin G is the set N(S) =(a E G: asa-1 = S). 1.25. Theorem. For any nonempty subsetS of the group G, N(S) is a subgroup of G and there is a one-to-one correspondence between the left cosets of G modulo N(S) and the distinct conjugates asa-1 of S. Proof We have e E N(S), and if a, bE N(S), then a-1 and ab are also in N(S), so that N(S) is a subgroup of G. Now asa-1 = bsb-1 = s = a-1bsb-1a = (a-1b)S(a-1b)-1 = a-1b E N(S) =bE aN(S). Thus, conjugates of S are equal if and only if they are defined by elements in the same left coset of G modulo N(S), and so the second part of the theorem is shown. 0 If we collect all elements conjugate to a fixed element a, we obtain a set called the conjugacy class of a. For certain elements the corresponding conjugacy class has only one member, and this will happen precisely for the elements of the center of the group. 1.26. Definition. For any group G, the center of G is defined as the set C = ( c E G: ac = ca for all a E G). It is straightforward to check that the center Cis a normal subgroup of G. Clearly, G is abelian if and only if C =G. A counting argument leads to the following result. 1.27. Theorem (Class Equation). Let G be a finite group with center C. Then k IGI=ICI+ L n,, i-1 where each n, is ;;. 2 and a divisor of IGI. In fact, n1, n2, .. .,n, are the numbers of elements of the distinct conjugacy classes in G containing more than one member. 2. Rings and Fields II Proof Since the relation "a is conjugate to b" is an equivalence relation on G, the distinct conjugacy classes in G form a partition of G. Thus, IGI is equal to the sum of the numbers of elements of the distinct conjugacy classes. There are ICI conjugacy classes (corresponding to the elements of C) containing only one member, whereas n1, n2, ...• nk are the numbers of elements of the remaining conjugacy classes. This yields the class equation. To show that each n, divides IGI, it suffices to note that n, is the number of conjugates of some a E G and so equal to the number of left cosets of G modulo N((a )) by Theorem 1.25. D 2. RINGS AND FIELDS In most of the number systems used in elementary arithmetic there are two distinct binary operations: addition and multiplication. Examples are pro­ vided by the integers, the rational numbers, and the real numbers. We now define a type of algebraic structure known as a ring that shares some of the basic properties of these number systems. 1.28. Definition. A ring (R, +, ·) is a set R, together with two binary operations, denoted by + and ·, such that: I. R is an abelian group with respect to +. 2. ·is associative-that is, (a·h)·c�a·(b·c) for all a,b,cER. 3. The distributive laws hold; that is, for all a, b, c E R we have a· ( b + c) � a· b + a· c and ( b + c)· a � b ·a + c · a. We shall useR as a designation for the ring (R, +,·)and stress that the operations + and · are not necessarily the ordinary operations with numbers. In following convention, we use 0 (called the zero element) to denote the identity element of the abelian group R with respect to addition. and the additive inverse of a is denoted by -a; also, a+ (-b) is abbrevi­ ated by a-b. Instead of a· b we will usually write a b. As a consequence of the definition of a ring one obtains the general property aO � Oa � 0 for all a E R. This, in turn, implies (-a )b �a(-b)�-ab for all a, bE R. The most natural example of a ring is perhaps the ring of ordinary integers. If we examine the properties of this ring, we realize that it has properties not enjoyed by rings in general. Thus, rings can be further classified according to the following definitions. 1.29. Definition (i) A ring is called a ring with identity if the ring has a multiplica­ tive identity-that is, if there is an element e such that ae = ea �a for all aER. (ii) A ring is called commutative if · is commutative. 12 Algebraic Foundations (iii) A ring is called an integral domain if it is a commutative ring with identity e"' 0 in which ab � 0 implies a� 0 orb� 0. (iv) A ring is called a division ring (or skew field) if the nonzero elements of R form a group under ·. (v) A commutative division ring is called a field. Since our study is devoted to fields, we emphasize again the defini­ tion of this concept. In the first place, a field is a set F on which two binary operations, called addition and multiplication, are defined and which con­ tains two distinguished elements 0 and e with 0-=�:-e. Furthermore, F is an abelian group with respect to addition having 0 as the identity element, and the elements of F that are "'0 form an abelian group with respect to multiplication having e as the identity element. The two operations of addition and multiplication are linked by the distributive law a( b +c)� ab + ac. The second distributive law (b + c)a � ba + ca follows automatically from the commutativity of multiplication. The element 0 is called the zero element and e is called the multiplicative identity element or simply the identity. Later on, the identity will usually be denoted by 1. The property appearing in Definition l.29(iii)-namely, that ab � 0 implies a� 0 or b � 0-is expressed by saying that there are no zero divisors. In particular, a field has no zero divisors, for if ab � 0 and a"' 0, then multiplication by a-1 yields b � a-10 � 0. In order to give an indication of the generality of the concept of ring, we present some examples. 1.30. Examples (i) Let R be any abelian group with group operation +. Define ab � 0 for all a, bE R: then R is a ring. (ii) The integers form an integral domain, but not a field. (iii) The even integers form a commutative ring without identity. (iv) The functions from the real numbers into the real numbers form a commutative ring with identity under the definitions for f+ g andfg given by(/+ gXx)� f(x)+ g(x) and (/gXx)� f(x)g(x) for x E R. (v) The set of all 2 X 2 matrices with real numbers as entries forms a noncommutative ring -with identity with respect to matrix addition and multiplication. 0 We have seen above that a field is, in particular, an integral domain. The converse is not true in general (see Example 1.30(ii)), but it will hold if the structures contain only finitely many elements. 1.31. Theorem. Every finite integral domain is a field. Proof Let the elements of the finite integral domain R be a1, a2, ... ,an. For a fixed nonzero element a E R, consider the products ...-....-. ...-....-._ nn Th�""�" Mf" cli ... tinct. for if aa, = aa,. then a( a,-a;)= 0, and 2. Rings and Fields 13 since a* 0 we must have a;-a1 = 0, or a;= a1. Thus each element of R is of the form aa;. in particular, e = aa; for some i with I� i � n, where e is the identity of R. Since R is commutative, we have also a;a = e, and so a; is the multiplicative inverse of a. Thus the nonzero elements of R form a commutative group, and R is a field. 0 1.32. Definition. A subset S of a ring R is called a subring of R provided S is closed under + and · and forms a ring under these operations. 1.33. Definition. A subset J of a ring R is called an ideal provided J is a subring of R and for all a EO J and r EO R we have ar EO J and ra EO J. 1.34. Examples (i) Let R be the field a of rational numbers. Then the set Z of integers is a subring of 0, but not an ideal since, for example, I EO Z. J: EO a, but J: ·I� J: � l. (ii) Let R be a commutative ring, a EO R, and let J � {ra: rEO R), then J is an ideal. (iii) Let R be a commutative ring. Then the smallest ideal contain­ ing a given element a EO R is the ideal (a)� (ra + na: rEO R. n EO Z). If R contains an identity. then (a)� {ra: r EO R). D 1.35. Definition. Let R be a commutative ring. An ideal J of R is said to be principal if there is an a EO R such that J � (a). In this case. J is also called the principal ideal generated by a. Since ideals are normal subgroups of the additive group of a ring, it follows immediately that an ideal J of the ring R defines a partition of R into disjoint cosets, called residue classes modulo J. The residue class of the element a of R modulo J will be denoted by [a]� a+ J. since it consists of all elements of R that are of the form a + c for some cEO J. Elements a. b EO R are called congruent modulo J, written a"' b mod J. if they are in the same residue class modulo J, or equivalently. if a-bE J (compare with Definition 1.4). One can verify that a"' bmod J implies u + r "'b + rmod J. ar "' br mod J, and ra "' rb mod J for any r E R and na "' nb mod J for any n E Z. If, in addition, r "'smod J, then a+ r "'b + smod J and ar"' bsmod J. It is shown by a straightforward argument that the set of residue classes of a ring R modulo an ideal J forms a ring with respect to the operations (a+ J)+(b+ J) �(a +b)+J, (a+ J )( b + J) � ab + J. ( 1.2) (13) 1.36. Definition. The ring of residue classes of the ring R modulo the ideal J under the operations ( 1.2) and ( 1.3) is called the residue class ring (or ''""'"" ,_;.,,..\ '"'f D ""'"'rl"l'"' 1 '>�rl ;,., riP�I"\tPrl l·nr 'R IT 14 Algebraic Foundations 1.37. Example (The residue class ring Z/(n)). As in the case of groups (compare with Definition 1.5). we denote the coset or residue class of the integer a modulo the positive integer n by [a], as well as by a+ ( n ), where (n) is the principal ideal generated by n. The elements of Z/(n) are [O]�O+(n). [l]�l+(n), ... ,[n-l]�n-l+(n). D 1.38. Theorem. Z/( p ), the ring of residue classes of the integers modulo the principal ideal generated by a prime p, is a field. Proof By Theorem 1.31 it suffices to show that Z/( p) is an integral domain. Now [I] is an identity of lj(p), and [a][b]�[ab]�[O] if and only if ab � kp for some integer k. But since p is prime, p divides ab if and only if p divides at least one of the factors. Therefore, either [a] � [0] or [ b] � [0], so that Z/( p) contains no zero divisors. D 1.39. Example. Let p�3. Then Z/(p) consists of the elements [0], [I], and [2]. The operations in this field can be described by operation tables that are similar to Cayley tables for finite groups (see Example 1.7): + [0] [I] [2] [0] [0] [I] [2] [I] [1] [2] [OJ [2] [2] [0] [1] [0] [I] [2] [0] [0] [0] [0] [1] [0] [I] [2] [2] [0] [2] [1] D The residue class fields Zj(p) are our first examples of finite fields -that is, of fields that contain only finitely many elements. The general theory of such fields will be developed later on. The reader is cautioned not to assume that in the formation of residue class rings all the properties of the original ring will be preserved in all cases. For example, the lack of zero divisors is not always preserved, as may be seen by considering the ring lj(n), where n is a composite integer. There is an obvious extension from groups to rings of the definition of a homomorphism. A mapping cp: R -+ S from a ring R into a ring S is called a homomorphism if for any a, b E R we have cp(a+b)�cp(a)+cp(b) and cp(ab)�cp(a)cp(b). Thus a homomorphism cp: R -+ S preserves both operations + and · of R and induces a homomorphism of the additive group of R into the additive group of S. The set kercp �{a E R: cp·(a) � 0 E S) is called the kernel of cp. Other concepts, such as that of an isomorphism , are analogous to those in Definition 1.16. The homomorphism theorem for rings, similar to Theorem 1.23 for groups, runs as follows. 1.40. Theorem (Homomorphism Theorem for Rings). If cp is a r .,_ --· 1--- _ :_ -·· ;J __ , -� D ---1 (" ;,. 2. Rings and Fields isomorphic to the factor ring R/kercp. Conversely, if J is an ideal of the·��_ng R, then the mapping of: R --> R I J defined by of (a) � a + J for a E R is a homomorphism of R onto R/J with kernel J. Mappings can be used to transfer a structure from an algebraic system to a set without structure. For instance, let R be a ring and let cp be a one-to-one and onto mapping from R to a set S; then by means of cp one can define a ring structure on S that converts cp into an isomorphism. In detail, let s1 and s2 be two elements of Sand let r1 and r2 be the elements of R uniquely determined by cp(r1)�s1 and cp(r2)�s2. Then one defines s1 + s2 to be cp(r1 + r2) and Sh to be cp(r1r2), and all the desired properties are satisfied. This structure on S may be called the ring structure induced by cp. In case R has additional properties, such as being an integral domain or a field, then these properties are inherited by S. We use this principle in order to arrive at a more convenient representation for the finite fields Z/( p ). 1.41. Definition. For a prime p, let F, be the set {0,1, ... ,p-I} of integers and let cp: Z/(p)--> F, be the mapping defined by cp([a]) �a for a� 0, I, ... ,p-I. Then F ,. endowed with the field structure induced by cp, is a finite field, called the Galois field of order p. By what we have said before, the mapping cp: Z/( p)--> F, is then an isomorphism, so that cp([a] +[b))� cp([a]) + cp([b]) and cp([a][b]) � cp([a])cp([b]). The finite field IF, has zero element 0, identity I, and its structure is exactly the structure of Z/( p ). Computing with elements of F, therefore means ordinary arithmetic of integers with reduction modulo p. 1.42. Examples (i) Consider Zj(5), isomorphic to IF5 � {0,1,2,3,4}, with the iso- morphism given by: [0]--> 0, [I]-> I, [2]--> 2, [3]--> 3, [4]--> 4. The tables for the two operations + and · for elements in IF 5 are as follows: + 0 2 3 4 0 2 3 4 0 0 I 2 3 4 0 0 0 0 0 0 I I 2 3 4 0 I 0 I 2 3 4 2 2 3 4 0 I 2 0 2 4 I 3 3 3 4 0 I 2 3 0 3 I 4 2 4 4 0 I 2 3 4 0 4 3 2 I (ii) An even simpler and more important example is the finite field F2. The elements of this field of order two are 0 and I, and the operation tables have the following form: In this context. the elements 0 and I are called binary elements. D 16 Algebraic Foundations If b is any nonzero element of the ring Z of integers, then the additive order of b is infinite; that is, nb = 0 implies n = 0. However, in the ring Z/( p ), p prime, the additive order of every nonzero element b is p; that is, pb = 0, and p is the least positive integer for which this holds. It is of interest to formalize this property. 1.43. Definition, If R is an arbitrary ring and there exists a positive integer n such that nr = 0 for every r E R, then the least such positive integer n is called the characteristic of R and R is said to have (positive) characteristic n. If no such positive integer n exists, R is said to have characteristic 0. 1.14. Theorem. A ring R * (0} of positive characteristic having an identity and no zero divisors must have prime characteristic. Proof Since R contains nonzero elements, R has characteristic n;;, 2. If n were not prime, we could write n = km with k, mE Z, l < k, m < n. Then 0 = ne = (km)e = (ke)(me), and this implies that either ke = 0 or me= 0 since R has no zero divisors. It follows that either kr = (ke)r = 0 for all r E R or mr = (me)r = 0 for all r E R, in contradiction to the definition of the characteristic n. D 1.45. Corollllry. A finite field has prime characteristic. Proof By Theorem 1.44 it suffices to show that a finite field F has a positive characteristic. Consider the multiples e,2e, 3e, ... of the identity. Since F contains only finitely many distinct elements, there exist integers k and m with 1.; k < m such that ke =me, or (m-k)e = 0, and so F has a positive characteristic. D The finite field Z/(p) (or, equivalently, F,) obviously has character­ istic p, whereas the ring Z of integers and the field Q of rational numbers have characteristic 0. We note that in a ring R of characteristic 2 we have 2a =a+ a= 0, hence a=-a for all a E R. A useful property of commuta­ tive rings of prime characteristic is the following. 1.46. Theorem. Let R be a commutative ring of prime characteristic p. Then (a+b)r "=aP"+bP " and (a-b)' "=aP"_bp" for a, bE Rand n EN. Proof We use the fact that (P)_p(p-l)···(p-i+l) _ i - 1. 2 ..... i = 0 mod p for all i E Z with 0 < i < p, which follows from <n being an integer and the observation that the factor p in the numerator cannot be cancelled. Then by 2. Rings and Fields 17 the binomial theorem (see Exercise 1.8), (a+b)'�a'+(�)aP-1b+ ··· +(p�l)abp-l +b'�aP+b', and induction on n completes the proof of the first identity. By what we have shown, we get a'"� ((a-b)+ b)'" � (a-b)p " +b'", and the second identity follows. D Next we will show for the case of commutative rings with identity which ideals give rise to factor rings that are integral domains or fields. For this we need some definitions from ring theory. Let R be a commutative ring with identity. An element a E R is called a divisor of bE R if there exists c E R such that ac �b. A unit of R is a divisor of the.id.e.ntity; two elements a, bE R are said to �.Qilllf& if there is a unit • of R such that a� b<. An element c E R is called a erime element if it is no uni�nc!_if)_t.!J'!.§.Q..'!.\Y..t!Je u�ULQf.B_an�l_the.assQc;iates of c as "iliiii"ScifS.-An .. ideal P � R of the ring lLiu:�JJ ed a prime ideal if for a, b E R we have ab E P only if either a E P or b E P. An ideal M "' R of R is called a maximal ideal of R if for any ideal J of R the property M <::: J implies J � R or J � M. Furthermore, R is said to be a principal ideal domain if R is an integral domain and if every ideal J of R is-principal-that is, if there is a generating element a for J such that J �(a)� {ra: r E R). 1.47. Theorem. Let R be a commutative ring with identity. Then: (i) An ideal M of R is a maximal ideal if and only if Rj M is a field. (ii) An ideal P of R is a prime ideal if and only if Rj Pis an integral domain. (iii) Every maximal ideal of R is a prime ideal. (iv) If R is a principalideal domain, then Rj(c) is afield if and only if c is a prime element of R. Proof (i) Let M be a maximal ideal of R. Then for a'/' M, a E R, the set J � {ar + m: r E R, mE M) is an ideal of R properly containing M, and therefore J � R. In particular, ar + m � 1 for some suitable r E R, mE M, where I denotes the multiplicative iden­ tity element of R. In other words, if a+ M"' 0 + M is an element of Rj M different from the zero element in Rj M, then it possesses a multiplicative inverse, because (a+ M)(r + M) � ar + M �(I-m)+ M �I+ M. Therefore, RjM is a field. Con­ versely; let Rj M be a field and Jet J � M, J"' M, be an ideal of R. Then for a E J, a'/' M, the residue class a+ M has a multi- 18 Algebraic Foundations plicative inverse, so that (a+ MXr + M) =I+ M for some r E R. This implies ar + m =I for some mE M. Since J is an ideal, we have I E J and therefore (I) = R c;: J, hence J = R. Thus M is a maximal ideal of R. (ii) Let P be a prime ideal of R; then R/P is a commutative ring with identity I+ P * 0+ P. Let (a+ P)(b + P) = 0+ P, hence abE P. Since P is a prime ideal, either a E P or bE P; that is, either a+ P = 0+ P orb+ P = 0+ P. Thus, R/P has no zero divisors and is therefore an integral domain. The converse follows immediately by reversing the steps of this proof. (iii) This follows from (i) and (ii) since every field is an integral domain. (iv) Let cER. If cis a unit, then (c)=R and the ring R/(c) consists only of one element and is no field. If c is neither a unit nor a prime element, then c has a divisor a E R that is neither a unit nor an associate of c. We note that a* 0, for if a= 0, then c = 0 and a would be an associate of c. We can write c = ab with bE R. Next we claim that a '1-(c). For otherwise a= cd = abd for some dE R, or a(!-bd) = 0. Since a* 0, this would imply bd =I, so that d would be a unit, which contradicts the fact that a is not an associate of c. It follows that (c) c;: (a) c;: R, where all containments are proper, and so R/(c) cannot be-'a field be­ cause of (i). Finally, we are left with the case where c is a prime element. Then (c)* R since cis no unit. Furthermore, if J :2 (cj is an ideal of R, then J = (a) for some a E R since R is a principal ideal domain. It follows that cE (a), and so a is a divisor of c. Consequentl y, a is either a unit or an associate of c, so that either J = R or J = (c). This shows that (c) is a maximal ideal of R. Hence Rj(c) is a field by (i). 0 As an application of this theorem, let us consider the case R = Z. We note that Z is a principal ideal domain since the additive subgroups of Z are already generated by a single element because of Theorem 1.15(i). A prime number p fits the definition of a prime element, and so Theorem 1.47(iv) yields another proof of the known result that Z/( p) is a field. Conse­ quently, ( p) is a maximal ideal and a prime ideal of Z. ·For a composite integer n. the ideal (n) is not a prime ideal of Z, and so lj(n) is not even an integral domain. Other applications will follow in the next section when we consider residue class rings of polynomial rings over fields. 3. POLYNOMIALS In elementary algebra one regards a polynomial as an expression of the fnrrn n_ + n_ y + ... + n r" Thf". n.'s ;ne C:Jlled coefficients and are usuallV 3. Polynomials 19 real or complex numbers; x is viewed as a variable: that is, substituting an arbitrary number a for x, a well-defined number a0 + a1a + · · · + a"a" is obtained. The arithmetic of polynomials is governed by familiar rules. The concept of polynomial and the associated operations can be generalized to a formal algebraic setting in a straightforward manner. Let R be an arbitrary ring. A polynomial over R is an expression of the form n f(x)� L a ,x'�a0+a1x+ ··· +a.x", ;-o where n is a nonnegative integer, the coefficients a;. 0 � i � n, are elements of R, and xis a symbol not belonging toR, called an indeterminate over R. Whenever it is clear which indeterminate is meant, we can use f as a designation for the polynomial f(x). We adopt the convention that a term a,x' with a,� 0 need not be written down. In particular, the polynomial f(x) above may then also be given in the equivalent formf(x)�a0+a1x + ··· +a11x"+Ox"+1+ ··· +Ox"+h,wherehisanypositive integer.When comparing two polynomia ls/(x) and g(x) over R, it is therefore possible to assume that they both involve the same powers of x. The polynomials n n f(x) � L a,x' and g(x) � L b,x' i-0 ;-o over R are considered equal if and only if a,� b1 for 0 .;; i.;; n. We define the sum of f(x) and g(x) by · n f(x)+g(x)� L (a,+b,)x'. i-0 To define the product of two polynomials over R, let and set n m f(x)� L a,x' and g(x)� L b1xi ;-o ;-o n+m f(x)g(x)� L c.x•, wherec. � k-0 i+ j-k O<!O;i"!i;II,O"!i; j<,m It is easily seen that with these operations the set of polynomials over R forms a ring. 1.48. Definition. The ring formed by the polynomials over R with the above operations is called the polynomial ring over R and denoted by R[x ]. The zero element of R[x] is the polynomial all of whose coeffi cients are 0. This polynomi;u is called the zero polynomial and denoted by 0. It should always be clear from the context whether 0 stands for the zero element of R or the zero polynomial. 20 Algebraic Foundations 1.49. Definition. Let f(x) = !:7-oa;x; be a polynomial over R that is not the zero polynomial, so that we can suppose a,"' 0. Then a, is called the leading coefficient of f(x) and a0 the constant term, while n is called the degree of f(x), in symbols n = deg(f(x)) = deg(f). By convention, we set deg(O) =-oo. Polynomials of degree .,;; 0 are called constant polynomials. If R has the identity I and if the leading coefficient of f(x) is I, then f(x) is called a monic polynomial. By computing the leading coefficient of the sum and the product of two polynomials, one finds the following result. 1.50. Theorem. Let f, g E R[x]. Then deg(f + g) .,;; max( deg(f ) , deg( g)) , deg(fg) .,;; deg(/ ) + deg( g) . If R is an integral domain, we have deg(fg) = deg(f ) + deg( g) . ( 1.4) If one identifies constant polynomials with elements of R, then R can be viewed as a subring of R[x1. Certain properties of R are inherited by R[x1. The essential step in the proof of part (iii) of the subsequent theorem depends on (1.4). 1.51. Theorem. Let R be a ring. Then: (i) R[x1 is commutative if and only if R is commutative. (ii) R[x 1 is a ring with identity if and only if R has an identity. (iii) R[x1 is an integral domain if and only if R is an integral domain. In the following chapters we will deal almost exclusively with poly­ nomials over fields. Let F denote a field (not necessarily finite). The concept of divisibility, when specialized to the ring F[x1, leads to the following. The polynomial g E F[x1 divides the polynomial f E F[x1 if there exists a polynomial h E F[x1 such that f = gh. We also say that g is a divisor off, or thatfis a multiple of g, or thatfis divisible by g. The units of F[x1 are the divisors of the constant polynomial I, which are precisely all nonzero constant polynomials. As for the ring of integers, there is a division with remainder in polynomial rings over fields. 1.52. Theorem (Division Algorithm). Let g"' 0 be a polynomial in F[x1. Then for any f E F[x1 there exist polynomials q, r E F[x1 such that f = qg + r, where deg(r) < deg(g). 1.53. Example. Consider f(x) = 2x' + x4 + 4x + 3 E F,[x1, g(x) = 3x2 + I E IF ,[x1. We compute the polynomials q, r E IF ,[x 1 with/= qg + r by using 3. Polynomials long division: 4x3+ 2x2+2x + I 3x2 + 11 2x5+x4 -2x5 -4 x3 x4 + x3 +4x+3 -x4 -2x2 x' +3x2+4x -x3 -2x 3x2+2x+3 -3x2 -1 2x+2 21 Thus q(x) � 4x3 +2x2 +2x +I, r(x) � Zx +2, and obviously deg(r) < deg(g). 0 The fact that F[ x 1 permits a division algorithm implies by a standard argument that every ideal of F[ x 1 is principal. 1.54. Theorem. F[x1 is a principal ideal domain . In fact, for every ideal J * (0) of F[ x 1 there exists a uniquely determined monic polynomial g E F[x1 with J� (g). Proof F[x1 is an integral domain by Theorem 1.5l(iii). Suppose J * (0) is an ideal of F[ x 1· Let h ( x) be a nonzero pelynomial of least degree contained in J, let b be the leading coefficient of h ( x ), and set g( x) � b-1h(x). Then g E J and g is monic. Iff E J is arbitrary, the division algorithm yields q, r E F[x1 with f � qg +rand deg(r) < deg(g) � deg(h). Since J is an ideal, we get/-qg � r E J, and by the definition of h we must have r � 0. Therefore, f is a multiple of g, and so J � (g). If g1 E F[x1 is another monic polynomial with J=(g1), then g�c1g1 and g1�c2g with c" c2 E F[x1. This implies g � c1c2g, hence c1c2 �I, and c1 and c2 are constant polynomials. Since both g and g1 are monic, it follows that g � g1, and the uniqueness of g is established. 0 1.55. Theorem. Let /1, •.• J. be polynomials in F[x1 not all of which are 0. Then there exists a uniquely determined monic polynomial dE F[x1 with the following properties: (i) d divides each Jj. I .;; j .;; n; (ii) any polynomial c E F[x1 dividing each Jj. I .;; j .;; n, divides d. Moreover, d can be expressed in the form d�bd1 + ··· +b.f. withb" ... ,b.EF[x]. (1.5) Proof The set J consisting of all polynomials of the form cd1 + · · · + c.f. with c1, ••• ,c. E F[x1 is easily seen to be an ideal of F[x1. Since not all Jj are 0, we have J * (0), and Theorem 1.54 implies that J � (d) 22 Algebraic Foundations for some monic polynomial dE F[x]. Property (i) and the representation ( 1.5) follow immediately from the construction of d. Property (ii) follows from (1.5). If d1 is another monic polynomial in F[x] satisfying (i) and (ii). then these properties imply that d and d1 are divisible by each other, and. so (d)� (d1). An application of the uniqueness part of Theorem 1.54 yields d�d1• D The monic polynomial d appearing in the theorem above is called the greatest common divisor of f1 .... ,f.,, in symbols d � gcd(/1, ••• ,f, ). If gcd(/1, ••• ,f.,) � I, then the polynomials /1 .... ,f., are said to be relatively prime. They are called pairwise relatively prime if gcd(/1, f)� I for I .;; i < j .;; n. The greatest common divisor of two polynomia ls/, g E F[x] can be computed by the Euclidean algorithm . Suppose . without loss of generality, that g"' 0 and that g does not divide f. Then we repeatedly use the division algorithm in the following manner: g=q2r1+r2 '1 = q3r1 + 'J 0 .;;deg(r1) <deg(g) 0 .;;deg(r2) <deg(r1) 0 .;; deg(r1) < deg(r2) 0 .;; deg(r,) < deg(r,_1) Here q1 .... ,q,. 1 and r1 ..... r, are polynomials in F[x ]. Since deg(g) is finite, the procedure must stop after finitely many steps. If the last nonzero remainder r, has leading coefficient b, then gcd(/, g)� b-1 r,. In order to find gcd(/1, ••• ,f.,) for n > 2 and nonzero polynomials f1, one first computes gcd( /1, /2 ), then gcd(gcd( /1, /2 ), /1 ), and so on, by the Euclidean algorithm. 1.56. Example. The Euclidean algorithm applied to f(x)�2x6+x1+x2+2Ef1[x], g(x)�x4+x2+2xEIF1[x] yields: 2x6 + x1 + x2 +2 � (2x2 + I)(x4 + x2 +2x)+x +2 x4 + x2 +2x � (x1 + x2 +2x + I)(x +2)+ I x+2�(x+2)1. Therefore gcd(/, g) � I and f and g are relatively prime. D A counterpart to the notion of greatest common divisor is that of least common multiple. Let /1, ••• ,f., be nonzero polynomials in F[x]. Then one shows (see Exercise 1.25). that there exists a uniquely determined monic J. Polynomials 23 polynomial mE F[x] with the following pfoperties: (i) m is a multiple of eachJj, I.; j.; n; (ii) any polynomial bE F[x] that is a multiple of eachJj. I.; j.; n, is a multiple of m. The polynomial m is called the least common multiple of /1 ..... /,, and denoted by m � lcm(/1 .... .f.). For two nonzero polynomials/, g E F[x] we have a-1/g � lcm(/, g )gcd(/, g), ( 1.6) where a is the leading coefficient of fg. This relation conveniently reduces the calculation of lcm(/. g) to that of gcd(/. g). There is no direct analog of (1.6) for three or more polynomials. In this case, one uses the identity lcm(/1, ••• .f.)� lcm(lcm(/1, ••• .f._ 1 ). f.) to compute the least common mul­ tiple. The prime elements of the ring F[x] are usually called irreducible polynomials. To emphasize this important concept. we give the definition again for the present context. 1.57. Definition. A polynomial p E F[x] is said to be irreducible over F (or irreducible in F[x], Or_l!,r ime infujfif p has posiiive'deg ree and n be with b, c E F[x] implies that either b or cis a constant p�ial. Briefly stated, a polynomial of positive degree is irreducible over F if it allows only trivial factorizations. A polynomial in F[x] of positive degree that is not irreducible over F is called reducible over F. The reducibility or irreducibility of a given polynomial depends heavily on the field under consideration. For instance. the polynomial x1-2 E O[x] is irreducible over the field Q of rational numbers. but x2 -2 � (x +/2)(x -/2) is reducible over the field of real numbers. Irreducible polynomials are of fundamental importance for the struc­ ture of the ring F[x] since the polynomials in F[x] can be written as products of irreducible polynomials in an essentially unique manner. For the proof we need the following result. 1.58. Lemma. If an irreducible polynomial p in F[x] divides a product /1 • • • fm of polynomials in F[x]. then at/east one of the factors!, is divisible by p. Proof Since p divides/1•• ·/, •• we get the identity (/1 +(p))·· · Um+(p))�O+(p) in the factor ring F[x]/(p). Now F[x]/(p) is a field by Theorem 1.47(iv). and so Jj + ( p) � 0 + ( p) for some j; that is, p divides f,. D 1.59. Theorem (Unique Factorization in F[x]). Any polynomial f E F[x] of positive degree can be written in the form f�ap;• .. ·p>'· (1.7) where a E F, p1, ••• ,pk are distinct monic irreducible polynomials in F[x], and e1, ••• ,ek are positive integers. Moreover. this factorization is unique apart from the order in which the factors occur. 24 Algebraic Foundations Proof The fact that any nonconstant f E F[x] can be represented in the form (1.7) is shown by induction on lhe degree of f. The case deg(f) =I is trivial since any polynomial in F[x] of degree I is irreducible over F. Now suppose the desired factorization is established for all noncon­ stant polynomials in F[x] of degree < n. If deg(f) =nand/ is irreducible over F, then we are done since we can write f =a( a-1/), where a is the leading coefficient off and a-if is a monic irreducible polynomial in F[x]. Otherwis e,/ allows a factorizatio n/= gh with I.; deg(g) < n, I.; deg(h) < n, and g, hE F[x]. By the induction hypothesis, g and h can be factored in the forrn (1.7), and so f can be factored in this forrn. To prove uniqueness, suppose f has two factorizations of the form (1.7), say (1.8) By comparing leading coefficien ts, we get a= b. Furthermore, the irreduc­ ible polynomial Pi in F[x] divides the right-hand side of (1.8), and so Lemma 1.58 shows that Pi divides q1 for some j, I.; j.; r. But q1 is also irreducible in F[x], so that we must have q1 = cpi with a constant poly­ nomial c. Since q1 and Pi are both monic, it follows that q1 =Pi· Thus we can cancel Pi against q1 in (1.8) and continue in the same manner with the remaining identity. After finitely many steps of this type, we obtain that the two factorizations are identical apart from the order of the factors. D We shall refer to ( 1.7) as the canonical factorization of the polynomial fin F[x]. IfF= 0, there is a method due to Kronecker for finding the canonical factorization of a polynomial in finitely many steps. This method is briefly described in Exercise 1.30. For polynomials over finite fields, factorization algorithms will be discussed in Chapter 4. A central question about polynomials in F[ x] is to decide whether a given polynomial is irreducible or reducible over F. For our purposes, irreducible polynomials over IF, are of particular interest. To determine all monic irreducible polynomials over F P of fixed degree n, one may first compute all monic reducible polynomials over f, of degree n and then eliminate them from the set of monic polynomials in F, [ x] of degree n. If p or n is large, this method is not feasible, and we will develop more powerful methods in Chapter 3, Sections 2 and 3. 1.60. Example. Find all irreducible polynomials over F2 of degree 4 (note that a nonzero polynomial in F2[x] is automatically monic). There are 24 = 16 polynomials in IF2[x] of degree 4. Such a polynomial is reducible over F 2 if and only if it has a divisor of degree I or 2. Therefore, we compute all products (a0 + aix + a2x2 + x3Xb0 + x) and (a0 + aix + x2Xb0+bix+x2) with a1,b1EIF2 and obtain all reducible polynomials over IF 2 of degree 4. Comparison with the 16 polynomials of degree 4 leaves 3. Polynomials 25 us with the irreducible polynomials /1(x) � x4 + x +I, /2(x) � x4 + x3 +I, f3(x)�x4+x3+x2+x+liniF2[x]. 0 Since the irreducible polynomials over a field Fare exactly the prime elements of F[x], the following result, one part of which was already used in Lemma 1.58, is an immediate consequence of Theorems 1.47(iv) and 1.54. 1.61. Theorem. For f E F[x], the residue class ring F[x]/(f) is a field if and only iff is irreducible over F. As a preparation for the next section, we shall take a closer look at the structure of the residue class ring F[x]/(/), where f is an arbitrary nonzero polynomial in F[x]. We recall that as a residue class ring F[x]/(/) consists of residue classes g+(/) (also denoted by [g]) with gEF[x], where the operations are defined as in ( 1.2) and ( 1.3). Two residue classes g + ( /) and h + ( /) are identical precisely if g = h mod f-that is, precisely if g-h is divisible by f. This is equivalent to the requirement that g and h leave the same remainder after division by f. Each residue class g + (f) contains a unique representative r E F[x] with deg(r) < deg(/), which is simply the remainder in the division of g by f. The process of passing from g to r is called reduction mod f. The uniqueness of r follows from the observation that if r1 E g + ( /) with deg( r1) < derj /), then r - r1 is divisible by f and deg(r-r1) < deg(/), which is only possible if r � r1• The distinct residue classes comprising F[x]/(/) can now be described explicitly; namely, they are exactly the residue classes r + ( /), where r runs through all polynomials in F [ x] with deg( r) < deg( /). Thus, i{ F � IF P and deg( /) � n ;;, 0, then the number of elem�nts of FP[x]/(/) is equal to the number of polynomials in IFP[x] of degree < n, which is p". 1.62, Examples (i) Let f(x) � x E IF2[x]. The p" � 21 polynomials in IF2[x] of degree <I determine all residue classes comprising F2[x]/(x), Thus, F2[x]/(x) consists of the residue classes [0] and [I] and is isomorphic to F 2. (ii) Let f(x) � x2 + x +IE IF2[x]. Then F2[x]/(/) has the p" � 22 elements [0], [I], [x], [x + 1]. The operation tables for this residue class ring are obtained by performing the required operations with the polynomials determining the residue classes and by carrying out reduction mod f if necessary: + [0] [ I] [X] [x +I] [0] [0] [I] [X 1 [x +I] [I] [I] [0] [X+ I] [X 1 [X] [x +I] [X] [x +I] [x +I] [X] [0] [ I] [I] [0] 26 [OJ [OJ [OJ [I] [OJ [x] [OJ [x+l] [OJ [I] [OJ [I] [x] [x +I] [X] [OJ [X] [x +I] [I] Algebraic Foundations [x +I] [OJ [x +I] [I] [x] By inspecting these tables, or from the irreducibility of I over F2 and Theorem 1.61, it follows that F2[x]/(/) is a field. This is our first example of a finite field for which the number of elements is not a prime. (iii) Let l(x) = x2 + 2 E F 3[x]. Then IF 3[x ]/(/) consists of the p" = 32 residue classes [0], [I], [2]. [x]. [x + 1], [x +2]. [2x]. [2x + 1], [2x+2]. The operation tables for F3[x]/(f) are again pro­ duced by performing polynomial operations and using reduc­ tion mod I whenever necessary. Since IF3[x ]/(/) is a commuta­ tive ring, we only have to compute the entries on and above the main diagonal. + (OJ (!] (2] [x] [x +I] [x +2] [2x] (2x +I] (2x +2] (OJ [I] [2] [x] [x +I] [x +2] (2x] (2x +I] (2x + 2] (OJ (! J (2] (OJ (I] (2] (2] (OJ [I] (OJ [I] (2] [OJ (OJ [OJ [I] [2] [I] [x] [x J [x +I] [x +2] [2x] [x] [OJ [x] [2x J [I] [x +I] [x+ I] [x +2] [x] [2x +I] (2x + 2] [x +I] (OJ [x +I] [2x +2] [x +I] [2x +2] [x +2] [x + 2] [x] [x +I] [">lx + 2] [2x J [2x +I] [x + 2] (OJ [x +2] [2x +I] (2x +I] [OJ [x +2] [2x] [2x J (2x +I] [2x+2] [OJ (!] [2] [x] [2x] (OJ [2x] [x J (2] (2x +2] [x +2] (!] [2x +I] [2x +I] [2x +2] [2x J [I] [2] (OJ [x +I] [x +2] [2x +I] (OJ [2x +I] [x +2] [x +2] [0] [2x +I] (2x +I] [x +2] (2x +2] [2x + 2] (2x J (2x +I] [2] (OJ [I] [x +2] [x] [x +I] (2x +2] (OJ (2x +2] [x +I] [2x +2] [x +I] (OJ [x +I] [OJ [2x +2] Note that F3[x]/(/) is not a field (and not even an integral domain). This is in accordance with Theorem 1.61 since x2 +2 = (x + IXx +2) is reducible over IF3. D IfF is again an arbitrary field andl(x)E F[x]. then replacement of the indeterminate x in I( x) by a fixed element of F yields a well-def ined 3. Polynomials 27 element of F. In detail, if f(x) = a0 + a1x + · · · + a,x" E F[x] and bE F, then replacing x by b we get f(b)=a0+a1b+ ··· +a,b"EF. In any polynomial identity in F[x] we can substitute a fixed bE F for x and obtain a valid identity in F (principle of substitution ). 1.63. Definition. An element b E F is called a root (or a zero) of the polynomia l/ E F[x] if f(b) = 0. An important connection between roots and divisibility is given by the following theorem. 1.64. Theorem. An element bE F is a root of the polynomial f E F[x] if and only if x-b divides f(x). Proof We use the division algorithm (see Theorem 1.52) to write f(x) = q(x)(x-b)+ c with q E F[x] and c E F. Substituting b for x, we get /(b)= c, hence f(x) = q(xXx-b)+ f(b). The theorem follows now from this identity. D 1.65. Definition. Let bE Fbe a root of the polynom ial/ E F[x]. If k is a positive integer such that f(x) is divisible by (x-b)', but not by (x-b )k+ 1, then k is called the multiplicity of b. If k =I, then b is called a simple root (or a simple zero) off, and if k ;. 2, then b is called a multiple root (or a multiple zero) of f. 1.66. Theorem. LetfEF[xrwith deg/."'n;.O. Ifb1, ••• ,bmEF are distinct roots off with multiplicities kp···•km, respectively, then (x­ b1)''···(x-bm)'··dividesf(x). Consequentl y,k1+ ··· +km"'n,andfcan have at most n distinct roots in F. Proof We note that each polynomial x-bj, 1., j"' m, is irreduc­ ible over F, and so (x-bj)k; occurs as a factor in the canonical factoriza­ tion of f. Altogether, the factor (x-b1)'' • • • (x-bm)'· appears in the canonical factorization off and is thus a divisor of f. By comparing degrees, we get k1 + · · · + km"' n, and m "'k1 + · · · + km "'n shows the last state­ ment. 0 1.6'7. Definition. If f(x) = a0 + a1x + a2x2 + · · · + a,x" E F[x], then the derivative f' off is defined by f' = f'(x) = a1 + 2a2x + · · · + na,x•-l E F[x]. 1.68. Theorem. The element bE F is a multiple root off E F[x] if and only if it is a root of both f and f'. There is a relation between the nonexistence of roots and irreducib il­ ity. Iff is an irreducible polynomial in F[x] of degree ;. 2, then Theorem 1.64 shows that f has no root in F. The converse holds for polynomials of degree 2 or 3, but not necessarily for polynomials of higher degree. 28 Algebraic Foundations 1.69. Theorem. The polynomial f E F[x] of degree 2 or 3 is irre­ ducible in F[x] if and only iff has no root in F. Proof The necessity of the condition was already noted. Con­ versely, if f has no root in F and were reducible in F[x], we could write f � gh with g, hE F[x] and 1 � deg(g) � deg(h). But deg(g)+deg(h) � deg(/)�3. hence deg(g)�l; that is, g(x)=ax+b with a,bEF, a*O. Then - ba-1 is a root of g, and so a root off in F, a contradiction . 0 1,70. Example. Because of Theorem 1.69, the irreducible polynomials in IF2[x] of degree 2 or 3 can be obtained by eliminating the polynomials with roots in IF2 from the set of all polynomials in F2[x] of degree 2 or 3. The only irreducible polynomial in IF2[x] of degree 2 is f(x) = x' + x + 1, and the irreducible polynomials in IF 2[ x] of degree 3 are /1 ( x) � x' + x + 1 and f2(x)�x '+x2+1. 0 In elementary analysis there is a well-known method for constructing a polynomial with real coefficients which assumes certain assigned values for given values of the indeterminate. The same method carries over to any field. 1. 71. Theorem (Lagrange Interpolation Formula ). For n;. 0, let a0, ... ,a, ben+ 1 distinct elements ofF, and let b0, ... ,b, ben+ 1 arbitrary elements of F. Then there exists exactly one polynomial f E F[x] of degree � n such that f( a,) -bJor i -0, .. ., n. This polynomial is given by " " t(x)� L b, n (a,-a.)-1(x-a.). i=O 1< -o /<=tJOi One can also consider polynomials in several indeterminates. Let R denote a commutative ring with identity and let x1, ... ,x, be symbols that will serve as indeterminates. We form the polynomial ring R[xd, then the polynomial ring R[x10 x2] � R[x1][x2], and so on, until we arrive at R[x1, ... ,x,]� R[x1, ... ,x,_1][x,]. The elements of R[x1, ... ,x,] are then expressions of the form I= f(x x ) ="'a x'' · · · x'• I•"" "' n /..... j\ ···in 1 n with coefficients a,, .. '· E R, where the summation is extended over finitely many n-tuples (ip ... ,i,) of nonnegative integers and the convention xJ = 1 (1 � j � n) is observed . Such an expression is called a polynomial in x 1, ••• , x, over R. Two polynomials f, g E R[x1, ... ,x,] are equal if and only if all corresponding coefficients are equal. It is tacitly assumed that the inde­ terminates x1, ••• ,x" commute with each other, so that, for instance, the expressions x1x2x3x4 and x4x1x3x2 are identified. 1.72. Definition. Let/ E R[x1, ... ,x,] be given by 3. Polynomials 29 If a,1 ... 1� * 0, then a11 ... ;�X�1 · · · x� � is called a term off and i 1 + · · · +in is the degree of the term. For I"* 0 one defines the degree of 1. denoted by deg( f), to be the maximum of the degrees of the terms of f. For I� 0 one sets deg( f) � -oo. If I� 0 or if all terms of f have the same degree, then I is called homogeneous. Any IE R[x1, ••• ,x.] can be written as a finite sum of homogeneous polynomials. The degrees of polynomials in R[x" ... ,x.] satisfy again the inequalities in Theorem 1.50, and if R is an integral domain, then (1.4) is valid and R[x1, ••• ,x.] is an integral domain. If F is a field, then the polynomials in F[x1, ••• ,x.] of positive degree can again be factored uniquely into a constant factor and a product of "monic" prime elements (using a suitable definition of "monic"), but for n ;;. 2 there is no analog of the division algorithm (in the case of commuting indeterminates) and F(x1, ••• ,x.] is not a principal ideal domain. An important special class of polynomials in n indeterminates is that of symmetric polynomials. 1.73. Definition. A polynomial IE R[x1, ••• ,x.] is called symmetric if l(x, , ... ,X;)� l(xp ... ,x.) for any permutation ip ... ,i. of the integers ' " 1, ... ,n. 1.74. Example. Let z be an indeterminate over R[x1, ... ,x.], and let g(z) � (z-x1)(z-x2) • • • (z-x.). Then with Thus: g(z)�z"-o1z"-1+o2;"-2+ .... +(-l)"o. x .. ·x. (k�l,2, ... ,n). 11 lk ol=xl+x2+ ... +xn, o2=x1x2+x1x3+ ··· +x1x,+x2x3+ ··· +x2xn+ ··· +xn-lxn, 0n = X1X2 · · · Xn. As g remains unaltered under any permutation of the X;, all the ok are symmetric polynomials; they are also homogeneous. The polynomial ok � o.(x1, ... ,x.) E R[x1, ... ,x.] is called the kth elementary symmetric poly­ nomial in the indeterminates x1, •••• x, over R. The adjective "elementary" is used because of the so-called "fundamental theorem on symmetric poly­ nomials," which states that for any symmetric polynomial IE R[x" ... ,x.] there exists a uniquely determined polynomial hE R[x1, ... ,x.] such that l(xp ... ,x.,)�h(op .... o.). D 1.75. Theorem (Newton's Formula). Let o" ... ,o. be the elemen- ·········-"-:- --1 .. -��;�1,. :,.. v ...,..,,. ,.. I} "'",/ lot r = H t= 7 n�·u/ 30 Algebraic Foundations s,�s,(x1, ••• ,x.)�x;+···+x!ER[x".,,x.]for k;;.L Then the for­ mula SJ. - Sk.-ICJI + Sk.-2(12 + ... + ( -l)m-ISk-m+ lam-\+ ( -l)m: Sk._m(Jm = Q holds fork ;;.I, where m � min(k, n). I. 76, Theorem (Waring's Formula). With 1he same notation as in Theorem L75, we have for k > I, where the summation is extended over all n-tuples ( i 1,. , , i") of nonneg�tive integers with i1 +2i2 + · · · + ni,. = k. The coefficient of a;1ai2• • • a�" is always an integer. 4. FIELD EXTENSIONS -Let F be a field. A subset K ofF that is itself a field under the operations of F will be called a subfield of F, In this context, F is called an extension (field) of K. If K "' F, we say that K is a proper subfield of F If K is a subfield of the finite field 'F,, p prime, then K must contain the elements 0 and I, and so all other elements of F, by the closure of K under addition. It follows that F, contains no proper subfields. We are thus led to the following concept, 1.77. Definition. A field containing no proper subfields is called a prime field. By the above argumen t, any finite field of order p, p prime, is a prime field. Another example of a prime field is the field 0 of rational numbers. The intersection of any nonempty collection of subfields of a given field F is again a subfield of F. If we form the intersection of all subfields of F, we obtain the prime subfield of F It is obviously a prime field. I. 78. Theorem The prime subfield of a field F is isomorphic to either FP or Q, according as the characteristic ofF is a prime p or 0. i.79. Definition. Let K be a subfield of the field F and M any subset of F Then the field K( M) is defined as the intersection of all sub fields of F containing both K and M and is called the extension (field) of K obtained by adjoining the elements in M. For finite M � {81,., ,8.) we write K( M) = K(81,.,,8.). If Mconsistsof a singleelement 8EF, then L� K(8) is said to be a simple extension of K and 8 is called a defining element of L over K. 4. Field Extensions 31 Obviously, K ( M) is the smallest sub field of F containing both K and M. We define now an important type of extension. 1.80. Definition. Let K be a subfield of F and 8 E F. If 8 satisfies a nontrivial polynomial equation with coefficients in K, that is, if a.8" + · · · + a18 + a0 � 0 with a, E K not all being 0, then 8 is said to be algebraic over K. An extension L of K is called algebraic over K (or an algebraic extension of K) if every element of L is algebraic over K. Suppose 8 E F is algebraic over K, and consider the set J � (/ E K[x1: f(8)� O).lt is easily checked that J is an ideal of K[x1, and we have J"' (0) since 8 is algebraic over K. It follows then from Theorem 1.54 that there exists a uniquely determined monic polynomial g E K[x1 such that J is equal to the principal ideal (g). It is important to note that ,ti�_ irreducible in K[x]. For, in the first place, g is of positive degree since it has theroolli; and if g � h1h2 in K[x1 with 1"' deg(h,) < deg(g) (i � 1,2), then 0 � g( 8) � h1(8)h2(8) implies that either h1 or h2 is in J and so divisible by g, which is impossible. 1.81. Definition. If 8 E F is algebraic over K, ti)en the uniquely de­ termined monic polynomial g E K[x1 generating the ideal J� (/ E K[x1: f( 8) � 0} of K [ x 1 is called the minimal polynomial (or defining polynomial, or irreducible polynomial) of 8 over K. By the degree of 8 over K we mean the degree of g. 1.82. Theorem. If 8 E F is algebraic over K, then its minimal polynomial g over K has the following properties : (i) g is irreducible in K[x]. (ii) For f E K[x1 we have /(8) � 0 if and only if g divides f. (iii) g is the monic polynomial in K [ x 1 of least degree having 8 as a root. Proof Property (i) was already noted and (ii) follows from the definition of g. As to (iii), it suffices to note that any monic polynomial in K[x1 having 8 as a root must be a multiple of g, and so it is either equal tog or its degree is larger than that of g. D We note that both the minimal polynomial and the degree of an algebraic element 8 depend on the field K over which it is considered, so that one must be careful not to speak of the minimal polynomial or the degree of 8 without specifying K, unless the latter is amply clear from the context. If L is an extension field of K, then L may be viewed as a vector space over K. For the elements of L ( �"vectors") form, first of all, an abelian group under addition. Moreover, each "vector" a E L can be multiplied by a "scalar" r E K so that ra is again in L (here ra is simply the 32 Algebraic Foundations product of the field elements r and a of L) and the laws for multiplication by scalars are satisfied : r(a+/3)=ra+rf3, (r+s)a=ra+s a, (rs)a= r(sa), and Ia =a, where r, s E Kanda, {3 E L. 1.83. Definition. Let L be an extension field of K. If L, considered as a vector space over K, is finite-dimensional, then L is called a finite extension of K. The dimension of the vector space L over K is then called the degree of Lover K, in symbols [L: K]. 1.84. Theorem. If L is a finite extension of K and M is a finite extension of L, then M is a finite extension of K with [M: K] = [M: L][L: K]. Proof Pul [M: L]=m, [L: K]=n, and let (a1, ••• ,a,} be a basis of M over L and ( {31, ... , {3,) a basis of L over K. Then every a E M is a linear combination a= y1a1 + · · · + Ymam with Y; E L for l � i .:::;; m, and writing each y, in terms of the basis elements {3j we get a= f:. y,a, = f:. ( t r,j/31) a,= f:. t r,1{3ja, i=l i�l j-\ 1-1,-1 with coefficients ruE K. If we can show that the mn elements Pja,. l � i � m, l � j � n, are linearly independent over K, then we are done. So suppose we have m " L: L: s,Aa,=o i-1 j-1 with coefficients s;1 E K. Then and from the linear independence of the Cl; over L we infer " L s;jf3j = 0 for l � i � m. J-1 But since the {31 are linearly independent over K, we conclude that all s,j are 0. D 1.85. Theorem. Every finite extension of K is algebraic over K. Proof Let L be a finite extension of K and put (L: K] = m. For 0 E L, them+ 1 elements 1, 0, ... ,0"' must then be linearly dependent over K, and so we get a relation a0 + a10 + · · · + amO"' = 0 with a, E Knot all being 0. This just says that 0 is algebraic over K. D 4. Field Extensions 33 For the study of the structure of a simple extension K(O) of K obtained by adjoining an algebraic element, let F be an extension of K and let 0 E F be algebraic over K. It turns out that K( 0) is a finite (and therefore an algebraic) extension of K. 1.86. Theorem. Let 0 E F be algebraic of degree n over K and let g be the minimal polynomial of 0 over K. Then: (i) K(O) is isomorphic to K[xJ!(g). (ii) [K( 0): K] � n and (I, 0, ... , 0"-1) is a basis of K( 0) over K. (iii) Every a E K(O) is algebraic over K and its degree over K is a divisor of n. Proof (i) Consider the mapping T: K[x] � K(O), defined by •(/) � f(O) for f E K[x], which is easily seen to be a ring homomorphism. We have ken�(/ E K[x]: f(O) � 0} �(g) by the definition of the minimal polynomial. Let S be the image of T; that is, S is the set of polynomial expressions in 0 with coefficients in K. Then the homomorphism theorem for rings (see Theorem 1.40) yields that Sis isomorphic to K[x]/(g). But K [ x ]/(g) is a field by Theorems 1.61 and 1.82(i), and so S is a field. Since K r;;Sr;;K(IJ) and OES, it follows from the definition of K(O) that S � K(O), and (i) is thus shown. (ii) Since S � K(O), any given a E K(O) can be written in the form a� f(O) for some f E K[x]. By the .division algorithm, f � qg + r with q,rEK[x] and deg(r)<deg(g)�n. Then a�f(O)�q(O)g(IJ) +r(O)� r(O), and so a is a linear combination of I, 0, ... ,0"-1 with coefficients inK. On the other hand, if a0+a11J+ ··· +a,_10"-1�0 for certain a1EK, then the polynomial h(x)�a0+a1x+ ··· +a,_1x"-1EK[x] has 0 as a root and is thus a multiple of g by Theorem 1.82(ii). Since deg(h) < n � deg(g), this is only possible if h � 0-that is, if all a,� 0. Therefore, the elements I, 0, ... ,0"-1 are linearly independent over K and (ii) follows. (iii) K(O) is a finite extension of K by (ii), and so a E K(O) is algebraic over K by Theorem 1.85. Furthermore, K( a) is a subfield of K( 0 ). If d is the degree of a over K, then (ii) and Theorem 1.84 imply that n � [K(O): K] � [K(O): K(a)][K(a): K] � [K(O): K(a)]d, hence d di­ vides n. D The elements of the simple algebraic extension K(O) of K are therefore polynomial expressions in 0. Any element of K(O) can be uniquely represented in the form a0 + a10 + · · · + a,_10"-1 with a, E K for 0.,;; i.,;; n-1. It should be pointed out that Theorem 1.86 operates under the assumption ,that both K and 0 are embedded in a larger field F. This is necessary �n "order that algebraic expressions involving 0 make sense. We now want to construct a simple algebraic extension ab ova-that is, without 34 Algebraic Foundations reference to a previously given larger field. The clue to this is contained in part (i) of Theorem 1.86. 1.87. Theorem. Let f E K[x] be irreducible over the field K. Then there exists a simple algebraic extension of K with a root off as a defining element. Proof Consider the residue class ring L = K[x]/(f), which is a field by Theorem 1.61. The elements of L are the residue classes [ h] = h + (f) with hE K[x]. For any a E K we can form the residue class [a] determined by the constant polynomial a, and if a,bEK are distinct, then [a]*[b] since f has positive degree. The mapping a>-> [a] gives an isomorphism from K onto a subfield K' of L, so that K' may be identified with K. In other words, we can view L as an extension of K. For every h(x) = a0+a1x+ ··· +a..,x"'EK[x] we have [h]=[a0+a1x+ ··· +a..,x"']= [a0]+[ad[x]+ · ·· +[a..,][x]"'=a0+a1[x]+ · · · +a..,[x]"' by the rules for operating with residue classes and the identification [a1] = a1• Thus, every element of L can be written as a polynomial expression in [x] with coefficients inK. Since any field containing both K and [x] must contain these polynomial expressions, L is a simple extension of K obtained by adjoining [x]. If f(x)=b0+b1x+ ··· +b.x", then /([x])=b0+b1[x] + · · · + b.[x]" = [b0 + b1x + · · · + b.x"] = [f] = [0], so that [x] is a root of f and Lis a simple algebraic extension of K. 0 1.88. Example. As an example of the formal process of root adjunction in Theorem 1.87, consider the prime field F3 and the polynomial f(x)=x2 + x + 2 E IF3[x], which is irreducible over IF3. Let 8 be a "root" off; that is, 8 is the residue class x +(f) in L = F3[x]/(f). The other root off in Lis then 28 +2, since /(28 +2) = (28 +2)2 +(28 +2)+2 = 82 + 8 +2 = 0. By Theorem 1.86(ii), or by the known structure of a residue class field, the simple algebraic extension L = IF3(8) consists of the nine elements 0,1,2,8,8+1,8+2,28,28+1,28+2. The operation tables for L can be constructed as in Example 1.62. 0 We observe that in the above example we may adjoin either the root 8 or the root 28 + 2 of f and we would still obtain the same field. This situation is covered by the following result, which is easily established. 1.89. Theorem. Let a and fJ be two roots of the polynomial f E K [ x] that is irreducible over K. Then K(a) and K({J) are isomorphic under an isomorphism mapping a to fJ and keeping the elements of K fixed. We are now asking for an extension field to which all roots of a given polynomial belong. 1.90. Definition. Let f E K [ x] be of positive degree and F an extension field of K. Then f is said to split in F iff can be written as a product of 4. Field Extensions 35 linear factors in F[x ]-that is, if there exist elements a1, a2, ... ,a" E F such that f(x)�a(x-a1)(x-a2)···(x-a,), where a is the leading coefficient of f. The field F is a spliuing field off over Kif f splits in F and if, moreover, F � K( a1, a2, •.. , a,). It is clear that a splitting field F off over K is in the following sense the smallest field containing all the roots off: no proper subfield ofF that is an extension of K contains all the roots of f. By repeatedly applying the process used in Theorem 1.87, one obtains the first part of the subsequent result. The second part is an extension of Theorem 1.89. 1.91. 1"1u!orem (Existence and Uniqueness of Splitting Field). If K is a field and f any polynomial of positive degree in K[x], then there exists a sp/iuing field off over K. Any two sp/iuing fields off over K are isomorphic under an isomorphism which keeps the elements of K fixed and maps roots off into each other. Since isomorphic fields may be identified, we can speak of the splitting field off over K. It is obtained from K by adjoining finitely many algebraic elements over K, and therefore one can show on the basis of Theorems 1.84 and 1.86(ii) that the splitting field off over K is a finite extension of K. As an illustration of the usefulness of splitting fields, we consider the question of deciding whether a given polynomial has a multiple root (compare with Definition 1.65). 1.92. Definition. Let f E K [ x] be a polynomial of degree n ;;, 2 and suppose that f(x) � a0(x- a1) • • • (x-a,) with a1, ••• ,a, in the splitting field off over K. Then the discriminant D(f) off is defined by D(f)�a�"-2 0 (a,-ay. los;i<}Etn It is obvious fro!)l.tpe defmition of D(f) thatfhas a multiple root if and only if D(f) � 0. Aiih'6ug!l D(f) is defined in terms of elements of an extension of K, it is actually an element of K itself. For small n this can be seen by direct calculation. For instance, if n � 2 and /( x) � ax 2 + bx + c � a(x- a1Xx- a2), then D(f) � a2(a1-a2)2 � a2((a1 + a2)2 -4a1a1) � a2(b2a-2 -4ca-1), hence D( ax'+ bx +c)� b2 -4ac, a well-known expression from the theory of quadratic equations. If n � 3 and f(x) �ax'+ bx2 +ex+ d � a(x-a1)(x-a2Xx-a3), then D(f) � a4(a1-a1)2(a1-a3)3(a2-a3)3, and a more inv.ol�ed computation yields !-''' ''• '1..., D( ax' + bx2 + ex+ d)� b2c2-4b3d-4ac3 -21a2d2 + 18abcd. ( 1.9) 36 Algebraic Foundations In the general case, consider first the polynomial s E K[x1, ••• ,x.] given by s(x,, ... ,x.)�a6•-' n (x,-xj. l<i<j<n Then sis a symmetric polynomial, and by a result in Example 1.74 it can be written as a polynomial expression in the elementary symmetric polynomi­ als o1, ... ,o. -that is, s = h( o1, ... ,o.) for some hE K[x1, ... ,x.]. If f(x) = a0x" + a,x•-l + · · · +a.= a0(x-a1) • • • (x-a.). then the definition of the elementary symmetric polynomials (see again Example 1.74) implies that ok(a1, ... ,a.) � ( -l)•a.a0 1 E K for I .;; k .;; n. Thus, D(/) �s ( a1 , ... ,a.)� h ( o1 ( a1, ... ,a.), ... ,o.( a1 , ... ,a.)) � h(-a1a01 , ... ,( -l}"a.a01} E K. Since D(/) E K, it should be possible to calculate D(f) without having to pass to an extension field of K. This can be done via the notion of resultant. We note first that if a polynomial f E K[x] is given in the form f(x) � a0x" + a,x•-l + · · · +a. and we accept the possibility that a0 � 0, then n need not be the degree of f. We speak of n as the formal degree off; it is always greater than or equal to deg(/ ). 1.93. Definition. Let f(x) = a0x" + a,x•-l + · · · +a. E K[x] and g(x) = b0xm + b1xm-l + · · · + bm E K[x] be two polynomials of formal degree n resp. m with n, m EN. Then the resultant R(f, g) of the two polynomials is defined by the determinant ao a, a. 0 0 )·-0 ao a, a. 0 0 R(/,g)� 0 0 ao a, a. ho b, bm 0 0 ) "'�' 0 ho b, bm 0 0 0 ho b, bm of order m + n. If deg(f) � n (i.e., if a0 "'0) and /(x) � a0(x-a1) • • • (x-a.) in the splitting field off over K, then R(f, g) is also given by the formula • R(!, g)� a;;' 0 g(a,). ( 1.10) i-1 In this case, we obviously have R(f, g)� 0 if and only if f and g have a common root, which is the same as saying that f and g have a common divisor in K[x] of positive degree. Exercises 37 Theorem 1.68 suggests a connection between the discriminant D( f) and the resultant R(f,/'). Let f E K[x] with deg(/) � n;;, 2 and leading coefficient a0. Then we have, in fact, the identity (1.11) where f' is viewed as a polynomial of formal degree n -l. The last remark is needed since we may have deg( /') < n -I and even f' � 0 in case K has prime character istic. At any rate, the identity ( 1.11) shows that we can obtain D(f) by calculating a determinant of order 2n-I with entries inK. EXERCISES l.l. Prove that the identity element of a group is uniquely determined. 1.2. For a multiplicative group G, prove that a nonempty subset H of G is a subgroup of G if and only if a, bE H implies ab-1 E H. If His finite, then the condition can be replaced by: a, bE H implies abE H. 1.3. Let a be an element of finite order k in the multiplicative group G. Show that formE l we have am� e if and only if k divides m. 1.4. FormE I'll, Euler's function .p(m) is defined to be the number of integers k with ! ,..k ,.. m and.gcd(k,m)�l. Show the following properties form, n, s E I'll and a prime p: (a) 4>(p') � p'( 1-il (b) .P(mn) � .p(m)<j>(n) if gcd(m, n) �I; (c) .P(m)�m(l-;J ··(l-;,). where m�pf'···p;• is the prime factor decomposition of m. 1.5. Calculate 4>(490) and 4>(768). 1.6. Use the class equation to show the following: if the order of a finite group is a prime power p', p prime, s;;, I, then the order of its center is divisible by p. 1.7. Prove that in a ring R we have (-a)(-b)� ab for all a, bE R. 1.8. Prove that in a commutative ring R the formula holds for all a, bE R and n E I'll. (Binomial Theorem ) 1.9. Let p be a prime number in Z. For all integers a not divisible by p, show that p divides a p-I-I. (Fermat's Little Theorem) 1.10. Prove that for any prime p we have (p-I)!= -I mod p. (Wilson's Theorem) 38 Algebraic Foundations 1.11. Prove: if pis a prime, we have ( p 71) = ( -l)imod p for 0 "j" p-l,jEZ. 1.12. A conjecture of Fermat stated that for all n;. 0 the integer 22" + 1 is a prime. Euler found to the contrary that 641 divides 232 + 1. Confirm this by using congruences. 1.13. Prove: if m1, ... ,mk are positive integers that are pairwise relatively prime-that is, gcd(m,, m) � 1 for 1 "i < j" k -then for any in­ tegers a1, ••• ,ak the system of congruences y = a,.mod m,., i = I, 2, ... , k, has a simultaneous solution y that is uniquely determined modulo m � m1 • • • m,. (Chinese Remainder Theorem) 1.14. Solve the system of congruences 5x = 20mod6, 6x = 6mod5, 4x = 5mod77. 1.15. For a commutative ring R of prime characteristic p, show that (a+ ... +a)'" �a'"+··· +a'" I .f I s for all a1, ... ,a, E Rand n E 1\1. 1.16. Deduce from Exercise 1.11 that in a commutative ring R of prime characteristic p we have p -l (a-b)'-'� L a1bp-l-J foralla,bER. j=O 1.17. Let F be a field and f E F[x]. Prove that (g(/(x)) : g E F[x]) is equal to F [ x] if and only if deg(/) � l. 1.18. Show that p2( x)-xq2( x) � xr2(x) for p, q, r E IRI[x] implies p � q � r � 0. 1.19. Show that if/, g E F[x], then the principal ideal(/) is contained in the principal ideal (g) if and only if g divides f. 1.20. Prove: if/, g E F [ x] are relatively prime and not both constant, then there exist a, bE F[x] such that a/+ bg � 1 and deg(a) < deg(g), deg( b) < deg( /). 1.21. Let /1, ... ,/.EF[x] with gcd(/1, ... ,/,,)�d, so that f.�dg1 with g, E F[x] for 1 "i" n. Prove that g1, ••• ,g. are relatively prime. 1.22. Prove that gcd(/1, ... J.) � gcd(gcd(/ 1, ... J._, )./.) for n ;. 3. 1.23. Prove: if/, g, hE F[x], f divides gh, and gcd(/, g)� 1, then f di­ vides h. 1.24. Use the Euclidean algorithm to comp11te gcd(/, g) for the polynomi­ als f and g with coefficients in the indicated field F: (a) F� Q, f(x) � x7 +2x' +2x2- x +2, g(x) � x' -2x'- x4 + x2+2x+3 (b) F� 'f2,f(x) � x7 + 1, g(x) � x' + x3 + x + 1 (c) F�'f2,f(x)�x'+x+l,g(x)�x'+x'+x4+1 (d) F� 'f3, f(x) � x8 +2x' + x3 + x2 + 1, g(x) � 2x6 + x' +2x3 +2x2 +2 Exercises 39 1.25. Let /1, ••• ,/,, be nonzero polynomials in F[x]. By considering the intersection (/1)n · · · n(/.) of principal ideals, prove the existence and uniqueness of the monic polynomial mE F[x] with the proper­ ties attributed to the least common multiple of /1, ••• .f •. 1.26. Prove ( 1.6). 1.27. If f1, ••• ,f. E F[x] are nonzero polynomials that are pairwise rela­ tively prime, show that lcm(/1, ••• ./.)�a-1/1•• ·f ., where a is the leading coefficient of /1 • • ·f •. 1.28. Prove that !em(/,. ... .f.) � lcm(lcm( /1, •••• f.,_ 1 ), f.,) for n ;;, 3. 1.29. Let f1, ••• ,f. E F[x] be nonzero polynomials. Write the canonical factorization of each/;. 1 � i � n, in the form t,. = a;nPe,.(p). where a, E F, the product is extended over all monic irreducible polynomials pin F[x], thee,( p) are nonnegative integers, and for each i we have e,( p) > 0 for only finitely many p. For each p set m(p)� min(e1(p), ... ,e.(p)) and M(p) � max(e1(p), ... ,e.(p)). Prove that gcd(f, .... ,f.) � nprnJp). lcm(j,, ... ,/,,) � npM(p). 1.30. Kronecker's method for finding .divisors of degree "s of a noncon­ stant polynomial / E O[x] proceeds as follows: (l) By multiplying f by a constant, we can assume f E Z[x]. (2) Choose distinct elements a0, ... ,a, E Z that are not roots of f and determine all divisors of f( a,) for each i,O" i" s. (3) For each (s +I)-tuple (b0, .•. .b,) with b1 dividing f(a,) for O .. i .. s, determine the polynomial gEO[x] with deg(g)"s and g( a,)� b1 for 0 "i "s (for instance, by the Lagrange interpolation formula). (4) Decide which of these polynomials g in (3) are divisors of f. If deg(/) � n;;. I and s is taken to be the greatest integer "n/2, then f is irreducible in Q[x] in case the method only yields constant polynomials as divisors. Otherwise, Kronecker's method yields a nontrivial factorization. By applying the method again to the factors and repeating the process, one eventually gets the canonical factoriz­ ation of f. Use this procedure to find the canonical factorization of f(x) �tx' -1x' +2x4-x3 +5x2-'fx -1 E O[x]. 1.31. Construct the addition and multiplication table for F2[x]/ (x3 + x2 + x). Determine whether or not this ring is a field. 1.32. Let [x +I] be the residue class of x +I in IF2[x]/(x4 + 1). Find the residue classes comprising the principal ideal ([x + 1]) in F2[x]/ I ,_4 I 1 \ 40 Algebraic Foundations 1.33. Let F be a field and a, b, g E F[x] with g"' 0. Prove that the congruence af = bmod g has a solution f E F[x] if and only if gcd( a, g) divides b. 1.34. Solve the congruence (x2 + 1)/(x)= 1 mod(x3 + 1) in �,[x], if poss­ ible. 1.35. Solve (x4+x3+x2 +1)/(x)=(x2+l)mod(x3+1) in �1[x], if possible. 1.36. Prove that R[x]/(x4 + x' + x + 1) cannot be a field, no matter what the commutative ring R with identity is. 1.37. Prove: given a field F, nonzero polynomials /1, ... ,fk E F[x]that are pairwise relatively prime, and arbitrary polynomials g1, ... ,gk E F[x ], then the simultaneous congruences h = g, mod/,, i � 1, 2, ... , k, have a unique solution hE F[x] modulo f � /1 • • • fk· (Chinese Remainder Theorem for F[x]) 1.38. Evaluate/(3) for f(x) � x214 + 3x152 + 2x47 + 2 E IF5[x]. 1.39. Let p be a prime and a0, ... ,a, integers with p not dividing a,. Show that a0 + a1y + · · · + G11J11 = 0 mod p has at most n different solu­ tions y modulo p. 1.40. If p > 2 is a prime, show that there are exactly two elements a E IF, such that a'� I. 1.41. Show: if/ E Z[x] and/(0)= /(1) = 1 mod2, thenfhas no roots in Z. 1.42. Let p be a prime and f E Z[x]. Show: /(a)= Omod p holds for all a E Z if and only if/( x) � (x' -x )g(x )+ph( x) with g. h E Z[x ]. 1.43. Let p be a prime integer and c an element of the field F. Show that xP -c is irreducible over F if and only if xl'-c has no root in F. 1.44. Show that for a polynomial/ E F[x] of positive degree the following conditions are equivalent: (a) f is irreducible over F; (b) the principal ideal(/) of F[x] is a maximal ideal; (c) the principal ideal(/) of F[x] is a prime ideal. 1.45. Show the following properties of the derivative for polynomials in F[x]: (a) (/, + · · · + fm)'� /{+ · · · + f�; (b) (/g)'� f'g + fg'; m (c) (/,···/"')'� L/1 ·· ·J,_J(J,+l .. ·fm· i-1 1.46. For f E F[ x] and F of characteristic 0, prove that f' � 0 if and only iff is a constant polynomial. IfF has prime characteristic p, prove that/'� 0 if and only if /(x) � g(x') for some g E F[x]. 1.47. Prove Theorem 1.68. 1.48. Prove that the nonzero polynomial f E F[x] has a multiple root (in some extension field of F) if and only iff and/' are not relatively prime. 1.49. Use the criterion in the previous exercise to determine whether the Exercises following polynomials have a multiple root: (a) f(x)�x4-5x3+6x2+4x-8EO[x] (b) f(x)�x6+x'+x4+x3+1EF2[x] 41 1.50. The nth derivative /'"' of/ E F[x] is defined recursively as follows: I f'0'�f.f'"'�(f'"-")' forn;.l. Prove that forf,gEF[x] we have (/g)'"'� t (�)f"'-"g'''. '-o 1.51. Let F be a field and k a positive integer such that k < p in case F has prime chara cteristic p. Prove: bE F is a root off E F(x] of multipl­ icity kif and only if I'"( b)� 0 for 0.; i.; k-I and jlk1( b)* 0. 1.52. Show that the Lagrange interpolation formula can also be written in the form " f(x)� t b,(g'(a,))_, g(x) i=O x-a; withg(x) � n (x-a.). k-0 1.53. Determine a polynomial f E F,(x] with /(0) � /(1) � /(4) �I and /(2) � /(3) � 3. 1.54. Determine a polynomial f E Q(x] of degree .; 3 such that /(- I)� -1./(0) � 3./(1) � 3, and /(2) � 5. 1.55. Express s5(x1, x2, x3, x4) = xf +xi+ xj + x� E IF3[x1, x2, x3, x4J in terms of the elementary symmetric polynomials o,, o2, o3, o4• 1.56. Prove that a subset K of a field F is a su"bfield if and only if the following conditions are satisfied: (a) K contains at least two elements; (b) ifa,bEK, thena-b EK; (c) if a, bE K and b * 0, then ab-' E K. · 1.57. Prove that an extension L of the field K is a finite extension if and only if L can be obtained from K by adjoining finitely many algebraic elements over K. 1.58. Prove: if 8 is algebraic over L and L is an algebraic extension of K, then 8 is algebraic over K. Thus show that if F is an algebraic extension of L, then F is an algebraic extension of K. 1.59. Prove: if the degree (L: K] is a prime, then the only fields F with K C:: F C:: L are F� K and F� L. 1.60. Construct the operation tables for the field L � IF3( 8) in Example 1.88. 1.61. Show that f(x) � x4 + x +IE F2[x] is irreducible over IF2. Then construct the operation tables for the simple extension F2(8), where 8 is a root of f. 1.62. Calculate the discriminant D(f) and decide whether or not f has a multiple root: (a) f(x)�2x3-3x2+x+lEO[x] 42 Algebraic Foundations (b) l(x) = 2x4 + x3 + x2 +2x +2 E IF3[x] 1.63. Deduce ( 1.9) from (I. II). 1.64. Prove that 1. g E K[x] have a common root (in some extension field of K) if and only if I and g have a common divisor in K [ x] of positive degree. 1.65. Determine the common roots of the polynomials x7-2x4-x3 + 2 and x5-3x4-x + 3 in O[x]. 1.66. Prove: if I and g are as in Definition 1.93, then R(/, g)= ( -l)m"R(g, /). 1.67. Let l,gEK[x] be of positive degree and suppose that l(x)= a0(x-a1)···(x-a.,), a0*0, and g(x)=b0(x-{31)···(x-/3m), b0 * 0, in the splitting field of lg over K. Prove that m " m where n and m are also taken as the formal degrees of I and g. respectively. 1.68. Calculate the resultant R(/, g) of the two given polynomials I and g (with the formal degree equal to the degree) and decide whether or not I and g have a common root: (a) l(x)=x3+x+l,g(x)=2x5+x2+2EIF3[x] (b) l(x) = x4 + x3 +I, g(x) = x4 + x2 + x +IE IF2[x] 1.69. For IE K[x1, ••• ,x.,], n;;. 2. an n-tuple (a1, ••• ,a.,) of elements a, belonging to some extension L of K may be called a zero of I if l(a1 •••• ,a.,)=O. Now let l.gEK[x1, ••• ,x.,] with x., actually ap­ pearing in I and g. Then I and g can be regarded as polynomials /(x,) and g(x.,) in K[x1, ••• ,x.,_,][x.,] of positive degree. Their resultant with respect to x., (with formal degree= degree) is R(j, g) = R x (/,g), which is a polynomial in x1, ••• ,x.,_1• Show that I and g have a common zero (aJ····•a n-l•an) if and only if (al•···•an-1) is a zero of R(/. g). 1.70. Using the result of the previous exercise, determine the common zeros of the polynomials l(x, y) = x(y2-x)2 + y5 and g(x, y) = y4 + y3-x2 in O[x, y]. Chapter 2 Structure of Finite Fields This chapter is of central importance since it contains various fundamental properties of finite fields and a description of methods for constructing finite fields. The field of integers modulo a prime number is, of course, the most familiar example of a finite field, but many of its properties extend to arbitrary finite fields. The characterization of finite fields (see Section 1) shows that every finite field is of prime-power order and that. conversely, for every prime power there exists a finite field whose number of elements is exactly that prime power. Furthermore, finite fields with the same number of elements are isomorphic and may therefore be identified. The next two sections provide information on roots of irreducible polynomials, leading to an interpretation of finite fields as splitting fields of irreducible polynomi­ als. and on traces, norms, and bases relative to field extensions. Section 4 treats roots of unity from the viewpoint of general field theory. which will be needed occasionally in Section 6 as well as in Chapter 5. Section 5 presents different ways of representing the elements of a finite field. In Section 6 we give two proofs of the famous theorem of Wedderburn according to which every finite division ring is a field. Many discussions in this chapter will be followed up. continued, and partly generalized in later chapters. 44 Structure of Finite Fields 1. CHARACTERIZATION OF FINITE FIELDS In the previous chapter we have already encountered a basic class of finite fields-that is, of fields with finitely many elements. For every prime p the residue class ring Z/( p) forms a finite field with p elements (see Theorem 1.38), which may be identified with the Galois field F, of order p (see Definition 1.41). The fields IF, play an important role in general field theory since every field of characteristic p must contain an isomorphic copy of IFP by Theorem 1.78 and can thus be thought of as an extension of IF,. This observation, together with the fact that every finite field has prime char­ acteristic (see Corollary 1.45), is fundamental for the classification of finite fields. We first establish a simple necessary condition on the number of elements of a finite field. 2.1. Lemma. Let F be a finite field containing a su/5field K with q elements. Then F has q"' elements, where m = [F: K]. Proof F is a vector space over K, and since F is finite, it is finite-dimensional as a vector space over K. If [F: K] = m, then F has a basis over K consisting of m elements, say b1, b2, ... ,bm. Thus every element ofF can be uniquely represented in the form a1b1+a2b2+ ··· +a.,b.,, where a1, a2, ... ,am E K. Since each a; can have q values, F has exactly qm elements. D 2.2. Theorem. Let F be a finite field. Then F hasp" elements, where the prime p is the characteristic of F and n is the degree of F over its prime subfield. Proof Since F is finite, its characteristic is a prime p according to Corollary 1.45. Therefore the prime sub field K ofF is isomorphic to F P by Theorem 1.78 and thus contains p elements. The rest follows from Lemma 2.1. 0 Starting from the prime fields F,. we can construct other finite fields by the process of root adjunction described in Chapter I, Section 4. If f E F ,[x] is an irreducible polynomial over IF, of degree n, then by adjoining a root of/to F, we get a finite field withp" elements. However, at this stage it is not clear whether for every positive integer n there exists an irreducible polynomial in F,[x] of degree n. In order to establish that for every primep and every n E 1\1 there is a finite field with p" elements, we use an approach suggested by the following results. 2.3. Lemma. IfF is a finite field with q elements, then every a E F satisfies a"= a. Proof The identity a• =a is trivial for a= 0. On the other hand, the nonzero elements ofF form a group of order q -I under multiplication. 1. Characterization of Finite Fields 45 Thus a•-1 �I for all a E F with a* 0. and multiplication by a yields the desired result. 0 2.4. Lemma. IfF is a finite field with q elements and K is a subfield ofF, then the polynomial x'-x in K[x] factors in F[x] as x•-x� n (x-a) n E F and F is a splitting field of x'-x over K. Proof The polynomial x'-x of degree q has at most q roots in F. By Lemma 2.3 we know q such roots-namely. all the elements of F. Thus the given polynomial splits in Fin the indicated manner, and it cannot split in any smaller field. 0 We are now able to prove the main characterization theorem for finite fields, the leading idea being contained in Lemma 2.4. 2.5. Theorem (Existence and Uniqueness of Finite Fields). For every prime p and every positive integer n there exists a finite field with v" 1 . 7,1<c-�tc...,/� elements. Any finite field with q = p" elements is isomorphic to the splitting field of x•-x over IF r· Proof (Existence) For q � p" consider x•-x in FP[x], and let F be its splitting field over FP. This polynomial has q distinct roots in F since its derivative is qxq-l -1 =-I in IFP[xJ and so can have no common root with x•-x (compare with Theorem 1.68). Let.S �{a E F: a•-a� 0). Then S is a subfield of F since: (i) S contains 0 and I; (ii) a, bE S implies by Theorem 1.46 that (a-b)'� a•-b' �a-b, and so a-bE S; (iii) for a, bE Sand b * 0 we have (ab-1 )' � a•b-• = aV 1, and so ah 1 E S. But, on the other hand, xq·_ x must split inS since S contains all its roots. Thus F � S, and since S has q elements, F is a finite field with q elements. (Uniqueness) Let Fbe a finite field with q � p" elements. Then F has characteristic p by Theorem 2.2 and so contains !' P as a subfie!d. It follows from Lemma 2.4 that F is a splitting field of x'-x over IFr. Thus the desired result is a consequence of the uniqueness (up to isomorphisms) of splitting fields, which was noted in Theorem 1.91. 0 The uniqueness part of Theorem 2.5 provides the justification for speaking of the finite field (or the Galois field) with q elements, or of the finite field (or the Galois field) of order q. We shall denote this field by IF,. where it is of course understood that q is a power of the prime characteristic p of IF,. The notation GF(q) is also used by many authors. 2.6. Theorem (Subfield Criterion). Let IF, be the finite field with q = p" elements. Then every subfield ofF q has order pm, where m is a positive divisor of n. Conversely, if m is a positive divisor of n. then there is exactly one subfield of IF, with pm elements. 46 Structure of Finite Fields Proof It is clear that a sub field K of IF, has order p"' for some positive integer m � n. Lemma 2.1 shows that q = p11 must be a power of p"'. and so m is necessarily a divisor of n. Conversely, if m is a positive divisor of n, then p"'-I divides p"-I, and soxP"'-1-1 divides xp"-1-1 in f,[x]. Consequently, xP"'-x divides xP"-x=xq-x in IFI'[x]. Thus, every root of xP�'-x is a root of xq-x and so belongs to IF,. It follows that F, must contain as a subfield a splitting field of xP"-x over IF,, and as we have seen in the proof of Theorem 2.5, such a splitting field has order p"'. If there were two distinct subfields of order p"' in IF q' they would together contain more than p"' roots of xP"'-x in IF q• an obvious contradiction. 0 The proof of Theorem 2.6 shows that the unique subfield of IF,. of order pm, where m is a positive divisor of n, consists precisely of the roots of the polynomial xP"-x E IF,[x] in F, •. 2.7. Example. The subfields of the finite field IF2, can be determined by listing all positive divisors of 30. The containment relations between these various subfields are displayed in the following diagram. "'"' /1� IF26 IF21o IF21� IXtXI IF22 IF2J F2s �1/ F, By Theorem 2.6, the containment relations are equivalent to divisibility relations among the positive divisors of 30. 0 For a finite field IF, we denote by· IF; the multiplicative group of nonzero elements ofF,. The following result enunciates a useful property of this group. 2.8. Theorem. For every finite field IF, the multiplicative group F; of nonzero elements of IF q is cyclic. Proof We may assume q > 3. Let h � p;'P2' · · · p;,• be the prime factor decomposition of the order h � q-I of the group F;. For every i, I.,;; i.,;; m, the polynomial x•IP, -I has at most h/p1 roots in IF,. Since h/p, < h, it follows that there are nonzero elements in IF, that are not roots of this polynomial. Let a, be such an element and set b1 � a�IP>'. We have bl�j = I, hence the order of h;. is a divisor of p;• and is therefore of the form p:·,. with 0 � s; � r;. On the other hand, bP�,-� = ah/p,. * 1 ' ' ' and so the order of b1 is p;•. We claim that the element b � b 1 b2 • · · bm has order h. Suppose, on the contrary, that the order of b is a proper divisor of h 2. Roots of Irreducible Polynomials 47 and is therefore a divisor of at least one of the m integers h 1 p1, I"' i"' m, say of hjp1• Then we have 1 = b11/P1 = b71Pib;IPI ... b!IP1. Now if 2 "'i"' m, then Pr' divides h/pp and hence bt/p, �I. Therefore b;;,, �I. This implies that the order of b1 must divide h/pp which is impossible since the order of b1 is Pt'· Thus, f; is a cyclic group with generator b. 0 2.9. Definition. A generator of the cyclic group F: is called a primitive element of F •. It follows from Theorem 1.15(v) that F• contains <t>(q -I) primitive elements, where <P is Euler's function. The existence of primitive elements can be used to show a result that implies, in particular, that every finite field can be thought of as a simple algebraic extension of its prime subfield. 210. Theorem. Let IF• be a finite field and IF, a finite extension field. Then F, is a simple algebraic extension ofF • and every primitive element ofF, can serve as a defining element ofF, over IFq. Proof Let I be a primitive element of IF,. We clearly have IF.(O � F,. On the other hand, F .(1) contains 0 and all powers of L and so all elements ofF,. Therefore IF, � IF.(I). I 0 211. Corollory. For every finite field IF • �nd every positive integer n there exists an irreducible polynomial in IF.[x] of degree n. Proof Let F, be the extension field of F• of order q•, so that [F,: F•] � n. By Theorem 2.10 we have IF,� F.(O for some IE IF,. Then the minimal polynomial of I over IF• is an irreducible polynomial in F.[x] of degree n, according to Theorems 1.82(i) and 1.86(ii). 0 2. ROOTS OF IRREDUCIBLE POLYNOMIALS In this section we collect some information about the set of roots of an irreducible polynomial over a finite field. 2.12 Lemma. Let f E F.[x] be an irreducible polynomial over a finite field F • and let a be a root off in an extension field of F •. Then for a polynomial h E F.[x] we have h (a)= 0 if and only iff divides h. Proof Let a be the leading coefficient off and set g(x) � a-1f(x). Then g is a monic irreducible polynomial in IF.[x] with g(a) � 0 and so it is the minimal polynomial of a over F • in the sense of Defirtition 1.81. The rest follows from Theorem 1.82(ii). 0 48 Structure of Finite Fields 2.13. Lemmt1. Let 1 E IF .[x 1 be an irreducible polynomial over IF • o{ degree m. Then {(x) divides x•"-xi{ and only i{ m divides n. Proof Suppose {(x) divides x•"-x. Let a be a root of 1 in the splitting field of 1 over IF •. Then a•" �a, so that a E F /_It follows that F.(a) is a subfield of IF ••. But since [Fq(a):IF.1,;;m and [IF •• :F.1�n, Theorem 1.84 shows that m divides n. Conversely, if m divides n, then Theorem 2.6 implies that f •" contains f •• as a subfield. If a is a root of 1 in the splitting field of 1 over IF •. then [F.(a):IF.1�m, and so IFq(a)�F •• _ Consequently, we have aEF •• , hence a•" � a, and thus a is a root of x•"-x E F •[ x 1-We infer then from Lemma 2.12 that{(x) divides x•"-x. 0 � Theorem. /{{is an irreducible polynomial in IF•[x1 o{ degree m. then {has a roat a in F.·-Furthermore, all the roots o{{ are simple and are -b h d- -I • •' ··-' {IF gwen � I e m lstmct e ements a, a , a , ... , a o q"'· Proof Let a be a root of {in the splitting field of 1 over IF.-Then [IF.(a):F.1�m, hence F•(a)�F •• , and in particular aEF •• _ Next we show that if {3 E IF q"' is a root of{, then {3 q is also a root of{-Write { ( x) � amxm + ... + alx +Do with a; E IF q for 0 � i � m. Then, using Lemma 2.3 and Theorem 1.46, we get 1({3•) � amf3qm + '" + a,f3• + ao � a'!.,{3qm + '" + arf3• + ag � (amr +---+ a,/3 + a0)• � 1(/3)• � 0_ l m-1 Therefore, the elements a, aq, aq , ... , aq are roots of f. It remains to prove that these elements are distinct. Suppose, on the contrary, that aq' = aq� for some integers j and k with 0 � j < k � m-1. By raising this identity to the power qm--k, we get It follows then from Lemma 2_12 that {(x) divides x•"-'''-x. By Lemma 2.13, this is only possible if m divides m- k + J-But we have 0 < m-k + j < m, and so we arrive at a contradiction. D 2.15. Corolklry. Let 1 be an irreducible polynomial in f•[x1 o{ degree m_ Then the splitting field o{{ over F • is given by F.·- �ro�f Th:.?!�ITl_ 2. 14 �ows that 1 splits in F... Furthermore, IF.(a,a ,a , .. ,,a )-F.(a)-F •• for a root a of { m F ••• where the second identity is taken from the proof of Theorem 2. 14. 0 216. Corolklry. Any two irreducible polynomials in IF •[x 1 o{ the same degree have isomorphic splitting fields. 2. Roots of Irreducible Polynomials 49 We introduce a convenient terminology for the elements appearing in Theorem 2.14, regardless of whether a E IF •• is a root of an irreducible polynomial in IF•[x] of degree m or not. 2.)7. Definition. Let IF •• be an extension of !' • and let a E IF ••. Then the elements a, aq. aq1. aq,.,_, are_calkd_tij�jugOies of a wjth respect to IF'q The conjugates of a E F •• with respect to IF• are distinct if and only if the minimal polynomial of a over F • has degree m. Otherwise, the degree d of this minimal polynomial is a proper divisor of m, and then the conjugates of a with respect to Fq are the distinct elements a,aq, ... ,aqd_,, each repeated m j d times. 218. Theorem. The conjugates of a E IF; with respect to any sub­ field of F q have the .same order ft. the group F;. Proof Since IF; is a cyclic group by Theorem 2.8, the result follows from Theorem l.l5(ii) and the fact that every power of the characteristic of F • is relatively prime to the order q -1 of F;. 0 2.19. Corollary. If a is a primitive element of IF •• then so are all its conjugate s with respect to any sub field of IF q· 2.20. Example. Let a E IF 16 be a root of f(x) = x4 + x + 1 E IF2[x]. Then the conjugates of a with respect to F2 are a, a2, a4 ;e a+ 1, and a8 = a2 + 1, each of them being a primitive element of F 16• The conjugates of a with respect to F 4 are a and a4 = a+ l. 0 There is an intimate relationship between conjugate elements and certain automorphisms of a finite field. Let F •• be an extension of IF •. By an automorphism a of IF •• over F q we mean an automorphism of F •• that fixes the elements of F •. Thus, in detail, we require that a be a one-to-one mapping from F •• onto itself with a(a+,B)=a(a)+a(,B) and a(a,B)= a(a)a(,B) for all a,,B E IF •• and a(a) =a for_�lE�J: •. 211- Theorem. The distinct automorphisms of IF q• over F q are exactly the mappings "o•"I>"""•"m-l• defined by a/a)=a•1 for a ElF •• and O.;j.;m-1. Proof For each a1 and all a,,B E F •• we obviously have a1(a,8)= a1(a)a/.B)-and also a1(a+ ,8)= a/a)+a1(,B) because of Theorem 1.46, so that a1 is an endomorphism of F ••. Furthermore, "/a) = 0 if and only if a:= 0, and so ai is one-to-one. Since IF q'" is a finite set, a1 is an epimorphism and therefore an automorphism of F ••. Moreover, we have a1(a) =a for all a E IF • by Lemma 2.3, and so each a1 is an automorphism of F •• over F •. so Structure of Finite Fields The mappings a0, a1, ••• , am-1 are distinct since they attain distinct values for a primitive element of IF,.. . Now suppose that a is an arbitrary automorphism of IF q"' over IF,. Let {J be a primitive element of IF,. and letl(x)=x"'+a.,_1x"'-1+ ··· + a0 E F ,[x 1 be its minimal polynomial over F ,. Then 0=CJ(fl"'+a.,_1{J"'-1+ · ·· +a0) =a(fl)"'+a.,_1CJ((J)"'-1+ · ·· +a0, so that <1({J) is a root of I in IF, •. It follows from Theorem 2.14 that <1( {J) = (J<' for some j, 0 "j" m-I. Since " is a homomorph ism, we get then <1( a)= a•' for all a E F ,.. 0 On the basis of Theorem 2.21 it is evident that the conjugates of a E IF,. with respect to F • are obtained by applying all automorphisms of IF•"' over F, to the element a. Til<: _au_IO_II19.!11..hism�()f_.f,.,_over F, form a gr_o_u_p�i!.IUhe..nperation-being. the...usual _.c.ompnsitinn.__oi.!!lajlpi�gs. The information provided in Theorem 2.21 shows that this group of auiomor­ phisms ofF,. over _F0_is)cycl[�_groupoforder m-ge-neratOd by a!" 3. TRACES, NORMS, AND BASES In this section we adopt again the viewpoint of regarding a finite extension F=F,. of the finite field K=F, as a vector space over K (compare with Chapter I, Section 4). Then F has dimension mover K, and if {a1, ... ,a.,} is a basis of F over K, each element a E F can be uniquely represented in the form a=c1a1+ ··· +cmam withc;EK for l�j�m. We introduce an important mapping from F to K which will turn out to be linear. 2.22. Definition. For QE F=F,. and K=IF,, the trace TrF;K(a) of a over K is defined by TrF;K(a) =a+ a•+ · · · + "'.·-• If K is the prime subfield of F, then TrF;K(a) is called the absolute trace of "' and simply denoted by Tr F( a). In other words, the trace of a over K is the sum of the conjugates of a with respect to K. Still another description of the trace may be obtained as follows. Let IE K [x 1 be the minimal polynomial of a over K; its degree dis a divisor of m. Then g(x} = l(x)mld E K[x1 is called the characteristic polynomial of a over K. By Theorem 2.14, the roots of I in F are given by 3. Traces, Norms. and Bases 51 a, a•, ... ,a•'-', and then a remark following Definition 2.17 implies that the roots of g in F are precisely the conjugates of a with respect to K. Hence g(x) � xm + am_,xm-l +-.Y·. + ao � (x-a)(x-a•) ... (x-ar'), (2.1) • and a comparison of coefficients shows that TrF/K(a) �-am-I· (2.2) In particular, TrF;K(a) is always an element of K. 2.23. Theorem. Let K � 'f q and F �IF q"· Then the trace function Tr F/K satisfies the following properties: (i) TrF/K(a + fJ) � TrF;K(a)+ TrF;K(fJ) for all a, fJ E F; (ii) TrF1K(ca)�cTrF/K(a)forallcEK, aEF; (iii) TrF/K is a linear transform ation from F onto K, where both F and K are viewed as vector spaces over K; (iv) TrF;K(a) � mo for all a E K; (v) TrF;K( a•) � TrF/K( a) for all a E F. Proof (i) For a, fJ E F we use Theorem 1.46 to get TrF;K(a+fJ)�a+fJ+(a+fJ) •+ ··· +(a+fJ) • --' �a+fJ+a•+fJ•+ : ·· +a•"-'+p• ·-• � TrF1K(a)+TrF1K(fJ). (ii) ForcE K we have c•' � c for all};;. 0 by Lemma 2.3. Therefore we obtain for a E F, TrF;K(ca)�ca+c•a• + ··· +c•"-'a•·-• = ca + caq + · · · + caq"'-1 � cTrF;K(a). (iii) The properties (i) and (ii), together with the fact that TrF/K(a) E K for all a E F, show that TrF/K is a linear transformation from F into K. To prove that this mapping is onto, it suffices then to show the existence of an a E Fwith TrF;K(a) "'0. Now TrF;K(a)�O if and only if a is a root of the polynomial x•"-'+ ··· +x•+xEK[x] in F. But since this polynomial can have at most qm-l roots in F and F has qm elements, we are done. (iv) This follows immediately from the definition of the trace function and Lemma 2.3. (v) For a E F we have a•" �a by Lemma 2.3, and so TrF;K(a•) � a•+a•'+ ·· · +a•"�TrF;K(a). 0 52 Structure of Finite Fields The trace function TrF/K is not only in itself a linear transformation from F onto K, but serves for a description of all linear transformations from F into K (or, in an equivalent terminology, of all linear functionals on F) that has the advantage of being independent of a chosen basis. 2.24. Theorem. Let F be a finite extension of the finite field K, both considered as vector spaces over K. Then the linear transformations from F into K are exactly the mappings Lp. fl E F, where Lp( a)� TrF/K(fla) for all a E F. Furthermore, we have Lp � L'l whenever f3 andy are distinct elements of F. Proof Each mapping Lp is a linear transformation from F into K by Theorem 2.23(iii). For fl, y E F with fl "'y, we have Lp(a)-Ly(a) � TrF;K(fla)-Tr F/K(ya)�Tr F/K((fl-y)a)"'O for suitable aEF since TrF/K maps F onto K, and so the mappings Lp and L, are different. If K � F• and F� IFq"'• then the mappings Lp yield qm different linear transfor­ mations from F into K. On the other hand, every linear transformation from F into K can be obtained by assigning arbitrary elements of K to the m elements of a given basis ofF over K. Since this can be done in qm different ways, the mappings Lp already exhaust all possible linear transformati ons �F�� D 2.25. Theorem. Let F be a finite extension of K �F •. Then for a E F we have TrF/K(a) � 0 if and only if a� fl•-fl for some fl E F. Proof The sufficiency of the condition is obvious by Theorem 2.23(v). To prove the necessity, suppose a E F� F q" with Tr F/K( a)� 0 and let fl be a root of x• - x -a in some extension field of F. Then fl • -fl � a and so that fl E F. � (fl•-fl)+(fl•-fl)q+ ... +(fl•-fl)··-· � (fl•-Ill+ (fJ•'-fl•)+ " + (fJ•"-{J··-·) �fl•"-fl, D In case a chain of extension fields is considered, the composition of trace functions proceeds according to a very simple rule. 226. Theorem (Transitivity of Trace). Let K be a finite field, let F be a finite extension of K and E a finite extension of F. Then Tr E/K (a) � TrF/K (Tr£1F( a)) for all a E E. 3_ Traces. Norms, and Bases 53 Proof LetK�F,, let[F:K]�mand [E:F]�n,sothat[E:K]� mn by Theorem 1.84. Then for a E E we have Tr,1K(Tr£1,(a))� mE,Tr£1,(a).'� mE1 ("i'a•1"')'' ;-o ,-o 1=o m-1 11-1 i = 0 j = () m11-1 L a•'�Tr E;K(a). k=O 0 Another interesting function from a finite field to a subfield is obtained by forming the product of the conjugates of an element of the field with respect to the subfield. ' 2.27. Definition. For a E F� IF,. and K �IF,, the norm N,1K(a) of a over K is defined, by NF/K(a) = a.•a.q• ... ·aq�•--1= a.tq"'-Il/(q-11 . By comparing the constant terms in (2.1), we see that N,1K(a) can be read off from the characteristic polynomial g of a over K -namely, (2.3) It follows, in particular, that N,1K(a) is.always an element of K. 228. Theorem. Let K � F, and F � F , •. Then the norm function N F/K satisfies the following properties: (i) N,1K(aj3) � N,1K(a)N,1K(/3)for all a, P E F; (ii) NFIK maps F onto K and F* onto K*; (iii) N,1K(a) �am for all a E K; (iv) N,1K(a')� N,1K(a)forallaEF. Proof (i) follows immediately from the definition of the norm. We have already noted that N,1K maps F into K. Since N,1K( a)� 0 if and only if a� 0, N,1K maps F* into K*. Property (i) shows that NF/K is a group homomorphism between these multiplicati ve groups. Since the elements of the kernel of N,1K are exactly the roots of the polynomial x<q"-IJM-IJ_l E K[x] in F, the order d of the kernel satisfies d.; (qm -1)/(q -1). By Theorem 1.23, the image of N,1K has order (qm -1)/d. which is :;. q -1. Therefore, NF/K maps F* onto K* and so F onto K. Property (iii) follows from the definition of the norm and the fact that for a E K the conjugates of a with respect to K are all equal to a. Finally, we have N,1K( a•) � N F/K(a)' � N F/K (a) because of (i) and N F;K( a) E K, and so (iv) is shown. 0 54 Structure of Finite Fields 229. Theorem (Transitivity of Norm). Let K be a finite field, let F be a finite extension of K and E a finite extension of F. Then NE/K(a) � NF;K(NE/F(a)) foral/aE E. Proof With the same notation as in the proof of Theorem 2.26, we have for a E E. NF/K (NE;F( a)) � NF!K ( a1•"'"-l)/\q"'-l)) = ( a(q"'"-�)/(q'"-1) )(qm-1)/(q -I) 0 If (a1, ••• ,am) is a basis of the finite field F over a subfield K, the question arises as to the calculation of the coefficients c1( a) E K, I .;; j.;; m, in the unique representation a� c1(a)a1 + · · · + cm(a)am (2.4) of an element a E F. We note that c1: a�---+ c/ a) is a linear transform ation from F into K, and thus, according to Theorem 2.24, there exists a {J1 E F such that c1(a) � TrF;K({J1a) for all a E F. Putting a� a1, I.;; i.;; m, we see that TrF1K({J1a,) � 0 for i"' j and I for i � j. Furthermore, ({J1, ••• ,{Jm) is again a basis of F over K, for if d1{J1+···+dmflm�O withd1EK forl.;;i.;;m, then by multiplying by a fixed a1 and applying the trace function TrF!K• one shows that d1 � 0. 2.30. Definition. Let K be a finite field and F a finite extension of K. Then two bases (a1, ••• ,a.,) and ({J1, ••• ,{Jm) of Fover K are said to be dual (or complementary) bases if for I.;; i,j.;; m we have fori"' j, fori� j. In the discussion above we have shown that for any basis ( a1, ••• , am) ofF over K there exists a dual basis ({J1, ••• ,{Jm). The dual basis is, in fact, uniquely determined since its definition implies that the coefficients c1( a), I.;; j.;; m, in (2.4) are given by c/a) � TrF;K({J1a) for all a E F, and by Theorem 2.24 the element {J1 E F is uniquely determined by the linear fransformation c1. 2.31. Example. Let a E F, be a root of the irreducible polynomial x3 + x2 +I in F2[x]. Then (a, a2• I+ a+ a2) is a basis of IF8 over F2• One checks easily that its uniquely determined dual basis is again (a, a2• I+ a+ a2). Such a basis that is its own dual basis is called a self-dual basis. The element a5 E IF11 can be uniquely represented in the form a5 = c1a + c2a2 + 3. Traces, Norms, and Bases I c3(1 +a+ a2) with c1, c2• c3 E IF2• and the coefficients are given by c1=Tr• (a·a')=O, • c = Tr ( a2 · a') = I 2 F8 • c3 =Tr.,((l+ a+ a2)a') =I, so that a'= a2 +(I+ a+ a2 ). ss 0 The number of distinct bases ofF over K is rather large (see Exercise 2.37), but there are two special types of bases of particular importance. The first is a polynomial basis (l,a,a2, ... ,am-t), made up of the powers of a defining element a of F over K. The element a is often taken to be a primitive element of F (compare with Theorem 2. 10). Another type of basis g. s a ormal basis defined by a suit�ble element of F. Definition. Let K = IF, and F = F , •. Then a basis of F over K of the a, aq •... , aq"'-1}. consisting of a suitable element a E F and its con­ jugates with respect to K, is called a normal basis of F over K. The basis (a. a2• I + a+ a2) of F8 over F2 discussed in Example 2.31 is a normal basis of F8 over IF2 since I+ a+ a2 = a4. We shall show that a normal basis exists in the general case as well. The proof depends on two lemmas, one on a kind of linear independence property of certain group homomorphisms and one on linear operators. 2.33. Lemma (Artin Lemma). Let¥-1 ..... -r.., be distinct homomor­ phisms from a group G into the multiplicative group F* of an arbitrary field F, and let a 1, ... , am be elements of F that are not all 0. Then for some g E G we have Proof We proceed by induction on m. The case m =I being trivial, we assume that m >I and that the statement is shown for any m-I distinct homomorphisms. No--: take ¥-1, .... ¥-m and a1, ... ,am as in the lemma. If a1 = 0, the induction hypothesis immediately yields the desired result. Thus let a 1 "' 0. Suppose we had a1¥-1(g)+ ... +am>l-m(g)=O forallgEG. (2.5) Since ¥-1 "' >1-m• there exists hE G with >i-1(h)"' >1-m(h). Then. replacing g by hg in (2.5). we get a1>l-1(h)¥-1(g)+ ... +am>l-m(h).r.,(g)=O forallgEG. After multiplication by ¥-m (h)-1 we obtain b,¥-,(g)+ ... +bm-1>1-m-l(g)+am¥-m(g)=O forallgEG, where b;=a;>l-,(h)>i-.,(h)-1 for l.;i.;m-1. By subtracting this identity 56 Structure of Finite Fields from (2.5), we arrive at where c, �a,-b, for 1.;; i.;; m-1. But c1 � a1 -a1,P 1( h Nm(h )-1 * 0, and we have a contradiction to the induction hypothesis. D We recall a few concepts and facts from linear algebra. If T is a linear operator on the finite-dimensional vector space V over the (arbitrary) field K, then a polynomial f(x) � a,x" + · · · + a1x + a0 E K[x] is said to annihilate T if a,T" + · · · + a1T + a0/ = 0, where I is the identity operator and 0 the zero operator on V. The uniquely determined monic polynomial of least positive degree with this property is called the minimal polynomial forT. It divides any other polynomial in K[x] annihilating T. In particular, the minimal polynomial for T divides the characteristic polynomial g(x) for T (Cayley-Hamilton theorem), which is given by g(x) � det(x/ -T) and is a monic polynomial of degree equal to the dimension of V. A vector a E Vis called a cyclic vector for T if the vectors T'a, k � 0, 1, ... , span V. The following is a standard result from linear algebra. 234. Lemma. Let T be a linear operator on the finite-dimensional vector space V. Then T has a cyclic vector if and only if the characteristic and minimal polynomials for T are identical. 235. Theorem (Normal Basis Theorem). For any finite field K and any finite extension F of K, there exists a normal basis ofF over K. Proof Let K � F, and F � F ,. with m ;;. 2. From Theorem 2.21 and the remarks following it, we know that the distinct automorphisms ofF over K are given byE, a, a2, ... ,am-l, where E is the identity mapping on F, a(a) �a' for a E F, and a power af refers to the j-fold composition of a with itself. Because of a(a+,B)�a(a)+a(,B) and a(ca)�a(c)a(a)� ca(a) for a, ,8 E F and c E K, the mapping a may also be considered as a linear operator on the vector space F over K. Since am= E, the polynomial xm-IE K[x] annihilates a. Lemma 2.33, applied to£, a, a2, ..• ,am-I viewed as endo.morphisms of F*, shows that no nonzero polynomial in K [ x] of degree less than m annihilates a. Consequently, xm-1 is the minimal polynomial for the linear operator a. Since the characteristic polynomial for a is a monic polynomial of degree m that is divisible by the minimal polynomial for a, it follows that the characteristic polynomial for a is also given by xm -1. Lemma 2.34 implies then the existence of an element a E F such that a, a(a), a2(a), ... span F. By dropping repeated elements, we see that a, a(a), a2(a), ... ,am-1(a) span F and thus form a basis ofF over K. Since this basis consists of a and its conjut;ates with respect to K, it is a normal basis of F over K. D 3. Traces, Norms. and Bases 57 An alternative proof of the normal basis theorem will be provided in Chapter 3. Section 4, by using so-called linearized polynomials. We introduce an expression that allows us to decide whether a given set of elements forms a basis of an extension field. 2.36. Definition. Let K be a finite field and Fan extension of K of degree mover K. Then the discriminant 6.F;K(a1, ... ,am) of the elements a1, ... ,am E F is defined by the determinant of order m .given by TrF;K(a1a1) TrF;K(a1a2) TrF;K(a1am) llF;K(a, .... ,am) � TrF;K(a2a1) Tr F/K ( a2a2) TrF;K(a2am) TrF;K(amal) Tr F!K (a mal) TrF;K(amam) It follows from the definition that l1F;K(a1, ... ,a.,) is always an element of K. The following simple characterization of bases can now be g�ven. 2.37. Theorem. Let K be a finite field, Fan extension of K of degree m over K, and a1, ... , am E F. Then { a1, ... , am)· is a basis ofF over K if and only if l1F;K(a1, ... ,am)"' 0. Proof Let {a1 .... ,am) be a ba.sis of F over K. We prove that l1F;K(a1 .... ,a.,)"' 0 by showing that the row veqors of the determinant defining l1F;K(a1,. ... am) are linearly independent. For suppose that c1TrF;K(a1a)+ · · · + cmTrF;K(amaj) � 0 for'"" j"" m, where c1, ... ,c., E K. Then with /3 � c1a1 + .. · + c.,am we get TrF;K(/3a) � 0 for'"" j"" m. and since a1, ... ,a., span F. it follows that TrF;K({Ja) � 0 for all a E F. However. this is only possible if p � 0, and then c1a1 + · · · + emam = 0 implies el = ... =em= 0. Conversely, suppose that l1F;K(a1, .... am)*O and c1a1+ .. ·+ emam = 0 for some e1, ... ,em E K. Then e1a1aj+ ··· +emamaj=O far l�j�m. and by applying the trace function we get c1TrF;K(a1aj)+ ··· +cmTrF;K(ama)�O forl"'j"'m. But since the row vectors of the determinant defining l1F;K(a1, ... ,am) are linearly independent, it follows that c1 � • • • �em� 0. Therefore. a1, ... ,a., are linearly independent over K. 0 There is another determinant of order m that serves the same purpose as the discriminant l1F;K(a1 .... ,am). The entries of this determi­ nant are, however. elements of the extension field F. For a1, .... am E F. let 58 Structure of Finite Fields A be them X m rilatrix whose entry in the ith row andjth column is af-1, where q is the number of elements of K. If AT denotes the transpose of A, then a simple calculation shows that ATA � B, where B is them X m matrix whose entry in the ith row and jth column is TrF;K(a1a). By taking determinants, we obtain dF/K(a1, ... ,am) � det(A)2 The following result is now implied by Theorem 2.37. 2.18, CoroUary, Let a1, ... ,am E F ••. Then {a1, ... ,am) is a basis of IF q"' over IF q if and only if a, a, am af a� a• m *0. a(' ' ·-' q"'-1 a� a., From the criterion above we are led to a relatively simple way of checking whether a g!ven element gives rise to a normal basis. 219 Th "" IF ( • •' ··-'). lba. . . eorem. z·or a E q"'' a, a , a , ... , a IS a norma SIS of IF • over IFq if and only if the polynomials xm �I and axm-l + aqxm�2 + · · · + aq"'-\ + aq"'_'_ in 1Fq ... [x] are relatively prime. Proof When a1 =a, a2 = aq, ... ,am = aq"' 1, the determinant m Corollary 2.38 becomes a a• a• , a"m-\ aqm-\ a• __ , a a• aq"'-� __ , __ , (2.6) ± a• a a • a• a •' a• ' a after a suitable permutation of the rows. Now consider the resultant R(/, g) of the polynomials f(x) � xm �I and g(x) � axm-l + a•xm-2 + · · · + afl"'-2x + aq"'-1 of formal degree m resp. m -I, which is given by a_determi­ nant of order 2m� I in accordance with Definition 1.93. In this determi­ nant, add the (m + l)st column to the first column, the (m +2)nd column to the second column, and so on, finally adding the (2m� l)st column to the (m � l)st column. The resulting determinant factorizes into the determinant of the diagonal matrix of order m � I with entries � I along the main diagonal and the determinant in (2.6). Therefore, R(/, g) is, apart from the sign, equal to the determinant in (2.6). The statement of the theorem follows 4. Roots or Unity and Cyclotomic Polynomials 59 then from Corollary 2.38 and the fact that R(f, g)* 0 if and·only iff and g are relatively pr_ime. D In connection with the preceding discussion. we mention without proof the following refinement of the normal basis theorem. 2.40 Theorem. For any finite extension F of a finite field K there exists a normal basis of F over K that consists of primitive elements of F. 4. ROOTS OF UNITY AND CYCLOTOMIC POLYNOMIAlS In this section we investigate the splitting field of the polynomial x"-I over an arbitrary field K. where n is a positive integer. At the same time we obtain a generalization of the concept of a root of unity. well kno\>n for complex numbers. 2.41. Definition. Let n be a positive integer. The splitting field of x"-I over a field K is called the nth cyclotomic field over K and denoted by K1"1. The roots of x"-1 in K<'11 are called the nth roots of unity over K and the set of all these roots is denoted by £1"1. A special case of this general definition is obtained if K is the field of rational numbers . Then K1"1 is a subfield of the field of complex numbers and the nth roots of unity have their known geometric interpretation as the vertices of a regular polygon with n vertices on the unit circle in the complex plane. For our purposes. the most important case is that of a finite field K. The basic properties of roots of unity can, however. be established without using this restriction. T_he_�tru�ture_2L� -�:.)_.i.S.JJ._�J_e_fJ!!_i�_f:.4 .. �Y the relation of n tothe characteristic of K.-as th�following theorem shows:Wfien-werefe-r to the ch3��-cteflsilCP-�f .. k in this discussion. we permit the case p = 0 as well. 2.42. Theorem. Let n be a positive integer and K a field of char­ acteristic p. Then: (i) If p does not divide n, then £1"1 is a cyclic group of order n with respect to multiplication in Kl"1. (ii) lfp divides n, write n = mpe with positive integers m and e and m not divisible by p. Then K<nl = Klml, £(nl = £<m>. and the roots of x"-1 in K1"1 are them elements of £lml. each auained with multiplicity p'. Proof (i) The case n �I is trivial. For n ;. 2. x" -I and its deriva­ tive nx·�-l have no common roots, as nx"-1 only has the root 0 in K1"1. Therefore. by Theorem 1.68. x" -I cannot have multiple roots, and hence £1"1 has n elements. Now if I.�E£1" 1, then (��-1)"�1"(71")-1�1. thus 60 Structure or Finite Fields �1J-l E £1"1. It follows that £l•l is a multiplicative group. Let n � Pi'P2' · · · p;• be the prime factor decomposition of n. Then one shows by the same argument as in the proof of Theorem 2.8 that for each i, 1.; i.; t, there e�ists an element a, E £1•l that is not a root of the polynomial x"IP, -I, that /J; = a71prr has order pf;, and that £(II) is a cyclic group with generator {3 � {31 {32 · · · {3,. (ii) This follows immediately from x"-I� xmp'-I� (xm-I)'' and �ro. o 2.43. Definition. Let K be a field of characteristic p and n a positive integer not divisible by p. Then a generator of the cyclic group £l•l is called a primitive nth root of unity over K. By Theorem 1.15(v) we know that under the conditions of Definition 2.43there are e�actly cl>(n) different primitive nth roots of unity over K. If� is one of them, then all primitive nth roots of unity over K are given by�·. where I.; s.; n and gcd(s, n) �I. The polynomial whose roots are precisely the primitive nth roots of unity over K is of great interest. 2.44. Definition. Let K be a field of characteristic p, n a positive integer not divisible by p, and � a primitive nth root of unity over K. Then the polynomial Q,(x) � • n (x-n ,_, gcd(s,n)-1 is called the nth cyclotomic polynomial over K. The polynomial Q,(x) is clearly independent of the choice oft The degree of Q,(x) is cl>(n) and its coefficients obviously belong to the nth cyclotomic field over K. A simple argument will show that they are actually contained in the prime subfield of K. We use the product symbol Tidi• to denote a product e�tended over all positive divisors d of a positive integer n. 245. Theorem. Let K be a field of characteristic p and n a positive integer not divisible by p. Then: (i) x"-I� Tid1.Qd(x); (ii) the coefficients of Q.(x) belong to the prime subfield, of K, and to Z if the prime sub field of K is the field.of'ational numbers. Proof (i) Each nth root of unity over K is a primitive dth root of unity over K for e�actly one positive divisor d of n. In detail, if � is a primitive nth root of unity over K and �·is an arbitrary nth root of unity over K, then d � njgcd(s, n); that is, dis the order of�· in E1"l. Since • x"-1� n<x-f'), ,_, 4. Roots of Unity and Cyclotomic Polynomials 61 the formula in (i) is obtained by collecting those factors (x-t'J 'for which t' is a primitive d th root of unity over K. (ii) This is proved by induction on n. Note that Q.,(x) is a monic polynomial. For n �I we have Q1(x) �x-I, and the claim is obviously valid. Now let n >I and suppose the proposition is true for all Qd(x) with l.;d<n. Then we have by (i), Q,(x)�(x"-1)/f(x), where f(x)� fl"1,.J., Qd(x). The induction hypothesis implies thatf(x) is a polynomial with coefficients in the prime subfield of K or in Z in case the characteristic of K is 0. Using long division with x" -I and the monic polynomial f(x), we see that the coefficients of Q,(x) belong to the prime sub field of K or to Z, respectively. D 2.46. Example. Let r be a prime and k E N. Then since x,.1c -1 x,.A -I Q,•(x) � Q1(x)Q,(x)· · · Q,•-•(x) x',_, -I by Theorem 2.45(i). For k �I we simply have Q,(x) �I+ x + x2 + · · · + xr-1. D An explicit expression for the .nth cyclotomic polynomial generaliz­ ing the formula for Q,•(x) in Example 2.46 will be given in Chapter 3, Section 2. For applications to finite fields it is useful to know some properties of cyclotomic fields. 247. Theorem. The cyclotomic field K'"' is a simple algebraic extension of K. Moreover: (i) If K � Q, then the cyclotomic polynomial Q, is irreducible over K and [K1"': K] � cp(n). (ii) If K � F• with gcd(q, n) �I, then Q,factors into cp(n)/d distinct monic irreducible polynomials in K[x] of the same degree d, K'"1 is the splitting field of any such irreducible factor over K, and [K'"1: K] � d, where d is the least positive integer such that qd =I mod n. Proof If there exists a primitive nth root of unity t over K, it is clear that K'"1 � K(t). Otherwise, we have the situation described in Theorem 2.42(ii), then K'"' � K'm1 and the result follows again. As to the remaining statements, we prove only (ii), the important case for our pur­ poses. Let � be a primitive nth root of unity over F •. Then � E IF •' if and only if �·· � �. and the latter identity is equivalent to q' = I mod n. The smallest positive integer for which this holds is k � d, and so� is in F•'• but 62 Structure of Finite Fields in no proper sub field thereof. Thus the minimal polynomial of � over F q has degree d, and since� is an arbitrary root of Q •• the desired results follow. D 2.48. Example. Let K�F11 and Q12(x)�x4-x 2+1EIF11[x]. In the notation of Theorem 2.47(ii) we have d � 2. In detail, Q12(x) factors in the form Q12(x) � ( x2 + Sx + l)(x2 -Sx + 1), with both factors being irreduci­ ble in IF 11 [ x ]. The cyclotomic field K1 121 is equal to IF 121• D A further connection between cyclotomic fields and finite fields is given by the following theorem. 2.49. Theorem. The finite field F q is the ( q -I )st cyclotomic field over any one of its subfields. Proof The polynomial x•-1 -I splits in IF q since its roots are exactly all nonzero elements of F q· Obviously, the polynomial cannot split in any proper subfield of F •• so that IF q is the splitting field of x•-1 -I over any one of its subfields. D Since F; is a cyclic group of order q-I by Theorem 2.8, there will exist, for any positive divisor n of q-I, a cyclic subgroup {1, a, ... , a"-1} of IF; of order n (see Theorem l.IS(iii)). All elements of this subgroup are nth roots of unity over any sub field of f q and the generating element a is a primitive nth root of unity over any sub field of F q· We conclude this section with a lemma we shall need later on. 2.50. Lemma. If dis a divisor of the positive integer n with I .;; d < n, then Q.(x) divides (x" -1)/(xd -I) whenever Q.(x) is defined. Proof From Theorem 2.45(i) we know that Q.(x) divides x"-l�(xd-l)x"-l. xd -I Since dis a proper divisor of n, the polynomials Q.(x) and xd -I have no common root, hence gcd(Q.(x), xa -I)� I and the proposition is true. D 5. REPRESENTATION OF ELEMENTS OF FINITE FIELDS In this section we describe three different ways of representing the elements of a finite field F q with q � p" elements, where p is the characteristic of F q· The first method is based on principles expounded in Chapter I, Section 4, and in the present chapter. We note that IF q is a simple algebraic extension of I' P by Theorem 2.1 0. In fact, iff is an irreducible polynomial in F,[x] of degree n, thenfhas a root a in F• according to Theorem 2.14, and so F• � F,(a). Then, by Theorem 1.86, every element of IF• can beuniquely 5_ Representation of Elements of Finite Fields 63 expressed as a polynomial in a over IF r of degree less than n. We may also view IF9 as the residue class ring F,[x]/(fl. 2.51. Example. To represent the elements of IF9 in this way, we regard F9 as a simple algebraic extension of IF 3 of degree 2, which is obtained by adjunction of a root a of an irreducible quadratic polynomial over F3, say /( x) � x2 +IE IF3[x]. Thus/( a)� a2 +I� 0 in F9, and the nine elements of IF9 are given in the form a0 + a1a with a0, a1 E IF3. In detail, IF9 = (0, I, 2, a, I + a, 2 + a, 2a, I + 2a, 2 + 2a}. The operation tables for F9 may be constructed as in Example 1.62, with a playing the role of the residue class [x]. 0 If we use Theorems 2.47 and 2.49, we get another possibility of expressing the elements of IF9. Since IF9 is the (q -l)st cyclotomic field over IF,, we can construct it by finding the decomposition of the (q-!)st cyclotomic polynomial Q,_, E IF,[x] into irreducible factors in F,[x], which are all of the same degree. A root of any one of these factors is then a primitive (q -l)st root of unity over F, and therefore a primitive element of IF,-Thus, F 9 consists of 0 and appropriate powers of that primitive element. 2.52. Example. To apply this to the construction of F9, we note that IF,� IFj''. the eighth cyclotomic field over IF3. Now Q8(x) � x4 +IE IF3[x] by Example 2.46, and Q8(x)�(x2+x.+2)(x2+2x+2) is the decomposition of Q8 into irreducible facto�s in IF3[x]. Let!; be a root of x2 + x + 2; then !; is a primitive eighth root of unity over IF3• Thus, all nonzero elements of F9 can be expressed as powers of t. and so IF9 = (0. !;. !;2, 1;3, 1;4, !;', !;', !;7, !;8). We may arrange the nonzero elements of IF9 in a so-called index table, where we list the elements !;' according to their exponents i. In order to establish the connection with the representation in Example 2.51, we observe that x2+x+2EF3[x] has !;�I+a as a root, where a2 +I� 0 as in Example 2.51. Therefore, the index table for F9 may be written as follows: !:' !:' I I+ a 5 2+2a 2 2a 6 a 3 I +2a 7 2+ a 4 2 8 I We see that we obtain, of course, the same elements as in Example 2,51, just in a different order. D A third possibility of representing the elements of IF 9 is given by means of matrices. In general, the companion matrix of a monic polynomial 64 Structure of Finite Fields f(x)�a0+a1x+ ··· +a._1x"-1+x" of positive degree n over a field is defined to be the n X n matrix 0 0 0· 0 -ao I 0 0 0 -a, A� 0 0 0 -a, 0 0 0 -a,_\ It is well known in linear algebra that A satisfies the equationf(A) � 0; that is, a01+a1A+ ··· +a._1A"-1+A"�O. where I is the nXn identity matrix. Thus, if A is the companion matrix of a monic irreducible poly­ nomial f over F, of degree n, then /(A)� 0, and therefore A can play the role of a root of f. The polynomials in A over F P of degree less than n yield a representation of the elements of IF •. 2.53. Example. As in Example 2.51, let f(x) � x' +IE IF3[x]. The com­ panion matrix off is The field F9 can then be represented in the form F9 � {0, /,2/, A, I+ A, 2/ + A,2A, I +2A,21 +2A}. Explicitly: /+A�(: �l· �� (6 n 21� (� i)• 2/+A�(i ;) . 2A� (� i )· :) . 21+2A� (� �)' With F9 given in this way, calculations in this finite field are then carried out by the usual rules of matrix algebra. For instance, (2/+A)(/+ 2A)�(i �)(i :)�(� 6)�2A. D In the same way, the method based on the factorization of the cyclotomic polynomial Q q-1 in IF P [ x] can be adapted to yield a representa­ tion of the elements ofF • in terms of matrices. 2.54. Example. As in Example 2.52, let h(x) � x' + x + 2 E F 3[x] be an irreducible factor of the cyclotomic polynomial Q8 E IF3[x]. The companion matrix of h is c� (� i)· 6. Wedderburn"s Theorem The field IF 9 can then be represented in the form IF9 � {0, C, C2, C3, C4, C', C', C7, C8}. Explicitly: 0 � (� � ). c � ( � i ). c'� (i � ). c'�(� n C' � (� . 0) 2 . C' � (� n C' � (i : ) . C' � (: �). c' � ( � n Calculations proceed by the rules of matrix algebra. For instance. C' +C� (i : )+ ( � 6. WEDDERBURN'S THEOREM 1 i) � (� 2) � C' 0 . 65 D All results for finite fields are at the same time also true for all finite division rings by a famous theorem due to Wedderburn. This theorem states that in a finite ring in which all the field properties except commutativity of multiplication are assumed (i.e., in a finite division ring), the multiplication must also be commutative. Basically, the first -proof we present of the theorem considers a subring of the finite divison ring that is a field and establishes a numerical relation between the multiplicative group of the field and the multiplicative group of the whole division ring. Using this relation and information about cyclotomic polynomials, one obtains a contra­ diction- unless the field is all of the division ring. Before we prove Wedderburn's theorem in detail. we mention some general principles that will be employed. Let D be a division ring and F a subring that is a field (later on, we will express this more briefly by saying that F is a subfield of D). Then D can be viewed as a (left) vector space over F (compare with the discussion of the analogou s situation for fields in Chapter I, Section 4). IfF� F q and D is of finite dimension n over F •• then D has q" elements. We shall write D• for the multiplicative group of nonzero elements of D. For a group G and a nonempty subset S of G, we defined the normalizer N(S) of SinG in Definition 1.24. If Sis a singleton {b), we may also refer to N({b)) as the normalizer of the element bin G. From Theorem 1This section can be omitted without losing necessary information for the following chapters. 66 Structure of Finite Fields 1.25 we infer that if G is finite, then the number of elements in the conjugacy class of b is given by IGI/IN((b})l. 2.55. Theorem (Wedderburn's Theorem}. Every finite division ring is a field. First Proof Let D be a finite division ring and let Z � (z E D: zd � dz for all dE D) be the center of D. We omit the obvious verification that Z is a field. Thus Z � f • for some prime power q. Now D is a vector space over Z of finite dimension n, and soD has q" elements. We shall show that D � Z, or, equivalently, that n � 1. Let us suppose, on the contrary, that n > 1. Now let a ED and define N. �(bED: ab � ba). Then N. is a division ring and N. contains Z. Thus N. has q' elements, where I"' r"' n. We wish to show that r divides n. Since N; is a subgroup of D*, we know that q'-I divides q" -I. If n � rm + I with 0"' I< r, then q" -I� q'"'q' -I� q'(q'"' -l)+(q' -I). Now q' -I divides q"-I and also q'"'-I, thus it follows that q'-I divides q'-1. But q'-I < q'-I, and so we must have 1 � 0. This implies that r divides n. We consider now the class equation for the group D* (see Theorem 1.27). The center of D* is z•. which has order q-1. For a E D*, the normalizer of a in D* is exactly Na*. Therefore, a conjugacy class in D* containing more than one member has (q" -1)/(q'-I) elements, where r is a divisor of n with I� r < n. Hence the class equation becomes k q" -I q"-l�q-1+ L -� . i-1 qr•-1 (2.7) where r1, ... ,rk are (not necessarily distinct) divisors of n with I� r; < n for l ... i ... k. Now let Q .. be the nth cyclotomic polynomial over the field of rational numbers. Then Q .. (q) is an integer by Theorem 2.45(ii). Further­ more, Lemma 2.50 implies that Q.,( q) divides ( q" -I )/(q'• -I) for I "'i"' k. We conclude then from (2.7) that Q.,(q} divides q -1. However. this will lead to a contradiction. By definition, we have n Q.,(x) � n (x-i'), s = 1 gcd(s,n)-1 where the complex number i is a primitive nth root of unity over the field of rationals. Therefore, as complex numbers, n n IQ.(qJI� n lq-i'l> n (q-l);.q-1 s-1 s=l gcdCs.n)=l gcd(s,n)-1 since n > I and q;. 2. This inequality is incompatible with the statement 6. Wedderburn"s Theorem 67 that Q"(q) divides q -I. Hence we must have n �I and D � Z, and the theorem is proved. 0 Before we start with the second proof of Wedderburn's theorem, we establish some preparatory results. Let D be a finite division ring with center Z, and let F denote a maximal subfield of D; that is, F is a subfield of D such that the only subfield of D containing F is F itself. Then F is an extension of Z, for if there were an element z E Z with z fl F, we could adjoin z to F and obtain a subfield of D properly containing F. From Theorem 2.10 we know that F� Z(E), where� E F* is a root of a monic irreducible polynomial / E Z[x]. If we view D as a vector space over F, then for each a E D the assignment T.( d)� da for dE D defines a linear operator T. on this vector space. We consider now the linear operator IE· If dis an eigenvector of IE· then for some A E F* we have d� �Ad. This implies dEd� 1 � A and hence dF*d-1 � F*, thus d EN( F*), the normalizer of F* in the group D*. Conversely, if dE N(F*), then d�d-1 �A for some A E F*, and so d is an eigenvector of IE· This proves the following result. 256. Lemma. An element d ED* is an eigenvector of 7! if and only if dE N(F*). Let A be an eigenvalue of 71 with eigenvector d, then dE� Ad. It follows that 0 � df(�)� /(A)d, hence A must be a root off. If d0 is another eigenvector corresponding to the eigenvalue A, then d0d-1 Add0 1 �A, and so the element b = d0d-1 commutes with A anc( consequently, with every element ofF� Z(A). Let P be the set of all polynomial expressions in b with coefficients in F. Then it is easily checked that P forms a finite integral domain, and so P is a finite field by Theorem 1.31. But P contains F, and thus P � F by the maximality of F. In particular, we have bE F, and since d0 � bd, we conclude that every eigenspace of 7! has dimension I. We use now the following result from linear algebra. 2.57. Lemma. Let T be a linear operator on the finite-dimensio nal vector space V over the field K. Then V has a basis consisting of eigenvectors of T if and only if the minimal polynomial for T splits in K into distinct monic linear factors. Since tal� 0, the polynomial f annihilates the linear operator IE· Furthermore, f splits in F into distinct monic linear factors by Theorem 2.14. The minimal polynomial for 7! divides/, and so it also splits in Finto distinct monic linear factors. It follows then from Lemma 2.57 that D has a basis as a vector space over F consisting of eigenvectors of JE. Since every eigenspace of 7! has dimension I, the dimension m of D over F is equal to the number of distinct eigenvalues of IE· Let�� �1• �2 •.•.• Em be the distinct eigenvalues of 7! and let I� d1, d2, ••• ,dm be corresponding eigenvectors. 68 Structure of Finite Fields Because N( F*) is closed under multiplication, it follows from Lemma 2.56 that d1dj must correspond to an eigenvalue�,. say, and hence d1d1� � �,d,dj. Using dj� � �jdj, we obtain d1�j � �,d,, or d1�1di 1 �� •• This shows that for each i, 1 .;; i.;; m, the mapping that takes �J to d1�1di 1 permutes the eigenvalues among themselves. Consequently, the coefficients of g(x) � (x-E1l · · · (x-�ml commute with the eigenvectors dp d,, ... ,dm of r,. Since the coefficients of g obviously belong to F and thus commute with all the elements of F, they commute with all the elements of D, since these can be written as linear combinations of d1, d2, ... ,dm with coefficients in F. Thus the coefficients of g are elements of the center Z of D. Since g( 0 � 0, Lemma 2.12 implies that f divides g. On the other hand, we have already observed that every eigenvalue of T, must be a root off, and so f �g. It follows that [F: Z] � [Z(�): Z] � deg(/) � rn. Now m is also the dimension of D over F, and so the argument in the proof of Theorem 1.84 shows that Dis of dimension m2 over Z. Since the latter dimension is independent ofF, we conclude that every maximal subfield of D has the same degree over Z. We state this result in the following equivalent form. 2.58. Lemma. All maximal subfields of D have the same order. Second Proof of Theorem 2.55. Let D be a finite division ring, and let Z, F� Z(n and f E Z[x] be as above. Let E be an arbitrary maximal sub field of D. Then, by Lemma 2.58, E and F have the same order, say q. In view of Lemma 2.4, both E and F are splitting fields of x•- x over Z. It follows then from Theorem 1.91 that there exists an isomorphism from F onto E that keeps the elements of Z fixed. The image� E E* of� under this isomorphism is therefore a root off in E, and so E � Z( � ). Consider the linear operator T, on the vector space D over F. Since /( �) � 0, the polynomial f annihilates T,. But f splits in F, and so there exists a root A E F off that is an eigenvalue of T,. For a corresponding eigenvector d we have then d� �Ad, and this implies E* � d-1F*d. Thus, E* is a conjugate of the subgroup F* of D*. For an arbitrary c E D*, the set of polynomial expressions in c with coefficients in Z forms a finite integral domain, and thus a finite field by Theorem 1.31. Hence, any element of D* is contained in some sub field of D, and so in some maximal subfield of D. From what we have already shown, it follows that any element of D* belongs to ,some conjugate of F*. By Theorem 1.25, the number of distinct conjugates of F* is given by ID*I/IN(F*)I. and so it is at most ID*I/IF*I. Since each conjugate ofF* contains the identity element of D*, the union of the conjugates ofF* has at most ID*I (IF*I-1)+ 1 � ID*I_ID*I + 1 IF*I IF*I Exercises 69 elements. This number is less than I D*l except when D* � F*. Hence D � F, and D is a field. 0 EXERCISES 2.1. 2.2. 2.3. 2.4. 2.5. 2.6. 2.7. 2.8. 2.9. 2.10. 2.11. 2.12. 2.13. 2.14. 2.15. 2.16. Prove that x2 +I is irreducible over F 11 and show directly that F11[x]/(x2+1) has 121 elements. Prove also that x2+x+4 is irreducible over !' ll and show that IF 11 [x ]/(x2 + I) is isomorphic to IF"[x]/(x2 + x +4). Show that the sum of all elements of a finite field is 0, except for F2. Let a, b be elements of IF,., n odd. Show that a2 + ab + b2 � 0 implies a � b � 0. Determine all primitive elements of F 7. Determine all primitive elements of F 17. Determine all primitive elements of F9. Write all elements of IF, as linear combinations of basis elements over IF5. Then find a primitive element fJ ofF, and determine for each aE 1Fi5 the least nonnegative integer n such that a= /3". If the elements of F; are represented as powers of a fixed primitive element bE F,, then addition in F, is facilitated by the introduction of Jacobi's logarithm L(n) defined by the equation I+ b" � bL'"'. where the case b" � -I is excluded. Show that we have then bm + b" � bm+Lc• -mJ whenever L is d�fined. Construct a table of Jacobi's logarithm for IF 9 and IF 17. Prove: for any field F, every finite subgroup of the multiplicative group F* is cyclic. Let F be any field. IfF* is cyclic, show that F is finite. Prove: if F is a finite field, then H U (0} is a subfield of F for every subgroup H of the multiplicative group F* if and only if the order of F* is either I or a prime number of the form 2'-I with a prime p. For every finite field F, ·of characteristic p, show that there exists exactly one pth root for each element of IF,. For a finite field IF, with q odd, show that an element a E IF; has a square root in F , if and only if a<q-IJ/2 � I. Prove that for given k E I'll the element a E IFf is the k th power of some element of F, tf and only tf a'•-1/d �I, where d � gcd(q -I, k). Prove: every element of F, is the k th power of some element of IF, if and only if gcd(q -I, k) �I. Let k be a positive divisor of q-I and a E F, be such that the equation x�< =a has no solution in IF q· Prove that the same equation has a solution in IF,. if m is divisible by k, and that the converse holds for a prime number k. 70 Structure of Finite Fields 2.17. Prove that l(x )• � l(x•) for I E F .[x ]. 2.18. Show that any quadratic polynomial in F.[x] splits over F•' into linear factors. 2.19. Show that for a E IF • and n E I'll the polynomial x•"-x + na is divisible by x• -x + a over F q· 2.20. Find all automorphisms of a finite field. 2.21. IfF is a field and >¥: F-> F is the mapping defined by'!'( a)� a-1 if a"" 0, >!'(a)� 0 if a� 0, show that >¥ is an automorphism ofF if and only if F has at most four elements. 2.22. Prove: if p is a prime and n a positive integer, then n divides �( p" -1). (Hint: Use Corollary 2.19.) 2.23. Let F• be a finite field of characteristic p. Prove that IEF.[x] satisfies f'(x) � 0 if and only if I is the pth power of some poly­ nomial in IF•[x]. 2.24. Let F be a finite extension of the finite field K with [F: K] � m and let l(x) � xd + bd_1xd-l + · · · + b0 E K[x] be the minimal poly­ nomial of a E F over K. Prove that TrF;K(a) �-(mjd)bd-l and NF/K(a) � ( -!)mbQ'Id. 2.25. Let F be a finite extension of the finite field K and a E F. The mapping L: p E F...., a{J E F is a linear transformation ofF, consid­ ered as a vector space over K. Prove that the characteristic poly­ nomial g(x) of a over K is equal to the characteristic polynomial of the linear transformation L; that is, g( x) � det( xi-L ), where I is the identity transformation. 2.26. Consider the same situation as in Exercise 2.25. Prove that TrF/K(a) is equal to the trace of the linear transformation L and that NF;K(a) � det(L). 2.27. Prove properties (i) and (ii) of Theorem 2.23 by using the interpreta­ tion of TrF/K(a) obtained in Exercise 2.26. 2.28. Prove properties (i) and (iii) of Theorem 2.28 by using the interpreta­ tion of NF/K(a) obtained in Exercise 2.26. 2.29. Let F be a finite extension of the finite field K of characteristic p. Prove that TrF;K(a'") � (TrF;K(a))'" for all a E F and n E I'll. 2.30. Give an alternative proof of Theorem 2.25 by viewing F as a vector space over K and showing by dimension arguments that the kernel of the linear transformation TrF/K is equal to the range of the linear operator Lon F defined by L({J) � p•-P for P E F. 2.31. Give an alternative proof of the necessity of the condition in Theo­ rem 2.25 by showing that if a E F with TrF ;K(a) � 0, "Y E F with TrF/K("Y) � -1, and 8j �a+ a• + · · · + a•J-•, then satisfies p•- p �a. [F,K] p� L 8j"Y·j-· j-1 Exercises 71 2.32. Let F be a finite extension of K � F • and a= {J•-fJ for some fJ E F. Prove that a� r•-y withy E F if and only if fJ-y E K. 2.33. Let F be a finite extension of K �IF •. Prove that for a E F we have NF/K(a)�l ifandonlyifa�p•-1 forsome{JEF*. 2.34. Prove Lj.-o'x•'-c � nc X-a) for all c E K �IF •• where the product is extended over all a E F �IF •• with TrF;K(a) �c. 2.35. Prove for any mE I'll. ( m -I ) x•·-x� n :L x•'-c cEF, ;-o 2 36. Consider IF •• as a vector space over F • and prove that for every linear operator L on F •• there exists a uniquely determined m-tuple (a0, a1, ... ,am_1) of elements of IFq"' such that 2.37. Prove that if the order of basis elements is taken into account, then the number of different bases of F •• over F • is 2.38. Prove: if (a1, ••• ,am) is a basis of F�F •• over K�IF., then TrF/K(a;) * 0 for at least one i, I .:S;; i .:S;; m. __ 2.39. Prove that there exists a normal basis {.;,a•, ... ,a•·-•} of F�IF •• over K � IF• with TrF/K(a) �I. 2.40. Let K be a finite field, F � K( a) a finite simple extension of degree n, and/ E K[x] the minimal polynomial of a over K. Let f(x) �[J0+fJ,x+ ... +fJ._1x"-1EF[x] and y�f'(a). x-a Prove that the dual basis of {l,a, ... ,a"-1} is ({J0y-1,{J1y-1, ••• , fJ._,y-'). 2.41. Show that there is a self-dual normal basis of F4 over F2, but no self -dual normal basis of IF 16 over F 2 (see Example 2.31 for the definition of a self-dual basis). 2.42. Construct a self-dual basis ofF 16 over F2 (see Example 2.31 for the definition of a self-dual basis). 2.43. Prove that the dual basis of a normal basis of IF •• over IF • is again a normal basis of F •• over F •. 2.44. Let F be an extension of the finite field K with basis (a1, ••• ,am} over K. Let {31, ••• ,{Jm E F with {J, � Lj.1bijaj for I .;; i .;; m and bij E K. Let B be the m X m matrix whose ( i, j) entry is bij. Prove that tJ.F/K ( {J,, ... ,{Jm) � det( B)'tJ.F/K ( a1, ••• , am). 72 Structure of Finite Fields 2.45. Let K = IF, and F = IF, •. Prove that for a E F we have ( n . I 2 /:,F/K l,a, ... ,am-l)= {a•'-a<) O.;;i<j�m -1 2.46. Prove that for a E F = F , •. with m;. 2 and K =IF, the discriminant t,,1K(i,a, ... ,am-l) is equal to the discriminant of the characteris tic polynomial of a over K. 2.47. Determine the primitive 4th and 8th roots of unity in IF9. 2.48. Determine the primitive 9th roots of unity in F 19• 2.49. Let !: be an nth root of unity over a field K. Prove that I+ I;+ !;2 + · · · + !:"-1 = 0 or n according as !: * 1 or !: = I. 2.50. For n ;. 2 let !;1, ••• , !:, be all the (not necessarily distinct) nth roots of unity over an arbitrary field K. Prove that 1:; + · · · + 1:: = n for k = 0 and r; + ... + !:,; = 0 for k = 1. 2, .... n -I. 2.51. For an arbitrary field K and an odd positive integer n, show that K(2n) = K(n). 2.52. Let K be an arbitrary field. Prove that the cyclotomic field Kldl is a subfield of K1"' for any positive divisor d of n EN. Determine the minimal polynomial over K <•l of a root of unity that can serve as a defining element of K112l over K14l. 2.53. Prove that for p prime the p-I primitive pth roots of unity over Q are linearly independent over Q and therefore form a basis of O''' over Q. 2.54. Let K be an arbitrary field and n ;. 2. Prove that the polynomial xn-l + xn-2 + · · · + x + 1 is irreducible over K only if n is a prime number. 2.55. Find the least prime p such that x22 + x21 + · · · + x +I is irreduci­ ble over F,. 2.56. Find the ten least primes p such that xr' + x•-2 + · · · + x + I IS irreducible over IF 2. 2.57. Prove the following properties of cyclotomic polynomials over a field for which the polynomials exist: (a) Qm,(x) = Qm(x')/Qm(x) if pis prime and mE I'll is not divisi­ ble by p; (b) Qmp(x) = Qm(x') for all mE I'll divisible by the prime p; (c) Qm,•(x) = Qm,(x''-') if p is a prime and m, kEN are arbi- trary; (d) Q2.(x) = Q.(-x) if n;. 3 and n odd; (e) Q.(O) =I if n;. 2; (f) Q.(x-• )x•<•l = Q.(x) if n ;. 2; (g) Q.(l) = {f if n =I, if n is a power of the prime p, if n has at least two distinct prime factors; E:\cn.:ises (h) ( 0 -2 Q.(-1}= � if n,;, 2, if n = 1, if n is 2 times a power of the prime p, otherwise. 73 2.58. Give the matrix representation for the elements of F8 using the irreducible polynomial x3 + x +I over IF2. 2.59. Let I be a primitive element ofF= F 16 with 14 +I+ I= 0. Fork;;, 0 write I' = E�_0a,..,l"' with a,., E IF2, and let M, be the 4 X 4 matrix whose (i, j) entry is ak+i-l,j-l· Show that the 15 matrices M,, 0" k "14, and the 4 X4 zero matrix form a field (with respect to addition and matrix multiplication over F2) which is isomorphic to F. For 0" k "14 prove that TrF(I') =trace of M, =a.,. Chapter 3 Polynomials over Finite Fields The theory of polynomials over finite fields is important for investigating the algebraic structure of finite fields as well as for many applications. Above all. irreducible polynomi als-the prime elements of the polynomial ring over a finite field-are indispensable for constructing finite fields and computing with the elements of a finite field. Section 1 introduces the notion of the order of a polynomial. An important fact is the connection between minimal polynomials of primitive elements (so-called primitive polynomials) and polynomials of the highest possible order for a given degree. Results about irreducible polynomials going beyond those discussed in the previous chapters are presented in Section 2. The next section is devoted to constructive aspects of irreducibil­ ity and deals also with the problem of calculating the minimal polynomial of an element in an extension field. Certain special types of polynomials are discussed in the last two sections. Linearized polynomials are singled out by the property that all the exponents occurring in them are powers of the characteristic. The remarkable theory of these polynomials enables us. in particular, to give an alternative proof of the normal basis theorem. Binomials and trinomials -that is, two-term and three-term polynomials- form another class of polynomials for which special results of considerable interest can be established. We remark that another useful collection of polynomials­ namely, that of cyclotomic polynomials-was already considered in Chapter 1. Order of Polynomials and Primitive Polynomials 75 2, Section 4, and that some additional information on cyclotomic polynomi­ als is contained in Section 2 of the present chapter. 1. ORDER OF POLYNOMIALS AND PRIMITIVE POLYNOMIALS Besides the degree, there is another important integer attached to a nonzero polynomial over a finite field, namely its order. The definition of the order of a polynomial is based on the following result. 3.1. Lemma. Let f E F.[x] be a polynomial of degree m ;.I with f(O) * 0. Then there exists a positive integer e.;; q'" -I such that f(x) divides xt' -1. Proof The residue class ring F .[x ]/(/) contains q'"-I nonzero residue classes. The q'" residue classes x1 + (/ ), j � 0, I, ... ,q'" -I, are all nonzero, and so there exist integers rands with 0 .:s;; r < s .:s;; qm-1 such that x' = x'modf(x). Since x and f(x) are relatively prime, it follows that x'-'=lmodf(x); thatis,f(x) dividesx'-'-1 andO <s-r.;;q'"-1. 0 Since a nonzero constant polynomial divides x -·I, these polynomi­ als can be included in the following definition. 3.2. Definition. Let f E F •[x] be a nonzero polynomial. If f(O)"' 0, then the least positive integer e for which f( x) divides x' -I is called the order of f and denoted by ord(/) � ord(f(x )). If /(0) � 0, thenf(x) � x'g(x ), where h EN and g E F •[x] with g(O)"' 0 are uniquely determined; ord(/) is then defined to be ord( g). The order of the polynomial f is sometimes also called the period off or the exponent of f. The order of an irreducible polynomial f can be characterized in the following alternative fashion. 3.3. Theorem. Let/ EIF.[x] be an irreducible polynomial over IF• of degree m and with f(O) * 0. Then ord(/) is equal to the· order of any root off in the multiplicative group r; .. Proof According to Corollary 2.15, IFq"' is the splitting field off over IF •. The roots off have the same order in the group IF;. by Theorem 2.18. Let a E IF;. be any root of f. Then we obtain from Lemma 2.12 that we have a'� I if and only if f(x) divides x' -I. The result follows now from the definitions of ord(/) and the order of a in the group IF;.. 0 3.4. Corollary. Iff E IF•[x] is an irreducible polynomial over IF• of degree m, then ord(/) divides q'" -I. 76 Polynomials over Finite Fields Proof If f(x) �ex with c E IF;. then ord(/) �I and the result is trivial. Otherwise, the result follows from Theorem 3.3 and the fact that IF;. is a group of order q"' -I. 0 For reducible polynomials the result of Corollary 3.4 need not be valid (see Example 3.10). There is another interpretation of ord(/) based on associating a square matrix to fin a canonical fashion and considering the order of this matrix in a certain group of matrices (see Lemma 6.26). Theorem 3.3 leads to a formula for the number of monic irreduc­ ible polynomials of given degree and given order. We use again .P to denote Euler's function introduced in Theorem l.IS(iv). The following terminology will be convenient: if n is a positive integer and the integer b is relatively prime ton, then the least positive integer k for which b'"" I mod n is called the multiplic ative order of b modulo n. 3.5. Theorem. The number of monic irreducible polynomials in IFq[x] of degree m and order e is equal to .P(e)jm if e:;, 2 and m is the multiplicative order of q modulo e, equal to 2 if m � e � I, and equal to 0 in all other cases. In particular, the degree of an irreducible polynomial in Fq[x] of order e must be equal to the multiplicative order of q modulo e. Proof Let f be an irreducible polynomial in IF q[x] with /(0)"' 0. Then, according to Theorem 3.3, we have ord( f)� e if and only if all roots off are primitive eth roots of unity over &= q· In other words, we have ord( f)� e if and only if f divides the cyclotomic polynomial Q_. By Theorem 2.47(ii), any monic irreducible factor of Q, has the same degree m, the least positive integer such that qm = I mode, and the number of such factors is given by .p(e)jm. For m�e�l. we also have to take into account the monic irreducible polynomial f(x) � x. 0 Values of or d(/) are available in tabulated form, at least for irre­ ducible polynomials f (see Chapter 10, Section 2). Since any polynomial of positive degree can be written as a product of irreducible polynomials, the computation of orders of polynomials can be achieved if one knows how to determine the order of a power of an irreducible polynomial and the order of the product of pairwise relatively prime polynomials, The subsequent discussion is devoted to these questions. 3.6 Lemma. Let c be a positive integer. Then the polynomial f E IF 9[x] with /(0) "'0 divides x'-I if and only if ord( /) divides c. Proof If e � ord(/) divides c. then f(x) divides x' -I and x'-I divides x' -I, so thatf(x) divides x' -I. Conversely, if /(x) divides x' -I, we have c � e, so that we can write c =m e+ r with mEN and 0 � r <e. Since x'-L� (xm• -l)x' +(x' -I), it follows that f(x) divides x' -I, which is only possible for r � 0. Therefore, e divides c. 0 I. Order of Polynomials and Primitive Polynomials 77 3.7. Corollary. If e1 and e2 are positive integers. then the greatest common divisor of X .. 1 -I and x"� -I in IFq[x] is xJ -I, where dis the greatest common divisor of e1 and e'}. Proof Let /(x) be the (monic) greatest common divisor of x'• - I and x"1-I. Since xd- I is a common divisor of x"· -I, i = 1,2, it follows that x• -I divides f(x). On the other hand, /(x) is a common divisor of x'• -I. i � 1.2. and so Lemma 3.6 implies that ord(/) divides e1 and e2• Consequently, ord(/) divides d, and hence /(x) divides x d -I by Lemma 3.6. Altogether. we have shown that/(x) � xd -I. D Since powers of x are factored out in advance when determining the order of a polynomial. we need not consider powers of the irreducible polynomials g(x) with g(O) � 0. 3.8. Theorem. Let gE Fq[x] be irreducible over IF• with g(O) "' 0 and ord(g) �e. and let f � g' with a positive integer b. Lett be the smallest integer with p' � b. where p is the characteris tic ofF •. Then ord(/) � ep'. Proof Setting c � ord(/) and noting that the divisibility of x'- I by /(x) implies the divisibility of x'- I by g(x). we obtain that e divides c by Lemma 3.6. Furthermore. g(x) divides x' -I; therefore, /(x) divides (x' -I)' and. a fortiori, it divides (x' -J)P' � x'P'-I. Thus according to Lemma 3.6. c divides ep'. It follows from what we have shown so far that c is of the form c � ep" with 0..; u..; t.· We note now that x' -I has only simple roots, since e is not a multiple of p because of Corollary 3.4. Therefore, all the roots of x•P" -I� (x'-I)P" have multiplicity p". But g( x )' divides x'P "-I, whence p" � b by comparing multiplicities of roots. and so u � t. Thus we get u = t and c = ep'. D 3.9. Theorem. Let g1, ••• ,gk. be pairwise relatively prime nonzero polynomials over F •. and let f� g1 • • • g,. Then ord(/) is equal to the least common multiple of ord( g1 ) .... ,ord( g, ). Proof It is easily seen that it suffices to consider the case where g,(O)"' 0 for I..; i..; k. Set e � ord(/) and e, � ord(g,) for I..; i..; k, and let c �I em( e 1 ••••• e, ). Then each g;(x ). I ..; i..; k. divides x'•-I, and so g,( x) divides x'-I. Because of the pairwise relative primality of the polynomials g1 ..... g,. we obtain that/(x) divides x' -I. An application of Lemma 3.6 shows that e divides c. On the other hand. /(x) divides x' -I, and so each g;(x). I..; i..; k. divides x' -I. Again by Lemma 3.6. it follows that each e,, I..; i..; k. divides e. and therefore c divides e. Thus we conclude that e �c. D By using the same argumen t as above. one may. in fact. show that the order of the least common multiple of finitely many nonzero polynomi­ als is equal to the least · common multiple of the orders of the polynomials. 78 Polynomials over Finite Fields 3.10. Example. Let us compute the order of f(x)�x10+x9+x3+ x2 +IE IF2[x]. The canonical factorization of f(x) over IF2 is given by f(x)�(x2+x+l)3(x4+x+l). Since ord(x2+x+l)�3. we get ord((x2 + x + 1)3) � 12 by Theorem 3.8. Furthermore, ord(x4 + x + 1) � 15_, and so Theorem 3.9 implies that ord(f) is equal to the least common multiple of 12 and 15; that is, ord(f) � 60. Note that ord(f) does not divide 210-I, which shows that Corollary 3.4 need not hold for reducible polynomials. o On the basis of the information provided above, one arrives then at the following general formula for the order of a polynomial. It suffices to consider polynomials of positive degree and with nonzero constant term. 3.11. Theorem. Let F, be a finite field of characteristic p, and let f E IF,[x] be a polynomial of positive degree and with /(0) * 0. Let f � aj,•• · · · jj•, where a E F ,, b1, ••• ,bk E 1'\J, and /1, ... ,fk are distinct monic irreducible polynomials in F,[x], be the canonical factorization off in F,[x]. Then ord( f) � ep', where e is the least common multiple of ord(/1 ), ••• , ord(/•) and I is the smallest integer with p' ;;. max( b 1, •.. , b k ). A method of determining the order of an irreducible polynomial fin F ,[ x] with /(0) * 0 is based on the observation that the order e off is the least positive integer such that x' =I modf(x). Furthermore, by Corollary 3.4, e divides qm-I, where m � deg(f). Assuming qm > 2, we start from the prime factor decomposition ' qm-1 = n p)'. j�l For l .;; j.;;s we calculate the residues of x<•"-ll!P,modf(x). This is accomplished by multiplying together a suitable combination of the residues of x, x•, x•', ... ,x•··-• mod f(x). If x<•"-ll!PJ ;�;I modf(x), then e is a mul­ tiple of p;. If x<•"'-I)/P; = I mod f(x), then e is not a multiple of P? In the latter case we check to see whether e is a multiple of pp-1, pp-2, ..• ,p1 by calculating the residues of x(q"' -l)/P}, x(q"'-l)/p}, ... , x<q"'-1l/Pjl mod f( x ). This computation is repeated for each prime factor of qm -I. A key step in the method above is the factorization of the integer qm -1. There exist extensive tables for the complete factorization of num­ bers of this form, especially for the case q � 2. We compare now the orders of polynomials obtained from each other by simple algebraic transformations. The following is a typical exam­ ple. 3.12. Definition. Let f(x)=a11x11+a,_1x11-1+ ··· +a1x+a0E1Fq[x] 1. Order of Polynomials and Primitive Polynomials with a,"' 0. Then the reciprocal polynomial f* off is defined by f*(x)�x"f(�)�a0x"+a1x"-1+ ··· +a,_1x+a,.. 79 3.13. Theorem. Lee f be a nonzero polynomial in F,[x] and/* irs reciprocal polynomial. Then ord(/) � ord(/*). Proof First consider the case /(0) "' 0. Then the result follows from the fact that f(x) divides x'- I if and only if /*(x) does. If /(0) � 0, write /( x) � x'g( x) with h E I'll and g E F ,[x] satisfying g(O)"' 0. Then from what we have already shown it follows that ord(/) � ord(g) � ord(g*) � ord(/*), where the last identity is valid since g* � f*. D There is also a close relationship between the orders of/( x) and /(-x). Since f(x) � /(-x) for a field of characteristic 2, it suffices to consider finite fields of odd characteri stic. 3.14. Theorem. For odd q. lee f E IF,[x] be a polynomial of positive degree wich /(0)"' 0. Lee e and E be che orders of f(x) and /(-x), respectively. Then E � e if e is a multiple of 4 and E � 2e if e is odd. If e is twice an odd number, chen E � e /2 if all irreducible factors off have even order and E = e otherwise. Proof Since ord(/(x))�e, j(x) divides x2'-1, and so /(-x) divides (-x )2'-I � x2'-1. Thus E divides 2e by Lemma 3.6. By the same argument, e divides 2£, and so E can only be 2e, e, or e/2. If e is a multiple of 4, then both e and E are even. Since f(x) divides x' -1,/(-x) divides (-x)' -1 � x'-I, and so E divides e. Similarly, e divides E, and thus it follows that E �e. If e is odd, then/(-x) divides (-x)' -1 �-x' -I and so x' + 1. But then /(-x) cannot divide x' -1, and so we must have E � 2e. In the remaining case we have e � 2h with an odd integer h. Let f be a power of an irreducible polynomial in f,[x]. Then f(x) divides (x' -lXx' + 1) and /(x) does not divide x ' -1 since ord(/) � 2h. But x' -1 and x' + 1 are relatively prime, and this implies that j(x) divides x' +I. Conseque ntly,/(-x) divides (-x)' +I�-x' +I and sox'-I. It follows that E � e /2. Note that by Theorem 3.8 the power of an irreducible polynomial has even order if and only if the irreducible polynomial itself has even order. For general f we have a factorization f � g 1 • • ·g., where each g, is a power of an irreducible polynomial and g1, ... ,gk are pairwise relatively prime. Furthermore, 2h � lcm(ord(g1 ), ... ,ord(gk)) according to Theorem 3.9. We arrange the g, in such a way that ord(g,) � 2h, for I.;; i.;; m and ord( g,) � h, for m + 1 .;; i.;; k, where the h, are odd integers with lcm( h 1, ... , hk)�h. By what we have already shown, we get ord(g,(-x))�h, for 1.;; i.;; m and ord(g,(-x)) = 2h, form+ I.;; i.;; k. Then Theorem 3.9 yields E � lcm(h,, ... ,h_,2h_.,, ... ,2h,), Polynomials over Finite Fields and so E�h�e /2 if m�k and E�2h�e if m<k. These formulas are equivalent to those given in the last part of the theorem. D It follows from Lemma 3.1 and Definition 3.2 that the order of a polynomial of degree m � I over IF q is at most q"1-I. This bound is attained for an important class of polynomials-namely, so-called primitive poly­ nomials. The definition of a primitive polynomial is based on the notion of primitive element introduced in Definition 2.9. 3.15. Definition. A polynomial f E IF ,[x] of degree m;;, I is called a primitive polynomial over F q if it is the minimal polynomial over IF q of a primitive element of IF q'"· Thus. a primitive polynomial over F, of degree m may be described as a monic polynomial that is irreducible over F q and has a root a E IF q"' that generates the multiplicative group ofF, •. Primitive polynomials can also be characterized as follows. 3.16. Theorem. A polynomial f EIF,[x] of degree m is a primitive polynomial over IF,1 if and only iff is monic, f(O)"' 0, and ord(/) � qm-I. Proof Iff is primitive over IF q• then f is monic and /(0)"' 0. Since f is irreducible over F q• we get ord( f)� qm-I from Theorem 3.3 and the fact that f has a primitive element of IF,. as a root. Conversely, the property ord( f)� qm-I implies that m;;, I. Next, we claim that f is irreducible over IF,. Suppose f were reducible over IF q· Then f is either a power of an irreducible polynomial or it can be written as a product of two relatively prime polynomials of positive degree. In the first case, we have[� g' with g E Fq[x] irreducible over F,. g(O)"' 0, and b;;, 2. Then, according to Theorem 3.8, ord( f) is divisible by the characteristic of IF q• but qm - I is not, a contradiction. In the second case, we have f = g1 g2 with relatively prime monic polynomials g1, g2 E IF q[x] of positive degree m1 and m2, respectively. If e,�ord(g,) for i�I.2, then ord(f)..;;e1e2 by Theorem 3.9. Furthermore. ei � q'"' -I fori= 1,2 by Lemma 3.1, hence ord(f)" (qm• -l)(qm' -I)< qm,+m, -I� qm -I, a contradiction. Therefore, f is irreducible over IF q• and it follows then from Theorem 3.3 that/is a primitive polynomial over F,. D We remark that the condition f(O)"' 0 in the theorem above is only needed to rule out the non-primitive polynomial f(x) � x in case q � 2 and m = I. Still another characterization of primitive polynomials is based on the following auxiliary result. 3.17. Lemma. Let f E IF q[x] be a polynomial of positive degree with /(0)"' 0. Let r he the least positive integer for which x' is congruent mod f( x) tv some element ofF,. so that x' = amodf(x) with a uniquely determined 1. Order of Polynomials and Primitive Polynomials 81 a E F;. Then ord(/) =hr. where his the order of a in the multiplicative group IF* q. Proof Put e = ord(/). Since x' =I modf(x), we must have e;. r. Thus we can write e = sr + 1 with s EN and 0 � t < r. Now ( 3 .I) thus x' = a-'modf(x), and because of the definition of r this is only possible if t = 0. The congruence (3.1) yields then a'= I modf(x), thus a'= I, and so s;. h and e;. hr. On the other hand, x•' = a• =I mod f(x), and so e =hr. D 3.18. Theorem. The monic polynomial f E F,[x] of degree m ;.I is a primitive polynomial over IF, if and only if( -1)"'/(0) is a primitive element of IF, and the least positive integer r for which x' is congruent modf(x) to some element of IF, is r= (qm -1)/(q -I). In case /is primitive over F,. we have x' = ( -l)m/(O)modf(x). Proof Iff is primitive over F ,. then f has a root a E IF, •• which is a primitive element of IF, •. By calculating the norm NF,.;F,(a) both by Definition 2.27 and by (2.3) and observing that f is the character istic polynomial of a over IF,. we arrive at the identity ( -l)m /(0) = a'•"-1)/(q-1)_ (3.2) It follows that the order of ( -l)m/(0) in F; is q -);that is, ( -l)m/(0) is a primitive element of F ,. Since f is the minimal polynomial of a over IF,. the identity (3.2) implies that x<•"-l)/(q-l) = (-I )m /(0) mod /(x ), and so r .;;(qm-i)j(q-1). But Theorem 3.16 and Lemma 3.17 yield qm -I= ord(/).;; (q -i)r, thus r = (qm -i)j(q -I). Conversely, suppose the conditions of the theorem are satisfied. It follows from r = (qm -1)/(q -I) and Lemma 3.17 that ord(/) is relatively prime to q. Then Theorem 3.11 shows that f has a factorization of the form f = /1 • • ·f., where the/, are distinct monic irreducible polynomials over IF,. If m, � deg(/;), then ord(/,) divides qm, -I for ! .;; i.;; k according to Corollary 3.4. Now qm,-I divides d = ( qm' -I) .. · ( qm' -J )/ ( q-J) k-1, thus ord(/1) divides d for 1 .;; i.;; k. It follows from Lemma 3.6 that /,(x) divides x" -I for 1 .;; i.;; k, and so f(x) divides x'-!."If k;. 2, then a contradiction to the definition of r. Thus k =I andfis irreducible over IF,. 82 Polynomials over Finite Field!> If {3 E F •• is a root of f. then the argument leading to (3.2) shows that {3'�(-1)"'/(0), and so x'=(-1)"'/(0)mod/(x). Since the order of (-1)"'/(0) in!'; is q -1, it follows from Lemma 3.17 that ord(/) � q"' -1, so that/is primitive over F• by Theorem 3.16. D 3.19. Example. Consider the polynomial /(x)�x4+x3+x2+2x+2E F 3 [ x ]. Since f is irreducible over F 3, one can use the method outlined after Theorem 3.11 to show that ord( /) � 80 � 34 - 1. Consequently, f is primi­ tive over IF3 by Theorem 3.16. We have x40 = 2modf(x) in accordance with Theorem 3.18. D 2. IRREDUCIBLE POLYNOMIALS We recall that a polynomial f E F •[x] is irreducible over IF q iff has positive degree and every factorization of f in IF.(x] must involve a constant polynomial (see Definition 1.57). Elementary properties of irreducible poly­ nomials over F q were discussed in Chapter 2, Section 2. 3.20. Theorem For every finite field IF• and every n E I'll, the prod­ uct of all monic irreducible polynomials over F q whose degrees divide n is equal to xq"-x. Proof According to Lemma 2.13, the monic irreducible polynomi­ als over F q occurring in the canonical factorization of g( x) = xq"- x in IF•[x] are precisely,those whose degrees divide n, Since g'(x) � -1, Theo­ rem 1.68 implies that g has no multiple roots in its splitting field over F , q ' and so each monic irreducible polynom!al over F q whose degree divides n occurs exactly once in the canonical factorization of gin Fq[x], D 3.21. CoroiJJJry. If N•( d) is the number of monic irreducible poly­ nomials in F.[x] of degree d, then q"� '[,dN.(d) fora/In EN, (33) din where the sum is extended over all positive divisors d of n. Proof The identity (33) follows from Theorem 3,20 by comparing the degree of g(x) � x•"-x with the total degree of the canonical factoriza­ tion ofg(x), D With a little elementary number theory we can derive from (33) an explicit formula for the number of monic irreducible polynomials in F.[x] of fixed degree, We need an arithmetic function, called the Moebius function, which is defined as follows. 2. Irreducible Polynomials 83 3.22. Definition. The Moebius function p. is the function on I'll defined by ifn=l, if 11 is the product of k distinct primes, if 11 is divisible by the square of a prime. As in (3.3), we use the summation symbol L:Jin to denote a sum extended over all positive divisors d of 11 E 1'\1. A similar convention applies to the product symbol ndi•' 3.23. Lemmo. For 11 E I'll the Moebius function p. satisfies ifn=!, ifn >I. Proof For 11 > I we have to take into account only those positive divisors d of 11 for which p.(d) * 0-that is, for which d =I or dis a product of distinct primes. Thus, if p1, p2, ... ,p, are the distinct prime divisors of n, we get k I;p.(d)=p.(ll+ I: p.(p,)+ I: p.(p,,p,,l+ ··· +p.(p,p,···p.J dl• i-1 l<;i\<i1"k =1+(7)<-ll+(;)<-Jl'+ ... +(Z)<-1)' =(1+(-!))'=0. The case n = I is trivial. D 3.24. Theo,..m (Moebius Inversion Formula) (i) Additive case: Let h and H be two functions from I'll into an additively written abelian group G. Then H( n) = L h (d) for a/In E I'll (3 .4) din if and only if h(n)= LP.(�)H(d)= LP.(d)H(�) fora//nEi'\1. (3.5) din din (ii) Multiplicative case: Let h and H be two functions from I'll into a multiplicativel y written abelian group G. Then H(n) = 0h(d) fora/In El'll (3.6) din foral/nEN. (3.7) 84 Polynomials over Finite Fields Proof Assuming (3.4) and using Lemma 3.23, we get LI'(�)H(d)= Ll'(d)H(�)= Ll'(d) L h(c) dfn dill dfn cfn/d = L L !'(d)h(c) = Lh(c) L !'(d)= h(n) cfn dln/c dln/c for all n E 1\1. The converse is derived by a similar calculation. The proof of part (ii) follows immediately from the proof of part (i) if we replace the sums by products and the multiples by powers. D 3. 25. Theorem. The number N, ( n ) of monic irreducible polynomials in F q[ x] of degree n is given by N,(n) =.!. L I'(�) q" =.!. L !'(d) q•ld. n din d n din Proof We apply the additive case of the Moebius inversion formula to the group G = l, the additive group of integers. Let h(n) = nN,(n) and H(n) = q" for all n E 1\1. Then (3.4) is satisfied because of the identity (3.3), and so (3.5) already gives the desired formula. D 3.26. Example. The number of monic irreducible polynomials in F,[x] of degree 20 is given by N,(20) = fo(!'(l)q20 + !'(2)q10 + !'(4)q5 + !'(5)q4 + !'(IO)q2 + !'(20)q) D It should be noted that the formula in Theorem 3.25 shows again that for every finite field IF • and every n E 1\1 there exists an irreducible polynomial in IF,[x] of degree n (compare with Corollary 2.11). Namely, using I' (I)= I and !'(d);. -I for all dE 1\1, a crude estimate yields N(n);..!.(q•-q•-l-qn-2_ ... -q)=.!.(q•-q"-q) >0. • n n q-1 As another application of the Moebius inversion formula, we estab­ lish an explicit formula for the nth cyclotomic polynomial Q •. 3.27. Theorem. For a field K of characteristic p and n E 1\1 not divisible by p, the nth cyclotomic polynomial Q. over K satisfies Q.(x)= O(x"-1)"'"1"1= O(x•l"-1)"'"1 dfn din Proof We apply the multiplicative case of the Moebius inversion formula to the multiplicative group G of nonzero rational functions over K. Let h(n) = Q.(x) and H(n) = x" -I for all n E 1\1. Then Theorem 2.45(i) shows that (3.6) is satisfied, and so (3.7) yields the desired result. D 2. Irreducible Polynomials 3.28. Example. For fields Kover which Q12 is defined, we have Qn(x) = n (x"fd -I)"(di d\ 12 = (x12 -1)"('1(x6 -1)"(2\x4 -1)"(31(x3 -1)"(41 (x2 -1)"('\x -1)"(121 (x12 -l)(x2 -1) = = x4- x2 +I. (x' -l)(x4 -I) 85 D The explicit formula in Theorem 3.27 can be used to establish the basic properties of cyclotomic polynomials (compare with Exercise 3.35). In Theorem 3.25 we determined the number of monic irreducible polynomials in F.[xl of fixed degree. We present now a formula for the product of all monic irreducible polynomials in F .[xI of fixed degree. 3.29. Theorem. The product /( q, n; x) of all monic irreducible poly­ nomials in F.[xl of degree n is given by I(q. n; x) = n (x•'-x)"(n/dl = n (x•""-x)"(dl din din Proof It follows from Theorem 3.20 that x•"-x= nl(q,d;x). din ' We apply the multiplicative case of the Moebius ;�version formula to the multiplicative group G of nonzero rational functions over F •• putting h(n)=I(q,n;x) and H(n)=x•"-x for all nEN, and we obtain the desired formula. D 3.30. Example. For q = 2, n = 4 we get /(2,4; X)= (x16-X )"(l)(x4-X )"(2\x2-X )"(4) x16- x x15-I --- x4-x x3 -I = xl2 + x9 + x6 + xJ +I. D All monic irreducible polynomials in IF • [xI of degree n can be determined by factoring I(q, n; x). For this purpose it is advantageous to have /( q, n; x) available in a partially factored form. This is achieved by the following result. 3.31. Theorem. Let I(q, n;x) be as in Theorem 3.29. Then for n >I we have I(q, n; x) = TI Qm(x), (3.8) m 86 Polynomials over Finite Fields where the product is extended over all positive divisors m of q• -I for which n is the multiplicative order of q modulo m, and where Qm(x) is the mth cyclotomic polynomial over F q· Proof For n >I let S be the set of elements of F q" that are of degree n over F q· Then every a E S has a minimal polynomial over IF q of degree n and is thus a root of J(q, n; x). On the other hand, if {J is a root of J(q, n; x), then {J is a root of some monic irreducible polynomial in IF•[x] of degree n, which implies that {J E S. Therefore, I(q,n;x) � 0 (x-a). aES If a E S, then a E IF;., and so the order of a in that multiplicative group is a divisor of q"-I. We note that y E F;. is an element of a proper subfield F •" of F•" if and only if y•'� y-that is, if and only if the order of y divides qd-I. Thus, the order m of an element a of S must be such that n is the least positive integer with q• =I mod m -that is, such that n is the multi­ plicative order of q modulo m. For a positive divisor m of q•-I with this property, lets., be the set of elements of S of order m. Then Sis the disjoint union of the subsets sm. so that we can write I(q,n;x)�O 0 (x-a). m aESm Now Sm contains exactly all elements of r; .. of order m. In other words, Sm is the set of primitive mth roots of unity over F q· From the definition of cyclotomic polynomials (see Definition 2.44), it follows that n (x-a)�Qm(x), aES,.. and so (3.8) is established. D 3.32. Example. We determine all (monic) irreducible polynomials in F2[x] of degree 4. The identity (3.8) yields /(2,4; x) � Q1(x)Q11(x) . By Theorem 2.47(ii), Q,(x) � x4 + x' + x2 + x +I is irreducible in F2[x]. By the same theorem, Q11(x) factors into two irreducible polynomials in F2[x] of degree 4. Since Q1(x+l)�x4+x3+1 is irreducible in IF2[x], this polynomial must divide Q11(x), and so Q11(x) �x8+ x1+ x' + x4 + x3 + x+ I= (x4 + x3 + l)(x4 + x+ 1). Therefore, the irreducible polynomials in IF2[x] of degree 4 are x4 + x' + x2 +x+l,x4+x3+l,andx4+x+l. D Irreducible polynomials often arise as minimal polynomials of ele­ ments of an extension field. Minimal polynomials were introduced in Definition 1.81 and their fundamental properties established in Theorem 1.82. With special reference to finite fields, we summarize now the most useful facts about minimal polynomials. 3. Construction of lrreduci�le Polynomi als 87 3.33. Theorem. Let a be an element of the extension field F q• of IF q· Suppose that the degree of a over !' • is d and that g E F •[ x] is the minimal polynomial of a over IF q· Then: (i) g is irreducible over IF • and its degree d divides m. (ii) A polynomial f E F q[x] satisfies/( a)= 0 if and only if g divides f. (iii) Iff is a monic irreducible polynomial in IF•[x] with f(a) = 0, thenf =g. (iv) g(x) divides x•'-x and x•"-x. (v) The roots of g are a,a•, ... ,a•'-', and g is the minimal poly­ nomial over IF• of all these elements. (vi) If a"' 0, then ord(g) is equal to the order of a in the multiplica­ tive group F: .... (vii) g is a primitive polynomial over F • if and only if a is of order d I . F* q - m q"'· Proof (i) The first part follows from Theorem 1.82(i) and the second part from Theorem 1.86. (ii) This follows from Theorem 1.82(ii). (iii) This is an immediate consequence of (ii). (iv) This follows from (i) and Lemma 2.13. (v) The first part follows from (i) and Theorem 2.14 and the second part from (iii). (vi) Since aE F;, and F;, is a subgroup of F; •. the result is contained in Theorem 3.3. (vii) If g is primitive over F •• then ord( g) = qd -I, and so a is of order qd-I in F ;. because of (vi). Conversely, if a is of order qd-I in F;. and so in F;c�, then a is a primitive element of F qJ, and therefore g is primitive over F • by Definition 3.15. D 3. CONSTRUCllON OF IRREDUCIBLE POLYNOMIALS We first describe a general principle of obtaining new irreducible polynomi­ als from known ones. It depends on an auxiliary result from number theory. We recall that if n is a positive integer and the integer b is relatively prime to n, then the least positive integer k for which b• = I mod n is called the multiplicative order of b modulo n. We note that this multiplicative order divides any other positive integer h for which b' =I mod n. 3.34. Lemma_ Let s;;. 2 and e;;. 2 be relatively prime integers and let m be the multiplicative order of s modulo e. Let 1;;. 2 be an integer whose prime factors divide e but not (sm-l)je. Assume also that sm =I mod4 if I= 0 mod4. Then the multiplicative order of s modulo et is equal to mt. 88 Polynomials over Finite Fields Proof We proceed by induction on the number of prime factors of t, each counted with its multiplicity. First, lett be a prime number. Writing d = (sm -l)je, we have sm =I+ de, and so sm' =(I+ de)' =l+(:)de+(�)d2e2+ ... +(,�1)d'-1e'-1+d'e'. In the last expression, each term except the first and the last is divisible by et because of a property of binomial coefficients noted in the proof of Theorem 1.46. Furthermore, the last term is divisible by et since t divides e. Therefore, sm' =I mod et, and so the multiplicative order k of s modulo et divides mi. Also, s• = I mod et implies s• =I mode, and so k is divisible by m. Since I is a prime number, k can only be m or mi. If k = m, then sm =I mod et, hence de= Omod et and I divides d, a contradiction. Thus we must have k = mt. Now suppose that I has at least two prime factors and write I= rt0, where r is a prime factor of I. By what we have already shown, the multiplicative order of s modulo er is equal to mr. If we can prove that each prime factor of 10 divides er but not d0 = (sm' -l)jer, then the induction hypothesis applied to 10 yields that the multiplicative order of s modulo ert0 = et is equal to mrt0 = mt. Let r0 be a prime factor of 10• Since every prime factor of t divides e, it is trivial that r0 divides er. We write again d = (sm-I)/e. We havesm'-I= c(sm -I) with c = sm(,-ll + · · · + sm +I, thus d0 = c(sm -l)jer = cdjr. Furthermore, since sm =I mode and r divides e, we get sm=Imodr, and so c=r=Omodr. Thus cjr is an integer. Since r0 does not divided, it suffices to demonstrate that r0 does not divide cj r in order to prove that r0 does not divide d0 = cd j r. We note that sm=Imodr0, and so c=rmodr0• If r0*r, then cjr=lmodr0, thus r0 does not divide cjr. Now let r0=r. Then sm=I+brmodr2 for some bE Z, hence sm; = (I + br); =I + jbrmod r2 for all j:;. 0, and thus It follows that ,_, r(r-1) c=r+brL,J=r+br modr2 j-0 2 c r(r-I) -=l+b modr r 2 · If r is odd, then cjr =I mod r, so that r0 = r does not divide cjr. In the remaining case we have r0 = r = 2. Then t = Omod4, and so sm =I mod4 by hypothesis. Since c=sm +I in this case, we get c= 2mod4, and thus c I r = c j2 = I mod 2. It follows again that r0 does not divide c j r. D 3.35. Theorem. Let f1 ( x ), /2 ( x ), ... ,f N ( x) be all the distinct monic irreducible polynomials in IF•[x] of degree m and order e, and lett:;. 2 be an 3. Construction or Irreducible Polynomials 89 integer whose prime factors divide e but not (qm-I)/e. Assume also that qm = lmod4 ift = Omod4. Thenf1(x')./2(x'), ... JN(x') are all the distinct monic irreducible polynomials in f•[x] of degree mt and order et. Proof The condition one implies e;;. 2. According to Theorem 3.5, monic irreducible polynomials in F•[x] of degree m and order e;;. 2 exist only if m is the multiplicative order of q modulo e, and then N� cj>(e)/m. By Lemma 3.34, the multiplicative order of q modulo et is equal to mt, and since cj>(el)/ml � cj>(e)/m by the formula in Exercise 1.4, part (c), it follows that the number of monic irreducible polynomials in IF q[ x] of degree ml and order et is also equal to N. Therefore, it remains to show that each of the polynomials f;(x'), IE; j E; N, is irreducible in F q[x] and of order et.· Since the roots of each /;(x) are primitive e th roots of unity over F • by Theorem 3.3, it follows that /;(x) divides the cyclotomic polynomial Q,(x) over f •. Then /;(x') divides Q,(x'), and repeated use of the property enunciated in Exercise 2.57, part (b), shows that Q,(x') � Q.,(x). Thus /;(x') divides Q,.(x). According to Theorem 2.47(ii), the degree of each irreducible factor of Q.,(x) in f•[x] is equal to the multiplicative order of q modulo et, which is mi. Since /;(x') has degree ml, it follows thatf;-(x') is irreducible in IF q[x]. Furthermore, since /;-(x') divides Q.,(x ), the order of /;(x') is et. 0 3.36. Example. The irreducible polynomials in F2[x] of degree 4 and order 15 are x4 + x +I and x4 + x3 +I. Then the irreducible polynomials in F2[x] of degree 12 and order 45 are x12 + x3 +I and x12 + x9 +I. The irreducible polynomials in F2[x] of degree 60 and order 225 are x60 + x" +I and x60 + x45 +I. The irreducible polynomials in F2[x] of degree 100 and order 375 are x"10 + x2' +I and x"10 + x 75 +I. 0 The case in which t = Omod4 and qm = -lmod4 is not covered in Theorem 3.35. Here we must have q =-I mod4 and m odd. The result referring to this case is somewhat more complicated than Theorem 3.35. 3.37. Theorem. Let f1(x), f2(x), ... JN(x) be all the distinct monic irreducible polynomiaLs in F•[x] of odd degree m and of order e. Let q = 2"u-I, t � 2•v with a, b;;. 2, where u and v are odd and all prime factors oft divide e but not (qm-I)/e. Let k be the smaller of a and b. Then each of the polynomials f;(x') factors as a product of 2•-• monic irreducible polynomiaLs giJ(x) in F•[x] of degree mt2•-•. The 2•-•N polynomials giJ(x) are all the distinct monic irreducible polynomials in F q[ x] of degree ml21 -k and order et. Proof If v;;. 3, then Theorem 3.35 implies thatf1(x"), f2(x"), ... , fN(x") are all the distinct monic irreducible polynomials in F•[x] of odd degree mv and of order ev. Thus we will be done once the special case I� 2• is settled. Let now t � 2•, and note that as in the proof of Theorem 3.35 we obtain that m is the multiplicative order of q modulo e, N � cj>( e)/ m, and 90 Polynomials over Finite Fields eachfj(x') divides Q.,(x). By Theorem 2.47(ii), Q.,(x) factors into distinct monic irreducible polynomials in F•[x] of degree d, where dis the multi­ plicative order of q modulo el. Since q• =I model, we have q• = I mode, and so m divides d. Consider first the case a;;. b. Then q2m -I= (qm -l)(qm +I), and the first factor is divisible bye, whereas the second factor is divisible by I since q = -I mod2" implies q = -I mod I, and thus qm = ( -l)m"' -I modi. Altogether, we get q2m =I model, and so d can only be m or 2m. If d = m, then qm =I model, hence qm =I mod I, a contradiction. Thus d =2m= m2•-• + 1 since k = b in this case. Now consider the case a< b. We prove by induction on h that qm2" = 1 +.w2a+hmod2a+h+ 1 for all hEN, where w is odd. For h =I we get q'm = (2"u -l)'m (3.9) 2m =1-2"+1um+ L (2,7')(-1)2m-•2""u"=l+w2"+1mod2"+2 o�2 with w = -um. If (3.9) is shown for some h EN, then qm2" = 1 + w2a+h + c2a+h+ 1 for some c E Z. It follows that and so the proof of (3.9) is complete. Applying (3.9) with h = b-a+ I, we get qm2h-HI = 1 mod2b+ 1. Furthermore, qm = 1 mode implies qm2b-a+, = I mode, and so qm2•--.' = I mod L, where L is the least common multiple of 2•+ 1 and e. Now e is even since all prime factors of 1 divide e, but also e $ Omod4 since qm =I mode and qm =-I mod4. Therefore, L = e2• = el, and thus qm2'-•" =I model. On the other hand, using (3.9) with h = b-a we get qm2o-. =I+ w2• ;t; I mod2b+ 1, which implies qm2•-· *I model. Consequently, we must have d = m2•-• + 1 -m2•->+ 1 since k =a in this case. Therefore, the formula d = m2•->+ 1 = ml 21 -• is valid in both cases. Since Q.,(x) factors into distinct monic irreducible polynomials in F•[x] of degree ml21-•, each Jj(x') factors into such polynomials. By comparing degrees, the number of factors is found to be 2• -I Since each irreducible factor g1;(x) off,(x') divides Q.,(x), each g,)x) is of order el. The various polynomials g1;(x), I<; i.;; 2•-1, I<; j.; N, are distinct, for otherwise one such polynomial, say g(x), would dividefj,(x') andfj,(x') for }1 * }2, and then any root P of g(x) would lead to a common root P' of Jj,(x) and Jj,(x), a contradiction. By Theorem 3.5, the number of monic 3. Construction of Irreducible Polynomials irreducible polynomials in IF •[ x 1 of degree mt21-• .p(et)/mt2'.-• = 2•-•.p(et)/mt = 2•-•.p(e)/m = 2•-•N, yield all such polynomials. 91 and order et is and so the g,1(x) D We will show how, from a given irreducible polynomial of order e, all the irreducible polynomials whose orders divide e may be obtained. Since in all cases g(x) = x will be among the latter polynomials, we only consider polynomials g with g(O) * 0. Let f be a monic irreducible polynomial in IF •[ x 1 of degree m and order e and with f(O),. 0. Let a E F •• be a root off, and for every IE N let g, E IF•[x1 be the minimal polynomial of a' over F •. Let T=(t,.t2, ••• ,t.) be a set of positive integers such that for each tEN there exists a uniquely determined i, '"' i"' n, with t = t,q•mod e for some integer b ;lo 0. Such a set T can, for instance, be constructed as follows. Put 11 =I and, when 11,12, ... ,11_; have been constructed, let t1 be the least positive integer such that t1 ;;E t,q•mode for 1,. i < j and all integers b ;lo 0. This procedure stops after fmitely many steps. With the notation introduced above, we have then the following general result. 3.38. Theorem. The polynomials g,,, g,,, ... ,g," are all the distinct monic irreducible polynomials in F•[x1 whose orders divide e and whose constant terms are nonzero. Proof Each g,, is monic and irreducible in IF•[x1 by definition and satisfies g, (0) * 0. Furthermore, since g, has the root a'• whose order in the group F;.'divides the order of a, it follows from Theorem 3.3 that ord(g,,) divides e. Let g be an arbitrary monic irreducible polynomial in F .[x1 of order d dividing e and with g(O) * 0. If Pis a root of g, then pd =I implies P' -1, and so P is aneth root of unity over F •. Since a is a primitive eth root of unity over f •• it follows from Theorem 2.42(i) that P =a' for some tEN. Then the definition of the set T implies that I"' t,q•mode for some i, '"' i"' n, and some b ;lo 0. Hence p =a'-(a'•)•', and so P is a root of g, because of Theorem 2.14. Since g is the minimal polynomial of p over F •' ii follows from Theorem 3.33(iii) that g = g,,. It remains to show that the polynomials g,, '"' i"' n, are distinct. Suppose g,, = g, for i * j. Then a'• and a'' ar� roots of g, , and so a''= ( a'•)•' for �me b ;lo 0. This implies 11 = t,q•mod e, but sin.;. we also have t1 = t1q0mode, we obtain a contradiction to the definition of the set T. D The minimal polynomial g, of a' E F •• over IF • is usually calculated by means of the characteristic polynomial !, of a' E F •• over F •. From the discussion following Definition 2.22 we know that !, = g;, where r = m / k and k is the degree of g,. Since g, is irreducible in F q[x], k is the multiplicative order of q modulo d = ord(g,), and dis equal to the order of 92 Polynomials over Finite Fields a' in the group IF; •• which is ejgcd(t,e) by Theorem 1.15(ii). Therefore d, and so k and r, can be determined easily. Several methods are known for calculating /,. One of them is based on a useful relationship between!, and the given polynomial f. 3.39. Theorem. Let f be a monic irreducible polynomial in F•[x] of degree m. Let a E F •" be a root off, and /or IE N let/, be the characteristic polynomial of a' E IF q" over F •. Then ' /,(x') = ( -\)m(<+ I) n /( WjX ), J-1 where w 1, ••• , w, are the t th roots of unity over IF q counted according to multiplicity. Proof Let a= a1, a2, ••. ,am be all the roots off. Then a�, a�, ... ,a� are the roots of/, counted according to multiplicity. Thus "' /,(x') = n (x' -,a:) i-1 "' = n n (x-a,wj) i-! J-! "' ' = n n "'A"'1�'x-a,). i-lj-1 A comparison of coefficients in the identity ' x'-1= n (x-w) J-l shows that and so I Ow1=(-1)'+1, j-l I m f,(x') = ( -l)m(<+l) n n (..,}�IX-a,) j-! i-1 I < = ( -\)m(<+l) n /( Wj�IX) = ( -\)m(<+l) n f(w1x) J-! j-l since w 1', ... , w,� 1 run exactly through alii th roots of unity over IF q· D 3.40. Example. Consider the irreducible polynomial f(x) = x4 + x +I in F2[x ]. To calculate /3, we note that the third roots of unity over F2 are I, w, 3. Construction of Irreducible Polynomials and w2, where w is a root of x2 + x+ I in F4• Then /3 (x3) = ( -1)16/(x )/( wx )/( w2x) = (x4 + x + 1)( wx4 + wx + 1)( w2x4 + w2x +I) =x12+x9+x6+x3+1, so thatf3(x) = x4 + x3 + x2 + x +I. 93 D Another method of calculating /, is based on matrix theory. Let f(x)=xm-am-lxm-l_ ··· -a1x-a0andletA be the companion matrix off, which is defined to be the m X m matrix 0 0 0 A= 0 0 0 0 0 0 Then f is the characteristic polynomial of A in the sense of linear algebra; that is, f(x) = det(x/-A) with I being the m X m identity matrix over F q· For each tEN,/, is the characteristic polynomial of A', the tth power of A. Thus, by calculating the powers of A one obtains the polynomials f.. 3.41. Example. It is of interest to determine which polynomials /, are irreducible in IF•[x1. From the discussion prior to Theorem 3.39 it follows immediately that/, is irreducible in F .[x 1 if and only if k = m, that is, if and only if m is the multiplicative order of q modulo d = ejgcd(t, e). Consider, for instance, the case q = 2, m = 6, e = 63. Since the multiplicative order of q modulo a divisor of e must be a divisor of m, the only possibilities for the multiplicative order apart from m are k =I, 2, 3. Then q•-I= I, 3, 7, and q•=imodd is only possible when d=l,3,7. Thus/, is reducible in IF2[x1 precisely if gcd(l, 63) = 9, 21, 63. Since it suffices to consider values oft with I.; t.; 63, it follows that /, is irreducible in IF2[x 1 except when I= 9, 18,21,27,36,42,45, 54,63. D In practice, irreducible polynomials often arise as minimal polynomi­ als of elements in an extension field. If in the discussion above we let f be a primitive polynomial over F q• so that e = qm -I, then the powers of a run through all nonzero elements of F ••. Therefore, the methods outlined above can be used to calculate the minimal polynomial over IF • of each element of F: .... A straightforward method of determining minimal polynomials is the following one. Let 8 be a defining element of F q" over F •• so that {1,8, ... ,8m-l) is a basis of IF •• over F •. In order to find the minimal polynomial g of /lEF;. over F •. we express the powers fl0,fl1, ••• ,pm in 94 Polynomials over Finite Fields terms of the basis elements. Let m {31-1= � biJ8J-l for l.;;i.;;m+l. i-1 We write gin the form g(x) = cmxm + ... + c,x +Co. We want g to be the monic polynomial of least positive degree with g({3) = 0. The condition g({3) = cmpm + · · · + c1{3 + c0 = 0 leads to the homogeneous system of linear equations m+l � c1_1biJ=O for l.;;j.;;m i-1 (3.10) with unknowns c0,c1, ••• ,cm. Let B be the matrix of coefficients of the system-that is, B is the (m + l)Xm matrix whose (i, j) entry is b11-and let r be the rank of B. Then the dimension of the space of solutions of the system iss= m +I-r, and since !.;; r.;; m, we have I.;; s.;; m. Therefore, we can prescribe values for s of the unknowns c0,c1, ••. ,cm, and then the remaining ones are uniquely determined. If s =I, we set em= I, and if s >I, we set em= cm-1-... = cm-s+2 = 0 and cm-s+l-1. 3.42. Example. Let 8 E IF 64 be a root of the irreducible polynomial x' + x +I in F2[x]. For {3 = 83 + 84 we have {3°= I P' = 83+84 P'= I +8 + 82+ 83 P'= 8+8'+8' {34= 8 + 82 +84 P'=l +83+84 P'= I +8 + 8' +84 Therefore, the matrix B is given by I 0 0 0 0 0 0 0 I I I I I I 0 B= 0 I I I 0 0 I I 0 I I 0 0 I I I I I 0 I 0 0 0 0 0 0 0 and its rank is r = 3. Hence s = m + I -r = 4, so that we set c6 = c, = c4 = 0, c3 -1. The remaining coefficients are determined from (3.10), and this yields c2 =I, c1 = 0, c0 -1. Consequently, the minimal polynomial of {3 over F2isg(x)=x3+x2+1. D Still another method of determining minimal polynomials is based on Theorem 3.33(v). If we wish to find the minimal polynomial g of {3 E F •• 3. Construction of Irreducible Polynomials 95 over IF •. we calculate the powers {3, {3<, (3•', ... until we find the least positive integer d for which {3•' � {3. This integer dis the degree of g, and g itself is given by g(x)� (x-{3)(x-{3•)· · · (x-(3<'-'). The elements {3, {3 • .... , {3 •'-' are the distinct conjugates of {3 with respect to IF,. and g is the minimal polynomial over IF • of all these elements. 3.43. Example. We compute the minimal polynomials over IF2 of all elements of IF 16. Let 0 E IF 16 be a root of the primitive polynomial x4 + x +I over F2, so that every nonzero element of IF 16 can be written as a power of 8. We have the following index table for IF 16: O' 0' 0 I 8 I+ 02 I 0 2 O' 9 0 + 03 3 03 10 I+ 0 + 02 4 I+ 0 II 0+02+0 3 5 0 + 02 12 1+0+0 2+03 6 02 + 03 13 1+02+03 7 I+ 0 + 03 14 I+ 03 The minimal polynomials of the elements {3 ofF 16 over F2 are: {3�0: g1(x)�x. {3�1: g2(x)�x+l . {3 � 0: The distinct conjugates of 0 with respect to F 2 are 0, 02, 04, 08, and the minimal polynomial is g3(x) � (x-O)(x-O')(x-04)(x-08) � x4 + x +I. {3 � 0 3: The distinct conjugates of 0 3 with respect to F 2 are 03, 06,012,024 � 09, and the minimal polynomial is g4(x) � (x-03)(x- 06)(x- O')(x-012) = x4 + x3 + x2 + x + I. {3 � 05: Since {34 � {3, the distinct conjugates of this element with respect to IF2 are 05, 010, and the minimal polynomial is g5(x)�(x-05)(x-010)�x2+x+l. {3 � 07: The distinct conjugates of 07 with respect to F2 are 01,014,028 �on, 056 � 011, and the minimal polynomial is g,(x) � (X-07 )(x- 0 II )(x-on)( X-014) = x4 + x3 +I. 96 Polynomials over Finite Fields These elements, together with their conjugates with respect to F2• exhaust F 16. 0 An important problem is that of the determination of primitive polynomials. One approach is based on the fact that the product of all primitive polynomials over F q of degree m is equal to the cyclotomic polynomial Q, with e � qm-1 (see Theorem 2.47(ii) and Exercise 3.42). Therefore, all primitive polynomials over IF q of degree m can be determined by applying one of the factorization algorithms in Chapter 4 to the cyclotomic polynomial Q ,. Another method depends on constructing a primitive element of IF q"' and then determining the minimal polynomial of this element over F q by the methods described above. To find a primitive element of F q"' one starts from the order qm-1 of such an element in the group F;. and factors it in the form qm -1 � h1 • • • h,. where the positive integers h1 .... ,h, are pair­ wise relatively prime. If for each i, I � i � k, one can find an element a, E IF:-· of order h,, then the product a1• ··"'*has order qm-1 and is thus a primitive element of F q"'· 3.44. Example. We determine a primitive polynomial over IF3 of degree 4. Since 34-1 � 16· 5, we first construct two elements of F81 of order 16 and 5, respectively. The elements of order 16 are the roots of the cyclotomic polynomial Q16(x) � x8 + 1 E IF3[x]. Since the multiplicative order of 3 modulo 16 is 4, Q16 factors into two monic irreducible polynomials in F3[x] of degree 4. Now x8 + 1 = ( x4-1)2- x4 �(x4-l+x 2)(x4-l-x 2), and so f(x) = x4-x2- 1 is irreducible over F3 and with a root (J off we have IF81 � IF3(9). Furthermore, fJ is an element of f81 of order 16. To find an element a of order 5, we write a� a+ bfJ + cfJ2 + dfJ' with a, b, c. dE IF3, and since we must have a10 = I, we get 1 = a'a = (a+ bfJ' + cfJ18 + dfJ21)( a+ bfJ + cfJ2 + d(J3) � (a-bfJ + cfJ2-dfJ' )(a+ bfJ + cfJ2 + dfJ') = (a+ cfJ2 )2-( bfJ + dfJ' )2 � a2 + (2ac-b2 )92 + ( c2-2bd )94-d2fJ6 = a2 + c2-d2 + bd+(c2 + d2- b2 -ac+ bd)fJ'- A comparison of coefficients yields a2 + c2-d2 + bd � 1, c2 + d2- b2 -ac + bd = 0. Setting a= d = 0, we get b2 = c2 = l. Take b = c = 1, and then it is easily checked that a= (J + 92 has order 5. Therefore, l" = fJa � 92 + 93 has order 80 and is thus a primitive element of F 81. The minimal polynomial g of l" 3. Construction of Irreducible Polynomials 97 over F3 is g(x) � (x-r)(x-r')(x-r')(x-f27) � (x -IJ2 -IJ')(x -I+ IJ + IJ2)(x -/}2 + IJ3)(x -1-IJ + IJ2) = x4 + x3 + x2 -x-1, and we have thus obtained a primitive polynomial over F3 of degree 4. 0 3.45. Example. We determine a primitive polynomial over F2 of degree 6. Since 26 -I� 9·7, we first construct two elements of IF6'. of order 9 and 7, respectively. The multiplicative order of 2 modulo 9 is 6, and so the cyclotomic polynomial Q9(x) � x' + x' +I is irreducible over F2. A root/} of Q, has order 9 and IF 64 � F2 ( IJ). An element a E IF;. of order 7 satisfies a8 =a, thus writing a= L.�_0a;D; with a; E F2, 0 � i � 5, we get E a,IJ' � ( E a,IJ')8 ;-o ;-o s � L a,IJ" i=O �a +a IJ8 +a IJ1 +a IJ' +a IJ' +a 1}4 0 I 2 3 4 S � a0 +a,+ a21J + a11J2 + a31J3 + ( a2 +a, )IJ4 + ( a1 + a4 )IJ', and a comparison of coefficients yields a3 � 0, a,"" a2, a4 � a2 +a,. Choose a0 �a,� a4 � 0, a,� a,� a,� I, so that a� IJ + IJ2 + IJ' is an element of order 7. Thus, f � IJa �I+ IJ2 is a primitiVe element of IF64• Then f2 � '+ IJ4• r' � IJ' + IJ' + IJ\ r• �' + IJ' + IJ'. r' �' + o + IJ'. r' �' + IJ' + IJ' + IJ4 + IJ' An application of the method in Example 3.42 yields the minimal polynomial g(x) = x' + x4 + x' +X+ I of r over F, and thus a primitive polynomial over F2 of degree 6. 0 If a primitive polynomial g over F • of degree m is known, all other such primitive polynomials can be obtained by considering a root IJ of g in IF •m and determirting the mirtimal polynomials over F • of all elements IJ', where t runs through all positive integers "qm-I that are relatively prime to qm -I. The calculation of these minimal polynomials is carried out by the methods described earlier in this section. It is useful to be able to decide whether an irreducible polynomial over a finite field remains irreducible over a certain finite extension field. The following results address themselves to this question. 3.46. Theorem. Let 1 be an irreducible polynomial over r. of degree nand let kEN. Then f factors into d irreducible polynomials in F •• [x] of the same degree n I d, where d � gcd( k, n ). 98 Polynomials over Finite Fields Proof Since the case f(O) � 0 is trivial, we can assume /(0)"" 0. Let g be an irreducible factor off in f •' [ x ]. If ord( f) � e, then also ord( g) � e by Theorem 3.3 since the roots of g are also roots of f. By Theorem 3.5 the multiplicative order of q modulo e is n and the degree of g is equal to the multiplicative order of q' modulo e. The powers qi, j � 0, !, ... ,considered modulo e, form a cyclic group of order n. Thus it follows from Theorem 1.15(ii) that the multiplicative order of q' modulo e is n/d , and so the degreeofgisn/d. 0 3.47. Corollary. An irreducible polynomial over F • of degree n remains irreducible over IF •' if and only if k and n are relatively prime. Proof This is an immediate consequence of Theorem 3.46. 0 3.48. Example. Consider the primitive polynomial g(x) � x' + x4 + x3 + x +I over F2 from Example 3.45 as a polynomial over IF 16• Then, in the notation of Theorem 3.46, we have n � 6, k � 4, and thus d � 2. Therefore. g factors in IF 16[x] into two irreducible cubic polynomials. Using the notation of Example 3.45, let g 1 be the factor that has I � I + 8 2 as a root. The other roots of g1 must be the conjugates I" and !'"' � 14 with respect to IF 16• Since these elements are also conjugates with respect to F4, it follows that g1 is actually in F4[x]. Now {3 � 121 is a primitive third root of unity over F2, and so F4 � (0, I, {3. {32). Furthermore, g1(x)�(x-n(x-l4)(x-l") � x' + U + 14 + l")x' +(I'+ 117 + l20)x + 121• We have 14 �I+ 82 + 85• I"� I+ 85, and so I+ 14 +I"� I. Similarly, we obtain I'+ 117 + 120 �I, so that g1(x) � x3 + x2 + x + {3. By dividing g by g 1 we get the second factor and thus the factorization g( x) � ( x3 + x2 + x + {3 )( x3 + x2 + x + {32) in F4[x], and hence in IF 16[x]. The two factors of g are primitive polynomi­ als over F 4, but not over IF 16. By Corollary 3.47, the polynomial g remains irreducible over certain other extension fields of F2, such as IF32 and F ,.. 0 4. LINEARIZED POLYNOMIALS Both in theory and in applications the special class of polynomials to be introduced below is of importance. A useful feature of these polynomials is the structure of the set of roots that facilitates the determination of the roots. Let q. as usual, denote a prime power. 4. Linearized Polynomials 3.49. Definition. A polynomial of the form • L(x) � L a,x•' ;-o 99 with coefficients in an extension field F q• of F q is called a q-polynomial over f ••. If the value of q is fixed once and for all or is clear from the context, it is also customary to speak of a linearized polynomial. This terminology stems from the following property of linearized polynomials. If F is an arbitrary extension field of F •• and L(x) is a linearized polynomial (i.e., a q-polynomial) over F ••. then L(f.l+y)�L(f.J)+L(y) forallf.J,yEF, (3.11) L(c/3) � cL(/3) for all c E F• and allf.J E F. (3.12) The identity (3.11) follows immediately from Theorem 1.46 and (3.12) follows from the fact that c•' � c for c E F • and i ;;. 0. Thus, if F is considered as a vector space over F •• then the linearized polynomial L(x) induces a linear operator on F. The special character of the set of roots of a linearized polynomial is shown by the following result. 3.50. Theorem. Let L ( x) be a nonzero q-polynomial over f q" and let the extension field F q' ofF q• contain all the roots of L ( x ). Then each root of L(x) has the same multiplicity, which is either . .! or a power of q, and the roots form a linear subspace of Fq'• where IFq' is regarded as a vector space over IF q· Proof It follows from (3.11) and (3.12) that any linear combination of roots with coefficients in F q is again a root, and so the roots of L ( x) form a linear subspace of IF ••. If • L(x)� L a,x•', ;-o then L'(x) � a0, so that L(x) has only simple roots in case a0 • 0. Other­ wise, we have a0 � a1 � • • • = ak-l = 0, but ak * 0 for some k;;. I, and then L ( ) -;.. q' ;.. ••• q'-( ;.. q<•-"' ··-·) •• X -£.., a;X = £.., a1 X -£.., «; X , i-k i-k i-k which is the q• th power of a linearized polynomial having only roots. In this case, each root of L ( x) has multiplicity q•. simple 0 There is also a partial converse of Theorem 3.50, which is given by Theorem 3.52. It depends on a result about certain determinants which extends Corollary 2.38. 100 Polynomials over Finite Fields 3.51. Lemma. Let {31, (32, ... , (3. be elements ofF ••. Then (3, M !3( /3(_, (3, {3!J. p!j' !3. /3." /Jnq2 (3.13} and so the determinant is * 0 if and only if {31, (32, ... ,(3. are linearly independent over F •. Proof Let D. be the determinant on the left-hand side of (3.13). We prove (3.13) by induction on n and note that the formula is trivial for n =I if the empty product on the right-hand side is interpreted as I. Suppose the formula is shown for some n ;;. I. Consider the polynomial (3, M /3(-' !3( (3, {3!J. /Jf-1 (3!J." D(x} = !3. /3." {Jnq"-I p:· ·-' x•" X x• x• By expansion along the last row we get •-1 D( x} = D.x•" + � a,x•' ;-o with a, E F ••. for 0.; i.; n -I. Assume first that {31, ... ,(3. are linearly independent over F •. We have D(/3•) = 0 for !.; k.; n, and since D(x) is a q-polynomial over F ••.• all linear combinations c1{31 + · · · + c.f3. with c• E F• for 1.; k.; n are roots of D(x). Thus D(x) has q" distinct roots, so that we obtain a factorization D(x} =D. '•· QeF, ( x-.t ck(3k )· (3.14) If {31, ... ,(3. are linearly dependent over F •. then D.= 0 and r.;_,b•/3• = 0 for some b 1, ... , b. E F •• not all of which are 0. It follows that " (" )qi � b•/3%1= � b•/3• =0 forj=O,I, ... ,n, k -I k -I and so the first n row vectors in the determinant defining D(x) are linearly 4. Linearized Polynomials 101 dependent over IF •. Thus D(x) � 0, and the identity (3.14) is satisfied in all cases. Consequently. D_.1 � D(/3,+1) � D, 0 (/3•+1-t c•/3•)· c1, .. ,c,.Ef¥ k""'l and (3.13) is established. D 3.52 Theorem. Let U be a linear subspace ofF ••• considered as a vector space over IF •. Then for any nonnegative integer k the polynomial L(x)� 0 (x-p)• • �EU is a q-polynomial over IF ••. Proof Since the q• th pow�r of a q·polynomial over F •" is again such a polynomial, it suffices to co�sider the case k � 0. Let {/31, ... ,{3.) be a basis of U over F •. Then the determinant D. on the left-hand side of (3.13) is * 0 by Lemma 3.51, and so L(x)� 0 (x-{3) �EU by (3.14), which shows already that L(x) is a q-poiynomial over F... o The properties of linearized polynomials lead to the following method of determining roots of such polynomials. Let " L(x) � L a,x•' i-0 be a q-polynomial over F ••• and suppose we want to find all roots of L(x) in the finite extension F of IF ••. As we noted above. the mapping L: {3EF....,L({3)EF is a linear operator on the vector space F over F •. Therefore, L can be represented by a matrix over IF •. Specifically, let {{31, ••• ,/3,) be a basis of Fover IF•, so that every {3 E Fcan be written in the form then ' {3 � L c1{31 with c1 E IF • for I "" j "" s; j=l ' L(/3)� L c1L(f3J. J-1 102 Polynomials over Finite Fields Now let ' L(fl;) � L b;•ll• for I.;; j.;; s, k-1 where b;• E IF • for I .;; j, k .;; s, and let B be the s x s matrix over f • whose (j, k) entry is b;•· Then, if (c1, ... ,c.)B � (d1, ... ,d.), we have L(/l) � L d.fl •. k-1 Therefore, the equation L(/l) = 0 is equivalent to (c1, ... ,c.)B � (0, ... ,0). (3.15) This is a homogeneous system of s linear equations for c 1, ••• , c ,. If r is the rank of the matrix B, then (3.15) has q'-' solution vectors (c1, ... ,c,). Each solution vector ( c1, ... , c,) yields a root fl � L.j_1c;fl; of L(x) in F. Thus, the problem of fmding the roots of L(x) in F is reduced to the easier problem of solving a homogeneous system of linear equations. 353. Example. Consider the linearized polynomial L(x) � x'-x'-ax E IF9[x], where a is a root of the primitive polynomial x2 +<-I over IF3. In order to find the roots of L(x) in IF8io we choose the basis {I,!;, !;2, !;3) of IF" over IF3, where!; is a root of the primitive polynomial x4 + x' + x2-x-I over F3 (compare with Example 3.44). Because of the orders involved, we must have a� !;10; withj �I, 3, 5, or 7, and since !;20 + !;10 -I� 0, we can take a� !;10 �-I+!;+ !;2- !;3• Next, we calculate and so we get L(i) �-a�l-!;-!;2 + !;3, L (!;) � !;' -!; ' -a!;� -!; -!;' -!; ' ' L (!;2) � !;18-!;6-a!;2 � -I+ !;3, L(!;') � !;27-!;'-a!;3 = 1-!;3, B�( 6 -I I -I -I 0 0 -I -I 0 0 -:) I . -I The system (3.15) has two linearly independent solutions, such as (0,0, I, I) and (-I, 1,0, 1). All solutions of (3.15) are obtained by forming all linear combinations of these two vectors with coefficients in F3• The roots of L(x) in F81 are then 81�0. 82�!;2+!;3, 83�-!;2-!;3, 84�-1+!;+!;3, 4. Linearized Polynomials 8,=1-t-t'. 8,=-l+t+t'-t'. 89= -l+t-r'. 103 8, ='-r-t' + t'. 8, = ,_ r + t'. 0 This method of finding roots can also be applied to a somewh at more general class of polynomials-namely, affine polynomials. 3.54. Definition. A polynomial of the form A(x) = L(x)-a., where L(x) is a q-polynomial over F •" and a E IF q•, is called an affine q-po/ynomial over IF ••. An element fl E F is a root of A(x) if and only if L(/l) =a. In the notation of (3.15), the equation L(fl) =a is equivalent to (3.16) where a=E�_1d•fl•· The system (3.16) of linear equations is solved for c1, ... ,c,, and each solution vector (c1, ... ,c,) yields a root fl=Ej.1cifli of A(x)inF. The fact that roots are easier to determine for affine polynomials suggests the following method of finding the roots of an arbitrary polynomial f( x) over f •" of positive degree in an extension field F of F... First determine a nonzero affme q-polynomia! A(x) over F •• that is divisible by f(x)-t hat is, a so-called affine multiple of f(x). Next, obtain all the roots of A(x) in F by the method described above. Since the roots of f(x) in F must be among the roots of A(x) in F, it suffices then to calculate f(fl) for all roots fl of A(x) in Fin order to locate the roots of f(x) in F. The only point that remains to be settled is how to determine an affine multiple A(x) of f(x). 1bis can be achieved as follows. Let n �I be the degree of f(x). Fori= O,l, ... ,n -I, calculate the unique polynomial r1(x) of degree .; n -I with x•' = r1(x)modf(x). Then determine elements a, E F ••. not all 0, such that E7�Ja,r,(x) is a constant polynomial. 1bis involves n - I conditions concerning the vanishing of the coefficients of xi, I.; j.; n-I, and thus leads to a homogeneous system of n-I linear equations for then unknowns a0,a1, ••• ,a"_1• Such a system always has a nontrivial solution. Once a nontrivial solution has been fixed, we have r.;�Ja,r1(x) =a for some a. E F ••. It follows that and so n-1 n-1 L a,x•'= L a,r,(x)=amodf(x), ;-o ;-o ·-· A(x)= L a,x•'-a ;-o is a nonzero affine q-polynomial over F •• divisible by f(x). It is clear that we may take A(x) to be a monic polynomial. 104 Polynomials over Finite Fields 3.55. Example. Let f(x) � x4 + O'x' +Ox'+ x + 0 E F4[x], where 0 is a root of x2 + x+ IE IF2[x]. We want to find the roots of f(x) in F64. We first determine an affine multiple A(x) of f(x) by using the method described above with q � 2. Modulo f(x) we have x = x � r0(x), x2 = x2 � r1(x), x4 = 02x3 +Ox'+ x + 0 � r2(x), x8 =Ox'+ Ox'+ x + 0 � r3(x). The con­ dition that o0r0(x) + o1r1(x) + o2r2(x) + o3r3(x) should be a constant polynomial leads to the system a0 + a2+ a3 = 0 a1+ Oa2+0a3 �o 02a2 + Oa3 � 0. We choose a3 �I and then obtain a2 � 02, a1 � 02, a0 � 0. Furthermore, a� a0r0(x )+ a1r1 (x )+ a2r2(x )+ a3r3( x) � 02, and so A(x) � a3x8 + a2x4+ a1x2 + a0x-a� x8+ 02x4+ 02x2 +Ox+ 02 Next, we calculate the roots of A(x) in F64. We have to solve the equation L(x) � 02 with the 2-polynomial L(x) � x8 + 02x4 + 02x2 +Ox over F •. Let r be a root of the primitive polynomial x6 +X+ I over IF,. Then {I, i. i2, i', i4, i'} is a basis of IF64 over F2. Since 0 is a primitive third root of unity over F2, we can take 0 � i21 �I+ i + i' + i4 + i'. Using 02�0+I�t+i' +i4+i'. we obtain L (I) r + i' + r• + i' L(i) r + r' + i' L(r') i' + i' + r• + i' L (t') r + i' + r• L(r•) i' L(r') t' + i' + r• Thus the matrix B in (3.16) is given by 0 I 0 I I I 0 I I 0 0 I B� 0 0 I I I I 0 I 0 I I 0 0 0 0 0 0 I 0 0 I I I 0 From the representation for 02 given above it follows that the vector (d1, ... ,d,) in (3.16) is equal to (0, 1,0, I, I, 1). The general solution of the system (3.16) is then ( 1,0,0,0,0,0)+ a1 (0, 1,1, 1,0,0)+ a2 (I, I, 1,0, 1,0) +a,( I, 1,0,0,0, I) 4. Linearized Polyno mials 105 with a1, a,, a3 E F2. Thus the roots of A(x) in IF64 are 1)1 �I, 1)2 �!; + !;5, 11, �!; + 1;2 + !;4,1J4 �I+ 1;2 + 1;4 + 1;5,1)5 �I+!;+ 1;2 + 1;3,1)6 � !:' + !:' + !;5, 11,�1;'+!;4, 1Js�l+!;+!;3+!;4+!;5�8. By calculating f(1J,) for j� 1,2, ... ,8, we find that the roots off(x) in !'64 are 1)3,1)5,1)7,1)8. 0 The method of determining the roots of an affine polynomial shows, in particular, that these roots form an affine subspace-that is, a translate of a linear subspace. This can also be deduced from abstract principles, together with a statement concerning multiplicities. 3.56. Theorem. Let A(x) be an affine q-polynomial over IF ••• of positive degree and let the extension field IF •• of F •• contain all the roots of A(x). Then each root of A(x) has the same multiplicity, which is either I or a power of q, and the roots form an affine subspace ofF q'• where IF •' is regarded as a vector space over F q· Proof The result about the multiplicities is shown in the same way as in the proof of Theorem 3.50. Now let A(x) � L(x)- a, where L(x) is a q-polynomial over IF•"'• and let fl be a fixed root of A(x). Then y E IF •• is a root ofA(x) if and only if L(y)�a�L(/l) if and only if L(y-fl)�O if and only if y E fl + U, where U is the linear subspace ofF •' consisting of the roots of L(x). Thus the roots of A(x) form an affine subspace of IF... 0 3.57. Theorem. Let T be an affine subspace ofF ••• considered as a vector space over IF •. Then for any nonnegative int�ger k the polynomial A(x)� 0 (x-y)•' yeT is an affine q-polynomial over F •"'· Proof Let T � 1J + U, where U is a linear subspace of f ••. Then L(x)� 0 (x-p)• • �eu is a q-polynomial over IF •" according to Theorem 3.52. Furthermore, • • A(x)� 0 (x-y)• � 0 (x-1J-fl)• �L(x-1J), yeT {jeU and L(x -1J) is easily seen to be an affine q-polynomial over IF... 0 The ordinary product of linearized polynomials need not be a linearized polynomial. However, the composition L1(L2(x)) of two q-poly­ nomials L 1 ( x ), L2 ( x) over F •• is again a q-polynomial. Instead of the word composition (or substitution) we use the phrase "symbolic multiplicat ion." Thus, we define symbolic multiplication by L1�x)®L2(x) � L1(L2(x)). 106 Polynomials over Finite Fields If we consider only q-polynomials over F ,. then a simple investigation shows that symbolic multiplication is commutative, associative, and distrib­ utive (with respect to ordinary addition). In fact, the set of q-polynomials over IF, forms an integral domain under the operations of symbolic multipli­ cation and ordinary addition. The operation of symbolic multiplication can be related to the conventional arithmetic of polynomials by means of the following notion. 3.58. Definition. The polynomials n n l(x)� L: a.1x1 and L(x)� L: a1x'' ; = 0 i=O over IF,. are called q-associates of each other. More specifically, I( x) is the conventional q-associate of L(x) and L(x) is the linearized q-associare of l(x). 3.59. Lemma. Let L 1 ( x) and L2 ( x) be q-polynomials ooer F, with conventional q-associates 11(x) and 12(x). Then l(x) � 11(x)l2(x) and L(x) � L1(x)®L2(x) are q-associates of each other. and Proof The equations l(x) � L;a,x' � L;bjx1L; c.x• � 11 (x )12 (x) 1 k L(x) � L;a,x•'� L;bj(L:c.x•')'' � L;bjL;c.x'1.,� L1(x)®L2(x) j j k j k. are each true if and only if a;= L b1ck foreveryi. j+ k-i D If L1(x) and L(x) are q-polynomials over F,, we say that L1(x) symbolically divides L(x) (or that L(x) is symbolically divisible by L1(x)) if L(x) � L1(x)®L2(x) for some q-polynomial L2(x) over IF,. The following criterion is then an immediate consequence of Lemma 3.59. 3.60. Corollary. Let L1(x) and L(x) be q-polynomials ooer F, with conventional q-associates 11(x) and l(x). Then L1(x) symbolically divides L(x) if and only if 11(x) divides l(x). 3.61. Example. Let L(x) be a q-polynomial over IF, that symbolically divides x•·-x for some mEN. Then there exists a q-polynomial L1(x) over F, such that x'"'-x � L(x )®L1 (x) � L1 (x )®L(x) � L1 (L(x )). (3.17) 4. Linearized Polynomials 107 This can be applied as follows. Let a be a fixed element of F q"· Then the affine polynomial L(x)-a has at least one root in Fq"' if and only if L1(a)�O, and if L1(a)�O, then actually all the roots of L(x)-a are in F ••. For if f3 E F •• is a root of L(x)-a, then L(/3) �a, and substituting x by {3 in (3.17) yields L1(a)�p•·-p�o. Conversely, suppose L1(a)�O and let y be a root of L(x)-a in some extension field of IF •• ; then L(y) �a, and substituting x by yin (3.17) yields y•"-y � L1(a) � 0, so that y E F ••. The polynomial L1(x) can be calculated by letting l(x) be the conventional q-associate of L(x), determining 11(x) � (xm -1)/l(x), and then taking L 1 ( x) to be the linearized q-associate of 11 ( x ). This application contains Theorem 2.25 as a special case, as one sees easily by choosing L(x)�x•-x. 0 It is an important fact that although symbolic multiplication and ordinary multiplication are quite different operations, the divisibility con­ cepts for linearized polynomials based on these operations are equivalent. ·/ .. 3.62. Theorem. Let L 1 ( x) and L( x) be q-polynomials over IF q with conventional q-associates 11 ( x) and I( x ). Then the following properties are equivalent: (i) L1(x) symbolically divides L(x); (ii) L1(x) divides L(x) in the ordinary sense; (iii) 11(x) divides l(x). Proof Since the equivalence of (i) and (iii) has been established in Corollary 3.60, it suffices to show the equivalence of (i) and (ii). If L1(x) symbolically divides L( x ), then L(x) � L1(x)®L2(x) � L2(x)®L1(x") � L,(L1(x)) for some q-polynomial L2(x) over F •. Let • L2(x) = L, a;x•', ;-o then q q" L(x)=a0L1(x)+a1L1(x) + ··· +a.L1(x) , and so L1(x) divides L(x) in the ordinary sense. Conversely, suppose L1(x) divides L(x) in the ordinary sense, where we can assume that L1(x) is nonzero. Using the division algorithm, we write l(x) � k(x)l1(x) +r(x), where deg(r(x)) < deg(l1(x)), and turning to linearized q-associates we get in an obvious notation L(x) = K(x)®L1(x) + R(x). By what we have already shown, L1(x) divides K(x)®L1(x) in the ordinary sense, and so L1(x) divides R(x) in the ordinary sense. But since deg (R(x)) < deg(L1(x)), R( x) must be the zero polynomial, and this proves that L 1 ( x) symbolically divides L( x ). o This result can be used to establish an interesting relationship between an irreducible polynomial and the irreducible factors of its lin­ earized q-associate. 108 Polynomials over Finite Fields 3.63. Theorem. Let f(x) be irreducible in F,[x] and let F(x) be its linearized q-associate. Then the degree of every irreducible factor ofF( x )/ x in f,[x] is equal to ord(/(x)). Proof Since the case f(O) � 0 is trivial, we can assume f(O) * 0. Put e � ord(/(x)) and let h(x) E F,[x] be an irreducible factor of F(x)/x of degree d. Then f(x) divides x' -I, and so by Theorem 3.62 F(x) divides x•'-x. It follows that h(x) divides x•'-x, hence d divides e by Theorem 3.20. By the division algorithm, we can write x" -I� g(x)f(x)+r(x) with g(x), r(x) E F,[x] and deg(r(x)) < deg(/(x)). Turning to linearized q-asso­ ciates, we get x•'-x � G(x) ®F(x )+ R(x ), and since h(x) divides x•·'-x and G(x)®F(x), it follows that h(x) divides R(x). If r(x) is not the zero polynomial, then r(x) and f(x) are relatively prime, and so by Theorem 1.55 there exist polynomials s(x ), k(x) E IF,[ x] with s(x)r(x)+k(x)f(x) �I. Turning to linearized q-associates, we get S(x )®R(x )+ K(x )®F(x) � x. Since h(x) divides R(x) and F(x), it follows that h(x) divides x, which is impossible. Thus r(x) is the zero polynomial, so that f(x) divides x" -I, and therefore e divides d by Lemma 3.6. Altogether, we have shown d �e. 0 We say that a q-polynomial L(x) over F, of degree >I is symboli­ cally irreducible over IF, if the only symbolic decompositions L(x) � L1(x) ®L2(x) with q-polynomials L1(x), L2(x) over F, are those for which one of the factors has degree I. A symbolically irreducible polynomial is always reducible in the ordinary sense since any linearized polynomial of degree > I has the nontrivial factor x. By using Lemma 3.59, one shows im­ mediately that the q-polynomial L(x) is symbolically irreducible over!', if and only if its conventional q-associate /(x) is irreducible over F,. Every q-polynomial L(x) over IF, of degree >I has a symbolic factorization into symbolically irreducible polynomials over F, and this factorization is essentially unique, in the sense that all other symbolic factorizations are obtained by rearranging factors and by multiplying fac­ tors by nonzero elements of IF,. Using the correspondence between lin­ earized polynomials and their conventional q-associates. one sees that the symbolic factorization of L(x) is obtained by writing down the canonical factorization in !' ,[x] of its conventional q-associate /(x) and then turning to linearized q-associates. 3.64. Example. Consider the 2-polynomial L(x) � x16 + x' + x' + x over IF2. Its conventional 2-associate /(x) � x4 + x' + x +I has the canonical 4. Linearized Polynomials factorization l(x) � (x2 + x + l)(x + 1)2 in IF2[x]. Thus, L(x)�(x4+x2+x)®(x2+x)®(x2+x) 109 is the symbolic factorization of L(x) into symbolically irreducible poly­ nomials over IF 2. D For two or more q-polynomials over IF •• not all of them 0, we may define their greatest common symbolic divisor to be the monic q-polynomial over F• of highest degree that symbolically divides all of them. In order to compare this notion with that of the ordinary greatest common divisor, we note first that the roots of the greatest common divisor are exactly the common roots of the given q-polynomials. Since the intersection of linear subspaces is another linear subspace, it follows that the roots of the greatest common divisor form a linear subspace of some extension field IF q'"• considered as a vector space over F •. Furthermore, by applying the first part of Theorem 3.50 to the given q-polynomials, we conclude that each root of the greatest common divisor has the same multiplicity, which is either I or a power of q. Therefore, Theorem 3.52 implies that the greatest common divisor is a q-polynomial. It follows then from Theorem 3.62 that the · greatest common divisor and the greatest common symbolic divisor are id enti­ cal. An efficient way of calculating the greatest common (symbolic) divisor of q-polynomials over F • is to consider the conventional q-associates and determine their greatest common divisor; then the linearized q-associate of this greatest common divisor is the greatest common (symbolic) divisor of the given q-polynomials. · By Theorem 3.50 the roots of a nonzero q-p;,lynomial over F• form a vector space over IF •. The roots have the additional property that the qth power of a root is again a root. A finite-dimensional vector space Mover F q that is contained in some extension field of IF • and has the property that the qth power of every element of M is again in Miscalled a q-modulus. On the basis of this concept we ean establish the following criterion. 3.65. Theorem The monic polynomial L(x) is a q-polynomial over IF • if and only if each root of L(x) has the same multiplicity, which is either I or a power of q. and the roots form a q-modulus. Proof The necessity of the conditions follows from Theorem 3.50 and the remarks above. Conversely. the given conditions and Theorem 3.52 imply that L(x) is a q-polynomial over some extension field of IF •. If M is the q-modulus consisting of the roots of L ( x ), then L(x)� n (x-f!)"' PEM for some nonnegative integer k. Since M � ({3•: f3 EM}, we obtain . ' L(x)•� n (x•-[3•)• � n (x•-p)• � L(x•). {lEM flEM 110 If then n L(x)� L a,x•', ;-o n n Polynomials over Finite Fields L arx• .. '�L(x)'�L(x•)� L a,x• .. ', ;-o i=O so that for 0 � i � n we have ar = a; and thus a; E IF q• Therefore, L (X) is a q-polynomial over !' ,. D Any q-polynomial over F • of degree q is symbolically irreducible over IF,. For q-polynomials of degree > q, the notion of q-modulus can be used to characterize symbolically irreducible polynomials. 3.66. Theorem. The q-polynomial L(x) over IF, of degree > q is symbolically irreducible over IF • if and only if L ( x) has simple roots and the q-modulus M consisting of the roots of L(x) contains no q-modulus other than {0} and M itself. Proof Suppose L(x) is symbolically irreducible over F,. If L(x) had multiple roots, then Theorem 3.65 would imply that we could write L(x) � L1(x)• with a q-polynomial L1(x) over!', of degree >I. But then L(x) � x•®L1(x), a contradiction to the symbolic irreducibility of L(x). Thus L(x) has only simple roots. Furthermore, if N is a q-modulus contained in M, then Theorem 3.65 shows that L2(x)�f1PEN(x-,8) is a q-polynomial over F,. Since L2(x) divides L(x) in the ordinary sense, it symbolically divides L(x) by Theorem 3.62. But L(x) is symbolically irreducible over IF,, and so deg(L2(x)) must be either I or deg(L(x)); that is, N is either {0} or M. To prove the sufficiency of the condition, suppose that L(x) � L1(x) ®L2(x) is a symbolic decomposition with q-polynomi als L1(x), L2(x) over f,. Then L1(x) symbolically divides L(x), and so it divides L(x) in the ordinary sense by Theorem 3.62. It follows that L 1 ( x) has simple roots and that the q-modulus N consisting of the roots of L 1 ( x) is contained in M. Consequen tly, N is either {0} or M, and so deg(L1(x)) is either I or deg(L(x)). Thus, either L1(x) or L2(x) is of degree I, which means that L ( x) is symbolically irreducible over !' ,. D 3.67. Definition. Let L(x) be a nonzero q-polynomial over IF, •. A root I of L ( x) is cal1ed a q-primitive root over IF q"' if it is not a root of any nonzero q-polynomial over F , •. of lower degree. This concept may also be viewed as follows. Let g( x) be the minimal polynomial of!' over F, •. Then!' is a q-primitive root of L(x) over F,. if 4. Linearized Polynomials 111 and only if g(x) divides L(x) and g(x) does not divide any nonzero q-polynomial over F •• of lower degree. Given an element I of a finite extension field of IF q"'• one can always find a nonzero q-polynomial over f q" for which !; is a q-primitive root over F ••. To see this, we proceed as in the construction of an affine multiple. Let g(x) be the minimal polynomial of !; over IF ••• let n be the degree of g(x), and calculate for i� 0, 1, ... ,n the unique polynomial r1(x) of degree" n -1 with x•' = r,(x )mod g(x ). Then determine elements a1 E IF ••• not all 0, such that E7-o a1r1(x) � 0. This involves n conditions concerning the vanishing of the coefficients of xi, 0 " j " n -1, and thus leads to a homogeneous system of n linear equations for the n + I unknowns a0, a1, ... , an. Such a system always has a nontrivial solution, and with such a solution we get n n L(x)� L a,x•'= L a,r,(x)=Omodg(x), i-0 i-0 so that L(x) is a nonzero q-polynomial over F •• divisible by g(x). By choosing the a, in such a way that L(x) is monic and of the lowest possible degree, one finds that !; is a q-primitive root of L(x) over�'··· It is easily seen that this monic q-polynomial L(x) over F •• of least positive degree that is divisible by g(x) is uniquely determined; it is called the minimal q-polynomial of !; over IF ••. 3.68. 17reorem. Let I be an element of a finite extension field ofF q" and let M( x) be its minimal q-polynomial over F ••. Then a q-polynomial K( x) over F •• has !; as a root if and only if K(x) � L(x)®M(x) for some q-polynomial L ( x) over F ••. In particular ,for the case m � 1 this means that K(x) has!; as a root if and only if K(x) is symbolical ly divisible by M(x). Proof If K(x) � L(x)®M(x) � L(M(x)), it follows immediately that K(!;) � 0. Conversely, let and suppose I M( X) = L YjXq' withy,� 1 J-0 K( x) � L a.x•' with r >I h-0 has!; as a root. Puts� r-I and y1 � 0 for j < 0, and consider the following 112 Polynomials over Finite Fields system of s +I linear equations in the s +I unknowns /J0,{31, ••• .{3,: Po+ y,<_ ,p, +yl,P, + · · · " + y•' " + ... PI 1-1P2 " + q' Ps-I Yt-1 f3s =a,_ 1 f3s = a,. It is clear that this system has a unique solution involving elements /J0,/J,, ... ,p, of "'··· With we get ' L(x)� L P,x•' and R(x)�K(x)-L(M(x)) i = 0 ' ' I � L a,x•'-L P, L yfx•"' h-0 i-0 J-0 � L a,x•'-E ( t Yt,P,)x•' h-o h-o ;-o It follows from the system above that R(x) has degree < q'. But since R(n � K(n-L(M(nJ � 0, the definition of M(x) implies that R(x) is the zero polynomial. Therefore, we have K(x) � L(M(x)) � L(x)®M(x). D We consider now the problem of determining the number NL of q-primitive roots over " • of a nonzero q-polynomial L(x) over F •. If L(x) has multiple roots, then by Theorem 3.65 we can write L(x) � L1(x)• with a q-polynomial L 1 ( x) over F q· Since every root of L( x) is then also a root of L1(x), we have NL � 0. Thus we can assume that L(x) has only simple roots. If L(x) has degree I, it is obvious that NL �I. If L(x) has degree q" >I and is monic (without loss of generality), let L(x) � L1(x)® · · · ®L1(x) ® · · · ® L,(x)® · · · ®L,(x) e, be the symbolic factorization of L(x) with distinct monic symbolically 4. Linearized Polynomials 113 irreducible polynomials L, (x) over IF •. We obtain NL by subtracting from the� total number q" of roots the number of roots of L(x) that are already rootS of some nonzero q-polynomial over F • of degree < q". If � is a root of L ( x) of the latter kind and M(x) is the minimal q-polynomial of � over r •. then deg(M(x)) < q" and M(x) symbolically divides L(x) by Theorem 3.68. It follows that M(x) symbolically divides one of the polynomials K,(x), l .; i .; r, obtained from the symbolic factorization of L ( x) by omitting the symbolic factor L,(x), in which case K1(0 � 0 by Theorem 3.68. Since every root of K,(x) is automatically a root of L(x), it follows that NL is q" minus the number of � that are roots of some K1(x). If q"• is the degree of L,(x), then the degree, and thus the number of roots, of K1(x) is q"-"•. If i 1, ••• , i .s are distinct subscripts, then the number of common roots of K, (x), ... ,K1 (x) is equal to the degree of the greatest common divisor, ' . which is the same as the degree of the greatest common symbolic divisor (see the discussion following Example 3.64). Using symbolic factorizations, one finds that this degree is equal to n-n -··· -n q 'I '•· Altogether, the inclusion-exclusion principle of combinatorics yields ' NL=q"-E q"-"s+ E qn-n,-n1� •.• +(-l)'qn-n1-··-n, i-1 l.,.;i<j<r �q"(l-q-"•)··· (1-q-"·). This expression can also be interpreted in a diffe�ent way. Let /(x) be the conventional q-associate of L ( x). Then l(x) � /1 (x )'' · .. l,(x)'' is the canonical factorization of /(x) in IF•[x], where /1(x) is the conven­ tional q-associate of L,(x). We define an analog of Euler's </>-function (see Exercise 1.4) for nonzero f E F•[x] by letting 4>•(/(x)) � ��>,(fl denote the number of polynomials in F•[x] that are of smaller degree than/as well as relatively prime to f. The following result will then imply the identity NL � 4>q(l(x)) for the case under consideration. 3.69. Lemma. The function 4> • defined for nonzero polynomials in IF •[ x] has the following properties: (i) ��>.(fl = l if deFfJ) � 0; (ii) 4>•(/g) � 4>•(/)ll>•(g) whenever f and g are relatively prime; (iii) if deg(/) � n ;;.l, then ��>.(!) � q"(l-q-"·)· .. (1-q-"·). where the n, are the degrees of the distinct monic irreducible polynomials appearing in the canonical factorization off in F .[x ]. 114 Polynomials over Finite Fields Proof Property (i) is trivial. For property (ii), let IPq(/) � s and IPq(g) � t, and let /1, ••• ,/, resp. g1, ..• ,g, be the polynomials counted by IPq(f) resp. il>q(g). If hEF.[x1 is a polynomial with deg(h)<deg(fg) and gcd(fg, h)� I, then gcd(f, h)� gcd(g, h)� I, and so h =/,mod/, h = g1mod g for a unique ordered pair (i, j) with I..; i ,;; s, I..; j..; t. On the other hand, given an ordered pair (i, j), the Chinese remainder theorem for F .[x 1 (see Exercise 1.37) shows that there exists a unique hE F .[x 1 with h=/,mod/ , h=g1modg, and deg(h)<deg(fg). This h satisfies gcd(f,h) � gcd(g, h)� I, and so gcd(fg, h)� I. Therefore, there is a one-to-one correspondence between the st ordered pairs (i, j) and the polynomi als hE IF•[x1 with deg(h) < deg(fg) and gcd(fg, h)� I. Consequently, IP•(fg) � st � IPq(fliPq(g). For an irreducible polynomial bin IF•[x1 of degree m and a positive integer e, we can calculate IPq(b') directly. The polynomials hE �'.[x1 with deg( h) < deg( b') � em that are not relatively prime to b' are exactly those divisible by b, and they are thus of the form h � gb with deg(g) <em-m. Since there are q•m-m different choices for g, we get IPq(b') � q•m-q•m-m = q'm(l-q-m). Property (iii) follows now from property (ii). D 3.70. Theorem Let L(x) be a nonzero q-polynomial over F• with conventional q-associate l(x). Then the number NL of q-primitive roots of L(x) over F • is given by NL � 0 if L(x) has multiple roots and by NL � IPq(l(x)) if L(x) has simple roots. Proof This follows from Lemma 3.69 and the discussion preceding �- D 3. 71. Corollmy. Every nonzero q-polynomial over IF • with srmple roots has at least one q-primitive root over F q· Earlier in this section we introduced the notion of a q-modulus. The results about q-primitive roots can be used to construct a special type of basis for a q-modulus. 3. 72. Theorem Let M be a q-modulus of di:nensio'!,_",';;. I over F •. Then there exists an element IE M such that { 1.1•.1• , ... ,1• } is a basis of Mover IF •. Proof According to Theorem 3.65, L(x)�npEM(x-P) is a q­ polynomial over F •. By Corollary 3.71, L(x) has a q-primitive root I over F •. Then 1.1•.1•', ... ,1•·-• are elements of M. If these elements were linearly dependent over F •• then I would be a root of a nonzero q-poly­ nomial over F • of degree less than qm � deg( L(x)), a contradiction to the definition of a q-primitive root of L ( x) over IF •. Therefore, these m elements are linearly independent over IF •• and so they form a basis of Mover IF q· D 5. Binomials and Trinomials 115 3.73. Theorem. In F •• there exist exactly <l>q(xm -I) elements !; such that (!;. !;•. !;•', ... , !;•"-') is a basis ofF •" over F q· Proof . Since IF •• can be viewed as a q-modulus, the argument in the proof of Theorem 3. 72 applies. Here L(x)� 0 (x-fJ)=x•"-x {jEfq'" by Lemma 2.4, and every q-primitive root of L(x) over IF• yields a basis of the desired type. On the other hand, if !; E F •• is not a q-primitive root of L(x) over F <' then!;, !;•, !;•' •... , !;•·-• are linearly dependent over F <' and so they do not form a basis of IF <C over IF.. Consequently, the number of !; E IF<" such that (!;, !;•, !;•', ... , !;• -') is a basis of F <" over F • is equal to the number of q·primitive roots of L(x) over "•· which is given by <l>•(xm -I) according to Theorem 3. 70. D This result provides a refinement of the normal basis theorem (compare with Definition 2.32 and Theorem 2.35). Since each of the 2 ,_I elements!;, !;•, !;• , ... ,!;• generates the same normal basis ofF •" over F <' the number of different normal bases of IF •" over IF • is given by (ljm)<l>q(xm -I). 3.74. Example. We calculate the number of different normal bases of F64 over F2. Since 64 � 26, this number is given by i<l>2(x6 -I). From the canonical factorization x6 -I� (x + 1)2(x2 + x + 1)2 in F2[x) and Lemma 3.69(iii) it follows that <1>2(x6 -I)� 26(1-!)(1-i) � 24. and so there are four different normal bases of IF64 over F2• 5. BINOMIALS AND TRINOMIALS D A binomial is a polynomial with two nonzero terms, one of them being the constant term. Irreducible binomials can be characterized explicitly. For this purpose it suffices to consider nonlinear, monic binomials. 3. 75. Theorem. Let I ;. 2 be an integer and a E F;. Then the bi­ nomial x'-a is irreducible in F .[x) if and only if the following two conditions are satisfied: (i) each prime factor of I divides the order e of a in F;, but not (q-l)je; (ii) q =I mod4 if t = Omod4. 116 Polynomi als over Finite Fields Proof Suppose (i) and (ii) are satisfied. Then we note that f(x) � x-a is an irreducible polynomial in F .[x] of order e, and so f(x') � x'-a is irreducible in F.[x] by Theorem 3.35. Suppose (i) is violated. Then there exists a prime factor r of t that either divides (q -1)/e or does not divide e. In the first case, we have rs � (q-1)/e for somes E 1\1. The subgroup of IF; consisting of rth powers has order (q-1)/r � es and thus contains the subgroup of order e of F; generated by a. In particular, a� b' for some bE F;, and sox'-a� x'•'-b' has the factor x'•-b. In the remaining case, r divides neither (q -1)/e nor e, and so r does not divide q -I. Then r1r =I mod(q-I) for some r1 E 1\1, and thus x'-a= x'1'-a'1' has the factor x'1-a'1• Suppose (i) is satisfied and (ii) is violated. Then t � 412 for some 12 E 1\1 and q $I mod4. But (i) implies that e is even, and since e divides q-I, q must be odd. Hence q = 3 mod4. The fact that x'-a is reducible in F.[x] is then a consequence of Theorem 3.37. This can also be seen directly as follows. First we note that the information on e and q yields e"' 2mod4. Moreover, a�/2 =-= -1, and so x'-a= x' + a<t'/2)+ 1 = x' +ad, where d = (e/2)+ I is even. Now a• � 4(z-lad12 )' � 4(z-ladf2) q+ I� 4c• with c � (z-lad/2 )<• + 1)/4 • and this leads to the decomposition x'-a= x411 +4c4 = (x2'2 +2cx12 +2c2)(x2'2 -2cx12 +2c2). 0 If q = 3mod4, we can write q in the forrn q � 2Au -I with A;;. 2 and u odd. Suppose condition (i) in Theorem 3.75 is satisfied and tis divisible by 2A. We write I� Bv with B � 2A-\ and v even. Then k =A in Theorem 3.37, so that with f(x) � x-a the polynomial f(x') � x'-a factors as a product of B monic irreducible polynomials in F.[x] of degree t/B � v. These irreducible factors can be determined explicitly. We note that as in the last part of the proof of Theorem 3.75, d � (e/2)+ I is even. Since gcd(2B, q-I)� 2, there exists r E 1\1 with 2Br = dmod( q-1). Setting b � a' E F •• we get then the following canonical factorization. 3. 76. Theorem. With the conditions and the notation introduced above, let F(x)� l:' (B-i-l)!B x8-2iEF [x). ;�o i!(B-2i)! • Then the roots c1, ••• ,c8 of F(x) are all in F •• and in F.[x] we have the S. Binomials and Trinomials · canonical factorization B x'-a� n (x"-bcjx"l'-b'). j"" 1 117 Proof For a nonzero element y in an extension field of IF q we have (x-y)(x + y-1) � x2 -/h-I with,B � y-y-1• Using the statement and the notation of Waring's formula (see Theorem I. 76), we get s8(xpx2)�xr+x: � ( )'' (i1 + i2-I)!B ( )'' ( )'' i..J -1 . 1• 1 a1 x1,x2 a2 x1,x2 i1+2i2-B 11·12· il, i2 OJ> 0 Bf2 (B-'-J)IB � L (-!)'' (B-'�. )t··t (x1+x2)8-"'(x1x2}''. ;2-o 12 ·12· Putting x1 = y, x2 =-y-1, we obtain y"+y-•� �' (-I)'(B-i-l)!B ,8"-"(-l)'�F(,B). ,_0 d(B -2• }! If c1 is a root of F(x) in some extension field of F q and y1 is such that Y -yc1�c then y8+yc8�F(c.)�O and so y�8�-I Since q+l� J J J ' J J J ' f • 2Bu with u odd, we get yf+ 1 �-I, hence yf �-y1-1• Then •-( - -\)q= q_ -q __ -1 -c1 -Y1 y1 Y1 Y1 -Y1 + Y1 -c1, and so c1 E IF q. Since F( x) is monic, we have hence It follows that • F(x)� 0 (x-c1), J-1 B Y28+I� 0 (y'-c1y-I). J-1 . Since this identity holds for any element y of any extension field of F q (also for y � 0), we get the polynomial identity B x28+I� 0 (x2-c1x-l). J -I 118 Polynomials over Finite Fields By substituting b-1x'l' for x and multiplying by b28, we get a factorization of x80 + b28 = x' + a28r = x' +ad= x'-a (compare with the final portion of the proof of Theorem 3.75 for the last step). The resulting factors are irreducible in IF,[x] because we know already that the canonical factoriza­ tion of x'-a involves B irreducible polynomials in F,[x] of degree v (see the discussion preceding Theorem 3.76). D 3.77. Example. We factor the binomial x24-3 in IF7[x]. Here q = 23-I, so that A� 3, B � 4, and v � 6. Furthermore, the element a� 3 is of order e � 6 in Fj, and so condition (i) in Theorem 3.75 is satisfied and Theorem 3.76 can be applied. We have d � 4, and a solution of the congru­ ence 8r = 4mod6 is given by r � 2. Therefore, b � a2 = 2. Furthermore, F(x)�x4+4x2+2 has the roots ±I and ±3 in F7. Thus x24-3� (x6 -2x3 -4Xx' +2x3 -4)(x6 + x3 -4)(x6-x3 -4) is the canonical fac­ torization in F7[x]. D A trinomial is a polynomial with three nonzero terms, one of them being the constant term. We first consider trinomials that are also affine polynomials. 3. 78. Theorem. Let a E F • and let p be the characteristic ofF,. Then the trinomial x' -x -a i.s irreducible in IF,[ x] if and only if it has no root in F,. Proof If /l is a root of x' -x -a in some extension field of F •' then by the proof of Theorem 3.56 the set of roots of x' -x-a is fl + U, where U is the set of roots of the linearized polynomial x' -x. But U � IFP' and so x'-x-a� n (x-fl-b). beFP Suppose now that x'-x-a has a factor g E F,[x] with I,. r-deg(g) < p and g monic. Then ' g(x) � n (x -ll-b,) i-1 for certain b1 E F.-A comparison of the coefficients of x ,_ 1 shows that rfl + b1 + · · · + b, is an element ofF,. Since r has a multiplicative inverse in F •' it follows that /l E F ,. Thus we have shown that if x' -x-a factors non trivially in IF,[ x], then it has a root in F ,. The converse is trivial. D 3, 79. Coro/Jary. With the notation of Theorem 3.78, the trinomial x'-x-a i.s irreducible in f,[x] if and only ifTr,,(a)"' 0. Proof By Theorem 2.25, x' -x -a has a root in IF • if and only if the absolute trace Tr, (a) is 0. The rest follows from Theorem 3.78. D • 5. Binomials and Trinomials 119 Since forb E IF; the polynomial f(x) is irreducible over IF• if and only if f(bx) is irreducible over F •• the criteria above hold also for trinomials of the form b'x'-bx-a. If we consider more general trinomials of the above type for which the degree is a higher power of the characteristic, then these criteria need not be valid any longer. In fact, the following decomposition formula can be established. 3.80. Theorem. For x•-x-a with a being an element of the subfield K = F, ofF= F •• we have the decomposition q/' x•-x-a= n (x'-x-PJ (3.18) 1-1 in IF •[x ], where the Pi are the distinct elements ofF • with TrF;x(P) =a. Proof For a given pi, let y be a root of x'-x-Pi in some extension field of F •. Then y'- y = Pi• and also a= TrF1x(PJ = TrF;x(Y'-y) = ( y'-y) + ( y'-y )' + ( y'-y r' + ... + ( y'-y) q/' = y•-y' so that y is a root of x•-x-a. Since x'-x-p1 has only simple roots, x'-x-Pi divides x•-x-a. Now the polynomials x'-x-Pi• I"' j"' qjr, are pairwise relatively prime, and so the polynomial on the right-hand side of (3.18) divides x•-x-a. A comparison of degrees and of leading coefficients shows that the two sides of (3.18) are identical. 0 3.81. Example. Consider x9-x -1 in IF9[x]. Viewing F9 as F3(a), where a is a root of the irreducible polynomial x.'-x-I in IF3[x], we find that the elements of F 9 with absolute trace equal to 1 are -1, a, 1-a. Thus (3.18) yields the decomposition x9-x-I= (x3-x + l)(x3-x-a)(x3-x -1 +a). Since all three factors are irreducible in F9[x], we have also obtained the canonical factorization of x9-x -1 in F9[x]. 0 The information about irreducible trinomials can be applied to the construction of new irreducible polynomials from given ones. 3.82. Theorem. Let f(x) = xm + am_,xm-l + · · · + a0 be an irre­ ducible pol ynomial over the finite field IF • of characteristic p and let b E F •. Then the polynomial f(x'-x-b) is irreducible over F• if and only if the absolute trace Tr• (mb-am_1) is * 0 . • 120 Polynomials over Finite Fields Proof Suppose Tr, (mb-a .. _,)"' 0. Put K = IF• and let F be the splitting field off over K. lf'a E F is a root off, then, according to Theorem 2.14, all the roots off are given by a, a•, ... ,a•·-' and F = K( a). Further­ more, TrF;K(a)= -am-I by (2.2), and using Theorem 2.26 we get TrF( a+ b)= TrK(TrF;K(a +b))= TrK(-am-J + mb) "'0. By Corollary 3.79, the trinomial x'-x -(a+ b) is irreducible over F. Thus [F(,ll): F] = p. where ll is a root of x'-x -(a+ b). It follows from Theorem 1.84 that [F(,B): K] = [F(,B): F][F: K] = pm. Now a= ,llP -il-b, so that a E K(,ll) and K(,ll) = K(a, ,B)= F(,ll). Hence [ K( ll): K] = pm and the minimal polynomial of 1l over K has degree pm. But /(il' -,ll -b)= f(a) = 0, and so ll is a root of the monic polyno­ mial f(x'-x-b) E K[x] of degree pm. Theorem 3.33(ii) shows that f(x'-x-b) is the minimal polynomial of ll over K. By Theorem 3.33(i), f(x'-x-b) is irreducible over K =IF •. If Tr,(mb-am_1)=0, then x'-x-(a+b) is reducible over F, and so [F(,ll): F] < p for any root ll of x'-x -(a+ b). The same argu­ ments as above show that ll is a root of f(x'-x-b) and that [F(,ll): K] < pm. hence f(x'-x-b) is reducible over K =F.. D For certain types of reducible trinomials we can establish the forrn of the canonical factorization. The hypothesis for this result involves the irreducibility of a binomial, which can be cbecked by Theorem 3.75. 3.83. Theorem_ Let f(x)=x'-ax-bEF.[x], where r>2 is a power of the characteristic ofF •' and suppose that the binomial x'-1 -a is irreducible over F •. Then f(x) is the product of a linear polynomial and an irreducible polynomial over IF • of degree r -l. Proof Since f'(x) =-a"' 0, f(x) has only simple roots. If pis the characteristic of F •' then f(x) is an affine p-polynomial over F •. Hence, Theorem 3.56 shows that the difference y of two distinct roots of f(x) is a root of the p-polynomial x'-ax, and so a root of x'-1-a. From r-I > l and the hypothesis about this binomial, it follows that y is not an element of F q' and so there exists a root a of f(x) that is not an element of F •. Then a•"' a is also a root of f(x) and, by what we have already shown, a•-a is a root of the irreducible polynomial x'-1 -a over IF •' so that [IF.(a•-a):F.J=r-1. Since F•(a•-a)<;;F.(a), it follows that m# [IF.< a) :IF .l is a multiple of r -l. On the other hand, a is a root of the polynomial f(x) of degree r, so that m.; r. Because of r > 2, this is only possible if m = r-l. Thus the minimal polynomial of a over F • is an irreducible polynomial over F • of degree r-I that divides f(x ). The result follows now immediately. D 5. Binomials and Trinomials 121 In the special case of prime fields, one can characterize the primitive polynomials among trinomials of a certain kind. 3.84. Theorem. For a prime p, the trinomial x' - x -a E IF P [ x J is a primitive polynomial over F, if and only if a is a primitive element ofF, and ord(x' -x-I)� (p' -1)/(p -I). Proof Suppose first that f(x) � x'-x-a is a primitive poly­ nomial over F.-Then a must be a primitive element of F, because of Theorem 3.18. If p is a root of g(x) � x'-x-I in some extension field of F,. then 0 � ag(p) � a(IJP-P -I)� a•{JP-a{J-a� f(a{J), and so a� a{J is a root off( x ). Consequently, we have P' "' I for 0 < r < (pP-1)/(p-1), for otherwise a'IP-1>�1 with O<r(p-l)<p'-1 , a contradiction to a being a primitive element of IF,,. On the other hand, g(x) is irreducible over IF, by Corollary 3.79, and so g(x)�x•-x-1� (x-P)(x-P')·--(x-W "'). A comparison of the constant terms leads to {J1•'-I)Ap-l) �I, hence ord(x' -x-I)� (p' -l)j(p -I) on account of Theorem 3.3. Conversely, if the conditions of the theorem are satisfied, then a and p have orders p-I and ( p'-1)/( p-1), respectively, in the multiplicative group IF;,. Now ( p'-I)/( p-I) �I+ p + p2 + · --+ pp-1 =I+ I+ I+ · · · +I = p = I mod( p -I), so that p-I and (p' -l)j(p -I) are relatively prime. Therefore, a� ap has order (p -1)-(p' -l)j(p -I);. p' -I in IF;,. Hence a is a primitive element of IF'_, andf(x) is a primitive polynomial over IF,. 0 3.85. Example. For p�5 we have (p'-l)/(p-1 )�7 81�11·71. From the proof of Theorem 3.84 it follows that x781 =I mod(x5-x-1), and since x11 ••d mod(x'-x-I) and x71 ••d mod(x'-x-I), we obtain ord(x'-x-I)� 781. Now 2 and 3 are primitive elements of F5, and so x'-x-2 and x'-x-3 are primitive polynomials over F, by Theorem 3.84. 0 For a trinomial x2 + x +a over a finite field F q of odd characteristic, it is easily seen that it is irreducible over F • if and only if a is not of the form a � 4-1 -b2, b E F •. Thus, there are exactly ( q -I )/2 choices for a E IF• that make x2 + x +a irreducible over f •. More generally, the number of a E f • that make x" + x +a irreducible over IF • is usually asymptotic to q In, according to the following result. 122 Polynomials over Finite Fields 1.86. Theorem. Let F q be a finite field of characteristic p. For an integer n;;. 2 such that 2n(n -I) is not divisible by p, let T,(q) denote the number of a E F q for which the trinomial x" +X+ a is irreducible over F q· Then there is a constant B,, depending only on n, such that IT,( q )-;I"' B,q'l'. We omit the proof, as it depends on an elaborate investigation of certain Galois groups. In Definition 1.92 we defined the discriminant of a polynomial. The following result gives an explicit formula for the discriminant of a trinomial. 1.87. 17Jeonm. The discriminant of the trinomial x" + axk +bE IF•[x] with n > k ;;.1 is given by D(x" + axk +b)= ( -1)"<•-l)f'bk-l . ( nNbN-K-( -J) N (n-k )N-K kKaN)d, where d = gcd(n, k), N= njd, K = k/d. EXERCISES 3.1. Determine the order of the polynomial (x2 + x + 1)5(x3 + x +I) over IF2. 3.2. Determine the order of the polynomial x7-x6 + x4-x2 + x over F,. 3.3. Determine ord(f) for all monic irreducible polynomia ls/in F3[x] of degree 3. 3.4. Prove that the polynomial x8 + x 7 + x' + x +I is irreducible over F2 and determine its order. 3.5. Let f E IF•[x] be a polynomial of degree m ;;.I with /(0),., 0 and suppose that the roots a1, ••• , am off in the splitting field off over F q are all simple. Prove that ord( /) is equal to the least positive integer e such that a7 =I for !.; i.; m. 3.6. Prove that ord( Q,) = e for all e for which the cyclotomic polynomial Q, E F .lx] is defined. 3.7. Let/be irreducible over "• with/(0)'* 0. ForeE 1\1 relatively prime to q, prove that ord(f) = e if and only iff divides the cyclotomic polynomial Q ,. 3.8. Let f E F .lx] be as in Exercise 3.5 and let bE 1\1. Find a general formula showing the relationship between ord( /•) and ord(f). 3.9. Let F q be a finite field of characteristic p, and let f E IF .lx] be a Exercises 123 3.10. 3.11. 3.12. 3.13. 3.14. 3.15. 3.16. 3.17. 3.18. 3.19. 3.20. 3.21. 3.22. 3.23. 3.24. 3.25. 3.26. polynomial of positive degree withf(O) "'0. Prove that ord(/(x')) = pord(/(x)). Let f be an irreducible polynomial in IF •[x I with /(0)"' 0 and ord(/) = e, and let r be a prime not dividing q. Prove: (i) if r divides e, then every irreducible factor of f(x') in IF •[x I has order er; (ii) if r does not divide e, then one irreducible factor of f(x') in IF•[xl has order e and the other factors have order er. Deduce from Exercise 3.10 that if f E F •[x I is a polynomial of positive degree with f(O)"' 0, and if r is a prime not dividing q, then ord(/(x')) = rord(/(x)). Prove that the reciprocal polynomial of an irreducible polynomial f over F • with f(O)"' 0 is again irreducible over IF q· A nonzero polynomial f E IF q[x I is called self-recipro cal if f = f*. Prove that iff= gh, where g and h are irreducible in IF •[x I and f is self-reciprocal, then either (i) h* = ag with a E F;; or (ii) g* = bg, h* = bh with b = ±I. Prove: if f. is a self-reciprocal irreducible polynomial m IF •[x I of degree m > I, then m must be even. Prove: if f is a self-reciprocal irreducible polynomial in F•[xl of degree > I and of order e, then every irreducible polynomial in F •[ xI of degree >I whose order divides e is self-reciprocal. Show that x6 + x' + x 2 + x + I is a primitive polynomial over IF 2. Show that x' + x6 + x' + x +I is a primitive polynomial over IF2. Show that x'-x +I is a primitive polynomial over IF3• Let/ E IF•[xl be monic of degree m;. I. Prove that/is primitive over IF • if and only iff is an irreducible factor over F • of the cyclotomic polynomial Qd E Fq[xl with d = qm -I. Determine the number of primitive polynomials over F • of degree m. If m E N is not a prime, prove that not every monic irreducible polynomial over IF • of degree m can be a primitive polynomial over F •. If m is a prime, prove that all monic irreducible polynomials over IF • of degree m are primitive over IF • if and only if q = 2 and 2m- I is a prime. Iff is a primitive polynomial over F q• prove that f(0)-1/* is again primitive over IF q· Prove that the only self-reciprocal primitive polynomials are x + I and x2 + x +I over f2 and x +I over F3 (see Exercise 3.13 for the definition of a self-reciprocal polynomial). Prove: if f(x) is irreducible in F •[x 1. then/( ax+ b) is irreducible in IF•[xl for any a, bE IF• with a"' 0. Prove that Nq(n),.(ljn)(q" -q) with equality if and only if n is prime. 124 Polynomials over Finite Fields 3.27. Prove that N(n)�.!_q"-q (q"l'-1). • n n(q-1) 3.28. Give a detailed proof of the fact that (3.5) implies (3.4). 3.29. Prove that the Moebius function p. satisfies p.(mn) = p.(m)p.(n) for all m, n E 1\1 with gcd(m, n) =I. 3.30. Prove the identity � p.(d) __ .p(n) ._, for all n E 1\1. din d n 3.31. Prove that r.d1,p.(d)<j>(d) = 0 for every even integer n � 2. 3.32. Prove the identity r.d1.1p.(d)l = 2•, where k is the number of distinct prime factors of n E 1\1. 3.33. Prove that N.(n) is divisible by eq provided that n � 2, e is a divisor of q -I, and gcd(eq, n)= I. 3.34. Calculate the cyclotomic polynomials Q12 and Q30 from the explicit formula in Theorem 3.27. 3.35. Establish the properties of cyclotomic polynomials listed in Exercise 2.57, Parts (a)-(f), by using the explicit formula in Theorem 3.27. 3.36. Prove that the cyclotomic polynomial Q, with gcd(n, q) =I is irre­ ducible over F • if and only if the multiplicative order of q modulo n is<j>(n). 3.37. If Q, is irreducible over f2, prove that n must be a prime = ± 3 mod 8 or a power of such a prime. Show also that this condition is not sufficient. 3.38. Prove that Q15 is reducible over any finite field over which it is defined. 3.39. Prove that for n E 1\1 there exists an integer b relatively prime to n whose multiplicative order modulo n is .p( n) if and only if n = I, 2, 4, p', or 2p', where p is an odd prime andrE 1\1. 3.40. Dirichlet's theorem on primes in arithmetic progressions states that any arithmetic progression of integers b, b + n, ... ,b + kn, ... with n E 1\1 and gcd(b, n) =I contains infinitely many primes. Use this theorem to prove the following: the integers n E 1\1 for which there exists a finite field F • with gcd(n, q) =I over which the cyclotomic polynomial Q. is irreducible are exactly given by n =I, 2, 4, p', or 2p', where p is an odd prime andrE 1\1. 3.41. Prove that Q19 and Q27 are two cyclotomic polynomials over F2 of the same degree that are both irreducible over F 2. 3.42. If e � 2, gcd( e, q) = I, and m is the multiplicative order of q modulo e, prove that the product of all monic irreducible polynomials in F.[x] of degree m and order e is equal to the cyclotomic polynomial Q, over IF q· Exercises 125 3.43. Find the factorization of x32 -x into irreducible polynomials over F,. 3.44. Calculate /(2,6; x) from the formula in Theorem 3.29. 3.45. Calculate /(2,6; x) from the formula in Theorem 3.31. 3.46. Prove that ( ) n( ,_, )•(•/d) I q,n;x = xq -1 forn>l. d]• 3.47. Prove that over a finite field of odd order q the polynomial !(I+ x<q+l)/2 +(1-x)<•+ll/2) is the square of a polynomial. 3.48. Determine all irreducible polynomials in F2[x] of degree 6 and order 21 and then all irreducible polynomials in IF2[x] of degree 294 and order 1029. 3.49. Determine all monic irreducible polynomials in F3[x] of degree 3 and order 26 and then all monic irreducible polynomials in F3[x] of degree 6 and order I 04. 3.50. Proceed as in Example 3.41 to determine which polynomials f. are irreducible in IF•[x] in the case q-5, m � 4, e = 78. 3.51. In the notation of Example 3.41, prove that if tis a prime with t -I dividing m -1, then f. is irreducible in F2[x]. 3.52. Given the irreducible polynomial l(x) � x3-x' + x +I over F3, calculate 12 and Is by the matrix-theoretic method. 3.53. Calculate 12 and Is in the previous exercise by using the result of Theorem 3.39. 3.54. Use a root of the primitive polynomial x'-x +I over f3 to repre­ sent all elements of IFJ'7 and compute the minimal polynomials over IF3 of all elements of F27. 3.55. Let 8 E IF64 be a root of the irreducible polynomial x6 + x +I in F2[x]. Find the minimal polynomial of fJ �I+ 82 + 83 over IF2. 3.56. Let 8 E F64 be a root of the irreducible polynomial x6 + x4 + x3 + x +I in F2[x]. Find the minimal polynomial of fJ �I+ 8 + 9s over F,. 3.57. Determine all primitive polynomials over F3 of degree 2. 3.58. Determine all primitive polynomials over F 4 of degree 2. 3.59. Determine a primitive polynomial over F s of degree 3. 3.60. Factor the polynomial g E F3[x] from Example 3.44 in F9[x] to obtain primitive polynomials over F9. 3.61. Factor the polynomial g E IF2[x] from Example 3.45 in F8[x] to obtain primitive polynomials over F8. 3.62. Find the roots of the following linearized polynomials in their splitting fields: (a) L(x) � x' + x4 + x' + x E IF2[x]; (b) L(x) � x9 + x E IF3[x]. 3.63. Find the roots of the following polynomials in the indicated fields by 126 Polynomials over Finite Fields first determining an affine multiple: (a) f(x)�x7+x6+x3+x2+1EIF2[x[ in IF32; (b) f(x)� x4 + 8x3-x2 -(8 + l)x + 1-8 E IF9[x[ in Fm, where 8 is a root of x2-x -1 E IF3[x]. 3.64. Prove that for every polynomial f over IF q" of positive degree there exists a nonzero q-polynomial over F q• that is divisible by f. 3.65. Prove that the greatest common divisor of two or more nonzero q-polynomials over f •" is again a q-polynomial, but that their least common multiple need not necessarily be a q-polynomial. 3.66. Determine the greatest common divisor of the following linearized polynomials: (a) L1(x)�x64+x16+x8+x4+x2+xEF2[x], L2(x) � x32 + x' + x2 + x E f2[x]; (b) L1(x)�x243-x81-x9+x3+xEF3[x], L2(x) � x81 + x EF3[x]. 3.67. Determine the symbolic factorizat ion of the following linearized polynomials into symbolically irreducible polynomials over the given prime fields: (a) L(x) � x32 + x16 + x' + x4 + x2 + x E IF2[x]; (b) L(x)�x81-x9-x3-xEIF3[x]. 3.68. Prove that the q-polynomial L1(x) over IF •• divides the q-polynomial L(x) over IF •• if and only if L(x) � L2(x)®L1(x) for some q-poly­ nomial L2 ( x) over IF ••. 3.69. Prove that the greatest common divisor of two or more affine q-polynomials over IF ••• not all of them 0, is again an affine q-poly­ nomial. 3.70. If A 1(x) � L 1(x )-a1 and A2(x) � L2(x )-a2 are affine q-polynomi­ als over IF •• and A1(x) divides A2(x), prove that the q-polynomial L1(x) divides the q-polynomial L2(x). 3.71. Let f(x) be irreducible in IF•[x] with f(O) * 0 and let F(x) be its linearized q-associate. Prove that F(x)/x is irreducible in Fq[x] if and only if f(x) is a primitive polynomial over F • or a nonzero constant multiple of such a polynomial. 3.72. Let!; be an element of a finite extension field of IF ••. Prove that a q-polynomial K(x) over F •• has !; as a root if and only if K(x) is divisible by the minimal q-polynomial of !; over F ••. 3.73. For a nonzero polynomial f E IF.[x], prove that I:<l>.(g) � q•<&<n, where the sum is extended over all monic divisors g E IF .I x] of f. 3.74. For a nonzero polynomial [ E F•[x] and g E F q[x] with gcd(f, g)� I, prove that g• =I mod/, where k � <l>q(f). 3.75. The function llq is defined on the set S of nonzero polynomials f over F • by p.q{ f) � I if deg(f) � 0, p. .<fl � 0 iff has at least one multiple root, and /lq(f) � ( -I)• if deg(f) ;.I and f has only simple roots, where k is the number of irreducible factors in the canonical factori- Exercises 127 zation off in IF•[xl. Let E denote a sum extended over all monic divisors g E IF .Jxl of f. Prove the following properties: { 1 ifdeg{!)�o, (a) l:l'.(g) � 0 if deg(/) �I; · (b) "•(/g) � "•(/)l'•(g) for all f, g E S with gcd(f, g)= I; (c) Eq•""<•>"•(//g) � Ill•(/) for all f E S; (d) if I} is a mapping from S into an additively written abelian group G with l}(cf)=l}(f) for all ceF; andfES, and if v(f)=EI}(g) for all /ES, then 1}(/)=EI'q(//g)v(g)= E"•(g)'l'(//g) for all/ E S. 3. 76. Prove that the number of different normal bases of IF •• over F • is provided that gcd(m, q) �I and the multiplicative order of q modulo m is <l>(m). 3.77. Refer to Example 2.31 for the definition of a self-dual basis and show that there exists a self-dual normal basis of F2• over F2 whenever m is odd. (Hint: Show first that the number of different normal bases of F2• over F2 is odd whenever m is odd.) 3.78. For a prime r and a E IF •• prove that x'-a is either irreducible in F•[xl or has a root in IF.. · 3.79. For an odd primer, an integer n �I, and a E F •• prove that x'"-a is irreducible in F•[xl if and only if a is not an rth power of an element of F •. 3.80. Find the canonical factorization of the following binomials over the given prime fields: (a) /(x)=x8+1EF3[xl; (b) f(x) = x27-4 E F 19[x I; (c) /(x) � x88-10 E IF23[xl. 3.81. Prove that under the conditions of Theorem 3. 76 the roots of the polynomial F( x) introduced there are simple. 3.82. Prove that the resultant of two binomials x•-a and xm-bin F •[x I is given by ( -i)"(b•l•-amfd)d with d � gcd(n, m), where nand m are considered to be the formal degrees of the binomials (compare with Definition 1.93). 3.83. For a nonzero element b of a prime field IF,, prove that the trinomial x'-x-b is irreducible in F,.[xl if and only if n is not divisible by p. 3.84. Prove that any polynomial of the form x•-ax-bE F .Jx I with a *I has a root in F •. 3.85. Prove: if x'-x-a is irreducible over the field IF • of characteristic p 128 Polynomials over Finite Fields and p is a root of this trinomial in an extension field of F •• then x'-x-ap•-1 is irreducible over F•(/3). 3.86. Prove: if l(x)=x"'+a.,_1x"'-1+ ··· +a0 is irreducib le over the field IF• of characteristic p and bE F • is such that Tr,,(mb-a.,_1) = 0, then l(x'-x-b) is the product of p irreducible polynomials over F • of degree m. 3.87. If m and p are distinct primes and the multiplicative order of p modulo m ism-1, prove that Ej_(/(x'-x); is irreducible over IF,. 3.88. Find the canonical factorization of the given polynomial over the indicated field: (a) l(x) = x'-ax -1 E F64[x], where a satisfies a3 =a+ 1; (b) l(x) = x9-ax+ a E IF9[x], where a satisfies a2 =a+ 1. 3.89. Let A(x)=L(x)-aEF.[x] be an affme p-polynomial of degree r > 2, and suppose the p-polynomial L(x) is such that L(x)/x is irreducib le over F •. Prove that A(x) is the product of a linear polynomial and an irreducib le polynomial over F • of degree r-1. 3.90. Prove: the trinomial x" + ax• +bE IF.[x], n > k ;;>l, q even, has multiple roots if and only if n and k are both even. 3.91. Prove that the degree of every irreducib le factor of x2" + x + 1 in IF2[x] divides 2n. 3.92. Prove that the degree of every irreducible factor of x'"+ 1 + x + 1 in IF2[x] divides 3n. 3.93. Recall the notion of a self-reciprocal polynomial defined in Exercise 3.13. Prove that if 1 E F2[x] is a self-reciprocal polynomial of posi­ tive degree, then I divides a trinomial in F2[x] only if ord(f) is a multiple of 3. Prove also that the converse holds if I is irreducible over F2• 3.94. Prove that for odd dEN the cyclotomic polynomial Qd E F2[x] divides a trinomial in F2[x] if and only if dis a multiple of 3. 3.95. Let l(x)=x"+ax•+bEIF.(x], n>k;;>l , be a trinomial and let mE I'll be a multiple of ord(f). Prove thatl(x) divides the trinomial g(x) = xm-k + b-1x"-k + ab-1• 3.96. Prove that the trinomial x2" + x" + 1 is irreducible over IF2 if and only if n = 3• for some nonnegative integer k. 3.97. Prove that the trinomial x4" + x" + 1 is irreducible over F if and only if n = 3•5"' for some nonnegative integers k and m. '< Chapter 4 Factorization of Polynomial s Any nonconstant polynomial over a field can be expressed as a product of irreducible polynomials. In the case of finite fields, some reasonably effi­ cient algorithms can be devised for the actual calculation of the irreducible factors of a given polynomial of positive degree. The availability of feasible factorization algorith ms for polynomials over finite fields is important for coding theory and for the study of linear recurrence relations in finite fields. Beyond the realm of finite fields, there are various computational problems in algebra and number theory that depend in one way or another on the factorization of polynomials over finite fields. We mention the factorization of polynomials over the ring of integers, the determination of the decomposition of rational primes in algebraic number fields, the calculation of the Galois group of an equation over the rationals, and the construction of field extensions. We shall present several algorithms for the factorization of poly­ nomials over finite fields. The decision on the choice of algorithm for a specific factorization problem usually depends on whether the underlying finite field is "small" or "large." In Section I we describe those algorithms that are better adapted to "small" finite fields and in the next section those that work better for "large" finite fields. Some of these algorithms reduce the problem of factoring polynomials to that of finding the roots of certain other polynomial s. Therefore, Section 3 is devoted to the discussion of the latter problem from the computational viewpoint. 130 Factorization of Polynomials 1. FACTORIZATION OVER SMALL FINITE FIELDS Any polynomial / E IF•[x1 of positive degree has a canonical factorization in F .[x1 by Theorem 1.59. For the discussion of factorization algorithms it will suffice to consider only monic polynomials. Our goal is thus to express a monic polynomial f E F .[x1 of positive degree in the form (4.1) where /1, ••• ./, are distinct monic irreducible polynomials in IF•[x1 and e1 •••• ,e" are positive integers. First we simplify our task by showing that the problem can be reduced to that of factoring a polynomial with no repeated factors, which means that the exponents e 1, ••• , e k in ( 4.1) are all equal to I (or, equiva­ lently, that the polynomial has no multiple roots). To this end, we calculate d(x) = gcd(!(x),f'(x)), the greatest common divisor of f( x) and its derivative, by the Euclidean algorithm. If d( x) = I, then we know that/( x) has no repeated factors because of Theorem 1.68. If d(x) = f(x), we must have f'(x) = 0. Hence f(x) = g( x )', where g( x) is a suitable polynomial in IF •[ x 1 and p is the characteris­ tic of F •. If necessary, the reduction process can be continued by applying the method to g( x ). If d(x)"" I and d(x) ""f(x), then d(x) is a nontrivial factor off(x) andf(x)jd(x) has no repeated factors. The factorization off(x) is achieved by factoring d(x) and/(x)jd(x) separately. In case d(x) still has repeated factors, further applications of the reduction process will have to be carried out. By applying this process sufficiently often, the original problem is reduced to that of factoring a certain number of polynomials with no repeated factors. The canonical factorizations of these polynomials lead directly to the canonical factorization of the original polynomial. Therefore, we may restrict the attention to polynomials with no repeated factors. The following theorem is crucial. 4.1. Theon"'- If f E IF •[ x 1 is monic and h E IF •[ x 1 is such that h• = hmodf, then f(x) = Il gcd(/(x), h(x)-c). (4.2) ,·eF, Proof Each greatest common divisor on the right-hand side of (4.2) divides f(x ). Since the polynomials h( x)-c, c E F •• are pairwise relatively prime, so are the greatest common divisors with/( x ), and thus the product of these greatest common divisors divides f(x). On the other hand, f(x) I. Factorization over Small Finite Fields Ill divides h(x)•-h(x)= fl (h(x)-c), cEFq and sof(x) divides the right-hand side of (4.2). Thus, the two sides of (4.2) are monic polynomials that divide each other, and therefore they must be ��- D In general, ( 4.2) does not yield the complete factorization off since gcd(f(x), h(x)-c) may be reducible in Fq[x]. If h(x) = cmodf(x) for some c E F •• then Theorem 4.1 gives a trivial factorization off and therefore is of no use. However, if h is such that Theorem 4.1 yields a nontrivial factorization off, we say that h is an !-reducing polynomial. Any h with h• = h mod f and 0 < deg( h)< deg(f) is obviously /-reducing. In order to obtain factorization algorithms on the basis of Theorem 4.1, we have to find methods of constructing /-reducing polynomials. It should be clear at this stage already that since the factorization provided by ( 4.2) depends on the calculation of q greatest common divisors, a direct application of this formula will only be feasible for small finite fields IF q· The first method of constructing /-reducing polynomials makes use of the Chinese remainder theorem for polynomials (see Exercise 1.37). Let us assume that f has no repeated factors, so that f = /1 • • ·f. is a product of distinct monic irreducible polynomials over r •. If (c1, ••• ,c.) is any k-tuple of elements of r •. the Chinese remainder theorem implies that there is a unique h E F•[x] with h(x) = c1mod f,(x) for I .;; i'<, k and deg (h) < deg(f). The polynomial h ( x) satisfies the condition h(x)• = c? = c, = h(x )mod.t;(x) for I<. i.;; k, and therefore h•=hmodf, deg(h) < deg(/). On the other hand, if h is a solution of ( 4.3), then the identity h(x)•-h(x) = fl (h(x)-c) cEF9 (4.3) implies that every irreducible factor of f divides one of the polynomi�s h(x)-c. Thus, �I solutions of (4.3) satisfy h(x)=c,mod.t;(x), i .;;i.;k, for some k-tuple (c1, ••• ,c.) of elements of IF •. Consequently, there are exactly q• solutions of (4.3). We find these solutions by reducing (4.3) to a system of linear equations. With n = deg(f) we construct the n X n matrix B = (b,j), 0 .;; i,j .; n -1, by calculating the powers x'•modf(x). Specifically ,let n-1 x'•= L b,jxjmodf(x) forOc;;i.;;n-1. j�O (4.4) 132 Factorization of Polynomials Then h(x) � a0 + a1x + · · · + a._,x•-l E IF•[x] is a solution of (4.3) if and only if (a0, a1, ••• ,a._,) B � (a0• a1 , ••• ,a._,). This follows from the fact that (4.5) holds if and only if n -I h(x) � L a,xi J-0 n-1 n -1 � L L a,b,1x1 J-0 i-0 n -I = L a,x'•�h(x)•modf(x). i-0 The system ( 4.5) may be written in the equivalent form (a0, a1, ••• ,a._,)(B-I)� (0,0, ... ,0), (4.5) (4.6) where I is the n X n identity matrix over F q· By the considerations above, the system (4.6) has q• solutions. Thus, the dimension of the null space of the matrix B -I is k, the number of distinct monic irreducible factors off, and the rank of B-I is n -k. Since the constant polynomial h1(x) �I is always a solution of (4.3), the vector (1,0, ... ,0) is always a solution of (4.6), as can also be checked directly. There will exist polynomials h2(x), ... ,h.(x) of degree "'n -] such that the vectors corresponding to h1(x), h2(x),. .. ,h.(x) form a basis for the null space of B -I. The polynomials h2(x), ... ,h.(x) have positive degree and are thus /-reducing. In this approach, an important role is played by the determination of the rank r of the matrix B-I. We have r � n -k as noted above, so that once the rank r is found, we know that the number of distinct monic irreducible factors off is given by n -r. On the basis of this information we can then decide when the factorization procedure can be stopped. The rank of B -I can be determined by using row and column operations to reduce the matrix to echelon form. However, since we also want to solve the system (4.6), it is advisable to use only column operations because they leave the null space invariant. Thus, we are allowed to multiply any column of the matrix B-I by a nonzero element of F q and to add any multiple of one of its columns to a different column. The rank r is the number of nonzero columns in the column echelon form. Having found r, we form k � n-r. If k �I, we know that f is irreducible over F q and the procedure terminates. In this case, the only solutions of (4.3) are the constant polynomials and the null space of B -I contains only the vectors of the form (c,O, ... ,O) with cEIF •. If k;. 2, we take the /-reducing basis polynomial h2(x) and ealculate I. Factorization over Small Finite Fields Ill gcd(f(x ), h"2(x )-c) for all c E F •. The result will be a nontrivial factoriza­ tion of f(x) afforded by (4.2). If the use of h2(x) does not succeed in splittingf(x) into k factors, we calculate gcd(g(x ), h3(x )-c) for all c E F • and all nontrivial factors g(x) found so far. lbis procedure is continued until k factors of f(x) are obtained. The process described above must eventually yield all the factors. For if we consider two distinct monic irreducible factors of f(x), say f1(x) and f2(x), then by the argument following (4.3) there exist elements ci'' ci2 E IF• such that h i(x) = ci1mod f1(x ), h i(x) = ci2mod f2(x) for I "j" k. Suppose we had ci1 = ci2 for I " j " k. Then, since any solution h ( x) of (4.3) is a linear combination of h1(x), ... ,hk(x) with coefficients in F•, there would exist for any such h(x) an element c E F• with h(x) = cmodf1(x), h ( x) = cmod f2 ( x ). But the argument leading to (4.3) shows, in particular, that there is a solution h(x) of (4.3) with h(x)=Omodf1(x), h(x)= I mod f2( x ). This contradiction proves that ci1 * ci2 for some j with I " j" k (in fact, since h1(x)=l, we will have}> 2). Therefore, hi(x)-ci1 will be divisible by f1(x), but not by f2(x). Hence any two distinct monic irreduc­ ible factors of f(x) will be separated by some hi(x). This factorization algorithm based on determining /-reducing poly­ nomials by solving the system (4.6) is called Berlekamp 's algorithm. 4.2. Example. Factor f(x) = x' + x6 + x4 + x3 + I over IF2 by Berlekamp's algorithm. Since gcd(f(x ), f'(x )) =I, f(x) has no repeated factors. We have to compute x'•modf(x) forq = 2 and 0" i" 7. This yields the following congruences mod f(x): x0 =I x2 = x' x4 = x• x6 = x' x' =I +x3+x4 +x' x10= 1 +x2+xl+x4+xs x\2= x' +x4+xs+x 6+x1 x14=l+x +xl+x4+xs Therefore, the 8 X 8 matrix B is given by I 0 0 0 0 0 0 0 0 0 I 0 0 0 0 0 0 0 0 0 I 0 0 0 B= 0 0 0 0 0 0 I 0 I 0 0 I I 0 I 0 I 0 I I I I 0 0 0 0 I 0 I I I I I I 0 I I 0 0 134 Factorization of Polynomials and B -I is given by 0 0 0 0 0 0 0 0 0 I I 0 0 0 0 0 0 0 I 0 I 0 0 0 B-1= 0 0 0 I 0 0 I 0 I 0 0 I 0 0 I 0 I 0 I I I 0 0 0 0 0 I 0 I I 0 I I I 0 I I I 0 I The matrix B -I has rank 6, and the two vectors (1,0,0,0,0,0,0,0) and (0, I, 1,0,0, I, I, I) form a basis of the null space of B-I. The corresponding polynomials are h1(x) =I and h2(x) = x + x2 + x' + x6 + x7 We calculate gcd(/(x), h2(x)-c) for c E IF2 by the Euclidean algorithm and obtain gcd(/(x), h2(x)) = x6 + x' + x4 + x +I, gcd(/(x), h2(x)-l) = x2 + x +I. The desired canonical factorization is therefore f(x) = (x6 + x' + x4 + x + i)(x2 + x + 1). D A second method of obtaining f-reducing polynomials is based on the explicit construction of a family of polynomials among which at least one /-reducing polynomial can be found. Let f be again a monic polynomial of degree n with no repeated factors. Let f = /1 • • ·f. be its canonical factorization in F.[x] with deg(/ )=nj for l.;j<;k. If N is the least positive integer with x•• = xmodf(x), then it follows from Theorem 3.20 that N = lcm( n 1, ••• , n• ), and it is also easily seen that N is the degree of the splitting field F of,! over IF •. �t the polynomial T E F•[x] be given by T(x)=x+x•+x• + ·· · +x• and define T,(x)=T(x') fori=O,i, .... The following result guarantees that in the case of interest, namely, when f is reducible, there are /-reducing polynomials among the T,. 4.3. Theorem . Iff is reducible in F .lx ], then at least one of the polynomials T;, 1 :::;;;; i:::;;;; n -1, is /-reducing. Proof It is immediate that any polynomial T, satisfies T,• = T,mod f. Suppose now that for all T,. I.; i.; n-I, the factorization off afforded by (4.2) were trivial. This means that there exist elements c1,. •• ,c._1 E F • such that T,(x) = c1modf(x) for 1.; i.; n -I. With c0 = N, viewed as an ele­ ment of IF •• we get T(x') = c,modf(x) for 0 .;i.; n -I. For any n -1 g(x)= La1x1EF.[x] i-1 of degree less than n we have then (n-1 ) n-1 n-1 T(g(x)) = T 1�0 a1x1 = 1�0 a1T(x') = 1�0 a1c1modf(x). I. Factorization over Small Finite Fields Putting we obtain n -I c(g)� L a1c1EF,. ;-o T( g ( x)) = c ( g )mod .0 ( x) for I " j " k. 135 (4.7) Since N � lcm(n1, •••• n.), at least one of the integers N/nj, say Njn1, is not divisible by the characteristic of F q· Let 61 be a root of /1 in the splitting field F1 of /1 over F •. Because of Theorem 2.23(iii) there exists g1 EIF.[x] with TrF/F (g1(61)}�1. ' . (4.8) Since k ;;. 2 by assumption, we can apply the Chinese remainder theorem to obtain a polynomial g E IF q[x] of degree < n with g = g1modfp g = Omod/2. From (4.8) and (4.9) we deduce that TrF/F (g(61)) �I, ' . and Theorems 2.23(iv) and 2.26 imply that TrF/F,(g(61)) � N/n1• (4.9) Because of the definitions of the trace and of the element 61, it follows that T(g(x)) = N/n1modf1(x). However, the second congruence in (4.9) leads to T(g(x))=Omodf2(x), and since N/n1 * 0 as an element of "•· we get a contradiction to (4.7). Therefore, at least one of the T,. I" i" n-I, is /-reducing. 0 4.4. Example. Factor f(x) � x11 + x14 + x13 + x12 + x" + x10 + x9 + x' + x1 + x5 + x4 + x +I over IF2. We have gcd(/(x), f'(x)) = x10 + x' +I, and sof0(x) = f(x)jgcd(f(x),f'(x)) = x1 + x5 + x4 + x +I has no repeated factors. We factor /0 by finding an fo-reducing polynomial of the type described above. To this end, we calculate the powers x, x2, x4, •.• mod f0(x) until we obtain the least positive integer N with x2" = xmod f0(x ). We simplify the notation by identifying a polynomial "f.7::d a1x1 with the n-tuple a0a1 • • • a._1 of its coefficients, so that, for instance, f0(x) = IJOOllOL The calculation of the required powers of xmod f0(x) is facilitated by the observation that squaring a polynomial a0a1 • • • a6mod /0(x) is the same as multiplying the vector a0a1 • • ·a, by the 7 x 7 matrix of even powers 136 Factorization of Polynomials x0, x2, .•• ,x12modf0(x). This matrix is obtained from x0 =I 0 0 0 0 0 0 x2 =0 0 I 0 0 0 0 x4 =0 0 0 0 I 0 0 x6 =0 0 0 0 0 0 x8 = 0 I 0 0 I x10 =I 0 I I 0 0 x12 =0 0 0 0 where all the congruences are mod/0(x). Therefore we get mod/0(x): x=O I 0 0 0 0 0 x2 =0 0 I 0 0 0 0 x4 =0 0 0 0 I 0 0 x8 =0 I 0 0 I I xl6 =I I 0 I 0 0 0 x32 =I 0 I 0 0 0 x64 =I 0 0 0 0 x\28 = I I I 0 I 0 I x256 = I 0 0 0 0 I 0 XS\2 =: Q 0 I I 0 0 I x1024 = 0 0 0 0 0 0 Thus N � 10 and 9 T1( x) � L x2' =I I 0 0 0 I mod/0(x). j=O Since T1(x) is not congruent to a constant modf0(x), T1(x) isfo-reducing. We have ged(/0(x),T1(x)}�ged(l I 0 0 I I 0 I, I I I 0 0 0 I} = xs + x4 + x3 + x2 + I' gcd(/0(x},T1(x}-I}�ged(l I 0 0 I I 0 1,0 I I 0 0 0 I) = x2 + x +I, and so /0 ( x} � ( x' + x4 + x3 + x2 + I)( x2 + x + I). The second factor is obviously irreducible in f2[x]. Since N � 10 is the least common multiple of the degrees of the irreducible factors of /0 ( x ), any nontrivial factorization of the first factor would lead to a value of N different from 10, so that the first factor is also irreducible in IF2[x]. I. Factorization over Small Finite Fields 137 It remains to factor gcd(/(x), f'(x) )�x10+x8+1 . We have x10 + x8 +I� (·x' + x4 + 1)2, and by checking whether x' + x4 +I is divisi­ ble by one of the irreducible factors of f0(x), we find that x' + x4 +I� (x' + x + l)(x2 + x + 1), with x' + x +I irreducible in F2[x]. Hence f( x) � ( x' + x4 + x' + x2 + i)( x' + x + 1)2( x2 + x + 1)3 is the canonical factorization ofj(x) in IF2[x]. 0 It should be noted that, in general, the /-reducing polynomials T, do not yield the complete factorization off since the T, are not able to separate those irreducible factors� for which N/n1 is divisible by the characteristic of IF •. In practice, however, one calculates the first /-reducing T, and then calculates new T, for each of the resulting factors. In this way, one eventually obtains the complete factorization of f. It is, however, possible to construct a related set of polynomials R 1 that are capable of separating all the irreducible factors off at once. We assume, without loss of generality, that /(0) * 0. Let ord(/(x)) � e, so that f(x) divides x' -I. Since f has no repeated factors, e and q are relatively prime by Corollary 3.4 and Theorem 3.9. For each i;;. 0 let m, be the least positive integer with Then we define x'•"· = x'modf(x). Since (4.10) is equivalent to iqm·=imode, (4.10) (4.11) which is in tum equivalent to qm; =I mod( ejgcd(e, i)), it follows that m, can also be described as the multiplicative order of q moduloej gcd(e, i). A comparison with the definition of T,(x) shows that T,(x) = �R,(x)modf(x). m, It is clear that R7 = R,modjfor all i, so that the R, can be used in (4.2) in place of h. We prove now the claim about the R, made above. 4.5. Theorem. Let f be monic and reducible in IF .[x] with no repeated factors, and suppose that f(O) * 0 and ord(f) �e. Then, if all the polynomials R,, 1,. i"" e-I, are used in (4.2), they will separate all irreducible factors of f. Proof Let h(x)�E�.::Ja1x1EF.[x] be a solution of h(x)•= h(x)mod(x' -1). If we interpret subscrip ts mod e, then h(x) = E7.::d a,.x'•mod (x' -I) since iq, i � O,l, ... ,e -I, runs through all residues !38 Factorization of Polynomials mode as q and e are relatively prime. Since h(x )q = L�.:ci a,.x,.q, we get e -I e -I L a,x'• = L a,.x'•mo d(x' -I). i-0 i-0 By considering the exponents mode, it follows that corresponding coeffi­ cients are identical. Thus a,.= a,.q for all i, and so a;= a1q = a;q2 = · · · for all i. Since m, is the least positive integer for which (4.11) holds, we obtain h(x)= L a,R,(x)mod(x'-1), iEJ where the set J contains exactly one representative from each equivalence class of residues mode determined by the equivalence relation -which is defined by i1-i2 if and only if i1 = i2q'mod e for some I;. 0. Thus, for suitable b, E IF q we have •-1 h(x)= L b,R,(x)mod(x'-1). ;-o (4.12) Let now /1 (x) and /2(x) be two distinct monic irreducible factors of f(x ), and so of x'-I. By the argument leading to (4.3), there is a solution h(x) E IFq[x] of h(x)• = h(x)mod(x' -I), deg(h(x)) < e, with h(x) =Omod/1(x), h(x) = lmod/2(x). (4.13) Since Rf = R,mod f, the argument subsequent to (4.3) shows that there exist elements cil, c, E Fq with R1(x) = c,1modf1(x), R,(x) = c,modf2(x) for 0.;; i .;; e-I. If we had cil = c, for 0.;; i.;; e-I, then it would follow from (4.12) that h(x) = cmodf1(x), h(x) = cmodf2(x) for some c E Fq, a contradiction to (4.13). Thus cil * c, for some i with 0.;; i.;; e -1, and since R0(x) =I, we must have i ;.I. Then R,(x)-c,1 will be divisible by f1(x), but not by /2(x). Hence the use of this R,(x) in (4.2) will separate f1(x) fromf2(x). D The argument in the proof of Theorem 4.5 shows, of course, that the polynomials R1, with i running through the nonzero elements of the set J, are already separating all irreducible factors of f. However, the determina­ tion of the set J depends on knowing the order e, and a direct calculation of e (i.e., one that does not have recourse to the canonical factorization of f) will be lengthy in most cases. This problem does not arise in the special cases f(x) = x' -I and f(x) = Q,(x), the eth cyclotomic polynomial, since it is trivial that ord(x' -I)= ord(Q,(x)) =e. The polynomials R, are, in fact, well suited for factoring these binomials and cyclotomic polynomials. 2. Factorization over Large Finite Fields 139 4.6. Example. We determine the canonical factorization of the cyclo­ tmnic polynomial Q,(x) in F3[x]. According to Theorem 3.27 we have (x" -l)(x2 -I) Q,(x)� (x26-I)(x4-l) = x24 _ x22 + x2o _ x1s + x\6 _ x\4 + x\2 - xlo + xs-x6 + x4- x2 +I. Now R1(x) = x + x3 + x9 + x27 + x81 + x243, and since x26 == -I modQ12(x), we_get R 1(x) = OmodQ1 2(x), so that R1 is not Q12-reduc­ ing. With R2(x) � x2 + x' + x18 we get gcd(Q,(x), R2(x)) � x'-x2 +I, gcd(Q,(x), R2(x)+ I)� x' + x4- x2 +I, gcd(Q,(x), R2(x)-I) � x12 + x10-x' + x' + x4 + x2 +I� g(x), say, so that (4.2) yields Q, ( x) � ( x'-x2 + I)( x' + x4-x2 + I )g( x). By Theorem 2.47(ii), Q12(x) is the product of four irreducible factors in F3[x] of degree 6. Thus, it remains to factor g(x). Since R3(x) � x' + x9 + x21 + x81 + x243 + x129 = OmodQ1 2(x), we next use R4(x) � x4 + x12 + x". We note that x12 = -x10 + x8 -x6 - x4 -x2 - I mod g(x), x36 == - x10mod g(x), and so R4(x) =x10 + x'-x6 -x2 -I modg(x). Therefore , gcd(g(x), R4(x)) � gcd(g(x), x10 + x'-x'- x2 -1) �I, gcd(g(x), R4(x)+I) � gcd(g(x),x10 + x'-x' -x2) �x'- x4+ x2 +I, gcd(g(x), R4(x)-1) � gcd(g(x), x10 + x'-x'-x2 +I)� x6-x4 +I. Thus, Q, ( x) � ( x6-x2 + I)( x' + x4- x2 + I)( x'-x4 + x2 + I)( x6 -x4 + I) is the desired canonical factorization. 2. FACI'ORIZATION OVER LARGE FINITE FIELDS D If IF 9 is a finite field with a large number q of elements, the practical implementation of the methods in the previous section will become more difficult. We may still be able to find an [-reducing polynomial with a reasonable effort, but a direct application of the basic formula ( 4.2) will be 140 Factorization of Polynomials problematic since it requires the calculation of q greatest common divisors. Thus, to make the use of /-reducing polynomials feasible for large finite fields, it is imperative that we devise ways of reducing the number of elements c E IF • for which the greatest common divisor in ( 4.2) needs to be calculated. We note that in the context of factorization we consider q to be "large" if q is (substantially) bigger than the degree of the polynomial to be factored. Letfagain be a monic polynomial in IF,[x] with no repeated factors, let deg(f) � n, and let k be the number of distinct monic irreducible factors of f. Suppose that hE F,[x] satisfies h• = hmodf and 0 < deg(h) < n, so that h is /-reducing. Since the various greatest common divisors in (4.2) are pairwise relatively prime, it is clear that at most k of these greatest common divisors will be "' l. The problem is to find an a priori characteriz ation of those c E IF • for which gcd(/(x ), h (x )-c)"' l. One such characterizat ion can be obtained by using the theory of resultants (see Definition 1.93 and the remarks following it). Let R(f(x),h(x)-c) be the resultant of f(x) and h(x)-c, where the degrees of the two polynomials are taken as the formal degrees in the definition of the resultant. Then gcd(/(x),h(x)-c)*l if and only if R(f(x),h(x)-c) � 0. We are thus led to consider F(y) � R(/(x), h(x)-y), which, from the representation of the resultant as a determinant, is seen to be a polynomial iny of degree.; n. Then we have gcd(/(xJ, h(x)-c)"' 1 if and only if cis a root of F(y) in F ,. The polynomial F(y) may be calculated from the definition, which involves the evaluation of a determinant of order .; 2n- 1 whose entries are either elements of F • or linear polynomials in y. In many cases it will, however, be preferable to use the following method. Choose n + 1 distinct elements c0, c1, •••• c, E F • and calculate the resultants r1 � R(f(x ), h (x )-c,) for 0 .; i.; n. Then the unique polynomial F( y) of degree .; n with F( c,) � r, for 0.; i.; n is obtained from the Lagrange interpolation formula (see Theorem 1.71). This method has the advantage that if any of the r, are 0, we automatically get roots of the polynomial F(y) in F,. At any rate, the question of isolating the elements c E IF • with gcd(/(x ), h(x )-c)"' 1 is now reduced to that of finding the roots of a polynomial in IF,. Computational methods for dealing with this problem will be discussed in the next section. 4.7. Example. Factor f(x) � x6-3x' + Sx4-9x3 -Sx2 + 6x +7 over F23. Since gcd(/(x), f'(x)) � l.f(x) has no repeated factors. We proceed by Berlekamp's algorithm and calculate x231modf(x) for 0.; i.; 5. This yields 2. Factorization over Large Finite Fields 141 the 6 X 6 matrix I 0 0 0 0 0 5 0 -I 8 -3 -10 B= -10 10 10 0 I -9 0 7 9 -8 10 -II II 0 -4 7 7 2 -3 0 -10 9 2 -9 and thus B - I is given by 0 0 0 0 0 0 5 -I -I 8 -3 -10 B-I= -10 10 9 0 I -9 0 7 9 -9 10 -II II 0 -4 7 6 2 -3 0 -10 9 2 -10 Reduction to column echelon form shows that B-I has rank r = 3, so that I has k = 6-r = 3 distinct monic irreducible factors in IF 23 [X]. A basis for the null space of B -I is given by the vectors h 1 = (I, 0, 0, 0, 0, 0), h 2 = (0,4,2, 1,0,0), h3 = (0, -2,9�0, I, 1), which correspond to the polynomials h1(x)=l, h2(x)=x3+2x2+4x, h3(x)=x5+x4+9x2-2x. We take the /-reducing polynomial h 2 ( x) and consider F(y) = R{!(x),h2(x)-y) I -3 5 -9 -5 6 7 0 0 0 I -3 5 -9 -5 6 7 0 0 0 I -3 5 -9 -5 6 7 I 2 4 -y 0 0 0 0 0 0 2 4 -y 0 0 0 0 0 0 I 2 4 -y 0 0 0 0 0 0 2 4 -y 0 ·o 0 0 0 0 ]• 2 4 -y 0 0 0 0 0 0 2 4 -y In this case a direct computation of F( y) is feasible, and we obtain F(y)=y6+4y5+3y4-1y3+IOy2+IIy+1. Since f has three distinct monic irreducible factors in F23[x], the polynomial F can have at most three roots in IF 23. By using either the methods to be discussed in the next section or trial and error, one determines the roots ofF in IF23 to be -3, 2, and 6. Furthermore, gcd(/(x ), h2(x )+3) = x -4, gcd(!(x), h2(x)-2) = x2- x + 7, gcd(/(x ), h2(x) -6) = x3 + 2x2 +4x-6, 142 Factorization of Polynomials so that f(x) � (x -4)(x2-x +7)(x3 + 2x2 +4x -6) is the canonical factorization of f(x) in F23[x). D Another method of characterizing the elements c E IF q for which the greatest common divisors in ( 4.2) need to be calculated is based on the following considerations. With the notation as above, let C be the set of all c E F• such that gcd( f(x), h(x)-c)* I. Then (4.2) implies f(x)� n gcd(!(x),h(x)-c), (4.14) ,ec and sof(x) divides n,ec(h(x)- c). We introduce the polynomial G(y)� 0 (y-c). ,e c Thenf(x) divides G(h(x)) and the polynomial G(y) may be characterized as follows. 4.8. Theorem. Among all the polynomials g E IF•[y) such that f(x) divides g(h(x)), the polynomial G(y) is the unique monic polynomial of least degree. Proof We have already shown that the monic polynomial G(y) is such that f(x) divides G(h(x)). It is easily seen that the polynomials g E F•[y) with f(x) dividing g(h(x)) form a nonzero ideal of F•(y). By Theorem 1.54, this ideal is a principal ideal generated by a uniquely determined monic polynomial G0 E F•[y). It follows that G0(y) divides G(y), and so Go(y)� 0 (y-c) c e c1 for some subset C1 of C. Furthermore, f(x) divides G0(h(x)) � n,.ec,(h(x)-c), and hence f(x) � n gcd(/(x), h(x)-c). ,.e c1 A comparison with (4.14) shows that C1 �C. Therefore G0(y) � G(y), and the theorem follows. D This result is applied in the following manner. Let m be the number of elements of the set C. Then we write m G(y)� n (y-c)� L bjyi rEC j=O 2. Factorization over Large Finite Fields wilh coefficienls b1 E IF •. Now f(x) divides G(h(x)). so !hal we have "' L b1h(x)' = Omodf(x). J=O 143 Since bm = I, this may be viewed as a nontrivial linear dependence relation over Fq of !he residues of I, h(x), h(x)2, ..• ,h(x)"'modf(x). Theorem 4.8 says !hal wilh !he normalizalion b., � I !his linear dependence relalion is unique, and !hal !he residues of l,h(x),h(x)2, ••• ,h(x)"'-1modf(x) are linearly independenl over IF •. The bound m.; k follows from (4.14). The polynomial G can !hus be de!ermined by calculaling !he residues modf(x) of I, h(x), h(x)2, ... unlil we find !he smallesl power of h(x) !hal is linearly dependenl (over IF•) on its predecess ors. The coefficienls of !his firs! linear dependence relalion, in !he normalized form, are !he coefficienls of G. We know !hal we need no! go beyond h(x)k 10 find !his linear dependepce relalion, and k can be obtained from Berlekamp's algorilhm. The elemenls of C are now precisely !he rools of !he polynomial G. This mel hod of reducing !he problem of finding !he elemen Is of C lo !hal of calculaling !he rools of a polynomial in F q is called !he Zassenhaus algo­ rithm. 4.9. Example. Consider again !he polynomial f E F23[x] from Example 4.7. From Berlekamp's algorilhm we oblained k � 3 and !he /-reducin g polynomial h(x) � x3 + 2x2 + 4x E f,23[x]. We apply !he Zassenhaus algorilhm in order 10 de!ermine !he elemenls c E.JF23 for which gcd(/(x), h(x)-c)* I. We have h(x) = x3 +2x2 +4x modf(x), h(x)2 = 7x5 +7x4 +2x3 -2x2 -6x -1modf(x), and so i! is clear !hal h(x)2 is no! linearly dependenl on I and h(x). Therefore, h(x)3 musl be !he smallesl power of h(x) !hal is linearly dependenl on ils predecessors . We have h(x)3 = -llx5 -llx4-x3 -9x2 -5x -2modf(x), and !he linear dependence relalion is h(x )3-5h (x )2 + llh (x )-10 = 0 modf(x ). so !hal G( y) � y3-5 y2 + lly-10. By using eilher !he mel hods lo be discussed in the next section or trial and error, one determines the roots of G lo be -3, 2, and 6. The canonical faclorizalion off in F,[x] is !hen oblained as in !he las! par! of Example 4. 7. 0 A me!hod !hal is conceplually more complica!ed, bu! of greal !heorelical inleresl, is based on !he use of malrices of polynomials . By a 144 Factori zation of Polynomials matrix of polynomials we mean here a matrix whose entries are elements of F •[x]. 4.10. Definition. A square matrix of polynomials is called nonsingular if its determinant is a nonzero polynomial, and it is called unimodular if its determinant is a nonzero element of IF q· 4.11. Definition. Two square matrices P and Q of polynomials are said to be equivalent if there exists a unimodular matrix U of polynomials and a nonsingular matrix E with entries in F• such that P � UQE. It is easily verified that this notion of equivalence is an equivalence relation, in the sense that it is reflexive, symmetric, and transitive. We have seen in Section 1 that there are polynomials h 2, ...• h. E F•[x] with 0 < deg(h1) < deg(/) for 2.;, i.;, k, which together with h1 � 1 are solutions of h• = h mod f that are linearly independent over F q· Clearly, the polynomials h 1 may be taken to be monic. The following theorem is fundamental. 4.12. Theorem. Let f � /1 • • • /,, where f1, ••• ,f, are distinct monic irreducible polynomials in F q[ x ], and let h 2, ... , h k E IF •[ x] be monic po(v­ nomials with O<deg(h1 )<deg(f)for 2.;,i.;,k, which together with h1�1 are solutions of h • = h mod f that are linearly independent over IF q· Then the diagonal matrix of polynomials /, 0 0 0 /, 0 D� 0 0 /, 0 0 0 is equivalent to the matrix of polynomials I 0 0 h, -1 0 A� h, 0 -1 h, 0 0 0 0 0 f. 0 0 0 -1 Proof By the argument following (4.3) we have h1(x) = e11mod /j(x) with e11 E F• for 1.;, i,j.;, k. Let E be the k X k matrix whose (i, j) entry is e,J' We show first that E is nonsingular. Otherwise, there would exist 2. Fac10rizalion over Large Finite Fields elements d 1, ... , d, E F •' not all zero, such that ' This implies that ' L, die if= 0 for 1 � j -E:; k. i-1 L d,h, = OmodJ; for l<i: j <i: k, i-1 t45 and so L.�_,d,h, = 0 mod f. Since deg(h,) < deg(/) for I <i: i <i: k, it follows that L.7_,d,h, � 0, a contradiction to the linear independence of h, .... ,h,. Next we note that AE is a nonsingular matrix of polynomials. Thus we can write D � ( D(AE)-1)AE, so that the theorem is established once we have shown that U � D(AE)-1 is a unimodular matrix of polynomials. Let b,j E F q[x) be the (i, j) entry of AE. Then b1j � le1j �I= Omod.fj 'for l"j-E;;k, and for 2-E;;i.E:;k we have bl1=hie11-eij= h,-eij = OmodJ; for l<i: j <i: k, so that Now b,,=Omod.t; for l<i:i,j,.k. (4.15) _, I (-!)'-' (AE) � det(AE) (B,J,�•.j�' � det(E)I (B,J,�,,J�'' where B,j is the cofactor of the (J, i) entry in AE,_and -1 (-!)'-' U� D(AE) � det(E)I (/.B,J,�,,j�,. Since (4.15) implies that B,j = Omod(// /,), it follows that each entry of U is a polynomial over f q· Furthermore, det(U) � det(D) det(AE) t=-L det( E) ' which is a nonzero element of F q· Thus, U is a unimodular matrix of polynomials. D Theorem 4.12 leads to the theoretical possibility of determining the irreducible factors of I by diagonalizing the matrix A. The number k as well as the entries h2, ... ,h, in the first column of A can be obtained with relative ease by Berlekamp's algorithm. The algorithm that achieves the diagonalization of A is, however, quite complicated. The diagonalization algorithm is based on the use of the following elementary operations: (i) permute any pair of rows (columns); (ii) multiply any row (column) by an element ofF;; (iii) multiply some row (column) by a monomial (element of Fq) and add the result to any other row (column). 146 Factorization of Polynomials The elementary row operations may be performed by multiplying the original matrix from the left by an appropriate unimodular matrix of polynomials. whereas the elementary column operations may be performed by multiplying the original matrix from the right by an appropriate nonsin­ gular matrix with entries in F •. Therefore, the new matrix obtained by any of these elementary operations is equivalent to the original matrix. One can show that A is equivalent to a matrix R of polynomials with the property that for each row of R the degree of the diagonal entry is greater than the degrees of the other entries in the row. The matrix R can be computed from A by performing at most (26 + k -IXk -I) elementary operations, where 6 � deg( h 2) + · · · + deg( h k ). We note that the diagonal entries of R can be permuted by carrying out suitable row and column permutations. We can thus obtain a matrix S that, in addition to the property of R stated above, satisfies deg(s;;);;. deg(s1) for I.; i.; j.; k, where the s;; are the diagonal entries of S. By multiplying the rows of S by appropriate elements ofF;. if necessary, we may assume that the s;; are monic polynomials. A matrix S of polynomials with all these properties is called a normalized matrix. The diagonal entries of the matrix D in Theorem 4.12 may also be arranged in such a way that deg(/,);;. deg(j;J for !.; i.; j.; k. The result­ ing equivalent matrix, which we again call D, is then diagonal and normal­ ized. Using the fact that the normalized matrix Sis equivalent to D, one can then show that deg(s,,) � deg(/,) for I.; i.; k. Thus, one can read off the degrees of the various irreducible factors of I from the diagonal entries of S. Furthermore, if dis a positive integer which occurs as the degree of somes", and if S(d> is the square submatrix of S whose main diagonal contains exactly all s,, of degree d, then one can prove that the determinant of S(Jl is equal to the determinant of the corresponding submatrix of D. Thus det(S("') � gd, where gd is the product of all/, of degree d. In this way we are led to the partial factorization I� [Jgd, (4.16) d where the product is over all positive integers d that occur as the degree of some/,. In summary, we see that the matrix S can be used to obtain the following information about the distinct monic irreducible factors of f: the degrees of these factors, the number of these factors of given degree, and the product of all these factors of given degree. If the /, have distinct degrees, or, equivalently, if the s,, have distinct degrees, then (4.16) repre­ sents already the canonical factorization of I in IF .lx ]. If ( 4.16) is not yet the canonical factorization, then one can proceed in various ways. An obvious option is the application ofone of the methods discussed earlier to factor the polynomials gd. One can also continue with 2. Factorization over Large Finite Fields 147 the diagonalization algorithm in order to obtain the diagonal matrix D equivalent to the normalized matrix S. For the latter purpose, we assume as above that D is put in normalized form. In addition to the properties mentioned above, it is then also true that each of the submatrices s<•> is equivalent to the correspond­ ing submatrix D<•> of D. It is therefore sufficient to diagonalize each of the submatrices s<d> separately. By the equivalence of s<d> and D<d> we have s<•> � UD<•>£ for some unimodular matrix U of polynomials and some nonsingular matrix E with entries in F •. We may then write s<d> � s<d> + s<d>x + · · · + s<d>xd 0 I d ' where the s:•>, D:•>, and U,, 0"' r"' d, 0 .,, "' m, are matrices with entries in F •' Um * 0, and SJdl � DJd> � I, the identity matrix of appropriate order. A comparison of the matrix coefficients of the highest powers of x on both sides of the equation s<•> � UD1d1E yields I� UmiE and m � 0. Thus, U � U0 � E-1 and hence s<d> � E-1D<•>£. Comparing the matrix coefficients of like powers of x in the last identity gives S,ldl = E-1D,Id>£ for 0 .,., "'d. Consequently, s,<dl and D,<dl have the same characteristic polynomial and eigenvalues, and since D,ldl is diagonal, its eigenvalues are exactly its diagonal entries. Therefore, the latter can be determined by finding the roots of the characteristic polynomial of s:dl, which must all be in IF •. As in the earlier methods, we have thus again reduced the factorization problem to that of finding the roots of certain polynomials in IF •. The partial factorization (4.16) can also be obtained by an entirely different method. To this end, we extend the definition of gd by letting g1, i ;.I, be the product of all monic irreducible polynomials in IF.[x] of degree i that divide f. In particular, g1(x) �I in case f has no irreducible factor in IF•[x] of degree i. We can thus write t� flg, i�l It is trivial that only those i with i "'deg(f) need to be considered. We calculate now recursively the polynomials . r0(x), r1(x),... and F0(x), F1(x), ... as well as d1(x), d2(x), .... We start with r0(x) � x, F0(x) � f(x), 148 Factorization of Polynomials and for i ;;. I we use the formulas r1 (x) = r1_1 ( x) •mod £,_1 (x ), deg( r,) < deg( £,_1 ), d1(x) � gcd( £,_1 (x ), r1(x )-x ), F,(x) � £,_1(x )/d,(x ). The algorithm can be stopped when d1(x) � £,_1(x ). 4.13. Theorem. With the notation above, we have d,(x) � g1(x)for al/i;.l. Proof Using the fact that F, divides£,_ 1, a straightforward induc­ tion shows that r1(x) = x•'mod £,_1 (x) for all i;;. I. We prove now by induction that F,-1� ngj and d,�g, foralli>l. jtJoi ( 4.17) (4.18) For i �I the first identity holds since F0 �f. As to the second identity, we have d1 (x) � gcd( F0(x ), r1 (x )-x): gcd(f(x ), x•-x) by (4.17), and since x•-xis the product of all monic linear polynomials in F.[x], it follows that d1 is the product of all monic linear polynomials in F.[x] dividing/, and hence d1 � g1. Now assume that (4.18) is shown for some i ;;. I. Then r; � r:-1/d, � r;_ ,;g, � n gj. j "> i +I ( 4.19) which proves the first identity in ( 4.18) for i + I. Furthermore, d,+ 1 (x) � gcd( F,(x ), r1+ 1 (x )-x) � gcd( F,(x ), x•"'-x) by (4.17). According to Theorem 3.20, x•"'-xis the product of all monic irreducible polynomials in F.[x] whose degrees divide i+ I. Consequently, d1 + 1 is the product of all monic irreducible polynomials in F •[ x] that divide F, and whose degrees divide i + I. It follows then from ( 4.19) that d1+ 1 � g1+ 1. D In the algorithm above, the most complicated step from the view­ point of calculation is that of obtaining r1 by computing the qth power of r1 _ 1 mod F, _ 1. A common technique of cutting down the amount of calcula · tion somewhat is based on computing first the residues mod F, _ 1 of r; _ 1, r/:_ 1, r;4_ 1, ••• , r/:_ 1 by repeated squaring and reduction mod F; ___ 1, where 2' is the largest power of 2 that is " q, and then multiplying together an appropriate combination of these residues mod £,_1 to obtain the residue of 2. Factorization over Large Finite Fields 149 r;'�_1mod£,-_1. For instance, to get the residue of r;�1mod�_1, one would multiply together the residues of r;1� 1, r;"� .. 1, r;:_1, and r;_1mod �-J· Instead of working with the repeated squaring technique, we could employ the matrix B from Berlekamp 's algorithm in Section I to calculate r1 from r1_1• We write n � deg(f) and n-l r;-J (x) = E r/:!.�xi, J-0 and define (s;(O),sp), ... ,s;<n-ll)EF; by the matrix identity ( s;<O)' S;(J)' ... ,sfn-I))= ( r;'f3_)1' r/!._)1• .... r/�11)) B, where B is the n X n matrix in (4.5). With n-l s,(x)= L s1Ulxj J-0 ( 4.20) (4.21) we get then r1_1(x)• = s,(x)modf(x), hence r1_1(x)• = s,(x)mod £;_1(x), and thus Therefore. once the matrix B has been calculated, we computer; from r;_1 in each step by reduction mod £,_1 of the polynomials, obtained from (4.20) and (4.21). 4.14. Example. We consider f(x)�x6- 3x5+5x4-9x3-5x2+6x+ 7EIF23[x] as in Example4.7. Then I 0 0 0 0 0 5 0 -I 8 -3 -10 B= -10 10 10 0 I -9 0 7 9 -8 10 -II II 0 -4 7 7 2 -3 0 -10 9 2 -9 We start the algorithm with r0(x) = x, F0(x) = f(x). From (4.20) and (4.21) we get s1 (x) � -lOx' -3x4 + 8x3 -x2 + 5, and reduction mod F0(x) yields r1(x) = s1(x). By Theorem 4.13 we have g1(x) � d1(x) = gcd(F0(x), r1(x)-x) � x -4. Furthermore, F1(x) � F0(x)jd1(x) = x' + x4 + 9x3 + 4x2 + llx +4. In the second iteration, we use again (4.20) and (4.21) to obtain s2(x)�5x5-8 x4+9x3-10x 2-ll, and reduction modF1(x) leads to r2(x)=l0x4+10x3-7 x2-9x-8. By Theorem 4.13 we have g2(x)= d2(x) = gcd(F1(x), r2(x)-x) = x2 -x + 7. Furthermore, F2(x) = F1(x)jd2(x) = x' +2x2 +4x -6. But, according to the first part of (4.18), all irreducible factors of F2(x) have degree;. 3, so that F2(x) itself must be 150 Factorization of Polynomials irreducible in F23[x] and g3(x) � F2(x). Thus, we arrive at the partial factorization f(x) � (x -4)(x2-x +7)(x3 +2x2 +4x -6), which, in this case, is already the canonical factorization off( x) in F 23 [ x]. D 3. CALCULATION OF ROOTS OF POLYNOMIALS We have seen in the preceding section that the problem of determining the canonical factorization of a polynomial can often be reduced to that of finding the roots of an auxiliary polynomial in a finite field. The calculation of roots of a polynomial is, of course, a matter of independent interest as well. In general. one will be interested in determining the roots of a polynomial in an extension of the field from which the coefficients are taken. However, it suffices to consider the situation in which we are asked to find the roots of a polynomial f E IF q(x] of positive degree in IF •• since a polynomial over a sub field can always be viewed as a polynomial over F q· It is clear that every factorization algorithm is, in particular, a root-finding algorithm since the roots off in F q can be read off from the linear factors that occur in the canonical factorization off in Fq[x]. Thus, the algorithms presented in the earlier sections of this chapter can also be used for the determination of roots. However, these algorithms will often not be the most efficient procedures for the more specialized task of calculating roots. Therefore, we shall discuss methods that are better suited to this particular purpose. As a first step, one may isolate that part off which contains the roots of fin IF •. This is achieved by calculating gcd(/(x), x•-x). Since x•-xis the product of all monic linear polynomials in IF q(x], this greatest common divisor is the product of all monic linear polynomials over F• dividing[, and so its roots are precisely the roots off in F q· Therefore, we may assume, without loss of generality, that the polynomial for which we want to find the roots in IF q is a product of distinct monic linear polynomials over F q· A useful method of finding roots of polynomials was already dis­ cussed in Chapter 3, Section 4. It is based on the determination of an affine multiple of the given polynomial. See Example 3.55 for an illustration of this method. In order to arrive at other methods, we consider first the case of a prime field F ,. As we have seen above, it suffices to deal with polynomials of the form " f(x)� n (x-c,), i=l 3. Calculation of Roots of Polynomials !51 where c 1, ••• , c, are distinct elements of IF P" If p is small, then it is feasible to determine the roots off by trial and error, that is, by simply calculating f(O),f(I), ... ,f(p -I). For large p the following method may be employed. For bE F,, p odd, we consider " f(x-b)� n (x-(b+c,)). i=l We note that f(x-b) divides x'-x � x(x<P-l)/2 + I)(x<p-l)/2-1). If x is a factor of f(x-b), then/(-b)� 0 and a root off has been found. If xis not a factor of f(x-b), then we have f(x-b)� gcd{f(x-b), x<p-l)/2 + I}gcd(/(x-b), x<p-l)/2-I}. ( 4.22) The identity (4.22) is now used as follows. We. calculate the residue mod f(x-b) of x<p-l)/2 -for example, by the repeated squaring technique discussed after Theorem 4.13. If x<p-l)/2�±Imodf(x-b), then (4.22) yields a nontrivial partial factorization of f(x-b). Replacing x by x + b, we get then a nontrivial partial factorization of f(x). In the rather unlikely case where x<p-l)/2-= ±I mod/(x-b), we try another value of b. Thus, by using, if necessary, several choices forb, we will find either a root off or a nontrivial partial factorization of f. Continuing this process, we will eventu­ ally obtain all the roots of f. It should be noted that, strictly speaking, this is not a deterministic, but a probabilistic root-finding algorithm, as it depends on the random selection of several elements b E F ,. 4.15. Example. Find the roots of f(x) � x6 -?x' + 3x4 -?x' + 4x2- x-2 E F 17[x] contained in F 17• The roots of f(x) in IF 17 are precisely the roots of g(x) � gcd(f(x), x11-x) in IF 17. By the Euclidean algorithm we obtain g(x) � x4 + 6x'-5x2 + ?x-2. To find the roots of g(x ), we use the algorithm above and first select b � 0. A straightforward calculation yields x<p-l)/2 � x'-= I mod g(x ), and so this value of b does not afford a nontriv­ ial partial factorization of g( x ). Next we choose b � 1. Then g( x -I) � x4 +2x' -3x -2 and x8 = -4x3 -7x2 + 8x -5mod g(x -I), so that b �I yields a nontrivial partial factorization of g(x-1). We have gcd( g(x -I), x8 +I}� gcd(x4 +2x' -3x -2, -4x3 -7x2 + 8x -4) � x2 -?x +4 and gcd( g(x-I), x8-I}� gcd(x4 +2x'-3x -2,-4x3 -7x2 + 8x -6) =x2-8x+8, 152 Factorization of Polynomials hence (4.22) implies g(x -I)� (x2 -7x +4)(x2 -8x +8), which leads to the partial factorization g(x) � (x2 -5x -2)(x2 -6x +I)� g1(x)g2(x), say. In order to factor g1(x) and g2(x), we try b � 2. We have g1(x -2) � x2 + 8x-5 and x8 =-8x + 2mod g1(x-2). Furthermore, gcd( g 1 ( x -2), x 8 + I} � gcd( x 2 + 8x -5, -8x + 3) � x + 6, and long division yields g 1 ( x -2) � ( x + 6)( x + 2), so that g1(x)� (x+8)(x+4). Turning to g2(x), we have g2(x-2) � x2 +7x � x(x + 7), thus -2 is a root of g2(x) and g2(x)�(x+2)(x-8). Combining these factorizations, we get g(x) � (x + 8)(x +4)(x + 2)(x-8). Therefore, the roots of g( x ), and thus of/( x ), in F 11 are -8, -4, -2, 8. D Next we discuss a root-finding algorithm for large finite fields F • with small characteristic p. As before, it suffices to consider the case where n /(x)�n(x-y,) i-1 with distinct elements y1,. .. , Yn E F q· Let q � pm and define the polynomial m-1 S(x) � L xP' J-0 We note that for y E IF• we have S(y) � TrF,(y) E FP' where TrF, is the absolute trace function (see Definition 2.22). Because of Theorem 2.23(iii), the equation S( y) � c has pm-1 solutions y E F • for every c E F P' and this observation leads to the identity x•-x� n (S(x)-c). (4.23) CE FP Sincef(x) divides x•-x, we get n (S(x)-c)=Omodf(x), cE FP and so f(x)� n gcd(/(x),S(x)-c). (4.24) CE fp 3. Calculalion of Rools or Polynomials 153 This yields a partial factorization of f(x) that calls for the calculation of p greatest common divisors. If p is small, this is certainly a feasible method. It can. however, happen th.at the factorization in (4.24) is trivial-namely, precisely when S(x) = cmodf(x) for some c E FP" In this case, other auxiliary polynomials related to S(x) have to be used. Let p be a defining element of F• over FP, so that {l,{J,{J2, ... ,pm-l) is a basis of F• over FP. For j � O,l, ... ,m -1 we substitute fJ'x for x in (4.23) and we get (pi)"x•-pix� 0 (s(P'x)-c). cEFP Since ([Jf)• � {J1, we obtain x•-x�p-, n (s(P1x)-c). eEFP This yields the following generalization of (4.24): f(x)� 0 gcd(f(x),S([Jix)-c) forO,.;j,.;m-1. (4.25) ceFP We show now that if n � deg(f);. 2, then there exists at least one j, 0,.; j,.; m-1, for which the partial factorization in (4.25) is nontrivial. For suppose, on the contrary, that all the partial factorizations in (4.25) are trivial. Then for eachj, 0,.; j,.; m -1, there exists a c, E IFP with s(pix) = cj�odf(x) .. In particular, we get s(piy,) � s(piy,) � cj for 0,. j .. m -1. By the linearity of the trace it follows that Tr.,((y1-y2)1Ji)�o forO,.;j,.;m-1 and Using the second part of Theorem 2.24, we conclude that y1 -y2 � 0, which is a contradiction. Thus, for at least one j the partial factorization in (4.25) is nontrivial. The defining element p of o=. over FP used in(4.25) is chosen as a root of a known irreducible polynomial in IFP[x] of degree m. Once a nontrivial factorization of the form (4.25) has been found, the method is applied to the nontrivial factors by employing other values of j. The argument above shows also that all distinct roots of f can eventually be separated by using all the values of j in (4.25). 154 Factorization of Polynomials 4.16. Example. Consider IF64 = F2(,8), where ,B is a root of the irreducible polynomial x6 + x + 1 in IF2[x], and let f( x) = x' + ( ,B' + ,84 + ,83 + ,82 )x' + ( ,B' + ,84 + ,82 + ,B + 1 )x2 + ( ,84 + ,83 + ,8) X + ,83 + ,8 E IF 64 [X]. Using x6 = ( ,B' + ,B + 1) x' + ( ,B 4 + ,83 + ,B 2) x 2 + ( ,B' + ,B 3 + ,82 + 1) x + ,85 + ,8 4 + ,82 + 1 modf(x), we get the following congruences mod f(x) by repeated squaring: X x' (/14 + pJ + fj2)x'+ (/l� + /33 +.8lx3+ ({J� + p4 +/12 + P+ l)xl+(Jj4 + pJ +{J)x+ pJ + /1 (/1� + f1 + l)x2 +(/1� + p + l)x+ /1� + /14 ( /33 + fl)x2. + f3�x + p4 + pl + p2 + fJ + I Thus./(x) divides x64-x and so has four distinct roots in !'64• We consider now S(x) = x + x2 + x4 + x8 + x16 + x32. From the congruences above we obtain S(x) = (,85 + ,83 + ,82 + ,B + l)x' + ,B5x2 + (,83 + .B')x +,83+,82+l modf(x). and therefore gcd(/(x ). S(x )) = gcd(/(x ). ( ,B' + ,83 + ,82 + ,B + l)x3 + ,B'x' +(,83 + ,B')x + ,83 + ,82 + 1) =x' +(,84 + ,83 + ,82)x2 + (,B' + ,82 + l)x + ,83 + ,82 = g(x) say, and gcd(/(x), S(x)-1) = gcd(/(x),(,B' + ,83 + ,82 + ,B + l)x' + ,B'x' + (,83 + ,82) X+ ,83 + ,82) =X + ,85• Then ( 4.24) yields f(x)=g(x)(x+,B'). To find the roots of g(x), we next use (4.25) withj = 1. We have S( ,Bx) = ,Bx + .B'x' + ,84x4 + ,B'x' + ,816x16 + ,B32x32 = ,Bx + ,B2x2 + ,84x4 + (,83 + ,82 )x' + (,84"+ ,B + l)x16 + (,83 + 1 )x32, (4.26) 3. Calculation of Roots of Polynomials !55 and the congruences above yield S(/h) = ({32 + l)x' +({3' + f3 + l)x2 + ({35 + {34 + {33 + {32 + f3 + l)x + {34 + {32 + f3modf(x ). Since g(x) divides f(x ), this congruence holds also mod g( x ), and so S(f3x) = ({32 + l)x' +({33 + f3 + l)x2 +({35 + {34 + {33 + {32 +{3 + l)x +{3'+{32+{3 = ( {35 + {32 )x2 + {33x + {35 + {33 + f3mod g( x). Thus, gcd( g (X), S( {3x)) � gcd( g( X), ( {35 + {32) X 2 + {33 X + f35 + {33 + {3) �x2 + (f3' + l)x + {34 + {33 + {32 + {3� h(x), say, and gcd( g( X), S( {3x)-1) � gcd( g (X), ( {35 + {3 2) X 2 + {33 X + {3 5 + {33 + {3 + 1) �x +{3' +{32 + 1. Then (4.25) with}� 1 yields To find the roots of h(x), we use (4.25) with} �·2. We have s( f32x) � {32x + f34x2 + f38x4 + {316x8 + f3"x 16 + f364x32 � {32x + {34x2 + ( {33 + {32 )x4 + ( {34 + f3 + 1 )x8 + ( {33 + 1 )x16 + f3x32, and a similar calculation as for S(f3x) yields S( {32 x) = ( {35 + {32 + 1 )x + {35 + {33 + {32 mod h ( x). Therefore, ( 4.27) gcd( h (X), S ( {3 2 X)) � gcd( h (X), ( f35 + {3 2 + 1) X + {3 5 + {3' + {3 2) �x+f3+1 and gcd( h (X), S( {3 2 X)-1) � gcd ( h (X), ( {35 + {3 2 + 1) X + {35 + {3 J + {3 2 + 1) �x+f3'+f3, so that from (4.25) with}� 2 we get h (X) � (X+ {3 + 1 )(X+ {33 + {3). (4.28) !56 Factorization of Polynomials Combining (4.26), (4.27), and (4.28), we arrive at the factorization /( x) � (x + fJ +I)( x + /l3 + fJ )( x + /l4 + /l2 + I)( x + fl'), and so the roots ofj(x) are fJ +I, fl3 + fl, fl4 + /l2 +I, and fl5. 0 Finally we consider the root-finding problem for large finite fields F • with large characteristic p. As we have seen before, it suffices to know how to treat polynomials of the form " f(x)�n(x-y,) i-1 with distinct elements y1, ... ,y. ElF •. To check whether f(x) has this form, we need only verify the congruence x• = xmod/(x) (compare with the first part of Example 4.16). We can assume that q is the least power of p for which this holds. The polynomial /(x) will. of course, be given by its standard representation " f(x) � L a1x1, j-0 where a1 E IF q for 0 � j � n and an = 1. It will be our first aim to find a nontrivial factor of f(x ). To exclude a trivial case. we can assume n ;. 2. Let q � pm and define the polynomials " j,(x) � L aJ'xi forO.;; k.;; m -I, J-0 (4.29) so that /0(x) � f(x) and each /,(x) is a monic polynomial over IF •. Furthermore, /, ( y(') � t o.j' Y/'' � ( t o.1 Y/) ,• � 0 J�O j-0 for 1 � i � n, 0 4; k � m -1, and so " /, (X) � n (X-Yr') for 0.;; k.;; m -J. i-1 We calculate now the polynomial m -1 F(x)�nt,(x). k-0 This is a polynomial over F P since m-1 n n m-1 n ( 4.30) F(x) � n n (x-y('} � n n (x-yf') � n F,(x)m;d,, k=O i-1 i-1 k=-0 i-1 where F,(x) is the minimal polynomial of y, over F, and d, is its degree (compare with the discussion following Definition 2.22). The F,(x) are 3. Calculation of Roots of Polynomials 157 therefore the irreducible factors of F(x) in F,[x], but certain F,(x) could be identical. Thus, the canonical factorization of F(x) in F,[x) has the form F(x) �Gb)· · · G,(x), (4.31) where the G,(x), I<;;l<;;r, are powers of the distinct F,(x). This canonical factorization can be obtained by one of the factorization algorithms in Section 2 of this chapter. Since f(x) � f0(x) divides F(x), it follows from (4.31) that f(x) � TI gcd(/(x),G,(x)). (4.32) t-1 In most cases. (4.32) will provide a nontrivial partial factorization of f(x). The factorization will be trivial precisely if gcd(/(x), G,(x))�j(x) for some I, 1.;; I<;; r, which is equivalent tor� I andf(x) dividing F1(x). A comparison of degrees shows then n � d 1 = m. Furthermore, the roots of f(x) are then all conjugate with respect to IF,. Thus, by labelling the roots of f(x) suitably, we can write y,.=y(' for 1�i�n,with0=b1<b2<··· <bn<m. We set bn+l = m and · d� min (b,+1-b,). I os; i <10: n It is clear that d.;; mjn. The following two possibilities can occur: (A) h;+ 1-h; > d for some i, 1 � i � n; (B) b1+1-b,�dforalli,I.;;i.;;n. In case (A) we note that the set of roots of f(x) is { ., r'' r'·) yf . "Y •.•.• "Y and the set of roots of fd ( x) is The condition in (A) implies that these two sets of roots are not identical. On the other hand, since bi+l-h; = d for some i, 1 � i � n, the two sets of roots have a common element. Thus, gcd(/(x),/d(x)) "'j(x) and"' I; that is, gcd(/(x)./d(x)) is a nontrivial factor of j(x). We observe also that in this case we have d < mjn. In case (B) a comparison of the sets of roots ofj(x) andfd(x) shows thatf(x) � fd(x), whereas gcd(/(x).f.(x)) �I for I.;; k <d. Moreover, we have d�mjn, so that n divides m, and also b,�d(i-I) for l.;;i.;;n.lt follows that • .:t1 j- u f I . Yi = yf or � 1 � n, 158 Factorization of Polynomials hence the y, are exactly all the conjugates of y1 with respect to IF, •. Consequently, .J(x) is the minimal polynomial of y1 over IF,, and thus irreducible over F Pd. Therefore, corresponding to the cases (A) and (B) above we have the following alternatives: (A) gcd(f(x),f,(x)) is a nontrivial factor of f(x) for some k,I.;k<m/n; (B) gcd(f(x), /,(x)) �I for I.; k < d � mjn EN andf(x) � fa(x) is the minimal polynomial of y1 over F, •. In alternative (A) our aim of finding a nontrivial factor of f(x) has been achieved. Further work is needed in alternative (B). Let fJ again denote a defining element of IF, over F ,. Then IF ,•( fJ) �IF,� IF,., and so fJ is of degree m/d � n over F, •. In particular, we have fJ'"' If,, for I.; j.; n -I. Now let the coefficients a1 of f(x) be such that a,,* 0 for some j0 with I :!5; j0 :!5; n -I. Consider (4.33) which is a monic polynomial of degree n over IF_,. Since fJ"-''"' IF,, and a10EIF; •. it_follows that the coefficient of x1' inf(x) is not an element of IF, •. Thus f(x) is not a polynomial over F,,, and so _the alternative (B) cannot occur if the procedure above is applied to f(x). Since f(x) � fl"j( fl-1x ). any nontrivial factor of j(x) yields immediately a nontrivial factor off ( x ). It remains to consider the case where alternative (B) is valid and a1 � 0 for I.; j.; n-I. Then f(x) is the binomial x" + a0 E F,.[x]. Now n is not a multiple of p, for otherwise we would havef(x) � (x•IP + aS'-')P, which would contradict the irreducibility of f(x) over IF, •. We set (4.34) and then it is easily seen from fJ-1 "' IF ,• that the coefficient of x"-1 in j( x) is not in IF ,•. Thus, the alternative (B) cannot �ur if the procedure described above is applied to f(x ). Since f(x) � fl"f( fl-1(x-I)), any non­ trivial factor of /(x) yields immediately a nontrivial factor of f(x). This root-finding algorithm is thus carried out as follows. We first form the polynomials J,(x) according to (4.29) and then the polynomial F(x) E IF,[x] according to (4.30). Next, we apply a factorization algorithm to obtain the canonical factorization (4.31) of F(x) in IF,[x]. This leads to the partial factorization of f(x) given by (4.32). Should this factorization be trivial, we calculate gcd(f(x), /,(x)) for I.; k < mjn. If this also does not produce a nontrivial factor of f(x). we transform f(x) into j(x) by either (4.34) or (4.33), depending on whether f(x) is a binomial or not. As we have shown above, an application of the algorithm to/< x) is bound to yield a Exercises !59 nontrivial factor of /(x) and thus of l(x). Once a nontrivial factor of l(x) has been found, the procedure is continued with the resulting factors in place of l(x ), until l(x) is split up completely into linear factors. EXERCISES 4.1. Factor x12 + x 7 + x5 + x4 + x' + x2 + 1 over F2 by Berlekamp's algo­ rithm. 4.2. Factor x7 + x6 + x5-x' + x2-x-1 over F3 by Berlekamp's algo­ rithm. 4.3. Let IF4=F2(8) and factor x5+8x4+x3+(1+8)x+8 over F4 by Berlekamp's algorithm. 4.4. Use Berlekamp's algorithm to prove that x6-x' -x-1 is irreduc­ ible in IF3[x]. 4.5. Use Berlekamp's algorithm to determine the number of distinct monic irreducible factors of x4 + 1 in F,(x] for all odd primes p. 4.6. Use the polynomials T; in Section 1 to factor x5 + x4 + 1 over F2. 4.7. Determine the splitting field of x8 + x6 + x5 + x4 + x' + x2 + 1 over IF,. 4.8. Determine the splitting field of x6-x4-x2-x + 1 over F3. 4.9. Use the polynomials R, in Section 1 to factor the polynomial of Exercise 4.1 over IF2• 4.10. Find the canonical factorization of x8 + x6 + x4 + x' + 1 in F2[x] by using the polynomials R, in Section 1. ·. 4.11. Determine the canonical factorization of the cyclotomic polynomial Q31(x) in IF2(x]. 4.12. Factor l(x) = x8 + x' + 1 over F2 and determine ord(f(x)). 4.13. Factorl(x)=x9+x8+x7+x4+x 3+x+l overF2 and determine ord(f(x)). 4.14. Prove in detail that if I is a nonzero polynomial over a field and d = gcd(f, /'), then 1/d has no repeated factors. (Note: Count nonzero constant polynomials among the polynomials with no re­ peated factors.) 4.15. Let I be a monic polynomial of positive degree with integer coeffi­ cients. Prove that if I has no repeated factors, then there are only finitely many primes p such that 1. considered as a polynomial over F,, has repeated factors. 4.16. Determine the number of monic polynomials in IF q[x J of degree n � 1 with no repeated factors. 4.17. Let I be a monic polynomial over "• and let g1, ••• ,g, be nonzero polynomials over IF • that are pairwise relatively prime. Prove that if I divides g, · · · g,. then I= n;_, gcd(f, g.J. 4.18. Use Berlekamp's algorithm to prove the following special case of 160 Factorization of Polynomials Theorem 3.75: the binomialx'- a, where I is a prime divisor of q -1 and a E f;, is irreducible in f .[x 1 if and only if al•-l>l• *I. 4.19. Let/be an irreducible polynomial in IF.[x1 of degree nand define the n X n matrix B = ( b,J) by (4.4). Prove that the characteristic polynomial det( xi -B) of B is equal to x" -I. 4.20. Let f = f1 • • • /, be a product of k distinct monic irreducible poly­ nomials /1, ... ,/, in IF.(x] of degree n1, ... ,n,, respectively. Put deg(f) = n = n1 + · · · + n, and define then X n matrix B = (b,) by (4.4). Prove that the characteristic polynomial det(x/-B) of B is equal to (x"•-I)··· (x"• -I). 4.21. In the notation of Section I, prove that the polynomials T, do not separate those irreducible factors.fj of/for which Njnj is divisible by the characteristic of F q· 4.22. Let f E IF .[x 1 be monic of degree n;, I. Define hE F .[x, y] by h(x,y)= (y-x)(y-x•)(y-x•')· · · (y-x•"-')-f(y) and write h(x,y)=s._1(x)y"-1+ ··· +s1(x)y+s0(x). Prove that f is irreducible over F • if and only if f divides sj for O�j�n-1. 4.23. Use the criterion in the preceding exercise to prove that x 7 + x6 + x' + x2 +I is reducible over !'2. 4.24. Prove that the quadratic polynomialf(x) = x2 + bx +cis irreducible over F • if and only if f(x) divides x• + x + b. 4.25. Let fbe an irreducible polynomial in IF .[x] of degree m and let h be a root of/in IF ••. Let g and h be nonzero polynomials in F•(x]. Prove that h(x)mf(g(x)jh(x)) is irreducible in F.(x] if and only if g(x)­ Ah(x) is irreducible in f •• [x]. 4.26. Use the method in Example 4.7 to factor x4 +3x3 +4x2 +2x -I over f 13. 4.27. Use the method in Example 4.7 to factor x3 -6x2 -8x -8 over F19. 4.28. Use the Zassenhaus algorithm to factor x4 + 3x3 + 4x1 + 2x-I over F n· 4.29. Use the Zassenhaus algorithm to factor x3 -6x2 -8x-8 over IF 19• 4.30. Use the Zassenhaus algorithm to factor x5 + 3x4 + 2x3 -6x2 + 5 over IF 17• 4.31. Factor x4 -7x3 + 4x2 + 2x + 4 over IF 17. 4.32. Factor x4 -3x3 + 4x2-6x-8 over IF 19. 4.33. Prove in detail that equivalence of square matrices of polynomials as defined by Definition 4.11 is reflexive, symmetric, and transitive. 4.34. Use the method in Example 4.14 to factor x3 -6x2 -8x -8 over F 19· Exercises 161 4.35. Use the method in Example 4.14 to factor x' + 3x4 + 2x'-6x2 + 5 over IF 17. 4.36. Use the method in Example 4.14 to obtain a partial factorization of x1-2x6-4x4 + 3x'-5x2 + 3x + 5 over IF 11 and complete the fac­ torization by another method. 4.37. Find the roots of /(x)�x'-x4+2x3 +x2-x-2EIF5[x] con­ tained in IF 5. 4.38. Find the roots of f(x) � x' + 6x4 + 2x'-6x2-5x + 5 E f n[x] con­ tained in IF 13. 4.39. Prove that all the roots of /(x)�x3+8x2+6x-7EF 19[x] are contained in F 19 and find them. 4.40. Let IF32 � IF2(/l), where /l is a root of the irreducible polyno­ mial x' + x2 +I over F2. Prove that all the roots of f(x) � x' +(/l4 + ll' + l)x2 + !l'x + /l4 + ll' + /l +IE f32[x] are contained in IF 32 and find them. 4.41. Let F27 � IF3(/l). where /l is a root of the irreducible polynomial x'-x +I over IF3. Prove that all the roots of f(x) � x' + x2- (/l2 -!l + l)x + !l' -IE IF27[x] are contained in F27 and find them. 4.42. Let IF 169 � F "(/l), where /l is a root of the irreducible polynomial x'-x-1 over F". Find the roots of /(x)�x2+(3/l+l)x+/l+ 5 E IF 169[x] contained in F 169. 4.43. If the polynomial f(x-b) in (4.22) is quadratic with constant term c"' 0, prove that the factorization in ( 4.22) is nontrivial if and only if cis not the square of an element of IFP" 4.44. Let /l be a defining element ofF� F2., ove[IF2. Prove: (a) There exists k, 0.; k.; m-I, with TrF(/l•) �I. (b) For each i � 0, I, ... , m-I there exists an a, E F such that { ll' a2 +a-= ' , ll' + p• ifTrF(/l') � 0, if TrF(/l') �I. (c) If y � E;"_01 c,/l', c, E IF2, and TrF(Y) � 0, then the roots of x2 + x +yare Er=01 ciai and 1 +Ei-01 cia;. Chapter 5 Exponential Sums Exponential sums are important tools in number theory for solving prob­ lems involving integers-and real numbers in general-that are often in tractable by other means. Analogous sums can be considered in the framework of finite fields and tum out to be useful in various applications of finite fields. A basic role in setting up exponential sums for finite fields is played by special group homomorphisms called characters. It is necessary to distinguish between two types of characters-namely, additive and multi­ plicative characters-depending on whether reference is made to the addi­ tive or the multiplicative group of the finite field. Exponential sums are formed by using the values of one or more characters and possibly combin­ ing them with weights or with other function values. If we only sum the values of a single character, we speak of a character sum. In Section 1 we lay the foundation by first discussing characters of finite abelian groups and then specializing to finite fields. Explicit formulas for additive and multiplicative characters of finite fields can be given. Both types of characters satisfy important orthogonality relations. Section 2 is devoted to Gaussian sums, which are arguably the most important types of exponential sums for finite fields as they govern the transition from the additive to the multiplicative structure and vice versa. They also appear in many other contexts in algebra and number theory. As an illustration of their usefulness in number theory, we present a proof of the law of quadratic reciprocity based on properties of Gaussian sums. I. Characters 163 Exponential sums with the terms of a linear recurring sequence as arguments will be treated in Chapter 6, Section 7. Deep investigations on exponential sums for finite fields have been carried out with the help of algebraic geometry, leading to the famous results of Wei! and Deligne, but a presentation of this work would lead far beyond the scope of this book. I. CHARACTERS Let G be a finite abelian group (written multiplicatively) of order IGI with identity element lG. A character X of G is a homomorphism from G into the multiplicative group U of complex numbers of absolute value !-that is, a mapping from G into U with x(g1g2) = x(g1)x(g2) for all g10 g2 E G. Since x(lG) = x(lGJx(lG), we must have x(lG) = l. Furthermore, (x(g))IGI = x(giGI) = x(lG) = l for every g E G, so that the values of X are IGith roots of unity. We note also that x(g)x(g- 1)=x(gg-1)=x(lG)=l, and so x(g-1)= (X( g))-1 =X (g) for every g E G, where the bar denotes complex conjuga­ tion. Among the characters of G we have the trivial character Xo defined by Xo( g)= 1 ·for all g E G; all other characters of G are called nontrivial. With each character x of G there is associated the conjugate .character 5( defined by )((g)=x(g) for all gEG. Given finitely many characters x10 ...• x. of G, one can form the product character x1• • • x. by setting <x�· · · x.)(g) = X1(g) · · · x.(g) for all g E G. If X1 = · · · = x. = x. we write x" for x1• • • x •. It is obvious that the set G A of characters of G forms an abelian group under this multiplication of characters. Since the values of characters of G can only be I Gl th roots of unity, G A is finite. After briefly considering the special case of il finite cyclic group, we establish some basic facts about characters. 5.1. Example. Let G be a finite cyclic group of order n, and let g be a generator of G. For a fixed integer j, 0.;; j.;; n -1, the function xj(gk) = e2wijk/n, k = 0, l, ... ,n -1, defines a character of G. On the other hand, if xis any character of G, then X(g) must be an nth root of unity, say x(g) = e2•;J!" for some), 0.;; j.;; n -1, and it follows that x = XF Therefore, G A consists exactly of the characters x0,Xp···•Xn-J· 0 5.2. Theorem. Let H be a subgroup of the finite abelian group G and let .Y be a character of H. Then .Y can be extended to a character of G; that is, there exists a character x of G with X( h) = .Y (h) for all h E H. 164 Exponential Sums Proof We may suppose that His a proper subgroup of G. Choose a E G with a 'l H. and let H1 be the subgroup of G generated by H and a. Let m be the least positive integer for which a"' E H. Then every element g E H1 can be written uniquely in the form g � ajh with 0" j < m and hE H. Define a function 1/>1 on H1 by .f1(g) � wl.f(h). where w is a fixed complex number satisfying w"' �If( a"'). To check that 1/>1 is indeed a character of H1, let g1 � akh1• 0 "k < m, h1 E H. be another element of H1• If j + k < m, then 1/>1( gg1) � wj+k\f( hh 1) �If 1( g)l/>1( g1 ). If j + k;, m, then gg1 � aj+k-m(a"'hh 1), and so If 1 ( ggl) � Wj+k-m\f ( a"'hh1) � wj+k-m.r( a"') If (hh1) � wJ+k.r( hh 1) � lf1 (g) lf1 ( gl) · It is obvious that l/>1(h)�.f(h) for hE H. If H1�G. then we are done. Otherwise. we can continue the process above until, after finitely many steps, we obtain an extension of If to G. 0 5.3. Corollary. For any two distinct elements g1, g2 E G there exists a character X of G with X( g1)"' X( g2 ). Proof It suffices to show that for h � g1g2 1"' lc there exists a character x of G with X( h)"' I. This follows, however, from Example 5.1 and Theorem 5.2 by letting H be the cyclic subgroup of G generated by h. 0 5.4. Theorem. If x is a nontrivial character of the finite abelian group G, then (5 .I) If g E G with g"' lc, then L x(g)�o. (5 .2) Proof Since xis nontrivial, there exists hE G with X(h)"' I. Then x(h) L x(g) � L x(hg) � E x(g). gEG gEG gEG because if g runs through G, so does hg. Thus we have (x(h)-I) E x(g)�o. gEG which already implies (5.1 ). For the second part, we note that the function g defined by g(x) � x< g) for X EGA is a character of the finite abelian group GA. This character is nontrivial since, by Corollary 5.3, there exists x EGA with x(g) "'x(lcl =I. Therefore from (5.1) applied to the group G \ 1. Characters 165 0 5.5. Theorem. The number of characters of a finite abelian group G is equal to I G[. Proof This follows from IG"i= L L x(g)= L L x(g)=iGI, geG xeG" X eG" gEG where we used (5.2) in the first identity and (5.1) in the last identity. 0 The statements of Theorems 5.4 and 5.5 can be combined into the orthogonality relations for characters. Let x and ,Y be characters of G. Then I -{0 iGT L x(g),Y(g) = I gEG (5 .3) The first part follows, of course, by applying (5.1) to the character xf; the second part is trivial. Furthermore, if g and h are elements of G, then I -{0 jGf L x(g)x(h) = 1 xeG" for g * h, forg=h. (5.4) Here, the first part is obtained from (5.2) applied to the element gh-1, whereas the second part follows from Theorem 5.5. Character theory is often used to obtain expressions for the number of solutions of equations in a finite abelian group G. Let f be an arbitrary map from the cartesian product G" = G X · · · X G ( n factors) into G. Then, for fixed h E G, the number N(h) of n-tuples (g1, ••• ,g,) E G" with /(g1, ••• ,g,) =his given by I N(h)=IGT L ··· L L x(/(g,, ... ,g.))x(h) (5.5) g1EG g�EG xeG" on account of (5.4). A character x of G may be nontrivial on G, but still annihilate a whole subgroup H of G, in the sense that x(h) =I for all hE H. The set of all characters of G annihilating a given subgroup H is called the annihilator ofHinG". 5.6. Theorem. Let H be a subgroup of the finite abelian group G. Then theannihilator of·H in G" is a subgroup ofG" of order IGI/IHI. Proof Let A be the annihilator in question. Then it is obvious from the defmition that A is a subgroup of G". Let xEA; thenp.(gH)=x (g), g E G, is a well-defined character of the factor group G/H. Conversely, if p. 166 Exponential Sums is a character of G/H, then x(g) � l'(gH), g E G, defines a character of G annihilating H. Distinct elements of A correspond to distinct characters of G 1 H. Therefore, A is in one-to-one correspondence with the character group (G/H) ', and so the order of A is equal to the order of (G/H) ', which is iG/HI � iGI/IHI according to Theorem 5.5. D In a finite field F • there are two finite abelian groups that are of significance-namely, the additive group and the multiplicative group of the field. Therefore, we will have to make an important distinction between the characters pertaining to these two group structures. In both cases, explicit formulas for the characters can be given. Consider first the additive group of F •. Let p be the characteristic of IF •; then the prime field contained in IF • is F,, which we identify with Z/( p ). Let Tr: f • --+ F, be the absolute trace function from IF • to F, (see Definition 2.22). Then the function x 1 defined by (5.6) is a character of the additive group of IF •• since for c1, c2 E IF • we have Tr(c1 + c2) � Tr(c1)+Tr(c2), and so x1(c1 + c2) � x1(c1)x1(c2). Instead of "character of the additive group of IF •·" we shall henceforth use the term additive character of IF q· The character x1 in (5.6) will be called the canonical additive character of F q· All additive characters of F • can be expressed in terms of x1• 5.7. Theorem. Forb E !'•, the function Xb with Xb(c) � x1(bc) for all c E IF • is an additive character ofF •• and every additive character of IF • is obtained in this way. Proof For c1, c2 E F • we have x.(c1 + c,) � x1(bc1 + bc2) � Xl(bc1)xl(bc,) � x.(c1)x.(c,), and the first part is established. Since Tr maps IF • onto F P by Theorem 2.23(iii), x 1 is a nontrivial character. Therefore, if a, bE IF • with a"' b, then x.(c) �xl(ac) �xl((a-b)c)"'i Xb(c) X1(bc) for suitable c E IF •• and sox. and x. are distinct characters. Hence, if b runs through F •• we get q distinct additive characters x •. On the other hand, F q has exactly q additive characters by Theorem 5.5. and so the list of additive characters of F • is already complete. D By setting b � 0 in Theorem 5.7, we obtain the trivial additive character Xo• for which x0(c) �I for all c E IF q· Let E be a finite extension field of F•, let x1 be the canonical \. Characters 167 additive character ofF •' and let/i, be the canonical additive character of E defined in analogy with (5.6), where Tr is of course replaced by the absolute trace function Tr£ from E to IF,. Then x1 and liJ are connected by the identity (5.7) where Tr E/F is the trace function from E to F •. This follows from the transitivity relation Tr£(/l) � Tr(Tr£/F,(/l)) for all fl E E, which was shown in Theorem 2.26. Characters of the multiplicative group IF; of f • are called multiplica­ tive characters of F •. Since F; is a cyclic group of order q -I by Theorem 2.8, its characters can be easily determined. 5.8. Theorem. Let g be a fixed primitive element of F •. For each j � 0, l, ... ,q -2, the function 1/11 with 1/IJ(g'}�e2•iJk/(q-J) fork�O,l, ... ,q-2 defines a multiplicative choracter of IF •' and every multiplicative character of F • is obtained in this way. Proof · This follows immediately from Example 5.1. 0 No matter what g is, the character lj!0 will always represent the trivial multiplicative character, which satisf1es ljl0(c) �I for all c E F;. 5.9. Corollary. The group of multiplicative characters ofF • is cyclic of order q-I with identity element 1/10• Proof Every character .jl1 in Theorem 5.8 with} relatively prime to q -I is a generator of the group in question. D 5.10. Example. Let q be odd and let � be the real-valued function on F; with�( c)� I if cis the square of an element ofF; and �(c)= -I otherwise. Then � is a multiplicative character of IF •. It can also be obtained from the characters in Theorem 5.8 by setting}� (q -1)/2. The character � annihi­ lates the subgroup ofF; consisting of the squares of elements ofF;, and by Theorem 5.6 it is the only nontrivial character ofF; with this property. This uniquely determined character � is called the quadratic character of F •. If q is an odd prime, then forcE F; we have �(c)= ( � ). the Legendre symbol from elementary number theory. D The orthogonality relations (5.3) and (5.4), when applied to additive or multiplicative characters of IF •' yield several fundamental identities. We consider first the case of additive characters, in which we use the notation from Theorem 5.7. Then, for additive characters x. and x. we have !68 In particular, -{0 L x.(c)x.(c) = q cEF11 for a* b, fora=b. L x.(c)=O fora*O. cEF9 Furthermore, for elements c, dE F • we obtain I: x.(c)x.(d) = { � bEF9 for C* d, for c= d. For multiplicative characters 1f and T of IF • we have In particular, If c, dE IF;, then -{0 L .f(c)T(c) = _1 cEP q • L .f(c)=Ofor.f*lfo· cEF; Exponential Sums (5.8) (5.9) (5.10) (5.11) (5.12) (5.13) where the sum is extended over all multiplicative characters 1f of IF •• 2. GAUSSIAN SUMS Let 1f be a multiplicative and x an additive character of IF •• Then the Gaussian sum G( 1f, x) is defined by G(.f.x)= I: .f(c)x(c). cEF; The absolute value of G( .f, x) can obviously be at most q -1, but is in general much smaller, as the following theorem shows. We recall that .fo denotes the trivial multiplicative character and Xo the trivial additive character of IF •• 5.11. Theorem. Let 1f be a multiplicative and x an additive char­ acter of 'f q· Then the Gaussian sum G( .f, x) satisfies {q -1 for.f = lfo• X= Xo• G(.f,x)= -1 for.f=.f0,X*Xo• 0 for.f * lfo• X= Xo· (5.14) 2. Gaussian Sums !69 If .Y"' .Yo and x ""Xo• then (5.15) Proof The first case in (5.14) is trivial, the third case follows from (5.12), and in the second case we have G(.Yo.xl= L x(c) = L x(c)-x(O)=-I cef; cEFq by (5.9). For .Y"' .Yo and X"' Xo we get IG(f,x)l'= G(.Y.x) G(.Y.x) ---- = L L >r(cJ x(cl >r(c,Jx(c,J cef; c1Ef; In the inner sum we substitute c-1c1 =d. Then, IG(.Y.x)l'= L L .Y(d)x(c(d-I)) ceF; deF; = d�./(d{� •• x(c(d -1))-x(O)) = L .Y(d) L x(c(d -I)) def; cef'i by (5.12). The inner sum has the value q if d =I and the value 0 if d"' I, according to (5.9). Therefore, iG(f, xJI2 = f(l)q = q. and (5.15) is estab­ lished. D The study of the behavior of Gaussian sums under various transfor­ mations of the additive or multiplicative character leads to a number of useful identities. 5.12 Tloeorem. Gaussian sums for the finite field IF• satisfy the following properties: (i) G(f,x •• J=.Y(a) G(f.x.JforaE'!i;,bEF.; (ii) G(f,)()=.y(-I)G(f.x); (iii) G(f.xJ=!Y(-IJG(.Y,x): (iv) G( f, x)G(f, X)= f( -I)q for .Y"" fo, X"" Xo; (v) G( .Y'. x.J = G( .y, x.,.,) forb E f •. where p is the characteristic of F• and u( b)= b'. Proof (i) For cEF• we have x •• (c)=x1(abc)=x.(ac) by the 170 Exponential Sums definition in Theorem 5.7. Therefore, G(.Y.x.,)� E ,Y(c)x.,(c) � E ,Y(c)x,(ac). Now set ac �d. Then G(.Y.x.,)� E ,Y(a-1d)x,(d) d EF; �.y(a-1) E .y(d)x,(d) d EF; � ,Y(a) G( .y, x,). (ii) We have X� Xb for a suitable bE f9 and x(c) �X;(-c)� x_,(c) for c E IF •. Therefore, by using (i) with a� -I and noting that ,Y(-1)� ±I, we get G(.Y.x)�G(.J-.x_,)� H-I) G(.Y.x.)�.y(-I)G(.Y.x). (iii) It follows from (ii) that G(f, x) � f(-I)G(f, x) � .y(-I)G(,Y,x) . (iv) By combining (iii) and (5.15), we obtain G(,Y,x)G(f,x)� .y(-I)G(,Y.x)G(,Y.x) � .y(-I)IG(,Y.x)l2� .y(-l)q. ( v) Since Tr( a) � Tr( aP) for a E !' • by Theorem 2.23(v), we have x 1 (a)� x 1 ( aP) according to (5.6). Thus, for c E IF • we get x,( c)� x1 (be)� >;:1(bPcP) � Xa(b)(cP), and SO G(.Y'.x,)� E .y'(c)x,(c)� E ,Y(c')x.1,)(c'). But c' runs through F; as c runs through IF;, and the desired result follows. 0 5.13. Remark. In connection with the properties above, the value .y( -I) is of interest. We obviously have .y(-I)�± I. Let m be the order of ,Y; that is, m is the least positive integer such that .ym = lj-0• Then m divides q-I since .y•-1 � lj-0• The values of .Yare mth roots of unity; in particular, -I can only appear as a value of .Y if m is even. If g is a primitive element of IF<' then ,Y(g) � r. a primitive mth root of unity. If m is even (and so q odd), then ,Y(-I)� .y(g<<-1112) � j<<-1>12, which is -I precisely if ( q-I )/2 = mj2mod m, or. equivalently, (q -1)/m =I mod2. Therefore, ,Y( -I)� -I if and only if m is even and (q -1)/m is odd. In all other cases we have ,Y(-1)�1. 0 Gaussian sums occur in a variety of contexts, for example in the following. Let .Y be a multiplicative character of IF •; then, using (5.10), we may write 2. Gaussian Sums I -�-E x.(c) E .j�(d)x,(d) q be:F deP ' ' for any c E F;. Therefore, I -1/l(c)�-EG(l/l,x)x(c) forcEF;. q X 171 (5.16) where the sum is extended over all additive characters x of F •. This may be thought of as the Fourier expansion of .jl in terms of the additive characters of F q• with Gaussian sums appearing as Fourier coefficients. Similarly, if x is an additive character of F •• then, using (5.13), we may write I -- x(c) � -1 E x(d)1;1/l(c ) .j�(d) q-def: V- �-1 -1 Ll/l(c) E f(d)x(d) forcEF;. q-I} dE F: Thus we obtain (5 .17) where the sum is extended over all multiplicative .characters 1/1 of F q· This can be interpreted as the Fourier expansion of the restriction of x to IF; in terms of the multiplicative characters of F •• again with Gaussian sums as Fourier coefficients. Therefore, Gaussian sums are instrumental in the transition from the additive to the multiplicative structure (or vice versa) of a finite field. Before we establish further properties of Gaussian sums, we develop a useful general principle. Let ci> be the set of monic polynomials over F •· and let A be a complex-valued function on ci> which is multiplicative in the sense that A(gh) � A(g)A(h) for allg, hE cf>, (5.18) and which satisfies I A( g) I .; I for all g E ci> and A (I) � I. With ci> k denoting the subset of ci> containing the polynomials of degree k, consider the power senes L(z)� E ( E A(g))zk k-0 ge<P" (5.19) Since there are qk polynomial s in <l>k, the coefficient of zk is in absolute value .; q', and so the power series converges absolutely for lz I < q-1 Because of (5.18) and unique factorization in F .[x ], we may write 172 Exponential Sums L(z)� L, A(g)z•'"" � 0(l+A(/)zd"'fl+A(/')z•"u'l+ ... ) I � 0{1 + A(/)z•'•"' +A(!)'z'd'&Ul + ... ). I where !he product is taken over all monic irreducible polynomials fin F.[x]. I! follows !hal L(z) � n (I-A(/)zd<&<llr 1 I Now apply logarithmic differentiation and multiply !he resull by z lo gel zdlogL(z) � L A(/)deg(J)zd'&<ll dz 1 1-A(f)z•<&<ll Expansion of (1-A(/)zd<&i!l)-1 into a geometric series leads 10 z dlog L ( z) � LA (f) deg( !)zd"'<fl dz 1 ·(l+A(J)z••&<fl+A(J)2z'••&lll+ ... ) � L deg( fl{ A( f) z•'•'" +A(/ )2 z2 dog(fl I +A(!)'z'•'•'"+ ... ). and collecting equal powers of z we obtain dlogL(z) _ ;'. L , z dz -i.... sz s-l with L, � L, deg(/)A(/)'1.'"". I (5.20) ( 5 .21) where !he sum is extended over all monic irreducible polynomials fin F .[x] wilh deg(/) dividing s. Now suppose !here exists a positive integer t such !hal L, A (g) � 0 for all k > t. (5.22) g E 411< Then L(z) is a complex polynomial of degree .;; t wilh conslanl term I, so that we can write L(z) �(I-w1z)(I-w2z)· ··(I-w,z) (5.23) 2. Gaussian Sums with complex numbers w1,w2, ... ,w,. It follows that dlogL(z) z dz ' 00 L wmz L wj1z1 m=l J-0 [ ( [ w.:,+1)zi+l�-[ ( t w:,)z', j=O m-1 .��1 m�l and comparison with (5.20) yields Ls =-wj-w2-· · · -w: for all s >I. 173 (5.24) As an application of the principle expressed in (5.24), we consider the following situation. Let x be an additive andY, a multiplicative character of F •. and let E be a finite extension field of F •. Then x and Y, can be "lilted" to E by setting x'(/J) � x(TrE;r,(/3)) lor {3 E E and Y,'(/3) � Y,(NE/F ({3)) lor {3 E E*. From the additivity of the trace and the multi­ plicativi'ty of the norm it follows that x' is an additive and Y,' a multipli­ cative character of E. The following theorem establishes an important relationship between the Gaussian sum G( Y,, x) in F • and the Gaussian sum G( Y,', x') in E. 5.14. Theorem (Davenport-Hasse Theore m). Let x be an additive andY, a multiplicative character of F •• not both of them trivial. Suppose x and Y, are lifted to characters x' andY,', respectively, of the finite extension field E of IF • with [ E: IF .1 � s. Then G ( �/>', x') � (-I)'-1 G ( 1/>, X)' Proof It is convenient to extend the definition of Y, by setting Y, (0) � 0. We use the notation of the discussion leading to (5.24); in particular, <l> denotes again the set of monic polynomials over F •. We define A by setting A(l) �I as required, and lor g E <l> of positive degree, say g(x)�x•- c1x'-1 + · · · +(-I)'c,, we set A( g)� Y,(c,)x(c1). The multi­ plicative property (5.18) is then easily checked. For k >I we split up <t>, according to the values of c1 and c,. Each given pair (c1, c,) occurs q'-2 times in �k• and so 174 Exponential Sums Since one of x and of is nontrivial, it follows from either (5.9) or (5.12) that L A (g) � 0 fork> I. g E cpA Therefore, (5.22) is satisfied with I� I. Furthermore, <1>1 comprises the linear polynomials x-c with c E F •. and so L A(g) � L of(c)x(c) � L of(c)x(c) �G(of,x). Thus, L(z)�l+G(of,x)z from (5.19), hence w1�-G(of,X) by (5.23). Now we consider L,, which, by (5.21) and the multiplicativ ity of A, is given by L, � L deg( f) A (f) '/d<g(fl f � L • deg( f) A (J•Id<s<!l), f where the sum is extended over all monic irreducible polynomials fin IF •[ x] with deg(f) dividing s, and where the asterisk indicates that f(x) � x is excluded. Each suchfhas deg(f) distinct nonzero roots in E, and each root {3 off has as its characteristic polynomial over F • the polynomial !( ),;•••<!>_ ' ,_,+ +( I)' x -x - c1x · · · -cs, say, where c 1 � Tr EfF ( {3) and c, � N E/F ( {3) by (2.2) and (2.3 ). Therefore, • • and so A (!•I•••U>) � H c, )x ( c,) � of { NE;F,( f3)) X (Tr E;F,( 13)) � of'(f3)x'(f3), L, � L*deg(f)A(f 'fd<g(/1)-I;• L of'({3)x'({3). f f fJ E E /I PI-0 If f runs through the range of summation above, then {3 runs exactly through all elements of E*. Consequently, L, � I: of'( f3)x'({3) � G( of', x'), fl E 1::• and an application of (5.24) yields G(of',x') � -( -G(of,x))', which completes the proof. 0 For certain special characters, the associated Gaussian sums can be evaluated explicitly. We thereby obtain formulas that go beyond the trivial 2. Gaussian Sum� 175 cases listed in (5.!4). A celebrated formula of this kind holds for the quadratic character '1 considered in Example 5.!0. 5.15. Theonm. Let F • be a finite field with q � p', where p is an odd prime and s E I'll. Let '1 be the quadratic character ofF• and let X1 be the canonical additive character of IF •. Then { ( -l)'-lql/2 G(.,.xl) � ( )'-1. 1/2 -l t'q ifp = l mod4, ifp=3mod4. Proof Using Theorem 5.l2(iv) and ii� .,, we obtain G(.,, x1)2 � '1(-l)q, and since '1(-l)�l for q=lmod4 and '1(-l)�-l for q= 3mod4 by Remark 5.!3, it follows that ifq=lmod4, if q = 3mod4. (5.25) The difficulty of the proof lies in the determination of the correct signs. We first consider the case s � l. Let V be the set of all complex­ valued functions on If;; it is a (p -!)-dimensional vector space over the complex numbers. A basis for Vis formed by the characteristic functions f1 ./2, ••• ./,_1 of elements of IF;; that is, �(c)= l if c � j and 0 otherwise, where j � l, 2, ... ,p-l. From the orthogonality relation (5.ll) it follows easily that the multiplicative characters .p0, 1f1, .•• ,1f,_2 ofF, described in Theorem 5.8 also form a basis for V. Let I� e2•'1P, and define a linear operator T on V by letting Th for h E V be given by p-1 (Th)(c)� L l"'kh(k) forc�l,2, ... ,p-l. k= I (5 .26) Then Theorem 5.l2(i) implies !hat T.p � G(.p, x1lf for every multiplicative character .p of F p· Since .p � 1/> precisely for the trivial character and the quadratic character, the matrix Tin the basis 1/>0, 1/>1, ••• ,1f,_1 contains two diagonal entries-namely, G( 1/>0, X 1) � -l and G( .,, X 1 )-and a collection of blocks ( o G(,f0.x1l) G( 1/>, x1) corresponding to pairs .p, f of conjugate characters that are nontrivial and nonquadratic. If we compute the determinant of T, then each block contrib­ utes -G(.p, x�)G(f.x1) �-.P( -l)p 176 Exponential Sums by Theorem 5.12(iv). Thus we obtain (p -3)/2 det(T) �-G( �. x1)(-p )1.-3'12 0 .j-1( -1). j=! Now¥-/-1) � lj-j( -1) � ( -1)1, and so (5.27) (p-3)/2 n >�-}( -1) � ( -1)1+2+ ··+(p-3)/2 � ( -1)'•-IXp-3)/8 (5.28) j=l Furthermore, since it follows from (5.25) that ifp = 1 mod4, ifp"' 3mod4, Combining (5.27), (5.28), and (5.29), we get det(T) � ±( -l)(p-IJ/2;<•-1)'14( -l)(r1Xp-3)/8p<.-2);2 hence (5.29) (5.30) Now we compute det(T) utilizing the matrix of T in the basis /1,/2, ... ./ .-1. From (5.26) we find det( T) � det( (ri• )1 �J. • �, _1) � det( (rirN-I> )1 <J. • •, _1) �'1+2+···+\p-lldet(('N-1>) . ) � � l c;;;,kc;;p-1 � det( (!i<<-l> )1 • 1. • •• -I), which is a V andermonde determinant. Therefore, det(T) � 0 W-I"'). \ .,;;.m<n.llliOp-1 With 8 = e"ifp we get det(T)� 0 (82"-82"') l..,.m<n.,;p-1 2. Gaussian Sums Since n 6"+m(6•-m-6-<•-ml) 1 -llii:m<n-'IE:;p-1 n ••+m n (2·. w(n-m)) u lSln . 1 -llii:m<n,.. p-1 l<:!iOm<n -��ii:p-1 P p-I n -I L (n+m)� L L (n+m) 1 -llii:m<n.lO;p -1 n�2 m=l 177 �_3_((p-2)(p-1)(2p-3) (p-2)(p-!)) 2 6 + 2 p(p -I)( p -2) 2 the first product is equal to 6P(p-l)(p-2)/2 � ( _ I)(p -l)(p-l)/2 � ( ( _ I) p -2)'P-1)/l � ( -l)(p -1)/2 Furthermore, and so A n (2. w(n-m)) 0 = stn > , l <:;;;m<n-'IE:;p-1 P ··' det( T) � (-I)'' -IJ/l i(p-1� p-lJ/lA with A> 0. Comparison with (5.30) shows that the plus sign always applies in (5.29), and the theorem is established for s � I. The general case follows from Theorem 5.14 since the canonical additive character ofF, is lifted to the canonical additive character of F• by (5.7) and the quadratic character of IF, is lifted to the quadratic character of �· 0 Because of (5.14) and Theorem 5.12(i), a formula for G(1J,X) can also be established for any additive character X of "F 9. We turn to another special formula for Gaussian sums which applies to a wider range of multiplicative characters but needs a restriction on the underlying field. We shall have to use the notion of order of a multiplicative character as introduced in Remark 5.13. 5.16. Theorem (Stickelberger's Theorem). Let q be a prime power, let .jl be a nontrivial multiplicative character of IF •' of order m dividing q + I, and let x1 be the canonical additive character ofF•'· Then, \18 Exponential Sums G(.J-.x,)� J q \-q q+I if m odd or --even, m q+I if m even and --odd. m Proof We write E � F•' and F� IF •. Let y be a primitive element of E and set g � y•+ 1 Then g•-• �I, so that g E F; furthermore, g is a primitive element of F. Every a E £* can be written in the form a� gjyk with 0 � j < q -I and 0 � k < q +I. Since l}(g) � .j-•+ 1(y) �I, we have q-2 q G(.J-, x,) � E E l}(gjy')x,(gjy') J-Ok-0 q q -2 � E .J-'bl E x,(gjy') k=O J-0 q � E .J-'( 1 J E x,(by'). k-0 bEF* (5.31) If T1 is the canonical additive character ofF, then x1(by') � T1(TrE;F(by')) by (5.7). Therefore, E x,(by')� E T1(bTrE;F(y')) beP beP { -1 = q-I for TrE;F( y') * 0, for TrE;F( y') � 0, because of (5.9). Now TrE;F(Y') = y' + y'•, and so TrE;F( y') � 0 if and only if y•c•-•l � -1. (5.32) (5.33) If q is odd, the last condition is equivalent to k � ( q + 1)/2, and then by (5.32), E x,(by•) � ( -1 bEF" q-J Together with (5.31) we get G(.J-.x,)�-q E k=O k*(q+l)/2 q+I for 0 � k < q + I, k * -2-, a+ I fork�2· 2. Gaussian Sums q L .p'( yJ + q.p<•+ ill'( Y l k=O �q.p<q+i)/l(y) 179 since .P(y)"' I and .p•+ i(y) �I. Now .p<q+ i1!2(y) �I if (q + 1)/m is even and -I if ( q + I)/ m is odd, and thus for q odd we have G(.P.xd�( q -q .f q +' 1 --even. m if q +I odd. m (5 .34) If q is even. then the condition in (5.33) is equivalent to y<lq-i) �I, and the only k with 0" k < q +I satisfying this property is k � 0. Then by (5.32), and (5.31) yields { -I L Xi(by')� bEF"' q-J forl�k�q. fork� 0, q q G(.P.xi) �-L .P'(y)+q-1�-L .P'(y)+q�q. k-1 k-0 Combined with (5.34), this implies the theorem. D We show how to use Gaussian sums to establish a classical result of number theory, namely the law of quadratic reciprocity. We recall from Example 5.10 that if pis an odd prime and q is the quadratic character off,, then for c ¢0 modp the Legendre symbol(�) is defined by(�)� q(c). 5.17. Theorem (Law of Quadratic Reciprocity). For any distinct odd primes p and r we have ( �)(%) � (-l)(p-iX,-i)/4 Proof Let 11 be the quadratic character ofF,, let Xi be the canoni­ cal additive character of IF,, and put G � G(11, Xi). Then it follows from (5.25) that G2 � ( -l)ip-ill'p � jj, and so ( 5.35) Let R be the ring of algebraic integers: that is, R consists of all complex numbers that are roots of monic polynomials with integer coefficients. Since the values of (additive and multiplicative) characters of finite fields are complex roots of unity, and since every complex root of unity is an algebraic integer, the values of Gaussian sums are algebraic integers. In particular. GER. Let (r) be the principal ideal of R generated by r. Then 180 Exponential Sums the residue class ring R/(r) has characteristic r, and thus an application of Theorem 1.46 yields Now G'� ( E �(c)x1(c))' = E �'(c)x](c)mod(r). cEF; cEF; by Theorem 5.12(i), and so G'=�(r)Gmod(r). Together with (5.35) we get pt'-1lf2G = � ( r )Gmod( r ), and multiplication by G leads to pi,_ 1 l/2 p = � ( r) p mod( r) because of G2 �ft. Since the numbers on both sides of the congruence above are, in fact. elements of Z, it follows that pt'-1112p= �( r )pmod r as a congruence in Z. But p and rare relatively prime, hence p<'-1'1' = �( r) mod r. Now ft� ( -I)Ir1ll2p and p'-1 =I mod r, thus multiplication by p1'-1112 yields ( -1)1' -ll('-1114 = p�'-1)/2�( r) mod r. (5.36) We have pl'-ll/2 =±I mod r, and the plus sign applies if and only if p is congruent to a square mod r. Thus, p''-IJ/2 = ( 7) mod r. Since �(r) � (�).we get from (5.36) (-I)'' -1)(,-IJ/4 = ( 7) (�)mod r. But the integers on both sides of this congruence can only be ±I, and since r <> 3, the congruence holds only if the two sides are identical. 0 We consider now character sums involving the quadratic character t1 of � •• q odd, and having a quadratic polynomial in the argument. The following explicit formula will be needed in Chapter 7, Section 2. 5.18. Theorem. Let f(x) � a2x2 + a1x + a0 E F .lx] with q odd and a2 * 0. Put d � af -4a0a2 and let � be the quadratic character ofF,. Then Exercises "' { -'l(a,) L. '1(/(c))� ( -1) ( ) cEF<i q 11 a2 Proof Multiplying the sum by '1(4aJ) �I, we get L 'I(/( c))� 'I( a,) L '1(4alc' +4a1a2c +4a0a2) 181 �'l(a,) L '1{(2a2c+a1)2-d)�'l(a2) L 'l(b2-d). cEff bEfq (5.37) The result for the case d � 0 follows now immediately. For d * 0 we write I: "(b'-d)�-q+ I: (l+"(b'-d)), bEf'l bEF9 and since I +'I( b2 -d) is the number of c E IF q with c2 � b2 -d, we obtain L 'l(b2-d)�-q+S(d), (5.38) bE f'l where S( d) is the number of ordered pairs ( b, c) with b, c E IF, and b2 -c2 =d. To solve this equation, we put b + c = u, b-c = v and note that the ordered pairs ( b, c) and ( u, v) are in one-to-one correspondence since q is odd. Thus S(d) is equal to the pumber of ordered pairs (u, v) with u, v E IF, and uv � d, hence S( d)� q-I. Togethe� with (5.37) and (5.38), this implies the desired formula. D EXERCISES 5.1. Let G be a finite abelian group, H a proper subgroup of G, and g E G, g �H. Prove that there exists a character x of G that annihilates H, but for which x(g) *I. 5.2. Let H be a subgroup of the finite abelian group G. Prove that the annihilator A of H in G A is isomorphic to G 1 H and that GAIA is isomorphic to H. 5.3. Let G be a finite abelian group and mE 1\1. Prove that g E G is an mth power of an element of G if and only if x(g) �I for all characters X of G for which xm is trivial. 5.4. Let G1, ••• ,G, be finite abelian groups. Define multiplication of k-tuples ( g1, ...• g, ), ( h 1, ... ,h,) with g,, h, E G, for I .; i.; k by ( g, .... ,g, )( h,, ... ,h,) � ( g,h,, ... ,g,h, ). Show that with this operation the set of all such k-tuples forms again a finite abelian group, the so-called direct product G1® · · · ®G,. 182 Exponential Sums Then prove that (G1® · · · ®Gk) A is isomorphic to G,' ® · · · ®Gt. 5.5. Use the structure theorem for finite abelian groups, which says in its simplest form that every such group is isomorphic to a direct product of finite cyclic groups, to prove that G A is isomorphic to G whenever G is a finite abelian group. 5.6. For additive characters of f• in the notation of Theorem 5.7, show that x,x. = Xo+b for all a, bE IF •. Thus prove without reference to Exercise 5.5 that the group of additive characters of IF q is isomorphic to the additive group of IF q· 5.7. If x1 is the canonical additive character of the finite field IF• of characteristicp, prove that x,(c'1)=x1(c) for all cEF• and} EN. 5.8. If .pis a multiplicative character of IF •• of order m, prove that the restriction of .p to IF q is a multiplicative character of order mjgcd(m,(q' -1)/(q -I)). 5.9. With the notation of Exercise 5.8, prove that the restriction of .p to F q is the trivial character if and only if m divides (q' -1)/(q -I). 5.10. Let .p be a multiplicative character of F• and let ,P' be the lifted character of the extension field F •.. Prove that ,P'(c) = t'(c) for c E (f:. 5.11. Prove that a multiplicative character T of F •. is equal to a character ,P' lifted from F q if and only if ,•-' is trivial. 5.12. If q =I mod m and .p varies over all multiplicative characters of IF• of order dividing m, prove that the lifted character .P' of F •. varies over all multiplicative characters of IF q' of order dividing m. 5 .13. Prove that an additive character x of the finite extension field E of IF q is equal to a character lifted from F q if and only if X= lib with bE IF•, where p.1 is the canonical additive character of E. 5.14. Prove forcEF; that { q-1 = :(q-1) if cis a primitive element ofF q, otherwise, where in the outer sum d runs through all positive divisors of q-I and in the inner sum .P'"' runs through the <j>(d) multiplicative characters ofF q of order d. Here p. denotes the Moebius function (see Definition 3.22) and <P Euler's function (see Theorem 1.15 (iv)). 5.15. Show that �(2) = (-J)l•'-lll', where� is the quadratic character of e: •. q odd. 5.16. For rEN prove G(.f''.x.l=G(.f.x,1.,). where p(b)=b'' for bE F q and p is the characteristic of F q· Exercises 183 5.17. Prove Lx G( 1/1, xl � 0 for all multiplicative characters 1/1 of F •. where the sum is extended over all additive characters x of F q· 5.18. Prove I:,G(,P.x)�(q-I)x(l) for all additive characters x of IF •. where the sum is extended over all multiplicative characters 1/1 of f q· 5.19. For the quadratic character � of F q• q � p', p an odd prime, s E I'll, and an additive character x •. bE F •. in the notation of Theorem 5.7. prove that G( �. x.) � � (b)(_ I)'• + ll/2 ;•<P'+2p+ Sl/4ql/'- 5.20. If q is odd and � is the quadratic character of IF q• prove that G(�. x.)G(�. x.l � �(-ab)q for a, bE IF;. 5.21. Use the law of quadratic reciprocity to evaluate the Legendre sym­ bols ( m and ( .!r ). 5.22. Determine all primes p such that ( �3) �I. 5.23. Determine all odd prime powers q such that the quadratic character � of IF q satisfies � (3) � I. 5.24. Prove that the polynomial x2 +ax+ bE Fq[x], q odd. is irreducible in F•[x] if and only if �(a2 -4b) �-I. 5.25. Determine whether the polynomial x2 + 12x +41 is irreducible in 1Fm[x]. 5.26. Let p and r be distinct odd primes, lets E I'll be such that r' =I mod p, and let!: be an element of order pin F,�. Fork E Z define p-1 ck � E ( � )rk' E IF,,. l'=l p Prove the following properties: (i) Gk � (% )c,: (ii) c; � ( -l)lP-Ill'p. where the last expression is viewed as an element of IF,. 5.27. Use the results of Exercise 5.26 to prove the law of quadratic reciprocity. 5.28. Prove that L ,P(c+a)f(c+b)�-1 cEF'l for a, bE IF • with a"' b, where 1/1 is a nontrivial multiplicative char­ acter of IF q· 5.29. Let lji be a nontrivial multiplicative character of IF • and let S be a subset of F q with h elements. Prove that L I L 1/l(c+alj' �h(q-h). cEfq aES 5.30. Let X1, X2, X3 be nontrivial multiplicative characters of IF• and let 184 a1, a2 E IF q with a1 =1= a2. Prove that L I L ;>..,(c+a1);\.2(c+a2);\.3(c+b)l2 bEF, cEF9 { q'-3q � q2-2q-l if ;1.1;1.2 nontrivial, if;\.1;\.2 trivial. Exponential Sums 5.31. Let 1/> be a multiplicative character of F • of order m > 1. For a E IF • prove L IJ>(ac") � { (q -1)1/>(a) cEF Q ' if m divides n, otherwise. 5.32. Prove that L"' �(f(c)) � 0 if q = 3 mod 4, � is the quadratic character off,, and /Ef.[x] is an odd polynomial-that is, a polynomial with f(-x) � -f(x). Chapter 6 Linear Recurring Sequences Sequences in finite fields whose terms depend in a simple manner on their predecessors are of importance for a variety of applications. Such sequences are easy to generate by recursive proced�res, which is certainly an advanta­ geous feature from the computational viewpoint, and they also tend to have useful structural properties. Of particular interest is the case where the terms depend linearly on a fixed number of predecessors, resulting in a so-called linear recurring sequence. These sequences are employed, for instance, in coding theory (see Chapter 8, Section 2), in cryptography (see Chapter 9, Section 2}, and in several branches of electrical engineering. In these applications, the underlying field is often taken to be � 2, but the theory can be developed quite generally for any finite field. In Section I we show how to implement the generation of linear recurring sequences on special switching circuits called feedback shift reg­ isters. We discuss also some basic periodicity properties of such sequences. Section 2 introduces the concept of an impulse response sequence, which is of both practical and theoretical interest. Further relations to periodicity properties are found in this way, and also througb the use of the so-called characteristic polynomial of a linear recurring sequence. Another applica­ tion of the characteristic polynomial yields explicit formulas for the terms of a linear recurring sequence. Maximal period sequences are also defined in this section. These sequences will appear in various applications in later chapters. The theory of linear recurring sequences can be approached via linear algebra. ideal theory, or formal power series. An approach based on 186 Linear Recurring Sequences the latter is presented in Section 3. This leads to a computation-oriented way of introducing the minimal polynomial of a linear recurring sequence in the next section. The minimal polynomial is of crucial importance for the linear recurring sequence, since the order of the minimal polynomial gives the least period of the sequence. In Section 5 we study the collection of all sequences satisfying a given linear recurrence relation. This information is useful in the discussion of operations with linear recurring sequences, such as termwise addition and multiplication for sequences in general finite fields and binary complemen­ tation for sequences in F2. We consider also the problem of determining the various least periods of the sequences generated by a fixed linear recurrence relation. Section 6 presents some determinantal criteria character izing linear recurring sequences as well as the Berlekamp-Massey algorithm for the calculation of minimal polynomials. Section 7 is devoted to distribution properties of linear recurring sequences. Exponential sums with linear recurring sequences are the main tools for studying such properties. 1. FEEDBACK SHIFT REGISTERS, PERIODICITY PROPERTIES Let k be a positive integer, and let a, a0 ....... ak _ 1 be given elements of a finite field F •. A sequence s0, s1, ••• of elements of IF, satisfying the relation sn+k=ak-lsn+k-l+ak_2sn+k-2+ ··· +a0sn+a forn=O,l, ... (6.1) is called a (kth-order) linear recurring sequence in F q· The terms s0, s1 •••• ,sk _1, which determine the rest of the sequence uniquely. are referred to as the initial values. A relation of the form (6.1) is called a (kth-order) linear recurrence relation. In the older literature one may also find the term .. difference equation." We speak of a homogeneous linear recurrence relation if a= 0; otherwise the linear recurrence relation is inhomogeneous. The sequence s0• s1 •.•. itself is called a homogeneous, or inhomogeneous, linear recurring sequence in IF q• respectively. The generation of linear recurring sequences can be implemented on a feedback shift register. This is a special kind of electronic switching circuit handling information in the form of elements of IF •• which are represented suitably. Four types of devices are used. The first is an adder. which has two inputs and one output, the output being the sum in IF, of the two inputs. The second is a constant multiplier, which has one input and yields as the output the product of the input with a constant element of IF •. The third is a constant adder, which is analogous to a constant multiplier, but adds a constant element of !', to the input. The fourth type of device is a delay 1. Feedback Shift Registers, Periodicity Properties 187 element ("flip-flop"), which has one input and one output and is regulated by an external synchronous clock so that its input at a particular time appears as its output one unit of time later. We shall not be concerned here with the physical realization of these devices. The representation of the components in circuit diagrams is shown in Figure 6.1. A feedback shift register is built by interconnecting a finite number of adders, constant multipliers, constant adders, and delay elements along a closed loop in such a way that two outputs are never connected together. Actually, for the purpose of generating linear recurring sequences, it suffices to connect the components in a rather special manner. A. feedback shift register that generates a linear recurring sequence satisfying (6.1) is shown in Figure 6.2. At the outset, each delay element D;, j = 0, I, ... ,k -I, contains the initial value sF If we think of the arithmetic operations and the transfer along the wires to be performed instantaneously, then after one time unit each D; will contains;+ 1• Continuing in this manner, we see that the output of the feedback shift register is the string of element s0, s1, s2, ... , received in intervals of one time unit. In most of the applications the desired linear recurring sequence is homogeneous, in which case the constant adder is not needed. 6.1. Example. In order to generate a linear recurring sequence in ·fs satisfying the homogeneous linear recurrence relation (a) Adder FIGURE 6.1 s,+6=sn+s+2s,+4+s,+1+3s, (orn=O,I, ... , (b) Constant multiplier (c) Constant adder (d) Delay element for multiplying by o for adding o The building blocks of feedback shift registers. (a) Adder. (b) Constant multiplier for multiplying by a. (c) Corn;tant adder for adding a. (d) Delay element. FIGURE 6.2 The general form of a feedback sbift register. 188 Linear Recurring Sequences one may use the feedback shift register shown in Figure 6.3. Since a2 � a3 � 0, no connections are necessary at these points. 0 6.2. Example. Consider the homogeneous linear recurrence relation A feedback shift register corresponding to this linear recurrence relation is shown in Figure 6.4. Since multiplication by a constant in f2 either preserves or annihilates elements, the effect of a constant multiplier can be simulated by a wire connection or a disconnection. Therefore, a feedback shift register for the generation of binary homogeneous linear recurring sequences requires only delay elements, adders, and wire connections. D Let s0, s1, ••• be a kth-order linear recurring sequence in F• satisfying (6.1). As we have noted, this sequence can be generated by the feedback shift register in Figure 6.2. If n is a nonnegative integer, then after n time units the delay element�.}� 0, I, ... ,k-I, will contain s•+j· It is therefore natural to call the row vector sn = (sn, sn+ 1, •.• ,sn+k _1) the nth state vector of the linear recurring sequence (or of the feedback shift register). The state vector s0 = (s0, s1, ••• ,sir. _1) is also referred to as the initial state vector. It is a characteristic feature of linear recurring sequences in finite fields that, after a possibly irregular behavior in the beginning, such sequences are eventually of a periodic nature (or ultimately periodic in the sense of Definition 6.3 below). Before studying this property in detail, we introduce some terminology and mention a few general facts about ulti· mately periodic sequences. FIGURE 6.3 The feedback shift register for Example 6.1. Output FIGURE 6.4 The feedback shift register for Example 6.2. \. Feedback Shift Registers, Periodicity Properties 189 6.3. Definition. LetS be an arbitrary nonempty set, and let s0, s1, ••• be a sequence of elements of S. If there exist integers r > 0 and n 0 ;;. 0 such that s,.+, = s,. for all n � n0, then the sequence is called ultimately periodic and r is called a period of the sequence. The smallest number among all the possible periods of an ultimately periodic sequence is called the least period of the sequence. 6.4. Lemma. Every period of an ultimately periodic sequence is divisible by the least period. Proof Let r be an arbitrary period of the ultimately periodic sequence s0, s1 .... and let r1 be its least period, so that we haves,.+,= s,. for all n � n0 and s,.+,1 = s,. for all n � n1 with suitable nonnegative integers n0 and n I" If r were not divisible by ri' we could use the division algorithm for integers to writer� mr1 + 1 with integers m;;. I and 0 < 1 < r1• Then, for all n;;. max(n0, n1) we get s,.=s,.+,=s,.+mr1+r=s,.+(m-1)r1+t= ·· · =s,.+t• and so t is a period of the sequence, which contradicts the definition of the least period. D 6.5. Definition. An ultimately periodic sequence s0, s1, ... with least period r is called periodic if s.+, � s. holds for all n � 0, I,. .. . The following condition, which is sometimes found in the literature, is equivalent to the definition of a periodic sequence. 6.6. Lemma. The sequence s0, Sp ..• is periodic if and only if there exists an integer r > 0 such that s,.+, = s,. for all n = 0,1, .... Proof The necessity of the condition is obvious. Conversely, if the condition is satisfied, then the sequence is ultimately periodic and has a least period r1. Therefore, with a suitable n0 we have s,.+,1=s,. for all n � n0. Now let n be an arbitrary nonnegative integer, and choose an integer m � n0 with m = nmod r. Then s,.+,, = sm+rt = sm = s,., which shows that the sequence is periodic in the sense of Definition 6.5. D If s0, s1, ... is ultimately periodic with least period r, then the least nonnegative integer n0 such that s,.+, = s,. for all n � n0 is called the preperiod. The sequence is periodic precisely if the preperiod is 0. We return now to linear recurring sequences in finite fields and establish the basic results concerning the periodicity behavior of such sequences. 6.7. Theanm. Let Fq be any finite field and k any positive integer. Then every kth-order linear recurring sequence in IF q is ultimately periodic with least period r satisfying r <; q•, and r.; q•-I if the sequence is homogeneous. 190 Linear Recurring Sequences Proof We note that there are exactly q' distinct k-tuples of ele­ ments of IF q· Therefore, by considering the state vectors sm, 0 � m � qk, of a given k th-order linear recurring sequence in F q• it follows that s1 = si for some i and j with 0 � i < j � q". Using the linear recurrence relation and induction, we arrive at s,+J-i = s, for all n � i, which shows that the linear recurring sequence itself is ultimately periodic with least period r � j-i � qk In case the linear recurring sequence is homogeneous and no state vector is the zero vector, one can go through the same argument, but with qk replaced by q' -I, to obtain r .;; q' -I. If, however, one of the state vectors of a homogeneous linear recurring sequence is the zero vector, then all subsequent state vectors are zero vectors, and so the sequence has least period r �I .;; q' -I. D 6.8, Example. The first-order linear recurring sequence s0, sl'··· in IF,, p prime, with s,+ 1 � s, +I for n � 0, I, ... and arbitrary s0 E F, shows that the upper bound for r in Theorem 6.7 may be attained. If IF• is any finite field and g is a primitive element of IF • (see Definition 2.9), then the first-order homogeneous linear recurring sequence s0,s1, •.• in Fq withs,+1=gs, for n � 0, I, ... and s0 "'0 has least period r � q-I. Therefore, the upper bound for r in the homogeneous case may also be attained. Later on, we shall show that in any F • and for any k ;;, I there exist k th-orderhomogeneous linear recurring sequences with least period r � q'-I (see Theorem 6.33). D 6.9. Example. For a first-order homogeneous linear recurring sequence in IF •' it is easily seen that the least period divides q-I. However, if k ;;, 2, then the least period of a k th-order homogeneous linear recurring sequence need not divide qk-1. Consider, for instance, the sequence s0, s1, ... in IF5 with s0=0. s1=1, and s,+2=s,+1+s,1 for n=O,l, ... , which has least period 20, as is shown by inspection. D 6.10. Example. A linear recurring sequence in a finite field is ultimately periodic, but it need not be periodic, as is illustrated by a second-order linear recurring sequence So, sl,. .. in F q with So* sl and s,+2 = s,+ I for n �0,!,.... D An important sufficient condition for the periodicity of a linear recurring sequence is provided by the following result. 6.11. Theorem. If s0, s1, ... is a linear recurring sequence in a finite field satisfying the linear recurrence relation (6.1), and if the coefficient a0 in (6.1) is nonzero, then the sequence s0, s1, ... is periodic. Proof According to Theorem 6.7, the given linear recurring se­ quence is ultimately periodic. If r is its least period and n0 its preperiod, then s•+• � s, for all ;, ;;, n0. Suppose we had n0;;, I. From (6.1) with Feedback Shift Regi::.ters, Periodicity Properties 191 n � n0 + r-l and the fact that a0 * 0, we obtain Using (6.1) with n � n0 -1, we find the same expression for s.,-1, and so s,0 _1 +r = s,0 _ 1• This is a contradiction to the definition of the preperiod. D Let s0, s1, ... be a kth-<>rder homogeneous linear recurring sequence in F q satisfying the linear recurrence relation s,+k = ak _1s,+k _1 + ak _ 2s11+k _ 2 + · · · + a0s, for n = 0, 1, ... , (6.2) where a1 E IF • for 0.; j.; k-l. With this linear recurring sequence we associate the k X k matrix A over F • defined by 0 0 0 0 0 0 0 0 0 0 0 0 0 (6.3) If k � l, then A is understood to be the 1 X 1 matdx (a0). We note that the matrix A depends only on the linear recurrence relation satisfied by the gtven sequence. 6.12. Lemma. If s0, s1, .•. is a homogeneous linear recurring se­ quence in F q satisfying (6.2) and A is the matrix in (6.3) associated with it, then for the state vectors of the sequence we have s. � s0A" for n � 0, l, ... . (6.4) Proof Since s, = (s,, s,+ 1, ••• ,s,+k _d. one checks easily that s.+ 1 � s.A for all n;. 0, so that (6.4) follows by induction. D We note that the set of all nonsingular k X k matrices over F q forms a finite group under matrix multiplication, called the general linear group GL(k,F.). 6.13. Theorem. If s0, s1, .•. is a kth-order homogeneous linear recur­ ring sequence in IF q satisfying (6.2) with a0 * 0, then the least period of the sequence divides the order of the associated matrix A from (6.3) in the general linear group GL(k,IF.). 192 Linear Recurring Sequences Proof We have det A� (-I)'-1a0 "'0, so that A is indeed an element of GL(k,Fq). If m is the order of A in GL(k,IFq), then from Lemma 6.12 we obtain sn+m=s0An+m=s0A11=S11 for all n�O. and somis a period of the linear recurring sequence. The rest follows from Lemma 6.4. D We remark that the above argument, together with Lemma 6.6, yields an alternative proof for Theorem 6.11 in the homogeneous case. From Theorem 6.13 it follows, in particular, that the least period of the sequence s0,s1, ••• divides the order of GL(k,F.), which is known to be q<•'-kl!Z (q -1Xq1-l) · · · (q' -I). Let now s0, s1, ••• be a kth-order inhomogeneous linear recurring sequence in IF q satisfying (6.1 ). By using (6.1) with n replaced by n + I and subtracting from the resulting identity the original form of (6.1) we obtain sn+k+1=bksn+k+b.t.:_1sn+k-l + ·· · +b0s11 forn=O,l, ... , (6.5) where b0�-a0, b1�ar1-a1 for j�1,2, ... ,k-1, and b,�a,_,+l. Therefore, the sequence s0,s,, ... can be interpreted as a (k + l)st-order homogeneous linear recurring sequence in F q· Consequently, results on homogeneous linear recurring sequences yield information for the inhomo­ geneous case as well. An alternative approach to the inhomogeneous case proceeds as follows. Let s0, s 1,... be a k th-order inhomogeneous linear recurring se­ quence in IF• satisfying (6.1), and consider the (k + I)X(k +I) matrix C over IF q defined by 0 0 0 a 0 0 0 0 ao 0 0 0 a, c� 0 0 0 a, 0 0 0 ak-1 If k �I, take We introduce modified state vectors by setting s�=(l,s11,S11+t•···•.fn+k-l) forn=O,l, .... Then it is easily seen that s�+ 1 = s�C for all n � 0, and so s� = sQC11 for all n:;, 0 by induction. If a0 "'0 in (6.1), then det C � ( -l)'-1a0 "'0, so that the matrix Cis an element of GL(k +I. F.). One shows then as in the proof of Theorem 6.13 that the least period of s0, s1, ... divides the order of C in GL(k + I.F.). 2. Impulse Response Sequences, Characteristic Polynomial 2. IMPULSE RESPONSE SEQUENCES, CHARACfERISTIC POLYNOMIAL 193 Among all the homogeneous linear recurring sequences in F q satisfying a given kth-order linear recurrence relation such as (6.2), we can single out one that yields the maximal value for the least period in this class of sequences. This is the impulse response sequence d0, d1,. .. determined uniquely by its initial values d0 � • · • � dk-2 � 0, dk-l �I (d0 �I if k �I) and the linear recurrence relation 6.14. Example. Consider the linear recurrence relation sn+s=sn+l+s", n=O,l, ... ,in!F2. The impulse response sequence d0, d1, ••• corresponding to it is given by the string of binary digits OOOOIOOOIIOOIOIOIIIIIOOOOI··· of least period 21. A feedback shift register generating this sequence is shown in Figure 6.5. We can think of this sequence as being obtained by starting with the state in which each delay element is "empty" (i.e., contains 0) and then sending the "impulse" I into the rightmost delay element. This explains the term "impulse response sequence." 0 6.15. Lemma. Let d0, d�o··· be the impulse response sequence in F• satisfying (6.6), and let A be the matrix in (6.3). Then two state vectors dm and d, are identical if and only if Am� A". Proof The sufficiency follows from Lemma 6.12. Conversely, sup­ pose that dm � d,. From the linear recurrence relation (6.6) we obtain then dm+t � d,+, for alii;. 0. By Lemma 6.12 we get d,Am � d,A" for alii;. 0. But since the vectors d0, d1, .•• , dk _1 obviously form a basis for the k-dimen­ sional vector space IF; over F q• we conclude that Am = A". 0 6.16. Theore,_ The least period of a homogeneous linear recurring sequence in F q divides the least period of the corresponding impulse response sequence. FIGURE 6.5 The feedback shift register for Example 6.14. 194 Linear Recurring Sequences Proof Let s0, s1, .•• be a homogeneous linear recurring sequence in IF • satisfying (6.2), let d0, d1, ••• be the corresponding impulse response sequence, and let A be the matrix in (6.3). If r is the least period of d0, d1, ••• and n0 the preperiod, then d,+, � d, for all n;. n0. It follows from Lemma 6.15 that A"+'= A" for all n;;;;.n0, and so s,+,=s, for all n;. n0 by Lemma 6.12. Therefore, r is a period of s0, s1, ••• , and an application of Lemma 6.4 completes the proof. 0 6.17. Theorem. If d0, d1, ••• is a kth-order impulse response se­ quence in F • satisfying (6.6) with a0 * 0 and A is the matrix in (6.3) associated with it, then the least period of the sequence is equal to the order of A in the genera/linear group GL(k,IF.). Proof If r is the least period of d0, d1, ••• , then r divides the order of A according to the Theorem 6.13. On the other hand, we have d, � d 0 by Theorem 6. 11, and so Lemma 6. 15 yields A'� A0, which implies already the desired result. 0 6.18. Example. For the linear recurrence relation s,+5 = s,.+ 1 + s,, n � 0,1, ... , in F2 considered in Example 6.14 we have seen that the least period of the corresponding impulse response sequence is equal to 21, which is the same as the order of the matrix 0 0 1 0 A� 0 1 0 0 0 0 0 0 0 0 0 0 1 0 0 I I 0 0 0 in GL(S,IF2). If the initial state vector of a linear recurring sequence in IF2 satisfying the given linear recurrence relation is equal to one of the 21 different state vectors appearing in the impulse response sequence, then the least period is again 21 (since such a sequence is just a shifted impulse response sequence). If we choose the initial state vector (1,1,1,0,1), we get the string of binary digits I I 1 0 1 0 0 I I I 0 I··· of least period 7, and the same least period results from any one of the 7 different state vectors of this sequence in the role of the initial state vector. If the initial state vector is ( 1, I, 0, I, I), then we obtain the string of binary digits I 1 0 1 I 0 I 1 · · · of least period 3, and the same least period results if any one of the 3 different state vectors of this sequence is taken as the initial state vector. The initial state vector (0,0,0,0,0) produces a sequence of least period I. We have now exhausted all 32 possibilities for initial state vectors. 0 6.19. Theorem. Let s0, s1, ••• be a kth-order homogeneous linear recurring sequence in F q with preperiod n0. If there exist k state vectors S'"1,S'"2, ..• ,s'"" with m1 � n0 (1 � j � k) that are linearly independent over IF q• 2. Impulse RespOnse Sequences, Characteristic Polynomial 195 then both s0, s1, ••• and its corresponding impulse response sequence are periodic and they have the same least period. Proof Let r be the least period of s0, s1, ••• • For l.; j.; k we have •m·A'�sm+,�sm· by using Lemma 6.12, and so A' is the k Xk identity ' ' ' matrix over IF q· Thus we get sr = s0Ar = s0, which shows that s0, s1, ••• is periodic. Similarly, if d. denotes the nth state vector of the impulse response sequence, then d, � d0A' � d0, and an application of Theorem 6.16 com­ pletes the proof. D 6.20. Example. The condition m,;. n0 in Theorem 6.19 is needed since there are k th-order homogeneous linear recurring sequences that are not periodic but contain k linearly independent state vectors. Let d0, d1, ••• be the second-order impulse response sequence in F q with dn+l = dn+ 1 for n � 0, 1, .... The terms of this sequence are 0, l, l, l, .... Clearly, the state vectors d0 and d1 are linearly independent over f q' but the sequence is not periodic (note that n0 � l in this case). The converse of Theorem 6.19 is not true. Consider the third-order linear recurring sequence s0, s 1, .•. in f 2 with s,.+3�s. for n�O,l, ... and s0�(l,l,O). Then both s0,s1, ••• and its corresponding impulse response sequence are periodic with least period 3, but any three state vectors of s0, s1, ..• are linearly dependent over F2. D Let s0, s1, ••• be a kth-order homogeneous linear recurring sequence in F q satisfying the linear recurrence relation sn+k=ak-lsn+k-l+ak-zSn+k-z+ ··· +a0�n forn=O,l, ... , (6.7) where a1 E F • for 0 .; j .; k -l. The polynomial f(x)�x'-a x'-1-a x'-2-···-a EF [x) k-1 k-2 0 q is called the characteristic polynomial of the linear recurring sequence. It depends, of course, only on the linear recurrence relation (6.7). If A is the matrix in (6.3), then it is easily seen that f(x) is identical with the characteristic polynomial of A in the sense of linear algebra�that is, f(x) � det(xi-A) with I being the k X k identity matrix over F •. On the other hand, the matrix A may be thought of as the companion matrix of the monic polynomial f( x ). As a first application of the characteristic polynomial, we show how the terms of a linear recurring sequence may be represented explicitly in an important special case. 6.21. Theore"'-Let s0, s1, ... be a kth-order homogeneous linear recurring sequence in IF • with characteristic polynomial f(x ). If the roots a1, ••• ,a, of f(x) are all distinct, then k s.� L f3,aj forn�O,l, ... , j-1 (6.8) 196 Linear Recurring Sequences where {31, ••• ,{3, are elements that are uniquely determined by the initial values of the sequence and belong to the splitting field of f(x) over IF •. Proof The constants {31, ••• ,{3, can be determined from the system of linear equations k L cx.jf31 � s., n � 0, l, ... , k-I. j -I Since the determinant of this system is a Vandermonde determinant, which is nonzero by the condition on a1, ••• ,a,, the elements /31, ••• , {3, are uniquely determined and belong to the splitting field F.(a1, ••• ,a,) off(x) over IF•, as is seen from Cramer's rule. To prove the identity (6.8) for all n ;;. 0, it suffices now to check whether the elements on the right-hand side of (6.8), with these specific values for {31, ••• ,{3,, satisfy the linear recurrence relation (6. 7). But k k k � {Ja"+'-a � f3a•+k-l_a � f3a•+k-l_ l.....jj k-11.....)} k-21.....}} j-1 j-1 j-1 k L f3J(a1)aj�O j=l for all n ;;. 0, and the proof is complete. k ... -ao L f3;aj J-1 0 6.22. Example. Consider the linear recurring sequence s0,s1, ••• in F2 with s0 = s1 = 1 and s,1+2 = s,+ 1 + s, for n = 0, 1, .... The characteristic polynomial isf(x) �x2-x-lEF2[x]. If IF4�1F2(a), then the roots of f(x) are a1 �a and a2 � l +a. Using the given initial values, we obtain {31 + {32 � l and {31a + {32(1 +a)� l, hence {31 �a and {32 � l +a. By Theo­ rem 6.21 it follows that s. � a•+ 1 + (l + a)"+ 1 for all n ;;. 0. Since {33 � l for every nonzero {3 E F 4, we deduce that s,+ 3 = s, for all n � 0, which is in accordance with the fact that the least period of the sequence is 3. 0 6.23. Remark. A formula similar to (6.8) is valid if the multiplicity of each root off( x) is at most the charact eristic p of IF •. In detail, let a1, •••• am be the distinct roots of f(x), and suppose that each a,, i � l,2, ... ,m, has multiplicity e,.;; p and that e, � l if a,� 0. Then we have m s. � L P, ( n) a7 for n � 0, l, ... , ;-1 where each P,, i � l,2, ... ,m, is a polynomial of degree less than e, whose coefficients are uniquely determined by the initial values of the sequence and belong to the splitting field of f(x) over F •. The integer n is of course identified in the usual way with an element ofF •. The reader familiar with differential equations will observe a certain analogy with the general solu- 2. Impulse RespOnse Sequences. Characteristic Polynomial 197 tion of a homogeneous linear differential equation with constant coeffi­ cients. 0 In case the characteristic polynomial is irreducible, the elements of the linear recurring sequence can be represented in terms of a suitable trace function (see Definition 2.22 and Theorem 2.23 for the definition and basic properties of trace functions). 6.24. Theorem. Let s0, s1,... be a kth-order homogeneous linear recurring sequence in K = IF q whose characteristic polynomial f( x) is irreduc­ ible over K. Let a be a root off( x) in the extension field F � f •'" Then there exists a uniquely determined 8 E F such that s.�TrF;K(8a") forn�O.l, .... Proof Since {l,a, ... ,a•-1) constitutes a basis of Fover K, we can define a uniquely determined linear mapping L from F into K by setting L(a")�s. for n�O,l, ... ,k-1. By Theorem 2.24 there exists a uniquely determined 8 E F such that L(y) � TrF;K(8y) for all "Y E F. In particular, we have s.�TrF;K(8a") forn=O,l, ... ,k-1. It remains to. show that the elements TrF;K(8a"), n =0, 1, ... , form a homogeneous linear recurring sequence with characteristic polynomial f(x). But if f(x)=x•-a._,x•-1-•·· -a0EK[x], then using properties of the trace function we get TrF1K(8a•+•)-a._1TrF;K(8a•+k-l)-· ·· -a0TrF;K(8a") -Tr (8an+k_a 8a"+k-1-···-a8an) -F/K k -I 0 � TrF;K(8a"f(a)) � 0 for all n ;;, 0. 0 Further relations between linear recurring sequences and their char­ acteristic polynomials can be found on the basis of the following polynomial identity. 6.25. Theorem. Let s0, s1, ... be a kth-order homogeneous linear recurring sequence in F q that satisfies the linear recurrence relation (6.7) and is periodic with period r. Let f(x) be the characteristic polynomial of the sequence. Then the identity f(x)s(x)� (1-x')h(x) (6.9) holds with 198 Linear Recurring Sequences and k-1 k-1-j h(x)= l: l: a1+J+Is,x1EFq[x]. J-O ;�o where we set ak = -1. (6.10) Proof We compare the coefficients on both sides of (6.9). For 0 .;; 1 .;; k + r-I, let c, (resp. d,) be the coefficient of x' on the left-hand side (resp. right-hand side) of (6.9). Since f(x) =-E7_0a1x1, we have c,=- l: a,.s,_1_1 forO::e;;t ::e;;k+r-1. O<.i<:k.O<j<.r-1 i+ J-t (6.11) We note also that the linear recurrence relation (6.7) may be written in the form k l: a;sn+i = 0 for all n � 0. ;-o (6.12) We distinguish now four cases. If k <;; I<;; r -I, then by (6.11) and (6.12), k c,=-l: a,.s,_1_1+;=0=d,. ;-o Ift<;;r-1 and t<k, then by (6.11), (6.12), and the periodicity of the given sequence, k c,=-l: a;sr-1-r+i= l: a;sr-1-t+i ;-o ;-r+l k k-1- r l: a,.s1_1_1= l: a1+1+1s,.=d,. i-r+l ;-o If 1;. rand 1;. k, then by (6.11), c=­' i-t-r+! k-1-t+r a;5r-l-t+i=-l: ai+t-r+ls;=d,. ;-o If r <;;I< k, then by (6.11) and the periodicity of the given sequence, c=­' ' l: i-t-r+l k-1-t+r l: i-, ,_J alsr-1-r+i =-l: ai+r-r+ lsi ;-o k-!-t+r l: ;-o k-1-r k-!-t+r l: ai+t+lsi+,-L ai+r-r+lsl i-0 ;-o k-1-r k-1-t+r l: ai+r+ls;-l: ai+t-r+ts;=d,. i-0 i-0 D 2. Impulse Response Sequences, Characteristic Polyrlomial 199 In Lemma 3.1 we have seen that for any polynomial f(x)EIFq[x) with /(0)"' 0 there exists a positive integer e such that f(x) divides x'-l. This gave rise to the definition of the order off (see Definition 3.2). We give the following interpretation of ord( fl. 6.26. Lemma. Let I( ) k k-I k-2 IF [ 1 x =x -ak_1x -ak_2x -··· -a0E q x with k ;.I and a0"' 0. Then ord(f(x)) is equal to the order of the matrix A from (6.3) in the genera/linear group GL(k,IFq). Proof Since A is the companion matrix of f(x ), the polynomial f(x) is, in tum, the minimal polynomial of A. Consequently, if I is the k X k identity matrix over F q• then we have A�= I for some positive integer e if and only if f(x) divides x' -I. The result follows now from the definitions of the order of f(x) and the order of A. D 6.27. Theorem. Let s0,s1, ..• be a homogeneous linear recurring sequence in Fq with characteristic polynomial f(x)E Fq[x]. Then the least period of the sequence divides ord(f(x)), and the least period of the corre­ sponding impulse response sequence is equal to ord(f(x )). If f(O)"' 0, then both sequences are periodic. Proof If f(O)"' 0, then in ti1e light of Lemma 6.26 the result is essentially a restatement of Theorems 6.13 and 6.17. In this case, the periodicity property follows from Theorem 6.11. If f(O) � 0, then we write f(x) � x"g(x) as in Definition 3.2 and set t, � sn+h for n � 0, l, .... Then t0,t1, ••• is a homogeneous linear recurring sequence with characteristic polynomial g(x), provided that deg(g(x)) > 0. Its least period is the same as that of the sequence s0, s 1, .... Therefore, by what we have already shown, the least period of s0,s1, ... divides ord(g(x))�ord(f(x)). The desired result concerning the impulse response sequence follows in a similar way. If g(x) is constant, the theorem is trivial. D We remark that for /(0)"' 0 the least period of the impulse response sequence may also be obtained from the identity (6.9) in the following way. For the impulse response sequence with characteri stic polynomialf(x), the polynomial h(x) in (6.10) is given by h(x) � -l. Therefore, if r is the least period of the impulse response sequence, then f(x) divides x' -I by (6.9) and so r;;. ord(/(x)). On the other hand, r must divide ord(/(x)) by the first part of Theorem 6.27, and so r � ord(f(x)). 6.28. Theorem. Let s0, s1, .•• be a homogeneous linear recurring sequence in IF q with nonzero initial state vector, and suppose the characteristic polynomial f(x) E F q[x) is irreducible over IF q and satisfies f(O)"' 0. Then the sequence is periodic with least period equal to ord(/( x )). 200 Linear Recurring Sequences Proof The sequence is periodic and its least period r divides ord(/(x)) by Theorem 6.27. On the other hand, it follows from (6.9) that f(x) divides (x' -l)h(x). Since s(x), and therefore h(x), is a nonzero polynomial and since deg(h(x)) < deg(/(x)), the irreducibility of /(x) implies that f(x) divides x'-I, and so r;. ord(/(x)). D Now we present a different proof of Corollary 3.4, which we restate for convenience. 6.29. Theorem. Let f(x) E IF•[x] be irreducible over �"• with deg(/(x)) = k. Then ord(/(x)) divides q' -I. Proof We may assume without loss of generality that /(0) * 0 and that f(x) is monic. We take a homogeneous linear recurring sequence in F • that hasf(x) as its characteristic polynomial and has a nonzero initial state vector. According to Theorem 6.28, this sequence is periodic with least period ord(/(x)), so that altogether ord(/(x)) different state vectors appear in it. If ord(/(x)) is less than q'-I, the total number of nonzero k-tuples of elements of r •. we can choose such a k-tuple that does not appear as a state vector in the sequence above and use it as an initial state vector for another homogeneous linear recurring sequence in F • with characteristic polynomial f(x). None of the ord(/(x)) different state vectors of the second sequence is equal to a state vector of the first sequence, for otherwise the two sequences would be identical from some points onwards and the initial state vector of the second sequence would eventually appear as a state vector in the first sequence-a contradiction. By continuing to generate linear recurring sequences of the type above, we arrive at a partition of the set of q'-I nonzero k-tuples of elements of F• into subsets of cardinality ord(/(x)), and the conclusion of the theorem follows. D 6.30. Example. Consider the linear recurrence relation s,+6 = s,+4 + s,+2 + s,+ 1 + s,, n = 0, I, ... , in F2. The corresponding characteristic polynomial is/(x)=x6-x4-x 2-x-IEF 2[x]. The polynomial /(x) is irreducible over F2• Furthermore, /(x) divides x21- I and no polynomial x'- I with 0 < e < 21, so that ord(/(x)) = 21. The impulse response sequence corre­ sponding to the linear recurrence relation is given by the string of binary digits 000001010010011001011000001··· of least period 21, as it should be. If (0, 0, 0, 0, I, I) is taken as the initial state vector, we arrive at the string of binary digits 00001111011010101 1101000011 ... of least period 21, and if (0,0,0, 1,0,0) is taken as the initial state vector, we 2. Impulse Response Sequences, Characteristic Polynomial 201 obtain the string of binary digits .000 I 000 I I 0 I I Ill I 00 II I 000 I 00 · · · of least period 21. Each one of the nonzero sextuples of elements of F2 appears as a state vector in exactly one of the three sequences. Any other nonzero initial state vector will produce a shifted version of one of the three sequences, which is again a sequence of least period 21. 0 6.31. Example. If /(x) E IF.[x] with deg(f(x)) � k is reducible, then ord(/(x)) need not divide q' -I. Consider f(x) � x' + x +IE IF2[x]. Then f(x) is reducible since x'+x+I�(x3+x2+I}(x2+x+l). It follows, for instance, from Theorem 6.27 and Example 6.14 that ord(/(x)) � 21, and this is not a divisor of 2' -I� 31. 0 Linear recurring sequences whose least periods are very large are of particular importance in applications. We know from Theorem 6.7 that for a k th-order homogeneous linear recurring sequence in IF q the least period can be at most q' -I. In order to generate such sequences for which the least period is actually equal to q' -I, we have to use the notion of a primitive polynomial (see Definition 3.15). 6.32. Definition. A homogeneous linear recurring sequence in f • whose characteristic polynomial is a primitive polynomial over IF • and which has a nonzero initial state vector is called a maximal period sequence in IF q· 6.33. Theorem. Every kth-order maximal period sequence in IF q is periodic and its least period is equal to the largest possible value for the least period of any kth-order homogeneous linear recurring sequence in F q-namely, q'-I. Proof The fact that the sequence is periodic and that the least period is q' -I is a consequence of Theorem 6.28 and Theorem 3.16. The remaining assertion follows from Theorem 6. 7. 0 6.34. Example. The linear recurrence relation s,+1=sn+4+sn+3+s,+2 + s", n � 0, I, ... , in F 2 considered in Example 6.2 has the polynomial /(x) � x1-x4-x'-x2 -IE F2[x] as its characteristic polynomial. Since /(x) is a primitive polynomial over F2, any sequence with nonzero initial state vector arising from this linear recurrence relation is a maximal period sequence in IF2. If we choose one particular nonzero initial state vector, then the resulting sequence s0, s1,. .. has least period 27 -I� 127 according to Theorem 6.33. Therefore, all possible nonzero vectors of IFI appear as state vectors in this sequence. Any other maximal period sequence arising from the given linear recurrence relation is just a shifted version of the sequence s0,s1,.... 0 202 Linear Recurring Sequences 3. GENERATING FUNCTIONS So far, our approach to linear recurring sequences has employed only linear algebra, polynomial algebra, and the theory of finite fields. By using the algebraic apparatus of formal power series, other remarkable facts about linear recurring sequences can be established. Given an arbitrary sequence s0, s1, ..• of elements of IF q' we associate with it its generating function, which is a purely formal expression of the type "' G(x)=so+slx+s2x2+ ... +s,,x"+ ... = L snx" n-O (6.13) with an indeterminate x. The underlying idea is that in G(x) we have "stored" all the terms of the sequence in the correct order, so that G ( x) should somehow reflect the properties of the sequence. The name "generat­ ing function" is, strictly speaking, a misnomer since we do not consider G(x) in any way as a function, but just as a formal object (in an obvious analogy, polynomials are essentially formal ob jects not to be confused with functions). The term is carried over from the case of real or complex sequences, where it may often turn out that the series analogous to the one in (6.13) is convergent after substitution of a real or complex number x0 for x, thus enabling us to attach a meaning to G(x0). In our present situation, the question of the convergence or divergence of the expression in (6.13) is moot, since we think of G ( x) as being nothing but a hieroglyph for the sequence s0, s1, .... In general, an object of the type B(x)�b0+b1x+b2x2+ ··· +h .. x"+ with b0, b1, ... being a sequence of elements of IF •. is called a formal power series (over F.). In this context, the terms b0, b1, ... of the sequence are also called the coefficients of the formal power series. The adjective "formal" refers again to the idea that the convergence or divergence (whatever that may mean) of these expressions is irrelevant for their study. Two such formal power series 00 B(x) � L b.,x" and ,,-o over IF• are considered identical if b, � c, for all n � 0,1, .... The set of all formal power series over IF q is then in an obvious one-to-one correspondence with the set of all sequences of elements of IF •. Thus, it seems as if we have not gained anything from the transition to formal power series (save a conceptual complication). The raison d 'etre of these objects is the fact that we can endow the set of all formal power series over IF q with a rich and 3. Generating Functions 203 interesting algebraic structure in a fairly natural way. This will be discussed in the sequel. We note first that we may think of a polynomial p(x) �Po+ p1x + · · · + p,x' E F.(x] as a formal power series over IF • by identifying it with P(x) �Po+ p1x + · · · + p,x' +O·x>+1 +0·x'+2 + · · ·. We introduce now the algebraic operations of addition and multiplication for formal power series in such a way that they extend the corresponding operations for polynomials. In detail, if "' 00 B(x)� L b.x• and C(x)� L c.x• •-0 .�o are two formal power series over IF q• we define their sum to be the formal power series 00 B(x)+C(x)� L (b.+c.)x" n=O and their product to be the formal power series n B(x)C(x)� L d.x•, whered.� L b,c._, forn�O,l, .... n=O k=O If B(x) and C(x) are both polynomials over F •. .then the operations above obviously coincide with polynomial addition and multiplication, respec­ tively. It should be observed at this point that the substitution principle, which is so useful in polynomial algebra, is not valid for formal power series, the simple reason being that the expression B(a) with a E IF• and B(x) a formal power series over IF• may be meaningless. This is. of course, the price we have to pay for disregarding convergence questions. 6.35. Example. Let and "' C(x)�l+x+x2+ ··· +x"+ L l·x" ·-0 be formal power series over IF 3• Then "' B(x)+C(x)�x+2x2+x3+ ··· +x"+ ··· � L d.x• n-0 with d0 � 0, d1 �I, d2 � 2, and d.� I for n;;. 3, and B(x)C(x) �2+2x+O·x2+0·x3+ ··· �2+2x. 0 204 Linear Recurring Sequences Addition of formal power series over IF q is clearly associative and commutative. The formal power series 0 = L�_00 ·xn serves as an identity element for addition, and if B(x) � f.':'�ob.x" is an arbitrary formal power series over F 9, then it has the additive inverse L':�o(-bn)xn, denoted by -B(x). As usual, we shall write B(x)-C(x) instead of B(x)+(- C(x)). Evidently, multiplication of formal power series over !F q is commuta­ tive,and theformalpowerseries 1=1+0·x+O ·x2+ ··· +0·x'1+ ···acts as a multiplicative identity. Multiplication is associative, for if "' 00 "' B(x)� L b.x", C(x) � L c.x", and D(x) � L d.x", "-0 n=O n-O then ( B(x)C(x))D(x) and B(x)(C(x)D(x)) are both identical with where L(n) is the set of all ordered triples (i, j, k) of nonnegative integers with i + j + k = n. Furthermore, the distributive law is satisfied since B(x)(C(x)+ D(x)) � ,,t (.t b,(c. _,+d._,) )x" f: ( t b,c._,+ t b,d._,)x• n-O k-0 k-0 f: ( t b,c,_,)x"+ f: ( t b,d._,)x" n=O k-0 n-O k-0 � B(x )C(x )+ B(x) D(x ). Altogether, we have shown that the set of all formal power series over IFq, furnished with this addition and multiplication, is a commutative ring with identity, called the ring of formal power series over f, and denoted by F,[[xll· The polynomial ring IF0[xl is contained as a subring in IF0[[xll· We collect and extend the information on IF q[[x II in the following theorem. 6.36. Theorem. The ring f ,[[x II of formal power series over IF q is an integral domain containing IF q[x I as a subring. Proof It remains to verify that IF0[[x]] has no zero divisors-that is, that a product in l' q[[x II can only be zero if one of the factors is zero. Suppose, on th� contrary, that we have B( x )C( x) � 0 with 00 00 B(x) � L b.x" "'0 and C(x) � L c,x" "'0 in IF,[[xl]. n=O •-0 Let k be the least nonnegative integer for which b, "'0. and let m be the 3. Generati ng Functions 205 least nonnegative integer for which em* 0. Then the coefficient of xk+m in B(x)C(x) is bkc., * 0, which contradicts B(x)C(x) � 0. D It will be important for the applications to linear recurring sequences to find those B(x) E IF .Ux]] that possess a multiplicative inverse-that is, for which there exists a C(x) E IF•[[x]] with B(x)C(x) � l. These formal power series can, in fact, be characterized easily. 6.37. 111eorem. The formal power series 00 B(x)� I: b,x"EF.[[x]] •-0 has a multiplicative inverse if and only if b0 * 0. Proof If "" C(x)� I: c,x"EIF.[[x]] .-o is such that B(x)C(x) � 1, then the following infinite system of equations must be satisfied: b0c0� 1 b0c1 + b1c0�0 b0c2 + b1c1 + b2c0 �o . . . bocn+blcn-1+ ... +bnco=O From the first equation we conclude that necessarily b0 * 0. However, if this condition is satisfied, then c0 is uniquely determined by the first equation. Passing to the second equation, we see that c1 is then uniquely determined. In general, the coefficients c0, c1, ••• can be computed recursively from the first equation and the recurrence relation " cn=-b0-1 L bkcn-k rorn=t,2, .... k =I The resulting formal power series C(x) is then a multiplicative inverse of B(x). D If a multiplicative inverse of B(x) E IF.[[x]] exists, then it is, of course. uniquely determined . We use the notation 1/B(x) for it. A product A(x)(l/B(x)) with A(x) E F•[[x]] will usually be written in the form A(x)/B(x). Since F.[[x]] is an integral domain, the familiar rules for operating with fra ctions hold. The multiplicative inverse of B(x) or an expression A(x)/B(x) can be computed by the algorithm in the proof of 206 Linear Recurring Sequences Theorem 6.37. Long division also provides an effective means for accom­ plishing such computations . 638. Example. Let B(x)�3+x+x 2, considered as a formal power series over IF,. Then B(x) has a multiplicative inverse by Theorem 6.37. We compute 1/B(x) by long division: 2+ x +4x2 +2x4 + · · · 3+x+x'II+O·x + O·x2 + O·x3+0·x4+0·x'+O·x6+ · · · -l-2x -2x2 Thus we get 3x + 3x2 + O·x' -3x -x2 x3 2x2 + 2x2 3+ x + x2 2 + x + 4x 2 + 2x4 + · · · . 6.39. Example. We compute A(x)/B(x) in F2[[x]], where 00 A(x)�I+x+x 2+x3+ ··· � L l·x" n-O 0 and B(x) �I+ x + x'- Using long division, dropping the terms with zero coefficients, and recalling that I � -I in F 2, we get: l+x2+x3+x1+ ··· l+x+x�l+x +x2+x3+x4 +x5+x6+x7+x8+x9+x10+ ··· Therefore, I+ x + x3 x2 +x4 +xs x2+x3 +xs x3+x4 +x6 x3+x4 +x6 1 +X+ X2 + x3 + · · · ..:._c..:.:-'....:.:...-'....:.:...-.:-'--- � I + X 2 + X' + X 7 + .... 1 +X+ X3 0 3. Generating Functions 207 In order to apply the theory of formal power series, we consider now a k th-order homogeneous linear recurring sequence s0, s1, ••• in F q satisfying the linear recurrence relation (6.7) and define its reciprocal characteristic polynomial to be f*(x)�l-a,_1x-a,_2x2-••• -a0x'EF.[x]. (6.14) The characteristic polynomial j(x) and the reciprocal characteristic poly­ nomial are related by f*(x) � x'f(l/x). The following basic identity can then be shown for the generating function of the given sequence. 6.40. Theorem. Let s0, s1,... be a kth-order homogeneous linear recurring sequence in f q satisfying the linear recurrence relation (6.7),_ let f*(x) E F .[x] be its reciprocal characteristic polynomial, and let G(x) E IF .nx ]] be its generating function in (6.13). Then the identity holds with G(x)�g(x) (6.15) f*(x) k -I j g(x) �-L L a1+k_1s1x1 EIF.[x], j-0 i-0 (6.16) where we set a,� -l. Conversely, if g(x) is any polynomial over IF• with deg(g(x)) < k and if f*(x) E F.[x] is given by (6.14), then the formal power series G(x) E F.[[x]] defined by (6.15) is" the generating function of a kth-order homogeneous linear recurring sequence in F q satisfYing the linear recurrence relation (6.7). Proof We have f*(x)G(x) �-( E a,_.,x")( E s.,x") n-O n-O 'f,' ( t a,+k-js,)x'-E ( t a,+k-js,)xj j-0 1-0 J=k i=j-k �g(x)-E ( E a,s1_,+1)xl (6.17) j-k. j-0 Thus, if the sequence s0, s1, ... satisfies (6.7), then f*(x)G(x) � g(x) be­ cause of (6.12). Since f*(x) has a multiplicative inverse in F•[[x]] by Theorem 6.37, the identity (6.15) follows. Conversely, we infer from (6.17) that f*(x )G( x) is equal to a polynomial of degree less than k only if k L a1sj-k+i = 0 for all}> k. j-0 208 Linear Recurring Sequences But these identities just express the fact that the sequence s0,s1, ... of coefficients of -G ( x) satisfies the linear recurrence relation (6.7). D One may summarize the theorem above by saying that the k th-order homogeneous linear recurring sequences with reciprocal characteristic poly­ nomial /*( x) are in one-to-one correspondence with the fractions g(x)//*(x) with deg(g(x)) < k. The identity (6.15) can be used to compute the terms of a linear recurring sequence by long division. 6.41. Example. Consider the linear recurrence relation Its reciprocal characteristic polynomial is /*(x) � 1-x-x3-x4 �I+ x + x3 + x4 EIF2[x]. If the initial state vector is (1,1,0,1), then the polynomial g(x) in (6.16) turns out to be g(x) �I+ x2 Therefore. the generating function G(x) of the sequence can be obtained from the following long division: +x +x3+x4+x6+ · · · l+x+x3+x41 +x2 The result is 1 +x +x3+x4 x +x2+x3+x4 x +x2 +x4+ x5 x4+ x5+x6+x1 x4+ xs +x7+xs ) I + x2 3 4 6 G(x �-----:--- c�l+x+x +x +x + ... 1+x+x 3+x4 ' which corresponds to the string of binary digits I 1 0 11 0 I · · · of least period 3. The impulse response sequence associated with the given linear recurrence relation can be obtained by observing that g(x) = x3 in this case, so that an appropriate long division yields which corresponds to the string of binary digits 000 Ill 000 1 II · · · of least period 6. D 3. Generating Functions 209 On the basis of the identity (6.15), we present now an alternative proof of Theorem 6.25. Since the sequence s0, s1, ••• is periodic with period r, its generating function G(x) can be written in the form G(x)�(s +sx+···+s x'-')(l+x'+x''+···)�s*(x) o 1 r-1 I-x' with s*( x) = s0 + s1 x + · · · + s, _ 1x'- 1• On the other hand, using the nota­ tion of Theorem 6.40 we have G(x) � g(x)/f*(x) by (6.15). By equating these expressions for G(x), we arrive at the polynomial identity f*(x)s*(x) � (l-x')g(x). If f(x) and s(x) are as in (6.9), then f( x) s( x) � x'J•( ±) x'-1s*( ±) � ( x'-l) x' -'g( ±), and a comparison of (6.10) and (6.16) shows that x'-'g(±) �-h(x). (6.18) which implies already (6.9). As another application of (6.15) we derive a general formula for the terms of a linear recurring sequence. Let s0, s1, ... be a kth-order homogeneous linear recurring sequence in IF, with characteristic polynomialf(x) E f, [ x]. Let e0 be the multiplicity of 0 as a root of f(x), where we can have e0 � 0, and let a1, ... , am be the distinct nonzero roots of f(x) with multiplicities e1, ••• , em, respectively. For the reciprocal characteristic polynomial we obtain then Since deg(f*(x)) � k-e0, we get from (6.15) g(x) .,-1 , b(x) G(x) = f*(x) = J. t,x + f*(x) with t,E IF, and deg(b(x)) < k-e0. Partial fraction decomposition yields b(x) m "-1 {JiJ f*(x) = 1�1 J�O (I -a,x)i+ 1' where the {JIJ belong to the splitting field of f(x) over IF,. Now and so I (I -a ,x)i+ 1 f (n: j)a;x", n-O ] Q) 00 m e;-1 n+j •o-1 ( ( ) ) G(x) = .�o s,x" = J. t,x' + .�o J, J. j fJ;;ai x". 210 Linear Recurring Sequences Comparison of coefficien ts yields m "-'(n+j) s, = t, + L L . fiijrt: 1=1 j=O ) for n = 0, 1, ... , where tn = 0 for n � e0• This is the desired formula. If e0 � 1 and ei � p for 1 � i � m, where p is the characteristic of f q' then it is easily seen that this formula is equivalent to the one given in Remark 6.23. 4. THE MINIMAL POLYNOMIAL Although we have not yet pointed it out. it is evident that a linear recurring sequence satisfies many other linear recurrence relations apart from the one by which it is defined. For instance, if the sequence s0, s1 .... is periodic with period r, it satisfies the linear recurrence relations s,.,+,.=sn (n =0.1, ... ), 511+2,. = sn (n = 0,1, ... ), and so on. The most extreme case is represented by the sequence 0,0,0, ... , which satisfies any homogeneous linear recurrence relation. The following theorem describes the relationship between the various linear recurrence relations valid for a given homogeneous linear recurring sequence. 6.42. Theorem. Let s0• s1, ••• be a homogeneous linear recurring sequence in IF q· Then there exists a uniquely determined monic polynomial m(x) E IF,[x 1 having the following property: a monic polynomial f(x) E F ,[x 1 of positive degree is a characteristic polynomial of s0, s1,. .. if and only if m(x) divides f(x). Proof Let f0(x) E F,[x1 be the characteristic polynomial of a homogeneous linear recurrence relation satisfied by the sequence, and let h0(x) E IF,[x1 be the polynomial in (6.10) determined by f0(x) and the sequence. If d(x) is the (monic) greatest common divisor of f0(x) and h0(x), then we can write f0(x) = m{x)d(x) and h0(.<) � b(x)d(x) with m(x), h(x) E IF,[x]. We shall prove that m(x) is the desired polynomial. Clearly, m(x) is monic. Now let f(x) E IF,[x) be an arbitrary characteristic polynomial of the given sequence, and let h(x) E F,[x1 be the polynomial in (6.10) determined by f(x) and the sequence. By applying Theorem 6.40, we obtain that the generating function G(x) of the sequence satisfies G(x) = g0(x) = g(x) fo*(x) r(x) with g0(x) and g(x) determined by (6.16). Therefore g(x)fo*(x) = g0(x)f*(x), and using (6.18) we arrive at h (x )f0( x) = -xd<r.<f<x)>-'g( ±) xd<g(f,(xllf.,O ( ±) 4. The Minimal Polynomial 2tt � -xd<g(f,(xll-I go ( �) xd<&lfl•llj• ( �) � ho (X)/( X). After division by d(x) we have h(x)m(x) � b(x)f(x), and since m(x) and b(x) are relatively prime, it follows that m(x) dividesf(x). Now suppose that f(x) E IF•[x] is a monic polynomial of positive degree that is divisible by m(x), say f(x) � m(x)c(x) with c(x) E IF•[x]. Passing to reciprocal polynomials, we getf*(x) � m*(x)c*(x) in an obvious notation. We also have h0(x)m(x) � b(x)f0(x), so that, using the relation (6.18), we obtain go( X) m*( X) � -Xdog(f,(x))-lho ( � )xdeg(m(x))m ( �) � -xd<g(m(x))-lb ( �) x•<&lfol•))to ( �). Since deg(b(x)) < deg(m(x)), the product of the first two factors on the right-hand side (negative sign included) is a polynomial a(x) E F .lx ]. Therefore, we have g0(x)m*(x) � a(x)frj(x). It follows then from Theorem 6.40 that the generating function G(x) of the sequence satisfies Since G(x) � go(x) � � � a(x)c•(x) � a(x)c*(x) f0*(x) m*(x) m*(x)c*(x) f*(x) deg(a(x )c•(x )) � deg( a(x )) +deg( c•(x )) < deg( m ( x)) + deg( c ( x)) � deg(/ ( x)), the second part of Theorem 6.40 shows that f(x) is a characteristic polynomial of the sequence. It is clear that there can only be one poly­ nomial m(x) with the indicated properties. D The uniquely determined polynomial m ( x) over F • associated with the sequence s0, s1 .... according to Theorem 6.42 is called the minimal polynomial of the sequence. If s, � 0 for all n ;;. 0, the minimal polynomial is equal to the constant polynomial I. For all other homogeneous linear recurring sequences, m(x) is a monic polynomial with deg(m(x)) > 0 that is. in fact, the characteristic polynomial of the linear recurrence relation of least possible order satisfied by the sequence. Another method of calculating the minimal polynomial will be introduced in Section 6. 6A3. Example. Let s0, s1 .... be the linear recurring sequence in IF2 with sn+4=sn+J+sn+l+sn, n=O,l, ... , and initial state vector (1, 1,0, I). To find the minimal polynomial, we proceed as in the proof of Theorem 6.42. We may take f0(x) � x4-x3- x-l�x 4+x3+x+lEIF 2[x]. Then by (6.10) the polynomial h0(x) is 212 Lin�ar Recurring Sequences given by h0(x) � x3 + x. The greatest common divisor off0(x) and h0(x) is d(x) � x2 + 1, and so the minimal polynomial of the sequence is m(x) � f0(x)/d(x) � x2 + x + 1. One checks easily that the sequence satisfies the linear recurrence relation Sn+2=sn+l+sn, n=O,I, ... , as it should according to the general theory. We note that ord(m(x)) � 3, which is identical with the least period of the sequence (compare with Example 6.41). We shall see in Theorem 6.44 below that this is true m p�. D The minimal polynomial plays a decisive role in the determination of the least period of a linear recurring sequence. This is shown by the following result. 6.44. Theorem. Let s0, sp··· be a homogeneous linear recurring sequence in IF• with minimal polynomial m(x) E F.[x]. Then the least period of the sequence is equal to ord( m ( x )). Proof If r is the least period of the sequence and n0 its preperiod, then we have sn+r = sn for all n � n0. Therefore. the sequence satisfies the homogeneous linear recurrence relation sn+na+r = sn+no for n = 0, I, .... Then, according to Theorem 6.42, m(x) divides x"o+r-x"0 = x"0(Xr-1), so that m(x) is of the form m(x) � x•g(x) with h.;;; n0 and g(x) E F.[x], where g(O) * 0 and g( x) divides x'-1. It follows from the definition of the order of a polynomial that ord(m(x)) � ord(g(x)).;;; r. On the other hand, r divides ord(m(x)) by Theorem 6.27, and so r � ord(m(x)). D 6.45. Example. Let s0, s1, ... be the linear recurring sequence in IF2 with s.+s �s.+1 +s •. n � 0, 1, ... , and initial state vector (1, l, 1,0, 1). Following the method in the proof of Theorem 6.42, we take /0( x) � x5 -x -1 � x5 + x + 1 E IF2[x] and get h0(x) � x4 + x3 + x2 from (6.10), Then d(x) � x2 + x + 1, and so the minimal polynomial m(x) of the sequence is given by m(x) � f0(x )/d(x) � x3 + x2 + 1. We have ord(m(x)) � 7, and so Theorem 6.44 implies that the least period of the sequence is 7 (compare with Example 6.18). D The argument in the example above shows how to find the least period of a linear recurring sequence without evaluating its terms. The method is particularly effective if a table of orders of polynomials is available. Since such tables usually incorporate only irreducible polynomials (see Chapter 10, Section 2), the results in Theorems 3.8 and 3.9 may have to be used to find the order of a given polynomial (compare with Example 3.10). 4. The Minimal Polynomial '213 6.46. Example. The method in Example 6.45 can also be applied Jo inhomogeneous linear recurring sequences. Let s0• s 1, ••• be such a seqUeil'ce. in rF2 with sn+4=s,+3+sn+1+s11+l forn=O.I, ... and initial state vector (1, 1,0, 1). According to (6.5), the sequence is also given by the homogeneous linear recurrence relation sn+ 5 = sn+J + S11 + 1 + S11, n � 0, 1, ... , with initial state vector (1, 1.0.1,0). Proceeding as in Example 6.45, we find that the characteristic polynomial f(x) � x5 +x' +x' +I� (x + l)'(x' + x +I) E IF2[x] IS m the present case identical with the minimal polynomial m(x) of the sequence. Since ord(( x + I)')� 4 by Theorem 3.8 and ord( x2 + x + I)� 3, it follows from Theorem 3.9 that ord(m(x)) � 12. Therefore, the sequence s0, s1 .... is periodic with least period 12. D 6.47. Example. Consider the linear recurring sequence s0,s1, ... in F2 with S11+4=sn+2+sn+l forn=O,I, ... and initial state vector (1,0, 1,0). Then f(x) �x4 +x2 +x �x(x' + x + 1) E F2[x] Is a characteristic polynomial of the sequence, and since neither x nor x3 + x +I is a characteristic polynomial .. we have m(x) = x4 + x2 + x. The sequence is not periodic,. but ultimately perio\lic with least period ord(m(x))�7. D 6.48. Theorem. Let s0, s1, ••• be a homogeneous linear recurring sequence in rF q and let b be a positive integer. Then the minimal polynomial m1(x) of the shifted sequence s., sb+ 1, ... divides the minimal polynomial m( x) of the original sequence. If s0, s1, ... is periodic, then m 1( x) � m( x ). Proof To prove the first assertion, it suffices to show because of Theorem 6.42 that every homogeneous linear recurrence relation satisfied by the original sequence is also satisfied by the shifted sequence. But this is immediately evident. For the second part, let s,+b+l.:=ak-lsn+b+lt-1+ ... +aosn+b• n=O,I, ... , be a homogeneous linear recurrence relation satisfied by the shifted se­ quence. Let r be a period of s0, s1, ••• , so that sn+r = s, for all n � 0, and choose an integer c with cr �b. Then, by using the linear recurrence relation with n replaced by n + cr-band invoking the periodicity property, we find that sn+�.:=a�,:_1s"+�t:-l+ ··· +a0s" foralln>O, that is, that the sequence s0, s1, ... satisfies the same linear recurrence relation as the shifted sequence. By applying again Theorem 6.42, we conclude that m.l xl � mt x\. n 214 Linear Recurring Sequences 6.49. Example. Let s0,s1, .•. be the linear recurring sequence in f2 con­ sidered in Example 6.47. Its minimal polynomial is x4 + x2 + x, whereas the minimal polynomial of the shifted sequence s1, s2, ... is x3 + x +I, which is a proper divisor of x4 + x2 + x. This example shows that the second assertion in Theorem 6.48 need not hold if s0, s1, ••• is only ultimately periodic. but not periodic. D 6.50. Theorem. Let f(x) E IF ,[x] be monic and irreducible over IF,. and let s0• s1 •... be a homogeneous linear recurring sequence in IFq not all of whose terms are 0. If the sequence has f(x) as a characteristic polynomial, then the minimal polynomial of the sequence is equal to f(x ). Proof Since the minimal polynomial m ( x) of the sequence divides f(x) according to Theorem 6.42, the irreduci bility off(x) implies that either m(x) �I or m(x) � f(x). But m(x) �I holds only for the sequence all of whose terms are 0, and so the result follows. D There is a general criterion for deciding whether the characteristic polynomial of the linear recurrence relation defining a given linear recurring sequence is already the minimal polynomial of the sequence. 6.51. Theorem. Let s0,s1, ... be a sequence in IF, satisfying a kth­ order homogeneous linear recurrence relation with characteristic polynomial f(x) E F,[x]. Then f(x) is the minimal polynomial of the sequence if and only 1/ the state vectors s0• s1, ..• , sk _1 are linearly i':'dependent over f q· Proof Suppose f(x) is the minimal polynomial of the sequence. If s0• s1, ...• sk _ 1 were linearly dependent over F q• we would have b0s0 + b1s1 + · · · + b,_1s,_1 �Owithcoefficientsb0,b1, ... ,b,_1 E!'9not all of which are zero. Multiplying from the right by powers of the matrix A in (6.3) associated with the given linear recurrence relation yields b0sn+b1sn+1+ ··· +blr._1sn+k-1=0 forn=O,l, .... because of (6.4). In particular, we obtain b0s_n+b1sn+1+ ··· +bk_1sn+k-1=0forn=O,l, .... If b; � 0 for I� j � k -I, it follows that s, � 0 for all n;,. 0, a contradiction to the fact that the minimal polynomial f(x) of the sequence has positive degree. In the remaining case, let};,. I be the largest index with b1 * 0. Then it follows that the sequence s0,s1, ... satisfies a jth-order homogeneous linear recurrence relation with}< k. which again contradicts the assumption that f(x) is the minimal polynomial. Therefore we have shown that s0, s1, •.. ,sk _ 1 are linearly independent over IF q· Conversely, suppose that s0, s1, ..• , sk _1 are linearly independent over F •. Since s0 * 0, the minimal polynomial has positive degree. If f(x) were not the minimal polynomial, the sequence s0,s1, ..• would satisfy an 5. Families of Linear Recurring Sequen(;es mth-order homogeneous linear recurrence relation with 1 � m < k, say sn+m=am-lsn+m-l+ ··· +a0s11 forn=O,l, ... 215 with coefficients from IF q· But this would imply sm =am _1sm _1 + · · · + a0s0, a contradiction to the given linear independence property. D 6.52. CoroUary. If s0• s 1,... is an impulse response sequence for some homogeneous linear recurrence relation in F q• then its minimal poly­ nomial is equal to the characteristic polynomial of that linear recurrence relation. Proof independence quence. This follows from Theorem 6.51 since the required linear property is obviously satisfied for an impulse response se­ D 5. FAMILIES OF LINEAR RECURRING SEQUENCES Letf(x)EF.[x] be a monic polynomial of positive degree. We denote the set of all homogeneous linear recurring sequences in IF q with characteristic polynomial f(x) by S(/(x)). In other words, S(/(x)) consists of all sequences in F q satisfying the homogeneous linear recurrence relation determined by f(x). If deg(/(x)) � k, then S(/(x)) contains exactly q• sequences, corresponding to the qk diff�rent choices for initial state vectors. The set S(/(x)) may be considered as avector space over IF• if operations for sequences are defined termwise. In detail. if o is the sequence s0, s1 •••• and., the sequence t0,t1, ... in f q' then the sumo+., is taken to be the sequence s0 + t 0• s 1 + 11, .... Furthermore, if c E F q• then co is defined as the sequence cs0, cs1 •••• • It is seen immediately from the recurrence relation that S(/( x)) is closed under this addition and scalar multiplication. The required axioms are easily checked. and so S(/(x)) is indeed a vector space over IF •. The role of the zero vector is played by the zero sequence, all of whose terms are 0. Since S(/(x)) has q• elements, the dimension of the vector space is k. We obtain k linearly independent elements of S(/(x)) by choosing k linearly independent k-tuples y1, .... y. of elements of IF• and considering the sequences o1, .... o. belonging to S(/(x)), where each o1, l .;; j.;; k, has y1 as its initial state vector. A natural choice for y1, .... y, is to take the standard basis vectors e1 � (l.O ..... O),e2 � (0, l, ... ,O). .... e, � (0, ... ,0,1). Another possibility that is often advantageous is to consider the impulse response sequence d0• d1, ... belonging to S(/( x)) and to choose for y1, ... ,y, the state vectors d0, ... ,dk _1 of this impulse response sequence. In the following discussion, we shall explore the relationship between the various sets S(/( x )). 216 Linear Recurring Sequences 6.53. Theorem. Let f(x) and g(x) be two nonconstant monic poly· nomials over F •. Then S(/(x)) is a subset of S(g(x)) if and only if f(x) divides g(x ). Proof Suppose S(/(x)) is contained in S(g(x)). Consider the impulse response sequence belonging to S(/(x )). This sequence has f( x) as its minimal polynomial because of Corollary 6.52. By hypothesis, the sequence belongs also to S( g(x )). Therefore. according to Theorem 6.42, its minimal polynomial f(x) divides g(x). Conversely, if f(x) divides g(x) and s0, ·' 1, ••• is any sequence belonging to S(/(x )), then the minimal poly­ nomial m(x) of the sequence divides f(x) by Theorem 6.42. Consequently, m(x) divides g(x), and so another application of Theorem 6.42 shows that the sequence s0,s1, ••• belongs to S(g(x)). Therefore, S(/(x)) is a subset of S(g(x)). D 6.54. Theorem. Let f1 ( x ), ... ,f, ( x) be nonconstant monic polynomi­ als over IF •. If f1(x), ... ,f,(x) are relatively prime, then the intersection s(/,(x))n ·· · ns(/,(x)) consists only of the zero sequence. If f1(x), ... ,f,(x) have a (monic) greatest common divisor d(x) of positive degree, then S(/,(x))n · · · n s(/,(x)) � S(d(x)). Proof The minimal polynomial m(x) of a sequence in the intersec­ tion must divide f1(x), ... ,f,(x). In the case of relative primality, m(x) is necessarily the constant polynomial I; but only the zero sequence has this minimal polynomial. In the second case, we conclude that m(x) divides d(x), and then Theorem 6.42 implies that S(/1(x))n ·· · ns(/,(x)) is contained in S(d(x)). The fact that S(d(x)) is a subset of S(/1(x))n · · · n S( f,(x)) follows immediately from Theorem 6.53. D We define S(/(x))+ S(g(x)) to be the set of all sequences a+ T with a E S(/(x)) and T E S(g(x)). This definition can, of course, be extended to any finite number of such sets. 6.55. Theorem. Let f1 ( x ), ... J, ( x) be nonconstant monic polynomi­ als over F q· Then S(/1(x))+ ·· · +S(/,(x))�S(c(x)), where c(x) is the (monic) least common multiple of f1 (x ), ... ,f,(x ). Proof It suffices to consider the case h � 2 since the general case follows easily by induction. We note first that, according to Theorem 6.53, each sequence belonging to S(/1(x)) or to S(/2(x)) belongs to S(c(x)), and since the latter is a vector space, it follows that S(/1(x))+ S(/2(x)) is contained in S(c(x)). We compare now the dimensions of these vector 5. Families of Linear Recurring Sequences 217 spaces over F •. Writing V1 � S(/1(x)) and V2 � S(/2(x)) and letting d(x) be the (monic) greatest common divisor of f1(x) and f2(x), we get dim(V, + V2) � dim(V1)+dim(V2)-dim(V1 n V2) � deg{!1 (x )) +deg{!2 ( x)) -deg( d( x )) , where we have applied Theorem 6.54. But c(x)� f1(x)f2(x)jd(x), and so dim(V1 + V2) � deg(c(x)) � dim{S(c(x))). Therefore, the linear subspace S(/1(x))+ S(/2(x)) has the same dimension as the vector spaceS( c(x )), and so S(/1(x ))+ S(/2(x)) � S( c(x )). D In the special case where f( x) and g( x) are relatively prime noncon­ stant monic polynomials over F q• we will have S{f(x )g(x )) � S(/(x )) + S(g(x )) . Since, in this case, Theorem 6.54 shows that S(f(x ))n S(g(x)) consists only of the zero sequence, S(f(x)g(x) ) is (in the language of linear algebra) the direct sum of the linear subspaces S(/(x)) and S(g(x)). In other words, every sequence o E S(/(x)g(x)) can be expressed uniquely in the form o � o1 + o2 with o1 E S(/(x)) and o2 E S(g(x)). Let us recall that S(/(x)) is a vector space over F• whose dimension is equal to the degree off(x). This vector space has an interesting additional property: if the sequence s0, s1, ... belongs to S(f(x )), then for every integer b>O the shifted sequence sb,sb+1,.:. again belongs to S(/(x)). This follows, of course, immediately from the linear""' recurrence relation. We express this property by saying that S(/(x)) is closed under shifts of sequences. Taken together, the properties listed here characterize the sets S(f(x)) completely. 6.56. Theorem. Let E be a set of sequences in IF q· Then E � S(f(x )) for some monic polynomial f( x) E IF .I x] of positive degree if and only if E is a vector space over F q of positive finite dimension (under the usual addition and scalar multiplication of sequences) which is closed under shifts of sequences. Proof We have already noted above that these conditions are necessary. To establish the converse, consider an arbitrary sequence o E E that is not the zero sequence. If s0, s1, ••• are the terms of o and b;. 0 is an integer, we denote by o<•l the shifted sequence sb, sb+ 1, .... By hypothesis, the sequences o<01,o01,o(21, ... all belong to E. But Eisa finite set, and so there exist nonnegative integers i < j with o"l � o<i1. It follows that the original sequence a satisfies the homogeneous linear recurrence relation s.+1�s.+;• n�O,l, .... According to Theorem 6.42, the sequence o has then a minimal polynomial m.(x) E F•[x] of positive degree k, say. The state vectors s0,s1, ... ,s •. 1 of the sequence o are thus lineasly independent over F• by virtue of Theorem 6.51. Consequently, the sequences 218 Linear Recurring Sequences a'0', a''' .... ,a''-" are linearly independent elements of S(m.(x)) and hence form a basis for S(m.(x)). Since a'0'.a(l' .... ,a''-'' belong to the vector space E, it follows that S(m.(x)) is a linear subspace of E. Letting E* denote the set E with the zero sequence deleted and carrying out the argument above for every a E E*, we arrive at the statement that the finite sum E.E pS(m.(x) ) of vector spaces is a linear subspace of E. On the other hand, it is trivial that E is contained in E.EPS(m.(x)), and so E =E. E pS(m.(x) ). By invoking Theorem 6.55, we get E = L, S(m.(x)) = S(/(x)), where f(x) is the least common multiple of all the polynomials m.(x) with a running through E*. 0 It follows from Theorem 6.55 that the sum of two or more homoge­ neous linear recurring sequences in f q is again a homogeneous linear recurring sequence. A characteristic polynomial of the sum sequence is also obtained from this theorem. In important special cases, the minimal poly­ nomial and the least period of the sum sequence can be determined directly on the basis of the corresponding information for the original sequences. 6.57. Theorem. For each i = I, 2, ... , h, let a, be a homogeneous linear recurring sequence in F • with minimal polynomial m 1 ( x) E IF •[ x ]. If the polynomials m1(x), ... ,m,(x) are pairwise relatively prime, then the minimal polynomial of the sum a1 + · · · +a, is equal to the product m1(x) · · · m,(x). Proof It suffices to consider the case h = 2 since the general case follows then by induction. If m1(x) or m2(x) is the constant polynomial I, the result is trivial. Similarly, if the minimal polynomial m(x) E IF'_[x] of a1 + a2 is the constant polynomial 1. we obtain a trivial case. Therefore, we assume that the polynomials m1(x), m2(x), and m(x) have positive degrees. Since a1 '\-a2 E S( m1(x ))+ S( m2(x )) = S(m1 (x )m2(x )) on account of Theorem 6.55, it follows that m(x) divides m1(x)m2(x). Now suppose that the terms of. a1 are s0, s1, ... , that those of a2 are 10, 11, ... , and that Then sn+k+t,.+�c.=a�c.-l(sn+k-l+t,.+k-1)+ ... +ao(s"+t") forn=O.l, .... If we set Un=Sn+k-ak-\Sn+k-1-... -aos,. =-tn+k+ak-lln+k-l+ ··· +a0t11 forn=O,l, ... 5. Families of Linear Recurring Sequences 219 and recall that S(m1(x)) and S(m2(x)) are vector spaces over IF• closed under shifts of sequences (see Theorem 6.56), then we can conclude that the sequence u0, u1, ••• belongs to both S(m1(x)) and S(m2(x)) and is thus the zero sequence, according to Theorem 6.54. But this shows that both m1(x) and m2(x) divide m(x), hence m1(x)m2(x) divides m(x), and so m(x) = m1(x)m2(x). D If the minimal polynomials m1(x), ... ,m,(x) of the individual se­ quences o1, ... ,oh are not pairwise relatively prime, then the special nature of the sequences o1, ... ,oh has to be taken into account in order to determine the minimal polynomial of the sum sequence a = a 1 + · · · + a,. The most feasible method is based on the use of generating functions. Suppose that for i=l,2, ... ,h the generating function of a, is G,(x)EIF.[[x]]. Then the generating function of a is given by G(x) = G1(x)+ · · · + G,(x). By Theo­ rem 6.40, each G,(x) can be written as a fraction with, for instance, the reciprocal polynomial of m,(x) as denominator. We add these fractions, reduce the resulting fraction to lowest terms. and combine the second part of Theorem 6.40 and the method in the proof of Theorem 6.42 to find the minimal polynomial of a. This technique yields also an alternative proof for Theorem 6.57. 6.58. Example. Let a 1 be the impulse response sequence in F 2 belonging to S(x4 + x3 + x +I) and a2 the impulse response sequence in IF2 belonging to S(x' + x4 + 1). Then, according .to Corollary 6.52, the corres ponding minimal polynomials are m1(x}=x4+x3 +x+ I= (x2 +x+ l}(x+ 1)2 EF2[x] and m 2 ( x) = x' + x4 +I = (x2 + x + I}( x3 + x + I) E F2 [ x ]. Using Theorem 6.40, the generating function G(x) of the sum sequence a= o1 + o2 turns out to be x3 x4 G (X ) = + ----cc----:---:-- -;:--- (x2+x+l}(x+l}2 (x2+x+l}(x3+x2+1} x' 2 . (x3+x2+1}(x+l} By the second part of Theorem 6.40, the reciprocal polynomial f0(x) = (x3 + x + l)(x + 1)2 of the denominator is a characteristic polynomial of a. According to (6.18}, the associated polynomial h0(x) is given by h0(x)= -x4(1jx)3 =-x. Since f0(x) and h0(x} are relatively prime, the method 220 Linear Recurring Sequences in the proof of Theorem 6.42 yields the minimal polynomial rn (X) � ( X3 +X + 1 )(X+ 1 )2 foro. We note that rn(x) is a proper divisor of the least common multiple of . m1(x) and m2(x), which is (x2+x+1 )(x+1)2(x3+x+1 ). 0 From the information about the minimal polynomial contained in Theorem 6.57, one can immediately deduce a useful result concerning the least period of a sum sequence. 6.59. Theorem. For each i � 1,2, ... ,h, let o, be a homogeneous linear recurring sequence in IF • with minimal polynomial m, ( x) E IF, [x] and least period r,. If the polynomials m1(x), ... ,m,(x) are pairwise relatively prime, then the least period of the sum o1 + · · · + o, is equal to the least common multiple of r1, ••• ,r,. Proof We consider only the case h � 2, the general result following by induction. If r is the least period of o1 + o2, then r � ord(m1(x)m2(x)) by Theorems 6.44 and 6.57. An application of Theorem 3.9 shows that r is the least common multiple of ord(m1(x)) and ord(m2(x)), and so of r1 and �- 0 6.60. Example. Let the sequences o1 and o2 be as in Example 6.58. Then the least periods of o1 and o2 are r1 � ord(m1(x)) � 6 and r2 � ord(m2(x)) � 21, respectively. The least period r of o1 + o2 is r � ord(m(x)) � 14. In these computations of orders we use, of course, Theorem 3.9. The arguments above have been carried out without having evaluated the terms of the sequences involved. In this special case we may, of course, compare the results with explicit computations of the least periods: o,: 00011100011100011100011100··· �: 00001111101010011000100001 ... least period r 1 = 6 least period r2 = 21 o1 +o2: 00010011110110000100111101·· · leastperiod r�l4 Notice that r is a proper divisor of the least common multiple of r1 and r2. 0 6.61. Theorem. For each i � 1, 2, ... , h, let o, be an ultimately peri­ odic sequence in IF q with least period r;. If r1, ••• ,r11 are painvise relatively prime, then the least period of the sum o1 + · · · + o, is equal to the product ,1 ... 'n.· Proof It suffices to consider the case h � 2 since the general case follows then by induction. It is obvious that r1r2 is a period of o1 + o2, so that the least period r of o1 + o2 divides r1r2• Therefore, r is of the form 5. Families of Linear Recurring Sequences 221 r � d1d2 with d1 and d2 being positive divisors of r1 and r2, respectively. In particular, d1r2 is a period of a1 + a2• Consequently, if the terms of a1 are s0,s1, ... and those ofa2 aret0,t1, ... , then we have for all sufficiently large n. But t,+a,,, � t, for all sufficiently large n, and so sn+d1r1 = S11 for all sufficiently large n. Therefore, r1 divides d1r2, and since r1 and r2 are relatively prime, r1 divides d1, which implies d1 � r1• Similarly, one shows that d2 � r2. D In the finite field IF 2, there is an interesting operation on sequences called binary complementation. If a is a sequence in F2, then its binary complement, denoted by ii, is obtained by replacing each digit 0 in a by I and each digit I in a by 0. Binary complementation is, in fact, a special case of addition of sequences since the binary complement ii of a arises by adding to a the sequence all of whose terms are I. Therefore. if a is a homogeneous linear recurring sequence, then ii is one as well. Clearly, the least period of ii is the same as that of a. The minimal polynomial of ii can be obtained from that of a in an easy manner. 6.62. Theorem. Let a be a homogeneous linear recurring sequence in IF2 with binary complement ii. Write the minimal polynomial m(x) E F2[x] of a in the form m(x) � (x + I)'m1(x) with an integer h;;. 0 and m1(x) E IF2[x] satisfying m1(1) �I. Then the minimal polynomial m(x) of ii is given by m(x)�(x+l)m(x) ifh�O. m(x)�m1(x) ifh�I, and m(x)�m(x) if h >I. . Proof Let < be the sequence in IF 2 all of whose terms are I. Since ii � a + < and the minimal polynomial of < is x + I, the case h � 0 is settled by invoking Theorem 6.57. If h ;;. I, then ii � a + < E S( m ( x)) because of Theorem 6.55, and So m(x) divides m(x). If m(x) is the constant poly­ nomial 1, then ii is necessarily the zero sequence and a = E, and the theorem holds. Therefore, we assume from now on that m(x) is of positive degree. We get a � ii + < E S( m( x )( x + I)) because of Theorems 6.53 and 6.55, thus m(x) divides m(xXx + 1), and so for h;;. I we have either m(x) � m(x) or m(x) � (x + l)'-1m1(x). If h >I, it follows that a� ii + <E S(m(x)), which yields m(x) � m(x). If h �I, let the terms of a be s0, s1, ••• and let m1(x)�x•+a._1x•-1+ ··· +a0 be of positive degree, the excluded case being trivial. We set Since the sequence s0, s 1,... has m ( x) � ( x + I )m 1 ( x) as a characteristic polynomial, it follows easily that u,+ 1 � u, for all n;;. 0. Therefore, u, � u0 for all n;;. 0, and we must have u0 �I, for otherwise m 1 ( x) would be a 222 Linear Recurring Sequences characteristic polynomial of a. Consequently, sn+k+l=a�c._1sn+k-l+ ··· +a0s,1 foralln�O. Sincem1(l)=l+a,_1+ ··· +a0=1, we obtain s,+,+i=a,_,(s,+k-l+i)+ ·· · +a0(s,+i) foralln�O, and this means that m 1 ( x) is a characteristic polynomial of ii. Thus, m(x)=m1(x)inthecasewhereh=l. D We recall that S(/(x)) denotes the set of all homogeneous linear recurring sequences in F q with characteristic polynomial /( x ), where/( x) E IF•[x] is a monic polynomial of positive degree. We want to determine the positive integers that appear as least periods of sequences from S(/(x)), and also,for how many sequences from S(/(x)) such a positive integer is attained as a least period. The polynomial f(x) can be written in the form f(x) = x'g(x), where h � 0 is an integer and g(x) E F q[x] with g(O) * 0. The case in which g(x) is a constant polynomial can be dealt with immediately, since then every sequence from S(/(x)) has least period I. If h �I and g(x) is of positive degree, then, by the discussion following Theorem 6.55, every sequence a E S(/(x)) can be expressed uniquely in the form a= a1 + a2 with a1 E S(x') and a2 E S(g(x)). Apart from finitely many initial terms, all terms of a 1 are zero. so that the least period of a is equal to the least period of a2. Furthermore, a given sequence a2 E S(g(x)) leads to q' different sequences from S(f(x)) by adding to it all the q' sequences from S(x'). Consequently, if r1, •••• r, are the least periods of sequences from S(g(x)) and N1 ...• ,N, are the corresponding numbers of sequences from S( g( x)) having these least periods, then, for I .; i .; t, there are exactly q'N; sequences belonging to S(f(x)) with least period.r,, and no other least periods occur among the sequences from S(f(x)). We may assume from now on that h = 0-that is, that /(0) * 0. Suppose first that/( x) is irreducible over F q· Then, according to Theorems 6.44 and 6.50, every sequence from S(f(x)) with nonzero initial state vector has least period ord(/(x)). Therefore, one sequence from S(f(x)) has least period I and q•'i\J(x)) -I sequences from S(/(x)) have least period ord(/(x)). Next, we consider the case that f(x) is a power of an irreducible polynomial. Thus, let/(x) = g(x)• with g(x) E F•[x] monic and irreducible over F q and b � 2 an integer. The minimal polynomial of any sequence from S(f(x)) with nonzero initial state vector is then of the form g(x)' with I .; c .; b. According to Theorem 6.53, we have S(g(x)) <;; s(g(x)2) <;; · .. <;; S(f(x)). Therefore, if deg(g(x)) = k, then there are q'-I sequences from S(/(x)) 5. Families of Linear Recurring Sequences 223 with minimal polynomial g(x), q2'-q' sequences from S(f(x)) with minimal polynomial g(x)2, and, in general, for c � 1,2, ... ,b there are q''-q(<-llk sequences from S(f(x)) with minimal polynomial g(x)'. By combining this information with Theorems 3.8 and 6.44, we arrive at the following result. 6.63. Theorem. Let f(x) � g(x )• with g(x) E IF .lx] monic and irre­ ducible over IF •• g(O)*O, deg(g(x))�k, ord(g(x))�e, and b a positive integer. Lett be the smallest integer with p';. b, where pis the characteristic of IF •. Then S(f(x)) contains the following numbers of sequences with the following least periods: one sequence with least period I, q'-I sequences with least period e, and for b � 2, qkpl-qkpi-t sequences with least period ep1 (j � 1,2, ... ,t -I) and q••-q'''-' sequences with least period ep'. In the case of an arbitrary monic polynomial f(x) E F•[x] of positive degree with f(O) * 0, we start from the canonical factorization • f(x)� ng,(x)\ i-1 where the g, ( x) are distinct monic irreducible polynomials over F • and the b, are positive integers. It follows then from Theorem 6.55 that In fact, every sequence from S(f(x)) is obtained exactly once by forming all possible sums a1 + · · · + a• with a, E S(g,(x)••) for 1.;; i.;; h. Since the least periods attained by sequences from S(g,(x)••) are known from Theo­ rem 6.63, the analogous information about S(f(x)) can thus be deduced from Theorem 6.59. 6.64. Example. Let f( x) � ( x2 +X +I )2( x4 + x' +I) E IF2 [X]. According to Theorem 6.63, S((x2 + x + 1)2) contains one sequence with least period I, 3 sequences with least period 3, and 12 sequences with least period 6, whereas S(x4 + x' +I) contains one sequence with least period I and 15 sequences with least period 15. Therefore, by forming all possible sums of sequences from S((x2+x+l)') and S(x4+x'+I) and using Theorem 6.59, we conclude that S(f(x)) contains one sequence with least period I, 3 sequences with least period 3, 12 sequences with least period 6, 60 sequences with least period 15, and 180 sequences with least period 30. D We have already investigated the behavior of linear recurring se­ quences under term wise addition. A similar theory can be developed for the 224 Linear Recurring Sequences operation of termwise multiplication, although it presents greater difficul­ ties. If a is the sequence of elements s0,s1, ... of IF• and Tis the sequence of elements t0, t 1,. •• off q' then the product sequence aT has terms s0t0, s1t1, ••. • Analogously, one defines the product of any finite number of sequences. Let S be the vector space over IF q consisting of all sequences of elements of F •• under the usual addition and scalar multiplication of sequences. For non­ constant monic polynomials f1(x), ... ,f,(x) over IF•, let S(/1(x)) · · · S(f,(x)) be the subspace of S spanned by all products o1• ··a, with o, E S(/;(x)), 1.;; i.;; h. The following result is basic. 6.65. Theorem. If /1(x), ... ,f,(x) are nonconstant monic polynomi­ als over IF•, then there exists a nonconstant monic polynomial g(x) E IFq[x] such that S(/1(x))· · · S(/,(x)) � S(g(x)). Proof Set E � S(f1(x)) · · · S(f,(x)). Since each S(f,(x)), 1.;; i.;; h, contains a sequence with initial term 1, the vector space E contains a nonzero sequence. Furthermore, E is spanned by finitely many sequences and thus finite-dimensional. From the fact that each S(/;(x)), 1.;; i .;; h, is closed under shifts of sequences it follows that E has the same property, and then the argument is complete by Theorem 6.56. D 6.66. Corollary. The product of finitely many linear recurring se­ quences in IF q is again a linear recurring sequence in IF q· Proof By the remarks following (6.5), the given linear recurring sequences can be taken to be homogeneous. The result is then implicit in Theorem 6.65. D The explicit determination of the polynomial g(x) in Theorem 6.65 is, in general, not easy. There is, however, a special case that allows a simpler treatment of the problem. For nonconstant polynomials f1(x), ... ,f,(x) over F •. we define /1 ( x) V · · · V /, ( x) to be the monic polynomial whose roots are the distinct elements of the form a1 • • • "•, where each a, is a root of /;( x) in the splitting field of /1(x)· · ·/,(x) over F •. Since the conjugates (over IF•) of such a product a1 • • • "• are again elements of this form, it follows that f1(x)V · · · V /,(x) is a polynomial over F •. 6.67. Theorem. For each i � 1,2, ... ,h, let /;(x) be a nonconstant monic polynomial over F q without multiple roots. Then we have S(/1 (X))··· S(f,( X))� S(/1 (x) V · · · V /,(x )). We need a preparatory lemma and some notation for the proof of this result. For a finite extension field F of F q• let SF be the vector space 5. Families of Linear Recurring Sequences 225 over F consisting of all sequences of elements ofF, under termwise addition and scalar multiplication of sequences. Thus, in particular, SF � S. By the • product V1 • • • V, of h subspaces V 1, ... , V, of SF we mean the subspace of SF spanned by all products a 1 • • • a11 with a; E v,., 1 -E;;: i -E;;: h. For a noncon­ stant monic polynomial f(x) E F[x], let SF(f(x)) be the vector space over F consisting of all homogeneous linear recurring sequences in F with characteristic polynomial f( x ). 6.68. Lemma. Let F be a finite extension field of F ,. and let f1(x), ... ,f,(x) be nonconstant monic polynomials over IF,. Then, S(/1 (x )) ... s(f,(x )) � s n (SF(!\ (x )) ... SF(fh (x ))). Proof Clearly, the vector space on the left-hand side is contained in the vector space on the rigbt-hand side. To show the converse, we note first that each S(/1(x)), I .;; i .;; h, spans SF(/,(x)) over F. Therefore, S(/1(x)) · · · S(f,(x)) spans SF(/1(x)) · · · SF(f,(x)) over F. Let p1, ... ,pm be a basis of S(/1 ( x)) · · · S(f, ( x)) over IF,. and let w 1, ... , w k be a basis of F over IF, with w1 ElF,. Then any aESF(/1(x))·· ·SF(f,(x)) can be written in the form k m a= L L C;jW;P1• i-1 j-1 where the coefficients c1j are in IF,. Let the terms of the sequence pj, I .;; j.;; m, be the elements r10, r11, ... of IF,. If now a E S, then for the terms s,, n�O,I, ... , of awe get Since the coefficient of each w1 is in F,. it follows from the definition of w 1, ••• • wk. that Lj� 1c;/'jn = 0 for 2 -E;;: i -E;;: k and all n. Consequen tly, a= L cl,wlp1ES(/1(x)) .. ·S(/,(x)) j-1 and the proof is complete. D Proof of Theorem 6.67. Let F be the splitting field of f1 ( x) · · · f, ( x) over IF,. For I .;; i.;; h, let a1 run througb the roots of /,(x). Then by Theorem 6.55, ., We note that we have the distributive law V1(V, + V3) � V1V2 + V1V, for subs paces V1• V2, V3 of SF, which is shown by observing that the left-hand 226 Linear Recurring Sequences vector space is contained in the right-hand vector space (by the distributive law for sequences) and that V1V2 c::: V1(V2 + V3) and V1V, c::: V1(V2 + V3) imply V1V2 + V1V, c::: V1(V2 + V3). On the basis of the distributive law, it follows that s,(!,(x)J· · · s,(!,(x)) � E s,(x-a,)· .. s,(x-a,). It is easy to check directly that s,(x-a,)· .. SF(x-a,)� s,(x-a,· .. a,). and so llr:l> ... ,a, �s,(/,(x)V · · · v f.(x)) by Theorem 6.55. The result of Theorem 6.67 follows now from Lemma U& D Theorem 6.67 shows, in particular, how to find a characteristic polynomial for the product of homogeneous linear recurring sequences. at least in the special case considered there. For this purpose, an alternative argument may be based on Theorem 6.21. It suffices to carry out the details for the product of two homogeneous linear recurring sequences. Let the sequence s0, s1, ... belong to S(/(x)) and let 10,11, ... belong to S(g(x)). If f(x) has only the simple roots a1, •••• a, and g(x) has only the simple roots {31, ••• ,{J.,. then by (6.8), ' s, = L bia; and i-1 m I � ... C·"" n 1.... ;PJ j=l forn�O.I, ... , where the coefficients b, and c1 belong to a finite extension field of IF q· If y1 ••••• y, are the distinct values of the products aJ31, 1 .-:e;; i .:e;; k. 1 .-:e;; j .:e;; m, then k m u.�s.t.� L L b,c1(aA)"� L d1y," forn�O.l, ... , i-1 J-1 i-1 with suitable coefficients d1, ••• ,d, in a finite extension field of F •. Now let h(x)�f(x)Vg(x)�x'-a,_,x'-1-··· -a0EIF.[x]. Then for n � 0, I, ... we have u,+,-a,_lun+r-\-... -GoUrr = L d/y;"h ( Y;):::: 0, i-1 and so the product sequence u0, u1, ... has h(x) as a characteristic poly­ nomial. 5. Families of linear Recurring Sequences 227 6.69. Example. Consider the sequence 0, 1,0, 1, ... in IF2 with the least period 2 and minimal polynomial (x-1)2• If we multiply this sequence with itself, we get back the same sequence. On the other hand, (x -1)2 V(x -1)2 � x - I, which is not a characteristic polynomial of the product sequence. Therefore, the identity in Theorem 6.67 may cease to hold if some of the polynomialsf ,(x) are allowed to have multiple roots. 0 There is an analog of Theorem 6.61 for multiplication of sequences. For obvious reasons, sequences for which all but finitely many terms are zero have to be excluded from consideration. 6.70. Theorem. For each i = 1,2, ... ,h, let a; be an ultimately peri­ odic sequence in F q with infinitely many nonzero terms and with least period r;. If r1, ... ,r, are pairwise relatively prime, then the least period of the product a1 · · · ah is equal to r1 · · · rh. Proof We consider only the case h � 2 since the general case follows then by induction. As in the proof of Theorem 6.61 one shows that the least period r of a1a2 must be of the form r � d1d2 with d1 and d2 being positive divisors of r1 and r2, respectively. In particular, d1r2 is a period of a1a2. Thus, if the terms of a1 are s0, s1, ••. and those of a2 are t0, t1, •.. , then we have for all sufficiently large n. Since there exists an integer b with t. * 0 for all sufficiently large n = bmod r2, it follows that s•+d,,, � s. for all such n. Now fix a sufficiently large n; by the Chinese remainder theorem, we can choose an integer m � n with m = nmod r1 and m = bmod r2. Then and so d1r2 is a period of a1• Therefore, r1 divides d1r2• and since r1 and r2 are relatively prime, r1 divides d1, which implies d1 � r1• Similarly, one shows that d2 � r2. 0 Multiplication of sequences can be used to describe the relation between homogeneous linear recurring sequences belonging to characteri stic polynomials that are powers of each other. The case in which one of the characteristic polynomials is linear has to be considered first. 6.71. Lemma. If c is a nonzero element of IF • and k is a positive integer, then s((x-c)•)�S(x-c)S((x-1)•). Proof Let the sequences0, s1, ... belong to S(x-c), and lett0.t" ... 228 Linear Recurring Sequences belong to S((x -I)'). Then s., =c"s0 for n = 0, !, ... and ' L (7)(-I)'-'t,+1=0 forn=O,l, .... i-0 It follows that for n =0, !, .... and so k L (k)(-c)'-'x'=(x-c)' i-0 I is a characteristic polynomial of the product sequence s0t0, s1t1, ••• • Conse­ quently, the vector space S( x -c )S(( x-I)') is a subspace of S(( x -c)'). Since c * 0, the first vector space has dimension k over IF q and is thus equal to S((x-c)'), which has the same dimension over F.. 0 6.72. Theorem. Let f(x) E IF•[x] be a nonconstant monic poly­ nomial with f(O) * 0 and without multiple roots, and let k be a positive integer. Then, S(f(x)') = S(f(x))S((x -I)'). Proof Let F be the splitting field of f(x) over F •. Then, with a running through the roots of /(x), we get a by Theorem 6.55. Using Lemma 6.71 and the distributive law shown in the proof of Theorem 6.67, we obtain s,(J(x)') = LS,((x -l)')s,(x-a)= s,((x -I)')LS,(x-a) a a where we applied Theorem 6.55 in the last step. The desired result follows now from Lemma 6.68. 0 6. CHARACfERIZATION OF LINEAR RECURRING SEQUENCES It is an important problem to decide whether a given sequence of elements of F q is a linear recurring sequence or not. From the theoretical point of 6. Characterization of Linear Recurring Sequences 229 view, the question can be settled immediately since the linear recurring sequences in F • are precisely the ultimately periodic sequences. However, the periods of a linear recurring sequence (even of one of moderately low order) can be extremely long, so that in practice it may not be feasible to determine the nature of the sequence on the basis of this criterion. Alternative ways of characterizing linear recurring sequences employ techniques from linear algebra. Let s0, s1, ••• be an arbitrary sequence of elements ofF,. For integers n;:.,. 0 and r ;a,. I, we introduce the Hankel determinants s. sn+ 1 sn+r-1 D'rl= s,+ I sn+2 s,+, • sn+r-1 s,+, sn+2r-2 It will transpire that linear recurring sequences can be characterized in terms of the vanishing of sufficiently many of these Hankel determinants. 6.73. LemnuJ. Let s0, s1, ••• be an arbitrary sequence in F,, and let n;:.,. 0 and r;:.,. 1 be integers. Then D�'> = D�'+ I)= 0 implies D��>1 = 0. Proof For m>O define the vector sm=(sm,sm+l•···•sm+r-l). From D�')=O it follows that the vectors s,,s,+1, ... ,s,+,-l are linearly dependent over IF,. If s.+ 1, ...• s.+,-l· are already linearly dependent over F q' we immediately get D��l1 = 0. Otherwise, s, is a linear combination of s,+1, ... ,s,+r-l· Set s�=(sm,sm+l•···•sm+r) for m;-.,.0. Then the vectors s�.s�+ 1, ••• , s�+r· being the row vectors of the vanishing determinant D�'+ 1l, are linearly dependent over IF q· If s�.s�+ 1, ••• ,s�+r-l are already linearly dependent over IF<' then an application of the linear transformation L 1: ( a0• a1, ••• ,a,) E F ;+ 1 ..,. ( a1, ... ,a,) E IF; shows that sn+l•s,+2, ... ,s,+, are linearly dependent over Fq, and so D,��)1 = 0. Otherwise, s:+, is a linear combination of s�, s�+ 1, ... , s�+r-1, and by an application of the linear transformation L2: (a0, ... ,a,_1, a,) E IF;+ 1 � (a0, .•. ,a,_1) E F; we obtain that s,+, is a linear combination of s,, s,+ 1, ••• , s,+r-l· But in the case under consideration s, is a linear combination of s,+ 1, ... ,s,+r-l• so that the row vectors sn+l•···•s,+r-l•s,+, of D��� are linearly dependent over IF q• which implies D��� = 0. 0 6.74. Theorem. The sequence s0, s1, ... in F q is a linear recurring sequence if and only if there exists a positive integer r such that D?' � 0 for all but finitely many n;;. 0. 230 Linear Recurring Sequences Proof Suppose s0, s1, ... satisfies a kth-order homogeneous linear recurrence relation. For any fixed n;;. 0, consider the determinant D�k+ ''· Because of the linear recurrence relation, the (k + l)st row of D�k+ '' is a linear combination of the first k rows, and so D�k+ '' = 0. The inhomoge­ neous case reduces to the homogeneous case by (6.5). To show sufficiency, let k +I be the least positive integer such that v�•+ '' = 0 for all but finitely many n;;. 0. If k +I= I, then we are do�e, and so we may assume k ;;.I. There is an integer m;;. 0 with D�k+ '' � 0 for all n;;. m. If we had D�:' = 0 for some n0;;. m, then v�•> = 0 for all n;;. n0 by Lemma 6.73, which contradicts the definition of k +I. Therefore, D�"> * 0 for all n � m. Setting s,. = (s,., s,.+ 1, ••• ,s,.+k), we note that for n �m the vectors s,.,s,.+1, ... ,s,.+k• being the row vectors of D�k+n, are linearly dependent over F q· Since D�k) * 0, the vectors s,.,s,.+ 1, ... ,s,.+k-t are linearly independent over F •• and so s,H is a linear combination of s,.,s,.+1, ... ,s11+k-l·lt follows then by induction that each s,. with n �m is a linear combination of sm, sm+ I• •.. ,sm+k-1" The latter are k vectors in F:+ I' therefore there exists a nonzero vector (a0, a1, ••. ,a.) E r;+ 1 with a0s,.+a1s,.+1+ ··· +aksrt+k=O form�n�m+k-1. This implies or Thus, the sequence s0, s1,. .. satisfies a homogeneous linear recurrence relation of order at most m + k. 0 6.75. Theorem. The sequence s0, s1, ... in F• is a homogeneous linear recurring sequence with minimal polynomial of degree k if and only if DJ" = 0 for all r;;. k + I and k + I is the least positive integer for which this holds. Proof If a given linear recurring sequence is the zero sequence, the necessity of the condition is clear. Otherwise, we have k;;. I, and D6" = 0 for all r ;;. k + I follows since the ( k + I )st row of DJ '' is a linear combina· tion of the first k rows. Moreover, we get DJ•> * 0 from Theorem 6.51, and so the necessity of the condition is shown in all cases. Conversely, suppose the condition on the Hankel determinants is satisfied. By 11sing Lemma 6.73 and induction on n, one establishes that D�'1 = 0 for all r;;. k + I and all n;;. 0. In particular, vJ• + n = 0 for all n;;. 0, and so s0, s1, ... is a linear recurring sequence by Theorem 6.74. If its minimal polynomial has degree d, then, by what we have already shown in 6. Characterization of Linear Recurring Sequences 231 the first part, we know that DJ'' � 0 for all r ;, d + I and that d + I is the least positive integer for which this holds. It follows that d � k. 0 We note that if a homogeneous linear recurring sequence is known to have a minimal polynomial of degree k;, I, then the minimal polynomial is determined by the first 2k terms of the sequence. To see this, write down the equations (6.2) for n � 0, I, ... ,k-I, thereby obtaining a system of k linear equations for the unknown coefficients a0, a1, ... , a._, of the minimal polynomial. The determinant of this system is DJ•l, which is * 0 by Theorem 6.51. Therefore, the system can be solved uniquely. An important question is that of the actual computation of the minimal polynomial of a given homogeneous linear recurring sequence. To be sure, a method of finding the minimal polynomial was already presented in the course of the proof of Theorem 6.42. This method depends on the prior knowledge of a characteristic polynomial of the sequence and on the determination of a greatest common divisor in F.[x]. We shall now discuss a recursive algorithm (called Berlekamp-Massey algorithm) which produces the minimal polynomial after finitely many steps, provided we know an upper bound for the degree of the minimal polynomial. Let s0, s1, ... be a sequence of elements of F• with generating function G(x) � I:�_0s.x•. For j � 0, I, ... we define polynomials g/x) and h1(x) over IF•, integers m1, and elements b1 of F• as follows. Initially, we set g0(x)=!, h0(x)�x, and m0�0. (6.19) Then we proceed recursively by letting b1 be the coefficient of x' in g/x)G(x) and setting: g1+1(x) � g1(x)-bh(x), {-ml m -j+I-mj+l if b1 * 0 and mi;, 0, otherwise, if bj * 0 and mj � 0, otherwise. (6.20) If s0, s1, ... is a homogeneous linear recurring sequence with a minimal polynomial of degree k, then it turns out that g,.(x) is equal to the reciprocal minimal polynomial. Thus, the minimal polynomial m(x) itself is given by m(x)�x•g,.(!jx). If it is only known that the minimal poly­ nomial is of degree ,;;. k, then set r � l k +!-!m,.J, where lY J denotes the greatest integer ,;;. y, and the minimal polynomial m(x) is given by m(x) � x'g,.(!jx). In both cases, it is seen immediately from the algorithm that m(x) depends only on the 2k terms s0,s1, ... ,s,._1 of the sequence. 232 Linear Recurring Sequences Therefore, one may replace the generating function G ( x) in the algorithm by the polynomial 2k -I G,._,(x)� L s,x". •-0 6.76. Example. The first 8 terms of a homogeneous linear recurring sequence in F, of order ,.4 are given by 0,2,1,0,1,2,1,0. To find the minimal polynomial, we use the Berlekamp-Massey algorithm with G7(x) � 2x + x' + x4 +2x' + x6Ef3[x] in place of G ( x ). The computation is summarized in the following table. j sjlx) h1(x) mf bj 0 X 0 0 I x' I 2 2 I+ x2 2x -I I 3 I+ x + x2 2x2 0 0 4 I+ x + x2 2x3 I 2 5 I+ x + x2 +2x3 2x +2x2 +2x1 -I 2 6 I+ x1 2x2 +2x1 +2x4 0 I 7 l+x2+2x1+x4 x+x4 0 I 8 I +2x + x2 +2x1 0 Then, r = l4+ -!-1m,J � 4, and so m(x) � x4 +2x3 + x' +2x. The homo­ geneous linear recurrence relation of least order satisfied by the sequence is therefores11+4=S11+1+2s,+2+s,+1 forn=O,l,.... 0 6.77. Example. Find the homogeneous linear recurring sequence in f2 of least order whose first 8 terms are 1,1,0,0,1,0,1,1. We use the Berlekamp­ Massey algorithm with G1(x)�l+x +x4+x6+x 7Ef2[x] in place of G(x). The computation is summarized in the following table. j gj(x) hjCx) mf bj 0 X 0 I I I+ X X 0 0 2 l+x x' I I 3 1 + x + x2 x + x2 -I I 4 I x2 + x3 0 I 5 l+x2+x3 X 0 0 6 l+x2+x1 x' I 0 7 l+x2+x1 x' 2 0 8 l+x2+x3 3 6. Characterization of Linear Recurring Sequences 233 Then, r � [4+ i -im,J � 3, and so m(x) � x3 + x + 1. Therefore, the given terms form the initial segment of a homogeneous linear recurring sequence s0, s1, ••• satisfying sn+ 3 = sn+ 1 + S17 for n = 0, I, ... , and no such sequence of lower order with these initial terms exists. D We shall now prove, in general, that the Berlekamp"Massey algorithm yields the minimal polynomial after the indicated number of steps. To this end, we define auxiliary polynomials u1( x) and v1( x) over IF q recursively by setting u0(x)�O and v0(x)�-l, and then for j � 0, 1, ... , u1+ 1(x) � u1(x)-h1v1(x), -{h1-1xu1(x) ifb1*0andm1;;,0, v1+1(x)-( ) xv1 x otherwise. We claim that for each};;, 0 we have (6.21) (6.22) deg(g1(x)) d(J+ 1-mJ) and deg(h,(x)) d(i+2+m1). (6.23) This is obvious for j � 0 because of the initial conditions in (6.19), and assuming the inequalities to be shown for some j;;, 0, we get from (6.20) in the case where bj '* 0 and m j � 0, deg( g;+ 1 (x)).;; max( deg( g1(x) ),deg(h 1( x))) .;; Hi +2+ m1) � H j +2-m1+ 1 ). Otherwise, deg(g;+1(x)) <>Hi+ 1-m1) � Hi+2-m1+ 1). The same distinction of cases proves the second inequality in (6.23). A similar inductive argument shows that for each}� 0 we have The auxiliary polynomials u1(x) and v/x) are related to the polynomials g1(x) and h1(x) occurring in the algorithm by means of the following congruences, valid foi each j � 0: g;(x )G(x) = u1(x )+ b1ximod xJ+ 1, h1(x )G( x) = v1 (x) + x'mod xf+ 1• (6.25) (6.26) Both (6.25) and (6.26) are true for j � 0 because of (6.19), (6.21), and the .-l�f:-:.:�- �f 1.. A_, .• _; __ •L-• L-•L --- -----·- --� 1----- L ---_1_ ---- -"- 234 Linear Recurring Sequences j � 0, we get g1+ 1 (x )G(x) � s;( x)G(x )-b1h1(x )G(x) == u1( x )+ b1x1 + c1+ 1xi+ 1-b1( v1(x )+xi+ d1+ 1xi+ 1) ==u-(x)+e-xi+1modxi+2 rt-l ; + 1 with suitable coefficients cJ+l•dJ+I•eJ+!EIFq. Since \m,\�). as is seen easily by induction, we have deg(u1+ 1(x)).; j from (6.24). Therefore, e + 1 is "+ 1 J the coeHicient of x1 in g;+1(x)G(x), and so eJ+I =b)+ I· The induction step for (6.26) is carried out similarly. Next, one establishes by a straightforward induction argument that h1(x)u1(x)-g1(x)v1(x)�x1 foreachj;.O. (6.27) Now let s(x) and u(x) be polynomials over F• with s(x)G(x)�u(x) and s(O) �I. Then by (6.26), h1( x) u(x )-s(x) v1(x) � s(x )( h1(x )G( x)-v1(x )) = s(x)xi �xi mod xi+ 1, and so for some �(x) E f•[x] we have h1(x)u(x)-s(x)v,(x) � x'�(x) with �(0) �I. (6.28) Similarly, one uses (6.25) to show that there exists lj(x) E IF'q(x] with g1(x)u(x)-s(x)u1(x) � xilj(x). (6.29) Now suppose the minimal polynomial m(x) of the given homoge­ neous linear recurring sequence satisfies deg(m(x)).; k, and let s(x) be the reciprocal minimal polynomial. Then s(O) �I and deg(s(x)).; k, and from (6.15) we know that there exists u(x) E F•[x] with s(x)G(x) � u(x) and deg(u(x)).; deg(m(x))-1.; k -I. Consider (6.28) with)� 2k. Using (6.23) and (6.24), we obtain deg( h2k(x )u(x )) .; 1{2k +2+ m,. )+ k -l � 2k + ):m2k and deg(s(x) v,. (x )) .; k + J:(2k + m2k) � 2k + ):m2k, and so deg(h2k (x) u(x )-s(x) v2k(x)).; 2k + ):m2k. On the other hand, deg( h2k( x )u(x)-s(x) v,.( x )) � deg(x,.u,.(x l) ;;> 2k, and these inequalities are only compatible if m2k ;;> 0. Using again (6.23) and (6.24), one verifies that deg(g2k(x)u(x)) and deg(s(x)u2k(x)) are both 7. Distribution Properties of Linear Recurring Sequences 235 .;; 2k-J:-J:m,k, hence (6.29) shows that deg( x2kV,k(x )) = deg(g2k(x) u(x) -s(x )u,k (x )) < 2k. But this is only possible if V,.(x) is the zero polynomial. Consequently, (6.29) yields g,.( x )u(x) = s(x )u2k(x), and multiplying (6.28) for j = 2k by g2k(x) leads to h2k(x )g2k (x) u(x)-s(x )g2k(x) v,. (x) = s(x )( h2k(x) "'* (x)-g,.(x) v2k (x )) = x2kU2k(x )g2k (x ). Together with (6.27), we get s(x)=U2k(x)g,.(x), which implies u(x)= U2k(x)u,.(x). Since s(x) is the reciprocal minimal polynomial, it follows from the second part of Theorem 6.40 that s(x) and u(x) are relatively prime. Because of this fact, U,.(x) must be a constant polynomial, and since U,.(O) =I by (6.28), we actually have U2k(x) =I. Therefore s(x) = g,.(x), and as a by-product we obtain u(x) = u,k(x). If deg(m(x)) = k, then m(x)=xks(�)=xkg2k(�). as we claimed earlier. If deg(m(x)) = t .;; k, then we have s(x) = g2,(x), u(x) = u2,(x), and m2,;,. 0. Clearly, max(deg(s(x)), l +deg(u(x))).;; t, and the second part of Theorem 6.40 implies that t = max( deg( s ( x)), I + deg( u ( x))). It follows then from (6.23) and (6.24) that t = max(deg(g2,(x)), I +deg( u2,(x))).;; t + J: -1m2, and so m2, = 0 or I. Furthermore, we note that g;(x) = s(x) and b1 = 0 for all j;,. 2t, so that m; = m2, + j-2t for all j;,. 2t by the definition of m ;· Settingj=2k, we obtain t=k+-im2,--im2k, and since m2,=0 or 1, we conclude that Therefore, m(x)=x's(�) =x'g2k(� ). in accordance with our claim. 7. DISTRIBUTION PROPERTIES OF LINEAR RECURRING SEQUENCES We are interested in the number of occurrences of a given element of Fq in either the full period or parts of the period of a linear recurring sequence in 236 Linear Recurring Sequences f q· In order to provide general information on this question, we first carry out a detailed study of exponential sums that involve linear recurring sequences. It will then become apparent that in the case of linear recurring sequences for which the least period is large, the elements of the underlying finite field appear about equally often in the full period and also in large segments of the full period. Let s0, s1, •.. be a kth-order linear recurring sequence in F q satisfying (6.1), let r be its least period and n0 its preperiod, so that s.,+, = s., for n � n0. With this sequence we associate a positive integer R in the following way. Consider the impulse response sequence d0, d1, ... satisfying (6.6), let r1 be its least period and n1 its preperiod; then we set R = r1 + n1• Of course, R depends only on the linear recurrence relation (6.1) and not on the specific form of the sequence. If s0, s11 .•• is a homogeneous linear recurring sequence with characteristic polynomial f(x) E F .Ix ], then r1 = ord(f(x )), and if in additionf(O)"' 0, then R = ord(f(x)), as implied by Theorem 6.27. By the same theorem, r divides r1 and r � R in the homogeneous case. In the exponential sums to be considered, we use additive characters of IF q as discussed in Chapter 5 and weights defined in terms of the function e(t) = e2"'' for real t. 6.78. Theorem. Let s0, s1, ... be a kth-order linear recurring se­ quence in IF• with least period rand preperiod n0, and let R be the positive integer introduced above. Let x be a nontrivial additive character of IF q· Then for every integer h we have \d,-1 (h l\ 1/2 "�" x(s,)e -f-._ ( �) qk/2 In particular, we have for all u > n0• \":��1x(s,)\._ (�('q•/2 forallu'3n0• (6.30) (6.31) Proof By changing the initial state vector from s0 to s •. which does not affect the upper bound in (6.30), we may assume, without loss of generality, that the sequence s0, s1, ... is periodic and that u = 0. For a column vectorb=(b0,b1, ... ,b,_1)T in F: and an integer h. we set o(b; h)= o(b0, b1, ... ,b,_1; h) Since the general term of this sum has period r as a function of n, we can write 7. Distribution Properties of Linear Recurring Sequences Using the linear recurrence relation (6.1), we get lo(b; h )I� I' I:' x( bos .. + I+ b,s.,+2 + ... + b,_,s,+k-1 +-b,_,aos .. n-O 237 +bk-1a1sll+l+ ··· +bk-lak-lsn+k-1 +bk-la)e(hrn)l �1 't' x(b,_,aos .. +(bo+b,_,a,)s .. +, + ... n-O +(b,_, +b,_,a,_,)s.,+k-J)e( hrn ll � lo(b,_1a0, b0 + b,_1a1, ... ,b,_2 + b,_,a,_1; h )I. This identity can be written in the form I o (b; h )I � I o ( Ab; h )I. where A is the matrix in (6.3). It follows by induction that lo(b;h)l�lo(Ajb;h)l forallj;>O. (6.32) Let d be the column vector d � (l,O, ... ,O)T in IF:. and let d0,d1, .•. be the state vectors of the impulse response sequence d0, d" ... satisfying (6.6). Then we claim that two state vectors dm and d, are identical if and only if A"'d � A"d. For if dm �d.,, then Amd � A"d follows from Lemma 6.15. On the other hand, if Amd � A"d, then· Am+jd � A"+jd. and so Am( Ajd) � A"(Ajd), for allj;>O. But since the vectors d, Ad,A2d, ... ,A'-'d form a basis for the vector space F; over IF q• we get A'"= A'', which implies d'" = d, by Lemma 6.15. The distinct vectors in the sequence d0,d1, ... are exactly given by d0,d1, ... ,d._1. Therefore, by what we have just shown, the distinct vectors among d, Ad, A2d, ... are exactly given by d, Ad, ... ,A•-'d. Using (6.32), we get R-I Rla(d;h)l2� L lo(Ajd;h)I2.;;Lio(b;h)l2• (6.33) j=O b where the last sum is taken over all column vectors bin F;. Now Llo(b; h)l2 � Lo(b; h) o(b; h) b b '-I L L x(bo(sm -s.,)+b,(sm+J-s .. +,) bo,b1, .,b�_1Ef" m,n=O + ... +b,_,(sm+k-1-s.,+k-l))e( h(m,-n)) � 'I;' e( h(mr-n)) (6.34) m,n-0 238 Linear Recurring Sequences IJo,bl> .. ,bk_1Ef01 ·x(bk-l(sm+k-l-s•+k-l)) � 'i:_l e(h(m,-nl)( L x(bo(sm-sJ))··· m,n�O boEF11 We note that for c E F, we have L x(hc) � { 0 hEF.., q if C* 0, if c�o. according to (5.9). Therefore, in the last expression in (6.34) one only gets a contribution from those ordered pairs (m, n) for which simultaneously s'" = s", ... ,sm+k-1 = sn-+k-t· But since 0 � m, n � r-I, this is only possible form� n. It follows that Llo(b; h)\2 � rq•. b By combining this with (6.33), we arrive at \o(d; h)\ "i ( � t' qk/2, which proves (6.30). The inequality (6.31) results from (6.30) by setting h�O. o 6.79. Remark. Let x be a nontrivial additive character of IF, and let 1/> be an arhitrary multiplicative character ofF q· Then the Gaussian sum G(l/>.x)� L ,P(c)x(c) can be considered as a special case of the sum in (6.30). To see this, let g be a primitive element of IF q and introduce the first-order linear recurring sequence s0,s1, .•. in !Fq with s0=1 and sn+1=gsn for n=O,l, .... Then r � R � q -I and n0 � 0. We note that ,P(g) � e(h/r) for some integer h. Thus we can write r -I r-I G( 1/>. x) � .�/( g" )I/> ( g") � .�/(s. )e ( h;). If .p is nontrivial, then in this special case both sides of (6.30) are identical according to (5.15). 0 The sums in Theorem 6.78 are extended over a full period of the given linear recurring sequence. An estimate for character sums over seg- 7. Di�tribution Properties of Linear Recurring Sequences 239 ments of the period can be deduced from this result. We need the following auxiliary inequality. 6.80. Lemma. For any positive integers r and N we have ·-I�N-I (h")l 2 2 L L e _I}_ <-rlogr+-5r+N. h�o J=O r '" Proof The inequality is trivial for r � l. For r ;. 2 we have IN-I (hjll le(hNir}-11 1 1�0 e --;-� ldhlr}-11 .;;; sinwllhlrll � esc wll � II for l .;;; h .;;; r -l, (6.35) where 11111 denotes the absolute distance from the real number t to the nearest integer. It follows that •-I N-1 (h") •-1 llhll [•/2J h h�O 1�0 e ; .;;; h�l cscw -; + N.;;; 2 h�l csc7 + N. By comparing sums with integrals, we obtain l•/2J wh " 1'12J wh " · · Jl•/2J wx L esc-= esc-+ L esc-� esc-+ csc-dx h-1 r r h=2 r r I r " r J•/2 �esc-+-csctdt r '1T wjr w r w w r 2r �esc-+ -logcot- .;;; esc-+ -log-. r w 2r r w w (6.36) For r ;. 6 we have ("I r)-1 sin(" 1 r) ;. ( "16)-1 sin(" 16 ), hence sin(" I r) ;. 31r. This implies and so 1'12J wh l (l l ") L esc-.;;; -rlogr + ---log-r 11-1 r '" 3 '" 2 for r � 6. l•/2J wh l 1 L csc-<-rlogr+-r r " 5 forr�6. h=l This inequality is easily checked for r � 3, 4, and 5, so that (6.35) holds for r;. 3 in view of (6.36). For r � 2 the inequality (6.35) is shown by inspec­ tioo. 0 240 Linear Recurring Sequences 6.81. Theorem. Let s0, s1,... be a kth-order linear recurring se­ quence in F,, and let r, n0, and R be as in Theorem 6.78. Then, for any nontrivial additive character x of IF q we have 1-+N-l I 1/2 (2 2 N) "�" x(s,) <(�) q'12 ;logr+5+-;-foru�n0andl"'N,.J. Proof We start from the identity •+N-l •+,-1 N-l 1 ,_, (h(n-u-j)) L x(s,)� L x(s..) L-; L e r for 1,. N,. r, n=u n�u 1-0 h-0 which is valid since the sum over j is 1 for u .:s;:; n .:s;:; u + N-1 and 0 for u + N � n � u + r -l. Rearranging terms, we get d N-I l '-I ( N-I ( _ h ( U + ) ) ) ("+'-I ( hn ) ) L x(s,)�-; L L e r 1 L x(s,)e--;-, n=u h-0 ,�o n-u and so by (6.30), [ x(s.l ,. -[ [ e [ x(s.Je -I u+ N- 1 I 1 '-' IN-I ( _ h ( u + j) ) I"+'-1 ( hn ) I 11-u 'h=O ;-o ' 11=u ' ,. .!. (!...) 112 q'12 '"[' IN [' e ( hj) I· r R h-0 J-0 r An application of Lemma 6.80 yields the desired inequality. D It should be noted that the inequalities in Theorems 6.78 and 6.81 are only of interest if the least period r of s0, s1, ••• is sufficiently large. For small r, these results are actually weaker than the trivial estimate I ": f 1 x ( s.) 1,. N for 1 ,. N ,. r. In order to obtain nontrivial statements. r should be somewhat larger than qk/2_ Let s0, s1 •. :. be a linear recurring sequence in IFq with least period r and preperiod n0. For b E F, we denote by Z( b) the number of n, n0,. n ,. n0 + r -1, with s., �b. Therefore Z(b) is the number of occurrences of bin a full period of the linear recurring sequence. If s0• s1 •••• is a kth-order maximal period sequence, then Z(b) can be determined explicitly. We have r � q'-1 and n0 � 0 according to Theorem 6.33, and so the state vectors s0,s1 ••.• ,s,_1 of the sequence run exactly through all nonzero vectors in IF:. Consequently, Z(b) is equal to the number of nonzero vectors in F: that have b as a first coordinate. Elementary counting arguments show then that Z(b) � q,_, forb"' 0 and 7. Distribution Proptrties of Linear Recurring Sequences 241 Z(O) � qk-J-I. Therefore, up to a slight aberration for the zero element, the elements of f • occur equally often in a full period of a maximal period sequence. In the general case, one cannot expect such an equitable distribution of elements. One may, however, estimate the deviation between the actual number of occurrences and the ideal number rjq. If r is sufficiently large, then this deviation is comparatively small. 6.82. Theorem. Let s0, s1, ••• be a kth-order linear recurring se­ quence in F• with least period r, and let R be as in Theorem 6.78. Then, for any b E IF • we have Proof For given bE F •• let the real-valued function �. on F • be defined by �.(b)� I and �.(c)� 0 for c"' b. Because of (5.10), the function �. can be represented in the form I �. (c) � -LX ( c -b) for all c E IF q, q X where the sum is extended over all additive characters x of IF •. It follows that n0+r-l n0+r-l 1 .. Z(b)� L �.(s.)� L -[x(s,-b) n-n0 n-no q x I no+ r-I �-[x(b) L x(s,). q X n-n0 By separating the contribution from the trivial additive character of F • and using an asterisk to indicate the deletion of this character from the range of summation, we get I n0+r-l Z(b)-��-[*x(b) L x(s,). q q X n =no Thus, by using (6.31), we obtain 1 n0+r-l IZ(b)-��.;-[* L x(s,) q q X n = n0 since there are q-I nontrivial additive characters of IF q· D 6.83. Corollmy. Let s0, sJ>··· be a homogeneous linear recurring 242 Linear Recurring Sequences sequence in IF • with least period r whose minimal polynomial m ( x) E IF .I x] has degree k;. I and satisfies m(O) * 0. Then, for every bE IF• we have Proof We haver� ord(m(x)) according to Theorem 6.44. Further­ more, R � ord(m(x)) by a remark preceding Theorem 6.78, and Theorem 6.82 yields the desired result. 0 If the linear recurring sequence has an irreducible minimal poly­ nomial, then an alternative method based on Gaussian sums leads to somewhat better estimates. In the subsequent proof, we shall use the formulas for Gaussian sums in Theorem 5.11. 6.84. Theorem. Let s0, s1, ... be a homogeneous linear recurring sequence in IF • with least period r. Suppose the minimal polynomial m ( x) of the sequence is irreducible over F •• has degree k, and satisfies m(O) * 0. Let h be the least common multiple of r and q -I. Then, and Z(O)- .,.; 1------q I I (q'-'-l)rl ( l)(r r ) , 2 q'-I q h q'-I Z(b)---.,.; ----+-=-ql/2 q<k/2)-l forb#'O. I q'-'r I ( r r h r ) q'-1 h q'-1 h (6.37) (6.38) Proof Set K � IF•, and let F be the splitting field of m(x) over K. Let a be a fixed root of m ( x) in F; then a* 0 because of m (0) * 0. By Theorem 6.24, there exists 0 E F such that s, � TrF;K(Oa") for n � 0, !,.... (6.39) We clearly have 0 * 0. Let X' be the canonical additive character of K. Then, for any given bE K, the character relation (5.9) yields I { I -L X'( c( b-s,)) � 0 q CE K ifsn=b, if s, -=1:-b, and so, together with (6.39), l r-I Z(b) �-L L "A'(bc)X'(TrF;K(-cOa")). q n=OcEK If A denotes the canonical additive character of F, then X' and A are related by "A'(TrF;K( /3 )) � X(/3) for all /3 E F (see (5.7)). Therefore, 7. Distribution Properties of Linear Recurring Sequences Now by (5.17), Z(b) �_I_ LA'( be) 'i_:1 X(cOa") q cEK n=O 1 r-I �!:+- L A'(bc) L X(cOa"). q q cEK• n-0 X(p)�-,- 1-L;G(,f.X).y(fl) forfJEF*, q -I ,_ 243 (6.40) where the sum is extended over all multiplicative characters .Y of F. For c E K* it follows that , -1 , - 1 L X(cOa")�-,-1-L L;G(f,X),Y(cO a") 11'"'0 q-1,.=0-.t- 1 , - 1 �-,-L:.Y (cO)G(f,X) L ,Y(a)". q-11/- n=O The inner sum in the last expression is a finite geometric series that vanishes if ,Y( a)"' I. because of ,Y( a)'� ,Y( a')� ,Y(l) �I. Therefore. we only have to sum over the set J of those characters .Y for which .Y (a) � I, and so '-I L X(cOa") � +-L ,Y(cO)G(f. X). n-0 q-11/-E} ... Substituting this in (6.40), we get Z(b)�!:+ ( ; ) L: A'(bc) L: ,Y(cO)G(f.X) q q q -J ,EK" "E) �!:+ ( : ) L ,Y(O)G(f,X) L ,Y(c)A'(bc). q q q -1 1¥ E j c E K* If we consider the restriction .Y' of .Y to K*. then the inner sum may be viewed as a Gaussian sum inK with an additive character A/,(c) �A'( be) for cE K. Thus, Z(b)�!:+ ( : ) L ,Y(O)G(f,X)G( ,Y',A/,). (6.41) q q q -j "E) Now let b � 0. Then A/, is the trivial additive character of K, and so the Gaussian sum G( Y,.', �b) vanishes unless Y,.' is trivial, in which case G( ,Y'. A/,)� q-I. Consequently, it suffices to extend the sum in (6.41) over the set A of characters .Y for which .Y (a) � I and ,Y' is trivial, so that ( r (q-l)r >:' (--) zo)�-+ (' ) L..>i-(O)G,Y,A. q q q -J "EA 244 Linear Recurring Sequences The trivial multiplicativ e character contributes -1 to the sum, hence we get Z(O)-(q'�'-l)r � (q�l)r L\1-(0)G(f.X), q -1 q(q -1) o/EA where the asterisk indicates that the trivial multiplica tive character is deleted from the range of summation. Since� is nontrivial, we have I G( f, X) I � q'l'· for every nontrivial .f, and so IZ(O)-(q'-'-l)rl._ (q-l)r (IAI-l)q'l'- (6.42) q'-1 q(q'-1) Let H be the smallest subgroup ofF* containing a and K*. The element a has order r in the cyclic group F*, therefore IHI � h, the least common multiple of rand q -1. Furthermore, we have .f E A if and only if .f(fJ) � 1 for all fJ E H. In other words, A is the annihilator of H in ( F*) A (see p. 165), and so IAI� IF*I � q'-1 IHI h (6.43) by Theorem 5.6. The inequality (6.37) follows now from (6.42) and (6.43). For b * 0, we go back to (6.41) and note first that the additive character�/, is then nontrivial. Therefore, the trivial multiplicative character contributes 1 to the sum in (6.41), so that we can write qk-1, , • -Z(b)--,-� ( k ) L ,P(O)G(,P.X)G(,P'.��). q-1 qq-l;,u Now G(.f', �/,) = -1 if,P' is trivial and IG(.f', �/,)I= q'l' if ,P' is nontrivial, which implies IZ( b)-q'-'r 1---'-(lA I-1 + (111-IA I) q'i') q(k!'l-l. q'-1 q'-1 Since J is the annihilator in ( F*) A of the subgroup of F* generated b)l a, we have 111 � (q' -1)/r by Theorem 5.6. This is combined with (6.43) to complete the proof of (6.38). 0 One can also obtain results about the distribution of elements in parts of the period. Let s0, s 1, ••• be an arbitrary linear recurring sequence in IF• with least period r and preperiod n0. For bEIFq, for N0;>n0 and 1._ N ._ r, let Z(b; N0, N) be the number of n, N0 ._ n ._ N0 + N -1, with sn =b. 6.85. Theorem. Let s0, s1, ... be a kth-order linear recurring se­ quence in F q with least period rand preperiod n0, and let R be as in Theorem 6. 78. Then, for any b E IF q we have Exercises 245 lz(b; N0, N)-�I.; ( 1-� )( � (2 q•l'( ;logr+ � + �) for N0? n0 and I� N � r. Proof Proceeding as in the proof of Theorem 6.82 and using the same notation as there, we arrive at the identity N I * N0+N-l Z(b;N0,N)--�-L:x(b) L: x(s.). q qX n-N0 On the basis of Theorem 6.81 we obtain then I Nl I • N,+N-1 Z(b;N0,N)-- .;-L: L: x(s,) q qX n=N0 .; (I -�) ( � ) 112 q•12 (;log r + � + �), since there are q-I nontrivial additive characters ofF q· 0 The method in the proof of Theorem 6.84 can also be adapted to produce results on the distribution of elements in parts of the period (compare with Exercises 6.69, 6.70, and 6.71). EXERCISES 6.1. Design a feedback shift register implementing the linear recurrence relation sn+5 = sn+4-sn+J-sn+ I+ Sn, n = 0, I, ... , in IF]. 6.2. Design a feedback shift register implementing the linear recurrence relation sn+? = 3sn+S -2sn+ 4 + sn+J +2sn +I, n = 0,1, ... , in F7. 6.3. Let r be a period of the ultimately periodic sequence s0, s1, ••• and let n0 be the least nonnegative integer such that sn+r = sn for all n? n0. Prove that n0 is equal to the preperiod of the sequence. 6.4. Determine the order of the matrix A� [ � 0 0 I 0 0 0 0 I in the general linear group GL(4,F3). -:) -I 6.5. Obtain the results of Example 6.18 by the methods of Section 5. 6.6. Use (6.8) to give an explicit formula for the terms of the lin­ ear recurring sequence in f3 with s0 = s1 =I, s2 = 0, and sn+J = -sn+l +s11 forn=O,l, .... 6.7. Use the result in Remark 6.23 to give an explicit formula for the 246 Linear Recurring Sequences terms of the linear recurring sequence in IF4 with s0 = s1 = s2 = 0, s3=1, and sn+4=asn+3 +sn+1+as11 for n=O,l, ... , where a is a primitive element of IF 4. 6.8. Prove that the terms s. given by the formula in Remark 6.23 satisfy the homogeneous linear recurrence relation with characteristic poly­ nomialf(x). 6.9. Prove the result in Remark 6.23 for the case where e,..; 2 for i = 1,2, ... ,m and e; =I if a;=O. 6.10. Represent the elements of the linear recurring sequence in F2 with s0=0, s1=s2=1, and sn+3=sn+2+s11 for n=O,l, ... in terms of a suitable trace function. 6.11. Prove Lemma 6.26 by using linear recurring sequences. 6.12. Determine the least period of the impulse response sequence in IF2 satisfying the linear recurrence relation sn+? = sn+6 + sn+S + sn+ 1 + S11 for n = 0, 1, .... 6.13. Calculate the least period of the impulse response sequence associ­ ated with the linear recurrence relations,,+ 10 = S11+1 + s,.+2 + sn+ 1 + S11 in F2. 6.14. Prove Theorem 6.27 by using generating functions. 6.15. Find a linear recurring sequence of least order m IF2 whose least period is 21. 6.16. Find a linear recurring sequence of least order m IF2 whose least period is 24. 6.17. Let r be the least period of the Fibonacci sequence in !F.-that is, of the sequence with s0 = 0, s 1 = I, and sn+ 2 = s,.+ 1 + s,. for n = 0, I, .... Let p be the characteristic of F q· Prove that r � 20 if p � 5, that r divides p-1 if p = ± 1 modS, and that r divides p2-1 in all other cases. 6.18. Construct a maximal period sequence in IF 3 of least period 80. 6.19. An (m, k) de Bruijn sequence is a finite sequence s0, s1, ••• ,sN-! with N � m' terms from a set of m elements such that the k-tuples (sn.sn+l•···•sn+Jr-d, n=O.l, .... N-1, with subscripts considered modulo N are all different. Prove that if d0, d1, ••• is a kth-order impulse response sequence and maximal period sequence in F q• then s0�0,s. �d._1 for l..;n..;q'-1 yields a (q,k) de Bruijn se­ quence. 6.20. Construct a (2, 5) de Bruijn sequence. 6.21. Let B(x) � 2-x + x3 E IF7[x]. Calculate the first six nonzero terms of the formal power series 1/B(x). 6.22. Let 00 A(x)�-1-x+x2, B(x)� L (-l)"x"EF3[[x]]. n�O Exercises 247 Calculate the first five nonzero terms of the formal power series A(x)/B(x). 6.23. Consider the linear recurring sequence in IF3 with s0 = s1 = s2 =I, s3=s4= -1, and sn+5=sn+4 +sn+2-sn+1+sn for n=O,l, .... Represent the generating function of the sequence in the form (6.15). 6.24. Calculate the first eight terms of the impulse response sequence associated with the linear recurrence relation sn+5 = sn+J + sn+2 + sn in IF 2 by long division. 6.25. Let s0, s1 •••• be a homogeneous linear recurring sequence in F q· Prove that the set of all polynomials /(x) � akxk + · · · + a1x + a0 E IF q[x] such that aksn+k + · · · + a1sn+ 1 + a0s, = 0 for n = 0, I, ... forms an ideal of Fq(x]. Thus show the existence of a uniquely determined minimal polynomial of the sequence. 6.26. Consider the linear recurring sequence in IF2 with s0 = s3 = s4 = s5 = s6=0, sl=s2=s7=1. and sn+8=sn+7+sn+6+sn+5+s, for n= 0. I, .... Use the method in the proof of Theorem 6.42 to determine the minimal polynomial of the sequence. 6.27. Consider the linear recurring sequence in IF5 with s0 = s1 = s2 =I, s3=-l, and s,+4=3sn +2-sn+l+sn for n=O,I, .... Use the method in the proof of Theorem 6.42 to determine the minimal polynomial of the sequence. 6.28. Prove that a homogeneous linear recurring sequence in a finite field is periodic if and only if its minimal polynomial rn(x) satisfies m(O)"' 0. 6.29. Given a homogeneous linear recurring sequence in a finite field with minimal polynomial m ( x ), prove that the preperiod of the sequence is equal to the multiplicity of 0 as a root of m(x). 6.30. Prove Corollary 6.52 by using the construction of the minimal polynomial in the proof of Theorem 6.42. 6.31. Use the criterion in Theorem 6.51 to determine the minimal polynomial of the linear recurring sequence in F2 with sn+6 = sn+J + sn+2+s"+1+sn for n=O, 1, ... and initial state vector (1, 1, 1, 0, 0, 1). 6.32. Find the least period of the linear recurring sequence in Exercise 6.26. 6.33. Find the least period of the linear recurring sequence m Exercise 6.27. 6.34. Find the least period of the linear recurring sequence in IF 2 with s0 = s1 = s2 = s6 = s7 = 0, s3 = s4 = s5 = s8 = 1, and sn+9 = sn+7 +sn+4 +s,+l +sn for n = 0, 1, .... 6.35. Find the least period of the linear recurring sequence in F3. with So= s1 = 1, sl = s3 = 0, s4 =-I, and Sn+5 = sn+4-s,.+-J + sn+2 + sn for n � 0, I, .... 6.36. Find the least period of the linear recurring sequence in IF 3 with 248 6.37. 6.38. 6.39. 6.40. 6.41. 6.42. 6.43. 6.44. 6.45. 6.46. 6.47. Linear Recurring Sequences S11+4=sn+3+sn+2-s"-l for n=O.I, ... and initial state vector (0, -1.1,0). Prove that a k th-order linear recurring sequence s0, s1, ... in IF q has least period q• exactly in the following cases: (a) k=l,qprime,s.+1=s.+aforn=O.I, ... withaEIF;; (b) k = 2, q = 2, s.+, = s. +I for n = 0.1. ... . Given a homogeneous linear recurring sequence in F q with a noncon­ stant minimal polynomial m(x) E IFq[x] whose roots are nonzero and simple, prove that the least period of the sequence is equal to the least positive integer r such that a'= I for all roots a of m (x). Prove: if the homogeneous linear recurring sequence o in F q has minimal polynomial f(x) E IF q[x] with deg(f(x)) = n;;. I, then every sequence in S(f(x)) can be expressed uniquely as a linear combina­ tion of o = o<01 and the shifted sequences o<ll, o(2\ ... ,o<n-l) with coefficients in F q· Let f1(x), ... ,f.(x) be nonconstan t monic polynomials over Fq that are pairwise relatively prime. Prove that S(f1(x) · · · f,(x)) is the direct sum of the linear subs paces S(/1 (x )), ... , S(f.(x)). Let s0, sl' ... be a homogeneous linear recurring sequence in K = F q with characteristic polynomial f(x) = f1(x) · · · f,(x ), where the [,(x) are distinct monic irreducible polynomials over K. Fori= l, ... ,r, let a, be a fixed root of [;(x) in its splitting field F; over K. Prove that there exist uniquely determined elements 81 E F1, ••• ,8, E F, such that s. = TrF,;K(81al)+ · · · +TrF,;K(8,.a�) for n = 0, 1, .... With the notation of Exercise 6.41, prove that the sequence s0, s1, ••• has f( x) as its minimal polynomial if and only if 81"' 0 for I .;. i .;. r. Thus show that the number of sequences in S(f(x)) that havef(x) as minimal polynomial is given by (q••-l)···(q•'-1), where k,=deg([;(x)) for I.;.i.;.r. Let a1 and a2 be the impulse response sequences in F2 associated with the linear recurrence relations sn+6 = sn+J + S11(n = 0,1, ... ) and sn+J = s. + 1 + s.(n = 0, I, ... ), respectiv ely. Find the least period of a1 + a2. Let o1 be the linear recurring sequence in 0:3 with sn+J = sn+l­ s.+ 1 -s. for n = 0, I, ... and initial state vector (0, I, 0), and let a2 be the linear recurring sequence in F3 with sn+S =-sn+J-sn+l + sn for n = 0, 1, ... and initial state vector (1, I, 1.0, 1). Use the method of Example 6.58 to determine the minimal polynomial of the sum sequence o1 + o2• Find the least period of the sum sequence in Exercise 6.44. Given a homogeneo us linear recurring sequence in IF2 with minimal polynomial x6 + x' + x4 +IE F2[x], determine the minimal poly­ nomial of its binary complement. Let f(x) = x' + x1 + x4 + x' + x2 + x +IE F2[x]. Determine the lea.'>t nericxh of .'>eauences from S( (( x n and the numher of .'>e- Exercises 249 quences attaining each possible least period. 6.48. Let l(x) � (x + I)'(x3 -x +I) E F3[x]. Determine the least periods of sequences from S(/(x)) and the number of sequences attaining each possible least period. 6.49. Let I( x) � x5 -2x4-x2-I E F5[x ]. Determine the least periods of sequences from S(/(x)) and the number of sequences attaining each possible least period. 6.50. Find a monic polynomi al g(x) E F3[x] such that S(x + I) S(x2 + x-I) S(x2 -x -I) � S( g( x)). 6.51. Find a monic polynomi al g(x) E F2[x] such that S(x2+x+l)S(x5+x4+l)�S(g(x)). 6.52. For odd q determine a monic g(x) E IF,[x] for which s((x-1)2)S((x-1)2) � S(g(x)). What is the situation for even q? 6.53. Prove that I V(gh)�(f V g)(/ V h) for nonconstant polynomials 1. g, hE IF,[x], provided the two factors on. the right-hand side are relatively prime. 6.54. Consider the impulse response sequence in F2 associated with the linear recurrence relation 511+4 = sn+Z + 511, n = 0, I, ... , and the lin- ear recurring sequence in F2 witl;l 511+4 = S11, n = 0,1, ... , and initial state vector (0, I, I, 1). Use these sequences to show that there is no analog of Theorem 6.59 for multiplication of sequences. 6.55. For r EN and IE IF ,[x] with deg(/) > 0, let o,(/) be the sum of the r th powers of the distinct roots of f. Prove that o,(f V g)� o,(/)o,(g) for nonconstant polynomials f, g E IF,[x], provided that the number of distinct roots of I V g is equal to the product of the numbers of distinct roots of I and g, respectively. 6.56. Let s0, s1, ... be an arbitrary sequence in IF,, and let n;;. 0 and r;;. I be integers. Prove that if both Hankel determinants D�:l2 and D�r+l> are 0, then also D�:l1 = 0. 6.57. Prove that the sequence s0, s1, ... in F9 is a homogeneous linear recurring sequence with minimal polynomial of degree k if and only if D�k+ 11 � 0 for all n;;. 0 and k +I is the least positive integer for which this holds. 6.58. Give a complete proof for the second inequality in (6.23). 6.59. Prove the inequalities in (6.24). 6.60. Give a complete proof for (6.26). 6.61. Prove (6.27). 6.62. The first 10 terms of a homogeneous linear recurring sequence in F2 of order.,; 5 are given by 0,1,1,0,0.0,0,1, I. I. Determine its minimal polynomial by the Berlekamp-Massey algorithm. 6.63. The first R te.rm� nf ;'! hnmnoP_nPnno;: linf"�r rPrnrrina o.:f"rmPnr•P in � _.,.( 250 Linear Recurring Sequences order .;; 4 are given by 2, I, 0, I, -2, 0, -2, - I. Determine its minimal polynomial by the Berlekamp-Massey algorithm. 6.64. The first I 0 terms of a homogeneous linear recurring sequence in IF 3 of order .;; 5 are given by I, -1,0, -l,O,O,O,O, 1,0. Determine its minimal polynomial by the Berlekamp-Massey algorithm. 6.65. Find the homogeneous linear recurring sequence in F 5 of least order whose first 10 terms are 2,0, -I, -2,0,0, -2,2, -I, -2. 6.66. Suppose the conditions of Theorem 6.78 hold and assume in addition that the characteristic polynomial f(x) of the sequence s0,s1, ... satisfies /(0)"' 0. Establish the following improvement of (6.31): I" I \(s.,)l.;; (; (' ( q'-r) 112 for all u > 0. (Hint: Note that b � 0 can be excluded in (6.33).) 6.67. Suppose the conditions of Theorem 6.84 hold, let r be a multiple of (q'-1)/(q-1) and let (q'-I)jrand k be relatively prime. Prove that Z(O) � (qk-l -l)r/(q' -I). 6.68. Suppose the conditions of Theorem 6.84 hold, let q be odd and h � (q' -1)/2. Prove that equality holds in (6.37). 6.69. Let Z(b: N0, N) be as in Theorem 6.85. Under the conditions of Theorem 6.84 and using the notation in the proof of this theorem, show that Z(b;N0,N) N Z(b) I �-; + q(q'-1) 7 >f ( O)G( f, X)G( >f', A/,) >f (a) N;; :)-=. i ( aY' lj.(a),... I 6.70. Deduce from the result of Exercise 6.69 that IZ(O:No,N)-(qk-l_I)NI.;; (1--'-)(N _ _!!_)q'l' q'-I q h q'-I +q''l'>-1(2log-h-+• ). 1T q-1 h where '• � 0 for h � q-I and '• � � for h > q-I. 6. 71. Deduce from the result of Exercise 6.69 that I k-IN I ( 2 2 N( h r) ) Z(b;N0,N)-�'-I.;; ;Iogr+s+ h; q"-1>12 +(N _ _!!_)q''l'>-1 h q' -I for h * n Chapter 7 Theoretical Applications of Finite Fields Finite fields play a fundamental role in some of the most fascinating applications of modern algebra to the real world. These applications occur in the general area of data communic 8tion, a vital cOncern in our information society. Technological breakthroughs like space and satellite communications and mundane matters like guarding the privacy of information in data banks all depend in one way or another on the use of finite fields. Because of the importance of these applications to communication and information theory, we will present them in greater detail in the following chapters. Chapter 8 discusses applications of finite fields to coding theory, the science of reliable transmission of messages, and Chapter 9 deals with applications to cryp­ tology, the art of enciphering and deciphering secret messages. This chapter is devoted to applications of finite fields within mathema­ tics. These applications are indeed numerous, so we can only offer a selection of possible topics. Section I contains some results on the use of finite fields in affine and projective geometry and illustrates in particular their role in the construction of projective planes with a finite number of points and lines. Section 2 on com binatorics demonstrates the variety of applications of finite fields to this subject and points out their usefulness in problems of design of statistical experiments. In Section 3 we give the definition of a linear modular system and show how finite fields are involved in this theory. A system is regarded as a structure into which something (matter, energy, or information) may be put at certain "' 252 Theoretical Applications of Finite Fields times and that itself puts out something at certain times. For instance, we may visualize a system as an electrical circuit whose input is a voltage signal and whose output is a current reading. Or we may think of a system as a network of switching elements whose input is an on/off setting of a number of input switches and whose output is the on/off pattern of an array of lights. Some applications of finite fields to the simulation of randomness are discussed in Section 4. In particular, we show how certain linear recurring sequences can be used to simulate random sequences of bits. In numerical analysis one often has to simulate random sequences of real numbers; it is perhaps surprising that linear recurring sequences in finite fields can also be instrumental in this task. We emphasize that the applications are only described to give examples for the use of various properties of finite fields. Therefore, the examples contain rather the algebraic and combinatorial aspects, without regard to their practical application or indeed other usefulness. For in­ stance, we are not going to discuss the analysis of experimental design or the analysis or synthesis of linear modular systems, nor do we explain geometric properties that are not directly connected with finite fields. l. FINITE GEOMETRIES In this section we describe the use of finite fields in geometric problems. A projective plane consists of a set of points and a set of lines together with an incidence relation that allows us to state for every point and for every line either that the point is on the line or is not on the line. In order to have a proper definition, certain axioms have to be satisfied. 7.1. Definition. A projective plane is defined as a set of elements, called points, together with distinguished sets of points, called lines, as well as a relation/, called incidence, between points and lines subject to the following conditions: (i) every pair of distinct lines is incident with a unique point (i.e., to every pair of distinct lines there is one point contained in both lines, called their intersection); (ii) every pair of distinct points is incident with a unique line (i.e., to eVery pair of distinct points there is exactly one line which contains both points); (iii) there exist four points such that no three of them are incident with a single line (i.e., there exist four points such that no three of them are on the same line). It follows that each line contains at least three points and that through each point there must be at least three lines. If the set of points is finite, we speak of a finite projective plane. From the three axioms above one 1. Finite Geometries 253 deduces that (iii) holds also with the concepts of "point" and "line" interchanged. This establishes a principle of duality between points and lines, from which one can derive the following result. 7.2. Theorem. Let IT be a finite projective plane. Then: (i) there is an integer m;;,. 2 such that every point (line) of rr is incident with exactly m + I lines (points) of IT; (ii) IT contains exact(v m2 + m +I points (lines). 7.3. Example. The simplest finite projective plane is that with m = 2; there are precisely three lines through each point and three points on each line. Altogether there are 7 points and 7 lines in the plane. This projective plane is called the Fano plane and it may be illustrated as shown in Figure 7.1. The points are A, B, C. D, E, F, and G and the lines are ADC, AGE, AFB, CGF, CEB, DGB, and DEF. Since straightness is not a meaningful concept in a finite plane, the subset DEF is a line in the finite projective pi�. D The integer m in Theorem 7.2 is called the order of the finite projective plane. We will see that finite projective planes of order m exist for every integer m of the form m = p", where p is a prime. It is known that there is no plane for m = 6, but it is not known whether a plane exists for m = I 0. Many planes have been found for m = 9, but no plane has yet been found for which m is not a power of a prime. . . In ordinary analytic geometry we represent points of the plane as ordered pairs (x, y) of real numbers and lines are sets of pointS that satisfy real equations of the form ax+ by+ c = 0 with a and b not both 0. Now the field of real numbers can be replaced by any other field, in particular a finite field. This type of geometry is known as affine geometry (or euclidean geometry) and leads to the concept of an affine plane. 7.4. Definition. An affine plane is a triple ('3', e. I) consisting of a set '3' of points. a set e of lines, and an incidence relation I such that: c A 8 FIGURE 7.1 The Fano plane. 254 Theoretical Applications of Finite Fields (i) every pair of distinct points is incident with a unique line; (ii) every point p E §' not on a line L E e lies on a unique line ME C which does not intersect L; (iii) there exist four points such that no three of them are incident with a single line. The proof of the following theorem is straightforward. 7.5. Theorem. Let K be any f�eld. Let !!!' denote the set of ordered pairs (x. y) with x. y E K. and let e consist of those subsets L of Gj' which satisfy linear equations, i.e .. LEe if for some a, b, c E K with (a, b)"' (0,0) we have L � {( x, y) : ax + by + c � 0). A point P E 6J' is incident with a line LEe if and only if PEL. Then (6j', C, I) is an affine plane, denoted by AG(2,K). It can be shown readily that if IKI � m, then each line of AG(2. K) contains exactly m points. We can construct a projective plane from AG(2, K) by adding a line to it (and, conversely, we can obtain an affine plane from any projective plane by deleting one line and all the points on it). We change the notation in AG(2, K) and rename all the points as (x. y, 1), that is, (x. y. z) with z � 1. and use the equation ax+ by+ cz � 0 with (a, b)"' (0.0) as the equation of a line. Now add the set of points L00 � {(l.O,O)}u((x,I,O): x E K) to 9 to form a new set 9' � "!' U L00• The points of L00 can be represented by the equation z � 0 and so can be interpreted as a line. Let this new line L00 be added to C to form the set e·� C U(L00). With the natural extended notion of incidence, it can be verified that ('3'', e·. !')satisfies all the axioms for a projective plane. 7.6. Theorem. Let AG(2, K) � (0', C, I) and let 9'� 9 U{(l,O,O)}U{(x, 1,0): x E K) � 6J' U L00, e·� C U{L00), and let the extended incidence relation be denoted by I'. Then ('3'', C', /') is a projective plane. denoted by PG(2. K ) . 7.7. Example. The plane PG(2, �1)-that is, the projective plane over the field �2 -has seven points: (0.0, I), (1,0, I), (0, I, I), and (1.1.1) with z "'0 and the three distinct points on the line z � 0, namely, (1,0,0), (0, 1,0), and (1, 1,0). It can be verified that PG(2.1F2) also contains seven lines and that this projective plane is the Fano plane of Example 7.3. 0 In constructing PG(2, K ), every line of AG(2. K) must meet the new line L00, so there will be an additional point on each line; also Lr:T,) contains 1. Finite Geometries 255 0 p B, FIGURE 7.2 Desargues's theorem. m + I points if K contains m elements. Since for every prime power m � p" � q there are finite fields F ,, we have the following theorem. 7.8. Theorem. For every prime power q � p", p prime, nE N, there exists a finite projective plane of order q-namely, PG(2, F .J. The additional line L00 added to an affine plane to obtain a projec­ tive plane is sometimes called the line at infinity. If two lines intersect on L00, they are called parallel. Next we present without proof two interesting theorems, which hold in all projective planes that can be .represented analytically in terms of fields. Two triangles ll.A1B1C1 and ll.A2B2C2 are said to be in perspective from a point 0 if the lines A1A2, B1 82, and C1C2 pass through 0. Points on the same line are said to be collinear. 7.9. Theorem (Desargues's Theorem). Ifll.A1B1C1 andll.A2B2C2 are in perspective from 0, then the intersections of the lines A1 81 and A2 82, of A1C1 and A2C2, and of B1C1 and B2C2, are collinear. The theorem is illustrated in Figure 7.2; the intersections of corre­ sponding lines are P, Q, and Rand are collinear. 7.10. Theorem (Theorem of Pappus). If A1, 81, C1 are points of a line and A2, 82, C2 are points of another line in the same plane, and if A1B2 and A2B1 intersect in P, A1C2 and A2C1 intersect in Q, and B1C2 and B2C1 intersect in R, then P, Q. and Rare collinear. The theorem is illustrated in Figure 7.3. Both theorems play an important role in projective geometry. If Desargues's theorem holds in some projective plane, then coordinates can be defined in terms of elements from a division ring. Here we define a point as an ordered triple (x0, x1, x2) of three homogeneous coordinates, where the x,. are elements of a division ring R, not all of them simultaneously 0. The triples (ax0, ax1, ax2), 0"' a E R, 256 Theoretical Applications of Finite Fields FIGURE 7.3 The theorem of Pappus. shall denote the same point. Thus each point is represented in m -I ways if !RI � m, and because there are m3 -I possible triples of coordinates, the total number of different points is ( m3 -I)/( m -I) � m2 + m +I. A line is defined as the set of all those points whose coordinates satisfy an equation of the form x0 + a1x1 + a1x2 = 0, or of the form x1 + a2x1 = 0, or of the form x2 = 0, where a; E R. There are m2 + m +I such lines in the plane and it is straightforward to show that the points and lines thus defined satisfy the axioms of a finite projective plane. From Theorem 2.55-that is, Wedderburn's theorem-we know that any finite division ring is a field, a finite field F •. In that case the equation of any line can be written as a0x0 + a1x1 + a2x1 = 0, where the a; are not simultaneously 0, a"d (aa0)x0 +(aa1)x1 +(aa2)x2 � 0 with a E F; is the same line. The line connecting the points (y0,y1,y 2) and (z0,z1,z 2) may then also be defined as the set of all points with coordinates where a and b are in IF •' not both equal to 0. There are q2-I such triples, and since simultaneous multiplication of a and b by the same nonzero element produces the same point, they yield q +I different points. In PG(2.1F .• ) Desargues's theorem and its converse hold, and the proof relies on commutativity of multiplication in IF q· In general, Desargues's theorem and its converse do not both apply if the coordinatizing ring does not have commutativity of multiplication. Thus Wedderburn's theorem plays an important role in this context. A projective plane in which Desargues's theorem holds is called Desarguesian; o.therwise it is called non-Desarguesi an. Desarguesian planes of order m exist only if m is the power of a prime, and up to isomorphism there exists only one Desarguesian plane for any given prime power m = p". 1. Finite Geometries 257 A finite Desarguesian plane can always be coordinatized by a finite field. Since such fields exist only when the order is a prime power, a projective plane with exactly m +I points on each line, m not a prime power, will have to be non-Desarguesian. It is not known whether such planes for m not a prime power exist. If it can be proved that up to isomorphism there exists only one finite projective plane of order m, and if m is a prime power, then this plane must be Desarguesian. This is the case form� 2, 3, 4, 5, 7, and 8. For m prime, only Desarguesian planes are known. But it has been shown that for all prime powers m � p", n:;, 2, except for 4 and 8, there exist non-Desarguesian planes of order m. The theorem of Pappus implies the theorem of Desargues. If the theorem of Pappus holds in some projective plane, then the multiplication in the coordinatizing ring is necessarily commutative. The theorem of Pappus holds in PG(2, F q) for any prime power q. A finite Desarguesian plane also satisfies the theorem of Pappus. A remarkable distinction between the properties of a PG(2,F,) with q even and a PG(2,1F,) with q odd is given in the following theorem. 7.11. Theorem. The diagonal points of a complete quadrangle in PG (2,1F,) are collinear if and only if q is even. Proof We assume, without loss of generality, that the vertices of the quadrangle are (1,0,0), (0,1,0), (0,0, 1), and (1, !,!). Its six sides are x2 = 0, x1 = 0, x1 � x2 = 0, x0 = 0, x0 � x2 = 0, and x0 � x1 = 0, while the three diagonal points are (1, 1,0), (1.0, 1), and (0,1,1). The line through the first two points contains all points with coordinates (a+ b, a, b), where (a, b)* (0,0), and the third point is one of these if and only if a� band a+ b � 0. In a finite field IF, this is only possible if the characteristic is 2. D The latter case is illustrated in Example 7.3. Let the vertices of the complete quadrangle be C, D, E, G. In this case, the diagonal points are A, F, B, and they are collinear. We introduce now concepts analogous to those with which we are familiar in analytic geometry, and we restrict ourselves to Desarguesian planes, coordinatized by a finite field F ,. Let the equations of two distinct lines be a01x0 + a11x1 + a21x2 = 0, aooxo+a12xl+anx2=0. (7.1) Let the point of intersection of these two lines be P. All lines through P form a pencil and each line in this pencil has an equation of the form ( ra01 + sa02)x0 + (ra11 + sa12)x1.+ ( ra21 + sa22 )x2 � 0, where r, s E IF, are not both 0. There are q + I lines in the pencil: the two lines (7.1) given above corresponding to s � 0 and r � 0, respectively, and 258 Theoretical Applications of Finite Fields those corresponding to q-I different ratios rs-1 with r"' 0 and s "'0. Let another pencil through a point Q"' P be given by (rb01 + sb02)x0 + (rbl! + sb12)x1 + (rb21 + sb22)x2 = 0. A projective correspondence between the lines of the two pencils is defined by letting a line of the first, given by a pair ( r, s ), correspond to the line of the second pencil that belongs to the same pair. Two corresponding lines meet in a unique point, except when the line PQ corresponds to itself, and the coordinates of all the points satisfy the equation (a01x0 + al!x1 + a21x2)(b02x0 + b12x1 + b22x2) -(a01x0 + a12x1 + a22x2)(b01x0 + bl!x1 + b21x2) = 0, (7.2) obtained by eliminating r and s from the equations of the two pencils. 7.12. Definition. The set of points whose coordinates satisfy equation (7.2) is called a conic. If the line PQ corresponds to itself under the correspondence above, then the conic is called degenerate. It consists then of the 2q + l points of two intersecting lines. A nondegenerate conic consists of the q + I points of intersection of corresponding lines. A line that has precisely one point in common with a conic is called a tangent of it; a line that has two points in common is a secant. The equation of a nondegenerate conic is quadratic, therefore it cannot have more than two points in common with any line. Take one point of a nondegenerate conic and connect it by lines to the other q points. Then the resulting lines are secants and the remaining one of the q + l lines through that point must be a tangent. The q + I points of a nondegenerate conic thus have the property that no three of them are collinear. It can be shown that any set of q +I points in a PG(2,F.), q odd, such that no three of them are collinear is a nondegenerate conic. The following theorem, which we prove only in part, exhibits a difference between conics in Desarguesian planes of odd and of even order. 7.13. Theorem. (i) In a Desarguesian plane of odd order there pass two or no tangents of a nondegenerate conic through a point not on the conic. (ii) In a Desarguesian plane of even order all the tangents of a nondegen erate conic meet in a single point. Proof We prove (ii) as an example of how properties of finite fields are used in the theory of finite projective planes. Assume without loss of generality that three points on a nondegenerate conic in a plane of even order are A(l,O,O), B(O,l,O), C(O,O, I) and that the tangents through these three points are, respectively, x1-k0x2 = 0, x2-k1x0 = 0, x0-k2x1 = 0. Let P(t0, 11, I 2) be another point of the conic. None of the t, can be 0, 1. Finite Geometries 259 because then P would be on a line through two of the points A. B, and C, contradicting the fact that no three points of the conic are collinear. Therefore we can write x1-t1121x2=0 for PA, x2-121Q1x0=0 for PB, and x0-t0t[1x1 � 0 for PC. Consider the equation for the line PA. As we choose for P the various points of the conic, leaving out A, B, and C, the ratio 11121 runs through the elements of f q apart from 0 and k0. Since n (x-c)�x'-1-1, cEF; the product of all nonzero elements of F• is ( -I)•. Thus, multiplying the product of the q-2 values t 1t2 1 assumes by k", we obtain ( -I)q �I, since q is even. We have where the product extends over all points of the conic except A, B, and C. Multiplying the three products above we get k0k1k2 �I. Therefore the points(!, k0k1, k1), (k2, I, k1k2), and (k0k2, k0, I) are identical. The three tangents at A, B, and C pass through this point; and because these points were arbitrary. any three tangents meet in the same point. D Analogs of the concept of a projective plane can be defined for dimensions higber than 2. 7.14. Definition. A projective space, or a projective geometry, or an m­ space is a set of points, together with distinguished sets of points, called lines, subject to the following conditions: (i) There is a unique line through any pair of distinct points. (ii) A line that intersects two lines of a triangle intersects the third line as well. (iii) Every line contains at least three points. (iv) Define a k-space as follows. A 0-space is a point. If A0, ... ,Ak are points not all in the same (k -I)-space, then all points collinear with A0 and any point in the (k-I)-space defined by A1, ... ,Ak form a k-space. Thus a line is a !-space, and all the other spaces are defined recursively. Axiom (iv) demands: If k < m, then not all points considered are in the same k-space. (v) There exists no (m +I)-space in the set of points considered. We say that an m-space has m dimensions, and if we refer to a k-space as a subspace of a projective space of higber dimension, we call it a k-flat. An ( m -1)-flat in a projective space of m dimensions is called a hyperplane. A 2-space is a projective plane in the sense of Definition 7.1. It can be proved that in any 2-flat in a projective space of at least three 260 Theoretical Applications of Finite Fields dimensions the theorem of Desargues (Theorem 7.9) is always valid. Desargues's theorem can only fail to be true in projective planes that cannot be embedded in a projective space of at least three dimensions. A projective space containing only finitely many points is called a finite projective space (or finite projective geometry, or finite m-;pace ). In analogy with PG(2,F.), we can construct the finite m-space PG(m,f.). Define a point as an ordered (m +!)-tuple (x0, x1, •••• x.,), where the coordinates x, E f • are not simultaneously 0. The (m + !)-tuples (ax0,axp····axm) with aEf; define the same point. There are therefore (q"'+ 1 -l)/(q -l) points in PG(m,F.). A k-flat in PG(m,F,) is the set of all those points whose coordinates satisfy m-k linearly independent homogeneous linear equations with coefficients a,1 E IF,. Alternatively, a k-flat consists of all those points with coordinates with the a, E F• not simultaneously 0 and the k + l given points ( Xoo, ···,X om),.·· • (xkO• · · · ,xkm) being linearly independent; that is, the matrix has rank k + l. The number of points in a k-flat is (qk+ 1 -1)/(q -1); there are q + l points on a line and q2 + q + l on a plane. That PG(m,IF•) satisfies the five axioms for an m-space is easily verified. We know that in f •"" all powers of a primitive element a can be represented as polynomials in a of degree at most m with coefficients in IF q· If a;=ama'"+ ··· +a0, we may consider a; as representing a point in PG(m,IFq) with coordinates (a0, ... ,a,J. Two powers a',ai represeiJ,t the same point if and only if a;= a a' for some a E F;-that is, if and only if i= imod(a"'+1-!)/(a-l). 1. Finite Geometries 261 A k-flat S through k +I linearly independent points represented by a'' .... , a;k will contain all points represented by L�_0a,a;•, a, E F q not simulta­ neously O. For each h = O,l, ... ,v -I with v = (qm+l -1)/(q -I), the points L�-o a,ai,+lr, a, E F q not simultaneously 0, form k-flats, and we denote the k-flat with given h by s •. We haveS,= S0 = S because a" E F •. Letj be the least positive integer for which S, = S. Then from s., = S for all n EN it follows that j divides v, say v = tj. We call j the cycle of S. If a"' is a point of the k-flat S, then so are the points with exponents d0,d0+ j, ... ,d0+(1-l)j, because s.; = S for n = 0,1, ... ,1-1. Further points on S can be wntten with the following exponents of a: dl, dl + j . ... ,dl +(1-l)j d._ \'du-1 + j, ... ,d•-1 +(I- l)j, where d,,-d,, is not divisible by j for r1 "'r2. The number of all these distinct points is tu = ( qk+ 1 -I)/( q-I). If tj=(qm+l_l)/(q-1) and lu=(qk+1-l) (q-1) are relatively prime, then r =I, j = v, and all k-flats have cycle v. This is the case for k = m -I, and for k = I when m is even. 7.15. Example. Consider PG(3,F2) with 15 points, 35 lines, 15 planes, and qm+ 1 = 16. Using a root a E IF 16 of the primitive polynomial x4 + x +I over IF2, we can establish a correspondence between the powers of a and the points of PG(3,1F2). We obtain: A(O.O,O,l) .. · a3 B(O,O,l,O) · · · a2 C(O,O,l,l) ···a' D(O,l,O,O) · · · a1 £(0.1,0,1) ···a' The plane F(O,l,l,O) · · · a5 G(O.l,l, I)··· a11 H(l,O,O,O) · · · a0 /(1,0,0,1) ··· a14 J(I,O, 1,0) ···a' K(l,O,l,l) · · · a13 L(l,l,O,O) · · · a4 M(l,l,O,l) · · · a7 N(l,l,l,O) · · · a10 0(1,1,1,1) · · · a12 S=S0={a0a0+a1a1+a2a2· a0,a1,a2EIF2notall 0} is the same as the plane x3 = 0. It contains the points B, D, F, H, J, L, and N. It has cycle 15, as has any other hyperplane. The plane S1 = {a0a1 + a1a2 + a2a3: a0,a1, a2 EF2 not all 0} is the same as the plane x0 = 0 and contains the points A, B, C, D, £, F. and G; and so on. The line {a0a3 + a,a8: a0, a, E F, not bothO}, 262 Theoretical Applications of Finite Fields that is, the line AJK, has cycle 5, the lines ABC and ADE both have cycle 15, and this accounts for all the 5 + 15 + 15 � 35 lines. D A finite affine (or euclidean) geometry, denoted by AG(m,F,), is the set of flats that remain when a hyperplane with all its flats is removed from PG( m, IF ,J. Those flats that were removed are called flats at infinity. Those remaining flats that intersect in a flat at infinity are called parallel. It is convenient to consider the excluded hyperplane as the one whose equation is x., � 0. Then we may fix x., for all points in A G(m, f ,) at I, and consider only the remaining coordinates as those of a point in AG(m,IF,). Since there are q"' + · · · + q +I points in PG(m,f,), and the q"'-1 + · · · + q +I points of a hyperplane were removed, there remain q"' points inAG(m,IF, ). A k-flat within AG(m,F,) contains all those q' points that satisfy a system of equations of the form a;0x0+ ··· +a;,m-IXm- l+a;m=O, i=l, ... ,m-k, where the coefficient matrix has rank m -k. In particular, a hyperplane is defined by OoXo + ... + am-IXm -1 +Om= Q, where a0, ... ,am-l are not all 0. If a0, ... ,am-l are kept constant and am runs through all elements of F ,. then we obtain a pencil of parallel hyperplanes. 2. COMBINATORICS In this section we describe some of the useful aspects of finite fields in combinatorics. There is a close connection between finite geometries and designs. The designs we wish to consider consist of two nonempty sets of objects, with an incidence relation between objects of different sets. For instance, the objects may be points and lines, with a given point lying or not lying on a given line. The terminology that is normally used in this area has its origin in the applications in statistics, in connection with the design of experi­ ments. The two types of objects are called varieties (in early applications these were plants or fertilizers) and blocks. The number of varieties will, as a rule, be denoted by v, and the number of blocks by b. A design for which every block is incident with the same number k of varieties and every variety is incident with the same number r of blocks is called a tactical configuration. Clearly vr � bk. (7.3) If v � b, and hence r � k, the tactical configuration is called symmetric. For instance, the points and lines of a PG(2,F,) form a symmetric tactical 2. Combinatorics 263 configuration with v � b � q2 + q + I and r � k � q + I. The property of a finite projective plane that every pair of distinct points is incident with a unique line may serve to motivate the following definition. 7.16. Definition. A tactical configuration is called a balanced incomplete block design (BIBD), or (v, k, A.) block design, if v;;. k;;. 2 and every pair of distinct varieties is incident with the same number A. of blocks. If for a fixed variety a1 we count in two ways all the ordered pairs (a2, B) with a variety a2"' a1 and a block B incident with a1, a2, we obtain the identity r(k-l)�A.(v-1) (7.4) for any (v, k, A.) block design. Thus, the parameters band r of a BIBD are determined by v, k, and A. because of (7.3) and (7.4). 7.17, Example. Let the set of varieties be {0, 1,2,3,4,5,6) and let the blocks be the subsets {0, 1,3), (1,2,4), {2,3,5), {3,4,6), {4,5,0), (5,6, 1), and {6, 0, 2), with the obvious incidence relation between varieties and blocks. This is a symmetric BIBD with v � b � 7, r � k � 3, and A.� I. It is equivalent to the Fano plane in Example 7.3. A BIBD with k � 3 and ). = 1 is called a Steiner triple system. D 7.18, Example, More generally, a BIBD is obtained by taking the points of a projective geometry PG(m,IFq) or of an affine geometry AG(m,F•) as varieties and its t-flats for some fixed 1, l,.t.< m, as blocks. In the projective case, the parameters of the resulting BIBD are as follows: v� qm+l -I t+ I m-t+i I t m-t+i 1 b�nq. -' r�nq. - ' q-1 i=l q'-1 i-1 q'-1 qt+l_l t-l qm-t+i -I k� .A.�n • q-1 i-1 q' -I where the last product is interpreted to be 1 if I � I. The BIBD is symmetric in case t � m -1-that is, if the blocks are the hyperplanes of PG(m,IFq). In the affine case, the parameters of the resulting BIBD are as follows: t m-t+i _I t m-t+i _I b � qm-• n q . ' r � n q . ' i-I q'-I j- I q' -I t-l qm-t+i -I k � q' A� n .:!___........:.. • i-1 q;-1 . with the same convention for t �I as above. Such a BIBD is never symmetri c. D A tactical configuration can be described by its incidence matrix. 264 Theoretical Applications of Finite Fields This is a matrix A of v rows and b columns, where the rows correspond to the varieties and the columns to the blocks. We number the varieties and blocks, and if the ith variety is incident with the jth block, we define the (i, j) entry of A to be the integer I, otherwise 0. The sum of entries in any row is r and that in any column is k. If A is the incidence matrix of a ( v, k, A) block design, then the inner product of two different rows of A is A. Thus, if AT denotes the transpose of A, then r A A A r A A A r � (r-A)l +AJ, where I is the v X v identity matrix and J is the v X v matrix with all entries equal to I. We compute the determinant of AAT by subtracting the first column from the others and then adding to the first row the sum of the others. The result is rk 0 A r-A 0 0 0 0 r-A 0 0 0 0 � rk ( r-A) v- 1, r-A where we have used (7.4). If v � k, the design is trivial, since each block is incident with all v varieties. If v > k, then r >A. by (7.4), and so AAT is of rank v. The matrix A cannot have smaller rank, hence we obtain b� v. (7.5) By (7.3), we must also have r ;>. k. For a symmetric ( v, k, A) block design we haver� k, hence AJ � JA, and so A commutes with (r-A)/+ AJ� AAT Since A is nonsingular if v > k, we get ATA � AAT � (r-A)/+ AJ. It follows that any two distinct blocks have exactly A varieties in common. This holds trivially if v � k. We have seen that the conditions (7.3) and (7.4), and furthermore (7.5) in the nontrivial case, are necessary for the existence of a BIBD with parameters v, b, r, k, A. These conditions are, however, not sufficient for the existence of such a design. For instance, a BIBD with v � b � 43, r � k � 7, and A � I is known to be impossible. The varieties and blocks of a symmetric ( v, k, A) block design with k ;>. 3 and A � I satisfy the conditions for points and lines of a finite projective plane. The converse is also true. Thus, the concepts of a symmetric ( v, k, I) block design with k ;>. 3 and of a finite projective plane are equivalent. Consider the BIBD in Examnle 7.17 and interoret the varieties 2. Combinatorics 265 0, 1,2,3,4,S,6 as integers modulo 7. Each block of this design has the property that the differences between its distinct elements yield all nonzero residues modulo 7. This suggests the following definition. 7.19. Definition. A set D � {d1, ••• ,d,) of k;, 2 distinct residues modulo v is called a ( v, k, .\) difference set if for every d ;�; 0 mod v there are exactly ,\ ordered pairs ( d,, d) with d,, dj ED such that d,-dj = dmod v. The following results provide a connection between difference sets, designs, and finite projective planes. 7.20, Theorem. Let {d1, ••• ,d,) be a (v, k, .\)difference set. Then with all residues modulo v as varieties, the blocks B, � {d1 + t, ... ,d, + 1), I� 0, l, ... ,v -I, form a symmetric ( v, k, .\) block design under the obvious incidence relation. Proof A residue a modulo v occurs exactly in the blocks with subscripts a-d1, ••• ,a-dk modulo v, thus every variety is incident with the same number k of blocks. For a pair of distinct residues a, c modulo v, we have a, c E B, if and only if a= d, + t mod v and c = dj + t mod v for some d,, dJ" Consequently, a-c = d, -djmod v, and conversely, for every solu­ tion ( d,, d) of the last congruence, both a and c occur in the block with subscript a-d, modulo v. By hypothesis, there are exactly ,\ solutions (d,, d) of this congruence , and so all the conditions for a symmetric ( v, k, ,\) block design are satisfied. D 7.21. Corollary. Let {d1, ••• ,d,) be a (v,k,l) difference set with k ;, 3. Then the residues modulo v and the blocks B,, t � 0, I, ... , v-I, from Theorem 1.20 satisfy the conditions for points and lines of a finite projective plane of order k -I. Proof This follows from Theorem 7.20 and the observation above that symmetric (v, k, I) block designs with k;, 3 are finite projective planes. D It follows from Theorem 7.20 and (7.4) that the parameters v, k, A of a difference set are linked by the identity k(k-I)�.\( v -1). This can also be seen directly from the definition of a difference set. 7.22. Example. The set (0, 1,2,4,S,8, 10) of residues modulo IS is a (IS, 7,3) difference set. The blocks B,� {t,t+ l,t+2,t+4,t +S,t +8,1 + 10), t�O,l, ... , 14, form a symmetric (IS, 7, 3) block design according to Theorem 7.20. The blocks of this design can be interpreted as the IS planes of the projective geometry PG(3.F2), with the IS residues representing the points. Each plane is a Fano nlane pr,(2.F .. )_ The lines of the hlock R can he nhtaineci hv 266 Theoretical Applications of Finite Fields cyclically permuting the points of the line L, � B, n 8,_4 � {t, t +I, t +4) in the plane B, according to the permu ta lion r-r+1 -r+2-t+4-r+5-r+I O-r+8-r. For instance, the lines in the plane 80 � (0, 1,2,4,5, 10,8) are (0, 1.4}, (1.2,5). (2,4, 10}, (4,5,8), (5, 10,0}, (10,8, 1}, (8,0,2}. D Examples of difference sets can be obtained from finite projective geometries. As in the discussion preceding Example 7.15, we identify points of PG(m,f•) with powers of a, where a is a primitive element of IF ••.• , and the exponents of a are considered modulo v � (qm+l -1)/(q -I). LetS be any hyperplane of PG(m,F.). Then S has cycle v, and so the hyperplanes s. � a•s, h � 0, I, ... , v-I, are distinct. These are already all hyperplanes of PG(m,F .), since v is also the total number of hyperplanes. Thus, the following is the complete list of hyperplanes of PG(m,f.), with the points contained in them indicated by the corresponding exponents of a: S0 d1 d2 d, S1 d1 +I d2 +I d, +I Here k � ( qm-I)/( q-I), the number of points in a hyperplane. If we look for those rows that contain a particular value, say 0, then we obtain the k hyperplanes through a0• These k rows are given by: d,-d, d,-d, d,-d, d,-d, Any point "'a0 appears in as many of those k hyperplanes as there are hyperplanes through two distinct points-that is, 'A� (qm-l -1)/(q -I) of them-so that the off-diagonal entries repeat each nonzero residue modulo v precisely A times. Hence (d1, ... ,d,) is a (v,k,'h) difference set. We summarize this result as follows. 7.23. Theorem. The points in any hyperplane of PG(m,IF•) de­ termine a ( v, k, A) difference set with parameters qm+ 1 _I qm _ 1 qm-1 _ 1 v� q-1 . k�-q---,-, 'A� q-1 7.24. Example. Consider the hyperplane x1 � 0 of PG(3,1F2) in Example 7.15. It contains the points A, B, C, H, I, J, K. and so the corresponding 2 Combinatorics 267 exponents of a yield the ( 15, 7, 3) difference set {0, 2, 3, 6, 8, 13, 14). D Another branch of combinatorics in which finite fields are useful is the theory of orthogonal latin squares. 7.25. Definition. An array a" a" a," a, a, aln L �(a,)� a", a"' a"" is called a latin square of order n if each row and each column contains every element of a set of n elements exactly once. Two latin squares (a,.) and (b,j) of order n are said to be orthogonal if the n2 ordered pairs (a,,, b,j) are all different. 7.26. Theorem. A latin square of order n exists for every positive integer n. Proof Consider(a,.)witha,j=i+ jmodn.l�a,j�n. Thena,j= a,.k implies i + j = i + kmod n. and so}= kmod n, which means }= k since I.; i, j, k.; n. Similarly, a,j � a,j implies i � k. Thus the elements of each row and each column are distinct. D Orthogonal latin squares were first studied �y Euler. He conjectured that there did not exist pairs of orthogonal latin squares of order n if n is twice an odd integer. This was disproved in 1959 by the construction of a pair of orthogonal latin squares of order 22. It is now known that the values of n for which there exists a pair of orthogonal latin squares of order n are precisely all n > 2 with n # 6. For some values of n, more than two latin squares of order n exist that are mutually orthogonal (i.e., orthogonal in pairs). We shall show that if n = q. a prime power, then there exist q-I mutually orthogonal latin squares of order q, by using the existence of finite fields of order q. 7.27. Theorem. Then the arrays Let a0�0,a1,a2, ... ,a._, be the elements of IF •. ao a, aq-1 aka1 aka1 + a1 aka1 + aq-l L,� aka2 aka2 + al akal + aq-1 k � l, ... ,q-1, akaq-1 akaq-l + a1 akaq-1 + aq-1 form a set of q-I mutually orthogonal latin squares of order q. 268 Theoretical Applications of Finite Fields Proof Each Lk is clearly a latin square. Let aLk, = ak.a;_1 + a1_1 be the (i, j) entry of L,. Fork* m, suppose Then and so (a��) a�'?'l) � (a<kl aCml) for some 1 :!>: i 1. g h "'q I) ' I} gh I gh ""<:: 1 1 1 ""<:: " Since ak*-am, it follows that a;_1=a g_1, ah_1=a1_1, hence i=g,j=h. Thus the ordered pairs of correspond ing entries from L, and Lm are all different, and soL, and Lm are orthogonal . 0 7.28. Example. A set of four mutually orthogonal latin squares of order 5 is given below, using the construction in Theorem 7.27: L, L2 0 l 2 3 4 0 l 2 3 4 l 2 3 4 0 2 3 4 0 l 2 3 4 0 l 4 0 l 2 3 3 4 0 l 2 l 2 3 4 0 4 0 l 2 3 3 4 0 l 2 L, L• 0 l 2 3 4 0 l 2 3 4 3 4 0 l 2 4 0 l 2 3 l 2 3 4 0 3 4 0 l 2 0 4 0 l 2 3 2 3 4 0 l 2 3 4 0 l l 2 3 4 0 The following result, which also yields information for the case where the order n of the latin squares is not a prime power, is proved in the same way as Theorem 7.27. Note that Theorem 7.29 shows, in particular, the existence of a pair of orthogonal latin squares of order n for any n > 1 with n¢2 mod 4. 7.29. Theorem. Let q 1, ... , q, be prime powers and let 0t�l = 0 0ln alil 0u1 0 • I • 2 •· · · • q,-l be the elements of 'f.,. Define the s-tuples b,�(ai'1 .... ,ai'1) forO<>.k<>.r� min (q,-1). l"i"J and let b,+1, ••• ,b,_1 with n = q1 • • • qs be the remaining s-tuples that can be formed by taking in the ith coordinate an element off •• These s-tuples are 2. Combinatorics 269 added and multiplied by adding and multiplying their coordinates. Then the arrays bo bl bn-1 b,bl b,bl +bl b,bl + b,_l L, � b,b, b,b, + bl b,b,+b,_l k = l, ... ,r, bkb,l_l b,b,_l + bl bkbn-l+bn-1 form a set of r mutually orthogonal latin squares of order n. Tactical configurations and latin squares are of use in the design of statistical experiments. For example, suppose that n varieties of wheat are to be compared as to their mean yield on a certain type of soil. At our disposal is a rectangular field subdivided into n2 plots. However, even if we are careful in the selection of our field, differences in soil fertility will occur on it. Thus, if all the plots of the first row are occupied by the first variety, it may very well be that the first row is of high fertility and we might obtain a high yield for the first variety although it is not superior to the other varieties. We shall be less likely to vitiate our comparisons if we set every variety once in every row and once in every column. In other words, the varieties should be planted on the n2 plots in such a way that a latin square of order n is formed. It is often desirable to test at the same time other factors influencing the yield. For instance, we might want to apply n different fertilizers and evaluate their effectiveness. We will then arrange fertilizers and varieties on the n2 plots in such a way that both the arrangement of fertilizers and the arrangement of varieties form a latin square of order n, and such that every fertilizer is applied exactly once to every variety. Thus, in the language of combinatorics, the latin squares of fertilizer and variety arrangements should be orthogonal. Similar applications exist for balanced incomplete block designs. As another example for a combinatorial concept allowing applica­ tions of finite fields, we introduce so-called Hadamard matrices. These matrices are useful in coding theory, in communication theory, and physics because of Hadamard transforms, and also in problems of determination of weights, resistances, voltages, and so on. 7.30. Definition. A Hadamard matrix H11 is an n X n matrix with integer entries ±I that satisfies HnH} =n/. Since H,-1 � (ljn)H,T, we also have H,TH, � nl. Thus, any two distinct rows and any two distinct columns of Hn are orthogonal. The 270 Theoretical Applications of Finite Fields determinant of a Hadamard matrix attains a bound due to Hadamard. We have det(H,H,T) � n". and so ldet(H,)I � n"l'. while Hadamard's result states that ldet(M)I "n"l' for any real n X n matrix M with entries of absolute value �I. Changing the signs of rows or columns leaves the defining property unaltered. so we may assume that H11 is normalized -that is, that all entries in the first row and first column are +I. It is easily seen that the order n of a Hadamard matrix (a1) can only be I. 2. or a multiple of 4. For we have " " j=l j=l for n ;;. 3 and every term in the first sum is either 0 or 4, hence the result follows. It is conjectured that a Hadamard matrix H, exists for all those n. 7.31. Example. Hadamard matrices of the lowest orders are: H.� I 1 I I -:I H1 �(I), H, � (: -:). -I I 0 I -I -1 . -I -I I We describe now a construction method for Hadamard matrices using finite fields. 7.32. Theorem. Let a1, ... ,a, be the elements ofF,, q=3mod4, and let � be the quadratic character of 'f ,. Then the matrix -I b, b, b,, b, -I b" b,, H� b, b" -I b,, b,, b,, b,, -I with b,1 � �( a1-a,) for 1 � i, j � q. i * j, is a Hadamard matrix of order q+l. Proof Since all entries are ±I, it suffices to show that the inner product of any two distinct rows is 0. The inner product of the first row with the (i + l)st row, I" i" q, is 1+(-1)+ �>iJ� L �(a1-a,)� L �(c)�O J""l J*l cEF; by (5.12). The inner product of the (i + l)st row with the (k + l)st row, I� i < k � q, is 3. Linear Modular Systems 1-bki-btk + L bi,bk1 j <#<I, k �1-�(a,-a,)-�(a,-a,)+ L �(a1-a,h(a1-a,) j""' i,k �1-[1+�(-l)h(a,-a,)+ I: �((c-a,)(c-a,))�o. cEFq 271 since �(-I)� -I for q"' 3 mod4 by Remark 5.13 and the last sum is -I by Theorem 5.18. D If H" is a Hadamard matrix of order n, then ( H" H") H11 -H, is one of order 2n. Therefore, Hadamard matrices of orders 2'(q +I) with h;;. 0 and prime powers q"' 3mod4 can be obtained in this manner. By starting from the Hadamard matrix H1 in Example 7.31, one can also obtain Hadamard matrices of orders 2', h;;. 0. 3. LINEAR MODULAR SYSTEMS System theory is a discipline that aims at providing a common abstract basis and unified conceptual framework for studying the behavior of various types and forms of systems. It is a collection of methods as well as special techniques and algorithms for dealing with problems in system analysis, synthesis, identification, optimization, and other areas. It is mainly the mathematica l structure of a system that is of interest to a system theorist, and not its physical form or area of applications, or whether a system is electrical, mechanic al, economic, biological, chemical, and so on. What matters to the theorist is whether it is linear or nonlinear, discrete-time or continuous-time, deterministic or stochastic, discrete-state or continuous­ state, and so on. In the introduction to this chapter we gave an informal description of systems. We present now a rigorous definition of finite-state systems, which provide an idealized model for a large number of physical devices and phenomena. Ideas and techniques developed for finite-state systems have also been found useful in such diverse problems as the investigation of human nervous activity, the analysis of English syntax, and the design of digital computers. 7.33. Definition. A (complete, deterministic) finite-state system GJ1L is de­ fined by the following: (I) A finite, nonempty set U�{a1,a2, ... ,a,), called the input 272 Theoretical Applications of Finite Fields alphabet of GJlL. An element of U is called an input symbol. (2) A finite, nonempty set Y � (/J1, p,, ... ,/3.), called the output alphabet of G)]L. An element of Y is called an output symbol. (3) A finite, nonempty set S � ( a1, a2, ... , a,}, called the state set of GJlL. An el ement of S is called a state. (4) A next-state function f that maps the set of all ordered pairs (a1, aj) into S. (S) An output function g that maps the set of all ordered pairs (a,aj) into Y. A finite-state system G)1L can be interpreted as a device whose input, output, and state at time I are denoted by u(t), y(t), and s(t), respectively, where these variables are defined for integers t only and assume values taken from U, Y, and S, respectively. Given the state and input of GJ1L at time 1, f specifies the state at time I+ 1 and g the output at time 1: s(t + 1) � f(s(t), u(t)). y(t) � g(s(t), u(t)). Linear modular systems constitute a special class of finite-state systems, where the input and output alphabets and the state set carry the structure of a vector space over a finite field F • and the next-state and output functions are linear. Linear modular systems have found wide applications in computer control circuitry, implementation of error-correct­ ing codes, random number generation , and other digital tasks. 7.34. Definition. A linear modular system ( LMS) G)1L of order n over F • is defined by the following: (I) A k-dimensional vector space U over IF,. called input space of GJlL, the el ements of which are called inputs and are written as column vectors. (2) An m-dimensional vector space Y over F •' called output space of GJlL, the el ements of which are called outputs and are written as column vectors. (3) Ann-dimensional vector spaceS over IF,, called state space of GJlL, the elements of which are called states and are written as column vectors. (4) Four characterizing matrices over F q: A= (a;),p:n' B= (b;Jnxk' The matrix A is called the characteristic matrix of G)1L. 3. Linear Modular Systems 273 (5) A rule relating the state at time 1 + l and output at time 1 to the state and input at time 1: s(t + l) � As(t)+ Bu(t), y(t) �cs(t)+Du(t). An LMS over IF • can be simulated by a switching circuit incorporat­ ing adders, constant multipliers, and delay elements (compare with Chapter 6, Section I). It is convenient here to use adders summing also more than two field el ements. Thus, an adder has two or more inputs 111 (I), u2 ( t), ... ,u,( I) E IFq and a single output y1(t)�u1(t)+u2(t)+ ··· +u,(t). A constant multiplier with a constant a E F • has a single input u1 ( 1) E F • and a single output y1(t) � au1(t). A delay element has a single input u1(t) E IF• and a single output y1(t) � u1(t -l). Symbolically, these components are represented as shown in Figure 7.4. We describe now how we can obtain a realization of an LMS �as a circuit simulating the operations of�: l. Draw k input terminals labelled "•·····"k• m output terminals labelled y" ... ,ym, and n delay elements, .. where the output of the ith delay element iss,� s,( t) and its input iss;� s1( 1 + l). 2. Insert an adder in front of each output terminal y, and each delay el ement. 3. The inputs to the adder associated with the i th delay element are the si' each applied via a constant multiplier with constant a;1, l .,; i, j.,; n, and the ui' each applied via a constant multiplier with constant h;J' I" j" k. Adder u2(1) : : + y1(t)=u1(t)+u2(t)+···+u,(l) u1(t)� Ur(t) Constant Multiplier u1(1)� y1(t)=ou1(1) Delay Element FIGURE7.4 The building blocks of linear modular systems. 274 Theoretical Applications of Finite Fields 4. The inputs to the adder associated with the output terminal y1, I � i � m, are the si' each applied via a constant multiplier with constant c1J, I� j � n, and the ui, each applied via a constant multiplier with constant d,i, I .;; j.;; k. If we define u(t) � u, (y') (s' , y(t)� : , s(t)� : , Ym s" •('+')� [:;) then the operation of the circuit represented in Figure 7.5 is precisely that described in Definition 7.34(5). 7.35. Example. Let the characterizing matrices of a fourth-order LMS over F3 be: A� I� 2 0 0 �I. 0 2 I B� c� (� 0 2 6)' v�(n. I I 0 2 0 0 I I Then its realization as a circuit is shown in Figure 7.6. D ���---------------------------------- �j-:��--------------------------,r-- u,----�------------------------�---- dij �I + J!; Ym C;j �I �; fJ s, FIGURE 7.5 The realization of an LMS as a switching circuit 3. Linear Modular Systems 275 u,-.�-------------------------------------------------, ---+ -- --��-1-1 ----,_+- --+- ---+_.-+-+ ----,_,_ __ r-t--s, __ _. __________ +-�----��--+--- -+--�r-+----+-+---+� >--s, --------------��----------._ __ _. __ ��t----t-4---+----s, ----------------�----------------------._ __ _. ____ _. ____ 5, FIGURE 7.6 The switching circuit for Example 7.3�. Conversely, we can describe an arbitrary switching circuit with a finite number of adders, constant multipliers, and delay elements over IF q as an LMS over IF• as follows (provided every closed loop contains at least one delay element): I. Locate in the given circuit all delay elements and all external input and output terminals, and label them as in Figure 7.5. 2. Trace the paths from sj to s; and compute the product of the multiplier constants encountered along each path and add the products. Let a ij denote this sum. 3. Let b1j denote the correspond ing sum for the paths from u1 to s;. cij for the paths from sJ toY;· d;j for the paths from u1 toY;· Then the circuit is the realization of an LMS over F q with characterizing matrices A, B, C, D. The states and the outputs of an LMS depend on the initial state s(O) and the sequence of inputs u(t), I= 0,1, .... The dependence on these data can be expressed explicitly. 7.36. 17teorem (General Response Formula). For an LMS with characterizing matrices A, B, C, D we have: 1-1 li) s(t)=A's(O)+ L A'-'-1Bu(i) fort=l,2, ... , ;-o (ii) y(t)=CA's(O)+ L H(t-i)u(i) fort=O,l, ... , i-0 276 Theoretical Applications of Finite Fields where if I� 0, if I " I. Proof (i) Let 1 � 0 in Definition 7.34(5), then s( I) � As(O) + Bu(O), which proves (i) for 1 � 1. Assume (i) is true for some 1" I, then ( 1-1 ) s(1 +I)� A A's(O)+ 1�0 A'_1_1Bu(i) + Bu(1) proves (i) for 1 + 1. �A'•'s(O)+ L A'-'Bu(i) i=O (ii) By (i) and Definition 7.34(5) we have y(1) �c(A's(O)+ 'f.' A'-1-1Bu(i))+Du(1) .-o �CA's(O)+ L H(l-i)u(i), ;-o where H(l-i) � CA'_,_,B when 1-i" I and H(1-i) � D when 1-i � 0. D By Theorem 7.36(ii) we can decompose the output of an LMS into two components, the free component y( I )1= � CA's(O) obtained in case u( 1) � 0 for all I " 0, and the forced component y(l)ro""' � L H(l-i)u(i) i-0 obtained by setting s(O) � 0. Given any input sequence u( 1 ), 1 � 0, I, ... , and an initial state s(O), these two components can be found separately and then added up. In the remainder of this section we study the states of an LMS in the input-free case-that is, when 11(1) � 0 for all I" 0. Some simple graph- 3. Linear Modular Systems 277 theoretic language will be useful. Given an LMS GJ1L of order 11 over IF • with characteristic matrix A, the state graph of GJ!L, or of A, is an oriented graph with q" vertices, one for each possible state of GJ!L. An arrow points from state s1 to state s2 if and only if s2 � As1• In this case we say that s1 leads to s2. A path of length r in a state graph is a sequence of r arrows b1,b2, ... ,b, and r+l vertices v1,v2, ... ,vr+l such that b; points from V; to V;+b i= 1,2, ... ,r. If the v1 are distinct except v,+1 � v1, the path is called a cycle of length r. If v1 is the only vertex leading to v1 + 1, i � I, 2, ... , r -I, and the only vertex leading to v 1 is v, then the cycle is called a pure cycle. For example, a pure cycle of length 8 is given as shown in Figure 7.7. The order of a given state s is the least positive integer t such that A's � s. Thus, the order of s is the length of the cycle which inciudes s. In the following, let A be nonsingu lar-that is, det(A) "'0. It is clear that in this case the corresponding state graph consists of pure cycles only. The order of the characteristic matrix A is the least positive integer 1 such that A'� I, the n X n identity matrix. 7.37. Lemma. If 11 , ••• , t x are the orders of the possible states of an LMS with nonsingular characteristic matrix A, then the order of A is lcm(t1, ... ,1x ). Proof Let 1 be the order of A and t' � lcm(t1, ... ,1x ). Since A 's � s for every s, t must be a multiple oft'. Also, (A'"-/)s � 0 for all s, hence A'"� I. Thus t';. t, and therefore 1 � t'. D 7.38. Lemma. If A has the form A� ( �� ;,) with square matrices A1 and A2, and (:) and ( :1) are two states, partitioned according to the partition of A, with orders 11 and t2, respectively, then the orderofs�(::) is lcm(t1,t2). Proof This follows immediately from the fact that A'(::)� ( ::) if and only if A\s1 � s1 and A�s2 � s2. D FIGURE 7.7 A pure cycle of length 8. 278 Theoretical Applications of Finite Fields Let GJlt be an LMS with nonsingular characteristic matrix A. Up to isomorphisms (i.e., one-to-one and onto mappings T such that T(s1) leads to T(s2) whenever s1 leads to s2) the state graph of GJlt is characteri zed by the formal sum which indicates that n1 is the number of cycles of length 11. E is called the cycle sum of GJlt, or of A, and each ordered pair (n1, t,) is called a cycle term. Cycle terms are assumed to commute with respect to +, and we observe the convention ( n', t) + (n", t) � (n' + n", 1). Consider a matrix A of the form with square matrices A1 and A2, and suppose the state graph of A1 has n1 cycles of length 11, i�l ,2. Hence there are n111 states of the form(�) of order 11, and n212 states of the form ( :,) of order 12. By Lemma 7.38 the state graph of A must contain n1n21112 states of order lcm(11, 12) and hence n 1n21,t,/lcm( 11, 12) � n1 n2 gcd( t,. 12) cycles of length lcm(t1, 12). The product of two cycle terms is the cycle term defined by (n1, 11)·(n2, 12) � (n1n2 gcd(11, 12), lcm(11, 12)). The product of two cycle sums is defined as the formal sum of all possible products of cycle terms from the two given cycle sums. In other words, the product is calculated by the distributive law. 7.39. Theorem If A� ( �� �,) and the cycle sums of A, and A2 are E, and E2, respectively, then the cycle sum of A is E1E2• Our aim is to give a procedure for computin g the cycle sum of an LMS over IF• with nonsingular character istic matrix A. We need some basic facts about matrices. The characteristic polynomial of a square matrix M over F• is defined by det(x/-M). The minimal polynomial m(x) of M is the monic polynomial over F• of least degree such that m(M) � 0, the zero matrix. For a monic polynomial g(x)�x*+a,_,x*-'+ ··· +a,x+a0 3. Linear Modular Systems 279 over F q• its companion matrix is given by 0 0 0 0 -ao 0 0 0 -a, M(g(x)) � 0 0 0 -a, 0 0 0 -ak-1 Then g(x) is the characteristic polynomial and the minimal polynomial of M(g(x)). Let M be a square matrix over IF q with the monic elementary divisors g,(x), ... ,g,(x). Then the product g1(x) · · · gw(x) is equal to the character­ istic polynomial of M, and M is similar to M*= M(g,(x)) 0 0 M(g,(x)) 0 0 0 0 M(g,(x)) that is, M = p-l M*P for some nonsingular matrix P over g: q· The matrix M* is called the rational canonical form of M and the submatrices M(g,(x)) are called the elementary blocks of M*. Now let the nonsingular matrix A be the characteristic matrix of an LMS over IF q· For the purpose of computing its cycle sum, A can be replaced by a similar matrix. Thus, we consider the rational canonical form A• of A. Extending Theorem 7.39 by induction, we obtain the following. Let g1(x), ... ,g,.(x) be the monic elementary divisors of A and let I:, be the cycle sum of the companion matrix M(g,(x)); then the cycle sum L of A•, and so of A, is given by Let the characteristic polynomial f(x) of A have the canonical factorization ' j(x) � n pj(x)'l, j-1 where the P/ x) are distinct monic irreducible polynomials over IF q· Then the elementary divisors of A are of the form ( ),,, ( )''' ( )''' pi X , pi X , ... ,pi X I, j=l,2, ... ,r, where 280 Theoretical Applications of Finite Fields The minimal polynomial of A is equal to m(x) � n P,(x)'''. j=! It remains to consider the question of determining the cycle sum of a typical elementary block M(g,(x)) of A*, where g,(x) is of the form p(x)' for some monic irreducible factor p(x) of f(x). The following result provides the required information. 7.40. Theorem. Let p(x) be a monic irreducible polynomial over F• of degree d and lett, � ord( p(x)'). Then the cycle sum of M(p(x)') is given by . ( q'-I ) . ( q'"- q" ) . . ( q'" _ q<•-'>" ) (1,1)+-t-,-,t,+ t, ,t,+···+ t, ,t,. In summary, we obtain the following procedure for determining the cycle sum of an LMS GJlt over IF• with nonsingular characteristic matrix A: Cl. Find the elementary divisors of A, say g1(x), ... ,gw(x). C2. Let g,(x) � f,(x)m', where /;(x) is monic and irreducible over F •. Find the orders ti'' � ord(/,(x)). C3. Evaluate the orders tl'1�ord(/;(x)') for i�l,2, ... ,w and h�I,2, ... ,m, by the formula tl''�t}'1p'•, where pis the characteristic of F • and c, is the least integer such that p'•;;,. h (see Theorem 3.8). C4. Determine the cycle sum [,of M(g,(x)) for i�l,2, ... ,w according to Theorem 7.40. C5. The cycle sum L of GJlt is given by L � L 1 L 2 · · • L ... 7.41. Example. Let the characteristic matrix of an LMS GJlt over F2 be given as Here 0 0 I 0 A� 0 I 0 0 0 0 I 0 I 0 I 0 0 0 0 I 0 0 0 I I g1(x)�x'+x2+x+I� (x+I)3, f1(x)�x+I, m1�3, g2(x)�x2+x+I , f2(x)�x2+x+I . m2�1. Steps C2 and C3 yield ti" �I. tl" � 2. tl11 � 4, ti21 � 3. Hence by Theorem 4. Pseudorandom Sequences 7.40, and so L I� (1, 1)+(1, 1)+(1,2)+(1,4) � (2, 1)+(1,2)+ (1,4), I:,� (1, 1)+(1,3), L � L I L2 � [(2, 1) + (1 ,2)+ (1' 4)][(1' 1) + (1 ,3)] � (2, 1)+ (1 ,2) + (2,3)+ (1 ,4)+ (1,6) + (1' 12). 281 Thus the state graph of 'JlL consists of two cycles of length 1, one cycle of length 2, two cycles of length 3, and one cycle each of length 4, 6, and 12. 0 From C5 it follows that the state orders realizable by 'J1L are given by lcm(t<l) 1(2) /(w)) h 1 ' h1 '• • •' h., for every combination of integers h1, ••• ,h...,, 0 .:s;; h; .:s;; m;. If one wishes to compute all possible state orders realizable by 'JJL, without computing its cycle sum, one uses the following theorem. 7.42. Theorem. Let 'JlL be an LMS with nonsingular characteristic matrix A. Let the canonical factorization .of the minimal polynomial of A be m (X) � pI (X) b, · · · p, (X) b, and let tlj 1 � ord( P/ x )' ). Then the state orders realizable by 'JlL are given by all the integers of the form 4. PSEUDORANDOM SEQUENCES The notion of a random sequence of events is basic in probability theory and statistics. Let us take a standard model for the description of this notion. Consider an experiment in which an unbiased coin is flipped repeatedly. Mark down 0 for heads and 1 for tails. The result of this experiment is then a sequence of binary digits (or bits in the parlance of computer science) which will display typieal features of randomness. For instance, the relative frequency of each bit will approach !in the long run, and the relative frequency of two successive O's (or of two successive l's) will approach± in the long run. More generally, for any given block of m bits the relative frequency of this block among all the blocks of m successive bits in the sequence will approach 282 Theoretical Applications of Finite Fields rm in the long run. In short, the sequence can be expected to have all the statistical properties satisfied by a sequence of independent random variables which attain each value 0 and I with probability t. Flipping coins is thus not just an idle pastime, but can serve as a method for generating random sequences of bits. Since there is no guarantee that our coin is truly unbiased, the generated sequence should be subjected to tests for randomness. For instance, we may check the statistical quantities mentioned above-namely, the relative frequency of each bit (distribution test) and the relative frequency ofblocks of bits (serial test). Another popular test for randomness is the correlation test, which is based on the calculation of the correlation coejf JCients N-1 CN(h) = L (-!)'·-··+> (7.6) n=O of the given sequence s0, s,, ... of bits for positive integers N and h. The correlation coefficient CN(h) can be interpreted as follows: write the shifted sequence sh, s"+ 1, ... underneath the original sequence and count the agree­ ments and disagreements among the first N corresponding terms; then CN(h) is equal to the number of agreements minus the number of disagreements. For a random sequence of bits CN(h) should be relatively small compared to N. Random sequences of bits are used frequently for simulation purposes, for various applications in electrical engineering, and also in cryptography (see Chapter 9, Section 2). In practice, the generation of such sequences by coin flipping or similar physical means is problematic. First of all, the practical applications require long strings of bits, and the physical generation of all those bits may simply take too long. Furthermore, it is an established principle that scientific calculations have to be reproducible and verifiable, and this means that all the bits used in a calculation must be stored for later recall. This may tie up a lot of the computer's memory capacity. In many applications it is therefore preferable to work with sequences of bits that can be generated directly in the computer. Since the computer only responds to deterministic programs, the resulting sequences will not be random. However, we can try to generate deterministic sequences of bits that pass various tests for randomness. Such deterministic sequences are called pseudorandom sequences of bits. A commonly employed method of generating pseudorandom se­ quences of bits is based on the use of suitable linear recurrence relations in the finite field IF1. The sequences that one generates are the maximal period sequences introduced in Chapter 6. We will show that-with certain qualifications-maximal period sequences in IF2 pass the tests for randomness described above-namely, the distribution test, the serial test, and the correlation test. Since there is no extra effort involved, we will establish the relevant facts for maximal period sequences in an arbitrary finite field IF,. We are thus dealing with pseudorandom sequences of elements of IF,. 4. Pseudorandom Sequences 283 We recall from Chapter 6 that a kth-order maximal period sequence in IF q is a sequence s0, s1, ... of elements of IF q generated by a linear recurrence relation Sn+k=ak-1sn+k-1 +···+a0S11 for n=O,l, ... , (7.7) for which the characteristic polynomial x" -a"_ 1 x"-1 -· · · -a0 is a primitive polynomial over �, and not all initial values s0, .•. , s, _1 are 0. A kth-order maximal period sequence is periodic with least period r = q'-I (see Theorem 6.33). A requirement we have to impose is that r be very large, say at least as large as the total number of pseudorandom elements ofF, to be used in the specific application. In this way the periodicity of the sequence-which is a distinctly nonrandom feature-will not come into play. With this proviso we will now investigate the performance of maximal period sequences under tests for randomness. The distribution test and the serial test can be treated simultaneously. For b = (b1, ... , bm)E�; let Z(b) be the number of n, 0 � n � r-1, such that S11+1_1 = b1 for 1 � i � rn. The case m = 1 corresponds to the distribution test and was already dealt with on p. 240. The case of an m ;;, 2 corresponds to the serial test for blocks of length m. The following result shows that Z(b) is close to the ideal number rq-m provided that m is not too large. 7.43. Theorem. Ifl"i;; m,;; k and bE�;, then for any kth-order maximal period sequence in IF q we have _ {q"-m...: I forb= 0, Z(b)-•-m fi b ·o q or # . Proof. Since r=q"-1, the state vectors s0, s1, ... ,s,_1 of the se­ quence run exactly through all nonzero vectors in �;.Therefore Z(b) is equal to the number of nonzero vectors SEf: that have b as the m-tuple of their first m coordinates. For b # 0 we can have all possible combinations of elements off, in the remaining k-m coordinates of s, so that Z(b) = q•-m. For b = 0 we have to exclude the possibility that all the remaining k-m coordinates of s are 0, hence Z(b) = q'-m-I. Theorem 6.85 shows that parts of the period of a maximal period sequence also perform well under the distribution test. We now turn to the correlation test for a maximal period sequence s0, s1, ... in IF q· We first extend the definition of correlation coefficients in (7.6) to the general case. Let x be a fixed nontrivial additive character off, (compare with Chapter 5, Section I) and set N-1 CN(h) = L x(s.-s.+.l (7.8) 11=0 for positive integers N and h. For q = 2 this definition reduces to (7.6) since 284 Theoretical Applications of Finite Fields there is only one nontrivial additive character of �2 and it is given by x(O) =I, x(l) = -I. In the case N = r we can give explicit formulas for the correlation coefficients. 7.44. Theorem. For any maximal period sequence in �. with least period r we have if h = 0 mod r, if h ¢0 mod r. Proof. If h = 0 mod r, then s, = s,+, for all n;. 0 and the result follows immediately from (7.8). If h ¢ 0 mod r, then u,-s, +h• n = 0, I, ... , defines a sequence satisfying the same linear recurrence relation as s0,s1, .... By Lemma 6.4. u0, u 1, ... cannot be the zero sequence, and so it is again a maximal period sequence in� •. Applying Theorem 7.43 with m =I to this sequence, we get r-1 r-1 C,(h)= L x(s,-s,+>)= L x(u,)=(q'-1-l)x(O)+q'-1 L x(b) n=O n=O bE�: =-l+q'-1 LX(b)=-1, where we used (5.9) in the last step. D 7.45. Example. Consider the linear recurring sequence s0,s1 , ... in �2 with s,+5 = 511+2 + 511 for n = 0, 1,... and initial values s0 = s2 = s4 = 1, s1 = s3 = 0. Since x5-x2- 1 is a primitive polynomial over IF2, this sequence is a maximal period sequence in �2 with least period r = 25-I= 31. Write down the 31 bits making up the period of the sequence and underneath the first 31 terms of the sequence shifted by h = 3 terms to the left: I 0 I 0 I 0 0 0 0 I 0 0 I 0 I I 0 0 I I I I I 0 0 0 I I 0 I 0 I 0 0 0 0 I 0 0 I 0 I I 0 0 I I I I I 0 0 0 I I 0 I I I 0 The number of agreements of corresponding terms is 15, the number of disagreements is 16, hence C31(3) = 15- 16 =-I, in accordance with Theorem 7.44.1fwe consider the pairs (s,s,+ 1), n = 0, I, ... , 30, then there are 7 of type (0,0) and 8 each of type (0, 1), (1,0), and (I, 1), in accordance with Theorem 7.43. D For N < r we can give bounds for the correlation coefficients CN(h), and in the trivial case h = 0 mod r we have an explicit formula. 7.46. Theorem. For any kth-order maximal period sequence in �.and I ,;;, N < r = q'-1 we have 4. Pseudorandom Sequences and ICN(h)l«/12 -logr+-+- if h¢0modr. (2 2 N) " 5 r 285 Proof We proceed as in the proof of Theorem 7.44. If h = 0 mod r, then Un = Sn-Sn+h = 0 for all n � 0 and SO N-1 CN(h) = L x(u,) = N. n=O lfh¢0modr, then u0, u1, ... is a kth-order maximal period sequence in�. and so by Theorem 6.81, since n0 = 0 and R = r in this case. 0 If we take every second term of a random sequence of elements ofiFq, we would expect that the resulting subsequence has again randomness properties. More generally, the property of being a random sequence should be invariant under the operations of decimation defined as follows. If CJ is a given sequence s0,s1,s2, ... of elements of Fq and d� 1 and h"?-0 are integers, then the decimated sequence �hl has the terms sh, sh+tJ• sh+U• .... In other words, �hl is obtained by taking every dth term of CJ, starting from s,. The following result shows that the property of being a maximal period sequence in �.is invariant under many decimations. This can be viewed as further evidence that maximal period sequences are good candidates for pseudorandom sequences. 7.47. Theorem. Let CJ be a given kth-order maximal period sequence in � •. Then CJI'' is a kth-order maximal period sequence in �.if and only if gcd (d, q'-1) = 1, and CJI'' is a maximal period sequence in �,satisfying the same linear recurrence relation as CI(or, equivalentl y, CJI'' is a shifted version of CI) if and only if d = qimod (q'-1) for some j with 0 .;,j,;, k-1. Proof. Denote the terms of CJ and CJI'' by s, and u, respectively. The minimal polynomial of CJ is a primitive polynomial f(x) over K =�.of degree k. If� is a fixed root of f(x) in F =� ••• then� is a primitive element ofF (see Definition 3.15). By Theorem 6.24 there is a unique OEF* such that s, = Tr,1K(OIX") for all n;;. 0. It follows that u, = s .. ,, = Tr,1"(fl(ct')') for all n;;. 0, where fJ = O�EF*. Let f,(x) be the minimal polynomial of ex' over K. Then the calculation in the proof of Theorem 6.24 shows that �•> is a linear recurring sequence with characteristic polynomial f,(x). Ifgcd(d, q'-1) = 1, then ex' is a 286 Theoretical Applications of Finite Fields primitive element ofF, and so f4(x) is a primitive polynomial over K of degree k. Since f3 # 0, not all u, are 0, thus ul"' is a kth-order maximal period sequence in f,. If gcd(d,q" -1) > 1, then rl is not a primitive element ofF, and sou<,'> cannot be a kth-order maximal period sequence in f ,. The first part of the theorem is thus shown. Furthermore, u�hl is a maximal period sequence in [F4 satisfying the same linear recurrence relation as u if and only if f4(x) = f(x). By Theorem 2.14, this identity holds if and only if rl = a."1, hence d = qj mod (q'-1), for some j with 0 .;; j .;; k-1. Since the state vectors of u run through all nonzero vectors in IF:. the maximal period sequences in IF4 satisfying the same linear recurrence relation as u are exactly the shifted versions of u. D Maximal period sequences possess a universality property, in the sense that a much larger class oflinear recurring sequences can be derived from them by applying decimations. 7.48. Theorem. Let u be a given kth-order maximal period sequence in IF4. Then every linear recurring sequence in iF4 having an irreducible minimal polynomial g(x) with g(O) # 0 and deg(g(x)) dividing k can be obtained from u by applying a suitable decimation. Proof. If the terms of u are denoted by s, then as in the proof of Theorem 7.47 we have s, = Tr,1K(O�') for all n;. 0, where a: is a primitive element ofF= IF q-'<• OEF*, and K = IF4. Let u0, Up ... be a linear recurring sequence in f, with irreducible minimal polynomial g(x), where g(O) # 0 and m = deg(g(x)) divides k. Then g(x) has a root yEE = f,-, and y # 0 since g(O) # 0. Furthermore, E is a subfield ofF by Theorem 2.6. It follows that there exists an integer d;. l such that y = rl. By Theorem 6.24 we have u, = Tr,1K(f3y') for all n;. 0, where f3 E E*. Let liEF* be such that Tr,1,(<5) = {3, and choose an integer h;. 0 with /i0-1 =�•. Then by the transitivity of the trace (see Theorem 2.26) we have sh+,, = Tr,1K(e�"+"'l = Tr,1K(Iiy') = TrEIK(Tr,1 ,(1iy')) = Tr,1K(/3y') = u, for all n � 0, and so the sequence u0, u1, ... is equal to the decimated sequence �- 0 The condition g(O) # 0 in Theorem 7.48 rules out the case g(x) = x in which the sequence has the form c, 0, 0, ... with cEf:. Such a sequence has preperiod l, and thus it cannot be derived from u by a decimation since every decimated sequence u�h) is periodic. 4. Pseudorandom Sequences 287 In the special case d = 1 we write u�l = <f'l, which is the sequence obtained by shifting u by h terms. Maximal period sequences can be characterized in terms of a structural property of the set of all shifted sequences. We use again the termwise operations for sequences introduced in Chapter 6, Section 5. 7.49. Theorem. If u is a nonzero periodic sequence of elements of'F,, then the shifted sequences <f'l,h = 0, 1, ... , together with the zero sequence form a vector space over F q under termwise operations for sequences if and only if u is a maximal period sequence in F q· Proof. If u is a kth-order maximal period sequence in 'f,, then the initial state vectors of the sequences u<•l, h = 0, 1, ... , q'� 2, and of the zero sequence run exactly through all vectors in 'f:. From this it follows easily that these sequences form a vector space over f,. Note also that any shifted sequence <f'l, h;;. 0, is identical to one with 0..; h..; q' � 2. Conversely, if u is a nonzero periodic sequence of elements of 'f, with least period r, then the distinct shifted sequences are u = u<0l, u<•l, ... , .,-(•-•l. If these together with the zero sequence form a vector space V over 'f ,, then Vis closed under shifts of sequences, and so Theorem 6.56 shows that V = S(.f(x)) for some monic polynomial f(x)e'f,[x] of degree k;;. 1. Counting the number of elements of Vin two different ways we get r +I= q', hence u is a kth-order linear recurring sequence in 'f, with least period r = q'� 1. In particular, the state vectors of u run through all nonzero vectors in 'f:, and so some u<•l is the impulse response sequence with characteristic polynomial f(x). Theorem 6.27 implies that ord (f(x)) = r = q'� 1. If we had f(O) = 0, then a0 = 0 in (7.7) and the sequence in S(f(x)) with initial values 1, 0, ... , 0 has all subsequent terms equal to 0; but this nonperiodic sequence cannot belong to V, a contradiction. Thus f(O) ,< 0, and so f(x) is a primitive polynomial over 'f, by Theorem 3.16. Consequently, u is a maximal period sequence in 'f,. D 7.50. Example. Let u be the linear recurring sequence s0,s1, ... in 'f2 withsn+4= sn+l + sn for n =0,1, ... and initial values s0 =s1 =s2 =0, s3 = 1. Since x• � x � 1 is a primitive polynomial over 'f2, u is a maximal period sequence in 'f2 with least period r = 24 � 1 = 15. The 15 bits making up the period of u are 000 10011 0101 111. As an illustration of Theorem 7.48 we derive all the linear recurring sequences in 'f2 having an irreducible minimal polynomial g(x) ,< x with deg(g(x)) = 1 or 2 by applying a suitable decimation to u. The constant sequence 1, 1, 1, .. . ( = u\'l) has minimal polynomial x� 1, and the periodic sequences 0, 1, 1, .. . ( = u�'l), 1, 0, 1, ... ( = u�'l), and 1, 1, 0, ... ( = u�6l) with least period 3 represent all the linear recurring sequences in 'f 2 with minimal polynomial x2 � x � 1. As an illustration of Theorem 7.49 we note that u + u"l must be either a shifted 288 Theoretical Applications of Finite Fields version of a or the zero sequence, and in fact a+ at3l = a04'. On the other hand, if t is the linear recurring sequence t0,t1, ..• in IF2 with t,+4 = t,+3 + t, + 1 + t,+ 1 + t, for n = 0, 1, ... and initial values t0 = t 1 = t 2 = 0, t3 = 1, then r is the periodic sequence 0, 0, 0, I, I, ... with least period 5 and r + r''' is neither a shifted version oft nor the zero sequence. This is again in accordance with Theorem 7.49 since r is not a maximal period sequence in f2. 0 For many simulation purposes, and especially for applications in numerical analysis, one needs random sequences of real numbers. These numbers should all belong to a given interval on the real line, which for simplicity we may take to be the interval [0, 1]. The generation of a random sequence of numbers in [0, I] can again be described by a statistical experiment. Pick a number from [0, I] at random, where the probability that the number belongs to a specific subinterval of [0, I] should be equal to the length of the subinterval. Repeat this procedure indefinitely, with each selection being statistically independent of all the previous ones. Since we are using here a special probability distribution giving equal likelihood to subintervals of the same length, one often speaks of the resulting sequence as a sequence of unifonn random numbers. The notion of a sequence of uniform random numbers is an idealized concept, and in practice one works with a deterministic analog called a sequence of uniform pseudorandom numbers. Such a sequence is generated by a deterministic method and should pass various tests for randomness. The advantages of such a sequence are similar to those of a pseudorandom sequence of bits described earlier. Maximal period sequences in finite fields can be used to generate sequences of uniform pseudorandom numbers. Let �,be a finite prime field­ that is, pis prime-and let s0, s,. ... be a kth-order maximal period sequence in �,.In the following we view the terms s, of the sequence as integers with 0.;; s, < p. The integers s, have to be transformed into numbers in [0,1]. One method of doing this is the normalization method, in which one chooses p to be a large prime and normalizes s, by setting s, w, �-E[O, I] for all n;;, 0. p Then w0, wl·· .. is taken as a sequence of uniform pseudorandom numbers. Clearly, this sequence is periodic with least period r � p'-I. Since the sequence w0, w1, ... differs from the sequence s0, s1, ... only by a constant factor, the statistical properties of the two sequences will essentially be the same. Thus it suffices to refer to our earlier discussion of statistical properties of maximal period sequences. A second method of transforming the integers s, into numbers in [0, I] is the digital (or Tausworthe) method. Here we let p be a small prime and we choose an integer m � 1. Then we set m "' -' w, = L. Smn+t-lP i=l for all n ;;, 0, (7.9) 4. Pseudorandom Sequences 289 and we use w0, w1, ... as a sequence of uniform pseudorandom numbers. The formula (7.9) means that the sequence s0, s1, ... is split up into blocks oflength m, and each block is interpreted as the digital representation in the base p of a number in [0, 1]. In practice one usually works with the prime p = 2, since this facilitates the calculation of the terms s, by the relation (7. 7) and since in this case we get the numbers w, in their binary representation which is well suited for computer calculations. 7.51. Lemma. The sequence w0, w1, ... of numbers defined by (7.9) is periodic with least period p' -1 r---'--�­-gcd(m, p'-1)" Proof Since mr is a multiple of p'- 1 and thus a period of the maximal period sequence s0,s1, ... , we have m m "' _, "' _, w,.+,= LJ Smn+i-1+'"'P = LJ Smn+i-1P = w,. i= 1 j= 1 for all n�O. Therefore w0, w1, ... is periodic with period r. Now let u be an arbitrary period of this sequence. Then w,.+u = w,. for all n � 0, hence m m L Smn+l-1+muP-1= L Smn+l-1P-i for all n �0. i= 1 i= 1 The uniqueness of digital represent ations implies that Smn+i- 1+mu=smn+l-1 for l<.i�m and all n�O. Now mn + i-1 runs through all nonnegative integers ifi and n run through all integers with 1 � i � m and n � 0, thus s,.+mu = s,. for all n � 0. This means that mu is a period of the sequence s0, s 1, ... , and so p' -1 divides mu. It follows that r divides u, and therefore r is the least period of the sequence w0, w1,.... 0 In order to make the least period of the sequence w0, w 1, ... as large as possible, we will choose the block length min such a way that gcd(m,p'-1) = 1. The least period of the sequence is then equal top'-1 by Lemma 7.51. If we want to make this least period large for p = 2, then k should not be chosen too small. We note also that ifm > k, then the last m-k digits of any w, depend on the first k digits on account of the relation (7.7). Therefore we impose the condition m .;; k in order to prevent such obvious dependencies. An important test for randomness for a sequence w0, w1, ... of uniform pseudorandom numbers is the uniformity test. We start from the observation that in the ideal case of a sequence x0, x1, ... of uniform random numbers the 290 Theoretical Applications of Finite Fields probability that the inequality x,.; tis satisfied for a given tE [0, 1] is equal to t. We compare this with the elementary probability PN(t) that the inequality W11 �tis satisfied among the first N terms of the given sequence w0, w1,. .. - that is, PN(t) is N-1 times the number of n, 0.; n < N, with w,.; t. The largest deviation (7.1 0) O'"t<Stl between these two probabilities provides a way of measuring the extent to which w0,w1, ... differs from a sequence of uniform random numbers. For a "good" sequence of uniform pseudorandom numbers the value of DN should be small for large N. When applying the uniformity test to a periodic sequence w0, w 1, •.. with least period r, it suffices to consider the case 1 :s; N � r since the behavior of the sequence repeats itself beyond the period. 7.52. Theorem. If m.; k and gcd(m, p'-!) = 1, then the sequence w0, w1,... of uniform pseudorandom numbers generated by (7.9) satisfies D,=p-m with r=pk-l. Proof Theleast period ofw0, w1, ... isr = p' -1 by Lemma 7.51. The sequence of m-tuples sn = (s,l, sn+ 1• ... ,Sn+m-1 ), n = 0, I, ... ' also has least period r; in other words, s, just depends on the residue class of n modulo r. From gcd(m, r) = 1 it follows then that the finite sequence smn• n = 0, 1, ... , r-I, is a rearrangement of the finite sequence sn, n = 0, 1, ... ,1·-l. In particular, for any bE{0,1, ... ,p-l}m the number of n, 0 � n � r-I, with smn = b is the same as the number of n, 0 � n � r-1, with s, =b. The latter number is given by Theorem 7.43. Together with (7.9) this yields the following information: the number of n, 0.; n.; r-1, with W11 = 0 is equal to pk-m-I, and for any rational number cp-m with cElL, I � c < p'", the number of n, 0 � n � r-1, with W11 = cp-"' is equal to pk-m; this exhausts all possible values of W11• For a ElL, 0 �a< p"', consider a real t with ap-m.;t<(a+ 1)p-m. Then and so Now 1 P,(t) = -(pk-m-1 + ap'-m), r a+ 1 1 0< ---t�-p"' p'" 4. Pseudorandom Sequences and hence Since 0 1-(a+ l)p-m 1-p-m .;; 't .;;,! p- p-I p"-1 I _. __ ,:: _ p'" pk.- I -...;:; pm' and P,(l) = I, it follows from (7.10) that D, = p -m. 291 0 Theorem 7.52 shows that if m is chosen sufficiently large, then the sequence w0, w1, ... passes the uniformity test when considered over the full period. For parts of the period-that is, for I .;; N < r-we can establish an upper bound for the quantity DN in (7.10). Let w0, w1, ... be a sequence of elements of [0, I] whose terms are given by finite digital representations m W-' cn-i n-01 "-L. wP p ' -, ' ... ' 1=1 (7.11) where the digits w�" belong to the set {0, I, .... p-I} and m is independent of n. For h EZ we define e,(h) = e(h/p), where e(t) is the complex exponential function used in Chapter 6, Section 7: 7.53. Lemma. Let w0,w1, ... be a sequence of elements of [0, I] given by (7.11) and let N be a positive integer. Let B be a constant such that for any h1, ••• , hmE{O, I, ... , p-I} that are not all 0 we have II N-1 I -" e (h wC11 + .. · + h w1"1) "' B NL.p ln mn-...;:; n=o Then the quantity DN in (7.10) satisfies I (2 7) DN .;; - + Bm -Iogp +-. p" " 5 Proof For 0.;; t <I let 00 r = L tjp-i 1=1 (7.12) be the digital representation oft in the base p, with t, E {0, I, ... , p-I} for all i;;. I and the usual condition that t1 <p-I for infinitely many i. Then we have w,�t if and only if w�11=t1, ... ,w�-11=ti-l• w�0<t1 for some i with 1 � i � m-1 (for i = I the condition reduces to w�u < t d or w:/ 1 = t1, ... ,w:;"-11=tm-I• w�m)�l111• Thus, if we put u1=ti-I for l�i�m-1 292 Theoretical Applic- .ttions of Finite Fields and um = tm and interpret empty sums to be equal to 0, then 1 m u; N-1 PN(t)= N ,f:1 1f:0 Jo d,,(w;1')· .. (d,,_,(w�-1')diw�'), where d/w) = 1 for j = w and d1(w) = 0 for j # w with j, wE{O, 1, ... , p -1). Now and so tp-1 d/w) =-L e,(h(w-j)), Ph=O ·e,(-h1t1-···- h1_1t1_1-h1j). Separating the contribution from the choice h1 = · · · = h1 = 0 in the inner sum and denoting by an asterisk the deletion of the corresponding term, we get Using m U· + 1 m 1 p-1 PN(t)= L -' -,-+ L--; L e,(-h1t1-···-h,_1t1_1) i=l P i"'lP hJ ••••• h;=O 1 N-1 u; ·-L e (h w1" + · · · + h.w"') L e (-hJ) N n=O p 1 n I n j=O p . I f: U; � 1 -t I ,; _!,. i=l p p and the condition (7.12), we obtain IPN(t)-tl,; _!,. + B t � I;_ It e,(hJ)I p 1-1 p hJ ..... hj-0 J-0 1 m 1 p-1 I .. I ,;Pm+B,f:1pr ,,, .. �,�o ;f:o e,(hj). =.,+-L L L e,(hj). 1 B m p-11 "' I p p i=l h=O )=0 By Lemma 6.80 we have and so L L e,(hj) <-plogp+-p+u1+1 ,;-plogp+-p, ,-1 I .. I 2 2 2 7 h=Oj=O 1t 5 7t 5 IPN(t)-tl,; _1_ + Bm(�logp + �) pm 7t 5 for 0,; t < 1. Since PN(1) = 1, the desired result follows. D 4. Pseudorandom Sequences 293 7.54. Theorem. Let m .;; k and gcd(m, p' -!) � I, and let w0, w1, ... be the sequence of uniform pseudorandom numbers generated by (1.9). Then for I ,;; N < r � p'-l the quantity DN in (7.10) satisfies I mp'l2 (2 2 N)(2 7) DN.;;-+ ---logr+-+--logp+-5 . pmNn 5rn Proof The bound for DN is obtained from Lemma 7.53 by determin­ ing a suitable constant B such that (7.12) holds. If thew. are given by (7.9), then we have w�il = sm��+i-1 for 1 � i � m and all n � 0. Thus We note that for any hEZ we have e,(h) � x1(h), where X1 is the canonical additive character of�, (see Chapter 5, Section I) and on the right-hand side we identify h with the corresponding element of �,-namely, with the residue class of h modulo p. If we now identify all h, and s. with the corresponding elements of IF" and define then we can write m V11 = L hism��+i-1 ElF" for all n;;,. 0, 1=1 tN-1 lN-1 -'<:' e (h w"1 + · · · + h w<ml) �-L X (v ). (7.13) N PI �0 l' 1 PI m PI N n = 0 1 PI Since s0, st> ... is a kth-order maximal period sequence inK= IF P' we get.as in the proof of Theorem 7.47 s. � Tr,1x(Ga") for all n � 0, where a is a primitive element ofF��,.. and e EF*. Suppose h1, ... , hm E �,are not all 0. Then v. � ,t1 h, TrF/K(e�•+ i-1) � TrF/K ( e ,t1 h,am•+i-1) � TrF/x(f3y") for all n � 0, where m P=O L h,.ai-1 and y=a"'. i= 1 Since m .;; k and {I, a, a2, ... , a•-1} is a basis of F over K, we have {3 of 0. Furthermore, the condition gcd(m,p'-I)� I implies that y is a primitive element of F. Theorem 6.24 and its proof show then that v0, v1, ... is a kth­ order maximal period sequence in K. Thus 11 N-1 I p''2(2 2 N) -I x1(v.l <--logr+-+- for N .�o N n 5 r ! .;;N<r (7.14) 294 Theoretical Applications of Finite Fields by Theorem 6.81, since n0 � 0 and R � r in this case. Taking into account (7.13), we can therefore use the expression on the right-hand side of(7.14) as a possible value of B in condition (7.12). The rest follows from Lemma 7.53. D In the proof of Theorem 7.52 we have obtained the exact distribution of values in the least period of the sequence w0, w1, ... generated by (7.9), under the conditions rn.;; k and gcd(m,p'-1) � 1. With these hypotheses we can show an analogous result for higher dimensions d as long as d .;; k(rn. For such a d we consider the d-tuples w,.=(W,11W11+1, ...• w,.+d-tlE[0,1]d ·for O�n�r -1, where r = pk-1 is the least period of the sequence w0, w1, .... Each w,. is ad­ tuple of the form (7.15) with cJE7L and 0 � cj < pm for 1 � j �d. Consider also the sequence of rnd­ tuples which has again least period r. The same argument as in the proof of Theorem 7.52 shows that for any bE{O, 1, ... ,p-1 }'""the number ofn, 0.;; n .;; r -1, with sm,. = b is the same as the number ofn, 0 � n � r-1, with S11 =b. The latter number can be obtained from Theorem 7.43 since the condition on d yields rnd.;; k. In this way we arrive at the following result: the number of n, 0 � n � r-1, with w,. = 0 is equal to pk-md-1, and for any c-=/=-0 of the form (7.15) the number of n, 0.;; n .;; r-1, with w. �cis equal to p'-m'. Thus the d­ tuples w. show a very regular distribution behavior. The study of the distribution of the w. amounts to performing an analog of the serial test for random sequences of bits described earlier in this section. We can therefore say that a sequence w0, w1, ... of uniform pseudorandom numbers generated by (7.9) passes the serial test for dimensions d.;; k(rn, at least when it is considered over the full period. Results for parts of the period can be obtained by an extension of the method in the proof of Theorem 7.54. EXERCISES 7.1. List the points and lines of PG(2,F3). Draw a diagram showing all the intersections. Enumerate the points on LIXJ and the families of parallel lines in AG(2,1F3). 7.2. In PG(2, F4) consider the quadrangle A(l, 1, 1 + fl), B(O, 1, fl), C(l, l,fl), D(l, 1 + fl,fl), where fl is a primitive element of F4. Find its diagonal points and verify that they are collinear. 7.3. There are six points in PG(2,1F4), no three of which are collinear. Exercises 295 Four of them are the points A, B, C, D of Exercise 7.2. Find the other two points. 7.4. Find the equation of the conic consisting of the points A, B, C, D of Exercise 7.2 and E(l, I + {J, I + {J), determine all its tangents and the point where they meet. 7.5. Show that for a nondegenerate conic in PG(2,f5) the tangents do not all meet in the same point. 7.6. Prove: if L is a set of points of PG(2,1F .l such that every line of PG(2,1F•) contains a point of L, then ILl;. q +I with equality if and only if L is a line. 7.7. Prove that among any m + 3 points of a finite projective plane of order m one can find three collinear ones. 7.8. Determine the number of points, lines, planes, and hyperplanes of PG( 4,1F 3 ). How many planes are there through a given line? 7.9. In PG(4,1F3) determine the 3-flats through the plane given by (1,0,0,0,0), (0,0,1,0,0), and (0,0,0,0, 1). 7.10. Prove that the number of k-flats of PG(m,IF .), I"' k < m, or also within a fixed m-flat of a projective geometry over IF q of higher dimension, is equal to (qm+l_J)(qm-l)···(qm-k+\_1) (qk+ I -J)(qk -J)· • • (q -I) 7.11. Show that the following system of blocks forms a BIBD and evaluate the parameters v, b, r, k, and A: (1,2,3) (1,4,7) (1,5,9) (1,6,8) �.�� ��� ��n ��� (7,8,9) (3,6,9) (3,4,8) (3,5.n 7.12. Solve the following special case of the Kirkman Schoolgirl Problem. A schoolmistress takes 9 girls for a daily walk, the girls arranged in rows of 3 girls. Plan the walk for 4 consecutive days so that no girl walks with any of her classmates in any triplet more than once. 7.13. In a school of b boys, t athletics teams of k boys each are formed in such a way that every boy plays on the same number of teams. Also, the arrangement is such that each pair of boys plays together the same number of times. On how many teams does a boy play and how often do two boys play on the same team? 7.14. Prove: if vis even for a symmetric ( v, k, A) block design, then k-A is a square. 7.15. Verify that (0,1,2,3,5,7,12,13,16) is a difference set of residues modulo 19. Determine the parameters v, k, and A. 7.16. Show that (0,4,5, ?)'is a difference set of residues modulo 13 which yields PG(2,1F 3 ). 296 Theoretical Applications of Finite Fields 7.17. Prove the following generalization of Theorem 7.20. Let {d,, ... ,d,.}, i�l, ... ,s, 7.18. 7.19. 7.20. 7.21. 7.22. 7.23. 7.24. 7.25. 7.26. 7.27. 7.28. 7.29. 7.30. be a system of (v, k, A) difference sets. Then with all residues modulo v as varieties, the vs blocks (d, + t, ... ,d,k + 1}, t � 0, l, ... ,v -I and i � l, ... ,s, form a (v,k,As) block design. Let L(*> � (a)J1), where a)J' = i + jkmod9, 0 .;; a),•' < 9 for I.;; i, j .;; 9. Which of the arrays L(kl, k � 1,2, ... ,8, are latin squares? Are L (ll and L (SI orthogonal? A latin square of order n is said to be in normalized form if the first row and the first column are both the ordered set (1,2, ... ,n}. How many normalized latin squares of each order n .;; 4 are there? Let L be a latin square of order m with entries in (I, 2, ... , m} and M a latin square of order n with entries in (1,2, ... ,n). From Land M construct a latin square of order mn with entries in {1,2, .. .,m}X (1,2,. .. ,n}. Construct three mutually orthogonal latin squares of order 4. Prove that for n;. 2 there can be at most n-I mutually orthogonal latin squares of order n. A magic square of order n consists of the integers I to n2 arranged in an n -X n array such that the sums of entries in rows, columns, and diagonals are all the same. Let A� (a,) and B � (b1j) be two orthogonal latin squares of order n with entries in (0, l, .. .,n -I} such that the sum of entries in each of the diagonals of A and B is n(n -1)/2. Show that M � (na,1 + b11 +I) is a magic square of order n. Construct a magic square of order 4 from two orthogonal latin squares obtained in Exercise 7.21. Determine Hadamard matrices of orders 8 and 12. If Hm and H. are Hadamard matrices, show that there exists a Hadamard matrix Hm,· Show that from a normalized Hadamard matrix of order 41, t ;. 2, one can construct a symmetric (4r -1,2t-l, t-I) block design. Prove that the state graph of an LMS over IF • with non singular characteristic matrix consists of pure cycles only. Prove that the state graphs of similar characteristic matrices over IF q are isomorphic. (Note: Two matrices A, B over IF• are similar if there exists a nonsingular matrix P over F q such that B �PAP-'.) Suppose the characteristic matrix A of an LMS � over IF2 has the minimal polynomial (x + l)'(x' + x + 1)3. What are the state orders realizable by �? Determine the orders of all states in the LMS �of Example 7.41. Exercises 297 7.31. 7.32. 7.33. 7.34. Suppose the characteristic matrix A of an LMS 0R over IF, is nonderoga tory; that is, its minimal polynomial is equal to its char­ acteristic polynomial. Let the minimal polynomial of A be of the form p(x )', where p(x) is a monic irreducible polynomial over IF • of degree d. Without using Theorem 7.40, prove that the cycle sum of GJn. is given by the expression in that theorem. Calculate the cycle sum of the LMS GJn. over F 3 given in Example 7.35. Prove Theorem 7.42. Let s0,s1, ... be a kth-order maximal period sequence in IF, and let N = d(q' -1)/(q-I) for some positive integer d. If ZN(O) denotes the number of n, 0,;; n,;; N-I, such that s, = 0, prove that d(q'-1-1) ZN(O) = . q-1 7.35. Let s0• s,. ... be a kth-order maximal period sequenee in IF,. For I ,;;m ,;;k, I ,;; N <r=</-1, and b=(b1, ... ,bm)EIF; let ZN(b) be the number of n, 0 � n � N-1, such that sn+i-I = bi for 1 � i � m. Prove that IZ.,(b)-Nq-ml ,;;(l-q-m)q'12 -logr+-+-. (2 2 N) n 5 r 7.36. Let s0, s1, ... be a periodic sequence of elements of IF, with least period r. For fixed cEIF, we say that a run of c of length m;;, I occurs if s, #' c, s,+i = c for 1 � i � m, and s,+m+ 1 '# c for some n with 0 � n � r-1. Prove that for a kth-order maximal period sequence in IF, with r = </ -I ;;, 2 exactly the following runs occur. For I ,;; m ,;; k -2 and any cEIF, there are (q-1)2</-m-2 runs of c oflength m. The number of runs of c of length k-1 is q -1 for c = 0 and q -2 for c #' 0. There is no run of 0 of length k, and there is one run of c of length k for every c #' 0. No runs of length > k can occur. 7.37. Prove: If u is a periodic sequence with period r, then the decimated sequence rrl" has period rfgcd(d, r). Use a suitable decimation of the sequence u in Example 7.50 to show that this result does not hold in general if "period'" is replaced by "least period". 7.38. Prove the following converse of Theorem 7.48: any decimated sequence of a kth-order maximal period sequence in lF q is either the zero sequence or a linear recurring sequence in lFq having an irreducible minimal polynomial g{x) with g(O) #' 0 and deg(g(x)) dividing k. 7.39. Let u be a given kth-order maximal period sequence in IF,. Prove that every kth-order maximal period sequence in IF, is equal to a shifted version of cr�0' for some d. 7.40. Let u be a nonzero periodic sequence of elements of1F2 with least period 298 Theoretical Applications of Finite Fields r. Prove that if for every h with I ,s; h ,s; r-I the sequence u + u''' is a shifted version of u. then u is a maximal period sequence in IF2• 7.41. Prove that for any maximal period sequence in�. there exists a shifted version u of the sequence such that u�0l =a. 7.42. Let s0, s1, ... be a kth-order maximal period sequence in the finite prime field IF P and view the terms sn oft he sequence as integers with 0:::;;; sn < p. For positive integers m and d define m "' -i Wn = L. Sdn+i-lP i= 1 for n = 0, I, .... Prove that if gcd(d, p'-I)= I, then the sequence w0, w1, ... is periodic with least period p'-I. Chapter 8 Algebraic Coding Theory One of the major applications of finite fields is coding theory. This theory has its origin in a famous theorem of Shannon that guarantees the existence of codes that can transmit information .at rates close to the capacity of a communication channel with an arbitrarily small. probability of error. One purpose of algebraic coding theory-the theory of error-correcting and error­ detecting codes-is to devise methods for the construction of such codes. During the last two decades more and more abstract algebraic tools such as the theory of finite fields and the theory of polynomials over finite fields have influenced coding. In particular, the description of redundant codes by polynomials over IF, is a milestone in this development. The fact that one can use shift registers for coding and decoding establishes a connection with linear recurring sequences. In our discussion of algebraic coding theory we do not consider any of the problems of the implementation or technical realization of the codes. We restrict ourselves to the study of basic properties of block codes and the description of some interesting classes of block codes. Section I contains some background on algebraic coding theory and discusses the important class of linear codes in which encoding is performed by a linear transformation. A particularly interesting type of linear code is a cyclic code-that is, a linear code invariant under cyclic shifts. Our study of cyclic codes in Section 2 includes a description of what is possibly the most widely known family of codes, the BCH codes named after Bose, Ray-Chaudh uri, and Hocquenghem. BCH codes can be implemented easily and permit a fast decoding algorithm. The Goppa codes discussed in Section 3 can be viewed as 299 300 Algebraic Coding Theory generalized BCH codes. Goppa codes allow a much wider choice of parameters than BCH codes, but can still be decoded efficiently. If the decoding algorithm for Goppa codes is specialized to BCH codes, one obtains a second way of decoding BCH codes. 1. LINEAR CODES The problem of the communication of informati on-in particular the coding and decoding of information for the reliable transmission over a "noisy" channel-is of great importance today. Typically, one has to transmit a message which consists of a finite string of symbols that are elements of some finite alphabet. For instance, if this alphabet consists simply of 0 and I, the message can be described as a binary number. Generally the alphabet is assumed to be a finite field. Now the transmission of finite strings of elements of the alphabet over a communication channel need not be perfect in the sense that each bit of information is transmitted unaltered over this channel. As there is no ideal channel without "noise," the receiver of the transmitted message may obtain distorted information and may make errors in interpreting the transmitted signal. One of the main problems of coding theory is to make the errors, which occur for instance because of noisy channels, extremely improbable. The methods to improve the reliability of transmission depend on properties of finite fields. A basic idea in algebraic coding theory is to transmit redundant information together with the message one wants to communicate; that is, one extends the string of message symbols to a longer string in a systematic manner. A simple model of a communication system is shown in Figure 8.1. We assume that the symbols of the message and of the coded message are elements of the same finite field IF •. Coding means to encode a block of k message symbols a1a2 · • • ak., a; E IF q• into a code word c1c2 ···en of n symbols cj E F,1, where n > k. We regard the code word as an n-dimensional row vector c in F;. Thus fin Figure 8.1 is a function from IF: in to IF;, called a coding scheme. and g: IF; -+ IF; is a decoding scheme. Message Coded Message a c Decoded Message g a c+e FIGURE 8.1 A communication system. ,...----''-----, ..--­ +-------"Noise .. '-----,--__J -- 1. Linear Codes 301 A simple type of coding scheme arises when each block a1a2 ···a, of message symbols is encoded into a code word of the form where the first k symbols are the original message symbols and the addi­ tional n -k symbols in F., are control symbols. Such coding schemes are often presented in the following way. Let H be a given (n-k)X n matrix with entries in F q that is of the special form where A is an (n-k)X k matrix and I._, is the identity matrix of order n-k. The control symbols ck+ 1 .... ,c. can then be calculated from the system of equations HcT �o for code words c. The equations of this system are called parity-check equations. 8.1. Example. Let H be the following 3X7 matrix over F2: Then the control symbols can be calculated by· solving HcT � 0. given cl' c2• cJ• c4: c, �o �o + c7� 0 The control symbols c5• c6, c1 can be expressed as cs=cl +c3+c4 c6=c1+c2 +c4 c7=c1 + c2+ cJ Thus the coding scheme in this case is the linear map from 1Ft into rFi given by D In general, we use the following terminology in connection with coding schemes that are given by linear maps. 302 Algebraic Coding Theory 8.2. Definition. Let H be an (n-k)Xn matrix of rank n-k with entries in IFq. The set C of all n-dimensional vectors c E F; such that HcT = 0 is called a linear ( n. k) code over I',; n is called the length and k the dimension of the code. The elements of Care called code words (or code vectors), the matrix His a parity-check matrix of C. If q � 2, Cis called a binary code. If II is of the form (A, 1, ..• ). then Cis called a systematic code. We note that the set C of solutions of the system HcT � 0 of linear equations is a subspace of dimension k of the vector space F;. Since the code words form an additive group. Cis also called a group code. Moreov er, C can be regarded as the null space of the rna trix H. 8.3. Example (Purity-Check Code). Let q � 2 and let the given message be a1 • • • ak, then the coding scheme/is defined by where h; =a; fori= I. ... ,k and Hence it follows that the sum of digits of any code word b, .. ·bk+ 1 is 0. If the sum of digits of the received word is I, then the receiver knows that a rransmission error must have occurred. Let n = k + I. then this code is a binary linear ( n, n -I) code with parity-check matrix H � (II · · · I). D 8.4. Example (Repetition Code). In a repetition code each code word consists of only one message symbol a1 and n-I control symbols c2 = ··=en all equal to a1: that is. a1 is repeated n -I times. This is a linear (n, I) code with parity-check matrix H � ( -1, /,_1). D The parity-check equations HcT � 0 with H �(A, I,_,) imply where a= a1 ••• ak is the message and c = c1• ··en is the code word. This leads to the following definition. 8.5. Definition. The k X n matrix G � U •. -AT) is called the canonical generator matrix of a linear (n, k) code with parity-check matrix H � (A,l,_k). From HcT � 0 and c � aG it follows that Hand G are related by (8.1) The code C is equal to the row space of the canonical generator matrix G. More generally, any k x n matrix G whose row space is equal to C is called 1. Linear Codes 303 a generator matrix of C. A genera tor rna trix G of C can be used for encoding­ namely, a message a is encoded by c =aGE C. 8.6. Example. The canonical genera tor rna trix for the code defined by H in Example 8.1 is given by G =I� 0 0 0 I I l I· I 0 0 0 I D 0 I 0 I 0 0 0 I I I 8. 7. Definition. If c is a code word and y is the received word after communication through a "noisy" channel, then e = y-c = e 1 • • • en 1s called the error word or the error vector. 8.8. Definition. Let x,y be two vectors in F;. Then: (i) the Hamming distance d(x,y) between x andy is the number of coordinates in which x and y differ; (ii) the (Hamming) weight w(x) of x is the number of nonzero coordinates of x. Thus d(x,y) gives the number of errors if x is the transmitted code word and y is the received word. It follows immediately that w(x) = d(x,O) and d(x.y) = w(x-y). The proof of the following lemma is left as an exercise. 8.9. Lemma. The Hamming distance is a metric on n:;; that is, for all x,y,z E F�' we have: (i) d(x, y) = 0 if and only if x = y; (ii) d(x,y) = d(y,x); (iii) d(x,z).;; d(x.y)+ d(y,z). In decoding received words y, one usually tries to find the code word c such that w(y-c) is as small as possible, that is, one assumes that it is more likely that few errors have occurred rather than many. Thus in decoding we are looking for a code word c that is closest to y according to the Hamming distance. This rule is called nearest neighbor decoding. 8.10. Definition. For I EN a code c <;: r; is called t-error-correcting if for any y E IF; there is at most one c E C such that d(y,c) .;;r. If c E C is transmitted and at most t errors occur, then we have d(y, c).;; 1 for the received word y. If C is t-error-corr ecting, then for all other code words z"' c we have d(y,z) > 1, which means that cis closest toy and nearest neighbor decoding gives the correct result. Therefore, one aim in coding theory is to construct codes with code words "far apart." On the other hand, one tries to transmit as much information as possible. To reconcile these two aims is one of the problems of coding. 304 8.11. Definition. The number de� min d(u,v) � min w(c) U,"EC O""cEC ·-· is called the minimum distance of the linear code C. Algebraic Coding Theory 8.12. Theorem. A code C with minimum distance de can correct up to 1 errors if de ;> 21 +I. Proof A ball B,(x) of radius t and center x E F; consists of all vectors y E F; such that d(x,y).; t. The nearest neighbor decoding rule ensures that each received word with 1 or fewer errors must be in a ball of radius 1 and center the transmitted code word. To correct/ errors, the balls with code words x as centers must not overlap. If u E B,(x) and u E B,(y). x,y E C, x '* y, then d(x,y) .; d(x,u)+ d(u,y).; 21. a contradiction to de� 2t +I. D 8.13. Example. The code of Example 8.1 has minimum distance de � 3 and therefore can correct one error. 0 The following lemma is often useful in determining the minimum distance of a code. 8.14. Lemma. A linear code C with parity-check matrix H has minimum distance de� s + 1 if and only if any s columns of H are linearly independent. Proof Assume there are s linearly dependent columns of H, then HcT � 0 and w(c).; s for suitable c E C, c"' 0. hence de.; s. Similarly, if any s columns of H are linearly independent. then there is no c E C, c "'0, of weight .;; s, hence de;> s +I. D Next we describe a simple decoding algorithm for linear codes. Let C be a linear (n, k) code over F •. The vector space F;;c consists of all cosets a+C�(a+c:cEC} with aEIF;. Each coset contains qk vectors and IF; can be regarded as being partitioned into cosets of C -namely, where a<0> � 0 and s � q•-k -l. A received vector y must be in one of the cosets, say in aCil +C. If the code word c was transmitted, then the error is given by e � y-c � aUl + z E aU>+ C for suitable z E C. This leads to the following decoding scheme. 8.15. Decoding of Linear Codes. All possible error vectors e of a received 1. Linear Codes 305 vector y are the vectors in the coset of y. The most likely error vector is the vector e with minimum weight in the coset of y. Thus we decode y as x = y-e. The implementation of this procedure can be facilitated by the coset-leader algorithm for error correction of linear codes. 8.16. Definition. Let C � o:; be a linear (n, k) code and let F;;c be the factor space. An element of minimum weight in a coset a+ C is called a coset leader of a+ C. If several vectors in a+ C have minimum weight, we choose one of them as coset leader. Let a11 1, ..• , a<•> be the coset leaders of the cosets * C and let c<'l = 0, c'21, .•. ,c1•'• be all code words in C. Consider the following array: c<l) c<2> aOl +c(ll a<ll +c<2) column of coset leaders c(q' l } row of code words a<'> +c<•'1 l ; remaining cosets a<sl +c<q*> If a word y = a<'l +c"1 is received, then the decoder decides that the errore is the corresponding coset leader a<". and decodes y as the code word x = y-e = cli1; that is, y is decoded as the code word in the column of y. The coset of y can be determined by evaluating the so-called syndrome of y. 8.17. Definition. Let H be the parity-check matrix of a linear (n, k) code C. Then the vector S(y) = Hy T of length n-k is called the syndrome of y. 8.18. Theorem. For y,z Eo:; we have: (i) S(y) = 0 if and only if y E C; (ii) S(y) = S(z) if and only if y+ C = z +C. Proof (i) follows immediately from the definition of C in terms of H. For (ii) note that S(y) = S(z) if and only if Hy T = HzT if and only if H(y-z)T = 0 if and only if y-z E C if and only if y + C = z +C. D If e = y-c, c E C, y E f;, then S(y) = S(c+e) = S(c)+ S(e) = S(e) (8. 2) and y and e are in the same coset. The coset leader of that coset also has the same syndrome. We have the following decoding algorith m. 8.19. Coset-Leader Algorithm. Let C � F; be a linear ( n. k) code and let 306 Algebraic Coding Theory y be the received vector. To correct errors in y, calculate S(y) and find the coset leader, say e, with syndrome equal to S(y). Then decode y as x � y-e. Here xis the code word with minimum distance toy. 8.20. Example. Let C be a binary linear (4,2) code with generator matrix G and parity-check matrix H: G � (� 0 n H� (� 1 n 1 0 The corresponding array of cosets is: message row 00 10 01 11 code words 0000 1010 0111 1101 m 1000 0010 1111 0101 (�) other cosets 0100 1110 0011 1001 ( : ) 0001 1011 0110 1100 m ..____..__-� coset syndromes leaders If y � 1110 is received, we could look where in the array y occurs. But for large arrays this is very time consuming. Therefore we find S(y) first-namely. S(y) � Hy T � (:)-and decide that the error is equal to the coset leader 0100 that also has syndrome (:).The original code word was most likely the word 1010 and the original message was 10. 0 In large linear codes it is practically impossible to find coset leaders with minimum weight: for example, a linear (50,20) code over F2 has some 109 cosets. Therefore it is necessary to construct special codes in order to overcome such difficulties. First we note the following. 8.21. Theorem. In a binary linear (n, k) code with parity-check matrix H the syndrome is the sum of those columns of H that correspond to positions where errors have occurred. Proof Let y E IF;' be the received vector, y � x+e, x E C; then from (8.2) we have S(y) � HeT. Let i1, i2, .•• be the error coordinates in e, say e � 0 · · · 0 1. 0 · · · 0 1. 0 · · · then S(y) � h + h + · · · where h. denotes IJ 12 ! /1 11 > I the i th column of H. 0 If all columns of H are different, then a single error in the ith 1. Linear Codes 307 posii!On of the transmitted word yields S(y) � h1, thus one error can be corrected. To simplify the process of error location, the following class of codes is useful. 8.22. Definition. A binary code C.., of length n � 2"' -I, m ;;. 2, with an m X (2"'-I) parity-check matrix His called a binary Hamming code if the columns of H are the binary representations of the integers I, 2, ... , 2"' -I. m-1. 8.23. Lemma. Cm is a 1-error-correcting code of dimension 2m- Proof By definition of the parity-check matrix H of C..,, the rank of H is m. Also, any two columns of H are linearly independent. Since H contains with any two of its columns also their sum, the minimum distance of C.., equals 3 by Lemma 8.14. Thus C.., is !-error-correcting by Theorem 8.11 D 8.24. Example. Let C3 be the (7,4) Hamming code with parity-check matrix H� (� 0 0 I I I ll· I I 0 0 I 0 I 0 I 0 If the syndrome of a received wordy is, say, S(y) �(I 0 l)T, then we know that an error must have occurre<! in the fifth position, since I 0 I is the binary representation of 5. o Hamming codes can also be defined in the non binary case- that is, over arbitrary finite fields F.. Here the parity-check matrix H is an m X(q"' -1)/(q -I) matrix that has pairwise linearly independent col­ umns. Such a matrix defines a linear ((q"' -1)/(q -I), (q"' -1)/(q -I) -m) code of minimum distance 3. Next we describe some relationships between the length n of code words, the number k of information or message symbols, and the minimum distance d c of a linear code over IF q· 8.25. Theorem (Hamming Bound). Let C be a t-error-correcting code over F • of length n with M code words. Then M(I+(7)(q-l)+ ··· +(�)(q-IJ').;q". Proof There are (; )( q -I)"' vectors with n coordinates in F • of weight m. The balls of radius I centered at the code words are all pairwise disjoint and each of the M balls contains 1+(7)(q-l)+ ... +(;)(q-1)' vectors of all the q11 vectors in F;. D 308 Algebraic Coding Theory 8.26. Theorem (Plotkin Bound). For a linear (n, k) code Cover F, of minimum distance d c we have d nq*-'(q-1) c� k · q -l Proof Let l..; i...; n be such that C contains a code word with nonzero i th component. Let D be the subspace of C consisting of all code words with i th component zero. In C I D there are q elements which correspond to q choices for the ith component of a code word. Thus I Ci/IDI =I C/DI implies IDI = q*-1• By counting along the components, the sum of the weights of the code words in C is then seen to be ...; nq*-'(q -1). The minimum distance de of the code is the minimum nonzero weight and therefore must satisfy the inequality given in the theorem since the total number of code words of nonzero weight is q* -l. 0 8.27. Theorem (Gilbert-Varshamov Bound). There exists a linear (n, k) code over Fq with minimum distance� d whenever d-2 q"-*> L (n�l)(q-l)'. '� 0 Proof We prove this theorem by constructing an ( n -k) X n parity-check matrix H for such a code. We choose the first column of Has any nonzero (n-k)-tuple over IF,. The second column is any (n-k)-tuple over IF, that is not a scalar multiple of the first column. In general, suppose j-l columns have been chosen so that any d-l of them are linearly independent. There are at most dt'(j-l)(q-1)' i-0 I vectors obtained by linear combinations of d-2 or fewer of these j -1 columns. If the inequality of the theorem holds, then it will be possible to choose a jth column that is linearly independent of any d -2 of the first j-1 columns. The construction can be carried out in such a way that H has rank n-k. The resulting code has minimum distance � d by Lemma 8.14. 0 We define the dual code of a given linear code C by means of the following concepts. Let u=(u1, ... ,u,), v=(v1, ..• ,v,)EF;, then u·v= u1v1 + · · · + u,v, denotes the dot product of u and v. If u·v = 0, then u and v are called orthogonal. 8.28. Definition. Let C be a linear (n, k) code over F,. Then its dual (or orthogonal) code C" is defined as C" ={uEIF;:u·v=O forallvEC}. The code Cis a k-dimensional subspace of F;. the dimension of C" 1. Linear Codes 309 is n-k. C � is a linear (n, n-k) code. It is easy to show that C � has generator matrix H if C has parity-check matrix H and that C � has parity-check matrix G if C has generator matrix G. Considerable information on a code is obtained from the weight enumeration. For instance, to determine decoding error probabilities or in certain decoding algorithms it is important to know the distribution of the weights of code words. There is a fundamental connection between the weight distribution of a linear code and of its dual code. This will be derived in the following theorem. 8.29. Definition. Let A; denote the number of code words c E C of weight i, 0 " i " n. Then the polynomial • A(x,y)= I: A;x;y•-; ;�o in the indeterminates x andy over the complex numbers is called the weight enumerator of C. We shall need characters of finite fields, as discussed in Chapter 5. 8.30. Definition. Let x be a nontrivial additive character of f • and let v · u denote the dot product of v,u E F;. We define for fixed v E F; the mapping x,:IF;-->c by x,(u)=x(v·u) foruEIF;. If Vis a vector space over C and fa mapping from F; into V, then we define g1: F;--> V by g1(u)= I: .x,(u)f(v) foruEF;. Y eF; 8.31. Lemma. Let E be a subspace ofF;, E � its orthogonal comple­ ment, f:F; --> V a mapping from IF; into a vector space V ooer C and x a nontrivial additive character ofF q· Then L g1(u)=IEI L f(v). uE E Proof I: g,(u) = I: I: x,(u)f(v) = I: I: x(v·u)f(v) UE£ UE£YE f; YEF;uE£ =lEi L f(v)+ L L L x(c)f(v). YE£.1 yf£;£.1cEfqy�:-=£c For fixed v 'f. E �, u E E,... v·u is a nontrivial linear functional onE, thus L g1(u)=IEI L f(v)+@l L !(•) L x(c)=IEI L f(v), UE£ \'E£.1 q yf£:£.1 cEfq yE£.1 by using (5.9). D 310 Algebraic Coding Theory We apply this lemma with V as the space of polynomials in two indeterminates x and y over C and the mapping f defined as f(v) = xw(•lyn-w(•l, where w(v) denotes the weight of v E rF;. 8.32. Theorem (MacWilliams Identity). Let C be a linear (n, k) code over IF • and C " irs dual code. If A ( x. y) is the weight enumerator of C and A" ( x, y) is the weight enumerator of C ". then A" (x, y) = q-'A(y -x,y +(q-l)x). Proof Let f:F; --+C[x, y] be as given above, then the weight enumerator of C .1 is A"(x.y)= L f(v). 'E CJ. Let g1 be as in Definition 8.30 and for v E F q define { I if v * 0, lvl= 0 ifv=O. For u = (u1,. .. ,un) E IF; we have g,(u) = L x(v·u)x•C•>y•-•<•> ¥ Ef; L x(u1v1 + ... + u,v,)xlvtl+ ··+lv�ly(l-lvtll+···+{l-lv�l) v1 •.•• V11Efq " E n [x(u,v,Jx'""y'-'"·'] v1 •••• v�Efql-1 " = n E [x(u,vJx1"1y'-1"1]. i-1 oEf'l For u, = 0 we have x(u,v) = x(O) =I, hence the corresponding factor in the product is ( q-l)x + y. For u, * 0 the corresponding factor is y+x E x(vJ=y-x. v Ef; Therefore. g1(u) = (y-x)"'"'(y +(q-l)x)"-"'"1• Lemma 8.31 implies ICIA"(x.y)=ICI L /(v)= L g1(u)=A(y-x.y+(q-l)x). ¥EC_j_ uEC Finally, I Ci = q• by hypothesis. 0 8.33. Corollary. Let x = z and y =I in the weight enumerators A ( x. y) and A" ( x. y) and denote the resulting polynomials by A( z) and 2. Cyclic Codes 311 A" ( z ). respectively. Then the Mac Williams identity can be wrillen in the form A"(z)�q-k(I+(q-l)z)"A( ;-z) )· I+ q-1 z 8.34. Example. Let C,, be the binary Hamming code of length n � 2"' -I and dimension n-mover IF2. The dual code C,;t has as its generator matrix the parity-check matrix H of C,,. which consists of all nonzero column vectors of length m over IF 2. Cm.l. consists of the zero vector and 2m - 1 vectors of weight 2m-I. Thus the weight enumerator of Cm.l. IS y" +(2"' -l)x2·-'y'·-•-1. By Theorem 8.32 the weight enumerator for C.., is given by A(x. y) � n � 1 [(y + x)" + n(y-x )'"+'112(y + x)'"-111']. Let A(z)�A(z,l)-that is, A(z)�L:;_0A,z'-then one can verify that A(z) satisfies the differential equation dA(z) " (l-z2)� +(I +nz)A(z) �(I+ z) with initial condition A(O) � A0 �I. This is equivalent to iA,� c� I )-A,_1-(n-i+2)A,_2 fori� 2,3, ... ,n with initial conditions A0 �I. A1 � 0. D 2. CYCLIC CODES Cyclic codes are a special class of linear codes that can be implemented fairly simply and whose mathematical structure is reasonably well known. 8.35. Definition. A linear. ( n, k) code C over IF q is called cyclic if ( a0, a, .... ,a,_,) E C implies (a,_,, a0, ... ,a,_,) E C. From now on we impose the restriction gcd(n, q) �I and let (x"-I) be the ideal generated by x"-IE F q[x ]. Then all elements ofF .[x ]/(x" -I) can be represented by polynomials of degree less than n and clearly this residue class ring is isomorphic to IF; as a vector space over IF q· An isomorphism is given by Because of this isomorphism, we denote the elements of F•[x]/(x" -I) either as polynomials of degree < n modulo x" -I or as vectors or words over F •. We introduce multiplication of polynomials modulo x" -I in the 312 Algebraic Coding Theory usual way; that is, iff E IF,[x]/(x" -I), g1, g2 E IF0[x], then g1g2 �/means that g1g2 = fmod(x"-1). A cyclic (n, k) code C can be obtained by multiplying each message of k coordinates (identified with a polynomial of degree < k) by a fixed polynomial g(x) of degree n-k with g(x) a divisor of x" -I. The poly­ nomials g(x ), xg(x ), ... , x'-1g(x) correspond to code words of C. A gener­ ator matrix of C is given by go g, gn-k 0 0 0 0 go g, gn-k 0 0 G� 0 0 0 0 go g, gn-k where g(x) � g0 + g1x + · · · + g,_,x"-'. The rows of G are obviously linearly independent and rank (G)� k, the dimension of C. If h(x) � (x" -1)/g(x) � h0 + h1x + · · · + h,x'. then we see that the matrix 0 0 0 h, h,_, ho 0 0 0 h, h,_, ho 0 H� h, h,_, ho 0 0 is a parity-check matrix for C. The code with generator matrix His the dual code of C, which is again cyclic. Since we are using' the terminologies of vectors (a0, a1, ••• ,a,_1) and polynomials a0 + a1x + · · · + a11_1x"-1 over IFq synonymously, we can interpret Cas a subset of the factor ring IF,[x]/(x" -I). 8.36. Theorem. The linear code C is cyclic if and only if C is an ideal ofiF,[x]/(x" -I). Proof If Cis an ideal and (a0, a1, .•. ,a.,_1) E C, then also x(a0+a1x+ ··· +a11_1x"-1)=(a11_1,a0, •.• ,a11_2)EC. Conversely, if (a0,a1, •.. ,a,1_1)EC implies (a,_1,a0, ..• ,a11_2)EC, then for every a(x) E C we have xa(x) E C, hence also x2a(x) E C. x3a(x) E C, and so on. Therefore also b(x)a(x) E C for any polynomial b(x); that is, C is an ideal. D Every ideal of IF,[x]/(x" -I) is principal; in particular, every non­ zero ideal C is generated by the monic polynomial of lowest degree in the ideal, say g( x ). where g( x) divides x" -I. 2. Cyclic Codes 311 8.37. Definition. Let C � (g(x)) be a cyclic code. Then g(x) is cafled the· generator polynomial of C and h(x) � (x" - I )/g( x) is called the parlty"chee� polynomial of C. Let x" -I� /1(x)/2(x)· · ·/..,(x) be the decomposition of x" -I in to monic irreducible factors over IF q· Since we assume gcd( n, q) � I, there are no multiple factors. If /;(x) is irreducible over IF•, then (/;(x)) is a maximal ideal and the cyclic code generated by /;(x) is called a maximal <yclic code. The code generated by (x" -1)//;(x) is called an irreducible cyclic code. We can find all cyclic codes of length n over Fq by factoring x"-1 as above and taking any of the 2m-2 nontrivial monic factors of x" -1 as a genera tor polynomial. If h(x) is the parity-check polynomial of a cyclic code C S::: IF.[x]/(x"-1) and v(x)EF9[x]/(x"-l), then v(x)EC if and only if v(x)h(x) = Omod(x"-1). A message polynomial a(x) � a0 + a1x + · · · + a,_,xk-l is encoded by C into w(x) � a(x)g(x), where g(x) is the genera­ tor polynomial of C. If we divide the received polynomial v(x) by g(x), and if there is a nonzero remainder, we know that an error occurs. The canonical generator matrix of C can be obtained as follows. Let deg((g(x)) � n-k. Then there are unique polynomials aj(x) and r1(x) with deg(r/x)) < n -k such that X1 � a i (X) g (X)+ 1j (X). Consequently, x' -r,(x) is a code polynomial, and so is gj(x) � x'(x' -r,(x)) considered modulo x" -I. The .. polynomials g1(x), j � n-k, ... ,n -I, are linearly independent and form the canonical generator matrix (1,,-R), where I, is the k x k identity matrix and R is the k x ( n-k) matrix whose i th row is the vector of coefficients of rn-k-1 +;(x ). 8.38. Example. Let n � 7, q � 2. Then x' -I� (x + I)(x3 + x + I)(x3 + x2 +I). Thus g(x) � x3 + x2 +I generates a cyclic (7,4) code with parity-check polynomial h( x) � x4 + x3 + x2 + I. The correspon ding canonical generator matrix and parity-check matrix is, respectively, I 0 0 0 I 0 �I. G� 0 1 0 0 I 1 0 0 1 0 I 1 0 0 0 1 0 1 H� ( f 1 0 1 0 �). 1 1 0 1 D 0 1 0 0 314 Algebraic Coding Theory We recall from Chapter 6 that iff E f•[x] is a polynomial of the form /(x)�/0+ /,x+ ··· + /,x', fo*O,f,�l. then the solutions of the linear recurrence relation k L �a,+1�0. i�O.I. .... j�O are periodic of period n. The set of then-tuples of the first n terms of each possible solution, considered as polynomials modulo x" -I, is the ideal generated by g(x) in IFq[x]/(x" -I), where g(x) is the reciprocal poly­ nomial of (x" -1)//(x) of degree n-k. Thus linear recurrence relations can be used to generate code words of cyclic codes, and this generation process can be implemented on feedback shift registers. 8.39. Example. Let /(x) � x' + x +I, a factor of x7 -I over IF,. The associated linear recurrence relation is a;+J +a;+ 1 +a;= 0, which gives rise to a (7,3) cyclic code, which encodes Ill, say, as Ill 00 I 0. The generator polynomial is the reciprocal polynomial of (x7 -1)//(x); that is, g(x) � x4 + x3 + x2 + 1. 0 Cyclic codes can also be described by prescribing certain roots of all code polynomials in a suitable extension field of IF q· The requirement that all code polynomials are multiples of g(x), a generator polynomial, simply means that they are all 0 at the roots of g(x ). Let a1, ... , a, be elements of a finite extension field of IF q and p,( x) be the minimal polynomial of a, over IF q for i � I, 2, ... ,s. Let n EN be such that a; � 1, i � I, 2, ... ,s, and define g(x)�lcm(p1(x), ... ,p,(x)). Thus g(x) divides x"-1. If C<:::IF; is the cyclic code with generator polynomial g(x), then we have v(x) E C if and only if v (a) � 0, i � I, 2, ... , s. As an example of the concurrence of the description of a cyclic code by a generator polynomial or by roots of code polynomials we prove the following result, which uses the concept of equivalence of codes in Exercise 8.10. 8.40. Theonm. The binary cyclic code of length n �2m-I for which the generator polynomial is the minimal polynomial over IF 2 of a primitive element of!F2• is equivalent to the binary (n, n-m) Hamming code. Proof Let a denote a primitive element of IF2• and let p(x)�(x-a)(x-a2)···(x-a1"-') be the minimal polynomial of a over IF 2. We now consider the cyclic code C generated by p(x). We construct an m X (2m-1) matrix H for which thejth column is (c0, c1, .• ,em-JlT if m-l al-l= L c1a1, j=l,2 .... ,2m-l, i = 0 2 Cyclic Codes 315 where c, E F2. If a� (a0, a1,. .. ,a,_1) and a(x) � a0 + a1x + · · · + a, _1x"-1EF2(x], then the vector HaT corresponds to the element a(a) expressed in the basis (1, a,. .. ,a'"-1). Consequently, HaT� 0 holds exactly when p(x) divides a(x), so H is a parity-check matrix of C. Since the columns of H are a permutation of the binary representations of the numbers 1, 2, .. ., 2'" � 1, the proof is complete. D 8.41. Example. The polynomial x4 + x +I is primitive over F2 and thus has a primitive element a of IF 16 as a root. If we use vector notation for the 15 elements ai E Fi6• j � 0, I, ... , 14, expressed in the basis (I, a, a2, a3) and we form a 4 X 15 matrix with these vectors as columns, then we get the parity-check matrix of a code equivalent to the (15, 11) Hamming code. A message (a0, a1, .. .,a10) is encoded into a code polynomial w(x) � a(x)(x4 +x + 1), where a(x} � a0 + a1x + · · · + a10x10 Now suppose the received poly­ nomial contains one error: that is. w(x)+ x�-1 is received when w(x) is transmitted. Then the syndrome is w( a)+ ae-1 = ae-1 and the decoder is led to the conclusion that there is an error in thee th position.· D 8.42. Theorem. Let C � F.(x]/(x" � 1} by a cyclic code with gener­ ator polynomial g and let a1,. .. , a,_. be the roots of g. Then f E IF .lx ]/(x" � 1) is a code polynomial if and only if the coefficient vector (/0, ••• ,f,_ 1) of/ is in the null space of the matrix a, a' I . ·a�-I H� (8.3) an-k a�-k ,_, a,,-k Proof Let/(x)�/0+/1x+ ··· +f,_1x"-1; then/(a,}�/0+/1a, + · · · + /,,_1a�-l = 0 for I� i � n-k, that is, (I, a,, ... ,a;-\ )(/0,/1, ..• ,f,_1)T � 0 for I .;;, i.;;, n � k, if and only if H(/0,f1, ..• ,f,_1)T �o. D We recall from Section I that for error correction we have to determine the syndrome of the received wordy. In the case of cyclic codes, the syndrome, which is a column vector of length n � k, can often be replaced by a simpler entity serving the same purpose. For instance, let a be a primitive nth root of unity in IF q" and let the generator polynomial g be the minimal polynomial of a over IF •. Since g divides f E IF•[x]/(x" �I) if and only if f(a) � 0, it suffices to replace the matrix H in (8.3) by H �(I a a2 The.o the role of the syndrome is played by S(y) � Hy T, and S(y) � y( a) since v�(v,.,v, .. .,v .. _,) can be regarded as a oolvnomial vlx) with 316 Algebraic Coding Theory coefficientsy,. In the following we use the notation w for a transmitted word and v for a received word, and we write w(x) and v(x), respectively, for the corresponding polynomials. Suppose eUl(x) � xr 1 with 1 .;; j.;; n is an error polynomial with a single error, and let v = w+ eCJl be the received word. Then v( a)� w( a)+ eUl( a)� e(}l( a)� a;-I e'11(a) is called the error-location number. S(v) � af-l indicates the error uniquely, since e'''( a)* eU1( a) for I.; i.; n with i * j. Before describing a general class of cyclic codes and their decoding, we consider a special example to motivate the theory. ' 8.43. Example. Let a E IF 16 be a root of x4 + x +I E f2[x ], then a and a3 have the minimal polynomials m'''(x) � x4 + x +I and m0'(x) � x4 + x' + x2 + x +I over IF2, respective ly. Both m'"(x) and m'''(x) are divisors of x"-I. Hence we can define a binary cyclic code C with generator poly­ nomial g � m'"m"'· Since g divides f E IF2[x]/(x" -I) if and only if f( a)�/( a')� 0, it suffices to replace the matrix H in (8.3) by H � (: :, :: :�: ) . We shall show (see Theorem 8.45 and Example 8.47) that the minimum distance of C is � 5, therefore C can correct up to 2 errors. C is a cyclic ( 15, 7) code. Let 14 14 sl = L v,.ai and SJ = L V;a]i i=O ,-o be the components of S(v) � Hv T Then v E C if and only if S(v) � Hv T � 0 if and only if S1 � S3 � 0. If we use binary notation to represent elements of IF 16, then H attains the form I 0 0 0 I 0 0 I I 0 0 I I 0 I 0 0 I I 0 I 0 I I 0 0 0 0 I 0 0 I I 0 I 0 I I I 0 H� 0 0 0 I 0 0 I I 0 I 0 I I I I I 0 0 0 I I 0 0 0 I I 0 0. 0 I 0 0 0 I I 0 0 0 I I 0 0 0 I I 0 0 I 0 I 0 0 I 0 I 0 0 I 0 I 0 I I I I 0 I I I I 0 I I I The columns of Hare calculated as follows: the first four entries of the first column are the coefficients in I�l·a0+0·a1+0·a2 +O·a'. the first four entries of the second column are the coefficients in a= 0· a0 + 1 · a1 + 0 · a2 + 0 · a3, and so on: the last four entries of the first column are the coefficients in I �I· a0 + 0 ·a' + 0 · a2 + 0 ·a', the last four entries of the 2. Cyclic Codes 317 second column are the coefficients in a3 = 0 · a0 + 0 · a1 + 0 · a2 + 1 · a3, and so on. We use a4 +a+ 1 = 0 in the calculations. Suppose the received vector v = ( v0, ...• v 14) has at most two errors; for example, e(x) = X01 + xu2 with 0 � a1, a1 � 14, a1 * a1. Then we have Let 111 = 0:01, 112 = a0l be the error-location numbers, then s, � �, + �,. s, � �l + ��. therefore hence 1 + s,�,-' +(Si + s,s,-')�1' � o. If two errors occurred, then 11]1 and 1121 are roots of the polynomial s(x)�l+S1x+(Si+S3S!')x2 (8.4) If only one error occurred, then S1 ��,and S3 � �l. hence S/ + S3 � 0: that IS, s(x) �I+ S1x. (8.5) If no error occurred. then S 1 � S3 � 0 and the correct code word w has been received. To summarize, we first evaluate the syndrome S(v) � Hv T of the received vector v, then determine s(x) and find the errors via the roots of s( x ). The polynomial in (8.5) has a root in F 10 whenever S1 ""0. If s( x) in (8.4) has no roots in F"' then we know that the error e(x) has more than two error locations and therefore cannot be corrected by the given (15, 7) code. More specifically, suppose v�IOOIIIOOOOOOOOO is the received word. Then S(v) � ( �:) is given by For the polynomial s(x) in (8.4) we obtain s(x) �I +(a2 + a3)x + [1 +a+ a2 + a3 +(I+ a2)(a2 + a3)-']x2 � I + ( a2 + a3) X + (I + a + a3) x 2 We determine the roots of s(x) by trial and error and find a and a7 as roots. Hence we have 11]1 =a, 1121 = a7, thus 111 = a14, 112 = a8. Therefore, we 318 Algebraic Coding Theory know that errors must have occurred in the positions corresponding to x8 and x14, that is, in the 9th and 15th position of v. The transmitted code word must have been w �I 00 I I I 00 I 00000 I. The code word w is decoded by dividing the corresponding polynomial by the generator polynomial g. This gives I+ x3 + x5 + x6 with remainder 0. Hence the original message was I 00 I 0 I I. D 8.44. Definition. Let b be a nonnegative integer and let a E IF •" be a primitive nth root of unity, where m is the multiplicative order of q modulo n. A BCH code over F• of length nand designed distanced, 2.;; d .;; n, is a cyclic code defined by the roots of the generator polynomial. If mU1(x) denotes the minimal polynomial of a' over F •. then the generator polynomial g(x) of a BCH code is of the form g(x) � lcm(m1•1(x), mib+ii(x), ... ,m'•+d-li(x)). Some special cases of the general Definition 8.44 are also important. If b �I, the corresponding BCH codes are called narrow-sense BCH codes. If n � qm-I, the BCH codes are called primitive. If n � q-I, a BCH code of length n over F• is called a Reed-Solomon code. 8.45. Theorem. The minimum distance of a BCH code of designed distance dis at least d. Proof The BCH code is contained in the null space of the matrix a• a'• 0:(11-l)b ab+l al<b+ IJ o:<n-l}(b+ I) H� a.b+d-1 o:l(b+d-2) o:<n-l)(b+d-2) We show that any d-I columns of this matrix are linearly independent. Take the determinant of any d-I distinct columns of H, then we obtain abi1 abi1 Q.biJ_ 1 a<b+ Ili1 a<b+ JJi2 a<b+ IJio�-1 a<b+d-2Ji1 a<b+d-2)12 0:(b+d-2)iJ-I 2. Cyclic Codes a'• =ab(i1+i2+···+iJ_1J n (ai1_ai")*0. 1110k<j .;;cJ-l Therefore the minimum distance of the code is at least d. 319 D 8.4<i. Example. Let m'n(x) � x4 + x +I be the minimal polynomial over F1 of a primitive element a E F 16. We represent the powers a;, 0 :s;;; i :s;;; 14, as linear combinations of I, a, a2, a3 and thus obtain a parity-check matrix H of a code equivalent to the (15, II) Hamming code: H� �� 0 0 0 I 0 0 I I 0 0 I I �I I 0 0 I I 0 I 0 I I I I 0 0 I 0 0 I I 0 I 0 I I I I 0 0 I 0 0 I I 0 I 0 I I I �(I a a' a' a• a' a• a' a• a' aw a'' a" a" a\4). This code can also be regarded as a narrow-sense BCH code of designed distanced� 3 over f2 (note that a2 is also a root of m'''(x)). Its minimum distance is also 3, and it can therefore correct one error. In order to decode a received vector v E IF)', we have to find the syndrome Hv T For this cyclic (15,11) code the syndrome is given as v(a) in the basis {I, a, a2, a3). It is obtained by dividing v(x) by m'''(x), say v(x) � a(x)m">(x)+ r(x) with deg(r(x)) < 4, for then o(a) � r(a); that is, the components of the syn­ drome are equal to the coefficients of r(x). For instance, let v�OIOIIOOOIOIIIOI, then r(x) �I+ x, hence HvT�(IIOO)T�l+a. Next we have to find the error e with weigbt w(e).; I and having the same syndrome. Thus we must determine the exponent j, 0.; j.; 14, such that ai � Hv T In our numerical example j � 4, thus in the received vector v the fifth position is in error and the transmitted word was w�OIOIOOOOIOIIIOI. D 8-47. Example. Let q � 2, n � 15, and d � 4. Then x4 + x +I is irreduc­ ible over IF2 and its roots are primitive elements ofF 16• If a is such a root, then a1 is a root, and a3 is then a root of x4 + x3 + x 2 + x + 1. Thus a 320 Algebraic Coding Theory narrow-sense BCH code with d � 4 is generated by g(x) � (x4 +x + I)(x4 +x3 +x2 +x + 1). This is also a generator for a BCH code with d � 5, since a4 is a root of x4+x+l. The dimension ofthiscodeis 15-deg(g(x))�7. This code was considered in greater detail in Example 8.43. D BCH codes are very powerful since for any positive integer d we can construct a BCH code of minimum distance ;;, d. To find a BCH code for a larger minimum distance, we have to increase the length n _and hence increase the number m -that is, the degree of IF,. over IF,. A BCH code of designed distance d ;;, 2t + I will correct t or fewer errors, but at the same time, in order to achieve the desired minimum distance, we musf use code words of great length. We describe now a general decoding algorithm for BCH codes. Let us denote by w(x), v(x), and e(x) the transmitted code polynomial, the received polynomial, and the error polynomial, respectively, so that v(x) � w(x)+ e(x ). First we have to obtain the syndrome of v, where S(v) � Hv T � (S,, s,+ I• ... ,Sb+d-2) T' S, � v ( a1) � w ( al) + e ( al) � e ( a1) for b .; j.; b + d -2. If r � t errors occur, then e(x) � L c,x"•. i-1 where a 1, .... a, are distinct elements of {0, 1,. .. , n -I). The elements 1), � a"• E IF q"' are called error-location numbers. the elements c; E IF; are called error values. Thus we obtain for the syndrome of v, s,�e(al)� L C,1); forb.;j.; b+d-2. i-1 Because of the computatio nal rules in IF q"' we have ( ' )' ' ' S' � "' C1)J � "' c'1J'" � "' C1J'" � S ) £... I I £... I I £... I I jq• i=l t=l i=l (8.6) The unknown quantities are the pairs ( 11,. c;). i = 1. ... ,r, the coordinates S1 of the syndrome S(v) are known since they can be calculated from the received vector v. In the binary case any error is completely characterized by the lJ; alone. since in this case all ci are I. In the next stage of the decoding algorithm we determine the 2. Cyclic Codes 321 coefficients a1 defined by the polynomial identity ' 0(7,-x)� L (-l)'a,_,x1 i= l i=O =ar-ar--lx+ ... +(-l)raoXr. Thus o0 =I and o1 .... ,or are the elementary symmetric polynomials in 11t····•11r· Substituting 11i for x gives (-I)'a,_+(-l)'-1a,_1,,+ ··· +(-l)a1,;-1+,;�o fori�I, ... ,r. Multiplying by c111( and summing these equations fori� I, ... ,r yields (-f)' a,� + (-I)'-1 a,_ 1S1+ 1 + · · · + (-I) a1S1+,-1 + s,+, � 0 forj�b,b+l .... ,b+r-1. 8.#J. Lemma. The system of equations L;c,,f ��. j�b,b+l, ... ,b+r-1, ,-1 in the "nknowns c, is solvable if the 11, are distinct elements of IF; .... Proof The determinant of the system is "� b+l ,, � ,�,� · · . ,� n ( ,, -,, J * o. o l'(;i<J'(;r yfr+r-1 8.49. Lemma. The system of equations (-I)'a,�+(-I)'-1a,_1S1+1+ ··· +(-l)a1S1+<_1+S,+,�o. j � b, b + 1, ... ,b + r-I, in the unknowns ( -1)1a1, i � 1,2, ... ,r, is solvable uniquely if and only if r errors occur. Proof The matrix of the system can be decomposed as follows: s. sb+l sb+r-l sb+l sb+2 sb+r �VDVT, sb+r-1 sb+r sb+2r-2 322 where 'h v� ,_, ,, and C11Jt 0 D� 0 'lz ,_, ,, 0 Cz1J� 0 ,_, ,, 0 0 Algebraic Coding Theory The matrix of the given system of equations is nonsingular if and only if V and D are nonsingular. V as a Vandermonde matrix is nonsingular if and only if the"'' i � l, ... ,r, are distinct and Dis nonsingular if and only if all the Tl; and C; are nonzero. Both condi tions are satisfied if and only if r errors occur. 0 We introduce the error-locator polynomial that is closely related to the considerations above: i-0 where the a, are as above. The roots of s(x) are '1\'. '12' .... ,TJ;'-In order to find these roots, we can use a search method due to Chien. First we want to know if an-I is an error-location number-that is, if a= a-tn-IJ is a root of s(x). To test this we form -a1a + a2a2 + · · · + (-I)' a,.a'. If this is equal to -I, then an-I is an error-location number since then s(a) � 0. More generally, a•-m is tested form� 1,2, ... ,n in the same way. In the binary case, the discovery of error locations is equivalent to correct­ ing errors. We summarize the BCH decoding algorithm, writing now ,, for (-l)'a,. 8.50. BCH Decoding. Suppose at most 1 errors occur in transmitting a code word w, using a BCH code of designed distance d;. 21 + I. Step 1. Determine the syndrome of the received word •, S(•) � (s •. s.+, .... sb+a-,)T. 2. Cyclic Codes Let Sj= Lc;1J/, b�j�b+d- 2. i-1 323 Step 2. Determine the maximum number r.;; t such that the system of equations Sj+r+Sj+r-1T1+ ··· +Sj'Tr=O, b�j�b+r-1, in the 'T; has a nonsingular coefficient matrix, thus obtaining the number r of errors that have occurred. Then set up the error-locator polynomial , s(xl � n (1-�,xl � L v'. i-1 i-0 Find the coefficients T' from the sj. Step 3. Solve s(x)� 0 by substituting the powers of a into s(x). Thus find the error-location numbers �� (Chien search). Step 4. Introduce the �� in the first r equations of Step l to determine the error values c;. Then find the transmitted word w from w(x) � v(x)-e(x). 8.51. Remark. We note that the difficult step in this algorithm is Step 2. There are various methods to perform this step, one possibility is to use the Berlekamp-Massey algorithm of Chapter 6 to· determine the unknown coefficients -r; in the linear recurrence relation for the Sj. D 8.52. Example, Consider a BCH code with designed distance d � 5 that is able to correct any single or double error. In this case, let b � l, n �IS, q � 2. If mU>(x) denotes the minimal polynomial of a' over IF2, where the primitive element a E F 16 is a root of x4 + x + l, then mn'(x) � m'''(x) � m'.,(x) � m"'(x) � l + x + x4, m"'(x) � m"'(x) � m'12'(x) � m'9'(x) � l + x + x2 + x3 + x4 Therefore a generator polynomial of the BCH code will be g(x) � mn'(x)m"'(x) � l + x4 + x6 + x1 + x8. The code is a ( 15, 7) code, with parity-check polynomial h(x) � (x" -1)/g(x) � l + x4 + x6 + x1. We take the vectors corresponding to g(x ), xg( x), x2g(x), x3g(x ), x4g( x), x'g( x), x6g( x) 324 Algebraic Coding Theory as the basis of the (I 5, 7) BCH code and obtain the generator matrix I 0 0 0 I 0 I I I 0 0 0 I 0 0 0 I 0 I I I 0 0 0 I 0 0 0 I 0 I I I G� 0 0 0 I 0 0 0 I 0 I I 0 0 0 0 I 0 0 0 I 0 I 0 0 0 0 0 I 0 0 0 I 0 0 0 0 0 0 0 I 0 0 0 I Suppose now that the received word v is or as a polynomial. I 0 0 I 0 0 I I 0 0 0 0 I 0 0, v(x) �I+ x3 + x' + x1 + x12 0 0 0 0 0 0 I 0 I I I I 0 I We calculate the syndrome according to Step I, using (8.6) work: sl�e(a)�v(a)�l. S2 � e(a2) � v(a') �I, S3 � e(a3) � v(a3) � a4, S4 � e ( a4) � v ( a4) � I. 0 0 0 0 0 0 0 0 0 0 I 0 I I to simplify the The largest possible system of linear equations in the unknowns 1, (Step 2) is then of the form or s,11 + S11, � s,. S3T1 + S2-r2 = S4• Tl+T2=a4, a4T1+T2=1. This system clearly has a nonsingular coeff icient matrix. Therefore two errors must have occurred-that is, r = 2. We solve this system of equations and obtain 11 �I, 12 �a. Substituting these values into s(x) and recalling To= I gives s(x)�l+x +ax2 As roots in IF 16 we find 71]1 = o:&, 1Ji-1 = cl', hence 711 = a1, 112 = a9. There­ fore, we know that errors ml1St have occurred in positions 8 and 10 of the code word. We correct these errors in the received polynomial and obtain w( X) � V (X)-e (X) �(l+x3+x'+x'+x12)-(x1+x9) =l+x3+x6+x9+x12. 3. Gappa Codes 325 The corresponding code word is I 0 0 I 0 0 I 0 0 I 0 0 I 0 0. The initi�l message can be recovered by dividing the corrected polynomial -that is, the transmitted code polynomial w(x)-by g(x). This gives w(x)/g(x) �I+ x' + x4, which yields the corresponding message word I 00 II 00. D 3. GOPPA CODES We generalize the narrow�sense BCH codes introduced in Section 2 to obtain an important class of linear codes which still allow an efficient decoding algorithm and which are also useful for applications in cryptography (see Chapter 9, Section 4). These codes meet the Gilbert-Varshamov bound in Theorem 8.27 at least asymptotically. To motivate the definition of this class of codes, we first go back to narrow-sense BCH codes and present another characterization of their code words. We recall that narrow-sense BCH codes correspond to the special case b = 1 of Definition 8.44. A narrow-sense BCH code over � 4 of length n and designed distance d is thus the cyclic code defmed by the roots a, a:2, ... ,�-I of the generator polynomial, where a:EG=4 ... is a primitive nth root of unity. We characterize the code words of this code by using an identity in the polynomial ring � .-[x]. 8.53. Lemma. (c0,c1, ... ,c11_J)EIF; is a code word of the narrow-sense BCH code over�, defined by the roots a, a2, ... , a•-I oft he generator polynomial if and only if 11-1 xd-1 -a:-i<d-1) "'C·"'l(d-1) 0 L. ,.... I . t=o x-a: (8.7) Pmof. By definition, (c0, c 1, ... , c,._1) is a code word of the given code if and only if •-1 L c1rrY=O for 1 �j�d-1. i=O On the other hand, we have 11-1 . xd-1_CJ:-1Cd-1l L CiCJ:i(d-1) i i=O X-CJ: 11-1 d-2 " l(d-1)" -i(d-2-j) J L. Cit>: L. a: X i=O }=0 = ''t' ("'t1 c,ai!)xi-1, )=I f=O and so (c 0, c 1, ... , c, _dis a code word if and only if the identity (8. 7) holds. 0 This result provides the motivation for the following definition of Goooa codes over L 326 Algebraic Coding Theory 8.54. Definition. Let g(x) be a polynomial of degree t, I .;; t < n, over an extension F,-off,, and let L= {y0, y1, ... ,y,_1) be a set ofn distinct elements of�,-such that g(y1) # 0 for 0 .;; i.;; n-I. The Goppa code r(L, g) over f, with Goppa polynomial g(x) is the set of all (c0, c1, ... , c,_1)E�; such that the identity 0 (8.8) holds in the polynomial ring f ,-[x]. If g(x) is irreducible over F,-, then r(L, g) is called an irreducible Goppa code. 8.55. Example. If g(x) = x'-1 and L= (a-': i = 0, I, ... , n-1}, where aEf ,­ is a primitive nth root of unity, then r(L,g) is a narrow-sense BCH code over f, of length n and designed distance d. 0 It is clear that r(L,g) is a linear code, since the condition (8.8) defines a subspace of the vector space f;. We want to find a matrix such that the intersection of its null space with f; is equal to r(L,g). If then g(x)-g(y) x-y ' g(x)= L gy.i, J-o Putting h,=g(y,)-1 for O.;;i.;;n-1, it follows that (c0,c, ... ,c,_1)Ef; satisfies (8.8) if and only if ,-1( ' ) L h, L g/1/_1_' c, = 0 for 0.;; s .;; t-I. i=O J-s+l Therefore r(L,g) is the intersection ofF; with the null space of the matrix ho�:, h,_1g, h0(g,_1 +g,yo) h,_1(g,_1 +g,y,_1) Since g, # 0, we can use row operations to transform this into the matrix ( g(y0)-1 ... g(y,_1)-1 l H= g(yo):-1Yo ··· g(y,-1):-1Y•-1 , g( )-1 •-1 g( )-1.;-1 Yo Yo Yn-l ln-1 (8.9) for which the intersection of its null space with f; is again r(L,g). The entries of Hare elements off,-. Each element of�.-has a unique representation in a fixed basis off,- over f ,. A matrix H' with ent!jesin f, having r(L,g) as its null 3. Gappa Codes 327 space can thus be obtained by replacing each entry of H by the column vector over f, of length m that we get from the coefficients in that representation. 8.56. Theorem. The dimension of the Goppa code r(L, g) is at least n -mt and its minimum distance is at least t + 1. Proof. The matrix H' described above is an mt x n matrix with entries in F,. Since r(L,g) is the null space of H', the dimension of r(L,g) is at least n-mt. For the second part consider the determinant of any t distinct columns of the matrix H in (8.9). After taking out obvious constant factors, such a determinant reduces to a Vandermonde determinant which is nonzero in view of the condition that the elements y0, y1, ... , y,_1 are distinct. Therefore any t columns of H are linearly independent, and so the minimum distance of r(L, g) is at least t + I. 0 In most applications one works with binary Goppa codes-that is, Goppa codes over f2. In this case the following improvement on the lower bound of the minimum distance can be obtained. 8.57. Theorem. For a binary Goppa code whose Goppa polynomial has no multiple roots, the minimum distance is at least 2t + I. Proof. If(c0,c1, ... ,c,_1)Ef; is a code word of weight w>O in the binary Goppa code r(L, g), then c,, � c,, � · · · � c,w � 1 with 0 ,;;; i 1 < i2 < · · · < iw,;;; n-1 and all other c, � 0. If L� {y0,y1, .•. ,y,_1},; f2m, define From (8.8) we obtain w f(x) = IT (x-Y.,)EF2m[X]. }=l 0 � f(x) 'i:1 c;g{y,)-1 g(x)-g(y,) i=o x-yi "' w � L: g(y,r 1(g(x)-g(y,)) IT (x-y,,J. j=l h=l •• J Considering the last polynomial modulo g(x), we get w w 0=- L IT (x-y,,)= -f'(x)modg(x), j=lh=l hti and so g(x) divides the derivative f'(x). Since we are working in characteristic 2, f'(x) contains only even powers and is thus the square of a polynomial in F2m[x]. Now g(x) has no multiple roots by hypothesis, hence it follows that g(x)2 divides f'(x). Consequently, w-1 ;;. deg (f'(x));;. 2t, and so any nonzero code word. has weight at least 2t + I. 0 328 Algebraic Coding Theory 8.58. Example. We describe the binary irreducible Goppa code i(L,g) with Goppa polynomial g(x) = x' + x +I and L= �. = {0, I, a, ... ,a6), where a is a primitive element of�. satisfying a3 +a+ I= 0. From Theorems 8.56 and 8.57 we get the following inf ormation on the parameters of this code: length n = 8, dimension k � n-mt = 2, and minimum distance d � 2t + 1 = 5. Furthermore, l(L,g) is the intersection of�; with the null space of the matrix H-(g(0)-1 g(W1 g(a•)-1 ) -g(0)-10 g(l)-11 g(a6)-1a6 =G I a' a• a' a a ,.) I a' a• a' a' a• o' obtained from (8.9). Using the basis {l,a,a2) of�. over corresponding binary matrix I I 0 0 0 0 0 0 0 0 0 0 H'= 0 0 0 0 0 I I 0 0 I 0 0 0 0 0 0 �,. we get the having l(L,g) as its null space. Since H' has rank 6, we have k = 2, and H' is a parity-check matrix of l{L,g). The linear (8,2) code i(L,g) consists of the following four code words: 0 0 0 0 0 0 0 0, 0 0 I I I I I I, I I 0 0 I 0 I I, I I I I 0 I 0 0. Thus it has minimum distance d = 5. A generator matrix of this code is G = (I I 0 0 I 0 I I)· 00111111 0 We discuss now a decoding algorithm for Goppa codes. We note that if this algorithm is applied in the special case of a narrow-sense BCH code, then it yields an algorithm that is different from the BCH decoding algorithm described in Section 2. Let l{L,g) be a Goppa code over �.with Goppa polynomial g(x) of degree t;;. 2. We suppose for simplicity that Lc; �:m­ that is, y, # 0 for 0.;; i.;; n-I. By Example 8.55, this condition is in particular satisfied for narrow-sense BCH codes. It follows from Theorems 8.12 and 8.56 that l(L,g) can correct up to Lt/2J errors. To correct errors, we take the received word v and the matrix H in (8.9) and calculate the syndrome S(v)=HvT =(S0,S1, ... ,S,_1)T (8.10) If S(v) = 0, then vis a code word and no error correction is needed. If S(v) # 0, we assume that r errors have occurred, where I .;; r.;; Lt/2J. Let the distinct 3, Goppa Codes 329 elements a1, ••• ,a, of {0, l, ... ,n -I) denote the error locations and Jet c1, ... , c,EIF; be the corresponding error values. We define the error-location numbers 1]1='}'411E1Fqm for 1 �i�r. Decoding means determining the pairs (�,, c1), I .;; i.;; r, given the compo­ nents S1, 0 <;;j.;; t-I, of the syndrome. From (8.10) we get ' S1= L: c,g(�,)-1'11 for O<;;j<;;t-1. /= 1 With these S1 we set up the syndrome polynomial <-1 f(x) = L S1xi j=O Furthermore, we need the error-locator polynomial ' s(x) = TI (I-q1x) i= 1 and the error-evaluator polynomial ' ' u(x) = L: c,g(qr 1 TI (I -,,,x). 1=1 h=1 h'fi As usual, an empty product is identified with the constant I. We note that u(x) and s(x) are relatively prime since ' u(�,-1)=c,g(�,)-1 TI (1-�,�,-1)#0 for l <;;i <;;r. (8.11) h=1 h 'fi 8.59. Lemma. The congruence u(x): s(x)f(x) mod x' holds in the ring of polynomials over f,-. Proof. Since s(O) = I, s(x) has a multiplicative inverse in the ring f,-[[x]] of formal power series over f,-by Theorem 6.37. Then u(x) = f c,g(qr 1 s(x) 1=11-q,x ' � L c,g(q,) -1 L qfxl i= 1 j=O JJ,t1 c,g(•Tr 1'1i)x1 = f(x) + x'B(x) for some B(x)Ef,-[[x]], and so u(x) = s(x)f(x) + x'B1(x) for some B1(x)Ef,m[[x]]. A comparison of terms of sufficiently large degrees 330 Algebraic Coding Theory shows that B1(x) is actually a polynomial, and this yields the desired congruence. 0 The congruence in Lemma 8.59 can be solved by using the Euclidean algorithm (see p. 22) with the polynomials r _1(x) = x' and r0(x) = f(x). This algorithm yields r, _ 1 (x) = q>+ 1 (x)r,(x) + r, + 1 (x), deg(r, + 1 (x)) < deg(r,(x)), forh=O, l, ... ,s-1, r,_1(x) = q,.1(x)r,(x). We define recursively the polynomials z_1(x)=0, z0(x}= 1, z,(x) = z,_2(x)-q,(x)z,_1(x) for h = 1, 2, ... , s. The following properties are shown by straightforward induction: r,(x):z,(x)f(x)modx' for h= -1,0, ... ,s, (8.12) deg(z,(x))=t-deg(r,_1(x)) for h=0,1, ... ,s. (8.13) The polynomials s(x) and u(x) are now determined by the following result. 8.60. Lemma. The error-locator polynomial s(x) and the e"or­ evaluator polynomial u(x) are given by s(x) = z,(o)-1 z,(x), u(x) = z,(o)-1r,(x), where b is the least index such that deg(r,(x)) < t/2. Proo( We have deg(s(x)) = r and deg(u(x)),; r-1. If d(x) = gcd(x', f(x)), then d(x) divides u(x) by Lemma 8.59 and so deg(r,(x)) = deg(d(x)),; deg(u(x)). It follows that there exists an index h, 0,; h,; s, such that deg(r,(x)),; deg(u(x)), deg(r,_1(x));;. deg(u(x)) + 1. From (8.13) we obtain deg(z"(x)) = t-deg(r"_1(x)),; t-deg(u(x))-1. Lemma 8.59 and (8.12) yield hence u(x) = s(x)f(x) mod x', r1,(x) = z,(x)f(x) mod x', u(x)z,(x) = r,(x)s(x) modx'. The polynomial on the left-hand side has degree,; t-1, and the one on the right-hand side has degree,; deg(u(x)) + r,; 2r-1,; 2Lt/2J-1,; t-1. Thus we have in fact the identity u(x)z,(x) = r,(x)s(x). (8.14) 3. Goppa Codes 331 Consequently, u(x) divides r,(x)s(x), and since u(x) and s(x) are relatively prime, u(x) divides r,(x). But 0.; deg(r,(x)).; deg(u(x)), hence u(x) = f3r1,(x) for some /JE�: ... It follows then from (8.14) that .•(x) = fJz,(x), and from s(O) =I we get fJ = z,(0)-1• It remains to show that h =b. Since deg(r,(x)) = deg(u(x)) < t/2, it is clear that h ;;. b. If we had h > b, then deg (r, _ 1 (x)) .; deg (r,(x)) < t/2, and so by (8.13), Lt/2J ;;. deg (s(x)) = deg (z,(x)) = t -deg (r, _ 1 (x)) > t/2, a contradiction. 0 We may summarize this decoding algorithm for Goppa codes in the following way. 8.61. Decoding of Goppa Codes. Suppose at most Lt/2J errors occur in transmitting a code word w, using a Goppa code l(L, g) over �, with Goppa polynomial of degree t;;. 2 and Lr;; �: ... Step 1. Determine the syndrome S(v) = (S0, S1, ... , S,_1)T of the received word v by (8.10) and set up the syndrome polynomial r-1 f(x) = L S;xi. j=O If f(x) = 0, no errors have occurred, so w = v. If f(x) # 0, proceed to Step 2. Step 2. Carry out the Euclidean algorithm with r _1(x) = x' and r0(x) = f(x) and stop as soon as deg(r,(x)) < t/2. Put s(x) = z,(0)-1 z,(x), u(x) = z,(0)-1r,(x). Step 3. Determine the error-location numbers �� as the multiplicative inverses of the roots of s(x). Step 4. Determine the error values c, from (8.11)-that is, ' c,= u(�,-1)g(�,) IT (1-�,�,-1)-1. h=l h1i Subtract c, from the component of vindicated by the error-location number �� to obtain the transmitted word w. 8.62. Example. We solve the decoding problem in Example 8.52 by the decoding algorithm for Goppa codes. According to Example 8.55, the narrow­ sense BCH code in Example 8.52 is equal to the binary Goppa code l(L, g) with g{x) = x4 and L= {y0, y, ... , y14}, where y1 =IX_, for 0.; i.; 14 and IZE� 16 332 Algebraic Coding Theory is a root of x4 + x + I. Let the received word • be I 0 0 I 0 0 I I 0 0 0 0 I 0 0. Using the 4 x 15 matrix H obtained from (8.9), we get the syndrome S(•)�H•' �(S0,S1,S2,S3)7 with S0=1, S1=o:4, S2=1, S3=1. This leads to the syndrome polynomial f(x) � x3 + x2 + a4x + I. Now carry out the Euclidean algorithm with r _1(x) � x4 and r0(x) � f(x) and stop as soon as deg(r,(x)) < 2. This yields x4 � (x + i)(x3 + x2 + a4x +I)+ (ax'+ ax+ 1), x3 + x2 + a4x +I� a14x(ax2 +ax+ I)+ (a9x + 1). Thus b � 2 and s(x) � z2(0)-1 z2(x). Since q1(x) � x + I and q2(x) � a14x, we calculate recursively z_ 1(x) = 0, z0(x) =I, z1 (x) � z_ 1(x)-q1(x)z0(x) = x + I, z,(x) = z0(x)-q2(x)z1(x) = a14x2 + a14x +I. Therefore s(x) = a14x2 + a14x + I. The roots of s(x) are a7 and a9, hence �1 = a-1 = y1 and �2 = a-• = y9. It follows that the errors have occurred in positions 8 and 10 of the transmitted code word. By observing that for a binary code the corresponding error values can only be c1 = c2 = I, or by a direct calculation of c1 and c2 from the formula in Step 4 of 8.61 with u(x) = z2(0)-1r2(x) = a9x +I, we find the transmitted code word I 0 0 I 0 0 I 0 0 I 0 0 I 0 0 in accordance with the result in Example 8.52. 0 EXERCISES 8.1. Determine all code-words, the minimum distance, and a parity-check matrix of the binary linear (5, 3) code that is defined by the generator matrix G= (� 1 0 0 0 1 0 0 0 1 ! ) . Exercises 333 8.2. Prove: a linear code can detect s or fewer errors if and only if its minimum distance is � s + I. 8.3. Prove that the Hamming distance is a metric on IF;. 8.4. Let H be a parity-check matrix of a linear code. Prove that the code has minimum distance d if and only if any d-l columns of H are linearly independent and there exist d linearly dependent columns. 8.5. If a linear (n, k) code has minimum distanced, prove that n-k + l ;. d (Singleton bound). 8.6. Let G1 and G2 be generator matrices for a linear (n1, k) code and (n2,k) code with minimum distance d1 and d2, respectively. Show that the linear codes with generator matrices (�I O ) and (G1, G2) G, are (n1 +n2,2k) codes and (n1 +n2,k) codes, respectively, with minimum distances min(d1, d2) and d;. d1 + d1, respectively. 8.7. Prove: given k and d, then for a binary linear (n, k) code to have minimum distanced= d0 we must have n>do+dl + ... +dk-1• where d,+1 � l(d, + l)/2J fori� 0, l, ... ,k -2. Here lxJ denotes the largest integer :s;,; x. 8.8. A code C �IF; is called perfect if for some integer t the balls B,(c) of radius t centered at code words care pairv.;i_se disjoint and "fill" the space F; -that is, U B,(c) � F;. <EC Prove that in the binary case all Hamming codes and all repetition codes of odd length are perfect codes. 8.9. Using the definition of Exercise 8.8, prove that all Hamming codes over IF q are perfect. 8.10. Two linear (n, k) codes C1 and C2 over IF• are called equivalent if the code words of C1 can be obtained from the code words of C2 by applying a fixed perm utation to the coordinate places of all words in C2• Let G be a generator matrix for a linear code C. Show that any permutation of the rows of G or any permutation of the columns of G gives a generator matrix of a linear code which is equivalent to C. 8.11. Use the definition of equivalent codes in Exercise 8.10 to show that the binary linear codes with generator matrices I I 0 respectively. are equivalent. 0 l 0 I I 0 334 Algebraic Coding Theory 8.12. Let C be a linear (n, k) code. Prove that the dimension of C" is n-k. 8.13. Prove that ( C " ) " � C for any linear code C. 8.14. Prove ( C1 + C2)" � C/ n C," for any linear codes C1, C2 over IF, of the same length. 8.15. If C is the binary (n, l) repetition code, prove that C" is the ( n, n -l) parity-check code. 8.16. Determine a generator matrix and all code words of the (7,3) code which is dual to the binary Hamming code C3. 8.17. Determine the dual code C" to the code given in Exercise 8.1. Find the table of cosets of IFi modulo C ",determine the coset leaders and syndromes. If y � 01001 is a received word, which message was probably sent? 8.18. Apply Theorem 8.32 to the binary linear code C � {000,0 ll, 10 l, I 10}; that is, find its dual code, determine the weight enumerators, and verify the MacWilliams identity. 8.19. Let C be a binary linear (n, k) code with weight enumerator and let " A(x, y) � L A,x'y"-' j = 0 n A"(x,y)� L A,"xy-• i-0 be the weight enumerator of the dual code C ". Show the following identity for r � 0, l, ... : where t i'A,� t (-l)'A/ t t!S(r,t)z•-t:::;). 1-0 1-0 r-0 S(r.t)�J, t (-l)'-'(1)}' I. J-0 } is a Stirling number of the second kind and the binomial coefficient ( �) is defined to be 0 whenever h > m or h < 0. Write down the identity for r � 0, l, and 2. 8.20. Let n � ( qm - l )/(q-l) and fJ a primitive nth root of unity in F ,., m;, 2. Prove that the null space of the matrix H � (l fJ {J2 • · · {J" -I) is a code over IF, with minimum distance at least 3 if and only ifgcd(m,q-l)�l. 8.2!. Let a be a primitive element of F9 with minimal polynomial x2-x-l over IF3. Find a generator polynomial for a BCH code of length 8 and dimension 4 over F 3. Determine the minimum distance of this code. Exercises 335 8.22. Find a generator polynomial for a BCH code of dimension 12 and designed distance d � 5 over IF 2. 8.23. Determine the dimension of a 5-error-correcting BCH code over IF 3 of length 80. 8.24. Find the generator polynomial for a 3-error-correcting binary BCH code of length 15 by using the primitive element a of F 16 with a4 = a3 +I. 8.25. Determine a generator polynomial g for a (31,31-deg(g)) binary BCH code with designed distance d � 9. 8.26. Let m and t be any two positive integers. Show that there exists a binary BCH code of length 2m -I which corrects all combinations of t or fewer errors using not more than mt control symbols. 8.27. Describe a Reed-Solomon (15, 13) code over IF 16 by determining its generator polynomial and the number of errors it will correct. 8.28. Prove that the minimum distance of a Reed-Solomon code with generator polynomial is equal to d. d-l g(x)�O(x-a') i=l 8.29. Determine if the dual of an arbitrary BCH code is a BCH code. Is the dual of an arbitrary Reed-Solomon code a Reed-Solomon code? 8.30. Find the error locations in Example 8.43, given that the syndrome of a received vector is (10010110?. Find a generator matrix for this code. 8.31. Let a binary 2-error-corr ecting BCH code of length 31 be defined by the root a of x5 + x2 + 1 in IF_'2· Suppose the received word has the syndrome (I I I 00 I I I 0 I )T Find the error polynomial. 8.32. Let a be a primitive element of I' 16 with a4 �a+ I, and let g(x) � x10 + x8 + x5 + x4 + x2 + x +I be the generator polynomial of a binary (15, 5) BCH code. Suppose the word v � 000 I 0 I I 00 I 000 I I is received. Determine the corrected code word and the message word. 8.33. A code Cis called reversible if (a0,a1, ••• ,a,_1)EC implies (a, 1 •••• ,a1.a0)EC. (a) Prove that a cyclic code C�(g(x)) is reversible if and only if with each root of g(x) also the reciprocal value of that root is a root of g(x). (b) Prove that any cyclic code over F q of length n is reversible if -I is a power of q modulo n. 8.34. Given a cyclic (n, k) code, a linear (n-m, k-m) code is obtained by omitting the last m rows and columns in the generator matrix of the cyclic code described prior to Theorem 8.36. Show that the resulting code is in general not cyclic. but that it has at least the same minimum distance as the original code. (Note: Such an (n- m, k-m) code is called a shortened cyclic code.) 336 Algebraic Coding Theory 8.35. Let !(L,g) be a Goppa code over �. with L� {l•0,)'1, ...• y,_1} <::: � •• ". Prove that (c0, c1, ... ,c,_1)E�; is a code word ofl(L,g) if and only if the congruence '-1 I _c'-=0 modg(x) i=ox-yi holds, where 1/(x-y,) is interpreted as the multiplicative inverse of x-y, in the residue class ring �,m[x]/(g). 8.36. Let !(L,g) be a Goppa code over �. whose Goppa polynomial of degree t has t distinct roots p 1, ... , p, in a suitable extension of�,-, and let L� { y0, y1, ... , y, _1} <::: � ,-. Prove that !(L, g) is the intersection of �;with the null space of the t x n matrix whose entry in thejth row and ith column is ({3i-y1_ tl-1 for 1 �j � t, 1 � i � n. 8.37. Prove that the minimum distance of a binary irreducible Goppa code with Goppa polynomial of degree t is at least 2t + I. 8.38. Determine the dimension of the binary Goppa code l(L,g) with L� �!6, g(x) � x2 + x + �3, and� a primitive element of �16. 8.39. Determine the dimension of the binary Goppa code 1(L, g) with L� f 16 and g(x) � x3 + x + I. Find also a generator matrix for this code. 8.40. Determine the transmitted code word in Exercise 8.32 by the algorithm in Section 3. 8.41. Determine the transmitted code word m Example 8.43 by the algorithm in Section 3. 8.42. Determine the transmitted code word m Example 8.46 by the algorithm in Section 3. 8.43. Let r _1(x) and r0(x) be two nonzero polynomials over a field F with deg(r _1(x));;. deg(r0(x)). The Euclidean algorithm yields r,_1(x) � q,+ 1(x)r,(x) + r,+ 1(x), deg(r>+ 1(x)) < deg(r,(x)), forh=0,1, ... ,s-1, r,_ 1 (x) � q,. 1 (x)r ,(x). Define recursively the polynomials z_1(x) � 0, z0(x) �I, z,(x) � z,_ 2(x)-q,(x)z,_1(x) for h � I, 2, ... , s. Prove the following properties: (a) r,(x)=z,(x)r0(x) modr_1(x) for h�-I,O, ... ,s; (b) z,(x)r,_1(x)-z,_1(x)r,(x) � (-l)'r _1(x) for h � 0, 1, ... ,s; (c) deg(z,(x)) � deg(r _1(x))-deg(r,_1(x)) for h � 0, l, ... ,s. 8.44. An alternant code A over �, is defined as follows. Let h 1, ... , h, be arbitrary elements of [F: m aHd let 0:1, ... , O:n be distinct elements of [F q"'· Fix an integer t with 1 � t < n. Then A consists of all vectors in [F: that are in the null space of the t x n matrix Exercises 337 hl h, h, hlet.l h2a2 h,a, h1ai h2et.� h,a; h r-1 1a1 h t-1 ,�, h,�-1 Show that any Goppa code is an alternant code. Prove that the dimension of A is at least n-mt and that its minimum distance is at least t +I. Chapter 9 Cryptology In this chapter we consider some aspects of cryptology that have received considerable attention over the last few years. Cryptology is concerned with the designing and the breaking of systems for the communication of secret information. Such •ystems are called cryptosystems or cipher systems or ciphers. The designing aspect is called cryptography, the breaking is referred to as cryptanalysis. The rapid development of computers, the electronic transmission of information, and the advent of electronic transfer of funds all contributed to the evolution of cryptology from a government monopoly that deals with military and diplomatic communications to a major concern of business. The concepts have changed from conventional (private-key) cryp­ tosystems to public-key cryptosystems that provide privacy and authenticity in communication via transfer of messages. Cryptology as a science is in its infancy since it is still searching for appropriate criteria for security and measures of complexity of cryptosystems. Conventional cryptosystems date back to the ancient Spartans and Romans. One elementary cipher, the Caesar cipher, was used by Julius Caesar and consists of a single key K = 3 such that a message M is transformed into M + 3 modulo 26, where the integers 0, I, ... , 25 represent the letters A, B, ... , Z of the alphabet. An obvious generalization of this cipher leads to the sub­ stitution ciphers often named after de Vigenere, a French cryptographer of the 16th century. Mechanical cipher devices based on such cryptosystems started to appear in the 19th century and were widely used in both World Wars. 338 1. Background 339 Significant advances in cryptanalysis, for instance the breaking of the German ENIGMA cipher in World War II, have led to the necessity of developing more sophisticated cryptosystems, some of which will be described in this chapter. In Section I a general background on cryptology is given and the distinction between conventional and public-key cryptosystems is discussed. The most secure cryptosystem is the one-time pad in which a random string of bits is added modulo 2 to a binary message. Since this requires very long keys, one has come up with the notion of a stream cipher in which a shorter key generates long strings of bits. This concept is studied in more detail in Section 2. Some very recent developments in cryptography are based on the use of discrete exponentiation in finite fields. A scrutiny of these cipher systems from the viewpoint of the cryptanalyst leads to a study of the inverse function-that is, the index or discrete logarithm in finite fields. In particular, it becomes necessary to analyze the computational complexity of the discrete logarithm. Various applications of discrete exponentiation and discrete logarithms to cryptology and several algorithms for the calculation of discrete logarithms are presented in Section 3. Two more cryptosystems, one based on Goppa codes and one on polynomial interpolation in finite fields, are discussed in Section 4. I. BACKGROUND Cryptosystems are designed to transform plaintext messages into ciphertexts. The particular transformations applied at any given time are controlled by the key of the cryptosystem used at that time. In conventional cryptosystems this key is supposed to be known to both the legitimate sender and the legitimate receiver, but not to the attacker (or cryptanalyst) who wants to break the cryptosystem. The general structure of a cryptosystem can be described as follows. The main ingredients are an enciphering scheme E (for encryption), a deciphering schemeD (for decryption), a key K, the plaintext message (or simply plaintext or message) M, and the ciphertext C. Given a plaintext message Manda key K, the enciphering scheme produces the ciphertext C = EK(M) which is trans­ mitted. The deciphering scheme recovers M by DK(C) = M. One basic requirement is that EK be injective-that is, EK should transform distinct messages into distinct ciphertexts. In this notation the parameter K remains fixed for a considerable number of messages. If only one key K is involved, the system is called a conventional (or single-key) cryptosystem. An attacker is assumed to have full knowledge of the general form of the enciphering and deciphering schemes, has access to a number of plaintext­ ciphertext pairs produced by the cryptosystem, and has additiona l inform- 340 Cryptology FIGURE 9.1 A cryptosystem. ation such as language statistics (letter frequencies and so on) and an idea about the general context of the communication. The attacker does not know the key K and has the task to produce the best estimate M' of M. Breaking a system means determining the key K. As most current data are stored, transmitted, and processed in binary form, cryptosystems over the binary alphabet f2 = {0,1} are of particular importance, but other alphabets such as IF, are also possible. Thus both plaintext and ciphertext are often given in the form of a string ofO's and 1's (or bits). If the plaintext string is broken into blocks of fixed length and then enciphered on a block-by-block basis, the correspondi;1g scheme is called a block cipher. In this chapter-as in this whole book-we are mainly interested in material directly connected with finite fields, and accordingly we will be concentrating on certain types of cryptosystems. However, we mention one of the commercially widely used block ciphers, the DES (Data Encryption Standard), which is the official system adopted by the National Bureau of Standards of the United States and used by most U.S. Federal Departments. It is a cryptosystem with 64-bit data blocks and a 64-bit key; 56 bits of the key are true key bits, the remaining 8 bits are used for error detection. The main disadvantage of conventional cryptosystems is that they require the advance establishment of a secret (or private) key between every pair of correspondents. This makes proper management of the keys a crucial problem for the security of the system. Key management is increasingly difficult if a large number of correspondents are involved in a communication system, because then it will be even harder to ensure key secrecy. In 1976 Diffie and Hellman suggested how to overcome some of these problems by introducing public-key cryptosystems. Public-key cryptosystems ensure that subscribers who have never met or communicated before could have instant secure communication. In general terms, each subscriber places an encipher­ ing procedure E into a public directory to be used by other subscribers while keeping secret his corresponding deciphering procedure D. These procedures, applied to message M or ciphertext C, must have the following properties: (i) If C = E(M), then M = D(C); hence D(E(M)} = M for each M. (ii) E and D must be fast and easy to apply. (iii) E can be made public without revealing D-that is, deriving D from E must be computationally infeasible. For instance, if A wants to send a message M to B, he looks up B's public 1. Background 341 enciphering method £8 and transmits C = £8(M) toBin the open. Only B can decipher C, since only B knows the secret deciphering method D8 to apply to c. Privacy or security of messages is not the only problem area in cryptology. It is also important that the correspondents or subscribers can be authenticated. For example, A has to be able to convince B that it is really from A the message came. The log-on procedure on computers is also an obvious example of authentication. The problem area of authentication or of digital signatures is increasingly important as computer networks, electronic mail, and similar communication systems grow. Digital signature features can be attained by public-key cryptosystems if we add a fourth property: (iv) D can be applied to every M, and if S = D(M), then M = E(S); hence E(D(M)) = M for each M. With this property, subscriber A can sign his message to B by first forming his message-dependent signatureS= D ,(M) and then computing C = £8(S). Only B can recover S by applying the secret deciphering method D8 to C. Then B computesE,(S) =EA(DA(M)) =M, by using A's public enciphering method EA. Now B can be satisfied that M came from A since no other person would have used A's secret deciphering method D, to compute S= D,(M). Public-key cryptosystems can be implemented by using trapdoor one­ way functions. A function f is said to be one-way iff is easy to compute and invertible, but it is computationally infeaSible to compute the inverse function f -1 from a complete description of f. A function f is trapdoor one-way iff-1 is easy to compute once certain private trapdoor information is known, but without this information f would be one-way. An example of a trapdoor one­ way function is contained in the RSA cryptosystem (see Section 3); it is based on exponentiation and the difficulty of factorization of integers. Another trapdoor one-way function is based on the difficulty of the general decoding problem for linear error-correcting codes (see the Goppa-code cryptosystem in Section 4). A major problem area in cryptology is to find appropriate criteria for the complexity of a cryptosystem that will replace the present unsatisfactory method of "certifying" a cryptosystem as secure through heuristics or concentrated man/com puter years of efforts rather than rigorous proof. Computational complexity theory seems to offer a suitable framework for doing that, since there one can classify problems as "hard". A problem is said to belong to the class P (for polynomial time) if there exists a deterministic algorithm that will solve every instance of the problem in a running time bounded by some polynomial in the number of bits needed for the binary representation of the problem parameters. Problems that can be solved in polynomial time by a nondeterministic algorithm-that is, by an algorithm in Which random choices are allowed in each step-make up the class NP (for 342 Cryptology nondeterministic polynomial time). Clearly, P is a subclass of NP. It is a fundamental open question of complexity theory whether P = NP. Particular­ ly interesting problems in the class NP from the viewpoint of complexity theory are the NP-complete problems, which have the property that if any one problem of the NP-complete class is found to be in P, then all ofNP belongs to P. Examples of NP-complete problems are the graph coloring problem, the traveling salesman problem, and the knapsack packing problem. The security of public-key cryptosystems is based on the comput­ ational infeasibility of performing certain tasks-su ch as factoring integers, decoding linear codes, or finding discrete logarithms in finite fields-with the best algorithms and the best hardware publicly available. Of course, there may be secret advances in software or hardware we do not know about. 2. STREAM CIPHERS The simplest and most secure of all cryptosystems is the one-time pad. Suppose the message is given as a string of bits-that is, of elements of �2. Then a long random string of bits is formed; this is the key which is known to sender and receiver. The sender adds this key to the message, using addition in �2. At the receiving end the key is again added in �2 to the enciphered message to recover the original message. The key string must be at least as long as the message string and is used only once. This is a perfect, unbreakable cipher since all the different key strings and all possible messages are equally likely. The major disadvantage of this cryptosystem is that it requires as much key as there is data to be sent. So it is restricted to sending only important messages. In a stream cipher one uses a much smaller key as the seed to produce longer key strings-or even infinite key sequences-which are then added to the message string. One possibility is to use feedback shift registers where certain initial values suffice to produce infinite linear recu�ring sequences in IF 2 (compare with Chapter 6, Section 1). Before we consider a specific crypto­ system, we list some general properties a stream cipher should have: (i) The number of possible keys must be large enough so that an exhaustive search for the key is not feasible. (ii) The infinite sequences must have a guaranteed minimum length for their periods which exceeds the length of the message strings. (iii) The ciphertext must appear to be random. There are a number of properties a random sequence ofbits should satisfy. We refer to Chapter 7, Section 4, for more details. On first glance it would seem that certain homogeneous linear recurring sequences CJ in �2 are good candidates for key sequences. We know from Theorem 6.33 that if the characteristic polynomial of CJ is primitive over �2 of degree k and CJ is not the zero sequence, then CJ has least period 2•-1, which can be made arbitrarily large ask varies. There are many such primitive 2. Stream Ciphers 343 polynomials available, namely </>(2' -1)/k. These maximal period sequences " (see Definition 6.32) of least period 2'-1 satisfy the basic randomness requirements imposed on sequences, as we have shown in Chapter 7, Section 4. Nevertheless, linear recurring sequences are not suitable for constructing secure cryptosystems, since it follows from the discussion on p. 231 that if we know that such a sequence has a characteristic polynomial of degree ,;; k, then any 2k consecutive terms determine a characteristic polynomial and thus the entire sequence. In spite of the proven insecurity of this cryptosystem, it is quite popular, perhaps because the large periods 2'-1 create an illusion of strength. Because of this weakness of linear recurring sequences, we have to consider pseudorandom generators of higher complexity. One possibility is to increase complexity by appropriately combining linear recurring sequences. We shall only describe one such approach, namely the construction of multiplexed sequences which may be used as building blocks in a cryptosystem in the category of stream ciphers. Here a multiplexer, which is a many-input­ one-output system, is used to produce a multiplexed sequence from two given linear recurring sequences. The construction can be carried out over any finite prime field f,. 9.1. Definition. A multiplexed sequence u0, u1, ... in !F P is constructed as follows: (i) Let s0, s,,. .. be a kth-order and t0,t,,. .. an mth-order maximal period sequence in !F P" . _ (ii) Choose an integer h in the range I ,;; h ,;; k such that p' ,;; m if h < k and p' -I ,;; m if h � k. (iii) Choose integers j,, ··· ,j, with 0 .;;j, <j1 < ··· <j,,;; k-I. For n = 0, 1, ···consider the h-tuple (sn+ j1, • • ·, sn+ i,) of elements of !F P and interpret it as the digital representation in the base p of an integer b.EI,, where I,�{O,I,···,p'-1) I,�{l,2,···,p'-1) if h <k, if h �k. (iv) Choose an injective mapping 1/1 from I, into {0, I, ··· ,m -I). (v) With these choices of h ,j1, ••• ,j,, and 1/1 we set un = t11+tJt(b.,l for n = 0, 1, .... Some comments on this definition are in order. We note that, if h < k, then all elements of f� appear among the h-tuples (s.+ 1,, · · ·, '•+ ;.) as n varies from 0 to p'-2, and so b. runs exactly through the values in I,. If h � k, then necessarily j1 � i-1 for I ,;; i,;; k, and the k-tuples (s., · · ·, '•+k-1) are just the state vectors of the sequence s0, s1, ···;the fact that b. runs exactly through the values in I, follows therefore from Theorem 7.43. We note also 344 Cryptology that the existence of an injection 1/1 in (iv) is guaranteed by the condition on min (ii). The definition in (v) says that we obtain the multiplexed sequence by scrambling the terms of the sequence t0, t 1, ···in a way that is controlled by the sequence s0, s1• ···. 9.2. Example. Let p�2, and let s0,s1,··· and t0,t1,··· be the maximal period sequences in IF2 with forn=O,l,···, for n � 0, I, · · ·, and initial state vectors (1, 0, 0) and (I, 0, 0, 0), respectively. The first sequence has least period 7 and the terms in the period are 0 0 0 I. The second sequence has least period 15 and the terms in the period are 0 0 0 0 0 0 0. Now choose h � 2, j1 � 0, j2 �I, and define the injective mapping 1/1 from (0, I, 2, 3} into itself by 1/J(O) �I, 1/1(1) � 2, 1/1(2) � 3, 1/1(3) � 0. The sequence b0, b1, · · · of integers in Definition 9.1(iii) has least period 7 and the terms in the period are 2 0 2 3 3. Consequently, the first few terms of the multiplexed sequence u0, u 1, ... are 0 0 0 0 0 0 0 0···. The diagrammatic representation of the two feedback shift registers and the multiplexer is given in Fig. 9.2. The delay elements of the first feedback shift register are labeled by A0, A1, A2 and those of the second feedback shift register are labeled by B0, B1, B2, B3. D A, A, A, Multiplexer Output u11 FIGURE 9.2 The switching circuit for Example 9.2. 2. Stream Ciphers 345 9.3. Theorem. The multiplexed seque11ce u0, u1, ··· is periodic and its least period divides lcm(p'- 1, pm-1). Proof Put r � lcm(p'- 1, p'"-1). Since r is a multiple of the period p"-1 ofs0,s1, .. ·,wehave and so b, � b,+, for all 11;;. 0. Since r is a multiple of the period pm-1 of t0, t1, · .. ,we obtain for all n ;;. 0. The rest follows from Lemmas 6.4 and 6.6. D The following property of certain decimations of multiplexed se· quences can be applied to obtain further information on the least period. We use again the notation for decimations introduced in Chapter 7, Section 4- that is, if a is a sequence with terms s0, s1, ···,then the decimated sequence af.jl is obtained by taking every dth term of o, starting from s,. 9.4. Lemma. If v denotes the multiplexed sequence u0, u1, · · · and r denotes the sequence t0, t,, ... in Definition 9.l(i), then for i � 0, 1, .. ·, where d � p'-1 and j(i) = i + lji(b,). Proof The terms of v�l are the elements u·���+i• n = 0, 1, ···. Since d � p'-1 is the least period of the sequence s0, s1, ··· in Definition 9.1(i), we have b,d+, � b, by the construction in Definition 9.1(iii), and so for all n ;;. 0, which is the desired result. D 9.5. Lemma. For any integers a;;. 2, k;;. 1, and m;;. 1 we have gcd(a'- 1, am-l)�a"d(k .m)_[. Proof If b � gcd (k, m), then it is clear that a'-1 divides c � gcd («'-1, am-1). Now write k � dm + e with integers d;;. 0 and 0;;;; e <m. Then a'-1 � (a'm-1)a' +(a'-1), and soc divides a'-1. Continuing this process in analogy with the Euclidean algorithm for k and m, we find that c divides a' -1, hence c � a'-1. D 9.6. Theorem. Ifgcd (k, m) � 1, then the least period of the multiplexed sequence u0, u1, ···is a multiple of ( pm-1)/(p-1). Proof We apply Lemma 9.4 with i � 0. Then vl01 � r�1 with d = p'-1 and j = j(O). Put K = � P and F = � P m. Since r is an mth-order maximal period sequence in K, it follows from Theorem 6.24 that there exists a primitive PlPTnPnt rt nf J<' �nrl � IJc::. J<'* Clllf'h th�t 346 Cryptology The terms w, oft�) are thus given by w, = t,<+ J = Tr,1K(y{3") for n = 0, I,···, (9.1) where fJ = a'EF* andy= GaJEF* By Theorem 1.15(ii), the order of fJ in the multiplicative group F* is gcd(p'-l,pm-1) pm-1 p-1' where we used Lemma 9.5 and the hypothesis gcd (k, m) = I in the last.step. Let f(x) be the minimal polynomial of fJ over K. Then it follows from (9.1) and the calculation in the proof of Theorem 6.24 that f(x) is a characteristic polynomial of the linear recurring sequence tY'. We claim that <Y' is not the zero sequence. We have m I � �pm-1 p-l r . (9.2) Furthermore, the elements yfJ", 0.;; n < (pm-1)/(p-1), are (pm-l)f(p-I) distinct elements ofF*. Since there are just pm-1-l elements �EF* with Tr,1��) = 0 by Theorem 2.23(iii), it follows from (9.1) and (9.2) that w, = TrF/K(yfJ") # 0 for some n. Thus, indeed, t�' is not the zero sequence, and since f(x) is irreducible over K by Theorem 3.33(i), the least period of t�1 is equal to ord (f(x)) = (pm-1)/(p-I) according to Theorems 6.28 and 3.3. Ifr is the least period of u0,u1, .•. , then r is a period of the decimated sequence vl0' = t�>, and so Lemma 6.4 shows that r is divisible by (pm-l)f(p-1). D It can be proved that if p = 2, gcd (k, m) = I, and m > I, then the least period of the multiplexed sequence u0, u1, ... is equal to (2'-!)(2m-1). For instance, the least period of the multiplexed sequence in Example 9.2 is equal to (23-1)(24-I)= 105. As to the application of multiplexed sequences in stream ciphers, it appears that such sequences may be quite complex, but further research will be needed in order to establish that their complexity is sufficiently high. 3. DISCRETE LOGARITHMS Let b be a primitive element of�. and let a be a nonzero element of� •. Then the index of a with respect to the base b is the uniquely determined integer r, 0.;; r < q-I, for which a= b'. We use the notation r = ind,(a), or simply r = ind (a) if b is kept fixed. The index of a is also called the discrete logarithm of a. The discrete exponential function exp,(r) = exp (r) = b' and the discrete logarithm form a pair of inverse functions of each other; compare also with Chapter 10, Section I. Their use for cryptography depends on the apparent one-way nature of the discrete exponential function: it is easy to compute, but appears hard to invert. 3. Discrete Logarithms 347 The discrete exponential function exp (r) = b' in 0', can be calculated for 1 ,; r < q-1 by an analog of the repeated squaring technique discussed after Theorem 4.13, which is often called the square and multiply technique in the present context. In detail, we first compute the elements b, b2, b4, · · ·, b2' by repeated squaring, where 2' is the largest power of 2 that is ,; r. Then b' is obtained by multiplying together an appropriate combination of these elements. For instance, to get b21 one would multiply together the elements b, b2, b8, and b16 A simple analysis shows that the calculation of b' requires at most 2Llog2 qj multiplications in 0',, where log2 denotes the real logarithm to the base 2. Until recently, the inverse problem of computing discrete logarithms in 0', was believed to be much harder, since for one of the best algorithms available then the required number of arithmetic operations in D', was of the order of magnitude q11'-If q is sufficiently large, say q > 2100, exponentiation in 0', might justly have been regarded as a one-way function. However, great progress has recently been achieved in the computation of discrete logarithms, which makes it necessary to construct cryptosystems based on discrete exponentiation in a careful manner in order to protect them against attacks by these recent algorithms. We now describe some cryptographic applications of discrete exponentiation and then present some discrete logarithm algorithms. 9.7. Example. The following is a cryptosystem for message transmission in 0',. Let M, K, and C denote the plaintext message, the key, and the ciphertext, respectively, where M, CED'i, K is ·an integer with 1,; K,; q-2 and gcd (K, q -1) = 1, and q is a large prime power. The last condition on K makes it possible to solve the congruence KD = 1 mod(q-1) for the integer D. We encipher by computing C=MK and decipher by CD=M. (9.3) (9.4) (9.5) Both operations are easily performed. To find the key, however, is as hard as finding discrete logarithms since (9.4) is equivalent to K ind(M) = ind(C)mod(q -1). (9.6) Even if we know a plaintext-ciphertext pair M and C, computing K can be expected to be difficult for large q. From (9.6) we see that M must be a primitive element of 0', so that M and C determine K uniquely. We also observe that there is a wide choice for the key K since for q > 2 there are </>(q -1) integers K that satisfy 1;,; K,; q -2 andgcd( K,q-1) = l.Primesoftheformq = 2p+ I, p also a prime, are the most promising values of q to use in order to get a secure 348 Cryptology system. For primes q we may view M and Cas integers with 1 .; M, C.; q-1, and then (9.4) and (9.5) are replaced by the congruences C=MKmodq, CD=Mmodq. 0 The cryptosystem in Example 9.7 can be made into a new system by replacing congruences modulo a large prime q by congruences modulo a product n of two large primes p and q. Such a cryptosystem was proposed by Rivest, Shamir, and Adleman and is now known as the RSA cryptosystem. Instead of using (9.3), we now find D from KD = 1 mod tj>(n) (9.7) in this generalized system, where we assume gcd(K, tf>(n)) =I. The security of the RSA cryptosystem is based on keeping the factors of n secret and depends on the difficulty of factoring large integers into primes. Normally n would be a product of two primes with approximately 100 decimal digits each. At present, the factorization of arbitrary integers is computationally feasible only if they have at most about 70 decimal digits. The RSA cryptosystem is an example of a public-key cryptosystem with public keys K and n that do not compromise the secret deciphering key D. Only by knowing the factors of nit is possible to solve (9.7) for D. Of special interest in Example 9. 7 is the finite field � 2�, where 2m-1 is a large Mersenne prime, because with this choice all the keys K with 1 .; K.; 2m-2 can be used. The field with 2127 elements attracted particular attention. It is generated by the primitive trinomial x127 + x + I over �2 and is used to implement a cryptosystem with discrete exponentiation. This parti­ cular system has recently been shown to be totally insecure; compare also with the discussion following Example 9.13. 9.8. Example. An application of discrete exponentiation to computer sys­ tems is the following. In such systems users' passwords are stored in specially protected files so that only authorized users have access to them. This can be achieved by utilizing discrete exponentiation as a candidate for a one-way functionf by creating a public file of pairs (i.f(p;)), where i denotes the user's log-on name and p, is the user's password. 0 9.9. Example. Discrete exponentiation can be used to create a well-known key-exchange system, the Diffie-Hellman scheme. Suppose users A and B wish to communicate by using a standard high-speed cryptosystem such as DES, but they do not have a common key. They choose random integers h and k, respectively, where 2 .; h, k.; q -2. Let b be a primitive element of�,. Then A sends b' to B, while B transmits b' to A. Both take b"' as their common key, which can be computed by A as (b')' and by Bas (b'}'. It is an unsolved problem to generate b" from knowledge of b' and b' only, without computing either h or k. The public-key cryptosystems that are known today have the disadvan- 3. Discrete Logarithms 349 tage that they are rather slow. Therefore their main use is for the distribution of keys for conventional cryptosystems. 0 9.10. Example. Consider the following conventional system for message transmission. User A wishes to send a message m-regarded as a nonzero element of the publicly known field �,-to user B. Then A chooses a random integer h, where 1.;; h.;; q-1 and gcd(h, q-1) � 1, and transmits x = m11 to B. User B chooses a random integer k, where 1 � k � q -1 and gcd(k, q-1) � 1, and sends y = x' � m" to A. Now A forms z = y"", where hh' = 1 mod(q-!),and sends zto B. Then B only has to compute z'" to recover m, where kk" = 1 mod(q- 1), since This three-pass procedure between A and B is also known as the no-key algorithm, where users A and B keep their own respective key pairs (h, h') and (k, k') secret. 0 9.11. Example. Consider the following public-key cryptosystem for message transmission. Let b be a primitive element of [F4, where q and b are known publicly. Let A's public key be the element b'E�., where h is kept secret by A. If B wants to send a message mE�: to A, then B selects a random integer k, 1 .;; k.;; q-2, and transmits the pair (b', mh") to A. Since A knows h, he can compute b" � (b')' and so recover m. This cryptosystem could be broken by computing h or k with an efficient discrete logarithm algorithm. 0 9.12. Example. The following is a digital signature scheme using discrete exponentiation. If user A wishes to attach a digital signature to a message m with 1 .;; m.;; p-1, he publishes a prime p, a primitive element b of �, identified with an integer, and an integer c, 1 � c � p-1, obtained from a secret random integer h such that c = b' mod p. To sign m, A provides a pair (r, s) of integers with 1.;; r.;; p-1, 0.;; s.;; p-1, such that The integer r is generated from a random integer k with gcd (k,p-1) = 1 by computing r = b' mod p. Then s has to satisfy bm = b"rbk:J = bhr+ks mod p, which is equivalent to m = hr + ksmod(p- 1). The unique solutions of this congruence is easily obtained by A since he knows h, r, and k. If an attacker could compute h from c by using a discrete logarithm algorithm, this digital signature scheme would be insecure. 0 Before we describe several discrete logarithm algorithms for � 4, we 350 Cryptology make a few general observations. As above, we repeatedly use the fact that arithmetic in the exponents is done modulo q-1 since b'-1 � b0 � 1 for any primitive element b off,. In the case of a prime field�, it is often convenient to identify elements of�. with integers, so that identities in f, are also written as congruences modulo p. Next we observe that it is not difficult to find the discrete logarithms of arbitrary elements of �: under the assumption that discrete logarithms are "easy" to calculate (or known) for a relatively small portion of all the elements of �:. For suppose it is easy to compute ind,(a) � ind(a) for a set E of e(q-1) special elements aE�:, where 0 < e <I. If a given a0E�: is not in E, take a uniform random sample t1 from {0, 1, ···,q -2} anddefinea1 � a0b''.if a1 EE, so that ind(a,) is easy to compute, then ind(a0) = ind(a1)-t1 mod(q-1). Otherwise, take independent and uniform random samples t2, t3, ··· from {0, I,···, q-2} until ana,= a0b'' inEisfound. Thenind(a0 )can be calculated by subtraction. Note that the probability that all the elements a0, a1, · · ·, a, are outside of E is (1-ef+ 1, which rapidly becomes small. As an illustration consider the case of a prime field f ,. If the discrete logarithms in�, of the first n primes 2 = p1 < · · · < P. <pare known and if an integer a satisfies then " a= TIPJ'modp, J= 1 " ind(a) = I e1ind(p)mod(p -I). J= 1 Integers which factor completely into small primes are called "smooth". In the case described here it is easy to compute ind(a) if a is smooth and the values ind(p1) are known. The set of smooth integers is then an example of a set E from above. The density of smooth integers is crucial in the analysis of several discrete logarithm algorithms. We first present the Silver-Pohlig-Hellman algorithm for computing discrete logarithms in f,. The main point to be made here is to show that if q-1 factors into small primes, then the discrete logarithms can be cal­ culated rather efficiently, and so cryptosystems based on discrete exponenti­ ation in IFq are insecure for such q. Let be the prime factor decomposition of q-1, where p1 < p2 < · · · < p, are the distinct prime factors. We wish to find the valuer= ind,(a) such that a= b', where b is a primitive element of� •. The value of r will be determined modulo 3. Discrete Logarithms 351 p/' fori= I, 2, · · ·, k and the results will then be combined by the Chinese Re­ mainder Theorem for integers (see Exercise 1.13) to obtain r modulo q-I, which completely determines r since 0..; r < q-I. Suppose e;-1 r = L s1p{ mod pf' j=O In order to determine s0 we form a(q-1)/pj = b(q-1)rfp; = cf = qo, (9.8) where ci = bC4 -l)/PJ is a primitive pith root of unity in [F 4. Therefore there are only p, possible values for a'•-"'" corresponding to s0 = 0, I,··· ,p1-I. The resulting value uniquely determines s0. The next digit s1 in (9.8) is obtained by letting Then eJ-1 where r1 = L s1p{. j-1 uniquely determines s1. This method is continued to find all the s1 in (9.8). It can be shown that this algorithm has a running time of order at most pt12(log q)2, where Pt is the largest prime factor of q -I. Therefore the algorithm is most efficient if q-I only has small prime factors. 9.13. Example. Let q = 17, then b = 3 is a primitive element of�17• We wish to find r = ind,(a) for a= -2 by the Silver-Pohlig-Hellman algorithm. Sinceq-I = 2\ we only have to work with theprimefactorp1 = 2. We calculate c1 = b<4-1112 = -1. Write Now r=s0+s1·2+s2·2 2+s3·23 with s1=0 or I. a<•-1>12 = (-2)' =I= C"\', and so s0 = 0. Then d = ab0 = -2 and d(q-1)f4 = ( -2)4 = -I= C"\', and so s1 =I. Then e = ab-2 = -4 and e<•-1>1' =( -4}' =-I= c1', and so s2 =I. Now f = ab-6 =I, hence a= b6, and so ind3( -2) = 6. 0 The fact that the Silver-Pohlig-Hellman algorithm is less efficient if q-I has a large prime factor has led to the idea that fields �2• be employed, where 2"-I is a Mersenne prime. Such fields are also easy to implement. At the time of this writing 29 Mersenne primes are known, the largest one being 352 Cryptology 2132049-I, but the case of2127-I is of particular interest since the field with 2127 elements has been used in practical hardware implementations. Unfortu­ nately, the resulting cryptosystem is completely unsafe since the discrete logarithm algorithms given below can be carried out rapidly. If one uses f 1• for a cryptosystem based on discrete exponentiation� an attacker would need access to a modern supercomputer in order to break a system based on such finite fields for n ;. 400. Within the next ten years it is recommended to choose n � 800 or even n � 2000 if one wishes to take into account developments in large special-purpose machines or improvements of algorithms. Another disadvantage of fields f 1• for cryptographic applications is that there are few fields of this type, in the sense that there is only one field of order 2", but there are many prime fields f, of comparable order since there are many primes p with 2'-1 < p < 2'. This also lessens the security of a cryptosystem. For large primes p it appears that fields of the form f P" do not offer increased security over fields f ,. If we take a system whose main objective is key exchange and which is based on discrete exponentiation in f ,, such as the Diffie-Hellman scheme in Example 9.9, and compare it with a public-key cryptosystem like RSA, then the former seems preferable since one can use keys that are about half as long for the same level of security. We now discuss another discrete logarithm algorithm for f ,, the index­ calculus algorithm, one variant of which is due to Blake, Fuji-Hara, Mullin, and Vanstone. This algorithm works best for q = 2', but it can also be carried out for q = p" with p prime and n;. 2. Let f, with q = p" be defined by the irreducible polynomialf(x) over f, of degree n. Since f, is isomorphic to the residue class ring f,[x]/(f), all elements off, can be uniquely represented as polynomials over f, of degree < n, with the arithmetic being polynomial arithmetic modulof(x); compare with Chapter 1, Section 3. This identification will be used throughout the rest of this section. Suppose b(x) is a primitive element off,. The algorithm to find the discrete logarithm ind(a(x)) to the base b(x) of an arbitrary nonzero element a(x) off, consists of two stages. In the initial stage we compute the discrete logarithms to the base b(x) of all elements of a chosen subset V off,. The set V usually consists of all the monic irreducible polynomials over lF P of degree� m, where the integer m < n is determined according to certain probability computations described later. We suppose that ind(d) is known for all dEf;. This is trivially satisfied for p = 2 since the only possibility is d = I and then ind(d) = ind(l) = 0. For p > 2 we use the observation that b = b(x)<•-<Jitp-IJ is a primitive element off, and q-1 indbt,,(d) = --1 ind,(d) for all dEf;. p- For small values of p, ind,(d) can be obtained by direct calculation. For large p we may use, for instance, the Silver-Pohlig-Hellman algorithm to compute these discrete logarithms. 3. Discrete Logarithms 353 9.I4 Index-Calculus Algorithm: Initial Stage. Choose a random integer, t, I.;; t.;; q-2, and form the polynomial c(x)E�,[x] determined by c(x) = b(x)' mod f(x), deg(c(x)) < n. Then factor c(x) into irreducible polynomials over � •• using techniques of Chapter 4 if necessary. If all the monic irreducible factors are elements of V, so that c(x) � d IT v(x)'"''' "'v with dE�; is the canonical factorization in �,[x], then t=ind(d)+ L: e,(c)ind(v(x))mod(q- 1). "'v As soon as we obtain more than I VI independent congruences of this type, we expect that the corresponding system in the unknowns ind(v(x)), VE V, will determine these discrete logarithms uniquely modulo q-I for all vE V. The initial stage depends on the possibility to factor c(x) in the way stated above and to obtain sufficiently many independent congruences. This stage is independent of a(x) and can be used for other computations in� •. The second stage of the algorithm is based on the principles described in the discussion following Example 9.12. In the earlier illustration the set E of elements with easily computable discrete logarithms was formed by the smooth integers. The role of the smooth integers is now played by those polynomials over �, all of whose irreducible factors are elements of V -that is, all of whose irreducible factors have degree.;; m. Note that the discrete logarithms of the elements of V are known from the precomputation in the initial stage. These discrete logarithms serve thus as a data base for the second stage of the algorithm, and as mentioned earlier this data base should also include the discrete logarithms of all elements of�;. 9.15. Index-Calculus Algorithm: Second Stage. To compute ind(a(x)) to the base b(x). choose a random integer t, 0.;; t.;; q-2, and form the polynomial adx)E�,[x] determined by a1(x) = a(x)b(x)' mod f(x), deg(a 1(x)) < n. Then factor a1(x) into irreducible polynomials over� •• using techniques of Chapter 4 if necessary. If all the monic irreducible factors are elements of V, so that a1(x) � d IT v(x)'"1"'1 ,.v with dE�; is the canonical factorization in�,[ x ], then ind (a(x) )is determined by ind(a(x))=ind(d)+ L: e,(a1)ind(v(x))-tmod(q-! ). "'v 354 Cryptology If a1 (x) does not have the desired type of factorization, choose other values oft until this type of factorization is obtained. For the analysis of both stages of the algorithm it is important to study the probability P(n, m) that a nonzero polynomial over f, of degree < n has all its irreducible factors in � ,[x] of degree:;;; m. We have 1 n-1 P(n,m)�- ,-L N(k,m), p -I k=O where N(k, m) is the number of polynomials over �,of degree k that have all their irreducible factors in f,[x] of degree:;;; m. A recurrence relation for evaluating N(k,m) is given in Exercise 9.14. For p � 2 this leads after lengthy calculations to the formula (m)"''·m),/m P(n, m) � A(n, m) n , where A(n,m) and B(n,m) tend to I for n--+ oo and n11100:;;; m:;;; n991100 Thus we will need roughly (n)'lm P(n, m)-1 "" ;;; (9.9) choices of integers t before the second stage of the algorithm can find the discrete logarithm of a(x). It is clear that m cannot be chosen too small, for otherwise the running time of the second stage would be exorbitantly long. On the other hand, if m is chosen too large, then the initial stage will require a very long running time. Thus one has to find a middle ground between these two extremes. For instance, in the important special case p � 2 and n � 127 the choice m = 17 is recommended; then 16510 discrete logarithms have to be precomputed in the initial stage since there are that many irreducible polynomials over �2 of degree:;;; 17. 9.16. Example. To illustrate how the initial stage is carried out, we consider � 64 defined by f(x) = x6 + x + I Ef2[x]. Since f(x) is a primitive polynomial over F2, we can take b(x) = x as a primitive element of �64. Suppose the maximum degree m of irreducible polynomials in the set Vis 2. So we have to find the discrete logarithms of x, x +I, and x2 + x +I to the base x. Oearly ind(x) = I. Now we choose integers t with I :;;; t:;;; 62. A good choice is t = 6, since then c(x) = x6 = x +I modf(x), hence ind(x + I) = 6. Another good choice is t = 32, since x64 = x = x6 +I= (x3 + 1)2 modf(x) implies c(x) = x32 = x3 + I= (x + l)(x2 + x +I) modf(x). 3. Discrete Logarithms This yields 32 = ind(x + I) + ind(x2 + x + I) = 6 + ind(x2 + x + I) mod 63, hence ind(x2 + x + I) = 26. 355 D 9.17. Example. To demonstrate a simple case for the second stage, let IF64 again be defined by f(x) = x6 + x + I ElF 2[x] and let b(x) = x. Suppose m = 2, so that the discrete logarithms of the elements of V are known from Example 9.16. These values constitute our data base. We wish to find the discrete logarithm of a(x) = x4 + x3 + x2 + x + I to the base x. We form a1(x) = a(x)x' modf(x) with a suitable t. The choice t = 2 yields a1(x) = a(x)x2 = x5 + x4 + x3 + x2 + x +I= (x2 + x + 1)2(x +I) modf(x), hence all the irreducible factors are in V. Therefore ind(a(x)) = 2 ind(x2 + x + I) + ind(x + I)-2 = 2·26 + 6-2 = 56mod63, and so ind(x4 + x3 + x2 + x + I) =56. 0 The second stage of the index-calculus algorithm can be speeded up by using the Euclidean algorithm. Consider again the nonzero polynomial a1(x)EIF,[x] determined by .· a1(x) = a(x)b(x)' mod f(x), deg(a1 (x)) < n. (9.1 0) The method in 9.15 is successful only if a1(x) has all its irreducible factors in IF,[x] of degree ,;;m. The main idea is to replace this now by the following condition: there exist nonzero polynomials w1(x) and w2(x) over IF, with w,(x)a1(x) = w1(x) mod f(x) (9.11) and deg(wJx)),;; n/2 for i = I, 2 such that each w�x) has all its irreducible factors in IF,[ x] of degree ,;; m. If such polynomials w,(x) can be found, then their canonical factorization in IF,[x] is of the form w1(x) = d, n v(x)•·<w<> for i =I, 2 (9.12) �v with d,EIF;.It follows then from (9.10) and (9.11) that the discrete logarithm of a(x) is determined by ind(a(x)) = ind(d1d2 1) + L (e,(w1)-e.,(w2))ind(v(x))- t mod(q -I). �y (9.13) Polynomials w1 (x) and w2(x) satisfying(9.11) and the degree restriction above can be calculated by an application of the Euclidean algorithm that is 356 Cryptology similar to the procedure for decoding Goppa codes (see Chapter 8, Section 3). In detail, we use the Euclidean algorithm with the polynomials r _1 (x) = f(x) and r0(x) = a1(x). This yields r, -l (x) = q,. 1 (x)r,(x) + r,. 1 (x), deg(r,. 1 (x)) < deg(r,(x)), for h=O,l, ... ,s-1, r,_1 (x) = q,. 1 (x)r,(x). Since 0,;; deg(a1(x)) < n = deg(f(x)) and f(x) is irreducible over �,,we have gcd(f(x), a1(x)) =I and so deg(r,(x)) = 0. Consequently, there exists a least index j, 0 ,;;j,;; s, such that deg(r,{x)) ,;; n/2. Now calculate recursively the polynomials z_ 1 (x) = 0, z0(x) = I, z,(x)=z,_2(x)-q,(x)z,_1(x) for h= 1,2, ... ,j. By the generalizations of(8.12) and (8.13)shown in Exercises 8.43(a) and 8.43(c) we have zj(x)a1(x) = rj(x) modf(x) and deg(zj(x)) = deg(f(x)) -deg(r;_1(x)) = n-deg(r;_1(x)). From the minimality ofj we get deg(r;_1(x)) > n/2, and so deg(z;(x)) < n/2. It follows that w1(x) = rj(x) and w2(x) = zj(x) are polynomials satisfying (9.11) and deg(w1(x)} ,;; n/'1., deg(w2(x)) < n/2. Moreover, w1(x) and w2(x) can be calculated very quickly. The condition about the irreducible factors ofw1(x} and w2(x) cannot be guaranteed by the algorithm above. However, we may heuristically estimate the probability that both w1(x) and w2(x) have the desired type of factorization in (9.12). Let P(n, m) again denote the probability that a nonzero polynomial over �,of degree< n has all its irreducible factors in �,[x] of degree,;; m. If we make the reasonable assumption that w1(x) and w2(x) behave like independently chosen random polynomials of degree < Ln/2J + I, then the probability that w1(x) and w2(x) have all their irreducible factors in �,[x] of degree ,;; m will be approximately P(Ln/2J + I, m)2• Usingthe approxim ation (9.9) in the case p = 2, we obtain that we will now need roughly choices of integers tin the second stage of the algorithm. This is a saving by a factor of approximately 2 -•tm over the corresponding expression in (9.9). Thus we can expect that this version of the second stage of the index-calculus algorithm will be significantly faster than the earlier one. We summarize this 3. Discrete Logarithms 357 method as follows, assuming again that we already have a data base containing the discrete logarithms of all elements of �; and of all elements of the set V consistin g of the monic irreducible polynomials over �. of degree� m. 9.18. Index-Calculus Algorithm: Improved Version of Second Stage. To compute ind(a(x)) to the base b(x), choose a random integer t, 0.;; t.;; q-2, and form the polynomial a1(x)E�,[x] determined by a1(x) = a(x)b(x)'modf(x), deg(a1(x)) < n. Then carry out the Euclidean algorithm with r _1(x) = f(x) and r0(x) = a1(x) and stop as soon as deg(ri(x)) .;; n/2. Put w1 (x) = r1(x) and w2(x) = z/x) and factor these polynomials into irreducible polynomials over � ,, using techni­ ques of Chapter 4 if necessary. If all the monic irreducible factors are elements of V, so that w1 (x) and w2(x) are of the form (9.12), then ind(a(x)) is determined by (9.13). If this condition on the monic irreducible factors ofw1 (x) and w2(x) is not satisfied, choose other values oft until this condition holds. In the case p = 2 further improvements on the construction of the data base and on the speeding up of the second stage of the index-calculus algorithm were recently achieved by Coppersmith. 9.19. Example. We give a simple illustration of the algorithm in 9.18. Consider the finite field f32, so that p = 2 and n = 5. Let IF32 be defined by the primitive polynomial f(x) = x' + x2 +I over �2. Then we can take b(x) = x as a primitive element of IF 32. We wish to find the discrete logarithm of a(x) = x3 + x + I to the base x. Suppose the data base consists of the discrete logarithms of all irreducib le polynomials over �2 of degree .;; 2: ind(x)=l, ind(x+l )=l8, ind(x2+x+l) =ll. Choose the integer t = 0, so that a1 (x) = a(x), and carry out the Euclidean algorithm with r _1 (x) = x' + x2 + I and r 0(x) = x3 + x + I. This yields x' + x2 + I = (x2 + I )(x3 + x + I) + x. Since r.(x) = x satisfies deg(r1(x)) .;; n/2, we can already stop. Thus w1 (x) = r1 (x) = x and w2(x) = z1 (x) = x2 + I = (x + I )2 It follows then from (9.13) that ind(x3 + x +I) =ind(x)-2ind(x +I)= 1-2·18= 27mod 31, and so ind(x3 + x +I)= 27. 0 These discrete logarithm algorithms have diminished the security of cryptosystems based on discrete exponentiation. It is therefore of interest to design cryptosystems that use similar principles, but employ more complex operations than discrete exponentiation. This is carried out in the recent proposal of FSR cryptosystems by Niederreiter, where FSR stands for 358 Cryptology "feedback shift register". In these cryptosystems, discrete exponentiation is replaced by the operation of decimation for linear recurring sequences in finite fields (compare with Chapter 7, Section 4). The ciphertexts are strings of consecutive terms of linear recurring sequences that are obtained by decimation from message-dependent linear recurring sequences. The cry­ ptanalysis amounts to inferring the value ofthe integer k from the knowledge of the polynomials J(x) = Tii�1(x- �1) and J,(x) = ru�,(x-"' over � •• where both factorizations are in the splitting fields ofthe polynomials over� •. This problem is more difficult than determining discrete logarithms. We now describe a public-key cryptosystem in which discrete logarithms are used for encryption. This cryptosystem due to Chor and Rivest is of the knapsack type -that is, it is based on the difficulty of recovering the summands from the value of their sum. The following auxiliary result is crucial. 9.20. Lemma. Let p be a prime and n;;. 2 an integer. Then there exist integers a0, a1, ..•• ap-t with 1 � ai� p" -2/or 0 � i � p-1 such that for any two distinct vectors (h0, h1, •.• , h,_1) and (k0, k1, ... , k,_1) with nonnegative integral coordinates satisfying we have p-1 L h,< n and i=O (9.14) Proof. Consider the finite field f 4 with q = p" and identify it as before with the residue class ring f,[x]/(f), where f(x) is an irreducible polynomial over �, of degree n. Relative to a fixed primitive element of � 4 set a, = ind (x -i) for i = 0, I, ... , p -I. Each a, satisfies I ,;;; a,,;;; q-2. Now suppose (h0, h1, •.• , h,_1) and (k0, k1, •.. , kP_1) are two vectors with nonnegative integral coordinates satisfying (9.14) and Then and so p-1 p-1 L h,a, = L k,a, mod (q-I). 1=0 i=O (p-1 ) (p-1 ) ind Il (x-i)'' = ind ,IJ (x-i)'' mod (q-I), p-1 p-1 TI (x -iJ'' = TI (x -i)'' mod f(x). i=O i=O Now (9.14) shows that on each side we have a polynomial over�. of degree < n, hence p-1 p-1 TI (x -i)'' = TI (x -i)''. i=O i=O 3. Discrete Logarithms 359 Unique factorization in f ,[x] implies h1 = k;for 0.;; i.;; p-I, and the desired result is established. D The cryptosystem is implemented as follows. Take a publicly known finite field �.with q = p", p prime, n;;. 2, in which discrete logarithms can be efficiently computed. Choose a random irreducible polynomial f(x) over f, of degree nand a random primitive element b(x) of� •. Relative to the base b(x) compute a,= ind (x-i) for i = 0, I, ... , p-I as in the proof of Lemma 9.20. Scramble the a, by selecting a random permutation 1/J of {0, !, ... ,p-!}and putting ci = ao;-(i) for i = 0, 1, ... ,p -1. Then publish c0, c1, ... , c,_1 as the public key and keep f(x), b(x), and 1/J secret. With this cryptosystem we can encipher binary messages M = m0m1 ..• m,_1 of length p for which the number N of I 's is less than n. In detail, let m1, = ... = m1 = I and all other m, = 0. Then encipher M as the N integer E(M) with 0 .;; E(M) .;; p"-2 and E(M) = c,, + · ·· + c1 mod(p" -I). N It follows from Lemma 9.20 that distinct messages are enciphered as distinct ciphertexts. To decipher the ciphertext s 0" E(M), we calculate the uniquely determined polynomial g(x)E � ,[x] with deg(g(x)) .< n and g(x) = b(x)'modf(x). From the definition of the c, and a, we obtain g(x) = b(x)"• + ··· +"• = (x-!/J(i1)) ... (x-1/J(iN))mod f(x). Since N < n = deg(f(x)), we have g(x) = (x-1/J(i,))· · · (x-1/J(iN)). Therefore 1/J(i,), ... , 1/J(iN) can be determined as the roots ofg(x) in�,, which are obtained either by successive substitution of elements of�, or by one of the root-finding algorithms in Chapter 4, Section 3. By applying the inverse permutation of ljl, we recover the positions i1, •.. , i,. where the original message M has the bit I. 9.21. Example. We illustrate the procedure with an example involving small parameters. Let p = 5 and n = 3, so that we are working in the finite field �125. Choose f(x) = x3 + x2 + 2, which is a primitive polynomial over�,. Therefore b(x) =xis a primitive element of �125. The part of Table A in Chapter 10 pertaining to f125 = GF(53) refers precisely to this situation. Thus we can read off the values of the a, from this table. This yields a0 =I, a1 = 84, a2 = 80, a3 = 99, a4 = 29. 360 Let the permutation t/1 of {0, 1, 2, 3, 4) be given by so that t/J(O) = 2, t/1(1) = 4, t/1(2) = 1, t/1{3) = 0, t/1(4) = 3, c0 = 80, c1 = 29, c2 = 84, c3 = 1, c4 = 99. If we wish to encipher the binary message M = 10100, then E(M) = c0 + c2 = 80 + 84 mod 124, and so E(M) = 40. To decipher s = 40, we calculate g(x) = x40 =x' + 2x + 2mod(x3 + x2 +2) from Table A, hence g(x) = x2 + 2x + 2 = (x-l)(x-2). Cryptology Therefore N = 2, tjl(i,) = 1, and t/J(i2) = 2, yielding i1 = 2 and i2 = 0, and we recover the original message M. D 4. FURTHER CRYPTOSYSTEMS We first describe a public-key cryptosystem that is based on binary irreducible Goppa codes (see Chapter 8, Section 3). This cryptosystem falls into the category of block ciphers. We recall from Theorems 8.56 and 8.57 that for any irreducible polynomial g{x) over �2� of degree t and any integer n, where 2.;;; t < n.;;; 2m, there exists a binary irreducible Goppa code i{L,g) oflength nand dimension k � n-mt that is capable of correcting any pattern oft or fewer errors. All one has to do is to choose Las a subset of �2� of cardinality n. We note also that Goppa codes allow a fast decoding algorithm discussed in Chapter 8, Section 3. The Goppa-code cryptosystem is set up as follows. We choose integers t and n with 2 � t < n � 2'" and then randomly select a monic irreducible polynomial g(x) over �2� of degree t. This is easy to do since the probability that a monic polynomial over IF 2m of degree tis irreducible is -m< 1 '<;" (t) md 1 N 2�(t)2 =2m, L..Jl -d 2 "='-t dlt t according to Theorem 3.25. The irreducibility of a randomly chosen poly­ nomial may be tested by applying one of the factorization algorithms in Chapter 4 to it. We consider now a t-error-correct ing binary irreducible Goppa code l(L, g) of length n and dimension k;;. n -mt. This code has a binary (n-k) x n parity-check matrix H. From H we can derive a binary k x n generator matrix G of i(L,g); compare with Chapter 8, Sections 1 and 3. This generator matrix is scrambled by selecting at random a binary invertible k x k matrix Sand ann x n permutation matrix P-that is, a matrix obtained from 4. Further Cryptosystems 361 the identity matrix by exchanging rows-and forming the new generator matrix G'�SGP. This k x n matrix G' generates a binary linear code with the same length, dimension, and minimum distance as the Goppa code r(L,g). The matrices G, S, and P are kept secret, whereas G' is made public. Let z denote a random binary vector of length n and weight.;; t chosen by the sender. Then the cryptosystem is implemented as follows. 9.22. Goppa-Code Cryptosystem. Enciphering: The plaintext data, given as k-bit blocks x, are enciphered as vectors y � xG' + z. -' Deciphering: On receipt ofy we compute y' � yP , which will be at a Hamming distance at most t from the code word xSG of the Goppa code r(L,g). Decoding y' gives the corresponding message x' � xS, and the plaintext is recovered by computing x = x'S-1. 9.23. Example. We present an example with very small parameters to demonstrate the procedure. However, the cryptosystem in this example does of course not offer any security. We choose m � 3, n � 8, t � 2, and use the Goppa code of dimension k � 2 in Example 8.58, with G being the generator matrix given there. Furthermore , let I .0 0 0 0 0 0 0 0 0 1 0 Q. 0 0 0 0 1 0 0 0 0 0 0 s�G 1) P�r1� 0 0 0 1 0 0 0 0 1 ' 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 Then the public key is G'�SGP�G 0 1 0 I 0 D· 0 1 1 1 Let z � 1 0 0 0 0 0 0 0 Then the plaintext x � 0 I, say, is enciphered as y � I I 0 1 I 1 I I. On receipt of y the authorized receiver computes y' � yP-1 � 1 0 I I 1 1 I l and decodes this to the code word 0 0 I 1111 I with corresponding message x' � 0 1. The plaintext is recovered as x � x·s-1 � 0 I. In this example decoding is performed merely as nearest neighbor decoding-that is, by comparing the received word y' with the nearest code word of Example 8.58 relative to the Hamming distance. For large parameters this approach will be infeasible, but then the efficient decoding algorithm for Goppa codes can do the job for us. D 362 Cryptology In order to break this cryptosystem, an attacker would have to determine G from G' or he might try to recover x from y without knowing G. To find G seems to be a hopeless task ifn and tare large enough, since there are so many possibilities for G, S, and P. If the attacker wants to find xfrom y, this amounts to decoding a random looking linear (n, k) code in the presence of up to t errors. Such an attack is expected to be infeasible for large enough code parameters, since the general decoding problem for linear codes has been shown to be NP-complete. For example, ifm = 10, n = 210 = 1024, and t =50, then there will be about 10149 possible Goppa polynomials and a gigantic number of choices for Sand P. The dimension of the code will be at least 524 and will make brute-force attacks based on comparisons ofy with code words or based on coset leaders impossible. This cryptosystem is not suitable for use in authentication, but its fast communication rate makes it attractive for data communication. We now discuss another scheme for the communication of secret information. Suppose the secret is some data D-for instance, the key for a cryptosystem or a bank safe combination. Then D is divided into n pieces D1, ... ,D, in such a way that for some k < n: (i) knowledge of any k or more pieces D, makes computing D easy; (ii) knowledge of any k-I or fewer pieces D, makes determining D impossible because of insufficient information. Such a scheme is called a (k, n) threshold scheme. It can be helpful in a variety of situations. For instance, if n = 2k-I, the original data D can be recovered even when Ln/2J = k-I of the n pieces D, are destroyed or lost, but an opponent cannot reconstruct D even when security breaches expose k-1 of the remaining k pieces. Other advantages are that a hierarchical scheme is possible where the number of pieces D1 given to each user is proportional to the user's importance. Threshold schemes are well suited to situations where a group of mutually suspicious individuals with conflicting interests must cooperate. By choosing the parameters nand k properly, any sufficiently large majority can be given the authority to take some action, while any sufficiently large minority can be given the power to block it. We describe a (k, n) threshold scheme that was originated by Shamir and by Blakley for f, and f2m, respectively. First we identify D with an element of a suitable finite field f ,. The pieces D, are derived-in a way to be specified-from a random polynomial f(x) = a,_1x'-1 + · · · + a1x + a0Ef,[x] of degree k-1 whose constant term a0 is D. Here q is a prime power larger than n and the number of possibilities for D. If one knows the polynomial f(x), then it is easy to computeD by D = f(O). The pieces D, are obtained by evaluating f(x) at n distinct elements c1, ••• ,c,Ef,-that is, D, = f(c,) fori= 1, 2, ... , n. These c, could be elements of�, which do not have to Exercises 363 be secret; they could be user identifiers. Since any k pairs (c,, D,) uniquely determine a polynomial of degree .;; k-1, the polynomial f(x) and therefore the secret data D can be reconstructed from k pieces, but not from fewer pieces. If the k pieces are denoted by D,,, ... , D,,, then f(x) can be computed by the Lagrange interpolation formula in Theorem 1.71, which yields k ' f(x) = L D,, TI (c,.-c,r 1(x-c,J s"" 1 t = 1 "' 9.24. Example. Let q = 8, n = 3, and k = 2. Suppose we know that D1=/(1)=a+a 2, D2 = f(a) =a, where a E IF 8 is a root of x3 + x + 1. Then f(x) can be reconstructed as follows: f(x) =(a+ a2)(1-a)-1(x- a)+ a( a-W1(x-1) = a(x + a) + ( 1 + a + a 2)(x + 1) =(1 +a2)x + 1 +a. Therefore the secret data is D = f(O) = 1 +a. 0 EXERCISES 9.1. Let s0, s1, ... and t0, t1, ... be the impulse response sequences with characteristic polynomial x4 + x + 1 and x' + x2 + 1 over IF2, respec­ tively. Let h = 2, j, = 0, j, = 1, and Jjl: {0, 1, 2, 3}--+ {0, 1, 2, 3, 4} be defined by Jjl(l) = i + I. Find the first 16 terms of the resulting multiplexed sequence. 9.2. If x15 + x' + x 7 + x2 + 1 and x16 + x15 + x4 + x + 1 are characteristic polynomials oftwo maximal period sequences in f2, respectively, what can you say about the least period of a multiplexed sequence based on these two sequences? 9.3. Suppose we know that a feedback shift register with 5 delay elements has been used to construct a binary sequence s0, s1, ... and that the first 10 values of s, are 0, 1, 0, 1, 0, 1, 1, 1, 0, 1. Find a characteristic polynomial of the sequence and determine the first 20 terms of the sequence. 9.4. In the notation of Definition 9.1, let s0, s1, ... be a kth-order maximal period sequence in IF2 with k > 1 and let 1 .;; h < k. For n = 0, I, ... let P�n), i=O, 1, ... ,2'-1, be the 2' Boolean monomials formed by taking all2' possible products of the terms s.+1,. ... ,s•+J•· Let< be a maximal period sequence in F2 with terms t0, t1, ... and minimal polynomial g(x)EF2[x], and let u0, u1, ••• be the resulting multiplexed 364 sequence. Prove that lh-1 u,= I Pi(n)t,+N(iJ for n=O,l, ... , i=O Cryptology where the integers N(O), N(l), ... , N(2"-I) are completely determined by 1/1(0), 1/1(1), ... , 1/1(2"-1). Moreover, prove that the 2" shifted sequences r<N<<JJ, i = 0, I, ... , 2"-I, are linearly independent in the vector space S(g(x)) over IF 2 defined on p. 215. 9.5. In the proof of Theorem 9.6 it is shown that if r is an mth-order maximal period sequence in the finite prime field f •• then the decimated sequence r:f with d = p' -I and gcd(k, m) = I has least period (pm - I)/ (p-1). Prove more generally that if r is an mth-order linear recurring sequence in an arbitrary finite field f, with least period rand irreducible minimal polynomial, then for j;;. 0 and d;;. I we have: (a) the decimated sequence rYl is either the zero sequence or it has least period rfgcd(d, r); (b) if gcd(d, r):;;; rq1-m, then rYJ has least period r/gcd(d, r). 9.6. How many possible enciphering keys K are there in the cryptosystem in Example 9.7 if q = 1987? 9.7. Letp = 47, q =59, andK =!57 be parameters of an RSA cryptosystem. Find the deciphering parameter D. 9.8. Let q = p = 13 and b = 2. Demonstr ate by a numerical example how each of the schemes in Examples 9.9, 9.10, 9.11, and 9.12 works. 9.9. Show that in the public-key cryptosystem in Example 9.11 it is not advisable to use the same value of k for enciphering more than one message block. 9.10. Use the Silver-Pohlig-Hellman algorithm for q = 73 and b = 5 to find the discrete logarithm of a= 7. 9.11. In Example 9.16let m = 3. Find the discrete logarithms to the base x for all polynomials in V. 9.12. Refer to Example 9.17 and find the discrete logarithm of a(x) = x4 + x3 +x2 +I to the base x. 9.13. Suppose IF32 is defined by f(x) = x' + x2 +I over IF2 and a data base for the second stage of the index-calculus algorithm is given as in Example 9.19, so that m = 2. Compute the discrete logarithm of a(x) = x4 + x + I to the base x. Repeat the calculation under the assumption that m = I. 9.14. For an arbitrary finite field f ,let N(k, m) be the number of polynomials over IF, of degree k all of whose irreducible factors in IF,[x] are of degree :;;; m. Define N(k, 0) = q -I if k = 0, N(k, 0) = 0 if k # 0, and N(k, m) = 0 if k < 0 and m;;. 0. Let N ,(n) be the number of monic irreducible polynomials over IF, of degree n (see Theorem 3.25). For k, m � 1 prove the recurrence m (i+N,(n)-1) N(k, m) = J, '�' N(k-in, n-I) i . Exercises 365 9.15. Let r _1(x) and r0(x) be two nonzero polynomials over a field F with deg(r _1(x));;. 1eg(r0(x)) and d(x) = gcd(r _1(x), r0(x)), and let k be an integer with deg(d(x)) .;; k < deg(r _1(x)). In the notation of Exercise 8.43, prove that there exists a unique index j, 0 .;;j.;; s, such that deg(rix)).;; k and deg(z/x)).;; deg(r _1(x))-k-I. 9.16. In several cryptosystems over f, involving discrete exponentiation it is necessary to generate enciphering keys e and deciphering keys d with e, dElL and ed =I mod(q-1). Show that such keys can be generated in the following way. Let ab =I mod(q-1), where a has the largest possible multiplicat ive order N modulo q-I, and let r be randomly chosen from {0, I, ... , N-I). Then e = a'mod(q-I) and d = b' mod(q- I) are multiplicativ e inverses of each other modulo q-I. 9.17. Prove that a polynomial xm + xm-l + ... +X+ I is irreducible over F2 and its roots o:2;, i = 0, 1, ... , m-1, form a normal basis ofiF2 ... over IF2 if and only if m + I is prime and 2 is a primitive element off m+ 1. (Note: Such all-one polynomials permit an attractive impleme ntation of discrete exponentiation in a normal basis of f2rn over �2.) 9.18. Let b be a primitive element of the finite prime field f ,, p > 2, and let aE f;. Prove that ind,(a) is determined as an element of f, by the formula p-2 ind,(a) =-1 + L (b-i -i)-1ai j=l (Hint: Use the Lagrange Interpolation Formula in Theorem 1.71.) 9.19. Prove that the formula in Exercise 9.18 reduces to p-2 ind,(a) = L (I-bi)-1al j= 1 provided that a# I. (Note: The formulas for discrete logarithms in Exercises 9.18 and 9.19 are of theoretical interest, but useless for computational purposes.) 9.20. Let f(x) be an irreducible polynomial over f, of degree nand let g(x) be an arbitrary polynomial over f ,. Prove that the degree of any nonzero divisor of .f(g(x)) in f,[x] is a multiple of n. (Note: This property is useful in the initial stage of the index-calculus algorithm.) 9.21. Let p, n, f(x), and >/! be as in Example 9.21 and choose the primi­ tive element b(x) = 4x2 + 3 of f 125. Encipher the binary message M = 01010 and then decipher it again. 9.22. Prove that Lemma 9.20 holds also if p is a prime power. 9.23. Show by a counterexample that Lemma 9.20 does not hold in general if (9.14) is replaced by the condition that Lf:Jh,.;; nand If;Jk1.;; n. (Hint: Consider n = 2 and p = 2 or 3.) 9.24. In Example 9.23 use as the matrix P the matrix obtained from the 366 Cryptology identity matrix by exchanging rows one and eight, let s = (: �) and z = I I 0 0 0 0 0 0. Encipher the plaintext x = 0 I with the Goppa-code cryptosystem and decipher the result by using nearest­ neighbor decoding and Example 8.58. 9.25. Explain why the Goppa-code cryptosystem cannot be used for digital signatures. 9.26. Let k = 3 and n = 5 be the parameters of a threshold scheme based on f8 as in Example 9.24. Suppose the following pairs (c,,DJ are known: (I, 0), (IX, 0), (1X2, I +IX). Reconstruct the polynomial f(x) over f 8 and thus find the secret data D. 9.27. A threshold scheme is given by the parameters q = 17, n = 5, and k = 3. Suppose f(i) = 8,f(2) = 7, and f(3) = 10 are three known pairs (c1, D1). Find the secret D. 9.28. Show how discrete exponentiation can be used in a threshold scheme. Also design a scheme in which n;;. 2 mutually suspicious users are all needed to encipher a common secret (for instance, a classified document), but each individual user should be able to gain access to the secret (read the document) and decipher individually. 9.29. A cryptosystem due to L. S. Hill is based on linear transformations of the residue class ring R. = Z/(n). The plaintext is represented as a k­ tuple in R�, enciphering is a nonsingular linear transformation and deciphering is its inverse. (a) Suppose n = 29, k = 2, and the linear transformation is P 4 AP(mod 29), where PERl, and A= G !). Encipher the message "CRYPTOGRAPHY IS FUN." under the assumption that the letters A to Z are denoted by 0 to 25, a period by 26, a comma by 27, and a blank space by 28. (b) This cryptosystem can also be based on linear transformations of f,. Let q = 27, k = 3, choose a nonsingular 3 x 3 matrix with entries in f27 and encipher the message "CIPHER", where A= 0, B = IX0, C = cx1, ... for a primitive element ct of f27. (c) Let A be an m x m matrix with integer entries, let b, xEZm, and let n be a positive integer. Prove that Ax= b mod n has a unique solution x modulo n (where a congruence between vectors is interpreted coordinatewise) if and only if gcd(det(A), n) = I. Find a similar condition for the existence of a unique solution of the equation Ax= b over IFq. Chapter 10 Tables In this chapter we collect tables that facilitate the computation in finite fields and tables of irreducible and primiiive polynomials. The description of these tables is given in Sections I and 2, respectively. 1. COMPUTATION IN FINITE FIELDS Multiplication and division of nonzero elements of F q can be performed using a notion analogous to logarithms. We speak of the index or discrete logarithm. If b is a primitive element of [Fq• then for any aErF: there exists a unique integer r with 0.;; r < q � 1 such. that a= b'. We write r = ind,(u), or simply r = ind(a) if b is kept fixed. The index function satisfies the following basic rules: ind(ac) = ind(a)+ind(c)mod(q -I). ind( ac-1) = ind( a) -ind( c) mod( q-I). The inverse function of the index function. corresponding to taking anti­ logarithms, is denoted by exp, or simply exp, and we have: exp(r)=b', exp(ind( a))=a, ind(exp(r))=r. Given a table of the ind and exp function, it is easy to carry out addition. subtraction, multiplication, and division in IF q· Addition and subtraction are 367 368 Tables performed by using the vector space structure of f 11 over its prime sub field IFP, multipl ication and division are performed by using the rules for the index function and the exp and ind table to co,nvert from one notation to the other. Table A provides a complete list of the nonzero elements and their indices for the finite fields l'q with q composite and q.; 128. In the exp column the parentheses and commas. of the vector notation for the following element of I' 9 with q � p" have been dropped: a=(a1, •••• a11) =a1bn-l+a2bn-2+ ···+a,. O�a;<p. In Table A we use GF(p') to denote the finite field with p" elements. 10.1. Example. As an example for the use of Table A we calculate [(b+ 1)+(2b+2)b](b+2)-1+b in the field 1'9. Working with the portion of the table pertaining to this field. we get ind((2b + 2)b) = ind(2b + 2) +ind(b) = 3+ I= 4mod8, (2b +2)b � exp(4) � 2. Thus. (b + 1)+(2b +2)b �band ind([{ b + I)+ (2b + 2) b ]( b + 2)-1) = ind( b)-ind( b + 2) = I-6 = 3 mod 8. [(b +I)+ (2b +2)b](b +2)-1 � cxp(3) � 2b +2. The final result is (2 b + 2) + b � 2. 0 Table B affords another possibility of doing arithmetic in finite fields. In the first two columns it provides a table of Jacobi's logarithm L( n) for the fields F2, with 2.; k.; 6 (compare with Exercise 2.8). The symbol n � s means that L(n) = s with respect to a fixed primitive element b. In characteristic 2 the value L(O) is undefined. The elements b" are multiplied in the obvious way and added according to the rule given in Exercise 2.8. The symbol "+" preceding the value of n indicates that b" is a primitive element. 10.2. Example. We use Table B to calculate ( b6 + b25 + b44 )(I+ b35) . 1 + b28 in the field IF64• We have b6 + b25 = b6+1-(19l = b40 and b40 + h44 = b40+l.(4J = b12. Since l+b35=b1·C351=b31• we get (b6 + b25 + b44 )(I+ b35) -I� b12b-31 � b41. Furthe rmore, since the argument of the function L and the exponent of h are considered modulo 63, we obtain b41 + b18 = b41 +L<-131 = h41 +L(SOJ = 1. Computation in Finite Fields 369 b101 = b38, which is the final result and happens to be a primitive element of �-D The remainder of Table B provides information about minimal and characteristic polynomials and about dual bases. We take the lines + 20 -+ 26[ I 0000 I] 26 6 49 29 9 46: 19 21-+42[101011] [11] from the table for IF64 over IF2 as illustrations. The symbol [a1 a2 • · · aml indicates that xm + a1x'"-1 + a2xm-2 + · · · +am is the characteristic poly­ nomial of the element with respect to the given field extension. Thus, x' + x' +I is the characteristic polynomial of b20 over IF2 and x' + x' + x3 + x +I is that of b21 over IF2. If b" is a defining element of the extension, then the set of integers between the characteri stic polynomial and the colon describes the dual basis of the polynomial basis determined by b". If b" is not a defining element, then the minimal polynomial of b" with respect to the given extension is listed in the bracket notation explained above. For instance, b20 is a defining element of F64 over IF2 and the dual basis of the polynomial basis {1, b20, b40, b60, b80, b100) is {b26, b6, b49, b 29, b1, b46}. On the other hand, b21 is not a defining element of IF 64 over F 2 and the minimal polynomial of b21 over IF2 is x2 + x +I, so that b21 E F 4• If b" is not only a defining element. but also determines a normal basis of the given extension, then the integer after the colon describes the element determining the dual normal basis. For instance, b20 determines ihe normal _]?asis { b'o • ( b'o )', ( b'o )', ( b'o )', ( b20) 16 • ( b'o )") of F64 over IF2, and its dual basis is given by { bl'. ( bl')'. ( bl')'. ( b")'. ( bl')l'. ( b\9 l"). Elements in subfields except IF2 are denoted in the table by capital letters whose meaning becomes clear upon inspection of the data for minimal polynomials. For example, in the table for F 64 the letter X stands for b21 E IF4 and D stands for b21 E F8. 370 Tables TABLE A exp ind exp ind exp ind exp ind GF(22) GF(25) GF(26) GF(27) 01 0 00011 14 101110 27 0000110 8 10 I 00110 15 Ill \01 28 0001100 9 II 2 01100 16 0\1011 29 0011000 \0 11000 17 1\01\0 30 0110000 II GF(23) 11001 18 001101 31 1100000 12 i\011 19 011010 32 1000011 13 001 0 il\11 20 \\0\00 33 0000101 14 010 I lOIII 21 001001 34 0001010 15 100 2 00111 22 010010 35 00\0\00 16 \0\ 3 01110 23 100100 36 0101000 17 Ill 4 11100 24 101001 37 \010000 18 Oil 5 10001 25 110011 38 0100011 \9 110 6 0\011 26 000111 39 1000110 20 \OliO 27 001110 40 GF(24) 00\01 28 011100 41 0001111 21 010\0 29 0011110 22 0001 0 10100 30 111000 42 0111100 23 0010 I 010001 43 1111000 24 0100 2 GF(26) 1000\0 44 11100\1 25 1000 3 100101 45 1100\0\ 26 \00\ 4 000001 0 \0\011 46 1001001 27 1011 5 000010 110111 47 0010001 28 \Ill 6 000100 2 001111 48 0100010 29 0111 7 00\000 3 011110 49 1000100 30 1110 8 0\0000 4 \11\00 50 000\011 31 0101 9 \00000 5 0\\00\ 51 0010110 32 1010 10 \00001 6 110010 52 0101100 33 I \01 II 100011 7 000101 53 1011000 34 0011 12 100111 8 0010\0 54 0\10011 35 0110 13 10\111 9 010\00 55 1100110 36 1100 14 \l\111 10 101000 56 1001111 37 0\\111 II 110001 57 0011101 38 GF(25) \\\110 12 000011 58 Oil 1010 39 011\01 \3 0001\0 59 II 10100 40 0000\ 0 1110\0 14 001100 60 110\0\\ 41 000\0 I 010\01 15 011000 61 00\00 2 101010 16 110000 62 \0\0101 42 01000 3 110\01 17 0101001 43 10000 4 001011 18 GF(27) 1010010 44 01001 5 0101\0 \9 0100111 45 10010 6 10\100 20 0000001 0 1001110 46 01101 7 0000010 I 0011111 47 11010 8 111001 21 0000100 2 0111110 48 II 101 9 010011 22 0001000 3 1111100 49 10011 10 1001\0 23 0010000 4 Ill \011 50 01111 11 101101 24 0100000 5 1110101 51 11110 12 \11011 25 1000000 6 I \01001 52 10101 \3 010111 26 0000011 7 1010001 53 1. Computation in Finite Fields exp GF(23) 0\0000\ 1000010 0000\11 000\\\0 0011100 0\11000 1110000 11000\\ 100010\ 000100\ 00\0010 0\00\00 100\000 00100\\ 01001\0 \001100 0011011 01\0\10 1101100 \011011 ind 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 01\0\01 74 11010\0 75 \0\0\11 76 0\01\01 77 \011010 78 0\\0\\1 79 1101110 80 \OII\11 81 0\\l\0\ 82 111\0\0 8) 1110111 84 \\0\\0\ 85 \0\\00\ 86 01\000\ 87 1100010 88 1000111 89 0001101 90 00\\010 91 0110\00 92 I \01000 9] \010011 94 010010\ 95 1001010 96 0010111 97 01011\0 98 1011100 99 0\\\0\\ 100 exp ind GF(23) II \0110 \01 I \01111 102 \011\01 103 0\\\00\ \04 1110010 \05 1100111 \06 \001101 107 00\\00\ 108 0\\00\0 \09 1100\00 110 1001011 ill 00\0\0\ 112 01010\0 Ill 1010100 114 0\0\0\\ 115 10\01\0 116 0\0\\11 117 \0111\0 118 Ollllll 119 1111110 120 llllill 121 ll\1101 122 l\1\00\ \2) 1110001 124 1100001 125 1000001 126 GF(l2) 01 0 10 I 21 2 22 J 02 4 20 5 12 6 II 7 GF(l3) 001 0 0\0 I I 00 2 102 J 122 4 022 5 220 6 \0\ 7 e:xp ind GF(l3) 112 222 121 012 120 002 020 200 201 211 Oil 110 202 221 Ill 212 021 210 8 9 10 II 12 \) 14 15 16 17 18 19 20 21 22 23 24 25 GF(l'l 0001 00\0 0\00 1000 2001 \012 2121 2212 0122 1220 1201 lOll 2111 2112 2122 2222 0222 2220 0202 2020 1202 1021 22\l 0112 1120 0201 20\0 0 2 J 4 5 6 7 8 9 10 II 12 \) 14 15 16 17 18 19 20 21 22 23 24 25 26 371 exp ind GF(l'l 1102 0021 0210 2100 2002 1022 2221 0212 2120 2202 0022 0220 2200 0002 0020 0200 2000 1002 2021 1212 1121 0211 2110 2102 2022 1222 1221 1211 ill\ Oil\ 1110 0\01 10\0 2101 2012 1122 0221 2210 0102 \020 2201 0012 0120 1200 1001 2011 1112 0121 27 28 29 30 31 32 )) 34 35 ]6 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 ]72 TABLE A (Cont.) exp ind 1210 75 1101 76 0011 77 0\\0 78 1100 79 GF(52\ 01 0 10 43 2 42 3 32 4 44 5 02 6 20 7 31 8 ]4 9 14 10 33 II 04 12 40 13 12 \4 13 15 23 \6 II 17 OJ 18 30 \9 24 20 21 21 41 22 22 23 GF(53) 00\ 010 100 403 \]2 223 OJ I 3\0 304 244 241 211 411 0 I 2 3 4 5 6 7 8 9 10 II 12 exp ind GF(53) 212 421 312 324 444 042 420 302 224 041 13 14 15 16 17 18 19 20 21 22 410 23 202 24 32\ 25 4\4 26 242 27 221 28 Oil 29 110 30 003 31 030 32 300 ]] 204 ]4 341 35 114 36 043 37 430 38 402 ]9 122 40 123 41 Ill 42 233 43 Ill 44 2\J 45 431 412 222 021 2\0 40\ 112 023 230 101 4\3 232 121 Ill Oll 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 exp ind GF(53) llO 004 040 400 102 423 332 024 240 201 311 3\4 344 144 343 134 243 231 Ill Oil IJO 203 331 0\4 140 303 234 141 3\ J 334 044 440 002 020 200 6\ 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 8\ 82 83 84 85 86 87 88 89 90 91 92 93 94 95 JOI 96 214 97 441 98 0\2 99 120 100 \OJ 101 4]] \02 432 \OJ 422 104 322 105 424 106 342 107 124 108 Tables exp ind GF(53) 143 \09 333 110 034 Ill 340 112 \04 Ill 443 114 032 115 320 116 404 117 142 118 323 119 434 120 442 121 022 122 220 \2] GF(72) 01 0 10 64 2 53 3 56 4 \6 5 54 6 66 7 03 8 JO 9 45 10 12 II \4 12 34 15 44 02 20 51 36 35 25 31 55 06 60 13 \3 14 15 16 17 18 \9 20 21 22 2] 24 25 26 L Computation in Finite Fields 373 exp ind exp ind exp ind exp ind GF(12) GF(l\2) GF(\12) GF(I\2) 24 27 07 12 JO 49 06 84 21 28 70 IJ 60 85 61 29 46 14 52 86 25 15 81 50 89 87 23 30 38 16 4' 51 I • 88 II 3 I 51 17 65 52 94 89 04 32 79 18 '2 53 40 33 26 19 37 54 63 90 32 34 41 55 R2 91 65 35 48 20 85 56 5' 92 63 36 45 21 R' 57 59 93 43 ]7 15 22 2' 58 49 94 62 38 44 23 88 59 55 95 33 39 05 24 09 96 50 25 o• 60 90 97 05 40 69 26 •o 61 23 98 50 41 32 27 17 62 18 99 26 42 'I 28 64 63 41 43 27 29 92 64 74 100 42 44 43 65 86 101 52 45 58 30 '5 66 9' 102 46 46 39 ]\ 67 67 \] 103 22 47 61 32 12 68 24 104 62 33 14 69 28 105 72 34 68 106 GF(\121 66 35 34 70 22 107 02 36 II 71 08 108 01 0 20 37 04 72 80 \09 \0 I 98 38 40 73 '4 2 '3 39 75 74 57 3 96 75 3' 110 29 4 47 40 83 76 71 Ill 78 5 35 4\ 6' 77 56 112 16 6 21 42 42 78 19 113 54 7 'R 43 95 79 84 114 '9 8 97 44 7' 115 '7 9 93 45 73 80 36 116 53 46 76 81 3\ 117 87 10 99 47 '6 82 9\ 118 .. II 03 48 77 83 33 119 The symbol • denotes the element 10 in F 11• 374 TABLE B over IF 2 o� • [OIJ 111 +1�2[ 11]20:1 +2�1 [11]10:2 0 �'[Ill] [I] +I�S [101]43S:I +2�3[ 101]163:2 +3�2 [011]063:­ +4�6 [101]2S6:4 + S �I [011]0 3 S:­ +6 � 4 [011]0 s 6:- over f2 over F 4 o� • [0001] [I] [01] [I] +I� 4[0011]14 2 I 0: - [IX] 4 0: ! +2� 8[0011]13 4 2 0: - [I Y] 8 0: 2 3 � 14 [1111]14 10 I 2: II [YI] 2 S:l3 +4� I [0011]11 8 4 0: -[IX] I 0: 4 s � 10 [0101] [II] [OY] [X] 6�13[1111]13 s 24: 7 [XI] 4 10:11 +7� 9 [1001]9 2 10 I: 6 [XX]8 10:12 +8� 2 [0011] 7 I 8 0: - [IY] 2 0: 8 9� 7 [Ill I] 7 s 8 1:13 [XI] I 10:14 10� s [0101] [II] [OX] +II� 12 [1001]12 I S 8: 3 [YY]4 12�11 [llll]IIIO 48:14 [Yl] 8 +13� 6[1001]6 8 10 4: 9 [XX]2 +14- 3 [1001]3 4 s 2:12 [YY]I F, over F2 0 • [10011] [I] +I �19 [10111]16 3 6 S 17: I +2� 7[10111] 1 61210 3:2 +3�11 [01001]0 282S 6 3:­ +4�14 [10111]2·122420 6: 4 +S�29[01111]4 28 s 14 9:­ +6�22[01001]0 2S 19 12 6: ­ + 7 � 2 [00101]27 20 17 10 3: - +8�28[10111]4 2417 912: 8 + 9 �IS [01111] I 7 9 19 10: - +10�2 7[ 01111]8 2SI02818:­ +II� 3 [11101]2312 7 6 3:1S +12�13[01001]0 19 72412:­ + 13 � 12 [11101]30 1728 2412:29 + 14 � 4 [00101]23 9 3 20 6: - +IS� 9 [11011]2620 S 1910:11 [Y] S: 6 S: 7 10: 3 S: 9 Tables I. Computation in Finite Fields over F2 +16�25[10111]8 17 318 24:16 +17�21[01001]0 1428 3 17:­ +18�30[01111]2 1418 7 20:­ +19� 1 [00101]291024 5 17:- +20�23[01111]16192025 5:­ +21�17 [11101]27 619 3 17:23 +22 � 6 [11101]15 2414 12 6:30 +23 � 20 [11011]13 1018 25 5:21 +24�26[01001]0 71 417 24: ­ + 25 � 16 [00101]30 5 12 18 24: - +26�24[11101]29 32517 24:27 +27�10 [11011]22 5 928 18:26 +28 � 8 [00101]15 18 6 9 12: - +29� 5 [11011]111820 14 9:13 +30�18[11011]21 910 7 20:22 over f2 0-'[010101] [I] + 1-R [101101]44 43 58 54 53 45: - + 2 -16 [101101]25 23 53 45 43 27: 3-53 [010111]60 47 46 43 3 0: + 4-32 [101101]50 46 43 27 23 54: + 5-38 [100001]38 33 28 23 18 43:52 6-43 [010111]57 312923 6 0: 7-62 [001001] 42 35 28 0 56 49: + 8-I [101101]37 29 23 54 4<> 45: 9-45 [010001] [101] + 10-13 [100001]13 3 56 46 36 23:41 +11-5 1[110011]3714 3553648:11 12-23 [010111]51 62 58 46 12 0: - +IJ-10[100111]10 759463323:17 14-61 [001001]21 7 56 0 49 35: - 15-44 [110101]51 36 46 31 47 3:15 + 16- 2 [101101]11 58 46 45 29 27: - + 17-41 [100001]41 24 7 53 36 58:13 18-27 [010001] [101] + 19-34 [100111]34 49 62 43 24 53:20 +20-26 [100001]26 6 49 29 9 46:19 21-42 [101011] [II] +22-39[110011]1128 647 933:22 +23 -12 [000011]40 29 6 46 23 0: - 24-46 [010111]39 61 53 29 24 0: - +25-30 [110011]44 49 24 62 36 6:25 over f4 [Ill] [I] [XXX]47 54 27: 8 [YYY]31 45 54:16 [OYI] 0 6 -3: - [XXX]62 27 45:32 [XYY]23 56 49: [OXI] 0 12 6: - [00 X] 0 56 49: [YYY]61 54 27: I [101] 36 27 45: 9 [ YXX]46 49 35: [Xi Y]55 48 24:25 [OYI] 0 24 12: - [XYX]43 49 35: - [OOY] 0 49 35: - [YO I] 18 3 33:57 [XXX]59 45 54: 2 [XYY]53 14 28: - [101] 9 54 27:18 [ XYX]58 28 56: - [XYY]29 35 7: - [XYI] [X] [ Yl X]47 33 48:50 [IXY]31 24 12:58 [OXI] 0 48 24: - [YIX]62 6 3:11 375 over IF11 [01] [I] [lA] 8 0: I [18]16 0: 2 [FD]42 18:39 [IC] 32 0: 4 [CF] 4 27:59 [D£]21 36:15 [£1] 2 9:25 [lA] I 0: 8 [08] [A] [AD] 8 54:55 [AC]16 54:56 [EF]42 9:30 [A£]32 54:58 [FI] 4 18:50 [CA]21 27: 6 [18] 2 0:16 [AD] I 54:62 [OC] [8] [ 8F] 8 45:46 [8£]16 45:47 [II] 42 0:21 [8A]32 45:49 [£8] 4 9:41 [FD]21 18:60 [AC] 2 54: 7 376 TABLE 8 (Cont.) over f 2 + 26 � 20 [100!11]20 14 55 29 3 46ol4 27�18 [000!01] [Oil] 28-59 [001001]42 \4 49 0 35 7o + 29-48 [000011]34 53 24 58 29 Oo 30-25 [110!01]39 9 29 62 31 6o30 +31�35 [011011]25 2961 02456o­ + 32- 4 [101!01]22 53 29 27 58 54o - 33-58 [010111]30 55 23 53 33 Oo - +34 -19 [100001]19 48 \4 43 9 5U6 35-31 [001001]2\ 49 14 028 56o- 36-54 [0\0001] [!01] +37�57 [\\0011]50 7 33 59\8 24o37 +38-5 [100!11] 5 35 6123 48 4NO 39-22 [\10101]57 \8 23 47 55 33o39 +40-52 [100001]52 12 35 58 !8 29o38 +41-17 [100111]1756 3\5312 58ol0 42-21 [10101\] [II] +43-6 [000011]20 46 3 23 43 Oo - +44-15 [110011]22 5612 3\ \8 3o44 45- 9 [00 0\01] [Oil] +46-24 [000011]17 58 12 29 46 Oo +47-49 [01\0l\]44 46 62 0 12 28o 4H - 29 [010\11]15 59 43 58 48 Oo 49 - 47 [001001]42 56 7 0 14 28o +50-60[\\00II]25 354H6\ 912o50 51-11 [110\0\]60 9 43 55 59 48o5\ +52�40[\00II\]402H2758 629o 5 +53-3 [000011]10 23 33 43 53 Oo 54 � 36 [000\01] [01 \] +55-56 [01101 1]22 23 31 0 6 14o 56-55 [001001]21 28 35 0 7 \4o - 57- 37 [110\01]30 36 53 59 61 24o57 +58-33 [000011] 5 43 48 53 58 Oo­ +59-28 [Ol!Oll]\\ 43 47 0 l 7o- 60 - 50 [\10\01]15 \8 58 6\ 62 IHO +61 � \4 [011011]37 53 55 0 33 35o +62� 7 [0\\01 1]50 58 59 0 48 49o-over f4 [ YXY]23 35 7o [Oil] o 54 n [OOX] 0 35 7o [\XY]61 JJ 48A3 [XOI] 36 6 loll [I!X]46 28 56o [ YYY]55 27 45o 4 [OX\] 0 3 33o [ YXX]43 28 56o [OOY] 0 28 56o [101] \8 45 54o36 [Y\X[59 24 12o44 [ YXYJ53 56 49o - jXOij 9 33 48o60 [YXXJ58 7 14o - [ YXY[29 14 28o - [YXIJ [Yj [\YXJ47 12 6o29 [XI Yjl I J 33o37 [Oil] 0 27 45o­ [IYX[ 62 48 24o53 [1\Yj 23 \428o [OY\j 0 33 48o - [OOX[ 0 14 28o - [X!Yj61 12 6o22 [ Y01j 36 48 24o30 [XYXj46 7 !4o - [\XYJ55 6 3o46 [011[ 0 45 54o­ [1\Xj 43 7 \4o­ [OOYJ 0 7 14o - [XOI] 18 24 12o\5 [\YX] 59 3 3U3 [1\Yj 53 35 7o- [YO!] 9 12 6o39 [l!X]58 4935o [i\Y]29 56 49o -Tables over F8 [BF] I 45o53 [OE] [D] I Dl] 8 36o37 [DA]\6 36o38 [AB]42 54o\2 [ DD]J2 36o40 [JCI 4 om [EF]21 9o51 [BE] 24Hl [D1j I 36o44 [OA] [C] [CB] 8 27o28 [CD]\6 27o29 [BC]42 45o 3 [CF]32 27o31 [A E] 4 54o23 [I\] 21 Oo42 IDA] 2 36o52 [CB] I 27o35 [OD] [F] [FC] 8 18oi9 [FF]\6 !SolO [D£]42 36o57 [Fij 32 1U2 [BA] 4 45o\4 [AB]ll 54oll [CD] 2 27A3 [FC] 1 18o26 [OF] [Ej [EE] 8 9o10 [El] 16 9o\1 [CA]42 27o48 [EB[l2 9o\3 [DD]436o 5 [BC]2\ 45o24 [EF] 2 18o34 [E£] I 9o\7 2. Tables of Irreducible Polynomials 2. TABLES OF IRREDUCIBLE POLYNOMIALS 377 Table C lists all monic irreducible polynomials of degree n over prime fields F1 for small values of n and p. The extent of the table may be summarized as follows: p � 2 and n � ll, p � 3 and n � 7, p � 5 and n � 5, p � 7 and n :s:;: 4. The polynomial a0x�'� + a1xn-l + · · · +an is abbreviated in the form a0 a1 ···a. with a0 � l. The left-hand column, headed by the value of n. lists all monic irreducible polynomials I for the degree n and the modulus p concerned . The right-hand column, headed by e, contains the corresponding value of ord(/ ). Table D lists one primitive polynomial over IF2 for each degree n � 100. In this table only the degrees of the separate terms in the poly­ nomial are given; thus 6 l 0 stands for x6 + x + l. Table E lists all primitive polynomials x2 + a1x + a2 of degree 2 over IFr for ll � p � 31. For smaller primes all quadratic primitive polynomials can be obtained from Table C by locating the polynomials I over IFP with ord(/) � p2 -1. Table F lists one primitive polynomial of degree n over IF, for all values of n;;. 2 andp withp <50 andp" < 109• The polynomial x" + a1x"-1 + a2x�'�- 2 + · · · +an is listed in the form a1 a2 ···an. 378 Tables TABLE C lrredu�ible Polynomials for the Modulus 2 n-1 e 10111001 127 I 0000110 II 511 1111100011 511 10111111 127 I 000 I 0000 I 511 1111101001 511 10 I 11000001 127 1000101101 511 lllllll OII 511 II I 11001011 127 1000110011 511 11010011 127 1001001011 73 n-10 e n=2 e 11010101 127 1001011001 511 11100101 127 100101 1111 511 1000000 1001 1023 Ill 3 11101111 127 1001100101 73 1000000 1111 341 11110001 127 1001101001 511 100000 11011 1023 n�3 e 11110111 127 1001101111 511 100000 11101 341 IIIIIIOI 127 1001110111 511 I 0000 I 00 II I 1023 lOll 7 1001111101 511 I 0000 I 0 I 10 I 1023 1101 7 n=8 e 10 I 0000 I I I 511 I 0000 110 10 I 93 lP<\QljiO) I 1010010101 511 10001000 111 341 n-4 e '• 51 1010011001 73 10001010011 341 100011101 255 1010100011 511 10001100011 341 10011 15 100101011 255 1010100101 511 10001100101 1023 11001 15 100101 101 255 1010101111 511 10001101111 1023 IIIII 5 100111001 17 10101101 11 511 10010000001 1023 100 llllll 85 1010111101 511 10010001011 1023 n-5 e 101001101 255 1011001 111 511 1001001 1001 341 101011111 255 1011010001 511 10010101001 33 100101 31 101100011 255 101101 1011 511 IOOIOIOIIII 341 101001 31 101100101 255 1011110101 511 10011000101 1023 lOIII! 31 101101001 255 1011111001 511 10011001001 341 !lOIII 31 IO!.UOOOI 255 1100000001 73 10011010111 1023 111011 31 (10111011\ 85 1100010011 511 10011100111 1023 111101 31 101111011 85 1100010101 511 10011101101 341 I I 0000 II I 255 1100011111 511 10011110011 1023 n�6 e 110001011 85 1100100011 511 10011111111 1023 110001101 255 1100110001 511 10 I 0000 10 II 93 1000011 63 110011111 51 1100111011 511 10 I 0000 110 I 1023 1001001 9 110100011 85 1101001001 73 10100011001 1023 1010111 21 110101001 255 1101001111 511 10100011111 341 1011011 63 110110001 51 1101011011 511 10100100011 1023 I I 0000 I 63 110111101 85 II 0 I 10000 I 511 101001 10001 1023 1100111 63 I I I 0000 I I 255 1101101011 511 101001 11101 1023 1101101 63 111001111 255 1101101101 511 10101000011 1023 1110011 63 111010111 17 1101110011 511 101010101 11 1023 1110101 21 111011101 85 1101111111 511 10 I 0 II 0000 I 93 111100111 255 I II 0000 10 I 511 10101100111 341 ,, = 7 e 111110011 51 1110001111 511 10101101011 1023 111110101 255 I I 10 I 0000 I 73 10 II 0000 10 I 1023 100000 11 127 IIIIIIOOI 85 1110110101 511 10110001111 1023 10001001 127 1110111001 511 10110010111 1023 10001111 127 n-9 e 1111000111 511 10110011011 341 10010001 127 1111001011 511 10110100001 1023 10011101 127 10000000 11 73 1111001101 511 10110101 011 341 101001 11 127 I 0000 I 000 I 5!1 1111010101 511 101101 11001 341 10101011 127 1000010 II I 73 1111011001 511 10111000001 341 2. Tables of Irreducible Polynomials 379 Irreducible Pol ynomials for the Modulus 2 10111000111 1023 11111011011 1023 100111100101 2047 101111101101 2047 10111100101 1023 11111101011 341 100111101111 89 11000000 1011 2047 10111110111 1023 11111110011 1023 100111110111 2047 11000000 1101 2047 10111111011 1023 11111111001 1023 10 I 00000000 I 2047 110000011001 2047 11000010011 1023 11111111111 II 101000000 111 2047 110000011111 2047 11000010101 1023 101000010011 2047 110000110001 89 110001000 11 33 n=!! e 10100001010 I 2047 110001010111 2047 11000100101 1023 101000101001 2047 110001100001 2047 11000110001 341 I 00000000 10 I 2047 101001001001 2047 110001101011 2047 11000110111 1023 1000000 10111 2047 101001100001 2047 110001110011 2047 11001000011 1023 100000 101011 2047 101001101101 2047 110001110101 23 11001001 111 1023 100000 101101 2047 101001111001 2047 110010000101 2047 11001010001 341 100001000 111 2047 101001111111 2047 IIOOIOOOHlol 2047 11001011011 1023 100001100011 2047 1010 I 0000101 2047 1100100101 11 2047 11001111001 1023 100001100101 2047 10101001 0001 2047 1100100110 11 2047 11001111111 1023 10000 1110001 2047 1010100 11101 2047 110010011101 2047 11010000101 93 10000 1111011 2047 101010100 111 2047 110010110011 2047 11010001001 1023 10001000 1101 :!047 101010101011 2047 110010111111 2047 110101001 11 93 100010010101 2047 1010101 10011 2047 110011000111 2047 11010101101 341 100010011111 2047 101010110101 2047 110011001 101 2047 11010110101 1023 1000 10101001 2047 101011010101 2047 110011010011 2047 11010111111 341 100010110001 2047 101011011111 2047 110011010101 2047 11011000001 1023 100011000011 89 101011100011 23 110011100011 2047 11011001 101 341 100011001111 2047 101011101001 2047 110011101001 2047 11011010011 1023 100011010001 2047 101011101111 2047 110011110111 2047 11011011111 1023 1000 11100001 2047 101011110001 1047 1101000000 11 2047 11011110111 341 100011100111 2047 101011111011 2047 110100001111 2047 11011111101 1023 100011101011 2047 1011000000 11 2047 110100011101 2047 11100001111 341 100011110101 2047 101100001001 2047 1101001001 11 2047 11100010001 341 100100001101 2047 101100010001 2047 110100101101 2047 11100010111 1023 100100010011 2047 101100110011 2047 110101000001 2047 11100011101 1023 100100100101 2047 101100111111 2047 110101000111 2047 11100100001 1023 100100101001 2047 101101000001 2047 110101010101 2047 11100101011 93 1001001101 11 89 101101001011 2047 11010101 1001 2047 11100110101 341 1001001 11011 2047 101101011001 2047 110101100011 2047 11100111001 1023 1001001 11101 2047 101101011111 2047 110101101 111 2047 11101000111 1023 100101000101 2047 101101100101 2047 110101110001 2047 11101001101 1023 100101001001 2047 1011011 01111 2047 110110010011 2047 11101010101 1023 10010101 0001 2047 101101111101 2047 110110011111 2047 11101011001 1023 10010101 1011 2047 101110000111 2047 110110101001 2047 11101100011 1023 100101110011 2047 101110001011 2047 110110111011 2047 11101111011 341 100101110101 2047 101110010011 2047 110110111101 2047 11101111101 1023 1001011111ll 2047 101110010101 2047 110111001001 2047 11110000001 341 100110000011 2047 101110101111 2047 110111010111 2047 11110000111 341 100110001111 2047 101110110111 2047 110111011011 2047 11110001101 1023 10011010101 1 2047 101110111101 2047 110111100001 2047 11110010011 1023 100110101101 2047 10ll11 001001 2047 1101ll100111 2047 11110101001 341 100110111001 2047 101111011011 2047 110111110101 2047 11110110001 1023 100111000111 2047 101111011101 2047 110111111111 89 11111000101 341 100111011001 2047 101111100111 2047 111000000 101 2047 380 Tables TABLE C (Cont.) Irreducible Polynomials for the Modulur 2 111000011101 2047 111001111011 2047 111011111001 2047 111110010001 2047 111000100001 2047 1110011111 01 2047 111100001011 2047 111110010111 2047 111000100111 2047 111010000001 2047 111100011001 2047 111110011011 2047 111000101011 2047 11101001001 1 2047 111100110001 2047 111110100111 2047 111000110011 2047 111010011111 2047 111100110111 2047 111110101101 2047 111000111001 2047 111010100011 2047 111101011101 2047 111110110101 2047 111001000111 2047 111010111011 2047 111101101011 2047 111111001101 2047 111001001011 2047 111011001001 89 111101101101 2047 111111010011 2047 111001010101 2047 111011001111 2047 111101110101 2047 111111100101 2047 111001011111 2047 111011011 101 2047 111101111001 89 1111111 01001 2047 111001110001 2047 111011110011 2047 111110000011 2047 111111111 011 89 Irreducible Polynomials for the Modulus 3 n =I ' 12101 40 120001 242 1011022 728 1111112 728 12112 80 120011 242 1011122 728 1111222 728 10 I 12121 10 120022 121 1012001 182 1112011 91 II 2 12212 80 120202 121 1012012 728 1112201 182 12 I 120212 121 1012021 364 1112222 728 n-5 ' 120221 242 1012112 728 1120102 728 n-2 e 121012 121 1020001 52 1120121 91 100021 242 121111 242 1020101 52 1120222 728 101 4 100022 121 121112 121 1020112 728 1121012 728 112 8 100112 121 121222 121 1020122 728 1121102 728 122 8 100211 242 122002 121 1021021 364 1121122 104 101011 242 122021 242 1021102 56 1121212 728 n�3 e 101012 121 122101 242 1021112 728 1121221 364 101102 121 122102 121 10 21121 91 1122001 91 1021 26 101122 121 122201 22 1022011 364 1122002 104 1022 13 101201 242 122212 121 1022102 56 1122122 104 1102 13 101221 242 1022111 182 1122202 728 1112 13 102101 242 n=6 ' 1022122 728 1122221 364 1121 26 102112 121 1100002 728 1200002 728 1201 26 102122 II 1000012 728 1100012 56 1200022 56 1211 26 102202 121 1000022 728 1100111 364 1200121 364 1222 13 102211 242 1000111 364 1101002 728 1201001 364 102221 22 1000121 364 1101011 28 1201111 182 n=4 ' 110002 121 1000201 52 1101101 364 1201121 182 110012 121 1001012 728 1101112 728 1201201 364 10012 80 110021 242 1001021 364 1101212 728 1201202 728 10022 80 110101 242 1001101 91 1102001 364 1202002 728 10102 16 110111 242 1001122 104 1102111 91 1202021 28 lOIII 40 110122 121 1001221 182 1102121 91 1202101 364 10121 40 111011 242 1002011 364 1102201 364 1202122 728 10202 16 111121 242 1002022 728 1102202 728 1202222 728 11002 80 111211 242 1002101 182 1110001 364 1210001 364 11021 20 111212 121 1002112 104 1110011 364 1210021 364 11101 40 112001 242 1002211 91 1110122 728 1210112 728 IIIII 5 112022 121 1010201 52 1110202 728 1210202 728 11122 80 112102 II 1010212 728 1110221 182 1210211 91 11222 80 112111 242 1010222 728 1111012 728 1211021 182 12002 80 112201 242 1011001 91 1111021 182 1211201 91 12011 20 112202 121 101101 1 364 1111111 7 1211212 728 2. Tables of Irreducible Polynomials 381 Irreducible Polynomials for the Modulus 3 1212011 91 10022021 2186 102020 12 1093 11021122 1093 11201222 1093 12\2022 728 10022101 2186 10210001 2186 11021201 2186 11202002 1093 1212121 14 10022212 1093 10210121 2186 11021212 1093 11202121 2186 1212122 728 10100011 2186 10210202 1093 11022101 2186 11202211 2186 1212212 728 10100012 1093 10211101 2186 11022122 1093 11202212 1093 1220102 728 10100102 1093 10211111 2186 11022211 2186 11210002 1093 1220111 182 10100122 1093 10211122 1093 11022221 2186 11210011 2186 12202\2 728 l0100201 2186 10211221 2186 11100002 1093 11210021 2186 1221001 182 10100221 2186 10212011 2186 11100022 1093 11210101 2186 1221002 104 10101101 2186 10212022 1093 11100121 2186 11211001 2186 1221 I 12 104 10101112 1093 10212101 2186 11100212 1093 11211022 1093 1221202 728 10101202 1093 10212112 1093 11101012 1093 11211122 1093 1221211 364 10l01211 2186 10212212 1093 11101022 1093 11211212 1093 1222022 728 10102102 1093 10220002 1093 11101102 1093 11211221 2186 1222102 728 10102201 2186 10220101 2186 ll!Ollll 2186 11212012 1093 1222112 104 10110022 1093 10220222 1093 11101121 2186 11212112 1093 1222211 364 10110101 2186 10221122 1093 11102002 1093 11212202 1093 1222222 728 l0ll0211 2186 10221202 1093 11102111 2186 11220001 2186 10111001 2186 10221212 !093 11102222 1093 11220112 1093 n-7 e 10111102 1093 10221221 2186 11110001 2186 11220211 2186 10111121 2186 10222012 1093 11110012 1093 11221022 1093 10000102 1093 10111201 2186 10222021 2186 11110111 2186 11221102 1093 10000121 2186 10112002 1093 10222111 2186 11110112 1093 11221112 1093 10000201 2186 10112012 1093 10222202 1093 11110211 2186 11221121 2186 10000222 1093 10112021 2186 102222 11 2186 11110222 1093 11222011 2186 10001011 2186 101121 11 2186 11000101 2186 Iilli (Jj I 2186 11222102 1093 10001012 1093 10112122 1093 11000222 1093 11111021 2186 11222122 1093 10001102 1093 10120021 2186 11001022 1093 11111201 2186 11222201 2186 10001111 2186 10120112 1093 11001112 1093 11111222 1093 11222221 2186 10001201 2186 10120202 1093 11001211 2186 11112011 2186 12000121 2186 10001212 1093 10121002 1093 11002012 1093 11112221 2186 12000202 1093 10002112 1093 10121102 1093 11002022 1093 11120102 1093 12001021 2186 10002122 1093 10121201 2186 11002121 2186 11120111 2186 12001112 1093 100022 11 2186 10121222 1093 11002202 1093 11120122 1093 12001211 2186 10002221 2186 10122001 2186 110!0001 2186 11120212 1093 12002011 2186 1001012 2 1093 10122011 2186 11010022 !093 11120221 2186 12002021 2186 10010222 1093 10122022 1093 11010121 2186 11121001 2186 12002101 2186 10011002 1093 10122212 1093 11010221 2186 11121101 2186 12002222 1093 10011101 2186 10122221 2186 110!1111 2186 11121202 1093 12010021 2186 10011211 2186 10200001 2186 11011202 !093 11122021 2186 120100 22 1093 10012001 2186 10200002 1093 11012002 !093 11122112 1093 1201010 2 1093 10012022 1093 10200101 2186 11012102 1093 11122201 2186 12010121 2186 10012111 2186 10200112 1093 11012212 1093 11122222 1093 12010201 2186 10012202 1093 10200202 1093 11020021 2186 11200201 2186 12010211 2186 10020121 2186 10200211 2186 11020022 1093 11200202 1093 12011102 1093 10020221 2186 10201021 2186 11020102 1093 11201012 1093 12011111 2186 10021001 2186 10201022 1093 11020112 1093 11201021 2186 12011212 1093 10021112 1093 10201121 2186 11020201 2186 11201101 2186 12011221 2186 10021202 1093 10201222 1093 11020222 1093 11201111 2186 12012112 1093 10022002 1093 102020 11 2186 11021111 2186 11201221 2186 12012122 1093 382 Tables TABLE C (Cont.) Irreducible Polynomials for the Modulus 3 12012202 1093 12101201 2186 12112211 2186 12201121 2186 12212122 1093 12012221 2186 12101212 1093 12120002 1093 12201122 1093 12212201 2186 12020002 1093 12101222 1093 12120011 2186 12201202 1093 12212221 2186 12020021 2186 12102001 2186 12120lli 1093 12201212 1093 12220001 2186 12020122 1093 12102121 2186 12120121 2186 12202001 2186 12220012 1093 12020222 1093 12102212 1093 12120211 2186 12202111 2186 12220022 1093 12021101 2186 12110111 2186 12120212 1093 12202112 1093 12220202 1093 12021212 1093 12110122 1093 12121012 1093 12202222 1093 12221002 1093 12022001 2186 12110201 2186 12121022 1093 12210002 1093 12221021 2186 12022111 2186 12110212 1093 12121102 1093 12210112 1093 12221111 2186 12022201 2186 12110221 2186 12121121 2186 12210211 2186 12221122 1093 12100001 2186 12111002 1093 12122012 1093 12211021 2186 12221221 2186 12100021 2186 12111101 2186 12122122 1093 12211201 2186 12222011 2186 121001 11 2186 12111202 1093 12200101 2186 12211211 2186 12222101 2186 12100222 1093 12112022 1093 12200102 1093 12211222 1093 12222211 2186 1210101 1 2186 12112102 1093 12201011 2186 12212012 1093 12101021 2186 12112121 2186 12201022 1093 1221210 2 1093 Irreducible Polynomials for the Modulus 5 n-l ' !Ill 124 n-4 ' 11013 624 12022 624 13102 208 1114 )I 11023 624 12033 624 13121 52 10 I Ill I 62 10002 16 11024 104 12042 624 13124 312 II 2 1134 )I 10003 16 11032 624 12102 208 llll I 26 12 4 1141 62 10014 312 11041 52 12121 13 !Jill 624 13 4 1143 124 10024 312 11042 624 12123 624 13201 78 14 I 1201 62 10034 312 11101 78 12131 52 13203 624 1203 124 10044 312 11113 624 12134 312 13232 624 n=2 e 1213 124 10102 48 11114 312 12201 39 13234 312 1214 31 lOIII 78 11124 104 12203 624 13241 !56 102 8 1222 124 10122 624 11133 208 12211 !56 13302 624 !OJ 8 1223 124 10123 624 11142 208 12222 624 Ill 14 104 Ill ) 1242 124 10132 624 11202 624 12224 312 13322 624 112 24 1244 l I 10133 624 11212 624 12302 624 13323 208 123 24 1302 124 10141 39 11213 208 12311 39 13334 312 124 12 1304 31 1020) 48 11221 !56 12312 208 13341 78 Ill 24 13 II 62 10221 39 11222 208 12324 312 13342 208 134 12 1312 124 10223 208 11234 104 12332 624 13401 !56 141 6 1322 124 10231 78 11244 312 12333 208 13413 208 142 24 1323 124 10233 208 IIJOI !56 12344 104 13423 624 1341 62 10303 48 Ill OJ 624 12401 !56 13424 312 n-) e 1343 124 lOlli !56 11321 39 12414 104 13432 208 1403 124 IOJIJ 208 11342 624 12422 208 13444 104 101 I 62 1404 )I 10341 !56 \\l44 312 12433 624 14004 312 1014 J I 1411 62 10343 208 11402 208 12434 312 14011 52 1021 62 1412 124 10402 48 11411 13 12443 208 14012 624 1024 31 1431 62 10412 624 11414 312 13004 312 14022 624 1032 124 1434 31 10413 624 11441 52 13012 624 14033 624 1033 124 1442 124 10421 !56 11443 624 13023 624 14034 104 1042 124 1444 )I 10431 !56 12004 312 IJOJI 13 14043 624 1043 124 10442 624 12013 624 13032 624 14101 39 1101 62 10443 624 12014 104 13043 624 14112 208 1102 1)_4 11004 "' J?n?l " """" 1M J.i1?1 '"' 2. Tables of Irreducible Polynomials 383 Irreducible Polynomials for the Modulus 5 14134 104 101033 284 103014 781 110123 3124 112034 781 114014 781 14143 624 101103 3124 103022 3124 110131 1562 112104 781 114024 781 14144 312 101104 781 103023 3124 110142 3124 112113 3124 114033 3124 14202 624 101141 1562 103101 1562 110144 781 1121JJ 3124 114044 781 14214 311 101142 3124 103104 781 110202 284 112142 3124 114102 3124 14224 104 101203 3124 103111 1562 110213 3124 112143 284 114132 3124 14231 156 101204 781 103112 3124 110232 3124 112201 1562 114141 1562 14232 208 101212 3124 103143 3124 110243 3124 112212 3124 114201 1562 14242 624 101213 284 103144 71 110244 781 112214 781 114204 71 14243 208 101301 1562 103211 1562 110301 1562 112234 781 114233 3124 14301 156 101302 3124 103212 3124 110303 3124 112241 1562 114242 3124 14303 624 101312 284 103221 1562 110322 3124 112243 3124 114314 781 14312 624 101313 3124 103223 3124 11033 I 1562 112301 1562 114321 1562 14314 312 101401 1562 103232 '3124 110333 3124 112311 1562 114322 3114 14331 78 101402 3124 103233 3124 110343 3124 112313 3124 11433 I 1562 14402 208 101443 3124 103313 3124 110403 3124 112314 781 114343 3124 14411 52 101444 781 103314 781 110411 1562 112323 3124 114401 1562 1441] 624 ·102001 1562 103322 3124 110421 1562 112334 71 114403 3124 14441 26 102004 781 103324 781 110432 3124 112342 3124 114424 781 14444 312 102012 3124 103332 3124 110441 1562 112422 3124 114431 22 102013 3124 103333 3124 110442 3124 112433 3124 114434 781 n-5 e 102021 1562 103401 1562 110444 781 112441 1562 114442 3124 102024 781 103404 781 111003 284 113002 3124 120003 3124 100041 1562 102112 3124 103413 3124 111013 3124 113004 781 120013 3124 100042 3124 102114 781 103414 781 111021 1562 113034 781 120042 3124 100043 3124 102121 1562 103441 142 111022 3124 113044 781 120104 71 100044 781 102122 3124 103442 3124 111024 781 113103 3124 120111 1562 100102 3124 102131 1562 104021 1562 111032 3124 IIlii I 1562 120134 781 100114 781 102134 781 104024 781 111044 781 113134 781 120141 1562 100124 71 102202 3124 104031 142 111102 3124 113142 284 120143 3124 100132 3124 102203 3124 104034 71 111114 781 Ill 143 3124 120201 1562 100143 3124 102211 1562 104101 1562 111123 3124 113211 1562 120212 312 4 100201 1562 102213 3124 104103 3124 111212 44 113222 3124 120222 3124 100212 3124 102242 284 104111 142 111224 781 113224 71 120234 781 100222 284 102244 781 104114 781 111231 1562 113231 1562 120242 3124 100231 1562 102302 3124 104202 3124 111234 781 113241 1562 120243 3124 100244 781 102303 3124 104204 781 111301 1562 113243 284 120244 781 100304 781 102312 3124 104241 1562 111311 1562 IIJJ04 781 120321 1562 100313 3124 102314 781 104243 3124 111312 3124 113312 3124 120332 3124 100323 284 102341 1562 104301 1562 111324 71 113321 1562 120343 3124 100334 781 102343 284 104303 3124 111334 781 IIJJ23 3124 120344 781 100341 1562 102411 1562 104342 3124 111401 142 113324 781 120401 1562 100403 3124 102413 3124 104344 781 111404 781 113332 3124 120402 3124 100411 1562 102423 3124 104402 3124 111423 3124 IIJJ42 3124 120424 781 100421 142 102424 781 104404 781 111431 1562 113412 3124 120431 1562 100433 3124 102431 1562 104411 1562 111433 3124 113422 3124 120432 3124 100442 3124 102434 781 104414 71 111442 3124 113434 781 120441 1562 101022 3124 103002 3124 110004 781 112012 3124 114001 1562 121002 3124 101023 3124 103003 3124 110014 781 112023 3124 114011 1562 121012 3124 101032 284 103011 1562 110041 1562 112032 3124 114012 3124 121013 3124 184 Tables TABLE C (Cont.) Irreducible Polynomials for the Modulus 5 121014 781 12l0l4 781 llOIOl 3124 I 12042 3124 114022 1124 141021 3124 121021 1124 121102 3124 110104 181 132102 3124 ll402l 1124 141024 781 12101 I 1562 12llll ] 124 I 10121 1562 112111 1562 ll40ll 1562 1410ll ]\24 121041 1124 121114 781 I lO Ill 1124 112122 1124 114042 ] 124 141041 1562 121102 1124 \2] \3] 3124 110134 181 132121 ]124 134103 3124 141101 1562 12!!03 284 123141 1562 130144 781 112124 781 134111 1562 141104 71 1211 l I 1562 123142 3124 I 10224 781 I 32� l I 1562 134111 1124 141122 ] 124 121144 181 121224 781 1302ll 1124 112141 1562 1]4122 284 1411 l2 3124 121201 1562 123211 1562 110241 1562 132204 781 I 34132 ] 124 141\]4 781 121202 3124 123242 ]\24 130242 3124 ll221l 3124 134201 1562 141143 3124 121221 ]\24 12ll03 3124 ll0l04 781 I l22l2 3124 114212 ]\24 141204 781 121212 44 12ll II 1562 IJOl I l 1124 132241 142 134224 781 14121 l 1124 1212ll 3124 12llll 1562 I l0l2l 3124 132244 781 I 14302 ll24 141214 781 121244 781 12ll41 142 IJOJJI 1562 132111 1562 I l430l 284 141221 142 121104 781 123144 181 ll0l41 1562 132121 1562 134324 781 14121 I 1562 121ll4 781 121402 1124 130342 3124 ll2ll2 1124 134313 ]\24 14ll I l 44 121142 1124 123411 1562 130341 3124 132413 3124 I 34334 m 14ll21 I 562 121411 ]\24 123412 3124 110401 142 132421 1562 114]41 1562 141ll I 1562 121422 3124 12l41l 3124 110414 781 I 32422 284 134411 22 141334 781 121424 781 123421 1562 130411 1562 1324]] ]\24 !34422 ]\24 141403 1124 121432 1124 123433 284 110442 1124 132443 1124 1344]2 3124 141411 1562 121441 1562 123444 781 110444 781 132444 71 1344]] 3124 \41422 3124 122001 3124 124001 142 lliOOJ 1124 IJJOII 1562 140001 1562 14201J 1124 122004 781 124011 1562 13 lOll 1562 133024 781 140011 1562 142022 1124 1220ll 1124 124022 3124 131012 3124 lll031 1562 140044 781 142031 1562 122043 1124 124023 1124 ll lOll 1124 IJJOJ2 1124 140102 ]124 l420ll 3124 122112 3124 124024 781 111022 1124 Ill IOl 3124 140114 781 142123 3124 122121 284 1240.34 781 1]1014 781 Ill 112 1124 140124 781 142132 ]\24 122124 781 124041 ]124 131042 3124 Ill Ill ]\24 1401 ll 1124 142144 781 122132 3124 124114 II ll 1112 3124 ]]] 114 781 140141 1562 142204 7RI 122141 142 124\23 ]124 ll 1121 1562 113124 781 140141 ]124 142211 1562 122142 3124 124\32 3124 llll2l ]\24 13lll2 284 140144 781 142212 ]\24 122214 781 12413] 1124 I l II ll 3124 IJJ141 1562 140202 3124 142214 781 122224 781 124202 284 ll 1144 781 133202 ]\24 140204 781 142222 1124 1222ll 3124 124203 3124 ll 1201 1562 133214 181 140223 3124 142231 142 122101 1562 124221 1562 I l 121 I 1562 lll2l4 781 140232 3124 142243 3124 122312 3124 124231 1562 ll124l 3124 13]241 1562 140214 781 142104 781 122333 3124 124232 3124 ll130l 3124 lll244 71 140242 3124 142111 1562 122341 1562 124244 781 131104 781 llll21 1562 140l0l 284 142313 3124 122344 71 124104 781 I l 1122 l 124 lllll4 781 140]12 ll24 142331 1562 122401 1124 124113 3124 Ill 3]2 3124 133343 3124 140133 3124 142142 3124 122414 781 124321 1562 llllll 44 lll40l 1124 140141 1562 142144 781 122421 1562 124402 1124 ll I 141 1562 lll411 1562 140142 l 124 142401 1562 122422 1124 124412 3124 1]1402 284 1]3412 ]124 140422 1124 142412 3124 122423 3124 124414 781 ll140l 3124 lll4l2 1124 140434 781 1424]2 3124 122434 781 124423 284 131434 781 lll443 l 124 140441 1562 142442 284 122444 781 124433 1124 131441 1562 I ll444 781 140441 1124 142443 ]124 121014 781 130002 3124 132001 1562 I 14004 71 141002 284 141001 1562 121021 1562 1)0012 ]124 1)2002 3124 114014 781 1410!2 3124 143001 3124 12l0ll 1124 ll004l 3124 132032 l 124 114021 I 562 141021 1562 14l0ll 1562 2. Tables of Irreducible Polynomials 143041 143113 14312l 143131 143201 143213 143221 143222 "=I 10 11 12 13 14 15 16 n=2 101 102 104 ill 114 116 122 123 125 131 135 136 141 145 146 152 153 155 163 164 166 n=3 1002 1003 1004 1005 lOll . "" 1562 3\24 3124 1562 1562 3124 1562 3124 ' 1 2 6 3 6 3 1 e 4 12 12 48 24 16 24 48 48 8 48 16 8 48 16 24 48 48 48 24 16 e 18 9 18 9 114 --143224 143233 143243 143314 143321 143323 143334 143342 1021 1026 1032 1035 1041 1046 1052 1055 1062 1065 1101 1103 1112 1115 1124 1126 ill 1 1135 1143 1146 1151 1152 1153 1154 1163 1165 1201 1203 1214 1216 1223 1226 1233 1235 1242 1245 1251 1255 1261 1262 1263 . �' . Irreducible Polynomials for the Modulus 5 781 143344 781 144013 3124 144131 3124 143402 3124 144014 781 144134 3124 143414 781 144021 1562 144143 781 143431 1562 144032 3124 144211 142 143442 3124 144041 1562 144223 3124 143443 284 144102 3124 144224 781 144004 781 144104 781 144234 284 144011 1562 144121 1562 144242 Irreducible Polynomials for the Modulus 7 38 19 342 171 114 57 342 171 342 171 114 171 342 171 342 57 38 171 171 57 114 342 171 342 171 171 38 171 342 57 l7l 57 171 171 342 171 114 171 114 342 171 . .. 1304 1306 llll 1314 1322 1325 llll ll34 1335 ll36 1341 1343 1352 1354 1362 1366 1401 1403 14ll 1416 1422 1425 1431 1432 1433 1434 1444 1446 1453 1455 1461 1465 1504 1506 1511 1513 1521 1524 1532 1534 1542 . - -342 57 38 342 342 171 171 342 171 19 38 171 342 342 342 57 114 171 171 19 342 171 38 342 171 342 342 19 171 171 114 171 342 19 114 171 114 342 342 342 342 -1552 342 10135 1556 57 10145 1563 171 10151 1564 342 10161 1565 171 10162 1566 57 10203 1604 342 10205 1606 57 10 211 1612 342 10214 1615 171 10224 1621 114 10236 1623 171 10246 1632 342 10254 1636 19 10261 1641 114 16264 1644 342 10305 1653 171 10306 1654 342 10316 1655 171 10322 1656 57 10326 1662 342 10333 1664 342 10334 10335 n=4 e 10343 10344 10011 400 10345 10012 1200 10352 10014 1200 10356 10023 480 10366 10025 480 10405 10026 160 10406 10053 480 10412 10055 480 10414 10056 160 10422 10061 400 10433 10062 1200 10443 10064 1200 10452 10103 96 10462 10106 32 10464 lOlli 400 10503 10112 600 10505 385 1562 144301 142 11 144304 781 3124 144332 3124 1562 144343 3124 3124 144403 3124 781 144433 3124 781 144444 781 3124 2400 10524 1200 2400 10525 2400 200 10531 80 400 10533 2400 600 10536 800 96 10541 80 96 10543 2400 200 10546 800 1200 10554 1200 600 10555 2400 800 10565 2400 800 10603 96 600 10606 32 200 10613 2400 1200 10621 400 96 10623 2400 32 10632 240 800 10635 2400 1200 10636 800 800 10642 240 2400 10645 2400 240 10646 800 2400 10651 400 2400 10653 2400 240 10663 2400 2400 11001 400 1200 11003 480 800 llOll 2400 800 11026 800 96 11031 400 32 11042 75 1200 11054 300 600 11056 800 600 11062 1200 2400 11063 2400 2400 11101 400 600 I i lOJ 2400 1200 11105 2400 600 11111 5 96 11112 1200 96 11124 75 386 Tables TABLE C (C011t.l Irreducible Polyllomials for the Modulus 7 11136 800 11556 800 12266 800 12665 480 13432 1200 14125 2400 11141 400 11562 1200 12303 2400 13004 1200 13434 1200 14132 1200 11152 1200 11566 160 12304 240 13005 480 13436 800 14145 2400 11153 2400 11602 240 12311 200 ll011 400 13441 20 14156 800 11161 100 11605 2400 12323 2400 13015 2400 13443 2400 14165 2400 11163 480 11614 600 12325 2400 13022 300 13445 2400 14204 1200 11166 800 11625 2400 12332 120 13023 2400 ll455 2400 14205 2400 11201 200 11626 800 12345 480 13031 50 13456 800 14206 800 11204 600 11631 40 12346 800 13044 1200 IJ465 2400 14211 400 11213 2400 11643 2400 12351 100 13053 2400 13501 80 14214 15 11223 2400 11646 160 12354 600 13065 2400 13506 800 14222 75 11225 2400 11652 600 12356 800 13103 2400 13512 600 14232 240 11232 60 11653 2400 12361 200 13106 800 13513 2400 142JJ 2400 11233 2400 11654 300 12363 2400 13115 2400 13516 800 14244 1200 11236 800 11664 600 12365 2400 13126 800 13521 200 14251 400 11241 400 11665 2400 12402 1200 13135 2400 13522 300 14255 2400 11244 1200 11666 800 12403 2400 13142 1200 13525 2400 14263 2400 11245 2400 12002 1200 12406 800 13151 400 13533 480 14264 300 11252 240 12006 160 12412 15 13155 2400 13535 2400 14265 480 11254 300 12016 800 12414 1200 13161 400 13544 120 14302 1200 11266 160 12025 2400 12421 25 13166 160 13553 2400 14314 ISO 11321 200 12032 1200 12431 80 13204 1200 13556 800 14325 2400 11323 2400 12044 75 12435 2400 13205 2400 13562 600 14335 2400 11324 ISO 12051 100 12442 1200 13206 800 13611 40 14341 25 IIlli 400 12055 2400 12454 1200 13213 2400 13612 1200 14346 800 11332 300 12064 1200 12456 800 13214 300 13616 800 14353 2400 11334 600 12066 800 12462 300 13215 480 13623 480 14354 1200 11351 200 12101 200 12465 2400 13221 400 13624 600 14361 400 11355 2400 12102 600 12466 160 13225 2400 13626 800 14363 480 11356 160 12116 800 12521 so 13234 1200 13641 100 14402 600 11362 120 12123 2400 12522 600 13242 240 13642 600 14404 600 11364 1200 12126 800 12526 800 13243 2400 13644 1200 14415 2400 11365 2400 12134 60 12531 200 13252 ISO 13652 75 14425 2400 11405 2400 12135 2400 12532 1200 13261 400 13654 600 14426 800 11406 800 12136 800 12534 300 13264 30 13655 2400 14431 20 11412 1200 12141 400 12552 600 13302 1200 14004 1200 144JJ 2400 11415 480 12142 1200 12553 2400 13311 400 14005 480 14435 2400 11422 1200 12143 2400 12555 480 13313 480 14015 2400 14442 1200 11423 2400 12151 100 12561 400 13323 2400 14023 2400 14444 1200 11434 1200 12154 240 12563 2400 13324 1200 14034 1200 14446 800 11443 2400 12165 480 12564 120 IJJ31 50 14041 25 14451 80 11455 2400 12203 2400 12601 400 13336 800 14052 300 14452 300 11463 2400 12205 2400 12612 150 13345 2400 14053 2400 14463 480 11504 1200 12213 480 12626 800 ll355 2400 14061 400 14SOI 80 11511 so 12214 1200 12636 800 lll64 75 14065 2400 14506 800 11523 2400 12224 1200 12643 2400 13402 600 14103 2400 14512 600 11533 2400 12226 800 12644 75 13404 600 14106 800 14523 2400 11542 75 12231 400 12652 1200 13413 480 14111 400 14526 800 11545 2400 12246 800 12655 2400 13421 80 14116 160 14534 120 11551 400 12253 2400 12664 1200 13422 300 14121 400 14543 480 2. Tables of Irreducible Polynomials 387 Irreducible Polynomials for !he Modulus 7 14545 2400 l5l2\ 100 15353 2400 15622 1200 16204 600 16453 2400 14551 200 15124 240 15355 2400 15625 2400 16216 160 16462 1200 14552 300 15131 400 15361 200 15633 2400 16222 240 16465 480 14555 2400 15132 1200 15402 1200 15634 150 16224 300 16504 1200 14562 600 15133 2400 15403 2400 15646 800 16231 400 16512 1200 14563 2400 15144 60 15406 800 15656 800 16234 1200 16516 160 14566 800 15145 2400 15412 300 15662 75 16235 2400 16521 400 14622 !50 15146 800 15415 2400 16001 400 16242 60 16526 800 14624 600 15153 2400 15416 160 16003 480 16243 2400 16532 150 14625 2400 15156 800 15424 1200 16012 1200 16246 800 16535 2400 14631 100 15166 800 15426 800 16013 2400 16253 2400 16543 2400 14632 600 15203 2400 15432 1200 16024 300 16255 2400 16553 2400 14634 1200 15205 2400 15441 80 16026 800 16263 2400 16561 25 14653 480 15216 800 15445 2400 16032 !50 16312 120 16602 240 14654 600 15223 2400 15451 50 16041 400 16314 1200 16605 2400 14656 800 15236 800 15462 30 16056 800 16315 2400 16614 600 14661 40 15241 400 15464 1200 16063 2400 16321 200 16615 2400 14662 1200 15254 1200 15511 400 l6l0l 400 16325 2400 16616 800 14666 800 15256 800 15513 2400 16103 2400 16>26 160 16622 600 15002 1200 15263 480 15514 120 16105 2400 16341 400 16623 2400 15006 160 15264 1200 15522 600 l6lll 100 16342 300 16624 300 15014 1200 15303 2400 15523 2400 l6lll 480 16344 600 16633 2400 15016 800 15304 240 15525 480 l6ll6 800 16351 200 16636 160 15021 100 15311 200 15541 200 16122 1200 16353 2400 16641 40 15025 2400 15313 2400 15542 1200 16123 2400 16)54 75 16655 2400 15034 !50 15315 2400 15544 300 l6l3l 400 16405 2400 16656 800 15042 1200 15321 100 15551 25 16144 240 16406 800 16664 600 15055 2400 15324 600 15552 600 16146 800 16413 2400 15066 800 15326 800 15556 800 16154 150 16425 2400 l5l0l 200 15335 480 15601 400 l6l6l lO 16433 2400 15102 600 15336 800 15614 1200 16162 1200 16444 1200 15115 480 15342 120 15615 480 16201 200 16452 1200 388 Tables TABLE D I 0 51 6 3 0 2 I 0 52 3 0 3 I 0 53 6 2 I 0 4 I 0 54 6 5 4 3 2 0 5 2 0 55 6 2 I 0 6 I 0 56 7 4 2 0 7 I 0 57 5 3 2 0 8 4 3 2 0 58 6 5 I 0 9 4 0 59 6 5 4 3 0 10 3 0 60 I 0 II 2 0 61 5 2 I 0 12 6 4 0 62 6 5 3 0 13 4 3 0 63 I 0 14 5 3 0 64 4 3 o· 15 I 0 65 4 3 0 16 5 3 2 0 66 8 6 5 3 2 0 17 3 0 67 5 2 I 0 18 5 2 0 68 7 5 I 0 19 5 2 0 69 6 5 2 0 20 3 0 70 5 3 I 0 21 2 0 71 5 3 I 0 22 I 0 72 6 4 3 2 0 23 5 0 73 4 3 2 0 24 4 3 0 74 7 4 3 0 25 3 0 75 6 3 I 0 26 6 2 0 76 5 4 2 0 27 5 2 0 77 6 5 2 0 28 3 0 78 7 2 I 0 29 2 0 79 4 3 2 0 30 6 4 0 80 7 5 3 2 0 31 3 0 81 4 0 32 7 5 3 2 0 82 8 7 6 4 0 33 6 4 I 0 83 7 4 2 0 34 7 6 5 2 0 84 8 7 5 3 0 35 2 0 85 8 2 I 0 36 6 5 4 2 0 86 6 5 2 0 37 5 4 3 2 0 87 7 5 I 0 38 6 5 I 0 88 8 5 4 3 0 39 4 0 89 6 5 3 0 40 5 4 3 0 90 5 3 2 0 41 3 0 91 7 6 5 3 2 0 42 5 4 3 2 0 92 6 5 2 0 43 6 4 3 0 93 2 0 44 6 5 2 0 94 6 5 I 0 45 4 3 I 0 95 6 5 4 2 0 46 8 5 3 2 0 96 7 6 4 3 2 0 47 5 0 97 6 0 48 7 5 4 2 0 98 7 4 3 2 0 49 6 5 4 0 99 7 5 4 0 50 4 3 2 0 100 8 7 2 0 2. Tables of Irreducible Polynomials 389 TABLE E p-11 n-2 q-121 120�2'·3·5 �(120)/2 � 16 a, a, a, a, a, a, a, a, 4 2 2 6 I 7 ) 8 5 2 3 6 4 7 3 8 6 2 8 6 7 7 8 8 7 2 9 6 lO 7 lO 8 p-13 n=2 q -169 168-23·3·7 �( 168)/2-24 a, a, a, a, a, a, a, a, I 2 2 6 2 7 4 II 4 2 3 6 3 7 5 ll 6 2 4 6 6 7 6 ll 7 2 9 6 7 7 7 ll 9 2 10 6 10 7 8 II 12 2 II 6 II 7 9 II p-17 n-2 q � 289 288""'25·32 �(288)/2 - 48 a, a, a, a, a, a, a, a, I 3 2 6 I 10 2 12 6 3 6 6 3 10 3 12 7 3 8 6 4 10 5 12 10 3 9 6 13 10 12 12 II 3 II 6 14 10 14 12 16 3 15 6 16 10 15 12 3 5 I 7 2 II 4 14 5 5 4 7 7 II 6 14 8 5 5 7 8 II 7 14 9 5 12 7 9 II lO 14 . 12 5 13 7 lO II II 14 14 5 16 7 15 II 13 14 p -19 n=2 q-361 360 -23·32·5 �(360)/2 � 48 a, a, a, a, a, a, a, a, I 2 10 3 3 13 II 14 4 2 II 3 4 13 12 14 7 2 12 3 6 13 13 14 8 2 18 3 9 13 18 14 II 2 2 10 10 ll 4 15 12 2 4 10 13 13 5 15 15 2 6 10 15 13 6 15 18 2 9 lO 16 13 9 15 I 3 10 lO I 14 10 15 7 3 13 lO 6 14 13 15 8 3 15 10 7 14 14 15 9 3 17 10 8 14 15 15 p-23 n-2 q-529 528-24·3· II �(528)/2-80 a, a, a, a, a, a, a, a, a, a, 2 5 2 10 I 14 3 17 4 20 4 5 3 10 3 14 4 17 7 20 5 5 6 10 5 14 6 17 8 20 8 5 10 10 10 14 II 17 10 20 15 5 13 10 13 14 12 17 13 20 18 5 17 10 18 14 17 17 15 20 390 Tables TABLE E (Cont.) p-23 n-2 q� 529 528-24·3·11 �(528)/2 -80 a, a, a, a, a, a, a, a, a, a, 19 5 20 10 20 14 19 17 16 20 21 5 21 10 22 14 20 17 19 20 I 7 3 II 5 15 I 19 5 21 2 7 7 II 9 15 2 19 6 21 4 7 8 II 10 15 7 19 7 21 9 7 9 II II 15 II 19 9 21 14 7 14 II 12 15 12 19 14 21 19 7 15 II 13 15 16 19 16 21 21 7 16 II 14 15 21 19 17 21 22 7 20 II 18 15 22 19 18 21 p-29 n-2 q�841 840-21·3·5·7 �(840)/2 -96 a, a, a, a, a, a, a, a, a, a, a, a, 5 2 I 8 6 II 7 15 2 19 5 26 7 2 7 8 9 II 9 15 4 19 6 26 II 2 10 8 10 II II 15 7 19 8 26 14 2 14 8 II II 12 15 8 19 12 26 15 2 15 8 18 II 17 15 21 19 17 26 18 2 19 8 19 II 18 15 22 19 21 26 22 2 22 8 20 II 20 15 25 19 23 26 24 2 28 8 23 II 22 15 27 19 24 26 I 3 3 10 I 14 4 18 3 21 2 27 2 3 5 10 3 14 8 18 4 21 3 27 9 3 9 10 8 14 13 18 6 21 6 27 14 3 10 10 13 14 14 18 12 21 13 27 15 3 19 10 16 14 15 18 17 21 16 27 20 3 20 10 21 14 16 18 23 21 23 27 27 3 24 10 26 14 21 18 25 21 26 27 28 3 26 10 28 14 25 18 26 21 27 27 p-31 n-2 q""' 961 960-26·3·5 �(960)/2 -128 a, a, a, a, a, a, a, a, a, a, a, a, a, a, a, a, 2 3 2 II I 12 I 13 I 17 2 21 22 I 24 5 3 3 II 3 12 4 13 2 17 5 21 4 22 3 24 6 3 4 II 4 12 6 13 3 17 7 21 5 22 4 24 7 3 5 II 10 12 8 13 6 17 8 21 7 22 5 24 8 3 6 II II 12 9 13 7 17 II 21 9 22 7 24 10 3 9 II 12 12 10 13 8 17 12 21 10 22 8 24 14 3 II II 14 12 12 13 9 17 13 21 14 22 12 24 15 3 15 II 15 12 13 '13 II 17 15 21 15 22 13 24 16 3 16 II 16 12 18 13 20 17 16 21 16 22 18 24 17 3 20 II 17 12 19 13 22 17 18 21 17 22 19 24 21 3 22 II 19 12 21 13 23 17 19 21 21 22 23 24 23 3 25 II 20 12 22 13 24 17 20 21 22 22 24 24 24 3 26 II 21 12 23 13 25 17 23 21 24 22 26 24 25 3 27 II 27 12 25 13 28 17 24 21 26 22 27 24 26 3 28 II 28 12 27 13 29 17 26 21 27 22 28 24 29 3 29 II 30 12 30 13 30 17 29 21 30 22 30 24 2. Tables of Irreducible Polynomials 391 TABLE F p" a1a2a3 · · . "· p" ala2a3 . . . a, p" a1a2 · · · a,_1a, 2 II 5' 12 192 I 2 2' 101 5' 102 193 10 16 2' 1001 5' 101J 194 100 2 2' 01001 5' 00102 19' 0001 16 2' 100001 5' 100002 196 00001 3 2' 0000011 5' 1000002 197 010000 9 2' 11000011 5' 00101003 2' 000100001 5' 011000003 232 I 7 2" 001000000 1 5" 101000000 3 233 10 16 2" 0100000000 I 5" 10000000002 234 001 II 2" 110000010001 5" 0000 I 00 I 0003 23' 1000 18 2" 110010000000 I 236 1 0000 7 2" 11000000000 10 I 2" I 0000000000000 I 7' 13 292 I 3 2" 10100000000 I 0001 7' 112 29' 01 18 2" 0010000000000000 I 7' 1103 294 100 2 2" 0000001 0000000000 I 7' 10004 29' 0100 26 2" 1100 I 0000000000000 I 7' 110003 296 00001 3 2" 001000000000000000 I 7' 0100004 2" 01000000000000000 I 7' 1000000 3 2" 10000000000000001 7' 100001002 3 12 I 12 2" 0000 I 000000000000000 I 7" 110000000 3 3 13 01 28 2" II 0000 I 0000000000000001 31' 100 lJ 2" 001000000000000000 1 3 I' 0100 20 2" 110001000000000000000 I 112 17 316 10000 12 2" 11001000000000000000 1 113 105 2" 001000000000000000 1 114 0012 2" 01000000000000000 1 11' Oli09 372 I 5 11' 100017 37' 10 24 11' 1000005 374 001 2 11' 000 10012 37' 0001 32 3' 12 3' 201 3' 1002 IJ' I 2 412 I 12 3' 10101 IJ' 10 7 413 01 35 3' 100002 IJ' 101 2 414 001 17 3' 1010001 13' 0101 II 41' 1000 35 3' 00100002 13' 10100 6 J' 010100001 13' 001000 6 432 I 3 3" 101000000 2 13' 0110000 2 433 0140 3" 100000 I 000 I 434 001 20 3" 1000 I 0000002 43' 100040 3" I 00000 I 00000 I 172 I 3 3" I 000000000000 2 173 01 14 3" 1000000000 1000 I 17' 100 5 472 I 13 3" 000000 1000000002 17' 1000 14 473 10 42 3" I 0000000 I 0000000 I 17' 10000 3 474 100 5 3" I 00000000000 I 00002 17' 000100 14 47' 0001 42 BIBLIOGRAPHY Note. We Jist only textbooks suggested for further reading and some basic research articles. A more detailed bibliography can be found in: Lidl, R., and Niederreiter, H.: Finite Fields, Encyclopedia of Math. and Its Appl., voL 20, Addison- Wesley, Reading, Mass., 1983; now published by Cambridge University Press. Chapter 1 Books on Abstract Algebra: Birkhoff, G., and MacLane, S.: A Survey of Modern Algebra. 4th ed., Macmillan, New York, 1977. Fraleigh, J. B.: A First CoW'se in Abstract Algebra. Addison-Wesley, Reading, Mass., 1982. Herstein, I. N.: Topics in Algebra. 2nd ed., Xerox College Publ., Lexington, Mass., 1975. Lang, S.: Algebra, Addison-Wesley, Reading, Mass., 1971. ROOei, L.: Algebra, Pergamon Press, London, 1967. van der Wae:rden, B. L.: Algebra, vol. 1, 7th ed., Springer-Verlag, Berlin, 1966. Books on Applied Algebra: Birkholf, G., and Bartee, T. C.: Modern Applied Algebra. McGraw-Hill, New York, 1970. Dornholf, L L, and Hohn, F. E.: Applied Modern Algebra. Macmillan, New York, 1978. Lid!, R., and Pilz, G.: Applied Abstract Algebra, Springer-Verlag, New York, 1984. 392 Bibliography Chapter 2 Dickson, L. E.: linear Groups with an Exposition of the Galois Field Theory, Teubner, Leipzig, 1901; Dover, New York, 1958. Herstein, I. N.: Noncommutative Rings, Carus Math. Monographs, no. 15, Math. Assoc. of America, Washington, D.C., 1968. Hoffman, K., and Kunze, R.: Linear Algebra, 2nd ed., Prentice-Hall, Englewood Cliffs, N.J., 1971. Jacobson, N.: Uctures in Abstract Algebra, vol. 3: Theory of Fields and Galois Theory, Springer-Verlag, New York, 1980; originally published by Van Nostrand, New York, 1964. Chapter 3 Albert, A. A.: Fundamen tal Concepts of Higher Algebra, Univ. of Chicago Press, Chicago, 1956. Berlekamp, E.R.: Algebraic Coding Theory, McGraw-Hill, New York, 1968. MacWilliams, F. 1., and Sloane, N.J. A.: The Theory of Error-Correcting Codes, North-Holland, Amsterdam, 1977. Ore, 0.: On a special class of polynomials, Trans. Amer. Math. Soc. 35, 559-584 (1933); Errata, ibid. 36, 275 (1934). Ore, 0.: Contributions to the theory of finite fields, Trans. Amer. Math. Soc. 36, 243-274 (1934). Chapter 4 393 Berlekarnp, E. R.: Algebraic Coding Theory, McGraw-Hill, New York, 1968. Berlekamp, E. R.: Factoring polynomials over large finite fields, Math. Comp. 24, 713-735 (1970). Cantor, D. G., and Zassenhaus. H.: A new algorithm for factoring polynomials over finite fields, Math. Comp. 36. 587-592 (1981). Knuth, D.E.: The Art of Computer Programming, vol. 2: Seminumerical Algorithms, 2nd ed., Addison-Wesley, Reading, Mass., 1981. McEliece, R. 1.: Factorization of polynomials over finite fields, Math. Comp. 23, 861-867 (1969). Rabin, M. 0.: Probabilistic algorithms in finite fields, SIAM J. Computing 9, 273- 280 (1980). Zassenhaus, H.: On Hensel factorization I, J. Number Theory I, 291-311 (1969). Chapter S Hasse, H.: Vorlesungen Uber Zahlentheorie, 2nd ed., Springer-Verlag, Berlin, 1964. Ireland, K., and Rosen, M.: A Classical Introduction to Modern Number Theory, Springer-Verlag, New York, 1982. 394 Bibliography Chapter 6 Berlekamp, E. R.: Algebraic Coding Theory, McGraw-Hill, New York, 1968. Fillmore, J. P., and Marx, M.L.: Linear recursive sequences, SIAM Rev. 10, 342- 353 (1968). Golomb, S. W.: Shift Register Sequences, Aegean Park Press, Laguna Hills, Cal., 1982. Massey, J. L.: Shift-register synthesis and BCH decoding, IEEE Trans. Information Theory 15, 122-127 (1969). Niederreiter , H.: On the cycle structure of linear recurring sequences, Math. Scand. 38, 53-77 (1976). Zierler, N.: Linear recurring sequences, J. Soc. Jndust. Appl. Math. 7, 31-48 (1959). Chapter 7 Finite Geometries: Albert, A.A., and Sandler, R.: An Introduction to Finite Projective Planes, Holt, Rinehart and Winston, New York, 1968. Dembowski, P.: Finite Geometries, 2nd ed., Springer-Verlag, Berlin, 1977. Hirschfeld, J. W. P.: Projective Geometries over Finite Fields, Clarendon Press, Oxford, 1979. Hughes, D. R., and Piper, F. C.: Projective Planes, Springer-Verlag, New York, 1973. Combinatorics: Beth, T., Jungnickel, D., and Lenz., H.: Design Theory., Bibliographisches Jnstitut, Mannheim, 1985. Brualdi, R. A.: Introductory Combinatorics, North-Holland, Amsterdam, 1977. Denes, J., and Keedwell, A. D.: Latin Squares and Their Applications, Academic Press, New York, 1974. Hall, M., Jr.: Combinatorial Theory, Blaisdell, Waltham, Mass., 1967. Raghavarao, D.: Constructions and Combinatorial Problems in Design of Experiments, Wiley, New York, 1971. Ryser, H. J.: Combinatorial Mathematics, Carus Math. Monographs, no. 14, Math. Assoc. of America, New York, 1963. Storer, T.: Cyclotomy and Difference Sets, Markham, Chicago, 1967. Linear Modular Systems: Arbib, M.A., Falb, P. L., and Kalman, R. E.: Topics in Mathematical System Theory, McGraw-Hill, New York, 1968. DornhofT, L. L., and Hohn, F. E.: Applied Modern Algebra, Macmillan, New York, 1978. Zadeh, L. A., and Polak, E.: System Theory, McGraw-Hill, New York, 1969. Pseudorandom Sequences: Golomb, S. W.: Shift Register Sequences, Aegean Park Press, Laguna Hills, Cal., 1982. Knuth, D. E.: The Art of Computer Programming, vol. 2: Seminumerical Algorithms, 2nd ed., Addison-Wesley, Reading, Mass., 1981. Niederreiter, H.: The performance of k-step pseudorandom number generators Bibliography 395 under the uniformity test, SIAM J. Sci. Statist. Computing 5, 798-810 (1984). Niederreiter, H.: Distribution properties of feedback shift register sequences, Problems of Control and In formation Theory, to appear. Tausworthe, R. C.: Random numbers generated by linear recurrence modulo two, Math. Comp. 19, 201-209 (1965). Zierler, N.: Linear recurring sequences, J. Soc. Indust. Appl. Math. 1, 31--48 (1959). Chapter 8 Berlekamp, E.R.: Algebraic Coding Theory, McGraw-Hill, New York, 1968. Blake, I. F., and Mullin, R. C.: The Mathematical Theory of Coding, Academic Press, New York, 1975. MacWilliams, F. J., and Sloane, N. J. A.: The Theory of Error-Correcting Codes, North-Holland, Amsterdam, 1977. McEliece, R. J.: The Theory of Information and Coding, Encyclopedia of Math. and Its Appl., vol. 3, Addison-Wesley, Reading, Mass., 1977; now published by Cambridge University Press. Peterson, W. W., and Weldon, E. J., Jr.: Error-Correcting Codes, 2nd ed., M.I.T. Press, Cambridge, Mass., 1972. Pless, V.: Introduction to the -Theory of Error-Correcting Codes, Wiley, New York, 1982. van Lint, J. H.: Introduction to Coding Theory, Springer-Verlag, New York, 1982. Chapter 9 Books: Beker, H., and Piper, F.: Cipher Systems. The Protection of Communications, Northwood Books, London, 1982. Denning, D. E. R.: Cryptography and Data Security, Addison-Wesley, Reading, Mass., 1983. Kahn, D.: The Codebreakers, Weidenfeld & Nicholson, London, 1967. Konheim, A. G.: Cryptography. A Primer, Wiley, New York, 1981. Meyer, C. H., and Matyas, S.M.: Cryptography. A New Dimension in Computer Data Security, Wiley, New York, 1982. Articles: Blake, I. F., Fu ji-Hara, R., Mullin, R. C., and Vanstone , S.A.: Computing logarithms in finite fields of characteristic two, SIAM J. Algebraic Discrete Methods 5, 276--285 (1984). Chor, B., and Rivest, R. L.: A knapsack type public key cryptosystem based on arithmetic in finite fields, Proc. CRYPTO '84, to appear. Coppersmith, D.: Fast evaluation of logarithms in fields of characteristic two, IEEE 'Irans. Information Theory 30, 587-594 (1984). Diffie, W., and Hellman, M. E.: New directions in cryptography, IEEE Trans. Information Theory 22, 644-{;54 (1976). ElGamal, T.: A public key cryptosystem and a signature scheme based on discrete logarithms, IEEE Trans. Information Theory, to appear. Jennings, S. M.: Multiplexed sequences: Some properties of the minimum polynomial, Cryptography (T. Beth, ed.). Lecture Notes in Computer Science, 396 Bibliography vol. 149, pp. 189-206, Springer-Verlag, Berlin, 1983. Lempel, A.: Cryptology in transition, ACM Computing Surveys 11, 285-303 (1979). McEliece, R. J.: A public-key cryptosystem based on algebraic coding theory, DSN Progress Report 42-44, Jet Propulsion Lab., Pasadena, Cal., 1978. Niederreiter, H.: A public. key cryptosystem based on shift register sequences, Proc. EUROCRYPT '85, to appear Odlyzko, A. M.: Discrete logarithms in finite fields and their cryptographic significance, Proc. EUROCRYPT ·s4, to appear. Pohlig, S. C., and Hellman, M. E.: An improved algorithm for computing logarithms Over GF(p) and its cryptographic significance, IEEE Trans. Information Theory 24, 106-110 (1978). Rivest, R. L., Shamir, A., and Adleman, L.: A method for obtaining digital signatures and public-key cryptosystems, Comm. ACM 21, 120-126 (1978). Chapter 10 Alanen, J. D., and Knuth, D. E.: Tables of finite fields, Sankhyii Ser. A 26, 305-328 (1964). Church, R.: Tables of irreducible polynomials for the first four prime moduli, Ann. of Math. (2) 36, 198-209 (1935). Conway, J. H.: A tabulation of some information concerning finite fields, Computers in Mathematical Research (R. F. Churchhouse and J.-C. Herz, eds.), pp.37-50, North-Holland, Amsterdam, 1968. Marsh, R. W.: Table of Irreducible Polynomials over GF(2) through Degree 19, Office of Techn. Serv., U.S. Dept. of Commerce, Washington, D.C., 1957. Stahnke, W.: Primitive binary polynomials, Math. Camp. 27, 977-980 (1973). Watson, E. J.: Primitive polynomials (mod 2), Math. Camp. 16, 368-369 (1962). List of Symbols Note. Symbols that appear only in a restricted context are not listed. Wherever appropriate, a page reference is given. N z Q R <C S1 x · · · x s, S" the set of natural numbers (=positive integers) the set of integers the set of rational numbers the set of real numbers the set of complex numbers the set of all n-tuples (s1, ... , s,.) with s1ESi for 1 � i � n the set of all n-tuples (s 1, ... , s.) with s,E S for I .;;; i .;;; n lSI [s] the cardinality (=number of elements) of the finite set S the equivalence class of s, 4 Z the complex conjugate of z I z I the absolute value of z log z the natural logarithm of z e(t) ehit for tE� ltJ the greatest integer .;;; IE� max(k1, ... ,k.) the maximum ofk1, ..• ,k. min (k 1, ..• , k.) the minimum of k1, ••• , k. gcd (k 1, .•• , k.) the greatest common divisor of k 1, .•. , k. lcm (k 1, ..• , k.) the least common multiple of k 1, ••• , k. (k,.) binomial coefficient 397 398 a= bmodn ¢(n) p.(n) (�) AT det (A) Tr(A) rank (A) n(r) ' dim(V) IGI (a) aH G/H N(S) kerf (a) [a], a+j a= bmodJ R/1 ll., ll./(n) GL(k, �,) R[x] R[x1, ... ,x11] deg(f) D(f) ord (f) !' !* R(f,g) gcd(f,, ... ,f,) a congruent to b modulo n, 4 Euler's function of n, 7 Moebius function of n, 83 Legendre symbol, 167 the transpose of the matrix A the determinant of the matrix A the trace of the matrix A the rank of the matrix A Hankel determinant, 229 the dimension of the vector space V the order of the finite group G, 5 the cyclic group generated by a, 4, 6 List of Symbols the left coset of the group element a modulo the subgroup H, 6 the factor group of the group G modulo the normal subgroup H, 9 the normalizer of the nonempty subset S of a group, 10 the kernel of the homomorphism f, 9, 14 the principal ideal generated by a, 13 the residue class of the ring element a modulo the ideal J, 13 congruence of ring elements a, b modulo the ideal J, 13 the residue class ring of the ring R modulo the ideal J, 13 the group of integers modulo n, 5 the ring of integers modulo n, 14 the general linear group of nonsingular k x k matrices over � •• 191 the polynomial ring over the ring R, 19 the ring of polynomials over the ring R in n indeterminates, 28 the degree of the polynomial f, 20, 29 the discriminant of the polynomial f, 35 the order of the polynomial f, 75 the derivative of the polynomial f, 27 the reciprocal polynomial of f, 79 the resultant of the polynomials f and g, 36 the greatest common divisor of the polynomials /1, ..• ,fn, 22 lcm(f1, ... ,f,) the least common multiple of the polynomials f1, •.. ,f,, 23 f1(x)v · · · v j,(x) 224 List of Symbols Q,(x) ak(xl, ... ,xn) K(M) [L :K] K''l E'> � •• GF(q) �: Tr,1x(�) Tr.(�) N,,K(�) AF/K(�,. · · · • �m) ind,(a) exp,(r) N,(d) I(q,n; x) <I> ,(f) �,[[x]] S(f(x)) (j X Xo X! 1/Jo � G(l/l.xl AG(2,K) PG(2, K) AG(m, �,) PG(m, �,) 399 symbolic multiplication of linearized polynomials L1(x) and L,(x), 105 the nth cyclotomic polynomial, 60 the kth elementary symmetric polynomial in n indetermi­ nates, 29 the extension of K obtained by adjoining M, 30 the degree of the field L over K, 32 the nth cyclotomic field over K, 59 the set of nth roots of unity over K, 59 the finite field of order q, 45 the multiplicative group of nonzero elements of � ,, 46 the trace of �EF over K, 50 the absolute trace of �EF, 50 the norm of �EF over K, 53 the discriminant of et1, ... , a.mEF over K, 57 the index (or discrete logarithm) of a with respect to the base b, 346 the discrete exponential function to the base b, 346 the number of monic irreducible polynomials in � ,[x] of degree d, 82 the product of all monic irreducible polynomials in � ,[x] of degree n, 85 the number of polynomials in �,[x] whose degree is less than deg(/) and which are relatively prime to /E�,[x], 113 the ring of formal power series over � ,. 204 the set of all homogeneous linear recurring sequences in �, with character istic polynomial f(x), 215 sequence obtained by decimation of the sequence <1, 285 sequence obtained by shifting the sequence <1, 287 the set of characters of the finite abelian group G, 163 the conjugate of the character x. 163 the trivial additive character of � ,. 166 the canonical additive character of � •. 166 the trivial multiplicative character of � •• 167 the quadractic character of �. (q odd), 167 Gaussian sum, 168 the affine plane over the field K, 254 the projective plane over the field K, 254 affine geometry over � ,, 262 projective geometry over � ,, 260 400 d(x, y) w(x) de c• S(y) f(L,g) D the Hamming distance between x andy, 303 the Hamming weight of x, 303 List of Symbols the minimum distance of the linear code C, 304 the dual code of G, 308 the syndrome of y, 305 Goppa code, 326 end of proof, end of example, end of remark Index adder. 186, 187, 273 affine geometry, 262, 263 affine multiple, 103 affine plane • .253-255 affine polynomial. 103, 105, 126. 128 see also q-polyno mial(s) affine subspace, 105 algebraic structure, 2 algebraic system, l. 2 alternant code, 336, 337 annihilating polynomial, 56 annihilator. 165, 181 Artin lemma, 55 q-associate. 106-108 canonical factorization of, 108 conventional. \06 linearized, 106. 126 authentication, 341 automorphism, 8, 49, 50, 70 inner, 8 balanced incomplete block design, 263-265 , 269, 295, 296 basis. 50, 54-59, 71. 114. 115 complementary, 54 dual, see dual basis normal, see normal basis polynom ial, 55 self-dual. 54, 71 BCH code, 299, 3!8-326, 335 narrow-sense, 318. 325. 326 primitive, 318 Berlekamp-Mas�y algorithm, 23\-235 , 323 Berlekamp's algorithm, 130-134, 140 BIBD, see balanced incomplete block design binary complementation, 221 binary operation, 2 associative, 2 closure property of, 2 binomial. 115-118. 127. 160 binomial theorem:. 37 bits. 281, 340 block cipher, 340 block design, see balanced incomplete block design Caesar cipher, 338 canonical factorization, 24 of q-associate, 108 see also factorization Cayley-Hamilton theorem. 56 Cayley table, 5 center of division ring. 66 of group, 10 character, 163-16 8 additive, 166 annihilating. 165 canonical additive, 166 conjugate, 163 lifting of. 173, 182 multiplicative, 167 nontrivial, 163 orthogonality relations. 165, 167, 168 product, 163 quadratic, 167 401 402 trivial, 163 trivial additive, 166 trivial multiplicative, 167 character group, 163, 182 characteristic, 16 characteristic matrix, 272 characteristic polynomial of element, 50, 70, 91-93, 369,374-376 for linear operator, 56 of matrix, see matrix reciprocal, 207 of sequence, see linear recurring sequenc(s) characterizing matrices, 272 character sum, 162. 180, 181,236-240, 250 Chien search, 322, 323 Chinese remainder theorem, 38, 40 cipher, 338 block, 340 Caesar, 338 stream, 342 substitution. 338 ,fee also cryptosystem cipher system, 338 see alro cryptosystem ciphertext, 339 class equation, 10, 66 code, 300, 301 alternant, 336, 337 BCH. see BCH code binary, 302 cyclic, see cyclic code dimension of, 302 dual, see dual code equivalent, 333 Gappa, see Gappa code Hamming, see Hamming code length of, 302 linear, 302-3ll. 333,334 minimum distance of, see minimum distance orthogonal. see dual code parity--check, 302, 334 perfect, 333 Reed-Soloman. 318, 335 repetition, 302, 333, 334 reversible, 335 systematic, 302 code polynomi al. 313-315 code vector, 302 code word. 300-302 coding scheme, 300, 301 coefficient, 19, 28. 202 leading. 20 collinear points, 255 companion matrix, 63, 64, 93, 195, 279 complete quadrangle, 257 component forced, 276 free, 276 congruence, 4, 6, 13 left. 6 conic, 258 degenerate, 258 nondegenerate, 258 tangent of, 258 conjugacy class, 10 conjugate, 49, 50 of set, 8 constant adder, 186, 187 constant multiplier, 186, 187. 273 constant term, 20 control symbol, 30 I Index conventional cryptosystem, 338-340, 349 correlation coefficient. 282-285 correlation test, 282 coset. 6, 7 left, 6 right, 6 coset leader. 305 coset�leader algorithm, 305. 306 cryptanalysis, 338 cryptography, 338 cryptology, 338 cryptosystem, 338-340 conventional. 338-340, 349 DES. 340 FSR, 357. 358 Goppa-code, 360-362 Hill, 366 knapsack-type, 358-360 public-key, 340, 341 RSA, 348 single-key, 339 cycle, 277 length of. 277 pure, 277 cycle sum. 278-281 cycle term, 278 cyclic code, 311-325 irreducible, 313 maximal, 313 shortened, 335 cyclic group, see group cyclic vector, 56 cyclotomic field, 59, 6l. 62, 72 cyclotomic polynomial, 60-62. 64, 66, 72, 73. 84-86. 96, 97, 124. 128, 138. 139 Davenport-Hasse theorem, 173 de Bruijn sequence. 246 decimated sequence, 285-287, 297, 298, 345, 364 decimation. 285-287, 297, 298, 345, 358, 364 deciphering scheme, 339 decoding algorithm for BCH code, 320-325, 328, 331, 332 for Gappa code, 328-332 Index for linear code, 304-306 decoding scheme. 300 degree of algebraic elemen t, 31 of extension, 32 formal. 36 of polynomial. 20. 29 delay elemen t, 186, 187, 273 derivative, 27, 40, 41, 70 Desarguesian plane. 256-259 · Desargues's theorem. 255-257, 260 DES cryptosystem. 340 design, 262 design of experiments, 269 diagonalization algorithm, 145-147 difference equation. see linear recurrence relation difference set. 265-267. 296 Diffie-Hellman scheme, 348 digital method, 288 digital signature. 341, 349 discrete exponential function. 346-349, 367 discrete logarithm, 346. 347, 358, 359, 365, 367 discrete logarithm algorithm, 349-357 discriminant of elernen ts, 57, 58, 71, 72 of polynomial, 35-37. 122 distribution test, 282. 283 distributive laws, 11, 12 divison algorithm, 20 divison ring. 12, 65-69 divisor, 17 dot product, 308 dual basis. 54, 71, 369, 374-376 dual code, 308-311,334.335 element algebraic. 31 associate. 17 binary. 15 conjugate. 8 defining. 30 identity, 2 inverse, 2 multiple of, 3 order of, 6, 7 power of, 3, 69, 181 prime. 17 primitive. see primitive element unity. 2 zero. II enciphering scheme. 339 endomorphism, 8 epimorphism, 8 equivalence class. 4 equivalence relation. 4 error-correcting code. 303 see also code error-evaluator polynomial. 329, 330 error-location number. 316, 320. 329 error-locator polynomial, 322. 329, 330 error value. 320, 329 error vector. 303 error word, 303 403 Euclideiln algorithm, 22. 38, 330, 336, 355, 356 Euler's function, 7, 37 exponential sum. 162-184, 236-240, 250 exponent of polynomial. see order extension (field), 30-35 algebraic, 31 degree of. 32 finite, 32 simple, 30, 33, 34 factor group, 9 factorization of integers, 78 of polynomials. 23, 24, 29, 39, 97, 98, 108, 116-118, 120, 129-150 symbolic. 108, 109 factor ring. 13 Fano plane, 253, 254, 263 feedback shift register. 186-188, 193, 314 Fermat's little theorem. 37 Fibonacci sequence, 246 field, 12 cyclotomic. see cyclotomic field finite. see finite field prime, 30 see also extension (field), splitting field finite affine geometry. 262, 263 finite euclidean geometry. 262 finite field, 15, 45 automorphism, 49, 50, 70 characterization of, 43-47 computation in, 367-369 definition, 14 existence and uniqueness, 45 multiplicative group of, 46, 47, 69 finite-state system, 271, 272 k-flat(s), 259-262, 295 cycle of, 261 at infinity. 262 parallel. 262 flip-flop, .ree delay element formal power series, 202 ring of, 204 Fourier coefficient, 171 Fourier expansion. 171 FSR cryptosystem, 357, 358 fundamental theorem on symmetric polynomials. 29 Galois field. 15. 45 see also finite field 404 Gaussian sum, 168-180. 182, 183, 238, 242-244. 250 general linear group, 191. 192 general response formula, 275, 276 generating function, 202. 20 7-209. 219 generator, 4 generator matrix, 303. 312. 333 canonical, 302. 303, 313 generator polynomial, 313 Gilbert-V arsharnov bound, 308, 325 Gappa code, 326-332, 336, 337, 360, 361 irreduci ble, 326, 336, 360 Goppa-code cryptosystern, 360-362 Gappa polynomial, 326 group, 2 abelian, 2 commutative, 2 cyclic, 3, 7, 163 finite, 5 general linear, 191, 192 infinite, 5 of integers modulo n, 5 order of, 5, 7 group code, 302 Hadamard matrix, 269-271, 296 normalized, 270, 296 Hamming bound, 307 Hamming code, 307, 311, 314, 315, 333 binary, 307,311,314,315,333 Hamming distance, 303 Hamming weight. 303 Hankel determ inant, 229-231, 249 Hill cryptosystem, 366 homomorphism. 8, 14 homomorphism theorem for groups. lO for rings, 14,15 hyperplane, 259, 262, 266 ideal, 13 maximal, 17 prime, 17 principal, 13 identity element, 2 impulse response sequence , 193-195, 199, 215 incidence matrix, 263, 264 incidence relation, 252-254. 262 indeterminate, 19 index-calculus algorithm, 352-357 index function. 346, 367 .�ee also discrete logarithm index of subgroup, 7 index table, 63, 368, 370-373 initial state vector, 188 initial value, 186 input alphabet, 271, 272 input space, 272 input symbol. 272 integral domain, 12 interpolation, 28, 4l. 363 inverse element, 2 Index irreducible polynomial, 23-25, 28, 31, 47, 48, 75, 76.82-91,97,98, 115, 118-128. 160. 183, 377-387 \somorphism. 8, 14 Jacobi's logarithm, 69, 368, 374-376 kernel of homomorphism group. 9 ring. 14 key. JJ9, 340 key-exchange system, 348 knapsac k-type cryptosystem, 358-360 Kronecker's method, 39 Lagrange interpolation formula, 28, 41, 363 Latin square(s), 267-269, 296 mutually orthogonal, 267-269, 296 normalized. 296 orthogonal. 267-269, 296 law of quadratic reciprocity, 179, 183 Legendre symbol. 167, 179 line(s) at infinity, 255 pllrallel, 255 linearized polynomial, 98-114, 126--128 see also q-associate, q-polynomial(s) linear modular system, 272-28 1, 296, 297 characteristic matrix, 272 characterizing matrices, 272 order, 272 linear recurrence relation, 186, 314 characteristic polynomial, 195-20 1, 207-211,214,215.226-228 homogeneous, 186 inhomogeneous, 186 order. 186 linear recurring sequence(s), 186 addition, 215, 218-221 binary complementat ion, 221 characteristic polynomial, 195-201, 207-21 1,214,215,226-228 characteriz ation, 228-23 1 decimation, see decimation distribution properties, 235-245, 250 families of, 215-228 homogeneous, 186 inhomogeneous, 186 least period, 189-195, 199, 200, 212, 213, 220-22 3,227,247,248 minimal polynomial, 211-215,218-223, 230-235. 247-249 multiplication, 224-228 Index order, 186 reciprocal characteristic polynomial. 207 scalar multiplication, 215 LM S, see linear modular system MacWilliams identity. 310, 311 magic square. 296 matrix associated with sequence, 191-195, 199 characteristic polynomial of. 93, 160. 278. 279 elementary block of, 279, 280 Hadamard, see Hadamard matrix minimal polynomial of, 278-280 rational canonical form of, 279 matrix of polynomials. 143-147 diagonalization. 145-147 equivalence. 144 nonsingular, 144 normalized. 146 unimodular, 144 maximal ideal, 17 maximal period sequence, 201, 240, 241. 246. 282-288. 297, 298. 343 Mersenne prime, 348, 351. 352 message symbol, 300. 301 minimal polynomial of element, 31. 86, 87,91-97,369, 374-376 for linear operator. 56 of matrix. 278-280 of sequence, see linear recurring sequence(s) minimum distance, 304. 308, 318, 319. 327. 328. 333-337 q-modulus, 109. 110, 114 Moebius function, 83, 124 Moebius inversion formula. 83. 84 multiplexed sequence, 343-346, 363. 364 multiplexer, 343 nearest neighbor decoding, 303 Newton's formula, 29, 30 next-state function, 272 no-key algorithm, 349 non-Desarguesian plane, 256, 257 norm, 53. 54, 70. 71 transitivity of, 54 normal basis. 55-59, 71, 115, 127, 365, 369, 374-376 self-dual. 71, 127 normal basis theorem. 56, 57, 59, 115 normalization method, 288 normalizer, 10 NP-complete problem, 342, 362 one-time pad, 342 one-way function. 341 operation .. fee Binary operation order of character, 170. 182 of element. 6, 7 of group, 5, 7 of linear modular system. 272 of linear recurrence relation. I 86 of linear recurring sequence. 186 multiplicative mod n, 76, 87 405 of polynomial. 75-82, 122. 123, 199-201, 212. 377-387 of projective plane, 253-257 of state, 277, 278. 281 orthogonal code, see dual code orthogonality relations. 165, 167, 168 orthogonal vectors, 308 output alphabet. 272 output function, 272 output space, 272 output symbol, 272 Pappus theorem, 255-257 parity-check code, 302, 334 parity-check equation. 301 parity-check matrix, 302 parity-check polynomial. 313 partition, 4 pencil, 257, 258, 262 period of polynomial, .�ee order period of sequence, 189-191 least, 189 (see also linear recurring Sl!quence(s)) permuta tion matrix·, "360, 361 plaintext, 339 plaintext message, 339 Plotkin bound. 308 polynomia l(s), 19. 28 affine. see affine polynomial affine multiple of, 103 canonical factorization of. 24 characteristic, see characteristic polynomial constant. 20 cyclotomic. see cyclotomic polynomial defining. 31 degree of, 20, 29 derivative of, 27, 40, 41, 70 discriminant of, .�ee discriminant division of. 20, 21 elementary symmetric, 29 exponent of, see order factorization of, l"ee factorization formal degree of, 36 greatest common divisor of. 22, 38, 39, 109 homogeneous. 29 irreducible. see irreducible polynomial least common multiple of. 22, 23, 39 406 linearized. see linearized polynomial matrix of. see matrix of polynomials minimal, see minimal polynomial monic, 20 order of, see order pairwise relatively prime. 22 period of, see order primitive. see primitive polynomial product of.l9 reciprocal, 79, 123 reciprocal characteristic, 207 reducible. 23 /-reducing. 131-13 7 relatively prime, 22 resultant of, see resultant root of, .fee root(s) self-recip rocal, 123. 128 splitting of. 34, 35 sum of, 19 symme tric. 29 zero. 19 q-polynomial(s), 99, 101-103, 106 -114. 126 affine, 103, 105, 126. 128 greatest common symbolic divisor of. 109 minimal. 111-113.126 symbolically irreducible, 108, llO symbolic division of, 106, 107 symbolic multiplication of, 105, 106 Jee also q-associate , linearized polynomial polynomial basis, 55 polynomial ring. 19, 28, 204 preperiod of sequence. 189, 245. 247 prime element. 17 prime field, 30 prime ideal, 17 primitive element. 47, 49, 59, 63. 80, 96, 97. 182. 368 primitive polynomial, 80-82, 87, 96-98, 121. 123. 377. 388-391 q-primitive root, 110-114 principal ideal. 13 principal ideal domain. 17 principle of substitution, 27 probabilistic root-finding algorithm, 151 projective correspondence. 258 projective geometry •. �ee projective space projective plane, 252-259. 262-26 5, 295 Desarguesian. 256-259 finite, 252-259, 262-265, 295 non-Desarguesian. 256, 257 order of, 253-257 projective space. 259-263, 266, 295 finite. 260---263, 266, 295 pseudorandom sequence of bits, 282 public-key cryptosystem. 340, 341 quadratic reciprocity. see law of quadratic reciprocity quotient group, 9 random sequence of bits, 281, 282, 342 of real numbers. 288 rational canonical form of matrix. 279 reducible polynomial, 23 /-reducing polynomi al, 131-137 reduction mod/, 25 Reed-Solomon code, 318, 335 reflexivity of relation, 4 Index repeated squaring technique, 148, 149, 151, 347 repetition code, 302, 333, 334 residue class, 13 residue class ring. 13, 25 resultant, 36. 37. 42, 127, 140 ring. 11-17 of algebraic integers, 179 characteristic of. 16 commutative, II of formal power series, 204 with identity, II of polynomials. see polynomial ring root(s), 27, 28. 34-36, 150-159, 161 of affine polynomial. 103-105, 107 of irreducibie polynomial. 48 of linearized polynomial, 99, 101-103 multiple, 27, 35, 40 multiplicity of. 27. 41 q-primitive, 110-114 simple, 27 root adjunction. 33-35 root-finding algorithm. 101-10 5, 150-159 probabilistic. 151 root of unity. 59-62. 72 primitive, 60---62. 72 RSA cryptosystem, 348 Run. 297 secant. 258 sequence decimated, see decimated sequence impulse response, .5ee impulse response sequence least period of. 189 maximal period. see maximal period sequence multiplexed , 343-346, 363, 364 periodic, !89, 247 period of, 189-191 preperiod of. 189, 245. 247 pseudorandom, 282 random, .,ee random sequence shifted, 287, 288, 297, 298 ultimately periodic, 189 of uniform pseudorandom numbers, 288-294 Index of uniform random numbers, 288 zero, 215 see also linear recurring sequence(s) serial test, 282, 294 Shannon's theorem, 299 shifted sequence, 287, 288. 297, 298 Silver-Pohlig-Hellman algorithm. 350-352 single-key cryptosystem, 339 Singleton bound, 333 skew field. see division ring smooth integer. 350 m-space, see projective space splitting field, 35, 48, 134 existence and uniqueness, 35 square and multiply technique, 347 state. 272. 273 order of, 277. 278, 281 state graph, 277, 278, 296 path in, 277 state set, 272 state space, 272 state vector. 188, 191, 193-195, 214, 215 initial. 188 modified. 192 Steiner triple system. 263 Stickelberger's theorem, 177-179 stream ciphe,r, 342 subfield, 30 criterion for, 45, 46 maximal, 67, 68 prime, 30 proper, 30 subgroup, 6 generated by c;:lement, 6 generated by subset, 6 index of, 7 nontrivial, 6 normal. 9 trivial, 6 subring, 13 substitution cipher, 338 symmetric polynomial, 29 elementary, 29 symmetry of relation, 4 syndrome, 305, 306, 315 syndrome polynomial, 329 tactical configuration, 262. 263 symmetric, 262 tangent, 258 Tausworthe method, 288 term of polynomial, 29 test for randomness, 282, 288, 289 theorem of Pappus, 255-257 threshold scheme, 362, 363 trace, 50-53, 70, 71 absolute, 50 transitivity of, 52, 53 transitivity of relation, 4 trapdoor one-way function, 341 trinomial, 118-122, 127, 128 407 irreducible, 118, 119, 121, 122, 127, 128 primitive. 121 uniformity test, 289. 290 uniform pseudorandom numbers, 288-294 uniform random numbers, 288 unique factorization, 23, 24, 29 unit, 17 unity element, 2 Waring's formula, 30 Wedderburn's theorem, 65-69, 256 weight. JOJ weight enumerator, 309-311, 334 Wilson's theorem, 37 Zassenhaus algorithm, 142, 143 zero divisor, 12 zero element, 11 zero of polynomial, 27, 42 see also root(s) zero polynomial, 19 zero sequence, 215