For an odd prime $p$, we say $f(X) \in {\mathbb F}_p[X]$ computes square roots in $\mathbb F_p$ if, for all nonzero perfect squares $a \in \mathbb F_p$, we have $f(a)^2 = a$. When $p \equiv 3 \mod 4$, it is well known that $f(X) = X^{(p+1)/4}$ computes square roots. This degree is surprisingly low (and in fact lowest possible), since we have specified $(p-1)/2$ evaluations (up to sign) of the polynomial $f(X)$. On the other hand, for $p \equiv 1 \mod 4$ there was previously no nontrivial bound known on the lowest degree of a polynomial computing square roots in $\mathbb F_p$; it could have been anywhere between $\frac{p}{4}$ and $\frac{p}{2}$. We show that for all $p \equiv 1 \mod 4$, the degree of a polynomial computing square roots has degree at least $p/3$. Our main new ingredient is a general lemma which may be of independent interest: powers of a low degree polynomial cannot have too many consecutive zero coefficients. The proof method also yields a robust version: any polynomial that computes square roots for 99\% of the squares also has degree almost $p/3$. In the other direction, we also show that for infinitely many $p \equiv 1 \mod 4$, the degree of a polynomial computing square roots can be $(\frac{1}{2} - \Omega(1))p$.
翻译:对于奇素数$p$,若对所有非零完全平方数$a \in \mathbb F_p$,均有$f(a)^2 = a$,则称$f(X) \in {\mathbb F}_p[X]$在$\mathbb F_p$中计算平方根。当$p \equiv 3 \mod 4$时,众所周知$f(X) = X^{(p+1)/4}$可计算平方根。该次数低得惊人(实际上已是最低可能值),因为我们指定了多项式$f(X)$的$(p-1)/2$个取值(相差一个符号)。另一方面,对于$p \equiv 1 \mod 4$的情形,此前关于计算$\mathbb F_p$中平方根的多项式的最低次数没有任何非平凡界;该次数可能介于$\frac{p}{4}$与$\frac{p}{2}$之间的任意值。我们证明对所有$p \equiv 1 \mod 4$,计算平方根的多项式次数至少为$p/3$。我们的主要新工具是一个可能具有独立价值的一般性引理:低次多项式的幂次不能包含过多连续零系数。证明方法还给出了一个稳健版本:任何对99%的平方数都能计算平方根的多项式,其次数也接近$p/3$。另一方面,我们也证明存在无穷多个$p \equiv 1 \mod 4$,使得计算平方根的多项式次数可达$(\frac{1}{2} - \Omega(1))p$。