English

On the degree of polynomials computing square roots mod p

Number Theory 2024-01-24 v2 Computational Complexity Combinatorics

Abstract

For an odd prime pp, we say f(X)Fp[X]f(X) \in {\mathbb F}_p[X] computes square roots in Fp\mathbb F_p if, for all nonzero perfect squares aFpa \in \mathbb F_p, we have f(a)2=af(a)^2 = a. When p3mod4p \equiv 3 \mod 4, it is well known that f(X)=X(p+1)/4f(X) = X^{(p+1)/4} computes square roots. This degree is surprisingly low (and in fact lowest possible), since we have specified (p1)/2(p-1)/2 evaluations (up to sign) of the polynomial f(X)f(X). On the other hand, for p1mod4p \equiv 1 \mod 4 there was previously no nontrivial bound known on the lowest degree of a polynomial computing square roots in Fp\mathbb F_p; it could have been anywhere between p4\frac{p}{4} and p2\frac{p}{2}. We show that for all p1mod4p \equiv 1 \mod 4, the degree of a polynomial computing square roots has degree at least p/3p/3. Our main new ingredient is a general lemma which may be of independent interest: powers of a low degree polynomial cannot have too many consecutive zero coefficients. The proof method also yields a robust version: any polynomial that computes square roots for 99\% of the squares also has degree almost p/3p/3. In the other direction, a result of Agou, Deligl\'ese, and Nicolas (Designs, Codes, and Cryptography, 2003) shows that for infinitely many p1mod4p \equiv 1 \mod 4, the degree of a polynomial computing square roots can be as small as 3p/83p/8.

Keywords

Cite

@article{arxiv.2311.10956,
  title  = {On the degree of polynomials computing square roots mod p},
  author = {Kiran Kedlaya and Swastik Kopparty},
  journal= {arXiv preprint arXiv:2311.10956},
  year   = {2024}
}

Comments

14 pages. Changes to previous version: We learnt that our upper bound for special $p$, Theorem 1.3, had been proved by Agou, Deligl\'ese and Nicolas in 2003. Added some relevant references

R2 v1 2026-06-28T13:24:52.506Z