平方剩余、二次互反律
平方剩余
Consider congruence ax^2 + bx + c \equiv 0 \,\mod\, p, with p is an odd prime and a \neq 0 \,\mod\, p.
x^2 + b^\prime x + c^\prime \equiv 0 \,\mod\, p,
x^2 + c^{\prime\prime} \equiv 0 \,\mod\, p,
x^2 \equiv a \,\mod\, p.
Definition 1 Let p be an odd prime, a \neq 0\,\mod\,p.
We say that a is a quadratic residue \,\mod\,p if a is a square \,\mod\,p. Namely,
a\equiv b^2 \,\mod\,p.
Otherwise, it is a quadratic non-residue.
x^2 \equiv a \,\mod\, p may have 0-2 solutions.
Exercise 1 Please convert the congruence
10x^2 + 3x + 9 \equiv 0 \,\mod\, 37, into the form of
x^2 \equiv a \,\mod\, 37.
Lemma 1 Let a\neq 0 \,\mod\, p. Then a is a quadratic residue mod p iff
a^{\frac{p-1}{2}}\equiv 1 \,\mod\, p.
Example 1 15 is a quadratic residue mod 17, because
15^{\frac{17-1}{2}}\equiv 1 \,\mod\, 17.
12 is a quadratic non-residue mod 17, because
12^{\frac{17-1}{2}}\equiv -1 \,\mod\, 17.
Proof. p is odd, so by Euler theorem, a^{p-1}\equiv 1 \,\mod\, p\,\,\Rightarrow\,\,(a^{\frac{p-1}{2}})^2\equiv 1 \,\mod\, p\,\,\Rightarrow\,\,a^{\frac{p-1}{2}}\equiv \pm 1 \,\mod\, p.
Let g be a primitive root mod p.
\{1,g,g^2,\cdots,g^{p−2} \} = 1,2,\cdots,p-1\,\mod\,p.
Let a \equiv g^k \,\mod\, p for some k. So, a\equiv g^{k+(p-1)m} \,\mod\, p.
a is quadratic residue mod p iff k is even.
if k = 2l then a \equiv g^{2l} \equiv (g^l)^2.
Conversely, if a \equiv b^2 \,\mod\, p and suppose b = g^l \,\mod\, p, then a \equiv g^{2l} \,\mod\, p, so k is even. \square
Note: Half of residue class mod p are quadratic residues, and half are quadratic non-residues.
Now, a^{\frac{p-1}{2}} \equiv (g^k)^{\frac{p-1}{2}}\equiv g^{\frac{k(p-1)}{2}} \,\mod\, p.
k is even iff a^{\frac{p-1}{2}} \equiv 1 \,\mod\, p.
Legendre符号
Definition 2 (Legendre Symbol)
\left( \frac{a}{p} \right) = \left\{ \begin{aligned} 1,\text{ if } a \text{ is a quadratic residue mod }p\\ -1,\text{ if } a \text{ is a quadratic nonresidue mod }p\\ \end{aligned} \right. where p is an odd prime. we simply write it as \left( \frac{a}{p} \right).
\left( \frac{a}{p} \right) = a^{\frac{p-1}{2}} \,\mod\, p.
Theorem 1 \left(\frac{a}{p}\right)\left(\frac{b}{p}\right) = \left(\frac{ab}{p}\right).
Proof. a^{\frac{p-1}{2}}b^{\frac{p-1}{2}} \equiv (ab)^{\frac{p-1}{2}}\,\mod\, p.\square
\left(\frac{a^2}{p}\right) = \left(\frac{a}{p}\right)^2 = 1.
Example 2 \left(\frac{-9}{71}\right)=\left(\frac{-1\times 3^2}{71}\right)=\left(\frac{-1}{71}\right)\left(\frac{3^2}{71}\right)=\left(\frac{-1}{71}\right)=(-1)^{35}\,\mod\,71=-1
\left(\frac{-9}{53}\right)=\left(\frac{-1\times 3^2}{53}\right)=\left(\frac{-1}{53}\right)\left(\frac{3^2}{53}\right)=\left(\frac{-1}{53}\right)=(-1)^{26}\,\mod\,53=1
高斯引理
Lemma 2 (Gauss Lemma) Let p be an odd prime, and a \neq 0 \,\mod\, p. For any integer x, let x_p be the residue of x\,\mod\,p which has the smallest absolute value.
Divide x by p, get the remainder 0\le b<p. If b<\frac{p}{2}, let x_p=b, if b>\frac{p}{2}, let x_p be b-p, then -\frac{p}{2} < x_p < \frac{p}{2}. Let n be the number of integers among (a)_p, (2a)_p, (3a)_p, \cdots, \left(\frac{p-1}{2}a\right)_p, which are negative. Then \left(\frac{a}{p}\right)=(-1)^n.
Example 3 p=13, a=5
\left\{a,2a,\cdots,\frac{p-1}{2}a\right\} is \{5,10,15,20,25,30\}
\left\{(a)_p, (2a)_p, \cdots, (\frac{p-1}{2}a)_p\right\} is \left\{5,-3,2,-6,-1,4\right\}
3 numbers are negtive, so \left(\frac{5}{13}\right)=(-1)^3=-1.
Example 4 p=13, a=10
\left\{a,2a,\cdots,\frac{p-1}{2}a\right\} is \left\{10,20,30,40,50,60\right\}
\left\{(a)_p, (2a)_p, \cdots, (\frac{p-1}{2}a)_p\right\} is \left\{-3,-6,4,1,-2,-5\right\}
4 numbers are negtive, so \left(\frac{10}{13}\right)=(-1)^4=1.
Proof. We first prove that if 1\le k \neq l \le \frac{p-1}{2} then (ka)_p \ne \pm(la)_p,
Suppose if (ka)_p=\pm(la)_p is not true. Then, we have ka\equiv \pm la \,\mod\,p \Rightarrow (k\pm l)a \equiv 0\,\mod\,p \Rightarrow k\pm l\equiv 0\,\mod\,p
This is impossible because 2\le k+l \le p-1 and -\frac{p}{2} < k-l < \frac{p}{2} and k-l\ne 0.
So the number |(ka)_p| for k=1,2,\cdots,\frac{p-1}{2} are all distinct mod p (there is \frac{p-1}{2} of them) and so must be the integer \left\{1,2,\cdots,\frac{p-1}{2}\right\} in some order.
1\cdot2\cdots \frac{p-1}{2}\equiv \prod_{k=1}^{\frac{p-1}{2}}|(ka)_p|\,\mod\,p
exactly n of the numbers (ka)_p are < 0.
\equiv (-1)^n\prod_{k=1}^{\frac{p-1}{2}}(ka)_p\,\mod\,p
\equiv (-1)^n\prod_{k=1}^{\frac{p-1}{2}}ka\,\mod\,p
\equiv a^{\frac{p-1}{2}}(-1)^n\left(1\cdot2\cdots \frac{p-1}{2}\right)\,\mod\,p
\Rightarrow 1\equiv a^{\frac{p-1}{2}}(-1)^n\,\mod\,p
\Rightarrow a^{\frac{p-1}{2}}\equiv (-1)^n\,\mod\,p
\Rightarrow \left(\frac{a}{p}\right)\equiv (-1)^n\,\mod\,p\square
Theorem 2 If p is an odd prime, and \gcd(a,p)=1, then if a is odd, we have \left( \frac{a}{p} \right)=(-1)^t, where
t=\sum_{j=1}^{\frac{p-1}{2}}\left \lfloor \frac{ja}{p} \right \rfloor. Also, \left(\frac{2}{p}\right)=(-1)^{\frac{p^2-1}{8}}.
Proof. We shall use Gauss Lemma. We are interested in (-1)^n or n\,\mod\,2.
For every k between 1 and \frac{p-1}{2},
ka=p\left \lfloor \frac{ka}{p} \right \rfloor+ka\,\mod\,p
ka=p\left \lfloor \frac{ka}{p} \right \rfloor+(ka)_p+\left\{ \begin{aligned} 0, \text{ if }(ka)_p>0\\ p, \text{ if }(ka)_p<0\\ \end{aligned} \right.
ka\equiv \left \lfloor \frac{ka}{p} \right \rfloor+|(ka)_p|+\left\{ \begin{aligned} 0,\text{ if }(ka)_p>0\\ 1,\text{ if }(ka)_p<0\\ \end{aligned} \right.\,(\mod\,2)
\sum_{k=1}^{\frac{p-1}{2}}ka\equiv \sum_{k=1}^{\frac{p-1}{2}}\left \lfloor \frac{ka}{p} \right \rfloor+ \sum_{k=1}^{\frac{p-1}{2}}|(ka)_p|+n \,(\mod\,2)
\sum_{k=1}^{\frac{p-1}{2}}ka= a\sum_{k=1}^{\frac{p-1}{2}}k=\frac{a}{2}(\frac{p-1}{2})(\frac{p-1}{2}+1) =\frac{a(p^2-1)}{8}.
Because \left\{|a|_p,\cdots,|\frac{p-1}{2}a|_p\right\} is \left\{1,\cdots,\frac{p-1}{2}\right\},
\sum_{k=1}^{\frac{p-1}{2}}|(ka)_p|=\sum_{k=1}^{\frac{p-1}{2}}k=\frac{1}{2}(\frac{p-1}{2})(\frac{p-1}{2}+1)=\frac{p^2-1}{8}.
So, n\equiv \frac{a(p^2-1)}{8}-\frac{p^2-1}{8}+ \sum_{k=1}^{\frac{p-1}{2}}\left \lfloor \frac{ka}{p} \right \rfloor\,(\mod\,2)
n\equiv \frac{(a-1)(p^2-1)}{8}+ \sum_{k=1}^{\frac{p-1}{2}}\left \lfloor \frac{ka}{p} \right \rfloor\,(\mod\,2)
Since a is odd, a-1 is even.
\left(\frac{a}{p}\right)=(-1)^t,\text{ where } n\equiv \sum_{k=1}^{\frac{p-1}{2}}\left \lfloor \frac{ka}{p} \right \rfloor \equiv t\,(\mod\,2). \square
If a=2, n\equiv \frac{p^2-1}{8}+ \sum_{k=1}^{\frac{p-1}{2}}\left \lfloor \frac{2k}{p} \right \rfloor\,(\mod\,2)
k\in\left\{1,2,\cdots,\frac{p-1}{2}\right\}, so \left \lfloor \frac{2k}{p} \right \rfloor=0.
So, n\equiv \frac{p^2-1}{8}\,(\mod\,2), namely, \left(\frac{2}{p}\right)=(-1)^{\frac{p^2-1}{8}} =\left\{\begin{aligned} 1,\text{ if }p=1,7\,(\mod\,8)\\ -1,\text{ if }p=3,5\,(\mod\,8)\\ \end{aligned}\right.
\left(\frac{-1}{p}\right)=(-1)^{\frac{p-1}{2}}=\left\{\begin{aligned} 1,\text{ if }p=1\,(\mod\,4)\\ -1,\text{ if }p=3\,(\mod\,4)\\ \end{aligned}\right.
二次互反律
Theorem 3 (Quadratic Reciprocity Law) “The fundamental theorem must certainly be regarded as one of the most elegant of its type.” Privately Gauss referred to it as the “golden theorem.”
If p,q are distinct odd primes, then \left(\frac{p}{q}\right) \left(\frac{q}{p}\right) = (-1)^{\frac{p-1}{2}\frac{q-1}{2}}.
or another version:
\left(\frac{p}{q}\right)=\begin{cases} +\left(\frac{q}{p}\right)&\text{ if }p\equiv 1 \,\mod\,{4} \text{ or } q \equiv 1 \,\mod\,{4}\\-\left(\frac{q}{p}\right)&\text{ if } p\equiv q \equiv 3\,\mod\,{4}. \end{cases}
Example 5 \left(\frac{37}{73}\right) \leftarrow \left(\frac{73}{37}\right) \leftarrow \left(\frac{-1}{37}\right)
Claim 1: No integer points on the vertical side.
Claim 2: No integer points on the hypotenuse.
\frac{b}{a} = \frac{q}{p} \Rightarrow pb=qa \Rightarrow p|a,q|b But (a,b)\neq (0,0) and (a<p, b<p), so it is impossible.
Claim 3: The number of integer points on interior of triangle is \sum_{k=1}^{\frac{p-1}{2}}\left \lfloor \frac{qk}{p} \right \rfloor.
If we have a point (k,l) , then 1\le k\le \frac{p-1}{2} and slope \frac{l}{k} < \frac{q}{p}\Rightarrow l<\frac{qk}{p}.
Number of points on the segment x = k is the number of possible l , which is \left \lfloor \frac{qk}{p} \right \rfloor.
The number of interior points of the rectangle is
\sum_{l=1}^{\frac{q-1}{2}}\left \lfloor \frac{pl}{q} \right \rfloor + \sum_{k=1}^{\frac{p-1}{2}}\left \lfloor \frac{qk}{p} \right \rfloor = \frac{p-1}{2}\frac{q-1}{2}.
\left(\frac{q}{p}\right)=(-1)^{t_1}\text{ where }t_1=\sum \left \lfloor \frac{qk}{p} \right \rfloor
\left(\frac{p}{q}\right)=(-1)^{t_2}\text{ where }t_2=\sum \left \lfloor \frac{pl}{q} \right \rfloor
\left(\frac{q}{p}\right)\left(\frac{p}{q}\right)=(-1)^{t_1+t_2}\text{ where }t_1+t_2=\frac{p-1}{2}\frac{q-1}{2}. \square
Example 6 \left(\frac{7}{11}\right)=-\left(\frac{11}{7}\right)=-\left(\frac{4}{7}\right)=-1.
\left(\frac{10}{13}\right)=\left(\frac{2}{13}\right)\left(\frac{5}{13}\right)=(-1)\left(\frac{13}{5}\right).
=-\left(\frac{3}{5}\right)=-\left(\frac{5}{3}\right)=-\left(\frac{2}{3}\right)=-(-1)=1.
Example 7 p = 11, x = \pm 1, \pm 2, \pm 3, \pm 4, \pm 5\Rightarrow x^2 = 1,3,4,5,9
p = 13, x = \pm 1, \pm 2, \pm 3, \pm 4, \pm 5, \pm 6 ⇒ x^2 = 1,3,4,9,10,12
Exercise 2 \left( \frac{7411}{9283} \right)=?
Legendre Symbol again:
\left( \frac{a}{p} \right) = \left\{ \begin{aligned} 1,\text{ if }a\text{ is a quadratic residue mod }p\\ -1,\text{ if }a\text{ is a quadratic nonresidue mod }p\\ 0,\text{ if a divides }p\\ \end{aligned} \right.
For any integer a and any positive odd integer n the Jacobi symbol is defined as the product of the Legendre symbols corresponding to the prime factors of n:
\left(\frac{a}{n}\right) = \left(\frac{a}{p_1}\right)^{\alpha_1}\left(\frac{a}{p_2}\right)^{\alpha_2}\cdots \left(\frac{a}{p_k}\right)^{\alpha_k},
where n=p_1^{\alpha_1}p_2^{\alpha_2}\cdots p_k^{\alpha_k}.
If \left(\frac{a}{n}\right) = -1 then a is a quadratic nonresidue \mod\,{n}.
If a is a quadratic residue \mod\,{n} and \gcd(a,n)=1, then \left(\frac{a}{n}\right) = 1.
But, unlike the Legendre symbol:
If \left(\frac{a}{n}\right) = 1 then a may or may not be a quadratic residue \mod\,{n}.
For example, \left(\frac{-1}{77}\right)=1, but -1 is a quadratic non-residue.
Example 8 \left(\frac{1001}{9907}\right) =\left(\frac{7}{9907}\right) \left(\frac{11}{9907}\right) \left(\frac{13}{9907}\right).
\left(\frac{7}{9907}\right) =-\left(\frac{9907}{7}\right) =-\left(\frac{2}{7}\right) =-1.
\left(\frac{11}{9907}\right) =-\left(\frac{9907}{11}\right) =-\left(\frac{7}{11}\right) =\left(\frac{11}{7}\right) =\left(\frac{4}{7}\right) =1.
\left(\frac{13}{9907}\right) =\left(\frac{9907}{13}\right) =\left(\frac{1}{13}\right) =1.
\left(\frac{1001}{9907}\right) =-1.
\left(\frac{1001}{9907}\right) =\left(\frac{9907}{1001}\right) =\left(\frac{898}{1001}\right) =\left(\frac{2}{1001}\right)\left(\frac{449}{1001}\right) =\left(\frac{449}{1001}\right) =\left(\frac{1001}{449}\right) =\left(\frac{103}{449}\right) =\left(\frac{449}{103}\right) =\left(\frac{37}{103}\right) =\left(\frac{103}{37}\right) =\left(\frac{29}{37}\right) =\left(\frac{37}{29}\right) =\left(\frac{8}{29}\right) =\left(\frac{2}{29}\right)^3 =-1.
Tonelli–Shanks算法
The Tonelli–Shanks algorithm is used to solve a congruence of the form x^2 \equiv n \,\mod\,p, where n is a quadratic residue (mod p), and p is an odd prime.
Inputs: p, an odd prime. n, an integer which is a quadratic residue (mod p), meaning that the Legendre symbol \left(\frac{n}{p}\right)=1.
Outputs: R, an integer satisfying R^2 \equiv n.
Factor out powers of 2 from p-1, defining Q and S as: p-1 = Q2^S with Q odd. If S = 1 (p \equiv 3 \,\mod\, 4), then solutions are given directly by R \equiv \pm n^{\frac{p+1}{4}}.
Select a z which is a quadratic non-residue mod p, and set c \equiv z^Q.
Let R \equiv n^{\frac{Q+1}{2}}, t\equiv n^Q, M = S.
- Loop:
If t \equiv 1, return R.
Otherwise, find the lowest i, 0 < i < M, such that t^{2^i} \equiv 1 (repeated squaring).
Let b \equiv c^{2^{(M-i-1)}}, and set R \equiv Rb, t \equiv tb^2, c \equiv b^2 and M =\; i.
If R is a solution, then the second solution is p-R.
Example 9 Solving the congruence x^2 \equiv 10 \,\mod\, {13}.
It is clear that 13 is odd, and since 10^{\frac{13-1}{2}} = 10^6 \equiv 1 \,\mod\, {13}, 10 is a quadratic residue.
Step 1: We know p-1 = 12 = 3 \cdot 2^2, so we set Q=3, S=2.
Step 2: Take z=2 as the quadratic nonresidue (2 is a quadratic non-residue because 2^{\frac{13-1}{2}} = -1 \,\mod\, {13}.
Set c = 2^3 \equiv 8 \,\mod\, {13}.
Step 3: R=10^2 \equiv -4,
t\equiv 10^3 \equiv -1 \,\mod\, {13},
M = 2.
Step 4: Now we start the loop: t \neq 1 \,\mod\, {13} so 0 < i < 2 and i = 1.
Let b \equiv 8^{2^{2-1-1}} \equiv 8 \,\mod\, {13},
c=b^2 \equiv 8^2 \equiv -1 \,\mod\, {13}.
R=Rb=-4\cdot8 \equiv 7 \,\mod\, {13},
t=tb^2 \equiv -1 \cdot -1 \equiv 1 \,\mod\, {13},
M=i=1.
Restarting the loop, because t \equiv 1 \,\mod\,{13}, we return R\equiv7 \,\mod\, {13}.
Indeed, 7^2 = 49 \equiv 10 \,\mod\, {13}.
Also (-7)^2 \equiv 6^2 \equiv 10 \,\mod\, {13}.
Lemma 3 ^{\star\star\star}. If a,b are coprime to p and have order 2^j \,\mod\, p (for j > 0) then ab has order 2^k for some k < j.
Proof. a has order 2^j \,\mod\, p, so, a^{2^{j-1}}\equiv -1 \,\mod\,p.
Likewise, b^{2^{j-1}}\equiv -1 \,\mod\,p.
So, (ab)^{2^{j-1}}\equiv 1 \,\mod\,p.
That is to say the order of ab divides 2^{j-1}, so k<j.
Proof of Tonelli–Shanks algorithm^{\star\star\star}.
We know p-1=Q2^S
r \equiv n^{\frac{Q+1}{2}}\,\mod\, p
t \equiv n^Q \,\mod\, p So, r^2 \equiv nt \,\mod\, p is true for every iteration.
If t \equiv 1 \,\mod\, p, then r^2 \equiv n \,\mod\, p and the algorithm terminates with R \equiv \pm r \,\mod\, p.
If t \neq 1 \,\mod\, p, then consider z which is a quadratic non-residue of \,\mod\,p.
Let c \equiv z^Q \,\mod\, p. Then c^{2^S} \equiv (z^Q)^{2^S} \equiv z^{2^SQ}\equiv z^{p-1} \equiv 1 \,\mod\, p and c^{2^{S-1}} \equiv z^\frac{p-1}{2}\equiv -1 \,\mod\, p, which shows that the order of c is 2^S.
Likewise, we have t^{2^S} \equiv 1 \,\mod\, p, so the order of t divides 2^S.
Suppose the order of t is 2^{S^\prime}.
Since n is a square p, t \equiv n^Q \,\mod\, p is also a square, and hence S^\prime\leq S-1.
Now we set b \equiv c^{2^{S-S^{\prime}-1}} \,\mod\, p and with r^{\prime} \equiv br \,\mod\, p, c^{\prime} \equiv b^2 \,\mod\, p and t^{\prime} \equiv c^{\prime}t \,\mod\, p. As before, r'^2\equiv{nt}^{\prime}\,\mod\,p holds.
However both t and c^{\prime} have order 2^{S^{\prime}}. It indicates that t^{\prime} has order 2^{S^{\prime\prime}} with S^{\prime\prime}< S^{\prime} .
If S^{\prime\prime} = 0 then t^{\prime} \equiv 1 \,\mod\, p, and the algorithm terminates with R \equiv \pm r^{\prime} \,\mod\, p.
Else, we restart the loop with similar definitions of b^{\prime}, r^{\prime\prime}, c^{\prime\prime} and t^{\prime\prime} until S^{{\prime\cdots\prime}} equals 0.
Since the sequence of S is strictly decreasing the algorithm will terminate. \square
Exercise 3 Try to find the solution of
x^2\equiv 78 \mod\, 137.