Trading GRH for algebra: algorithms for factoring polynomials and related structures

Gábor Ivanyos, Marek Karpinski, Lajos Rónyai, Nitin Saxena

Introduction

The problem of finding a nontrivial factor of a given polynomial over a finite field is a fundamental computational problem. There are many problems whose known algorithms first require factoring polynomials. Thus, polynomial factoring is an intensely studied question and various randomized polynomial time algorithms are known – Berlekamp [Be67], Rabin [Rab80], Cantor and Zassenhaus [CZ81], von zur Gathen and Shoup [GS92], Kaltofen and Shoup [KS98] – but its deterministic complexity is a longstanding open problem. There are although several partial results known about the deterministic complexity of polynomial factoring based on the conjectured truth of the generalized Riemann Hypothesis (GRH). The surprising connection of GRH with polynomial factoring is based on the fact that if GRH is true and rr is a prime dividing (∣k∣−1)(|k|-1) then one can find primitive rr-th nonresidues in the finite field kk, which can then be used to factor ‘special’ polynomials, xr−ax^{r}-a over kk, in deterministic polynomial time (see [Ev89]).

Based on this are many deterministic factoring algorithms known, but all of them are super-polynomial time except on special instances.

The special instance when the degree nn of the input polynomial f(x)f(x) has a “small” prime factor rr has been particularly interesting. Rónyai [Ró87] showed that under GRH one can find a nontrivial factor of f(x)f(x) in deterministic polynomial time. Later it was shown by Evdokimov [Ev94] that Rónyai’s algorithm can be modified to get under GRH a deterministic algorithm that factors any input polynomial f(x)∈k[x]f(x)\in k[x] of degree nn in sub-exponential time poly(nlog⁡n,log⁡∣k∣)poly(n^{\log n},\log|k|). This line of approach has since been investigated, in an attempt to remove GRH or improve the time complexity, leading to several algebraic-combinatorial conjectures and quite special case solutions [CH00, Gao01, IKS08].

Another instance studied is that of “special” finite fields. Bach, von zur Gathen and Lenstra [BGL01] showed under GRH that polynomials over finite fields of characteristic pp can be factored in deterministic polynomial time if ϕk(p)\phi_{k}(p) is “smooth” for some integer kk, where ϕk(x)\phi_{k}(x) is the kk-th cyclotomic polynomial. This result generalizes the previous works of Rónyai [Ró89a], Mignotte and Schnorr [MS88], von zur Gathen [G87], Camion [Cam83] and Moenck [Moe77].

Polynomial factoring has several applications both in the real world - coding theory and cryptography - and in fundamental computational algebra problems. The latter kind of applications are relevant to this work. Friedl and Rónyai [FR85] studied the computational problem of finding the simple components and a zero divisor of a given finite algebra over a finite field. They showed that all these problems depend on factoring polynomials over finite fields and hence have randomized polynomial time algorithms. Furthermore, they have under GRH deterministic subexponential time algorithms. In this work we give an unconditional version of this result. We show that if the given algebra is noncommutative then in fact we can find a zero divisor in deterministic subexponential time without needing GRH.

As we saw above there are several results on polynomial factoring that assume the truth of the GRH. Of course one would like to eliminate the need of GRH but that goal is still elusive. As a first step in that direction we give in this work GRH free versions of all the results mentioned above. In these versions the basic tool is that we either successfully find a nontrivial factor of a polynomial f(x)f(x) over a finite field kk or we find a nontrivial automorphism of the algebra k[x]/(f(x))k[x]/(f(x)). Formally speaking the main result of the paper is:

Main Theorem: Let A{\cal A} be a commutative semisimple algebra of dimension nn over a finite field kk and let A{\cal A} be given in the input in terms of basis elements over kk. Then there is a deterministic algorithm which in subexponential time poly(nlog⁡n,log⁡∣k∣)poly(n^{\log n},\log|k|) computes a decomposition of A{\cal A} into a direct sum A1⊕…⊕At{\cal A}_{1}\oplus\ldots\oplus{\cal A}_{t} and finds an automorphism of order dim⁡kAi\dim_{k}{\cal A}_{i} of the algebra Ai{\cal A}_{i}, for each 1≤i≤t1\leq i\leq t.

This main theorem can be considered as a GRH-free version of Evdokimov’s factoring result [Ev94], but its proof leads us to significantly generalize standard notions and develop novel algebraic techniques that suggest a general paradigm for GRH elimination. We are going to use it as a tool for more important applications but first let us explain the importance of this result itself. It is the first deterministic subexponential time algorithm to find a nontrivial automorphism of a given commutative semisimple algebra over a finite field. Finding a nontrivial automorphism of a given arbitrary ring is in general as hard as integer factoring [KS05] but our result shows that it might be a lot easier for a commutative semisimple algebra over a finite field. Note that in the special case when A=k[x]/(f(x)){\cal A}=k[x]/(f(x)) with f(x)f(x) splitting over kk as ∏j=1n\prod_{j=1}^{n} (x−αj)(x-\alpha_{j}), with α1,…,αn\alpha_{1},\ldots,\alpha_{n} all distinct, we have A≅⊕j=1n{\cal A}\cong\oplus_{j=1}^{n} k[x]/(x−αj)k[x]/(x-\alpha_{j}). The above algorithm either gives t>1t>1 components of A{\cal A} – in which case it effectively yields a nontrivial factor of f(x)f(x) – or t=1t=1 and it gives an automorphism σ\sigma of A{\cal A} of order nn, thus yielding nn distinct “roots” of f(x)f(x) – xx, σ(x),…\sigma(x),\ldots, σn−1(x)\sigma^{n-1}(x) – all living in A∖k{\cal A}\setminus k. This latter case can be interpreted as finding roots over finite fields in terms of “radicals”, in analogy to classical Galois theory where one studies rational polynomials whose roots can be expressed by radicals, see Section 4 for details.

The key ideas in finding a nontrivial automorphism of a given commutative semisimple B{\cal B}-algebra A{\cal A} over a finite field k⊆Bk\subseteq{\cal B} are as follows. We consider a special ideal A′{\cal A}^{\prime} (what we call the essential part in Section 5.2) of the tensor product A⊗BA{\cal A}\otimes_{\cal B}{\cal A}. The ideal A′{\cal A}^{\prime} is just the kernel of a standard homomorphism of A⊗BA{\cal A}\otimes_{\cal B}{\cal A} onto A{\cal A} and has rank (“dimension”) rkBA(rkBA−1){\rm rk}_{\cal B}{\cal A}({\rm rk}_{\cal B}{\cal A}-1) over B{\cal B}. The algebra A{\cal A} gets naturally embedded in A′{\cal A}^{\prime} by a map ϕ\phi, hence A′{\cal A}^{\prime} is an extension algebra of ϕ(A)≅A\phi({\cal A})\cong{\cal A} which in turn is an extension algebra of ϕ(B)≅B\phi({\cal B})\cong{\cal B}. Also, we know a natural automorphism of A′{\cal A}^{\prime} fixing B{\cal B} – the map τ:x⊗y↦\tau:x\otimes y\mapsto y⊗xy\otimes x. A lot of technical effort goes into “bringing down” this automorphism (or certain other automorphism σ\sigma of order 22 obtained by recursion) from A′{\cal A}^{\prime} to A{\cal A}, i.e. getting a B{\cal B}-automorphism σ′\sigma^{\prime} of A{\cal A}. The technical arguments fall into two cases, depending on whether rkAA′=rkBA′/rkBA{\rm rk}_{\cal A}{\cal A}^{\prime}={\rm rk}_{\cal B}{\cal A}^{\prime}/{\rm rk}_{\cal B}{\cal A} is odd or even.

(1) If the rank rkBA{\rm rk}_{\cal B}{\cal A} is even then rkAA′{\rm rk}_{\cal A}{\cal A}^{\prime} is odd. We find an element u∈A′u\in{\cal A}^{\prime} with uτ=−uu^{\tau}=-u. If u∈Au\in{\cal A} then the restriction of τ\tau is a B{\cal B}-automorphism of the subalgebra B[u]{\cal B}[u] of A{\cal A} generated by B{\cal B} and uu. If u∉Au\not\in{\cal A} then either the subalgebra A[u]{\cal A}[u] of A′{\cal A}^{\prime} is not a free A{\cal A}-module or A′{\cal A}^{\prime} is not a free A[u]{\cal A}[u]-module. Both cases give us a zero divisor in A′{\cal A}^{\prime} to go to a smaller ideal I{\cal I} of A′{\cal A}^{\prime} such that we know an automorphism of I{\cal I}, it contains a “copy” of A{\cal A} and rkAI{\rm rk}_{\cal A}{\cal I} is odd, thus we can continue this “descent” (from A′{\cal A}^{\prime} to I{\cal I}) till we have a B{\cal B}-automorphism of A{\cal A} or of a subalgebra of A{\cal A} (this process appears in Section 5.1). In the former case we are done while in the latter case we use two recursive calls and certain techniques to “glue” the three available automorphisms. (2) If the rank rkBA{\rm rk}_{\cal B}{\cal A} is odd then rkAA′{\rm rk}_{\cal A}{\cal A}^{\prime} is even and we can use the technique above to find an A{\cal A}-automorphism σ\sigma of A′{\cal A}^{\prime}. It turns out that σ\sigma and τ\tau generate a group of automorphisms of A′{\cal A}^{\prime} which is big enough to find a proper ideal I{\cal I} of A′{\cal A}^{\prime} efficiently. We may further assume that the rank of I{\cal I} over A{\cal A} is at most rkAA′/2=(rkBA−1)/2{\rm rk}_{\cal A}{\cal A}^{\prime}/2=({\rm rk}_{\cal B}{\cal A}-1)/2. This allows us a recursive call with (I,A)({\cal I},{\cal A}) in place of (A,B)({\cal A},{\cal B}) to get an A{\cal A}-automorphism of I{\cal I}, which we eventually show is enough to extract an automorphism of A{\cal A} using tensor properties and a recursive call (this case 2 gets handled in 5.3).

This algebraic-extensions jugglery either goes through and yields a nontrivial automorphism σ′\sigma^{\prime} of A{\cal A} fixing B{\cal B} or it “fails” and yields a zero divisor in A{\cal A} which we use to “break” A{\cal A} into smaller subalgebras and continue working there. As in each recursive call, in the above two cases, the rank of the bigger algebra over the subalgebra is at most half of the original one, the depth of the recursion is at most log⁡rkBA\log{\rm rk}_{\cal B}{\cal A}. This gives an nlog⁡nn^{\log n} term in the time complexity analysis.

Roots of unity play a significant role in gluing automorphisms (i.e. in extending an automorphism of a subalgebra, of elements fixed by another automorphism, to the whole algebra). The gluing process is described in Section 4.4. As we do not know roots of unity in kk we resort to attaching virtual rr-th roots of unity for a suitable prime rr, i.e. working in the cyclotomic extension k[ζr]:=k[x]/(∑i=1r−1xi)k[\zeta_{r}]:=k[x]/(\sum_{i=1}^{r-1}x^{i}) and A′[ζr]:={\cal A}^{\prime}[\zeta_{r}]:= k[ζr]⊗kA′k[\zeta_{r}]\otimes_{k}{\cal A}^{\prime}. We then need to generalize standard algebraic constructions, like Kummer extensions and Teichmüller subgroups which were first used in a context similar to ours by Lenstra [L91] to find isomorphisms between fields, to our situation of commutative semisimple algebras.

The above theorem and its proof techniques have important applications. The first one is in finding zero divisors in a noncommutative algebra.

Application 1: Let A{\cal A} be an algebra of dimension nn over a finite field kk and let A{\cal A} be given in the input in terms of basis elements over kk. Assume that A{\cal A} is noncommutative. Then there is a deterministic algorithm which finds a zero divisor in A{\cal A} in time poly(nlog⁡n,log⁡∣k∣)poly(n^{\log n},\log|k|).

The previous best result was due to Rónyai [Ró90] who gave an algorithm invoking polynomial factorization over finite fields and hence taking subexponential time assuming GRH. Our result removes the GRH assumption. It is interesting to note that if we prove such a result for commutative algebras as well then we would basically be able to factor polynomials in subexponential time without needing GRH.

If A{\cal A} is a simple algebra over the finite field kk then it is isomorphic to the algebra Mm(K)M_{m}(K) of the m×mm\times m matrices with entries from an extension field KK of kk. By Application 1 we find a proper left ideal of A{\cal A}. A recursive call to a certain subalgebra of the left ideal will ultimately give a minimal left ideal of A{\cal A} and using this minimal one-sided ideal an isomorphism with Mm(K)M_{m}(K) can be efficiently computed. Thus, for constant mm, Application 1 extends Lenstra’s result (on computing isomorphisms between input fields) to noncommutative simple algebras, i.e, the explicit isomorphism problem is solved in this case. We note that, in general, algebra isomorphism problem over finite fields is not “believed” to be NP-hard but it is at least as hard as the graph isomorphism problem [KS05]. We also remark that the analogous problem of constructing isomorphism with the algebra of matrices over the rationals has a surprising application to rational parametrization of certain curves, see [GHPS06].

The techniques used to prove Main Theorem can be applied to find a nontrivial factor of an rr-th cyclotomic polynomial over a finite field kk, for almost all rr’s, in deterministic polynomial time.

Roots of an rr-th cyclotomic polynomial over kk are the rr-th roots of unity and thus naturally related to all polynomial factoring algorithms. Assuming GRH several algorithms are known to factor these important polynomials (see [Ev89]). The above result gives the first deterministic polynomial time algorithm to nontrivially factor “most” of the cyclotomic polynomials without assuming GRH.

The third application of the techniques used to prove Main Theorem is in the instance of polynomial factoring over prime fields when we know the Galois group of the input polynomial. The following theorem can be seen as the GRH-free version of the main theorem of Rónyai [Ró89b].

Thus over “special” fields (i.e. when p−1p-1 has only small prime factors) the above actually gives a deterministic polynomial time algorithm, a significant improvement over Main Theorem.

2 Organization

In Section 2 we collect various standard objects and structural facts associated to algebras. We also discuss the three basic methods that lead to discovering a zero divisor in an algebra – finding discrete log for elements of prime-power order, finding a free base of a module and refining an ideal by a given automorphism.

In this work we use methods for finding zero divisors in algebras in the case when certain groups of automorphisms are given. One of such methods is computing fixed subalgebras and testing freeness over them. In Section 3 we give a characterization of algebras and groups which survive these kinds of attacks. These algebras, called semiregular wrt the group, behave like fields in the sense that the whole algebra is a free module over the subalgebra of fixed points of the group and the rank equals the size of the group.

In Section 4 we build a small theory for the main algebraic construction, Kummer-type extensions over algebras, that we are going to use. We investigate there the action of the automorphisms of an algebra A{\cal A} on a certain subgroup, Teichmüller subgroup, of the multiplicative group of a Kummer-type extension of A{\cal A}. The proofs of Applications 2 and 3 get completed in this section.

In Section 5 we apply the machinery of Section 4 to the tensor power algebras and complete the proof of Main Theorem.

In Section 6 we find suitable subalgebras of a given noncommutative algebra to invoke Main Theorem and complete the proof of Application 1.

In Section 7 we use the techniques developed for the Main Theorem in the case of special finite fields and complete the proof of Application 4.

Preliminaries

In this section we list some algebraic notions that we use in this work and that can be found in standard algebra texts, for example [La80].

Rings, Units and Zero-divisors: A ring with identity (or ring, for short) RR is a set of elements together with two operations – denoted by addition ++ and multiplication ⋅\cdot – such that (R,+)(R,+) is an Abelian group, ⋅\cdot is associative, distributes over ++ and has an identity element 1R1_{R}. Note that the set R∗R^{*}, containing all the elements of RR that have a multiplicative inverse, is a multiplicative group called the group of units. For a prime integer rr we call a unit xx an rr-element if the multiplicative order of xx is a power of rr. An element xx is called a zero divisor if x≠0x\not=0 and there exist nonzero y,y′∈Ay,y^{\prime}\in{\cal A} such that yx=xy′=0yx=xy^{\prime}=0.

Free and Cyclic: For an RR-module MM, a set E⊂ME\subset M is called a free basis of MM if: EE is a generating set for MM, i.e. every element of MM is a finite sum of elements of EE multiplied by coefficients in RR, and EE is a free set, i.e. for all r1,…,rn∈Rr_{1},\ldots,r_{n}\in R; e1,…,en∈Ee_{1},\ldots,e_{n}\in E, r1e1+⋯+rnen=0r_{1}e_{1}+\cdots+r_{n}e_{n}=0 implies that r1=⋯=rn=0r_{1}=\cdots=r_{n}=0. A free module is a module with a free basis. ∣E∣|E| is called the rank or dimension of the free module MM over RR. Clearly, a vector space is a free module. A module is called a cyclic module if it is generated by one element.

Algebras: Let (R,+,⋅)(R,+,\cdot) be a commutative ring and (A,+,⋅)({\cal A},+,\cdot) be a ring which is also an RR-module, where the additive operation of A{\cal A} as a module coincides with ++. We say that A{\cal A} is an associative RR-algebra with identity (or just an RR-algebra for short) if multiplication by elements of RR commutes with multiplication by elements of A{\cal A}: for every r∈Rr\in R and for every a,b∈Aa,b\in{\cal A} we have r(ab)=(ra)b=a(rb)r(ab)=(ra)b=a(rb).

Subalgebras: A subalgebra B{\cal B} of an RR-algebra (A,+,⋅)({\cal A},+,\cdot) is just a submodule of A{\cal A} closed under multiplication. In this paper unless otherwise stated, by a subalgebra of A{\cal A} we mean a subalgebra containing the identity element 1A1_{\cal A}. Note that if B{\cal B} is a commutative subalgebra of A{\cal A} then A{\cal A} is a B{\cal B}-module in a natural way. If, furthermore, B{\cal B} is contained in the center of A{\cal A} (that is, ab=baab=ba for every a∈Aa\in{\cal A} and for every b∈Bb\in{\cal B}) then A{\cal A} is a B{\cal B}-algebra.

Extension: If B{\cal B} is a commutative kk-algebra and a B{\cal B}-algebra A{\cal A} is also a free module over B{\cal B} then we call A{\cal A} an algebra extension or an extension algebra over B{\cal B}. This terminology is justified by the fact that B{\cal B} is embedded into (the center of) A{\cal A} by the map b↦b1Ab\mapsto b1_{\cal A}. We denote the rank (“dimension”) of A{\cal A} as a B{\cal B}-module by rkBA{\rm rk}_{\cal B}{\cal A} or [A:B][{\cal A}:{\cal B}]. We sometimes use this notation also when there is an implicit embedding of B{\cal B} in A{\cal A}.

Primitive Element: We call an algebra extension A{\cal A} over B{\cal B} simple if there is an α∈A\alpha\in{\cal A} such that {1,α,…\{1,\alpha,\ldots, αn−1}\alpha^{n-1}\} forms a free basis of A{\cal A} over B{\cal B}. We call α\alpha a primitive element and write A=B[α]{\cal A}={\cal B}[\alpha].

Following is a version of the standard Primitive Element Theorem.

If K⊇FK\supseteq F are fields such that char Fchar\ F is or >[K:F]2>[K:F]^{2}, then KK has a primitive element over FF.

There are two natural operations defined on algebras – the direct sum and the tensor product – each constructs a bigger algebra.

Direct Sum: Let (A1,+,⋅)({\cal A}_{1},+,\cdot) and (A2,+,⋅)({\cal A}_{2},+,\cdot) be two algebras. Then the direct sum algebra, A1⊕A2{\cal A}_{1}\oplus{\cal A}_{2}, is the set {(a1,a2)∣a1∈A1,a2∈A2}\{(a_{1},a_{2})\mid a_{1}\in{\cal A}_{1},a_{2}\in{\cal A}_{2}\} together with component-wise addition and multiplication operations. In a similar vein, for subalgebras A1,A2{\cal A}_{1},{\cal A}_{2} of an algebra A{\cal A} we write A=A1⊕A2{\cal A}={\cal A}_{1}\oplus{\cal A}_{2}, if A=A1+A2{\cal A}={\cal A}_{1}+{\cal A}_{2} and A1,A2{\cal A}_{1},{\cal A}_{2} are orthogonal i.e. ∀\forall a1∈A1a_{1}\in{\cal A}_{1}, a2∈A2a_{2}\in{\cal A}_{2}, a1a2=a2a1=0a_{1}a_{2}=a_{2}a_{1}=0.

Tensor Product: Furthermore, if B{\cal B} is a commutative algebra such that A1,A2{\cal A}_{1},{\cal A}_{2} are B{\cal B}-algebras of dimensions n1,n2n_{1},n_{2} respectively over B{\cal B} then their tensor product algebra wrt B{\cal B}, A1⊗BA2{\cal A}_{1}\otimes_{\cal B}{\cal A}_{2}, is the set {a1⊗a2∣a1∈A1,a2∈A2}\{a_{1}\otimes a_{2}\mid a_{1}\in{\cal A}_{1},a_{2}\in{\cal A}_{2}\} naturally viewed as a B{\cal B}-module having the multiplication operation: (a1⊗a2)⋅(a_{1}\otimes a_{2})\cdot (a1′⊗a2′)=(a_{1}^{\prime}\otimes a_{2}^{\prime})= (a1a1′⊗a2a2′)(a_{1}a_{1}^{\prime}\otimes a_{2}a_{2}^{\prime}) for all a1,a1′∈A1a_{1},a_{1}^{\prime}\in{\cal A}_{1} and a2,a2′∈A2a_{2},a_{2}^{\prime}\in{\cal A}_{2}. Note that the tensor product algebra has dimension n1n2n_{1}n_{2} over B{\cal B}. Thus, if B{\cal B} is finite then ∣A1⊕A2∣=∣B∣n1+n2|{\cal A}_{1}\oplus{\cal A}_{2}|=|{\cal B}|^{n_{1}+n_{2}}, while ∣A1⊗BA2∣=∣B∣n1n2|{\cal A}_{1}\otimes_{\cal B}{\cal A}_{2}|=|{\cal B}|^{n_{1}n_{2}}.

Decomposability: An algebra A{\cal A} is called indecomposable if there are no nonzero algebras R,SR,S such that A≅R⊕S{\cal A}\cong R\oplus S.

Following are some standard facts relating decomposability to idempotents in commutative algebras.

Let A{\cal A} be a commutative algebra then: (1) A{\cal A} decomposes iff A{\cal A} has a nontrivial idempotent. (2) If ee is an idempotent in A{\cal A} then A≅{\cal A}\cong eA⊕(1−e)Ae{\cal A}\oplus(1-e){\cal A}. (3) If ee is a primitive idempotent in A{\cal A} then eAe{\cal A} is indecomposable.

Ideal: An ideal II of an algebra A{\cal A} is a subset that is an additive subgroup of A{\cal A}, is closed under multiplication and it contains both aI:={a⋅i∣i∈I}aI:=\{a\cdot i\mid i\in I\}; Ia:={i⋅a∣i∈I}Ia:=\{i\cdot a\mid i\in I\} for all a∈Aa\in{\cal A}. Note that {0}\{0\} and A{\cal A} are ideals of A{\cal A}, we call them trivial ideals. Also note that proper ideals are not subalgebras in the strict sense used in this paper.

Semisimplicity: An algebra A{\cal A} is called simple if it has no nontrivial ideal. An algebra is called semisimple if it is a direct sum of simple algebras.

Following are some standard facts about commutative semisimple algebras.

Let A{\cal A} be a commutative semisimple algebra then: (1) A{\cal A} is a direct sum of fields. (2) If II is an ideal of A{\cal A} and I⊥:={a∈A∣aI=0}I^{\perp}:=\{a\in{\cal A}\mid aI=0\} (called the complement of II) then A=I⊕I⊥{\cal A}=I\oplus I^{\perp}. Furthermore, there exists an idempotent ee of A{\cal A} such that I=eAI=e{\cal A} thus giving an explicit projection from A{\cal A} to II.

Following is the celebrated Artin-Wedderburn Theorem that classifies semisimple algebras.

Any semisimple algebra A{\cal A} is isomorphic to a direct sum of ni×nin_{i}\times n_{i} matrix algebras over division rings DiD_{i} (i.e. DiD_{i} satisfies all field axioms except commutative multiplication). Both the nin_{i}’s and DiD_{i}’s are uniquely determined up to permutation of the indices ii.

Morphisms: Let ϕ\phi be a map between two algebras A{\cal A}, B{\cal B}. If ϕ\phi preserves the addition and multiplication operations of the algebras then we call it a homomorphism. If the homomorphism ϕ\phi is injective then we call it an embedding. If the homomorphism ϕ\phi is both injective and surjective then we call it an isomorphism. A homomorphism from an algebra to itself is called an endomorphism. An isomorphism from an algebra to itself is called an automorphism. A set SS is said to be invariant under the automorphism ϕ\phi of A{\cal A} if for all s∈Ss\in S, ϕ(s)∈S\phi(s)\in S. ϕ\phi is said to fix SS if ϕ\phi fixes each element of SS, i.e. for all s∈Ss\in S, ϕ(s)=s\phi(s)=s. The group of SS-automorphisms of A{\cal A}, AutS(A)Aut_{S}({\cal A}), is the set of all automorphisms of A{\cal A} that fix SS.

Throughout this paper all algebras are algebras with identity elements. Unless otherwise stated explicitly, by a subalgebra we mean a subalgebra containing the identity element. Thus, in this strict sense a proper ideal is not considered as a subalgebra. In the rest of this section A{\cal A} stands for a commutative semisimple algebra over the finite field kk.

Given two rr-elements (i.e. having order a power of the prime rr) in a commutative semisimple algebra there is an algorithm that computes the discrete logarithm or finds a zero divisor (of a special form) in A{\cal A}. We describe this algorithm below, it is a variant of the Pohlig-Hellman [PH78] algorithm with the equality testing of elements replaced by testing whether their difference is a zero divisor.

Given a prime rr distinct from the characteristic of a finite field kk, a finite dimensional commutative semisimple algebra A{\cal A} over kk and two rr-elements a,b∈A∗a,b\in{\cal A}^{*}, such that the order of aa is greater than or equal to the order of bb. There is a deterministic algorithm which computes in time poly(r,log⁡∣A∣)poly(r,\log|{\cal A}|): (1) either two non-negative integers s,s′s,s^{\prime} such that as−bs′a^{s}-b^{s^{\prime}} is a zero divisor in A{\cal A}, (2) or an integer s≥0s\geq 0 with as=ba^{s}=b.

Let tat_{a} be the smallest non negative integer such that arta−1a^{r^{t_{a}}}-1 is zero or a zero divisor in A{\cal A}. Since ta≤log⁡r∣A∣t_{a}\leq\log_{r}|{\cal A}| we can compute ar0−1,ar1−1,…,arta−1a^{r^{0}}-1,a^{r^{1}}-1,\ldots,a^{r^{t_{a}}}-1 in poly(log⁡∣A∣)poly(\log|{\cal A}|) time via fast exponentiation. We are done if 0≠arta−1=arta−b00\not=a^{r^{t_{a}}}-1=a^{r^{t_{a}}}-b^{0} is a zero divisor. Therefore we may assume that arta=1a^{r^{t_{a}}}=1, i.e. the order of aa is rtar^{t_{a}}. Let tbt_{b} be the smallest non-negative integer such that brtb−1b^{r^{t_{b}}}-1 is a zero divisor. Like tat_{a}, tbt_{b} can be computed in polynomial time and we may again assume that rtbr^{t_{b}} is the order of bb. Replacing aa with arta−tba^{r^{t_{a}-t_{b}}} we may assure that ta=tb=tt_{a}=t_{b}=t. In this case for every primitive idempotent ee of A{\cal A}: ea,ebea,eb have order rtr^{t} in the finite field eAe{\cal A}. As the multiplicative group of a finite field is cyclic, this means that there exists a nonnegative integer s<rts<r^{t} such that (ea)s=eb(ea)^{s}=eb. So we now attempt to find this discrete log, ss, and the corresponding idempotent ee as well.

We iteratively compute the consecutive sections of the base rr expansion of ss. To be more specific, we compute integers s0=0,s1,s2,…,sts_{0}=0,s_{1},s_{2},\ldots,s_{t} together with idempotents e1,…,ete_{1},\ldots,e_{t} of A{\cal A} such that, for all 1≤j≤t1\leq j\leq t: 0≤sj<rj0\leq s_{j}<r^{j}, sj≡sj−1(modrj−1)s_{j}\equiv s_{j-1}\pmod{r^{j-1}} and asjrt−jej=brt−jeja^{{s_{j}}r^{t-j}}e_{j}=b^{r^{t-j}}e_{j}.

In the initial case j=1j=1 we find by exhaustive search, in at most rr rounds, an s1∈{1,…,r−1}s_{1}\in\{1,\ldots,r-1\} such that z1=z_{1}= (art−1s1−brt−1)(a^{r^{t-1}{s_{1}}}-b^{r^{t-1}}) is zero or a zero divisor. If it is zero then we set e1=1e_{1}=1 otherwise we compute and set e1e_{1} equal to the identity element of the annihilator ideal {x∈A∣z1x=0}\{x\in{\cal A}|z_{1}x=0\}.

Assume that for some j<tj<t we have found already sjs_{j} and eje_{j} with the desired property. Then we find by exhaustive search, in at most rr rounds, an integer dj+1∈{0,…,r−1}d_{j+1}\in\{0,\ldots,r-1\} such that zj+1=z_{j+1}= (a(sj+rjdj+1)rt−j−1−brt−j−1)(a^{(s_{j}+r^{j}d_{j+1})r^{t-j-1}}-b^{r^{t-j-1}}) is zero or a zero divisor. We set sj+1=(sj+dj+1rj)s_{j+1}=(s_{j}+d_{j+1}r^{j}) and take as ej+1e_{j+1} the identity element of the annihilator ideal {x∈ejA∣xzj+1=0}\{x\in e_{j}{\cal A}|xz_{j+1}=0\}.

The above procedure clearly terminates in tt rounds and using fast exponentiation can be implemented in poly(r,log⁡∣A∣)poly(r,\log|{\cal A}|) time. □\Box

2 Free Bases of Modules

One of the possible methods for finding zero divisors in algebras is attempting to compute a free basis of a module over it. Following Lemma states the basic tool to do that.

Let VV be a finitely generated module over a finite dimensional algebra A{\cal A} over a finite field kk. If VV is not a free A{\cal A}-module then one can find a zero divisor in A{\cal A} deterministically in time poly(dim⁡AV,log⁡∣A∣)poly(\dim_{\cal A}V,\log|{\cal A}|).

We give an algorithm that attempts to find a free basis of VV over A{\cal A}, but as there is no free basis it ends up finding a zero divisor.

Pick a nonzero v1∈Vv_{1}\in V. We can efficiently check whether a nonzero x∈Ax\in{\cal A} exists such that xv1=0xv_{1}=0, and also find it by linear algebra over kk. If we get such an xx then it is a zero divisor, for otherwise x−1x^{-1} would exist implying v1=0v_{1}=0. So suppose such an xx does not exist, hence V1:=Av1V_{1}:={\cal A}v_{1} is a free A{\cal A}-module. Now V1≠VV_{1}\neq V so find a v2∈V∖V1v_{2}\in V\setminus V_{1} by linear algebra over kk. Again we can efficiently check whether a nonzero x∈Ax\in{\cal A} exists such that xv2∈V1xv_{2}\in V_{1}, and also find it by linear algebra over kk. If we get such an xx then it is a zero divisor, for otherwise x−1x^{-1} would exist implying v2∈V1v_{2}\in V_{1}. So suppose such an xx does not exist, hence V2:=Av1+Av2V_{2}:={\cal A}v_{1}+{\cal A}v_{2} is a free A{\cal A}-module. Now V2≠VV_{2}\neq V so we can find a v3∈V∖V2v_{3}\in V\setminus V_{2} by linear algebra over kk and continue this process. This process will, in at most dimAVdim_{\cal A}V iterations, yield a zero divisor as VV is not a free A{\cal A}-module. □\Box

3 Automorphisms and Invariant Ideal Decompositions

Given an ideal II of A{\cal A} and an automorphism σ\sigma of A{\cal A} we usually try to find zero divisors from the action of σ\sigma on II. Note that, by Fact 3, A=I⊕I⊥{\cal A}=I\oplus I^{\perp}. Now IσI^{\sigma} is an ideal of A{\cal A}, and if it is neither II nor I⊥I^{\perp} then we try computing I∩IσI\cap I^{\sigma}. This can be easily computed by first finding the identity element ee of II, and then I∩IσI\cap I^{\sigma} is simply Aeeσ{\cal A}ee^{\sigma}. By the hypothesis this will be a proper ideal of II, thus leading to a refinement of the decomposition: A=I⊕I⊥{\cal A}=I\oplus I^{\perp}. This basic idea can be carried all the way to give the following tool that finds a refined, invariant, ideal decomposition.

Given A{\cal A}, a commutative semisimple algebra over a finite field kk together with a set of kk-automorphisms Γ\Gamma of A{\cal A} and a decomposition of A{\cal A} into a sum of pairwise orthogonal ideals J1,…,JsJ_{1},\ldots,J_{s}, there is a deterministic algorithm of time complexity poly(∣Γ∣,log⁡∣A∣)poly(|\Gamma|,\log|{\cal A}|) that computes a decomposition of A{\cal A} into a sum of pairwise orthogonal ideals I1,…,ItI_{1},\ldots,I_{t} such that: (1) the new decomposition is a refinement of the original one – for every j∈{1,…,t}j\in\{1,\ldots,t\}, there exists i∈{1,…,s}i\in\{1,\ldots,s\} such that Ij⊆JiI_{j}\subseteq J_{i}, and (2) the new decomposition is invariant under Γ\Gamma – the group generated by Γ\Gamma permutes the ideals I1,…,ItI_{1},\ldots,I_{t}, i.e. for every σ∈Γ\sigma\in\Gamma and for every index j∈{1,…,t}j\in\{1,\ldots,t\}, we have Ijσ=IjσI_{j}^{\sigma}=I_{j^{\sigma}} for some index jσ∈{1,…,t}j^{\sigma}\in\{1,\ldots,t\}.

Semiregularity

In this section we continue to assume that A{\cal A} is a commutative semisimple algebra over a finite field kk. Given Γ⊆Autk(A)\Gamma\subseteq{\rm Aut}_{k}({\cal A}), a basis of AΓ{\cal A}_{\Gamma} can be computed by solving a system of linear equations in A{\cal A}. Thus, we can apply the method of Lemma 2.2 considering A{\cal A} as a AΓ{\cal A}_{\Gamma}-module wrt the multiplication in A{\cal A}. In this section we describe a class of algebras, together with automorphisms, that are free modules over the subalgebra of the fixed points of the corresponding set of automorphisms, i.e. on which the tool of Lemma 2.2 is ineffective.

Let σ\sigma be a kk-automorphism of A{\cal A}. We say that σ\sigma is fix-free if there is no nontrivial ideal II of A{\cal A} such that σ\sigma fixes II. We call a group G≤Aut(A)G\leq{\rm Aut}({\cal A}) semiregular if every non-identity element of GG is fix-free. A single automorphism σ\sigma of A{\cal A} is semiregular if σ\sigma generates a semiregular group of automorphisms of A{\cal A}.

We have the following characterization of semiregularity.

Let A{\cal A} be a commutative semisimple algebra over a finite field kk and let GG be a group of kk-automorphisms of A{\cal A}. Then dim⁡kA≤∣G∣⋅dim⁡kAG\dim_{k}{\cal A}\leq|G|\cdot\dim_{k}{\cal A}_{G}, where equality holds if and only if GG is semiregular. This condition is also equivalent to saying that A{\cal A} is a free AG{\cal A}_{G}-module of rank ∣G∣|G|.

The proof is based on the observation that A{\cal A} is a direct sum of fields and a kk-automorphism of A{\cal A} just permutes these component fields.

Let ee be a primitive idempotent of A{\cal A}. We denote the stabilizer of ee in GG by GeG_{e}, i.e, Ge={σ∈G∣eσ=e}G_{e}=\{\sigma\in G|e^{\sigma}=e\}. Let CC be a complete set of right coset representatives modulo GeG_{e} in GG. The orbit of ee under GG is {eγ∣γ∈C}\{e^{\gamma}|\gamma\in C\} and they are ∣G:Ge∣|G:G_{e}| many pairwise orthogonal primitive idempotents in A{\cal A}. This means that the component field eAe{\cal A} is sent to the other component fields {eγA∣γ∈C}\{e^{\gamma}{\cal A}|\gamma\in C\} by GG. Thus, the element f:=∑γ∈Ceγf:=\sum_{\gamma\in C}e^{\gamma} ∈AG\in{\cal A}_{G} is a primitive idempotent of AG{\cal A}_{G} and equivalently fAGf{\cal A}_{G} is a field.

The subgroup GeG_{e} acts as a group of field automorphisms of eAe{\cal A}. This gives a restriction map λ:Ge→Autk(eA)\lambda:G_{e}\rightarrow Aut_{k}(e{\cal A}) whose kernel say is NeN_{e}, so Ne={σ∈G∣σ fixes eA}N_{e}=\{\sigma\in G|\sigma\text{ fixes }e{\cal A}\} is a normal subgroup of GeG_{e}, thus Ge/NeG_{e}/N_{e} are distinct kk-automorphisms of the field eAe{\cal A}. We claim that (eA)Ge=eAG(e{\cal A})_{G_{e}}=e{\cal A}_{G}. The inclusion eAG⊆(eA)Gee{\cal A}_{G}\subseteq(e{\cal A})_{G_{e}} is trivial. To see the reverse inclusion, let x∈(eA)Gex\in(e{\cal A})_{G_{e}} and consider y:=∑γ∈Cxγy:=\sum_{\gamma\in C}x^{\gamma}. Since x∈eAx\in e{\cal A} we get ex=xex=x and y=∑γ∈Ceγxγy=\sum_{\gamma\in C}e^{\gamma}x^{\gamma}, whence using the orthogonality of the idempotents eγe^{\gamma}, we infer ey=xey=x. The fact that y∈AGy\in{\cal A}_{G} completes the proof of the claim. As GeG_{e} is a group of automorphisms of the field eAe{\cal A}, this claim implies eAGe{\cal A}_{G} is a field too and also by Galois theory [eA:eAG]=∣Ge/Ne∣[e{\cal A}:e{\cal A}_{G}]=|G_{e}/N_{e}|.

Observe that ef=eef=e and this makes multiplication by ee a onto homomorphism from fAGf{\cal A}_{G} to eAGe{\cal A}_{G}. This homomorphism is also injective as eAGe{\cal A}_{G}, fAGf{\cal A}_{G} are fields, thus making fAG≅eAGf{\cal A}_{G}\cong e{\cal A}_{G}. Together with the fact that fAf{\cal A} is a free eAe{\cal A}-module of dimension ∣G:Ge∣|G:G_{e}| this implies that dim⁡fAGfA=∣G:Ge∣dim⁡eAGeA\dim_{f{\cal A}_{G}}f{\cal A}=|G:G_{e}|\dim_{e{\cal A}_{G}}e{\cal A}. Furthermore, from the last paragraph dim⁡eAGeA=∣Ge:Ne∣\dim_{e{\cal A}_{G}}e{\cal A}=|G_{e}:N_{e}|, thus dim⁡fAGfA=∣G:Ne∣≤∣G∣\dim_{f{\cal A}_{G}}f{\cal A}=|G:N_{e}|\leq|G|. Finally, this gives dim⁡kfA≤dim⁡kfAG⋅∣G∣\dim_{k}f{\cal A}\leq\dim_{k}f{\cal A}_{G}\cdot|G|. Applying this for all the primitive idempotents ee of A{\cal A} (and thus to all the corresponding primitive idempotents ff of AG{\cal A}_{G}), we obtain the asserted inequality.

Observe that equality holds iff ∣Ne∣=1|N_{e}|=1 for every primitive idempotent ee of A{\cal A}. In that case for every primitive idempotent ee of A{\cal A}, there is no non-identity automorphism in GG that fixes eAe{\cal A}, thus equivalently for every nontrivial ideal II of A{\cal A} there is no non-identity automorphism in GG that fixes II. This means that equality holds iff GG is semiregular.

Also, equality holds iff dim⁡fAGfA=∣G∣\dim_{f{\cal A}_{G}}f{\cal A}=|G| for every primitive idempotent ee of A{\cal A}. The latter condition is equivalent to saying that every component field of AG{\cal A}_{G} has multiplicity ∣G∣|G| in the AG{\cal A}_{G}-module A{\cal A}, this in turn is equivalent to saying that A{\cal A} is a free AG{\cal A}_{G}-module of dimension ∣G∣|G|. □\Box

Using the above Lemma we can decide semiregularity in an efficient way.

Given a commutative semisimple algebra A{\cal A} over a finite field kk, together with a set Γ\Gamma of kk-automorphisms of A{\cal A}. Let GG be the group generated by Γ\Gamma. In deterministic poly(∣Γ∣,log⁡∣A∣)poly(|\Gamma|,\log|{\cal A}|) time one can list all the elements of GG if GG is semiregular, or one can find a zero divisor of A{\cal A} if GG is not semiregular.

We first compute AΓ{\cal A}_{\Gamma} by linear algebra over kk. We can assume that A{\cal A} is a free AΓ{\cal A}_{\Gamma}-module otherwise the algorithm in Lemma 2.2 finds a zero divisor. By Lemma 3.1 ∣G∣≥dim⁡AΓA=:m|G|\geq\dim_{{\cal A}_{\Gamma}}{\cal A}=:m so try to enumerate (m+1)(m+1) different elements in the group GG. If we are unable to get that many elements then, by Lemma 3.1, GG is semiregular and we end up with a list of mm elements that exactly comprise GG.

If we do get a set SS of (m+1)(m+1) elements then GG is clearly not semiregular. Let ee be a primitive idempotent of A{\cal A} such that the subgroup Ne≤GN_{e}\leq G, consisting of automorphisms that fix eAe{\cal A}, is of maximal size. Then from the proof of Lemma 3.1 we obtain ∣G:Ne∣≤m|G:N_{e}|\leq m which means, by pigeon-hole principle, that in the set SS there are two different elements σ1,σ2\sigma_{1},\sigma_{2} such that σ:=σ1σ2−1∈Ne\sigma:=\sigma_{1}\sigma_{2}^{-1}\in N_{e}, thus σ\sigma fixes eAe{\cal A}. We now compute Aσ{\cal A}_{\sigma} and we know from this discussion that eA⊆Aσe{\cal A}\subseteq{\cal A}_{\sigma}. Thus we get two orthogonal component algebras eAσe{\cal A}_{\sigma} and (1−e)Aσ(1-e){\cal A}_{\sigma} of Aσ{\cal A}_{\sigma}. We have from the proof of Lemma 3.1 that eAσ=(eA)σ=eAe{\cal A}_{\sigma}=(e{\cal A})_{\sigma}=e{\cal A} while (1−e)Aσ=(1-e){\cal A}_{\sigma}= ((1−e)A)σ≠(1−e)A((1-e){\cal A})_{\sigma}\neq(1-e){\cal A} (if ((1−e)A)σ=(1−e)A((1-e){\cal A})_{\sigma}=(1-e){\cal A} then σ\sigma would fix every element in A{\cal A} and would be a trivial automorphism). As a result A{\cal A} is not a free module over Aσ{\cal A}_{\sigma} and hence we can find a zero divisor of A{\cal A} using the method of Lemma 2.2. □\Box

Subgroup GBG_{\cal B}: Let GG be a semiregular group of kk-automorphisms of A{\cal A} and let B{\cal B} be a subalgebra of A{\cal A}. We define GBG_{\cal B} to be the subgroup of automorphisms of GG that fix B{\cal B}. We give below a Galois theory-like characterization of GBG_{\cal B}.

Given a semiregular group GG of automorphisms of a commutative semisimple algebra A{\cal A} over a finite field kk and a subalgebra B{\cal B} of A{\cal A} containing AG{\cal A}_{G}, one can find a zero divisor in A{\cal A} in deterministic polynomial time if B≠AGB{\cal B}\not={\cal A}_{G_{\cal B}}.

If A{\cal A} is a field extension of kk then by Galois theory B=AGB{\cal B}={\cal A}_{G_{\cal B}}. If ∣k∣<(dim⁡kA)2|k|<(\dim_{k}{\cal A})^{2} and A{\cal A} is not a field then we can find a zero divisor in A{\cal A} using Berlekamp’s deterministic polynomial time algorithm. So for the rest of the proof we may assume that ∣k∣≥(dim⁡kA)2|k|\geq(\dim_{k}{\cal A})^{2} and then the usual proof of Fact 1 gives a deterministic polynomial time algorithm for finding a primitive element xx of A{\cal A} over kk, see [GI00].

Let ∣G∣=d|G|=d. We may assume that the elements 1,x,x2,…,xd−11,x,x^{2},\ldots,x^{d-1} form a free basis of A{\cal A} over AG{\cal A}_{G} since otherwise we find a zero divisor in A{\cal A} using the method of Lemma 2.2. Let xd=∑i=0d−1aixix^{d}=\sum_{i=0}^{d-1}a_{i}x^{i} with ai∈AGa_{i}\in{\cal A}_{G} and let f(X):=Xd−∑i=0d−1aiXd∈AG[X]f(X):=X^{d}-\sum_{i=0}^{d-1}a_{i}X^{d}\in{\cal A}_{G}[X]. Obviously xx is a root of f(X)f(X) and as any σ∈G\sigma\in G fixes the coefficients of f(X)f(X) we get that xσx^{\sigma} is also a root of f(X)f(X). Again by Lemma 2.2 we may assume that A{\cal A} is a B{\cal B}-module with {1,x,…xm−1}\{1,x,\ldots x^{m-1}\} as a free basis, where m:=dimBAm:=dim_{\cal B}{\cal A}. Let xm=∑i=0m−1bixix^{m}=\sum_{i=0}^{m-1}b_{i}x^{i} with bi∈Bb_{i}\in{\cal B}, thus xx is a root of the polynomial g(X):=Xm−∑i=0m−1biXi∈B[X]g(X):=X^{m}-\sum_{i=0}^{m-1}b_{i}X^{i}\in{\cal B}[X].

Let us consider f(X)f(X) as a polynomial in B[X]{\cal B}[X]. As g(X)g(X) is monic we can apply the usual polynomial division algorithm to obtain polynomials h(X)h(X) and r[X]r[X] from B(X){\cal B}(X) such that the degree of h(X)h(X) is (d−m)(d-m); the degree of r(X)r(X) is less than mm and f(X)=g(X)h(X)+r(X)f(X)=g(X)h(X)+r(X). We have r(x)=0r(x)=0 which together with the freeness of the basis {1,…,xm−1}\{1,\ldots,x^{m-1}\} implies that r(X)=0r(X)=0 and f(X)=g(X)h(X)f(X)=g(X)h(X). We know from the last paragraph that for all σ∈G\sigma\in G, xσx^{\sigma} is a root of g(X)h(X)g(X)h(X). If neither g(xσ)g(x^{\sigma}) nor h(xσ)h(x^{\sigma}) is zero then we have a pair of zero divisors. If g(xσ)=0g(x^{\sigma})=0 then we can perform the division of g(X)g(X) by (X−xσ)(X-x^{\sigma}) obtaining a polynomial g1(X)∈B[X]g_{1}(X)\in{\cal B}[X] with g(X)=(X−Xσ)g1(X)g(X)=(X-X^{\sigma})g_{1}(X) and can then proceed with a new automorphism σ′∈G\sigma^{\prime}\in G and with g1(X)g_{1}(X) in place of g(X)g(X). In dd rounds we either find a zero divisor in A{\cal A} or two disjoint subsets K,K′K,K^{\prime} of GG with g(X)=∏σ∈K(X−xσ)g(X)=\prod_{\sigma\in K}(X-x^{\sigma}) and h(X)=∏σ′∈K′(X−xσ′)h(X)=\prod_{\sigma^{\prime}\in K^{\prime}}(X-x^{\sigma^{\prime}}). For σ∈K\sigma\in K let ϕσ:B[X]→A\phi_{\sigma}:{\cal B}[X]\rightarrow{\cal A} be the homomorphism which fixes B{\cal B} but sends XX to xσx^{\sigma}. As g(xσ)=0g(x^{\sigma})=0, ϕσ\phi_{\sigma} induces a homomorphism from B[X]/(g(X)){\cal B}[X]/(g(X)) to A{\cal A}, which we denote again by ϕσ\phi_{\sigma}. We know that ϕ1\phi_{1} is actually an isomorphism B[X]/(g(X))≅A{\cal B}[X]/(g(X))\cong{\cal A}, therefore the maps μσ=ϕσ∘ϕ1−1\mu_{\sigma}=\phi_{\sigma}\circ\phi_{1}^{-1} (σ∈K\sigma\in K) are B{\cal B}-endomorphisms of A{\cal A}. Note that we can find a zero divisor in A{\cal A} if any μσ\mu_{\sigma} is not an automorphism, also by Proposition 3.2 we can find a zero divisor in A{\cal A} if the maps μσ\mu_{\sigma} (σ∈K\sigma\in K) generate a non-semiregular group of B{\cal B}-automorphisms of A{\cal A}. Thus, we can assume that μσ\mu_{\sigma}, for all σ∈K\sigma\in K, generate a semiregular group of B{\cal B}-automorphisms of A{\cal A}. As ∣K∣=dimBA|K|=dim_{\cal B}{\cal A} this means, by Lemma 3.1, that the set {μσ∣σ∈K}\{\mu_{\sigma}|\sigma\in K\} is a group say HH. We can as well assume that the group of kk-automorphisms of A{\cal A} generated by GG and HH is semiregular, for otherwise we find a zero divisor in A{\cal A}. Again as ∣G∣=dimkA|G|=dim_{k}{\cal A} this means, by Lemma 3.1, that HH is a subgroup of GG. Thus, by Lemma 3.1, [A:AH]=∣H∣=∣K∣=[A:B][{\cal A}:{\cal A}_{H}]=|H|=|K|=[{\cal A}:{\cal B}] which together with the fact B≤AH{\cal B}\leq{\cal A}_{H} gives AH=B{\cal A}_{H}={\cal B}. As H≤GBH\leq G_{\cal B} we also get H=GBH=G_{\cal B} (if H<GBH<G_{\cal B} then [A:AH]<[{\cal A}:{\cal A}_{H}]< [A:AGB]≤[A:B][{\cal A}:{\cal A}_{G_{\cal B}}]\leq[{\cal A}:{\cal B}] which is a contradiction). Thus, if none of the above steps yield a zero divisor then B=AGB{\cal B}={\cal A}_{G_{\cal B}}. □\Box

Kummer Extensions and Automorphisms of an Algebra over a Finite Field

In classical field theory a field extension LL over kk is called a Kummer extension if kk has, say, an rr-th primitive root of unity and L=k(ar)L=k(\sqrt[r]{a}). Kummer extensions are the building blocks in field theory because they have a cyclic Galois group. In the previous section we developed a notion of semiregular groups to mimic the classical notion of Galois groups, now in this section we extend the classical notion of Kummer extensions to commutative semisimple algebra A{\cal A} over a finite field kk. The properties of Kummer extensions of A{\cal A}, that we prove in the next three subsections, are the reason why we can get polynomial factoring-like results without invoking GRH.

We generalize below several tools and results in field theory, from the seminal paper of Lenstra [L91], to commutative semisimple algebras.

k[ζr]k[\zeta_{r}] and Δr\Delta_{r}: Let kk be a finite field and let rr be a prime different from char kchar\ k. By k[ζr]k[\zeta_{r}] we denote the factor algebra k[X]/(∑i=1r−1Xi)k[X]/(\sum_{i=1}^{r-1}X^{i}) and ζr:=X(mod∑i=1r−1Xi)\zeta_{r}:=X\pmod{\sum_{i=1}^{r-1}X^{i}}. Then k[ζr]k[\zeta_{r}] is an (r−1)(r-1)-dimensional kk-algebra with basis {1,ζr,…,ζrr−2}\{1,\zeta_{r},\ldots,\zeta_{r}^{r-2}\} and for every integer aa coprime to rr, there exists a unique kk-automorphism ρa\rho_{a} of k[ζr]k[\zeta_{r}] which sends ζr\zeta_{r} to ζra\zeta_{r}^{a}. Let Δr\Delta_{r} denote the set of all ρa\rho_{a}’s.

Clearly, Δr\Delta_{r} is a group isomorphic to the multiplicative group of integers modulo rr, therefore it is a cyclic group of order (r−1)(r-1). Note that for r=2r=2, we have ζ2=−1\zeta_{2}=-1, A[ζ2]=A{\cal A}[\zeta_{2}]={\cal A} and Δ2={id}\Delta_{2}=\{id\}.

A[ζr]{\cal A}[\zeta_{r}] and Δr\Delta_{r}: Let A{\cal A} be a commutative semisimple algebra over kk then by A[ζr]{\cal A}[\zeta_{r}] we denote A⊗kk[ζr]{\cal A}\otimes_{k}k[\zeta_{r}]. We consider A{\cal A} as embedded into A[ζr]{\cal A}[\zeta_{r}] via the map x↦x⊗1x\mapsto x\otimes 1 and k[ζr]k[\zeta_{r}] embedded into A[ζr]{\cal A}[\zeta_{r}] via the map x↦1⊗xx\mapsto 1\otimes x. Every element ρa\rho_{a} of the group Δr\Delta_{r} can be extended in a unique way to an automorphism of A[ζr]{\cal A}[\zeta_{r}] which acts as an identity on A{\cal A}. These extended automorphisms of A[ζr]{\cal A}[\zeta_{r}] are also denoted by ρa\rho_{a} and their group by Δr\Delta_{r}.

Note that if A=A1⊕…⊕At{\cal A}={\cal A}_{1}\oplus\ldots\oplus{\cal A}_{t} then A[ζr]=A1[ζr]⊕…⊕At[ζr]{\cal A}[\zeta_{r}]={\cal A}_{1}[\zeta_{r}]\oplus\ldots\oplus{\cal A}_{t}[\zeta_{r}], thus A{\cal A}’s semisimplicity implies that A[ζr]{\cal A}[\zeta_{r}] is semisimple as well. We can also easily see the fixed points in A[ζr]{\cal A}[\zeta_{r}] of Δr\Delta_{r} just like Proposition 4.1 of [L91]:

A[ζr]Δr=A{\cal A}[\zeta_{r}]_{\Delta_{r}}={\cal A}.

Observe that A[ζr]{\cal A}[\zeta_{r}] is a free A{\cal A}-module with basis {ζr,…,ζrr−1}\{\zeta_{r},\ldots,\zeta_{r}^{r-1}\}. As rr is prime this basis is transitively permuted by Δr\Delta_{r}, thus an x=∑i=1r−1aiζri∈A[ζr]x=\sum_{i=1}^{r-1}a_{i}\zeta_{r}^{i}\in{\cal A}[\zeta_{r}] is fixed by Δr\Delta_{r} iff aia_{i}’s are equal iff x∈Ax\in{\cal A}. □\Box

Consider the multiplicative group A[ζr]∗{\cal A}[\zeta_{r}]^{*} of units in A[ζr]{\cal A}[\zeta_{r}].

Sylow subgroup A[ζr]r∗{\cal A}[\zeta_{r}]^{*}_{r}: Let A[ζr]r∗{\cal A}[\zeta_{r}]^{*}_{r} be the rr-elements of A[ζr]∗{\cal A}[\zeta_{r}]^{*}. Note that A[ζr]r∗{\cal A}[\zeta_{r}]^{*}_{r} is of an rr-power size and is also the rr-Sylow subgroup of the group A[ζr]∗{\cal A}[\zeta_{r}]^{*}. Let ∣A[ζr]r∗∣=:rt|{\cal A}[\zeta_{r}]^{*}_{r}|=:r^{t}.

Teichmüller subgroup: Notice that if x∈A[ζr]x\in{\cal A}[\zeta_{r}] has order rur^{u} then xω(a)=xaru−1x^{\omega(a)}=x^{a^{r^{u-1}}}. Thus, ω(a)\omega(a) can be considered as an extension of the map ρa\rho_{a} that raised elements of order rr to the aa-th power. The elements on which the actions of ω(a)\omega(a) and ρa\rho_{a} are the same, for all aa, form the Teichmüller subgroup, TA,rT_{{\cal A},r}, of A[ζr]∗{\cal A}[\zeta_{r}]^{*}:

Note that for r=2r=2, TA,2T_{{\cal A},2} is just the 22-Sylow subgroup of A∗{\cal A}^{*}.

By [L91], Proposition 4.2, if A{\cal A} is a field then TA,rT_{{\cal A},r} is cyclic . We show in the following lemma that, in our general case, given a witness of non-cylicness of TA,rT_{{\cal A},r} we can compute a zero divisor in A{\cal A}.

Given u,v∈TA,ru,v\in T_{{\cal A},r} such that the subgroup generated by uu and vv is not cyclic, we can find a zero divisor in A{\cal A} in deterministic poly(r,log⁡∣A∣)poly(r,\log|{\cal A}|) time.

Suppose the subgroup generated by uu and vv is not cyclic. Then, by Lemma 2.1 we can efficiently find a zero divisor zz, in the semisimple algebra A[ζr]{\cal A}[\zeta_{r}], of the form z=(us−vs′)z=(u^{s}-v^{s^{\prime}}). Next we compute the annihilator ideal II of zz in A[ζr]{\cal A}[\zeta_{r}] and its identity element ee, thus I=eA[ζr]I=e{\cal A}[\zeta_{r}]. If we can show that II is invariant under Δr\Delta_{r} then Δr\Delta_{r} is a group of algebra automorphisms of II which of course would fix the identity element ee of II. Thus, ee is in A[ζr]Δr{\cal A}[\zeta_{r}]_{\Delta_{r}} and hence ee is in A{\cal A} by Lemma 4.1, so we have a zero divisor in A{\cal A}.

Now we show that the annihilator ideal I=eA[ζr]I=e{\cal A}[\zeta_{r}] of zz in A[ζr]{\cal A}[\zeta_{r}] is invariant under Δr\Delta_{r}. By definition ee is an idempotent such that e(us−vs′)=0e(u^{s}-v^{s^{\prime}})=0. Observe that for any a∈{1,…,r−1}a\in\{1,\ldots,r-1\}, we have that (eus)ω(a−1)=(evs′)ω(a−1)(eu^{s})^{\omega(a^{-1})}=(ev^{s^{\prime}})^{\omega(a^{-1})}. Using this together with the fact that us,vs′∈TA,ru^{s},v^{s^{\prime}}\in T_{{\cal A},r} we obtain eρa(us−vs′)=(e((us)ρa−1−(vs′)ρa−1))ρa=(e((us)ω(a−1)−(vs′)ω(a−1)))ρa=((eus)ω(a−1)−(evs′)ω(a−1))ρa=0ρa=0e^{\rho_{a}}(u^{s}-v^{s^{\prime}})=(e((u^{s})^{\rho_{a}^{-1}}-(v^{s^{\prime}})^{\rho_{a}^{-1}}))^{\rho_{a}}=(e((u^{s})^{\omega(a^{-1})}-(v^{s^{\prime}})^{\omega(a^{-1})}))^{\rho_{a}}=((eu^{s})^{\omega(a^{-1})}-(ev^{s^{\prime}})^{\omega(a^{-1})})^{\rho_{a}}=0^{\rho_{a}}=0. Thus, for all a∈{1,…,r−1}a\in\{1,\ldots,r-1\}, eρa∈Ie^{\rho_{a}}\in I which means that II is invariant under Δr\Delta_{r}. □\Box

Now we are in a position to define what we call Kummer extension of an algebra A{\cal A}.

Kummer extension A[ζr][cs]{\cal A}[\zeta_{r}][\sqrt[s]{c}]: For c∈A[ζr]∗c\in{\cal A}[\zeta_{r}]^{*} and a power ss of rr, by A[ζr][cs]{\cal A}[\zeta_{r}][\sqrt[s]{c}] we denote the factor algebra A[ζr][Y]/(Ys−c){\cal A}[\zeta_{r}][Y]/(Y^{s}-c) and cs:=Y(modYs−c)\sqrt[s]{c}:=Y\pmod{Y^{s}-c}.

Remark. Given c,c1∈TA,rc,c_{1}\in T_{{\cal A},r} such that the order of cc is greater than or equal to the order of c1c_{1} and c1c_{1} is not a power of cc, by Lemma 4.2, we can find a zero divisor in A{\cal A} in poly(r,log⁡∣A∣)poly(r,\log|{\cal A}|) time. Therefore, the really interesting Kummer extensions are of the form A[ζr][cs]{\cal A}[\zeta_{r}][\sqrt[s]{c}], where c∈TA,rc\in T_{{\cal A},r} and ζr\zeta_{r} is a power of cs\sqrt[s]{c}.

Clearly, A[ζr][cs]{\cal A}[\zeta_{r}][\sqrt[s]{c}] is a free A[ζr]{\cal A}[\zeta_{r}]-module of rank ss with basis {1,cs,…,css−1}\{1,\sqrt[s]{c},\ldots,\sqrt[s]{c}^{s-1}\}. If c∈TA,rc\in T_{{\cal A},r} then cs\sqrt[s]{c} is an rr-element of A[ζr][cs]∗{\cal A}[\zeta_{r}][\sqrt[s]{c}]^{*} and for any integer aa coprime to rr, we now identify an automorphism of the Kummer extension. Extending [L91], Proposition 4.3, we obtain:

Let c∈TA,rc\in T_{{\cal A},r}. Then we can extend every ρa∈Δr\rho_{a}\in\Delta_{r} to a unique automorphism of A[ζr][cs]{\cal A}[\zeta_{r}][\sqrt[s]{c}] that sends cs\sqrt[s]{c} to (cs)ω(a)(\sqrt[s]{c})^{\omega(a)}.

We saw above automorphisms of the Kummer extension A[ζr][cs]{\cal A}[\zeta_{r}][\sqrt[s]{c}] that fixed A{\cal A}. When s=rs=r we can also identify automorphisms that fix A[ζr]{\cal A}[\zeta_{r}]:

Let c∈TA,rc\in T_{{\cal A},r} and Δr\Delta_{r} be the automorphisms of A[ζr][cs]{\cal A}[\zeta_{r}][\sqrt[s]{c}] identified in Lemma 4.3. Then there is a unique automorphism σ\sigma of A[ζr][cr]{\cal A}[\zeta_{r}][\sqrt[r]{c}] such that: (1) σ\sigma fixes A[ζr]{\cal A}[\zeta_{r}] and maps cr\sqrt[r]{c} to ζrcr\zeta_{r}\sqrt[r]{c}. (2) σ\sigma commutes with the action of Δr\Delta_{r}. (3) σ\sigma is a semiregular automorphism of A[ζr][cr]Δr{\cal A}[\zeta_{r}][\sqrt[r]{c}]_{\Delta_{r}} of order rr and (A[ζr][cr]Δr)σ=A({\cal A}[\zeta_{r}][\sqrt[r]{c}]_{\Delta_{r}})_{\sigma}={\cal A}.

The map fixing A[ζr]{\cal A}[\zeta_{r}] and mapping YY to ζrY\zeta_{r}Y is clearly an automorphism of A[ζr][Y]/{\cal A}[\zeta_{r}][Y]/ (Yr−c)(Y^{r}-c). Thus implying the existence and uniqueness of σ\sigma.

Let ρa∈Δr\rho_{a}\in\Delta_{r} be an automorphism of A[ζr][cr]{\cal A}[\zeta_{r}][\sqrt[r]{c}]. Clearly, the action of σ\sigma and ρa\rho_{a} is commutative on any element x∈A[ζr]x\in{\cal A}[\zeta_{r}]. Also, (cr)σρa=(ζrcr)ρa=(ζrcr)ω(a)=ζrω(a)(cr)ω(a)=((cr)ω(a))σ=(cr)ρaσ(\sqrt[r]{c})^{\sigma\rho_{a}}=(\zeta_{r}\sqrt[r]{c})^{\rho_{a}}=(\zeta_{r}\sqrt[r]{c})^{\omega(a)}=\zeta_{r}^{\omega(a)}(\sqrt[r]{c})^{\omega(a)}=((\sqrt[r]{c})^{\omega(a)})^{\sigma}=(\sqrt[r]{c})^{\rho_{a}\sigma}. This implies the commutativity of the actions of σ\sigma and Δr\Delta_{r} on A[ζr][cr]{\cal A}[\zeta_{r}][\sqrt[r]{c}].

From commutativity it follows that (A[ζr][cr]Δr)σ=A[ζr][cr]Δr({\cal A}[\zeta_{r}][\sqrt[r]{c}]_{\Delta_{r}})^{\sigma}={\cal A}[\zeta_{r}][\sqrt[r]{c}]_{\Delta_{r}}, thus σ\sigma is an automorphism of A[ζr][cr]Δr{\cal A}[\zeta_{r}][\sqrt[r]{c}]_{\Delta_{r}}. Let GG be the group generated by Δr\Delta_{r} and σ\sigma. Then GG is a commutative group of order r(r−1)r(r-1). As A[ζr][cr]G=(A[ζr][cr]σ)Δr=A[ζr]Δr=A{\cal A}[\zeta_{r}][\sqrt[r]{c}]_{G}=({\cal A}[\zeta_{r}][\sqrt[r]{c}]_{\sigma})_{\Delta_{r}}={\cal A}[\zeta_{r}]_{\Delta_{r}}={\cal A}, Lemma 3.1 implies that GG is semiregular on A[ζr][cr]{\cal A}[\zeta_{r}][\sqrt[r]{c}]. But then the subgroup Δr\Delta_{r} is semiregular as well and by Lemma 3.1: dim⁡kA[ζr][cr]Δr=dim⁡kA[ζr][cr]/∣Δr∣=rdim⁡kA=∣(σ)∣dim⁡kA\dim_{k}{\cal A}[\zeta_{r}][\sqrt[r]{c}]_{\Delta_{r}}=\dim_{k}{\cal A}[\zeta_{r}][\sqrt[r]{c}]/|\Delta_{r}|=r\dim_{k}{\cal A}=|(\sigma)|\dim_{k}{\cal A}. This again implies that σ\sigma is a semiregular automorphism of A[ζr][cr]Δr{\cal A}[\zeta_{r}][\sqrt[r]{c}]_{\Delta_{r}}. □\Box

In this subsection we show how to express A[ζr]{\cal A}[\zeta_{r}] as a Kummer extension of Aτ{\cal A}_{\tau} given a semiregular τ∈Autk(A)\tau\in Aut_{k}({\cal A}) of order rr. The Lagrange resolvent technique of [Ró87] remains applicable in our context as well and leads to the following:

Given a commutative semisimple algebra A{\cal A} over a finite field kk, a kk- automorphism τ\tau of A{\cal A} of prime order r≠char kr\not=char\ k and a root ξ∈Aτ\xi\in{\cal A}_{\tau} of the cyclotomic polynomial Xr−1X−1\frac{X^{r}-1}{X-1}. We can find in deterministic poly(r,log⁡∣A∣)poly(r,\log|{\cal A}|) time a nonzero x∈Ax\in{\cal A} such that xτ=ξxx^{\tau}=\xi x.

Observe that if ξ∈A\xi\in{\cal A} is a root of 1+X+…+Xr−11+X+\ldots+X^{r-1} then so is every power ξi    (i=1,…,r−1)\xi^{i}\;\;(i=1,\ldots,r-1). Take an element y∈A∖Aτy\in{\cal A}\setminus{\cal A}_{\tau} and compute the Lagrange-resolvents for 0≤j≤r−10\leq j\leq r-1:

It is easy to see that (y,ξ0)=y+yτ+…+yτr−1∈Aτ(y,\xi^{0})=y+y^{\tau}+\ldots+y^{\tau^{r-1}}\in{\cal A}_{\tau} as τr=id\tau^{r}=id, while ∑j=0r−1(y,ξj)=ry+∑i=1r−1∑j=0r−1ξijyτi=ry+∑i=1r−1yτi∑j=0r−1(ξi)j=ry∉Aτ\sum_{j=0}^{r-1}(y,\xi^{j})=ry+\sum_{i=1}^{r-1}\sum_{j=0}^{r-1}\xi^{ij}y^{\tau^{i}}=ry+\sum_{i=1}^{r-1}y^{\tau^{i}}\sum_{j=0}^{r-1}(\xi^{i})^{j}=ry\not\in{\cal A}_{\tau}. It follows that for some 1≤j≤(r−1)1\leq j\leq(r-1), (y,ξj)∉Aτ(y,\xi^{j})\not\in{\cal A}_{\tau}, fix this jj. In particular, (y,ξj)≠0(y,\xi^{j})\not=0 and taking l:=(−j)−1(modr)l:=(-j)^{-1}\pmod{r} we find x:=(y,ξj)lx:=(y,\xi^{j})^{l} is also nonzero as commutative semisimple algebras do not contain nilpotent elements. This xx is then the element promised in the claim as: xτ=((y,ξj)τ)l=(ξ−j(y,ξj))l=ξx.x^{\tau}=((y,\xi^{j})^{\tau})^{l}=(\xi^{-j}(y,\xi^{j}))^{l}=\xi x. □\Box

We now proceed to describe an algorithm that given a kk-automorphism τ\tau of A{\cal A} of prime order rr, expresses A[ζr]{\cal A}[\zeta_{r}] as a Kummer extension of Aτ{\cal A}_{\tau}.

Embedding Autk(A)Aut_{k}({\cal A}) in Autk(A[ζr])Aut_{k}({\cal A}[\zeta_{r}]): Given a semiregular automorphism τ\tau of A{\cal A} we extend τ\tau to an automorphism of A[ζr]{\cal A}[\zeta_{r}] by letting ζrτ:=ζr\zeta_{r}^{\tau}:=\zeta_{r}. It is easy to see that the extension (denoted again by τ\tau) is a semiregular automorphism of A[ζr]{\cal A}[\zeta_{r}] as well and it commutes with Δr\Delta_{r}.

Application of Lemma 4.5, techniques from [L91] and a careful treatment of cases when we find zero divisors, give the following.

Given a commutative semisimple algebra A{\cal A} over a finite field kk together with a semiregular kk-automorphism τ\tau of A{\cal A} of prime order r≠char kr\not=char\ k, we can find in deterministic poly(log⁡∣A∣)poly(\log|{\cal A}|) time an element x∈TA,rx\in T_{{\cal A},r} such that xτ=ζrxx^{\tau}=\zeta_{r}x.

Any such xx satisfies c:=xr∈TAτ,rc:=x^{r}\in T_{{\cal A}_{\tau},r} and defines an isomorphism ϕ:Aτ[ζr][cr]≅A[ζr]\phi:{\cal A}_{\tau}[\zeta_{r}][\sqrt[r]{c}]\cong{\cal A}[\zeta_{r}] which fixes Aτ[ζr]{\cal A}_{\tau}[\zeta_{r}]. Also ϕ\phi commutes with the action of Δr\Delta_{r}, therefore inducing an isomorphism (Aτ[ζr][cr])Δr≅A({\cal A}_{\tau}[\zeta_{r}][\sqrt[r]{c}])_{\Delta_{r}}\cong{\cal A}.

The proof idea is to first apply Lemma 4.5 to find a nonzero x∈A[ζr]x\in{\cal A}[\zeta_{r}] such that xτ=ζrxx^{\tau}=\zeta_{r}x. Note that this xx maybe a zero divisor of A[ζr]{\cal A}[\zeta_{r}], in that case we intend to decompose A[ζr]{\cal A}[\zeta_{r}] as much as possible and apply Lemma 4.5 to each of these components. This process is repeated till it yields an y∈A[ζr]∗y\in{\cal A}[\zeta_{r}]^{*} such that yτ=ζryy^{\tau}=\zeta_{r}y. Secondly, this yy is used to form the xx and ϕ\phi as promised in the claim.

We maintain: a decomposition of the identity element 1=1A[ζr]=1A1=1_{{\cal A}[\zeta_{r}]}=1_{\cal A} into orthogonal idempotents e,fe,f that are fixed by τ\tau; and an element y∈(fA[ζr])∗y\in(f{\cal A}[\zeta_{r}])^{*} such that yτ=ζryy^{\tau}=\zeta_{r}y (for f=0f=0 we define (fA[ζr])∗(f{\cal A}[\zeta_{r}])^{*} as (0)(0)). Initially, we take e=1,  f=0,  y=0e=1,\;f=0,\;y=0. Since τ\tau is semiregular its restriction to eA[ζr]e{\cal A}[\zeta_{r}] has to be nontrivial (as long as e≠0e\not=0) and hence of prime order rr. Therefore we can apply Lemma 4.5 with ξ=eζr\xi=e\zeta_{r} to find a nonzero x∈eA[ζr]x\in e{\cal A}[\zeta_{r}] such that xτ=(eζr)x=ζrxx^{\tau}=(e\zeta_{r})x=\zeta_{r}x. Now compute the identity element e1e_{1} of xA[ζr]x{\cal A}[\zeta_{r}] (which is an ideal of eA[ζr]e{\cal A}[\zeta_{r}]). Note that xA[ζr]x{\cal A}[\zeta_{r}] is invariant under τ\tau since for all z∈A[ζr]z\in{\cal A}[\zeta_{r}], (xz)τ=xτzτ=ζrxzτ∈xA[ζr](xz)^{\tau}=x^{\tau}z^{\tau}=\zeta_{r}xz^{\tau}\in x{\cal A}[\zeta_{r}]. This makes τ\tau an automorphism of xA[ζr]x{\cal A}[\zeta_{r}] and so τ\tau fixes the identity element e1e_{1}. We could now replace ee with (e−e1)(e-e_{1}), ff with (f+e1)(f+e_{1}), yy with (x+y)(x+y) and repeat the above steps. Note that the above one iteration decomposed eA[ζr]e{\cal A}[\zeta_{r}] into orthogonal components (e−e1)A[ζr](e-e_{1}){\cal A}[\zeta_{r}] and e1A[ζr]e_{1}{\cal A}[\zeta_{r}] and thus the procedure has to stop in at most dim⁡kA[ζr]\dim_{k}{\cal A}[\zeta_{r}] rounds with e=0e=0.

Let us define the map ϕ\phi from Aτ[ζr][cr]{\cal A}_{\tau}[\zeta_{r}][\sqrt[r]{c}] to A[ζr]{\cal A}[\zeta_{r}] as the one that sends cr\sqrt[r]{c} to xx and fixes Aτ[ζr]{\cal A}_{\tau}[\zeta_{r}]. It is obvious from c=xrc=x^{r} that ϕ\phi is a homomorphism. If ϕ\phi maps an element ∑i=0r−1ai(cr)i\sum_{i=0}^{r-1}a_{i}(\sqrt[r]{c})^{i} to zero then ∑i=0r−1aixi=0\sum_{i=0}^{r-1}a_{i}x^{i}=0. Applying τ\tau on this jj times gives ∑i=0r−1aiζrijxi=0\sum_{i=0}^{r-1}a_{i}\zeta_{r}^{ij}x^{i}=0 (remember τ\tau fixes Aτ[ζr]{\cal A}_{\tau}[\zeta_{r}] and hence aia_{i}’s). Summing these equations for all 0≤j≤(r−1)0\leq j\leq(r-1) we get a0=0a_{0}=0, as xx is invertible this means that ϕ\phi maps ∑i=1r−1aixi−1\sum_{i=1}^{r-1}a_{i}x^{i-1} to zero. We can now repeat the argument and deduce that aia_{i}’s are all zero, thus ϕ\phi is injective. Using that x∈TA,rx\in T_{{\cal A},r}, it is also straightforward to verify that ϕ\phi commutes with Δr\Delta_{r} (viewed as automorphisms of A[ζr][cr]{\cal A}[\zeta_{r}][\sqrt[r]{c}]). Thus it remains to show that ϕ\phi is surjective. To this end let B{\cal B} denote the image of ϕ\phi. Then B{\cal B} is the subalgebra of A[ζr]{\cal A}[\zeta_{r}] generated by Aτ[ζr]{\cal A}_{\tau}[\zeta_{r}] and xx, thus B{\cal B} is τ\tau-invariant. Suppose we can show τ\tau semiregular on B{\cal B}. Then by Lemma 3.1, dim⁡kB=rdim⁡kBτ\dim_{k}{\cal B}=r\dim_{k}{\cal B}_{\tau}, this together with Bτ{\cal B}_{\tau} containing Aτ[ζr]{\cal A}_{\tau}[\zeta_{r}] and the injectivity of ϕ\phi means that dim⁡kB≥rdim⁡kAτ[ζr]=rdim⁡kA[ζr]τ\dim_{k}{\cal B}\geq r\dim_{k}{\cal A}_{\tau}[\zeta_{r}]=r\dim_{k}{\cal A}[\zeta_{r}]_{\tau} which is further equal to dim⁡kA[ζr]\dim_{k}{\cal A}[\zeta_{r}] as τ\tau is semiregular on A[ζr]{\cal A}[\zeta_{r}]. Thus, dim⁡kB≥dim⁡kA[ζr]\dim_{k}{\cal B}\geq\dim_{k}{\cal A}[\zeta_{r}] which obviously means that ϕ\phi is indeed surjective.

It remains to prove the semiregularity of τ\tau on B{\cal B}. Assume for contradiction that II is a nonzero ideal of B{\cal B} such that τ\tau fixes II and ee be the identity element of II. Then (ex)τ=ex(ex)^{\tau}=ex. On the other hand, as eτ=ee^{\tau}=e and xτ=ζrxx^{\tau}=\zeta_{r}x, we have (ex)τ=ζrex(ex)^{\tau}=\zeta_{r}ex. Combining the two equalities we obtain that (ex)(ζr−1)=0(ex)(\zeta_{r}-1)=0. Note that if r=2r=2 then char k>2char\ k>2 and (ζr−1)(\zeta_{r}-1) is not a zero divisor and if r>2r>2 then A[ζr]{\cal A}[\zeta_{r}] is a free A{\cal A}-module with basis {1,…,ζrr−2}\{1,\ldots,\zeta_{r}^{r-2}\}. Thus, x(ζr−1)x(\zeta_{r}-1) is invertible in all cases, implying e=0e=0 which is a contradiction. Thus τ\tau is indeed semiregular on B{\cal B} completing the proof that ϕ\phi is an isomorphism. □\Box

3 Zero Divisors using Noncyclic Groups: Proof of Application 2

In this part we prove Application 2 by proving the following stronger result.

Given a commutative semisimple algebra A{\cal A} over a finite field kk together with a noncyclic group GG of kk-automorphisms of A{\cal A} (in terms of generators), one can find a zero divisor in A{\cal A} in deterministic polynomial time.

Notice that since GG is noncyclic, the algebra A{\cal A} is certainly not a field and zero divisors do exist. We assume that GG is semiregular otherwise we can efficiently find a zero divisor in A{\cal A} by Proposition 3.2. We can also assume that ∣G∣|G| is not divisible by char kchar\ k otherwise char k≤∣G∣≤dim⁡kAchar\ k\leq|G|\leq\dim_{k}{\cal A} and Berlekamp’s deterministic algorithm for polynomial factoring can be used to find all the simple components of A{\cal A}.

As GG is a small group of size dim⁡kA\dim_{k}{\cal A}, we can list all its elements of prime order. The proof now proceeds by analyzing the Sylow subgroups of GG and showing them all cyclic unless they yield a zero divisor of A{\cal A}. For every prime divisor rr of ∣G∣|G| let Πr\Pi_{r} be the set of elements of GG of order rr and let PrP_{r} be an rr-Sylow subgroup of GG. For every σ∈Πr\sigma\in\Pi_{r} we can use Proposition 4.6 to compute an element xσ∈TA,rx_{\sigma}\in T_{{\cal A},r} with xσσ=ζrxσx_{\sigma}^{\sigma}=\zeta_{r}x_{\sigma}. Let HrH_{r} be the subgroup of TA,rT_{{\cal A},r} generated by {xσ∣σ∈Πr}\{x_{\sigma}|\sigma\in\Pi_{r}\}.

We can assume HrH_{r} to be cyclic or else we can find a zero divisor in A{\cal A} by Lemma 4.2. So choose an element x∈{xσ∣σ∈Πr}x\in\{x_{\sigma}|\sigma\in\Pi_{r}\} such that xx is a generator of HrH_{r}. Now for any σ∈G\sigma\in G, as xσx^{\sigma} is again in TA,rT_{{\cal A},r}, we can assume xσ∈Hrx^{\sigma}\in H_{r} for otherwise we can find a zero divisor by Lemma 4.2. Thus, HrH_{r} is GG-invariant and GG acts as a group of automorphisms of HrH_{r}. As every element of PrP_{r} of order rr moves some element in HrH_{r}, there is no nontrivial element of PrP_{r} acting trivially on HrH_{r}, thus PrP_{r} intersects trivially with the kernel KrK_{r} of the restriction homomorphism G→Aut(Hr)G\rightarrow Aut(H_{r}). Since HrH_{r} is cyclic, its automorphism group is Abelian. The last two observations imply that G/KrG/K_{r} is an Abelian group with a natural embedding of Pr→G/Kr≅Aut(Hr)P_{r}\rightarrow G/K_{r}\cong Aut(H_{r}). Thus the normal series Kr⊲GK_{r}\lhd G can be refined to Kr⊴Nr⊲GK_{r}\unlhd N_{r}\lhd G such that ∣Pr∣=∣G/Nr∣|P_{r}|=|G/N_{r}|. Since we have this for every rr dividing ∣G∣|G|, it follows that GG is a direct product of its Sylow subgroups. Also, as each PrP_{r} is Abelian, GG is Abelian. Moreover, since the automorphism group of a cyclic group of odd prime-power order is cyclic, Aut(Hr)Aut(H_{r}) is cyclic and finally PrP_{r} is cyclic, for every odd prime r∣∣G∣r||G|.

Rational polynomials known to have small but noncommutative Galois groups also emerge in various branches of mathematics and its applications. For example, the six roots of the polynomial Fj(X)=(X2−X+1)3−j28X2(X−1)2F_{j}(X)=(X^{2}-X+1)^{3}-\frac{j}{2^{8}}X^{2}(X-1)^{2} are the possible parameters λ\lambda of the elliptic curves from the Legendre family EλE_{\lambda} having prescribed jj-invariant jj, see [Hu86]. (Recall that the curve EλE_{\lambda} is defined by the equation Y2=X(X−1)(X−λ)Y^{2}=X(X-1)(X-\lambda).) The Galois group of Fj(X)F_{j}(X) is S3S_{3}, whence Theorem 4.7 gives a partial factorization of the polynomial Fj(X)F_{j}(X) modulo pp where pp is odd and jj is coprime to pp.

Given a commutative semisimple algebra A{\cal A} over a finite field kk, a kk- automorphism τ\tau of A{\cal A} and a kk-automorphism μ\mu of Aτ{\cal A}_{\tau}. Assume that the order of τ\tau is coprime to char kchar\ k. Then in deterministic poly(log⁡∣A∣)poly(\log|{\cal A}|) time we can compute either a zero divisor in A{\cal A} or a kk-automorphism μ′\mu^{\prime} of A{\cal A} that extends μ\mu such that Aμ′=(Aτ)μ{\cal A}_{\mu^{\prime}}=({\cal A}_{\tau})_{\mu}.

5 Zero Divisors using Galois Groups: Proof of Application 3

Assume that we are given a semiregular group GG of automorphisms of a commutative semisimple algebra A{\cal A} over a finite field kk with AG=k{\cal A}_{G}=k and a nonzero ideal B{\cal B} (with kk embedded) of a subalgebra of A{\cal A}. Then in deterministic poly(log⁡∣A∣)poly(\log|{\cal A}|) time we can either find a zero divisor in B{\cal B} or a semiregular kk-automorphism σ\sigma of B{\cal B} of order dim⁡kB\dim_{k}{\cal B}.

Remark. Here B{\cal B} is an ideal of a subalgebra of A{\cal A}, thus it is not assumed that 1A∈B1_{\cal A}\in{\cal B}.

The idea of the algorithm is to find a nontrivial ideal II of A{\cal A} and then reduce the problem to the smaller instance II.

If GG is noncyclic then using Theorem 4.7 we can find a nontrivial ideal II of A{\cal A}. If GG is cyclic then using Proposition 3.3 we can find either a nontrivial ideal II of A{\cal A} or a subgroup HH of GG with B=AH{\cal B}={\cal A}_{H}. In the latter case HH is trivially a normal subgroup of GG and the restriction of any generator σ\sigma of GG will generate a semiregular group, of kk-automorphisms of B{\cal B}, isomorphic to G/HG/H. Thus, we get a semiregular kk-automorphism of B{\cal B} of order ∣G/H∣=dim⁡kB|G/H|=\dim_{k}{\cal B}.

Let us assume we have a nontrivial ideal II of A{\cal A}. Then, using the method of Lemma 2.3, we find an ideal JJ of A{\cal A} such that the ideals {Jσ∣σ∈G}\{J^{\sigma}|\sigma\in G\} are pairwise orthogonal or equal. By the hypothesis AG=k{\cal A}_{G}=k, GG acts transitively on the minimal ideals of A{\cal A}, thus the group G1:={σ∈G∣Jσ=J}G_{1}:=\{\sigma\in G|J^{\sigma}=J\} acts semiregularly on JJ and for coset representatives CC of G/G1G/G_{1}: A=⊕σ∈CJσ{\cal A}=\oplus_{\sigma\in C}J^{\sigma}. Also, note that for all σ∈C\sigma\in C the conjugate subgroup G1σ:=σ−1G1σG_{1}^{\sigma}:=\sigma^{-1}G_{1}\sigma acts semiregularly on JσJ^{\sigma}. We can find a zero divisor in B{\cal B} if the projection of B{\cal B} to some JσJ^{\sigma} is neither the zero map nor injective. Thus we assume that there is an ideal JσJ^{\sigma} such that the projection of A{\cal A} onto JσJ^{\sigma} injectively embeds B{\cal B}. In that case we reduce our original problem to the smaller instance – JσJ^{\sigma} instead of A{\cal A}, G1σG_{1}^{\sigma} instead of GG and the embedding of B{\cal B} instead of B{\cal B} – and apply the steps of the last paragraph. □\Box

The following Corollary gives the proof of a slightly stronger version of Application 3.

Finding Automorphisms of Algebras via Kummer Extensions

In this section we complete the proof of our main Theorem, i.e. given a commutative semisimple algebra A{\cal A} over a finite field kk we can unconditionally find a nontrivial kk-automorphism of A{\cal A} in deterministic subexponential time. The proof involves computing tensor powers of A{\cal A}, whose automorphisms we know, and then bringing down those automorphisms to A{\cal A}. Before embarking on the proof we need to first see how to bring down automorphisms using Kummer extensions; and define notions related to tensor powers of A{\cal A}.

We do this by using Kummer extensions, so we first show how to embed a Kummer extension of A{\cal A} into the cyclotomic extension of D{\cal D}.

Let A≤D{\cal A}\leq{\cal D} be commutative semisimple algebras over a finite field kk and let r≠char kr\not=char\ k be a prime. Then for any x∈TD,r∖A[ζr]x\in T_{{\cal D},r}\setminus{\cal A}[\zeta_{r}] satisfying c:=xr∈A[ζr]c:=x^{r}\in{\cal A}[\zeta_{r}], there is a unique ring homomorphism ϕ:A[ζr][cr]→D[ζr]\phi:{\cal A}[\zeta_{r}][\sqrt[r]{c}]\rightarrow{\cal D}[\zeta_{r}] that fixes A[ζr]{\cal A}[\zeta_{r}], maps cr\sqrt[r]{c} to xx and: (1) ϕ\phi commutes with the action of Δr\Delta_{r}, thus ϕ(A[ζr][cr]Δr)⊆D\phi({\cal A}[\zeta_{r}][\sqrt[r]{c}]_{\Delta_{r}})\subseteq{\cal D}. (2) ϕ\phi is injective if and only if its restriction to A[ζr][cr]Δr{\cal A}[\zeta_{r}][\sqrt[r]{c}]_{\Delta_{r}} is injective. (3) If ϕ\phi is not injective then we can find a zero divisor of D{\cal D} in deterministic polynomial time .

The existence and uniqueness of the homomorphism ϕ\phi are obvious: the map from A[ζr][X]{\cal A}[\zeta_{r}][X] to D[ζr]{\cal D}[\zeta_{r}] which sends XX to xx factors through A[ζr][cr]{\cal A}[\zeta_{r}][\sqrt[r]{c}].

As x∈TD,rx\in T_{{\cal D},r}, for every ρa∈Δr\rho_{a}\in\Delta_{r} we have ϕ((cr)ρa)=ϕ((cr)ω(a))=xω(a)=(ϕ(cr))ρa\phi((\sqrt[r]{c})^{\rho_{a}})=\phi((\sqrt[r]{c})^{\omega(a)})=x^{\omega(a)}=(\phi(\sqrt[r]{c}))^{\rho_{a}}. On the other hand, for every u∈A[ζr]u\in{\cal A}[\zeta_{r}] we have ϕ(u)ρa=uρa=ϕ(uρa)\phi(u)^{\rho_{a}}=u^{\rho_{a}}=\phi(u^{\rho_{a}}). As A[ζr]{\cal A}[\zeta_{r}] and (cr)(\sqrt[r]{c}) generate A[ζr][cr]{\cal A}[\zeta_{r}][\sqrt[r]{c}], the two equalities above prove that ϕ\phi commutes with the action of Δr\Delta_{r}. As a consequence, ϕ(A[ζr][cr]Δr)⊆D[ζr]Δr=D\phi({\cal A}[\zeta_{r}][\sqrt[r]{c}]_{\Delta_{r}})\subseteq{\cal D}[\zeta_{r}]_{\Delta_{r}}={\cal D}.

Since the elements ζr0,…,ζrr−2\zeta_{r}^{0},\ldots,\zeta_{r}^{r-2} form a free basis of D[ζr]{\cal D}[\zeta_{r}] as a D{\cal D}-module, the subspaces ζriD\zeta_{r}^{i}{\cal D} of D[ζr]{\cal D}[\zeta_{r}] (i=0,…,r−2i=0,\ldots,r-2) are independent over kk. This means the images ϕ(ζri(A[ζr][cr]Δr))\phi(\zeta_{r}^{i}({\cal A}[\zeta_{r}][\sqrt[r]{c}]_{\Delta_{r}})) are independent as well thus, dim⁡kϕ(A[ζr][cr])=(r−1)dim⁡kϕ(\dim_{k}\phi({\cal A}[\zeta_{r}][\sqrt[r]{c}])=(r-1)\dim_{k}\phi( A[ζr][cr]Δr){\cal A}[\zeta_{r}][\sqrt[r]{c}]_{\Delta_{r}}). This together with the fact dim⁡kA[ζr][cr]=(r−1)dim⁡kA[ζr][cr]Δr\dim_{k}{\cal A}[\zeta_{r}][\sqrt[r]{c}]=(r-1)\dim_{k}{\cal A}[\zeta_{r}][\sqrt[r]{c}]_{\Delta_{r}} means that ϕ\phi is injective if and only if its restriction to A[ζr][cr]Δr{\cal A}[\zeta_{r}][\sqrt[r]{c}]_{\Delta_{r}} is.

To see the last assertion assume that ϕ\phi, and hence its restriction to C:=A[ζr][cr]Δr{\cal C}:={\cal A}[\zeta_{r}][\sqrt[r]{c}]_{\Delta_{r}}, is not injective. We compute the kernel II of ϕ∣C\phi|_{\cal C}, clearly II is a nonzero ideal of C{\cal C}. Let σ\sigma be the semiregular kk-automorphism of C{\cal C} investigated in Proposition 4.4, which also tells us that dim⁡kC=rdim⁡kA\dim_{k}{\cal C}=r\dim_{k}{\cal A}. Assume that ϕ(C)=:D′\phi({\cal C})=:{\cal D}^{\prime}. We compute J:={u∈C∣uI=0}J:=\{u\in{\cal C}|uI=0\}, the ideal complementary to II so that C=I⊕J{\cal C}=I\oplus J. Note that by the definition of II, the restriction of ϕ\phi to JJ yields an isomorphism J≅D′J\cong{\cal D}^{\prime}. Hence finding a zero divisor in JJ implies finding a zero divisor in D{\cal D}. Let eJe_{J} be the identity element of JJ, then as ϕ\phi fixes A{\cal A}, for all a∈Aa\in{\cal A}, a=ϕ(a)=ϕ(eJa)a=\phi(a)=\phi(e_{J}a), in other words ϕ\phi induces an isomorphism eJA≅Ae_{J}{\cal A}\cong{\cal A}. Using this we now show that the action of σ\sigma on JJ yields a zero divisor in JJ.

Firstly, we claim that for all 1≤i≤(r−1)1\leq i\leq(r-1), J≠JσiJ\not=J^{\sigma^{i}}. Suppose for some 1≤i≤(r−1)1\leq i\leq(r-1), Jσi=JJ^{\sigma^{i}}=J and σi\sigma^{i} fixes JJ, then J⊆Cσi=AJ\subseteq{\cal C}_{\sigma^{i}}={\cal A}. This together with the fact that ϕ−1\phi^{-1} injectively embeds A{\cal A} in JJ gives J=AJ={\cal A}, which implies that ϕ(C)=A\phi({\cal C})={\cal A}, thus ϕ(A[ζr][cr])=ϕ(C[ζr])=A[ζr]\phi({\cal A}[\zeta_{r}][\sqrt[r]{c}])=\phi({\cal C}[\zeta_{r}])={\cal A}[\zeta_{r}] contradicting x∉A[ζr]x\not\in{\cal A}[\zeta_{r}]. The other case then is: for some 1≤i≤(r−1)1\leq i\leq(r-1), Jσi=JJ^{\sigma^{i}}=J and the restriction of σi\sigma^{i} to JJ is a semiregular automorphism of order rr of JJ, therefore dim⁡kJ=rdim⁡kJσi≥rdim⁡keJA=rdim⁡kA\dim_{k}J=r\dim_{k}J_{\sigma^{i}}\geq r\dim_{k}e_{J}{\cal A}=r\dim_{k}{\cal A} (as σi\sigma^{i} fixes A{\cal A} it has to fix eJAe_{J}{\cal A}), which contradicts to dim⁡kJ<dim⁡kC=rdim⁡kA\dim_{k}J<\dim_{k}{\cal C}=r\dim_{k}{\cal A}. Secondly, we claim that for some i∈{1,…,r−1}i\in\{1,\ldots,r-1\}, J∩Jσi≠0J\cap J^{\sigma^{i}}\not=0. Indeed, assuming the contrary, we would have Jσj∩Jσi=(J∩Jσi−j)σj=0J^{\sigma^{j}}\cap J^{\sigma^{i}}=(J\cap J^{\sigma^{i-j}})^{\sigma^{j}}=0 whenever i≢j(modr)i\not\equiv j\pmod{r}, whence the JσiJ^{\sigma^{i}} would be pairwise orthogonal ideals, whence dim⁡kJ=1rdim⁡k∑t=0r−1Jσt≤1rdim⁡kC=dim⁡kA\dim_{k}J={\frac{1}{r}}\dim_{k}\sum_{t=0}^{r-1}J^{\sigma^{t}}\leq{\frac{1}{r}}\dim_{k}{\cal C}=\dim_{k}{\cal A}. This together with the fact that ϕ−1\phi^{-1} injectively embeds A{\cal A} in JJ gives J=AJ={\cal A}, which implies that ϕ(C)=A\phi({\cal C})={\cal A}, thus ϕ(A[ζr][cr])=ϕ(C[ζr])=A[ζr]\phi({\cal A}[\zeta_{r}][\sqrt[r]{c}])=\phi({\cal C}[\zeta_{r}])={\cal A}[\zeta_{r}] contradicting x∉A[ζr]x\not\in{\cal A}[\zeta_{r}].

From the above two claims we get an i∈{1,…,r−1}i\in\{1,\ldots,r-1\}, for which J≠JσiJ\not=J^{\sigma^{i}} and J∩Jσi≠0J\cap J^{\sigma^{i}}\not=0, whence by the method of Lemma 2.3 we get a zero divisor of JJ, thus finishing the proof. □\Box

Now we show the main result of this subsection: bringing down automorphisms of D{\cal D} to A≤D{\cal A}\leq{\cal D}.

Given a commutative semisimple algebra D{\cal D} over a finite field kk, its semiregular kk-automorphism τ\tau of prime order r≠char kr\not=char\ k, a subalgebra A⊃k{\cal A}\supset k of D{\cal D} such that dim⁡kDdim⁡kA\frac{\dim_{k}{\cal D}}{\dim_{k}{\cal A}} is an integer not divisible by rr. Then we can find in deterministic poly(log⁡∣D∣)poly(\log|{\cal D}|) time either a zero divisor in A{\cal A} or a subalgebra C≤A{\cal C}\leq{\cal A} together with a semiregular automorphism τ′\tau^{\prime} of C{\cal C} of order rr such that Cτ′≥Aτ(:=A∩Dτ){\cal C}_{\tau^{\prime}}\geq{\cal A}_{\tau}(:={\cal A}\cap{\cal D}_{\tau}).

We use the method of Proposition 4.6 to find an element x∈TD,rx\in T_{{\cal D},r} such that xτ=ζrxx^{\tau}=\zeta_{r}x. If x∈A[ζr]x\in{\cal A}[\zeta_{r}] then we define C:=Aτ[ζr][x]Δr{\cal C}:={\cal A}_{\tau}[\zeta_{r}][x]_{\Delta_{r}}. As τ\tau fixes ζr\zeta_{r} while Δr\Delta_{r} fixes D{\cal D}, τ\tau commutes with Δr\Delta_{r}. Thus, Cτ=(Aτ[ζr][x]τ)Δr=Aτ[ζr]Δr=Aτ{\cal C}_{\tau}=({\cal A}_{\tau}[\zeta_{r}][x]_{\tau})_{\Delta_{r}}={\cal A}_{\tau}[\zeta_{r}]_{\Delta_{r}}={\cal A}_{\tau}. This means that we have the C{\cal C} and the τ′:=τ∣C\tau^{\prime}:=\tau|_{\cal C} as promised. On the other hand if x∉A[ζr]x\not\in{\cal A}[\zeta_{r}] then we claim that we can find a zero divisor in D{\cal D}, decompose D{\cal D} into a direct sum of orthogonal ideals and construct the C{\cal C} and the τ′\tau^{\prime} in one of the ideals recursively.

Say x∉A[ζr]x\not\in{\cal A}[\zeta_{r}], then since xrt=1D∈Ax^{r^{t}}=1_{\cal D}\in{\cal A} for some integer t>0t>0, we can choose a y∈{x,xr,xr2,…}y\in\{x,x^{r},x^{r^{2}},\ldots\} such that y∉A[ζr]y\not\in{\cal A}[\zeta_{r}] but c′:=yr∈A[ζr]c^{\prime}:=y^{r}\in{\cal A}[\zeta_{r}]. By Lemma 5.1, we can find a zero divisor in D{\cal D} unless A[ζr][c′r]{\cal A}[\zeta_{r}][\sqrt[r]{c^{\prime}}] is isomorphic to the subalgebra A[ζr][y]{\cal A}[\zeta_{r}][y]. In the latter case D0:=A[ζr][y]Δr≤D{\cal D}_{0}:={\cal A}[\zeta_{r}][y]_{\Delta_{r}}\leq{\cal D} is a free A{\cal A}-module of rank rr, by Proposition 4.4. Comparing dimensions it follows that D{\cal D} cannot be a free D0{\cal D}_{0}-module, therefore we can find a zero divisor zz in D0{\cal D}_{0} by Lemma 2.2. Thus, whenever x∉A[ζr]x\not\in{\cal A}[\zeta_{r}], we can find a zero divisor zz in D{\cal D}.

We proceed with computing the ideal of D{\cal D} generated by zz and using Lemma 2.3, obtain a τ\tau-invariant decomposition of D{\cal D} into the orthogonal ideals I1,…,ItI_{1},\ldots,I_{t}. For 1≤j≤t1\leq j\leq t, we denote by ϕj\phi_{j} the projection D→Ij{\cal D}\rightarrow I_{j}. We can assume that for all jj, ϕj∣A\phi_{j}|_{\cal A} is injective as otherwise we find a zero divisor in A{\cal A} and let E⊆{I1,…,It}E\subseteq\{I_{1},\ldots,I_{t}\} be a set of representatives of all the rr-sized orbits of τ\tau. We have dim⁡kDdim⁡kA=∑j=1tdim⁡kIjdim⁡kA=∑Ijτ=Ijdim⁡kIjdim⁡kA+r∑Ij∈Edim⁡kIjdim⁡kA\frac{\dim_{k}{\cal D}}{\dim_{k}{\cal A}}=\sum_{j=1}^{t}\frac{\dim_{k}I_{j}}{\dim_{k}{\cal A}}=\sum_{I_{j}^{\tau}=I_{j}}\frac{\dim_{k}I_{j}}{\dim_{k}{\cal A}}+r\sum_{I_{j}\in E}\frac{\dim_{k}I_{j}}{\dim_{k}{\cal A}}, from which we infer that the first sum is nonempty and includes at least one term not divisible by rr, therefore we can choose an index jj such that IjI_{j} is τ\tau-invariant and r∤dim⁡kIjdim⁡kAr\not|\frac{\dim_{k}I_{j}}{\dim_{k}{\cal A}}. So we can proceed with IjI_{j} and ϕjA≅A\phi_{j}{\cal A}\cong{\cal A} in place of D{\cal D} and A{\cal A} respectively in the algorithm described above.

The process described above stops when either we find a zero divisor in A{\cal A} or an element x∈TA′,rx\in T_{{\cal A}^{\prime},r} with xτ=ζrxx^{\tau}=\zeta_{r}x, where A′≅A{\cal A}^{\prime}\cong{\cal A} is the image of A{\cal A} under the projection ϕ\phi of D{\cal D} to some τ\tau-invariant ideal II. In the latter case we compute the subalgebra C′:=Aτ′[ζr][x]Δr{\cal C}^{\prime}:={\cal A}^{\prime}_{\tau}[\zeta_{r}][x]_{\Delta_{r}}. Finally put C:=ϕ−1(C′){\cal C}:=\phi^{-1}({\cal C}^{\prime}) and τ′:=ϕ−1∘τ∘ϕ\tau^{\prime}:=\phi^{-1}\circ\tau\circ\phi. Notice that, if eIe_{I} is the identity element of II then τ\tau will fix eIe_{I} and ϕ:D→I\phi:{\cal D}\rightarrow I will just be the homomorphism d↦eIdd\mapsto e_{I}d, thus τ\tau commutes with ϕ\phi. Consequently, Cτ′=ϕ−1(Cτ′)=ϕ−1(Aτ′)≥Aτ{\cal C}_{\tau^{\prime}}=\phi^{-1}({\cal C}^{\prime}_{\tau})=\phi^{-1}({\cal A}^{\prime}_{\tau})\geq{\cal A}_{\tau}. □\Box

2 Essential Part of the Tensor Power

Let A{\cal A} be a commutative semisimple algebra over a finite field kk. Let B{\cal B} be its subalgebra such that k⊆Bk\subseteq{\cal B} and A{\cal A} be a free module over B{\cal B} of rank mm. If char k≤m2char\ k\leq m^{2} then polynomial factorization can be done in deterministic time by Berlekamp’s algorithm and consequently, all our results can be obtained easily. So we assume from now on that char k>m2char\ k>m^{2}. But then we can also assume that A{\cal A} is a simple extension algebra of B{\cal B} and find a primitive element α\alpha by running an algorithmic version of Fact 1 (if this “fails” then it gives a zero divisor of A{\cal A}). If g(X)∈B[X]g(X)\in{\cal B}[X] is a minimal polynomial of α\alpha then we have that A=B[X]/(g(X)){\cal A}={\cal B}[X]/(g(X)).

It was shown by Rónyai [Ró87] that, under GRH, a zero divisor in A{\cal A} can be found in time poly((dim⁡kA)r,log⁡∣k∣)poly((\dim_{k}{\cal A})^{r},\log|k|) if rr is a prime divisor of dim⁡kA\dim_{k}{\cal A}. In this section we extend the method of [Ró87] and obtain a GRH-free version that will be crucial in the proof of Main Theorem. A key idea of Rónyai was to work in the essential part of the tensor powers of A{\cal A}. Before going to the formal definition of it we give a motivating definition assuming A=k[X1]/(f(X1)){\cal A}=k[X_{1}]/(f(X_{1})), the essential part of A⊗k2:={\cal A}^{\otimes_{k}2}:= A⊗kA{\cal A}\otimes_{k}{\cal A} is its ideal isomorphic to the algebra:

Similarly, we can write down an expression for the essential part of A⊗kr{\cal A}^{\otimes_{k}r} inductively, as a factor algebra of k[X1,…,Xr]k[X_{1},\ldots,X_{r}].

Functional interpretation of tensor powers: Let a commutative semisimple A{\cal A} be a simple extension algebra over B⊇k{\cal B}\supseteq k such that A=B[X]/(g(X)){\cal A}={\cal B}[X]/(g(X)) and g(X)∈B[X]g(X)\in{\cal B}[X] is a monic polynomial of degree mm. Let r≤mr\leq m. We consider the rr-th tensor power A⊗Br{\cal A}^{\otimes_{\cal B}r} (A{\cal A} tensored with itself rr times wrt B{\cal B}). To define (and compute) the essential part of this tensor power it is convenient to interpret A{\cal A} as a collection of functions V→B‾V\rightarrow\overline{\cal B} that are expressible as a polynomial over B{\cal B} (called B{\cal B}-polynomial functions), where B‾:=k‾⊗kB\overline{\cal B}:=\overline{k}\otimes_{k}{\cal B} is the algebraic closure of B{\cal B} and V⊂B‾V\subset\overline{\cal B} is a set of roots of g(X)g(X). If B{\cal B} is not a field then there are various possibilities for VV and we need one with ∏v∈V(X−v)=g(X)\prod_{v\in V}(X-v)=g(X). Such a VV clearly exists by the definition of the algebraic closure. This functional interpretation of A{\cal A} generalizes to A⊗BA{\cal A}\otimes_{\cal B}{\cal A}, which now becomes the set of all B{\cal B}-polynomial functions from the set V×VV\times V to B‾\overline{\cal B} and finally A⊗Br{\cal A}^{\otimes_{\cal B}r} is the set of all B{\cal B}-polynomial functions from the set VrV^{r} to B‾\overline{\cal B}. Note that in this interpretation a rank 11 tensor element h1⊗⋯⊗hrh_{1}\otimes\cdots\otimes h_{r} in A⊗Br{\cal A}^{\otimes_{\cal B}r} corresponds to the function Vr→B‾V^{r}\rightarrow\overline{\cal B} that maps (v1,…,vr)↦(v_{1},\ldots,v_{r})\mapsto h1(v1)⋯hr(vr)h_{1}(v_{1})\cdots h_{r}(v_{r}) .

Essential part of tensor powers: The essential part A⊗Br~\widetilde{{\cal A}^{\otimes_{\cal B}r}} of A⊗Br{\cal A}^{\otimes_{\cal B}r} is the subset of functions that vanish on all the rr-tuples (v1,…,vr)(v_{1},\ldots,v_{r}) that have vi=vjv_{i}=v_{j} for some i≠ji\neq j. It can be seen that A⊗Br~\widetilde{{\cal A}^{\otimes_{\cal B}r}} is an ideal of A⊗Br{\cal A}^{\otimes_{\cal B}r}. We show below that given a basis of A{\cal A} over B{\cal B} we can directly compute a basis for A⊗Br~\widetilde{{\cal A}^{\otimes_{\cal B}r}} over B{\cal B}.

A basis for A⊗Br~\widetilde{{\cal A}^{\otimes_{\cal B}r}} over B{\cal B} can be computed by a deterministic algorithm in time poly(mr,log⁡∣A∣)poly(m^{r},\log|{\cal A}|).

Consider embeddings μi\mu_{i} of A{\cal A} into A⊗Br{\cal A}^{\otimes_{\cal B}r} (i=1,…,ri=1,\ldots,r) given as μi(a)=1⊗…⊗1⊗a⊗1⊗…⊗1\mu_{i}(a)=1\otimes\ldots\otimes 1\otimes a\otimes 1\otimes\ldots\otimes 1 where aa is in the ii-th place. In the interpretation as functions, μi(A)\mu_{i}({\cal A}) correspond to the B{\cal B}-polynomial functions on VrV^{r} which depend only on the iith element in the tuples. Observe that the set, for 1≤i<j≤r1\leq i<j\leq r:

is the ideal of A⊗Br{\cal A}^{\otimes_{\cal B}r} consisting of the B{\cal B}-polynomial functions which are zero on every tuple (v1,…,vr)(v_{1},\ldots,v_{r}) with vi≠vjv_{i}\neq v_{j}. Given a basis for A{\cal A}, a basis for Δi,jr\Delta^{r}_{i,j} can be computed by solving a system of linear equations in time (counting kk-operations as unit time) polynomial in dim⁡kA⊗Br=mrdim⁡kB\dim_{k}{\cal A}^{\otimes_{\cal B}r}=m^{r}\dim_{k}{\cal B}. Finally, notice that A⊗Br~\widetilde{{\cal A}^{\otimes_{\cal B}r}} can be computed as well since it is the annihilator of ∑1≤i<j≤rΔi,jr\sum_{1\leq i<j\leq r}\Delta^{r}_{i,j}. □\Box

Automorphisms of the essential part: The symmetric group SrS_{r} acts as a group of automorphisms of A⊗Br{\cal A}^{\otimes_{\cal B}r}. The action of π∈Sr\pi\in S_{r} is the B{\cal B}-linear extension of the map h1⊗⋯⊗hr↦hπ(1)⊗⋯⊗hπ(r)h_{1}\otimes\cdots\otimes h_{r}\mapsto h_{\pi(1)}\otimes\cdots\otimes h_{\pi(r)}. This action is not semiregular on the tensor power algebra as it fixes the set I0I_{0} of B{\cal B}-polynomial functions on VrV^{r} that are zero on all the points Vr∖{(v,…,v)∣v∈V}V^{r}\setminus\{(v,\ldots,v)|v\in V\}, where I0I_{0} can be seen to be an ideal of A⊗Br{\cal A}^{\otimes_{\cal B}r}. However, the ideal A⊗Br~\widetilde{{\cal A}^{\otimes_{\cal B}r}} is invariant under this action and on it SrS_{r} acts semiregularly.

Embedding A{\cal A} in the essential part: A{\cal A} can be embedded into A⊗Br{\cal A}^{\otimes_{\cal B}r} by sending h∈Ah\in{\cal A} to h⊗1A⊗⋯⊗1Ah\otimes 1_{\cal A}\otimes\cdots\otimes 1_{\cal A}. Composing this embedding with the projection onto ideal A⊗Br~\widetilde{{\cal A}^{\otimes_{\cal B}r}} (which exists by the semisimplicity of the tensor power) we obtain an embedding of A{\cal A} in A⊗Br~\widetilde{{\cal A}^{\otimes_{\cal B}r}}.

Note that the ideal A⊗Br~\widetilde{{\cal A}^{\otimes_{\cal B}r}} is a free B{\cal B}-module of rank m⋯(m−r+1)m\cdots(m-r+1). Denoting the above embedding of A{\cal A} also by A{\cal A}, if rr is a prime divisor of mm then m⋯(m−r+1)/m=m\cdots(m-r+1)/m= dim⁡kA⊗Br~/dim⁡kA\dim_{k}{\widetilde{{\cal A}^{\otimes_{\cal B}r}}}/\dim_{k}{\cal A} is not divisible by rr and we can apply Proposition 5.2 with A⊗Br~\widetilde{{\cal A}^{\otimes_{\cal B}r}} as D{\cal D} and the cyclic permutation (1…r)(1\ldots r) as τ\tau. This immediately gives us the following GRH-free version of the result of [Ró87]:

Let B{\cal B} be a subalgebra of a commutative semisimple algebra A{\cal A} over a finite field kk such that k⊆Bk\subseteq{\cal B}; let A{\cal A} be a free B{\cal B}-module of rank mm; and let rr be a prime divisor of mm. Then in deterministic poly(mr,log⁡∣A∣)poly(m^{r},\log|{\cal A}|) time one can either find a zero divisor in A{\cal A} or compute a subalgebra C{\cal C} of A{\cal A} together with a semiregular automorphism τ\tau of C{\cal C} of order rr such that Cτ≥B{\cal C}_{\tau}\geq{\cal B}.

In the proof of Main Theorem we will need one more property of the essential part of the tensor square.

Left and Right Mappings: Note that there are two ways to map A{\cal A} into an ideal I⊴A⊗BA~I\unlhd\widetilde{{\cal A}\otimes_{\cal B}{\cal A}}: either by first embedding A{\cal A} into A⊗BA{\cal A}\otimes_{\cal B}{\cal A} by h↦h⊗1h\mapsto h\otimes 1 or by first embedding A{\cal A} into A⊗BA{\cal A}\otimes_{\cal B}{\cal A} by h↦1⊗hh\mapsto 1\otimes h, and then projecting to the ideal II (which is also an ideal of A⊗BA{\cal A}\otimes_{\cal B}{\cal A}). The former we call the left mapping while the latter the right mapping (of A{\cal A} into II).

We will now show that these two mappings of A{\cal A} into I⊴A⊗BA~I\unlhd\widetilde{{\cal A}\otimes_{\cal B}{\cal A}} are quite different if II is large enough.

Let m:=dimBAm:=dim_{\cal B}{\cal A} and II be a nonzero ideal of A⊗BA~\widetilde{{\cal A}\otimes_{\cal B}{\cal A}}. Let τ1:A→I\tau_{1}:{\cal A}\rightarrow I be the left mapping of A{\cal A} while τ2\tau_{2} be the right mapping of A{\cal A} into II. Then there exists an element x∈Ax\in{\cal A} such that τ1(x)≠τ2(x)\tau_{1}(x)\neq\tau_{2}(x). Furthermore, if dimkI/dim⁡kB>mdim_{k}I/\dim_{k}{\cal B}>m then τ1(A)≠τ2(A)\tau_{1}({\cal A})\neq\tau_{2}({\cal A}).

To see the first statement observe that A⊗BA~\widetilde{{\cal A}\otimes_{\cal B}{\cal A}} is the ideal of A⊗BA{\cal A}\otimes_{\cal B}{\cal A} generated by the set of elements {x⊗1−1⊗x∣x∈A}\{x\otimes 1-1\otimes x|x\in{\cal A}\}, see Lemma 5.3. It follows that II (as an ideal) is generated by the elements {τ1(x)−τ2(x)∣x∈A}\{\tau_{1}(x)-\tau_{2}(x)|x\in{\cal A}\}. Consequently, if τ1(x)−τ2(x)=0\tau_{1}(x)-\tau_{2}(x)=0 for all x∈Ax\in{\cal A} then I=0I=0.

To see the second assertion, note that as II is an ideal of the essential part of the semisimple A⊗BA{\cal A}\otimes_{\cal B}{\cal A}, there is a natural projection ϕ:A⊗BA→I\phi:{\cal A}\otimes_{\cal B}{\cal A}\rightarrow I. Then τ1(A)=ϕ(A⊗B1)\tau_{1}({\cal A})=\phi({\cal A}\otimes_{\cal B}1) and τ2(A)=ϕ(1⊗BA)\tau_{2}({\cal A})=\phi(1\otimes_{\cal B}{\cal A}). From this and from the fact that A⊗B1{\cal A}\otimes_{\cal B}1 and 1⊗BA1\otimes_{\cal B}{\cal A} generate A⊗BA{\cal A}\otimes_{\cal B}{\cal A} we infer that τ1(A)\tau_{1}({\cal A}) and τ2(A)\tau_{2}({\cal A}) generate II. As dim⁡kτi(A)≤dim⁡kA=mdim⁡kB<dim⁡kI\dim_{k}\tau_{i}({\cal A})\leq\dim_{k}{\cal A}=m\dim_{k}{\cal B}<\dim_{k}I, this excludes the possibility of τ1(A)=τ2(A)\tau_{1}({\cal A})=\tau_{2}({\cal A}). □\Box

3 Proof of Main Theorem

We now prove the following slightly stronger version of Main Theorem.

Given a commutative semisimple algebra A{\cal A} over a finite field kk and a subalgebra B⊇k{\cal B}\supseteq k of A{\cal A} such that A{\cal A} is a free B{\cal B}-module of rank mm. Then in deterministic poly(mlog⁡m,log⁡∣A∣)poly(m^{\log m},\log|{\cal A}|) time one can either find a zero divisor in A{\cal A} or a semiregular automorphism σ\sigma of A{\cal A} of order mm with Aσ=B{\cal A}_{\sigma}={\cal B}.

We may assume that char k>m2char\ k>m^{2} as otherwise using Berlekamp’s factoring algorithm we can completely decompose A{\cal A} into simple components.

If mm is even then using the algorithm of Theorem 5.4 we either find a zero divisor in A{\cal A} or a subalgebra C≤A{\cal C}\leq{\cal A} together with a semiregular automorphism σ0\sigma_{0} of C{\cal C} of order 22 with Cσ0≥B{\cal C}_{\sigma_{0}}\geq{\cal B} in deterministic polynomial time. In the former case we are done while in the latter case we make two recursive calls: one on the pair (A,C)({\cal A},{\cal C}) and the other on the pair (Cσ0,B)({\cal C}_{\sigma_{0}},{\cal B}). This way we either find a zero divisor in A{\cal A} or we find a semiregular automorphism σ1\sigma_{1} of A{\cal A} satisfying Aσ1=C{\cal A}_{\sigma_{1}}={\cal C} as well as a semiregular automorphism σ2\sigma_{2} of Cσ0{\cal C}_{\sigma_{0}} satisfying (Cσ0)σ2=B({\cal C}_{\sigma_{0}})_{\sigma_{2}}={\cal B}. In the former case we are done while in the latter case we apply the algorithm of Lemma 4.8 two times to construct σ\sigma from σ0,σ1,σ2\sigma_{0},\sigma_{1},\sigma_{2}. This finishes the even mm case.

Assume for the rest of the proof that mm is odd. We outline here the overall flow of the algorithm. We work in the algebra A′:=A⊗BA~{\cal A}^{\prime}:=\widetilde{{\cal A}{\otimes_{\cal B}{\cal A}}} and B′:=ϕ1(A){\cal B}^{\prime}:=\phi_{1}({\cal A}) where, ϕ1\phi_{1} and ϕ2\phi_{2} are respectively the left and right embeddings of A{\cal A} into A′{\cal A}^{\prime}. During the course of the algorithm we maintain a nonzero ideal I⊴A′I\unlhd{\cal A}^{\prime} with B′{\cal B}^{\prime} embedded in it. Any time we find a zero divisor in II we replace II with either the ideal generated by the zero divisor or its complement, depending on which has smaller dimension. We can assume the new ideal to be a free module over an embedded B′{\cal B}^{\prime} as otherwise we can find a zero divisor in B′{\cal B}^{\prime} (equivalently in A{\cal A}). Note that the rank of the new ideal over the embedded B′{\cal B}^{\prime} is at most half of the original one. Initially I=A′I={\cal A}^{\prime} and it is a free B′{\cal B}^{\prime}-module of even rank (m−1)(m-1) and so we can apply the recursion outlined in the second paragraph of this proof. In this way at any stage we either find a smaller ideal of II or a semiregular automorphism σ\sigma of II such that Iσ=eIB′≅B′I_{\sigma}=e_{I}{\cal B}^{\prime}\cong{\cal B}^{\prime}, where eIe_{I} is the identity element of II. In the former case we replace II by the smaller ideal (with an embedded B′{\cal B}^{\prime}) and apply recursion which again either finds a zero divisor (and hence a smaller ideal) or a B′{\cal B}^{\prime}-automorphism of the new ideal.

The recursion outlined above halts either with a zero divisor found in B′{\cal B}^{\prime} (equivalently in A{\cal A}) or with a semiregular automorphism σ\sigma of an I⊴A′I\unlhd{\cal A}^{\prime} such that Iσ=eIB′≅B′I_{\sigma}=e_{I}{\cal B}^{\prime}\cong{\cal B}^{\prime}. In the former case we are done while the latter case is what we handle now. Let τ1:A→I\tau_{1}:{\cal A}\rightarrow I mapping a↦eIϕ1(a)a\mapsto e_{I}\phi_{1}(a) be the embedding of A{\cal A} into II. Look at the homomorphism τ2:A→I\tau_{2}:{\cal A}\rightarrow I that maps a↦eIϕ2(a)a\mapsto e_{I}\phi_{2}(a). It is a nonzero homomorphism as τ2(1)=eI≠0\tau_{2}(1)=e_{I}\not=0. So we can assume τ2\tau_{2} to be an embedding of A{\cal A} in II as well or else we get a zero divisor in A{\cal A}

If σ\sigma is trivial, i.e. I=eIB′≅B′≅AI=e_{I}{\cal B}^{\prime}\cong{\cal B}^{\prime}\cong{\cal A}, then μ:=τ2−1τ1\mu:=\tau_{2}^{-1}\tau_{1} is a nontrivial B{\cal B}-automorphism of A{\cal A} by the first part of Lemma 5.5. If μ\mu is not semiregular then we can find a zero divisor by Proposition 3.2 while if μ\mu is semiregular then we can apply recursion to the pair (Aμ,B)({\cal A}_{\mu},{\cal B}), find an automorphism of Aμ{\cal A}_{\mu} and finally extend it to a promised automorphism of A{\cal A} by Lemma 4.8.

So let us assume that σ\sigma is nontrivial, i.e. I>Iσ=τ1(A)I>I_{\sigma}=\tau_{1}({\cal A}), thus rkτ1(B)I>m{\rm rk}_{\tau_{1}({\cal B})}I>m. Then we define B′′:=τ2(A){\cal B}^{\prime\prime}:=\tau_{2}({\cal A}) and apply recursion to the pair (I,B′′)(I,{\cal B}^{\prime\prime}). We either find a zero divisor of II or obtain a semiregular automorphism σ′\sigma^{\prime} of II with Iσ′=B′′I_{\sigma^{\prime}}={\cal B}^{\prime\prime}. In the former case we can proceed with a smaller ideal of II or finish with a zero divisor of B′′{\cal B}^{\prime\prime} and hence of A{\cal A}, so the latter case of having a σ′\sigma^{\prime} is what we think about now. We can assume that σ\sigma and σ′\sigma^{\prime} commute as otherwise we can find a zero divisor of II by the algorithm of Theorem 4.7 and proceed with recursion. Thus, Iσ′I_{\sigma^{\prime}} is σ\sigma-invariant and IσI_{\sigma} is σ′\sigma^{\prime}-invariant. Thus both σ\sigma and σ′\sigma^{\prime} can be viewed as automorphisms of τ2(A)\tau_{2}({\cal A}) and τ1(A)\tau_{1}({\cal A}) respectively. If both these actions are trivial then τ1(A)=Iσ=(Iσ)σ′=(Iσ′)σ=Iσ′=τ2(A)\tau_{1}({\cal A})=I_{\sigma}=(I_{\sigma})_{\sigma^{\prime}}=(I_{\sigma^{\prime}})_{\sigma}=I_{\sigma^{\prime}}=\tau_{2}({\cal A}), which contradicts the second statment of Lemma 5.5. Thus one of them is nontrivial, wlog say σ\sigma is a nontrivial automorphism of τ2(A)\tau_{2}({\cal A}). Then μ:=τ2−1στ2\mu:=\tau_{2}^{-1}\sigma\tau_{2} is a nontrivial automorphism of A{\cal A}. Again we can either find a zero divisor of A{\cal A} or proceed with a recursion to the pair (Aμ,B)({\cal A}_{\mu},{\cal B}), getting a promised automorphism of A{\cal A} by the algorithm of Lemma 4.8.

To see the dominating term in the time complexity observe that in any recursive call on some pair, say C,D{\cal C},{\cal D} with d:=rkDCd:={\rm rk}_{\cal D}{\cal C}, if dd is odd then we need to go to the tensor square of C{\cal C} wrt D{\cal D}. Thus we need to then work in an algebra of rank dd times the original rank. As we start with rank mm we have d≤md\leq m and as the rank dd is at least halved in the subsequent recursive call (if there is one), we deduce that the algorithm works at all times in an algebra of rank (over B{\cal B}) at most mlog⁡mm^{\log m}. It is then routine to verify that the algorithm requires in all just poly(mlog⁡m)poly(m^{\log m}) many B{\cal B}-operations, which proves the time complexity as promised. □\Box

To finish the proof of Main Theorem, apply the process described in the above Theorem to B=k{\cal B}=k. If it yields a zero divisor zz of A{\cal A} then the ideal I:=AzI:={\cal A}z and its complementary ideal I⊥I^{\perp} give a decomposition of A=I⊕I⊥{\cal A}=I\oplus I^{\perp}. If eIe_{I} is the identity element of II then we can repeat the process now with A{\cal A} replaced by eIA=Ie_{I}{\cal A}=I and B{\cal B} replaced by eIk≅ke_{I}k\cong k. Thus after several iterations based on Theorem 5.6 we get the direct sum decomposition of A{\cal A} together with automorphisms as promised in Main Theorem.

Noncommutative Applications

In this section we show that given a noncommutative algebra A{\cal A} over a finite field we can unconditionally find zero divisors of A{\cal A} in deterministic subexponential time. The idea is to compute a commutative subalgebra D{\cal D} of A{\cal A}, find an automorphism of D{\cal D} using the algorithm described in Theorem 5.6, and finally construct a zero divisor of A{\cal A} using this automorphism.

Preprocessing: Let A{\cal A} be a finite dimensional noncommutative algebra over a finite field kk. If A{\cal A} is not semisimple then we can compute the radical of A{\cal A}, by the deterministic polynomial time algorithm of [Ró90, CIW96], and get several zero divisors. So we can assume that A{\cal A} is semisimple. We can efficiently compute the center C{\cal C} of A{\cal A} (C{\cal C} is the subalgebra having elements that commute with all elements in A{\cal A}) by solving a system of linear equations. By the Artin-Wedderburn Theorem (see Fact 4) we know that if C1,…,Cr{\cal C}_{1},\ldots,{\cal C}_{r} are the simple components of C{\cal C} then, structurally, A=⨁i=1rMmi(Ci){\cal A}=\bigoplus_{i=1}^{r}M_{m_{i}}({\cal C}_{i}), where Mm(R)M_{m}(R) stands for the algebra of all m×mm\times m matrices over the kk-algebra RR. Note that if the mim_{i}’s are not all the same then A{\cal A} would not be a free module over C{\cal C} and hence we can find a zero divisor in C{\cal C} by Lemma 2.2. So we can assume A=⨁i=1rMm(Ci)=Mm(⊕i=1rCi)=Mm(C){\cal A}=\bigoplus_{i=1}^{r}M_{m}({\cal C}_{i})=M_{m}(\oplus_{i=1}^{r}{\cal C}_{i})=M_{m}({\cal C}). Thus the hard case is to find a zero divisor in an algebra isomorphic to Mm(C)M_{m}({\cal C}), this is what we focus on in the remaining section. We identify C{\cal C} with the scalar matrices in Mm(C)M_{m}({\cal C}).

Note that for any invertible matrix AA there is a natural automorphism of the full matrix algebra that maps xx to A−1xAA^{-1}xA, we call this a conjugation automorphism. We show in the first Lemma that, under certain mild condition, an automorphism of a commutative semisimple subalgebra of the full matrix algebra corresponds to a conjugation automorphism.

Recall that every maximal commutative semisimple algebra of the full matrix algebra Mm(F)M_{m}(F) over a perfect field FF has dimension mm over FF. If FF is algebraically closed then every commutative semisimple subalgebra of Mm(F)M_{m}(F) is in fact (upto a conjugation isomorphism) a subalgebra of the diagonal matrices.

Let C{\cal C} be a commutative semisimple algebra over a finite field kk, let B≤Mm(C){\cal B}\leq M_{m}({\cal C}) be a commutative semisimple C{\cal C}-algebra and let σ\sigma be a C{\cal C}-automorphism of B{\cal B}. Let there be a maximal commutative semisimple subalgebra D≤Mm(C){\cal D}\leq M_{m}({\cal C}) containing B{\cal B} such that D{\cal D} is a free B{\cal B}-module. Then there exists a nonzero y∈Mm(C)y\in M_{m}({\cal C}) such that ∀x∈B\forall x\in{\cal B}, xσ=y−1xyx^{\sigma}=y^{-1}xy.

We get hold of this element yy by reducing the question to the case of C{\cal C} being an algebraically closed field, when D{\cal D} becomes a direct sum of mm copies of C{\cal C} and B{\cal B} becomes a direct sum of r∣mr|m copies of C{\cal C}. In that case we can find a basis of -11 diagonal matrices for B{\cal B} that is permuted by σ\sigma and hence construct the promised yy as a permutation matrix.

Firstly, we can assume C{\cal C} to be a field because if I1,…,IcI_{1},\ldots,I_{c} are the simple components of C{\cal C} then clearly the IiI_{i}’s are all finite fields, and we can try finding the promised yiy_{i} for the instance of (DIi,BIi,Ii)({\cal D}I_{i},{\cal B}I_{i},I_{i}). Note that since σ\sigma was fixing IiI_{i}, σ\sigma is still a (Ii)(I_{i})-automorphism of BIi{\cal B}I_{i} and by freeness condition, DIi{\cal D}I_{i} is still a free (BIi)({\cal B}I_{i})-module and it is a maximal commutative semisimple subalgebra of Mm(Ii)M_{m}(I_{i}). Also, once we have the yiy_{i}, for all 1≤i≤c1\leq i\leq c, satisfying yixσ=xyiy_{i}x^{\sigma}=xy_{i} for all x∈Iix\in I_{i}; it is easy to see that (y1+…+yr)(y_{1}+\ldots+y_{r}) is the promised yy. So for the rest of the proof we assume that C{\cal C} is a finite field extension of kk. Secondly, notice that the condition yxσ=xyyx^{\sigma}=xy is equivalent to the system of equations: yx1σ=x1y,…,yxrσ=xryyx_{1}^{\sigma}=x_{1}y,\ldots,yx_{r}^{\sigma}=x_{r}y for a C{\cal C}-basis x1,…,xrx_{1},\ldots,x_{r} of B{\cal B}. In terms of the entries of the matrix yy this is a system of homogeneous linear equations in the field C{\cal C}. This system has a nonzero solution over C{\cal C} iff the same system has a nonzero solution over the algebraic closure C‾\overline{\cal C} of C{\cal C}. A solution over C‾\overline{\cal C} gives a matrix y∈Mm(C‾)y\in M_{m}({\overline{\cal C}}) such that yxσ=xyyx^{\sigma}=xy for every x∈B‾x\in{\overline{\cal B}} where B‾:=C‾⊗CB{\overline{\cal B}}:={\overline{\cal C}}\otimes_{\cal C}{\cal B} and we extend σ\sigma C‾{\overline{\cal C}}-linearly to an algebra automorphism of B‾\overline{\cal B}. Because kk was a finite field, B‾≤Mm(C‾)\overline{\cal B}\leq M_{m}({\overline{\cal C}}) is a commutative semisimple algebra over C‾\overline{\cal C}. Similarly, D‾:=C‾⊗CD\overline{\cal D}:={\overline{\cal C}}\otimes_{\cal C}{\cal D} is a maximal commutative semisimple subalgebra of Mm(C‾)M_{m}({\overline{\cal C}}), and is also a free B‾\overline{\cal B}-module. By the former condition dim⁡C‾D‾=m\dim_{\overline{\cal C}}\overline{\cal D}=m and by the latter condition r∣mr|m. We will now focus on the instance of (D‾,B‾,C‾)(\overline{\cal D},\overline{\cal B},\overline{\cal C}) and try to construct the promised yy.

As D‾\overline{\cal D} is a sum of mm copies of C‾\overline{\cal C}, by an appropriate basis change we can make D‾\overline{\cal D} the algebra of all diagonal matrices in Mm(C‾)M_{m}(\overline{\cal C}). Also, as D‾\overline{\cal D} is a free B‾\overline{\cal B}-module, a further basis change makes B‾\overline{\cal B} the algebra generated by the matrices e1,…ere_{1},\ldots e_{r} where each eje_{j} is a diagonal -11 matrix having m/rm/r consecutive 11’s. In that case the automorphism σ\sigma has a simple action, namely it permutes the matrices {e1,…,er}\{e_{1},\ldots,e_{r}\}. Let yy be a block r×rr\times r-matrix whose blocks are all m/r×m/rm/r\times m/r zero matrices except at positions i,iσi,i^{\sigma} (iσi^{\sigma} is defined by eiσ=eiσe_{i}^{\sigma}=e_{i^{\sigma}}), where the block is the m/r×m/rm/r\times m/r identity matrix. Clearly then, eiσ=y−1eiye_{i^{\sigma}}=y^{-1}e_{i}y for all 1≤i≤r1\leq i\leq r and hence xσ=y−1xyx^{\sigma}=y^{-1}xy for every x∈B‾x\in\overline{\cal B} by extending the equalities linearly to B‾\overline{\cal B}. □\Box

In the second Lemma we show that a conjugation automorphism of prime order of a commutative semisimple subalgebra corresponds to a zero divisor of the original algebra.

Let A{\cal A} be a finite dimensional algebra over the perfect field FF and let B≤A{\cal B}\leq{\cal A} be a commutative semisimple algebra containing F1AF1_{\cal A}. Let rr be a prime different from charF{\rm char}F and let y∈Ay\in{\cal A} be of order rr such that: y−1By=By^{-1}{\cal B}y={\cal B} but there is an element x∈Bx\in{\cal B} with y−1xy≠xy^{-1}xy\neq x. Then the minimal polynomial of yy over FF is in fact (Xr−1)(X^{r}-1). As a consequence, (y−1)(y-1) and (1+y+…+yr−1)(1+y+\ldots+y^{r-1}) is a pair of zero divisors in A{\cal A}.

Let F‾\overline{F} be the algebraic closure of FF. Note that in A‾:=F‾⊗FA\overline{\cal A}:={\overline{F}}\otimes_{F}{\cal A}, the minimal polynomial of 1⊗y1\otimes y is the same as that of yy in A{\cal A}, B‾:=F‾⊗B\overline{\cal B}:={\overline{F}}\otimes{\cal B} remains commutative semisimple and conjugation by 1⊗y1\otimes y acts on it as an automorphism of order rr. Thus for the rest of the proof we can assume FF to be algebraically closed.

As conjugation by yy does not fix B{\cal B}, there exists a primitive idempotent ee of B{\cal B} for which the elements ej=y−jeyje_{j}=y^{-j}ey^{j} (j=1,…,rj=1,\ldots,r) are pairwise orthogonal primitive idempotents of B{\cal B}. This means that the corresponding left ideals Lj:=AejL_{j}:={\cal A}e_{j} are linearly independent over FF. Assume now that the minimal polynomial of yy has degree less than rr. So there are elements α0,…,αr−1∈F\alpha_{0},\ldots,\alpha_{r-1}\in F, not all zero, such that ∑j=0r−1αjyj=0\sum_{j=0}^{r-1}\alpha_{j}y^{j}=0. Implying that e∑j=0r−1αjyj=∑j=0r−1αjyjej=0e\sum_{j=0}^{r-1}\alpha_{j}y^{j}=\sum_{j=0}^{r-1}\alpha_{j}y^{j}e_{j}=0, this together with the fact that yjejy^{j}e_{j}’s are all nonzero, contradicts the linear independence of L1,…,LrL_{1},\ldots,L_{r}. □\Box

2 Proof of Application 1

In this subsection we give the proof of Application 1: given a noncommutative algebra A{\cal A} over a finite field kk, one can unconditionally find zero divisors of A{\cal A} in deterministic subexponential time. By the preprocessing discussed in the beginning of the section it is clear that we need to only handle the case of A≅Mm(C){\cal A}\cong M_{m}({\cal C}), where C{\cal C} is a commutative semisimple algebra over kk. The basic idea in the algorithm then is to find a maximal commutative semisimple subalgebra D≤A{\cal D}\leq{\cal A}, find a C{\cal C}-automorphism σ\sigma of D{\cal D}, use it to define a subalgebra of A{\cal A} which is a so called cyclic algebra, and then find a zero divisor in this cyclic algebra by the method of [W05]. The cyclic algebras A′{\cal A}^{\prime} over C{\cal C} we encounter have two generators x,yx,y such that for a prime rr: xy=ζryxxy=\zeta_{r}yx and the multiplicative orders of x,yx,y are powers of rr. These algebras have the ring of quaternions as their classic special case, when x2=y2=−1x^{2}=y^{2}=-1 and xy=−yxxy=-yx.

Given the algebra A{\cal A} (with an unknown isomorphism to Mm(C)M_{m}({\cal C})) in basis form over the finite field kk. We can compute easily the center of A{\cal A}, and it will be C{\cal C}. We can also compute a maximal commutative semisimple subalgebra D{\cal D} of A{\cal A} by the deterministic polynomial time algorithm of [GI00] (D{\cal D} has an unknown isomorphism to the subalgebra of diagonal matrices of Mm(C)M_{m}({\cal C})). Being maximal, D{\cal D} is a free module over C{\cal C} of rank mm. By Theorem 5.6 we can, in deterministic poly(mlog⁡m,log⁡∣A∣)poly(m^{\log m},\log|{\cal A}|) time, either find a zero divisor in D{\cal D} or compute a semiregular automorphism σ\sigma of D{\cal D} such that Dσ=C{\cal D}_{\sigma}={\cal C}. In the former case we are done, so it is the latter case that we now assume. By Lemma 6.1, there certainly exists a y∈Ay\in{\cal A} such that dσ=y−1dyd^{\sigma}=y^{-1}dy for every d∈Dd\in{\cal D}, so by picking a nonzero solution of the corresponding system of linear equations we either find a zero divisor of A{\cal A} or we find such a yy. So suppose we find a yy such that dσ=y−1dy≠dd^{\sigma}=y^{-1}dy\neq d for every d∈D∖Cd\in{\cal D}\setminus{\cal C}.

We can efficiently obtain a multiple MM of the multiplicative order of yy, ord(y)ord(y), just by looking at the degrees of the irreducible factors of the minimal polynomial of yy over kk (this can be done deterministically without actually computing the factorization). Fix a prime factor r∣mr|m, as σ\sigma is a semiregular C{\cal C}-automorphism of D{\cal D}, σ\sigma is of order mm, hence using MM we can replace yy and σ\sigma by an appropriate power such that ord(y)ord(y) is a power of rr while ord(σ)=rord(\sigma)=r. By this construction, conjugation by yy is now a C{\cal C}-automorphism σ\sigma of D{\cal D} of order rr. Put z:=yrz:=y^{r}, thus d=dσr=z−1dzd=d^{\sigma^{r}}=z^{-1}dz for every d∈Dd\in{\cal D}. Note that we can assume z≠1z\neq 1 as otherwise (y−1)(y-1) is a zero divisor of A{\cal A} by Lemma 6.2. Thus an appropriate power, say ζr\zeta_{r}, of zz has order rr. Consider the subalgebra D[z]{\cal D}[z], it is commutative by the action of zz on D{\cal D} as seen before, it can also be assumed to be semisimple as otherwise we can find many zero divisors by just computing its radical. So D[z]{\cal D}[z] is a commutative semisimple algebra. By the maximality of D{\cal D} we deduce that D[z]=D{\cal D}[z]={\cal D}, hence z∈Dz\in{\cal D} and ζr∈D\zeta_{r}\in{\cal D}. So by Lemma 4.5 we can find efficiently either a zero divisor in D{\cal D} or an x∈D∗x\in{\cal D}^{*} such that xσ=ζrxx^{\sigma}=\zeta_{r}x. We assume the latter case and we replace xx by an appropriate power so that ord(x)ord(x) is an rr-power. Let w:=xrw:=x^{r}, as σ\sigma fixes ww, it has to be in C{\cal C}.

Let A′:=C[x,y]{\cal A}^{\prime}:={\cal C}[x,y], Dx:=C[x]≤A′{\cal D}_{x}:={\cal C}[x]\leq{\cal A}^{\prime}, Dy:=C[y]≤A′{\cal D}_{y}:={\cal C}[y]\leq{\cal A}^{\prime} and C′:=C[w,z]≤A′{\cal C}^{\prime}:={\cal C}[w,z]\leq{\cal A}^{\prime}. Note that by the definitions of w,zw,z it is easy to deduce that C′{\cal C}^{\prime} is in the center of A′{\cal A}^{\prime} and x,y∉C′x,y\not\in{\cal C}^{\prime}. Furthermore by xy=ζryxxy=\zeta_{r}yx it follows that the set {xiyj∣1≤i,j≤(r−1)}\{x^{i}y^{j}|1\leq i,j\leq(r-1)\} is a system of generators for A′{\cal A}^{\prime} as a C′{\cal C}^{\prime}-module. The relation xy=ζryxxy=\zeta_{r}yx also implies, that conjugation by yy acts on Dx{\cal D}_{x} as an automorphism of order rr and that the conjugation by xx acts on Dy{\cal D}_{y} as an automorphism of order rr. We can assume that both these C′{\cal C}^{\prime}-automorphisms are semiregular as otherwise we can find a zero divisor by Proposition 3.2. Thus both Dx{\cal D}_{x} and Dy{\cal D}_{y} are free modules over C{\cal C} of rank rr, furthermore assume A′{\cal A}^{\prime} to be a free C{\cal C}-module (also free C′{\cal C}^{\prime}-module) or else we find a zero divisor in C{\cal C} (or C′{\cal C}^{\prime}) by Lemma 2.2.

We can assume that w,zw,z generate a cyclic subgroup of C′{\cal C}^{\prime} otherwise by Lemma 2.1 we can find a zero divisor in C′{\cal C}^{\prime}. If the order of zz is larger than the order of ww then there is a u∈C′u\in{\cal C}^{\prime} with ur=wu^{r}=w. Put x′:=u−1xx^{\prime}:=u^{-1}x, then x′r=1x^{\prime r}=1 and x′y=ζryx′x^{\prime}y=\zeta_{r}yx^{\prime}, thus conjugation by x′x^{\prime} gives an automorphism of Dy{\cal D}_{y}, whence (x′−1)(x^{\prime}-1) is a zero divisor by Lemma 6.2. Similarly, we find a zero divisor if the order of ww is larger than the order of zz. Thus we can assume that ww and zz have equal orders, say rtr^{t}. By looking at the elements wrt−1w^{r^{t-1}} and zrt−1z^{r^{t-1}}, both of which have order rr and they generate a cyclic group, we can find a unique 0<j<r0<j<r such that ord(wjz)<rtord(w^{j}z)<r^{t}. We now follow the method of the proof of Theorem 5.1 of [W05] to find a zero divisor in A′{\cal A}^{\prime}.

Define y′:=xjyy^{\prime}:=x^{j}y, and using (yxy−1=ζr−1x)(yxy^{-1}=\zeta_{r}^{-1}x) repeatedly we get, y′r=(xjy)r−2(xjy)(xjy)y^{\prime r}=(x^{j}y)^{r-2}(x^{j}y)(x^{j}y) =(xjy)r−3(xjy)(ζr−jx2jy2)=⋯=ζr−jr(r−1)/2xrjyr=ζr−jr(r−1)/2wjz=(x^{j}y)^{r-3}(x^{j}y)(\zeta_{r}^{-j}x^{2j}y^{2})=\cdots=\zeta_{r}^{-jr(r-1)/2}x^{rj}y^{r}=\zeta_{r}^{-jr(r-1)/2}w^{j}z. Thus if rr is odd then y′r=wjzy^{\prime r}=w^{j}z, and replacing yy with y′y^{\prime} leads to the case discussed above where the order of the new zz (i.e. wjzw^{j}z) is less than that of ww (remember that xy′=ζry′xxy^{\prime}=\zeta_{r}y^{\prime}x still holds), and we already get a zero divisor. If r=2r=2 then y′2=−wzy^{\prime 2}=-wz (j=1j=1), and the argument of the odd rr case can be repeated except when ord(−wz)ord(-wz) does not fall, i.e. orders are such that ord(wz)<ord(w)=ord(z)=ord(−wz)ord(wz)<ord(w)=ord(z)=ord(-wz). This case is only possible (recall z≠1z\neq 1) when w=z=−1w=z=-1, so x2=y2=−1x^{2}=y^{2}=-1 and y−1xy=−xy^{-1}xy=-x. Notice that in this case A′{\cal A}^{\prime} is like a ring of quaternions and we handle this case next in a standard way.

To treat this case, by Theorem 6.1 of [W05], one can efficiently find α,β∈k\alpha,\beta\in k such that α2+β2=−1\alpha^{2}+\beta^{2}=-1. Put u:=(αy+β)∈Dyu:=(\alpha y+\beta)\in{\cal D}_{y} and x′:=uxx^{\prime}:=ux. If x′∈Dyx^{\prime}\in{\cal D}_{y} then x∈u−1Dy=Dyx\in u^{-1}{\cal D}_{y}={\cal D}_{y} which is a contradiction. Thus, x′∉Dyx^{\prime}\not\in{\cal D}_{y}, in particular x′≠±1x^{\prime}\neq\pm 1. While using xy=−yxxy=-yx we can deduce that x′2=(αy+β)x(αy+β)x=(αy+β)(−αy+β)x2=(α2+β2)(−1)=1x^{\prime 2}=(\alpha y+\beta)x(\alpha y+\beta)x=(\alpha y+\beta)(-\alpha y+\beta)x^{2}=(\alpha^{2}+\beta^{2})(-1)=1. Thus (x′−1)(x^{\prime}-1) is a zero divisor. This finishes the proof of Application 1 in all cases.

In this part we briefly outline an alternative of the approach of Application 1. Formal statements and details of proofs will be subject of a subsequent paper.

Assume that A≅Mm(C){\cal A}\cong M_{m}({\cal C}) for some commutative semisimple algebra C{\cal C} over the finite field kk. As in the proof of Application 1, we use the method of [GI00] to find a maximal semisimple subalgebra D{\cal D} of A{\cal A}. Note that D{\cal D} is a free module over C{\cal C} of rank mm. Let rr be a prime divisor of mm. Then we can use the algorithm of Theorem 5.4 to find an automorphism of a subalgebra B{\cal B} of order rr in time poly(mr,log⁡∣A∣)poly(m^{r},\log|{\cal A}|). The remaining part of the proof of Application 1 can be modified so that an automorphism of prime order of a subalgebra of D{\cal D} rather than one of the whole D{\cal D} can be used to find a zero divisor in A{\cal A} in polynomial time. This way we obtain a deterministic algorithm of complexity poly(mr,log⁡∣A∣)poly(m^{r},\log|{\cal A}|) for finding a zero divisor in an algebra A{\cal A} isomorphic to Mm(C)M_{m}({\cal C}), where rr is the smallest prime divisor of mm.

Special Finite Fields: Proof of Application 4

We first show an algorithm that constructs an rr-th Kummer extension of an algebra given a prime r∣(p−1)r|(p-1). We basically generalize Lemma 2.3 of [Ró89a] to the following form:

Assume that A{\cal A} is a free module over its subalgebra B{\cal B} of rank dd. Then in time poly(log⁡∣A∣,S)poly(\log|{\cal A}|,S) we can find either a zero divisor in A{\cal A} or an element x∈A∗x\in{\cal A}^{*} with a power of rr order, for a prime r∣(p−1)r|(p-1), satisfying one of the following conditions: (1) r≠dr\neq d, x∉Bx\not\in{\cal B} and xr∈Bx^{r}\in{\cal B}, (2) r=dr=d, xr∉Bx^{r}\not\in{\cal B} and xr2∈Bx^{r^{2}}\in{\cal B},

As B{\cal B} is a completely split semisimple algebra, say of dimension nn over kk, there are orthogonal primitive idempotents f1,…,fnf_{1},\ldots,f_{n} such that fiB≅kf_{i}{\cal B}\cong k for all ii. For an i∈{1,…,n}i\in\{1,\ldots,n\}, we can project the hypothesis to the fif_{i} component, thus dim⁡kfiA=d\dim_{k}f_{i}{\cal A}=d and there are orthogonal primitive idempotents ei,1,…,ei,de_{i,1},\ldots,e_{i,d} of A{\cal A} such that fiA=ei,1A⊕⋯⊕ei,dAf_{i}{\cal A}=e_{i,1}{\cal A}\oplus\cdots\oplus e_{i,d}{\cal A}. As fif_{i} is an identity element of fiAf_{i}{\cal A} we further get that fi=(ei,1+⋯+ei,d)f_{i}=(e_{i,1}+\cdots+e_{i,d}).

Now pick an y∈A∖By\in{\cal A}\setminus{\cal B}. Suppose (for the sake of contradiction) for all 1≤i≤n1\leq i\leq n there is a single yi∗∈ky_{i}^{*}\in k that satisfies for all 1≤j≤d1\leq j\leq d, yei,j=yi∗ei,jye_{i,j}=y_{i}^{*}e_{i,j}. Then their sum gives us that y=∑i=1nyi∗fiy=\sum_{i=1}^{n}y_{i}^{*}f_{i}, as each yi∗fi∈By_{i}^{*}f_{i}\in{\cal B} we further get that y∈By\in{\cal B}. This contradiction shows that there is an i∈{1,…,n}i\in\{1,\ldots,n\} and distinct j,j′∈{1,…,d}j,j^{\prime}\in\{1,\ldots,d\} such that yei,j=y1ei,jye_{i,j}=y_{1}e_{i,j} and yei,j′=y2ei,j′ye_{i,j^{\prime}}=y_{2}e_{i,j^{\prime}} for some y1≠y2∈ky_{1}\neq y_{2}\in k. Let us fix these i,j,j′,y1,y2i,j,j^{\prime},y_{1},y_{2} for the rest of the proof, we do not compute them but use their existence for the correctness of the algorithm. We can assume y∈A∗y\in{\cal A}^{*} otherwise we have a zero divisor and we are done.

Note that zp−1=1z^{p-1}=1, in particular zp−1∈Bz^{p-1}\in{\cal B}. Thus we can find two, not necessarily distinct, prime divisors r1r_{1} and r2r_{2} of (p−1)(p-1) such that replacing zz with an appropriate power of it we have zr1,zr2∉Bz^{r_{1}},z^{r_{2}}\not\in{\cal B} but zr1r2∈Bz^{r_{1}r_{2}}\in{\cal B}. Either r1=r2=dr_{1}=r_{2}=d and we take (x,r)=(z,d)(x,r)=(z,d), or r1≠r2r_{1}\neq r_{2} in which case say wlog r1≠dr_{1}\neq d and we take (x,r)=(zr2,r1)(x,r)=(z^{r_{2}},r_{1}). Finally we can raise xx by a suitable power (coprime to rr) so that xx has a power of rr order together with the other properties. □\Box

For an integer mm we denote by Φm(X)\Phi_{m}(X) the mmth cyclotomic polynomial in k[X]k[X]. Let r1,…,rtr_{1},\ldots,r_{t} be the prime divisors of (p−1)(p-1). Then for a subset II of {1,…,t}\{1,\ldots,t\} we denote the product ∏i∈Iri\prod_{i\in I}r_{i} by rIr_{I}. We now give an algorithm that either finds a zero divisor in A{\cal A} or a homomorphism from an rIr_{I}-th cyclotomic extension onto A{\cal A}.

Let B<A{\cal B}<{\cal A}. Assume that we are also given a surjective homomorphism from k[X]/(ΦrI(X))k[X]/(\Phi_{r_{I}}(X)) onto B{\cal B} for some subset II of {1,…,t}\{1,\ldots,t\}. Then in time poly(log⁡∣A∣,S)poly(\log|{\cal A}|,S) we can compute either a zero divisor in A{\cal A} or a subalgebra B′>B{\cal B}^{\prime}>{\cal B} of A{\cal A} together with a surjective homomorphism from k[X]/(ΦrI′(X))k[X]/(\Phi_{r_{I^{\prime}}}(X)) onto B′{\cal B}^{\prime} for some subset I′⊆{1,…,t}I^{\prime}\subseteq\{1,\ldots,t\}.

We may clearly assume that A{\cal A} is a free module (of rank dd) over B{\cal B}. Let the prime rr and the element x∈A∗x\in{\cal A}^{*} be the result of an application of the algorithm of Lemma 7.1. If B[x]{\cal B}[x] is a proper subalgebra of A{\cal A} then we can solve the problem by two recursive calls: first on (B[x],B)({\cal B}[x],{\cal B}) and then on (A,B[x])({\cal A},{\cal B}[x]). Thus the base case of the recursion is when A=B[x]{\cal A}={\cal B}[x]. We handle this case now. In this case clearly d≤rd\leq r.

Assume case (2) i.e. d=rd=r. We can assume A=B[xr]{\cal A}={\cal B}[x^{r}] as otherwise the subalgebra B[xr]{\cal B}[x^{r}] is a proper subalgebra of A{\cal A} and we can find a zero divisor because A{\cal A} cannot be a free module over this subalgebra (as dimBA=rdim_{\cal B}{\cal A}=r is a prime). It follows that Φr(xr)≠0\Phi_{r}(x^{r})\neq 0 because otherwise the rank of A{\cal A} as a B{\cal B}-module would be at most ϕ(r)<r\phi(r)<r, a contradiction. So we can assume xr2≠1x^{r^{2}}\neq 1 as otherwise Φr(xr)∣(xr2−1)\Phi_{r}(x^{r})|(x^{r^{2}}-1) is a zero divisor and we are done. Thus we can find a power ζ≠1\zeta\neq 1 of xr2x^{r^{2}} for which ζr=1\zeta^{r}=1. This means, in particular, that a primitive rr-th root of unity is in B{\cal B}, and we have A≅B[X]/(Xr−xr2){\cal A}\cong{\cal B}[X]/(X^{r}-x^{r^{2}}). So we get a B{\cal B}-automorphism σ\sigma of A{\cal A} that sends xr↦ζxrx^{r}\mapsto\zeta x^{r}. The automorphism σ\sigma is of order rr, is semiregular and satisfies Aσ=B{\cal A}_{\sigma}={\cal B}. We compute the element z:=∏i=0r−1xσiz:=\prod_{i=0}^{r-1}x^{\sigma^{i}}. Then zσ=zz^{\sigma}=z, therefore z∈Bz\in{\cal B}. Also, zr=∏i=0r−1(xr)σi=ζr(r−1)/2xr2z^{r}=\prod_{i=0}^{r-1}{(x^{r})}^{\sigma^{i}}=\zeta^{r(r-1)/2}x^{r^{2}}. If rr is odd then zr=xr2z^{r}=x^{r^{2}} while z≠ζixrz\neq\zeta^{i}x^{r} for all ii (z,ζi∈Bz,\zeta^{i}\in{\cal B} but xr∉Bx^{r}\not\in{\cal B}), thus (z−ζixr)(z-\zeta^{i}x^{r}) is a zero divisor of A{\cal A}, for some ii, and we are done. If r=2r=2 then z2=−x4z^{2}=-x^{4}. We use the algorithm of [Sch85] for finding a square root ww of −1-1 in kk, observe that (wz)2=x4(wz)^{2}=x^{4}. Again as wz≠±x2wz\neq\pm x^{2} (z,w∈Bz,w\in{\cal B} but x2∉Bx^{2}\not\in{\cal B}), thus (wz−x2)(wz-x^{2}) is a zero divisor of A{\cal A} and we are done.

Assume case (1) i.e. d<rd<r, with xr≠1x^{r}\neq 1. We could assume A=B[x]{\cal A}={\cal B}[x] to be a free B{\cal B}-module with the free basis {1,x,…,xd−1}\{1,x,\ldots,x^{d-1}\}, as otherwise we can find a zero divisor in B{\cal B} by Lemma 2.2. Also we can find a power ζ≠1\zeta\neq 1 of xrx^{r} for which ζr=1\zeta^{r}=1. These two facts mean that there is a well defined endomorphism ϕ\phi of A{\cal A} that maps xx to ζx\zeta x and fixes B{\cal B}. Compute the kernel J⊊AJ\subsetneq{\cal A} of this endomorphism. If JJ is nonzero then the elements of JJ are zero divisors of A{\cal A} (as ϕ\phi cannot send a unit to zero), and we are done. If JJ is zero then ϕ\phi is a B{\cal B}-automorphism of A{\cal A}, clearly of order rr. As dim⁡BA<r\dim_{\cal B}{\cal A}<r, ϕ\phi cannot be semiregular, so we get a zero divisor by Proposition 3.2 and we are done.

Finally assume again case (1) i.e. d<rd<r, with xr=1x^{r}=1. Let ψ\psi denote the given map k[X]/(ΦrI(X))k[X]/(\Phi_{r_{I}}(X)) onto B{\cal B}. If r∈Ir\in I then put y:=ψ(XrI/r)y:=\psi(X^{r_{I}/r}). Then y∈B∗∖{1}y\in{\cal B}^{*}\setminus\{1\} because XrI/r,(XrI/r−1)X^{r_{I}/r},(X^{r_{I}/r}-1) are coprime to ΦrI(X)\Phi_{r_{I}}(X) and are thus units. As xr=yrx^{r}=y^{r} but x≠xiyx\neq x^{i}y for all ii (y∈By\in{\cal B} while x∉Bx\not\in{\cal B}), we deduce that (x−xiy)(x-x^{i}y) is a zero divisor for some ii, and we are done. Assume that r∉Ir\not\in I. Let I′:=I∪{r}I^{\prime}:=I\cup\{r\} and let C=k[X]/(ΦrI′(X)){\cal C}=k[X]/(\Phi_{r_{I^{\prime}}}(X)). We now break C{\cal C} using Chinese Remaindering. Let q1q_{1} be a multiple of rr which is congruent to 1 modulo rIr_{I} and let q2q_{2} be a multiple of rIr_{I} congruent 1 modulo rr. Let X1:=Xq1X_{1}:=X^{q_{1}}, X2:=Xq2X_{2}:=X^{q_{2}} and let C1{\cal C}_{1} resp. C2{\cal C}_{2} be the subalgebras of C{\cal C} generated by X1X_{1} resp. X2X_{2}. Then C1≅k[X1]/(ΦrI(X1)){\cal C}_{1}\cong k[X_{1}]/(\Phi_{r_{I}}(X_{1})) and C2≅k[X2]/(Φr(X2)){\cal C}_{2}\cong k[X_{2}]/(\Phi_{r}(X_{2})). Let ψ1\psi_{1} be the given surjective map from C1{\cal C}_{1} onto B{\cal B} and let ψ2\psi_{2} be the map from C2{\cal C}_{2} sending X2X_{2} to xx. Let ψ′\psi^{\prime} be the map from C≅C1⊕C2{\cal C}\cong{\cal C}_{1}\oplus{\cal C}_{2} into A{\cal A} that is the linear extension of the map sending Xi=(X1i,X2i)X^{i}=(X_{1}^{i},X_{2}^{i}) to ψ1(X1i)ψ2(X2i)\psi_{1}(X_{1}^{i})\psi_{2}(X_{2}^{i}). Clearly, ψ′\psi^{\prime} is a homomorphism from C{\cal C} to A{\cal A} and is onto (as A=B[x]{\cal A}={\cal B}[x]). This finishes the proof. □\Box

Using Lemma 7.2 as an induction tool, we obtain the following.

References