Fast Deterministic Normal Bases and Circulant Polynomial Determinants
Let $\mathsf{E}=\mathbb{F}_q[x]/(Γ)$ describe an algebraic extension of a finite field $\mathbb{F}_q$, where $q$ is a prime power and $Γ\in\mathbb{F}_q[x]$ is monic and irreducible of degree $n$. We give a deterministic algorithm that finds $β\in \mathsf{E}$ whose conjugates $β,β^q,\ldots,β^{q^{n-1}}$ form an $\mathbb{F}_q$-basis of $\mathsf{E}/\mathbb{F}_q$, a normal basis, using $O_ε((n^2\log q)^{1+ε})+{O\tilde{}}(n\log^2 q)$ bit operations for any $ε>0$. For $n>1$, let $θ=x\bmodΓ$, so $\mathsf{E}=\mathbb{F}_q[θ]$. A variant of a construction of Artin shows that $β_t=(θ-t)^{-1}$ is normal for all but at most $n(n-1)$ parameters $t\in\mathbb{F}_q$. We present an algorithm to construct an $n\times n$ circulant matrix over $\mathbb{F}_q[\mathcal T]$, for an indeterminate $\mathcal T$, whose determinant at $\mathcal T=t$ is non-zero precisely when $β_t$ is normal, and show this algorithm requires ${O\tilde{}}(n^2+n\log q)$ operations in $\mathbb{F}_q$. Then, as a primary subroutine, using triangular-set power projection and modular composition, we show how to compute the determinant of any $n\times n$ circulant over $\mathbb{F}_q[\mathcal T]$, given by its first row of polynomials of degree at most $m\geq1$, using $O_ε((nm\log q)^{1+ε})$ bit operations. For $q\leq n(n-1)$, we show how to embed our problem into a sufficiently large field extension, construct a normal basis there, and descend to the ground field, within the same stated cost.