具有有理预处理的多项式快速求值
Fast Evaluation of Polynomials with Rational Preprocessing
浏览论文内容
中文总结 AI 辅助
本文提出有理预处理下用约n/2次乘法求值多项式,解决Rabin-Winograd猜想,并给出特征2下的调度及通用哈希改进构造。
中文摘要 AI 辅助
霍纳法则使用$n-1$次乘法来求值一个首一$n$次多项式。我们证明,在系数经过有理预处理的情况下,在特征为零或特征$p>n$的域上,任何这样的多项式都可以仅使用$\n-1$次乘法来求值。这解决了Rabin和Winograd(Comm. Pure Appl. Math 1972)的一个猜想中的乘法次数方面,他们实现了$n/2 + 2\lceil\log_2 n\rceil$次乘法,并猜想对数开销是必要的。我们证明了这个乘法次数在一般情况下无法被超越,证明了对于次数$6$,三次乘法是不够的。这加强了Pan(STOC 1978)的下界,他证明了对于一般的复数预处理有一个紧的下界。在特征为$2$的情况下,对于每个$n>1$和每个大小至少为$2n$的有限域,我们证明一个$n$次乘法链不能参数化在$2n$个不同求值点上的所有值向量,即使有任意预处理。我们给出了特征为$2$下的$\lfloor n/2 \rfloor + 1$次乘法调度,每个调度都有显式的逆,适用于每个奇数次数$n\le 25$,并猜想这对所有$n$都是可能的。我们还给出了一个用于通用哈希的单射多项式构造,它使用$N$次乘法来用单个随机密钥哈希$2N$个值。这改进了Daniel J. Bernstein(此http URL)之前的最佳构造。
英文摘要
Horner's rule evaluates a monic degree-$n$ polynomial using $n-1$ multiplications. We show that with rational preprocessing of the coefficients, any such polynomial can be evaluated using only $\lfloor n/2 \rfloor + 1$ multiplications over fields of characteristic zero or of characteristic $p>n$. This resolves the multiplication side of a conjecture of Rabin and Winograd (Comm. Pure Appl. Math 1972), who achieved $n/2 + 2\lceil\log_2 n\rceil$ multiplications and conjectured the logarithmic overhead was necessary. We show that this multiplication count can't be beaten in general, proving that three multiplications do not suffice for degree~$6$. This strengthens the lower bound of Pan (STOC 1978), who proved a tight bound for general, complex preprocessing. In characteristic~2, for every $n>1$ and every finite field of size at least $2n$, we prove that an $n$-multiplication chain cannot parametrize all value vectors at $2n$ distinct evaluation points, even with arbitrary preprocessing. We give $\lfloor n/2 \rfloor + 1$ multiplication schedules over characteristic~2, each with an explicit inverse, for every odd degree $n\le 25$ and conjecture that this is possible for all $n$. We also give an injective polynomial construction for universal hashing that uses $N$ multiplications to hash $2N$ values with a single random key. This improves the best previous construction by Daniel J. Bernstein (cryp.to).
发表机构
- Normal Computing
- Alipes ApS
机构由 AI 辅助整理,请以论文原文为准。