<?xml-model href='http://www.tei-c.org/release/xml/tei/custom/schema/relaxng/tei_all.rng' schematypens='http://relaxng.org/ns/structure/1.0'?><TEI xmlns="http://www.tei-c.org/ns/1.0">
	<teiHeader>
		<fileDesc>
			<titleStmt><title level='a'>Rationality of four-valued families of Weil sums of binomials</title></titleStmt>
			<publicationStmt>
				<publisher>Elsevier</publisher>
				<date>09/01/2024</date>
			</publicationStmt>
			<sourceDesc>
				<bibl> 
					<idno type="par_id">10525556</idno>
					<idno type="doi">10.1016/j.jnt.2024.04.012</idno>
					<title level='j'>Journal of Number Theory</title>
<idno>0022-314X</idno>
<biblScope unit="volume">262</biblScope>
<biblScope unit="issue">C</biblScope>					

					<author>Daniel J Katz</author><author>Allison E Wong</author>
				</bibl>
			</sourceDesc>
		</fileDesc>
		<profileDesc>
			<abstract><ab><![CDATA[We investigate the rationality of Weil sums of binomials of the form W K,s u = ∑︁ x∈K ψ(x s -ux), where K is a finite field whose canonical additive character is ψ, and where u is an element of K × and s is a positive integer relatively prime to |K × |, so that x ↦ → x s is a permutation of K. The Weil spectrum for K and s, which is the family of values W K,s u as u runs through K × , is of interest in arithmetic geometry and in several information-theoretic applications. The Weil spectrum always contains at least three distinct values if s is nondegenerate (i.e., if s is not a power of p modulo |K × |, where p is the characteristic of K). It is already known that if the Weil spectrum contains precisely three distinct values, then they must all be rational integers. We show that if the Weil spectrum contains precisely four distinct values, then they must all be rational integers, with the sole exception of the case where |K| = 5 and s ≡ 3 (mod 4).]]></ab></abstract>
		</profileDesc>
	</teiHeader>
	<text><body xmlns="http://www.tei-c.org/ns/1.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xlink="http://www.w3.org/1999/xlink">
<div xmlns="http://www.tei-c.org/ns/1.0"><head n="1.">Introduction</head><p>In this paper, we assume that K is a finite field of characteristic p and order q = p n . Let &#950; = exp(2&#960;i/p). The canonical additive character of K is &#968; : K &#8594; Q(&#950;) given by &#968;(x) = &#950; Tr(x) , where Tr : K &#8594; F p with Tr(x) = x + x p + &#8226; &#8226; &#8226; + x q/p . We use s to denote an invertible exponent over K, that is, a positive integer with gcd(s, q -1) = 1. This ensures that s has a multiplicative inverse, 1/s, modulo q -1 and makes x &#8614; &#8594; x s a permutation of the field K with inverse map x &#8614; &#8594; x 1/s . For each u &#8712; K, we define</p><p>which is a Weil sum of a binomial (if u &#824; = 0) or a Weil sum of a monomial (if u = 0). When the field K and the exponent s are clear from context, we omit the superscript and write W u . Note that Weil sum values lie in Z[&#950;], the ring of algebraic integers in Q(&#950;). In fact, it is known that they lie in</p><p>or see <ref type="bibr">[Tra70,</ref><ref type="bibr">Theorem 2.3</ref>] for an earlier equivalent statement in terms of crosscorrelation of linear recursive sequences.</p><p>Theorem 1.1 <ref type="bibr">(Trachtenberg, 1970)</ref>. If K is a finite field and s is an invertible exponent over K, then W K,s u &#8712; R for every u &#8712; K.</p><p>A multiset of elements from a set X is a function &#181; from X into the nonnegative integers, where for x &#8712; X the value &#181;(x) is the frequency (number of instances) of x in the multiset. Thus, &#181; represents a normal set if and only if it maps X into {0, 1} (in which case &#181; is identified with the subset &#181; -1 ({1}) of X). The Weil spectrum for the field K and the exponent s is the multiset of values W K,s u as u runs through K &#215; . That is, the Weil spectrum is a multiset of elements from Z <ref type="bibr">[&#950;]</ref>, where a given value A &#8712; Z[&#950;] has a frequency, written N K,s A (or N A when K and s are clear from context), with</p><p>We define the value set for the field K and the exponent s, written W K,s , to be the set of distinct values in the Weil spectrum, that is,</p><p>Note that we do not record W K,s 0 in W K,s , but this value is always 0 because x &#8614; &#8594; x s is a permutation of K and &#8721;&#65025; x&#8712;K &#968;(x) = 0. The evaluation and estimation of Weil sums has been studied extensively [Klo27, DH36, Aku65, Kar67, Car78, Car79, Cou98, CP03, CP11, SV20], including special cases such as Kloosterman sums, which are of the form W K,|K|-2 u -1. Weil sums are used to count points in algebraic sets over finite fields; see, for example, Sections 7.7 and 7.11 of <ref type="bibr">[Kat19]</ref> and Section 5 of this paper. In the Kloosterman case, the Weil spectra for fields of characteristic 2 and 3 were studied in <ref type="bibr">[LW87]</ref> and <ref type="bibr">[KL89]</ref>, and Sections 7.2-7.4 of <ref type="bibr">[Kat19]</ref> describe applications of Weil spectra in information theory, which we summarize here. The Walsh spectrum of the permutation x &#8614; &#8594; x s of K is obtained from the Weil spectrum by also including the value W K,s 0 = 0. The Walsh spectrum measures the nonlinearity of the permutation, which indicates its resistance to linear cryptanalysis. The crosscorrelation spectrum of two maximum length linear recursive sequences is obtained by subtracting 1 from each value in the Weil spectrum. This crosscorrelation spectrum determines the performance of communications networks and remote sensing systems employing these sequences for modulation. Weil spectra also determine the weight distribution of certain error correcting codes, thus indicating the performance of the codes.</p><p>For a finite field K, we say that two exponents s and s &#8242; are equivalent to mean that s &#8242; &#8801; p k s &#8467; (mod q -1) for some k &#8712; Z and &#8467; &#8712; {-1, 1}; this defines an equivalence relation, and equivalent exponents produce the same Weil spectrum by [Tra70, Theorems 2.4, 2.5] (in the language of crosscorrelation), or see [Kat19, Lemmas 7.5.2, 7.5.6] 1 . We say that s is degenerate over K to mean that it is equivalent to 1, that is, s is a power of p modulo q -1. If K has four or fewer elements, then all exponents are degenerate over K; larger finite fields always have at least one nondegenerate exponent (see <ref type="bibr">[Kat19,</ref><ref type="bibr">Lemma 7.5</ref>.4]). If s is degenerate, then W K,s = {0, q} if q &gt; 2 and W K,s = {q} if q = 2; see <ref type="bibr">[Kat19,</ref><ref type="bibr">Corollary 7.5.5</ref>].</p><p>We say the Weil spectrum for K and s is v-valued (resp., at least vvalued, at most v-valued ) to mean that |W K,s | = v (resp., |W K,s | &#8805; v, |W K,s | &#8804; v). Thus, Weil spectra of degenerate exponents are at most 2valued, and Helleseth showed that Weil spectra of nondegenerate exponents are always at least 3-valued in [Hel76, Theorem 4.1].</p><p>Theorem 1.2 <ref type="bibr">(Helleseth, 1976)</ref>. Let K be a finite field and s be an invertible exponent over K. Then the Weil spectrum for K and s is at least 3-valued if and only if s is nondegenerate over K.</p><p>There is much interest in which pairs (K, s) produce Weil spectra with few values (e.g., 3-valued or 4-valued spectra). All known 3-valued spectra have been classified into ten infinite families (see <ref type="bibr">[Kat19,</ref><ref type="bibr">Table 7</ref>.1]), and 4-valued spectra have been studied in [Nih72, Theorems 3-6, 3-7], [Hel76, Theorem 4.13], [Dob98, Proposition 1], [HR05, Theorem 6], [DFHR06, Theorem 23], [ZLFG14, Theorem II.5], and [XHW14, Theorem 1]. Although each Weil sum value is always an algebraic integer in some cyclotomic extension of Q, one observes that Weil spectra with few distinct values often have all of their values in Z. We say that the Weil spectrum for K and s is rational (or that W K,s is rational) to mean W K,s &#8838; Z. Helleseth proved a simple criterion for rationality in [Hel76, Theorem 4.2].</p><p>Theorem 1.3 <ref type="bibr">(Helleseth, 1976)</ref>. Let K be a finite field of characteristic p and s be an invertible exponent over K. Then the Weil spectrum for K and s is rational if and only if s &#8801; 1 (mod p -1).</p><p>Later, in [Kat12, Theorem 1.7], it was proved that 3-valued Weil spectra are invariably rational.</p><p>Theorem 1.4 <ref type="bibr">(Katz, 2012)</ref>. Let K be a finite field and s be an invertible exponent over K. If the Weil spectrum for K and s is 3-valued, then it is rational.</p><p>Thus, in view of Theorem 1.3, when K is a field of characteristic p and s &#824; &#8801; 1 (mod p -1), the Weil spectrum for K and s cannot be 3-valued. Katz and Langevin set an open problem [KL16, Problem 3.6], part of which is to find an analogue of Theorem 1.4 for 4-valued spectra. The main result of this paper is this analogue, which we now state.</p><p>1 Lemma 7.5.6 of <ref type="bibr">[Kat19]</ref> has a typographical error: a 1/d should be fixed to read a -1/d there.</p><p>Theorem 1.5. Let K be a finite field and s be an invertible exponent over K. If the Weil spectrum for K and s is 4-valued, then it is rational unless K = F 5 and s &#8801; 3 (mod 4) (in which case W K,s = {(5 &#177; &#8730; 5)/2, &#177; &#8730; 5}).</p><p>By Theorem 1.3, this means that, other than in the exceptional case when |K| = 5 and s &#8801; 3 (mod 4), the condition s &#8801; 1 (mod p -1) is necessary for the Weil spectrum to be 4-valued. Since the Walsh spectrum of the power permutation x &#8614; &#8594; x s over K is obtained from the Weil spectrum for K and s by including W K,s 0 = 0, Theorems 1.4 and 1.5 show that all the values in a four-valued Walsh spectrum must lie in Z.</p><p>The remainder of this paper is devoted to proving Theorem 1.5. We start in Section 2 by using Galois theory and algebraic number theory to study the structure of Weil spectra. Then, in Section 3, we present some archimedean and p-adic bounds on Weil sum values. Section 4 introduces some algebraic sets over finite fields, which we then relate to Weil sums in Section 5 via a group algebra. Finally, we prove Theorem 1.5 in Section 6.</p></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head n="2.">Algebraic number theory</head><p>In this section we introduce the number systems that are used in our proof of Theorem 1.5. Algebraic number theory provides several results that constrain the structure of Weil spectra and thus help us achieve our proof.</p><p>Recall that K is a finite field of characteristic p and order q = p n , that s is a positive integer such that gcd(s, q -1) = 1, and that &#950; = exp(2&#960;i/p). We use N to denote the set of nonnegative integers and Z + to denote the set of strictly positive integers. We know that Gal(Q(&#950;)/Q) is a cyclic group of order p -1; an element of this Galois group fixes all elements of Q and maps &#950; to &#950; j for some j &#8712; F &#215; p . Let &#947; denote a primitive element of the prime subfield F p and let &#963; denote the automorphism in Gal(Q(&#950;)/Q) that maps &#950; to &#950; &#947; : note that &#963; is a generator of the Galois group. Then [Kat12, Theorem 2.1(b)] shows that &#963;(W u ) = W &#947; 1-1/s u for every u &#8712; K, where 1/s is interpreted as the multiplicative inverse of s modulo p -1. Thus, &#963; maps the value set W K,s (see (3)) to itself. From now on, we let &#964; : W K,s &#8594; W K,s be the permutation obtained by restricting &#963;, so that for every u &#8712; K, we have &#964;</p><p>where 1/s is interpreted as the multiplicative inverse of s modulo p -1.</p><p>The following result indicates important relationships between the exponent s, the characteristic p of the field K, the order of &#964; , the order of the element &#947; 1-1/s in (4), and the degree of the extension of Q generated by the values in the Weil spectrum.</p><p>Proposition 2.1. The following are all equal:</p><p>(i) the order of the permutation &#964; of W K,s , (ii) the degree, [Q(W K,s ) : Q], of the field extension of the rationals generated by W K,s , (iii) the order of &#947; 1-1/s in F &#215; p (where 1/s indicates the multiplicative inverse of s modulo p -1), and (iv) the quantity (p -1)/ gcd(p -1, s -1). Let m denote the common value of these. If p = 2, then m = 1, but if p &gt; 2, then p &#8801; 1 (mod 2m).</p><p>equals the order of the restriction to Q(W K,s ) of &#963;, which is the same as the order of &#964; . Lemma 5.3 of <ref type="bibr">[AKL15]</ref> shows that [Q(W K,s ) : Q] equals (p -1)/ gcd(p -1, s -1), which is the order of &#947; 1-1/s = (&#947; 1/s ) s-1 because &#947; has order p -1 and s is invertible modulo p -1 (since gcd(s, q -1) = 1).</p><p>If</p><p>), an extension of Q of degree (p -1)/2, and so m | (p -1)/2. &#9633; Remark 2.2. Proposition 2.1 shows that W K,s is rational when p = 2 or 3.</p><p>Recall from (2) that the frequency of a value A in the Weil spectrum is</p><p>The action of &#964; on the Weil spectrum gives us information about these frequencies.</p><p>Lemma 2.3. Suppose that &#964; has order m, and let A 0 , A 1 , . . . , A k-1 be distinct elements of W K,s that &#964; permutes in a k-cycle, that is, &#964;</p><p>kZ and let &#955; = &#947; 1-1/s , where we interpret 1/s as the multiplicative inverse of s modulo p -1. For u &#8712; U 0 and j &#8712; Z we have, by (4), that W &#955; j u = &#964; j (W u ) = &#964; j (A 0 ) = A j mod k . In particular, we have k | m since &#964; has order m. Moreover, W &#955; k u = A 0 = W u , so U 0 is a union of cosets of the subgroup &#10216;&#955; k &#10217; of the group K &#215; . Since &#955; is of order m by Proposition 2.1 and k | m, this subgroup is of order m/k, and so N A 0 = |U 0 | is a multiple of m/k. Lastly, for any j &#8712; Z, the map u &#8614; &#8594; &#955; j u provides a bijection from U 0 to U j mod k because we have seen that W &#955; j u = A j mod k for every u &#8712; U 0 , and we can similarly prove</p><p>Let f be a permutation of a finite set X. The cycle type of f is the multiset of lengths of cycles that is obtained when f is written as a composition of disjoint cycles. Note that the sum of the values in the cycle type of a permutation f is equal to the size of the set being permuted. We say that f is a single cycle to mean that f can be written as a single cycle that contains all elements of X. The next two results explore constraints on the cycle type of &#964; .</p><p>Lemma 2.4. When p = 2, the cycle type of &#964; is a collection of |W K,s | instances of 1. When p is odd, the cycle type of &#964; contains no number larger than (p -1)/2.</p><p>Proof. Let m be the order of &#964; . When p = 2, the field Q(&#950;) = Q(-1) = Q, so &#963; and &#964; are identity maps. When p is odd, Proposition 2.1 implies that m &#8804; (p -1)/2, so the desired result follows since m is the least common multiple of all the numbers in the cycle type of &#964; . &#9633; Proposition 2.5. The permutation &#964; is a single cycle if and only if K = F 2 (and then s is degenerate and &#964; is a 1-cycle).</p><p>Proof. Suppose p = 2. Lemma 2.4 shows that &#964; is a single cycle if and only if |W K,s | = 1, which happens exactly when K = F 2 (and then every exponent is degenerate and &#964; is a 1-cycle). Now suppose p is odd. Let W K,s = {A 0 , . . . , A k-1 } and suppose for a contradiction that &#964; is a single cycle. Then</p><p>Weil sum values is equal to q by [Kat12, Proposition 3.1(b)], so that kN A 0 = q -1 and</p><p>is an algebraic integer fixed by &#963; (of which &#964; is a restriction). Thus, N A 0 is a common divisor of q and q -1, and hence N A 0 = 1 and k = q -1. But then, by Lemma 2.4, we must have (p -1)/2 &#8805; k = q -1 &#8805; p -1, which is impossible. &#9633;</p></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head n="3.">Bounds on Weil sum values</head><p>In this section we discuss some archimedean and non-archimedean bounds on the Weil sum W K,s u that are used in proving the main result (Theorem 1.5). Recall that we use N to refer to the set of nonnegative integers. We use the p-adic valuation, v p . One begins with v p : Z &#8594; N &#8746; {&#8734;}, where v p (0) = &#8734; and v p (a) = max{j &#8712; N : p j | a} when a &#824; = 0. Then one extends the domain of</p><p>1); see [Lan02, Theorem 4.1], [Lan90, p. 7], and [Hel76, p. 218]. For the purposes of this paper, the most important facts about v p (which we shall use without proof) are that v p</p><p>From (1), we know that Weil sums are sums of pth roots of unity, so we first explore linear combinations of these roots.</p><p>Lemma 3.1. For any t &#8712; Q and any v &#8712; Q(&#950;), there is one and only one way to write v as a Q-linear combination of 1, &#950;, . . . , &#950; p-1 such that the coefficients sum to t.</p><p>Proof. Our claim will follow if we show that the map &#966; :</p><p>) is an isomorphism of Q-vector spaces. Since &#966; is clearly a Q-linear map between two Q-vector spaces of dimension p, it suffices to show that ker(&#966;) is trivial. Let pr 1 :</p><p>0, we know that pr 1 &#8226;&#966; is surjective, which makes ker(pr 1 &#8226;&#966;) equal to the 1-dimensional space span Q {(1, 1, . . . , 1)}. Then ker(&#966;) is a subspace of ker(pr 1 &#8226;&#966;), but (pr 2 &#8226;&#966;)(1, 1, . . . , 1) &#824; = 0, so ker(&#966;) must be trivial. &#9633;</p><p>Now we shall apply the previous result to obtain an archimedean bound on nondegenerate Weil sums. Recall that we let K be a finite field with characteristic p and order q = p n and that s is a positive integer with gcd(s, q -1) = 1. Lemma 3.2. For any u &#8712; K, there exist unique w 0 , . . . , w p-1 &#8712; N with</p><p>Proof. By definition (1), a Weil sum W u is a sum of q terms from the set</p><p>The uniqueness of this representation follows from Lemma 3.1. Note that w 0 &gt; 0 because one term in</p><p>When s is nondegenerate, [Kat12, Theorem 2.1(f)] tells us |W u | &lt; q, which makes it impossible for w i = q for any i (else</p><p>The next two results explore p-adic bounds on Weil sums.</p><p>Proof. This is [Kat12, Theorem 2.1(e)]. For an equivalent version in terms of crosscorrelation, see <ref type="bibr">[Hel76,</ref><ref type="bibr">Theorem 4.5]</ref>.</p><p>, where w 0 , . . . , w p-1 are nonnegative integers that are strictly less than q with &#8721;&#65025; 0&#8804;i&lt;p w</p><p>, where each r i = w i /q is a nonnegative rational number strictly less than 1 with &#8721;&#65025; 0&#8804;i&lt;p r i = 1. Then we write r as &#8721;&#65025; 0&#8804;i&lt;p-1 (r i -r p-1 )&#950; i , which is the unique Q-linear combination of 1, &#950;, . . . , &#950; p-2 equal to r, and since r &#8712; Z[&#950;], the coefficients r i -r p-1 are all in Z. Since 0 &#8804; r i &lt; 1 for every i, this forces r 0 = &#8226; &#8226; &#8226; = r p-1 , so that r = 0, and then W u = 0. &#9633; Recall from Section 2 that &#947; is a primitive element of the prime subfield F p and &#963; is the generator of Gal(Q </p><p>where &#951; is the quadratic character (Legendre symbol) of F &#215; p . Lemma 3.5. Suppose that p &#8801; 1 (mod 4). An expression of the form &#8721;&#65025; i&#8712;Fp w i &#950; i with rational coefficients w i lies in Q( &#8730; p) if and only if, for every i, j &#8712; F p , we have w i = w j when &#951;(i) = &#951;(j). In this case, if we write w + for the common value of the w i 's with &#951;(i) = +1 and w -for the common value of the w i 's with &#951;(i) = -1, then our sum becomes</p><p>and only if it is fixed by &#963; 2 , that is, if and only if &#8721;&#65026; i&#8712;Fp</p><p>and then Lemma 3.1 tells us that this happens if and only if w i = w &#947; -2 i for every i &#8712; F p , which is true if and only if w i = w j whenever j &#8712; i &#10216;&#65025; &#947; 2 &#10217;&#65025; , i.e., whenever &#951;(i) = &#951;(j). In this case, write w + and w -as in the statement of this lemma, and then our sum becomes</p><p>where the penultimate summation is clearly -1 and the ultimate one is the quadratic Gauss sum (5). &#9633;</p><p>We now apply the previous result to Weil sums.</p><p>Lemma 3.6. Let p be a prime with p &#8801; 1 (mod 4) and suppose that s is an invertible exponent over K. Any Weil sum W K,s u in Q( &#8730; p) can be written uniquely in the form (I + J &#8730; p)/2, where I, J &#8712; Z. Furthermore, I &#8801; J (mod 2) and v p (I) &#8805; 1. If s is nondegenerate, then -q &lt; -2(q-1)/(p-1) &lt; I &lt; 2q and |J| &#8804; 2(q -1)/(p -1) &lt; q.</p><p>Proof. From Lemmas 3.2 and 3.5, it follows that any Weil sum in Q( &#8730; p) can be written as</p><p>where w 0 , w + , w -&#8712; Z. Thus, if we let I = 2w 0 -(w + + w -) and J = w + -w -, then I, J &#8712; Z and our Weil sum is (I + J &#8730; p)/2; since {1, &#8730; p} is Q-linearly independent, the I and J are uniquely determined. Since J &#8712; Z, we know that v p (J &#8730; p) has strictly positive p-adic valuation, as does the entire Weil sum (by Lemma 3.3), and so v p (I) must be a strictly positive integer. Note also that I &#8801; J (mod 2) since, as we stated in the paragraph before Lemma 3.5, algebraic integers in</p><p>where a, b &#8712; Z and a &#8801; b (mod 2). From now on, let us suppose that s is nondegenerate. Then by Lemma 3.2, we know that w 0 , w + , w -are all nonnegative integers that are strictly less than q with w 0 &#8805; 1 and w 0 + (w + + w -)(p -1)/2 = q. Thus,</p><p>)&#65027; , and since w 0 &lt; q, we know that w + + w -&gt; 0, so -2</p><p>where since p -1 &gt; 2, we have 2(q -1)/(p -1) &lt; q -1 &lt; q. &#9633;</p></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head n="4.">Algebraic sets over finite fields</head><p>In this section, we study a certain type of algebraic set over the finite field K. It turns out that these sets are closely related to sums of products of Weil sum values (as we shall see in Section 5), and thus will help us prove our main result (Theorem 1.5).</p><p>Recall that K is a finite field of characteristic p and order q = p n and that s is a positive integer such that gcd(s, q -1) = 1. First, we introduce two notations that enable us to express our algebraic sets very compactly.</p><p>The next four results relate various values of Q t a,b with each other.</p><p>Lemma 4.3. For any k &#8712; Z + , any t &#8712; (K &#215; ) k , and any b &#8712; K we have</p><p>The second summation counts the points in the hyperplane t &#8226; v = b in K k , while the first sum counts points with &#8741;v&#8741; s s = b s , which has the same cardinality because x &#8614; &#8594; x s is a permutation of K.</p><p>Proof. Lemma 4.4 shows that Q t a,0 (resp., Q t 0,a ) has the same value for every a &#8712; K &#215; , so (6) and the b = 0 case of (7) follow from Lemma 4.3. The b &#824; = 0 case of (7) then similarly follows from Lemma 4.3, using (6). &#9633; Lemma 4.6. For any k &#8712; Z + , any b, t 1 , . . . , t k &#8712; K &#215; , and any a &#8712; K, we have</p><p>Proof. For the rest of this proof, let t = (t 1 , . . . , t k ) and t &#8242; = (a/b, t 1 , . . . , t k ), and let u and v &#8242; be shorthand for (u 1 , . . . , u k ) and (v 0 , v 1 , . . . , v k ), respectively. Then</p><p>, where the second equality uses the reparameterization with u j = -bv j /v 0 for j &#8712; {1, . . . , k} and the fact that the invertibility of s makes (-1) s = -1. &#9633; Now we compute certain values of Q t a,b that will be useful later. Lemma 4.7. Let t 1 , t 2 &#8712; K &#215; and let &#948; denote the Kronecker delta.</p><p>Proof. The first claim is clear because</p><p>a,b counts the number of v 1 &#8712; K such that t 1 v 1 = a and (v s 1 ) 1/s = b. Applying this result to the fact that</p><p>0,0 by Lemma 4.6 gives the expression in the first case of the second claim, and then the second case follows from using Lemma 4.5 to deduce the value of</p><p>We explore certain special values of Q t a,b that are critical for our proof of Theorem 1.5.</p><p>The first result follows from the observation that (x 1 , x 2 ) &#8712; K 2 satisfies the system of equations corresponding to Q</p><p>(1,-1) 1,w if and only if (-x 2 , -x 1 ) satisfies the system of equations corresponding to Q</p><p>1,-1 counts how many (x 1 , x 2 ) &#8712; K 2 satisfy x 1 + x 2 = 1 and x s 1 + x s 2 = (-1) s , and since these equations preclude x 2 = 0 in odd characteristic, we can reparameterize with x 2 = -1/y for y &#8712; K &#215; and eliminate x 1 to see that Q</p><p>(1,1) 1,-1 is the same as the number of y &#8712; K &#215; such that (y + 1)</p><p>For the third result, note that the system of equations that corresponds to Q</p><p>(1,1) 1,w is symmetric in both unknowns, so (x 1 , x 2 ) satisfies this system if and only if (x 2 , x 1 ) does. This implies that Q</p><p>(1,1) 1,w is even except when there is some x &#8712; K such that 2x = 1 and 2 1/s x = w, which happens exactly when p is odd, x = 1/2, and w = 2 1/s-1 . &#9633;</p></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head n="5.">Group algebra</head><p>In this section, we use a group algebra that gives us a convenient way to encapsulate all the Weil spectrum values in a single object; this builds upon the methods of Feng <ref type="bibr">[Fen12]</ref> and developments in <ref type="bibr">[Kat15]</ref>. After introducing the relevant group algebra here, we define the key group algebra elements of interest in Section 5.1 and demonstrate their relation to the cardinalities of algebraic sets studied in Section 4. Then we present other related group algebra elements designed to have a particular symmetry in Section 5.2, and focus on a particularly important case of this symmetry in Section 5.3.</p><p>Let L = Q(&#950;, &#958;), where &#958; = exp(2&#960;i/(q -1)), and consider the group L-algebra L[K &#215; ], whose elements are of the form S = &#8721;&#65025; u&#8712;K &#215; S u [u], where S u &#8712; L for each u &#8712; K &#215; . We write the elements of K &#215; in brackets to distinguish them from similar-appearing elements in L. We identify any subset</p><p>. Below, we record some easily proved observations. Lemma 5.1. For any S, T &#8712; L[K &#215; ] and any t &#8712; Z, we have</p><p>Let K &#215; y denote the group of multiplicative characters from K &#215; to L &#215; . The identity element of K &#215; y is called the principal character and is written &#967; 0 ; it maps every element of K &#215; to 1. We define the application of a multiplicative character &#967; &#8712; K &#215; y to a group algebra element</p><p>and we call &#967;(S) the Fourier coefficient of S at &#967;. The following facts, which we record without proof, are easy to verify.</p><p>Lemma 5.2. The following facts hold for any S, T &#8712; L[K &#215; ] and any &#967; &#8712; The next lemma follows from Theorem 5.4 of <ref type="bibr">[LN97]</ref>.</p><p>Lemma 5.3. We have</p><p>The next result says that a group algebra element is determined by its Fourier transform.</p><p>Proof. This follows from the fact that the Fourier transform (the map from</p><p>) is an isomorphism of L-algebras with the inverse map</p><p>where</p><p>and</p><p>and when the field K and the exponent s are clear from context, we simply write</p><p>. We now relate W to &#936;.</p><p>Lemma 5.5. We have</p><p>from which the result follows. &#9633;</p><p>Let &#967; &#8712; K &#215; y . Then the Gauss sum G(&#967;) is given by &#8721;&#65025; u&#8712;K &#215; &#968;(u)&#967;(u). Note that G(&#967;) = &#967;(&#936;). We list some useful facts about Gauss sums, which will be useful later when we calculate the Fourier transform of group algebra elements that generalize W . Lemma 5.6. Let &#967; 0 be the principal character and &#967; &#8712; K &#215; y . Then (i)</p><p>&#8730; q for &#967; &#824; = &#967; 0 , and</p><p>Proof. For a proof of the first and second parts, see [LN97, Theorem 5.11]; for a proof of the third part, see [LN97, Theorem 5.12(iii)]. &#9633;</p><p>We record two more useful calculations concerning &#936; and W .</p><p>Lemma 5.7. If t &#8712; Z and gcd(t, q -1) = 1, then</p><p>Proof. The first result follows from Lemmas 5.5, 5.1, and 5.6, which give us</p><p>The second is proved as follows:</p><p>where the third equality uses Lemmas 5.7 and 5.1, and the fourth equality uses Lemmas 5.1 and 5.6. &#9633;</p><p>The proof of our main result requires us to use generalizations of W whose coefficients are products of Weil sum values rather than individual ones. We introduce a convenient notation for these. Notation 5.9. Let k &#8712; Z + and let t = (t 1 , t 2 , . . . , t k ) &#8712; (K &#215; ) k . We write</p><p>Often, we just write W [t 1 ,...,t k ] instead of W [(t 1 ,...,t k )] and W</p><p>[t]</p><p>u for (W [t] ) u . Also, note that W [1] = W . Lemma 5.10 and Proposition 5.13 below make a connection between the group algebra elements just defined in Notation 5.9 and the cardinalities of algebraic sets defined in Notation 4.2. The connecting object is defined in Notation 5.11. Lemma 5.10. Let k &#8712; Z + and let t = (t 1 , . . . , t k ) &#8712; (K &#215; ) k . Then</p><p>Proof. This is Lemma 7.7.2 of <ref type="bibr">[Kat19]</ref>. &#9633;</p><p>Recall the notations &#8226; and &#8741;&#8226;&#8741; s from Notation 4.1, which we use for the rest of this section. Notation 5.11. Let k &#8712; Z + and let t = (t 1 , t 2 , . . . , t k ) &#8712; (K &#215; ) k . Then, adopting the convention that [0] is the 0 of the group algebra L[K &#215; ], we write</p><p>We often write V [t 1 ,...,t k ] instead of V [(t 1 ,...,t k )] and use the notation</p><p>The following calculation is needed for our proof of Proposition 5.13, which connects W [t] to V [t] . Lemma 5.12. Let k &#8712; Z + and t &#8712; (K &#215; ) k . Then</p><p>Proof. The first equality comes from using Notation 5.11 to write</p><p>and then applying Lemma 4.3. The second equality then follows from Lemma 4.5. &#9633;</p><p>Now we show the relation between V [t] and W [t] .</p><p>Proposition 5.13. For k &#8712; Z + and t &#8712; (K &#215; ) k , we have</p><p>Proof. Since both sides of this equation are elements of L[K &#215; ], it suffices to show that &#967;(W [t] ) = &#967;(W V [t] ) for all &#967; &#8712; K &#215; y by Lemma 5.4. For the principal character &#967; 0 we have</p><p>where the first and last equalities follow from Lemma 5.2, the second comes from Lemmas 5.8 and 5.12, and the third comes from Lemma 5.10. Now let &#967; be any non-principal character. On one hand, we have</p><p>where we use Lemma 5.3 to impose t &#8226; x &#824; = 0 following the second equals sign, and we use the Gauss sum in the third and second-to-last equalities and the reparameterization w = z 1/s , x = z 1/s v in the fourth equality.</p><p>On the other hand, Lemmas 5.5, 5.2, 5.3, and Notation 5.11 give us</p><p>where</p><p>by Lemmas 5.6 and 5.2, so the result is proved. &#9633;</p><p>For future convenience, we explicitly calculate some values of |W [t] | and V [t] . Lemma 5.14. For any t 1 , t 2 , t 3 &#8712; K &#215; , we have</p><p>Proof. The first result is from Lemma 5.8. Next, we use Theorem 1.1 and Lemma 5.8 to obtain</p><p>For (iii), we use Theorem 1.1 to show that</p><p>)&#65025; 1/t 3 . Then, Lemmas 5.13 and 5.8 and Notation 5.11 give us that</p><p>Lastly, we observe that</p><p>) 1 , so the fourth result follows from Lemmas 5.13 and 5.8, which tell us that</p><p>, then we have</p><p>that is,</p><p>u &#8805; -1 for every u &#8712; K &#215; , and if</p><p>u &#8805; 0 for every u &#8712; K &#215; . Furthermore,</p><p>Proof. These facts follow from Notation 5.11 and Lemma 5.12, as well as the formula for Q t 1,0 found in Lemma 4.7 and the fact that Q t 1,u values are always nonnegative, since they count solutions to systems of equations. &#9633; 5.2. Symmetrized Weil sums. In later sections we study Weil spectra where there is a symmetry among the Weil sums W K,s u . Here we present some general results.</p><p>Fix some k &#8712; Z + and suppose that p &#8801; 1 (mod k). Then we let</p><p>where &#955; is a primitive kth root of unity in F &#215; p . We also let</p><p>We call &#8486; u = &#8721;&#65025; k-1 i=0 W &#955; i u the k-laterally symmetrized Weil sum at u, and we use the word bilateral to mean 2-lateral. Note that &#8486; has real coefficients by Theorem 1.1. First, we relate &#8486; to W and T . Lemma 5.16. We have &#8486; = W T .</p><p>Proof. Reordering the sums in the definition of &#8486; gives us</p><p>We compute power moments for &#8486;.</p><p>Lemma 5.17. We have (i)</p><p>). Proof. The first equation comes from the fact that |K &#215; | = q -1. The second and third results follow from Lemmas 5.16 and 5.8 as well as the fact that the coefficients of &#8486; are real, so that</p><p>so the desired result follows from Lemma 5.14(iii). &#9633; When p is odd and k = 2, we have further results, which we explore in the next section. 5.3. Bilateral symmetry in the group algebra. In Propositions 6.4 and 6.5 below we study bilaterally symmetrized Weil sums. Here, we present some general results that hold in this situation. To this end, suppose that p is odd and let</p><p>Note that this use of T and &#8486; is consistent with the notation introduced in Section 5.2 when k = 2. Also, note that &#934;, &#8486;, and &#933; have real coefficients by Theorem 1.1. For convenience of notation, we set</p><p>We relate the various group algebra elements that we have just defined.</p><p>Lemma 5.18. We have &#934; = W S and &#933; = W (T V -2U ).</p><p>Proof. These results come from the above notation and Proposition 5.13. &#9633;</p><p>Before we prove further results, we shall restate in the notation of this section a few key facts that we have proved earlier.</p><p>Lemma 5.19. We have</p><p>Proof. Part (i) follows from the definitions of U and V and Lemma 5.15. Then, using the result in part (i) and the assumption that p is odd, parts (ii) and (iii) follow from the first two parts of Lemma 4.8. Lastly, the part (iv) comes from Lemma 5.15. &#9633;</p><p>We compute some power moments for &#934; and a related sum that involves both &#934; and &#8486;.</p><p>Lemma 5.20. We have</p><p>), and (iv)</p><p>Recall that &#934; and &#933; have real coefficients.</p><p>To prove the first part, we use Lemmas 5.18 and 5.1(iv) to get |&#934;| = |W ||S| = 0. The second part follows from Lemmas 5.18, 5.8, and 5.1(vii), which give us &#8721;&#65025; u&#8712;K &#215; &#934; 2 u = (&#934;&#934;) 1 = (W SW S) 1 = q 2 (SS) 1 = 2q 2 . We can prove the third part by observing that &#8721;&#65025; u&#8712;K &#215; &#934; 2 u &#8226; &#8486; u = (&#933; &#8226; &#8486;) 1 and then using Lemmas 5.18, 5.16, 5.8, and 5.19(iii) to get that</p><p>). The fourth and final part is a consequence of Lemmas 5.1(vii) (using the fact that all coefficients in our group algebra elements here are real), 5.18 and 5.8, since we have</p></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head n="6.">Cyclotomic actions on value sets of size four</head><p>In this section, we examine the action on the value set W K,s (see (3)) of &#964; , the restriction of the generator &#963; of Gal(Q(&#950;)/Q) to W K,s . We shall prove our main theorem (Theorem 1.5), which is: Theorem 6.1. Let K be a finite field and s be an invertible exponent over K. If the Weil spectrum for K and s is 4-valued, then it is rational unless K = F 5 and s &#8801; 3 (mod 4) (in which case W K,s = {(5 &#177; &#8730; 5)/2, &#177; &#8730; 5}).</p><p>Suppose W K,s = {A, B, C, D}, where A, B, C, and D are distinct. Recall that &#963; is a generator of Gal(Q(&#950;)/Q) and that &#964; is the restriction of &#963; to W K,s . We saw in (4) that &#964; always permutes the elements of W K,s , so here &#964; must act trivially, as a transposition (while keeping two values fixed), as a composition of two disjoint transpositions, as a 3-cycle (while keeping one value fixed), or as a 4-cycle on the set {A, B, C, D}. We shall address each of the non-trivial actions in the next four propositions, and then finally prove the theorem. Throughout this section, we shall use the notation (from (2) in the Introduction) where N K,s A (or simply N A ) denotes the frequency of a value A in the Weil spectrum for the field K and the exponent s. Step 1. The exponent s is nondegenerate.</p><p>Proof. This is from Theorem 1.2.</p><p>Step 2. We have p &#8801; 1 (mod 6), so p &#8805; 7, and there is a primitive third root of unity &#955; &#8712; F &#215; p such that &#964; (W u ) = W &#955;u for all u &#8712; K &#215; . Proof. This is from Proposition 2.1 and (4), since &#964; has order 3.</p><p>Step 3. We have 3</p><p>Proof. This is from Lemma 2.3, since &#964; has order 3, permutes A in a 1-cycle, and permutes B, C, D in a 3-cycle.</p><p>Step 4. Let X = 3A and Y = B + C + D. Then X and Y are rational integers with 3 | X and 3q 2 -3q(X + Y ) + (q -1)XY = 0.</p><p>(9)</p><p>Proof. We know that A and Y are in Z because &#963; (of which &#964; is a restriction) fixes both of these algebraic integers. Thus, X is a rational integer with 3 | X. By Step 2, we can let &#8486; u = W u +W &#955;u +W &#955; 2 u = W u +&#964; (W u )+&#964; 2 (W u ) for all u &#8712; K &#215; , as in Section 5.2 (with k = 3). Notice that &#8486; u only assumes two values as u runs through K &#215; , namely X = 3A (N A times) and Y = B+C+D (3N B times by Step 3). This means that &#8721;&#65025; u&#8712;K &#215; (&#8486; u -X)(&#8486; u -Y ) = 0, so we obtain (9) from the first three results in Lemma 5.17.</p><p>Step 5. We have max{v p (X), v p (Y )} &#8805; v p (q). Proof. If max{v p (X), v p (Y )} &lt; v p (q), then v p ((q -1)XY ) &lt; v p (3q 2 -3q(X + Y )), contradicting (9) in Step 4.</p><p>Step 6. We have 0 / &#8712; {X, Y }.</p><p>Proof. We assume 0 &#8712; {X, Y } to show contradiction. Then {X, Y } = {0, q} by (9). Now q is a power of the prime p with p &#8805; 7 (by Step 2), but X is a rational integer with 3 | X (by Step 4), so we cannot have X = q. Thus, X = 3A = 0 and Y = B +C +D = q. Since s is nondegenerate by Step 1, we have |B|, |C|, |D| &lt; q by Lemma 3.2, so that B + C + D = q makes at least two of B, C, D positive, while [AKL15, Corollary 2.3] makes at least one negative, and so BCD &lt; 0. Now Lemma 5.14(iii) gives us</p><p>. Recalling the relation involving &#964; and &#955; from Step 2, this means that</p><p>. Then in view of the fact that W K,s = {A, B, C, D} with &#964; (B) = C, &#964; (C) = D, and &#964; (D) = B, and since we have shown that A = 0 here and</p><p>= -1, and hence 3N B BCD = -q 2 . But BCD &#8712; Z since it is an algebraic integer fixed by &#964; , which is a restriction of &#963;, the generator of Gal(Q(&#950;)/Q). This means that 3 | q 2 , contradicting p &#8805; 7 from Step 2.</p><p>Step 7. We have v p (X) &lt; v p (q) and v p (Y ) &#8805; v p (q). Proof. Recall from Step 4 that X = 3A. Therefore, by Step 2 we have v p (X) = v p (3A) = v p (A), and then by Step 6 and Lemma 3.4, we know that v p (A) &lt; v p (q). Thus v p (X) &lt; v p (q) and so by Step 5 we know that v p (Y ) &#8805; v p (q).</p><p>Step 8. We have Y = rq for some r &#8712; {&#177;1, &#177;2}.</p></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head>Proof. Recall from</head><p>Step 4 that Y = B + C + D. By Steps 6 and 1 combined with Lemma 3.2, we know that 0 &lt; |Y | = |B + C + D| &lt; 3q. Thus, 0 &lt; |Y | &lt; pq by Step 2. Now Step 4 shows that Y &#8712; Z, so by Step 7 we have v p (Y ) = v p (q). Then Y = rq for some r &#8712; Z and recall that 0 &lt; |Y | &lt; 3q.</p><p>Step 9. We conclude that &#964; does not permute W K,s as a 3-cycle.</p><p>Proof. We rule out each of the four possible values of r in Step 8 using the following formula for X &#8712; Z, which comes from (9) and Y = rq:</p><p>(note that the denominator is not zero because q -1 &#8805; p -1 &#8805; 6 by Step 2). If r = 1, then X = 0, which contradicts Step 6. If r = -2 (resp., -1, 2), then (10) becomes 4+(q-4)/(2q+1) (resp., 6-12/(q+2), 1+(q+5)/(2q-5)). None of these expressions can be a rational integer, since q is a power of some prime p &#8805; 7 by Step 2, so Step 4 is contradicted. &#9633; Proposition 6.4 (Action as a composition of two disjoint 2-cycles).</p><p>The following are equivalent: (i) |W K,s | = 4 and &#964; permutes W K,s as a composition of two disjoint transpositions; (ii) q = 5 and s &#8801; 3 (mod 4). When these hold, W K,s = {(5 &#177; &#8730; 5)/2, &#177; &#8730; 5}.</p><p>Suppose that q = 5 and s &#8801; 3 (mod 4). In fact, we may assume s = 3 since W K,s &#8242; = W K,s &#8242;&#8242; if s &#8242; &#8801; s &#8242;&#8242; (mod q -1) (see the definition of equivalent exponents in Section 1). Let &#950; = e 2&#960;i/5 . The polynomial x 3 -x represents 0 thrice and each of &#177;1 only once over K = F 5 , and so W K,s</p><p>)/2 by Lemma 3.5. Similarly, x 3 -2x represents 0 once and each of &#177;1 twice over K; x 3 -3x represents 0 once and each of &#177;2 twice; and x 3 -4x represents 0 three times and each of &#177;2 once over K, so we can calculate that W K,s</p><p>, it is clear that &#964; acts on W K,s as a product of two disjoint transpositions. Now suppose that |W K,s | = 4 and suppose that &#964; acts on W K,s as a composition of two disjoint transpositions. For clarity, the remainder of the proof is broken up into steps.</p><p>Step 1. We have p &#8801; 1 (mod 4), so p &#8805; 5, and &#964; (W u ) = W -u for all u &#8712; K &#215; .</p><p>Proof. This is from Proposition 2.1 and (4), since &#964; has order 2.</p><p>Step 2. We write W K,s = {A, B, C, D} with Proof. Since &#964; has order 2 and since Step 1 tells us that p &#8801; 1 (mod 4), Proposition 2.1 shows that the elements of W K,s are algebraic integers in Q( &#8730; p), the unique degree 2 extension of Q that lies in Q(&#950;). Thus, each element of W K,s has the form described in Lemma 3.6, and the four elements consist of two pairs of Galois conjugates because of the action of &#964; . This establishes the existence of the integers E, F , G, and H which are used to describe our four elements of W K,s above (making sure to arrange so that v p (E) &#8804; v p (G)), and we also name the elements A, B, C, and D as above, so that the Galois conjugate pairs are {A, B} and {C, D}; this means that &#964; must act as (AB)(CD).</p><p>Step 3. We have</p><p>Proof. This is due to Lemma 2.3 since &#964; = (AB)(CD) from Step 2.</p><p>Step 4. We have the following equations:</p><p>Proof. For u &#8712; K &#215; , let &#8486; u = W u + W -u and &#934; u = W u -W -u . This is consistent with the notation we introduced in Section 5.2 (with k = 2) and in Section 5.3 since p &#8801; 1 (mod 2) by Step 1. Thus, by Step 1, we have</p><p>As we run through u &#8712; K &#215; , Steps 2 and 3 tell us that &#8486; u has</p><p>so that (11), (12), and (13) follow from parts (i), (ii), and (iii) of Lemma 5.17 and ( <ref type="formula">14</ref>) follows from 5.20(ii). The left-hand side of Lemma 5.14(iii) (with t 1 = t 2 = t 3 = 1) is summing W 3 u over all u &#8712; K &#215; , and since N A = N B and N C = N D by Step 3, we obtain (15).</p><p>Step 5. We have G = 0.</p><p>Proof. Add EG times (11) and -(E + G) times (12) to (13) to get 0 = EG (&#65027; q -1 2</p><p>Recall from Step 2 that v p (E) &#8804; v p (G). Note that if either v p (G) &lt; v p (q) or v p (E) &gt; v p (q), then one of the terms in (16) would have strictly lower p-adic valuation than the other terms. Thus, v p (E) &#8804; v p (q) &#8804; v p (G), so that E &#824; = 0 and q | G. On the other hand, since N A , N C &#8712; Z + , (13) tells us that</p><p>, and so G = 0.</p><p>Step 6. We have E = q and N A = 1.</p><p>Proof. Since G = 0 by Step 5, (12) and (13) imply that E = q and N A = 1.</p><p>Step 7. We have N C = (q -3)/2.</p><p>Proof. Since N A = 1 by Step 6, (11) gives us that N C = (q -3)/2.</p><p>Step 8. The quantity F is odd and H = 2I for some I &#8712; Z \ {0}.</p><p>Proof. We know that G = 0 by Step 5 and E = q by Step 6. Furthermore, q is odd since p is odd by Step 1.</p><p>Step 2 tells us that E &#8801; F (mod 2) and G &#8801; H (mod 2), so F is odd and H is even. But H &#824; = 0, else C = D (see Step 2), so H = 2I for some I &#8712; Z \ {0}.</p><p>Step 9. We must have q &#8804; 5.</p><p>Proof. We can substitute the results from Steps 5-8 into (15) and ( <ref type="formula">14</ref>) to obtain</p><p>Since p &#8801; 1 (mod 4) by Step 1, we have gcd(q/p, 3) = gcd(q/p, 2(q -3)) = 1, and therefore since V</p><p>[1,1] 1</p><p>&#8712; Z, (17) and ( <ref type="formula">18</ref>) consecutively give us that (q/p) | F 2 and (q/p) | I 2 . Now we know from Step 8 that F, I &#824; = 0, so F 2 /(q/p), I 2 /(q/p) &#8805; 1. If we substitute this into (18), the equality becomes the inequality q = q 2 /p q/p = F 2 q/p + 2(q -3) &#8226; I 2 q/p &#8805; 1 + 2(q -3) = 2q -5, so that q &#8804; 5.</p><p>Step 10. We conclude that q = 5 and s &#8801; 3 (mod 4).</p><p>Proof. Steps 1 and 9 give us that an action with two disjoint transpositions can only occur when q = p = 5. We now consider the possible values for s. Since W K,s &#8242; = W K,s &#8242;&#8242; if s &#8242; &#8801; s &#8242;&#8242; (mod q -1) (see the definition of equivalent exponents in Section 1), it suffices to consider the cases when s &#8801; 0, 1, 2, 3 (mod 4). We cannot have s &#8801; 0, 2 (mod 4), for then gcd(s, q -1) = gcd(s, 4) &#824; = 1, so s would not be invertible. Nor can we have s &#8801; 1 (mod 4), for then s would be degenerate and this would make |W K,s | &#8804; 2 by Theorem 1.2. Thus s &#8801; 3 (mod 4). &#9633; Proposition 6.5 (No action as a transposition). If |W K,s | = 4, then &#964; does not permute the elements of W K,s as a transposition.</p><p>Suppose that |W K,s | = 4. Assume that &#964; permutes W K,s as a transposition to show a contradiction. For clarity, the proof of this proposition is broken into steps.</p><p>Step 1. We have p &#8801; 1 (mod 4), so p &#8805; 5, and there exist A, B, E, F &#8712; Z with |A| &#8804; |B|, F &gt; 0, and E &#8801; F (mod 2) such that W Proof. Since &#964; has order 2, we know by Proposition 2.1 that p &#8801; 1 (mod 4) and that Q(W K,s ) = Q( &#8730; p), the unique degree 2 extension of Q that lies in Q(&#950;). This means that the two elements of W K,s exchanged by &#964; are Galois conjugate algebraic integers in Q( &#8730; p), and hence can be written as</p><p>for some E, F &#8712; Z where E &#8801; F (mod 2) and F &gt; 0 by Lemma 3.6. The other two elements of W K,s are algebraic integers fixed by &#964; (and hence by &#963;), so they must be rational integers; we label these A and B in such a way that |A| &#8804; |B|. Then both N A and N B are even and N C = N D by Lemma 2.3.</p><p>Step 2. We have &#964; (W u ) = W -u for all u &#8712; K &#215; , so as in Sections 5.2 (with k = 2) and 5.3 we can let</p><p>Proof. Since Step 1 implies that &#964; has order 2 and p &#8801; 1 (mod 2), Proposition 2.1 and (4) give us that &#964; (W u ) = W -u for all u &#8712; K &#215; and we have the bilateral symmetry alluded to in Sections 5.2 (with k = 2) and 5.3.</p><p>Step 3. The integer E is odd and there exist rational integers</p><p>, (E, 2N C )} and the following equations hold:</p><p>Proof. Since N C = N D by Step 1, we observe that as u runs through</p><p>and &#8486; u = E for those u such that &#934; u &#824; = 0. Thus, we obtain (26)-(28) from Lemma 5.20(ii)-(iv). Note that (26) and Step 1 imply that E and F are odd, whereas 2A and 2B must be distinct and even, so that there are rational integers X &lt; Y &lt; Z with {X, Y, Z} = {2A, 2B, E} and we can let M X , M Y , and M Z be as stated above. Equations ( <ref type="formula">19</ref>)-( <ref type="formula">21</ref>) then follow from Lemma 5.17(i)-(iii), which we also use to prove (22) from the following observation:</p><p>and ( <ref type="formula">23</ref>) and ( <ref type="formula">24</ref>) follow similarly by exchanging the roles of X, Y , and Z.</p><p>Similarly, one can prove (25) using all parts of Lemma 5.17 (and the fact that V = V [1,1] ) from the following observation:</p><p>Step 4. We have -q &lt; -2(q -1)/(p -1) &lt; X &lt; Y &lt; Z &lt; 2q and v p (X), v p (Y ), v p (Z) &#8805; 1. If any of X, Y , or Z is nonzero, then its p-adic valuation is less than the p-adic valuation of q. If none of X, Y , and Z is zero, then v p (XY ), v p (Y Z), v p (ZX) &gt; v p (q).</p><p>Proof. The first chain of inequalities follows from Step 3 and Lemma 3.6 (which applies due to Step 1 and Theorem 1.2), once we notice that 2A, 2B, and E take the place of I in Lemma 3.6. Lemma 3.6 also tells us that v p (X), v p (Y ), v p (Z) &#8805; 1. Next, M X X 2 , M Y Y 2 , and M Z Z 2 are all even rational integers by Step 3, so if X &#824; = 0 but v p (X) &#8805; v p (q), then 2q 2 | M X X 2 , and hence M X X 2 = 2q 2 and Y = Z = 0 by (21). This contradicts Step 3. Analogous arguments show that the same result holds for Y and Z. In particular, if 0 &#824; &#8712; {X, Y, Z}, then v p (X), v p (Y ), v p (Z) &lt; v p (q). Thus, if we write (25) as</p><p>then (q -1)XY Z has a strictly smaller p-adic valuation than every other term on the right-hand side of the above equation. This implies that</p><p>and so the desired inequalities follow from subtracting one of the terms on the left-hand side from both sides.</p><p>Step 5. We have -q &lt; X &lt; Y = 0 &lt; Z &lt; q.</p><p>Proof. Recall from Step 3 that M X is a strictly positive count, so the numerator and denominator in (22) must have the same sign. Thus, to prove this step, it suffices to show that Y = 0 since -q &lt; X &lt; Y &lt; Z by Step 4, for then the numerator in (22), which is positive, becomes 2q(q -Z).</p><p>Suppose that Y &#824; = 0. By Step 3, we know that Z &gt; 0, since otherwise the right-hand side of (20) would be negative. Moreover, the numerator in ( <ref type="formula">22</ref>) is positive, that is,</p><p>Thus, using Step 4 and the fact that p &#8805; 5 from Step 1 in (29) gives us</p><p>We cannot have Y &lt; 0, for that would imply both 0 &#824; &#8712; {X, Y, Z} and v p (Y Z) &#8804; v p (q), which contradicts Step 4. So we must have Y &gt; 0. If we use the same argument, replacing ( <ref type="formula">22</ref>) with ( <ref type="formula">24</ref>), Z with Y , and Y with X, we show that X &lt; 0 is also impossible, and so obtain X &#8805; 0. If X &gt; 0, then Step 4 implies that X, Y, Z &#8805; p, so (20), ( <ref type="formula">19</ref>), and the fact that q &#8805; p &#8805; 5 by Step 1 give us the contradiction 2q &#8805; p(M X + M Y + M Z ) = p(q -1) &#8805; 5q -p &#8805; 4q. This forces X = 0 &lt; Y &lt; Z by Step 3, so that (20) and ( <ref type="formula">21</ref> </p><p>so that v p (Y ) = v p (q) + v p (Z) -v p (Z -Y ), and so v p (Z -Y ) = v p (q). In other words, q | Z -Y . Since 0 &lt; Y &lt; Z &lt; 2q by Step 4, this is only possible if Z = Y + q. If we substitute this equation for Z into (30) and (31) and solve for Y , we obtain 3Y = q, which is impossible because p &#8801; 1 (mod 4) by Step 1.</p><p>Step 6. We have E = X &lt; 0 and A = Y /2 = 0 and B = Z/2 &gt; 0. Moreover, |E| &lt; |B| and V -1 &gt; 0 and B = 2V -1 /(1 -E/q).</p><p>Proof. Recall from Step 3 that {X, Y, Z} = {2A, 2B, E} is a set of three distinct numbers and that E is odd. Since |A| &#8804; |B| by Step 1 and Y = 0 is even by Step 5, we must have 0 = Y = A and {X, Z} = {2B, E}. We obtain B = 2V -1 /(1 -E/q) by substituting these facts into (25) and using (27) (note that we can divide by 1 -E/q since Step 5 implies that |E| &lt; q). Now, since B is nonzero, 1 -E/q is positive (since |E| &lt; q), and V -1 is nonnegative (by Lemma 5.19(i)), we must have B = Z/2 is positive, and hence V -1 &gt; 0 and E = X &lt; 0. It then follows that 1 &lt; 1 -E/q &lt; 2 and V -1 &lt; B &lt; 2V -1 . Lastly, Lemma 5.19(i) tells us that V 1 &#8805; 0, so E &#8805; -V -1 by (27), and thus |E| &lt; |B|.</p><p>Step 7. There exists an odd integer m with 0 &lt; m &lt; n such that N C = p m and F = p n-(m+1)/2 . Let &#8467; = v p (B) -v p (E). Then v p (N B ) = m -2&#8467;. Moreover, we have</p><p>Proof. The results about m, N C , and F follow from (26) since N C &lt; q, while (32) and (33) come from equations ( <ref type="formula">20</ref>) and ( <ref type="formula">21</ref>) and Steps 3 and 6. Lastly, (33) implies that v p (N B B 2 ) = v p (N C E 2 ) since 2N B B 2 &gt; 0 and N C E 2 &gt; 0 by Step 6 and p &#8740; 2 by Step 1, so v p (N B ) = m -2&#8467;.</p><p>Step 8. We have &#8467; &gt; 0, and there exist &#946;, &#949;, &#957; &#8712; Z + all relatively prime to p such that B = &#946;p n-m+2&#8467; , E = -&#949;p n-m+&#8467; , and</p><p>Moreover, we have the following equations:</p><p>2&#957;&#946; -&#949;p &#8467; = 1 (35)</p><p>Proof. Steps 1, 6, and 7 allow us to write B = &#946;p vp(E)+&#8467; , N B = 2&#957;p m-2&#8467; , E = -&#949;p vp(E) , and N C = p m with &#946;, &#949;, &#957; &#8712; Z + all relatively prime to p, so that (32) and (33) become 2&#957;&#946;p m+vp(E)-&#8467; -&#949;p m+vp(E) = p n (37)</p><p>It thus suffices to show that &#8467; &gt; 0, for then m + v p (E) -&#8467; &lt; m + v p (E), and hence m + v p (E) -&#8467; = n by (37), so that v p (E) = n -m + &#8467;, and so the expressions for E and B at the beginning of this proof become those in (34) while (37) and (38) become (35) and (36). Suppose &#8467; &#8804; 0, and let g = n -m -v p (E). Then (37) and (38) become 2&#957;&#946;p -&#8467; -&#949; = p g (39)</p><p>By</p><p>Step 6, we have &#949; = |E|/p vp(E) &lt; |B|/p vp(E)+&#8467; = &#946;, so (39) gives us</p><p>and hence g &gt; 0 since &#946;, &#957; &#8805; 1. Note that this implies that &#8467; = 0, for otherwise the p-adic valuation of the left-hand side of (39) would be 0. We can thus solve (39) for &#949; and substitute the resulting expression into (40) to get 4&#946; 2 &#957;(&#957; + 1) -4&#957;&#946;p g + p 2g -p 2g+m = 0. (42)</p><p>Since g &gt; 0, the third and fourth terms on the left-hand side of (42) have strictly larger p-adic valuation than the second term does, so we must have v p (4&#946; 2 &#957;(&#957; + 1)) = v p (4&#957;&#946;p g ), that is, v p (&#957; + 1) = g. So &#957; = -1 + &#181;p g for some &#181; &#8805; 1 such that p &#8740; &#181;. But if we substitute this into p g &gt; &#946;(2&#957; -1) from (41) and rearrange to obtain an upper bound for &#181;, then (keeping in mind that p &#8805; 5 by Step 1) we obtain</p><p>which is a contradiction. We thus have &#8467; &gt; 0, as we wished.</p><p>Step 9. We have both BE -2CD = &#946;p 2n-2m+2&#8467; and C 2 + D 2 -BE = p 2n-2m+2&#8467; (p m-2&#8467; -&#946;).</p><p>Proof. These results come from using the expressions for C and D in Step 1 and those for B, E, and F in Steps 7 and 8 to write</p><p>(&#65027; p m-2&#8467; + &#949; 2 2 + &#946;&#949;p &#8467; )&#65027;</p><p>and then using (35) and (36) to simplify these expressions.</p><p>Step 10. Let S R = {u &#8712; K &#215; : W u = R} for R &#8712; W K,s . If we identify these subsets of K &#215; with group algebra elements as described before Lemma 5.1, then, using the definitions of W = W K,s from (8) in Section 5.1 and of T , U , V from Step 2, we have</p><p>Proof. The left-hand equalities follow from the definitions of T , U , and V and also Proposition 5.13 in the case of (44) and (45). The right-hand equalities follow from the fact that W -u = &#964; (W u ) (by Step 2) and the values for W u in Steps 1 and 6.</p><p>Step 11. We have &#946; = 1, so B = p n-m+2&#8467; .</p></div></body>
		</text>
</TEI>
