In mathematics, the Lucas–Lehmer test (LLT) is a primality test for Mersenne numbers. The test was originally developed by Édouard Lucas in 1878[1] and subsequently proved by Derrick Henry Lehmer in 1930.
The Lucas–Lehmer test works as follows. Let Mp = 2p - 1 be the Mersenne number to test with p an odd prime. The primality of p can be efficiently checked with a simple algorithm like trial division since p is exponentially smaller than Mp. Define a sequence
\{si\}
si= \begin{cases} 4&ifi=0; \\
2-2 | |
s | |
i-1 |
&otherwise. \end{cases}
The first few terms of this sequence are 4, 14, 194, 37634, ... .Then Mp is prime if and only if
sp-2\equiv0\pmod{Mp}.
// Determine if Mp = 2p - 1 is prime for p > 2 Lucas–Lehmer(p) var s = 4 var M = 2p - 1 repeat p - 2 times: s = ((s × s) - 2) mod M if s
Performing the mod M
at each iteration ensures that all intermediate results are at most p bits (otherwise the number of bits would double each iteration). The same strategy is used in modular exponentiation.
Starting values s0 other than 4 are possible, for instance 10, 52, and others .[2] The Lucas-Lehmer residue calculated with these alternative starting values will still be zero if Mp is a Mersenne prime. However, the terms of the sequence will be different and a non-zero Lucas-Lehmer residue for non-prime Mp will have a different numerical value from the non-zero value calculated when s0 = 4.
It is also possible to use the starting value (2 mod Mp)(3 mod Mp)−1, usually denoted by 2/3 for short.[2] This starting value equals (2p + 1) /3, the Wagstaff number with exponent p.
Starting values like 4, 10, and 2/3 are universal, that is, they are valid for all (or nearly all) p. There are infinitely many additional universal starting values.[2] However, some other starting values are only valid for a subset of all possible p, for example s0 = 3 can be used if p = 3 (mod 4).[3] This starting value was often used where suitable in the era of hand computation, including by Lucas in proving M127 prime.[4] The first few terms of the sequence are 3, 7, 47, ... .
If sp−2 = 0 mod Mp then the penultimate term is sp−3 = ± 2(p+1)/2 mod Mp. The sign of this penultimate term is called the Lehmer symbol ϵ(s0, p).
In 2000 S.Y. Gebre-Egziabher proved that for the starting value 2/3 and for p ≠ 5 the sign is:
\epsilon({2\over3}, p)=(-1)p-1
The same author also proved Woltman's conjecture[5] that the Lehmer symbols for starting values 4 and 10 when p is not 2 or 5 are related by:
\epsilon(10, p)=\epsilon(4, p) x (-1){(p+1)(p+3)\over8}
OEIS sequence shows ϵ(4, p) for each Mersenne prime Mp.
In the algorithm as written above, there are two expensive operations during each iteration: the multiplication s × s
, and the mod M
operation. The mod M
operation can be made particularly efficient on standard binary computers by observing that
k\equiv(k\bmod2n)+\lfloork/2n\rfloor\pmod{2n-1}.
This says that the least significant n bits of k plus the remaining bits of k are equivalent to k modulo 2n-1. This equivalence can be used repeatedly until at most n bits remain. In this way, the remainder after dividing k by the Mersenne number 2n-1 is computed without using division. For example,
916 mod 25-1 | = | 11100101002 mod 25-1 | |
= | ((916 mod 25) + int(916 ÷ 25)) mod 25-1 | ||
= | (101002 + 111002) mod 25-1 | ||
= | 1100002 mod 25-1 | ||
= | (100002 + 12) mod 25-1 | ||
= | 100012 mod 25-1 | ||
= | 100012 | ||
= | 17. |
Moreover, since s × s
will never exceed M2 < 22p, this simple technique converges in at most 1 p-bit addition (and possibly a carry from the pth bit to the 1st bit), which can be done in linear time. This algorithm has a small exceptional case. It will produce 2n-1 for a multiple of the modulus rather than the correct value of 0. However, this case is easy to detect and correct.
With the modulus out of the way, the asymptotic complexity of the algorithm only depends on the multiplication algorithm used to square s at each step. The simple "grade-school" algorithm for multiplication requires O(p2) bit-level or word-level operations to square a p-bit number. Since this happens O(p) times, the total time complexity is O(p3). A more efficient multiplication algorithm is the Schönhage–Strassen algorithm, which is based on the Fast Fourier transform. It only requires O(p log p log log p) time to square a p-bit number. This reduces the complexity to O(p2 log p log log p) or Õ(p2). An even more efficient multiplication algorithm, Fürer's algorithm, only needs
plog
O(log*p) | |
p 2 |
By comparison, the most efficient randomized primality test for general integers, the Miller–Rabin primality test, requires O(k n2 log n log log n) bit operations using FFT multiplication for an n-digit number, where k is the number of iterations and is related to the error rate. For constant k, this is in the same complexity class as the Lucas-Lehmer test. In practice however, the cost of doing many iterations and other differences leads to worse performance for Miller–Rabin. The most efficient deterministic primality test for any n-digit number, the AKS primality test, requires Õ(n6) bit operations in its best known variant and is extremely slow even for relatively small values.
The Mersenne number M3 = 23−1 = 7 is prime. The Lucas–Lehmer test verifies this as follows. Initially s is set to 4 and then is updated 3-2 = 1 time:
Since the final value of s is 0, the conclusion is that M3 is prime.
On the other hand, M11 = 2047 = 23 × 89 is not prime. Again, s is set to 4 but is now updated 11-2 = 9 times:
Since the final value of s is not 0, the conclusion is that M11 = 2047 is not prime. Although M11 = 2047 has nontrivial factors, the Lucas–Lehmer test gives no indication about what they might be.
The proof of correctness for this test presented here is simpler than the original proof given by Lehmer. Recall the definition
si= \begin{cases} 4&ifi=0;\\
2-2 | |
s | |
i-1 |
&otherwise. \end{cases}
sp-2\equiv0\pmod{Mp}.
The sequence
{\langle}si{\rangle}
\omega=2+\sqrt{3}
\bar{\omega}=2-\sqrt{3}
si=
2i | |
\omega |
+
2i | |
\bar{\omega} |
s0=
20 | |
\omega |
+
20 | |
\bar{\omega} |
=\left(2+\sqrt{3}\right)+\left(2-\sqrt{3}\right)=4
\begin{align} sn &=
2 | |
s | |
n-1 |
-2\\ &=
2n-1 | |
\left(\omega |
+
2n-1 | |
\bar{\omega} |
\right)2-2\\ &=
2n | |
\omega |
+
2n | |
\bar{\omega} |
+
2n-1 | |
2(\omega\bar{\omega}) |
-2\\ &=
2n | |
\omega |
+
2n | |
\bar{\omega} |
. \end{align}
\omega\bar{\omega}=\left(2+\sqrt{3}\right)\left(2-\sqrt{3}\right)=1.
The goal is to show that
sp-2\equiv0\pmod{Mp}
Mp
Suppose
sp-2\equiv0\pmod{Mp}.
2p-2 | |
\omega |
+
2p-2 | |
\bar{\omega} |
=kMp
2p-2 | |
\omega |
=kMp-
2p-2 | |
\bar{\omega} |
.
2p | |
\omega |
2p-2 | |
\left(\omega |
\right)2=k
2p-2 | |
M | |
p\omega |
-(\omega
2p-2 | |
\bar{\omega}) |
.
2p-1 | |
\omega |
=k
2p-2 | |
M | |
p\omega |
-1. (1)
For a contradiction, suppose Mp is composite, and let q be the smallest prime factor of Mp. Mersenne numbers are odd, so q > 2. Let
Zq
X=\left\{a+b\sqrt{3}\mida,b\inZq\right\}.
X
\left(a+\sqrt{3}b\right)\left(c+\sqrt{3}d\right)=[(ac+3bd)\bmodq]+\sqrt{3}[(ad+bc)\bmodq].
Clearly, this multiplication is closed, i.e. the product of numbers from X is itself in X. The size of X is denoted by
|X|.
Since q > 2, it follows that
\omega
\bar{\omega}
|X*|.
|X*|\leq|X|-1=q2-1.
Now
Mp\equiv0\pmod{q}
\omega\inX
2p-2 | |
kM | |
p\omega |
=0
2p-1 | |
\omega |
=-1
2p | |
\omega |
=1.
\omega
2p-1 | |
\omega |
.
\omega
2p.
2p-1 | |
\omega |
≠ 1
2p-1.
2p.
The order of an element is at most the order (size) of the group, so
2p\leq|X*|\leqq2-1<q2.
Mp
q2\leqMp=2p-1.
2p<2p-1
Mp
In the other direction, the goal is to show that the primality of
Mp
sp-2\equiv0\pmod{Mp}
Since
2p-1\equiv7\pmod{12}
p>1
(3|Mp)=-1.
Mp.
| ||||
3 |
\equiv-1\pmod{Mp}.
In contrast, 2 is a quadratic residue modulo
Mp
2p\equiv1\pmod{Mp}
2\equiv2p+1=
| ||||
\left(2 |
\right)2\pmod{Mp}.
| ||||
2 |
\equiv1\pmod{Mp}.
Combining these two equivalence relations yields
| ||||
24 |
\equiv
| ||||
\left(2 |
\right)3
| ||||
\left(3 |
\right)\equiv(1)3(-1)\equiv-1\pmod{Mp}.
Let
\sigma=2\sqrt{3}
X=\{a+b\sqrt{3}\mida,b\in
Z | |
Mp |
\}.
\begin{align}
Mp | |
(6+\sigma) |
&=
Mp | |
6 |
+
Mp | |
\left(2 |
\right)
Mp | |
\left(\sqrt{3} |
\right)\\ &=6+2
| ||||
\left(3 |
\right)\sqrt{3}\\ &=6+2(-1)\sqrt{3}\\ &=6-\sigma, \end{align}
where the first equality uses the Binomial Theorem in a finite field, which is
Mp | |
(x+y) |
\equiv
Mp | |
x |
+
Mp | |
y |
\pmod{Mp}
and the second equality uses Fermat's little theorem, which is
Mp | |
a |
\equiva\pmod{Mp}
for any integer a. The value of
\sigma
\omega=
(6+\sigma)2 | |
24 |
.
| ||||
\omega |
\begin{align}
| ||||
\omega |
&=
| |||||||
|
\\ &=
| |||||||||
|
\\ &=
(6+\sigma)(6-\sigma) | |
-24 |
\\ &=-1. \end{align}
All that remains is to multiply both sides of this equation by
| ||||
\bar{\omega} |
\omega\bar{\omega}=1
\begin{align}
| ||||
\omega |
| ||||
\bar{\omega} |
&=
| ||||
-\bar{\omega} |
\\
| ||||
\omega |
+
| ||||
\bar{\omega} |
&=0\\
| ||||
\omega |
+
| ||||
\bar{\omega} |
&=0\\
2p-2 | |
\omega |
+
2p-2 | |
\bar{\omega} |
&=0\\ sp-2&=0. \end{align}
Since
sp
Mp.
The Lucas–Lehmer test is one of the main primality tests used by the Great Internet Mersenne Prime Search (GIMPS) to locate large primes. This search has been successful in locating many of the largest primes known to date.[11] The test is considered valuable because it can provably test a large set of very large numbers for primality within an affordable amount of time. In contrast, the equivalently fast Pépin's test for any Fermat number can only be used on a much smaller set of very large numbers before reaching computational limits.
Zq=Z/qZ
X=Zq[T]/\langleT2-3\rangle
\omega+\langleT2-3\rangle
\bar{\omega}+\langleT2-3\rangle
\omega
\bar{\omega}
Z[\sqrt{3}]
\sqrt{3}