---
title: Subspace Polynomials in Finite Fields
url: https://www.emergentmind.com/topics/subspace-polynomials
type: topic
---

# Subspace Polynomials in Finite Fields

In finite-field algebra, a subspace polynomial over $\mathbb{F}_{q^n}$ is a monic $q$-linearized polynomial
$$
P(x)=x^{[k]}+a_{k-1}x^{[k-1]}+\cdots+a_1x^{[1]}+a_0x,\qquad x^{[i]}:=x^{q^i},
$$
that divides $x^{[n]}-x$; equivalently, it splits completely over $\mathbb{F}_{q^n}$ into distinct roots. This notion gives an exact algebraic representation of $\mathbb{F}_q$-subspaces of $\mathbb{F}_{q^n}$, and it is used in the construction of cyclic subspace codes for random network coding as well as in repair schemes for Reed–Solomon codes [1404.7739] [2007.15253].

## 1. Definition in the finite-field setting

Let $\mathbb{F}_q$ denote the finite field of order $q$, and let $\mathbb{F}_{q^n}$ be the degree-$n$ extension field, often identified with the vector space $\mathbb{F}_q^n$. A $q$-linearized polynomial, also called a $q$-polynomial, is a polynomial of the form
$$
P(x)=a_kx^{[k]}+a_{k-1}x^{[k-1]}+\cdots+a_1x^{[1]}+a_0x,
$$
with coefficients in $\mathbb{F}_{q^n}$ and $a_k\neq 0$. It is monic when $a_k=1$. A monic $q$-linearized polynomial is a subspace polynomial if and only if it divides $x^{[n]}-x$, or equivalently if and only if it splits completely over $\mathbb{F}_{q^n}$ into distinct linear factors [1404.7739].

In the notation of linearized polynomials, the ordinary degree and the $q$-degree play different roles. For subspace polynomials, the relevant degree parameter is the $q$-degree $k$, which matches the dimension of the associated $\mathbb{F}_q$-subspace. The same finite-field definition also appears in later work on cyclic constant-dimension codes, where a monic $q$-polynomial $P(x)\in \mathbb{F}_{q^n}[x]$ is called a subspace polynomial with respect to $\mathbb{F}_{q^n}$ exactly when it divides $x^{q^n}-x$ [2509.18704].

A related formulation is used in coding-theoretic applications over $F=\mathrm{GF}(q^\ell)$ with base field $K=\mathrm{GF}(q)$. If $W\subseteq F$ is an $m$-dimensional $K$-subspace, its subspace polynomial is
$$
L_W(x)=\prod_{w\in W}(x-w)\in F[x].
$$
This polynomial can be written in linearized form
$$
L_W(x)=\sum_{i=0}^m a_i x^{q^i},
$$
so it defines a $K$-linear map $F\to F$ [2007.15253].

## 2. Root spaces and the representation theorem

A basic structural fact, traced in the literature to Ore and standard finite-field references, is that if a $q$-linearized polynomial splits over $\mathbb{F}_{q^n}$, then all of its roots in $\mathbb{F}_{q^n}$ form an $\mathbb{F}_q$-linear subspace. Conversely, for any $k$-dimensional subspace $V\subseteq \mathbb{F}_{q^n}$, the polynomial
$$
P_V(x)=\prod_{v\in V}(x-v)
$$
is a monic $q$-linearized polynomial of $q$-degree $k$ whose roots are exactly $V$, each with multiplicity $1$ [1404.7739].

This yields a one-to-one correspondence between subspaces and subspace polynomials. Two $k$-dimensional subspaces $U,V\subseteq \mathbb{F}_{q^n}$ are equal if and only if $P_U(x)=P_V(x)$. Equivalently, for every $k$-dimensional $\mathbb{F}_q$-subspace $V\subseteq \mathbb{F}_{q^n}$ there exists a unique monic $q$-linearized polynomial
$$
P_V(x)=x^{[k]}+a_{k-1}x^{[k-1]}+\cdots+a_1x^{[1]}+a_0x,\qquad a_0\neq 0,
$$
characterized by $\mathrm{Roots}(P_V)=V$ and $P_V\mid(x^{[n]}-x)$; conversely, every such divisor arises from a unique $k$-subspace [1404.7739].

Several coefficient-level consequences are used repeatedly. In any subspace polynomial $P(x)=x^{[k]}+\cdots+a_1x^{[1]}+a_0x$, the coefficient $a_0$ is nonzero. Since $P_V\mid(x^{[n]}-x)$, the polynomial $P_V$ factorizes over $\mathbb{F}_q$ into irreducible $q$-linearized factors whose degrees divide $n$ [1404.7739].

In the Reed–Solomon repair setting, the same correspondence is expressed in kernel language. The map $L_W:F\to F$ is $K$-linear, $\ker(L_W)=W$, $\dim_K(\ker(L_W))=m$, $\deg L_W=q^m$, and $L_W(x)\mid(x^{q^\ell}-x)$. All roots are simple, and $\dim_K(\operatorname{im}(L_W))=\ell-m$ [2007.15253].

## 3. Explicit families and the gap invariant

The simplest explicit family arises from subfields. If $t\mid n$, then the subfield $\mathbb{F}_{q^t}\subseteq \mathbb{F}_{q^n}$ is a $t$-dimensional $\mathbb{F}_q$-subspace, and its subspace polynomial is
$$
P_{\mathbb{F}_{q^t}}(x)=x^{[t]}-x.
$$
This example makes the divisor condition transparent, since $x^{[t]}-x$ already vanishes exactly on the subfield [1404.7739].

A second family comes from trinomials. Under the irreducibility hypothesis stated for the corresponding ordinary trinomial in $\mathbb{F}_q[x]$, the polynomial
$$
P(x)=x^{[k]}+x^{[1]}+x
$$
is a subspace polynomial over $\mathbb{F}_{q^n}$. The resulting $k$-subspace $V=\mathrm{Roots}(P)$ yields a cyclic subspace code
$$
C=\{a\cdot V\mid a\in \mathbb{F}_{q^n}^*\}\subseteq G_q(n,k)
$$
of size
$$
|C|=\frac{q^n-1}{q-1}
$$
and minimum subspace distance at least $2k-2$. By factoring the trinomial $T(x)=x^{[k]}+x^{[1]}+x$ over $\mathbb{F}_q$ and taking $n$ to be any multiple of the least common multiple of its factor-degrees, one obtains infinitely many $n$ for each fixed $(q,k)$ giving a cyclic code of size $(q^n-1)/(q-1)$ and distance at least $2k-2$ [1404.7739].

The coefficient pattern of a subspace polynomial is summarized by the gap parameter. If
$$
P_V(x)=x^{[k]}+a_sx^{[s]}+\cdots+a_0x,\qquad a_s\neq 0,\ s<k,
$$
then
$$
\mathrm{gap}(V):=k-s.
$$
If $U,V\in G_q(n,k)$ have gaps $\mathrm{gap}(U)=k-t$ and $\mathrm{gap}(V)=k-s$, then
$$
\dim(U\cap V)\le k-\min\{\mathrm{gap}(U),\mathrm{gap}(V)\},
$$
so the subspace distance satisfies
$$
d(U,V)=2k-2\dim(U\cap V)\ge 2\min\{\mathrm{gap}(U),\mathrm{gap}(V)\}.
$$
This algebraic bound is the basic distance estimate behind many cyclic-code constructions [1404.7739].

Small-field instances illustrate the same mechanism. Over $F=\mathrm{GF}(8)$ with $q=2$ and $\ell=3$, if $W=\{0,1\}$ then
$$
L_W(x)=x(x-1)=x^2+x.
$$
If $W=\{0,1,\alpha,\alpha+1\}$, where $\alpha$ is a root of $x^3+x+1=0$, then
$$
L_W(x)=x(x-1)(x-\alpha)(x-\alpha-1)=x^4+x^2+x.
$$
These examples exhibit explicit linearized forms for concrete root subspaces [2007.15253].

## 4. Cyclic subspace codes and orbit structure

For a subspace $V\subseteq \mathbb{F}_{q^n}$ and $a\in \mathbb{F}_{q^n}^*$, the cyclic shift of $V$ is
$$
a\cdot V=\{av\mid v\in V\}.
$$
The associated subspace polynomial transforms by
$$
P_{a\cdot V}(x)=a^{[k]}\,P_V(a^{-1}x).
$$
Thus cyclic shifts act directly on the coefficients of the representing linearized polynomial [1404.7739].

The orbit size of $V$ under all nonzero scalars is
$$
|\{a\cdot V\}|=\frac{q^n-1}{q^t-1},
$$
where $t$ is the minimal divisor of $n$ such that every nonzero coefficient index $s$ of $P_V$ satisfies $t\mid \gcd(n,s)$. A subspace has a full-length orbit when $t=1$, in which case the size is
$$
\frac{q^n-1}{q-1}.
$$
This criterion turns coefficient support into an orbit-length invariant [1404.7739].

One-orbit codes with large size and controlled distance are obtained by choosing $V$ so that $P_V(x)$ has a nonzero $x^{[1]}$-coefficient. Then $\mathrm{gap}(V)=k-1$, its orbit under $\mathbb{F}_{q^n}^*$ has size $(q^n-1)/(q-1)$, and the gap bound gives pairwise distance at least $2(k-1)$. The irreducible-trinomial construction provides infinitely many such examples [1404.7739].

The orbit construction can also be enlarged by Frobenius shifts. If $F_i:v\mapsto v^{q^i}$, then under mild coefficient conditions one has
$$
C=\bigcup_{i=0}^{n-1}\{a\cdot F_i(V)\mid a\in \mathbb{F}_{q^n}^*\},
$$
and this union is still cyclic, has size
$$
n\cdot \frac{q^n-1}{q-1},
$$
and has the same minimum distance $2k-2$ [1404.7739].

## 5. Generalized multi-orbit constructions

A later extension considers several subspace polynomials simultaneously. Fix a prime power $q$, integers $k>2$ and $1\le s<k-1$, a field extension $\mathbb{F}_{q^N}\supset \mathbb{F}_{q^n}$, and a positive integer $e$. For each $1\le i\le e$, choose nonzero coefficients
$\gamma_{s+1,i},\gamma_{s,i},\dots,\gamma_{0,i}\in\mathbb{F}_{q^n}^*$ and form
$$
P_{V_i}(x)=x^{q^k}+\gamma_{s+1,i}x^{q^{s+1}}+\gamma_{s,i}x^{q^s}+\cdots+\gamma_{0,i}x\in\mathbb{F}_{q^n}[x].
$$
If each $P_{V_i}$ divides $x^{q^n}-x$, then its root set
$$
V_i=\{v\in \mathbb{F}_{q^N}:P_{V_i}(v)=0\}
$$
is an $\mathbb{F}_q$-subspace of dimension exactly $k$ [2509.18704].

Writing
$$
\operatorname{orb}(V_i)=\{\alpha V_i:\alpha\in \mathbb{F}_{q^N}^*\},
$$
one has
$$
|\operatorname{orb}(V_i)|=\frac{q^N-1}{q-1}
$$
since $V_i$ is not $\mathbb{F}_{q^t}$-linear for any $t>1$. By comparing the greatest common divisors of $P_{V_i}$ and $P_{\alpha V_i}$, one obtains
$$
\dim(V_i\cap \alpha V_i)\le s\qquad \forall\,\alpha\notin \mathbb{F}_q^*,
$$
so the minimum distance of the single-orbit code $\operatorname{orb}(V_i)$ satisfies
$$
d\ge 2k-2s.
$$
To combine several orbits, one further requires for any $i\neq j$ and any $\alpha\in \mathbb{F}_{q^N}^*$ that
$$
\dim(V_i\cap \alpha V_j)\le s.
$$
This is enforced through the polynomial
$$
R_\alpha(x)=P_{V_i}(x)-P_{\alpha V_j}(x)=\sum_{t=0}^{s+1} r_{t,\alpha}x^{q^t},
$$
with
$$
r_{t,\alpha}=\gamma_{t,i}-\gamma_{t,j}\alpha^{\,q^k-q^t},
$$
together with a determinant/rank condition asserting that a certain $(k+1)\times (k-s+1)$ matrix $M_\alpha^{\,i,j}$ has full column rank $k-s+1$ [2509.18704].

Under that matrix-rank condition, the union of orbits
$$
\mathcal{C}=\bigcup_{i=1}^e \operatorname{orb}(V_i)
$$
remains an $(N,d,k)_q$-code with
$$
d\ge 2k-2s
$$
and size
$$
|\mathcal{C}|=e\frac{q^N-1}{q-1}.
$$
When $s=1$ and $e=1$, this recovers earlier trinomial-based constructions. Allowing arbitrary $s<k-1$ and multiple distinct polynomials $P_{V_i}$ gives up to $e$ disjoint orbits rather than a single one, so the resulting codes can be much larger. An explicit example takes $q=2$, $k=3$, three polynomials over $\mathbb{F}_{2^2}$, embeds their root spaces in $\mathbb{F}_{2^{14}}$, verifies the rank conditions, and obtains a cyclic $(14,4,3)_2$-code of size $3(2^{14}-1)$, whereas the earlier single-trinomial construction gives size $(2^{14}-1)$ [2509.18704].

## 6. Reed–Solomon repair and the relation to trace polynomials

In distributed storage, subspace polynomials are used to construct repair checks for Reed–Solomon codes over $F=\mathrm{GF}(q^\ell)$ with base field $K=\mathrm{GF}(q)$. For an $m$-dimensional $K$-subspace $W\subseteq F$, the polynomial
$$
L_W(x)=\prod_{w\in W}(x-w)
$$
is $K$-linear, has kernel $W$, degree $q^m$, divides $x^{q^\ell}-x$, and splits completely over $F$ with simple roots. The associated conventional $q$-associate is
$$
\ell_W(x)=\sum_{i=0}^m a_i x^i,
$$
and under symbolic composition $\otimes$, the associate of $L_W^{\otimes s}$ is $\ell_W(x)^s$ [2007.15253].

Trace polynomials appear as a special case. If $W=\ker(\mathrm{Tr}_{F/K})$ has dimension $m=\ell-1$, then
$$
L_W(x)=\sum_{i=0}^{\ell-1} x^{q^i}=\mathrm{Tr}_{F/K}(x),
$$
and $\ker(L_W)=W$. In this sense, subspace polynomials generalize trace polynomials by allowing the kernel to be any $m$-dimensional $K$-subspace, not only a hyperplane. The Guruswami–Wootters repair scheme uses only $W=\ker(\mathrm{Tr})$, whereas the subspace-polynomial approach uses all subspaces $W$ of dimension $m$ [2007.15253].

For an $[n,k]$ Reed–Solomon code over $F$ with redundancy $r=n-k\ge q^m$, if the symbol at $\alpha^*$ is erased, one chooses an $m$-dimensional subspace $W$ and defines
$$
g_i(x)=\frac{L_W(x-\alpha^*)}{x-\alpha^*}.
$$
The resulting checks have degree at most $r-1$, the values at the erased position span $F$ over $K$, and for each helper node at $\alpha\neq \alpha^*$ one has
$$
\dim_K\bigl(\mathrm{span}\{g_i(\alpha)\}\bigr)\le \ell-m.
$$
Hence the total repair bandwidth, measured in $K$-subsymbols, is
$$
(n-1)(\ell-m).
$$
When $n=q^\ell$ and $r=q^m$, this bandwidth is information-theoretically optimal for one erasure. For two erasures, the same bandwidth per erasure is obtained when $\ell/m$ is a power of $q$, and also for $\ell=q^a$, $m=q^b-1>1$ with $a\ge b\ge 1$, and for $m\ge \ell/2$ when $\ell$ is even and $q$ is a power of two [2007.15253].

## 7. Distinct usage in learning theory

A separate line of work studies subspace-sparse polynomials, which are not finite-field subspace polynomials. In that setting, the ambient space is $\mathbb{R}^D$, the input distribution is standard Gaussian, and a target function is called subspace-sparse when there exists an unknown $p$-dimensional subspace $V\subset \mathbb{R}^D$ with orthogonal projector $P_V$ such that
$$
f^*(x)=h^*(P_Vx)=h^*(x_V),
$$
where $h^*:V\to \mathbb{R}$ is a polynomial of total degree $n$ [2402.08948].

The learning model is a wide two-layer network represented in the mean-field limit by a probability distribution $\rho_t$ on parameters $\theta=(a,w)\in \mathbb{R}\times \mathbb{R}^D$, with network output
$$
f_{\mathrm{NN}}(x;\rho)=\int a\,\sigma(w^\top x)\,\rho(d\,a,d\,w),
$$
and population squared loss
$$
E(\rho)=\tfrac12\,\mathbb{E}_{x\sim N(0,I_D)}\bigl[(f^*(x)-f_{\mathrm{NN}}(x;\rho))^2\bigr].
$$
In the vanishing-step-size and infinite-width limit, the SGD evolution satisfies a mean-field PDE, and
$$
\frac{d}{dt}E(\rho_t)\le 0,
$$
so the flow is a gradient descent in $2$-Wasserstein space [2402.08948].

The conceptual overlap with finite-field subspace polynomials lies only in the shared emphasis on low-dimensional subspace structure. The actual objects are different. In the learning-theoretic setting, the main results concern a necessary condition based on a reflective property of $h^*$ on a proper subspace $S\subset V$, under which the loss stays bounded away from zero for finite time horizons, and an almost-sufficient condition under which one can design a two-stage SGD schedule achieving
$$
E(\rho_t)\le C_1 e^{-C_2 t},
$$
with constants depending on $(p,n,h^*,\sigma)$ but not on the ambient dimension $D$ [2402.08948].

This distinction matters terminologically. In finite-field coding theory, a subspace polynomial is a monic linearized divisor of $x^{q^n}-x$ that represents an $\mathbb{F}_q$-subspace. In contemporary learning theory, a subspace-sparse polynomial is a real polynomial target that depends only on the projection of the input onto a low-dimensional subspace. The two notions share a geometric motif but belong to different algebraic and analytic frameworks [1404.7739] [2402.08948].

Source: https://www.emergentmind.com/topics/subspace-polynomials