scieee AI-readable full text Open interactive document viewer

Entanglement-assisted quantum error-correcting codes from subfield subcodes of projective Reed–Solomon codes

Ruano Benito, Diego,Giménez, Philippe Thierry,San José Rubio, Rodrigo

Abstract

Producción Científica

Full text

Computational and Applied Mathematics (2023) 42:363 https://doi.org/10.1007/s40314-023-02506-4 Entanglement-assisted quantum error-correcting codes from subfield subcodes of projective Reed–Solomon codes Philippe Gimenez1·Diego Ruano1·Rodrigo San-José1 Received: 11 April 2023 / Revised: 20 October 2023 / Accepted: 22 October 2023 / Published online: 25 November 2023 © The Author(s) 2023 Abstract We study the subfield subcodes of projective Reed–Solomon codes and their duals: we provide bases for these codes and estimate their parameters. With this knowledge, we can construct symmetric and asymmetric entanglement-assisted quantum error-correcting codes, which in many cases have new or better parameters than the ones available in the literature. Keywords Asymmetric quantum codes ·EAQECC ·Evaluation codes ·Linear codes · Projective Reed–Solomon codes ·Subfield subcodes ·Trace Mathematics Subject Classification 81P70 ·94B05 ·13P25 Communicated by Gaojun Luo. This work was supported in part by the following grants: Grant TED2021-130358B-I00 funded by MCIN/AEI/10.13039/501100011033 and by the “European Union NextGenerationEU/ PRTR”, Grants PID2022-138906NB-C21 and PID2022-137283NB-C22 funded by MCIN/AEI/10.13039/501100011033 and by ERDF “A way of making Europe”, FPU20/01311 funded by the Spanish Ministry of Universities, and by QCAYLE project funded by MCIN, the European Union NextGenerationEU (PRTR C17.I1) and Junta de Castilla y León. BRodrigo San-José [email protected] Philippe Gimenez [email protected] Diego Ruano [email protected] 1IMUVA-Mathematics Research Institute, Universidad de Valladolid, 47011 Valladolid, Spain 123 363 Page 2 of 31 P. Gimenez et al. 1 Introduction The subfield subcode of a linear code C⊂Fn qs, with s≥1, is the linear code C∩Fn q. Considering subfield subcodes is a standard technique for constructing long linear codes over a small finite field. For instance, BCH codes are obtained in this way. They can be regarded as subfield subcodes of Reed–Solomon codes and their duals (Bierbrauer 2002). In this work, we study subfield subcodes of projective Reed–Solomon codes. Reed–Solomon codes are constructed by evaluating one-variable polynomials at points of the affine line. They have optimal parameters, although they cannot be defined over a small finite field. Projective Reed–Solomon codes are constructed by evaluating two-variable homogeneous polynomials at points of the projective line. When one evaluates at all the points they are commonly called doubly extended Reed–Solomon codes. Subfield subcodes of projective Reed–Solomon codes, when one evaluates at all the points of the projective line, were studied in Bierbrauer and Edel (1997). In this work, we consider a more general setting: we may evaluate at fewer points to define a projective Reed–Solomon code and then compute its subfield subcode. We provide bases for both the subfield subcodes of projective Reed–Solomon codes and their duals and, thus, a formula for their dimension. For the dual code, we use Delsarte’s Theorem 4.1, for which we need to study first the metric structure of the codes we are considering. We also study the vanishing ideal of the points in which we evaluate, which allows us to discuss linear independence between the traces that arise when using Delsarte’s Theorem. Moreover, we estimate the minimum distance for both primary and dual codes. For the primary code we simply use the bound given by the projective Reed–Solomon code, and for the dual one we use a BCH-type bound. Reed–Solomon and BCH codes have been extensively used to construct quantum codes using the CSS construction, see, for instance, (Bierbrauer and Edel 2000; Galindo et al. 2021;LaGuardia2020). It is, therefore, natural to consider subfield subcodes of projective Reed–Solomon for constructing quantum codes. The construction of quantum computers has important consequences because of their computing capabilities. Despite the fact that quantum mechanical systems are sensitive to disturbances and arbitrary quantum states cannot be replicated, error correction is possible. Quantum error-correcting codes are designed for protecting quantum information from quantum noise and particularly decoherence. An important class of quantum error-correcting codes are stabilizer codes; they can be derived from classical ones using self-orthogonal codes for the symplectic product (Calderbank and Shor 1996). One can also consider the Euclidean and the Hermitian inner product, and we will call the resulting quantum error-correcting codes QECCs. Entanglement-assisted quantum error-correcting codes (EAQECCs) constitute an extension of quantum codes. EAQECCs make use of pre-existing entanglement between transmitter and receiver to correct more errors (Brun et al. 2006; Galindo et al. 2019b). One virtue of this class of codes is that one can get a quantum code from any linear code without any assumption on dual containment. The main additional task for EAQECCs is to give formulae to obtain the optimal number cof maximally entangled pairs of qudits needed. Moreover, both for QECCs and EAQECCs, one can consider the asymmetric case (Galindo et al. 2020; Ioffe and Mézard 2007; Sarvepalli et al. 2009). Asymmetric quantum codes have a different error-correction capability for phase-shift and qudit-flip errors. These two types of errors are not equally likely, and it is desirable to construct quantum codes with a higher correction capability for phase-shift errors (Ioffe and Mézard 2007). 123 Entanglement-assisted quantum error-correcting codes from… Page 3 of 31 363 In this work, we provide EAQECCs with excellent parameters coming from different constructions. In the Euclidean case, we are able to obtain both symmetric and asymmetric EAQECCs with excellent parameters from subfield subcodes of projective Reed–Solomon codes. A key fact for the construction of these codes and the computation of their parameters is the knowledge of the parameters and structure of both the primary and dual codes. We also obtain QECCs, i.e. EAQECCs without entanglement assistance, from subfield subcodes of projective Reed–Solomon codes in some cases. By considering the Hermitian inner product we are also able to obtain codes with excellent parameters. In fact, we produce new parameters according to Grassl (2007). Furthermore, as we are giving several different constructions using subfield subcodes of projective Reed–Solomon codes, this contributes to expanding the known constellation of parameters for EAQECC. Finally, we consider the codes in Galindo et al. (2019c), Reed–Solomon, and BCH codes obtained by evaluating at the roots of a trace function. We construct the projective version of the codes in Galindo et al. (2019c), that is, the subfield subcodes of projective Reed–Solomon codes evaluating at the roots of a trace function and the point at infinity. This allows us to give classical linear codes which are record in Grassl (2007), and new EAQECCs. Our results can be summarized as follows. •We consider projective Reed–Solomon codes over the zero locus of xN−x(and the point at infinity), where we evaluate an arbitrary set of monomials. We obtain bases for the subfield subcodes of these codes in Theorem 3.4. •When p|N, bases for the duals of the subfield subcodes are obtained in Theorem 4.14. •Considering sets of monomials whose exponents are a union of consecutive cyclotomic sets and the next minimal element, we obtain EAQECCs with entanglement parameter c≤1inTheorems5.5 and 5.15. Some of the resulting codes improve the table for EAQECCs from Grassl (2007). •Assuming p|N, by considering the sets of monomials {0,1,...,di},forsome1≤ d1,d2≤N−1, we obtain asymmetric EAQECCs with entanglement parameter c=1, which compare favorably with the current literature. •By evaluating in the zeroes of the trace function, plus the point at infinity, and evaluating monomials whose exponents are a union of consecutive cyclotomic sets and the next minimal element, we obtain linear codes with good parameters in Theorem 6.4,some of which improve the best known parameters in Grassl (2007), see Example 6.5.Moreover, we obtain EAQECCs with good parameters and entanglement parameter c≤1in Theorem 6.6. 2 Preliminaries We consider a finite field Fqof qelements with characteristic p, and its degree sextension Fqs, with s≥1. We consider the affine space A1over Fqsand the polynomial ring R= Fqs[x]. We choose a set of elements Y={Q1,...,Qn}⊂A1and its vanishing ideal I(Y)= n i=1(x−Qi), where we are regarding the points of A1as elements in Fqs.We define the following evaluation map: evY:R/I(Y)→Fn qs,f→ (f(Q1),..., f(Qn))Qi∈Y. where we denote a polynomial and its class in the quotient ring R/I(Y)in the same way. Let be a subset of {0,1,...,n−1}. Then, the Reed–Solomon code associated to and Y, denoted by RS(Y,), is the code generated by 123 363 Page 4 of 31 P. Gimenez et al. {evY(xi)|i∈}. The usual choices are ={0,1...,d}and Y=F∗ qs=Fqs\{0}, which give a Reed– Solomon code with parameters [qs−1,d+1,qs−d−1]. This code can be extended by evaluating at 0 as well, obtaining a code with parameters [qs,d+1,qs−d]. Let N>1besuchthatN−1|qs−1. We can consider the set of points Y∗ N= {Q1,...,QN}given by the zero locus of I(Y∗ N)=xN−1−1. In this case, Y∗ Nforms a multiplicative subgroup of F∗ qsand it is already known how to obtain bases for its subfield subcodes (see, for example, Hattori et al. 1998; Hernando et al. 2010). Moreover, BCH codes can be defined as the duals of the subfield subcodes of Reed–Solomon codes when we evaluate in a subgroup Y∗ N(Bierbrauer 2002). Indeed, let α∈Fqsbe a primitive (N−1)th root of unity. Cis a BCH code of designed distance δif it has as generator polynomial the least common multiple of the minimal polynomials of the δ−1 consecutive elements αb,αb+1,...,αb+δ−2, with b≥1, which implies that Cis formed by the vectors over FN−1 q that are orthogonal to the rows of the matrix: H=⎛ ⎜ ⎜ ⎜ ⎝ 1αbα2b··· α(N−2)b 1αb+1α2(b+1)··· α(N−2)(b+1) . . .. . .. . ..... . . 1αb+δ−2α2(b+δ−2)··· α(N−2)(b+δ−2) ⎞ ⎟ ⎟ ⎟ ⎠ .(1) However, this is precisely the generator matrix of the Reed Solomon code over Fqswith ={b,b+1,...,b+δ−2}and Y=Y∗ N. Furthermore, the vectors in FN−1 qthat are orthogonal to the rows of Hare precisely the vectors of the subfield subcode of the dual code of this Reed–Solomon code, which is, therefore, equal to the aforementioned BCH code. In this situation, we say that His a pseudo parity check-matrix for C. Because of the previous discussion, throughout this work we will focus on evaluating in subgroups of the form Y∗ Nunless stated otherwise. As before, we can also include the evaluation of 0, which corresponds to considering instead the set YN, the zero locus of I(YN)=xN−x. For the Reed–Solomon codes obtained by evaluating the associated monomials to in YNwe will use the notation RS(N,). The subfield subcode of the code RS(N,)over Fqis denoted by RS(N,) q:= RS(N,)∩FN q. In this case, for the sake of simplicity, we are also going to denote RN:= R/I(YN). Now, we are going to introduce some necessary definitions to obtain bases for the codes RS(N,) q.WedefineZN={0}∪Z/N−1, where we represent the classes of Z/N−1 by {1,...,N}. A subset Iof ZNis called a cyclotomic set with respect to qif q·z∈Ifor any z∈I.Iis said to be minimal (with respect to q) if it can be expressed as I={qi·z,i= 1,2,...}for a fixed z∈I, and in that situation we will write Iz:= Iand nz=|Iz|.We say zis a minimal representative of Izif zis the least element in Iz, and we will say it is a maximal representative of Izif it is the biggest element. We will denote by Athe set of minimal representatives of the minimal cyclotomic cosets, and by Bthe set of maximal representatives of the minimal cyclotomic cosets. Example 2.1 Consider the extension F9⊃F3. We consider N=9 and we have ZN= {0}∪Z/8. We have the following minimal cyclotomic sets: I0={0},I1={1,3},I2={2,6},I4={4},I5={5,7},I8={8}. The set of minimal representatives is A={0,1,2,4,5,8}, and the set of maximal representatives is B={0,3,4,6,7,8}. 123 Entanglement-assisted quantum error-correcting codes from… Page 5 of 31 363 The dimension of the subfield subcodes of Reed–Solomon codes is already present in Hattori et al. (1998). For the codes RS(N,) qit is possible to obtain a basis given by the evaluation of some polynomials. For each a∈A, we define the following trace map: Ta:RN→RN,f→ f+fq+···+ fq(na−1), and given ⊂{0,1,...,N−1},wedenoteI:= Ia⊂Ia⊂. The following result gives a basis for the code RS(N,) q(Galindo et al. 2019a, Thm. 11). Theorem 2.2 Let be a subset of {0,1,...,N−1}and set ξaa primitive element of the field Fqna. Then, a basis of the vector space RS(N,) qis given by the images under the map evYNof the set of classes in RN:  a∈A|Ia⊂ {Ta(ξr axa)|0≤r≤na−1}. As a consequence, we have that dim RS(N,) q= Iz:Iz⊂ nz=|I|. Having seen the affine setting, we are now going to introduce the codes we are going to use throughout this work. We consider the projective line P1over Fqsand the polynomial ring S=Fqs[x0,x1].Givenadegreed≥1, we denote by Sdthe homogeneous polynomials of degree d. We are going to fix representatives for the points of P1in the following way: for each point [P]∈P1, we choose the representative whose first nonzero coordinate is equal to 1. We will denote by P1this set of representatives, seen as points in the affine space A2, and we will call them standard representatives. If we also consider a finite set of points X={Q1,...,Qn}⊂P1, we can define the following evaluation map: evX:S/I(X)→Fn qs,f→ (f(Q1),..., f(Qn))Qi∈X, where, as before, we denote a polynomial in Sand its class in S/I(X)inthesameway.Given ⊂{0,1,...,n−1},wedefined() := max{i|i∈}.Theprojective Reed–Solomon code associated to and Xis the code generated by {evX(xd()−i 0xi 1)|i∈}, which will be denoted by PRS(X,). We note that we are only evaluating monomials of exactly degree d(), which means that their linear combinations are homogeneous polynomials of degree d().If0 /∈,PRS(X,)is a degenerate code, because all the previous monomials would evaluate to 0 at the point [1:0]. Therefore, we are always going to assume in what follows that 0 ∈. Some authors define these codes over the projective space without fixing representatives, as in Martínez-Bernal et al. (2017), but then they can only define the code up to monomial equivalence. Monomially equivalent codes do not necessarily have monomially equivalent subfield subcodes, for example in Hernando et al. (2013) the authors see that the dimension of the subfield subcode of a generalised Reed–Solomon code depends on the twist vector chosen, and that is why we fix representatives from the beginning. Given a degree 1 ≤d≤qs, the most standard definition of projective Reed–Solomon code in the literature is the code PRS(P1, d),whered:= {0,1,...,d}. The code PRS(P1, d) is also called doubly extended Reed–Solomon code and its parameters are [qs+1,d+1,qs− d+1]. 123 363 Page 6 of 31 P. Gimenez et al. To obtain bases for the subfield subcodes of the codes PRS(X,), we are going to evaluate in subgroups similarly to the affine case. The natural ideal is to add the point at infinity [0:1]to the points that we were considering in the affine case. Therefore, given N, such that N−1|qs−1, we define X∗ N=[{1}×Y∗ N]∪[0:1]⊂P1and XN=[{1}×YN]∪[0:1]⊂P1, where we recall that Y∗ Nand YNare the zero locus of xN−1−1and xN−x, respectively. However, it is easy to see that another set of representatives for X∗ Nis [YN×{1}]. Thus, the codes obtained when evaluating in this set would be monomially equivalent to the ones obtained in the affine case when evaluating in YN. As we said before, this does not mean that their subfield subcodes are monomially equivalent. Nevertheless, our experiments show that the parameters that we obtain when evaluating in the set X∗ Nare strictly worse than the ones obtained in the affine case with YN. Hence, in what follows we are going to focus on evaluating in the set XN, although we note that the theory we are going to develop can be adapted for the set X∗ Nas well. We denote the standard representatives of XNby XN, and we also denote PRS(N,):= PRS(XN,). With this notation, doubly extended Reed–Solomon codes are denoted by PRS(qs, d). Similarly to the case of doubly extended Reed–Solomon codes, given 1 ≤ d≤N, the parameters of the code PRS(N, d)are [N+1,d+1,N−d+1]. In general, for the codes PRS(N,)we have the parameters [N+1,||,≥N−d() +1],wherethe bound for the minimum distance is given by the smallest doubly extended Reed–Solomon code that contains PRS(N,). 3 Subfield subcodes of codes over the projective line Let Fqs⊃Fqand N, such that N−1|qs−1. In this section, we want to obtain bases for the subfield subcodes of the codes PRS(N,)with respect to this extension, which we will denote by PRS(N,) q:= PRS(N,)∩Fq.Given f∈S, we say that fevaluates to Fq in XNwhenever f(Q)∈Fqfor all Q∈XN(similarly for polynomials in Revaluating in YN). The following lemma gives the key idea to obtain bases for PRS(N,) q. Lemma 3.1 Let XN⊂P1. Then, f ∈S evaluates to Fqin XN⇐⇒ f(1,x1)evaluates to Fqin YNand f (0,1)is in Fq. We will see now that we can take advantage of the knowledge from the affine case in Theorem 2.2 by homogenizing and using Lemma 3.1.Givenadegreedand a polynomial f(x)∈Rwith deg(f)≤d, its homogenization up to degree dis the homogeneous polynomial fh(x0,x1):= xd 0f(x1/x0)∈Sd. Unless stated otherwise, when we consider the code PRS(N,), we are always going to assume that we are homogenizing up to degree d=d(). For a polynomial f∈Fq[x1], we choose Ta(f)as the representative of the class in Fqs[x1]/I(YN)which has the exponents of each monomial reduced modulo qs−1. Given d≥1, if the degree of Ta(f)is lower than d, then we define Th a(f):= (Ta(f))h,which we call homogenized trace. If we consider one of the traces that appear in Theorem 2.2, its homogenized trace automatically satisfies that, when setting x0=1, the resulting polynomial evaluates to Fqin YN, i.e., the first condition from Lemma 3.1 is satisfied. However, the second condition, which means that the coefficient of xd 1in the homogenized trace must be in Fq, might not be satisfied. Because of this, the projective case is more involved than the affine case, as we will see in the next example. 123 Entanglement-assisted quantum error-correcting codes from… Page 7 of 31 363 Example 3.2 We continue with Example 2.1. By Theorem 2.2, the following polynomial associated to I1evaluates to F3: T1(x)=x+x3. Let d=3 (the degree up to which we homogenize). If we consider the polynomial f= Th 1(x1)=x2 0x1+x3 1, this is a homogeneous polynomial of degree 3, such that f(1,x1)takes the same values as T1(x1)in F9,and f(0,1)=1∈F3. By Lemma 3.1, we know that f evaluates to F3when evaluating in P1. If ξis a primitive element in F9, by Theorem 2.2, the following polynomial also evaluates to F3: T1(ξ x)=ξx+ξ3x3. However, if we consider g=Th 1(ξ x1)=ξx2 0x1+ξ3x3 1, we see that g(0,1)=ξ3/∈F3. Therefore, gdoes not evaluate to F3. Remark 3.3 If we have f∈Sdwhich evaluates to Fq,thenx0f∈Sd+1also evaluates to Fq. Moreover, if f(1,x1)evaluates to Fqin YN,theng=x0f∈Sd+1evaluates to Fqin XN,evenif fdoes not, because g(1,x1)=f(1,x1), which evaluates to Fq,and g(0,1)=0∈Fq. This already gives a hint about the fact that the sequence of dimensions of the subfield subcodes is going to be non-decreasing. With Lemma 3.1, we can consider polynomials in one variable that evaluate to Fqto obtain polynomials in Sdthat evaluate to Fqin XNin some cases. One could also consider the polynomials in two variables that evaluate to Fqwhen evaluating in the points of A2. All of those polynomials are going to evaluate to Fqwhen evaluating in points of P1.However, there are bivariate polynomials that evaluate to Fqin P1, but not in A2. For example, in Example 3.2 we consider f=x2 0x1+x3 1, which evaluates to F3over P1, but if we consider this polynomial over A2, then it is clear that it does not evaluate to F3. For example, if ξis a primitive element in F9,f(0,ξ)=ξ3/∈F3. The following result shows how to use the previous ideas to obtain a basis for PRS(N,) q. Theorem 3.4 Let be a nonempty subset of {0,1,...,N−1}and let d =d().Setξba primitive element of the field Fqnb. A basis for PRS(N,) qis given by the image by evXN of the following polynomials. If Id⊂:  b∈B|Ib⊂,b<d {Th b(ξr bxb 1)|0≤r≤nb−1}∪{Th d(xd 1)}. If Id⊂ :  b∈B|Ib⊂ {Th b(ξr bxb 1)|0≤r≤nb−1}. Proof If we consider  b∈B|Ib⊂,b<d {Th b(ξr bxb 1)|0≤r≤nb−1}, these are functions which have linearly independent evaluations, because when evaluating in [{1}×XN]they are linearly independent by Theorem 2.2. These polynomials do not have the monomial xd 1in their support. Therefore, by Lemma 3.1,theyevaluatetoFqin XN. 123 363 Page 8 of 31 P. Gimenez et al. If Id⊂ , we are going to see that the evaluation of these polynomials generates the whole subfield subcode. Let Sd, ⊂Sdbe the linear space generated by {xd−i 0xi 1|i∈}, and let f∈Sd, be such that its evaluation is in PRS(N,) q.If f(0,1)=0, then, using Theorem 2.2, we know that we can generate the evaluation of fwith these polynomials. On the other hand, we claim that f(0,1)= 0 cannot happen in this case, which means that the image by the evaluation map of the stated polynomials generate the whole subfield subcode. If we had f(0,1)= 0, that would imply that f(1,x1)has the monomial xd 1in its support. However, if Id⊂ , then we know that there is at least one a1∈Idwhich is not in . Therefore, we cannot obtain the monomial xa1 1in the support of f(1,x1), because using Theorem 2.2 in YN, once you have xd 1in the support of f(1,x1), you should have xa 1in its support for all a∈Id, because f(1,x1)should be a linear combination of traces. Therefore, f(0,1)= 0 is not possible in this case, and the stated polynomials generate the whole subfield subcode. In the case Id⊂,wehavethatd∈B, i.e., there is a minimal cyclotomic set whose maximal representative is equal to d. By Lemma 3.1,wehavethatTh d(xd 1)evaluates to Fq, and it is linearly independent from the other polynomials that we consider, because it is the only one that takes a nonzero value at [0:1]. We are going to show now that the evaluation of the given set of polynomials generates the whole code in this case. Let f∈Sd,, such that fevaluates to Fq. By Lemma 3.1,f(0,1)is in Fq. Hence, we can subtract Th d(xd 1)multiplied by f(0,1)∈Fqand the evaluation would still be in Fq. Therefore, we can assume that fdoes not have the monomial xd 1in its support, i.e., f(0,1)=0. Then, we can use the affine case and argue that if f(1,x1)evaluates to Fq, by Theorem 2.2 it must be a linear combination of the polynomials in  b∈B|Ib⊂,b<d {Tb(ξr bxb 1)|0≤r≤nb−1}. The homogenized polynomials that we consider have the same evaluation as these polynomials in [{1}×YN], which completes the proof.  Remark 3.5 We note that we are obtaining a basis which is the image by the evaluation map of some homogeneous polynomials of degree d, which we already knew that should be possible, because PRS(N,) q⊂PRS(N,). Example 3.6 We continue with Examples 2.1 and 3.2.WeconsiderN=9and= {0,1,2,3}, which means that we have d() =3. Looking at the cyclotomic sets from Example 2.1, we see that I0∪I1⊂(and these are the only complete minimal cyclotomic sets in ). By Theorem 3.4, taking into account that in this case we have I3=Id⊂,we see that the evaluation of the following polynomials is a basis for PRS(9,) 3: Th 0(x0 1)=x3 0,Th 3(x3 1)=x2 0x1+x3 1. We note that the second polynomial is precisely the polynomial fin Example 3.2. If we take ={0,1,2,3,4},thenwehaved() =4andI0∪I1∪I4⊂.By Theorem 3.4, the evaluation of the following polynomials is a basis for PRS(9,) 3: Th 0(x0 1)=x4 0,Th 3(x3 1)=x3 0x1+x0x3 1,Th 3(ξ x3 1)=ξ3x3 0x1+ξx0x3 1,Th 4(x4 1)=x4 1. Corollary 3.7 The dimension of PRS(N,) qis the following: dim PRS(N,) q=b∈B:Ib⊂nb−(nd−1)=b∈B:Ib⊂,b<dnb+1if Id⊂ b∈B:Ib⊂nbotherwise 123 Entanglement-assisted quantum error-correcting codes from… Page 9 of 31 363 Remark 3.8 Let d=d().IfId⊂, we have dimension 1 more than in the affine case with \{d}. On the other hand, if Id⊂ , we obtain a degenerate code with a 0 at the point [0:1]. Therefore, the interesting case is when Id⊂, which is the one in which we are going to mainly focus in what follows. With respect to the minimum distance, if we denote by wt(C)the minimum distance of a code C⊂Fn qs,wehavewt(PRS(N,)) ≥N−d() +1, which implies that wt(PRS(N,) q)≥N−d() +1, because PRS(N,) q⊂PRS(N,). For the case of subfield subcodes of doubly extended Reed–Solomon codes we obtain the following corollary. Corollary 3.9 Let d ∈B. The parameters of PRS(qs, d)qare [qs+1,b∈B:b<dnb+1,≥ qs−d+1]. Moreover, the first nontrivial (dimension higher than 1) subfield subcode is obtained when d =qs−1. Proof The parameters are a special case of the previous results and discussions. For the last statement, it is clear that qs/q=qs−1is the lowest possible element in B(besides 0), and d=qs−1is the first degree, such that I1={1,q,q2,...,qs−1}⊂d. The bound used for the minimum distance of the subfield subcodes of doubly extended Reed–Solomon codes is sharp in all cases we have checked with d∈B. The codes obtained in this way have one more length and dimension than in the affine case, with the same minimum distance. Example 3.10 If we look at the results from Example 3.6, we see that we obtained dimension 2 and 4 for PRS(9, 3)3and PRS(9, 4)3. These are the values obtained with Corollary 3.9, because 2 =n0+1and4=n0+n3+1. We would obtain codes with parameters [10,2,7] and [10,4,6]over F3. 4 Dual codes of the previous subfield subcodes To compute the dual codes of the previous subfield subcodes, we are going to use Delsarte’s Theorem (Delsarte 1975). Theorem 4.1 Let C ⊂Fn qsbe a linear code: (C∩Fn q)⊥=Tr(C⊥), where Tr :Fqs→Fq, which maps x to x +xq+···+xqs−1, is applied componentwise to C⊥. To use this result, we need to compute the dual of the codes PRS(N,). It is well known that PRS(qs, d)⊥=PRS(qs, qs−1−d)(the dual of a doubly extended Reed–Solomon code is another doubly extended Reed–Solomon code). However, computing the dual of the codes PRS(N,)in general can be involved. Nevertheless, we can easily compute the dual in some cases. To do so, we are going to state the metric structure of these codes first. Part of the following result already appears in Galindo et al. (2015, Prop. 1) and López (2021,Lem. 7.1). 123 363 Page 16 of 31 P. Gimenez et al. Proof We assume that the point [0:1]corresponds to the last coordinate. We have PRS(N,) q⊃(RS(N, )q,0), which implies (PRS(N,) q)⊥⊂(RS(N, )q,0)⊥=((RS(N, )q)⊥,0)+(0,...,0,1). We know that (0,...,0,1)/∈(PRS(N,) q)⊥, because that would imply that PRS(N,) qis degenerate, and that is not the case because of the assumptions that we have made. Thus, any vector in (PRS(N,) q)⊥must belong to (RS(N, )q)⊥after puncturing the last coordinate, and therefore, the weight of any vector in (PRS(N,) q)⊥must be at least t+1 because of the BCH-type bound for (RS(N, )q)⊥. As a corollary, we have the following result about the duals of the subfield subcodes of doubly extended Reed–Solomon codes. Corollary 4.18 Let d={0,1,...,d}with d ∈B. If t is the number of consecutive exponents in ( d)I, the parameters of (PRS(qs, d)q)⊥are [qs+1,a∈A|Ia∩⊥=∅ na,≥t+1]. This estimate would give codes with length 1 more than in the affine case, but same dimension and same bound for the minimum distance. However, the bound for the minimum distance is not sharp in general and we are able to improve upon the affine case in many examples. For instance, in the next result we show that when |Id|=1 we have a better estimate for the minimum distance. Proposition 4.19 Let ⊂{0,1,...,N−1}, such that |Id()|=1. Then, PRS(N, I)is Galois invariant, we have that (PRS(N, I)⊥)q=(PRS(N, I)q)⊥=(PRS(N,) q)⊥, and, if there are t consecutive exponents in I, the parameters of (PRS(N,) q)⊥are [N+1,a∈A|Ia∩⊥ I=∅ na+1,≥t+1]. Proof Let d=d().WehavethatPRS(N, I)is generated by the evaluation of monomials. Because of the fact that Iis a union of cyclotomic sets, we can divide the monomials into sets corresponding to different minimal cyclotomic sets. For a= dwe have the monomials {x0xα 1|α∈Ia⊂}. If we consider these monomials to the power of q, the set remains invariant in S/I(P1), because the exponents of x1are in a cyclotomic set, and the exponent of x0does not change the evaluation. For Idwe have that xq(N−1−d) 1≡xN−1−d 1mod I(P1), because |Id|=1. Therefore, the set of monomials is invariant under taking powers of q, which implies that PRS(N, I)=(PRS(N, I))q. Because of the previous discussion, we have that being Galois invariant implies in this case that (PRS(N, I)⊥)q=(PRS(N, I)q)⊥.Takinginto account that PRS(N, I)q=PRS(N,) qbecause of Theorem 3.4, the parameters are clear from Theorem 4.14 and the BCH-type bound.  In many situations, the previous result gives codes with higher length and dimension than in the affine case. Assuming the hypotheses of the previous result, the affine code with (RS(N,) q)⊥would have parameters [N,a∈A|Ia∩⊥ I=∅ na,≥t+1], meanwhile the projective code (PRS(N,) q)⊥would have parameters [N+1,a∈A|Ia∩⊥ I=∅ na+1,≥ t+1]. These codes can also be compared to (RS(N, )q)⊥, with =\{d()}.Taking into account that |Id|=1, this code has parameters [N,a∈A|Ia∩⊥ I=∅ na+1,≥t+1], where tis the number of consecutive exponents in . We see that this code has the same 123 Entanglement-assisted quantum error-correcting codes from… Page 17 of 31 363 dimension as (PRS(N,) q)⊥. However, the bound for the minimum distance is worse than the one for (PRS(N,) q)⊥. The following result shows many situations in which we can use Proposition 4.19 besides the obvious case with ={0}. Lemma 4.20 Let q >2.Ifd λ:= λ(N−1)/(q−1)∈N,forsomeλ,1≤λ≤q−1,then |Idλ|=1. Proof We only have to observe that λN−1 q−1q−λN−1 q−1=λ(N−1)≡0modN−1.  Remark 4.21 If q−1|N−1, then with the previous result we obtain q−1 cyclotomic sets with cardinality one besides I0. For example, if N=qs, then we directly have q−1|N−1. However, that is not the only case. For example we can consider qs=38and N=83. In that situation it can be checked that q−1=2|82 =N−1, and we have that |I41|=1. In this situation, when we have q−1|N−1, the previous result is actually a characterization of when we have |Id|=1: |Id|=1⇐⇒ dq ≡dmod N−1⇐⇒ d(q−1)=λ(N−1)=λ(q−1)N−1 q−1 ⇐⇒ d=λN−1 q−1,for some 1 ≤λ<q−1. Example 4.22 We consider the field extension F16 ⊃F4, which gives the following minimal cyclotomic sets: I0={0},I1={1,4},I2={2,8},I3={3,12},I5={5}, I6={6,9},I7={7,13},I10 ={10},I11 ={11,14},I15 ={15}. Weseethatwehave|I10|=1. If we take ={0,1,4,10}=I0∪I1∪I10,then ⊥={0,1,...,N−1}\{I15 ∪I11 ∪I5}and we can use Corollary 4.16 to compute the dimension. All the cyclotomic sets, besides I5,I11 and I15, have nonzero intersection with ⊥, and we have Id() =I10 ⊂. Hence, by Corollary 4.16,dim(PRS(N,) q)⊥= (n0+n1+n2+n3+n6+n7+n10)+n10 =13. For the minimum distance, we have t=2 consecutive elements in I=, which gives the following parameters for (PRS(N,) q)⊥: [17,13,≥3]. We can do the same for ={0,1,2,4,8,10}=I0∪I1∪I2∪I10, and we obtain the parameters [17,11,≥4]. The true parameters are [17,13,3]and [17,11,4], which lengthen the parameters of the affine case [16,12,3]and [16,10,4]. We see that the bound for the minimum distance coincides with the real minimum distance in this case. Remark 4.23 If we do not assume in Proposition 4.19 that |Id|=1, then, if d=d() ∈B and Id⊂(which is the interesting case in the projective setting), we will have the evaluation of the monomial xd 1in PRS(N,), and also the evaluation of at least one monomial xd−a 0xa 1 with a∈Id\{d}. We know that d≡qramod N−1forsomer>0. Thus, we have the image of xd−qr−1a 0xqr−1a 1in PRS(N,), but if we take this monomial to the power of q,we get xq(d−qr−1a) 0xd 1≡ xd 1mod I(P1). It is not hard to check that we do not have the image of this monomial in PRS(N,), which implies that PRS(N,) is not Galois invariant. In the following example we show how this affects the bound for the minimum distance. 123 363 Page 18 of 31 P. Gimenez et al. Example 4.24 We continue with Example 4.22. We can consider ={0,1,2,3,4},which gives I=I0∪I1. However, we do not have |I4|=1 and Proposition 4.19 does not hold in this case. For instance, there are t=2 consecutive elements in , but the parameters of (PRS(N,) q)⊥are [17,15,2],and2<t+1=3. On the other hand, we have that ()I=I0, which only has t=1 consecutive elements, and Proposition 4.17 would give the parameters [17,15,≥2]. 5 Applications to EAQECCs This section is devoted to providing quantum codes from the linear codes developed in the previous section. Namely, we will construct EAQECCs using the CSS construction (Galindo et al. 2019b, Thm. 4) and the Hermitian construction (Galindo et al. 2019b,Thm.3),aswell as asymmetric EAQECCs (Galindo et al. 2020). 5.1 Euclidean EAQECCs In this section, we will be interested in obtaining EAQECCs using the CSS construction (Galindo et al. 2019b, Thm. 4). Given a nonempty set U⊂Fn q,wedenotebywt(U)the number min{wt(v) |v∈U\{0}}, extending the notation that we have been using only for linear codes until now. Theorem 5.1 (CSS Construction) Let Ci⊂Fn qbe linear codes of dimension ki,fori =1,2. Then, there is an EAQECC with parameters [[n,κ,δ;c]]q,where c=k1−dim(C1∩C⊥ 2), κ =n−(k1+k2)+c,and δ=min wt C⊥ 1\C⊥ 1∩C2,wt C⊥ 2\C⊥ 2∩C1. We are going to introduce some new notation for the codes we are going to use. In what follows, we are assuming that p|N. Definition 5.2 Let A={a0=0<a1<···<aj}, the set of minimal representatives of the minimal cyclotomic sets. We are going to consider a set =t−1 i=0Iai∪{at}, i.e., the union of consecutive minimal cyclotomic sets with minimal representatives a0,...,at−1,andthe minimal element at. For such a set , we are going to consider the code D(N,)defined as the linear code generated by {evXN(x0xα 1)|α∈\{at}} ∪ {evXN(xat 1)}. Remark 5.3 If we look at the basis for the dual codes from Proposition 4.10, we see that D(N,)=PRS(N, ∗)⊥, with ∗={0,1,...,N−1}\ t−1 i=0IN−1−ai. In particular, the codes we are considering are not degenerate. Although the previous remark shows that we can use the notation PRS(N, ∗)⊥instead of D(N,), in what follows we are going to use D(N,), because this will be the appropriate notation for Sect. 6. This allows us to make reference to the following proofs directly from Sect. 6, which helps to avoid repetition. Remark 5.4 By the definitions, it is clear that D(N,) =(RS(N, ), 0)+evXN(xat 1), where =\{at}. This means that dim D(N,)=dim RS(N, )+1=dim RS(N,). 123 Entanglement-assisted quantum error-correcting codes from… Page 19 of 31 363 We also have that dim (D(N,) ⊥)q=dim PRS(N, ∗)q=N+1−t i=0naifrom Corollary 3.7.IfGN, is a generator matrix of RS(N,),thenwehavethat ⎛ ⎜ ⎜ ⎜ ⎝ GN, 0 . . . 0 evYN(xat)1 ⎞ ⎟ ⎟ ⎟ ⎠ is a generator matrix of D(N,). We see that this does not correspond to any standard lengthening technique for linear codes. On the other hand, the BCH-type bound gives wt((D(N,) ⊥)q)≥wt(D(N,) ⊥)≥at+2. Theorem 5.5 Let A={a0=0<a1<a2<···<az}be the set of minimal representatives of the cyclotomic sets Iai,0≤i≤z, of {0,1,...,N−1}with respect to q. Let = t−1 i=0Iai∪{at}, such that RS(N, )⊂RS(N, )⊥,where =t i=0Iai. Then, we can construct an EAQECC with parameters [[n,κ,≥δ;c]]q,wheren =N+1,κ= N+1−2t i=0nai+c, δ=at+2, and c ≤1. Proof We are going to consider the code C1=C2=((D(N,) ⊥)q)⊥for the CSS Construction 5.1.Wehavedim((D(N,) ⊥)q)⊥=N+1−dim (D(N,) ⊥)q=N+1− dim PRS(N, ∗)q=t i=0naiby Remark 5.4. Remark 5.4 also gives wt((D(N,) ⊥)q)≥ at+2. For the parameter c, we claim that dim (D(N,) ⊥)q∩((D(N,) ⊥)q)⊥≥ dim(RS(N, )q,0)−1=t i=0nai−1, which gives c≤1. Let =\{at}.By Remark 5.4 we have D(N,)=(RS(N, ), 0)+evXN(xat 1). We consider v∈(RS(N,) ⊥,0). Then, vis orthogonal to (RS(N, ), 0)(taking into account that RS(N, )⊂RS(N,)), and it is also orthogonal to evXN(xat 1), because the last coordinate of vis 0, which means that v·evXN(xat 1)=v·evXN(x0xat 1),andev XN(x0xat 1)∈ (RS(N,),0). Therefore, v∈D(N,) ⊥. Taking into account the dimension and the fact that the codes D(N,) ⊥are not degenerate, we can write D(N,) ⊥=(RS(N,) ⊥,0)+ w,wherewis a vector with a nonzero last entry. We consider a basis for (D(N,) ⊥)qnow, and we can also assume that all the vectors in the basis, besides one vector w, have 0 as their last coordinate. Taking into account that (D(N,) ⊥)qis not degenerate, this means that we have (D(N,) ⊥)q= ((RS(N,) ⊥)q,0)+wfor some vector wwith nonzero last coordinate. In this case we have (RS(N,) ⊥)q=(RS(N, )⊥)q, because ⊥and ⊥ contain the same complete minimal cyclotomic sets (which is what matters to compute the subfield subcode of the dual, this can be seen using Theorem 2.2 and Galindo and Hernando 2015, Prop. 3). Moreover, we have that RS(N, )q⊂(RS(N, )⊥)q=(RS(N, )q)⊥, because this code is Galois invariant by the reasoning after Corollary 4.16. Thus, we have seen that (D(N,) ⊥)q⊃((RS(N, )⊥)q,0)⊃(RS(N, )q,0).On the other hand, we have ((D(N,) ⊥)q)⊥=(PRS(N, )q,0)+(0,0,...,0,1)∩w⊥. Note that (0,0,...,0,1)/∈w⊥, because whas a nonzero last coordinate. Hence, we can consider a basis for ((D(N,) ⊥)q)⊥formed by (dim RS(N, )q−1)vectors ui∈ (RS(N, )q,0),andavectorw, such that its last coordinate is nonzero. Note that not all vectors can have the last coordinate equal to 0 because that would mean that we have the vector (0,0,...,0,1)∈(D(N,) ⊥)q, contradicting the bound given for the minimum 123 363 Page 20 of 31 P. Gimenez et al. distance. Therefore, all the vectors uiare in (D(N,) ⊥)q∩((D(N,) ⊥)q)⊥, which gives c≤1.  Remark 5.6 In Galindo et al. (2015), there are conditions to have RS(N, )⊂RS(N, )⊥. For example, for the type of set  that we are considering in Theorem 5.5, if, for every cyclotomic set Ia⊂,wehaveIN−1−a⊂ ,thenRS(N, )⊂RS(N, )⊥. For the code RS(N, )⊥we have the bound wt(RS(N, )⊥)≥at+1+1. However, we have at+1+1=at+2 in many cases (this happens if and only if at+1/∈, because in that case at+1=at+1). In that situation, we have the same bound for the minimum distance for RS(N, )⊥and for the corresponding EAQECC from Theorem 5.5. In the following discussion we will assume that at+1+1=at+2. If we get a QECC with parameters [[n,κ,δ;0]]qfrom the affine case using RS(N, )q, then we would get an EAQECC with parameters [[n+1,κ+1+c,δ;c]]qin the projective case using Theorem 5.5,wherec≤1. If we take into account the rate ρ:= κ/nand the net rate ρ:= (κ −c)/n, we see that the code obtained with Theorem 5.5 has better rate and net rate than the one obtained in the affine case. Moreover, it can be checked that the codes we obtain are not directly obtainable from the affine case using the propagation rules from Luo et al. (2022), which can be adapted for EAQECCs arising from Theorem 5.1 (for example, see Anderson et al. 2022). In the constructions from Theorems 5.15 and 6.6, the same argument shows that, as long as at+1+1=at+2, we can obtain codes with better rates than the ones from the affine case, which cannot be deduced from the propagation rules from Luo et al. (2022). Example 5.7 We consider N=qs=34=81, with q=32(s=2). The first minimal cyclotomic sets, ordered by their minimal element, are I0={0},I1={1,9},I2={2,18},I3={3,27},I4={4,36},I5={5,45}. With the notation that we have been using, we consider the minimal elements ai,fori= 0,...,5, and =4 i=0Iai∪{5}(t=5 with the previous notation). We have 5 i=0nai=11, and we have at+2=7. It is easy to check that IN−1−ai⊂ for i=0,...,5. By Remark 5.6 we have RS(N, )⊂RS(N, )⊥and we can apply Theorem 5.5 to obtain a quantum code with parameters [[82,61,7;1]]9. If we had used the affine code RS(N, ) with  =5 i=0Iai, the bound for the minimum distance would have been the same, because at+1=8/∈, and we would have obtained the code [[81,59,7;0]]9. We can also get QECCs (EAQECCs with c=0) directly under some assumptions, as the following result shows. Proposition 5.8 Assume that p >2. Let N be an odd integer, such that N −1|qs−1 and p |N. We consider a union of cyclotomic sets ⊂{0,1,...,N−1}, such that d=d() =(N−1)/2. If t is the number of consecutive exponents in ,thenwecan construct a QECC with parameters [[n,κ,≥δ;0]]q,wheren=N+1,κ=N+1−2||, and δ=t+1. Proof By Proposition 4.19, Lemma 4.20 and Remark 5.3,wehavethatPRS(N,)is Galois invariant, and we have wt((PRS(N,) q)⊥)≥t+1. By Corollary 4.11,ifweconsider d={0,1,...,(N−1)/2},wehavethat PRS(N,)⊂PRS(N, d)=PRS(N, d)⊥⊂PRS(N,) ⊥. 123 Entanglement-assisted quantum error-correcting codes from… Page 21 of 31 363 Therefore, considering the intersection with Fn qwe obtain that PRS(N,) q⊂ (PRS(N,) q)⊥.IfweconsiderC1=C2=PRS(N,) qin the CSS Construction 5.1, we have already obtained the length, the bound for the minimum distance, and c=0, for the parameters of the corresponding quantum error-correcting code. For the dimension, we have dim PRS(N,) q=||by Corollary 3.7, taking into account that |Id|=1inthiscaseby Lemma 4.20. Example 5.9 We consider qs=33,q=3andN=33=27. Let =I0∪I1∪I4∪I13 (note that 13 =(N−1)/2). We are not considering consecutive cyclotomic sets, which means that the BCH-type bound for the minimum distance might not be accurate. Hence, we have computed it directly with Magma (Bosma et al. 1997). The code (PRS(N,) q)⊥has parameters [28,20,6], which gives a QECC with parameters [[28,12,6;0]]3by Proposition 5.8,which are the best known parameters for a quantum code over F3with that length and dimension according to Grassl (2007). With RS(N,)and RS(N, )(where =\{(N−1)/2}), we obtain the parameters [27,19,6]and [27,20,5]for the dual codes of their subfield subcodes, respectively. These codes would give QECCs with parameters [[27,11,6;0]]3and [[27,13,5;0]]3, respectively, applying the CSS Construction 5.1. 5.2 Asymmetric EAQECCs As we said in the introduction, phase-shift and qudit-flip errors are not equally likely to occur. It is, therefore, desirable to obtain EAQECCs with different error correction capabilities for each of these types of errors. To construct asymmetric EAQECCs, we can use the following result from Galindo et al. (2020). Theorem 5.10 Let Ci⊂Fn qbe linear codes of dimension ki,fori =1,2. Then, there is an asymmetric EAQECC with parameters [[n,κ,δ z/δx;c]]q,where c=k1−dim(C1∩C⊥ 2), κ =n−(k1+k2)+c, δz=wt C⊥ 1\C⊥ 1∩C2and δx=wt C⊥ 2\C⊥ 2∩C1. The two minimum distances δzand δxgive the error correction capability of the corresponding asymmetric EAQECC, which can correct up to (δz−1)/2phase-shift errors and (δx−1)/2qudit-flip errors. In Sects. 3and 4, we obtained bases for both the primary codes PRS(N,) qand their duals (PRS(N,) q)⊥. This is the key for the proof of the following result, which allows us to construct asymmetric EAQECCs from subfield subcodes of projective Reed–Solomon codes. We recall that, for ⊂{0,1,...,N−1}, we denote I=Ia⊂Ia,andwealso recall that Bis the set of maximal representatives of the minimal cyclotomic sets. Theorem 5.11 Let 1≤d1,d2≤N−1, such that di∈B,fori =1,2, and p |N. We consider di={0,1,...,di}and we denote  di:= di\{di},fori =1,2.If(( d1)I)⊥⊂( d2)I, then we can construct an asymmetric EAQECC with parameters ⎡ ⎣⎡ ⎣N+1, b∈B,b<d1 nb+ b∈B,b<d2 nb+2−N,δ z/δx;1⎤ ⎦⎤ ⎦q , where δz≥N−d1+1,δx≥N−d2+1. 123 363 Page 22 of 31 P. Gimenez et al. Proof We are going to consider Ci=(PRS(N, di)q)⊥,fori=1,2, and we are going to use Theorem 5.10. The bounds for δzand δxare clear, and we obtain the dimension using Corollary 3.7 if we assume c=1. For the parameter c=dim(PRS(N, d1)q)⊥− dim((PRS(N, d1)q)⊥∩PRS(N, d2)q), we are going to study dim((PRS(N, d1)q)⊥∩ PRS(N, d2)q).For(PRS(N, d1)q)⊥we have the basis given by the evaluation of the following set from Theorem 4.14:  a∈A|Ia∩⊥ d1=∅ {Ta(ξr ax0xa 1)|0≤r≤na−1}∪ {TN−1−d1(ξr N−1−d1xN−1−d1 1)|0≤r≤nd1−1}.(6) From Theorem 3.4 it is easy to obtain that the evaluation of the following set gives a basis for PRS(N, d2)q:  a∈A|Ia⊂ d2 {Ta(ξr ax0xa 1)|0≤r≤na−1}∪{Th d2(xd2 1)}.(7) It is also clear that the a∈A, such that Ia∩⊥ d1=∅are precisely the a∈A, such that Ia⊂((d1)I)⊥.Wealsohavethat(( d1)I)⊥=((d1)I)⊥∪IN−1−d1. Therefore, taking into account the assumption (( d1)I)⊥⊂( d2)I⊂ d2, we have that all the traces of monomials of the type x0xa 1, with a∈A, in the set from (6), are contained in the set from (7). This implies that the evaluation of the set  a∈A|Ia∩⊥ d1=∅ {Ta(ξr ax0xa 1)|0≤r≤na−1}(8) is in (PRS(N, d1)q)⊥∩PRS(N, d2)q. Now we are going to study which polynomials from the set generated by {TN−1−d1(ξr N−1−d1xN−1−d1 1)|0≤r≤nd1−1} have their evaluation in (PRS(N, d1)q)⊥∩PRS(N, d2)q. As in Theorem 4.14,we assume that ξN−1−d1is a primitive element of Fqnd1(note that nd1=nN−1−d1), such that TN−1−d1(ξN−1−d1)= 0. For ease of notation, we are going to denote now d 1=N−1−d1. For 0 ≤r≤nd1−1, r= 1, we have Td 1(ξd 1)Td 1(ξr d 1 x0xd 1 1)−Td 1(ξr d 1 )Td 1(ξd 1x0xd 1 1) ≡Td 1(ξd 1)Td 1(ξr d 1 xd 1 1)−Td 1(ξr d 1 )Td 1(ξd 1xd 1 1)mod I(XN). (9) This is easy to see, because when we set x0=1, we obtain the same polynomials at each side, which means that they have the same evaluation in [{1}×YN], and both polynomials evaluate to 0 in [0:1]. Therefore, they have the same evaluation in XN. Because of the assumption (( d1)I)⊥=((d1)I)⊥∪Id 1⊂( d2)I, we obtain Id 1⊂ d2and it is clear that we have the evaluation of the polynomial in the left-hand side of (9)inPRS(N, d2)q if we consider the basis from (7). The evaluation of the polynomial in the right-hand side is clearly in (PRS(N, d1)q)⊥(see (6)). Thus, we have proved that the image by the evaluation map of the polynomials in the set {Td 1(ξd 1)Td 1(ξr d 1 x0xd 1 1)−Td 1(ξr d 1 )Td 1(ξd 1x0xd 1 1)|0≤r≤nd1−1,r= 1}(10) 123 Entanglement-assisted quantum error-correcting codes from… Page 23 of 31 363 is in (PRS(N, d1)q)⊥∩PRS(N, d2)q. Hence, the evaluation of the union of the sets from (8)and(10)isin(PRS(N, d1)q)⊥∩ PRS(N, d2)q, and it is easy to see that the evaluation of this union is linearly independent. Taking into account the basis from (6), we obtain that dim((PRS(N, d1)q)⊥∩ PRS(N, d2)q)≥dim((PRS(N, d1)q)⊥)−1, i.e., c≤1. On the other hand, having c=0 means that (PRS(N, d1)q)⊥⊂PRS(N, d2)q.This implies that the evaluation of all the traces appearing in (9)areinPRS(N, d2)q.However, the evaluations of Td 1(ξd 1x0xd 1 1)and Td 1(ξd 1xd 1 1)differ only at the coordinate associated to the point [0:1]. This would imply that the minimum distance of PRS(N, d2)qis 1, a contradiction. Therefore, c=1.  Remark 5.12 We note that in the previous result we have that ( d)I=b∈B|b<dIb. As we said in the introduction, it is desirable to obtain asymmetric quantum codes with higher error-correction capability for phase-shift errors, i.e. with δz>δ x. For the codes obtained using Theorem 5.11, this corresponds to choosing d1<d2. In the next example we show that we are able to obtain codes which are better than the ones available in the current literature. Example 5.13 We consider the extension F16 ⊃F4, which is the setting from Example 4.22. We choose d1=14, d2=15, and apply Theorem 5.11, which gives the parameters [[17,14,3/2;1]]4. In Galindo et al. (2020), we can find a code with parameters [[15,12,3/2;1]]4using BCH codes. We see that the code we have obtained has better rate κ/n, and also better net rate (κ −c)/n. If we consider the extension F25 ⊃F5instead, and choose d1=22, d2=23, we obtain a code with parameters [[26,19,4/3;1]]5using Theorem 5.11. It is possible to adapt the propagation rules from Luo et al. (2022) to asymmetric EAQECCs arising from Theorem 5.10. For example, we can reduce the length by using extra entanglement, provided that c≤ n−κ−2: [[n,κ,δ z/δx;c]]q→[[n−1,κ,δ z/δx;c+1]]q.(11) In Galindo et al. (2020) a code with parameters [[24,19,4/3;3]]5is presented, which can be obtained from our code with parameters [[26,19,4/3;1]]5by applying (11) two times. In this sense, we can say that the parameters [[24,19,4/3;3]]5appearing in Galindo et al. (2020) are a consequence of the parameters [[26,19,4/3;1]]5that we obtain with Theorem 5.11. Finally, if we consider the extension F64 ⊃F8,ford1=60 and d2=63, we obtain the parameters [[65,58,5/2;1]]8, which give a better rate and net rate than the code with parameters [[63,56,5/2;1]]8from Galindo et al. (2020). If we choose d1=58 and d2=62 instead, we obtain the parameters [[65,52,7/3;1]]8, which, after using the propagation rule (11) as before, give the parameters [[63,52,7/3;3]]8that appear in Galindo et al. (2020). If we do not assume (( d1)I)⊥⊂( d2)Iin Theorem 5.11, then we would obtain instead the parameters [[N+1,b∈B,b<d1nb+b∈B,b<d2nb+1+c−N,δ z/δx;c]]q,forc= dim(PRS(N, d1)q)⊥−dim((PRS(N, d1)q)⊥∩PRS(N, d2)q). 5.3 Hermitian EAQECCs In the Hermitian case, we have to work with three different fields. Hence, we are going to change the notation from the previous sections. We consider the field extension Fq2⊃Fq2, 123 363 Page 24 of 31 P. Gimenez et al. where q2=p2r,q=ps,forsomer,s>0, and r=s. Thus, in what follows we are going to obtain codes of length n=N+1, where N>1isaninteger,suchthatN−1|q2−1. As before, we are going to consider the set ZN={0}∪{1,2,...,N−1},where {1,2,...,N−1}is regarded as the set of representatives of the ring Z/(N−1)Z.Weconsider the cyclotomic sets with respect to q2over {0,1,...,N−1}. We call Athe set of minimal elements of the different cyclotomic sets. We introduce now the Hermitian construction (Galindo et al. 2019b, Thm. 3) that we are going to use. Theorem 5.14 (Hermitian construction) Let C ⊂Fn q2be a linear code of dimension k and C⊥hits Hermitian dual. Then, there is an EAQECC with parameters [[n,κ,δ;c]]q,where c=k−dim(C∩C⊥h), κ =n−2k+c,and δ=wt(C⊥h\(C∩C⊥h)). We are only going to consider the Hermitian product over Fq2. Therefore, for a,b∈Fn q2 we have a·hb:= n  i=0 aibq i. In what follows, when considering a power of a code or a vector, we will be considering the component-wise power, i.e., Cq:= {cq:= (cq 1,...,cq n)|c=(c1,...,cn)∈C}.Itis easy to check that, for codes over Fq2,wehavethatC⊥=(C⊥h)q,whereC⊥hdenotes the Hermitian dual. Theorem 5.15 Let A={a0=0<a1<a2<··· <az}be the set of minimal representatives of the cyclotomic sets Iai,0≤i≤z, of {0,1,...,N−1}with respect to q2.Let =t−1 i=0Iai∪{at}, such that RS(N, )q2⊂(RS(N, )q2)⊥h,where =t i=0Iai. Then, we can construct an EAQECC with parameters [[n,κ,≥δ;c]]q,wheren=N+1, κ=N+1−2t i=0nai+c, δ=at+2and c ≤1. Proof We are going to consider the code C=((D(N,) ⊥)q2)⊥hfor the Hermitian construction 5.14. Using what we obtained in Theorem 5.5, the only thing left to prove is the statement about the parameter c. Following the proof of Theorem 5.5,wehave(D(N,) ⊥)q2=((RS(N, )⊥)q2,0)+ wfor some vector wwith nonzero last coordinate. Therefore, we see that dim ((D(N,) ⊥)q2)⊥h=dim RS(N, )q2=dim((RS(N, )⊥)q2)⊥h. Moreover, we have ((RS(N, )⊥)q2)⊥h=((RS(N, )q2)⊥)⊥h=(((RS(N, )q2)⊥)⊥)q =RS(N, )q2q. Thus, we obtain ((D(N,) ⊥)q2)⊥h=(((PRS(N, )q2)q,0)+(0,0,...,0,1))∩(w)⊥h. Note that (0,0,...,0,1)/∈(w)⊥h, because whas a nonzero last coordinate. We can consider a basis for ((D(N,) ⊥)q2)⊥hformed by (dim RS(N, )q2−1)vectors ui∈ ((RS(N, )q2)q,0), and a vector w, such that its last coordinate is nonzero (not all vectors can have the last coordinate equal to 0 because that would mean that we have the vector (0,0,...,0,1)∈(D(N,) ⊥)q2, contradicting the bound given for the minimum distance). 123 Entanglement-assisted quantum error-correcting codes from… Page 25 of 31 363 By our hypothesis, we have RS(N, )q2⊂(RS(N, )q2)⊥h. This implies that RS(N, )q2q⊂(RS(N, )q2)⊥hq=(RS(N, )q2)⊥=(RS(N, )⊥)q2.Taking into account that (D(N,) ⊥)q2⊃((RS(N, )⊥)q2,0)⊃((RS(N, )q2)q,0),we see that the vectors uiare in (D(N,) ⊥)q2as well, and we obtain the desired inequality for the dimension of the intersection.  Remark 5.16 From Galindo et al. (2015, Prop. 3) we can obtain conditions to have RS(N, )q2⊂(RS(N, )q2)⊥h, like the one we show next. Let  =t i=0Iai, and we denote by a ithe minimal element in A, such that Ia i=I−qai. Assuming d() < N−1, if  ⊂()⊥h:= {0,1,...,N−1}\ t i=0Ia i,thenwehave RS(N, )q2⊂(RS(N, )q2)⊥h. Example 5.17 We continue with the setting from Example 5.7. It is easy to check that the set in Example 5.7 satisfies ⊂⊥h, and by Remark 5.16 and Theorem 5.15 we obtain a quantum code with parameters [[82,67,7;1]]3. With the construction from Theorem 5.15 we can obtain several quantum codes over F2 whose parameters do not appear in the table of EAQECCs from Grassl (2007), and therefore, we improve the table. With the extension F24⊃F22, we can obtain a code with parameters [[17,12,3;1]]2, which is not in the table from Grassl (2007). We can consider now the following propagation rule from Luo et al. (2022): let Cbe an EAQECC with parameters [[n,κ,δ;c]]qobtained from Theorem 5.14 (for example, the codes from Theorem 5.15). If c≤n−κ−2, then we can reduce the length using extra entanglement: [[n,κ,δ;c]]q→[[n−1,κ,δ;c+1]]q.(12) Iterating this rule, it is easy to check that, from an EAQECC with parameters [[n,κ,δ;c]]q, one can obtain EAQECCs with parameters [[n−s,κ,δ;c+s]]q,s=1,...,(n−κ−c)/2. Note that the maximum value for cis k=dim C,whereCis the classical code used for Theorem 5.14, and for the maximum value of sthat we have stated we have precisely that c+s=k: c+s=c+n−κ−c 2=c+2k−2c 2=k. Applying the propagation rule (12) to the parameters [[17,12,3;1]]2,weobtain [[16,12,3;2]]2and [[15,12,3;3]]2, which are also missing in the table (Grassl 2007). For the extension F26⊃F22, we obtain codes with length 65, which is greater than the current maximum length in Grassl (2007) for EAQECCs over F2. Nevertheless, we can reduce the length with the propagation rule (12) and check if the corresponding parameters are in the table. A code with parameters [[64,58,3;2]]2, whose parameters are missing in Grassl (2007), is obtained from the code with parameters [[65,58,3;1]]2derived from Theorem 5.15 using (12). Moreover, by applying the propagation rule (12) to the code with parameters [[65,40,7;1]]2deduced from Theorem 5.15, we obtain codes with parameters [[65 −i,40,7;1+i]]2,fori=1,2,...,12, whose parameters are also missing in Grassl (2007). In total, we obtain in this way 16 EAQECCs over F2whose parameters are missing in Grassl (2007). The table of EAQECCs from Grassl (2007) also covers codes over F3.However,the smaller length that we can achieve with Theorem 5.15 over F3would be 34+1=82, much higher than the current maximum length in the table from Grassl (2007) for this case. For 123