To provide a circuit constitution method capable of constituting an arithmetic circuit for performing an operation on a finite body in a small scale with less circuit components, compared with in the past.
A first primitive root α1 is obtained on the basis of a first polynomial equation for the fist extension from a first finite body to a second finite body (ST1). A second primitive root α2 is obtained on the basis of a second polynomial expression for the second extension from the second finite body to a third finite body, in which a coefficient of 0-order term is regulated by use of the first primitive root 1 obtained in ST1 and the coefficient of 0-order term of the first polynomial equation (ST2). The operation on the third finite body is regulated by use of a base expressed by use of the second primitive root α2 to constitute the arithmetic circuit (ST3 and 4).