Let (b1,b2,…,bk) be a permutation of {a1,a2,…,ak} which is an arithmetic sequence in (mod p). Then, for some integers c and d we have bi≡c+id(modp) for every i=1,2,…,k.
It is easy to see that k is the order of a in (mod p). Then, we have ak≡1(modp) and
b1+b2+⋯+bk≡a+a2+⋯+ak=a−1ak−1≡0(modp).
On the other hand, we have
b1+b2+⋯+bk≡2k(2c+d(k+1))(modp)
and hence, we get
2c+d(k+1)≡0(modp).
Similarly, we have
b12+b22+⋯+bk2≡a2+a4+⋯+a2k=a2a2−1a2k−1≡0(modp).
since 1<a<p−1. Moreover,
i=1∑kbi2=i=1∑k(c+id)2=kc2+cdk(k+1)+d26k(k+1)(2k+1)
Therefore, we get
kc2+cdk(k+1)+d26k(k+1)(2k+1)≡0(modp)(2)
By (1), we can replace c=−d(k+1)/2 in (2) and get
4d2k(k+1)2−2d2k(k+1)2+6d2k(k+1)(2k+1)≡0(modp)
and hence,
2d2k(k+1)(−2k+1+32k+1)=12d2k(k+1)(k−1)≡0(modp).
Clearly, d=0 (mod p) and 2<k≤p−1. Therefore, we see that k=p−1.