Alphabeta Math
Session-authored (Fable 5 assisted)
How statement and proof provenance work

The first chip identifies the source of the statement or construction; the second identifies the source of its local proof or verification.

  • Literature-sourced: the exact statement appears in a cited source; only wording and notation differ.
  • AI-adapted: a semantically identical restatement of literature-sourced material, modulo indexing, notation, and boundary cases adopted by the library.
  • AI-generated: a genuinely novel statement formulated by AI, with no source for the claim itself.

These labels describe origin, not correctness: citations and verification chips remain separate evidence.

58 results · all verified · 43 also independently AI-judged
Every result on this page is machine-checked by a proof checker and read in full and owner-audited; the judge is an additional, independent cross-model AI review of the proofs. The 15 not AI-judged were verified by owner audit (typically over a confirmed judge false positive), not failures.

Finite Fields and Cyclotomic Extensions

1 · Prerequisites

2 · Summary

Finite fields on this page are governed by the Frobenius endomorphism, Artin's fixed-field theorem, and the finite Galois correspondence. The page uses the published algebraic-extension and Galois pages for degree, splitting, and automorphism machinery, then adds the relative Frobenius, the finite cyclic-group lemmas it needs, Dedekind independence for normal bases, and the polynomial and unit-group facts that control cyclotomic extensions and finite-field factorisations.

The development begins with finite fields: the q-power map identifies the fixed field, determines the full Galois group, describes every intermediate field, and controls Frobenius conjugates and normal bases. It then turns to roots of unity and cyclotomic extensions, defines Φn by the divisor recursion, proves the primitive-root and irreducibility theorems, and uses the resulting Galois groups to study finite-field factorisation, composita and intersections over Q, primes congruent to 1 modulo n, and finite abelian Galois groups over Q.

3 · Logical flowchart

4 · Definitions, theorems and proofs

LemmaStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

A finite cyclic group has exactly one subgroup of each order dividing its own

Statement

Let G=g be a cyclic group of finite order n1 (The subgroup S generated by a subset, the cyclic subgroup g, and cyclic groups). For every positive divisor d of n (Divisibility in Z: da when a=dq for some integer q):

gn/d is a subgroup of G of order d,

it is the only subgroup of G of order d, and every subgroup of G is of this form for exactly one such d. Moreover, for positive divisors d and e of n,

gn/dgn/ede.

The two extremes are instances rather than exceptions: d=1 gives the trivial subgroup {e} and d=n gives G itself, and at n=1 the only divisor is d=1, where G is trivial.

Facts & Assumptions

Given: A cyclic group G=g whose underlying set is finite of order n1; divisibility of integers is that of Divisibility in Z: da when a=dq for some integer q, and orders are those of The order G of a finite group and the order ord(g) of an element, with ord(g)= when no positive power of g is the identity.

[A1]

G=n, and since G=g, [L1] gives ord(g)=g=n.

[L1]

For an element x of finite order m in a group: xk=e if and only if mk; the powers x0,x1,,xm1 are pairwise distinct; and x={xs:sN, s<m}, so x is finite with x=m=ord(x) (If ord(g)=n then gk=e iff k is an integer multiple of n, the powers g0,,gn1 are distinct, and g has exactly n elements; if g has infinite order then gj=gk only for j=k).

[L2]

x={xk:kZ}: the cyclic subgroup generated by x is exactly the set of integer powers of x (g={gn:nZ}, and every cyclic group is abelian).

[L3]

For a finite group G and HG one has G=[G:H]H; consequently H divides G (Lagrange's theorem: G=[G:H]H for every subgroup H of a finite group G).

Proof

technique · direct
1.1

Fix a positive divisor d of n and put c:=n/d, an integer with c1 and n=cd.

givenalgebra
2.1

The element gc has order exactly d: first (gc)d=gcd=gn=e by [A1] and [L1]; and if 1j<d then 1cj<cd=n, so ncj and hence (gc)j=gcje by [L1]. Therefore gc=d by [L1].

step 1.1A1L1algebra
2.2

The set of xG with xd=e is exactly gc: writing x=gm with mZ by [L2] and [A1], the condition xd=gmd=e says nmd by [L1], that is cdmd, that is cm; and {gm:cm}={(gc)k:kZ}=gc by [L2].

step 1.1A1L1L2algebra
2.3

For positive divisors d,e of n with de, write e=df with f1; then n/d=(n/e)f, so gn/d=(gn/e)fgn/e by [L2], and therefore gn/dgn/e, the latter being a subgroup containing gn/d.

step 1.1L2algebra
3.1

If HG has H=d, then H=gc: each hH has ord(h)=h dividing H=d by [L1] and [L3], so hd=e by [L1] and hence hgc by step 2.2; thus Hgc, and both sets have exactly d elements by step 2.1, so they are equal.

step 2.1step 2.2L1L3
4.1

Every subgroup HG has this form for exactly one positive divisor of n: H is a subset of the finite set G, so d:=H is defined and divides n by [L3] and [A1], and step 3.1 gives H=gn/d; the divisor is determined by H, being its order.

step 2.1step 3.1A1L3
5.1

Conversely, if gn/dgn/e then de, since by step 2.1 the two subgroups have orders d and e and [L3] applied to the subgroup gn/d of gn/e makes d divide e. Together with steps 2.1, 3.1, 4.1 and 2.3 this proves every clause of the lemma.

step 2.1step 3.1step 2.3step 4.1L3

Remarks

  • What the divisor lattice buys. The clause that matters downstream is not existence but uniqueness: a subgroup of a finite cyclic group is pinned down by its order alone, so the Galois correspondence turns "subgroups of Gal(Fqn/Fq)" into "divisors of n" with nothing left to choose (The intermediate fields of Fqn/Fq are the Fqd, one for each positive divisor d of n).

  • Where cyclicity is used. Uniqueness fails without it. In the Klein four-group there are three distinct subgroups of order two, and the argument breaks at step 2.2, where the solutions of x2=e form the whole group rather than a single cyclic subgroup.

LemmaStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

A cyclic group of order n has exactly φ(n) generators

Statement

Let G=g be a cyclic group of finite order n1 (The subgroup S generated by a subset, the cyclic subgroup g, and cyclic groups). For an integer a,

ga=Ggcd(a,n)=1,

that is, ga generates G exactly when a and n are coprime (Coprime integers: gcd(a,b)=1). Consequently G has exactly φ(n) generators (The unit group (Z/n)× and Euler's totient φ(n)=(Z/n)× for n1).

At n=1 the group is trivial, every integer is coprime to 1, and the single element is its own generator, in agreement with φ(1)=1.

Facts & Assumptions

Given: A cyclic group G=g whose underlying set is finite of order n1.

[A1]

G=n, and since G=g, [L1] gives ord(g)=g=n; in particular gn=e.

[L1]

For an element x of finite order m in a group: xk=e if and only if mk; the powers x0,x1,,xm1 are pairwise distinct; and x={xs:sN, s<m}, so x=m=ord(x) (If ord(g)=n then gk=e iff k is an integer multiple of n, the powers g0,,gn1 are distinct, and g has exactly n elements; if g has infinite order then gj=gk only for j=k, The order G of a finite group and the order ord(g) of an element, with ord(g)= when no positive power of g is the identity).

[L4]

gcd(a,b) is a common divisor of a and b, and gcd(a,b)1 whenever (a,b)(0,0) (Common divisor, and the greatest common divisor gcd(a,b), with the convention gcd(0,0):=0).

[L5]

For n1, every class in Z/n contains exactly one integer r with 0r<n, and r[r]n is a bijection from {0,,n1} onto Z/n (For n1, every class in Z/n has one representative r with 0r<n, so Z/n=n; while Z/0 is in bijection with Z).

[L6]

For n1 and aZ, the class [a]n is a unit of Z/n if and only if gcd(a,n)=1 (For n1, [a]n is a unit if and only if gcd(a,n)=1).

Proof

technique · direct
1.1

Put m:=gcd(a,n). Since n1 the pair (a,n) is not (0,0), so m1, ma and mn by [L4].

L4given
2.1

If m=1 then ga generates G: by [L3] there are integers u,v with au+nv=1, whence g=gau+nv=(ga)u(gn)v=(ga)u using gn=e from [A1]; so gga by [L2], and ga is then a subgroup containing g, so it contains g=G by [L2] and equals G.

step 1.1A1L2L3
2.2

Conversely, if ga generates G then m=1: from ma and mn the integer n/m is at least 1 and (ga)n/m=(gn)a/m=e by [A1], so ord(ga)n/m and hence gan/m by [L1]; but ga=G has n elements, so nn/m and therefore m=1.

step 1.1A1L1algebra
3.1

By [A1] and [L1] the powers g0,g1,,gn1 are pairwise distinct and exhaust G, so the generators of G are exactly the elements gr with 0r<n and gcd(r,n)=1, one for each such r.

step 2.1step 2.2A1L1
4.1

By [L5] the map r[r]n is a bijection from {0,,n1} onto Z/n, and by [L6] it carries the r with gcd(r,n)=1 onto the units of Z/n; so the number of such r is (Z/n)×=φ(n) by [L7], and by step 3.1 that is the number of generators of G.

step 3.1L5L6L7

Remarks

DefinitionDefinition: Literature-sourcedProof: Not applicablejudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

The relative Frobenius xxq of an extension of finite fields

Definition

Let Fq be a finite field of order q (Finite fields and their order) and let E be a finite field having Fq as a subfield. The relative Frobenius of the extension E/Fq is the map

σq ⁣:EE,σq(x)=xq.

It is an Fq-automorphism of E, and no separate result is needed for that. Let p be the characteristic of E; the subfield Fq has the same identity element and hence the same characteristic, so q=pk with k=[Fq:Fp] by Every finite field has order pn for a unique prime characteristic p and positive integer n. The Frobenius map FrE ⁣:xxp is an injective field endomorphism of E, is an automorphism because E is finite, and has k-fold iterate xxpk (Frobenius xxp is an injective endomorphism in characteristic p, and an automorphism for finite fields); that iterate is σq. Every aFq satisfies aq=a (A field with q elements is the splitting field of xqx over its prime subfield), so σq fixes Fq pointwise. Hence

σqAut(E/Fq)

(Relative field automorphisms and Aut(K/F)). Its iterates are σqi(x)=xqi for iN, with σq0 the identity.

Remarks

  • The letter. The relative Frobenius is written σq rather than φq because φ is Euler's totient (The unit group (Z/n)× and Euler's totient φ(n)=(Z/n)× for n1) everywhere below, and the two symbols would otherwise stand side by side in the same formula.

  • Relative, not absolute. FrE is intrinsic to E; σq depends on the chosen base field Fq, and it is the identity exactly when E=Fq. Taking Fq to be the prime field returns FrE itself.

LemmaStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

The elements of a finite extension fixed by the q-power map are exactly the base field

Statement

Let Fq be a finite field of order q and let E be a finite field having Fq as a subfield. Then

{xE:xq=x}=Fq.

Equivalently, the fixed field of the cyclic group generated by the relative Frobenius σq (The relative Frobenius xxq of an extension of finite fields) is the base field:

Eσq=Fq.

Facts & Assumptions

Given: Finite fields FqE with Fq=q (Finite fields and their order), and the set S:={xE:xq=x}.

[L1]

The relative Frobenius is σq(x)=xq, an Fq-automorphism of E (The relative Frobenius xxq of an extension of finite fields).

[L2]

If F is a field with q elements, then every aF satisfies aq=a (A field with q elements is the splitting field of xqx over its prime subfield).

[L3]

Let D be an integral domain. A nonzero polynomial fD[x] of degree n has at most n distinct roots in D (A nonzero polynomial of degree n over an integral domain has at most n distinct roots).

[L4]

The fixed field of a subgroup G of the automorphism group of K is KG={xK:σ(x)=x for every σG} (The fixed field KG of a group of field automorphisms).

Proof

technique · direct
1.1

Applying [L2] to the field Fq, which has exactly q elements, every aFq satisfies aq=a; hence FqS.

L2given
1.2

S is the set of roots in E of the polynomial tqtE[t], which is nonzero of degree q; a field is an integral domain, so [L3] gives Sq.

L3given
2.1

Since FqS, Fq=q and Sq, the finite sets Fq and S coincide: {xE:xq=x}=Fq.

step 1.1step 1.2given
3.1

An element of E is fixed by every power of σq precisely when it is fixed by σq itself, so Eσq={xE:xq=x} by [L1] and [L4], and step 2.1 identifies this with Fq.

step 2.1L1L4

Remarks

LemmaStatement: AI-adaptedProof: AI-generatedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

For a degree-n extension of a field of order q, the q-power map has order exactly n

Statement

Let Fq be a finite field of order q and let E/Fq be an extension of finite fields of degree n (The degree [K:F]=dimFK of a finite field extension). Then

E=qn,

and the relative Frobenius σq (The relative Frobenius xxq of an extension of finite fields) has order exactly n in Aut(E/Fq) (The order G of a finite group and the order ord(g) of an element, with ord(g)= when no positive power of g is the identity). At n=1 this says σq is the identity, of order one.

Facts & Assumptions

Given: Finite fields FqE with Fq=q and [E:Fq]=n; the prime subfield of E is Fp with p the characteristic, and Fq has the same characteristic, its identity element being that of E.

[L1]

The relative Frobenius is σq(x)=xq, an Fq-automorphism of E, with σqi(x)=xqi (The relative Frobenius xxq of an extension of finite fields).

[L2]

If F is a field with q elements, then every aF satisfies aq=a (A field with q elements is the splitting field of xqx over its prime subfield).

[L3]

Let D be an integral domain. A nonzero polynomial fD[x] of degree n has at most n distinct roots in D (A nonzero polynomial of degree n over an integral domain has at most n distinct roots).

[L4]

If F is a finite field, then there is a unique prime p and a unique positive integer m with F=pm; here p=charF and m=[F:Fp] (Every finite field has order pn for a unique prime characteristic p and positive integer n).

[L5]

For fields FKL with K/F and L/K finite, L/F is finite and [L:F]=[L:K][K:F] (Tower law for finite extensions: [L:F]=[L:K][K:F]).

Proof

technique · direct
1.1

By [L4] applied to Fq, q=pk with k=[Fq:Fp]; by [L4] applied to E, E=pm with m=[E:Fp].

L4given
2.1

The tower FpFqE and [L5] give m=[E:Fq][Fq:Fp]=nk, so E=pnk=(pk)n=qn.

step 1.1L5algebra
3.1

Every xE satisfies xqn=x, by [L2] applied to E, whose order is qn by step 2.1; by [L1] this says σqn=idE.

step 2.1L1L2
3.2

For an integer j with 1j<n one has σqjidE: otherwise every one of the qn elements of E would be a root of the nonzero polynomial tqjtE[t], whose degree qj is smaller than qn because q2, contradicting [L3].

step 2.1L1L3algebra
4.1

The least j1 with σqj=idE is therefore j=n, that is ord(σq)=n; for n=1 steps 3.1 and 3.2 say only that σq=idE, of order one.

step 3.1step 3.2L1
TheoremStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

A finite extension of a finite field of order q is Galois with cyclic Galois group generated by xxq

Statement

Let Fq be a finite field of order q and let E be a finite field having Fq as a subfield, with [E:Fq]=n (The degree [K:F]=dimFK of a finite field extension). Then E/Fq is a finite Galois extension (Finite Galois extensions and Gal(K/F)) and

Gal(E/Fq)=σq

is cyclic of order n, generated by the relative Frobenius σq ⁣:xxq (The relative Frobenius xxq of an extension of finite fields).

Facts & Assumptions

Given: Finite fields FqE with Fq=q and [E:Fq]=n, and the subgroup G:=σq of Aut(E/Fq).

[L1]

The relative Frobenius σq(x)=xq is an Fq-automorphism of E (The relative Frobenius xxq of an extension of finite fields).

[L2]

{xE:xq=x}=Fq, that is Eσq=Fq (The elements of a finite extension fixed by the q-power map are exactly the base field).

[L3]

E=qn and σq has order exactly n in Aut(E/Fq) (For a degree-n extension of a field of order q, the q-power map has order exactly n).

[L4]

If G is a finite group of automorphisms of K, then [K:KG]=G and Aut(K/KG)=G (Artin's fixed-field theorem: [K:KG]=G and Aut(K/KG)=G).

[L5]

For a finite extension K/F with G=Aut(K/F), the conditions "K/F is Galois", "K is the splitting field over F of a separable polynomial", "G=[K:F]" and "KG=F" are equivalent (Equivalent characterizations of a finite Galois extension).

[L6]

KG={xK:σ(x)=x for every σG} (The fixed field KG of a group of field automorphisms).

Proof

technique · direct
1.1

G=σq is a cyclic group of automorphisms of E, finite of order n by [L1] and [L3].

L1L3
1.2

Its fixed field is EG=Fq by [L2] and [L6].

L2L6
2.1

Applying [L4] to the finite automorphism group G of E and using step 1.2, [E:Fq]=[E:EG]=G=n and Aut(E/Fq)=Aut(E/EG)=G.

step 1.1step 1.2L4
3.1

Hence Aut(E/Fq)=n=[E:Fq], so E/Fq is Galois by [L5], and Gal(E/Fq)=Aut(E/Fq)=σq is cyclic of order n by step 2.1 and step 1.1. At n=1 the group is trivial and E=Fq.

step 1.1step 2.1L5

Remarks

  • Separability and normality are never argued separately. The usual route checks that E is a splitting field of tqnt and that this polynomial has no repeated root. Routing through Artin's fixed-field theorem: [K:KG]=G and Aut(K/KG)=G instead replaces both checks by one count: an automorphism group of order n whose fixed field is Fq already forces Aut=[E:Fq], which is one of the equivalent Galois conditions.
TheoremStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

The intermediate fields of Fqn/Fq are the Fqd, one for each positive divisor d of n

Statement

Let Fq be a finite field of order q, let n1, and let Fqn be a finite field having Fq as a subfield with [Fqn:Fq]=n (The degree [K:F]=dimFK of a finite field extension). For a positive divisor d of n (Divisibility in Z: da when a=dq for some integer q) put

Fqd:={xFqn:xqd=x}.

Then the fields Fqd, as d runs over the positive divisors of n, are exactly the intermediate fields of Fqn/Fq, with distinct divisors giving distinct fields;

[Fqd:Fq]=d,Fqd=qd;

and for positive divisors d,e of n,

FqdFqede.

The two ends of the lattice are instances: d=1 gives the base field Fq and d=n gives Fqn.

Facts & Assumptions

Given: Finite fields FqE:=Fqn with Fq=q and [E:Fq]=n1, and the relative Frobenius σq(x)=xq (The relative Frobenius xxq of an extension of finite fields), whose i-th iterate is xxqi.

[L1]

E/Fq is Galois and Gal(E/Fq)=σq is cyclic of order n (A finite extension of a finite field of order q is Galois with cyclic Galois group generated by xxq).

[L2]

In a cyclic group g of finite order n, for each positive divisor c of n the subgroup gn/c has order c and is the unique subgroup of that order, every subgroup has this form for exactly one such c, and gn/cgn/c if and only if cc (A finite cyclic group has exactly one subgroup of each order dividing its own).

[L3]

For K/F finite Galois with G=Gal(K/F), the assignments HKH and FGal(K/F) are mutually inverse inclusion-reversing bijections between subgroups HG and intermediate fields FFK, and [K:KH]=H, [KH:F]=[G:H] (The fundamental theorem of finite Galois theory).

[L5]

For an extension of finite fields L/Fq of degree m one has L=qm (For a degree-n extension of a field of order q, the q-power map has order exactly n).

[L6]

KH={xK:σ(x)=x for every σH} (The fixed field KG of a group of field automorphisms).

[L7]

For a finite group G and HG one has G=[G:H]H (Lagrange's theorem: G=[G:H]H for every subgroup H of a finite group G).

Proof

technique · direct
1.1

Write G:=Gal(E/Fq)=σq, cyclic of order n by [L1], and for a positive divisor d of n put Hd:=σqd.

L1
2.1

By [L2] applied to G with generator σq and c=n/d, the subgroup Hd=σqn/(n/d) has order n/d; every subgroup of G is Hd for exactly one positive divisor d of n; and HeHd if and only if de, since HeHd reads σqn/(n/e)σqn/(n/d), which by [L2] says (n/e)(n/d), that is de.

step 1.1L2algebra
2.2

The fixed field of Hd is EHd={xE:σqd(x)=x}={xE:xqd=x}=Fqd, because an element fixed by σqd is fixed by all its powers and conversely.

step 1.1L6given
3.1

By [L3] the map HEH is a bijection from the subgroups of G onto the intermediate fields of E/Fq; composing with the bijection of step 2.1 between positive divisors of n and subgroups, the fields Fqd=EHd are exactly the intermediate fields, distinct divisors giving distinct fields.

step 2.1step 2.2L3
3.2

Degrees: [L3] gives [Fqd:Fq]=[EHd:Fq]=[G:Hd], and [L7] with step 2.1 turns this into G/Hd=n/(n/d)=d; then [L5] gives Fqd=qd.

step 2.1step 2.2L3L5L7algebra
4.1

Inclusions: [L3] makes the correspondence inclusion-reversing, so Fqd=EHdEHe=Fqe exactly when HeHd, which by step 2.1 holds exactly when de. At d=1 one has H1=G and Fq1=EG=Fq by [L4], and at d=n one has Hn={id} and Fqn=E; with steps 3.1 and 3.2 this proves every clause.

step 2.1step 2.2step 3.1step 3.2L3L4

Remarks

  • Why the lattice is exactly the divisor lattice. Uniqueness of the subgroup of each order in a cyclic group is what leaves no choice: had Gal(E/Fq) been the Klein four-group, three distinct subgroups of order two would have produced three intermediate fields of the same degree, and no indexing by divisors could exist.
RemarkRemark: AI-adaptedProof: Not applicablejudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

The Galois description of the subfields of a finite field and the elementary divisibility criterion agree

Statement

Two statements in this library describe the subfields of a finite field, and they describe the same objects.

The subfields of Fpn are the unique fields Fpd for positive divisors d of n fixes a finite field F of order pm with p its characteristic and says that for each positive divisor e of m the set {aF:ape=a} is the unique subfield of F of order pe, and that these are all of the subfields of F. Its index set is therefore the divisors of m, and its base point is the prime field.

The intermediate fields of Fqn/Fq are the Fqd, one for each positive divisor d of n fixes a base field Fq inside F and says that the intermediate fields of F/Fq are the {xF:xqd=x} for the positive divisors d of n=[F:Fq]. Its index set is therefore the divisors of n, and its base point is Fq.

The dictionary. Write q=pk, so that m=kn. For a positive divisor d of n the two prescriptions produce literally the same set,

{xF:xqd=x}={xF:xpkd=x},

which is the subfield of order pkd named by the first statement; and kd runs exactly over the divisors e of m that are multiples of k as d runs over the divisors of n. So the intermediate fields of F/Fq are precisely those subfields of F whose order is pe with ke, which is the expected answer: a subfield of F contains the unique subfield of order pk exactly when k divides e, by the divisibility clause of The intermediate fields of Fqn/Fq are the Fqd, one for each positive divisor d of n applied over the prime field.

Neither statement is the other. The published one is elementary: it counts roots of tpet and needs no Galois theory. The one proved here reads the lattice off the subgroup lattice of a cyclic Galois group, and it is that reading which the rest of this page uses, because the same correspondence also supplies the degrees and the automorphism groups of the intermediate fields. Recording their agreement here is what keeps the two vocabularies from drifting apart in later proofs.

TheoremStatement: Literature-sourcedProof: AI-adaptedprecheck passaudited 2026-08-26Open item page →

A monic irreducible of degree d over Fq has the d distinct roots α,αq,,αqd1

Statement

Let Fq be a finite field of order q, let πFq[t] be monic irreducible of degree d1, and let α be a root of π in some extension field of Fq. Then Fq(α) is a finite field of order qd, the d elements

α, αq, αq2, , αqd1

are pairwise distinct roots of π lying in Fq(α),

π=i=0d1(tαqi)in Fq(α)[t],

and Fq(α) is a splitting field of π over Fq (Polynomials that split and splitting fields of a polynomial or a family of polynomials), of degree d over Fq (The degree [K:F]=dimFK of a finite field extension). In particular these d elements are pairwise conjugate over Fq (Conjugate algebraic elements over a field) and form a single orbit of the relative Frobenius. The list starts at i=0, so its first member is α itself, and at d=1 it is the single element αFq.

Facts & Assumptions

Given: A finite field Fq of order q2, a monic irreducible πFq[t] of degree d1 (Degree, leading coefficient and monic polynomial, with the zero polynomial having no degree), a root α of π in an extension field, and the field K:=Fq(α).

[L1]

If K/F is a field extension and aK is algebraic, there is a unique monic irreducible maF[x] with ker(eva)=(ma), and for every fF[x] one has f(a)=0 if and only if maf (The evaluation kernel and the unique monic irreducible minimal polynomial of an algebraic element).

[L2]

If a is algebraic over F with minimal polynomial of degree n, then [F(a):F]=n (An element is algebraic over F if and only if its simple extension F(a)/F is finite).

[L4]

An extension E/Fq of finite fields of degree m is Galois with Gal(E/Fq)=σq cyclic of order m, where σq(x)=xq (A finite extension of a finite field of order q is Galois with cyclic Galois group generated by xxq, The relative Frobenius xxq of an extension of finite fields).

[L5]

Let R be a commutative ring, aR and fR[x]. Then f(a)=0 if and only if xa divides f in R[x] (Factor theorem over a commutative ring).

[L6]

A nonzero polynomial of degree n over an integral domain has at most n distinct roots in that domain (A nonzero polynomial of degree n over an integral domain has at most n distinct roots).

[L7]

If F is a field with q elements, then every aF satisfies aq=a (A field with q elements is the splitting field of xqx over its prime subfield).

[L8]

Two elements algebraic over F are conjugate over F when they have the same minimal polynomial over F (Conjugate algebraic elements over a field).

Proof

technique · direct
1.1

π is the minimal polynomial of α over Fq: since π(α)=0, [L1] gives mαπ, and π is irreducible while mα is monic of degree at least one, so π=mα. Hence [K:Fq]=d by [L2].

L1L2given
2.1

Fix the length-d basis supplied by [L3]. Unique coordinates give a bijection FqdK, so K=qd and K is a finite field. Now [L4] applies: K/Fq is Galois with Gal(K/Fq)=σq cyclic of order d, where σq(x)=xq.

step 1.1L3L4algebra
3.1

Each σqi fixes the coefficients of π, which lie in Fq, so applying the field homomorphism σqi to the equation π(α)=0 gives π(αqi)=0: every αqi is a root of π lying in K.

step 2.1L4given
4.1

The elements α,αq,,αqd1 are pairwise distinct. Suppose αqi=αqj with 0i<jd1 and apply the automorphism σqdj: since xqd=x for every xK by [L7] and step 2.1, this yields αqr=α with r:=i+dj and 1rd1. The set S:={xK:xqr=x} is the fixed set of the automorphism σqr, hence a subfield of K; it contains Fq by [L7] and contains α, so K=Fq(α)S. But S is the root set in K of the nonzero polynomial tqrt, so Sqr by [L6], giving qd=Kqr<qd because q2 and r<d. This is impossible.

step 2.1step 3.1L6L7algebra
5.1

The product P:=i=0d1(tαqi) divides π in K[t]. Indeed, listing the distinct roots as r0,,rd1, [L5] writes π=(tr0)g0; for j1 the equation 0=π(rj)=(rjr0)g0(rj) and rjr0 in the field K give g0(rj)=0, so the same step applies to g0 with the remaining d1 distinct roots, and after d such steps π=Ph for some hK[t].

step 3.1step 4.1L5
6.1

Both π and P are monic of degree d, so h is monic of degree 0, that is h=1 and π=P.

step 5.1givenalgebra
7.1

Consequently π splits over K, and K=Fq(α) is generated over Fq by the root α; since the subfield of K generated over Fq by all the roots of π contains α, it contains and hence equals K, so K is a splitting field of π over Fq. All d roots share the minimal polynomial π by step 1.1 and [L1], so they are pairwise conjugate over Fq by [L8], and step 3.1 exhibits them as one orbit of σq.

step 1.1step 3.1step 4.1step 6.1L1L8

Remarks

  • The index starts at zero. The orbit is αq0=α,αq,,αqd1, so the factor tα is present in the product; dropping the term i=0 would leave a polynomial of degree d1 that is not π.

  • Where irreducibility is used. It enters twice: to identify π with the minimal polynomial of α in step 1.1, and through that identification to force [K:Fq]=d, which is what makes the count in step 4.1 tight. For a reducible π the conclusion fails outright, as t21 over F3 shows: its roots 1 and 1 are not a Frobenius orbit.

PropositionStatement: AI-adaptedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

dndNq(d)=qn for the counts Nq(d) of monic irreducibles of degree d over Fq

Statement

Let Fq be a finite field of order q and, for an integer d1, let Nq(d) denote the number of monic irreducible polynomials of degree d in Fq[t]. Then each Nq(d) is finite, and for every n1

dndNq(d)=qn,

the sum being over the positive divisors d of n (Divisibility in Z: da when a=dq for some integer q, The sum iSai over a finite index set, and its product form). At n=1 the identity reads Nq(1)=q.

Facts & Assumptions

Given: A finite field Fq of order q2 and an integer n1; monic polynomials are as in Degree, leading coefficient and monic polynomial, with the zero polynomial having no degree.

[L1]

In Fq[t] one has tqnt=P(t), the product being over the monic irreducible PFq[t] whose degree divides n, each such P occurring once (Over Fq, xqnx is the product of all monic irreducibles whose degrees divide n).

[L2]

If R is an integral domain and f,gR[x] are nonzero, then fg0 and deg(fg)=degf+degg (Over an integral domain, degrees add under multiplication of nonzero polynomials).

[L3]

If R is an integral domain, then R[x] is an integral domain (A polynomial ring over an integral domain is an integral domain).

Proof

technique · direct
1.1

For each d1 the monic polynomials of degree d in Fq[t] are the td+ad1td1++a0 with a0,,ad1Fq, so there are exactly qd of them and Nq(d)qd is finite.

givenalgebra
2.1

Consequently the family of monic irreducible PFq[t] with degPn is finite, having at most dnqd members, so the product in [L1] is a finite product of nonzero polynomials in the integral domain Fq[t] ([L3]).

step 1.1L1L3
3.1

Taking degrees in [L1] and applying [L2] repeatedly to that finite product gives deg(tqnt)=degPndegP, where the sum runs over the same finite family; and deg(tqnt)=qn because qn>1.

step 2.1L1L2algebra
4.1

Splitting that sum according to the degree of P: the possible degrees are exactly the positive divisors d of n, there are Nq(d) monic irreducibles of degree d, and each contributes d; hence dndNq(d)=qn.

step 1.1step 3.1algebra
5.1

At n=1 the only positive divisor is d=1, so the identity reads Nq(1)=q, in agreement with the fact that the monic polynomials of degree one are the ta for aFq and each is irreducible.

step 1.1step 4.1algebra

Remarks

  • What the identity does not give. It determines Nq(n) only once every Nq(d) for proper divisors d of n is known, so it is a recursion rather than a formula. Inverting it into a closed form is a separate matter and is not carried out here.
DefinitionDefinition: Literature-sourcedProof: Not applicablejudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

Normal bases of a finite Galois extension

Definition

Let K/F be a finite Galois extension (Finite Galois extensions and Gal(K/F)) of degree n=[K:F] (The degree [K:F]=dimFK of a finite field extension), and list its Galois group as

Gal(K/F)={σ1,,σn},

which has exactly n elements because Gal(K/F)=[K:F] for a finite Galois extension (Equivalent characterizations of a finite Galois extension). Scalar multiplication by F makes K an F-vector space of dimension n.

An element αK is a normal basis generator for K/F when the list

(σ1α, σ2α, , σnα)

is an ordered basis of K as an F-vector space (Basis of a vector space: a linearly independent spanning subset; and ordered basis: an injective finite list whose image is a basis). Such a list is called a normal basis of K over F: a basis that is a single orbit of the Galois group.

Two conditions, not one. A list is an ordered basis when it is injective and its image is a basis, so a normal basis generator must in particular have n distinct conjugates σiα. Neither half implies the other: a basis of K over F need not be a Galois orbit, and a Galois orbit of size n need not be a basis.

The list is indexed by the group, not ordered by it. Reordering σ1,,σn permutes the list and leaves the property of being a basis unchanged, since a basis is a property of the underlying set together with injectivity of the list (Basis of a vector space: a linearly independent spanning subset; and ordered basis: an injective finite list whose image is a basis). The automorphisms are those of Relative field automorphisms and Aut(K/F).

LemmaStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

A polynomial vanishing at every tuple from an infinite subdomain is the zero polynomial

Statement

Let S be an integral domain, let RS be a subring whose underlying set is infinite, let m1, and let fS[x1,,xm] (Polynomial rings in finitely many commuting indeterminates by iteration). If

f(a1,,am)=0for all a1,,amR,

then f=0 in S[x1,,xm].

Here f(a1,,am) is the iterated evaluation of Evaluation and roots of a polynomial in a commutative target ring, carried out one indeterminate at a time along the construction of S[x1,,xm].

Facts & Assumptions

Given: An integral domain S, an infinite subring RS, and the polynomial rings S[x1,,xm] built by iteration (Polynomial rings in finitely many commuting indeterminates by iteration).

[L1]

A nonzero polynomial gD[x] of degree k over an integral domain D has at most k distinct roots in D (A nonzero polynomial of degree n over an integral domain has at most n distinct roots).

[L2]

If R is an integral domain, then R[x1,,xn] is an integral domain for every nN, including n=0 (A polynomial ring in finitely many indeterminates over an integral domain is an integral domain).

[L3]

A nonzero g=iaixi has a largest index with ai0, its degree; the zero polynomial has no degree (Degree, leading coefficient and monic polynomial, with the zero polynomial having no degree).

Proof

technique · induction
1.1

Base case m=1: let gS[x] vanish at every element of R. If g0 it has a degree k by [L3], so by [L1] it has at most k distinct roots in S; but every one of the infinitely many elements of RS is a root, and an infinite set has more than k elements. Hence g=0.

L1L3base
1.2

Inductive hypothesis: fix m1 and assume that every gS[x1,,xm] vanishing at all tuples from R is zero.

ih
2.1

Let fS[x1,,xm+1]=S[x1,,xm][xm+1] vanish at every tuple from R, and write f=jkgjxm+1j with gjS[x1,,xm]. Fix a=(a1,,am)Rm; then jkgj(a)xm+1j is an element of S[xm+1] vanishing at every element of R, so it is zero by step 1.1, and therefore gj(a)=0 for every jk.

step 1.1L2given
3.1

Since aRm was arbitrary, each gj vanishes at every tuple from R, so gj=0 by step 1.2 and hence f=0. This completes the induction, and the statement holds for every m1.

step 1.2step 2.1discharge-induction

Remarks

  • Infinite, not merely large. The hypothesis cannot be weakened to a finite R of any size: over R=S=Fq the nonzero polynomial xqx vanishes at every element, and in m indeterminates so does x1qx1. This is exactly why the normal basis theorem needs a separate argument over a finite base field (Every finite cyclic extension has a normal basis).
LemmaStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

For a finite Galois extension, (αj) is a base-field basis exactly when the matrix (σiαj) is invertible

Statement

Let K/F be a finite Galois extension of degree n, list its Galois group as Gal(K/F)={σ1,,σn}, and let α1,,αnK. Let AMn(K) be the matrix with entries

Aij=σi(αj)(1i,jn).

Then (α1,,αn) is an ordered basis of K as an F-vector space (Basis of a vector space: a linearly independent spanning subset; and ordered basis: an injective finite list whose image is a basis) if and only if A is invertible over K (Invertible matrices and the general linear group GLn(F)).

Facts & Assumptions

Given: A finite Galois extension K/F of degree n with Gal(K/F)={σ1,,σn}; elements α1,,αnK; the matrix AMn(K) with Aij=σi(αj) (Finite rectangular matrices over a commutative ring, their entries, rows and columns); and the F-linear map Φ ⁣:FnK given by Φ(a)=jajαj. Each σi is an F-automorphism of K (Relative field automorphisms and Aut(K/F)), hence additive and F-linear.

[L1]

For a finite Galois extension K/F with G=Gal(K/F) one has G=[K:F] (Equivalent characterizations of a finite Galois extension, Finite Galois extensions and Gal(K/F)); so dimFK=n (The degree [K:F]=dimFK of a finite field extension).

[L2]

Let G be a group and K a field. Every finite family of distinct group homomorphisms GK× is linearly independent over K as a family of functions (Dedekind's linear independence theorem for distinct characters).

[L3]

For a linear map T:VW of F-vector spaces with V finite-dimensional, dimFV=dimF(kerT)+dimF(imT) (Rank-nullity: dimFV=nullityT+rankT).

[L4]

For AMn(F) and LA(x)=Ax on Mn×1(F): A is invertible if and only if LA is a linear isomorphism (A square matrix is invertible exactly when its multiplication map is a linear isomorphism; matrices preserve inverses of linear isomorphisms).

[L5]

Let R be a commutative ring, n1, AMn(R). Then A is invertible if and only if det(A) is a unit of R (A positive-sized square matrix over a commutative ring is invertible if and only if its determinant is a unit).

[L6]

det(AT)=det(A) for every AMn(R) over a commutative ring (For every square matrix over a commutative ring, det(AT)=det(A)); the transpose is (AT)ji=Aij (Entrywise ring-matrix operations, rectangular matrix products, identity matrices and transpose).

Proof

technique · direct
1.1

By [L1] the F-vector space K has dimension n, and Φ is a map between F-vector spaces of dimension n; so by [L3] it is injective if and only if it is surjective, and (α1,,αn) is an ordered basis of K over F exactly when Φ is bijective.

L1L3
1.2

For the implication that a basis has an invertible matrix, suppose (α1,,αn) is an ordered basis, and let cKn satisfy ATc=0, that is iciσi(αj)=0 for every j. The map θ ⁣:KK, θ(x)=iciσi(x), is F-linear because each σi is, and it vanishes at every αj, hence on their F-span, which is K.

given
2.1

For the implication that a non-basis has a singular matrix, suppose (α1,,αn) is not an ordered basis. By step 1.1 the map Φ is not injective, so there is aFn with a0 and jajαj=0. Applying σi and using σi(aj)=aj for ajF gives jσi(αj)aj=0 for every i, that is Aa=0 with a0 in Kn. Were A invertible with inverse B, this would force a=B(Aa)=0; so A is not invertible.

step 1.1given
2.2

So iciσi is the zero function on K, in particular on K×. The restrictions σiK× ⁣:K×K× are group homomorphisms and are pairwise distinct, since two automorphisms of K agreeing on K× agree on K; so [L2] forces ci=0 for every i.

step 1.2L2
3.1

Hence the K-linear map xATx on Kn has zero kernel, so by [L3] over K it is also surjective and therefore a linear isomorphism; by [L4] the matrix AT is invertible, so det(AT) is a unit of K by [L5], and det(A)=det(AT) by [L6] is a unit, whence A is invertible by [L5].

step 2.2L3L4L5L6
4.1

Step 2.1 gives one implication, that a list which is not a basis has a matrix that is not invertible, and step 3.1 gives the other, that a list which is a basis has an invertible matrix; together they are the stated equivalence.

step 2.1step 3.1

Remarks

  • Why the transpose appears. The dependence relation among the αj produces a null vector on the right of A, while the Dedekind relation among the σi produces one on the right of AT. Only the determinant sees both, which is why the two halves are joined through For every square matrix over a commutative ring, det(AT)=det(A) rather than by a single rank computation.

  • Where the Galois hypothesis is used. Twice: to know that the group has exactly n=[K:F] elements, so that A is square, and to know that the σi are F-linear, which is what lets step 2.1 pull the scalars aj through.

LemmaStatement: Literature-sourcedProof: Literature-sourcedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

Over an infinite base field, no nonzero polynomial vanishes at the conjugate tuple of every element

Statement

Let K/F be a finite Galois extension of degree n whose base field F is infinite, and list Gal(K/F)={σ1,,σn}. Then for every nonzero fK[x1,,xn] (Polynomial rings in finitely many commuting indeterminates by iteration) there exists αK with

f(σ1α,,σnα)0.

Facts & Assumptions

Given: A finite Galois extension K/F of degree n with F infinite and Gal(K/F)={σ1,,σn}; by [L4] the F-vector space K has dimension n, so an ordered F-basis (α1,,αn) of K exists (Basis of a vector space: a linearly independent spanning subset; and ordered basis: an injective finite list whose image is a basis).

[L1]

Let S be an integral domain and RS an infinite subring. If gS[x1,,xm] satisfies g(a1,,am)=0 for all a1,,amR, then g=0 (A polynomial vanishing at every tuple from an infinite subdomain is the zero polynomial).

[L2]

For a finite Galois extension K/F of degree n with Gal(K/F)={σ1,,σn} and α1,,αnK, the list (α1,,αn) is an ordered F-basis of K if and only if the matrix A with Aij=σi(αj) is invertible (For a finite Galois extension, (αj) is a base-field basis exactly when the matrix (σiαj) is invertible).

[L3]

For commutative rings R,S, a unital ring homomorphism φ ⁣:RS and sS, there is a unique unital ring homomorphism R[x]S extending φ on constants and sending x to s (Universal property of R[x]: a coefficient homomorphism and the image of x determine a unique ring homomorphism). Iterating this along Polynomial rings in finitely many commuting indeterminates by iteration gives, for any commutative K-algebra T and any t1,,tnT, a unique K-algebra homomorphism K[x1,,xn]T sending xi to ti.

[L5]

AMn(K) is invertible when some BMn(K) satisfies AB=In=BA; such a B is unique and written A1 (Invertible matrices and the general linear group GLn(F), Entrywise ring-matrix operations, rectangular matrix products, identity matrices and transpose).

Proof

technique · contrapositive
1.1

It suffices to prove the contrapositive: if fK[x1,,xn] satisfies f(σ1α,,σnα)=0 for every αK, then f=0. Assume that hypothesis on f.

contrapositive-reduceassume-hyp
1.2

Fix an ordered F-basis (α1,,αn) of K and put Aij=σi(αj); by [L2] the matrix A is invertible, with inverse A1 as in [L5].

L2L4L5given
2.1

For cFn write α(c):=jcjαj; then cα(c) is a bijection FnK because the αj form a basis, and σi(α(c))=jcjσi(αj)=(Ac)i since each σi fixes F pointwise and is additive.

step 1.2given
2.2

Let ψ ⁣:K[x1,,xn]K[x1,,xn] be the unique K-algebra homomorphism with ψ(xi)=jAijxj, and ψ the unique one with ψ(xi)=j(A1)ijxj; both exist by [L3].

step 1.2L3
3.1

For cFn, the evaluation homomorphism K[x1,,xn]K at c composed with ψ sends xi to jAijcj=(Ac)i, so by the uniqueness clause of [L3] it is evaluation at Ac; hence ψ(f) evaluated at c equals f(Ac)=f(σ1α(c),,σnα(c)), which is 0 by the hypothesis of step 1.1.

step 1.1step 2.1step 2.2L3
4.1

So ψ(f) vanishes at every tuple from the infinite subring F of the integral domain K, and [L1] gives ψ(f)=0.

step 3.1L1given
5.1

The composite ψψ is a K-algebra endomorphism sending xi to jAijk(A1)jkxk=k(AA1)ikxk=xi, so it is the identity by the uniqueness clause of [L3]; applying ψ to step 4.1 therefore gives f=ψ(ψ(f))=ψ(0)=0, which is the contrapositive.

step 2.2step 4.1L3L5discharge-contrapositive

Remarks

  • Where infiniteness of F enters. Only in step 4.1, through [L1]. Over a finite base field the conclusion is false: with F=q and n=[K:F], the nonzero polynomial x1qnx1 vanishes at every conjugate tuple, since every element of K satisfies xqn=x. The finite case of the normal basis theorem is therefore proved by a different argument (Every finite cyclic extension has a normal basis).
TheoremStatement: Literature-sourcedProof: Literature-sourcedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

Every finite Galois extension of an infinite field has a normal basis

Statement

Let K/F be a finite Galois extension whose base field F is infinite. Then K/F has a normal basis (Normal bases of a finite Galois extension): there is αK such that (σ1α,,σnα) is an ordered F-basis of K, where Gal(K/F)={σ1,,σn}.

Facts & Assumptions

Given: A finite Galois extension K/F (Finite Galois extensions and Gal(K/F)) of degree n with F infinite, and Gal(K/F)={σ1,,σn} numbered so that σ1=idK; the matrix B over K[x1,,xn] with Bij:=xk where k is the index determined by σiσj=σk; and D:=detB (For n1, the determinant over a commutative ring by the Leibniz formula, and detA for a real matrix).

[L1]

For every nonzero fK[x1,,xn] there is αK with f(σ1α,,σnα)0 (Over an infinite base field, no nonzero polynomial vanishes at the conjugate tuple of every element).

[L2]

(α1,,αn) is an ordered F-basis of K if and only if the matrix A with Aij=σi(αj) is invertible (For a finite Galois extension, (αj) is a base-field basis exactly when the matrix (σiαj) is invertible).

[L3]

det(A)=σSnsgn(σ)iaσ(i),i (For n1, the determinant over a commutative ring by the Leibniz formula, and detA for a real matrix); a matrix over a commutative ring is invertible if and only if its determinant is a unit (A positive-sized square matrix over a commutative ring is invertible if and only if its determinant is a unit).

[L5]

K[x1,,xn] is an integral domain (A polynomial ring in finitely many indeterminates over an integral domain is an integral domain, Polynomial rings in finitely many commuting indeterminates by iteration), and for any commutative K-algebra T and t1,,tnT there is a unique K-algebra homomorphism K[x1,,xn]T with xiti (Universal property of R[x]: a coefficient homomorphism and the image of x determine a unique ring homomorphism).

Proof

technique · direct
1.1

B is a well-defined n×n matrix over K[x1,,xn]: for each pair (i,j) the product σiσj lies in the group Gal(K/F) and so equals σk for exactly one index k.

given
2.1

Let ε ⁣:K[x1,,xn]K be the K-algebra homomorphism with ε(x1)=1 and ε(xk)=0 for k1, supplied by [L5]. Applying ε entrywise to B gives the matrix PMn(K) with Pij=1 when σiσj=σ1=id, that is when σj=σi1, and Pij=0 otherwise.

step 1.1L5given
3.1

P is invertible, with PT as an inverse: the (i,i) entry of PPT is jPijPij, and a term is nonzero exactly when σj=σi1 and σj=σi1, which happens for exactly one j when i=i and for no j otherwise; so PPT=In, and the same computation on PTP gives In. Hence detP is a unit of K by [L3], and in particular detP0.

step 2.1L3L4
4.1

Since det is a polynomial expression in the entries by [L3] and ε is a ring homomorphism, ε(D)=ε(detB)=detP0; hence D0 in K[x1,,xn].

step 2.1step 3.1L3L5
5.1

By [L1] there is αK with D(σ1α,,σnα)0. Substituting xkσk(α) in B replaces the entry Bij=xk, where σiσj=σk, by σk(α)=σi(σj(α)); since substitution is a ring homomorphism, it carries D=detB to the determinant of the matrix A with Aij=σi(αj) for αj:=σj(α). So detA0.

step 4.1L1L3L5
6.1

A nonzero element of the field K is a unit, so A is invertible by [L3], and [L2] makes (α1,,αn)=(σ1α,,σnα) an ordered F-basis of K; that is a normal basis.

step 5.1L2L3

Remarks

  • What the specialisation is for. The matrix of indeterminates is a device for showing that one determinant polynomial is not the zero polynomial, and the cheapest way to see that is to send it to a permutation matrix. Nothing about the particular substitution x11 survives into the conclusion: the element α produced in step 5.1 has no relation to it.

  • Why σ1 is the identity. Only so that the specialised matrix is the permutation matrix of σσ1; any other choice of which indeterminate to set to 1 would give the permutation matrix of a different bijection, with the same conclusion.

TheoremStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

Every finite cyclic extension has a normal basis

Statement

Let K/F be a finite Galois extension whose Galois group is cyclic, say Gal(K/F)=σ of order n=[K:F]. Then K/F has a normal basis (Normal bases of a finite Galois extension): there is αK for which

(α, σα, , σn1α)

is an ordered F-basis of K (Basis of a vector space: a linearly independent spanning subset; and ordered basis: an injective finite list whose image is a basis).

Facts & Assumptions

Given: A finite Galois extension K/F with Gal(K/F)=σ cyclic of order n; by [L6] dimFK=[K:F]=n, and σ is an F-linear endomorphism of the F-vector space K, written T when regarded as such. Evaluation of a polynomial at T is that of Polynomial evaluation at an endomorphism: p(T)=kakTk.

[L1]

Let G be a group and K a field. Every finite family of distinct group homomorphisms GK× is linearly independent over K as a family of functions (Dedekind's linear independence theorem for distinct characters).

[L2]

For every endomorphism T of a finite-dimensional F-vector space, Ann(T)={pF[x]:p(T)=0} is a nonzero ideal with a unique monic generator μT, and p(T)=0 if and only if μTp (The annihilator ideal is nonzero and has a unique monic generator; p(T)=0 if and only if μTp, The annihilator set Ann(T)={pF[x]:p(T)=0}; once existence is proved, its unique monic generator μT is the minimal polynomial).

[L4]

μTχT for every endomorphism T of a finite-dimensional vector space (The minimal polynomial divides the characteristic polynomial, μTχT).

[L5]

An endomorphism T of a finite-dimensional vector space has a cyclic vector if and only if μT=χT (A cyclic vector exists exactly when the minimal and characteristic polynomials agree); v is a cyclic vector when Z(v;T)={p(T)v:pF[x]} is all of V (Cyclic subspaces, cyclic vectors, and vector annihilators).

[L7]

With mT,v the unique monic generator of AnnT(v)={p:p(T)v=0} (The vector annihilator is the unique monic generator of AnnT(v) and divides the minimal polynomial) and d=degmT,v, the list (v,Tv,,Td1v) is an ordered basis of Z(v;T) (A vector annihilator gives a power basis and its companion matrix).

Proof

technique · direct
1.1

Tn=idK, because σ has order n in Gal(K/F); so the polynomial xn1 lies in Ann(T) and μTxn1 by [L2]. In particular degμTn.

L2given
1.2

The maps id,σ,σ2,,σn1 are pairwise distinct elements of Gal(K/F), and their restrictions to K× are pairwise distinct group homomorphisms K×K×, since two field automorphisms of K agreeing on K× agree on K.

L1given
2.1

If p=i<naixi with aiF satisfies p(T)=0, then i<naiσi is the zero function on K, hence on K×, so [L1] applied to the family of step 1.2 forces every ai to be 0; thus no nonzero polynomial of degree less than n annihilates T, and degμTn.

step 1.2L1L2
3.1

Combining steps 1.1 and 2.1, degμT=n, and since μT is monic and divides the monic xn1 of the same degree, μT=xn1.

step 1.1step 2.1L2algebra
4.1

By [L3] the polynomial χT is monic of degree dimFK=n, and μTχT by [L4]; two monic polynomials of the same degree, one dividing the other, are equal, so μT=χT.

step 3.1L3L4given
5.1

By [L5] there is a cyclic vector αK for T, that is Z(α;T)=K.

step 4.1L5
6.1

Let d=degmT,α. By [L7] the list (α,Tα,,Td1α) is an ordered basis of Z(α;T)=K, which has dimension n, so d=n and (α,σα,,σn1α) is an ordered F-basis of K.

step 5.1L6L7given
7.1

Since Gal(K/F)={id,σ,,σn1}, that list is exactly the family of conjugates of α, so it is a normal basis.

step 1.2step 6.1given

Remarks

  • Why the minimal polynomial is forced to be xn1. The divisibility μTxn1 is cheap; the content is the lower bound on its degree, and that is exactly Dedekind's independence of characters. Without it the minimal polynomial could be a proper divisor of xn1 and no cyclic vector would be available.

  • The hypothesis is on the group, not on the base field. No finiteness or infiniteness of F is used, so this proof also covers cyclic extensions of infinite fields, for which Every finite Galois extension of an infinite field has a normal basis gives a second and quite different argument.

TheoremStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

Every finite Galois extension has a normal basis

Statement

Every finite Galois extension K/F has a normal basis (Normal bases of a finite Galois extension): there is αK whose family of conjugates (σ1α,,σnα), indexed by Gal(K/F)={σ1,,σn}, is an ordered F-basis of K.

Facts & Assumptions

Given: A finite Galois extension K/F of degree n, so that K is an F-vector space of dimension n (The degree [K:F]=dimFK of a finite field extension, Equivalent characterizations of a finite Galois extension).

[L1]

Every finite Galois extension of an infinite field has a normal basis (Every finite Galois extension of an infinite field has a normal basis).

[L2]

Every finite Galois extension whose Galois group is cyclic has a normal basis (Every finite cyclic extension has a normal basis).

[L3]

An extension E/Fq of finite fields of degree m is Galois with Gal(E/Fq) cyclic of order m, generated by xxq (A finite extension of a finite field of order q is Galois with cyclic Galois group generated by xxq).

[L5]

A finite field is a field whose underlying set is finite, and its order is that cardinality (Finite fields and their order).

Proof

technique · cases
1.1

In the case that F is infinite, [L1] applies directly and K/F has a normal basis.

assume-case infL1
1.2

In the case that F is finite, fix an ordered F-basis v of K of length n; by [L4] the map sending a coordinate list λ:nF to i<nλivi is a bijection onto K, so K=Fn is finite and K is a finite field.

assume-case finL4L5given
2.1

In that same finite case, K/ ⁣F is therefore an extension of finite fields of degree n, so Gal(K/F) is cyclic by [L3], and [L2] gives a normal basis.

step 1.2L2L3
3.1

The two cases are exhaustive, a field being finite or infinite and not both, so a normal basis exists in either case.

step 1.1step 2.1cases-exhaustive

Remarks

  • Two genuinely different proofs, not one proof with a case split. The infinite case runs on a determinant that is a nonzero polynomial (Every finite Galois extension of an infinite field has a normal basis); the finite case runs on a cyclic vector for the Frobenius acting linearly (Every finite cyclic extension has a normal basis). Neither argument covers the other case: the first fails because a polynomial can vanish on all of a finite field, the second because a Galois group need not be cyclic.

  • The finite case is not a hypothesis on the group. It is a hypothesis on the base field, which forces the group to be cyclic through [L3]. That is the whole reason the split is by the base field rather than by the group.

DefinitionDefinition: Literature-sourcedProof: Not applicablejudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

The group μn(K) of n-th roots of unity in a field, and primitive n-th roots of unity

Definition

Let K be a field and let n1 be an integer. An element xK is an n-th root of unity when xn=1, that is when x is a root of tn1K[t] (Evaluation and roots of a polynomial in a commutative target ring). Write

μn(K):={xK:xn=1}.

This is a subgroup of K× (Subgroup). Every xμn(K) is invertible, with inverse xn1 (Left inverse, right inverse, and invertible element of a monoid), so μn(K)K×; it contains 1; it is closed under multiplication, since (xy)n=xnyn=1; and it is closed under inverses, since (x1)n=(xn)1=1.

An element ζμn(K)K× is a primitive n-th root of unity when its order in the group K× is exactly n (The order G of a finite group and the order ord(g) of an element, with ord(g)= when no positive power of g is the identity):

ord(ζ)=n.

Equivalently, ζn=1 and no exponent k with 1k<n has ζk=1.

An n-th root of unity need not be primitive. In Q the element 1 is a fourth root of unity of order two, not four; and μn(K) may consist of 1 alone, as μ3(Q) does. The two notions are separated deliberately, and the exact circumstances under which a primitive n-th root of unity exists are the content of μn(K) is cyclic of order dividing n, and has a primitive n-th root of unity exactly when its order is n and tn1 is separable over K exactly when the characteristic does not divide n, and then a splitting field carries n distinct n-th roots of unity.

Remarks

PropositionStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

μn(K) is cyclic of order dividing n, and has a primitive n-th root of unity exactly when its order is n

Statement

Let K be a field and n1. Then μn(K)={xK:xn=1} (The group μn(K) of n-th roots of unity in a field, and primitive n-th roots of unity) is a finite cyclic subgroup of K× whose order divides n (Divisibility in Z: da when a=dq for some integer q). It contains a primitive n-th root of unity if and only if μn(K)=n, and in that case the primitive n-th roots of unity in K are exactly the generators of μn(K), of which there are φ(n) (The unit group (Z/n)× and Euler's totient φ(n)=(Z/n)× for n1).

Facts & Assumptions

Given: A field K, an integer n1, and the subgroup μn(K) of K× (The group μn(K) of n-th roots of unity in a field, and primitive n-th roots of unity).

[L1]

Let D be an integral domain. Every finite subgroup GD× of the unit group of D is cyclic (Every finite subgroup of the unit group of an integral domain is cyclic).

[L2]

A nonzero polynomial of degree k over an integral domain has at most k distinct roots in that domain (A nonzero polynomial of degree n over an integral domain has at most n distinct roots).

[L4]

In a cyclic group g of finite order m, the element ga generates the group if and only if gcd(a,m)=1, and the group has exactly φ(m) generators (A cyclic group of order n has exactly φ(n) generators).

Proof

technique · direct
1.1

μn(K) is the set of roots in K of the nonzero polynomial tn1, of degree n; a field is an integral domain, so μn(K)n by [L2] and μn(K) is finite.

L2given
2.1

Being a finite subgroup of K×, μn(K) is cyclic by [L1]; write m:=μn(K) and fix a generator ζ0, so that ord(ζ0)=m by [L3].

step 1.1L1L3
3.1

The order m divides n: ζ0μn(K) gives ζ0n=1, and [L3] turns this into mn.

step 2.1L3
3.2

If K contains a primitive n-th root of unity ζ, that is an element of order n, then ζn=1 puts ζ in μn(K), and ζμn(K) has n elements by [L3], so nm; with step 1.1 this forces m=n.

step 1.1step 2.1L3
3.3

Conversely, if m=n then the generator ζ0 of step 2.1 has order n and so is a primitive n-th root of unity in K.

step 2.1L3
4.1

Suppose m=n. An element xK of order n lies in μn(K)=ζ0 and satisfies x=n=μn(K) by [L3], so x=μn(K) and x is a generator; conversely a generator has order n by [L3]. So the primitive n-th roots of unity in K are exactly the generators of μn(K), and [L4] counts them as φ(n).

step 2.1step 3.2step 3.3L3L4

Remarks

TheoremStatement: AI-adaptedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

tn1 is separable over K exactly when the characteristic does not divide n, and then a splitting field carries n distinct n-th roots of unity

Statement

Let K be a field and n1. Then

tn1 is separable over KcharKn

(Repeated roots in extension fields and separable polynomials, The characteristic of a ring: the least n1 with n1R=0 when one exists, and 0 otherwise; divisibility of integers being that of Divisibility in Z: da when a=dq for some integer q, under which 0n holds only for n=0, so characteristic 0 never divides n1).

When charKn and E is a splitting field of tn1 over K, the group μn(E) is cyclic of order exactly n, it contains exactly φ(n) primitive n-th roots of unity, and

E=K(ζ)

for every primitive n-th root of unity ζE.

Facts & Assumptions

Given: A field K, an integer n1, the polynomial f:=tn1K[t], and the element n1K obtained by adding 1K to itself n times.

[L1]

f=i1iaixi1 for f=iaixi (The formal derivative of a polynomial); (xk)=kxk1 for k1 and constants have derivative 0, and the derivative is additive (Linearity, power rule, Leibniz rule and the degree bound for the formal derivative). Hence f=(n1K)tn1.

[L2]

For a field F and 0fF[x]: f is separable over F if and only if gcd(f,f)=1 in F[x] (A nonzero polynomial over a field is separable exactly when its gcd with its derivative is 1).

[L3]

For f,gF[x] not both zero, d=gcd(f,g) is monic, divides both f and g, and every common divisor of f and g divides d (Bézout identity and the Euclidean algorithm for polynomials over a field).

[L5]

Every nonzero fK[x] has a splitting field over K (Every nonzero polynomial over a field has a splitting field); f of degree m splits over E when f=cj=1m(tαj) with cK× and αjE, repetitions allowed, and a splitting field is generated over K by the roots (Polynomials that split and splitting fields of a polynomial or a family of polynomials), the notation K(S) for the subfield generated by K and a finite set S being that of Finitely generated field extensions F(a1,,ar).

[L6]

μn(F) is a finite cyclic subgroup of F× of order dividing n; it contains a primitive n-th root of unity exactly when its order is n, and there are then φ(n) of them, namely the generators (μn(K) is cyclic of order dividing n, and has a primitive n-th root of unity exactly when its order is n, The group μn(K) of n-th roots of unity in a field, and primitive n-th roots of unity, The unit group (Z/n)× and Euler's totient φ(n)=(Z/n)× for n1).

[L7]

f is separable over K when it has no repeated root in any extension field of K, where a is a repeated root of f in E when (ta)2 divides the image of f in E[t] (Repeated roots in extension fields and separable polynomials).

Proof

technique · cases
1.1

In the case n1K0, put d:=gcd(f,f). By [L1] f=(n1K)tn1 with n1K a unit of K, so dtn1 by [L3], hence dttn1=tn; and df=tn1, so d divides tn(tn1)=1 and, being monic, d=1. By [L2] the polynomial f is separable over K.

assume-case posL1L2L3
1.2

In the case n1K=0, [L1] gives f=0, so every polynomial dividing f is a common divisor of f and f; by [L3] the monic gcd(f,0) is divisible by every such divisor and divides f, so it is f itself, of degree n1. Thus gcd(f,f)1 and f is not separable over K by [L2].

assume-case zeroL1L2L3
2.1

The two cases are exhaustive and, by [L4], n1K0 says exactly charKn; so f is separable over K if and only if charKn.

step 1.1step 1.2L4cases-exhaustive
3.1

Assume now charKn and let E be a splitting field of f over K, which exists by [L5]. Over E one has f=cj=1n(tαj) with αjE, and comparing leading coefficients of the monic f gives c=1.

step 2.1L5
4.1

The αj are pairwise distinct: if αi=αj for ij then (tαi)2 divides f in E[t], making αi a repeated root of f in the extension E of K, which contradicts the separability supplied by step 2.1 through [L7].

step 2.1step 3.1L7
5.1

Hence f has exactly n distinct roots in E, that is μn(E)=n; by [L6] the group μn(E) is cyclic of order n and contains exactly φ(n) primitive n-th roots of unity.

step 3.1step 4.1L6
6.1

Fix such a ζ. Every root of f in E lies in μn(E)=ζ, so is a power of ζ; since E is generated over K by those roots by [L5], E=K(ζ). At n=1 the polynomial is t1, μ1(E)={1}, φ(1)=1, ζ=1 and E=K.

step 5.1L5L6

Remarks

  • The failing direction is inseparability, not a shortage of roots. When charK=p divides n, the derivative vanishes identically and no extension can separate the roots: writing n=pkm with pm, one has μn=μm in every field of characteristic p (In characteristic p the only pk-th root of unity is 1, and tpk1=(t1)pk). Passing to a larger field does not help, which is why the hypothesis is carried on every later statement rather than removed by enlarging K.
PropositionStatement: Literature-sourcedProof: AI-adaptedprecheck passaudited 2026-08-26Open item page →

In characteristic p the only pk-th root of unity is 1, and tpk1=(t1)pk

Statement

Let K be a field of characteristic p>0 (The characteristic of a ring: the least n1 with n1R=0 when one exists, and 0 otherwise; p is prime by The characteristic of a field is zero or a prime number) and let k1. Then in K[t] (The polynomial ring over a commutative ring as finitely supported coefficient sequences with convolution)

tpk1=(t1)pk,

and consequently μpk(K)={1} (The group μn(K) of n-th roots of unity in a field, and primitive n-th roots of unity).

More generally, if k0 and m1 with pm (Divisibility in Z: da when a=dq for some integer q), and if n:=pkm, then

μn(K)=μm(K).

Facts & Assumptions

Given: A field K of characteristic p>0, so that p1K=0K and hence jc=(j1K)c=0 for every cK[t] and every integer j divisible by p; and an integer k1.

[L1]

For a commutative ring R, all x,yR and nN, (x+y)n=j=0n(nj)xjynj, the natural-number coefficients acting by repeated addition (The binomial theorem over an arbitrary commutative ring).

[L2]

If p is prime and 0<j<p, then p(pj) (A prime p divides (pk) for 0<k<p).

Proof

technique · direct
1.1

For every uK[t] one has (u1)p=up1: by [L1] applied in the commutative ring K[t], (u+(1))p=j=0p(pj)uj(1)pj; for 0<j<p the coefficient (pj) is a multiple of p by [L2], so that term vanishes by the hypothesis on K; the surviving terms are up and (1)p, and (1)p=1 for odd p while for p=2 one has 1=1 in K, so (1)p=1 in either case.

L1L2given
2.1

Hence (t1)pk=tpk1 for every k1, by induction on k: at k=1 this is step 1.1 with u=t; and if it holds at k, then (t1)pk+1=((t1)pk)p=(tpk1)p=tpk+11, the last equality being step 1.1 with u=tpk.

step 1.1algebra
3.1

Therefore μpk(K)={1}: an xK with xpk=1 is a root of tpk1, so (x1)pk=0 by step 2.1, and a field has no nonzero element with a vanishing power, so x=1; and 1pk=1.

step 2.1L3
4.1

Let k0 and m1 with pm, and put n=pkm. If xn=1 then (xm)pk=xn=1, so xmμpk(K), which is {1} by step 3.1 when k1 and is {1} trivially when k=0; either way xm=1. Conversely xm=1 gives xn=(xm)pk=1. Hence μn(K)=μm(K).

step 3.1L3algebra

Remarks

  • This is why every later hypothesis reads "the characteristic does not divide n". Nothing is lost by it: the p-part of n contributes no roots of unity at all in characteristic p, so a statement about μn there is already a statement about μm for the prime-to-p part m. The hypothesis excludes a degenerate case rather than a genuine one.
DefinitionDefinition: Literature-sourcedProof: Not applicablejudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

The cyclotomic extension K(μn) as a splitting field of tn1

Definition

Let K be a field and n1. A cyclotomic extension of K of order n is a splitting field E of tn1 over K (Polynomials that split and splitting fields of a polynomial or a family of polynomials); one exists by Every nonzero polynomial over a field has a splitting field. It is written

K(μn):=E.

The notation is accurate. The roots of tn1 in E are exactly the elements of μn(E) (The group μn(K) of n-th roots of unity in a field, and primitive n-th roots of unity), and a splitting field is generated over K by the roots, so

E=K(μn(E))

in the sense of Finitely generated field extensions F(a1,,ar): E is the smallest subfield of itself containing K and the n-th roots of unity it holds.

When the characteristic does not divide n the extension has a single generator: by tn1 is separable over K exactly when the characteristic does not divide n, and then a splitting field carries n distinct n-th roots of unity the group μn(E) is then cyclic of order n and

K(μn)=K(ζ)

for any primitive n-th root of unity ζE. Without that hypothesis the notation still names a splitting field, but μn(E) can be much smaller than n and no primitive n-th root of unity need exist (In characteristic p the only pk-th root of unity is 1, and tpk1=(t1)pk).

Remarks

  • Which splitting field. Any two splitting fields of tn1 over K are K-isomorphic (Any two splitting fields of a polynomial are isomorphic over the base field), and every statement made below about K(μn) is invariant under a K-isomorphism, so the definite article is harmless; where a fixed ambient field matters, as in the compositum and intersection results, the statement says so and works inside one chosen extension of K.
TheoremStatement: Literature-sourcedProof: Literature-sourcedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

K(μn)/K is Galois and σaσ embeds its Galois group into (Z/n)×

Statement

Let K be a field and n1 with charKn (The characteristic of a ring: the least n1 with n1R=0 when one exists, and 0 otherwise), and let E=K(μn) (The cyclotomic extension K(μn) as a splitting field of tn1). Then E/K is a finite Galois extension, and there is an injective group homomorphism

Gal(E/K)(Z/n)×,σ[aσ]n,

where aσ is any integer with σ(ζ)=ζaσ for a primitive n-th root of unity ζE. The class [aσ]n does not depend on which primitive n-th root of unity is used, and σ(x)=xaσ holds for every xμn(E).

Facts & Assumptions

Given: A field K, an integer n1 with charKn, the extension E=K(μn) (The cyclotomic extension K(μn) as a splitting field of tn1), and a primitive n-th root of unity ζE (The group μn(K) of n-th roots of unity in a field, and primitive n-th roots of unity).

[L1]

For n1, tn1 is separable over K when charKn; in a splitting field E the group μn(E) is then cyclic of order n, has φ(n) primitive n-th roots of unity, and E=K(ζ) for every primitive n-th root of unity ζE (tn1 is separable over K exactly when the characteristic does not divide n, and then a splitting field carries n distinct n-th roots of unity).

[L2]

For a finite extension L/F with G=Aut(L/F), the conditions "L/F is Galois", "L is the splitting field over F of a separable polynomial", "G=[L:F]" and "LG=F" are equivalent (Equivalent characterizations of a finite Galois extension, Finite Galois extensions and Gal(K/F), Relative field automorphisms and Aut(K/F)).

[L3]

μn(E) is a finite cyclic subgroup of E× of order dividing n, and when its order is n its generators are exactly the primitive n-th roots of unity (μn(K) is cyclic of order dividing n, and has a primitive n-th root of unity exactly when its order is n).

[L4]

In a cyclic group g of finite order m, ga generates the group if and only if gcd(a,m)=1 (A cyclic group of order n has exactly φ(n) generators).

[L6]

For n1 and aZ, the class [a]nZ/n (The congruence class [a]n and the quotient set Z/n) is a unit of Z/n if and only if gcd(a,n)=1 (For n1, [a]n is a unit if and only if gcd(a,n)=1); the units form the group (Z/n)× of order φ(n) (The unit group (Z/n)× and Euler's totient φ(n)=(Z/n)× for n1).

[L7]

If a is algebraic over a field K, then the simple extension K(a)/K is finite, with degree equal to the degree of the minimal polynomial of a (A simple algebraic extension is its minimal-polynomial quotient and has power basis 1,a,,an1 and degree n).

Proof

technique · direct
1.1

By [L1] the polynomial tn1 is separable over K, the group μn(E) is cyclic of order n generated by ζ, and E=K(ζ). The element ζ is algebraic because it is a root of tn1, so [L7] makes E/K finite. Since E is the splitting field of the separable polynomial tn1, [L2] now makes E/K finite Galois.

L1L2L3L7given
2.1

Each σGal(E/K) maps μn(E) into itself, since σ(x)n=σ(xn)=σ(1)=1; being injective on the finite set μn(E) it restricts to a bijection, and it is multiplicative, so it restricts to a group automorphism of μn(E).

step 1.1given
3.1

Hence σ(ζ) generates μn(E)=ζ, so σ(ζ)=ζa for some integer a, and [L4] gives gcd(a,n)=1, so [a]n(Z/n)× by [L6]. The class is well defined: ζa=ζb means ζab=1, which by [L5] and ord(ζ)=n says nab, that is [a]n=[b]n. Write [aσ]n for this class.

step 1.1step 2.1L4L5L6
4.1

For every xμn(E) one has x=ζj for some j, so σ(x)=σ(ζ)j=ζaσj=xaσ.

step 1.1step 3.1
4.2

The map σ[aσ]n is a group homomorphism: (στ)(ζ)=σ(ζaτ)=σ(ζ)aτ=ζaσaτ, so [aστ]n=[aσ]n[aτ]n by the well-definedness of step 3.1.

step 3.1L6
4.3

It is injective: if [aσ]n=[1]n then σ(ζ)=ζ by step 3.1, and since E=K(ζ) and σ fixes K pointwise, σ is the identity on E.

step 1.1step 3.1
5.1

The class is independent of the chosen primitive n-th root of unity: any other one is a generator ζ of μn(E) by [L3], so ζ=ζb for some b, and σ(ζ)=σ(ζ)b=ζaσb=(ζb)aσ=(ζ)aσ, which exhibits the same exponent class. With steps 4.1, 4.2 and 4.3 this proves the theorem.

step 1.1step 3.1step 4.1step 4.2step 4.3L3

Remarks

CorollaryStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

The Galois group of a cyclotomic extension is abelian

Statement

Facts & Assumptions

Given: A field K and n1 with charKn.

[L1]

K(μn)/K is finite Galois and σ[aσ]n is an injective group homomorphism Gal(K(μn)/K)(Z/n)× (K(μn)/K is Galois and σaσ embeds its Galois group into (Z/n)×).

Proof

technique · direct
1.1

Multiplication on Z/n is commutative by [L2], so the group (Z/n)×, whose operation is that multiplication restricted to the units, is abelian.

L2
2.1

By [L1] the group Gal(K(μn)/K) is isomorphic to its image in (Z/n)×, a subgroup of an abelian group; a subgroup of an abelian group is abelian, and a group isomorphic to an abelian group is abelian, so Gal(K(μn)/K) is abelian.

step 1.1L1
TheoremStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

For gcd(n,q)=1 the image of Gal(Fq(μn)/Fq) in (Z/n)× is generated by [q]

Statement

Let Fq be a finite field of order q (Finite fields and their order) and let n1 with gcd(n,q)=1 (Coprime integers: gcd(a,b)=1). Then the image of the embedding

Gal(Fq(μn)/Fq)(Z/n)×

of K(μn)/K is Galois and σaσ embeds its Galois group into (Z/n)× is the cyclic subgroup generated by [q]n, and

[Fq(μn):Fq]=ord([q]n),

the multiplicative order of [q]n in (Z/n)× (The order G of a finite group and the order ord(g) of an element, with ord(g)= when no positive power of g is the identity).

Facts & Assumptions

Given: A finite field Fq of order q, of characteristic p with q a power of p (Every finite field has order pn for a unique prime characteristic p and positive integer n), and an integer n1 with gcd(n,q)=1; the extension E:=Fq(μn) (The cyclotomic extension K(μn) as a splitting field of tn1).

[L1]

For a field K and n1 with charKn, the extension K(μn)/K is finite Galois and σ[aσ]n, determined by σ(ζ)=ζaσ on a primitive n-th root of unity, is an injective homomorphism into (Z/n)× with σ(x)=xaσ for every xμn (K(μn)/K is Galois and σaσ embeds its Galois group into (Z/n)×).

[L2]

An extension L/Fq of finite fields of degree m is Galois with Gal(L/Fq)=σq cyclic of order m, where σq(x)=xq (A finite extension of a finite field of order q is Galois with cyclic Galois group generated by xxq, The relative Frobenius xxq of an extension of finite fields).

[L3]
[L4]

For a finite Galois extension L/F one has Gal(L/F)=[L:F] (Equivalent characterizations of a finite Galois extension, The degree [K:F]=dimFK of a finite field extension).

Proof

technique · direct
1.1

The characteristic p divides q, and gcd(n,q)=1, so pn; hence [L1] applies to K=Fq and E=Fq(μn) is finite Galois over Fq. Also [q]n is a unit of Z/n by [L3].

L1L3given
2.1

E is a finite field: it is a finite extension of the finite field Fq by step 1.1, so it is a finite-dimensional Fq-vector space over a finite field and therefore has finitely many elements. By [L2], Gal(E/Fq)=σq with σq(x)=xq.

step 1.1L2
3.1

The exponent attached to σq by [L1] is [q]n, since σq(ζ)=ζq for a primitive n-th root of unity ζE. Because the embedding is a homomorphism and Gal(E/Fq) is generated by σq, the image is the subgroup of (Z/n)× generated by [q]n.

step 1.1step 2.1L1
4.1

The embedding is injective, so Gal(E/Fq) equals the order of [q]n, which is ord([q]n); and [E:Fq]=Gal(E/Fq) by [L4]. Hence [E:Fq]=ord([q]n).

step 3.1L1L4

Remarks

DefinitionDefinition: AI-adaptedProof: Not applicablejudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

The cyclotomic polynomials ΦnZ[t], defined by dnΦd=tn1

Definition

The cyclotomic polynomials ΦnZ[t] (The polynomial ring over a commutative ring as finitely supported coefficient sequences with convolution) are defined by recursion on n1:

Φ1:=t1,Φn:=tn1dn0<d<nΦd(n2),

the divisors being the positive divisors of n (Divisibility in Z: da when a=dq for some integer q). The product is formed in the commutative ring Z[t] (Polynomial convolution makes R[x] a commutative ring containing R as its constant subring): multiply the finitely many factors in any enumeration of the divisor set. Associativity and commutativity make the result independent of that enumeration.

What the fraction means. The denominator Pn:=dn,d<nΦd is a product of monic polynomials in Z[t], hence itself monic (Degree, leading coefficient and monic polynomial, with the zero polynomial having no degree), so Division by a monic polynomial over a commutative ring supplies a unique pair q,rZ[t] with tn1=qPn+r and r=0 or degr<degPn. The definition sets Φn:=q, and asserts r=0. That assertion, together with the consequences that each Φn is monic of degree φ(n) and that

dnΦd=tn1

for every n1, is discharged by The recursion defines a unique monic ΦnZ[t], of degree φ(n) , which is why that theorem is a numbered result and not a parenthesis: the division is carried out over Z, not over a field, so exactness is a statement about integer coefficients and does not follow from the division algorithm.

Remarks

TheoremStatement: AI-adaptedProof: AI-adaptedprecheck passaudited 2026-08-26Open item page →

The recursion defines a unique monic ΦnZ[t], of degree φ(n)

Statement

The recursion of The cyclotomic polynomials ΦnZ[t], defined by dnΦd=tn1 is well posed: for every n1 the division defining Φn is exact, Φn is a monic element of Z[t],

dnΦd=tn1,

the product being over the positive divisors of n, and

degΦn=φ(n)

(The unit group (Z/n)× and Euler's totient φ(n)=(Z/n)× for n1). Moreover (Φn)n1 is the only family of monic polynomials in Z[t] satisfying the displayed product identity for every n1.

Facts & Assumptions

Given: The recursion of The cyclotomic polynomials ΦnZ[t], defined by dnΦd=tn1; the field Q, which is an ordered field (The rationals form a totally ordered field), so that m1>0 and in particular m10 for every m1, whence charQ=0 (The characteristic of a ring: the least n1 with n1R=0 when one exists, and 0 otherwise) and charQ divides no n1 (Divisibility in Z: da when a=dq for some integer q).

[L1]

Let R be a commutative ring and gR[x] monic. For every fR[x] there are unique q,rR[x] with f=qg+r and r=0 or degr<degg (Division by a monic polynomial over a commutative ring).

[L3]

Every nonzero fK[x] has a splitting field over K (Every nonzero polynomial over a field has a splitting field); f monic of degree m splits over E when f=j=1m(tαj) with αjE, repetitions allowed (Polynomials that split and splitting fields of a polynomial or a family of polynomials).

[L4]

f is separable over K when it has no repeated root in any extension field, a repeated root of f in E being an a with (ta)2 dividing the image of f in E[t] (Repeated roots in extension fields and separable polynomials).

[L7]

If R is an integral domain then so is R[x] (A polynomial ring over an integral domain is an integral domain), and for nonzero f,g one has deg(fg)=degf+degg and lc(fg)=lc(f)lc(g) (Over an integral domain, degrees add under multiplication of nonzero polynomials, Degree, leading coefficient and monic polynomial, with the zero polynomial having no degree).

Proof

technique · induction
1.1

The assertion to be proved by strong induction on n is: the division defining Φn is exact, ΦnZ[t] is monic, dnΦd=tn1, and degΦn=φ(n). At n=1 the recursion sets Φ1=t1 outright, the only positive divisor of 1 is 1 so the product is Φ1=t1, and degΦ1=1=φ(1).

basegiven
1.2

Inductive hypothesis: fix n2 and assume the assertion for every m with 1m<n.

ih
1.3

Since charQ=0 does not divide n, [L2] and [L3] supply a splitting field E of tn1 over Q in which tn1 is separable and μn(E) is cyclic of order n. For a positive divisor d of n put Sd:={ζμn(E):ord(ζ)=d} and Ψd:=ζSd(tζ)E[t], a monic polynomial of degree Sd.

L2L3given
2.1

For every positive divisor m of n one has tm1=ζμm(E)(tζ) with μm(E)=m: the polynomial tm1 divides tn1 in Z[t], since tn1=(tm1)(tnm+tn2m++1) when mn, so it splits over E by [L3], and a repeated root of tm1 in an extension would be a repeated root of tn1 there, which [L4] excludes; hence its m roots are distinct and they are by definition the elements of μm(E).

step 1.3L3L4algebra
3.1

For every positive divisor m of n, μm(E) is the disjoint union of the Sd over positive divisors d of m: an element ζμn(E) has finite order dividing n, and ζm=1 holds exactly when ord(ζ)m by [L5]. Hence dmΨd=ζμm(E)(tζ)=tm1 by step 2.1.

step 1.3step 2.1L5
4.1

For every positive divisor d of n with d<n one has Φd=Ψd, by induction on d through the divisors of n: at d=1 both equal t1, since S1={1}; and if Φe=Ψe for every positive divisor e of d with e<d, then step 1.2 and step 3.1 give (ed,e<dΨe)Φd=td1=(ed,e<dΨe)Ψd, and cancelling the nonzero left factor in the integral domain E[t] ([L7]) yields Φd=Ψd.

step 1.2step 3.1L7
5.1

Write P:=dn,d<nΦd, monic in Z[t] by step 1.2 and [L7]. By step 4.1 and step 3.1 applied with m=n, in E[t] one has tn1=(dn,d<nΨd)Ψn=PΨn.

step 1.2step 3.1step 4.1L7
6.1

The division of tn1 by P in Z[t] is exact and its quotient is Ψn: by [L1] over Z there are unique q,rZ[t] with tn1=qP+r and r=0 or degr<degP; this is also a division by the monic P in E[t], where step 5.1 exhibits the division with quotient Ψn and remainder 0, so the uniqueness clause of [L1] over E forces q=Ψn and r=0. Hence Φn=q=Ψn is monic in Z[t] and dnΦd=PΦn=tn1.

step 5.1L1L7
7.1

Degrees: taking degrees in tn1=PΦn with [L7] gives n=degP+degΦn, and degP=dn,d<ndegΦd=dn,d<nφ(d) by step 1.2 and [L7]; so degΦn=ndn,d<nφ(d)=φ(n) by [L6].

step 1.2step 6.1L6L7
8.1

This is the assertion at n, so the strong induction is complete and the assertion holds for every n1. Uniqueness of the family follows by the same induction: if (Φm)m1 is monic in Z[t] with dmΦd=tm1 for all m, then Φ1=t1=Φ1, and if Φm=Φm for all m<n then PΦn=tn1=PΦn with P0 in the integral domain Z[t] ([L7]), so Φn=Φn.

step 6.1step 7.1L7discharge-induction

Remarks

LemmaStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

Φ1(0)=1 and Φn(0)=1 for n2

Statement

For the cyclotomic polynomials of The cyclotomic polynomials ΦnZ[t], defined by dnΦd=tn1,

Φ1(0)=1,Φn(0)=1  for every n2.

Facts & Assumptions

Given: The cyclotomic polynomials ΦnZ[t] and their defining identity; evaluation at 0 is as in Evaluation and roots of a polynomial in a commutative target ring.

[L2]

Evaluation at an element of a commutative ring is a unital ring homomorphism Z[t]Z (Universal property of R[x]: a coefficient homomorphism and the image of x determine a unique ring homomorphism), so it carries finite products to finite products.

Proof

technique · induction
1.1

Φ1=t1 by The cyclotomic polynomials ΦnZ[t], defined by dnΦd=tn1, so Φ1(0)=1; this is also the base of the induction below, taken at n=2, where [L1] and [L2] give Φ1(0)Φ2(0)=021=1, hence Φ2(0)=1 and Φ2(0)=1.

baseL1L2given
1.2

Inductive hypothesis: fix n3 and assume Φm(0)=1 for every m with 2m<n.

ih
2.1

Evaluating the identity of [L1] at 0 and using [L2] gives dnΦd(0)=1; separating the factor d=1, which is 1 by step 1.1, leaves dn,d>1Φd(0)=1.

step 1.1L1L2
3.1

Every factor with 1<d<n equals 1 by step 1.2, so the product reduces to Φn(0)=1, which is the assertion at n; the induction is complete and Φn(0)=1 for every n2.

step 1.2step 2.1discharge-induction

Remarks

TheoremStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

Over a field whose characteristic does not divide n, the roots of Φn are exactly the primitive roots of unity

Statement

Facts & Assumptions

Given: A field K, an integer n1 with charKn, a splitting field E of tn1 over K, and the convention that for every finite subset TE the product ζT(tζ)E[t] means the finite product along any enumeration of T; because E[t] is a commutative ring, the value is independent of the enumeration (The product g0g1gn1 of a finite list in a monoid, by recursion, with the empty product (n=0) equal to the identity, Generalised associativity: in a monoid the product of a finite list does not depend on the bracketing, and in a commutative monoid it does not depend on the order of the factors either, Polynomial convolution makes R[x] a commutative ring containing R as its constant subring). In particular, for each positive divisor d of n, let Sd:={ζμn(E):ord(ζ)=d} and Ψd:=ζSd(tζ)E[t].

[L2]

For every m1 one has dmΦd=tm1 in Z[t], each Φd monic of degree φ(d) (The recursion defines a unique monic ΦnZ[t], of degree φ(n)); reduction into K[t] preserves this identity.

[L3]

A monic f of degree m splits over E when f=j=1m(tαj) with αjE, repetitions allowed, and a splitting field is generated over K by the roots (Polynomials that split and splitting fields of a polynomial or a family of polynomials).

[L4]

f is separable over K when no extension field of K contains an a with (ta)2 dividing the image of f (Repeated roots in extension fields and separable polynomials).

[L6]

R[x] is an integral domain when R is (A polynomial ring over an integral domain is an integral domain); and f(a)=0 if and only if xa divides f (Factor theorem over a commutative ring).

Proof

technique · direct
1.1

By [L1] the polynomial tn1 is separable over K and μn(E) is cyclic of order n; so tn1 has n distinct roots in E, namely the elements of μn(E), and tn1=ζμn(E)(tζ) by [L3].

L1L3
1.2

Each ζμn(E) has order dividing n by [L5], and for a positive divisor m of n the condition ζm=1 says exactly ord(ζ)m; so μm(E) is the disjoint union of the Sd over positive divisors d of m.

L5given
2.1

For every positive divisor m of n the polynomial tm1 divides tn1 in Z[t], since tn1=(tm1)(tnm+tn2m++1); hence it splits over E with distinct roots, which are the elements of μm(E), and tm1=ζμm(E)(tζ) with μm(E)=m.

step 1.1L3L4algebra
3.1

Consequently dmΨd=ζμm(E)(tζ)=tm1 for every positive divisor m of n.

step 2.1step 1.2
4.1

For every positive divisor d of n the image of Φd in E[t] is Ψd, by induction on d through the divisors of n: at d=1 both are t1, since S1={1}; and if the claim holds for every positive divisor e of d with e<d, then [L2] and step 3.1 give (ed,e<dΨe)Φd=td1=(ed,e<dΨe)Ψd, and cancelling the nonzero left factor in the integral domain E[t] ([L6]) gives Φd=Ψd.

step 3.1L2L6
5.1

Taking d=n: the image of Φn in E[t] is ζSn(tζ), so Φn splits over E and its roots there are exactly the elements of Sn, which are the elements of order n in μn(E), that is the primitive n-th roots of unity in E; there are φ(n) of them by [L1], in agreement with degΦn=φ(n) from [L2].

step 4.1L1L2
6.1

Φn is separable over K. The product identity [L2] shows that the image of Φn divides tn1 in K[t]. If an extension field L/K contained an a for which (ta)2 divided the image of Φn, then the same square would divide the image of tn1 in L[t], making a a repeated root of tn1. This contradicts the separability of tn1 supplied by [L1]. Thus [L4] applies.

L1L2L4algebra

Remarks

PropositionStatement: Literature-sourcedProof: Literature-sourcedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

Φn is irreducible over K exactly when [K(ζn):K]=φ(n), exactly when the embedding into (Z/n)× is onto

Statement

Facts & Assumptions

Given: A field K, an integer n1 with charKn, the extension E=K(μn), a primitive n-th root of unity ζE, and the minimal polynomial mζK[t] of ζ over K.

[L1]

The image of Φn in K[t] has as its roots in E exactly the primitive n-th roots of unity in E (Over a field whose characteristic does not divide n, the roots of Φn are exactly the primitive roots of unity).

[L3]

For a algebraic over K there is a unique monic irreducible maK[t] with f(a)=0 if and only if maf (The evaluation kernel and the unique monic irreducible minimal polynomial of an algebraic element).

[L4]

If a is algebraic over K with minimal polynomial of degree m, then [K(a):K]=m (A simple algebraic extension is its minimal-polynomial quotient and has power basis 1,a,,an1 and degree n).

[L5]

For this n1, E/K is finite Galois and σ[aσ]n is an injective homomorphism Gal(E/K)(Z/n)× (K(μn)/K is Galois and σaσ embeds its Galois group into (Z/n)×); moreover E=K(ζ) for every primitive n-th root ζ (tn1 is separable over K exactly when the characteristic does not divide n, and then a splitting field carries n distinct n-th roots of unity).

[L6]

(Z/n)×=φ(n) (The unit group (Z/n)× and Euler's totient φ(n)=(Z/n)× for n1), and Gal(E/K)=[E:K] for a finite Galois extension (Equivalent characterizations of a finite Galois extension).

[L7]

In an integral domain, an irreducible element is a nonzero nonunit every one of whose factorisations has a unit factor (Irreducible and prime elements of an integral domain).

Proof

technique · direct
1.1

ζ is a root of the image of Φn in K[t] by [L1], so mζ divides that image by [L3]; both are monic, and mζ has positive degree because ζ0 is not a root of a nonzero constant. Write the image of Φn as mζg with gK[t] monic.

L1L2L3
1.2

For the equivalence of clauses 2 and 3: by [L5] one has E=K(ζ) and the embedding is injective into a group of order φ(n) by [L6], so it is surjective if and only if Gal(E/K)=φ(n); and Gal(E/K)=[E:K]=[K(ζ):K] by [L6]. An injective homomorphism onto its target is an isomorphism.

L5L6
2.1

For the implication from clause 1 to clause 2: if the image of Φn is irreducible, then in the factorisation of step 1.1 one factor is a unit by [L7], and mζ is not, so g is a nonzero constant; both mζg and mζ being monic forces g=1 and mζ=Φn. Hence [K(ζ):K]=degmζ=φ(n) by [L2] and [L4].

step 1.1L2L4L7
2.2

For the implication from clause 2 to clause 1: if [K(ζ):K]=φ(n) then degmζ=φ(n)=degΦn by [L2] and [L4], so g in step 1.1 is monic of degree 0, that is g=1 and the image of Φn equals mζ, which is irreducible by [L3].

step 1.1L2L3L4
3.1

Steps 2.1 and 2.2 give the equivalence of clauses 1 and 2, and step 1.2 the equivalence of clauses 2 and 3; so all three are equivalent.

step 2.1step 2.2step 1.2

Remarks

PropositionStatement: Literature-sourcedProof: Literature-sourcedprecheck passaudited 2026-08-26Open item page →

Φpr(t)=k<ptkpr1, and Φpr(t+1) is Eisenstein at p

Statement

Let p be a prime (Prime and composite integers: p is prime when p>1 and its only positive divisors are 1 and p) and r1. Then

Φpr(t)=k=0p1tkpr1=tpr1tpr11,

the polynomial Φpr(t+1)Z[t] satisfies the Eisenstein criterion at p (Eisenstein criterion over the integers), and consequently Φpr is irreducible in Q[t] (Irreducible and prime elements of an integral domain).

The sum starts at k=0: its first term is the constant 1, and evaluation at t=1 (Evaluation and roots of a polynomial in a commutative target ring) gives Φpr(1)=p.

Facts & Assumptions

Given: A prime p and an integer r1; the cyclotomic polynomials of The cyclotomic polynomials ΦnZ[t], defined by dnΦd=tn1 and the substitution homomorphisms of Universal property of R[x]: a coefficient homomorphism and the image of x determine a unique ring homomorphism, under which tt+1 is a ring automorphism of Z[t] and of Q[t] with inverse tt1.

[L1]

For every n1, dnΦd=tn1 with each Φd monic in Z[t] of degree φ(d) (The recursion defines a unique monic ΦnZ[t], of degree φ(n), Degree, leading coefficient and monic polynomial, with the zero polynomial having no degree).

[L2]

Let f=anxn++a0Z[x] be primitive with n1. If a prime p satisfies pan, pai for every i<n, and p2a0, then f is irreducible in Q[x] (Eisenstein criterion over the integers).

[L3]

A nonzero integer polynomial is primitive exactly when no prime divides all of its coefficients (Content is the positive common divisor of the coefficients divisible by every common divisor, Content and primitive integer polynomials).

[L5]

φ(pk)=pkpk1 for every prime p and k1 (For a prime p and k1, φ(pk)=pkpk1).

[L7]

R[x] is an integral domain when R is (A polynomial ring over an integral domain is an integral domain).

Proof

technique · direct
1.1

The positive divisors of pj are exactly p0,,pj: a positive d dividing pj with d>1 has a prime divisor q by [L6], and qpj forces qp by [L6], hence q=p since p is prime and q>1 (Prime and composite integers: p is prime when p>1 and its only positive divisors are 1 and p, Divisibility in Z: da when a=dq for some integer q); writing d=pd gives dpj1 by cancellation, and repeating reduces d to a power of p not exceeding pj.

L6given
2.1

By [L1] at n=pr and at n=pr1, using step 1.1, j=0rΦpj=tpr1 and j=0r1Φpj=tpr11; dividing, (tpr11)Φpr=tpr1.

step 1.1L1
3.1

With u:=tpr1 the elementary identity (u1)k=0p1uk=up1 gives (tpr11)k=0p1tkpr1=tpr1; comparing with step 2.1 and cancelling the nonzero factor tpr11 in the integral domain Z[t] ([L7]) yields Φpr=k=0p1tkpr1.

step 2.1L7algebra
3.2

Reducing step 2.1 modulo p and applying [L4] twice in (Z/p)[t] gives Φpr(t1)pr1=(t1)pr, and cancelling in the integral domain (Z/p)[t] ([L7]) gives Φpr=(t1)prpr1.

step 2.1L4L7
4.1

Evaluating step 3.1 at t=1 gives Φpr(1)=p, since the sum has p terms each equal to 1; so the constant term of Φpr(t+1) is p, which is divisible by p and not by p2.

step 3.1algebra
4.2

Substituting t+1, which commutes with reduction modulo p because both are ring homomorphisms fixing the coefficients appropriately, gives Φpr(t+1)=tprpr1=tφ(pr) by [L5]. So every coefficient of Φpr(t+1) other than the leading one is divisible by p, while the leading coefficient is 1 because Φpr(t+1) is monic of degree φ(pr) by [L1] and the substitution being degree preserving.

step 3.2L1L5given
5.1

Φpr(t+1) is primitive by [L3], no prime dividing its leading coefficient 1, and its degree φ(pr) is at least 1 by [L5]; steps 4.1 and 4.2 supply the three Eisenstein conditions at p, so [L2] makes it irreducible in Q[t].

step 4.1step 4.2L2L3L5
6.1

The substitution tt1 is a ring automorphism of Q[t] carrying Φpr(t+1) to Φpr; a ring automorphism preserves units and factorisations, so it carries irreducible elements to irreducible elements, and Φpr is irreducible in Q[t].

step 5.1given

Remarks

  • The term k=0 is load bearing. Dropping it would change Φpr(1) from p to p1, and the Eisenstein constant-term condition would fail. The highest exponent would be unchanged, so the degree alone would not detect the wrong polynomial.

  • A self-contained route for prime powers. This gives irreducibility over Q for n a prime power without the general argument of Φn is irreducible in Q[t] for every n1, and unlike that argument it exhibits an explicit polynomial to which a named criterion applies. The general theorem covers every n and does not supersede this computation; the companion page works out the case p=7 in Φ7(t+1) is Eisenstein at seven .

LemmaStatement: Literature-sourcedProof: Literature-sourcedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

If p is a prime not dividing n, a rational minimal polynomial of a primitive n-th root of unity also kills its p-th power

Statement

Let n1, let E be a splitting field of tn1 over Q, let ζE be a primitive n-th root of unity (The group μn(K) of n-th roots of unity in a field, and primitive n-th roots of unity), let fQ[t] be the minimal polynomial of ζ over Q (The evaluation kernel and the unique monic irreducible minimal polynomial of an algebraic element), and let p be a prime (Prime and composite integers: p is prime when p>1 and its only positive divisors are 1 and p) with pn (Divisibility in Z: da when a=dq for some integer q). Then

f(ζp)=0.

Facts & Assumptions

Given: The data of the statement; Q is an ordered field (The rationals form a totally ordered field), so m1>0 and in particular m10 for every m1, whence charQ=0 (The characteristic of a ring: the least n1 with n1R=0 when one exists, and 0 otherwise), which divides no n1, so tn1 is separable over Q and μn(E) is cyclic of order n generated by ζ (tn1 is separable over K exactly when the characteristic does not divide n, and then a splitting field carries n distinct n-th roots of unity, μn(K) is cyclic of order dividing n, and has a primitive n-th root of unity exactly when its order is n); Φn denotes the cyclotomic polynomial (The cyclotomic polynomials ΦnZ[t], defined by dnΦd=tn1) and also its images in Q[t] and in (Z/p)[t], where reduction is the ring homomorphism of Universal property of R[x]: a coefficient homomorphism and the image of x determine a unique ring homomorphism and Z/p is a field (For every prime p, the two operations on Z/p make it a field).

[L2]

For a algebraic over a field K there is a unique monic irreducible maK[t] with h(a)=0 if and only if mah (The evaluation kernel and the unique monic irreducible minimal polynomial of an algebraic element).

[L3]

For a commutative ring R and monic gR[x], every hR[x] has unique q,rR[x] with h=qg+r and r=0 or degr<degg (Division by a monic polynomial over a commutative ring).

[L4]

For nonzero u,vZ[x], cont(uv)=cont(u)cont(v) (The product of primitive integer polynomials is primitive, and contents multiply); content is the nonnegative gcd of the coefficients and primitive means content 1 (Content and primitive integer polynomials); a nonzero integer polynomial is primitive exactly when no prime divides all its coefficients (Content is the positive common divisor of the coefficients divisible by every common divisor).

[L5]

In a field L of characteristic p>0 the map xxp is a field endomorphism (Frobenius xxp is an injective endomorphism in characteristic p, and an automorphism for finite fields); and every c in a field with p elements satisfies cp=c (A field with q elements is the splitting field of xqx over its prime subfield).

[L6]
[L7]

R[x] is an integral domain when R is (A polynomial ring over an integral domain is an integral domain), and h(a)=0 if and only if xa divides h (Factor theorem over a commutative ring).

[L8]

In a cyclic group g of finite order m, ga generates the group if and only if gcd(a,m)=1 (A cyclic group of order n has exactly φ(n) generators).

Proof

technique · contradiction
1.1

Suppose, for contradiction, that f(ζp)0.

assume-contra
1.2

ζp is again a primitive n-th root of unity: gcd(p,n)=1 because p is prime and pn, so [L8] makes ζp a generator of μn(E), of order n. Hence Φn(ζp)=0 by [L1].

L1L8given
1.3

Since Φn(ζ)=0 by [L1], [L2] gives fΦn in Q[t]; write Φn=fg with gQ[t], monic because f and Φn are.

L1L2
2.1

Both f and g lie in Z[t]. Let b1 be least with bfZ[t] and d1 least with dgZ[t]; these exist because clearing denominators gives some such integer. If a prime q divided every coefficient of bf then q would divide its leading coefficient b, and (b/q)f would lie in Z[t], contradicting minimality; so bf is primitive by [L4], and likewise dg. Then [L4] gives cont(bdΦn)=cont((bf)(dg))=1, while cont(bdΦn)=bdcont(Φn)=bd because Φn is monic in Z[t] and hence primitive by [L4]; so bd=1 and b=d=1.

step 1.3L1L4
2.2

From step 1.2 and step 1.3, 0=Φn(ζp)=f(ζp)g(ζp) in the field E, and f(ζp)0 by step 1.1, so g(ζp)=0.

step 1.1step 1.2step 1.3
3.1

Hence ζ is a root of the polynomial g(tp), so fg(tp) in Q[t] by [L2]; writing g(tp)=fh with hQ[t], the division of the monic g(tp)Z[t] by the monic fZ[t] has quotient and remainder in Z[t] by [L3], and by the uniqueness clause of [L3] read in Q[t] that quotient is h and the remainder is 0; so hZ[t].

step 2.1step 2.2L2L3
4.1

Reduce modulo p and let L be a splitting field of fˉ over Z/p, which exists by [L6]; fˉ is monic of the same degree as f, which is at least 1, so it has a root aL.

step 2.1step 3.1L6given
5.1

Evaluating the reduction of step 3.1 at a gives gˉ(ap)=fˉ(a)hˉ(a)=0. Writing gˉ=iciti with ciZ/p and using [L5] twice, gˉ(a)p=icipaip=ici(ap)i=gˉ(ap)=0, so gˉ(a)=0 because L is a field.

step 3.1step 4.1L5
6.1

Thus ta divides both fˉ and gˉ in L[t] by [L7], so (ta)2 divides fˉgˉ=Φn, which divides tn1 in (Z/p)[t] by [L1]. Then a is a repeated root of tn1 in the extension L of Z/p, contradicting [L6], since pn. The assumption of step 1.1 is therefore untenable and f(ζp)=0.

step 1.1step 4.1step 5.1L1L6L7discharge-contradiction

Remarks

  • Where pn is used. Twice, and both uses are essential: in step 1.2, to know that ζp is still primitive, and in step 6.1, to know that tn1 is separable modulo p. If p divided n the reduction Φn could genuinely have a repeated factor and the argument would produce no contradiction.

  • Why the passage to Z[t] is not cosmetic. Reduction modulo p is defined on integer polynomials, so the factorisation Φn=fg has to be known to happen over Z before step 4.1 can start. That is exactly what step 2.1 supplies, and it is where Gauss's content lemma enters.

TheoremStatement: Literature-sourcedProof: Literature-sourcedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

Φn is irreducible in Q[t] for every n1

Facts & Assumptions

Given: An integer n1; Q is an ordered field (The rationals form a totally ordered field), so m1>0 and in particular m10 for m1, whence charQ=0 (The characteristic of a ring: the least n1 with n1R=0 when one exists, and 0 otherwise) and divides no n1 (Divisibility in Z: da when a=dq for some integer q); a splitting field E of tn1 over Q (Every nonzero polynomial over a field has a splitting field); a primitive n-th root of unity ζE (The group μn(K) of n-th roots of unity in a field, and primitive n-th roots of unity); and fQ[t] the minimal polynomial of ζ over Q.

[L3]

For a algebraic over K there is a unique monic irreducible maK[t] with h(a)=0 if and only if mah (The evaluation kernel and the unique monic irreducible minimal polynomial of an algebraic element).

[L4]

If ξ is a primitive n-th root of unity in E, gQ[t] is its minimal polynomial and p is a prime with pn, then g(ξp)=0 (If p is a prime not dividing n, a rational minimal polynomial of a primitive n-th root of unity also kills its p-th power).

[L6]

In a cyclic group g of finite order m, ga generates the group if and only if gcd(a,m)=1, that is when a and m are coprime (A cyclic group of order n has exactly φ(n) generators, Coprime integers: gcd(a,b)=1).

[L7]

A nonzero polynomial of degree k over an integral domain has at most k distinct roots in it (A nonzero polynomial of degree n over an integral domain has at most n distinct roots).

Proof

technique · direct
1.1

ζ is a root of Φn by [L2], so fΦn in Q[t] by [L3], and f is monic and irreducible.

L2L3
1.2

Let ξE be any primitive n-th root of unity. By [L1] it generates μn(E)=ζ, so ξ=ζa for some integer a, which may be taken with a1 after adding a multiple of n; and gcd(a,n)=1 by [L6]. Write a=p1p2ps as a product of primes by [L5], with s=0 when a=1. No pi divides n, since pia and gcd(a,n)=1.

L1L5L6given
2.1

Put ζ0:=ζ and ζj:=ζj1pj for 1js, so that ζs=ζa=ξ. By induction on j, each ζj is a primitive n-th root of unity and f(ζj)=0: at j=0 this is the hypothesis on ζ and step 1.1; and given it at j1, the polynomial f is monic irreducible and vanishes at the primitive n-th root of unity ζj1, so f is the minimal polynomial of ζj1 by [L3], whence f(ζj)=f(ζj1pj)=0 by [L4], while ζj is primitive by [L6] because gcd(pj,n)=1.

step 1.1step 1.2L3L4L6
3.1

So f vanishes at every primitive n-th root of unity in E, of which there are φ(n) distinct ones by [L1]; hence degfφ(n) by [L7].

step 2.1L1L7
4.1

On the other hand fΦn with degΦn=φ(n) by [L2], so degfφ(n); therefore degf=φ(n), and f and Φn are monic with fΦn, so Φn=f is irreducible. At n=1 this reads Φ1=t1, of degree φ(1)=1.

step 1.1step 3.1L2L3

Remarks

CorollaryStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

[Q(ζn):Q]=φ(n) and Gal(Q(μn)/Q)(Z/n)×

Facts & Assumptions

[L1]

Φn is irreducible in Q[t] for every n1 (Φn is irreducible in Q[t] for every n1).

[L2]

For a field K with charKn and a primitive n-th root of unity ζ in a splitting field, irreducibility of the image of Φn in K[t], the equality [K(ζ):K]=φ(n), and surjectivity of the embedding Gal(K(μn)/K)(Z/n)× are equivalent (Φn is irreducible over K exactly when [K(ζn):K]=φ(n), exactly when the embedding into (Z/n)× is onto).

Proof

technique · direct
1.1

Since charQ=0 does not divide n, [L2] applies with K=Q.

L2given
2.1

The image of Φn in Q[t] is Φn itself, irreducible by [L1]; so the first clause of [L2] holds, and therefore so do the other two: [Q(ζ):Q]=φ(n), and the embedding is onto, hence an isomorphism, being injective.

step 1.1L1L2

Remarks

TheoremStatement: AI-adaptedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

For gcd(n,q)=1 the reduction of Φn in Fq[t] is a product of distinct monic irreducibles, each of degree the order of [q] modulo n

Statement

Let Fq be a finite field of order q and let n1 with gcd(n,q)=1 (Coprime integers: gcd(a,b)=1). Put d:=ord([q]n), the multiplicative order of [q]n in (Z/n)× (The order G of a finite group and the order ord(g) of an element, with ord(g)= when no positive power of g is the identity, The unit group (Z/n)× and Euler's totient φ(n)=(Z/n)× for n1). Then the image of Φn in Fq[t] (The cyclotomic polynomials ΦnZ[t], defined by dnΦd=tn1) is a product of pairwise distinct monic irreducible polynomials, each of degree d, and there are φ(n)/d of them.

Facts & Assumptions

[L1]

Over a field K with charKn and a splitting field E of tn1, the image of Φn in K[t] is separable, splits over E, and its roots in E are exactly the φ(n) primitive n-th roots of unity in E (Over a field whose characteristic does not divide n, the roots of Φn are exactly the primitive roots of unity, The group μn(K) of n-th roots of unity in a field, and primitive n-th roots of unity).

[L4]

For πFq[t] monic irreducible of degree e with a root α in an extension field, Fq(α) is a finite field of order qe and [Fq(α):Fq]=e (A monic irreducible of degree d over Fq has the d distinct roots α,αq,,αqd1).

[L5]

F[x] is a unique factorisation domain for every field F (For every field F, F[x] is a unique factorisation domain); irreducible elements are as in Irreducible and prime elements of an integral domain.

[L6]

f is separable over K when no extension field contains an a with (ta)2 dividing the image of f (Repeated roots in extension fields and separable polynomials).

[L7]

Over an integral domain, deg(fg)=degf+degg for nonzero f,g (Over an integral domain, degrees add under multiplication of nonzero polynomials).

[L8]

In any field F, the group μn(F) is cyclic of order dividing n; if it contains a primitive n-th root of unity, then its order is n, and in that case its generators are exactly the primitive n-th roots of unity (μn(K) is cyclic of order dividing n, and has a primitive n-th root of unity exactly when its order is n).

Proof

technique · direct
1.1

Since q is a power of p and gcd(n,q)=1, the prime p does not divide n; so [L1] applies with K=Fq and the splitting field E=Fq(μn), and [L3] gives [E:Fq]=d.

L1L3given
1.2

By [L2] the polynomial Φˉn is monic of degree φ(n)1, so by [L5] it is a product of monic irreducible polynomials of Fq[t], say Φˉn=π1πr with each πi monic irreducible.

L2L5
2.1

Each πi has a root in E. By [L1] the polynomial Φˉn splits over E into φ(n) distinct linear factors, and πi divides it; since E[t] is a unique factorisation domain by [L5], πi is, up to a unit, a product of some of those linear factors. Thus it has a root αiE, and αi is a primitive n-th root of unity by [L1].

step 1.2L1L5
3.1

No two of the πi coincide. If πi=πj=π for ij, then π2 divides Φˉn. By step 2.1 the polynomial π has a linear factor tα in E[t], so (tα)2 divides Φˉn there, contradicting the separability supplied by [L1] and [L6].

step 1.2step 2.1L1L5L6
3.2

Every πi has degree d. Writing ei:=degπi, [L4] gives [Fq(αi):Fq]=ei. Since αi is primitive, [L8] makes μn(E) a cyclic group of order n with generators exactly the primitive n-th roots, so αi generates μn(E). Hence μn(E)Fq(αi) and therefore E=Fq(μn(E))Fq(αi); and αiE gives Fq(αi)E. Thus Fq(αi)=E and ei=[E:Fq]=d by step 1.1.

step 1.1step 2.1L4L8
4.1

Comparing degrees with [L7] and [L2], φ(n)=degΦˉn=i=1rei=rd, so r=φ(n)/d; with steps 3.1 and 3.2 this is the assertion.

step 1.2step 3.1step 3.2L2L7

Remarks

  • The degree of every factor is the same, and that is the content. A polynomial can factor into irreducibles of different degrees; here it cannot, because adjoining any primitive root produces the same field Fq(μn). The primitive roots need not form a single Frobenius orbit: for n=7 over F2 they split into two orbits of size three, one for each irreducible cubic factor on the companion page.
CorollaryStatement: AI-adaptedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

The reduction of Φn is irreducible over Fq exactly when [q] generates (Z/n)×

Statement

Let Fq be a finite field of order q and n1 with gcd(n,q)=1 (Coprime integers: gcd(a,b)=1). The image of Φn in Fq[t] (The cyclotomic polynomials ΦnZ[t], defined by dnΦd=tn1) is irreducible (Irreducible and prime elements of an integral domain) if and only if [q]n generates (Z/n)× (The subgroup S generated by a subset, the cyclic subgroup g, and cyclic groups, The unit group (Z/n)× and Euler's totient φ(n)=(Z/n)× for n1). In particular this can happen only when (Z/n)× is cyclic.

Facts & Assumptions

Proof

technique · direct
1.1

By [L1] the number of monic irreducible factors of Φˉn, counted without repetition and with none repeated, is r=φ(n)/d.

L1
2.1

If r=1 then Φˉn is itself one of those monic irreducible polynomials, hence irreducible; if r2 then Φˉn is a product of r polynomials each of degree d1, none of them a unit, so it is not irreducible. Hence Φˉn is irreducible exactly when r=1, that is exactly when d=φ(n).

step 1.1L1L2
3.1

By [L3] the subgroup [q]n has order d and (Z/n)× has order φ(n), so d=φ(n) holds exactly when [q]n=(Z/n)×, that is exactly when [q]n generates the unit group. With step 2.1 this proves the equivalence, and a group with a generator is cyclic.

step 2.1L3

Remarks

  • When the criterion cannot be met at all. If (Z/n)× is not cyclic then no class generates it, so the reduction of Φn is reducible over every finite field of order coprime to n; the smallest such n is 8, where (Z/8)× has three elements of order two and no element of order four.
LemmaStatement: AI-adaptedProof: AI-adaptedprecheck passaudited 2026-08-26Open item page →

For E/F finite Galois and L/F finite inside a common field, [EL:F]=[E:F][L:F]/[EL:F]

Statement

Let E/F be a finite Galois extension (Finite Galois extensions and Gal(K/F)) and L/F a finite extension (The degree [K:F]=dimFK of a finite field extension), both subfields of a common field. Then the compositum EL is finite over F and

[EL:F]=[E:F][L:F][EL:F].

Only one of the two extensions is required to be Galois.

Facts & Assumptions

Given: Subfields E and L of a common field, both containing F, with E/F finite Galois and L/F finite; EL is a subfield containing F and contained in E, hence an intermediate field of E/F.

[L1]

For E/F finite Galois and L/F an extension inside a common overfield, EL/L is finite Galois and restriction gives Gal(EL/L)Gal(E/EL) (The Galois translation theorem).

[L2]

If K/F is finite Galois and FEK, then K/E is finite Galois (A finite Galois extension is Galois over every intermediate field).

[L3]

For fields FKM with K/F and M/K finite, M/F is finite and [M:F]=[M:K][K:F] (Tower law for finite extensions: [L:F]=[L:K][K:F]).

[L4]

For finite subextensions E/F and E/F of a common field, the compositum is finite and [EE:F][E:F][E:F] (For finite subextensions in a common field, [EE:F][E:F][E:F]).

[L5]

For a finite Galois extension M/K one has Gal(M/K)=[M:K] (Equivalent characterizations of a finite Galois extension).

Proof

technique · direct
1.1

EL is an intermediate field of E/F, so E/(EL) is finite Galois by [L2].

L2given
1.2

By [L4] the compositum EL is finite over F.

L4given
1.3

Applying [L3] to FELE gives [E:F]=[E:EL][EL:F], so [E:EL]=[E:F]/[EL:F].

L3given
2.1

By [L1] the extension EL/L is finite Galois with Gal(EL/L)Gal(E/EL), so [L5] applied to both sides gives [EL:L]=Gal(EL/L)=Gal(E/EL)=[E:EL].

step 1.1step 1.2L1L5
3.1

Applying [L3] to FLEL and substituting steps 2.1 and 1.3 gives [EL:F]=[EL:L][L:F]=[E:EL][L:F]=[E:F][L:F]/[EL:F].

step 2.1step 1.3L3

Remarks

  • The Galois hypothesis is not decoration. Without it the formula fails: over F=Q take E=Q(23) and L=Q(ω23) inside a splitting field of t32, where ω is a primitive cube root of unity. Both have degree three over Q, since t32 is irreducible there. The compositum contains ω=(ω23)/23, hence contains the splitting field Q(23,ω) and equals it, so [EL:Q]=6. And EL=Q: its degree over Q divides 3 by the tower law, and it cannot be 3, since E=EL=L would put ω in E and force [E:Q]6. The formula would predict 9. Neither E nor L is Galois over Q.
TheoremStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

K(μm)K(μn)=K(μlcm(m,n))

Statement

Let K be a field and let m,n1 be integers such that charK divides neither m nor n (The characteristic of a ring: the least n1 with n1R=0 when one exists, and 0 otherwise, Divisibility in Z: da when a=dq for some integer q). Put :=lcm(m,n) (Common multiple, and the least common multiple lcm(a,b), taken to be 0 when a=0 or b=0) and let Ω be a splitting field of t1 over K (Every nonzero polynomial over a field has a splitting field). Then charK; the subfields K(μm(Ω)) and K(μn(Ω)) of Ω are cyclotomic extensions of K of orders m and n (The cyclotomic extension K(μn) as a splitting field of tn1); and their compositum inside Ω is

K(μm)K(μn)=K(μ)=Ω.

Facts & Assumptions

Given: A field K, integers m,n1 with charK dividing neither, =lcm(m,n), and a splitting field Ω of t1 over K; the characteristic of a field is 0 or a prime (The characteristic of a field is zero or a prime number), and 0 divides no positive integer.

[L1]

lcm(a,b) is a common multiple of a and b (Common multiple, and the least common multiple lcm(a,b), taken to be 0 when a=0 or b=0); every common multiple of a and b is a multiple of lcm(a,b), and gcd(a,b)lcm(a,b)=ab (Every common multiple of a and b is a multiple of lcm(a,b), and gcd(a,b)lcm(a,b)=ab).

[L4]

A polynomial is separable over K when no extension field contains a repeated root (Repeated roots in extension fields and separable polynomials); a splitting field is generated over K by the roots (Polynomials that split and splitting fields of a polynomial or a family of polynomials, Finitely generated field extensions F(a1,,ar)).

Proof

technique · direct
1.1

charK. If charK=0 this is immediate; if charK=p is a prime dividing , then divides mn because gcd(m,n)=mn by [L1] and gcd(m,n)1, so pmn and [L2] gives pm or pn, contrary to hypothesis.

L1L2given
2.1

By [L3] and step 1.1 the polynomial t1 is separable over K, the group μ(Ω) is cyclic of order , and Ω=K(μ(Ω)).

step 1.1L3L4
3.1

For every positive divisor k of one has μk(Ω)=k and K(μk(Ω)) is a splitting field of tk1 over K, hence a cyclotomic extension of K of order k: indeed tk1 divides t1, since t1=(tk1)(tk+t2k++1), so it splits over Ω, and a repeated root of it would be a repeated root of t1, excluded by step 2.1 through [L4]; so its k roots are distinct and they are the elements of μk(Ω), which generate K(μk(Ω)) over K.

step 2.1L3L4algebra
4.1

m and n are positive divisors of by [L1], so step 3.1 applies to both: K(μm(Ω)) and K(μn(Ω)) are cyclotomic extensions of K of orders m and n, and each contains a primitive root of unity of its order by [L3].

step 3.1L1L3
5.1

Both are contained in Ω=K(μ(Ω)), since μm(Ω) and μn(Ω) are subsets of μ(Ω) by m and n; hence their compositum inside Ω is contained in K(μ).

step 2.1step 4.1L1
5.2

For the reverse inclusion, fix a primitive m-th root of unity ζmμm(Ω) and a primitive n-th root of unity ζnμn(Ω), and let H:=ζm,ζnμ(Ω). By [L5] the orders m=ζm and n=ζn both divide H, so H is a common multiple of m and n and therefore a multiple of by [L1]; and H divides by [L5]. Hence H= and H=μ(Ω).

step 2.1step 4.1L1L5
6.1

Both ζm and ζn lie in the compositum K(μm)K(μn), which is a field, so HK(μm)K(μn) and therefore μ(Ω)K(μm)K(μn) by step 5.2; hence Ω=K(μ(Ω))K(μm)K(μn). With step 5.1 this gives K(μm)K(μn)=K(μ)=Ω.

step 2.1step 5.1step 5.2

Remarks

LemmaStatement: AI-adaptedProof: AI-generatedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

φ(m)φ(n)=φ(gcd(m,n))φ(lcm(m,n))

Statement

For all integers m,n1,

φ(m)φ(n)=φ(gcd(m,n))φ(lcm(m,n))

(The unit group (Z/n)× and Euler's totient φ(n)=(Z/n)× for n1, Common divisor, and the greatest common divisor gcd(a,b), with the convention gcd(0,0):=0, Common multiple, and the least common multiple lcm(a,b), taken to be 0 when a=0 or b=0). At m=n=1 both sides are 1; at gcd(m,n)=1 the identity is the multiplicativity φ(m)φ(n)=φ(mn).

Facts & Assumptions

Given: Integers m,n1; write g:=gcd(m,n) and :=lcm(m,n), both 1 because m and n are nonzero. For a prime p (Prime and composite integers: p is prime when p>1 and its only positive divisors are 1 and p) and an integer e0 put w(p,e):=pepe1 when e1 and w(p,0):=1. For k1 write D(k) for the set of primes dividing k (Divisibility in Z: da when a=dq for some integer q); it is finite, being contained in {2,,k} by If da and a0 then d0 and da; hence the set of divisors of a nonzero integer is bounded above by a. Put P:=D(m)D(n). Finite products over such sets are those of The sum iSai over a finite index set, and its product form.

[L1]

Let k1 and let p0,,pr1 be an injective finite list consisting exactly of the prime divisors of k; put ei:=vpi(k), so ei1. Then φ(k)=i<r(pieipiei1) (Euler's product formula φ(n)=npn(11/p)=pkn(pkpk1) for n1, stated through a finite injective list of its prime divisors).

[L3]

For a prime p and a nonzero integer a, vp(a) is the greatest kN with pka (The p-adic valuation vp(a) of a nonzero integer: the greatest kN with pka).

Proof

technique · direct
1.1

For a prime p and an integer k1: pk if and only if vp(k)1. If vp(k)1 then p divides pvp(k), which divides k by [L3]; conversely pk says p1k, so the greatest such exponent is at least 1.

L3
1.2

For each pP write a:=vp(m) and b:=vp(n); then vp(g)=min{a,b} and vp()=max{a,b} by [L2], and the unordered pair {min{a,b},max{a,b}} is {a,b}, so w(p,a)w(p,b)=w(p,vp(g))w(p,vp()).

L2given
2.1

Consequently D(g)=D(m)D(n) and D()=D(m)D(n): by [L2] and step 1.1, pD(g) says min{vp(m),vp(n)}1, that is pD(m) and pD(n); and pD() says max{vp(m),vp(n)}1, that is pD(m) or pD(n).

step 1.1L2
3.1

The set P is a finite set of primes containing D(m), D(n), D(g) and D() by step 2.1. For every k{m,n,g,} one has φ(k)=pPw(p,vp(k)): applying [L1] with the list D(k) gives φ(k)=pD(k)w(p,vp(k)), and for pP outside D(k) step 1.1 gives vp(k)=0, so the extra factors are w(p,0)=1.

step 1.1step 2.1L1given
4.1

Multiplying the equalities of step 1.2 over the finite set P and using step 3.1 four times gives φ(m)φ(n)=pPw(p,vp(m))w(p,vp(n))=pPw(p,vp(g))w(p,vp())=φ(g)φ().

step 3.1step 1.2

Remarks

  • Why the identity is not simply multiplicativity. For coprime m and n it reduces to φ(mn)=φ(m)φ(n), but the general case is what the intersection theorem needs: the degrees of Q(μm) and Q(μn) multiply to the degree of the compositum times the degree of the intersection, and it is the gcd–lcm form of the identity that turns that into φ(gcd(m,n)) (Q(μm)Q(μn)=Q(μgcd(m,n))).
TheoremStatement: Literature-sourcedProof: AI-adaptedprecheck passaudited 2026-08-26Open item page →

Q(μm)Q(μn)=Q(μgcd(m,n))

Statement

Let m,n1, put d:=gcd(m,n) and :=lcm(m,n) (Common divisor, and the greatest common divisor gcd(a,b), with the convention gcd(0,0):=0, Common multiple, and the least common multiple lcm(a,b), taken to be 0 when a=0 or b=0), and let Ω be a splitting field of t1 over Q (Every nonzero polynomial over a field has a splitting field), inside which the cyclotomic extensions Q(μk) for k are taken (The cyclotomic extension K(μn) as a splitting field of tn1). Then

Q(μm)Q(μn)=Q(μd).

Facts & Assumptions

Given: Integers m,n1 with d=gcd(m,n) and =lcm(m,n); Q is an ordered field (The rationals form a totally ordered field), so charQ=0 (The characteristic of a ring: the least n1 with n1R=0 when one exists, and 0 otherwise) and divides no positive integer (Divisibility in Z: da when a=dq for some integer q); a splitting field Ω of t1 over Q; and, for each positive divisor k of , the subfield Q(μk):=Q(μk(Ω)) of Ω. Write I:=Q(μm)Q(μn).

[L1]

For a positive divisor k of , the subfield Q(μk(Ω)) generated by the k-th roots of unity in Ω is a cyclotomic extension of Q of order k (The cyclotomic extension K(μn) as a splitting field of tn1, The group μn(K) of n-th roots of unity in a field, and primitive n-th roots of unity); because charQ=0 divides no positive integer, tn1 is separable over K exactly when the characteristic does not divide n, and then a splitting field carries n distinct n-th roots of unity gives μk(Ω) cyclic of order k, with exactly φ(k) primitive k-th roots of unity.

[L4]

For E/F finite Galois and L/F finite inside a common field, [EL:F]=[E:F][L:F]/[EL:F] (For E/F finite Galois and L/F finite inside a common field, [EL:F]=[E:F][L:F]/[EL:F]).

[L5]

Q(μm)Q(μn)=Q(μ) inside Ω (K(μm)K(μn)=K(μlcm(m,n))).

[L6]
[L7]

For fields FKM with K/F and M/K finite, [M:F]=[M:K][K:F] (Tower law for finite extensions: [L:F]=[L:K][K:F]).

Proof

technique · direct
1.1

d divides m and n, and m,n,d all divide . For each positive divisor k of , write =kq; then t1=(tk)q1=(tk1)(tk(q1)++tk+1), so tk1 splits over the splitting field Ω of t1, and [L1] applies to k. In particular all four cyclotomic extensions for k=m,n,d, sit inside Ω.

L1givenalgebra
2.1

For the inclusion Q(μd)I: since dm, every x with xd=1 satisfies xm=1, so μd(Ω)μm(Ω) and hence Q(μd)Q(μm); the same argument with n gives Q(μd)Q(μn).

step 1.1givenalgebra
2.2

By [L3] the extension Q(μm)/Q is finite Galois and Q(μn)/Q is finite, both inside Ω, so [L4] and [L5] give φ()=[Q(μ):Q]=[Q(μm)Q(μn):Q]=φ(m)φ(n)/[I:Q], using [L2] twice.

step 1.1L2L3L4L5
3.1

Hence [I:Q]=φ(m)φ(n)/φ()=φ(d) by [L6].

step 2.2L6
4.1

By step 2.1 the tower QQ(μd)I is defined, and [L7] with [L2] gives φ(d)=[I:Q]=[I:Q(μd)]φ(d), so [I:Q(μd)]=1 and I=Q(μd).

step 2.1step 3.1L2L7

Remarks

  • Where the base field is used. Only through [L2]: the equality [Q(μk):Q]=φ(k) for every k, which is irreducibility of Φk over Q. Over a base field where some Φk becomes reducible the degrees drop unevenly and the degree count in step 2.2 no longer forces the intersection down to Q(μd).

  • The base field really matters. Over a general base field the same formula can fail; the companion page gives a finite-field witness in F3(μ5)F3(μ7) is larger than F3 although five and seven are coprime .

CorollaryStatement: AI-generatedProof: AI-generatedprecheck passaudited 2026-08-26Open item page →

For an odd prime p, Q(ζp) has exactly one intermediate field of degree two over Q

Statement

Let p be an odd prime (Prime and composite integers: p is prime when p>1 and its only positive divisors are 1 and p) and let ζ be a primitive p-th root of unity (The group μn(K) of n-th roots of unity in a field, and primitive n-th roots of unity) in Q(μp) (The cyclotomic extension K(μn) as a splitting field of tn1). Then there is exactly one intermediate field F with

QFQ(ζ),[F:Q]=2

(The degree [K:F]=dimFK of a finite field extension).

Intermediate, not proper. At p=3 the Galois group has order two, the unique subgroup of index two is the trivial one, and the field it names is Q(ζ3) itself. Reading the statement as "proper subfield" would make it false at the smallest case in scope.

Facts & Assumptions

Given: An odd prime p and a primitive p-th root of unity ζ in the cyclotomic extension Q(μp)=Q(ζ); write G:=Gal(Q(μp)/Q).

[L2]

Every finite subgroup of the unit group of an integral domain is cyclic (Every finite subgroup of the unit group of an integral domain is cyclic); Z/p is a field (For every prime p, the two operations on Z/p make it a field, Field), hence an integral domain, and (Z/p)× is its group of units (The unit group (Z/n)× and Euler's totient φ(n)=(Z/n)× for n1).

[L4]

In a cyclic group of finite order m there is exactly one subgroup of each order dividing m, and every subgroup has that form (A finite cyclic group has exactly one subgroup of each order dividing its own).

[L5]

For K/F finite Galois with G=Gal(K/F), the maps HKH and EGal(K/E) are mutually inverse bijections between subgroups and intermediate fields, and [KH:F]=[G:H] (The fundamental theorem of finite Galois theory).

[L6]

For a finite group G and HG, G=[G:H]H (Lagrange's theorem: G=[G:H]H for every subgroup H of a finite group G).

Proof

technique · direct
1.1

By [L1] the group G is isomorphic to (Z/p)×, which is cyclic by [L2] and has order p1 by [L3]; so G is cyclic of order p1.

L1L2L3
2.1

Since p is odd, p1 is even, so 2 divides p1 and (p1)/2 is a positive divisor of p1 (Divisibility in Z: da when a=dq for some integer q). By [L4] there is exactly one subgroup HG with H=(p1)/2.

step 1.1L4given
2.2

By [L5] and [L6], an intermediate field F of Q(μp)/Q has [F:Q]=[G:H]=G/H for its corresponding subgroup H, so [F:Q]=2 holds exactly when H=(p1)/2.

step 1.1L5L6
3.1

The correspondence of [L5] is a bijection, so the intermediate fields of degree two over Q are in bijection with the subgroups of order (p1)/2, of which there is exactly one by step 2.1. Hence there is exactly one such field.

step 2.1step 2.2L5

Remarks

  • Which field it is, is a different question. The argument counts intermediate fields; it produces no generator of the one it counts, and no claim is made here about identifying it. Naming that field concretely requires a computation this proof does not carry out.

  • Oddness is needed. At p=2 the field Q(μ2) is Q itself, of degree φ(2)=1, and it has no intermediate field of degree two at all; the step that fails is step 2.1, where p1=1 is odd.

TheoremStatement: Literature-sourcedProof: AI-adaptedprecheck passaudited 2026-08-26Open item page →

For every n1 there are infinitely many primes p with p1(modn)

Statement

Facts & Assumptions

[L2]

Φn(0)=1 for every n2 (Φ1(0)=1 and Φn(0)=1 for n2).

[L7]

A nonzero polynomial of degree k over an integral domain has at most k distinct roots in it (A nonzero polynomial of degree n over an integral domain has at most n distinct roots).

Proof

technique · cases
1.1

In the case n=1, every integer is congruent to 1 modulo 1, since 1 divides every integer, so T1 is the set of all primes, which is not finite by [L8].

assume-case oneL8given
1.2

In the case n2, let STn be any finite set and put M:=npSp, an integer with M2; the goal is to produce a prime in Tn outside S.

assume-case biggiven
2.1

There is an integer k1 with Φn(kM)>1: the three polynomials Φn, Φn1 and Φn+1 are nonzero of degree φ(n)1 by [L1], so by [L7] over the integral domain Z at most 3φ(n) integers x satisfy Φn(x){1,0,1}; the integers M,2M,3M, are pairwise distinct, so some kM with k1 avoids that finite set.

step 1.2L1L7
2.2

Since Φn(0)=1 by [L2], there is hZ[t] with Φn=1+th; evaluating at kM gives N:=Φn(kM)=1+kMh(kM).

step 1.2L1L2given
3.1

By step 2.1 the integer N exceeds 1, so it has a prime divisor p by [L6], and pN. That prime does not divide kM: otherwise p would divide kMh(kM) and hence NkMh(kM)=1, which is impossible for a prime. In particular pM, so pn and pS, both n and every member of S dividing M.

step 2.1step 2.2L6given
4.1

Reduce modulo p. Since pΦn(kM), the class α:=[kM]p is a root of the image of Φn in (Z/p)[t], and α0 because pkM by step 3.1. Let E be a splitting field of tn1 over Z/p, which exists by [L4]; as char(Z/p)=p does not divide n, [L3] applies and α, lying in Z/pE, has order exactly n in E×.

step 3.1L3L4
5.1

The order of α in the subgroup (Z/p)× of E× is the same n, so n divides (Z/p)×=p1 by [L5]; that is p1(modn), so pTn and pS.

step 3.1step 4.1L5given
6.1

In the case n2, then, no finite subset of Tn exhausts it, so Tn is not finite; with step 1.1 the two cases are exhaustive and cover every n1.

step 1.1step 5.1cases-exhaustive

Remarks

  • What replaces the archimedean estimate. The usual proof chooses x large enough that Φn(x)>1 by a growth estimate. Step 2.1 replaces that by a root count, which needs no order structure on Z beyond the distinctness of the multiples of M, and gives exactly the same conclusion.

  • The case n=1 is not a degenerate instance. For n=1 one has Φ1(0)=1, not 1 (Φ1(0)=1 and Φn(0)=1 for n2), so step 2.2 is unavailable; the congruence is vacuous there and the statement is Euclid's theorem.

LemmaStatement: Literature-sourcedProof: AI-generatedprecheck passaudited 2026-08-26Open item page →

Every finite abelian group is a quotient of (Z/n)k for some n and k

Statement

For every finite abelian group G there are positive integers n and k and a surjective group homomorphism

(Z/n)kG,

where (Z/n)k denotes the set of k-tuples of classes in Z/n, with componentwise addition, for the additive group Z/n (The congruence class [a]n and the quotient set Z/n, For every natural n, (Z/n,+) is an abelian group, multiplication is a commutative monoid operation, and both distributive laws hold). Equivalently, G(Z/n)k/H for a subgroup H (The quotient group G/N and coset product (gN)(hN)=ghN, First isomorphism theorem for groups: G/kerfimf).

Facts & Assumptions

Given: A finite abelian group G.

[L1]

For every finite abelian group G there is a unique list 1<n1n2nr with GCn1××Cnr; the trivial group corresponds to the empty list (Fundamental theorem of finite abelian groups: invariant-factor form, Invariant-factor data for a finite abelian group).

[L2]

A cyclic group of finite order m is isomorphic to (Z/m,+) (Every cyclic group is isomorphic to (Z,+) or to (Z/n,+) for its finite order n1).

[L4]

For a homomorphism f:AB, the rule akerff(a) is an isomorphism A/kerfimf (First isomorphism theorem for groups: G/kerfimf, The quotient group G/N and coset product (gN)(hN)=ghN).

Proof

technique · cases
1.1

In the case that the invariant-factor list of [L1] is empty, G is trivial; take n=1 and k=1, so that (Z/1)1 is a one-element group and the unique map to G is a surjective homomorphism.

assume-case trivialL1
1.2

In the case r1, put n:=nr and k:=r. Each ni divides n, the list being a divisibility chain by [L1].

assume-case nontrivialL1
2.1

For each i the rule [a]n[a]ni is a well-defined surjective group homomorphism Z/nZ/ni: if [a]n=[b]n then nab, hence niab because nin, so [a]ni=[b]ni by [L3]; it respects addition by [L3]; and every class [a]ni is the image of [a]n.

step 1.2L3
3.1

Let P:=(Z/n)r and Q:=(Z/n1)××(Z/nr), both with componentwise addition. By [L3] each coordinate (Z/n,+) and (Z/ni,+) is an abelian group, so P and Q are abelian groups under these coordinatewise operations. Define π ⁣:PQ by π([a1]n,,[ar]n):=([a1]n1,,[ar]nr). Step 2.1 gives each coordinate map Z/nZ/ni as a well-defined surjective homomorphism, so π is a well-defined surjective group homomorphism. Fact [L2] identifies each coordinate group (Z/ni,+) with Cni, and [L1] identifies Cn1××Cnr with G up to isomorphism. Composing with that isomorphism gives a surjective homomorphism (Z/n)kG.

step 1.2step 2.1L1L2L3
4.1

The two cases are exhaustive, the invariant-factor list being empty or not, so such n and k exist for every finite abelian G; and [L4] turns any such surjection into an isomorphism G(Z/n)k/H with H its kernel.

step 1.1step 3.1L4cases-exhaustive

Remarks

  • Why the invariant-factor form is convenient. The invariant factors form a divisibility chain, so the single modulus n=nr works immediately. A primary decomposition also proves the statement: take n to be the least common multiple of the finitely many prime-power orders and reduce Z/n onto each cyclic factor. The invariant-factor form simply avoids that extra choice of modulus.
TheoremStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

Every finite abelian group is the Galois group of some finite Galois extension of Q

Statement

For every finite abelian group G there is a finite Galois extension L/Q (Finite Galois extensions and Gal(K/F)) with

Gal(L/Q)G,

and L may be taken inside a cyclotomic field Q(μN) (The cyclotomic extension K(μn) as a splitting field of tn1).

Facts & Assumptions

[L1]

There are positive integers n,k and a surjective group homomorphism (Z/n)kG (Every finite abelian group is a quotient of (Z/n)k for some n and k, The external direct product G×H with componentwise multiplication).

[L5]

A cyclic group of finite order m is isomorphic to (Z/m,+) (Every cyclic group is isomorphic to (Z,+) or to (Z/n,+) for its finite order n1).

[L7]

For K/Q finite Galois with group G and HG, the field KH is an intermediate field (The fundamental theorem of finite Galois theory); it is Galois over Q exactly when H is normal (Normal subgroup: invariance under conjugation), and then Gal(KH/Q)G/H (Normal subgroups, conjugate fields, and quotient groups in the Galois correspondence, The quotient group G/N and coset product (gN)(hN)=ghN).

[L8]

For a homomorphism f:AB the rule akerff(a) is an isomorphism A/kerfimf (First isomorphism theorem for groups: G/kerfimf).

Proof

technique · direct
1.1

Fix n,k1 and a surjection π ⁣:(Z/n)kG by [L1].

L1
2.1

Choose pairwise distinct primes p1,,pk with pi1(modn): the set of such primes is not finite by [L2], so at each of the k steps one may pick a prime outside the finitely many already chosen. Put N:=p1pk.

step 1.1L2
3.1

Distinct primes are coprime: a positive common divisor of pi and pj is 1 or pi, and is 1 or pj, so if it is not 1 then pi=pj. Hence p1,,pk is a pairwise-coprime list.

step 2.1givenalgebra
3.2

For each i there is a surjective homomorphism (Z/pi)×Z/n: by [L4] the group (Z/pi)× is cyclic of order mi=pi1, which n divides by step 2.1; [L5] identifies it with (Z/mi,+), and [a]mi[a]n is well defined because nmi, is a homomorphism, and is onto.

step 2.1L4L5
4.1

By [L3] the map [x]N([x]pi)i is a bijection Z/NiZ/pi preserving multiplication and [1], so it carries units to units bijectively and restricts to a group isomorphism (Z/N)×i(Z/pi)×.

step 3.1L3
5.1

Taking the product of the maps of step 3.2 and composing with step 4.1 and with π gives a surjective group homomorphism Ψ0 ⁣:(Z/N)×G; composing with the isomorphism of [L6] gives a surjective homomorphism Ψ ⁣:Gal(Q(μN)/Q)G.

step 1.1step 4.1step 3.2L6
6.1

Put G:=Gal(Q(μN)/Q) and H:=kerΨ. The group G is abelian by [L6], so every subgroup is normal, gHg1=H holding for all g; hence L:=Q(μN)H is an intermediate field, L/Q is finite Galois, and Gal(L/Q)G/H by [L7].

step 5.1L6L7
7.1

By [L8] applied to Ψ, which is surjective, G/HimΨ=G; hence Gal(L/Q)G, with L inside Q(μN).

step 5.1step 6.1L8

Remarks

  • What is produced is a subfield, not a cyclotomic field. The construction realises G as the Galois group of an intermediate field of Q(μN)/Q, and it must: the Galois group of Q(μN) itself is (Z/N)×, whose order φ(N) is even for N3, so most finite abelian groups are not of that form. The companion page spells out that failure in FALSE: every finite abelian group is Gal(Q(μn)/Q) for some n .

  • The distinctness of the primes is needed twice. It makes the list pairwise coprime so that the Chinese remainder theorem applies, and it makes the product N have exactly the intended unit group. Repeating a prime would collapse two factors into one.

PropositionStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

Every intermediate field of Q(μn)/Q is Galois over Q with abelian Galois group

Statement

Let n1 and let F be an intermediate field of Q(μn)/Q (The cyclotomic extension K(μn) as a splitting field of tn1). Then F/Q is a finite Galois extension (Finite Galois extensions and Gal(K/F)) and Gal(F/Q) is abelian.

Facts & Assumptions

Given: An integer n1 and an intermediate field QFQ(μn); Q is an ordered field (The rationals form a totally ordered field), so charQ=0 (The characteristic of a ring: the least n1 with n1R=0 when one exists, and 0 otherwise) and divides no positive integer (Divisibility in Z: da when a=dq for some integer q). Write G:=Gal(Q(μn)/Q).

[L2]

For K/F0 finite Galois with group G, the maps HKH and EGal(K/E) are mutually inverse bijections between subgroups of G and intermediate fields (The fundamental theorem of finite Galois theory).

[L3]

With K/F0 finite Galois, G=Gal(K/F0), HG and E=KH: the extension E/F0 is Galois exactly when H is normal in G (Normal subgroup: invariance under conjugation), and then restriction gives Gal(E/F0)G/H (Normal subgroups, conjugate fields, and quotient groups in the Galois correspondence, The quotient group G/N and coset product (gN)(hN)=ghN).

Proof

technique · direct
1.1

By [L1] the extension Q(μn)/Q is finite Galois and G is abelian.

L1
2.1

By [L2] there is a subgroup HG with F=Q(μn)H.

step 1.1L2
3.1

Since G is abelian, gHg1=H for every gG, so H is normal in G; hence F/Q is Galois and Gal(F/Q)G/H by [L3].

step 1.1step 2.1L3
4.1

A quotient of an abelian group is abelian, since the images of two commuting elements commute and every element of G/H is such an image; so Gal(F/Q) is abelian.

step 1.1step 3.1L3

Remarks

RemarkRemark: Literature-sourcedProof: Not supplied sources checked 2026-08-26 not proved hereOpen item page →
Recorded, not proved here. This statement is included so the library can refer to it honestly, with a citation to the literature. It is not proved anywhere in this library: the track that would prove it has not been developed here yet.

Recorded, not proved: every finite abelian extension of Q lies in a cyclotomic field

Statement

Kronecker–Weber theorem. Let L/Q be a finite Galois extension whose Galois group is abelian. Then there is an integer n1 with

LQ(μn)

(The cyclotomic extension K(μn) as a splitting field of tn1).

The statement fails over larger base fields. Over K=Q(i) the extension obtained by adjoining a fourth root of 1+i is abelian over K and is contained in no cyclotomic extension of K.

Remarks

What this library does prove. The converse half is Every intermediate field of Q(μn)/Q is Galois over Q with abelian Galois group: every intermediate field of Q(μn)/Q is Galois over Q with abelian Galois group. Together with [Q(ζn):Q]=φ(n) and Gal(Q(μn)/Q)(Z/n)×, which computes Gal(Q(μn)/Q) exactly, that half says the subfields of cyclotomic fields are abelian; Kronecker–Weber says there are no others.

What would prove it, and which track that belongs to. The standard argument reduces the global statement to a local one at each prime that ramifies in L, and then analyses the higher ramification groups of the p-adic rationals to show that the local extension is contained in a local cyclotomic extension. Every ingredient of that reduction — valuations, local fields, the ring of integers of a number field, decomposition and inertia groups — belongs to algebraic number theory, and none of it is developed anywhere in this library. An alternative route through class field theory needs strictly more. Neither source consulted here proves the theorem: Conrad calls it deep and states it without proof, and Milne states it only in a footnote to an exercise.

Why it is recorded rather than omitted. The arithmetic consequences of the theorem are stated elsewhere in terms of it, so a page that builds the cyclotomic machinery and then says nothing about its sharpest classical application would leave that seam pointing at nothing. Recording it with the fuchsia not-proved-here marking is the honest form: the reader is told, at the point of contact, that the proof belongs to a later algebraic-number-theory track.

5 · Examples, counterexamples and false statements

ExampleConstruction: AI-adaptedVerification: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

Gal(F8/F2) is cyclic of order three with no proper intermediate field

Example

Let K:=F2[t]/(t3+t+1) and let α be the class of t. Then K is a field of order 8, the squaring map σ(x)=x2 generates

Gal(K/F2)={id,σ,σ2},

cyclic of order three, its two orbits on KF2 are

{α, α2, α2+α}and{α+1, α2+1, α2+α+1},

and K/F2 has no intermediate field other than F2 and K.

Facts & Assumptions

Given: The polynomial π:=t3+t+1F2[t], the ring K=F2[t]/(π) and the class α of t, so that α3=α+1 because α3+α+1=0 and 1=1 in characteristic two.

[L1]

A polynomial of degree 2 or 3 over a field is irreducible if and only if it has no root in that field (A polynomial of degree two or three over a field is irreducible exactly when it has no root in the field).

[L2]

For a field F and nonconstant pF[x], p is irreducible if and only if F[x]/(p) is a field (For a nonconstant p in F[x], the ideal (p) is maximal and F[x]/(p) is a field exactly when p is irreducible).

[L3]

If a is algebraic over F with minimal polynomial ma of degree n, then F(a) has power basis 1,a,,an1 and [F(a):F]=n (A simple algebraic extension is its minimal-polynomial quotient and has power basis 1,a,,an1 and degree n, The degree [K:F]=dimFK of a finite field extension); a monic irreducible vanishing at a is that minimal polynomial (The evaluation kernel and the unique monic irreducible minimal polynomial of an algebraic element).

[L4]

An extension E/Fq of finite fields of degree n is Galois with Gal(E/Fq)=σq cyclic of order n, where σq(x)=xq, and E=qn (A finite extension of a finite field of order q is Galois with cyclic Galois group generated by xxq, The relative Frobenius xxq of an extension of finite fields, For a degree-n extension of a field of order q, the q-power map has order exactly n, Finite fields and their order).

[L5]

The intermediate fields of Fqn/Fq are the Fqd for the positive divisors d of n, one for each divisor (The intermediate fields of Fqn/Fq are the Fqd, one for each positive divisor d of n, Divisibility in Z: da when a=dq for some integer q).

Verification

technique · direct
1.1

π has no root in F2: π(0)=1 and π(1)=1+1+1=1. By [L1] it is irreducible, so K is a field by [L2].

L1L2given
2.1

π is monic irreducible with π(α)=0, so it is the minimal polynomial of α over F2 and [K:F2]=3 with power basis 1,α,α2 by [L3]; hence K=23=8 by [L4].

step 1.1L3L4
3.1

By [L4] the extension K/F2 is Galois with Galois group generated by σ(x)=x2 and of order three.

step 2.1L4
4.1

The orbit of α: α2 is α2; α4=αα3=α(α+1)=α2+α; and (α2+α)2=α4+α2=(α2+α)+α2=α, using that squaring is additive in characteristic two. So {α,α2,α2+α} is one orbit of size three.

step 2.1step 3.1given
5.1

The orbit of α+1: (α+1)2=α2+1, (α2+1)2=α4+1=α2+α+1, and (α2+α+1)2=α4+α2+1=α+1. So {α+1,α2+1,α2+α+1} is the other orbit of size three, and together with {0} and {1} these account for all eight elements.

step 2.1step 3.1step 4.1given
6.1

The positive divisors of three are 1 and 3, so by [L5] the intermediate fields are exactly two: F2 and K itself. There is no field strictly between them.

step 2.1step 3.1L5

Remarks

ExampleConstruction: AI-adaptedVerification: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

The intermediate fields of F212/F2 match the divisors of twelve

Example

Let E be a field with F2 as a subfield and [E:F2]=12, so that E=212. Its intermediate fields over F2 are exactly

F2,F22,F23,F24,F26,F212=E,

one for each of the six positive divisors 1,2,3,4,6,12 of twelve, with F2dF2e exactly when d divides e. Neither of F24 and F26 contains the other, and

F24F26=F22,F24F26=F212.

Facts & Assumptions

[L2]

The intermediate fields of Fqn/Fq are exactly the Fqd={x:xqd=x} for the positive divisors d of n, one for each divisor, with [Fqd:Fq]=d and FqdFqe if and only if de (The intermediate fields of Fqn/Fq are the Fqd, one for each positive divisor d of n).

[L3]

A field of order pm has, for each positive divisor e of m, exactly one subfield of order pe, namely {a:ape=a}, and these are all of its subfields (The subfields of Fpn are the unique fields Fpd for positive divisors d of n).

Verification

technique · direct
1.1

The positive divisors of twelve are 1,2,3,4,6,12, six in all, since a positive divisor d of 12 satisfies d12 and direct inspection of 1,,12 leaves exactly these.

givenalgebra
2.1

By [L1] and [L2] the intermediate fields of E/F2 are the F2d for those six d, one for each, with F2dF2e exactly when de.

step 1.1L1L2
3.1

Neither 46 nor 64, so by step 2.1 neither of F24 and F26 contains the other.

step 2.1given
4.1

Their intersection is an intermediate field of E/F2, being a subfield of E containing F2, so it is F2c for a unique divisor c of 12 by step 2.1; from F2cF24 and F2cF26 one gets c4 and c6, so [L4] gives cgcd(4,6)=2; and 24 and 26 put F22 inside both, so 2c. Hence c=2 and the intersection is F22.

step 2.1step 3.1L4
5.1

Their compositum is likewise an intermediate field F2c, and it contains both, so 4c and 6c by step 2.1. Thus [L4] gives lcm(4,6)=12c; since c12, c=12 and the compositum is E=F212.

step 2.1step 4.1L4
6.1

The same six fields are what [L3] produces for E, whose order is 212: its subfields are the {a:a2e=a} for the divisors e of 12, and these are the sets named in [L2]. So the Galois indexing and the elementary one agree here.

step 2.1step 5.1L2L3

Remarks

ExampleConstruction: Literature-sourcedVerification: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

The divisor-sum identity at q=2, n=3 finds exactly two monic irreducible cubics

Example

Over F2 the divisor-sum identity (dndNq(d)=qn for the counts Nq(d) of monic irreducibles of degree d over Fq) at n=3 reads

N2(1)+3N2(3)=23=8,

and N2(1)=2, so N2(3)=2. The two monic irreducible cubics in F2[t] are

t3+t+1andt3+t2+1.

Facts & Assumptions

Given: The field F2 with two elements and the counts N2(d) of monic irreducible polynomials of degree d in F2[t] (Degree, leading coefficient and monic polynomial, with the zero polynomial having no degree).

[L2]

A polynomial of degree 2 or 3 over a field is irreducible if and only if it has no root in that field (A polynomial of degree two or three over a field is irreducible exactly when it has no root in the field).

[L3]

For a commutative ring R, aR and fR[x]: f(a)=0 if and only if xa divides f (Factor theorem over a commutative ring, Evaluation and roots of a polynomial in a commutative target ring).

Verification

technique · direct
1.1

The monic polynomials of degree one in F2[t] are t and t+1, and each is irreducible, having degree one; so N2(1)=2.

givenalgebra
1.2

A monic cubic over F2 is f=t3+at2+bt+c with a,b,cF2, so there are eight of them. Such an f has no root in F2 exactly when f(0)=c0 and f(1)=1+a+b+c0, that is exactly when c=1 and a+b=1.

givenalgebra
2.1

The positive divisors of 3 are 1 and 3, so [L1] at q=2 and n=3 reads N2(1)+3N2(3)=8; with step 1.1 this gives 3N2(3)=6 and N2(3)=2.

step 1.1L1algebra
3.1

The pairs (a,b) with a+b=1 in F2 are (0,1) and (1,0), so exactly two monic cubics have no root in F2, namely t3+t+1 and t3+t2+1; by [L2] these two are irreducible and by [L2] and [L3] the other six are not, each having a root and hence a linear factor. This agrees with the count N2(3)=2 of step 2.1.

step 2.1step 1.2L2L3algebra

Remarks

  • The identity is a recursion, not a formula. It determines N2(3) only because N2(1) is already known; at n=4 it would read N2(1)+2N2(2)+4N2(4)=16 and would need N2(2) first.
ExampleConstruction: Literature-sourcedVerification: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

The four roots of t4+t+1 over F2 are the Frobenius powers of any one of them

Example

Let K:=F2[t]/(t4+t+1) and let α be the class of t, so α4=α+1. Then K is a field of order 16, and the four conjugates of α over F2,

α,α2,α4=α+1,α8=α2+1,

are pairwise distinct, are exactly the roots of t4+t+1 in K, and satisfy α16=α, so the Frobenius orbit closes at length four.

Facts & Assumptions

Given: The polynomial π:=t4+t+1F2[t], the ring K=F2[t]/(π), and the class α of t, so α4=α+1 since 1=1 in characteristic two; squaring is additive there.

[L1]

A polynomial of degree 2 or 3 over a field is irreducible if and only if it has no root in that field (A polynomial of degree two or three over a field is irreducible exactly when it has no root in the field).

[L2]

f(a)=0 if and only if xa divides f (Factor theorem over a commutative ring); and over an integral domain deg(fg)=degf+degg for nonzero f,g (Over an integral domain, degrees add under multiplication of nonzero polynomials, Degree, leading coefficient and monic polynomial, with the zero polynomial having no degree).

[L3]

For a field F and nonconstant pF[x], p is irreducible if and only if F[x]/(p) is a field (For a nonconstant p in F[x], the ideal (p) is maximal and F[x]/(p) is a field exactly when p is irreducible).

[L6]

A monic irreducible π of degree d over Fq with a root α has the d distinct roots α,αq,,αqd1 and π=i<d(tαqi) (A monic irreducible of degree d over Fq has the d distinct roots α,αq,,αqd1).

Verification

technique · direct
1.1

π has no root in F2, since π(0)=1 and π(1)=1+1+1=1; so by [L2] it has no factor of degree one.

L2given
1.2

The only monic irreducible quadratic in F2[t] is t2+t+1: the four monic quadratics are t2, t2+1, t2+t and t2+t+1, and the first three have the root 0, 1 and 0 respectively, so [L1] leaves only the last.

L1L2given
2.1

π is irreducible. A factorisation of π into two nonconstant factors has degrees summing to four by [L2], so it is either 1+3, excluded by step 1.1, or 2+2; and every monic quadratic factor would have to be irreducible, hence equal to t2+t+1 by step 1.2, giving π=(t2+t+1)2=t4+t2+1, which is not π.

step 1.1step 1.2L2given
3.1

By [L3] the ring K is a field; π is monic irreducible with π(α)=0, so [K:F2]=4 with power basis 1,α,α2,α3 by [L4], and K=24=16 by [L5].

step 2.1L3L4L5
4.1

Compute the conjugates in that basis: α4=α+1 by hypothesis, and α8=(α4)2=(α+1)2=α2+1. So the four elements α,α2,α4,α8 have coordinate lists (0,1,0,0), (0,0,1,0), (1,1,0,0) and (1,0,1,0), which are pairwise different, so the four elements are pairwise distinct.

step 3.1given
5.1

α16=(α8)2=(α2+1)2=α4+1=(α+1)+1=α, so the orbit closes after four steps.

step 4.1given
6.1

By [L6] applied to π, of degree four, the elements α,α2,α4,α8 are exactly the roots of π and π=(tα)(tα2)(tα4)(tα8) in K[t]; steps 4.1 and 5.1 verify the distinctness and the closing of the orbit directly.

step 2.1step 4.1step 5.1L6
ExampleConstruction: AI-generatedVerification: AI-generatedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

A normal basis of F8 over F2

Example

Let K:=F2[t]/(t3+t+1), a field of order 8, let α be the class of t, and let σ(x)=x2 generate Gal(K/F2). Put

β:=α+1.

Then the conjugate list

(β, β2, β4)=(α+1, α2+1, α2+α+1)

is a normal basis of K over F2 (Normal bases of a finite Galois extension).

Not every element works. The generator α itself does not: its conjugate list is (α,α2,α2+α), whose three members sum to 0, so they are linearly dependent over F2 and are not a basis.

Facts & Assumptions

Given: The field K=F2[t]/(t3+t+1) with α the class of t, so α3=α+1 and α4=α2+α; squaring is additive in characteristic two.

[L4]

For a linear map T:VW with V finite-dimensional, dimV=dimkerT+dimimT (Rank-nullity: dimFV=nullityT+rankT).

[L5]

Every finite Galois extension with cyclic Galois group has a normal basis (Every finite cyclic extension has a normal basis).

Verification

technique · direct
1.1

By [L1] and [L2] the space K is a three-dimensional F2-vector space with basis 1,α,α2, and Gal(K/F2)={id,σ,σ2} acts by xx, x2, x4.

L1L2
2.1

The conjugate list of α is (α,α2,α4) with α4=αα3=α(α+1)=α2+α; hence α+α2+α4=α+α2+α2+α=0. A vanishing combination with all coefficients 1 is nontrivial, so this list is linearly dependent over F2 and is not a basis.

step 1.1L3given
3.1

The conjugates of β=α+1 are β, β2=(α+1)2=α2+1 and β4=(β2)2=(α2+1)2=α4+1=α2+α+1.

step 1.1step 2.1given
4.1

The seven nonzero F2-combinations of β,β2,β4 are nonzero: the three single terms are α+1, α2+1 and α2+α+1; the three pairwise sums are β+β2=α2+α, β+β4=α2 and β2+β4=α; and the total sum is β+β2+β4=1. None of these seven is 0, as each has a nonzero coordinate list in the basis 1,α,α2.

step 1.1step 3.1given
5.1

So the F2-linear map T ⁣:F23K sending (c1,c2,c3) to c1β+c2β2+c3β4 has trivial kernel by step 4.1; both spaces have dimension three by step 1.1, so [L4] makes T surjective as well, hence bijective, and [L3] makes (β,β2,β4) an ordered basis of K over F2.

step 1.1step 4.1L3L4
6.1

That list is the family of conjugates of β under Gal(K/F2) by step 3.1, so it is a normal basis, as [L5] guarantees exists for this cyclic extension.

step 3.1step 5.1L2L5

Remarks

  • A conjugate family of the right size can still fail. The list (α,α2,α4) has three distinct members and is a single Galois orbit, yet it is not a basis; what fails is independence, not the orbit condition. The normal basis theorem asserts that some element works, never that every element does (FALSE: every basis of a finite field over a subfield is a normal basis).
ExampleConstruction: Literature-sourcedVerification: AI-adaptedprecheck passaudited 2026-08-26Open item page →

{1+i,1i} is a normal basis of C/R while {1,i} is not

Example

The extension C/R (The complex numbers as R[x]/(x2+1), with the real embedding and imaginary unit i) is finite Galois of degree two with Gal(C/R)={id, zz} (Real and imaginary parts, complex conjugation, and modulus). For it:

  1. the conjugate list (1+i, 1i) is a normal basis (Normal bases of a finite Galois extension);
  2. (1,i) is an R-basis of C that is not a conjugate list of any element;
  3. (i,i) is the conjugate list of i but is not a basis.

The last two show that the two conditions in the definition of a normal basis are independent of each other.

Facts & Assumptions

Given: The complex field with i2=1 and conjugation a+bi=abi for a,bR (Real and imaginary parts, complex conjugation, and modulus); in R one has 20.

[L1]

C=R(i) is a simple algebraic extension with power basis 1,i and [C:R]=2 (C/R has power basis 1,i and degree 2, The degree [K:F]=dimFK of a finite field extension).

[L2]

Every field automorphism of C fixing R pointwise is either the identity or complex conjugation, and these two are distinct (The only real-field automorphisms of C are the identity and complex conjugation, Relative field automorphisms and Aut(K/F)).

[L4]

A finite extension K/F with G=Aut(K/F) is Galois exactly when G=[K:F] (Equivalent characterizations of a finite Galois extension, Finite Galois extensions and Gal(K/F)).

[L6]

Every finite Galois extension of an infinite field has a normal basis (Every finite Galois extension of an infinite field has a normal basis).

Verification

technique · direct
1.1

By [L2] and [L3] the group Aut(C/R) has exactly the two elements id and conjugation, so its order is 2=[C:R] by [L1]; hence C/R is finite Galois with that Galois group by [L4].

L1L2L3L4
2.1

The conjugate list of 1+i is (1+i, 1i), whose members have coordinate lists (1,1) and (1,1) in the ordered basis (1,i) of [L1]. For a,bR, a(1+i)+b(1i)=(a+b)+(ab)i vanishes exactly when a+b=0 and ab=0, hence when 2a=0, that is a=0 and then b=0.

step 1.1L1given
2.2

(1,i) is a basis by [L1], but no zC has conjugate list (z,z) with underlying set {1,i}: such a z would lie in {1,i}, and the set for z=1 is {1} while for z=i it is {i,i}, neither of which is {1,i}.

step 1.1L1given
3.1

So the linear map R2C sending (a,b) to a(1+i)+b(1i) has trivial kernel; both spaces have dimension two by [L1], so [L5] makes it bijective and (1+i,1i) an ordered R-basis of C. Being the conjugate list of 1+i, it is a normal basis, in agreement with [L6].

step 1.1step 2.1L1L5L6
4.1

(i,i) is the conjugate list of i, since i=i, and its two members are distinct; but 1i+1(i)=0 is a vanishing combination with nonzero coefficients, so the list is not independent and by [L5] is not a basis. With steps 3.1 and 2.2 this establishes all three claims.

step 1.1step 3.1step 2.2L5given
False statementConstruction: AI-adaptedVerification: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

FALSE: every basis of a finite field over a subfield is a normal basis

Statement

False claim. For every extension E/Fq of finite fields, every Fq-basis of E is a normal basis (Normal bases of a finite Galois extension).

Facts & Assumptions

Given: The ring L:=F2[t]/(t2+t+1) with α the class of t, so that α2=α+1 because α2+α+1=0 and 1=1 in characteristic two.

[L1]

A polynomial of degree 2 or 3 over a field is irreducible if and only if it has no root in that field (A polynomial of degree two or three over a field is irreducible exactly when it has no root in the field); and F[x]/(p) is a field exactly when p is irreducible (For a nonconstant p in F[x], the ideal (p) is maximal and F[x]/(p) is a field exactly when p is irreducible).

[L4]

A normal basis of K/F is an ordered F-basis of the form (σ1γ,,σnγ) for a single γK, indexed by Gal(K/F) (Normal bases of a finite Galois extension).

[L5]

Every finite Galois extension has a normal basis (Every finite Galois extension has a normal basis).

Refutation

technique · direct
1.1

t2+t+1 has no root in F2, its values at 0 and 1 both being 1, so it is irreducible and L is a field by [L1]; it is the minimal polynomial of α, so [L:F2]=2 with ordered basis (1,α) by [L2], and L has four elements 0,1,α,α+1.

L1L2given
2.1

By [L3] the extension L/F2 is Galois with Gal(L/F2)={id,σ}, where σ(x)=x2.

step 1.1L3
3.1

The conjugate lists of the four elements are (0,0), (1,1), (α,α+1) and (α+1,α), using α2=α+1 and (α+1)2=α2+1=α. Their underlying sets are {0}, {1} and {α,α+1}.

step 1.1step 2.1given
4.1

The list (1,α) is an F2-basis of L by step 1.1, but its underlying set {1,α} is none of the three sets in step 3.1, so it is not the conjugate list of any element and hence is not a normal basis by [L4]. The false claim therefore fails already for L/F2.

step 1.1step 3.1L4
5.1

What is true is the existential statement: some element of L generates a normal basis, and α does, since (α,α+1) is a list of two distinct elements whose only vanishing F2-combinations are trivial, as α0, α+10 and α+(α+1)=10. That is the content of [L5], which asserts existence and never universality.

step 3.1step 4.1L4L5

Remarks

  • Where the false claim comes from. The normal basis theorem is an existence statement, and its proofs single out an element by a nonvanishing condition — a determinant in the infinite case, a cyclic vector in the finite case. Both conditions genuinely exclude some elements, as A normal basis of F8 over F2 shows over F8.
ExampleConstruction: AI-adaptedVerification: AI-adaptedprecheck passaudited 2026-08-26Open item page →

Φ1 through Φ12 computed from the divisor recursion

Example

Running the recursion of The cyclotomic polynomials ΦnZ[t], defined by dnΦd=tn1 gives

Φ1=t1,Φ2=t+1,Φ3=t2+t+1,Φ4=t2+1,Φ5=t4+t3+t2+t+1,Φ6=t2t+1,Φ7=t6+t5+t4+t3+t2+t+1,Φ8=t4+1,Φ9=t6+t3+1,Φ10=t4t3+t2t+1,Φ11=k=010tk,Φ12=t4t2+1,

each monic in Z[t], with degrees

1, 1, 2, 2, 4, 2, 6, 4, 6, 4, 10, 4

matching φ(1),,φ(12) (The unit group (Z/n)× and Euler's totient φ(n)=(Z/n)× for n1).

Facts & Assumptions

Given: The recursion Φ1=t1 and Φn=(tn1)/dn,d<nΦd (The cyclotomic polynomials ΦnZ[t], defined by dnΦd=tn1, The sum iSai over a finite index set, and its product form, Divisibility in Z: da when a=dq for some integer q); and the elementary identity (ta1)(ta(b1)++ta+1)=tab1 for a,b1.

[L1]

For every n1, Φn is monic in Z[t] with dnΦd=tn1 and degΦn=φ(n) (The recursion defines a unique monic ΦnZ[t], of degree φ(n), Degree, leading coefficient and monic polynomial, with the zero polynomial having no degree).

[L2]

For a prime p and r1, Φpr=k=0p1tkpr1 (Φpr(t)=k<ptkpr1, and Φpr(t+1) is Eisenstein at p).

[L3]

Z[t] is an integral domain (A polynomial ring over an integral domain is an integral domain), so a nonzero factor may be cancelled; and division by a monic polynomial has a unique quotient and remainder (Division by a monic polynomial over a commutative ring).

[L4]

φ(1)=1 and φ(p)=p1 for a prime p (φ(1)=1, and φ(p)=p1 for every prime p); φ(pk)=pkpk1 (For a prime p and k1, φ(pk)=pkpk1); and for n1 with prime divisors p0,,pr1 and ki=vpi(n), φ(n)=i<r(pikipiki1) (Euler's product formula φ(n)=npn(11/p)=pkn(pkpk1) for n1, stated through a finite injective list of its prime divisors).

Verification

technique · direct
1.1

Φ1=t1 is the base clause of the recursion, of degree 1=φ(1) by [L4].

L4given
1.2

The prime powers among 2,,12 are 2,3,4,5,7,8,9,11, and [L2] gives their cyclotomic polynomials directly: Φ2=1+t, Φ3=1+t+t2, Φ4=1+t2, Φ5=1+t+t2+t3+t4, Φ7=k=06tk, Φ8=1+t4, Φ9=1+t3+t6 and Φ11=k=010tk.

L2
2.1

For n=6: the positive divisors of 6 are 1,2,3,6 and those of 3 are 1,3, so [L1] gives Φ1Φ2Φ3Φ6=t61 and Φ1Φ3=t31; dividing and using the given identity with a=3, b=2 yields Φ2Φ6=(t61)/(t31)=t3+1. Since (t+1)(t2t+1)=t3+1 and Φ2=t+1 is nonzero, cancelling in Z[t] by [L3] gives Φ6=t2t+1.

step 1.2L1L3given
2.2

For n=10: the divisors of 10 are 1,2,5,10 and those of 5 are 1,5, so Φ2Φ10=(t101)/(t51)=t5+1 by [L1] and the given identity with a=5, b=2; and (t+1)(t4t3+t2t+1)=t5+1, so cancelling gives Φ10=t4t3+t2t+1.

step 1.2L1L3given
3.1

For n=12: the divisors of 12 are 1,2,3,4,6,12 and those of 6 are 1,2,3,6, so Φ4Φ12=(t121)/(t61)=t6+1 by [L1] and the given identity with a=6, b=2; and (t2+1)(t4t2+1)=t6+1 with Φ4=t2+1, so cancelling gives Φ12=t4t2+1.

step 1.2step 2.1L1L3given
4.1

The degrees read off the displayed polynomials are 1,1,2,2,4,2,6,4,6,4,10,4. By [L4] these are φ(1)=1, φ(2)=1, φ(3)=2, φ(4)=222=2, φ(5)=4, φ(6)=(21)(31)=2, φ(7)=6, φ(8)=2322=4, φ(9)=323=6, φ(10)=(21)(51)=4, φ(11)=10 and φ(12)=(222)(31)=4, so every degree matches [L1].

step 1.1step 1.2step 2.1step 2.2step 3.1L1L4

Remarks

ExampleConstruction: Literature-sourcedVerification: Literature-sourcedprecheck passaudited 2026-08-26Open item page →

Φ7(t+1) is Eisenstein at seven

Example

The translated seventh cyclotomic polynomial is

Φ7(t+1)=t6+7t5+21t4+35t3+35t2+21t+7.

Its leading coefficient is 1, every other coefficient is divisible by 7, and its constant term 7 is not divisible by 72. So it satisfies Eisenstein's criterion at the prime 7, and therefore Φ7 is irreducible over Q.

Facts & Assumptions

Given: The prime-power cyclotomic formula and the polynomial Φ7.

[L1]

For a prime p and r1, Φpr(t)=k=0p1tkpr1, and Φpr(t+1) is Eisenstein at p (Φpr(t)=k<ptkpr1, and Φpr(t+1) is Eisenstein at p).

[L2]

Eisenstein's criterion: if a prime p divides every non-leading coefficient of a polynomial in Z[t], does not divide the leading coefficient, and p2 does not divide the constant term, then the polynomial is irreducible over Q (Eisenstein criterion over the integers).

Verification

technique · direct
1.1

Applying [L1] at p=7 and r=1 gives Φ7(t)=1+t+t2+t3+t4+t5+t6.

L1
2.1

Therefore Φ7(t+1)=(t+1)71t=t6+7t5+21t4+35t3+35t2+21t+7, by the binomial theorem.

step 1.1algebra
3.1

In the polynomial of step 2.1 the leading coefficient is 1, the remaining coefficients 7,21,35,35,21,7 are all divisible by 7, and the constant term 7 is not divisible by 49; so [L2] applies at the prime 7.

step 2.1L2algebra
4.1

Hence Φ7(t+1) is irreducible over Q, and this is exactly the degree-one prime-power case of [L1].

step 3.1L1

Remarks

  • Why this example matters later. The explicit coefficients are what the counterexample page uses when it says the Eisenstein route already proves irreducibility for prime-power cyclotomic polynomials before the general Dedekind argument is built.
ExampleConstruction: Literature-sourcedVerification: Literature-sourcedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

Φ5 has four roots in F11

Example

Over F11 the fifth cyclotomic polynomial

Φ5(t)=t4+t3+t2+t+1

splits into four distinct linear factors:

Φ5(t)=(t3)(t4)(t5)(t9).

The four roots 3,4,5,9 are exactly the primitive fifth roots of unity in F11.

Facts & Assumptions

Given: The field F11 and the polynomial Φ5(t)=t4+t3+t2+t+1.

[L1]

If gcd(n,q)=1, the reduction of Φn in Fq[t] is a product of distinct monic irreducibles, each of degree the order of [q] modulo n (For gcd(n,q)=1 the reduction of Φn in Fq[t] is a product of distinct monic irreducibles, each of degree the order of [q] modulo n).

[L2]

For gcd(n,q)=1, the image of Gal(Fq(μn)/Fq) in (Z/n)× is generated by [q], so the extension degree is the order of [q] modulo n (For gcd(n,q)=1 the image of Gal(Fq(μn)/Fq) in (Z/n)× is generated by [q]).

Verification

technique · direct
1.1

In (Z/5)× one has [11]=[1], so the order of [11] modulo 5 is 1. Hence [L1] and [L2] say every irreducible factor of Φ5 over F11 is linear, and the factors are distinct.

L1L2algebra
1.2

The powers of 3 in F11× are 32=9, 33=5, 34=4 and 35=1, so the four nontrivial fifth roots of unity in F11 are 3,9,5,4.

givenalgebra
2.1

Each of 3,4,5,9 is therefore a root of t51 and is not 1, so each is a root of Φ5(t)=(t51)/(t1). Since Φ5 is monic of degree 4, it follows that Φ5(t)=(t3)(t4)(t5)(t9).

step 1.2algebra
3.1

The roots 3,4,5,9 all have multiplicative order 5 by step 1.2, so they are exactly the primitive fifth roots of unity in F11.

step 1.2algebra

Remarks

  • This is the order-one case of the finite-field factorisation theorem. When [q] has order one modulo n, every irreducible factor has degree one and the whole cyclotomic polynomial splits over the base field.
ExampleConstruction: Literature-sourcedVerification: Literature-sourcedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

Φ7 factors over F2 into the two monic irreducible cubics

Example

Over F2 one has

Φ7(t)=t6+t5+t4+t3+t2+t+1=(t3+t+1)(t3+t2+1).

These are the two monic irreducible cubic factors, and over a splitting field the two factors correspond to the Frobenius orbits

{ζ,ζ2,ζ4}and{ζ3,ζ6,ζ5}

of a primitive seventh root of unity ζ.

Facts & Assumptions

Given: The field F2 and a primitive seventh root of unity ζ in a splitting field of Φ7.

[L1]

If gcd(n,q)=1, the reduction of Φn in Fq[t] is a product of distinct monic irreducibles, each of degree the order of [q] modulo n (For gcd(n,q)=1 the reduction of Φn in Fq[t] is a product of distinct monic irreducibles, each of degree the order of [q] modulo n).

[L2]

For gcd(n,q)=1, the image of Gal(Fq(μn)/Fq) in (Z/n)× is generated by [q] (For gcd(n,q)=1 the image of Gal(Fq(μn)/Fq) in (Z/n)× is generated by [q]).

[L3]

The roots of a monic irreducible polynomial of degree d over Fq are one Frobenius orbit α,αq,,αqd1 (A monic irreducible of degree d over Fq has the d distinct roots α,αq,,αqd1).

Verification

technique · direct
1.1

In (Z/7)× the class [2] has order 3, since 23=81(mod7) and 2≢1, 22=4≢1(mod7). So [L1] and [L2] say every irreducible factor of Φ7 over F2 is a distinct cubic.

L1L2algebra
2.1

The product of the two monic cubics is (t3+t+1)(t3+t2+1)=t6+t5+t4+t3+t2+t+1=Φ7(t) in F2[t]. Since both factors are monic of degree 3, step 1.1 makes them the two irreducible factors of Φ7.

step 1.1algebra
3.1

Frobenius acts by ζζ2, so the orbit of ζ is {ζ,ζ2,ζ4} because ζ8=ζ, and the orbit of ζ3 is {ζ3,ζ6,ζ5} because (ζ3)2=ζ6, (ζ6)2=ζ12=ζ5 and (ζ5)2=ζ10=ζ3. These are the two size-three Frobenius orbits of primitive seventh roots, and [L3] identifies them as the respective root sets of the two irreducible cubic factors from step 2.1.

step 1.1step 2.1L3algebra

Remarks

  • This is the degree-three case of the theorem, not a coincidence of cubics. The orbit size and the factor degree are both the order of [2] modulo 7.
ExampleConstruction: AI-generatedVerification: AI-generatedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

Gal(Q(ζ12)/Q)(Z/12)× and its three quadratic subfields

Example

Let ζ:=ζ12. Then

Gal(Q(ζ)/Q)(Z/12)×={[1],[5],[7],[11]},

every nonidentity element has order two, and the three order-two subgroups have fixed fields

Q(i),Q(3),Q(3).

So Q(ζ12) has exactly three quadratic intermediate fields.

Facts & Assumptions

Given: A primitive twelfth root of unity ζ=ζ12 and the automorphisms σa(ζ)=ζa for [a](Z/12)×.

[L1]

[Q(ζ12):Q]=φ(12)=4 and Gal(Q(ζ12)/Q)(Z/12)× ([Q(ζn):Q]=φ(n) and Gal(Q(μn)/Q)(Z/n)×).

[L2]

For a finite Galois extension E/F, subgroups of Gal(E/F) correspond bijectively to intermediate fields, and the fixed field of a subgroup H has degree [EH:F]=[Gal(E/F):H] (The fundamental theorem of finite Galois theory).

Verification

technique · direct
1.1

The units modulo 12 are [1],[5],[7],[11], since these are exactly the residue classes in {1,,11} coprime to 12. Their squares are [25]=[1], [49]=[1] and [121]=[1], so every nonidentity element has order two.

L1algebra
2.1

Therefore (Z/12)× is the Klein four-group, with three order-two subgroups: Hi={[1],[5]},H3={[1],[7]},H3={[1],[11]}. By [L1] and [L2], each fixed field has degree 2 over Q.

step 1.1L1L2
3.1

The subgroup Hi fixes i=ζ3, because σ5(ζ3)=ζ15=ζ3. Since iQ and the fixed field has degree 2 by step 2.1, that fixed field is Q(i).

step 2.1algebra
3.2

The subgroup H3 fixes 2ζ21, because σ7(ζ2)=ζ14=ζ2; and (2ζ21)2=4ζ44ζ2+1=3, since ζ2 is a root of t2t+1. So the fixed field contains 3, and again step 2.1 makes it exactly Q(3).

step 2.1algebra
3.3

The subgroup H3 fixes ζ+ζ1, because σ11 is complex conjugation. Moreover (ζ+ζ1)2=ζ2+2+ζ2=3, since ζ2+ζ2=1. So the fixed field contains 3, and step 2.1 makes it exactly Q(3).

step 2.1algebra
4.1

The three order-two subgroups of step 2.1 therefore yield the three quadratic intermediate fields Q(i), Q(3) and Q(3), and there are no others because [L2] gives a bijection between subgroups and intermediate fields.

step 2.1step 3.1step 3.2step 3.3L2

Remarks

  • The same phenomenon already occurs at order eight. The field Q(ζ8) also has Klein four Galois group and three quadratic subfields. The order-twelve calculation is useful because its three fields are the familiar Q(i), Q(3) and Q(3).
ExampleConstruction: AI-generatedVerification: AI-generatedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

In characteristic three, t31=(t1)3 and μ6 coincides with μ2

Example

Let K be a field of characteristic 3. Then

t31=(t1)3,μ3(K)={1},μ6(K)=μ2(K)={1,1},

so t61 has only the two distinct roots 1 and 1 rather than six.

Facts & Assumptions

Given: A field K of characteristic 3.

[L1]

For a fixed integer k1, in characteristic p the only pk-th root of unity is 1, and tpk1=(t1)pk (In characteristic p the only pk-th root of unity is 1, and tpk1=(t1)pk).

Verification

technique · direct
1.1

Applying [L1] at p=3 and k=1 gives t31=(t1)3 and μ3(K)={1}.

L1
1.2

Since (1)2=1 and (1)2=1, one has {1,1}μ2(K). Conversely, if xμ2(K) then x2=1, so x21=(x1)(x+1)=0 and therefore x=1 or x=1 in the field K; hence μ2(K)={1,1}.

L2algebra
2.1

If xμ6(K) then (x2)3=x6=1, so x2μ3(K) by [L2]; step 1.1 gives x2=1, hence xμ2(K) by [L2]. Thus μ6(K)μ2(K).

step 1.1step 1.2L2
2.2

Conversely, if xμ2(K) then x6=(x2)3=1, so xμ6(K). Therefore μ6(K)=μ2(K)={1,1}.

step 1.2L2algebra
3.1

Using step 1.1, t61=(t31)(t3+1)=(t1)3(t+1)3, so its only distinct roots are 1 and 1, exactly the two elements of step 2.2.

step 1.1step 2.2algebra

Remarks

  • This is why the characteristic hypothesis is load-bearing. The statement "μn=n" fails here for two different reasons at once: the polynomial t31 is inseparable, and the extra cube roots never appear even after passing to a splitting field because the splitting field is already the base field.
CounterexampleConstruction: Literature-sourcedVerification: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

F3(μ5)F3(μ7) is larger than F3 although five and seven are coprime

Statement refuted

That the rational intersection theorem Q(μm)Q(μn)=Q(μgcd(m,n)) holds over every base field: that for every field K and all positive integers m,n with the characteristic of K dividing neither,

K(μm)K(μn)=K(μgcd(m,n)).

The witness below takes K=F3, m=5 and n=7, and realizes both splitting fields inside one fixed field Ω of order 312. Since gcd(5,7)=1, the right-hand side is K(μ1)=F3, while the intersection on the left is the common subfield F9Ω.

Facts & Assumptions

Given: The base field K=F3 and a field Ω of order 312, which exists by For every prime p and n1, a field with pn elements exists. The two cyclotomic splitting fields will be identified with their base-field-isomorphic copies inside Ω.

[L1]

For gcd(n,q)=1, the image of Gal(Fq(μn)/Fq) in (Z/n)× is generated by [q], so the degree of Fq(μn)/Fq is the order of [q] modulo n (For gcd(n,q)=1 the image of Gal(Fq(μn)/Fq) in (Z/n)× is generated by [q]).

[L2]

The intermediate fields of FqN/Fq are exactly the Fqd for the positive divisors d of N, one for each divisor, with FqdFqe exactly when de (The intermediate fields of Fqn/Fq are the Fqd, one for each positive divisor d of n).

[L3]

Over Q one has Q(μm)Q(μn)=Q(μgcd(m,n)) (Q(μm)Q(μn)=Q(μgcd(m,n))).

[L4]

K(μr) is the splitting field of tr1 over K (The cyclotomic extension K(μn) as a splitting field of tn1).

[L5]

Finite fields of the same order are isomorphic by an isomorphism fixing their common prime field (Finite fields of the same order are isomorphic).

Counterexample

technique · direct
1.1

In (Z/5)×, the class [3] has order 4, since 34=811(mod5) and no smaller positive power of 3 is congruent to 1 modulo 5. So [L1] gives [F3(μ5):F3]=4, hence this splitting field has order 34 and [L5] lets us identify it over F3 with the unique subfield F34 of Ω.

L1L2L4L5algebra
1.2

In (Z/7)×, the powers of [3] are [3],[2],[6],[4],[5],[1], so [3] has order 6. Thus [L1] gives [F3(μ7):F3]=6, hence this splitting field has order 36 and [L5] lets us identify it over F3 with the unique subfield F36 of Ω.

L1L2L4L5algebra
2.1

Under the fixed identifications of steps 1.1 and 1.2, both F34 and F36 are subfields of Ω=F312 by [L2], since 412 and 612. Their intersection is then an intermediate field of Ω/F3, so by [L2] it is F3d for some divisor d of 12. Because the intersection lies in both fields, [L2] gives d4 and d6, hence d2; and since F32 lies in both fields, [L2] gives 2d. Therefore d=2 and F3(μ5)F3(μ7)=F32=F9.

step 1.1step 1.2L2
3.1

Since gcd(5,7)=1, the right-hand side of the refuted identity is K(μ1), which is just K=F3 because t1 already splits over K. So the claimed equality would read F9=F3, which is false.

step 2.1L4algebra
4.1

The refuted statement therefore fails over the base field F3, even though the rational theorem [L3] is true.

step 3.1L3

Remarks

  • Why the rational hypothesis matters. Over finite fields the intersection is controlled by the gcd of the extension degrees, not by the gcd of the orders of the roots of unity.
False statementConstruction: Literature-sourcedVerification: AI-adaptedprecheck passaudited 2026-08-26Open item page →

FALSE: every cyclotomic polynomial has all coefficients in {1,0,1}

Statement

False claim. Every coefficient of every cyclotomic polynomial ΦnZ[t] lies in {1,0,1}.

The failure first appears at n=105: the coefficient of t7 in Φ105(t) is 2.

Facts & Assumptions

Given: The cyclotomic recursion dnΦd(t)=tn1 for n1 (The cyclotomic polynomials ΦnZ[t], defined by dnΦd=tn1).

[L1]

For every n1, Φn is a monic polynomial in Z[t] and the displayed divisor recursion holds (The recursion defines a unique monic ΦnZ[t], of degree φ(n)).

Refutation

technique · direct
1.1

Running the divisor recursion for n=105=357 and truncating modulo t8 gives Φ105(t)(1t3)(1t5)(1t7)1t1+t+t2t5t62t7(modt8). The first congruence is the defining recursion with every factor of degree at least 15 dropped modulo t8, and the second comes from expanding (1t)1=1+t+t2+t3+t4+t5+t6+t7(modt8).

givenL1algebra
2.1

Step 1.1 shows that the coefficient of t7 in Φ105(t) is 2, and 2{1,0,1}. So the false claim fails.

step 1.1algebra

Remarks

  • Why this is a real pattern and not a silly claim. For many small values of n the coefficients do lie in {1,0,1}, so the first counterexample is not visually obvious from the recursion alone.
False statementConstruction: AI-adaptedVerification: AI-adaptedprecheck passaudited 2026-08-26Open item page →

FALSE: Φn is irreducible over every field

Statement

False claim. For every field K and every n1 with the characteristic of K not dividing n, the image of Φn in K[t] is irreducible.

What is true is different in two directions: over Q every Φn is irreducible, but over a finite field the factor degree is governed by the order of the Frobenius class modulo n.

Facts & Assumptions

Given: The rational irreducibility theorem and the finite-field factorisation theorem.

[L1]

For every n1, the cyclotomic polynomial Φn is irreducible in Q[t] (Φn is irreducible in Q[t] for every n1).

[L2]

If gcd(n,q)=1, the reduction of Φn in Fq[t] is a product of distinct monic irreducibles, each of degree the order of [q] modulo n (For gcd(n,q)=1 the reduction of Φn in Fq[t] is a product of distinct monic irreducibles, each of degree the order of [q] modulo n).

Refutation

technique · direct
1.1

In (Z/5)× one has [11]=[1], so the order of [11] modulo 5 is 1. Therefore [L2] says that over F11 every irreducible factor of Φ5 has degree 1.

L2algebra
2.1

Hence the reduction of Φ5 in F11[t] is a product of distinct linear factors, so it is reducible there. This contradicts the false claim.

step 1.1algebra
3.1

The contradiction does not touch [L1]: irreducibility over Q is a theorem, but it does not persist over arbitrary base fields.

step 2.1L1

Remarks

  • The finite-field theorem is the correct replacement. The question over Fq is not "irreducible or not?" in the abstract, but "what is the order of [q] modulo n?"
False statementConstruction: AI-adaptedVerification: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

FALSE: μn(K) has n elements in every field K

Statement

False claim. For every field K and every n1, the group μn(K) of n-th roots of unity in K has exactly n elements.

The witness below shows two different failures: over Q there is no primitive cube root of unity in the field at all, while in characteristic 3 the equation x3=1 is inseparable and has only one root.

Facts & Assumptions

Given: The groups μn(K) of roots of unity.

[L1]

μn(K) is cyclic of order dividing n, and it has a primitive n-th root of unity exactly when its order is n (μn(K) is cyclic of order dividing n, and has a primitive n-th root of unity exactly when its order is n).

[L3]

Refutation

technique · direct
1.1

If μ3(Q) had three elements, then [L1] would give a primitive cube root of unity ζ3 in Q. But then Q(ζ3)=Q, contradicting [L2], which says this extension has degree 2. So μ3(Q) does not have three elements.

L1L2
1.2

If K has characteristic 3, then [L3] gives μ3(K)={1}, so again μ3(K) does not have three elements.

L3
2.1

The false claim fails already at n=3, both over Q and over every field of characteristic 3.

step 1.1step 1.2

Remarks

  • The two failures have different causes. Over Q the polynomial t31 is separable but its nontrivial roots lie in a quadratic extension; in characteristic 3 the polynomial itself collapses to (t1)3.
False statementConstruction: AI-adaptedVerification: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

FALSE: every finite abelian group is Gal(Q(μn)/Q) for some n

Statement

False claim. For every finite abelian group G there is an n1 with

Gal(Q(μn)/Q)G.

The obstruction is visible already at the level of cardinality: the cyclic group C3 occurs as a Galois group over Q, but never as the Galois group of a cyclotomic field.

Facts & Assumptions

Given: Cyclotomic Galois groups and the theorem realising finite abelian groups over Q.

[L2]

Every finite abelian group is the Galois group of some finite Galois extension of Q (Every finite abelian group is the Galois group of some finite Galois extension of Q).

[L3]

In a finite group, the order of every subgroup divides the order of the group (Lagrange's theorem: G=[G:H]H for every subgroup H of a finite group G).

Refutation

technique · direct
1.1

For n=1 and n=2, the group (Z/n)× is trivial, so φ(1)=φ(2)=1.

L1algebra
1.2

If n3, then the unit class [1] in (Z/n)× has order 2: one has [1]2=[1], and [1][1] because otherwise n would divide 2, contrary to n3. Therefore [L3] makes the group order φ(n)=(Z/n)× even.

L1L3algebra
2.1

Steps 1.1 and 1.2 show that φ(n) is never 3. So no cyclotomic field Q(μn) has Galois group of order 3, and in particular none has Galois group isomorphic to C3.

step 1.1step 1.2L1
3.1

By [L2], however, some finite Galois extension of Q does have Galois group C3. Hence the false claim fails.

step 2.1L2

Remarks

  • What the true theorem says instead. The proved result is that every finite abelian group is the Galois group of a subfield of a cyclotomic field, not of the cyclotomic field itself.
ExampleConstruction: AI-adaptedVerification: AI-adaptedprecheck passaudited 2026-08-26Open item page →

A degree-three Galois extension of Q inside Q(ζ7)

Example

Let ζ:=ζ7. Then the fixed field of the unique order-two subgroup of Gal(Q(ζ)/Q) is

Q(ζ+ζ1),

a degree-three Galois extension of Q with cyclic Galois group, and the element ζ+ζ1 has minimal polynomial

t3+t22t1.

Facts & Assumptions

Given: A primitive seventh root of unity ζ=ζ7.

[L1]

Gal(Q(ζ7)/Q)(Z/7)× and has order φ(7)=6 ([Q(ζn):Q]=φ(n) and Gal(Q(μn)/Q)(Z/n)×).

[L2]

A finite cyclic group has exactly one subgroup of each order dividing its own (A finite cyclic group has exactly one subgroup of each order dividing its own).

[L3]

For a finite Galois extension, subgroups correspond to intermediate fields, and the fixed field of a subgroup H has degree equal to the subgroup index (The fundamental theorem of finite Galois theory).

[L4]

Every finite subgroup of the unit group of an integral domain is cyclic (Every finite subgroup of the unit group of an integral domain is cyclic).

[L5]

Under the finite Galois correspondence, a normal subgroup H has a Galois fixed field and restriction gives Gal(F/Q)G/H (Normal subgroups, conjugate fields, and quotient groups in the Galois correspondence).

Verification

technique · direct
1.1

By [L1] the Galois group of Q(ζ)/Q is isomorphic to the finite subgroup (Z/7)× of the unit group of the field Z/7, so [L4] makes it cyclic; its order is 6. Thus [L2] gives a unique subgroup H of order 2, and [L3] makes its fixed field F have degree [F:Q]=6/2=3.

L1L2L3L4
2.1

The subgroup H is generated by the class [1], so it acts by complex conjugation. Therefore ζ+ζ1 is fixed by H and lies in F.

step 1.1algebra
3.1

Put x:=ζ+ζ1. Then ζ2+ζ2=x22,ζ3+ζ3=x33x. Since 1+ζ+ζ2+ζ3+ζ4+ζ5+ζ6=0, dividing by ζ3 gives 1+(ζ+ζ1)+(ζ2+ζ2)+(ζ3+ζ3)=0. Substituting the expressions above yields x3+x22x1=0.

step 2.1algebra
4.1

The element x is not rational: if it were, then ζ would satisfy the quadratic polynomial t2xt+1Q[t], which would force [Q(ζ):Q]2, contradicting [L1]. Since xF, the prime degree [F:Q]=3 from step 1.1 leaves only the subfields Q and F, so Q(x)=F. Therefore the minimal polynomial of x has degree 3, and the cubic from step 3.1 is that minimal polynomial.

step 1.1step 3.1L1
5.1

The ambient Galois group is cyclic and hence abelian, so H is normal. By [L5], the fixed field F/Q is Galois and Gal(F/Q) is isomorphic to the quotient by H, which has order 3. The group is cyclic by [L6], so F/Q is a cyclic cubic Galois extension.

step 1.1L5L6algebra

Remarks

  • This is the smallest nontrivial case of the subfield theorem. The subgroup lattice of (Z/7)× has one index-two subgroup, and the fixed field is already visible through the real element ζ+ζ1.

Sources