Alphabeta Math
How statement and proof provenance work

The first chip identifies the source of the statement or construction; the second identifies the source of its local proof or verification.

  • Literature-sourced: the exact statement appears in a cited source; only wording and notation differ.
  • AI-adapted: a semantically identical restatement of literature-sourced material, modulo indexing, notation, and boundary cases adopted by the library.
  • AI-generated: a genuinely novel statement formulated by AI, with no source for the claim itself.

These labels describe origin, not correctness: citations and verification chips remain separate evidence.

✓ 57 results · all verified · 42 also independently AI-judged
Every result on this page is machine-checked by a proof checker and read in full and owner-audited; the judge is an additional, independent cross-model AI review of the proofs. The 15 not AI-judged were verified by owner audit (typically over a confirmed judge false positive), not failures.

Finite Fields and Cyclotomic Extensions

1 · Prerequisites

2 · Summary

Finite fields on this page are governed by the Frobenius endomorphism, Artin's fixed-field theorem, and the finite Galois correspondence. The page uses the published algebraic-extension and Galois pages for degree, splitting, and automorphism machinery, then adds the relative Frobenius, the finite cyclic-group lemmas it needs, Dedekind independence for normal bases, and the polynomial and unit-group facts that control cyclotomic extensions and finite-field factorisations.

The development begins with finite fields: the q-power map identifies the fixed field, determines the full Galois group, describes every intermediate field, and controls Frobenius conjugates and normal bases. It then turns to roots of unity and cyclotomic extensions, defines Φn by the divisor recursion, proves the primitive-root and irreducibility theorems, and uses the resulting Galois groups to study finite-field factorisation, composita and intersections over Q, primes congruent to 1 modulo n, and finite abelian Galois groups over Q.

3 · Logical flowchart

4 · Definitions, theorems and proofs

LemmaStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

A finite cyclic group has exactly one subgroup of each order dividing its own

Statement

Let G=⟨g⟩ be a cyclic group of finite order n≥1 (The subgroup ⟨S⟩ generated by a subset, the cyclic subgroup ⟨g⟩, and cyclic groups). For every positive divisor d of n (Divisibility in Z: d∣a when a=dq for some integer q):

⟨gn/d⟩ is a subgroup of G of order d,

it is the only subgroup of G of order d, and every subgroup of G is of this form for exactly one such d. Moreover, for positive divisors d and e of n,

⟨gn/d⟩⊆⟨gn/e⟩⟺d∣e.

The two extremes are instances rather than exceptions: d=1 gives the trivial subgroup {e} and d=n gives G itself, and at n=1 the only divisor is d=1, where G is trivial.

Facts & Assumptions

Given: A cyclic group G=⟨g⟩ whose underlying set is finite of order n≥1; divisibility of integers is that of Divisibility in Z: d∣a when a=dq for some integer q, and orders are those of The order ∣G∣ of a finite group and the order ord⁡(g) of an element, with ord⁡(g)=∞ when no positive power of g is the identity.

[A1]

∣G∣=n, and since G=⟨g⟩, [L1] gives ord⁡(g)=∣⟨g⟩∣=n.

[L1]

For an element x of finite order m in a group: xk=e if and only if m∣k; the powers x0,x1,…,xm−1 are pairwise distinct; and ⟨x⟩={ xs:s∈N, s<m }, so ⟨x⟩ is finite with ∣⟨x⟩∣=m=ord⁡(x) (If ord⁡(g)=n then gk=e iff k is an integer multiple of n, the powers g0,…,gn−1 are distinct, and ⟨g⟩ has exactly n elements; if g has infinite order then gj=gk only for j=k).

[L2]

⟨x⟩={ xk:k∈Z }: the cyclic subgroup generated by x is exactly the set of integer powers of x (⟨g⟩={ gn:n∈Z }, and every cyclic group is abelian).

[L3]

For a finite group G and H≤G one has ∣G∣=[G:H] ∣H∣; consequently ∣H∣ divides ∣G∣ (Lagrange's theorem: ∣G∣=[G:H]∣H∣ for every subgroup H of a finite group G).

Proof

technique · direct
1.1givenalgebra

Fix a positive divisor d of n and put c:=n/d, an integer with c≥1 and n=cd.

2.1step 1.1A1L1algebra

The element gc has order exactly d: first (gc)d=gcd=gn=e by [A1] and [L1]; and if 1≤j<d then 1≤cj<cd=n, so n∤cj and hence (gc)j=gcj≠e by [L1]. Therefore ∣⟨gc⟩∣=d by [L1].

2.2step 1.1A1L1L2algebra

The set of x∈G with xd=e is exactly ⟨gc⟩: writing x=gm with m∈Z by [L2] and [A1], the condition xd=gmd=e says n∣md by [L1], that is cd∣md, that is c∣m; and { gm:c∣m }={ (gc)k:k∈Z }=⟨gc⟩ by [L2].

2.3step 1.1L2algebra

For positive divisors d,e of n with d∣e, write e=df with f≥1; then n/d=(n/e)f, so gn/d=(gn/e)f∈⟨gn/e⟩ by [L2], and therefore ⟨gn/d⟩⊆⟨gn/e⟩, the latter being a subgroup containing gn/d.

3.1step 2.1step 2.2L1L3

If H≤G has ∣H∣=d, then H=⟨gc⟩: each h∈H has ord⁡(h)=∣⟨h⟩∣ dividing ∣H∣=d by [L1] and [L3], so hd=e by [L1] and hence h∈⟨gc⟩ by step 2.2; thus H⊆⟨gc⟩, and both sets have exactly d elements by step 2.1, so they are equal.

4.1step 2.1step 3.1A1L3

Every subgroup H≤G has this form for exactly one positive divisor of n: H is a subset of the finite set G, so d:=∣H∣ is defined and divides n by [L3] and [A1], and step 3.1 gives H=⟨gn/d⟩; the divisor is determined by H, being its order.

5.1step 2.1step 3.1step 2.3step 4.1L3∎

Conversely, if ⟨gn/d⟩⊆⟨gn/e⟩ then d∣e, since by step 2.1 the two subgroups have orders d and e and [L3] applied to the subgroup ⟨gn/d⟩ of ⟨gn/e⟩ makes d divide e. Together with steps 2.1, 3.1, 4.1 and 2.3 this proves every clause of the lemma.

Remarks

  • What the divisor lattice buys. The clause that matters downstream is not existence but uniqueness: a subgroup of a finite cyclic group is pinned down by its order alone, so the Galois correspondence turns "subgroups of Gal⁡(Fqn/Fq)" into "divisors of n" with nothing left to choose (The intermediate fields of Fqn/Fq are the Fqd, one for each positive divisor d of n).

  • Where cyclicity is used. Uniqueness fails without it. In the Klein four-group there are three distinct subgroups of order two, and the argument breaks at step 2.2, where the solutions of x2=e form the whole group rather than a single cyclic subgroup.

LemmaStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

A cyclic group of order n has exactly φ(n) generators

Statement

Let G=⟨g⟩ be a cyclic group of finite order n≥1 (The subgroup ⟨S⟩ generated by a subset, the cyclic subgroup ⟨g⟩, and cyclic groups). For an integer a,

⟨ga⟩=G⟺gcd⁡(a,n)=1,

that is, ga generates G exactly when a and n are coprime (Coprime integers: gcd⁡(a,b)=1). Consequently G has exactly φ(n) generators (The unit group (Z/n)× and Euler's totient φ(n)=∣(Z/n)×∣ for n≥1).

At n=1 the group is trivial, every integer is coprime to 1, and the single element is its own generator, in agreement with φ(1)=1.

Facts & Assumptions

Given: A cyclic group G=⟨g⟩ whose underlying set is finite of order n≥1.

[A1]

∣G∣=n, and since G=⟨g⟩, [L1] gives ord⁡(g)=∣⟨g⟩∣=n; in particular gn=e.

[L1]

For an element x of finite order m in a group: xk=e if and only if m∣k; the powers x0,x1,…,xm−1 are pairwise distinct; and ⟨x⟩={ xs:s∈N, s<m }, so ∣⟨x⟩∣=m=ord⁡(x) (If ord⁡(g)=n then gk=e iff k is an integer multiple of n, the powers g0,…,gn−1 are distinct, and ⟨g⟩ has exactly n elements; if g has infinite order then gj=gk only for j=k, The order ∣G∣ of a finite group and the order ord⁡(g) of an element, with ord⁡(g)=∞ when no positive power of g is the identity).

[L4]

gcd⁡(a,b) is a common divisor of a and b, and gcd⁡(a,b)≥1 whenever (a,b)≠(0,0) (Common divisor, and the greatest common divisor gcd⁡(a,b), with the convention gcd⁡(0,0):=0).

[L5]

For n≥1, every class in Z/n contains exactly one integer r with 0≤r<n, and r↦[r]n is a bijection from {0,…,n−1} onto Z/n (For n≥1, every class in Z/n has one representative r with 0≤r<n, so ∣Z/n∣=n; while Z/0 is in bijection with Z).

[L6]

For n≥1 and a∈Z, the class [a]n is a unit of Z/n if and only if gcd⁡(a,n)=1 (For n≥1, [a]n is a unit if and only if gcd⁡(a,n)=1).

Proof

technique · direct
1.1L4given

Put m:=gcd⁡(a,n). Since n≥1 the pair (a,n) is not (0,0), so m≥1, m∣a and m∣n by [L4].

2.1step 1.1A1L2L3

If m=1 then ga generates G: by [L3] there are integers u,v with au+nv=1, whence g=gau+nv=(ga)u(gn)v=(ga)u using gn=e from [A1]; so g∈⟨ga⟩ by [L2], and ⟨ga⟩ is then a subgroup containing g, so it contains ⟨g⟩=G by [L2] and equals G.

2.2step 1.1A1L1algebra

Conversely, if ga generates G then m=1: from m∣a and m∣n the integer n/m is at least 1 and (ga)n/m=(gn)a/m=e by [A1], so ord⁡(ga)≤n/m and hence ∣⟨ga⟩∣≤n/m by [L1]; but ⟨ga⟩=G has n elements, so n≤n/m and therefore m=1.

3.1step 2.1step 2.2A1L1

By [A1] and [L1] the powers g0,g1,…,gn−1 are pairwise distinct and exhaust G, so the generators of G are exactly the elements gr with 0≤r<n and gcd⁡(r,n)=1, one for each such r.

4.1step 3.1L5L6L7∎

By [L5] the map r↦[r]n is a bijection from {0,…,n−1} onto Z/n, and by [L6] it carries the r with gcd⁡(r,n)=1 onto the units of Z/n; so the number of such r is ∣(Z/n)×∣=φ(n) by [L7], and by step 3.1 that is the number of generators of G.

Remarks

DefinitionDefinition: Literature-sourcedProof: Not applicablejudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

The relative Frobenius x↦xq of an extension of finite fields

Definition

Let Fq be a finite field of order q (Finite fields and their order) and let E be a finite field having Fq as a subfield. The relative Frobenius of the extension E/Fq is the map

σq ⁣:E⟶E,σq(x)=xq.

It is an Fq-automorphism of E, and no separate result is needed for that. Let p be the characteristic of E; the subfield Fq has the same identity element and hence the same characteristic, so q=pk with k=[Fq:Fp] by Every finite field has order pn for a unique prime characteristic p and positive integer n. The Frobenius map Fr⁡E ⁣:x↦xp is an injective field endomorphism of E, is an automorphism because E is finite, and has k-fold iterate x↦xpk (Frobenius x↦xp is an injective endomorphism in characteristic p, and an automorphism for finite fields); that iterate is σq. Every a∈Fq satisfies aq=a (A field with q elements is the splitting field of xq−x over its prime subfield), so σq fixes Fq pointwise. Hence

σq∈Aut⁡(E/Fq)

(Relative field automorphisms and Aut⁡(K/F)). Its iterates are σq i(x)=xqi for i∈N, with σq 0 the identity.

Remarks

  • The letter. The relative Frobenius is written σq rather than φq because φ is Euler's totient (The unit group (Z/n)× and Euler's totient φ(n)=∣(Z/n)×∣ for n≥1) everywhere below, and the two symbols would otherwise stand side by side in the same formula.

  • Relative, not absolute. Fr⁡E is intrinsic to E; σq depends on the chosen base field Fq, and it is the identity exactly when E=Fq. Taking Fq to be the prime field returns Fr⁡E itself.

LemmaStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

The elements of a finite extension fixed by the q-power map are exactly the base field

Statement

Let Fq be a finite field of order q and let E be a finite field having Fq as a subfield. Then

{ x∈E:xq=x }=Fq.

Equivalently, the fixed field of the cyclic group generated by the relative Frobenius σq (The relative Frobenius x↦xq of an extension of finite fields) is the base field:

E⟨σq⟩=Fq.

Facts & Assumptions

Given: Finite fields Fq⊆E with ∣Fq∣=q (Finite fields and their order), and the set S:={ x∈E:xq=x }.

[L1]

The relative Frobenius is σq(x)=xq, an Fq-automorphism of E (The relative Frobenius x↦xq of an extension of finite fields).

[L2]

If F is a field with q elements, then every a∈F satisfies aq=a (A field with q elements is the splitting field of xq−x over its prime subfield).

[L3]

Let D be an integral domain. A nonzero polynomial f∈D[x] of degree n has at most n distinct roots in D (A nonzero polynomial of degree n over an integral domain has at most n distinct roots).

[L4]

The fixed field of a subgroup G of the automorphism group of K is KG={ x∈K:σ(x)=x for every σ∈G } (The fixed field KG of a group of field automorphisms).

Proof

technique · direct
1.1L2given

Applying [L2] to the field Fq, which has exactly q elements, every a∈Fq satisfies aq=a; hence Fq⊆S.

1.2L3given

S is the set of roots in E of the polynomial tq−t∈E[t], which is nonzero of degree q; a field is an integral domain, so [L3] gives ∣S∣≤q.

2.1step 1.1step 1.2given

Since Fq⊆S, ∣Fq∣=q and ∣S∣≤q, the finite sets Fq and S coincide: { x∈E:xq=x }=Fq.

3.1step 2.1L1L4∎

An element of E is fixed by every power of σq precisely when it is fixed by σq itself, so E⟨σq⟩={ x∈E:xq=x } by [L1] and [L4], and step 2.1 identifies this with Fq.

Remarks

LemmaStatement: AI-adaptedProof: AI-generatedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

For a degree-n extension of a field of order q, the q-power map has order exactly n

Statement

Let Fq be a finite field of order q and let E/Fq be an extension of finite fields of degree n (The degree [K:F]=dim⁡FK of a finite field extension). Then

∣E∣=qn,

and the relative Frobenius σq (The relative Frobenius x↦xq of an extension of finite fields) has order exactly n in Aut⁡(E/Fq) (The order ∣G∣ of a finite group and the order ord⁡(g) of an element, with ord⁡(g)=∞ when no positive power of g is the identity). At n=1 this says σq is the identity, of order one.

Facts & Assumptions

Given: Finite fields Fq⊆E with ∣Fq∣=q and [E:Fq]=n; the prime subfield of E is Fp with p the characteristic, and Fq has the same characteristic, its identity element being that of E.

[L1]

The relative Frobenius is σq(x)=xq, an Fq-automorphism of E, with σq i(x)=xqi (The relative Frobenius x↦xq of an extension of finite fields).

[L2]

If F is a field with q elements, then every a∈F satisfies aq=a (A field with q elements is the splitting field of xq−x over its prime subfield).

[L3]

Let D be an integral domain. A nonzero polynomial f∈D[x] of degree n has at most n distinct roots in D (A nonzero polynomial of degree n over an integral domain has at most n distinct roots).

[L4]

If F is a finite field, then there is a unique prime p and a unique positive integer m with ∣F∣=pm; here p=char⁡F and m=[F:Fp] (Every finite field has order pn for a unique prime characteristic p and positive integer n).

[L5]

For fields F⊆K⊆L with K/F and L/K finite, L/F is finite and [L:F]=[L:K][K:F] (Tower law for finite extensions: [L:F]=[L:K][K:F]).

Proof

technique · direct
1.1L4given

By [L4] applied to Fq, q=pk with k=[Fq:Fp]; by [L4] applied to E, ∣E∣=pm with m=[E:Fp].

2.1step 1.1L5algebra

The tower Fp⊆Fq⊆E and [L5] give m=[E:Fq] [Fq:Fp]=nk, so ∣E∣=pnk=(pk)n=qn.

3.1step 2.1L1L2

Every x∈E satisfies xqn=x, by [L2] applied to E, whose order is qn by step 2.1; by [L1] this says σq n=idE.

3.2step 2.1L1L3algebra

For an integer j with 1≤j<n one has σq j≠idE: otherwise every one of the qn elements of E would be a root of the nonzero polynomial tqj−t∈E[t], whose degree qj is smaller than qn because q≥2, contradicting [L3].

4.1step 3.1step 3.2L1∎

The least j≥1 with σq j=idE is therefore j=n, that is ord⁡(σq)=n; for n=1 steps 3.1 and 3.2 say only that σq=idE, of order one.

TheoremStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

A finite extension of a finite field of order q is Galois with cyclic Galois group generated by x↦xq

Statement

Let Fq be a finite field of order q and let E be a finite field having Fq as a subfield, with [E:Fq]=n (The degree [K:F]=dim⁡FK of a finite field extension). Then E/Fq is a finite Galois extension (Finite Galois extensions and Gal⁡(K/F)) and

Gal⁡(E/Fq)=⟨σq⟩

is cyclic of order n, generated by the relative Frobenius σq ⁣:x↦xq (The relative Frobenius x↦xq of an extension of finite fields).

Facts & Assumptions

Given: Finite fields Fq⊆E with ∣Fq∣=q and [E:Fq]=n, and the subgroup G:=⟨σq⟩ of Aut⁡(E/Fq).

[L1]

The relative Frobenius σq(x)=xq is an Fq-automorphism of E (The relative Frobenius x↦xq of an extension of finite fields).

[L2]

{ x∈E:xq=x }=Fq, that is E⟨σq⟩=Fq (The elements of a finite extension fixed by the q-power map are exactly the base field).

[L3]

∣E∣=qn and σq has order exactly n in Aut⁡(E/Fq) (For a degree-n extension of a field of order q, the q-power map has order exactly n).

[L4]

If G is a finite group of automorphisms of K, then [K:KG]=∣G∣ and Aut⁡(K/KG)=G (Artin's fixed-field theorem: [K:KG]=∣G∣ and Aut⁡(K/KG)=G).

[L5]

For a finite extension K/F with G=Aut⁡(K/F), the conditions "K/F is Galois", "K is the splitting field over F of a separable polynomial", "∣G∣=[K:F]" and "KG=F" are equivalent (Equivalent characterizations of a finite Galois extension).

[L6]

KG={ x∈K:σ(x)=x for every σ∈G } (The fixed field KG of a group of field automorphisms).

Proof

technique · direct
1.1L1L3

G=⟨σq⟩ is a cyclic group of automorphisms of E, finite of order n by [L1] and [L3].

1.2L2L6

Its fixed field is EG=Fq by [L2] and [L6].

2.1step 1.1step 1.2L4

Applying [L4] to the finite automorphism group G of E and using step 1.2, [E:Fq]=[E:EG]=∣G∣=n and Aut⁡(E/Fq)=Aut⁡(E/EG)=G.

3.1step 1.1step 2.1L5∎

Hence ∣Aut⁡(E/Fq)∣=n=[E:Fq], so E/Fq is Galois by [L5], and Gal⁡(E/Fq)=Aut⁡(E/Fq)=⟨σq⟩ is cyclic of order n by step 2.1 and step 1.1. At n=1 the group is trivial and E=Fq.

Remarks

  • Separability and normality are never argued separately. The usual route checks that E is a splitting field of tqn−t and that this polynomial has no repeated root. Routing through Artin's fixed-field theorem: [K:KG]=∣G∣ and Aut⁡(K/KG)=G instead replaces both checks by one count: an automorphism group of order n whose fixed field is Fq already forces ∣Aut⁡∣=[E:Fq], which is one of the equivalent Galois conditions.
TheoremStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

The intermediate fields of Fqn/Fq are the Fqd, one for each positive divisor d of n

Statement

Let Fq be a finite field of order q, let n≥1, and let Fqn be a finite field having Fq as a subfield with [Fqn:Fq]=n (The degree [K:F]=dim⁡FK of a finite field extension). For a positive divisor d of n (Divisibility in Z: d∣a when a=dq for some integer q) put

Fqd:={ x∈Fqn:xqd=x }.

Then the fields Fqd, as d runs over the positive divisors of n, are exactly the intermediate fields of Fqn/Fq, with distinct divisors giving distinct fields;

[Fqd:Fq]=d,∣Fqd∣=qd;

and for positive divisors d,e of n,

Fqd⊆Fqe⟺d∣e.

The two ends of the lattice are instances: d=1 gives the base field Fq and d=n gives Fqn.

Facts & Assumptions

Given: Finite fields Fq⊆E:=Fqn with ∣Fq∣=q and [E:Fq]=n≥1, and the relative Frobenius σq(x)=xq (The relative Frobenius x↦xq of an extension of finite fields), whose i-th iterate is x↦xqi.

[L1]

E/Fq is Galois and Gal⁡(E/Fq)=⟨σq⟩ is cyclic of order n (A finite extension of a finite field of order q is Galois with cyclic Galois group generated by x↦xq).

[L2]

In a cyclic group ⟨g⟩ of finite order n, for each positive divisor c of n the subgroup ⟨gn/c⟩ has order c and is the unique subgroup of that order, every subgroup has this form for exactly one such c, and ⟨gn/c⟩⊆⟨gn/c′⟩ if and only if c∣c′ (A finite cyclic group has exactly one subgroup of each order dividing its own).

[L3]

For K/F finite Galois with G=Gal⁡(K/F), the assignments H↦KH and F′↦Gal⁡(K/F′) are mutually inverse inclusion-reversing bijections between subgroups H≤G and intermediate fields F⊆F′⊆K, and [K:KH]=∣H∣, [KH:F]=[G:H] (The fundamental theorem of finite Galois theory).

[L5]

For an extension of finite fields L/Fq of degree m one has ∣L∣=qm (For a degree-n extension of a field of order q, the q-power map has order exactly n).

[L6]

KH={ x∈K:σ(x)=x for every σ∈H } (The fixed field KG of a group of field automorphisms).

[L7]

For a finite group G and H≤G one has ∣G∣=[G:H] ∣H∣ (Lagrange's theorem: ∣G∣=[G:H]∣H∣ for every subgroup H of a finite group G).

Proof

technique · direct
1.1L1

Write G:=Gal⁡(E/Fq)=⟨σq⟩, cyclic of order n by [L1], and for a positive divisor d of n put Hd:=⟨σq d⟩.

2.1step 1.1L2algebra

By [L2] applied to G with generator σq and c=n/d, the subgroup Hd=⟨σq n/(n/d)⟩ has order n/d; every subgroup of G is Hd for exactly one positive divisor d of n; and He⊆Hd if and only if d∣e, since He⊆Hd reads ⟨σq n/(n/e)⟩⊆⟨σq n/(n/d)⟩, which by [L2] says (n/e)∣(n/d), that is d∣e.

2.2step 1.1L6given

The fixed field of Hd is EHd={ x∈E:σq d(x)=x }={ x∈E:xqd=x }=Fqd, because an element fixed by σq d is fixed by all its powers and conversely.

3.1step 2.1step 2.2L3

By [L3] the map H↦EH is a bijection from the subgroups of G onto the intermediate fields of E/Fq; composing with the bijection of step 2.1 between positive divisors of n and subgroups, the fields Fqd=EHd are exactly the intermediate fields, distinct divisors giving distinct fields.

3.2step 2.1step 2.2L3L5L7algebra

Degrees: [L3] gives [Fqd:Fq]=[EHd:Fq]=[G:Hd], and [L7] with step 2.1 turns this into ∣G∣/∣Hd∣=n/(n/d)=d; then [L5] gives ∣Fqd∣=qd.

4.1step 2.1step 2.2step 3.1step 3.2L3L4∎

Inclusions: [L3] makes the correspondence inclusion-reversing, so Fqd=EHd⊆EHe=Fqe exactly when He⊆Hd, which by step 2.1 holds exactly when d∣e. At d=1 one has H1=G and Fq1=EG=Fq by [L4], and at d=n one has Hn={id} and Fqn=E; with steps 3.1 and 3.2 this proves every clause.

Remarks

  • Why the lattice is exactly the divisor lattice. Uniqueness of the subgroup of each order in a cyclic group is what leaves no choice: had Gal⁡(E/Fq) been the Klein four-group, three distinct subgroups of order two would have produced three intermediate fields of the same degree, and no indexing by divisors could exist.
RemarkRemark: AI-adaptedProof: Not applicablejudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

The Galois description of the subfields of a finite field and the elementary divisibility criterion agree

Statement

Two statements in this library describe the subfields of a finite field, and they describe the same objects.

The subfields of Fpn are the unique fields Fpd for positive divisors d of n fixes a finite field F of order pm with p its characteristic and says that for each positive divisor e of m the set { a∈F:ape=a } is the unique subfield of F of order pe, and that these are all of the subfields of F. Its index set is therefore the divisors of m, and its base point is the prime field.

The intermediate fields of Fqn/Fq are the Fqd, one for each positive divisor d of n fixes a base field Fq inside F and says that the intermediate fields of F/Fq are the { x∈F:xqd=x } for the positive divisors d of n=[F:Fq]. Its index set is therefore the divisors of n, and its base point is Fq.

The dictionary. Write q=pk, so that m=kn. For a positive divisor d of n the two prescriptions produce literally the same set,

{ x∈F:xqd=x }={ x∈F:xpkd=x },

which is the subfield of order pkd named by the first statement; and kd runs exactly over the divisors e of m that are multiples of k as d runs over the divisors of n. So the intermediate fields of F/Fq are precisely those subfields of F whose order is pe with k∣e, which is the expected answer: a subfield of F contains the unique subfield of order pk exactly when k divides e, by the divisibility clause of The intermediate fields of Fqn/Fq are the Fqd, one for each positive divisor d of n applied over the prime field.

Neither statement is the other. The published one is elementary: it counts roots of tpe−t and needs no Galois theory. The one proved here reads the lattice off the subgroup lattice of a cyclic Galois group, and it is that reading which the rest of this page uses, because the same correspondence also supplies the degrees and the automorphism groups of the intermediate fields. Recording their agreement here is what keeps the two vocabularies from drifting apart in later proofs.

TheoremStatement: Literature-sourcedProof: AI-adaptedprecheck passaudited 2026-08-26Open item page →

A monic irreducible of degree d over Fq has the d distinct roots α,αq,…,αqd−1

Statement

Let Fq be a finite field of order q, let π∈Fq[t] be monic irreducible of degree d≥1, and let α be a root of π in some extension field of Fq. Then Fq(α) is a finite field of order qd, the d elements

α, αq, αq2, …, αqd−1

are pairwise distinct roots of π lying in Fq(α),

π=∏i=0d−1(t−αqi)in Fq(α)[t],

and Fq(α) is a splitting field of π over Fq (Polynomials that split and splitting fields of a polynomial or a family of polynomials), of degree d over Fq (The degree [K:F]=dim⁡FK of a finite field extension). In particular these d elements are pairwise conjugate over Fq (Conjugate algebraic elements over a field) and form a single orbit of the relative Frobenius. The list starts at i=0, so its first member is α itself, and at d=1 it is the single element α∈Fq.

Facts & Assumptions

Given: A finite field Fq of order q≥2, a monic irreducible π∈Fq[t] of degree d≥1 (Degree, leading coefficient and monic polynomial, with the zero polynomial having no degree), a root α of π in an extension field, and the field K:=Fq(α).

[L1]

If K/F is a field extension and a∈K is algebraic, there is a unique monic irreducible ma∈F[x] with ker⁡(ev⁡a)=(ma), and for every f∈F[x] one has f(a)=0 if and only if ma∣f (The evaluation kernel and the unique monic irreducible minimal polynomial of an algebraic element).

[L2]

If a is algebraic over F with minimal polynomial of degree n, then [F(a):F]=n (An element is algebraic over F if and only if its simple extension F(a)/F is finite).

[L4]

An extension E/Fq of finite fields of degree m is Galois with Gal⁡(E/Fq)=⟨σq⟩ cyclic of order m, where σq(x)=xq (A finite extension of a finite field of order q is Galois with cyclic Galois group generated by x↦xq, The relative Frobenius x↦xq of an extension of finite fields).

[L5]

Let R be a commutative ring, a∈R and f∈R[x]. Then f(a)=0 if and only if x−a divides f in R[x] (Factor theorem over a commutative ring).

[L6]

A nonzero polynomial of degree n over an integral domain has at most n distinct roots in that domain (A nonzero polynomial of degree n over an integral domain has at most n distinct roots).

[L7]

If F is a field with q elements, then every a∈F satisfies aq=a (A field with q elements is the splitting field of xq−x over its prime subfield).

[L8]

Two elements algebraic over F are conjugate over F when they have the same minimal polynomial over F (Conjugate algebraic elements over a field).

Proof

technique · direct
1.1L1L2given

π is the minimal polynomial of α over Fq: since π(α)=0, [L1] gives mα∣π, and π is irreducible while mα is monic of degree at least one, so π=mα. Hence [K:Fq]=d by [L2].

2.1step 1.1L3L4algebra

Fix the length-d basis supplied by [L3]. Unique coordinates give a bijection Fqd→K, so ∣K∣=qd and K is a finite field. Now [L4] applies: K/Fq is Galois with Gal⁡(K/Fq)=⟨σq⟩ cyclic of order d, where σq(x)=xq.

3.1step 2.1L4given

Each σq i fixes the coefficients of π, which lie in Fq, so applying the field homomorphism σq i to the equation π(α)=0 gives π(αqi)=0: every αqi is a root of π lying in K.

4.1step 2.1step 3.1L6L7algebra

The elements α,αq,…,αqd−1 are pairwise distinct. Suppose αqi=αqj with 0≤i<j≤d−1 and apply the automorphism σq d−j: since xqd=x for every x∈K by [L7] and step 2.1, this yields αqr=α with r:=i+d−j and 1≤r≤d−1. The set S:={ x∈K:xqr=x } is the fixed set of the automorphism σq r, hence a subfield of K; it contains Fq by [L7] and contains α, so K=Fq(α)⊆S. But S is the root set in K of the nonzero polynomial tqr−t, so ∣S∣≤qr by [L6], giving qd=∣K∣≤qr<qd because q≥2 and r<d. This is impossible.

5.1step 3.1step 4.1L5

The product P:=∏i=0d−1(t−αqi) divides π in K[t]. Indeed, listing the distinct roots as r0,…,rd−1, [L5] writes π=(t−r0)g0; for j≥1 the equation 0=π(rj)=(rj−r0)g0(rj) and rj≠r0 in the field K give g0(rj)=0, so the same step applies to g0 with the remaining d−1 distinct roots, and after d such steps π=P h for some h∈K[t].

6.1step 5.1givenalgebra

Both π and P are monic of degree d, so h is monic of degree 0, that is h=1 and π=P.

7.1step 1.1step 3.1step 4.1step 6.1L1L8∎

Consequently π splits over K, and K=Fq(α) is generated over Fq by the root α; since the subfield of K generated over Fq by all the roots of π contains α, it contains and hence equals K, so K is a splitting field of π over Fq. All d roots share the minimal polynomial π by step 1.1 and [L1], so they are pairwise conjugate over Fq by [L8], and step 3.1 exhibits them as one orbit of σq.

Remarks

  • The index starts at zero. The orbit is αq0=α,αq,…,αqd−1, so the factor t−α is present in the product; dropping the term i=0 would leave a polynomial of degree d−1 that is not π.

  • Where irreducibility is used. It enters twice: to identify π with the minimal polynomial of α in step 1.1, and through that identification to force [K:Fq]=d, which is what makes the count in step 4.1 tight. For a reducible π the conclusion fails outright, as t2−1 over F3 shows: its roots 1 and −1 are not a Frobenius orbit.

PropositionStatement: AI-adaptedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

∑d∣nd Nq(d)=qn for the counts Nq(d) of monic irreducibles of degree d over Fq

Statement

Let Fq be a finite field of order q and, for an integer d≥1, let Nq(d) denote the number of monic irreducible polynomials of degree d in Fq[t]. Then each Nq(d) is finite, and for every n≥1

∑d∣nd Nq(d)=qn,

the sum being over the positive divisors d of n (Divisibility in Z: d∣a when a=dq for some integer q, The sum ∑i∈Sai over a finite index set, and its product form). At n=1 the identity reads Nq(1)=q.

Facts & Assumptions

Given: A finite field Fq of order q≥2 and an integer n≥1; monic polynomials are as in Degree, leading coefficient and monic polynomial, with the zero polynomial having no degree.

[L1]

In Fq[t] one has tqn−t=∏P(t), the product being over the monic irreducible P∈Fq[t] whose degree divides n, each such P occurring once (Over Fq, xqn−x is the product of all monic irreducibles whose degrees divide n).

[L2]

If R is an integral domain and f,g∈R[x] are nonzero, then fg≠0 and deg⁡(fg)=deg⁡f+deg⁡g (Over an integral domain, degrees add under multiplication of nonzero polynomials).

[L3]

If R is an integral domain, then R[x] is an integral domain (A polynomial ring over an integral domain is an integral domain).

Proof

technique · direct
1.1givenalgebra

For each d≥1 the monic polynomials of degree d in Fq[t] are the td+ad−1td−1+⋯+a0 with a0,…,ad−1∈Fq, so there are exactly qd of them and Nq(d)≤qd is finite.

2.1step 1.1L1L3

Consequently the family of monic irreducible P∈Fq[t] with deg⁡P∣n is finite, having at most ∑d∣nqd members, so the product in [L1] is a finite product of nonzero polynomials in the integral domain Fq[t] ([L3]).

3.1step 2.1L1L2algebra

Taking degrees in [L1] and applying [L2] repeatedly to that finite product gives deg⁡(tqn−t)=∑deg⁡P∣ndeg⁡P, where the sum runs over the same finite family; and deg⁡(tqn−t)=qn because qn>1.

4.1step 1.1step 3.1algebra

Splitting that sum according to the degree of P: the possible degrees are exactly the positive divisors d of n, there are Nq(d) monic irreducibles of degree d, and each contributes d; hence ∑d∣nd Nq(d)=qn.

5.1step 1.1step 4.1algebra∎

At n=1 the only positive divisor is d=1, so the identity reads Nq(1)=q, in agreement with the fact that the monic polynomials of degree one are the t−a for a∈Fq and each is irreducible.

Remarks

  • What the identity does not give. It determines Nq(n) only once every Nq(d) for proper divisors d of n is known, so it is a recursion rather than a formula. Inverting it into a closed form is a separate matter and is not carried out here.
DefinitionDefinition: Literature-sourcedProof: Not applicablejudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

Normal bases of a finite Galois extension

Definition

Let K/F be a finite Galois extension (Finite Galois extensions and Gal⁡(K/F)) of degree n=[K:F] (The degree [K:F]=dim⁡FK of a finite field extension), and list its Galois group as

Gal⁡(K/F)={σ1,…,σn},

which has exactly n elements because ∣Gal⁡(K/F)∣=[K:F] for a finite Galois extension (Equivalent characterizations of a finite Galois extension). Scalar multiplication by F makes K an F-vector space of dimension n.

An element α∈K is a normal basis generator for K/F when the list

(σ1α, σ2α, …, σnα)

is an ordered basis of K as an F-vector space (Basis of a vector space: a linearly independent spanning subset; and ordered basis: an injective finite list whose image is a basis). Such a list is called a normal basis of K over F: a basis that is a single orbit of the Galois group.

Two conditions, not one. A list is an ordered basis when it is injective and its image is a basis, so a normal basis generator must in particular have n distinct conjugates σiα. Neither half implies the other: a basis of K over F need not be a Galois orbit, and a Galois orbit of size n need not be a basis.

The list is indexed by the group, not ordered by it. Reordering σ1,…,σn permutes the list and leaves the property of being a basis unchanged, since a basis is a property of the underlying set together with injectivity of the list (Basis of a vector space: a linearly independent spanning subset; and ordered basis: an injective finite list whose image is a basis). The automorphisms are those of Relative field automorphisms and Aut⁡(K/F).

LemmaStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

A polynomial vanishing at every tuple from an infinite subdomain is the zero polynomial

Statement

Let S be an integral domain, let R⊆S be a subring whose underlying set is infinite, let m≥1, and let f∈S[x1,…,xm] (Polynomial rings in finitely many commuting indeterminates by iteration). If

f(a1,…,am)=0for all a1,…,am∈R,

then f=0 in S[x1,…,xm].

Here f(a1,…,am) is the iterated evaluation of Evaluation and roots of a polynomial in a commutative target ring, carried out one indeterminate at a time along the construction of S[x1,…,xm].

Facts & Assumptions

Given: An integral domain S, an infinite subring R⊆S, and the polynomial rings S[x1,…,xm] built by iteration (Polynomial rings in finitely many commuting indeterminates by iteration).

[L1]

A nonzero polynomial g∈D[x] of degree k over an integral domain D has at most k distinct roots in D (A nonzero polynomial of degree n over an integral domain has at most n distinct roots).

[L2]

If R is an integral domain, then R[x1,…,xn] is an integral domain for every n∈N, including n=0 (A polynomial ring in finitely many indeterminates over an integral domain is an integral domain).

[L3]

A nonzero g=∑iaixi has a largest index with ai≠0, its degree; the zero polynomial has no degree (Degree, leading coefficient and monic polynomial, with the zero polynomial having no degree).

Proof

technique · induction
1.1L1L3base

Base case m=1: let g∈S[x] vanish at every element of R. If g≠0 it has a degree k by [L3], so by [L1] it has at most k distinct roots in S; but every one of the infinitely many elements of R⊆S is a root, and an infinite set has more than k elements. Hence g=0.

1.2ih

Inductive hypothesis: fix m≥1 and assume that every g∈S[x1,…,xm] vanishing at all tuples from R is zero.

2.1step 1.1L2given

Let f∈S[x1,…,xm+1]=S[x1,…,xm][xm+1] vanish at every tuple from R, and write f=∑j≤kgjxm+1 j with gj∈S[x1,…,xm]. Fix a=(a1,…,am)∈Rm; then ∑j≤kgj(a) xm+1 j is an element of S[xm+1] vanishing at every element of R, so it is zero by step 1.1, and therefore gj(a)=0 for every j≤k.

3.1step 1.2step 2.1discharge-induction∎

Since a∈Rm was arbitrary, each gj vanishes at every tuple from R, so gj=0 by step 1.2 and hence f=0. This completes the induction, and the statement holds for every m≥1.

Remarks

  • Infinite, not merely large. The hypothesis cannot be weakened to a finite R of any size: over R=S=Fq the nonzero polynomial xq−x vanishes at every element, and in m indeterminates so does x1q−x1. This is exactly why the normal basis theorem needs a separate argument over a finite base field (Every finite cyclic extension has a normal basis).
LemmaStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

For a finite Galois extension, (αj) is a base-field basis exactly when the matrix (σiαj) is invertible

Statement

Let K/F be a finite Galois extension of degree n, list its Galois group as Gal⁡(K/F)={σ1,…,σn}, and let α1,…,αn∈K. Let A∈Mn(K) be the matrix with entries

Aij=σi(αj)(1≤i,j≤n).

Then (α1,…,αn) is an ordered basis of K as an F-vector space (Basis of a vector space: a linearly independent spanning subset; and ordered basis: an injective finite list whose image is a basis) if and only if A is invertible over K (Invertible matrices and the general linear group GL⁡n(F)).

Facts & Assumptions

Given: A finite Galois extension K/F of degree n with Gal⁡(K/F)={σ1,…,σn}; elements α1,…,αn∈K; the matrix A∈Mn(K) with Aij=σi(αj) (Finite rectangular matrices over a commutative ring, their entries, rows and columns); and the F-linear map Φ ⁣:Fn→K given by Φ(a)=∑jajαj. Each σi is an F-automorphism of K (Relative field automorphisms and Aut⁡(K/F)), hence additive and F-linear.

[L1]

For a finite Galois extension K/F with G=Gal⁡(K/F) one has ∣G∣=[K:F] (Equivalent characterizations of a finite Galois extension, Finite Galois extensions and Gal⁡(K/F)); so dim⁡FK=n (The degree [K:F]=dim⁡FK of a finite field extension).

[L2]

Let G be a group and K a field. Every finite family of distinct group homomorphisms G→K× is linearly independent over K as a family of functions (Dedekind's linear independence theorem for distinct characters).

[L3]

For a linear map T:V→W of F-vector spaces with V finite-dimensional, dim⁡FV=dim⁡F(ker⁡T)+dim⁡F(im⁡T) (Rank-nullity: dim⁡FV=nullity⁡T+rank⁡T).

[L4]

For A∈Mn(F) and LA(x)=Ax on Mn×1(F): A is invertible if and only if LA is a linear isomorphism (A square matrix is invertible exactly when its multiplication map is a linear isomorphism; matrices preserve inverses of linear isomorphisms).

[L5]

Let R be a commutative ring, n≥1, A∈Mn(R). Then A is invertible if and only if det⁡(A) is a unit of R (A positive-sized square matrix over a commutative ring is invertible if and only if its determinant is a unit).

[L6]

det⁡(AT)=det⁡(A) for every A∈Mn(R) over a commutative ring (For every square matrix over a commutative ring, det⁡(AT)=det⁡(A)); the transpose is (AT)ji=Aij (Entrywise ring-matrix operations, rectangular matrix products, identity matrices and transpose).

Proof

technique · direct
1.1L1L3

By [L1] the F-vector space K has dimension n, and Φ is a map between F-vector spaces of dimension n; so by [L3] it is injective if and only if it is surjective, and (α1,…,αn) is an ordered basis of K over F exactly when Φ is bijective.

1.2given

For the implication that a basis has an invertible matrix, suppose (α1,…,αn) is an ordered basis, and let c∈Kn satisfy ATc=0, that is ∑iciσi(αj)=0 for every j. The map θ ⁣:K→K, θ(x)=∑iciσi(x), is F-linear because each σi is, and it vanishes at every αj, hence on their F-span, which is K.

2.1step 1.1given

For the implication that a non-basis has a singular matrix, suppose (α1,…,αn) is not an ordered basis. By step 1.1 the map Φ is not injective, so there is a∈Fn with a≠0 and ∑jajαj=0. Applying σi and using σi(aj)=aj for aj∈F gives ∑jσi(αj)aj=0 for every i, that is Aa=0 with a≠0 in Kn. Were A invertible with inverse B, this would force a=B(Aa)=0; so A is not invertible.

2.2step 1.2L2

So ∑iciσi is the zero function on K, in particular on K×. The restrictions σi∣K× ⁣:K×→K× are group homomorphisms and are pairwise distinct, since two automorphisms of K agreeing on K× agree on K; so [L2] forces ci=0 for every i.

3.1step 2.2L3L4L5L6

Hence the K-linear map x↦ATx on Kn has zero kernel, so by [L3] over K it is also surjective and therefore a linear isomorphism; by [L4] the matrix AT is invertible, so det⁡(AT) is a unit of K by [L5], and det⁡(A)=det⁡(AT) by [L6] is a unit, whence A is invertible by [L5].

4.1step 2.1step 3.1∎

Step 2.1 gives one implication, that a list which is not a basis has a matrix that is not invertible, and step 3.1 gives the other, that a list which is a basis has an invertible matrix; together they are the stated equivalence.

Remarks

  • Why the transpose appears. The dependence relation among the αj produces a null vector on the right of A, while the Dedekind relation among the σi produces one on the right of AT. Only the determinant sees both, which is why the two halves are joined through For every square matrix over a commutative ring, det⁡(AT)=det⁡(A) rather than by a single rank computation.

  • Where the Galois hypothesis is used. Twice: to know that the group has exactly n=[K:F] elements, so that A is square, and to know that the σi are F-linear, which is what lets step 2.1 pull the scalars aj through.

LemmaStatement: Literature-sourcedProof: Literature-sourcedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

Over an infinite base field, no nonzero polynomial vanishes at the conjugate tuple of every element

Statement

Let K/F be a finite Galois extension of degree n whose base field F is infinite, and list Gal⁡(K/F)={σ1,…,σn}. Then for every nonzero f∈K[x1,…,xn] (Polynomial rings in finitely many commuting indeterminates by iteration) there exists α∈K with

f(σ1α,…,σnα)≠0.

Facts & Assumptions

Given: A finite Galois extension K/F of degree n with F infinite and Gal⁡(K/F)={σ1,…,σn}; by [L4] the F-vector space K has dimension n, so an ordered F-basis (α1,…,αn) of K exists (Basis of a vector space: a linearly independent spanning subset; and ordered basis: an injective finite list whose image is a basis).

[L1]

Let S be an integral domain and R⊆S an infinite subring. If g∈S[x1,…,xm] satisfies g(a1,…,am)=0 for all a1,…,am∈R, then g=0 (A polynomial vanishing at every tuple from an infinite subdomain is the zero polynomial).

[L2]

For a finite Galois extension K/F of degree n with Gal⁡(K/F)={σ1,…,σn} and α1,…,αn∈K, the list (α1,…,αn) is an ordered F-basis of K if and only if the matrix A with Aij=σi(αj) is invertible (For a finite Galois extension, (αj) is a base-field basis exactly when the matrix (σiαj) is invertible).

[L3]

For commutative rings R,S, a unital ring homomorphism φ ⁣:R→S and s∈S, there is a unique unital ring homomorphism R[x]→S extending φ on constants and sending x to s (Universal property of R[x]: a coefficient homomorphism and the image of x determine a unique ring homomorphism). Iterating this along Polynomial rings in finitely many commuting indeterminates by iteration gives, for any commutative K-algebra T and any t1,…,tn∈T, a unique K-algebra homomorphism K[x1,…,xn]→T sending xi to ti.

[L5]

A∈Mn(K) is invertible when some B∈Mn(K) satisfies AB=In=BA; such a B is unique and written A−1 (Invertible matrices and the general linear group GL⁡n(F), Entrywise ring-matrix operations, rectangular matrix products, identity matrices and transpose).

Proof

technique · contrapositive
1.1contrapositive-reduceassume-hyp

It suffices to prove the contrapositive: if f∈K[x1,…,xn] satisfies f(σ1α,…,σnα)=0 for every α∈K, then f=0. Assume that hypothesis on f.

1.2L2L4L5given

Fix an ordered F-basis (α1,…,αn) of K and put Aij=σi(αj); by [L2] the matrix A is invertible, with inverse A−1 as in [L5].

2.1step 1.2given

For c∈Fn write α(c):=∑jcjαj; then c↦α(c) is a bijection Fn→K because the αj form a basis, and σi(α(c))=∑jcjσi(αj)=(Ac)i since each σi fixes F pointwise and is additive.

2.2step 1.2L3

Let ψ ⁣:K[x1,…,xn]→K[x1,…,xn] be the unique K-algebra homomorphism with ψ(xi)=∑jAijxj, and ψ′ the unique one with ψ′(xi)=∑j(A−1)ijxj; both exist by [L3].

3.1step 1.1step 2.1step 2.2L3

For c∈Fn, the evaluation homomorphism K[x1,…,xn]→K at c composed with ψ sends xi to ∑jAijcj=(Ac)i, so by the uniqueness clause of [L3] it is evaluation at Ac; hence ψ(f) evaluated at c equals f(Ac)=f(σ1α(c),…,σnα(c)), which is 0 by the hypothesis of step 1.1.

4.1step 3.1L1given

So ψ(f) vanishes at every tuple from the infinite subring F of the integral domain K, and [L1] gives ψ(f)=0.

5.1step 2.2step 4.1L3L5discharge-contrapositive∎

The composite ψ′∘ψ is a K-algebra endomorphism sending xi to ∑jAij∑k(A−1)jkxk=∑k(AA−1)ikxk=xi, so it is the identity by the uniqueness clause of [L3]; applying ψ′ to step 4.1 therefore gives f=ψ′(ψ(f))=ψ′(0)=0, which is the contrapositive.

Remarks

  • Where infiniteness of F enters. Only in step 4.1, through [L1]. Over a finite base field the conclusion is false: with ∣F∣=q and n=[K:F], the nonzero polynomial x1qn−x1 vanishes at every conjugate tuple, since every element of K satisfies xqn=x. The finite case of the normal basis theorem is therefore proved by a different argument (Every finite cyclic extension has a normal basis).
TheoremStatement: Literature-sourcedProof: Literature-sourcedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

Every finite Galois extension of an infinite field has a normal basis

Statement

Let K/F be a finite Galois extension whose base field F is infinite. Then K/F has a normal basis (Normal bases of a finite Galois extension): there is α∈K such that (σ1α,…,σnα) is an ordered F-basis of K, where Gal⁡(K/F)={σ1,…,σn}.

Facts & Assumptions

Given: A finite Galois extension K/F (Finite Galois extensions and Gal⁡(K/F)) of degree n with F infinite, and Gal⁡(K/F)={σ1,…,σn} numbered so that σ1=idK; the matrix B over K[x1,…,xn] with Bij:=xk where k is the index determined by σiσj=σk; and D:=det⁡B (For n≥1, the determinant over a commutative ring by the Leibniz formula, and ∣det⁡A∣ for a real matrix).

[L1]

For every nonzero f∈K[x1,…,xn] there is α∈K with f(σ1α,…,σnα)≠0 (Over an infinite base field, no nonzero polynomial vanishes at the conjugate tuple of every element).

[L2]

(α1,…,αn) is an ordered F-basis of K if and only if the matrix A with Aij=σi(αj) is invertible (For a finite Galois extension, (αj) is a base-field basis exactly when the matrix (σiαj) is invertible).

[L3]

det⁡(A)=∑σ∈Snsgn⁡(σ)∏iaσ(i),i (For n≥1, the determinant over a commutative ring by the Leibniz formula, and ∣det⁡A∣ for a real matrix); a matrix over a commutative ring is invertible if and only if its determinant is a unit (A positive-sized square matrix over a commutative ring is invertible if and only if its determinant is a unit).

[L5]

K[x1,…,xn] is an integral domain (A polynomial ring in finitely many indeterminates over an integral domain is an integral domain, Polynomial rings in finitely many commuting indeterminates by iteration), and for any commutative K-algebra T and t1,…,tn∈T there is a unique K-algebra homomorphism K[x1,…,xn]→T with xi↦ti (Universal property of R[x]: a coefficient homomorphism and the image of x determine a unique ring homomorphism).

Proof

technique · direct
1.1given

B is a well-defined n×n matrix over K[x1,…,xn]: for each pair (i,j) the product σiσj lies in the group Gal⁡(K/F) and so equals σk for exactly one index k.

2.1step 1.1L5given

Let ε ⁣:K[x1,…,xn]→K be the K-algebra homomorphism with ε(x1)=1 and ε(xk)=0 for k≠1, supplied by [L5]. Applying ε entrywise to B gives the matrix P∈Mn(K) with Pij=1 when σiσj=σ1=id, that is when σj=σi−1, and Pij=0 otherwise.

3.1step 2.1L3L4

P is invertible, with PT as an inverse: the (i,i′) entry of PPT is ∑jPijPi′j, and a term is nonzero exactly when σj=σi−1 and σj=σi′−1, which happens for exactly one j when i=i′ and for no j otherwise; so PPT=In, and the same computation on PTP gives In. Hence det⁡P is a unit of K by [L3], and in particular det⁡P≠0.

4.1step 2.1step 3.1L3L5

Since det⁡ is a polynomial expression in the entries by [L3] and ε is a ring homomorphism, ε(D)=ε(det⁡B)=det⁡P≠0; hence D≠0 in K[x1,…,xn].

5.1step 4.1L1L3L5

By [L1] there is α∈K with D(σ1α,…,σnα)≠0. Substituting xk↦σk(α) in B replaces the entry Bij=xk, where σiσj=σk, by σk(α)=σi(σj(α)); since substitution is a ring homomorphism, it carries D=det⁡B to the determinant of the matrix A with Aij=σi(αj) for αj:=σj(α). So det⁡A≠0.

6.1step 5.1L2L3∎

A nonzero element of the field K is a unit, so A is invertible by [L3], and [L2] makes (α1,…,αn)=(σ1α,…,σnα) an ordered F-basis of K; that is a normal basis.

Remarks

  • What the specialisation is for. The matrix of indeterminates is a device for showing that one determinant polynomial is not the zero polynomial, and the cheapest way to see that is to send it to a permutation matrix. Nothing about the particular substitution x1↦1 survives into the conclusion: the element α produced in step 5.1 has no relation to it.

  • Why σ1 is the identity. Only so that the specialised matrix is the permutation matrix of σ↦σ−1; any other choice of which indeterminate to set to 1 would give the permutation matrix of a different bijection, with the same conclusion.

TheoremStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

Every finite cyclic extension has a normal basis

Statement

Let K/F be a finite Galois extension whose Galois group is cyclic, say Gal⁡(K/F)=⟨σ⟩ of order n=[K:F]. Then K/F has a normal basis (Normal bases of a finite Galois extension): there is α∈K for which

(α, σα, …, σn−1α)

is an ordered F-basis of K (Basis of a vector space: a linearly independent spanning subset; and ordered basis: an injective finite list whose image is a basis).

Facts & Assumptions

Given: A finite Galois extension K/F with Gal⁡(K/F)=⟨σ⟩ cyclic of order n; by [L6] dim⁡FK=[K:F]=n, and σ is an F-linear endomorphism of the F-vector space K, written T when regarded as such. Evaluation of a polynomial at T is that of Polynomial evaluation at an endomorphism: p(T)=∑kakTk.

[L1]

Let G be a group and K a field. Every finite family of distinct group homomorphisms G→K× is linearly independent over K as a family of functions (Dedekind's linear independence theorem for distinct characters).

[L2]

For every endomorphism T of a finite-dimensional F-vector space, Ann⁡(T)={p∈F[x]:p(T)=0} is a nonzero ideal with a unique monic generator μT, and p(T)=0 if and only if μT∣p (The annihilator ideal is nonzero and has a unique monic generator; p(T)=0 if and only if μT∣p, The annihilator set Ann⁡(T)={p∈F[x]:p(T)=0}; once existence is proved, its unique monic generator μT is the minimal polynomial).

[L4]

μT∣χT for every endomorphism T of a finite-dimensional vector space (The minimal polynomial divides the characteristic polynomial, μT∣χT).

[L5]

An endomorphism T of a finite-dimensional vector space has a cyclic vector if and only if μT=χT (A cyclic vector exists exactly when the minimal and characteristic polynomials agree); v is a cyclic vector when Z(v;T)={p(T)v:p∈F[x]} is all of V (Cyclic subspaces, cyclic vectors, and vector annihilators).

[L7]

With mT,v the unique monic generator of Ann⁡T(v)={p:p(T)v=0} (The vector annihilator is the unique monic generator of Ann⁡T(v) and divides the minimal polynomial) and d=deg⁡mT,v, the list (v,Tv,…,Td−1v) is an ordered basis of Z(v;T) (A vector annihilator gives a power basis and its companion matrix).

Proof

technique · direct
1.1L2given

Tn=idK, because σ has order n in Gal⁡(K/F); so the polynomial xn−1 lies in Ann⁡(T) and μT∣xn−1 by [L2]. In particular deg⁡μT≤n.

1.2L1given

The maps id,σ,σ2,…,σn−1 are pairwise distinct elements of Gal⁡(K/F), and their restrictions to K× are pairwise distinct group homomorphisms K×→K×, since two field automorphisms of K agreeing on K× agree on K.

2.1step 1.2L1L2

If p=∑i<naixi with ai∈F satisfies p(T)=0, then ∑i<naiσi is the zero function on K, hence on K×, so [L1] applied to the family of step 1.2 forces every ai to be 0; thus no nonzero polynomial of degree less than n annihilates T, and deg⁡μT≥n.

3.1step 1.1step 2.1L2algebra

Combining steps 1.1 and 2.1, deg⁡μT=n, and since μT is monic and divides the monic xn−1 of the same degree, μT=xn−1.

4.1step 3.1L3L4given

By [L3] the polynomial χT is monic of degree dim⁡FK=n, and μT∣χT by [L4]; two monic polynomials of the same degree, one dividing the other, are equal, so μT=χT.

5.1step 4.1L5

By [L5] there is a cyclic vector α∈K for T, that is Z(α;T)=K.

6.1step 5.1L6L7given

Let d=deg⁡mT,α. By [L7] the list (α,Tα,…,Td−1α) is an ordered basis of Z(α;T)=K, which has dimension n, so d=n and (α,σα,…,σn−1α) is an ordered F-basis of K.

7.1step 1.2step 6.1given∎

Since Gal⁡(K/F)={id,σ,…,σn−1}, that list is exactly the family of conjugates of α, so it is a normal basis.

Remarks

  • Why the minimal polynomial is forced to be xn−1. The divisibility μT∣xn−1 is cheap; the content is the lower bound on its degree, and that is exactly Dedekind's independence of characters. Without it the minimal polynomial could be a proper divisor of xn−1 and no cyclic vector would be available.

  • The hypothesis is on the group, not on the base field. No finiteness or infiniteness of F is used, so this proof also covers cyclic extensions of infinite fields, for which Every finite Galois extension of an infinite field has a normal basis gives a second and quite different argument.

TheoremStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

Every finite Galois extension has a normal basis

Statement

Every finite Galois extension K/F has a normal basis (Normal bases of a finite Galois extension): there is α∈K whose family of conjugates (σ1α,…,σnα), indexed by Gal⁡(K/F)={σ1,…,σn}, is an ordered F-basis of K.

Facts & Assumptions

Given: A finite Galois extension K/F of degree n, so that K is an F-vector space of dimension n (The degree [K:F]=dim⁡FK of a finite field extension, Equivalent characterizations of a finite Galois extension).

[L1]

Every finite Galois extension of an infinite field has a normal basis (Every finite Galois extension of an infinite field has a normal basis).

[L2]

Every finite Galois extension whose Galois group is cyclic has a normal basis (Every finite cyclic extension has a normal basis).

[L3]

An extension E/Fq of finite fields of degree m is Galois with Gal⁡(E/Fq) cyclic of order m, generated by x↦xq (A finite extension of a finite field of order q is Galois with cyclic Galois group generated by x↦xq).

[L5]

A finite field is a field whose underlying set is finite, and its order is that cardinality (Finite fields and their order).

Proof

technique · cases
1.1assume-case infL1

In the case that F is infinite, [L1] applies directly and K/F has a normal basis.

1.2assume-case finL4L5given

In the case that F is finite, fix an ordered F-basis v of K of length n; by [L4] the map sending a coordinate list λ:n→F to ∑i<nλivi is a bijection onto K, so ∣K∣=∣F∣n is finite and K is a finite field.

2.1step 1.2L2L3

In that same finite case, K/ ⁣F is therefore an extension of finite fields of degree n, so Gal⁡(K/F) is cyclic by [L3], and [L2] gives a normal basis.

3.1step 1.1step 2.1cases-exhaustive∎

The two cases are exhaustive, a field being finite or infinite and not both, so a normal basis exists in either case.

Remarks

  • Two genuinely different proofs, not one proof with a case split. The infinite case runs on a determinant that is a nonzero polynomial (Every finite Galois extension of an infinite field has a normal basis); the finite case runs on a cyclic vector for the Frobenius acting linearly (Every finite cyclic extension has a normal basis). Neither argument covers the other case: the first fails because a polynomial can vanish on all of a finite field, the second because a Galois group need not be cyclic.

  • The finite case is not a hypothesis on the group. It is a hypothesis on the base field, which forces the group to be cyclic through [L3]. That is the whole reason the split is by the base field rather than by the group.

DefinitionDefinition: Literature-sourcedProof: Not applicablejudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

The group μn(K) of n-th roots of unity in a field, and primitive n-th roots of unity

Definition

Let K be a field and let n≥1 be an integer. An element x∈K is an n-th root of unity when xn=1, that is when x is a root of tn−1∈K[t] (Evaluation and roots of a polynomial in a commutative target ring). Write

μn(K):={ x∈K:xn=1 }.

This is a subgroup of K× (Subgroup). Every x∈μn(K) is invertible, with inverse xn−1 (Left inverse, right inverse, and invertible element of a monoid), so μn(K)⊆K×; it contains 1; it is closed under multiplication, since (xy)n=xnyn=1; and it is closed under inverses, since (x−1)n=(xn)−1=1.

An element ζ∈μn(K)⊆K× is a primitive n-th root of unity when its order in the group K× is exactly n (The order ∣G∣ of a finite group and the order ord⁡(g) of an element, with ord⁡(g)=∞ when no positive power of g is the identity):

ord⁡(ζ)=n.

Equivalently, ζn=1 and no exponent k with 1≤k<n has ζk=1.

An n-th root of unity need not be primitive. In Q the element −1 is a fourth root of unity of order two, not four; and μn(K) may consist of 1 alone, as μ3(Q) does. The two notions are separated deliberately, and the exact circumstances under which a primitive n-th root of unity exists are the content of μn(K) is cyclic of order dividing n, and has a primitive n-th root of unity exactly when its order is n and tn−1 is separable over K exactly when the characteristic does not divide n, and then a splitting field carries n distinct n-th roots of unity.

Remarks

PropositionStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

μn(K) is cyclic of order dividing n, and has a primitive n-th root of unity exactly when its order is n

Statement

Let K be a field and n≥1. Then μn(K)={x∈K:xn=1} (The group μn(K) of n-th roots of unity in a field, and primitive n-th roots of unity) is a finite cyclic subgroup of K× whose order divides n (Divisibility in Z: d∣a when a=dq for some integer q). It contains a primitive n-th root of unity if and only if ∣μn(K)∣=n, and in that case the primitive n-th roots of unity in K are exactly the generators of μn(K), of which there are φ(n) (The unit group (Z/n)× and Euler's totient φ(n)=∣(Z/n)×∣ for n≥1).

Facts & Assumptions

Given: A field K, an integer n≥1, and the subgroup μn(K) of K× (The group μn(K) of n-th roots of unity in a field, and primitive n-th roots of unity).

[L1]

Let D be an integral domain. Every finite subgroup G≤D× of the unit group of D is cyclic (Every finite subgroup of the unit group of an integral domain is cyclic).

[L2]

A nonzero polynomial of degree k over an integral domain has at most k distinct roots in that domain (A nonzero polynomial of degree n over an integral domain has at most n distinct roots).

[L4]

In a cyclic group ⟨g⟩ of finite order m, the element ga generates the group if and only if gcd⁡(a,m)=1, and the group has exactly φ(m) generators (A cyclic group of order n has exactly φ(n) generators).

Proof

technique · direct
1.1L2given

μn(K) is the set of roots in K of the nonzero polynomial tn−1, of degree n; a field is an integral domain, so ∣μn(K)∣≤n by [L2] and μn(K) is finite.

2.1step 1.1L1L3

Being a finite subgroup of K×, μn(K) is cyclic by [L1]; write m:=∣μn(K)∣ and fix a generator ζ0, so that ord⁡(ζ0)=m by [L3].

3.1step 2.1L3

The order m divides n: ζ0∈μn(K) gives ζ0 n=1, and [L3] turns this into m∣n.

3.2step 1.1step 2.1L3

If K contains a primitive n-th root of unity ζ, that is an element of order n, then ζn=1 puts ζ in μn(K), and ⟨ζ⟩⊆μn(K) has n elements by [L3], so n≤m; with step 1.1 this forces m=n.

3.3step 2.1L3

Conversely, if m=n then the generator ζ0 of step 2.1 has order n and so is a primitive n-th root of unity in K.

4.1step 2.1step 3.2step 3.3L3L4∎

Suppose m=n. An element x∈K of order n lies in μn(K)=⟨ζ0⟩ and satisfies ∣⟨x⟩∣=n=∣μn(K)∣ by [L3], so ⟨x⟩=μn(K) and x is a generator; conversely a generator has order n by [L3]. So the primitive n-th roots of unity in K are exactly the generators of μn(K), and [L4] counts them as φ(n).

Remarks

TheoremStatement: AI-adaptedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

tn−1 is separable over K exactly when the characteristic does not divide n, and then a splitting field carries n distinct n-th roots of unity

Statement

Let K be a field and n≥1. Then

tn−1 is separable over K⟺char⁡K∤n

(Repeated roots in extension fields and separable polynomials, The characteristic of a ring: the least n≥1 with n⋅1R=0 when one exists, and 0 otherwise; divisibility of integers being that of Divisibility in Z: d∣a when a=dq for some integer q, under which 0∣n holds only for n=0, so characteristic 0 never divides n≥1).

When char⁡K∤n and E is a splitting field of tn−1 over K, the group μn(E) is cyclic of order exactly n, it contains exactly φ(n) primitive n-th roots of unity, and

E=K(ζ)

for every primitive n-th root of unity ζ∈E.

Facts & Assumptions

Given: A field K, an integer n≥1, the polynomial f:=tn−1∈K[t], and the element n⋅1K obtained by adding 1K to itself n times.

[L1]

f′=∑i≥1iaixi−1 for f=∑iaixi (The formal derivative of a polynomial); (xk)′=kxk−1 for k≥1 and constants have derivative 0, and the derivative is additive (Linearity, power rule, Leibniz rule and the degree bound for the formal derivative). Hence f′=(n⋅1K) tn−1.

[L2]

For a field F and 0≠f∈F[x]: f is separable over F if and only if gcd⁡(f,f′)=1 in F[x] (A nonzero polynomial over a field is separable exactly when its gcd with its derivative is 1).

[L3]

For f,g∈F[x] not both zero, d=gcd⁡(f,g) is monic, divides both f and g, and every common divisor of f and g divides d (Bézout identity and the Euclidean algorithm for polynomials over a field).

[L5]

Every nonzero f∈K[x] has a splitting field over K (Every nonzero polynomial over a field has a splitting field); f of degree m splits over E when f=c∏j=1m(t−αj) with c∈K× and αj∈E, repetitions allowed, and a splitting field is generated over K by the roots (Polynomials that split and splitting fields of a polynomial or a family of polynomials), the notation K(S) for the subfield generated by K and a finite set S being that of Finitely generated field extensions F(a1,…,ar).

[L6]

μn(F) is a finite cyclic subgroup of F× of order dividing n; it contains a primitive n-th root of unity exactly when its order is n, and there are then φ(n) of them, namely the generators (μn(K) is cyclic of order dividing n, and has a primitive n-th root of unity exactly when its order is n, The group μn(K) of n-th roots of unity in a field, and primitive n-th roots of unity, The unit group (Z/n)× and Euler's totient φ(n)=∣(Z/n)×∣ for n≥1).

[L7]

f is separable over K when it has no repeated root in any extension field of K, where a is a repeated root of f in E when (t−a)2 divides the image of f in E[t] (Repeated roots in extension fields and separable polynomials).

Proof

technique · cases
1.1assume-case posL1L2L3

In the case n⋅1K≠0, put d:=gcd⁡(f,f′). By [L1] f′=(n⋅1K)tn−1 with n⋅1K a unit of K, so d∣tn−1 by [L3], hence d∣t⋅tn−1=tn; and d∣f=tn−1, so d divides tn−(tn−1)=1 and, being monic, d=1. By [L2] the polynomial f is separable over K.

1.2assume-case zeroL1L2L3

In the case n⋅1K=0, [L1] gives f′=0, so every polynomial dividing f is a common divisor of f and f′; by [L3] the monic gcd⁡(f,0) is divisible by every such divisor and divides f, so it is f itself, of degree n≥1. Thus gcd⁡(f,f′)≠1 and f is not separable over K by [L2].

2.1step 1.1step 1.2L4cases-exhaustive

The two cases are exhaustive and, by [L4], n⋅1K≠0 says exactly char⁡K∤n; so f is separable over K if and only if char⁡K∤n.

3.1step 2.1L5

Assume now char⁡K∤n and let E be a splitting field of f over K, which exists by [L5]. Over E one has f=c∏j=1n(t−αj) with αj∈E, and comparing leading coefficients of the monic f gives c=1.

4.1step 2.1step 3.1L7

The αj are pairwise distinct: if αi=αj for i≠j then (t−αi)2 divides f in E[t], making αi a repeated root of f in the extension E of K, which contradicts the separability supplied by step 2.1 through [L7].

5.1step 3.1step 4.1L6

Hence f has exactly n distinct roots in E, that is ∣μn(E)∣=n; by [L6] the group μn(E) is cyclic of order n and contains exactly φ(n) primitive n-th roots of unity.

6.1step 5.1L5L6∎

Fix such a ζ. Every root of f in E lies in μn(E)=⟨ζ⟩, so is a power of ζ; since E is generated over K by those roots by [L5], E=K(ζ). At n=1 the polynomial is t−1, μ1(E)={1}, φ(1)=1, ζ=1 and E=K.

Remarks

  • The failing direction is inseparability, not a shortage of roots. When char⁡K=p divides n, the derivative vanishes identically and no extension can separate the roots: writing n=pkm with p∤m, one has μn=μm in every field of characteristic p (In characteristic p the only pk-th root of unity is 1, and tpk−1=(t−1)pk). Passing to a larger field does not help, which is why the hypothesis is carried on every later statement rather than removed by enlarging K.
PropositionStatement: Literature-sourcedProof: AI-adaptedprecheck passaudited 2026-08-26Open item page →

In characteristic p the only pk-th root of unity is 1, and tpk−1=(t−1)pk

Statement

Let K be a field of characteristic p>0 (The characteristic of a ring: the least n≥1 with n⋅1R=0 when one exists, and 0 otherwise; p is prime by The characteristic of a field is zero or a prime number) and let k≥1. Then in K[t] (The polynomial ring over a commutative ring as finitely supported coefficient sequences with convolution)

tpk−1=(t−1)pk,

and consequently μpk(K)={1} (The group μn(K) of n-th roots of unity in a field, and primitive n-th roots of unity).

More generally, if k≥0 and m≥1 with p∤m (Divisibility in Z: d∣a when a=dq for some integer q), and if n:=pkm, then

μn(K)=μm(K).

Facts & Assumptions

Given: A field K of characteristic p>0, so that p⋅1K=0K and hence j⋅c=(j⋅1K)c=0 for every c∈K[t] and every integer j divisible by p; and an integer k≥1.

[L1]

For a commutative ring R, all x,y∈R and n∈N, (x+y)n=∑j=0n(nj)xjyn−j, the natural-number coefficients acting by repeated addition (The binomial theorem over an arbitrary commutative ring).

[L2]

If p is prime and 0<j<p, then p∣(pj) (A prime p divides (pk) for 0<k<p).

Proof

technique · direct
1.1L1L2given

For every u∈K[t] one has (u−1)p=up−1: by [L1] applied in the commutative ring K[t], (u+(−1))p=∑j=0p(pj)uj(−1)p−j; for 0<j<p the coefficient (pj) is a multiple of p by [L2], so that term vanishes by the hypothesis on K; the surviving terms are up and (−1)p, and (−1)p=−1 for odd p while for p=2 one has 1=−1 in K, so (−1)p=−1 in either case.

2.1step 1.1algebra

Hence (t−1)pk=tpk−1 for every k≥1, by induction on k: at k=1 this is step 1.1 with u=t; and if it holds at k, then (t−1)pk+1=((t−1)pk)p=(tpk−1)p=tpk+1−1, the last equality being step 1.1 with u=tpk.

3.1step 2.1L3

Therefore μpk(K)={1}: an x∈K with xpk=1 is a root of tpk−1, so (x−1)pk=0 by step 2.1, and a field has no nonzero element with a vanishing power, so x=1; and 1pk=1.

4.1step 3.1L3algebra∎

Let k≥0 and m≥1 with p∤m, and put n=pkm. If xn=1 then (xm)pk=xn=1, so xm∈μpk(K), which is {1} by step 3.1 when k≥1 and is {1} trivially when k=0; either way xm=1. Conversely xm=1 gives xn=(xm)pk=1. Hence μn(K)=μm(K).

Remarks

  • This is why every later hypothesis reads "the characteristic does not divide n". Nothing is lost by it: the p-part of n contributes no roots of unity at all in characteristic p, so a statement about μn there is already a statement about μm for the prime-to-p part m. The hypothesis excludes a degenerate case rather than a genuine one.
DefinitionDefinition: Literature-sourcedProof: Not applicablejudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

The cyclotomic extension K(μn) as a splitting field of tn−1

Definition

Let K be a field and n≥1. A cyclotomic extension of K of order n is a splitting field E of tn−1 over K (Polynomials that split and splitting fields of a polynomial or a family of polynomials); one exists by Every nonzero polynomial over a field has a splitting field. It is written

K(μn):=E.

The notation is accurate. The roots of tn−1 in E are exactly the elements of μn(E) (The group μn(K) of n-th roots of unity in a field, and primitive n-th roots of unity), and a splitting field is generated over K by the roots, so

E=K(μn(E))

in the sense of Finitely generated field extensions F(a1,…,ar): E is the smallest subfield of itself containing K and the n-th roots of unity it holds.

When the characteristic does not divide n the extension has a single generator: by tn−1 is separable over K exactly when the characteristic does not divide n, and then a splitting field carries n distinct n-th roots of unity the group μn(E) is then cyclic of order n and

K(μn)=K(ζ)

for any primitive n-th root of unity ζ∈E. Without that hypothesis the notation still names a splitting field, but μn(E) can be much smaller than n and no primitive n-th root of unity need exist (In characteristic p the only pk-th root of unity is 1, and tpk−1=(t−1)pk).

Remarks

  • Which splitting field. Any two splitting fields of tn−1 over K are K-isomorphic (Any two splitting fields of a polynomial are isomorphic over the base field), and every statement made below about K(μn) is invariant under a K-isomorphism, so the definite article is harmless; where a fixed ambient field matters, as in the compositum and intersection results, the statement says so and works inside one chosen extension of K.
TheoremStatement: Literature-sourcedProof: Literature-sourcedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

K(μn)/K is Galois and σ↦aσ embeds its Galois group into (Z/n)×

Statement

Let K be a field and n≥1 with char⁡K∤n (The characteristic of a ring: the least n≥1 with n⋅1R=0 when one exists, and 0 otherwise), and let E=K(μn) (The cyclotomic extension K(μn) as a splitting field of tn−1). Then E/K is a finite Galois extension, and there is an injective group homomorphism

Gal⁡(E/K)⟶(Z/n)×,σ⟼[aσ]n,

where aσ is any integer with σ(ζ)=ζaσ for a primitive n-th root of unity ζ∈E. The class [aσ]n does not depend on which primitive n-th root of unity is used, and σ(x)=xaσ holds for every x∈μn(E).

Facts & Assumptions

Given: A field K, an integer n≥1 with char⁡K∤n, the extension E=K(μn) (The cyclotomic extension K(μn) as a splitting field of tn−1), and a primitive n-th root of unity ζ∈E (The group μn(K) of n-th roots of unity in a field, and primitive n-th roots of unity).

[L1]

For n≥1, tn−1 is separable over K when char⁡K∤n; in a splitting field E the group μn(E) is then cyclic of order n, has φ(n) primitive n-th roots of unity, and E=K(ζ) for every primitive n-th root of unity ζ∈E (tn−1 is separable over K exactly when the characteristic does not divide n, and then a splitting field carries n distinct n-th roots of unity).

[L2]

For a finite extension L/F with G=Aut⁡(L/F), the conditions "L/F is Galois", "L is the splitting field over F of a separable polynomial", "∣G∣=[L:F]" and "LG=F" are equivalent (Equivalent characterizations of a finite Galois extension, Finite Galois extensions and Gal⁡(K/F), Relative field automorphisms and Aut⁡(K/F)).

[L3]

μn(E) is a finite cyclic subgroup of E× of order dividing n, and when its order is n its generators are exactly the primitive n-th roots of unity (μn(K) is cyclic of order dividing n, and has a primitive n-th root of unity exactly when its order is n).

[L4]

In a cyclic group ⟨g⟩ of finite order m, ga generates the group if and only if gcd⁡(a,m)=1 (A cyclic group of order n has exactly φ(n) generators).

[L6]

For n≥1 and a∈Z, the class [a]n∈Z/n (The congruence class [a]n and the quotient set Z/n) is a unit of Z/n if and only if gcd⁡(a,n)=1 (For n≥1, [a]n is a unit if and only if gcd⁡(a,n)=1); the units form the group (Z/n)× of order φ(n) (The unit group (Z/n)× and Euler's totient φ(n)=∣(Z/n)×∣ for n≥1).

[L7]

If a is algebraic over a field K, then the simple extension K(a)/K is finite, with degree equal to the degree of the minimal polynomial of a (A simple algebraic extension is its minimal-polynomial quotient and has power basis 1,a,…,an−1 and degree n).

Proof

technique · direct
1.1L1L2L3L7given

By [L1] the polynomial tn−1 is separable over K, the group μn(E) is cyclic of order n generated by ζ, and E=K(ζ). The element ζ is algebraic because it is a root of tn−1, so [L7] makes E/K finite. Since E is the splitting field of the separable polynomial tn−1, [L2] now makes E/K finite Galois.

2.1step 1.1given

Each σ∈Gal⁡(E/K) maps μn(E) into itself, since σ(x)n=σ(xn)=σ(1)=1; being injective on the finite set μn(E) it restricts to a bijection, and it is multiplicative, so it restricts to a group automorphism of μn(E).

3.1step 1.1step 2.1L4L5L6

Hence σ(ζ) generates μn(E)=⟨ζ⟩, so σ(ζ)=ζa for some integer a, and [L4] gives gcd⁡(a,n)=1, so [a]n∈(Z/n)× by [L6]. The class is well defined: ζa=ζb means ζa−b=1, which by [L5] and ord⁡(ζ)=n says n∣a−b, that is [a]n=[b]n. Write [aσ]n for this class.

4.1step 1.1step 3.1

For every x∈μn(E) one has x=ζj for some j, so σ(x)=σ(ζ)j=ζaσj=xaσ.

4.2step 3.1L6

The map σ↦[aσ]n is a group homomorphism: (στ)(ζ)=σ(ζaτ)=σ(ζ)aτ=ζaσaτ, so [aστ]n=[aσ]n[aτ]n by the well-definedness of step 3.1.

4.3step 1.1step 3.1

It is injective: if [aσ]n=[1]n then σ(ζ)=ζ by step 3.1, and since E=K(ζ) and σ fixes K pointwise, σ is the identity on E.

5.1step 1.1step 3.1step 4.1step 4.2step 4.3L3∎

The class is independent of the chosen primitive n-th root of unity: any other one is a generator ζ′ of μn(E) by [L3], so ζ′=ζb for some b, and σ(ζ′)=σ(ζ)b=ζaσb=(ζb)aσ=(ζ′)aσ, which exhibits the same exponent class. With steps 4.1, 4.2 and 4.3 this proves the theorem.

Remarks

CorollaryStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

The Galois group of a cyclotomic extension is abelian

Statement

Facts & Assumptions

Given: A field K and n≥1 with char⁡K∤n.

[L1]

K(μn)/K is finite Galois and σ↦[aσ]n is an injective group homomorphism Gal⁡(K(μn)/K)→(Z/n)× (K(μn)/K is Galois and σ↦aσ embeds its Galois group into (Z/n)×).

Proof

technique · direct
1.1L2

Multiplication on Z/n is commutative by [L2], so the group (Z/n)×, whose operation is that multiplication restricted to the units, is abelian.

2.1step 1.1L1∎

By [L1] the group Gal⁡(K(μn)/K) is isomorphic to its image in (Z/n)×, a subgroup of an abelian group; a subgroup of an abelian group is abelian, and a group isomorphic to an abelian group is abelian, so Gal⁡(K(μn)/K) is abelian.

TheoremStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

For gcd⁡(n,q)=1 the image of Gal⁡(Fq(μn)/Fq) in (Z/n)× is generated by [q]

Statement

Let Fq be a finite field of order q (Finite fields and their order) and let n≥1 with gcd⁡(n,q)=1 (Coprime integers: gcd⁡(a,b)=1). Then the image of the embedding

Gal⁡(Fq(μn)/Fq)⟶(Z/n)×

of K(μn)/K is Galois and σ↦aσ embeds its Galois group into (Z/n)× is the cyclic subgroup generated by [q]n, and

[Fq(μn):Fq]=ord⁡([q]n),

the multiplicative order of [q]n in (Z/n)× (The order ∣G∣ of a finite group and the order ord⁡(g) of an element, with ord⁡(g)=∞ when no positive power of g is the identity).

Facts & Assumptions

Given: A finite field Fq of order q, of characteristic p with q a power of p (Every finite field has order pn for a unique prime characteristic p and positive integer n), and an integer n≥1 with gcd⁡(n,q)=1; the extension E:=Fq(μn) (The cyclotomic extension K(μn) as a splitting field of tn−1).

[L1]

For a field K and n≥1 with char⁡K∤n, the extension K(μn)/K is finite Galois and σ↦[aσ]n, determined by σ(ζ)=ζaσ on a primitive n-th root of unity, is an injective homomorphism into (Z/n)× with σ(x)=xaσ for every x∈μn (K(μn)/K is Galois and σ↦aσ embeds its Galois group into (Z/n)×).

[L2]

An extension L/Fq of finite fields of degree m is Galois with Gal⁡(L/Fq)=⟨σq⟩ cyclic of order m, where σq(x)=xq (A finite extension of a finite field of order q is Galois with cyclic Galois group generated by x↦xq, The relative Frobenius x↦xq of an extension of finite fields).

[L3]
[L4]

For a finite Galois extension L/F one has ∣Gal⁡(L/F)∣=[L:F] (Equivalent characterizations of a finite Galois extension, The degree [K:F]=dim⁡FK of a finite field extension).

Proof

technique · direct
1.1L1L3given

The characteristic p divides q, and gcd⁡(n,q)=1, so p∤n; hence [L1] applies to K=Fq and E=Fq(μn) is finite Galois over Fq. Also [q]n is a unit of Z/n by [L3].

2.1step 1.1L2

E is a finite field: it is a finite extension of the finite field Fq by step 1.1, so it is a finite-dimensional Fq-vector space over a finite field and therefore has finitely many elements. By [L2], Gal⁡(E/Fq)=⟨σq⟩ with σq(x)=xq.

3.1step 1.1step 2.1L1

The exponent attached to σq by [L1] is [q]n, since σq(ζ)=ζq for a primitive n-th root of unity ζ∈E. Because the embedding is a homomorphism and Gal⁡(E/Fq) is generated by σq, the image is the subgroup of (Z/n)× generated by [q]n.

4.1step 3.1L1L4∎

The embedding is injective, so ∣Gal⁡(E/Fq)∣ equals the order of ⟨[q]n⟩, which is ord⁡([q]n); and [E:Fq]=∣Gal⁡(E/Fq)∣ by [L4]. Hence [E:Fq]=ord⁡([q]n).

Remarks

DefinitionDefinition: AI-adaptedProof: Not applicablejudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

The cyclotomic polynomials Φn∈Z[t], defined by ∏d∣nΦd=tn−1

Definition

The cyclotomic polynomials Φn∈Z[t] (The polynomial ring over a commutative ring as finitely supported coefficient sequences with convolution) are defined by recursion on n≥1:

Φ1:=t−1,Φn:=tn−1∏d∣n0<d<nΦd(n≥2),

the divisors being the positive divisors of n (Divisibility in Z: d∣a when a=dq for some integer q). The product is formed in the commutative ring Z[t] (Polynomial convolution makes R[x] a commutative ring containing R as its constant subring): multiply the finitely many factors in any enumeration of the divisor set. Associativity and commutativity make the result independent of that enumeration.

What the fraction means. The denominator Pn:=∏d∣n, d<nΦd is a product of monic polynomials in Z[t], hence itself monic (Degree, leading coefficient and monic polynomial, with the zero polynomial having no degree), so Division by a monic polynomial over a commutative ring supplies a unique pair q,r∈Z[t] with tn−1=qPn+r and r=0 or deg⁡r<deg⁡Pn. The definition sets Φn:=q, and asserts r=0. That assertion, together with the consequences that each Φn is monic of degree φ(n) and that

∏d∣nΦd=tn−1

for every n≥1, is discharged by The recursion defines a unique monic Φn∈Z[t], of degree φ(n) ↗, which is why that theorem is a numbered result and not a parenthesis: the division is carried out over Z, not over a field, so exactness is a statement about integer coefficients and does not follow from the division algorithm.

Remarks

TheoremStatement: AI-adaptedProof: AI-adaptedprecheck passaudited 2026-08-26Open item page →

The recursion defines a unique monic Φn∈Z[t], of degree φ(n)

Statement

The recursion of The cyclotomic polynomials Φn∈Z[t], defined by ∏d∣nΦd=tn−1 is well posed: for every n≥1 the division defining Φn is exact, Φn is a monic element of Z[t],

∏d∣nΦd=tn−1,

the product being over the positive divisors of n, and

deg⁡Φn=φ(n)

(The unit group (Z/n)× and Euler's totient φ(n)=∣(Z/n)×∣ for n≥1). Moreover (Φn)n≥1 is the only family of monic polynomials in Z[t] satisfying the displayed product identity for every n≥1.

Facts & Assumptions

Given: The recursion of The cyclotomic polynomials Φn∈Z[t], defined by ∏d∣nΦd=tn−1; the field Q, which is an ordered field (The rationals form a totally ordered field), so that m⋅1>0 and in particular m⋅1≠0 for every m≥1, whence char⁡Q=0 (The characteristic of a ring: the least n≥1 with n⋅1R=0 when one exists, and 0 otherwise) and char⁡Q divides no n≥1 (Divisibility in Z: d∣a when a=dq for some integer q).

[L1]

Let R be a commutative ring and g∈R[x] monic. For every f∈R[x] there are unique q,r∈R[x] with f=qg+r and r=0 or deg⁡r<deg⁡g (Division by a monic polynomial over a commutative ring).

[L3]

Every nonzero f∈K[x] has a splitting field over K (Every nonzero polynomial over a field has a splitting field); f monic of degree m splits over E when f=∏j=1m(t−αj) with αj∈E, repetitions allowed (Polynomials that split and splitting fields of a polynomial or a family of polynomials).

[L4]

f is separable over K when it has no repeated root in any extension field, a repeated root of f in E being an a with (t−a)2 dividing the image of f in E[t] (Repeated roots in extension fields and separable polynomials).

[L7]

If R is an integral domain then so is R[x] (A polynomial ring over an integral domain is an integral domain), and for nonzero f,g one has deg⁡(fg)=deg⁡f+deg⁡g and lc⁡(fg)=lc⁡(f)lc⁡(g) (Over an integral domain, degrees add under multiplication of nonzero polynomials, Degree, leading coefficient and monic polynomial, with the zero polynomial having no degree).

Proof

technique · induction
1.1basegiven

The assertion to be proved by strong induction on n is: the division defining Φn is exact, Φn∈Z[t] is monic, ∏d∣nΦd=tn−1, and deg⁡Φn=φ(n). At n=1 the recursion sets Φ1=t−1 outright, the only positive divisor of 1 is 1 so the product is Φ1=t−1, and deg⁡Φ1=1=φ(1).

1.2ih

Inductive hypothesis: fix n≥2 and assume the assertion for every m with 1≤m<n.

1.3L2L3given

Since char⁡Q=0 does not divide n, [L2] and [L3] supply a splitting field E of tn−1 over Q in which tn−1 is separable and μn(E) is cyclic of order n. For a positive divisor d of n put Sd:={ζ∈μn(E):ord⁡(ζ)=d} and Ψd:=∏ζ∈Sd(t−ζ)∈E[t], a monic polynomial of degree ∣Sd∣.

2.1step 1.3L3L4algebra

For every positive divisor m of n one has tm−1=∏ζ∈μm(E)(t−ζ) with ∣μm(E)∣=m: the polynomial tm−1 divides tn−1 in Z[t], since tn−1=(tm−1)(tn−m+tn−2m+⋯+1) when m∣n, so it splits over E by [L3], and a repeated root of tm−1 in an extension would be a repeated root of tn−1 there, which [L4] excludes; hence its m roots are distinct and they are by definition the elements of μm(E).

3.1step 1.3step 2.1L5

For every positive divisor m of n, μm(E) is the disjoint union of the Sd over positive divisors d of m: an element ζ∈μn(E) has finite order dividing n, and ζm=1 holds exactly when ord⁡(ζ)∣m by [L5]. Hence ∏d∣mΨd=∏ζ∈μm(E)(t−ζ)=tm−1 by step 2.1.

4.1step 1.2step 3.1L7

For every positive divisor d of n with d<n one has Φd=Ψd, by induction on d through the divisors of n: at d=1 both equal t−1, since S1={1}; and if Φe=Ψe for every positive divisor e of d with e<d, then step 1.2 and step 3.1 give (∏e∣d, e<dΨe)Φd=td−1=(∏e∣d, e<dΨe)Ψd, and cancelling the nonzero left factor in the integral domain E[t] ([L7]) yields Φd=Ψd.

5.1step 1.2step 3.1step 4.1L7

Write P:=∏d∣n, d<nΦd, monic in Z[t] by step 1.2 and [L7]. By step 4.1 and step 3.1 applied with m=n, in E[t] one has tn−1=(∏d∣n, d<nΨd)Ψn=P Ψn.

6.1step 5.1L1L7

The division of tn−1 by P in Z[t] is exact and its quotient is Ψn: by [L1] over Z there are unique q,r∈Z[t] with tn−1=qP+r and r=0 or deg⁡r<deg⁡P; this is also a division by the monic P in E[t], where step 5.1 exhibits the division with quotient Ψn and remainder 0, so the uniqueness clause of [L1] over E forces q=Ψn and r=0. Hence Φn=q=Ψn is monic in Z[t] and ∏d∣nΦd=PΦn=tn−1.

7.1step 1.2step 6.1L6L7

Degrees: taking degrees in tn−1=PΦn with [L7] gives n=deg⁡P+deg⁡Φn, and deg⁡P=∑d∣n, d<ndeg⁡Φd=∑d∣n, d<nφ(d) by step 1.2 and [L7]; so deg⁡Φn=n−∑d∣n, d<nφ(d)=φ(n) by [L6].

8.1step 6.1step 7.1L7discharge-induction∎

This is the assertion at n, so the strong induction is complete and the assertion holds for every n≥1. Uniqueness of the family follows by the same induction: if (Φm′)m≥1 is monic in Z[t] with ∏d∣mΦd′=tm−1 for all m, then Φ1′=t−1=Φ1, and if Φm′=Φm for all m<n then PΦn′=tn−1=PΦn with P≠0 in the integral domain Z[t] ([L7]), so Φn′=Φn.

Remarks

LemmaStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

Φ1(0)=−1 and Φn(0)=1 for n≥2

Statement

For the cyclotomic polynomials of The cyclotomic polynomials Φn∈Z[t], defined by ∏d∣nΦd=tn−1,

Φ1(0)=−1,Φn(0)=1  for every n≥2.

Facts & Assumptions

Given: The cyclotomic polynomials Φn∈Z[t] and their defining identity; evaluation at 0 is as in Evaluation and roots of a polynomial in a commutative target ring.

[L2]

Evaluation at an element of a commutative ring is a unital ring homomorphism Z[t]→Z (Universal property of R[x]: a coefficient homomorphism and the image of x determine a unique ring homomorphism), so it carries finite products to finite products.

Proof

technique · induction
1.1baseL1L2given

Φ1=t−1 by The cyclotomic polynomials Φn∈Z[t], defined by ∏d∣nΦd=tn−1, so Φ1(0)=−1; this is also the base of the induction below, taken at n=2, where [L1] and [L2] give Φ1(0) Φ2(0)=02−1=−1, hence −Φ2(0)=−1 and Φ2(0)=1.

1.2ih

Inductive hypothesis: fix n≥3 and assume Φm(0)=1 for every m with 2≤m<n.

2.1step 1.1L1L2

Evaluating the identity of [L1] at 0 and using [L2] gives ∏d∣nΦd(0)=−1; separating the factor d=1, which is −1 by step 1.1, leaves ∏d∣n, d>1Φd(0)=1.

3.1step 1.2step 2.1discharge-induction∎

Every factor with 1<d<n equals 1 by step 1.2, so the product reduces to Φn(0)=1, which is the assertion at n; the induction is complete and Φn(0)=1 for every n≥2.

Remarks

TheoremStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

Over a field whose characteristic does not divide n, the roots of Φn are exactly the primitive roots of unity

Statement

Facts & Assumptions

Given: A field K, an integer n≥1 with char⁡K∤n, a splitting field E of tn−1 over K, and the convention that for every finite subset T⊆E the product ∏ζ∈T(t−ζ)∈E[t] means the finite product along any enumeration of T; because E[t] is a commutative ring, the value is independent of the enumeration (The product g0g1⋯gn−1 of a finite list in a monoid, by recursion, with the empty product (n=0) equal to the identity, Generalised associativity: in a monoid the product of a finite list does not depend on the bracketing, and in a commutative monoid it does not depend on the order of the factors either, Polynomial convolution makes R[x] a commutative ring containing R as its constant subring). In particular, for each positive divisor d of n, let Sd:={ζ∈μn(E):ord⁡(ζ)=d} and Ψd:=∏ζ∈Sd(t−ζ)∈E[t].

[L2]

For every m≥1 one has ∏d∣mΦd=tm−1 in Z[t], each Φd monic of degree φ(d) (The recursion defines a unique monic Φn∈Z[t], of degree φ(n)); reduction into K[t] preserves this identity.

[L3]

A monic f of degree m splits over E when f=∏j=1m(t−αj) with αj∈E, repetitions allowed, and a splitting field is generated over K by the roots (Polynomials that split and splitting fields of a polynomial or a family of polynomials).

[L4]

f is separable over K when no extension field of K contains an a with (t−a)2 dividing the image of f (Repeated roots in extension fields and separable polynomials).

[L6]

R[x] is an integral domain when R is (A polynomial ring over an integral domain is an integral domain); and f(a)=0 if and only if x−a divides f (Factor theorem over a commutative ring).

Proof

technique · direct
1.1L1L3

By [L1] the polynomial tn−1 is separable over K and μn(E) is cyclic of order n; so tn−1 has n distinct roots in E, namely the elements of μn(E), and tn−1=∏ζ∈μn(E)(t−ζ) by [L3].

1.2L5given

Each ζ∈μn(E) has order dividing n by [L5], and for a positive divisor m of n the condition ζm=1 says exactly ord⁡(ζ)∣m; so μm(E) is the disjoint union of the Sd over positive divisors d of m.

2.1step 1.1L3L4algebra

For every positive divisor m of n the polynomial tm−1 divides tn−1 in Z[t], since tn−1=(tm−1)(tn−m+tn−2m+⋯+1); hence it splits over E with distinct roots, which are the elements of μm(E), and tm−1=∏ζ∈μm(E)(t−ζ) with ∣μm(E)∣=m.

3.1step 2.1step 1.2

Consequently ∏d∣mΨd=∏ζ∈μm(E)(t−ζ)=tm−1 for every positive divisor m of n.

4.1step 3.1L2L6

For every positive divisor d of n the image of Φd in E[t] is Ψd, by induction on d through the divisors of n: at d=1 both are t−1, since S1={1}; and if the claim holds for every positive divisor e of d with e<d, then [L2] and step 3.1 give (∏e∣d, e<dΨe)Φd=td−1=(∏e∣d, e<dΨe)Ψd, and cancelling the nonzero left factor in the integral domain E[t] ([L6]) gives Φd=Ψd.

5.1step 4.1L1L2

Taking d=n: the image of Φn in E[t] is ∏ζ∈Sn(t−ζ), so Φn splits over E and its roots there are exactly the elements of Sn, which are the elements of order n in μn(E), that is the primitive n-th roots of unity in E; there are φ(n) of them by [L1], in agreement with deg⁡Φn=φ(n) from [L2].

6.1L1L2L4algebra∎

Φn is separable over K. The product identity [L2] shows that the image of Φn divides tn−1 in K[t]. If an extension field L/K contained an a for which (t−a)2 divided the image of Φn, then the same square would divide the image of tn−1 in L[t], making a a repeated root of tn−1. This contradicts the separability of tn−1 supplied by [L1]. Thus [L4] applies.

Remarks

PropositionStatement: Literature-sourcedProof: Literature-sourcedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

Φn is irreducible over K exactly when [K(ζn):K]=φ(n), exactly when the embedding into (Z/n)× is onto

Statement

Facts & Assumptions

Given: A field K, an integer n≥1 with char⁡K∤n, the extension E=K(μn), a primitive n-th root of unity ζ∈E, and the minimal polynomial mζ∈K[t] of ζ over K.

[L1]

The image of Φn in K[t] has as its roots in E exactly the primitive n-th roots of unity in E (Over a field whose characteristic does not divide n, the roots of Φn are exactly the primitive roots of unity).

[L3]

For a algebraic over K there is a unique monic irreducible ma∈K[t] with f(a)=0 if and only if ma∣f (The evaluation kernel and the unique monic irreducible minimal polynomial of an algebraic element).

[L4]

If a is algebraic over K with minimal polynomial of degree m, then [K(a):K]=m (A simple algebraic extension is its minimal-polynomial quotient and has power basis 1,a,…,an−1 and degree n).

[L5]

For this n≥1, E/K is finite Galois and σ↦[aσ]n is an injective homomorphism Gal⁡(E/K)→(Z/n)× (K(μn)/K is Galois and σ↦aσ embeds its Galois group into (Z/n)×); moreover E=K(ζ) for every primitive n-th root ζ (tn−1 is separable over K exactly when the characteristic does not divide n, and then a splitting field carries n distinct n-th roots of unity).

[L6]

∣(Z/n)×∣=φ(n) (The unit group (Z/n)× and Euler's totient φ(n)=∣(Z/n)×∣ for n≥1), and ∣Gal⁡(E/K)∣=[E:K] for a finite Galois extension (Equivalent characterizations of a finite Galois extension).

[L7]

In an integral domain, an irreducible element is a nonzero nonunit every one of whose factorisations has a unit factor (Irreducible and prime elements of an integral domain).

Proof

technique · direct
1.1L1L2L3

ζ is a root of the image of Φn in K[t] by [L1], so mζ divides that image by [L3]; both are monic, and mζ has positive degree because ζ≠0 is not a root of a nonzero constant. Write the image of Φn as mζ g with g∈K[t] monic.

1.2L5L6

For the equivalence of clauses 2 and 3: by [L5] one has E=K(ζ) and the embedding is injective into a group of order φ(n) by [L6], so it is surjective if and only if ∣Gal⁡(E/K)∣=φ(n); and ∣Gal⁡(E/K)∣=[E:K]=[K(ζ):K] by [L6]. An injective homomorphism onto its target is an isomorphism.

2.1step 1.1L2L4L7

For the implication from clause 1 to clause 2: if the image of Φn is irreducible, then in the factorisation of step 1.1 one factor is a unit by [L7], and mζ is not, so g is a nonzero constant; both mζg and mζ being monic forces g=1 and mζ=Φn. Hence [K(ζ):K]=deg⁡mζ=φ(n) by [L2] and [L4].

2.2step 1.1L2L3L4

For the implication from clause 2 to clause 1: if [K(ζ):K]=φ(n) then deg⁡mζ=φ(n)=deg⁡Φn by [L2] and [L4], so g in step 1.1 is monic of degree 0, that is g=1 and the image of Φn equals mζ, which is irreducible by [L3].

3.1step 2.1step 2.2step 1.2∎

Steps 2.1 and 2.2 give the equivalence of clauses 1 and 2, and step 1.2 the equivalence of clauses 2 and 3; so all three are equivalent.

Remarks

PropositionStatement: Literature-sourcedProof: Literature-sourcedprecheck passaudited 2026-08-26Open item page →

Φpr(t)=∑k<ptkpr−1, and Φpr(t+1) is Eisenstein at p

Statement

Let p be a prime (Prime and composite integers: p is prime when p>1 and its only positive divisors are 1 and p) and r≥1. Then

Φpr(t)=∑k=0p−1tkpr−1=tpr−1tpr−1−1,

the polynomial Φpr(t+1)∈Z[t] satisfies the Eisenstein criterion at p (Eisenstein criterion over the integers), and consequently Φpr is irreducible in Q[t] (Irreducible and prime elements of an integral domain).

The sum starts at k=0: its first term is the constant 1, and evaluation at t=1 (Evaluation and roots of a polynomial in a commutative target ring) gives Φpr(1)=p.

Facts & Assumptions

Given: A prime p and an integer r≥1; the cyclotomic polynomials of The cyclotomic polynomials Φn∈Z[t], defined by ∏d∣nΦd=tn−1 and the substitution homomorphisms of Universal property of R[x]: a coefficient homomorphism and the image of x determine a unique ring homomorphism, under which t↦t+1 is a ring automorphism of Z[t] and of Q[t] with inverse t↦t−1.

[L1]

For every n≥1, ∏d∣nΦd=tn−1 with each Φd monic in Z[t] of degree φ(d) (The recursion defines a unique monic Φn∈Z[t], of degree φ(n), Degree, leading coefficient and monic polynomial, with the zero polynomial having no degree).

[L2]

Let f=anxn+⋯+a0∈Z[x] be primitive with n≥1. If a prime p satisfies p∤an, p∣ai for every i<n, and p2∤a0, then f is irreducible in Q[x] (Eisenstein criterion over the integers).

[L3]

A nonzero integer polynomial is primitive exactly when no prime divides all of its coefficients (Content is the positive common divisor of the coefficients divisible by every common divisor, Content and primitive integer polynomials).

[L5]

φ(pk)=pk−pk−1 for every prime p and k≥1 (For a prime p and k≥1, φ(pk)=pk−pk−1).

[L7]

R[x] is an integral domain when R is (A polynomial ring over an integral domain is an integral domain).

Proof

technique · direct
1.1L6given

The positive divisors of pj are exactly p0,…,pj: a positive d dividing pj with d>1 has a prime divisor q by [L6], and q∣pj forces q∣p by [L6], hence q=p since p is prime and q>1 (Prime and composite integers: p is prime when p>1 and its only positive divisors are 1 and p, Divisibility in Z: d∣a when a=dq for some integer q); writing d=pd′ gives d′∣pj−1 by cancellation, and repeating reduces d to a power of p not exceeding pj.

2.1step 1.1L1

By [L1] at n=pr and at n=pr−1, using step 1.1, ∏j=0rΦpj=tpr−1 and ∏j=0r−1Φpj=tpr−1−1; dividing, (tpr−1−1)Φpr=tpr−1.

3.1step 2.1L7algebra

With u:=tpr−1 the elementary identity (u−1)∑k=0p−1uk=up−1 gives (tpr−1−1)∑k=0p−1tkpr−1=tpr−1; comparing with step 2.1 and cancelling the nonzero factor tpr−1−1 in the integral domain Z[t] ([L7]) yields Φpr=∑k=0p−1tkpr−1.

3.2step 2.1L4L7

Reducing step 2.1 modulo p and applying [L4] twice in (Z/p)[t] gives Φpr‾ (t−1)pr−1=(t−1)pr, and cancelling in the integral domain (Z/p)[t] ([L7]) gives Φpr‾=(t−1)pr−pr−1.

4.1step 3.1algebra

Evaluating step 3.1 at t=1 gives Φpr(1)=p, since the sum has p terms each equal to 1; so the constant term of Φpr(t+1) is p, which is divisible by p and not by p2.

4.2step 3.2L1L5given

Substituting t+1, which commutes with reduction modulo p because both are ring homomorphisms fixing the coefficients appropriately, gives Φpr(t+1)‾=tpr−pr−1=tφ(pr) by [L5]. So every coefficient of Φpr(t+1) other than the leading one is divisible by p, while the leading coefficient is 1 because Φpr(t+1) is monic of degree φ(pr) by [L1] and the substitution being degree preserving.

5.1step 4.1step 4.2L2L3L5

Φpr(t+1) is primitive by [L3], no prime dividing its leading coefficient 1, and its degree φ(pr) is at least 1 by [L5]; steps 4.1 and 4.2 supply the three Eisenstein conditions at p, so [L2] makes it irreducible in Q[t].

6.1step 5.1given∎

The substitution t↦t−1 is a ring automorphism of Q[t] carrying Φpr(t+1) to Φpr; a ring automorphism preserves units and factorisations, so it carries irreducible elements to irreducible elements, and Φpr is irreducible in Q[t].

Remarks

  • The term k=0 is load bearing. Dropping it would change Φpr(1) from p to p−1, and the Eisenstein constant-term condition would fail. The highest exponent would be unchanged, so the degree alone would not detect the wrong polynomial.

  • A self-contained route for prime powers. This gives irreducibility over Q for n a prime power without the general argument of Φn is irreducible in Q[t] for every n≥1, and unlike that argument it exhibits an explicit polynomial to which a named criterion applies. The general theorem covers every n and does not supersede this computation; the companion page works out the case p=7 in Φ7(t+1) is Eisenstein at seven ↗.

LemmaStatement: Literature-sourcedProof: Literature-sourcedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

If p is a prime not dividing n, a rational minimal polynomial of a primitive n-th root of unity also kills its p-th power

Statement

Let n≥1, let E be a splitting field of tn−1 over Q, let ζ∈E be a primitive n-th root of unity (The group μn(K) of n-th roots of unity in a field, and primitive n-th roots of unity), let f∈Q[t] be the minimal polynomial of ζ over Q (The evaluation kernel and the unique monic irreducible minimal polynomial of an algebraic element), and let p be a prime (Prime and composite integers: p is prime when p>1 and its only positive divisors are 1 and p) with p∤n (Divisibility in Z: d∣a when a=dq for some integer q). Then

f(ζp)=0.

Facts & Assumptions

Given: The data of the statement; Q is an ordered field (The rationals form a totally ordered field), so m⋅1>0 and in particular m⋅1≠0 for every m≥1, whence char⁡Q=0 (The characteristic of a ring: the least n≥1 with n⋅1R=0 when one exists, and 0 otherwise), which divides no n≥1, so tn−1 is separable over Q and μn(E) is cyclic of order n generated by ζ (tn−1 is separable over K exactly when the characteristic does not divide n, and then a splitting field carries n distinct n-th roots of unity, μn(K) is cyclic of order dividing n, and has a primitive n-th root of unity exactly when its order is n); Φn denotes the cyclotomic polynomial (The cyclotomic polynomials Φn∈Z[t], defined by ∏d∣nΦd=tn−1) and also its images in Q[t] and in (Z/p)[t], where reduction is the ring homomorphism of Universal property of R[x]: a coefficient homomorphism and the image of x determine a unique ring homomorphism and Z/p is a field (For every prime p, the two operations on Z/p make it a field).

[L2]

For a algebraic over a field K there is a unique monic irreducible ma∈K[t] with h(a)=0 if and only if ma∣h (The evaluation kernel and the unique monic irreducible minimal polynomial of an algebraic element).

[L3]

For a commutative ring R and monic g∈R[x], every h∈R[x] has unique q,r∈R[x] with h=qg+r and r=0 or deg⁡r<deg⁡g (Division by a monic polynomial over a commutative ring).

[L4]

For nonzero u,v∈Z[x], cont⁡(uv)=cont⁡(u)cont⁡(v) (The product of primitive integer polynomials is primitive, and contents multiply); content is the nonnegative gcd of the coefficients and primitive means content 1 (Content and primitive integer polynomials); a nonzero integer polynomial is primitive exactly when no prime divides all its coefficients (Content is the positive common divisor of the coefficients divisible by every common divisor).

[L5]

In a field L of characteristic p>0 the map x↦xp is a field endomorphism (Frobenius x↦xp is an injective endomorphism in characteristic p, and an automorphism for finite fields); and every c in a field with p elements satisfies cp=c (A field with q elements is the splitting field of xq−x over its prime subfield).

[L6]
[L7]

R[x] is an integral domain when R is (A polynomial ring over an integral domain is an integral domain), and h(a)=0 if and only if x−a divides h (Factor theorem over a commutative ring).

[L8]

In a cyclic group ⟨g⟩ of finite order m, ga generates the group if and only if gcd⁡(a,m)=1 (A cyclic group of order n has exactly φ(n) generators).

Proof

technique · contradiction
1.1assume-contra

Suppose, for contradiction, that f(ζp)≠0.

1.2L1L8given

ζp is again a primitive n-th root of unity: gcd⁡(p,n)=1 because p is prime and p∤n, so [L8] makes ζp a generator of μn(E), of order n. Hence Φn(ζp)=0 by [L1].

1.3L1L2

Since Φn(ζ)=0 by [L1], [L2] gives f∣Φn in Q[t]; write Φn=fg with g∈Q[t], monic because f and Φn are.

2.1step 1.3L1L4

Both f and g lie in Z[t]. Let b≥1 be least with bf∈Z[t] and d≥1 least with dg∈Z[t]; these exist because clearing denominators gives some such integer. If a prime q divided every coefficient of bf then q would divide its leading coefficient b, and (b/q)f would lie in Z[t], contradicting minimality; so bf is primitive by [L4], and likewise dg. Then [L4] gives cont⁡(bd Φn)=cont⁡((bf)(dg))=1, while cont⁡(bd Φn)=bdcont⁡(Φn)=bd because Φn is monic in Z[t] and hence primitive by [L4]; so bd=1 and b=d=1.

2.2step 1.1step 1.2step 1.3

From step 1.2 and step 1.3, 0=Φn(ζp)=f(ζp)g(ζp) in the field E, and f(ζp)≠0 by step 1.1, so g(ζp)=0.

3.1step 2.1step 2.2L2L3

Hence ζ is a root of the polynomial g(tp), so f∣g(tp) in Q[t] by [L2]; writing g(tp)=fh with h∈Q[t], the division of the monic g(tp)∈Z[t] by the monic f∈Z[t] has quotient and remainder in Z[t] by [L3], and by the uniqueness clause of [L3] read in Q[t] that quotient is h and the remainder is 0; so h∈Z[t].

4.1step 2.1step 3.1L6given

Reduce modulo p and let L be a splitting field of fˉ over Z/p, which exists by [L6]; fˉ is monic of the same degree as f, which is at least 1, so it has a root a∈L.

5.1step 3.1step 4.1L5

Evaluating the reduction of step 3.1 at a gives gˉ(ap)=fˉ(a)hˉ(a)=0. Writing gˉ=∑iciti with ci∈Z/p and using [L5] twice, gˉ(a)p=∑icipaip=∑ici(ap)i=gˉ(ap)=0, so gˉ(a)=0 because L is a field.

6.1step 1.1step 4.1step 5.1L1L6L7discharge-contradiction∎

Thus t−a divides both fˉ and gˉ in L[t] by [L7], so (t−a)2 divides fˉgˉ=Φn‾, which divides tn−1 in (Z/p)[t] by [L1]. Then a is a repeated root of tn−1 in the extension L of Z/p, contradicting [L6], since p∤n. The assumption of step 1.1 is therefore untenable and f(ζp)=0.

Remarks

  • Where p∤n is used. Twice, and both uses are essential: in step 1.2, to know that ζp is still primitive, and in step 6.1, to know that tn−1 is separable modulo p. If p divided n the reduction Φn‾ could genuinely have a repeated factor and the argument would produce no contradiction.

  • Why the passage to Z[t] is not cosmetic. Reduction modulo p is defined on integer polynomials, so the factorisation Φn=fg has to be known to happen over Z before step 4.1 can start. That is exactly what step 2.1 supplies, and it is where Gauss's content lemma enters.

TheoremStatement: Literature-sourcedProof: Literature-sourcedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

Φn is irreducible in Q[t] for every n≥1

Facts & Assumptions

Given: An integer n≥1; Q is an ordered field (The rationals form a totally ordered field), so m⋅1>0 and in particular m⋅1≠0 for m≥1, whence char⁡Q=0 (The characteristic of a ring: the least n≥1 with n⋅1R=0 when one exists, and 0 otherwise) and divides no n≥1 (Divisibility in Z: d∣a when a=dq for some integer q); a splitting field E of tn−1 over Q (Every nonzero polynomial over a field has a splitting field); a primitive n-th root of unity ζ∈E (The group μn(K) of n-th roots of unity in a field, and primitive n-th roots of unity); and f∈Q[t] the minimal polynomial of ζ over Q.

[L3]

For a algebraic over K there is a unique monic irreducible ma∈K[t] with h(a)=0 if and only if ma∣h (The evaluation kernel and the unique monic irreducible minimal polynomial of an algebraic element).

[L4]

If ξ is a primitive n-th root of unity in E, g∈Q[t] is its minimal polynomial and p is a prime with p∤n, then g(ξp)=0 (If p is a prime not dividing n, a rational minimal polynomial of a primitive n-th root of unity also kills its p-th power).

[L6]

In a cyclic group ⟨g⟩ of finite order m, ga generates the group if and only if gcd⁡(a,m)=1, that is when a and m are coprime (A cyclic group of order n has exactly φ(n) generators, Coprime integers: gcd⁡(a,b)=1).

[L7]

A nonzero polynomial of degree k over an integral domain has at most k distinct roots in it (A nonzero polynomial of degree n over an integral domain has at most n distinct roots).

Proof

technique · direct
1.1L2L3

ζ is a root of Φn by [L2], so f∣Φn in Q[t] by [L3], and f is monic and irreducible.

1.2L1L5L6given

Let ξ∈E be any primitive n-th root of unity. By [L1] it generates μn(E)=⟨ζ⟩, so ξ=ζa for some integer a, which may be taken with a≥1 after adding a multiple of n; and gcd⁡(a,n)=1 by [L6]. Write a=p1p2⋯ps as a product of primes by [L5], with s=0 when a=1. No pi divides n, since pi∣a and gcd⁡(a,n)=1.

2.1step 1.1step 1.2L3L4L6

Put ζ0:=ζ and ζj:=ζj−1 pj for 1≤j≤s, so that ζs=ζa=ξ. By induction on j, each ζj is a primitive n-th root of unity and f(ζj)=0: at j=0 this is the hypothesis on ζ and step 1.1; and given it at j−1, the polynomial f is monic irreducible and vanishes at the primitive n-th root of unity ζj−1, so f is the minimal polynomial of ζj−1 by [L3], whence f(ζj)=f(ζj−1 pj)=0 by [L4], while ζj is primitive by [L6] because gcd⁡(pj,n)=1.

3.1step 2.1L1L7

So f vanishes at every primitive n-th root of unity in E, of which there are φ(n) distinct ones by [L1]; hence deg⁡f≥φ(n) by [L7].

4.1step 1.1step 3.1L2L3∎

On the other hand f∣Φn with deg⁡Φn=φ(n) by [L2], so deg⁡f≤φ(n); therefore deg⁡f=φ(n), and f and Φn are monic with f∣Φn, so Φn=f is irreducible. At n=1 this reads Φ1=t−1, of degree φ(1)=1.

Remarks

CorollaryStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

[Q(ζn):Q]=φ(n) and Gal⁡(Q(μn)/Q)≅(Z/n)×

Facts & Assumptions

[L1]

Φn is irreducible in Q[t] for every n≥1 (Φn is irreducible in Q[t] for every n≥1).

[L2]

For a field K with char⁡K∤n and a primitive n-th root of unity ζ in a splitting field, irreducibility of the image of Φn in K[t], the equality [K(ζ):K]=φ(n), and surjectivity of the embedding Gal⁡(K(μn)/K)→(Z/n)× are equivalent (Φn is irreducible over K exactly when [K(ζn):K]=φ(n), exactly when the embedding into (Z/n)× is onto).

Proof

technique · direct
1.1L2given

Since char⁡Q=0 does not divide n, [L2] applies with K=Q.

2.1step 1.1L1L2∎

The image of Φn in Q[t] is Φn itself, irreducible by [L1]; so the first clause of [L2] holds, and therefore so do the other two: [Q(ζ):Q]=φ(n), and the embedding is onto, hence an isomorphism, being injective.

Remarks

TheoremStatement: AI-adaptedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

For gcd⁡(n,q)=1 the reduction of Φn in Fq[t] is a product of distinct monic irreducibles, each of degree the order of [q] modulo n

Statement

Let Fq be a finite field of order q and let n≥1 with gcd⁡(n,q)=1 (Coprime integers: gcd⁡(a,b)=1). Put d:=ord⁡([q]n), the multiplicative order of [q]n in (Z/n)× (The order ∣G∣ of a finite group and the order ord⁡(g) of an element, with ord⁡(g)=∞ when no positive power of g is the identity, The unit group (Z/n)× and Euler's totient φ(n)=∣(Z/n)×∣ for n≥1). Then the image of Φn in Fq[t] (The cyclotomic polynomials Φn∈Z[t], defined by ∏d∣nΦd=tn−1) is a product of pairwise distinct monic irreducible polynomials, each of degree d, and there are φ(n)/d of them.

Facts & Assumptions

[L1]

Over a field K with char⁡K∤n and a splitting field E of tn−1, the image of Φn in K[t] is separable, splits over E, and its roots in E are exactly the φ(n) primitive n-th roots of unity in E (Over a field whose characteristic does not divide n, the roots of Φn are exactly the primitive roots of unity, The group μn(K) of n-th roots of unity in a field, and primitive n-th roots of unity).

[L4]

For π∈Fq[t] monic irreducible of degree e with a root α in an extension field, Fq(α) is a finite field of order qe and [Fq(α):Fq]=e (A monic irreducible of degree d over Fq has the d distinct roots α,αq,…,αqd−1).

[L5]

F[x] is a unique factorisation domain for every field F (For every field F, F[x] is a unique factorisation domain); irreducible elements are as in Irreducible and prime elements of an integral domain.

[L6]

f is separable over K when no extension field contains an a with (t−a)2 dividing the image of f (Repeated roots in extension fields and separable polynomials).

[L7]

Over an integral domain, deg⁡(fg)=deg⁡f+deg⁡g for nonzero f,g (Over an integral domain, degrees add under multiplication of nonzero polynomials).

[L8]

In any field F, the group μn(F) is cyclic of order dividing n; if it contains a primitive n-th root of unity, then its order is n, and in that case its generators are exactly the primitive n-th roots of unity (μn(K) is cyclic of order dividing n, and has a primitive n-th root of unity exactly when its order is n).

Proof

technique · direct
1.1L1L3given

Since q is a power of p and gcd⁡(n,q)=1, the prime p does not divide n; so [L1] applies with K=Fq and the splitting field E=Fq(μn), and [L3] gives [E:Fq]=d.

1.2L2L5

By [L2] the polynomial Φˉn is monic of degree φ(n)≥1, so by [L5] it is a product of monic irreducible polynomials of Fq[t], say Φˉn=π1⋯πr with each πi monic irreducible.

2.1step 1.2L1L5

Each πi has a root in E. By [L1] the polynomial Φˉn splits over E into φ(n) distinct linear factors, and πi divides it; since E[t] is a unique factorisation domain by [L5], πi is, up to a unit, a product of some of those linear factors. Thus it has a root αi∈E, and αi is a primitive n-th root of unity by [L1].

3.1step 1.2step 2.1L1L5L6

No two of the πi coincide. If πi=πj=π for i≠j, then π2 divides Φˉn. By step 2.1 the polynomial π has a linear factor t−α in E[t], so (t−α)2 divides Φˉn there, contradicting the separability supplied by [L1] and [L6].

3.2step 1.1step 2.1L4L8

Every πi has degree d. Writing ei:=deg⁡πi, [L4] gives [Fq(αi):Fq]=ei. Since αi is primitive, [L8] makes μn(E) a cyclic group of order n with generators exactly the primitive n-th roots, so αi generates μn(E). Hence μn(E)⊆Fq(αi) and therefore E=Fq(μn(E))⊆Fq(αi); and αi∈E gives Fq(αi)⊆E. Thus Fq(αi)=E and ei=[E:Fq]=d by step 1.1.

4.1step 1.2step 3.1step 3.2L2L7∎

Comparing degrees with [L7] and [L2], φ(n)=deg⁡Φˉn=∑i=1rei=rd, so r=φ(n)/d; with steps 3.1 and 3.2 this is the assertion.

Remarks

  • The degree of every factor is the same, and that is the content. A polynomial can factor into irreducibles of different degrees; here it cannot, because adjoining any primitive root produces the same field Fq(μn). The primitive roots need not form a single Frobenius orbit: for n=7 over F2 they split into two orbits of size three, one for each irreducible cubic factor on the companion page.
CorollaryStatement: AI-adaptedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

The reduction of Φn is irreducible over Fq exactly when [q] generates (Z/n)×

Statement

Let Fq be a finite field of order q and n≥1 with gcd⁡(n,q)=1 (Coprime integers: gcd⁡(a,b)=1). The image of Φn in Fq[t] (The cyclotomic polynomials Φn∈Z[t], defined by ∏d∣nΦd=tn−1) is irreducible (Irreducible and prime elements of an integral domain) if and only if [q]n generates (Z/n)× (The subgroup ⟨S⟩ generated by a subset, the cyclic subgroup ⟨g⟩, and cyclic groups, The unit group (Z/n)× and Euler's totient φ(n)=∣(Z/n)×∣ for n≥1). In particular this can happen only when (Z/n)× is cyclic.

Facts & Assumptions

Proof

technique · direct
1.1L1

By [L1] the number of monic irreducible factors of Φˉn, counted without repetition and with none repeated, is r=φ(n)/d.

2.1step 1.1L1L2

If r=1 then Φˉn is itself one of those monic irreducible polynomials, hence irreducible; if r≥2 then Φˉn is a product of r polynomials each of degree d≥1, none of them a unit, so it is not irreducible. Hence Φˉn is irreducible exactly when r=1, that is exactly when d=φ(n).

3.1step 2.1L3∎

By [L3] the subgroup ⟨[q]n⟩ has order d and (Z/n)× has order φ(n), so d=φ(n) holds exactly when ⟨[q]n⟩=(Z/n)×, that is exactly when [q]n generates the unit group. With step 2.1 this proves the equivalence, and a group with a generator is cyclic.

Remarks

  • When the criterion cannot be met at all. If (Z/n)× is not cyclic then no class generates it, so the reduction of Φn is reducible over every finite field of order coprime to n; the smallest such n is 8, where (Z/8)× has three elements of order two and no element of order four.
LemmaStatement: AI-adaptedProof: AI-adaptedprecheck passaudited 2026-08-26Open item page →

For E/F finite Galois and L/F finite inside a common field, [EL:F]=[E:F][L:F]/[E∩L:F]

Statement

Let E/F be a finite Galois extension (Finite Galois extensions and Gal⁡(K/F)) and L/F a finite extension (The degree [K:F]=dim⁡FK of a finite field extension), both subfields of a common field. Then the compositum EL is finite over F and

[EL:F]=[E:F] [L:F][E∩L:F].

Only one of the two extensions is required to be Galois.

Facts & Assumptions

Given: Subfields E and L of a common field, both containing F, with E/F finite Galois and L/F finite; E∩L is a subfield containing F and contained in E, hence an intermediate field of E/F.

[L1]

For E/F finite Galois and L/F an extension inside a common overfield, EL/L is finite Galois and restriction gives Gal⁡(EL/L)≅Gal⁡(E/E∩L) (The Galois translation theorem).

[L2]

If K/F is finite Galois and F⊆E′⊆K, then K/E′ is finite Galois (A finite Galois extension is Galois over every intermediate field).

[L3]

For fields F⊆K⊆M with K/F and M/K finite, M/F is finite and [M:F]=[M:K][K:F] (Tower law for finite extensions: [L:F]=[L:K][K:F]).

[L4]

For finite subextensions E/F and E′/F of a common field, the compositum is finite and [EE′:F]≤[E:F][E′:F] (For finite subextensions in a common field, [EE′:F]≤[E:F][E′:F]).

[L5]

For a finite Galois extension M/K one has ∣Gal⁡(M/K)∣=[M:K] (Equivalent characterizations of a finite Galois extension).

Proof

technique · direct
1.1L2given

E∩L is an intermediate field of E/F, so E/(E∩L) is finite Galois by [L2].

1.2L4given

By [L4] the compositum EL is finite over F.

1.3L3given

Applying [L3] to F⊆E∩L⊆E gives [E:F]=[E:E∩L] [E∩L:F], so [E:E∩L]=[E:F]/[E∩L:F].

2.1step 1.1step 1.2L1L5

By [L1] the extension EL/L is finite Galois with Gal⁡(EL/L)≅Gal⁡(E/E∩L), so [L5] applied to both sides gives [EL:L]=∣Gal⁡(EL/L)∣=∣Gal⁡(E/E∩L)∣=[E:E∩L].

3.1step 2.1step 1.3L3∎

Applying [L3] to F⊆L⊆EL and substituting steps 2.1 and 1.3 gives [EL:F]=[EL:L] [L:F]=[E:E∩L] [L:F]=[E:F][L:F]/[E∩L:F].

Remarks

  • The Galois hypothesis is not decoration. Without it the formula fails: over F=Q take E=Q(23) and L=Q(ω23) inside a splitting field of t3−2, where ω is a primitive cube root of unity. Both have degree three over Q, since t3−2 is irreducible there. The compositum contains ω=(ω23)/23, hence contains the splitting field Q(23,ω) and equals it, so [EL:Q]=6. And E∩L=Q: its degree over Q divides 3 by the tower law, and it cannot be 3, since E=E∩L=L would put ω in E and force [E:Q]≥6. The formula would predict 9. Neither E nor L is Galois over Q.
TheoremStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

K(μm)K(μn)=K(μlcm⁡(m,n))

Statement

Let K be a field and let m,n≥1 be integers such that char⁡K divides neither m nor n (The characteristic of a ring: the least n≥1 with n⋅1R=0 when one exists, and 0 otherwise, Divisibility in Z: d∣a when a=dq for some integer q). Put ℓ:=lcm⁡(m,n) (Common multiple, and the least common multiple lcm⁡(a,b), taken to be 0 when a=0 or b=0) and let Ω be a splitting field of tℓ−1 over K (Every nonzero polynomial over a field has a splitting field). Then char⁡K∤ℓ; the subfields K(μm(Ω)) and K(μn(Ω)) of Ω are cyclotomic extensions of K of orders m and n (The cyclotomic extension K(μn) as a splitting field of tn−1); and their compositum inside Ω is

K(μm) K(μn)=K(μℓ)=Ω.

Facts & Assumptions

Given: A field K, integers m,n≥1 with char⁡K dividing neither, ℓ=lcm⁡(m,n), and a splitting field Ω of tℓ−1 over K; the characteristic of a field is 0 or a prime (The characteristic of a field is zero or a prime number), and 0 divides no positive integer.

[L1]

lcm⁡(a,b) is a common multiple of a and b (Common multiple, and the least common multiple lcm⁡(a,b), taken to be 0 when a=0 or b=0); every common multiple of a and b is a multiple of lcm⁡(a,b), and gcd⁡(a,b)lcm⁡(a,b)=∣ab∣ (Every common multiple of a and b is a multiple of lcm⁡(a,b), and gcd⁡(a,b)⋅lcm⁡(a,b)=∣ab∣).

[L4]

A polynomial is separable over K when no extension field contains a repeated root (Repeated roots in extension fields and separable polynomials); a splitting field is generated over K by the roots (Polynomials that split and splitting fields of a polynomial or a family of polynomials, Finitely generated field extensions F(a1,…,ar)).

Proof

technique · direct
1.1L1L2given

char⁡K∤ℓ. If char⁡K=0 this is immediate; if char⁡K=p is a prime dividing ℓ, then ℓ divides mn because gcd⁡(m,n)ℓ=mn by [L1] and gcd⁡(m,n)≥1, so p∣mn and [L2] gives p∣m or p∣n, contrary to hypothesis.

2.1step 1.1L3L4

By [L3] and step 1.1 the polynomial tℓ−1 is separable over K, the group μℓ(Ω) is cyclic of order ℓ, and Ω=K(μℓ(Ω)).

3.1step 2.1L3L4algebra

For every positive divisor k of ℓ one has ∣μk(Ω)∣=k and K(μk(Ω)) is a splitting field of tk−1 over K, hence a cyclotomic extension of K of order k: indeed tk−1 divides tℓ−1, since tℓ−1=(tk−1)(tℓ−k+tℓ−2k+⋯+1), so it splits over Ω, and a repeated root of it would be a repeated root of tℓ−1, excluded by step 2.1 through [L4]; so its k roots are distinct and they are the elements of μk(Ω), which generate K(μk(Ω)) over K.

4.1step 3.1L1L3

m and n are positive divisors of ℓ by [L1], so step 3.1 applies to both: K(μm(Ω)) and K(μn(Ω)) are cyclotomic extensions of K of orders m and n, and each contains a primitive root of unity of its order by [L3].

5.1step 2.1step 4.1L1

Both are contained in Ω=K(μℓ(Ω)), since μm(Ω) and μn(Ω) are subsets of μℓ(Ω) by m∣ℓ and n∣ℓ; hence their compositum inside Ω is contained in K(μℓ).

5.2step 2.1step 4.1L1L5

For the reverse inclusion, fix a primitive m-th root of unity ζm∈μm(Ω) and a primitive n-th root of unity ζn∈μn(Ω), and let H:=⟨ζm,ζn⟩≤μℓ(Ω). By [L5] the orders m=∣⟨ζm⟩∣ and n=∣⟨ζn⟩∣ both divide ∣H∣, so ∣H∣ is a common multiple of m and n and therefore a multiple of ℓ by [L1]; and ∣H∣ divides ℓ by [L5]. Hence ∣H∣=ℓ and H=μℓ(Ω).

6.1step 2.1step 5.1step 5.2∎

Both ζm and ζn lie in the compositum K(μm)K(μn), which is a field, so H⊆K(μm)K(μn) and therefore μℓ(Ω)⊆K(μm)K(μn) by step 5.2; hence Ω=K(μℓ(Ω))⊆K(μm)K(μn). With step 5.1 this gives K(μm)K(μn)=K(μℓ)=Ω.

Remarks

LemmaStatement: AI-adaptedProof: AI-generatedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

φ(m)φ(n)=φ(gcd⁡(m,n)) φ(lcm⁡(m,n))

Statement

For all integers m,n≥1,

φ(m) φ(n)=φ(gcd⁡(m,n)) φ(lcm⁡(m,n))

(The unit group (Z/n)× and Euler's totient φ(n)=∣(Z/n)×∣ for n≥1, Common divisor, and the greatest common divisor gcd⁡(a,b), with the convention gcd⁡(0,0):=0, Common multiple, and the least common multiple lcm⁡(a,b), taken to be 0 when a=0 or b=0). At m=n=1 both sides are 1; at gcd⁡(m,n)=1 the identity is the multiplicativity φ(m)φ(n)=φ(mn).

Facts & Assumptions

Given: Integers m,n≥1; write g:=gcd⁡(m,n) and ℓ:=lcm⁡(m,n), both ≥1 because m and n are nonzero. For a prime p (Prime and composite integers: p is prime when p>1 and its only positive divisors are 1 and p) and an integer e≥0 put w(p,e):=pe−pe−1 when e≥1 and w(p,0):=1. For k≥1 write D(k) for the set of primes dividing k (Divisibility in Z: d∣a when a=dq for some integer q); it is finite, being contained in {2,…,k} by If d∣a and a≠0 then d≠0 and ∣d∣≤∣a∣; hence the set of divisors of a nonzero integer is bounded above by ∣a∣. Put P:=D(m)∪D(n). Finite products over such sets are those of The sum ∑i∈Sai over a finite index set, and its product form.

[L1]

Let k≥1 and let p0,…,pr−1 be an injective finite list consisting exactly of the prime divisors of k; put ei:=vpi(k), so ei≥1. Then φ(k)=∏i<r(piei−piei−1) (Euler's product formula φ(n)=n∏p∣n(1−1/p)=∏pk∥n(pk−pk−1) for n≥1, stated through a finite injective list of its prime divisors).

[L3]

For a prime p and a nonzero integer a, vp(a) is the greatest k∈N with pk∣a (The p-adic valuation vp(a) of a nonzero integer: the greatest k∈N with pk∣a).

Proof

technique · direct
1.1L3

For a prime p and an integer k≥1: p∣k if and only if vp(k)≥1. If vp(k)≥1 then p divides pvp(k), which divides k by [L3]; conversely p∣k says p1∣k, so the greatest such exponent is at least 1.

1.2L2given

For each p∈P write a:=vp(m) and b:=vp(n); then vp(g)=min⁡{a,b} and vp(ℓ)=max⁡{a,b} by [L2], and the unordered pair {min⁡{a,b},max⁡{a,b}} is {a,b}, so w(p,a) w(p,b)=w(p,vp(g)) w(p,vp(ℓ)).

2.1step 1.1L2

Consequently D(g)=D(m)∩D(n) and D(ℓ)=D(m)∪D(n): by [L2] and step 1.1, p∈D(g) says min⁡{vp(m),vp(n)}≥1, that is p∈D(m) and p∈D(n); and p∈D(ℓ) says max⁡{vp(m),vp(n)}≥1, that is p∈D(m) or p∈D(n).

3.1step 1.1step 2.1L1given

The set P is a finite set of primes containing D(m), D(n), D(g) and D(ℓ) by step 2.1. For every k∈{m,n,g,ℓ} one has φ(k)=∏p∈Pw(p,vp(k)): applying [L1] with the list D(k) gives φ(k)=∏p∈D(k)w(p,vp(k)), and for p∈P outside D(k) step 1.1 gives vp(k)=0, so the extra factors are w(p,0)=1.

4.1step 3.1step 1.2∎

Multiplying the equalities of step 1.2 over the finite set P and using step 3.1 four times gives φ(m)φ(n)=∏p∈Pw(p,vp(m))w(p,vp(n))=∏p∈Pw(p,vp(g))w(p,vp(ℓ))=φ(g)φ(ℓ).

Remarks

  • Why the identity is not simply multiplicativity. For coprime m and n it reduces to φ(mn)=φ(m)φ(n), but the general case is what the intersection theorem needs: the degrees of Q(μm) and Q(μn) multiply to the degree of the compositum times the degree of the intersection, and it is the gcd–lcm form of the identity that turns that into φ(gcd⁡(m,n)) (Q(μm)∩Q(μn)=Q(μgcd⁡(m,n))).
TheoremStatement: Literature-sourcedProof: AI-adaptedprecheck passaudited 2026-08-26Open item page →

Q(μm)∩Q(μn)=Q(μgcd⁡(m,n))

Statement

Let m,n≥1, put d:=gcd⁡(m,n) and ℓ:=lcm⁡(m,n) (Common divisor, and the greatest common divisor gcd⁡(a,b), with the convention gcd⁡(0,0):=0, Common multiple, and the least common multiple lcm⁡(a,b), taken to be 0 when a=0 or b=0), and let Ω be a splitting field of tℓ−1 over Q (Every nonzero polynomial over a field has a splitting field), inside which the cyclotomic extensions Q(μk) for k∣ℓ are taken (The cyclotomic extension K(μn) as a splitting field of tn−1). Then

Q(μm)∩Q(μn)=Q(μd).

Facts & Assumptions

Given: Integers m,n≥1 with d=gcd⁡(m,n) and ℓ=lcm⁡(m,n); Q is an ordered field (The rationals form a totally ordered field), so char⁡Q=0 (The characteristic of a ring: the least n≥1 with n⋅1R=0 when one exists, and 0 otherwise) and divides no positive integer (Divisibility in Z: d∣a when a=dq for some integer q); a splitting field Ω of tℓ−1 over Q; and, for each positive divisor k of ℓ, the subfield Q(μk):=Q(μk(Ω)) of Ω. Write I:=Q(μm)∩Q(μn).

[L1]

For a positive divisor k of ℓ, the subfield Q(μk(Ω)) generated by the k-th roots of unity in Ω is a cyclotomic extension of Q of order k (The cyclotomic extension K(μn) as a splitting field of tn−1, The group μn(K) of n-th roots of unity in a field, and primitive n-th roots of unity); because char⁡Q=0 divides no positive integer, tn−1 is separable over K exactly when the characteristic does not divide n, and then a splitting field carries n distinct n-th roots of unity gives μk(Ω) cyclic of order k, with exactly φ(k) primitive k-th roots of unity.

[L4]

For E/F finite Galois and L/F finite inside a common field, [EL:F]=[E:F][L:F]/[E∩L:F] (For E/F finite Galois and L/F finite inside a common field, [EL:F]=[E:F][L:F]/[E∩L:F]).

[L5]

Q(μm)Q(μn)=Q(μℓ) inside Ω (K(μm)K(μn)=K(μlcm⁡(m,n))).

[L6]
[L7]

For fields F⊆K⊆M with K/F and M/K finite, [M:F]=[M:K][K:F] (Tower law for finite extensions: [L:F]=[L:K][K:F]).

Proof

technique · direct
1.1L1givenalgebra

d divides m and n, and m,n,d all divide ℓ. For each positive divisor k of ℓ, write ℓ=kq; then tℓ−1=(tk)q−1=(tk−1)(tk(q−1)+⋯+tk+1), so tk−1 splits over the splitting field Ω of tℓ−1, and [L1] applies to k. In particular all four cyclotomic extensions for k=m,n,d,ℓ sit inside Ω.

2.1step 1.1givenalgebra

For the inclusion Q(μd)⊆I: since d∣m, every x with xd=1 satisfies xm=1, so μd(Ω)⊆μm(Ω) and hence Q(μd)⊆Q(μm); the same argument with n gives Q(μd)⊆Q(μn).

2.2step 1.1L2L3L4L5

By [L3] the extension Q(μm)/Q is finite Galois and Q(μn)/Q is finite, both inside Ω, so [L4] and [L5] give φ(ℓ)=[Q(μℓ):Q]=[Q(μm)Q(μn):Q]=φ(m)φ(n)/[I:Q], using [L2] twice.

3.1step 2.2L6

Hence [I:Q]=φ(m)φ(n)/φ(ℓ)=φ(d) by [L6].

4.1step 2.1step 3.1L2L7∎

By step 2.1 the tower Q⊆Q(μd)⊆I is defined, and [L7] with [L2] gives φ(d)=[I:Q]=[I:Q(μd)] φ(d), so [I:Q(μd)]=1 and I=Q(μd).

Remarks

  • Where the base field is used. Only through [L2]: the equality [Q(μk):Q]=φ(k) for every k, which is irreducibility of Φk over Q. Over a base field where some Φk becomes reducible the degrees drop unevenly and the degree count in step 2.2 no longer forces the intersection down to Q(μd).

  • The base field really matters. Over a general base field the same formula can fail; the companion page gives a finite-field witness in F3(μ5)∩F3(μ7) is larger than F3 although five and seven are coprime ↗.

CorollaryStatement: AI-generatedProof: AI-generatedprecheck passaudited 2026-08-26Open item page →

For an odd prime p, Q(ζp) has exactly one intermediate field of degree two over Q

Statement

Let p be an odd prime (Prime and composite integers: p is prime when p>1 and its only positive divisors are 1 and p) and let ζ be a primitive p-th root of unity (The group μn(K) of n-th roots of unity in a field, and primitive n-th roots of unity) in Q(μp) (The cyclotomic extension K(μn) as a splitting field of tn−1). Then there is exactly one intermediate field F with

Q⊆F⊆Q(ζ),[F:Q]=2

(The degree [K:F]=dim⁡FK of a finite field extension).

Intermediate, not proper. At p=3 the Galois group has order two, the unique subgroup of index two is the trivial one, and the field it names is Q(ζ3) itself. Reading the statement as "proper subfield" would make it false at the smallest case in scope.

Facts & Assumptions

Given: An odd prime p and a primitive p-th root of unity ζ in the cyclotomic extension Q(μp)=Q(ζ); write G:=Gal⁡(Q(μp)/Q).

[L2]

Every finite subgroup of the unit group of an integral domain is cyclic (Every finite subgroup of the unit group of an integral domain is cyclic); Z/p is a field (For every prime p, the two operations on Z/p make it a field, Field), hence an integral domain, and (Z/p)× is its group of units (The unit group (Z/n)× and Euler's totient φ(n)=∣(Z/n)×∣ for n≥1).

[L4]

In a cyclic group of finite order m there is exactly one subgroup of each order dividing m, and every subgroup has that form (A finite cyclic group has exactly one subgroup of each order dividing its own).

[L5]

For K/F finite Galois with G=Gal⁡(K/F), the maps H↦KH and E↦Gal⁡(K/E) are mutually inverse bijections between subgroups and intermediate fields, and [KH:F]=[G:H] (The fundamental theorem of finite Galois theory).

[L6]

For a finite group G and H≤G, ∣G∣=[G:H] ∣H∣ (Lagrange's theorem: ∣G∣=[G:H]∣H∣ for every subgroup H of a finite group G).

Proof

technique · direct
1.1L1L2L3

By [L1] the group G is isomorphic to (Z/p)×, which is cyclic by [L2] and has order p−1 by [L3]; so G is cyclic of order p−1.

2.1step 1.1L4given

Since p is odd, p−1 is even, so 2 divides p−1 and (p−1)/2 is a positive divisor of p−1 (Divisibility in Z: d∣a when a=dq for some integer q). By [L4] there is exactly one subgroup H≤G with ∣H∣=(p−1)/2.

2.2step 1.1L5L6

By [L5] and [L6], an intermediate field F of Q(μp)/Q has [F:Q]=[G:H]=∣G∣/∣H∣ for its corresponding subgroup H, so [F:Q]=2 holds exactly when ∣H∣=(p−1)/2.

3.1step 2.1step 2.2L5∎

The correspondence of [L5] is a bijection, so the intermediate fields of degree two over Q are in bijection with the subgroups of order (p−1)/2, of which there is exactly one by step 2.1. Hence there is exactly one such field.

Remarks

  • Which field it is, is a different question. The argument counts intermediate fields; it produces no generator of the one it counts, and no claim is made here about identifying it. Naming that field concretely requires a computation this proof does not carry out.

  • Oddness is needed. At p=2 the field Q(μ2) is Q itself, of degree φ(2)=1, and it has no intermediate field of degree two at all; the step that fails is step 2.1, where p−1=1 is odd.

TheoremStatement: Literature-sourcedProof: AI-adaptedprecheck passaudited 2026-08-26Open item page →

For every n≥1 there are infinitely many primes p with p≡1(modn)

Statement

Facts & Assumptions

[L2]

Φn(0)=1 for every n≥2 (Φ1(0)=−1 and Φn(0)=1 for n≥2).

[L7]

A nonzero polynomial of degree k over an integral domain has at most k distinct roots in it (A nonzero polynomial of degree n over an integral domain has at most n distinct roots).

Proof

technique · cases
1.1assume-case oneL8given

In the case n=1, every integer is congruent to 1 modulo 1, since 1 divides every integer, so T1 is the set of all primes, which is not finite by [L8].

1.2assume-case biggiven

In the case n≥2, let S⊆Tn be any finite set and put M:=n∏p∈Sp, an integer with M≥2; the goal is to produce a prime in Tn outside S.

2.1step 1.2L1L7

There is an integer k≥1 with ∣Φn(kM)∣>1: the three polynomials Φn, Φn−1 and Φn+1 are nonzero of degree φ(n)≥1 by [L1], so by [L7] over the integral domain Z at most 3φ(n) integers x satisfy Φn(x)∈{−1,0,1}; the integers M,2M,3M,… are pairwise distinct, so some kM with k≥1 avoids that finite set.

2.2step 1.2L1L2given

Since Φn(0)=1 by [L2], there is h∈Z[t] with Φn=1+t h; evaluating at kM gives N:=Φn(kM)=1+kM h(kM).

3.1step 2.1step 2.2L6given

By step 2.1 the integer ∣N∣ exceeds 1, so it has a prime divisor p by [L6], and p∣N. That prime does not divide kM: otherwise p would divide kM h(kM) and hence N−kM h(kM)=1, which is impossible for a prime. In particular p∤M, so p∤n and p∉S, both n and every member of S dividing M.

4.1step 3.1L3L4

Reduce modulo p. Since p∣Φn(kM), the class α:=[kM]p is a root of the image of Φn in (Z/p)[t], and α≠0 because p∤kM by step 3.1. Let E be a splitting field of tn−1 over Z/p, which exists by [L4]; as char⁡(Z/p)=p does not divide n, [L3] applies and α, lying in Z/p⊆E, has order exactly n in E×.

5.1step 3.1step 4.1L5given

The order of α in the subgroup (Z/p)× of E× is the same n, so n divides ∣(Z/p)×∣=p−1 by [L5]; that is p≡1(modn), so p∈Tn and p∉S.

6.1step 1.1step 5.1cases-exhaustive∎

In the case n≥2, then, no finite subset of Tn exhausts it, so Tn is not finite; with step 1.1 the two cases are exhaustive and cover every n≥1.

Remarks

  • What replaces the archimedean estimate. The usual proof chooses x large enough that ∣Φn(x)∣>1 by a growth estimate. Step 2.1 replaces that by a root count, which needs no order structure on Z beyond the distinctness of the multiples of M, and gives exactly the same conclusion.

  • The case n=1 is not a degenerate instance. For n=1 one has Φ1(0)=−1, not 1 (Φ1(0)=−1 and Φn(0)=1 for n≥2), so step 2.2 is unavailable; the congruence is vacuous there and the statement is Euclid's theorem.

LemmaStatement: Literature-sourcedProof: AI-generatedprecheck passaudited 2026-08-26Open item page →

Every finite abelian group is a quotient of (Z/n)k for some n and k

Statement

For every finite abelian group G there are positive integers n and k and a surjective group homomorphism

(Z/n)k⟶G,

where (Z/n)k denotes the set of k-tuples of classes in Z/n, with componentwise addition, for the additive group Z/n (The congruence class [a]n and the quotient set Z/n, For every natural n, (Z/n,+) is an abelian group, multiplication is a commutative monoid operation, and both distributive laws hold). Equivalently, G≅(Z/n)k/H for a subgroup H (The quotient group G/N and coset product (gN)(hN)=ghN, First isomorphism theorem for groups: G/ker⁡f≅im⁡f).

Facts & Assumptions

Given: A finite abelian group G.

[L1]

For every finite abelian group G there is a unique list 1<n1∣n2∣⋯∣nr with G≅Cn1×⋯×Cnr; the trivial group corresponds to the empty list (Fundamental theorem of finite abelian groups: invariant-factor form, Invariant-factor data for a finite abelian group).

[L2]

A cyclic group of finite order m is isomorphic to (Z/m,+) (Every cyclic group is isomorphic to (Z,+) or to (Z/n,+) for its finite order n≥1).

[L4]

For a homomorphism f:A→B, the rule aker⁡f↦f(a) is an isomorphism A/ker⁡f→im⁡f (First isomorphism theorem for groups: G/ker⁡f≅im⁡f, The quotient group G/N and coset product (gN)(hN)=ghN).

Proof

technique · cases
1.1assume-case trivialL1

In the case that the invariant-factor list of [L1] is empty, G is trivial; take n=1 and k=1, so that (Z/1)1 is a one-element group and the unique map to G is a surjective homomorphism.

1.2assume-case nontrivialL1

In the case r≥1, put n:=nr and k:=r. Each ni divides n, the list being a divisibility chain by [L1].

2.1step 1.2L3

For each i the rule [a]n↦[a]ni is a well-defined surjective group homomorphism Z/n→Z/ni: if [a]n=[b]n then n∣a−b, hence ni∣a−b because ni∣n, so [a]ni=[b]ni by [L3]; it respects addition by [L3]; and every class [a]ni is the image of [a]n.

3.1step 1.2step 2.1L1L2L3

Let P:=(Z/n)r and Q:=(Z/n1)×⋯×(Z/nr), both with componentwise addition. By [L3] each coordinate (Z/n,+) and (Z/ni,+) is an abelian group, so P and Q are abelian groups under these coordinatewise operations. Define π ⁣:P→Q by π([a1]n,…,[ar]n):=([a1]n1,…,[ar]nr). Step 2.1 gives each coordinate map Z/n→Z/ni as a well-defined surjective homomorphism, so π is a well-defined surjective group homomorphism. Fact [L2] identifies each coordinate group (Z/ni,+) with Cni, and [L1] identifies Cn1×⋯×Cnr with G up to isomorphism. Composing with that isomorphism gives a surjective homomorphism (Z/n)k→G.

4.1step 1.1step 3.1L4cases-exhaustive∎

The two cases are exhaustive, the invariant-factor list being empty or not, so such n and k exist for every finite abelian G; and [L4] turns any such surjection into an isomorphism G≅(Z/n)k/H with H its kernel.

Remarks

  • Why the invariant-factor form is convenient. The invariant factors form a divisibility chain, so the single modulus n=nr works immediately. A primary decomposition also proves the statement: take n to be the least common multiple of the finitely many prime-power orders and reduce Z/n onto each cyclic factor. The invariant-factor form simply avoids that extra choice of modulus.
TheoremStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

Every finite abelian group is the Galois group of some finite Galois extension of Q

Statement

For every finite abelian group G there is a finite Galois extension L/Q (Finite Galois extensions and Gal⁡(K/F)) with

Gal⁡(L/Q)≅G,

and L may be taken inside a cyclotomic field Q(μN) (The cyclotomic extension K(μn) as a splitting field of tn−1).

Facts & Assumptions

[L1]

There are positive integers n,k and a surjective group homomorphism (Z/n)k→G (Every finite abelian group is a quotient of (Z/n)k for some n and k, The external direct product G×H with componentwise multiplication).

[L5]

A cyclic group of finite order m is isomorphic to (Z/m,+) (Every cyclic group is isomorphic to (Z,+) or to (Z/n,+) for its finite order n≥1).

[L7]

For K/Q finite Galois with group G′ and H≤G′, the field KH is an intermediate field (The fundamental theorem of finite Galois theory); it is Galois over Q exactly when H is normal (Normal subgroup: invariance under conjugation), and then Gal⁡(KH/Q)≅G′/H (Normal subgroups, conjugate fields, and quotient groups in the Galois correspondence, The quotient group G/N and coset product (gN)(hN)=ghN).

[L8]

For a homomorphism f:A→B the rule aker⁡f↦f(a) is an isomorphism A/ker⁡f→im⁡f (First isomorphism theorem for groups: G/ker⁡f≅im⁡f).

Proof

technique · direct
1.1L1

Fix n,k≥1 and a surjection π ⁣:(Z/n)k→G by [L1].

2.1step 1.1L2

Choose pairwise distinct primes p1,…,pk with pi≡1(modn): the set of such primes is not finite by [L2], so at each of the k steps one may pick a prime outside the finitely many already chosen. Put N:=p1⋯pk.

3.1step 2.1givenalgebra

Distinct primes are coprime: a positive common divisor of pi and pj is 1 or pi, and is 1 or pj, so if it is not 1 then pi=pj. Hence p1,…,pk is a pairwise-coprime list.

3.2step 2.1L4L5

For each i there is a surjective homomorphism (Z/pi)×→Z/n: by [L4] the group (Z/pi)× is cyclic of order mi=pi−1, which n divides by step 2.1; [L5] identifies it with (Z/mi,+), and [a]mi↦[a]n is well defined because n∣mi, is a homomorphism, and is onto.

4.1step 3.1L3

By [L3] the map [x]N↦([x]pi)i is a bijection Z/N→∏iZ/pi preserving multiplication and [1], so it carries units to units bijectively and restricts to a group isomorphism (Z/N)×→∏i(Z/pi)×.

5.1step 1.1step 4.1step 3.2L6

Taking the product of the maps of step 3.2 and composing with step 4.1 and with π gives a surjective group homomorphism Ψ0 ⁣:(Z/N)×→G; composing with the isomorphism of [L6] gives a surjective homomorphism Ψ ⁣:Gal⁡(Q(μN)/Q)→G.

6.1step 5.1L6L7

Put G′:=Gal⁡(Q(μN)/Q) and H:=ker⁡Ψ. The group G′ is abelian by [L6], so every subgroup is normal, gHg−1=H holding for all g; hence L:=Q(μN)H is an intermediate field, L/Q is finite Galois, and Gal⁡(L/Q)≅G′/H by [L7].

7.1step 5.1step 6.1L8∎

By [L8] applied to Ψ, which is surjective, G′/H≅im⁡Ψ=G; hence Gal⁡(L/Q)≅G, with L inside Q(μN).

Remarks

  • What is produced is a subfield, not a cyclotomic field. The construction realises G as the Galois group of an intermediate field of Q(μN)/Q, and it must: the Galois group of Q(μN) itself is (Z/N)×, whose order φ(N) is even for N≥3, so most finite abelian groups are not of that form. The companion page spells out that failure in FALSE: every finite abelian group is Gal⁡(Q(μn)/Q) for some n ↗.

  • The distinctness of the primes is needed twice. It makes the list pairwise coprime so that the Chinese remainder theorem applies, and it makes the product N have exactly the intended unit group. Repeating a prime would collapse two factors into one.

PropositionStatement: Literature-sourcedProof: AI-adaptedOpen item page →

Every intermediate field of Q(μn)/Q is Galois over Q with abelian Galois group

Statement

Let n≥1 and let F be an intermediate field of Q(μn)/Q (The cyclotomic extension K(μn) as a splitting field of tn−1). Then F/Q is a finite Galois extension (Finite Galois extensions and Gal⁡(K/F)) and Gal⁡(F/Q) is abelian.

Facts & Assumptions

Given: An integer n≥1 and an intermediate field Q⊆F⊆Q(μn); Q is an ordered field (The rationals form a totally ordered field), so char⁡Q=0 (The characteristic of a ring: the least n≥1 with n⋅1R=0 when one exists, and 0 otherwise) and divides no positive integer (Divisibility in Z: d∣a when a=dq for some integer q). Write G:=Gal⁡(Q(μn)/Q).

[L2]

For K/F0 finite Galois with group G, the maps H↦KH and E↦Gal⁡(K/E) are mutually inverse bijections between subgroups of G and intermediate fields (The fundamental theorem of finite Galois theory).

[L3]

With K/F0 finite Galois, G=Gal⁡(K/F0), H≤G and E=KH: the extension E/F0 is Galois exactly when H is normal in G (Normal subgroup: invariance under conjugation), and then restriction gives Gal⁡(E/F0)≅G/H (Normal subgroups, conjugate fields, and quotient groups in the Galois correspondence, The quotient group G/N and coset product (gN)(hN)=ghN).

Proof

technique · direct
1.1L1

By [L1] the extension Q(μn)/Q is finite Galois and G is abelian.

2.1step 1.1L2

By [L2] there is a subgroup H≤G with F=Q(μn)H.

3.1step 1.1step 2.1L3

Since G is abelian, gHg−1=H for every g∈G, so H is normal in G; hence F/Q is Galois and Gal⁡(F/Q)≅G/H by [L3].

4.1step 1.1step 3.1L3∎

A quotient of an abelian group is abelian, since the images of two commuting elements commute and every element of G/H is such an image; so Gal⁡(F/Q) is abelian.

5 · Examples, counterexamples and false statements

ExampleConstruction: AI-adaptedVerification: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

Gal⁡(F8/F2) is cyclic of order three with no proper intermediate field

Example

Let K:=F2[t]/(t3+t+1) and let α be the class of t. Then K is a field of order 8, the squaring map σ(x)=x2 generates

Gal⁡(K/F2)={id,σ,σ2},

cyclic of order three, its two orbits on K∖F2 are

{α, α2, α2+α}and{α+1, α2+1, α2+α+1},

and K/F2 has no intermediate field other than F2 and K.

Facts & Assumptions

Given: The polynomial π:=t3+t+1∈F2[t], the ring K=F2[t]/(π) and the class α of t, so that α3=α+1 because α3+α+1=0 and −1=1 in characteristic two.

[L1]

A polynomial of degree 2 or 3 over a field is irreducible if and only if it has no root in that field (A polynomial of degree two or three over a field is irreducible exactly when it has no root in the field).

[L2]

For a field F and nonconstant p∈F[x], p is irreducible if and only if F[x]/(p) is a field (For a nonconstant p in F[x], the ideal (p) is maximal and F[x]/(p) is a field exactly when p is irreducible).

[L3]

If a is algebraic over F with minimal polynomial ma of degree n, then F(a) has power basis 1,a,…,an−1 and [F(a):F]=n (A simple algebraic extension is its minimal-polynomial quotient and has power basis 1,a,…,an−1 and degree n, The degree [K:F]=dim⁡FK of a finite field extension); a monic irreducible vanishing at a is that minimal polynomial (The evaluation kernel and the unique monic irreducible minimal polynomial of an algebraic element).

[L4]

An extension E/Fq of finite fields of degree n is Galois with Gal⁡(E/Fq)=⟨σq⟩ cyclic of order n, where σq(x)=xq, and ∣E∣=qn (A finite extension of a finite field of order q is Galois with cyclic Galois group generated by x↦xq, The relative Frobenius x↦xq of an extension of finite fields, For a degree-n extension of a field of order q, the q-power map has order exactly n, Finite fields and their order).

[L5]

The intermediate fields of Fqn/Fq are the Fqd for the positive divisors d of n, one for each divisor (The intermediate fields of Fqn/Fq are the Fqd, one for each positive divisor d of n, Divisibility in Z: d∣a when a=dq for some integer q).

Verification

technique · direct
1.1L1L2given

π has no root in F2: π(0)=1 and π(1)=1+1+1=1. By [L1] it is irreducible, so K is a field by [L2].

2.1step 1.1L3L4

π is monic irreducible with π(α)=0, so it is the minimal polynomial of α over F2 and [K:F2]=3 with power basis 1,α,α2 by [L3]; hence ∣K∣=23=8 by [L4].

3.1step 2.1L4

By [L4] the extension K/F2 is Galois with Galois group generated by σ(x)=x2 and of order three.

4.1step 2.1step 3.1given

The orbit of α: α2 is α2; α4=α⋅α3=α(α+1)=α2+α; and (α2+α)2=α4+α2=(α2+α)+α2=α, using that squaring is additive in characteristic two. So {α,α2,α2+α} is one orbit of size three.

5.1step 2.1step 3.1step 4.1given

The orbit of α+1: (α+1)2=α2+1, (α2+1)2=α4+1=α2+α+1, and (α2+α+1)2=α4+α2+1=α+1. So {α+1,α2+1,α2+α+1} is the other orbit of size three, and together with {0} and {1} these account for all eight elements.

6.1step 2.1step 3.1L5∎

The positive divisors of three are 1 and 3, so by [L5] the intermediate fields are exactly two: F2 and K itself. There is no field strictly between them.

Remarks

ExampleConstruction: AI-adaptedVerification: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

The intermediate fields of F212/F2 match the divisors of twelve

Example

Let E be a field with F2 as a subfield and [E:F2]=12, so that ∣E∣=212. Its intermediate fields over F2 are exactly

F2,F22,F23,F24,F26,F212=E,

one for each of the six positive divisors 1,2,3,4,6,12 of twelve, with F2d⊆F2e exactly when d divides e. Neither of F24 and F26 contains the other, and

F24∩F26=F22,F24 F26=F212.

Facts & Assumptions

[L2]

The intermediate fields of Fqn/Fq are exactly the Fqd={x:xqd=x} for the positive divisors d of n, one for each divisor, with [Fqd:Fq]=d and Fqd⊆Fqe if and only if d∣e (The intermediate fields of Fqn/Fq are the Fqd, one for each positive divisor d of n).

[L3]

A field of order pm has, for each positive divisor e of m, exactly one subfield of order pe, namely {a:ape=a}, and these are all of its subfields (The subfields of Fpn are the unique fields Fpd for positive divisors d of n).

Verification

technique · direct
1.1givenalgebra

The positive divisors of twelve are 1,2,3,4,6,12, six in all, since a positive divisor d of 12 satisfies d≤12 and direct inspection of 1,…,12 leaves exactly these.

2.1step 1.1L1L2

By [L1] and [L2] the intermediate fields of E/F2 are the F2d for those six d, one for each, with F2d⊆F2e exactly when d∣e.

3.1step 2.1given

Neither 4∣6 nor 6∣4, so by step 2.1 neither of F24 and F26 contains the other.

4.1step 2.1step 3.1L4

Their intersection is an intermediate field of E/F2, being a subfield of E containing F2, so it is F2c for a unique divisor c of 12 by step 2.1; from F2c⊆F24 and F2c⊆F26 one gets c∣4 and c∣6, so [L4] gives c∣gcd⁡(4,6)=2; and 2∣4 and 2∣6 put F22 inside both, so 2∣c. Hence c=2 and the intersection is F22.

5.1step 2.1step 4.1L4

Their compositum is likewise an intermediate field F2c′, and it contains both, so 4∣c′ and 6∣c′ by step 2.1. Thus [L4] gives lcm⁡(4,6)=12∣c′; since c′∣12, c′=12 and the compositum is E=F212.

6.1step 2.1step 5.1L2L3∎

The same six fields are what [L3] produces for E, whose order is 212: its subfields are the {a:a2e=a} for the divisors e of 12, and these are the sets named in [L2]. So the Galois indexing and the elementary one agree here.

Remarks

ExampleConstruction: Literature-sourcedVerification: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

The divisor-sum identity at q=2, n=3 finds exactly two monic irreducible cubics

Example

Over F2 the divisor-sum identity (∑d∣nd Nq(d)=qn for the counts Nq(d) of monic irreducibles of degree d over Fq) at n=3 reads

N2(1)+3 N2(3)=23=8,

and N2(1)=2, so N2(3)=2. The two monic irreducible cubics in F2[t] are

t3+t+1andt3+t2+1.

Facts & Assumptions

Given: The field F2 with two elements and the counts N2(d) of monic irreducible polynomials of degree d in F2[t] (Degree, leading coefficient and monic polynomial, with the zero polynomial having no degree).

[L2]

A polynomial of degree 2 or 3 over a field is irreducible if and only if it has no root in that field (A polynomial of degree two or three over a field is irreducible exactly when it has no root in the field).

[L3]

For a commutative ring R, a∈R and f∈R[x]: f(a)=0 if and only if x−a divides f (Factor theorem over a commutative ring, Evaluation and roots of a polynomial in a commutative target ring).

Verification

technique · direct
1.1givenalgebra

The monic polynomials of degree one in F2[t] are t and t+1, and each is irreducible, having degree one; so N2(1)=2.

1.2givenalgebra

A monic cubic over F2 is f=t3+at2+bt+c with a,b,c∈F2, so there are eight of them. Such an f has no root in F2 exactly when f(0)=c≠0 and f(1)=1+a+b+c≠0, that is exactly when c=1 and a+b=1.

2.1step 1.1L1algebra

The positive divisors of 3 are 1 and 3, so [L1] at q=2 and n=3 reads N2(1)+3N2(3)=8; with step 1.1 this gives 3N2(3)=6 and N2(3)=2.

3.1step 2.1step 1.2L2L3algebra∎

The pairs (a,b) with a+b=1 in F2 are (0,1) and (1,0), so exactly two monic cubics have no root in F2, namely t3+t+1 and t3+t2+1; by [L2] these two are irreducible and by [L2] and [L3] the other six are not, each having a root and hence a linear factor. This agrees with the count N2(3)=2 of step 2.1.

Remarks

  • The identity is a recursion, not a formula. It determines N2(3) only because N2(1) is already known; at n=4 it would read N2(1)+2N2(2)+4N2(4)=16 and would need N2(2) first.
ExampleConstruction: Literature-sourcedVerification: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

The four roots of t4+t+1 over F2 are the Frobenius powers of any one of them

Example

Let K:=F2[t]/(t4+t+1) and let α be the class of t, so α4=α+1. Then K is a field of order 16, and the four conjugates of α over F2,

α,α2,α4=α+1,α8=α2+1,

are pairwise distinct, are exactly the roots of t4+t+1 in K, and satisfy α16=α, so the Frobenius orbit closes at length four.

Facts & Assumptions

Given: The polynomial π:=t4+t+1∈F2[t], the ring K=F2[t]/(π), and the class α of t, so α4=α+1 since −1=1 in characteristic two; squaring is additive there.

[L1]

A polynomial of degree 2 or 3 over a field is irreducible if and only if it has no root in that field (A polynomial of degree two or three over a field is irreducible exactly when it has no root in the field).

[L2]

f(a)=0 if and only if x−a divides f (Factor theorem over a commutative ring); and over an integral domain deg⁡(fg)=deg⁡f+deg⁡g for nonzero f,g (Over an integral domain, degrees add under multiplication of nonzero polynomials, Degree, leading coefficient and monic polynomial, with the zero polynomial having no degree).

[L3]

For a field F and nonconstant p∈F[x], p is irreducible if and only if F[x]/(p) is a field (For a nonconstant p in F[x], the ideal (p) is maximal and F[x]/(p) is a field exactly when p is irreducible).

[L6]

A monic irreducible π of degree d over Fq with a root α has the d distinct roots α,αq,…,αqd−1 and π=∏i<d(t−αqi) (A monic irreducible of degree d over Fq has the d distinct roots α,αq,…,αqd−1).

Verification

technique · direct
1.1L2given

π has no root in F2, since π(0)=1 and π(1)=1+1+1=1; so by [L2] it has no factor of degree one.

1.2L1L2given

The only monic irreducible quadratic in F2[t] is t2+t+1: the four monic quadratics are t2, t2+1, t2+t and t2+t+1, and the first three have the root 0, 1 and 0 respectively, so [L1] leaves only the last.

2.1step 1.1step 1.2L2given

π is irreducible. A factorisation of π into two nonconstant factors has degrees summing to four by [L2], so it is either 1+3, excluded by step 1.1, or 2+2; and every monic quadratic factor would have to be irreducible, hence equal to t2+t+1 by step 1.2, giving π=(t2+t+1)2=t4+t2+1, which is not π.

3.1step 2.1L3L4L5

By [L3] the ring K is a field; π is monic irreducible with π(α)=0, so [K:F2]=4 with power basis 1,α,α2,α3 by [L4], and ∣K∣=24=16 by [L5].

4.1step 3.1given

Compute the conjugates in that basis: α4=α+1 by hypothesis, and α8=(α4)2=(α+1)2=α2+1. So the four elements α,α2,α4,α8 have coordinate lists (0,1,0,0), (0,0,1,0), (1,1,0,0) and (1,0,1,0), which are pairwise different, so the four elements are pairwise distinct.

5.1step 4.1given

α16=(α8)2=(α2+1)2=α4+1=(α+1)+1=α, so the orbit closes after four steps.

6.1step 2.1step 4.1step 5.1L6∎

By [L6] applied to π, of degree four, the elements α,α2,α4,α8 are exactly the roots of π and π=(t−α)(t−α2)(t−α4)(t−α8) in K[t]; steps 4.1 and 5.1 verify the distinctness and the closing of the orbit directly.

ExampleConstruction: AI-generatedVerification: AI-generatedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

A normal basis of F8 over F2

Example

Let K:=F2[t]/(t3+t+1), a field of order 8, let α be the class of t, and let σ(x)=x2 generate Gal⁡(K/F2). Put

β:=α+1.

Then the conjugate list

(β, β2, β4)=(α+1, α2+1, α2+α+1)

is a normal basis of K over F2 (Normal bases of a finite Galois extension).

Not every element works. The generator α itself does not: its conjugate list is (α,α2,α2+α), whose three members sum to 0, so they are linearly dependent over F2 and are not a basis.

Facts & Assumptions

Given: The field K=F2[t]/(t3+t+1) with α the class of t, so α3=α+1 and α4=α2+α; squaring is additive in characteristic two.

[L4]

For a linear map T:V→W with V finite-dimensional, dim⁡V=dim⁡ker⁡T+dim⁡im⁡T (Rank-nullity: dim⁡FV=nullity⁡T+rank⁡T).

[L5]

Every finite Galois extension with cyclic Galois group has a normal basis (Every finite cyclic extension has a normal basis).

Verification

technique · direct
1.1L1L2

By [L1] and [L2] the space K is a three-dimensional F2-vector space with basis 1,α,α2, and Gal⁡(K/F2)={id,σ,σ2} acts by x↦x, x2, x4.

2.1step 1.1L3given

The conjugate list of α is (α,α2,α4) with α4=α⋅α3=α(α+1)=α2+α; hence α+α2+α4=α+α2+α2+α=0. A vanishing combination with all coefficients 1 is nontrivial, so this list is linearly dependent over F2 and is not a basis.

3.1step 1.1step 2.1given

The conjugates of β=α+1 are β, β2=(α+1)2=α2+1 and β4=(β2)2=(α2+1)2=α4+1=α2+α+1.

4.1step 1.1step 3.1given

The seven nonzero F2-combinations of β,β2,β4 are nonzero: the three single terms are α+1, α2+1 and α2+α+1; the three pairwise sums are β+β2=α2+α, β+β4=α2 and β2+β4=α; and the total sum is β+β2+β4=1. None of these seven is 0, as each has a nonzero coordinate list in the basis 1,α,α2.

5.1step 1.1step 4.1L3L4

So the F2-linear map T ⁣:F23→K sending (c1,c2,c3) to c1β+c2β2+c3β4 has trivial kernel by step 4.1; both spaces have dimension three by step 1.1, so [L4] makes T surjective as well, hence bijective, and [L3] makes (β,β2,β4) an ordered basis of K over F2.

6.1step 3.1step 5.1L2L5∎

That list is the family of conjugates of β under Gal⁡(K/F2) by step 3.1, so it is a normal basis, as [L5] guarantees exists for this cyclic extension.

Remarks

  • A conjugate family of the right size can still fail. The list (α,α2,α4) has three distinct members and is a single Galois orbit, yet it is not a basis; what fails is independence, not the orbit condition. The normal basis theorem asserts that some element works, never that every element does (FALSE: every basis of a finite field over a subfield is a normal basis).
ExampleConstruction: Literature-sourcedVerification: AI-adaptedprecheck passaudited 2026-08-26Open item page →

{1+i, 1−i} is a normal basis of C/R while {1,i} is not

Example

The extension C/R (The complex numbers as R[x]/(x2+1), with the real embedding and imaginary unit i) is finite Galois of degree two with Gal⁡(C/R)={id, z↦z‾} (Real and imaginary parts, complex conjugation, and modulus). For it:

  1. the conjugate list (1+i, 1−i) is a normal basis (Normal bases of a finite Galois extension);
  2. (1,i) is an R-basis of C that is not a conjugate list of any element;
  3. (i,−i) is the conjugate list of i but is not a basis.

The last two show that the two conditions in the definition of a normal basis are independent of each other.

Facts & Assumptions

Given: The complex field with i2=−1 and conjugation a+bi‾=a−bi for a,b∈R (Real and imaginary parts, complex conjugation, and modulus); in R one has 2≠0.

[L1]

C=R(i) is a simple algebraic extension with power basis 1,i and [C:R]=2 (C/R has power basis 1,i and degree 2, The degree [K:F]=dim⁡FK of a finite field extension).

[L2]

Every field automorphism of C fixing R pointwise is either the identity or complex conjugation, and these two are distinct (The only real-field automorphisms of C are the identity and complex conjugation, Relative field automorphisms and Aut⁡(K/F)).

[L4]

A finite extension K/F with G=Aut⁡(K/F) is Galois exactly when ∣G∣=[K:F] (Equivalent characterizations of a finite Galois extension, Finite Galois extensions and Gal⁡(K/F)).

[L6]

Every finite Galois extension of an infinite field has a normal basis (Every finite Galois extension of an infinite field has a normal basis).

Verification

technique · direct
1.1L1L2L3L4

By [L2] and [L3] the group Aut⁡(C/R) has exactly the two elements id and conjugation, so its order is 2=[C:R] by [L1]; hence C/R is finite Galois with that Galois group by [L4].

2.1step 1.1L1given

The conjugate list of 1+i is (1+i, 1−i), whose members have coordinate lists (1,1) and (1,−1) in the ordered basis (1,i) of [L1]. For a,b∈R, a(1+i)+b(1−i)=(a+b)+(a−b)i vanishes exactly when a+b=0 and a−b=0, hence when 2a=0, that is a=0 and then b=0.

2.2step 1.1L1given

(1,i) is a basis by [L1], but no z∈C has conjugate list (z,z‾) with underlying set {1,i}: such a z would lie in {1,i}, and the set for z=1 is {1} while for z=i it is {i,−i}, neither of which is {1,i}.

3.1step 1.1step 2.1L1L5L6

So the linear map R2→C sending (a,b) to a(1+i)+b(1−i) has trivial kernel; both spaces have dimension two by [L1], so [L5] makes it bijective and (1+i,1−i) an ordered R-basis of C. Being the conjugate list of 1+i, it is a normal basis, in agreement with [L6].

4.1step 1.1step 3.1step 2.2L5given∎

(i,−i) is the conjugate list of i, since i‾=−i, and its two members are distinct; but 1⋅i+1⋅(−i)=0 is a vanishing combination with nonzero coefficients, so the list is not independent and by [L5] is not a basis. With steps 3.1 and 2.2 this establishes all three claims.

False statementConstruction: AI-adaptedVerification: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

FALSE: every basis of a finite field over a subfield is a normal basis

Statement

False claim. For every extension E/Fq of finite fields, every Fq-basis of E is a normal basis (Normal bases of a finite Galois extension).

Facts & Assumptions

Given: The ring L:=F2[t]/(t2+t+1) with α the class of t, so that α2=α+1 because α2+α+1=0 and −1=1 in characteristic two.

[L1]

A polynomial of degree 2 or 3 over a field is irreducible if and only if it has no root in that field (A polynomial of degree two or three over a field is irreducible exactly when it has no root in the field); and F[x]/(p) is a field exactly when p is irreducible (For a nonconstant p in F[x], the ideal (p) is maximal and F[x]/(p) is a field exactly when p is irreducible).

[L4]

A normal basis of K/F is an ordered F-basis of the form (σ1γ,…,σnγ) for a single γ∈K, indexed by Gal⁡(K/F) (Normal bases of a finite Galois extension).

[L5]

Every finite Galois extension has a normal basis (Every finite Galois extension has a normal basis).

Refutation

technique · direct
1.1L1L2given

t2+t+1 has no root in F2, its values at 0 and 1 both being 1, so it is irreducible and L is a field by [L1]; it is the minimal polynomial of α, so [L:F2]=2 with ordered basis (1,α) by [L2], and L has four elements 0,1,α,α+1.

2.1step 1.1L3

By [L3] the extension L/F2 is Galois with Gal⁡(L/F2)={id,σ}, where σ(x)=x2.

3.1step 1.1step 2.1given

The conjugate lists of the four elements are (0,0), (1,1), (α,α+1) and (α+1,α), using α2=α+1 and (α+1)2=α2+1=α. Their underlying sets are {0}, {1} and {α,α+1}.

4.1step 1.1step 3.1L4

The list (1,α) is an F2-basis of L by step 1.1, but its underlying set {1,α} is none of the three sets in step 3.1, so it is not the conjugate list of any element and hence is not a normal basis by [L4]. The false claim therefore fails already for L/F2.

5.1step 3.1step 4.1L4L5∎

What is true is the existential statement: some element of L generates a normal basis, and α does, since (α,α+1) is a list of two distinct elements whose only vanishing F2-combinations are trivial, as α≠0, α+1≠0 and α+(α+1)=1≠0. That is the content of [L5], which asserts existence and never universality.

Remarks

  • Where the false claim comes from. The normal basis theorem is an existence statement, and its proofs single out an element by a nonvanishing condition — a determinant in the infinite case, a cyclic vector in the finite case. Both conditions genuinely exclude some elements, as A normal basis of F8 over F2 shows over F8.
ExampleConstruction: AI-adaptedVerification: AI-adaptedprecheck passaudited 2026-08-26Open item page →

Φ1 through Φ12 computed from the divisor recursion

Example

Running the recursion of The cyclotomic polynomials Φn∈Z[t], defined by ∏d∣nΦd=tn−1 gives

Φ1=t−1,Φ2=t+1,Φ3=t2+t+1,Φ4=t2+1,Φ5=t4+t3+t2+t+1,Φ6=t2−t+1,Φ7=t6+t5+t4+t3+t2+t+1,Φ8=t4+1,Φ9=t6+t3+1,Φ10=t4−t3+t2−t+1,Φ11=∑k=010tk,Φ12=t4−t2+1,

each monic in Z[t], with degrees

1, 1, 2, 2, 4, 2, 6, 4, 6, 4, 10, 4

matching φ(1),…,φ(12) (The unit group (Z/n)× and Euler's totient φ(n)=∣(Z/n)×∣ for n≥1).

Facts & Assumptions

Given: The recursion Φ1=t−1 and Φn=(tn−1)/∏d∣n, d<nΦd (The cyclotomic polynomials Φn∈Z[t], defined by ∏d∣nΦd=tn−1, The sum ∑i∈Sai over a finite index set, and its product form, Divisibility in Z: d∣a when a=dq for some integer q); and the elementary identity (ta−1)(ta(b−1)+⋯+ta+1)=tab−1 for a,b≥1.

[L1]

For every n≥1, Φn is monic in Z[t] with ∏d∣nΦd=tn−1 and deg⁡Φn=φ(n) (The recursion defines a unique monic Φn∈Z[t], of degree φ(n), Degree, leading coefficient and monic polynomial, with the zero polynomial having no degree).

[L2]

For a prime p and r≥1, Φpr=∑k=0p−1tkpr−1 (Φpr(t)=∑k<ptkpr−1, and Φpr(t+1) is Eisenstein at p).

[L3]

Z[t] is an integral domain (A polynomial ring over an integral domain is an integral domain), so a nonzero factor may be cancelled; and division by a monic polynomial has a unique quotient and remainder (Division by a monic polynomial over a commutative ring).

[L4]

φ(1)=1 and φ(p)=p−1 for a prime p (φ(1)=1, and φ(p)=p−1 for every prime p); φ(pk)=pk−pk−1 (For a prime p and k≥1, φ(pk)=pk−pk−1); and for n≥1 with prime divisors p0,…,pr−1 and ki=vpi(n), φ(n)=∏i<r(piki−piki−1) (Euler's product formula φ(n)=n∏p∣n(1−1/p)=∏pk∥n(pk−pk−1) for n≥1, stated through a finite injective list of its prime divisors).

Verification

technique · direct
1.1L4given

Φ1=t−1 is the base clause of the recursion, of degree 1=φ(1) by [L4].

1.2L2

The prime powers among 2,…,12 are 2,3,4,5,7,8,9,11, and [L2] gives their cyclotomic polynomials directly: Φ2=1+t, Φ3=1+t+t2, Φ4=1+t2, Φ5=1+t+t2+t3+t4, Φ7=∑k=06tk, Φ8=1+t4, Φ9=1+t3+t6 and Φ11=∑k=010tk.

2.1step 1.2L1L3given

For n=6: the positive divisors of 6 are 1,2,3,6 and those of 3 are 1,3, so [L1] gives Φ1Φ2Φ3Φ6=t6−1 and Φ1Φ3=t3−1; dividing and using the given identity with a=3, b=2 yields Φ2Φ6=(t6−1)/(t3−1)=t3+1. Since (t+1)(t2−t+1)=t3+1 and Φ2=t+1 is nonzero, cancelling in Z[t] by [L3] gives Φ6=t2−t+1.

2.2step 1.2L1L3given

For n=10: the divisors of 10 are 1,2,5,10 and those of 5 are 1,5, so Φ2Φ10=(t10−1)/(t5−1)=t5+1 by [L1] and the given identity with a=5, b=2; and (t+1)(t4−t3+t2−t+1)=t5+1, so cancelling gives Φ10=t4−t3+t2−t+1.

3.1step 1.2step 2.1L1L3given

For n=12: the divisors of 12 are 1,2,3,4,6,12 and those of 6 are 1,2,3,6, so Φ4Φ12=(t12−1)/(t6−1)=t6+1 by [L1] and the given identity with a=6, b=2; and (t2+1)(t4−t2+1)=t6+1 with Φ4=t2+1, so cancelling gives Φ12=t4−t2+1.

4.1step 1.1step 1.2step 2.1step 2.2step 3.1L1L4∎

The degrees read off the displayed polynomials are 1,1,2,2,4,2,6,4,6,4,10,4. By [L4] these are φ(1)=1, φ(2)=1, φ(3)=2, φ(4)=22−2=2, φ(5)=4, φ(6)=(2−1)(3−1)=2, φ(7)=6, φ(8)=23−22=4, φ(9)=32−3=6, φ(10)=(2−1)(5−1)=4, φ(11)=10 and φ(12)=(22−2)(3−1)=4, so every degree matches [L1].

Remarks

ExampleConstruction: Literature-sourcedVerification: Literature-sourcedprecheck passaudited 2026-08-26Open item page →

Φ7(t+1) is Eisenstein at seven

Example

The translated seventh cyclotomic polynomial is

Φ7(t+1)=t6+7t5+21t4+35t3+35t2+21t+7.

Its leading coefficient is 1, every other coefficient is divisible by 7, and its constant term 7 is not divisible by 72. So it satisfies Eisenstein's criterion at the prime 7, and therefore Φ7 is irreducible over Q.

Facts & Assumptions

Given: The prime-power cyclotomic formula and the polynomial Φ7.

[L1]

For a prime p and r≥1, Φpr(t)=∑k=0p−1tkpr−1, and Φpr(t+1) is Eisenstein at p (Φpr(t)=∑k<ptkpr−1, and Φpr(t+1) is Eisenstein at p).

[L2]

Eisenstein's criterion: if a prime p divides every non-leading coefficient of a polynomial in Z[t], does not divide the leading coefficient, and p2 does not divide the constant term, then the polynomial is irreducible over Q (Eisenstein criterion over the integers).

Verification

technique · direct
1.1L1

Applying [L1] at p=7 and r=1 gives Φ7(t)=1+t+t2+t3+t4+t5+t6.

2.1step 1.1algebra

Therefore Φ7(t+1)=(t+1)7−1t=t6+7t5+21t4+35t3+35t2+21t+7, by the binomial theorem.

3.1step 2.1L2algebra

In the polynomial of step 2.1 the leading coefficient is 1, the remaining coefficients 7,21,35,35,21,7 are all divisible by 7, and the constant term 7 is not divisible by 49; so [L2] applies at the prime 7.

4.1step 3.1L1∎

Hence Φ7(t+1) is irreducible over Q, and this is exactly the degree-one prime-power case of [L1].

Remarks

  • Why this example matters later. The explicit coefficients are what the counterexample page uses when it says the Eisenstein route already proves irreducibility for prime-power cyclotomic polynomials before the general Dedekind argument is built.
ExampleConstruction: Literature-sourcedVerification: Literature-sourcedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

Φ5 has four roots in F11

Example

Over F11 the fifth cyclotomic polynomial

Φ5(t)=t4+t3+t2+t+1

splits into four distinct linear factors:

Φ5(t)=(t−3)(t−4)(t−5)(t−9).

The four roots 3,4,5,9 are exactly the primitive fifth roots of unity in F11.

Facts & Assumptions

Given: The field F11 and the polynomial Φ5(t)=t4+t3+t2+t+1.

[L1]

If gcd⁡(n,q)=1, the reduction of Φn in Fq[t] is a product of distinct monic irreducibles, each of degree the order of [q] modulo n (For gcd⁡(n,q)=1 the reduction of Φn in Fq[t] is a product of distinct monic irreducibles, each of degree the order of [q] modulo n).

[L2]

For gcd⁡(n,q)=1, the image of Gal⁡(Fq(μn)/Fq) in (Z/n)× is generated by [q], so the extension degree is the order of [q] modulo n (For gcd⁡(n,q)=1 the image of Gal⁡(Fq(μn)/Fq) in (Z/n)× is generated by [q]).

Verification

technique · direct
1.1L1L2algebra

In (Z/5)× one has [11]=[1], so the order of [11] modulo 5 is 1. Hence [L1] and [L2] say every irreducible factor of Φ5 over F11 is linear, and the factors are distinct.

1.2givenalgebra

The powers of 3 in F11× are 32=9, 33=5, 34=4 and 35=1, so the four nontrivial fifth roots of unity in F11 are 3,9,5,4.

2.1step 1.2algebra

Each of 3,4,5,9 is therefore a root of t5−1 and is not 1, so each is a root of Φ5(t)=(t5−1)/(t−1). Since Φ5 is monic of degree 4, it follows that Φ5(t)=(t−3)(t−4)(t−5)(t−9).

3.1step 1.2algebra∎

The roots 3,4,5,9 all have multiplicative order 5 by step 1.2, so they are exactly the primitive fifth roots of unity in F11.

Remarks

  • This is the order-one case of the finite-field factorisation theorem. When [q] has order one modulo n, every irreducible factor has degree one and the whole cyclotomic polynomial splits over the base field.
ExampleConstruction: Literature-sourcedVerification: Literature-sourcedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

Φ7 factors over F2 into the two monic irreducible cubics

Example

Over F2 one has

Φ7(t)=t6+t5+t4+t3+t2+t+1=(t3+t+1)(t3+t2+1).

These are the two monic irreducible cubic factors, and over a splitting field the two factors correspond to the Frobenius orbits

{ζ,ζ2,ζ4}and{ζ3,ζ6,ζ5}

of a primitive seventh root of unity ζ.

Facts & Assumptions

Given: The field F2 and a primitive seventh root of unity ζ in a splitting field of Φ7.

[L1]

If gcd⁡(n,q)=1, the reduction of Φn in Fq[t] is a product of distinct monic irreducibles, each of degree the order of [q] modulo n (For gcd⁡(n,q)=1 the reduction of Φn in Fq[t] is a product of distinct monic irreducibles, each of degree the order of [q] modulo n).

[L2]

For gcd⁡(n,q)=1, the image of Gal⁡(Fq(μn)/Fq) in (Z/n)× is generated by [q] (For gcd⁡(n,q)=1 the image of Gal⁡(Fq(μn)/Fq) in (Z/n)× is generated by [q]).

[L3]

The roots of a monic irreducible polynomial of degree d over Fq are one Frobenius orbit α,αq,…,αqd−1 (A monic irreducible of degree d over Fq has the d distinct roots α,αq,…,αqd−1).

Verification

technique · direct
1.1L1L2algebra

In (Z/7)× the class [2] has order 3, since 23=8≡1(mod7) and 2≢1, 22=4≢1(mod7). So [L1] and [L2] say every irreducible factor of Φ7 over F2 is a distinct cubic.

2.1step 1.1algebra

The product of the two monic cubics is (t3+t+1)(t3+t2+1)=t6+t5+t4+t3+t2+t+1=Φ7(t) in F2[t]. Since both factors are monic of degree 3, step 1.1 makes them the two irreducible factors of Φ7.

3.1step 1.1step 2.1L3algebra∎

Frobenius acts by ζ↦ζ2, so the orbit of ζ is {ζ,ζ2,ζ4} because ζ8=ζ, and the orbit of ζ3 is {ζ3,ζ6,ζ5} because (ζ3)2=ζ6, (ζ6)2=ζ12=ζ5 and (ζ5)2=ζ10=ζ3. These are the two size-three Frobenius orbits of primitive seventh roots, and [L3] identifies them as the respective root sets of the two irreducible cubic factors from step 2.1.

Remarks

  • This is the degree-three case of the theorem, not a coincidence of cubics. The orbit size and the factor degree are both the order of [2] modulo 7.
ExampleConstruction: AI-generatedVerification: AI-generatedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

Gal⁡(Q(ζ12)/Q)≅(Z/12)× and its three quadratic subfields

Example

Let ζ:=ζ12. Then

Gal⁡(Q(ζ)/Q)≅(Z/12)×={[1],[5],[7],[11]},

every nonidentity element has order two, and the three order-two subgroups have fixed fields

Q(i),Q(3),Q(−3).

So Q(ζ12) has exactly three quadratic intermediate fields.

Facts & Assumptions

Given: A primitive twelfth root of unity ζ=ζ12 and the automorphisms σa(ζ)=ζa for [a]∈(Z/12)×.

[L1]

[Q(ζ12):Q]=φ(12)=4 and Gal⁡(Q(ζ12)/Q)≅(Z/12)× ([Q(ζn):Q]=φ(n) and Gal⁡(Q(μn)/Q)≅(Z/n)×).

[L2]

For a finite Galois extension E/F, subgroups of Gal⁡(E/F) correspond bijectively to intermediate fields, and the fixed field of a subgroup H has degree [EH:F]=[Gal⁡(E/F):H] (The fundamental theorem of finite Galois theory).

Verification

technique · direct
1.1L1algebra

The units modulo 12 are [1],[5],[7],[11], since these are exactly the residue classes in {1,…,11} coprime to 12. Their squares are [25]=[1], [49]=[1] and [121]=[1], so every nonidentity element has order two.

2.1step 1.1L1L2

Therefore (Z/12)× is the Klein four-group, with three order-two subgroups: Hi={[1],[5]},H−3={[1],[7]},H3={[1],[11]}. By [L1] and [L2], each fixed field has degree 2 over Q.

3.1step 2.1algebra

The subgroup Hi fixes i=ζ3, because σ5(ζ3)=ζ15=ζ3. Since i∉Q and the fixed field has degree 2 by step 2.1, that fixed field is Q(i).

3.2step 2.1algebra

The subgroup H−3 fixes 2ζ2−1, because σ7(ζ2)=ζ14=ζ2; and (2ζ2−1)2=4ζ4−4ζ2+1=−3, since ζ2 is a root of t2−t+1. So the fixed field contains −3, and again step 2.1 makes it exactly Q(−3).

3.3step 2.1algebra

The subgroup H3 fixes ζ+ζ−1, because σ11 is complex conjugation. Moreover (ζ+ζ−1)2=ζ2+2+ζ−2=3, since ζ2+ζ−2=1. So the fixed field contains 3, and step 2.1 makes it exactly Q(3).

4.1step 2.1step 3.1step 3.2step 3.3L2∎

The three order-two subgroups of step 2.1 therefore yield the three quadratic intermediate fields Q(i), Q(−3) and Q(3), and there are no others because [L2] gives a bijection between subgroups and intermediate fields.

Remarks

  • The same phenomenon already occurs at order eight. The field Q(ζ8) also has Klein four Galois group and three quadratic subfields. The order-twelve calculation is useful because its three fields are the familiar Q(i), Q(3) and Q(−3).
ExampleConstruction: AI-generatedVerification: AI-generatedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

In characteristic three, t3−1=(t−1)3 and μ6 coincides with μ2

Example

Let K be a field of characteristic 3. Then

t3−1=(t−1)3,μ3(K)={1},μ6(K)=μ2(K)={1,−1},

so t6−1 has only the two distinct roots 1 and −1 rather than six.

Facts & Assumptions

Given: A field K of characteristic 3.

[L1]

For a fixed integer k≥1, in characteristic p the only pk-th root of unity is 1, and tpk−1=(t−1)pk (In characteristic p the only pk-th root of unity is 1, and tpk−1=(t−1)pk).

Verification

technique · direct
1.1L1

Applying [L1] at p=3 and k=1 gives t3−1=(t−1)3 and μ3(K)={1}.

1.2L2algebra

Since (1)2=1 and (−1)2=1, one has {1,−1}⊆μ2(K). Conversely, if x∈μ2(K) then x2=1, so x2−1=(x−1)(x+1)=0 and therefore x=1 or x=−1 in the field K; hence μ2(K)={1,−1}.

2.1step 1.1step 1.2L2

If x∈μ6(K) then (x2)3=x6=1, so x2∈μ3(K) by [L2]; step 1.1 gives x2=1, hence x∈μ2(K) by [L2]. Thus μ6(K)⊆μ2(K).

2.2step 1.2L2algebra

Conversely, if x∈μ2(K) then x6=(x2)3=1, so x∈μ6(K). Therefore μ6(K)=μ2(K)={1,−1}.

3.1step 1.1step 2.2algebra∎

Using step 1.1, t6−1=(t3−1)(t3+1)=(t−1)3(t+1)3, so its only distinct roots are 1 and −1, exactly the two elements of step 2.2.

Remarks

  • This is why the characteristic hypothesis is load-bearing. The statement "∣μn∣=n" fails here for two different reasons at once: the polynomial t3−1 is inseparable, and the extra cube roots never appear even after passing to a splitting field because the splitting field is already the base field.
CounterexampleConstruction: Literature-sourcedVerification: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

F3(μ5)∩F3(μ7) is larger than F3 although five and seven are coprime

Statement refuted

That the rational intersection theorem Q(μm)∩Q(μn)=Q(μgcd⁡(m,n)) holds over every base field: that for every field K and all positive integers m,n with the characteristic of K dividing neither,

K(μm)∩K(μn)=K(μgcd⁡(m,n)).

The witness below takes K=F3, m=5 and n=7, and realizes both splitting fields inside one fixed field Ω of order 312. Since gcd⁡(5,7)=1, the right-hand side is K(μ1)=F3, while the intersection on the left is the common subfield F9⊆Ω.

Facts & Assumptions

Given: The base field K=F3 and a field Ω of order 312, which exists by For every prime p and n≥1, a field with pn elements exists. The two cyclotomic splitting fields will be identified with their base-field-isomorphic copies inside Ω.

[L1]

For gcd⁡(n,q)=1, the image of Gal⁡(Fq(μn)/Fq) in (Z/n)× is generated by [q], so the degree of Fq(μn)/Fq is the order of [q] modulo n (For gcd⁡(n,q)=1 the image of Gal⁡(Fq(μn)/Fq) in (Z/n)× is generated by [q]).

[L2]

The intermediate fields of FqN/Fq are exactly the Fqd for the positive divisors d of N, one for each divisor, with Fqd⊆Fqe exactly when d∣e (The intermediate fields of Fqn/Fq are the Fqd, one for each positive divisor d of n).

[L3]

Over Q one has Q(μm)∩Q(μn)=Q(μgcd⁡(m,n)) (Q(μm)∩Q(μn)=Q(μgcd⁡(m,n))).

[L4]

K(μr) is the splitting field of tr−1 over K (The cyclotomic extension K(μn) as a splitting field of tn−1).

[L5]

Finite fields of the same order are isomorphic by an isomorphism fixing their common prime field (Finite fields of the same order are isomorphic).

Counterexample

technique · direct
1.1L1L2L4L5algebra

In (Z/5)×, the class [3] has order 4, since 34=81≡1(mod5) and no smaller positive power of 3 is congruent to 1 modulo 5. So [L1] gives [F3(μ5):F3]=4, hence this splitting field has order 34 and [L5] lets us identify it over F3 with the unique subfield F34 of Ω.

1.2L1L2L4L5algebra

In (Z/7)×, the powers of [3] are [3],[2],[6],[4],[5],[1], so [3] has order 6. Thus [L1] gives [F3(μ7):F3]=6, hence this splitting field has order 36 and [L5] lets us identify it over F3 with the unique subfield F36 of Ω.

2.1step 1.1step 1.2L2

Under the fixed identifications of steps 1.1 and 1.2, both F34 and F36 are subfields of Ω=F312 by [L2], since 4∣12 and 6∣12. Their intersection is then an intermediate field of Ω/F3, so by [L2] it is F3d for some divisor d of 12. Because the intersection lies in both fields, [L2] gives d∣4 and d∣6, hence d∣2; and since F32 lies in both fields, [L2] gives 2∣d. Therefore d=2 and F3(μ5)∩F3(μ7)=F32=F9.

3.1step 2.1L4algebra

Since gcd⁡(5,7)=1, the right-hand side of the refuted identity is K(μ1), which is just K=F3 because t−1 already splits over K. So the claimed equality would read F9=F3, which is false.

4.1step 3.1L3∎

The refuted statement therefore fails over the base field F3, even though the rational theorem [L3] is true.

Remarks

  • Why the rational hypothesis matters. Over finite fields the intersection is controlled by the gcd of the extension degrees, not by the gcd of the orders of the roots of unity.
False statementConstruction: Literature-sourcedVerification: AI-adaptedprecheck passaudited 2026-08-26Open item page →

FALSE: every cyclotomic polynomial has all coefficients in {−1,0,1}

Statement

False claim. Every coefficient of every cyclotomic polynomial Φn∈Z[t] lies in {−1,0,1}.

The failure first appears at n=105: the coefficient of t7 in Φ105(t) is −2.

Facts & Assumptions

Given: The cyclotomic recursion ∏d∣nΦd(t)=tn−1 for n≥1 (The cyclotomic polynomials Φn∈Z[t], defined by ∏d∣nΦd=tn−1).

[L1]

For every n≥1, Φn is a monic polynomial in Z[t] and the displayed divisor recursion holds (The recursion defines a unique monic Φn∈Z[t], of degree φ(n)).

Refutation

technique · direct
1.1givenL1algebra

Running the divisor recursion for n=105=3⋅5⋅7 and truncating modulo t8 gives Φ105(t)≡(1−t3)(1−t5)(1−t7)1−t≡1+t+t2−t5−t6−2t7(modt8). The first congruence is the defining recursion with every factor of degree at least 15 dropped modulo t8, and the second comes from expanding (1−t)−1=1+t+t2+t3+t4+t5+t6+t7(modt8).

2.1step 1.1algebra∎

Step 1.1 shows that the coefficient of t7 in Φ105(t) is −2, and −2∉{−1,0,1}. So the false claim fails.

Remarks

  • Why this is a real pattern and not a silly claim. For many small values of n the coefficients do lie in {−1,0,1}, so the first counterexample is not visually obvious from the recursion alone.
False statementConstruction: AI-adaptedVerification: AI-adaptedprecheck passaudited 2026-08-26Open item page →

FALSE: Φn is irreducible over every field

Statement

False claim. For every field K and every n≥1 with the characteristic of K not dividing n, the image of Φn in K[t] is irreducible.

What is true is different in two directions: over Q every Φn is irreducible, but over a finite field the factor degree is governed by the order of the Frobenius class modulo n.

Facts & Assumptions

Given: The rational irreducibility theorem and the finite-field factorisation theorem.

[L1]

For every n≥1, the cyclotomic polynomial Φn is irreducible in Q[t] (Φn is irreducible in Q[t] for every n≥1).

[L2]

If gcd⁡(n,q)=1, the reduction of Φn in Fq[t] is a product of distinct monic irreducibles, each of degree the order of [q] modulo n (For gcd⁡(n,q)=1 the reduction of Φn in Fq[t] is a product of distinct monic irreducibles, each of degree the order of [q] modulo n).

Refutation

technique · direct
1.1L2algebra

In (Z/5)× one has [11]=[1], so the order of [11] modulo 5 is 1. Therefore [L2] says that over F11 every irreducible factor of Φ5 has degree 1.

2.1step 1.1algebra

Hence the reduction of Φ5 in F11[t] is a product of distinct linear factors, so it is reducible there. This contradicts the false claim.

3.1step 2.1L1∎

The contradiction does not touch [L1]: irreducibility over Q is a theorem, but it does not persist over arbitrary base fields.

Remarks

  • The finite-field theorem is the correct replacement. The question over Fq is not "irreducible or not?" in the abstract, but "what is the order of [q] modulo n?"
False statementConstruction: AI-adaptedVerification: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

FALSE: μn(K) has n elements in every field K

Statement

False claim. For every field K and every n≥1, the group μn(K) of n-th roots of unity in K has exactly n elements.

The witness below shows two different failures: over Q there is no primitive cube root of unity in the field at all, while in characteristic 3 the equation x3=1 is inseparable and has only one root.

Facts & Assumptions

Given: The groups μn(K) of roots of unity.

[L1]

μn(K) is cyclic of order dividing n, and it has a primitive n-th root of unity exactly when its order is n (μn(K) is cyclic of order dividing n, and has a primitive n-th root of unity exactly when its order is n).

[L3]

Refutation

technique · direct
1.1L1L2

If μ3(Q) had three elements, then [L1] would give a primitive cube root of unity ζ3 in Q. But then Q(ζ3)=Q, contradicting [L2], which says this extension has degree 2. So μ3(Q) does not have three elements.

1.2L3

If K has characteristic 3, then [L3] gives μ3(K)={1}, so again μ3(K) does not have three elements.

2.1step 1.1step 1.2∎

The false claim fails already at n=3, both over Q and over every field of characteristic 3.

Remarks

  • The two failures have different causes. Over Q the polynomial t3−1 is separable but its nontrivial roots lie in a quadratic extension; in characteristic 3 the polynomial itself collapses to (t−1)3.
False statementConstruction: AI-adaptedVerification: AI-adaptedprecheck passjudge pass (deepseek-v4-pro + gpt-5.6-terra)audited 2026-08-26Open item page →

FALSE: every finite abelian group is Gal⁡(Q(μn)/Q) for some n

Statement

False claim. For every finite abelian group G there is an n≥1 with

Gal⁡(Q(μn)/Q)≅G.

The obstruction is visible already at the level of cardinality: the cyclic group C3 occurs as a Galois group over Q, but never as the Galois group of a cyclotomic field.

Facts & Assumptions

Given: Cyclotomic Galois groups and the theorem realising finite abelian groups over Q.

[L2]

Every finite abelian group is the Galois group of some finite Galois extension of Q (Every finite abelian group is the Galois group of some finite Galois extension of Q).

[L3]

In a finite group, the order of every subgroup divides the order of the group (Lagrange's theorem: ∣G∣=[G:H]∣H∣ for every subgroup H of a finite group G).

Refutation

technique · direct
1.1L1algebra

For n=1 and n=2, the group (Z/n)× is trivial, so φ(1)=φ(2)=1.

1.2L1L3algebra

If n≥3, then the unit class [−1] in (Z/n)× has order 2: one has [−1]2=[1], and [−1]≠[1] because otherwise n would divide 2, contrary to n≥3. Therefore [L3] makes the group order φ(n)=∣(Z/n)×∣ even.

2.1step 1.1step 1.2L1

Steps 1.1 and 1.2 show that φ(n) is never 3. So no cyclotomic field Q(μn) has Galois group of order 3, and in particular none has Galois group isomorphic to C3.

3.1step 2.1L2∎

By [L2], however, some finite Galois extension of Q does have Galois group C3. Hence the false claim fails.

Remarks

  • What the true theorem says instead. The proved result is that every finite abelian group is the Galois group of a subfield of a cyclotomic field, not of the cyclotomic field itself.
ExampleConstruction: AI-adaptedVerification: AI-adaptedprecheck passaudited 2026-08-26Open item page →

A degree-three Galois extension of Q inside Q(ζ7)

Example

Let ζ:=ζ7. Then the fixed field of the unique order-two subgroup of Gal⁡(Q(ζ)/Q) is

Q(ζ+ζ−1),

a degree-three Galois extension of Q with cyclic Galois group, and the element ζ+ζ−1 has minimal polynomial

t3+t2−2t−1.

Facts & Assumptions

Given: A primitive seventh root of unity ζ=ζ7.

[L1]

Gal⁡(Q(ζ7)/Q)≅(Z/7)× and has order φ(7)=6 ([Q(ζn):Q]=φ(n) and Gal⁡(Q(μn)/Q)≅(Z/n)×).

[L2]

A finite cyclic group has exactly one subgroup of each order dividing its own (A finite cyclic group has exactly one subgroup of each order dividing its own).

[L3]

For a finite Galois extension, subgroups correspond to intermediate fields, and the fixed field of a subgroup H has degree equal to the subgroup index (The fundamental theorem of finite Galois theory).

[L4]

Every finite subgroup of the unit group of an integral domain is cyclic (Every finite subgroup of the unit group of an integral domain is cyclic).

[L5]

Under the finite Galois correspondence, a normal subgroup H has a Galois fixed field and restriction gives Gal⁡(F/Q)≅G/H (Normal subgroups, conjugate fields, and quotient groups in the Galois correspondence).

Verification

technique · direct
1.1L1L2L3L4

By [L1] the Galois group of Q(ζ)/Q is isomorphic to the finite subgroup (Z/7)× of the unit group of the field Z/7, so [L4] makes it cyclic; its order is 6. Thus [L2] gives a unique subgroup H of order 2, and [L3] makes its fixed field F have degree [F:Q]=6/2=3.

2.1step 1.1algebra

The subgroup H is generated by the class [−1], so it acts by complex conjugation. Therefore ζ+ζ−1 is fixed by H and lies in F.

3.1step 2.1algebra

Put x:=ζ+ζ−1. Then ζ2+ζ−2=x2−2,ζ3+ζ−3=x3−3x. Since 1+ζ+ζ2+ζ3+ζ4+ζ5+ζ6=0, dividing by ζ3 gives 1+(ζ+ζ−1)+(ζ2+ζ−2)+(ζ3+ζ−3)=0. Substituting the expressions above yields x3+x2−2x−1=0.

4.1step 1.1step 3.1L1

The element x is not rational: if it were, then ζ would satisfy the quadratic polynomial t2−xt+1∈Q[t], which would force [Q(ζ):Q]≤2, contradicting [L1]. Since x∈F, the prime degree [F:Q]=3 from step 1.1 leaves only the subfields Q and F, so Q(x)=F. Therefore the minimal polynomial of x has degree 3, and the cubic from step 3.1 is that minimal polynomial.

5.1step 1.1L5L6algebra∎

The ambient Galois group is cyclic and hence abelian, so H is normal. By [L5], the fixed field F/Q is Galois and Gal⁡(F/Q) is isomorphic to the quotient by H, which has order 3. The group is cyclic by [L6], so F/Q is a cyclic cubic Galois extension.

Remarks

  • This is the smallest nontrivial case of the subfield theorem. The subgroup lattice of (Z/7)× has one index-two subgroup, and the fixed field is already visible through the real element ζ+ζ−1.

Sources