Alphabeta Math
Pipeline-generated
How statement and proof provenance work

The first chip identifies the source of the statement or construction; the second identifies the source of its local proof or verification.

  • Literature-sourced: the exact statement appears in a cited source; only wording and notation differ.
  • AI-adapted: a semantically identical restatement of literature-sourced material, modulo indexing, notation, and boundary cases adopted by the library.
  • AI-generated: a genuinely novel statement formulated by AI, with no source for the claim itself.

These labels describe origin, not correctness: citations and verification chips remain separate evidence.

✓ 16 results · all verified · 13 also independently AI-judged
Every result on this page is machine-checked by a proof checker and read in full and owner-audited; the judge is an additional, independent cross-model AI review of the proofs. The 3 not AI-judged were verified by owner audit (typically over a confirmed judge false positive), not failures.

Cyclotomic Arithmetic and Reciprocity via Frobenius

1 · Prerequisites

2 · Summary

This page develops the arithmetic of the full cyclotomic fields Q(ζn) for reduced indices: an index n is reduced when it is odd or divisible by 4. The single excluded shape n≡2(mod4) is not intrinsic, because −ζm is a primitive 2m-th root of unity for odd m, so Q(ζ2m)=Q(ζm); the conductor theorem identifies the least admissible index of each cyclotomic field and makes the reduced-index convention precise.

The ring of integers is Z[ζn] throughout. The prime-power case is handled first, by the relation (1−ζpa)pa−1(p−1)=p up to a unit; the general ring-of-integers result then follows from a coprime-discriminant compositum step. These results give the discriminant formula. For prime decomposition, a choice-free monogenic factorisation lemma starts from the published choice-free ideal-factorisation theorem and compares local nilpotency indices with the multiplicities in the reduction of Φn modulo ℓ. The resulting prime factorisation gives the ramification criterion (ℓ ramifies exactly when ℓ∣n); for ℓ∤n it gives residue degree ord⁡n(ℓ), the count φ(n)/ord⁡n(ℓ) of primes, and complete splitting exactly when ℓ≡1(modn).

The second half passes to the quadratic Gauss sum τp=∑a(a/p)ζp a, whose Galois action is the Legendre symbol, whose square is p∗=(−1)(p−1)/2p, and which generates the unique quadratic subfield Q(p∗) of Q(ζp). Computing the restriction of the arithmetic Frobenius to that subfield in two ways identifies (p∗q) with (qp). Together with the first supplement, this proves quadratic reciprocity; the first and second supplements are also derived from the Frobenius power map and Euler's criterion. The Gauss sum itself is attached to a chosen primitive root and has no root-independent sign; only its square and its field are canonical.

3 · Logical flowchart

4 · Definitions, theorems and proofs

DefinitionDefinition: Literature-sourcedProof: Not applicableprecheck passjudge pass (gpt-6.1-sol)audited 2026-10-02Open item page →

Cyclotomic conductor of a full cyclotomic field

Definition

Let n≥1 and let K=Q(μn) be a cyclotomic extension of Q of order n (The cyclotomic extension K(μn) as a splitting field of tn−1): a splitting field of tn−1 over Q. When a primitive n-th root of unity ζn is fixed, K=Q(ζn).

A positive integer f is admissible for K when there is a Q-algebra embedding K↪F into a splitting field F of tf−1 over Q. The cyclotomic conductor of K is the least admissible positive integer,

cond⁡(K):=min⁡{ f≥1 : K↪Q(ζf) }.

Well-definedness. The set is nonempty, since the identity of K exhibits K↪K and K=Q(μn) is a splitting field of tn−1; by the well-ordering of the positive integers it therefore has a least element (The well-ordering principle). The value depends only on the Q-isomorphism class of K: if φ:K→K′ is an isomorphism of splitting fields of tn−1 and K↪Q(ζf) is an embedding, then composing with φ−1 exhibits K′↪Q(ζf), so K and K′ have the same admissible integers. In particular the conductor is unchanged by the choice of splitting field (Any two splitting fields of a polynomial are isomorphic over the base field).

Conductors are compared inside a common field. Every assertion below about an inclusion K⊆Q(ζf) is read inside one fixed algebraic closure of Q, in which one copy of each cyclotomic field has been chosen; by the previous paragraph this loses no information, because conductor statements are invariant under the Q-isomorphisms relating the choices.

Scope. This is a conductor of a full cyclotomic field only. It is not the Artin conductor of a Dirichlet character, not a conductor assigned to an arbitrary abelian number field, and no Kronecker-Weber premise is used or implied: the definition does not assert that an arbitrary abelian field lies in some Q(ζf). Admissibility of f=n does not make n the least admissible integer; identifying the least one is the content of Conductor of a full cyclotomic field.

LemmaStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (gpt-6.1-sol)audited 2026-10-02Open item page →

Prime-power cyclotomic ring, discriminant support and p factor

Statement

For a prime p and an integer a≥1 put K=Q(ζpa), e=φ(pa) and λ=1−ζpa. Then OK=Z[ζpa],(p)=(λ)e, the power basis 1,ζpa,…,ζpae−1 is an integral basis of OK, and the discriminant of that basis is a signed power of p with absolute value p pa−1(a(p−1)−1).

Facts & Assumptions

Given: A prime p, an integer a≥1, e:=φ(pa), a primitive pa-th root of unity ζ=ζpa in a fixed algebraic closure of Q, the field K:=Q(ζ), the element λ:=1−ζ, the subring R:=Z[ζ]⊆K, the polynomial Φ:=Φpa∈Z[t], and the index m:=[OK:R] of the order R in the ring of integers OK of K.

[F1]

Φ is monic of degree e=φ(pa), Φ(1)=p, and Φ(t) (tpa−1−1)=tpa−1 (Φpr(t)=∑k<ptkpr−1, and Φpr(t+1) is Eisenstein at p).

[F2]

Φ is irreducible over Q (Φn is irreducible in Q[t] for every n≥1), so Φ is the minimal polynomial of ζ over Q, K=Q[t]/(Φ), [K:Q]=deg⁡Φ=e, and 1,ζ,…,ζe−1 is a Q-basis of K (The cyclotomic extension K(μn) as a splitting field of tn−1).

[F3]

K/Q is Galois and Gal⁡(K/Q)≅(Z/pa)× via σj(ζ)=ζj; in particular for every integer j coprime to p there is σj∈Gal⁡(K/Q) with σj(ζ)=ζj ([Q(ζn):Q]=φ(n) and Gal⁡(Q(μn)/Q)≅(Z/n)×).

[F4]

ζ is integral over Z, being a root of the monic polynomial tpa−1, and the integral elements form a subring; hence R=Z[ζ]⊆OK (Integral elements over a commutative ring and algebraic integers, Integral elements over a nonzero base ring form a subring). A unital subring of OK that is free of rank [K:Q] as a Z-module is an order, every order has an integral basis and finite additive index in OK, and OK itself is free of rank [K:Q] (Order in a number field, Orders have integral bases and finite index, The ring of integers has rank the degree). Consequently R is an order in K, m is finite, and mOK⊆R: the quotient group OK/R is finite of order m and every element of a finite group of order m has order dividing m (The order of every element of a finite group divides the order of the group).

[F5]

Since K/Q is Galois of degree e, for x∈K the norm is NK/Q(x)=∏σ∈Gal⁡(K/Q)σ(x), and if x∈OK then NK/Q(x)∈Z (Norm and trace from embeddings, with the inseparable exponent in the norm formula, The rational algebraic integers are exactly the integers).

[F6]

disc⁡(1,ζ,…,ζe−1)=(−1)e(e−1)/2NK/Q(Φ′(ζ)) (Power-basis and polynomial discriminants), this is the discriminant disc⁡(R) of the order R, and disc⁡(R)=m2dK with dK:=disc⁡(OK) a nonzero integer (Discriminant of a basis and order, Order-index discriminant formula, Number-field discriminant is well-defined and nonzero).

[F7]

OK∩Q=Z: a rational number that is a root of a monic polynomial in Z[t] lies in Z (The rational algebraic integers are exactly the integers).

Proof

technique · direct
1.1F1F2F4given

Φ(ζ)=0 by [F1], so ζ is a root of the degree-e monic Φ, which is irreducible by [F2]; hence K has degree e over Q, the powers 1,ζ,…,ζe−1 form a Z-basis of R, and R is an order in OK with finite index m satisfying mOK⊆R.

1.2F1F2F3

For every integer j coprime to p the element ζj is a root of Φ: its order is pa, so (ζj)pa=1 while (ζj)pa−1≠1, and [F1] then forces Φ(ζj)=0; the e elements ζj with j∈(Z/pa)× are pairwise distinct, so comparison with the monic degree-e polynomial Φ gives Φ(X)=∏j∈(Z/pa)×(X−ζj) and p=Φ(1)=∏j∈(Z/pa)×(1−ζj).

2.1F1step 1.2

Each factor of the product in step 1.2 is a unit multiple of λ=1−ζ inside R: after replacing j by its least positive residue modulo pa the quotient (1−ζj)/(1−ζ)=1+ζ+⋯+ζj−1 lies in R, and if s satisfies js≡1(modpa) then ζ=(ζj)s and (1−ζ)/(1−ζj)=1+ζj+⋯+(ζj)s−1∈Z[ζj]⊆R; the two quotients are inverse to each other, so (1−ζj)/(1−ζ)∈R×. Hence p=uλe for some u∈R×, and consequently λeOK=pOK.

2.2F1F3F5step 1.2

Taking the product formula of [F5] over the Galois group identified in [F3] and substituting step 1.2 gives NK/Q(1−ζ)=∏σσ(1−ζ)=∏j∈(Z/pa)×(1−ζj)=Φ(1)=p; moreover NK/Q(ζ)∈Z by [F5] and NK/Q(ζ)pa=NK/Q(ζpa)=NK/Q(1)=1, so NK/Q(ζ)=±1, since the only integers whose pa-th power is 1 are ±1.

3.1F2F5step 2.2

For 0≤s≤a−1 one has NK/Q(1−ζps)=p ps: the element ζs:=ζps is a primitive pa−s-th root of unity in Ls:=Q(ζs), the computation of step 2.2 with a replaced by a−s gives NLs/Q(1−ζs)=p, and the embedding formula of [F5] applied to the tower Q⊆Ls⊆K gives NK/Q(1−ζps)=NLs/Q(1−ζs)[K:Ls]=p ps, since [K:Ls]=φ(pa)/φ(pa−s)=ps by [F2].

3.2F7step 2.1

Z∩λOK=pZ: step 2.1 gives p=uλe with u∈R×, so p∈λOK and pZ⊆Z∩λOK; conversely, if c∈Z∩λOK, then ce∈Z∩λeOK=Z∩pOK by step 2.1, say ce=pβ with β=ce/p∈OK, and β∈OK∩Q=Z by [F7], so p divides ce in Z and hence p divides c, that is c∈pZ.

4.1step 2.1step 3.2

(pOK)∩R=pR: the inclusion ⊇ is clear; for ⊆ let α∈pOK∩R and expand α=c0+c1λ+⋯+ce−1λe−1 with ci∈Z, which is possible because ζ=1−λ makes 1,λ,…,λe−1 a Z-basis of R as well. We show ci∈pZ for all i by induction: if α=∑i≥i0ciλi∈pOK with 0≤i0<e, then i0+1≤e and pOK=λeOK by step 2.1, so α∈λi0+1OK and α/λi0∈λOK; on the other hand α/λi0=ci0+λ∑i>i0ciλi−i0−1∈ci0+λOK, the bracket lying in R⊆OK. Hence ci0∈Z∩λOK=pZ by step 3.2, and subtracting ci0λi0∈pR⊆pOK from α leaves ∑i>i0ciλi∈pOK∩R for the next index. Thus all coefficients are multiples of p and α∈pR.

4.2F1F5F6step 2.2step 3.1

Differentiating the identity tpa−1=(tpa−1−1)Φ(t) of [F1] gives Φ′(t)(tpa−1−1)+Φ(t)pa−1tpa−1−1=patpa−1, and evaluating at t=ζ, where Φ(ζ)=0 and ζpa=1, yields Φ′(ζ)=paζpa−1/(ζpa−1−1). Taking norms with the product formula of [F5] and using multiplicativity of the norm together with step 3.1 at s=a−1 and NK/Q(ζ)=±1 from step 2.2 gives NK/Q(Φ′(ζ))=(pa)eNK/Q(ζ)pa−1/NK/Q(ζpa−1−1)=±p ae−pa−1=±p pa−1(a(p−1)−1), so [F6] gives disc⁡(R)=±pN with N:=pa−1(a(p−1)−1).

5.1F6step 4.2

Since disc⁡(R)=m2dK by [F6] and both disc⁡(R) and dK are nonzero integers, m2 divides disc⁡(R)=±pN in Z, so the positive index is m=pν for some integer ν≥0.

5.2step 4.1

OK∩p−1R=R: if β∈OK and pβ∈R, then pβ∈pOK∩R=pR by step 4.1, say pβ=pρ with ρ∈R, and cancelling p in the domain K gives β=ρ∈R; the reverse inclusion is trivial.

6.1step 5.2

By induction on j≥0 one has OK∩p−jR=R: the case j=0 is trivial and the case j=1 is step 5.2; if j≥1 and x∈OK satisfies pjx∈R, then pj−1(px)∈R with px∈OK, so the induction hypothesis gives px∈R, and then step 5.2 gives x∈R.

7.1step 1.1step 2.1step 4.2step 5.1step 6.1∎

By step 5.1 write the finite index as m=pν with ν≥0; then mOK=pνOK⊆R by step 1.1, so for any x∈OK we get pνx∈R and step 6.1 with j=ν gives x∈R. Hence OK=R=Z[ζ], and the equality p=uλe with u∈R× from step 2.1 is an equality of principal ideals (p)=(λ)e in OK; in particular the power basis 1,ζ,…,ζe−1 is an integral basis of OK whose discriminant, by step 4.2, equals ±p pa−1(a(p−1)−1). For pa=2 one has e=1, λ=2, K=Q and exponent 0, in agreement with the general computation.

Remarks

  • Both halves of the index argument are needed. The order-index formula alone gives only that the index m is a power of p; the descent through the coefficients of λ=1−ζ in steps 4.1 and 5.2 is what forces m=1. The unit identity p=uλe of step 2.1 is used in both places, through λeOK=pOK.
  • The boundary case pa=2 has K=Q, λ=2 and discriminant 1=20; the formulas Φ2(t)=t+1 and ζpa−1−1=ζ−1=−2 are consistent with the general computation in step 4.2, whose exponent is 0 there.
LemmaStatement: Literature-sourcedProof: AI-adaptedjudge pass (gpt-6.1-sol)audited 2026-10-02Open item page →

Integral basis and discriminant of a coprime-discriminant compositum

Statement

Let K and L be number fields inside a common algebraic closure, with compositum KL, let [KL:Q]=[K:Q] [L:Q], let α1,…,αm and β1,…,βn be integral bases of OK and OL, and suppose gcd⁡(dK,dL)=1. Then

OKL=OKOL,

the products αiβj form an integral basis of OKL, and

dKL=dK[L:Q] dL[K:Q].

Facts & Assumptions

Given: Number fields K,L inside a fixed algebraic closure of Q, with m:=[K:Q], n:=[L:Q], compositum KL, [KL:Q]=mn, integral bases α1,…,αm of OK and β1,…,βn of OL, and gcd⁡(dK,dL)=1.

[F1]

OK and OL are free Z-modules of ranks m and n, freely generated by the given integral bases (The ring of integers has rank the degree, Integral and power integral bases); OKL is free of rank mn.

[F2]

Degrees multiply in a tower and equal the dimension of the top field over the bottom one (Tower law for finite extensions: [L:F]=[L:K][K:F], The degree [K:F]=dim⁡FK of a finite field extension): [KL:L]=m and [KL:K]=n because [KL:Q]=[KL:L] [L:Q] and [L:Q]=n.

[F3]

The algebraic integers form a subring of C (Integral elements over a nonzero base ring form a subring, Integral elements over a commutative ring and algebraic integers); if γ is a root of a monic polynomial in Z[t] then so is u(γ) for every field homomorphism u fixing Z, because u commutes with the polynomial expression.

[F4]

OL is the integral closure of Z in L (Ring of integers, Integral closure in an extension ring and integrally closed domains), and it is integrally closed in L (The integral closure of a domain in a field extension is integrally closed). Hence L∩Z‾=OL, an element of OL has integer coordinates in the integral basis β1,…,βn, and a rational algebraic integer is an integer (The rational algebraic integers are exactly the integers).

[F5]

For a number field F of degree r a Q-basis x1,…,xr has discriminant disc⁡(x1,…,xr)=det⁡(σi(xj))2≠0, the determinant being taken over the r distinct embeddings F→C (Embedding determinant formula); for an integral basis this number is the well-defined nonzero integer dF (Discriminant of a basis and order, Number-field discriminant is well-defined and nonzero). In particular dK=D2 for D=det⁡(σk(αi)) and dK,dL≠0.

[F6]

If (u1,…,ur) is an F-basis of K and (v1,…,vs) is a K-basis of L, then the products uivj form an F-basis of L (Products of bases form a basis in a tower of finite extensions).

[F7]

If an m-dimensional vector space has a spanning list of m vectors, then that list is a basis: a dependence lets one vector be solved for in terms of the others, leaving an (m−1)-element spanning set, which cannot span a space containing an independent m-element basis by the finite-bound corollary. A basis is an independent spanning set (If V has a spanning set with n elements, then every linearly independent subset of V is finite with at most n elements; in particular V has no linearly independent subset equinumerous with N, Basis of a vector space: a linearly independent spanning subset; and ordered basis: an injective finite list whose image is a basis).

[F8]

If a positive integer r and a finite list of integers aij have no common prime divisor, then repeated applications of integer Bézout give integers c,bij with cr+∑i,jbijaij=1. Also, gcd⁡(dK,dL)=1 gives integers u,v with u dK+v dL=1 (Bézout's identity: for integers a,b not both zero, gcd⁡(a,b) is the least positive element of { ax+by:x,y∈Z }; in particular ax+by=gcd⁡(a,b) has an integer solution).

[F9]

Q has characteristic zero and is perfect (Fields of characteristic zero, finite fields, and algebraically closed fields are perfect), so the finite extension K/Q is simple: K=Q(α) for some α, with minimal polynomial f∈Q[t] of degree m and K≅Q[t]/(f) (Every finite extension of a perfect field is simple, The evaluation kernel and the unique monic irreducible minimal polynomial of an algebraic element).

[F10]

det⁡(S∘T)=det⁡(S)det⁡(T) for endomorphisms of a finite-dimensional space (Determinant multiplicativity follows from the top exterior power), and simultaneous reordering of the rows and columns of a square matrix does not change its determinant, being a similarity by a permutation matrix (Similar matrices over a commutative ring have the same determinant). The determinant of a matrix is given by the Leibniz sum ∑πsgn⁡(π)∏iaπ(i),i (For n≥1, the determinant over a commutative ring by the Leibniz formula, and ∣det⁡A∣ for a real matrix).

Proof

technique · direct
1.1F1F2given

By [F1] the given bases are Q-bases of K and L, and [F2] gives [KL:L]=m and [KL:K]=n.

1.2F2F9given

Every embedding σ:K→C extends to an embedding σ~:KL→C with σ~∣L=idL. Indeed, by [F9] write K=Q(α) with minimal polynomial f of degree m; then KL=L(α), and [L(α):L]=m=deg⁡f shows that f has no factor of intermediate degree over L, so f is irreducible over L and KL≅L[t]/(f) as L-algebras. The evaluation homomorphism L[t]→C, t↦σ(α), kills f because σ fixes Q and f(α)=0; it therefore induces the required σ~ under the isomorphism L[t]/(f)≅KL.

2.1F7F2step 1.1given

Put V:=∑i=1mLαi⊆KL. Since α1,…,αm are a Q-basis of K, each product αiαj is a Q-linear combination of them; the same structure constants lie in L, so V is closed under multiplication. Also 1∈V, and V contains both L and K. It is finite-dimensional over L. For each nonzero x∈V, multiplication by x is an injective L-linear map V→V, because V lies in the field KL; finite dimensionality makes the map surjective, so some y∈V satisfies xy=1. Thus V is a field containing K and L, hence V=KL. By [F2] it has L-dimension m. Its m elements αi span V; if they were dependent, a nonzero coefficient in a dependence relation could be inverted in L to express one αi in terms of the others, so the remaining m−1 vectors would still span V. But an m-element basis of V is an independent subset of a space with that (m−1)-element spanning set, contradicting [F7]. Thus the αi are independent and spanning, hence an L-basis by [F7]. The symmetric argument with W:=∑j=1nKβj shows that β1,…,βn form a K-basis of KL by the same finite argument.

3.1F6step 2.1

Applying [F6] to the tower Q⊆L⊆KL with the Q-basis β1,…,βn of L and the L-basis α1,…,αm of KL, the products αiβj form a Q-basis of KL; in particular they are Q-linearly independent and there are mn of them.

3.2step 2.1F4given

Let γ∈OKL. By step 2.1 there are unique x1,…,xm∈L with γ=∑ixiαi. Each xi lies in L=Frac⁡(OL), so there are integers aij and a positive integer r with xi=∑j(aij/r)βj; dividing out common factors, we may assume that no prime divides r and all aij simultaneously.

4.1F3F5step 3.2step 1.2

Let σ1,…,σm be the distinct embeddings of K into C and let σ~k extend σk as in step 1.2. Applying σ~k to γ=∑ixiαi and using σ~k∣L=id together with xi∈L gives the linear system ∑iσk(αi)xi=σ~k(γ), k=1,…,m. Its coefficient matrix M:=(σk(αi)) has determinant D with D2=dK≠0 by [F5]; the entries σk(αi) of M are algebraic integers, and so are the entries σ~k(γ), by [F3] applied to the integral elements αi∈OK and γ∈OKL.

5.1F3F5F10step 4.1

Cramer's rule applied to the system of step 4.1 gives D xi=Di, where Di is the determinant of a matrix with algebraic-integer entries; hence D and every Di are algebraic integers by [F3], and Δxi=D⋅Di is an algebraic integer, where Δ:=D2=dK is a nonzero integer.

6.1F4step 3.2step 5.1

By step 3.2, Δxi=∑j(Δaij/r)βj lies in L, so Δxi∈L∩Z‾=OL by step 5.1 and [F4]. As β1,…,βn is an integral basis, the rational numbers Δaij/r are integers; equivalently r∣Δaij=dKaij for all i,j.

7.1F8step 3.2step 6.1

The denominator was reduced in step 3.2, so no prime divides r and every aij; therefore their common gcd is 1. By [F8], choose integers c,bij with cr+∑i,jbijaij=1. Multiplying by dK and using r∣dKaij from step 6.1 shows that every term on the left is divisible by r, hence r∣dK.

8.1F8step 3.2step 2.1step 6.1step 7.1given

Regroup the same expansion from step 3.2 as γ=∑jyjβj, where yj=∑i(aij/r)αi∈K. The symmetric trace-matrix argument, now using the K-basis αi and the L-basis βj from step 2.1, gives r∣dLaij for every same coefficient aij. The same reduced-denominator identity of [F8] therefore gives r∣dL. Together with step 7.1 and gcd⁡(dK,dL)=1, this implies r=1. Thus γ=∑i,jaijαiβj∈OKOL for every γ∈OKL, proving OKL⊆OKOL.

9.1F3step 3.1step 8.1

Conversely OKOL⊆OKL: products and sums of integral elements are integral by [F3], and they lie in KL. With step 8.1 this gives OKL=OKOL, and since the products αiβj are Q-linearly independent by step 3.1 and span OKOL over Z by construction, they form an integral basis of OKL.

10.1F5step 9.1

The restrictions of the mn distinct embeddings of KL into C to K and to L define a map Emb⁡(KL)→Emb⁡(K)×Emb⁡(L); it is injective, because an embedding of KL is determined by its restrictions to K and to L, which together generate KL over Q. Both sides have mn elements by [F5], so the map is a bijection. Order rows by pairs (k,l) and columns by pairs (i,j), with the first index slow in each order. The embedding matrix of the integral basis αiβj of step 9.1 then has entries σk(αi)τl(βj).

11.1F10step 10.1

The embedding matrix of step 10.1 is K1K2: summing over the intermediate pair (a,b) gives ∑a,bσk(αa)δlbδaiτb(βj)=σk(αi)τl(βj). Here (K1)(k,l),(i,j)=σk(αi)δlj and (K2)(k,l),(i,j)=δkiτl(βj). By [F10], det⁡(K1K2)=det⁡(K1)det⁡(K2). In the first-index-slow ordering of step 10.1, K2 is block diagonal with m blocks N=(τl(βj)), so det⁡(K2)=det⁡(N)m. For K1, reorder both its rows and its columns by the same perfect shuffle from (k,l) to (l,k) and from (i,j) to (j,i). These are the same permutation of mn positions, so their determinant signs multiply to 1; in the resulting ordering K1 is block diagonal with n blocks M=(σk(αi)). Hence det⁡(K1)=det⁡(M)n, using [F10] and the Leibniz formula for block diagonal matrices.

12.1F5step 11.1∎

By [F5], dKL=det⁡(σk(αi)τl(βj))2=(det⁡M)2n(det⁡N)2m=dKndLm=dK[L:Q]dL[K:Q], using det⁡(M)2=dK and det⁡(N)2=dL from [F5] and m=[K:Q], n=[L:Q]. This completes the proof.

TheoremStatement: Literature-sourcedProof: AI-adaptedprecheck passaudited 2026-10-02Open item page →

Ring of integers of every cyclotomic field

Statement

For every n≥1, with ζn a primitive n-th root of unity in a fixed algebraic closure of Q, OQ(ζn)=Z[ζn], and 1,ζn,…,ζnφ(n)−1 is an integral basis of OQ(ζn).

Facts & Assumptions

Given: An integer n≥1 and a primitive n-th root of unity ζn in a fixed algebraic closure Ω of Q. When n>1, write n=p1a1⋯prar,i=1,…,r, with p1,…,pr pairwise distinct primes and ai≥1, put mi:=n/piai and ζi:=ζn mi, and put Ki:=Q(ζi). For j=1,…,r put nj:=p1a1⋯pjaj and Mj:=K1⋯Kj.

[F1]

Φn∈Z[t] is monic of degree φ(n), Φn(ζn)=0, and Φn is irreducible in Q[t] (The recursion defines a unique monic Φn∈Z[t], of degree φ(n), Φn is irreducible in Q[t] for every n≥1). Hence Φn is the minimal polynomial of ζn, so [Q(ζn):Q]=φ(n) and 1,ζn,…,ζnφ(n)−1 are linearly independent over Q, and Q(ζn) is a cyclotomic extension of Q of order n (The cyclotomic extension K(μn) as a splitting field of tn−1).

[F2]

For a field F and positive integers m,m′ such that char⁡F divides neither m nor m′, the compositum inside a splitting field of tlcm⁡(m,m′)−1 satisfies F(μm)F(μm′)=F(μlcm⁡(m,m′)); over F=Q, the characteristic hypothesis is vacuous (K(μm)K(μn)=K(μlcm⁡(m,n))).

[F3]

Euler's totient is multiplicative on coprime arguments, so by induction on j one has φ(nj)=φ(p1a1)⋯φ(pjaj) (Euler's totient is multiplicative: gcd⁡(m,n)=1 implies φ(mn)=φ(m)φ(n) for positive m,n).

[F4]

For each prime power piai the prime-power cyclotomic structure theorem gives OKi=Z[ζi], with 1,ζi,…,ζiφ(piai)−1 an integral basis of OKi, and with the field discriminant satisfying ∣dKi∣=pi Ni for the integer Ni:=piai−1(ai(pi−1)−1)≥0 (Prime-power cyclotomic ring, discriminant support and p factor).

[F5]

Coprime-discriminant compositum: if K,L are number fields inside a common algebraic closure with [KL:Q]=[K:Q][L:Q] and gcd⁡(dK,dL)=1, then OKL=OKOL, the products of an integral basis of OK and an integral basis of OL form an integral basis of OKL, and dKL=dK[L:Q]dL[K:Q] (Integral basis and discriminant of a coprime-discriminant compositum).

[F7]

If a,b,c∈Z satisfy a∣c, b∣c and gcd⁡(a,b)=1, then ab∣c; consequently, if finitely many pairwise coprime integers each divide c, their product divides c (If gcd⁡(a,b)=1 and a∣bc then a∣c; and if a∣c, b∣c and gcd⁡(a,b)=1 then ab∣c).

[F8]

An integral basis of OK is an ordered Z-basis of OK (Integral and power integral bases, Ring of integers).

Proof

technique · direct
1.1F1F4given

For n=1 one has ζ1=1, φ(1)=1, Q(ζ1)=Q and OQ=Z, so OQ(ζ1)=Z[ζ1]=Z and the single element 1=ζ10 is a Z-basis. For n>1 we keep the notation of the Given; each ζi=ζnmi has order piai, because ζn has order n; hence ζi is a primitive piai-th root of unity and Ki=Q(ζi) is a prime-power cyclotomic field as in [F4].

1.2F1F2F3

By induction on j the compositum is Mj=Q(ζnj) and [Mj:Q]=φ(nj)=∏i≤jφ(piai): for j=1 this is K1=Q(ζp1a1) with degree φ(p1a1) by [F1]; and if it holds for j−1, then Mj=Mj−1Kj=Q(μnj−1)Q(μpjaj)=Q(μnj) by [F2] because lcm⁡(nj−1,pjaj)=nj, while [Mj:Q]=φ(nj)=φ(nj−1)φ(pjaj)=[Mj−1:Q][Kj:Q] by [F1] and [F3]. In particular [Mr:Q]=φ(n)=[Q(ζn):Q] and Mr=Q(ζn) inside Ω.

1.3F6F7given

The two rings agree: Z[ζ1]⋯Z[ζr]=Z[ζn]. Indeed each ζi=ζnmi lies in Z[ζn], which gives the inclusion ⊆. Conversely, for each i the numbers mi and piai are coprime, so [F6] provides ei∈Z with eimi≡1(modpiai); since piai∣mj for j≠i, the integer ∑jejmj−1 is divisible by every piai, and these are pairwise coprime with product n, so n∣∑jejmj−1 by [F7]. Hence ζn∑jejmj=ζn, that is ζn=∏j(ζnmj)ej=∏jζjej∈Z[ζ1]⋯Z[ζr], giving the reverse inclusion.

2.1F4F5step 1.2

Applying step 1.2 and the compositum theorem [F5] inductively on j gives OMj=OK1⋯OKj=Z[ζ1]⋯Z[ζj], with the products of the individual power bases as an integral basis, and ∣dMj∣=∏i≤jpi Ni⋅[Mj:Ki] is a product of powers of the distinct primes p1,…,pj. Indeed, for j=1 this is [F4]; and for the induction step Mj=Mj−1Kj satisfies the degree hypothesis by step 1.2, while gcd⁡(dMj−1,dKj)=1 because the first discriminant is ± a product of powers of p1,…,pj−1 and the second is ±pj Nj by [F4], so [F5] converts OMj−1OKj into OMj and preserves the basis statement.

3.1F1F8step 1.2step 1.3step 2.1∎

By steps 1.2, 1.3 and 2.1 with j=r, OQ(ζn)=OMr=Z[ζ1]⋯Z[ζr]=Z[ζn]. Every power ζnk is a Z-linear combination of 1,ζn,…,ζnφ(n)−1: this is clear for k<φ(n), and the monic relation Φn(ζn)=0 of degree φ(n) expresses ζnφ(n) as such a combination, after which induction on k handles all larger powers; hence 1,ζn,…,ζnφ(n)−1 spans the Z-module Z[ζn]=OQ(ζn), and by [F1] these φ(n) elements are also linearly independent over Q, hence over Z. A linearly independent spanning set of a Z-module is a Z-basis (Basis of a vector space: a linearly independent spanning subset; and ordered basis: an injective finite list whose image is a basis), so 1,ζn,…,ζnφ(n)−1 is an ordered Z-basis of OQ(ζn), that is, an integral basis by [F8].

Remarks

  • Where coprimality is used. The prime-power discriminants are (up to sign) powers of the distinct primes pi, so the coprime-discriminant hypothesis of the compositum theorem holds at every step. The degree hypothesis is supplied by the compositum identity Mj=Q(ζnj) together with multiplicativity of φ on coprime arguments; neither hypothesis is automatic.
  • The Bezout step is the only place where the product structure of n enters additively. It shows that ζn is a monomial in the ζi, so the ring generated by all the local roots is already Z[ζn].
TheoremStatement: Literature-sourcedProof: AI-adaptedjudge pass (gpt-6.1-sol)audited 2026-10-02Open item page →

Signed discriminant of a cyclotomic field

Statement

Let f>1 be a reduced index, that is f is odd or 4∣f, and let K=Q(ζf) for a primitive f-th root of unity ζf. Then the signed field discriminant is dK=(−1)φ(f)/2 fφ(f)∏p∣fpφ(f)/(p−1), the product being over the primes p dividing f; for f=1 one has dQ=1. The conductor theorem later identifies the reduced index f with the intrinsic conductor of K.

Facts & Assumptions

Given: A reduced index f and a primitive f-th root of unity ζ=ζf in a fixed algebraic closure of Q, with K:=Q(ζ) and n:=[K:Q]=φ(f). In the main case f>1, write f=p1a1⋯prar with pairwise distinct primes pi and ai≥1, put ei:=φ(piai) and Ki:=Q(ζpiai), and for j≤r put nj:=p1a1⋯pjaj and Mj:=K1⋯Kj.

[F1]

Ki has ring of integers OKi=Z[ζpiai] with the power basis as an integral basis, and ∣dKi∣=pi Li,Li:=piai−1(ai(pi−1)−1)=aiei−eipi−1 (Prime-power cyclotomic ring, discriminant support and p factor).

[F2]

Coprime-discriminant compositum: for number fields A,B with [AB:Q]=[A:Q][B:Q] and gcd⁡(dA,dB)=1, the ring of integers satisfies OAB=OAOB and dAB=dA[B:Q] dB[A:Q] (Integral basis and discriminant of a coprime-discriminant compositum).

[F3]

For every m≥1, OQ(ζm)=Z[ζm] and 1,ζm,…,ζmφ(m)−1 is an integral basis (Ring of integers of every cyclotomic field); the discriminant of an order is independent of the chosen integral basis, so it may be computed from this basis (Discriminant of a basis and order, Power-basis and polynomial discriminants).

[F4]

Mj=Q(ζnj) inside the fixed algebraic closure, with [Mj:Q]=φ(nj)=∏i≤jei: this is the compositum identity F(μa)F(μb)=F(μlcm⁡(a,b)) together with irreducibility of the cyclotomic polynomials and multiplicativity of φ on coprime arguments (K(μm)K(μn)=K(μlcm⁡(m,n)), Φn is irreducible in Q[t] for every n≥1, Euler's totient is multiplicative: gcd⁡(m,n)=1 implies φ(mn)=φ(m)φ(n) for positive m,n, The cyclotomic extension K(μn) as a splitting field of tn−1).

[F5]

For an ordered Q-basis α1,…,αn of a number field L with distinct embeddings σ1,…,σn ⁣:L→C one has disc⁡(α1,…,αn)=det⁡(σi(αj))2 and the determinant is nonzero (Embedding determinant formula).

[F6]

A real number that is a root of unity is ±1, of multiplicative order 1 or 2 (The group μn(K) of n-th roots of unity in a field, and primitive n-th roots of unity). The signature (r1,r2) of a number field satisfies r1+2r2=[L:Q] (Archimedean embeddings and signature).

Proof

technique · direct
1.1F4given

In the main case f>1, each piai is at least 3: if pi is odd this is clear, and if pi=2 then 4∣f because f is reduced, so ai≥2. Hence each Ki has degree ei≥2, and φ(f)=∏i≤rei by multiplicativity of φ on the coprime factors piai.

1.2F1given

For every i the power-basis computation of [F1] gives ∣dKi∣=piLi with Li=aiei−ei/(pi−1), and the p_i-adic exponent of the claimed formula is φ(f)ai−φ(f)/(pi−1).

1.3F6given

The field K=Q(ζ) has no real embedding: if σ(K)⊆R for an embedding σ, then σ(ζ)∈R is a root of unity whose order is exactly f≥3, because σ(ζ)m=1 if and only if ζm=1 if and only if f∣m; but by [F6] a real root of unity has order 1 or 2, a contradiction. Hence r1=0, complex conjugation acts on the n embeddings as a fixed-point-free involution, and r2=n/2=φ(f)/2 by [F6].

1.4F3

In the separate case from the Statement with f=1, one has K=Q, and [F3] gives the integral basis (1) of OQ=Z. Its trace Gram matrix is the 1×1 matrix [Tr⁡Q/Q(1⋅1)]=[1], so its determinant is 1; by the discriminant definition in [F3], dQ=1.

2.1F2F4step 1.2

By induction on j, ∣dMj∣=∏i≤j∣dKi∣φ(nj)/ei: for j=1, M1=K1 and the exponent is 1; for j≥2, [F4] gives [Mj−1:Q]=φ(nj−1) and [Kj:Q]=ej with Mj=Mj−1Kj, the discriminants dMj−1 and dKj are coprime because one is ± a product of powers of p1,…,pj−1 and the other is ±pjLj, and [F2] then gives ∣dMj∣=∣dMj−1∣ej∣dKj∣φ(nj−1).

2.2F3F5step 1.3

With respect to the integral basis 1,ζ,…,ζn−1 of [F3], the determinant Δ:=det⁡(σi(ζj−1)) of [F5] is nonzero and dK=Δ2. Complex conjugation permutes the index set of the embeddings by a product of n/2 transpositions by step 1.3, so Δ‾=(−1)n/2Δ and therefore ∣Δ∣2=Δ‾Δ=(−1)n/2Δ2=(−1)n/2dK; since ∣Δ∣2>0, the sign of dK is (−1)n/2=(−1)φ(f)/2.

3.1F4step 1.2step 2.1

Taking absolute values in the induction of step 2.1 with j=r and using Mr=K and φ(nr)=φ(f) gives ∣dK∣=∏i≤rpi Liφ(f)/ei=∏i≤rpi φ(f)(ai−1/(pi−1))=fφ(f)/∏i≤rpiφ(f)/(pi−1).

4.1step 2.2step 3.1step 1.4∎

Combining the sign of step 2.2 with the absolute value of step 3.1 gives dK=(−1)φ(f)/2fφ(f)/∏p∣fpφ(f)/(p−1) for the given reduced index f>1; the separate f=1 case has dQ=1 by step 1.4. These are the cases in the Statement.

Remarks

  • Sign and absolute value are computed separately. The absolute value comes from the prime-power absolute discriminants and the coprime-discriminant compositum formula; the sign comes from the pairing of complex embeddings. Neither the different ideal nor its positive norm is used.
  • Reduced index. For an unreduced index 2m with m odd one has Q(ζ2m)=Q(ζm), and the formula must be applied to the reduced index m; the statements of this pair therefore exclude f≡2(mod4).
CorollaryStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (gpt-6.1-sol)audited 2026-10-02Open item page →

Total ramification at a prime-power cyclotomic level

Statement

For a prime p and an integer a≥1, put K=Q(ζpa) and λ=1−ζpa. Then pOK=(λ)φ(pa), and the principal ideal λOK is the unique prime ideal of OK lying above p, with residue field OK/λOK≅Fp.

Facts & Assumptions

Given: A prime p, an integer a≥1, e:=φ(pa), a primitive pa-th root of unity ζ=ζpa, K:=Q(ζ), λ:=1−ζ and R:=Z[ζ]=OK.

[F1]

OK=R=Z[ζ] and pR=(λ)e; moreover 1,ζ,…,ζe−1 is an integral basis of OK (Prime-power cyclotomic ring, discriminant support and p factor, Ring of integers of every cyclotomic field).

[F2]

Φpa∈Z[t] is monic of degree e and Φpa(1)=p (Φpr(t)=∑k<ptkpr−1, and Φpr(t+1) is Eisenstein at p).

[F3]

Division by the monic polynomial t−1 in Z[t] writes every f∈Z[t] uniquely as f=q⋅(t−1)+f(1) with q∈Z[t] and constant remainder f(1) (Division by a monic polynomial over a commutative ring); hence the evaluation homomorphism Z[t]→Z, f↦f(1), is a surjective ring homomorphism with kernel (t−1), so Z[t]/(t−1)≅Z (First isomorphism theorem for rings: R/ker⁡f≅im⁡f).

[F4]

An ideal M of a commutative ring R is maximal if and only if R/M is a field (R/M is a field if and only if M is a maximal ideal), and every maximal ideal is prime (Every maximal ideal of a commutative ring is prime). Also Z/p is a field (For every prime p, the two operations on Z/p make it a field).

[F5]

A nonzero prime P of OK lies above p when P∩Z=pZ, and its residue degree is [OK/P:Fp] (Primes above and residue degree).

Proof

technique · direct
1.1F1F2F3F4

Under the presentation R=Z[ζ]=Z[t]/(Φpa) with t↦ζ, the element λ=1−ζ corresponds to the class of 1−t, so R/λR≅Z[t]/(Φpa, t−1); sending t to 1 via [F3] identifies this quotient with Z/(Φpa(1))=Z/pZ=Fp.

2.1F1F4F5step 1.1

Since R/λR≅Fp is a field, λR is a maximal and hence prime ideal of R, and it is proper; consequently λR∩Z is a proper ideal of Z containing pZ (as pR=(λ)e⊆λR by [F1]) and therefore equals pZ, so λR lies above p with residue field OK/λOK≅Fp, of residue degree 1.

3.1F1F4step 2.1

If P is any prime ideal of R with p∈P, then λe∈λeR=pR⊆P, so λ∈P because P is prime, hence λR⊆P; as λR is maximal and P is proper, P=λR. Thus λR is the unique prime above p.

4.1F1step 2.1step 3.1∎

Combining [F1] with steps 2.1 and 3.1, pOK=(λ)φ(pa) and λOK is the unique prime of OK above p, with residue field Fp. For p=2, a=1 this reads K=Q, λ=2, e=1, and 2Z is the unique prime above 2 with residue field F2.

Remarks

  • Total ramification. The exponent equals the degree [Q(ζpa):Q]=φ(pa), and the residue degree is 1, so p is totally ramified; the equality pOK=(λ)e exhibits the ramification index without invoking any general ramification theory beyond the definitions.
  • The quotient computation is the only place where Φpa(1)=p is used, and it also shows that no prime other than λOK can contain p.
LemmaStatement: Literature-sourcedProof: AI-adaptedaudited 2026-10-02Open item page →

Choice-free prime factorisation for a monogenic number ring

Statement

Let K=Q(α) be a number field with OK=Z[α], and let F be the monic minimal polynomial of α. For a rational prime p, factor the image Fˉ of F in Fp[t] as ∏igiai into distinct monic irreducibles. Let g~i∈Z[t] be the coefficientwise lift of gi with coefficients in {0,…,p−1}. Then

pOK=∏iPiai,Pi=(p, g~i(α)),

The ideal (p,g~i(α)) is independent of the integer lift, since two lifts differ by a polynomial in pZ[t]. The Pi are distinct primes of OK with residue degrees deg⁡gi. This proof uses no Axiom of Choice.

Facts & Assumptions

Given: A number field K=Q(α) with OK=Z[α], its monic minimal polynomial F∈Z[t], a rational prime p, and a factorisation Fˉ=∏i=1kgiai in Fp[t] into distinct monic irreducibles gi, where di:=deg⁡gi and ai≥1, and their coefficientwise integer lifts g~i as in the Statement.

[F1]

Evaluation at α identifies Z[t]/(F) with Z[α]=OK (The evaluation kernel and the unique monic irreducible minimal polynomial of an algebraic element, First isomorphism theorem for rings: R/ker⁡f≅im⁡f, The quotient ring R/I with (r+I)(s+I)=rs+I). Reducing this presentation modulo p gives OK/pOK≅Fp[t]/(Fˉ).

[F2]

Since p is prime, Fp is a field (For every prime p, the two operations on Z/p make it a field). The powers (giai) are pairwise comaximal in Fp[t], so the Chinese remainder theorem gives Fp[t]/(Fˉ)≅∏i=1kFp[t]/(giai). Each factor has unique prime ideal generated by the image of gi, and its residue field is Fp[t]/(gi) (Bézout identity and the Euclidean algorithm for polynomials over a field, Chinese remainder theorem for pairwise comaximal ideals, For every field F, F[x] is a unique factorisation domain).

[F3]

Every nonzero integral ideal of a number field's ring of integers has a unique finite factorisation into powers of distinct nonzero prime ideals; the finite construction uses no Choice (Integral ideal factorisation in a number field, in ZF).

[F4]

If P is a prime ideal, OK,P is the localisation at the multiplicative set OK∖P, and its maximal ideal is POK,P (Localisation at a prime ideal: Rp=(R∖p)−1R, Rp is local with unique maximal ideal pRp). Localisation commutes with quotient rings (Localisation commutes with quotient rings: S−1R/S−1I≅Sˉ−1(R/I)).

[F5]

A prime P⊆OK lies above (p) when P∩Z=(p), and its residue degree is [OK/P:Fp] (Primes above and residue degree).

Proof

technique · direct
1.1F1given

Put A:=OK=Z[α]. By [F1], A/pA≅Fp[t]/(Fˉ).

1.2F3given

Since pA≠0, apply [F3] to write pA=∏j=1rQjej with distinct nonzero primes Qj and positive exponents ej.

2.1F2step 1.1

Under this isomorphism, [F2] decomposes A/pA as the product of the local rings Bi:=Fp[t]/(giai). The unique prime of Bi is generated by gi and has residue field Fp[t]/(gi); therefore the primes of A containing pA are exactly the distinct inverse images Pi=(p,g~i(α)).

3.1F5step 1.1step 2.1

It follows that A/Pi≅Fp[t]/(gi), a field of degree di over Fp. Thus each Pi is a nonzero prime above (p) with residue degree di by [F5].

3.2step 2.1step 1.2

The finite ring A/pA is the product in [F2], so every prime containing pA is maximal. Each Qj contains pA and hence equals one of the Pi by step 2.1. Conversely, each Pi contains pA=∏jQjej; its primality implies Qj⊆Pi for some j, and maximality makes Qj=Pi. Hence the list Q1,…,Qr is exactly the list P1,…,Pk, with one exponent ei attached to each Pi.

4.1F4step 2.1step 3.2

Fix i and put S:=APi and m:=PiS. Each other Pj contains an element outside Pi, which becomes a unit, so pS=mei. By [F4], S is local with maximal ideal m; it is a domain because it is a localisation of the domain A. Also m=(p,g~i(α))S, so each power of m is finitely generated by the monomials in these two generators.

5.1F4step 4.1algebra

The ideal J:=mei−1 is nonzero: it contains pei−1≠0. If J⊆mei, then J=mJ. Among finite generating lists of J, take one of minimum length n≥1, say v1,…,vn. The equality J=mJ gives vn=∑j=1ncjvj with cj∈m. Since 1−cn is a unit in the local ring S, this expresses vn in terms of the first n−1 generators, contradicting minimality. Hence mei−1⊈mei. In S/pS=S/mei the maximal ideal therefore has nilpotency index exactly ei, including ei=1.

6.1F1F2F4step 5.1

By [F1] and [F4], APi/pAPi≅Fp[t](gi)/(Fˉ). Writing Fˉ=giaiui with ui=∏j≠igjaj, each factor of ui is a unit in Fp[t](gi). Thus the displayed local ring is Fp[t](gi)/(giai). Its maximal ideal is generated by gi and has nilpotency index exactly ai: its ai-th power vanishes, while giai−1∉(giai), since cancellation in the polynomial localisation domain would otherwise make the nonunit gi a unit. Comparing its nilpotency index with step 5.1 gives ei=ai.

7.1F3step 3.1step 1.2step 6.1∎

Substituting ei=ai into the factorisation of step 1.2 yields pOK=∏i=1kPiai,Pi=(p,g~i(α)). The residue degrees are those proved in step 3.1, and ∑iaidi=deg⁡Fˉ. The polynomial factorisation and its CRT decomposition are finite; the only ideal-factorisation input [F3] explicitly uses finite least-coded choices and no Choice.

Remarks

  • Repeated factors are retained. The multiplicities ai are recovered by localising the polynomial quotient at (gi) and comparing its nilpotency index with the local exponent in the ideal factorisation.
  • Supplier route. This proof uses the published choice-free ideal-factorisation theorem Integral ideal factorisation in a number field, in ZF for existence of the ideal factorisation. The exact local nilpotency index is proved here using the explicit finite generators and a minimal generating list. It therefore no longer claims to avoid general ideal-factorisation theory.
  • The monogenic hypothesis is essential. It identifies OK with the explicit quotient Z[t]/(F); for a non-monogenic order, reduction of a minimal polynomial does not by itself describe the primes of OK.
LemmaStatement: Literature-sourcedProof: AI-adaptedaudited 2026-10-02Open item page →

Arithmetic Frobenius is the power map in an unramified cyclotomic field

Statement

Let f≥1 be a reduced index, that is f is odd or 4∣f, let ℓ be a rational prime with ℓ∤f, let ζf be a primitive f-th root of unity and K=Q(ζf). Let σℓ be the automorphism of K with σℓ(ζf)=ζf ℓ. Then for every prime P of OK above ℓ, the element σℓ is the arithmetic Frobenius Frob⁡P: it is the unique σ∈Gal⁡(K/Q) with σ(P)=P and σ(a)≡aℓ(modP) for all a∈OK. In particular it does not depend on the chosen prime above ℓ, the Galois group being abelian.

Facts & Assumptions

Given: A reduced index f≥1, a rational prime ℓ with ℓ∤f, a primitive f-th root of unity ζ=ζf, the field K=Q(ζ), and the automorphism σℓ∈Gal⁡(K/Q) with σℓ(ζ)=ζℓ.

[F1]

OK=Z[ζ], and 1,ζ,…,ζφ(f)−1 is an integral basis (Ring of integers of every cyclotomic field).

[F2]
[F3]

K/Q is Galois with Gal⁡(K/Q)≅(Z/f)× via σb(ζ)=ζb; this group is abelian and every automorphism has this form ([Q(ζn):Q]=φ(n) and Gal⁡(Q(μn)/Q)≅(Z/n)×).

[F4]

For gcd⁡(f,ℓ)=1, the reduction of Φf in Fℓ[t] is a product of pairwise distinct monic irreducibles, each of degree d:=ord⁡f(ℓ) (For gcd⁡(n,q)=1 the reduction of Φn in Fq[t] is a product of distinct monic irreducibles, each of degree the order of [q] modulo n).

[F5]

Since OK=Z[ζ], applying the monogenic factorisation lemma to Φˉf=∏igi gives ℓOK=∏iPi where Pi=(ℓ,g~i(ζ)) are distinct primes above ℓ, each of residue degree d, where g~i∈Z[t] is the coefficientwise lift of gi with coefficients in {0,…,ℓ−1} (Choice-free prime factorisation for a monogenic number ring, Primes above and residue degree).

[F6]

Over a field whose characteristic does not divide f, the roots of Φf in a splitting field of tf−1 are exactly the primitive f-th roots of unity. For the residue field κ(Pi), take a splitting field of tf−1 over it; its natural field embedding is injective and preserves the multiplicative order of each element. Since κ(Pi) has characteristic ℓ and ℓ∤f, the theorem applies to the image of ζˉ there (Over a field whose characteristic does not divide n, the roots of Φn are exactly the primitive roots of unity, The cyclotomic extension K(μn) as a splitting field of tn−1).

[F7]

For a prime P above an unramified rational prime ℓ in a finite Galois extension, there is a unique arithmetic Frobenius Frob⁡P in the decomposition group satisfying Frob⁡P(a)≡aℓ(modP) for all algebraic integers a (Unramified frobenius element exists uniquely).

Proof

technique · direct
1.1F1F2F3

By [F1] and [F2], the ring of integers is Z[ζ], the minimal polynomial of ζ is Φf, and its degree is φ(f). By [F3], K/Q is abelian and each automorphism is σb for a unit class b modulo f, in particular σℓ exists. If f=1, then K=Q and the unique prime over ℓ is ℓZ; the trivial automorphism is its arithmetic Frobenius.

1.2F4F5

Since ℓ∤f, [F4] and [F5] give ℓOK=∏i=1gPi with distinct primes Pi=(ℓ,g~i(ζ)), each of residue degree d=ord⁡f(ℓ). Thus ℓ is unramified and these are all the primes above it.

1.3F7

Fix i. By [F7] the prime Pi has an arithmetic Frobenius Frob⁡Pi satisfying the ℓ-power congruence. Evaluating it at ζ gives Frob⁡Pi(ζ)≡ζℓ(modPi).

1.4F6

The residue class ζˉ=ζ+Pi is a root of the reduction of Φf, since Φf(ζ)=0. Embed the residue field into a splitting field of tf−1 over it. By [F6], the image of ζˉ has multiplicative order exactly f there; injectivity of the field embedding gives the same order for ζˉ in the residue field.

2.1F3step 1.3step 1.4

Write Frob⁡Pi=σb using [F3]. Reducing the congruence in step 1.3 gives ζˉ b=ζˉ ℓ. Since ζˉ has order f by step 1.4, b≡ℓ(modf); hence σb=σℓ. This comparison is made directly in the residue field at Pi, so it does not require σℓ to stabilise Pi in advance.

3.1F3step 2.1∎

The argument applies to every prime Pi above ℓ, and each gives the same automorphism σℓ. Thus this arithmetic Frobenius is independent of the prime above ℓ, as also follows from the abelian Galois group in [F3].

Remarks

  • Reduced index. The hypothesis that f is odd or 4∣f is the standing reduced-index convention of this pair; for the present lemma the essential hypothesis is ℓ∤f, which makes Φf separable modulo ℓ.
  • Power map, not inverse. The identification uses the arithmetic convention ζ↦ζℓ; the geometric inverse would send ζ to ζℓ−1 and agrees with the arithmetic map exactly when ℓ2≡1(modf), since ℓ is a unit modulo f.
TheoremStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (gpt-6.1-sol)audited 2026-10-02Open item page →

Prime factorisation in a cyclotomic field

Statement

Let f≥1 be a reduced index, that is, f is odd or 4∣f. Let ℓ be a rational prime, write f=ℓam with gcd⁡(ℓ,m)=1 (so a is the ℓ-adic valuation of f, m=f/ℓa, and m=f when ℓ∤f), and put e:=φ(ℓa), d:=ord⁡m(ℓ), the multiplicative order of ℓ modulo m, and g:=φ(m)/d, with the conventions φ(1)=1 and ord⁡1(ℓ)=1. Let ζf be a primitive f-th root of unity and K=Q(ζf). Then ℓOK=(P1⋯Pg)e with pairwise distinct primes P1,…,Pg of residue degree d, and edg=φ(f).

Facts & Assumptions

Given: A reduced index f≥1, a rational prime ℓ, the factorisation f=ℓam with gcd⁡(ℓ,m)=1, the numbers e=φ(ℓa), d=ord⁡m(ℓ), g=φ(m)/d (with the conventions φ(1)=1 and ord⁡1(ℓ)=1), a primitive f-th root of unity ζ=ζf, the field K=Q(ζ), and, for n≥1, the image Φˉn of Φn in Fℓ[t].

[F2]

Φf is monic of degree φ(f) with Φf(ζ)=0, its roots in a field of characteristic not dividing f are exactly the primitive f-th roots of unity, and Φf is irreducible over Q; hence Φf is the minimal polynomial of ζ over Q, and K=Q(μf) is a cyclotomic extension of order f (The recursion defines a unique monic Φn∈Z[t], of degree φ(n), Over a field whose characteristic does not divide n, the roots of Φn are exactly the primitive roots of unity, Φn is irreducible in Q[t] for every n≥1, The cyclotomic extension K(μn) as a splitting field of tn−1).

[F3]

Monogenic factorisation: if K=Q(α) is a number field with OK=Z[α] and monic minimal polynomial F of α, and if the image of F in Fp[t] factors as ∏ihiai into distinct monic irreducibles, then pOK=∏iPiai with pairwise distinct primes Pi=(p,h~i(α)) of residue degree deg⁡hi, where h~i∈Z[t] is the coefficientwise lift of hi with coefficients in {0,…,p−1}; the argument uses no Axiom of Choice (Choice-free prime factorisation for a monogenic number ring, Primes above and residue degree).

[F4]

For every n≥1, ∏j∣nΦj=tn−1 in Z[t], and Φn is monic of degree φ(n); in particular Φ1=t−1 (The recursion defines a unique monic Φn∈Z[t], of degree φ(n), The cyclotomic polynomials Φn∈Z[t], defined by ∏d∣nΦd=tn−1).

[F6]

Euler's totient is multiplicative on coprime arguments: φ(uv)=φ(u)φ(v) when gcd⁡(u,v)=1 (Euler's totient is multiplicative: gcd⁡(m,n)=1 implies φ(mn)=φ(m)φ(n) for positive m,n).

[F7]

Fℓ[t] is an integral domain (indeed a unique factorisation domain), so a product identity A⋅B=A⋅C with A≠0 implies B=C (For every field F, F[x] is a unique factorisation domain).

[F8]

Total ramification in a prime-power cyclotomic field: for b≥1, pOQ(ζpb)=(λ)φ(pb) with λ=1−ζpb, and λOQ(ζpb) is the unique prime above p, with residue field Fp (Total ramification at a prime-power cyclotomic level).

Proof

technique · direct
1.1F4F7

Assume a≥1. Since gcd⁡(ℓ,m)=1, the divisors of ℓam are exactly the ℓjm′ with 0≤j≤a and m′∣m; reducing the product identity of [F4] at n=ℓam and at n=ℓa−1m modulo ℓ and using (Xm)ℓj−1=(Xm−1)ℓj in Fℓ[t] therefore gives ∏j=0a∏m′∣mΦˉℓjm′=(Xm−1)ℓa and ∏j=0a−1∏m′∣mΦˉℓjm′=(Xm−1)ℓa−1. The second product is the part j≤a−1 of the first, and (Xm−1)ℓa−1≠0, so cancelling this common factor in the domain Fℓ[t] gives ∏m′∣mΦˉℓam′=(Xm−1)ℓa−ℓa−1=(Xm−1)φ(ℓa).

1.2F5

Applied to n=m, which is coprime to ℓ, [F5] gives Φˉm=∏i=1ghi with g=φ(m)/d, where the hi are pairwise distinct monic irreducible elements of Fℓ[t] of degree d=ord⁡m(ℓ); in particular Φˉm≠0.

2.1step 1.1F4F7

Claim: for our fixed a≥1, Φˉℓan=Φˉnφ(ℓa) in Fℓ[t] for every n≥1 with gcd⁡(n,ℓ)=1. This is proved by strong induction on n. For n=1, step 1.1 with m=1 gives Φˉℓa=(X−1)φ(ℓa), while Φˉ1=X−1 by [F4], so Φˉℓa=Φˉ1φ(ℓa). For n>1, assume the claim for every proper divisor m′∣n, m′≠n; step 1.1 with m=n gives ∏m′∣nΦˉℓam′=(Xn−1)φ(ℓa), and [F4] gives ∏m′∣nΦˉm′=Xn−1, so substituting Φˉℓam′=Φˉm′φ(ℓa) for the proper divisors yields Φˉℓan⋅∏m′∣n, m′<nΦˉm′φ(ℓa)=Φˉnφ(ℓa)⋅∏m′∣n, m′<nΦˉm′φ(ℓa); the common factor is a nonzero product of nonzero monic polynomials, so cancellation in the domain Fℓ[t] gives Φˉℓan=Φˉnφ(ℓa).

2.2F6step 1.2

Since gcd⁡(ℓa,m)=1, [F6] gives φ(f)=φ(ℓam)=φ(ℓa)φ(m), so edg=φ(ℓa)⋅d⋅(φ(m)/d)=φ(ℓa)φ(m)=φ(f).

3.1step 1.2step 2.1

In all cases a≥0 one has Φˉf=Φˉℓam=∏i=1ghie in Fℓ[t], a product of pairwise distinct monic irreducibles of degree d with common multiplicity e: if a≥1 this is step 2.1 at n=m combined with step 1.2, and if a=0 then e=φ(1)=1 and m=f, so the same formula is step 1.2 itself.

4.1F1F2F3step 3.1

By [F1], [F2] the element α:=ζ has OK=Z[α] and monic minimal polynomial Φf, so the monogenic factorisation [F3] applies with p=ℓ to the factorisation of step 3.1: ℓOK=∏i=1gPie with pairwise distinct primes Pi=(ℓ,h~i(ζ)) of residue degree deg⁡hi=d, where h~i is the coefficientwise integer lift modulo ℓ, and ∏i=1gPie=(P1⋯Pg)e.

5.1F8step 4.1step 2.2∎

Edge cases. If f=1 then a=0, m=1, e=d=g=1 and Φˉ1=X−1, so steps 3.1 and 4.1 give ℓZ=(ℓ), and step 2.2 gives edg=1=φ(1); if m=1 and a≥1>0 then g=d=1 and P1=(ℓ,ζ−1), so ℓOK=P1 φ(ℓa), while [F8] with p=ℓ, b=a gives ℓOK=(λ)φ(ℓa) with λ=1−ζ the unique prime above ℓ; the two descriptions agree by uniqueness of the prime above ℓ.

Remarks

  • Where reducedness enters. The factorisation argument itself only uses gcd⁡(ℓ,m)=1; the reduced-index hypothesis is the standing convention for cyclotomic conductors in this pair, and it is exactly what excludes the degenerate shape f=2m with m odd, where 2∣f yet Q(ζf)=Q(ζm) and 2 is unramified, so the companion ramification criterion needs the reduced index as stated.
  • Unramified case. When a=0 the theorem specialises to ℓOK=P1⋯Pg with g=φ(f)/ord⁡f(ℓ) primes of residue degree ord⁡f(ℓ), the form in which the unramified-decomposition corollary of this page reads off the residue degree of the arithmetic Frobenius (Decomposition of an unramified prime in a cyclotomic field).
  • Choice. The proof's only structural inputs are the choice-free monogenic reduction [F3] and finite polynomial arithmetic; the monograph-level finite field factorisation [F5] is quoted as a published interface.
CorollaryStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (gpt-6.1-sol)audited 2026-10-02Open item page →

Ramification primes of a reduced cyclotomic conductor

Statement

Let f≥1 be a reduced index, that is, f is odd or 4∣f, and let K=Q(ζf). A rational prime ℓ ramifies in K — that is, in the factorisation of ℓOK some prime ideal occurs with exponent at least 2 — if and only if ℓ∣f.

Facts & Assumptions

Given: A reduced index f≥1, a primitive f-th root of unity ζf, the field K=Q(ζf), a rational prime ℓ, and the factorisation f=ℓam with gcd⁡(ℓ,m)=1 (so a is the ℓ-adic valuation of f and ℓ∤f exactly when a=0).

[F1]

By the prime factorisation theorem for reduced indices, ℓOK=(P1⋯Pg)e,e=φ(ℓa), with pairwise distinct primes P1,…,Pg; in particular every prime above ℓ has exponent exactly e in ℓOK, so ℓ is unramified in K if and only if e=1 (Prime factorisation in a cyclotomic field).

[F2]

For a prime ℓ and a≥1, φ(ℓa)=ℓa−ℓa−1=ℓa−1(ℓ−1), and φ(1)=1; hence for a≥1 one has φ(ℓa)=1 exactly when ℓ=2 and a=1 (For a prime p and k≥1, φ(pk)=pk−pk−1).

[F3]

Since f is reduced, f is odd or 4∣f; consequently, if 2∣f then 4∣f, so the exponent a=v2(f) is not 1 — it is either 0 or at least 2. [definition of reduced index, arithmetic]

Proof

technique · direct
1.1F2

If a=0 then e=φ(1)=1, while if a≥1 then e=ℓa−1(ℓ−1)=1 holds exactly for ℓ=2, a=1; hence e=1 if and only if a=0, or ℓ=2 and a=1.

2.1F3

If ℓ∣f then a≥1; if moreover ℓ=2 then a≥2 by [F3], so the exceptional case ℓ=2, a=1 of step 1.1 cannot occur for the reduced index f.

3.1step 1.1step 2.1

Combining steps 1.1 and 2.1: when ℓ∤f we have a=0 and e=1, and when ℓ∣f we have a≥1 with (ℓ,a)≠(2,1), hence e≥2.

4.1F1step 3.1∎

By [F1] the ramification behaviour of ℓ is read off from the single exponent e: ℓ is unramified exactly when e=1 and ramified exactly when e≥2. Step 3.1 therefore gives: ℓ∤f implies e=1 and ℓ unramified, while ℓ∣f implies e≥2 and ℓ ramified. Hence ℓ ramifies in K=Q(ζf) if and only if ℓ∣f.

Remarks

  • Reducedness is essential for the converse. For the non-reduced index f=6 one has Q(ζ6)=Q(ζ3) and ℓ=2 divides f although 2 is unramified; the exclusion of indices f≡2(mod4) is exactly what makes "ℓ∣f" equivalent to ramification here.
  • Prime divisors of the conductor. Once the companion conductor theorem identifies the reduced index f with the conductor (Cyclotomic conductor of a full cyclotomic field) of Q(ζf), the corollary reads: the ramified primes are exactly the prime divisors of the conductor, and away from them the Frobenius is the power map by Arithmetic Frobenius is the power map in an unramified cyclotomic field.
TheoremStatement: Literature-sourcedProof: AI-adaptedjudge pass (gpt-6.1-sol)audited 2026-10-02Open item page →

Conductor of a full cyclotomic field

Statement

Let n≥1 and let Q(ζn) be the n-th cyclotomic field. The cyclotomic conductor of Q(ζn) is {n,n odd or 4∣n,n/2,n≡2(mod4). In particular Q(ζ2m)=Q(ζm) for odd m, and for n=2 one has Q(ζ2)=Q of conductor 1.

Facts & Assumptions

Given: An integer n≥1; for every N≥1 the index t(N):={N,N odd or 4∣N,N/2,N≡2(mod4), and the number r:=t(n). Also a primitive N-th root of unity ζN for each N.

[F1]

Conductor: the cyclotomic conductor of a full cyclotomic field K=Q(μf) is the least positive f that is admissible, meaning that there is a Q-algebra embedding K↪F into a splitting field F of tf−1 over Q (Cyclotomic conductor of a full cyclotomic field). Splitting fields of tf−1 over Q are unique up to Q-isomorphism and Q(ζf) is one, so f is admissible for K exactly when K embeds in Q(ζf) (Any two splitting fields of a polynomial are isomorphic over the base field, The cyclotomic extension K(μn) as a splitting field of tn−1).

[F2]

For a primitive r-th root ζr, the polynomial Φr is its monic minimal polynomial over Q and its roots are exactly the primitive r-th roots of unity (Φn is irreducible in Q[t] for every n≥1, Over a field whose characteristic does not divide n, the roots of Φn are exactly the primitive roots of unity); hence a Q-algebra embedding Q(ζr)↪E into a field E sends ζr to a primitive r-th root of unity ξ∈E, and Q(ξ) is the splitting field of tr−1 over Q inside E, that is, a copy of Q(ζr).

[F3]

If m is odd then (−ζm)2m=1 and (−ζm)m=−1, so −ζm is a primitive 2m-th root of unity; hence the splitting field of t2m−1 over Q is Q(−ζm)=Q(ζm), that is, Q(ζ2m)=Q(ζm) (The cyclotomic extension K(μn) as a splitting field of tn−1).

[F4]

Prime factorisation in a reduced cyclotomic field: for a reduced index f and a rational prime p, writing f=pam with gcd⁡(p,m)=1, one has pOQ(ζf)=(P1⋯Pg)φ(pa) with pairwise distinct primes Pi; in particular every prime of OQ(ζf) above p occurs with exponent φ(pa)=φ(pvp(f)) in pOQ(ζf) (Prime factorisation in a cyclotomic field).

[F5]

Tower of ramification groups: for a tower of number fields M/L/K with M/K and L/K finite Galois and primes Q∣P∣p, the restriction maps fit in the exact sequence 1→I(Q/P)→I(Q/p)→I(P/p)→1 (Decomposition and inertia in towers); and for a finite Galois extension the inertia group order is the ramification exponent, ∣I(P/p)∣=e(P/p) (Orders of decomposition and inertia groups).

[F6]

Euler totient of prime powers: φ(1)=1 and, for a≥1, φ(pa)=pa−1(p−1) for every prime p (For a prime p and k≥1, φ(pk)=pk−pk−1); hence a↦φ(pa) is strictly increasing on a≥1, and φ(pa)>1 for a≥1 except for p=2, a=1.

[F7]
[F8]

A nonzero prime P of a number-field ring of integers lies above a prime p of the base ring when its contraction is exactly p (Primes above and residue degree).

Proof

technique · direct
1.1F3

For every N≥1 the index t(N) is reduced and Q(ζN)=Q(ζt(N)): this is immediate by definition when N is odd or 4∣N, and if N=2m with m odd then t(N)=m is odd and [F3] gives Q(ζN)=Q(ζm).

1.2F2

If Q(ζr)↪E is a Q-algebra embedding into a field E, then the image ξ of ζr is a primitive r-th root of unity and the subfield Q(ξ) is a splitting field of tr−1 inside E, hence a copy of Q(ζr); in particular an embedding Q(ζr)↪Q(ζs) exhibits Q(ζr) as a subfield of Q(ζs).

2.1F1step 1.1

By step 1.1, Q(ζn)=Q(ζr) is a splitting field of tr−1 over Q that contains ζr, so the identity embedding shows that r is admissible for Q(ζn); hence the conductor of Q(ζn) is at most r.

2.2F1step 1.1step 1.2

Let g≥1 be admissible for Q(ζn) and put s:=t(g). By step 1.1, s is reduced and Q(ζg)=Q(ζs), so admissibility gives a Q-algebra embedding Q(ζn)↪Q(ζs), i.e., since Q(ζn)=Q(ζr) by step 1.1, an embedding Q(ζr)↪Q(ζs); step 1.2 then makes Q(ζr) a subfield of Q(ζs).

3.1F4F5F7F8step 2.2

Let p be a prime with p∣r, and write L=Q(ζr) and M=Q(ζs), so step 2.2 gives L⊆M. By [F4], choose a prime Q of OM above p; define P:=Q∩OL. The inclusion OL↪OM makes P the inverse image of the prime Q, hence P is prime. Since p∈Q, one has p∈P, so P≠(0); moreover P∩Z=(Q∩OL)∩Z=Q∩Z=(p), so [F8] says P lies above p. By [F4], the ramification exponents of these primes are e(P/p)=φ(pvp(r)) and e(Q/p)=φ(pvp(s)) (with vp(s)=0 allowed and φ(1)=1). By [F7], both L/Q and M/Q are Galois, so [F5] applies to M/L/Q and makes I(P/p) a quotient of I(Q/p); therefore φ(pvp(r)) divides φ(pvp(s)).

4.1F6step 3.1

For every prime p the exponents of p in the reduced indices r and s lie in {0,1,2,… } when p is odd and in {0}∪{k≥2} when p=2; by [F6] the function a↦φ(pa) is strictly increasing on these sets and satisfies φ(p0)=1<φ(p2)=2 for p=2 and 1<φ(p)=p−1 for odd p, so φ(pvp(r))≤φ(pvp(s)) implies vp(r)≤vp(s). Step 3.1 therefore gives vp(r)≤vp(s) for every prime p∣r — vacuously when r=1 — so r∣s; and s=t(g) equals g or g/2, so s≤g and hence r≤g.

5.1F1step 2.1step 4.1∎

Step 2.1 shows that r is admissible and step 4.1 shows that every admissible g satisfies g≥r; hence the least admissible index — the conductor of Q(ζn) — equals r=t(n). Consequently the conductor is n when n is odd or 4∣n and is n/2 when n≡2(mod4); in particular Q(ζ2m)=Q(ζm) for odd m by step 1.1, and for n=2 the conductor is t(2)=1, with Q(ζ2)=Q.

Remarks

  • Dependency reconciliation (Step 3a observation). The comparison of ramification exponents inside the inclusion Q(ζr)⊆Q(ζs) is supplied here by the published tower theorem Decomposition and inertia in towers together with Orders of decomposition and inertia groups; the local monogenic/DVR route sketched in the scaffold is not needed, and no use is made of any general ideal factorisation theorem beyond the pair's own Prime factorisation in a cyclotomic field.
  • The excluded shape. For n=2m with m odd one has Q(ζn)=Q(ζm), so n is never the conductor; Remark 11.7 of Conrad-Landesman makes the same point via −ζm and Z[ζm]=Z[−ζm].
CorollaryStatement: Literature-sourcedProof: AI-adaptedprecheck passaudited 2026-10-02Open item page →

Decomposition of an unramified prime in a cyclotomic field

Statement

Let f be the conductor of the cyclotomic field K=Q(ζf), and let ℓ be a rational prime with ℓ∤f. Then every prime P of OK above ℓ has residue degree deg⁡(P/ℓ)=ord⁡f(ℓ), the multiplicative order of ℓ modulo f, and there are exactly φ(f)/ord⁡f(ℓ) such primes.

Facts & Assumptions

Given: A cyclotomic field K=Q(ζf) presented by its conductor f, so that f is the least admissible index for K (Cyclotomic conductor of a full cyclotomic field), a rational prime ℓ with ℓ∤f, and the factorisation f=ℓam with gcd⁡(ℓ,m)=1 (so a=0 and m=f under the hypothesis ℓ∤f).

[F1]

The conductor f of a full cyclotomic field is a reduced index: it is odd or divisible by 4 (Conductor of a full cyclotomic field, Cyclotomic conductor of a full cyclotomic field).

[F2]

Prime factorisation in a reduced cyclotomic field: for the reduced index f, a rational prime ℓ, and f=ℓam with gcd⁡(ℓ,m)=1, ℓOK=(P1⋯Pg)e,e=φ(ℓa), d=ord⁡m(ℓ), g=φ(m)/d, with the Pi pairwise distinct primes of residue degree d; here ord⁡1(ℓ)=1 (Prime factorisation in a cyclotomic field).

[F3]

For ℓ∤f the arithmetic Frobenius at every prime above ℓ is the automorphism σℓ with σℓ(ζf)=ζf ℓ (Arithmetic Frobenius is the power map in an unramified cyclotomic field).

Proof

technique · direct
1.1F1

By [F1], f is a reduced index; as ℓ∤f the ℓ-adic valuation is a=0, so m=f and e=φ(1)=1.

2.1F2step 1.1

Applying [F2] with a=0, m=f, the ideal ℓOK factors as P1⋯Pg with g=φ(f)/d pairwise distinct primes of residue degree d=ord⁡f(ℓ), so ℓ is unramified and these are exactly the primes above ℓ.

3.1F2F3step 2.1given∎

Therefore every prime above ℓ has residue degree ord⁡f(ℓ) and their number is φ(f)/ord⁡f(ℓ). This degree also equals the order of the arithmetic Frobenius in [F3]: for r≥1, σℓr(ζf)=ζfℓr, so, since ζf has order f and generates K, σℓr=id exactly when ℓr≡1(modf). The least such r is ord⁡f(ℓ), including r=1 for f=1.

Remarks

  • Conductor versus displayed index. The statement is about the conductor f; for an unreduced displayed index such as 6 the count and degrees are those of the reduced index 3, as recorded in The reduced conductor of Q(zeta_6) ↗.
  • Order-one convention. For f=1 one has ord⁡1(ℓ)=1 and the formula gives the single prime ℓZ=ℓOQ, consistent with φ(1)=1.
CorollaryStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (gpt-6.1-sol)audited 2026-10-02Open item page →

Complete splitting criterion for a cyclotomic field

Statement

Let f be the conductor of the cyclotomic field K=Q(ζf), and let ℓ be a rational prime with ℓ∤f. Then ℓ splits completely in K if and only if ℓ≡1(modf).

Facts & Assumptions

Given: The cyclotomic field K=Q(ζf) presented by its conductor f (Cyclotomic conductor of a full cyclotomic field), and a rational prime ℓ∤f, so gcd⁡(ℓ,f)=1 and the class of ℓ lies in (Z/f)×.

[F1]

Unramified decomposition: for the conductor f and ℓ∤f, every prime of OK above ℓ has residue degree ord⁡f(ℓ) and there are exactly φ(f)/ord⁡f(ℓ) of them; in particular ℓ is unramified (Decomposition of an unramified prime in a cyclotomic field).

[F2]

Splitting terminology: a rational prime ℓ splits completely in K if it is unramified in K and every prime of OK above it has residue degree 1 (Splitting and ramification terminology).

[F3]

For a positive integer f and an integer ℓ with gcd⁡(ℓ,f)=1, the order of the class [ℓ]∈(Z/f)× equals 1 if and only if ℓ≡1(modf) (The order ∣G∣ of a finite group and the order ord⁡(g) of an element, with ord⁡(g)=∞ when no positive power of g is the identity, The unit group (Z/n)× and Euler's totient φ(n)=∣(Z/n)×∣ for n≥1).

Proof

technique · direct
1.1F1

By [F1] the prime ℓ is unramified in K and every prime above it has residue degree d:=ord⁡f(ℓ), so the primes above ℓ number φ(f)/d.

1.2F3

By [F3], d=1 holds if and only if ℓ≡1(modf).

2.1F2F4step 1.1

By [F2] and step 1.1, ℓ splits completely in K if and only if every prime above ℓ has residue degree 1, i.e., if and only if d=1; equivalently (step 1.1) the number of primes above ℓ is then φ(f)=[K:Q] by [F4].

3.1step 1.2step 2.1∎

Combining steps 1.2 and 2.1: ℓ splits completely in K=Q(ζf) if and only if ord⁡f(ℓ)=1, if and only if ℓ≡1(modf).

Remarks

  • Consistency of counts. Complete splitting gives φ(f) primes of residue degree 1, matching the decomposition count φ(f)/ord⁡f(ℓ)=φ(f) and the degree [K:Q]=φ(f).
  • Unramified hypothesis. The equivalence is stated for ℓ∤f; for ℓ∣f the prime ℓ is ramified and the Frobenius element is not defined, by Ramification primes of a reduced cyclotomic conductor.
DefinitionDefinition: Literature-sourcedProof: Not applicableprecheck passjudge pass (gpt-6.1-sol)audited 2026-10-02Open item page →

Quadratic Gauss sum in a prime cyclotomic field

Definition

Let p be an odd prime, let ζp be a fixed primitive p-th root of unity (The cyclotomic extension K(μn) as a splitting field of tn−1), and let (⋅/p) be the Legendre symbol (The Legendre symbol, including its zero value). The quadratic Gauss sum attached to ζp is

τp:=∑a mod p(ap)ζp a=∑a=1p−1(ap)ζp a ∈ Z[ζp].

The sum lies in Z[ζp] and is an algebraic integer. The term a=0 vanishes because (0/p)=0, so the sum is finite over the classes a=1,…,p−1; each ζpa is a root of tp−1 and hence integral over Z (Integral elements over a commutative ring and algebraic integers), and the integral elements of C form a subring, so τp is an algebraic integer lying in Z[ζp]⊆OQ(ζp) (Ring of integers).

The chosen root is part of the data. The notation τp always refers to the sum built from the explicitly chosen ζp. Replacing ζp by another primitive p-th root changes τp up to a sign: indeed σb(ζp)=ζp b gives ∑a(a/p)ζp ab=(b/p)τp for every b≢0(modp). The square τp2=p∗=(−1)(p−1)/2p and the field Q(τp) are unchanged by that replacement (Square of the quadratic Gauss sum, Quadratic subfield generated by the Gauss sum), but the sign of τp is not fixed until the primitive root (equivalently, a complex embedding) is fixed.

LemmaStatement: Literature-sourcedProof: AI-adaptedprecheck passaudited 2026-10-02Open item page →

Galois action on the quadratic Gauss sum

Statement

Let p be an odd prime, let ζp be a fixed primitive p-th root of unity, let τp=∑a mod p(a/p)ζp a be the quadratic Gauss sum attached to ζp, and let b be an integer not divisible by p. For the automorphism σb of Q(ζp) with σb(ζp)=ζp b one has σb(τp)=(bp)τp.

Facts & Assumptions

Given: An odd prime p, a fixed primitive p-th root of unity ζ=ζp in a fixed algebraic closure of Q, the Gauss sum τ:=τp=∑a mod p(a/p)ζa, and an integer b with p∤b.

[F1]

τ=∑a=1p−1(a/p)ζa∈Z[ζ], because the a=0 term of the defining sum carries the factor (0/p)=0 (Quadratic Gauss sum in a prime cyclotomic field, The Legendre symbol, including its zero value).

[F2]

K=Q(ζp) is Galois over Q, and Gal⁡(K/Q)≅(Z/p)× via σb(ζ)=ζb; every such σb fixes Q and hence acts on Z[ζ] by b-th powers of ζ ([Q(ζn):Q]=φ(n) and Gal⁡(Q(μn)/Q)≅(Z/n)×).

[F3]

The Legendre symbol is multiplicative for all integer numerators: (uv/p)=(u/p)(v/p) for all u,v∈Z (The Legendre symbol is multiplicative for all integer numerators); moreover (1/p)=1 and (b/p)∈{±1} for p∤b, so (b−1/p)=(b/p) by multiplicativity applied to b⋅b−1≡1.

Proof

technique · direct
1.1F1F2

Applying the automorphism σb of [F2] to the finite sum of [F1] gives σb(τ)=∑a=1p−1(a/p)σb(ζ)a=∑a=1p−1(a/p)ζab, since σb fixes the rational integers (a/p).

2.1step 1.1

Multiplication by b permutes the nonzero residue classes modulo p, so substituting c≡ab(modp) rewrites the sum as σb(τ)=∑c=1p−1(b−1c/p)ζc, where b−1 denotes an inverse of b modulo p.

3.1F1F3step 2.1∎

By multiplicativity of the Legendre symbol the coefficient factors as (b−1c/p)=(b−1/p)(c/p), and (b−1/p)=(b/p) because (b/p)(b−1/p)=(bb−1/p)=(1/p)=1 and (b/p)=±1. Therefore σb(τ)=(b/p)∑c=1p−1(c/p)ζc=(b/p)τ.

Remarks

  • No analytic sign is used. The argument is a finite rearrangement of the defining sum together with the multiplicativity of the Legendre symbol; it never chooses a complex embedding of Q(ζp) or a sign of τp. Later, together with the theorem that τp2=p∗≠0, this identity shows that exactly the square classes b fix τp, which identifies the quadratic subfield generated by τp.
  • Convention. As in the definition, σb(ζ)=ζb is the arithmetic power map. Its inverse ζ↦ζb−1 has the same action on τp, since (b−1/p)=(b/p) by [F3].
TheoremStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (gpt-6.1-sol)audited 2026-10-02Open item page →

Square of the quadratic Gauss sum

Statement

For every odd prime p and every primitive p-th root of unity ζp, with τp=∑a mod p(a/p)ζp a, τp2=p∗=(−1)(p−1)/2p.

Facts & Assumptions

Given: An odd prime p, a fixed primitive p-th root of unity ζ=ζp in a fixed algebraic closure of Q, and the Gauss sum τ:=τp=∑a mod p(a/p)ζa.

[F1]

τ=∑s=1p−1(s/p)ζs∈Z[ζ], the term a=0 vanishing because (0/p)=0 (Quadratic Gauss sum in a prime cyclotomic field, The Legendre symbol, including its zero value).

[F2]

The Legendre symbol is multiplicative for all integer numerators: (uv/p)=(u/p)(v/p) for all u,v∈Z (The Legendre symbol is multiplicative for all integer numerators).

[F3]

Restricted to (Z/p)× the Legendre symbol is a surjective homomorphism onto {±1} with kernel the nonzero square classes (On the units, the Legendre symbol is the unique nontrivial homomorphism to {±1}); hence ∑u=1p−1(u/p)=0, because choosing v with (v/p)=−1 and substituting u↦vu permutes the nonzero classes and multiplies the sum by −1, forcing it to be 0.

[F4]

First supplement: (−1/p)=(−1)(p−1)/2 (First supplement: (−1/p)=(−1)(p−1)/2).

[F5]

For an element x with xp=1 and x≠1 one has ∑s=0p−1xs=xp−1x−1=0, so ∑s=1p−1xs=−1; and ζ has order p, so ζ1+u≠1 exactly when u≢−1(modp) (The group μn(K) of n-th roots of unity in a field, and primitive n-th roots of unity).

Proof

technique · direct
1.1F1

Squaring the sum of [F1] and multiplying out the finite product of sums gives τ2=∑s=1p−1∑t=1p−1(s/p)(t/p)ζs+t.

1.2F5

For every integer u≢0(modp) the inner geometric sum over s is ∑s=1p−1ζs(1+u)=−1 when u≢−1(modp), while for u≡−1(modp) it equals ∑s=1p−11=p−1.

2.1F2step 1.1

Multiplication by u permutes the nonzero classes modulo p, so substituting t≡su(modp) in the double sum of step 1.1 rewrites it as τ2=∑u=1p−1∑s=1p−1(s/p)(su/p)ζs(1+u)=∑u=1p−1(u/p)∑s=1p−1ζs(1+u), using multiplicativity of the Legendre symbol in the last equality.

3.1F3step 1.2step 2.1

Substituting the two evaluations of step 1.2, the contribution of u≡−1(modp) is (−1/p)(p−1) and every other u contributes −(u/p); hence τ2=(−1/p)(p−1)−(∑u=1p−1(u/p)−(−1/p))=p (−1/p)−∑u=1p−1(u/p)=p (−1/p), since the character sum vanishes by [F3].

4.1F4step 3.1∎

By the first supplement [F4], (−1/p)=(−1)(p−1)/2, so τ2=(−1)(p−1)/2p=p∗.

Remarks

  • Only finite sums and the first supplement are used. Neither quadratic reciprocity nor any analytic determination of the sign of τp enters; the square p∗ is insensitive to replacing ζp by another primitive p-th root, since that multiplies τp by ±1.
  • Nonvanishing. Since p∗=±p≠0 in the domain Z[ζp], the identity shows that τp≠0, which is what makes the fixed field computation in Quadratic subfield generated by the Gauss sum possible.
TheoremStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (gpt-6.1-sol)audited 2026-10-02Open item page →

Quadratic subfield generated by the Gauss sum

Statement

For an odd prime p, the unique intermediate field Q⊆F⊆Q(ζp) with [F:Q]=2 is Q(τp)=Q(p∗),p∗=(−1)(p−1)/2p, where τp is the quadratic Gauss sum attached to a chosen primitive p-th root of unity ζp. At p=3 the field Q(ζ3) itself has degree two over Q, so the intermediate field of degree two may equal the full cyclotomic field.

Facts & Assumptions

Given: An odd prime p, a fixed primitive p-th root of unity ζ in a fixed algebraic closure of Q, and the Gauss sum τ:=τp=∑a mod p(a/p)ζa.

[F1]

τ=∑a=1p−1(a/p)ζa∈Z[ζ]⊆Q(ζ), the term a=0 vanishing, and the chosen root ζ is part of the data (Quadratic Gauss sum in a prime cyclotomic field, The Legendre symbol, including its zero value).

[F2]

τ2=p∗=(−1)(p−1)/2p (Square of the quadratic Gauss sum).

[F3]

For every integer b not divisible by p, the automorphism σb(ζ)=ζb satisfies σb(τ)=(b/p)τ; consequently the Gauss sum built from another primitive p-th root ζb equals (b/p)τ and generates the same field as τ (Galois action on the quadratic Gauss sum).

[F4]

Q(ζp) is a finite Galois extension of Q with group G:=Gal⁡(Q(ζp)/Q); the embedding G→(Z/p)× taking σ with σ(ζ)=ζb to b is an isomorphism, and [Q(ζp):Q]=p−1. The group (Z/p)× is cyclic of order p−1, so G is cyclic of order p−1 ([Q(ζn):Q]=φ(n) and Gal⁡(Q(μn)/Q)≅(Z/n)×, For every prime p, the multiplicative group (Z/pZ)× is cyclic, The cyclotomic extension K(μn) as a splitting field of tn−1).

[F5]

In a finite cyclic group of order n, every positive divisor d of n is the order of exactly one subgroup, and every subgroup is the unique subgroup of its own order; in particular the cyclic group G of [F4] has exactly one subgroup of order (p−1)/2 (A finite cyclic group has exactly one subgroup of each order dividing its own).

[F6]

Fundamental theorem of finite Galois theory: for a finite Galois extension K/F with group G, the maps H↦KH and E↦Gal⁡(K/E) are mutually inverse bijections between subgroups of G and intermediate fields, and [KH:F]=[G:H]; in particular intermediate fields of degree two over F correspond bijectively to subgroups of index two (The fundamental theorem of finite Galois theory).

[F7]

Lagrange's theorem: for a finite group G and a subgroup H≤G one has ∣G∣=[G:H] ∣H∣ (Lagrange's theorem: ∣G∣=[G:H]∣H∣ for every subgroup H of a finite group G).

[F8]

The Legendre symbol on (Z/p)× is a homomorphism onto {±1}, so (b/p)−1=(b/p) for every nonzero class b (On the units, the Legendre symbol is the unique nontrivial homomorphism to {±1}).

Proof

technique · direct
1.1F1F2

The sum τ is an element of Z[ζ], hence of Q(ζ), and it satisfies τ2=p∗=(−1)(p−1)/2p.

1.2F1F3F8

If ζ′=ζb is any primitive p-th root of unity, then the Gauss sum built from ζ′ is ∑a=1p−1(a/p)ζab=σb(τ)=(b/p)τ, a nonzero multiple of τ; hence it generates the same subfield Q(τ).

1.3F2

The rational number p∗=±p is not a square in Q: if x=a/b in lowest terms had x2=p∗, then a2=p∗b2; for p∗=p the exponent of p on the left side of a2=pb2 is 2vp(a), while on the right it is 1+2vp(b), which is odd, a contradiction, and for p∗=−p the left side a2/b2 is positive while −p is negative.

2.1step 1.1step 1.3

Since τ2=p∗≠0, we have τ≠0, and τ∉Q by step 1.3; as τ is a root of the degree-two polynomial X2−p∗∈Q[X], the degree [Q(τ):Q] divides 2 and is not 1, so it equals 2, and Q(τ)⊆Q(ζ) by step 1.1. Moreover τ is a square root of p∗, so τ=±p∗ and Q(τ)=Q(p∗).

3.1F4F5F6F7step 2.1

Let F⊆Q(ζp) be any intermediate field with [F:Q]=2 and put H:=Gal⁡(Q(ζp)/F). By [F6] the subgroup H has index [G:H]=[F:Q]=2 in G, so [F7] together with ∣G∣=p−1 from [F4] gives ∣H∣=(p−1)/2. As (p−1)/2 is a positive divisor of p−1, [F5] shows that the cyclic group G has exactly one subgroup of order (p−1)/2, so H is that same subgroup for every such F; the bijection [F6] then gives F=Q(ζp)H, the same field for every such F. Since step 2.1 exhibits Q(τ) as one of them, Q(τ) is the unique degree-two intermediate field.

4.1F4step 1.2step 2.1step 3.1∎

Combining steps 1.2 and 3.1 with the identification of step 2.1: the unique degree-two intermediate field is Q(τp)=Q(p∗), independently of the chosen primitive p-th root, and for p=3 one has [Q(ζ3):Q]=p−1=2 by [F4], so the unique degree-two intermediate field there is Q(ζ3) itself.

Remarks

  • Nonvanishing is the decisive input. Without τp2=p∗≠0 the element τp might generate only Q; the square computation of Square of the quadratic Gauss sum is what makes the generated field quadratic.
  • The sign of τp is not needed. Replacing ζp by ζp b multiplies τp by the Legendre sign (b/p), which leaves both the square and the generated field unchanged; this is the content of the sign counterexample on the companion examples page.
TheoremStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (gpt-6.1-sol)audited 2026-10-02Open item page →

Quadratic reciprocity as a Frobenius restriction identity

Statement

Let p≠q be odd primes, let ζp be a fixed primitive p-th root of unity, let τp=∑a mod p(a/p)ζp a be the quadratic Gauss sum attached to it, and put p∗=(−1)(p−1)/2p. The arithmetic Frobenius Frob⁡q of q in Q(ζp) sends ζp⟼ζp q,τp⟼(qp)τp. Its restriction to the quadratic subfield Q(p∗) acts by τp⟼(p∗q)τp, and consequently (p∗q)=(qp).

Facts & Assumptions

Given: Distinct odd primes p and q, a fixed primitive p-th root of unity ζ=ζp, the Gauss sum τ=τp attached to it, the field K=Q(ζ), the element p∗=(−1)(p−1)/2p, and the automorphism σq∈Gal⁡(K/Q) with σq(ζ)=ζ q.

[F1]

The index p is reduced and q∤p; hence σq is the arithmetic Frobenius at every prime P of OK above q: it is the unique element of Gal⁡(K/Q) with σq(x)≡xq(modP) for all x∈OK, and it does not depend on the choice of P (Arithmetic Frobenius is the power map in an unramified cyclotomic field, Arithmetic frobenius coset).

[F2]

For every integer b not divisible by p one has σb(τ)=(b/p)τ, where σb(ζ)=ζ b; in particular σq(τ)=(q/p)τ (Galois action on the quadratic Gauss sum).

[F3]

τ2=p∗ and Q(τ)=Q(p∗) is the unique intermediate field Q⊆F⊆K with [F:Q]=2; moreover τ∈OK and τ∉Q (Square of the quadratic Gauss sum, Quadratic subfield generated by the Gauss sum, Quadratic Gauss sum in a prime cyclotomic field).

[F4]

Euler's criterion: for every integer a and the odd prime q, (a/q)≡a(q−1)/2(modq), and (a/q)∈{−1,0,1} (Euler's criterion: (a/p)≡a(p−1)/2(modp), The Legendre symbol, including its zero value).

[F5]

q∤p∗: indeed p∗=±p with q≠p, so p∗≢0(modq). [given, arithmetic]

Proof

technique · direct
1.1F1F2F3

By [F1] the automorphism σq sends ζ to ζq and is the arithmetic Frobenius at each prime above q, while by [F2] it sends σq(τ)=(q/p)τ; since (q/p)=±1, it maps τ to ±τ and therefore preserves F=Q(τ).

1.2F3F5

Let P be a prime of OK above q and let κ=OK/P be its residue field. Since τ2=p∗ and q∤p∗ by [F5], we have τ2≡p∗≢0(modP), so the residue class of τ in the field κ is nonzero.

1.3F4

Euler's criterion [F4] with a=p∗ gives (p∗)(q−1)/2≡(p∗/q)(modq).

1.4F1F3

By the congruence property of [F1] applied to x=τ∈OK, for every prime P above q one has σq(τ)≡τq(modP).

2.1F3step 1.3

In κ one has τq=τ⋅(τ2)(q−1)/2=τ⋅(p∗)(q−1)/2=(p∗/q) τ, the last equality because (p∗)(q−1)/2≡(p∗/q)(modq) by step 1.3 and P contains q.

3.1step 1.1step 1.2step 1.4step 2.1

Fix P above q. Steps 1.1, 1.4 and 2.1 compare the same element in the field κ and give (q/p)τ=σq(τ)≡τq=(p∗/q)τ(modP); the residue class of τ is nonzero by step 1.2, so cancellation gives (qp)≡(p∗q)(modP).

4.1step 3.1F4

Both (qp) and (p∗q) lie in {−1,1}; their difference lies in P∩Z, which is the prime ideal (q) because P lies above q and qZ is maximal. A difference of two elements of {−1,1} that is divisible by the odd prime q must be 0; hence (p∗q)=(qp).

5.1step 1.1step 4.1F3∎

The element τ generates F=Q(p∗) over Q by [F3], and step 1.1 together with step 4.1 gives σq(τ)=(qp)τ=(p∗q)τ; therefore the restriction of the arithmetic Frobenius to the quadratic subfield Q(p∗) acts on τ by multiplication by (p∗q), that is, it is the identity if (p∗q)=1 and the nontrivial automorphism if (p∗q)=−1.

Remarks

  • Arithmetic convention. The result uses the arithmetic Frobenius ζ↦ζq; the geometric inverse would send ζ to ζq−1, whose exponent is a different nonzero class modulo p in general, and the identity with (qp) would then read with the inverse symbol.
  • No prior reciprocity. Neither this theorem nor its supplier Square of the quadratic Gauss sum uses quadratic reciprocity: the comparison is between two independently computed signs for the same residue class.
CorollaryStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (gpt-6.1-sol)audited 2026-10-02Open item page →

Quadratic reciprocity via Frobenius

Statement

For distinct odd primes p and q, (pq)(qp)=(−1)(p−1)(q−1)/4.

Facts & Assumptions

Given: Distinct odd primes p and q, and p∗=(−1)(p−1)/2p.

[F1]

Quadratic Frobenius restriction identity: for distinct odd primes p,q, (p∗q)=(qp) (Quadratic reciprocity as a Frobenius restriction identity).

[F2]

Legendre symbol multiplicativity: (ab/q)=(a/q)(b/q) for all integers a,b; consequently (((−1)kp)/q)=((−1)/q)k(p/q) for every integer k≥0, and (a/q)∈{−1,0,1} with (a/q)=0 exactly when q∣a (The Legendre symbol is multiplicative for all integer numerators, The Legendre symbol, including its zero value).

[F3]

First supplement: (−1/q)=(−1)(q−1)/2 (First supplement: (−1/p)=(−1)(p−1)/2).

[F4]

q∤p, so (p/q)≠0 and hence (p/q)2=1 (The Legendre symbol, including its zero value).

Proof

technique · direct
1.1F2

By [F2], p∗=(−1)(p−1)/2p gives (p∗q)=(−1q)(p−1)/2(pq).

1.2F3algebra

By [F3], (−1q)(p−1)/2=(−1)((p−1)/2)((q−1)/2)=(−1)(p−1)(q−1)/4, the exponent (p−1)(q−1)/4 being an integer because p−1 and q−1 are even.

1.3F4

Since p≠q, the symbol (p/q) is ±1, so (p/q)2=1.

2.1step 1.1step 1.2

Substituting step 1.2 into step 1.1 gives (p∗q)=(−1)(p−1)(q−1)/4(pq).

3.1F1step 2.1

Combining with [F1], (qp)=(p∗q)=(−1)(p−1)(q−1)/4(pq).

4.1step 1.3step 3.1∎

Multiplying both sides of step 3.1 by (pq) and using (p/q)2=1 from step 1.3 yields (pq)(qp)=(−1)(p−1)(q−1)/4(pq)2=(−1)(p−1)(q−1)/4.

Remarks

  • The earlier reciprocity theorem is not used. The only inputs are the Frobenius restriction identity, Legendre multiplicativity and the first supplement; in particular neither the published quadratic reciprocity theorem nor an analytic Gauss-sum sign is a supplier.
  • Symmetry check. (p−1)(q−1)/4 is symmetric in p and q, as the product form must be; the two special values p=q and the case p=2 are excluded, the latter being exactly the case covered by the second supplement Second supplement from Frobenius on Q(zeta_8).
CorollaryStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (gpt-6.1-sol)audited 2026-10-02Open item page →

First supplement from Frobenius on Q(i)

Statement

For every odd prime q, the arithmetic Frobenius of q in the quadratic field Q(i)=Q(ζ4) sends i to Frob⁡q(i)=iq=(−1)(q−1)/2i, so it acts on Q(i) by the quadratic sign (−1/q)=(−1)(q−1)/2.

Facts & Assumptions

Given: An odd prime q, the element i=ζ4, a primitive fourth root of unity, and the field K=Q(i)=Q(ζ4) of degree 2 over Q.

[F1]

The index f=4 is reduced, and q∤4; hence the arithmetic Frobenius of q in Q(ζ4)/Q is the power map σq(ζ4)=ζ4 q (Arithmetic Frobenius is the power map in an unramified cyclotomic field, The cyclotomic extension K(μn) as a splitting field of tn−1).

[F2]

OQ(i)=Z[i], and i2=−1, so iq=i (i2)(q−1)/2=(−1)(q−1)/2i for odd q (Ring of integers of every cyclotomic field).

[F3]

Euler's criterion: for every integer a and odd prime q, (a/q)≡a(q−1)/2(modq) (Euler's criterion: (a/p)≡a(p−1)/2(modp), The Legendre symbol, including its zero value); the Legendre symbol satisfies (a/q)∈{−1,0,1}.

Proof

technique · direct
1.1F1F2

By [F1] the Frobenius of q acts on K as the power map on ζ4=i, and by [F2] this is Frob⁡q(i)=iq=(−1)(q−1)/2i.

1.2F3

By Euler's criterion with a=−1, (−1/q)≡(−1)(q−1)/2(modq); both (−1/q) and (−1)(q−1)/2 are elements of {−1,1}, so their difference is 0 or ±2, and a multiple of the odd prime q; hence the difference is 0 and (−1/q)=(−1)(q−1)/2.

2.1step 1.1step 1.2∎

Therefore the arithmetic Frobenius acts on i by multiplication by the quadratic sign (−1/q), that is Frob⁡q(i)=(−1/q) i.

Remarks

  • Independence from the earlier supplement. The sign is computed here from the power map and Euler's criterion; the published first-supplement theorem is not used as a supplier, so no circularity arises with the quadratic reciprocity corollary that consumes this item.
CorollaryStatement: Literature-sourcedProof: AI-adaptedprecheck passjudge pass (gpt-6.1-sol)audited 2026-10-02Open item page →

Second supplement from Frobenius on Q(zeta_8)

Statement

For every odd prime q, the element t=ζ8+ζ8−1 satisfies t2=2, so Q(2)=Q(t) is a quadratic subfield of Q(ζ8), and the arithmetic Frobenius of q acts on it by Frob⁡q(t)=(2q)t=(−1)(q2−1)/8 t.

Facts & Assumptions

Given: An odd prime q, a primitive eighth root of unity ζ=ζ8, and the element t:=ζ+ζ−1∈Q(ζ).

[F1]

The index f=8 is reduced, and q∤8; hence the arithmetic Frobenius of q in Q(ζ8)/Q is the power map σq(ζ)=ζ q (Arithmetic Frobenius is the power map in an unramified cyclotomic field, The cyclotomic extension K(μn) as a splitting field of tn−1).

[F2]

ζ2=ζ4 has order 4, so ζ2+ζ−2=i+(−i)=0 and t2=ζ2+2+ζ−2=2; in particular t is a square root of 2 and Q(t)=Q(2) is a degree-two subfield of Q(ζ8) (Ring of integers of every cyclotomic field, The cyclotomic extension K(μn) as a splitting field of tn−1).

[F3]

For every odd integer m, writing the residue of m modulo 8 gives ζm+ζ−m=t when m≡±1(mod8) and ζm+ζ−m=−t when m≡±3(mod8), because ζ4=−1 and ζ3=−ζ−1. For residues 1,7 the integer (m2−1)/8 is even, and for residues 3,5 it is odd. Thus σq(t)=(−1)(q2−1)/8t. [F1, algebra]

[F4]

Euler's criterion: for every integer a and odd prime q, (a/q)≡a(q−1)/2(modq), and (a/q)∈{−1,0,1} (Euler's criterion: (a/p)≡a(p−1)/2(modp), The Legendre symbol, including its zero value).

Proof

technique · direct
1.1F2

By [F2], t generates the quadratic field Q(2) inside Q(ζ8), and t≠0.

1.2F3

By [F3] there is a sign ε∈{±1} with σq(t)=εt, namely ε=(−1)(q2−1)/8.

2.1F1F2step 1.2

Since σq is the arithmetic Frobenius, σq(t)≡tq(modP) for every prime P above q; here tq=t (t2)(q−1)/2=2(q−1)/2t, and t≢0(modP) because t2=2 and q is odd. Hence ε≡2(q−1)/2(modq) as integers.

3.1F4step 2.1

Euler's criterion with a=2 gives 2(q−1)/2≡(2/q)(modq); since both ε and (2/q) lie in {−1,1} and their difference is divisible by the odd prime q, they are equal. Therefore Frob⁡q(t)=(2/q)t.

4.1step 1.2step 3.1∎

Finally (2/q)=(−1)(q2−1)/8, the exponent (q2−1)/8 being an integer for odd q and even exactly when q≡±1(mod8), which matches the sign computed in step 1.2.

Remarks

  • The quadratic field Q(2) is a subfield of Q(ζ8) because ζ8+ζ8−1=2 up to sign; no uniqueness statement for the quadratic subfield is needed for the Frobenius restriction.
  • Consistency of the two signs. The combinatorial sign in step 1.2 and the Legendre sign in step 3.1 are computed by different means and then compared modulo q; this is what fixes (2/q)=(−1)(q2−1)/8 without invoking the earlier second-supplement theorem.

5 · Examples, counterexamples and false statements

None yet.

Sources