Mathematics · Book 5 · Bachelor Year 3

University Mathematics — Year 3

University Mathematics — Year 3 · Bachelor Year 3

4Field Extensions and Galois Theory

Can every equation be solved by radicals, as the quadratic formula and Cardano’s cubic formulas suggest? Can one trisect an angle with ruler and compass? Both questions, open for centuries, are answered — negatively — by a single idea of Évariste Galois: attach to every polynomial a finite group of symmetries of its roots, and read the answer off the group. This chapter builds the dictionary: field extensions and degrees, splitting fields and algebraic closures, finite fields (a complete theory — and the promised cyclicity of Fq×\mathbb F_q^\times), separability, then the Galois correspondence itself, with full proofs. We harvest: the impossibility of the classical constructions, the structure of cyclotomic fields, and the unsolvability of the quintic by radicalsChapter 1’s simplicity of A5A_5 striking its target.

4.1 Extensions, degree, algebraicity

Definition 4.1

A field extension L/KL/K is a field LL containing KK as a subfield; LL is then a KK-vector space, and the degree [L:K][L:K] is its dimension. The extension is finite if [L:K]<[L:K] < \infty. The characteristic of a field is the generator 0\geq 0 of the kernel of ZK\Z \to K, nn1n \mapsto n\cdot 1: it is 00 or a prime pp; correspondingly KK contains a smallest subfield (prime field) isomorphic to Q\Q or to Fp=Z/pZ\mathbb F_p = \Z/p\Z.

Theorem 4.2 (Tower law)

If KLMK \subseteq L \subseteq M, then [M:K]=[M:L][L:K][M:K] = [M:L]\,[L:K]: if (ei)(e_i) is a basis of LL over KK and (fj)(f_j) a basis of MM over LL, then (eifj)(e_if_j) is a basis of MM over KK.

Proof. Generating: xMx \in M writes x=jλjfjx = \sum_j \lambda_jf_j (λjL\lambda_j \in L), each λj=iμijei\lambda_j = \sum_i \mu_{ij}e_i (μijK\mu_{ij} \in K): x=i,jμijeifjx = \sum_{i,j}\mu_{ij}e_if_j. Independent: i,jμijeifj=0\sum_{i,j}\mu_{ij}e_if_j = 0 rewrites j(iμijei)fj=0\sum_j (\sum_i \mu_{ij}e_i)f_j = 0; the inner sums are in LL, so vanish (fjf_j independent over LL); then all μij=0\mu_{ij} = 0 (eie_i independent over KK).

Definition 4.3

Let L/KL/K and αL\alpha \in L. If some nonzero PK[X]P \in K[X] has P(α)=0P(\alpha) = 0, α\alpha is algebraic over KK; the monic generator πα\pi_\alpha of the ideal {P:P(α)=0}\{P : P(\alpha) = 0\} of K[X]K[X] is its minimal polynomial, an irreducible polynomial (π=QR\pi = QR with Q(α)=0Q(\alpha) = 0 forces RR constant by minimality of the degree). Otherwise α\alpha is transcendental. We write K(α)K(\alpha) for the smallest subfield of LL containing KK and α\alpha, and K[α]K[\alpha] for the smallest subring.

Theorem 4.4

If α\alpha is algebraic over KK with d=degπαd = \deg\pi_\alpha, then

K(α)=K[α]K[X]/(πα),[K(α):K]=d,K(\alpha) = K[\alpha] \cong K[X]/(\pi_\alpha), \qquad [K(\alpha) : K] = d,

with basis 1,α,,αd11, \alpha, \dots, \alpha^{d-1}. Conversely, if [L:K]<[L:K] < \infty, every αL\alpha \in L is algebraic of degree degπα\deg \pi_\alpha dividing [L:K][L:K].

Proof. Evaluation K[X]LK[X] \to L, PP(α)P \mapsto P(\alpha), has image K[α]K[\alpha] and kernel (πα)(\pi_\alpha); since πα\pi_\alpha is irreducible, K[X]/(πα)K[X]/(\pi_\alpha) is a field (Proposition 2.4: in the PID K[X]K[X], irreducible generates a maximal ideal), so K[α]K[\alpha] is a field containing KK and α\alpha: it equals K(α)K(\alpha). The classes of 1,X,,Xd11, X, \dots, X^{d-1} form a basis of the quotient (Euclidean division), whence the basis and the degree. Conversely if [L:K]=n<[L:K] = n < \infty: 1,α,,αn1, \alpha, \dots, \alpha^n are dependent, giving an annihilating polynomial; then [K(α):K]=degπα[K(\alpha):K] = \deg\pi_\alpha divides nn by the tower law.

Corollary 4.5

If α,β\alpha, \beta are algebraic over KK, so are α±β\alpha \pm \beta, αβ\alpha\beta, α/β\alpha/\beta (β0\beta \ne 0): the elements of LL algebraic over KK form a subfield of LL. Moreover algebraicity is transitive: algebraic over algebraic is algebraic.

Proof. K(α,β)=(K(α))(β)K(\alpha, \beta) = (K(\alpha))(\beta) is finite over K(α)K(\alpha) (β\beta algebraic over KK(α)K \subseteq K(\alpha)) and K(α)/KK(\alpha)/K is finite: by the tower law [K(α,β):K]<[K(\alpha,\beta):K] < \infty, and every element of K(α,β)K(\alpha, \beta) — including the four listed — is algebraic (Theorem 4.4). Transitivity: if β\beta is algebraic over LL and L/KL/K is algebraic, the coefficients c0,,cm1c_0, \dots, c_{m-1} of πβ/L\pi_{\beta/L} generate a finite extension F=K(c0,,cm1)F = K(c_0, \dots, c_{m-1}) of KK (repeated tower law), and F(β)/FF(\beta)/F is finite: [F(β):K]<[F(\beta):K] < \infty, so β\beta is algebraic over KK.

Example 4.6

[Q(2):Q]=2[\Q(\sqrt2):\Q] = 2, [Q(23):Q]=3[\Q(\sqrt[3]2):\Q] = 3 (X32X^3 - 2 is irreducible: Eisenstein), [Q(ζp):Q]=p1[\Q(\zeta_p):\Q] = p - 1 for ζp=e2iπ/p\zeta_p = \eu^{2\iu\pi/p} (Φp\Phi_p is irreducible, Example 2.26). The tower law is already a weapon: 23Q(2)\sqrt[3]2 \notin \Q(\sqrt2), since 323 \nmid 2.

4.2 Splitting fields; algebraic closure

Theorem 4.7 (Splitting fields)

Let PK[X]P \in K[X] be nonconstant. There exists a splitting field of PP over KK: an extension L=K(α1,,αn)L = K(\alpha_1, \dots, \alpha_n) generated by roots of PP in which PP splits into linear factors. It is unique up to KK-isomorphism, and [L:K](degP)![L:K] \leq (\deg P)!.

Proof. Existence, by induction on degP\deg P: pick an irreducible factor QQ of PP; the field K1=K[X]/(Q)K_1 = K[X]/(Q) contains the root α1=Xˉ\alpha_1 = \bar X of QQ, hence of PP; write P=(Xα1)P1P = (X - \alpha_1)P_1 over K1K_1 and apply induction to P1P_1 over K1K_1; degrees multiply to at most n(n1)=n!n(n-1)\cdots = n!.

Uniqueness follows from the stronger isomorphism extension lemma: let σ ⁣:KK\sigma \colon K \to K' be an isomorphism, PK[X]P \in K[X], PσP^\sigma the polynomial with mapped coefficients, L,LL, L' splitting fields of P,PσP, P^\sigma; then σ\sigma extends to an isomorphism LLL \to L'. Induction on [L:K][L:K]: if PP splits in KK, then L=KL = K, and L=KL' = K' (PσP^\sigma splits in KK', and LL' is generated by its roots). Otherwise choose a root αLK\alpha \in L \setminus K of an irreducible factor QQ of PP with degQ2\deg Q \geq 2; QσQ^\sigma is an irreducible factor of PσP^\sigma, with a root βL\beta \in L'; then

K(α)K[X]/(Q) σ K[X]/(Qσ)K(β)K(\alpha) \cong K[X]/(Q) \xrightarrow{\ \sigma\ } K'[X]/(Q^\sigma) \cong K'(\beta)

extends σ\sigma with αβ\alpha \mapsto \beta. Now LL is a splitting field of PP over K(α)K(\alpha), and LL' of PσP^\sigma over K(β)K'(\beta), with [L:K(α)]<[L:K][L : K(\alpha)] < [L:K]: induction extends further to LLL \to L'.

Definition 4.8

A field Ω\Omega is algebraically closed if every nonconstant polynomial of Ω[X]\Omega[X] has a root in Ω\Omega (hence splits). An algebraic closure of KK is an algebraic extension Kˉ/K\bar K/K with Kˉ\bar K algebraically closed.

Theorem 4.9 (Steinitz)

Every field KK has an algebraic closure, unique up to KK-isomorphism.

Proof. Existence (Artin’s construction). Let R=K[(Xf)f]R = K[(X_f)_f] be the polynomial ring with one variable XfX_f per nonconstant monic fK[X]f \in K[X], and II the ideal generated by all f(Xf)f(X_f). II is proper: a relation 1=i=1rgifi(Xfi)1 = \sum_{i=1}^r g_i\, f_i(X_{f_i}) involves finitely many polynomials; in a common splitting field EE of f1frf_1\cdots f_r pick roots αi\alpha_i of fif_i and evaluate XfiαiX_{f_i} \mapsto \alpha_i (other variables 0\mapsto 0): 1=01 = 0, absurd. Let mI\mathfrak m \supseteq I be maximal (Theorem 2.8; Zorn) and K1=R/mK_1 = R/\mathfrak m: a field extension of KK in which every nonconstant fK[X]f \in K[X] has a root, namely Xˉf\bar X_f, and which is algebraic over KK (it is generated by the Xˉf\bar X_f, each algebraic). Iterate: KK1K2K \subseteq K_1 \subseteq K_2 \subseteq \cdots, where Kn+1K_{n+1} does to KnK_n what K1K_1 did to KK, and let Ω=nKn\Omega = \bigcup_n K_n, a field. Any nonconstant gΩ[X]g \in \Omega[X] has its finitely many coefficients in some KnK_n; an irreducible factor of gg over KnK_n has a root in Kn+1ΩK_{n+1} \subseteq \Omega: Ω\Omega is algebraically closed, and algebraic over KK (each KnK_n is, by transitivity, Corollary 4.5): Ω\Omega is an algebraic closure.

Uniqueness. Let Ω,Ω\Omega, \Omega' be two algebraic closures. Consider the set of pairs (E,τ)(E, \tau) where KEΩK \subseteq E \subseteq \Omega and τ ⁣:EΩ\tau\colon E \to \Omega' is a KK-embedding, ordered by extension; it is nonempty ((K,id)(K, \mathrm{id})) and inductive (union of a chain), so Zorn gives a maximal (E0,τ0)(E_0, \tau_0). If E0ΩE_0 \neq \Omega, pick αΩE0\alpha \in \Omega\setminus E_0: πα/E0\pi_{\alpha/E_0} maps to a polynomial over τ0(E0)\tau_0(E_0) having a root β\beta in the algebraically closed Ω\Omega', and τ0\tau_0 extends to E0(α)ΩE_0(\alpha) \to \Omega' (αβ\alpha \mapsto \beta), contradicting maximality. So there is a KK-embedding τ ⁣:ΩΩ\tau \colon \Omega \to \Omega'; its image, isomorphic to Ω\Omega, is algebraically closed, and Ω\Omega' is algebraic over it: for xΩx \in \Omega', πx/τ(Ω)\pi_{x/\tau(\Omega)} splits over τ(Ω)\tau(\Omega), so xτ(Ω)x \in \tau(\Omega). Thus τ\tau is onto: an isomorphism.

Remark 4.10

For K=QK = \Q one may avoid the transfinite machinery: the algebraic numbers Qˉ={zC:z algebraic over Q}\bar\Q = \{z \in \C : z \text{ algebraic over } \Q\} form an algebraic closure — a subfield of C\C by Corollary 4.5, algebraically closed because C\C is (d’Alembert–Gauss, proved by complex analysis in Chapter 16) and roots of polynomials over Qˉ\bar\Q are algebraic over Q\Q by transitivity.

4.3 Finite fields

Theorem 4.11

Let pp be prime, n1n \geq 1, q=pnq = p^n.

  1. A finite field has cardinality a prime power, and for each qq there is exactly one field Fq\mathbb F_q with qq elements up to isomorphism: the splitting field of XqXX^q - X over Fp\mathbb F_p.
  2. The Frobenius F ⁣:xxpF \colon x \mapsto x^p is an automorphism of Fq\mathbb F_q, and the automorphism group of Fq\mathbb F_q is cyclic of order nn, generated by FF.
  3. Fpm\mathbb F_{p^m} embeds in Fpn\mathbb F_{p^n} iff mnm \mid n.

Proof. (1) A finite field EE has characteristic p>0p > 0 and is a finite-dimensional Fp\mathbb F_p-vector space: E=pn\abs E = p^n. Its multiplicative group has order q1q - 1, so every xEx \in E satisfies xq=xx^q = x: EE consists of qq roots of XqXX^q - X, hence is a splitting field of it over Fp\mathbb F_p — determining EE up to isomorphism (Theorem 4.7). Conversely, in a splitting field LL of XqXX^q - X, the set EE of its roots is a subfield: (x+y)q=xq+yq(x + y)^q = x^q + y^q by iterating the freshman’s dream (a+b)p=ap+bp(a+b)^p = a^p + b^p (p(pk)p \mid \binom pk), and (xy)q=xqyq(xy)^q = x^qy^q, (x1)q=(xq)1(x^{-1})^q = (x^q)^{-1}; it has exactly qq elements since XqXX^q - X is separable: its derivative is qXq11=1qX^{q-1} - 1 = -1 (as pqp \mid q), coprime to it, so no repeated roots. Thus L=EL = E has qq elements.

(2) FF is a field morphism (freshman’s dream), injective (fields), hence bijective on the finite Fq\mathbb F_q. Fn=idF^n = \mathrm{id} (xq=xx^q = x), and no smaller power is the identity: Fm=idF^m = \mathrm{id} means all qq elements are roots of XpmXX^{p^m} - X, forcing pmqp^m \geq q. So F\langle F\rangle is cyclic of order nn; and there are no other automorphisms, by the bound Aut[Fq:Fp]=n\abs{\operatorname{Aut}} \leq [\,\mathbb F_q : \mathbb F_p\,] = n proved below (Proposition 4.16 with L=FqL = \mathbb F_q, K=FpK = \mathbb F_p: automorphisms fix the prime field).

(3) If FpmFpn\mathbb F_{p^m} \subseteq \mathbb F_{p^n}, the tower law gives pn=(pm)dp^n = (p^m)^d: mnm \mid n. Conversely if mnm \mid n, then pm1pn1p^m - 1 \mid p^n - 1 (geometric sum), so XpmXX^{p^m} - X divides XpnXX^{p^n} - X (same argument on exponents: Xa1Xb1X^{a} - 1 \mid X^{b} - 1 when aba \mid b), and the roots of the former inside Fpn\mathbb F_{p^n} form the required subfield, of cardinality pmp^m (separability as in (1)).

Theorem 4.12 (Cyclicity)

Every finite subgroup of the multiplicative group of a field is cyclic. In particular Fq×Z/(q1)Z\mathbb F_q^\times \cong \Z/(q-1)\Z.

Proof. Let GK×G \leq K^\times be finite. By the structure theorem (Corollary 3.13), GZ/d1××Z/dsG \cong \Z/d_1 \times \dots \times \Z/d_s with d1dsd_1 \mid \dots \mid d_s. Every xGx \in G then satisfies xds=1x^{d_s} = 1; but Xds1X^{d_s} - 1 has at most dsd_s roots in the field KK: G=d1dsds\abs G = d_1\cdots d_s \leq d_s, forcing s=1s = 1: GG is cyclic.

Example 4.13

F8=F2[X]/(X3+X+1)\mathbb F_8 = \mathbb F_2[X]/(X^3 + X + 1): the cubic has no root in F2\mathbb F_2, hence is irreducible. Writing ω=Xˉ\omega = \bar X: F8×\mathbb F_8^\times is cyclic of order 77, so every element 0,1\neq 0, 1 generates. The subfields of Fp12\mathbb F_{p^{12}} form the divisor lattice of 1212: Fp,Fp2,Fp3,Fp4,Fp6,Fp12\mathbb F_p, \mathbb F_{p^2}, \mathbb F_{p^3}, \mathbb F_{p^4}, \mathbb F_{p^6}, \mathbb F_{p^{12}} — a first, complete instance of the Galois correspondence.

4.4 Separability and embeddings

Definition 4.14

A polynomial PK[X]P \in K[X] is separable if it has no repeated root in a splitting field — equivalently gcd(P,P)=1\gcd(P, P') = 1 (a repeated root is a common root; conversely, over the splitting field, a common root is repeated; and the gcd does not change under field extension, Corollary 3.17’s argument). An algebraic element is separable if its minimal polynomial is; an extension L/KL/K is separable if all its elements are.

Proposition 4.15

An irreducible PK[X]P \in K[X] is separable unless P=0P' = 0, which forces charK=p>0\operatorname{char} K = p > 0 and PK[Xp]P \in K[X^p]. Consequently every algebraic extension of a field of characteristic 00, and of a finite field, is separable (such fields are called perfect).

Proof. gcd(P,P)\gcd(P, P') divides PP; if it is not 11, irreducibility forces gcd=P\gcd = P (up to a constant), so PPP \mid P' with degP<degP\deg P' < \deg P: P=0P' = 0. Writing P=akXkP = \sum a_kX^k: kak=0ka_k = 0 for all kk, so in characteristic 00, PP is constant (excluded); in characteristic pp, ak=0a_k = 0 unless pkp \mid k: P=Q(Xp)P = Q(X^p). Over a finite field, every element is a pp-th power (Frobenius is onto), so Q(Xp)=bkpXpk=(bkXk)pQ(X^p) = \sum b_k^p X^{pk} = (\sum b_kX^k)^p is not irreducible: P=0P' = 0 cannot happen for irreducible PP there either.

Proposition 4.16 (Counting embeddings)

Let L=K(α1,,αr)L = K(\alpha_1, \dots, \alpha_r) be finite over KK, and σ ⁣:KΩ\sigma \colon K \to \Omega an embedding into an algebraically closed field. Then the number of extensions of σ\sigma to LL is at most [L:K][L:K], with equality if L/KL/K is separable. In particular AutK(L)[L:K]\abs{\operatorname{Aut}_K(L)} \leq [L:K].

Proof. Induction on [L:K][L:K] via simple steps. For L=K(α)L = K(\alpha): an extension τ\tau is determined by τ(α)\tau(\alpha), which must be a root in Ω\Omega of πασ\pi_\alpha^\sigma; conversely each such root gives one extension (K(α)K[X]/(πα)K(\alpha) \cong K[X]/(\pi_\alpha)). The number of extensions is the number of distinct roots of πασ\pi_\alpha^\sigma in Ω\Omega: at most degπα=[K(α):K]\deg\pi_\alpha = [K(\alpha):K], with equality iff πα\pi_\alpha is separable (separability of πσ\pi^\sigma and π\pi agree: gcd with the derivative is preserved by σ\sigma). In general, factor L=K(α1)(α2,)L = K(\alpha_1)(\alpha_2, \dots): extensions of σ\sigma to K(α1)K(\alpha_1) number [K(α1):K]\leq [K(\alpha_1):K], and each extends in [L:K(α1)]\leq [L : K(\alpha_1)] ways by induction; multiply (tower law). In the separable case both counts are equalities: minimal polynomials over the bigger field K(α1)K(\alpha_1) divide those over KK, hence remain separable.

Theorem 4.17 (Primitive element)

Every finite separable extension is simple: L=K(γ)L = K(\gamma) for some γ\gamma.

Proof. If KK is finite, so is LL, and a generator γ\gamma of the cyclic group L×L^\times (Theorem 4.12) does it. Let KK be infinite; by induction it suffices to treat L=K(α,β)L = K(\alpha, \beta). Let n=[L:K]n = [L:K]; by Proposition 4.16 there are nn distinct KK-embeddings σ1,,σn ⁣:LΩ\sigma_1, \dots, \sigma_n \colon L \to \Omega (Ω\Omega an algebraic closure). The polynomial

D(T)=i<j[(σi(α)σj(α))+T(σi(β)σj(β))]D(T)=\prod_{i<j}\bigl[\bigl(\sigma_i(\alpha)-\sigma_j(\alpha) \bigr) + T\bigl(\sigma_i(\beta) - \sigma_j(\beta)\bigr)\bigr]

is not identically zero: a factor vanishes identically only if σi,σj\sigma_i, \sigma_j agree on both α\alpha and β\beta, hence on LL — excluded for iji \neq j. As KK is infinite, pick cKc \in K with D(c)0D(c) \ne 0: then the nn elements σi(α+cβ)\sigma_i(\alpha + c\beta) are pairwise distinct, so γ=α+cβ\gamma = \alpha + c\beta has at least nn distinct conjugates in Ω\Omega, i.e. degπγn\deg \pi_\gamma \geq n: [K(γ):K]n=[L:K][K(\gamma):K] \geq n = [L:K] forces L=K(γ)L = K(\gamma).

4.5 The Galois correspondence

Definition 4.18

A finite extension L/KL/K is Galois if it is the splitting field of a separable polynomial over KK. Its Galois group is Gal(L/K)=AutK(L)\operatorname{Gal}(L/K) = \operatorname{Aut}_K(L), the group of field automorphisms of LL fixing KK pointwise.

Proposition 4.19

If L/KL/K is Galois, then Gal(L/K)=[L:K]\abs{\operatorname{Gal}(L/K)} = [L:K]; moreover L/FL/F is Galois for every intermediate field KFLK \subseteq F \subseteq L, and every FF-embedding LΩLL \to \Omega \supseteq L has image LL (normality).

Proof. Let LL split the separable PP over KK, and fix an algebraic closure ΩL\Omega \supseteq L. L/KL/K is separable: it is generated by roots of PP; separability of every element follows from the equality case below, but let us argue directly — Proposition 4.16 applied to the generators (roots of the separable PP, whose minimal polynomials divide PP) yields exactly [L:K][L:K] extensions of KΩK \hookrightarrow \Omega (in the inductive step, the minimal polynomial of a root of PP over an intermediate field still divides PP, hence is separable). Each such embedding τ ⁣:LΩ\tau \colon L \to \Omega permutes the roots of PP (τ\tau fixes the coefficients), and LL is generated by them: τ(L)=L\tau(L) = L. Hence embeddings == automorphisms: Gal(L/K)=[L:K]\abs{\operatorname{Gal}(L/K)} = [L:K]. For intermediate FF: LL is also the splitting field of PP over FF, and PP remains separable: L/FL/F is Galois; the same argument gives normality over FF.

Lemma 4.20 (Artin)

Let GG be a finite group of automorphisms of a field LL and K=LG={x:σ(x)=x σG}K = L^G = \{x : \sigma(x) = x\ \forall\sigma \in G\} its fixed field. Then [L:LG]G[L : L^G] \leq \abs G.

Proof. Let n=Gn = \abs G, G={σ1,,σn}G = \{\sigma_1, \dots, \sigma_n\}, and suppose x1,,xn+1Lx_1, \dots, x_{n+1} \in L are linearly independent over KK. The homogeneous linear system of nn equations in n+1n+1 unknowns (cj)(c_j) over LL,

j=1n+1cjσi(xj)=0(i=1,,n),\sum_{j=1}^{n+1} c_j\,\sigma_i(x_j) = 0 \qquad (i = 1, \dots, n),

has a nonzero solution; choose one with the fewest nonzero entries, say c1,,cr0c_1, \dots, c_r \neq 0 (renumbering), r2r \geq 2 (a single cjσi(xj)=0c_j\sigma_i(x_j) = 0 is impossible), normalized cr=1c_r = 1. Not all cjc_j lie in KK: the equation for σi=id\sigma_i = \mathrm{id} would contradict independence; say c1Kc_1 \notin K, so τ(c1)c1\tau(c_1) \ne c_1 for some τG\tau \in G. Apply τ\tau to all equations: since τσi\tau\sigma_i runs over GG, the vector (τ(cj))j(\tau(c_j))_j is another solution; subtracting, (cjτ(cj))j(c_j - \tau(c_j))_j is a solution with fewer nonzero entries (the rr-th entry 11=01 - 1 = 0 vanishes, the first does not) and not zero: contradiction. So any n+1n+1 elements are dependent: [L:K]n[L:K] \leq n.

Theorem 4.21 (Fundamental theorem of Galois theory)

Let L/KL/K be a Galois extension with group G=Gal(L/K)G = \operatorname{Gal}(L/K).

  1. LG=KL^G = K.
  2. The maps HLHH \mapsto L^H and FGal(L/F)F \mapsto \operatorname{Gal}(L/F) are mutually inverse, inclusion-reversing bijections between subgroups of GG and intermediate fields KFLK \subseteq F \subseteq L; moreover [L:LH]=H[L : L^H] = \abs H and [LH:K]=[G:H][L^H : K] = [G : H].
  3. HGH \trianglelefteq G iff LH/KL^H/K is Galois, and then restriction induces Gal(LH/K)G/H\operatorname{Gal}(L^H/K) \cong G/H.

Proof. (1) Clearly KLGK \subseteq L^G. Conversely let αLK\alpha \in L \setminus K; we exhibit σG\sigma \in G with σ(α)α\sigma(\alpha) \ne \alpha. The minimal polynomial πα\pi_\alpha over KK has degree 2\geq 2 and is separable (L/KL/K separable, Proposition 4.19), so it has another root βα\beta \neq \alpha in an algebraic closure ΩL\Omega \supseteq L. Extend the KK-embedding K(α)ΩK(\alpha) \to \Omega, αβ\alpha \mapsto \beta, to an embedding τ ⁣:LΩ\tau\colon L \to \Omega (Proposition 4.16); by normality (Proposition 4.19) τ(L)=L\tau(L) = L, so τG\tau \in G, β=τ(α)L\beta = \tau(\alpha) \in L, and τ(α)α\tau(\alpha) \neq \alpha.

(2) For a subgroup HH: L/LHL/L^H is Galois (Proposition 4.19), and Gal(L/LH)H\operatorname{Gal}(L/L^H) \supseteq H trivially, so [L:LH]=Gal(L/LH)H[L:L^H] = \abs{\operatorname{Gal}(L/L^H)} \geq \abs H; Artin’s lemma gives [L:LH]H[L:L^H] \leq \abs H: equality, and Gal(L/LH)=H\operatorname{Gal}(L/L^H) = H. For an intermediate field FF: L/FL/F Galois gives LGal(L/F)=FL^{\operatorname{Gal}(L/F)} = F by (1) applied to L/FL/F. The two maps are mutually inverse; they reverse inclusions evidently. Degrees: [L:LH]=H[L:L^H] = \abs H just proved, and [LH:K]=[L:K]/[L:LH]=G/H[L^H:K] = [L:K]/[L:L^H] = \abs G/\abs H.

(3) For σG\sigma \in G and HGH \leq G: σ(LH)=LσHσ1\sigma(L^H) = L^{\sigma H\sigma^{-1}} (direct check). By the bijection, σ(LH)=LH\sigma(L^H) = L^H for all σ\sigma iff HGH \trianglelefteq G. Now if HGH \trianglelefteq G, set F=LHF = L^H: every σG\sigma \in G restricts to an automorphism of FF, giving a morphism ρ ⁣:GAutK(F)\rho \colon G \to \operatorname{Aut}_K(F) with kernel {σ:σF=id}=Gal(L/F)=H\{\sigma : \sigma\restriction_F = \mathrm{id}\} = \operatorname{Gal}(L/F) = H. So G/HG/H embeds in AutK(F)\operatorname{Aut}_K(F), whence AutK(F)[G:H]=[F:K]\abs{\operatorname{Aut}_K(F)} \geq [G:H] = [F:K]; the reverse inequality always holds (Proposition 4.16): AutK(F)=[F:K]\abs{\operatorname{Aut}_K(F)} = [F:K] and ρ\rho is onto. It remains to see F/KF/K is Galois: FF is separable over KK (inside the separable L/KL/K), and F=K(γ)F = K(\gamma) (Theorem 4.17); the polynomial σG/H(Xσ(γ))\prod_{\sigma \in G/H}\bigl(X - \sigma(\gamma)\bigr) (product over the distinct images, which lie in FF: σ(F)=LσHσ1=LH=F\sigma(F) = L^{\sigma H\sigma^{-1}} = L^H = F by normality of HH) has coefficients fixed by GG, hence in KK by (1): it is a separable polynomial of K[X]K[X] split by FF, and its roots generate FF: F/KF/K is Galois. Conversely, if F=LHF = L^H with F/KF/K Galois, normality of FF (Proposition 4.19, applied to embeddings FΩF \to \Omega restricted from elements of GG) gives σ(F)=F\sigma(F) = F for all σG\sigma \in G, i.e. HGH \trianglelefteq G.

The Galois correspondence for the splitting field L of X3 - 2 over ℚ (j = 2 π/3): subgroups of Gal(L/ℚ) S_3 (left, order reversed) match intermediate fields (right). The unique normal proper subgroup (1\,2\,3) corresponds to the unique subextension ℚ( √3)/ℚ that is Galois; the three conjugate subgroups (i\,j) correspond to the three conjugate cubic fields ℚ(jk√[3]2), none of them normal over ℚ.
The Galois correspondence for the splitting field LL of X32X^3 - 2 over Q\Q (j=e2iπ/3j = \eu^{2\iu\pi/3}): subgroups of Gal(L/Q)S3\operatorname{Gal}(L/\Q) \cong S_3 (left, order reversed) match intermediate fields (right). The unique normal proper subgroup (123)\langle(1\,2\,3)\rangle corresponds to the unique subextension Q(i3)/Q\Q(\iu\sqrt3)/\Q that is Galois; the three conjugate subgroups (ij)\langle(i\,j)\rangle correspond to the three conjugate cubic fields Q(jk23)\Q(j^k\sqrt[3]2), none of them normal over Q\Q.

4.6 Cyclotomic extensions

Definition 4.22

Let n1n \geq 1 and ζn=e2iπ/n\zeta_n = \eu^{2\iu\pi/n}. The nn-th cyclotomic polynomial is Φn=gcd(k,n)=1, 1kn(Xζnk)\Phi_n = \prod_{\gcd(k,n)=1,\ 1 \le k \le n} \bigl(X - \zeta_n^k\bigr), of degree φ(n)\varphi(n); grouping the roots of Xn1X^n - 1 by exact order, Xn1=dnΦdX^n - 1 = \prod_{d \mid n}\Phi_d, which shows inductively that ΦnZ[X]\Phi_n \in \Z[X] (Euclidean division of monic integer polynomials).

Theorem 4.23

Φn\Phi_n is irreducible over Q\Q; hence [Q(ζn):Q]=φ(n)[\Q(\zeta_n) : \Q] = \varphi(n) and

Gal(Q(ζn)/Q)    (Z/nZ)×,σa(ζn)=ζna.\operatorname{Gal}\bigl(\Q(\zeta_n)/\Q\bigr) \;\cong\; (\Z/n\Z)^\times, \qquad \sigma_a(\zeta_n) = \zeta_n^a .

The extension Q(ζn)/Q\Q(\zeta_n)/\Q is thus Galois with abelian group.

Proof. Let f=πζnf = \pi_{\zeta_n}, so Φn=fg\Phi_n = fg with f,gZ[X]f, g \in \Z[X] monic (Gauss’s lemma Lemma 2.23: contents multiply, all polynomials monic). Claim: if ζ\zeta is a root of ff and pnp \nmid n is prime, then ζp\zeta^p is a root of ff. Otherwise ζp\zeta^p is a root of gg (it is a primitive nn-th root of unity), so ζ\zeta is a root of g(Xp)g(X^p), and fg(Xp)f \mid g(X^p) in Z[X]\Z[X] (minimal polynomial, then Gauss again). Reduce mod pp: gˉ(Xp)=gˉ(X)p\bar g(X^p) = \bar g(X)^p (Frobenius on Fp[X]\mathbb F_p[X]: coefficientwise ap=aa^p = a, and freshman’s dream), so fˉgˉp\bar f \mid \bar g^{\,p}: fˉ\bar f and gˉ\bar g share an irreducible factor, and Φˉn=fˉgˉ\bar\Phi_n = \bar f\bar g has a repeated factor. Then so does Xn1ˉX^n - \bar 1; but its derivative nˉXn1\bar nX^{n-1} is coprime to it (pnp \nmid n, and 00 is not a root): contradiction.

Every primitive root ζnk\zeta_n^k (gcd(k,n)=1\gcd(k, n) = 1) is obtained from ζn\zeta_n by successive prime powers not dividing nn (factor kk): the claim propagates, so every primitive root is a root of ff: f=Φnf = \Phi_n, irreducible. Consequently [Q(ζn):Q]=φ(n)[\Q(\zeta_n):\Q] = \varphi(n), and Q(ζn)\Q(\zeta_n) is the splitting field of the separable Xn1X^n - 1 (all roots are powers of ζn\zeta_n): Galois. An automorphism σ\sigma sends ζn\zeta_n to another primitive root ζna(σ)\zeta_n^{a(\sigma)}, and σa(σ)\sigma \mapsto a(\sigma) is an injective morphism into (Z/nZ)×(\Z/n\Z)^\times; both groups have order φ(n)\varphi(n): isomorphism.

4.7 Ruler and compass

Definition 4.24

Identify the plane with C\C; start from {0,1}\{0, 1\}. A point is constructible if it is obtainable by finitely many intersections of lines through two already-constructed points and circles centered at a constructed point with radius a distance of two constructed points.

Theorem 4.25 (Wantzel)

zCz \in \C is constructible iff there is a tower Q=F0F1Fr\Q = F_0 \subseteq F_1 \subseteq \dots \subseteq F_r with [Fi+1:Fi]=2[F_{i+1} : F_i] = 2 and zFrz \in F_r. In particular, a constructible number is algebraic of degree a power of 22 over Q\Q.

Proof. (\Rightarrow) The coordinates of the intersection of two lines through points with coordinates in a subfield FRF \subseteq \R solve a linear system over FF: they stay in FF. Line–circle and circle–circle intersections lead, after eliminating the linear part (subtracting the two circle equations gives a line), to a quadratic equation over FF: the new coordinates lie in FF or in F(d)F(\sqrt d) for some dFd \in F, d>0d > 0. By induction, every constructed point has coordinates in a tower of quadratic extensions of Q\Q; and z=x+iyz = x + \iu y is in a quadratic tower too (adjoin i\iu: one more quadratic step). The degree consequence: [Q(z):Q][\Q(z):\Q] divides [Fr:Q]=2r[F_r : \Q] = 2^r (tower law).

(\Leftarrow) The constructible numbers form a field: sums and differences by parallelograms (parallels are constructible: drop and raise perpendiculars twice — the classical perpendicular through a point uses one circle and two arcs); products and quotients by Thales’ intercept configurations (given lengths a,ba, b construct abab and a/ba/b with similar triangles on two rays). And the field is closed under square roots: for a>0a > 0, the circle of diameter 1+a1 + a and the perpendicular at the junction point meet at height a\sqrt a (altitude-geometric-mean relation in a right triangle); for a complex w=ρeiθw = \rho\eu^{\iu\theta}, construct ρ\sqrt\rho and bisect θ\theta (angle bisection is a compass construction). Real and imaginary parts of members of a quadratic tower are therefore constructible by induction on the tower: each step adjoins roots of a quadratic, expressible by field operations and one square root of an already-constructed number (the quadratic formula; in characteristic 00).

Corollary 4.26

The three classical problems are unsolvable by ruler and compass:

  1. Duplication of the cube: 23\sqrt[3]2 has degree 33, not a power of 22.
  2. Trisection of the angle: trisecting 6060^\circ requires cos20\cos 20^\circ, a root of the irreducible 8X36X18X^3 - 6X - 1: degree 33.
  3. Squaring the circle: π\sqrt\pi is transcendental (π\pi is — Lindemann’s theorem, admitted here: its proof belongs to a course in transcendence theory).

Also, the regular nn-gon is constructible iff φ(n)\varphi(n) is a power of 22 (Gauss–Wantzel; the “if” uses the weekend problem’s method, the “only if” is Theorem 4.25 applied to ζn\zeta_n, of degree φ(n)\varphi(n)). For n=7n = 7: φ(7)=6\varphi(7) = 6: the regular heptagon is impossible; for n=17n = 17: φ(17)=16=24\varphi(17) = 16 = 2^4: constructible — the weekend problem constructs it.

Proof. (1) X32X^3 - 2 is irreducible (Eisenstein). (2) From cos3θ=4cos3θ3cosθ\cos 3\theta = 4\cos^3\theta - 3\cos\theta with 3θ=603\theta = 60^\circ: 8c36c=18c^3 - 6c = 1 for c=cos20c = \cos 20^\circ; the cubic 8X36X18X^3 - 6X - 1 has no rational root (candidates ±1,±12,±14,±18\pm1, \pm\frac 12, \pm\frac14, \pm\frac18 fail), hence is irreducible: degree 33. A general 6060^\circ angle is constructible, so a trisector would construct cc. (3) If π\sqrt\pi were constructible it would be algebraic, hence also π\pi. The nn-gon statement: the degree of ζn\zeta_n is φ(n)\varphi(n) (Theorem 4.23); necessity follows from Wantzel; for sufficiency, the Galois group, abelian of order 2m2^m, admits a chain of index-22 subgroups (a finite 22-group does: Exercise 1.10), whose fixed fields form a quadratic tower ending at Q(ζn)\Q(\zeta_n) (Theorem 4.21); conclude by Theorem 4.25.

4.8 Solvability by radicals

Definition 4.27

An extension L/KL/K (characteristic 00 throughout this section) is radical if there is a tower K=F0Fr=LK = F_0 \subseteq \dots \subseteq F_r = L with Fi+1=Fi(αi)F_{i+1} = F_i(\alpha_i), αiniFi\alpha_i^{n_i} \in F_i: each step adjoins an nin_i-th root. A polynomial PK[X]P \in K[X] is solvable by radicals if its splitting field is contained in some radical extension of KK.

Lemma 4.28

Let KK contain a primitive nn-th root of unity ζ\zeta, i.e. ζ\zeta of order nn in K×K^\times, and aK×a \in K^\times. Then K(an)/KK(\sqrt[n]a)/K is Galois with cyclic group. Conversely — not needed below — every cyclic extension of degree nn is of this form. Moreover K(ζn)/KK(\zeta_n)/K is Galois with abelian group, for any KK of characteristic 00.

Proof. XnaX^n - a is separable (gcd\gcd with nXn1nX^{n-1}: a0a \neq 0) and splits in K(α)K(\alpha), αn=a\alpha^n = a: its roots are the ζkαK(α)\zeta^k\alpha \in K(\alpha). So K(α)/KK(\alpha)/K is Galois; the map σσ(α)/αμn=ζ\sigma \mapsto \sigma(\alpha)/\alpha \in \mu_n = \langle \zeta\rangle is an injective morphism (στ(α)=σ(τ(α)/αα)=τ(α)/ασ(α)\sigma\tau(\alpha) = \sigma(\tau(\alpha)/\alpha \cdot \alpha) = \tau(\alpha)/\alpha\cdot\sigma(\alpha), the quotient being in KK), into a cyclic group: Gal\operatorname{Gal} is cyclic. The converse is Kummer theory, which we shall not need (see the remark below). For K(ζn)K(\zeta_n): it splits the separable Xn1X^n - 1, and σa(σ)\sigma \mapsto a(\sigma) with σ(ζn)=ζna(σ)\sigma(\zeta_n) = \zeta_n^{a(\sigma)} embeds the group in the abelian (Z/nZ)×(\Z/n\Z)^\times as in Theorem 4.23 (injectivity only needs ζn\zeta_n to generate the roots of unity involved).

Theorem 4.29 (Galois)

Let KK be of characteristic 00 and PK[X]P \in K[X] with splitting field LL. If PP is solvable by radicals, then Gal(L/K)\operatorname{Gal}(L/K) is a solvable group. (The converse is also true; we shall not need it.)

Proof. Step 1: enlarge the radical tower to a Galois one. Let LML \subseteq M with M/KM/K radical, with root exponents n1,,nrn_1, \dots, n_r and n=n1nrn = n_1\cdots n_r. First adjoin ζn\zeta_n: the tower KK(ζn)M(ζn)K \subseteq K(\zeta_n) \subseteq M(\zeta_n) is still radical (ζn\zeta_n is a root of unity: a radical step, ζnn=1\zeta_n^n = 1), and its steps beyond the first happen over fields containing the needed roots of unity. Next, replace M(ζn)M(\zeta_n) by the composite NN of all σ(M(ζn))\sigma(M(\zeta_n)), σ\sigma ranging over the (finitely many) KK-embeddings of M(ζn)M(\zeta_n) into a fixed algebraic closure: NN is the splitting field of the product of minimal polynomials of a generating set (characteristic 00: finite and separable), hence N/KN/K is Galois; and NN is radical over KK: each σ(M(ζn))\sigma(M(\zeta_n)) is radical over KK (apply σ\sigma to a radical tower), and a composite of radical extensions is radical (concatenate the towers: if F/KF'/K is radical with tower adjoining βj\beta_j, then F(βj)F''(\beta_j)-type steps remain radical over any bigger base).

Step 2: read solvability off the Galois tower. So assume LNL \subseteq N, N/KN/K Galois and radical with tower KK(ζn)=E0E1Es=NK \subseteq K(\zeta_n) = E_0 \subseteq E_1 \subseteq \dots \subseteq E_s = N, each Ei+1=Ei(aini)E_{i+1} = E_i(\sqrt[n_i]{a_i}) with ζniE0Ei\zeta_{n_i} \in E_0 \subseteq E_i. Let G=Gal(N/K)G = \operatorname{Gal}(N/K) and Gi=Gal(N/Ei)G_i = \operatorname{Gal}(N/E_i): a decreasing chain GG0G1Gs={e}G \supseteq G_0 \supseteq G_1 \supseteq \dots \supseteq G_s = \{e\}. Each Ei+1/EiE_{i+1}/E_i is Galois with cyclic group (Lemma 4.28), so by the fundamental theorem applied to the Galois extension N/EiN/E_i (Theorem 4.21(3), with ambient group GiG_i): Gi+1GiG_{i+1} \trianglelefteq G_i with Gi/Gi+1Gal(Ei+1/Ei)G_i/G_{i+1} \cong \operatorname{Gal}(E_{i+1}/E_i) cyclic. Similarly E0/KE_0/K is Galois with abelian group G/G0G/G_0 (Lemma 4.28). The chain exhibits GG as solvable (Proposition 1.29). Finally Gal(L/K)\operatorname{Gal}(L/K) is a quotient of GG: L/KL/K is Galois (PP separable in characteristic 00) and restriction GGal(L/K)G \to \operatorname{Gal}(L/K) is onto (Theorem 4.21(3) with H=Gal(N/L)H = \operatorname{Gal}(N/L)); quotients of solvable groups are solvable.

Corollary 4.30 (Unsolvability of the quintic)

There are polynomials of degree 55 over Q\Q that are not solvable by radicals: for instance X54X+2X^5 - 4X + 2, whose Galois group is S5S_5 (Exercise 4.11), a non-solvable group (Corollary 1.34). No general formula in radicals can exist for degree 5\geq 5.

Remark 4.31

The converse of Theorem 4.29 — a solvable Galois group implies solvability by radicals — is proved by descending the derived series and showing every cyclic extension (with enough roots of unity) is radical, via Lagrange resolvents; it explains why degrees 2,3,42, 3, 4 have formulas: S2,S3,S4S_2, S_3, S_4 are solvable (Example 1.30). We leave it admitted at this level; a full treatment belongs to a master’s course, but Exercise 4.8 makes it concrete for the cubic.

4.9 Exercises

Exercise 4.1

Show [Q(2,3):Q]=4[\Q(\sqrt2, \sqrt3):\Q] = 4, that Q(2+3)=Q(2,3)\Q(\sqrt2 + \sqrt3) = \Q(\sqrt2, \sqrt3), and compute the minimal polynomial of 2+3\sqrt2 + \sqrt3 over Q\Q.

Solution

Solution of Exercise 4.1.

3Q(2)\sqrt3 \notin \Q(\sqrt2): from 3=a+b2\sqrt3 = a + b\sqrt2 (a,bQa, b \in \Q), squaring gives 3=a2+2b2+2ab23 = a^2 + 2b^2 + 2ab\sqrt2, so ab=0ab = 0; b=0b = 0 makes 3\sqrt3 rational, a=0a = 0 gives 6=2bQ\sqrt6 = 2b \in \Q — both false (standard prime-factorization arguments). Hence [Q(2,3):Q(2)]=2[\Q(\sqrt2,\sqrt3) : \Q(\sqrt2)] = 2 and the tower law gives degree 44.

Let γ=2+3\gamma = \sqrt2 + \sqrt3. Then γ2=5+26\gamma^2 = 5 + 2\sqrt6 and (γ25)2=24(\gamma^2 - 5)^2 = 24: γ\gamma annihilates X410X2+1X^4 - 10X^2 + 1. Moreover γ3=112+93\gamma^3 = 11\sqrt2 + 9\sqrt3, so γ39γ=22\gamma^3 - 9\gamma = 2\sqrt2: 2Q(γ)\sqrt2 \in \Q(\gamma), then 3=γ2Q(γ)\sqrt3 = \gamma - \sqrt2 \in \Q(\gamma): Q(γ)=Q(2,3)\Q(\gamma) = \Q(\sqrt2,\sqrt3), of degree 44. The annihilating quartic, having the degree of the minimal polynomial, is the minimal polynomial: X410X2+1X^4 - 10X^2 + 1 (in particular it is irreducible over Q\Q).

Exercise 4.2

Let α=23\alpha = \sqrt[3]2. Show that Q(α)/Q\Q(\alpha)/\Q is not normal (exhibit an embedding Q(α)C\Q(\alpha) \to \C whose image is not Q(α)\Q(\alpha)), determine the splitting field LL of X32X^3 - 2 and [L:Q][L:\Q], and check AutQ(Q(α))={id}\operatorname{Aut}_\Q(\Q(\alpha)) = \{\mathrm{id}\}: for non-Galois extensions, the automorphism group can be far smaller than the degree.

Solution

Solution of Exercise 4.2.

The three roots of X32X^3 - 2 in C\C are α,jα,j2α\alpha, j\alpha, j^2\alpha with j=e2iπ/3j = \eu^{2\iu\pi/3}. The map αjα\alpha \mapsto j\alpha defines a Q\Q-embedding Q(α)C\Q(\alpha) \to \C (Theorem 4.4: both generate degree-33 extensions with the same minimal polynomial), whose image Q(jα)⊈R\Q(j\alpha) \not\subseteq \R differs from Q(α)R\Q(\alpha) \subseteq \R: Q(α)/Q\Q(\alpha)/\Q is not normal. The splitting field is L=Q(α,j)L = \Q(\alpha, j), with [L:Q]=[L:Q(α)][Q(α):Q]=23=6[L:\Q] = [L:\Q(\alpha)]\,[\Q(\alpha):\Q] = 2 \cdot 3 = 6 (jj satisfies X2+X+1X^2 + X + 1, irreducible over the real field Q(α)\Q(\alpha)). An automorphism of Q(α)\Q(\alpha) must send α\alpha to a root of X32X^3 - 2 inside Q(α)R\Q(\alpha) \subseteq \R: only α\alpha qualifies, so AutQ(Q(α))={id}\operatorname{Aut}_\Q(\Q(\alpha)) = \{\mathrm{id}\}, of order 1<31 < 3.

Exercise 4.3

Construct F9\mathbb F_9 as F3[X]/(X2+1)\mathbb F_3[X]/(X^2+1) and find a generator of F9×\mathbb F_9^\times. List the monic irreducible polynomials of degrees 1,2,31, 2, 3 over F2\mathbb F_2, and verify X8X=X(X+1)(X3+X+1)(X3+X2+1)X^8 - X = X(X+1)(X^3+X+1)(X^3+X^2+1) over F2\mathbb F_2.

Solution

Solution of Exercise 4.3.

X2+1X^2 + 1 has no root in F3\mathbb F_3 (0,1,21,2,20, 1, 2 \mapsto 1, 2, 2), so F9=F3[X]/(X2+1)\mathbb F_9 = \mathbb F_3[X]/(X^2+1) is a field with 99 elements; write ω=Xˉ\omega = \bar X, ω2=1\omega^2 = -1. The group F9×\mathbb F_9^\times is cyclic of order 88; ω\omega has order 44, but 1+ω1 + \omega works: (1+ω)2=1+2ω+ω2=2ω(1+\omega)^2 = 1 + 2\omega + \omega^2 = 2\omega, (1+ω)4=4ω2=ω2=11(1+\omega)^4 = 4\omega^2 = \omega^2 = -1 \ne 1: order 88.

Over F2\mathbb F_2degree 11: XX, X+1X + 1; degree 22: X2+X+1X^2 + X + 1 (the other three quadratics have roots); degree 33: X3+X+1X^3 + X + 1 and X3+X2+1X^3 + X^2 + 1 (no roots in F2\mathbb F_2; the other six cubics have roots). Verification:

(X3+X+1)(X3+X2+1)=X6+X5+X4+X3+X2+X+1,(X^3{+}X{+}1)(X^3{+}X^2{+}1) = X^6 + X^5 + X^4 + X^3 + X^2 + X + 1,

and X(X+1)(X6++1)=X(X7+1)=X8+X=X8XX(X{+}1)(X^6 + \dots + 1) = X(X^7 + 1) = X^8 + X = X^8 - X over F2\mathbb F_2 — exactly the irreducibles of degree dividing 33, as Exercise 4.6 predicts (degree 22 is absent: 232 \nmid 3).

Exercise 4.4 ★★

(a) Find all primitive roots modulo 77 and modulo 1111 (i.e. generators of F7×\mathbb F_7^\times, F11×\mathbb F_{11}^\times). (b) Show that for pp odd, xFp×x \in \mathbb F_p^\times is a square iff x(p1)/2=1x^{(p-1)/2} = 1 (Euler’s criterion), and recover the criterion for 1-1 of Problem 2.1.

Solution

Solution of Exercise 4.4.

(a) Mod 77: the powers of 33 are 3,2,6,4,5,13, 2, 6, 4, 5, 1: order 66, a generator; the primitive roots are the 3k3^k with gcd(k,6)=1\gcd(k, 6) = 1: 33 and 35=53^5 = 5. Mod 1111: powers of 22: 2,4,8,5,10,9,7,3,6,12, 4, 8, 5, 10, 9, 7, 3, 6, 1: a generator; primitive roots 2k2^k, gcd(k,10)=1\gcd(k, 10) = 1: 2,23=8,27=7,29=62, 2^3 = 8, 2^7 = 7, 2^9 = 6.

(b) Write x=gkx = g^k with gg a generator (Theorem 4.12). Then xx is a square iff kk is even (squares are the g2lg^{2l}, and g2l=gkg^{2l} = g^{k} iff k2lmodp1k \equiv 2l \bmod p-1, solvable iff kk even, p1p - 1 being even). And x(p1)/2=gk(p1)/2=1x^{(p-1)/2} = g^{k(p-1)/2} = 1 iff (p1)kp12(p-1) \mid k\frac{p-1}2 iff kk even: the two conditions agree. For x=1=g(p1)/2x = -1 = g^{(p-1)/2}: it is a square iff p12\frac{p-1}2 is even, iff p1(mod4)p \equiv 1 \pmod 4Problem 2.1 again.

Exercise 4.5 ★★

Show that FpmFpn=Fpgcd(m,n)\mathbb F_{p^m} \cap \mathbb F_{p^n} = \mathbb F_{p^{\gcd(m,n)}} and FpmFpn=Fplcm(m,n)\mathbb F_{p^m}\mathbb F_{p^n} = \mathbb F_{p^{\operatorname{lcm}(m,n)}} inside a fixed algebraic closure Fˉp\bar{\mathbb F}_p, and describe Gal(Fpn/Fpm)\operatorname{Gal}(\mathbb F_{p^n}/\mathbb F_{p^m}) for mnm \mid n.

Solution

Solution of Exercise 4.5.

Inside Fˉp\bar{\mathbb F}_p, Fpk={x:xpk=x}\mathbb F_{p^k} = \{x : x^{p^k} = x\} is the fixed set of FkF^k. The intersection FpmFpn\mathbb F_{p^m} \cap \mathbb F_{p^n} is fixed by FmF^m and FnF^n, hence by Fgcd(m,n)F^{\gcd(m,n)} (gcd=am+bn\gcd = am + bn: on a fixed element, Fam+bn=(Fm)a(Fn)bF^{am + bn} = (F^m)^a(F^n)^b acts trivially — exponents may be taken positive by periodicity); so it lies in Fpgcd(m,n)\mathbb F_{p^{\gcd(m,n)}}, which is conversely contained in both (Theorem 4.11(3)). The composite FpmFpn\mathbb F_{p^m}\mathbb F_{p^n}: any field containing both has degree divisible by mm and nn, hence by lcm(m,n)\operatorname{lcm}(m,n); and Fplcm\mathbb F_{p^{\operatorname{lcm}}} contains both: it is the composite. For mnm \mid n: Gal(Fpn/Fpm)\operatorname{Gal}(\mathbb F_{p^n}/\mathbb F_{p^m}) consists of the powers of FF fixing Fpm\mathbb F_{p^m}, i.e. of FmF^m: cyclic of order n/mn/m, generated by Fm ⁣:xxpmF^m \colon x \mapsto x^{p^m} (order as in Theorem 4.11(2)).

Exercise 4.6 ★★

Let Id(q)I_d(q) be the number of monic irreducible polynomials of degree dd over Fq\mathbb F_q. Prove

XqnX  =  dn P irred. monic, degP=dP,henceqn=dndId(q).X^{q^n} - X \;=\; \prod_{d \mid n}\ \prod_{P \text{ irred. monic, } \deg P = d} P , \qquad\text{hence}\qquad q^n = \sum_{d \mid n} d\, I_d(q).

Deduce I1,I2,I3,I4I_1, I_2, I_3, I_4 explicitly, and Id(q)1I_d(q) \geq 1 for every dd (so extensions Fqd/Fq\mathbb F_{q^d}/\mathbb F_q exist as quotients Fq[X]/(P)\mathbb F_q[X]/(P) for all dd).

Solution

Solution of Exercise 4.6.

XqnXX^{q^n} - X is separable (derivative 1-1) with root set Fqn\mathbb F_{q^n}. Let PP be monic irreducible of degree dd. If dnd \mid n: Fq[X]/(P)FqdFqn\mathbb F_q[X]/(P) \cong \mathbb F_{q^d} \subseteq \mathbb F_{q^n}, so PP has a root αFqn\alpha \in \mathbb F_{q^n}; αqn=α\alpha^{q^n} = \alpha, and P=παP = \pi_\alpha divides XqnXX^{q^n} - X. If PXqnXP \mid X^{q^n} - X: a root αFqn\alpha \in \mathbb F_{q^n} generates FqdFqn\mathbb F_{q^d} \subseteq \mathbb F_{q^n}, so dnd \mid n (Theorem 4.11(3)). Distinct irreducibles are coprime and the product is separable: each PP appears with exponent exactly 11, and every root of XqnXX^{q^n}-X is a root of its minimal polynomial: the factorization holds. Comparing degrees: qn=dndId(q)q^n = \sum_{d\mid n} d\,I_d(q).

Consequently I1=qI_1 = q; q2=I1+2I2q^2 = I_1 + 2I_2 gives I2=q2q2I_2 = \frac{q^2 - q}2; q3=I1+3I3q^3 = I_1 + 3I_3 gives I3=q3q3I_3 = \frac{q^3 - q}3; q4=I1+2I2+4I4q^4 = I_1 + 2I_2 + 4I_4 gives I4=q4q24I_4 = \frac{q^4 - q^2}4. Existence: nIn=qndn,d<ndIdqndn/2qd>qnqn/2+10nI_n = q^n - \sum_{d \mid n,\, d < n} dI_d \geq q^n - \sum_{d \leq n/2} q^d > q^n - q^{n/2 + 1} \geq 0 for n2n \geq 2 (and I1=q1I_1 = q \geq 1): In1I_n \geq 1 always.

Exercise 4.7 ★★

Determine Gal(Q(2,3)/Q)\operatorname{Gal}(\Q(\sqrt2,\sqrt3)/\Q) and the complete lattice of intermediate fields. Same question for the splitting field of (X22)(X23)(X26)(X^2-2)(X^2-3)(X^2-6) — what do you notice?

Solution

Solution of Exercise 4.7.

L=Q(2,3)L = \Q(\sqrt2, \sqrt3) is the splitting field of (X22)(X23)(X^2 - 2)(X^2 - 3), separable: Galois of degree 44 (Exercise 4.1). An automorphism sends 2±2\sqrt2 \mapsto \pm\sqrt2 and 3±3\sqrt3 \mapsto \pm\sqrt3: at most 44 choices, and G=4\abs G = 4 realizes all: G(Z/2Z)2G \cong (\Z/2\Z)^2, with elements id,σ(22),τ(33),στ\mathrm{id}, \sigma (\sqrt2 \mapsto -\sqrt2), \tau (\sqrt3\mapsto-\sqrt3), \sigma\tau. Subgroups of order 22: σ,τ,στ\langle\sigma\rangle, \langle\tau\rangle, \langle\sigma\tau\rangle, with fixed fields Q(3)\Q(\sqrt3), Q(2)\Q(\sqrt2), Q(6)\Q(\sqrt6) (note στ\sigma\tau fixes 6=23\sqrt6 = \sqrt2\sqrt3). The lattice: Q\Q below, the three quadratic fields in the middle, LL on top — and nothing else (Theorem 4.21). For (X22)(X23)(X26)(X^2-2)(X^2-3)(X^2-6): the splitting field is the same LL (6=23\sqrt6 = \sqrt2\sqrt3), so the answer is identical: the Galois correspondence is an invariant of the extension, not of the polynomial chosen to present it.

Exercise 4.8 ★★

(The cubic, solved by its group) Let P=X3+pX+qQ[X]P = X^3 + pX + q \in \Q[X] be irreducible with roots x1,x2,x3x_1, x_2, x_3 and splitting field LL. Let δ=(x1x2)(x1x3)(x2x3)\delta = (x_1 - x_2)(x_1 - x_3)(x_2 - x_3) and Δ=δ2=4p327q2\Delta = \delta^2 = -4p^3 - 27q^2 (admit this classical identity or verify it by expanding symmetric functions). (a) Show Gal(L/Q)A3\operatorname{Gal}(L/\Q) \cong A_3 or S3S_3, according to whether Δ\Delta is or is not a square in Q\Q. (b) With j=ζ3j = \zeta_3, define the Lagrange resolvents u=x1+jx2+j2x3u = x_1 + jx_2 + j^2x_3 and v=x1+j2x2+jx3v = x_1 + j^2x_2 + jx_3. Show u3+v3=27qu^3 + v^3 = -27q and uv=3puv = -3p, and solve for u3,v3u^3, v^3: Cardano’s formulas drop out. Where did solvability of S3S_3 get used?

Solution

Solution of Exercise 4.8.

(a) GG acts faithfully and transitively (irreducibility) on the three roots: GS3G \hookrightarrow S_3 with 3G3 \mid \abs G: GA3G \cong A_3 or S3S_3. Every σG\sigma \in G permutes the xix_i, and σ(δ)=ε(σ)δ\sigma(\delta) = \varepsilon(\sigma)\,\delta (δ\delta is alternating in the roots). If Δ\Delta is a square in Q\Q: δQ×\delta \in \Q^\times (note δ0\delta \neq 0: separable), so ε(σ)=1\varepsilon(\sigma) = 1 for all σ\sigma: GA3G \subseteq A_3, hence =A3= A_3. If not: δQ\delta \notin \Q, so some σ\sigma has ε(σ)=1\varepsilon(\sigma) = -1: G=S3G = S_3. (In both cases Q(δ)=LGA3\Q(\delta) = L^{G \cap A_3}.)

(b) With x1+x2+x3=0x_1 + x_2 + x_3 = 0: u+v=2x1(x2+x3)=3x1u + v = 2x_1 - (x_2 + x_3) = 3x_1. Also

uv=ixi2+(j+j2)i<kxixk=(xi)23i<kxixk=3p,uv = \sum_i x_i^2 + (j + j^2)\sum_{i<k}x_ix_k = \Bigl(\sum x_i\Bigr)^2 - 3\sum_{i<k}x_ix_k = -3p,

using j+j2=1j + j^2 = -1 and i<kxixk=p\sum_{i<k}x_ix_k = p. Then

u3+v3=(u+v)33uv(u+v)=27x13+9p3x1=27(x13+px1)=27q.u^3 + v^3 = (u+v)^3 - 3uv(u+v) = 27x_1^3 + 9p\cdot 3x_1 = 27\,(x_1^3 + px_1) = -27q .

So u3,v3u^3, v^3 are the roots of Y2+27qY27p3=0Y^2 + 27qY - 27p^3 = 0 (product (uv)3=27p3(uv)^3 = -27p^3): u3=27q+729q2+108p32u^3 = \frac{-27q + \sqrt{729q^2 + 108p^3}}2, and x1=u+v3x_1 = \frac{u + v}3 with v=3p/uv = -3p/u: Cardano. Solvability of S3S_3 is the skeleton: the tower QQ(δ)Q(δ,j,u)\Q \subseteq \Q(\delta) \subseteq \Q(\delta, j, u) adjoins first a square root (δ\delta, fixed field of A3A_3: the step S3S3/A3S_3 \to S_3/A_3), then a cube root (uu, since u3Q(δ,j)u^3 \in \Q(\delta, j): the step A3{e}A_3 \to \{e\}) — the derived series S3A3{e}S_3 \supset A_3 \supset \{e\} made flesh.

Exercise 4.9 ★★

In Q(ζ5)\Q(\zeta_5): show that the unique quadratic subfield is Q(5)\Q(\sqrt5), via the Gauss sums η0=ζ5+ζ54\eta_0 = \zeta_5 + \zeta_5^4, η1=ζ52+ζ53\eta_1 = \zeta_5^2 + \zeta_5^3: compute η0+η1\eta_0 + \eta_1 and η0η1\eta_0\eta_1, and deduce cos2π5=514\cos\frac{2\pi}5 = \frac{\sqrt5 - 1}4. Conclude that the regular pentagon is constructible.

Solution

Solution of Exercise 4.9.

η0+η1=ζ5+ζ52+ζ53+ζ54=1\eta_0 + \eta_1 = \zeta_5 + \zeta_5^2 + \zeta_5^3 + \zeta_5^4 = -1 (sum of all 55-th roots of unity is 00). η0η1=(ζ+ζ4)(ζ2+ζ3)=ζ3+ζ4+ζ6+ζ7=ζ3+ζ4+ζ+ζ2=1\eta_0\eta_1 = (\zeta + \zeta^4)(\zeta^2 + \zeta^3) = \zeta^3 + \zeta^4 + \zeta^6 + \zeta^7 = \zeta^3 + \zeta^4 + \zeta + \zeta^2 = -1 (indices mod 55). So η0,η1\eta_0, \eta_1 are the roots of Y2+Y1Y^2 + Y - 1: 1±52\frac{-1 \pm \sqrt5}2. Since η0=2cos2π5>0\eta_0 = 2\cos\frac{2\pi}5 > 0: η0=512\eta_0 = \frac{\sqrt5 - 1}2, whence cos2π5=514\cos\frac{2\pi}5 = \frac{\sqrt5 - 1}4, and η1=152\eta_1 = \frac{-1-\sqrt5}2. The group Gal(Q(ζ5)/Q)(Z/5Z)×\operatorname{Gal}(\Q(\zeta_5)/\Q) \cong (\Z/5\Z)^\times is cyclic of order 44: it has a unique subgroup of order 22 ({±1}\{\pm 1\}, i.e. ζζ±1\zeta \mapsto \zeta^{\pm1}), hence Q(ζ5)\Q(\zeta_5) has a unique quadratic subfield (Theorem 4.21), which contains η0Q\eta_0 \notin \Q: it is Q(η0)=Q(5)\Q(\eta_0) = \Q(\sqrt5). Constructibility: cos2π5\cos\frac{2\pi}5 lies in the quadratic tower QQ(5)\Q \subseteq \Q(\sqrt5), and ζ5\zeta_5 one quadratic step above: Theorem 4.25 constructs the pentagon.

Exercise 4.10 ★★★

Let K=Fp(S,T)K = \mathbb F_p(S, T) (rational functions in two indeterminates) and L=K(S1/p,T1/p)L = K(S^{1/p}, T^{1/p}). (a) Show [L:K]=p2[L:K] = p^2 and that αpK\alpha^p \in K for every αL\alpha \in L. (b) Deduce that L/KL/K is not simple: no primitive element exists — inseparability is fatal to Theorem 4.17.

Solution

Solution of Exercise 4.10.

(a) Write s=S1/ps = S^{1/p}, t=T1/pt = T^{1/p} (elements of a chosen algebraic closure with sp=Ss^p = S, tp=Tt^p = T). XpSX^p - S is irreducible over K=Fp(S,T)=(Fp(T))(S)K = \mathbb F_p(S, T) = (\mathbb F_p(T))(S)-fractions: Eisenstein at the prime element SS of the UFD Fp(T)[S]\mathbb F_p(T)[S] (Theorem 2.25). So [K(s):K]=p[K(s):K] = p; likewise XpTX^p - T is Eisenstein at TT over K(s)=Fp(s)(T)K(s) = \mathbb F_p(s)(T)-fractions — TT remains prime in Fp(s)[T]\mathbb F_p(s)[T] — giving [L:K(s)]=p[L : K(s)] = p and [L:K]=p2[L:K] = p^2. For αL\alpha \in L: L=K[s,t]L = K[s, t], so α=cijsitj\alpha = \sum c_{ij}s^it^j (cijKc_{ij} \in K), and by the Frobenius morphism αp=cijpSiTjK\alpha^p = \sum c_{ij}^p S^iT^j \in K.

(b) If L=K(α)L = K(\alpha), then [K(α):K]=p2[K(\alpha):K] = p^2; but αp=aK\alpha^p = a \in K means α\alpha annihilates XpaX^p - a, so degπαp<p2\deg\pi_\alpha \leq p < p^2: contradiction. No primitive element: Theorem 4.17 genuinely needs separability (here every πα\pi_\alpha divides some Xpa=(Xα)pX^p - a = (X - \alpha)^p: purely inseparable).

Exercise 4.11 ★★★

Let P=X54X+2P = X^5 - 4X + 2 and GG its Galois group over Q\Q, acting on the 55 roots. (a) Show PP is irreducible, and deduce 5G5 \mid \abs G; conclude that GG contains a 55-cycle (Cauchy, Theorem 1.13). (b) Show, by studying the variations of xx54x+2x \mapsto x^5 - 4x + 2, that PP has exactly 33 real roots; deduce that complex conjugation restricts to a transposition in GG. (c) Show that a subgroup of S5S_5 containing a transposition and a 55-cycle is S5S_5 (conjugate the transposition by powers of the cycle). Conclude GS5G \cong S_5 and, with Theorem 4.29, that PP is not solvable by radicals.

Solution

Solution of Exercise 4.11.

(a) Eisenstein at 22 (24,22 \mid 4, 2; 424 \nmid 2): PP irreducible. If α\alpha is a root, [Q(α):Q]=5[\Q(\alpha):\Q] = 5 divides [L:Q]=G[L:\Q] = \abs G (LL the splitting field): Cauchy (Theorem 1.13) gives an element of order 55 in GS5G \leq S_5; in S5S_5, only 55-cycles have order 55 (orders are lcms of cycle lengths).

(b) P(x)=5x44P'(x) = 5x^4 - 4 vanishes at ±(4/5)1/4±0.946\pm(4/5)^{1/4} \approx \pm 0.946: one local maximum then one local minimum. Values: P(2)=22<0P(-2) = -22 < 0, P(0)=2>0P(0) = 2 > 0, P(1)=1<0P(1) = -1 < 0, P(2)=26>0P(2) = 26 > 0: three sign changes, and at most three real roots (two critical points): exactly 33 real roots, hence one pair of complex conjugate roots. Take the splitting field LL inside C\C: complex conjugation maps LL to itself (it permutes the roots, which generate LL) and fixes Q\Q, so it defines an element of GG; it fixes the three real roots and swaps the other two: a transposition.

(c) Let τ=(ab)\tau = (a\,b) and σ\sigma a 55-cycle in GG. Some power σk\sigma^k sends aa to bb (k0mod5k \ne 0 \bmod 5), and σk\sigma^k is again a 55-cycle: renaming, assume σ=(12345)\sigma = (1\,2\,3\,4\,5) and τ=(12)\tau = (1\,2). Conjugating, σmτσm=(σm(1) σm(2))\sigma^m\tau\sigma^{-m} = (\sigma^m(1)\ \sigma^m(2)): the adjacent transpositions (12),(23),(34),(45),(51)(1\,2), (2\,3), (3\,4), (4\,5), (5\,1) all lie in GG; adjacent transpositions generate S5S_5 (every transposition (ij)(i\,j) is a product of adjacent ones, and transpositions generate). So G=S5G = S_5, not solvable (Corollary 1.34), and Theorem 4.29 concludes: X54X+2X^5 - 4X + 2 is not solvable by radicals.

Exercise 4.12 ★★★

(The dihedral quartic) Let α=24\alpha = \sqrt[4]2 and L=Q(α,i)L = \Q(\alpha, \iu), the splitting field of X42X^4 - 2 over Q\Q. (a) Show [L:Q]=8[L : \Q] = 8 and that G=Gal(L/Q)G = \operatorname{Gal}(L/\Q) is generated by σ ⁣:αiα, ii\sigma\colon \alpha \mapsto \iu\alpha,\ \iu \mapsto \iu and complex conjugation τ\tau, with σ4=τ2=e\sigma^4 = \tau^2 = e and τστ=σ1\tau\sigma\tau = \sigma^{-1}: GD4G \cong D_4. (b) List the subgroup lattice of D4D_4 (ten subgroups) and match each to its fixed field; verify in particular that Q(2)\Q(\sqrt2), Q(i)\Q(\iu), Q(i2)\Q(\iu\sqrt2) are the three quadratic subfields, and locate Q(α)\Q(\alpha), Q(iα)\Q(\iu\alpha), Q(2,i)\Q(\sqrt2, \iu). (c) Which intermediate fields are Galois over Q\Q? Match your answer against the normal subgroups of D4D_4, and explain why Q(α)/Q\Q(\alpha)/\Q fails while Q(2)/Q\Q(\sqrt2)/\Q succeeds.

Solution

Solution of Exercise 4.12.

(a) X42X^4 - 2 is irreducible (Eisenstein at 22): [Q(α):Q]=4[\Q(\alpha):\Q] = 4; iQ(α)R\iu \notin \Q(\alpha) \subseteq \R, so [L:Q(α)]=2[L : \Q(\alpha)] = 2 and [L:Q]=8[L:\Q] = 8. The extension is Galois (splitting field of a separable polynomial: the roots are ikα\iu^k\alpha), so G=8\abs G = 8. An automorphism sends α\alpha to one of the four roots and i\iu to ±i\pm\iu: at most 88 maps, all realized. The stated σ\sigma (order 44: σ2(α)=α\sigma^2(\alpha) = -\alpha, σ4=e\sigma^4 = e) and τ\tau (order 22) satisfy

τστ(α)=τσ(α)=τ(iα)=iα=σ1(α),τστ(i)=i(1)(1)=i,\tau\sigma\tau(\alpha) = \tau\sigma(\alpha) = \tau(\iu\alpha) = -\iu\alpha = \sigma^{-1}(\alpha), \qquad \tau\sigma\tau(\iu) = \iu\cdot(-1)(-1) = \iu ,

more carefully: τστ(i)=τσ(i)=τ(i)=i=σ1(i)\tau\sigma\tau(\iu) = \tau\sigma(-\iu) = \tau(-\iu) = \iu = \sigma^{-1}(\iu). So τστ=σ1\tau\sigma\tau = \sigma^{-1}: the presentation of D4D_4.

(b) The ten subgroups of D4=σ,τD_4 = \langle\sigma, \tau\rangle: {e}\{e\}; five of order 22: σ2\langle\sigma^2\rangle, τ\langle\tau\rangle, σ2τ\langle\sigma^2\tau\rangle, στ\langle\sigma\tau\rangle, σ3τ\langle\sigma^3\tau\rangle; three of order 44: σ\langle\sigma\rangle, {e,σ2,τ,σ2τ}\{e, \sigma^2, \tau, \sigma^2\tau\}, {e,σ2,στ,σ3τ}\{e, \sigma^2, \sigma\tau, \sigma^3\tau\}; and D4D_4. Fixed fields (degree = index): {e}L\{e\} \leftrightarrow L; order-22 subgroups \leftrightarrow the five quartic fields

τQ(α),σ2τQ(iα),σ2Q(2,i),στQ((1+i)α),σ3τQ((1i)α).\langle\tau\rangle \leftrightarrow \Q(\alpha),\quad \langle\sigma^2\tau\rangle \leftrightarrow \Q(\iu\alpha), \quad \langle\sigma^2\rangle \leftrightarrow \Q(\sqrt2, \iu),\quad \langle\sigma\tau\rangle \leftrightarrow \Q\bigl((1+\iu)\alpha\bigr),\quad \langle\sigma^3\tau\rangle \leftrightarrow \Q\bigl((1-\iu)\alpha\bigr) .

Checks: τ\tau fixes the real α\alpha; σ2τ\sigma^2\tau sends αα\alpha \mapsto -\alpha and ii\iu \mapsto -\iu, fixing iα\iu\alpha; and since στ(α)=iα\sigma\tau(\alpha) = \iu\alpha, στ(i)=i\sigma\tau(\iu) = -\iu:

στ((1+i)α)=(1i)iα=(1+i)α,σ3τ((1i)α)=(1+i)(i)α=(1i)α:\sigma\tau\bigl((1+\iu)\alpha\bigr) = (1 - \iu)\,\iu\alpha = (1 + \iu)\alpha, \qquad \sigma^3\tau\bigl((1-\iu)\alpha\bigr) = (1 + \iu)(-\iu)\alpha = (1 - \iu)\alpha :

each reflection fixes its generator, and the fixed field, of degree 4=4 = index, is exactly the field it generates (the generator is a root of X4+8X^4 + 8, irreducible). Order-44 subgroups \leftrightarrow the three quadratic fields: σQ(i)\langle\sigma\rangle \leftrightarrow \Q(\iu) (σ\sigma fixes i\iu); {e,σ2,τ,σ2τ}Q(2)\{e, \sigma^2, \tau, \sigma^2\tau\} \leftrightarrow \Q(\sqrt2) (all four fix α2\alpha^2 up to sign checks: τ(2)=2\tau(\sqrt2) = \sqrt2, σ2(α2)=(α)2\sigma^2(\alpha^2) = (-\alpha)^2); {e,σ2,στ,σ3τ}Q(i2)\{e, \sigma^2, \sigma\tau, \sigma^3\tau\} \leftrightarrow \Q(\iu\sqrt2) (στ(iα2)=(i)(iα)2=iα2\sigma\tau(\iu\alpha^2) = (-\iu)(\iu\alpha)^2 = \iu\alpha^2).

(c) Galois over Q\Q \leftrightarrow normal subgroups of D4D_4: {e}\{e\}, σ2\langle\sigma^2\rangle (the center), the three subgroups of order 44, and D4D_4 — so the Galois intermediate fields are LL, Q(2,i)\Q(\sqrt2, \iu), the three quadratic fields, and Q\Q. The five quartic fields fixed by non-normal reflections are not Galois: Q(α)\Q(\alpha) contains one root of X42X^4 - 2 but not iα\iu\alpha (it is real) — conjugation by σ\sigma moves τ\langle\tau\rangle to σ2τ\langle\sigma^2\tau\rangle, exactly as it moves Q(α)\Q(\alpha) to Q(iα)\Q(\iu\alpha): non-normality of the subgroup is the existence of a conjugate field.

4.10 Problem: Gauss and the regular 17-gon

Problem 4.1

Weekend problem — constructibility of the 17-gon

On March 30, 1796, the nineteen-year-old Gauss showed that the regular 1717-gon is constructible — the first progress on the question since antiquity. We reconstruct his computation with the tools of this chapter. Set ζ=e2iπ/17\zeta = \eu^{2\iu\pi/17}, L=Q(ζ)L = \Q(\zeta), G=Gal(L/Q)G = \operatorname{Gal}(L/\Q).

Part I — The group and its filtration.

  1. Justify: [L:Q]=16[L:\Q] = 16, G(Z/17Z)×G \cong (\Z/17\Z)^\times, cyclic of order 1616. Verify that 33 is a generator of (Z/17Z)×(\Z/17\Z)^\times (compute the powers of 33 modulo 1717: 3,9,10,13,5,15,11,16,3, 9, 10, 13, 5, 15, 11, 16, \dots).
  2. Let σG\sigma \in G with σ(ζ)=ζ3\sigma(\zeta) = \zeta^3, and Hk=σ2kH_k = \langle \sigma^{2^k}\rangle for k=0,,4k = 0, \dots, 4. Show that G=H0H1H2H3H4={e}G = H_0 \supset H_1 \supset H_2 \supset H_3 \supset H_4 = \{e\} with each index [Hk:Hk+1]=2[H_k : H_{k+1}] = 2, and that the fixed fields Q=L0L1L2L3L4=L\Q = L_0 \subset L_1 \subset L_2 \subset L_3 \subset L_4 = L form a tower of quadratic extensions.
  3. Conclude a priori, using Theorem 4.25, that ζ\zeta — hence the 1717-gon — is constructible. The rest of the problem makes the tower explicit.

Part II — The periods of length 8. Define the Gauss periods

η0=k evenζ3kmod17=ζ1+ζ9+ζ13+ζ15+ζ16+ζ8+ζ4+ζ2,η1=k oddζ3kmod17.\eta_0 = \sum_{k \text{ even}} \zeta^{3^k \bmod 17} = \zeta^{1} + \zeta^{9} + \zeta^{13} + \zeta^{15} + \zeta^{16} + \zeta^{8} + \zeta^{4} + \zeta^{2}, \qquad \eta_1 = \sum_{k \text{ odd}} \zeta^{3^k \bmod 17}.
  1. Show that η0,η1\eta_0, \eta_1 are fixed by H1H_1 and swapped by σ\sigma; deduce η0,η1L1\eta_0, \eta_1 \in L_1 and that they are the two roots of a quadratic over Q\Q.
  2. Compute η0+η1=1\eta_0 + \eta_1 = -1. Show η0η1=4\eta_0\eta_1 = -4 (each product ζaζb\zeta^a\zeta^b is some ζc\zeta^c, c0c \neq 0; count how many times each cc occurs, or argue that the product is a rational integer fixed by GG, equal to the sum over all 6464 products, and use that each nonzero residue appears equally often).
  3. Deduce η0=1+172\eta_0 = \frac{-1 + \sqrt{17}}2, η1=1172\eta_1 = \frac{-1-\sqrt{17}}2 (identify which is which numerically: η01.56\eta_0 \approx 1.56), and L1=Q(17)L_1 = \Q(\sqrt{17}).

Part III — Periods of length 4 and 2. Define

β0=ζ+ζ13+ζ16+ζ4,β1=ζ3+ζ5+ζ14+ζ12,β2=ζ9+ζ15+ζ8+ζ2,β3=ζ10+ζ11+ζ7+ζ6.\beta_0 = \zeta + \zeta^{13} + \zeta^{16} + \zeta^{4},\quad \beta_1 = \zeta^3 + \zeta^5 + \zeta^{14} + \zeta^{12},\quad \beta_2 = \zeta^9 + \zeta^{15} + \zeta^{8} + \zeta^{2},\quad \beta_3 = \zeta^{10} + \zeta^{11} + \zeta^{7} + \zeta^{6}.
  1. Show β0+β2=η0\beta_0 + \beta_2 = \eta_0, β1+β3=η1\beta_1 + \beta_3 = \eta_1, and that β0,β2\beta_0, \beta_2 are fixed by H2H_2, swapped by σ2\sigma^2.
  2. Compute β0β2=1\beta_0\beta_2 = -1 and β1β3=1\beta_1\beta_3 = -1 (expand: the sixteen exponents obtained cover 1,,161, \dots, 16 exactly once).
  3. Deduce β0=η0+η02+42\beta_0 = \frac{\eta_0 + \sqrt{\eta_0^2 + 4}}2 (check the sign numerically: β02.05\beta_0 \approx 2.05) and the analogous formula for β1\beta_1; hence L2=Q(β0)L_2 = \Q(\beta_0), quadratic over L1L_1.
  4. Let γ0=ζ+ζ16=2cos2π17\gamma_0 = \zeta + \zeta^{16} = 2\cos\frac{2\pi}{17} and γ1=ζ13+ζ4\gamma_1 = \zeta^{13} + \zeta^4. Show γ0+γ1=β0\gamma_0 + \gamma_1 = \beta_0 and γ0γ1=β1\gamma_0\gamma_1 = \beta_1, so that γ0=β0+β024β12\gamma_0 = \frac{\beta_0 + \sqrt{\beta_0^2 - 4\beta_1}}2.
  5. Assemble the chain of formulas expressing cos2π17\cos\frac{2\pi}{17} by nested square roots, and give a decimal check (cos2π170.93247\cos\frac{2\pi}{17} \approx 0.93247).

Part IV — Epilogue.

  1. Where exactly did the argument use that 1717 is a Fermat prime (17=222+117 = 2^{2^2} + 1)? Show that for a prime pp, the regular pp-gon is constructible iff p=22t+1p = 2^{2^t} + 1 for some tt (if p1=2mp - 1 = 2^m, show mm must itself be a power of 22).
  2. Deduce the complete list of constructible regular nn-gons for n20n \leq 20, using the Gauss–Wantzel criterion of Corollary 4.26.

Part V — Gauss sums and quadratic reciprocity. The periods of Part II hide a treasure. For an odd prime pp, the Legendre symbol (ap)\bigl(\frac ap\bigr) is +1+1 if aa is a nonzero square mod pp, 1-1 if it is not, 00 if pap \mid a; Exercise 4.4(b) (Euler’s criterion) gives (ap)a(p1)/2(modp)\bigl(\frac ap\bigr) \equiv a^{(p-1)/2} \pmod p, whence multiplicativity. Write ζ=e2iπ/p\zeta = \eu^{2\iu\pi/p}, p=(1)(p1)/2pp^* = (-1)^{(p-1)/2}p, and define the Gauss sum

g  =  a=1p1(ap)ζa.g \;=\; \sum_{a=1}^{p-1}\Bigl(\frac ap\Bigr)\zeta^a .
  1. Show a=1p1(ap)=0\sum_{a=1}^{p-1}\bigl(\frac ap\bigr) = 0 (as many squares as nonsquares), and prove the alternative form g=a=0p1ζa2g = \sum_{a=0}^{p-1}\zeta^{a^2} (each nonzero square is hit twice, and aζa=0\sum_{a}\zeta^a = 0). For p=17p = 17: relate gg to the periods of Part II — show g=η0η1g = \eta_0 - \eta_1 (the squares mod 1717 are exactly the even powers of the generator 33).
  2. Prove g2=pg^2 = p^*: expand

    g2=a,b0(abp)ζa+b=c a0(a(ca)p)ζcg^2 = \sum_{a,b\neq0}\Bigl(\frac{ab}p\Bigr) \zeta^{a+b} = \sum_{c}\ \sum_{a \neq 0}\Bigl(\frac{a(c - a)}p\Bigr)\zeta^{c}

    (set b=cab = c - a), substitute ca=atc - a = at to evaluate the inner sum as (1p)(p1)\bigl(\frac{-1}p\bigr)(p - 1) for c=0c = 0 and (1p)-\bigl(\frac{-1}p\bigr) otherwise, and conclude with question 14. Check numerically: for p=17p = 17, (η0η1)2=17(\eta_0 - \eta_1)^2 = 17 (Part II).

  3. Deduce pQ(ζp)\sqrt{p^*} \in \Q(\zeta_p), and conclude that the unique quadratic subfield of Q(ζp)\Q(\zeta_p) is Q(p)\Q(\sqrt{p^*}) — unique because Gal(Q(ζp)/Q)\operatorname{Gal}(\Q(\zeta_p)/\Q) is cyclic (Theorem 4.23) and a cyclic group has exactly one subgroup of index 22. (Every quadratic field embeds in some cyclotomic field — this is the first case of the Kronecker–Weber theorem, whose general form lies far ahead.)
  4. Now let qpq \neq p be another odd prime. Working in the ring Z[ζ]\Z[\zeta] modulo qq, prove

    gq(qp)g(modqZ[ζ])g^q \equiv \Bigl(\frac qp\Bigr)\,g \pmod{q\Z[\zeta]}

    (freshman’s dream: (x+y)qxq+yq(x + y)^q \equiv x^q + y^q mod qq in any commutative ring; then gqa(ap)qζaqg^q \equiv \sum_a\bigl(\frac ap\bigr)^q\zeta^{aq}, reindex b=aqb = aq and pull out (q1p)=(qp)\bigl(\frac{q^{-1}}p\bigr) = \bigl(\frac qp\bigr)).

  5. On the other hand, gq=g(g2)(q1)/2=g(p)(q1)/2g^q = g\,(g^2)^{(q-1)/2} = g\,(p^*)^{(q-1)/2}; using Euler’s criterion mod qq, deduce gq(pq)g(modqZ[ζ])g^q \equiv \bigl(\frac{p^*}q\bigr)g \pmod{q\Z[\zeta]}, then — multiplying the two expressions for gqg^q by gg and using g2=pg^2 = p^*, invertible mod qq — conclude

    (qp)=(pq).\Bigl(\frac qp\Bigr) = \Bigl(\frac{p^*}q\Bigr) .

    (Why does a congruence between the integers ±p\pm p^* modulo qZ[ζ]q\Z[\zeta] imply their equality? Intersect with Z\Z.)

  6. Unfold (pq)=(1q)(p1)/2(pq)\bigl(\frac{p^*}q\bigr) = \bigl(\frac{-1}q\bigr)^{(p-1)/2}\bigl(\frac pq\bigr) and (1q)=(1)(q1)/2\bigl(\frac{-1}q\bigr) = (-1)^{(q-1)/2} to obtain the law of quadratic reciprocity:

    (pq)(qp)=(1)p12q12.\Bigl(\frac pq\Bigr)\Bigl(\frac qp\Bigr) = (-1)^{\frac{p-1}2\cdot\frac{q-1}2} .

    Verify it on (p,q)=(17,3)(p, q) = (17, 3) by listing the squares mod 1717 and mod 33, and use it to decide in three lines whether x2219(mod383)x^2 \equiv 219 \pmod{383} is solvable (383383 is prime, 219=373219 = 3\cdot73).

Part VI — Counting irreducible polynomials: the prime number theorem of Fq[X]\mathbb F_q[X]. Fix a prime power qq and let Nq(n)N_q(n) be the number of monic irreducible polynomials of degree nn over Fq\mathbb F_q; recall from Exercise 4.6 the factorization of XqnXX^{q^n} - X and the identity qn=dndNq(d)q^n = \sum_{d\mid n}d\,N_q(d), which we now invert, reinterpret, and exploit.

  1. (Words) Call a word wFqnw \in \mathbb F_q^n primitive if it is not a power un/d=uuu^{n/d} = u\cdots u of a strictly shorter word uu, and let A(d)A(d) be the number of primitive words of length dd. Show that every word of length nn is uniquely a power of a primitive word of some length dnd \mid n, so that qn=dnA(d)q^n = \sum_{d \mid n}A(d); comparing with Exercise 4.6, conclude A(d)=dNq(d)A(d) = d\,N_q(d) for every dd, and explain this coincidence by an explicit bijection: an element αFqd\alpha \in \mathbb F_{q^d} of degree dd has Frobenius orbit (α,αq,,αqd1)(\alpha, \alpha^q, \dots, \alpha^{q^{d-1}}) of exactly dd distinct elements, and elements of degree dd correspond dd-to-one to irreducibles of degree dd.
  2. Prove the Möbius inversion formula: if f(n)=dng(d)f(n) = \sum_{d\mid n}g(d) for all nn, then g(n)=dnμ(d)f(n/d)g(n) = \sum_{d\mid n}\mu(d)\,f(n/d), where μ\mu is the Möbius function (μ(m)=(1)#prime factors\mu(m) = (-1)^{\#\text{prime factors}} if mm is squarefree, 00 otherwise) (key lemma: dmμ(d)=0\sum_{d \mid m}\mu(d) = 0 for m>1m > 1 — pair the divisors with and without a fixed prime factor). Deduce

    Nq(n)=1ndnμ(d)qn/d.N_q(n) = \frac1n\sum_{d \mid n}\mu(d)\,q^{n/d} .
  3. Show Nq(n)1n(qn2qn/2)>0N_q(n) \geq \frac1n\bigl(q^n - 2q^{n/2}\bigr) > 0 for every n1n \geq 1: a new proof that Fqn\mathbb F_{q^n} exists for all nn. Interpret the leading term: a random monic polynomial of degree nn is irreducible with probability 1n\sim \frac1n — the perfect analogue of the prime number theorem, with logx\log x traded for nn; verify numerically for q=2q = 2, n4n \leq 4 (Exercise 4.6 lists the counts).
  4. Prove the multiplicative companion of question 21:

    π monic irred.degπ=nπ  =  dn(XqdX)μ(n/d)\prod_{\substack{\pi \text{ monic irred.}\\ \deg\pi = n}}\pi \;=\; \prod_{d \mid n} \bigl(X^{q^d} - X\bigr)^{\mu(n/d)}

    (Möbius inversion in the abelian group of nonzero rational functions); verify it by hand for q=2q = 2, n=2n = 2: (X4X)/(X2X)=X2+X+1(X^4 - X)/(X^2 - X) = X^2 + X + 1.

Part VII — Two codas.

  1. (The second supplement) Part V’s method also computes (2q)\bigl(\frac2q\bigr). Let ω=e2iπ/8\omega = \eu^{2\iu\pi/8} and g=ω+ω1g = \omega + \omega^{-1}. Show g2=2g^2 = 2 (ω2=i\omega^2 = \iu); then, for an odd prime qq, prove in Z[ω]\Z[\omega] modulo qq that

    gqωq+ωq(modqZ[ω]),g^q \equiv \omega^q + \omega^{-q} \pmod{q\Z[\omega]},

    and that the right side equals gg if q±1(mod8)q \equiv \pm1 \pmod 8 and g-g if q±3(mod8)q \equiv \pm3 \pmod 8. Comparing with gq=g(g2)(q1)/2(2q)gg^q = g\,(g^2)^{(q-1)/2} \equiv \bigl(\frac2q\bigr)g as in question 18, conclude

    (2q)=(1)(q21)/8,\Bigl(\frac2q\Bigr) = (-1)^{(q^2-1)/8},

    checking that (q21)/8(q^2 - 1)/8 is even exactly when q±1(mod8)q \equiv \pm1 \pmod 8. Verify: 22 is a square mod 77 and mod 1717 (323^2 and 626^2), not mod 33 nor mod 55.

  2. (The zeta function of Fq[X]\mathbb F_q[X]) Prove the identity of formal power series in tt:

    n1(1tn)Nq(n)=11qt\prod_{n \geq 1}\bigl(1 - t^n\bigr)^{-N_q(n)} = \frac1{1 - qt}

    (unique factorization into monic irreducibles: expand each factor as a geometric series and count monic polynomials of degree nn). Recover the identity qm=dmdNq(d)q^m = \sum_{d \mid m}d\,N_q(d) of Exercise 4.6 by taking logarithms. Check the coefficient of t2t^2 by hand for q=2q = 2, and use question 21’s formula to compute N2(6)=9N_2(6) = 9, verifying 26=12+21+32+692^6 = 1\cdot2 + 2\cdot1 + 3\cdot2 + 6\cdot9.

Solution

Solution of Problem 4.1.

1. Φ17\Phi_{17} is irreducible (Theorem 4.23, or Example 2.26 for prime index): [L:Q]=φ(17)=16[L:\Q] = \varphi(17) = 16 and G(Z/17Z)×G \cong (\Z/17\Z)^\times, cyclic of order 1616 (Theorem 4.12). Powers of 33 mod 1717:

3, 9, 10, 13, 5, 15, 11, 16, 14, 8, 7, 4, 12, 2, 6, 13,\ 9,\ 10,\ 13,\ 5,\ 15,\ 11,\ 16,\ 14,\ 8,\ 7,\ 4,\ 12,\ 2,\ 6,\ 1

— sixteen distinct values: 33 generates.

2. G=σG = \langle\sigma\rangle cyclic of order 1616; Hk=σ2kH_k = \langle\sigma^{2^k}\rangle has order 24k2^{4-k}, and [Hk:Hk+1]=2[H_k : H_{k+1}] = 2. By the fundamental theorem (Theorem 4.21), Lk=LHkL_k = L^{H_k} satisfy [Lk:Q]=[G:Hk]=2k[L_k : \Q] = [G : H_k] = 2^k: each [Lk+1:Lk]=2[L_{k+1}:L_k] = 2.

3. ζL=L4\zeta \in L = L_4 sits atop a tower of quadratic extensions of Q\Q: by Theorem 4.25, ζ\zeta is constructible; the 1717-gon has vertices ζk\zeta^k.

4. σ2\sigma^2 multiplies exponents by 99; the exponents of η0\eta_0 are the even powers of 33,

{32kmod17}={1,9,13,15,16,8,4,2},\{3^{2k} \bmod 17\} = \{1, 9, 13, 15, 16, 8, 4, 2\},

a set stable under multiplication by 9=329 = 3^2; so η0\eta_0 (and likewise η1\eta_1) is fixed by H1=σ2H_1 = \langle\sigma^2\rangle: η0,η1L1\eta_0, \eta_1 \in L_1, a quadratic field. σ\sigma maps even powers to odd: it swaps η0,η1\eta_0, \eta_1. Hence η0+η1\eta_0 + \eta_1 and η0η1\eta_0\eta_1 are fixed by all of GG: rational; η0,η1\eta_0, \eta_1 are the roots of a rational quadratic.

5. η0+η1=c=116ζc=1\eta_0 + \eta_1 = \sum_{c=1}^{16}\zeta^c = -1. The product expands into 6464 terms ζa+b\zeta^{a + b}, aa in the even set, bb in the odd set. No term is ζ0\zeta^0: b=ab = -a is impossible, because 1=16=38-1 = 16 = 3^8 is an even power, so a-a stays in the even set. Thus η0η1=c0ncζc\eta_0\eta_1 = \sum_{c \neq 0} n_c\zeta^c with nc=64\sum n_c = 64; applying σ\sigma fixes η0η1\eta_0\eta_1 (it swaps the factors) and permutes the ζc\zeta^c transitively over all c0c \neq 0, so all ncn_c are equal: nc=4n_c = 4 and η0η1=4c0ζc=4\eta_0\eta_1 = 4\sum_{c\neq0}\zeta^c = -4.

6. η0,1\eta_{0,1} solve Y2+Y4=0Y^2 + Y - 4 = 0: 1±172\frac{-1 \pm \sqrt{17}}2. Numerically, pairing conjugate exponents, η0=2(cos2π17+cos4π17+cos8π17+cos16π17)1.56>0\eta_0 = 2\bigl(\cos\tfrac{2\pi}{17} + \cos\tfrac{4\pi}{17} + \cos\tfrac{8\pi}{17} + \cos\tfrac{16\pi}{17}\bigr) \approx 1.56 > 0: η0=1+172\eta_0 = \frac{-1+\sqrt{17}}2, η1=1172\eta_1 = \frac{-1-\sqrt{17}}2, and L1=Q(η0)=Q(17)L_1 = \Q(\eta_0) = \Q(\sqrt{17}).

7. The exponent sets: β0\beta_0: {1,13,16,4}\{1, 13, 16, 4\} = powers 34k3^{4k}; β2\beta_2: {9,15,8,2}\{9, 15, 8, 2\} = 9×9 \times that set. Union: the even set: β0+β2=η0\beta_0 + \beta_2 = \eta_0; likewise β1+β3=η1\beta_1 + \beta_3 = \eta_1. Multiplication by 13=3413 = 3^4 stabilizes each βi\beta_i’s exponent set: fixed by H2=σ4H_2 = \langle\sigma^4\rangle; and σ2\sigma^2 (×9\times 9) sends {1,13,16,4}\{1,13,16,4\} to {9,15,8,2}\{9, 15, 8, 2\}: swaps β0,β2\beta_0, \beta_2.

8. Expanding β0β2\beta_0\beta_2, the sixteen exponent sums

{1,13,16,4}+{9,15,8,2}={10,16,9,3, 5,11,4,15, 8,14,7,1, 13,2,12,6}\{1,13,16,4\} + \{9,15,8,2\} = \{10,16,9,3,\ 5,11,4,15,\ 8,14,7,1,\ 13,2,12,6\}

cover 1,,161, \dots, 16 exactly once: β0β2=c0ζc=1\beta_0\beta_2 = \sum_{c\ne0}\zeta^c = -1. Applying σ\sigma (which maps β0β1\beta_0 \mapsto \beta_1, β2β3\beta_2 \mapsto \beta_3: exponents ×3\times 3): β1β3=σ(β0β2)=1\beta_1\beta_3 = \sigma(\beta_0\beta_2) = -1.

9. β0,β2\beta_0, \beta_2 solve Y2η0Y1=0Y^2 - \eta_0 Y - 1 = 0, so β0=η0+η02+42\beta_0 = \frac{\eta_0 + \sqrt{\eta_0^2 + 4}}2 (numerically β0=2cos2π17+2cos8π172.05>0\beta_0 = 2\cos\frac{2\pi}{17} + 2\cos\frac{8\pi}{17} \approx 2.05 > 0, the ++ sign). Likewise β1=η1+η12+420.344\beta_1 = \frac{\eta_1 + \sqrt{\eta_1^2 + 4}}2 \approx 0.344 (numerical check fixes the sign again). L2=L1(β0)L_2 = L_1(\beta_0), quadratic over L1L_1.

10. γ0+γ1=ζ+ζ16+ζ13+ζ4=β0\gamma_0 + \gamma_1 = \zeta + \zeta^{16} + \zeta^{13} + \zeta^4 = \beta_0. And

γ0γ1=(ζ+ζ16)(ζ13+ζ4)=ζ14+ζ5+ζ12+ζ3=β1.\gamma_0\gamma_1 = (\zeta + \zeta^{16})(\zeta^{13} + \zeta^4) = \zeta^{14} + \zeta^{5} + \zeta^{12} + \zeta^{3} = \beta_1 .

So γ0,γ1\gamma_0, \gamma_1 solve Y2β0Y+β1=0Y^2 - \beta_0Y + \beta_1 = 0; numerically γ0=2cos2π171.865>γ10.185\gamma_0 = 2\cos\frac{2\pi}{17} \approx 1.865 > \gamma_1 \approx 0.185: γ0=β0+β024β12\gamma_0 = \frac{\beta_0 + \sqrt{\beta_0^2 - 4\beta_1}}2.

11. Chaining:

η0=1+172,β0=η0+η02+42,β1=η1+η12+42,cos2π17=β0+β024β14.\eta_0 = \frac{-1 + \sqrt{17}}2, \quad \beta_0 = \frac{\eta_0 + \sqrt{\eta_0^2 + 4}}2, \quad \beta_1 = \frac{\eta_1 + \sqrt{\eta_1^2 + 4}}2, \quad \cos\frac{2\pi}{17} = \frac{\beta_0 + \sqrt{\beta_0^2 - 4\beta_1}}4 .

Numerically: 174.1231\sqrt{17} \approx 4.1231, η01.5616\eta_0 \approx 1.5616, η12.5616\eta_1 \approx -2.5616, β02.0494\beta_0 \approx 2.0494, β10.3441\beta_1 \approx 0.3441, β024β12.8234\beta_0^2 - 4\beta_1 \approx 2.8234, and cos2π172.0494+1.680340.93242\cos\frac{2\pi}{17} \approx \frac{2.0494 + 1.6803}4 \approx 0.93242 — against cos2π17=0.93247\cos\frac{2\pi}{17} = 0.93247\dots: the small discrepancy is rounding in the intermediate displays; carrying more digits reproduces 0.9324720.932472.

12. The construction needed [L:Q]=p1[L:\Q] = p - 1 to be a power of 22, so that a full chain of index-22 subgroups exists. If p=2m+1p = 2^m + 1 is prime and m=abm = ab with aa odd >1> 1: x+1xa+1x + 1 \mid x^a + 1 at x=2bx = 2^b shows 2b+12^b + 1 properly divides pp — impossible. So mm is a power of 22: p=22t+1p = 2^{2^t} + 1, a Fermat prime (3,5,17,257,655373, 5, 17, 257, 65537, …). Conversely for such pp, φ(p)=22t\varphi(p) = 2^{2^t} and the argument of questions 1–3 (or Corollary 4.26) applies: the regular pp-gon is constructible iff pp is a Fermat prime.

13. φ(n)\varphi(n) is a power of 22 exactly when n=2ap1prn = 2^a p_1\cdots p_r with distinct Fermat primes pip_i (multiplicativity of φ\varphi; an odd prime power pkp^k, k2k \geq 2, contributes the factor p2mp \nmid 2^m). For n20n \leq 20, the constructible regular nn-gons are

n=3,4,5,6,8,10,12,15,16,17,20n = 3, 4, 5, 6, 8, 10, 12, 15, 16, 17, 20

with respective values

φ(n)=2, 2, 4, 2, 4, 4, 4, 8, 8, 16, 8.\varphi(n) = 2,\ 2,\ 4,\ 2,\ 4,\ 4,\ 4,\ 8,\ 8,\ 16,\ 8 .

The impossible ones are n=7,9,11,13,14,18,19n = 7, 9, 11, 13, 14, 18, 19, where φ(n)=6,6,10,12,6,6,18\varphi(n) = 6, 6, 10, 12, 6, 6, 18 has an odd prime factor.

14. The squares form the image of the squaring morphism on the cyclic (Z/pZ)×(\Z/p\Z)^\times, of index 22: p12\frac{p-1}2 squares, p12\frac{p-1}2 nonsquares, so the symbols sum to 00. Then

a=0p1ζa2=1+2b square0ζb=1+b0(1+(bp))ζb=bζb+g=g,\sum_{a=0}^{p-1}\zeta^{a^2} = 1 + 2\sum_{b \text{ square} \neq 0}\zeta^b = 1 + \sum_{b\neq0}\Bigl(1 + \Bigl(\frac bp\Bigr)\Bigr) \zeta^b = \sum_{b}\zeta^b + g = g,

using 1+(bp)=#{a:a2=b}1 + \bigl(\frac bp\bigr) = \#\{a : a^2 = b\} and b=0p1ζb=0\sum_{b=0}^{p-1}\zeta^b = 0. For p=17p = 17: the squares mod 1717 are the even powers of the generator 33, i.e. the exponents appearing in η0\eta_0 (Part II), so g=even kζ3kodd kζ3k=η0η1g = \sum_{\text{even }k}\zeta^{3^k} - \sum_{\text{odd }k} \zeta^{3^k} = \eta_0 - \eta_1.

15. With b=cab = c - a (a,ba, b run over nonzero residues, c=a+bc = a + b over all residues):

g2=cζca0,ac(a(ca)p).g^2 = \sum_c\zeta^c\sum_{a\neq0,\,a\neq c} \Bigl(\frac{a(c-a)}p\Bigr) .

For c=0c = 0: (a2p)=(1p)\bigl(\frac{-a^2}p\bigr) = \bigl(\frac{-1}p\bigr), summed over p1p - 1 values. For c0c \neq 0: substitute ca=atc - a = at, i.e. t=c/a1t = c/a - 1; as aa runs over the nonzero residues, tt runs bijectively over the residues 1\neq -1 (invert: a=c/(1+t)a = c/(1 + t)). The summand becomes (a2tp)=(tp)\bigl(\frac{a^2t}p\bigr) = \bigl(\frac tp\bigr), and

t1(tp)=(1p)\sum_{t \neq -1}\Bigl(\frac tp\Bigr) = -\Bigl(\frac{-1}p\Bigr)

(the full sum vanishes by question 14). Hence

g2=(1p)[(p1)c0ζc]=(1p)p=p,g^2 = \Bigl(\frac{-1}p\Bigr)\Bigl[(p-1) - \sum_{c\neq0}\zeta^c\Bigr] = \Bigl(\frac{-1}p\Bigr)\,p = p^* ,

using c0ζc=1\sum_{c\neq0}\zeta^c = -1 and Euler’s criterion (1p)=(1)(p1)/2\bigl(\frac{-1}p\bigr) = (-1)^{(p-1)/2}. For p=17p = 17: (η0η1)2=(η0+η1)24η0η1=1+16=17(\eta_0 - \eta_1)^2 = (\eta_0 + \eta_1)^2 - 4\eta_0\eta_1 = 1 + 16 = 17, matching Part II.

16. g2=pg^2 = p^* exhibits p=±gQ(ζp)\sqrt{p^*} = \pm g \in \Q(\zeta_p), so Q(p)\Q(\sqrt{p^*}) is a quadratic subfield. Uniqueness: subfields of degree 22 correspond, by the Galois correspondence, to subgroups of index 22 of the cyclic Gal(Q(ζp)/Q)(Z/pZ)×\operatorname{Gal}(\Q(\zeta_p)/\Q) \cong (\Z/p\Z)^\times, and a cyclic group of even order has exactly one such subgroup (the squares). Every quadratic field is Q(d)\Q(\sqrt{d}) with dd squarefree, and combining the fields Q(p)\Q(\sqrt{p^*}), Q(i)Q(ζ4)\Q(\iu) \subseteq \Q(\zeta_4) and Q(2)Q(ζ8)\Q(\sqrt2) \subseteq \Q(\zeta_8) inside a common Q(ζN)\Q(\zeta_N) captures every d\sqrt d: the quadratic case of Kronecker–Weber.

17. In any commutative ring, (x+y)q=xq+yq+q()(x + y)^q = x^q + y^q + q(\cdots): the binomial coefficients (qk)\binom qk, 0<k<q0 < k < q, are divisible by the prime qq. Iterating on the p1p - 1 terms of gg:

gqa(ap)qζaq=a(ap)ζaq(modqZ[ζ]),g^q \equiv \sum_{a}\Bigl(\frac ap\Bigr)^{q}\zeta^{aq} = \sum_a\Bigl(\frac ap\Bigr)\zeta^{aq} \pmod{q\Z[\zeta]},

(qq odd: the symbol is unchanged). Reindex b=aqb = aq: a=q1ba = q^{-1}b and (q1bp)=(qp)(bp)\bigl(\frac{q^{-1}b}p\bigr) = \bigl(\frac{q}p\bigr)\bigl(\frac bp\bigr) (multiplicativity; (q1p)=(qp)\bigl(\frac{q^{-1}}p\bigr) = \bigl(\frac qp\bigr) since the symbol of an inverse equals the symbol): gq(qp)gg^q \equiv \bigl(\frac qp\bigr)g.

18. gq=g(g2)(q1)/2=g(p)(q1)/2g^q = g\,(g^2)^{(q-1)/2} = g\,(p^*)^{(q-1)/2} exactly (question 15), and Euler’s criterion in Z\Z gives (p)(q1)/2(pq)(modq)(p^*)^{(q-1)/2} \equiv \bigl(\frac{p^*}q\bigr) \pmod q, hence mod qZ[ζ]q\Z[\zeta]: gq(pq)gg^q \equiv \bigl(\frac{p^*}q\bigr)g. Comparing with question 17 and multiplying by gg:

(qp)p(pq)p(modqZ[ζ]).\Bigl(\frac qp\Bigr)p^* \equiv \Bigl(\frac{p^*}q\Bigr)p^* \pmod{q\Z[\zeta]} .

Both sides are rational integers; their difference, 00 or ±2p\pm2p^*, lies in qZ[ζ]Z=qZq\Z[\zeta] \cap \Z = q\Z (an integer mqZ[ζ]m \in q\Z[\zeta] has m/qQZ[ζ]=Zm/q \in \Q \cap \Z[\zeta] = \Z, the latter because 1,ζ,,ζp21, \zeta, \dots, \zeta^{p-2} is a Q\Q-basis with rational coordinates reading off integrality). Since q2pq \nmid 2p^* (qq odd, qpq \neq p), the difference is 00: (qp)=(pq)\bigl(\frac qp\bigr) = \bigl(\frac{p^*}q\bigr).

19. By multiplicativity, (pq)=(1q)(p1)/2(pq)=(1)q12p12(pq)\bigl(\frac{p^*}q\bigr) = \bigl(\frac{-1}q\bigr)^{(p-1)/2}\bigl(\frac pq\bigr) = (-1)^{\frac{q-1}2\cdot\frac{p-1}2}\bigl(\frac pq\bigr), so question 18 reads (qp)(pq)=(1)p12q12\bigl(\frac qp\bigr)\bigl(\frac pq\bigr) = (-1)^{\frac{p-1}2\frac{q-1}2}: reciprocity. Check (17,3)(17, 3): the exponent 16222=8\frac{16}2\cdot\frac22 = 8 is even, so the two symbols must agree; squares mod 33 are {1}\{1\} and 17217 \equiv 2: (173)=1\bigl(\frac{17}3\bigr) = -1; squares mod 1717 are {1,4,9,16,8,2,15,13}\{1, 4, 9, 16, 8, 2, 15, 13\} and 33 is absent: (317)=1\bigl(\frac3{17}\bigr) = -1. Product +1+1, as predicted. For x2219(mod383)x^2 \equiv 219 \pmod{383}: (219383)=(3383)(73383)\bigl(\frac{219}{383}\bigr) = \bigl(\frac3{383}\bigr)\bigl(\frac{73}{383}\bigr). First: 3833(mod4)383 \equiv 3 \pmod4 and 333 \equiv 3: reciprocity gives (3383)=(3833)=(23)=(1)=+1\bigl(\frac3{383}\bigr) = -\bigl(\frac{383}3\bigr) = -\bigl(\frac23\bigr) = -(-1) = +1. Second: 731(mod4)73 \equiv 1 \pmod 4: (73383)=(38373)=(1873)=(273)\bigl(\frac{73}{383}\bigr) = \bigl(\frac{383}{73}\bigr) = \bigl(\frac{18}{73}\bigr) = \bigl(\frac2{73}\bigr) (18=23218 = 2\cdot3^2), and 731(mod8)73 \equiv 1 \pmod 8 makes 22 a square mod 7373 (supplementary law, provable by g=ζ8+ζ81=2g = \zeta_8 + \zeta_8^{-1} = \sqrt2 in Q(ζ8)\Q(\zeta_8) by the same method): +1+1. Total +1+1: the congruence is solvable.

20. Existence and uniqueness of the primitive root: if ww has period set {d:w=un/d, u=d}\{d : w = u^{n/d},\ \abs u = d\}, the minimal such d0d_0 divides every other period dd (if ww is both a dd-power and a dd'-power, it is a gcd(d,d)\gcd(d, d')-power: compare letters at indices agreeing modulo the gcd, via Bézout), and the length-d0d_0 block is primitive. Sorting the qnq^n words by the length of their primitive root: qn=dnA(d)q^n = \sum_{d \mid n}A(d). Since AA and dNq(d)d\,N_q(d) satisfy the same recursion with the same values for n=1n = 1 (both determine each other inductively from qn=dn()q^n = \sum_{d\mid n}(\cdot)), they are equal: A(d)=dNq(d)A(d) = d\,N_q(d). Bijection: an element α\alpha of degree dd yields the word wαw_\alpha of the coefficients of… better, directly: elements of degree dd in Fq\overline{\mathbb F_q} are the roots of the Nq(d)N_q(d) irreducibles of degree dd, each contributing its dd distinct roots (separability): dNq(d)d\,N_q(d) elements of degree dd, matching the count qn=dn#{elements of degree d in Fqn}q^n = \sum_{d\mid n}\#\{ \text{elements of degree } d \text{ in } \mathbb F_{q^n}\} — the same sieve, once on words, once on field elements.

21. Lemma: dmμ(d)=1m=1\sum_{d \mid m}\mu(d) = \mathbf 1_{m=1}. For m>1m > 1 fix a prime pmp \mid m: squarefree divisors of mm pair off as {d,pd}\{d, pd\} with pdp \nmid d, and μ(pd)=μ(d)\mu(pd) = -\mu(d): the sum cancels. Then, for f(n)=eng(e)f(n) = \sum_{e\mid n}g(e):

dnμ(d)f(nd)=dnμ(d) ⁣ ⁣en/d ⁣ ⁣g(e)=eng(e) ⁣ ⁣dn/e ⁣ ⁣μ(d)=g(n).\sum_{d \mid n}\mu(d)\,f\bigl(\tfrac nd\bigr) = \sum_{d \mid n}\mu(d)\!\!\sum_{e \mid n/d}\!\!g(e) = \sum_{e \mid n}g(e)\!\!\sum_{d \mid n/e}\!\!\mu(d) = g(n) .

With f(n)=qnf(n) = q^n and g(n)=nNq(n)g(n) = nN_q(n) (Exercise 4.6): Nq(n)=1ndnμ(d)qn/dN_q(n) = \frac1n\sum_{d\mid n}\mu(d)\,q^{n/d}.

22. The d=1d = 1 term is qnq^n; every other term has μ(d)qn/dqn/2\abs{\mu(d)q^{n/d}} \leq q^{n/2}, and crudely dn,d>1qn/djn/2qj<2qn/2\sum_{d \mid n, d > 1}q^{n/d} \leq \sum_{j \leq n/2}q^j < 2q^{n/2} (geometric, q2q \geq 2). So nNq(n)>qn2qn/20nN_q(n) > q^n - 2q^{n/2} \geq 0 for n1n \geq 1: irreducibles of every degree exist, and Fq[X]/(π)=Fqn\mathbb F_q[X]/(\pi) = \mathbb F_{q^n} is (re)built — existence with a census. The proportion of irreducibles among the qnq^n monic degree-nn polynomials is 1n(1+O(qn/2))\frac1n(1 + O(q^{-n/2})): the prime number theorem of Fq[X]\mathbb F_q[X], with nn playing logx\log x. For q=2q = 2 the counts 2,1,2,32, 1, 2, 3 of Exercise 4.6 match the formula: e.g. N2(4)=14(2422)=3N_2(4) = \frac14(2^4 - 2^2) = 3.

23. In the multiplicative abelian group of nonzero rational functions over Fq\mathbb F_q, set F(n)=XqnXF(n) = X^{q^n} - X and G(n)=degπ=nπG(n) = \prod_{\deg\pi = n}\pi; Exercise 4.6 says F(n)=dnG(d)F(n) = \prod_{d\mid n}G(d). The Möbius argument of question 21, written multiplicatively (exponents add exactly as the sums did), gives G(n)=dnF(d)μ(n/d)G(n) = \prod_{d \mid n}F(d)^{\mu(n/d)}. For q=2q = 2, n=2n = 2: G(2)=X4XX2X=X(X31)X(X1)=X2+X+1G(2) = \frac{X^4 - X}{X^2 - X} = \frac{X(X^3 - 1)}{X(X - 1)} = X^2 + X + 1, the unique irreducible quadratic over F2\mathbb F_2, as it must be.

24. ω2=i\omega^2 = \iu and ω2=i\omega^{-2} = -\iu, so g2=ω2+2+ω2=2g^2 = \omega^2 + 2 + \omega^{-2} = 2. Freshman’s dream in the commutative ring Z[ω]/qZ[ω]\Z[\omega]/q\Z[\omega]: gq=(ω+ω1)qωq+ωqg^q = (\omega + \omega^{-1})^q \equiv \omega^q + \omega^{-q}. The value of ωq+ωq\omega^q + \omega^{-q} depends only on qmod8q \bmod 8: for q±1q \equiv \pm1, ωq+ωq=ω±1+ω1=g\omega^q + \omega^{-q} = \omega^{\pm1} + \omega^{\mp1} = g; for q±3q \equiv \pm3, using ω4=1\omega^4 = -1, ω3=ω1\omega^{3} = -\omega^{-1} and ω3=ω\omega^{-3} = -\omega, so ωq+ωq=g\omega^q + \omega^{-q} = -g. On the other hand gq=g(g2)(q1)/2=g2(q1)/2(2q)g(modqZ[ω])g^q = g\,(g^2)^{(q-1)/2} = g\,2^{(q-1)/2} \equiv \bigl(\frac2q\bigr) g \pmod{q\Z[\omega]} by Euler’s criterion mod qq. Comparing and multiplying by gg: 2(2q)±2(modqZ[ω])2\bigl(\frac2q\bigr) \equiv \pm2 \pmod{q\Z[\omega]}; if the signs disagreed, qq would divide 44 in Z[ω]\Z[\omega], hence in Z\Z (qZ[ω]Z=qZq\Z[\omega] \cap \Z = q\Z: coordinates on the basis 1,ω,ω2,ω31, \omega, \omega^2, \omega^3), impossible for qq odd. So (2q)=+1\bigl(\frac2q\bigr) = +1 iff q±1(mod8)q \equiv \pm1 \pmod 8. Parity check: q=8k±1q = 8k \pm 1 gives (q21)/8=2k(4k±1)(q^2 - 1)/8 = 2k(4k \pm 1), even; q=8k±3q = 8k \pm 3 gives (q21)/8=8k2±6k+1(q^2 - 1)/8 = 8k^2 \pm 6k + 1, odd: the formula (1)(q21)/8(-1)^{(q^2-1)/8} encodes the case split. Numerically: 32=92(mod7)3^2 = 9 \equiv 2 \pmod 7 (717 \equiv -1), 62=362(mod17)6^2 = 36 \equiv 2 \pmod{17} (17117 \equiv 1); the squares mod 33 are {0,1}\{0, 1\} and mod 55 are {0,1,4}\{0, 1, 4\}, neither containing 22 (333 \equiv 3, 53(mod8)5 \equiv -3 \pmod 8).

25. Every monic fFq[X]f \in \mathbb F_q[X] factors uniquely as ππeπ\prod_\pi\pi^{e_\pi} over the monic irreducibles: sorting by degree,

f monictdegf=π e0tedegπ=π(1tdegπ)1=n1(1tn)Nq(n),\sum_{f \text{ monic}}t^{\deg f} = \prod_\pi\ \sum_{e \geq 0}t^{e\deg\pi} = \prod_\pi\bigl(1 - t^{\deg\pi}\bigr)^{-1} = \prod_{n \geq 1}\bigl(1 - t^n\bigr)^{-N_q(n)},

all products t-adically legitimate (only degrees m\leq m touch the coefficient of tmt^m, and there are finitely many irreducibles of each degree). The left side is mqmtm=(1qt)1\sum_m q^mt^m = (1 - qt)^{-1}: the identity. Logarithms: log(1qt)=mqmmtm-\log(1 - qt) = \sum_m\frac{q^m}mt^m, while nNq(n)(log(1tn))=nNq(n)ktnkk\sum_nN_q(n)\bigl(-\log(1 - t^n)\bigr) = \sum_nN_q(n)\sum_k\frac{t^{nk}}k; the coefficient of tmt^m gives qmm=dk=mNq(d)k=1mdmdNq(d)\frac{q^m}m = \sum_{dk = m} \frac{N_q(d)}k = \frac1m\sum_{d \mid m}d\,N_q(d), i.e. qm=dmdNq(d)q^m = \sum_{d\mid m}d\,N_q(d). Hand check, q=2q = 2, coefficient of t2t^2: N2(1)=2N_2(1) = 2, N2(2)=1N_2(2) = 1, and (1t)2(1t2)1=(1+2t+3t2+)(1+t2+)(1 - t)^{-2}(1 - t^2)^{-1} = (1 + 2t + 3t^2 + \dots)(1 + t^2 + \dots) has t2t^2-coefficient 3+1=4=223 + 1 = 4 = 2^2. Finally, question 21’s formula with the divisors 1,2,3,61, 2, 3, 6:

N2(6)=16(262322+2)=546=9,N_2(6) = \tfrac16\bigl(2^6 - 2^3 - 2^2 + 2\bigr) = \tfrac{54}6 = 9,

and indeed 12+21+32+69=2+2+6+54=64=261\cdot2 + 2\cdot1 + 3\cdot2 + 6\cdot9 = 2 + 2 + 6 + 54 = 64 = 2^6.