Cyclotomic Fields
Introduction
The $n$-th roots of unity are the roots of $x^n - 1$, and the field they generate over the prime field is the $n$-th cyclotomic field. Over $\mathbb{Q}$ this field has degree $\varphi(n)$, its Galois group is the group $(\mathbb{Z}/n\mathbb{Z})^\times$ of units modulo $n$ acting by $\zeta \mapsto \zeta^k$, and it is therefore abelian over $\mathbb{Q}$; the Kronecker–Weber theorem says that these are the only abelian extensions of $\mathbb{Q}$. Over a field of characteristic $p$ the same polynomials govern the arithmetic of the prime $p$, since $x^n - 1$ has multiple roots exactly when $p$ divides $n$.
The cyclotomic fields are the first family of number fields for which everything can be computed: the ring of integers is $\mathbb{Z}[\zeta_n]$ itself, the ramified primes are exactly the divisors of $n$, and the splitting of an unramified prime is decided by the order of $p$ modulo $n$. They are also the source of the reciprocity laws: the quadratic reciprocity law is a statement about the quadratic subfield of a cyclotomic field, and the Kronecker–Weber theorem, that every abelian extension of $\mathbb{Q}$ is a subfield of a cyclotomic field, is proved.
This article develops the cyclotomic polynomial and its irreducibility over $\mathbb{Q}$, the Galois group of the cyclotomic field, the subfield lattice with the quadratic subfields in the prime case, the ring of integers, ramification and splitting, the norm of $1 - \zeta$, and the cyclotomic units. Throughout, $\zeta_n$ denotes a primitive $n$-th root of unity, so that the $n$-th roots of unity are $1, \zeta_n, \ldots, \zeta_n^{n-1}$ and $\zeta_n$ generates them as a group; $\varphi$ is the Euler totient function. Field extensions, splitting fields and algebraic closure are from Field Extensions and Splitting Fields and Algebraic Closure; the Galois correspondence is from Galois Theory, which also records the computation of the Galois group of $\mathbb{Q}(\zeta_n)$ used here; finite fields are from Finite Fields; unique factorisation and Eisenstein's criterion from Unique Factorisation Domains; and Dedekind domains, ramification and the ideal class group from Dedekind Domains and Ideal Class Groups. The constructibility of the regular $n$-gon is a statement about a plane and a compass and belongs to Part II; it is named here only to defer it.
Roots of Unity
The Group of Roots of Unity
Definition. Let $K$ be a field and $n \geq 1$ an integer. An element $\zeta \in K$ is an $n$-th root of unity if $\zeta^n = 1$; it is primitive if its multiplicative order is exactly $n$.
Proposition. The $n$-th roots of unity in $K$ form a cyclic subgroup $\mu_n(K)$ of $K^\times$. It has order $n$ if and only if $x^n - 1$ has $n$ distinct roots in $K$; if $\operatorname{char} K = p$ divides $n$, then $x^n - 1$ has fewer than $n$ distinct roots, and writing $n = p^v m$ with $p \nmid m$ the distinct roots are exactly the elements of $\mu_m(K)$.
Proof. The set of $n$-th roots of unity is a finite subgroup of $K^\times$, and every finite subgroup of the multiplicative group of a field is cyclic, by the argument that a finite abelian group with at most $d$ solutions of $x^d = 1$ for every $d$ is cyclic. Hence $\mu_n(K)$ is cyclic and has order equal to the number of distinct roots of $x^n - 1$. The derivative of $x^n - 1$ is $nx^{n-1}$, which vanishes identically when $p \mid n$, so $x^n - 1 = (x^m - 1)^{p^v}$ in characteristic $p$ with $p^v(x^m-1)^{p^v-1}$ as derivative, and the distinct roots are those of $x^m - 1$.
Proposition. A field $K$ contains a primitive $n$-th root of unity if and only if $n$ divides $\lvert K^\times \rvert$ when $K$ is finite, and if and only if $x^n - 1$ splits in $K$ with $n$ distinct roots when $\operatorname{char} K \nmid n$. Over a finite field $\mathbb{F}_q$, the group $\mu_n(\mathbb{F}_q)$ has order $\gcd(n, q - 1)$, and a primitive $n$-th root of unity lies in $\mathbb{F}_{q^f}$ exactly when $n \mid q^f - 1$.
Proof. A cyclic group of order $q-1$ has a subgroup of order $n$ exactly when $n \mid q-1$, and that subgroup is $\mu_n(\mathbb{F}_q)$. For the last statement, $\mathbb{F}_{q^f}^\times$ is cyclic of order $q^f - 1$.
Example. In $\mathbb{C}$ the group of $n$-th roots of unity is the group generated by $e^{2\pi i/n}$, and it is cyclic of order $n$. The identification of $\mathbb{C}$ as a field is that of The Complex Numbers; only the field structure and the equation $x^n = 1$ are used here.
Example. In $\mathbb{Q}$ the only roots of unity are $\pm 1$; in $\mathbb{R}$ the same. In a finite field $\mathbb{F}_q$ every nonzero element is a root of unity, so the roots of unity form the cyclic group $\mathbb{F}_q^\times$ of order $q-1$. Over a field with a discrete valuation whose residue field has characteristic $p$, the roots of unity of order prime to $p$ are exactly the lifts of the roots of unity of the residue field, by Hensel's lemma in the form given in Valuation Theory and Henselian Rings.
The Cyclotomic Polynomial
Definition. For $n \geq 1$ the $n$-th cyclotomic polynomial is
$$ \Phi_n(x) = \prod_{\substack{1 \leq k \leq n \\ \gcd(k,n) = 1}} (x - \zeta_n^k), $$
the product over the primitive $n$-th roots of unity in a splitting field of $x^n - 1$. It has degree $\varphi(n)$, the number of integers $1 \leq k \leq n$ coprime to $n$.
Proposition. For every $n \geq 1$,
$$ x^n - 1 = \prod_{d \mid n} \Phi_d(x), $$
the product over the positive divisors of $n$. Consequently $\Phi_n(x) \in \mathbb{Z}[x]$, is monic of degree $\varphi(n)$, and satisfies $\sum_{d \mid n} \varphi(d) = n$.
Proof. Every $n$-th root of unity is a primitive $d$-th root of unity for exactly one $d \mid n$, namely $d$ equal to its order; grouping the linear factors of $x^n - 1$ by this order gives the displayed product. The polynomial $\Phi_n$ is then determined by induction on $n$ from the division $x^n - 1 = \Phi_n(x) \prod_{d \mid n, d < n} \Phi_d(x)$: since the divisor on the right is monic with integer coefficients by induction, the quotient has integer coefficients. The degree statement follows from the sum formula, which is the count $\sum_{d\mid n}\varphi(d) = n$.
Corollary. $\Phi_1(x) = x - 1$, $\Phi_2(x) = x + 1$, and for a prime $p$, $\Phi_p(x) = (x^p-1)/(x-1) = x^{p-1} + x^{p-2} + \cdots + x + 1$ and $\Phi_{p^v}(x) = \Phi_p(x^{p^{v-1}})$. The constant term is $\Phi_n(0) = -1$ for $n = 1$ and $\Phi_n(0) = 1$ for every $n \geq 2$; the value at $1$ is $\Phi_n(1) = p$ when $n = p^v$ is a prime power and $\Phi_n(1) = 1$ when $n$ is divisible by two distinct primes.
Proof. The prime case is immediate. For $n = p^v$ the divisors are $1, p, \ldots, p^v$, so $x^{p^v}-1 = \prod_{j=0}^{v} \Phi_{p^j}(x)$; comparing with $x^{p^v} - 1 = (x^{p^{v-1}})^p - 1 = (x^{p^{v-1}}-1)\Phi_p(x^{p^{v-1}})$ and inducting gives $\Phi_{p^v}(x) = \Phi_p(x^{p^{v-1}})$, whence $\Phi_{p^v}(1) = \Phi_p(1) = p$. For the constant term, $\Phi_n(0) = \prod_{k}(-\zeta_n^k) = (-1)^{\varphi(n)}\zeta_n^{\sum k}$, the sum over $k \in (\mathbb{Z}/n\mathbb{Z})^\times$; for $n \geq 3$ the pairs $k$ and $n-k$ sum to $n$, so $\sum k = n\varphi(n)/2$ and $\zeta_n^{\sum k} = (\zeta_n^n)^{\varphi(n)/2} = 1$, while $\varphi(n)$ is even; for $n = 2$ the product is $-\zeta_2 = 1$; for $n = 1$ it is $-1$. Finally, if $n = pm$ with $p \nmid m$ and $m > 1$ one has the identity $\Phi_n(x) = \Phi_m(x^p)/\Phi_m(x)$, obtained by dividing the two instances of $x^r - 1 = \prod_{d\mid r}\Phi_d$; evaluating at $x = 1$, where $\Phi_m(1) \neq 0$, gives $\Phi_n(1) = 1$ whenever $n$ is not a prime power.
The values $\Phi_1$ to $\Phi_{12}$ are the following.
| $n$ | $\Phi_n(x)$ |
|---|---|
| $1$ | $x - 1$ |
| $2$ | $x + 1$ |
| $3$ | $x^2 + x + 1$ |
| $4$ | $x^2 + 1$ |
| $5$ | $x^4 + x^3 + x^2 + x + 1$ |
| $6$ | $x^2 - x + 1$ |
| $7$ | $x^6 + x^5 + x^4 + x^3 + x^2 + x + 1$ |
| $8$ | $x^4 + 1$ |
| $9$ | $x^6 + x^3 + 1$ |
| $10$ | $x^4 - x^3 + x^2 - x + 1$ |
| $11$ | $x^{10} + x^9 + \cdots + x + 1$ |
| $12$ | $x^4 - x^2 + 1$ |
Theorem (irreducibility over $\mathbb{Q}$). The cyclotomic polynomial $\Phi_n(x)$ is irreducible in $\mathbb{Q}[x]$, and hence is the minimal polynomial of every primitive $n$-th root of unity over $\mathbb{Q}$.
Proof. Since $\Phi_n$ is monic with integer coefficients, Gauss's lemma applied to $\mathbb{Z}[x]$ shows it suffices to prove that $\Phi_n$ is irreducible in $\mathbb{Z}[x]$. Let $f \in \mathbb{Z}[x]$ be the monic irreducible factor of $\Phi_n$ with $f(\zeta_n) = 0$, so that $f$ divides $\Phi_n$ and hence divides $x^n - 1$. Write $\zeta = \zeta_n$ and $\Phi_n = f h$ with $h \in \mathbb{Z}[x]$ monic. It is enough to prove that $f(\zeta^p) = 0$ for every prime $p \nmid n$, because then $\zeta^k$ is a root of $f$ for every $k$ coprime to $n$ — each such $k$ being a product of primes not dividing $n$ — so $\deg f \geq \varphi(n) = \deg \Phi_n$ and $f = \Phi_n$ up to sign.
Suppose therefore that $p \nmid n$ and $f(\zeta^p) \neq 0$. Since $\zeta^p$ is a primitive $n$-th root of unity, $\Phi_n(\zeta^p) = 0$, and as $f(\zeta^p) \neq 0$ we get $h(\zeta^p) = 0$. Hence $\zeta$ is a root of $h(x^p)$, and since $f$ is the minimal polynomial of $\zeta$ over $\mathbb{Q}$ and $h(x^p) \in \mathbb{Z}[x]$, Gauss's lemma gives that $f$ divides $h(x^p)$ in $\mathbb{Z}[x]$. Reduction modulo $p$ is a ring homomorphism $\mathbb{Z}[x] \to \mathbb{F}_p[x]$, and in $\mathbb{F}_p[x]$ the Frobenius identity gives $\bar h(x^p) = \bar h(x)^p$. Therefore
$$ \bar f \mid \bar h^{\,p} \quad \text{in } \mathbb{F}_p[x]. $$
Let $\varphi$ be an irreducible factor of $\bar f$ in the unique factorisation domain $\mathbb{F}_p[x]$; since $\bar f$ is nonconstant and $\mathbb{F}_p[x]$ is a unique factorisation domain, $\varphi$ is irreducible and $\varphi \mid \bar h^{\,p}$, hence $\varphi \mid \bar h$. On the other hand $f h = \Phi_n$ and $\Phi_n \mid x^n - 1$, so $\bar f \bar h = \overline{\Phi_n}$ divides $x^n - \bar 1$ in $\mathbb{F}_p[x]$; since $\varphi$ divides both $\bar f$ and $\bar h$, the square $\varphi^2$ divides $\bar f \bar h$ and therefore divides $x^n - 1$. But $x^n - 1$ is separable over $\mathbb{F}_p$ when $p \nmid n$, because its derivative $n x^{n-1}$ has no root in common with $x^n - 1$: a common root $\alpha$ would satisfy $\alpha^{n-1} = 0$ and hence $\alpha = 0$, which is not a root of $x^n - 1$. A separable polynomial has no repeated irreducible factor. This contradiction proves $f(\zeta^p) = 0$.
Corollary. $\mathbb{Q}(\zeta_n)$ has degree $\varphi(n)$ over $\mathbb{Q}$ for every $n$, and $\Phi_n$ is the minimal polynomial of $\zeta_n$. For positive integers $m, n$, with $\zeta_1 = 1$ so that $\mathbb{Q}(\zeta_1) = \mathbb{Q}(\zeta_2) = \mathbb{Q}$,
$$ \mathbb{Q}(\zeta_m) \cap \mathbb{Q}(\zeta_n) = \mathbb{Q}(\zeta_{\gcd(m,n)}), $$
so two cyclotomic fields intersect in $\mathbb{Q}$ exactly when $m$ and $n$ are coprime.
Remark. The proof used only that a finite subgroup of the multiplicative group of a field is cyclic, Gauss's lemma, and the separability of $x^n-1$ modulo a prime not dividing $n$. It is the standard proof of Dedekind and it does not require the factorization of $n$.
The Galois Group
Automorphisms
Theorem. Let $K = \mathbb{Q}(\zeta_n)$. Then $K/\mathbb{Q}$ is a Galois extension with
$$ \operatorname{Gal}(K/\mathbb{Q}) \cong (\mathbb{Z}/n\mathbb{Z})^\times, $$
the isomorphism sending $k \in (\mathbb{Z}/n\mathbb{Z})^\times$ to the automorphism $\sigma_k$ determined by $\sigma_k(\zeta_n) = \zeta_n^k$. In particular $\operatorname{Gal}(\mathbb{Q}(\zeta_n)/\mathbb{Q})$ is abelian of order $\varphi(n)$, and its exponent divides $\lambda(n)$, the exponent of $(\mathbb{Z}/n\mathbb{Z})^\times$.
Proof. $K$ is the splitting field of $x^n - 1$ over $\mathbb{Q}$, hence normal; $x^n-1$ is separable over $\mathbb{Q}$ since $\operatorname{char}\mathbb{Q} = 0$, so $K/\mathbb{Q}$ is Galois. Every $\sigma \in \operatorname{Gal}(K/\mathbb{Q})$ sends $\zeta_n$ to another root of $\Phi_n$, that is, to $\zeta_n^k$ for a unique $k \in (\mathbb{Z}/n\mathbb{Z})^\times$; conversely, since $\Phi_n$ is irreducible, for each such $k$ there is a $\mathbb{Q}$-automorphism of $K$ sending $\zeta_n$ to $\zeta_n^k$. The map $k \mapsto \sigma_k$ is a group homomorphism $(\mathbb{Z}/n\mathbb{Z})^\times \to \operatorname{Gal}(K/\mathbb{Q})$ and a bijection, hence an isomorphism.
Corollary. When $(\mathbb{Z}/n\mathbb{Z})^\times$ is cyclic, $K$ has exactly one subfield of each degree dividing $\varphi(n)$; in particular it has exactly $\tau(\varphi(n))$ subfields, where $\tau$ is the divisor-counting function. For $n$ a prime $p$ the group $(\mathbb{Z}/p\mathbb{Z})^\times$ is cyclic of order $p-1$, and the subfields of $\mathbb{Q}(\zeta_p)$ correspond bijectively to the divisors of $p-1$.
Proof. The subgroups of a cyclic group of order $m$ correspond to the divisors of $m$, one of each order; the Galois correspondence of Galois Theory turns this into the statement about subfields.
Example. For $n = 4$, $K = \mathbb{Q}(i)$ and $\operatorname{Gal}(K/\mathbb{Q}) = \{1, \sigma\}$ with $\sigma(i) = -i$, the complex conjugation; the fixed field of the whole group is $\mathbb{Q}$ and the unique proper subfield over which $K$ is quadratic is $\mathbb{Q}$ itself in degree $1$.
Example. For $n = 8$, $\zeta_8 = (1+i)/\sqrt2$ and $K = \mathbb{Q}(i, \sqrt2)$, of degree $4$ over $\mathbb{Q}$ with group $(\mathbb{Z}/8\mathbb{Z})^\times \cong \mathbb{Z}/2 \times \mathbb{Z}/2$. The three quadratic subfields are $\mathbb{Q}(i)$, $\mathbb{Q}(\sqrt2)$ and $\mathbb{Q}(\sqrt{-2})$.
Example. For $n = 12$, $\zeta_{12}$ has minimal polynomial $x^4 - x^2 + 1$ and $K = \mathbb{Q}(i, \sqrt3)$, again of degree $4$ with group $\mathbb{Z}/2 \times \mathbb{Z}/2$; the quadratic subfields are $\mathbb{Q}(i)$, $\mathbb{Q}(\sqrt3)$ and $\mathbb{Q}(\sqrt{-3})$.
Quadratic Subfields
Theorem. Let $p$ be an odd prime and put $p^\ast = (-1)^{(p-1)/2} p$. Then $\mathbb{Q}(\zeta_p)$ contains the quadratic field $\mathbb{Q}(\sqrt{p^\ast})$, which is its unique quadratic subfield.
Proof. The group $(\mathbb{Z}/p\mathbb{Z})^\times$ is cyclic of order $p-1$, hence has a unique subgroup of index $2$, the squares modulo $p$; the corresponding subfield is the fixed field of the squares, of degree $2$ over $\mathbb{Q}$. Its discriminant is known to be $p^\ast$: the unique quadratic subfield of $\mathbb{Q}(\zeta_p)$ is ramified precisely at $p$ (the primes ramified in $\mathbb{Q}(\zeta_p)$ being the divisors of $p$), and a quadratic field $\mathbb{Q}(\sqrt{d})$ ramified only at $p$ has $d = p^\ast$ up to squares.
Corollary. The field $\mathbb{Q}(\zeta_p)$ has exactly one quadratic subfield for each prime $p$, since $\mathbb{Z}/(p-1)$ has a unique subgroup of index $2$; for $p = 5$ it is $\mathbb{Q}(\sqrt5)$, for $p = 3$ it is $\mathbb{Q}(\sqrt{-3})$, and for $p = 7$ it is $\mathbb{Q}(\sqrt{-7})$.
Theorem (the Gauss sum identity). For $p$ an odd prime, the quadratic Gauss sum
$$ g = \sum_{k=1}^{p-1} \left(\frac{k}{p}\right) \zeta_p^k, $$
where $\left(\frac{\cdot}{p}\right)$ is the Legendre symbol, satisfies $g^2 = p^\ast$ in $\mathbb{Z}[\zeta_p]$.
Proof sketch. The standard computation gives $g^2 = \left(\frac{-1}{p}\right) p$ by a change of variables $k \mapsto k + a$ and an evaluation of the resulting multiplicativity of the symbol; for $p \equiv 1 \pmod 4$ one gets $g^2 = p$ and for $p \equiv 3 \pmod 4$ one gets $g^2 = -p$, uniformly $g^2 = p^\ast$.
Thus $\sqrt{p^\ast} = g \in \mathbb{Z}[\zeta_p]$, which exhibits the quadratic subfield concretely inside the cyclotomic field. This identity is the seed of the quadratic reciprocity law: the automorphism $\sigma_k$ of $\mathbb{Q}(\zeta_p)$ acts on $g$ by a factor $\left(\frac{k}{p}\right)$, and comparing this with the action of the Frobenius at a prime $q \neq p$ gives $\left(\frac{p}{q}\right) = \left(\frac{q}{p}\right)$ up to the sign $(-1)^{(p-1)(q-1)/4}$; the general formulation and the higher reciprocity laws are.
Arithmetic in Cyclotomic Fields
The Ring of Integers
Theorem. Let $K = \mathbb{Q}(\zeta_n)$, $n \geq 1$. The ring of integers of $K$ is
$$ \mathcal{O}_K = \mathbb{Z}[\zeta_n], $$
the smallest subring of $K$ containing $\mathbb{Z}$ and $\zeta_n$. Consequently $\{1, \zeta_n, \ldots, \zeta_n^{\varphi(n)-1}\}$ is an integral basis of $K$ over $\mathbb{Q}$, and $\mathcal{O}_K$ is a Dedekind domain in the sense of Dedekind Domains and Ideal Class Groups.
Proof sketch. Let $\zeta = \zeta_n$ and $\Phi = \Phi_n$. The ring $\mathbb{Z}[\zeta] \cong \mathbb{Z}[x]/(\Phi)$ is contained in $\mathcal{O}_K$ and is a Noetherian domain. To see that it is integrally closed it suffices to show it is integrally closed in $K$; one shows that $\Phi$ is a Kronecker polynomial, meaning that for every root $\zeta'$ of $\Phi$ and every $k$, the quotients $(\zeta'^k - \zeta^k)/(\zeta' - \zeta)$ lie in $\mathbb{Z}[\zeta][\zeta']$, and then the elementary symmetric functions of the conjugates of a purported integral element force it back into $\mathbb{Z}[\zeta]$ — this is Dedekind's argument. Alternatively one shows the discriminant of the basis $\{1, \zeta, \ldots, \zeta^{\varphi(n)-1}\}$ is the squarefree part times a power of $n$, and that no prime dividing $n$ can contribute to the index of $\mathbb{Z}[\zeta]$ in $\mathcal{O}_K$ by a reduction modulo $1 - \zeta$.
Example. For $n = 4$, $\mathcal{O}_{\mathbb{Q}(i)} = \mathbb{Z}[i]$, the Gaussian integers, an integral basis being $\{1, i\}$. For $n = 3$, $\mathcal{O}_{\mathbb{Q}(\sqrt{-3})} = \mathbb{Z}[\zeta_3] = \mathbb{Z}[(1+\sqrt{-3})/2]$, an integral basis being $\{1, (1+\sqrt{-3})/2\}$; the ring $\mathbb{Z}[\sqrt{-3}]$ is strictly smaller and is not integrally closed.
Corollary. Since $\mathcal{O}_{\mathbb{Q}(\zeta_n)} = \mathbb{Z}[\zeta_n]$ is a quotient of the polynomial ring, the norm of an element $f(\zeta_n)$ with $f \in \mathbb{Z}[x]$ is $\operatorname{N}_{K/\mathbb{Q}}(f(\zeta_n)) = \prod_{k \in (\mathbb{Z}/n\mathbb{Z})^\times} f(\zeta_n^k) = \operatorname{Res}(\Phi_n, f)$, the resultant of $\Phi_n$ and $f$, which is an integer.
Proof. The conjugates of $f(\zeta_n)$ are the $f(\zeta_n^k)$ over the primitive roots, and the product of the conjugates is by definition the norm; the identification with the resultant is the standard formula $\operatorname{Res}(\Phi_n, f) = \prod_{\Phi_n(\alpha) = 0} f(\alpha)$ for monic $\Phi_n$.
Ramification
Theorem. Let $K = \mathbb{Q}(\zeta_n)$ and let $p$ be a rational prime.
(a) $p$ ramifies in $K$ if and only if $p \mid n$. Every prime ideal of $\mathcal{O}_K$ above such a $p$ contains $1 - \zeta_n$, and $(1 - \zeta_n)$ is a prime ideal only when $n$ is a prime power.
(b) If $n = p^v$, then $p$ is totally ramified: $p\mathcal{O}_K = (1-\zeta_{p^v})^{\varphi(p^v)}$, and $\mathcal{O}_K/(1-\zeta_{p^v}) \cong \mathbb{F}_p$. Moreover $(1-\zeta_{p^v})$ is the unique prime above $p$.
(c) If $p \nmid n$, then $p$ is unramified. If $f$ is the order of $p$ in $(\mathbb{Z}/n\mathbb{Z})^\times$, then $p$ splits into $\varphi(n)/f$ distinct primes of residue degree $f$:
$$ p \mathcal{O}_K = \mathrm{P}_1 \cdots \mathrm{P}_{\varphi(n)/f}, \qquad [\mathcal{O}_K/\mathrm{P}_i : \mathbb{F}_p] = f . $$
(d) In general, writing $n = p^v m$ with $p \nmid m$, the primes above $p$ correspond to the primes above $p$ in $\mathbb{Q}(\zeta_m)$ and each acquires the totally ramified factor of degree $\varphi(p^v)$ contributed by the $p$-power part.
Proof sketch. For (b), the identity
$$ \frac{x^{p^v} - 1}{x^{p^{v-1}} - 1} = \Phi_{p^v}(x) = \prod_{\gcd(k,p)=1}(x - \zeta_{p^v}^k) $$
evaluated at $x = 1$ gives $\prod_{k}(1 - \zeta_{p^v}^k) = p$, so $p \in (1-\zeta_{p^v})$ and $p \mathcal{O}_K \subseteq (1-\zeta_{p^v})$; the quotient $\mathcal{O}_K/(1-\zeta_{p^v})$ is $\mathbb{F}_p$ because the norm computation shows $(1-\zeta_{p^v})$ has index $p$, and the discriminant computation $\operatorname{disc}(K) = \pm p^{p^{v-1}(v p - v - 1)}$ shows the ramification index is $\varphi(p^v)$. For (a), if $p \mid n$ then $1-\zeta_n$ is a non-unit in every prime above $p$; if $p \nmid n$ then $x^n-1$ is separable modulo $p$ and the standard theorem on the splitting of primes in $\mathbb{Z}[\zeta_n]$ applies, which gives (c): the polynomial $\Phi_n$ modulo $p$ factors into irreducible factors all of the same degree $f$, equal to the order of $p$ mod $n$, by the theory of finite fields of Finite Fields, and each factor corresponds to a prime of $\mathcal{O}_K$ of residue degree $f$, since $\mathcal{O}_K/(p) \cong \mathbb{F}_p[x]/(\bar\Phi_n)$.
Example ($p = 2$ and the Gaussian integers). For $n = 4$, $2$ ramifies: $2\mathcal{O}_{\mathbb{Q}(i)} = (1+i)^2$ and $1 + i = 1 - \zeta_4$ up to a unit, in agreement with (b) for $p^v = 2$.
Example (splitting). For $n = 5$, the group $(\mathbb{Z}/5\mathbb{Z})^\times$ has order $4$. The prime $p = 2$ has order $4$ modulo $5$, so $2$ is inert: $2\mathcal{O}_{\mathbb{Q}(\zeta_5)}$ is prime. The prime $p = 11$ has $11 \equiv 1 \pmod 5$, so $f = 1$ and $11$ splits into four primes. The prime $p = 19$ has $19 \equiv 4 \equiv -1 \pmod5$, of order $2$, so $19$ splits into two primes of residue degree $2$. And $p = 5$ is totally ramified, by (b) with $v = 1$.
Example (inertia). For $n = 7$, the order of $2$ modulo $7$ is $3$, so $2$ splits into $\varphi(7)/3 = 2$ primes of residue degree $3$.
Norms and Cyclotomic Units
Theorem. Let $n \geq 2$ and $\zeta = \zeta_n$. Then
$$ \operatorname{N}_{\mathbb{Q}(\zeta_n)/\mathbb{Q}}(1 - \zeta) = \begin{cases} p & \text{if } n = p^v \text{ is a prime power}, \\ 1 & \text{otherwise.}\end{cases} $$
Proof. By the corollary on norms, $\operatorname{N}(1-\zeta) = \Phi_n(1)$, the resultant of $\Phi_n(x)$ and $x - 1$ being $\Phi_n(1)$. Now $\Phi_n(1) = p$ when $n = p^v$: from $\Phi_{p^v}(x) = \Phi_p(x^{p^{v-1}})$ and $\Phi_p(1) = p$. When $n$ is divisible by at least two distinct primes, write $n = pm$ with $p \nmid m$ and use $\Phi_n(x) = \Phi_m(x^p)/\Phi_m(x)$ for such $n$; at $x=1$ this gives $\Phi_n(1) = \Phi_m(1)/\Phi_m(1) = 1$ by induction on the number of prime factors.
Corollary. $1 - \zeta_n$ is a unit precisely when $n$ is not a prime power; when $n = p^v$ it generates the unique ramified prime.
Definition. A cyclotomic unit of $\mathbb{Q}(\zeta_n)$ is an element of the form
$$ \frac{\zeta_n^a - 1}{\zeta_n^b - 1}, \qquad a, b \in \mathbb{Z},\ \gcd(a,n) = \gcd(b,n) = 1 . $$
Each such quotient is a unit of $\mathbb{Z}[\zeta_n]$. When $n$ is not a prime power both $\zeta_n^a - 1$ and $\zeta_n^b - 1$ are units by the norm computation above, so the quotient is a unit; when $n = p^v$ both generate the unique prime $(1-\zeta_{p^v})$ above $p$, so the quotient is a unit generating the trivial ideal.
Proposition. The roots of unity $\pm\zeta_n^k$ are cyclotomic units, and the cyclotomic units form a subgroup $C_n$ of the unit group $\mathcal{O}_K^\times$ containing $\mu_{2n}(\mathcal{O}_K)$, the group of roots of unity of $K$. For $n = 3, 4, 6$ the unit group consists of the roots of unity, since the maximal real subfield is $\mathbb{Q}$ and the unit rank is $0$. For $n = 5$ the element $1 + \zeta_5$ is a unit, of norm $\Phi_5(-1) = 1$, whose minimal polynomial is $u^4 - 3u^3 + 4u^2 - 4u + 1$ and which is therefore not a root of unity; the unit group of $\mathbb{Z}[\zeta_5]$ is generated by the roots of unity together with $1+\zeta_5$, and it has rank $1$. For $n = 8$ the element $1 + \sqrt2 = 1 + \zeta_8 + \zeta_8^{-1}$ is a unit of norm $1$, with inverse $\sqrt2 - 1$, and it generates the unit group together with the $8$-th roots of unity, again of rank $1$. The full structure of $\mathcal{O}_K^\times$ — in particular its rank, by Dirichlet's unit theorem — belongs; the index of the cyclotomic units in the full unit group is governed by the class number of the maximal real subfield, a theorem of the analytic theory.
Proof sketch. The norm of a cyclotomic unit is $1$. Integrality of both the quotient and its inverse is checked by the Kronecker-polynomial argument used for the ring of integers, or directly: for $n = p^v$ the quotient equals a product of conjugates of a unit. The listed small cases are verified by the explicit unit group computations: $u^4-3u^3+4u^2-4u+1$ is not any cyclotomic polynomial of degree $4$, namely not $x^4+x^3+x^2+x+1$, $x^4+1$, $x^4-x^3+x^2-x+1$ or $x^4-x^2+1$, so $1+\zeta_5$ is not a root of unity, and $(1+\sqrt2)(\sqrt2-1) = 2\sqrt2 - 1 + 2 - \sqrt2 = 1$ in $\mathbb{Z}[\zeta_8]$.
The Maximal Real Subfield
Definition. For $n \geq 3$ the maximal real subfield of $\mathbb{Q}(\zeta_n)$ is $K^+ = \mathbb{Q}(\zeta_n + \zeta_n^{-1})$, the fixed field of complex conjugation.
Theorem. $K^+$ is a real field, $[K^+ : \mathbb{Q}] = \varphi(n)/2$, and $\operatorname{Gal}(K^+/\mathbb{Q}) \cong (\mathbb{Z}/n\mathbb{Z})^\times / \{\pm 1\}$. The field $K = \mathbb{Q}(\zeta_n)$ is a quadratic extension of $K^+$, and $\mathcal{O}_{K^+} = \mathbb{Z}[\zeta_n + \zeta_n^{-1}]$.
Proof. Complex conjugation is the automorphism $\sigma_{-1}$, of order $2$; its fixed field is $K^+$, which consists of the elements invariant under $\zeta \mapsto \zeta^{-1}$, and $\zeta + \zeta^{-1}$ generates it because the conjugates $\zeta^k + \zeta^{-k}$ are distinct on the classes modulo $\pm1$ and separate the elements of the fixed field. The degree formula and the group statement follow from the Galois correspondence. The ring of integers statement is proved by the same Kronecker argument applied to the real subfield, using the relation $x^2 - (\zeta+\zeta^{-1})x + 1 = 0$.
Summary
For $n \geq 1$ the $n$-th cyclotomic polynomial $\Phi_n(x) = \prod (x - \zeta_n^k)$, the product over the primitive $n$-th roots of unity, is monic with integer coefficients of degree $\varphi(n)$, satisfies $x^n - 1 = \prod_{d \mid n} \Phi_d(x)$, and is irreducible over $\mathbb{Q}$; hence $\mathbb{Q}(\zeta_n)$ has degree $\varphi(n)$ over $\mathbb{Q}$. The extension $\mathbb{Q}(\zeta_n)/\mathbb{Q}$ is Galois, abelian, with $\operatorname{Gal}(\mathbb{Q}(\zeta_n)/\mathbb{Q}) \cong (\mathbb{Z}/n\mathbb{Z})^\times$ acting by $\zeta_n \mapsto \zeta_n^k$, so the subfields of $\mathbb{Q}(\zeta_n)$ correspond to the subgroups of $(\mathbb{Z}/n\mathbb{Z})^\times$. For an odd prime $p$ the unique quadratic subfield is $\mathbb{Q}(\sqrt{p^\ast})$ with $p^\ast = (-1)^{(p-1)/2}p$, exhibited by the Gauss sum $g^2 = p^\ast$; the comparison of the Galois action on $g$ with the action of the Frobenius at a prime $q \neq p$ yields the quadratic reciprocity law.
The ring of integers of $\mathbb{Q}(\zeta_n)$ is $\mathbb{Z}[\zeta_n]$, which is therefore a Dedekind doma, and the ramified primes are exactly the divisors of $n$. When $n = p^v$ the prime $p$ is totally ramified, $p = (1-\zeta_{p^v})^{\varphi(p^v)}$ up to units, and $\operatorname{N}(1-\zeta_{p^v}) = p$; when $p \nmid n$ the prime $p$ is unramified and splits into $\varphi(n)/f$ primes of residue degree $f$, where $f$ is the order of $p$ modulo $n$. Cyclotomic units are the quotients $(\zeta_n^a-1)/(\zeta_n^b-1)$; they form a subgroup of the unit group, whose rank is determined by Dirichlet's unit theorem. The maximal real subfield $\mathbb{Q}(\zeta_n + \zeta_n^{-1})$ has degree $\varphi(n)/2$ over $\mathbb{Q}$ and is the fixed field of complex conjugation. The constructibility of the regular $n$-gon, a statement about ruler and compass in the plane, is deferred to Part II, where the plane is available; the Kronecker–Weber theorem, that every abelian extension of $\mathbb{Q}$ is a subfield of a cyclotomic one, is proved.
Summary of Notation
| Symbol | Meaning |
|---|---|
| $\zeta_n$ | A primitive $n$-th root of unity |
| $\mu_n(K)$ | Group of $n$-th roots of unity in $K$, cyclic |
| $\Phi_n(x)$ | $n$-th cyclotomic polynomial, degree $\varphi(n)$ |
| $\varphi$ | Euler totient function |
| $\mathbb{Q}(\zeta_n)$ | The $n$-th cyclotomic field, of degree $\varphi(n)$ over $\mathbb{Q}$ |
| $\sigma_k$ | Automorphism $\zeta_n \mapsto \zeta_n^k$ |
| $\operatorname{Gal}(\mathbb{Q}(\zeta_n)/\mathbb{Q})$ | $\cong (\mathbb{Z}/n\mathbb{Z})^\times$ |
| $\lambda(n)$ | Exponent of $(\mathbb{Z}/n\mathbb{Z})^\times$ |
| $p^\ast$ | $(-1)^{(p-1)/2}p$ |
| $g$ | Quadratic Gauss sum $\sum_k (k/p)\zeta_p^k$, with $g^2 = p^\ast$ |
| $\left(\frac{k}{p}\right)$ | Legendre symbol |
| $\mathcal{O}_K$ | Ring of integers, $= \mathbb{Z}[\zeta_n]$ |
| $\operatorname{N}_{K/\mathbb{Q}}$ | Field norm |
| $f$ | Order of $p$ modulo $n$; residue degree |
| $\zeta_n + \zeta_n^{-1}$ | Generator of the maximal real subfield |
Further Reading
- Carl Friedrich Gauss, Disquisitiones Arithmeticae (Fleischer, 1801), for the cyclotomic polynomial, the constructible polygons and the first proof of quadratic reciprocity through roots of unity.
- Leopold Kronecker, "Mémoire sur les facteurs irréductibles de l'expression $x^n-1$", Journal de Mathématiques Pures et Appliquées 19 (1854), for the value of the cyclotomic polynomial at $1$ and the arithmetic of cyclotomic integers.
- Richard Dedekind, "Beweis für die Irreductibilität der Kreisteilungsgleichung", Journal für die reine und angewandte Mathematik 54 (1857), 27–30, for the irreducibility argument reproduced in this article.
- Lawrence C. Washington, Introduction to Cyclotomic Fields (Springer, 2nd ed. 1997), for the ring of integers, ramification, cyclotomic units and the class number formula.
- Serge Lang, Cyclotomic Fields I and II (Springer, 1990), for the deeper arithmetic, the Iwasawa theory and the distribution of the primes.
- Jürgen Neukirch, Algebraic Number Theory (Springer, 1999), for cyclotomic fields inside the general theory of number fields and their ramification.
- Kenneth Ireland and Michael Rosen, A Classical Introduction to Modern Number Theory (Springer, 2nd ed. 1990), for the Gauss sums and the deduction of quadratic reciprocity.
- Paulo Ribenboim, Classical Theory of Algebraic Numbers (Springer, 2001), for the elementary development of the ring of integers and the prime decomposition.