# Difference between revisions of "Fermat's Little Theorem"

PI-Dimension (talk | contribs) (→Statement) |
m (→Proof 5 (Burnside's Lemma)) |
||

(28 intermediate revisions by 20 users not shown) | |||

Line 6: | Line 6: | ||

If <math>{a}</math> is an [[integer]], <math>{p}</math> is a [[prime number]] and <math>{a}</math> is not [[divisibility|divisible]] by <math>{p}</math>, then <math>a^{p-1}\equiv 1 \pmod {p}</math>. | If <math>{a}</math> is an [[integer]], <math>{p}</math> is a [[prime number]] and <math>{a}</math> is not [[divisibility|divisible]] by <math>{p}</math>, then <math>a^{p-1}\equiv 1 \pmod {p}</math>. | ||

− | A frequently used corollary of Fermat's Little Theorem is <math> a^p \equiv a \pmod {p}</math>. As you can see, it is derived by multipling both sides of the theorem by <math>a</math>. The restated form is nice because we no longer need to restrict ourselves to integers <math>{a}</math> not divisible by <math>{p}</math>. | + | A frequently used corollary of Fermat's Little Theorem is <math>a^p \equiv a \pmod {p}</math>. As you can see, it is derived by multipling both sides of the theorem by <math>a</math>. The restated form is nice because we no longer need to restrict ourselves to integers <math>{a}</math> not divisible by <math>{p}</math>. |

This theorem is a special case of [[Euler's Totient Theorem]], which states that if <math>a</math> and <math>n</math> are integers, then <math>a^{\varphi(n)} \equiv 1 \pmod{n}</math>, where <math>\varphi(n)</math> denotes [[Euler's totient function]]. In particular, <math>\varphi(p) = p-1</math> for prime numbers <math>p</math>. In turn, this is a special case of [[Lagrange's Theorem]]. | This theorem is a special case of [[Euler's Totient Theorem]], which states that if <math>a</math> and <math>n</math> are integers, then <math>a^{\varphi(n)} \equiv 1 \pmod{n}</math>, where <math>\varphi(n)</math> denotes [[Euler's totient function]]. In particular, <math>\varphi(p) = p-1</math> for prime numbers <math>p</math>. In turn, this is a special case of [[Lagrange's Theorem]]. | ||

Line 23: | Line 23: | ||

Note that <math>p</math> divides into any binomial coefficient of the form <math>{p \choose k}</math> for <math>1 \le k \le p-1</math>. This follows by the definition of the binomial coefficient as <math>{p \choose k} = \frac{p!}{k! (p-k)!}</math>; since <math>p</math> is prime, then <math>p</math> divides the numerator, but not the denominator. | Note that <math>p</math> divides into any binomial coefficient of the form <math>{p \choose k}</math> for <math>1 \le k \le p-1</math>. This follows by the definition of the binomial coefficient as <math>{p \choose k} = \frac{p!}{k! (p-k)!}</math>; since <math>p</math> is prime, then <math>p</math> divides the numerator, but not the denominator. | ||

− | Taken <math>\mod p</math>, all of the middle terms disappear, and we end up with <math>(a+1)^p \equiv a^p + 1 \pmod{p}</math>. Since we also know that <math>a^p \equiv a\pmod{p}</math>, then <math>(a+1)^p \equiv a+1 \pmod{p}</math>, as desired | + | Taken <math>\mod p</math>, all of the middle terms disappear, and we end up with <math>(a+1)^p \equiv a^p + 1 \pmod{p}</math>. Since we also know that <math>a^p \equiv a\pmod{p}</math>, then <math>(a+1)^p \equiv a+1 \pmod{p}</math>, as desired <math>\square</math> |

=== Proof 2 (Inverses) === | === Proof 2 (Inverses) === | ||

Line 31: | Line 31: | ||

<center><cmath>S \equiv \{1a, 2a, \cdots, (p-1)a\} \pmod{p}.</cmath></center><br> | <center><cmath>S \equiv \{1a, 2a, \cdots, (p-1)a\} \pmod{p}.</cmath></center><br> | ||

− | Clearly none of the <math>ia</math> for <math>1 \le i \le p-1</math> are divisible by <math>p</math>, so it suffices to show that all of the elements in <math>a \cdot S</math> are distinct. Suppose that <math>ai \equiv aj \pmod{p} | + | Clearly none of the <math>ia</math> for <math>1 \le i \le p-1</math> are divisible by <math>p</math>, so it suffices to show that all of the elements in <math>a \cdot S</math> are distinct. Suppose that <math>ai \equiv aj \pmod{p}</math>. Since <math>\text{gcd}\, (a,p) = 1</math>, by the cancellation rule, that reduces to <math>i \equiv j \pmod{p},</math> which means <math>i = j</math> as <math>1 \leq i, j \leq p-1.</math> |

Thus, <math>\mod{p}</math>, we have that the product of the elements of <math>S</math> is | Thus, <math>\mod{p}</math>, we have that the product of the elements of <math>S</math> is | ||

Line 39: | Line 39: | ||

Cancelling the factors <math>1, 2, 3, \ldots, p-1</math> from both sides, we are left with the statement <math>a^{p-1} \equiv 1 \pmod{p}</math>.<br> | Cancelling the factors <math>1, 2, 3, \ldots, p-1</math> from both sides, we are left with the statement <math>a^{p-1} \equiv 1 \pmod{p}</math>.<br> | ||

− | A similar version can be used to prove [[Euler's Totient Theorem]], if we let <math>S = \{\text{natural numbers relatively prime to and less than}\ n\}</math> | + | A similar version can be used to prove [[Euler's Totient Theorem]], if we let <math>S = \{\text{natural numbers relatively prime to and less than}\ n\}</math> <math>\square</math> |

− | === Proof 3 ( | + | === Proof 3 (Combinatoriccs) === |

<center><asy> | <center><asy> | ||

real r = 0.3, row1 = 3.5, row2 = 0, row3 = -3.5; | real r = 0.3, row1 = 3.5, row2 = 0, row3 = -3.5; | ||

Line 57: | Line 57: | ||

</asy><br> An illustration of the case <math>p=3,a=2</math>.<br></center> | </asy><br> An illustration of the case <math>p=3,a=2</math>.<br></center> | ||

− | Consider a necklace with <math>p</math> beads, each bead of which can be colored in <math>a</math> different ways. There are <math>a^p</math> ways to pick the colors of the beads. <math>a</math> of these are necklaces that consists of beads of the same color. Of the remaining necklaces, for each necklace, there are exactly <math>p-1</math> more necklaces that are rotationally equivalent to this necklace. It follows that <math>a^p-a</math> must be divisible by <math>p</math>. Written in another way, <math>a^p \equiv a \pmod{p}</math>. | + | Consider a necklace with <math>p</math> beads, each bead of which can be colored in <math>a</math> different ways. There are <math>a^p</math> ways to pick the colors of the beads. <math>a</math> of these are necklaces that consists of beads of the same color. Of the remaining necklaces, for each necklace, there are exactly <math>p-1</math> more necklaces that are rotationally equivalent to this necklace. It follows that <math>a^p-a</math> must be divisible by <math>p</math>. Written in another way, <math>a^p \equiv a \pmod{p}</math> <math>\square</math> |

+ | |||

+ | [https://www.khanacademy.org/computing/computer-science/cryptography/random-algorithms-probability/v/fermat-s-little-theorem-visualization Video explanation] | ||

=== Proof 4 (Geometry) === | === Proof 4 (Geometry) === | ||

Line 95: | Line 97: | ||

<cmath>P(x_1, x_2, \ldots, x_n) \mapsto P(x_2, x_3, \ldots, x_n, x_1)</cmath><br> | <cmath>P(x_1, x_2, \ldots, x_n) \mapsto P(x_2, x_3, \ldots, x_n, x_1)</cmath><br> | ||

− | maps one unit hypercube to a distinct hypercube. Much like the combinatorial proof, this splits the non-main diagonal unit hypercubes into groups of size <math>p</math>, from which it follows that <math>a^p \equiv a \pmod{p}</math>. Thus, we have another way to visualize the above combinatorial proof, by imagining the described transformation to be, in a sense, a rotation about the main diagonal of the hypercube. | + | maps one unit hypercube to a distinct hypercube. Much like the combinatorial proof, this splits the non-main diagonal unit hypercubes into groups of size <math>p</math>, from which it follows that <math>a^p \equiv a \pmod{p}</math>. Thus, we have another way to visualize the above combinatorial proof, by imagining the described transformation to be, in a sense, a rotation about the main diagonal of the hypercube <math>\square</math> |

+ | |||

+ | === Proof 5 (Burnside's Lemma) === | ||

+ | Consider the number of ways to color a <math>p</math>-beaded oriented necklace in <math>a</math> colors up to symmetry where <math>p</math> is prime. The group <math>C_p</math>, or the cyclic group of order <math>p</math>, acts on the <math>a</math> colorings of an oriented necklace by rotation. The identity fixes all <math>a^p</math> of the colorings by definition. If <math>g\in C_p</math> where <math>g\ne e</math> then <math>g</math> permutes the necklace in a single orbit which we can denote as <math>\mathcal{O}</math> (since the size of the orbit is a factor of <math>p</math>). Hence, if <math>g\ne e</math> then <math>g</math> fixes only the <math>a</math> monochromatic paintings. By [https://artofproblemsolving.com/wiki/index.php/Burnside%27s_Lemma Burnside's Lemma] the number of ways to paint the necklace (up to symmetry) is | ||

+ | <center><cmath>|\mathcal{O}|=\frac{1}{|G|}\sum_{g\in G}|\text{Fix}(g)|=\frac{1}{p}\sum_{g\in C_p}|\text{Fix}(g)|=\frac{1}{p}|\text{Fix}(e)|+\frac{1}{p}\sum_{g\in C_p}|\text{Fix}(g)|.</cmath></center><br> | ||

+ | This simplifies to | ||

+ | <center><cmath>\frac{a^p}{p}+\frac{a(p-1)}{p}=a+\frac{a^p-a}{p}</cmath></center><br> | ||

+ | and since <math>|\mathcal{O}|</math> must be an integer we must have that <math>a^p-a\mid p</math> or that <math>a^p-a\equiv 0 \pmod{p}\implies a^{p}\equiv a\pmod{p}</math> which finishes <math>\square</math> <math>\square</math> | ||

+ | |||

+ | ===Proof 6 (Lagrange's Theorem)=== | ||

+ | The key to this proof is to recognize that <math>(\mathbb{Z} / p\mathbb{Z})^{\times}</math> for some prime <math>p</math> where <math>(\mathbb{Z} / p\mathbb{Z})^{\times}=\{1,2,3,4,5,...p-1\}</math> is actually a group. Notice that the order of <math>(\mathbb{Z} / p\mathbb{Z})^{\times}</math> is <math>\varphi(p)=p-1</math>. Suppose there exists some <math>a\in(\mathbb{Z} / p\mathbb{Z})^{\times}</math> such that for some sufficient <math>k</math>, <math>a^k\equiv 1\pmod{p}</math>. By Lagrange's Theorem we must have that <math>k\,|\,p-1</math> so <math>p-1=km</math> for some <math>m</math>. Therefore we have | ||

+ | <center><cmath>a^{p-1}\equiv a^{km}\equiv (a^k)^m\equiv 1^m\equiv 1\pmod{p}</cmath></center><br> | ||

+ | which yields <math>a^p\equiv a\pmod{p}</math> as desired <math>\square</math> | ||

+ | |||

+ | ===Proof 7 (Field Theory)=== | ||

+ | Define a field <math>k</math> such that <math>k^{\times}</math> is its group of units written as <math>(k\backslash\{0\},\times)</math>. If we can prove the cyclicity of <math>k^{\times}</math> then the claim follows. We first prove the following lemma: | ||

+ | |||

+ | '''Lemma''': For any integer <math>n>1</math> and any finite field <math>k</math>, <math>C_n\times C_n</math> is not a subgroup of <math>k^{\times}</math>. | ||

+ | |||

+ | '''Proof''': Our aim is to show that <math>|C_n\times C_n|>|k^{\times}|</math>. It is evident that any element in <math>C_n\times C_n</math> has to satisfy <math>x^n=1</math>. However, at most <math>n</math> elements satisfy this equation (which can be proven inductively), and <math>|C_n\times C_n|=n^2</math> which means that it can not be a subgroup of <math>k^{\times}</math> since <math>|k^{\times}|=n</math>. This completes the proof <math>\blacksquare</math> | ||

+ | |||

+ | Since <math>k^{\times}</math> is abelian, we can use the Fundamental Theorem of Finitely Generated Abelian Groups (FToFGAG) and we can write <math>k^{\times}</math> as a product of cyclic groups of prime order where the set of prime power orders is unique. We can do this because if any two prime powers are not coprime then <math>k^{\times}</math> contains <math>C_{p^a}\times C_{p^b}</math> and consequently <math>C_p\times C_p</math>, contradicting our lemma. We can therefore write <math>k^{\times}</math> as | ||

+ | <center><cmath>k^{\times}\cong C_{p_{1}^{d_1}}\times C_{p_{2}^{d_2}}\times\ldots\times C_{p_{m}^{d_m}}</cmath></center><br> | ||

+ | where <math>p_1<p_2<p_3<\ldots p_m</math>. By the [[Chinese Remainder Theorem]] we can then write | ||

+ | <cmath>k^{\times}\cong C_{p_{1}^{d_1}p_{2}^{d_2}\ldots p_{m}^{d_m}}</cmath> | ||

+ | which means <math>k^{\times}</math> is cyclic. Our proof of Fermat's Little Theorem, however, comes as a corollary of this theorem. If <math>k=\mathbb{Z}/p\mathbb{Z}</math> (which is always a field for prime <math>p</math>) then <math>k^{\times}</math> must be a cyclic group of order <math>p-1</math>. Hence for any nonzero <math>a\in k</math>, <math>a^{p-1}=1</math> or that <math>a^{p}\equiv a\pmod{p}</math> for prime <math>p</math> which completes our work <math>\square</math> | ||

== Problems == | == Problems == | ||

Line 108: | Line 135: | ||

* One of Euler's conjectures was disproved in the 1960s by three American mathematicians when they showed there was a positive integer such that <math>133^5+110^5+84^5+27^5=n^5</math>. Find the value of <math>{n}</math>. ([[1989 AIME Problems/Problem 9|1989 AIME, #9]])<br><br> | * One of Euler's conjectures was disproved in the 1960s by three American mathematicians when they showed there was a positive integer such that <math>133^5+110^5+84^5+27^5=n^5</math>. Find the value of <math>{n}</math>. ([[1989 AIME Problems/Problem 9|1989 AIME, #9]])<br><br> | ||

− | *If <math>f(x) = x^{x^{x^x}}</math>, find the last two digits of <math>f(17) + f(18) + f(19) + f(20)</math>. ([ | + | *If <math>f(x) = x^{x^{x^x}}</math>, find the last two digits of <math>f(17) + f(18) + f(19) + f(20)</math>. ([https://pumac.princeton.edu/info/archives/pumac-2008/ 2008 PUMaC, NT A#5]) |

=== Advanced === | === Advanced === | ||

− | * | + | *Is it true that if <math>p</math> is a prime number, and <math>k</math> is an integer <math>2 \le k \le p</math>, then the sum of the products of each <math>k</math>-element subset of <math>\{1, 2, \ldots, p\}</math> will be divisible by <math>p</math>? <br><br> |

== Hints/Solutions == | == Hints/Solutions == | ||

Line 131: | Line 158: | ||

Advanced: | Advanced: | ||

* Hint: try to establish the identity <math>x^{p} - x \equiv x(x-1)(x-2) \cdots (x-(p-1)) \pmod{p}</math>, and then apply [[Vieta's formulas]]. | * Hint: try to establish the identity <math>x^{p} - x \equiv x(x-1)(x-2) \cdots (x-(p-1)) \pmod{p}</math>, and then apply [[Vieta's formulas]]. | ||

+ | |||

+ | ==Extensions== | ||

+ | |||

+ | If <math>{a}</math> is an [[integer]], <math>{p}</math> is a [[prime number]] and <math>{a}</math> is not [[divisibility|divisible]] by <math>{p}</math>, then <math>a^{(p-1)k}\equiv 1 \pmod {p}</math>. | ||

+ | |||

+ | The above follows from the exponent rule <math>(a^b)^c=a^{bc}</math> | ||

+ | |||

+ | An extension of the Collary given above is that : | ||

+ | <cmath>(a^p)^w \equiv a^w \pmod {p}</cmath> | ||

+ | |||

+ | Immediately by normal exponent rules, it follows that if: <cmath>z=(d_1d_2\ldots d_f)_p</cmath> Then, <cmath>a^z\equiv a^{d_1+d_2+\cdots +d_f}\pmod p</cmath> Which means, by repeating the process, we have that we can reduce the exponent to its digital root base <math>p</math> . | ||

+ | |||

+ | |||

+ | |||

== See also == | == See also == |

## Latest revision as of 15:58, 6 January 2023

**Fermat's Little Theorem** is highly useful in number theory for simplifying the computation of exponents in modular arithmetic (which students should study more at the introductory level if they have a hard time following the rest of this article). This theorem is credited to Pierre de Fermat.

## Statement

If is an integer, is a prime number and is not divisible by , then .

A frequently used corollary of Fermat's Little Theorem is . As you can see, it is derived by multipling both sides of the theorem by . The restated form is nice because we no longer need to restrict ourselves to integers not divisible by .

This theorem is a special case of Euler's Totient Theorem, which states that if and are integers, then , where denotes Euler's totient function. In particular, for prime numbers . In turn, this is a special case of Lagrange's Theorem.

In contest problems, Fermat's Little Theorem is often used in conjunction with the Chinese Remainder Theorem to simplify tedious calculations.

## Proof

We offer several proofs using different techniques to prove the statement . If , then we can cancel a factor of from both sides and retrieve the first version of the theorem.

### Proof 1 (Induction)

The most straightforward way to prove this theorem is by by applying the induction principle. We fix as a prime number. The base case, , is obviously true. Suppose the statement is true. Then, by the binomial theorem,

Note that divides into any binomial coefficient of the form for . This follows by the definition of the binomial coefficient as ; since is prime, then divides the numerator, but not the denominator.

Taken , all of the middle terms disappear, and we end up with . Since we also know that , then , as desired

### Proof 2 (Inverses)

Let . Then, we claim that the set , consisting of the product of the elements of with , taken modulo , is simply a permutation of . In other words,

Clearly none of the for are divisible by , so it suffices to show that all of the elements in are distinct. Suppose that . Since , by the cancellation rule, that reduces to which means as

Thus, , we have that the product of the elements of is

Cancelling the factors from both sides, we are left with the statement .

A similar version can be used to prove Euler's Totient Theorem, if we let

### Proof 3 (Combinatoriccs)

An illustration of the case .

Consider a necklace with beads, each bead of which can be colored in different ways. There are ways to pick the colors of the beads. of these are necklaces that consists of beads of the same color. Of the remaining necklaces, for each necklace, there are exactly more necklaces that are rotationally equivalent to this necklace. It follows that must be divisible by . Written in another way,

### Proof 4 (Geometry)

We imbed a hypercube of side length in (the -th dimensional Euclidean space), such that the vertices of the hypercube are at . A hypercube is essentially a cube, generalized to higher dimensions. This hypercube consists of separate unit hypercubes, with centers consisting of the points

where each is an integer from to . Besides the centers of the unit hypercubes in the main diagonal (from to ), the transformation carrying

maps one unit hypercube to a distinct hypercube. Much like the combinatorial proof, this splits the non-main diagonal unit hypercubes into groups of size , from which it follows that . Thus, we have another way to visualize the above combinatorial proof, by imagining the described transformation to be, in a sense, a rotation about the main diagonal of the hypercube

### Proof 5 (Burnside's Lemma)

Consider the number of ways to color a -beaded oriented necklace in colors up to symmetry where is prime. The group , or the cyclic group of order , acts on the colorings of an oriented necklace by rotation. The identity fixes all of the colorings by definition. If where then permutes the necklace in a single orbit which we can denote as (since the size of the orbit is a factor of ). Hence, if then fixes only the monochromatic paintings. By Burnside's Lemma the number of ways to paint the necklace (up to symmetry) is

This simplifies to

and since must be an integer we must have that or that which finishes

### Proof 6 (Lagrange's Theorem)

The key to this proof is to recognize that for some prime where is actually a group. Notice that the order of is . Suppose there exists some such that for some sufficient , . By Lagrange's Theorem we must have that so for some . Therefore we have

which yields as desired

### Proof 7 (Field Theory)

Define a field such that is its group of units written as . If we can prove the cyclicity of then the claim follows. We first prove the following lemma:

**Lemma**: For any integer and any finite field , is not a subgroup of .

**Proof**: Our aim is to show that . It is evident that any element in has to satisfy . However, at most elements satisfy this equation (which can be proven inductively), and which means that it can not be a subgroup of since . This completes the proof

Since is abelian, we can use the Fundamental Theorem of Finitely Generated Abelian Groups (FToFGAG) and we can write as a product of cyclic groups of prime order where the set of prime power orders is unique. We can do this because if any two prime powers are not coprime then contains and consequently , contradicting our lemma. We can therefore write as

where . By the Chinese Remainder Theorem we can then write which means is cyclic. Our proof of Fermat's Little Theorem, however, comes as a corollary of this theorem. If (which is always a field for prime ) then must be a cyclic group of order . Hence for any nonzero , or that for prime which completes our work

## Problems

### Introductory

- Compute some examples, for example find , and , and check your answers by calculator where possible.

- Let . What is the units digit of ? (2008 AMC 12A Problems/Problem 15)

- Find mod . (Discussion).

### Intermediate

- One of Euler's conjectures was disproved in the 1960s by three American mathematicians when they showed there was a positive integer such that . Find the value of . (1989 AIME, #9)

- If , find the last two digits of . (2008 PUMaC, NT A#5)

### Advanced

- Is it true that if is a prime number, and is an integer , then the sum of the products of each -element subset of will be divisible by ?

## Hints/Solutions

Introductory:

- Hint: For the first example, we have by FLT (Fermat's Little Theorem). It follows that .

Intermediate:

- Solution (1989 AIME, 9) To solve this problem, it would be nice to know some information about the remainders can have after division by certain numbers. By Fermat's Little Theorem, we know is congruent to modulo 5. Hence,

- Continuing, we examine the equation modulo 3,

- Thus, is divisible by three and leaves a remainder of four when divided by 5. It's obvious that , so the only possibilities are or . It quickly becomes apparent that 174 is much too large, so must be 144.

Advanced:

- Hint: try to establish the identity , and then apply Vieta's formulas.

## Extensions

If is an integer, is a prime number and is not divisible by , then .

The above follows from the exponent rule

An extension of the Collary given above is that :

Immediately by normal exponent rules, it follows that if: Then, Which means, by repeating the process, we have that we can reduce the exponent to its digital root base .