Algebra
Galois theory
Links field extensions to groups of symmetries, explaining why some equations have no formula for their roots.
IntuitionFrom solving equations to the symmetry of roots
Every student knows the quadratic formula: has roots . The two roots swap places when we flip the sign — that swap is itself a symmetry. Galois's key idea was to attach to every polynomial equation a group of permutations of its roots that preserve every algebraic relation between them, and the structure of this group decides exactly how "hard" the equation is to solve by radicals.
SchoolBridge from high-school algebra: Vieta and Cardano
Vieta's formulas state that the roots of satisfy and — symmetric expressions in the roots, unchanged when . Cardano found a similar radical formula for cubics; Ferrari did the same for quartics. But every attempt at a quintic formula failed. Abel (1824) proved no general radical formula exists for degree ; Galois (1832) explained exactly why, through the language of groups.
UndergraduateField extensions and the Galois group
Definition: Field extension, Galois extension
Given fields , we call a field extension. It is finite if is a finite-dimensional -vector space, and its degree is that dimension. is Galois if it is normal (every irreducible polynomial over with one root in has all its roots in ) and separable (no irreducible factor has repeated roots) — automatic whenever has characteristic , e.g. .
is the set of all field automorphisms of that fix every element of , with composition as the group operation. When is a finite Galois extension, this is a finite group whose size is controlled precisely by the degree of the extension.
The degree of the field extension equals the order of the Galois group exactly — a direct bridge between linear algebra (dimension of a vector space) and group theory (size of a permutation group of the roots).
| Degree n | Generic Galois group | Solvable by radicals? |
|---|---|---|
| 2 | Yes (quadratic formula) | |
| 3 | Yes (Cardano) | |
| 4 | Yes (Ferrari) | |
| 5 | No (Abel–Ruffini: is not solvable) |
Let be a finite Galois extension with . The map (the field fixed by ) is an inclusion-reversing bijection between subgroups and intermediate fields , with inverse . Moreover , , and is Galois iff , in which case .
Why is it true?
The theorem turns questions about fields (infinite, hard-to-enumerate algebraic objects) into questions about a finite group's subgroup lattice — every question about intermediate fields (how many, which contains which, which are Galois over ) is answered by staring at the subgroups of instead.
Proof
Step 1 (Artin's lemma gives ). Let be an intermediate field, . Clearly since every fixes by definition. For the reverse inclusion, use Artin's theorem: if is a finite group of automorphisms of then ; this follows from Dedekind's lemma that distinct field automorphisms are linearly independent as functions , which forces . Since is Galois, , and combined with , we get .
Step 2 (the two maps are mutually inverse). Given any subgroup , set ; we must show . By definition (every element of fixes ). Artin's theorem applied to gives . Applying it again to (always valid since is automatically Galois) gives . Since and both have the same finite size , we get .
Step 3 (order-reversing). Directly from the definition of fixed field, , so the bijection reverses inclusions in both directions.
Step 4 (degree formulas). We already showed . From the tower formula and , we get .
Step 5 (normal subgroups correspond to Galois subextensions). For , direct verification gives : indeed . So is stable under every (which is exactly the normality condition that makes Galois, since is generated by roots of polynomials over on which acts transitively) if and only if for all , i.e. . In that case restriction gives a surjective homomorphism with kernel exactly , so by the first isomorphism theorem.
Worked example: the Galois group of
Consider , irreducible over by Eisenstein's criterion at . Its four complex roots are , where is the real positive fourth root. The splitting field is : we need both (for one root) and (to generate the other three from it).
Since (degree- irreducible) and (as ), we get . This group is generated by with ( cycles the four roots, is complex conjugation), satisfying , — exactly the dihedral group of the square with vertices at the four roots, so .
has exactly subgroups. By the Fundamental Theorem, each corresponds to exactly one intermediate field: for instance (order ) fixes (degree over ), while (order , normal since index ) fixes (degree , and is indeed Galois since , matching the familiar fact that is a normal quadratic extension).
If is irreducible over (characteristic ) and is its splitting field over , then , acting on the set of roots of in by permutation, acts transitively: for any there is with .
Why is it true?
This is why we can speak of "the Galois group of a polynomial" and not just "of a field extension": it explains why every root of an irreducible polynomial is algebraically indistinguishable from every other — there is always a symmetry of carrying one root to the other.
Proof
Step 1: Since is irreducible over and are both roots, there is a -isomorphism with , — the basic property of minimal polynomials: via the isomorphism sending .
Step 2: is a splitting field of over both and (since is a splitting field over , and ). By the isomorphism extension theorem for splitting fields, extends to a field isomorphism .
Step 3: Since , we have , and . So for any two roots there is always some sending one to the other — precisely the definition of transitivity.
UndergraduateReal-World Applications and Worked Examples
Though born to answer a purely theoretical question ("does the general quintic have a radical formula?"), Galois theory became foundational for modern cryptography, error-correcting codes, and deciding what can and cannot be built with straightedge and compass.
Example: Finite fields in AES encryption
The AES cipher operates on bytes, each viewed as an element of the finite field — a degree- Galois extension of . Explain why multiplicative inverses (used in the SubBytes step) always exist and are unique for every nonzero byte, and why this fails if the modulus were a reducible polynomial like over .
Solution
Step 1: is a field (not merely a ring) exactly when is irreducible over — this is the condition for to be a finite field extension (automatically Galois: separable since Frobenius is an automorphism, and normal since is always the splitting field of ).
Step 2: AES chose , which is irreducible over (it has no root in and no factorization into degree- or pairs over ), so the quotient is a field with elements — every nonzero element is invertible, computed efficiently by the extended Euclidean algorithm on .
Step 3: If were replaced by a reducible polynomial such as over (characteristic ), the quotient is no longer a field: the nonzero element satisfies , making it a nilpotent zero-divisor with no multiplicative inverse. SubBytes would be undefined on such bytes, breaking the whole cipher — which is exactly why cryptographic standards must verify irreducibility of the modulus polynomial (e.g. via Berlekamp's algorithm, itself built on Galois theory) before publication.
Example: Why the regular heptagon cannot be constructed with straightedge and compass
Ancient Greeks could construct a regular pentagon with straightedge and compass but never a regular heptagon (), despite 2000 years of attempts. Use Galois theory to explain exactly why.
Solution
Step 1: The vertices of a regular -gon correspond to the -th roots of unity, and constructing it is equivalent to constructing from using only straightedge-and-compass steps. Gauss and Wantzel proved: is constructible iff is a power of , because every elementary construction step (intersecting lines/circles) adjoins only a degree- or degree- extension, so any constructible point sits atop a tower of with degree a power of ; conversely a degree- Galois group is a -group, hence solvable with an index- subgroup chain, which by the Fundamental Theorem corresponds to a tower of degree- field steps, each realizable by straightedge and compass.
Step 2: The minimal polynomial of over is the th cyclotomic polynomial (degree , since is prime all primitive roots share this minimal polynomial), so .
Step 3: is not a power of (it has an odd factor ), so by the Gauss–Wantzel criterion the regular heptagon is NOT constructible with straightedge and compass — no amount of cleverness could have found a construction, which is exactly why 2000 years of attempts failed. (Contrast: the regular pentagon has , a power of , so it IS constructible, matching Euclid's construction in the Elements.)
What is for a finite Galois extension ?
What is for , the splitting field of ?
Why is the regular heptagon not constructible with straightedge and compass?
Why must the modulus polynomial for the AES finite field be irreducible over ?
References
- Ian Stewart (2015). Galois Theory (4th ed.) · DOI:10.1201/b18187
- David S. Dummit, Richard M. Foote (2004). Abstract Algebra (3rd ed.)