MathLabs

Algebra

Galois theory

Links field extensions to groups of symmetries, explaining why some equations have no formula for their roots.

IntuitionFrom solving equations to the symmetry of roots

Every student knows the quadratic formula: x2+px+q=0x^2+px+q=0 has roots x=−p±p2−4q2x=\dfrac{-p\pm\sqrt{p^2-4q}}{2}. The two roots swap places when we flip the ±\pm sign — that swap is itself a symmetry. Galois's key idea was to attach to every polynomial equation a group of permutations of its roots that preserve every algebraic relation between them, and the structure of this group decides exactly how "hard" the equation is to solve by radicals.

Unit circle widget with rotation angle theta demonstrating the Galois group action as a rotation of the four roots of x^4-2.
Rotating by θ=90°\theta=90° multiplies a point by ii — exactly how the generator σ\sigma of Gal(L/Q)\mathrm{Gal}(L/\mathbb{Q}) acts on the root α=24\alpha=\sqrt[4]{2} of x4−2=0x^4-2=0, cycling the four roots.

SchoolBridge from high-school algebra: Vieta and Cardano

Vieta's formulas state that the roots x1,x2x_1,x_2 of x2+px+q=0x^2+px+q=0 satisfy x1+x2=−px_1+x_2=-p and x1x2=qx_1x_2=q — symmetric expressions in the roots, unchanged when x1↔x2x_1\leftrightarrow x_2. Cardano found a similar radical formula for cubics; Ferrari did the same for quartics. But every attempt at a quintic formula failed. Abel (1824) proved no general radical formula exists for degree 55; Galois (1832) explained exactly why, through the language of groups.

UndergraduateField extensions and the Galois group

Definition: Field extension, Galois extension

Given fields K⊆LK\subseteq L, we call L/KL/K a field extension. It is finite if LL is a finite-dimensional KK-vector space, and its degree [L:K][L:K] is that dimension. L/KL/K is Galois if it is normal (every irreducible polynomial over KK with one root in LL has all its roots in LL) and separable (no irreducible factor has repeated roots) — automatic whenever KK has characteristic 00, e.g. K=QK=\mathbb{Q}.

Gal(L/K)={σ:L→∼L∣σ(a)=a ∀a∈K}\mathrm{Gal}(L/K)=\{\sigma:L\xrightarrow{\sim}L \mid \sigma(a)=a\ \forall a\in K\}

Gal(L/K)\mathrm{Gal}(L/K) is the set of all field automorphisms of LL that fix every element of KK, with composition as the group operation. When L/KL/K is a finite Galois extension, this is a finite group whose size is controlled precisely by the degree of the extension.

∣Gal(L/K)∣=[L:K]|\mathrm{Gal}(L/K)|=[L:K]

The degree of the field extension equals the order of the Galois group exactly — a direct bridge between linear algebra (dimension of a vector space) and group theory (size of a permutation group of the roots).

Solvability by radicals of the general degree-n equation
Degree nGeneric Galois groupSolvable by radicals?
2Z/2Z\mathbb{Z}/2\mathbb{Z}Yes (quadratic formula)
3S3S_3Yes (Cardano)
4S4S_4Yes (Ferrari)
5S5S_5No (Abel–Ruffini: S5S_5 is not solvable)

Let L/KL/K be a finite Galois extension with G=Gal(L/K)G=\mathrm{Gal}(L/K). The map H↦LHH\mapsto L^H (the field fixed by HH) is an inclusion-reversing bijection between subgroups H≤GH\le G and intermediate fields K⊆F⊆LK\subseteq F\subseteq L, with inverse F↦Gal(L/F)F\mapsto\mathrm{Gal}(L/F). Moreover [L:F]=∣Gal(L/F)∣[L:F]=|\mathrm{Gal}(L/F)|, [F:K]=[G:Gal(L/F)][F:K]=[G:\mathrm{Gal}(L/F)], and F/KF/K is Galois iff Gal(L/F)⊴G\mathrm{Gal}(L/F)\trianglelefteq G, in which case Gal(F/K)≅G/Gal(L/F)\mathrm{Gal}(F/K)\cong G/\mathrm{Gal}(L/F).

Why is it true?

The theorem turns questions about fields (infinite, hard-to-enumerate algebraic objects) into questions about a finite group's subgroup lattice — every question about intermediate fields (how many, which contains which, which are Galois over KK) is answered by staring at the subgroups of GG instead.

Proof

Step 1 (Artin's lemma gives LGal(L/F)=FL^{\mathrm{Gal}(L/F)}=F). Let FF be an intermediate field, H=Gal(L/F)H=\mathrm{Gal}(L/F). Clearly F⊆LHF\subseteq L^H since every σ∈H\sigma\in H fixes FF by definition. For the reverse inclusion, use Artin's theorem: if HH is a finite group of automorphisms of LL then [L:LH]=∣H∣[L:L^H]=|H|; this follows from Dedekind's lemma that distinct field automorphisms are linearly independent as functions L→LL\to L, which forces [L:LH]≥∣H∣[L:L^H]\ge|H|. Since L/FL/F is Galois, [L:F]=∣Gal(L/F)∣=∣H∣[L:F]=|\mathrm{Gal}(L/F)|=|H|, and combined with F⊆LHF\subseteq L^H, [L:LH]=∣H∣=[L:F][L:L^H]=|H|=[L:F] we get F=LHF=L^H.

Step 2 (the two maps are mutually inverse). Given any subgroup H≤GH\le G, set F=LHF=L^H; we must show Gal(L/F)=H\mathrm{Gal}(L/F)=H. By definition H⊆Gal(L/F)H\subseteq\mathrm{Gal}(L/F) (every element of HH fixes LH=FL^H=F). Artin's theorem applied to HH gives [L:F]=[L:LH]=∣H∣[L:F]=[L:L^H]=|H|. Applying it again to Gal(L/F)\mathrm{Gal}(L/F) (always valid since L/FL/F is automatically Galois) gives ∣Gal(L/F)∣=[L:F]=∣H∣|\mathrm{Gal}(L/F)|=[L:F]=|H|. Since H⊆Gal(L/F)H\subseteq\mathrm{Gal}(L/F) and both have the same finite size ∣H∣|H|, we get H=Gal(L/F)H=\mathrm{Gal}(L/F).

Step 3 (order-reversing). Directly from the definition of fixed field, H1⊆H2⇒LH1⊇LH2H_1\subseteq H_2\Rightarrow L^{H_1}\supseteq L^{H_2}, so the bijection reverses inclusions in both directions.

Step 4 (degree formulas). We already showed [L:F]=∣Gal(L/F)∣=∣H∣[L:F]=|\mathrm{Gal}(L/F)|=|H|. From the tower formula [L:K]=[L:F][F:K][L:K]=[L:F][F:K] and [L:K]=∣G∣[L:K]=|G|, we get [F:K]=∣G∣/∣H∣=[G:H][F:K]=|G|/|H|=[G:H].

Step 5 (normal subgroups correspond to Galois subextensions). For σ∈G\sigma\in G, direct verification gives σ(LH)=LσHσ−1\sigma(L^H)=L^{\sigma H\sigma^{-1}}: indeed x∈LH  ⟺  ∀h∈H, hx=x  ⟺  ∀h∈H, (σhσ−1)(σx)=σx  ⟺  σx∈LσHσ−1x\in L^H\iff\forall h\in H,\ hx=x\iff\forall h\in H,\ (\sigma h\sigma^{-1})(\sigma x)=\sigma x\iff \sigma x\in L^{\sigma H\sigma^{-1}}. So F=LHF=L^H is stable under every σ∈G\sigma\in G (which is exactly the normality condition that makes F/KF/K Galois, since FF is generated by roots of polynomials over KK on which GG acts transitively) if and only if σHσ−1=H\sigma H\sigma^{-1}=H for all σ\sigma, i.e. H⊴GH\trianglelefteq G. In that case restriction σ↦σ∣F\sigma\mapsto\sigma|_F gives a surjective homomorphism G→Gal(F/K)G\to\mathrm{Gal}(F/K) with kernel exactly HH, so Gal(F/K)≅G/H\mathrm{Gal}(F/K)\cong G/H by the first isomorphism theorem.

Worked example: the Galois group of x4−2x^4-2

Consider x4−2=0x^4-2=0, irreducible over Q\mathbb{Q} by Eisenstein's criterion at p=2p=2. Its four complex roots are α=24, iα, −α, −iα\alpha=\sqrt[4]{2},\ i\alpha,\ -\alpha,\ -i\alpha, where α=24>0\alpha=\sqrt[4]{2}>0 is the real positive fourth root. The splitting field is L=Q(24, i)L=\mathbb{Q}(\sqrt[4]{2},\,i): we need both α\alpha (for one root) and ii (to generate the other three from it).

Since [Q(α):Q]=4[\mathbb{Q}(\alpha):\mathbb{Q}]=4 (degree-44 irreducible) and [Q(α,i):Q(α)]=2[\mathbb{Q}(\alpha,i):\mathbb{Q}(\alpha)]=2 (as i∉Q(α)⊂Ri\notin\mathbb{Q}(\alpha)\subset\mathbb{R}), we get ∣Gal(L/Q)∣=[L:Q]=8|\mathrm{Gal}(L/\mathbb{Q})|=[L:\mathbb{Q}]=8. This group is generated by σ,τ\sigma,\tau with σ(α)=iα, σ(i)=i,τ(α)=α, τ(i)=−i\sigma(\alpha)=i\alpha,\ \sigma(i)=i,\qquad \tau(\alpha)=\alpha,\ \tau(i)=-i (σ\sigma cycles the four roots, τ\tau is complex conjugation), satisfying σ4=τ2=id\sigma^4=\tau^2=\mathrm{id}, τστ−1=σ−1\tau\sigma\tau^{-1}=\sigma^{-1} — exactly the dihedral group of the square with vertices at the four roots, so Gal(L/Q)≅D4\mathrm{Gal}(L/\mathbb{Q})\cong D_4.

D4D_4 has exactly 1010 subgroups. By the Fundamental Theorem, each corresponds to exactly one intermediate field: for instance ⟨τ⟩\langle\tau\rangle (order 22) fixes L⟨τ⟩=Q(α)L^{\langle\tau\rangle}=\mathbb{Q}(\alpha) (degree 4=[G:⟨τ⟩]4=[G:\langle\tau\rangle] over Q\mathbb{Q}), while ⟨σ⟩\langle\sigma\rangle (order 44, normal since index 22) fixes L⟨σ⟩=Q(i)L^{\langle\sigma\rangle}=\mathbb{Q}(i) (degree 22, and Q(i)/Q\mathbb{Q}(i)/\mathbb{Q} is indeed Galois since ⟨σ⟩⊴D4\langle\sigma\rangle\trianglelefteq D_4, matching the familiar fact that Q(i)/Q\mathbb{Q}(i)/\mathbb{Q} is a normal quadratic extension).

If f∈K[x]f\in K[x] is irreducible over KK (characteristic 00) and LL is its splitting field over KK, then Gal(L/K)\mathrm{Gal}(L/K), acting on the set RR of roots of ff in LL by permutation, acts transitively: for any r1,r2∈Rr_1,r_2\in R there is σ∈Gal(L/K)\sigma\in\mathrm{Gal}(L/K) with σ(r1)=r2\sigma(r_1)=r_2.

Why is it true?

This is why we can speak of "the Galois group of a polynomial" and not just "of a field extension": it explains why every root of an irreducible polynomial is algebraically indistinguishable from every other — there is always a symmetry of LL carrying one root to the other.

Proof

Step 1: Since ff is irreducible over KK and r1,r2∈R⊂Lr_1,r_2\in R\subset L are both roots, there is a KK-isomorphism φ:K(r1)→K(r2)\varphi:K(r_1)\to K(r_2) with φ(r1)=r2\varphi(r_1)=r_2, φ∣K=idK\varphi|_K=\mathrm{id}_K — the basic property of minimal polynomials: K(r1)≅K[x]/(f)≅K(r2)K(r_1)\cong K[x]/(f)\cong K(r_2) via the isomorphism sending r1↦x↦r2r_1\mapsto x\mapsto r_2.

Step 2: LL is a splitting field of ff over both K(r1)K(r_1) and K(r2)K(r_2) (since LL is a splitting field over KK, and K⊆K(ri)⊆LK\subseteq K(r_i)\subseteq L). By the isomorphism extension theorem for splitting fields, φ\varphi extends to a field isomorphism σ:L→L\sigma:L\to L.

Step 3: Since σ∣K=φ∣K=idK\sigma|_K=\varphi|_K=\mathrm{id}_K, we have σ∈Gal(L/K)\sigma\in\mathrm{Gal}(L/K), and σ(r1)=φ(r1)=r2\sigma(r_1)=\varphi(r_1)=r_2. So for any two roots r1,r2r_1,r_2 there is always some σ\sigma sending one to the other — precisely the definition of transitivity.

UndergraduateReal-World Applications and Worked Examples

Though born to answer a purely theoretical question ("does the general quintic have a radical formula?"), Galois theory became foundational for modern cryptography, error-correcting codes, and deciding what can and cannot be built with straightedge and compass.

Example: Finite fields in AES encryption

The AES cipher operates on bytes, each viewed as an element of the finite field F28=F2[x]/(x8+x4+x3+x+1)\mathbb{F}_{2^8}=\mathbb{F}_2[x]/(x^8+x^4+x^3+x+1) — a degree-88 Galois extension of F2\mathbb{F}_2. Explain why multiplicative inverses (used in the SubBytes step) always exist and are unique for every nonzero byte, and why this fails if the modulus were a reducible polynomial like x8+1=(x+1)8x^8+1=(x+1)^8 over F2\mathbb{F}_2.

Solution

Step 1: F2[x]/(m(x))\mathbb{F}_2[x]/(m(x)) is a field (not merely a ring) exactly when m(x)m(x) is irreducible over F2\mathbb{F}_2 — this is the condition for L/F2L/\mathbb{F}_2 to be a finite field extension (automatically Galois: separable since Frobenius x↦x2x\mapsto x^2 is an automorphism, and normal since F2n\mathbb{F}_{2^n} is always the splitting field of x2n−xx^{2^n}-x).

Step 2: AES chose m(x)=x8+x4+x3+x+1m(x)=x^8+x^4+x^3+x+1, which is irreducible over F2\mathbb{F}_2 (it has no root in F2\mathbb{F}_2 and no factorization into degree-4×44\times4 or 2×62\times6 pairs over F2\mathbb{F}_2), so the quotient is a field with 28=2562^8=256 elements — every nonzero element is invertible, computed efficiently by the extended Euclidean algorithm on F2[x]\mathbb{F}_2[x].

Step 3: If m(x)m(x) were replaced by a reducible polynomial such as x8+1=(x+1)8x^8+1=(x+1)^8 over F2\mathbb{F}_2 (characteristic 22), the quotient F2[x]/(x8+1)\mathbb{F}_2[x]/(x^8+1) is no longer a field: the nonzero element x+1x+1 satisfies (x+1)8≡0(x+1)^8\equiv 0, making it a nilpotent zero-divisor with no multiplicative inverse. SubBytes would be undefined on such bytes, breaking the whole cipher — which is exactly why cryptographic standards must verify irreducibility of the modulus polynomial (e.g. via Berlekamp's algorithm, itself built on Galois theory) before publication.

Example: Why the regular heptagon cannot be constructed with straightedge and compass

Ancient Greeks could construct a regular pentagon with straightedge and compass but never a regular heptagon (n=7n=7), despite 2000 years of attempts. Use Galois theory to explain exactly why.

Solution

Step 1: The vertices of a regular nn-gon correspond to the nn-th roots of unity, and constructing it is equivalent to constructing ζn=e2πi/n\zeta_n=e^{2\pi i/n} from Q\mathbb{Q} using only straightedge-and-compass steps. Gauss and Wantzel proved: ζn\zeta_n is constructible iff [Q(ζn):Q][\mathbb{Q}(\zeta_n):\mathbb{Q}] is a power of 22, because every elementary construction step (intersecting lines/circles) adjoins only a degree-11 or degree-22 extension, so any constructible point sits atop a tower of Q\mathbb{Q} with degree a power of 22; conversely a degree-2k2^k Galois group is a 22-group, hence solvable with an index-22 subgroup chain, which by the Fundamental Theorem corresponds to a tower of degree-22 field steps, each realizable by straightedge and compass.

Step 2: The minimal polynomial of ζ7\zeta_7 over Q\mathbb{Q} is the 77th cyclotomic polynomial x6+x5+x4+x3+x2+x+1=0x^6+x^5+x^4+x^3+x^2+x+1=0 (degree 66, since 77 is prime all 66 primitive roots share this minimal polynomial), so [Q(ζ7):Q]=6[\mathbb{Q}(\zeta_7):\mathbb{Q}]=6.

Step 3: 6=2×36=2\times3 is not a power of 22 (it has an odd factor 33), so by the Gauss–Wantzel criterion the regular heptagon is NOT constructible with straightedge and compass — no amount of cleverness could have found a construction, which is exactly why 2000 years of attempts failed. (Contrast: the regular pentagon has [Q(ζ5):Q]=4=22[\mathbb{Q}(\zeta_5):\mathbb{Q}]=4=2^2, a power of 22, so it IS constructible, matching Euclid's construction in the Elements.)

What is ∣Gal(L/K)∣|\mathrm{Gal}(L/K)| for a finite Galois extension L/KL/K?

What is Gal(L/Q)\mathrm{Gal}(L/\mathbb{Q}) for L=Q(24,i)L=\mathbb{Q}(\sqrt[4]{2},i), the splitting field of x4−2=0x^4-2=0?

Why is the regular heptagon not constructible with straightedge and compass?

Why must the modulus polynomial for the AES finite field F28\mathbb{F}_{2^8} be irreducible over F2\mathbb{F}_2?

References

  1. Ian Stewart (2015). Galois Theory (4th ed.) · DOI:10.1201/b18187
  2. David S. Dummit, Richard M. Foote (2004). Abstract Algebra (3rd ed.)