Groups, Rings, and Fields
August 25, 20268 min readbeginner
In the previous note we listed five things that an operation might or might not have: closure, associativity, commutativity, an identity element, and inverses for each element.
In the previous note we listed five things that an operation might or might not have: closure, associativity, commutativity, an identity element, and inverses for each element. Mathematicians have given names to the most important combinations of these properties. Three of those names are group, ring, and field. Each one demands more than the last. Each one shows up in the cryptography we are working towards.
Names alone are abstract. We will start by playing with the integers and seeing which structure they fit, then peel the definitions off the example.
A small experiment with
Look at the integers together with ordinary addition. Run through the five properties:
- Closure. Adding any two integers gives an integer. Pass.
- Associativity. for any integers. Pass.
- Identity. The number does nothing: . Pass.
- Inverses. Every integer has an additive inverse , also an integer, with . Pass.
- Commutativity. . Pass.
The integers under addition pass all five. Stripping the commutativity check off (it is not strictly required for the basic name "group") still leaves four passes, and that is enough to call a group. Because the commutativity does happen to hold here, it is more specifically called a commutative group or an abelian group, after Niels Henrik Abel.
02.What a group is
A group is a set together with a binary operation such that the following four conditions hold.
- Closure. For every , the element is also in .
- Associativity. For every , .
- Identity. There is an element such that for every .
- Inverses. For every , there is some such that .
If, in addition, for every , the group is called abelian or commutative.
The five-property check on is doing exactly this. The operation is , the identity is , the inverse of is .
It is worth pausing on a non-example before moving on. is not a group. Closure, associativity, identity () all hold. But inverses fail: the integer is the additive inverse of in , but . So is missing inverses, and that is enough to disqualify it. The smallest extra thing you would need to add to to turn it into a group under addition is exactly the negative integers.
A second non-example: under multiplication is not a group. Closure and associativity and identity () all hold. But inverses fail: the multiplicative inverse of would be , which is not an integer.
So the integers form a group under addition but not under multiplication. The rationals , on the other hand, form a group under addition (with as identity), and the non-zero rationals form a group under multiplication (with as identity, and as the inverse of ). The reason for excluding from the multiplicative group is that has no multiplicative inverse: there is no with .
This pattern (a set that is a group under one operation, and a different set, almost the same, that is a group under another operation) shows up so often that it has its own name: a ring. In a ring, both groups exist on the same underlying set, and the two operations interact through a distributive law.
03.What a ring is
A ring is a set together with two binary operations, called addition (written ) and multiplication (written ), such that
- is an abelian group. The additive identity is written and the additive inverse of is written .
- Multiplication is associative: .
- Multiplication has an identity: there is some with for every . (Some textbooks omit this, but we always include it. A ring without a multiplicative identity is sometimes called a rng, the missing "i" being a wink.)
- Multiplication distributes over addition, on both sides:
If multiplication is also commutative, , the ring is called a commutative ring. Every ring we will meet in this chapter is commutative.
There is no requirement that every element have a multiplicative inverse. That is the gap between a ring and a field.
The integers are the first example, and the canonical one. The two operations, the additive identity , the multiplicative identity : everything you want is there. Distributivity is the law you have used since elementary school, . The integers form a commutative ring. They are not a field, because has no multiplicative inverse inside .
04.What a field is
A field is a commutative ring in which every non-zero element has a multiplicative inverse. Concretely, a field is a set with two operations and such that
- is an abelian group.
- is an abelian group.
- Multiplication distributes over addition.
The condition is a group is the new ingredient. It says that every has an inverse with . That single addition is the whole difference between a field and a commutative ring.
The rationals are a field. So are the reals . The integers are not a field, because .
The point of having a field is that you can divide. In a ring, you can add, subtract, and multiply, but division can fail. In a field, division by anything non-zero is always allowed. That makes fields the cleanest setting for solving equations like : in a field, always exists.
05.A useful picture
Picture three nested boxes.
Every field is a commutative ring. Every commutative ring is a ring. As you move from the outer ring into the inner field, more is guaranteed and more equations have solutions.
The example labels indicate where the named number systems sit. lives in the commutative-ring box but not in the field box, because integer division fails. , and the modular fields for prime (which we are about to construct) all live in the innermost field box.
06.Why this matters for what comes next
The post-quantum schemes Kyber and Dilithium do all their arithmetic inside a particular ring, called . This is built in three steps. Step one is to take the integers and reduce them modulo a number , producing . When is a prime, turns out to be a field. Step two is to make polynomials with coefficients in , giving the bigger ring . Step three is to quotient that polynomial ring by the relation , giving . At each step the same checklist of axioms (the ones in this note) gets verified.
Knowing the words "group", "ring", and "field" precisely is what lets you read the rest of the literature. When a paper says "the secret key is an element of ", it is saying "the secret key is a vector of elements, each one drawn from this ring whose name we have just defined". Without the vocabulary, the sentence is unreadable. With it, the sentence is just a fact.
07.A short exercise
Decide which of the following are groups, commutative rings, or fields, under the operations indicated.
- . A group, abelian. Not a ring on its own because we have only one operation. With multiplication added, it becomes a commutative ring but not a field.
- . A group, abelian. Not a ring, only one operation.
- . A field.
- with the rule "take the ordinary result and keep only the last bit". We will see in the next two notes that this is the field . It happens to be the smallest field there is.
The fourth one is the bridge to the next note, where modular arithmetic is built up properly, and the small finite rings are constructed.