Algebra

Units that form a lattice

In the whole numbers only 1 and −1 have whole-number reciprocals. In the integers of a bigger field there can be infinitely many such units, and they are not scattered: take logarithms of their sizes under each way of placing the field in the real or complex numbers, and the units land exactly on a lattice. How many dimensions that lattice has is a count of those placements, and the area of its cell is a number no formula gives.

Worth reading first: The integers a field contains · How a polynomial breaks modulo the primes.

A unit is an integer whose reciprocal is also an integer. Among the ordinary whole numbers there are two, 1 and −1: the reciprocal of anything else is a fraction. The integers of the field Q(5)\mathbb{Q}(\sqrt5) were more generous. The golden ratio φ\varphi has reciprocal φ−1\varphi - 1, also an integer there, and so does every power of φ\varphi, positive or negative: that field has infinitely many units, all of the form ±φk\pm\varphi^k.

That essay quoted Dirichlet’s unit theorem for real quadratic fields — every unit is a power of one fundamental unit, up to sign — and stopped. The general theorem says much more, and the more is a picture. In any number field the units, once their sizes are replaced by logarithms, lie on a lattice — a regular grid in a space of some dimension — and the dimension is determined by counting how the field sits inside the real and complex numbers.

Units are what the norm makes invertible

The test for a unit is the norm: the product of an integer’s conjugates. For an integer α\alpha of a field of degree nn, multiplication by α\alpha is a linear map on the field, and on a basis of the integers it is an n×nn \times n matrix with whole-number entries. The determinant of that matrix is the norm, a whole number, and it multiplies: the norm of a product is the product of the norms.

If α\alpha is a unit, then α⋅α−1=1\alpha \cdot \alpha^{-1} = 1, so the two norms multiply to 1 and each is ±1\pm 1. Conversely, if the norm is ±1\pm 1, the inverse of the matrix has whole-number entries — its determinant is ±1\pm1 — and the reciprocal of α\alpha is an integer. So the units are exactly the integers of norm ±1\pm 1, and finding them is a matter of computing determinants.

The powers of φ, the units of ℤ[φ]. A table of the powers of φ up to the 9th with their coordinates, their norms of ±1, and — for every third power — their form in ℤ[√5].
Fig. 1 The rank-one case from the quadratic field: the powers of φ up to the ninth, each written as a + bφ and as (c+d5)/2(c + d\sqrt 5)/2, with its norm — the product with its conjugate — always +1 or −1. Every unit of the field is ± a power of φ, and every third power lies in the smaller ring Z[5]\mathbb{Z}[\sqrt 5].

For the golden ratio’s field, the units all sit on one line: take logarithms and log⁡∣±φk∣=klog⁡φ\log|\pm\varphi^k| = k \log\varphi, the multiples of one number. That is a one-dimensional lattice. The same picture, drawn as points on a hyperbola, is Pell’s equation:

Whole-number points on x² − 2y² = 1. The branch of the hyperbola x² − 2y² = 1 in the first quadrant, with the whole-number points on it marked and labelled, and the lattice drawn faintly behind.
Fig. 2 The whole-number points on the hyperbola x2−2y2=1x^2 - 2y^2 = 1 in the first quadrant: (3, 2), (17, 12), (99, 70) and so on. Each is a unit x+y2x + y\sqrt 2 of norm 1 in Z[2]\mathbb{Z}[\sqrt 2], and each is a power of the first, 3+22=(1+2)23 + 2\sqrt 2 = (1 + \sqrt 2)^2. The hyperbola is where the norm is 1; the units are its lattice points.

A unit x+y2x + y\sqrt2 of norm 1 is a whole-number point on the hyperbola x2−2y2=1x^2 - 2y^2 = 1, and the points are the powers of a fundamental solution. Along the hyperbola they are spaced exponentially; after taking logarithms they are evenly spaced. The question is what happens in fields where there is more than one direction to be spaced in.

A cubic field with three real embeddings

Take θ\theta to be a root of x3−3x+1x^3 - 3x + 1 — the polynomial whose factorisations modulo primes followed the cyclic group of order three. All three of its roots are real: about 1.5321.532, 0.3470.347 and −1.879-1.879. So the field Q(θ)\mathbb{Q}(\theta) can be placed inside the real numbers in three different ways, by sending θ\theta to each root. An element a+bθ+cθ2a + b\theta + c\theta^2 then has three real images, its three conjugates, and its norm is their product.

The units of a cubic field, as a lattice of logarithms. Points for 66 units of the field of a root of x³ − 3x + 1, plotted by the logarithms of two of their conjugates, lying on the lattice spanned by the logarithms of θ and θ − 1.
Fig. 3 Every a+bθ+cθ2a + b\theta + c\theta^2 with whole a, b, c between −5 and 5 — 1,330 elements — tested exactly: 66 have norm ±1 and are units. Plotted at (log⁡∣u1∣,log⁡∣u2∣)(\log|u_1|, \log|u_2|), the logarithms of the sizes of two of their three conjugates, they fall on a lattice (faint): every one is ± a whole-number combination of θ and θ − 1, whose cell (shaded) has area 0.8493, the regulator of the field.

The search tests 1,330 elements, computing for each the determinant of a three-by-three whole-number matrix, and finds 66 units — 33 up to sign. Most elements have norms in the dozens or hundreds; the units are the rare ones whose three conjugates multiply to exactly one in size, balancing a large conjugate against small ones. For each it takes the logarithms of the absolute values of its three conjugates. Those three numbers always add to zero, because their sum is the logarithm of the absolute value of the norm, log⁡1=0\log 1 = 0; so each unit is really a point in a plane, and the figure plots the first two coordinates.

The points are not scattered. They fall exactly on the lattice spanned by two particular units, θ\theta itself and θ−1\theta - 1: every unit found is ±θj(θ−1)k\pm\theta^j(\theta - 1)^k for whole numbers jj and kk, which the figure checks by solving for jj and kk and confirming that both are integers to nine decimal places. The field’s units form a two-dimensional lattice.

The area of the lattice’s basic cell — the parallelogram spanned by the logarithm vectors of θ\theta and θ−1\theta - 1 — is 0.84930.8493, and it has a name: the regulator of the field. It measures how sparse the units are. A field whose fundamental units are huge has a large regulator, because their logarithms are long vectors. For comparison, the golden ratio’s field has regulator log⁡φ≈0.4812\log\varphi \approx 0.4812, the length of its one-dimensional cell, and Q(2)\mathbb{Q}(\sqrt2) has log⁡(1+2)≈0.8814\log(1 + \sqrt2) \approx 0.8814. The regulator is a length in rank one, an area in rank two, a volume in rank three — always the size of the cell that the fundamental units span.

One real embedding, one complex pair

Now take the real cube root of 2. The polynomial x3−2x^3 - 2 has one real root and two complex ones, so the field Q(23)\mathbb{Q}(\sqrt[3]{2}) has one real embedding and one pair of complex embeddings, conjugate to each other.

The units of the field of ∛2, on a line. Points on a number line at the exponents 3, 2, 1, 0, −1, −2: the positive units of ℚ(∛2) found by search, each a power of ∛2 − 1.
Fig. 4 Every a+b23+c43a + b\sqrt[3]{2} + c\sqrt[3]{4} with whole a, b, c between −5 and 5 tested exactly for norm ±1: the positive units found, placed by the power of 23−1\sqrt[3]{2} - 1 they are — 3, 2, 1, 0, −1, −2. One real embedding and one complex pair: the units form a line, not a plane, and every unit is ± a power of 23−1\sqrt[3]{2} - 1, whose inverse is 1+23+431 + \sqrt[3]{2} + \sqrt[3]{4}.

Here the units lie on a line. Every unit is ±(23−1)k\pm(\sqrt[3]{2} - 1)^k for some whole number kk, and the search finds the ones with small coefficients — the powers from −2-2 to 33. The inverse of 23−1\sqrt[3]{2} - 1 is 1+23+431 + \sqrt[3]{2} + \sqrt[3]{4}, since (23−1)(1+23+43)=2−1=1(\sqrt[3]{2} - 1)(1 + \sqrt[3]{2} + \sqrt[3]{4}) = 2 - 1 = 1 by the difference-of-cubes identity. So a cubic field can have a lattice of units of dimension two or of dimension one, depending on how many of its embeddings are real.

Why does the complex pair cost a dimension? A unit uu of this field has three conjugates: a real one, u1u_1, and a complex pair u2u_2 and uˉ2\bar u_2 of equal size. Its norm is u1⋅u2⋅uˉ2=u1∣u2∣2=±1u_1 \cdot u_2 \cdot \bar u_2 = u_1 |u_2|^2 = \pm 1, so once u1u_1 is known, ∣u2∣|u_2| is determined: log⁡∣u2∣=−12log⁡∣u1∣\log|u_2| = -\tfrac12 \log|u_1|. A single number, the logarithm of the real conjugate, fixes everything about the unit’s size. In the field of x3−3x+1x^3 - 3x + 1 the three conjugates are independent real numbers subject only to their product being ±1\pm1, which leaves two free logarithms. Conjugate complex embeddings always come as a pair of equal size, and a pair contributes one logarithm, not two — which is the whole reason Dirichlet’s count is r1+r2−1r_1 + r_2 - 1 rather than the degree minus one.

Multiplication becomes addition

Taking logarithms turns the units’ multiplication into addition of vectors: the logarithm vector of a product is the sum of the logarithm vectors, because log⁡∣uv∣=log⁡∣u∣+log⁡∣v∣\log|uv| = \log|u| + \log|v| in each embedding. So the set of logarithm vectors is closed under addition and subtraction — it is a group — and the only question is what shape the group has.

A subgroup of the plane can be many things: a lattice, a line, or a dense set of points filling the plane, like the multiples of an irrational number along a line. What rules out the dense case is that there are only finitely many integers of the field whose conjugates are all bounded by a given amount — their minimal polynomials have bounded whole-number coefficients, and there are finitely many such polynomials. So only finitely many units have logarithm vectors in any bounded region, the group is discrete, and a discrete subgroup of a space is a lattice. That argument gives “a lattice of dimension at most r1+r2−1r_1 + r_2 - 1” with almost no work; Dirichlet’s achievement was the lower bound, that the dimension is not smaller.

The units whose logarithm vector is zero — all conjugates of size exactly 1 — are the roots of unity in the field, ±1\pm1 for both cubic fields here. So the unit group is the roots of unity times a lattice, and choosing a basis of the lattice gives the fundamental units: every unit is a root of unity times a unique product of their powers.

Dirichlet’s count

The general statement, proved by Peter Gustav Lejeune Dirichlet in 1846, is this. Let a number field have r1r_1 embeddings into the real numbers and r2r_2 pairs of complex-conjugate embeddings into the complex numbers, so that its degree is r1+2r2r_1 + 2r_2. Then its units are ±\pm products of powers of exactly

r1+r2−1r_1 + r_2 - 1

fundamental units — up to the roots of unity the field contains — and their logarithm vectors form a lattice of that dimension.

How many independent units a field has. A table of six number fields with their numbers of real and complex embeddings, the unit rank from Dirichlet's theorem, and their fundamental units.
Fig. 5 Six fields, their real embeddings and pairs of complex ones, and the unit rank r1+r2−1r_1 + r_2 - 1. Q(i)\mathbb{Q}(i) has no real embedding and one pair, rank 0: finitely many units, ±1 and ±i. Q(2)\mathbb{Q}(\sqrt 2) and Q(23)\mathbb{Q}(\sqrt[3]{2}) have rank 1; the field of x3−3x+1x^3 - 3x + 1 has rank 2; Q(2,3)\mathbb{Q}(\sqrt 2, \sqrt 3), with four real embeddings, has rank 3; the fifth roots of unity, with two complex pairs, rank 1.

The count is easy to motivate. A unit gives one logarithm for each embedding, counting a complex pair once since conjugates have equal size — r1+r2r_1 + r_2 numbers in all — and they must add to zero because the norm is ±1\pm1. So the units live in a space of dimension r1+r2−1r_1 + r_2 - 1. The substance of the theorem is that they fill it: that there are that many independent units, not fewer. The proof uses Minkowski’s theorem on lattice points in convex regions to produce integers with prescribed sizes under the embeddings, and then shows that among them some are units pointing in every direction.

The table’s first row explains why the ordinary whole numbers and the Gaussian integers have so few units: Q\mathbb{Q} has r1=1r_1 = 1, r2=0r_2 = 0, rank 0; Q(i)\mathbb{Q}(i) has r1=0r_1 = 0, r2=1r_2 = 1, rank 0. Any field whose rank is zero — the rationals and the imaginary quadratic fields — has only finitely many units, the roots of unity it contains. Every other number field has infinitely many.

The search and the units it misses

A smaller search box finds fewer units, and which ones it misses is instructive.

The units of a cubic field, as a lattice of logarithms. Points for 42 units of the field of a root of x³ − 3x + 1, plotted by the logarithms of two of their conjugates, lying on the lattice spanned by the logarithms of θ and θ − 1.
Fig. 6 The same field with coefficients only between −3 and 3: 342 elements tested, 42 units found — fewer, and every one still on the same lattice. The units the smaller box misses are the ones further out on the lattice, whose coefficients are larger.

The units are spread evenly in the logarithms, which means they grow exponentially in the coefficients: a unit twice as far out on the lattice has coefficients roughly squared. A search over coefficients up to BB therefore finds only a patch of the lattice of radius about log⁡B\log B, and the patch fills in slowly. For fields with large fundamental units — some real quadratic fields have fundamental units with hundreds of digits — a coefficient search finds nothing at all beyond ±1\pm1, and the units must be found by continued fractions or by more sophisticated algorithms that walk the lattice rather than searching the box.

That is also why the regulator is hard to compute. It is the area of a cell whose sides are the logarithms of units that may be astronomically large, and there is no formula for it in terms of the polynomial’s coefficients.

The search in the figures is the naive method, and it succeeds here only because this field’s fundamental units are tiny — θ\theta and θ−1\theta - 1 have coefficients 0 and 1. It is the analogue, one dimension up, of finding the fundamental solution of Pell’s equation by trying small xx and yy, which works for x2−2y2=1x^2 - 2y^2 = 1 and fails hopelessly for x2−61y2=1x^2 - 61y^2 = 1, whose smallest solution has ten digits. The continued-fraction algorithm replaced trial for Pell’s equation; for higher-degree fields its replacements are more elaborate, and they all work by walking from one unit to its neighbours on the lattice rather than by searching coefficients.

Where the regulator appears

The regulator is not merely a measure of spacing. It enters the class number formula, which relates the class number hh — the measure of how badly unique factorisation fails in the field — to the behaviour of the field’s zeta function at s=1s = 1:

lim⁡s→1(s−1) ζK(s)=2r1(2π)r2 h Rw∣D∣,\lim_{s \to 1} (s - 1)\,\zeta_K(s) = \frac{2^{r_1} (2\pi)^{r_2}\, h\, R}{w \sqrt{|D|}},

where RR is the regulator, ww the number of roots of unity and DD the discriminant. The left side is analytic, computable from the distribution of prime ideals; the right side multiplies the class number and the regulator together. So the two arithmetic invariants of a field that are hardest to compute — how badly factorisation fails, and how sparse the units are — appear only as a product, and separating them is exactly the difficulty behind Gauss’s conjecture that infinitely many real quadratic fields have class number one: a large regulator can hide a small class number, and nobody can control the regulators well enough to prove it.

For the field of x3−3x+1x^3 - 3x + 1 the class number is 1 and the discriminant is 81, and the regulator in the figure, 0.84930.8493, is the number the formula needs.

What the searches show and what they assume

Norms are exact; logarithms are not. Whether an element is a unit is decided by a determinant of whole numbers, computed exactly. Its position on the lattice uses logarithms of real conjugates, found numerically, and the check that it lies on the lattice is to nine decimal places — convincing, and not a proof.

The fundamental units are named, not found. The figure uses θ\theta and θ−1\theta - 1 as the basis and checks that every unit in the search box is a combination of them. That the box contains no unit outside their lattice is shown; that they generate all units is a theorem about this field — the regulator is minimal — which the search supports and does not prove.

The integers are assumed to be the obvious ones. For both cubic fields the ring of integers is Z[θ]\mathbb{Z}[\theta] and Z[23]\mathbb{Z}[\sqrt[3]{2}] — the polynomial’s discriminant equals the field’s — so testing a+bθ+cθ2a + b\theta + c\theta^2 with whole coefficients reaches every integer. For fields where the obvious ring is too small, as the golden ratio’s half showed for Q(5)\mathbb{Q}(\sqrt5), the search would miss units — and the lattice it drew would be a sublattice of the true one, of some finite index, with a regulator that many times too large.

Still open: how large the fundamental units are

For real quadratic fields Q(d)\mathbb{Q}(\sqrt d) the fundamental unit can be as small as φ\varphi or have thousands of digits, and its size is erratic in dd. The regulator is known to be at most about dlog⁡d\sqrt d \log d, and conjectured to be usually close to that; but for any particular dd nothing better than computing it is known, and the distribution of regulators — how often they are small — is understood only heuristically, through the Cohen–Lenstra heuristics for class groups that it is entangled with.

For higher-degree fields, even computing the unit group is a serious algorithmic problem: the best algorithms run in time subexponential in the discriminant, and assuming the generalised Riemann hypothesis is needed to certify that the units found generate everything. Whether the unit group of a field can be computed in time polynomial in the size of its discriminant’s digits — the analogue of factoring being easy — is not known, and there are quantum algorithms that do it, which is one reason the question matters for cryptography. Some proposed cryptographic systems rest on the difficulty of problems about lattices of exactly this kind, and a fast classical method for unit groups would weaken them.

A grid hiding in the invertible numbers

The units of a number field look, at first, like an arbitrary collection of algebraic numbers whose norms happen to be ±1\pm1. Taking logarithms reveals a grid: evenly spaced in as many directions as the field has real embeddings and complex pairs, less one. The dimension is a count anybody can do from the polynomial’s roots; the grid’s spacing — the regulator — is a number that must be computed, cannot be predicted, and multiplies the class number in the one formula that relates them. Dirichlet’s theorem turns the multiplicative mystery of the units into the additive regularity of a lattice, and the lattice is where both the easy and the hard questions about them live.

It is also the first place in this sequence of essays where the different ways a field sits inside the real and complex numbers are all used at once. The tower law counted an extension’s size by its dimension; the integers were a lattice inside the field; the primes took a census of the field’s symmetries. The units bring in the embeddings — the field seen from each of its real and complex vantage points — and the lattice they form lives in a space with one axis for each vantage point. The next questions about a field, its class group and its zeta function, need all of those structures together.

Shares its objects with

Essays that name at least two of the same things, and that neither author linked.

Named objects

A dashed tag is an object no other essay names yet.

Algebraic integerDeterminantField extensionLatticeLogarithmNormUnit