src/HOL/Number_Theory/Residues.thy
author haftmann
Mon Oct 09 19:10:48 2017 +0200 (21 months ago)
changeset 66837 6ba663ff2b1c
parent 66817 0b12755ccbb2
child 66888 930abfdf8727
permissions -rw-r--r--
tuned proofs
     1 (*  Title:      HOL/Number_Theory/Residues.thy
     2     Author:     Jeremy Avigad
     3 
     4 An algebraic treatment of residue rings, and resulting proofs of
     5 Euler's theorem and Wilson's theorem.
     6 *)
     7 
     8 section \<open>Residue rings\<close>
     9 
    10 theory Residues
    11 imports
    12   Cong
    13   "HOL-Algebra.More_Group"
    14   "HOL-Algebra.More_Ring"
    15   "HOL-Algebra.More_Finite_Product"
    16   "HOL-Algebra.Multiplicative_Group"
    17   Totient
    18 begin
    19 
    20 definition QuadRes :: "int \<Rightarrow> int \<Rightarrow> bool"
    21   where "QuadRes p a = (\<exists>y. ([y^2 = a] (mod p)))"
    22 
    23 definition Legendre :: "int \<Rightarrow> int \<Rightarrow> int"
    24   where "Legendre a p =
    25     (if ([a = 0] (mod p)) then 0
    26      else if QuadRes p a then 1
    27      else -1)"
    28 
    29 
    30 subsection \<open>A locale for residue rings\<close>
    31 
    32 definition residue_ring :: "int \<Rightarrow> int ring"
    33   where
    34     "residue_ring m =
    35       \<lparr>carrier = {0..m - 1},
    36        monoid.mult = \<lambda>x y. (x * y) mod m,
    37        one = 1,
    38        zero = 0,
    39        add = \<lambda>x y. (x + y) mod m\<rparr>"
    40 
    41 locale residues =
    42   fixes m :: int and R (structure)
    43   assumes m_gt_one: "m > 1"
    44   defines "R \<equiv> residue_ring m"
    45 begin
    46 
    47 lemma abelian_group: "abelian_group R"
    48 proof -
    49   have "\<exists>y\<in>{0..m - 1}. (x + y) mod m = 0" if "0 \<le> x" "x < m" for x
    50   proof (cases "x = 0")
    51     case True
    52     with m_gt_one show ?thesis by simp
    53   next
    54     case False
    55     then have "(x + (m - x)) mod m = 0"
    56       by simp
    57     with m_gt_one that show ?thesis
    58       by (metis False atLeastAtMost_iff diff_ge_0_iff_ge diff_left_mono int_one_le_iff_zero_less less_le)
    59   qed
    60   with m_gt_one show ?thesis
    61     by (fastforce simp add: R_def residue_ring_def mod_add_right_eq ac_simps  intro!: abelian_groupI)
    62 qed
    63 
    64 lemma comm_monoid: "comm_monoid R"
    65   unfolding R_def residue_ring_def
    66   apply (rule comm_monoidI)
    67     using m_gt_one  apply auto
    68   apply (metis mod_mult_right_eq mult.assoc mult.commute)
    69   apply (metis mult.commute)
    70   done
    71 
    72 lemma cring: "cring R"
    73   apply (intro cringI abelian_group comm_monoid)
    74   unfolding R_def residue_ring_def
    75   apply (auto simp add: comm_semiring_class.distrib mod_add_eq mod_mult_left_eq)
    76   done
    77 
    78 end
    79 
    80 sublocale residues < cring
    81   by (rule cring)
    82 
    83 
    84 context residues
    85 begin
    86 
    87 text \<open>
    88   These lemmas translate back and forth between internal and
    89   external concepts.
    90 \<close>
    91 
    92 lemma res_carrier_eq: "carrier R = {0..m - 1}"
    93   by (auto simp: R_def residue_ring_def)
    94 
    95 lemma res_add_eq: "x \<oplus> y = (x + y) mod m"
    96   by (auto simp: R_def residue_ring_def)
    97 
    98 lemma res_mult_eq: "x \<otimes> y = (x * y) mod m"
    99   by (auto simp: R_def residue_ring_def)
   100 
   101 lemma res_zero_eq: "\<zero> = 0"
   102   by (auto simp: R_def residue_ring_def)
   103 
   104 lemma res_one_eq: "\<one> = 1"
   105   by (auto simp: R_def residue_ring_def units_of_def)
   106 
   107 lemma res_units_eq: "Units R = {x. 0 < x \<and> x < m \<and> coprime x m}"
   108   using m_gt_one
   109   unfolding Units_def R_def residue_ring_def
   110   apply auto
   111     apply (subgoal_tac "x \<noteq> 0")
   112      apply auto
   113    apply (metis invertible_coprime_int)
   114   apply (subst (asm) coprime_iff_invertible'_int)
   115    apply (auto simp add: cong_int_def mult.commute)
   116   done
   117 
   118 lemma res_neg_eq: "\<ominus> x = (- x) mod m"
   119   using m_gt_one unfolding R_def a_inv_def m_inv_def residue_ring_def
   120   apply simp
   121   apply (rule the_equality)
   122    apply (simp add: mod_add_right_eq)
   123    apply (simp add: add.commute mod_add_right_eq)
   124   apply (metis add.right_neutral minus_add_cancel mod_add_right_eq mod_pos_pos_trivial)
   125   done
   126 
   127 lemma finite [iff]: "finite (carrier R)"
   128   by (simp add: res_carrier_eq)
   129 
   130 lemma finite_Units [iff]: "finite (Units R)"
   131   by (simp add: finite_ring_finite_units)
   132 
   133 text \<open>
   134   The function \<open>a \<mapsto> a mod m\<close> maps the integers to the
   135   residue classes. The following lemmas show that this mapping
   136   respects addition and multiplication on the integers.
   137 \<close>
   138 
   139 lemma mod_in_carrier [iff]: "a mod m \<in> carrier R"
   140   unfolding res_carrier_eq
   141   using insert m_gt_one by auto
   142 
   143 lemma add_cong: "(x mod m) \<oplus> (y mod m) = (x + y) mod m"
   144   by (auto simp: R_def residue_ring_def mod_simps)
   145 
   146 lemma mult_cong: "(x mod m) \<otimes> (y mod m) = (x * y) mod m"
   147   by (auto simp: R_def residue_ring_def mod_simps)
   148 
   149 lemma zero_cong: "\<zero> = 0"
   150   by (auto simp: R_def residue_ring_def)
   151 
   152 lemma one_cong: "\<one> = 1 mod m"
   153   using m_gt_one by (auto simp: R_def residue_ring_def)
   154 
   155 (* FIXME revise algebra library to use 1? *)
   156 lemma pow_cong: "(x mod m) (^) n = x^n mod m"
   157   using m_gt_one
   158   apply (induct n)
   159   apply (auto simp add: nat_pow_def one_cong)
   160   apply (metis mult.commute mult_cong)
   161   done
   162 
   163 lemma neg_cong: "\<ominus> (x mod m) = (- x) mod m"
   164   by (metis mod_minus_eq res_neg_eq)
   165 
   166 lemma (in residues) prod_cong: "finite A \<Longrightarrow> (\<Otimes>i\<in>A. (f i) mod m) = (\<Prod>i\<in>A. f i) mod m"
   167   by (induct set: finite) (auto simp: one_cong mult_cong)
   168 
   169 lemma (in residues) sum_cong: "finite A \<Longrightarrow> (\<Oplus>i\<in>A. (f i) mod m) = (\<Sum>i\<in>A. f i) mod m"
   170   by (induct set: finite) (auto simp: zero_cong add_cong)
   171 
   172 lemma mod_in_res_units [simp]:
   173   assumes "1 < m" and "coprime a m"
   174   shows "a mod m \<in> Units R"
   175 proof (cases "a mod m = 0")
   176   case True
   177   with assms show ?thesis
   178     by (auto simp add: res_units_eq gcd_red_int [symmetric])
   179 next
   180   case False
   181   from assms have "0 < m" by simp
   182   then have "0 \<le> a mod m" by (rule pos_mod_sign [of m a])
   183   with False have "0 < a mod m" by simp
   184   with assms show ?thesis
   185     by (auto simp add: res_units_eq gcd_red_int [symmetric] ac_simps)
   186 qed
   187 
   188 lemma res_eq_to_cong: "(a mod m) = (b mod m) \<longleftrightarrow> [a = b] (mod m)"
   189   by (auto simp: cong_int_def)
   190 
   191 
   192 text \<open>Simplifying with these will translate a ring equation in R to a congruence.\<close>
   193 lemmas res_to_cong_simps =
   194   add_cong mult_cong pow_cong one_cong
   195   prod_cong sum_cong neg_cong res_eq_to_cong
   196 
   197 text \<open>Other useful facts about the residue ring.\<close>
   198 lemma one_eq_neg_one: "\<one> = \<ominus> \<one> \<Longrightarrow> m = 2"
   199   apply (simp add: res_one_eq res_neg_eq)
   200   apply (metis add.commute add_diff_cancel mod_mod_trivial one_add_one uminus_add_conv_diff
   201     zero_neq_one zmod_zminus1_eq_if)
   202   done
   203 
   204 end
   205 
   206 
   207 subsection \<open>Prime residues\<close>
   208 
   209 locale residues_prime =
   210   fixes p :: nat and R (structure)
   211   assumes p_prime [intro]: "prime p"
   212   defines "R \<equiv> residue_ring (int p)"
   213 
   214 sublocale residues_prime < residues p
   215   unfolding R_def residues_def
   216   using p_prime apply auto
   217   apply (metis (full_types) of_nat_1 of_nat_less_iff prime_gt_1_nat)
   218   done
   219 
   220 context residues_prime
   221 begin
   222 
   223 lemma is_field: "field R"
   224 proof -
   225   have "0 < x \<Longrightarrow> x < int p \<Longrightarrow> coprime (int p) x" for x
   226     by (rule prime_imp_coprime) (auto simp add: zdvd_not_zless)
   227   then show ?thesis
   228     by (intro cring.field_intro2 cring)
   229       (auto simp add: res_carrier_eq res_one_eq res_zero_eq res_units_eq ac_simps)
   230 qed
   231 
   232 lemma res_prime_units_eq: "Units R = {1..p - 1}"
   233   apply (subst res_units_eq)
   234   apply auto
   235   apply (subst gcd.commute)
   236   apply (auto simp add: p_prime prime_imp_coprime_int zdvd_not_zless)
   237   done
   238 
   239 end
   240 
   241 sublocale residues_prime < field
   242   by (rule is_field)
   243 
   244 
   245 section \<open>Test cases: Euler's theorem and Wilson's theorem\<close>
   246 
   247 subsection \<open>Euler's theorem\<close>
   248 
   249 lemma (in residues) totient_eq: "totient (nat m) = card (Units R)"
   250 proof -
   251   have *: "inj_on nat (Units R)"
   252     by (rule inj_onI) (auto simp add: res_units_eq)
   253   define m' where "m' = nat m"
   254   from m_gt_one have "m = int m'" "m' > 1"
   255     by (simp_all add: m'_def)
   256   then have "x \<in> Units R \<longleftrightarrow> x \<in> int ` totatives m'" for x
   257     unfolding res_units_eq
   258     by (cases x; cases "x = m") (auto simp: totatives_def gcd_int_def)
   259   then have "Units R = int ` totatives m'"
   260     by blast
   261   then have "totatives m' = nat ` Units R"
   262     by (simp add: image_image)
   263   then have "card (totatives (nat m)) = card (nat ` Units R)"
   264     by (simp add: m'_def)
   265   also have "\<dots> = card (Units R)"
   266     using * card_image [of nat "Units R"] by auto
   267   finally show ?thesis
   268     by (simp add: totient_def)
   269 qed
   270 
   271 lemma (in residues_prime) totient_eq: "totient p = p - 1"
   272   using totient_eq by (simp add: res_prime_units_eq)
   273 
   274 lemma (in residues) euler_theorem:
   275   assumes "coprime a m"
   276   shows "[a ^ totient (nat m) = 1] (mod m)"
   277 proof -
   278   have "a ^ totient (nat m) mod m = 1 mod m"
   279     by (metis assms finite_Units m_gt_one mod_in_res_units one_cong totient_eq pow_cong units_power_order_eq_one)
   280   then show ?thesis
   281     using res_eq_to_cong by blast
   282 qed
   283 
   284 lemma euler_theorem:
   285   fixes a m :: nat
   286   assumes "coprime a m"
   287   shows "[a ^ totient m = 1] (mod m)"
   288 proof (cases "m = 0 | m = 1")
   289   case True
   290   then show ?thesis by auto
   291 next
   292   case False
   293   with assms show ?thesis
   294     using residues.euler_theorem [of "int m" "int a"] transfer_int_nat_cong
   295     by (auto simp add: residues_def gcd_int_def) force
   296 qed
   297 
   298 lemma fermat_theorem:
   299   fixes p a :: nat
   300   assumes "prime p" and "\<not> p dvd a"
   301   shows "[a ^ (p - 1) = 1] (mod p)"
   302 proof -
   303   from assms prime_imp_coprime [of p a] have "coprime a p"
   304     by (auto simp add: ac_simps)
   305   then have "[a ^ totient p = 1] (mod p)"
   306      by (rule euler_theorem)
   307   also have "totient p = p - 1"
   308     by (rule totient_prime) (rule assms)
   309   finally show ?thesis .
   310 qed
   311 
   312 
   313 subsection \<open>Wilson's theorem\<close>
   314 
   315 lemma (in field) inv_pair_lemma: "x \<in> Units R \<Longrightarrow> y \<in> Units R \<Longrightarrow>
   316     {x, inv x} \<noteq> {y, inv y} \<Longrightarrow> {x, inv x} \<inter> {y, inv y} = {}"
   317   apply auto
   318   apply (metis Units_inv_inv)+
   319   done
   320 
   321 lemma (in residues_prime) wilson_theorem1:
   322   assumes a: "p > 2"
   323   shows "[fact (p - 1) = (-1::int)] (mod p)"
   324 proof -
   325   let ?Inverse_Pairs = "{{x, inv x}| x. x \<in> Units R - {\<one>, \<ominus> \<one>}}"
   326   have UR: "Units R = {\<one>, \<ominus> \<one>} \<union> \<Union>?Inverse_Pairs"
   327     by auto
   328   have "(\<Otimes>i\<in>Units R. i) = (\<Otimes>i\<in>{\<one>, \<ominus> \<one>}. i) \<otimes> (\<Otimes>i\<in>\<Union>?Inverse_Pairs. i)"
   329     apply (subst UR)
   330     apply (subst finprod_Un_disjoint)
   331          apply (auto intro: funcsetI)
   332     using inv_one apply auto[1]
   333     using inv_eq_neg_one_eq apply auto
   334     done
   335   also have "(\<Otimes>i\<in>{\<one>, \<ominus> \<one>}. i) = \<ominus> \<one>"
   336     apply (subst finprod_insert)
   337         apply auto
   338     apply (frule one_eq_neg_one)
   339     using a apply force
   340     done
   341   also have "(\<Otimes>i\<in>(\<Union>?Inverse_Pairs). i) = (\<Otimes>A\<in>?Inverse_Pairs. (\<Otimes>y\<in>A. y))"
   342     apply (subst finprod_Union_disjoint)
   343        apply auto
   344      apply (metis Units_inv_inv)+
   345     done
   346   also have "\<dots> = \<one>"
   347     apply (rule finprod_one)
   348      apply auto
   349     apply (subst finprod_insert)
   350         apply auto
   351     apply (metis inv_eq_self)
   352     done
   353   finally have "(\<Otimes>i\<in>Units R. i) = \<ominus> \<one>"
   354     by simp
   355   also have "(\<Otimes>i\<in>Units R. i) = (\<Otimes>i\<in>Units R. i mod p)"
   356     by (rule finprod_cong') (auto simp: res_units_eq)
   357   also have "\<dots> = (\<Prod>i\<in>Units R. i) mod p"
   358     by (rule prod_cong) auto
   359   also have "\<dots> = fact (p - 1) mod p"
   360     apply (simp add: fact_prod)
   361     using assms
   362     apply (subst res_prime_units_eq)
   363     apply (simp add: int_prod zmod_int prod_int_eq)
   364     done
   365   finally have "fact (p - 1) mod p = \<ominus> \<one>" .
   366   then show ?thesis
   367     by (simp add: cong_int_def res_neg_eq res_one_eq zmod_int)
   368 qed
   369 
   370 lemma wilson_theorem:
   371   assumes "prime p"
   372   shows "[fact (p - 1) = - 1] (mod p)"
   373 proof (cases "p = 2")
   374   case True
   375   then show ?thesis
   376     by (simp add: cong_int_def fact_prod)
   377 next
   378   case False
   379   then show ?thesis
   380     using assms prime_ge_2_nat
   381     by (metis residues_prime.wilson_theorem1 residues_prime.intro le_eq_less_or_eq)
   382 qed
   383 
   384 text \<open>
   385   This result can be transferred to the multiplicative group of
   386   \<open>\<int>/p\<int>\<close> for \<open>p\<close> prime.\<close>
   387 
   388 lemma mod_nat_int_pow_eq:
   389   fixes n :: nat and p a :: int
   390   shows "a \<ge> 0 \<Longrightarrow> p \<ge> 0 \<Longrightarrow> (nat a ^ n) mod (nat p) = nat ((a ^ n) mod p)"
   391   by (simp add: int_one_le_iff_zero_less nat_mod_distrib order_less_imp_le nat_power_eq[symmetric])
   392 
   393 theorem residue_prime_mult_group_has_gen :
   394  fixes p :: nat
   395  assumes prime_p : "prime p"
   396  shows "\<exists>a \<in> {1 .. p - 1}. {1 .. p - 1} = {a^i mod p|i . i \<in> UNIV}"
   397 proof -
   398   have "p \<ge> 2"
   399     using prime_gt_1_nat[OF prime_p] by simp
   400   interpret R: residues_prime p "residue_ring p"
   401     by (simp add: residues_prime_def prime_p)
   402   have car: "carrier (residue_ring (int p)) - {\<zero>\<^bsub>residue_ring (int p)\<^esub>} = {1 .. int p - 1}"
   403     by (auto simp add: R.zero_cong R.res_carrier_eq)
   404 
   405   have "x (^)\<^bsub>residue_ring (int p)\<^esub> i = x ^ i mod (int p)"
   406     if "x \<in> {1 .. int p - 1}" for x and i :: nat
   407     using that R.pow_cong[of x i] by auto
   408   moreover
   409   obtain a where a: "a \<in> {1 .. int p - 1}"
   410     and a_gen: "{1 .. int p - 1} = {a(^)\<^bsub>residue_ring (int p)\<^esub>i|i::nat . i \<in> UNIV}"
   411     using field.finite_field_mult_group_has_gen[OF R.is_field]
   412     by (auto simp add: car[symmetric] carrier_mult_of)
   413   moreover
   414   have "nat ` {1 .. int p - 1} = {1 .. p - 1}" (is "?L = ?R")
   415   proof
   416     have "n \<in> ?R" if "n \<in> ?L" for n
   417       using that \<open>p\<ge>2\<close> by force
   418     then show "?L \<subseteq> ?R" by blast
   419     have "n \<in> ?L" if "n \<in> ?R" for n
   420       using that \<open>p\<ge>2\<close> by (auto intro: rev_image_eqI [of "int n"])
   421     then show "?R \<subseteq> ?L" by blast
   422   qed
   423   moreover
   424   have "nat ` {a^i mod (int p) | i::nat. i \<in> UNIV} = {nat a^i mod p | i . i \<in> UNIV}" (is "?L = ?R")
   425   proof
   426     have "x \<in> ?R" if "x \<in> ?L" for x
   427     proof -
   428       from that obtain i where i: "x = nat (a^i mod (int p))"
   429         by blast
   430       then have "x = nat a ^ i mod p"
   431         using mod_nat_int_pow_eq[of a "int p" i] a \<open>p\<ge>2\<close> by auto
   432       with i show ?thesis by blast
   433     qed
   434     then show "?L \<subseteq> ?R" by blast
   435     have "x \<in> ?L" if "x \<in> ?R" for x
   436     proof -
   437       from that obtain i where i: "x = nat a^i mod p"
   438         by blast
   439       with mod_nat_int_pow_eq[of a "int p" i] a \<open>p\<ge>2\<close> show ?thesis
   440         by auto
   441     qed
   442     then show "?R \<subseteq> ?L" by blast
   443   qed
   444   ultimately have "{1 .. p - 1} = {nat a^i mod p | i. i \<in> UNIV}"
   445     by presburger
   446   moreover from a have "nat a \<in> {1 .. p - 1}" by force
   447   ultimately show ?thesis ..
   448 qed
   449 
   450 end