This deck presents congruence modulo n as an equivalence relation that is also compatible with addition and multiplication, which is what gives the ring Z/nZ. It covers units and the gcd, modular inverses via the extended Euclidean algorithm, the theorems of Fermat and Euler, fast exponentiation, the Chinese Remainder Theorem, and RSA. It targets the traps of cancelling by something that is not a unit, misapplying Fermat's theorem when the gcd is not 1, reducing "mod" to a bare remainder operator, and using the Chinese Remainder Theorem with moduli that are not coprime.
Subject: Foundations of Higher Mathematics · 113 slides · symbolic lesson
Open the interactive version of this deck · Homework for this lesson
Objectives
This deck turns clock arithmetic into real structure. By the end you can:
1. State the definition of congruence and prove it is an equivalence relation that respects addition and multiplication.
2. Work inside the ring of integers modulo n, and decide which elements are units.
3. Compute modular inverses with the extended Euclidean algorithm and solve linear congruences.
4. Apply Fermat's little theorem, Euler's theorem, fast exponentiation, and the Chinese Remainder Theorem, and see why RSA works.
Warm-up
Discussion prompt
Before we open Modular Arithmetic & Congruence: without looking back, what was the main idea of Functions: Injections, Surjections, Bijections, and what could you do by the end of it that you could not do before?
Hint: One sentence for the idea, one for the skill. If the second one is blank, that is the part to revisit.
Answer:
That deck presents functions as a special kind of relation and draws the distinction between the codomain and the image. It covers injective, surjective, and bijective maps and their characterizations in terms of inverses, the behavior of image and preimage under unions and intersections, and the pigeonhole principle. It targets the misconceptions that being one-to-one can be checked on a single pair, that the codomain has no bearing on whether a map is onto, that image distributes over intersection, and that the preimage notation requires an inverse function to exist.
Concept
Before congruence we need one idea: one integer dividing another, exactly, with no remainder.
\[ d \mid m \iff \exists\, k \in \mathbb{Z}\ \text{such that}\ m = dk \]
divides — We say d divides m, written d bar m, when m is an exact integer multiple of d. For example 7 divides 21 because 21 is 7 times 3, but 7 does not divide 20.
Counterexample
Discussion prompt
Before congruence we need one idea: one integer dividing another, exactly, with no remainder.
That is stated as though it always holds. Do one of two things: produce a case where it fails, or say precisely what rules such a case out. "It just does" is not on the menu.
Hint: Hunt at the extremes first — zero, one, negative, empty, equal. If every extreme survives, the reason they survive is the proof.
Concept
Fix a positive integer n, the modulus. Two integers are congruent modulo n when n divides their difference.
\[ a \equiv b \pmod{n} \iff n \mid (a-b) \]
Read it as: a and b are interchangeable as far as multiples of n are concerned. They sit at the same position once you wrap around every n steps.
modulus — The fixed number n you reduce by. Everything in this deck happens relative to a chosen modulus n, which is at least 1.
Definition probe
Sort into buckets
Every line below is part of the definition of divides or of modulus — one or the other, never both. Put each where it belongs.
Picture it
Figure (svg): A circular clock face marked 0 through 11 with an arrow wrapping from 10 past 12 to land on 3.
Discussion prompt
Read the picture before the words. What is this showing, and what is the one thing it is built to make obvious? Commit to an answer, then read on.
Hint: Name the parts, then say what changes between them — and if nothing changes, say what is being held still.
Answer:
A 12-hour clock never shows 15 o'clock. Five hours after 10 o'clock it reads 3, because the hour hand wraps around at 12.
Intuition
A 12-hour clock never shows 15 o'clock. Five hours after 10 o'clock it reads 3, because the hour hand wraps around at 12.
\[ 10 + 5 = 15 \equiv 3 \pmod{12} \]
Modular arithmetic is exactly this wrap-around, done with any modulus. The numbers 3, 15, 27, and negative 9 all name the same clock position when the modulus is 12.
Figure (svg): A circular clock face marked 0 through 11 with an arrow wrapping from 10 past 12 to land on 3.
Analogy
Discussion prompt
Explain It is a clock by analogy to something with no Foundations of Higher Mathematics in it at all — a queue, a recipe, a map, a bank balance, whatever fits. Then say where your analogy breaks.
Hint: An analogy that never breaks is not an analogy, it is the same idea wearing a hat. Find the seam — that is the part that is actually new.
Answer:
A 12-hour clock never shows 15 o'clock. Five hours after 10 o'clock it reads 3, because the hour hand wraps around at 12.
Picture it
Figure (svg): A number line from 0 to 11 folded onto six pegs 0 through 5, with 5 and 11 landing on the same peg.
Discussion prompt
Read the picture before the words. What is this showing, and what is the one thing it is built to make obvious? Commit to an answer, then read on.
Hint: Name the parts, then say what changes between them — and if nothing changes, say what is being held still.
Answer:
Another picture: take the integer number line and fold it so every point lands on one of n pegs, labelled 0 up to n minus 1.
Intuition
Another picture: take the integer number line and fold it so every point lands on one of n pegs, labelled 0 up to n minus 1.
Two integers land on the same peg exactly when they leave the same remainder after division by n. That remainder is the peg's name.
\[ 17 = 2\cdot 6 + 5, \qquad 5 = 0\cdot 6 + 5 \;\Rightarrow\; 17 \equiv 5 \pmod{6} \]
Figure (svg): A number line from 0 to 11 folded onto six pegs 0 through 5, with 5 and 11 landing on the same peg.
Explain it
Discussion prompt
Explain Same remainder, folded number line to a student a year behind you. No notation, no jargon they have not met — and it still has to be true.
Hint: If your explanation needs a symbol they have never seen, you are describing the notation rather than the idea.
Answer:
Another picture: take the integer number line and fold it so every point lands on one of n pegs, labelled 0 up to n minus 1.
Ranking
Put in order
Put the moves of Testing congruences from the definition into the order they have to happen.
Why: These are the moves of the worked example in the order it makes them, and each one is set up by the one before it. Form the difference and test divisibility by 7.
Worked example
Decide each claim by checking whether the modulus divides the difference. Do not compute remainders yet, use the definition directly.
Is 100 congruent to 2 modulo 7?
Why: Form the difference and test divisibility by 7.
\[ 100 - 2 = 98 = 7 \cdot 14 \;\Rightarrow\; 7 \mid 98 \]
Yes, 100 is congruent to 2 modulo 7
Why: Since 7 divides the difference 98, the definition is satisfied.
Is negative 7 congruent to 3 modulo 5?
Why: Negatives are allowed. Test whether 5 divides the difference.
\[ -7 - 3 = -10 = 5 \cdot (-2) \;\Rightarrow\; 5 \mid (-10) \]
Yes, negative 7 is congruent to 3 modulo 5
Why: The difference is a multiple of 5, so they share the peg named 3.
Verify by remainders
Why: Cross-check: 100 divided by 7 leaves 2, and negative 7 equals 5 times negative 2 plus 3, leaving remainder 3. Both agree with the divisibility test.
\[ 100 = 7\cdot 14 + 2, \qquad -7 = 5\cdot(-2) + 3 \]
Picture it
Animation
Shows: Each line of the worked example "Testing congruences from the definition", appearing one at a time.
The same working the example does, in the order a tutor would write it.
Takeaway: Cross-check: 100 divided by 7 leaves 2, and negative 7 equals 5 times negative 2 plus 3, leaving remainder 3. Both agree with the divisibility test.
Concept
These three statements say exactly the same thing. Fluency means switching between them without thinking.
\[ n \mid (a-b) \;\;\Longleftrightarrow\;\; a = b + kn\ \text{for some } k \in \mathbb{Z} \;\;\Longleftrightarrow\;\; a \bmod n = b \bmod n \]
The first is the definition, the second solves for a, and the third compares remainders. Pick whichever makes the current problem easy.
Step zero
Discussion prompt
The three views really do coincide — before any calculation: what is the plan? Name the moves in order, in plain English, without doing the arithmetic.
Hint: It starts with: Write both numbers by the division algorithm
Answer:
Worked example
Prove that n divides the difference exactly when the two numbers leave the same remainder. This justifies using remainders freely.
Write both numbers by the division algorithm
Why: Every integer has a unique quotient and remainder with the remainder between 0 and n minus 1.
\[ a = q_1 n + r_1, \qquad b = q_2 n + r_2, \qquad 0 \le r_1, r_2 < n \]
Subtract to isolate the difference of remainders
Why: The multiples of n collect together, leaving the remainder gap.
\[ a - b = (q_1 - q_2)n + (r_1 - r_2) \]
Note the remainder gap is trapped in a narrow range
Why: Both remainders lie in a window of width n, so their difference cannot reach n in size.
\[ -(n-1) \le r_1 - r_2 \le n-1 \]
Conclude n divides the difference iff the remainders match
Why: n divides a minus b iff n divides the gap; but the only multiple of n in that narrow window is 0, forcing the remainders equal.
\[ n \mid (a-b) \iff n \mid (r_1 - r_2) \iff r_1 - r_2 = 0 \]
Verify on a concrete pair
Why: Take a as 17 and b as 5 with n as 6: the gap is 12, a multiple of 6, and both leave remainder 5. Both sides of the equivalence hold, as required.
Picture it
Animation
Shows: Each line of the worked example "The three views really do coincide", appearing one at a time.
The same working the example does, in the order a tutor would write it.
Takeaway: Take a as 17 and b as 5 with n as 6: the gap is 12, a multiple of 6, and both leave remainder 5. Both sides of the equivalence hold, as required.
Anomaly
Predict first
A student writes this, and it looks reasonable:
A programmer reads mod as the remainder operator that returns one canonical value, and expects it to behave like a calculator key.
It is wrong. Say what breaks — and say it before you turn the page.
Correct: Some languages really do return negative 2 for this, because they define the operator to keep the sign of the dividend.
Congruence is a relationship between integers, not a single output. Negative 7 belongs to the same class as 3, and as 8, and as negative 2, all at once.
Why: Some languages really do return negative 2 for this, because they define the operator to keep the sign of the dividend. Treating that value as THE class loses information.
Trap
A programmer reads mod as the remainder operator that returns one canonical value, and expects it to behave like a calculator key.
\[ -7 \bmod 5 \;\overset{?}{=}\; -2 \]
Claims the answer is negative 2
Why: Some languages really do return negative 2 for this, because they define the operator to keep the sign of the dividend. Treating that value as THE class loses information.
Congruence is a relationship between integers, not a single output. Negative 7 belongs to the same class as 3, and as 8, and as negative 2, all at once.
\[ -7 \equiv 3 \pmod 5, \qquad [-7] = \{\dots, -7, -2, 3, 8, 13, \dots\} \]
Report the canonical representative as 3
Why: The standard representatives modulo 5 are 0,1,2,3,4. Negative 7 plus 10 equals 3, so its class is 3. The equivalence-class view keeps every equal value in view instead of one signed remainder.
Notation
Annotate
From Trap: mod is not just the remainder button — read this one piece at a time. What is each part doing?
On: \( -7 \bmod 5 \;\overset{?}{=}\; -2 \)
Concept
Because congruence bundles interchangeable integers together, it should satisfy the three axioms of an equivalence relation. It does.
\[ a \equiv a; \quad a \equiv b \Rightarrow b \equiv a; \quad a \equiv b \wedge b \equiv c \Rightarrow a \equiv c \pmod n \]
Reflexive, symmetric, transitive. So it carves the integers into disjoint classes, exactly like the folding-onto-pegs picture promised.
Estimation
Predict first
Each axiom reduces to a divisibility fact. Watch how transitivity uses that the sum of two multiples of n is again a multiple of n.
Commit before you compute: what does Proving congruence is an equivalence relation come out to? A rough magnitude and the right form is enough — the point is to have something concrete to be wrong about.
Correct: Verify transitivity on numbers
Why: A prediction you can defend turns the computation into a check rather than a leap of faith — and an answer that contradicts it is caught on the spot. Take 17, 11, 5 modulo 6: 17 minus 11 is 6, 11 minus 5 is 6, and 17 minus 5 is 12, which is 6 times 2.
Worked example
Each axiom reduces to a divisibility fact. Watch how transitivity uses that the sum of two multiples of n is again a multiple of n.
Reflexive
Why: The difference of a with itself is 0, and n divides 0 since 0 equals n times 0.
\[ a - a = 0 = n\cdot 0 \;\Rightarrow\; a \equiv a \pmod n \]
Symmetric
Why: If n divides a minus b, it divides the negative, which is b minus a.
\[ n \mid (a-b) \;\Rightarrow\; n \mid -(a-b) = (b-a) \]
Transitive
Why: Write each difference as a multiple of n, then add: the multiples combine.
\[ a-b = kn,\; b-c = \ell n \;\Rightarrow\; a-c = (k+\ell)n \]
Verify transitivity on numbers
Why: Take 17, 11, 5 modulo 6: 17 minus 11 is 6, 11 minus 5 is 6, and 17 minus 5 is 12, which is 6 times 2. The chained multiple is exactly the sum, confirming the algebra.
\[ (17-11)+(11-5) = 6 + 6 = 12 = 6\cdot 2 = 17 - 5 \]
Concept
The class of an integer collects every integer congruent to it. This is the equivalence class of the relation we just verified.
\[ [a]_n = \{\, x \in \mathbb{Z} : x \equiv a \pmod n \,\} = \{\, a + kn : k \in \mathbb{Z} \,\} \]
residue class — The set of all integers sharing a fixed remainder modulo n. Modulo 5 there are exactly five of them, named 0,1,2,3,4, and every integer lands in exactly one.
Intuition
Because congruence is an equivalence relation, the classes tile the integers with no gaps and no overlaps. There are exactly n of them.
Figure (svg): Five boxes labelled class 0 through class 4, each listing integers three apart, covering all integers modulo 5.
The set of these n classes is the object we will do arithmetic in. It has a name.
Concept
Collect the n residue classes into one finite set. This is the world where modular arithmetic lives.
\[ \mathbb{Z}/n\mathbb{Z} = \{\, [0],\,[1],\,\dots,\,[n-1] \,\} \]
It has exactly n elements. To do algebra here we must add and multiply classes, not just integers. The next question is whether that is even well defined.
Concept
An equivalence relation that is also compatible with the operations is called a congruence. This compatibility is what makes arithmetic on classes legal.
\[ a \equiv a',\; b \equiv b' \pmod n \;\Rightarrow\; a+b \equiv a'+b' \ \text{and}\ ab \equiv a'b' \pmod n \]
In words: if you swap either input for a congruent one, the sum and the product only change to a congruent result. The answer's class never wobbles.
Intuition
To add classes we secretly pick a representative from each, add the integers, and take the class of the result. That is only meaningful if the choice of representative cannot change the answer.
Compatibility guarantees exactly that. Because 3 and 15 name the same class modulo 12, adding 4 to either must land in the same class, and it does: 7 and 19 agree modulo 12.
\[ [3]+[4] = [7], \qquad [15]+[4] = [19], \qquad 7 \equiv 19 \pmod{12} \]
Missing information
Discussion prompt
Prove the multiplication half, the one students get wrong. The trick is to add and subtract a bridging term.
What do you need to know — or decide — before the first line can be written? List everything the problem has to hand you.
Hint: Anything you would have to invent to get started is a thing the problem must supply.
Answer:
Congruence unpacks directly into equations.
Worked example
Prove the multiplication half, the one students get wrong. The trick is to add and subtract a bridging term.
Write the two hypotheses as multiples of n
Why: Congruence unpacks directly into equations.
\[ a = a' + kn, \qquad b = b' + \ell n \]
Multiply and expand
Why: Substitute both and expand the product fully.
\[ ab = (a'+kn)(b'+\ell n) = a'b' + a'\ell n + b'kn + k\ell n^2 \]
Collect every term after the first into a multiple of n
Why: Each of the last three terms carries a factor of n, so their sum is n times an integer.
\[ ab - a'b' = n\,(a'\ell + b'k + k\ell n) \]
Conclude the products are congruent
Why: n divides the difference, which is the definition of congruence for the products.
\[ n \mid (ab - a'b') \;\Rightarrow\; ab \equiv a'b' \pmod n \]
Verify with a swap
Why: Modulo 12 use a as 15 for a-prime 3, and b as 16 for b-prime 4. Then 15 times 16 is 240 and 3 times 4 is 12, and 240 minus 12 is 228, which is 12 times 19. Same class, exactly as the proof promised.
\[ 15\cdot 16 = 240 \equiv 0, \quad 3\cdot 4 = 12 \equiv 0 \pmod{12} \]
Picture it
Animation
Shows: Each line of the worked example "Proving the operations are well defined", appearing one at a time.
The same working the example does, in the order a tutor would write it.
Takeaway: Modulo 12 use a as 15 for a-prime 3, and b as 16 for b-prime 4. Then 15 times 16 is 240 and 3 times 4 is 12, and 240 minus 12 is 228, which is 12 times 19. Same class, exactly as the proof promised.
Anomaly
Predict first
A student writes this, and it looks reasonable:
A strong student over-generalizes: if plus and times respect congruence, surely exponentiation in the exponent does too. So they reduce the exponent modulo n.
It is wrong. Say what breaks — and say it before you turn the page.
Correct: This treats the exponent as if it lived modulo 7.
Compatibility is a statement about the base under plus and times. The exponent is reduced by a different rule, coming later from Fermat and Euler, using the order of the base.
Why: This treats the exponent as if it lived modulo 7. But 2 to the 5th is 32, which is 4 modulo 7, while 2 to the 1st is 2. They are not equal. The base and the exponent obey different moduli.
Trap
A strong student over-generalizes: if plus and times respect congruence, surely exponentiation in the exponent does too. So they reduce the exponent modulo n.
\[ 2^{5} \overset{?}{\equiv} 2^{\,5 \bmod 4} = 2^{1} \pmod{7} \]
Claims 2 to the 5th is 2 to the 1st modulo 7
Why: This treats the exponent as if it lived modulo 7. But 2 to the 5th is 32, which is 4 modulo 7, while 2 to the 1st is 2. They are not equal. The base and the exponent obey different moduli.
Compatibility is a statement about the base under plus and times. The exponent is reduced by a different rule, coming later from Fermat and Euler, using the order of the base.
\[ 2^{5} = 32 \equiv 4 \pmod 7, \qquad \text{exponents reduce modulo the order, not modulo } 7 \]
Reduce the base, keep the exponent honest
Why: You may replace the base by any congruent value, then multiply it out. Only once we know Fermat can we reduce the exponent, and then modulo p minus 1, not modulo p.
Concept
With well-defined addition and multiplication of classes, the set of classes becomes a ring: you can add, subtract, and multiply, with the usual laws.
\[ [a] + [b] = [a+b], \qquad [a]\cdot[b] = [ab] \]
The class of 0 is the additive identity, the class of 1 is the multiplicative identity, and every class has an additive inverse. What is not automatic is a multiplicative inverse.
Pattern
Predict first
The table runs: 0 | 0 | 0 | 0 | 0 | 0 | 0 · 1 | 0 | 1 | 2 | 3 | 4 | 5 · 2 | 0 | 2 | 4 | 0 | 2 | 4 · 3 | 0 | 3 | 0 | 3 | 0 | 3 · 4 | 0 | 4 | 2 | 0 | 4 | 2
In Arithmetic inside Z mod 6, given the rows so far: what is the next one — the row where times is 5?
Correct: 5 | 0 | 5 | 4 | 3 | 2 | 1
| times | 0 | 1 | 2 | 3 | 4 | 5 |
|---|---|---|---|---|---|---|
| 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| 1 | 0 | 1 | 2 | 3 | 4 | 5 |
| 2 | 0 | 2 | 4 | 0 | 2 | 4 |
| 3 | 0 | 3 | 0 | 3 | 0 | 3 |
| 4 | 0 | 4 | 2 | 0 | 4 | 2 |
| 5 | 0 | 5 | 4 | 3 | 2 | 1 |
Why: The relationship between the columns, not the individual numbers, is what generates the next row. Multiply representatives, then take the remainder.
Worked example
Build the multiplication table of the six classes modulo 6, reducing every product. Watch for a surprise the integers never show.
Reduce each product modulo 6
Why: Multiply representatives, then take the remainder. For instance 4 times 5 is 20, and 20 is 6 times 3 plus 2, so it reduces to 2.
| times | 0 | 1 | 2 | 3 | 4 | 5 |
|---|---|---|---|---|---|---|
| 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| 1 | 0 | 1 | 2 | 3 | 4 | 5 |
| 2 | 0 | 2 | 4 | 0 | 2 | 4 |
| 3 | 0 | 3 | 0 | 3 | 0 | 3 |
| 4 | 0 | 4 | 2 | 0 | 4 | 2 |
| 5 | 0 | 5 | 4 | 3 | 2 | 1 |
Spot the zeros away from the zero row
Why: 2 times 3 is 0 modulo 6, yet neither factor is 0. These are zero divisors, impossible for ordinary integers.
\[ 2 \cdot 3 = 6 \equiv 0 \pmod 6 \]
Spot which rows reach 1
Why: Only the rows for 1 and 5 contain a 1. Those classes have multiplicative inverses; the others do not.
Verify the inverse of 5
Why: The table claims 5 times 5 is 1. Check: 25 equals 6 times 4 plus 1, so 25 is 1 modulo 6. So 5 is its own inverse, confirming the table entry.
\[ 5 \cdot 5 = 25 = 6\cdot 4 + 1 \equiv 1 \pmod 6 \]
Picture it
Animation
Shows: Each line of the worked example "Arithmetic inside Z mod 6", appearing one at a time.
The same working the example does, in the order a tutor would write it.
Takeaway: The table claims 5 times 5 is 1. Check: 25 equals 6 times 4 plus 1, so 25 is 1 modulo 6. So 5 is its own inverse, confirming the table entry.
Concept
A unit is a class that has a multiplicative inverse: some other class multiplies it to give 1. The zeros-off-the-diagonal we saw are exactly the non-units.
\[ [a] \text{ is a unit} \iff \exists\, [x]\ \text{with}\ [a][x] = [1] \text{ in } \mathbb{Z}/n\mathbb{Z} \]
unit — An element with a two-sided multiplicative inverse. In the integers only 1 and negative 1 are units; modulo n there can be many, and they form a group under multiplication.
Concept
There is a clean criterion. A class is a unit exactly when its representative shares no factor with the modulus other than 1.
\[ [a] \text{ is a unit in } \mathbb{Z}/n\mathbb{Z} \iff \gcd(a,n) = 1 \]
This is why prime moduli are special: modulo a prime, every nonzero class is a unit, so you can divide by anything nonzero.
Intuition
The reason is Bezout's identity: the greatest common divisor of a and n can always be written as an integer combination of a and n.
\[ \gcd(a,n) = 1 \iff \exists\, x,y \in \mathbb{Z}:\ ax + ny = 1 \]
Read that equation modulo n. The n times y term vanishes, leaving a times x congruent to 1. So x is the inverse of a. When the gcd exceeds 1, no combination can reach 1, and no inverse exists.
\[ ax + ny = 1 \;\Rightarrow\; ax \equiv 1 \pmod n \]
Step zero
Discussion prompt
Finding all units modulo 12 — before any calculation: what is the plan? Name the moves in order, in plain English, without doing the arithmetic.
Hint: It starts with: Compute the gcd of each class with 12
Answer:
Worked example
List the classes coprime to 12. Since 12 factors as 4 times 3, a class is a unit exactly when it avoids the factors 2 and 3.
Compute the gcd of each class with 12
Why: Only classes with gcd equal to 1 qualify.
| a | gcd(a,12) | unit? |
|---|---|---|
| 1 | 1 | yes |
| 2 | 2 | no |
| 3 | 3 | no |
| 4 | 4 | no |
| 5 | 1 | yes |
| 6 | 6 | no |
| 7 | 1 | yes |
| 8 | 4 | no |
| 9 | 3 | no |
| 10 | 2 | no |
| 11 | 1 | yes |
Collect the units
Why: The coprime classes are 1, 5, 7, 11. That is four units.
\[ (\mathbb{Z}/12\mathbb{Z})^{\times} = \{\,1,\,5,\,7,\,11\,\} \]
Verify each is invertible
Why: Each squares to 1 modulo 12: 5 times 5 is 25, 7 times 7 is 49, 11 times 11 is 121, all one more than a multiple of 12. So every listed class really has an inverse, itself.
\[ 5^2 = 25,\; 7^2 = 49,\; 11^2 = 121 \;\equiv\; 1 \pmod{12} \]
Picture it
Animation
Shows: Each line of the worked example "Finding all units modulo 12", appearing one at a time.
The same working the example does, in the order a tutor would write it.
Takeaway: Each squares to 1 modulo 12: 5 times 5 is 25, 7 times 7 is 49, 11 times 11 is 121, all one more than a multiple of 12. So every listed class really has an inverse, itself.
Trap
In ordinary algebra you cancel a common factor from both sides. A student does the same to a congruence without checking whether that factor is a unit.
\[ 3\cdot 2 \equiv 3\cdot 6 \pmod{12} \;\overset{?}{\Rightarrow}\; 2 \equiv 6 \pmod{12} \]
Cancels the 3 and claims 2 is congruent to 6 modulo 12
Why: The left congruence is true: 6 and 18 are both 6 modulo 12. But the conclusion is false, because 6 minus 2 is 4, which 12 does not divide. Cancelling was illegal: gcd of 3 and 12 is 3, so 3 is not a unit.
You may only cancel a factor that is a unit. Cancelling a factor c is legal in general only after dividing the modulus by the gcd of c and n.
\[ ca \equiv cb \pmod n \;\Rightarrow\; a \equiv b \pmod{\tfrac{n}{\gcd(c,n)}} \]
Divide the modulus too
Why: Here gcd of 3 and 12 is 3, so the modulus drops to 4. The correct conclusion is 2 congruent to 6 modulo 4, and indeed 6 minus 2 is 4, which 4 divides.
\[ 2 \equiv 6 \pmod{4} \quad\checkmark \]
Break the constraint
Discussion prompt
The rule this trap just fixed:
You may only cancel a factor that is a unit. Cancelling a factor c is legal in general only after dividing the modulus by the gcd of c and n.
Now break it on purpose. Build a case that violates it and follow the consequences until something visibly fails. Where does the failure first show up — and would you have noticed it if you had not been looking?
Hint: The dangerous rules are the ones whose violation still produces an answer. If yours fails loudly, try to find one that fails quietly.
Answer:
The left congruence is true: 6 and 18 are both 6 modulo 12. But the conclusion is false, because 6 minus 2 is 4, which 12 does not divide. Cancelling was illegal: gcd of 3 and 12 is 3, so 3 is not a unit.
Concept
For a unit, the inverse is the class you multiply by to get 1. It is unique, and it is what plays the role of division modulo n.
\[ a^{-1} \bmod n\ \text{is the unique class } x \in \{0,\dots,n-1\}\ \text{with}\ ax \equiv 1 \pmod n \]
Dividing by a modulo n means multiplying by this inverse. There is no other notion of division here.
Estimation
Predict first
Find the inverse of 5 modulo 12. Because 5 is a unit, it exists and is unique.
Commit before you compute: what does A small inverse by search, then by structure come out to? A rough magnitude and the right form is enough — the point is to have something concrete to be wrong about.
Correct: Verify the inverse
Why: A prediction you can defend turns the computation into a check rather than a leap of faith — and an answer that contradicts it is caught on the spot. 5 times 5 is 25, and 25 is 12 times 2 plus 1, so it is 1 modulo 12.
Worked example
Find the inverse of 5 modulo 12. Because 5 is a unit, it exists and is unique.
Check gcd first
Why: gcd of 5 and 12 is 1, so an inverse exists.
Scan multiples of 5 until one is 1 modulo 12
Why: Compute 5, 10, 15, 20, 25 modulo 12. The last is 1.
\[ 5,\ 10,\ 3,\ 8,\ 1 \pmod{12} \]
Read off the inverse
Why: The fifth multiple, 5 times 5, hit 1. So the inverse of 5 is 5.
\[ 5^{-1} \equiv 5 \pmod{12} \]
Verify the inverse
Why: 5 times 5 is 25, and 25 is 12 times 2 plus 1, so it is 1 modulo 12. The inverse checks out.
\[ 5 \cdot 5 = 25 \equiv 1 \pmod{12} \]
Picture it
Animation
Shows: Each line of the worked example "A small inverse by search, then by structure", appearing one at a time.
The same working the example does, in the order a tutor would write it.
Takeaway: gcd of 5 and 12 is 1, so an inverse exists.
Concept
Searching is fine for small n. For real moduli we need the extended Euclidean algorithm, which produces the Bezout coefficients directly.
\[ \text{it returns } x,y \text{ with } ax + ny = \gcd(a,n) \]
Run the ordinary Euclidean algorithm forward to the gcd, then back-substitute to express that gcd as a combination of a and n. When the gcd is 1, the coefficient of a is the inverse.
Hypothesis
Predict first
Inverse of 11 modulo 26 by extended Euclid is about to be worked. State your hypothesis first: which rule or definition decides this one, and what is the first move it forces? Then watch whether the example agrees with you.
Correct: Forward pass: divide with remainder
Why: Each line divides the previous divisor by the previous remainder.
A hypothesis you wrote down is falsifiable; a vague sense of how it will go is not. If the example opens somewhere else, that gap is the thing worth chasing.
Worked example
This is exactly an RSA-sized step: invert 11 modulo 26. First confirm coprimality by running Euclid down to 1.
Forward pass: divide with remainder
Why: Each line divides the previous divisor by the previous remainder.
\[ 26 = 2\cdot 11 + 4, \quad 11 = 2\cdot 4 + 3, \quad 4 = 1\cdot 3 + 1, \quad 3 = 3\cdot 1 + 0 \]
The gcd is 1, so an inverse exists
Why: The last nonzero remainder is 1, confirming 11 and 26 are coprime.
Back-substitute to reach a combination equal to 1
Why: Start from the 1-line and replace each remainder by its earlier expression.
\[ 1 = 4 - 3 = 4 - (11 - 2\cdot 4) = 3\cdot 4 - 11 = 3(26 - 2\cdot 11) - 11 = 3\cdot 26 - 7\cdot 11 \]
Read the coefficient of 11 modulo 26
Why: The combination gives negative 7 times 11 congruent to 1. Reduce negative 7 to a standard class by adding 26.
\[ -7 \cdot 11 \equiv 1 \pmod{26} \;\Rightarrow\; 11^{-1} \equiv 19 \pmod{26} \]
Verify
Why: 11 times 19 is 209, and 209 is 26 times 8 plus 1, so it is 1 modulo 26. The inverse is confirmed.
\[ 11 \cdot 19 = 209 = 26\cdot 8 + 1 \equiv 1 \pmod{26} \]
Picture it
Animation
Shows: Each line of the worked example "Inverse of 11 modulo 26 by extended Euclid", appearing one at a time.
The same working the example does, in the order a tutor would write it.
Takeaway: 11 times 19 is 209, and 209 is 26 times 8 plus 1, so it is 1 modulo 26. The inverse is confirmed.
Concept
A linear congruence asks for every class of x making a first-degree expression hit a target modulo n.
\[ ax \equiv b \pmod n \]
When a is a unit, there is exactly one solution class, found by multiplying through by the inverse. When a is not a unit, there may be several solutions or none at all.
Intuition
If a is a unit, treat the inverse of a like dividing. Multiply both sides by it and a becomes 1, leaving x alone.
\[ ax \equiv b \;\Rightarrow\; a^{-1}ax \equiv a^{-1}b \;\Rightarrow\; x \equiv a^{-1}b \pmod n \]
Every legal move here is multiplication by a unit, which is reversible. That is why the solution class is unique.
Ranking
Put in order
Put the moves of Solving 3x congruent to 4 modulo 7 into the order they have to happen.
Why: These are the moves of the worked example in the order it makes them, and each one is set up by the one before it. Look for a multiple of 3 that is 1 modulo 7: 3 times 5 is 15, which is 1 modulo 7.
Worked example
Solve for the class of x. Modulo 7 is prime, so 3 is a unit and there will be a unique answer.
Find the inverse of 3 modulo 7
Why: Look for a multiple of 3 that is 1 modulo 7: 3 times 5 is 15, which is 1 modulo 7.
\[ 3 \cdot 5 = 15 \equiv 1 \pmod 7 \;\Rightarrow\; 3^{-1} \equiv 5 \pmod 7 \]
Multiply both sides by 5
Why: This clears the coefficient of x, since 5 times 3 is 1.
\[ 5\cdot 3x \equiv 5\cdot 4 \;\Rightarrow\; x \equiv 20 \pmod 7 \]
Reduce the right side
Why: 20 is 7 times 2 plus 6, so it is 6 modulo 7.
\[ x \equiv 6 \pmod 7 \]
Verify by substituting back
Why: Put x equal to 6 into the original: 3 times 6 is 18, and 18 is 7 times 2 plus 4, so it is 4 modulo 7. The original congruence holds, so x congruent to 6 is correct.
\[ 3\cdot 6 = 18 = 7\cdot 2 + 4 \equiv 4 \pmod 7 \quad\checkmark \]
Picture it
Animation
Shows: Each line of the worked example "Solving 3x congruent to 4 modulo 7", appearing one at a time.
The same working the example does, in the order a tutor would write it.
Takeaway: Put x equal to 6 into the original: 3 times 6 is 18, and 18 is 7 times 2 plus 4, so it is 4 modulo 7. The original congruence holds, so x congruent to 6 is correct.
Anomaly
Predict first
A student writes this, and it looks reasonable:
The student always multiplies by an inverse. Faced with a coefficient sharing a factor with the modulus, they invent an inverse that does not exist.
It is wrong. Say what breaks — and say it before you turn the page.
Correct: gcd of 4 and 6 is 2, so 4 is not a unit and has no inverse.
First check solvability: the congruence has a solution exactly when the gcd of the coefficient and modulus divides the target.
Why: gcd of 4 and 6 is 2, so 4 is not a unit and has no inverse. Worse, the multiples of 4 modulo 6 are 0, 4, 2, 0, 4, 2, never landing on the target 3. There is simply no solution, but the student reports a phantom one.
Trap
The student always multiplies by an inverse. Faced with a coefficient sharing a factor with the modulus, they invent an inverse that does not exist.
\[ 4x \equiv 3 \pmod 6 \]
Tries to invert 4 modulo 6
Why: gcd of 4 and 6 is 2, so 4 is not a unit and has no inverse. Worse, the multiples of 4 modulo 6 are 0, 4, 2, 0, 4, 2, never landing on the target 3. There is simply no solution, but the student reports a phantom one.
First check solvability: the congruence has a solution exactly when the gcd of the coefficient and modulus divides the target.
\[ ax \equiv b \pmod n \text{ solvable} \iff \gcd(a,n) \mid b \]
Test the gcd against the target
Why: Here gcd of 4 and 6 is 2, and 2 does not divide 3, so there is no solution. If instead the target were 2, there would be exactly gcd-many solution classes, here two of them.
\[ \gcd(4,6) = 2 \nmid 3 \;\Rightarrow\; \text{no solution} \]
Translation
\( 4x \equiv 3 \pmod 6 \)
Draw it
Translate both ways. First write the expression above as a sentence with no symbols in it at all. Then cover it, and write your sentence back as notation. If the two versions disagree, the disagreement is the thing to fix.
Concept
The number of units modulo n has its own name and symbol. It counts the classes coprime to n.
\[ \varphi(n) = \#\{\, a : 1 \le a \le n,\ \gcd(a,n) = 1 \,\} \]
For a prime every nonzero class is a unit, and for a product of two distinct primes the count multiplies out.
\[ \varphi(p) = p-1, \qquad \varphi(pq) = (p-1)(q-1)\ \text{for distinct primes } p,q \]
Worked example
Compute three totients, using the prime structure rather than listing when possible.
phi of 7
Why: 7 is prime, so every one of 1 through 6 is coprime to it.
\[ \varphi(7) = 7 - 1 = 6 \]
phi of 12 by listing
Why: The units modulo 12 are 1, 5, 7, 11, which we found earlier.
\[ \varphi(12) = 4 \]
phi of 33 by the product rule
Why: 33 is 3 times 11, both prime, so the totient is 2 times 10.
\[ \varphi(33) = \varphi(3)\varphi(11) = 2 \cdot 10 = 20 \]
Verify phi of 12 against the prime-power formula
Why: Since 12 is 2 squared times 3, the formula gives 12 times one-half times two-thirds, which is 4, matching the direct count.
\[ \varphi(12) = 12\left(1-\tfrac12\right)\left(1-\tfrac13\right) = 12\cdot\tfrac12\cdot\tfrac23 = 4 \quad\checkmark \]
Picture it
Animation
Shows: Each line of the worked example "Computing the totient", appearing one at a time.
The same working the example does, in the order a tutor would write it.
Takeaway: Since 12 is 2 squared times 3, the formula gives 12 times one-half times two-thirds, which is 4, matching the direct count.
Concept
Raising a unit to one less than a prime always returns 1. This is the workhorse for taming large exponents modulo a prime.
\[ p \text{ prime},\ p \nmid a \;\Rightarrow\; a^{\,p-1} \equiv 1 \pmod p \]
The coprimality hypothesis is not decoration. If p divides a, the left side is 0, not 1, and the theorem simply does not apply.
Intuition
Multiplying every nonzero class by a fixed unit just shuffles those classes among themselves, a permutation. So the product of all of them is unchanged.
\[ \prod_{k=1}^{p-1} (a k) \equiv \prod_{k=1}^{p-1} k \pmod p \]
The left side pulls out one factor of a for each term, giving a to the power p minus 1 times the same product. Cancel that product, which is a unit, and 1 remains.
\[ a^{\,p-1}\,(p-1)! \equiv (p-1)! \;\Rightarrow\; a^{\,p-1} \equiv 1 \pmod p \]
Step zero
Discussion prompt
Computing 7 to the 222 modulo 11 with Fermat — before any calculation: what is the plan? Name the moves in order, in plain English, without doing the arithmetic.
Hint: It starts with: Apply Fermat with p equal to 11
Answer:
Worked example
A brute exponent of 222 is hopeless by hand. Fermat collapses it, because 11 is prime and does not divide 7.
Apply Fermat with p equal to 11
Why: Since 7 is coprime to 11, the tenth power is 1.
\[ 7^{10} \equiv 1 \pmod{11} \]
Reduce the exponent modulo 10
Why: Write 222 as 10 times 22 plus 2. The bulk becomes a power of 1.
\[ 7^{222} = \left(7^{10}\right)^{22}\cdot 7^{2} \equiv 1^{22}\cdot 7^{2} \pmod{11} \]
Evaluate the leftover
Why: Only 7 squared remains: 49, which is 11 times 4 plus 5.
\[ 7^{2} = 49 = 11\cdot 4 + 5 \equiv 5 \pmod{11} \]
Verify the exponent split
Why: Check the arithmetic: 10 times 22 is 220, plus 2 is 222, so the exponent was reduced correctly, and the answer is 5.
\[ 10\cdot 22 + 2 = 222 \;\Rightarrow\; 7^{222} \equiv 5 \pmod{11} \]
Picture it
Animation
Shows: Each line of the worked example "Computing 7 to the 222 modulo 11 with Fermat", appearing one at a time.
The same working the example does, in the order a tutor would write it.
Takeaway: Check the arithmetic: 10 times 22 is 220, plus 2 is 222, so the exponent was reduced correctly, and the answer is 5.
Anomaly
Predict first
A student writes this, and it looks reasonable:
The student memorizes the little theorem as a power p minus 1 equals 1, and applies it without checking coprimality.
It is wrong. Say what breaks — and say it before you turn the page.
Correct: But 22 is a multiple of 11, so 22 is 0 modulo 11, and 0 to any positive power is 0, not 1.
Check the hypothesis first. If the prime divides the base, reduce the base to 0 and read off the power directly.
Why: But 22 is a multiple of 11, so 22 is 0 modulo 11, and 0 to any positive power is 0, not 1. Fermat needs the base coprime to the prime; here it fails outright.
Trap
The student memorizes the little theorem as a power p minus 1 equals 1, and applies it without checking coprimality.
\[ 22^{10} \overset{?}{\equiv} 1 \pmod{11} \]
Claims 22 to the 10th is 1 modulo 11
Why: But 22 is a multiple of 11, so 22 is 0 modulo 11, and 0 to any positive power is 0, not 1. Fermat needs the base coprime to the prime; here it fails outright.
Check the hypothesis first. If the prime divides the base, reduce the base to 0 and read off the power directly.
\[ 22 \equiv 0 \pmod{11} \;\Rightarrow\; 22^{10} \equiv 0 \pmod{11} \]
Reduce the base, then decide
Why: For a base coprime to 11, such as 7, Fermat applies and the tenth power is 1. For a multiple of 11 the power is 0. Always test coprimality before invoking the theorem.
Concept
For a composite modulus, the exponent that returns 1 is the totient, not the modulus minus 1.
\[ \gcd(a,n) = 1 \;\Rightarrow\; a^{\varphi(n)} \equiv 1 \pmod n \]
When n is prime the totient is n minus 1, and this collapses back to Fermat. The proof is the same permutation argument, run over the units instead of all nonzero classes.
Missing information
Discussion prompt
Find the last digit of 3 to the 100, which is the same as reducing modulo 10.
What do you need to know — or decide — before the first line can be written? List everything the problem has to hand you.
Hint: Anything you would have to invent to get started is a thing the problem must supply.
Answer:
The units modulo 10 are 1, 3, 7, 9, so the totient is 4.
Worked example
Find the last digit of 3 to the 100, which is the same as reducing modulo 10.
Compute the totient of 10
Why: The units modulo 10 are 1, 3, 7, 9, so the totient is 4.
\[ \varphi(10) = 4 \]
Apply Euler with base 3
Why: 3 is coprime to 10, so the fourth power is 1 modulo 10.
\[ 3^{4} = 81 \equiv 1 \pmod{10} \]
Reduce the exponent modulo 4
Why: 100 is 4 times 25, so the whole power is 1 to the 25th, which is 1.
\[ 3^{100} = \left(3^{4}\right)^{25} \equiv 1 \pmod{10} \]
Verify against the cycle of last digits
Why: Powers of 3 end in 3, 9, 7, 1 repeating with period 4. Since 100 is a multiple of 4, the last digit is 1, agreeing with the answer.
\[ 3,9,7,1,\,3,9,7,1,\dots \;\Rightarrow\; \text{position } 100 \to 1 \]
Picture it
Animation
Shows: Each line of the worked example "Computing 3 to the 100 modulo 10 with Euler", appearing one at a time.
The same working the example does, in the order a tutor would write it.
Takeaway: Powers of 3 end in 3, 9, 7, 1 repeating with period 4. Since 100 is a multiple of 4, the last digit is 1, agreeing with the answer.
Concept
Even after reducing the exponent, powers can be huge. Square-and-multiply computes them with a handful of squarings, reducing at every step so numbers stay small.
\[ a^{2k} = \left(a^{k}\right)^{2}, \qquad a^{2k+1} = a\cdot\left(a^{k}\right)^{2} \]
Reading the exponent in binary, each bit costs one squaring, plus one extra multiply when the bit is 1. This is how computers do modular powers at cryptographic sizes.
Intuition
Write the exponent in binary and you are just summing selected powers of two. Repeated squaring produces those powers-of-two powers one after another.
\[ 13 = 8 + 4 + 1 = (1101)_2 \;\Rightarrow\; a^{13} = a^{8}\cdot a^{4}\cdot a^{1} \]
So you never multiply thirteen copies. You square to reach the eighth, fourth, and first powers, then multiply the chosen ones together.
Estimation
Predict first
Compute 5 to the 13 modulo 23 by repeated squaring, reducing after every square.
Commit before you compute: what does Square-and-multiply for 5 to the 13 modulo 23 come out to? A rough magnitude and the right form is enough — the point is to have something concrete to be wrong about.
Correct: Verify by a left-to-right scan of the bits
Why: A prediction you can defend turns the computation into a check rather than a leap of faith — and an answer that contradicts it is caught on the spot. Scanning 1101 from the top: start 5; square-and-multiply gives 10; square gives 8; square-and-multiply gives 21.
Worked example
Compute 5 to the 13 modulo 23 by repeated squaring, reducing after every square.
Build the powers of two by squaring
Why: Each entry is the square of the one above, reduced modulo 23. For example 16 squared is 256, and 256 is 23 times 11 plus 3, so it reduces to 3, but we only need up to the eighth power here.
| power | value mod 23 |
|---|---|
| 5 to the 1 | 5 |
| 5 to the 2 | 2 |
| 5 to the 4 | 4 |
| 5 to the 8 | 16 |
Confirm the squarings
Why: 5 squared is 25, which is 2; then 2 squared is 4; then 4 squared is 16. Each is already reduced modulo 23.
\[ 5^{2} = 25 \equiv 2, \quad 2^{2} = 4, \quad 4^{2} = 16 \pmod{23} \]
Multiply the pieces for bits 8, 4, 1
Why: Since 13 is 8 plus 4 plus 1, multiply the corresponding powers: 16 times 4 times 5.
\[ 5^{13} = 5^{8}\cdot 5^{4}\cdot 5^{1} \equiv 16\cdot 4\cdot 5 \pmod{23} \]
Reduce the product step by step
Why: 16 times 4 is 64, which is 23 times 2 plus 18, so 18; then 18 times 5 is 90, which is 23 times 3 plus 21, so 21.
\[ 16\cdot 4 = 64 \equiv 18, \quad 18\cdot 5 = 90 \equiv 21 \pmod{23} \]
Verify by a left-to-right scan of the bits
Why: Scanning 1101 from the top: start 5; square-and-multiply gives 10; square gives 8; square-and-multiply gives 21. Same answer, so 5 to the 13 is 21 modulo 23.
\[ 5 \to 10 \to 8 \to 21 \;\Rightarrow\; 5^{13} \equiv 21 \pmod{23} \]
Picture it
Animation
Shows: Each line of the worked example "Square-and-multiply for 5 to the 13 modulo 23", appearing one at a time.
The same working the example does, in the order a tutor would write it.
Takeaway: Scanning 1101 from the top: start 5; square-and-multiply gives 10; square gives 8; square-and-multiply gives 21. Same answer, so 5 to the 13 is 21 modulo 23.
Concept
Several congruences with pairwise coprime moduli can always be solved together, and the joint solution is unique modulo the product of the moduli.
\[ \left. \begin{aligned} x &\equiv a_1 \pmod{n_1}\\ &\;\;\vdots\\ x &\equiv a_k \pmod{n_k} \end{aligned} \right\} \Rightarrow x \text{ unique modulo } n_1 n_2 \cdots n_k \]
Coprimality of the moduli is essential. It is what makes the separate clocks independent, so any combination of readings occurs exactly once per full cycle.
Explain it
Discussion prompt
Explain The Chinese Remainder Theorem to a student a year behind you. No notation, no jargon they have not met — and it still has to be true.
Hint: If your explanation needs a symbol they have never seen, you are describing the notation rather than the idea.
Answer:
Several congruences with pairwise coprime moduli can always be solved together, and the joint solution is unique modulo the product of the moduli.
Intuition
Think of gears with coprime tooth counts. As the whole assembly turns, every possible pairing of gear positions appears exactly once before the pattern repeats.
\[ \mathbb{Z}/n_1 n_2 \mathbb{Z} \;\cong\; \mathbb{Z}/n_1\mathbb{Z} \times \mathbb{Z}/n_2\mathbb{Z} \quad (\gcd(n_1,n_2)=1) \]
The theorem is really this isomorphism: an integer modulo the product is the same data as its list of readings on the coprime parts.
Analogy
Discussion prompt
Explain Independent clocks by analogy to something with no Foundations of Higher Mathematics in it at all — a queue, a recipe, a map, a bank balance, whatever fits. Then say where your analogy breaks.
Hint: An analogy that never breaks is not an analogy, it is the same idea wearing a hat. Find the seam — that is the part that is actually new.
Answer:
Think of gears with coprime tooth counts. As the whole assembly turns, every possible pairing of gear positions appears exactly once before the pattern repeats.
Step zero
Discussion prompt
Solving a three-congruence CRT system — before any calculation: what is the plan? Name the moves in order, in plain English, without doing the arithmetic.
Hint: It starts with: Set the total modulus and the partial products
Answer:
Worked example
Solve the classic system. The moduli 3, 5, 7 are pairwise coprime, so a unique class modulo 105 exists.
\[ x \equiv 2 \pmod 3, \quad x \equiv 3 \pmod 5, \quad x \equiv 2 \pmod 7 \]
Set the total modulus and the partial products
Why: The product is 105; each partial product leaves out one modulus.
\[ N = 105, \quad N_1 = 35, \quad N_2 = 21, \quad N_3 = 15 \]
Invert each partial product against its own modulus
Why: 35 is 2 modulo 3, and 2 inverse is 2; 21 is 1 modulo 5, inverse 1; 15 is 1 modulo 7, inverse 1.
\[ 35^{-1} \equiv 2 \pmod 3, \quad 21^{-1} \equiv 1 \pmod 5, \quad 15^{-1} \equiv 1 \pmod 7 \]
Assemble the weighted sum
Why: Each term is the target times the partial product times its inverse, so it matches one congruence and vanishes in the others.
\[ x \equiv 2\cdot 35\cdot 2 + 3\cdot 21\cdot 1 + 2\cdot 15\cdot 1 = 140 + 63 + 30 = 233 \pmod{105} \]
Reduce modulo 105
Why: 233 minus 210 is 23, so the solution class is 23.
\[ 233 = 105\cdot 2 + 23 \;\Rightarrow\; x \equiv 23 \pmod{105} \]
Verify against all three congruences
Why: 23 is 21 plus 2, so 2 modulo 3 and 2 modulo 7; and 23 is 20 plus 3, so 3 modulo 5. All three original congruences hold, confirming 23.
\[ 23 \equiv 2 \ (3), \quad 23 \equiv 3 \ (5), \quad 23 \equiv 2 \ (7) \quad\checkmark \]
Picture it
Animation
Shows: Each line of the worked example "Solving a three-congruence CRT system", appearing one at a time.
The same working the example does, in the order a tutor would write it.
Takeaway: 23 is 21 plus 2, so 2 modulo 3 and 2 modulo 7; and 23 is 20 plus 3, so 3 modulo 5. All three original congruences hold, confirming 23.
Anomaly
Predict first
A student writes this, and it looks reasonable:
The student applies CRT to any system, ignoring whether the moduli are coprime, and multiplies the moduli to get the combined modulus.
It is wrong. Say what breaks — and say it before you turn the page.
Correct: But 4 and 6 are not coprime; they share the factor 2.
For non-coprime moduli, a solution exists only if the congruences agree on every shared factor. When they do, the combined modulus is the least common multiple, not the product.
Why: But 4 and 6 are not coprime; they share the factor 2. Reducing both congruences modulo 2 gives x is 1 and x is 0 at once, a contradiction. This system has no solution, and 24 is the wrong modulus anyway.
Trap
The student applies CRT to any system, ignoring whether the moduli are coprime, and multiplies the moduli to get the combined modulus.
\[ x \equiv 1 \pmod 4, \quad x \equiv 2 \pmod 6 \;\overset{?}{\Rightarrow}\; \text{unique } x \bmod 24 \]
Claims a unique solution modulo 24
Why: But 4 and 6 are not coprime; they share the factor 2. Reducing both congruences modulo 2 gives x is 1 and x is 0 at once, a contradiction. This system has no solution, and 24 is the wrong modulus anyway.
For non-coprime moduli, a solution exists only if the congruences agree on every shared factor. When they do, the combined modulus is the least common multiple, not the product.
\[ \text{solvable} \iff a_1 \equiv a_2 \pmod{\gcd(n_1,n_2)} \]
Check compatibility on the gcd first
Why: Here gcd of 4 and 6 is 2, and 1 is not congruent to 2 modulo 2, so there is genuinely no solution. Had the readings agreed, the answer would be unique modulo the lcm, which is 12.
\[ 1 \not\equiv 2 \pmod 2 \;\Rightarrow\; \text{no solution} \]
Two truths and a lie
Sort into buckets
Some of these hold up and some are the exact mistakes this lesson is built to prevent. Sort them.
Concept
RSA encrypts by raising a message to a public power, and decrypts by raising to a private power. It works because those two powers compose to the identity, courtesy of Euler.
\[ n = pq, \quad ed \equiv 1 \pmod{\varphi(n)}, \qquad c = m^{e} \bmod n, \quad m = c^{d} \bmod n \]
Since the exponents multiply to 1 modulo the totient, encrypting then decrypting raises the message to a power that is 1 more than a multiple of the totient, and Euler's theorem sends that back to the original message.
\[ \left(m^{e}\right)^{d} = m^{ed} = m^{1 + k\varphi(n)} \equiv m \pmod n \]
Counterexample
Discussion prompt
RSA encrypts by raising a message to a public power, and decrypts by raising to a private power. It works because those two powers compose to the identity, courtesy of Euler.
That is stated as though it always holds. Do one of two things: produce a case where it fails, or say precisely what rules such a case out. "It just does" is not on the menu.
Hint: Hunt at the extremes first — zero, one, negative, empty, equal. If every extreme survives, the reason they survive is the proof.
Ranking
Put in order
Put the moves of A toy RSA round trip into the order they have to happen.
Why: These are the moves of the worked example in the order it makes them, and each one is set up by the one before it. The modulus is the product, and the totient multiplies the two prime-minus-ones.
Worked example
Run RSA with tiny primes to see the machinery close the loop. Take p as 3 and q as 11.
Set up the modulus and totient
Why: The modulus is the product, and the totient multiplies the two prime-minus-ones.
\[ n = 3\cdot 11 = 33, \qquad \varphi(33) = 2\cdot 10 = 20 \]
Pick the public exponent and find the private one
Why: Choose e as 7, coprime to 20. The private d solves 7 d congruent to 1 modulo 20, and 7 times 3 is 21, which is 1.
\[ e = 7, \qquad 7d \equiv 1 \pmod{20} \;\Rightarrow\; d = 3 \]
Encrypt the message 2
Why: Raise 2 to the public exponent 7 modulo 33: 128 is 33 times 3 plus 29.
\[ c = 2^{7} = 128 \equiv 29 \pmod{33} \]
Decrypt with the private exponent
Why: Raise 29 to the 3rd modulo 33. Using 29 congruent to negative 4, the cube is negative 64, and negative 64 plus 66 is 2.
\[ c^{d} = 29^{3} \equiv (-4)^{3} = -64 \equiv 2 \pmod{33} \]
Verify the round trip
Why: Decryption returned 2, the original message. The public and private exponents composed to the identity exactly as Euler's theorem guarantees.
\[ m = 2 \;\to\; c = 29 \;\to\; m = 2 \quad\checkmark \]
Picture it
Animation
Shows: Each line of the worked example "A toy RSA round trip", appearing one at a time.
The same working the example does, in the order a tutor would write it.
Takeaway: Decryption returned 2, the original message. The public and private exponents composed to the identity exactly as Euler's theorem guarantees.
Pattern
1. Reduce first, always
Why: Replace every number by its smallest representative before doing anything. Reductions commute with plus and times, so they never change the answer's class.
2. Check gcd before you divide or invert
Why: A class is a unit, hence invertible or cancellable, exactly when it is coprime to the modulus. Otherwise expect zero divisors and phantom solutions.
3. Get inverses from extended Euclid
Why: The Bezout combination gives the inverse directly, and confirms coprimality on the way.
4. Tame big exponents with Fermat or Euler, then square-and-multiply
Why: Reduce the exponent modulo p minus 1 for a prime, or modulo the totient for a coprime base, then square-and-multiply what remains.
5. Split coprime moduli with CRT
Why: Solve each congruence separately and recombine. If the moduli are not coprime, first check agreement on the gcd.
Pattern
1. Compute the gcd of coefficient and modulus
Why: Call it d. It decides everything about solvability.
\[ d = \gcd(a,n) \]
2. Test whether d divides the target
Why: If it does not, stop: there is no solution. If it does, there are exactly d solution classes.
\[ d \mid b \;? \]
3. Divide the whole congruence by d
Why: This produces a congruence with coefficient coprime to the reduced modulus n over d.
\[ \tfrac{a}{d}x \equiv \tfrac{b}{d} \pmod{\tfrac{n}{d}} \]
4. Multiply by the inverse and spread the solutions
Why: Invert the now-coprime coefficient to get one class modulo n over d, which unpacks into d classes modulo n.
Notation
Annotate
From Solving a linear congruence, step by step — read this one piece at a time. What is each part doing?
On: \( \tfrac{a}{d}x \equiv \tfrac{b}{d} \pmod{\tfrac{n}{d}} \)
Check
Modulo 7 is prime, so 3 is a unit. Find the class that multiplies 3 to give 1.
\[ 3^{-1} \equiv \;?\; \pmod 7 \]
Check your understanding
What is the inverse of 3 modulo 7?
Answer: A
Why: The inverse solves 3 times x congruent to 1 modulo 7. Testing multiples of 3, we get 3 times 5 equal to 15, which is 7 times 2 plus 1, so 15 is 1 modulo 7. Hence the inverse is 5.
Elimination
Eliminate the wrong options
Which of these classes is invertible modulo 12?
3 of these 4 are wrong. Strike them one at a time, and say what rules each one out before you strike the next. The survivor is the answer.
Survives elimination: A
Why: A class is a unit modulo 12 exactly when its gcd with 12 is 1. Since 12 factors as 4 times 3, a unit must avoid the factors 2 and 3. Only 5 is coprime to 12 here, and indeed 5 times 5 is 25, which is 1 modulo 12.
Check
A class is invertible modulo 12 exactly when it shares no factor with 12 other than 1. Only one of these qualifies.
Check your understanding
Which of these classes is invertible modulo 12?
Answer: A
Why: A class is a unit modulo 12 exactly when its gcd with 12 is 1. Since 12 factors as 4 times 3, a unit must avoid the factors 2 and 3. Only 5 is coprime to 12 here, and indeed 5 times 5 is 25, which is 1 modulo 12.
Prediction
Predict first
From 3 times 2 congruent to 3 times 6 modulo 12, what follows correctly?
Answer it in your own words, now, with nothing to choose from. The options are on the next slide — and picking the right one off a list is an easier skill than producing it.
Correct: 2 is congruent to 6 modulo 4
Why: Because 3 is not a unit modulo 12, you cancel only after dividing the modulus by the gcd of 3 and 12, which is 3. So the modulus drops to 12 over 3, which is 4, giving 2 congruent to 6 modulo 4, and indeed 6 minus 2 is 4.
Check
The following congruence is true, because 6 and 18 are both 6 modulo 12. What may you correctly conclude by cancelling the 3?
\[ 3\cdot 2 \equiv 3\cdot 6 \pmod{12} \]
Check your understanding
From 3 times 2 congruent to 3 times 6 modulo 12, what follows correctly?
Answer: A
Why: Because 3 is not a unit modulo 12, you cancel only after dividing the modulus by the gcd of 3 and 12, which is 3. So the modulus drops to 12 over 3, which is 4, giving 2 congruent to 6 modulo 4, and indeed 6 minus 2 is 4.
Check
Use Fermat's little theorem. Note 11 is prime and does not divide 7.
\[ 7^{222} \equiv \;?\; \pmod{11} \]
Check your understanding
What is 7 to the 222 modulo 11?
Answer: A
Why: By Fermat, 7 to the 10 is 1 modulo 11. Writing 222 as 10 times 22 plus 2 leaves 7 squared, which is 49, and 49 is 11 times 4 plus 5. So the answer is 5.
Check
The moduli 3, 5, 7 are pairwise coprime, so there is a unique class modulo 105.
\[ x \equiv 2 \ (3), \quad x \equiv 3 \ (5), \quad x \equiv 2 \ (7) \]
Check your understanding
What is the smallest positive x solving all three congruences?
Answer: A
Why: The CRT weighted sum gives 233, and reducing modulo 105 leaves 23. Checking, 23 is 2 modulo 3, 3 modulo 5, and 2 modulo 7, so 23 is the smallest positive solution.
Check
You have the repeated squares 5 to the 1 is 5, 5 to the 2 is 2, 5 to the 4 is 4, and 5 to the 8 is 16, all modulo 23. Combine them for the thirteenth power.
\[ 5^{13} = 5^{8}\cdot 5^{4}\cdot 5^{1} \equiv \;?\; \pmod{23} \]
Check your understanding
What is 5 to the 13 modulo 23?
Answer: A
Why: Since 13 is 8 plus 4 plus 1, multiply 16 times 4 times 5. First 16 times 4 is 64, which is 18 modulo 23; then 18 times 5 is 90, which is 21 modulo 23. So the answer is 21.
Check
Be careful with the coprimality hypothesis before invoking Fermat.
\[ 22^{10} \equiv \;?\; \pmod{11} \]
Check your understanding
What is 22 to the 10 modulo 11?
Answer: A
Why: Fermat requires the base coprime to the prime, but 22 is 2 times 11, so 22 is 0 modulo 11. Any positive power of 0 is 0, so 22 to the 10 is 0 modulo 11.
Elimination
Eliminate the wrong options
Which class of x solves 7x congruent to 3 modulo 10?
3 of these 4 are wrong. Strike them one at a time, and say what rules each one out before you strike the next. The survivor is the answer.
Survives elimination: A
Why: The inverse of 7 modulo 10 is 3, because 7 times 3 is 21, which is 1 modulo 10. Multiplying both sides by 3 gives x congruent to 9, and checking, 7 times 9 is 63, which is 3 modulo 10.
Check
Modulo 10, the coefficient 7 is a unit. Solve for the class of x.
\[ 7x \equiv 3 \pmod{10} \]
Check your understanding
Which class of x solves 7x congruent to 3 modulo 10?
Answer: A
Why: The inverse of 7 modulo 10 is 3, because 7 times 3 is 21, which is 1 modulo 10. Multiplying both sides by 3 gives x congruent to 9, and checking, 7 times 9 is 63, which is 3 modulo 10.
Connect it up
Draw it
One page, no notation unless you need it: draw how these connect — The modular toolkit · Solving a linear congruence, step by step · Divisibility, the one relation everything rests on · Congruence modulo n · It is a clock. Put an arrow wherever one of them is what makes another possible, and label the arrow with why.
Recap
Congruence modulo n is an equivalence relation that also respects addition and multiplication. That single fact is what turns the integers into the finite ring of classes.
\[ a \equiv a',\ b \equiv b' \;\Rightarrow\; a+b \equiv a'+b',\ ab \equiv a'b' \pmod n \]
Inside that ring, a class is invertible exactly when it is coprime to the modulus. The gcd decides whether you may cancel, divide, or solve, and the extended Euclidean algorithm hands you the inverse.
\[ [a] \text{ a unit} \iff \gcd(a,n) = 1, \qquad ax + ny = 1 \Rightarrow x = a^{-1} \]
Big exponents fall to Fermat and Euler, then to square-and-multiply; independent coprime congruences recombine by the Chinese Remainder Theorem; and RSA is just Euler's theorem wearing a disguise.
\[ a^{\varphi(n)} \equiv 1 \pmod n, \qquad m^{ed} = m^{1+k\varphi(n)} \equiv m \pmod n \]
The through-line: an equivalence relation compatible with the operations is a congruence, and quotienting by it builds a new algebraic world. You will meet this same move again with normal subgroups and ideals.
Want this taught 1-on-1? Alexander tutors Foundations of Higher Mathematics — $55/session, free consultation.