Frequent Links
Euler's totient function
In number theory, Euler's phi function (or Euler's totient function), denoted as <math>\varphi(n)</math> or <math>\phi(n)</math>, is an arithmetic function that counts the positive integers less than or equal to n that are relatively prime to n. (These integers are sometimes referred to as totatives of n.) Thus, if n is a positive integer, then φ(n) is the number of integers k in the range 1 ≤ k ≤ n for which the greatest common divisor gcd(n, k) = 1.^{[1]}^{[2]} Euler's phi function is a multiplicative function, meaning that if two numbers m and n are relatively prime (to each other), then φ(mn) = φ(m)φ(n).^{[3]}^{[4]}
For example let n = 9. Then gcd(9, 3) = gcd(9, 6) = 3 and gcd(9, 9) = 9. The other six numbers in the range 1 ≤ k ≤ 9, that is 1, 2, 4, 5, 7 and 8 are relatively prime to 9. Therefore, φ(9) = 6. As another example, φ(1) = 1 since gcd(1, 1) = 1.
Euler's phi function is important mainly because it gives the order of the multiplicative group of integers modulo n (the group of units of the ring <math>\mathbb{Z}/n\mathbb{Z}</math>). See Euler's theorem. It also plays a key role in the definition of the RSA encryption system.
Contents
 1 History, terminology, and notation
 2 Computing Euler's function
 3 Some values of the function
 4 Euler's theorem
 5 Other formulae involving φ
 6 Generating functions
 7 Growth of the function
 8 Ratio of consecutive values
 9 Totient numbers
 10 Applications
 11 Unsolved problems
 12 See also
 13 Notes
 14 References
 15 External links
History, terminology, and notation
Leonhard Euler introduced the function in 1763.^{[5]}^{[6]}^{[7]} However, he did not at that time choose any specific symbol to denote it. In a 1784 publication Euler studied the function further, choosing the Greek letter π to denote it: he wrote πD for "the multitude of numbers less than D, and which have no common divisor with it".^{[8]} The standard notation^{[6]}^{[9]} φ(A) comes from Gauss's 1801 treatise Disquisitiones Arithmeticae.^{[10]} However, Gauss didn't use parentheses around the argument and wrote φA. Thus, it is usually called Euler's phi function or simply the phi function.
In 1879 J. J. Sylvester coined the term totient for this function,^{[11]}^{[12]} so it is also referred to as the totient function, the Euler totient, or Euler's totient. Jordan's totient is a generalization of Euler's.
The cototient of n is defined as n – φ(n), i.e. the number of positive integers less than or equal to n that are divisible by at least one prime that also divides n.
Computing Euler's function
There are several formulas for the Euler's phi function.
Euler's product formula
It states
 <math>
\varphi(n) =n \prod_{p\mid n} \left(1\frac{1}{p}\right), </math> where the product is over the distinct prime numbers dividing n. (The notation is described in the article Arithmetical function.)
The proof of Euler's product formula depends on two important facts.
The function φ(n) is multiplicative
This means that if gcd(m, n) = 1, then φ(mn) = φ(m) φ(n). (Sketch of proof: let A, B, C be the sets of residue classes moduloandcoprime to m, n, mn respectively; then there is a bijection between A × B and C, by the Chinese remainder theorem.)
φ(p^{k}) = p^{k} − p^{k−1} = p^{k−1}(p − 1)
That is, if p is prime and k ≥ 1 then
 <math>\varphi(p^k) = p^k p^{k1} =p^{k1}(p1) = p^k \left( 1  \frac{1}{p} \right).</math>
Proof: Since p is a prime number the only possible values of gcd(p^{k}, m) are 1, p, p^{2}, ..., p^{k}, and the only way for gcd(p^{k}, m) to not equal 1 is for m to be a multiple of p. The multiples of p that are less than or equal to p^{k} are p, 2p, 3p, ..., p^{k − 1}p = p^{k}, and there are p^{k − 1} of them. Therefore the other p^{k} − p^{k − 1} numbers are all relatively prime to p^{k}.
Proof of the formula: The fundamental theorem of arithmetic states that if n > 1 there is a unique expression for n,
 <math>n = p_1^{k_1} \cdots p_r^{k_r}, </math>
where p_{1} < p_{2} < ... < p_{r} are prime numbers and each k_{i} ≥ 1. (The case n = 1 corresponds to the empty product.)
Repeatedly using the multiplicative property of φ and the formula for φ(p^{k}) gives
 <math>
\begin{align} \varphi(n) &= \varphi(p_1^{k_1}) \varphi(p_2^{k_2}) \cdots\varphi(p_r^{k_r})\\
&= p_1^{k_1} \left(1 \frac{1}{p_1} \right) p_2^{k_2} \left(1 \frac{1}{p_2} \right) \cdots p_r^{k_r} \left(1 \frac{1}{p_r} \right)\\
&= p_1^{k_1} p_2^{k_2} \cdots p_r^{k_r} \left(1 \frac{1}{p_1} \right) \left(1 \frac{1}{p_2} \right) \cdots \left(1 \frac{1}{p_r} \right)\\
&=n \left(1 \frac{1}{p_1} \right)\left(1 \frac{1}{p_2} \right) \cdots\left(1 \frac{1}{p_r} \right). \end{align} </math>
This is Euler's product formula.
Example
 <math>\varphi(36)=\varphi\left(2^2 3^2\right)=36\left(1\frac{1}{2}\right)\left(1\frac{1}{3}\right)=36\cdot\frac{1}{2}\cdot\frac{2}{3}=12.</math>
In words, this says that the distinct prime factors of 36 are 2 and 3; half of the thirtysix integers from 1 to 36 are divisible by 2, leaving eighteen; a third of those are divisible by 3, leaving twelve numbers that are coprime to 36. And indeed there are twelve positive integers that are coprime with 36 and lower than 36: 1, 5, 7, 11, 13, 17, 19, 23, 25, 29, 31, and 35.
Fourier transform
The totient is the discrete Fourier transform of the gcd, evaluated at 1: (Schramm (2008))
 <math>\begin{align}
\mathcal{F} \left\{ \mathbf{x} \right\}[m] &= \sum\limits_{k=1}^n x_k \cdot e^{{2\pi i}\frac{mk}{n}}, \mathbf{x_k} = \left\{ \gcd(k,n) \right \} \quad\text{for}\, k \in \left\{1 \dots n \right\} \\ \varphi (n) &= \mathcal{F} \left\{ \mathbf{x} \right\}[1] = \sum\limits_{k=1}^n \gcd(k,n) e^{{2\pi i}\frac{k}{n}}.
\end{align}</math> The real part of this formula is
 <math>\varphi (n)=\sum\limits_{k=1}^n \gcd(k,n) \cos {2\pi\frac{k}{n}}.</math>
Note that unlike the other two formulae (the Euler product and the divisor sum) this one does not require knowing the factors of n. However, it does involve the calculation of the greatest common divisor of n and every positive integer less than n, which would suffice to provide the factorization anyway.
Divisor sum
The property established by Gauss,^{[13]} that
 <math>
\sum_{d\mid n}\varphi(d)=n, </math> where the sum is over all positive divisors d of n, can be proven in several ways. (see Arithmetical function for notational conventions.)
One way is to note that φ(d) is also equal to the number of possible generators of the cyclic group C_{d}; specifically, if C_{d} = <g>, then g^{k} is a generator for every k coprime to d. Since every element of C_{n} generates a cyclic subgroup, and all subgroups of C_{d} ≤ C_{n} are generated by some element of C_{n}, the formula follows.^{[14]} In the article Root of unity Euler's formula is derived by using this argument in the special case of the multiplicative group of the nth roots of unity.
This formula can also be derived in a more concrete manner.^{[15]} Let n = 20 and consider the fractions between 0 and 1 with denominator 20:
 <math>
\tfrac{ 1}{20},\,\tfrac{ 2}{20},\,\tfrac{ 3}{20},\,\tfrac{ 4}{20},\, \tfrac{ 5}{20},\,\tfrac{ 6}{20},\,\tfrac{ 7}{20},\,\tfrac{ 8}{20},\, \tfrac{ 9}{20},\,\tfrac{10}{20},\,\tfrac{11}{20},\,\tfrac{12}{20},\, \tfrac{13}{20},\,\tfrac{14}{20},\,\tfrac{15}{20},\,\tfrac{16}{20},\, \tfrac{17}{20},\,\tfrac{18}{20},\,\tfrac{19}{20},\,\tfrac{20}{20}
</math>
Put them into lowest terms:
 <math>
\tfrac{ 1}{20},\,\tfrac{ 1}{10},\,\tfrac{ 3}{20},\,\tfrac{ 1}{ 5},\, \tfrac{ 1}{ 4},\,\tfrac{ 3}{10},\,\tfrac{ 7}{20},\,\tfrac{ 2}{ 5},\, \tfrac{ 9}{20},\,\tfrac{ 1}{ 2},\,\tfrac{11}{20},\,\tfrac{ 3}{ 5},\, \tfrac{13}{20},\,\tfrac{ 7}{10},\,\tfrac{ 3}{ 4},\,\tfrac{ 4}{ 5},\, \tfrac{17}{20},\,\tfrac{ 9}{10},\,\tfrac{19}{20},\,\tfrac{ 1}{ 1}
</math>
First note that all the divisors of 20 are denominators. And second, note that there are 20 fractions. Which fractions have 20 as denominator? The ones whose numerators are relatively prime to 20 <math> \left(\tfrac{ 1}{20},\,\tfrac{ 3}{20},\,\tfrac{ 7}{20},\,\tfrac{ 9}{20},\,\tfrac{ 11}{20},\,\tfrac{13}{20},\,\tfrac{17}{20},\,\tfrac{19}{20}\right).</math> By definition this is φ(20) fractions. Similarly, there are φ(10) = 4 fractions with denominator 10 <math> \left(\tfrac{ 1}{10},\,\tfrac{ 3}{10},\,\tfrac{ 7}{10},\,\tfrac{ 9}{10}\right),</math> φ(5) = 4 fractions with denominator 5 <math> \left(\tfrac{ 1}{5},\,\tfrac{ 2}{5},\,\tfrac{ 3}{5},\,\tfrac{ 4}{5}\right),</math> and so on.
In detail, we're considering the fractions of the form k/n where k is an integer from 1 to n inclusive. Upon reducing these to lowest terms, each fraction will have as its denominator some divisor of n. We can group the fractions together by denominator, and we must show that for a given divisor d of n, the number of such fractions with denominator d is φ(d).
Note that to reduce k/n to lowest terms, we divide the numerator and denominator by gcd(k, n). The reduced fractions with denominator d are therefore precisely the ones originally of the form k/n in which gcd(k, n)=n/d. The question therefore becomes: how many k are there less than or equal to n which verify gcd(k, n)=n/d? Any such number must clearly be a multiple of n/d, but it must also be coprime to d (if it had any common divisor s with d, then sn/d would be a larger common divisor of n and k). Conversely, any multiple k of n/d which is coprime to d will satisfy gcd(n, k)=n/d. We can generate φ(d) such numbers by taking the numbers less than d coprime to d and multiplying each one by n/d (these products will of course each by smaller than n, as required). This in fact generates all such numbers, as if k is a multiple of n/d coprime to d (and less than n), then k/(n/d) will still be coprime to d, and must also be smaller than d, else k would be larger than n. Thus there are precisely φ(d) values of k less than or equal to n such that gcd(k, n)=n/d, which was to be demonstrated.
Möbius inversion gives
 <math>
\varphi(n) = \sum_{d\mid n} d \cdot \mu\left(\frac{n}{d} \right) = n\sum_{d\mid n} \frac{\mu (d)}{d},
</math>
where μ is the Möbius function.
This formula may also be derived from the product formula by multiplying out <math> \prod_{p\mid n} \left(1  \frac{1}{p}\right) </math> to get <math> \sum_{d\mid n} \frac{\mu (d)}{d}. </math>
Riemann zeta function limit
For <math> n>1 </math> the Euler totient function can be calculated as a limit involving the Riemann zeta function:^{[citation needed]}
 <math> \varphi(n)=n\lim\limits_{s \rightarrow 1} \zeta(s)\sum\limits_{dn} \mu(d)(e^{1/d})^{(s1)}</math>
where
<math> \zeta(s)</math> is the Riemann zeta function, <math> \mu</math> is the Möbius function, <math> e</math> is e (mathematical constant), and <math> d</math> is a divisor.
Some values of the function
The first 99 values (sequence A000010 in OEIS) are shown in the table and graph below:^{[16]}
<math>\varphi(n)</math>  +0  +1  +2  +3  +4  +5  +6  +7  +8  +9 

0+  1  1  2  2  4  2  6  4  6  
10+  4  10  4  12  6  8  8  16  6  18 
20+  8  12  10  22  8  20  12  18  12  28 
30+  8  30  16  20  16  24  12  36  18  24 
40+  16  40  12  42  20  24  22  46  16  42 
50+  20  32  24  52  18  40  24  36  28  58 
60+  16  60  30  36  32  48  20  66  32  44 
70+  24  70  24  72  36  40  36  60  24  78 
80+  32  54  40  82  24  64  42  56  40  88 
90+  24  72  44  60  46  72  32  96  42  60 
The top line in the graph, y = n − 1, is a true upper bound. It is attained whenever n is prime. There is no lower bound that is a straight line of positive slope; no matter how gentle the slope of a line is, there will eventually be points of the plot below the line. More precisely, the lower limit of the graph is proportional to n/log log n rather than being linear.^{[17]}
Euler's theorem
This states that if a and n are relatively prime then
 <math> a^{\varphi(n)} \equiv 1\mod n.\,</math>
The special case where n is prime is known as Fermat's little theorem.
This follows from Lagrange's theorem and the fact that φ(n) is the order of the multiplicative group of integers modulo n.
The RSA cryptosystem is based on this theorem: it implies that the inverse of the function <math>a\mapsto a^e \mod n</math>, where <math>e</math> is the (public) encryption exponent, is the function <math>b\mapsto b^d \mod n</math>, where <math>d</math>, the (private) decryption exponent, is the multiplicative inverse of <math>e</math> modulo <math>\varphi(n)</math>. The difficulty of computing <math>\varphi(n)</math> without knowing the factorization of <math>n</math> is thus the difficulty of computing <math>d</math>: this is known as the RSA problem which can be solved by factoring <math>n</math>. The owner of the private key knows the factorization, since an RSA private key is constructed by choosing <math>n</math> as the product of two (randomly chosen) large primes <math>p</math> and <math>q</math>. Only <math>n</math> is publicly disclosed, and given the difficulty to factor large numbers we have the guarantee that noone else knows the factorization.
Other formulae involving φ
 <math>a\mid b</math> implies <math>\varphi(a)\mid\varphi(b).</math>
 <math> n \mid \varphi(a^n1)</math> (a, n > 1)
 <math>\varphi(mn) = \varphi(m)\varphi(n)\cdot\frac{d}{\varphi(d)}</math> where d = gcd(m, n). Note the special cases
 <math>
\varphi(2m) = \begin{cases} 2\varphi(m) &\text{ if } m \text{ is even} \\ \varphi(m) &\text{ if } m \text{ is odd} \end{cases} </math> and
 <math>\;\varphi\left(n^m\right) = n^{m1}\varphi(n).
</math>
 <math>\varphi(\mathrm{lcm}(m,n))\cdot\varphi(\mathrm{gcd}(m,n)) = \varphi(m)\cdot\varphi(n).</math>
 Compare this to the formula <math>\mathrm{lcm}(m,n)\cdot \mathrm{gcd}(m,n) = m \cdot n.</math> (See lcm).
 <math>\varphi(n)\;</math> is even for <math>n \geq 3.</math> Moreover, if n has r distinct odd prime factors, <math>2^r \mid \varphi(n).</math>
 For any a > 1 and n > 6 such that <math> 4 \nmid n </math> there exists an <math> l \geq 2n </math> such that <math> l \mid \varphi(a^n1)</math>.
 <math>\sum_{d \mid n} \frac{\mu^2(d)}{\varphi(d)} = \frac{n}{\varphi(n)}</math> ^{[18]}
 <math>\sum_{1\le k\le n \atop (k,n)=1}\!\!k = \frac{1}{2}n\varphi(n)\text{ for }n>1</math>
 <math>\sum_{k=1}^n\varphi(k) = \frac{1}{2}\left(1+ \sum_{k=1}^n \mu(k)\left\lfloor\frac{n}{k}\right\rfloor^2\right)
=\frac3{\pi^2}n^2+O\left(n(\log n)^{2/3}(\log\log n)^{4/3}\right)</math> (^{[19]} cited in ^{[20]})
 <math>\sum_{k=1}^n\frac{\varphi(k)}{k} = \sum_{k=1}^n\frac{\mu(k)}{k}\left\lfloor\frac{n}{k}\right\rfloor=\frac6{\pi^2}n+O\left((\log n)^{2/3}(\log\log n)^{4/3}\right)</math> ^{[19]}
 <math>\sum_{k=1}^n\frac{k}{\varphi(k)} = \frac{315\zeta(3)}{2\pi^4}n\frac{\log n}2+O\left((\log n)^{2/3}\right)</math> ^{[21]}
 <math>\sum_{k=1}^n\frac{1}{\varphi(k)} = \frac{315\zeta(3)}{2\pi^4}\left(\log n+\gamma\sum_{p\text{ prime}}\frac{\log p}{p^2p+1}\right)+O\left(\frac{(\log n)^{2/3}}n\right)</math> ^{[22]}
(here γ is the Euler constant).
 <math>\sum_{1\le k\le n \atop (k,m)=1} 1 = n \frac {\varphi(m)}{m} +
O \left ( 2^{\omega(m)} \right ),</math>
where m > 1 is a positive integer and ω(m) is the number of distinct prime factors of m. (a, b) is a standard abbreviation for gcd(a, b).^{[23]}
Menon's identity
In 1965 P. Kesava Menon proved
 <math>
\sum_{\stackrel{1\le k\le n}{ \gcd(k,n)=1}} \gcd(k1,n) =\varphi(n)d(n), </math> where d(n) = σ_{0}(n) is the number of divisors of n.
Formulae involving the golden ratio
Schneider^{[24]} found a pair of identities connecting the totient function, the golden ratio and the Möbius function <math>\mu(n)</math>. In this section <math>\varphi(n)</math> is the totient function, and <math> \phi = \frac{1+\sqrt{5}}{2}= 1.618\dots </math> is the golden ratio.
They are:
 <math>
\phi=\sum_{k=1}^\infty\frac{\varphi(k)}{k}\log\left(1\frac{1}{\phi^k}\right) </math> and
 <math>
\frac{1}{\phi}=\sum_{k=1}^\infty\frac{\mu(k)}{k}\log\left(1\frac{1}{\phi^k}\right). </math> Subtracting them gives
 <math>
\sum_{k=1}^\infty\frac{\mu(k)\varphi(k)}{k}\log\left(1\frac{1}{\phi^k}\right)=1. </math> Applying the exponential function to both sides of the preceding identity yields an infinite product formula for Euler's number e
 <math>e= \prod_{k=1}^{\infty} \left(1\frac{1}{\phi^k}\right)^\frac{\mu(k)\varphi(k)}{k}. </math>
The proof is based on the formulae
 <math>
\sum_{k=1}^\infty\frac{\varphi(k)}{k}(\log(1x^k))=\frac{x}{1x} </math> and <math> \sum_{k=1}^\infty\frac{\mu(k)}{k}(\log(1x^k))=x, </math> valid for 0 < x < 1.
Generating functions
The Dirichlet series for φ(n) may be written in terms of the Riemann zeta function as:^{[25]}
 <math>\sum_{n=1}^\infty \frac{\varphi(n)}{n^s}=\frac{\zeta(s1)}{\zeta(s)}.</math>
The Lambert series generating function is^{[26]}
 <math>\sum_{n=1}^{\infty} \frac{\varphi(n) q^n}{1q^n}= \frac{q}{(1q)^2}</math>
which converges for q < 1.
Both of these are proved by elementary series manipulations and the formulae for φ(n).
Growth of the function
In the words of Hardy & Wright, the order of φ(n) is "always ‘nearly n’."^{[27]}
First^{[28]}
 <math>
\lim\sup \frac{\varphi(n)}{n}= 1, </math> but as n goes to infinity,^{[29]} for all δ > 0
 <math>
\frac{\varphi(n)}{n^{1\delta}}\rightarrow\infty. </math> These two formulae can be proved by using little more than the formulae for φ(n) and the divisor sum function σ(n).
In fact, during the proof of the second formula, the inequality
 <math>
\frac {6}{\pi^2} < \frac{\varphi(n) \sigma(n)}{n^2} < 1, </math> true for n > 1, is proven.
We also have^{[17]}
 <math>
\lim\inf\frac{\varphi(n)}{n}\log\log n = e^{\gamma}. </math> Here γ is Euler's constant, γ = 0.577215665..., e^{γ} = 1.7810724..., e^{−γ} = 0.56145948... .
Proving this doesn't quite require the prime number theorem.^{[30]}^{[31]} Since log log (n) goes to infinity, this formula shows that
 <math>
\lim\inf\frac{\varphi(n)}{n}= 0. </math>
In fact, more is true.^{[32]}^{[33]}
 <math>
\varphi(n) > \frac {n} {e^\gamma\; \log \log n + \frac {3} {\log \log n}} </math> for n > 2, and
 <math>
\varphi(n) < \frac {n} {e^{ \gamma}\log \log n} </math> for infinitely many n.
The second inequality was shown by JeanLouis Nicolas. Ribenboim says "The method of proof is interesting, in that the inequality is shown first under the assumption that the Riemann hypothesis is true, secondly under the contrary assumption."^{[33]}
For the average order, we have^{[19]}^{[34]}
 <math>
\varphi(1)+\varphi(2)+\cdots+\varphi(n) = \frac{3n^2}{\pi^2}+O\left(n(\log n)^{2/3}(\log\log n)^{4/3}\right)\ \ (n\rightarrow\infty), </math> due to Arnold Walfisz, its proof exploiting estimates on exponential sums due to I. M. Vinogradov and N.M. Korobov (this is currently the best known estimate of this type). The "Big O" stands for a quantity that is bounded by a constant times the function of "n" inside the parentheses (which is small compared to n^{2}).
This result can be used to prove^{[35]} that the probability of two randomly chosen numbers being relatively prime is <math>\tfrac{6}{\pi^2}.</math>
Ratio of consecutive values
In 1950 Somayajulu proved^{[36]}^{[37]}
 <math>
\lim\inf \frac{\varphi(n+1)}{\varphi(n)}= 0 </math> and
 <math>
\lim\sup \frac{\varphi(n+1)}{\varphi(n)}= \infty. </math> In 1954 Schinzel and Sierpiński strengthened this, proving^{[36]}^{[37]} that the set
 <math>
\left\{\frac{\varphi(n+1)}{\varphi(n)},\;\;n = 1,2,\cdots\right\} </math> is dense in the positive real numbers. They also proved^{[36]} that the set
 <math>
\left\{\frac{\varphi(n)}{n},\;\;n = 1,2,\cdots\right\} </math> is dense in the interval (0, 1).
Totient numbers
A totient number is a value of Euler's totient function: that is, an m for which there is at least one x for which φ(x) = m. The valency or multiplicity of a totient number m is the number of solutions to this equation.^{[38]} A nontotient is a natural number which is not a totient number: there are infinitely many nontotients,^{[39]} and indeed every odd number has an even multiple which is a nontotient.^{[40]}^{[clarification needed]}
The number of totient numbers up to a given limit x is
 <math>\frac{x}{\log x}\exp\left({ (C+o(1))(\log\log\log x)^2 }\right) \ </math>
for a constant C = 0.8178146... .^{[41]}
If counted accordingly to multiplicity, the number of totient numbers up to a given limit x is
 <math>\vert\{ n : \phi(n) \le x \}\vert = \frac{\zeta(2)\zeta(3)}{\zeta(6)} \cdot x + R(x) \ </math>
where the error term R is of order at most <math>x / (\log x)^k</math> for any positive k.^{[42]}
It is known that the multiplicity of m exceeds m^{δ} infinitely often for any δ < 0.55655.^{[43]}^{[44]}
Ford's theorem
Ford (1999) proved that for every integer k ≥ 2 there is a totient number m of multiplicity k: that is, for which the equation φ(x) = m has exactly k solutions; this result had previously been conjectured by Wacław Sierpiński,^{[45]} and it had been obtained as a consequence of Schinzel's hypothesis H.^{[41]} Indeed, each multiplicity that occurs, does so infinitely often.^{[41]}^{[44]}
However, no number m is known with multiplicity k = 1. Carmichael's totient function conjecture is the statement that there is no such m.^{[46]}
Applications
Cyclotomy
In the last section of the Disquisitiones^{[47]}^{[48]} Gauss proves^{[49]} that a regular ngon can be constructed with straightedge and compass if φ(n) is a power of 2. If n is a power of an odd prime number the formula for the totient says its totient can be a power of two only if a) n is a first power and b) n − 1 is a power of 2. The primes that are one more than a power of 2 are called Fermat primes, and only five are known: 3, 5, 17, 257, and 65537. Fermat and Gauss knew of these. Nobody has been able to prove whether there are any more.
Thus, a regular ngon has a straightedgeandcompass construction if n is a product of distinct Fermat primes and any power of 2. The first few such n are^{[50]} 2, 3, 4, 5, 6, 8, 10, 12, 15, 16, 17, 20, 24, 30, 32, 34, 40, ... . (sequence A003401 in OEIS)
The RSA cryptosystem
Setting up an RSA system involves choosing large prime numbers p and q, computing n = pq and k = φ(n), and finding two numbers e and d such that ed ≡ 1 (mod k). The numbers n and e (the "encryption key") are released to the public, and d (the "decryption key") is kept private.
A message, represented by an integer m, where 0 < m < n, is encrypted by computing S = m^{e} (mod n).
It is decrypted by computing t = S^{d} (mod n). Euler's Theorem can be used to show that if 0 < t < n, then t = m.
The security of an RSA system would be compromised if the number n could be factored or if φ(n) could be computed without factoring n.
Unsolved problems
Lehmer's conjecture
If p is prime, then φ(p) = p − 1. In 1932 D. H. Lehmer asked if there are any composite numbers n such that φ(n)  n − 1. None are known.^{[51]}
In 1933 he proved that if any such n exists, it must be odd, squarefree, and divisible by at least seven primes (i.e. ω(n) ≥ 7). In 1980 Cohen and Hagis proved that n > 10^{20} and that ω(n) ≥ 14.^{[52]} Further, Hagis showed that if 3 divides n then n > 10^{1937042} and ω(n) ≥ 298848.^{[53]}^{[54]}
Carmichael's conjecture
This states that there is no number n with the property that for all other numbers m, m ≠ n, φ(m) ≠ φ(n). See Ford's theorem above.
As stated in the main article, if there is a single counterexample to this conjecture, there must be infinitely many counterexamples, and the smallest one has at least ten billion digits in base 10.^{[38]}
See also
 Carmichael function
 Duffin–Schaeffer conjecture
 Generalizations of Fermat's little theorem
 Highly composite number
 Multiplicative group of integers modulo n
 Ramanujan sum
Notes
 ^ Long (1972, p. 85)
 ^ Pettofrezzo & Byrkit (1970, p. 72)
 ^ Long (1972, p. 162)
 ^ Pettofrezzo & Byrkit (1970, p. 80)
 ^ L. Euler "Theoremata arithmetica nova methodo demonstrata" (An arithmetic theorem proved by a new method), Novi commentarii academiae scientiarum imperialis Petropolitanae (New Memoirs of the SaintPetersburg Imperial Academy of Sciences), 8 (1763), 74104. (The work was presented at the SaintPetersburg Academy on October 15, 1759. A work with the same title was presented at the Berlin Academy on June 8, 1758). Available online in: Ferdinand Rudio, ed., Leonhardi Euleri Commentationes Arithmeticae, volume 1, in: Leonhardi Euleri Opera Omnia, series 1, volume 2 (Leipzig, Germany, B. G. Teubner, 1915), pages 531555. On page 531, Euler defines n as the number of integers that are smaller than N and relatively prime to N (… aequalis sit multitudini numerorum ipso N minorum, qui simul ad eum sint primi, …), which is the phi function, φ(N).
 ^ ^{a} ^{b} Sandifer, p. 203
 ^ Graham et al. p. 133 note 111
 ^ L. Euler, Speculationes circa quasdam insignes proprietates numerorum, Acta Academiae Scientarum Imperialis Petropolitinae, vol. 4, (1784), pp. 1830, or Opera Omnia, Series 1, volume 4, pp. 105115. (The work was presented at the SaintPetersburg Academy on October 9, 1775).
 ^ Both <math>\varphi(n)\;</math> and <math>\phi(n)\;</math> are seen in the literature. These are two forms of the lowercase Greek letter phi.
 ^ Gauss, Disquisitiones Arithmeticae article 38
 ^ J. J. Sylvester (1879) "On certain ternary cubicform equations", American Journal of Mathematics, 2 : 357393; Sylvester coins the term "totient" on page 361.
 ^ "totient". Oxford English Dictionary (2nd ed.). Oxford University Press. 1989.
 ^ Gauss, DA, art 39
 ^ Gauss, DA art. 39, arts. 5254
 ^ Graham et al. pp. 134135
 ^ The cell for n = 0 in the upperleft corner of the table is empty, as the function φ(n) is commonly defined only for positive integers, so it is not defined for n = 0.
 ^ ^{a} ^{b} Hardy & Wright 1979, thm. 328
 ^ Dineva (in external refs), prop. 1
 ^ ^{a} ^{b} ^{c} Walfisz, Arnold (1963). Weylsche Exponentialsummen in der neueren Zahlentheorie. Mathematische Forschungsberichte (in German) 16. Berlin: VEB Deutscher Verlag der Wissenschaften. Zbl 0146.06003.
 ^ Lomadse, G., "The scientific work of Arnold Walfisz" (PDF), Acta Arithmetica 10 (3): 227–237
 ^ R. Sitaramachandrarao. On an error term of Landau II, Rocky Mountain J. Math. 15 (1985), 579588
 ^ Also R. Sitaramachandrarao (loc. cit.)
 ^ Bordellès in the external links
 ^ All formulae in the section are from Schneider (in the external links)
 ^ Hardy & Wright 1979, thm. 288
 ^ Hardy & Wright 1979, thm. 309
 ^ Hardy & Wright 1979, intro to § 18.4
 ^ Hardy & Wright 1979, thm. 326
 ^ Hardy & Wright 1979, thm. 327
 ^ In fact Chebychev's theorem (Hardy & Wright 1979, thm.7) and Mertens' third theorem is all that's needed
 ^ Hardy & Wright 1979, thm. 436
 ^ Bach & Shallit, thm. 8.8.7
 ^ ^{a} ^{b} Ribenboim, The Book of Prime Number Records, Section 4.I.C
 ^ Sándor, Mitrinović & Crstici (2006) pp.2425
 ^ Hardy & Wright 1979, thm. 332
 ^ ^{a} ^{b} ^{c} Ribenboim, p.38
 ^ ^{a} ^{b} Sándor, Mitrinović & Crstici (2006) p.16
 ^ ^{a} ^{b} Guy (2004) p.144
 ^ Sándor & Crstici (2004) p.230
 ^ Zhang, Mingzhi (1993). "On nontotients". Journal of Number Theory 43 (2): 168–172. ISSN 0022314X. Zbl 0772.11001. doi:10.1006/jnth.1993.1014.
 ^ ^{a} ^{b} ^{c} Ford, Kevin (1998). "The distribution of totients". Ramanujan J. 2 (12): 67–151. ISSN 13824090. Zbl 0914.11053. doi:10.1007/9781475745078_8.
 ^ Sándor et al (2006) p.22
 ^ Sándor et al (2006) p.21
 ^ ^{a} ^{b} Guy (2004) p.145
 ^ Sándor & Crstici (2004) p.229
 ^ Sándor & Crstici (2004) p.228
 ^ Gauss, DA. The 7th § is arts. 336366
 ^ Gauss proved if n satisfies certain conditions then the ngon can be constructed. In 1837 Pierre Wantzel proved the converse, if the ngon is constructible, then n must satisfy Gauss's conditions
 ^ Gauss, DA, art 366
 ^ Gauss, DA, art. 366. This list is the last sentence in the Disquisitiones
 ^ Ribenboim, pp. 3637.
 ^ Cohen, Graeme L.; Hagis, Peter, jun. (1980). "On the number of prime factors of n if φ(n) divides n−1". Nieuw Arch. Wiskd., III. Ser. 28: 177–185. ISSN 00289825. Zbl 0436.10002.
 ^ Hagis, Peter, jun. (1988). "On the equation M⋅φ(n)=n−1". Nieuw Arch. Wiskd., IV. Ser. 6 (3): 255–261. ISSN 00289825. Zbl 0668.10006.
 ^ Guy (2004) p.142
References
The Disquisitiones Arithmeticae has been translated from Latin into English and German. The German edition includes all of Gauss' papers on number theory: all the proofs of quadratic reciprocity, the determination of the sign of the Gauss sum, the investigations into biquadratic reciprocity, and unpublished notes.
References to the Disquisitiones are of the form Gauss, DA, art. nnn.
 Abramowitz, M.; Stegun, I. A. (1964), Handbook of Mathematical Functions, New York: Dover Publications, ISBN 0486612724. See paragraph 24.3.2.
 Bach, Eric; Shallit, Jeffrey (1996), Algorithmic Number Theory (Vol I: Efficient Algorithms), MIT Press Series in the Foundations of Computing, Cambridge, MA: The MIT Press, ISBN 0262024055, Zbl 0873.11070
 Ford, Kevin (1999), "The number of solutions of φ(x) = m", Annals of Mathematics 150 (1): 283–311, ISSN 0003486X, JSTOR 121103, MR 1715326, Zbl 0978.11053, doi:10.2307/121103.
 Gauss, Carl Friedrich; Clarke, Arthur A. (translator into English) (1986), Disquisitiones Arithemeticae (Second, corrected edition), New York: Springer, ISBN 0387962549
 Gauss, Carl Friedrich; Maser, H. (translator into German) (1965), Untersuchungen uber hohere Arithmetik (Disquisitiones Arithemeticae & other papers on number theory) (Second edition), New York: Chelsea, ISBN 0828401918
 Graham, Ronald; Knuth, Donald; Patashnik, Oren (1994), Concrete Mathematics: a foundation for computer science (2nd ed.), Reading, MA: AddisonWesley, ISBN 0201558025, Zbl 0836.00001
 Guy, Richard K. (2004), Unsolved Problems in Number Theory, Problem Books in Mathematics (3rd ed.), New York, NY: SpringerVerlag, ISBN 0387208607, Zbl 1058.11001
 Hardy, G. H.; Wright, E. M. (1979), An Introduction to the Theory of Numbers (Fifth ed.), Oxford: Oxford University Press, ISBN 9780198531715
 Long, Calvin T. (1972), Elementary Introduction to Number Theory (2nd ed.), Lexington: D. C. Heath and Company, LCCN 77171950
 Pettofrezzo, Anthony J.; Byrkit, Donald R. (1970), Elements of Number Theory, Englewood Cliffs: Prentice Hall, LCCN 7781766
 Ribenboim, Paulo (1996), The New Book of Prime Number Records (3rd ed.), New York: Springer, ISBN 0387944575, Zbl 0856.11001
 Sandifer, Charles (2007), The early mathematics of Leonhard Euler, MAA, ISBN 0883855593
 Sándor, József; Mitrinović, Dragoslav S.; Crstici, Borislav, eds. (2006), Handbook of number theory I, Dordrecht: SpringerVerlag, pp. 9–36, ISBN 1402042159, Zbl 1151.11300
 Sándor, Jozsef; Crstici, Borislav (2004). Handbook of number theory II. Dordrecht: Kluwer Academic. pp. 179–327. ISBN 1402025467. Zbl 1079.11001.
 Schramm, Wolfgang (2008), "The Fourier transform of functions of the greatest common divisor", Electronic Journal of Combinatorial Number Theory A50 (8(1)).
External links
 Hazewinkel, Michiel, ed. (2001), "Totient function", Encyclopedia of Mathematics, Springer, ISBN 9781556080104
 Kirby Urner, Computing totient function in Python and scheme, (2003)
 Euler's Phi Function and the Chinese Remainder Theorem — proof that Φ(n) is multiplicative
 Euler's totient function calculator in JavaScript — up to 20 digits
 Bordellès, Olivier, Numbers prime to q in <math>[1, n</math>]
 Dineva, Rosica, The Euler Totient, the Möbius, and the Divisor Functions
 Miyata, Daisuke & Yamashita, Michinori, Derived logarithmic function of Euler's function
 Plytage, Loomis, Polhill Summing Up The Euler Phi Function
 Schneider, Robert P. A Golden Product Identity for e.
