KEVOS
ArticlesServicesCase studiesAboutContact
ArticlesServicesCase studiesAboutContact
← ArticlesFermat and Strong Pseudoprime TestsEngineering · Engineering MathematicsLesson 849/884← PrevNext →
ArticlePublished 7 Aug 20262 min readBy Kevin JoginFermat teststrong pseudoprimeMiller RabinCarmichael number
On this page

Ask about this page

KEVOS AIFermat and Strong Pseudoprime Tests

KEVOS knowledge first · trusted web sources when needed

Classical Primality and Factoring

Fermat and Strong Pseudoprime Tests

The Fermat test, its failure on Carmichael numbers, and the strong pseudoprime test that repairs it.

Engineering / MathematicsClassical Primality and Factoring2 min readKV-MATH-0647

The Fermat test is the starting point for all compositeness testing. It has a fatal flaw which the strong test repairs, and the repair costs essentially nothing.

The Fermat test

a^(n-1) = 1 (mod n) for every a coprime to n, if n is primeFailure proves compositeness; success proves nothing.

Pitfall

Carmichael numbers pass the Fermat test for every base coprime to them. They are composite and no choice of base exposes them, so the Fermat test is not merely weak but genuinely unsound as a primality indicator. There are infinitely many.

The strong test

Write the exponent as an odd number times a power of two. For a prime, the sequence of repeated squarings from the odd power must reach one through a specific pattern.

n - 1 = d * 2^s with d oddThen either a^d = 1, or a^(d*2^r) = -1 for some r below s.

The strong pseudoprime test

  1. Factor out powers of twoFrom one less than the candidate.
  2. Compute the odd powerBy binary powering.
  3. Check for oneIf the result is one, the test passes.
  4. Square repeatedlyChecking for minus one at each step.
  5. Declare compositeIf neither condition is met.

Why it is stronger

Key point

The strong test additionally exploits the fact that a prime modulus has only two square roots of one. Finding a different square root of one during the squaring chain proves compositeness, and this is what Carmichael numbers cannot evade.

Error probability

Probability a composite passes a random base < 1/4And in practice far smaller for most composites.
Error probability with independent random bases
Number of random basesError bound
1Below one quarter
10Below one in a million
20Below one in a trillion
40Negligible for any practical purpose

Note

The one quarter bound is worst case and is essentially never attained. For a random composite the probability of passing even one base is astronomically smaller, which is why so few bases are needed in practice.

Deterministic variants

Caution

Fixed small base sets give deterministic tests below explicit bounds, and these are widely tabulated. But an adversary who knows the base set can construct a composite passing it. For adversarial input, random bases are essential.

Finding a factor

Key point

When the test finds a non-trivial square root of one, the GCD of that root plus or minus one with the modulus is a factor. This is rare but free, and it is the mechanism underlying Pollard's p-1 method.

Source. Henri Cohen, A Course in Computational Algebraic Number Theory, Springer GTM 138 — 8.2. Structural reference unverified: the source file was not available during authoring; chapter and section numbers are taken from the published edition and have not been checked against a physical copy.

Related pages

  • Binary Powering and Exponentiation Chains
  • The Baillie-PSW Compositeness Test
  • Primality Versus Factoring: Framing the Problems
  • Lucas Sequences and Lucas Pseudoprimes

Continue learning

Primality Versus Factoring: Framing the ProblemsArticle · Engineering MathematicsNEXT LESSON →Lucas Sequences and Lucas PseudoprimesArticle · Engineering MathematicsSchoof's Point Counting AlgorithmArticle · Engineering MathematicsThe Baillie-PSW Compositeness TestArticle · Engineering Mathematics
KEVOS · Engineering, manufacturing and project improvement
ArticlesServicesCase studiesAboutContact
© 2026 KEVOS®