Let be a primitive root modulo .

is the collection of all quadratic residues.

This is because and every element in is a square due to the even exponent. Since there are only quadratic residues, must be the list of quadratic residues modulo .

.

, otherwise doesn't exist.