If , square-freeness gives the cuspidal reduction . Its nonsingular group is isomorphic to the additive group , so it is cyclic of order .
Suppose . The reduction is an elliptic curve. Since , is a quadratic nonresidue. Pairing with in the quadratic-character sum and using
shows that the two contributions cancel. Therefore . The three roots are distinct, so the full 2-torsion is rational. A cyclic group has at most two elements killed by , hence is noncyclic. Thus
A positive integer is a congruent number when it is the area of a right triangle with positive rational side lengths. For a point with on
the formulas
give and , after changing signs if necessary. Conversely, a rational right triangle of area gives
so these constructions are inverse up to the usual sign choices.
It remains to distinguish torsion. If an odd prime divided the order of a rational torsion point, choose by the Dirichlet theorem on primes in arithmetic progressions a good prime for which . Part (a) gives , while part (b), applied to the formal group of an elliptic curve, makes reduction injective on -power torsion because is a unit in . This is impossible. Similarly, a good prime shows that the rational -primary torsion has order at most four. Since
already form the full rational 2-torsion,
The triangle construction uses exactly the points with , which are therefore nontorsion. By the Mordell-Weil theorem, such a point exists exactly when the free part has positive rank. Hence
Use the two-descent on an elliptic curve map associated with the three rational roots ,
with the standard limiting values at the 2-torsion. Only the square classes of , and can occur, because all other numerator and denominator valuations in the three factors are even. Checking solubility over , and leaves exactly
These four classes are represented respectively by , , and . Thus . Since part (b) gives
the quotient by doubling has order . Therefore
When an elliptic curve has full rational 2-torsion, its Kummer map embeds into a product of square-class groups. Valuation and local-solubility conditions reduce the image to finitely many classes and thereby bound the rank of the Mordell-Weil group.