Write the cubic in the Weierstrass equation of an elliptic curve as . A suitable invariant differential on an elliptic curve is
It is regular and nonzero wherever . At a point with , nonsingularity gives , and differentiating the equation shows , again regular and nonzero. At the identity , use the parameter : the expansions start , , so . Thus it is a nowhere-vanishing regular differential on the whole smooth projective curve.
Here is a direct proof of translation invariance of a Weierstrass differential. Fix , let vary, and write . On the open set where the chord-and-tangent group law uses an ordinary chord, put . The addition formulas are and . The line-intersection identity is
Differentiate this polynomial in at to obtain . Differentiating along the curve now gives , and hence
This proves translation invariance on a dense open set. Since the translation on an elliptic curve is an automorphism and both sides are regular differentials, it proves invariance everywhere, including the exceptional addition cases. Translation by is the identity.
Translation invariance also gives for the addition map: its differential on a tangent pair is the sum of the two translated tangent vectors. Therefore for every integer .
Let , with the zero endomorphism assigned degree zero. The assumed degree identity, applied to and , gives
Induction gives for positive ; negation is an automorphism, so the result holds for negative as well. This is quadratic degree recursion for elliptic multiplication.
For a prime , the invariant differential on an elliptic curve has nonzero pullback under , so that map is a separable isogeny. Translation identifies all its fibres and their local multiplicities, so its geometric kernel has exactly its degree distinct points. It is killed by , and therefore
The algebraic closure is essential here; the assertion is not generally true for the rational-point subgroup over itself. This is prime-to-characteristic geometric torsion.
For , the pullback differential vanishes. Its total degree is , and its inseparable degree is at least , so its kernel has at most geometric points. Thus has dimension at most one over , while every other prime-torsion subgroup has dimension at most two. The rational-point group is finite and abelian. The structure theorem for finite abelian groups says that the number of cyclic factors of an -primary component equals the dimension of its subgroup killed by . Each component therefore has at most two factors. Combining the smaller primary factors into one cyclic group and the larger ones into another yields
One may also choose , since the -primary component is cyclic. This explains two generators for elliptic curves over finite fields.
Put , and , all in characteristic three. Since , the numerator and denominator have no common factor, and has degree three. The map has degree two. Comparing the degrees in gives , so . This is the degree of an isogeny from its x-coordinate map.
In characteristic three, direct differentiation gives
The supplied -coordinate is , so the invariant differential on an elliptic curve satisfies
In particular is separable. Its dual isogeny satisfies . Since and , the scalar by which pulls back the differential is zero.
Pullback on the elliptic invariant differential is additive for sums of homomorphisms, by the addition identity proved in (a). Consequently
The differential criterion for separability of an isogeny therefore gives separability exactly when , with arbitrary. Such a map is automatically nonzero. When , every nonzero resulting map is inseparable; the zero map is not a separable isogeny. In fact the zero map occurs only at : equality of the degrees of and in a nontrivial vanishing relation would force , and then cancellation would force , contradicting their different differential scalars.
In this setting a formal group law means a one-dimensional commutative series with identity zero and
It starts with ; there is a unique inverse series satisfying . For coefficients in , the series and its inverse converge on , making this ideal a topological abelian group under .
Set , and write . The formal logarithm is
Differentiate associativity in the third variable at zero. It gives , so . Subtracting leaves a series independent of , whose value at zero is . Thus .
For odd , the logarithm converges on : the valuation of its degree- term is at least , which tends to infinity. Put . For , factor to obtain
for every and odd . Hence is a contraction with constant at most and maps into . The equation is equivalent to ; the contraction mapping theorem gives a unique solution in for every . The same estimate shows , so the logarithm is a topological group isomorphism. Dividing its values by gives
This is the deep logarithm subgroup of a formal group argument, here with depth one.
For , the degree-two estimate at depth one need not be strict. At depth two, however,
so the same proof gives . This subgroup has index two in , because when .
Indeed the topological structure of a formal group on twice the 2-adic integers has just two possibilities. Let , let its index-two subgroup have topological generator , and choose . Write , with , using group notation. If is odd, generates and generates , giving . If is even, has order two and lies outside , giving . The multiples are defined by continuity in this compact pro-two group.
For explicit contrasting examples, the formal additive group gives , which is a torsion-free group. The formal multiplicative group is identified by with . Its element corresponds to and has order two. Moreover
and the logarithm identifies the second factor with . The two resulting groups are and , so they are not isomorphic.
An elliptic curve has good reduction of an elliptic curve at if it admits a Weierstrass equation of an elliptic curve over whose reduced projective cubic is nonsingular. Equivalently its minimal discriminant is a -adic unit.
For the given integral short equation,
It therefore directly supplies good reduction outside . These three primes cannot be rescued by changing the model. An admissible change of Weierstrass model changes the discriminant by a twelfth power, so its valuation changes by a multiple of twelve. The displayed valuations are not congruent to zero modulo twelve. No integral model can have unit discriminant at any of those primes. The good primes are exactly .
At the tangent slope is zero. The elliptic-curve addition formula gives
The chord from to has slope , so its sum has -coordinate and -coordinate . Thus .
Reduction at the good prime seven gives . For , the right sides are respectively . There are respectively choices of . Including the point at infinity gives . Its nonzero torsion points of an elliptic curve of order two are , so it cannot be cyclic. Its two-primary component is and its three-primary component is cyclic of order three; hence
In particular its exponent is six.
The reduction of an elliptic curve is a group homomorphism defined on every -point by projectivity. Thus reduces to the identity for every rational . A finite point with integral coordinates reduces to an affine point, whose projective last coordinate is one, so it cannot reduce to the identity at infinity. Therefore every nonzero finite point has nonintegral coordinates. If , it has no affine coordinates at all. This is the reduction exponent obstruction to integral multiples.
The Lutz–Nagell theorem says that for a nonsingular short equation with , every nonidentity rational torsion point of an elliptic curve has , and either or
This is a necessary condition for torsion, not a converse.
To prove integrality, fix a prime . If , the term dominates the right side of the equation. Hence , so , for some . The parameter has valuation and identifies the point with the formal neighbourhood of the identity, namely the formal group of an elliptic curve evaluated on .
For odd , this group is a torsion-free group by the logarithm argument of Question 2. For , use the special short-model structure. Negation sends exactly to , so the formal multiplication series is odd and has integral coefficients:
If , the first term has valuation and all the others have valuation at least . Thus , and no iteration of doubling kills a nonzero point. Multiplication by an odd integer has unit linear coefficient and also cannot kill it. This proves the torsion-free formal subgroup for a short Weierstrass equation, including at two. Consequently a rational torsion point of an elliptic curve cannot have at any prime. Its is integral, and the equation then makes its rational integral too.
For the divisibility conclusion suppose . Then and is also a rational torsion point of an elliptic curve, so is integral. Its tangent slope satisfies . Thus ; a rational number with integral square is itself integral. In particular . Reduce the supplied polynomial identity modulo : both terms on the left are divisible by , so the right side is too. This is the divisibility proof in the Nagell–Lutz theorem.
For the specific curve, . The computed equality makes a point of exact order three. The coordinate has square not dividing , so has infinite order. To decide , use the already computed point . Its -coordinate has even square, which cannot divide the odd number , so that sum has infinite order. Since is torsion, must have infinite order as well. has order three; and both have infinite order.
Kummer theory studies extracting roots through Galois actions, and on an elliptic curve the corresponding operation is division of points. The bridge is a cocycle: different Galois conjugates of a chosen division point differ by torsion. Controlling the ramification of these cocycles is what proves the Weak Mordell-Weil theorem.
Classically, for a characteristic-zero field , the sequence
is exact. Hilbert's theorem 90 gives , so Galois cohomology identifies
The class of is represented by . If , the module is constant and these are continuous characters into ; the associated fields are cyclic Kummer extensions of degree dividing . Several such classes give abelian extensions of exponent dividing . Without the roots-of-unity hypothesis the cohomological description still holds, but the action on must not be discarded.
For an elliptic curve over a number field , multiplication by gives the exact sequence of Galois modules
The map is onto because it is a nonconstant isogeny over an algebraically closed field. For choose with , and set
It satisfies , the Galois 1-cocycle identity. Changing by a torsion point of an elliptic curve changes the cocycle by a coboundary. If the class is zero, a corresponding change of makes it Galois-fixed, so . Conversely a rational division point gives the zero class. Thus the Kummer map of an elliptic curve is injective on the quotient, and the cohomology sequence gives
This is the Kummer exact sequence of an elliptic curve. The last group parametrizes the appropriate torsor classes. It is important that the entire middle group need not be finite; an unrestricted Kummer class can ramify at arbitrarily many primes.
The Weak Mordell-Weil theorem states is finite for every number field and every . The case is trivial. To prove the remaining cases, choose a finite set containing the primes of bad reduction and the primes dividing . At a prime outside , the elliptic curve extends to a smooth proper group scheme over the valuation ring, and is finite étale. Properness extends a local rational point to a section; its division fibre is a finite étale torsor over that ring. Therefore its Kummer class is unramified. This is unramified division torsors at good primes, and shows that lies in first Galois cohomology unramified outside a finite set.
Let , enlarged if necessary to contain , and include in the finitely many primes ramified in . This is a finite Galois extension. Over the torsion module is constant, isomorphic to , and so to two copies of . Restricting a cocycle to therefore reduces it to two classical Kummer classes unramified outside the primes above . Such a class is represented by satisfying
Write this power-class group as . The implication follows locally because, away from residue characteristic dividing , the valuation of an unramified th-root extension must be divisible by .
Its finiteness comes from two standard arithmetic finiteness results, rather than from an assertion that all of is finite. The valuations outside associate to an ideal whose th power is principal. There is an exact sequence
The left group is finite by the finite generation of the S-unit group, and the right group is finite by finiteness of the ideal class group. This proves finiteness of S-unramified Kummer classes. Hence there are only finitely many restricted cocycles over . The kernel of restriction from is contained in , which is finite because both group and module are finite. The restricted cohomology group over is therefore finite, and its injected subgroup is finite too. This completes a Kummer-theoretic proof of the weak Mordell-Weil theorem.
For arithmetic computation one adds local conditions. The Selmer group of an elliptic curve consists of classes in whose restriction at every completion lies in the image of the corresponding local Kummer map. They are unramified outside the same finite set, so this group is finite. The failure of a everywhere locally soluble torsor to have a global point is measured by the Tate–Shafarevich group, defined as the kernel of the local restriction map on . The resulting exact sequence is
Thus the Selmer group of an elliptic curve gives a computable upper bound for the quotient; actual rational points supply lower bounds. Equality need not follow just from local solubility. Finiteness of this fixed torsion subgroup does not prove finiteness of the whole Tate–Shafarevich group.
Finally, weak finiteness alone is not finite generation: the additive group has trivial quotients by multiplication and is not finitely generated. The additional ingredient for the Mordell-Weil theorem is height descent. Choose representatives of and write . The quadratic growth of the canonical height of an elliptic curve, together with bounds for translation by the finitely many , makes have smaller height whenever is sufficiently large. Northcott theorem gives only finitely many points of bounded height, and repeated descent yields a finite generating set. This explains the roles of Kummer theory, local information and heights without conflating the weak and full theorems.
Translate the rational point of order two to and clear denominators to obtain an integral equation
The two-isogeny formula gives
with and its dual . One choice of signs is
These extend across their displayed poles as isogenies; their composition is and their kernels are the respective rational points of order two.
The two-isogeny descent maps into square classes are
and the analogous map on uses at its point . They are homomorphisms, with kernels and . For instance the product of the three intersection -coordinates of a chord is the square of its intercept, proving the square-class addition rule; the values at exceptional points come from the same rule or from the divisor . This also identifies the maps as the Kummer maps for the two isogenies.
The square-class index formula for two-isogeny descent is
where is the rank. To see the torsion correction explicitly, put on . Factoring multiplication by two gives
The last denominator is : is in exactly when the two additional torsion points of an elliptic curve of order two on are rational. Since , cancellation gives the formula in both the single and full rational two-torsion cases.
For computing the images, unit square-class bound for two-isogeny descent restricts to signed squarefree divisors of , and to those of . To justify the prime support, negative valuations of a rational -coordinate are even; at a prime not dividing , a positive valuation of makes a unit, so the equation again forces the valuation to be even. A candidate occurs precisely when the quartic covering in a two-isogeny descent
has a rational point, with the limiting points at or included. Clearing denominators gives integers with . For , the associated point is , . Test these finitely many coverings over and over relevant to eliminate impossible classes; surviving locally soluble classes give an upper bound. Finding rational points on them proves membership and often makes the bound exact. Local solubility alone need not prove global solubility, so one must retain the possible Selmer obstruction.
For the illustration take
with . On all possible square classes are . They all occur: supplies and the three points with , at , supply . Hence .
On , a nonzero real point has , because . Thus only need be considered, and occurs already at . The other three classes are excluded as follows.
For , the covering is . Reducing modulo forces and . If were divisible by , then would be too, contradicting primitivity. Otherwise , impossible since . For , the equation is , which similarly forces . Thus neither class occurs. These are odd-prime obstructions for the congruent-number isogeny coverings.
For , the equation is . If exactly one of is odd, its right side is , not a square. If both are odd, their fourth powers are and ; hence the right side is , also not a square. Both even is forbidden by primitivity. This is the modulo-thirty-two obstruction for a congruent-number descent class. Consequently , and the rank formula gives
To complete the congruent-number conclusion, also determine torsion. At a good prime , the character sum for cancels in pairs , so . Rational torsion injects into good reduction at every odd prime, by the formal kernel, which is a torsion-free group. If , use to bound its order by . If , use , giving . The three rational points of order two already give four points, so . This is rational torsion of a congruent number curve in the present cases.
A congruent number is the positive area of a right triangle with rational side lengths. A point on with would give such a triangle with sides
for which and . Conversely a rational right triangle of area gives a point with nonzero , for example , . But every rational point on the curve just determined is or has . Every prime is therefore not a congruent number.

Articles by others on the same topic (0)

There are currently no matching articles.