The Hasse theorem for elliptic curves states thatLet be the Frobenius isogeny of an elliptic curve and put . The degree on is a positive-definite quadratic form, its associated bilinear form gives , and . Consequentlyfor all integers . If , this real quadratic form is indefinite, so by density of rational slopes it is negative at some nonzero integer pair , contradicting nonnegativity of the degree. Hence , which is the claimed bound.
The zeta function of an elliptic curve over a finite field is the formal power seriesThe proof of Hasse's theorem gives the characteristic equation . If are the roots of , then the elliptic-curve point count over a finite field isUsing therefore gives
Equality of the two point groups implies equality of their orders. Since ,soIts two integral solutions are and . The Hasse theorem for elliptic curves excludes the first for every prime and permits the second only when . Thus or .
Both occur. Over , the smooth curve has five rational points and trace . Over , the smooth curve has seven rational points and trace . In either case the point-count formula gives . Since , equal orders give equality of groups.
A one-dimensional commutative formal group law over a ring is a series satisfyingAn isomorphism from to is a series with and
Over a characteristic-zero field , every such formal group is isomorphic to the additive formal group. Differentiate the associativity identity and define the invariant differentialTermwise integration is possible in characteristic zero; the formal logarithmhas leading term . Invariance of givesand evaluation at removes the integration constant. Hence . Its unit linear coefficient gives a compositional inverse, so it is an isomorphism to . Therefore any two one-dimensional commutative formal groups over are isomorphic.
For , the duplication formula isAt , the tangent slope is , so and . If , the unique lowest-valuation terms in the numerator and denominator are respectively and , givingInduction yields .
For a minimal integral equation, let be the parameter of the formal group of an elliptic curve. Definewhere is the kernel of reduction to the identity. The parameter identifies with the formal group on . For odd , the formal logarithm converges on and is an analytic group isomorphism
For , the logarithm gives . The formal duplication series satisfies , so ; successive lifting makes surjective. Its kernel is rational 2-torsion, but has no root in because it has no root modulo . Thus is an isomorphism and
Apply the Riemann-Roch theorem to the divisors . Since the genus is one and the canonical divisor is trivial, for . ChooseThen and have exact pole orders two and three at . The seven functionslie in the six-dimensional space , so they satisfy one relation. Comparing pole orders and completing squares and cubes gives a nonsingular Weierstrass equation of an elliptic curveThe functions define the morphism away from . Their pole orders show that it extends with . It has degree one and is therefore an isomorphism of smooth projective curves.
The Hessian determinant of is a nonzero scalar multiple of . Hence the inflection points areThere are nine of them. Since is an inflection point, these are exactly . They are all defined overso .
The Weil pairing is nondegenerate and Galois equivariant. If all of is rational over a field, pairing a basis produces a primitive cube root of unity in that field. Thus a quadratic field with full 3-torsion must contain and must equal it.
More generally, if , Frobenius acts as the identity on . Its characteristic polynomial is therefore congruent to modulo . Comparing coefficients givesIn particular with .
Writing , , and turns the cubic into . The birational coordinatesgive the Weierstrass equationThe original projective cubic has no common zero of its three partial derivatives modulo any , so it is already a smooth proper model and has good reduction at every such prime.
If , then , all nine inflection points are rational, and contains , so it is not cyclic. If , cubing is a bijection on . Counting on the Fermat model gives . A finite elliptic-curve group has the form with and , so . For odd , the equation has exactly one root because cubing is bijective, so there is only one nonzero rational 2-torsion point and . Hence the group is cyclic. For it has order three and is cyclic as well.
For , choose with and define the Kummer pairingChanging by an th power or changing its root leaves the quotient unchanged because . Multiplication of radicals proves bilinearity. If an automorphism pairs trivially with every class, it fixes all generating radicals and hence all of . If a class pairs trivially with every automorphism, its radical lies in , so the class is trivial. Thus the pairing is well-defined, bilinear, and nondegenerate on both sides.
For , choose with and define the elliptic Kummer pairingReplacing by with changes nothing because all -torsion is -rational; replacing by permits replacing by , again without changing the value. The group laws prove bilinearity. An automorphism pairing trivially with every class fixes every division point and hence . Conversely, if pairs trivially with every automorphism, a chosen is Galois fixed, so and . The pairing is therefore nondegenerate.
Define the S-unramified power class group byThere is an exact sequence from the -unit group modulo th powers into and then into the -torsion of the ideal class group. By the Dirichlet unit theorem,after absorbing the fixed roots of unity into the exponent. The ideal class group has fixed finite order . Since , choose a constant depending only on with and the unit contribution bounded by . Then
Take to contain every finite prime dividing and every prime of bad reduction of . The local theory of reduction of an elliptic curve shows that Kummer classes of rational points are unramified outside . Choose a basis of the constant group . Kummer theory and the Weil pairing identify the resulting two scalar coordinates ofwith power classes in . The ramification statement places both coordinates in . Restriction to is injective by the nondegeneracy proved in part b, and therefore
For with rational 2-torsion , the quotient by that point is the two-isogenous curveThe two-isogeny descent maps a nonexceptional point to the square class of its -coordinate, with mapping to . The images are finite collections of squarefree divisors of and , determined by testing the associated homogeneous quartics for rational points. If their orders are and , thenwhich determines the Mordell-Weil rank .
The method requires a rational 2-isogeny, and deciding whether every locally soluble quartic is globally soluble can be difficult. Computing only local conditions gives a 2-isogeny Selmer group and hence an upper bound; a nontrivial Tate-Shafarevich group can make that bound strict. Even after finding the rank, a separate saturation and point search may be needed to find generators.
Let , the rational point of order two. Direct use of the chord-and-tangent law givesTranslation by a torsion point sends torsion points to torsion points, proving the claim.
For this curve, the square-class image in the first two-isogeny descent is contained in . All four classes occur: gives , gives , and gives . The isogenous curve isIts image is contained in . Negative cannot occur because for , while and are represented by the identity and . Thus the two image orders are four and two, andgives .
The point has order three because , and has order two, so the rational torsion contains a cyclic subgroup of order six. At the good primes and , direct point counting givesReduction bounds the rational torsion order by their greatest common divisor, namely six, so this is all the torsion. The structure theorem for finitely generated modules over a principal ideal domain now givesThus one may take , , and .
Articles by others on the same topic
There are currently no matching articles.