Arithmetic and number theory
Elliptic curves
Smooth cubic curves whose points form an abelian group under a geometric chord-and-tangent law, linking classical Diophantine geometry to modular forms, elliptic-curve cryptography, and the unsolved Birch and Swinnerton-Dyer conjecture.
IntuitionA curve that turns points into a group
Take a smooth cubic curve — a shape that looks like a lazy S-curve, or (depending on ) a single wavy branch plus a separate oval loop. Pick any two points and on the curve. A remarkable fact of algebra guarantees that the straight line through and always meets the curve at exactly one more point (counting multiplicity), because substituting the line's equation into the cubic leaves a degree- polynomial, and two of its three roots are already pinned down by and . Call that third point . Now reflect across the -axis: the mirror image is defined to be the sum . This purely geometric recipe — draw a chord, find the third point, flip it over — turns the points on the curve into a commutative group, with the point at infinity (where every vertical line meets the curve) playing the role of the identity element .
Example: Adding two rational points by hand
On the curve , check that and are both rational points, then use the chord construction to compute .
Solution
First, and , so both points lie on (this is the congruent number curve, linked to the -- right triangle of area ). The chord through and has slope . The third intersection point has -coordinate and -coordinate . So the line meets again at — and since this point already sits on the -axis, its own reflection is itself, giving . As a sanity check, , confirming .
UndergraduateWeierstrass form, the discriminant, and nonsingularity
Definition: Elliptic curve (short Weierstrass form)
Over a field of characteristic (such as , , or a finite field with ), every smooth plane cubic curve with a rational point can be put in short Weierstrass form for some constants in the field. An elliptic curve is such a curve together with the extra point at infinity , required to be nonsingular: no point of the curve may have both partial derivatives of vanish simultaneously (a singular point would be a self-crossing node or a sharp cusp, where the chord-and-tangent recipe breaks down).
The curve is nonsingular if and only if the discriminant is nonzero, which happens if and only if the cubic has three distinct roots (over an algebraic closure).
Why is it true?
A point where the cubic has a repeated root is exactly where the curve pinches into a cusp or crosses itself, because the tangent direction becomes undefined there — precisely the geometric flaw that would break the chord-and-tangent group law.
Proof
The point is singular iff , , and all hold. The second equation forces , so must be a root of ; the third equation forces , i.e. is also a root of the derivative . A polynomial and its derivative share a common root exactly at a repeated root of the polynomial, so is singular iff has a repeated root. The classical discriminant of the depressed cubic is , which vanishes exactly when the cubic has a repeated root; multiplying by the normalization constant gives , so is nonsingular iff .
The geometric chord-and-tangent recipe translates into explicit algebra. For distinct points , with , the chord has slope ; for doubling a point with , the tangent line at has slope (found by implicit differentiation of ). In both cases, the sum's coordinates are given by the same two formulas below. If and are added, the vertical line through them meets only at , so , matching the identity axiom of a group.
Since has characteristic for , the same addition and doubling formulas apply verbatim when is reduced modulo a prime , giving the reduced curve the structure of a finite abelian group. This is the setting used throughout elliptic-curve cryptography, and it raises an obvious question: how large is ?
For an elliptic curve over a finite field ( prime), the number of points satisfies .
Why is it true?
The quantity measures the 'error term' of the naive guess that a random cubic should have about solutions plus the point at infinity; Hasse's bound says this error can never be more than about , an astonishingly small deviation compared to the trivial bound of size , and it is what makes usable as a reliable, predictable group order in cryptographic constructions.
Proof
Consider the Frobenius endomorphism , . Its fixed points are exactly , and one shows where is the trace of Frobenius acting on the endomorphism ring. The degree map on endomorphisms of is a positive-definite integer-valued quadratic form (it satisfies for all integers , with equality only when ), and . Expanding as a quadratic form in forces its discriminant to be non-positive: , i.e. . Since , this is exactly the claimed bound.
Example: Counting points on a curve over a small finite field
Let over . Compute by direct enumeration and check it satisfies Hasse's bound.
Solution
For each , compute and check whether it is a square mod (the squares mod are , since ): (square, , points); (not a square, points); (square, , points); (square, , points); (square, , points). This gives affine points, plus the point at infinity, so . Checking Hasse's bound: , and , so holds.
AdvancedRank, torsion, and the shape of
Over the group is infinite whenever it contains a point of infinite order, and Henri Poincaré's 1901 paper first asked how many rational points are needed to generate all the others by chords and tangents. Louis Mordell answered this in 1922 using a refinement of Fermat's method of infinite descent, and André Weil generalized the result in his 1929 thesis to abelian varieties over arbitrary number fields.
For an elliptic curve over , the group of rational points is finitely generated: for some integer called the rank, where is a finite abelian group.
Why is it true?
This theorem is the arithmetic payoff of the group law: it says that however intricate the set of rational points looks, it is always controlled by finitely many 'seed' points — a finite generating set — from which every other rational point is reached by repeated chord-and-tangent addition.
Proof
The proof combines two ingredients. Weak Mordell–Weil: one shows is a finite group, by embedding it (via Galois cohomology, using the -descent map for the roots of the cubic) into a group built from the class group and unit group of a related number field, both of which are known to be finite. Height descent: one attaches to each point a canonical height , a real-valued measure of arithmetic complexity satisfying and for which only finitely many points have height below any given bound. Combining a finite set of coset representatives for with the fact that repeatedly halving the height of any point (via the parallelogram law for heights) eventually lands in a bounded-height region shows every point is a -combination of the finitely many representatives and finitely many bounded-height points — hence is finitely generated.
For an elliptic curve over , the torsion subgroup is isomorphic to exactly one of the following groups: the cyclic group for or , or the group for ; no other finite abelian group occurs.
Why is it true?
This is a striking rigidity statement: among infinitely many abstractly possible finite abelian groups, only these ever occur as the torsion of a rational elliptic curve — a torsion subgroup of order, say, or is simply impossible.
Proof
Mazur's 1977 proof translates the existence of a rational point of exact order on into the existence of a non-cuspidal rational point on the modular curve , which classifies pairs with of order . The strategy studies the Jacobian of the related modular curve and the Eisenstein ideal — the ideal in the Hecke algebra generated by for primes — acting on it. By analyzing the Eisenstein quotient of and its reduction modulo auxiliary primes, Mazur shows that for outside the allowed list, consists only of cusps, so no elliptic curve over can have a rational point of that exact order; explicit constructions (for instance using the curves and ) exhibit examples realizing each of the permitted groups.
Definition: The -invariant
For , the **-invariant** is . Two elliptic curves over an algebraically closed field are isomorphic if and only if they have the same -invariant, so is the complete classifying invariant of the curve's shape, independent of which Weierstrass equation is used to present it (curves sharing a -invariant over but not isomorphic over are called twists of one another).
Because arithmetic in is fast to compute forward but (for well-chosen curves) extremely slow to invert, elliptic curves underpin much of today's public-key cryptography. Fix a public base point ; computing (adding to itself times, done efficiently by repeated doubling) is easy, but recovering the secret integer from and alone — the Elliptic Curve Discrete Logarithm Problem (ECDLP) — is believed to require roughly operations for the best known classical algorithms, with no faster method known. This lets protocols like ECDSA and ECDH use much shorter keys than RSA for the same security level.
Example: A toy discrete logarithm computation
On over , verify that lies on , then compute using the doubling formula, illustrating (at a toy scale) the arithmetic behind the Elliptic Curve Discrete Logarithm Problem.
Solution
First, , and , so . To double , the tangent slope is ; since , the inverse of mod is , so . Then , and , so . Checking: , and ✓. On this toy curve with only possible -values, an attacker could search every multiple of by hand; real ECC uses primes with roughly bits, making the analogous search ( steps) utterly infeasible.
AdvancedThe bridge to modular forms and Fermat's Last Theorem
Elliptic curves live in a second world too: that of modular forms, highly symmetric holomorphic functions on the upper half-plane. Attaching to its Hasse–Weil -function (built from the same that appears in Hasse's bound), the Modularity Theorem (Taniyama–Shimura–Weil conjecture) asserts that always agrees with the -function of a weight- modular form. Equivalently, is covered by a modular curve via a non-constant map defined over , where is the conductor of . This links the purely arithmetic data for every prime to the Fourier coefficients of a single, highly structured function — an extraordinary bridge between two areas of mathematics that look unrelated at first sight. The associated Galois representation on the -adic Tate module of (a construction built from the group-theoretic ideas pioneered by Évariste Galois) is exactly the object whose 'modularity' is being asserted.
Every elliptic curve over is modular: there is a nonconstant morphism defined over , where is the conductor of ; equivalently, equals the -function of a weight- newform on .
Why is it true?
Modularity turns every elliptic curve into a modular form in disguise, transferring the powerful analytic machinery available for modular forms (analytic continuation, functional equations) to elliptic curves, and — crucially for Fermat's Last Theorem — it means a curve that cannot be modular cannot exist.
Proof
Wiles proved modularity for semistable elliptic curves over in 1994–95 (with the final step, a numerical criterion for isomorphism between deformation rings and Hecke algebras — the ' theorem' — established jointly with Richard Taylor). The strategy shows that the Galois representation on the -adic Tate module of , and the corresponding representation attached to a candidate modular form, live in the same deformation space; proving the deformation ring and the Hecke algebra acting on modular forms coincide forces every allowed Galois representation — in particular 's — to come from a modular form. Since every semistable curve suffices to rule out a counterexample to Fermat's equation (any solution would yield a semistable Frey curve that Kenneth Ribet had shown, via his 1990 proof of -conjecture, cannot be modular), this proved Fermat's Last Theorem. The semistability restriction was later removed entirely, extending modularity to all elliptic curves over , by Christophe Breuil, Brian Conrad, Fred Diamond, and Richard Taylor in 2001.
ResearchOpen problems: the Birch and Swinnerton-Dyer conjecture and post-quantum cryptography
Which of these Weierstrass equations is singular (i.e. does NOT define an elliptic curve)?
Which statement must hold for every elliptic curve over the finite field ?
By Mazur's torsion classification, which of the following can NOT be the torsion subgroup of an elliptic curve over ?
The Modularity Theorem, proved for semistable elliptic curves by Wiles (with Taylor) in 1994–95, was the key ingredient in the proof of which classical problem?
References
- Joseph H. Silverman (2009). The Arithmetic of Elliptic Curves · DOI:10.1007/978-0-387-09494-6
- Andrew Wiles (1995). Modular elliptic curves and Fermat's Last Theorem · DOI:10.2307/2118559
- Andrew Wiles / Clay Mathematics Institute (2000). The Birch and Swinnerton-Dyer Conjecture (official Millennium Problem description)
- Wouter Castryck, Thomas Decru (2022). An efficient key recovery attack on SIDH