MathLabs

Arithmetic and number theory

Arithmetic geometry

The study of solutions to polynomial equations using tools from algebraic geometry and number theory together.

IntuitionTwo lenses on the same points

Take a curve given by a polynomial equation, such as y2=x3+ax+by^2 = x^3 + ax + b. A geometer sees a shape: a smooth curve winding through the plane, with a well-defined tangent line at every point. A number theorist asks a much narrower question: which points on that shape have coordinates that are whole numbers or fractions — E(Q)E(\mathbb{Q}), the rational points? Arithmetic geometry is the discipline that refuses to separate the two questions. It uses the geometric shape (its genus, its symmetries, the way curves sit inside higher-dimensional spaces) to control the arithmetic: how many rational points there are, and how they are organized.

Interactive plot of the cubic curve y equals x minus 1 cubed.
The cubic y=(x−1)3=x3−3x2+3x−1y=(x-1)^3=x^3-3x^2+3x-1: a single algebraic identity turns into a curve you can rotate, zoom and trace point by point.

SchoolFrom integer puzzles to shapes of curves

Long before the word geometry entered the picture, school mathematics already asks arithmetic-geometry questions in disguise: which right triangles have whole-number sides (Pythagorean triples), or which integers are the area of a right triangle with rational sides (the congruent number problem). Both questions turn out to be about counting rational points on a specific cubic curve. The leap that arithmetic geometry makes is to treat every polynomial equation this way: attach to it a geometric object (a curve, or a higher-dimensional variety), and read off arithmetic answers from geometric invariants like the genus — a whole number that measures, roughly, how many holes the curve's set of complex solutions has when drawn as a surface.

Definition: Rational points of an elliptic curve

An elliptic curve over Q\mathbb{Q} is a smooth cubic curve given by a Weierstrass equation y2=x3+ax+by^2 = x^3 + ax + b with a,b∈Qa,b\in\mathbb{Q}, together with one extra point OO at infinity. Its set of rational points E(Q)E(\mathbb{Q}) consists of OO plus every pair of rational numbers satisfying the equation. Remarkably, E(Q)E(\mathbb{Q}) carries a natural abelian group structure: three points sum to OO exactly when they are collinear, with OO acting as the identity element.

y2=x3+ax+by^2 = x^3 + ax + b

Here x,yx,y are the coordinates of a point on the curve, and a,b∈Qa,b\in\mathbb{Q} are fixed rational coefficients that determine which cubic curve is being studied, subject to the mild condition that x3+ax+bx^3+ax+b has no repeated root, which keeps the curve smooth.

E(Q)≅E(Q)tors⊕ZrE(\mathbb{Q}) \cong E(\mathbb{Q})_{\mathrm{tors}} \oplus \mathbb{Z}^r

This is the Mordell–Weil theorem: E(Q)≅E(Q)tors⊕ZrE(\mathbb{Q}) \cong E(\mathbb{Q})_{\mathrm{tors}} \oplus \mathbb{Z}^r. It says the group of rational points, however it looks at first, is always built from a finite piece E(Q)torsE(\mathbb{Q})_{\mathrm{tors}} (the torsion subgroup, points of finite order) plus finitely many independent points of infinite order, whose count rr is called the rank.

How genus controls the size of the rational-point set
GenusTypical equationRational points
g=0g=0a conic, e.g. x2+y2=1x^2+y^2=1either none, or infinitely many described by one rational parametrization
g=1g=1an elliptic curve, e.g. y2=x3+ax+by^2 = x^3 + ax + ba finitely generated group E(Q)E(\mathbb{Q}), possibly infinite but always described by finitely many generators
g≥2g \ge 2a Fermat curve, e.g. x5+y5=1x^5 + y^5 = 1finite, ∣C(Q)∣<∞|C(\mathbb{Q})| < \infty (Faltings' theorem)

UndergraduateTwo theorems that shape the field

For an elliptic curve EE over Q\mathbb{Q}, the group E(Q)E(\mathbb{Q}) is finitely generated: E(Q)≅E(Q)tors⊕ZrE(\mathbb{Q}) \cong E(\mathbb{Q})_{\mathrm{tors}} \oplus \mathbb{Z}^r for some integer r≥0r\ge 0, the rank of EE.

Why is it true?

Rational points could in principle accumulate in an arbitrarily complicated way; the theorem says the opposite happens — the whole infinite set, if infinite, is completely controlled by finitely many chosen points combined by the group law.

Proof

Step 1 (weak Mordell–Weil). First show the quotient group E(Q)/2E(Q)E(\mathbb{Q})/2E(\mathbb{Q}) is finite. For a point P∈E(Q)P\in E(\mathbb{Q}) that is not twice a rational point, Kummer theory attaches to PP a class in the Galois cohomology group H1(Gal(Q‾/Q),E[2])H^1(\mathrm{Gal}(\overline{\mathbb{Q}}/\mathbb{Q}), E[2]); this class is unramified outside the finitely many primes dividing 22 and the discriminant of EE. Hermite–Minkowski's finiteness theorem says there are only finitely many extensions of Q\mathbb{Q} of bounded degree unramified outside a fixed finite set of primes, which forces the image of this map — and hence E(Q)/2E(Q)E(\mathbb{Q})/2E(\mathbb{Q}) — to be finite.

Step 2 (height functions). Define a height h(P)h(P) on points by taking the logarithm of the largest numerator or denominator appearing in the xx-coordinate of PP (written in lowest terms). Two facts about hh drive the argument: it grows like h(2P)=4h(P)+O(1)h(2P) = 4h(P) + O(1) under doubling, and for any bound HH there are only finitely many rational points with h(P)≤Hh(P) \le H, since only finitely many fractions have numerator and denominator below a given size.

Step 3 (descent). Fix coset representatives Q1,…,QnQ_1,\dots,Q_n for the finite group E(Q)/2E(Q)E(\mathbb{Q})/2E(\mathbb{Q}) found in Step 1. Given any P∈E(Q)P\in E(\mathbb{Q}), some QiQ_i satisfies P−Qi=2P1P - Q_i = 2P_1 for a rational point P1P_1, and the height estimates of Step 2 show h(P1)≤14h(P)+Ch(P_1) \le \tfrac14 h(P) + C for a constant CC depending only on EE. Repeating this — replace PP by P1P_1, then P2P_2, and so on — the height keeps shrinking by a factor close to 14\tfrac14 each time, so after finitely many steps it drops below the fixed bound C′=4C3C'=\tfrac{4C}{3}. This expresses every PP as a combination of the finitely many QiQ_i and a point of height at most C′C', of which there are only finitely many.

Step 4 (conclusion). Steps 1–3 show E(Q)E(\mathbb{Q}) is generated by a finite set. A finitely generated abelian group is, by the structure theorem, a direct sum of a finite torsion part and a free part, giving exactly E(Q)≅E(Q)tors⊕ZrE(\mathbb{Q}) \cong E(\mathbb{Q})_{\mathrm{tors}} \oplus \mathbb{Z}^r.

If CC is a smooth projective curve over Q\mathbb{Q} of genus g≥2g \ge 2, then ∣C(Q)∣<∞|C(\mathbb{Q})| < \infty: the curve has only finitely many rational points.

Why is it true?

Genus 0 curves can have infinite parametrized families of rational points, and genus 1 curves can have infinite but finitely-generated groups of them; genus g≥2g \ge 2 curves are geometrically rigid enough (they admit no non-constant maps from the projective line, and their universal cover is the hyperbolic disk) that rational points cannot accumulate.

Proof

Step 1 (from curves to abelian varieties). Attach to CC its Jacobian JJ, an abelian variety of dimension gg that contains CC (via the Abel–Jacobi embedding, once one rational point is fixed). A rational point of CC corresponds to a rational point of JJ, and Parshin's construction (1968) turns a hypothetical infinite sequence of distinct rational points on CC into infinitely many pairwise non-isomorphic abelian varieties of dimension gg defined over Q\mathbb{Q}, all with good reduction outside one fixed finite set of primes SS that depends only on CC.

Step 2 (Shafarevich's finiteness conjecture). Shafarevich conjectured, for fixed gg and fixed finite SS, that only finitely many isomorphism classes of principally polarized abelian varieties of dimension gg over Q\mathbb{Q} have good reduction outside SS. Faltings proves this using Arakelov theory: he constructs a height function on the moduli space of such abelian varieties (the Faltings height), shows this height changes in a controlled way under isogeny, and bounds it using the finiteness of number fields unramified outside SS together with estimates from the theory of heights and semistable reduction. Bounded height in a fixed-dimensional moduli space forces finiteness.

Step 3 (contradiction closes the argument). Step 1 produced infinitely many non-isomorphic abelian varieties under the false assumption that CC has infinitely many rational points; Step 2 shows that only finitely many such abelian varieties can exist. This contradiction is only avoided if the original assumption was wrong, so CC has only finitely many rational points: ∣C(Q)∣<∞|C(\mathbb{Q})| < \infty.

UndergraduateReal-World Applications and Worked Examples

The same chord-and-tangent group law that organizes rational points on y2=x3+ax+by^2 = x^3 + ax + b also works when the coordinates are reduced modulo a large prime pp. In that finite-field setting, adding a point to itself kk times (2P2P and higher multiples kPkP) is fast, while recovering kk from PP and kPkP — the elliptic-curve discrete logarithm problem — is computationally infeasible for well-chosen curves. This asymmetry secures TLS handshakes across the web, SSH keys, and digital signatures in payment and blockchain systems. Closer to pure number theory, Hasse–Weil LL-functions L(E,s)L(E,s) package the point counts of EE modulo every prime pp into a single analytic function; the Birch and Swinnerton-Dyer conjecture predicts ord⁡s=1L(E,s)=r\operatorname{ord}_{s=1} L(E,s) = r, reading the global rank rr of rational points directly from the order of vanishing of L(E,s)L(E,s) at s=1s=1.

Example: Integer points on the Mordell curve y² = x³ − 2

Find all integer solutions to the Mordell equation y2=x3−2y^2 = x^3 - 2.

Solution

Step 1 (factor in a quadratic ring). Rewrite y2=x3−2y^2 = x^3 - 2 as x3=y2+2=(y+−2)(y−−2)x^3 = y^2 + 2 = (y+\sqrt{-2})(y-\sqrt{-2}) inside the ring Z[−2]\mathbb{Z}[\sqrt{-2}], which is a unique factorization domain (it has a Euclidean algorithm, just like the ordinary integers).

Step 2 (coprimality of the two factors). Any common divisor δ\delta of y+−2y+\sqrt{-2} and y−−2y-\sqrt{-2} also divides their difference 2−2=−(−2)32\sqrt{-2} = -(\sqrt{-2})^3. If −2\sqrt{-2} divided both factors, then 22 would divide y2+2=x3y^2+2 = x^3, forcing xx and hence yy to be even; but then x3x^3 is a multiple of 88 while y2+2≡2(mod4)y^2+2 \equiv 2 \pmod 4, impossible. Thus y+−2y+\sqrt{-2} and y−−2y-\sqrt{-2} are coprime in Z[−2]\mathbb{Z}[\sqrt{-2}].

Step 3 (each factor is a cube). Since their product is the cube x3x^3 and the units of Z[−2]\mathbb{Z}[\sqrt{-2}] are ±1\pm 1 (both already cubes), unique factorization forces y+−2=(u+v−2)3y+\sqrt{-2} = (u+v\sqrt{-2})^3 for some integers u,vu,v. Expanding the cube gives y+−2=(u3−6uv2)+(3u2v−2v3)−2y+\sqrt{-2} = (u^3-6uv^2) + (3u^2v - 2v^3)\sqrt{-2}.

Step 4 (read off the integer solutions). Comparing coefficients of −2\sqrt{-2} gives 1=v(3u2−2v2)1 = v(3u^2-2v^2). Because u,vu,v are integers, v=±1v = \pm 1; only v=1v=1 makes 3u2−2=13u^2-2 = 1 solvable, giving u=±1u = \pm 1. Substituting back yields y=u3−6uv2=±5y = u^3 - 6uv^2 = \pm 5 and x=u2+2v2=3x = u^2+2v^2 = 3, so the only integer points on y2=x3−2y^2 = x^3 - 2 are (x,y)=(3,±5)(x,y) = (3, \pm 5). (Notice that E(Q)E(\mathbb{Q}) itself is still infinite here: repeatedly applying the chord-and-tangent law to (3,5)(3,5) produces infinitely many rational points with growing denominators, such as (129100,±3831000)(\tfrac{129}{100}, \pm\tfrac{383}{1000}).)

Example: Doubling a point in elliptic-curve cryptography

On the elliptic curve y2=x3+2x+3(mod97)y^2 = x^3 + 2x + 3 \pmod{97}, compute the doubled point 2P2P for P=(3,6)P = (3,6).

Solution

Step 1 (check PP is on the curve and find the tangent slope). Substitute P=(3,6)P=(3,6) into y2=x3+2x+3(mod97)y^2 = x^3 + 2x + 3 \pmod{97}: the left side is 62=366^2 = 36, and the right side is 33+2⋅3+3=363^3 + 2\cdot 3 + 3 = 36, so PP lies on the curve. Implicit differentiation of y2=x3+ax+by^2 = x^3+ax+b gives the tangent slope at P=(x1,y1)P=(x_1,y_1) as λ≡3x12+a2y1(mod97)\lambda \equiv \frac{3x_1^2+a}{2y_1} \pmod{97}. With a=2a=2 and (x1,y1)=(3,6)(x_1,y_1)=(3,6), the numerator is 3⋅9+2=293\cdot 9 + 2 = 29 and the denominator is 2⋅6=122\cdot 6 = 12.

Step 2 (invert the denominator modulo 9797). Because 12⋅8=96≡−1(mod97)12\cdot 8 = 96 \equiv -1 \pmod{97}, the modular inverse of 1212 modulo 9797 is −8≡89(mod97)-8 \equiv 89 \pmod{97}. Thus λ≡29⋅(−8)=−232≡59(mod97)\lambda \equiv 29\cdot(-8) = -232 \equiv 59 \pmod{97}.

Step 3 (intersect the tangent with the curve and reflect). The chord-and-tangent formula gives the coordinates (x3,y3)(x_3,y_3) of 2P2P by x3≡λ2−2x1(mod97)x_3 \equiv \lambda^2 - 2x_1 \pmod{97} and y3≡λ(x1−x3)−y1(mod97)y_3 \equiv \lambda(x_1 - x_3) - y_1 \pmod{97}. Computing: x3≡592−6=3475=35⋅97+80≡80(mod97)x_3 \equiv 59^2 - 6 = 3475 = 35\cdot 97 + 80 \equiv 80 \pmod{97}, and y3≡59(3−80)−6=−4549=−47⋅97+10≡10(mod97)y_3 \equiv 59(3-80) - 6 = -4549 = -47\cdot 97 + 10 \equiv 10 \pmod{97}, so 2P=(80,10)2P = (80,10).

In the Mordell–Weil theorem E(Q)≅E(Q)tors⊕ZrE(\mathbb{Q}) \cong E(\mathbb{Q})_{\mathrm{tors}} \oplus \mathbb{Z}^r, what does the integer rr represent?

Elliptic-curve cryptography, used in TLS and blockchain signatures, relies on which structure studied in arithmetic geometry?

By Faltings' theorem, a smooth projective curve C/QC/\mathbb{Q} of genus g≥2g \ge 2 has:

The Birch and Swinnerton-Dyer conjecture predicts that the rank rr of E(Q)E(\mathbb{Q}) equals:

References

  1. Joseph H. Silverman (2009). The Arithmetic of Elliptic Curves
  2. Gerd Faltings (1983). Endlichkeitssätze für abelsche Varietäten über Zahlkörpern · DOI:10.1007/BF01388432
  3. Marc Hindry, Joseph H. Silverman (2000). Diophantine Geometry: An Introduction
  4. Manjul Bhargava, Christopher Skinner, Wei Zhang (2014). A majority of elliptic curves over Q satisfy the Birch and Swinnerton-Dyer conjecture · arXiv:1407.1826 [preprint, not peer-reviewed]