Hasse's bound
Statement
For an elliptic curve over a finite field ( prime), the number of points satisfies .
Why is it true?
The quantity measures the 'error term' of the naive guess that a random cubic should have about solutions plus the point at infinity; Hasse's bound says this error can never be more than about , an astonishingly small deviation compared to the trivial bound of size , and it is what makes usable as a reliable, predictable group order in cryptographic constructions.
Proof sketch
Consider the Frobenius endomorphism , . Its fixed points are exactly , and one shows where is the trace of Frobenius acting on the endomorphism ring. The degree map on endomorphisms of is a positive-definite integer-valued quadratic form (it satisfies for all integers , with equality only when ), and . Expanding as a quadratic form in forces its discriminant to be non-positive: , i.e. . Since , this is exactly the claimed bound.
Topics that use this theorem
Step-by-step proofs
No step-by-step proof yet for this theorem.
References
- Joseph H. Silverman (2009). The Arithmetic of Elliptic Curves · DOI:10.1007/978-0-387-09494-6
- Andrew Wiles (1995). Modular elliptic curves and Fermat's Last Theorem · DOI:10.2307/2118559
- Andrew Wiles / Clay Mathematics Institute (2000). The Birch and Swinnerton-Dyer Conjecture (official Millennium Problem description)
- Wouter Castryck, Thomas Decru (2022). An efficient key recovery attack on SIDH