maths.freeNumber Theory › Deeper water › Elliptic curve

Elliptic curve

In mathematics, an elliptic curve is a smooth, projective, algebraic curve of genus one, on which there is a specified point O.

Elliptic curve

In mathematics, an elliptic curve is a smooth, projective, algebraic curve of genus one, on which there is a specified point O. An elliptic curve is defined over a field K and describes points in K, the Cartesian product of K with itself. If the field's characteristic is different from 2 and 3, then the curve can be described as a plane algebraic curve which consists of solutions (x, y) for:

\(y^2 = x^3 + ax + b\)

for some coefficients a and b in K. The curve is required to be non-singular, which means that the curve has no cusps or self-intersections. (This is equivalent to the condition 4a + 27b ≠ 0, that is, being square-free in x.) It is usually understood that the curve is embedded in the projective plane, with the point O being the unique point at infinity. Many sources define an elliptic curve to be simply a curve given by an equation of this form. (When the coefficient field has characteristic 2 or 3, the above equation is not quite general enough to include all non-singular cubic curves; see § Elliptic curves over a general field below.)

An elliptic curve is an abelian variety (that is, it has a group law defined algebraically, with respect to which it is an abelian group) and O serves as the identity element.

If y = P(x), where P is any polynomial of degree three in x with no repeated roots, the solution set is a nonsingular plane curve of genus one, an elliptic curve. If P has degree four and is square-free this equation again describes a plane curve of genus one; however, it has no natural choice of identity element. More generally, any algebraic curve of genus one, for example the intersection of two quadric surfaces embedded in three-dimensional projective space, is called an elliptic curve, provided that it is equipped with a marked point to act as the identity.

Using the theory of elliptic functions, it can be shown that elliptic curves defined over the complex numbers correspond to embeddings of the torus into the complex projective plane. The torus is also an abelian group, and this correspondence is also a group isomorphism.

Elliptic curves are especially important in number theory, and constitute a major area of current research; for example, they were used in Andrew Wiles's proof of Fermat's Last Theorem. They also find applications in elliptic curve cryptography (ECC) and integer factorization.

Condensed: the full section is in Wikipedia.

Elliptic curves over the real numbers

Although the formal definition of an elliptic curve requires some background in algebraic geometry, it is possible to describe some features of elliptic curves over the real numbers using only introductory algebra and geometry.

In this context, an elliptic curve is a plane curve defined by an equation of the form

\(y^2 = x^3 + ax + b\)

after a linear change of variables (a and b are real numbers). This type of equation is called a Weierstrass normal form, Weierstrass form, or Weierstrass equation.

The definition of elliptic curve also requires that the curve be non-singular. Geometrically, this means that the graph has no cusps, self-intersections, or isolated points. Algebraically, this holds if and only if the discriminant, \(\Delta\), is not equal to zero, where \(\Delta\) is defined as:

\(\Delta = -16\left(4a^3 + 27b^2\right)\)

(see J-invariant#Algebraic_definition for the derivation).

The discriminant is zero when \(a=-3k^2, b=2k^3\) for some real \(k\), and in this case \(E\) factors into \(E: y^2 = (x-k)^2(x+2k)\).

Although the factor −16 is irrelevant to whether or not the curve is non-singular, this definition of the discriminant is useful in a more advanced study of elliptic curves.

Condensed: the full section is in Wikipedia.

Group law

When working in the projective plane, the equation in homogeneous coordinates becomes

\(\frac{Y^2}{Z^2} = \frac{X^3}{Z^3} + a\frac{X}{Z} + b.\)

This equation is not defined on the line at infinity, but we can multiply by \(Z^3\) to get one that is:

\(ZY^2 = X^3 + aZ^2X + bZ^3.\)

This resulting equation is defined on the whole projective plane, and the curve it defines projects onto the elliptic curve of interest. To find its intersection with the line at infinity, we can just posit \(Z = 0\). This implies \(X^3 = 0\), which in a field means \(X = 0\). \(Y\) on the other hand can take any value, and thus all triplets \((0,Y,0)\) satisfy the equation. In projective geometry this set is simply the point \(O = [0:1:0]\), which is thus the unique intersection of the curve with the line at infinity.

Since the curve is smooth, hence continuous, it can be shown that this point at infinity is the identity element of a group structure whose operation is geometrically described as follows:

Since the curve is symmetric about the x axis, given any point P, we can take −P to be the point opposite it. We then have \(-O = O\), as \(O\) lies on the XZ plane, so that \(-O\) is also the symmetrical of \(O\) about the origin, and thus represents the same projective point.

If P and Q are two points on the curve, then we can uniquely describe a third point P + Q in the following way. First, draw the line that intersects P and Q. This will generally intersect the cubic at a third point, R. We then take P + Q to be −R, the point opposite R.

This definition for addition works except in a few special cases related to the point at infinity and intersection multiplicity. The first is when one of the points is O. Here, we define P + O = P = O + P, making O the identity of the group. If P = Q, we only have one point, thus we cannot define the line between them. In this case, we use the tangent line to the curve at this point as our line. In most cases, the tangent will intersect a second point R, and we can take its opposite. If P and Q are opposites of each other, we define P + Q = O. Lastly, if P is an inflection point (a point where the concavity of the curve changes), we take R to be P itself, and P + P is simply the point opposite itself, i.e. itself.

Condensed: the full section is in Wikipedia.

Algebraic interpretation

The above groups can be described algebraically as well as geometrically. Given the curve y = x + bx + c over the field K (whose characteristic we assume to be neither 2 nor 3), and points P = (xP, yP) and Q = (xQ, yQ) on the curve, assume first that xPxQ (case 1). Let y = sx + d be the equation of the line that intersects P and Q, which has the following slope:

\(s = \frac{y_P - y_Q}{x_P - x_Q}.\)

The line equation and the curve equation intersect at the points xP, xQ, and xR, so the equations have identical y values at these values.

\((sx + d)^2 = x^3 + bx + c,\)

which is equivalent to

\(x^3 - s^2 x^2 - 2sdx + bx + c - d^2 = 0.\)

Since xP, xQ, and xR are solutions, this equation has its roots at exactly the same x values as

\((x - x_P) (x - x_Q) (x - x_R) = x^3 + (-x_P - x_Q - x_R) x^2 + (x_P x_Q + x_P x_R + x_Q x_R) x - x_P x_Q x_R,\)

and because both equations are cubics, they must be the same polynomial up to a scalar. Then equating the coefficients of x in both equations

\(-s^2 = (-x_P - x_Q - x_R)\)

and solving for the unknown xR,

\(x_R = s^2 - x_P - x_Q.\)

yR follows from the line equation

\(y_R = y_P - s(x_P - x_R),\)

\(\begin{aligned} s &= \frac{3{x_P}^2 + b}{2y_P}, \\ x_R &= s^2 - 2x_P, \\ y_R &= y_P - s(x_P - x_R). \end{aligned}\)

\(s = \frac{{x_P}^2 + x_P x_Q + {x_Q}^2 + b}{y_P + y_Q},\)

Condensed: the full section is in Wikipedia.

Non-Weierstrass curves

For the curve y = x + ax + bx + c (the general form of an elliptic curve with characteristic 3), the formulas are similar, with s = ⁠xP + xP xQ + xQ + axP + axQ + b/yP + yQ⁠ and xR = saxPxQ.

For a general cubic curve not in Weierstrass normal form, we can still define a group structure by designating one of its nine inflection points as the identity O. In the projective plane, each line will intersect a cubic at three points when accounting for multiplicity. For a point P, −P is defined as the unique third point on the line passing through O and P. Then, for any P and Q, P + Q is defined as −R where R is the unique third point on the line containing P and Q.

For an example of the group law over a non-Weierstrass curve, see Hessian curves.

Elliptic curves over the rational numbers

A curve E defined over the field of rational numbers is also defined over the field of real numbers. Therefore, the law of addition (of points with real coordinates) by the tangent and secant method can be applied to E. The explicit formulae show that the sum of two points P and Q with rational coordinates has again rational coordinates, since the line joining P and Q has rational coefficients. This way, one shows that the set of rational points of E forms a subgroup of the group of real points of E.

Integral points

This section is concerned with points P = (x, y) of E such that x is an integer.

For example, the equation y = x + 17 has eight integral solutions with y > 0:

(x, y) = (−2, 3), (−1, 4), (2, 5), (4, 9), (8, 23), (43, 282), (52, 375), (5234, 378661).

As another example, Ljunggren's equation, a curve whose Weierstrass form is y = x − 2x, has only four solutions with y ≥ 0 :

(x, y) = (0, 0), (−1, 1), (2, 2), (338, 6214).

The structure of rational points

Rational points can be constructed by the method of tangents and secants detailed above, starting with a finite number of rational points. More precisely the Mordell-Weil theorem states that the group E(Q) is a finitely generated (abelian) group. By the fundamental theorem of finitely generated abelian groups it is therefore a finite direct sum of copies of Z and finite cyclic groups.

The proof of the theorem involves two parts. The first part shows that for any integer m > 1, the quotient group E(Q)/mE(Q) is finite (this is the weak Mordell-Weil theorem). Second, introducing a height function h on the rational points E(Q) defined by h(P0) = 0 and h(P) = log max(|p|, |q|) if P (unequal to the point at infinity P0) has as abscissa the rational number x = p/q (with coprime p and q). This height function h has the property that h(mP) grows roughly like the square of m. Moreover, only finitely many rational points with height smaller than any constant exist on E.

The proof of the theorem is thus a variant of the method of infinite descent and relies on the repeated application of Euclidean divisions on E: let PE(Q) be a rational point on the curve, writing P as the sum 2P1 + Q1 where Q1 is a fixed representant of P in E(Q)/2E(Q), the height of P1 is about ⁠1/4⁠ of the one of P (more generally, replacing 2 by any m > 1, and ⁠1/4⁠ by ⁠1/m⁠). Redoing the same with P1, that is to say P1 = 2P2 + Q2, then P2 = 2P3 + Q3, etc. finally expresses P as an integral linear combination of points Qi and of points whose height is bounded by a fixed constant chosen in advance: by the weak Mordell-Weil theorem and the second property of the height function P is thus expressed as an integral linear combination of a finite number of fixed points.

The theorem however doesn't provide a method to determine any representatives of E(Q)/mE(Q).

The rank of E(Q) is the number of copies of Z in E(Q) or, equivalently, the number of independent points of infinite order. The Birch and Swinnerton-Dyer conjecture is concerned with determining the rank. One conjectures that it can be arbitrarily large, even if only examples with relatively small rank are known. The elliptic curve with the currently largest exactly-known rank is

y + xy + y = xx − 244537673336319601463803487168961769270757573821859853707x + 961710182053183034546222979258806817743270682028964434238957830989898438151121499931

It has rank 20, found by Noam Elkies and Zev Klagsbrun in 2020. Curves of rank higher than 20 have been known since 1994, with lower bounds on their ranks ranging from 21 to 31, but their exact ranks are not known and in particular it is not proven which of them have higher rank than the others or which is the true "current champion".

As for the groups constituting the torsion subgroup of E(Q), the following is known: the torsion subgroup of E(Q) is one of the 15 following groups (a theorem due to Barry Mazur): Z/NZ for N = 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, or 12, or Z/2Z × Z/2NZ with N = 1, 2, 3, 4. Examples for every case are known. Moreover, elliptic curves whose Mordell-Weil groups over Q have the same torsion groups belong to a parametrized family.

The Birch and Swinnerton-Dyer conjecture

The Birch and Swinnerton-Dyer conjecture (BSD) is one of the Millennium problems of the Clay Mathematics Institute. The conjecture relies on analytic and arithmetic objects defined by the elliptic curve in question.

At the analytic side, an important ingredient is a function of a complex variable, L, the Hasse-Weil zeta function of E over Q. This function is a variant of the Riemann zeta function and Dirichlet L-functions. It is defined as an Euler product, with one factor for every prime number p.

For a curve E over Q given by a minimal equation

\(y^2 + a_1xy + a_3y = x^3 + a_2x^2 + a_4x + a_6\)

with integral coefficients \(a_i\), reducing the coefficients modulo p defines an elliptic curve over the finite field Fp (except for a finite number of primes p, where the reduced curve has a singularity and thus fails to be elliptic, in which case E is said to be of bad reduction at p).

The zeta function of an elliptic curve over a finite field Fp is, in some sense, a generating function assembling the information of the number of points of E with values in the finite field extensions Fp of Fp. It is given by

\(Z(E(\mathbf{F}_p), T) = \exp\left(\sum_{n=1}^\infty \# \left[E({\mathbf F}_{p^n})\right]\frac{T^n}{n}\right)\)

The interior sum of the exponential resembles the development of the logarithm and, in fact, the so-defined zeta function is a rational function in T:

\(Z(E(\mathbf{F}_p), T) = \frac{1 - a_pT + pT^2}{(1 - T)(1 - pT)},\)

where the 'trace of Frobenius' term \(a_p\) is defined to be the difference between the 'expected' number \(p+1\) and the number of points on the elliptic curve \(E\) over \(\mathbb{F}_p\), viz.

\(a_p = p + 1 - \#E(\mathbb{F}_p)\)

\(\#E(\mathbb{F}_p) = p + 1 - a_p\).

\(L(E(\mathbf{Q}), s) = \prod_{p\not\mid N} \left(1 - a_p p^{-s} + p^{1 - 2s}\right)^{-1} \cdot \prod_{p\mid N} \left(1 - a_p p^{-s}\right)^{-1}\)

\(L(E(\mathbf{Q}), 1) = \prod_{p\not\mid N} \left(1 - a_p p^{-1} + p^{-1}\right)^{-1} = \prod_{p\not\mid N} \frac{p}{p - a_p + 1} = \prod_{p\not\mid N}\frac{p}{\#E(\mathbb{F}_p)}\)

  • A congruent number is defined as an odd square-free integer n which is the area of a right triangle with rational side lengths. It is known that n is a congruent number if and only if the elliptic curve \(y^2 = x^3 - n^2x\) has a rational point of infinite order; assuming BSD, this is equivalent to its L-function having a zero at s = 1. Tunnell has shown a related result: assuming BSD, n is a congruent number if and only if the number of triplets of integers (x, y, z) satisfying \(2x^2 + y^2 + 8z^2 = n\) is twice the number of triples satisfying \(2x^2 + y^2 + 32z^2 = n\). The interest in this statement is that the condition is easy to check.
  • In a different direction, certain analytic methods allow for an estimation of the order of zero in the center of the critical strip for certain L-functions. Admitting BSD, these estimations correspond to information about the rank of families of the corresponding elliptic curves. For example: assuming the generalized Riemann hypothesis and BSD, the average rank of curves given by \(y^2=x^3+ax+b\) is smaller than 2.

Condensed: the full section is in Wikipedia.

Elliptic curves over finite fields

Let K = Fq be the finite field with q elements and E an elliptic curve defined over K. While the precise number of rational points of an elliptic curve E over K is in general difficult to compute, Hasse's theorem on elliptic curves gives the following inequality:

\(|\# E(K) - (q + 1)| \le 2\sqrt{q}\)

In other words, the number of points on the curve grows proportionally to the number of elements in the field. This fact can be understood and proven with the help of some general theory; see local zeta function and étale cohomology for example.

The set of points E(Fq) is a finite abelian group. It is always cyclic or the product of two cyclic groups. For example, the curve defined by

\(y^2 = x^3 - x\)

over F71 has 72 points (71 affine points including (0,0) and one point at infinity) over this field, whose group structure is given by Z/2Z × Z/36Z. The number of points on a specific curve can be computed with Schoof's algorithm.

Studying the curve over the field extensions of Fq is facilitated by the introduction of the local zeta function of E over Fq, defined by a generating series (also see above)

\(Z(E(K), T) = \exp \left(\sum_{n=1}^{\infty} \# \left[E(K_n)\right] {T^n\over n} \right)\)

where the field Kn is the (unique up to isomorphism) extension of K = Fq of degree n (that is, \(K_n=F_{q^n}\)).

The zeta function is a rational function in T. To see this, consider the integer \(a\) such that

\(\#E(K) = 1 - a + q\)

\(1 - a + q = (1 - \alpha)(1 - \bar\alpha)\)

\(\alpha+\bar\alpha = a\)

\(\alpha\bar\alpha = q\)

\(\#E(K_n) = 1 - a_n + q^n\)

\(\begin{alignedat}{2} Z(E(K),T) & = \exp \left(\sum_{n=1}^{\infty} \left(1 - \alpha^n - \bar\alpha^n + q^n\right){T^n\over n} \right) \\ & = \exp \left(\sum_{n=1}^{\infty} {T^n\over n} - \sum_{n=1}^{\infty}\alpha^n{T^n\over n} - \sum_{n=1}^{\infty}\bar\alpha^n{T^n\over n} + \sum_{n=1}^{\infty}q^n{T^n\over n} \right) \\ & = \exp \left(-\ln(1-T) + \ln(1-\alpha T) + \ln(1-\bar\alpha T) - \ln(1-qT) \right) \\ & = \exp \left(\ln\frac{(1-\alpha T)(1-\bar\alpha T)}{(1-T)(1-qT)} \right) \\ & =\frac{(1-\alpha T)(1-\bar\alpha T)}{(1-T)(1-qT)} \\ \end{alignedat}\)

\(Z(E(K), T) = \frac{1 - aT + qT^2}{(1 - qT)(1 - T)}\)

\(\frac{1 + 2T^2}{(1 - T)(1 - 2T)}\)

\(\left| E(\mathbf{F}_{2^r}) \right| = \begin{cases} 2^r + 1 & r \text{ odd} \\ 2^r + 1 - 2(-2)^{\frac{r}{2}} & r \text{ even} \end{cases}\)

\(Z \left(E(K), \frac{1}{qT} \right) = \frac{1 - a\frac{1}{qT} + q\left(\frac{1}{qT}\right)^2}{(1 - q\frac{1}{qT})(1 - \frac{1}{qT})}= \frac{q^2T^2 - aqT + q}{(qT - q)(qT - 1)} = Z(E(K), T)\)

\(Z(a, T) = \exp \left(\sum_{n=1}^{\infty} -a_n {T^n\over n} \right)\)

\(Z(a, T) = \exp \left(\sum_{n=1}^{\infty} -\alpha^n {T^n\over n} - \bar\alpha^n {T^n\over n} \right)\)

\(Z(a, T) = \exp \left(\ln(1-\alpha T) + \ln(1-\bar\alpha T)\right)\)

\(L(E(K), T) = 1 - aT + qT^2\)

Condensed: the full section is in Wikipedia.

Elliptic curves over a general field

Elliptic curves can be defined over any field K; the formal definition of an elliptic curve is a non-singular projective algebraic curve over K with genus 1 and endowed with a distinguished point defined over K.

If the characteristic of K is neither 2 nor 3, then every elliptic curve over K can be written in the form

\(y^2 = x^3 - px - q\)

after a linear change of variables. Here p and q are elements of K such that the right hand side polynomial xpxq does not have any double roots. If the characteristic is 2 or 3, then more terms need to be kept: in characteristic 3, the most general equation is of the form

\(y^2 = x^3 + b_2 x^2 - b_4 x + b_6\)

for arbitrary constants b2, b4, b6 such that the polynomial on the right-hand side has distinct roots (the notation is chosen for historical reasons). In characteristic 2, even this much is not possible, and the most general equation is

\(y^2 + a_1 xy + a_3 y = x^3 + a_2 x^2 + a_4 x + a_6\)

provided that the variety it defines is non-singular. If characteristic were not an obstruction, each equation would reduce to the previous ones by a suitable linear change of variables.

One typically takes the curve to be the set of all points (x,y) which satisfy the above equation and such that both x and y are elements of the algebraic closure of K. Points of the curve whose coordinates both belong to K are called K-rational points.

Many of the preceding results remain valid when the field of definition of E is a number field K, that is to say, a finite field extension of Q. In particular, the group E(K) of K-rational points of an elliptic curve E defined over K is finitely generated, which generalizes the Mordell-Weil theorem above. A theorem due to Loïc Merel shows that for a given integer d, there are (up to isomorphism) only finitely many groups that can occur as the torsion groups of E(K) for an elliptic curve defined over a number field K of degree d. More precisely, there is a number B(d) such that for any elliptic curve E defined over a number field K of degree d, any torsion point of E(K) is of order less than B(d). The theorem is effective: for d > 1, if a torsion point is of order p, with p prime, then

Condensed: the full section is in Wikipedia.

Elliptic curves over the complex numbers

The formulation of elliptic curves as the embedding of a torus in the complex projective plane follows naturally from a curious property of Weierstrass's elliptic functions. These functions and their first derivative are related by the formula

\(\wp'(z)^2 = 4\wp(z)^3 -g_2\wp(z) - g_3\)

Here, g2 and g3 are constants; ℘(z) is the Weierstrass elliptic function and ℘′(z) its derivative. It should be clear that this relation is in the form of an elliptic curve (over the complex numbers). The Weierstrass functions are doubly periodic; that is, they are periodic with respect to a lattice Λ; in essence, the Weierstrass functions are naturally defined on a torus T = C/Λ. This torus may be embedded in the complex projective plane by means of the map

\(z \mapsto \left[1 : \wp(z) : \tfrac12\wp'(z)\right]\)

This map is a group isomorphism of the torus (considered with its natural group structure) with the chord-and-tangent group law on the cubic curve which is the image of this map. It is also an isomorphism of Riemann surfaces from the torus to the cubic curve, so topologically, an elliptic curve is a torus. If the lattice Λ is related by multiplication by a non-zero complex number c to a lattice cΛ, then the corresponding curves are isomorphic. Isomorphism classes of elliptic curves are specified by the j-invariant.

The isomorphism classes can be understood in a simpler way as well. The constants g2 and g3, called the modular invariants, are uniquely determined by the lattice, that is, by the structure of the torus. However, all real polynomials factorize completely into linear factors over the complex numbers, since the field of complex numbers is the algebraic closure of the reals. So, the elliptic curve may be written as

\(y^2 = x(x - 1)(x - \lambda)\)

One finds that

\(\begin{aligned} g_2' &= \frac{\sqrt[3]4}{3} \left(\lambda^2 - \lambda + 1\right) \\[4pt] g_3' &= \frac{1}{27} (\lambda + 1)\left(2\lambda^2 - 5\lambda + 2\right) \end{aligned}\)

and

\(j(\tau) = 1728\frac{{g_2'}^3}{{g_2'}^3 - 27{g_3'}^2} = 256\frac{ \left(\lambda^2 - \lambda + 1\right)^3}{\lambda^2\left(\lambda - 1\right)^2}\)

with j-invariant j(τ) and λ(τ) is sometimes called the modular lambda function. For example, let τ = 2i, then λ(2i) = (−1 + √2) which implies g2, g3, and therefore g2
− 27g3
of the formula above are all algebraic numbers if τ involves an imaginary quadratic field. In fact, it yields the integer j(2i) = 66 = 287496.

\(\Delta(\tau) = g_2(\tau)^3 - 27g_3(\tau)^2 = (2\pi)^{12}\,\eta^{24}(\tau)\)

\(\eta(2i)=\frac{\Gamma \left(\frac14\right)}{2^\frac{11}{8} \pi^\frac34}\)

\(\frac{a}{n} \omega_1 + \frac{b}{n} \omega_2\)

\(E : y^2=4(x-e_1)(x-e_2)(x-e_3)\)

\(a_0=\sqrt{e_1-e_3}, \qquad b_0=\sqrt{e_1-e_2}, \qquad c_0=\sqrt{e_2-e_3},\)

\(\omega_1=\frac{\pi}{\operatorname{M}(a_0,b_0)}, \qquad \omega_2=\frac{\pi}{\operatorname{M}(c_0,ib_0)}\)

Condensed: the full section is in Wikipedia.

The dual isogeny

Given an isogeny

\(f : E \to E'\)

of elliptic curves of degree \(n\), the dual isogeny is an isogeny

\(\hat{f} : E' \to E\)

of the same degree such that

\(f \circ \hat{f} = [n].\)

Here \([n]\) denotes the multiplication-by-\(n\) isogeny \(e \mapsto ne\) which has degree \(n^2.\)

Construction of the dual isogeny

Often only the existence of a dual isogeny is needed, but it can be explicitly given as the composition

\(E' \to \operatorname{Div}^0(E') \to \operatorname{Div}^0(E) \to E,\)

where \(\operatorname{Div}^0\) is the group of divisors of degree 0. To do this, we need maps \(E \to \operatorname{Div}^0(E)\) given by \(P \to P - O\) where \(O\) is the neutral point of \(E\) and \(\operatorname{Div}^0(E) \to E\) given by \(\sum n_P P \to \sum n_P P.\)

To see that \(f \circ \hat{f} = [n]\), note that the original isogeny \(f\) can be written as a composite

\(E \to \operatorname{Div}^0(E) \to \operatorname{Div}^0(E') \to E',\)

and that since \(f\) is finite of degree \(n\), \(f_* f^*\) is multiplication by \(n\) on \(\operatorname{Div}^0(E').\)

Alternatively, we can use the smaller Picard group \(\operatorname{Pic}^0\), a quotient of \(\operatorname{Div}^0.\) The map \(E \to \operatorname{Div}^0(E)\) descends to an isomorphism, \(E \to \operatorname{Pic}^0(E).\) The dual isogeny is

\(E' \to \operatorname{Pic}^0(E') \to \operatorname{Pic}^0(E) \to E.\)

Note that the relation \(f \circ \hat{f} = [n]\) also implies the conjugate relation \(\hat{f} \circ f = [n].\) Indeed, let \(\phi = \hat{f} \circ f.\) Then \(\phi \circ \hat{f} = \hat{f} \circ [n] = [n] \circ \hat{f}.\) But \(\hat{f}\) is surjective, so we must have \(\phi = [n].\)

Тепер ти Цей калькулятор не можна використовувати, але його частини можна легко перевірити. Спробуйте один нижче або наберіть власний.

Нехай ваша робота буде такою ж, як у вас

Вільний рахунок додає нотатки до кожного уроку, запису того, що ви завершили, ваших розв' язаних проблем у одному місці, і репетитора, який ви можете запитати про цю сторінку. Сама математика відкрита для всіх, підписані чи ні.

Підписування Вхід

Символи, що тут використовуються

Взяти будь-який символ до повного визначення, зображення і що означає кожна літера.

Запитання людей

Why are primes so important?

Every integer factors into primes in exactly one way, so primes are the atoms of multiplication. Cryptography relies on that factoring being easy to state and hard to do.

How do I tell whether a big number is prime?

Trial division up to the square root works for small numbers. For large ones, probabilistic tests (Miller-Rabin) give an answer that is wrong with negligible probability, and deterministic tests (AKS) exist but are slower.

Частини цієї сторінки адаптуються від Wikipedia (CC BY-SA 4.0). Засуджені і пояснені тут; помилки є нашими.

Більше в Number Theory