Elliptic Curves
Daniel Naylor

Contents

1Fermat’s Method of Infinite Descent
1.1A variant for polynomials
2Some Remarks on Plane Curves
2.1The degree of a morphism
3Weierstrass Equations
4The Group Law
5Isogenies
6The Invariant Differential
7Elliptic Curves over Finite Fields
7.1Zeta functions
8Formal Groups
9Elliptic Curves over Local Fields
10Elliptic Curves over Number Fields: The torsion subgroup
11Kummer Theory
12Elliptic Curves over Number Fields: The weak Mordell-Weil Theorem
13Heights
14Dual isogenies and the Weil pairing
15Galois Cohomology
16Descent by Cyclic Isogeny
16.1Descent by 2-isogeny
16.2Birch Swinnerton Dyer Conjecture
Index

1 Fermat’s Method of Infinite Descent

PIC

Definition (Rational, primitive triangle). A triangle is rational if a,b,c ∈ ℚ.

A triangle is primitive if a,b,c ∈ ℤ and are coprime.

Lemma 1.1. Assuming that:

Then Δ is of the form

PIC

for some integers u > v > 0.

Proof. Without loss of generality a odd, b even (work modulo 4). This then forces c odd.

Then

(b 2 )2 = c + a 2 ⋅c − a 2 ,

and note that all the fractions are integers. Also note that the product on the right hand side is a product of positive coprime integers.

Unique prime factorisation in ℤ gives that c+a 2 = u2, c−a 2 = v2 for some u,v ∈ ℤ.

Then a = u2 − v2, b = 2uv, c = u2 + v2. □

Definition (Congruent number). D ∈ ℚ>0 is a congruent number if there exists a rational triangle Δ with area ⁡ (Δ) = D.

Note. It suffices to consider D ∈ ℤ>0 square-free.

Example. D = 5,6 are congruent.

Lemma 1.2. Assuming that:

  • D ∈ ℚ>0

Then D is congruent if and only if Dy2 = x3 − x for some x,y ∈ ℚ, y≠0.

Proof. Lemma 1.1 shows

D congruent⟺Dw2 = uv(u2 − v2)

for some u,v,w ∈ ℚ, with w≠0. Put x = u v and y = w v2 . □

Fermat showed that 1 is not a congruent number.

Theorem 1.3. There is no solution to

w2 = uv(u + v)(u − v) (∗)

for u,v,w ∈ ℤ and w≠0.

Proof. Without loss of generality u,v are coprime, u > 0, w > 0. If v < 0 then replace (u,v,w) by (−v,u,w). If u,v both odd then replace (u,v,w) by (u+v 2 , u−v 2 , w 2 ).

Then u,v,u + v,u − v are pairwise coprime positive integers with product a square.

Unique factorisation in ℤ gives

u = a2,v = b2,u + v = c2,u − v = d2

for some a,b,c,d ∈ ℤ>0.

Since u⁄ ≡ v(mod2), both c and d are odd.

Then consider:

(c + d 2 )2 + (c − d 2 )2 = c2 + d2 2 = u = a2.

PIC

This is a primitive triangle. The area is c2−d2 8 = v 4 = (b 2 ) 2.

Let w1 = b 2. Lemma 1.1 gives w12 = u1v1(u1 + v1)(u1 − v1) for u1,v1 ∈ ℤ. Therefore we have a new solution to (∗). But 4w12 = b2 = v|w2 so w1 ≤ 1 2w.

So by Fermat’s method of infinite descent, there is no solution to (∗) . □

1.1 A variant for polynomials

In Section 1, K is a field with char ⁡ K≠2.

Write K¯ for the algebraic closure of K.

Lemma 1.4. Assuming that:

  • u,v ∈ K[t] coprime

  • αu + βv is a square for 4 distinct (α : β) ∈ ℙ1

Then u,v ∈ K.

Proof. Without loss of generality K = K¯.

Changing coordinates on ℙ1, we may assume the ratios (α : β) are (1 : 0),(0 : 1),(1 : −1),(1 : −λ) for some λ ∈ K ∖{0,1} (Möbius map).

u = a2 v = b2 u − v = (a + b)(a − b) u − λv = (a + μb)(a − μb)

(where μ is a square root of λ). Unique factorisation in K[t] gives that a + b, a − b, a + μb, a − μb are squares. But

max ⁡ (deg⁡ ⁡ (a),deg⁡ ⁡ (b)) ≤ 1 2max ⁡ (deg⁡ ⁡ (u),deg⁡ ⁡ (v)).

So Fermat’s method of infinite descent, we get a contradiction, unless the degrees of u and v are zero. So u,v ∈ K. □

Definition 1.5 (Elliptic curve (temporary definition)).

  • (i) An elliptive curve E∕K is the projective closure of the plane affine curve
    y2 = f(x)

    where f ∈ K[x] is a monic cubic polynomial with distinct roots in K¯. We call this equation “a Weierstrass equation”.

  • (ii) For L∕K any field extension
    E(L) = {(x,y) ∈ L2|y2 = f(x)}∪{0}.

    0 is the “point at infinity” that we get because we take the projective closure.

Fact: E(L) is naturally an abelian group.

In this course, we study E(K) for K being a finite field, local field ([K : ℚp] < ∞) or number field ([K : ℚ] < ∞).

Lemma 1.2 and Theorem 1.3 tells us that if E is y2 = x3 − x, then

E(ℚ) = {0,(0,0),(±1,0)}.

Corollary 1.6. Let E∕K be an elliptic curve. Then E(K(t)) = E(K).

Proof. Without loss of generality K = K¯. By a change of coordinates, we may assume

y2 = x(x − 1)(x − λ)

for some λ ∈ K ∖{0,1}. Suppose (x,y) ∈ E(K(t)). Put x = u v, where u,v ∈ K[t] are coprime.

Then w2 = uv(u − v)(u − λv) for some w ∈ K[t].

Unique factorisation in K[t] gives that u,v,u − v,u − λv are squares. Hence by Section 1.1, u,v ∈ K, so x ∈ K, so y ∈ K. □

2 Some Remarks on Plane Curves

Work over K = K¯.

Definition 2.1 (Rational plane affine curve). A plane affine curve C = {f(x,y) = 0}⊂ 𝔸2 is rational if it has a rational parametrisation, i.e. ∃ ⁡ϕ(t),ψ(t) ∈ K(t) such that:

  • (i) 𝔸1 → 𝔸2, t↦(ϕ(t),ψ(t)) is injective on 𝔸1 ∖{finite set}.
  • (ii) f(ϕ(t),ψ(t)) = 0.

Example 2.2.

Remark 2.3. The genus g(C) ∈ ℤ≥0 is an invariant of a smooth projective curve C.

Proposition 2.4. Assuming that:

  • K = K¯

  • C a smooth projective curve

Then
  • (i) C is rational (see Definition 2.1) if and only if g(C) = 0.
  • (ii) C is an elliptic curve (see Definition 1.5) if and only if g(C) = 1.

Proof.

□
Order of vanishing

C algebraic curve, function field K(C), P ∈ C smooth point.

We write ord ⁡ p(f) for the order of vanishing of f ∈ K(C)× at P (negative of f has a pole).

Fact: ord ⁡ p : K(C)×→ ℤ is a discrete valuation, i.e. ord ⁡ p(f1f2) = ord ⁡ p(f1) + ord ⁡ p(f2) and ord ⁡ p(f1 + f2) ≥ min ⁡ (ord ⁡ p(f1),ord ⁡ p(f2)).

Definition (Uniformiser). t ∈ K(C)× is a uniformiser at P if ord ⁡ p(t) = 1.

Example 2.5. C = {g = 0}⊂ 𝔸2, g ∈ K[x,y] irreducible.

K(C) = Frac ⁡ K[x,y] (g) .

g = g0 + g1(x,y) + g2(x,y) + ⋯

where gi are homogeneous of degree i.

Suppose P = (0,0) ∈ C is a smooth point, i.e. g0 = 0, g1(x,y) = αx + βy with α,β not both zero.

PIC

Fact: γx + δy ∈ K(C) is a uniformiser at P if and only if αδ − βγ≠0.

Example 2.6.

{y2 = x(x − 1)(x − λ)}⊂ 𝔸2

where λ≠0,1. Projective closure (x = X Z , y = Y Z):

{Y 2Z = X(X − Z)(X − λZ)}⊂ ℙ2.

Let P = (0 : 1 : 0).

Aim: Compute ord ⁡ p(x) and ord ⁡ p(y).

Put w = Z Y , t = X Y . So

w = t(t − w)(t − λw) (∗)

Now Pis the point (t,w) = (0,0). This is a smooth point with

ord ⁡ p(t) = ord ⁡ p(t − w) = ord ⁡ p(t − λw) = 1.

(∗) implies ord ⁡ p(w) = 3. Therefore ord ⁡ p(x) = ord ⁡ p(t∕w) = 1 − 3 = −2 and ord ⁡ p(y) = ord ⁡ p(1∕w) = −3.

Riemann Roch Spaces

Let C be a smooth projective curve.

Definition (Divisor). A divisor is a formal sum of points on C, say

D = ∑ P∈CnpP

where np ∈ ℤ and np = 0 for all but finitely many P ∈ C.

We write deg⁡D = ∑ nP.

We say D is effective (written D ≥ 0) if nP ≥ 0 for all P.

If f ∈ K(C)×, then div ⁡ (f) = ∑ ⁡ P∈C ord ⁡ p(f)P.

The Riemann Roch space of D ∈ Div ⁡ (C) is

L (D) = {f ∈ K(C)×|div ⁡ (f) + D ≥ 0}∪{0},

i.e. the K-vector space of rational functions on C with “poles no worse than specified by D”.

We quote: Riemann Roch for genus 1:

dim⁡L(D) = { deg⁡D if deg⁡D > 0 0 or 1if deg⁡D = 0 0 if deg⁡D < 0

For example, in Example 2.6:

L(2P) = ⟨1,x⟩ L(3P) = ⟨1,x,y⟩

Proposition 2.7. Assuming that:

  • K = K¯, char ⁡ K≠2

  • C ⊂ ℙ2 a smooth plane cubic

  • P ∈ C a point of inflection

Then we may change coordinates such that
C : Y 2Z = X(X − Z)(X − λZ)

for some λ≠0,1 and P = (0 : 1 : 0).

Proof. We change coordinates such that P = (0 : 1 : 0), Tp(C) = {Z = 0}, and C : {F(X,Y,Z) = 0}⊂ ℙ2.

P ∈ C part of inflection implies F(t,1,0) = constt3, i.e. F has no terms X2Y , XY 2 or Y 3.

Therefore

F ∈⟨Y 2Z,XY Z,Y Z2,X3,X2Z,XZ2,Z3⟩.

The Y 2Z coefficient must be ≠0 otherwise P ∈ C is singular, and the coefficient of X3 is ≠0 otherwize Z|F.

We are free to rescale X, Y , Z and F. Then without loss of generality C is defined by

Y 2Z + a 1XY Z + a3Y Z2 = X3 + a 2XzZ + a 4XZ2 + a 6Z3.

Weierstrass form.

Substituting Y ← Y −1 2a1X −1 2a3Z, we may suppose a1 = a3 = 0. Now

Y 2Z = Z3f (X Z )

for some monic cubic polynomial f.

C is smooth, so f has distinct roots. Without loss of generality say 0,1,λ. Then C is given by

Y 2Z = X(X − Z)(X − λZ).□

Remark. It may be shown that the points of inflection on a smooth plane curve

C = {F(X1,X2,X3) = 0}⊂ ℙ2

are given by

F = det ⁡ ( ∂2F ∂Xi∂Xj )⏟ Hessian = 0,

2.1 The degree of a morphism

Let ϕ : C1 → C2 be a non-constant morphism of smooth projective curves.

Then ϕ∗ : K(C2) → K(C1), f↦f ∘ ϕ.

Definition (Degree of a morphism). deg⁡ϕ[K(C1) : ϕ∗K(C2)].

Definition (Separable morphism). ϕ is separable if K(C1)∕ϕ∗K(C2) is a separable field extension.

Definition (Ramification index). Suppose P ∈ C1, Q ∈ C2, ϕ : P↦Q. Let t ∈ K(C2) be a uniformiser at Q.

The ramification index of ϕ at P is

eϕ(P) = ord ⁡ P(ϕ∗t)

(always ≥ 1, independent of choice of t).

Theorem 2.8. Assuming that:

  • ϕ : C1 → C2 a non-constant morphism of smooth projective curves

Then
∑ P∈ϕ−1Qeϕ(P) = deg⁡ϕ∀ ⁡Q ∈ C2.

Moreover, if ϕ is separable then eϕ(P) = 1 for all but finitely many P ∈ C1. In particular:

  • (i) ϕ is surjective (on K¯-points)
  • (ii) #ϕ−1(Q) ≤deg⁡ϕ
  • (iii) If ϕ is separable then equality holds in (ii) for all but finitely many Q ∈ C2.

Remark 2.9. Let C be an algebraic curve. A rational map is given C −−→ ℙn, P↦(f0(P) : f1(P) : ⋯ : fn(P)) where f0,f1,…,fn ∈ K(C) are not all zero.

Important Fact: If C is smooth then ϕ is a morphism.

3 Weierstrass Equations

In this section, we drop the assumption that K = K¯, but we instead assume that K is a perfect field.

Definition (Elliptic curve). An elliptic curve E∕K is a smooth projective curve of genus 1, defined over K with a specified K-rational point 0E ∈ E(K).

Example. {X3 + pY 3 + p2Z3 = 0}⊂ ℙ2 is not an elliptic curve over ℚ, since it has no ℚ-rational points.

Theorem 3.1. Assuming that:

Then E is isomorphic over K to a curve in Weierstrass form via an isomorphism taking 0E to (0 : 1 : 0).

Remark. Proposition 2.7 treated the special case E is a smooth plane cubic and 0E is a point of inflection.

Fact: If D ∈ Div ⁡ (E) is defined over K (i.e. fixed by Gal ⁡ (K¯∕K)) then L(D) has a basis in K(E) (not just K¯(E)).

Proof of Theorem 3.1. L(2.0E) ⊂L(3.0E). Pick basis 1,x for L(2.0E) and 1,x,y for L(3.0E).

Note: ord ⁡ 0E(x) = −2, ord ⁡ 0E(y) = −3.

The 7 elements 1,x,y,x2,xy,x3,y2 in the 6-dimensional space L(6.0E) must satisfy a dependence relation.

Leaving out x3 or y2 gives a basis for L(6.0E) since each term has a different order pole at 0E.

Therefore the coefficients of x3 and y2 are non-zero. Rescaling x and y (if necessary) we get

y2 + a 1xy + a3y = x3 + a 2x2 + a 4x + a6

for some ai ∈ K.

Let E′ be the curve defined by this equation (or rather its projective closure). There is a morphism

ϕ : E → E′⊂ ℙ2 P ↦(x(P) : y(P) : 1) = (x y(P) : 1 : 1 y(P)) 0E ↦(0 : 1 : 0)

Then

[K(E) : K(x)] = deg⁡(E→xℙ1) = ord ⁡ 0E ( 1 x ) = 2[K(E) : K(y)] = deg⁡(E→yℙ1) = ord ⁡ 0E ( 1 y ) = 3

This gives us a diagram of field extensions:

           K (E)


           K (x,y)


K (x)                  K (y)
By the Tower Law (since 2,3 are coprime), we get that [K(E) : K(x,y)] = 1. Hence K(E) = K(x,y) = ϕ∗K(E′), so deg⁡ϕ = 1, so ϕ is birational.

If E′ is singular then E and E′ are rational, contradiction.

So E′ is smooth. Then Remark 2.9 implies that ϕ−1 is a morphism. So ϕ is an isomorphism. □

Proposition 3.2. Assuming that:

Then E≅E′ over K if and only if the equations are related by a change of variables x = u2x′ + r y = u3y′ + u2sx′ + t

where u,r,s,t ∈ K with u≠0.

Proof.

A Weierstrass form equation defines an elliptic curve if and only if it defines a smooth curve, which happens if and only if Δ(a1,…,a6)≠0, where Δ ∈ ℤ[a1,…,a6] is a certain polynomial.

If char ⁡ K≠2,3, we may reduce to the case E : y2 = x3 + ax + b, with discriminant Δ = −16(4a3 + 27b2).

Corollary 3.3. Assuming that:

  • char ⁡ K≠2,3 and K is perfect

  • elliptic curves E : y2 = x3 + ax + b, E′ : y2 = x3 + a′x + b′

Then E and E′ are isomorphic over K if and only if a′ = u4a, b′ = u6b for some u ∈ K∗.

Proof. E and E′ are related by a substitution as in Proposition 3.2 with r = s = t = 0. □

Definition (j-invariant). The j-invariant is

j(E) = 1728(4a3) 4a3 + 27b2.

Corollary 3.4. Assuming that:

  • E≅E′

Then j(E) = j(E′). Moreover, the converse holds if K = K¯.

Proof.

E≅E′ ⟺ { a′ = u4a b′ = u6b  for some u ∈ K∗ ⟹(a3 : b2) = ((a′)3 : (b′)2) ⟺j(E) = j(E′)

and the converse holds if K = K¯ (to go backwards on the ⟹ step, we only need to take some kind of n-th root). □

4 The Group Law

Let E ⊂ ℙ2 be a smooth plane cubic, and 0E ∈ E(K).

PIC

E meets any line in 3 points counted with multiplicity.

Let S be the third point of intersection of PQ with E, and R be the third intersection point of 0ES and E.

Define P ⊕ Q = R.

If PQ then take TPE instead of PQ etc.

This is called the “chord and tangent process”.

Theorem 4.1. (E,⊕) is an abelian group.

Note. E here means E(K¯). As mentioned before, we only ever mean “over K” if it is explicitly mentioned (otherwise we are always working “over K¯”).

Proof.

Definition (Linearly equivalent). D1,D2 ∈ Div ⁡ (E) are linearly equivalent if there exists f ∈K¯(E)∗ such that div ⁡ (f) = D1 − D2.

Write D1 ∼ D2 and [D] = {D′ : D′∼ D}.

Definition. Pic ⁡ (E) = Div ⁡ (E) ∼ , Pic ⁡ 0(E) = Div ⁡ 0(E) ∼. where Div ⁡ 0(E) = {D ∈ Div ⁡ E|deg⁡ ⁡ D = 0}.

Proposition 4.2. Assuming that:

  • we define

    ψ : E → Pic ⁡ 0(E) P ↦[(P) − (0E)]

Then
  • (i) ψ(P ⊕ Q) = ψ(P) + ψ(Q).
  • (ii) ψ is a bijection.

Proof.

Formulae for E in Weierstrass form
E : y2 + a 1xy + a3y = x3 + a 2x2 + a 4x + a6 (∗)

0E = (0 : 1 : 0).

PIC

P1 ⊕ P2 = P3. ⊖ P1 = (x1,−(a1x + a3) − y1).

Substituting y = λx + ν into (∗) and looking at coefficient of x2 gives

λ2 + a 1λ − a2 = x1 + x2 + x′⏟ =x3.

Therefore

x3 = λ2 + a 1λ − a2 − x1 − x2 y3 = −(a1x′ + a 3) − y′ = −(a1x3 + a3) − (λx3 + ν) = −(λ + a1)x3 − a3 − ν

It remains to find formulae for λ and ν.

Corollary 4.3. E(K) is an abelian group.

Proof. It is a subgroup of (E,⊕). Identity 0E ∈ E(K) by definition.

Closure / inverses: see formulae above.

Associative / commutative: inherited. □

Theorem 4.4. Elliptic curves are group varieties, i.e. [−1] : E → E; P↦ ⊖ P and ⊕ : E × E → E; (P,Q)↦P ⊕ Q are morphisms of algebraic varieties.

Proof.

Statement of Results

The isomorphisms in (i), (ii), (iv) respect the relevant topologies.

Brief remarks on the case K = ℂ

Let

Λ = {aω1 + bω2 : a,b ∈ ℤ},

where ω1,ω2 a basis for ℂ as an ℝ-vector space.

Then

{meromorphic functions on the Riemann surface ℂ∕Λ}↔{Λ-invariant meromorphic functions on ℂ}.

The function field of ℂ∕Λ is generated by

℘(z) = 1 z2 + ∑ 0≠λ∈Λ ( 1 (z − λ)2 − 1 λ2 ) ℘′(z) = −2∑ λ∈Λ 1 (z − λ)3

These satisfy

℘′(z)2 = 4℘(z)3 − g 2℘(z) − g3

for some g2,g3 ∈ ℂ depending only on Λ.

One shows ℂ∕Λ = E(ℂ) (isomorphism as groups and as Riemann surfaces) where E: y2 = 4x3 − g2x − g3.

Theorem (Uniformisation Theorem). Every elliptic curve over ℂ arises this way (one proof uses modular forms).

Definition. For n ∈ ℤ, let [n] : E → E be defined by

P↦P ⊕ P ⊕⋯ ⊕ P⏟ n copies

for n ≥ 0, and [−n] = [−1] ∘ [n].

Definition (n-torsion subgroup). The n-torsion subgroup of E is

E[n] = ker⁡(E→[n]E).

If K = ℂ then E(ℂ)≅ℂ∕Λ. Therefore

{ E[n]≅(ℤ∕nℤ)2 (1) deg⁡[n] = n2 (2)

We’ll show (2) holds over any field K, and (1) holds if char ⁡ K ∤ n.

Lemma 4.5. Assuming that:

  • char ⁡ K≠2

  • E: y2 = f(x) = (x − e1)(x − e2)(x − e3), e1,e2,e3 ∈K¯

Then E[2] = {0E,(e1,0),(e2,0),(e3,0)}≅(ℤ∕2ℤ)2.

Proof. Let P = (x,y) ∈ E. Then

[2]P = 0 ⟹P = −P ⟹(x,y) = (x,−y) ⟹y = 0□

5 Isogenies

Let E1,E2 be elliptic curves.

Definition (Isogeny). An isogeny ϕ : E1 → E2 is a nonconstant morphism with ϕ(0E1) = 0E2 (by Theorem 2.8, a morphism is nonconstant if and only if surjective on K¯-points).

We say E1 and E2 are isogenous in this case.

Definition. Hom ⁡ (E1,E2) = {isogenies E1 → E2}∪{0}.

This is an abelian group under

(ϕ + ψ)(P) = ϕ(P) + ψ(P).

If E1→ϕE2→ψE3 are isogenies then ψ ∘ ϕ is an isogeny.

Tower Law implies deg⁡(ψϕ) = deg⁡(ϕ)deg⁡(ψ).

Proposition 5.1. Assuming that:

  • 0≠n ∈ ℤ

Then [n] : E → E is an isogeny.

Proof. [n] is a morphism by Theorem 4.4. We must show [n]≠[0].

Assume char ⁡ K≠2.

Case n = 2: Lemma 4.5 implies E[2]≠E implies [2]≠[0].

Case n odd: Lemma 4.5 implies ∃ ⁡0≠T ∈ E[2]. Then nT = T≠0 which gives [n]≠[0].

Now use [mn] = [m] ∘ [n].

If char ⁡ K = 2, then could rpelace Lemma 4.5 with an explicit lemma about 3-torsion points. □

Corollary 5.2. Hom ⁡ (E1,E2) is a torsion free ℤ-module.

Theorem 5.3. Assuming that:

Then ϕ(P + Q) = ϕ(P) + ϕ(Q) for all P,Q ∈ E1.

Proof (sketch). ϕ incudes

ϕ∗ : Div ⁡ 0(E 1) → Div ⁡ 0(E 2) ∑ P∈E1nPP ↦∑ P∈E1nPϕ(P)

Recall ϕ∗ : K(E2)↪K(E1).

   K (E1)


normKm(aEp2)
Fact: If f ∈K¯(E1)∗ then

div ⁡ (NK(E1)∕K(E2)f) = ϕ∗(div ⁡ f).

So ϕ∗ sends principal divisors to principal divisors.

Since ϕ(0E1) = 0E2, the following diagram commutes:

      P              E1            E2             Q

                        0             0
ϕ∼=∼=ϕ∗    [(P )− (0E1)]    Pic (E1)      Pic(E2)        [(Q )− (0E2)]
ϕ∗ a group homomorphism implies ϕ is a group homomorphism. □

Lemma 5.4. Assuming that:

Then there exists a morphism ξ making the following diagram commute:
  E1      E2

ϕxxξ ℙ1      ℙ1
 12
(xi = x-coordinate on a Weierstrass equation for Ei). Moreover if ξ(t) = r(t) s(t), r,s ∈ K[t] coprime, then
deg⁡ϕ = deg⁡ξ = max ⁡ (deg⁡ ⁡ (r),deg⁡ ⁡ (s)).

Proof. For i = 1,2. K(Ei)∕K(xi) is a degree 2 Galois extension, with Galois group generated by [−1]∗.

Theorem 5.3 implies that ϕ ∘ [−1] = [−1] ∘ ϕ.

So if f ∈ K(x2) then

[−1]∗ϕ∗f = ϕ∗[−1]∗f = ϕ∗f.

Therefore ϕ∗f ∈ K(x1).

                    K (E1) = K (x1,y1)

   K (x1)


                    K (E2) = K (x2,y2)


2dd2eeggKϕξ (x2)
In particular, ϕ∗ = ξ(x1) for some rational function ξ.

Tower Law implies deg⁡ϕ = deg⁡ξ.

Now K(x2)↪K(x1), x2↦ξ(x1) = r(x1) s(x1), r,s ∈ K[t] coprime.

We claim the minimal polynomial of x1 over K(x2) is

F(t) = r(t) − s(t)x2 ∈ K(x2)[t].

Check:

Therefore

deg⁡ξ = [K(x1) : K(x2)] = deg⁡F = max ⁡ (deg⁡ ⁡ r,deg⁡ ⁡ s).□

Lemma 5.5. deg⁡[2] = 4.

Proof. Assume char ⁡ K≠2,3 (the result is true even in the case of char ⁡ K ∈{2,3}, but we will only prove the simpler case).

E: y2 = x3 + ax + b = f(x).

If P = (x,y) ∈ E, then

x(2P) = (3x2 + a 2y )2 − 2x = (3x2 + a)2 − 8xf(x) 4f(x) = x4 + ⋯ f(x)

The numerator and denominator are coprime. Indeed, otherwise there exists 𝜃 ∈K¯ with f(𝜃) = f′(𝜃) = 0 and hence f has a multiple root (contradiction).

Now Lemma 5.4 implies deg⁡[2] = max ⁡ (4,3) = 4. □

Definition (Quadratic form in an abelian group). Let A be an abelian group. We say q : A → ℤ is a quadratic form if

  • (i) q(nx) = n2q(x) for all n ∈ ℤ, x ∈ A.
  • (ii) (x,y)↦q(x + y) − q(x) − q(y) is ℤ-bilinear.

Lemma 5.6. q : A → ℤ is a quadratic form if and only if it satisfies the parallelogram law:

q(x + y) + q(x − y) = 2q(x) = 2q(y)∀ ⁡x,y ∈ A.

Proof.

Theorem 5.7. deg⁡ : Hom ⁡ (E1,E2) → ℤ is a quadratic form.

Note. We define deg⁡(0) = 0.

For the proof we assume char ⁡ K≠2,3. Write E2: y2 = x3 + ax + b.

Let P,Q ∈ E2 with P,Q,P + Q,P − Q≠0. Let x1,…,x4 be the x-coordinates of the 4 points.

Lemma 5.8. There exists W0,W1,W2 ∈ ℤ[a,b][x1,x2] of degree in x1 and of degree ≤ 2 in x2 such that

(1 : x3 + x4 : x3x4) = (W0 : W1 : W2).

Proof. Two methods.

We show that if ϕ,ψ ∈ Hom ⁡ (E1,E2), then

deg⁡(ϕ + ψ) + deg⁡(ϕ − ψ) ≤ 2deg⁡(ϕ) + 2deg⁡(ψ).

We may assume ϕ,ψ,ϕ + ψ,ϕ − ψ≠0 (otherwise trivial, or use deg⁡[−1] = 1, deg⁡[2] = 4).

ϕ : (x,y)↦(ξ1(x),…) ψ : (x,y)↦(ξ2(x),…) ϕ + ψ : (x,y)↦(ξ3(x),…) ϕ − ψ : (x,y)↦(ξ4(x),…)

Lemma 5.8 implies

(1 : ξ3 + ξ4 : ξ3ξ4) = ((ξ1 − ξ2)2 : ⋯).

Put ξi = ri s i, ri,si ∈ K[t] coprime.

(s3s4 : r3s4 + r4s4 : r3r4)⏟coprime = ((r1s2 − r2s1)2 : ⋯). (∗)

Therefore

deg⁡(ϕ + ψ) + deg⁡(ϕ − ψ) = max ⁡ (deg⁡ ⁡ (r3),deg⁡ ⁡ (s3)) + max ⁡ (deg⁡ ⁡ (r4),deg⁡ ⁡ (s4)) = max ⁡ (deg⁡ ⁡ (s3s4),deg⁡ ⁡ (r3s4 + r3s3),deg⁡ ⁡ (r3r4)) ≤ 2max ⁡ (deg⁡ ⁡ (r1),deg⁡ ⁡ (s1)) + 2max ⁡ (deg⁡ ⁡ (r2),deg⁡ ⁡ (s2)) = 2deg⁡(ϕ) + 2deg⁡(ψ) (1)

Now replace ϕ,ψ by ϕ + ψ,ϕ − ψ to get

deg⁡(2ϕ) + deg⁡(2ψ) ≤ 2deg⁡(ϕ + ψ) + 2deg⁡(ϕ − ψ) 4deg⁡(ϕ) + 4deg⁡(ψ) ≤ 2deg⁡(ϕ + ψ) + 2deg⁡(ϕ − ψ) 2deg⁡(ϕ) + 2deg⁡(ψ) ≤deg⁡(ϕ + ψ) + deg⁡(ϕ − ψ) (2)

(1) and (2) give that deg⁡ satisfies the parallelogram law, hence deg⁡ is a quadratic form.

This proves Theorem 5.7.

Corollary 5.9. deg⁡(nϕ) = n2 deg⁡(ϕ) for all n ∈ ℤ, ϕ ∈ Hom ⁡ (E1,E2). In particular, deg⁡[n] = n2.

Example 5.10. Let E∕K be an elliptic curve. Suppose char ⁡ K≠2. Let 0≠T ∈ E(K)[2].

Without loss of generality E: y2 = x(x2 + ax + b), a,b ∈ K, b(a2 − 4b)≠0, and T = (0,0).

If P = (x,y) and P′ = P + T = (x′,y′) then

x′ = (y x )2 − a − x = x2 + ax + b x − a − x = b x y′ = (y x )x′ = −by x

Let

ξ = x + x′ + a = (y x )2 η = y + y′ = y x (x − b x ) η2 = (y x )2 [(x + b x )2 − 4b] = ξ[(ξ − a)2 − 4b] = ξ(ξ2 − 2aξ + a2 − 4b)

Let E′: y2 = x(x2 + a′x + b′), where a′ = −2a, b′ = a2 − 4b. There is an isogeny

ϕ : E → E′ (x,y) ↦ ((y x )2 : y(x2 − b) x2 : 1)       − 2         − 3       0       ord ⁡ 0E(∙)          1           0       3        + 3 0E ↦(0 : 1 : 0) = 0E′

To compute the degree: (y x ) 2 = x2+ax+b x (coprime numerator and denominator as b≠0). Lemma 5.4 gives deg⁡ϕ = 2.

We say ϕ is a 2-isogeny.

6 The Invariant Differential

Let C be an algebraic curve over K = K¯.

Definition (Space of differentials). The space of differentials ΩC is the K(C)-vector space generated by df for f ∈ K(C), subject to the relations

  • (i) d(f + g) = df + dg
  • (ii) d(fg) = fdg + gdf
  • (iii) da = 0  ∀ ⁡a ∈ K

Fact: ΩC is a 1-dimensional K(C)-vector space.

Let 0≠ω ∈ΩC. Let P ∈ C be a smooth point, and t ∈ K(C) a uniformiser at P.

Then ω = fdt for some f ∈ K(C)∗. We define ord ⁡ p(ω) = ord ⁡ p(f) (independent of choice of t).

We assume C is a smooth projective curve.

Definition. div ⁡ (ω) = ∑ ⁡ P∈C ord ⁡ P(ω)P ∈ Div ⁡ (C).

Note. This is a divisor, i.e. ord ⁡ p(ω) = 0 for all but finitely many P ∈ C.

Definition (Regular differential). A differential ω ∈ΩC is regular if div ⁡ (ω) ≥ 0, i.e. it has no poles.

g(C) = dim⁡K{ω ∈ΩC : div ⁡ (ω) ≥ 0}.

As a consequence of Riemann-Roch we have:

If 0¬ ⁡ω ∈ΩC, then deg⁡(div ⁡ ω) = 2g − 2.

Fact: Suppose f ∈ K(C)∗, ord ⁡ p(f) = n≠0. If char ⁡ K ∤ n, then ord ⁡ p(df) = n − 1.

Lemma 6.1. Assuming that:

  • char ⁡ K≠2

  • E: y2 = (x − e1)(x − e2)(x − e3), e1,e2,e3 ∈ K distinct

Then ω = dx y is a differential on E with no zeroes or poles ⟹g(E) = 1. In particular, the K-vector space of regular differentials on E is 1-dimensional, spanned by ω.

Proof. Let Ti = (ei,0), E[2] = {0,T1,T2,T3}.

div ⁡ (y) = (T1) + (T2) + (T3) − 3(0). (1)

For P ∈ E ∖{0},

div ⁡ (x − xp) = (P) + (−P) − 2(0).

If P ∈ E ∖ E[2], then ord ⁡ p(x − xp) = 1⟹ord ⁡ p(dx) = 0.

If P ∈ E ∖ E[2] then ord ⁡ p(x − xp) = 1 ⟹ord ⁡ p(dx) = 0.

If P = Ti then ord ⁡ p(x − xp) = 2 ⟹ord ⁡ p(dx) = 1.

If P = 0 then ord ⁡ p(x) = −2 ⟹ord ⁡ p(dx) = −3.

Therefore

div ⁡ (dx) = (T1) + (T2) + (T3) − 3(0). (2)

(1) and (2) implies div ⁡ (dx y ) = 0. □

Definition. For ϕ : C1 → C2 a non-constant morphism we define

ϕ∗ : Ω C2 →ΩC1 fdg ↦(ϕ∗f)d(ϕ∗g)

Lemma 6.2. Assuming that:

  • P ∈ E,

    τP : E → E X ↦P + X

  • ω = dx y as above

Then τP∗ω = ω (we say ω is the invariant differential).

Proof. τP∗ω is a regular differential on E. So τP∗ω = λpω.

The map E → ℙ1, P↦λP is a morphism of smooth projective curves but not surjective (misses 0 and ∞). Therefore it is constant (by Theorem 2.8), i.e. there exists λ ∈ K∗ such that τP∗ω = λω for all P ∈ E.

Taking P = 0E shows λ = 1. □

Remark. If K = ℂ, ℂ∕Λ→∼E(ℂ), z↦(℘(z),℘′(z)),

d x y = ℘′(z)dz ℘′(z) = dz.

(invariant under z↦z + (const)).

Lemma 6.3. Assuming that:

  • ϕ,ψ ∈ Hom ⁡ (E1,E2)

  • ω an invariant differential on E2

Then (ϕ + ψ)∗ω = ϕ∗ω + ψ∗ω.

Proof. Write E = E2

E × E → E μ : (P,Q) ↦P + Q pr1 : (P,Q) ↦P pr2 : (P,Q) ↦Q

Fact: ΩE×E is a 2-dimensional K(E × E)-vector space with basis pr1∗ω and pr2∗ω.

Therefore

μ∗ω = fpr 1∗ω + gpr 2∗ω (1)

for some f,g ∈ K(E × E).

For fixed Q ∈ E, let

ιQ : E → E × E P ↦(P,Q)

Applying ιQ∗ to (1) gives

(μιQ)∗ω = (ιQ∗f)(pr 1ιQ)∗ω + (ι Q∗g)(pr 2ιQ)∗ω τQ∗ω⏟ =ω = (ιQ∗f)⏟ by Lemma 6.2ω + 0

Therefore ιQ∗f = 1 for all Q ∈ E, so f(P,Q) = 1 for all P,Q ∈ E.

Similarly g(P,Q) = 1 for all P,Q ∈ E.

(1) ⟹ μ∗ω = pr 1∗ω + pr 2∗ω.

Now pull back by

E1 → E × E P ↦(ϕ(P),ψ(P))

to get

(ϕ + ψ)∗ω = ϕ∗ω + ψ∗ω.□

Lemma 6.4. Assuming that:

  • ϕ : C1 → C2 a non-constant morphism

Then ϕ is separable if and only if ϕ∗ : ΩC1 →ΩC2 is non-zero

Proof. Omitted. □

Example. 𝔾m = 𝔸1 ∖{0} (multiplicative group).

ϕ : 𝔾m → 𝔾m x ↦xn

(n ≥ 2 integer).

ϕ∗(dx) = d(xn) = nxn−1dx. So if char ⁡ K ∤ n then ϕ is separable.

Theorem 2.8 implies #ϕ−1(Q) = deg⁡ϕ for all but finitely many Q ∈ 𝔾m.

But ϕ is a group homomorphism, so

#ϕ−1(Q) = #ker⁡(Q)

for all Q ∈ 𝔾m. Thus #ker⁡ϕ = deg⁡ϕ = n and hence K(= K¯) contains exactly n n-th roots of unity.

Theorem 6.5. Assuming that:

  • char ⁡ K ∤ n

Then E[n]≅(ℤ∕nℤ)2.

Proof. Lemma 6.3 + induction gives [n]∗ω = nω.

char ⁡ K ∤ n implies [n] is separable. So #[n]−1(Q) = deg⁡[n] for all but finitely many Q ∈ E. But [n] is a group homomorphism, so [n]−1(Q) = #E[n] for all Q ∈ E.

Putting these two statements together gives

#E[n] = deg⁡[n]=Corollary 5.9n2.

Group theory (structure theorem) gives that

E[n]≅ℤ∕d1ℤ ×⋯ × ℤ∕dtℤ

for some 1 < d1|d2|⋯|dt|n.

Let p be a prime with p|d1. Then E[p]≅(ℤ∕pℤ)t. But #E[p] = p2, so t = 2. But #E[p] = p2, so t = 2, i.e. E[n]≅ℤ∕d1ℤ × ℤ∕d2ℤ. Since d1|d2|n and d1d2 = n2, we get d1 = d2 = n.

Thus E[n]≅(ℤ∕nℤ)2. □

Remark. If char ⁡ K = p then [p] is inseparable. It can be shown that:

either E[pr] ≅ℤ∕prℤ ∀ ⁡r ≥ 1 “ordinary”or E[p] = 0 “supersingular”

Do not use this remark on Example Sheet 2!

7 Elliptic Curves over Finite Fields

Lemma 7.1. Assuming that:

  • A an abelian group

  • q : A → ℤ a positive definit quadratic form

Then
|q(x + y) − q(x) − q(y)⏟=⟨x,y⟩|≤ 2 q(x)q(y)∀ ⁡x,y ∈ A.

Proof. We may assume x≠0, otherwise the result is clear. So q(x)≠0.

Let m,n ∈ ℤ. Then

0 ≤ q(mx + ny) = 1 2⟨mx + ny,mx + ny⟩ = m2q(x) + mn⟨x,y⟩ + n2q(y) = q(x) (m + ⟨x,y⟩ 2q(x)n)2 + (q(y) −⟨x,y⟩2 4q(x) )n2

Take m = −⟨x,y⟩, n = 2q(x)≠0 to deduce

q(y) −⟨x,y⟩2 4q(x) ≥ 0

hence ⟨x,y⟩2 ≤ 4q(x)q(y) and hence

|⟨x,y⟩|≤ 2 q(x)q(y).
□

Theorem 7.2 (Hasse’s Theorem). Assuming that:

Then
|#E(𝔽q) − (q + 1)|≤ 2q.

Proof. Recall Gal ⁡ (𝔽qr∕𝔽q) is cyclic of order r and generated by Frobenius x↦xq.

Let E have Weierstrass equation with coefficients a1,…,a6 ∈ 𝔽q (so aiq = ai). Define the Frobenius endomorphism

ϕ : E → E (x,y) ↦(xq,yq)

This is an isogeny of degree q.

Then

E(𝔽q) = {P ∈ E|ϕ(P) = P} = ker⁡(1 − ϕ).

ϕ∗ω = ϕ∗(dx y ) = d(xq) yq = qxq−1dx yq = 0 (q ≡ 0(modp)) Lemma 6.3 tells us that
(1 − ϕ)∗ω = ω − ϕ∗(ω) = ω≠0.

Hence 1 − ϕ is separable.

By Theorem 2.8 and the fact that 1 − ϕ is a group homomorphism, we argue as in the proof of Theorem 6.5 that

#ker⁡ ⁡(1 − ϕ)⏟=#E(𝔽q) = deg⁡ ⁡(1 − ϕ).

deg⁡ : Hom ⁡ (E,E) → ℤ is a positive definite quadratic form (Theorem 5.7, and positive definiteness is obvious since non-constant morphisms have positive degree).

Lemma 7.1 gives

|deg⁡(1 − ϕ) − 1 −deg⁡ϕ|≤ 2 deg⁡ϕ.

Hence

|#E(𝔽q) − 1 − q|≤ 2q.□

Definition. For ϕ,ψ ∈ End ⁡ (E) = Hom ⁡ (E,E), we put ⟨ϕ,ψ⟩ = deg⁡(ϕ + ψ) −deg⁡ϕ −deg⁡ψ and tr ⁡ (ϕ) = ⟨ϕ,1⟩.

Corollary 7.3. Assuming that:

Then #E(𝔽q) = q + 1 −tr ⁡ (ϕ) and |tr ⁡ (ϕ)|≤ 2q.

7.1 Zeta functions

For K a number field, let

ζK(s) = ∑ 𝔞⊂OK 1 (N𝔞)s = ∏ 𝔭⊂OK prime (1 − 1 (N𝔭)s ) −1.

For K a function field, i.e. K = 𝔽q(C) where C∕𝔽q is a smooth projective curve,

ζK(s) = ∏ x∈|C|(1 − 1 (Nx)s ) −1,

where

|C| = {closed points on C}

(closed points are orbits for action of Gal ⁡ (𝔽q¯∕𝔽q) on C(𝔽q¯)) and Nx = qdeg⁡x, deg⁡x is the size of orbit.

We have ζK(s) = F(q−s) for some F ∈ ℚ[[T]],

F(T) = ∏ x∈|C|(1 − Tdeg⁡x)−1 log⁡F(T) = ∑ x∈|C|∑ m=1∞ 1 mTmdeg⁡x −log⁡(1 − x) = ∑ m=1∞xm m T d d T(log⁡F(T)) = ∑ x∈|C|∑ m=1∞deg⁡xTmdeg⁡x = ∑ n=1∞(∑ x∈|C| deg⁡x|n deg⁡x)Tn n = mdeg⁡x = ∑ n=1∞#C(𝔽 qn)Tn

Therefore

F(T) = exp⁡ (∑ n=1∞#C(𝔽qn) n Tn) .

Definition (Zeta function). The zeta function ZC(T) of a smooth projective curve C∕𝔽q is defined by

ZC(T) = exp⁡ (∑ n=1∞#C(𝔽qn) n Tn) .

Theorem 7.4. Assuming that:

Then
Z E (T) = 1 − aT + qT2 (1 − T)(1 − qT).

Proof. Let ϕ : E → E be the q power Frobenius map. By Corollary 7.3

#E(𝔽q) = q + 1 −tr ⁡ (ϕ).

Hence tr ⁡ (ϕ) = a, deg⁡(ϕ) = q.

Example Sheet 2, Q6(iii) implies ϕ2 − aϕ = q = 0, hence ϕn=2 − aϕn+1 + qϕn = 0, so

tr ⁡ (ϕn+2) − atr ⁡ (ϕn+1) + qtr ⁡ (ϕn) = 0.

This second order difference equation with initial conditions tr ⁡ (1) = 2, tr ⁡ (ϕ) = a has solution

tr ⁡ (ϕn) = αn + βn,

where α,β are roots of X2 − aX + q = 0.

Again by Corollary 7.3,

#E(𝔽qn) = qn + 1 −tr ⁡ (ϕn) = 1 + qn − αn − βn

Therefore

ZE(T) = exp⁡∑ n=1∞(Tn n + (qT)n n −(αT)n n −(βT)n n ) = (1 − αT)(1 − βT) (1 − T)(1 − qT) = 1 − aT + qT2 (1 − T)(1 − qT)□

Remark. Hasse’s Theorem tells us that |a|≤ 2q. α = β¯, and so |α| = |β| = q (∗).

Let K = 𝔽q(E). ζK(s) = 0, so ZE(q−s) = 0, so qs = α or β. Then qRe ⁡ (s) = |α| or |β|, so by (∗), Re ⁡ (s) = 1 2.

“This is an analog of the Riemann hypothesis.”

8 Formal Groups

Definition (I-adic topology). Let R be a ring and I ⊂ R an ideal. The I-adic topology on R has basis {r + In|r ∈ R,n ≥ 1}.

Definition (Cauchy sequence). A sequence (xn) in R is Cauchy if ∀ ⁡k,∃ ⁡N such that ∀ ⁡m,n ≥ N, xm − xn ∈ Ik.

Definition (Complete). R is complete if

  • (i) ⋂ ⁡ n≥0In = {0}
  • (ii) every Cauchy sequence converges

Useful remark: if x ∈ I then

1 1 − x = 1 + x + x2 + ⋯

so 1 − x ∈ R×.

Example. R = ℤp, I = pℤp.

R = ℤ[[t]], I = (t).

Lemma 8.1 (Hensel’s Lemma). Assuming that:

  • R is complete with respect to an ideal I

  • F ∈ R[X], s ≥ 1

  • a ∈ R satisfies F(a) ≡ 0(modIs), F′(a) ∈ R×

Then there exists a unique b ∈ R such that F(b) = 0 and b ≡ 0(modIs).

Proof. Let u ∈ R× with F(a) = u(modI) (e.g. we could take u = F′(a)). Replacing F(X) by F(X+a) u , we may assume a = 0, F′(0) ≡ 1(modI).

We put x0 = 0,

xn+1 = xn − F(xn) (1)

Easy induction gives

xn ≡ 0(modIs)∀ ⁡n (2)

Let

F(X) − F(Y ) = (X − Y )(F′(0) + XG(X,Y ) + Y H(X,Y )) (3)

for some G,H ∈ R[X,Y ].

Claim: xn+1 ≡ xn(modIn+s) for all n ≥ 0.

Proof: By induction on n. Case n = 0 is true.

Suppose xn ≡ xn=1(modIn+s−1). Then

F(xn) − F(xn−1) = (xn − xn−1)(1 + c)(modIn+s)

for some c ∈ I. Hence

F(xn) − F(xn−1) = xn − xn−1(modIn+s)

Hence

xn − F(xn) ≡ xn−1 − F(xn−1)(modIn+s)

and hence xn+1 ≡ xn(modIn+s).

This proves the claim.

Therefore (xn)n≥0 is Cauchy. Since R is complete, we have xn → b as n →∞ for some b ∈ R.

Taking limit n →∞ in (1) gives b = b − F(b), hence F(b) = 0.

Taking limit n →∞ in (2) gives b ≡ 0(modIs).

Uniqueness is proved using (3) and the “useful remark” (if x ∈ I then 1 − x ∈ R×). □

E : Y 2Z + a 1XY Z + a3Y Z2 = X3 + a 2X2Z + a 4XZ2 + a 6Z3.

Affine piece Y ≠0. t = −X Y , w = −Z Y .

w = t3 + a 1tw + a2t2w + a 3w2 + a 4tw2 + a 6w3⏟ =f(t,w).

We apply Lemma 8.1 with

R = ℤ[a1,…,a6][[t]] I = (t) F(X) = X − f(t,X) ∈ R[X]

s = 3, a = 0.

Check:

F(0) = −f(t,0) = −t3 ≡ 0(modI3) F′(0) = 1 − a1t − a2t2 ∈ R×

Hence there exists a unique w(t) ∈ R = ℤ[a1,…,a6][[t]] such that

w(t) = f(t,w(t)) w(t) ≡ 0(modt3)

Remark. Taking u = 1 in the proof of Lemma 8.1, w(t) = lim ⁡ n→∞wn(t) where w0(t) = 0, wn+1(t) = f(t,wn(t)).

In fact,

w(t) = t3(1 + A 1t + A2t2 + ⋯)

where A1 = a1, A2 = a12 + a2, A3 = a13 + 2a1a2 + 2a3, …

Lemma 8.2. Assuming that:

  • R an integral domain which is complete with respect to an ideal I

  • a1,…,a6 ∈ R

  • K = Frac ⁡ (R)

Then
Ê (I) := {(t,w) ∈ E(K)|t,w ∈ I}

is a subgroup of E(K).

Note. By uniqueness in Hensel’s lemma:

Ê (I) = {(t,w(t)) ∈ E(K)|t ∈ I}.

Proof. Taking (t,w) = (0,0) show 0E ∈Ê(I).

So it suffices to show that P1,P2 ∈Ê(I) then

−P1 − P2⏟ =P3 ∈Ê(I).

PIC

P1,P2 ∈Ê(I) implies t1,t2 ∈ I, w1 = w(t1) ∈ I, w2 = w(t2) ∈ I.

w(t) = ∑ n=2∞A n−2tn+1 (A0 = 1) λ = { w(t2)−w(t1) t2−t1 t1≠t2 w′(t1) t1 = t2 = ∑ n=2∞A n−2(t1n + t 1n−1t 2 + ⋯ + t2n) ∈ I ν = w1 − λt1 ∈ I

Substituting w = λt + ν into w = f(t,w) gives

λt + ν = t3 + a 1t(λt + ν) + a2t2(λt + ν) + a 3(λt + ν)2 + a 4t(λt + ν)2 + a 6(λt + ν)3 A = (coefficient of t3) = 1 + a2λ + a4λ2 + a 6λ3 B = (coefficient of t2) = a1λ + a2ν + a3λ2 + 2a 4λν + 3a6λ2ν

We have A ∈ R× and B ∈ I. Hence t3 = −B A − t1 − t2 ∈ I, w3 = λt3 + ν ∈ I. □

Taking R = ℤ[a1,…,a6][[t]], I = (t), then Lemma 8.2 gives that there exists ι ∈ ℤ[a1,…,a6][[t]] with ι(0) = 0 and

[−1](t,w(t)) = (ι(t),w(ι(t))).

Taking R = ℤ[a1,…,a6][[t1,t2]], I = (t1,t2), Lemma 8.2 gives that there exists F ∈ ℤ[a1,…,a6][[t1,t2]] with F(0,0) = 0 and

(t1,w(t1)) + (t2,w(t2)) = (F(t1,t2),w(F(t1,t2)))

and

F(X,Y ) = X + Y − a1XY − a2(X2Y + XY 2) + ⋯

By properties of the group law, we deduce

Definition (Formal group). Let R be a ring. A formal group over R is a power series F(X,Y ) ∈ R[[X,Y ]] satisfying

  • (i)
    F(X,Y ) = F(Y,X)
  • (ii)
    F(X,0) = X and F(0,Y ) = Y
  • (iii)
    F(X,F(Y,Z)) = F(F(X,Y ),Z)

This looks like it would only define a monoid, but in fact inverses are guaranteed to exist in this context.

Exercise: Show that for any formal group, there exists a unique

ι(X) = −X + ⋯ ∈ R[[X]]

such that F(X,ι(X)) = 0.

Example.

Definition (Morphism / isomorphic (formal groups)). Let F and G be formal groups over R given by power series F and G.

  • (i)
    A morphism f : F →G is a power series f ∈ R[[T]] such that f(0) = 0 satisfying
    f(F(X,Y )) = G(f(x),f(Y )).

  • (ii)
    F≅G if there exists F→fG and G→gF morphisms such that f(g(X)) = g(f(X)) = X.

Theorem 8.3 (All formal groups are isomorphic). Assuming that:

  • char ⁡ R = 0

Then any formal group F over R is isomorphic to 𝔾^a over R ⊗ ℚ. More precisely
  • (i)
    There is a unique power series
    log⁡(T) = T + a2 2 T2 + a3 3 T3 + ⋯

    with ai ∈ R such that

    log⁡(F(X,Y )) = log⁡(X) + log⁡(Y ). (∗)

  • (ii)
    There is a unique power series
    exp⁡(T) = T + b2 2! + b3 3! T3 + ⋯

    with bi ∈ R such that

    exp⁡(log⁡(T)) = log⁡(exp⁡(T)) = T.

Proof.

Lemma 8.4. Assuming that:

  • f(T) = aT + ⋯ ∈ R[[T]] with a ∈ R×

Then there exists a unique g(T) = a−1T + ⋯ ∈ R[[T]] such that f(g(T)) = g(f(T)) = T.

Proof. We construct polynomials gn(T) ∈ R[T] such that

f(gn(T)) ≡ T(modTn+1) gn+1(T) ≡ gn(T)(modTn+1)

Then g(T) = lim ⁡ n→∞gn(T) satisfies f(g(T)) = T.

To start the induction, we set g1(T) = a−1T. Now suppose n ≥ 2 and gn−1(T) exists. Then

f(gn−1(T)) ≡ T + bTn(modTn+1).

We put gn(T) = gn−1(T) + λTn for some λ ∈ R to be chosen later.

Then

f(gn(T)) = f(gn−1(T) + λTn) ≡ f(gn−1(T)) + λaTn(modTn+1) ≡ T + (b + λa)Tn(modTn+1)

We take λ = −b a (a ∈ R×,b ∈ R⟹λ ∈ R).

This completes the induction step.

We get g(T) = a−1T + ⋯ ∈ R[[T]] such that f(g(T)) = T. Applying the same construction to g gives h(T) = aT + ⋯ ∈ R[[T]] such that g(h(T)) = T.

Now note f(T) = f(g(h(T))) = h(T). □

Theorem 8.3(ii) now follows by Lemma 8.4 and Q12 from Example Sheet 2.

Notation. Let F (e.g. 𝔾^a, 𝔾^m, Ê) be a formal group given by a power series F ∈ R[[X,Y ]].

Suppose R is a ring complete with respect to ideal I. For x,y ∈ I, put

x ⊕Fy = F(x,y) ∈ I.

Then F(I) := (I,⊕F) is an abelian group.

Examples:

Corollary 8.5. Assuming that:

Then
  • (i) [n] : F →F is an isomorphism of formal groups
  • (ii) If R is complete with respect to ideal I then F(I)→×nF(I) is an isomorphism of groups. In particular, F(I) has no n-torsion.

Proof. We have

[1](T) = T [n](T) = F([n − 1](T),T)

(for n < 0 use [−1](T) = ι(T)).

Since

F(X,Y ) = X + Y + XY (⋯)

we get

[2](T) = F(T,T)2T + ⋯ ∈ R[[T]]

and by induction we get

[n](T) = nT + ⋯ ∈ R[[T]].

Lemma 8.4 shows that if n ∈ R× then [n] is an isomorphism. This proves (i), and (ii) follows. □

9 Elliptic Curves over Local Fields

Let K be a field, complete with respect to discrete valuation v : K∗→ ℤ.

Notation. Valuation ring (= ring of integers) will be denoted by

O K = {x ∈ K∗|v(x) ≥ 0}∪{0}.

Unit group will be denoted by

O K∗ = {x ∈ K∗|v(x) = 0}.

The maximal ideal will be denoted by πOK where v(π) = 1.

The residue field will be denoted by k = OK∕πOK.

We assume char ⁡ K = 0 and char ⁡ k = p > 0. For example, K = ℚp, OK = ℤp, k = 𝔽p.

Let E∕K be an elliptic curve.

Definition (Integral / minimal Weierstrass equation). A Weierstrass equation for E with coefficients a1,…,a6 ∈ K is integral if a1,…,a6 ∈OK and minimal if v(Δ) is minimal among all integral Weierstrass equations for E.

Remark.

Lemma 9.1. Assuming that:

Then either x,y ∈OK or
{ v(x) = −2s v(y) = −3s

for some s ≥ 1.

(Compare with Q5 from Example Sheet 1)

Proof. Throughout this proof, LHS and RHS refer to the Weierstrass equation of the curve.

Case v(x) ≥ 0:. If v(y) < 0 then v(LHS ⁡ ) < 0 and v(RHS ⁡ ) ≥ 0. Therefore x,y ∈OK.

Case v(x) < 0: v(LHS ⁡ ) ≥ min ⁡ (2v(y),v(x) + v(y),v(y)) and v(RHS ⁡ ) = 3v(x). We get 3 possible inequalities from this, and each of them gives v(y) < v(x).

Now

v(LHS ⁡ ) = 2v(y) v(RHS ⁡ ) = 3v(x)

so

{ v(x) = −2s v(y) = −3s

for some s ≥ 1. □

If K is complete, then OK is complete with respect to πrOK (for any r ≥ 1).

We fix a minimal Weierstrass equation for E∕K. Get formal group Ê over OK.

Taking I = πrOK (with r ≥ 1) in Lemma 8.2 gives

Ê(I) = {(x,y) ∈ E(K) |  −x y,−1 y ∈ πrO K} ∪{0} = {(x,y) ∈ E(K) | v (x y ) ≥ r,v (1 y ) ≥ r} ∪{0} = {(x,y) ∈ E(K)|v(x) = −2s,v(y) = −3s for s ≥ r}∪{0} (using Lemma 9.1) = {(x,y) ∈ E(K)|v(x) ≤−2r,v(y) ≤−3r}∪{0} (using Lemma 9.1)

By Lemma 8.2 this is a subgroup of E(K), say Er(K).

⋯ ⊂ E2(K) ⊂ E1(K) ⊂ E(K).

More generally, for F a formal group over OK

⋯ ⊂F(π2O K) ⊂F(πOK).

We claim that

Reminder: char ⁡ K = 0, char ⁡ k = p > 0.

Theorem 9.2. Assuming that:

  • K a local field with char ⁡ K = 0, char ⁡ k = p > 0

  • F a formal group over OK

  • e = v(p)

  • r > e p−1

Then
log⁡ : F(πrO K) →≅𝔾^a(πrO K)

is an isomorphism of groups with inverse

exp⁡ : 𝔾^a(πrO K) →≅F(πrO K).

Remark. 𝔾^a(πrOK) = (πrOK,+)≅(OK,+), x ↔ π−rx.

Proof. For x ∈ πrOK we must show the power series log⁡(x) and exp⁡(x) converge to elements in πrOK.

Recall

exp⁡(T) = T + b2 2! T2 + b3 3! T3 + ⋯

for some bi ∈OK.

Claim: vp(n!) ≤ n−1 p−1 .

Proof of claim:

vp(n!) = ∑ r=1∞⌊n pr ⌋ < ∑ r=1∞n pr = n ⋅1 p 1 −1 p = n p − 1.

Therefore

(p − 1)vp(n!) < n (p − 1)vp(n!) ≤ n − 1

(we go from < to ≤∙− 1 by noting that the LHS is in ℤ).

This proves the claim.

Now

v (bnxn n! ) ≥ nr − e (n − 1 p − 1 ) = (n − 1) (r − e p − 1 )⏟>0 + r

This is always ≥ r and →∞ as n →∞. Therefore exp⁡(x) converges to an element in πrOK.

Same method works for log⁡. □

Lemma 9.3. F(πrO K) F (πr+1OK)≅ (k,+) for all r ≥ 1.

Proof. Definition of formal group gives

F(X,Y ) = X + Y + XY (⋯).

So if x,y ∈OK,

F(πrx,πry) ≡ πr(x + y)(modπr+1).

Therefore

F(πrO K) → (k,+) πrx ↦x mod π

is a surjective group homomorphism with kernel F(πr+1OK). □

Corollary. Assuming that:

  • |k| < ∞

Then F(πOK) has a subgroup of finite index isomorphic to (OK,+).

Notation. Reduction modulo π

OK → OK πOK = k x ↦x~

Proposition 9.4. Assuming that:

Then the reduction mod π of any two minimal Weierstrass equations for E define isomorphic curves over k.

Proof. Say Weierstrass equations are related by [u;r,s,t], u ∈ K∗, r,s,t ∈ K. Then Δ1 = u12Δ2. Both equations minimal gives us that v(Δ1) = v(Δ2), hence u ∈OK∗.

Transformation formula for the ai and bi + OK is integrally closed, hence r,s,t ∈OK.

The Weierstrass equations obtained by reducing mod π are now related by [ũ;r~,s~,t~], ũ ∈ k∗, r~,s~,t~ ∈ k. □

Definition. The reduction Ẽ∕k of E∕K is defined by the reduction of a minimal Weierstrass equation.

E has good reduction if Ẽ is non-singular (and so an elliptic curve) otherwise has bad reduction.

For an integral Weierstrass equation,

  • If v(Δ) = 0 then good reduction.

  • If 0 < v(Δ) < 12 then bad reduction.

  • If v(Δ) ≥ 12 then beware that the equation might not be minimal.

There is a well-defined map

ℙ2(K) → ℙ2(k) (x : y : z) ↦(x~ : ỹ : z~)

(choose a representative with min ⁡ (v(x),v(y),v(z)) = 0).

We restrict to give

E(K) →Ẽ(K) P ↦P~

If P = (x,y) ∈ E(K) then by Lemma 9.1 either

Therefore

E1(K) = Ididn′tmanagetowritethisbeforeitwasrubbedoff

“kernel of reduction”.

Notation.

{ Ẽ if E has good reduction Ẽ ∖{singular point}if E has bad reduction

The chord and tangent process still defines a group law on Ẽns.

In cases of bad reduction, Ẽns≅𝔾m (over k or possibly a quadratic extension of k) or Ẽns≅𝔾a (over k).

For simplicity we suppose char ⁡ k≠2.

Then Ẽ = y2 = f(x), deg⁡f = 3.

PIC

Ẽns →≅𝔾a (x,y) ↦x y (t−2,t−3) ←↤ t (point at ∞) ←↤ 0 Let P1,P2,P3 lie on the line ax + by = 1. Write Pi = (xi,yi), ti = xi y i. Then xi3 = yi2 = yi2(axi + byi). So ti3 − ati − b = 0. So t1,t2,t3 are the roots of T3 − aT − b = 0.

Looking at coefficient of T2 gives t1 + t2 + t3 = 0.

Definition (E0(K)). E0(K) = {P ∈ E(K)|P~ ∈Ẽns(k)}.

Proposition 9.5. E0(K) is a subgroup of E(K) and reduction modulo π is a surjective group homomorphism E0(K) →Ẽns(k).

Note. If E∕K has good reduction, then this is a surjective group homomorphism E(K) →Ẽ(k).

Proof. Group homomorphism: A line l in ℙ2 defined over K has equation

l : aX + bY + cZ = 0a,b,c ∈ K.

We may assume min ⁡ (v(a),v(b),v(c)) = 0. Reduction modulo π gives a line

l~ : ãX + b~Y + c~Z = 0.

If P1,P2,P3 ∈ E(K) with P1 + P2 + P3 = 0 then these points lie on a line l. So P~1,P~2,P~3 lie on the line l~. If P~1,P~2 ∈(~nsk) then P~3 ∈(~nsk).

So if P1,P2 ∈ E0(K) then P3 ∈ E0(K) and P~1 + P~2 + P~3 = 0.

[Exercise: check this still works if #{P~1,P~2,P~3} < ∞]

Surjective: Let f(x,y) = y2 + a1xy + a3y − (x3 + ⋯). Let P~ ∈Ẽns(k) ∖{0}, say P~ = (x~0,ỹ0) for some x0,y0 ∈OK.

Since P~ non-singular, either:

If (i) then put g(t) = f(t,y0) ∈OK[t]. Then

{ g(x0) ≡ 0 (modπ) g′(x0) ∈OK∗

Hensel’s lemma gives us that there exists b ∈OK such that

{ g(b) = 0 b ≡ x0(modπ)

Then (b,y0) ∈ E(K) has erduction P~. asdfadsf □

Recall that for r ≥ 1 we put

Er(K) = {(x,y)|v(x) ≤−2r,v(y) ≤−3r}∪{0}.

If r > e p−1, these give:

Er(K)⏟≅ ⁡(OK,+) ⊂⋯ ⊂ E2(K)⏟=Ê(π2OK) ⊂ E1(K)⏟=Ê(πOK) ⊂ E0(K) ⊂ E(K),

where for i ≥ 1, each Ei+1(K) ⊂ Ei(K) gives a quotient isomorphic to (k,+).

We have E0(K) E1(K)≅Ẽns(k).

What about E(K) E0(K)?

Lemma 9.6. Assuming that:

  • |k| < ∞

Then E0(K) ⊂ E(K) has finite index.

Proof. |k| < ∞ implies that OK πr O K is finite for all r ≥ 1.

Hence

O K ≅ lim ⁡ r []← O K πrOK

is a profinite group, hence compact.

Then ℙn(K) is the union of sets

{(a0 : ⋯ : ai−1 : 1 : ai+1 : ⋯ : an) : aj ∈OK}

and hence compact (for the π-adic topology).

Now note E(K) ⊂ ℙ2(K) is a closed subset, hence compact.

So E(K) is a compact topological group.

If Ẽ has a singular point (x~0,ỹ0) then

E(K) ∖ E0(K) = {(x,y) ∈ E(K)|v(x − x0) ≥ 1,v(y − y0) ≥ 1}

is a closed subset of E(K) hence E0(K) is an open subgroup of E(K).

The cosets of E0(K) are an open cover of E(K). Hence [E(K) : E0(K)] < ∞. □

Definition (Tamagawa number). cK(E) = [E(K) : E0(K)] is called the Tamagawa number.

Remark.

We deduce:

Theorem 9.7. Assuming that:

  • [K : ℚp] < ∞

Then E(K) contains a subgroup of finite index isomorphic to (OK,+).

Let [K : ℚp] < ∞ and L∕K a finite extension. Let the residue fields be k′ and k, and let f = [k′ : k].

    ∗
   K       ℤ

V⊂×Ve L∗      ℤ
 KL

Facts:

Definition (Unramified). L∕K is unramified if e = 1.

Fact: For each m ≥ 1

These extensions are Galois, with cyclic Galois groups.

Definition (Maximal unramified extension). Knr = ⋃ ⁡ m≥1Km (inside K¯). “maximal unramified extension”

Theorem 9.8. Assuming that:

Then K([n]−1P)∕K is unramified.

Notation.

[n]−1(P) = {Q ∈ E(K¯) : nQ = P},
K({Q1,…,Qr}) = K(x1,…,xr,y1,…,yr),

where Qi = (xi,yi).

Proof. For each m ≥ 1 there is a short exact sequence

0 → E1(Km) → E(Km) →Ẽ(Km) → 0.

Taking ⋃ ⁡ m≥1 gives a commutative diagram with exact rows:

                                     --
0          E1(Knr)     E (Knr)     ˜E(k)    0


0          E1(Knr)     E (Knr)     ˜E(k)    0

PIC

An isomorphism by Corollary 8.5 applied over each Km (using p ∤ n here).

Snake lemma gives

{ E(Knr)[n]≅(ℤ∕nℤ)2 E(Knr) nE(Knr) = 0

So if P ∈ E(K) then there exists Q ∈ E(Knr) such that nQ = P and

[n]−1P = {Q + T : T ∈ E[n]}⊂ E(Knr).

Hence K([n]−1P) ⊂ Knr and so K([n]−1P)∕K is unramified. □

10 Elliptic Curves over Number Fields: The torsion subgroup

[K : ℚ] < ∞, E∕K an elliptic curve.

Notation. 𝔭 a prime of K (i.e. a prime) ideal in OK).

K𝔭 is the 𝔭-adic completion of K, valuation ring O𝔭.

k𝔭 = OK∕𝔭 residue field.

Definition (Good reduction (prime)). 𝔭 is a prime of good reduction for E∕K if E∕K𝔭 has good reduction.

Lemma 10.1. E∕K has only finitely many primes of bad reduction.

Proof. Take a Weierstrass equation for E with a1,…,a6 ∈OK. E non-singular implies that 0≠Δ ∈OK.

Write (Δ) = 𝔭α1⋯𝔭rαr (factorisation into prime ideals).

Let S = {𝔭1,…,𝔭r}. If 𝔭∉S then v𝔭(Δ) = 0. Hence E∕K𝔭 has good reduction.

Therefore {bad primes for E}⊂ S, hence is finite. □

Remark. If K has class number 1 (e.g. K = ℚ) then we can always find a Weierstrass equation for E with a1,…,a6 ∈OK which is minimal at all primes 𝔭.

Basic group theory: If A is a finitely generatead abelian group then A≅{finite group}× ℤr. We call r the “rank”, and {finite subgroup} is the torsion subgroup.

Lemma 10.2. E(K)tors is finite.

Proof. Take any prime 𝔭. We saw that E(K𝔭) has a finite index subgroup A (say) with A≅(O𝔭,+).

In particular, A is torsion free

E(K)tors↪E(K𝔭)tors↪ E(K𝔭) A⏟ finite.□

Lemma 10.3. Assuming that:

Then reduction modulo 𝔭 gives an injective group homomorphism
E(K)[n]↪Ẽ(k𝔭).

Proof. Proposition 9.5 gives that E(K𝔭) →Ẽ(k𝔭) is a group homomorphism, with kernel E1(K𝔭).

Corollary 8.5 and 𝔭 ∤ n gives that E1(K𝔭) has no n-torsion. □

Example. E∕ℚ: y2 + y = x3 − x, Δ = −11.

E has good reduction at all p≠11.

p 2 3 5 7 11 13







#Ẽ(𝔽p) 5 5 5 5 − 10

Lemma 10.3 gives:

{ #(ℚ)tors|5 ⋅ 2a for some a ≥ 0 #E(ℚ)tors|5 ⋅ 3bfor some b ≥ 0

Hence #(ℚ)tors|5.

Let T = (0,0) ∈ E(ℚ). Calculation gives 5T = 0. Therefore E(ℚ)tors≅ℤ∕5ℤ.

Example. E∕ℚ: y2 + y = x3 + x2, Δ = −43

p 2 3 5 7 11 13







#Ẽ(𝔽p) 5 6 10 8 9 19

Lemma 10.3 gives:

{ #E(ℚ)tors|5 ⋅ 2a for some a ≥ 0 #E(ℚ)tors|9 ⋅ 11bfor some b ≥ 0

Therefore E(ℚ)tors = {0}.

Therefore P = (0,0) is a point of infinite order.

In particular, E(ℚ) is infinite.

Example. ED: y2 = x3 − D2x = f(x). D ∈ ℤ square-free, Δ = 26D6. If p ∤ 2D, then

#ẼD(𝔽p) = 1 + ∑ x∈𝔽p (( f(x) p ) + 1).

If p ≡ 3(mod4) then since f is odd,

(f(−x) p ) = ( − f(x) p ) = ( − 1 p ) (f(x) p ) = −(f(x) p ).

Hence

#ẼD(𝔽p) = p + 1.
ED(ℚ)tors ⊃{0,(0,0),(±D,0)}≅(ℤ∕2ℤ)2.

Let m = #ED(ℚ)tors.

We have 4|m|p + 1 forr all sufficiently large (p ∤ 2mD) primes p with p ≡ 3(mod4). Hence m = 4 (otherwise get contradiction to Dirichlet’s theorem on primes on arithmetic progressions).

So

rank ⁡ ED(ℚ) ≥ 1 ⟺∃ ⁡x,y ∈ ℚ,y≠0 ∧ y2 = x3 − D2x ⟺Lecture 1D is a congruent number

Lemma 10.4. Assuming that:

Then
  • (i) 4x,8y ∈ ℤ
  • (ii) If 2|a1 or 2T≠0 then x,y ∈ ℤ

Proof.

Example. y2 + xy = x3 + 4x + 1, (−1 4, 1 8 ) ∈ E(ℚ)[2].

Theorem 10.5 (Lutz Nagell). Assuming that:

  • E∕ℚ: y2 = x3 + ax + b, a,b ∈ ℤ

  • 0≠T = (x,y) ∈ E(ℚ)tors

Then x,y ∈ ℤ and either y = 0 or y2|(4a3 + 27b2).

Proof. Lemma 10.4 gives that x,y ∈ ℤ.

If 2T = 0 then y = 0. Otherwise 0≠2T = (x2,y2) ∈ E(ℚ)tors.

Lemma 10.4 gives x2,y2 ∈ ℤ. But

x2 = (f′(x) 2y )2 − 2x

hence y|f′(x).

E non-singular gives that f(X) adn f′(X) are coprime, so f(X) and f′(X)2 are coprime. Therefore there exists g,h ∈ ℚ[X] satisfying

g(X)f(X) + h(X)f′(X)2 = 1.

Doing this and clearing denominators gives

(3X2 + 4a)f′(X)2 − 27(X3 + aX − b)f(X) = 4a3 + 27b2.

Since y|f′(x) and y2 = f(x), we get y2|(4a3 + 27b2). □

Remark. Mazur showed that if E∕ℚ is an elliptic curve then

E(ℚ)tors≅ { ℤ∕nℤ 1 ≤ n ≤ 12,n≠11 ℤ∕2ℤ × ℤ∕2nℤ1 ≤ n ≤ 4

Moreover, all 15 possibilities occur.

11 Kummer Theory

Let K be a field and char ⁡ K ∤ n. Assume μn ⊂ K.

Lemma 11.1. Assuming that:

  • Δ ⊂ K∗∕(K∗)n a finite subgroup

  • L = K(Δn)

Then L∕K is Galois and Gal ⁡ (L∕K)≅ ⁡ Hom ⁡ (Δ,μn).

Proof. μn ⊂ K gives L∕K normal, and char ⁡ K ∤ n gives that L∕K is separable. So L∕K is Galois.

Define the Kummer pairing

⟨,⟩ : Gal ⁡ (L∕K) ×Δ → μn (σ,x) ↦σ(xn) x n

Well-defined: Suppose α,β ∈ L with αn = βn = x. Then (α β ) n = 1, so α β ∈ μn ⊂ K. Then σ (α β ) = α β for all σ ∈ Gal ⁡ (L∕K), hence σ(α) α = σ(β) β for all σ ∈ Gal ⁡ (L∕K).

Bilinear:

⟨στ,x⟩ = σ(τxn) τxn τxn x n = ⟨σ,x⟩⟨τ,x⟩ ⟨σ,xy⟩ = σxyn xy n = σxn x n σyn y n = ⟨σ,x⟩⟨σ,y⟩

Non-degenerate: Let σ ∈ Gal ⁡ (L∕K). If ⟨σ,x⟩ = 1 for all x ∈Δ, then

σxn = xn∀ ⁡x ∈Δ

adn hence σ fixes L pointwise, i.e. σ = 1.

Let x(K∗)n ∈Δ. If ⟨σ,x⟩ = 1 for all σ ∈ Gal ⁡ (L∕K), then

σxn = xn∀ ⁡σ ∈ Gal ⁡ (L∕K).

So xn ∈ K, so x ∈ (K∗)n, i.e. x(K∗)n ∈Δ is the identity element.

We get injective group homomorphisms

(i) implies Gal ⁡ (L∕K) is abelian and of exponent dividing n.

Fact: If G is a finite abelian group of exponent dividing n then Hom ⁡ (G,μn)≅ ⁡ G (non canonically).

So

|Gal ⁡ (L∕K)|≤(i)|Δ|≤(ii)|Gal ⁡ (L∕K)|.

Therefore (i) and (ii) are isomorphisms. □

Example. Gal ⁡ (ℚ( 2, 3, 5)∕ℚ)≅ ⁡ (ℤ∕2ℤ)3.

Definition (Abelian extension). We say L∕K is abelian if it is Galois, and has abelian Galois group.

Similarly for other group terminology (e.g. we can say that L∕K has exponent dividing n to mean that it is Galois, with Galois group having exponent dividing n).

Theorem 11.2. There is a bijection

{finite subgroups Δ⊂K∗∕(K∗)n } ↔ {finite abelian extension L∕K of exponent dividing n } Δ ↦K(Δn) (L∗)n ∩ K∗ (K∗)n ←↤ L

Proof.

Proposition 11.3. Assuming: - K a number field - μn ⊂ K - S a finite set of promes of K Then there are only finitely many extensions L∕K such that

  • (i) L∕K is a finite abelian extension of exponent dividing n
  • (ii) L∕K is unramified at all 𝔭∉S

Proof. Theorem 11.2 gives L = K(Δn) for some Δ ⊂ K∗∕(K∗)n a finite subgroup.

Let 𝔭 be a prime of K.

𝔭OL = P1e1 ⋯Prer

for P1,…,Pr some distinct primes in OL.

If x ∈ K∗ represents an element of Δ then

nvPi(xn) = vPi(x) = eiv𝔭(x).

If 𝔭∉S then all ei = 1, so v𝔭(x) ≡ 0(modn). Therefore Δ ⊂ K(S,n) where

K(S,n) = {x ∈ K∗∕(K∗)n|v𝔭(x) ≡ 0(modn) ∀ ⁡𝔭∉S}.

The proof is completed by the next lemma. □

Lemma 11.4. K(S,n) is finite.

Proof. The map

K(S,n) → (ℤ∕nℤ)|S| x ↦(v𝔭(x)(modn))𝔭∈S

is a group homomorphism with kernel K(∅,n).

Since |S| < ∞, it suffices to prove the lemma with S = ∅.

If x ∈ K∗ represents an element of K(∅,n) then (x) = 𝔞n for some fractional ideal 𝔞. There is a short exact sequence

0 →OK∗∕(O K∗)n → K(∅,n) → Cl ⁡ K → 0 x(K∗)n ↦[𝔞]

|Cl ⁡ K| < ∞ and OK∗ being a finitely generated abelian group (Dirichlet’s unit theorem) gives us that K(ϕ,n) is finite. □

12 Elliptic Curves over Number Fields: The weak Mordell-Weil Theorem

Theorem 12.1. Assuming that:

Then the natural map E(K) nE(K) → E(L) nE(L) has finite kernel.

Proof. For each element in the kernel we pick a coset representative P ∈ E(K) and then Q ∈ E(L) such that nQ = P.

For any σ ∈ Gal ⁡ (L∕K) we have

n(σQ − Q) = σP − P = 0.

So σQ − Q ∈ E[n].

Since Gal ⁡ (L∕K) and E[n] are finite, there are only finitely many possibilities for the map

Gal ⁡ (L∕K) → E[n] σ ↦σQ − Q

(even without requiring it to be a group homomorphism!).

So we have a map

ker⁡ ( E(K) nE(K) → E(L) nE(L) ) →(∗)Maps ⁡ (Gal ⁡ (L∕L),E[n]) P + nE(K) ↦(σ↦σQ − Q) where nQ = P

It remains to show (∗) is injective.

So suppose P1,P2 ∈ E(K), Pi = nQi for i = 1,2, and suppose σQ1 − Q1 = σQ2 − Q2 for all σ ∈ Gal ⁡ (L∕K). Then σ(Q1 − Q2) = Q1 − Q2 for all σ ∈ Gal ⁡ (L∕K), hence Q1 − Q2 ∈ E(K), so P1 − P2 ∈ nE(K). Hence P1 + nE(K) = P2 + nE(K) as desired. □

Theorem (Weak Mordell-Weil Theorem). Assuming that:

Then E(K) nE(K) is finite.

Proof. Theorem 12.1 tells us that we may replace K by a finite Galois extension.

So without loss of generality μn ⊂ K and E[n] ⊂ E(K). Let

S = {𝔭|n}∪{primes of bad reduction for E∕K}.

For each P ∈ E(K), the extension K([n]−1P)∕K is unramified outisde S by Theorem 9.8. Since Gal ⁡ (K¯∕K) acts on [n]−1P, it follows that Gal ⁡ (K¯∕K([n]−1P)) is a normal subgroup of Gal ⁡ (K¯∕K) and hence K([n]−1P)∕K is a Galois extension.

Let Q ∈ [n]−1P. Since E[n] ⊂ E(K), we have K(Q) = K([n]−1P). Consider

Gal ⁡ (K(Q)∕K) → E[n]≅(ℤ∕nℤ)2 σ ↦σQ − Q

Group homomorphism: στQ − Q = σ(τQ − Q) + (σQ − Q).

Injective: If σQ = Q then σ fixes K(Q) pointwise, i.e. σ = 1.

Therefore K(Q)∕K is an abelian extension of exponent n, unramified outside S.

Proposition 11.3 shows that as we vary P ∈ E(K) there are only finitely many possibilities for K(Q).

Let L be the composite of all such extensions of K. Then L∕K is finite and Galois, and E(K) nE(K) → E(L) nE(L) is the zero map. Theorem 12.1 gives | E(K) nE(K) | < ∞. □

Remark. If K = ℝ or ℂ, or [K : ℚp] < ∞ then | E(K) nE(K) | < ∞, yet E(K) is uncountable, so not finitely generated.

Fact: If K is a number field, then there exists a quadratic form (= canonical height) ĥ : E(K) → ℝ≥0 with the property that for any B ≥ 0,

{P ∈ E(K)|ĥ(P) ≤ B} (∗)

is finite.

Theorem (Mordell-Weil Theorem). Assuming that:

Then E(K) is a finitely generated abelian group.

Proof. Fix an integer n ≥ 2.

Weak Mordell-Weil Theorem implies that | E(K) nE(K) | ∞. Pick coset representatives P1,P2,…,Pm. Let

Σ = {P ∈ E(K)|(P)^ ≤ max ⁡ 1≤i≤mĥ(Pi)}.

Claim: Σ generates E(K).

If not, then there exists P ∈ E(K) ∖ (subgroup generated by Σ) of minimal height (exists by (∗)). Then P = Pi + nQ for some i and Q ∈ E(K). Note that Q ∈ E(K) ∖ (subgroup generated by Σ).

Minimal choice of P gives

4ĥ(P) ≤ 4ĥ(Q) ≤ n2ĥ(Q) = ĥ(nQ) = ĥ(P − Pi) ≤ĥ(P − Pi) + ĥ(P + Pi) = 2ĥ(P) + 2ĥ(Pi) parallelogram law

Therefore ĥ(P) ≤ĥ(Pi). Hence P ∈Σ (by definition of Σ), which contradicts the choice of P.

This proves the claim.

By (∗), Σ is finite. □

13 Heights

For simplicity, take K = ℚ. Write P ∈ ℙn(Q) as P = (a0 : a1 : ⋯ : an) where a0,…,an ∈ ℤ and gcd ⁡ (a0,an) = 1.

Definition (Height of a point). H(P) = max ⁡ 0≤i≤n|ai|.

Lemma 13.1. Assuming that:

  • f1,f2 ∈ ℚ[X1,X2] coprime homogeneous polynomials of degree d

  • let

    F : ℙ1 → ℙ1 (x1 : x2) ↦(f1(x1,x2) : f2(x1,x2))

Then there exist c1,c2 > 0 such that for all P ∈ ℙ1(ℚ),
c1H(P)d ≤H(F(P)) ≤ c 2H(P)d.

Proof. Without loss of generality f1,f2 ∈ ℤ[X1,X2].

Upper bound: Write P = (a1 : a2), a1,a2 ∈ ℤ coprime.

H(F(P)) ≤ max ⁡ (|f1(a1,a2)|,|f2(a1,a2)|) ≤ c2 max ⁡ (|a1|d,|a 2|d)

where

c2 = max ⁡ i=1,2(sum of absolute values of coefficients of fi).

Therefore H(F(P)) ≤ c2H(P)d.

Lower bound: We claim that there exists gij ∈ ℤ[X1,X2] homogeneous of degree d − 1 and κ ∈ ℤ>0 such that

∑ j=12g ijfj = κXi2d−1,i = 1,2. (†)

Indeed, running Euclid’s algorithm on f1(X,1) and f2(X,1) gives r,s ∈ ℚ[X] of degree < d such that

r(X)f1(X,1) + s(X)f2(X,1) = 1.

Homogenising and clearing denominators gives (†) for i = 2. Likewise for i = 1.

Write P = (a1 : a2) with a1,a2 ∈ ℤ coprime. (†) gives

∑ j=12g ij(a1,a2)fj(a1,a2) = κai2d−1,i = 1,2.

Therefore gcd ⁡ (f1(a1,a2),f2(a1,a2)) divides gcd ⁡ (κa12d−1,κa22d−1) = κ.

|κai2d−1|≤ max ⁡ j=1,2 |fj(a1,a2)|⏟≤κH(F(P)) ∑ j=12|g ij(a1,a2)|⏟≤γiH(D)d−1

where

γi = ∑ j=12(sum of absolute values of coefficients of g ij).

Therefore

κ|ai|2d−1 ≤ κH(F(P))γ iH(P)d−1

so

H (P)2d−1 ≤ max ⁡ (γ 1,γ2)H(F(P))H(P)d−1

so

1 max ⁡ (γ1,γ2)⏟ =c1H(P)d ≤H(F(P)).□

Notation. For x ∈ ℚ, H(X) = H((x : 1)) = max ⁡ (|u|,|v|), where x = u v, u,v ∈ ℤ coprime.

Definition (Height of a point). Let E∕ℚ be an elliptic curve, y2 = x3 + ax + b.

Define the height

H : E(ℚ) → ℝ≥1 P ↦ { H(x) if P = (x,y) 1 if P = 0E

Alsdefine logarithmic height

h : E(ℚ) → ℝ≥0 P ↦log⁡H(P)

Lemma 13.2. Assuming that:

Then there exists c > 0 such that
|h(ϕ(P)) − (deg⁡ϕ)h(P)|≤ c∀ ⁡P ∈ E(ℚ).

Note. c depends on E and E′, but not P.

Proof. Recall (Lemma 5.4)

  E       E ′


ϕxxξ ℙ1      ℙ1
deg⁡ϕ = deg⁡ξ ( = d say). Lemma 13.1 tells us that there exists c1,c2 > 0 such that

c1H(P)d ≤H(ϕ(P)) ≤ c 2H(P)d∀ ⁡P ∈ E(ℚ).

Taking logs gives

|h(ϕ(P)) − dh(P)|≤max ⁡ (log⁡ ⁡ c2 −log⁡ ⁡ c1)⏟=c□

Example. ϕ = [2] : E → E. Then there exists c > 0 such that

|h(2P) − 4h(P)|≤ c∀ ⁡P ∈ E(ℚ).

Definition (Canonical height of a point). The canonical height is

ĥ (P) = lim ⁡ n→∞ 1 4nh(2nP).

We check convergence:

Let m ≥ n. Then

| 1 4mh(2mP) − 1 4nh(2nP)| ≤∑ r=nm−1 | 1 4r+1h(2r+1P) − 1 4rh(2rP)| = ∑ r=nm−1 1 4r+1|h(2(2rP)) − 4h(2rP)| < c∑ r=n∞ 1 4r+1 = c 4n+1 1 1 −1 4 = c 3 × 4n → 0

as n →∞. So the sequence is Cauchy, ĥ(P) exists.

Lemma 13.3. |h(P) −ĥ(P)| is bounded for P ∈ E(ℚ).

Proof. Put n = 0 in above calculation to get

| 1 4mh(2mP) −h(P) | < c 3.

Take limit m →∞. □

Lemma 13.4. Assuming that:

  • B > 0

Then
#{P ∈ E(ℚ)|ĥ(P) ≤ B} < ∞.

Proof. ĥ(P) bounded means we have a bound on h(P) (by Lemma 13.3). So only finitely many possibilities for x. Each x gives ≤ 2 choices for y. □

Lemma 13.5. Assuming that:

  • ϕ : E → E′ an isogeny defined over ℚ

Then
ĥ (ϕP) = (deg⁡ϕ)ĥ(P)∀ ⁡P ∈ E(ℚ).

Proof. By ?? 66, there exists c > 0 such that

|h(ϕP) − (deg⁡ϕ)h(P)| < c∀ ⁡P ∈ E(ℚ).

Replace P by 2nP, divide by 4n and take limit n →∞. □

Remark.

Lemma 13.6. Assuming that:

Then there exists c > 0 such that for all P,Q ∈ E(ℚ) with P,Q,P + Q,P − Q≠0, we have
H (P + Q)H(P − Q) ≤ cH(P)2H(Q)2.

Proof. Let E have Weierstrass equation y2 = x3 + ax + b, a,b ∈ ℤ. Let P,Q,P + Q,P − Q have x coordinates x1,…,x4. By Lemma 5.8, there exists W0,W1,W2 ∈ ℤ[x1,x2] of degree ≤ 2 in x2 such that

(1 : x3 + x4 : x3x4) = (W0⏟ =(x1−x2)2 : W1 : W2).

Write xi = ri s i with ri,si ∈ ℤ coprime.

(s3s4 : r3s4 + r4s3 : r3r4)⏟gcd ⁡ =1 = ((r1s2 − r2s1)2 : ⋯) H(P + Q)H(P − Q) = max ⁡ (|r3|,|s3|)max ⁡ (|r4|,|s4|) ≤ 2max ⁡ (|s3s4|,|r3s4 + r4s3|,|r3r4|) ≤ 2max ⁡ (|r1s2 − r2s1|2,… ⁡ ) ≤ cmax ⁡ (|r1|2,|s 1|)2 max ⁡ (|r 2|,|s2|)2 = cH(P)2H(Q)2

where c depends on E, but not on P and Q. □

Theorem 13.7. ĥ : E(ℚ) → ℝ≥0 is a quadratic form.

Proof. Lemma 13.6 and |h(2P) − 4h(P)| bounded gives that there exists c ∈ ℝ such that

h (P + Q) + h(P − Q) ≤ 2h(P) + 2h(Q) + c∀ ⁡P,Q ∈ E(ℚ).

Replacing P, Q by 2nP, 2nQ, dividing by 4n and taking the limit n →∞ gives

ĥ (P + Q) + ĥ(P − Q) ≤ 2ĥ(P) + 2ĥ(Q).

Replacing P,Q by P + Q, P − Q and ĥ(2P) = 4ĥ(P) gives the reverse inequality. Therefore ĥ satisfies the parallelogram law, and hence ĥ is a quadratic form. □

Remark. For K a number field and P = (a0 : a1 : ⋯ : an) ∈ ℙn(K), define

H(P) = ∏ v max ⁡ 0≤i≤n|ai|v

where the product is over all places v, and the absolute values are normalised such that

∏ v|λ|v = 1∀ ⁡λ ∈ K∗.

Using this definition, all results in this section generalise when ℚ is replaced by a number field K.

14 Dual isogenies and the Weil pairing

Let K be a perfect field and E∕K an elliptic curve.

Proposition 14.1. Assuming that:

  • Φ ⊂ E(K¯) be a finite Gal ⁡ (K¯∕K)-stable subgroup

Then there exists an elliptic curve E′∕K and a separable isogeny ϕ : E → E′ defined over K, with kernel Φ, such that every isogeny ψ : E → E″ with Φ ⊂ ψ factors uniquely via ϕ:
 E                E′′

           ′
ψϕ∃ unique  E

Proof. Omitted (see Silverman, Chapter III, Proposition 4.12). □

Proposition 14.2. Assuming that:

  • ϕ : E → E′ an isogeny of degree n

Then there exists a unique isogeny ϕ^ : E′→ E such that ϕ^ϕ = [n].

Proof. Case ϕ is separable: We have |ker⁡ϕ| = n, hence ker⁡ϕ ⊂ E[n]. Apply Proposition 14.1 with ψ = [n].

Case ϕ is inseparable: omitted.

Uniqueness: Suppose ψ1ϕ = ψ2ϕ = [n]. Then (ψ1 − ψ2)ϕ = 0, so deg⁡(ψ1 − ψ2)deg⁡ϕ = 0. Then deg⁡(ψ1 − ψ2) = 0, hence ψ1 = ψ2. □

Remark.

Lemma 14.3. Assuming that:

  • ϕ,ψ ∈ Hom ⁡ (E,E′)

Then ϕ + ψ^ = ϕ^ + ψ^.

Proof.

Remark. In Silverman’s book he proves Lemma 14.3first, and uses this to show deg⁡ : Hom ⁡ (E,E′) → ℤ is a quadratic form.

Notation.

sum ⁡ : Div ⁡ (E) → E ∑ np(P)⏟formal sum ↦∑ nP(P)⏟addusinggrouplaw

Recall

E →≅Pic ⁡ 0(E) P ↦[(P) − (0)]

Therefore sum ⁡ D↦[D] for all D ∈ Div ⁡ 0(E).

We deduce:

Lemma 14.4. Assuming that:

  • D ∈ Div ⁡ (E)

Then D ∼ 0 if and only if deg⁡D = 0 and sum ⁡ D = 0E.

We will now discuss Weil pairing.

Let ϕ : E → E′ be an isogeny of degree n, with Dual isogeny ϕ^ : E′→ E. Assume char ⁡ K ∤ n (hence ϕ, ϕ¯ separable).

We define the Weil pairing

eϕ : E[ϕ] × E′[ϕ^] → μ n.

Let T ∈ E′[ϕ]. Then nT = 0, so there exists f ∈K¯(E′)∗ such that

div ⁡ (f) = n(T) − n(0).

Pick T0 ∈ E(K¯) with ϕ(T0) = T. Then

ϕ∗(T) − ϕ∗(0) = ∑ P∈E[ϕ](P + T0) −∑ P∈E[ϕ](P)

has sum

nT0 = ϕ^ϕT0 = ϕ^T = 0.

So there exists g ∈K¯(E)∗ such that

div ⁡ (g) = ϕ∗(T) − ϕ∗(0).

Now

div ⁡ (ϕ∗f) = ϕ∗(div ⁡ f) = n(ϕ∗(T) − ϕ∗(0)) = div ⁡ (gn)

Therefore ϕ∗f = cgn for some c ∈K¯∗.

Rescaling f, we can say without loss of generality c = 1, i.e. ϕ∗f = gn.

For S ∈ E[ϕ] we get τS∗(div ⁡ g) = (div ⁡ g) so τS∗g = ζg for some ζ ∈K¯∗, i.e. ζ = g(X+S) g(X) is independent of choice of X ∈ E(K¯).

Now

ζn = g(X + S)n g(X)n = f(ϕ(X + S)) f(ϕ(X)) = 1

since S ∈ E[ϕ]. Hence ζ ∈ μn.

We define

eϕ(S,T) = g(X + S) g(X) .

Proposition 14.5. e is bilinear and non-degenerate.

Proof.

We’ve shown E′[ϕ]↪Hom ⁡ (E[ϕ],μn). It is an isomorphism since #E[ϕ] = #E′[ϕ^] = n.

Remark.

Corollary 14.6. Assuming that:

  • E[n] ⊂ E(K)

Then μn ⊂ K.

Proof. Let T ∈ E[n] have order n. Non degeneracy of en implies that there exists S ∈ E[n] such that en(S,T) is a primitive n-th root of unity, say ζn.

Then

σ(ζn) = σ(en(S,T)) = en(σS,σT) = ζn

for all σ ∈ Gal ⁡ (K¯∕K). So ζn ∈ K. □

Example. There does not exist E∕ℚ with E(ℚ)tors≅(ℤ∕3ℤ)2.

Remark. In fact, en is alternating, i.e. en(T,T) = 1 for all T ∈ E[n].

(This implies en(S,T) = en(T,S)−1).

15 Galois Cohomology

Let G be a group and A be a G-module (an abelian group with an action of G via group homomorphisms). G-module means exactly the same thing as ℤ[G]-module.

Definition (H0). Define

H0(G,A) = AG = {a ∈ A|σ(a) = a ∀ ⁡σ ∈ G}.

Definition (Cochains). Define

C1(G,A) = {maps G → A}

(called “cochains”).

Definition (Cocycles). Define

Z1(G,A) = {(a σ)σ∈G|aστ = σ(aτ) + aσ ∀ ⁡σ,τ ∈ G}

(called “cocycles”).

Definition (Coboundaries). Define

B1(G,A) = {(σb − b) σ∈G|b ∈ A}

(called “coboundaries”).

Note. C1(G,A) ⊃ Z1(G,A) ⊃ B1(G,A).

Then we can define:

Definition (H1). Define

H1(G,A) = Z1(G,A) B1 (G,A).

Remark. If G acts trivially on A, then

H1 (G,A) = Hom ⁡ (G,A).

Theorem 15.1. Assuming that:

  • we have a short exact sequence of G-modules

    0 → A→ϕB→ψC → 0.

Then it gives rise to a long exact sequence of abelian groups:
0 → AG→ϕBG→ψCG→δH1(G,A)→ϕ∗H1(G,B)→ψ∗H1(G,C).

Proof. Omitted. □

Definition (delta). Let c ∈ CG. Then b ∈ B such that ψ(b) = c. Then

ψ(σb − b) = σc − c = 0∀ ⁡σ ∈ G

so σb − b = ϕ(aσ) for some aσ ∈ A.

Can check (aσ)σ∈G ∈Z1(G,A).

Then δ(c) = class of (aσ)σ∈G in H1(G,A).

Theorem 15.2. Assuming that:

  • A is a G-module

  • H ⊴ G a normal subgroup

Then there is an inflation restriction exact sequence
0 →H1(G∕H,AH)→inf ⁡ H1(G,A)→res ⁡ H1(H,A)

Proof. Omitted. □

Let K be a perfect field. Then Gal ⁡ (K¯∕K) is a topological group with basis of open subgroups being the Gal ⁡ (K¯∕L) for [L : K] < ∞.

If G = Gal ⁡ (K¯∕K) then we modify the definition of H1(G,A) by insisting:

Then

H1 (Gal ⁡ (K¯∕K),A) = lim ⁡ → L L∕K finite Galois H1(Gal ⁡ (L∕K),AGal ⁡ (K¯∕L)).

(direct limit is with respect to inflation maps).

Theorem (Hilbert’s Theorem 90). Assuming that:

  • L∕K a finite Galois extension

Then
H1 (Gal ⁡ (L∕K),L∗) = 0.

Proof. Let G = Gal ⁡ (L∕K). Let (aσ)σ∈G ∈Z1(G,L∗). Distinct automorphisms are linearly independent, so there exists y ∈ L such that

∑ τ∈Gaτ−1τ(y)⏟ =x≠0.

Then

σ(x) = ∑ τ∈Gσ(aτ)−1στ(y) = aσ ∑ τ∈Gaστ−1στ(y)⏟ =x

Then aσ = σ(x) x for all σ ∈ G. (aστ = σ(aτ)aσ ⟹ σ(aτ)−1 = aσaστ−1).

So (aσ)σ∈G ∈B1(G,L∗). Therefore H1(G,L∗) = 0. □

Corollary. H1(Gal ⁡ (K¯∕K),K¯∗) = 0.

Application: Assume char ⁡ K ∤ n. There is a short exact sequence of Gal ⁡ (K¯∕K)-modules

0 → μn →K¯∗ →K¯∗→ 0 x ↦xn

Long exact sequence:

K∗ → K∗→H1(Gal ⁡ (K¯∕K),μ n) →H1(Gal ⁡ (K¯∕K),K¯∗)︷=0 by Hilbert 90 x ↦xn

Therefore H1(Gal ⁡ (K¯∕K),μn)≅ ⁡ K∗∕(K∗)n.

If μn ⊂ K then

Hom ⁡ cts(Gal ⁡ (K¯∕K),μn)≅ ⁡ K∗∕(K∗)n

Finite subgroups of Hom ⁡ cts(Gal ⁡ (K¯∕K),μn) are of the form Hom ⁡ (Gal ⁡ (L∕K),μn) for L∕K a finite abelian extension of K of exponent dividing n.

This gives another proof of Theorem 11.2.

Notation. H1(K,−) means H1(Gal ⁡ (K¯∕K),−).

Let ϕ : E → E′ be an isogeny of elliptic curves over K. Short exact sequence of Gal ⁡ (K¯∕K)-modules

0 → E[ϕ] → E→ϕE′→ 0

has long exact seqeucne

E(K)→ϕE′(K)→δH1(K,E[ϕ]) →H1(K,E)→ϕ ∗H1(K,E′).

We get a short exact sequence

              ′
 0           EϕE(K(K-))            H1 (K,E [ϕ])          H1 (K, E)[ϕ∗]  0


            ∏   E′(Kv)-        ∏    1               ∏    1        ∗
δrrδ0esesVvv           v ϕE(Kv)           vH  (Kv,E[ϕ])        vH  (Kv, E)[ϕ0]
Now take K a number field.

For each place v, fix an embedding K¯ ⊂K¯v. Then Gal ⁡ (K¯v∕Kv) ⊂ Gal ⁡ (K¯∕K).

Definition (Selmer-group). We define the ϕ-Selmer group

S(ϕ)(E∕K) = ker⁡ (H1(K,E[ϕ]) →∏ vH1(K v,E)) = {α ∈H1(K,E[ϕ])|res ⁡ v(α) ∈ Im ⁡ (δv) ∀ ⁡v}

(the map H1(K,E[ϕ]) →∏ ⁡ vH1(Kv,E) is as in the commutative diagram above).

Definition (Tate-Shafarevich group). The Tate-Shafarevich group is

TS(E∕K) = ker⁡(H1(K,E) →∏ vH1(K v,E)).

We get a short exact sequence

0 → E′(K) ϕE(K) →S(ϕ)(E∕K) →TS(E∕K)[ϕ K] → 0.

Taking ϕ = [n] gives

0 → E(K) nE(K) →S(n)(E∕K) →TS(E∕K)[n] → 0.

Reorganising the proof of Mordell-Weil gives

Theorem 15.3. S(n)(E∕K) is finite.

Proof. For L∕K a finite Galois extension,

                          finite
                  ◜-1------◞◟--------◝
 0                H  (Gal(L∕K ),E(L)[n ]) H1 (K,E [n])      H1(L,E [n])


inr⊃⊃fes                                     S (n)(E ∕K )       S(n)(E∕L )
Therefore by extending our field, we may assume E[n] ⊂ E(K) and hence by the Weil pairing μn ⊂ K.

Therefore E[n]≅μn × μn as a Gal ⁡ (K¯∕K)-module. Then

H1(K,E[n]) ≅H1(K,μ n) ×H1(K,μ n) ≅K∗∕(K∗)n × K∗∕(K∗)n

Let

S = {primes of bad reduction for E}∪{v|n∞}

(a finite set of places).

Define the subgroup of H1(K,A) unramified outside of S as

H1 (K,A;S) = ker⁡(H1(K,A) →∏ v∉SH1(K vnr,A)).

There is a commutative diagram with exact rows:

    E (Kv )       E(Kv )          H1(Kv,E [n])


×δr×0nvesn  E (Knrv )      E(Kvnr )        H1(Knrv ,E [n])
The bottom map × n is surjective ∀ ⁡v∉S (see Theorem 9.8).

Therefore

S(n)(E∕K) ⊂H1(K,E[n];S) ≅H1(K,μ n;S) ×H1(K,μ n;S)

But

H1(K,μ n;S) = ker⁡ ( K∗ (K∗)n →∏ v∉S (Kvnr)∗ (Kvnr)∗n ) ⊂ K(S,n)

which is finite by Lemma 11.4. □

Remark. S(n)(E∕K) is finite and effectively computable.

It is conjectured that |TS(E∕K)| < ∞. This would imply that rank ⁡ E(K) is effectively computable.

16 Descent by Cyclic Isogeny

Let E,E′ be elliptic curves over a number field K, and ϕ : E → E′ an isogeny of degree n.

Suppose E′[ϕ^]≅ℤ∕nℤ generated by T ∈ E′(K). Then E[ϕ]≅μn as a Gal ⁡ (K¯∕K)-module

S↦e(S,T).

Have a short exact sequence of Gal ⁡ (K¯∕K)-modules

0 → μn → E→ϕE′→ 0.

Get long exact sequence

   E (K )      E ′(K )        H1(K, μn)     H1 (K,E )


ϕδα∼=                           K∗∕(K ∗)n
(the ≅ is by Hilbert 90).

Theorem 16.1. Assuming that:

  • f ∈ K(E′) and g ∈ K(E)

  • div ⁡ (f) = n(T) − n(0)

  • ϕ∗f = gn

Then α(P) = f(P)(mod(K∗)n) for all P ∈ E;(K) ∖{0,T}.

Proof. Let Q ∈ ϕ−1P. Then δ(P) ∈H1(K,μn) is represented by σ↦σQ − Q ∈ E[ϕ]≅μn.

e(σQ − Q,T) = g(σQ − Q + X) g(X) for any X ∈ E avoiding zeroes and poles of g = g(σQ) g(Q) pick X = Q = σ(g(Q)) g(Q) = σf(P)n f n (P)

(ϕ∗f = gn, f(P) = g(Q)n).

But

H1(K,μ n) ≅K∗∕(K∗)n (σ↦xn x n ) ←↤ x

Hence α(P) = f(P)(mod(K∗)n). □

16.1 Descent by 2-isogeny

E :   y2 = x(x2 + ax + b) E′ :   y2 = x(x2 + a′x + b′) b(a2 − 4b)≠0, a′ = −2a, b′ = a2 − 4b. ϕ : E → E′ (x,y) ↦ ((y x )2, y(x2 − b) x2 ) ϕ^ : E′ → E (x,y) ↦ (1 4 (y x )2, y(x2 − b′) 8x2 )

E[ϕ] = {0,T}, T = (0,0) ∈ E(K).

E′[ϕ^] = {0,T′}, T′ = (0,0) ∈ E′(K).

Proposition 16.2. There is a group homomorphism

E′(K) → K∗∕(K∗)2 (x,y) ↦ { x mod (K∗)2 if x≠0 b′ mod (K∗)2if x = 0

with kernel ϕE(K).

Proof. Either: Apply Theorem 16.1 with f = x ∈ K(E′), g = y x ∈ K(E).

Or: direct calculation – see Example Sheet 4. □

αE : E(K) ϕ^ E′(K) ↪K∗∕(K∗)2 αE′ : E′(K) ϕE(K) ↪K∗∕(K∗)2

Lemma 16.3. 2rank ⁡ E(K) = | Im ⁡ αE|⋅| Im ⁡ αE′| 4 .

Proof. If A→fB→gC are homomorphisms of abelian groups, then there is an exact sequence

 0         ker(f)        ker(gf )       ker(g)


fg          coker(f)      coker(gf)      coker(g)   0
Since ϕ^ϕ = [2]E, we get an exact sequence

0 → E(K)[ϕ]⏟≅ ⁡ℤ∕2ℤ → E(K)[2]→ϕE′(K)[ϕ′]⏟ ≅ ⁡ℤ∕2ℤ → E′(K) ϕE(K)⏟ ≅ ⁡ Im ⁡ (αE′)→ϕ^ E(K) 2E(K) → E(K) ϕ^ E′(K)⏟ ≅ ⁡ Im ⁡ (αE) → 0.

Therefore

|E(L)∕2E(K)| |E(K)[2]| = |Im ⁡ αE|⋅|Im ⁡ αE′| 4 . (1)

Mordell-Weil: E(K)≅Δ × ℤr, where Δ is a finite group and r = rank ⁡ E(K).

E(K) 2E(K)≅ Δ 2Δ ×(ℤ 2ℤ ) r.

E(K)[2]≅Δ[2].

Since Δ is finite, we have that Δ 2Δ and Δ[2] have the same order, and therefore

|E(K)∕2E(K)| |E(K)[2]| = 2r. (2)

So we are done, by using (1) and (2). □

Lemma 16.4. Assuming that:

  • K is a number field

  • a,b ∈OK

Then Im ⁡ (αE) ⊂ K(S,2), where S = {𝔭|b}.

Proof. We must show that x,y ∈ K, y2 = x(x2 + ax + b) and v𝔭(b) = 0 then v𝔭(x) ≡ 0(mod2).

Case v𝔭(x) < 0: Lemma 9.1 gives that for some r ≥ 1, v𝔭(x) = −2r and v𝔭(y) = −3r, so done.

Case v𝔭(x) > 0: Then v𝔭(x2 + ax + b) = 0. So v𝔭(x) = v𝔭(y2) = 2v𝔭(y). □

Lemma 16.5. Assuming that:

  • b1b2 = b

Then b1(K∗) ∈ Im ⁡ (αE) if and only if
w2 = b 1u4 + au2v2 + b 2v4 (∗)

is soluble for u,v,w ∈ K not all zero.

Proof. If b1 ∈ (K∗)2 or b2 ∈ (K∗)2 then both conditions are satisfied. So we may assume b1,b2∉(K∗)2.

Now note b1(K∗)2 ∈ Im ⁡ (αE) if and only if there exists (x,y) ∈ E(K) such that x = b1t2 for some t ∈ K∗. This implies

y2 = (b 1t2)(b 12t2 + ab 1t2 + b)

hence

( y b1t )2 = b 1t4 + at2 + b b1⏟ =b2.

So (∗) has solution (u,v,w) = (t,1, y b1t ).

Conversely, if (u,v,w) is a solution to (∗) then uv≠0 and (b1 (u v ) 2,b 1uw v3 ) ∈ E(K). □

Now take K = ℚ.

Example. E: y2 = x3 − x (a = 0, b = −1).

Im ⁡ (αE) = ⟨−1⟩⊂ ℚ∗∕(ℚ∗)2.

E′: y2 = x3 + 4x.

Im ⁡ (αE′) ⊂⟨−1,2⟩⊂ ℚ∗∕(ℚ∗)2.

b1 = −1 w2 = −u4 − 4v4 b1 = 2 w2 = 2u4 + 2v4 b1 = −2 w2 = −2u4 − 2v4 The first and last lines are insoluble over ℝ (squares are non-negative). The middle line does have a solution: (u,v,w) = (1,1,2).

Therefore Im ⁡ (αE′) = ⟨2⟩⊂ ℚ∗∕(ℚ∗)2.

Hence 2rank ⁡ E(ℚ) = 2⋅2 4 = 1, so rank ⁡ E(ℚ) = 0.

So 1 is not a congruent number.

Example. E: y2 = x3 + px, p a prime which is 5 modulo 8.

b1 = −1 w2 = −u4 − pv4

This is insoluble over ℝ, hence Im ⁡ (αE) = ⟨p⟩⊂ ℚ∗∕(ℚ∗)2.

E′: y2 = x3 − 4px.

Im ⁡ (αE′) ⊂⟨−1,2,p⟩⊂ ℚ∗∕(ℚ∗)2.

Note: αE′(T′) = (−4p)(ℚ∗)2 = (−p)(ℚ∗)2.

b1 = 2 w2 = 2u4 − 2pv4 b1 = 2 w2 = −2u4 + 2pv4 b1 = p w2 = pu4 − 4v4

Suppose the first line is soluble. Then without loss of generality u,v,w ∈ ℤ with gcd ⁡ (u,v) = 1. If p|u, then p|w and then p|v, contradiction. Therefore w2 ≡ 2u4⁄ ≡ 0(modp). So (2 p ) = +1, which contradicts p ≡ 5(mod8).

Likewise the second line has no solution since (−2 p ) = −1.

TODO

Example (Lindemann). E: y2 = x3 + 17x.

Im ⁡ (αE) = ⟨17⟩⊂ ℚ∗∕(ℚ∗)2.

E′: y2 = x3 − 68x.

Im ⁡ (αE′) ⊂⟨−1,2,17⟩⊂ ℚ∗∕(ℚ∗)2.

b1 = 2, w2 = 2u4 − 34v4.

Replacing w by 2w and dividing by 2 gives

C :  2w2 = u4 − 17v4.

Notation. C(K) = {(u,v,w) ∈ K3 ∖{0}satisfying equation above}∕ ∼, where (u,v,w) ∼ (λu,λv,λ2w) for all λ ∈ K∗.

C(ℚ2)≠∅ since 17 ∈ (ℤ2∗)4.

C(ℚ17)≠∅ since 2 ∈ (ℤ17∗)2.

C(ℝ)≠∅ since 2 ∈ ℝ.

Therefore C(ℚv)≠∅ for all places v of ℚ.

Suppose (u,v,w) ∈ C(ℚ). Without loss of generality say u,v,w ∈ ℤ, gcd ⁡ (u,,v) = 1 and w > 0.

If 17|w then 17|u and then 17|v, contradiction

So if p|w then p≠17 and (17 p ) = +1. Therefore ( p 17 ) = (17 p ) = 1 (using quadratic reciprocity). (If p is odd, also ( 2 17 ) = +1).

Therefore ( w 17 ) = +1. But 2w2 ≡ u4(mod17), so 2 ∈ (𝔽17∗)4 = {±1,±4}, contradiction.

So C(ℚ) = ∅, i.e. C is a counterexample to the Hasse Principle. It represents a non-trivial element of TS(E∕ℚ).

16.2 Birch Swinnerton Dyer Conjecture

Let E∕ℚ be an elliptic curve.

Definition (L(E,s)). Define

L(E,s) = ∏ pLp(E,s)

where

Lp(E,s) = { (1 − app−s + p1−2s)−1 if good reduction (1 − p−s)−1 if split multiplicative reduction (1 + p−s)−1 if nonsplit multiplicative reduction 1 if additive reduction

where #Ẽ(𝔽p) = 1 + p − ap.

Hasse’s Theorem implies |ap|≤ 2p, which shows that L(E,s) converges for Re ⁡ (s) > 3 2.

Theorem (Wiles, Breuil, Conrad, Diamon, Taylor). L(E,s) is the L-function of a weight 2 modular form, and hence has an analytic continuation to all of ℂ (and a function equation relating L(E,s) = L(E,2 − s)).

Conjecture (Weak Birch Swinnerton-Dyer Conjecture). ord ⁡ s=1L(E,s) = rank ⁡ E(ℚ).

( = r say).

Conjecture (Strong Birch Swinnerton-Dyer Conjecture). ord ⁡ s=1L(E,s) = rank ⁡ E(ℚ), which we shall call r, and

lim ⁡ s→1 1 (s − 1)rL(E,s) = ΩE Reg ⁡ E(ℚ)|TS(E∕ℚ)|∏ pcp(E) |E(ℚ)tors|2 ,

where

Theorem (Kolyvagin). If ord ⁡ s=1L(E,s) is 0 or 1, then Weak Birch Swinnerton-Dyer holds, and also |TS(E∕ℚ)| < ∞.

˙

Index

Tamagawa number

bad reduction

Cauchy

cochain

complete

congruent

elliptic curve

formal group

morphism

good reduction

Hilbert 90

integral

isogeny

isogenous

j-invariant

linearly equivalent

minimal

Mordell-Weil

bad reduction

good reduction

primitive

quadratic form

rational

rational

separable

elliptic curve

unramified

Weierstrass equation

Weierstrass form

Weak Mordell-Weil Theorem