ISEGORIA / MATH ENCYCLOPEDIA
Elliptic curves: geometry that adds
A cubic curve whose points form a group: the chord-and-tangent law, curves over finite fields, and the torus hidden behind every curve.
Before you begin: Group theory, modular arithmetic and complex numbers
Predict, manipulate, then check your reasoning against the example and question. Graphs illustrate the mathematics; they do not replace a proof.
1. Adding points with a ruler
A line through two points of a cubic curve meets it in exactly one more point, counted with multiplicity. Reflect that third point in the x axis and call the result P + Q. Drag P and Q along the curve, and switch to 2P to use the tangent instead. In the (a, b) plane, cross the cusp-shaped discriminant curve and watch the curve split into two pieces or merge into one.
Worked example. On \(y^2=x^3-2x+1\), take \(P=(0,1)\) and \(Q=(1,0)\). Then \(\lambda=-1\), \(x_{P+Q}=1-0-1=0\) and \(y_{P+Q}=-1\cdot(0-0)-1=-1\), so \(P+Q=(0,-1)=-P\). This is consistent: \(Q\) has order 2, and the line through \(P\) and \(Q\) passes through \(-(P+Q)=(0,1)=P\) as a tangent point.
Watch out. The identity is the point at infinity O, where every vertical line meets the curve. Associativity is not obvious from the picture: it is a theorem (it follows from the Cayley–Bacharach theorem on cubics), which the checks behind this page verify numerically.
When is 2P = O?
Exactly when the tangent at P is vertical, that is when \(y_P=0\). Those points are the real roots of \(x^3+ax+b\), so there are one or three of them besides O.
2. The same curve over a finite field
Replace the real numbers by the integers mod p. The curve becomes a finite scatter of points with the same symmetry y ↔ −y, and the same formulas still add them. Hasse proved that the number of points never strays from p + 1 by more than 2√p. The histogram counts every curve for this p; the walk of G, 2G, 3G, … shows why undoing multiplication is hard.
Worked example. For \(y^2=x^3+x\) with \(p\equiv3\pmod 4\), the substitution \(x\mapsto-x\) flips the sign of every Legendre symbol, so the sum is 0 and \(\#E=p+1\) exactly. Try \(a=1,\ b=0\) with \(p=23\): there are 24 points.
Watch out. The semicircle drawn over the histogram is a limit: Birch showed in 1968 that, over all curves mod p, the moments of the normalised trace approach those of the semicircle as p grows. For small p the match is rough.
Why must the order of G divide #E?
The multiples of G form a subgroup of the group of points, and by Lagrange’s theorem the size of a subgroup divides the size of the group.
3. Every complex curve is a torus
Over the complex numbers an elliptic curve is a doughnut: the plane rolled up along a lattice of periods. The Weierstrass function ℘ repeats over the lattice and sends a point z of the torus to (℘(z), ℘′(z)) on the curve. Drag u and v along the two lines where ℘ is real. Adding u and v on the torus, which is just adding complex numbers, lands exactly where the chord through P and Q predicts.
Worked example. For the square lattice \(\tau=i\), symmetry under \(z\mapsto iz\) forces \(g_3=0\), and \(g_2=\tfrac{4\pi^4}{3}E_4(i)\approx189.07\). The curve is \(y^2=4x^3-189.07\,x\), symmetric about \(x=0\).
Watch out. Only rectangular lattices are shown, so that \(g_2\) and \(g_3\) are real and the curve can be drawn in the real plane. The colouring is a picture of the complex function ℘; the curve on the right shows only its real points.
Why does ℘ have a double pole at each lattice point but no other poles?
Each term \(1/(z-\omega)^2\) has its only pole at \(\omega\), and the subtracted constants make the sum converge. A doubly periodic function with a single simple pole per period is impossible, since the residues in a period must sum to zero, so a double pole is the simplest possibility.