\documentclass[a4paper]{article}

\usepackage{amsmath,amssymb,amsthm,enumerate,eucal,tikz,url}


\input amssym.def 
\input amssym.tex
%\def\Bbb{\bf}
%\nopagenumbers
%% \magnification=\magstep1
%\hoffset=1truecm
%\voffset=2truecm
%\baselineskip = 5.2 true mm
\def\notdiv{{\not\hskip-.5pt |\ }}
\font\frkkk=eufm10
\font\twelverm=cmr12
\font\tenrm=cmr10
\font\ninerm=cmr9
\font\ninebf=cmbx9
\font\eightrm=cmr8
\font\sixrm=cmr6
\font\sevrm=cmr7
\font\scrpp=eusm10 
\font\frkk=eufm10
\font\deffont=cmssi10
\font\chaptitle=cmbx10 at 14 pt
\tolerance=10000
\def\sqr{\ifmmode\square\else{$\square$}\fi}
\def\square{\vcenter{
            \hrule height.1mm
            \hbox{\vrule width.1mm height2.2mm\kern2.18mm\vrule width.1mm}
            \hrule height.1mm}}                  % This is a slimmer sqr.
%\def\sqr{$\vcenter{\hrule height .3mm
%\hbox {\vrule width .3mm height 2mm \kern 1.4mm
%\vrule width .3mm} \hrule height .3mm}$}
%
\null
%
%\vsize=19.5 true cm
%\hsize=11.5 true cm
%\vskip 5 true cm
\def\leqslant{\le}
\def\c{{\cal C}}
\def\pk{\phi _\kappa}
\def\im{{\hbox{\sl im}}}
\def\hs{H_{\varsigma}}
\def\hpk{\hat \phi _\kappa}
\font\sc=cmssqi8 
\def\scc#1{\hbox{\sc #1}}
\def\sf{{\scc F}}
\def\pnbq{{\Bbb P}^n(\overline {\Bbb Q} )}
\def\hk{{\hat \kappa}}
\def\bq{{\overline {\Bbb Q}}}
\def\hq{{\hat q}}
\def\pv{\prod\limits_v }
\def\pnk{{\Bbb P}^n(K)}
\def\mnkvw{{\Bbb M}^n(K[{\bf v}^2,{\bf w}^2])}
\def\pnkv{{\Bbb P}^n(K[{\bf v}^2])}
\def\kj{\kappa (J)}
\def \qmods {{\Bbb Q}^*/({\Bbb Q}^*)^2}
\def \qmodss { {\Bbb Q}^*/({\Bbb Q}^*)^2 \times 
  {\Bbb Q}^*/({\Bbb Q}^*)^2 }
\def \qs{{\Bbb Q}^*}
\def \qss{({\Bbb Q}^*)^2}
\def\bbQ{\Bbb Q}
\def\bbF{\Bbb F}
\def\bbZ{\Bbb Z}
\def\bbR{\Bbb R}
\def\bbC{\Bbb C}
\def\R{\Bbb R}
\def\Q{\Bbb Q}

\def\F{\Bbb F}
\def\e{{\mathcal E}}
%

\def\etq{{\cal E}_{\lower 1pt\hbox{\eightrm tors}}({\Bbb Q})}
\def\ctq{{\cal C}_{\lower 1pt\hbox{\eightrm tors}}({\Bbb Q})}
\def\cotq{{\cal C}_{\lower 1pt\hbox{\eightrm oddtors}}({\Bbb Q})}
\def\dotq{{\cal D}_{\lower 1pt\hbox{\eightrm oddtors}}({\Bbb Q})}

\newcommand{\M}{\mathfrak{m}}

\begin{document}

\noindent
\centerline{{\bf Elliptic Curves MT25: Solutions to Sheet 3}}
\bigskip

\begin{enumerate}[{\bf (1)}]


\item
Following the hint, there exist polynomials $p(x),q(x)\in R[x]$
such that $p(x) f(x) + q(x) f'(x) = D$,
and so: $p(a_0) f(a_0) + q(a_0) f'(a_0) = D$.
Since $|a_0|\leqslant 1$, and since $p(x),q(x),f(x),f'(x)\in R[x]$,
we must have $|p(a_0)|,|f(a_0)|,|q(a_0)|,|f'(a_0)| \leqslant 1$
and so $|D| \leqslant \hbox{max}( |p(a_0) f(a_0)|,|q(a_0) f'(a_0)| )
\leqslant 1$, which also implies $|D^2| = |D|^2 \leqslant |D|$.
Now, we are given that $|f(a_0)| < |D|^2$
and so $| p(a_0) f(a_0) | \leqslant | f(a_0) | < |D^2| \leqslant |D|$.
Hence $|D| \not= |p(a_0) f(a_0) |$, and
so $|q(a_0) f'(a_0)| = |D - p(a_0) f(a_0)| = \hbox{max}( |D|, |p(a_0) f(a_0)|)
= |D|$ [using the fact that, if $|u| \not= |v|$
then $|u\pm v| = \hbox{max}(|u|,|v|)$].
Since also $|q(a_0)| \leqslant 1$, this gives
that $|f'(a_0)| \geqslant |D|$. Finally,
$|f(a_0)| < |D|^2 \leqslant |f'(a_0)|^2$, and so $f(X)$
has a root $a\in R$ by Hensel's Lemma.
\medskip


\item
In projective form, the point is:
$(-64/25,59/125,1)$. The coordinate with largest $5$-adic value
is $59/125$, and on dividing all coordinates
through by this, we can also represent
the point as: $(-320/59,1,125/59)$, which is in $5$-adic standard
form (that is, $1$ is the maximum of the $5$-adic valuations
of the coordinates). Reducing mod~$5$ gives $(0,1,0)$ on $\widetilde \e$,
which is the point at infinity.
\medskip

\item
Let $\c$ be the curve $2 Y^2 = X^4 - 17$.
Over~$\R$, the curve has the point
$(4,\sqrt{239/2})$. 
In $\Q_2$, let $x=11$. Then
$11^4 - 17 = 2^5 \cdot 457$; but 457 is an integer congruent to~1 mod~8,
and so, from lectures, there exists $\gamma \in \mathbb{Z}_2 \subset \Q_2$ such that
$457 = \gamma^2$; then $(11, 4\gamma)$ is a point on the curve
over~$\Q_2$. For the next few primes,
we shall repeatedly use the result from lectures that, if $p\not= 2$
and $|a|_p = 1$, then $a$ is a square in $\Q_p$ iff it
is a square mod~$p$. Now, note that $-8,-34,-34,-8,10,-8$ are
quadratic residues modulo~$p=3,5,7,11,13,17$, respectively,
and so there exists $\gamma \in \Q_p$
such that $\gamma^2 = -8,-34,-34,-8,10,-8$, respectively;
this gives the $\Q_p$-rational points on the
curve: $(1,\gamma), (0,\gamma/2), (0,\gamma/2),
(1,\gamma), (4,\gamma/2), (1,\gamma)$, respectively.
Hence $\c$ has $\Q_p$-rational points for all primes
up to and including $p=17$ [in fact, it was only necessary to
do here $p=2,3,5,7,11,17$ here].
\par Let $p$ be any prime $p\geqslant 13$ and $p\not= 17$.
Our curve~$\c$ (after multiplying both sides by~$2$) is
birationally equivalent to $V^2 = 2 X^4 - 34$, where $V = 2Y$;
note that $2 X^4 - 34$ has discriminant $-2^{11} 17^3$.
Recall Theorem~2.16 from lectures, 
that any curve $y^2 = Q(x)$, where $Q(x) = f_4 x^4 + \ldots + f_0$
has nonzero discriminant over~$\F_p$, 
has at least $p - 1 - 2\sqrt{p} > 4$
affine points over~$\F_p$, and so at least~$5$ affine points.
At most~$4$ of these can have $2 x^4 - 34 \equiv 0$~(mod~$p$),
and so there exists
$x_0 \in \mathbb{Z}$ 
such that $2(x_0^4 - 17)$ is a nonzero quadratic residue mod~$p$.
As above, there exists $\gamma \in \Q_p$ such that
$\gamma^2 = 2(x_0^4 - 17)$, and so $(x_0,\gamma/2)$ is a
$\Q_p$-rational point on our original curve~$\c$.
Hence $\c$ has points in~$\R$ and every~$\Q_p$.
\newpage

\par {\it Alternative method for the above parts:}
Note that for $p \notdiv 2\Delta$
(that is: $p \not= 2,17$)
$p \geqslant 7$, we have (from a theorem from lectures)
the number of affine points in 
${\widetilde \c} (\F_p) \geqslant p-1 - 2\sqrt{p} > 0$, and so the
number of affine points is $ > 0$; these are non-singular, since
$2\Delta \not= 0$ in~$\F_p$. Also, 
by a theorem from lectures, any non-singular point on 
${\widetilde \c} (\F_p)$ lifts to a point on $\c (\Q_p)$; 
also, any affine non-singular point on ${\widetilde \c} (\F_p)$ 
lifts to an affine point on $\c (\Q_p)$
(since the point at infinity on $\c (\Q_p)$ maps to the point at 
infinity on ${\widetilde \c} (\F_p)$ under the reduction map mod~$p$).
This shows the existence of such $x,y \in \Q_p$ for
all~$p$ except $p = 2,3,5$ and bad primes, so only still need
to consider $p = 2,3,5,17$. Also, note that for $p = 3$ there
is the non-singular affine point $(1,1)$ on ${\widetilde \c} (\F_3)$, 
for $p = 5$ there
is the non-singular affine point $(0,2)$ on ${\widetilde \c} (\F_5)$, 
and for $p = 17$ there is the non-singular affine point 
$(1,3)$ on ${\widetilde \c} (\F_{17})$, and as before these must 
lift to affine points $(x,y) \in \c(\Q_p)$.
Over~$\R$, the curve has the point
$(4,\sqrt{239/2})$.
In $\Q_2$, let $x=11$. Then
$11^4 - 17 = 2^5 \cdot 457$; but 457 is an integer congruent to~1 mod~8,
and so, from lectures, there exists $\gamma \in \mathbb{Z}_2 \subset \Q_2$ such that
$457 = \gamma^2$; then $(11, 4\gamma)$ is a point on the curve
over~$\Q_2$.
This completes the alternative method of showing
that $\c$ has points in~$\R$ and every~$\Q_p$.

\par Now, imagine that $\c$ had a $\Q$-rational point; that is,
imagine that there exist $X,Y\in \Q$ such that $2 Y^2 = X^4 - 17$.
Let $X = t/r$, where $r,t\in \mathbb{Z}$ and $\hbox{gcd}(r,t) = 1$.
Then $2(r^2 Y)^2 = t^4 - 17 r^4 \in \mathbb{Z}$. For any prime~$p$,
this gives that $|2|_p |r^2 Y|_p^2 \leqslant 1$. When $p\not= 2$,
we have $|2|_p = 1$ and so $|r^2 Y|_p^2 \leqslant 1$
and so $|r^2 Y|_p \leqslant 1$. When $p=2$,
we have $2^{-1} |r^2 Y|_2^2 \leqslant 1$; but this still
gives $|r^2 Y|_2 \leqslant 1$ [since $|r^2 Y|_2 > 1$
would mean $|r^2 Y|_2 \geqslant 2^1$ and so $2^{-1} |r^2 Y|_2^2 
\geqslant 2^{-1} 2^2 > 1$]. Overall, we have shown that
$|r^2 Y|_p \leqslant 1$ for all~$p$; since also $r^2 Y \in \Q$,
this gives that $r^2 Y \in \mathbb{Z}$; let us say: $s = r^2 Y \in \mathbb{Z}$.
Therefore $r,s,t\in\mathbb{Z}$ satisfy $2 s^2 = t^4 - 17 r^4$
and $\hbox{gcd}(r,t) = 1$.
%% \newpage 

\par Let $q$ be any prime such that $q | s$. Note that
$q\not= 17$ [since if $17 | s$ then our equation
$2 s^2 = t^4 - 17 r^4$ would force $17 | t$, and so
$17^2 | 2 s^2$ and $17^2 | t^4$, which would give $17^2 | 17 r^4$,
forcing $17 | r$, which
would contradict $\hbox{gcd}(r,t) = 1$]. 
Note also that
we must not then have $q|r$ [since if $q|s$ and $q|r$, then
our equation $2 s^2 = t^4 - 17 r^4$ would force $q | t$, which
would contradict $\hbox{gcd}(r,t) = 1$]. 
Reducing our equation modulo~$q$ gives that $0 \equiv t^4 - 17 r^4$
and so $(t^2/r^2)^2 \equiv 17$ mod~$q$ [note that division
by $r^2$ is allowable mod~$q$ since $r$ is not divisible by~$q$].
Hence $17$ is a nonzero quadratic residue mod~$q$.
For $q\not= 2$, quadratic reciprocity then allows us to
deduce that~$q$ is a quadratic residue mod~$17$
[since $17 \equiv 1$ (mod~$4$)]. Furthermore, one can check
directly that $2$ is a quadratic residue mod~$17$, since
$2 \equiv 6^2$ mod~$17$. Overall, we have shown that
every prime~$q$ dividing~$s$ must be a quadratic residue
mod~$17$, 
and we can take $s>0$ (if necessary, replacing~$s$ by~$-s$),
so that~$s$ is the product of its prime factors.
It follows that $s$ itself must be a quadratic residue mod~$17$,
since it is a product of quadratic residues mod~$17$.
Hence $s^2$ is a nonzero fourth power [also known as
a {\it quartic residue}] mod~$17$.
Note also that reducing our equation mod~$17$ gives
$2 s^2 \equiv t^4$ (mod~$17$), so that $2 s^2$ is also
a nonzero fourth power mod~$17$. Since $s, 2s^2$ are
both nonzero fourth powers mod~$17$, it follows that
$2 = (2s^2)/s^2$ is also a fourth power mod~$17$.
On the other hand, one can compute directly that
$0^4,1^4,2^4,3^4,4^4,5^4,6^4,7^4,8^4,9^4,10^4,11^4,12^4,13^4,14^4,
15^4,16^4$ are congruent mod~$17$ to: 
$0,1,16,13,1,13,4,4,16,16,4,4,13,1,13,16,1$, respectively,
so that in fact $2$ is not a fourth power mod~$17$
(alternatively: if $2 \equiv w^4$ (mod~17) then $-1 \equiv 2^4
\equiv w^{16} \equiv 1$ (mod~17) by FLT, a contradiction,
avoiding the need for an enumeration).
This contradication show that our original curve $\c$
has no $\Q$-rational points.

\medskip



\item
\par \noindent {\bf (a).} Let $\e : Y^2 = X^3 + p^2$. Then
the point $(0,p)$ on $\e$ reduces modulo~$p$ to the
cusp~$(0,0)$ on $\widetilde \e : Y^2 = X^3$, which is another
way of saying that $(0,0)$ on $\widetilde \e$ lifts to the
point $(0,p)$ in~$\e (\Q_p)$.  
\par \noindent {\bf (b).} Question~3 is an example of this.
\par \noindent {\bf (c).} Let $\e : Y^2 = X^3 + X^2 + p^2$. Then 
the point $(0,p)$ on $\e$ reduces modulo~$p$ to the 
node~$(0,0)$ on $\widetilde \e : Y^2 = X^3 + X^2$, which is another
way of saying that $(0,0)$ on $\widetilde \e$ lifts to the  
point $(0,p)$ in~$\e (\Q_p)$.
\par \noindent {\bf (d).} Let $\e : Y^2 = X^3 + X^2 + p$ and
$\widetilde \e : Y^2 = X^3 + X^2$. Then the node~$(0,0)$ on
$\widetilde \e$ does not lift to any point in~$\e(\Q_p)$ by the
same argument as in Question~2.
\medskip

\item
By definition of a homomorphism, we need to show
\[ [m] F(X,Y) \stackrel{?}{=} F([m](X),[m]Y).\]
This is true when $m = 0$, since $[0](T) := 0$.
Now for $m \geq 1$ we can use the recursive definition to rewrite this as
\[ F([m-1]F(X,Y),F(X,Y)) \stackrel{?}{=} F(F([m-1](X),X), F([m-1]Y,Y)).\]
By induction we can assume
$[m-1] F(X,Y) =  F([m-1](X),[m-1]Y)$.
Starting from the LHS we compute
\[ F([m-1]F(X,Y),F(X,Y))  = F(F([m-1](X),[m-1](Y)), F(X,Y))\] \[ = 
F([m-1](X),F([m-1](Y),F(X,Y))) = F([m-1](X),F(F(X,Y),[m-1](Y))) \] \[ = F([m-1](X),F(X,F(Y,[m-1](Y))))
= F(F([m-1](X),X),F(Y,[m-1](Y)))\]
which by commutativity equals the RHS.
Here we have used, in order, induction, associativity, commutativiity, associativity, associativity.

\item {\bf (a)} We can regard $F$ as a formal group law over $K$, and then $\log_F$ is a homomorphism from $F$ to $\widehat{\mathbb{G}}_a$. In particular, we have an identity of formal power series (with coefficients in $K$):
$\log_F(X)+\log_F(Y) = \log_F(F(X,Y))$. When $x,y \in \M$, it follows from the result in Question 10 that $\log_F(x)+\log_F(y) = \log_F(F(x,y))$. This gives the desired homomorphism.

{\bf{(b)}} We have $\log_F(x) = x + \sum_{n \ge 2}\frac{c_n}{n}x^n$, with $c_n \in R$. So to show that $|\log_F(x)| = |x|$, it suffices to show that $\left|\frac{c_n}{n}x^n\right| < |x|$ for all $n \ge 2$. Using $|c_n| \le 1$ and rearranging, we need to show $|x| < |n|^{1/(n-1)}$ for all $n\ge 2$. Write $n=p^km$, so $|n|^{1/(n-1)} = |p|^{k/(p^km-1)}$. We have $k/(p^km-1) \le k/(p^k-1) = \frac{1}{p-1}\frac{k}{1+\cdots+p^{k-1}} \le 1/(p-1)$. This shows that $\min_n(|n|^{1/(n-1)}) = |p|^{1/(p-1)}$. We deduce that a sufficient condition to ensure $|x| < |n|^{1/(n-1)}$ for all $n\ge 2$ is $|x| < |p|^{1/(p-1)}$. This gives the desired statement. We get injectivity because $\log_F(x) = 0$ implies $|x| = 0$. 

{\bf (c)}  Suppose that $z \in F(\M)$ has exact order $p$. We deduce from part (a) that $p\log_F(z) = 0$, which implies that $\log_F(z) = 0$. We deduce from part (b) that  $|z| \ge |p|^{1/(p-1)}$. 

\item
In all of the following, we use
the result from lectures that (when the coefficients
of $\cal E$ are in $\Bbb Z$) $\etq$ is isomorphic to a subgroup
of $\widetilde {\cal E}$ mod~$p$, where $p\not=2$ is a prime
not dividing the discriminant. Note that this typically
gives a much faster way of computing $\etq$ than the
Nagell-Lutz result. N.B. (a),(b),(c) are about the level that
could be asked as part of a 3-hour exam.
\par\noindent {\bf (a).} There are the obvious points
$P = (0,1)$ of order~$3$ and $Q = (-1,0)$ of order~$2$ in $\etq$,
which generate a subgroup of $\etq$ of size~$6$ (namely,
the~$6$ points $mP+nQ$ for $0\leqslant m \leqslant 2$ and
$0\leqslant n \leqslant 1$). Further, $\Delta = 4A^3 + 27B^2 = 27$,
so we can reduce modulo any prime except~$2$ (which must always
be avoided) and~$3$. Over ${\Bbb F}_5$, there are only
six points: ${\bf o}, (0,\pm 1), (2,\pm 3), (4,0)$. So, we conclude
that $\etq$ has size at most~$6$, which means that it consists
of precisely the $C_6 = C_2\times C_3$ group
of points we have found already.
\par Note that, if $P=(0,1)$ and $Q=(-1,0)$, then the complete
list of torsion points is: ${\bf o}, P = (0,1), 2P = (0,-1),
Q = (-1,0), P+Q = (2,-3), 2P+Q = (2,3)$.
\par\noindent {\bf (b).} Here, the (birational over~$\Bbb Q$)
transformation $(X,Y) \mapsto (X-1,Y)$ takes the given
curve to: $Y^2 = X(X+1)(X-1) = X^3 - X$, which has discriminant $-4$, 
and so we can reduce modulo the prime~$3$
Over~${\Bbb F}_3$
there are the points: ${\bf o}, (0,0), (1,0), (2,0)$ giving
that $\etq$ has size at most~$4$. But, in fact, $\etq$
contains ${\bf o}, (0,0), (-1,0), (1,0)$, which means
the this $C_2\times C_2$ group gives all of $\etq$.
[{\it Alternatively, even without using a birational transformation
to the form $Y^2=X^3 + AX + B$, we could just work entirely
with the given equation of the curve, noting that
the original cubic $X(X-1)(X-2)$ has no repeated
roots~mod~$3$, so that $Y^2 = X(X-1)(X-2)$ is an elliptic curve
mod~$3$, and then noting that the only points are:
${\bf o}, (0,0), (1,0), (2,0)$.}]
\par\noindent {\bf (c).} The (birational over~$\Bbb Q$)
transformation $(X,Y) \mapsto (3^2X, 3^3Y)$ takes the
given curve to: $Y^2 = X^3 + 1$ which we have already seen
in part~(a) to have a $C_2\times C_3$ group as its
torsion group.
\par Note that, if $P = (0,1/27)$ and $Q = (-1/9,0)$ then the
complete list of torsion points is given by: ${\bf o}, P=(0,1/27),
2P=(0,-1/27), Q = (-1/9,0), P+Q = (2/9,-1/9), 2P+Q = (2/9,1/9)$.

\item
Take $F(X,Y) = X + Y + t X Y^p$,
clearly non-commutative. One only has to check associativity.
$$ F(F(X,Y),Z) = F( X + Y + t X Y^p, Z )
= X + Y + t X Y^p + Z + t(X + Y + t X Y^p) Z^p
$$
$$
\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ 
= X + Y + t X Y^p + Z + t X Z^p + t Y Z^p,$$
since the remaining term $t^2 X Y^p Z^p \in I = t^2 \F_p[t]$
and so $t^2 X Y^p Z^p = 0$ in $R = \F_p[t]/I$.
Also:
$$ F(X, F(Y,Z))
= X + F(Y,Z) + t X F(Y,Z)^p
= X + Y + Z + t Y Z^p + t X (Y + Z + t Y Z^p)^p
$$
$$
\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ 
= X + Y + Z + t Y Z^p + t X (Y^p + Z^p + (t Y Z^p)^p),
$$
since all other terms in the binomial expansion
of $(Y + Z + t Y Z^p)^p$ are divisible by~$p$ and
so are equal to~$0$ in $R$, which has characteristic~$p$.
But $(t Y Z^p)^p = t^2 (t^{p-2} Y^p Z^{p^2})\in I$ 
and so $(t Y Z^p)^p = 0$ in~$R$, so that the above
are the same, giving associativity, as required.


\item
We are going to use the fact that these curves admit unusual endomorphisms (`complex multiplication'), and therefore so do the associated formal groups. In the first example, $Y^2 = X^3 + AX$, the map $(x,y)\mapsto (-x,iy)$ induces an endomorphism of the curve (compatible with the group law). In the $(z,w)$-coordinates, this map is $(z,w) \mapsto (iz,-iw)$. This tells us that $f(z) = iz$ is an endomorphism of the formal group $F(X,Y)$ (regarded as a formal group law over $\mathbb{C}$, for example). This implies that $F(iX,iY) = iF(X,Y)$, so looking at each homogeneous piece we have $i^n F_n(X,Y) = iF(X,Y)$.  We deduce that $F_n = 0$ unless $i^n = i$, i.e.~$n \equiv 1$ mod $4$. 

In the second case, our unusual endomorphism is given by $(x,y)\mapsto (\zeta x,-y)$, where $\zeta = e^{2i\pi/3}$ (we have changed the sign of $y$ to get an endomorphism of maximal order, $6$). In the $(z,w)$-coordinates, this map is $(z,w) \mapsto (-\zeta z,-w)$. This tells us that $f(z) = -\zeta z$ is an endomorphism of the formal group $F(X,Y)$. This implies that $F(-\zeta X,-\zeta Y) = -\zeta F(X,Y)$, so looking at each homogeneous piece we have $(-\zeta)^n F_n(X,Y) = -\zeta F(X,Y)$.  We deduce that $F_n = 0$ unless $(-\zeta)^n = -\zeta$, i.e.~$n \equiv 1$ mod $6$. 
 

Here is a (perhaps) more direct solution, reproduced from an earlier version of these solutions:
Recall from lectures that the first step in deriving the
formal group of an elliptic curve is to write the
equation $\e : Y^2 = X^3 + A X + B$ as: 
$\e' : w = f(z,w) = z^3 + A w^2 z + B w^3$,
where $z = -x/y, w = -1/y$.
We then Inductively define $f_n(z,w)$ by: $f_1(z,w) = f(z,w)$
and $f_{m+1}(z,w) = f_m( z, f(z,w) )$ and define
$$ w(z) = \lim_{m\rightarrow \infty} f_m(z,0) \in \mathbb{Z}[A,B][[z]],$$
which satisfies $w(z) = f\bigl( z, w(z) \bigr)$.
The terms of $f_1(z,w) = z^3 + A w^2 z + B w^3$ all have
weighted degree~$\equiv 3$ [where we give $z$ weight~1, $w$ weight~$3$,
$A$ weight~$-4$ and $B$ weight~$-6$].
Suppose that this is also true of $f_m(z,w)$;
then $f_{m+1}(z,w) = f_m ( z, z^3 + A w^2 z + B w^3 )$, where
$z$ has weighted degree~$1$, $z^3 + A w^2 z + B w^3$ is homogeneous
of weighted degree~$3$,
and so the same will be true of~$f_{m+1}$.
So, by induction, all terms of every $f_m$ and so all terms
of $w(z)$ will have weighted degree~$3$.

We now perform the addition 
$ (z_1,w_1) + (z_2,w_2)$. As usual, we first write
the line $z = \lambda w + \mu$ through the points,
given by $\lambda = (w(z_1) - w(z_2))/(z_1 - z_2)$
and $\mu = (z_1 w(z_2) - z_2 w(z_1))/(z_1 - z_2)$,
both in $\mathbb{Z}[A,B][[z_1,z_2]]$. Letting $z_1$ and $z_2$ each
have weight~$1$, the numerator $w(z_1) - w(z_2)$
is homogeneous of weighted degree~$3$, and so
$\lambda$ is homogeneous of weighted degree~$2$.
Similarly, $\mu$ is homogeneous of weighted degree~$3$.
As in lectures, substituting $w = \lambda z + \mu$ into $\e'$ gives
$\lambda z + \mu = z^3 + A(\lambda z + \mu)^2 z + B (\lambda z + \mu)^3$,
and so:
$$(1 + A \lambda^2 + B \lambda^3) z^3 
+ ( 2 A \lambda \mu + 3 B \lambda^2 \mu ) z^2 + \ldots = 0.$$
Let $(z_3, w(z_3))$ be the third point of intersection of
$\e'$ and the line $z = \lambda w + \mu$, so that $z_1,z_2,z_3$
are the roots of the above cubic, giving
that $z_1 + z_2 + z_3 = -(\hbox{coeff of }z^2)/(\hbox{coeff of }z^3)$,
so:
$$ z_3 = -z_1 - z_2 - {2 A \lambda \mu + 3 B \lambda^2 \mu\over
1 + A \lambda^2 + B \lambda^3} \in \mathbb{Z}[A,B][[z_1,z_2]],
$$
since the denominator is of the form $1 + \phi(z)$,
where $\phi(z)$ has no constant term [and so is an invertible
power series, with $1/(1 + \phi(z)) = 1 - \phi(z) + \phi(z)^2 + \ldots$].
The sum $(z_1,w_1) + (z_2,w_2) + (z_3,w_3) =$ the identity,
and so $(z_1,w_1) + (z_2,w_2) = -(z_3,w_3)$.
Negation $(x,y) \mapsto (x,-y)$ induces $(z,w)\mapsto (-z,-w)$
[since $z=-x/y, w=-1/y$], so that the
$z$-coordinate of $(z_1,w_1) + (z_2,w_2)$ is given
by $F_\e(z_1,z_2)$, where:
$$
F_\e(z_1,z_2)
= z_1 + z_2 + (\hbox{ terms of degree }\geqslant 2) \in \mathbb{Z}[A,B][[z_1,z_2]].
$$
But note that the expression for $z_3$ above consists
of the terms $z_1,z_2$, both homogeneous of weighted degree~$1$,
and the fraction whose numerator $2 A \lambda \mu + 3 B \lambda^2 \mu$
is homogeneous of weighted degree~$1$, and whose
denominator $1 + A \lambda^2 + B \lambda^3$ is homogeneous of
weighted degree~$0$. Therefore the final power series giving
the formal group must be homogeneous of weighted degree~$1$.
\par For the case when our curve is of the form $Y^2 = X^3 + AX$
(so that $B=0$),
each term of the formal group must be an integer multiple
of $A^k z_1^{n_1} z_2^{n_2}$.
Since the weighted degree is~1 and since $A$ has weight~$-4$,
we see that the degree purely in $z_1,z_2$ must by $\equiv 1$
mod~$4$, as required.
\par When our curve is of the form $Y^2 = X^3 + B$ (so that $A = 0$)
the fact that $B$ has weight~$-6$ similarly gives that
each term of the formal group has degree $\equiv 1$
mod~$6$ in $z_1,z_2$.

\item First we show convergence of the right hand side. For each $i$, set $g_i = G_i(x_1,\ldots,x_l)$. We have $|g_i| \le \max(|x_i|) < 1$. Choose $\rho < 1$ such that $\max(|x_i|) = \rho\delta$ with $\delta < 1$.  Since $\{|a_n|\rho^{\sum n_i}\}$ is bounded, say by $C$, we have \[\left|\sum_{n: \sum n_i \ge N} a_n g_1^{n_1}\cdots g_k^{n_k}\right| \le C \delta^N.\] It follows that the right hand side converges, and is the limit of the sequence \[\sum_{n: \sum n_i \le N-1} a_n g_1^{n_1}\cdots g_k^{n_k}\] as $N \to \infty$. 

Write $G_i = \sum b_{i,m} X_1^{m_1} \ldots X_l^{m_l}$ and for a positive integer $M$ consider the finite truncations $G_{i,M} = \sum_{\sum m_i \le M-1} b_{i,m} X_1^{m_1} \ldots X_l^{m_l}$ with values $g_{i,M}$ when we substitute the $x_i$. 

We have \[\left|a_n g_1^{n_1}\cdots g_k^{n_k}-a_n g_{1,M}^{n_1}\cdots g_{k,M}^{n_k}\right| =\left|a_n(g_1^{n_1}\cdots g_k^{n_k}- g_{1,M}^{n_1}\cdots g_{k,M}^{n_k})\right|   \le |a_n|\rho^M\delta^M,\] since all the terms which appear in $g_1^{n_1}\cdots g_k^{n_k}$, but not in $g_{1,M}^{n_1}\cdots g_{k,M}^{n_k}$, have valuation $\le \rho^M\delta^M$. We deduce that \[F(g_1,\ldots,g_k) - \sum_{n: \sum n_i \le N-1} a_n g_{1,N}^{n_1}\cdots g_{k,N}^{n_k}\] \[\le \max(C\delta^N,|a_n| \rho^N\delta^N : \sum n_i \le N-1) = C\delta^N.\]

On the other hand, if we consider the formal power series $F\circ G$ then the difference \[(F\circ G)
-  \sum_{n: \sum n_i \le N-1} a_n G_{1,N}^{n_1}\cdots G_{k,N}^{n_k}\] only contains terms of degree $\ge N$. From this and the condition on the $|a_n|$, it follows easily that $(F\circ G)(x_1,\ldots,x_l)$ converges and its value is the limit of \[\sum_{n: \sum n_i \le N-1} a_n g_{1,N}^{n_1}\cdots g_{k,N}^{n_k}\] as $N \to \infty$.

\end{enumerate}

\end{document}


