\documentclass[a4paper]{article}

\usepackage{amsmath,amssymb,amsthm,enumerate,eucal,tikz}


\input amssym.def 
\input amssym.tex
%\def\Bbb{\bf}
%\nopagenumbers
%% \magnification=\magstep1
%\hoffset=1truecm
%\voffset=2truecm
%\baselineskip = 5.2 true mm
%\def\notdiv{{\not\hskip-.5pt |\ }}
%\font\frkkk=eufm10
%\font\twelverm=cmr12
%\font\tenrm=cmr10
%\font\ninerm=cmr9
%\font\ninebf=cmbx9
%\font\eightrm=cmr8
%\font\sixrm=cmr6
%\font\sevrm=cmr7
%\font\scrpp=eusm10 
%\font\frkk=eufm10
%\font\deffont=cmssi10
%\font\chaptitle=cmbx10 at 14 pt
%\tolerance=10000
\def\sqr{\ifmmode\square\else{$\square$}\fi}
\def\square{\vcenter{
            \hrule height.1mm
            \hbox{\vrule width.1mm height2.2mm\kern2.18mm\vrule width.1mm}
            \hrule height.1mm}}                  % This is a slimmer sqr.
%\def\sqr{$\vcenter{\hrule height .3mm
%\hbox {\vrule width .3mm height 2mm \kern 1.4mm
%\vrule width .3mm} \hrule height .3mm}$}
%
\null
%
%\vsize=19.5 true cm
%\hsize=11.5 true cm
%\vskip 5 true cm
\def\leqslant{\le}
\def\geqslant{\ge}
\def\c{{\cal C}}
\def\d{{\cal D}}

\def\C{{\cal C}}
\def\D{{\cal D}}


\def\pk{\phi _\kappa}
\def\im{{\hbox{\sl im}}}
\def\hs{H_{\varsigma}}
\def\hpk{\hat \phi _\kappa}
\font\sc=cmssqi8 
\def\scc#1{\hbox{\sc #1}}
\def\sf{{\scc F}}
\def\pnbq{{\Bbb P}^n(\overline {\Bbb Q} )}
\def\hk{{\hat \kappa}}
\def\bq{{\overline {\Bbb Q}}}
\def\hq{{\hat q}}
\def\pv{\prod\limits_v }
\def\pnk{{\Bbb P}^n(K)}
\def\mnkvw{{\Bbb M}^n(K[{\bf v}^2,{\bf w}^2])}
\def\pnkv{{\Bbb P}^n(K[{\bf v}^2])}
\def\kj{\kappa (J)}
\def \qmods {{\mathbb Q}^*/({\mathbb Q}^*)^2}
\def \qmodss { {\Bbb Q}^*/({\Bbb Q}^*)^2 \times 
  {\Bbb Q}^*/({\Bbb Q}^*)^2 }
\def \qs{{\Bbb Q}^*}
\def \qss{({\Bbb Q}^*)^2}
\def\bbQ{\Bbb Q}
\def\bbF{\Bbb F}
\def\bbZ{\Bbb Z}
\def\bbR{\Bbb R}
\def\bbC{\Bbb C}
\def\R{\Bbb R}
\def\Q{\mathbb Q}
\def\Z{\mathbb{Z}}
\def\F{\Bbb F}
\def\e{{\mathcal E}}

\def\q{\mathbb Q}
%

\def\etq{{\mathcal E}_{\mathrm{tors}}({\mathbb Q})}
\def\ctq{{\mathcal C}_{\mathrm{tors}}({\mathbb Q})}
\def\cotq{{\mathcal C}_{\mathrm{oddtors}}({\mathbb Q})}
\def\dotq{{\mathcal D}_{\mathrm{oddtors}}({\mathbb Q})}

\def\g{{\cal G}}
\def\h{{\cal H}}


\begin{document}

\noindent
\centerline{{\bf Elliptic Curves: Solutions to Sheet 4}}
\bigskip

\begin{enumerate}[{\bf (1)}]

\item
Let $\phi : \c (\q ) \rightarrow \d (\q)$
be the usual isogeny, which is a group homomorphism with
kernel: $\mathbf{o}, (0,0)$, and let $\hat\phi : \d (\q ) \rightarrow \c (\q)$
be the usual dual isogeny, which is also a group homomorphism with 
kernel: $\mathbf{o}, (0,0)$. Now, let $\cotq$ be the set of torsion
elements of $\c (\q)$ which have odd order. First check
that $\cotq$ is a subgroup: (1) The identity {\bf o} has order~1,
which is odd, so ${\bf o}\in \cotq$, (2) If $P,Q$ have odd torsion
orders $m,n$, respectively, then $mn(P+Q) = n(mP) + m(nQ) = {\bf o}$
and so the order of~$P+Q$ divides $mn$, giving that the order
of $P+Q$ is odd, i.e.\ $P+Q
\in \cotq$, (3) The order of $-P$ is the same as the order
of $P$, so $P\in\cotq \Rightarrow -P \in \cotq$. Similarly
define $\dotq$, a subgroup of $\d (\q)$. 
\par
Now, consider any $P\in \cotq$. Then $P$ must have odd
order~$m$, say. Let $R = \phi (P)$. Then $mR = m\phi(P)
= \phi (mP) = \phi ({\bf o}) = {\bf o}$, which means
that the order of~$R$ divides~$m$, and so the order
of~$R$ is odd; that is: $R\in \dotq$. Hence, $\phi$
gives a map from $\cotq$ to $\dotq$, which certainly satisfies
the homomorphism property $\phi (P+Q) = \phi(P) + \phi(Q)$
for all $P,Q\in \cotq$, since
$\phi$ satisfies this property on the larger set $\c (\q )$.
Furthermore,
the kernel of $\phi : \cotq \rightarrow \dotq$ must only
contain {\bf o} [since $(0,0) \not\in \cotq$], and so
$\phi : \cotq \rightarrow \dotq$ is an injection. We have therefore
established that there is an injective homomorphism
 from $\cotq$ to $\dotq$, which implies
that $\cotq$ is isomorphic to a subgroup of $\dotq$.
Applying the same argument to $\hat\phi : \dotq \rightarrow \cotq$
gives that $\dotq$ is isomorphic to a subgroup of $\cotq$.

Since $\cotq$ and $\dotq$ are finite groups, we deduce that we have inequalities $|\cotq| \le |\dotq|$ and $|\dotq|\le |\cotq|$, hence $|\cotq| = |\dotq|$. Now $\phi : \cotq \rightarrow \dotq$ is an injective homomorphism between finite groups of the same size, and is hence an isomorphism. 

\item
The preimages of~$(0,0)$ under $\hat\phi$
are given by the points of order~2 on $\d$ distinct from~$(0,0)$,
namely $Q_1 = ((-a_1 + \sqrt{a_1^2 - 4b_1})/2,0) = (a + 2\sqrt{b},0)$ and
$Q_2 = ((-a_1 - \sqrt{a_1^2 - 4b_1})/2,0) = (a - 2\sqrt{b},0)$.
Recall
the standard map from lectures $q : \d (\q) \rightarrow \qmods$
which takes ${\bf o} \rightarrow 1$, $(0,0) \rightarrow b_1$,
and otherwise takes $(u,v) \rightarrow u$. We know from lectures
that this map has kernel precisely $\phi ( \c (\Q ))$.
Now, the multiplication by 2 map on $\c (\Q)$ is $\hat\phi \circ \phi$,
and so $(0,0) \in 2\c (\Q)$ iff either $Q_1$ or $Q_2$
is a member of $\phi (\c (\Q) )$. In particular, the $Q_i$ need to be in $\d(\Q)$ which is equivalent to $b = m^2$ for some $m \in \Z$. The additional condition that $Q_i \in \phi(\c(\Q))$ is equivalent to $q(Q_i) = 1$, or $a \pm 2m \in (\Q^\ast)^2$. Finally, since $a \pm 2m \in \Z$, this condition is equivalent to the existence of $n \in \Z$ with $a \pm 2m = n^2$. Changing the sign of $m$ if necessary gives the desired result. 

\newpage

\item
{\bf (a).} The map is well-defined since $\hat{\phi} \circ \phi = [2]$ and is obviously
surjective.

Let $[P] \in  \h /\phi(\g)$ map to $[o]$, i.e. $\hat{\phi}(P + \phi(\g)) = [o]$, that is
$\hat{\phi}(P) + 2\g = 2\g$ so $\hat{\phi}(P) \in 2\g$.
Then $\hat{\phi}(P) = 2R$ for some $R \in \g$. Hence $\hat{\phi}(P - \phi(R)) = o$ 
as $\hat{\phi} \circ \phi = [2]$. From lectures (Lemma 6.1) we know $P - \phi(R) = o$ or
$P - \phi(R) = (0,0)$. Hence $[P]$ in $\h /\phi(\g)$ is $[o]$ or $[(0,0)]$.

{\bf (b).} We thus get $ \hat{\phi}(\h) / 2 \g$ is $C_2^{b}$ or $C_2^{b-1}$ according to whether the 
class $[(0,0)]$ is trivial or not. The result now follows from the isomorphism of groups
\[ \g / \hat{\phi}(\h) \cong \g  /  2 \g   \, / \, \hat{\phi}(\h) / 2 \g.\]

{\bf (c).} 
Assume $\phi(P) = (0,0)_{\h}$ for some $P \in \g$. Applying $\hat{\phi}$ to both sides we see $2 P = \hat{\phi}((0,0)_\h) = o_\g$.
But $P$ cannot be $(0,0)_\g$ for then we'd have $\phi(P) = o_\h$. So we have an additional $2$-torsion point in $\g$ and
the $2$-torsion is $C_2^2$.

Conversely, assume that the $2$-torsion in $\g$ is $C_2^2$ and let $P \in \g$ with $P \ne (0,0)_\g$ and $2P = o_\g$.
Then we have $\hat{\phi} (\phi(P)) = o_\g$ and by Lemma 6.1 again we see $\phi(P) = o_\h$ or $(0,0)_\h$. But since $P \ne (0,0)_\g$
we cannot have the former.

Recall that $\g/2\g \cong C_2^{r+t}$ where $r$ is the rank and $\g[2] \cong C_2^t$. We have either $t = 1$ or $2$. In the first case, $(0,0) \not \in \phi(\g)$, so the rank is $(a+b-1)-t = a + b -2$. In the second case, $(0,0) \in \phi(\g)$, so the rank is  $(a + b) - t = a+b-2$.

\item
\par\noindent{\bf (a).}
Consider $\c : Y^2 = X(X^2 + aX + b) = X(X^2 + 2X + 3)$,
where $a=2, b=3$,
and the isogenous curve $\d : Y^2 = X(X^2 + a_1X + b_1) = X(X^2 - 4X - 8)$,
where $a_1 = -4, b_1=-8$,
with the usual isogeny $\phi : \c (\Q ) \rightarrow 
\d (\Q) : (x,y) \mapsto (y^2/x^2 , y - 3y/x^2)$,
and dual isogeny $\hat\phi : \d (\Q ) \rightarrow 
\c (\Q) : (u,v) \mapsto ( {1\over 4} v^2/u^2 , {1\over 8}( v + 8v/u^2) )$. 
%{\bf [3~marks]}
\par
The map $q : \d (\Q) / \phi (\c (\Q)) \rightarrow \qmods : (u,v) \mapsto u$,
for $(u,v) \not= (0,0)$, with $q : (0,0) \mapsto b_1$
and $q: {\bf o} \mapsto 1$, is an injection with $\hbox{im}(q)$
contained in $\{ d : d\hbox{ is square free and } d | b_1\}
= \{ \pm 1 , \pm 2 \}$. Also, 
$(0,0) \mapsto -8 = -2$, so that
$\{ 1,-2 \} \subset \hbox{im} q \subset \{ \pm 1 , \pm 2\}$.
%{\bf [3 marks]}
\par
There is only one coset to check, represented by $-1$, say.
We know that $-1 \in \hbox{im} q$ iff there are integers $\ell , m , n$,
not all~0, and with $\hbox{gcd}(\ell,m) = 1$, such that:
$(-1)\cdot \ell^4 + a_1 \ell^2m^2 + (b_1/(-1))\cdot m^4 = n^2$
that is: $-\ell^4 - 4 \ell^2m^2  + 8 m^4 = n^2$.
Rewrite as: $-(\ell^2 + 2m^2)^2 + 12 m^4 = n^2$. Reducing modulo~3
gives $ - (\ell^2 + 2m^2 )^2 \equiv n^2$ (modulo~3).
If $n$ were
coprime to~$3$, then this would give: $(( \ell^2 + 2 m^2 )/n)^2 = -1$
in $\F_3$, contradicting the fact that~$-1$
is not a quadratic residue modulo~3. So,  
$3 | n$ and so $3 | (\ell^2 + 2m^2 )$ also. This means that
$9 | (\ell^2 + 2m^2 )^2$ and $9 | n^2$, which can be combined
with $-(\ell^2 + 2m^2)^2 + 12 m^4 = n^2$ to give: $9 | 12 m^4$
and so $3 | m$. Combining $3 | m$ with $3 | (\ell^2 + 2m^2 )$
gives that $3 | \ell$. 
This
contradicts the fact that $\hbox{gcd}(\ell,m) = 1$. Hence
our equation is impossible in~$\Q_3$, and so impossible in~$\Q$.
Hence $-1 \not\in \hbox{im} q$.
%{\bf [6 marks]}
\par We conclude that $\hbox{im} q  = \{ 1,-2 \}$, and
so $\d (\Q) / \phi (\c (\Q))$ is generated by~$(0,0)$.
%{\bf [1 mark]}
\par
The map $\hat q : \c (\Q ) / \hat\phi (\d (\Q))
\rightarrow \qmods : (x,y) \mapsto x$,
for $(x,y) \not= (0,0)$, with $\hat q : (0,0) \mapsto b$
and $\hat q: {\bf o} \mapsto 1$, is an injection with $\hbox{im}\hat q$
contained in $\{ d : d\hbox{ is square free and } d | b\}
= \{ \pm 1 , \pm 3 \}$.
Also, ${\bf o} \mapsto 1$ and
$(0,0) \mapsto 3$, so that
$\{ 1,3 \} \subset \hbox{im} \hat q \subset \{ \pm 1 , \pm 3\}$.
%{\bf [3 marks]}
\par There is only one coset to check, represented by $-1$, say.
We know that $-1 \in \hbox{im} \hat q$ iff there are integers
$\ell , m , n$,
not all~0, and with $\hbox{gcd}(\ell,m) = 1$, such that:
$(-1)\cdot \ell^4 + a \ell^2m^2 + (b/(-1))\cdot m^4 = n^2$;
that is: $-\ell^4 + 2\ell^2m^2  - 3 m^4 = n^2$.
Rewrite
as: $ - ( \ell^2 - m^2 )^2 - 2 m^4 =  n^2$. This is impossible
in~$\R$ (the left hand side is $\leqslant 0$ and the
right hand side is $\ge 0$, and equality only occurs when
$\ell^2 - m^2 = m^4 = n^2 = 0$, implying $\ell = m = n = 0$, which is
not allowed).
Hence $-1 \not\in \hbox{im} \hat q$.
%{\bf [4 marks]}
\par  We conclude that $\hbox{im} \hat q  = \{ 1,3 \}$, and    
so $\c (\Q) / \hat\phi (\d (\Q))$ is generated by~$(0,0)$.
%{\bf [1 mark]}
\par Finally, since multiplication by 2 in $\c (\Q)$
is $\hat\phi \circ \phi$,
we have that $\c (\Q) / 2\c (\Q)$ is generated by: generators for
$\c (\Q) / \hat\phi (\d (\Q))$ [namely: $(0,0)$] together with
the images under $\hat \phi$ of generators for $\d (\Q) / \phi (\c (\Q))$
[namely, $\hat\phi \bigl( (0,0) \bigr) = {\bf o}$]. Conclusion:
$\c (\Q ) / 2\c(\Q )$ is generated by $(0,0)$, and so is isomorphic
to $C_2$. We also know that $\c (\Q ) / 2\c(\Q )$ is isomorphic to
$\ctq / 2\ctq \times C_2^r$,
which is isomorphic to $\c (\Q )[2] \times C_2^r$, where $\c (\Q )[2]$
is the $2$-torsion group and $r$ is the rank. We know that $(0,0) \in \c (\Q )[2]$, so we deduce that $r = 0$. 

\par\noindent
{\bf (b).} Let $\c : Y^2 = X(X^2 + aX + b) = X(X^2 + 14X + 1)$,
where $a=14, b=1$,
and isogenous curve $\d : Y^2 = X(X^2 + a_1X  + b_1 ) = X(X^2 - 28X +192)$,
where $a_1 = -28, b_1=192$,
with the usual isogeny $\phi : \c (\Q ) \rightarrow 
\d (\Q) : (x,y) \mapsto (y^2/x^2 , y - y/x^2)$,
and dual isogeny $\hat\phi : \d (\Q ) \rightarrow 
\c (\Q) : (u,v) \mapsto ( {1\over 4} v^2/u^2 , {1\over 8}( v - 192 v/u^2) )$. 
\par
The map $q : \d (\Q) / \phi (\c (\Q)) \mapsto \qmods : (u,v) \mapsto u$,
for $(u,v) \not= (0,0)$, with $q : (0,0) \mapsto b_1$
and $q: {\bf o} \mapsto 1$, is an injection with $\hbox{im}q$
contained in $\{ d : d\hbox{ is square free and } d | b_1\}
= \{ \pm 1 , \pm 2, \pm 3, \pm 6 \}$. Also, ${\bf o} \mapsto 1$,
$(0,0) \mapsto 192 = 3$ and the point $(8,16) \mapsto 2$
[N.B. when searching for a point in~$\d (\Q)$ which might
map to~$2$ under~$q$, one need only try points with $x$-coordinate
equal to~$2$ modulo squares, e.g.~2,8,1/2,18,etc, so one should
find the point $(8,16)$ quickly; also, it's a good idea at the
outset just to look for ``obvious'' members of $\d (\q )$
with $x$ coordinates being integers in the range from $-10$ to $10$;
doing this at the outset would also reveal the point $(8,16)$.]
This means that
$1,3,2 \in \hbox{im} q$; but $\hbox{im} q$ is a group, so
$6 \in \hbox{im} q$ also (indeed $(0,0) + (8,16) = (24,-48)$, which maps to $6$ under $q$.
Hence,
$\{ 1,2,3,6 \} \subset \hbox{im} q \subset \{ \pm 1 , \pm 2,\pm 3, \pm 6\}$.
\par
There is only one coset to check, represented by $-1$, say.
We know that $-1 \in \hbox{im} q$ iff there are integers $\ell , m , n$,
not all~0, and with $\hbox{gcd}(\ell,m) = 1$, such that:
$(-1)\cdot \ell^4 + a_1 \ell^2m^2 + (b_1/(-1))\cdot m^4 = n^2$
that is: $-\ell^4 - 28 \ell^2m^2  - 192 m^4 = n^2$.
We can see that
the LHS is $\leqslant 0$ and the RHS is $\geqslant 0$,
and there is equality iff $\ell =  m = n = 0$, a contradiction.
Hence $-1 \not\in \hbox{im} q$. We conclude
that $\hbox{im} q = \{ 1,2,3,6 \}$ and that
$\d (\Q) / \phi (\c (\Q)) = \{ {\bf o}, (0,0), (8,16), (24,-48) \}$,
and so $\d (\Q) / \phi (\c (\Q))$ is generated by $(0,0)$ and $(8,16)$.
\par
The map $\hat q : \c (\Q ) / \hat\phi (\d (\Q))
\mapsto \qmods : (u,v) \mapsto u$,
for $(u,v) \not= (0,0)$, with $\hat q : (0,0) \mapsto a_1^2 - 4b_1 = b$
and $\hat q: {\bf o} \mapsto 1$, is an injection with $\hbox{im}\hat q$
contained in $\{ d : d\hbox{ is square free and } d | b\}
= \{ \pm 1 \}$. 
Also, ${\bf o} \mapsto 1$ and
$(0,0) \mapsto 1$, so that
$\{ 1 \} \subset \hbox{im} \hat q \subset \{ \pm 1 \}$.
\par There is only one coset to check, represented by $-1$, say.
We know that $-1 \in \hbox{im} \hat q$ iff there are integers
$\ell , m , n$,
not all~0, and with $\hbox{gcd}(\ell,m) = 1$, such that:
$(-1)\cdot \ell^4 + a \ell^2m^2 + (b/(-1))\cdot m^4 = n^2$;
that is: $-\ell^4 + 14\ell^2m^2 - m^4 = n^2$.
Rewrite
as: $ - (  \ell^2 - 7 m^2 )^2 + 48 m^4 = n^2$.
Reducing modulo~3
gives: $ - ( \ell^2 - 7 m^2 )^2 \equiv n^2$ (modulo~3). If $n$ were
coprime to~$3$, then this would give: $(( \ell^2 - 7 m^2 )/n)^2 = -1$
in $\F_3$, contradicting the fact that~$-1$
is not a quadratic residue modulo~3. So,
$3 | n$ and so $3 | ( \ell^2 - 7 m^2 )$, also. Hence $9$ divides
$(  \ell^2 - 7 m^2 )^2$ and $n^2$ and so must divide $48 m^4$;
but $48$ is only divisible by $3$ (not by~$9$) so that $3$ must divide
$m^4$; hence $3$ divides $m$. Combining this with the fact (already
found) that
$3 | ( \ell^2 - 7 m^2 )$ gives that $3 | \ell$ also. We've shown
that $3$ divides all of $\ell,m,n$, a contradiction.
Hence $-1 \not\in \hbox{im} \hat q$.
\par  We conclude that $\hbox{im} \hat q  = \{ 1 \}$, and    
so $\c (\Q) / \hat\phi (\d (\Q))$ contains only {\bf o}.
[N.B. $(0,0)$ should not also be included as a separate member
of $\c (\Q) / \hat\phi (\d (\Q))$ even
though it is a rational point; $(0,0)$ maps to~1 under~$\hat q$, and so
$(0,0) \in \hat\phi (\d (\Q))$; that is $(0,0) = {\bf o}$ in
$\c (\Q) / \hat\phi (\d (\Q))$; the same comment applies to
the obvious point $(1,4)$; in general, for each distinct member $r$ of
$\hbox{im} \hat q$, you should only include exactly one point in $\c (\Q)$
which maps to~$r$]. 
\par Finally, since multiplication by 2 in $\c (\Q)$
is $\hat\phi \circ \phi$,
we have that $\c (\Q) / 2\c (\Q)$ is generated by: generators for
$\c (\Q) / \hat\phi (\d (\Q))$ [namely: {\bf o}] together with
the images under $\hat \phi$ of generators for $\d (\Q) / \phi (\c (\Q))$
[namely, $\hat\phi \bigl( (0,0) \bigr) = {\bf o}$
and $\hat\phi \bigl( (8,16) \bigr) = (1,-4)$]. Conclusion:
$\c (\Q ) / 2\c(\Q )$ is generated by $(1,-4)$,
and so is the group $C_2$.
Now $\c (\q)/2\c (\q)$ is isomorphic to $\ctq/2\ctq \times C_2^{rank}$, and
$\ctq /2\ctq$ is isomorphic to the $2$-torsion group of $\ctq$
which is $C_2$ (consisting only of {\bf o} and $(0,0)$),
so that
$\ctq/2\ctq$ is isomorphic to~$C_2$. Conclusion: rank~$=0$. [If this
seems surprising, then note that $(1,4),(1,-4)$ are points of
order~$4$ in $\c (\q)$].
%\par\noindent {\bf (d).} $Y^2 = X(X^2 + 2X + 9)$.  
%\par\noindent {\bf (e).} $Y^2 = X(X^2 + 9X - 1)$.    
%\par\noindent {\bf (f).} $Y^2 = X(X-12)(X-36)$. 
\medskip

\item
Let $\C : Y^2 = X(X^2 + aX + b) = X(X^2 + p^2)$,
where $a=0, b=p^2$,
and isogenous curve $\D : Y^2 = X(X^2 + a_1X  + b_1 ) = X(X^2 - 4p^2)$,
where $a_1 = -2a = 0, b_1= a^2 - 4b = -4p^2$,
with the usual isogeny $\phi : \C (\Q ) \rightarrow 
\D (\Q) : (x,y) \mapsto (y^2/x^2 , y - p^2y/x^2)$,
and dual isogeny $\hat\phi : \D (\Q ) \rightarrow 
\C (\Q) : (u,v) \mapsto ( \frac{1}{4} v^2/u^2 , \frac{1}{8}(v + 4p^2v/u^2))$. 
\par
The map $q : \D (\Q) / \phi (\C (\Q)) \mapsto \qmods : (u,v) \mapsto u$,
for $(u,v) \not= (0,0)$, with $q : (0,0) \mapsto b_1$
and $q: {\bf o} \mapsto 1$, is an injection with $\hbox{im}q$
contained in $\{ d : d\hbox{ is square free and } d | b_1\}
= \{ \pm 1 , \pm 2, \pm p, \pm 2p \}$. Also, ${\bf o} \mapsto 1$,
$(0,0) \mapsto -1$, $(2p,0)\mapsto 2p$, $(-2p,0)\mapsto -2p$, so that 
$\{ \pm 1,\pm 2p \} \subset \hbox{im} q \subset 
\{ \pm 1 , \pm 2, \pm p, \pm 2p \}$.
There is only one coset to check, represented by~$-2$, say.
We know that $-2 \in \hbox{im} q$ iff there are integers
$\ell , m , n$,
not all~0, and with $\hbox{gcd}(\ell,m) = 1$, such that:
$(-2)\cdot \ell^4 + a_1 \ell^2m^2 + (b_1/(-2))\cdot m^4 = n^2$;
that is: $-2\ell^4 + 2 p^2 m^4 = n^2$.
Since $p\equiv 5$~(mod~$8$), $\bigl( \frac{-2}{p} \bigr) = -1$,
and so $p | \ell$, $p | n$. Let $\ell = p \ell'$, $n = p n'$.
Then $-2 p^2 (\ell')^4 + 2 m^4 = (n')^2$. Since
also $\bigl( \frac{2}{p} \bigr) = -1$, this
implies $p | m$, $p | n'$. This gives a contradiction,
since $p| \ell, p | m$ and $\hbox{gcd}(\ell,m) = 1$.
Hence~$-2\not\in \hbox{im} q$, giving that
$\hbox{im} q = \{ \pm 1 , \pm 2p \}$,
and $\D (\Q) / \phi (\C (\Q)) = \{{\bf o}, (0,0), (2p,0), (-2p,0)\}$.\\

\par
The map $\hat q : \C (\Q ) / \hat\phi (\D (\Q))
\mapsto \qmods : (u,v) \mapsto u$,
for $(u,v) \not= (0,0)$, with $\hat q : (0,0) \mapsto a_1^2 - 4b_1 = b$
and $\hat q: {\bf o} \mapsto 1$, is an injection with $\hbox{im}\hat q$
contained in $\{ d : d\hbox{ is square free and } d | b\}$
$= \{ \pm 1 , \pm p\}$. 
Also, ${\bf o} \mapsto 1$ and
$(0,0) \mapsto p^2 = 1$, so that
$\{ 1 \} \subset \hbox{im} \hat q \subset \{ \pm 1 , \pm p\}$.
\par
We know that $-1 \in \hbox{im} \hat q$ iff there are integers
$\ell , m , n$,
not all~0, and with $\hbox{gcd}(\ell,m) = 1$, such that:
$(-1)\cdot \ell^4 + a \ell^2m^2 + (b/(-1))\cdot m^4 = n^2$;
that is: $-\ell^4 - p^2 m^4 = n^2$, clearly impossible in $\R$.
Hence~$-1\not\in \hbox{im} \hat q$. Similarly, $-p\not\in\hbox{im} \hat q$.
We know that $p \in \hbox{im} \hat q$ iff there are integers
$\ell , m , n$,
not all~0, and with $\hbox{gcd}(\ell,m) = 1$, such that:
$p\cdot \ell^4 + a \ell^2m^2 + (b/p)\cdot m^4 = n^2$;
that is: $p\ell^4 + p m^4 = n^2$, and so $p | n$. Letting $n = p n'$,
the equation becomes $\ell^4 + m^4 = p^2 (n')^2$, which 
in turn implies $p | \ell, p | m$, since $-1 \not\equiv a^4$
for any~$a$ [as can be seen by taking both sides of $-1 \equiv a^4$
to the power of $(p-1)/4$]. This again contradicts $\hbox{gcd}(\ell,m) = 1$,
and so $p\not\in \hat q$.
We conclude that $\hbox{im} \hat q  = \{ 1 \}$, and    
so $\C (\Q) / \hat\phi (\D (\Q)) = \{ \bf o\}$.\\

\par Finally, since multiplication by 2 in $\C (\Q)$
is $\hat\phi \circ \phi$,
we have that $\C (\Q) / 2\C (\Q)$ is generated by: generators for
$\C (\Q) / \hat\phi (\D (\Q))$ [namely: $\bf o$] together with
the images under $\hat \phi$ of generators for $\D (\Q) / \phi (\C (\Q))$
[namely, $\hat\phi \bigl( (0,0) \bigr) = {\bf o}$,
and
$\hat\phi \bigl( (2p,0) \bigr) = (0,0)$]. Conclusion:
$\C (\Q ) / 2\C(\Q )$ is generated by $(0,0)$,
and so is the group $C_2$. 
Now $\C (\Q)/2\C (\Q)$ is isomorphic to $\C(\Q)_{tors}/2\C(\Q)_{tors} \times C_2^{rank}$, and
$\C(\Q)_{tors} /2\C(\Q)_{tors}$ is isomorphic to the $2$-torsion group of $\C(\Q)_{tors}$
which is $C_2$ (consisting only of {\bf o} and $(0,0)$), so that
$\C(\Q)_{tors}/2\C(\Q)_{tors}$ is isomorphic to $C_2$. Conclusion: rank $=0$.



\item
We are given that $A,+$ is an Abelian group,
and that $h : A \rightarrow \R_{\ge 0}$ satisfies:
\par\noindent \ \ \ \ (I) There exists a constant~$C$, 
independent of~$P,Q$, such that
\par \ \ \ \ $ | h(P+Q) + h(P-Q) - 2 h(P) - 2 h(Q) | \le C $, 
for all $P,Q \in A$,
\par\noindent \ \ \ \ (II) For any~$B\in\R$, 
the set $\{P\in A:h(P)\le B\}$ is finite.
\par From~(I) we obtain: $h(P+Q) + h(P-Q) - 2 h(P) - 2 h(Q) \le C $
and so (since $h(P-Q) \ge 0$): $h(P+Q) \le h(P+Q) + h(P-Q)
\le 2 h(P) + 2 h(Q) + C \le 2 h(P) + C_1(Q)$, where
$C_1(Q) = 2 h(Q) + C$. Hence Property~(1) in the definition
of height function is satisfied.
\par Letting $Q=P$ in~(I), we obtain:
\par \ \ \ \ $ | h(2P) + h(e) - 4 h(P) | \le C, \ \ \ \ (*) $
\par\noindent where~$e$ denotes the identity element of the
group~$A$. This gives: $h(2P) + h(e) - 4 h(P) \ge -C$,
and so: $h(2P) \ge 4 h(P) - C_2$, where $C_2 = C + h(e)$.
Hence Property~(2) in the definition
of height function is satisfied. Furthermore, (II) is the
same as Property~(3) in the definition of height function.
Hence all~3 required properties are satisfied, giving
that~$h$ is a height function, as required.
\par Replacing $P,Q$ in~(I) with $2P,P$, respectively, gives:
\par \ \ \ \ $ | h(3P) - 2 h(2P) - h(P) | \le C $.
\par\noindent Multiplying $(*)$ by~$2$ gives:
\par \ \ \ \ $ | 2 h(2P) + 2 h(e) - 8 h(P) | \le 2C$.
\par\noindent These last two equations then give:
\par $ | h(3P) - 9 h(P) | 
  = | h(3P) - 2 h(2P) - h(P) + 2 h(2P) + 2 h(e) - 8 h(P) - 2 h(e) |$
\par\ \ \ \ \ $\le | h(3P) - 2 h(2P) - h(P) | 
+ | 2 h(2P) + 2 h(e) - 8 h(P) | + 2 | h(e) | \le C_3,$
\par\noindent where $C_3 = 3C + 2 | h(e) |$ (which is independent
of~$P$).
\medskip

\item
In all of the following, each step multiplies
numbers $\leqslant N$ (followed by a possible reduction
modulo~$N$), and so we are guaranteed that
everything can be done on an $9$-digit
calculator, since $N^2$ has only 9~digits.
\par\noindent {\bf (a).} First compute (modulo $N=10481$):
$2^1 \equiv 2$, $2^2 \equiv 4$, $2^4 \equiv 16$, $2^8 \equiv 256$,
$2^{16} \equiv 2650$, $2^{32} \equiv 230$
(where each of these
was obtained be squaring the previous one, and reducing modulo~$N$). 
Now, we write $46$ in base~2: $46 = 2 + 4 + 8 + 32$ and
so $2^{46} \equiv 2^2 2^4 2^8 2^{32} \equiv 
4\cdot 16 \cdot 256 \cdot 230 \equiv 64\cdot 6475
\equiv 5641$ modulo~$N$, 
so that $2^{46} - 1 \equiv 5640$ modulo~$N$.
\par
Now, compute $\hbox{gcd}(5640, N)$ by Euclid's Algorithm:
$10481 = 1 \cdot 5640 + 4841$; $5640 = 1\cdot 4841 + 799$;
$4841 = 6\cdot 799 + 47$, $799 = 17\cdot 47 + 0$.
So, $47$ is a factor of $N$.
Compute $10481/47 = 223$, giving the factorisation
$N = 10481 = 47 \cdot 223$. %{\bf [7~marks]} 
\par\noindent {\bf (b).} The line tangent to~$\e$ at $P=(5,11)$
has slope $y'$ given by $2yy' = 3x^2 - 1$, with $x=5,y=11$;
that is, the slope is $74/22 = 37/11$. This tangent line also goes
through $(5,11)$ and so has equation: $Y = (37/11)X - 64/11$.
The $x$-coordinate of $2P$ is therefore $(37/11)^2 - (5+5) = 159/121$.
[It will turn out not to be necessary to evaluate this
mod~$N$, although if this is done using EA, then it is~7364],
and the $y$-coordinate is: $-((37/11)\cdot (159/121) - (64/11))
= 1861/1331$ [again, although unnecessary in this example,
this can be computed by EA to be: 6679 mod~N], 
so that $Q = 2P = (159/121 , 1861/1331)$. We now wish
to compute $3P = P + Q$, and so again the first step
is to find the line joining $P$ and $Q$. This has
slope given by $(1861/1331 - 11)/(159/121 - 5) = 6930/2453$,
and so we need to compute $6930/2453$
(modulo~$N=10481$), for which the first step is to find the
inverse of $2453$ (modulo~$N=10481$).
Using Euclid's Algorithm: $10481 = 4\cdot 2453 + 669$;
$2453 = 3 \cdot 669 + 446$; $669 = 1\cdot 446 + 223$;
$446 = 2\cdot 223 + 0$. So, we cannot
find the inverse of $2453$ (modulo~$N=10481$), and this
step has given us a factor~$223$ of~$N$. As before,
compute $10481/223 = 47$, giving the factorisation
$N = 10481 = 47 \cdot 223$. %{\bf [10~marks]}
\par\noindent {\bf (c).}  Since $N = 47 \cdot 223$, we have
$\phi (N) = 46 \cdot 222 = 10212$. Compute the gcd of $d=4085$ and
$\phi(N)$, we see:
$10212 = 2\cdot 4085 + 2042$; $4085 = 2\cdot 2042 + 1$,
so that $\hbox{gcd}(10212,4085) = 1$. Reversing the steps:
$1 = 4085 - 2\cdot 2042 = 4085 - 2\cdot (10212 - 2\cdot 4085)
= 5\cdot 4085 - 2\cdot 10212$.
Hence, $5$ is the inverse of
$4085$ modulo~$10212$.
The decoding operation is therefore $X \mapsto X^{5} \hbox{ mod }N$.
Computing $6012^{5} = 
(6012^2)^2 \cdot 6012
\equiv 
5656^2\cdot 6012
\equiv
2324\cdot 6012
\equiv
715$.
(modulo~$N = 10481$). Also:
$3236^{5} =
(3236^2)^2 \cdot 3236
\equiv
1177^2 \cdot 3236
\equiv
1837 \cdot 3236
\equiv
1805$
(modulo~$N = 10481$). The decoded
message is therefore: $0715,\, 1805$; that is: GORE.
\medskip




\end{enumerate}

\end{document}


