%% Delete everything above this line and latex the resulting file. %%%
%%% LaTeX 2e

\documentclass{amsart}
\usepackage{amscd}
\usepackage{latexsym}
\usepackage{graphicx}

\newfont{\cyr}{wncyr10 scaled \magstep1}
\newcommand{\Sha}{\hbox{\cyr Sh}}
% The following line is Toby's suggestion for getting the
% word "Section" into the section titles. Unfortunately,
% it messes up the numbering of the defns, thms, etc.
%\renewcommand{\thesection}{Section \arabic{section}}
% The following makes sure that the first section is section 0.
\setcounter{section}{-1}
% The following works on my laptop, but not on University unix
% for getting the work "Section" into the section titles:
\makeatletter
\def\@seccntformat#1{Section \csname the#1\endcsname.\quad}
\makeatother

% The following suppresses bullet points in itemize:
\renewcommand{\labelitemi}{}
{\makeatletter\gdef\reallynopagebreak{\par\nopagebreak\@nobreaktrue}}
% If I want to get the bullets back later in the document:
%\renewcommand{\labelitemi}{$\bullet$}
%\begin{itemize}
%\item Item 1.
%\item Item 2.
%\end{itemize}


%\DeclareFontEncoding{OT2}{}{} % to enable usage of cyrillic fonts
%\newcommand{\textcyr}[1]{%
%  {\fontencoding{OT2}\fontfamily{wncyr}\fontseries{m}\fontshape{n}%
%   \selectfont #1}}
%\newcommand{\Sha}{{\mbox{\textcyr{Sh}}}}
\usepackage{amssymb}
\usepackage{amsfonts}
\def\hp{{\hat\phi}}
\def\hq{{\hat q}}
\def\bbbq{{\mathbb Q}}
\def\bbba{{\mathbb A}}
\def\adeles{{\bbba}_K}
\def\adelesQ{{\bbba}_\bbbq}
\def\bbbc{{\mathbb C}}
\def\bbbz{{\mathbb Z}}
\def\bbbn{{\mathbb N}}
\def\bbbr{{\mathbb R}}
\def\bbbf{{\mathbb F}}
\def\dd{\hbox{d}}
\def\ddd{\mathrm{d}}
\def\qp{{\bbbq_p}}
\def\notdiv{\not \hskip -.2pt | \,\ }
\def\notdivv{\not \hskip -1.2pt | \,\ }
\def\mod{\hbox{mod }}
\def\max{\hbox{max }}
\def\gcd{\hbox{gcd}}
\def\lcm{\hbox{lcm}}
\def\P{{\mathbb P}}
\def\bb{{|\ \, |}}
\def\bp{{|\ \, |_p}}
\def\binf{{|\ \, |_\infty}}
\def\K{{K}}
\def\pp{{\mathfrak{p}}}
\def\m{{m}}
\def\a{{\bf a}}
\def\b{{\bf b}}
\def\c{{\bf c}}
\def\d{{\bf d}}
\def\e{{\bf e}}
\def\f{{\bf f}}
\def\u{{\bf u}}
\def\v{{\bf v}}
\def\w{{\bf w}}
\def\k{{\bf k}}
\def\Fl{{Fl}}
\def\B{{\hbox{B}}}
\def\o{\underline{\bf o}}
\def\uphi{\underline{\phi}}
\def\upsi{\underline{\psi}}
\newcommand{\lb}{[\![}
\newcommand{\rb}{]\!]}

% The following decides whether to use style E_{ij} or E_{i,j} throughout:
\newcommand{\TJFP}{{\widetilde {\mathcal{J}}}({{\bbbf}_p})}
\newcommand{\TJKP}{{\widetilde {\mathcal{J}}}({{k}_\p})}
\newcommand{\KP}{K_\p}
\newcommand{\JKP}{{\mathcal{J}}({K_\p})}
\newcommand{\com}{,}
\newcommand{\fr}{\mathfrak}
\newcommand{\imp}{\Longrightarrow}
\newcommand{\lra}{\longrightarrow}
\newcommand{\non}{\nonumber}
%\newcommand{\tors}{\mbox{tors}}
\newcommand{\tors}{\mathrm{tors}}
%\newcommand{\log}{\mathrm{log}}
\newcommand{\im}{\mbox{im }}
\newcommand{\kker}{\mbox{ker }}
\newcommand{\nin}{\noindent}
\newcommand{\eq}{equation}
\renewcommand{\theenumi}{\roman{enumi}}
\renewcommand{\labelenumi}{(\theenumi)}
\renewcommand{\theenumii}{\alph{enumii}}
\renewcommand{\labelenumii}{(\theenumii)}

%\newcommand{\latop}[2]{{#1\atop#2}}
\newcommand{\latop}[2]{{\genfrac{}{}{0pt}{}{#1}{#2}}}
\newcommand{\lchoose}[2]{{#1\choose#2}}
\newcommand{\ttilde}{\lower4.5pt\hbox{$\widetilde{\ \ \ }$}}
\newcommand{\jqpaqo}{{J(\Q)/\phi_1\bigl(A_1(\Q)\bigr)}}
\newcommand{\jqpaqt}{{J(\Q)/\phi_2\bigl(A_2(\Q)\bigr)}}
\newcommand{\jtqpaqo}{{J_3(\Q)/\phi_1\bigl(A_1(\Q)\bigr)}}
\newcommand{\jfqpaqo}{{J_4(\Q)/\phi_1\bigl(A_1(\Q)\bigr)}}
\newcommand{\jfqpaqt}{{J_4(\Q)/\phi_2\bigl(A_2(\Q)\bigr)}}
\newcommand{\imq}{{\hbox{im}\,q}}
%%%
\def \neweij {(\ref{eq:neweij})}
\def \newpij {(\ref{eq:newepij})}
\def \newepaij {(\ref{eq:newep71ij})}
\def \newepbij {(\ref{eq:newep72ij})}
\def \topeaj {(\ref{eq:tope1j})}
\def \topebj {(\ref{eq:tope2j}) }
\def \refseq {\neweij,\newpij,\newepaij,\newepbij,\topeaj,\topebj}
%%%
\def \qsq {({\Q}^*)^2}
\def \qmsq {{\Q}^*/({\Q}^*)^2}
\def \qpmsq {{\Q_p}^*/({\Q_p}^*)^2}
\def \qtmsq {{\Q_2}^*/({\Q_2}^*)^2}
\def \qimsq {{\Q(i)}^*/({\Q(i)}^*)^2}
\def \qpimsq {{\Q_p(i)}^*/({\Q_p(i)}^*)^2}
\def \qipmsq {\Q(i)_p^*/(\Q(i)_p^*)^2}
\def \qtimsq {{\Q_2(i)}^*/({\Q_2(i)}^*)^2}
\newcommand{\two}{{1+i}}
\def \qitmsq {\Q(i)_\two^*/(\Q(i)_\two^*)^2}
\def \kmsq {{K}^*/({K}^*)^2}
\newcommand{\Lmodsq}{{L_1^*/(L_1^*)^2\times
                      L_2^*/(L_2^*)^2\times L_3^*/(L_3^*)^2}}
\newcommand{\bs}{{\underline s}}
\newcommand{\bt}{{\underline t}}
\newcommand{\bY}{{\underline Y}}
\newcommand{\bx}{{\underline x}}
\newcommand{\by}{{\underline y}}
\newcommand{\ZZ}{\bbbz}
\newcommand{\Z}{\bbbz}
\newcommand{\QQ}{\bbbq}
\newcommand{\Q}{\bbbq}
\newcommand{\R}{\bbbr}
\newcommand{\QA}{\bbbq(\alpha)}
\newcommand{\QB}{\bbbq(\beta)}
\newcommand{\FF}{\bbbf}
\newcommand{\C}{\mathcal{C}}
\newcommand{\LL}{\mathcal{L}}
\newcommand{\M}{\mathcal{M}}
\newcommand{\X}{\mathcal{X}}
\newcommand{\twC}{\mathcal{C}^{\mathrm {tw}}}
\newcommand{\HH}{\mathcal{H}}
\newcommand{\fC}{\mathfrak{C}}
\newcommand{\fE}{\mathfrak{E}}
\newcommand{\fJ}{\mathfrak{J}}
\newcommand{\J}{\mathcal{J}}
\newcommand{\twJ}{{\J}^{\mathrm {tw}}}
\newcommand{\D}{\mathcal{D}}
\newcommand{\E}{\mathcal{E}}
\newcommand{\SSS}{\mathcal{S}}
\newcommand{\tzeta}{{\tilde \zeta}}
\newcommand{\TE}{{\widetilde{\mathcal{E}}}}
\newcommand{\TC}{{\widetilde{\mathcal{C}}}}
\newcommand{\TJ}{{\widetilde{\mathcal{J}}}}
\newcommand{\TD}{{\widetilde{D}}}
\newcommand{\F}{\mathcal{F}}
\newcommand{\G}{\mathcal{G}}
\newcommand{\OO}{\mathcal{O}}
\newcommand{\W}{\mathcal{W}}
\newcommand{\CQ}{\mathcal{C}(\bbbq)}
\newcommand{\DQ}{\mathcal{D}(\bbbq)}
\newcommand{\EOT}{\mathcal{E}_{1\com 2}}
\newcommand{\ETT}{\mathcal{E}_{2\com 2}}
\newcommand{\EQ}{\mathcal{E}(\bbbq)}
\newcommand{\EQP}{\mathcal{E}(\bbbq_p)}
\newcommand{\EQA}{\mathcal{E}(\bbbq(\alpha))}
\newcommand{\EQB}{\mathcal{E}(\bbbq(\beta))}
\newcommand{\EQAT}{\mathcal{E}(\bbbq(\alpha))_\mathrm{tors}}
\newcommand{\EPA}{\mathcal{E}_p^a}
\newcommand{\EPB}{\mathcal{E}_p^b}
\newcommand{\EPAQ}{\mathcal{E}_p^a(\bbbq)}
\newcommand{\EPBQ}{\mathcal{E}_p^b(\bbbq)}
\newcommand{\EPAQT}{\mathcal{E}_p^a(\bbbq)_\mathrm{tors}}
\newcommand{\EPBQT}{\mathcal{E}_p^b(\bbbq)_\mathrm{tors}}
\newcommand{\JQ}{\mathcal{J}(\bbbq)}
\newcommand{\fCQ}{\mathfrak{C}(\bbbq)}
\newcommand{\fEQ}{\mathfrak{E}(\bbbq)}
\newcommand{\fEQA}{\mathfrak{E}(\bbbq(\alpha))}
\newcommand{\fEQB}{\mathfrak{E}(\bbbq(\beta))}
\newcommand{\fEQAT}{\mathfrak{E}(\bbbq(\alpha))_\mathrm{tors}}
\newcommand{\fEPA}{\mathfrak{E}_p^a}
\newcommand{\fEPB}{\mathfrak{E}_p^b}
\newcommand{\fEPAQ}{\mathfrak{E}_p^a(\bbbq)}
\newcommand{\fEPBQ}{\mathfrak{E}_p^b(\bbbq)}
\newcommand{\fEPAQT}{\mathfrak{E}_p^a(\bbbq)_\mathrm{tors}}
\newcommand{\fEPBQT}{\mathfrak{E}_p^b(\bbbq)_\mathrm{tors}}
\newcommand{\fJQ}{\mathfrak{J}(\bbbq)}
\newcommand{\JQp}{\mathcal{J}(\bbbq_p)}
\newcommand{\JK}{\mathcal{J}(K)}
\newcommand{\JKp}{\mathcal{J}(K_\p)}
\newcommand{\JQT}{J(\bbbq)_\mathrm{tors}}
\newcommand{\CK}{\mathcal{C}(K)}
\newcommand{\EK}{\mathcal{E}(K)}
\newcommand{\ET}{\E_\mathrm{tors}}
\newcommand{\ETK}{\E_\mathrm{tors}(K)}
\newcommand{\EKT}{\E(K)_\mathrm{tors}}
\newcommand{\ETQ}{\E_\mathrm{tors}(\bbbq)}
\newcommand{\CTQ}{\E_\mathrm{tors}(\bbbq)}
\newcommand{\ETQP}{\E_\mathrm{tors}(\bbbq_p)}
\newcommand{\EQT}{\E(\bbbq)_\mathrm{tors}}
\newcommand{\JKT}{\mathcal{J}(K)_\mathrm{tors}}
\newcommand{\Pic}{\mathrm{Pic}}
\newcommand{\A}{{\bf A}}
\newcommand{\p}{{\mathbb P}}
\newtheorem{thm}{Theorem}[section]
\newtheorem{conj}[thm]{Conjecture}
\newtheorem{meth}[thm]{Method}
\newtheorem{lem}[thm]{Lemma}
\newtheorem{cor}[thm]{Corollary}
\newtheorem{qn}[thm]{Question}
\newenvironment{prf}{\noindent{\it Proof}}{\hfill$\square$}
\theoremstyle{definition}
\newtheorem{defn}[thm]{Definition}
\newtheorem{ex}[thm]{Example}
\newtheorem{exs}[thm]{Examples}
\newtheorem{comm}[thm]{Comment}
\theoremstyle{remark}
\newtheorem{rem}[thm]{Remark}	\renewcommand{\therem}{}
\newtheorem{rems}[thm]{Remarks}	\renewcommand{\therems}{}
\numberwithin{equation}{section}

%\theoremstyle{definition}
%\newtheorem{defn}{Definition}	\renewcommand{\thedefn}{}
%\newtheorem{question}{Question}	\renewcommand{\thequestion}{}

\topmargin -0.3in
\headsep 0.3in
\oddsidemargin 0in
\evensidemargin 0in
\textwidth 6.5in
\textheight 9in

%%% \renewcommand{\baselinestretch}{3}

\begin{document}

% The following [] suppress the title running header on the odd pages.
\title[]{Elliptic Curves MT 2025/26: Preliminary Reading}

\footnote{These notes were written by Victor Flynn, with minor edits by James Newton.}

% The following [] suppress the author running header on the even pages.
%% \author[]{E.V.\ Flynn}
%% \address{New College, Oxford OX1 3BN}
%% \email{flynn@maths.ox.ac.uk}

%********************************************************************
\maketitle
\normalsize
\Large
\baselineskip=18pt
%********************************************************************
\section{\bf Background Material in Algebra, Number Theory 
and Geometry}\label{sec:background}

The following gives a summary of the main ideas you need to
know as prerequisites to the lecture course on Elliptic Curves.
%% There is an associated optional Sheet~0 of questions for you to
%% try, if you feel you need to refresh your skills in these topics.
Most of you should have seen most of this material before
in lecture courses from previous years, but it is just as well to 
read through it carefully, in order to fill in any gaps.
%% \par Please email me at flynn@maths.ox.ac.uk
%% if you notice any typos.

\bigskip\bigskip
\centerline{\bf Groups}
\begin{defn}\label{defn:group}
A {\it group} is a set~$G$ with a binary operation~$*$ which satisfies the
following properties.
\par\noindent {\it Closure:} If $f,g\in G$ then $f * g \in G$.
\par\noindent {\it Associativity:} For all $f,g,h\in G$, \ 
$(f * g) * h = f * (g * h)$.
\par\noindent {\it Existence of identity:}
There exists $e \in G$ such that, for all $g\in G$, $e * g = g * e = g$.
\par\noindent {\it Existence of inverses:}
For all $g\in G$, there exists $h\in G$ such that $g * h = h * g = e$.
\end{defn}
\begin{comm}\label{comm:inversenotation}
The element~$h$ is the~{\it inverse}
of~$g$, and is typically denoted~$g^{-1}$, when referring to
a general group $G,*$, and any specific group whose operation
is some type of multiplication. On the other hand, the inverse
of~$g$ will typically be denoted~$-g$ when dealing with a specific
group whose operation is some form of addition.
\end{comm}
\begin{defn}\label{defn:abelian}
We say that a group~$G$ is a {\it commutative} (or {\it Abelian}) group
if it also satisfies
\par\noindent {\it Commutativity:} For all $f,g\in G$,\ $f * g = g * f$.
\end{defn}
\par
\begin{exs}\label{exs:groups}\
\par\noindent {\bf (a)} $\bbbz, +$ is an Abelian group (identity~$0$).
\par\noindent {\bf (b)} $\bbbz, \times$ has identity $= 1$ but, for example,
$2$ has no inverse, and so this is not a group.
\par\noindent {\bf (c)} $\bbbr^+, \times$ (the positive real numbers under
multiplication) is an Abelian group with identity~$1$.
\par\noindent {\bf (d)} $\bbbr \times \bbbr, +$ [which means all
pairs~$(a,b)$, with operation $(a_1,b_1) + (a_2,b_2) = 
(a_1 + a_2, b_1 + b_2)$] is an Abelian group with identity~$(0,0)$.
\par\noindent {\bf (e)} \{$2\times 2$ matrices with nonzero determinant\}
under matrix multiplication is a group. 
Identity $= \Bigl( \latop{1}{0} \latop{0}{1} \Bigr)$.
\par\noindent {\bf (f)} $C_6, +$ [the cyclic group of order~$6$],
denoting $\{ 0,1,2,3,4,5\}$ under~$+$ modulo~$6$ [e.g.\ $3 + 4 = 1$].
This is an Abelian group with identity~$0$.
\par\noindent {\bf (g)} $C_2 \times C_3, +$, which is
$\{ (0,0), (0,1), (0,2), (1,0), (1,1), (1,2) \}$ under the operation:
\par\noindent
$(a_1,b_1) + (a_2,b_2) 
= ( a_1 + a_2 \hbox{ mod } 2, b_1 + b_2 \hbox{ mod } 3)$.
This is an Abelian group with identity~$(0,0)$.
\par\noindent {\bf (h)} Let $S_3, \circ$ be the set of permutations
of~$\{ 1,2,3\}$, with:
$f \circ g = `g$-followed-by-$f$' as our operation [we shall normally
abbreviate $f \circ g$ as $fg$].
This is a group and the elements
are: $\{ e, (12), (13), (23), (123), (132) \}$ [where, for example,
$(132)$ represents the permutation: $1 \rightarrow 3, 3 \rightarrow 2,
2 \rightarrow 1$, and $(23)$ represents $2 \rightarrow 3, 3 \rightarrow 2$
(with~$1 \rightarrow 1$)]. This is not an Abelian group since,
for example, $(132)(12) = (23)$, but $(12)(132) = (13)$.
\end{exs}
\begin{defn}\label{defn:homomorphism} 
Let $G_1, *_1$ and $G_2, *_2$ be groups, and
let $\phi : G_1 \rightarrow G_2$ [a map from~$G_1$ to~$G_2$].
We say that~$\phi$ is a {\it homomorphism} if, for all~$g,h\in G$,
$\phi( g *_1 h) = \phi(g) *_2 \phi(h)$.
\par An {\it endomorphism} on a group~$G$ is a homomorphism
from~$G$ to itself.
\end{defn}
\begin{exs}\label{exs:homomorphism}\
\par\noindent{\bf (a)} $\log : \bbbr^+, \times \rightarrow \bbbr, +$
is a homomorphism since, for all $a,b\in \bbbr^+$,
$\log( a \times b) = \log(a) + \log(b)$ [that is,
$\log( a *_1 b) = \log(a) *_2 \log(b)$].
\par\par\noindent{\bf (b)} 
$\phi : \bbbr \times \bbbr , + \rightarrow \bbbr, +$
defined by $\phi \bigl( (a,b) \bigr) = a$ [can also express
this as $\phi : (a,b) \mapsto a$] is a homomorphism.
\par\noindent{\bf Proof.} $\phi\bigl( (a,b) *_1 (c,d) \bigr)
= \phi\bigl( (a,b) + (c,d) \bigr) = \phi\bigl( (a + c, b + d) \bigr)
= a + c$. 
\par Also, $\phi\bigl( (a,b) \bigr) *_2 \phi\bigl( (c,d) \bigr)
= \phi\bigl( (a,b) \bigr) + \phi\bigl( (c,d) \bigr) = a + c$, and
these are the same.
\par\par\noindent {\bf (c)} $\phi : \bbbz, + \rightarrow \bbbz, +$,
defined by $\phi (a) = 2a$ is a homomorphism.
\par\par\noindent {\bf (d)} 
$\phi : \bbbz, + \rightarrow \bbbz, + : a \mapsto a^2$
is not a homomorphism since, for example, $\phi(2+3) = \phi(5) = 5^2 = 25$,
but $\phi(2) + \phi(3) = 2^2 + 3^2 = 13$, and these are not equal.
\end{exs}
\begin{defn}\label{defn:bijection}
Let $\phi : S \rightarrow T$, for any sets $S,T$.
We say that~$\phi$ is {\it injective} (or 1--1 or an {\it injection})
if, for all $f,g\in S, \ \phi(f) = \phi(g) \implies f=g$;
that is, $f\not= g \implies \phi(f) \not= \phi(g)$ [i.e.\ when
it never happens that two distinct~$f$ and~$g$ are mapped by~$\phi$
to the same element]. We say that~$\phi$ is {\it surjective}
(or {\it onto} or a {\it surjection}) if, for all $w\in T$,
there exists $g\in S$ such that $w = \phi (g)$ [i.e.\ when 
every member of~$T$ is mapped onto by at least one element of~$S$].
We say that~$\phi$ is {\it bijective} (or a {\it bijection})
if it is both injective and surjective.
\end{defn}
\begin{defn}\label{defn:kernelimage}
Let~$\phi : G_1 , *_1 \rightarrow G_2, *_2$ be a homomorphism.
The {\it kernel} of~$\phi$ (denoted $\kker \phi$) is defined as
the set of all members of~$G_1$ which are mapped to the identity 
element~$e_2$ in~$G_2$. That is:
$\kker \phi = \{ g \in G_1 : \phi(g) = e_2 \}$.
The image of~$\phi$ (denoted $\im \phi$) is the set of all
members of~$G_2$ which are mapped onto by some member of~$G_1$.
That is to say: 
$\im \phi = \{ \phi(g) : g \in G_1 \}$.
\end{defn}
\begin{comm}\label{comm:keriminjsurj}
Clearly, a homomorphism $\phi : G_1, *_1 \rightarrow G_2, *_2$ 
is injective if and only if $\kker \phi = \{ e_1 \}$,
where $e_1$ is the identity element in~$G_1$.
It is surjective if and only if $\im \phi = G_2$.
\end{comm}
\begin{exs}\label{exs:bijection}\
\par\noindent {\bf (a)} $\log : \bbbr^+, \times \rightarrow \bbbr, +$ 
is an injection since, for any~$f,g\in \bbbr^+$: 
$\phi(f) = \phi(g) \implies \log f = \log g \implies e^{\log f} = e^{\log g}
\implies f = g$. 
\par It is also a surjection since, if $w \in \bbbr$, we can take 
$g = e^w \in \bbbr^+$ and $\phi(g) = \log(e^w) = w$.
Hence~$\phi$ is a bijection, since it is both an injection
and a surjection. The kernel is~$\{ 1 \}$ [that is, $1$ is the unique
member of~$\bbbr^+,\times$ mapped by $\log$ to the identity element~$0$
in $\bbbr, +$]. The image is all of~$\bbbr$ [since the map
is surjective].
\par\noindent {\bf (b)} Let 
$\phi : \bbbr \times \bbbr, + \rightarrow \bbbr, +$ be defined
by~$\phi\bigl( (a,b) \bigr) = a$. This is not an injection
since, for example, $\phi\bigl( (2,1) \bigr) = 2$
and $\phi\bigl( (2,3) \bigr) = 2$, but $(2,1) \not= (2,3)$.
It is a surjection since,
for any~$r\in \bbbr$, we can take $(r,0)\in \bbbr \times \bbbr$
which satisfies $\phi\bigl( (r,0) \bigr) = r$
[of course, we could just as easily have used $(r,1)$; we merely
had to show that every~$r\in \bbbr$ is mapped onto by at least
one member of of $\bbbr \times \bbbr$].
The kernel is $\{ (0,b) : b \in \bbbr \}$ and
the image is all of $\bbbr$ [since~$\phi$ is surjective].
\par\noindent {\bf (c)} $\phi : \bbbz, + \rightarrow \bbbz, +,
a \mapsto 2a$. This is an injection since, for any~$a,b\in\bbbz$:
$\phi(a) = \phi(b) \implies 2a = 2b \implies a = b$. It is
not a surjection since nothing maps to~$3$ (for example).
The kernel is $\{ 0 \}$ and the image is $\{ \ldots , -4,-2,0,2,4,\ldots \}$.
\end{exs}
\begin{defn}\label{defn:isomorphism}
Let~$G_1,*_1$ and $G_2, *_2$ be groups
and let~$\phi : G_1 \rightarrow G_2$.
If~$\phi$ is both a bijection and a homomorphism, then we
say that~$\phi$ is an {\it isomorphism}. If there exists
an isomorphism $\phi : G_1 \rightarrow G_2$, we say that
the two groups are {\it isomorphic} (same shape) and
we write~$G_1 \cong G_2$.
\end{defn}
\begin{comm}\label{comm:isomorphism}
If $G_1$ and $G_2$ are isomorphic groups, then $G_2$ 
can be regarded as the same group as $G_1$, merely with
the elements relabelled. $G_1$ and $G_2$ will have all
of the same structural properties
(for example, $G_1$ will be Abelian iff $G_2$ is Abelian,
$G_1$ will have an element~$g\not=e$ satisfying~$g*g=e$ iff $G_2$ has
such an element, etc).
\end{comm}
\begin{ex}\label{ex:isomorphism}
$\log : \bbbr^+, \times \rightarrow \bbbr, +$ is an
isomorphism, since it is both a homomorphism and a bijection.
The groups $\bbbr^+, \times$ and $\bbbr, +$ are isomorphic.
\end{ex}
\begin{comm}\label{comm:isogptables}
Two finite groups $G_1,G_2$ are isomorphic if the group
table of~$G_1$ can have its elements relabelled to give the
group table of~$G_2$.
\end{comm}
\begin{ex}\label{ex:c6}
Let $G_1 = C_2 \times C_3$ and $G_2 = C_6$.
Let $\phi : G_1 \rightarrow G_2$ be defined by:
\par $(0,0) \mapsto 0,\ (1,1) \mapsto 1,\ (0,2) \mapsto 2,\
(1,0) \mapsto 3,\ (0,1) \mapsto 4,\ (1,2) \mapsto 5.$
%\eject
\par\noindent The group table of $G_1$ is as follows.
\medskip
\begin{center}
\begin{tabular}{c||c|c|c|c|c|c|}
+ & (0,0) & (0,1) & (0,2) & (1,0) & (1,1) & (1,2)\\
\hline
\hline
(0,0) & (0,0) & (0,1) & (0,2) & (1,0) & (1,1) & (1,2)\\
\hline
(0,1) & (0,1) & (0,2) & (0,0) & (1,1) & (1,2) & (1,0)\\
\hline
(0,2) & (0,2) & (0,0) & (0,1) & (1,2) & (1,0) & (1,1)\\
\hline 
(1,0) & (1,0) & (1,1) & (1,2) & (0,0) & (0,1) & (0,2)\\
\hline
(1,1) & (1,1) & (1,2) & (1,0) & (0,1) & (0,2) & (0,0)\\
\hline
(1,2) & (1,2) & (1,1) & (1,1) & (0,2) & (0,0) & (0,1)\\
\hline
\end{tabular}
\end{center}
\medskip
Replacing all entries using~$\phi$ gives the following table.
\medskip
\begin{center}
\begin{tabular}{c||c|c|c|c|c|c|}
+ & 0 & 4 & 2 & 3 & 1 & 5\\
\hline
\hline
0 & 0 & 4 & 2 & 3 & 1 & 5\\
\hline
4 & 4 & 2 & 0 & 1 & 5 & 3\\
\hline
2 & 2 & 0 & 4 & 5 & 3 & 1\\
\hline
3 & 3 & 1 & 5 & 0 & 4 & 2\\
\hline
1 & 1 & 5 & 3 & 4 & 2 & 0\\
\hline
5 & 5 & 3 & 1 & 2 & 0 & 4\\
\hline
\end{tabular}
\end{center}
\medskip
This is just the group table for~$C_6$, which proves that
$C_2 \times C_3 \cong C_6$.
\end{ex}
The last example is a special case of the following result.
\begin{lem}\label{lem:cyclic}
When $m,n\in\bbbz$ and $m,n$ have no common factors (apart from~$1$)
then $C_m \times C_n \cong C_{mn}$.
\end{lem}
The following is also quite a useful property of finite Abelian groups.
\begin{lem}\label{lem:cyclicdecom}
Any finite Abelian group~$G$ is isomorphic to the
product of cyclic groups: 
$G \cong C_{m_1} \times C_{m_2} \times \ldots \times C_{m_k}$,
for some $C_{m_1},\ldots , C_{m_k}$.
\end{lem}
For any group~$G$, it is natural to consider groups which
lie inside~$G$ (that is to say, which are subsets of~$G$).
\begin{defn}\label{defn:subgroup}
Let $G,*$ be a group and let~$H \subset G$ [$H$ is a subset of~$G$].
We say that~$H$ is a {\it subgroup} of~$G$ (written: $H \leqslant G$)
if $H$ is nonempty, and forms a groups with respect to
the same operation~$*$ as~$G$. This is equivalent to:
\par $e_G \in H$ (where $e_G$ is the identity element in~$G$),
\par If $f,g \in H$ then $f * g \in H$,
\par If $h\in H$ then $h^{-1} \in H$.
Note that associativity automatically holds in~$H$ since it holds
in the group~$G$, of which~$H$ is a subset.
\end{defn}
\begin{exs}\label{exs:subgroups}\
\par\noindent{\bf (a)} $H = \{ \ldots , -4, -2, 0, 2, 4, \ldots \} 
\leqslant \bbbz, +$. 
\par\noindent{\bf (b)} $H = \{ \ldots , -3, -1, 1, 3, \ldots \}
\not\leqslant \bbbz, +$, since the identity element~$0$ is
not in the set (we could alternatively have used the fact that
it is not closed; for example, $1, 3\in H$ but $1 + 3 \not\in H$).
\par\noindent{\bf (c)} $H = \{ 0, 1, 2, 3, \ldots \} 
\not\leqslant \bbbz, +$. It is fine for containing the identity element
and closure, but~$H$ does not contain the inverse of every
element in~$H$ (for example, $3 \in H$ but $-3 \not\in H$).
\end{exs}
\begin{defn}\label{defn:coset}
Let~$H \leqslant G$ and let $g \in G$. The set $gH = \{ g*h : h \in H\}$
is called a {\it left coset} of~$H$ and the set $Hg = \{ h*g : h \in H\}$
is called a {\it right coset} of~$H$.
\end{defn}
\begin{comm}\label{comm:coset}
When the group operation is some form of multiplication,
one typically writes the left (or right) cosets, as above, 
in the style~$gH$ (or~$Hg$). When the group operation is some
form of addition, then one typically writes $g + H = \{ g + h : h \in H\}$
(similarly for~$H + g$).
\end{comm}
\begin{ex}\label{ex:coset}
Let $G = \bbbz, +$ and let $H = 3\bbbz = \{ \ldots ,-6,-3,0,3,6,\ldots \} 
\leqslant G$. Then some examples of left cosets are:
\par $0 + H = \{ \ldots ,0+(-6),0+(-3),0+0,0+3,0+6,\ldots \}
= \{ \ldots ,-6,-3,0,3,6,\ldots \}$,
\par $1 + H = \{ \ldots ,1+(-6),1+(-3),1+0,1+3,1+6,\ldots \}
= \{ \ldots ,-5,-2,1,4,7,\ldots \}$,
\par $2 + H = \{ \ldots ,2+(-6),2+(-3),2+0,2+3,2+6,\ldots \}
= \{ \ldots ,-4,-1,2,5,8,\ldots \}$,
\par $3 + H = \{ \ldots ,3+(-6),3+(-3),3+0,3+3,3+6,\ldots \}
= \{ \ldots ,-3,0,3,6,9,\ldots \}$.
\par $4 + H = \{ \ldots ,4+(-6),4+(-3),4+0,4+3,4+6,\ldots \}
= \{ \ldots ,-2,1,4,7,10,\ldots \}$.
\par\noindent Note that $0 + H = 3 + H$ and $1 + H = 4 + H$. Clearly
\par \ldots $-6 + H = -3 + H = 0 + H = 3 + H = 6 + H = \ldots$
\par \ldots $-5 + H = -2 + H = 1 + H = 4 + H = 7 + H = \ldots$
\par \ldots $-4 + H = -1 + H = 2 + H = 5 + H = 8 + H = \ldots$
\par\noindent so that there are only~$3$ distinct left cosets.
\end{ex}
The left coset $e H = H$, where~$e$ is the identity element, so
that $H$ is one of the left cosets of itself (and similarly is
one of the right cosets of itself).
It can be shown two left cosets $g_1 H$ and $g_2 H$ are either equal
or disjoint and that every element of~$G$ is a member of some coset.
When~$G$ is a finite group, it can also be shown
that any $g_1 H$ and $g_2 H$ have the same number of elements
(and so every left coset of~$H$ has the same number of elements as~$H$).
It follows that the left cosets of~$H$ give a partition of~$G$, that is,
they give $G$ as a union of disjoint subsets. Since each of
these subsets has the same number of elements as~$H$, we see
that~$| G | = | H | + \ldots + | H | = k |H|$, where $k$ is the number
of distinct left cosets of~$H$
[here, $| S |$ is the standard notation for the number of elements 
in~$S$, for any set~$S$]. The following immediately follows. 
\begin{thm}\label{thm:lagrange}
(Lagrange's Theorem) Let~$G$ be a finite group, and let~$H \leqslant G$.
Then~$| H |$ is a factor of~$| G |$ {\rm [}this can also be expressed
as $|H|$ divides $|G|$, or as $| H | \ | \ |G|${\rm ]}. 
\end{thm}
There are many situations where we would like to consider the elements 
of a group~$G$, but in a simplified context, where we `mod out'
(or `quotient out') by a subgroup, and focus on the information
that remains. For example, when $G = \bbbz, +$, we might want
to collapse $H = 3\bbbz \leqslant G$ down to a single element,
and consider the elements mod~$H$ (considering elements to
be the same if they lie in the same coset). The natural way to
do this is to create a new group $G/H$, whose elements are (say)
the left cosets of~$H$, in which case there are only $3$~distinct
elements: 
$$
\{ \ldots ,-6,-3,0,3,6,\ldots \},
\{ \ldots ,-5,-2,1,4,7,\ldots \},
\{ \ldots ,-4,-1,2,5,8,\ldots \},
$$
which give all the members of~$G/H$.
It is natural to ask whether the group law on~$G$ carries over
to give group law on~$G/H$.
How might we add, for example, the second and third of these?
That is, we want to perform the addition:
$$ \{ \ldots ,-5,-2,1,4,7,\ldots \} + \{ \ldots ,-4,-1,2,5,8,\ldots \}. $$
A natural attempt is add any element in the first coset 
to any element in the second coset, and see what coset the sum lies in.
For example, $-5$ is in the first coset, and~$2$ is the second
coset, and $-5 + 2 = -3$, which lies in: $\{ \ldots ,-6,-3,0,3,6,\ldots \}$,
suggesting that, in~$G/H$:
$$ \{ \ldots ,-5,-2,1,4,7,\ldots \} + \{ \ldots ,-4,-1,2,5,8,\ldots \}
= \{ \ldots ,-6,-3,0,3,6,\ldots \}.$$
Furthermore, it doesn't matter what members you take: you can
add any member of $\{ \ldots ,-5,-2,1,4,7,\ldots \}$ to
any member of $\{ \ldots ,-4,-1,2,5,8,\ldots \}$
and you will get a member of $\{ \ldots ,-6,-3,0,3,6,\ldots \}$,
reinforcing our confidence in this definition of the sum.
It is easy to see that this gives a way of turning the $3$ members
of $G/H$ into a group. We can also express this group law on~$G/H$ as:
$(g_1 + H) + (g_2 + H) = (g_1 + g_2) + H$, where the well-definedness
of this rule is due to the fact that, at least for this choice of~$G, H$,
whenever $g_1 + H = g_1' + H$ and $g_2 + H = g_2' + H$
then $(g_1 + g_2) + H = (g_1' + g_2') + H$.
Even though the members of~$G/H$ are sets, it is often convenient
to denote them by selected representative elements; for example,
we can use~$0,1,2$ to denote the cosets containing~$0,1,2$, respectively,
in which case that above addition could be expressed as: $1 + 2 = 0$
in~$G/H$.
Of course,~$91$ lies in the same coset as~$1$, so that
$1 = 91$ in $G/H$;
we could just as easily represent our~$3$ members of~$G/H$ as~$0,91,2$
and say that~$91 + 2 = 0$ in~$G/H$.
\par
Similarly, let $G = \bbbc^*, \times$, the group of nonzero complex numbers
under multiplication, and let $H = \{ z : |z| = 1 \} \leqslant G$,
the unit circle on an Argand diagram. Then an example of a left coset is
$(3 + 4i)H = \{ (3 + 4i) z : |z| = 1\}$, which is easily seen
to be just the circle, centre~$0$, with radius~$5$ (the modulus of~$3 + 4i$).
Note that the group operation is multiplication here,
so the cosets are written as $gH = \{ g * h : h\in H\} = \{ gh : h\in H\}$ 
[rather than $g + H = \{ g * h : h\in H\} = \{ g + h : h\in H\}$, as in
the previous example]. Two complex numbers are in the same coset
iff they have the same modulus. 
Clearly, the left cosets are just the circles with centre~$0$, 
and these are the elements of~$G/H$. We have `modded out'
by~$H$, removing the argument information, and retaining only
the modulus information. We can turn~$G/H$ into a group under multiplication:
for example, the set of complex numbers of modulus~$5$ multiplied by the
set of complex numbers of modulus~$2$ gives the set of complex numbers
modulus~$10$. This is well defined, since it does not matter which
representative is taken: any member of the first coset (any complex number 
of modulus~$5$) times
any member of the second coset (any complex number of modulus~$2$)  
will give a member of the third coset (a complex number of modulus~$10$).
\par
By way of contrast, let $G$ be as in~Example~\ref{exs:groups}(h),
that is, $G = S_3, \circ$, the group of permutations of
$\{ 1,2,3\}$ under the operation $f \circ g = `g$-followed-by-$f$'
[where, as usual, we shall abbreviate $f \circ g$ as $fg$].
Consider $H = \{ e, (12) \} \leqslant G$. There are only 3 distinct
left cosets of~$H$:
\par $ eH = (12)H = \{ e, (12) \},$
\par $ (123)H = (13)H = \{ (123), (13) \},$
\par $ (132)H = (23)H = \{ (132), (23) \}.$
\par\noindent How might we try to perform:
$ \{ e, (12) \} \{ (123), (13) \}$? We could attempt the same approach
as before: take any element from each set, combine them according
to the group law on~$G$ and see what coset the results lies in.
For example, $e$ is a member of~$\{ e, (12) \}$ and
$(123)$ is a member of~$\{ (123), (13) \}$ and $e (123) = (123) \in
\{ (123), (13) \}$. So we might be tempted to say
that $ \{ e, (12) \} \{ (123), (13) \} = \{ (123), (13) \}$.
On the other hand, $(12) \in \{ e, (12) \}$ and $(13) \in \{ (123), (13) \}$,
and $(12)(13) = (132) \in \{ (132), (23) \}$, so this suggests
that $ \{ e, (12) \} \{ (123), (13) \} = \{ (132), (23) \}$.
We see that there is no sensible unambiguous way of defining 
$ \{ e, (12) \} \{ (123), (13) \}$. To put it another way,
our attempt to use the natural rule $(g_1H)(g_2H) = (g_1g_2)H$
to give a group law on~$G/H$, has foundered on the fact that 
there are instances where $g_1H = g_1'H$ and $g_2H = g_2'H$,
but $(g_1g_2)H \not= (g_1'g_2')H$ [for example, when
$g_1 = e, g_1' = (12), g_2 = (123), g_2' = (13)$].
Any attempt to turn the set of right cosets into a group would
also suffer the same problem.
Note that if we keep the group~$G = S_3$, as before, but
use instead $H = \{ e, (123), (132) \} \leqslant G$,
then it is easy to check that everything is fine, and we can
turn~$G/H$ into a group.
\par
The key property which allows $G/H$ to be a group is the following.
\begin{defn}\label{defn:normal}
Let~$G,*$ be a group and let~$H \leqslant G$.
We say that~$H$ is a {\it normal} subgroup of~$G$, 
denoted~$H \triangleleft G$ if, for every $g\in G$,
$gH = Hg$. 
\par An equivalent definition is: 
$\forall g \in G, \ \forall h\in H,\ \ g^{-1} h g \in H$.
\end{defn}
\begin{comm}\label{comm:leftrightcosets}
When~$H \triangleleft G$, the left cosets of~$H$ are the same
as the right cosets, and so we can just refer to them
as {\it cosets}, without needing to specify left or right.
\end{comm}
\begin{defn}\label{defn:quotient}
Let~$G,*$ be a group and let~$H \triangleleft G$. Then~$G/H$
(or `$G$ quotient~$H$' or `$G$~mod~$H$') is defined as 
$G/H = \{ gH : g\in G \}$, under the group operation:
$(g_1H)(g_2H) = (g_1g_2)H$ [here, we are writing $g_1 g_2,
g_1H, g_2H$
as shorthand for $g_1 * g_2, g_1*H, g_2*H$].
\end{defn}
Why is it that the condition $H \triangleleft G$ is sufficient
for this group operation on~$G/H$ to be well defined?
Recall, the guarantee we need for unambiguity is that,
whenever $g_1 H = g_1' H$ and $g_2H = g_2'H$, then $(g_1g_2)H = (g_1'g_2')H$. 
So, suppose that $H \triangleleft G$ and that 
$g_1 H = g_1' H, g_2H = g_2'H$. Then:
\begin{align*}
(g_1 g_2) H &= g_1 (g_2 H) = g_1 (g_2'H) = g_1 (H g_2') = (g_1 H) g_2'\\
&= (g_1' H) g_2' = (H g_1') g_2' = H (g_1' g_2') = (g_1' g_2') H,
\hbox{ as required.}
\end{align*}
\begin{comm}\label{comm:abelimpliesnormal}
If~$G,*$ is Abelian then any subgroup~$H$ must be normal, guaranteeing
that we can always form the quotient group~$G/H$.
\end{comm}
\begin{defn}\label{defn:eqreln}
Let~$X$ be any set, and let~$\ttilde$ be a binary relation on~$X$.
We say that~$\ttilde$ is an {\it equivalence relation} if it satisfies:
\par (1) $a \ttilde a$ for all~$a\in X$ \ \ [reflexivity].
\par (2) $a \ttilde b \implies b \ttilde a$ for all~$a,b\in X$ 
\ \ [symmetry].
\par (3) $a \ttilde b \hbox{ and } b \ttilde c
\implies a \ttilde c$ for all~$a,b,c\in X$ 
\ \ [transitivity].
\par\noindent The {\it equivalence class} of an element~$a\in X$,
denoted~$[a]$, is the set of all members of~$X$ which are equivalent
to~$a$. This is to say: $[a] = \{ x\in X : x \ttilde a \}$. 
\end{defn}
Given any~$g_1,g_2 \in G$, it is easy to check that~$g_1 H = g_2 H$
exactly when $g_1 = g_2 * h$, for some $h\in H$; that is,
when $g_1*g_2^{-1} \in H$.
Define the relation $g_1 \ttilde g_2$
by: 
$$ g_1 \ttilde g_2 \iff g_1 = g_2 * h, \hbox{ for some }h\in H,
$$
which gives an equivalence relation on~$G$.
Another way to describe members of~$G/H$ is to say that they
are equivalence classes under this relation (or, we can also
say that they are the members of~$G$ {\it modulo} the
equivalence relation).
\begin{comm}\label{comm:easynormal}
It can sometimes seem cumbersome to deal directly with the above
definition of~$G/H$, since the group elements in~$G/H$ are cosets
(so that~$G/H$ is a set of sets).
Suppose nobody had ever mentioned cosets. There is a more intuitive
approach to quotient groups (which is in fact the way they
are mostly dealt with in practice) which requires no explicit mention
of cosets. Namely, one writes the elements of~$G/H$ 
exactly as the elements of~$G$, except that certain elements
become equal in~$G/H$ which were distinct in~$G$. Specifically,
one imposes the rule: 
$$ g_1 = g_2 \hbox{ in } G/H \iff g_1 = g_2 * (\hbox{some member of~$H$}). $$ 
Equivalently: $g_1 = g_2 \hbox{ in } G/H \iff g_1 * g_2^{-1} \in H$.
When~the operation in~$G$ is addition, this means
two elements are equal in~$G/H$ exactly when their difference is in~$H$.
When~the operation in~$G$ is multiplication,
two elements are equal in~$G/H$ exactly when their quotient is in~$H$
[of course, when the group operation is neither an addition nor
a multiplication, then just use the general
criterion $g_1 * g_2^{-1} \in H$].
The following examples are described in this spirit, with
no explicit mention of cosets.
\end{comm}
\begin{exs}\label{exs:quotients}\
\par\noindent{\bf (a)} Let $G = \bbbz, +$ and 
$H = 3\bbbz = \{ \ldots ,-6,-3,0,3,6,\ldots\} \leqslant G$.
We see that, for example, $1 = 16 * (-15)$ in~$G$ [since~$*$ is~$+$ here],
so that $1 = 16*(\hbox{member of~$H$})$, and so~$1 = 16$ in~$G/H$.
Equivalently, $1 * 16^{-1} = 1 + (-16) = -15 \in H \implies 1 = 16$ in~$G/H$
[note that $16^{-1}$ is the inverse of~$16$ in~$G$, which is~$-16$].
On the other hand, $1 \not= 20$ in~$G/H$, since~$1 = 20*(-19)$
and $-19 \not\in  H$.
\par In the group~$G/H = \bbbz / 3\bbbz$:
\par $\ldots = -6 = -3 = 0 = 3 = 6 = \ldots$
\par $\ldots = -5 = -2 = 1 = 4 = 7 = \ldots$
\par $\ldots = -4 = -1 = 2 = 5 = 8 = \ldots$
\par\noindent and so $\bbbz / 3\bbbz$ contains only~$3$ distinct elements. 
The usual convention is to pick out~$0,1,2$ as listing the
distinct members of~$\bbbz / 3\bbbz$. We can see that~$\bbbz / 3\bbbz, +$
is isomorphic to~$C_3,+$.
\par\noindent{\bf (b)} Let~$G = \bbbq^*, \times =$ nonzero members of~$\bbbq$
under multiplication. Let $H = \qsq
= \{\hbox{squares of nonzero members of~$\bbbq$}\}$. 
For example, $4/9\in H$ but $2\not\in H$.
\par In~$\bbbq^*$, $2/3 = 6\times \frac{1}{9}$ and 
$\frac{1}{9}\in \qsq$ so that $2/3 = 6$ in $\qmsq$.
Similarly, $6 = \frac{24}{25}$ in $\qmsq$ since 
$6 = \frac{24}{25} \times \frac{25}{4}$ and $\frac{25}{4} \in \qsq$.
However, $2 \not= 3$ in~$\qmsq$ since $2 = 3 \times \frac{2}{3}$
and $\frac{2}{3} \not\in \qsq$.
\par Note that any~$\frac{a}{b} \in \qmsq$ 
[where $a,b \in \bbbz$] can be written
as $\frac{a}{b} = \frac{a}{b} b^2 = ab \in \bbbz$.
We can write any integer in the form~$r s^2$ where~$r,s\in \bbbz$
and~$r$ is square-free [where {\it square free} means not divisible 
by any integer square except~$1$; for example,~$6$ is square free,
but~$12$ is not square free, since it is divisible by~$4$].
Write the integer~$ab$ in the form~$r s^2$, so that
$\frac{a}{b} = ab = rs^2 = r$ in $\qmsq$. 
The standard way of working in~$\qmsq$ is to write each distinct element
as a square free integer. For example:
\par $\frac{20}{13} = \bigl(\frac{20}{13}\bigr) 13^2
= 20\times 13 = 4\times 5\times 13 = 5\times 13 = 65\hbox{ in }\qmsq,$
\par\noindent which is a square free integer.
\par\noindent{\bf (c)} Let $G = \bbbc^*, \times$ and $H = \{ z : |z| = 1\}$.
Then $z_1 = z_2$ in~$G/H$ $\iff z_1/z_2 \in H \iff | z_1 / z_2 | = 1
\iff |z_1| = |z_2|$. That is, $z_1 = z_2$ in~$G/H$ exactly when
they have the same modulus. So, for example, $3 + 4i = 5i = 5$
in~$G/H$. Clearly, every member of~$G$ is equal in~$G/H$ to precisely
one nonzero real number (namely, its modulus). So, each element of~$G/H$
can be represented by a nonzero real numbers, and it
is easy to see that~$G/H$ is isomorphic $\bbbr^*, \times$.
\end{exs}
The idea of a normal subgroup is related to homomorphisms in
the following way.
\begin{lem}\label{lem:kernelisnormal}
Let $\phi : G_1, *_1 \rightarrow G_2, *_2$ be a homomorphism.
Then $\kker \phi \triangleleft G_1$ and $\im \phi \leqslant G_2$.
\end{lem}
Since the kernel of a homomorphism is a normal subgroup, we
can form the quotient group $G_1/\kker \phi$. The map
$g *_1 \kker \phi \mapsto g$ can be shown to be well defined
and an isomorphism, giving the following result (often
called the First Isomorphism Theorem).
\begin{thm}\label{thm:isom}
Let $\phi : G_1, *_1 \rightarrow G_2, *_2$ be a homomorphism.
Then $G_1/\kker\phi \cong \im \phi$.
\end{thm}
\begin{comm}\label{comm:isom}
Note that, in the case when $\phi$ is surjective, we
have $\im \phi = G_2$ and so $G_1/\kker\phi \cong G_2$.
\end{comm}
%\eject
\begin{exs}\label{exs:isom}\
\par\noindent{\bf (a)} Let $\phi : \bbbr \times \bbbr \times \bbbr, + 
\rightarrow \bbbr \times \bbbr, +$ be 
defined by $\phi \bigl( (x,y,z) ) = (x,y)$ [the projection
map to the $(x,y)$-plane]. Then $\kker \phi$
is the $z$-axis $\{ (0,0,z) : z \in \bbbr \}$, and
$\im \phi$ is all of~$\bbbr \times \bbbr$ (the map is surjective).
The isomorphism theorem tells us that
$\bbbr \times \bbbr \times \bbbr/\kker \phi \cong \bbbr \times \bbbr$. 
\par\noindent{\bf (b)} Let $\phi : \bbbc^*, \times 
\rightarrow \bbbr^*, \times : z \mapsto |z|$.
Then $\kker\phi = \{ z : |z| = 1\}$ and $\im\phi$ is
all of $\bbbr$ (the map is surjective).
The isomorphism theorem tells us that
$\bbbc^*/\kker\phi \cong \bbbr^*$.
\end{exs}
Another important idea is that of the order of an element.
\begin{defn}\label{defn:order}
Let~$G,*$ be a group and $g\in G$. If there exists $k > 0$
such that $g * g * \ldots * g$ [$k$ times] $= e$
then we say that~$g$ has {\it finite order} (or is
a {\it torsion} element), and the smallest such~$k$
is the {\it order} of~$g$, denoted o($g$). If no such~$k$ exists, we say
that~$g$ has {\it infinite order}. For an Abelian group~$G$,
the set of all elements in~$G$ of finite order is a subgroup
of~$G$, the {\it torsion subgroup} of~$G$, denoted $G_\tors$.
\end{defn}
Since~$\{e,g,g^2,\ldots ,g^{o(g) - 1}\}$ is a subgroup of~$G$
[the {\it subgroup generated by~$g$}] with o($g$) elements, we obtain
the following consequence of Lagrange's Theorem.
\begin{cor}\label{cor:orderdivG}
Let~$G,*$ be a group and $g\in G$. The order of~$g$ is always
a factor of~$|G|$. As a consequence, $g^{|G|} = e$.
\end{cor}
\begin{defn}\label{defn:boolean}
We say that~$G,*$ is {\it Boolean} if, for all $g\in G$,
$g * g = e$ [and so every element apart from the identity will
have order~$2$].
\end{defn}
\begin{comm}\label{comm:boolean}
Any finite Boolean group~$G$ is isomorphic to the product of a finite number
of copies of~$C_2$; 
that is: $G \cong C_2 \times C_2 \times \ldots \times C_2$.
It follows that the order of~$G$ [that is, the number of elements in~$G$]
is a power of~$2$.
\end{comm}
\begin{defn}\label{defn:Gm}
Let~$G,*$ be an Abelian group. The {\it $m$-torsion subgroup}
of~$G$, denote by~$G[m]$, is defined as
$\{ g\in G : g*g*\ldots *g \hbox{ [$m$ times] } = e\}$.
This is same as the set of members of~$G$ whose orders are
factors of~$m$. 
\end{defn}
\begin{comm}\label{comm:Gm}
When~$G$ is an Abelian group, let~$2G$ denote
the subgroup $\{ g * g : g \in G\}$. Clearly $G/2G$ is always
a Boolean group
When~$G$ is a finite Abelian group, it can be shown that $G/2G \cong G[2]$.
\end{comm}
\medskip
\centerline{\bf Elementary Number Theory}
We have already seen the idea of the `integers modulo~$m$'
developed as a quotient group in Example~\ref{exs:quotients}(a).
The next few definitions rephrase this idea in the
language of congruences (which we have already used
in Examples~\ref{exs:groups}(f),(g), but which we now formalise).
First a few preliminaries are necessary.
\begin{defn}\label{defn:divides}
For any $a,b\in\bbbz$, we say that $a$ {\it divides}~$b$ [or that~$a$ 
is a {\it factor} of~$b$, or that~$a$ is a {\it divisor} of~$b$], 
denoted $a | b$, if there exists~$k\in \bbbz$ such
that $b = ka$. When~$a$ does not divide~$b$, this is denoted $a\notdiv b$
[for example, $5 | 20$, but $7 \notdiv 20$ and $20 \notdiv 5$].
\end{defn}
\begin{ex}\label{ex:polyintroot}
If~$x\in\bbbz$ is a root of a polynomial $f(x) = f_n x^n + \ldots + f_0$
with integer coefficients, then $x | f_0$ [since, $f(x) = 0$
implies $x(-f_n x^{n-1} - \ldots - f_1) = f_0$].
So, for example, to test whether~$x^3 + 11 x - 6 = 0$ has any integer
solutions, it is only necessary to check the
possibilities~$x = \pm 1, \pm 2, \pm 3, \pm 6$. Since none of these
are solutions, it follows that the equation $x^3 + 11 x - 6 = 0$ 
has no integer solutions. 
\end{ex}
\begin{defn}\label{defn:prime}
Let~$m\in\bbbz, m > 1$. We say that~$m$ is {\it prime} [or a {\it prime number}]
if its only divisors are~$1$ and~$m$ itself; otherwise~$m$
is {\it composite} [by convention,~$1$ is neither prime nor composite].
\end{defn}
\begin{defn}\label{defn:gcd}
For any~$m,n\in\bbbz$, the {\it greatest common divisor}
of~$m,n$, denoted~$\gcd(m,n)$, is the largest~$d \geqslant 1$
such that~$d | m$ and~$d | n$ (sometime also called the
{\it highest common factor} of~$m,n$ or~$\hbox{hcf}(m,n)$). 
The {\it least common multiple}
of~$m,n$, denoted~$\lcm(m,n)$, is the smallest~$D \geqslant 1$
such that~$m | D$ and~$n | D$. Sometimes~$\gcd(m,n)$ is abbreviated
as~$(a,b)$ and $\lcm(m,n)$ as~$[a,b]$.
When $\gcd(m,n) = 1$ we say that $m$ and~$n$ are {\it coprime}.
\end{defn}
For example, the positive divisors of~$12$ are: $1,2,3,4,6,12$
and the positive divisors of~$18$ are: $1,2,3,6,9,18$.
The common divisors are: $1,2,3,6$, the greatest of which is~$6$,
and so $\gcd(12,18) = 6$. 
\par Note that any common divisor of~$a$ and~$b$ is also a
common divisor of~$a+kb$ and~$b$, and vice versa, giving the
following property of gcd's. 
\begin{lem}\label{lem:akb}
For any~$a,b,k\in \bbbz$, $\gcd(a+kb,b) = \gcd(a,b) = \gcd(a,b+ka)$.
\end{lem}
\par A fundamental property of~$\bbbn$ is that, given any~$a,b \in \bbbn$,
one can find the highest multiple of~$b$ [say $qb$] $\leqslant a$,
and the remainder~$a - qb$ will be less than~$b$. This is to say,
given any~$a,b \in \bbbn$, there exist~$q,r\in\bbbn$ such that
$a = qb + r$ and $r < b$. This is known as the {\it Division Algorithm},
and the existence of such~$q,r$ [given any~$a,b$] can be
proved by induction.
For example, given~$a = 22$ and $b = 5$,
we can say that~$5$ goes into~$22$
a total of~$q=4$ times with remainder~$r=2$, and
write: $22 = 4\cdot 5 + 2$, and indeed~$0 \leqslant 2 < 5$.
Repeated applications of the Division Algorithm give the
following technique for finding the greatest common divisor
of two numbers.
\begin{defn}\label{defn:EA}
Given positive integers~$m,n$, {\it Euclid's Algorithm}
for finding~$\gcd(m,n)$ is as follows.
\par First find $q_1, r_2$ such that $m = q_1 n + r_2
\ \ (0 \leqslant r_2 < n)$,
\par Then find $q_2, r_3$ such that $n = q_2 r_2 + r_3
\ \ (0 \leqslant r_3 < r_2)$,
\par Then find $q_3, r_4$ such that $r_2 = q_3 r_3 + r_4
\ \ (0 \leqslant r_4 < r_3)$,\hbox{ and so on.}
\par\noindent Since the remainders~$r_i \geqslant 0$ are strictly  
decreasing, we will at some point get remainder~$0$.
The last nonzero remainder~$r_k$ is $\gcd(m,n)$.
\end{defn}
The proof that Euclid's Algorithm gives~$\gcd(m,n)$ is a repeated
application of Lemma~\ref{lem:akb}. 
\begin{ex}\label{ex:EA}
Consider~$m = 9108, n = 1121$.
The first step of Euclid's Algorithm is: $9108 = 8\cdot 1121 + 140$. 
The second
step is: $1121 = 8\cdot 140 + 1$, and the final step
is~$140 = 140\cdot 1 = 0$, giving remainder~$0$. The last nonzero
remainder is~$1$, which must be~$\gcd(9108,1121)$.
\par Note that we can reverse the steps of Euclid's Algorithm
to express $\gcd(m,n)$ as an integer linear combination of~$m,n$.
In this example, we write the equation from the last-nonzero-remainder
step as: $1 = 1121 - 8\cdot 140$. We then use the previous equation
[expressed as $140 = 9108 - 8\cdot 1121$] to obtain:
$1 = 1121 - 8\cdot (9108 - 8\cdot 1121)$
and so $1 = -8\cdot 9108 + 65\cdot 1121$.
\par Another way of performing the same computation is by
row operations on the matrix 
$\bigl( \latop{1}{0} \ \latop{0}{1} \ | \ \latop{m}{n} \bigr)$. 
In this case:
\par $ \bigl( \latop{1}{0} \ \latop{0}{1} \ | \ \latop{9108}{1121} \bigr)
\rightarrow^{R_1 - 8R_2}
\bigl( \latop{1}{0} \ \latop{-8}{1} \ | \ \latop{140}{1121} \bigr)
\rightarrow^{R_2 - 8R_1} 
\bigl( \latop{1}{-8} \ \latop{-8}{65} \ | \ \latop{140}{1} \bigr)
\rightarrow^{R_1 - 140 R_2} 
\bigl( \latop{*}{-8} \ \latop{*}{65} \ | \ \latop{0}{1} \bigr)$,
\par\noindent where the $*$ entries need not be computed.
This gives us, all in the same computation, that 
$\gcd(9108,1121) = 1$, and the bottom row of the last matrix
gives $\gcd(9108,1121)$ as a linear combination of~$9108,1121$,
namely: $1 = -8\cdot 9108 + 65\cdot 1121$, as before. 
\end{ex}
This process can be performed for any~$m,n$, giving the
following result.
\begin{lem}\label{lem:EArev}
For any~$m,n\in\bbbn$, there exist $\lambda, \mu \in \bbbz$
such that $\lambda m + \mu n = \gcd(m,n)$.
\end{lem}
\begin{defn}\label{defn:cong}
Let~$a,b,m\in \bbbz$. We say that $a \equiv b$~(mod~$m$) [`$a$ is congruent
to~$b$ modulo~$m$'] when $m | (a - b)$.
\end{defn}
For example, $2 \equiv 12$~(mod~$5$), since~$5 | (2-12)$.
It is straightforward to show that, if $a \equiv b$~(mod~$m$)
and $c \equiv d$~(mod~$m$), then
\par $a + c \equiv b + d,\ a-c \equiv b-d,\ ac \equiv bd,\
a^n \equiv b^n,\ ka \equiv kb\ (\mod n),$
\par\noindent for any~$k\in \bbbz$ and any $n\in\bbbz, n \geqslant 0$.
So, congruences in most ways can be manipulated like standard
equations. An exception is cancellation: $ka \equiv kb\ (\mod m)$
does not always imply that $a \equiv b\ (\mod m)$;
for example $2\cdot 4 \equiv 2 \cdot 1\ (\mod 6)$ even though
$ 4 \not\equiv 1\ (\mod 6)$. However, the implication 
is always true when~$k$ and~$m$ are coprime.
\begin{lem} If $\gcd(m,n) = 1$ then there exists $\lambda \in \bbbz$
such that $\lambda m \equiv 1\ (\mod n)$. In particular, if~$p$ is prime
and~$p\notdiv m$ then there exists $\lambda \in \bbbz$
such that $\lambda m \equiv 1\ (\mod p)$.
\end{lem}
\begin{prf}\ \ We know from Lemma~\ref{lem:EArev} that there exist
$\lambda, \mu$ such that $\lambda m + \mu n = \gcd(m,n)$.
Reducing modulo~$n$ immediately gives the required result.
\end{prf}
\begin{cor}\label{cor:fpgroup}
For any~$m\in \bbbn$, the set 
$G_m = \{ x : 1 \leqslant x \leqslant m, \gcd(x,m) = 1\}$
is a group under multiplication modulo~$m$.
In particular, for any prime~$p$, the set~$\{ 1,2,\ldots ,p-1\}$
is a group under multiplication modulo~$p$.
\end{cor}
Letting $G = \{ 1,2,\ldots ,p-1\}$, we can apply 
Corollary~\ref{cor:orderdivG} to obtain the following.
\begin{thm} (Fermat's Little Theorem). Let~$p$ be prime.
If $p \notdiv a$ then $a^{p-1} \equiv 1\ (\mod p)$.
\end{thm}
As a consequence, $a^p \equiv a\ (\mod p)$ for all~$a$, regardless
of whether $p | a$ or $p \notdiv a$.
\par Another natural problem in Number Theory is that of trying
to decide when one number is congruent to a square
modulo a prime.
\begin{defn}\label{defn:quadres}
Let ~$p$ be prime and $m \in \bbbz$. We say that~$m$ is
a {\it quadratic residue} mod~$p$ if there exists $x\in \bbbz$
such that $m \equiv x^2\ (\mod p)$. Otherwise $m$ is a
{\it quadratic non-residue} mod~$p$.
\end{defn}
For example, consider what happens modulo~$p=5$. Every number is
congruent to one of~$0,1,2,3\hbox{ or } 4\ (\mod 5)$
[which are the same as~$0,1,2,-2,-1\ (\mod 5)$].
Now: $0^2 \equiv 0, 1^2 \equiv 1, 2^2 \equiv 4, 3^2 = (-2)^2 \equiv 4,
4^2 = (-1)^2 \equiv 1$ (mod~$5$). So, $0,1,4$ are quadratic residues
mod~$5$, but~$2,3$ are not.
\begin{lem}\label{lem:halfsq}
For any prime~$p\not= 2$, $\psi : \bbbf_p^* \rightarrow \bbbf_p^*
: x \mapsto x^2$
is a $2$-to-$1$ map \hbox{[}$2$~elements map to~$1$ element\hbox{]},
with $\psi( x ) = \psi( p - x )$, or equivalently $\psi ( x ) = \psi (-x)$
\hbox{[}since $(p - x)^2 \equiv (-x)^2 \equiv x^2\ (\mod p)$\hbox{]}.
So exactly half of $\{ 1,\ldots ,p-1\}$ are quadratic residues
mod~$p$ and half are quadratic non-residues mod~$p$.
\end{lem}
\begin{defn}\label{defn:legendre}
For prime~$p$ and $p \notdiv m$, define the {\it Legendre symbol} by:
\par
$\bigl( \frac{m}{p} \bigr) = \begin{cases} 1 & \hbox{ if $m$ is a quadratic
residue mod~$p$,} \\
-1 & \text{ otherwise.}\end{cases}$
\par\noindent When~$p | m$, we normally
define~$\bigl( \frac{m}{p} \bigr) = 0$.
\end{defn}
For example, we have already seen that~$\bigl( \frac{2}{5} \bigr) = -1$.
Also, $\bigl( \frac{7}{5} \bigr) = \bigl( \frac{2}{5} \bigr) = -1$,
since~$7$ and~$2$ are congruent~(mod~$5$).
Similarly, $\bigl( \frac{11}{5} \bigr) = \bigl( \frac{1}{5} \bigr) = 1$
and $\bigl( \frac{10}{5} \bigr) = 0$.
\begin{lem}\label{lem:legendre}
Let~$p$ be an odd prime and let~$p \notdiv m, n, m_1, m_2$.
\par\noindent{\bf (a)} If $m_1 \equiv m_2\ (\mod p)$ then
$\bigl( \frac{m_1}{p} \bigr) = \bigl( \frac{m_2}{p} \bigr)$.
\par\noindent{\bf (b)} $\bigl( \frac{mn}{p} \bigr) = 
\bigl( \frac{m}{p} \bigr) \bigl( \frac{n}{p} \bigr)$, which is the same
as saying:
\par\noindent $mn\hbox{ is a quadratic residue mod }p \iff \hbox{ either }
(m\hbox{ and }n\hbox{ are both quadratic residues mod }p)$
\par
\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \
\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \
$\hbox{ or }
(m\hbox{ and }n\hbox{ are both quadratic non-residues mod }p)$
\par\noindent{\bf (c)} $\bigl( \frac{-1}{p} \bigr) = 1
\iff p \equiv 1\ (\mod 4) \hbox{ or } p = 2.
\ \ \bigl( \frac{-1}{p} \bigr) = -1 \iff p \equiv 3\ (\mod 4).$
\par\noindent{\bf (d)}  $\bigl( \frac{2}{p} \bigr) = 1
\iff p \equiv \pm 1\ (\mod 8). \ \ \bigl( \frac{2}{p} \bigr) = -1
\iff p \equiv \pm 3\ (\mod 8).$
\end{lem}
\begin{thm}\label{thm:recip} (Gauss' Law of Quadratic Reciprocity).
Let~$p\not= 2, q \not= 2$ be distinct primes.
\par If either $p \equiv 1\ (\mod 4) \hbox{ or } q \equiv 1\ (\mod 4)
\hbox{ then } \bigl( \frac{p}{q} \bigr) = \bigl( \frac{q}{p} \bigr)$.
\par If both $p \equiv 3\ (\mod 4) \hbox{ and } q \equiv 3\ (\mod 4)
\hbox{ then } \bigl( \frac{p}{q} \bigr) = -\bigl( \frac{q}{p} \bigr)$.
\end{thm}
\begin{ex}\label{ex:recip}
Let us decide whether~$6$ is a quadratic residue mod~$1019$
[which is prime],
using applications of quadratic reciprocity.
\par $\bigl( \frac{6}{1019} \bigr) 
= \bigl( \frac{2}{1019} \bigr) \bigl( \frac{3}{1019} \bigr)
= (-1) \bigl( \frac{3}{1019} \bigr)$ \hbox{\ [by Lemma~\ref{lem:legendre}(d)]}
\par $= (-1)(-1) \bigl( \frac{1019}{3} \bigr)$ \ [by quadratic reciprocity,
since both~$1019$ and~$3$ are $\equiv 3$~(mod~$4$)]
\par $= (-1)(-1) \bigl( \frac{2}{3} \bigr) = (-1)(-1)(-1) = -1,$
\par\noindent establishing that~$6$ is a quadratic non-residue
mod~$1019$ [and so there does not exist an integer~$x$ such 
that $6 \equiv x^2\ (\mod 1019)$], in a way much quicker
than checking that none of $0^2, 1^2, \ldots , 1018^2$
are congruent to~$6$ (mod~$1019$).
\end{ex}
\medskip
\centerline{\bf Rings}
There are many situations where we have two operations
on the same set, for example $\bbbz$ with both addition and multiplication.
\begin{defn}\label{defn:ring} 
Let~$R$ have two binary operations~$+,\times$.
$R$ is a {\it ring} (with~$1$) if:
\par $R$ is a commutative group under~$+$ with identity~$0$.
\par There exists an element~$1$ ($\not= 0$) such that,
for all~$r\in R$, $1\times r = r \times 1 = r$.
\par For all $r,s,t\in R$, $(r\times s)\times t = r\times (s\times t)$
[associativity of multiplication].
\par For all $r,s,t\in R$, $r\times (s + t) = r\times s + r\times t,\
(s + t)\times r = s\times r+ t\times r$ [left and right distributivity].
\par\noindent Note that, for any ring, addition is always commutative,
but multiplication need not be commutative.
When multiplication is commutative [that is, $r\times s = s\times r$
for all~$r,s\in R$] we say that~$R$ is a {\it commutative ring}.
\end{defn}
\begin{exs}\label{exs:ring}\
\par\noindent{\bf (a)} $\bbbz, +, \times$ is a commutative ring.
\par\noindent{\bf (b)} For any ring~$R$, define
$R[x] = \{ \hbox{polynomials in~$x$ with coefficients in }~R\}$,
which is also a ring, with the usual addition and multiplication
of polynomials. Also define the ring $R[[x]] = 
\{ \hbox{power series in~$x$ with 
coefficients in~$R$}\}$. The same is true when there are
several variables, for example: $R[x,y], R[[x,y]]$.
\par\noindent{\bf (c)} Let $G, +$ be any commutative group.
Let
$\hbox{End}(G) = \{ \phi : \phi \hbox{ is an endomorphism on }G\}$. 
Then $\hbox{End}(G)$ is a ring, with operations:
$(\phi_1 + \phi_2)(g) = \phi_1(g) + \phi_2(g)$ [defining
ring addition~$\phi_1 + \phi_2$],
and with ring multiplication given by~$\phi_1 \circ \phi_2$
[composition]. This is the {\it endomorphism ring} of the group~$G$.
\par\noindent{\bf (d)} $M_2(\bbbz) = \{ 2\times 2\hbox{ matrices
with integer entries}\}$ is a non-commutative ring,
with `0' given by $\bigl( \latop{0}{0} \latop {0}{0} \bigr)$
and `1' given by $\bigl( \latop{1}{0} \latop {0}{1} \bigr)$.
\par\noindent{\bf (e)} The set $\{ 0,\ldots , n-1\}$
under addition and multiplication modulo~$n$ is a commutative ring.
\end{exs}
\begin{defn}\label{defn:intdomain}
A commutative ring~$R$ is an {\it integral domain} if, for
all $r,s\in R$,
\par
\centerline{$rs = 0 \implies (r=0 \hbox{ or } s=0)$.}
\par
For example, $\bbbz$ and $\bbbz[[x]]$
are integral domains, but $M_2(\bbbz)$
is not, since $\bigl( \latop{1}{0} \latop {0}{0} \bigr)
\bigl( \latop{0}{0} \latop {0}{1} \bigr)
= \bigl( \latop{0}{0} \latop {0}{0} \bigr)$.
\end{defn}
\begin{defn}\label{defn:ringhom}
Let~$R_1,R_2$ be rings. A function $f : R_1 \rightarrow R_2$
is a {\it ring homomorphism} if, for all $r,s\in R_1$,
$f(r_1 + r_2) = f(r_1) + f(r_2)$ and 
$f(r_1 \times r_2) = f(r_1) \times f(r_2)$.
If~$f$ is also a bijection, then~$f$ is a {\it ring isomorphism}.
\par If there exists an isomorphism from~$R_1$ to~$R_2$,
then $R_1$ and $R_2$ are {\it isomorphic}, denoted~$R_1\cong R_2$.
\end{defn} 
The equivalent idea for rings to that of normal subgroups is as follows.
\begin{defn}\label{defn:ideal}
An {\it ideal} of a ring~$R$ is a subset~$I \subset R$ satisfying:
\par $I, +$ is a subgroup of~$R,+$.
\par For all $x\in I, r\in R$ we have $x \times r \in I$
and $r \times x \in I$.
\par\noindent This last condition can be phrased as: `the product
of anything in the ring with anything in the ideal must
be in the ideal'. Note that $1\in I\iff I = R$. If~$I \not= R$
then~$I$ is a {\it proper ideal}. If~$I$ is a proper ideal
and is not contained in a larger proper ideal, then~$I$
is a {\it maximal ideal}.
\end{defn}
\begin{defn}\label{defn:quotring}
Let~$I$ be an ideal of a ring~$R$; define the quotient
ring $R/I = \{ r + I : r\in R\}$, under the
operations $(r_1 + I) + (r_2 + I) = (r_1 + r_2) + I$
and $(r_1 + I) \times (r_2 + I) = (r_1 \times r_2) + I$.
\par
Note that~$I$ is an ideal if and only if it occurs
as the kernel of a ring homomorphism from~$R$ to some ring.
\end{defn}
For example, $x \bbbz[x]$ [the polynomials with~$0$ constant term]
is an ideal of the ring~$\bbbz[x]$. It is the kernel of
the ring homomorphism from~$\bbbz[x]$ to~$\bbbz$, defined
by~$p(x) \mapsto p(0)$. Furthermore: $\bbbz[x]/x \bbbz[x] \cong \bbbz$. 
Similarly, the ring of Example~\ref{exs:ring}(e) is
just the quotient ring $\bbbz/n\bbbz$.
\begin{defn}\label{defn:char}
Let~$R$ be a ring. If there exists an integer~$n \geqslant 1$
such that~$1 + 1 + \ldots + 1 [n\hbox{ times}] = 0$,
then the smallest such~$n$ is the {\it characteristic} of~$R$.
If no such~$n$ exists, then~$R$ is said to have
characteristic~$0$.
\par
For example, $\bbbz/n\bbbz$ has characteristic~$n$, whereas
$\bbbz, \bbbq, \bbbc$ all have characteristic~$0$.
\end{defn}
\medskip
\centerline{\bf Fields}
\begin{defn}\label{defn:field} 
Let~$K$ have two binary operations~$+,\times$.
$K$ is a {\it field} if:
\par $K$ is an Abelian group under~$+$ with identity~$0$,
\par The nonzero elements of~$K$ is an Abelian group under~$\times$
with identity~$1$,
\par For all $a,b\in K$, $a\times (b + c) = a\times b + a\times c$
[distributivity].
\end{defn}
Equivalently, we could define a field to be a commutative
ring for which every nonzero element has a multiplicative inverse.
\begin{exs}\label{exs:fields}\
\par\noindent{\bf (a)} $\bbbq,+,\times$ is a field.
\par\noindent{\bf (b)} Let $\bbbf_p, +,\times$ denote $\{ 0,1,\ldots,p-1\}$
under addition and multiplication modulo~$p$, where~$p$ is prime
[this is the same as $\bbbz/p\bbbz,+,\times$].
This a field with~$p$ elements (a {\it finite field}, since it
has only finitely many elements, as opposed to the infinite field~$\bbbq$).
The fact that it is a group under addition modulo~$p$
is straightforward. The fact that the nonzero elements form
a group under multiplication modulo~$p$ was shown in 
Corollary~\ref{cor:fpgroup}
\par\noindent{\bf (c)} $\bbbr, \bbbc, \bbbq(\sqrt{2}), \bbbq(i)$
are all fields. By $\bbbq(\sqrt{2})$ we 
mean $\{ a + b\sqrt{2} : a,b\in \bbbq\}$, and similarly for~$\bbbq(i)$.
\par\noindent{\bf (d)} $\bbbz,+,\times$ is not a field since the nonzero
integers is not a group under multiplication (for example,~$3$
has no inverse under multiplication).
\par\noindent{\bf (e)} $\bbbz/6\bbbz = \{ 0,1,2,3,4,5 \}$
under addition and multiplication modulo~$6$ is not a field for the
same reason. 
\par\noindent{\bf (f)} Given any ring~$R$ and maximal ideal~$\M$,
the quotient~$R/\M$ is always a field.
\par\noindent{\bf (g)} Given any integral domain~$R$, define
$K = \{ \frac{a}{b} : a,b\in R, b\not= 0\}$, where
we regard $\frac{a}{b} = \frac{a'}{b'}$ when $a b' = a'b$.
This is the {\it field of fractions} of~$R$. 
Addition and multiplication are defined as you would expect:
$\frac{a_1}{b_1} + \frac{a_2}{b_2} 
= \frac{a_1 \times b_2 + a_2\times b_1}{b_1 b_2}$
and $\frac{a_1}{b_1}\times \frac{a_2}{b_2} = \frac{a_1 a_2}{b_1 b_2}$.
More pedantically, you could define the field of
fractions as $\{ (a,b) : a,b\in R\}$ modulo the equivalence
relation: $(a,b) = (a',b') \iff a b' = a'b$, with
addition and multiplication defined by:
$(a_1,b_1) + (a_2,b_2)
= (a_1 \times b_2 + a_2\times b_1, b_1 b_2)$
and $(a_1,b_1)\times (a_2,b_2) = (a_1 a_2,b_1 b_2)$.
For example, $\bbbq$ is the field of fractions of~$\bbbz$.
\par\noindent{\bf (h)} For any integral domain~$R$, 
the field of fractions of~$R[x]$ is
denoted $R(x)$; it is the field of {\it rational functions}
in~$x$ over~$R$,
that is, $R(x) = \{ \frac{p(x)}{q(x)} : p(x),q(x)\in \bbbz[x], q(x)\not= 0\}$. 
Note that, if~$K$ is the field of fractions of~$R$, then
$R(x) = K(x)$.
\end{exs}
Since fields are special cases of rings, the definitions
for field homomorphism, field isomorphism and characteristic
are exactly as described for rings. An isomorphism from
a field to itself is an {\it automorphism}. 
\begin{defn}\label{defn:kstar}
Let $K,+,\times$ be a field. Then~$K^*$ always denotes the
group of nonzero elements of~$K$ under~$\times$
[for example, $\bbbq^*, \bbbr^*, \bbbc^*$ are all groups
under~$\times$].
\end{defn}
\begin{defn}\label{defn:algebraic}
Let~$K$ be a field. Any $p(x) \in K[x]$ is {\it irreducible}
if it cannot be written as a product of two polynomials
in~$K[x]$ both of degree~$\geqslant 1$. 
It is~{\it monic} if the leading coefficient [that is, the coefficient
of the highest power of~$x$] is~$1$.
Let~$\alpha$ be the root of any~$p(x) \in K[x]$ (not necessarily
irreducible); then~$\alpha$ is {\it algebraic} over~$K$.
For example, $\sqrt{2}$ is algebraic over~$\bbbq$, since it
is a root of~$x^2 - 2$; on the other hand, $\sqrt{-\pi}$
is algebraic over~$\bbbr$, but can be shown not to be algebraic
over~$\bbbq$. Given any~$\alpha$, algebraic over~$K$, there
always exists $p_\alpha(x)\in K[x]$ of smallest degree~$m_\alpha$
which has~$\alpha$ as a root, and which has the property that
it is a factor of any other member of~$K[x]$ which has~$\alpha$
as a root. We say that~$p_\alpha(x)$ is the {\it minimal polynomial}
of~$\alpha$ and that~$\alpha$ is {\it algebraic of degree~$m_\alpha$}
over~$K$. A field~$K$ is {\it algebraically closed} if every
polynomial $p(x)\in K[x]$ contains a root in~$K$.
\par
For example,~$\bbbc$ is algebraically closed, but~$\bbbq$ is not.
For any field~$K$ (whether algebraically closed or not),
there exists a field~$\overline K$, the {\it algebraic closure}
of~$K$, which is the smallest algebraically closed field
containing~$K$. Given~$\alpha$, algebraic of degree~$m_\alpha$
over~$K$, we can form the field~$K(\alpha)$, which is the smallest
subfield of~$\overline K$ containing~$K$ and~$\alpha$.
We say that~$K(\alpha)$ is the field obtained by {\it adjoining}~$\alpha$
to~$K$. A similar definition applied for any~$K(\alpha_1,\ldots ,\alpha_n)$.
A field~$L$ is an~{\it algebraic extension} of~$K$ if
$K\subset L$ and every~$\ell \in L$ is algebraic over~$K$,
otherwise~$L$ is a {\it transcendental} extension of~$K$.
\end{defn}
\begin{exs}\label{exs:alg}\
\par\noindent{\bf (a)} $\bbbc$ is the algebraic closure of~$\bbbr$.
\par\noindent{\bf (b)} The minimal polynomial of~$i$ over~$\bbbq$
is~$x^2 + 1$, so that~$i$ is algebraic of degree~$2$ over~$\bbbq$,
and $\bbbq(i) = \{ a + bi : a,b\in \bbbq\}$.
\end{exs}
\begin{defn}\label{defn:degext}
Let~$L$ be a field extension of~$K$ [that is,~$K,L$
are fields and~$K\subset L$; this is sometimes denoted $L/K$].
If there exists a finite
set $\ell_1,\ldots ,\ell_n\in L$ such that
every $\ell\in L$ can be written as 
$\ell = k_1 \ell_1 + \ldots + k_n \ell_n$, for some~$k_1,\ldots ,k_n\in K$,
then~$L$ is a {\it finite extension} of~$K$.
In such cases, it is then always possible to find such a set
with the extra property that~$k_1 \ell_1 + \ldots + k_n \ell_n\not= 0$
except when $k_1 = \ldots = k_n = 0$, in which case we say
that~$\ell_1,\ldots ,\ell_n$ is a {\it basis} for the field extension. 
We then say that~$n$ is the {\it degree} of the extension $L:K$,
or that $[L : K] = n$. Of course, if you wish, you can also phrase
this in terms of vector spaces. Letting the set of vectors be~$L$
and the field of scalars be~$K$, then~$L$ forms a vector space
with respect to vector addition: $\ell_1 + \ell_2$, 
for any~$\ell_1,\ell_2\in L$, being simply
the usual addition in the field~$L$, and scalar multiplication~$k\ell$,
for any $k\in K, \ell\in L$, being simple the usual multiplication in~$L$.
Then the degree of the extension $L:K$ is just the dimension
of this vector space.
\par A {\it number field} is a finite extension of~$\bbbq$
\end{defn}
\begin{ex}\label{numf}
The field~$\bbbq(\sqrt{2})$ is a degree~$2$ extension of~$\bbbq$,
with basis~$1,\sqrt{2}$.
\end{ex}
\begin{comm}\label{comm:extformula}
Let $K\subset L \subset M$ be fields. Then $[M:K] = [M:L][L:K]$.
\end{comm}
\begin{defn}\label{defn:galois}
Let~$L$ be a field extension of~$K$. Define the set
$$ \hbox{Aut}(L:K) = \{ \sigma : L \rightarrow L : \sigma
\hbox{ is an automorphism and } \sigma(k) = k\hbox{ for all }k\in K\},$$
that is, the set of all automorphisms of~$L$ which fix~$K$
[recall that an automorphism of~$L$ is a field isomorphism
from~$L$ to itself]. Then $\hbox{Aut}(L:K)$ forms a group under
the operation of function composition, the {\it automorphism group}
of the extension~$L:K$.
\par For any subgroup~$H\leqslant \hbox{Aut}(L:K)$, the {\it fixed field}
of~$H$ is the field~$\{ \ell \in L : \sigma(\ell) = \ell
\hbox{ for all }\sigma \in H\}$. If~$K$ is the fixed field
of~$\hbox{Aut}(L:K)$, we say that $L:K$ is a {\it Galois extension}
and we refer to $\hbox{Aut}(L:K)$ as the {\it Galois group}
of the extension, denoted $\hbox{Gal}(L:K)$ or $\hbox{Gal}(L/K)$ 
or $\hbox{Gal}_{L/K}$.
\end{defn}
\begin{ex}\label{ex:galois}
The group $\hbox{Gal}\bigl(\bbbq(\sqrt{2}):\bbbq\bigr)$ has two
elements: $e : a + b \sqrt{2} \mapsto a + b \sqrt{2}$
and $\sigma : a + b \sqrt{2} \mapsto a - b\sqrt{2}$.
\end{ex}
\medskip
\centerline{\bf Fields with Valuations}
\begin{defn}\label{defn:valuation0}
Let~$K$ be a field. A {\it valuation} on~$K$
is a function $\bb : K \rightarrow \bbbr$ satisfying:
\par $(1)\ |x| \geqslant 0$ for all~$x\in K$, with
equality if and only if~$x=0$.
\par $(2)\ |xy| = |x|\cdot |y|$ for all~$x,y\in K$.
\par $(3)\ |x + y| \leqslant |x| + |y|$ 
for all~$x,y\in K$ [the {\it triangle inequality}].
\par\noindent If a valuation also satisfies 
$|x + y| \leqslant \max (|x|,|y|)$, then we say that it is
a {\it non-Archimedean valuation}; otherwise we say that it is
an {\it Archimedean valuation}.
\end{defn}
\begin{ex}\label{ex:valuation0}
Any of~$\bbbq, \bbbr$, together with the usual notion of
absolute value: $|x| = \max(x,-x)$ [for example, $|-5| = |5| = 5$],
is a field with 
an Archimedean valuation. The same is true of~$\bbbc$, together
with the usual definition of modulus: $|a + bi| = \sqrt{a^2 + b^2}$. 
\end{ex}
Fields with valuations are special cases of metric spaces.
We first recall what these are.
\begin{defn}\label{defn:metric0}
A {\it metric space} is a set~$M$ together with a {\it metric}~$d$,
which is a function $d : M \times M \rightarrow \bbbr$, satisfying:
\par $(1)\ d(x,y) \geqslant 0$, for all~$x,y\in K$, with equality
if and only if $x=y$.
\par $(2)\ d(x,y) = d(y,x)$ for all~$x,y\in M$.
\par $(3)\ d(x,z) \leqslant d(x,y) + d(y,z)$ for all $x,y,z\in M$
[the {\it triangle inequality}].
\end{defn}
\begin{ex}\label{ex:metric0}
Let~$K, \bb$ be a field with valuation. Then~$K$ is a metric space
with respect to the associated metric $d(x,y) = |x - y|$.
\end{ex}
\begin{comm}\label{comm:absinf0}
The standard absolute value on~$\bbbq$ is sometimes denoted~$\binf$,
in order to distinguish is from other valuations on~$\bbbq$
(the $p$-adic valuations) that will be mentioned in the lecture course.
The associated metric is often denoted~$d_\infty$.
So, for example, $|-5|_\infty = |5|_\infty = 5$
and $d_\infty( 5, -3) = | 5 - (-3) |_\infty = 8$.  
\end{comm}
We shall give the following definitions in the context of a field
with a valuation,
but they could just as easily be given for a general metric space. 
\begin{defn}\label{defn:converge0}
Let~$K, \bb$ be a field with valuation. For $a_n, \ell \in K$,
we say that the sequence
$a_n$ {\it converges} to~$\ell$ [denoted $a_n \rightarrow \ell$] in~$K,\bb$
when $| a_n - \ell | \rightarrow 0$ in~$\bbbr, \binf$
as $n \rightarrow \infty$.
That is: for any~$\epsilon > 0$ there exists $N\in \bbbn$ such
that, $| a_n - \ell | < \epsilon$ for all~$n > N$. 
Given a sequence $a_n \in K$, if there exists $\ell\in K$ such that
$a_n \rightarrow \ell$ in~$K,\bb$ then we say that~$a_n$
{\it converges} in~$K,\bb$, or that it is {\it convergent} in~$K,\bb$.
\end{defn}
\begin{lem}\label{lem:limitprops0}
Let~$K, \bb$ be a field with valuation and suppose
that~$a_n \rightarrow \ell$ and $b_n \rightarrow m$ in~$K$
and let~$k\in K$. Then
the following standard limit properties are always satisfied.
\par $a_n + b_n \rightarrow \ell + m,\ \  a_n - b_n \rightarrow \ell - m,
\ \ ka_n \rightarrow k\ell,\ \
a_n b_n \rightarrow \ell m,\ \ \frac{a_n}{b_n} \rightarrow 
\frac{\ell}{m}\ \ [\hbox{when } b_n \not=0, m\not= 0].$ 
\end{lem}
\begin{defn}\label{defn:cauchy0}
Let~$K, \bb$ be a field with valuation. A sequence~$a_n\in K$
is {\it Cauchy} if $| a_m - a_n | \rightarrow 0$ in~$\bbbr,\binf$
as~$m,n\rightarrow \infty$.
That is: for any~$\epsilon > 0$ there exists $N\in \bbbn$ such
that, $| a_m - a_n | < \epsilon$ for all~$m,n > N$. 
\end{defn} 
Using $|a_m - a_n| = | a_m - \ell + \ell - a_n |
\leqslant | a_m - \ell | + | a_n - \ell |$, the following is immediate.
\begin{lem}\label{lem:convcauchy0}
If a sequence is convergent in~$K,\bb$ then it is also Cauchy.
\end{lem}
\begin{defn}\label{defn:complete0}
A field with valuation is {\it complete} if every Cauchy sequence
is convergent.
\end{defn}
\begin{exs}\label{exs:conv0}\
\par\noindent{\bf (a)} Define the sequence~$a_n = \frac{n-1}{n}$
in~$\bbbq, \binf$. Then $| a_n - 1 |_\infty = | - \frac{1}{n} |_\infty
= \frac{1}{n} \rightarrow 0$ as~$n\rightarrow \infty$, so
that $a_n \rightarrow 1$ in~$\bbbq, \binf$. This proves
that~$a_n$ is convergent in~$\bbbq, \binf$
(and therefore is also Cauchy).
\par\noindent{\bf (b)} Define~$a_1 = \frac{1}{10},\
a_2 = \frac{1}{10} + \frac{1}{10^2},\
a_3 = \frac{1}{10} + \frac{1}{10^2} + \frac{1}{10^3}, \ldots$
in~$\bbbq, \binf$.
Then $9 a_n + \frac{1}{10^n} = 1$ and
so $| a_n - \frac{1}{9}|_\infty = | - \frac{1}{9\cdot 10^n} |_\infty
= \frac{1}{9\cdot 10^n} \rightarrow 0$, as $n\rightarrow \infty$,
so that $a_n \rightarrow \frac{1}{9}$ in~$\bbbq, \binf$. This proves
that~$a_n$ is convergent in~$\bbbq, \binf$
(and therefore is also Cauchy).
\par\noindent{\bf (c)} Let~$f(x) = x^2 - 2$, and let~$\bigl(x_n,f(x_n)\bigr)$ 
be a point on~$y = f(x)$. The tangent line to~$y=f(x)$ at this point
has equation: $y - f(x_n) = f'(x_n) (x - x_n)$.
This tangent line cuts the $x$-axis when~$y=0$ and so solving
for~$x$ gives: $x = x_n - \frac{f(x_n)}{f'(x_n)}$.
In summary, the tangent line cuts the $x$-axis at
the point~$\bigl( x_n - \frac{f(x_n)}{f'(x_n)}, 0\bigr)$.
Define~$x_{n+1}$ to be the $x$-coordinate, that is:
\par \ \ \ \ $ x_{n+1} = x_n - \frac{f(x_n)}{f'(x_n)}
\ \ [\hbox{the Newton-Raphson formula}].$
\par\noindent So, now define a sequence~$a_n$ by $a_1 = 1$
and $a_{n+1} = a_n - \frac{f(a_n)}{f'(a_n)} = a_n - \frac{a_n^2-2}{2a_n}$,
the first few of which are: $a_1 = 1, a_2 = \frac{3}{2},
a_3 = \frac{17}{12},\ldots$
\par Does $a_n$ converge in~$\bbbq, \binf$? Well, imagine
that $a_n \rightarrow \ell$ in~$\bbbq, \binf$ for some~$\ell\in\bbbq$.
Taking the limit as $n\rightarrow \infty$
of $a_{n+1} = a_n - \frac{a_n^2-2}{2a_n}$
gives $\ell = \ell - \frac{\ell^2-2}{2\ell}$
and so~$\ell^2 - 2 = 0$; this is impossible for~$\ell\in \bbbq$,
which is a contradiction. We deduce that~$a_n$ is not convergent
in~$\bbbq, \binf$. However, it is easy to check that~$a_n$
is Cauchy, and so the converse of Lemma~\ref{lem:convcauchy0}
does not always hold. This shows that~$\bbbq, \binf$
is not a complete field.
\end{exs}
Suppose that we were living in a world where all we know is~$\bbbq$.
What would we make of this last example? It would appear
to have convergence-like properties, and yet does not converge
to anything within~$\bbbq$. We would feel that the sequence
is approaching some gap or `incompleteness' in our set, and that
it would be nice to extend~$\bbbq$ to a larger set in which
the sequence actually converges. One way of constructing such
a set is simply to consider the set of all Cauchy sequences
in~$\bbbq, \binf$. This certainly includes a copy of~$\bbbq$
since, for any $q\in \bbbq$, the sequence $q,q,q,\ldots$ is Cauchy.
However, there is the problem that we now have many different
Cauchy sequences representing what we would prefer to be just
one element. For example, the sequences $a_n = 0$, $b_n = 1/n$
and $c_n = 1/n^2$ are all Cauchy, and we would prefer to have
all of them simply be represented by the~$0$ element.
A natural solution is to say that two Cauchy sequences~$a_n,b_n$
are equivalent if $a_n - b_n \rightarrow 0$. The set of equivalence
classes of Cauchy sequences then gives us the set we want.
We can extend the field operations~$+,\times$ by defining
$[(a_n)] + [(b_n)]$ to be $[(a_n + b_n)]$ and similarly for
multiplication. Any equivalence class of sequences that actually
converge to a given~$q\in\bbbq$ can be denoted~$[q]$
(or simply~$q$), and these
give a copy of~$\bbbq$ within our new set. 
The equivalence class $\alpha$ containing the sequence
$a_n$ of Example~\ref{exs:conv0}(c) is a member of our new set,
and $\alpha^2 = [2]$, so that our new larger set includes a square
root of~$2$. This construction is generalised as follows.
\begin{defn}\label{defn:completion0}
Let~$K, \bb$ be a field with valuation. 
Define an equivalence relation on Cauchy sequences by:
$(a_n) \ttilde (b_n) \iff a_n - b_n \rightarrow 0$.
The {\it completion} $K'$
of~$K$ is the set of equivalence classes of Cauchy sequences.
This is a field with respect to the operations:
$[(a_n)] + [(b_n)] = [(a_n + b_n)]$ and 
$[(a_n)] \times [(b_n)] = [(a_n \times b_n)]$.
For any~$k\in K$, we can use~$[k]$ to denote the equivalence class of all
sequences converging to~$k$. Then $\{ [k] : k\in K\}$
gives a copy of~$K$ in~$K'$.
The field~$K'$ is complete and it is the smallest complete
field containing~$K$.
\end{defn}
\begin{comm}\label{comm:real0}
The completion of~$\bbbq, \binf$ is typically denoted~$\bbbr$,
and this gives a way of constructing the real numbers, having
starting only with~$\bbbq$. You might legitimately complain that
$\bbbr$ was mentioned in Definition~\ref{defn:valuation0}, the original
definition of valuation (since a valuation is defined to
be a map from~$K$ to~$\bbbr$). However, this is easily overcome, since
for~$\bbbq, \binf$ we can amend the definition of
valuation to be a map from~$\bbbq$ to~$\bbbq$, avoiding
any mention of~$\bbbr$ until its construction.
The status of the sequence~$a_n$ of Example~\ref{exs:conv0}(c)
is that it is both Cauchy and convergent in~$\bbbr, \binf$, but 
only Cauchy (and not convergent) in~$\bbbq, \binf$.
\end{comm}
\par
It might seem cumbersome to think of a real number as being
an equivalence class of Cauchy sequences, but of course in practice
it is easier to try a similar trick here as for quotient groups,
where we choose a representative for each equivalence class.
After all, this is what we are really doing with decimal
expansions of real numbers. When we write: $\sqrt{2} = 1.414\ldots$
this is a shorthand notation for the sequence $a_1 = 1.4,
a_2 = 1.41, a_3 = 1.414,\ldots$, where~$a_n \in \bbbq$
is the largest number to~$n$ decimal places satisfying~$a_n^2 < 2$. 
This sequence is Cauchy but not convergent in~$\bbbq, \binf$,
and it can be taken as the representative of its equivalence class,
and labelled~$\sqrt{2}$ in~$\bbbr$.
\par
If one were to replace all occurrences of~$|x-y|$ by $d(x,y)$,
and remove all mention of the field operations,
then the above discussion also describes completion
in the more general context of an arbitrary metric space.
However, we shall not require that level of generality here,
since all completions in the lecture course will be for
fields with valuations.
\par
Of course, if a different valuation were to be used on~$\bbbq$
then we would expect different sequences to converge, and
a different completion. In the lecture course, we shall see
another example of a valuation on~$\bbbq$,
the $p$-adic valuation~$\bp$.
The completion of~$\bbbq$ with respect to this valuation
is called the field of~$p$-adic numbers, denoted~$\bbbq_p$.
We shall see in the lecture course that the field~$\bbbq_p$ 
is helpful for tackling certain types of problems in Number Theory.
\par\medskip
\centerline{\bf Geometry}
\begin{defn}\label{defn:affinespace}
Let~$K$ be a field. $\A^n = \{ (x_1,\ldots ,x_n): x_1,\ldots x_n \in K\}$
is called {\it affine $n$-space}\footnote{Usually the field $K$ will be implicit, but we could write $\A^n_K$ if we want to remember it in the notation.}. When $P \in \A^n(K)$,
we say that~$P$ is {\it $K$-rational} or {\it defined over~$K$}.
\end{defn}
\begin{ex}\label{ex:affinespace}
$(\frac{1}{2}, \frac{3}{4}) \in \A^2(\bbbq) \subset \A^2(\bbbc)$.
The point $(\frac{1}{2}, \frac{3}{4})$ is $\bbbq$-rational
(we can also say: it is a $\bbbq$-rational point, or that it
is defined over~$\bbbq$). Of course, it is also $\bbbr$-rational
and $\bbbc$-rational. The point $(\frac{1}{2}, 2 + i, \sqrt{2}) 
\in \A^3(\bbbc)$ but is not a member of~$\A^3(\bbbq)$.
The point $(\frac{1}{2}, 2 + i, \sqrt{2})$ is defined over~$\bbbc$,
but not defined over~$\bbbq$ (it is $\bbbc$-rational, but
not $\bbbq$-rational).
\end{ex}
\begin{defn}\label{defn:ratfn}
A {\it monomial} is a product of the form $k x_1^{m_1}\ldots x_\ell^{m_\ell}$,
where $x_1,\ldots ,x_\ell$ are variables, $k\in K$, $m_1,\ldots ,m_\ell
\geqslant 0$, which has {\it degree} $m_1 + \ldots + m_\ell$
[so that a polynomial is a sum of monomials; we also call
the monomials the {\it terms} of the polynomials].
A {\it rational function} is a quotient of two polynomials.
\end{defn}
For example, $\frac{1 + x^2}{4 + x + x^3}$ is a rational function
in the variable~$x$, and $\frac{s + \sqrt{2}t^2}{1 + s + st^2}$ 
is a rational function in the variables~$s,t$.
Note that~$x^{1/2}$ is neither a polynomial nor a rational
function (all exponents in a polynomial must be integers~$\geqslant 0$).
\begin{defn}\label{defn:definedoverK}
An algebraic expression such as a curve, polynomial, rational function,
is said to be {\it defined over~$K$} (or $K$-rational)
if it can be described by an equation with coefficients in~$K$.
\end{defn}
\begin{exs}\label{exs:definedoverK}\
\par\noindent{\bf (a)} $x^3 + 1$ is a polynomial in~$x$, defined over~$\bbbq$.
\par\noindent{\bf (b)} $\frac{s + \sqrt{2}t^2}{1 + s + st^2}$ is
a rational function in~$s,t$, defined over~$\bbbq(\sqrt{2})$.
We could also say that it is a $\bbbq(\sqrt{2})$-rational
rational function. Note the two different uses of the word rational
here: in the phrase $\bbbq(\sqrt{2})$-rational, which refers
to the fact that the coefficients are in~$\bbbq(\sqrt{2})$,
and in the phrase `rational function', which refers to the fact
that the expression is a quotient of two polynomials.
\end{exs}
\begin{defn}\label{defn:affinecurve}
A (nonzero) polynomial in two variables $f(x,y)$, with coefficients
in~$K$, defines an (affine) {\it curve defined over~$K$}.
For any field~$L$ with $K\subset L$, the set of $L$-rational
points on a curve~$\C$ is denoted $\C(L)$. The field~$K$ is often
called the {\it field of definition} (or the {\it ground field}).
\end{defn}
\begin{ex}\label{ex:affinecurve}
Let $\C : f(x,y) = x^2 + y^2 = 0$. This defines an affine
curve over~$\bbbq$ [so, we can also say it is a curve defined over~$\bbbq$].
Of course, this same curve~$\C$ could be regarded having
field of definition (ground field) $\bbbq, \bbbq(\sqrt{2}), \bbbr, \bbbc$
or indeed any field containing~$\bbbq$. When the field of definition
is not stated explicitly, it is taken to be the smallest possible field
over which the curve is defined (in this case, $\bbbq$). 
The point $(0,0)$ is $\bbbq$-rational [since all the coordinates
are in~$\bbbq$] and it is the only $\bbbq$-rational point on~$\C$,
so that $\CQ = \{ (0,0) \}$. It has many $\bbbc$-rational points,
for example $(i,1) \in \C(\bbbc)$, since $i\in \bbbc, 1\in \bbbc$.
\end{ex}
\begin{comm}\label{comm:affinecurve}
Of course, it is also possible to embed curves in higher dimensional
space, as long as the number of `independent' polynomials
is one less than the number of variables; for example the~$2$
equations: $y^2 + 4 x^2 - 1 = 0, z^2 - x^2 - x = 0$ define
a curve in the variables $x,y,z$. However, we shall not concern ourselves
with that here, and we shall assume that all of our affine curves
are defined by a single polynomial in two variables.
\end{comm}
\begin{defn}\label{defn:homog}
The {\it degree} of a polynomial is the degree of its highest
degree monomial. A {\it homogeneous} polynomial is a polynomial
whose terms all have the same degree.
\end{defn}
\begin{ex}\label{ex:degree}
$f(x,y) = x + y - 8 = 0$ defines a curve of degree~$1$ (a {\it linear} curve),
$g(x,y) = xy + y^2 - y + 3 = 0$ defines a curve of degree~$2$
(a {\it quadratic} curve) and
$h(x,y) = x^3 + y^3 + y - 1$ defines
a curve of degree~$3$ (a {\it cubic} curve).
None of these polynomials are homogeneous.
\end{ex}
If you try drawing an accurate sketch of, for example, the three curves
$\C_1,\C_2,\C_3$ defined by $x^2 + y^2 = 1, y^2 = x^3, y^2 = x(x-2)^2$,
respectively, you will notice distinguishing features.
The first curve~$\C_1$ appears smooth at all points, and it
is easy to see that there is a unique tangent at each point.
The curve~$\C_2$ has a `sharp corner' at~$(0,0)$, and the third curve~$\C_3$
crosses itself at the point~$(2,0)$, when there is a plausible choice of
two distinct tangents. These sharp corners and crossing points
are typified by the fact that both partial derivatives of~$f$ vanish,
when the curve is written as~$f(x,y) = 0$.
\begin{defn}\label{defn:singular}
Let $\C : f(x,y) = 0$ be an (affine) curve defined over a field $K$ and let $P = (x_0,y_0)$
be a point in~$\C(\overline{K})$, where $\overline{K}$ is an algebraic closure of $K$. We say that $P$ is a {\it singular point}
(or a {\it singularity}) on~$\C$ if $\frac{\partial f}{\partial x}(P) = 0$
and $\frac{\partial f}{\partial y}(P) = 0$.
Otherwise,~$P$ is a {\it smooth point} (or a {\it nonsingular point})
on~$\C$. A curve~$\C$ is called {\it smooth} (or {\it nonsingular})
if it does not contain any singular points (the curve is
called {\it singular} if it contains at least one singular point).
\end{defn}
\begin{comm}\label{comm:tangents}
There is a standard technique for computing all tangents to~$\C : f(x,y)=0$
at a point~$P = (x_0,y_0)$, in which we first translate the curve
by~$(-x_0,-y_0)$ [so that~$(x_0,y_0)$ is taken
to~$(0,0)$], then use the fact that the lowest degree terms
dominate near~$(0,0)$ and determine the tangent behaviour at~$(0,0)$,
and then finally translate the curve back to its original position.
This gives three steps.
\par\noindent {\bf Step~1.} Consider~$f(x+x_0,y+y_0)$ [same as~$f(x,y)$
translated by~$(-x_0,-y_0)$] which contains the point~$x=y=0$ and
so has no constant term. We can write:
$$ f(x+x_0,y+y_0) = R_k(x,y) + R_{k+1}(x,y) + \ldots + R_n(x,y),
$$
where $k \geqslant 1$ and where each $R_i(x,y)$ is homogeneous of degree~$i$
(for $k\leqslant i \leqslant n$) and $R_k(x,y) \not= 0$.
\par\noindent {\bf Step~2.} Consider $R_k(x,y)$, which is the lowest degree
portion of $f(x+x_0,y+y_0)$, and factorise
$R_k(x,y) = L_1(x,y) L_2(x,y)\ldots L_k(x,y)$
over the algebraic closure, where $L_1,\ldots ,L_k$
are linear.
\par\noindent {\bf Step~3.} There are~$k$ tangents to
$f(x+x_0,y+y_0)=0$ at~$(0,0)$ namely:
$L_1(x,y) = 0, \ldots , L_k(x,y) = 0$. So, after reversing the translation
of Step~1, there are~$k$ tangents to~$\C : f(x,y) = 0$ at $P = (x_0,y_0)$,
namely:
$$ L_1(x-x_0,y-y_0) = 0, \ldots , L_k(x-x_0,y-y_0) = 0.$$
Note that the same tangent may be repeated more than once
[e.g.\ $\C : f(x,y) = y^2 - x^3 = 0$ has~$2$ tangents at~$(0,0)$,
namely: $y=0$ twice, in which case we can say that the tangent~$y=0$
occurs with multiplicity~$2$].
\end{comm}
\begin{comm}\label{comm:doublepoint}
$P = (x_0,y_0)$ is a smooth point on~$\C$
\par \ \ \ \ \ \ \ \ \ \ \ \ $\iff k=1$ in Step~1
\par \ \ \ \ \ \ \ \ \ \ \ \ $\iff$ there is only one tangent to~$\C$ at~$P$.
\par\noindent When $k \geqslant 2$, the singularity at~$P$
is called a {\it double point} ($k=2$), {\it triple point} ($k=3$), and so on.
\end{comm}
\begin{ex}\label{ex:sing1}
Let $\C_1 : x^2 + y^2 = 1$ [circle of radius~$1$ and centre~$(0,0)$].
Then we can write: $\C_1 : f(x,y) = x^2 + y^2 - 1 = 0$, and so
$\frac{\partial f}{\partial x} = 2x, \frac{\partial f}{\partial y} = 2y$.
A point~$(x,y)$ is a singular point on~$\C_1$ exactly when: it lies
on~$\C_1$ and both partial derivatives are zero, that is, when:
$$ (1)\ x^2 + y^2 - 1 = 0,\ \ \ (2)\ 2x = 0,\ \ \ (3)\ 2y = 0.$$
Assuming our ground field does not have characteristic $2$, equations (2),(3) force~$x=y=0$, but this does not satisfy~(1).
We conclude that there are no singular points and that~$\C_1$ is smooth.
\end{ex}
\begin{ex}\label{ex:sing2}
Let $\C_2 : y^2 = x^3$, that is: $\C_2 : f(x,y) = y^2 - x^3 = 0$.
Then $\frac{\partial f}{\partial x} = -3x^2,
\frac{\partial f}{\partial y} = 2y$.
We can see that the only singular point is~$(0,0)$.
For computing tangents at~$(0,0)$, we first take
$f(x + 0, y + 0) = y^2 - x^3 = R_2(x,y) + R_3(x,y)$,
where $R_2(x,y) = y^2$ and $R_3(x,y) = -x^3$.
Then $R_2(x,y) = y^2 = L_1(x,y)L_2(x,y) = y\cdot y$,
so there are two tangents to~$\C_2$ at~$(0,0)$, namely:
$L_1(x-0,y-0) = 0$ and $L_2(x-0, y-0) = 0$, that is:
$y=0$ and $y=0$ (i.e.\ $y=0$ with multiplicity~$2$).
A double point singularity where the same tangent line has
multiplicity~$2$ is called a~{\it cusp} (or a {\it cuspidal singularity}).
\end{ex}
\begin{ex}\label{ex:sing3}
Let $\C_3 : y^2 = x(x-2)^2$, that is: $\C_3 : f(x,y) = y^2 - x(x-2)^2 = 0$.
The point~$(x,y)$ on~$\C_3$ is singular when:
$$ (1)\ y^2 - x(x-2)^2 = 0,\ \ \ 
(2)\ \frac{\partial f}{\partial x} = -3x^2 + 8x - 4 = 0,\ \ \ 
(3)\ \frac{\partial f}{\partial y} =2y = 0.$$
Assuming our ground field does not have characteristic $2$, from~(3) we see that~$y=0$, and substituting this into~(1)
gives: $x(x-2)^2 = 0$, so that~$x=0$ or~$2$. Now, $x=2$ satisfies~(2),
but $x=0$ does not, giving $x=2$ as the only common solution. So, the
only possible singular point is~$(2,0)$ [conversely, check that
$x=2,y=0$ satisfies~(1),(2),(3) so that~$(2,0)$ is a singular point].
We conclude that~$(2,0)$ is the only singularity on~$\C_3$.
\par For the tangents at~$(2,0)$, first compute
$f(x+2,y+0) = y^2 - (x+2)x^2 = y^2 - 2x^2 - x^3 = R_2(x,y) + R_3(x,y)$,
where $R_2(x,y) = y^2 - 2x^2$ and $R_3(x,y) = -x^3$.
Factorising~$R_2(x,y)$ into linear factors gives: 
$R_2(x,y) = (y + \sqrt{2}x)(y - \sqrt{2}x) = L_1(x,y)L_2(x,y)$.
The tangents to the curve~$\C_3$ at~$(2,0)$ are then:
$L_1(x-2,y-0)=0$ and $L_2(x-2,y-0)=0$, that is:
$y = -\sqrt{2}(x-2)$ and $y = \sqrt{2}(x-2)$.
The point~$(2,0)$ is a double point with two distinct tangents;
such a point is called a {\it node} (or a {\it nodal singularity}).
\end{ex}
Note that the system of equations satisfied by singular points
is over-represented, since there are~$3$ equations and only~$2$
variables. If you choose a curve `at random', you would expect
the first two of these equations to have only finitely many solutions,
and it is rather a fluke if one of these solutions also happens
to satisfy the third equation. So, a `typical' curve will be smooth.
\par
A useful tool, for computing singularities and other purposes,
is the idea of the resultant of two polynomials.
\begin{defn}\label{defn:resultant}
Let $f(x) = f_m x^m + \ldots + f_0$ and $g(x) = g_n x^n + \ldots + g_0$,
where $f_m\not= 0$ and $g_n \not= 0$.
The {\it resultant} of~$f(x)$ and~$g(x)$, denoted 
$\hbox{Res}\bigl( f(x), g(x) \bigr)$ or just $\hbox{Res}( f, g )$,
the following determinant of an $(m+n) \times (m+n)$ matrix.
$$
\begin{array}{| c c c c c c c c c |}
 & \langle n-1 & \hbox{$0$'s}\rangle &  & & f_m    & \ldots & \ldots & f_0\\
 & \langle n-2 & \hbox{$0$'s}\rangle & & f_m & \ldots & \ldots &  f_0   &  0\\
  &   &   &     &  \vdots   &  &        &        &   \\
  &   &   &     &  \vdots   &  &        &        &   \\
f_m & \ldots & \ldots &  f_0   & &  & \langle n-1 & \hbox{$0$'s}\rangle &\\
 & \langle m-1 & \hbox{$0$'s}\rangle &  & & g_n & \ldots & \ldots & g_0\\
 & \langle m-2 & \hbox{$0$'s}\rangle & & g_n & \ldots & \ldots & g_0 &  0\\
  &   &   &     &  \vdots   &  &        &        &   \\
  &   &   &     &  \vdots   &  &        &        &   \\
g_n & \ldots & \ldots &  g_0 & &  & \langle m-1 & \hbox{$0$'s}\rangle & \\
\end{array}
$$
\end{defn}
The following are easy to show.
\begin{lem}\label{lem:resultant}
Let~$f(x), g(x)\in R[x]$ be polynomials of degree~$m,n$, respectively,
defined over a commutative ring~$R$.
\par\noindent{\bf (a)} There exist polynomials $p(x)\in R[x]$, of degree at
most~$n-1$, and~$q(x)\in R[x]$, of degree at most~$m-1$, such that:
$p(x) f(x) + q(x) g(x) = \hbox{Res}\bigl( f(x), g(x) \bigr)$.
\par\noindent{\bf (b)} When~$R$ is a field, 
$\hbox{Res}\bigl( f(x), g(x) \bigr) = 0
\iff f(x) \hbox{ and } g(x)$ have a non-constant common factor.
\end{lem}
\begin{defn}\label{defn:discrim}
The~{\it discriminant} of a degree~$n$ polynomial 
$f(x) = f_n x^n + \ldots f_0$ is given by:
$\hbox{Disc}(f) = \hbox{Res}(f,f')/f_n$.
\end{defn}
\begin{comm}\label{comm:discrim}
\par\noindent{\bf (a)} Given a monic polynomial $f(x) \in R[x]$,
there exist polynomials $p(x),q(x)\in R[x]$
such that $p(x) f(x) + q(x) f'(x) = \hbox{Disc}(f)$.
\par\noindent{\bf (b)}
$\hbox{Disc}(f) = 0 \iff f \hbox{ and } f'\hbox{ have a common
root} \iff f \hbox{ has a repeated root.}$
For example, $\hbox{Disc}(x^3 - 2x^2 + x) = 0$, 
%[roots~$0,1,1$, so there is a repeated root],
whereas $\hbox{Disc}(x^2 + 1) \not= 0$.
\end{comm}
\begin{ex}\label{ex:quadresultant}
Let~$f(x) = a x^2 + b x + c$. Then $\hbox{Disc}(f) =\hbox{Res}(f,f')/a$
$$
\begin{array}{c | c c c | c}
  & a & b & c &\\
= \hbox{Res}(ax^2+bx+c,2ax+b)/a 
=\ \ \frac{1}{a}& 0 & 2a & b & \ \ = b^2 - 4ac,\\
   & 2a & b & 0 &\\
\end{array}
$$
which is the discriminant you know from school,
appearing under the square root sign in the quadratic formula.
\end{ex}
\begin{ex}\label{ex:cubresultant}
Let~$f(x) = x^3 + Ax + B$. Then $\hbox{Disc}(f) =\hbox{Res}(f,f')$
$$
\begin{array}{c | c c c c c | c}
     & 0 & 1 & 0 & A & B &\\
     & 1 & 0 & A & B & 0 &\\
= \hbox{Res}(x^3 + Ax + B, 3x^2 + A) =\ \ 
                       & 0 & 0 & 3 & 0 & A &\ \ = 4A^3 + 27 B^2.\\
     & 0 & 3 & 0 & A & 0 &\\
     & 3 & 0 & A & 0 & 0 &\\
\end{array}
$$
\end{ex}
\begin{ex}\label{ecdiscrim}
An application of resultants to singularities is as follows.
Consider the curve $\C : y^2 = x^3 + Ax + B$ [that
is: $g(x,y) = x^3 + Ax + B - y^2 = 0$], where~$A,B \in K$,
a field of characteristic not equal to~$2$. 
Suppose $(x_0,y_0)$ is a singular point on~$\C$, so that:
$$ (1)\ g(x_0,y_0) = 0,\ \ (2)\ \frac{\partial g}{\partial x}(x_0,y_0) = 0,
\ \ (3)\ \frac{\partial g}{\partial y}(x_0,y_0) = 0,
$$
giving:
$$ (1)\ y_0^2 = x_0^3 + Ax_0 + B,\ \ 
(2)\ 3 x_0^2 + A = 0,
\ \ (3)\ 2 y_0 = 0.
$$
Since the characteristic of~$K$ is not equal to~$2$, we know
that~$2\not=0$, and so~(3) gives~$y_0 = 0$.
Substituting this into~(1) tells us that~$x_0$ is a root
of~$x^3 + Ax + B$, and~(2) tells us that~$x_0$ is a root
of its derivative; this is possible exactly when~$x^3 + Ax + B$
has a repeated root -- in other words, when $\hbox{Disc}(x^3 + Ax + B) = 0$.
We have already seen in Example~\ref{ex:cubresultant}
that $\hbox{Disc}(x^3 + Ax + B) = 4A^3 + 27 B^2$.
\par In summary, the curve~$\C$ is smooth if and only if
$4A^3 + 27 B^2 \not= 0$.
\end{ex}
Another basic idea in geometry applies to situations where
$f(x,y)$ itself has a proper factorisation, for example:
$\C : f(x,y) = x^2 - y^2 = 0$. This is a quadratic curve,
but it factors as $(x+y)(x-y) = 0$, and so the graph of~$\C$
is just the union of the graphs of the lines~$x+y=0$ and $x-y=0$.
This seems geometrically different from curve such as $x^2 - y^2 + 1 = 0$,
which has no such factorisation. This is formalised in the following
definition.
\begin{defn}\label{defn:irred}
Let~$\C : f(x,y) = 0$ be a curve defined over~$K$, and let~$L$
be any field containing~$K$.
We say that~$\C$ is {\it irreducible over~$L$} if~$f(x,y)$ cannot
be expressed as a product of two polynomials, both of degree~$\geqslant 1$
and both defined over~$L$ [by the word~{\it irreducible} on its own,
we mean irreducible over~$K$]. For any~$\C : f(x,y) = 0$, we
can write~$f$ uniquely (up to constants and reordering) as a 
product $f = f_1 f_2 \ldots f_n$, where $f_1,\ldots ,f_n$
are irreducible over~$L$. The curves 
$\C_1 : f_1(x,y) = 0, \ldots , \C_n : f_n(x,y) = 0$
are called the {\it irreducible components} of~$\C$ over~$L$.
\end{defn}
\begin{exs}\label{exs:irred}\
\par\noindent{\bf (a)} $\C : f(x,y) = y^2 - 2x^2 = 0$, defined over~$\bbbq$.
This is irreducible [by which we mean irreducible over~$\Q$],
but it becomes reducible over~$\bbbc$, with irreducible
components $\C_1 : y = \sqrt{2}x$ and $\C_2 : y = -\sqrt{2}x$.
\par\noindent{\bf (b)} $\C : f(x,y) = y^4 - x^4 = 0$ is reducible.
Its irreducible components (over~$\bbbq$) are: $y-x=0, y+x=0, y^2+x^2=0$.
The last of these becomes reducible over~$\bbbc$ , and the 
irreducible components over~$\bbbc$ are: $y-x=0, y+x=0, y+ix=0, y-ix=0$. 
%\par\noindent{\bf (c)} It can be shown that $\C : y^2 - x^3 - 1$
%is irreducible over~$\bbbc$. 
\end{exs}
It is also helpful to formalise the relationship between curves
such as $x^2 + y^3 - 5 = 0$ and $(x+1)^2 + y^3 - 5 = 0$,
where there are maps from one to the other.
In this case, one can map each curve to the
other with a linear map, but more generally we consider 
maps between curves described by rational 
functions (quotients of polynomials).
\begin{defn}\label{defn:birat}
Let $\C : f(x,y) = 0$ and $\C' : g(x,y) = 0$ be curves over~$K$.
A {\it rational map}~$\uphi$ over~$L$ from~$\C$ to~$\C'$
is a map given by a pair $\phi_1,\phi_2$ of rational functions
in~$x,y$, defined over~$L$ [i.e.\ $\phi_1, \phi_2$ are both
of the form $\frac{\hbox{polynomial in $x,y$}}{\hbox{polynomial in $x,y$}}$
and the coefficients of~$\phi_1, \phi_2$ are in~$L$], with the property that,
given any point $P = (x_0,y_0)$ on~$\C$, then the point
$\bigl( \phi_1(x_0,y_0), \phi_2(x_0,y_0) \bigr)$ lies on~$\C'$
[for all but finitely many points~$(x_0,y_0)$ at which the denominators
of~$\phi_1,\phi_2$ are~$0$]. If there also exists a rational map
$\upsi = \bigl( \psi_1(x,y), \psi_2(x,y) \bigr)$ from~$\C'$ to~$\C$
such that $\upsi \ \uphi$ is the identity on~$\C$ and
$\uphi \ \upsi$ is the identity on~$\C'$ then we say that~$\uphi$
is a {\it birational transformation} over~$L$ from~$\C$ to~$\C'$
and that~$\C$ and~$\C'$ are {\it birationally equivalent}
over~$L$.
\end{defn}
\begin{exs}\label{exs:birat}\
\par\noindent{\bf (a)} Let $\C : x^4 + y^4 = 1$ 
[i.e.\ $f(x,y) = x^4 + y^4 - 1 = 0$] and let $\C' : x^4 + y^2 = 1$
[i.e.\ $g(x,y) = x^4 + y^2 - 1 = 0$]. 
Define~$\uphi : \C \rightarrow \C'$ by $\uphi(x,y) = (x,y^2)$
[in the notation of the Definition~\ref{defn:birat}: $\phi_1(x,y)=x$ and
$\phi_2(x,y) = y^2$]. This is a rational map from~$\C$
to~$\C'$ over~$\bbbq$ since, if~$(x,y)$ satisfies $\C : x^4 + y^4 = 1$
then $x^4 + (y^2)^2 = 1$ and so $(x,y^2)$ lies on~$\C'$.
This is a rational map from~$\C$ to~$\C'$, but it is not a birational
transformation, since there is no inverse map ($\uphi$ is $2$-to-$1$).
\par\smallskip\noindent{\bf (b)} Let $\C : x^2 + y^3 - 5 = 0$ and
$\C' : (x+1)^2 + y^3 - 5 = 0$.
If~$(x,y)$ is on~$\C$ then $x^2 + y^3 - 5= 0$ and 
so $((x-1)+1)^2 + y^3 - 5 = 0$,
giving that $(x-1,y)$ lies on~$\C'$. The
map $\uphi(x,y) = \bigl( \phi_1(x,y), \phi_2(x,y)\bigr) = (x-1,y)$
is then a rational map over~$\bbbq$ from~$\C$ to~$\C'$,
and the inverse map is clearly $\upsi(x,y) = (x+1,y)$.
The map $\uphi$ is a birational transformation from~$\C$ to~$\C'$ 
over~$\bbbq$, and so~$\C$ and~$\C'$ are birationally equivalent
over~$\bbbq$.
\par Note that the rational map from~$\C$ to~$\C'$ is in the opposite
direction to the variable replacement which transforms the equations.
In the above example, $\uphi(x,y) = (x-1,y)$ is the map from~$\C$ to~$\C'$
[in that it maps points on~$\C$ to points on~$\C'$; for example,
the point~$(2,1)$ on~$\C$ maps to~$(1,1)$ on~$\C'$], but
the variable replacement `replace~$x$ by~$x-1$ and~$y$ by~$y$'
changes the equation for~$\C'$ into the equation for~$\C$.
\par\smallskip\noindent {\bf (c)} Let~$\C : x^2 - y^2 = 0$
and $\C' : x^2 + y^2 = 0$. Clearly $\uphi : \C \rightarrow \C'$,
defined by $\uphi(x,y) = (x,iy)$ is a rational map from~$\C$ to~$\C'$,
with inverse~$\upsi(x,y) = (x,-iy)$. This shows that~$\C$ and~$\C'$
are birationally equivalent over~$\bbbc$. However, $\C$ and~$\C'$
are not birationally equivalent over~$\bbbq$, since any such
map would take the infinitely many members of~$\CQ$ to infinitely
many members of~$\C'(\bbbq)$, contradicting the fact that
$\C'(\bbbq) = \{ (0,0) \}$.
\par\smallskip\noindent {\bf (d)} Let~$\C : y^2 = x^4 + 3x^2 + 5$
and $\C' : y^2 = 5x^4 + 3x^2 + 1$. Define $\uphi(x,y) = 
(\frac{1}{x}, \frac{y}{x^2})$. If $(x,y)$ is a point on~$\C$
then $y^2 = x^4 + 3x^2 + 5$ and so $\frac{y^2}{x^4} = 1 + \frac{3}{x^2}
+ \frac{5}{x^4}$, giving: 
$\bigl( \frac{y}{x^2} \bigr)^2 = 1 + 3\bigl( \frac{1}{x}\bigr)^2 
+ 5\bigl( \frac{1}{x}\bigr)^4$, so that 
$\bigl(\frac{1}{x},\frac{y}{x^2}\bigr)$ is a point on~$\C'$.
Our map~$\uphi$ is then a rational map (over~$\bbbq$)
from~$\C$ to~$\C'$. The inverse map is $\upsi(x,y) = 
(\frac{1}{x}, \frac{y}{x^2})$ [check that 
$\upsi\bigl(\uphi(x,y)\bigr) = \upsi\bigl( \frac{1}{x}, \frac{y}{x^2} \bigr)
= \bigl( \frac{1}{1/x} , \frac{y/x^2}{(1/x)^2} \bigr) = (x,y)$,
so that $\upsi\ \uphi$ is the identity, as is $\uphi\ \upsi$]. 
Hence~$\uphi$ is a birational transformation over~$\bbbq$;
the curves~$\C$ and~$\C'$ are birationally equivalent over~$\bbbq$.
\par\smallskip\noindent {\bf (e)} Let $\C : x^2 + y^2 = 1$ and $\C' : y = 0$.
It might at first seem surprising that a circle should be birationally
equivalent to a line, but we can establish the map first by fixing
a specific point on~$\C$, say~$P_0 = (-1,0)$, and mapping a point
on~$\C$ to~$s = \frac{y}{x+1}$, the slope of the line from~$P_0$
to~$(x,y)$ [literally, we are mapping it to~$(s,0)$].
Define: $\uphi(x,y) = ( \frac{y}{x+1} , 0 )$ from~$\C$ to~$\C'$
[defined everywhere except at the point~$(-1,0)$, but this is
permissible, since the definition of rational map allows
us to have a finite number of points where the map is not defined].
For the inverse, note that if the slope is~$s$, then the line
through~$P_0$ and~$(x,y)$ has equation: $y = s(x+1)$;
substituting this into~$\C$ gives $x^2 + s^2(x+1)^2 = 1$,
and so: $(x + 1)( x - 1 + s^2(x + 1) ) = 0$. When~$x\not = -1$,
this gives~$x = \frac{1 - s^2}{1 + s^2}$ and
$y = s(x+1) = \frac{2s}{1 + s^2}$. This suggests
that, for the inverse map, we should take:
$\upsi(x,y) = \bigl( \frac{1 - x^2}{1 + x^2}, \frac{2x}{1 + x^2} \bigr)$.
It is straightforward to check that this is indeed a map
from~$\C'$ to~$\C$ [since $\bigl( \frac{1 - x^2}{1 + x^2} \bigr)^2
+ \bigl( \frac{2x}{1 + x^2} \bigr)^2 = 1$  for any~$x$],
that $\upsi \ \uphi =$ identity on~$\C$ and
that $\uphi \ \upsi =$ identity on~$\C'$.
Hence~$\C$ and~$\C'$ are birationally equivalent over~$\Q$.
\end{exs}
\begin{defn}\label{defn:param}
A {\it parametrisation} of a curve~$\C$ is a birational equivalence
between~$\C$ and a line.
\end{defn}
\begin{comm}\label{comm:param}
The birational transformation in Example~\ref{exs:birat}(e)
is a parametrisation of the circle~$x^2 + y^2 = 1$.
Note that a parametrisation is an unusual type of birational
transformation, in that it gives a map to a single variable;
in this case, $\bigl( \frac{1 - s^2}{1 + s^2}, \frac{2s}{1 + s^2} \bigr)$
gives a description of the points on~$\C$ in terms of the
parameter~$s$. Since the maps~$\uphi$ and~$\upsi$ are defined over~$\bbbq$,
this gives a way of describing all $\bbbq$-rational points on~$\C$,
namely: $(x,y) \in \CQ \iff s \in \Q$. For example,
$s=2$ gives $\bigl( -\frac{3}{5}, \frac{4}{5}\bigr) \in \CQ$.
\end{comm}
The curve~$x^2 + y^2 = 1$ is a special case of the following
class of curves.
\begin{defn}\label{defn:conic}
A {\it conic} is a quadratic curve: 
$a x^2 + 2 b x y + c y^2 + 2 d x + 2 f y + g = 0$, satisfying
$$ 
\begin{array}{ | c c c | c}
 a & b & d & \\
 b & c & f & \ \not= 0
\ \ \ \hbox{(which guarantees that the curve is smooth).}\\
 d & f & g & \\
\end{array}
$$
\end{defn}
A conic is an ellipse, hyperbola or parabola; the name `conic'
refers to the fact that these are the curves which can be obtained
by intersecting a plane and a double-cone [two cones with the same
axis, placed apex to apex]. The parametrisation of the circle
given in Example~\ref{exs:birat}(e) is a special case of
the following result.
\begin{thm}\label{thm:conic}
Any conic~$\C$ (over~$K$) with a $K$-rational point is birationally
equivalent to a line [i.e.\ it is parametrisable].
\end{thm}
\begin{prf}\ \
We are given that there exists a $K$-rational point $(x_0,y_0)$
on the curve $\C : f(x,y) = 0$. Let $g(x,y) = f(x + x_0, y + y_0)$.
This contains the point~$(0,0)$ so that we can write:
$g(x,y) = g_1(x,y) + g_2(x,y)$, where~$g_1$ is homogeneous 
\& linear, and~$g_2$ is homogeneous \& quadratic.
Hence $g(x,tx) = x\phi_1(t) + x^2\phi_2(t) = 0$.
Apart from~$x=0$, we can take $x = -\phi_1(t)/\phi_2(t),
y = -t \phi_1(t)/\phi_2(t)$ [with inverse $t = y/x$]
as a parametrisation of~$g(x,y) = 0$.
The parametrisation of~$\C$ is then:
$x = x_0-\phi_1(t)/\phi_2(t), y = y_0 -t \phi_1(t)/\phi_2(t)$ 
[with inverse $t = (y-y_0)/(x-x_0)$].
\end{prf}
\begin{defn}\label{defn:intersect}
The curves $\C : f(x,y) = 0$ and $\C' : g(x,y) = 0$
{\it intersect} at~$P = (x_0,y_0)$ if~$P$ lies on
both of~$\C$ and~$\C'$ [that is, $f(x_0,y_0) =
g(x_0,y_0) = 0$]. 
%The curves {\it intersect with multiplicity~$r>0$}
%at~$P$ if both~$f(x_0,y_0) = g(x_0,y_0) = 0$ 
%and $\frac{\ddd^i y}{\ddd x^i}(P) \hbox{ on~$\C$} = 
%\frac{\ddd^i y}{\ddd x^i}(P) \hbox{ on~$\C'$}$ for 
%all $1\leqslant i \leqslant r-1$ [if the tangents at~$P$ are vertical,
%then use~$\frac{\ddd^i x}{\ddd y^i}$ instead of~$\frac{\ddd^i y}{\ddd x^i}$].
\end{defn}
\begin{defn}\label{defn:intersectmult}
Suppose the curves $\C : f(x,y) = 0$ and $\C' : g(x,y) = 0$
intersect at~$P = (x_0,y_0) \in \C(L)$ (with $L$ a field containing the field of definition of the curve). The curves {\it intersect with multiplicity~$r>0$}
at~$P$ if the dimension of the quotient ring \[\dim_L L\lb x,y \rb/(f(x+x_0,y+y_0),g(x+x_0,y+y_0)) = r.\]
\end{defn}
The intersection multiplicity is $\infty$ if and only if $\C$ and $\C'$ have a common irreducible component containing $P$. We refer to Fulton \emph{Algebraic Curves} for details and proofs of the fundamental properties of the intersection multiplicity. You can also take a look at Part B Algebraic Curves for an approach via resultants. 

\begin{lem}\label{lem:curvelinemult}
Consider a curve $\C : f(x,y) = 0$ over $K$ and a line $\D$ parameterised by $x = at + b$, $y = ct + d$, with $a,b,c,d \in K$ and $a,c$ not both zero. Then $\C$ and $\D$ intersect at the points $P = (a t_0 + b,ct_0+d)$ with $t_0$ a root of the polynomial $F(t) = f(at+b,ct+d)$. If $F(t)$ is identically $0$, then $\C$ contains the line $\D$. 

Suppose $t_0 \in \overline{K}$ is a root of $F(t)$ and let $P = (a t_0 + b,ct_0+d)$. Then $\C$ and $\D$ intersect at $P$ with multiplicity equal to the multiplicity of $t_0$ as a root of $F(t)$. 
\end{lem}
\begin{proof} The intersection property is clear, so we need to verify the assertion about multiplicities. We can apply an affine transformation and assume WLOG that $t_0 = 0$, so $P = (b,d)$. The line $\D$ has equation $g(x,y) = cx - ay +ad-bc = 0$. 
	We have to compute the dimension of the $\overline{K}$-vector space 
	\[\overline{K}\lb x,y\rb/(f(x+b,y+d),g(x+b,y+d)).\] It is not hard to check that the map
	\begin{align*}
\overline{K}\lb x,y\rb/(g(x+b,y+d) &\to  \overline{K}\lb t \rb \\
x &\mapsto a t\\
y &\mapsto ct
	\end{align*} is an isomorphism. So we need to compute the dimension of the $\overline{K}$-vector space 
	\[\overline{K}\lb t\rb/(f(at+b,ct+d)) = \overline{K}\lb t\rb/(F(t)).\]
We claim that this is equal to the multiplicity of $0$ as a root of $F(t)$. Write $F(t) = t^r \tilde{F}(t)$, where $\tilde{F}(t)$ has non-zero constant term. It is a nice exercise to show that $\tilde{F}(t)$ has a multiplicative inverse in the formal power series ring $\overline{K}\lb t\rb$. So the ideal generated by $F(t)$ is equal to $(t^r)$. Finally, we see that $\overline{K}\lb t \rb/(t^r)$ has dimension $r$, since it has $1,t,\ldots,t^{r-1}$ as a basis.
\end{proof}
\begin{lem}
	Suppose $\C$ and $\C'$ are two curves intersecting at a point $P \in \C(K) \cap \C'(K)$. Suppose moreover that $P$ is a nonsingular point on both curves. Then the intersection multiplicity at $P$ is $> 1$ if and only if the tangent lines to $\C$ and $\C'$ at $P$ coincide. 
\end{lem}
\begin{proof}
	Translating $x$ and $y$, we may assume that $P= (0,0)$. If $f(x,y)$ is the equation for $\C$, suppose WLOG that $\lambda = \frac{\partial f}{\partial y}(P) \ne 0$ (otherwise we can swap the roles of $x$ and $y$). Then the tangent line to $\C$ at $P$ has equation $y = -\lambda^{-1}\frac{\partial f}{\partial x}(P)x$. In this situation, the natural map $K\lb x\rb \to K\lb x,y\rb/(f(x,y))$ is an isomorphism, with inverse given by mapping $y$ to a power series $Y(x)$ of the form $Y(x) = -\lambda^{-1}\frac{\partial f}{\partial x}(P)x~+$ higher order terms. (This can be proved by a version of Hensel's lemma, which we will see in the course, and is the implicit function theorem for formal power series.) So we have to compute the dimension of the quotient $K\lb x \rb / (g(x,Y(x)))$. As in the proof of Lemma \ref{lem:curvelinemult}, this is given by the multiplicity of $0$ as a root of $g(x,Y(x))$. It is $> 1$ if and only if the linear part $ax+by$ of $g(x,y)$ satisfies $a - b\lambda^{-1}\frac{\partial f}{\partial x}(P) = 0$. On the other hand, the tangent to $\C'$ at $P$ has equation $ax + by = 0$. A short calculation shows that this tangent is the same as the tangent for $\C$ if and only if we do indeed have $a - b\lambda^{-1}\frac{\partial f}{\partial x}(P) = 0$ (necessarily with $b$ nonzero, since $P$ is a nonsingular point of $\C'$). 
\end{proof}
In the situation of the above proof, if $\frac{\partial f}{\partial y}(P) \ne 0$ and $\frac{\partial g}{\partial y}(P) \ne 0$, we can moreover compute the intersection multiplicity using the power series $Y(x), \tilde{Y}(x)$ which respectively satisfy $f(x,Y(x)) = 0, g(x,\tilde{Y}(x)) = 0$. Indeed, the ideals generated by $f(x,y)$ and $g(x,y)$ in $K\lb x,y\rb$ are equal to $(y-Y(x))$ and $(y-\tilde{Y}(x))$ respectively, so $K\lb x,y \rb / (f(x,y),g(x,y)) = K\lb x,y \rb / (y-Y(x),y-\tilde{Y}(x)) = K\lb x \rb / (Y(x)-\tilde{Y}(x))$. So the multiplicity is the order of vanishing at $x = 0$ of $Y(x)-\tilde{Y}(x)$. When $K$ has characteristic $0$, we deduce that the curves intersect with multiplicity $\ge r$ if $\frac{\ddd^i y}{\ddd x^i}(P) \hbox{ on~$\C$} = 
\frac{\ddd^i y}{\ddd x^i}(P) \hbox{ on~$\C'$}$ for 
all $1\leqslant i \leqslant r-1$ (via the Taylor expansion formula, these derivatives determine the power series $Y(x)$ and $\tilde{Y}(x)$ up to degree $r-1$).

\begin{ex}\label{ex:intersect}
Let $\C : y^2 = x^3 + 2x + 1$ and $\D : y = x + 1$.
On substituting~$\D$ into~$\C$ we see that the $x$-coordinate of
any point of intersection must satisfy $(x + 1)^2 = x^3 + 2x + 1$,
and so $x^2(x-1) = 0$, giving only~$x=0,1$ as possibilities.
Substituting~$x=0$ in~$\D$ gives~$y=1$; substituting~$x=1$ in~$\D$
gives~$y=2$. So, the only possible points of intersection
are~$(0,1)$ and~$(1,2)$ [and these do indeed lie on~$\C$ and~$\D$]. It also follows from Lemma \ref{lem:curvelinemult} that the intersection multiplicities at these points are $2$ and $1$ respectively.
%To find the multiplicity of intersection at~$(0,1)$, compute:
%\par On~$\C$, $2y \frac{\ddd y}{\ddd x} = 3x^2 + 2$,
%and so $\frac{\ddd y}{\ddd x}(0,1)  = \frac{3\cdot 0^2 + 2}{2\cdot 1} = 1$.
%\par On~$\D, \frac{\ddd y}{\ddd x} = 1$ everywhere.
%\par On~$\C$, $2\frac{\ddd y}{\ddd x}\frac{\ddd y}{\ddd x} 
%+ 2y\frac{\ddd^2 y}{\ddd x^2}
%= 6x$ gives $2 \frac{\ddd y}{\ddd x}(0,1)\frac{\ddd y}{\ddd x}(0,1) 
%+ 2y\frac{\ddd^2 y}{\ddd x^2}(0,1) = 6\cdot 0$,
%so $\frac{\ddd^2 y}{\ddd x^2}(0,1) = -1$.
%\par On~$\D$, $\frac{\ddd^2 y}{\ddd x^2} = 0$ everywhere.
%\par\noindent In summary,~$(0,1)$ lies on both~$\C$ and~$\D$,
%and $\frac{\ddd y}{\ddd x}(0,1)$ on~$\C$ is equal to
%$\frac{\ddd y}{\ddd x}(0,1)$ on~$\D$, but
%$\frac{\ddd^2 y}{\ddd x^2}(0,1)$ in~$\C$ is not equal to
%$\frac{\ddd^2 y}{\ddd x^2}(0,1)$ on~$\D$. Hence~$(0,1)$ is a point
%of intersection of multiplicity~$2$.
%\par The points~$(1,2)$ lies on both~$\C$ and~$\D$, but
%$\frac{\ddd y}{\ddd x}(1,2) = \frac{3\cdot 1^2 + 2}{2\cdot 2} = \frac{5}{4}$
%on~$\C$, which is not equal to $\frac{\ddd y}{\ddd x}(1,2) = 1$ on~$\D$,
%so that~$(1,2)$ is a point of intersection of multiplicity~$1$.
%\par In summary, we say that~$\C$ and~$\D$ have $3$ points
%of intersection, namely: $(0,1)$ with multiplicity~$2$
%and~$(1,2)$ with multiplicity~$1$.
\end{ex}
\begin{comm}\label{comm:resintersect}
For more complicated examples, we cannot always find the points
of intersection by a straightforward substitution of one equation
into the other. Given two curves~$\C : f(x,y) = 0$ of degree~$m$
and $\D : g(x,y) = 0$ of degree~$n$,
a systematic approach to finding the points
of intersection is possible via resultants. One initially picks
one of the variables, $y$~say, and
computes the resultant of~$f(x,y)$ and~$g(x,y)$, regarded as
polynomials in~$y$, by writing them as:
$f(x,y) = f_m(x)y^m + \ldots + f_0(x)$, and similarly for~$g(x,y)$.
The matrix in Definition~\ref{defn:resultant} will have
entries that are polynomials in~$x$, and consideration of the
degrees of these polynomials shows that the resultant
of~$f(x,y)$ and~$g(x,y)$ (regarded as 
polynomials in~$y$) will be a polynomial in~$x$ of degree at
most~$mn$. Any point of intersection of~$\C$ and~$\D$ must
have $x$-coordinate  which is a root of the at-most-degree-$mn$
polynomial. For each value of~$x$, one can then substitute back
into~$\C$ and~$\D$ to find the corresponding $y$-coordinates.
\end{comm}
\medskip
\centerline{\bf Projective Space}
There are several respects in which affine space is unsatisfying.
Consider, for example, the true statement in affine space:
two distinct lines meet at exactly one point, except when parallel.
It would be much nicer to have a cleaner statement,
in which we remove `except when parallel'.
Intuitively, parallel lines intersect `at infinity', given
that the point of intersection shoots off to infinity as
two lines become closer and closer to parallel.
Similarly, consider the affine curves: $\C : y^2 = x^3 + 1$
and $D : y = x + 1$; these meet at the points~$(-1,0), (0,1),(2,3)$,
each with multiplicity~$1$. On trying other lines in place
of~$\D$, one typically finds again that there are 3~points
of intersection (when counted with multiplicity). An apparent exception
is~$\D : x = 0$, which intersects~$\C$ only at~$(0,1)$ and~$(0,-1)$,
and this is true for any vertical line. We seem to have a rule:
any line intersects~$\C$ at exactly $3$~points (counted with
multiplicity) except when the line is vertical. Again, we
would like a cleaner statement, in which we remove `except
when the line is vertical'. Again, the third point
of intersection seems to be `at infinity'.
\par
Points at infinity are intuitively points~$(x,y)$ where there
is a denominator of~$0$. We cannot express this idea using only
pairs~$(x,y)$, where~$x,y$ lie in a field~$K$. A natural approach
is to write: $x = X/Z, y = Y/Z$ and identify the point~$(x,y)$
with the triple~$(X,Y,Z)$. As long as~$Z\not= 0$, we can
go in the other direction from the triple~$(X,Y,Z)$ to~$(x,y)$.
Note that, for any~$k\in K^*$, the triple~$(kX, kY, kZ)$
corresponds to~$(kX/kZ, kY/kZ) = (X/Z, Y/Z) = (x,y)$, and so
we impose a relation, that two triples are regarded 
as being the same if they
are nonzero scalar multiples of each other. Subject to this
relation, there is then a $1-1$ correspondence between~$(x,y)$
and triples~$(X,Y,Z)$ with~$Z\not=0$.
On the other hand, the triples~$(X,Y,Z)$ with~$Z=0$
do not correspond to any~$x,y\in K$, and such triples give
us a way of describing formally these new points at infinity.
\begin{defn}\label{defn:proj}
Let~$K$ be a field.
$\P^n(K) = \{ (x_0,\ldots ,x_n) : x_0,\ldots ,x_n \in K,
\hbox{ not all }0\}$, subject to the relation that
$(x_0,\ldots x_n) = (y_0,\ldots ,y_n)$ in~$\P^n(K)$
if there exists~$r\in K, r\not=0$, such
that $(y_0,\ldots ,y_n) = (r x_0,\ldots r x_n)$.
$\P^n(K)$ is called {\it projective} $n$-space over~$K$.
\end{defn}
\begin{ex}\label{ex:proj}
$(1,2,3) = (3,6,9)$ in $\P^2(\bbbq)$. [N.B.\ $(0,0,0)\not\in \P^2(\bbbq)$.] 
\end{ex}
\begin{defn}\label{defn:projpoly}
A {\it polynomial in $n$ projective variables}
is an $(n+1)$-variable homogeneous polynomial.
%[recall: this means
%that all terms have the same degree].
% for example,
%$X^3 - 3X Z^2 + Z^3$ is a polynomial in $1$~projective variable,
%defined over~$\bbbq$.
A {\it projective curve} in~$\P^2$ is defined by a homogeneous 
polynomial in~$3$ variables~$F(X,Y,Z) = 0$, for example,
$X^3 + Y^3 - Z^3 = 0$.
\end{defn}
\begin{defn}\label{defn:homogenisation}
Let~$\C : f(x,y) = 0$ be an (affine) curve.
The {\it homogenisation} of~$\C$ is the projective curve~$F(X,Y,Z) = 0$
of the same degree as~$f(x,y)$, with the 
property that~$F(x,y,1) = f(x,y)$. A point~$(X_0,Y_0,Z_0)$
on~$F(X,Y,Z)=0$ with~$Z_0=0$ is called a {\it point at infinity} on~$\C$.
When~$Z_0\not= 0$, the point~$(X_0,Y_0,Z_0)$ corresponds
to~$(X_0/Z_0, Y_0/Z_0)$ on~$f(x,y) = 0$.
\end{defn}
\begin{ex}\label{ex:homog1}
Let~$\C : y^2 = 4 x^2 + 1$, so that~$f(x,y) = y^2 - 4 x^2 - 1 = 0$.
The associated projective curve (the homogenisation) is:
$Y^2 = 4 X^2 + Z^2$ [so that $F(X,Y,Z) = Y^2 - 4 X^2 - Z^2$].
The two points at infinity are: $(1,2,0)$ and~$(1,-2,0)$.
\end{ex}
\begin{ex}\label{ex:homog2}
For the curve~$\C : y^2 = x^3 + 1$, the associated projective
curve is~$Z Y^2 = X^3 + Z^3$. To find the points at infinity
(the points where~$Z=0$),
substitute~$Z=0$ into the equation, giving $X^3= 0$ and so~$X=0$.
This forces~$Y\not= 0$ [since~$(0,0,0)$ is not allowed as
a point in~$\P^2$]. So, the points at infinity are of the
form~$(0,Y,0)$, where~$Y\not= 0$. But these are all the
same in~$\P^2$, since they are scalar multiples of each other;
therefore this is exactly one point at infinity, which we
can represent by~$(0,1,0)$, say.
\end{ex}
\begin{comm}\label{comm:parallel}
Two distinct affine lines $a_1 x + b_1 y + c_1 = 0$
and $a_2 x + b_2 y + c_2 = 0$ meet at exactly one point,
except when parallel. For example, $x + y + 2 = 0$
and $x + y + 3 = 0$ do not intersect.
For projective lines, the rule is the same, but we
can remove the phrase `except when parallel'.
For example, the projective lines $X + Y  + 2Z = 0$
and $X + Y + 3Z = 0$ have~$(1,-1,0)$ as the unique
point of intersection.
\end{comm}
\begin{defn}\label{defn:projsing}
A projective curve~$F(X,Y,Z) = 0$ has a {\it singularity}
at~$(X_0,Y_0,Z_0)$ when:
\par $F(X_0,Y_0,Z_0) = \frac{\partial F}{\partial X}(X_0,Y_0,Z_0) =
\frac{\partial F}{\partial Y}(X_0,Y_0,Z_0) =
\frac{\partial F}{\partial Z}(X_0,Y_0,Z_0) = 0$.
\end{defn}
\begin{comm}\label{comm:projbirat}
Note that, by multiplying through by denominators, we can take
rational maps and birational transformations between projective
curves to be of the form: 
\par \ \ $ \uphi (X,Y,Z) = \bigl( \phi_1(X,Y,Z), \phi_2(X,Y,Z),
\phi_3(X,Y,Z) \bigr)$,
\par\noindent where $\phi_1, \phi_2, \phi_3$ are homogeneous
polynomials, rather than rational functions.
\end{comm}
\begin{comm}\label{projint}
Suppose that two projective curves $F(X,Y,Z) = 0$
and $G(X,Y,Z) = 0$ have a point of intersection~$(X_0,Y_0,Z_0)$.
The multiplicity of intersection can always be computed by
using some associated affine curve. 
At least one of~$X_0,Y_0,Z_0$ must be nonzero, since~$(0,0,0)$
is not allowed in~$\P^2$.
If~$Z_0\not= 0$ then the
multiplicity of intersection is the same as that
of~$(X_0/Z_0, Y_0/Z_0)$ on the affine curves~$F(x,y,1) = 0$
and $G(x,y,1) = 0$ [here, $x = X/Z, y = Y/Z$].
If~$Y_0\not= 0$ then one can use~$F(x,1,z), G(x,1,z)$, where
$x = X/Y, z = Z/Y$. If~$X_0 \not= 0$ then 
one can use~$F(1,y,z), G(1,y,z)$, where $y = Y/X, z = Z/X$.
\end{comm}
\begin{thm}\label{thm:bezout}
(B\'ezout's Theorem). Two projective curves, with no common
component [i.e.\ with no common non-constant factor]
of degrees~$m,n$ intersect at precisely~$mn$ points, counted
with multiplicity.
\end{thm}
\begin{ex}\label{ex:bezout}
The projective curves~$Z Y^2 = X^3 + Z^3$ and $X = 0$
intersect at the points $(0,1,1), (0,-1,1), (0,1,0)$, 
each with multiplicity~$1$.
\end{ex}
\medskip
\centerline{\bf Elliptic Curves}
The following overlaps with the material that
will be presented during the first week of the Part~C Elliptic Curves
lecture course.
\par Curves can be classified according to a property called
{\it genus}, which is invariant under birational equivalence.
We shall not go into the technicalities of what precisely
is meant by genus, and its properties, which would be
an entire lecture course in its own right.
The simplest type are curves of genus~$0$, which can be defined
by quadratic and linear equations. 
Recall from Theorem~\ref{thm:conic} that any conic with
a rational point can be parametrised. 
%Arithmetic questions about
%curves of genus~$0$ are reasonably straightforward to answer;
%given a conic defined over~$\bbbq$, say, one can decide within
%a predetermined amount of time whether the curve has a rational
%point. If a rational point exists, then the parametrisation
%of Theorem~\ref{thm:conic} describes all the rational points.
\par
Curves of genus~$1$ are the next natural class of curves to
consider; they are, in a sense, the next `simplest' type
of curve after conics. 
Please don't confuse `elliptic curves' (which are
of genus~$1$) with ellipses (which are of genus~$0$).
The classical terminology comes from a relationship between cubic curves
and elliptic integrals, which were much studied in the 19th century.
It can be shown that a curve of genus~$1$
is not parametrisable.
An {\it elliptic curve} over~$K$ is defined to be a nonsingular projective
curve of genus~$1$, defined over~$K$, together with a $K$-rational point on the curve.
It can also be shown that any curve
of genus~$1$ is birationally equivalent over~$K$ to a nonsingular projective cubic curve. 
\par
For the purposes of this lecture course, you can 
forget about the term `genus' and simply take this as the definition
of an elliptic curve, as follows.
\begin{defn}\label{defn:elliptic0}
An elliptic curve over a field~$K$ is a nonsingular projective cubic curve, defined over~$K$, with a specified $K$-rational point. 
\end{defn}
A property which makes elliptic curves of particular interest
is the fact that there is a natural way to combine any two points~$\a,\b$
on the curve to obtain a third point~$\a+\b$. The following defines
what we mean by~$\a + \b$ and by~$-\a$.
\begin{defn}\label{defn:grouplaw0}
	Let $\C : F(X,Y,Z) = 0$ be an elliptic curve $/ K$
	(the notation $/ K$ means `defined over~$K$'; that is, all
	of the coefficients of~$\C$ are in the field~$K$).
	So,~$\C$ is a nonsingular projective cubic curve, with a $K$-rational
	point, which we shall denote~$\o$.
	For any two points~$\a,\b$ on~$\C$ (defined over a common extension field $L/K$), let~$\ell_{\a,\b}$
	denote the line which meets~$\C$ at~$\a,\b$ (if~$\a,\b$ are distinct
	then~$\ell_{\a,\b}$ is the unique line through~$\a,\b$;
	if~$\a=\b$ then $\ell_{\a,\b}$ is the line tangent to~$\C$ at~$\a=\b$).
	
	\begin{minipage}[c]{0.4\textwidth}
		\includegraphics[width=\textwidth]{add-1.png}
	\end{minipage}\begin{minipage}[c]{0.6\textwidth}
		Let $\ell_{\a,\b}$ denote the line which meets~$\C$ at~$\a,\b$.
		
		Then~$\ell_{\a,\b}$ and~$\C$ have~$3$ points of intersection
		(B\'ezout).
		
		Let~$\d$ be the third point of intersection between~$\C$
		and~$\ell_{\a,\b}$. 
		
		Now, let~$\ell_{\o,\d}$ denote the line which meets~$\C$ at~$\o$
		and~$\d$.
		
		Let~$\c$ be the third point of intersection between~$\C$ and~$\ell_{\o,\d}$.
		
		Define~$\a + \b = \c$.
	\end{minipage}
	%\vskip 20pt
	%\newpage
	%\hskip 120 pt \vrule width 1 pt depth 2 pt height 130 pt
	%\reallynopagebreak
	%\vskip-150pt
	%\hskip 37 pt {\lower 6.8pt \hbox{\a}} \hskip 28 pt 
	%{\lower 6.8pt \hbox{\b}}
	%\par  $\ell_{\a,\b}$ \hskip 30 pt {\lower 3pt\hbox{$|$}} 
	%\hskip 30 pt {\lower 3pt\hbox{$|$}}
	%\hskip 40 pt $\d$
	%\hrule width 150 pt depth 1 pt height 1 pt
	%\vskip 30 pt \hskip 117 pt --- \c
	%\vskip 20 pt \hskip 117 pt --- \o
	%\vskip 20 pt \hskip 123 pt $\ell_{\o,\d}$
	%\reallynopagebreak
	%\vskip-125pt
	
	\begin{minipage}[c]{0.4\textwidth}
		\includegraphics[width=\textwidth]{add-2.png}
	\end{minipage}\begin{minipage}[c]{0.6\textwidth}
		Let~$\ell_{\o,\o}$ be the line tangent to~$\C$ at~$\o$.
		
		Let~$\k$ be the third point of intersection between~$\C$ and~$\ell_{\o,\o}$.
		
		Now, let~$\ell_{\a,\k}$ be the line which meets~$\C$ at~$\a$ and~$\k$.
		
		Let~$\overline\a$ be the third point of intersection between~$\C$ and~$\ell_{\a,\k}$.
		
		Define~$-\a$ to be~$\overline\a$.
	\end{minipage}
\end{defn}
%\reallynopagebreak
\par
We shall soon show that $\a + \b$ is a commutative 
group law on the points on~$\C$, with identity~$\o$ and
the inverse of~$\a$ given by~$-\a$. 
First we need the
following technical lemma.
\par
\begin{lem}\label{lem:pregplaw0}
Let~$P_1,\ldots , P_8$ be such that no~$4$ points lie on
a line and no~$7$ points lie on a conic. Then there exists
a unique point~$P_9$ which is
a 9th point of intersection of any two cubics passing
through~$P_1,\ldots ,P_8$.
\end{lem}
\begin{prf}\ (Sketch). Any projective cubic curve
$\C : F(X,Y,Z) = f_1 X^3 + f_2 Y^3 + \ldots + f_{10} XYZ = 0$
has~$10$ coefficients~$f_1,\ldots ,f_{10}$, and the condition
that~$P_1,\ldots ,P_8$ lie on~$\C$ gives linear equations
which must be satisfied by the coefficients [the condition that
no~$4$ lie on a line and no~$7$ lie on a conic give that
the equations are linearly independent].
So, there are two free parameters~$\lambda, \mu$ and~$F$
can be written: $F = \lambda F_1 + \mu F_2$, where~$F_1,F_2$ are
fixed cubic through~$P_1,\ldots ,P_8$. By B\'ezout's Theorem,
$F_1,F_2$ have a 9th point of intersection~$P_9$, which
must lie on any~$\lambda F_1 + \mu F_2$.
\end{prf}
\newpage\begin{thm}\label{thm:gplaw0}
Let~$\C$ be an elliptic curve~$/K$, with $K$-rational point~$\o$.
Then~$\a + \b$, as in Definition~\ref{defn:grouplaw0},
gives a commutative group law on the points on~$\C$, with
identity~$\o$. The inverse of~$\a$ is given by the point $-\a$,
constructed in in Definition~\ref{defn:grouplaw0}.
Further, the $K$-rational points~$\C(K)$ form a subgroup,
called the~{\it Mordell-Weil group}.
\end{thm}
\begin{prf}\ \
It is easy to show commutativity, the fact that~$\o$ is the identity, and the
fact that~$-\a$ is the inverse of~$\a$.
The only difficult problem is associativity. In order
to prove associativity, consider the following diagram.
\par
\medskip
\hskip 50 pt \vrule width 1 pt depth 2 pt height 240 pt \hskip 60 pt
\vrule width 1 pt depth 2 pt height 240 pt \hskip 60 pt
\vrule width 1 pt depth 2 pt height 240 pt 
\reallynopagebreak
\vskip-230pt \hskip 127 pt {\lower 5.5pt \hbox{\bf w}} \vskip -5 pt
\hskip 53 pt {\bf a} \hskip 67 pt {\lower 3pt\hbox{$|$}} 
\hskip 36 pt {\bf v} \hskip 60 pt $r$ \vskip -2.5 pt
\hrule width 240 pt depth 1 pt height 1 pt \vskip 15 pt
\hskip 98 pt {\bf f} \hskip -2 pt --- \vskip 28 pt
\hskip 52.5 pt {\bf b} \hskip 50 pt {\bf c} \hskip 50 pt {\bf u}
\hskip 60 pt $s$ \vskip 2pt
\hrule width 240 pt depth 1 pt height 1 pt \vskip 65 pt
\hskip 52.5 pt {\bf d} \hskip 50 pt {\bf e} \hskip 51 pt \o
\hskip 62 pt $t$ \vskip 1pt
\hrule width 240 pt depth 1 pt height 1 pt \vskip 50 pt
\hskip 49 pt $\ell$ \hskip 51 pt $m$ \hskip 48 pt $n$
\medskip
\par
Here, $r,s,t,\ell,m,n$ are lines. On each line, the labelled points
are the points of intersection between~$\C$ and that line.
From the construction of Definition~\ref{defn:grouplaw0}:
\par
\centerline{$\a + \b = \e$,}
\par\noindent and so:
\par
\centerline{$(\a + \b) + \c =$ 3rd point of intersection on~$\ell_{\o,\f}$.}
Similarly:
\par
\centerline{$\b + \c = \v$,}
\par
\centerline{$\a + (\b + \c) =$ 3rd point of intersection on~$\ell_{\o,\w}$.}
\par\noindent To show $(\a + \b) + \c = \a + (\b + \c)$, it
is sufficient to show that~$\f = \w$. Let $F_1 = \ell m n$
and $F_2 = rst$, both of which are cubic curves.
\par $\C$ and~$F_1$ have~$8$ common points: $\a,\b,\c,\d,\e,\u,\v,\o$.
\par $\C$ and~$F_2$ also have these~$8$ 
common points: $\a,\b,\c,\d,\e,\u,\v,\o$.
\par\noindent From Lemma~\ref{lem:pregplaw0}, the 9th point of
intersection of~$\C$ and~$F_1$ must be the same as the 9th
point of intersection of~$\C$ and~$F_2$; that is, $\f = \w$,
as required. 
\par
Hence, $+$ is a commutative group law.
\par
It remains to show that~$\CK$ is a subgroup. We are given that
$\o \in \CK$. Let~$\a,\b \in \CK$. It is sufficient to
show that~$\a + \b \in \CK$ and that~$-\a\in \CK$.
In the following, we shall write points and equations of
lines in affine form, as a shorthand notation for the corresponding
projective points and lines (their homogenisations).
\par Let~$\a = (x_1,y_1)$ and $\b = (x_2,y_2)$,
where~$x_1,y_1,x_2,y_2\in K$. Then the line through~$\a,\b$
is (in affine form) $\ell_{\a,\b} : y = \ell x + m$, where 
$\ell = \frac{y_1 - y_2}{x_1 - x_2}\in K$
and $m = \frac{x_1 y_2 - x_2 y_1}{x_1 - x_2} \in K$.
Substitute $y = \ell x + m$ into the cubic equation for~$\C$
to get; $\phi(x) = x^3 + c_2 x^2 + c_1 x + c_0 = 0$, defined over~$K$.
Let~$\phi(x) = (x - x_1)(x-x_2)(x-x_3)$ be the factorisation of~$\phi(x)$.
Then~$x_1,x_2,x_3$ are the $3$~roots of~$\phi$ and so~$x_1+x_2+x_3 = -c_2$,
giving: $x_3 = -c_2 - x_1 - x_2 \in K$ and $y_3 = \ell x_3 + m \in K$.
The line~$\ell_{\a,\b}$ then meets~$\C$ at 
$\a,\b,\d = (x_3,y_3) \in \CK$.
The same argument shows that the line $\ell_{\o,d}$ through~$\o,\d$
has 3rd point of intersection~$\c$ which is also in~$\CK$.
But $\c = \a+\b$ and so we have shown that~$\a + \b \in \CK$.
A similar argument shows that if $\a \in \CK$ then $-\a \in \CK$.
Hence $\CK$ is a subgroup, as required.
\end{prf}
\par
It is apparent that, in the above proof, we have dealt
with the `typical' case, where none of our points are repeated
(for the proof of associativity),
and none are at infinity (for the proof that~$\CK$ is a subgroup,
since the points were written in affine form). It
is straightforward to check these special cases; we shall not
bother to do so here.
\par
\begin{comm}\label{comm:affineell0}
By an elliptic curve, we shall always mean a projective curve,
but often write the equation in affine form. Note that,
whichever way it is written, we are always referring to the
projective curve. For example, if we say `let $\C : y^2 = x^3 + 3$
be an elliptic curve', it should be understood that
this is a shorthand notation for the corresponding
projective curve $Z Y^2 = X^3 + 3 Z^3$.
\end{comm}
It can be shown that any elliptic curve over~$K$ can 
be birationally transformed
over~$K$ to {\it Weierstrass form}, which is quadratic in
one of the variables ($y$, say) and cubic in the other variable~($x$,~say):
$$ \E : y^2 + a_1 x y + a_3 y = x^3 + a_2 x^2 + a_4 x + a_6.$$
Indeed, as long as we avoid fields with small characteristic,
we can simplify the equation still further.
\begin{thm}\label{thm:wform0}
Let~$K$ be a field satisfying $\hbox{char}(K) \not= 2$ [recall -- this
means that $1 + 1\not= 0$].
Then any elliptic curve over~$K$ is birationally equivalent over~$K$
to the form $y^2 = \hbox{cubic in }x$. If $\hbox{char}(K) \not= 2,3$
then the curve is birationally equivalent over~$K$ to
a curve of the form $y^2 = x^3 + A x + B$.
\end{thm}
\begin{comm}\label{comm:wform0}
When $char(K) \neq 2,3$, we shall typically take our elliptic curves to have the form
$$ \E : y^2 = x^3 + Ax + B, \hbox{ where } A,B \in K,$$
which should be regarded as shorthand for the projective
curve $Z Y^2 = X^3 + A X Z^2 + B Z^3$. Sometimes it will
be convenient to include the $x^2$ term. 
Since~$\E$ is nonsingular, we must have~$\Delta = 4 A^3 + 27 B^2 \not= 0$,
as was shown in Example~\ref{ecdiscrim} (note the assumption there that $char(K)\neq 2$).
The notation~$\Delta = 4 A^3 + 27 B^2$ is standard.
\par It is conventional to choose~$\o = (0,1,0)$, the point
at infinity, as the identity [we shall always take $\o = (0,1,0)$
unless otherwise stated]. Note that the line~$Z = 0$ meets~$\E$
at~$\o$ three times (such a point is called an~{\it inflexion}).
Given a point~$\a = (X,Y,Z)$, if we take the line through~$\a$
and~$\o = (0,1,0)$ then the third point of intersection is
$(X,-Y,Z)$, which must then be~$-\a$. In affine form: 
$$ -(x,y) = (x,-y). $$
This gives an easy rule for finding the inverse of a point,
under the group law, namely: the inverse of~$\a$ is its
reflection in the $x$-axis.
\par So, for an elliptic curve $\E$ written in the form 
$y^2 = \hbox{cubic in }x$, the points are $\o$ (the point
at infinity) and the affine points $(x,y)$, and
the group law has a simpler description:
\par Let $\d = (x_3,y_3)$ the 3rd point of intersection of~$\E$
and~$\ell_{\a,\b}$.
\par Then $\a + \b = (x_3,-y_3)$, the reflection of~$\d$ in
the $x$-axis.
\end{comm}
\begin{comm} Note that any $y^2 = \hbox{ cubic in }x$, over~$\Q$, can
be birationally transformed to a curve of the
form $y^2 = x^3 + Ax + B$, where~$A,B\in \bbbz$,
using only linear changes in~$x,y$.
For example, starting with $y^2 = 5x^3 + 6x^2 + 4x + 2$,
the birational transformation $(x,y)\mapsto (5x,5y)$ [with inverse
$(x,y) \mapsto (\frac{x}{5},\frac{y}{5})$] takes this curve
to $\bigl( \frac{y}{5} \bigr)^2 = 5 \bigl( \frac{x}{5} \bigr)^3
+ 6 \bigl( \frac{x}{5} \bigr)^2 + 4 \bigl( \frac{x}{5} \bigr) + 2$,
that is: $y^2 = x^3 + 6 x^2 + 20 x + 50$.
Then the birational transformation $(x,y) \mapsto (x + 6/3, y) = (x+2,y)$
[with inverse $(x,y) \mapsto (x-2,y)$] takes this curve
to: $y^2 = (x-2)^3 + 6(x-2)^2 + 20(x-2) + 50 = x^3 + 8 x + 26$. 
\end{comm}
We illustrate the group law with the following computation.
\begin{ex}\label{ex:gplaw0}
Let $\E : y^2 = x^3 + 1$. Let us compute $\a + \b$, where 
$\a = (x_1,y_1) = (-1,0)$
and $\b = (x_2,y_2) = (0,1)$.
\par 
The line through $\a,\b$ is $\ell_{\a,\b} : y = x + 1$.
Substituting this into~$\E$, we see that the $x$-coordinate
of any point of intersection satisfies: $(x + 1)^2 = x^3 + 1$,
and so:
$$ x^3 - x^2 - 2x = 0. \ \ \ \ \ \ \ \ (*) $$
We are looking for~$(x_3,y_3)$, the 3rd point of intersection
of~$\E$ and $\ell_{\a,\b}$. We first find~$x_3$; note that
$x_1,x_2,x_3$ must be the roots of~$(*)$.
\par\noindent {\bf Method A} (for finding~$x_3$). 
Since the roots of~$(*)$ are $x_1,x_2,x_3$, it follows
that $x^3 - x^2 - 2x = (x - x_1)(x - x_2)(x - x_3)$;
equating coefficients of~$x^2$ gives that:
$$ x_1 + x_2 + x_3 = -(\hbox{coefficient of $x^2$ in $(*)$}) 
= - (-1) = 1,$$
so that~$(-1) + 0 + x_3 = 1$, giving $x_3 = 2$.
\par\noindent {\bf Method B} (for finding~$x_3$).
Factorise~$(*)$ to give: $x(x+1)(x-2)$, whose roots are: $0,-1,2$.
Two of these are the already known $x_1 = -1, x_2 = 0$,
and so~$x_3$ must be the remaining root: $x_3 = 2$.
\par Having found~$x_3$ (by either method), we use the equation
of $\ell_{\a,\b}$ to compute $y_3 = x_3 + 1 = 3$.
In summary: $\E$ and $\ell_{\a,\b}$ intersect at: $(-1,0),(0,1),(2,3)$,
and so $(-1,0) + (0,1) + (2,3) = \o$.
\par Finally, this gives: $(-1,0) + (0,1) = -(2,3) = (2,-3)$,
using the rule that negation is given by reflection in the $x$-axis.
\end{ex}
One can also obtain an explicit general formula for the group law.
\begin{lem}\label{lem:expl0}
Let $\E : y^2 = x^3 + A x + B$, where~$A,B\in K$, with
(as usual) $\o = $ the point at infinity. Let~$(x_3,y_3) = (x_1,y_1)
+ (x_2,y_2)$.
\par\noindent {\bf Case 1.} When $x_1\not= x_2$ then:
$$ x_3 = \frac{x_1 x_2^2 + x_1^2 x_2 + A(x_1 + x_2) + 2B - 2 y_1 y_2}
{(x_1 - x_2)^2},\ \ \ y_3 = -\ell x_3 - m, $$
$$ \hbox{where: }\ell = \frac{y_1-y_2}{x_1-x_2},\ \ 
m = \frac{x_1 y_2 - x_2 y_1}{x_1 - x_2}.
$$
\noindent{\bf Case 2.} When $(x_1,y_1) = (x_2,y_2)$ then  
$(x_3,y_3) = (x_1,y_1) + (x_1,y_1)$ 
\hbox{\rm [}which can be written as~$2(x_1,y_1)$\hbox{\rm ]}, and:
$$ x_3 = \frac{x_1^4 - 2 A x_1^2 - 8 B x_1 + A^2}{4 y_1^2}
= \frac{x_1^4 - 2 A x_1^2 - 8 B x_1 + A^2}{4(x_1^3 + A x_1 + B)},
\ \ \ y_3 = -\ell x_3 - m, $$
$$ \hbox{where: }\ell = \frac{3x_1^2+A}{2y_1},\ \ 
m = \frac{-x_1^3 + A x_1 + 2B}{2y_1}.
$$
\end{lem}
\eject
\begin{prf}:
\par\noindent {\bf Case 1.} When~$x_1 \not= x_2$, the line
through $(x_1,y_1),(x_2,y_2)$ is $y = \ell x + m$,
where~$\ell = \frac{y_1-y_2}{x_1-x_2},\
m = \frac{x_1 y_2 - x_2 y_1}{x_1 - x_2}$. Replacing~$y$ by~$\ell x + m$
in $y^2 = x^3 + Ax + B$, we see that~$x_1,x_2,x_3$ satisfy
$(\ell x + m)^2 = x^3 + A x + B$, and so:
$$ x^3 - \ell^2 x^2 + \hbox{terms of lower degree} = 0.$$
Hence $x_1 + x_2 + x_3 = -(\hbox{coefficient of~$x^2$}) = \ell^2$,
and so $x_3 = \ell^2 - x_1 - x_2 = 
\bigl( \frac{y_1 - y_2}{x_1 - x_2} \bigr)^2 - x_1 - x_2$.
On expanding this expression and using the fact that
each $y_i^2 = x_i^3 + A x_i + B$, for $i =1,2$ [since $(x_1,y_1),(x_2,y_2)$
lie on~$\E$], we obtain the given formula for~$x_3$.
The~$3$ points of intersection of~$\E$ and~$y = \ell x + m$
are then 
$(x_1,y_1),(x_2,y_2),(x_3,\ell x_3 + y_3),$
so that
$$(x_1,y_1) + (x_2,y_2) + (x_3,\ell x_3 + y_3) = \o,$$
giving $(x_1,y_1) + (x_2,y_2) = -(x_3,\ell x_3 + y_3)
= (x_3,-\ell x_3 - y_3)$, as required.
\par\noindent {\bf Case 2.} When $(x_1,y_1) = (x_2,y_2)$, we should
first compute the tangent to~$\E$ at~$(x_1,y_1)$. Using $2yy' = 3x^2+A$,
we see that the slope of the tangent at~$(x_1,y_1)$
is $\ell = \frac{3x_1^2 + A}{2y}$. The equation of the tangent
is then $y = \ell x + m$, where
$m = y_1 - \ell x_1 = \frac{-x_1^3 + A x_1 + 2B}{2y_1}$.
As in case~1, $x_3 = \ell^2 - x_1 - x_2$, which simplifies
to the given formula, and $y_3 = -\ell x_3 - m$.
\end{prf}
\par The only case not considered above is when~$(x_1,y_1) = (x_2,-y_2)$,
but it this case the points are inverses and so
$(x_1,y_1) + (x_2,y_2) = \o$. The above formulas give an alternative
method for computing the group law, although in practice it
often turns out to be easier to compute the group law
from first principles, as in Example~\ref{ex:gplaw0}.
\par This lecture course will concentrate on the number theoretic
properties of elliptic curves, in particular results about
$\EQ$, when~$\E$ is an elliptic curve defined over~$\Q$.
The number theoretic properties of elliptic curves is a substantial
area of research. Recently, elliptic curves were use in the proof
of Fermat's conjecture, that there are no solutions in positive
integers to the equation $a^n + b^n = c^n$, for any $n\geqslant 3$.
It is sufficient to prove the result for~$n = p$ prime. If there
were a solution, then the elliptic curve~$y^2 = x(x-a^p)(x+b^p)$
[often called the `Frey curve'] cannot be modular, and so
would disobey the Taniyama-Shimura conjecture [that all elliptic    
curves are modular], a conjecture that has recently been proved
(alas, the proof is far beyond the scope of any first lecture course
on elliptic curves).
\par The main goal of the lecture course will be to gain some
understanding of the properties of the Mordell-Weil group~$\EQ$.
We shall begin by giving basic definitions and properties that
apply to an elliptic curve over any field~$K$ [some of the first week
will overlap with the above introduction to elliptic curves].
We shall then explore elliptic curves over finite fields,
and over the field of $p$-adic numbers~$\bbbq_p$. This will
include the development of the {\it formal group} of an elliptic
curve, which describes how to expand the group law as a power series
in a neighbourhood of the identity. We shall see that this
exploration over~$\bbbq_p$ gives us results that help us to
understand~$\EQ$. We shall then discuss the subgroup of~$\EQ$
consisting of points of finite order (the {\it torsion subgroup}).
For elliptic curves with a rational point of order~$2$, there
is a map (a {\it $2$-isogeny}) to an associated elliptic curve,
which is a homomorphism and has kernel of order~$2$. We shall
describe properties of this isogeny and use it to prove that
such curves satisfy the {\it Weak Mordell-Weil Theorem},
that $\EQ/2\EQ$ is always finite. We shall then describe the
theory of heights on elliptic curves [essentially, a measure
of the `size' of a point on an elliptic curve], and use this to prove
the climactic result of the lecture course:
the {\it Mordell-Weil Theorem}, that $\EQ$ is always finitely
generated. As an added extra at the end will be a short
section on the relevance of elliptic curves to cryptography. 
\par The sections will be as follows.
\par\noindent {\bf Section 1. The Group Law on an Elliptic Curve.}
\par The group law, associativity, examples, torsion, the number of
points on an elliptic curve over a finite field. 
\par\noindent {\bf Section 2. The $p$-adic Numbers $\bbbq_p$.}
\par The $p$-adic valuation on~$\bbbq$, the definition of
$\bbbq_p$ as the completion of~$\bbbq$ with respect to
this valuation, basic properties of~$\bbbq_p$,
Hensel's Lemma for determining when an approximate solution
to a univariate polynomial equation lifts to a actual solution.
\par\noindent {\bf Section 3. The Reduction
Map on an Elliptic Curve.}
\par The reduction map on an elliptic curve,
the use of Hensel's Lemma to decide when a given point over~$\bbbf_p$
has a preimage (a `lift') under the reduction map.
\par\noindent {\bf Section 4. Formal Groups.}
\par General 1-parameter formal groups and their properties,
the invariant differential and formal logarithm,
the formal group of an elliptic curve.
\par\noindent {\bf Section 5. Global Torsion.}
\par Injectivity of the reduction map on torsion, the
Nagell-Lutz Theorem [which gives an effective procedure for
computing the torsion group of~$\EQ$].
\par\noindent {\bf Section 6. A $2$-isogeny on an Elliptic Curve.}
\par Elliptic curves with a point of order~$2$, a $2$-isogeny from
such an elliptic curve to an associated elliptic curve
and its properties.
The Weak Mordell-Weil Theorem that $\EQ/2\EQ$ is finite,
for the case when an elliptic
curve has a point of order~$2$.
\par\noindent {\bf Section 7. The Mordell-Weil Theorem.}
\par Height functions on Abelian groups,
height functions on elliptic
curves, the Mordell-Weil Theorem, that~$\EQ$ is finitely generated.
\par\noindent {\bf Section 8. Cryptography.}
Public keys, cryptography, Pollard's $p-1$ method
and the elliptic curve method for factorising large integers.
\bigskip
\bigskip
\hrule
\par\medskip
The following are the two main references for the lecture course.
\par\medskip\noindent
J.W.S.\ Cassels.  {\em Lectures on Elliptic Curves.}
LMS--ST~{\bf 24}. Cambridge University Press, Cambridge, 1991.
\par\medskip\noindent
J.H.\ Silverman. {\em The Arithmetic of Elliptic Curves}.
\newblock GTM {\bf 106}. Springer-Verlag, 1986.
\par\medskip
During the lecture course, I shall refer to these simply
as `Cassels' and `Silverman', respectively.
\bigskip
\bigskip
\hrule
\par\medskip
\bigskip
The following gives some possible pre-course reading options if you find
that you have gaps in your knowledge of any of the pre-requisite
material described in Section~0.
\par\medskip\noindent
W.\ Keith Nicholson. {\it Introduction to Abstract Algebra.}
(Second Edition, John Wiley, 1999).
\par\medskip\noindent
Peter J.\ Cameron. {\it Introduction to Algebra.}
OUP 1998.
\par\medskip\noindent
Alan Baker. {\it A Concise Introduction to the Theory of Numbers.} CUP,
1985.
\par\medskip\noindent
I.M.\ Niven, H.S.\ Zuckerman and H.L.\ Montgomery.
{\it An Introduction to the Theory of Numbers.} Wiley, 1991.
\par\medskip\noindent
W.A. Sutherland. {\it Introduction to Metric and Topological Spaces.}
OUP, 1975.
\par\medskip\noindent
Miles Reid. {\it Undergraduate Algebraic Geometry.} CUP, 1988.
\par\medskip\noindent
\bigskip
\hrule
\vfil\eject
%\chaptitle
%\noindent
%\centerline{\bf Elliptic Curves. Sheet 0.}
%%\rm
%\par \bigskip
%{\it This sheet is not intended to be handed in. It is merely
%for you to use (as you please) to reinforce the preliminary
%reading in Section~0 ``Background Material in Algebra,
%Number Theory and Geometry''.}
%\par
%\bigskip
%\bigskip
%\noindent {\bf 1.} Determine whether the following are groups.
%\par\noindent {\bf (a).} The set of all $2\times 2$ matrices
%under matrix multiplication. 
%\par\smallskip
%\noindent {\bf (b).} The set of all $2\times 2$ matrices
%under matrix addition. 
%\par
%\medskip
%\noindent {\bf 2.} For each of the following, decide whether
%$\phi$ is a homomorphism. When $\phi$ is a homomorphism,
%decide whether~$\phi$ is injective, surjective, bijective, and
%find the kernel of~$\phi$.
%\par\noindent {\bf (a).} $\phi : \bbbz , + \rightarrow \bbbq^* , \times
%: x \mapsto x^2+1$.
%\par\smallskip
%\noindent {\bf (b).} $\phi : \bbbq , + \rightarrow \bbbr , +
%: w \mapsto \sqrt{2}\, w$.
%\par\smallskip
%\noindent {\bf (c).} $\phi : \bbbz  , +  \rightarrow
%\bbbz / 3\bbbz , + : x \mapsto 2x$.
%\par
%\medskip
%\noindent {\bf 3.} 
%\par\noindent {\bf (a).} In $\qmsq$, decide whether
%the following are
%true or false: $3=1/27$, $-4=4$, $3=5/6$.
%\par\smallskip
%\noindent {\bf (b).} In $\qmsq$, write each of the following as
%a square free integer: $-2/27$, $16$, $12$, $1/3$.
%\par\smallskip
%\noindent {\bf (c).} Perform each of the following in $\qmsq$,
%writing your answer as a square free integer:
%$6\times 10$, $10 / 21$, $15^{101}$, $3^{-1}$.
%\par\smallskip
%\noindent {\bf (d).} How many elements are in each of
%the groups: $\qmsq$,
%${\bbbr}^*/({\bbbr}^*)^2$,
%${\bbbc}^*/({\bbbc}^*)^2$?
%\par\medskip
%\noindent {\bf 4.}
%\par\noindent {\bf (a).} Find all singular points on the curve
%$$ \C : f(X,Y) = X^4 + Y^3 - 3 X^2 Y = 0. $$
%\noindent Find all tangents to $\C$ at the point $(0,0)$.
%\par\smallskip
%\noindent {\bf (b).} Find all singular points on the curve
%$$ \C : f(X,Y) = Y^2 - X(X^2-1)^2 = 0.$$
%\noindent Find all tangents to $\C$ at the points $(0,0)$ and $(1,0)$.
%\par
%\medskip \noindent {\bf 5.} Show that $\C : Y^2 = X^3 + AX + B$ is smooth
%if $4A^3 + 27B^2 \not= 0$.
%\par
%\medskip\noindent {\bf 6.} For each of the following curves,
%find the irreducible components over~$\bbbq$ and the irreducible
%components over~$\bbbc$.
%\par\noindent {\bf (a).} $\C : Y^2 = X^5$.
%\par\smallskip
%\noindent {\bf (b).} $\C : Y^3 = X^3$.
%\par\smallskip
%\noindent {\bf (c).} $\C : Y^2 = X^3 + 1$.
%\par\medskip\noindent{\bf 7.}
%\par\noindent {\bf (a).} Find a birational transformation over~$\bbbq$
%between the curves $2X^2 - Y^2 = 1$ and $X^2 + Y^2 - 6XY = 1$.
%\par\smallskip
%\noindent {\bf (b).} Find a birational transformation over~$\bbbq$
%between the curves $Y^2=(X+2)^6(X^3+1)$ and $Y^2 = X^3 + 1$.
%\par\smallskip
%\noindent {\bf (c).} Find a birational transformation over~$\bbbc$
%between the curves~$Y^2=2X^2$ and~$Y^2=X^2$. Is there a birational
%transformation over~$\bbbq$?
%\par\medskip
%\noindent {\bf 8.}
%\par\noindent {\bf (a).} Find the discriminant of~$X^4-2$.
%\par\smallskip
%\noindent {\bf (b).} Find the resultant of $X^3 - a$ and $X^2 - b$,
%where $a,b$ are constants.
%\par\medskip\noindent {\bf 9.} Find all intersection points
%(with multiplicities) over~$\bbbc$ of the curves:
%$X^3 + Y^3 = Z^3$ and $X^2 + Y^2 = Z^2$.
%\par
%\medskip
%\noindent {\bf 10.}
%\par\noindent {\bf (a).}
%Decide whether each of 
%$2,3,5,10,15$
%are quadratic residues modulo~1009 (if you use quadratic reciprocity,
%this should not involve any lengthy computations).
%\par\smallskip
%\noindent {\bf (b).} Describe all primes~$p$ such that $3$
%is a quadratic residue modulo~$p$.   
%Describe all primes~$p$ such that $5$
%is a quadratic residue modulo~$p$. 
%Describe all primes~$p$ such that $10$
%is a quadratic residue modulo~$p$. 
%\par\medskip
%\noindent {\bf 11.} Are there integers $a,b,c$, not all~$0$,
%such that $2a^2 + 5b^2 = c^2$?
%\par\medskip
%\noindent {\bf 12.} For any $n\in{\bbbn}$ define, as usual, Euler's
%$\phi$-function by: 
%$$ \phi(n) = \# \{ x :
%1 \leqslant x \leqslant n \hbox{ and gcd} (x,n) = 1 \}.
%$$
%For any prime~$p$, what is $\phi(p^r)$?
%For any distinct primes $p_1,p_2$, what is $\phi(p_1 p_2)$?
%\par
%For each of the following examples of
%the type $a^b \ (\hbox{mod }n)$, reduce $a^b \ (\hbox{mod }n)$ to a member
%of $\{ 0, \ldots , n-1 \}$.
%\par\noindent
%$2^{12} \ (\hbox{mod }13)$,
%$3^{12} \ (\hbox{mod }13)$,
%$3^{24} \ (\hbox{mod }13)$,
%$3^{12000} \ (\hbox{mod }13)$,
%$3^{12002} \ (\hbox{mod }13)$,
%\hfill\par\noindent
%$4^{24} \ (\hbox{mod }35)$,
%$4^{48} \ (\hbox{mod }35)$,
%%$4^{48000} \ (\hbox{mod }35)$,
%$4^{48000001} \ (\hbox{mod }35)$,
%\hfill\par\noindent
%$7^{24} \ (\hbox{mod }35)$,
%$7^{48} \ (\hbox{mod }35)$,
%%$7^{48000} \ (\hbox{mod }35)$,
%$7^{48000001} \ (\hbox{mod }35)$.
%\vfil \eject %\end
%********************************************************************
\end{document}
