Dear Michael, I can't really give my model solutions to one student when I haven't given them to the whole class, but here are some hints. For further details, you could email one of the students who was at the class. My suggestion is: use the below hints to try to finish off the questions, email other students (who were at the class) if you are then still stuck on any remaining points. If, after that, there are still any remaining small points on which you are stuck, then feel free to email me about those specific points. Best wishes, Victor Qn 1 (a). C : Y^2 = X(X^2 + 2X + 3), so D : Y^2 = X(X^2 - 4X - 8). with the usual isogenies phi and phihat. Step 1. First show { 1,-2 } subset im q subset { +- 1 , +- 2}. There is only one coset to check, represented by -1, say, and now show -1 is not in im q by a 3-adic argument, so that: im q = { 1,-2 } and D(Q) / phi (C(Q)) is generated by (0,0). Step 2. First show: { 1,3 } subset im qhat subset { +- 1 , +- 3 }. There is only one coset to check, represented by -1, say, and now show -1 is not in im q by a real (inequality) argument, so that: im q = { 1,-2 } and C(Q) / phihat (D(Q)) is generated by (0,0). Step 3. C(Q) / 2C(Q) is generated by: generators for C(Q) / phihat (D(Q)) and phihat of generators for D(Q) / phi (C(Q)), and so C(Q) / 2C(Q) is generated by (0,0) and is isomorphic to C_2. We also know that C(Q) / 2C(Q) is isomorphic to C(Q)[2] x C_2^r, where r is the rank. Now show that C(Q)[2] is isomorphic to C_2 and deduce that the rank r = 0. (b) C : Y^2 = X(X^2 + 14X + 1) and so D : X(X^2 - 28X +192). Similarly to the last example, show: Step 1. Show D(Q) / phi (C(Q)) = { o, (0,0), (8,16), (24,-48) }, and is generated by (0,0) and (8,16). Step 2. Show C(Q) / phihat (D(Q)) = { o }. Step 3. Deduce that C(Q)/2C(Q) is generated by: generators for C(Q) / phihat (D(Q)) [namely: o] and phihat( (0,0) ) = o, and phihat( (8,16) ) = (1,-4). So, C(Q)/2C(Q) is generated by (1,-4) and is isomorphic to C_2. We also know that C(Q) / 2C(Q) is isomorphic to C(Q)[2] x C_2^r, where r is the rank. Now show that C(Q)[2] is isomorphic to C_2 and deduce that the rank r = 0. Qn 2. From (I) we obtain: h(P+Q) + h(P-Q) - 2 h(P) - 2 h(Q) <= C, and now use the fact that h(P-Q) >= 0 to show that height function property (1) is satisfied, with C_1(Q) = 2 h(Q) + C. Also, let Q = P in (I) to show that height function property (2) is satisfied. Also, note that (II) is the same as height function property (3). Replace P,Q in (I) with P,P and label this (*). Replace P,Q in (I) with 2P,P, respectively, and combine this with (*) (and make use of the triangle inequality) to get the final part of the qn. Qn 3. (a) Write 46 = 2 + 4 + 8 + 32 and use this to show: 2^46 - 1 is congruent to 5640 (mod N = 10481). Now, compute gcd(5640, N) by Euclid's Algorithm to find: 47, which is a factor of N, and use 10481/47 = 223, so that: N = 47 x 223. (b). We are given P = (5,11). Apply the Elliptic Curve group law to show that: Q = 2P = (159/121 , 1861/1331) on the given elliptic curve. We now wish to compute 3P = P + Q, for which the first step is to find the line joining P and Q. This has slope given by (1861/1331 - 11)/(159/121 - 5) = 6930/2453, and so we need to compute 6930/2453 (modulo N), for which the first step is to find the inverse of 2453 (modulo N). Using Euclid's Algorithm, we find that gcd(N,2453_ = 223, so we cannot find the inverse of 2453 (modulo N), and this step has given us a factor 223 of N. As before, compute 10481/223 = 47, giving the factorisation N = 47 x 223. (c). Show phi (N) = 10212. Use (and then reverse) EA to show that 5 is the inverse of 4085 modulo phi(N), so that the decoding operation is Y |--> Y^5 (mod N). Then decode the messages to get the original messages: 715 and 1805; that is: GORE.