\documentclass{oxmathexam}
\usepackage{standardmacros}





\school{Honour School of Mathematics Part C:  Paper C3.7\\
	Master of Science in Mathematical Sciences: Paper C3.7}
%Please put the name of the examination in the brackets above, e.g. Honour Moderations, Final Honour School of Mathematics Part B, etc.
\title{Elliptic Curves\\
	James Newton\\
	Draft solutions}
%Please put your course title, your name and the name of your checker in the brackets above.
\date{12/6/2025}
%Please be sure to mark each draft submitted with the correct date.

\begin{document}

\makecoverpage

\input{C3.7_qns_2025_V3}

\begin{itemize}
	\newpage
	\item[Solution 1.]
(a)(i) [5 marks, S] We have to complete the square on the left hand side, so we write \[(Y-1/2)^2 = X^3-X^2 + 1/4.\]

Completing the cube on the right hand side, gives us
\[(Y-1/2)^2 = (X-1/3)^3 - (X-1/3)/3 + 1/4 - 1/9 + 1/27 = (X-1/3)^3 - (X-1/3)/3 + 19/(2^23^3).\]

Rescaling to get an integral equation we get:
\[(2^{-6}3^{-6})(2^33^3Y-2^23^3)^2 = (2^{-6}3^{-6})(2^23^2X-2^23)^3 - (2^{-2}3^{-2})(2^23^2X-2^23)/3 + 19/(2^23^3)\] or
\[(2^33^3Y-2^23^3)^2 = (2^23^2X-2^23)^3- (2^43^3)(2^23^2X-2^23) + 2^43^319.\]

So the birational transformation $X' = 2^23^2X-2^23, Y' = 2^33^3Y-2^23^3$
maps to the curve with equation $(Y')^2 = (X')^3 - 2^43^3 X' + 2^43^319$.

(a)(ii) [5 marks, S] We see from the short Weierstrass equation that $3$ is a prime of bad reduction, so we consider the reduction mod $5$. The equation is $Y^2 = X^3 - 2X -2$. Checking the discriminant, we see that $5$ is a prime of good reduction, and computing the $\mathbb{F}_5$-points on the curve gives $5$ points in total. We deduce that the group $E(\mathbb{Q})_{\mathrm{tors}}$ has order dividing 5. We do have rational points different from the identity, e.g.~$(0,0)$ in the initial coordinates. Since the rank is $0$, this point must be a torsion point, which shows that $E(\mathbb{Q})_{\mathrm{tors}}$ is cyclic of order 5, with $(0,0)$ a generator.

(b)(i)[5 marks, B] We first consider the tangent $t_P$ to $E_\alpha$ at the point $P$. This intersects $E_\alpha$ with multiplicity three, by B\'{e}zout's theorem. Since $t_P$ is a tangent at $P$, the intersection at $P$ has multiplicity $\ge 2$. If the third point of intersection (which could be $P$ itself, if $P$ is an inflexion) is $(x,y)$, then $2P$ is defined to be $(x,-y)$. [The general definition, without assuming that the identity is an inflexion, is also acceptable.]

For the rationality, the tangent $t_P$ has a rational equation, and so it suffices to show that its intersections with $E_\alpha$ have rational $X$-coordinate. The $X$-coordinates of the intersection points are roots of the cubic with rational coefficients obtained by substituting the equation for the tangent line into the equation for the curve. Since at least two of these roots have rational $X$-coordinate, the third will. 

\newpage
(b)(ii)[10 marks, S/N - they have seen plenty of examples of doubling a point] Suppose $P \in E_\alpha(\mathbb{Q})$ has order 4. Then $2P$ has order 2. Therefore we must have $2P = (0,0)$, and $P$ has non-zero $X$- and $Y$-coordinate otherwise it would have order 2. 

[\textit{3 marks for noticing that we need to solve $2P=(0,0)$}]

Suppose $P= (x,y)$. The tangent at $P$ has equation \[Y-y = \frac{3x^2+\alpha}{2y}(X-x).\] If $2P = (0,0)$, this tangent passes through $(0,0)$, so we have $(3x^2 + \alpha)(-x)+2y^2 = 0$. Substituting in the equation of the curve gives $(3x^2 + \alpha)(-x)+2(x^3+\alpha x) = -x^3 + \alpha x = 0$. Since the $X$-coordinate of $Y$ is non-zero, we deduce that $x = \pm\sqrt{\alpha}$. This gives a rational point only if $\alpha$ is a perfect square. 

[\textit{4 more marks for deducing that $\alpha$ must be a square}]

If we consider the $Y$-coordinate, we find that $Y^2 = \pm2\alpha\sqrt{\alpha}$. 

So we need both $\alpha$ and $2\alpha\sqrt{\alpha}$ to be a perfect square. Thinking about the prime factorization of $\alpha$, we see that $\alpha = n^2$ for a positive integer $n$ which itself is of the form $n = 2 m^2$. We deduce that a necessary and sufficient condition is for $\alpha = 4m^4$ for a positive integer $m$. 

[\textit{Final 3 marks for finishing off problem.}]

\newpage
\item[Solution 2.] (a)(i) [5 marks, B] An invariant differential $\omega(T) = P(T) dT$ satisfies $\omega(F(T,S)) = \omega(T)$, or more explicitly: 
\[P(F(T,S))\frac{\partial F}{\partial{X}}(T,S) = P(T).\] It is normalized if the constant term of $P(T)$ is $1$. Suppose $\omega(T)$ is a normalized invariant differential. Note that, setting $T=0$, we have $P(S) = P(0)\left(\frac{\partial F}{\partial{X}}(0,S)\right)^{-1}$. Note that $\frac{\partial F}{\partial{X}}(0,S) = 1 + S(\cdots)$, so this power series is invertible. Since $\omega(T)$ is normalized, $P(0) = 1$, and we necessarily have $P(T) = \left(\frac{\partial F}{\partial{X}}(0,T)\right)^{-1}$, hence the uniqueness.

%Now it suffices to show that $\left(\frac{\partial F}{\partial{X}}(0,T)\right)^{-1} dT$ is indeed an invariant differential. We must show that \[\left(\frac{\partial F}{\partial{X}}(0,F(T,S))\right)^{-1} \frac{\partial F}{\partial{X}}(T,S) = \left(\frac{\partial F}{\partial{X}}(0,T)\right)^{-1},\] or equivalently \[\frac{\partial F}{\partial{X}}(0,T)\frac{\partial F}{\partial{X}}(T,S) = \frac{\partial F}{\partial{X}}(0,F(T,S)).\] To prove this identity of formal power series, we take the associativity law,
%\[ F(F(X,Y),Z) = F(X, F(Y,Z)),\] differentiate with respect to $X$ to get
%\[\frac{\partial F}{\partial{X}}(F(X,Y),Z)\frac{\partial F}{\partial{X}}(X,Y) = \frac{\partial F}{\partial{X}}(X,F(Y,Z))\] and then set $X=0, Y=T, Z=S$. We use the fact that $F(0,Y) = Y$. 

(a)(ii) [5 marks, B] If $\omega(T)$ is the normalized differential $\left(\frac{\partial F}{\partial{X}}(0,T)\right)^{-1} dT$, we define $\log_F = \int \omega(T)$. In other words we integrate the power series $\left(\frac{\partial F}{\partial{X}}(0,T)\right)^{-1}$ term by term. To show that it defines an isomorphism to $\widehat{\mathbb{G}}_a$, first we note that it suffices to show that it defines a homomorphism, since  $\log_F(T) = T + $higher order terms, so the linear coefficient is invertible. Now we need to check that $\log_F(F(X,Y)) = \log_F(X)+\log_F(Y)$. We know that the derivative $\frac{\partial}{\partial X}(\log_F(F(X,Y)) - \log_F(X))$ is $0$, by the invariance of $\omega$. We deduce that $\log_F(F(X,Y)) - \log_F(X) = G(Y)$ for a power series $Y \in K\lb Y\rb$. Setting $X=0$, we deduce that $G(Y) = \log_F(Y)$, and we have shown that $\log_F$ is indeed a homomorphism. 

(b)(i) [12 marks, N but similar to proofs in the formal power series section of the lecture notes, where power series are defined term by term] We follow the hint. We necessarily have $g_{a,1}(X) = aX$. Suppose we have shown that there is a unique $g_{a,r}$. Then we have $h(g_{a,r}(X)) = g_{a,r}(h(X)) + \delta_{r+1}(X) + $terms of degree $\ge r+2$, where $\delta_{r+1}(X)$ is a degree $r+1$ monomial. We are looking for $g_{a,r+1}(X) = g_{a,r}(X) + \alpha_{r+1}X^{r+1}$ for some $\alpha_{r+1}$ in $R$. Now we have $h(g_{a,r+1}(X)) = h(g_{a,r}(X)) + p\alpha_{r+1}X^{r+1}+ $terms of degree $\ge r+2$. On the other hand, we have $g_{a,r+1}(h(X)) = g_{a,r}(h(X)) + \alpha_{r+1}p^{r+1}X^{r+1} + $terms of degree $\ge r+2$.

We deduce that we must have $0 = \delta_{r+1}(X) +p\alpha_{r+1}X^{r+1}-\alpha_{r+1}p^{r+1}X^{r+1}$, and therefore $\alpha_{r+1}X^{r+1}= \frac{\delta_{r+1}(X)}{p^{r+1}-p}$. This gives the unique polynomial $g_{a,r+1} = g_{a,r} + \frac{\delta_{r+1}(X)}{p^{r+1}-p} \in K[X]$. 

[\textit{9 marks for getting this far}]

For this to be an element of $R[X]$, we need $p$ to divide $\delta_{r+1}(X)$ (note that $p^r - 1$ is invertible in $R$). If we consider the equation $h(g_{a,r}(X)) = g_{a,r}(h(X)) + \delta_{r+1}(X) + $terms of degree $\ge r+2$ modulo $p$, we get $g_{a,r}(X)^q = g_{a,r}(X^q) + \delta_{r+1}(X)$ mod $p$. Since the residue field of $R$ has size $q$, we have $z^q = z$ mod $p$ for all $z \in R$. We deduce that $g_{a,r}(X)^q = g_{a,r}(X^q)$ mod $p$, and therefore $\delta_{r+1}(X) = 0$ mod $p$. [\textit{remaining 3 marks for checking the divisibility by $p$}]

(b)(ii) [3 marks, N but easy given the previous part] Since $h(X)$ is a homomorphism, we have $h([p](X)) = [p](h(X))$. It follows that $[p](X) = g_p(X)$, the power series from part (i). But $h(x)$ itself also satisfies the property uniquely characterising $g_p(X)$. We deduce that $[p](X) = h(X)$. 

%(b)(iii) 
\newpage
\item[Solution 3.]
(a) [10 marks, B] The definition of the map is that $q(u,v) = u$ if $u \neq 0$, $q(0,0) = a^2 - 4b$, and $q(O) = 1$. 
[\textit{1 mark for definition.}]

A point $(u,v)$ with $u \neq 0$ maps to the identity coset if and only if $u$ is a square. If  $(u,v) = \phi(x,y)$ then $u = (y/x)^2$ is a square. Conversely, if $u$ is a square then we look for a preimage $(x,y)$ with $y = \sqrt{u}x$. We have $v= \sqrt{u}x(1-b/x^2)$, so $x-b/x = v/\sqrt{u}$.  We also have $y^2 = ux^2 = x(x^2+ax+b)$, so $u = x+a+b/x$. We deduce that $2x+a = u + v/\sqrt{u}$, so $x = 1/2(u -a + v/\sqrt{u})$. That gives a preimage $(1/2(u -a + v/\sqrt{u}),\sqrt{u}/2(u -a + v/\sqrt{u}) )$ of $(u,v)$. 
[\textit{7 marks for this part.}]

It remains to consider when $q(0,0)$ is equal to the identity coset. This happens if and only if $a^2-4b$ is a rational square, which happens if and only if all the $2$-torsion points of $C$ are rational. This is equivalent to the two preimages of $(0,0)$ being rational points, since these preimages are precisely the order two points other that $(0,0)$. 

[\textit{Final 2 marks for handling the case of $q(0,0)$.}]

(b)(i) [5 marks, S] We consider the reduction mod $5$, which gives equation $Y^2 = X(X^2 +3)$. This curve has 10 points over $\mathbb{F}_5$. Reducing mod $7$ gives a curve with $10$ points over $\mathbb{F}_7$ as well. Persevering, the reduction mod $11$ has $16$ points. Since $C(\mathbb{Q})_{\mathrm{tors}}$ is isomorphic to a subgroup of both $\widetilde{C}(\mathbb{F}_5)$ and $\widetilde{C}(\mathbb{F}_{11})$, it has size at most two. On the other hand, $(0,0)$ gives a point of order two. So $C(\mathbb{Q})_{\mathrm{tors}}$ is cyclic of order two, generated by $(0,0)$. One can also attempt to use Nagell--Lutz, but there are some infinite order points which satisfy the `Nagell--Lutz criterion'. 

(b)(ii) [10 marks, S although they have seen more rank 0 examples than positive rank.] We follow the usual $2$-descent procedure. The group $D(\mathbb{Q})/\phi(C(\mathbb{Q}))$ has image under $q$ given by certain squarefree integers $r$ dividing $a^2-4b = 13$. So $r \in \{\pm1,\pm13\}$. The integer $r$ is contained in the image if the equation \[W_r: rl^4  -2a l^2m^2 + \frac{(a^2-4b)}{r}m^4 = n^2\] has non-zero solution $(l,m,n)$ with $\gcd(l,m) = 1$. Considering signs, we have $r \in {1,13}$ and $q(0,0) = 13$, so $D(\mathbb{Q})/\phi(C(\mathbb{Q}))$ is generated by $(0,0)$, which is sent to $O$ by $\hat{\phi}$. 

[\textit{3 marks for this part}]

Now we consider $C(\mathbb{Q})/\hat{\phi}(D(\mathbb{Q}))$. The group $D(\mathbb{Q})/\phi(C(\mathbb{Q}))$ has image under $\hat{q}$ given by certain squarefree integers $r$ dividing $3$. So $r \in \{\pm1,\pm3\}$. We have $\hat{q}(0,0) = 3$. We consider the equation \[\widehat{W}_{-1}: -l^4 + 5 l^2 m^2 - 3 m^4 = n^2.\] It has a solution $(l,m,n) = (1,1,1)$. We have $\hat{q}(-1,1) = -1$.

[\textit{5 more marks for this part}]

We deduce that $C(\Q)/2C(\Q)$ has order $4$ and is generated by $(0,0)$ and $(-1,1)$. Since $C(\Q)[2] = \langle (0,0) \rangle$, we deduce that $C(\Q)$ has rank one and $(-1,1)$ is a point of infinite order. 

[\textit{2 marks for final deduction}]

\end{itemize}
\end{document}




