A cubic curve whose points form a group
An elliptic curve is a non-singular cubic with a distinguished point at infinity. Its points form an abelian group under the chord-and-tangent construction, with the point at infinity as identity. Over a finite field the group is finite with order constrained by Hasse's bound to within 2√q of q + 1 — and that near-freedom in the group order is precisely what the elliptic curve factoring and primality methods exploit.
Learning objectives
- Write a curve in Weierstrass form and compute its discriminant and j-invariant.
- Apply the group law formulas including the special cases.
- State Hasse's theorem and its significance.
- Explain why varying the curve varies the group order.
- Choose coordinates that avoid modular inversions.
Section 01Weierstrass form
The general Weierstrass equation is
Away from characteristic 2 and 3 this simplifies by completing the square and the cube to the short form y2 = x3 + ax + b, with
The curve is non-singular exactly when Δ ≠ 0. The j-invariant classifies curves up to isomorphism over an algebraically closed field; over a smaller field, curves with the same j may still be non-isomorphic twists.
The reduction to short Weierstrass form divides by 2 and 3. In characteristic 2 or 3 the general five-coefficient equation must be retained, and the group law formulas differ. Code that assumes the short form will silently fail on these fields.
Section 02The group law
Three collinear points on the curve sum to the identity. Turning that into formulas:
- If P = O, return Q; if Q = O, return P.
- If x1 = x2 and y1 = −y2, return O. The points are inverse to one another.
- If P ≠ Q, set λ ← (y2 − y1) / (x2 − x1).
- If P = Q, set λ ← (3x12 + a) / (2y1) — the tangent slope.
- Set x3 ← λ2 − x1 − x2 and y3 ← λ(x1 − x3) − y1.
- Return (x3, y3).
Projective and Jacobian coordinates represent a point with an extra coordinate so that addition uses no inversion, deferring a single inversion to the end of a long computation. For scalar multiplication with hundreds of doublings this is a large saving — but note that it also suppresses the inversion failures that ECM depends on, so factoring implementations must handle this deliberately.
Section 03Groups over finite fields
Over Fq the group of points is finite, and Hasse's theorem bounds its order:
The structure is cyclic or a product of two cyclic groups, the second factor's order dividing the first and dividing q − 1.
For a fixed field, different curves give different group orders spread across the Hasse interval. The p−1 method works only when p−1 happens to be smooth; ECM replaces that fixed group with a curve group that can be resampled until a smooth order appears. That resampling is the entire advantage of ECM over p−1.
Section 04Points over ℚ and torsion
The Mordell–Weil theorem states that E(ℚ) is finitely generated:
The torsion subgroup is easy to compute — by Mazur's theorem it is one of fifteen possibilities, all small — and the Nagell–Lutz criterion bounds candidate torsion points by requiring integral coordinates with y2 dividing the discriminant. The rank r is by contrast genuinely difficult, and no algorithm is known that provably computes it in all cases.
The asymmetry is stark: torsion is decided by a short finite search, while rank computation relies on descent, may fail to terminate conclusively, and is entangled with the unproven finiteness of the Tate–Shafarevich group.
ReferenceFrequently asked questions
Why is the point at infinity needed?
Because the group law requires an identity, and two points with the same x-coordinate have no third intersection in the affine plane. The projective point at infinity supplies both, making the group law total.
Is the group law associative, and is that obvious?
It is associative, but it is not obvious — a direct verification from the formulas is lengthy. The conceptual proof identifies the group with the divisor class group of degree zero, where associativity is inherited from addition of divisors.
How is the group order computed in practice?
By Schoof's algorithm and its SEA refinement, which determine the order modulo many small primes using the action of Frobenius on torsion points, then combine by the Chinese remainder theorem within the Hasse interval.
NavigateContinue in this stream
Curated next steps from this page. The site also surfaces algorithmically related reading below.
ProvenanceSources and further reading
This page is an original KEVOS explanatory article. It presents the underlying mathematics — definitions, algorithms, complexity results and selection criteria — in KEVOS editorial voice. No text is reproduced from any copyrighted source. Where numerical tables are relevant, KEVOS links to live authoritative databases rather than republishing static values.
