← LibraryElliptic Curves: Definitions and the Group LawEngineering · MathematicsLesson 1/4← PrevNext →
GuidePublished 6 Aug 20265 min readBy Kevin JoginComputational Number TheoryElliptic CurvesElliptic CurveWeierstrass Equation
Skip to the main content

MathematicsElliptic Curves

Elliptic Curves: Definitions and the Group Law

Weierstrass equations, the chord-and-tangent group law, and the arithmetic that makes curves usable in factoring, primality proving and cryptography.

Executive summary

A cubic curve whose points form a group

An elliptic curve is a non-singular cubic with a distinguished point at infinity. Its points form an abelian group under the chord-and-tangent construction, with the point at infinity as identity. Over a finite field the group is finite with order constrained by Hasse's bound to within 2√q of q + 1 — and that near-freedom in the group order is precisely what the elliptic curve factoring and primality methods exploit.

Learning objectives

  • Write a curve in Weierstrass form and compute its discriminant and j-invariant.
  • Apply the group law formulas including the special cases.
  • State Hasse's theorem and its significance.
  • Explain why varying the curve varies the group order.
  • Choose coordinates that avoid modular inversions.

Section 01Weierstrass form

The general Weierstrass equation is

y2 + a1xy + a3y = x3 + a2x2 + a4x + a6

Away from characteristic 2 and 3 this simplifies by completing the square and the cube to the short form y2 = x3 + ax + b, with

Δ = −16(4a3 + 27b2),     j = −1728 (4a)3 / Δ

The curve is non-singular exactly when Δ ≠ 0. The j-invariant classifies curves up to isomorphism over an algebraically closed field; over a smaller field, curves with the same j may still be non-isomorphic twists.

Small characteristic needs the general form

The reduction to short Weierstrass form divides by 2 and 3. In characteristic 2 or 3 the general five-coefficient equation must be retained, and the group law formulas differ. Code that assumes the short form will silently fail on these fields.

Section 02The group law

Three collinear points on the curve sum to the identity. Turning that into formulas:

AlgorithmAddition on y² = x³ + ax + bin: points P, Q on E  →  out: P + Q
  1. If P = O, return Q; if Q = O, return P.
  2. If x1 = x2 and y1 = −y2, return O. The points are inverse to one another.
  3. If P ≠ Q, set λ ← (y2 − y1) / (x2 − x1).
  4. If P = Q, set λ ← (3x12 + a) / (2y1) — the tangent slope.
  5. Set x3 ← λ2 − x1 − x2 and y3 ← λ(x1 − x3) − y1.
  6. Return (x3, y3).
Each addition needs one field inversion. Over ℤ/nℤ with n composite, that inversion can fail — and the failure reveals a factor of n, which is the entire basis of the elliptic curve factoring method.
Inversion-free coordinates

Projective and Jacobian coordinates represent a point with an extra coordinate so that addition uses no inversion, deferring a single inversion to the end of a long computation. For scalar multiplication with hundreds of doublings this is a large saving — but note that it also suppresses the inversion failures that ECM depends on, so factoring implementations must handle this deliberately.

Section 03Groups over finite fields

Over Fq the group of points is finite, and Hasse's theorem bounds its order:

|#E(Fq) − (q + 1)| ≤ 2√q

The structure is cyclic or a product of two cyclic groups, the second factor's order dividing the first and dividing q − 1.

2√qwidth of the Hasse interval
O(log8 q)Schoof's algorithm for point counting
SEAthe practical improvement, used to this day
Why the freedom in group order matters

For a fixed field, different curves give different group orders spread across the Hasse interval. The p−1 method works only when p−1 happens to be smooth; ECM replaces that fixed group with a curve group that can be resampled until a smooth order appears. That resampling is the entire advantage of ECM over p−1.

Section 04Points over ℚ and torsion

The Mordell–Weil theorem states that E(ℚ) is finitely generated:

E(ℚ) ≅ E(ℚ)tors ⊕ ℤr

The torsion subgroup is easy to compute — by Mazur's theorem it is one of fifteen possibilities, all small — and the Nagell–Lutz criterion bounds candidate torsion points by requiring integral coordinates with y2 dividing the discriminant. The rank r is by contrast genuinely difficult, and no algorithm is known that provably computes it in all cases.

Torsion is easy, rank is not

The asymmetry is stark: torsion is decided by a short finite search, while rank computation relies on descent, may fail to terminate conclusively, and is entangled with the unproven finiteness of the Tate–Shafarevich group.

ReferenceFrequently asked questions

Why is the point at infinity needed?

Because the group law requires an identity, and two points with the same x-coordinate have no third intersection in the affine plane. The projective point at infinity supplies both, making the group law total.

Is the group law associative, and is that obvious?

It is associative, but it is not obvious — a direct verification from the formulas is lengthy. The conceptual proof identifies the group with the divisor class group of degree zero, where associativity is inherited from addition of divisors.

How is the group order computed in practice?

By Schoof's algorithm and its SEA refinement, which determine the order modulo many small primes using the action of Frobenius on torsion points, then combine by the Chinese remainder theorem within the Hasse interval.

NavigateContinue in this stream

Curated next steps from this page. The site also surfaces algorithmically related reading below.

ProvenanceSources and further reading

This page is an original KEVOS explanatory article. It presents the underlying mathematics — definitions, algorithms, complexity results and selection criteria — in KEVOS editorial voice. No text is reproduced from any copyrighted source. Where numerical tables are relevant, KEVOS links to live authoritative databases rather than republishing static values.

Page ID
KV-MATH-0040
Taxonomy
ENG-MATH — Engineering / Mathematics
Collection
COL-CANT-001
Topic stream
CANT-ELLIPTIC-CURVES
Version
1.1.0 / content 2026.08
Last reviewed
2026-08-06

Continue learning

NEXT LESSON →Complex Multiplication and Class FieldsGuide · MathematicsElliptic Curve L-functions and the Birch–Swinnerton-Dyer ConjectureGuide · MathematicsAlgorithms for Elliptic Curves over ℚGuide · MathematicsComputational Algebraic Number Theory: Discipline OverviewGuide · Mathematics