5.1 Ordinary and Supersingular Curves
نویسنده
چکیده
Theorem 15.1. Let E/Fq be an elliptic curve over a finite field, and let πE be the Frobenius endomorphism of E. Then E is supersingular if and only if trπE ≡ 0 mod p. Proof. Let q = pn and let π be the p-power Frobenius map π(x, y) = (xp, yp) (note that π is an isogeny, but not necessarily an endomorphism, since E need not be defined over Fp). We have π̂π = [p], where [p] denotes the multiplication-by-p endomorphism on E. We first suppose that E is supersingular. The kernel of π̂ must then be trivial, since the kernel of [p] is trivial, and π̂ is therefore inseparable, since it has degree p > 1. The map π̂n = π̂n = π̂E is also inseparable, as is πE , so trπE = πE + π̂E is a sum of inseparable endomorphisms. Thus the endomorphism [trπE ] is inseparable, which means that p divides trπE , since [m] is separable ⇔ p m, by Theorem 6.9. So trπE ≡ 0 mod p. Conversely, if trπE ≡ 0 mod p, then [trπE ] is inseparable, and π̂E = trπE−πE is a sum of inseparable isogenies and therefore inseparable. This means that π̂n and therefore π̂ is inseparable. Therefore π̂ must have trivial kernel, since its degree is prime, and the same is true of π. So the kernel of [p] = π̂π is trivial and E is supersingular.
منابع مشابه
The main conjecture for CM elliptic curves at supersingular primes
At a prime of ordinary reduction, the Iwasawa “main conjecture” for elliptic curves relates a Selmer group to a p-adic L-function. In the supersingular case, the statement of the main conjecture is more complicated as neither the Selmer group nor the p-adic L-function is well-behaved. Recently Kobayashi discovered an equivalent formulation of the main conjecture at supersingular primes that is ...
متن کاملTwo p-adic L-functions and rational points on elliptic curves with supersingular reduction
Let E be an elliptic curve over Q. We assume that E has good supersingular reduction at a prime p, and for simplicity, assume p is odd and ap = p+ 1− #E(Fp) is zero. Then, as the second author showed, the p-adic L-function Lp,α(E) of E corresponding to α = ±√−p (by Amice-Vélu and Vishik) can be written as Lp,α(E) = f log+p +g logp α by using two Iwasawa functions f and g ∈ Zp[[Gal(Q∞/Q)]] ([20]...
متن کاملDiffie-Hellman type key exchange protocols based on isogenies
In this paper, we propose some Diffie-Hellman type key exchange protocols using isogenies of elliptic curves. The first method which uses the endomorphism ring of an ordinary elliptic curve $ E $, is a straightforward generalization of elliptic curve Diffie-Hellman key exchange. The method uses commutativity of the endomorphism ring $ End(E) $. Then using dual isogenies, we propose...
متن کامل2 9 A ug 2 00 7 On the modularity of supersingular elliptic curves over certain totally real number fields
We study generalisations to totally real fields of the methods originating with Wiles and Taylor-Wiles ([32], [31]). In view of the results of Skinner-Wiles [26] on elliptic curves with ordinary reduction, we focus here on the case of supersingular reduction. Combining these, we then obtain some partial results on the modularity problem for semistable elliptic curves, and end by giving some app...
متن کاملTowards Quantum-Resistant Cryptosystems from Supersingular Elliptic Curve Isogenies
We present new candidates for quantum-resistant public-key cryptosystems based on the conjectured difficulty of finding isogenies between supersingular elliptic curves. The main technical idea in our scheme is that we transmit the images of torsion bases under the isogeny in order to allow the two parties to arrive at a common shared key despite the noncommutativity of the endomorphism ring. Ou...
متن کامل