Supersingular elliptic curve

From HandWiki
Short description: Mathematical concept

In arithmetic geometry, supersingular elliptic curves form a certain class of elliptic curves over a field of characteristic p>0 with unusually large endomorphism rings. Elliptic curves over such fields which are not supersingular are called ordinary, and these two classes of elliptic curves behave fundamentally differently in many aspects. (Hasse 1936) discovered supersingular elliptic curves during his work on the Riemann hypothesis for elliptic curves by observing that positive characteristic elliptic curves could have endomorphism rings of unusually large rank 4, and (Deuring 1941) developed their basic theory.

The term "supersingular" has nothing to do with singular points of curves, and all supersingular elliptic curves are non-singular. It comes from the phrase "singular values of the j-invariant" used for values of the j-invariant for which a complex elliptic curve has complex multiplication. The complex elliptic curves with complex multiplication are those for which the endomorphism ring has the maximal possible rank 2. In positive characteristic it is possible for the endomorphism ring to be even larger: it can be an order in a quaternion algebra of dimension 4, in which case the elliptic curve is supersingular.[1]

Definition

There are many different but equivalent ways of defining supersingular elliptic curves.[2] Let K be a field with algebraic closure K of characteristic p>0, and let E be an elliptic curve over K.

  • The K-valued points E(K) have the structure of an abelian group. For every n, we have a multiplication map [n]:EE whose kernel is denoted by E[n]. One can show that either
E[pr](K){0, or/pr
for r=1,2,3, In the first case, E is called supersingular. Otherwise it is called ordinary. In other words, an elliptic curve is supersingular if and only if the group of geometric points of order p is trivial.[3]
  • An elliptic curve is supersingular if and only if its endomorphism algebra End(E) over K is an order in a quaternion algebra. In this case the endomorphism algebra has rank 4, while the endomorphism ring of every ordinary elliptic curve has rank 1 or 2.[3] The endomorphism ring of a supersingular elliptic curve over a given base field can have rank less than 4; it may be necessary to pass to a finite extension of K to realize the full rank. In particular, the endomorphism ring of an elliptic curve over a field of prime order is never of rank 4, even if the elliptic curve is supersingular.[1]
  • Let G be the formal group associated to E. Then E is supersingular if and only if the height ht(G)=2; for ordinary curves the height is 1.[4]
  • The Frobenius morphism F:EE induces a map F*:H1(E,𝒪E)H1(E,𝒪E). The curve E is supersingular if and only if F*=0.[5]
  • The Verschiebung operator V:EE induces a map V*:H0(E,ΩE1)H0(E,ΩE1). The curve E is supersingular if and only if V*=0.[5]
  • An elliptic curve is supersingular if and only if its Hasse invariant is 0.[5]
  • An elliptic curve is supersingular if and only if the group scheme E[p] is connected.[1]
  • An elliptic curve is supersingular if and only if the dual of the Frobenius map is purely inseparable.[1]
  • An elliptic curve is supersingular if and only if the "multiplication by p" map is purely inseparable and the j-invariant of the curve lies in 𝔽p2.[3]
  • Suppose E is in Legendre form, defined by the equation y2=x(x1)(xλ), and p is odd. Then for λ0,1, the curve E is supersingular if and only if the sum
i=0n(ni)2λi
vanishes, where n=(p1)/2.[5] Using this formula, one can show that there are only finitely many supersingular elliptic curves over K (up to isomorphism).
  • Suppose E is given as a cubic curve in the projective plane by a homogeneous cubic polynomial f(x,y,z). Then E is supersingular if and only if the coefficient of (xyz)p1 in fp1 is zero.[6]
  • If K is a finite field of order q, then E is supersingular if and only if the trace of the q-power Frobenius endomorphism is congruent to zero modulo p. When q=p>3 this is equivalent to having the trace of Frobenius equal to zero (by the Hasse bound); this does not hold for p=2 or 3.[3]

Examples

  • If K is a field of characteristic 2, every curve defined by an equation of the form y2+a3y=x3+a4x+a6 with a30 is a supersingular elliptic curve, and conversely every supersingular curve in characteristic 2 is isomorphic to one of this form.[7]
  • Over the field with 2 elements, any supersingular elliptic curve is isomorphic to exactly one of the following:[5]
y2+y=x3+x+1
y2+y=x3+1
y2+y=x3+x
with 1, 3, and 5 points respectively.
  • Over an algebraically closed field of characteristic 2, there is (up to isomorphism) exactly one supersingular elliptic curve, given by y2+y=x3, with j-invariant 0. Its ring of endomorphisms is the ring of Hurwitz quaternions, and its automorphism group has order 24, contains a normal subgroup of order 8 isomorphic to the quaternion group, and is the binary tetrahedral group.[1]
  • If K is a field of characteristic 3, every curve defined by an equation of the form y2=x3+a4x+a6 with a40 is a supersingular elliptic curve, and conversely every supersingular curve in characteristic 3 is isomorphic to one of this form.[7]
  • Over an algebraically closed field of characteristic 3, there is (up to isomorphism) exactly one supersingular elliptic curve, given by y2=x3x, with j-invariant 0. Its ring of endomorphisms is the ring of quaternions of the form a+bj with a and b Eisenstein integers, and its automorphism group has order 12.[1]
  • For p>3, the elliptic curve y2=x3+1 (with j-invariant 0) is supersingular if and only if p2(mod3), and the elliptic curve y2=x3+x (with j-invariant 1728) is supersingular if and only if p3(mod4).[8]
  • The elliptic curve y2=x(x1)(x+2) is nonsingular over 𝔽p for p2,3. It is supersingular for p=23 and ordinary for every other prime p73.[6]
  • The modular curve X0(11), with j-invariant 212115313 and equation y2+y=x3x210x20, is supersingular at primes p for which the coefficient of qp in η(τ)2η(11τ)2 vanishes mod p. These primes begin 2, 19, 29, 199, 569, 809, 1289, 1439, 2539, 3319, ... (sequence A006962 in the OEIS).[9]

Classification

For each prime p there are only finitely many j-invariants of supersingular elliptic curves in characteristic p. Over an algebraically closed field, an elliptic curve is determined by its j-invariant, so the number of isomorphism classes is finite.[5] If each supersingular curve E is weighted by 1/|Aut(E)|, then the total weight is (p1)/24.[5]

Since elliptic curves generically have automorphism groups of order 2 (with exceptions at j=0 and j=1728), the classification is as follows:[5]

  • There are exactly p/12 supersingular elliptic curves with automorphism groups of order 2.
  • If p3(mod4), there is an additional supersingular curve with j-invariant 1728 whose automorphism group is cyclic of order 4, except when p=3, where it has order 12.
  • If p2(mod3), there is an additional supersingular curve with j-invariant 0 whose automorphism group is cyclic of order 6, except when p=2, where it has order 24.

All supersingular j-invariants in characteristic p lie in the finite field 𝔽p2.[3] For small primes, they all lie in the prime subfield 𝔽p itself, but this property fails for larger primes—the first failure occurs at p=37, where the supersingular j-invariants include the roots of x26x+6𝔽37[x], which are the conjugate pair 3±15 in 𝔽372.[10] The distinction between primes for which all supersingular j-invariants are rational (lie in 𝔽p) and primes for which some require the quadratic extension 𝔽p2 is central to the connection with monstrous moonshine, described in the next section.

(Birch Kuyk) give a table of all j-invariants of supersingular curves for primes up to 307. For the first few primes, the supersingular j-invariants are:[10]

Prime p Supersingular j-invariants All in 𝔽p?
2 0 Yes
3 1728 Yes
5 0 Yes
7 1728 Yes
11 0, 1728 Yes
13 5 Yes
17 0, 8 Yes
19 7, 1728 Yes
23 0, 19, 1728 Yes
29 0, 2, 25 Yes
31 2, 4, 1728 Yes
37 8, 3±√15 No

Connection with supersingular primes

The notion of supersingular elliptic curves gives rise to two different but related uses of the term "supersingular prime" in number theory.

Supersingular primes for a given curve

Given an elliptic curve E defined over the rationals and a prime p of good reduction, the prime p is called a supersingular prime for E if the reduction of E modulo p is a supersingular elliptic curve over 𝔽p.[5] This notion depends on the choice of curve: different elliptic curves have different sets of supersingular primes. (Elkies 1987) proved that every elliptic curve over has infinitely many supersingular primes, though Serre showed that for curves without complex multiplication, the set of such primes has asymptotic density zero.[11][12]

Supersingular primes in moonshine theory

A prime p is called a supersingular prime (without reference to any particular curve) if every supersingular elliptic curve in characteristic p can be defined over the prime subfield 𝔽p—equivalently, if every supersingular j-invariant in characteristic p lies in 𝔽p rather than requiring the extension 𝔽p2.[13] Andrew Ogg proved that this condition is equivalent to the modular curve X0+(p)=X0(p)/wp having genus zero, and that exactly fifteen primes satisfy it: 2, 3, 5, 7, 11, 13, 17, 19, 23, 29, 31, 41, 47, 59, and 71.[13]

Ogg then noticed that these are precisely the prime divisors of the order of the Monster group, the largest sporadic simple group. This coincidence—connecting the arithmetic geometry of modular curves to the representation theory of sporadic groups—was one of the starting points of the theory of monstrous moonshine, later developed by Conway and Norton (1979) and proved by Richard Borcherds (1992).[13]

See also

Notes

  1. 1.0 1.1 1.2 1.3 1.4 1.5 Silverman 2009, Ch. V, §3.
  2. Silverman 2009, Ch. V, §3–4.
  3. 3.0 3.1 3.2 3.3 3.4 Silverman 2009, Ch. V, Theorem 3.1.
  4. Silverman 2009, Ch. IV, Theorem 7.4.
  5. 5.0 5.1 5.2 5.3 5.4 5.5 5.6 5.7 5.8 Silverman 2009, Ch. V, §4.
  6. 6.0 6.1 Hartshorne 1977, p. 332.
  7. 7.0 7.1 Washington 2003, p. 122.
  8. Washington 2003, p. 119.
  9. Elkies 1991, p. 127.
  10. 10.0 10.1 Birch & Kuyk 1975, pp. 142–144.
  11. Elkies 1987.
  12. Serre 1998, p. I-25.
  13. 13.0 13.1 13.2 Ogg 1980.

References