KEVOS
ArticlesServicesCase studiesAboutContact
ArticlesServicesCase studiesAboutContact
← ArticlesElliptic Curves: Definitions and the Group LawEngineering · Engineering MathematicsLesson 1/4← PrevNext →
GuidePublished 6 Aug 20265 min readBy Kevin JoginComputational Number TheoryElliptic CurvesElliptic CurveWeierstrass Equation
On this page

Ask about this page

KEVOS AIElliptic Curves: Definitions and the Group Law

KEVOS knowledge first · trusted web sources when needed

Skip to the main content

Mathematics•Elliptic Curves

Elliptic Curves: Definitions and the Group Law

Weierstrass equations, the chord-and-tangent group law, and the arithmetic that makes curves usable in factoring, primality proving and cryptography.

  • Engineering
  • Mathematics
  • Part 1 of 4
  • 5 min read
  • KV-MATH-0040
Executive summary

A cubic curve whose points form a group

An elliptic curve is a non-singular cubic with a distinguished point at infinity. Its points form an abelian group under the chord-and-tangent construction, with the point at infinity as identity. Over a finite field the group is finite with order constrained by Hasse's bound to within 2√q of q + 1 — and that near-freedom in the group order is precisely what the elliptic curve factoring and primality methods exploit.

Learning objectives

  • Write a curve in Weierstrass form and compute its discriminant and j-invariant.
  • Apply the group law formulas including the special cases.
  • State Hasse's theorem and its significance.
  • Explain why varying the curve varies the group order.
  • Choose coordinates that avoid modular inversions.

Section 01Weierstrass form

The general Weierstrass equation is

y2 + a1xy + a3y = x3 + a2x2 + a4x + a6

Away from characteristic 2 and 3 this simplifies by completing the square and the cube to the short form y2 = x3 + ax + b, with

Δ = −16(4a3 + 27b2),     j = −1728 (4a)3 / Δ

The curve is non-singular exactly when Δ ≠ 0. The j-invariant classifies curves up to isomorphism over an algebraically closed field; over a smaller field, curves with the same j may still be non-isomorphic twists.

Small characteristic needs the general form

The reduction to short Weierstrass form divides by 2 and 3. In characteristic 2 or 3 the general five-coefficient equation must be retained, and the group law formulas differ. Code that assumes the short form will silently fail on these fields.

Section 02The group law

Three collinear points on the curve sum to the identity. Turning that into formulas:

AlgorithmAddition on y² = x³ + ax + bin: points P, Q on E  →  out: P + Q
  1. If P = O, return Q; if Q = O, return P.
  2. If x1 = x2 and y1 = −y2, return O. The points are inverse to one another.
  3. If P ≠ Q, set λ ← (y2 − y1) / (x2 − x1).
  4. If P = Q, set λ ← (3x12 + a) / (2y1) — the tangent slope.
  5. Set x3 ← λ2 − x1 − x2 and y3 ← λ(x1 − x3) − y1.
  6. Return (x3, y3).
Each addition needs one field inversion. Over ℤ/nℤ with n composite, that inversion can fail — and the failure reveals a factor of n, which is the entire basis of the elliptic curve factoring method.
Inversion-free coordinates

Projective and Jacobian coordinates represent a point with an extra coordinate so that addition uses no inversion, deferring a single inversion to the end of a long computation. For scalar multiplication with hundreds of doublings this is a large saving — but note that it also suppresses the inversion failures that ECM depends on, so factoring implementations must handle this deliberately.

Section 03Groups over finite fields

Over Fq the group of points is finite, and Hasse's theorem bounds its order:

|#E(Fq) − (q + 1)| ≤ 2√q

The structure is cyclic or a product of two cyclic groups, the second factor's order dividing the first and dividing q − 1.

2√qwidth of the Hasse interval
O(log8 q)Schoof's algorithm for point counting
SEAthe practical improvement, used to this day
Why the freedom in group order matters

For a fixed field, different curves give different group orders spread across the Hasse interval. The p−1 method works only when p−1 happens to be smooth; ECM replaces that fixed group with a curve group that can be resampled until a smooth order appears. That resampling is the entire advantage of ECM over p−1.

Section 04Points over ℚ and torsion

The Mordell–Weil theorem states that E(ℚ) is finitely generated:

E(ℚ) ≅ E(ℚ)tors ⊕ ℤr

The torsion subgroup is easy to compute — by Mazur's theorem it is one of fifteen possibilities, all small — and the Nagell–Lutz criterion bounds candidate torsion points by requiring integral coordinates with y2 dividing the discriminant. The rank r is by contrast genuinely difficult, and no algorithm is known that provably computes it in all cases.

Torsion is easy, rank is not

The asymmetry is stark: torsion is decided by a short finite search, while rank computation relies on descent, may fail to terminate conclusively, and is entangled with the unproven finiteness of the Tate–Shafarevich group.

ReferenceFrequently asked questions

Why is the point at infinity needed?

Because the group law requires an identity, and two points with the same x-coordinate have no third intersection in the affine plane. The projective point at infinity supplies both, making the group law total.

Is the group law associative, and is that obvious?

It is associative, but it is not obvious — a direct verification from the formulas is lengthy. The conceptual proof identifies the group with the divisor class group of degree zero, where associativity is inherited from addition of divisors.

How is the group order computed in practice?

By Schoof's algorithm and its SEA refinement, which determine the order modulo many small primes using the action of Frobenius on torsion points, then combine by the Chinese remainder theorem within the Hasse interval.

NavigateContinue in this stream

Curated next steps from this page. The site also surfaces algorithmically related reading below.

  • FactoringThe Elliptic Curve Method (ECM)
  • Elliptic CurvesComplex Multiplication and Class Fields
  • Elliptic CurvesAlgorithms for Elliptic Curves over ℚ
  • Foundational AlgorithmsModular Exponentiation and Powering Algorithms

ProvenanceSources and further reading

This page is an original KEVOS explanatory article. It presents the underlying mathematics — definitions, algorithms, complexity results and selection criteria — in KEVOS editorial voice. No text is reproduced from any copyrighted source. Where numerical tables are relevant, KEVOS links to live authoritative databases rather than republishing static values.

On this page

  1. Executive summary
  2. Weierstrass form
  3. The group law
  4. Groups over finite fields
  5. Points over ℚ and torsion
  6. FAQ
  7. Continue in this stream
  8. Sources
Page ID
KV-MATH-0040
Taxonomy
ENG-MATH — Engineering / Mathematics
Collection
COL-CANT-001
Topic stream
CANT-ELLIPTIC-CURVES
Version
1.1.0 / content 2026.08
Last reviewed
2026-08-06

Continue learning

NEXT LESSON →Complex Multiplication and Class FieldsGuide · Engineering MathematicsElliptic Curve L-functions and the Birch–Swinnerton-Dyer ConjectureGuide · Engineering MathematicsAlgorithms for Elliptic Curves over ℚGuide · Engineering MathematicsElliptic Curves: Basic DefinitionsArticle · Engineering Mathematics
KEVOS · Engineering, manufacturing and project improvement
ArticlesServicesCase studiesAboutContact
© 2026 KEVOS®