Wikiwand AI

Supersingular prime (algebraic number theory)

Prime number with a certain relationship to an elliptic curve From Wikipedia, the free encyclopedia

In algebraic number theory, a supersingular prime for a given elliptic curve is a prime number with a certain relationship to that curve. If the curve is defined over the rational numbers, then a prime is supersingular for E if the reduction of modulo is a supersingular elliptic curve over the residue field .[1]

Equivalently, for a prime of good reduction for , the prime is supersingular for if and only if the trace of the Frobenius endomorphism is zero, that is, .[1] This condition means that the reduction of modulo has the maximum possible endomorphism ring—an order in a quaternion algebra—rather than an order in an imaginary quadratic field.[2]

Distribution

Complex multiplication case

When has complex multiplication (CM) by an order in an imaginary quadratic field , the distribution of supersingular primes is well understood. A classical result of Deuring (1941) implies that a prime of good reduction is supersingular for if and only if is inert or ramified in .[2] By the Chebotarev density theorem, these primes constitute exactly half of all primes, so the set of supersingular primes for a CM curve has natural density .[3]

Non-CM case

When does not have complex multiplication, the situation is more subtle. In 1968, Serre proved that the set of supersingular primes has asymptotic density zero by applying the Chebotarev density theorem to the number fields generated by coordinates of the torsion points of .[3][4] Serre later obtained the unconditional upper bound

for any , where denotes the number of supersingular primes up to , and showed that under the Generalized Riemann Hypothesis (GRH) one could achieve the bound .[5][4] The unconditional exponent was subsequently improved by Wan (1990), who showed

by incorporating sieve-theoretic techniques.[6]

Despite this rarity, Noam Elkies proved in 1987 that every elliptic curve over has infinitely many supersingular primes.[7] His proof uses the theory of complex multiplication and Deuring's lifting lemma: given any finite set of primes, one can find a negative fundamental discriminant such that the Hilbert class polynomial evaluated at the j-invariant has a prime factor outside , and this prime is necessarily supersingular for .[7] Elkies later extended this result to elliptic curves defined over any number field with at least one real embedding.[8]

Lang–Trotter conjecture

Lang & Trotter (1976) conjectured that the number of supersingular primes less than a bound satisfies

as , where is an explicit constant depending on .[9] This prediction arises from a probabilistic heuristic: by the Hasse bound, , so the "probability" that for a random prime is roughly , and summing this over primes up to gives an expected count on the order of .[9] As of 2026, this conjecture remains open.[10]

Example

Consider the elliptic curve , which is the modular curve with j-invariant . The supersingular primes for this curve begin: 2, 19, 29, 199, 569, 809, 1289, 1439, 2539, 3319, ... (sequence A006962 in the OEIS).[4] These are exactly the primes for which the coefficient of in vanishes modulo , where is the Dedekind eta function.

Generalization

More generally, if is any global field—that is, a finite extension of or of —and is an abelian variety defined over , then a supersingular prime for A is a finite place of such that the reduction of modulo is a supersingular abelian variety.[1] It is conjectured that every abelian variety over a number field has infinitely many supersingular primes, but this is known only in special cases.[8]

See also

Notes

References

Related Articles

Timelines

Top Qs

Fact Checks