Mathematics RU

Practice · Chapter 44

Adding points on an elliptic curve

Adding points on an elliptic curve: by a chord, doubling by a tangent, and the same modulo a prime — the basis of elliptic curve cryptography.

How to solve it

On the curve $y^2 = x^3 + ax + b$ points can be added: the line through $P$ and $Q$ meets the curve at a third point, and its reflection in the $x$-axis is $P + Q$. For $P + P$ the tangent replaces the chord. The same formulas work modulo a prime $p$ — elliptic curve cryptography rests on that.

Step by step

  1. The slope: for a chord $\lambda = \frac{y_2 - y_1}{x_2 - x_1}$, for a tangent (doubling) $\lambda = \frac{3x_1^2 + a}{2y_1}$.
  2. The result's $x$: $x_3 = \lambda^2 - x_1 - x_2$ (when doubling, $x_2 = x_1$).
  3. Its $y$: $y_3 = \lambda(x_1 - x_3) - y_1$ — already the reflected third point.
  4. Modulo $p$: division is multiplication by the inverse modulo $p$; work with remainders throughout.
The slope of the line through $P$ and $Q$ (for doubling, the slope of the tangent). The $x$ of the third intersection point. The $y$ of the sum, with its sign, already reflected. Example: $y^2 = x^3 + 2x + 4$, $P = (-1,\ 1)$, $Q = (2,\ 4)$: $\lambda = \frac{3}{3} = 1$, $x_3 = 1 + 1 - 2 = 0$, $y_3 = 1 \cdot (-1 - 0) - 1 = -2$. The sum is $(0,\ -2)$.

Common mistakes

  • Answering with the third intersection point without reflecting it: the sign of $y$ must change (the formula already does it).
  • Using the chord formula for doubling — the denominator becomes zero.
  • Forgetting the coefficient $a$ in the tangent: $\lambda = \frac{3x_1^2 + a}{2y_1}$.
  • Dividing like ordinary fractions modulo $p$ instead of multiplying by the inverse.

Example