(Annals of Mathematics) Andrew Wiles-Modular Elliptic Curves and Fermat's Last Theorem-Princeton University Press (1995) PDF

Download as pdf or txt
Download as pdf or txt
You are on page 1of 109

Annals of Mathematics, 141 (1995), 443-551

Modular elliptic curves


and
Fermats Last Theorem
By Andrew John Wiles*
For Nada, Claire, Kate and Olivia
Pierre de Fermat

Andrew John Wiles

Cubum autem in duos cubos, aut quadratoquadratum in duos quadratoquadratos, et generaliter nullam in infinitum ultra quadratum
potestatum in duos ejusdem nominis fas est dividere: cujes rei
demonstrationem mirabilem sane detexi. Hanc marginis exiguitas
non caperet.
- Pierre de Fermat 1637
Abstract. When Andrew John Wiles was 10 years old, he read Eric Temple Bells The
Last Problem and was so impressed by it that he decided that he would be the first person
to prove Fermats Last Theorem. This theorem states that there are no nonzero integers
a, b, c, n with n > 2 such that an + bn = cn . The object of this paper is to prove that
all semistable elliptic curves over the set of rational numbers are modular. Fermats Last
Theorem follows as a corollary by virtue of previous work by Frey, Serre and Ribet.

Introduction
An elliptic curve over Q is said to be modular if it has a finite covering by
a modular curve of the form X0 (N ). Any such elliptic curve has the property
that its Hasse-Weil zeta function has an analytic continuation and satisfies a
functional equation of the standard type. If an elliptic curve over Q with a
given j-invariant is modular then it is easy to see that all elliptic curves with
the same j-invariant are modular (in which case we say that the j-invariant
is modular). A well-known conjecture which grew out of the work of Shimura
and Taniyama in the 1950s and 1960s asserts that every elliptic curve over Q
is modular. However, it only became widely known through its publication in a
paper of Weil in 1967 [We] (as an exercise for the interested reader!), in which,
moreover, Weil gave conceptual evidence for the conjecture. Although it had
been numerically verified in many cases, prior to the results described in this
paper it had only been known that finitely many j-invariants were modular.
In 1985 Frey made the remarkable observation that this conjecture should
imply Fermats Last Theorem. The precise mechanism relating the two was
formulated by Serre as the -conjecture and this was then proved by Ribet in
the summer of 1986. Ribets result only requires one to prove the conjecture
for semistable elliptic curves in order to deduce Fermats Last Theorem.
*The work on this paper was supported by an NSF grant.

444

ANDREW JOHN WILES

Our approach to the study of elliptic curves is via their associated Galois

representations. Suppose that p is the representation of Gal(Q/Q)


on the
p-division points of an elliptic curve over Q, and suppose for the moment that
3 is irreducible. The choice of 3 is critical because a crucial theorem of Langlands and Tunnell shows that if 3 is irreducible then it is also modular. We
then proceed by showing that under the hypothesis that 3 is semistable at 3,
together with some milder restrictions on the ramification of 3 at the other
primes, every suitable lifting of 3 is modular. To do this we link the problem,
via some novel arguments from commutative algebra, to a class number problem of a well-known type. This we then solve with the help of the paper [TW].
This suffices to prove the modularity of E as it is known that E is modular if
and only if the associated 3-adic representation is modular.
The key development in the proof is a new and surprising link between two
strong but distinct traditions in number theory, the relationship between Galois
representations and modular forms on the one hand and the interpretation of
special values of L-functions on the other. The former tradition is of course
more recent. Following the original results of Eichler and Shimura in the
1950s and 1960s the other main theorems were proved by Deligne, Serre and
Langlands in the period up to 1980. This included the construction of Galois
representations associated to modular forms, the refinements of Langlands and
Deligne (later completed by Carayol), and the crucial application by Langlands
of base change methods to give converse results in weight one. However with
the exception of the rather special weight one case, including the extension by
Tunnell of Langlands original theorem, there was no progress in the direction
of associating modular forms to Galois representations. From the mid 1980s
the main impetus to the field was given by the conjectures of Serre which
elaborated on the -conjecture alluded to before. Besides the work of Ribet and
others on this problem we draw on some of the more specialized developments
of the 1980s, notably those of Hida and Mazur.
The second tradition goes back to the famous analytic class number formula of Dirichlet, but owes its modern revival to the conjecture of Birch and
Swinnerton-Dyer. In practice however, it is the ideas of Iwasawa in this field on
which we attempt to draw, and which to a large extent we have to replace. The
principles of Galois cohomology, and in particular the fundamental theorems
of Poitou and Tate, also play an important role here.
The restriction that 3 be irreducible at 3 is bypassed by means of an
intriguing argument with families of elliptic curves which share a common
5 . Using this, we complete the proof that all semistable elliptic curves are
modular. In particular, this finally yields a proof of Fermats Last Theorem. In
addition, this method seems well suited to establishing that all elliptic curves
over Q are modular and to generalization to other totally real number fields.
Now we present our methods and results in more detail.

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

445

Let f be an eigenform associated to the congruence subgroup 1 (N ) of


SL2 (Z) of weight k 2 and character . Thus if Tn is the Hecke operator
associated to an integer n there is an algebraic integer c(n, f ) such that T n f =
c(n, f )f for each n. We let Kf be the number field generated over Q by the
{c(n, f )} together with the values of and let Of be its ring of integers.
For any prime of Of let Of, be the completion of Of at . The following
theorem is due to Eichler and Shimura (for k = 2) and Deligne (for k > 2).
The analogous result when k = 1 is a celebrated theorem of Serre and Deligne
but is more naturally stated in terms of complex representations. The image
in that case is finite and a converse is known in many cases.
Theorem 0.1. For each prime p Z and each prime |p of Of there
is a continuous representation

f, : Gal(Q/Q)
GL2 (Of, )
which is unramified outside the primes dividing N p and such that for all primes
q - N p,
trace f, (Frob q) = c(q, f ),

det f, (Frob q) = (q)q k1 .

We will be concerned with trying to prove results in the opposite direction,


that is to say, with establishing criteria under which a -adic representation
arises in this way from a modular form. We have not found any advantage
in assuming that the representation is part of a compatible system of -adic
representations except that the proof may be easier for some than for others.
Assume

p)
0 : Gal(Q/Q)
GL2 (F
is a continuous representation with values in the algebraic closure of a finite
field of characteristic p and that det 0 is odd. We say that 0 is modular
p for some f and and some
if 0 and f, mod are isomorphic over F
p . Serre has conjectured that every irreducible 0 of
embedding of Of / in F
odd determinant is modular. Very little is known about this conjecture except
p ) is dihedral, A4 or S4 . In the dihedral case
when the image of 0 in PGL2 (F
it is true and due (essentially) to Hecke, and in the A4 and S4 cases it is again
true and due primarily to Langlands, with one important case due to Tunnell
(see Theorem 5.1 for a statement). More precisely these theorems actually
associate a form of weight one to the corresponding complex representation
but the versions we need are straightforward deductions from the complex
case. Even in the reducible case not much is known about the problem in
the form we have described it, and in that case it should be observed that
one must also choose the lattice carefully as only the semisimplification of
2
f, = f, mod is independent of the choice of lattice in Kf,
.

446

ANDREW JOHN WILES

If O is the ring of integers of a local field (containing Qp ) we will say that

: Gal(Q/Q)
GL2 (O) is a lifting of 0 if, for a specified embedding of the
p , and 0 are isomorphic over F
p . Our point of view
residue field of O in F
will be to assume that 0 is modular and then to attempt to give conditions
under which a representation lifting 0 comes from a modular form in the
sense that ' f, over Kf, for some f, . We will restrict our attention to
two cases:
(I) 0 is ordinary (at p) by which we mean that there is a one-dimensional
2 , stable under a decomposition group at p and such that
subspace of F
p
the action on the quotient space is unramified and distinct from the
action on the subspace.
(II) 0 is flat (at p), meaning that as a representation of a decomposition
group at p, 0 is equivalent to one that arises from a finite flat group
scheme over Zp , and det 0 restricted to an inertia group at p is the
cyclotomic character.
2,
We say similarly that is ordinary (at p), if viewed as a representation to Q
p
2 stable under a decomposition group
there is a one-dimensional subspace of Q
p
at p and such that the action on the quotient space is unramified.

Let : Gal(Q/Q)
Z
p denote the cyclotomic character. Conjectural
converses to Theorem 0.1 have been part of the folklore for many years but
have hitherto lacked any evidence. The critical idea that one might dispense
with compatible systems was already observed by Drinfield in the function field
case [Dr]. The idea that one only needs to make a geometric condition on the
restriction to the decomposition group at p was first suggested by Fontaine and
Mazur. The following version is a natural extension of Serres conjecture which
is convenient for stating our results and is, in a slightly modified form, the one
proposed by Fontaine and Mazur. (In the form stated this incorporates Serres
conjecture. We could instead have made the hypothesis that 0 is modular.)

Conjecture. Suppose that : Gal(Q/Q)


GL2 (O) is an irreducible
lifting of 0 and that is unramified outside of a finite set of primes. There
are two cases:
(i) Assume that 0 is ordinary. Then if is ordinary and det = k1 for
some integer k 2 and some of finite order, comes from a modular
form.
(ii) Assume that 0 is flat and that p is odd. Then if restricted to a decomposition group at p is equivalent to a representation on a p-divisible
group, again comes from a modular form.

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

447

In case (ii) it is not hard to see that if the form exists it has to be of
weight 2; in (i) of course it would have weight k. One can of course enlarge
this conjecture in several ways, by weakening the conditions in (i) and (ii), by
considering other number fields of Q and by considering groups other
than GL2 .
We prove two results concerning this conjecture. The first includes the
hypothesis that 0 is modular. Here and for the rest of this paper we will
assume that p is an odd prime.
Theorem 0.2. Suppose that 0 is irreducible and satisfies either (I) or
(II) above. Suppose also that 0 is modular and that
q

p1
(i) 0 is absolutely irreducible when restricted to Q
(1) 2 p .

(ii) If q 1 mod p is ramified in 0 then either 0 |Dq is reducible over


the algebraic closure where Dq is a decomposition group at q or 0 |Iq is
absolutely irreducible where Iq is an inertia group at q.

Then any representation as in the conjecture does indeed come from a modular form.
The only condition which really seems essential to our method is the requirement that 0 be modular.
The most interesting case at the moment is when p = 3 and 0 can be defined over F3 . Then since PGL2 (F3 ) ' S4 every such representation is modular
by the theorem of Langlands and Tunnell mentioned above. In particular, every representation into GL2 (Z3 ) whose reduction satisfies the given conditions
is modular. We deduce:
Theorem 0.3. Suppose that E is an elliptic curve defined over Q and
that 0 is the Galois action on the 3-division points. Suppose that E has the
following properties:
(i) E has good or multiplicative reduction at 3.
(ii) 0 is absolutely irreducible when restricted to Q

3 .

(iii) For any q 1 mod 3 either 0 |Dq is reducible over the algebraic closure
or 0 |Iq is absolutely irreducible.
Then E should be modular.
We should point out that while the properties of the zeta function follow
directly from Theorem 0.2 the stronger version that E is covered by X 0 (N )

448

ANDREW JOHN WILES

requires also the isogeny theorem proved by Faltings (and earlier by Serre when
E has nonintegral j-invariant, a case which includes the semistable curves).
We note that if E is modular then so is any twist of E, so we could relax
condition (i) somewhat.
The important class of semistable curves, i.e., those with square-free conductor, satisfies (i) and (iii) but not necessarily (ii). If (ii) fails then in fact 0
is reducible. Rather surprisingly, Theorem 0.2 can often be applied in this case
also by showing that the representation on the 5-division points also occurs for
another elliptic curve which Theorem 0.3 has already proved modular. Thus
Theorem 0.2 is applied this time with p = 5. This argument, which is explained
in Chapter 5, is the only part of the paper which really uses deformations of
the elliptic curve rather than deformations of the Galois representation. The
argument works more generally than the semistable case but in this setting
we obtain the following theorem:
Theorem 0.4. Suppose that E is a semistable elliptic curve defined over
Q. Then E is modular.
More general families of elliptic curves which are modular are given in Chapter 5.
In 1986, stimulated by an ingenious idea of Frey [Fr], Serre conjectured
and Ribet proved (in [Ri1]) a property of the Galois representation associated
to modular forms which enabled Ribet to show that Theorem 0.4 implies Fermats Last Theorem. Freys suggestion, in the notation of the following theorem, was to show that the (hypothetical) elliptic curve y 2 = x(x + up )(x v p )
could not be modular. Such elliptic curves had already been studied in [He]
but without the connection with modular forms. Serre made precise the idea
of Frey by proposing a conjecture on modular forms which meant that the representation on the p-division points of this particular elliptic curve, if modular,
would be associated to a form of conductor 2. This, by a simple inspection,
could not exist. Serres conjecture was then proved by Ribet in the summer
of 1986. However, one still needed to know that the curve in question would
have to be modular, and this is accomplished by Theorem 0.4. We have then
(finally!):
Theorem 0.5. Suppose that up + v p + wp = 0 with u, v, w Q and p 3,
then uvw = 0. (Equivalently - there are no nonzero integers a, b, c, n with n > 2
such that an + bn = cn .)
The second result we prove about the conjecture does not require the
assumption that 0 be modular (since it is already known in this case).

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

449

Theorem 0.6. Suppose that 0 is irreducible and satisfies the hypothesis


of the conjecture, including (I) above. Suppose further that
(i) 0 = IndQ
L 0 for a character 0 of an imaginary quadratic extension L
of Q which is unramified at p.
(ii) det 0 |Ip = .
Then a representation as in the conjecture does indeed come from a modular
form.
This theorem can also be used to prove that certain families of elliptic
curves are modular. In this summary we have only described the principal
theorems associated to Galois representations and elliptic curves. Our results
concerning generalized class groups are described in Theorem 3.3.
The following is an account of the origins of this work and of the more
specialized developments of the 1980s that affected it. I began working on
these problems in the late summer of 1986 immediately on learning of Ribets
result. For several years I had been working on the Iwasawa conjecture for
totally real fields and some applications of it. In the process, I had been using
and developing results on `-adic representations associated to Hilbert modular
forms. It was therefore natural for me to consider the problem of modularity
from the point of view of `-adic representations. I began with the assumption
that the reduction of a given ordinary `-adic representation was reducible and
tried to prove under this hypothesis that the representation itself would have
to be modular. I hoped rather naively that in this situation I could apply the
techniques of Iwasawa theory. Even more optimistically I hoped that the case
` = 2 would be tractable as this would suffice for the study of the curves used
by Frey. From now on and in the main text, we write p for ` because of the
connections with Iwasawa theory.
After several months studying the 2-adic representation, I made the first
real breakthrough in realizing that I could use the 3-adic representation instead:
the Langlands-Tunnell theorem meant that 3 , the mod 3 representation of any
given elliptic curve over Q, would necessarily be modular. This enabled me
to try inductively to prove that the GL2 (Z/3n Z) representation would be
modular for each n. At this time I considered only the ordinary case. This led
quickly to the study of H i (Gal(F /Q), Wf ) for i = 1 and 2, where F is the
splitting field of the m-adic torsion on the Jacobian of a suitable modular curve,
m being the maximal ideal of a Hecke ring associated to 3 and Wf the module
associated to a modular form f described in Chapter 1. More specifically, I
needed to compare this cohomology with the cohomology of Gal(Q /Q) acting
on the same module.
I tried to apply some ideas from Iwasawa theory to this problem. In my
solution to the Iwasawa conjecture for totally real fields [Wi4], I had introduced

450

ANDREW JOHN WILES

a new technique in order to deal with the trivial zeroes. It involved replacing
the standard Iwasawa theory method of considering the fields in the cyclotomic
Zp -extension by a similar analysis based on a choice of infinitely many distinct
primes qi 1 mod pni with ni as i . Some aspects of this method
suggested that an alternative to the standard technique of Iwasawa theory,
which seemed problematic in the study of Wf , might be to make a comparison
between the cohomology groups as varies but with the field Q fixed. The
new principle said roughly that the unramified cohomology classes are trapped
by the tamely ramified ones. After reading the paper [Gre1]. I realized that the
duality theorems in Galois cohomology of Poitou and Tate would be useful for
this. The crucial extract from this latter theory is in Section 2 of Chapter 1.
In order to put ideas into practice I developed in a naive form the
techniques of the first two sections of Chapter 2. This drew in particular on
a detailed study of all the congruences between f and other modular forms
of differing levels, a theory that had been initiated by Hida and Ribet. The
outcome was that I could estimate the first cohomology group well under two
assumptions, first that a certain subgroup of the second cohomology group
vanished and second that the form f was chosen at the minimal level for m.
These assumptions were much too restrictive to be really effective but at least
they pointed in the right direction. Some of these arguments are to be found
in the second section of Chapter 1 and some form the first weak approximation
to the argument in Chapter 3. At that time, however, I used auxiliary primes
q 1 mod p when varying as the geometric techniques I worked with did
not apply in general for primes q 1 mod p. (This was for much the same
reason that the reduction of level argument in [Ri1] is much more difficult
when q 1 mod p.) In all this work I used the more general assumption that
p was modular rather than the assumption that p = 3.
In the late 1980s, I translated these ideas into ring-theoretic language. A
few years previously Hida had constructed some explicit one-parameter families of Galois representations. In an attempt to understand this, Mazur had
been developing the language of deformations of Galois representations. Moreover, Mazur realized that the universal deformation rings he found should be
given by Hecke ings, at least in certain special cases. This critical conjecture
refined the expectation that all ordinary liftings of modular representations
should be modular. In making the translation to this ring-theoretic language
I realized that the vanishing assumption on the subgroup of H 2 which I had
needed should be replaced by the stronger condition that the Hecke rings were
complete intersections. This fitted well with their being deformation rings
where one could estimate the number of generators and relations and so made
the original assumption more plausible.
To be of use, the deformation theory required some development. Apart
from some special examples examined by Boston and Mazur there had been

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

451

little work on it. I checked that one could make the appropriate adjustments to
the theory in order to describe deformation theories at the minimal level. In the
fall of 1989, I set Ramakrishna, then a student of mine at Princeton, the task
of proving the existence of a deformation theory associated to representations
arising from finite flat group schemes over Zp . This was needed in order to
remove the restriction to the ordinary case. These developments are described
in the first section of Chapter 1 although the work of Ramakrishna was not
completed until the fall of 1991. For a long time the ring-theoretic version
of the problem, although more natural, did not look any simpler. The usual
methods of Iwasawa theory when translated into the ring-theoretic language
seemed to require unknown principles of base change. One needed to know the
exact relations between the Hecke rings for different fields in the cyclotomic
Zp -extension of Q, and not just the relations up to torsion.
The turning point in this and indeed in the whole proof came in the
spring of 1991. In searching for a clue from commutative algebra I had been
particularly struck some years earlier by a paper of Kunz [Ku2]. I had already
needed to verify that the Hecke rings were Gorenstein in order to compute the
congruences developed in Chapter 2. This property had first been proved by
Mazur in the case of prime level and his argument had already been extended
by other authors as the need arose. Kunzs paper suggested the use of an
invariant (the -invariant of the appendix) which I saw could be used to test
for isomorphisms between Gorenstein rings. A different invariant (the p/p 2 invariant of the appendix) I had already observed could be used to test for
isomorphisms between complete intersections. It was only on reading Section 6
of [Ti2] that I learned that it followed from Tates account of Grothendieck
duality theory for complete intersections that these two invariants were equal
for such rings. Not long afterwards I realized that, unlike though it seemed at
first, the equality of these invariants was actually a criterion for a Gorenstein
ring to be a complete intersection. These arguments are given in the appendix.
The impact of this result on the main problem was enormous. Firstly, the
relationship between the Hecke rings and the deformation rings could be tested
just using these two invariants. In particular I could provide the inductive argument of section 3 of Chapter 2 to show that if all liftings with restricted
ramification are modular then all liftings are modular. This I had been trying
to do for a long time but without success until the breakthrough in commutative algebra. Secondly, by means of a calculation of Hida summarized in [Hi2]
the main problem could be transformed into a problem about class numbers
of a type well-known in Iwasawa theory. In particular, I could check this in
the ordinary CM case using the recent theorems of Rubin and Kolyvagin. This
is the content of Chapter 4. Thirdly, it meant that for the first time it could
be verified that infinitely many j-invariants were modular. Finally, it meant
that I could focus on the minimal level where the estimates given by me earlier

452

ANDREW JOHN WILES

Galois cohomology calculations looked more promising. Here I was also using
the work of Ribet and others on Serres conjecture (the same work of Ribet
that had linked Fermats Last Theorem to modular forms in the first place) to
know that there was a minimal level.
The class number problem was of a type well-known in Iwasawa theory
and in the ordinary case had already been conjectured by Coates and Schmidt.
However, the traditional methods of Iwasawa theory did not seem quite sufficient in this case and, as explained earlier, when translated into the ringtheoretic language seemed to require unknown principles of base change. So
instead I developed further the idea of using auxiliary primes to replace the
change of field that is used in Iwasawa theory. The Galois cohomology estimates described in Chapter 3 were now much stronger, although at that time
I was still using primes q 1 mod p for the argument. The main difficulty
was that although I knew how the -invariant changed as one passed to an
auxiliary level from the results of Chapter 2, I did not know how to estimate
the change in the p/p2 -invariant precisely. However, the method did give the
right bound for the generalised class group, or Selmer group as it often called
in this context, under the additional assumption that the minimal Hecke ring
was a complete intersection.
I had earlier realized that ideally what I needed in this method of auxiliary
primes was a replacement for the power series ring construction one obtains in
the more natural approach based on Iwasawa theory. In this more usual setting,
the projective limit of the Hecke rings for the varying fields in a cyclotomic
tower would be expected to be a power series ring, at least if one assumed
the vanishing of the -invariant. However, in the setting with auxiliary primes
where one would change the level but not the field, the natural limiting process
did not appear to be helpful, with the exception of the closely related and very
important construction of Hida [Hi1]. This method of Hida often gave one step
towards a power series ring in the ordinary case. There were also tenuous hints
of a patching argument in Iwasawa theory ([Scho], [Wi4, 10]), but I searched
without success for the key.
Then, in August, 1991, I learned of a new construction of Flach [Fl] and
quickly became convinced that an extension of his method was more plausible. Flachs approach seemed to be the first step towards the construction of
an Euler system, an approach which would give the precise upper bound for
the size of the Selmer group if it could be completed. By the fall of 1992, I
believed I had achieved this and begun then to consider the remaining case
where the mod 3 representation was assumed reducible. For several months I
tried simply to repeat the methods using deformation rings and Hecke rings.
Then unexpectedly in May 1993, on reading of a construction of twisted forms
of modular curves in a paper of Mazur [Ma3], I made a crucial and surprising
breakthrough: I found the argument using families of elliptic curves with a

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

453

common 5 which is given in Chapter 5. Believing now that the proof was
complete, I sketched the whole theory in three lectures in Cambridge, England
on June 21-23. However, it became clear to me in the fall of 1993 that the construction of the Euler system used to extend Flachs method was incomplete
and possibly flawed.
Chapter 3 follows the original approach I had taken to the problem of
bounding the Selmer group but had abandoned on learning of Flachs paper.
Darmon encouraged me in February, 1994, to explain the reduction to the complete intersection property, as it gave a quick way to exhibit infinite families
of modular j-invariants. In presenting it in a lecture at Princeton, I made,
almost unconsciously, critical switch to the special primes used in Chapter 3
as auxiliary primes. I had only observed the existence and importance of these
primes in the fall of 1992 while trying to extend Flachs work. Previously, I had
only used primes q 1 mod p as auxiliary primes. In hindsight this change
was crucial because of a development due to de Shalit. As explained before, I
had realized earlier that Hidas theory often provided one step towards a power
series ring at least in the ordinary case. At the Cambridge conference de Shalit
had explained to me that for primes q 1 mod p he had obtained a version of
Hidas results. But excerpt for explaining the complete intersection argument
in the lecture at Princeton, I still did not give any thought to my initial approach, which I had put aside since the summer of 1991, since I continued to
believe that the Euler system approach was the correct one.
Meanwhile in January, 1994, R. Taylor had joined me in the attempt to
repair the Euler system argument. Then in the spring of 1994, frustrated in
the efforts to repair the Euler system argument, I begun to work with Taylor
on an attempt to devise a new argument using p = 2. The attempt to use p = 2
reached an impasse at the end of August. As Taylor was still not convinced that
the Euler system argument was irreparable, I decided in September to take one
last look at my attempt to generalise Flach, if only to formulate more precisely
the obstruction. In doing this I came suddenly to a marvelous revelation: I
saw in a flash on September 19th, 1994, that de Shalits theory, if generalised,
could be used together with duality to glue the Hecke rings at suitable auxiliary
levels into a power series ring. I had unexpectedly found the missing key to my
old abandoned approach. It was the old idea of picking qi s with qi 1mod pni
and ni as i that I used to achieve the limiting process. The switch
to the special primes of Chapter 3 had made all this possible.
After I communicated the argument to Taylor, we spent the next few days
making sure of the details. the full argument, together with the deduction of
the complete intersection property, is given in [TW].
In conclusion the key breakthrough in the proof had been the realization
in the spring of 1991 that the two invariants introduced in the appendix could
be used to relate the deformation rings and the Hecke rings. In effect the -

454

ANDREW JOHN WILES

invariant could be used to count Galois representations. The last step after the
June, 1993, announcement, though elusive, was but the conclusion of a long
process whose purpose was to replace, in the ring-theoretic setting, the methods
based on Iwasawa theory by methods based on the use of auxiliary primes.
One improvement that I have not included but which might be used to
simplify some of Chapter 2 is the observation of Lenstra that the criterion for
Gorenstein rings to be complete intersections can be extended to more general
rings which are finite and free as Zp -modules. Faltings has pointed out an
improvement, also not included, which simplifies the argument in Chapter 3
and [TW]. This is however explained in the appendix to [TW].
It is a pleasure to thank those who read carefully a first draft of some of this
paper after the Cambridge conference and particularly N. Katz who patiently
answered many questions in the course of my work on Euler systems, and
together with Illusie read critically the Euler system argument. Their questions
led to my discovery of the problem with it. Katz also listened critically to my
first attempts to correct it in the fall of 1993. I am grateful also to Taylor for
his assistance in analyzing in depth the Euler system argument. I am indebted
to F. Diamond for his generous assistance in the preparation of the final version
of this paper. In addition to his many valuable suggestions, several others also
made helpful comments and suggestions especially Conrad, de Shalit, Faltings,
Ribet, Rubin, Skinner and Taylor.I am most grateful to H. Darmon for his
encouragement to reconsider my old argument. Although I paid no heed to his
advice at the time, it surely left its mark.
Table of Contents

Chapter 1 1. Deformations of Galois representations


2. Some computations of cohomology groups
3. Some results on subgroups of GL2 (k)
Chapter 2 1. The Gorenstein property
2. Congruences between Hecke rings
3. The main conjectures
Chapter 3

Estimates for the Selmer group

Chapter 4 1. The ordinary CM case


2. Calculation of
Chapter 5
Appendix
References

Application to elliptic curves

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

455

Chapter 1

This chapter is devoted to the study of certain Galois representations.


In the first section we introduce and study Mazurs deformation theory and
discuss various refinements of it. These refinements will be needed later to
make precise the correspondence between the universal deformation rings and
the Hecke rings in Chapter 2. The main results needed are Proposition 1.2
which is used to interpret various generalized cotangent spaces as Selmer groups
and (1.7) which later will be used to study them. At the end of the section we
relate these Selmer groups to ones used in the Bloch-Kato conjecture, but this
connection is not needed for the proofs of our main results.
In the second section we extract from the results of Poitou and Tate on
Galois cohomology certain general relations between Selmer groups as varies,
as well as between Selmer groups and their duals. The most important observation of the third section is Lemma 1.10(i) which guarantees the existence of
the special primes used in Chapter 3 and [TW].
1. Deformations of Galois representations

Let p be an odd prime. Let be a finite set of primes including p and


let Q be the maximal extension of Q unramified outside this set and .
Throughout we fix an embedding of Q, and so also of Q , in C. We will also
fix a choice of decomposition group Dq for all primes q in Z. Suppose that k
is a finite field characteristic p and that

(1.1)

0 : Gal(Q /Q) GL2 (k)

is an irreducible representation. In contrast to the introduction we will assume


in the rest of the paper that 0 comes with its field of definition k. Suppose
further that det 0 is odd. In particular this implies that the smallest field of
definition for 0 is given by the field k0 generated by the traces but we will not
assume that k = k0 . It also implies that 0 is absolutely irreducible. We consider the deformation [] to GL2 (A) of 0 in the sense of Mazur [Ma1]. Thus
if W (k) is the ring of Witt vectors of k, A is to be a complete Noeterian local
W (k)-algebra with residue field k and maximal ideal m, and a deformation []
is just a strict equivalence class of homomorphisms : Gal(Q /Q) GL2 (A)
such that mod m = 0 , two such homomorphisms being called strictly equivalent if one can be brought to the other by conjugation by an element of
ker : GL2 (A) GL2 (k). We often simply write instead of [] for the
equivalent class.

456

ANDREW JOHN WILES

We will restrict our choice of 0 further by assuming that either:


(i) 0 is ordinary; viz., the restriction of 0 to the decomposition group Dp
has (for a suitable choice of basis) the form
0 | Dp

(1.2)

1
0

where 1 and 2 are homomorphisms from Dp to k with 2 unramified.


Moreover we require that 1 6= 2 . We do allow here that 0 |Dp be
semisimple. (If 1 and 2 are both unramified and 0 |Dp is semisimple
then we fix our choices of 1 and 2 once and for all.)
(ii) 0 is flat at p but not ordinary (cf. [Se1] where the terminology finite is
used); viz., 0 |Dp is the representation associated to a finite flat group
scheme over Zp but is not ordinary in the sense of (i). (In general when we
refer to the flat case we will mean that 0 is assumed not to be ordinary
unless we specify otherwise.) We will assume also that det 0 |Ip =
where Ip is an inertia group at p and is the Teichm
uller character
giving the action on pth roots of unity.
In case (ii) it follows from results of Raynaud that 0 |Dp is absolutely
irreducible and one can describe 0 |Ip explicitly. For extending a Jordan-Holder
series for the representation space (as an Ip -module) to one for finite flat group
schemes (cf. [Ray 1]) we observe first that the trivial character does not occur on
a subquotient, as otherwise (using the classification of Oort-Tate or Raynaud)
the group scheme would be ordinary. So we find by Raynauds results, that
0 |Ip k ' 1 2 where 1 and 2 are the two fundamental characters of
k

degree 2 (cf. Corollary 3.4.4 of [Ray1]). Since 1 and 2 do not extend to


p /Qp ), 0 |D must be absolutely irreducible.
characters of Gal(Q
p
We sometimes wish to make one of the following restrictions on the
deformations we allow:
(i) (a) Selmer deformations. In this case we assume that 0 is ordinary, with notion as above, and that the deformation has a representative
: Gal(Q /Q) GL2 (A) with the property that (for a suitable choice
of basis)

1
|Dp
0
2
with
2 unramified,
2 mod m, and det |Ip = 1 1 2 where
is the cyclotomic character, : Gal(Q /Q) Zp , giving the action
on all p-power roots of unity, is of order prime to p satisfying
mod p, and 1 and 2 are the characters of (i) viewed as taking values in
k , A .

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

457

(i) (b) Ordinary deformations. The same as in (i)(a) but with no condition on
the determinant.
(i) (c) Strict deformations. This is a variant on (i) (a) which we only use when
0 |Dp is not semisimple and not flat (i.e. not associated to a finite flat
group scheme). We also assume that 1 1
= in this case. Then a
2
strict deformation is as in (i)(a) except that we assume in addition that
(
1 /
2 )|Dp = .
(ii) Flat (at p) deformations. We assume that each deformation to GL2 (A)
has the property that for any quotient A/a of finite order |Dp mod a
p -points of a finite flat
is the Galois representation associated to the Q
group scheme over Zp .
In each of these four cases, as well as in the unrestricted case (in which we
impose no local restriction at p) one can verify that Mazurs use of Schlessingers
criteria [Sch] proves the existence of a universal deformation
: Gal(Q /Q) GL2 (R).
In the ordinary and restricted case this was proved by Mazur and in the
flat case by Ramakrishna [Ram]. The other cases require minor modifications
of Mazurs argument. We denote the universal ring R in the unrestricted
se
ord
str
f
case and R
, R
, R
, R
in the other four cases. We often omit the if the
context makes it clear.
There are certain generalizations to all of the above which we will also
need. The first is that instead of considering W (k)-algebras A we may consider
O-algebras for O the ring of integers of any local field with residue field k. If
we need to record which O we are using we will write R,O etc. It is easy to
see that the natural local map of local O-algebras
R,O R O
W (k)

is an isomorphism because for functorial reasons the map has a natural section
which induces an isomorphism on Zariski tangent spaces at closed points, and
one can then use Nakayamas lemma. Note, however, hat if we change the
residue field via i :, k 0 then we have a new deformation problem associated
to the representation 00 = i 0 . There is again a natural map of W (k 0 )algebras
R(00 ) R W (k 0 )
W (k)

which is an isomorphism on Zariski tangent spaces. One can check that this
is again an isomorphism by considering the subring R1 of R(00 ) defined as the
subring of all elements whose reduction modulo the maximal ideal lies in k.
Since R(00 ) is a finite R1 -module, R1 is also a complete local Noetherian ring

458

ANDREW JOHN WILES

with residue field k. The universal representation associated to 00 is defined


over R1 and the universal property of R then defines a map R R1 . So we
obtain a section to the map R(00 ) R W (k 0 ) and the map is therefore
W (k)

an isomorphism. (I am grateful to Faltings for this observation.) We will also


need to extend the consideration of O-algebras tp the restricted cases. In each
case we can require A to be an O-algebra and again it is easy to see that

R,O
' R
O in each case.
W (k)

The second generalization concerns primes q 6= p which are ramified in 0 .


We distinguish three special cases (types (A) and (C) need not be disjoint):
(A) 0 |Dq = ( 1 2 ) for a suitable choice of basis, with 1 and 2 unramified,
1 1
2 = and the fixed space of Iq of dimension 1,
(B) 0 |Iq = ( 0q 01 ), q 6= 1, for a suitable choice of basis,
(C) H 1 (Qq , W ) = 0 where W is as defined in (1.6).
Then in each case we can define a suitable deformation theory by imposing
additional restrictions on those we have already considered, namely:
(A) |Dq = ( 1 2 ) for a suitable choice of basis of A2 with 1 and 2 unramified and 1 21 = ;
(B) |Iq = ( 0q 01 ) for a suitable choice of basis (q of order prime to p, so the
same character as above);
(C) det |Iq = det 0 |Iq , i.e., of order prime to p.
Thus if M is a set of primes in distinct from p and each satisfying one of
(A), (B) or (C) for 0 , we will impose the corresponding restriction at each
prime in M.
Thus to each set of data D = {, , O, M} where is Se, str, ord, flat or
unrestricted, we can associate a deformation theory to 0 provided
(1.3)

0 : Gal(Q /Q) GL2 (k)

is itself of type D and O is the ring of integers of a totally ramified extension


of W (k); 0 is ordinary if is Se or ord, strict if is strict and flat if is fl
(meaning flat); 0 is of type M, i.e., of type (A), (B) or (C) at each ramified
primes q 6= p, q M. We allow different types at different qs. We will refer
to these as the standard deformation theories and write RD for the universal
ring associated to D and D for the universal deformation (or even if D is
clear from the context).
We note here that if D = (ord, , O, M) and D 0 = (Se, , O, M) then
there is a simple relation between RD and RD0 . Indeed there is a natural map

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

459

RD RD0 by the universal property of RD , and its kernel is a principal ideal


generated by T = 1 () det D () 1 where Gal(Q /Q) is any element
whose restriction to Gal(Q /Q) is a generator (where Q is the Zp -extension
of Q) and whose restriction to Gal(Q(Np )/Q) is trivial for any N prime to p
with N Q , N being a primitive N th root of 1:
0
RD /T ' RD
.

(1.4)

It turns out that under the hypothesis that 0 is strict, i.e. that 0 |Dp
is not associated to a finite flat group scheme, the deformation problems in
(i)(a) and (i)(c) are the same; i.e., every Selmer deformation is already a strict
deformation. This was observed by Diamond. the argument is local, so the
p /Q).
decomposition group Dp could be replaced by Gal(Q
Proposition 1.1 (Diamond). Suppose that : Dp GL2 (A) is a continuous representation where A is an Artinian local ring with residue field k, a
finite field of characteristic p. Suppose ( 01 2 ) with 1 and 2 unramified
and 1 6= 2 . Then the residual representation
is associated to a finite flat
group scheme over Zp .
Proof (taken from [Dia, Prop. 6.1]). We may replace by 1
and
2
t
1

we let = 1 2 . Then = ( 0 1 ) determines a cocycle t : Dp M (1) where


M is a free A-module of rank one on which Dp acts via . Let u denote the
cohomology class in H 1 (Dp , M (1)) defined by t, and let u0 denote its image
in H 1 (Dp , M0 (1)) where M0 = M/mM. Let G = ker and let F be the fixed
field of G (so F is a finite unramified extension of Qp ). Choose n so that pn A
= 0. Since H 2 (G, pr H 2 (G, ps ) is injective for r s, we see that the
natural map of A[Dp /G]-modules H 1 (G, pn Zp M ) H 1 (G, M (1)) is an
n
isomorphism. By Kummer theory, we have H 1 (G, M (1))
= F /(F )p Zp M
as Dp -modules. Now consider the commutative diagram

Dp

p
Dp
Dp
H 1 (G, M
(1)) ((F /(F ) Zp M ) M

,
y
y
y

H 1 (G, M0 (1)) (F /(F )p ) Fp M0 M0

where the right-hand horizontal maps are induced by vp : F Z. If 6= 1,


then M Dp mM, so that the element res u0 of H 1 (G, M0 (1)) is in the image
of (OF /(OF )p ) Fp M0 . But this means that
is peu ramifie in the sense of
[Se] and therefore
comes from a finite flat group scheme. (See [E1, (8.20].)
Remark. Diamond also observes that essentially the same proof shows
q /Qq ) GL2 (A), where A is a complete local Noetherian
that if : Gal(Q

460

ANDREW JOHN WILES

ring with residue field k, has the form |Iq


ramified then is
= ( 10 1 ) with
of type (A).
Globally, Proposition 1.1 says that if 0 is strict and if D = (Se, , O, M)
and D 0 = (str, , O, M) then the natural map RD RD0 is an isomorphism.
In each case the tangent space of RD may be computed as in [Ma1]. Let
be a uniformizer for O and let U ' k 2 be the representation space for 0 .
(The motivation for the subscript will become apparent later.) Let V be the
representation space of Gal(Q /Q) on Ad0 = Homk (U , U ) ' M2 (k). Then
there is an isomorphism of k-vector spaces (cf. the proof of Prop. 1.2 below)
(1.5)

1
Homk (mD /(m2D , ), k) ' HD
(Q /Q, V )

1
where HD
(Q /Q, V ) is a subspace of H 1 (Q /Q, V ) which we now describe
and mD is the maximal ideal of RC alD. It consists of the cohomology classes
which satisfy certain local restrictions at p and at the primes in M. We call
mD /(m2D , ) the reduced cotangent space of RD .
We begin with p. First we may write (since p 6= 2), as k[Gal(Q /Q)]modules,

(1.6)

V = W k, where W = {f Homk (U , U ) : tracef = 0}


' (Sym2 det1 )0

and k is the one-dimensional subspace of scalar multiplications. Then if 0


is ordinary the action of Dp on U induces a filtration of U and also on W
and V . Suppose we write these 0 U0 U , 0 W0 W1 W and
0 V0 V1 V . Thus U0 is defined by the requirement that Dp act on it
via the character 1 (cf. (1.2)) and on U /U0 via 2 . For W the filtrations
are defined by
W1 = {f W : f (U0 ) U0 },
W0

{f W1 : f = 0 on U0 },

and the filtrations for V are obtained by replacing W by V . We note that


these filtrations are often characterized by the action of Dp . Thus the action
of Dp on W0 is via 1 /2 ; on W1 /W0 it is trivial and on Q /W1 it is via
2 /1 . These determine the filtration if either 1 /2 is not quadratic or 0 |Dp
is not semisimple. We define the k-vector spaces
Vord = {f V1 : f = 0 in Hom(U /U0 , U /U0 )},

1
0
HSe
(Qp , V ) = ker{H 1 (Qp , V ) H 1 (Qunr
p , V /W )},

1
ord
Hord
(Qp , V ) = ker{H 1 (Qp , V ) H 1 (Qunr
p , V /V )},

1
Hstr
(Qp , V ) = ker{H 1 (Qp , V ) H 1 (Qp , W /W0 ) H 1 (Qunr
p , k)}.

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

461

1
In the Selmer case we make an analogous definition for HSe
(Qp , W ) by
replacing V by W , and similarly in the strict case. In the flat case we use
the fact that there is a natural isomorphism of k-vector spaces

H 1 (Qp , V ) Ext1k[Dp ] (U , U )
where the extensions are computed in the category of k-vector spaces with local
Galois action. Then Hf1 (Qp , V ) is defined as the k-subspace of H 1 (Qp , V )
which is the inverse image of Ext1fl (G, G), the group of extensions in the category of finite flat commutative group schemes over Zp killed by p, G being the
(unique) finite flat group scheme over Zp associated to U . By [Ray1] all such
extensions in the inverse image even correspond to k-vector space schemes. For
more details and calculations see [Ram].
For q different from p and q M we have three cases (A), (B), (C). In
case (A) there is a filtration by Dq entirely analogous to the one for p. We
write this 0 W0,q W1,q W and we set

ker : H 1 (Qq , V

H 1 (Qq , W /W0,q ) H 1 (Qunr

q , k) in case (A)

1
HD
(Qq , V ) =
q

ker : H 1 (Qq , V )

H 1 (Qunr
in case (B) or (C).
q , V )
1
Again we make an analogous definition for HD
(Qq , W ) by replacing V
q
by W and deleting the last term in case (A). We now define the k-vector
1
space HD
(Q /Q, V ) as
1
1
HD
(Q /Q, V ) = { H 1 (Q /Q, V ) : q HD
(Qq , V ) for all q M,
q

q H1 (Qp , V )}

where is Se, str, ord, fl or unrestricted according to the type of D. A similar


1
definition applies to HD
(Q /Q, W ) if is Selmer or strict.
Now and for the rest of the section we are going to assume that 0 arises
from the reduction of the -adic representation associated to an eigenform.
More precisely we assume that there is a normalized eigenform f of weight 2
and level N , divisible only by the primes in , and that there ia a prime
of Of such that 0 = f, mod . Here Of is the ring of integers of the field
generated by the Fourier coefficients of f so the fields of definition of the two
representations need not be the same. However we assume that k Of, /
and we fix such an embedding so the comparison can be made over k. It will
be convenient moreover to assume that if we are considering 0 as being of
type D then D is defined using O-algebras where O Of, is an unramified
extension whose residue field is k. (Although this condition is unnecessary, it
is convenient to use as the uniformizer for O.) Finally we assume that f,

462

ANDREW JOHN WILES

itself is of type D. Again this is a slight abuse of terminology as we are really


considering the extension of scalars f, O and not f, itself, but we will
Of,

do this without further mention if the context makes it clear. (The analysis of
this section actually applies to any characteristic zero lifting of 0 but in all
our applications we will be in the more restrictive context we have described
here.)
With these hypotheses there is a unique local homomorphism RD O
of O-algebras which takes the universal deformation to (the class of) f, . Let
pD = ker : RD O. Let K be the field of fractions of O and let Uf = (K/O)2
with the Galois action taken from f, . Similarly, let Vf = Adf, O K/O '
(K/O)4 with the adjoint representation so that
Vf ' Wf K/O
where Wf has Galois action via Sym2 f, det 1
f, and the action on the
second factor is trivial. Then if 0 is ordinary the filtration of Uf under the
Ad action of Dp induces one on Wf which we write 0 Wf0 Wf1 Wf .
Often to simplify the notation we will drop the index f from Wf1 , Vf etc. There
n
is also a filtration on Wn = {ker n : Wf Wf } given by Wi n = W W i
(compatible with our previous description for n = 1). Likewise we write V n
for {ker n : Vf Vf }.
1
We now explain how to extend the definition of HD
to give meaning to
1
n
1
n
HD (Q /Q, V ) and HD (Q /Q, V ) and these are O/ and O-modules, respectively. In the case where 0 is ordinary the definitions are the same with
Vn or V replacing V and O/n or K/O replacing k. One checks easily that
as O-modules
(1.7)

1
1
(Q /Q, V )n ,
(Q /Q, Vn ) ' HD
HD

where as usual the subscript n denotes the kernel of multiplication by n .


This just uses the divisibility of H 0 (Q /Q, V ) and H 0 (Qp , W/W 0 ) in the
strict case. In the Selmer case one checks that for m > n the kernel of
1
unr
0
0
H 1 (Qunr
p , Vn /Wn ) H (Qp , Vm /Wm )

has only the zero element fixed under Gal(Qunr


p /Qp ) and the ord case is similar.
Checking conditions at q M is dome with similar arguments. In the Selmer
and strict cases we make analogous definitions with Wn in place of Vn and
W in place of V and the analogue of (1.7) still holds.
We now consider the case where 0 is flat (but not ordinary). We claim
first that there is a natural map of O-modules
(1.8)

H 1 (Qp , Vn ) Ext1O[Dp ] (Um , Un )

for each m n where the extensions are of O-modules with local Galois
action. To describe this suppose that H 1 (Qp , Vn ). Then we can asso p /Qp ) GL2 (On []) (where On [] =
ciate to a representation : Gal(Q

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

463

O[]/(n , 2 )) which is an O-algebra deformation of 0 (see the proof of Proposition 1.1 below). Let E = On []2 where the Galois action is via . Then there
is an exact sequence
0

E/m

E/m

(E/)/m

|o

|o

U n

U m

and hence an extension class in Ext1 (Um , Un ). One checks now that (1.8)
is a map of O-modules. We define Hf1 (Qp , Vn ) to be the inverse image of
Ext1fl (Un , Un ) under (1.8), i.e., those extensions which are already extensions
in the category of finite flat group schemes Zp . Observe that Ext1fl (Un , Un )
Ext1O[Dp ] (Un , Un ) is an O-module, so Hf1 (Qp , Vn ) is seen to be an O-submodule of H 1 (Qp , Vn ). We observe that our definition is equivalent to requiring that the classes in Hf1 (Qp , Vn ) map under (1.8) to Ext1fl (Um , Un ) for all
m n. For if em is the extension class in Ext1 (Um , Un ) then em , en Um
as Galois-modules and we can apply results of [Ray1] to see that e m comes
from a finite flat group scheme over Zp if en does.
In the flat (non-ordinary) case 0 |Ip is determined by Raynauds results as
mentioned at the beginning of the chapter. It follows in particular that, since
0 |Dp is absolutely irreducible, V (Qp = H 0 (Qp , V ) is divisible in this case
(in fact V (Qp ) ' KT /O). This H 1 (Qp , Vn ) ' H 1 (Qp , V )n and hence we can
define

[
1
Hf (Qp , V ) =
Hf1 (Qp , Vn ),
n=1

and we claim that Hf1 (Qp , V )n ' Hf1 (Qp , Vn ). To see this we have to compare
representations for m n,
p /Qp )
n,m : Gal(Q

p /Qp )
m,m : Gal(Q

GL2 (On []/m )

ym,n

GL2 (Om []/m )

where n,m and m,m are obtained from n H 1 (Qp , V Xn ) and im(n )
H 1 (Qp , Vm ) and m,n : a + b a + mn b. By [Ram, Prop 1.1 and Lemma
2.1] if n,m comes from a finite flat group scheme then so does m,m . Conversely
m,n is injective and so n,m comes from a finite flat group scheme if m,m does;
1
1
(Q /Q, V ) now extend
cf. [Ray1]. The definitions of HD
(Q /Q, Vn ) and HD
to the flat case and we note that (1.7) is also valid in the flat case.
Still in the flat (non-ordinary) case we can again use the determination
of 0 |Ip to see that H 1 (Qp , V ) is divisible. For it is enough to check that
H 2 (Qp , V ) = 0 and this follows by duality from the fact that H 0 (Qp , V ) = 0

464

ANDREW JOHN WILES

where V = Hom(V , p ) and p is the group of pth roots of unity. (Again


this follows from the explicit form of 0 |Dp .) Much subtler is the fact that
Hf1 (Qp , V ) is divisible. This result is essentially due to Ramakrishna. For,
using a local version of Proposition 1.1 below we have that
HomO (pR /p2R , K/O) ' Hf1 (Qp , V )
where R is the universal local flat deformation ring for 0 |Dp and O-algebras.
(This exists by Theorem 1.1 of [Ram] because 0 |Dp is absolutely irreducible.)
Since R ' Rfl O where Rfl is the corresponding ring for W (k)-algebras
W (k)

the main theorem of [Ram, Th. 4.2] shows that R is a power series ring and
the divisibility of Hf1 (Qp , V ) then follows. We refer to [Ram] for more details
about Rfl .
Next we need an analogue of (1.5) for V . Again this is a variant of standard
results in deformation theory and is given (at least for D = (ord, , W (k), )
with some restriction on 1 , 2 in i(a)) in [MT, Prop 25].
Proposition 1.2. Suppose that f, is a deformation of 0 of type
D = (, , O, M) with O an unramified extension of Of, . Then as O-modules
1
HomO (pD /p2D , K/O) ' HD
(Q /Q, V ).

Remark. The isomorphism is functorial in an obvious way if one changes


D to a larger D 0 .
Proof. We will just describe the Selmer case with M = as the other
cases use similar arguments. Suppose that is a cocycle which represents a
1
cohomology class in HSe
(Q /Q, Vn ). Let On [] denote the ring O[]/(n , 2 ).
We can associate to a representation
: Gal(Q /Q) GL2 (On [])
as follows: set (g) = (g)f, (g) where f, (g), a priori in GL2 (O), is viewed
in GL2 (On []) via the natural mapping O On []. Here a basis for O 2
is chosen so that the representation f, on the decomposition group Dp
Gal(Q /Q) has the upper triangular form of (i)(a), and then (g) Vn is
viewed in GL2 (On []) by identifying
Vn '

1 + y
z

x
1 t

Then
W0n

= {ker : GL2 (On []) GL2 (O)}.

1 x
1

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

W1n

W n =

V1n

and
=

1 + y

x
1 y

1 + y
z

x
1 y

1 + y

x
1 t

465

,
,

One checks readily that is a continuous homomorphism and that the deformation [ ] is unchanged if we add a coboundary to .
We need to check that [ ] is a Selmer deformation. Let H =
p /Qunr ) and G = Gal(Qunr /Qp ). Consider the exact sequence of O[G]Gal(Q
p
p
modules
0 (V1n /W0n )H (Vn /W0n )H X 0
where X is a submodule of (Vn /V1n )H . Since the action of p on Vn /V1n is
via a character which is nontrivial mod (it equals 2 1
1 mod and 1 6 2 ),
G
1
we see that X = 0 and H (G, X) = 0. Then we have an exact diagram of
O-modules
0

y
H 1 (G, (V1n /W0n )H )' H 1 (G, (Vn /W0n )H )

y
H 1 (Qp , Vn /W0n )

0 G
H 1 (Qunr
p , Vn /Wn ) .
0 G
By hypothesis the image of is zero in H 1 (Qunr
p , Vn /Wn ) . Hence it
is in the image of H 1 (G, (V1n /W0n )H ). Thus we can assume that it is represented in H 1 (Qp , Vn /W0n ) by a cocycle, which maps G to V1n /W0n ; i.e.,
f (Dp ) V1n /W0n , f (Ip ) = 0. The difference between f and the image of is
a coboundary { 7

} for some u Vn . By subtracting the coboundary


{ 7 u u} from globally we get a new such that = f as cocycles
mapping G to V1n /W0n . Thus (Dp ) V1n , (Ip ) W0n and it is now easy
to check that [ ] is a Selmer deformation of 0 .
Since [ ] is a Selmer deformation there is a unique map of local Oalgebras : RD On [] inducing it. (If M 6= we must check the

466

ANDREW JOHN WILES

other conditions also.) Since f, mod we see that restricting to pD


gives a homomorphism of O-modules,
: pD .O/n
such that (p2D ) = 0. Thus we have defined a map : ,
1
: HSe
(Q /Q, Vn ) HomO (pD /p2D , O/n ).

It is straightforward to check that this is a map of O-modules. To check the


injectivity of suppose that (pD ) = 0. Then factors through RD /pD ' O
and being an O-algebra homomorphism this determines . Thus [f, ] = [ ].
If A1 A = f, then A mod is seen to be central by Schurs lemma and so
may be taken to be I. A simple calculation now shows that is a coboundary.
To see that is surjective choose
HomO (pD /p2D , O/n ).
Then : Gal(Q /Q) GL2 (RD /(p2D , ker )) is induced by a representative
of the universal deformation (chosen to equal f, when reduced mod pD ) and
we define a map : Gal(Q /Q) Vn by
(g) = (g)f, (g)1

1 + pD /(p2D , ker )

pD /(p2D , ker )

pD /(p2D , ker )
1+

pD /(p2D , ker )

V n

where f, (g) is viewed in GL2 (RD /(p2D , ker )) via the structural map O
RD (RD being an O-algebra and the structural map being local because of
the existence of a section). The right-hand inclusion comes from
pD /(p2D , ker )

, O/n
1

(O/n )
.

Then is really seen to be a continuous cocycle whose cohomology class


1
lies in HSe
(Q /Q, Vn ). Finally ( ) = . Moreover, the constructions are
compatible with change of n, i.e., for Vn , Vn+1 and : O/n , O/n+1 .
We now relate the local cohomology groups we have defined to the theory
of Fontaine and in particular to the groups of Bloch-Kato [BK]. We will distinguish these by writing HF1 for the cohomology groups of Bloch-Kato. None
of the results described in the rest of this section are used in the rest of the
paper. They serve only to relate the Selmer groups we have defined (and later
compute) to the more standard versions. Using the lattice associated to f, we
obtain also a lattice T ' O 4 with Galois action via Ad f, . Let V = T Zp Qp
be associated vector space and identify V with V/T. Let pr : V V be

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

467

the natural projection and define cohomology modules by


HF1 (Qp , V) = ker : H 1 (Qp , V) H 1 (Qp , V Bcrys ),
Qp

HF1 (Qp , V ) = pr HF1 (Qp , V) H 1 (Qp , V ),

1
1
1
n
HF (Qp , V ) = (jn )
HF (Qp , V ) H 1 (Qp , Vn ),

where jn : Vn V is the natural map and the two groups in the definition
of HF1 (Qp , V) are defined using continuous cochains. Similar definitions apply
to V = HomQp (V, Qp (1)) and indeed to any finite-dimensional continuous
p-adic representation space. The reader is cautioned that the definition of
HF1 (Qp , Vn ) is dependent on the lattice T (or equivalently on V ). Under
certainly conditions Bloch and Kato show, using the theory of Fontaine and
Lafaille, that this is independent of the lattice (see [BK, Lemmas 4.4 and
4.5]). In any case we will consider in what follows a fixed lattice associated to
= f, , Ad , etc. Henceforth we will only use the notation HF1 (Qp , ) when
the underlying vector space is crystalline.
Proposition 1.3. (i) If 0 is flat but ordinary and f, is associated
to a p-divisible group then for all n

(ii) If f,

Hf1 (Qp , Vn ) = HF1 (Qp , Vn ).

is ordinary, det f, = and f, is associated to a p-divisible


Ip

group, then for all n,

1
HF1 (Qp , Vn ) HSe
(Qp , Vn .

Proof. Beginning with (i), we define Hf1 (Qp , V) = { H 1 (Qp , V) :


(/n ) Hf1 (Qp , V ) for all n} where : H 1 (Qp , V) H 1 (Qp , V ). Then
we see that in case (i), Hf1 (Qp , V ) is divisible. So it is enough to how that
HF1 (Qp , V) = Hf1 (Qp , V).
We have to compare two constructions associated to a nonzero element of
H 1 (Qp , V). The first is to associate an extension
(1.9)

0 V E K 0

of K-vector spaces with commuting continuous Galois action. If we fix an e


with (e) = 1 the action on e is defined by e = e + ()

with
a cocycle
representing . The second construction begins with the image of the subspace
hi in H 1 (Qp , V ). By the analogue of Proposition 1.2 in the local case, there
is an O-module isomorphism
H 1 (Qp , V ) ' HomO (pR /p2R , K/O)

468

ANDREW JOHN WILES

where R is the universal deformation ring of 0 viewed as a representation


p /Q) on O-algebras and pR is the ideal of R corresponding to pD
of Gal(Q
(i.e., its inverse image in R). Since 6= 0, associated to hi is a quotient
pR /(p2R , a) of pR /p2R which is a free O-module of rank one. We then obtain a
homomorphism

: Gal(Qp /Qp ) GL2 R/(p , a)


R

induced from the universal deformation (we pick a representation in the universal class). This is associated to an O-module of rank 4 which tensored with
K gives a K-vector space E 0 ' (K)4 which is an extension
(1.10)

0 U E0 U 0

where U ' K 2 has the Galis representation f, (viewed locally).


In the first construction HF1 (Qp , V) if and only if the extension (1.9) is
crystalline, as the extension given in (1.9) is a sum of copies of the more usual
extension where Qp replaces K in (1.9). On the other hand hi Hf1 (Qp , V) if
and only if the second construction can be made through R fl , or equivalently if
and only if E 0 is the representation associated to a p-divisible group. A priori,
the representation associated to only has the property that on all finite
quotients it comes from a finite flat group scheme. However a theorem of
Raynaud [Ray1] says that then comes from a p-divisible group. For more
details on Rfl , the universal flat deformation ring of the local representation
0 , see [Ram].) Now the extension E 0 comes from a p-divisible group if and
only if it is crystalline; cf. [Fo, 6]. So we have to show that (1.9) is crystalline
if and only if (1.10) is crystalline.
One obtains (1.10) from (1.9) as follows. We view V as HomK (U, U) and
let
X = ker : {HomK (U, U) U U}
where the map is the natural one f w 7 f (w). (All tensor products in this
proof will be as K-vector spaces.) Then as K[Dp ]-modules
E 0 ' (E U)/X.
To check this, one calculates explicitly with the definition of the action on E
(given above on e) and on E 0 (given in the proof of Proposition 1.1). It follows
from standard properties of crystalline representations that if E is crystalline,
so is E U and also E 0 . Conversely, we can recover E from E 0 as follows.
Consider E 0 U ' (E U U)/(X U). Then there is a natural map
: E (det) E 0 U induced by the direct sum decomposition U U '
(det) Sym2 U. Here det denotes a 1-dimensional vector space over K with
Galois action via det f, . Now we claim that is injective on V (det). For

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

469

if f V then (f ) = f (w1 w2 w2 w1 ) where w1 , w2 are a basis for U


for which w1 w2 = 1 in det ' K. So if (f ) X U then
f (w1 ) w2 f (w2 ) w1 = 0 in U U.
But this is false unless f (w1 ) = f (w2 ) = 0 whence f = 0. So is injective
on V det and if itself were not injective then E would split contradicting
6= 0. So is injective and we have exhibited E (det) as a subrepresentation
of E 0 U which is crystalline. We deduce that E is crystalline if E 0 is. This
completes the proof of (i).

1
1
To prove (ii) we check first that HSe
(Qp , Vn ) = jn1 HSe
(Qp , V ) (this

1
was already used in (1.7)). We next have to show that HF1 (Qp ,V) HSe
(Qp ,V)
where the latter is defined by
0
1
(Qp , V) = ker : H 1 (Qp , V) H 1 (Qunr
HSe
p , V/V )

with V 0 the subspace of V on which Ip acts via . But this follows from the
computations in Corollary 3.8.4 of [BK]. Finally we observe that

1
1
pr HSe
(Qp , V) HSe
(Qp , V )
although the inclusion may be strict, and

pr HF1 (Qp , V) = HF1 (Qp , V )


by definition. This completes the proof.

These groups have the property that for s r,

1
(1.11)
H 1 (Qp , Vr ) jr,s
HF1 (Qp , Vs ) = HF1 (Qp , Vr )

where jr,s : Vr Vs is the natural injection. The same holds for Vr and
Vs in place of Vr and Vs where Vr is defined by
Vr = Hom(Vr , pr )
and similarly for Vs . Both results are immediate from the definition (and
indeed were part of the motivation for the definition).
We also give a finite level version of a result of Bloch-Kato which is easily
deduced from the vector space version. As before let T V be a Galois stable
lattice so that T ' O 4 . Define

1
1
1
HF (Qp , T ) = i
HF (Qp , V)

under the natural inclusion i : T , V, and likewise for the dual lattice T =
HomZp (V, (Qp /Zp )(1)) in V . (Here V = Hom(V, Qp (1)); throughout this
paper we use M to denote a dual of M with a Cartier twist.) Also write

470

ANDREW JOHN WILES

prn : T T /n for the natural projection map, and for the mapping it
induces on cohomology.
Proposition 1.4. If f, is associated to a p-divisible group (the ordinary case is allowed) then

(i) prn HF1 (Qp , T ) = HF1 (Qp , T /n ) and similarly for T , T /n .

(ii) HF1 (Qp , Vn ) is the orthogonal complement of HF1 (Qp , Vn ) under Tate
local duality between H 1 (Qp , Vn ) and H 1 (Qp , Vn ) and similarly for Wn
and Wn replacing Vn and Vn .

More generally these results hold for any crystalline representation V 0 in


place of V and 0 a uniformizer in K 0 where K 0 is any finite extension of Qp
with K 0 EndGal(Qp /Qp ) V 0 .
Proof. We first observe that prn (HF1 (Qp , T )) HF1 (Qp , T /n ). Now
from the construction we may identify T /n with Vn . A result of BlochKato ([BK, Prop. 3.8]) says that HF1 (Qp , V) and HF1 (Qp , V ) are orthogonal
complements under Tate local duality. It follows formally that H F1 (Qp , Vn )
and prn (HF1 (Qp , T )) are orthogonal complements, so to prove the proposition
it is enough to show that
#HF1 (Qp , Vn )#HF1 (Qp , Vn ) = #H 1 (Qp , Vn ).

(1.12)

Now if r = dimK HF1 (Qp , V) and s = dimK HF1 (Qp , V ) then


(1.13)

r + s = dimK H 0 (Qp , V) + dimK H 0 (Qp , V ) + dimK V.

From the definition,


(1.14)

#HF1 (Qp , Vn ) = #(O/n )r # ker{H 1 (Qp , Vn ) H 1 (Qp , V )}.

The second factor is equal to #{V (Qp )/n V (Qp )}. When we write V (Qp )div
for the maximal divisible subgroup of V (Qp ) this is the same as
#(V (Qp )/V (Qp )div )/n = #(V (Qp )/V (Qp )div )n
= #V (Qp )n /#(V (Qp )div )n .
Combining this with (1.14) gives
(1.15)

#HF1 (Qp , Vn ) = #(O/n )r


#H 0 (Qp , Vn )/#(O/n )dimK H

(Qp ,V)

This, together with an analogous formula for #HF1 (Qp , Vn ) and (1.13), gives
n

#HF1 (Qp , V )#HF1 (Qp , Vn ) = #(O/n )4 #H 0 (Qp , Vn )#H 0 (Qp , Vn ).

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

471

As #H 0 (Qp , V n ) = #H 2 (Qp , Vn ) the assertion of (1.12) now follows from


the formula for the Euler characteristic of Vn .
The proof for Wn , or indeed more generally for any crystalline representation, is the same.

We also give a characterization of the orthogonal complements of


We write these

1
1
HSe
(Qp , Wn ) and HSe
(Qp , Vn ), under Tates local duality.

1
duals as HSe (Qp , Wn ) and HSe
(Qp , Vn ) respectively. Let

w : H 1 (Qp , Wn ) (Qp , Wn /(Wn )0 )


be the natural map where (Wn )i is the orthogonal complement of W1i
in
n

Wn , and let Xn,i be defined as the image under the composite map
n

p
Xn,i = im : Z
O/n H 1 (Qp , pn O/n )
p /(Zp )

H 1 (Qp , Wn /(Wn )0 )

where in the middle term pn O/n is to be identified with (Wn )1 /(Wn )0 .


pn
Similarly if we replace Wn by Vn we let Yn,i be the image of Z

p /(Zp )
0
n 2
1

(O/ ) in H (Qp , Vn /(Wn ) ), and we replace w by the analogous map v .


Proposition 1.5.

1
HSe
(Qp , Wn ) = w (Xn,i ),
1

1
HSe
(Qp , Vn ) = v (Yn,i ).

Proof. This can be checked by dualizing the sequence


1
1
0 HStr
(Qp , Wn ) HSe
(Qp , Wn )

0
ker : {H 1 (Qp , Wn /(Wn )0 ) H 1 (Qunr
p , Wn /(Wn ) },

1
where Hstr
(Qp , Wn ) = ker : H 1 (Qp , Wn ) H 1 (Qp , Wn /(Wn )0 ). The first
term is orthogonal to ker : H 1 (Qp , Wn ) H 1 (Qp , Wn /(Wn )1 ). By the
naturality of the cup product pairing with respect to quotients and subgroups
the claim then reduces to the well known fact that under the cup product
pairing
H 1 (Qp , pn ) H 1 (Qp , Z/pn ) Z/pn

the orthogonal complement of the unramified homomorphisms is the image


pn
of the units Z
H 1 (Qp , pn ). The proof for Vn is essentially the
p /(Zp )
same.

472

ANDREW JOHN WILES

2. Some computations of cohomology groups


We now make some comparisons of orders of cohomology groups using
the theorems of Poitou and Tate. We retain the notation and conventions of
Section 1 though it will be convenient to state the first two propositions in a
more general context. Suppose that
Y
Y
L=
Lq
H 1 (Qq , X)
p

is a subgroup, where X is a finite module for Gal(Q /Q) of p-power order.


We define L to be the orthogonal complement of L under the perfect pairing
(local Tate duality)
Y
Y
H 1 (Qq , X)
H 1 (Qq , X ) Qp /Zp
q

where X = Hom(X, p ). Let


X : H 1 (Q /Q, X)

H 1 (Qq , X)

be the localization map and similarly X for X . Then we set


1
1

HL1 (Q /Q, X) = 1
X (L), HL (Q /Q, X ) = X (L ).

The following result was suggested by a result of Greenberg (cf. [Gre1]) and
is a simple consequence of the theorems of Poitou and Tate. Recall that p is
always assumed odd and that p .
Proposition 1.6.
#HL1 (Q /Q, X)/#HL1 (Q /Q, X ) = h

hq

where

hq

= #H 0 (Qq , X )/[H 1 (Qq , X) : Lq ]

= #H 0 (R, X )#H 0 (Q, X)/#H 0 (Q, X ).

Proof.Adapting the exact sequence proof of Poitou and Tate(cf.[Mi2,Th.4.20])


we get a seven term exact sequence
Q 1
H (Qq , X)/Lq
0 HL1 (Q /Q, X) H 1 (Q /Q, X)
q

y
Q 2
2
1
H (Qq , X) H (Q /Q, X) HL (Q /Q, X )
q

| H 0 (Q /Q, X ) 0,

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

473

where M = Hom(M, Qp /Zp ). Now using local duality and global Euler characteristics (cf. [Mi2, Cor. 2.3 and Th. 5.1]) we easily obtain the formula in the
proposition. We repeat that in the above proposition X can be arbitrary of
p-power order.

1
We wish to apply the proposition to investigate HD
. Let D = (, , O, M)
be a standard deformation theory as in Section 1 and define a corresponding
group Ln = LD,n by setting
1
n
for q 6= p and q 6 M

H (Qq , V )
1
HDq (Qq , Vn ) for q 6= p and q M
Ln,q =

1
H. (Qp , Vn ) for q = p.
1
Then HD
(Q /Q, Vn ) = HL1 n (Q /Q, Vn ) and we also define
1

HD
(Q /Q, Vn ) = HL (Q /Q, Vn ).
n

We will adopt the convention implicit in the above that if we consider 0


1
then HD
(Q0 /Q, Vn ) places no local restriction on the cohomology classes at
1

primes q 0 . Thus in HD
(Q0 /Q, Vn ) we will require (by duality) that
the cohomology class be locally trivial at q 0 .
We need now some estimates for the local cohomology groups. First we
consider an arbitrary finite Gal(Q /Q)-module X:
Proposition 1.7. If q 6 , and X is an arbitrary finite Gal(Q /Q)module of p-power order,
#HL1 0 (Qq /Q, X)/#HL1 (Q /Q, X) #H 0 (Qq , X )
where L0` = L` for ` and L0q = H 0 (Qq , X).
Proof. Consider the short exact sequence of inflation-restriction:
0 HL1 (Q /Q, X) HL1 0 (Qq /Q, X) Hom(Gal(Qq /Q ), X)Gal(Q /Q)

y
y
unr

Gal(Qq
H 1 (Qunr
q , X)

/Qq )

unr

Gal(Qq
H 1 (Qunr
q , X)

/Qq )

The proposition follows when we note that


unr

Gal(Qq
#H 0 (Qq , X ) = #H 1 (Qunr
q , X)

/Qq )

Now we return to the study of Vn and Wn .


Proposition 1.8. If q M (q 6= p) and X = Vn then hq = 1.

474

ANDREW JOHN WILES

Proof. This is a straightforward calculation. For example if q is of type


(A) then we have
n
Ln,q = ker{H 1 (Qq , Vn ) H 1 (Qq , Wn /W0n ) H 1 (Qunr
q , O/ )}.

Using the long exact sequence of cohomology associated to


0 W0n Wn Wn /W0n 0

one obtains a formula for the order of Ln,q in terms of #H 1 (Qq , Wn ),


#H i (Qq , Wn /W0n ) etc. Using local Euler characteristics these are easily re
duced to ones involving H 0 (Qq , Wn ) etc. and the result follows easily.
The calculation of hp is more delicate. We content ourselves with an
inequality in some cases.
Proposition 1.9. (i) If X = Vn then
hp h = #(O/)3n #H 0 (Qp , Vn )/#H 0 (Q, Vn )
in the unrestricted case.
(ii) If X = Vn then

hp h #(O/)n #H 0 (Qp , (Vord


n ) )/#H (Q, Wn )

in the ordinary case.


(iii) If X = Vn or Wn then hp h #H 0 (Qp , (W0n ) )/#H 0 (Q, Wn )
in the Selmer case.
(iv) If X = Vn or Wn then hp h = 1 in the strict case.
(v) If X = Vn then hp h = 1 in the flat case.
(vi) If X = Vn or Wn then hp h = 1/#H 0 (Q, Vn ) if Ln,p =
1
HF (Qp , X) and f, arises from an ordinary p-divisible group.
Proof. Case (i) is trivial. Consider then case (ii) with X = Vn . We have
a long exact sequence of cohomology associated to the exact sequence:
(1.16)

0 W0n Vn Vn /W0n 0.

In particular this gives the map u in the diagram


H 1 (Qp , Vn )

y
&

0 H
1
0
1 unr
0 G
1 Z = H 1(Qunr
p /Qp ,(Vn/Wn) ) H (Qp ,Vn/Wn) H (Qp ,Vn/Wn) 1
unr

where G = Gal(Qunr
p /Qp ), H = Gal(Qp /Qp ) and is defined to make the
triangle commute. Then writing hi (M ) for #H 1 (Qp , M ) we have that #Z =

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

475

h0 (Vn /W0n ) and #im (#im u)/(#Z). A simple calculation using the
long exact sequence associated to (1.16) gives
(1.17)

#im u =

h1 (Vn /W0n )h2 (Vn )


.
h2 (W0n )h2 (Vn /W0n )

Hence
[H 1 (Qp , Vn ) : Ln,p ] = #im #(O/)3n h0 (Vn )/h0 (W0n ) .
The inequality in (iii) follows for X = Vn and the case X = Wn is similar.
Case (ii) is similar. In case (iv) we just need #im u which is given by (1.17)
with Wn replacing Vn . In case (v) we have already observed in Section 1 that
Raynauds results imply that #H 0 (Qp , Vn ) = 1 in the flat case. Moreover
#Hf1 (Qp , Vn ) can be computed to be #(O/)2n from
Hf1 (Qp , Vn ) ' Hf1 (Qp , V )n ' HomO (pR /p2R , K/O)n
where R is the universal local flat deformation ring of 0 for O-algebras. Using
the relation R ' Rfl O where Rfl is the corresponding ring for W (k)W (k)

algebras, and the main theorem of [Ram] (Theorem 4.2) which computes R fl ,
we can deduce the result.
We now prove (vi). From the definitions

(#O/n )r #H 0 (Qp , Wn ) if f, |Dp does not split


1
#HF (Qp , Vn ) =
(#O/n )r
if f, |Dp splits
where r = dimK HF1 (Qp , V). This we can compute using the calculations in
[BK, Cor. 3.8.4]. We find that r = 2 in the non-split case and r = 3 in the
split case and (vi) follows easily.

3. Some results on subgroups of GL2 (k)


We now give two group-theoretic results which will not be used until
Chapter 3. Although these could be phrased in purely group-theoretic terms
it will be more convenient to continue to work in the setting of Section 1, i.e.,
with 0 as in (1.1) so that im 0 is a subgroup of GL2 (k) and det 0 is assumed
odd.
Lemma 1.10. If im 0 has order divisible by p then:
(i) It contains an element 0 of order m 3 with (m, p) = 1 and 0 trivial
on any abelian quotient of im 0 .
(ii) It contains an element 0 () with any prescribed image in the Sylow
2-subgroup of (im 0 )/(im 0 )0 and with the ratio of the eigenvalues not equal
to (). (Here (im 0 )0 denotes the derived subgroup of (im 0 ).)

476

ANDREW JOHN WILES

The same results hold if the image of the projective representation 0 associated to 0 is isomorphic to A4 , S4 or A5 .
Proof. (i) Let G = im 0 and let Z denote the center of G. Then we
have a surjection G0 (G/Z)0 where the 0 denotes the derived group. By
Dicksons classification of the subgroups of GL2 (k) containing an element of
order p, (G/Z) is isomorphic to PGL2 (k 0 ) or PSL2 (k 0 ) for some finite field k 0 of
characteristic p or possibly to A5 when p = 3, cf. [Di, 260]. In each case we can
find, and then lift to G0 , an element of order m with (m, p) = 1 and m 3,
except possibly in the case p = 3 and PSL2 (F3 ) ' A4 or PGL2 (F3 ) ' S4 .
However in these cases (G/Z)0 has order divisible by 4 so the 2-Sylow subgroup
of G0 has order greater than 2. Since it has at most one element of exact order
2 (the eigenvalues would both be 1 since it is in the kernel of the determinant
and hence the element would be I) it must also have an element of order 4.
The argument in the A4 , S4 and A5 cases is similar.

(ii) Since 0 is assumed absolutely irreducible, G = im 0 has no fixed line.


We claim that the same then holds for the derived group G0 For otherwise
since G0 / G we could obtain a second fixed line by taking hgvi where hvi is the
original fixed line and g is a suitable element of G. Thus G0 would be contained
in the group of diagonal matrices for a suitable basis and it would be
central in which case G would be abelian or its normalizer in GL 2 (k), and
hence also G, would have order prime to p. Since neither of these possibilities
is allowed, G0 has no fixed line.
By Dicksons classification of the subgroups of GL2 (k) containing an element of order p the image of im 0 in PGL2 (k) is isomorphic to PGL2 (k 0 )
or PSL2 (k 0 ) for some finite field k 0 of characteristic p or possibly to A5 when
p = 3. The only one of these with a quotient group of order p is PSL 2 (F3 )
when p = 3. It follows that p - [G : G0 ] except in this one case which we treat
separately. So assuming now that p - [G : G0 ] we see that G0 contains a nontrivial unipotent element u. Since G0 has no fixed line there must be another
noncommuting unipotent element v in G0 . Pick a basis for 0 |G0 consisting
of their fixed vectors. Then let be an element of Gal(Q /Q) for which the
image of 0 ( ) in G/G0 is prescribed and let 0 ( ) = (ac db). Then

a
c

b
d

1 s
1

1
r

has det () = det 0 ( ) and trace = s(ra + c) + br + a + d. Since p 3


we can choose this trace to avoid any two given values (by varying s) unless
ra + c = 0 for all r. But ra + c cannot be zero for all r as otherwise
a = c = 0. So we can find a for which the ratio of the eigenvalues is not
( ), det() being, of course, fixed.

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

477

Now suppose that im 0 does not have order divisible by p but that the
associated projective representation f
0 has image isomorphic to S4 or A5 , so
necessarily p 6= 3. Pick an element such that the image of 0 ( ) in G/G0 is
any prescribed class. Since this fixes both det 0 ( ) and ( ) we have to show
that we can avoid at most two particular values of the trace for . To achieve
this we can adapt our first choice of by multiplying by any element og G 0 . So
pick G0 as in (i) which we can assume in these two cases has order 3. Pick
a basis for 0 , by expending scalars if necessary, so that 7 ( 1 ). Then one
checks easily that if 0 ( ) = (ac db) we cannot have the traces of all of , and
2 lying in a set of the form {t} unless a = d = 0. However we can ensure
that 0 ( ) does not satisfy this by first multiplying by a suitable element of
G0 since G0 is not contained in the diagonal matrices (it is not abelian).
In the A4 case, and in the PSL2 (F3 ) ' A4 case when p = 3, we use a
different argument. In both cases we find that the 2-Sylow subgroup of G/G 0
is generated by an element z in the centre of G. Either a power of z is a suitable
candidate for 0 () or else we must multiply the power of z by an element of
G0 , the ratio of whose eigenvalues is not equal to 1. Such an element exists
because in G0 the only possible elements without this property are {I} (such
elements necessary have determinant 1 and order prime to p) and we know
that #G0 > 2 as was noted in the proof of part (i).

Remark. By a well-known result on the finite subgroups of PGL2 (Fp ) this


lemma covers all 0 whose images are absolutely irreducible and for which f
0
is not dihedral.

Let K1 be the splitting field of 0 . Then we can view W and W as


Gal(K1 (p )/Q)-modules. We need to analyze their cohomology. Recall that
we are assuming that 0 is absolutely irreducible. Let f
0 be the associated
projective representation to PGL2 (k).
The following proposition is based on the computations in [CPS].

Proposition 1.11. Suppose that 0 is absolutely irreducible. Then


H 1 (K1 (p )/Q, W ) = 0.
Proof. If the image of 0 has order prime to p the lemma is trivial. The
subgroups of GL2 (k) containing an element of order p which are not contained
in a Borel subgroup have been classified by Dickson [Di, 260] or [Hu, II.8.27].
Their images inside PGL2 (k 0 ) where k 0 is the quadratic extension of k are
conjugate to PGL2 (F ) or PSL2 (F ) for some subfield F of k 0 , or they are
isomorphic to one of the exceptional groups A4 , S4 , A5 .
Assume then that the cohomology group H 1 (K1 (p )/Q, W ) 6= 0. Then
by considering the inflation-restriction sequence with respect to the normal

478

ANDREW JOHN WILES

subgroup Gal(K1 (p )/K1 ) we see that p K1 . Next, since the representation


is (absolutely) irreducible, the center Z of Gal(K1 /Q) is contained in the
diagonal matrices and so acts trivially on W . So by considering the inflationrestriction sequence with respect to Z we see that Z acts trivially on p (and
on W ). So Gal(Q(p )/Q) is a quotient of Gal(K1 /Q)/Z. This rules out all
cases when p 6= 3, and when p = 3 we only have to consider the case where the
image of the projective representation is isomporphic as a group to PGL 2 (F )
for some finite field of characteristic 3. (Note that S4 ' PGL2 (F3 ).)
Extending scalars commutes with formation of duals and H 1 , so we may
assume without loss of generality F k. If p = 3 and #F > 3 then
H 1 (PSL2 (F ), W ) = 0 by results of [CPS]. Then if f
0 is the projective
1
representation associated to 0 suppose that g im f
0 g = PGL2 (F ) and let
H = gPSL2 (F )g 1 . Then W ' W over H and
(1.18)

H 1 (H, W ) F ' H 1 (g 1 Hg, g 1 (W F )) = 0.


F

We deduce also that H 1 (im 0 , W ) = 0.


Finally we consider the case where F = F3 . I am grateful to Taylor for the
following argument. First we consider the action of PSL2 (F3 ) on W explicitly
by considering the conjugation action on matrices {A M2 (F3 ) : trace A = 0}.
One sees that no such matrix is fixed by all the elements of order 2, whence
H 1 (PSL2 (F3 ), W ) ' H 1 (Z/3, (W )C2 C2 ) = 0
where C2 C2 denotes the normal subgroup of order 4 in PSL2 (F3 ) ' A4 . Next
3 ) up to conjugation.
we verify that there is a unique copy of A4 in PGL2 (F
2

For suppose that A, B GL2 (F3 ) are such that A = B 2 = I with the images
3 ). We
of A, B representing distinct nontrivial commuting elements of PGL 2 (F
1 0
can choose A = (0 1) by a suitable choice of basis, i.e., by a suitable conjugation. Then B is diagonal or antidiagonal as it commutes with A up to a
1
scalar, and as B, A are distinct in PGL2 (F3 ) we have B = (a0 a0 ) for some
a. By conjugating by a diagonal matrix (which does not change A) we can
assume that a = 1. The group generated by {A, B} in PGL2 (F3 ) is its own
centralizer so it has index at most 6 in its normalizer N . Since N/hA, Bi ' S 3
there is a unique subgroup of N in which hA, Bi has index 3 whence the image
3 ) is indeed unique (up to conjugation). So
of the embedding of A4 in PGL2 (F
arguing as in (1.18) by extending scalars we see that H 1 (im 0 , W ) = 0 when
F = F3 also.

The following lemma was pointed out to me by Taylor. It permits most


dihedral cases to be covered by the methods of Chapter 3 and [TW].
Lemma 1.12. Suppose that 0 is absolutely irreducible and that
(a) 0 is dihedral (the case where the image is Z/2 Z/2 is allowed),

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

(b) 0 |L is absolutely irreducible where L = Q

479

(1)(p1)/2 p .

Then for any positive integer n and any irreducible Galois stable subspace X

of W k there exists an element Gal(Q/Q)


such that
(i) 0 () 6= 1,
(ii) fixes Q(pn ),
(iii) has an eigenvalue 1 on X.
Proof. If 0 is dihedral then 0 k = IndG
H for some H of index 2 in G,
where G = Gal(K1 /Q). (As before, K1 is the splitting field of 0 .) Here H
can be taken as the full inverse image of any of the normal subgroups of index
0
2 defining the dihedral group. Then W k ' IndG
H (/ ) where is the
quadratic character G G/H and 0 is the conjugate of by any element of

G H. Note that 6= 0 since H has nontrivial image in PGL2 (k).


To find a such that () = 1 and conditions (i) and (ii) hold, observe
that M (pn ) is abelian where M is the quadratic field associated to . So
conditions (i) and (ii) can be satisfied if 0 is non-abelian. If 0 is abelian (i.e.,
0
the image has the form Z/2 Z/2), then we use hypothesis (b). If IndG
H (/ )

is irreducible over k then W k is a sum of three distinct quadratic characters,


none of which is the quadratic character associated to L, and we can repeat
the argument by changing the choice of H for the other two characters. If
0

X = IndG
H (/ ) k is absolutely irreducible then pick any G H. This
satisfies (i) and can be made to satisfy (ii) if (b) holds. Finally, since GH
we see that has trace zero and 2 = 1 in its action on X. Thus it has an
eigenvalue equal to 1.

Chapter 2
In this chapter we study the Hecke rings. In the first section we recall
some of the well-known properties of these rings and especially the Gorenstein property whose proof is rather technical, depending on a characteristic
p version of the q-expansion principle. In the second section we compute the
relations between the Hecke rings as the level is augmented. The purpose is to
find the change in the -invariant as the level increases.
In the third section we state the conjecture relating the deformation rings
of Chapter 1 and the Hecke rings. Finally we end with the critical step of
showing that if the conjecture is true at a minimal level then it is true at
all levels. By the results of the appendix the conjecture is equivalent to the

480

ANDREW JOHN WILES

equality of the -invariant for the Hecke rings and the p/p2 -invariant for the
deformation rings. In Chapter 2, Section 2, we compute the change in the
-invariant and in Chapter 1, Section 1, we estimated the change in the p/p 2 invariant.
1. The Gorenstein property
For any positive integer N let X1 (N ) = X1 (N )/Q be the modular curve
over Q corresponding to the group 1 (N ) and let J1 (N ) be its Jacobian. Let
T1 (N ) be the ring of endomorphisms of J1 (N ) which is generated over Z by
the standard Hecke operators {Tl = Tl for l - N, Uq = Uq for q|N, hai = hai
for (a, N ) = 1}. For precise definitions of these see [MW1, Ch. 2,5]. In
particular if one identifies the cotangent space of J1 (N )(C) with the space of
cusp forms of weight 2 on 1 (N ) then the action induced by T1 (N ) is the usual
one on cusp forms. We let = {hai : (a, N ) = 1}.
The group (Z/N Z) acts naturally on X1 (N ) via and for any subgroup H (Z/N Z) we let XH (N ) = XH (N )/Q be the quotient X1 (N )/H.
Thus for H = (Z/N Z) we have XH (N ) = X0 (N ) corresponding to the group
0 (N ). In Section 2 it willQsometimes be convenient
that H decomQ tor assume

poses as a product H = Hq in (Z/N Z) ' (Z/q Z) where the product


is over the distinct prime powers dividing N . We let JH (N ) denote the Jacobian of XH (N ) and note that the above Hecke operators act naturally on
JH (N ) also. The ring generated by these Hecke operators is denoted TH (N )
and sometimes, if H and N are clear from the context, we addreviate this
to T.
Let p be a prime 3. Let m be a maximal ideal of T = TH (N ) with
p m. Then associated to m there is a continuous odd semisimple Galois
representation m ,
(2.1)

m : Gal(Q/Q) GL2 (T/m)

unramified outside N p which satisfies


trace m (Frob q) = Tq , det m (Frob q) = hqiq
for each prime q - N p. Here Frob q denotes a Frobenius at q in Gal(Q/Q).
The representation m is unique up to isomorphism. If p - N (resp. p|N ) we
say that m is ordinary if Tp
/ m (resp. Up
/ m). This implies (cf., for example,
theorem 2 of [Wi1]) that for our fixed decomposition group Dp at p,

Dp

1
0

for a suitable choic of basis, with 2 unramified and 2 (Frob p) = Tp mod


m (resp. equal to Up ). In particular m is ordinary in the sense of Chapter 1

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

481

provided 1 6= 2 . We will say that m is Dp -distinguished if m is ordinary and


1 6= 2 . (In practice 1 is usually ramified so this imposes no extra condition.)
We caution the reader that if m is ordinary in the sense of Chapter 1 then we
can only conclude that m is Dp -distinguished if p - N .
Let Tm denote the completion of T at m so that Tm is a direct factor of
the complete semi-local ring Tp = TZp . Let D be the points of the associated
m-divisible group
D = JH (N )(Q)m ' JH (N )(Q)p Tm .
Tp

= HomZ (D, Qp /Zp ) is a rank 2 Tm -module, i.e., that


It is known that D
p
Qp ' (Tm Qp )2 . Briefly it is enough to show that H 1 (XH (N ), C) is
D
Zp

Zp

free of rank 2 over T C and this reduces to showing that S2 (H (N ), C),


the space of cusp forms of weight 2 on H (N ), is free of rank 1 over T C.
One shows then that if {f1 , . . . , fr } is a complete set of normalized newforms
in S2 (H (N ), C) of levels m1 , . . . , mr then if we set di = N/mi , the form
f = fi (di z) is a basis vector of S2 (H (N ), C) as a T C-module.
If m is ordinary then Theorem 2 of [Wi1], itself a straightforward generalization of Proposition 2 and (11) of [MW2], shows that (for our fixed decomposition group Dp ) there is a filtration of D by Pontrjagin duals of rank 1
Tm -modules (in the sense explained above)
(2.2)

0 D0 D DE 0

where D 0 is stable under Dp and the induced action on D E is unramified with


Frob p = Up on it if p|N and Frob p equal to the unit root of x2 Tp x + phpi
= 0 in Tm if p - N . We can describe D 0 and D E as follows. Pick a
Ip which induces a generator of Gal(Qp (N p )/Qp (N p )). Let : Dp Z
p
be the cyclotomic character. Then D 0 = ker( ())div , the kernel being
taken inside D and div meaning the maximal divisible subgroup. Although
in [Wi1] this filtration is given only for a factor Af of J1 (N ) it is easy to
deduce the result for JH (N ) itself. We note that this filtration is defined
without reference to characteristic p and also that if m is Dp -distinguished, D 0
(resp. D E ) can be described as the maximal submodule on which
1 ()
is topologically nilpotent for all Gal(Qp /Qp ) (resp. quotient on which

2 () is topologically nilpotent for all Gal(Qp /Qp )), where


i () is
any lifting of i () to Tm .
The Weil pairing h , i on JH (N )(Q)pM satisfies the relation ht x, yi =

hx, t yi for any Hecke operator t. It is more convenient to use an adapted


pairing defined as follows. Let w , for a primitive N th root of 1, be the
involution of X1 (N )/Q() defined in [MW1, p. 235]. This induces an involution
of XH (N )/Q() also. Then we can define a new pairing [ , ] by setting (for a

482

ANDREW JOHN WILES

fixed choice of )
(2.3)

[x, y] = hx, w yi.

Then [t x, y] = [x, t y] for all Hecke operators t. In particular we obtain an


induced pairing on DpM .
The following theorem is the crucial result of this section. It was first
proved by Mazur in the case of prime level [Ma2]. It has since been generalized
in [Ti1], [Ri1] [M Ri], [Gro] and [E1], but the fundamental argument remains
that of [Ma2]. For a summary see [E1, 9]. However some of the cases we need
are not covered in these accounts and we will present these here.
Theorem 2.1. (i) If p - N and m is irreducible then
JH (N )(Q)[m] ' (T/m)2 .
(ii) If p - N and m is irreducible and m is Dp -distinguished then
JH (N p)(Q)[m] ' (T/m)2 .
(In case (ii) m is a maximal ideal of T = TH (N p).)

T2m .

\
2
Corollary 1. In case (i), JH (N )(Q)m ' Tm and Tam JH (N )(Q) '

In case (ii), JH (N\


p)(Q)m ' T2m and Tam JH (N p)(Q) ' T2m (where

Tm = TH (N p)m ).

Corollary 2. In either of cases (i) or (ii) Tm is a Gorenstein ring.


In each case the first isomorphisms of Corollary 1 follow from the theorem
together with the rank 2 result alluded to previously. Corrollary 2 and the
second isomorphisms of corollory 1 then follow on applying duality (2.4). (In
the proof and in all applications we will only use the notion of a Gorenstein
Zp -algebra as defined in the appendix. For finite flat local Zp -algebras the
notions
ring
Zp -algebra are the same.) Here
of Gorenstein
and Gorenstein

Tam JH (N )(Q)

= Tap JH (N )(Q) Tm is the m-adic Tate module of


Tp

JH (N ).
We should also point out that although Corollary 1 gives a representation
from the m-adic Tate module
= Tm : Gal(Q/Q) GL2 (Tm )

this can be constructed in a much more elementary way. (See [Ca3] for another
argument.) For, the representation exists with Tm Q replacing Tm when we
use the fact that Hom(Qp /Zp , D)Q was free of rank 2. A standard argument

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

483

using the Eichler-Shimura relations implies that this representation 0 with


values in GL2 (Tm Q) has the property that
trace 0 (Frob `) = T` , det 0 (Frob `) = `h`i
for all ` - N p. We can normalize this representation
picking a complex
1 0by
0
conjugation c and choosing a basis such that (c) = 0 1 , and then by picking

a for which 0 ( ) = ac db with b c 6 0(m) and by rescaling the basis so


that b = 1. (Note that the explicit description
of the traces shows that if m

0
1
is also normalized so that m (c) = 0 1 then b c mod m = b,m c,m where
,m b,m
. The existence of a such that b c 6 0(m) comes from
m ( ) = ac,m
d,m
the irreducibility of m .) With this normalization one checks that 0 actually
takes values in the (closed) subring of Tm generated over Zp by the traces.
One can even construct the representation directly from the representations in
Theorem 0.1 using this ring which is reduced. This is the method of Carayol
which requires also the characterization of by the traces and determinants
(Theorem 1 of [Ca3]). One can also often interpret the Uq operators in terms
of for q|N using the q ' (q ) theorem of Langlands (cf. [Ca1]) and the
Uq operator in case (ii) using Theorem 2.1.4 of [Wi1].
Proof (of theorem). The important technique for proving such multiplicityone results is due to Mazur and is based on the q-expansion principle in characteristic p. Since the kernel of JH (N )(Q) J1 (N )(Q) is an abelian group on
which Gal(Q/Q) acts through an abelian extension of Q, the intersection with
ker m is trivial when m is irreducible. So it is enough to verify the theorem
for J1 (N ) in part (i) (resp. J1 (N p) in part (ii)). The method for part (i) was
developed by Mazur in [Ma2, Ch. II, Prop. 14.2]. It was extended to the case
of 0 (N ) in [Ri1, Th. 5.2] which summarizes Mazurs argument. The case of
1 (N ) is similar (cf. [E1, Th. 9.2]).
Now consider case (ii). Let (p) = {hai : a 1(N )} . Let us first
assume that (p) is nontrivial mod m, i.e., that 1
/ m for some (p) . This
case is essentially covered in [Ti1] (and also in [Gro]). We briefly review the
argument for use later. Let K = Qp (p ), p being a primitive pth root of unity,
and let O be the ring of integers of the completion of the maximal unramified
extension of K. Using the fact that (p) is nontrivial mod m together with
Proposition 4, p. 269 of [MW1] we find that
et
J1 (N p)m/O
(Fp ) ' (Pic0 1et Pic0 1 )m (Fp )

where the notation is taken from [MW1] loc. cit. Here 1et and 1 are the
two smooth irreducible components of the special fibre of the canonical model
of X1 (N p)/O described in [MW1, Ch. 2]. (The smoothness in this case was
et
proved in [DR].) Also J1 (N p)m/O
denotes the canonical etale quotient of the
m-divisible group over O. This makes sense because J1 (N p)m does extend to

484

ANDREW JOHN WILES

a p-divisible group over O (again by a theorem of Deligne and Rapoport [DR]


and because (p) is nontrivial mod m). It is ordinary as follows from (2.2) when
we use the main theorem of Tate ([Ta]) since D 0 and D E clearly correspond
to ordinary p-divisible groups.
Now the q-expansion principle implies that dimFp X[m0 ] 1 where
X = {H 0 (1 , 1 ) H 0 (1et , 1 )}
and m0 is defined by embedding T/m , Fp and setting m0 = ker : TFp Fp
under the map t a 7 at mod m. Also T acts on Pic0 1 Pic0 1et , the
abelian variety part of the closed fibre of the Neron model of J1 (N p)/O , and
hence also on its cotangent space X. (For a proof that X[m0 ] is at most onedimensional, which is readily adapted to this case, see Lemma 2.2 below. For
similar versions in slightly simpler contexts see [Wi3, 6] or [Gro, 12]. Then
the Cartier map induces an injection 9cf. Prop. 6.5 of [Wi3])
: {Pic0 1 Pic0 1et }[p](Fp ) Fp , X.
Fp

The composite w can be checked to be Hecke invariant (cf. Prop. 6.5 of


[Wi3]. In checking the compatibility for Up use the formulas of Theorem 5.3
of [Wi3] but note the correction in [MW1, p. 188].) It follows that
J1 (N p)m/O (Fp )[m] ' T/m
is the Pontrjagin dual of
as a T-module.
This shows that if H
' Tm since H/m

H = J1 (N p)m/O (Fp ) then H


' T/m. Thus

J1 (N p)m/O (Fp )[p] Hom(Tm /p, Z/pZ).


Now our assumption that m is Dp -distinguished enables us to identify
et
(Qp ).
D0 = J1 (N p)0m/O (Qp ) , DE = J1 (N p)m/O

For the groups on the right are unramified and those on the left are dual to
groups where inertia acts via a character of finite order (duality with respect
to Hom( , Qp /Zp (1))). So

D0 [p] Tm /p, D E [p] Hom(Tm /p, Z/pZ)


as Tm -modules, the former following from the latter when we use duality under
the pairing [ , ]. In particular as m is Dp -distinguished,
(2.4)

D[p] ' Tm /p Hom(Tm /p, Z/pZ).

We now use an argument of Tilouine [Ti1]. We pick a complex conjugation


. This has distinct eigenvalues 1 on ]m so we may decompose D[p] into
eigenspaces for :
D[p] = D[p]+ D[p] .

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

485

Since Tm /p and Hom(Tm /p, Z/pZ) are both indecomposable Hecke-modules,


by the Krull-Schmidt theorem this decomposition has factors which are isomorphic to those in (2.4) up to order. So in the decomposition
D[m] = D[m]+ D[m]
one of the eigenspaces is isomorphic to Tm and the other to (Tm /p)[m]. But
since m is irreducible it is easy to see by considering D[m]Hom(D[m], det m )
that has the same number of eigenvalues equal to +1 as equal to 1 in D[m],

whence #(Tm /p)[m] = #(T/m). This shows that D[m]+ D[m] ' T/m as
required.
Now we consider the case where (p) is trivial mod m. This case was
treated (but only for the group 0 (N p) and m new at pthe crucial restriction being the last one) in [M Ri]. Let X1 (N, p)/Q be the modular curve
corresponding to 1 (N ) 0 (p) and let J1 (N, p) be its Jacobian. Then since
the composite of natural maps J1 (N, p) J1 (N p) J1 (N, p) is multiplication
by an integer prime to p and since (p) is trivial mod m we see that
J1 (N, p)m (Q) ' J1 (N p)m (Q).
It will be enough then to use J1 (N, p), and the corresponding ring T and ideal
m.
The curve X1 (N, p) has a canonical model X1 (N, p)/Zp which over Fp
consists of two smooth curves et and intersecting transversally at the
supersingular points (again this is a theorem of Deligne and Rapoport; cf.
[DR, Ch. 6, Th. 6.9], [KM] or [MW1] for more details). We will use the models
described in [MW1, Ch. II] and in particular the cusp will lie on . Let
denote the sheaf of regular differentials on X1 (N, p)/Fp (cf. [DR, Ch. 1 2],
[M Ri, 7]). Over Fp , since X1 (N, p)/Fp has ordinary double point singularities,
the differentials may be identified with the meromorphic differentials on the
^
normalization X1 (N,
p)/Fp = et which have at most simple poles at the
supersingular points (the intersection points of the two components) and satisfy
resx1 + resx2 = 0 if x1 and x2 are the two points above such a supersingular
point. We need the following lemma:
Lemma 2.2. dimT/m H 0 (X1 (N, p)/Fp , )[m] = 1.
Proof. First we remark that the action of the Hecke operator Up here is
most conveniently defined using an extension from characteristic zero. This is
explained below. We will first show that dimT/m H 0 (X1 (N, p)/Fp , )[m] 1,
this being the essential step. If we embed T/m , Fp and then set
m0 = ker : T Fp Fp (the map given by t a 7 at mod m) then it is
enough to show that dimFp H 0 (X1 (N, p)/Fp , )[m0 ] 1. First we will suppose

486

ANDREW JOHN WILES

that there is no nonzero holomorphic differential in H 0 (X1 (N, p)/Fp , )[m0 ],


i.e., no differential form which pulls back to holomorphic differentials on et
and . Then if 1 and 2 are two differentials in H 0 (X1 (N, p)/Fp , )[m0 ],
the q-expansion principle shows that 1 2 has zero q-expansion at for
2
some pair (, ) 6= (0, 0) in Fp and thus is zero on . As 1 2 = 0 on
it is holomorphic on et . By our hypothesis it would then be zero which
shows that 1 and 2 are linearly dependent.
This use of the q-expansion principle in characteristic p is crucial and due
to Mazur [Ma2]. The point is simply that all the coefficients in the q-expansion
are determined by elementary formulae from the coefficient of q provided that
is an eigenform for all the Hecke operators. The formulae for the action of
these operators in characteristic p follow from the formulae in characteristic
zero. To see this formally (especially for the Up operator) one checks first
that H 0 (X1 (N, p)/Zp , ), where denotes the sheaf of regular differentials on
X1 (N, p)/Zp , behaves well under the base changes Zp Zp and Zp Qp ;
cf. [Ma2, II.3] or [Wi3, Prop. 6.1]. The action of the Hecke operators on
J1 (N, p) induces an action on the connected component of the Neron model of
J1 (N, p)/Qp , so also on its tangent space and cotangent space. By Grothendieck
duality the cotangent space is isomorphic to H 0 (X1 (N, p)/Zp , ); see (2.5)
below. (For a summary of the duality statements used in this context, see
[Ma2, II.3]. For explicit duality over fields see [AK, Ch. VIII].) This then
defines an action of the Hecke operators on this group. To check that over Q p
this gives the standard action one uses the commutativity of the diagram after
Proposition 2.2 in [Mi1].
Now assume that there is a nonzero holomorphic differential in
H 0 (X1 (N, p)/Fp , )[m0 ].
We claim that the space of holomorphic differentials then has dimension 1 and
that any such differential 6= 0 is actually nonzero on . The dimension
claim follows from the second assertion by using the q-expansion principle. To
prove that 6= 0 on we use the formula
Up (x, y) = (F x, y 0 )
for (x, y) (Pic0 et Pic0 )(Fp ), where F denotes the Frobenius endomorphism. The value of y 0 will not be needed. This formula is a variant
on the second part of Theorem 5.3 of [Wi3] where the corresponding result is proved for X1 (N p). (A correction to the first part of Theorem 5.3
was noted in [MW1, p. 188].) One check then that the action of Up on
X0 = H 0 ( , 1 ) H 0 (et , 1 ) viewed as a subspace of H 0 (X1 (N, p)/Fp , )
is the same as the action on X0 viewed as the cotangent space of Pic0
Pic0 et . From this we see that if = 0 on then Up = 0 on et . But Up

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

487

acts as a nonzero scalar which gives a contradiction if 6= 0. We can thus assume that the space of m0 -torsion holomorphic differentials has dimension 1 and
is generated by . So if 2 is now any differential in H 0 (X1 (N, p)/Fp , )[m0 ]
then 2 has zero q-expansion at for some choice of . Then 2 = 0
on whence 2 is holomorphic and so 2 = . We have now shown
in general that dim(H 0 (X1 (N, p)/Fp , )[m0 ]) 1.
The singularities of X1 (N, p)/Zp at the supersingular points are formally
unr to Z
unr [[X, Y ]]/(XY pk ) with k = 1, 2 or 3 [cf. [DR,
d
isomorphic over Zd
p
p
Ch. 6, Th. 6.9]). If we consider a minimal regular resolution M 1 (N, p)/Zp
then H 0 (M1 (N, p)/Fp , ) ' H 0 (X1 (N, p)/Fp , ) (see the argument in [Ma2,
Prop. 3.4]), and a similar isomorphism holds for H 0 (M1 (N, p)/Zp , ).
As M1 (N, p)/Zp is regular, a theorem of Raynaud [Ray2] says that the
connected component of the Neron model of J1 (N, p)/Qp is J1 (N, p)0/Zp '
Pic0 (M1 (N, p)/Zp ). Taking tangent spaces at the origin, we obtain
(2.5)

Tan(J1 (N, p)0/Zp ) ' H 1 (M1 (N, p)/Zp , OM1 (N,p) ).

Reducing both sides mod p and applying Grothendieck duality we get an isomorphism
(2.6)

Tan(J1 (N, p)0/Fp ) Hom(H 0 (X1 (N, p)/Fp , ), Fp ).

(To justify the reduction in detail see the arguments in [Ma2, II. 3]). Since
Tan(J1 (N, p)0/Zp ) is a faithful T Zp -module it follows that
H 0 (X1 (N, p)/Fp , )[m]
is nonzero. This completes the proof of the lemma.

To complete the proof of the theorem we choose an abelian subvariety


A of J1 (N, p) with multiplicative reduction at p. Specifically let A be the
connected part of the kernel of J1 (N, p) J1 (N ) J1 (N ) under the natural
map described in Section 2 (see (2.10)). Then we have an exact sequence
0 A J1 (N, p) B 0
and J1 (N, p) has semistable reduction over Qp and B has good reduction.
By Proposition 1.3 of [Ma3] the corresponding sequence of connected group
schemes
0 A[p]0/Zp J1 (N, p)[p]0/Zp B[p]0/Zp 0
is also exact, and by Corollary 1.1 of the same proposition the corresponding
sequence of tangent spaces of Neron models is exact. Using this we may check
that the natural map
(2.7)

Tan(J1 (N, p)[p]t/Fp ) Tm Tan(J1 (N, p)/Fp ) Tm


Tp

Tp

488

ANDREW JOHN WILES

is an isomorphism, where t denotes the maximal multiplicative-type subgroup


scheme (cf. [Ma3, 1]). For it is enough to check such a relation on A and B
separately and on B it is true because the m-divisible group is ordinary. This
follows from (2.2) by the theorem of Tate [Ta] as before.
Now (2.6) together with the lemma shows that
Tan(J1 (N, p))/Zp Tm ' Tm .
Tp

We claim that (2.7) together with this implies that as Tm -modules


V := J1 (N, p)[p]t (Qp )m ' (Tm /p).
To see this it is sufficient to exhibit an isomorphism of Fp -vector spaces
(2.8)

Tan(G/Fp ) ' G(Qp ) Fp


Fp

for any multiplicative-type group scheme (finite and flat) G/Zp which is killed
by p and moreover to give such an isomorphism that respects the action of
endomorphism of G/Zp . To obtain such an isomorphism observe that we have
isomorphisms
(2.9)

HomQp (p , G) Fp ' HomFp (p , G) Fp


Fp
Fp

' Hom Tan(p /Fp ), Tan(G/Fp )

where HomQp denotes homomorphisms of the group schemes viewed over Qp


and similarly for HomFp . The second isomorphism can be checked by reducing
to the case G = p . Now picking a primitive pth root of unity we can identify the left-hand term in (2.9) with G(Qp ) Fp . Picking an isomorphism of
Fp

Tan(p/Fp ) with Fp we can identify the last term in (2.9) with Tan(G/Fp ).
Thus after these choices are made we have an isomorphism in (2.8) which
respects the action of endomorphisms of G.
On the other hand the action of Gal(Qp /Qp ) on V is ramified on every
subquotient, so V D 0 [p]. (Note that our assumption that (p) is trivial
mod m implies that the action on D 0 [p] is ramified on every subquotient and
on DE [p] is unramified on every subquotient.) By again examining A and B
separately we see that in fact V = D 0 [p]. For A we note that A[p]/A[p]t is
t where A is the dual abelian variety. We
unramified because it is dual to A[p]
can now proceed as we did in the case where (p) was nontrivial mod m.

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

489

2. Congruences between Hecke rings


Suppose that q is a prime not dividing N . Let 1 (N, q) = 1 (N ) 0 (q)
and let X1 (N, q) = X1 (N, q)/Q be the corresponding curve. The two natural
maps X1 (N, q) X1 (N ) induced by the maps z z and z qz on the
upper half plane permit us to define a map J1 (N ) J1 (N ) J1 (N, q). Using
a theorem of Ihara, Ribet shows that this map is injective (cf. [Ri2, Cor. 4.2]).
Thus we can define by
(2.10)

0 J1 (N ) J1 (N ) J1 (N, q).

Dualizing, we define B by

0 B J1 (N, q) J1 (N ) J1 (N ) 0.
Let T1 (N, q) be the ring of endomorphisms of J1 (N, q) generated by the
standard Hecke operators {Tl for l - N q, Ul for l|N q, hai = hai for
(a, N q) = 1}. One can check that Up preserves B either by an explicit calculation or by noting that B is the maximal abelian subvariety of J 1 (N, q) with
multiplicative reduction at q. We set J2 = J1 (N ) J1 (N ).
More generally, one can consider JH (N ) and JH (N, q) in place of J1 (N )
and J1 (N,q) (where JH (N, q) corresponds to X1 (N, q)/H) and we write TH (N )
and TH (N, q) for the associated Hecke rings. In this case the corresponding
map may have a kernel. However since the kernel of JH (N ) J1 (N ) does
not meet ker m for any maximal ideal m whose associated m is irreducible,
the above sequence remain exact if we restrict to m(q) -divisible groups, m(q)
(q)
being the maximal ideal associated to m of the ring TH (N, q) generated by
the standard Hecke operators but ommitting Uq . With this minor modification the proofs of the results below for H 6= 1 follow from the cases of full
level. We will use the same notation in the general case. Thus is the map
J2 = JH (N )2 JH (N, q) induced by z z and z qz on the two factors,
and B = ker .
(B will not be an abelian variety in general.)
The following lemma is a straightforward generalization of a lemma of
Ribet ([Ri2]). Let nq be an integer satisfying nq q(N ) and nq 1(q), and
write hqi = hnq i TH (N q).
Lemma 2.3 (Ribet). (B) (J2 )m(q) = (J2 )[Uq2 hqi]m(q) for irreducible m .
Proof. The left-hand side is (im ker ),
so we compute 1 (im
ker )
= ker( ).
An explicit calculation shows that

q+1
=
Tq

Tq
q+1

on J2

490

ANDREW JOHN WILES

where Tq = Tq hqi1 . The matrix action here is on the left. We also find that
on J2

0 hqi
Uq =
,
q
Tq

(2.11)
whence
(Uq2

hqi
hqi) =
Tq

0
( ).
hqi

Now suppose that m is a maximal ideal of TH (N ), p m and m is irreducible. We will now give a slightly stronger result than that given in the
lemma in the special case q = p. (The case q 6= p we will also strengthen but
we will do this separately.) Assume the that p - N and Tp 6 m. Let ap be
the unit root of x2 Tp x + phpi = 0 in TH (N )m . We first define a maximal
ideal mp of TH (N, p) with the same associated representation as m. To do this
consider the ring
S1 = TH (N )[U1 ]/(U12 Tp U1 + phpi) End(JH (N )2 )
where U1 is the endomorphism of JH (N )2 given by the matrix

Tp
p

hpi
.
0

It is thus compatible with the action of Up on JH (N, p) when compared using


.
Now m1 = (m, U1 f
ap ) is a maximal ideal of S1 where f
ap is any element
of TH (N ) representing the class a
p TH (N )m /m ' TH (N )/m. Moreover
S1,m1 ' TH (N )m and we let mp be the inverse image of m1 in TH (N, p) under
the natural map TH (N, p) S1 . One checks that mp id Dp -distinguished. For
any standard Hecke operator t except Up (i.e., t = Tl , Uq0 for q 0 6= p or hai) the
image of t is t. The image of Up is U1 .
We need to check that the induced map
: TH (N, p)mp S1,m1 ' TH (N )m
is surjective. The only problem is to show that Tp is in the image. In the present
context one can prove this using the surjectivity of in (2.12) and using the
fact that the Tate-modules in the range and domain of are free of rank 2 by
Corollary 1 to Theorem 2.1. The result then follows from Nakayamas lemma as
one deduces easily that TH (N)m is a cyclic TH (N, p)mp -module. This argument
was suggested by Diamond. A second argument using representations can be
found at the end of Proposition 2.15. We will now give a third and more direct
proof due to Ribet (cf. [Ri4, Prop. 2]) but found independently and shown to
us by Diamond.

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

491

lemma we let TM , for an integer M , denote the subring of


For the following

End S2 (1 (N )) generated by the Hecke operators Tn for positive integers n

relatively prime to M . Here S2 1 (N ) denotes the vector space of weight 2

cusp forms on 1 (N ). Write T for T1 . It will be enough to show that Tp is


a redundant operator in T1 , i.e., that Tp = T. The result for TH (N )m then
follows.
Lemma (Ribet). Suppose that (M, N ) = 1. If M is odd then TM = T.
If M is even then TM has finite index in T equal to a power of 2.

As the rings are finitely generated free Z-modules, it suffices to prove that
T Fl T Fl is surjective unless l and M are both even. The claim
follows from
M

1. TM Fl TM/p Fl is surjective if p|M and p - lN .


2. Tl Fl T Fl is surjective if l - 2N.
Proof of 1. Let A denote the Tate module Tal (J1 (N )). Then R = TM/p
Zl acts faithfully on A. Let R0 = (R Ql ) EndZl A and choose d so that
Zl

ld R0 lR. Consider the Gal(Q/Q)-module


B = J1 (N )[ld ] N ld . By

Cebotarev
density, there is a prime q not dividing M N l so that Frobp = Frobq
on B. Using the fact that Tr = Frobr + hrir(Frobr)1 on A for r = p and
r = q, we see that Tp = Tq on J1 (N )[ld ]. It follows that Tp Tq is in ld EndZl A
and therefore in ld R0 lR.
Proof of 2. Let S be the set of cusp forms in S2 (1 (N )) whose q-expansions
at have coefficients in Z. Recall that S2 (1 (N )) = S C and that S is stable
under the action of T (cf. [Sh1, Ch. 3] and [Hi4, 4]). The pairing T S Z
defined by T f 7 a1 (T f ) is easily checked to induce an isomorphism of
T-modules
S
= HomZ (T, Z).
The surjectivity of Tl /lTl T/lT is equivalent to the injectivity of the dual
map
Hom(T, Fl ) Hom(Tl , Fl ).
Hom(T, Fl ) and note that if f is in the
Now use the isomorphism S/lS =
l
kernel of S Hom(T , Fl ), then an (f ) = a1 (Tn f ) is divisible by l for all n
prime to l. But then the mod l form defined by f is in the kernel of the operator
d
, and is therefore trivial if l is odd. (See Corollary 5 of the main theorem
q dq
of [Ka].) Therefore f is in lS.
Remark. The argument does not prove that TM d = Td if (d, N ) 6= 1.

492

ANDREW JOHN WILES

We now return to the assumptions that m is irreducible, p - N and


Tp 6 m. Next we define a principal ideal (p ) of TH (N )m as follows. Since
TH (N, p)mp and TH (N )m are both Gorenstein rings (by Corollary 2 of Theorem 2.1) we can define an adjoint
to
: TH (N, p)mp S1,m1 ' TH (N )m
in the manner described in the appendix and we set p = ( )(1).

Then
(p ) is independent of the choice of (Hecke-module) pairings on TH (N, p)mp
and TH (N )m . It is equal to the ideal generated by any composite map

TH (N )m TH (N, p)mp TH (N )m
provided that is an injective map of TH (N, p)mp -modules with Zp torsion-free
cokernel. (The module structure on TH (N )m is defined via .)
Proposition 2.4. Assume that m is Dp -distinguished and that m is
irreducible of level N with p - N . Then

(p ) = Tp2 hpi(1 + p)2 = (a2p hpi).


Proof. Consider the maps on p-adic Tate-modules induced by and :

Tap JH (N )2 Tap JH (N, p) Tap JH (N )2 .

These maps commute with the standard Hecke operators with the exception
of Tp or Up (which are not even defined on all the terms). We define

S2 = TH (N )[U2 ]/(U22 Tp U2 + phpi) End JH (N )2

where U2 is the endomorphism of JH (N )2 defined by ( p0 hpi


Tp ). It satisfies
U2 = Up . Again m2 = (m, U2 f
ap ) is a maximal ideal of S2 and we have,
on restricting to the m1 , mp and m2 -adic Tate-modules:

b
Tamp JH (N, p)
Tam1 JH (N )2
Tam2 JH (N )2

(2.12)

o v2

Tam JH (N )

o v1

Tam JH (N ) .

The vertical isomorphisms are defined by v2 : x (hpix, ap x) and v1 : x


(a
Qp x, px). (Here ap TH (N )m can be viewed as an element of TH (N )p '
TH (N )n where the product is taken over the
ideals containing
maximal

p. So v1 and v2 can be viewed as maps to Tap JH (N )2 whose images are

respectively Tam1 JH (N )2 and Tam2 JH (N )2 .)


Now
b is surjective and is injective with torsion-free

cokernel by the result of Ribet mentioned before.


Also Tam JH (N ) ' TH (N )2m and

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

493

b
Tamp JH (N, p) ' TH (N, p)2mp by Corollary 1 to Theorem 2.1. So as ,
are maps of TH (N, p)mp -modules we can use this diagram to compute p as
remarked just prior to the statement of the proposition. (The compatibility of
the Up actions requires that, on identifying the completions S1,m1 and S2,m2
with TH (N )m , we get U1 = U2 which is indeed the case.) We find that
2
v11
b v2 (z) = a1
p (ap hpi)(z).

We now apply to J1 (N, q 2 ) (but q 6= p) the same analysis that we have just
applied to J1 (N, q 2 ). Here X1 (A, B) is the curve corresponding to 1 (A)0 (B)
and J1 (A, B) its Jacobian. First we need the analogue of Iharas result. It is
convenient to work in a slightly more general setting. Let us denote the maps
X1 (N q r1 , q r ) X1 (N q r1 ) induced by z z and z qz by 1,r and 2,r
respectively. Similarly we denote the maps X1 (N q r , q r+1 ) X1 (N q r ) induced
by z z and z qz by 3,r and 4,r respectively. Also let : X1 (N q r )
X1 (N q r1 , q r ) denote the natural map induced by z z.
In the following lemma if m is a maximal ideal of T1 (N q r1 ) or T1 (N q r )
(q)
we use m(q) to denote the maximal ideal of T1 (N q r , q r+1 ) compatible with
(q)
m, the ring T1 (N q r , q r+1 ) T1 (N q r , q r+1 ) being the subring obtained by
omitting Uq from the list of generators.
Lemma 2.5. If q 6= p is a prime and r 1 then the sequence of abelian
varieties
1

0 J1 (N q r1 ) J1 (N q r ) J1 (N q r ) J1 (N q r , q r+1 )

) induces a correwhere 1 = (1,r ) , (2,r ) and 2 = (4,r


, 3,r
sponding sequence of p-divisible groups which becomes exact when localized at
any m(q) for which m is irreducible.
n

1
r
Proof. Let (N q ) denote the group ( ac db ) 1 (N ) : a d 1(q r ),
o
c 0(q r1 ), b 0(q) . Let B1 and B 1 be given by
B1 = 1 (N q r )/1 (N q r ) (q),

B 1 = 1 (N q r )/1 (N q r ) (q)

and let q = 1 (N q r1 )/1 (N q r ) (q). Thus q ' SL2 (Z/q) if r = 1 and


is of order a power of q if r > 1.
The exact sequences of inflation-restriction give:
1

H 1 (1 (N q r ) (q), Qp /Zp )B1 ,


H1 (1 (N q r ), Qp /Zp )

together with a similar isomorphism with 1 replacing 1 and B 1 replacing B1 .


We also obtain

H 1 (1 (N q r1 ), Qp /Zp ) H 1 (1 (N q r ) (q), Qp /Zp )q .

494

ANDREW JOHN WILES

The vanishing of H 2 (SL2 (Z/q), Qp /Zp ) can be checked by restricting to the


Sylow p-subgroup which is cyclic. Note that im1 im1 H 1 (1 (N q r )(q),
Qp /Zp )q since B1 and B 1 together generate q . Now consider the sequence
(2.13)

0 H 1 (1 (N q r1 ), Qp /Zp )
res1 res1

H 1 (1 (N q r ), Qp /Zp ) H 1 (1 (N q r ), Qp /Zp )
1

1
H 1 (1 (N q r ) (q), Qp /Zp ).

We claim it is exact. To check this, suppose that 1 (x) = 1 (y). Then


q
1 (x) H 1 (1 (N q r ) (q),
Qp /Zp ) . So 1 (x) is the restriction of an
x0 H 1 1 (N q r1 ), Qp /Zp whence x res1 (x0 ) ker 1 = 0. It follows
also that y = res1 (x0 ).
Now conjugation by the matrix ( 0q 01 ) induces isomorphisms
1 (N q r ) ' 1 (N q r ),

1 (N q r ) (q) ' 1 (N q r , q r+1 ).

So our sequence (2.13) yields the exact sequence of the lemma, except that we
have to change from group cohomology to the cohomology of the associated
complete curves. If the groups are torsion-free then the difference between
these cohomologies is Eisenstein (more precisely Tl 1 l for l 1modN q r+1
is nilpotent) so will vanish when we localize at the preimage of m (q) in the
abstract Hecke ring generated as a polynomial ring by all the standard Hecke
operators excluding Tq . If M 3 then the group 1 (M ) has torsion. For
M = 1, 2, 3 we can restrict to (3), (4), (3), respectively, where the cohomology is Eisenstein as the corresponding curves have genus zero and the
groups are torsion-free. Thus one only needs to check the action of the Hecke
operators on the kernels of the restriction maps in these three exceptional cases.
This can be done explicitly and again they are Eisenstein. This completes the
proof of the lemma.

Let us denote the maps X1 (N, q) X1 (N ) induced by z z and z qz


by 1 and 2 respectively. Similarly we denote the maps X1 (N, q 2 ) X1 (N, q)
induced by z z and z qz by 3 and 4 respectively.
From the lemma (with r = 1) and Iharas result (2.10) we deduce that
there is a sequence
(2.14)

0 J1 (N ) J1 (N ) J1 (N ) J1 (N, q 2 )

where = (1 3 ) (2 3 ) (2 4 ) and that the induced map of pdivisible groups becomes injective after localization at m(q) s which correspond
to irreducible m s. By duality we obtain a sequence

J1 (N, q 2 ) J1 (N )3 0
which is surjective on Tate modules in the same sense. More generally we
can prove analogous results for JH (N ) and JH (N, q 2 ) although there may be

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

495

a kernel of order divisible by p in JH (N ) J1 (N ). However this kernel will


not meet the m(q) -divisible group for any maximal ideal m(q) whose associated
m is irreducible and hence, as in the earlier cases, will not affect the results if
after passing to p-divisible groups we localize at such an m(q) . We use the same
notation in the general case when H 6= 1 so is the map JH (N )3 JH (N, q 2 ).
We suppose now that m is a maximal ideal of TH (N ) (as always with p
m) associated to an irreducible representation and that q is a prime, p - N p.
We now define a maximal ideal mq of TH (N, q 2 ) with the same associated
representation as m. To do this consider the ring

S1 = TH (N )[U1 ]/U1 (U12 Tq U1 + qhqi) End JH (N )3


where the action of U1 on JH (N )3 is given by the matrix

Tq
q
0

hqi 0
0
0.
q
0

Then U1 satisfies the compatibility


b
b Uq = U1 .

One checks this using the actions on cotangent spaces. For we may identify
the cotangent spaces with spaces of cusp forms and with this identification any
Hecke operator t induces the usual action on cusp forms. There is a maximal
ideal m1 = (U1 , m) in S1 and S1,m1 ' TH (N )m . We let mq denote the reciprocal
image of m1 in TH (N, q 2 ) under the natural map TH (N, q 2 ) S1 .
Next we define a principal ideal (0q ) of TH (N )m using the fact that
TH (N, q 2 )mq and TH (N )m are both Gorenstein rings (cf. Corollary 2 to The 0 ) where
orem 2.1). Thus we set (0q ) = (b
0 : TH (N, q 2 )mq S1,m1 ' TH (N )m
is the natural map and
b0 is the adjoint with respect to selected Hecke-module
pairings on TH (N, q 2 )mq and TH (N )m . Note that 0 is surjective. To show
that the Tq operator is in the image one can use the existence of the associated
2-dimensional representation (cf. 1) in which Tq = trace(Frob q) and apply

the Cebotarev
density theorem.
Proposition 2.6. Suppose that f rakm is a maximal ideal of TH (N )
associated to an irreducible m . Suppose also that q - N p. Then
(0p ) = (q 1)(Tq2 hqi(1 + q)2 ).

496

ANDREW JOHN WILES

Proof. We prove this in the same manner as we proved Proposition 2.4.


b
Consider the maps on p-adic Tate-modules induced by and :

(2.15)
Tap JH (N )3 Tap JH (N, q 2 ) Tap JH (N )3 .

These maps commute with the standard Hecke operators with the exception
of Tq and Uq (which are not even defined on all the terms). We define

2
3
S2 = TH (N )[U2 ]/U2 (U2 Tq U2 + qhqi) End JH (N )
where U2 is the endomorphism of JH (N )3 given by the matrix

0 0
0
q 0 hqi .
0 q
Tq

Then Uq = U2 as one can verify by checking the equality (b)U 2 = U1 (b)


because b is an isogeny. The formula for b is given below. Again
m2 = (m, U2 ) is a maximal ideal of S2 and S2,m2 ' TH (N )m . On restricting
(2.15) to the m2 , mq and m1 -adic Tate modules we get

(2.16)

Tam2 (JH (N )3 ) Tamq (JH (N, q 2 ))


x

o u2

Tam1 (JH (N )3 )
x

o u1

Tam (JH (N ))
Tam (JH (N )).
The vertical isomorphisms are induced by u2 : z (hqiz, Tq z, qz) and u1 :
z (0, 0, z). Now a calculation shows that on JH (N )3

q(q + 1)
Tq q
Tq2 hqi(1 + q)

Tq q
q(q + 1)
Tq q
=
2
1

Tq hqi (1 + q)
Tq q
q(q + 1)

where Tq = hqi1 Tq .
We compute then that
(u1
1

1
2
2
b
u2 ) = hq i(q 1) Tq hqi(1 + q) .

Now using the surjectivity of b and that


cokernel
in (2.16)

has torsion-free
2
(by Lemma 2.5) and that Tam JH (N ) and Tamq JH (N, q ) are each free of
rank 2 over the respective Hecke rings (Corollary 1 of Theorem 2.1), we deduce
the result as in Proposition 2.4.

There is one further (and completely elementary) generalization of this


result. We let : XH (N q, q 2 ) XH (N, q 2 ) be the map given by z z.
Then : JH (N, q 2 ) JH (N q, q 2 ) has kernel a cyclic group and as before
this will vanish when we localize at m(q) if m is associated to an irreducible
representation. (As before the superscript q denotes the omission of Uq from
the list of generators of TH (N q, q 2 ) and m(q) denotes the maximal ideal of
(q)
TH (N q, q 2 ) compatible with m.)

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

497

We thus have a sequence (not necessarily exact)

0 JH (N )3 JH (N q, q 2 ) Z 0

where = which induces a corresponding sequence of p-divisible groups


which becomes exact when localized at an m(q) corresponding to an irreducible
m . Here Z is the quotient abelian variety JH (N q, q 2 )/im. As before there is
a natural surjective homomorphism
: TH (N q, q 2 )mq S1,m1 ' TH (N )m

where mq is the inverse image of m1 in TH (N q, q 2 ). (We note that one can


replace TH (N q, q 2 ) by TH (N q 2 ) in the definition of and Proposition 2.7
below would still hold unchanged.) Since both rings are again Gorenstein we
can define an adjoint
b and a principal ideal
(q ) = (
b).

Proposition 2.7. Suppose that m is a maximal ideal of T = TH (N )


associated to an irreducible representation. Suppose that q - N p. Then

2
2
2
(q ) = (q 1) Tq hqi(1 + q) ).
The proof is a trivial generalization of that of Proposition 2.6.
Remark 2.8. We have included the operator Uq in the definition of Tmq =
TH (N q, q 2 )mq as in the application of the q-expansion principle it is important
to have all the Hecke operators. However Uq = 0 in Tmq . To see this we recall
that the absolute values of the eigenvalues c(q, f ) of Uq on newforms of level
N q with q - N are known (cf. [Li]). They satisfy c(q, f )2 = hqi in Of (the
ring of integers generated by the Fourier coefficients of f ) if f is on 1 (N, q),
and |c(q, f )| = q 1/2 if f is on 1 (N q) but not on 1 (N, q). Also when f is
a newform of level dividing N the roots of x2 c(q, f )x + qf (q) = 0 have
absolute value q 1/2 where c(q, f ) is the eigenvalue of Tq and f (q) of hqi. Since
for f on 1 (N q, q 2 ), Uq f is a form on 1 (N q) we see that

Y
Y
Uq (Uq2 hqi)
(Uq c(q, f ))
Uq2 c(q, f )Uq + qhqi = 0
f S1

f S2

in TH (N q, q 2 ) C where S1 is the set of newforms on 1 (N q) which are not


on 1 (n, q) and S2 is the set of newforms of level dividing N . In particular as
Uq is in mq it must be zero in Tmq .
A slightly different situation arises if m is a maximal ideal of T = T H (N, q)
(q 6= p) which is not associated to any maximal ideal of level N (in the sense of
having the same associated m ). In this case we may use the map 3 = (4 , 3 )
to give
(2.17)

JH (N, q) JH (N, q) JH (N, q 2 ) JH (N, q) JH (N, q).

498

ANDREW JOHN WILES

Then 3 3 is given by the matrix


3 3 =

q
Uq

Uq
q

on JH (N, q)2 , where Uq = Uq hqi1 and Uq2 = hqi on the m-divisible group. The
second of these formulae is standard as mentioned above; cf. for example [Li,
Th. 3], since m is not associated to any maximal ideal of level N . For the first
consider any newform
f of level divisible Eby q and observe that the Petersson
D

inner product (Uq Uq 1)f (rz), f (mz) is zero for any r, m|(N q/level f )
by [Li, Th. 3]. This shows that Uq Uq f (rz), a priori a linear combination of
f (mi z), is equal to f (rz). So Uq Uq = 1 on the space of forms on H (N, q)
which are new at q, i.e. the space spanned by forms {f (sz)} where f runs
through newforms with q|level f. In particular Uq preserves the m-divisible
group and satisfies the same relation on it, again because m is not associated
to any maximal ideal of level N .
Remark 2.9. Assume that m is of type (A) at q in the terminology of
Chapter 1, 1 (which ensures that m does not occur at level N ). In this
case Tm = TH (N, q)m is already generated by the standard Hecke operators
with the omission of Uq . To see this, consider the GL2 (Tm ) representation of
Gal(Q/Q) associated to the m-adic Tate module of JH (N, q) (cf. the discussion
following Corollary 2 of Theorem 2.1). Then this representation is already
defined over the Zp -subalgebra Ttr
m of Tm generated by the traces of Frobenius
elements, i.e. by the T` for ` - N qp. In particular hqi Ttr
m . Furthermore, as
2
Ttr
is
local
and
complete,
and
as
U
=
hqi,
it
is
enough
to solve X 2 = hqi
m
q
in the residue field of Ttr
m . But we can even do this in k0 (the minimal field
of definition of m ) by letting X be the eigenvalue of Frob q on the unique
unramified rank-one free quotient of k02 and invoking the q ' (q ) theorem
of Langlands (cf. [Ca1]). (It is to ensure that the unramified quotient is free
of rank one that we assume m to be of type (A).)
We assume now that m is of type (A) at q. Define S1 this time by setting

S1 = TH (N, q)[U1 ]/U1 (U1 Uq ) End JH (N, q)2


where U1 is given by the matrix
(2.18)

0 q
U1 =
0 Uq

on JH (N, q)2 . The map b3 is not necessarily surjective and to remedy this we
(q)
(q)
introduce m(q) = m TH (N, q) where TH (N, q) is the subring of TH (N, q)
generated by the standard Hecke operators but omitting Uq . We also write m(q)

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

499

(q)

for the corresponding maximal ideal of TH (N q, q 2 ). Then on m(q) -divisible


groups, b3 and b3 are surjective and we get a natural restriction map of
localization TH (N q, q 2 )(m(q) ) S1(m(q) ) . (Note that the image of Uq under this
map is U1 and not Uq .) The ideal m1 = (m, U1 ) is maximal in S1 and so also
in S1,(m(q) ) and we let mq denote the inverse image of m1 under this restriction
map. The inverse image of mq in TH (N q, q 2 ) is also a maximal ideal which we
agin write mq . Since the completions TH (N q, q 2 )mq and S1,m1 ' TH (N, q)m
are both Gorenstein rings (by Corollary 2 of Theorem 2.1) we can define a
principal ideal (q ) of TH (N, q)m by
(q ) = (
b)

where : TH (N q, q 2 )mq S1,m1 ' T(N, q)m is the restriction map induced
by the restriction map on m(q) -localizations described above.
Proposition 2.10. Suppose that m is a maximal ideal of TH (N, q)
associated to an irreducible m of type (A). Then
(q ) = (q 1)2 (q + 1).
Proof. The method is a straightforward adaptation of that used for Propositions 2.4 and 2.6. We let S2 = TH (N, q)[U2 ]/U2 (U2 Uq ) be the ring of
endomorphisms of JH (N, q)2 where U2 is given by the matrix

Uq q
.
0 0
This satisfies the compatability 3 U2 = Uq 3 . We define m2 = (m, U2 ) in S2
and observe that S2 , m2 ' TH (N, q)m .
Then we have maps

2
2
2
Tam2 JH (N, q)
, Tamq JH (N q, q )

Tam1 JH (N, q)
o v2

Tam JH (N, q)

o v1

Tam JH (N, q) .

The maps v1 and v2 are given by v2 : z (qz, aq z) and v1 : z (z, 0)


where Uq = aq in TH (N, q)m . One checks then that v11 (3 ) ( 3 ) v2
is equal to (q 1)(q 2 1) or 21 (q 1)(q 2 1).
The surjectivity of b3 on the completions is equivalent to the statement
that
JH (N q, q 2 )[p]mq JH (N, q)2 [p]m1

is surjective. We can replace this condition by a similar one with m (q) substituted for mq and for m1 , i.e., the surjectivity of
JH (N q, q 2 )[p]m(q) JH (N, q)2 [p]m(q) .

500

ANDREW JOHN WILES

By our hypothesis that m be of type (A) at q it is even sufficient to show that


the cokernel of JH (N q, q 2 )[p] Fp JH (N, q)2 [p] Fp has no subquotient as
a Galois-module which is irreducible, two-dimensional and ramified at q. This
statement, or rather its dual, follows from Lemma 2.5. The injectivity of 3
on the completions and the fact that it has torsion-free cokernel also follows
from Lemma 2.5 and our hypothesis that m be of type (A) at q.

The case that corresponds to type (B) is similar. We assume in the analysis of type (B) (and also of type (C) below) that H decomposes as Hq as
described at the beginning of Section 1. We assume that m is a maximal ideal
of TH (N q r ) where H contains the Sylow p-subgroup Sp of (Z/q r Z) and that
(2.19)

Iq

q
1

for a suitable choice of basis with q 6= 1 and condq = q r . Here q - N p and


we assume also that m is irreducible. We use the sequence
( 0 ) 2

2 0

JH (N q r ) JH (N q r )
JH (N q r ) JH (N q r ) JH 0 (N q r , q r+1 )

defined analogously to (2.17) where 2 was as defined in Lemma 2.5 and where
H 0 is defined as follows. Using the notation H = Hl as at the beginning of
Section 1 set Hl0 = Hl for l 6= q and Hq0 Sp = Hq . Then define H 0 = Hl0 and
let 0 : XH 0 (N q r , q r+1 ) XH (N q r , q r+1 ) be the natural map z z. Using
(q)
Lemma 2.5 we check that 2 is injective on the m
group. Again we
-divisible

r
r 2
set S1 = TH (N q )[U1 ]/U1 (U1 Uq ) End(JH N q ) where U1 is given by
the matrix in (2.18). We define m1 = (m, U1 ) and let mq be the inverse image
of m1 in TH 0 (N q r , q r+1 ). The natural map (in which Uq U1 )
: TH 0 (N q r , q r+1 )mq S1,m1 ' TH (N q r )m
is surjective by the following remark.
Remark 2.11. When we assume that m is of type (B) then the Uq operator
is redundant in Tm = TH (N q r )m . To see this, first assume that Tm is reduced
and consider the GL2 (Tm ) representation of Gal(Q/Q) associated to the madic Tate module. Pick a q Iq , the inertia group in Dq in Gal(Q/Q), such
that q (q ) 6= 1. Then because the eigenvalues of q are distinct mod m we can
diagonalize the representation with respect to q . If Frobq is a Frobenius in Dq ,
then in the GL2 (Tm ) representation the image of Frob q normalizes Iq and we
can recover Uq as the entry of the matrix giving the value of Frob q on the unit
eigenvector for q . This is by the q ' (q ) theorem of Langlands as before
(cf. [Ca1]) applied to each of the representations obtained from maps T m
Of, . Since the representation is defined over the Zp -algebra Ttr
m generated by
the traces, the same reasoning applied to Ttr
shows
that
U

Ttr
q
m
m.

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

501

If Tm is not reduced the above argument shows only that there is an


r
operator vq Ttr
m such that (Uq vq ) is nilpotent. Now TH (N q ) can be
r
viewed as a ring of endomorphisms of S2 (H (N q )), the space of cusp forms
of weight 2 on H (N q r ). There is a restriction map TH (N q r ) TH (N q r )new
where TH (N q r )new is the image of TH (N q r ) in the ring of endomorphisms of
S2 (H (N q r ))/S2 (H (N q r ))odd , the old part being defined as the sum of two
copies of S2 (H (N q r1 )) mapped via z z and z qz. One sees that on
m-completions Tm ' (TH (N q r )new )m since the conductor of m is divisible by
q r . It follows that Uq Tm satisfies an equation of the form P (Uq ) = 0 where
P (x) is a polynomial with coefficients in W (km ) and with distinct roots. By
extending scalars to O (the integers of a local field containing W (k m )) we can
assume that the roots lie in T ' Tm O.
W (km )

Since (Uq vq ) is nilpotent it follows that P (vq )r = 0 for some r. Then


since vq Ttr
m which is reduced, P (vq ) = 0. Now consider the map T T(p)
where the product is taken over the localizations of T at the minimal primes
p of T . The map is injective since the associated primes of the kernel are all
maximal, whence the kernel is of finite cardinality and hence zero. Now in
each T(p) , Uq = i and vq = j for roots i , j of P (x) = 0 because the roots
are distinct. Since Uq vq p for each p it follows that i = j for each p
whence Uq = vq in each T(p) . Hence Uq = vq in T also and this finally shows
that Uq Ttr
m in general.
We can therefore define a principal ideal
(q ) = (
b)

using,as previously, that the rings TH 0 (N q r, q r+1 )mq and TH (N q r )m are Gorenstein. We compute (q ) in a similar manner to the type (A) case, but using
this time that Uq Uq = q on the space of forms on H (N q r ) which are new at
q, i.e., the space spanned by forms {f (sz)} where f runs through newforms
r
with q r |level f . To see this let f be any newform
of level divisible by
D
E q and
observe that the Petersson inner product (Uq Uq q)f (rz), f (mz) = 0 for
any m|(N q r /level f ) by [Li, Th. 3(ii)]. This shows that (Uq Uq q)f (rz),
a priori a linear combination of {f (mi z)}, is zero. We obtain the following
result.

Proposition 2.12. Suppose that m is a maximal ideal of TH (N q r )


associated to an irreducible m of type (B) at q, i.e., satisfying (2.19) including
the hypothesis that H cantains Sp . (Again q - N p.) Then

(q ) = (q 1) .

Finally we have the case where m is of type (C) at q. We assume then


that m is a maximal ideal of TH (N q r ) where H contains the Sylow p-subgroup

502

ANDREW JOHN WILES

Sp of (Z/q r Z) and that


H 1 (Qq , W ) = 0

(2.20)

where W is defined as in (1.6) but with m replacing 0 , i.e., W = ad0 m .


This time we let mq be the inverse image of m in TH 0 (N q r ) under the
natural restriction map TH 0 (N q r ) TH (N q r ) with H 0 defined as in the
case of type B. We set
(q ) = ( )

where : TH 0 (N q r )mq TH (N q r )m is the induced map on the completions,


which as before are Gorenstein rings. The proof of the following proposition
is analogous (but simpler) to the proof of Proposition 2.10. (Notice that the
proposition does not require the condition that m satisfy (2.20) but this is the
case in which we will use it.)
Proposition 2.13. Suppose that m is a maximal of TH (N q r ) associated to an irreducible m with H containing the Sylow p-subgroup of (Z/q r Z) .
Then
(q ) = (q 1).
Finally, in this section we state Proposition 2.4 in the case q 6= p as this
will be used in Chapter 3. Let q be a prime, q - N p and let S1 denote the ring
(2.21)

TH (N )[U1 ]/{U12 Tq U1 + hqiq} End(JH (N )2 )

where : JH (N, q) JH (N )2 is the map defined after (2.10) and U1 is the


matrix

Tq hqi
.
q
0
Thus, U
q = U1 .
Also hqi is defined as hnq i where nq q(N ), nq 1(q).
Let m1 be a maximal ideal of S1 containing the image of m, where m is a
maximal ideal of TH (N ) with associated irreducible m . We will also assume
that m (Frob q) has distinct eigenvalues. (We will only need this case and
it simplifies the exposition.) Let mq denote the corresponding maximal ideals of TH (N, q) and TH (N q) under the natural restriction maps TH (N q)
TH (N, q) S1 . The corresponding maps on completions are
(2.22)

TH (N q)mq TH (N, q)mq

S1,m1 ' TH (N )m

W (km )

W (k + )

where k + is the extension of km generated by the eigenvalues of {m (Frob q)}.


That k + is either equal to km or its quadratic extension. The maps , are
surjective, the latter because Tq is a trace in the 2-dimensional representation

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

503

to GL2 (TH (N )m ) given after Theorem 2.1 and hence is redundant by the

Cebotarev
density theorem. The completions are Gorenstein by Corollary 2 to
Theorem 2.1 and so we define invariant ideals of S1,m1
(2.23)

() = ( ),

(0 ) = ( ) ([
).

Let q be the image of U1 in TH (N )m

W (km )

W (k + ) under the last isomorphism

in (2.22). The proof of Proposition 2.4 yields


Proposition 2.40 . Suppose that m is irreducible where m is a maximal
ideal of TH (N ) and that m (Frob q) has distinct eigenvalues. Then
() = (q2 hqi),

(0 ) = (q2 hqi)(q 1).


Remark. Note that if we suppose also that q 1(p) then () is the unit
ideal and is an isomorphism in (2.22).

3. The main conjectures


As we suggested in Chapter 1, in order to study the deformation theory
of 0 in detail we need to assume that it is modular. That this should always
be so for det 0 odd was conjectured by Serre. Serre also made a conjecture
(the -conjecture) making precise where one could find a lifting of 0 once
one assumed it to be modular (cf. [Se]). This has now been proved by the
combined efforts of a number of authors including Ribet, Mazur, Carayol,
Edixhoven and others. The most difficult step was to show that if 0 was
unramified at a prime l then one could find a lifting in which l did not divide
the level. This was proved (in slightly less generality) by Ribet. For a precise
statement and complete references we refer to Diamonds paper [Dia] which
removed the last restrictions referred to in Ribets survey article [Ri3]. The
following is a minor adaptation of the epsilon conjecture to our situation which
can be found in [Dia, Th. 6.4]. (We wish to use weight 2 only.) Let N ( 0 ) be
the prime to p part of the conductor of 0 as defined for example in [Se].
Theorem 2.14. Suppose that 0 is modular and satisfies (1.1) (so in
particular is irreducible) and is of type D = (, , O, M) with = Se, str or fl.
Suppose that at least one of the following
conditions holds (i) p > 3 or (ii) 0
is not induced from a character of Q( 3). Then there exists a newform f
of weight 2 and a prime of Of such that f, is of type D 0 = (, , O 0 , M)
for some O 0 , and such that (f, mod ) ' 0 over Fp . Moreover we can
assume that f has character f of order prime to p and has level N (0 )p(0 )

504

ANDREW JOHN WILES

where (0) = 0 if 0 |Dp is associated to a finite flat group scheme over Zp

and det 0 = , and (0 ) = 1 otherwise. Furthermore in the Selmer case


Ip

we can assume that ap (f ) 2 (Frob p) mod in the notation of (1.2) where


ap (f ) is the eigenvalue of Up .
For the rest of this chapter we will assume that 0 is modular and that
if p = 3 then 0 is not induced from a character of Q( 3). Here and in the
rest of the paper we use the term induced to signify that the representation
is induced after an extension of scalars to the algebraic closure.
For each D = {, , O, M} we will now define a Hecke ring TD except
where is unrestricted. Suppose first that we are in the flat, Slemer or strict
cases. Recall that when referring to the flat case we assume that 0 is not
ordinary and that det 0 |Ip = . Suppose that = {qi } and that N (0 ) =
qisi with si 0. If U ' k 2 is the representation space of 0 we set nq =
dimk (U )Iq where Iq in the inertia group at q. Define M0 and M by
(2.24)

M0 = N (0 )

nq =1
i
qi 6M{p}

qi

qi2 ,

M = M0 p (0 )

nqi =2

where (0 ) = 1 if 0 is ordinary and (0 ) = 0 otherwise. Let H be the


subgroup of (Z/M Z) generated by the Sylow p-subgroup of (Z/qi Z) for each
qi M as well as by all of (Z/qi Z) for each qi M of type (A). Let T0H (M )
denote the ring generated by the standard Hecke operators {Tl for l - M p, hai
for (a, M p) = 1}. Let m0 denote the maximal ideal of T0H (M ) associated to the
f and given in the theorem and let km0 be the residue field T0H (M )/m. Note
that m0 does not depend on the particular choice of pair (f, ) in theorem 2.14.
Then km0 ' k0 where k0 is the smallest possible field of definition for 0 because
km0 is generated by the traces. Henceforth we will identify k0 with km0 . There
is one exceptional case where 0 is ordinary and 0 |Dp is isomorphic to a sum
of two distinct unramified characters (1 and 2 in the notation of Chapter 1,
1). If 0 is not exceptional we define
(2.25(a))

TD = T0H (M )m0

O.

W (k0 )

If 0 is exceptional we let T00H (M ) denote the ring generated by the operators


{Tl for l - M p, hai for (a, M p) = 1, Up }. We choose m00 to be a maximal
ideal of T00H (M ) lying above m0 for which there is an embedding km00 , k (over
k0 = km0 ) satisfying Up 2 (Frob p). (Note that 2 is specified by D.) Then
in the exceptional case km00 is either k0 or its quadratic extension and we define
(2.25(b))

TD = T00H (M )m00

W (km00 )

O.

The omission of the Hecke operators Uq for q|M0 ensures that TD is reduced.

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

505

We need to relate TD to a Hecke ring with no missing operators in order


to apply the results of Section 1.
Proposition 2.15. In the nonexceptional case there is a maximal ideal
m for TH (M ) with m 0H (M ) = m0 and k0 = km , and such that the natural
map T0H (M )m0 TH (M )m is an isomorphism, thus given
TD ' TH (M )m O.
W (k0 )

In the exceptional case the same statements hold with m00 replacing m0 , T00H (M )
replacing T0H (M ) and km00 replacing k0 .
Proof. For simplicity we describe the nonexceptional case indicating where
appropriate the slight modifications needed in the exceptional case. To construct m we take the eigenform f0 obtain from the newform f of Theorem 2.14
by removing the Euler factors at all primes q {M p}. If 0 is ordinary
and f has level prime to p we also remove the Euler factor (1 p ps ) where
p is the non-unit eigenvalue in Of . (By removing Euler factors we mean
take the eigenform whose L-series is that of f with these Euler factors removed.) Then f0 is an eigenform of weight 2 on H (M ) (this is ensured by the
choice of f ) with Of, coefficients. We have a corresponding homomorphism
f0 : TH (M ) Of, and we let m = f1
().
0
Since the Hecke operators we have used to generate T0H (M ) are prime to
the level these is an inclusion with finite index
T0H (M ) ,

Og

where g runs over representatives of the Galois conjugacy classes of newforms


associated to H (M ) and where we note that by multiplicity one Og can also be
described as the ring of integers generated by the eigenvalues of the operators
in T0H (M ) acting on g. If we consider TH (M ) in place of T0H (M ) we get a
similar map but we have to replace the ring Og by the ring
Sg = Og [Xq1 , . . . , Xqr , Xp ]/{Yi , Zp }ri=1
where {p, p1 , . . . , qr } are the distinct primes dividing M p. Here
(2.26)

Xqrii 1 Xqi qi (g) Xqi qi (g)


if qi - level(g)

Yi =
X ri X a (g)
if qi | level(g),
q
q
qi
i
i

where the Euler factor of g at qi (i.e., of its associated L-series) is


s
s
(1qi (g)qis )(1
qi (g)qi ) in the first cases and (1aqi (g)qi ) in the second

case, and qiri || M/level(g) . (We allow aqi (g) to be zero here.) Similarly Zp is

506

ANDREW JOHN WILES

defined by
2

Xp ap (g)Xp + pg (p) if p|M, p - level(g)


Zp =
Xp ap (g)
if p - M

Xp ap (g)
if p|level(g),

where the Euler factor of g at p is (1 ap (g)ps + g (p)p12s ) in the first


two cases and (1 ap (g)ps ) in the third case. We then have a commutative
diagram
Q
T0H (M )
Og
g

(2.27)
y
y
Q
Q
Sg = Og [Xq1 , . . . , Xqr , Xp ]/{Yi , Zp }ri=1
TH (M )
g

where the lower map is given on {Uq , Up or Tp } by Uqi Xqi , Up or


Tp Xp (according as p|M or p - M ). To verify the existence of such a
homomorphism one considers the action of TH (M
Pr) on the space of forms of
weight 2 invariant under H (M ) and uses that j=1 gj (mj z) is a free generator as a TH (M ) C-module where {gj } runs over the set of newforms and
mj = M/level(gj ).
Now we tensor all the rings in (2.27) with Zp . Then completing the top
row of (2.27) with respect to m0 and the bottom row with respect to m we get
a commutative diagram
Q
Q
0
TH (M )m0
Og 0 '
Og,
g
m
g
0
m

(2.28)

y
y
y
Q
Q
'
(Sg )m .
Sg
TH (M )m
m
g

Here runs through the primes above p in each Og for which m0 under
TH 0 (M ) Og . Now (Sg )m is given by

r
(2.29)
(Sg Zp )m ' (Og Zp )[Xq1 , . . . , Xqr , Xp ]/{Yi , Zp }i=1
! m

Q
'
Og, [Xq1 , . . . , Xqr , Xp ]/{Yi , Zp }ri=1
'

|p

|p

Ag,

where Ag, denotes the product of the factors of the complete semi-local ring
Og, [Xq1 , . . . , Xqr , Xp ]/{Yi , Zp }ri=1 in which Xqi is topologically nilpotent for

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

507

qi 6 M and in which Xp is a unit if we are in the ordinary case (i.e., when


p|M ). This is because Uqi m if qi 6 M and Up is a unit at m in the ordinary
case.
Now if m0 then in (Ag, ) we claim that Yi is given up to a unit by
Xqi bi for some bi Og, with bi = 0 if qi 6 M. Similarly Zp is given up to a
unit by Xp p (g) where p (g) is the unit root of x2 ap (g)x + pg (p) = 0 in
Og, if p - level g and p|M and by Xp ap (g) if p|level g or p - M . This
will show that (Ag, )m ' Og, when m0 and (Ag, )m = 0 otherwise.
For qi M and for p, the claim is straightforward. For qi 6 M, it amounts
to the following. Let Ug, denote the 2-dimensional Kg, -vector space with
Galois action via g, and let nqi (g, ) = dim(Ug, )Iqi . We wish to check that
Yi = unit.Xqi in (Ag, )m and from the definition of Yi in (2.26) this reduces
to checking that ri = nqi (g, ) by the q ' (q ) of theorem (cf. [Ca1]). We use
here that qi (g), qi (g) and aqi (g) are p-adic units when they are nonzero since
they are eigenvalues of Frob(qi ). Now by definition the power of qi dividing M
nq
is the same as that dividing N (0 )qi i (cf. (2.21)). By an observation of Livne
(cf. [Liv], [Ca2,1]),

nq nqi (g,)
.
(2.30)
ordqi (level g) = ordqi N (0 )qi i
As by definition qiri ||(M/level g) we deduce that ri = nqi (g, ) as reqired.
We have now shown that each Ag, ' Og, (when m0 ) and it follows
from (2.28) and (2.29) that we have homomorphisms
T0H (M )m0 TH (M )m

g
m0

Og,

where the inclusions are of finite index. Moreover we have seen that U qi = 0
in TH (M )m for qi 6 M. We now consider the primes qi M. We have
to show that the operators Uq for q M are redundant in the sense that
they lie in T0H (M )m0 , i.e., in the Zp -subalgebra of TH (M )m generated by the
{Tl : l - M p, hai : a (Z/M Z) }. For q M of type (A), Uq T0H (M )m0
as explained in Remark 2.9 are for q M of type (B), Uq T0H (M )m0 as
explained in Remark 2.11. For q M of type (C) but not of type (A), U q = 0
by the q ' (q ) theorem (cf. [Ca1]). For in this case nq = 0 whence also
nq (g, ) = 0 for each pair (g, ) with m0 . If 0 is strict or Selmer at p then
Up can be recovered from the two-dimensional representation (described after
the corollaries to Theorem 2.1) as the eigenvalue of Frob p on the (free, of rank
one) unramified quotient (cf. Theorem 2.1.4 of [Wi4]). As this representation
is defined over the Zp -subalgebra generated by the traces, it follows that Up
is contained in this subring. In the exceptional case Up is in T00H (M )m00 by
definition.
Finally we have to show that Tp is also redundant in the sense explained
above when p - M . A proof of this has already been given in Section 2 (Ribets

508

ANDREW JOHN WILES

lemma). Here we give an alternative argument using the Galois representations. We know that Tp m and it will be enough to show that Tp (m2 , p).
Writing km for the residue field TH (M )m /m we reduce to the following situation. If Tp 6 (m2 , p) then there is a quotient
TH (M )m /(m2 , p) km [] = TH (M )m /a
where km [] is the ring of dual numbers (so 2 = 0) with the property that
Tp 7 with 6= 0 and such that the image of T0H (M )m0 lies in km . Let G/Q
denote the four-dimensional km -vector space associated to the representation
: Gal(Q/Q) GL2 (km [])
induced from the representation in Theorem 2.1. It has the form
G/Q ' G0 /Q G0 /Q
where G0 is the corresponding space associated to 0 by our hypothesis that
the traces lie in km . The semisimplicity of G/Q here is obtained from the main
theorem of [BLR]. Now G/Qp extends to a finite flat group scheme G/Zp .
Explicitly it is a quotient of the group scheme JH (M )m [p]/Zp . Since extensions
to Zp are unique (cf. [Ray1]) we know
G/Zp ' G0 /Zp G0 /Zp .
Now by the Eichler-Shimura relation we know that in JH (M )/Fp
Tp = F + hpiF T .
Since Tp m it follows that F + hpiF T = 0 on G0 /Fp and hence the same holds
on G/Fp . But Tp is an endomorphism of G/Zp which is zero on the special
fibre, so by [Ray1, Cor. 3.3.6], Tp = 0 on G/Zp . It follows that Tp = 0 in km []
which contradicts our earlier hypothesis. So Tp (m2 , p) as required. This
completes the proof of the proposition.

From the proof of the proposition it is also clear that m is the unique maximal ideal of TH (M ) extending m0 and satisfying the conditions that Uq m
for q {M p} and Up 6 m if 0 is ordinary. For the rest of this chapter
we will always make this choice of m (given 0 ).
Next we define TD in the case when D = (ord, , O, M). If n is any
ordinary maximal ideal (i.e. Up 6 n) of TH (N p) with N prime to p then Hida
has constructed a 2-dimensional Noetherian local Hecke ring
T = eTH (N p )n := lim eTH (N pr )nr

which is a = Zp [[T ]]-algebra satisfying T /T ' TH (N p)n . Here nr is the


inverse image of n under the natural restriction map. Also T = lim h1 + N pi 1

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

509

and e = lim
U r! . For an irreducible 0 of type D we have defined TD0 in
p
r
(2.25(a)), where D 0 = (Se, , O, M) by
TD0 ' TH (M0 p)m

W (km )

O,

the isomorphism coming from Proposition 2.15. We will define T D by


(2.31)

TD = eTH (M0 p )m

W (km )

O.

In particular we see that


TD /T ' TD0 ,

(2.32)

i.e., where D 0 is the same as D but with Selmer


ord. Moreover if

replacing
n
p
pn (k2)
q is a height one prime ideal of TD containing (1 + T ) (1 + N p)
for any integers n 0, k 2, then TD /q is associated to an eigenform in a
natural way (generalizing the case n = 0, k = 2). For more details about these
rings as well as about -adic modular forms see for example [Wi1] or [Hi1].
For each n 1 let Tn = TH (M0 pn )mn . Then by the argument given
after the statement ofTheorem 2.1 we can construct a Galois representation n
unramified outside M p with values in GL2 (Tn ) satisfying tracen (Frobl) = Tl ,
det n (Frob l) = lhli for (l, M p) = 1. These representations can be patched
together to give a continuous representation
(2.33)

= lim n : Gal(Q /Q) GL2 (TD )

where is the set of primes dividing M p. To see this we need to check the
commutativity of the maps
R Tn
&
Tn1
where the horizontal maps are induced by n and n1 and the vertical map is
the natural one. Now the commutativity is valid on elements of R , which are
traces or determinants in the universal representation, since trace(Frob l) 7 T l
under both horizontal maps and similarly for determinants. Here R is the
universal deformation ring described in Chapter 1 with respect to 0 viewed
with residue field k = km . It suffices then to show that R is generated (topologically) by traces and this reduces to checking that there are no nonconstant
tr
deformations of 0 to k[] with traces lying in k (cf. [Ma1, 1.8]). For then if R
denotes the closed W (k)-subalgebra of R generated by the traces we see that
tr
R
(R /m2 ) is surjective, m being the maximal ideal of R , from which
tr
we easily conclude that R
= R . To see that the condition holds, assume

510

ANDREW JOHN WILES

that a basis is chosen so that 0 (c) = ( 10 10 ) for a chosen complex cunjugation


c and 0 () = ( ac db ) with b = 1 and c 6= 0 for some . (This is possible
because 0 is irreducible.) Then any deformation [p] to k[] can be represented
by a representation such that (c) and () have the same properties. It
follows easily that if the traces of lie in k then takes values in k whence
it is equal to 0 . (Alternatively one sees that the universal representation can
tr
be defined over R
by diagonalizing complex conjugation as before. Since the
tr
two maps R Tn1 induced by the triangle are the same, so the associated representations are equivalent, and the universal property then implies
the commutativity of the triangle.)
The representations (2.33) were first exhibited by Hida and were the original inspiration for Mazurs deformation theory.
For each D = {, , O, M} where is not unrestricted there is then a
canonical surjective map
D : R D T D
which induces the representations described after the corollaries to Theorem 2.1
and in (2.33). It is enough to check this when O = W (k0 ) (or W (km00 ) in the
exceptional case). Then one just has to check that for every pair (g, ) which
appears in (2.28) the resulting representation is of type D. For then we claim
g
that the image of the canonical map RD T
D = Og, is TD where here
denotes the normalization. (In the case where is ord this needs to be checked
instead for Tn O for each n.) For this we just need to see that RD is
W (k0 )

generated by traces. (In the exceptional case we have to show also that U p is
in the image. This holds because it can be identified, using Theorem 2.1.4 of
[Wi1], with the image of u RD where u is the eigenvalue of Frob p on the
2
unique rank one unramified quotient of RD
with eigenvalue 2 (Frobp) which
is specified in the definition of D.) But we saw above that this was true for
R . The same then holds for RD as R RD is surjective because the map
on reduced cotangent spaces is surjective (cf. (1.5)). To check the condition
on the pairs (g, ) observe first that for q M we have imposed the following
conditions on the level and character of such gs by our choice of M and H:

q of type (A): q|| level g, det g, = 1,


Iq

q of type (B): cond q || level g, det g,

Iq

q of type (C): det g,

Iq

= q ,

is the Teichm
uller lifting of det 0 .

In the first two cases the desired form of q,

Iq

Dq

then follows from the

q ' (q ) theorem of Langlands (cf. [Ca1]). The third case is already of

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

511

type (C). For q = p one can use Theorem 2.1.4 of [Wi1] in the ordinary case,
the flat case being well-known.
The following conjecture generalized a fundamantal conjecture of Mazur
and Tilouine for D = (ord, , W (k0 ), ); cf. [MT].
Conjecture 2.16. D is an isomorphism.
Equivalently this conjecture says that the representation described after
the corollaries to Theorem 2.1 (or in (2.33) in the ordinary case) is the universal
one for a suitable choice of H, N and m. We remind the reader that throughout
this section we are assuming that if p = 3 then 0 is not induced from a
character of Q( 3 ).
Remark. The case of most interest to us is when p = 3 and 0 is a
representation with values in GL2 (F3 ). In this case it is a theorem of Tunnell,
extending results of Langlands, that 0 is always modular.
For GL2 (F3 ) is a

double cover of S4 and can be embedded in GL2 (Z[ 2 ]) whence in GL2 (C);
cf. [Se] and [Tu]. The conjecture will be proved with a mild restriction on 0
at the end of Chapter 3.
Remark. Our original restriction to the types (A), (B), (C) for 0 was
motivated by the wish that the deformation type (a) be of minimal conductor among its twists, (b) retain property (a) under unramified base changes.
Without this kind of stability it can happen that after a base change of Q to an
extension unramified at , 0 has smaller
conductor for some character

Q
. The typical example of this is where 0 = IndKq () with q 1(p) and
Dq

is a ramified character over K, the unramified quadratic extension of Q q .


What makes this difficult for us is that there are then nontrivial ramified local
Q
deformations (IndKp for a ramified character of order p of K) which we
cannot detect by a change of level.

For the purposes of Chapter 3 it is convenient to digress now in order to


introduce a slight varient of the deformation rings we have been considering
so far. Suppose that D = (, , O, M) is a standard deformation problem
(associated to 0 ) with = Se, str or fl and suppose that H, M0 , M and m
are defined as in (2.24) and Proposition 2.15. We choose a finite set of primes
Q = {q1 , . . . , qr } with qi - M p. Furthermore we assume that each qi 1(p)
and that the eigenvalues {i , i } of 0 (Frob qi ) are distinct for each qi Q.
This last condition ensures that 0 does not occur as the residual representation
of the -adic representation associated to any newform on H (M, q1 . . . qr )
where any qi divides the level of the form. This can be seen directly by looking
at (Frob qi ) in such a representation or by using Proposition 2.4 at the end of
Section 2. It will be convenient to assume that the residue field of O contains
i , i for each qi .

512

ANDREW JOHN WILES

Pick i for each i. We let DQ be the deformation problem associated to


representations of Gal(QQ /Q) which are of type D and which in addition
satisfy the property that at each qi Q

1,qi

(2.34)

2,qi
D qi

with 2,qi unramified and 2,qi (Frob qi ) i mod m for a suitable choice of
basis. One checks as in Chapter 1 that associated to DQ there is a universal
deformation ring RQ . (These new contions are really variants on type (B).)
We will only need a corresponding Hecke ring in a very special case and it
is convenient in this case to define it using all the Hecke operators. Let us now
set N = N (0 )p(0 ) where (0 ) in as defined in Theorem 2.14. Let m0 denote
a maximal ideal of TH (N ) given by Theorem 2.14 with the property that
m0 ' 0 over Fp relative to a suitable embedding of km0 k over k0 . (In the
exceptional case we also impose the same condition on m0 about the reduction
of Up as in the definition of TD in the exceptional case before (2.25)(b).) Thus
m0 ' f, mod over the residue field of Of, for some choice of f and
with f of level N . By dropping one of the Euler factors at each qi as in the
proof of Proposition 2.15, we obtain a form and hence a maximal ideal m Q of
TH (N q1 . . . qr ) with the property that mQ ' 0 over Fp relative to a suitable
embedding kmQ k over km0 . The field kmQ is the extension of k0 (or km00 in
the exceptional case) generated by the i , i . We set
(2.35)

TQ = TH (N q1 . . . qr )mQ

W (kmQ )

O.

It is easy to see directly (or by the arguments of Proposition 2.15) that


TQ is reduced and that there is an inclusion with finite index
Y
Q =
(2.36)
QQ , T
Og,

where the product is taken over representatives of the Galois conjugacy classes
of eigenforms g of level N q1 . . . qr with mQ . Now define DQ using the
choices i for which Uqi i under the chosen embedding kmQ k. Then
each of the 2-dimensional representations associated to each factor O g, is of
type DQ . We can check this for each q Q using either the q ' (q )
theorem (cf. [Ca1]) as in the case of type (B) or using the Eichler-Shimura
relation if q does not divide the level of the newform associated to g. So we get
Q and hence also an O-algebra map
a homomorphism of O-algebras RQ T
(2.37)

Q : R Q TQ

as RQ is generated by traces. This is not an isomorphism in general as we


have used N in place of M . However it is surjective by the arguments of
Proposition 2.15. Indeed, for q|N (0 )p, we check that Uq is in the image of

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

513

Q using the arguments in the second half of the proof of Proposition 2.15.
For q Q we use the fact that Uq is the image of the value of 2,q (Frob q)
in the universal representation;cf. (2.34). For q|M , but not of the previous

types, Tq is a trace in TQ and we can apply the Cebotarev


density theorem
to show that it is in the image of Q .
Finally, if there is a section : TQ O, then set pQ = ker and let p denote the 2-dimensional representation to GL2 (O) obtained from TQ mod pQ .
Let V = Adp K/O where K is the field of fractions of O. We pick a basis
O

for p satisfying (2.34) and then let


V

(qi )

(2.38)
Adm K/O =
O

a
0

0
0

a
c

b
d

: a, b, c, d O K/O
O

and let V(qi ) = V /V (qi ) . Then as in Proposition 1.2 we have an isomorphism


(2.39)

1
HomO (pRQ /p2RQ , K/O) ' HD
(QQ /Q, V )
Q

where pRQ = ker( Q ) and the second term is defined by


(2.40)

1
HD
(QQ /Q, V
Q

) = ker :

1
HD
(QQ /Q, V

r
Y

H 1 (Qunr
qi , V(qi ) ).

i=1

We return now to our discussion of Conjecture 2.16. We will call a deformation theory D minimal if = M {p} and is Selmer, strict or flat.
This notion will be critical in Chapter 3. (A slightly stronger notion of minimality is described in Chapter 3 where the Selmer condition is replaced, when
possible, by the condition that the representations arise from finite flat group
schemes - see the remark after the proof of Theorem 3.1.) Unfortunately even
up to twist, not every 0 has an associated minimal D even when 0 is flat or
ordinary at p as explained in the remarks after Conjecture 2.16. However this
could be achieved if one replaced Q by a suitable finite extension depending
on 0 .
Suppose now that f is a (normalized) newform, is a prime of Of above p
and f, a deformation of 0 of type D where D = (, , Of, , M) with = Se,
str or fl. (Strictly speaking we may be changing 0 as we wish to choose its
field of definition to be k = Of, /.) Suppose further that level(f )|M where
M is defined by (2.24).
Now let us set O = Of, for the rest of this section. There is a homomorphism
(2.41)

= D,f : TD O

514

ANDREW JOHN WILES

whose kernel is the prime ideal pT,f associated to f and . Similary there is
a homomorphism
RD O
whose kernel is the prime ideal pR,f associated to f and and which factors
through f . Pick perfect pairings of O-modules, the second one TD -bilinear,
(2.42)

O O O,

h , i : TD TD O.

In each case we use the term perfect pairing to signify that the pairs of induced
maps O HomO (O, O) and TD HomO (TD , O) are isomorphisms. In
addition the second one is required to be TD -linear. The existence of the second
pairing is equivalent to the Gorenstein property, Corollary 2 of Theorem 2.1,
as we explain below. Explicitly if h is a generator of the free T D -module
HomO (TD , O) we set ht1 , t2 i = h(t1 t2 ).
A priori TH (M )m (occurring in the description of TD in Proposition 2.15)
is only Gorenstein as a Zp -algebra but it follows immediately that it is also a
Gorenstein W (km )-algebra. (The notion of Gorenstein O-algebra is explained
in the appendix.) Indeed the map

HomW (km ) TH (M )m , W (km ) HomZp TH (M ), Zp


given by 7 trace is easily seen to be an isomorphism, as the reduction
mod p is injective and the ranks are equal. Thus TD is a Gorenstein O-algebra.
Now let
: O TD be the adjoint of with respect to these pairings.
Then define a principal ideal () of TD by
() = (D,f ) = (
(1)).
This is well-defined independently of the pairings and moreover one sees that
TD / is torsion-free (see the appendix). From its description () is invariant
under extensions of O to O 0 in an obvious way. Since TD is reduced () 6= 0.
One can also verify that
(2.43)

() = h, i

up to a unit in O.
We will say that D1 D if we obtain D1 by relaxing certain of the
hypotheses on D, i.e., if D = (, , O, M) and D1 = (, 1 , O1 , M1 ) we allow
that 1 , any O1 , M M1 (but of the same type) and if is Se or str
in D it can be Se, str, ord or unrestricted in D1 , if is fl in D1 it can be fl
or unrestricted in D1 . We use the term restricted to signify that is Se, str,
fl or ord. The following theorem reduces conjecture 2.16 to a class number
criterion. For an interpretation of the right-hand side of the inequality in
the theorem as the order of a cohomology group, see Propostion 1.2. For an
interpretation of the left-hand side in terms of the value of an inner product,
see Proposition 4.4.

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

515

Theorem 2.17. Assume, as above, that f, is a deformation of 0 of


type D = (, , O = Of, , M) with = Se, str or fl. Suppose that
#O/(D,f ) #pR,f /p2R,f .

Then
(i) D1 : RD1 ' TD1 is an isomorphism for all (restricted) D1 D.
(ii) TD1 is a complete intersection (over O1 if is Se, str or fl) for all restricted D1 D.
Proof. Let us write T for TD , pT for pT,f , pR for pR,f and for ,f .
Then we always have
(2.44)

#O/ #pT /p2T .

(Here and in what follows we sometimes write for () if the context makes
this reasonable.) This is proved as follows. T/ acts faithfully on p T . Hence
the Fitting ideal of pT as a T/-module is zero. The same is then true of
pT /p2T as an O/ = (T/)/pT -module. So the Fitting ideal of pT /p2T as an
O-module is contained in () and the conclusion is then easy. So together with
the hypothesis of the theorem we get inequality (and hence equalities)
#O/() #pR /p2R #pT /p2T #O/().

By Proposition 2 of the appendix T is a complete intersection over O. Part (ii)


of the theorem then follows for D. Part (i) follows for D from Proposition 1 of
the appendox.
We now prove inductively that we can deduce the same inequality
(2.45)

#O1 /D1 ,f #pR1 ,f /p2R1 ,f

for D1 D and R1 = RD1 . The above argument will then prove the theorem
for D1 . We explain this first in the case D1 = Dq where Dq differs from D only
in replacing by {q}. Let us write Tq for TDq , pR,q for pR,f with R = RDq
and q for Dq ,f . We recall that Uq = 0 in Tq .
We choose isomorphisms
(2.46)

T ' HomO (T, O),

Tq ' HomO (Tq , O)

coming from the fact that each of the rings is a Gorenstein O-algebra. If
q : Tq T is the natural map we may consider the element q = q
q T
where the adjoint is with respect to the above isomorphisms. Then it is clear
that

(2.47)
q (q ) = (q )

as principal ideals of T. In particular (q ) = (q ) in O.


Now it follows from Proposition 2.7 that the principal ideal ( q ) is given by
(2.48)

2
2
2
(q ) = (q 1) (Tq hqi(1 + q) ) .

516

ANDREW JOHN WILES

In the statement of Proposition 2.7 we used Zp -pairings


T ' HomZp (T, Zp ),

Tq ' HomZp (Tq , Zp )

to define (q ) = (q
q ). However, using the description of the pairings
as W (km )-algebras derived from these Zp -pairings in the paragraph following
(2.42) we see that the ideal (q ) is unchanged when we use W (km )-algebra
pairings, and hence also when we extend scalars to O as in (2.42).
On the other hand
n

o
#pR,q /p2R,q #pR /p2R # O/(q 1)2 Tq2 hqi(1 + q)2
by Propositions 1.2 and 1.7. Combining this with (2.47) and (2.48) gives (2.45).
If M 6= we use a similar argument to pass from D to Dq where this time
Dq signifies that D is unchanged except for dropping q from M. In each of
types (A), (B), and (C) one checks from Propositions 1.2 and 1.8 that
#pR,q /p2R,q #pR /p2R #H 0 (Qq , V ).
This is in agreement with Propositions 2.10, 2.12 and 2.13 which give the
corresponding change in by the method described above.
To change from an O-algebra to an O1 -algebra is straightforward (the
complete intersection property can be checked using [Ku1, Cor. 2.8 on p. 209]),
and to change from Se to ord we use (1.4) and (2.32). The change from str
to ord reduces to this since by Proposition 1.1 strict deformations and Selmer
deformations are the same. Note that for the ord case if R is a local Noetherian
ring and f R is not a unit and not a zero divisor, then R is a complete
intersection if and only if R/f is (cf. [BH, Th. 2.3.4]). This completes the
proof of the theorem.

Remark 2.18. If we suppose in the Selmer case that f has level N with
p - N we can also consider the ring TH (M0 )m0 (with M0 as in (2.24) and m0
defined in the same way as for TH (M )). This time set
T0 = TH (M0 )m0

W (km0 )

O,

T = TH (M )m

W (km )

O.

Define 0 , , p0 and p with respect to these rings, and let (p ) = p


p where
p : T T0 and the adjoint is taken with respect to O-pairings on T and T0 .
We then have by Proposition 2.4



= (a2p hpi)
(2.49)
(p ) = ( p ) = Tp2 hpi(1 + p)2
as principal ideals of T , where ap is the unit root of x2 Tp x + phpi = 0.

Remark. For some earlier work on how deformation rings change with
see [Bo].

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

517

Chapter 3
In this chapter we prove the main results about Conjecture 2.16. We
begin by showing that bound for the Selmer group to which it was reduced
in Theorem 2.17 can be checked if one knows that the minimal Hecke ring
is a complete intersection. Combining this with the main result of [TW] we
complete the proof of Conjecture 2.16 under a hypothesis that ensures that a
minimal Hecke ring exists.

Estimates for the Selmer group


Let 0 : Gal(Q /Q) GL2 (k) be an odd irreducible representation which
we will assume is modular. Let D be a deformation theory of type (, , O, M)
such that 0 is type D, where is Selmer, strict or flat. We remind the reader
that k is assumed to be the residue field of O. Then as explained in Theorem
2.14, we can pick a modular lifting f, of 0 of type D (altering k if necessary
and replacing O by a ring
containing Of, ) provided that 0 is not induced
from a character of Q( 3 ) if p = 3. For the rest of this chapter, we will
make the assumption that 0 is not of this exceptional type. Theorem 2.14 also
specifies a certain minimum level and character for f and in particular ensures
that we can pick f to have level prime to p when 0 |Dp is associated to a finite
flat group scheme over Zp and det 0 |Ip = .
In Chapter 2, Section 3, we defined a ring TD associated to D. Here we
make a slight modification of this ring. In the case where is Selmer and 0 |Dp
is associated to a finite flat group scheme and det 0 |Ip = we set
(3.1)

TD0 = T0H (M0 )m00

W (k0 )

with M0 as in (2.24), H defined following (2.24) (it is actually a subgroup


of (Z/M0 Z) ) and m00 the maximal ideal of T0H (M0 ) associated to 0 . The
same proof as in Proposition 2.15 ensures that there is a maximal ideal m 0 of
TH (M0 ) with m0 T0H (M0 ) = m00 and such that the natural map
(3.2)

TD0 = T0H (M0 )m00

O TH (M0 )m0

W (k0 )

W (k0 )

is an isomorphism. The maximal ideal m0 which we choose is characterized by


the properties that m0 = 0 and Uq m0 for q M {p}. (The value of
Tp or of Uq for q M is determined by the other operators; see the proof of
Proposition 2.15.) We now define TD0 in general by the following:

518

ANDREW JOHN WILES

TD0 is given by (3.1) if is Se and 0 |Dp is associated


to a finite flat group scheme over Zp and
det 0 |Ip = ;
(3.3)
TD0 = TD if is str or fl, or 0 |Dp is not associated
to a finite flat group scheme over Zp , or
det 0 |Ip 6= .
We choose a pair (f, ) of minimum level and character as given by Theorem 2.14 and this gives a homomorphism of O-algebras
f : TCalD0 O Of, .
We set pT,f = ker f and similarly we let pR,f denote the inverse image of pT,f
in RD . We define a principal ideal (T,f ) of TD0 by taking an adjoint
f of f
with respect to parings as in (2.42) and write
T,f = (
f (1)).
Note that pT,f /p2T,f is finite and f (T,f ) 6= 0 because TD0 is reduced. We
also write T,f for f (T,f ) if the context makes this usage reasonable. We let
Vf = Ad p K/O where p is the extension of scalars of f, to O.
O

P
Theorem 3.1. Assume that D is minimal,i.e.,
= M {p}, and that
q
p1
(1) 2 p . Then
0 is absolutely irreducible when restricted to Q
1
(i) #HD
(Q /Q, Vf ) #(pT,f /p2T,f )2 cp /#(O/T,f )

where cp = #(O/Up2 hpi) < when 0 is Selmer and 0 |Dp is associated to


a finite flat group scheme over Zp and det 0 |Ip = , and cp = 1 otherwise;
(ii) if TD0 is a complete intersection over O then (i) is an equality, RD '
TD and TD is a complete intersection.
In general, for any (not necessarily minimal) D of Selmer, strict or flat
1
type, and any f, of type D, #HD
(Q /Q, Vf ) < if 0 is as above.
Remarks. The finiteness was proved by Flach in [Fl] under some restrictions on f, p and D by a different method. In particular, he did not consider
the strict case. The bound we obtain in (i) is in fact the actual order of
1
HD
(Q /Q, Vf ) as follows from the main result of [TW] which proves the hypothesis of part (ii). Then applying Theorem 2.17 we obtain the order of this
group for more general Ds associated to 0 under the condition that a minimal
D exists associated to 0 . This is stated in Theorem 3.3.

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

519

The case where the projective representation associated to 0 is dihedral


does not always have the property that a twist of it has an associated minimal
D. In the case where the associated quadratic field is imaginary we will give a
different argument in Chapter 4.
Proof. We will assume throughout the proof that D is minimal, indicating
only at the end the slight changes needed fot the final assertion of the theorem.
Let Q be a finite set of primes disjoint from satisfying q 1(p) and 0 (Frobq)
having distinct eigenvalues for each q Q. For the minimal deformation
problem D = (, , O, M), let DQ be the deformation problem described before
(2.34); i.e., it is the refinement of (, Q, O, M) obtained by imposing the
additional restriction (2.34) at each q Q. (We will assume for the proof that
O is chosen so O/ = k contains the eigenvalues of 0 (Frob q) for each q Q.)
We set
T = T D0 ,

R = RD

and recall the definition of TQ and RQ from Chapter 2, 3 (cf. (2.35)). We


write V for Vf and recall the definition of V(q) following (2.38). Also remember
that mQ is a maximal ideal of TH (N q1 . . . qr ) as in (2.35) for which mQ ' 0
p (recall that this uses the same choice of embedding km k as in
over F
Q
the definition of TQ ). We use mQ also to denote the maximal ideal of TQ if
the context makes this reasonable.
Consider the exact and commutative diagram
0

1 (Q /Q, V )
HD

|o

|o

(pR /p2R )

(pRQ /p2R )
Q

1 (Q
HD
Q /Q, V )

qQ

(pTQ /p2T )
Q

unr

(q) )Gal(Qq
H 1 (Qunr
q ,V

/Qq )

(pT /p2T )

uQ

KQ 0

where KQ is by definition the cokernel in the horizontal sequence and denotes


HomO ( , K/O) for K the field of fractions of O. The key result is:
Lemma 3.2.
satisfying

The map Q is injective for any finite set of primes Q

q 1(p), Tq2 6 hqi(1 + q)2 mod m f or all q Q.

Proof. Note that the hypotheses of the lemma ensure that 0 (Frob q) has
distinct eigenvaluesw for each q Q. First, consider the ideal aQ of RQ defined

520

ANDREW JOHN WILES

by

ai
(3.4) aQ = ai 1, bi , ci , di 1 :
ci

bi
di

= DQ (i ) with i Iqi , qi Q .

Then the universal property of RQ shows that RQ /aQ ' R. This permits us
to identify (pR /p2R ) as
(pR /p2R ) = {f (pRQ /p2RQ ) : f (aQ ) = 0}.
If we prove the same relation for the Hecke rings, i.e., with T and TQ replacing
R and RQ then we will have the injectivity of Q . We will write aQ for the
image of aQ in TQ under the map Q of (2.37).
It will be enough to check that for any q Q0 , Q0 a subset of Q, TQ0 /
aq '
TQ0 {q} where aq is defined as in (3.4) but with Q replaced by q. Let
Q
N 0 = N (0 )p(0 ) qi Q0 {q} qi where (0 ) is as defined in Theorem 2.14.
q /Qq ) which restricts to a generator
Then take an element Iq Gal(Q
of Gal(Q(N 0 q /Q(N 0 )). Then det() = htq i TQ0 in the representation to
GL2 (TQ0 ) defined after Theorem 2.1. (Thus tq 1(N 0 ) and tq is a primitive
root mod q.) It is easily checked that
(3.5)

' JH (N 0 q)m 0 (Q)[ht

JH (N 0 .q)mQ0 (Q)
q i 1].
Q

Here H is still a subgroup of (Z/M0 Z) . (We use here that 0 is not reducible

for the injectivity and also that 0 is not induced from a character of Q( 3 )
for the surjectivity when p = 3. The latter is to avoid the ramification points of
the covering XH (N 0 q) XH (N 0 , q) of order 3 which can give rise to invariant
divisors of XH (N 0 q) which are not the images of divisors on XH (N 0 , q).)
Now by Corollary 1 to Theorem 2.1 the Pontrjagin duals of the modules
in (3.5) are free of rank two. It follows that
(3.6)

(TH (N 0 q)mQ0 )2 /(htq i 1) ' (TH (N 0 , q)mQ0 )2 .

The hypotheses of the lemma imply the condition that 0 (Frob q) has distinct
eigenvalues. So applying Proposition 2.4 (at the end of 2) and the remark
following it (or using the fact remarked in Chapter 2, 3 that this condition
implies that 0 does not occur as the residual representation associated to any
form which has the special representation at q) we see that after tensoring over
W (kmQ0 ) with O, the right-hand side of (3.6) can be replaced by T2Q0 {q} thus
giving
T2Q0 /aq ' T2Q0 {q} ,
since htq i 1
aq . Repeated inductively this gives the desired relation
aQ ' T, and completes the proof of the lemma.

TQ /

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

521

Suppose now that Q is a finite set of primes chosen as in the lemma. Recall
that from the theory of congruences (Prop. 2.4 at the end of 2)
Y
TQ,f /T,f =
(q 1),
qQ

the factors (q2 hqi) being units by our hypotheses on q Q. (We only need
that the right-hand side divides the left which is somewhat easier.) Also, from
the theory of Fitting ideals (see the proof of (2.44))
#(pT /p2T ) #(O/Tf )

#(pTQ /p2TQ #(O/TQ,f ).


We dedeuce that

#KQ # O

.Y

qQ

(q 1)

t1

where t = #(pT /p2T )/#(O/T,f ). Since the range of Q has order given by
(
)
.Y
# O
(q 1) ,
qQ

we compute that the index of the image of Q is t as Q is injective.


Keeping our assumption on Q from Lemma 3.2, consider the kernel of M
applied to the diagram at the beginning of the proof of the theorem. Then
with M chosen large enough so that M annihilates pT /p2T (which is finite
because T is reduced) we get:
Q

1 (Q /Q, V [M ]) H 1 (Q
M
0 HD

Q /Q, V [ ])
D
Q

0 (pT /p2T )

qQ

unr

(q) [M ])Gal(Qq
H 1 (Qunr
q ,V

/Qq )

(pTQ /p2T ) [M ]
Q

KQ [M ] (pT /p2T ) .

See (1.7) for the justification that M can be taken inside the parentheses in
the first two terms. Let XQ = Q ((pTQ /p2TQ ) [M ]). Then we can estimate
the order of Q (XQ ) using the fact that the image if Q has index at most t.
We get
!

Y
#O/(M , q 1) (1/t) (1/#(pT /p2T )).
(3.7)
#Q (XQ )
qQ

Now we choose Q to be a set of primes with the property that


Y
1

H 1 (Qq , VM )
(3.8)
Q : HD
(Q /Q, VM )
qQ

522

ANDREW JOHN WILES

is injective. We also keep the condition that Q is injective by only allowing


Q to contain primes of the form given in the lemma. In addition, we require
these qs to satisfy q 1(pM ).
To see that this can be done, suppose that x ker Q and x = 0 but
x 6= 0. We have a commutative diagram
Q 1
Q
H (Qq , VM )[]
H 1 (Q /Q, VM []
qQ

|o

H 1 (Q /Q, V )

qQ

|o

H 1 (Qq , V )

the left-hand isomorphisms coming from our particular choices of qs and the
left-hand isomorphism from our hypothesis on 0 . The same diagram will hold
if we replace Q by Q0 = Q {q0 } and we now need to show that we can choose
q0 so that Q0 (x) 6= 0.
The restriction map
Gal(K0 (p )/Q)

H 1 (Q /Q, V ) Hom(Gal(Q/K
0 (p )), V )

has kernel H 1 (K0 (p )/Q, k(1)) by Proposition 1.11 where here K0 is the splitting field of 0 . Now if x H 1 (K0 (p )/Q, k(1)) and x 6= 0 then p = 3 and x
factors through an abelian extension L of Q(3 ) of exponent 3 which is nonabelian over Q. In this exeptional case, L must ramify at some prime q of
Q(3 ), and if q lies over the rational prime q 6= 3 then the composite map
1
unr
M
H 1 (K0 (3 )/Q, k(1)) H 1 (Qunr
q , k(1)) H (Qq , (O/ )(1))

is nonzero on x. But then x is not of type D which gives a contradiction. This


only leaves the possibility that L = Q(3 , 3 3) but again this means that x is
not of type D as locally at the prime above 3, L is not generated by the cube
root of a unit over Q3 (3 ). This argument holds whether or not D is minimal.
So x, which we view in ker Q , gives a nontrivial Galois-equivalent ho

momorphism fx Hom(Gal(Q/K
0 (p )), V ) which factors through an abelian
extension Mx of K0 (p ) of exponent p. Specifically we choose Mx to be the
minimal such extension. Assume first that the projective representation 0
associated to 0 is not dihedral so that Sym2 0 is absolutely irreducible. Pick
a Gal(Mx (pM )/Q) satisfying
(3.9)

(i) 0 () has order m 3 with (m, p) = 1,


(ii) fixes Q(det 0 )(pM ),
(iii) fx ( m ) 6= 0.

To show that this is possible, observe first that the first two conditions can
be achieved by Lemma 1.10(i) and the subsequent remark. Let 1 be an el-

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

523

ement satisfying (i) and (ii) and let


1 denote its image in Gal(K0 (p )/Q).
Then h
1 i acts on G = Gal(Mx /K0 (p )) and under this action G decomposes as G ' G1 G01 where 1 acts trivially on G1 and without fixed points

on G01 . If X is any irreducible Galois stable k-subspace


of fx (G) Fp k then
ker(1 1)|X 6= 0 since Sym2 0 is assumed absolutely irreducible. So also
ker(1 1)|fx (G) 6= 0 and thus we can find G1 such that fx ( ) 6= 0.
Viewing as an element of G we then take
1 = 1 Gal(Mx (pM )/K0 (p )) ' G Gal(K0 (pM )/K0 (p ))
(This decomposition holds because Mx is minimal and because Sym2 0 and
p are distinct from the trivial representation.) Now 1 commutes with 1 and
either fx ((1 1 )m ) 6= 0 or fx (1m ) 6= 0. Since 0 (1 1 ) = 0 (1 ) this gives
(3.9) with at least one of = 1 1 or = 1 . We may then choose q0 so that
Frobq0 = and we will then have Q0 (x) 6= 0. Note that conditions (i) and (ii)
imply that q0 1(p) and also that 0 () has distinct eigenvalues, thus giving
both the hypothses of Lemma 3.2.
If on the other hand 0 is dihedral then we pick s satisfying
(i) 0 () 6= 1,
(ii) fixes Q(pM ),
(iii) fx ( m ) 6= 0,
with m the order of 0 () (and p - m since 0 is dihedral). The first two conditions can be achieved using Lemma 1.12 and, in addition, we can assume that
takes the eigenvalue 1 on any given irreducible Galois stable subspace X
Arguing as above, we find a G1 such that fx ( ) 6= 0 and
of W k.
we proceed as before. Again, conditions (i) and (ii) imply the hypotheses of
Lemma 3.2. So by successively adjoining qs we can assume that Q is chosen
so that Q is injective.
We have thus shown that we can choose Q = {q1 , . . . , qr } to be a finite
set of primes qi 1(pM ) satisfying the hypotheses of Lemma 3.2 as well as the
injectivity of Q in (3.8). By Proposition 1.6, the injectivity of Q implies that
(3.10)

1
#HD
(QQ /Q, Vg [M ]) = h

hq .

qQ

1
Here we are using the convention explained after Proposition
P 1.6 to define H D .
Now, as D was chosen to be minimal, hq = 1 for q
{p} by Proposition 1.8. Also, hq = #(O/M )2 for q Q. If is str or fl then h hp = 1
by Proposition 1.9 (iv) and (v). If is Se, h hp cp by Proposition 1.9 (iii).
(To compute this we can assume that Ip acts on W0 via , as otherwise we

524

ANDREW JOHN WILES

get h hp 1. Then with this hypothesis, (W0n ) is easily verified to be unramified with Frob p acting as Up2 hpi1 by the description of f, |Dp in [Wi1,
Th. 2.1.4].) On the other hand, we have constructed classes which are ramified
at primes in Q in (3.7). These are of type DQ . We also have classes in
Hom(Gal(QQ /Q), O/M ) = H 1 (QQ /Q, O/M ) , H 1 (QQ /Q, VM )
coming from the cyclotomic extension Q(q1 . . . qr ). These are of type D and
disjoint from the classes obtained from (3.7). Combining these with (3.10)
gives
1
#HD
(Q /Q, Vf [M ]) t #(pT /p2T ) cp
as required. This proves part (i) of Theorem 3.1.
Now if we assume that T is a complete intersection we have that t = 1
by Proposition 2 of the appendix. In the strict or flat cases (and indeed in
all cases where cp = 1) this implies that RD ' TD by Proposition 1 of the
appendix together with Proposition 1.2. In the Selmer case we get
(3.11)

#(pT /p2T ) cp = #(O/T,f )cp = #(O/TD,f ) #(pTD /p2TD )

where the central equality is by Remark 2.18 and the right-hand inequality
is from the theory of Fitting ideals. Now applying part (i) we see that the
inequality in (3.11) is an equality. By Proposition 2 of the appendix, T D is
also a complete intersection.
The final assertion of the theorem is proved in exactly the same way on
noting that we only used the minimality to ensure that the hq s were 1. In
general, they are bounded independently of M and easily computed. (The only
point to note is that if f, is multiplicative type at q then f,|Dq does not
split.)

Remark. The ring TD0 defined in (3.1) and used in this chapter should
be the deformation ring associated to the following deformation prblem D 0 .
One alters D only by replacing the Selmer condition by the condition that the
deformations be flat in the sense of Chapter 1, i.e., that each deformation
of 0 to GL2 (A) has the property that for any quotient A/a of finite order,
p -points of a finite
|Dp mod a is the Galois representation associated to the Q
flat group scheme over Zp . (Of course, 0 is ordinary here in contrast to our
usual assumption for flat deformations.)
From Theorem 3.1 we deduce our main results about representations
by using the main result of [TW], which proves the hypothesis of Theorem
3.1 (ii), and then applying Theorem 2.17. More precisely, the main result of
[TW] shows that T is a complete intersection and hence that t = 1 as explained above. The hypothesis of Theorem 2.17 is then given by Theorem 3.1
(i), together with the equality t = 1 (and the central equality of (3.11) in the

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

525

Selmer case) and Proposition 1.2. Strictly speaking, Theorem 1 of [TW] refers
to a slightly smaller class of Ds than those covered by Theorem 3.1 but up to
a twist every such D is covered. It is straightforward to see that it is enough
to check Theorem 3.3 for 0 up to a suitable twist.
Theorem 3.3.

Assume that 0 is modular and absolutely irreducible


q

p1
2
when restricted to Q
(1)
p . Assume also that 0 is of type (A), (B)
or (C) at each q 6= p in . Then the map D : RD TD of Conjecture 2.16
is an isomorphism for all D associated to 0 , i.e., where D = (, , O, M) with
= Se, str, fl or ord. In particular if = Se, str or fl and f is any newform
for which f, is a deformation of 0 of type D then
1
#HD
(Q /Q, Vf ) = #(O/D,f ) <

where D,f is the invariant defined in Chapter 2 prior to (2.43).


The condition at q 6= p in ensures that there is a minimal D associated
to 0 . The computation of the Selmer group follows from Theorem 2.17 and
Proposition 1.2. Theorem 0.2 of the introduction follows from Theorem 3.3,
after it is checked that a twist of a 0 as in Theorem 0.2 satisfies the hypotheses
of Theorem 3.3.

Chapter 4
In this chapter we give a different (and slightly more general) derivation
of the bound for the Selmer group in the CM case. In the first section we
estimate the Selmer group using the main theorem of [Ru 4] which is based on
Kolyvagins method. In the second section we use a calculation of Hida to relate
the -invariant to special values of an L-function. Some of these computations
are valid in the non-CM case also. They are needed if one wishes to give the
order of the Selmer group in terms of the special value of an L-function.
1. The ordinary CM case

In this section we estimate the order of the Selmer group in the ordinary
CM case. In Section 1 we use the proof of the main conjecture by Rubin to
bound the Selmer group in terms of an L-function. The methods are standard
(cf. [de Sh]) and some special cases have been described elsewhere (cf. [Guo]).
In Section 2 we use a calculation of Hida to relate this to the -invariant.
We assume that
(4.1)

= IndQ
L : Gal(Q/Q) GL2 (O)

526

ANDREW JOHN WILES

is the p-adic representation associated to a character : Gal(L/L) O of an


imaginary quadratic field L. We assume that p is unramified in L and that
factors through an extension of L whose Galois group has the form A ' Z p T
where T is a finite group of order prime to p. The ring O is assumed to be the
ring of integers of a local field with maximal ideal and we also assume that
is a Selmer deformation of 0 = mod which is supposed irreducible with
det 0 |Ip = . In particular it follows that p splits in L, p = p
p say, and that

precisely one of , is ramified at p ( being the character ( 1 )

for any representing the nontrivial coset in Gal(Q/Q)/Gal(


Q/L)).
We can
suppose without loss of generality that is ramified at p.
We consider the representation module V ' (K/O)4 (where K is the field
of fractions of O) and the representation is Ad . In this case V splits as
V ' Y (K/O)() K/O

where is the quadratic character of Gal(Q/Q)


associated to L. We let
denote a finite set of primes including all those which ramify in (and in
1
particular p). Our aim is to compute HSe
(Q /Q, V ). The decomposition of
V gives a corresponding decomposition of H 1 (Q /Q, V ) and we can use it to
1
define HSe
(Q /Q, Y ). Since W 0 Y (see Chapter 1 for the definition of W 0 )
1
we can define HSe
(Q /Q, Y ) by
1
0
HSe
(Q /Q, Y ) = ker{H 1 (Q /Q, Y ) H 1 (Qunr
p , Y /W )}.

Let Y be the arithmetic dual of Y , i.e., Hom(Y, p ) Qp /Zp . Where


for / and let L() be the splitting field of . Then we claim that
Gal(L()/L) ' Zp T 0 with T 0 a finite group of order prime to p. For this
it is enough to show that = / factors through a group of order prime
to p since = 2 1 . Suppose that has order m = m0 pr with (m0 , p) = 1.
Then m0 extends to a character of Q which is then unramified at p since the
same is true of . Also it factors through an abelian extension of L with Galois
group isomorphic to Z2p since factors through such an extension with Galois
group isomorphic to Z2p T1 with T1 of order prime to p (the composite of the
splitting fields of and ). It follows that m0 is also unramified outside p,
whence it is trivial. This proves the claim.
Over L there is an isomorphism of Galois modules
Y ' (K/O)() (K/O)( 1 2 ).
1
In analogy to the above we define HSe
(Q /Q, Y ) by
1
0
HSe
(Q /Q, Y ) = ker{H 1 (Q /Q, Y ) H 1 (Qunr
p , (W ) )}.

Analogous definitions apply if Y is replaced by Yn . Also we say informally


0
that a cohomology class is Selmer at p if it vanishes in H 1 (Qunr
p , (W ) ) (resp.

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

527

0
H 1 (Qunr
p , (Wn ) )). Let M be the maximal abelian p-extension of L() unramified outside p. The following proposition generalizes [CS, Prop. 5.9].

Proposition 4.1. There is an isomorphism

1
Hunr
(Q /Q, Y ) Hom(Gal(M /L()), (K/O)())Gal(L()/L)
1
where Hunr
denotes the subgroup of classes which are Selmer at p and unramified everywhere else.

Proof. The sequence is obtained from the inflation-restriction sequence as


follows. First we can replace H 1 (Q /Q, Y ) by

o
n
H 1 (Q /L, (K/O)()) H 1 Q /L, (K/O)( 1 2 )

where = Gal(L/Q). The unramified condition then translates into the


requirement that the cohomology class should lie in
n

o
1
1
1 2
Hunr
(Q
/L,
(K/O)())

H
Q
/L,
(K/O)(

)
.

in p
unr in p

Since interchanges the two groups inside the parentheses it is enough to


compute the first of them, i.e.,
1
Hunr

(4.2)

in p (Q /L, K/O()).

The inflation-restriction sequence applied to this gives an exact sequence


(4.3)

1
0 Hunr

in p (L()/L, (K/O)())
1
Hunr in p (Q /L, (K/O)())

Hom(Gal(M /L()), (K/O)())Gal(L()/L) .

The first term is zero as one easily check using the divisibility of (K/O)().
Next note that H 2 (L()/L, (K/O)()) is trivial. If 6 1() this is straightforward (cf. Lemma 2.2 of [Ru1]). If 1() then Gal(L()/L) ' Zp and so
it is trivial in this case also. It follows that any class in the final term of (4.3)
lifts to a class c in H 1 (Q /L, (K/O)()). Let L0 be the splitting field of Y .
Then M L0 /L0 is unramified outside p and L0 /L has degree prime to p. It
follows that c is unramified outside p.

1
(Q /Q, Yn ) (where Yn = Yn and similarly for Yn ) for
Now write Hstr
1
the supgroup of Hunr (Q /Q, Yn ) given by
o
n
1
1
(Q /Q, Yn ) : p = 0 in H 1 (Qp , Yn /(Yn )0 )
(Q /Q, Yn ) = Hunr
Hstr

where (Yn )0 is the first step in the filtration under Dp , thus equal to (Yn /Yn0 )
or equivalently to (Y )0n where (Y )0 is the divisible submodule of Y on
which the action of Ip is via 2 . (If p 6= 3 one can characterize (Yn )0 as the

528

ANDREW JOHN WILES

maximal submodule on which Ip acts via 2 .) A similar definition applies with


Yn replacing Yn . It follows from an examination of the action of Ip on Y that
1
1
Hstr
(Q /Q, Yn ) = Hunr
(Q /Q, Yn ).

(4.4)

In the case of Y we will use the inequality


(4.5)

1
1
#Hstr
(Q /Q, Y ) #Hunr
(Q /Q, Y ).

We also need the fact that for n sufficiently large the map
1
1
Hstr
(Q /Q, Yn ) Hstr
(Q /Q, Y )

(4.6)

is injective. One can check this by replacing these groups by the subgroups
of H 1 (L, (K/O)()n ) and H 1 (L, (K/O)()) which are unramified outside p
and trivial at p , in a manner similar to the beginning of the proof of Proposition 4.1. the above map is then injective whenever the connecting homomorphism
H 0 (Lp , (K/O)()) H 1 (Lp , (K/O)()n )
is injective, which holds for sufficiently large n.
Now, by Propsition 1.6,
(4.7)

0
1
#Hstr
(Q /Q, Yn )
0
0 #H (Q, Yn )
=
#H
(Q
,
(Y
)
)
.
p
n
1 (Q /Q, Y )
#Hstr
#H 0 (Q, Yn )

Also, H 0 (Q, Yn ) = 0 and a simple calculation shows that


(
inf #(O/1 (q)) if = 1 mod
q
#H 0 (Q, Yn ) =
1
otherwise
where q runs through a set of primes of OL prime to p cond() of density one.
This can be checked since Y = IndQ
L () K/O. So, setting
O

(4.8)

t=

we get
(4.9)
1
#HSe
(Q /Q, Y )

1
t

inf q #(O/(1 (q))) if mod = 1


1

if mod 6= 1

`q #Hom(Gal(M /L()), (K/O)())Gal(L()/L)

where `q = #H 0 (Qq , Y ) for q 6= p, `p = lim #H 0 (Qp , (Yn0 ) ). This follows


n

from Proposition 4.1, (4.4)-(4.7) and the elementary estimate


Y
1
1
(Q /Q, Y ))
`q ,
(Q /Q, Y )/Hunr
(4.10)
#(HSe
q{p}

unr

Gal(Qq
which follows from the fact that #H 1 (Qunr
q ,Y )

/Qq )

= `q .

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

529

1
Our objective is to compute HSe
(Q /Q, V ) and the main problem is to es1
timate HSe (Q /Q, Y ). By (4.5) this in turn reduces to the problem of estimating
#Hom(Gal(M /L()), (K/O)())Gal(L()/L) ). This order can be computed
using the main conjecture established by Rubin using ideas of Kolyvagin. (cf.
[Ru2] and especially [Ru4]. In the former reference Rubin assumes that the
class number of L is prime to p.) We could now derive the result directly from
this by referring to [de Sh, Ch.3], but we will recall some of the steps here.
Let wf denote the number of roots of unity of L such that 1 mod f
(f an integral ideal of OL ). We choose an f prime to p such that wf = 1.
Then there is a grossencharacter of L satisfying (()) = for 1 mod f
, Q
p we
(cf. [de Sh, II.1.4]). According to Weil, after fixing an embedding Q
can asssociate a p-adic character p to (cf. [de Sh, II.1.1 (5)]). We choose
an embedding corresponding to a prime above p and then we find p =
for some of finite order and conductor prime to p. Indeed p and are
both unramified at p and satisfy p |Ip = |Ip = where is the cyclotomic
character and Ip is an inertia group at p. Without altering f we can even choose
so that the order of is prime to p. This is by our hyppothesis that factored
through an extension of the form Zp T with T of order prime to p. To see
this pick an abelian splitting field of p and whose Galois group has the form
G G0 with G a pro-p-group and G0 of order prime to p. Then we see that
|G has conductor dividing fp . Also the only primes which ramify in a Zp extension lie above p so our hypothesis on ensures that |G has conductor
dividing fp . The same is then true of the p-part of which therefore has
conductor dividing f. We can therefore adjust so that has order prime
to p as claimed. We will not however choose so that is 1 as this would
require fp to be divisible by cond . However we will make the assumption,
by altering f if necessary, but still keeping f prime to p, that both and p
have conductor dividing fp . Thus we replace fp by l.c.m.{f, cond }.
The grossencharacter (or more precisely NF/L ) is associated to a
(unique) elliptic curve E defined over F = L(f), the ray class field of conductor
f, with complex multiplication by OL and isomorphic over C to C/OL (cf.
[de Sh, II. Lemma 1.4]). We may even fix a Weierstrass model of E over O F
which has good reduction at all primes above p. For each prime P of F above
P , and this is a relative Lubin-Tate group with
p we have a formal group E
respect to FP over Lp (cf. [de Sh, Ch. II, 1.10]). We let = EP be the
logarithm of this formal group.
Let U be the product of the principal local units at the primes above p
of L(fp ); i.e.,

U =

P|p

U,P

where

U,P = lim Un , P,

530

ANDREW JOHN WILES

each Un,P being the principal local units in L(fpn )P . (Note that the primes
of L(f) above p are totally ramified in L(fp ) so we still call them {P}.) We
wish to define certain homomorphisms k on U . These were first introduced
in [CW] in the case where the local field FP is Qp .
P is isomorphic to
Assume for the moment that FP is Qp . In this case E
the Lubin-Tate group associated to x + xp where = (p). Then letting n
be nontrivial roots of [ n ](x) = 0 chosen so that [](n ) = n1 , it was shown
in [CW] that to each element u = lim un U,P there corresponded a unique

power series fu (T ) Zp [[T ]] such that fu (n ) = un for n 1. The definition


of k,P (k 1) in this case was then
k,P (u) =

1
d
0
(T ) dT

log fn (T )

T =0

It is easy to see that k,P gives a homomorphism:

U U,P Op satisfying
k,P ( ) = ()k k,P () where : Gal F /F

Op is the character giving

the action on E[p ].


The construction of the power series in [CW] does not extend to the case
where the formal group has height > 1 or to the case where it is defined over
an extension of Qp . A more natural approach was developed bt Coleman [Co]
which works in general. (See also [Iw1].) The corresponding generalizations of
k were given in somewhat greater generality in [Ru3] and then in full generality
by de Shalit [de Sh]. We now summarize these results, thus returning to the
general case where FP is not assumed to be Qp .
To an element u = lim un U we can associate a power series fu,P (T )

OP [[T ]] where OP is the ring of integers of FP ; see [de Sh, Ch. II 4.5]. (More
precisely fu,P (T ) is the P-component of the power series described there.) For
P we will choose the prime above p corresponding to our chosen embedding
Q , Qp . This power series satisfies un,P = (fu,P )(n ) for all n > 0, n 0(d)
where d = [FP : Lp ] and {n } is chosen as before as an inverse system of n
P . We define a homomorphism k : U OP by
division points of E
(4.11)
Then
(4.12)

k (u) := k,P (u) =

1
d
0
Eb (T ) dT
P

k (u ) = ( )k k (u)

!k

log fu,P (T )

T =0

for Gal(F /F )

where again denotes the action on E[p ]. Now = p on Gal(F /F ). We


actually want a homomorphism on u with a transformation property corre
sponding to on all of Gal(L/L).
Observe that = 2p on Gal(F /F ). Let S

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

531

) and define
be a set of coset representatives for Gal(L/L)/Gal(
L/F
X
(4.13)
2 (u) =
1 ()2 (u ) OP [].
S

Each term is independent of the choice of coset representative by (4.8) and it


is easily checked that
2 (u ) = ()2 (u).
It takes integral values in OP []. Let U () denote the product of the groups
of local principal units at the primes above p of the field L() (by which we
mean projective limis of local principal units as before). Then 2 factors
through U () and thus defines a continuous homomorphism
2 : U () Cp .
Let C be the group of projective limits of elliptic units in L() as defined
in [Ru4]. Then we have a crucial theorem of Rubin (cf. [Ru4], [Ru2]), proved
using the ideas of Kolyvagin:
Theorem 4.2. There is an equality of characteristic ideals as =
Zp [[Gal(L()/L)]]-modules:
char (Gal(M /L())) = char (U ()/C ).
Let 0 = mod . For any Zp [Gal(L(0 )/L)]-module X we write X (0 )
for the maximal quotient of X O on which the action of Gal(L(0 )/L) is via
Zp

the Teichm
uller lift of 0 . Since Gal(L()/L) decomposes into a direct product
of a pro-p group and a group of order prime to p,
Gal(L()/L) ' Gal(L()/L(0 )) Gal(L(0 )/L),
we can also consider any Zp [[Gal(L()/L)]]-module also as a Zp [Gal(L(0 )/L)]module. In particular X (0 ) is a module over Zp [Gal(L(0 )/L)](0 ) ' O. Also
0 ) ' O[[T ]].
Now according to results of Iwasawa ([Iw2, 12], [Ru2, Theorem 5.1]),
U ()(0 ) is a free (0 ) -module of rank one. We extend 2 O-linearly to
U () Zp O and it then factors through U ()(0 ) . Suppose that u is a
( )
generator of U ()(0 ) and an element of C0 . Then f ( 1)u = for some
f (T ) O[[T ]] and a topological generator of Gal(L()/L(0 )). Computing
2 on both u and gives
(4.14)

f (() 1) = 2 ()/2 (u).

Next we let e(a) be the projective limit of elliptic units in lim L


fpn for

a some ideal prime to 6fp described in [de Sh, Ch. II,4.9]. Then by the
proposition of Chapter II, 2.7 of [de Sh] this is a 12th power in lim L
fpn . We

532

ANDREW JOHN WILES

let 1 = (a)1/12 be the projection of e(a)1/12 to U and take = Norm 1


where the norm is from Lfp to L(). A generalization of the calculation in
[CW] which may be found in [de Sh, Ch. II, 4.10] shows that
(4.15)

2 () = (root of unity)2 (N a (a))Lf (2, ) OP []

where is a basis for the OL -module of periods of our chosen Weierstrass model
of E/F . (Recall that this was chosen to have good reduction at primes above p.
The periods are those of the standard Neron differential.) Also here should
be interpreted as the grossencharacter whose associated p-adic character, via
the chosen embedding Q , Qp , is , and is the complex conjugate of .
The only restrictions we have placed on f are that (i) f is prime to p;
(ii) wf = 1; and (iii) cond |fp . Now let f0 p be the conductor of with f0
prime to p. We show now that we can choose f such that Lf (2, )/Lf0 (2, ) is
a p-adic unit unless 0 = 1 in which case we can choose it to be t as defined
in (4.4). We can clearly choose Lf (2, )/Lf0 (2, ) to be a unit if 0 6= 1, as
(q)(q) = Norm q2 for any ideal q prime to f0 p. Note that if 0 = 1 then also
p = 3. Also if 0 = 1 then we see that
n
o
inf # O/{Lf0 q (2, )/Lf0 (2, )} = t
q

since 2 = 1 .
We can compute 2 (u) by choosing a special local unit and showing that
2 (u) is a p-adic unit, but it is sufficient for us to know that it is integral. Then
since Gal(M /L()) has no finite -submodule (by a result of Greenberg; see
[Gre2, end of 4]) we deduce from Theorem 4.2, (4.14) and (4.15) that
#Hom(Gal(M /L()), (K/O)())Gal(L()/L)

#O/2 Lf0 (2, )


if 0 =
6 1

2
(#O/ Lf0 (2, )) t if 0 = 1.
Combining this with (4.9) gives:

Y
1
#HSe
(Q /Q, Y ) # O/2 Lf0 (2, )
`q
q

where `q = #H 0 (Qq , Y ) (for q 6= p), `p = #H 0 (Qp , (Y 0 ) ).


Since V ' Y (K/O)() K/O we need also a formula for
n
o
# ker H 1 (Q /Q, (K/O)() K/O) H 1 (Qunr
,
(K/O)()

K/O)
.
p

This is easily computed to be


(4.16)

#(O/hL )

q{p}

`q

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

533

where `q = #H 0 (Qq , ((K/O)() K/O) ) and hL is the class number of OL .


Combining these gives:
Proposition 4.3.
1
#HSe
(Q /Q, V ) #(O/2 Lf0 (2, )) #(O/hL )

`q

where `q = #H 0 (Qq , V ) (for q 6= p), `p = #H 0 (Qp , (Y 0 ) ).


2. Calculation of
We need to calculate explicitly the invariants D,f introduced in Chapter 2,
3 in a special case. Let 0 be an irreducible representation as in (1.1). Suppose
that f is a newform of weight 2 and level N, a prime of Of above p and f, a
deformation of 0 . Let m be the kernel of the homomorphism T1 (N ) Of /
arising from f . We write T for T1 (N )m O, where O = Of, and km is
W (km )

the residue field of m. Assume that p - N . We assume here that k is the


residue field of O and that it is chosen to contain km . Then by Corollary 1 of
Theorem 2.1, T1 (N )m is Gorenstein andit follows that T is also a Gorenstein
O-algebra (see the discussion following (2.42)). So we can use perfect pairings
(the second one T -bilinear)
O O O,

h , i:T T O

to define an invariant of T . If : T O is the natural map, we set


() = (
(1)) where
is the adjoint of with respect to the pairings. It is
well-defined as an ideal of T , depending only on . Furthermore, as we noted
in Chapter 2, 3, () = h, i up to a unit in O and as noted in the appendix
= Ann p = T [p] where p = ker . We now give an explicit formula for
developed by Hida (cf. [Hi2] for a survey of his earlier results) by interpreting
h , i in terms of the cup product pairing on the cohomology of X1 (N ), and
then in terms of the Petersson inner product of f with itself. The following
account (which does not require the CM hypothesis) is adapted from [Hi2] and
we refer there for more details.
Let
(4.17)

( , ) : H 1 (X1 (N ), Of ) H 1 (X1 (N ), Of ) Of

be the cup product pairing with Of as coefficients. (We sometimes drop the
C from X1 (N )/C or J1 (N )/C if the context makes it clear that we are referring to the complex manifolds.) In particular (t x, y) = (x, t y) for all
x, y and for each standard Hecke correspondence t. We use the action of t on
H 1 (X1 (N ), Of ) given by x 7 t x and simply write tx for t x. This is the same

534

ANDREW JOHN WILES

as the action induced by t T1 (N ) on H 1 (J1 (N ), Of ) ' H 1 (X1 (N ), Of ).


Let pf be the minimal prime of T1 (N ) Of associated to f (i.e., the kernel of
T1 (N ) Of Of given by tl 7 ct (f ) where tf = ct (f )f ), and let
Lf = H 1 (X1 (N ), Of )[pf ].
If f = an q n let f =
an q n . Then f is again a newform and we define
Lf by replacing f by f in the definition of Lf . (Note here that Of = Of
as these rings are the integers of fields which are either totally real or CM by
a result of Shimura. Actually this is not essential as we could replace O f by
any ring of integers containing it.) Then the pairing ( , ) induces another by
restriction
(4.18)

( , ) : L f Lf Of .

Replacing O (and the Of -modules) by the localization of Of at p (if necessary)


we can assume that Lf and Lf are free of rank 2 and direct summands as
Of -modules of the respective cohomology groups. Let 1 , 2 be a basis of Lf .
Then also 1 , 2 is a basis of Lf = Lf . Here complex conjugation acts on
H 1 (X1 (N ), Of ) via its action on Of . We can then verify that
:= det(i , j )
(, )
is an element of Of (or its localization at p) whose image in Of, is given by
( 2 ) (unit). To see this, consider a modified pairing h , i defined by
(4.19)

hx, yi = (x, w y)

where w is defined as in (2.4). Then htx, yi = hx, tyi for all x, y and Hecke
operators t. Furthermore
dethi , j i = det(i , w j ) = c det(i j )
for some p-adic unit c (in Of ). This is because w (Lf ) = Lf and w (Lf ) =
Lf . (One can check this, foe example, using the explicit bases described
below.) Moreover, by Theorem 2.1,
H 1 (X1 (N ), Z) T1 (N ) T1 (N )m ' T1 (N )2m ,
H 1 (X1 (N ), Of ) T1 (N )Of T ' T 2 .

Thus (4.18) can be viewed (after tensoring with Of, and modifying it as in
(4.19)) as a perfect pairing of T -modules and so this serves to compute ( 2 )
as explained earlier (the square coming from the fact that we have a rank 2
module).
we observe that f and f can be
To give a more useful expression for (, )
1
viewed as elements of H 1 (X1 (N ), C) ' HDR
(X1 (N ), C) via f 7 f (z)dz, f 7
f dz. Then {f, f } form a basis for Lf Of C. Similarly {f, f } form a basis

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

535

for Lf Of C. Define the vectors 1 = (f, f ), 2 = (f, f ) and write


1 = C and 2 = C with C M2 (C). Then writing f1 = f, f2 = f we set
det(C C).

:= det((fi , fj )) = (, )
(, )
is given explicitly in terms of the (non-normalized) Petersson inner
Now (, )
product h , i:
= 4hf, f i2
(, )
R
where hf, f i = H/1 (N ) f f dx dy.
To compute det(C) we consider integrals over classes in H1 (X1 (N ), Of ).
By Poincare
duality there exist classes c1 , c2 in H1 (X1 (N ), Of ) such that
R
det( cj i ) is a unit in Of . Hence det C generates the same Of -module as
n
R
o
is generated by det cj fi
for all such choices of classes (c1 , c2 ) and with
o
n
R
{f1 , f2 } = {f, f }. Letting uf be a generator of the Of -module det cj fi
we have the following formula of Hida:
Proposition 4.4. ( 2 ) = hf, f i2 /uf u
f ( unit in Of, ).
Now we restrict to the case where 0 = IndQ
L 0 for some imaginary
quadratic field L which is unramified at p and some k -valued character 0

of Gal(L/L).
We assume that 0 is irreducible, i.e., that 0 6= 0, where
0, () = 0 ( 1 ) for any representing the nontrivial coset of

Gal(L/Q)/Gal(
L/L).
In addition we wish to assume that 0 is ordinary and
det 0 |Ip = . In particular p splits in L. These conditions imply that, if p is a
prime of L above p0 () 1 mod p on Up after possible replacement of 0
by 0, . Here the Up are the units of Lp and since 0 is a character, the restriction of 0 to an inertia group Ip induces a homomorphism on Up . We assume
now that p is fixed and 0 chosen to satisfy this congruence. Our choice of
0 will imply that the grossencharacter introduced below has conductor prime
to p.
We choose a (primitive) grossencharacter on L together with an embedding Q , Qp corresponding to the prime p above p such that the induced
p-adic character p has the properties:
(i) p mod p = 0 (p = maximal ideal of Qp ).
(ii) p factors through an abelian extension isomorphic to Zp T with T of
finite order prime to p.
(iii) (()) = for 1(f) for some integral ideal f prime to p.
To obtain it is necessary first to define p . Let M denote the maximal
abelian extension of L which is unramified outside p. Let : Gal(M /L)

Qp be any character which factors through a Zp -extension and induces the

536

ANDREW JOHN WILES

homomorphism 7 1 on Up,1 7 Gal(M /L) where Up,1 = {u Up : u


1(p)}. Then set p = 0 , and pick a grossencharacter such that ()p = p .
Note that our choice of here is not necessarily intended to be the same as
the choice of grossencharacter in Section 1.
Now let f be the conductor of and let F be the ray class field of conductor ff . Then over F there is an elliptic curve, unique up to isomorphism,
with complex multiplication by OL and period lattice free, of rank one over OL
and with associated grossencharacter NF/L . The curve E/F is the extension
of scalars of a unique elliptic curve E/F + where F + is the subfield of F of
index 2. (See [Sh1, (5.4.3)].) Over F + this elliptic curve has only the p-power
isogenies of the form pm for m Z. To see this observe that F is unramified
at p and 0 is ordinary so that the only isogenies of degree p over F are the
ones that correspond to division by ker p and ker p0 where pp0 = (p) in L. Over
F + these two subgroups are interchanged by complex conjugation, which gives
the assertion. We let E/OF + ,(p) denote a Weierstrass model over OF + ,(p) , the
localization of OF + at p, with good reduction at the primes above p. Let E
be a Neron differential of E/OF + ,(p) . Let be a basis for the OL -module of

periods of E . Then = u for some p-adic unit in F .


According to a theorem of Hecke, is associated to a cusp form f in such
a way that the L-series L(s, ) and L(s, f ) are equal (cf. [Sh4, Lemma 3]).
Moreover since was assumed primitive, f = f is a newform. Thus the
integer N = cond f = |L/Q |NormL/Q (cond ) is prime to p and there is a
homomorphism
f : T1 (N ) Rf Of O
satisfying f (Tl ) = (c) + (c) if l = cc in L, (l - N ) and f (Tl ) = 0 if l is inert
in L (l - N ). Also f (lhli) = ((l))(l) where is the quadratic character
in Q
p chosen above we get a
associated to L. Using the embedding of Q
prime of Of above p, a maximal ideal m of T1 (N ) and a homomorphism
T1 (N )m Of, such that the associated representation f, reduces to
0 mod .
Let p0 = ker f : T1 (N ) Of and let
Af = J1 (N )/p0 J1 (N )
be the abelian variety associated to f by Shimura. Over F + there is an isogeny
Af /F + (E/F + )d
where d = [Of : Z] (see [Sh4, Th. 1]). To see this one checks that the p-adic Galois representation associated to the Tate modules on each side are equivalent
+

to (IndF
F o ) Zp Kf,p where Kf,p = Of Qp and where p : Gal(F /F ) Zp
is the p-adic character associated to and restricted to F . (one compares
trace(Frob `) in the two representations for ` - N p and ` split completely in
F + ; cf. the discussion after Theorem 2.1 for the representation on Af .)

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

537

Now pick a nonconstant map


: X1 (N )/F + E/F +
which factors through Af /F + . Let M be the composite of F + and the normal closure of Kf viewed in C. Let E be a Neron differential of E/OF + ,(p) .
Extending scalars to M we can write
X
E =
a f , a M
Hom(Kf ,C)

where f =

n=1

an (f )q n dq
q for each . By suitably choosing we can assume

that aid 6= 0. Then there exist i OM and ti T1 (N ) such that


X
i ti E = c1 f for some c1 M.

We consider the map

0 : H1 (X1 (N )/C , Z) OM,(p) H1 (E/C , Z) OM,(p)


P
given by 0 =
i ( ti ). Even if 0 is not surjective we claim that the image
of 0 always has the form H1 (E/C , Z) aOM,(p) for some a OM . This is
because tensored with Zp 0 can be viewed as a Gal(Q/F + )-equivariant map
of p-adic Tate-modules, and the omly p-power isogenies on E/F + have the form
pm for some m Z. It follows that we can factor 0 as (1 a) for some
other surjective

(4.20)

: H1 (X1 (N )/C , Z) OM H 1 (E/C , Z) OM ,

P 1
now allowing a to be in OM,(p) . Now define on 1E/C by =
a i ti
where : 1E/C 1J1 (N )/C is the map induced by and ti has the usual
action on 1J1 (N )/C . Then (E ) = cf for some c M and
Z
Z

(4.21)
(E ) =
E

()

for any class H1 (X1 (N )/C , OM ). We note that (on homology as in


(4.20)) also comes from a map of abelian varieties : J1 (N )/F + Z OM
E/F + Z OM although we have not used this to define .
We claim now that c OM,(p) . We can compute (E ) by considering
P
(E 1) =
ti a1 i on 1E/F + OM and then mapping the image in
1J1 (N )/F + OM to 1J1 (N )/F + OF + OM = 1J1 (N )/M . Now let us write O1 for
OF + ,(p) . Then there are isomorphisms
1J1 (N )/O

s2

s1

1
1
1
O2 Hom(OM , J1 (N )/O ) J1 (N )/O
1

538

ANDREW JOHN WILES

where is the different of M/Q. The first isomorphism can be described as


follows. Let e() : J1 (N ) J1 (N ) OM for OM be the map x 7 x .
Then t1 ()() = e() . Similar identifications occur for E in place of J1 (N ).
So to check that (E 1) 1J1 (N )/O OM it is enough to observe that by
1
its construction comes from a homomorphism J1 (N )/O1 OM E/O1 OM .
It follows that we can compare the
R periods of
R f and of E .

For f we use the fact that f dz = c f dz where c is the OM -linear


map on homology coming from complex conjugation on the curve. We deduce:
Proposition 4.5. uf =

1
2
4 2 .(1/p-adic

integer)).

We now give an expression for hf , f i in terms of the L-function of .


This was first observed by Shimura [Sh2] although the precise form we want
was given by Hida.
Proposition 4.6.
1
hf , f i =
N2
16 3

)
Y
1
N (1, )
LN (2, 2 )L
1
q
q|N

q6S

where is the character of f and


its restriction to L;
is the quadratic character associated to L;
LN ( ) denotes that the Euler factors for primes dividing N have been
removed;
S is the set of primes q|N such that q = qq0 with q - cond and q, q0
primes of L, not necessarily distinct.
Proof. One begins with a formula of Petterson that for an eigenform of
weight 2 on 1 (N ) says
hf, f i = (4)2 (2)
where D(s, f, f ) =

n=1

1
3

[SL2 (Z) : 1 (N ) (1)] Ress=2 D(s, f, f )

|an |2 ns if f =

an q n (cf. [Hi3, (5.13)]). One checks

n=1

that, removing the Euler factors at primes dividing N ,


N (s 1, )Q,N (s 1)/Q,N (2s 2)
DN (s, f, f ) = LN (s, 2 )L
by using Lemma 1 of [Sh3]. For each Euler factor of f at a q|N of the form
(1q q s ) we get also an Euler factor in D(s, f, f ) of the form (1q
q q s ).
0
When f = f this can only happen for a split prime q where q divides the
conductor of but q does not, or for a ramified prime q which does not divide
the conductor of . In this case we get a term (1 q 1s ) since |(q)|2 = q.
Putting together the propositions of this section we now have a formula for
() as defined at the beginning of this section. Actually it is more convenient

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

539

to give a formula for (M ), an invariant defined in the same way but with
T1 (M )m1 W (km1 ) O replacing T1 (N )m W (km ) O where M = pM0 with p - M0
and M/N is of the form
Y
Y
q2 .
q
qS

q-N
q|M0

Here m1 is defined by the requirements that m1 = 0 , Uq m if q|M (q 6= p)


and there is an embedding (which we fix) km1 , k over k0 taking Up p
where p is the unit eigenvalue of Frob p in f, . So if f 0 is the eigenform
obtained from f by removing the Euler factors at q|(M/N )(q 6= p) and
removing the non-unit Euler factor at p we have M =
(1) where : T1 =
T1 (M )m1 O O corresponds to f 0 and the adjoint is taken with respect
W (km1 )

to perfect pairings of T1 and O with themselves as O-modules, the first one


assumed T1 -bilinear.
Property (ii) of p ensures that M is as in (2.24) with D = (Se, , O, )
where is the set of primes dividing M . (Note that S is precisely the set of
primes q for which nq = 1 in the notation of Chapter 2, 3.) As in Chapter 2,
3 there is a canonical map
RD TD ' T1 (M )m1

W (km1 )

which is surjective by the arguments in the proof of Proposition 2.15. Here


we are considering a slightly more general situation than that
in Chapter 2,
3 as we are allowing 0 to be induced from a character of Q( 3). In this
special case we define TD to be T1 (M )m1 O. The existence of the map
W (km1 )

in (4.22) is proved as in Chapter 2, 3. For the surjectivity, note that for each
q|M (with q 6= p) Uq is zero in TD as Uq m1 for each such q so that we
can apply Remark 2.8. To see that Up is in the image of RD we use that it
is the eigenvalue of Frob p on the unique unramified quotient which is free of
rank one in the representation described after the corollaries to Theorem 2.1
(cf. Theorem 2.1.4 of [Wi1]). To verify this one checks that TD is reduced
or alternatively one can apply the method of Remark 2.11. We deduce that
Up Ttr
D , the W (km1 )-subalgebra of T1 (M )m1 generated by the traces, and it
follows then that it is in the image of RD . We also need to give a definition
of
TD where D = (ord, , O, ) and 0 is induced from a character of Q( 3).
For this we use (2.31).
Now we take
Y
M = Np
q.
qS

540

ANDREW JOHN WILES

The arguments in the proof of Theorem 2.17 show that


Y
(q 1)
(M ) is divisible by ()(p2 hpi)
qS

where p is the unit eigenvalue of Frob p in f, . The factor at p is given by


remark 2.18 and at q it comes from the argument of Proposition 2.12 but with
H = H 0 = 1. Combining this with Propositions 4.4, 4.5, and 4.6, we have that
(4.23) (M ) is divisible by

Y
2 LN (1, )

LN 2,
(p2 hpi)
(q 1).

q|N

We deduce:
1
(Q /Q, V ).
Theorem 4.7. #(O/(M )) = #HSe

Proof. As explained in Chapter 2, 3 it is sufficient to prove the inequality


1
#(O/(M )) #HSe
(Q /Q, V ) as the opposite one is immediate. For this it
suffices to compare (4.23) with Proposition 4.3. Since

LN (2, ) = LN (2, ) = LN (2, 2 )


(note that the right-hand term is real by Proposition 4.6) it suffices to air up
the Euler factors at q for q|N in (4.23) and in the expression for the upper
1
bound of #HSe
(Q /Q, V ).

We now deduce the main theorem in the CM case using the method of
Theorem 2.17.
Theorem 4.8. Suppose that 0 as in (1.1) is an irreducible representation of odd determinant such that 0 = IndQ
L 0 for a character 0 of an
imaginary quadratic extension L of Q which is unramified at p. Assume also
that:

(i) det 0 = ;
Ip

(ii) 0 is ordinary.

Then for every D = (, , O, ) uch that 0 os of type D with = Se or ord,


RD ' T D
and TD is a complete intersection.
Corollary. For any 0 as in the theorem suppose that

: Gal(Q/Q)
GL2 (O)
is a continuous representation with values in the ring of integers of a local
field, unramified outside a finite set of primes, satisfying ' 0 when viewed
p ). Suppose further that:
as representations to GL2 (F

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

(i)

541

is ordinary;

(ii) det = k1 with of finite order, k 2.


Dp

Ip

Then is associated to a modular form of weight k.

Chapter 5

In this chapter we prove the main results about elliptic curves and especially show how to remove the hypothesis that the representation associated
to the 3-division points should be irreducible.

Application to elliptic curves


The key result used is the following theorem of Langlands and Tunnell,
extending earlier results of Hecke in the case where the projective image is
dihedral.

Theorem 5.1 (Langlands-Tunnell). Suppose that : Gal(Q/Q)

GL2 (C) is a continuous irreducible representation whose image is finite and


solvable. Suppose further that det is odd. Then there exists a weight one
newform f such that L(s, f ) = L(s, ) up to finitely many Euler factors.
Langlands actually proved in [La] a much more general result without
restriction on the determinant or the number field (which in our case is Q).
However in the crucial case where the image in PGL2 (C) is S4 , the result was
only obtained with an additional hypothesis. This was subsequently removed
by Tunnell in [Tu].
Suppose then that

0 : Gal(Q/Q)
GL2 (F3 )
is an irreducible representation of odd determinant. We now show, using
3,
the theorem, that this representation is modular in the sense that over F
0 g, mod for some pair (g, ) with g some newform of weight 2 (cf. [Se,
5.3]). There exists a representation
h i
i : GL2 (F3 ) , GL2 Z 2 GL2 (C).
By composing i with an automorphism of GL2 (F3 ) if
necessary
we can assume

that i induces the identity on reduction mod 1 + 2 . So if we consider

542

ANDREW JOHN WILES

i 0 : Gal(Q/Q)
GL2 (C) we obtain an irreducible representation which is
easily seen to be odd and whose image is solvable. Applying the theorem we
find a newform
f of weight one associated to this representation. Its eigenvalues
lie in Z 2 . Now pick a modular form E of weight one such that E 1(3).
For example, we can take E = 6E1, where E1, is the Eisenstein series with
Mellintransform given by (s)(s, ) for the quadratic character associated
to Q( 3). Then f E f mod 3 and using the Deligne-Serre lemma ([DS,
Lemma 6.11]) we can find an eigenform
g 0 of weight 2 with the same eigenvalues

as f modulo a prime 0 above (1 + 2). There is a newform g of weight 2


0
0
which has the same eigenvalues as g 0 for
almost all Tl s, and we replace (g , )
by (g, ) for some prime above (1 + 2). Then the pair (g, ) satisfies our
requirements for a suitable choice of (compatible with 0 ).
We can apply this to an elliptic curve E defined over Q by considering
E[3]. We now show how in studying elliptic curves our restriction to irreducible
representations in the deformation theory can be circumvented.
Theorem 5.2. All semistable elliptic curves over Q are modular.
Proof. Suppose that E is a semistable elliptic curve over Q. Assume
first that the representation
E,3 on E[3] is irreducible. Then if 0 = E,3

restricted to Gal(Q/Q( 3)) were not absolutely irreducible, the image of the
restriction would be abelian of order prime to 3. As the semistable hypothesis
implies that all the inertia groups outside 3 in the splitting field of 0 have
order dividing 3this means that the splitting field of 0 is unramified outside
3. However, Q( 3) has no nontrivial abelian extensions unramified outside 3
and of order prime to 3. So 0 itself would factor through an abelian extension
of Q and this is a contradiction
as 0 is assumed odd and irreducible. So

0 restricted to Gal(Q/Q(
3)) is absolutely irreducible and E,3 is then
modular by Theorem 0.2 (proved at the end of Chapter 3). By Serres isogeny
theorem, E is also modular (in the sense of being a factor of the Jacobian of a
modular curve).
So assume now that E,3 is reducible. Then we claim that the representation E,5 on the 5-division points is irreducible. This is because X0 (15)(Q)
has only four rational points besides the cusps and these correspond to nonsemistable curves which in any case are modular; cf. [BiKu, pp. 79-80]. If we
knew that E,5 was modular we could now prove the theorem in the same way
we did knowing
that E,3 was modular once we observe that E,5 restricted to

Gal(Q/Q( 5)) is absolutely irreducible. This irreducibility follows a similar


argument
to the one for E,3 since the only nontrivial abelian extension of

Q( 5) unramified outside 5 and of order prime to 5 is Q(5 ) which is abelian


over Q. Alternatively, it is enough to check that there
are no elliptic curves
E for which E,5 is an induced representation over Q( 5) and E is semistable

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

543

at 5. This can be checked in the supersingular case using the description of


E,5 |D5 (in particular it is induced from a character of the unramified quadratic
extension of Q5 whose restriction to inertia is the fundamental character of
level 2) and in the ordinary case it is straightforward.
Consider the twisted form X()/Q of X(5)/Q defined as follows. Let
X(5)/Q be the (geometrically disconnected) curve whose non-cuspidal points
classify elliptic curves with full level 5 structure and let the twisted curve be
defined by the cohomology class (even homomorphism) in
H 1 (Gal(L/Q),

Aut !X(5)/L )

given by E,5 : Gal(L/Q) GL2 (Z/5Z) Aut X(5)/L where L denotes the
splitting field of E,5 . Then E defines a rational point on X()/Q and hence
also of an irreducible component of it which we denote C. This curve C is
smooth as X()/Q
= X(5)/Q
is smooth. It has genus zero since the same is
true of the irreducible components of X(5)/Q
.
A rational point on C (necessarily non-cuspidal) corresponds to an elliptic
curve E 0 over Q with an isomorphism E 0 [5] ' E[5] as Galois modules (cf. [DR,
VI, Prop. 3.2]). We claim that we can choose such a point with the two
properties that (i) the Galois representation E 0 ,3 is irreducible and (ii) E 0 (or
a quadtratic twist)has semistable reduction at 5. The curve E 0 (or a quadratic
twist) will then satisfy all the properties needed to apply Theorem 0.2. (For the
primes q 6= 5 we just use the fact that E 0 is semistable at q #
E 0 ,5 (Iq )|5.)
0
So E will be modular and hence so too will E 0 ,5 .
To pick a rational point on C satisfying (i) and (ii) we use the Hilbert irreducibility theorem. For, to ensure condition (i) holds, we only have to eliminate
the possibility that the image of E 0 ,3 is reducible. But this corresponds to E 0
being the image of a rational point on an irreducible covering of C of degree
4. Let Q(t) be the function field of C. We have therefore an irreducible polynomial f (x, t) Q(t)[x] of degree > 1 and we need to ensure that for many
values t0 in Q, f (x, t0 ) has no rational solution. Hilberts theorem ensures
that there exists a t1 such that f (x, t1 ) is irreducible. Then we pick a prime
p1 6= 5 such that f (x, t1 ) has no root mod p1 . (This is easily achieved using the

Cebotarev
density theorem; cf. [CF, ex. 6.2, p. 362].) So finally we pick any
t0 Q which is p1 -adically close to t1 and also 5-adically close to the original
value of t giving E. This last condition ensures that E 0 (corresponding to t0 )
or a quadratic twist has semistable reduction at 5. To see this, observe that
since jE 6= 0, 1728, we can find a family E(j) : y 2 = x3 g2 (j)x g3 (j) with
rational functions g2 (j), g3 (j) which are finite at jE and with the j-invariant of
E(j0 ) equal to j0 whenever the gi (j0 ) are finite. Then E is given by a quadratic
twist of E(jE ) and so after a change of functions of the form g2 (j) 7 u2 g2 (j),
g3 (j) 7 u3 g3 (j) with u Q we can assume that E(jE ) = E and that the
equation E(jE ) is minimal at 5. Then for j 0 Q close enough 5-adically to jE

544

ANDREW JOHN WILES

the equation E(j 0 ) is still minimal and semistable at 5, since a criterion for this,
for an integral model, is that either ord5 (4(E(j 0 ))) = 0 or ord5 (c4 (E(j 0 ))) = 0.
So up to a quadratic twist E 0 is also semistable.

This kind of argument can be applied more generally.


Theorem 5.3. Suppose that E is an elliptic curve defined over Q with
the following properties:
(i) E has good or multiplicative reduction at 3, 5,
(ii) For p = 3, 5 and for any prime q 1 mod p either E,p |Dq is reducible
p or E,p |Iq is irreducible over F
p.
over F
Then E is modular.
Proof. the main point to be checked is that one can carry over condition (ii) to the new curve E 0 . For this we use that for any odd prime p 6= q,
E,p |Dq is absolutely irreducible and E,p |Iq is absolutely reducible
and 3 - #
E,p (Iq )
m
E acquires good reduction over an abelian 2-power extension of
Qunr
but not over an abelian extension of Qq .
q
Suppose then that q 1(3) and that E 0 does not satisfy condition (ii) at
q (for p = 3). Then we claim that also 3 - #
E 0 ,3 (Iq ). For otherwise E 0 ,3 (Iq )
has its normalizer in GL2 (F3 ) contained in a Borel, whence E 0 ,3 (Dq ) would
be reducible which contradicts our hypothesis. So using the above equivalence
we deduce, by passing via E 0 ,5 ' E,5 , that E also does not satisfy hypothesis
(ii) at p = 3.

We also need to ensure that E 0 ,3 is absolutely irreducible over Q( 3 ).


This we can do by observing that the property that the image of E 0 ,3 lies in the
Sylow 2-subgroup of GL2 (F3 ) implies that E 0 is the image of a rational point
on a certain irreducible covering of C of nontrivial degree. We can then argue
in the same way we did in the previous theorem to eliminate the possibility
that E 0 ,3 was reducible, this time using two separate coverings to ensure that
the image of E 0 ,3 is neither reducible nor contained in a Sylow 2-subgroup.
Finally one also has to show
that if both E,5 is irreducible and E,3 is
induced from a character of Q( 3 ) then E is modular. (The case where
both were reducible has already been considered.) Taylor has pointed out
that curves satisfying both these conditions are classified by the non-cuspidal
rational points on a modular curve isomorphic to X0 (45)/W9 , and this is an
elliptic curve isogenous to X0 (15) with rank zero over Q. The non-cuspidal
rational points correspond to modular elliptic curves of conductor 338.

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

545

Appendix
Gorenstein rings and local complete intersections
Proposition 1. Suppose that O is a complete discrete valuation ring
and that : S T is a surjective local O-algebra homomorphism between complete local Noetherian O-algebras. Suppose further that pT is a prime ideal of

T such that T /pT


O and let pS = 1 (pT ). Assume that
(i) T ' O[[x1 , . . . , xr ]]/(f1 , . . . , fru ) where r is the size of a minimal set of
O-generators of pT /p2T ,

(ii) induces an isomorphism pS /p2S


pT /p2T and that these are finitely
generated O-modules whose free part has rank u.

Then is an isomorphism.
Proof. First we consider the case where u = 0. We may assume that the

generators x1 , . . . , xr lie in pT by subtracting their residues in T /pT


O. By
(ii) we may also write
S ' O[[x1 , . . . , xr ]]/(g1 , . . . , gs )
with s r (by allowing repetitions if necessary) and pS generated by the
images of {x1 . . . , xr }. Let p = (x1 , . . . , xr ) in [[x1 , . . . , xr ]]. Writing fi
aij xj mod p2 with aij O, we see that the Fitting ideal as an O-module of
pT /p2T is given by
FO (pT /p2T ) = det(aij ) O
and that this is nonzero by the hypothesis that u = 0. Similarly, if each
gi bij xj mod p2 , then
FO (pS /p2S ) = {det(bij ) : i I, #I = r, I {1, . . . , s}}.
By (ii) again we see that det(aij ) = det(bij ) as ideals of O for some choice I0
of I. After renumbering we may assume that I0 = {1, . . . , r}. Then each gi
(i = 1, . . . , r) can be written gi = rij fi for some rij [[x1 , . . . , xr ]] and we
have
det(bij ) det(rij ) det(aij ) mod p.
Hence det(rij ) is a unit, whence (rij ) is an invertible matrix. Thus the fi s can
be expressed in terms of the gi s and so S ' T .
We can extend this to the case u 6= 0 by picking x1 , . . . , xru so that they
Pru
generate (pT /p2T )tors . Then we can write each fi i=1 aij xj mod p2 and
likewise for the gi s. The argument is now just as before but applied to the
Fitting ideals of (pT /p2T )tors .

546

ANDREW JOHN WILES

For the next proposition we continue to assume that O is a complete


discrete valuation ring. Let T be a local O-algebra which as a module is finite
and free over O. In addition, we assume the existence of an isomorphism of

T -modules T
HomO (T, O). We call a local O-algebra which is finite and
free and satisfies this extra condition a Gorenstein O-algebra (cf. 5 of [Ti1]).
Now suppose that p is a prime ideal of T such that T /p ' O.
Let : T T /p ' O be the natural map and define a principal ideal of T
by

(T ) = ((1))
where : O T is the adjoint of with respect to perfect O-pairings on O
and T , and where the pairing of T with itself is T -bilinear. (By a perfect
pairing on a free O-module M of finite rank we mean a pairing M M O
such that both the induced maps M HomO (M, O) are isomorphisms. When
M = T we are thus requiring that this be an isomorphism of T -modules also.)
The ideal (T ) is independent of the pairing. Also T /T is torsion-free as an
O-module, as can be seen by applying Hom( , O) to the sequence
0 p T O 0,
to obtain a homomorphism T /T , Hom(p, O). This also shows that (T ) =
Annp.
If we let l(M ) denote the length of an O-module M , then
l(p/p2 ) l(O/T )
(where we write T for (T )) because p is a faithful T /T -module. (For a
brief account of the relevant properties of Fitting ideals see the appendix to
[MW1].) Indeed, writing FR (M ) for the Fitting ideal of M as an R-module,
we have
FT /T (p) = 0 FT (p) (T ) FT /p (p/p2 ) (T )
and we then use the fact that the length of an O-module M is equal to the
length of O/FO (M ) as O is a discrete valuation ring. In particular when p/p2
is a torsion O-module then T 6= 0.
We need a criterion for a Gorenstein O-algebra to be a complete intersection. We will say that a local O-algebra S which is finite and free over
O is a complete intersection over O if there is an O-algebra isomorphism
S ' O[[x1 , . . . , xr ]]/(f1 , . . . , fr ) for some r. Such a ring is necessarily a Gorenstein O-algebra and {f1 , . . . , fr } is necessarily a regular sequence. That (i)
(ii) in the following proposition is due to Tate (see A.3, conclusion 4, in the
appendix in [M Ro].)
Proposition 2. Assume that O is a complete discrete valuation ring
and that T is a local Gorenstein O-algebra which is finite and free over O and

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM

547

that pT is a prime ideal of T such that T /pT


= O and pT /p2T is a torsion
O-module. Then the following two conditions are equivalent:
(i) T is a complete intersection over O.

(ii) l(pT /p2T ) = l(O/T ) as O-modules.

Proof. To prove that (ii) (i), pick a complete intersection S over O (so
assumed finite and flat over O) such that : ST and such that pS /p2S ' pT /p2T
where pS = 1 (pT ). The existence of such an S seems to be well known
(cf. [Ti2, 6]) but here is an argument suggested by N. Katz and H. Lenstra
(independently).
Write T = O[x1 , . . . , xr ]/(f1 , . . . , fs ) with pT the image in T of p =
(x1 , . . . , xr ). Since T is local and finite and free over O, it follows that also
T ' O[[x1 , . . . , xr ]]/(f1 , . . . , fs ). We can pick g1 , . . . , gr such that gi = aij fj
with aij O and such that
(f1 , . . . , fs , p2 ) = (g1 , . . . , gr , p2 ).
We then modify g1 , . . . , gr by the addition of elements {i } of (f1 , . . . , fs )2 and
set (g10 = g1 + 1 , . . . , gr0 = gr + r ). Since T is finite over O, there exists an N
such that for each i, xN
i can be written in T as a polynomial hi (x1 , . . . , xr ) of
total degree less than N . We can assume also that N is chosen greater than
2
the total degree of gi for each i. Set i = (xN
i hi (x1 , . . . , xr )) . Then set
S = O[[x1 , . . . , xr ]]/(g10 , . . . , gr0 ). Then S is finite over O by construction and also
dim(S) 1 since dim(S/) = 0 where () is the maximal ideal of O. It follows
that {g10 , . . . , gr0 } is a regular sequence and hence that depth(S) = dim(S) = 1.
In particular the maximal O-torsion submodule of S is zero since it is also a
finite length S-submodule of S.
Now O/(
S ) ' O/(
T ), since l(O/(
S )) = l(pS /p2S ) by (i) (ii) and
2
l(O/(
T )) = l(pT /pT ) by hypothesis. Pick isomorphisms
T ' HomO (T, O), S ' HomO (S, O)
as T -modules and S-modules, respectively. The existence of the latter for
complete intersections over O is well known; cf. conclusion 1 of Theorem A.3
of [M Ro]. Then we have a sequence of maps, in which
and denote the
adjoints with respect to these isomorphisms:

S
T O.
O T

One checks that


is a map of S-modules (T being given an S-action via )
and in particular that
is multiplication by an element t of T . Now

( ) = (
T ) in O and ( ) ( \
) = (
S ) in O. As (
S ) = (
T ) in O, we
have that t is a unit mod pT and hence that
is an isomorphism. It follows

548

ANDREW JOHN WILES

that S ' T , as otherwise S ' ker im


is a nontrivial decomposition as
S-modules, which contradicts S being local.

Remark. Lenstra has made an important improvement to this proposition by showing that replacing T by (ann p) gives a criterion valid for all
local O-algebra which are finite and free over O, thus without the Gorenstein
hypothesis.
Princeton University, Princeton, NJ
References
[AK]
[BiKu]
[Bo]
[BH]
[BK]
[BLR]
[CF]
[Ca1]
[Ca2]
[Ca3]

[CPS]
[CS]
[CW]
[Co]
[DR]
[DS]
[Dia]

[Di]

A.Altman and S.Kleiman,An Introduction to Grothendieck Duality Theory, vol.


146, Springer Lecture Notes in Mathematics, 1970.
B. Birch and W. Kuyk (eds.), Modular Functions of One Variable IV, vol. 476,
Springer Lecture Notes in Mathematics, 1975.
N. Boston, Families of Galois representations Increasing the ramification, Duke
Math. J. 66, 357-367.
W. Bruns and J. Herzog, Cohen-Macauley Rings, Cambridge University Press,
1993.
S. Bloch and K. Kato, L-Functions and Tamagawa Numbers of Motives, The
Grothendieck Festschrift, Vol. 1 (P. Cartier et al. eds.), Birkh
auser, 1990.
N.Boston, H.Lenstra, and K.Ribet, Quotients of group rings arising from twodimensional representations, C. R. Acad. Sci. Paris t312, Ser. 1 (1991), 323-328.
lich (eds.),Algebraic Number Theory,Academic Press,
J.W.S.Cassels and A.Fro
1967.
H. Carayol, Sur les repr
esentations p-adiques associ
ees aux formes modulares de
Hilbert, Ann. Sci. Ec. Norm. Sup. IV, Ser. 19 (1986), 409-468.
, Sur les repr
esentationes galoisiennes modulo ` attach
ees aux formes modulaires, Duke Math. J. 59 (1989), 785-901.
, Formes modulaires et repr
esentations Galoisiennes a
` valeurs dans un anneau local complet, in p-Adic Monodromy and the Birch-Swinnerton-Dyer Conjecture (eds. B. Mazur and G. Stevens), Contemp. Math., vol. 165, 1994.
E. Cline, B. Parshall, and L. Scott, Cohomology of finite groups of Lie type I,
Publ. Math. IHES 45 (1975), 169-191.
J.Coates and C.G.Schmidt,Iwasawa theory for the symmetric square of an elliptic
curve, J. reine und angew. Math. 375/376 (1987), 104-156.
J.Coates and A.Wiles, On p-adic L-functions and elliptic units, Ser.A26,J.Aust.
Math. Soc. (1978), 1-25.
R. Coleman, Division values in local fields, Invent. Math. 53 (1979), 91-116.
P.DeligneandM.Rapoport,Sch
emas de modulares de courbes elliptiques,inSpringer
Lecture Notes in Mathematics, Vol. 349, 1973.
P. Deligne and J-P. Serre, Formes modulaires de poids 1, Ann. Sci. Ec. Norm.
Sup. IV, Ser. 7 (1974), 507-530.
F. Diamond, The refined conjecture of Serre, in Proc. 1993 Hong Kong Conf. on
Elliptic Curves, Modular Forms and Fermats Last Theorem, J. Coates, S. T. Yau,
eds., International Press, Boston, 22-37 (1995).
L.E.Dickson,Linear Groups with an Exposition of the Galois Field Theory,Teubner, Leipzig, 1901.

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM


[Dr]

[E1]
[E2]

[Fl]
[Fo]

[Fr]
[Gre1]
[Gre2]
[Gro]
[Guo]
[He]
[Hi1]
[Hi2]
[Hi3]
[Hi4]
[Hu]
[Ih]
[Iw1]
[Iw2]
[Ka]
[Ku1]
[Ku2]
[KM]
[La]
[Li]
[Liv]
[Ma1]

549

V. Drinfeld, Two-dimensional `-adic representations of the fundamental group of


a curve over a finite field and automorphic forms on GL(2), Am. J. Math. 105
(1983), 85-114.
B. Edixhoven, Two weight in Serres conjecture on modular forms, Invent. Math.
109 (1992), 563-594.
, Laction de lalg`
ebre de Hecke sur les groupes de composantes des jacobiennes des courbes modulaires set Eisenstein, in Courbes Modulaires et Courbes
de Shimura, Ast
erisque 196-197 (1991), 159-170.
M.Flach,A finiteness theorem for the symmetric square of an elliptic curve,Invent.
Math. 109 (1992), 307-327.
J.-M.Fontaine,Sur certains types de repr
esentations p-adiques du groupe de Galois
dun corp local; construction dun anneau de Barsotti-Tate, Ann. of Math. 115
(1982), 529-577.
G. Frey, Links between stable elliptic curves and certain diophantine equations,
Annales Universitatis Saraviensis 1 (1986), 1-40.
R.Greenberg,Iwasawa theory for p-adic representations, Adv.St.Pure Math. 17
(1989), 97-137.
,On the structure of certain Galois groups,Invent.Math. 47 (1978), 85-99.
B.H.Gross,A tameness criterion for Galois representations associated to modular
forms mod p, Duke Math. J. 61 (1990), 445-517.
L. Gou, General Selmer groups and critical values of Hecke L-functions, Math.
Ann. 297 (1993), 221-233.
Y.Hellegouarch,Points dordre 2ph sur les courbes elliptiques,Acta Arith.XXVI
(1975), 253-263.
H. Hida, Iwasawa modules attached to congruences of cusp forms, Ann. Sci. Ecole
Norm. Sup. (4) 19 (1986), 231-273.
, Theory of p-adic Hecke algebras and Galois representations, Sugaku Expositions 2-3 (1989), 75-102.
, Congruences of Cusp forms and special values of their zeta functions,
Invent. Math. 63 (1981), 225-261.
, On p-adic Hecke algebras for GL2 over totally real fields, Ann. of Math.
128 (1988), 295-384.
B. Huppert, Endliche Gruppen I, Springer-Verlag, 1967.
Y. Ihara, On modular curves over finite fields, in Proc. Intern. Coll. on discrete
subgroups of Lie groups and application to moduli, Bombay, 1973, pp. 161-202.
K. Iwasawa, Local Class Field Theory, Oxford University Press, Oxford, 1986.
, On Zl -extension of algebraic number fields, Ann. of Math. 98 (1973),
246-326.
N. Katz, A result on modular forms in characteristic p, in Modular Functions of
One Variable V, Springer L. N. M. 601 (1976), 53-61.
E.Kunz,Introduction to Commutative Algebra and Algebraic Geometry,Birkha
user,
1985.
, Almost complete intersection are not Gorenstein, J. Alg. 28 (1974), 111115.
N.Katz and B.Mazur, Arithmetic Moduli of Elliptic Curves,Ann.of Math.Studies
108, Princeton University Press, 1985.
R. Langlands, Base Change for GL2 , Ann. of Math. Studies, Princeton University Press 96, 1980.
W. Li, Newforms and functional equations, Math. Ann. 212 (1975), 285-315.
R.Livn
e,On the conductors of mod ` Galois representations coming from modular
forms, J. of No. Th. 31 (1989), 133-141.
B. Mazur, Deforming Galois representations, in Galois Groups over Q, vol. 16,
MSRI Publications, Springer, New York, 1989.

550

ANDREW JOHN WILES

[Ma2]

, Modular curves and the Eisenstein ideal, Publ. Math. IHES 47 (1977),
33-186.

[Ma3]
[M Ri]

[M Ro]
[MT]
[MW1]
[MW2]
[Mi1]
[Mi2]
[Ram]
[Ray1]
[Ray2]
[Ri1]
[Ri2]
[Ri3]
[Ri4]
[Ru1]
[Ru2]
[Ru3]
[Ru4]
[Sch]
[Scho]

[Se]
[de Sh]
[Sh1]
[Sh2]
[Sh3]

, Rational isogenies of prime degree, Invent. Math. 44 (1978), 129-162.


B. Mazur and K. Ribet, Two-dimensional representations in the arithmetic of
modular curves, Courbes Modulaires et Courbes de Shimura, Ast
erisque 196-197
(1991), 215-255.
B. Mazur and L. Roberts, Local Euler characteristics, Invent. Math. 9 (1970),
201-234.
B. Mazur and J. Tilouine, Repr
esentations galoisiennes, differentielles de K
ahler
et conjectures principales, Publ. Math. IHES 71 (1990), 65-103.
B. Mazur and A. Wiles, Class fields of abelian extensions of Q, Invent.Math. 76
(1984), 179-330.
, On p-adic analytic families of Galois representations, Comp. Math. 59
(1986), 231-264.
J. S. Milne, Jacobian varieties, in Arithmetic Geometry (Cornell and Silverman,
eds.), Springer-Verlag, 1986.
, Arithmetic Duality Theorems, Academic Press, 1986.
R.Ramakrishna,On a variation of Mazurs deformation functor, Comp.Math. 87
(1993), 269-286.
M. Raynaud, Sch
emas en groupes de type (p, p, . . . , p), Bull. Soc. Math. France
102 (1974), 241-280.
,Sp
ecialisation du foncteur de Picard, Publ.Math.IHES 38 (1970), 27-76.

K.A.Ribet,On modular representations of Gal(Q/Q)


arising from modular forms,
Invent. Math. 100 (1990), 431-476.
, Congruence relations between modular forms, Proc. Int. Cong. of Math.
17 (1983), 503-514.

, Report on mod l representations of Gal(Q/Q),


Proc. of Symp. in Pure
Math. 55 (1994), 639-676.
, Multiplicities of p-finite mod p Galois representations in J0 (N p), Boletim
da Sociedade Brasileira de Matematica, Nova Serie 21 (1991), 177-188.
K. Rubin, Tate-Shafarevich groups and L-functions of elliptic curves with complex
multiplication, Invent. Math. 89 (1987), 527-559.
, The main conjectures of Iwasawa theory for imaginary quadratic fields,
Invent. Math. 103 (1991), 25-68.
, Elliptic curves with complex multiplication and the conjecture of Birch
and Swinnerton-Dyer, Invent. Math. 64 (1981), 455-470.
, More main conjectures for imaginary quadratic fields, CRM Proceedings
and Lecture Notes, 4, 1994.
M. Schlessinger, Functors on Artin Rings, Trans. A. M. S. 130 (1968), 208-222.
R. Schoof, The structure of the minus class groups of abelian number fields,
in Seminaire de Th
eorie des Nombres, Paris (1988-1989), Progress in Math. 91,
Birkhauser (1990), 185-204.

J.-P. Serre, Sur les repr


esentationes modulaires de degr
e 2 de Gal(Q/Q),
Duke
Math. J. 54 (1987), 179-230.
E. de Shalit, Iwasawa Theory of Elliptic Curves with Complex Multiplication,
Persp. in Math., Vol. 3, Academic Press, 1987.
G. Shimura, Introduction to the Arithmetic Theory of Automorphic Functions,
Iwanami Shoten and Princeton University Press, 1971.
, On the holomorphy of certain Dirichlet series, Proc. London Math. Soc.
(3) 31 (1975), 79-98.
, The special values of the zeta function associated with cusp forms, Comm.
Pure and Appl. Math. 29 (1976), 783-803.

MODULAR ELLIPTIC CURVES AND FERMATS LAST THEOREM


[Sh4]
[Ta]
[Ti1]
[Ti2]
[Tu]
[TW]
[We]
[Wi1]
[Wi2]
[Wi3]
[Wi4]
[Win]

551

, On elliptic curves with complex multiplication as factors of the Jacobians


of modular function fields, Nagoya Math. J. 43 (1971), 1999-208.
J.Tate,p-divisible groups, Proc.Conf.on Local Fields,Driebergen,1966,SpringerVerlag, 1967, pp. 158-183.
J.Tilouine,Un sous-groupe p-divisible de la jacobienne de X1(Npr) comme module
sur lalgebre de Hecke, Bull. Soc. Math. France 115 (1987), 329-360.
, Th
eorie dIwasawa classique et de lalgebre de Hecke ordinaire, Comp.
Math. 65 (1988), 265-320.
J.Tunnell,Artins conjecture for representations of octahedral type,Bull.A.M.S.
5 (1981), 173-175.
R. Taylor and A. Wiles, Ring theoretic properties of certain Hecke algebras,
Ann. of Math. 141 (1995), 553-572.
A.Weil,Uber die Bestimmung Dirichletscher Reihen durch Funktionalgleichungen,
Math. Ann. 168 (1967), 149-156.
A.Wiles, On ordinary -adic representations associated to modular forms, Invent.
Math. 94 (1988), 529-573.
,On p-adic representations for totally real fields, Ann.of Math.123(1986),
407-456.
, Modular curves and the class group of Q(p ), Invent. Math. 58 (1980),
1-35.
, The Iwasawa conjecture for totally real fields, Ann. of Math. 131 (1990),
493-540.
J.P.Wintenberger, Structure galoisienne de limites projectives dunit
ees locales,
Comp. Math. 42 (1982), 89-103.
(Received October 14, 1994)

You might also like