Maths●●●●●Difficulty 4 of 5

How can a key twelve times shorter be just as secure?

A 256-bit elliptic-curve key should be about as hard to break as a 3,072-bit RSA key, and Bitcoin has signed its transactions with elliptic curves from the start.

▶ Start the story

By building the lock from a harder-to-shortcut problem. Elliptic-curve cryptography (ECC) is public-key cryptography built on the algebraic structure of elliptic curves over finite fields, and the fastest known ways to attack it need roughly the square root of the number of possibilities. So a curve only needs about twice as many bits as the security level you want: 256 bits for 128-bit security. RSA, which rests on factoring a huge number, needs a 3,072-bit number for the same protection. That makes a 256-bit elliptic-curve key comparable to a 3,072-bit RSA key, saving storage and transmission.

Four panels of the same elliptic curve, each crossed by a straight line through points labeled P, Q and R
Adding points on an elliptic curve: a line through two points generally meets the curve at a third. Adding a point to itself k times gives kP, and recovering k is the hard problem.Photo: SuperManu · CC BY-SA 3.0

The idea was suggested independently by Neal Koblitz and Victor S. Miller in 1985, though elliptic-curve algorithms only entered wide use starting in 2004. Along the way, the U.S. National Institute of Standards and Technology recommended fifteen elliptic curves for its Digital Signature Standard in 1999, and in 2005 the NSA announced Suite B, which used ECC for signatures and key exchange. Bitcoin, too, signed its transactions with a custom elliptic curve and the ECDSA algorithm until a 2021 upgrade added another kind of signature.

The hard problem itself is easy to state: given a public starting point P on the curve and another point Q reached by adding P to itself a secret number k of times, it should be infeasible to recover k. Computing Q from k is quick; going back from Q to k is the part no known shortcut makes easy.

None of this makes elliptic curves immune to scrutiny. A historic 112-bit elliptic-curve challenge was broken in 2009 using a cluster of over 200 PlayStation 3 game consoles, and in 2013 The New York Times reported that an elliptic-curve random number generator had become a NIST standard under NSA influence, with a deliberate weakness in the algorithm and its recommended curve. The lesson: which curve and which standard you trust matters as much as the math.

Quiz me

0/3

  1. 1.Why does 128-bit security with elliptic curves need a curve of only about 256 bits?
  2. 2.What did the 2009 PlayStation 3 cluster demonstrate about elliptic-curve cryptography?
  3. 3.What did the 2013 Dual_EC_DRBG revelation show about elliptic-curve cryptography's security?

Recap

The fastest attacks need about the square root of the possibilities, so a curve needs only twice the bits of the security level, but the chosen curve still has to be trustworthy.

Surprising fact · A 256-bit elliptic-curve key should match the security of a 3,072-bit RSA key.

Sources (3)

No source, no claim. Every fact in this lesson (15 claims) cites at least one of these.

  1. [1]Elliptic-curve cryptography · Wikipedia
  2. [2]Bitcoin · Wikipedia
  3. [3]Elliptic curve · Wikipedia
More lessons in ➗ Maths (3) See all maths lessons →

One more light on your map.

Get one lesson like this every day, about the things you love. Free, in two or five minutes.

Get the share card for this lesson ↗