Overview
Elliptic-curve cryptography (ECC) is an approach to public-key cryptography based on the algebraic structure of elliptic curves over finite fields. ECC allows smaller keys to provide equivalent security, compared to cryptosystems based on modular exponentiation in finite fields, such as the RSA cryptosystem and ElGamal cryptosystem.
Elliptic curves are applicable for key agreement, digital signatures, pseudo-random generators and other tasks. Indirectly, they can be used for encryption by combining the key agreement with a symmetric encryption scheme. They are also used in several integer factorization algorithms that have applications in cryptography, such as Lenstra elliptic-curve factorization.
History
The use of elliptic curves in cryptography was suggested independently by Neal Koblitz and Victor S. Miller in 1985. Elliptic curve cryptography algorithms entered wide use starting in 2004.
In 1999, U.S. NIST recommended fifteen elliptic curves for use in the Digital Signature Standard. These curves were later specified in FIPS 186-4, which was superseded by FIPS 186-5 in 2023 and withdrawn in 2024. NIST moved its recommended elliptic-curve domain parameters to Special Publication 800-186. SP 800-186 includes previously recommended Weierstrass curves and two Edwards curves for EdDSA; it also deprecates binary-field curves and strongly recommends use of prime curves.
At the RSA Conference 2005, the National Security Agency (NSA) announced Suite B, which used ECC for digital signature generation and key exchange. Suite B was later superseded by the Commercial National Security Algorithm Suite (CNSA), and NSA announced CNSA 2.0 as a quantum-resistant transition suite for national security systems.
8 sources for this section
- 1Elliptic-curve cryptography — Wikipedia, revision 1373254036
- 3Koblitz, N. (1987). "Elliptic curve cryptosystems". Mathematics of Computation. 48 (177): 203–209. doi:10.2307/2007884. JSTOR 2007884.
- 4Miller, V. (1986). "Use of Elliptic Curves in Cryptography". Advances in Cryptology — CRYPTO '85 Proceedings. Lecture Notes in Computer Science. Vol. 85. pp. 417–426. doi:10.1007/3-540-39799-X_31. ISBN 978-3-540-16463-0. S2CID 206617984.
- 5"FIPS 186-4, Digital Signature Standard (DSS)". National Institute of Standards and Technology. Retrieved 30 April 2026.
- 6"NIST Releases FIPS 186-5 and SP 800-186". National Institute of Standards and Technology. 3 February 2023. Retrieved 30 April 2026.
Security concerns
In 2013, The New York Times stated that Dual Elliptic Curve Deterministic Random Bit Generation (or Dual_EC_DRBG) had been included as a NIST national standard due to the influence of NSA, which had included a deliberate weakness in the algorithm and the recommended elliptic curve. RSA Security in September 2013 issued an advisory recommending that its customers discontinue using any software based on Dual_EC_DRBG.
In the wake of the exposure of Dual_EC_DRBG as "an NSA undercover operation", cryptography experts have also expressed concern over the security of the NIST recommended elliptic curves, suggesting a return to encryption based on non-elliptic-curve groups.
Additionally, in August 2015, the NSA announced that it planned to replace Suite B with a new cipher suite due to concerns about quantum computing attacks on ECC. NSA later published CNSA 2.0 guidance for a transition to quantum-resistant algorithms for national security systems.
8 sources for this section
- 1Elliptic-curve cryptography — Wikipedia, revision 1373254036
- 9Perlroth, Nicole; Larson, Jeff; Shane, Scott (2013-09-05). "N.S.A. Able to Foil Basic Safeguards of Privacy on Web". New York Times. Archived from the original on 2022-01-01. Retrieved 28 October 2018.
- 10RSA Tells Its Developer Customers: Stop Using NSA-Linked Algorithm
- 11"Search – CSRC". csrc.nist.gov.
- 12Are the NIST Standard Elliptic Curves Back-doored?
- 13"Commercial National Security Algorithm Suite". www.nsa.gov. 19 August 2015. Archived from the original on 2019-06-04. Retrieved 2020-01-08.
Patents
While the RSA patent expired in 2000, there may be patents in force covering certain aspects of ECC technology, including at least one ECC scheme (ECMQV). However, RSA Laboratories and Daniel J. Bernstein have argued that the US government elliptic curve digital signature standard (ECDSA; NIST FIPS 186-3) and certain practical ECC-based key exchange schemes (including ECDH) can be implemented without infringing those patents.
Elliptic curve theory
For the purposes of this article, an elliptic curve is a plane curve over a finite field (rather than the real numbers). A common form for curves over finite fields of characteristic not equal to 2 or 3 consists of the points satisfying the equation
along with a distinguished point at infinity, denoted ∞. Curves over fields of characteristic 2 or 3, and curves used in other representations such as Montgomery or Edwards form, are written differently.
1 source for this section
The source notesEvidence & further reading16 sources
- Elliptic-curve cryptography — Wikipedia, revision 1373254036 Wikipedia contributors · Reference source · accessed 2026-09-22
- "The Case for Elliptic Curve Cryptography". NSA. Archived from the original on 2009-01-17. nsa.gov · Reference source · link imported 2026-09-22
- Koblitz, N. (1987). "Elliptic curve cryptosystems". Mathematics of Computation. 48 (177): 203–209. doi:10.2307/2007884. JSTOR 2007884. jstor.org · Reference source · link imported 2026-09-22
- Miller, V. (1986). "Use of Elliptic Curves in Cryptography". Advances in Cryptology — CRYPTO '85 Proceedings. Lecture Notes in Computer Science. Vol. 85. pp. 417–426. doi:10.1007/3-540-39799-X_31. ISBN 978-3-540-16463-0. S2CID 206617984. api.semanticscholar.org · Reference source · link imported 2026-09-22
- "FIPS 186-4, Digital Signature Standard (DSS)". National Institute of Standards and Technology. Retrieved 30 April 2026. csrc.nist.gov · Reference source · link imported 2026-09-22
- "NIST Releases FIPS 186-5 and SP 800-186". National Institute of Standards and Technology. 3 February 2023. Retrieved 30 April 2026. csrc.nist.gov · Reference source · link imported 2026-09-22
- Chen, Lily; Moody, Dustin; Regenscheid, Andrew; Randall, Karen (February 2023). Recommendations for Discrete Logarithm-Based Cryptography: Elliptic Curve Domain Parameters (PDF) (Report). National Institute of Standards and Technology. doi:10.6028/NIST.SP.800-186. NIST SP 800-186.