๐Ÿ” Cryptographic Key Strength Reference

Symmetric (AES, etc.)128-bit
RSA/DH key length3,072-bit
ECC key length256-bit
Reference table
Symmetric (AES, etc.)RSA/DH key lengthECC key length
801,024160
1122,048224
1283,072256
1927,680384
25615,360521

Compare symmetric key sizes (like AES) against the RSA/DH key length and ECC (elliptic curve) key length needed for equivalent security strength. Based on the widely cited approximate equivalences from NIST SP 800-57.

How to use

  1. Select the symmetric key size you want to check.
  2. The equivalent RSA/DH and ECC key lengths are shown automatically.
  3. See the full reference table below for all sizes.

How the calculation works

This chart summarises the equivalent key sizes for different kinds of cryptography from NIST Special Publication 800-57 Part 1. Cryptographic strength is compared in "bits of security": 128-bit security means about 2ยนยฒโธ operations to find the key by brute force. For symmetric ciphers such as AES, the key length is essentially the security strength. RSA and Diffie-Hellman can be attacked with efficient factoring and discrete-logarithm algorithms, so they need much longer keys for the same strength. Elliptic curve cryptography (ECC) reaches the same strength with keys about twice the symmetric length. Selecting a row highlights the symmetric, RSA/DH and ECC key sizes for that strength.

Worked example

128-bit security Symmetric: 128 bits (AES-128) RSA / DH: 3072 bits Elliptic curve: 256 bits (such as P-256) The widely used RSA-2048 corresponds to 112-bit security. NIST allows 112-bit-equivalent keys until the end of 2030 and expects a move to 128-bit strength or higher after that.

Things to be aware of

  • 80-bit-equivalent keys (such as RSA-1024) are no longer considered secure.
  • A large-scale quantum computer is expected to break RSA and elliptic curve cryptography. NIST published post-quantum standards (ML-KEM, ML-DSA and others) in 2024.
  • Quantum attacks are thought to roughly halve the strength of symmetric ciphers, so AES-256 would remain strong.

FAQ

Why do different key types need such different bit sizes?

Factorization- and discrete-log-based algorithms like RSA and DH need much larger key sizes than symmetric ciphers (AES) or elliptic curve cryptography (ECC) to reach the same security level.

How secure is 128-bit AES?

128-bit AES is considered roughly equivalent in strength to a 3072-bit RSA/DH key or a 256-bit ECC key.

Are these numbers absolute?

No, these are general guidelines from NIST SP 800-57. Actual security also depends on implementation quality and advances in attack techniques.