๐ Cryptographic Key Strength Reference
| Symmetric (AES, etc.) | RSA/DH key length | ECC key length |
|---|---|---|
| 80 | 1,024 | 160 |
| 112 | 2,048 | 224 |
| 128 | 3,072 | 256 |
| 192 | 7,680 | 384 |
| 256 | 15,360 | 521 |
Compare symmetric key sizes (like AES) against the RSA/DH key length and ECC (elliptic curve) key length needed for equivalent security strength. Based on the widely cited approximate equivalences from NIST SP 800-57.
How to use
- Select the symmetric key size you want to check.
- The equivalent RSA/DH and ECC key lengths are shown automatically.
- See the full reference table below for all sizes.
How the calculation works
This chart summarises the equivalent key sizes for different kinds of cryptography from NIST Special Publication 800-57 Part 1. Cryptographic strength is compared in "bits of security": 128-bit security means about 2ยนยฒโธ operations to find the key by brute force. For symmetric ciphers such as AES, the key length is essentially the security strength. RSA and Diffie-Hellman can be attacked with efficient factoring and discrete-logarithm algorithms, so they need much longer keys for the same strength. Elliptic curve cryptography (ECC) reaches the same strength with keys about twice the symmetric length. Selecting a row highlights the symmetric, RSA/DH and ECC key sizes for that strength.
Worked example
128-bit security Symmetric: 128 bits (AES-128) RSA / DH: 3072 bits Elliptic curve: 256 bits (such as P-256) The widely used RSA-2048 corresponds to 112-bit security. NIST allows 112-bit-equivalent keys until the end of 2030 and expects a move to 128-bit strength or higher after that.
Things to be aware of
- 80-bit-equivalent keys (such as RSA-1024) are no longer considered secure.
- A large-scale quantum computer is expected to break RSA and elliptic curve cryptography. NIST published post-quantum standards (ML-KEM, ML-DSA and others) in 2024.
- Quantum attacks are thought to roughly halve the strength of symmetric ciphers, so AES-256 would remain strong.
FAQ
Why do different key types need such different bit sizes?
Factorization- and discrete-log-based algorithms like RSA and DH need much larger key sizes than symmetric ciphers (AES) or elliptic curve cryptography (ECC) to reach the same security level.
How secure is 128-bit AES?
128-bit AES is considered roughly equivalent in strength to a 3072-bit RSA/DH key or a 256-bit ECC key.
Are these numbers absolute?
No, these are general guidelines from NIST SP 800-57. Actual security also depends on implementation quality and advances in attack techniques.