🔑 Key Size Security Reference
A quick comparison of common RSA and elliptic-curve key sizes against their approximate equivalent symmetric-cipher security strength, per NIST guidance.
What the middle column means
Nothing is computed here: the table is a fixed list of eight key types, filtered by substring against the name. The strength figures are the comparable-strength estimates from NIST SP 800-57, and they answer one question - how much work would breaking this key cost, expressed as the symmetric cipher that would cost the same to brute-force.
The two families scale very differently. Elliptic curves fall to Pollard's rho at about 2n/2 operations, so strength is simply half the curve size: P-256 gives 128 bits, P-384 gives 192. RSA faces the number field sieve, which is far better than brute force, so bits buy less and less - 2048 is worth 112, 3072 is worth 128, and doubling again to 4096 only reaches about 152.
ec narrows to the three NIST curves; typing 128 returns
no matches even though three rows are 128-bit.Picking one in practice
- P-256 or RSA 2048 for public TLS. Both are universally supported; P-256 gives more security for a much smaller key.
- RSA 4096 is rarely worth it. It costs signing time on every handshake for 24 bits of headroom over 3072.
- Ed25519 is excellent for SSH and code signing, but public CAs cannot issue TLS certificates for it, so a web server key is not the place.
To read the size off something you already have:
openssl x509 -in cert.pem -noout -text | grep -A1 "Public Key Algorithm".
Frequently asked questions
Is RSA 2048 still safe in 2026?
Yes, and CAs still accept it, but it is the floor rather than a recommendation. NIST guidance treats 112-bit security as disallowed after 2030, so anything you expect to still be running then should be P-256 or RSA 3072.
Why is RSA 3072 equivalent to a 256-bit curve?
Both cost an attacker roughly 2128 operations. The curve needs 256 bits to reach that because the best attack is square-root; RSA needs 3072 because factoring, while hard, is much easier than searching a key space.
Do these numbers hold against quantum computers?
No. The column is classical strength. Shor's algorithm breaks RSA and elliptic curves alike, and a bigger RSA key does not help; that is a different problem, solved by post-quantum algorithms rather than by more bits.