Elliptische-Kurven-Kryptografie (ECC)
Ein Public-Key-Kryptosystem, dessen Sicherheit auf der mathematischen Schwierigkeit des Elliptic Curve Discrete Logarithm Problem (ECDLP) basiert und gleichwertige Sicherheit wie RSA mit deutlich kleineren Schlüsselgrößen bietet.
Post-Quantum-Migration: NIST hat ML-KEM (Kyber) und ML-DSA (Dilithium) als Nachfolger für ECDH und ECDSA standardisiert. TLS 1.3 führt hybriden Schlüsselaustausch (X25519+Kyber) ein.
graph LR
Center["Elliptische-Kurven-Kryptografie (ECC)"]:::main
Pre_cryptography["cryptography"]:::pre --> Center
click Pre_cryptography "/terms/cryptography"
Pre_asymmetric_encryption["asymmetric-encryption"]:::pre --> Center
click Pre_asymmetric_encryption "/terms/asymmetric-encryption"
Rel_private_key["private-key"]:::related -.-> Center
click Rel_private_key "/terms/private-key"
Rel_public_key["public-key"]:::related -.-> Center
click Rel_public_key "/terms/public-key"
Rel_public_key_cryptography["public-key-cryptography"]:::related -.-> Center
click Rel_public_key_cryptography "/terms/public-key-cryptography"
classDef main fill:#7c3aed,stroke:#8b5cf6,stroke-width:2px,color:white,font-weight:bold,rx:5,ry:5;
classDef pre fill:#0f172a,stroke:#3b82f6,color:#94a3b8,rx:5,ry:5;
classDef child fill:#0f172a,stroke:#10b981,color:#94a3b8,rx:5,ry:5;
classDef related fill:#0f172a,stroke:#8b5cf6,stroke-dasharray: 5 5,color:#94a3b8,rx:5,ry:5;
linkStyle default stroke:#4b5563,stroke-width:2px;
🧒 Erkläre es wie einem 5-Jährigen
Stell dir eine magische Multiplikation vor, die in eine Richtung einfach, aber unmöglich zu umzukehren ist. Du multiplizierst einen speziellen Punkt auf einer Kurve mit einer Geheimzahl (dein privater Schlüssel) und erhältst einen öffentlichen Punkt (dein öffentlicher Schlüssel). Aber wenn jemand nur den öffentlichen Punkt und den ursprünglichen Punkt kennt, würde es länger dauern als das Alter des Universums, deine Geheimzahl zurückzurechnen — selbst mit einem Supercomputer. Diese Einweg-Mathematik macht ECC so leistungsfähig.
🤓 Expert Deep Dive
Gruppenstruktur: y² ≡ x³ + ax + b (mod p). secp256k1-Parameter: a=0, b=7, p = 2²⁵⁶ - 2³² - 977. Schlüsselgrößen-Äquivalenz (NIST SP 800-57): 256-Bit ECC = 3072-Bit RSA (128-Bit Sicherheitsniveau). Curve25519: Von Daniel Bernstein für Constant-Time-Implementierung entwickelt — keine geheimen Datenverzweigungen — inherent resistent gegen Timing-Seitenkanalangriffe. X25519 ist in TLS 1.3 vorgeschrieben. Dual_EC_DRBG-Backdoor (2013): Snowden-Dokumente enthüllten einen mutmaßlichen NSA-Backdoor im NIST-RNG mit ECC-Konstanten.
❓ Häufig gestellte Fragen
Why is ECC more efficient than RSA?
ECC achieves the same security level as RSA with much smaller key sizes (256-bit ECC ≈ 3072-bit RSA). Smaller keys mean faster signature generation/verification, less bandwidth for certificate transmission, and lower computational overhead — critical for constrained devices like hardware wallets and IoT sensors.
What is the difference between ECC and ECDSA?
ECC is the mathematical framework (the geometry of elliptic curves over finite fields). ECDSA is a specific digital signature algorithm that uses ECC mathematics. Similarly, ECDH is a key agreement protocol built on ECC. ECC is the foundation; ECDSA and ECDH are applications built on top of it.
Why do Bitcoin and Ethereum use secp256k1 instead of the more common P-256 (NIST) curve?
Satoshi Nakamoto chose secp256k1 — a less common curve at the time — partly because P-256 was designed with NSA-selected constants of unclear provenance. secp256k1 parameters are derived transparently from the simple equation y² = x³ + 7, with no arbitrary constants that could hide a backdoor.