Cryptographie sur Courbes Elliptiques (ECC)

Un système cryptographique à clé publique dont la sécurité repose sur la difficulté mathématique du problème du logarithme discret sur courbe elliptique (ECDLP), offrant une sécurité équivalente à RSA avec des clés beaucoup plus petites.

Migration post-quantique : NIST a standardisé ML-KEM (Kyber) et ML-DSA (Dilithium) pour remplacer ECDH et ECDSA. TLS 1.3 introduit un échange de clés hybride (X25519+Kyber).

        graph LR
  Center["Cryptographie sur Courbes Elliptiques (ECC)"]:::main
  Pre_cryptography["cryptography"]:::pre --> Center
  click Pre_cryptography "/terms/cryptography"
  Pre_asymmetric_encryption["asymmetric-encryption"]:::pre --> Center
  click Pre_asymmetric_encryption "/terms/asymmetric-encryption"
  Rel_private_key["private-key"]:::related -.-> Center
  click Rel_private_key "/terms/private-key"
  Rel_public_key["public-key"]:::related -.-> Center
  click Rel_public_key "/terms/public-key"
  Rel_public_key_cryptography["public-key-cryptography"]:::related -.-> Center
  click Rel_public_key_cryptography "/terms/public-key-cryptography"
  classDef main fill:#7c3aed,stroke:#8b5cf6,stroke-width:2px,color:white,font-weight:bold,rx:5,ry:5;
  classDef pre fill:#0f172a,stroke:#3b82f6,color:#94a3b8,rx:5,ry:5;
  classDef child fill:#0f172a,stroke:#10b981,color:#94a3b8,rx:5,ry:5;
  classDef related fill:#0f172a,stroke:#8b5cf6,stroke-dasharray: 5 5,color:#94a3b8,rx:5,ry:5;
  linkStyle default stroke:#4b5563,stroke-width:2px;

      

🧒 Explique-moi comme si j'avais 5 ans

Imagine une multiplication magique facile dans un sens mais impossible à inverser. Tu multiplies un point spécial sur une courbe par un nombre secret (ta clé privée) pour obtenir un point public (ta clé publique). Mais si quelqu'un ne connaît que le point public et le point de départ, retrouver ton nombre secret prendrait plus de temps que l'âge de l'Univers — même avec un superordinateur. C'est cette mathématique à sens unique qui rend l'ECC si puissant.

🤓 Expert Deep Dive

Structure de groupe : y² ≡ x³ + ax + b (mod p). Paramètres secp256k1 : a=0, b=7, p = 2²⁵⁶ - 2³² - 977. Équivalences de clés (NIST SP 800-57) : 256 bits ECC = 3072 bits RSA (128 bits de sécurité). Curve25519 : conçue par Daniel Bernstein pour une implémentation en temps constant — sans branchement sur données secrètes — inhéremment résistante aux attaques par canal auxiliaire de timing. X25519 est obligatoire dans TLS 1.3. Backdoor Dual_EC_DRBG (2013) : les documents Snowden ont révélé un backdoor NSA présumé dans le générateur aléatoire NIST basé sur ECC.

❓ Questions fréquentes

Why is ECC more efficient than RSA?

ECC achieves the same security level as RSA with much smaller key sizes (256-bit ECC ≈ 3072-bit RSA). Smaller keys mean faster signature generation/verification, less bandwidth for certificate transmission, and lower computational overhead — critical for constrained devices like hardware wallets and IoT sensors.

What is the difference between ECC and ECDSA?

ECC is the mathematical framework (the geometry of elliptic curves over finite fields). ECDSA is a specific digital signature algorithm that uses ECC mathematics. Similarly, ECDH is a key agreement protocol built on ECC. ECC is the foundation; ECDSA and ECDH are applications built on top of it.

Why do Bitcoin and Ethereum use secp256k1 instead of the more common P-256 (NIST) curve?

Satoshi Nakamoto chose secp256k1 — a less common curve at the time — partly because P-256 was designed with NSA-selected constants of unclear provenance. secp256k1 parameters are derived transparently from the simple equation y² = x³ + 7, with no arbitrary constants that could hide a backdoor.

🔗 Termes associés

📚 Sources