Criptografia de Curva Elíptica (ECC)
Um sistema criptográfico de chave pública cuja segurança se baseia na dificuldade matemática do Problema do Logaritmo Discreto em Curva Elíptica (ECDLP), oferecendo segurança equivalente ao RSA com tamanhos de chave muito menores.
Migração pós-quântica: NIST padronizou ML-KEM (Kyber) e ML-DSA (Dilithium) como substitutos do ECDH e ECDSA. TLS 1.3 implementa troca de chaves híbrida (X25519+Kyber).
graph LR
Center["Criptografia de Curva Elíptica (ECC)"]:::main
Pre_cryptography["cryptography"]:::pre --> Center
click Pre_cryptography "/terms/cryptography"
Pre_asymmetric_encryption["asymmetric-encryption"]:::pre --> Center
click Pre_asymmetric_encryption "/terms/asymmetric-encryption"
Rel_private_key["private-key"]:::related -.-> Center
click Rel_private_key "/terms/private-key"
Rel_public_key["public-key"]:::related -.-> Center
click Rel_public_key "/terms/public-key"
Rel_public_key_cryptography["public-key-cryptography"]:::related -.-> Center
click Rel_public_key_cryptography "/terms/public-key-cryptography"
classDef main fill:#7c3aed,stroke:#8b5cf6,stroke-width:2px,color:white,font-weight:bold,rx:5,ry:5;
classDef pre fill:#0f172a,stroke:#3b82f6,color:#94a3b8,rx:5,ry:5;
classDef child fill:#0f172a,stroke:#10b981,color:#94a3b8,rx:5,ry:5;
classDef related fill:#0f172a,stroke:#8b5cf6,stroke-dasharray: 5 5,color:#94a3b8,rx:5,ry:5;
linkStyle default stroke:#4b5563,stroke-width:2px;
🧒 Explique como se eu tivesse 5 anos
Imagine uma multiplicação mágica fácil em uma direção mas impossível de reverter. Você multiplica um ponto especial em uma curva por um número secreto (sua chave privada) para obter um ponto público (sua chave pública). Mas se alguém conhece apenas o ponto público e o ponto original, reconstruir seu número secreto levaria mais tempo que a idade do universo — mesmo com um supercomputador. Essa matemática de sentido único é o que torna a ECC tão poderosa.
🤓 Expert Deep Dive
Estrutura de grupo: y² ≡ x³ + ax + b (mod p). Parâmetros secp256k1: a=0, b=7, p = 2²⁵⁶ - 2³² - 977. Equivalências de tamanho de chave (NIST SP 800-57): 256 bits ECC = 3072 bits RSA (128 bits de segurança). Curve25519: projetada por Daniel Bernstein para implementação em tempo constante, inerentemente resistente a ataques de canal lateral de temporização. X25519 é obrigatória no TLS 1.3. Backdoor Dual_EC_DRBG (2013): documentos Snowden revelaram um presunto backdoor NSA no gerador aleatório NIST baseado em ECC.
❓ Perguntas frequentes
Why is ECC more efficient than RSA?
ECC achieves the same security level as RSA with much smaller key sizes (256-bit ECC ≈ 3072-bit RSA). Smaller keys mean faster signature generation/verification, less bandwidth for certificate transmission, and lower computational overhead — critical for constrained devices like hardware wallets and IoT sensors.
What is the difference between ECC and ECDSA?
ECC is the mathematical framework (the geometry of elliptic curves over finite fields). ECDSA is a specific digital signature algorithm that uses ECC mathematics. Similarly, ECDH is a key agreement protocol built on ECC. ECC is the foundation; ECDSA and ECDH are applications built on top of it.
Why do Bitcoin and Ethereum use secp256k1 instead of the more common P-256 (NIST) curve?
Satoshi Nakamoto chose secp256k1 — a less common curve at the time — partly because P-256 was designed with NSA-selected constants of unclear provenance. secp256k1 parameters are derived transparently from the simple equation y² = x³ + 7, with no arbitrary constants that could hide a backdoor.