Cryptography Advanced

Elliptic Curve Arithmetic

The group behind modern public-key cryptography. Pick a curve over a small prime field, list all its points, add and double them with the chord-and-tangent rule, and run a key exchange on the result — the same arithmetic TLS uses, just small enough to see.

All points listed and plotted
Addition and doubling working
Curve Diffie-Hellman
Live
The Curve
Curve: y² ≡ x³ + ax + b (mod p)
Points on the curve—
Discriminant 4a³+27b²—
Hasse interval—
All points — click to set P, shift-click for Q
Point Arithmetic
P + Q
—
2P (tangent rule)
—
—
Order of P—
Every point on the curve. P, Q and P+Q are highlighted.
Chord-and-Tangent Working
Elliptic Curve Diffie-Hellman

The same exchange as the integer version, with point addition replacing multiplication. Alice and Bob each pick a secret scalar, publish their multiple of the base point, and multiply what they receive by their own secret.

nAG—
nA(nBG)—
nBG—
nB(nAG)—

The base point G is the first point listed on the curve. An eavesdropper sees G, nAG and nBG and must find nA from them — the elliptic curve discrete logarithm problem, and the reason a 256-bit curve matches a 3072-bit RSA key.

Adding Points With a Straightedge
s = (y2-y1)/(x2-x1), x3 = s^2-x1-x2, y3 = s(x1-x3)-y1

Draw the line through two points on the curve. A line meets a cubic in exactly three places, so it hits one more point — reflect that third point in the x-axis and you have the sum.

When the two points coincide, use the tangent instead: that is doubling, and the slope comes from implicit differentiation, s = (3x² + a) / 2y.

The point at infinity plays the role of zero, and the negative of (x, y) is (x, −y). With those conventions the points form an abelian group, which is all a cryptosystem needs.

Over a finite field there is no curve to look at — just a scatter of points — but the formulas are identical, with division replaced by multiplication by a modular inverse.

Notice the plot is symmetric about the horizontal midline. That is the reflection y → −y, which is why points pair up and why the group has the structure it does.
Why Curves Beat Integers

Elliptic curve cryptography does the same jobs as RSA and Diffie-Hellman with far smaller keys. The reason is not that the curve is cleverer — it is about which attacks exist:

  • No index calculus. Discrete logs modulo a prime fall to index calculus, which is subexponential, so the prime must be large. No analogue is known for curves, so the best attacks are generic and take about √n steps.
  • So the key can be small. A 256-bit curve gives roughly 128-bit security — comparable to a 3072-bit RSA modulus. That means shorter keys, shorter signatures and less bandwidth per handshake.
  • It is what actually runs. X25519 for key exchange and Ed25519 for signatures are in TLS, SSH, Signal and every modern device. Bitcoin and Ethereum use secp256k1.
  • The advantage is contingent. It rests on an attack not existing, not on a proof. And a quantum computer breaks curves faster than RSA, because the keys are shorter.
Real failures of curve systems are almost never mathematical. They are unvalidated input points, non-constant-time scalar multiplication, and reused signature nonces.
Put It Into Practice

The tool shows the mechanism — the slides show why it is built that way.

Curves, without the hand-waving

Why does adding points work? Why is the group law associative? Why are the keys so much shorter? One-on-one tutoring builds elliptic curve cryptography from the geometry up.

Book a Free Consultation →