The group behind modern public-key cryptography. Pick a curve over a small prime field, list all its points, add and double them with the chord-and-tangent rule, and run a key exchange on the result — the same arithmetic TLS uses, just small enough to see.
The same exchange as the integer version, with point addition replacing multiplication. Alice and Bob each pick a secret scalar, publish their multiple of the base point, and multiply what they receive by their own secret.
The base point G is the first point listed on the curve. An eavesdropper sees G, nAG and nBG and must find nA from them — the elliptic curve discrete logarithm problem, and the reason a 256-bit curve matches a 3072-bit RSA key.
s = (y2-y1)/(x2-x1), x3 = s^2-x1-x2, y3 = s(x1-x3)-y1
Draw the line through two points on the curve. A line meets a cubic in exactly three places, so it hits one more point — reflect that third point in the x-axis and you have the sum.
When the two points coincide, use the tangent instead: that is doubling, and the slope comes from implicit differentiation, s = (3x² + a) / 2y.
The point at infinity plays the role of zero, and the negative of (x, y) is (x, −y). With those conventions the points form an abelian group, which is all a cryptosystem needs.
Over a finite field there is no curve to look at — just a scatter of points — but the formulas are identical, with division replaced by multiplication by a modular inverse.
Elliptic curve cryptography does the same jobs as RSA and Diffie-Hellman with far smaller keys. The reason is not that the curve is cleverer — it is about which attacks exist:
The tool shows the mechanism — the slides show why it is built that way.
Why does adding points work? Why is the group law associative? Why are the keys so much shorter? One-on-one tutoring builds elliptic curve cryptography from the geometry up.