{"id":2492,"date":"2018-03-29T05:48:11","date_gmt":"2018-03-29T05:48:11","guid":{"rendered":"https:\/\/www.thesslstore.com\/knowledgebase\/?post_type=ht_kb&#038;p=2492"},"modified":"2023-11-13T21:38:11","modified_gmt":"2023-11-13T21:38:11","slug":"elliptic-curve-cryptography-ecc","status":"publish","type":"ht_kb","link":"https:\/\/www.thesslstore.com\/knowledgebase\/ssl-basics\/elliptic-curve-cryptography-ecc\/","title":{"rendered":"Elliptic Curve Cryptography (ECC) Certificates"},"content":{"rendered":"<p>Cryptography, the science of encrypting data and information, is the backbone of SSL. Every time you visit a website that is secured by an SSL certificate, your computer works with that website\u2019s server to <strong>encrypt<\/strong> and then <strong>decipher<\/strong> all data sent over the connection. Without going into too much detail, this process is made possible by the computation of a specific algorithm that is used to sign that website\u2019s certificate.<\/p>\n<p>The most commonly used signature algorithm is RSA (Rivest-Shamir-Adleman, named for the first people to work with it). The vast majority of SSL certificates are signed by an RSA algorithm that is incredibly difficult to solve without the associated private key.<\/p>\n<p>Although RSA is the industry standard signature algorithm, many system admins rightfully believe that one can never be too secure. Any SSL user that is not satisfied with the strength of RSA might be interested in a relatively newer cryptographic signature algorithm called Elliptic Curve Cryptography (ECC), which is thought to be significantly harder to break into than RSA due to its discrete mathematical properties.<\/p>\n<h2>Overview of Elliptic Curve Cryptography (ECC)<\/h2>\n<p>The signature algorithm of Elliptical Curve Cryptography is based on the algebraic properties of <strong>eliptical curves<\/strong>. Because ECC uses a different, more complex algorithm, ECC private keys are generally much shorter in length than RSA keys, but are also considerably stronger. A 256-bit ECC key is equal in power to a 3072-bit RSA key&#8211;for reference, the industry standard RSA key size for SSL certificates is 2048-bits.<\/p>\n<p>This difference in strength does not mean that the widely-used RSA algorithm is insecure or being phased out any time soon. ECC simply grants an even higher level of security than is standard, and often allows systems to complete their \u201chandshakes\u201d over a secured connection <strong>faster<\/strong> than usual because of the shorter key.<\/p>\n<p>However, there are a few reasons why you might not want to switch to ECC just yet. It\u2019s a newer algorithm, which means it hasn\u2019t been as thoroughly tested for <strong>vulnerabilities<\/strong> as the tried and true RSA. There are also a number of browsers, servers, and devices that don\u2019t support it, and will not be able to create a secure connection with a website that uses an ECC certificate. Additionally, slower processors can take longer to decipher ECC encrypted data because the algorithm is just that much more <strong>complicated<\/strong> than RSA.<\/p>\n<h2>How to Get an ECC Certificate<\/h2>\n<p>Any SSL certificate issued by DigiCert or Sectigo can use the ECC algorithm as long as you submit the right kind of certificate signing request.<\/p>\n<p>When you\u2019re ready to generate your certificate, you\u2019ll need to create an <strong>ECC Certificate Signing Request<\/strong> on your system. This should be something you enable during the CSR generation process on your server. Then all you have to do is finish the SSL process the same way it\u2019s always done. After validation the Certificate Authority will provide an ECC signed certificate to you, ready to secure your domain.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cryptography, the science of encrypting data and information, is the backbone of SSL. Every time you visit a website that is secured by an SSL certificate, your computer works with that website\u2019s server to encrypt and then decipher all data sent over the connection. Without going into too much detail,&#8230;<\/p>\n","protected":false},"author":1,"comment_status":"closed","ping_status":"closed","template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"ht-kb-category":[67],"ht-kb-tag":[],"class_list":["post-2492","ht_kb","type-ht_kb","status-publish","format-standard","hentry","ht_kb_category-ssl-basics"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Overview of Elliptic Curve Cryptography (ECC) - The SSL Store\u2122<\/title>\n<meta name=\"description\" content=\"Although RSA is the industry standard signature algorithm, many system admins rightfully believe that one can never be too secure. Any SSL user that is not satisfied with the strength of RSA might be interested in a relatively newer cryptographic signature algorithm called Elliptic Curve Cryptography (ECC)\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.thesslstore.com\/knowledgebase\/ssl-support\/elliptic-curve-cryptography-ecc\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Overview of Elliptic Curve Cryptography (ECC) - The SSL Store\u2122\" \/>\n<meta property=\"og:description\" content=\"Although RSA is the industry standard signature algorithm, many system admins rightfully believe that one can never be too secure. Any SSL user that is not satisfied with the strength of RSA might be interested in a relatively newer cryptographic signature algorithm called Elliptic Curve Cryptography (ECC)\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.thesslstore.com\/knowledgebase\/ssl-support\/elliptic-curve-cryptography-ecc\/\" \/>\n<meta property=\"og:site_name\" content=\"Knowledge Base\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/thesslstoredotcom\" \/>\n<meta property=\"article:modified_time\" content=\"2023-11-13T21:38:11+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.thesslstore.com\/knowledgebase\/wp-content\/uploads\/2017\/04\/thesslstore.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"300\" \/>\n\t<meta property=\"og:image:height\" content=\"300\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"Overview of Elliptic Curve Cryptography (ECC) - The SSL Store\u2122\" \/>\n<meta name=\"twitter:description\" content=\"Although RSA is the industry standard signature algorithm, many system admins rightfully believe that one can never be too secure. Any SSL user that is not satisfied with the strength of RSA might be interested in a relatively newer cryptographic signature algorithm called Elliptic Curve Cryptography (ECC)\" \/>\n<meta name=\"twitter:site\" content=\"@thesslstore\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"3 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Overview of Elliptic Curve Cryptography (ECC) - The SSL Store\u2122","description":"Although RSA is the industry standard signature algorithm, many system admins rightfully believe that one can never be too secure. Any SSL user that is not satisfied with the strength of RSA might be interested in a relatively newer cryptographic signature algorithm called Elliptic Curve Cryptography (ECC)","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.thesslstore.com\/knowledgebase\/ssl-support\/elliptic-curve-cryptography-ecc\/","og_locale":"en_US","og_type":"article","og_title":"Overview of Elliptic Curve Cryptography (ECC) - The SSL Store\u2122","og_description":"Although RSA is the industry standard signature algorithm, many system admins rightfully believe that one can never be too secure. Any SSL user that is not satisfied with the strength of RSA might be interested in a relatively newer cryptographic signature algorithm called Elliptic Curve Cryptography (ECC)","og_url":"https:\/\/www.thesslstore.com\/knowledgebase\/ssl-support\/elliptic-curve-cryptography-ecc\/","og_site_name":"Knowledge Base","article_publisher":"https:\/\/www.facebook.com\/thesslstoredotcom","article_modified_time":"2023-11-13T21:38:11+00:00","og_image":[{"width":300,"height":300,"url":"https:\/\/www.thesslstore.com\/knowledgebase\/wp-content\/uploads\/2017\/04\/thesslstore.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_title":"Overview of Elliptic Curve Cryptography (ECC) - The SSL Store\u2122","twitter_description":"Although RSA is the industry standard signature algorithm, many system admins rightfully believe that one can never be too secure. Any SSL user that is not satisfied with the strength of RSA might be interested in a relatively newer cryptographic signature algorithm called Elliptic Curve Cryptography (ECC)","twitter_site":"@thesslstore","twitter_misc":{"Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.thesslstore.com\/knowledgebase\/ssl-basics\/elliptic-curve-cryptography-ecc\/","url":"https:\/\/www.thesslstore.com\/knowledgebase\/ssl-support\/elliptic-curve-cryptography-ecc\/","name":"Overview of Elliptic Curve Cryptography (ECC) - The SSL Store\u2122","isPartOf":{"@id":"https:\/\/www.thesslstore.com\/knowledgebase\/#website"},"datePublished":"2018-03-29T05:48:11+00:00","dateModified":"2023-11-13T21:38:11+00:00","description":"Although RSA is the industry standard signature algorithm, many system admins rightfully believe that one can never be too secure. Any SSL user that is not satisfied with the strength of RSA might be interested in a relatively newer cryptographic signature algorithm called Elliptic Curve Cryptography (ECC)","breadcrumb":{"@id":"https:\/\/www.thesslstore.com\/knowledgebase\/ssl-support\/elliptic-curve-cryptography-ecc\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.thesslstore.com\/knowledgebase\/ssl-support\/elliptic-curve-cryptography-ecc\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.thesslstore.com\/knowledgebase\/ssl-support\/elliptic-curve-cryptography-ecc\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.thesslstore.com\/knowledgebase\/"},{"@type":"ListItem","position":2,"name":"Elliptic Curve Cryptography (ECC) Certificates"}]},{"@type":"WebSite","@id":"https:\/\/www.thesslstore.com\/knowledgebase\/#website","url":"https:\/\/www.thesslstore.com\/knowledgebase\/","name":"Knowledge Base","description":"TheSSLstore","publisher":{"@id":"https:\/\/www.thesslstore.com\/knowledgebase\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.thesslstore.com\/knowledgebase\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.thesslstore.com\/knowledgebase\/#organization","name":"The SSL Store\u2122","url":"https:\/\/www.thesslstore.com\/knowledgebase\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.thesslstore.com\/knowledgebase\/#\/schema\/logo\/image\/","url":"https:\/\/www.thesslstore.com\/knowledgebase\/wp-content\/uploads\/2017\/04\/thesslstore.jpg","contentUrl":"https:\/\/www.thesslstore.com\/knowledgebase\/wp-content\/uploads\/2017\/04\/thesslstore.jpg","width":300,"height":300,"caption":"The SSL Store\u2122"},"image":{"@id":"https:\/\/www.thesslstore.com\/knowledgebase\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/thesslstoredotcom","https:\/\/x.com\/thesslstore","https:\/\/www.linkedin.com\/company\/the-ssl-store","https:\/\/www.youtube.com\/user\/thesslstore"]}]}},"_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/knowledgebase\/wp-json\/wp\/v2\/ht-kb\/2492","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/knowledgebase\/wp-json\/wp\/v2\/ht-kb"}],"about":[{"href":"https:\/\/www.thesslstore.com\/knowledgebase\/wp-json\/wp\/v2\/types\/ht_kb"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/knowledgebase\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/knowledgebase\/wp-json\/wp\/v2\/comments?post=2492"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/knowledgebase\/wp-json\/wp\/v2\/ht-kb\/2492\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/knowledgebase\/wp-json\/wp\/v2\/media?parent=2492"}],"wp:term":[{"taxonomy":"ht_kb_category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/knowledgebase\/wp-json\/wp\/v2\/ht-kb-category?post=2492"},{"taxonomy":"ht_kb_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/knowledgebase\/wp-json\/wp\/v2\/ht-kb-tag?post=2492"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}