ECC and SHA Algorithms

ECC and SHA Algorithms

SSL certificates typically use RSA keys, and the recommended size for these keys keeps growing (for example, from 1024 bits to 2048 bits over the past few years). This is tied to maintaining adequate cryptographic strength. Both key types rely on asymmetric algorithms (one key for encryption, another for decryption). However, ECC (Elliptic Curve Cryptography) provides the same level of cryptographic strength while using much smaller keys, offering increased security and reduced computational requirements. Let's take a look at what ECC is and why you should consider using it.

What is ECC?

ECC is a public-key cryptography method based on the use of elliptic curves over finite fields. The key difference between ECC and RSA is the relationship between cryptographic strength and key size. ECC offers cryptographic strength equivalent to RSA while using much smaller keys. For example, a 256-bit ECC key is equivalent to a 3072-bit RSA key (which is 50% longer than the 2048-bit keys used today). As a result, since the most secure symmetric algorithms used in TLS (such as AES) use at least 128-bit keys, moving to asymmetric keys of a comparable strength seems like the most sensible step.

Why Should We Use ECC?

The small key size makes ECC an ideal choice for devices with limited storage or processing resources — devices that are becoming increasingly common, especially in the IoT (Internet of Things) space. On the server side, the smaller key size speeds up SSL handshakes, shortening page load times and increasing security.

Which Certificates Support ECC?

  • All Sectigo SSL certificates
  • All GoGetSSL certificates
  • DigiCert PRO products

How Do I Generate an ECC Key?

We've published a detailed guide on generating an ECC private key and CSR code. Please refer to the Wiki guide.

Conclusion

We use ECC Certificates to secure our own services and recommend all webmasters do the same.

Can't find the answer you need?

Contact Us