On Sat, Oct 11, 2025 at 12:31:57PM +0530, tirumal reddy wrote:
> 
> For the P-256, the equivalent symmetric security level is 128 bits, it
> should be paired with the AES-128 algorithm for a matching security
> strength.

The (pre-quantum) strengths of P-256 and AES-128 can not be directly
compared because scaling is different (P-256 has quadric scaling and
AES-128 has linear scaling). However, P-256 is clearly stronger of the
two.

Even worse would be trying to to match strengths of confidentiality
and authentication. See RFC9420 for an example of this going very
wrong.




-Ilari

_______________________________________________
jose mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to