Knowledge Base
Elliptic-Curve Parameter
A

prime239v1

Summary

Name:
prime239v1
Long Name:
prime239v1 elliptic curve (239-bit prime field)
Key size:
239 bits
Object identifier:
1.2.840.10045.3.1.4
Publishers:

Check your host!

Type a URL to analyze a service

Get a prompt and clear overview of your security configuration. Right now!

Security

A+
Key Size
Security

The elliptic-curve cryptography[118][119][120][121] is an approach to public-key cryptography[164][165][166] based on the elliptic curve[116][117]s. The most important property in terms of encryption strength, beyond the designer is elliptic curve key size[292][293][294]. All the key sizes available are considered secure, so there is no consideration about it.

A
Trusted Design
Security

The elliptic-curve cryptography[118][119][120][121] is an approach to public-key cryptography[164][165][166] based on the elliptic curve[116][117]s. Note that there is controversy[287][288][289][290][291] around some of the National Institute of Standards and Technology[470][471] designed elliptic curveselliptic curves designed by NIST[285][286].

Recommendations

Add at least one elliptic curve to the list of elliptic curves supported by your server designed by independent researchers and prefer them as server configuration makes it possible.

A
Post-Quantum
Security

The elliptic curve[116][117] cryptography provides no protection against a cryptanalytic attack by a quantum computer, and no classical elliptic curve does — just as classical Diffie-Hellman does not — because a quantum computer breaks the hardness assumption they rely on. Only a hybrid key exchange (a classical algorithm combined with a post-quantum cryptography[158][159] one) or a pure post-quantum algorithm is quantum-safe.

Recommendations

Enable a hybrid key exchange or a pure post-quantum algorithm on your server, and prefer it where the configuration allows, so the connection stays secure against a future quantum computer.

Parameter Numbers

Prime (p)
0x7fffffffffffffffffffffff7fffffffffff8000000000007fffffffffff
Copy to clipboard
Coefficient (a)
0x7fffffffffffffffffffffff7fffffffffff8000000000007ffffffffffc
Copy to clipboard
Coefficient (b)
0x6b016c3bdcf18941d0d654921475ca71a9db2fb27d1d37796185c2942c0a
Copy to clipboard
Generator (x)
0xffa963cdca8816ccc33b8642bedf905c3d358573d3f27fbbd3b3cb9aaaf
Copy to clipboard
Generator (y)
0x7debe8e4e90a5dae6e4054ca530ba04654b36818ce226b39fccb7b02f1ae
Copy to clipboard
Order (n)
0x7fffffffffffffffffffffff7fffff9e5e9a9f5d9071fbd1522688909d0b
Copy to clipboard
Cofactor (h)
0x1
Copy to clipboard

Representations

PEM

-----BEGIN EC PARAMETERS-----
BggqhkjOPQMBBA==
-----END EC PARAMETERS-----
Download ecparam.pem
Copy to clipboard

PARI/GP

p = 0x7fffffffffffffffffffffff7fffffffffff8000000000007fffffffffff;
a = 0x7fffffffffffffffffffffff7fffffffffff8000000000007ffffffffffc;
b = 0x6b016c3bdcf18941d0d654921475ca71a9db2fb27d1d37796185c2942c0a;
E = ellinit([a, b], p);
G = [0xffa963cdca8816ccc33b8642bedf905c3d358573d3f27fbbd3b3cb9aaaf, 0x7debe8e4e90a5dae6e4054ca530ba04654b36818ce226b39fccb7b02f1ae];
n = 0x7fffffffffffffffffffffff7fffff9e5e9a9f5d9071fbd1522688909d0b;
h = 0x1;
Copy to clipboard

LaTeX

$\begin{aligned}
y^2 &\equiv x^3 + a x + b \pmod{p} \\
p &= 0x7fffffffffffffffffffffff7fffffffffff8000000000007fffffffffff \\
a &= 0x7fffffffffffffffffffffff7fffffffffff8000000000007ffffffffffc \\
b &= 0x6b016c3bdcf18941d0d654921475ca71a9db2fb27d1d37796185c2942c0a \\
G &= (0xffa963cdca8816ccc33b8642bedf905c3d358573d3f27fbbd3b3cb9aaaf, 0x7debe8e4e90a5dae6e4054ca530ba04654b36818ce226b39fccb7b02f1ae) \\
n &= 0x7fffffffffffffffffffffff7fffff9e5e9a9f5d9071fbd1522688909d0b \\
h &= 0x1
\end{aligned}$
Copy to clipboard