On Sat, Oct 11, 2025 at 12:31:57PM +0530, tirumal reddy wrote: > > For the P-256, the equivalent symmetric security level is 128 bits, it > should be paired with the AES-128 algorithm for a matching security > strength.
The (pre-quantum) strengths of P-256 and AES-128 can not be directly compared because scaling is different (P-256 has quadric scaling and AES-128 has linear scaling). However, P-256 is clearly stronger of the two. Even worse would be trying to to match strengths of confidentiality and authentication. See RFC9420 for an example of this going very wrong. -Ilari _______________________________________________ jose mailing list -- [email protected] To unsubscribe send an email to [email protected]
