VI · Cryptographic foundations

Discrete log

What it is

Given g and gˣ mod p, find x. Believed hard for primes ~2048-bit; very hard for elliptic curves at 256-bit.

Where it lives

Diffie-Hellman key exchange, ECDSA, Ed25519. The math behind TLS's key exchange.

The key insight

Elliptic curves give 128-bit security at 256-bit keys; classical DH needs ~3072-bit primes for the same strength.