Encryption Strength Calculator
Estimate brute-force time from key length and attacker computing power. Covers symmetric (AES) and asymmetric (RSA) algorithms with quantum threat modeling.
About this calculator
A key's raw bit length is not the same thing as its real-world security strength, and this calculator's job is to bridge that gap into an actual estimated crack time. For a symmetric cipher like AES, the effective strength equals the key length directly, since brute force must search the full 2^n keyspace. For an asymmetric algorithm like RSA, effective strength is far lower than the key length because RSA is broken by factoring rather than by exhaustive key search — the calculator's lower key sizes follow NIST SP 800-57 Part 1 Rev. 5's published Table 2 security-strength equivalences directly (RSA-2048 = 112 bits, RSA-3072 = 128 bits); RSA-4096's 152-bit figure extends that same table's methodology to a key size NIST's table doesn't tabulate explicitly, using the widely cited general-number-field-sieve-based estimate.
A quantum-threat toggle applies the two well-known quantum attacks: Grover's algorithm, which provides a quadratic speedup against symmetric ciphers and is modeled here as simply halving the effective bit strength, and Shor's algorithm, which factors RSA's underlying math efficiently and is modeled as breaking it completely (effective strength drops to zero). From the resulting effective bit count, the calculator computes the average number of brute-force attempts needed (half the keyspace, 2^(bits−1)) and divides by your specified attacker speed — expressed as a log10 of keys tested per second, so the whole crack-time calculation is done in log space to avoid numeric overflow on truly enormous numbers — then converts the result into a human-readable duration, scaling all the way up to multiples of the age of the universe where relevant. It also flags whether the effective strength clears 128 bits, the security strength NIST SP 800-57's Table 4 requires for applying new cryptographic protection from 2031 onward (112-bit strength, like RSA-2048, remains merely "acceptable" only through 2030) — so a 128-bit-or-higher key clears NIST's floor under either time frame. Keep in mind the RSA-4096 figure specifically is an extension of NIST's published methodology rather than a value NIST's own table lists outright, and real attacker capabilities (especially nation-state or future quantum hardware) are inherently uncertain estimates, not measured facts.
Inputs
Results
Effective key strength (bits)
256
Security rating (0-4)
4
How to Use This Calculator
- Enter key length (bits) -- AES-128, AES-256, RSA-2048, RSA-4096, EC-256, or EC-384.
- Set attacker speed in log10 keys/sec -- GPU farm ~15, nation-state ~18.
- Select algorithm type (symmetric or asymmetric) and toggle quantum threat.
- Review effective security bits, estimated crack time (log10 seconds), security rating, and NIST 2030 compliance.
- Migrate RSA-2048 to RSA-4096 or EC-256 -- NIST recommends minimum 128 bits of security through 2030.
How the result changes with Key length (bits)
| Key length (bits) | Effective key strength (bits) | Security rating (0-4) |
|---|---|---|
| 128 | 128 | 3 |
| 192 | 192 | 3 |
| 384 | 384 | 4 |
| 640 | 640 | 4 |
What each input means
- Key length (bits)
- Cryptographic key size. AES: 128/192/256. RSA: 1024/2048/3072/4096.
- Attacker speed (log10 keys/sec)
- Log10 of keys tested per second. 9 = single GPU, 12 = GPU cluster, 15 = nation-state, 20 = theoretical quantum.
- Algorithm type (0-1)
- 0 = Symmetric (AES, ChaCha20). 1 = Asymmetric (RSA, DSA) — effective strength is much lower than key length.
- Quantum threat (0-1)
- 0 = Classical computing only. 1 = Quantum (Grover halves symmetric strength; Shor breaks RSA entirely).
What each result means
- Effective key strength (bits)
- Effective symmetric-equivalent key strength after algorithm and quantum adjustments.
- Log10 crack time (seconds)
- Logarithm (base 10) of average brute-force time in seconds. >17 ≈ beyond human lifetime.
- Security rating (0-4)
- 0 = Broken, 1 = Weak (<80 bits), 2 = Acceptable (80-127), 3 = Strong (128-255), 4 = Overkill (256+).
- Meets NIST 2030 standard
- 1 = Yes (≥128 effective bits), 0 = No. NIST requires 128-bit minimum security strength through 2030+.
How this is calculated
Worked example, using the default values
- Identify Input Parameters4 parametersKey length (bits) = 256, Attacker speed (log10 keys/sec) = 12, Algorithm type (0-1) = 0, Quantum threat (0-1) = 0 = 4 input(s) provided
- Calculate Effective key strengthEffective key strength256 = 256
- Calculate Security ratingSecurity rating4 = 4
- Calculate Log10 crack timeLog10 crack time = log10AvgAttempts - keysPerSecondLog1064.76 = 64.76
- Calculate Meets NIST 2030 standard1 = 1
Figures and sources
- Comparable security strengths of RSA and symmetric-key algorithms; 128-bit minimum security strength from 2031 onward (2020) — NIST Special Publication 800-57 Part 1 Revision 5, "Recommendation for Key Management: Part 1 – General," Table 2 (RSA modulus k=2048 -> 112-bit, k=3072 -> 128-bit estimated maximum security strength) and Table 4 (security strength time frames: 112-bit acceptable through 2030, 128-bit required for applying protection from 2031 onward)
Engine last updated . Checked against 3 independently-derived tests — how we verify calculators. Built by Paul Gunder, a software engineer, not a licensed financial, medical, or legal professional.
Frequently Asked Questions
Why is RSA's effective bit strength so much lower than its actual key length?
RSA's security doesn't depend on brute-forcing a keyspace the way symmetric ciphers do — it depends on how hard it is to factor a large number, and factoring is a much easier problem than exhaustive search for the same number of bits. The calculator's RSA-2048 (112 bits) and RSA-3072 (128 bits) values come directly from the security-strength equivalence table in NIST SP 800-57 Part 1 Rev. 5; RSA-4096 (152 bits) extrapolates that same NIST methodology to a key size the table doesn't list outright. That's why a 2048-bit RSA key shows far less effective strength than a 2048-bit symmetric key would.
What's the practical difference between Grover's and Shor's algorithm in this tool?
These model two distinct quantum threats depending on the algorithm type you select. Against a symmetric cipher, Grover's algorithm gives only a quadratic speedup, modeled here as simply halving the effective bit strength, still leaving meaningful security at large key sizes. Against RSA, Shor's algorithm can factor the underlying math efficiently, so effective strength is modeled as dropping straight to zero — quantum computing is an existential threat to RSA in a way it isn't to AES.
How does the attacker-speed input change the crack-time estimate?
You enter attacker speed as a log10 of keys tested per second (12 for a GPU cluster, 15 for a nation-state, for example), and the calculator subtracts that value from the log10 of the average number of brute-force attempts needed. Because the whole calculation is done in log space, doubling your assumed attacker speed doesn't just double the crack-time estimate — every whole step you raise the input by (say from 12 to 15) means the attacker is 1,000 times faster.
Why does the security rating only go up to Overkill instead of a numeric score?
The 0-4 rating (Broken, Weak, Acceptable, Strong, Overkill) is a simplified bucket built directly from effective bit-strength thresholds — 0, under 80, under 128, under 256, and 256 or more — rather than from crack time directly, mirroring how standards bodies communicate cryptographic strength in tiers rather than raw numbers. It gives a quick read on whether a key size clears widely accepted minimums, alongside the more precise Meets NIST 2030 flag that checks the 128-bit floor specifically.
Related Calculators
The questions that sit next to this one — chosen by subject, including calculators filed under a different category.
Encryption Strength Calculator
Complete encryption strength analysis. Key strength, hash functions, cipher modes, post-quantum cryptography, and random number generation.
Cryptography & SecurityRSA Key Strength Calculator
Calculate RSA key strength, equivalent symmetric key length, brute force time, and security margins.
Cryptography & SecurityEncryption Key Space Calculator
Calculate encryption key space size, brute force time, and security level for cryptographic algorithms.
Cryptography & SecurityElliptic Curve Cryptography Calculator
Calculate ECC key strength, equivalent RSA key length, security level, and cryptographic parameters.
Cryptography & SecurityBrute Force Attack Time Calculator
Calculate brute force attack time, cost, energy consumption, and feasibility for cryptographic systems.
More in Technology & Computing.