Skip to main content
Calcimator

RSA Key Strength Calculator

Calculate RSA key strength, equivalent symmetric key length, brute force time, and security margins.

About this calculator

This calculator converts an RSA key length into its estimated security strength using the equivalence table published in NIST Special Publication 800-57 Part 1 Revision 5, Table 2 (page 54), which maps RSA modulus sizes to an equivalent symmetric-key security level in bits: 1024-bit RSA is roughly equivalent to 80-bit security (now considered too weak), 2048- bit to 112-bit security (the current widely used minimum), 3072-bit to 128-bit security, 7680-bit to 192-bit security, and 15360-bit to 256-bit security. Those five points are the only ones NIST's table actually publishes -- it has no entry at 4096 bits, a size common in practice, so between published points this tool linearly interpolates rather than reporting an exact published figure, which is why a value like 4096-bit RSA shows an approximate rather than an authoritative security level.

RSA's security does not scale linearly with key length -- doubling the key length adds far less than double the security margin, which is why RSA keys need to be so much larger than symmetric keys (like AES) to reach the same security level; a 2048-bit RSA key and a 112-bit AES key are considered roughly equivalent in brute-force resistance. The brute-force time estimate assumes a fixed, arbitrary attacker compute budget (10^12 operations per second) applied to the security-bit exponent, which is a simplified illustration of how astronomically the effort scales with each additional security bit -- it is not a claim about any real attacker's actual capability, since real-world cryptanalysis also depends on algorithmic advances, not just raw brute-force speed.

Inputs

bits

Results

Security Level

112 bits

Equivalent Symmetric Key

112 bits

Brute Force Time

164,500,000,000,000 years

ECC Equivalent Key Length224 bits
Key Length (Modulus)2,048 bits

Figures current as of 2020. Source: NIST Special Publication 800-57 Part 1 Revision 5, "Recommendation for Key Management: Part 1 – General," Table 2 (p. 54): RSA modulus k=1024 -> <=80-bit, k=2048 -> 112-bit, k=3072 -> 128-bit, k=7680 -> 192-bit, k=15360 -> 256-bit estimated maximum security strength.

How to Use This Calculator
  1. Enter the RSA key size in bits (e.g. 1024, 2048, 3072, 4096, 7680, 15360).
  2. Review the equivalent symmetric security level in bits, interpolated from NIST SP 800-57's published table.
  3. Verify that 2048-bit keys provide about 112-bit security -- the current commonly used NIST minimum for new systems.
  4. Check the ECC Equivalent Key Length to compare against an elliptic-curve alternative.
  5. Plan migration to 3072+ bits for longer-lived security needs per NIST SP 800-131A recommendations.

How the result changes with Key Length

Key LengthSecurity LevelEquivalent Symmetric KeyBrute Force Time
1,02480 bits80 bits38,310 years
1,53696 bits96 bits2,511,000,000 years
3,072128 bits128 bits10,780,000,000,000,000,000 years
5,120156.4 bits156.4 bits3,939,000,000,000,000,000,000,000,000 years

What each input means

Key Length
RSA key length in bits

What each result means

Key Length (Modulus)
The RSA modulus length you entered, restated in bits -- not a brute-force search-space size. See Brute Force Time above for the actual attack-effort estimate, which uses the interpolated security level, not this raw key length.

How this is calculated

Formula

Security level per NIST SP 800-57 lookup (e.g., RSA-2048 ≈ 112-bit security)

Worked example, using the default values

  1. Identify Input Parameters
    Key Length = 2048 = 1 input(s) provided
  2. Calculate Security Level
    Security Level
    112 = 112
  3. Calculate Equivalent Symmetric Key
    Equivalent Symmetric Key
    112 = 112
  4. Calculate Brute Force Time
    Brute Force Time = Number.isFinite(bruteForceTimeYears)
    164500000000000 = 164500000000000
  5. Calculate ECC Equivalent Key Length
    ECC Equivalent Key Length
    224 = 224
  6. Calculate Key Length (Modulus)
    Key Length (Modulus)
    2048 = 2048

Figures and sources

Engine last updated . Checked against 1 independently-derived test — how we verify calculators. Built by Paul Gunder, a software engineer, not a licensed financial, medical, or legal professional.

Frequently Asked Questions

Why isn't 4096-bit RSA exactly twice as secure as 2048-bit RSA?

RSA's security strength does not scale linearly with key length because breaking RSA means factoring its modulus, and the best known factoring algorithms (the general number field sieve) get relatively more efficient, not less, as the modulus grows -- so each additional bit of key length buys a diminishing security return. That is why NIST's published equivalence table shows roughly 112-bit security at 2048 bits but only about 128-bit security at 3072 bits, not 224-bit security from simply doubling the length.

Why do RSA keys need to be so much larger than AES keys for similar security?

RSA and AES rely on different mathematical hardness assumptions -- RSA's security rests on the difficulty of factoring large numbers, which yields to subexponential-time attacks, while AES's security rests on brute-forcing a keyspace with no known shortcut, a fully exponential problem. Because factoring is comparatively easier to attack per bit than brute-forcing a symmetric key, an RSA key must be many times longer than a symmetric key to reach the same practical security margin -- 2048-bit RSA is roughly equivalent to a 112-bit symmetric key.

Is 2048-bit RSA still considered safe?

As of NIST's published guidance, 2048-bit RSA (about 112-bit security) is the commonly used minimum for new systems today, though NIST has recommended planning a migration to 3072 bits or larger for longer-lived security needs. Cryptographic recommendations evolve as computing power and factoring algorithms improve, so treat any specific "safe until" date as guidance current at time of publication rather than a permanent guarantee.

What does the ECC equivalent key length tell me?

It shows the elliptic-curve key length that reaches the same estimated security level as your entered RSA key length, using NIST's published ECC key-size equivalences. Because elliptic-curve cryptography does not suffer from the same subexponential factoring attacks RSA does, ECC keys can be dramatically shorter than RSA keys for equivalent security -- a 256-bit ECC key is roughly equivalent to a 3072-bit RSA key.

Should I take the brute-force time estimate literally?

No -- it is an illustration of how quickly the effort required grows with each additional bit of security, computed against an arbitrary fixed attacker compute budget, not a prediction of how long any specific real-world attacker or organization would actually take. Real cryptanalysis of RSA targets the factoring problem directly using algorithms far more efficient than brute force, and continues to improve over time, so this number should be read as a rough scale illustration rather than a literal timeline.

The questions that sit next to this one — chosen by subject, including calculators filed under a different category.

More in Technology & Computing.