Glossary

RSA

RSA is a public-key algorithm, named for Rivest, Shamir and Adleman, that encrypts data and signs messages using a modulus that is the product of two large primes. A 2048-bit RSA key gives about 112 bits of security and a 3072-bit key about 128 bits, according to NIST SP 800-57. The current standard text is PKCS #1 version 2.2, published as RFC 8017.

How it works

An RSA public key is two numbers: the modulus n and the public exponent e. The modulus is p times q for two secret primes of equal length. The private key is the exponent d, calculated so that d times e leaves remainder 1 modulo (p-1)(q-1). RFC 8017 requires e to be at least 3 and coprime to the Carmichael function of n, and in practice almost everyone uses e = 65537.

The core operation is modular exponentiation. Encrypting a number m gives c = m^e mod n, and decrypting gives m = c^d mod n. Signing is the reverse: you raise a digest to d, and anyone verifies it with e. Nobody can compute d from n and e without factoring n, and that is the hard problem RSA relies on.

The toy run below uses p = 61 and q = 53, so n = 3233 and the totient is 3120. It prints n, the totient, d, the ciphertext and the decrypted value. The OpenSSL commands after it show a real 2048-bit key and its signature size.

python3 -c "
p,q,e=61,53,17
n=p*q;phi=(p-1)*(q-1);d=pow(e,-1,phi)
m=65;c=pow(m,e,n)
print(n,phi,d,c,pow(c,d,n))"
openssl genpkey -algorithm RSA -pkeyopt rsa_keygen_bits:2048 -out rsa.pem
openssl pkey -in rsa.pem -text -noout | grep -E "Private-Key|publicExponent"
echo hi | openssl dgst -sha256 -sign rsa.pem | wc -c
3233 3120 2753 2790 65
Private-Key: (2048 bit, 2 primes)
publicExponent: 65537 (0x10001)
256

Never use raw textbook RSA like this. Real systems add padding: OAEP for encryption and PSS for signatures, both defined in RFC 8017.

What RSA key size should I use?

Use at least 2048 bits, and choose 3072 bits when the key must stay trusted for many years. NIST SP 800-57 maps 1024 bits to 80 bits of security, 2048 to 112, 3072 to 128, 7680 to 192 and 15360 to 256. FIPS 186-5 requires an even modulus length of at least 2048 bits for new signatures. The signature or ciphertext is always as long as the modulus: 256 bytes for 2048 bits, as the run above shows.

How much data can RSA encrypt?

RSA-OAEP with SHA-256 and a 2048-bit key encrypts at most 190 bytes. RFC 8017 limits the message to k minus 2 times the hash length minus 2, where k is the modulus length in bytes. Node.js accepts 190 bytes and rejects 191 with ERR_OSSL_RSA_DATA_TOO_LARGE_FOR_KEY_SIZE. For larger payloads, encrypt with AES and wrap only the AES key with RSA.

Common pitfalls

  • Using PKCS #1 v1.5 encryption: it is open to padding-oracle attacks of the Bleichenbacher type. RFC 8017 recommends OAEP for new applications.
  • Reusing one key pair for encryption and signing: a flaw in one scheme can expose the other. RFC 8017 advises a single scheme per key.
  • Keeping 1024-bit keys: they are rated at 80 bits and below the 2048-bit minimum in FIPS 186-5. Reissue them.
  • Encrypting bulk data directly: the size limit above makes it fail, and slow private-key operations make it expensive. Use hybrid encryption.
  • Assuming RSA survives quantum computers: a large quantum computer running Shor's algorithm factors n. Plan a migration for data that must stay secret for decades.

Related terms

  • ECC — the elliptic-curve alternative that gives similar strength with far shorter keys.
  • ECDSA — the elliptic-curve signature scheme often chosen over RSA signatures.
  • AES — the symmetric cipher that RSA normally wraps keys for.
  • TLS — uses RSA in certificates and, in older versions, for key exchange.
  • SSH key — RSA is one of the key types ssh accepts.
  • JWT — the RS256 signing algorithm uses RSA with SHA-256.

See also