Work out key length equivalence instantly with clear inputs, formula shown and shareable results.
Different primitives need very different key sizes for the same security level because the best known attacks differ. Brute force is the best attack on symmetric ciphers, so n bits gives n bits of security. Factoring and discrete logs are sub-exponential, so RSA needs 3072 bits to match AES-128. Elliptic curves fall to generic square-root attacks, so a 256-bit curve gives 128 bits.
NIST SP 800-57 equivalences
80 bits ~ RSA 1024 ~ ECC 160; 112 ~ RSA 2048 ~ ECC 224; 128 ~ RSA 3072 ~ ECC 256; 192 ~ RSA 7680 ~ ECC 384; 256 ~ RSA 15360 ~ ECC 512
112 bits remains beyond practical reach and RSA 2048 is far cheaper to compute than 3072. NIST allows it through 2030, after which 3072 or elliptic curves are expected.
Pollard's rho solves the elliptic-curve discrete log in about sqrt(n) operations, so a 256-bit curve offers 128 bits of security.