The performance comparison of ECDSA vs RSA is somewhat unfair. In ECDSA, signing is the cheapest operation, whereas in RSA it is the most expensive. If the timings chosen were signature verification time, RSA would be much faster. See:
Doing 2048 bit private rsa's for 10s: 1266 2048 bit private RSA's in 9.98s
Doing 256 bit sign ecdsa's for 10s: 22544 256 bit ECDSA signs in 9.97s
Doing 2048 bit public rsa's for 10s: 42332 2048 bit public RSA's in 9.98s
Doing 256 bit verify ecdsa's for 10s: 4751 256 bit ECDSA verify in 9.92s
A fairer comparison would probably pitch DH-2048 against ECDH-256, which is more apples-to-apples.
there is also a huge difference between newer and older versions of openssl.
# default openssl install (osx mavericks)
Doing 224 bit sign ecdsa's for 10s: 39077 224 bit ECDSA signs in 9.98s
Doing 224 bit verify ecdsa's for 10s: 8285 224 bit ECDSA verify in 9.98s
OpenSSL 0.9.8y 5 Feb 2013
vs
# homebrew openssl install
Doing 224 bit sign ecdsa's for 10s: 61047 224 bit ECDSA signs in 9.99s
Doing 224 bit verify ecdsa's for 10s: 15609 224 bit ECDSA verify in 9.84s
OpenSSL 1.0.1e 11 Feb 2013
Comments
The performance comparison of ECDSA vs RSA is somewhat unfair. In ECDSA, signing is the cheapest operation, whereas in RSA it is the most expensive. If the timings chosen were signature verification time, RSA would be much faster. See:
A fairer comparison would probably pitch DH-2048 against ECDH-256, which is more apples-to-apples.I don't believe 2048bit rsa and 256bit ecdsa are of equivalent security though[1]. What do things look like with 3072bit rsa?
[1]: http://wiki.openssl.org/index.php?title=Elliptic_Curve_Crypt...
OpenSSL's 'speed' utility doesn't seem to have RSA-3072 on the list, but I suppose I can downgrade to ECDSA-224 instead:
there is also a huge difference between newer and older versions of openssl.
vs Both on same mac laptop.