Cryptographic Curves Used by the Tor Network

The Tor network relies heavily on modern elliptic-curve cryptography to ensure privacy, forward secrecy, and high performance across its distributed routing protocol. Primarily, Tor utilizes Daniel J. Bernstein’s Curve25519 family of curves—specifically Curve25519 for Diffie-Hellman key exchanges and its Twisted Edwards equivalent, Ed25519, for digital signatures and identity verification. This article breaks down how and where these cryptographic curves are implemented within the Tor ecosystem.

Curve25519 and the ntor Circuit Handshake

The primary cryptographic curve used for building Tor circuits is Curve25519. When a Tor client creates a circuit through guard, middle, and exit relays, it performs a key exchange with each node using the ntor handshake protocol.

The ntor protocol uses Curve25519-based Elliptic-Curve Diffie-Hellman (ECDH). This mechanism replaced the legacy TAP (Tor Authentication Protocol) handshake, which relied on 1024-bit RSA and Diffie-Hellman parameters. Curve25519 provides approximately 128 bits of security, defends against side-channel timing attacks, and significantly reduces circuit creation latency and CPU overhead on relays.

Ed25519 for Relay Identities and Onion Services v3

While Curve25519 handles key agreement, Ed25519 (an Edwards-curve digital signature algorithm based on Curve25519) handles authentication and identity management:

For point-to-point connections between relays, Tor encapsulates traffic inside standard TLS connections. At this transport layer:

Why Tor Standardized on Curve25519

Tor explicitly chose Curve25519 and Ed25519 over standard NIST curves (such as P-256) for its internal protocol design. The decision was driven by Curve25519’s immune design against timing and side-channel attacks, its exceptional verification and key generation speed, and complete transparency in its curve parameter selection, avoiding doubts regarding arbitrary constants.