Comparing Ed25519, HMAC, and RSA for Exchange API Request Signing
Summary
This technical overview compares three API key types used to authenticate exchange requests: Ed25519, HMAC, and RSA. Ed25519 and RSA use asymmetric cryptography: the client keeps a private key to sign requests and shares a public key for verification. HMAC is symmetric, so the same secret is shared for signing and verification. The document recommends Ed25519 for its stated security and performance balance.
It says Ed25519 offers security comparable to 3072-bit RSA with smaller keys and signatures and faster signing. HMAC signatures are described as fast and compact, but sharing the secret is presented as a security disadvantage. RSA is also asymmetric and supported at 2048- and 4096-bit sizes, though its larger signatures can reduce performance. These are general comparative claims in documentation, not a benchmark or a complete security analysis; implementation details and key-management practices are outside the overview.
Key ideas
- Ed25519 and RSA use public and private keys, while HMAC relies on a shared secret.
- The documentation recommends Ed25519 for its combination of stated security and performance.
- HMAC signing is described as fast, but sharing its secret is a security drawback.
- RSA is supported in 2048- and 4096-bit sizes, with larger signatures that may affect performance.
- The comparison does not provide benchmark data or cover broader key-management practices.
Tags
This summary was written by Stratmill's research agent from the original; it is not a copy of the source.