RSA is one of the most important algorithms in the history of
cryptography. Created by Ron Rivest, Adi Shamir, and Leonard Adleman in
1977, it became one of the first practical implementations of
public-key cryptography. RSA made it possible to encrypt data and
create digital signatures without two parties first having to exchange a
shared secret key. This idea became fundamental to secure communication
on the Internet.

But for many years, using RSA was not completely free.

The algorithm was covered in the United States by U.S. Patent
4,405,829
, owned by MIT and exclusively licensed to RSA Data Security.
Developers and companies that wanted to implement RSA in products
distributed in the United States generally needed a license. In the late
1990s, RSA's published licensing terms even specified a royalty of 2%
of the selling price
for products covered by the patent.

There were exceptions. RSA provided the RSAREF library for certain
non-commercial uses, and the U.S. patent did not generally restrict
implementations developed and used outside the United States. But the
patent still created a serious complication for open-source projects:
software could be legal to distribute internationally while its RSA
implementation could cause patent problems for users in the U.S.

That changed on September 6, 2000.

RSA Security announced that it would immediately stop enforcing the
patent against third parties creating their own implementations of RSA.
From that day, developers and companies could implement RSA and sell
products containing it in the United States without obtaining a patent
license from RSA Security
.

The timing was largely symbolic: the patent was already scheduled to
expire on September 20, 2000, just two weeks later. RSA Security's
own software, such as the BSAFE cryptographic toolkit, also remained
copyrighted and proprietary. What became unrestricted was the ability to
implement the algorithm itself.

RSA today

More than 25 years later, RSA is still deeply embedded in Internet
infrastructure, particularly in digital signatures, certificates,
authentication systems, and enterprise security
.

Its role has changed, however. Modern TLS 1.3 removed RSA-based key
exchange
, replacing it with mechanisms that provide forward secrecy.
RSA is still supported for authentication and digital signatures,
particularly through RSA-PSS. In July 2026, the IETF also formally
deprecated RSA key exchange in TLS 1.2.

RSA is therefore no longer the universal default it once was.
Elliptic-curve algorithms such as ECDSA have taken a large part of its
role because they provide comparable security with much smaller keys.
Nevertheless, RSA remains extremely widespread: an August 2026 scan of
several hundred of the world's busiest websites found RSA keys in about
62% of their TLS leaf certificates.

RSA's longer-term future is less certain. A sufficiently powerful
quantum computer running Shor's algorithm could break both RSA and
today's elliptic-curve cryptography, which is why the industry has
begun moving toward post-quantum algorithms standardized by NIST.

So September 6, 2000 was not the day RSA was invented or even the day it
became widely used. It was the moment when one of the foundational
technologies of Internet security stopped requiring permission from
its U.S. patent holder to implement
.

Sources

  • RSA Security’s official patent statement, preserved by the IETF
    the strongest source for the September 6, 2000 event itself. It
    explains that RSA Security would stop enforcing the patent against
    third-party implementations, that the patent was due to expire on
    September 20, 2000, and that RSA Security’s own software remained
    proprietary.
    RSA Security patent statement — IETF
  • The original RSA paper by Rivest, Shamir, and Adleman“A Method
    for Obtaining Digital Signatures and Public-Key Cryptosystems.”
    This
    is the primary source for explaining why RSA mattered: public-key
    encryption and digital signatures without first sharing a secret key.
    Original RSA paper — MIT
  • U.S. Patent 4,405,829 — “Cryptographic communications system and
    method”
    — the original RSA patent. It shows the inventors, MIT
    ownership, filing date, and patent grant date.
    RSA patent — Google Patents
  • RFC 2437 / PKCS #1, 1998 — a useful historical source for RSA
    licensing before the patent was released. It documents RSA Data
    Security’s licensing terms at the time, including a royalty rate of 2%
    of the selling price for covered products.
    RFC 2437 — PKCS #1
  • Archived RSA announcement from September 6, 2000 — a preserved
    copy of the original announcement stating that developers could freely
    create their own implementations of the RSA algorithm.
    Archived RSA announcement — GNU mailing list archive
  • RFC 8446 — TLS 1.3 — useful for describing RSA’s modern role. TLS
    1.3 removed RSA key exchange, while RSA signatures, especially
    RSA-PSS, remain supported.
    RFC 8446 — TLS 1.3
  • NIST Post-Quantum Cryptography project — a strong source for the
    long-term future of RSA and the transition toward post-quantum
    cryptography.
    NIST Post-Quantum Cryptography
  • The State of Signatures on the Web, August 2026 — the source for
    the modern usage figure. In its sample of major websites, around 61.6%
    of measured TLS leaf certificates used RSA.
    The State of Signatures on the Web
  • RFC 10015 — Deprecating Obsolete Key Exchange Methods in TLS 1.2 and
    DTLS 1.2
    — the source for the July 2026 IETF deprecation of RSA key
    exchange in (D)TLS 1.2.
    RFC 10015 — RFC Editor

See also Feb 2, 1952: Celebrating Ralph Merkle’s Pioneering Contributions to Cryptography and The 1993 U.S. Encryption Initiative: The Clipper Chip and Its Legacy.