Search

How Public Key Cryptography Works

The short answer

Quick answer: Public key cryptography uses a pair of mathematically linked keys. The public key can be shared with anyone. The private key is kept secret. What one key does, only the other can undo. That gives two abilities. Encryption: anyone can lock a message with your public key, and only your private key can unlock it. Signatures: you can sign data with your private key, and anyone can check the signature with your public key, proving it came from you and has not been changed. Together these let strangers communicate securely over an open network without ever having met to exchange a secret.

The problem it solved

Traditional (symmetric) encryption uses one key to lock and unlock. It is fast and secure, with one awkward requirement: both sides need the same secret key. How do you get it to the other person? If you send it over the network, an eavesdropper copies it. If you could send it securely, you would not need encryption in the first place.

For most of history, keys travelled by courier. That does not work for a web browser connecting to a shop it has never visited.

In 1976, Whitfield Diffie and Martin Hellman published a way round this, and in 1977 Ron Rivest, Adi Shamir and Leonard Adleman followed with RSA. (British intelligence researchers had found the same ideas a few years earlier, in secret.) The breakthrough was to split the key in two.

Two keys

Think of a letterbox. Anyone can post a letter through the slot (the public key). Only the person with the key to the box can take letters out (the private key).

Or think of a padlock you hand out freely. Anyone can snap it shut on a box. Only you can open it.

Mathematically, the two keys are related through a one-way function: a calculation that is easy in one direction and impractical to reverse without a secret.

SystemEasy directionHard direction
RSAMultiply two large prime numbersFind the primes from their product
Diffie-HellmanRaise a number to a power, modulo a primeRecover the exponent
Elliptic curve cryptographyMultiply a point on a curve by a numberRecover the number

The public key can be derived from the private one, but not the reverse, at least not with any known method on today's computers.

Use 1: Encryption

  1. Bob publishes his public key.
  2. Alice encrypts a message with it.
  3. Only Bob's private key can decrypt it.

Even Alice cannot decrypt what she just encrypted. An eavesdropper who sees the message and has Bob's public key learns nothing.

Use 2: Digital signatures

Run it the other way.

  1. Alice computes a hash (a short fingerprint) of her message.
  2. She transforms that hash using her private key. The result is the signature.
  3. Anyone with her public key can verify that the signature matches the message.

A valid signature proves two things:

  • Authenticity: it was made by the holder of the private key.
  • Integrity: the message has not been altered, since any change alters the hash.

It also provides non-repudiation: the signer cannot plausibly deny having signed. Note that signing does not hide the message; it only vouches for it.

Signatures are everywhere: software updates, app stores, HTTPS certificates, signed emails, Git commits, cryptocurrency transactions.

Use 3: Agreeing on a shared secret

Public key operations are slow, hundreds to thousands of times slower than symmetric encryption, and they can only handle small amounts of data. So real systems use them to establish a symmetric key, then switch to fast symmetric encryption for the bulk of the data. This is hybrid encryption.

The usual method is a Diffie-Hellman key exchange. The well-known paint analogy:

  1. Alice and Bob agree publicly on a common colour, say yellow.
  2. Each picks a secret colour and mixes it with the yellow.
  3. They exchange the mixtures in the open.
  4. Each adds their own secret colour to the mixture they received.

Both end up with the same final colour: yellow plus both secrets. An eavesdropper saw only the two intermediate mixtures and cannot un-mix them to get there.

With numbers in place of paint, both sides compute the same secret without it ever crossing the network.

When fresh, temporary keys are used for each session, the result is forward secrecy: even if someone later steals a server's long-term private key, recordings of earlier sessions stay unreadable.

The remaining problem: whose key is it?

Public key cryptography guarantees that only the holder of the matching private key can read your message. It does not tell you who that holder is. If an attacker substitutes their own public key for the real one, you will encrypt neatly for the attacker. This is a man-in-the-middle attack.

Three ways of tying keys to identities:

  • Certificates. A trusted certificate authority signs a statement saying "this public key belongs to example.com". Your browser trusts a built-in list of authorities. This is how the web works; see how HTTPS works.
  • Trust on first use. SSH shows you a server's key fingerprint the first time and warns you if it ever changes.
  • Direct verification. Messaging apps let two people compare a safety code or scan a QR code. See how WhatsApp delivers messages.

The algorithms in use

AlgorithmUsed forNotes
RSAEncryption and signaturesThe classic; needs large keys (2,048 bits or more)
ECDH (elliptic curve Diffie-Hellman), such as X25519Key exchangeSmall keys, fast; the modern default
ECDSA, Ed25519SignaturesSmall, fast signatures
ML-KEM, ML-DSAKey exchange and signaturesNew post-quantum standards

Elliptic curve keys give the same strength as RSA with far fewer bits: roughly 256 bits against about 3,000.

Where you use it every day

  • HTTPS. Every secure website. The Cloudflare explainer describes its role in TLS.
  • SSH. Logging in to servers with a key pair in place of a password.
  • End-to-end encrypted messaging.
  • Software updates and app signing.
  • Passkeys. Your device holds a private key, and websites store only the public one. See how two-factor authentication works.
  • Email signing with DKIM. See how email works.
  • Signed tokens such as JWTs. See JWT vs sessions.

The quantum threat

The hard problems behind RSA and elliptic curves could be solved efficiently by a sufficiently large quantum computer running Shor's algorithm. No such machine exists today, and it is uncertain when one will.

But there is a reason to act now: an adversary can record encrypted traffic today and decrypt it later, once the technology arrives. So the industry is already migrating to post-quantum cryptography: new algorithms, based on different mathematical problems, that are believed to resist quantum attack. Standards bodies finalised the first of these in 2024, and browsers and major services have begun using them alongside existing algorithms. See post-quantum cryptography.

Symmetric encryption and hash functions are much less affected; longer keys are enough.

Looking after private keys

All of this depends on the private key staying private.

  • Generate keys with a secure random source.
  • Protect them with a passphrase, or store them in hardware: a security key, a phone's secure element, or a hardware security module.
  • Never share or email a private key, and never commit one to a code repository.
  • Rotate keys, and have a way to revoke them if they leak.
  • Use established libraries. See why you should never roll your own crypto.

Frequently asked questions

What is the difference between a public key and a private key?

The public key is shared openly and is used to encrypt messages to you or verify your signatures. The private key is kept secret and is used to decrypt those messages or create signatures.

What is the difference between symmetric and asymmetric encryption?

Symmetric encryption uses one shared key for both locking and unlocking. Asymmetric (public key) encryption uses a pair of keys, one public and one private.

Can a private key be worked out from a public key?

Not with any known practical method on current computers, which is what makes the system secure.

Is RSA still safe?

With sufficiently large keys and correct usage, yes, for now. New systems generally prefer elliptic curve algorithms, and are beginning to add post-quantum ones.

Conclusion

Public key cryptography replaced the impossible task of sharing a secret in advance with a simple one: publish half a key pair. From that come encryption for strangers, signatures anyone can check, and key agreement in the open. Almost every secure interaction on the internet starts with it.

Related articles

Sources and further reading

Usama Muneer

Usama Muneer

Coder, Blogger, Tech Speaker & Web Technologies Enthusiast. Passionate about working on open-source Programming languages & Tools while utilizing my Product Development skills.

Your experience on this site will be improved by allowing cookies Cookie Policy