Public-Key Cryptography
- In Turkish
- Açık Anahtarlı Kriptografi
In short
Public-key cryptography is a method that uses a pair of linked keys, a public key anyone can see and a private key kept secret, to encrypt and sign data.
What is public-key cryptography?
Public-key cryptography, also called asymmetric cryptography, uses two mathematically linked keys instead of one shared secret. The public key can be given to anyone, while the private key must be kept secret by its owner. Data encrypted with the public key can only be decrypted with the matching private key, and a digital signature created with the private key can be verified by anyone who has the public key.
Its security rests on math problems that are easy to compute in one direction but practically impossible to reverse, such as factoring the product of two huge prime numbers, used by RSA, or problems on elliptic curves, used by ECDSA, Ed25519, and ECDH. Because asymmetric operations are slow, real systems combine them with symmetric encryption: in a TLS handshake, the two sides use public-key methods to verify the server's identity and agree on a fresh shared key, then encrypt the rest of the conversation with fast symmetric encryption such as AES.
A classic analogy is a mailbox with a slot: anyone can drop a letter through the slot, which is the public key, but only the owner holds the key that opens the box, which is the private key. Public-key cryptography is behind HTTPS certificates, SSH logins, signed software updates, encrypted email, passkeys, and JWTs signed with algorithms such as RS256 or ES256.
It is often contrasted with symmetric encryption, where the same secret key both encrypts and decrypts, which is fast but requires both sides to share that key safely in advance. Public-key cryptography solves the key-sharing problem, but on its own it can't prove who a public key belongs to, which is why certificates signed by trusted certificate authorities link public keys to domain names and organizations. Because future large-scale quantum computers could break RSA and elliptic-curve methods, post-quantum algorithms such as ML-KEM and ML-DSA, standardized by NIST in 2024, are already being deployed.
At a glance
Key takeaways
- Each party has a key pair: a public key to share and a private key to keep secret.
- Data encrypted with a public key can only be decrypted with the matching private key.
- Signatures made with a private key can be verified by anyone with the public key.
- Protocols like TLS combine it with fast symmetric encryption.
- Certificates link public keys to real identities such as domain names.
Example
import { generateKeyPairSync, sign, verify } from "node:crypto";
// Create a key pair: share the public key, keep the private key secret
const { publicKey, privateKey } = generateKeyPairSync("ed25519");
const message = Buffer.from("Transfer $100 to Ada");
// Sign with the private key...
const signature = sign(null, message, privateKey);
// ...and anyone with the public key can check the signature
console.log(verify(null, message, publicKey, signature)); // true
const tampered = Buffer.from("Transfer $900 to Eve");
console.log(verify(null, tampered, publicKey, signature)); // falseReaders ask
What is the difference between symmetric and asymmetric encryption?
Symmetric encryption uses one shared secret key for both encrypting and decrypting, and it is fast. Asymmetric encryption uses a public and private key pair, so no secret has to be shared in advance, but it is slower, which is why protocols like TLS use both.
Can a public key decrypt data?
It cannot decrypt data that was encrypted with that same public key; only the matching private key can. A public key is used to verify signatures made with the private key, which is sometimes loosely described as decrypting, but it is a separate operation.
What happens if my private key is leaked?
Anyone with the private key can decrypt messages meant for you and create signatures in your name. Revoke the key, for example by revoking its certificate, generate a new key pair, and replace the old public key everywhere it was used.
Often compared
See also
- EncryptionSecurity, p. 12Encryption is the process of scrambling data with a key so that only someone holding the correct key can turn it back into its original, readable form.
- TLSSecurity, p. 45TLS is the cryptographic protocol that encrypts data sent over a network and verifies the server's identity, securing HTTPS, email, and many other connections.
- HTTPSSecurity, p. 17HTTPS is the secure version of HTTP that encrypts traffic between a browser and a website with TLS, protecting data from eavesdropping and tampering.
- HashingSecurity, p. 14Hashing is the process of turning any input into a fixed-length value with a one-way function, used to verify data integrity and store passwords safely.
- JWTSecurity, p. 19A JWT is a compact, signed token that carries claims like a user ID and expiry time, letting a server verify requests without looking up a session.
- AuthenticationSecurity, p. 2Authentication is the process of verifying that a user, device, or service really is who it claims to be, for example by checking a password or passkey.
- Symmetric EncryptionSecurity, p. 44Symmetric encryption uses the same secret key to encrypt and decrypt data; it is fast, so it protects most stored and transmitted data, usually with AES.
Sources
Spotted a mistake or something missing on this page?Suggest an edit