Symmetric Encryption
- In Turkish
- Simetrik Şifreleme
- Pronunciation
- sih-MET-rik in-KRIP-shun
In short
Symmetric encryption uses the same secret key to encrypt and decrypt data; it is fast, so it protects most stored and transmitted data, usually with AES.
What is symmetric encryption?
With symmetric encryption, whoever holds the key can turn plaintext into ciphertext and back. The dominant algorithm is AES, chosen as a US standard in 2001 and supported directly by modern processors, with keys of 128, 192 or 256 bits. ChaCha20 is a widely used alternative that is fast on devices without AES hardware support.
Modern systems use authenticated modes, such as AES-GCM or ChaCha20-Poly1305, which encrypt the data and also add a tag that detects any tampering. Each message needs a unique nonce, a number used once; reusing a nonce with the same key can break the encryption entirely. Using a well-reviewed library rather than combining primitives by hand avoids such mistakes.
The hard part is sharing the key. Both sides need it, and anyone who intercepts it can read everything. That is why protocols such as TLS start with public-key cryptography to agree on a fresh symmetric key, then switch to symmetric encryption for the actual data, which is far faster. Disk encryption, encrypted databases and password managers all rely on symmetric keys protected by a password or a key management service.
A common misconception is that symmetric encryption is weaker than public-key encryption. A 128-bit AES key is considered secure, while public-key algorithms need far longer keys for similar strength. The two are used together: public keys solve key exchange, symmetric keys protect the data.
Key takeaways
- Symmetric encryption uses one shared key to encrypt and decrypt.
- AES is the standard algorithm; ChaCha20 is a common alternative.
- Authenticated modes such as AES-GCM also detect tampering.
- Nonces must never be reused with the same key.
- TLS agrees on a symmetric key with public-key cryptography, then uses it.
Example
import os
from cryptography.hazmat.primitives.ciphers.aead import AESGCM
key = AESGCM.generate_key(bit_length=256) # keep this secret, e.g. in a key manager
aes = AESGCM(key)
nonce = os.urandom(12) # unique for every message
ciphertext = aes.encrypt(nonce, b"card ending 4242", b"order-1001")
# Decrypting with the same key; any change to the data raises InvalidTag
plaintext = aes.decrypt(nonce, ciphertext, b"order-1001")
print(plaintext)Readers ask
What is the difference between symmetric and asymmetric encryption?
Symmetric encryption uses one shared key for both encryption and decryption and is very fast. Asymmetric encryption uses a public key to encrypt and a private key to decrypt, which solves key sharing but is much slower.
Is AES secure?
Yes. AES with 128-bit or 256-bit keys, used in an authenticated mode such as GCM with unique nonces, is considered secure and is used by governments, banks and every major browser.
Often compared
See also
- EncryptionSecurity, p. 12Encryption is the process of scrambling data with a key so that only someone holding the correct key can turn it back into its original, readable form.
- Public-Key CryptographySecurity, p. 30Public-key cryptography is a method that uses a pair of linked keys, a public key anyone can see and a private key kept secret, to encrypt and sign data.
- TLSSecurity, p. 45TLS is the cryptographic protocol that encrypts data sent over a network and verifies the server's identity, securing HTTPS, email, and many other connections.
- HashingSecurity, p. 14Hashing is the process of turning any input into a fixed-length value with a one-way function, used to verify data integrity and store passwords safely.
- Secrets ManagementSecurity, p. 37Secrets management is the practice of securely storing, distributing, rotating, and auditing sensitive credentials such as passwords, API keys, and tokens.
- End-to-End EncryptionSecurity, p. 13End-to-end encryption (E2EE) encrypts messages on the sender's device so only the intended recipients can decrypt them, not even the service carrying them.
Spotted a mistake or something missing on this page?Suggest an edit