← Blog

Private Key and Public Key

Marco Montorsi

Private Key and Public Key

The Problem of Not Being Understood

Before introducing the concepts of using two keys for computer security, it is appropriate to review what we mean by symmetric encryption with a single key to understand the differences.

The need to communicate in secret has existed since the time of the invention of the Caesar Cipher. The basic concept is to encrypt information with an algorithm and a secret key, the encrypted content of which must be so complex to decipher that it is impossible for those who do not know the key to decrypt it.

In the field of computer science, this methodology is called Symmetric Cryptography, as communication occurs through encryption with a secret key known only to the two communicating parties.

It is a method of encryption still widely used because with a good algorithm and a sufficiently long key, even today, attempts of Brute Force Attack are futile as the estimated decryption times far exceed millennia.

However, this method, while considered very secure, is weak in the simplest yet most fundamental point: the exchange of the secret key.

The Asymmetric Solution

In 1975, this problem was solved thanks to Whitfield Diffie and Martin Hellman with the invention of Asymmetric Cryptography based on two keys, a private and a public key. This method is truly extraordinary; the only way to decrypt it is by using the respective key, allowing secure communication without any key exchange.

Let's understand the dynamics better.

The public key is called so because it is available to everyone, while the private key must be kept in a secure, very secure place; a post-it on your computer won't do. This allows anyone who wants to communicate with us securely to do so using our public key since the only way to decrypt the encrypted message is by using the private key.

But not only that, this methodology allows us to validate the source of the message because if you receive a message encrypted with a private key, the only way to decipher it is by using the public key of the sender, so you will always be able to tell whether a message comes from an entity or not.

Finally, it can be used in combination to ensure authenticity and security. The sender encrypts the message first with their own private key and then encrypts it again with the public key of the recipient. Consequently, the recipient decrypts the message first with their own private key and then with the public key of the sender; this ensures that the message is sent securely and that the source is correct.

The use of symmetric and asymmetric encryption should not be mutually exclusive; in fact, it often happens that the combination of both methods is used. Asymmetric encryption is often used to share a secret key and then continue communication in a symmetric manner because asymmetric encryption requires more time for message encryption.

Conclusions

Take a moment to admire this invention; it is truly extraordinary. However, this article may raise many questions. We have not discussed the various encryption algorithms, the mathematical reasons for how these two keys work, or the various real-world use cases.

The purpose of this article is to explain in a simple way the difference between the two encryption methods because it is important to understand their differences and various advantages/disadvantages. I will try to delve deeper and answer any questions that may arise from these few lines in my upcoming articles.

← All articles