Information Technology • eSafety and Security

Encryption Lab

One key locks and unlocks

Toy cipher
Cipher
Ciphertext (what is sent)
Bob decrypts with the same key

Encryption Lab — Explanation

How to use it. Choose a topic in the title bar. In Symmetric, type a message and change the key; then step through the key-sharing problem. In Public key, Signatures and HTTPS, press Next to go one step at a time (or Play). Challenges tests all four.

Honest about the toys. The Caesar and XOR ciphers, the RSA keys made from two-digit primes, and the hash are toy examples of the idea, small enough to see every number. Any of them could be broken in seconds. Real systems use AES (symmetric, 128- or 256-bit keys), RSA or elliptic-curve keys of 2048 bits or more, and SHA-256 hashes, but the steps are the same.

Symmetric encryption

One secret key encrypts the plaintext into ciphertext, and the same key decrypts it. It is fast. Its weakness is the key distribution problem: the key must reach the receiver without anyone else seeing it.

Asymmetric (public-key) encryption

Each person has a key pair: a public key anyone may have, and a private key that never leaves its owner. A message encrypted with Bob's public key can only be decrypted with Bob's private key, so Alice can send Bob secrets without ever sharing a secret key. It is much slower than symmetric encryption.

Digital signatures

Alice hashes her message and encrypts the hash with her private key: that is the digital signature. Bob decrypts it with Alice's public key and compares it with his own hash of the message. If they match, the message came from Alice (authentication), hasn't been changed (integrity), and she can't deny sending it (non-repudiation). A signature doesn't hide the message.

Certificates and HTTPS

A digital certificate is issued by a certificate authority (CA): it contains the owner's name and public key, the dates it is valid, and the CA's digital signature. When a browser connects to an https:// site using TLS (the successor to SSL), the server sends its certificate; the browser checks it; the browser then sends a new symmetric session key, encrypted with the server's public key; and from then on everything is encrypted with that fast session key. This mix is hybrid encryption. (Newer TLS 1.3 agrees the session key with a Diffie–Hellman exchange rather than sending it encrypted, but the certificate check and the switch to a symmetric key are the same.)

Common exam mistakes: saying the sender encrypts with their own public key; saying the private key is sent to the receiver; saying a signature encrypts the message (it signs a hash of it); saying a certificate contains the private key; and saying HTTPS uses asymmetric encryption for all the data.

Objective: Cambridge International AS & A Level Information Technology (9626), data security and eSafety: symmetric and asymmetric encryption, public and private keys, digital signatures, digital certificates, and the protocols (SSL/TLS, HTTPS) that use them. Also supports IGCSE ICT (0417) encryption and secure websites.

Where this fits

  • AP: AP Computer Science Principles
  • AQA: AQA A Level Computer Science (7517)
  • Cambridge: Cambridge IGCSE Information and Communication Technology (0417); Cambridge IGCSE Computer Science (0478); Cambridge A Level Computer Science (9618); Cambridge AS Level Computer Science (9618); Cambridge A Level Information Technology (9626); Cambridge AS Level Information Technology (9626) Goes beyond Cambridge IGCSE Information and Communication Technology (0417): 0417 covers encryption's purpose, certificates and SSL; key pairs, signatures and ciphers go further. Goes beyond Cambridge IGCSE Computer Science (0478): Digital signatures and hashing go beyond 0478. Goes beyond Cambridge AS Level Computer Science (9618): Public keys, certificates and the HTTPS handshake are A Level (17.1); AS names encryption and signatures. Goes beyond Cambridge A Level Information Technology (9626): Digital signatures and hashing go beyond 9626 1.3. Goes beyond Cambridge AS Level Information Technology (9626): Digital signatures and hashing go beyond 9626 1.3.
  • IB: IB Computer Science HL; IB Computer Science SL
  • NCEA Level 2 Digital Technologies: 91898 Demonstrate understanding of a computer science concept; 91898 Demonstrate understanding of a computer science concept
  • Pearson Edexcel International: Edexcel International GCSE Computer Science (4CP0); Edexcel International GCSE ICT (4IT1); Edexcel International A Level Information Technology Goes beyond Edexcel International GCSE Computer Science (4CP0): 4CP0 has classic ciphers (Caesar); keys, public-key encryption, signatures and HTTPS go beyond it. Goes beyond Edexcel International GCSE ICT (4IT1): 4IT1 only names encryption as a protection; ciphers, public keys, signatures and HTTPS go further.
  • USDP: USDP Computer Science

Encryption Lab — Key Terms

Key concepts in English, with te reo Māori, Chinese (Simplified) and Korean.

EnglishTe reo Māori中文(简体)한국어What it means on this page
Encryptionno attested term加密 (jiāmì)암호화 (amhohwa)Scrambling data with a key so that it cannot be understood by anyone who does not have the key to decrypt it.
Plaintextno attested term明文 (míngwén)평문 (pyeongmun)The original, readable message before it is encrypted.
Ciphertextno attested term密文 (mìwén)암호문 (amhomun)The scrambled, unreadable form of a message after encryption.
Symmetric Encryptionno attested term对称加密 (duìchèn jiāmì)대칭 암호화 (daeching amhohwa)Encryption where the same secret key is used to encrypt and to decrypt, so both people must have it.
Asymmetric Encryptionno attested term非对称加密 (fēi duìchèn jiāmì)비대칭 암호화 (bidaeching amhohwa)Encryption with a key pair: data encrypted with the public key can only be decrypted with the matching private key.
Public Keyno attested term公钥 (gōngyào)공개 키 (gonggae ki)The key of a key pair that is shared openly: used to encrypt data for its owner, or to check its owner's digital signature.
Private Keyno attested term私钥 (sīyào)개인 키 (gaein ki)The key of a key pair that only its owner has: used to decrypt data sent to them, and to make digital signatures.
Digital Signatureno attested term数字签名 (shùzì qiānmíng)디지털 서명 (dijiteol seomyeong)A hash of a message encrypted with the sender's private key; checked with their public key, it shows who sent it and that it hasn't been changed.
Hashno attested term哈希值 (hāxīzhí)해시 (haesi)A short, fixed-length value worked out from data by a one-way algorithm; any change to the data changes the hash.
Digital Certificateno attested term数字证书 (shùzì zhèngshū)디지털 인증서 (dijiteol injeungseo)An electronic document that proves a website is who it says it is, so the browser can set up a secure connection. A certificate warning means something is wrong.
Certificate Authority (CA)no attested term证书颁发机构 (zhèngshū bānfā jīgòu)인증 기관 (injeung gigwan)A trusted organisation that checks who owns a public key and issues digital certificates signed with its own private key.
HTTPSno attested term超文本传输安全协议 (chāowénběn chuánshū ānquán xiéyì)보안 하이퍼텍스트 전송 프로토콜 (boan haipeotekseuteu jeonsong peurotokol)Hypertext Transfer Protocol Secure: web pages sent over an encrypted connection, shown by https:// and a padlock in the address bar.
Transport Layer Security (TLS)no attested term传输层安全协议 (chuánshūcéng ānquán xiéyì)전송 계층 보안 (jeonsong gyecheung boan)The protocol (successor to SSL) that authenticates a server with its certificate and encrypts the data sent between it and a browser.
Session Keyno attested term会话密钥 (huìhuà mìyào)세션 키 (sesyeon ki)A symmetric key made for one connection, shared securely using public-key encryption, then used to encrypt that session's data.

On the te reo Māori column. Terms marked as gaps have no attested equivalent in the sources checked — Karaitiana Taiuru's Dictionary of Māori Computer and Social Media Terms, Paekupu, the Reserve Bank's te reo financial glossary, NZQA and Te Aka. No coinage is printed as though it were established; where a class needs one, commission it from Te Taura Whiri i te Reo Māori and credit the translator. Te reo Māori is not italicised and takes no plural "s".