How to use it. Choose a topic in the title bar. In Symmetric, type a message and change the key; then step through the key-sharing problem. In Public key, Signatures and HTTPS, press Next to go one step at a time (or Play). Challenges tests all four.
Honest about the toys. The Caesar and XOR ciphers, the RSA keys made from two-digit primes, and the hash are toy examples of the idea, small enough to see every number. Any of them could be broken in seconds. Real systems use AES (symmetric, 128- or 256-bit keys), RSA or elliptic-curve keys of 2048 bits or more, and SHA-256 hashes, but the steps are the same.
Symmetric encryption
One secret key encrypts the plaintext into ciphertext, and the same key decrypts it. It is fast. Its weakness is the key distribution problem: the key must reach the receiver without anyone else seeing it.
Asymmetric (public-key) encryption
Each person has a key pair: a public key anyone may have, and a private key that never leaves its owner. A message encrypted with Bob's public key can only be decrypted with Bob's private key, so Alice can send Bob secrets without ever sharing a secret key. It is much slower than symmetric encryption.
Digital signatures
Alice hashes her message and encrypts the hash with her private key: that is the digital signature. Bob decrypts it with Alice's public key and compares it with his own hash of the message. If they match, the message came from Alice (authentication), hasn't been changed (integrity), and she can't deny sending it (non-repudiation). A signature doesn't hide the message.
Certificates and HTTPS
A digital certificate is issued by a certificate authority (CA): it contains the owner's name and public key, the dates it is valid, and the CA's digital signature. When a browser connects to an https:// site using TLS (the successor to SSL), the server sends its certificate; the browser checks it; the browser then sends a new symmetric session key, encrypted with the server's public key; and from then on everything is encrypted with that fast session key. This mix is hybrid encryption. (Newer TLS 1.3 agrees the session key with a Diffie–Hellman exchange rather than sending it encrypted, but the certificate check and the switch to a symmetric key are the same.)
Common exam mistakes: saying the sender encrypts with their own public key; saying the private key is sent to the receiver; saying a signature encrypts the message (it signs a hash of it); saying a certificate contains the private key; and saying HTTPS uses asymmetric encryption for all the data.
Objective: Cambridge International AS & A Level Information Technology (9626), data security and eSafety: symmetric and asymmetric encryption, public and private keys, digital signatures, digital certificates, and the protocols (SSL/TLS, HTTPS) that use them. Also supports IGCSE ICT (0417) encryption and secure websites.
Where this fits
- AP: AP Computer Science Principles
- AQA: AQA A Level Computer Science (7517)
- Cambridge: Cambridge IGCSE Information and Communication Technology (0417); Cambridge IGCSE Computer Science (0478); Cambridge A Level Computer Science (9618); Cambridge AS Level Computer Science (9618); Cambridge A Level Information Technology (9626); Cambridge AS Level Information Technology (9626) Goes beyond Cambridge IGCSE Information and Communication Technology (0417): 0417 covers encryption's purpose, certificates and SSL; key pairs, signatures and ciphers go further.
Goes beyond Cambridge IGCSE Computer Science (0478): Digital signatures and hashing go beyond 0478.
Goes beyond Cambridge AS Level Computer Science (9618): Public keys, certificates and the HTTPS handshake are A Level (17.1); AS names encryption and signatures.
Goes beyond Cambridge A Level Information Technology (9626): Digital signatures and hashing go beyond 9626 1.3.
Goes beyond Cambridge AS Level Information Technology (9626): Digital signatures and hashing go beyond 9626 1.3.
- IB: IB Computer Science HL; IB Computer Science SL
- NCEA Level 2 Digital Technologies: 91898 Demonstrate understanding of a computer science concept; 91898 Demonstrate understanding of a computer science concept
- Pearson Edexcel International: Edexcel International GCSE Computer Science (4CP0); Edexcel International GCSE ICT (4IT1); Edexcel International A Level Information Technology Goes beyond Edexcel International GCSE Computer Science (4CP0): 4CP0 has classic ciphers (Caesar); keys, public-key encryption, signatures and HTTPS go beyond it.
Goes beyond Edexcel International GCSE ICT (4IT1): 4IT1 only names encryption as a protection; ciphers, public keys, signatures and HTTPS go further.
- USDP: USDP Computer Science