What is public key encryption?
Public key encryption uses two linked keys: one you share and one you keep. How the pair works, and where your business already relies on it.
Public key encryption uses two related keys where ordinary encryption uses one. The public key can be given to anyone. The private key is kept secret by its owner. One key encrypts or signs, and the other decrypts or checks.
The problem it solves
Ordinary encryption uses the same secret key to lock and unlock. That works until you need to exchange data with someone you have never dealt with, because before you can send anything safely you have to get the key to them safely. With a key pair there is no secret to deliver. NIST describes the result as two parties being able to communicate securely without sharing a secret key beforehand.
How the pair works
Think of the public key as an open padlock that you hand out freely. Anyone can put a message in a box and snap your padlock shut. Only you hold the key that opens it. The two keys are mathematically linked, but working out the private key from the public one is not something today’s computers can do in any useful time.
The pair also works the other way round. The owner uses the private key to sign something, and anyone with the public key can check that the signature is genuine and that the content has not been changed since. That is a digital signature.
Where it is used
In practice the two kinds of encryption work together. When a secure connection starts, a public key method is used to establish a fresh shared key between the two devices, and that shared key then encrypts the traffic. Your devices do this each time they open a secure connection to a website or a mail server.
Key pairs are also used to sign in without a password. The Information Security Manual from the Australian Signals Directorate (ASD) prefers public key sign-in for remote administration of servers, because it is much harder to break by guessing than a password is.
What a business should know
- The private key is the whole secret. Whoever copies it can read what was meant for you, or sign as you. Keep private keys where few people can reach them, and protect them with a password.
- A public key says nothing about who owns it. A digital certificate fills that gap by tying a key to a name.
- The methods used today will be replaced. ASD expects that a powerful enough quantum computer would defeat current public key algorithms such as RSA. No such computer exists yet, but ASD will not approve those algorithms beyond 2030 and asks organisations to have a plan for moving to the new post-quantum ones.
For a small business, that plan is mostly a matter of keeping systems updated and asking suppliers when their products will support post-quantum algorithms.
Who holds which keys and logins is part of identity and access management. For the wider picture, start with A cyber security checklist for small business.
Sources
- Glossary: public key cryptography (NIST Computer Security Resource Center) csrc.nist.gov
- Glossary: digital signature (NIST Computer Security Resource Center) csrc.nist.gov
- Glossary: symmetric key algorithm (NIST Computer Security Resource Center) csrc.nist.gov
- Implementing certificates, TLS, HTTPS and opportunistic TLS (Australian Signals Directorate) cyber.gov.au
- Information security manual: Guidelines for cryptography (Australian Signals Directorate) cyber.gov.au