Mastodon Mastodon Mastodon Mastodon

Encryption

Updated: · CyberSecureFox Editorial Team

Encryption is the process of transforming readable data into an unreadable form (ciphertext) using an algorithm and a key, so that only someone with the right key can turn it back into the original.

How encryption works

An encryption algorithm (a cipher) combines the plaintext with a secret key. There are two main families:

  • Symmetric encryption uses the same key to encrypt and decrypt. It is fast and protects most data today; AES and ChaCha20 are the standard choices.
  • Asymmetric (public-key) encryption uses a key pair: a public key to encrypt and a private key to decrypt. RSA and elliptic-curve cryptography are used to exchange keys and to create digital signatures.

In practice both are combined. TLS, which protects HTTPS, uses asymmetric cryptography to agree on a session key and then encrypts the traffic symmetrically. Digital certificates issued by certificate authorities prove that the public key really belongs to the website.

Where encryption is used

Data in transit is protected by TLS, SSH and VPNs; data at rest by disk encryption such as BitLocker and FileVault; messages by end-to-end encryption, as in the Signal protocol, where even the service provider cannot read them. Encryption is different from hashing: a hash cannot be reversed, while encrypted data is meant to be decrypted.

Why encryption matters for security

Encryption keeps stolen data useless and prevents eavesdropping. Criminals use it too: ransomware encrypts victims’ files and sells the key. Looking ahead, NIST published its first post-quantum encryption standard, ML-KEM (FIPS 203), in 2024 to prepare for quantum computers.

Best practices

Use well-reviewed libraries instead of custom ciphers, prefer authenticated modes such as AES-GCM, protect and rotate keys, and enable encryption by default for devices and backups.

Synonyms:
data encryption