Public-key cryptography, or asymmetric cryptography, uses a pair of mathematically linked keys: a public key that can be shared with anyone and a private key that its owner keeps secret.
How public-key cryptography works
Data encrypted with the public key can only be decrypted with the matching private key, and a value signed with the private key can be verified by anyone holding the public key. Deriving the private key from the public one is computationally infeasible because it relies on hard mathematical problems:
- Integer factorisation – the basis of RSA, published in 1977.
- Discrete logarithms – used by Diffie–Hellman key exchange (1976) and DSA.
- Elliptic curves – ECDSA, Ed25519 and X25519 offer the same security with much shorter keys.
The concept was published by Whitfield Diffie and Martin Hellman in 1976; British GCHQ researchers had found similar ideas earlier, but their work stayed classified until 1997.
How public-key cryptography is used
Asymmetric algorithms are slow, so they are used mainly to agree on or protect symmetric session keys and to create digital signatures. They underpin TLS and HTTPS, SSH logins, code signing, PGP and S/MIME email, cryptocurrency wallets and passkeys. To prove that a public key really belongs to a website or company, certificate authorities issue digital certificates, forming a public key infrastructure (PKI).
Security risks
The math is rarely the weak spot; key handling is. Stolen private keys let attackers sign malware – Stuxnet (2010) carried drivers signed with certificates stolen from Realtek and JMicron. Poor random number generation, as in the 2008 Debian OpenSSL bug, produced predictable keys. In the long term, Shor’s algorithm on a large quantum computer would break RSA and elliptic-curve schemes, which is why post-quantum algorithms are being deployed.
- Protect private keys in HSMs, TPMs or smart cards.
- Use at least 2048-bit RSA or modern elliptic curves.
- Rotate and revoke keys promptly after any suspected compromise.