Introduction
By now, you know that encryption is the practice of altering the appearance of data so that it is unreadable or unusable to individuals other than the authorized parties. To make encryption useful for a company, it has to be a two-way process. Data must be encrypted to be made unreadable, but it also needs to be decrypted to return the data to its original form to make it usable again. This twofold process requires keys and can be achieved in two ways: symmetrically or asymmetrically. This reading explores both methods in depth.
Symmetric encryption
Symmetric encryption requires that keys be generated for every secure interaction. Consider the needs of a small business versus a multinational corporation. If there are a hundred employees, each requiring secure communication, 4950 keys will be required. A company ten times that size will require 499500 keys. This growth can be expressed with a formula in which p represents the number of people who need to communicate:
p x (p-1) /2
The number of keys needed presents three challenges:
- Key management: Securing and distributing these keys becomes challenging and potentially costly.
- Lacking non-repudiation: The generation of unique keys per transaction means that there is no specific key linked to one individual, meaning the sender’s identity cannot be verified.
- Scalability: The more the organization grows, the greater the number of keys required. This will make this solution impractical at a certain stage.
But symmetric encryption does have some advantages over its asymmetric counterpart:
- Efficiency: This approach requires less computation power, so it is suitable for real-time communication.
- Simplicity: It is a more straightforward system to implement and manage.
- Speed: Because it is a simpler approach, it can be applied to large amounts of data in a shorter time.
In contrast, asymmetric encryption only requires two keys per employee.
Asymmetric encryption
So, how does asymmetric communication work? The simplicity of it is that public keys do not need to be kept secret. They can be exchanged as plaintext through an email. Consider an exchange between two individuals, Quincy and Monica. They need to communicate securely and privately. Using a software tool, both create their own key pair. First, they must share their public keys with each other. Because public keys aren’t secret, they can exchange them via email.
When Quincy wants to send a secured message via email to Monica, he uses her public key to encrypt the plaintext and create the ciphertext. When she receives the ciphertext she can use her private key to decrypt the data, turning it back to plaintext.
When Monica wants to respond, she uses Quincy’s public key to encrypt the message before sending it. And like Monica, he then uses his private key to decrypt it.
In the event that the cipher text is intercepted, a would-be-hacker has no way of knowing what the private key is, so they can’t decrypt it. Equally, the sender has no insight into how the receiver will decrypt it, meaning that the information can be sent securely without creating excessive keys, which would require safeguarding and management.
The main advantages of this approach are:
- Strong security: Using two different keys for encryption and decryption makes this approach inherently safer than a one-key-fits-all approach.
- Key distribution and management: The two key approach also means that it is easy to share the key without compromising security. This has the added advantage of not requiring excessive key storage practices.
- Non-repudiation: This means that the identity of the sender can be verified. This feature adds to the degree of security as you know who is sending you the data.
But it does come with some disadvantages:
- Slower performance: Adding the second key adds complexity, making this a slower process than a symmetric approach.
- Computational overhead: Besides taking more time to compute, it also draws more resources as many more computations are needed.
- Key size: Keys associated with this approach are longer and will thus take up more storage space.
Encryption methods
Encryption methods are being developed all the time. Some examples include:
- Data encryption standard (DES) and Triple-DES: This was one of the first symmetric encryption standards used.
- Advanced encryption standard (AES): AES replaced DES and Triple DES and is still widely used today.
- RSA: This was one of the first asymmetric encryption standards, and variations are still used today.
Conclusion
This reading explored encryption in depth and explained the difference between symmetric and asymmetric encryption in greater detail. While symmetric encryption offers speed and efficiency, asymmetric encryption provides heightened security through distinct keys. Both play pivotal roles in safeguarding digital information tailored to specific needs and scenarios. Later in this lesson, you will review a third distinct but related variation: hashing.