Secure algorithms : Cryptography
M4-R5.1 · Chapter 5: Security and Future of IoT Ecosystem · 5 min read
1. What is Cryptography?
Cryptography is the science and art of securing information by transforming it into an unreadable format so that only authorised parties can access and understand it. The word 'cryptography' comes from the Greek words kryptos (hidden) and graphein (to write).
"Cryptography is the practice of protecting information through the use of coded algorithms, hashes, and signatures. Its primary goal is to keep data confidential, intact, and accessible only to those who are authorised."
1.1 Why Do We Need Cryptography?
- Protect sensitive data like passwords, bank details, and personal messages.
- Ensure data is not tampered during transmission (integrity).
- Verify the identity of users and systems (authentication).
- Prevent senders from denying they sent a message (non-repudiation).
- Enable secure communication over the internet (HTTPS, SSL/TLS).
2. Encryption and Decryption
Encryption and Decryption are the two core operations of cryptography. Together they form a cycle that protects data when it is stored or transmitted.
2.1 What is Encryption?
Encryption is the process of converting plaintext (readable data) into ciphertext (scrambled, unreadable data) using a mathematical algorithm and a key.
Only someone with the correct key can reverse the process.
Formula: Plaintext + Key + Algorithm = Ciphertext
2.2 What is Decryption?
Decryption is the reverse of encryption — it converts ciphertext back into readable plaintext using the correct key.
Without the key, decryption is computationally infeasible.
Formula: Ciphertext + Key + Algorithm = Plaintext
3. Types of Cryptography
Cryptography can be classified into three major types based on how keys are used and how data is transformed.
|
Type |
Key Usage |
|
Symmetric |
Same key for encrypt & decrypt |
|
Asymmetric |
Public key encrypts, private key decrypts |
|
Hash Functions |
No key; one-way transformation |
3.1. Symmetric Cryptography
Symmetric cryptography (also called Secret-Key or Single-Key cryptography) uses the SAME key for both encryption and decryption.
The sender and receiver must both know and keep this key secret.
4.1 How It Works
Step 1 — Both parties agree on and share a secret key in advance (key distribution).
Step 2 — The sender uses the shared key + algorithm to encrypt the plaintext into ciphertext.
Step 3 — The ciphertext is transmitted over the network.
Step 4 — The receiver uses the same shared key + algorithm to decrypt the ciphertext back to plaintext.
Analogy – House Key
Think of a house with one type of key. Every family member who needs access gets a copy of the same key.
Anyone with that key can both lock (encrypt) and unlock (decrypt) the door.
If the key is lost or stolen, the entire security is compromised — you must change the lock for everyone.
3.2. Asymmetric Cryptography
Asymmetric cryptography (also called Public-Key cryptography) uses TWO mathematically linked keys — a Public Key (shared openly) and a Private Key (kept secret).
Data encrypted with one key can only be decrypted with the other.
3.2.1 The Key Pair Concept
Every user generates a key pair:
- Public Key – Shared openly with everyone. Used to encrypt data meant for you, or to verify your signature.
- Private Key – Kept absolutely secret. Used to decrypt data encrypted with your public key, or to sign messages.
Mathematical Link: The two keys are mathematically related — what one key locks, only the other can unlock — yet knowing the public key does NOT allow you to derive the private key.
3.2.2 How It Works (Encryption Flow)
Step 1 — Bob generates a public/private key pair. He publishes his public key freely.
Step 2 — Alice wants to send Bob a secret message. She encrypts it using Bob's public key.
Step 3 — The ciphertext travels over the network.
Step 4 — Only Bob can decrypt it using his private key. Even Alice cannot decrypt it now!
Analogy – Bank Safe Deposit Slot
A bank vault has a deposit slot (public key) that anyone can use to drop money in.
But only the bank manager with the master key (private key) can open the vault and take money out.
Anyone can put data IN using the public key, but only the key owner can GET data OUT.