Cryptography is the study and construction of methods that protect information against unauthorized disclosure, alteration, and impersonation. It combines mathematics and computer science to develop algorithms and protocols for communication and computation in the presence of adversaries. Its purposes extend beyond concealing messages to verifying their origin and integrity. Cryptography is a component of cybersecurity, rather than a substitute for the other technical and organizational measures needed to secure a system. (cacr.uwaterloo.ca)
Goals and terminology
The principal cryptographic goals include confidentiality, integrity, authentication, and support for non-repudiation. Confidentiality restricts access to information; integrity makes unauthorized changes detectable; authentication provides evidence about an entity’s identity or a message’s origin. Non-repudiation concerns evidence that can counter a subsequent denial of an action, although its practical effectiveness also depends on procedures and key protection. (cacr.uwaterloo.ca)
Encryption converts readable plaintext into ciphertext using an algorithm and a cryptographic key. Decryption reverses this transformation with the appropriate key. Encryption does not automatically authenticate a message or detect modification. Cryptanalysis investigates methods for defeating cryptographic protections; the broader term cryptology encompasses both cryptography and cryptanalysis. (cacr.uwaterloo.ca)
Historical development
Earlier cryptography relied heavily on substitution and transposition: replacing symbols or rearranging their order. These techniques illustrate how recognizable patterns in a message can survive an apparently complicated transformation. Modern cryptography instead treats messages as mathematical objects and evaluates security against explicitly described adversaries. (cacr.uwaterloo.ca)
Claude Shannon’s 1949 work connected secrecy with information theory, giving cryptography a rigorous mathematical foundation. In 1976, Whitfield Diffie and Martin Hellman published New Directions in Cryptography, establishing public-key ideas in the open literature and describing a method for key agreement. Related discoveries had previously been made in classified British research by James Ellis, Clifford Cocks, and Malcolm Williamson. These developments transformed the problem of establishing secure communication without a previously shared secret. (ee.stanford.edu)
Symmetric and public-key methods
Symmetric-key cryptography uses a shared secret for encryption and decryption. It is generally suitable for protecting large amounts of data, but communicating parties must first obtain that secret securely. The Advanced Encryption Standard (AES) is a block cipher that processes 128-bit blocks and supports keys of 128, 192, or 256 bits. A block cipher must be incorporated into an appropriate construction to protect messages longer than one block. (cacr.uwaterloo.ca)
Public-key cryptography separates public information from a private secret. In public-key encryption, the public key permits encryption while the corresponding private key permits decryption. Other public-key constructions provide key agreement or signatures rather than encryption. Many established systems use mathematical problems from number theory, including integer factorization and discrete logarithms. Their security depends on the difficulty of attacking the particular construction, not merely on the presence of a difficult mathematical problem. (cacr.uwaterloo.ca)
Practical protocols often combine both approaches. Public-key operations authenticate participants or establish shared secrets, while symmetric algorithms protect subsequent traffic. Transport Layer Security (TLS), used for communication over the Internet, is an example of this combination. Its security also depends on how authentication, key derivation, and message protection are integrated. (rfc-editor.org)
Hashes, authentication, and signatures
A cryptographic hash function maps a message to a fixed-length digest. Important security properties include resistance to finding an input for a specified digest, a different input with the same digest, or any pair of distinct inputs that collide. A digest alone does not authenticate data: an adversary able to replace both the message and its digest can recompute it. (cacr.uwaterloo.ca)
A message authentication code uses a secret key to produce a tag that supports integrity and origin verification among parties sharing that key. A digital signature instead uses a private signing key and a public verification key, allowing verification without sharing the signing secret. Signatures do not conceal the signed message. (cacr.uwaterloo.ca)
Key management covers key generation, distribution, storage, replacement, and destruction. Certificates and other mechanisms help establish which public key belongs to an entity. Possession of a public key is insufficient unless its association with the intended participant is trustworthy. (cacr.uwaterloo.ca)
Security models and implementation
Perfect secrecy means that observing ciphertext provides no additional information about plaintext. The one-time pad achieves this under strict conditions: its key is uniformly random, independent of the message, at least as long as the message, secret, and never reused. Most practical systems instead offer computational security, making attacks infeasible within specified resource bounds. This connects cryptography with computational complexity and probabilistic analysis. (crypto.stanford.edu)
Security definitions specify an adversary’s capabilities, including access to encryptions of chosen messages or decryptions of selected ciphertexts. A proof establishes a claim within those assumptions; it does not guarantee that an implementation satisfies them. Side-channel attacks exploit information such as execution time, power consumption, or electromagnetic emissions rather than directly solving the underlying mathematical problem. (crypto.stanford.edu)
Quantum-related cryptography
A sufficiently capable quantum computer could defeat important public-key systems based on factorization and discrete logarithms. Post-quantum cryptography develops classical algorithms intended to resist both classical and quantum attacks. On August 13, 2024, NIST released its first three finalized standards: ML-KEM for key establishment, and ML-DSA and SLH-DSA for digital signatures. These constructions use different mathematical foundations from the threatened systems. (nist.gov)
Post-quantum cryptography differs from quantum key distribution, which uses physical quantum processes to establish keys. Quantum key distribution requires specialized equipment and an authenticated classical channel; it does not independently solve every problem of authentication, endpoint security, or key management. (nsa.gov)