Heads up: posts on this site are drafted by Claude and fact-checked by Codex. Both can still get things wrong — read with care and verify anything load-bearing before relying on it.
why → how

What is public-key cryptography?

Until 1976, published cryptography required both sides to already share a secret. Public-key crypto broke that chicken-and-egg problem and quietly became the substrate of the modern internet.

Security intro Apr 30, 2026 · updated Aug 25, 2026 · 10 min read

On this page

The picture version

Five pictures for a reader who has never met the idea, following one ordinary moment: your laptop, your bank, and a hotel Wi-Fi network run by strangers.

1 · The problem

To share a secret, you first needed to share a secret.

your laptop your bank the one key that locks and unlocks and the hotel Wi-Fi is carrying it, so everyone on the network now has it too Every fix loops back on itself. encrypt the key before sending it — with which key? deliver it out of band — your bank cannot courier a codebook to every customer Until 1976, published cryptography had no answer to this. two strangers simply could not start a private conversation over a channel other people could hear
This is the chicken-and-egg problem the whole field was stuck behind. Secrecy required a secret you had already delivered somehow — fine for an embassy with a courier, useless for a bank with ten million customers it has never met.

2 · The break

Make one key public and keep the other half back.

the half you publish public key hand it to anyone; it costs you nothing encrypts to you · verifies you the half you guard private key never leaves your machine decrypts to you · signs as you The two halves are generated together and are not interchangeable. going forward is easy for everyone — multiply two big primes, or walk an elliptic curve coming back is believed infeasible — unless you hold the one secret that makes it easy again note the load-bearing word: believed. Nobody has proved factoring or discrete log is hard.
The trapdoor is the whole invention: an operation the world can perform and only one person can undo. Publishing the forward direction gives nothing away, which is what finally lets a stranger send you something only you can open.

3 · How the shared secret appears

Neither side sends it. Both sides compute it.

your laptop computes your private + bank public the bank computes bank private + your public same secret only the public halves crossed the hotel Wi-Fi — the secret itself was never on the wire to steal and then the slow math gets out of the way the asymmetric step runs once, over a few hundred bytes — it is orders of magnitude slower than a symmetric cipher that one small shared key then drives AES-GCM or similar, which does the actual work of encrypting the page Public-key crypto almost never encrypts your real payload. it exists to get one small symmetric key agreed on — that pattern is called hybrid encryption, and it is what your browser just did
This is the scene that answers the hotel-Wi-Fi question. The shared secret is not delivered, it is derived on both ends at once — and everything you actually read and typed was protected by fast symmetric encryption underneath it.

4 · The hole the math can’t close

Perfect encryption, to whoever handed you the key.

your laptop the network hands you a key your bank reads it re-encrypts it on Nothing failed. You had a flawless private conversation with the wrong party. “here is a public key” is worthless until you know whose it is that is what a certificate is for a public key bundled with an identity and signed by someone your browser already trusts the math was never the weak part — deciding whose key to trust is where the real failures live
The substitution attack costs the attacker nothing and breaks no mathematics. Key management, not key arithmetic, is where public-key systems actually fail — which is why the padlock means “a name was checked” and not just “this is encrypted.”

5 · Keep this card

The whole thing on one index card.

public-key crypto = a key pair, one half published, one half guarded + math where only the private half can decrypt or sign + a symmetric key, agreed on rather than sent, doing the real work + a certificate answering “whose public key is this?” the smallest part by volume, and the only part that lets two strangers start from nothing every TLS handshake, SSH session, signed package, passkey login and signed commit is standing on this
Picture to keep: a mailbox bolted to a public street. Anyone walking past can drop a letter through the slot; only the person with the key on their keyring can open the front and take the letters out. Where it breaks: no mailbox explains signing, where the private half produces something the whole world can check.

Why it exists

You type your bank’s address into a browser on hotel Wi-Fi. A padlock appears, and within a few hundred milliseconds you’re typing a password into a page you trust. You and your bank have never met, never agreed on a password for the connection itself, and every byte between you just crossed a network run by strangers — including whoever else is on that hotel Wi-Fi. Somehow the two of you now share a secret that none of them have.

That’s the running example for this post: your laptop, your bank, and a network you don’t trust in between.

For most of cryptography’s history this was flatly impossible. “Encrypt a message” meant: pick a key, get it to the other party through some out-of-band channel — a courier, a codebook, a meeting in person — and use that same key on both ends. This is symmetric crypto, and it has a chicken-and-egg problem the moment your partner is someone you’ve never met: you can’t share a secret over a channel that requires already sharing a secret. Your bank cannot courier a codebook to every customer.

Diffie and Hellman named this directly in their 1976 paper New Directions in Cryptography, and gave the first published construction that escapes it — two parties agreeing on a shared secret over a channel everyone can hear. They also framed the authentication side, arguing that a public-key cryptosystem could be turned into a one-way authentication system, though without the concrete signature scheme people would end up using. Rivest, Shamir, and Adleman worked that out in 1977 and published it in 1978 as RSA. Together those results built asymmetric crypto in the open literature.

Why it matters now

The padlock is only the visible instance. Almost every secure thing your computer does rides on the same primitive: every TLS handshake, every SSH session, every signed software package (apt, container images, model checkpoints), every passkey login, every Git commit signed by a maintainer, every certificate authority stamp on a domain. Remove asymmetric crypto and there is no general way for two parties who haven’t met to start a private, authenticated conversation — which is the assumption nearly all of the above is built on. It’s the layer underneath the layer most engineers think about, which is exactly why it’s worth understanding once rather than trusting blindly forever.

The short answer

public-key crypto = a key pair (public, private) + math designed so the public key can encrypt-to or verify, but only the private key can decrypt or sign

Picture to keep: a mailbox bolted to a public street. Anyone walking past can drop a letter through the slot; only the person with the key on their keyring can open the front and take the letters out. The slot is the public key, the keyring is the private key — and handing out slots costs you nothing.

You generate two keys at once, mathematically linked. One you publish; one you guard. The two halves play different roles:

That asymmetry is the whole trick. The companion post signatures vs encryption explains why encrypting and signing aren’t one primitive run in opposite directions; here we take the shape as given.

How it works

Follow the problem forward and the design builds itself. Your laptop wants to send your bank a secret over hostile Wi-Fi.

Naive attempt: agree on a key first. Symmetric encryption is fast and well-understood, so just pick a key and send it to the bank.

Why it breaks: you’d have to send the key over the same hostile network, where anyone listening now has it. Encrypting the key requires a key. You’re back where you started.

Fix 1: make the two directions different. What you need is an operation that everyone can perform but only one person can undo. That’s a trapdoor function: easy forward, infeasibly hard to invert — unless you hold a particular secret, in which case inverting is easy too. Publish the forward direction as your public key; keep the trapdoor as your private key. Two families supply one:

Note the load-bearing word in both: believed. Nobody has proved factoring or discrete log is hard. We have decades of very motivated people failing to make them easy, which is a different and weaker kind of assurance.

Fix 2: don’t actually encrypt your data with it. Here’s the detail almost everyone gets wrong on first encounter — public-key crypto is almost never used to encrypt the real payload.

Why the naive version breaks: it’s slow, by orders of magnitude, and the math has sharp edges on large or structured inputs. Encrypting a 4 MB page directly with RSA is both impractical and a good way to introduce a vulnerability.

The fix — hybrid encryption: generate a fresh random symmetric key, encrypt the bulk payload with that (AES-GCM or similar), and use public-key crypto only to encrypt — or, more commonly these days, to agree on — that one small key. The slow asymmetric math runs once over a few hundred bytes; the fast symmetric cipher does the heavy lifting. This is precisely what your browser and your bank did during the handshake.

Fix 3: figure out whose key it is. Now your laptop can encrypt to a public key nobody can reverse. But the hotel Wi-Fi handed you that public key.

Why it breaks: whoever runs that network could have substituted their own key, read everything, and re-encrypted it onward to the bank. The math worked perfectly and you had a private conversation with the wrong party. “Here is a public key” is worthless until you know whose it is.

The fix: certificates and certificate authorities — a public key bundled with an identity and signed by someone your browser already trusts. That’s a different post (HTTPS certificates), but it’s the reason the padlock means anything at all.

Show the seams

You started with public-key crypto = a key pair + math where the halves do different jobs. What did the walk from your laptop to your bank add? — + a symmetric key doing the actual encrypting — agreed on rather than sent — and a certificate answering "whose public key is this?". The asymmetric math is the smallest part of the system by volume, and it’s load-bearing anyway: it’s the only piece that lets two strangers start from nothing.

Going deeper