EMZETT.
Login

Encryption

Verschlüsselung Image: Stern, Public domain, Wikimedia Commons

In short: Converting readable data (plaintext) into an unreadable form (ciphertext) using an algorithm and a key — reversible, unlike hashing.

In more detail: There are fundamentally two types: symmetric encryption (one key for both directions) and asymmetric encryption (a key pair of public and private key). Encryption protects the confidentiality of data — both “in transit” (during transmission, e.g. via TLS) and “at rest” (in stored form, e.g. encrypted hard drives).

In Depth

The two basic types compared directly:

Symmetric (e.g. AES)             Asymmetric (e.g. RSA)
-----------------------          -------------------------
1 shared key                     key pair (public + private)
very fast                        considerably slower
Problem: secure exchange         no exchange problem
         of the key              (the public part is allowed to be public)

The distinction “in transit” vs. “at rest” describes WHEN data is protected, and both cases often need different solutions: “in transit” (during transmission) usually runs via TLS, which automatically negotiates a fresh key per connection. “At rest” (in stored form, e.g. a database or hard drive), on the other hand, needs a permanent key that has to be securely managed — if you lose this key, the data is also irretrievably lost; if an attacker does NOT get hold of it, the data remains worthless to them even if they physically steal the hard drive.

An often-overlooked third state is “in use” (while being processed in main memory) — here, in the vast majority of systems, data actually exists unencrypted, because a CPU normally can’t compute directly on encrypted data. Specialised technologies like “homomorphic encryption” or “confidential computing” (isolated, encrypted memory regions of the CPU) try to close this gap too, but are (as of today) considerably more complex and not yet the standard case in ordinary web applications.

End-to-end encryption as a special case

A particularly strict encryption model is end-to-end encryption (E2EE), as used by Signal or WhatsApp for messages, for example: here data is already encrypted on the sending device and only decrypted again on the receiving device — even the operator of the service whose servers the message passes through can never view the content in plain text at any point. This differs from “merely” encrypted transmission (TLS between client and server), where the server operator could at least briefly process the data unencrypted — E2EE closes exactly this gap, but complicates features that require server-side access to the plaintext (e.g. server-side full-text search over your own messages).

Historical encryption methods

Encryption isn’t an invention of the computer age: Caesar cipher (shifting every letter by a fixed number of positions in the alphabet) is attributed to Julius Caesar and already shows the basic principle of algorithm (shift) and key (number of positions) — although with only 25 possible keys, extremely insecure by today’s standards. The Enigma machine in the Second World War was considerably more complex (mechanical rotors produced a constantly changing encryption), but was ultimately broken by Allied codebreakers (including Alan Turing) — a historical example that even systems considered “unbreakable” can fall with enough mathematical and computational effort, which continues to drive the motivation for steadily growing key lengths and new cryptographic schemes to this day.

See also: Symmetric encryption, Asymmetric encryption, Encryption algorithm