Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Public-key cryptography—also called asymmetric cryptography—uses a mathematically related public key and private key for operations such as encryption, digital signatures, and key agreement. The public key can be shared; the private key must be protected. Which operation the pair supports depends on the algorithm.

What public-key cryptography means

NIST’s CSRC glossary defines public-key cryptography as cryptography using two separate, related keys: one to encrypt data or create a digital signature, and the other to decrypt data or verify the signature. NIST lists asymmetric cryptography as another name for it. See the NIST CSRC glossary definition.

The two keys are related mathematically but have different roles. The public key is intended to be shared. The private key is kept secret by its holder. A public key is not a password, and knowing it should not reveal the corresponding private key.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the keys are used for

Public-key cryptography supports several distinct tasks. A particular algorithm or protocol may support one or more of them; it is not correct to assume every public-key algorithm does all three.

Use What happens What it provides
Encryption and decryption In a basic example, a sender uses the recipient’s public key to encrypt data, and the recipient uses the corresponding private key to decrypt it. Actual algorithms and protocols impose specific conditions on what can be encrypted and how. Confidentiality: the intended recipient can recover the protected data.
Digital signatures The signer uses a private key to create a signature; another party uses the corresponding public key to verify it. Evidence of authenticity and integrity: verification can show that the signature matches the data and the key. A signature does not make the data secret.
Key agreement Participants use public-key techniques to calculate or establish shared secret material. A way to establish shared data for secure communications without first having access to a shared secret key.

NIST’s public key glossary entry describes these uses as dependent on the algorithm: a public key can verify a signature, encrypt data or keys for decryption with the corresponding private key, or contribute to computing a shared secret. NIST’s SP 800-63-4 digital identity guidance distinguishes signature protections from confidentiality: a valid signature can support authenticity and integrity, but it does not conceal the signed message.

How public and private keys work together

For confidentiality

Suppose Alex needs to send protected information to Sam. In the simple public-key encryption model, Alex obtains Sam’s public key and uses it to encrypt the information. Sam uses the matching private key to decrypt it. The public key can be distributed without giving others the ability to perform that private-key operation.

This describes the roles, not a universal recipe for encrypting any message. Real algorithms and protocols have specific constraints, and a public key may be used to encrypt a key rather than a large message directly.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For a signature

To sign a message, Sam uses a private key to create a digital signature. Alex checks the signature with the corresponding public key. If verification succeeds, it supports the conclusion that the signed data has not changed since signing and that the signature was made using the private key paired with that public key. It does not, by itself, prove that the key belongs to the person named as Sam.

For key agreement

In key agreement, participants use public-key techniques to establish shared secret material that can then support secure communication. The goal is not necessarily to encrypt the conversation directly with a public key; rather, the public-key operation helps the parties arrive at shared data without requiring them to have already shared a secret key.

Does a public key prove someone’s identity?

No. A public key can be shared, but the key alone does not establish who controls it or whether it belongs to a claimed person, organization, or service. If identity matters, a system needs a trusted way to bind the key to that identity.

A public-key certificate is a digitally signed document that binds an identifier to a subscriber’s public key. Public-key infrastructure (PKI) consists of the policies, processes, platforms, and workstations used to administer certificates and public/private key pairs. In practice, a verifier must also rely on the relevant certificate and trust mechanisms; merely receiving a key is not proof of identity. NIST describes these terms in its SP 800-63-4 guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Public-key cryptography versus symmetric cryptography

The defining distinction is how keys are arranged. Public-key cryptography uses a related public/private pair, with different roles for operations such as encryption and decryption or signing and verification. Symmetric cryptography uses a shared secret key. Public-key techniques can help participants establish shared secret material when they do not already have it; that is different from saying that all secure communication is encrypted directly with a public key.

What to remember

  • Public-key cryptography is also called asymmetric cryptography and uses two related keys with distinct roles.
  • The public key may be shared; the private key must remain protected.
  • Encryption, signatures, and key agreement serve different purposes, and a given algorithm does not necessarily support all of them.
  • A digital signature can support authenticity and integrity, but it does not provide confidentiality.
  • A public key does not identify its owner by itself; certificates and trust mechanisms provide the identity binding when needed.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.