Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

A public/private key pair consists of two mathematically related keys: the public key can be shared, while its matching private key must remain secret. Hashing is different: a cryptographic hash function turns input of any length into a fixed-length digest. Keys support operations such as signing, verification, encryption, and key agreement; a hash produces a digest and does not create a key pair.

What are public and private keys?

In public-key cryptography, the two keys are related mathematically but have different handling rules. The public key may be distributed. The private key is kept secret; NIST notes that it cannot efficiently be determined from knowledge of the public key.

  • Public key: Shared information used for a particular cryptographic operation, depending on the algorithm. It may verify a digital signature, encrypt material intended for the matching private key, or help establish a shared secret.
  • Private key: Secret information paired with the public key. Depending on the algorithm, it may create a digital signature or decrypt information encrypted for its public key.

These roles are not interchangeable, and not every public-key algorithm supports every operation. NIST’s SP 800-63-4 Digital Identity Guidelines and SP 800-133 Rev. 2 provide authoritative U.S. federal guidance on these concepts and key generation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How do key pairs work for signatures, encryption, and key agreement?

Digital signatures: private key signs, public key verifies

A signer uses the private key to create a digital signature; someone with the corresponding public key can verify it. NIST defines a digital signature as “An asymmetric key operation in which the private key is used to digitally sign data, and the public key is used to verify the signature.”

A valid signature supports authenticity and integrity: it helps establish that the data came from someone controlling the signing key and has not changed since it was signed. It does not make the data confidential, and a signature alone does not prevent replay attacks. Signing is not “encrypting with the private key.”

Public-key encryption: public key encrypts, matching private key decrypts

In schemes that support public-key encryption, a sender can use the recipient’s public key to encrypt data or, commonly, material such as a symmetric encryption key. The corresponding private key is used to recover it. This is a confidentiality use, unlike signing, and algorithm and protocol details determine exactly what is encrypted.

Key agreement: keys help establish a shared secret

Some public-key algorithms let participants use their keys to compute a shared secret. This is a distinct operation from signing or encrypting a message. The particular protocol specifies which keys and additional information are required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What is hashing?

A cryptographic hash function maps a message of arbitrary length to a fixed-length message digest. NIST’s Hash Functions reference gives this definition and describes the security properties expected of approved hash functions.

A digest is a compact output representing the input for uses such as integrity checks and signature workflows. Hashing is not encryption: it does not produce encrypted content that can be recovered with a corresponding decryption key. Hashing also does not generate a public/private key pair.

Approved cryptographic hash functions are designed to resist three kinds of attack:

  • Collision attack: Finding any two different inputs that produce the same digest.
  • Preimage attack: Given a digest, finding an input that produces it.
  • Second-preimage attack: Given one input, finding a different input with the same digest.

How does hashing work with a digital signature?

When a message is large, a signature workflow commonly hashes it first, then uses the private key to sign the resulting digest. The recipient verifies the signature with the public key and can check the message against its digest. The digest is input to the signature process; it is not itself the signature. The signature’s security and exact steps depend on the chosen algorithm and protocol.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This use of hashing does not turn a signature into encryption. It provides a way to sign and verify data, not to hide the message.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Is a blockchain address the same as a public key?

Not necessarily. Some blockchain systems derive an address from a public key by hashing it and adding other data. The resulting address is not necessarily the public key itself or simply its raw hash. As NIST’s 2018 NISTIR 8202 explains, each blockchain implementation may use a different address-derivation method; the system’s rules determine the relationship.

Which hash function should you use?

There is no single best hash function for every situation. The appropriate choice depends on the application, protocol, algorithm requirements, and applicable standards. NIST lists SHA-2 and SHA-3 options and reports these security-strength estimates:

Hash function NIST collision-resistance strength NIST preimage-resistance strength
SHA-256 128 bits 256 bits
SHA3-256 128 bits 256 bits

These are NIST’s stated estimates, not guarantees about every implementation. NIST reports that SHA-1 was deprecated in 2011 and disallowed for digital signatures at the end of 2013; it should not be treated as an appropriate choice for new digital signatures. These policy references are in the U.S. federal context, so other standards or jurisdictions may specify their own requirements.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.