Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Public-key cryptography uses a mathematically related pair of keys: one can be shared openly, while the other is kept secret. RSA is one of the best-known systems built on this idea. MIT researchers Ron Rivest, Adi Shamir, and Leonard Adleman developed RSA in the late 1970s; their landmark paper appeared in 1978.

What is public-key cryptography?

Public-key cryptography, also called asymmetric cryptography, uses two related keys rather than one shared secret. A public key can be distributed to other people; its matching private key must remain under its owner’s control. The mathematics links the keys so that operations involving one key can be checked or, in some schemes, reversed only with the other.

This solves a practical problem with symmetric cryptography: two parties do not first need to send a shared secret through a protected channel. As the National Institute of Standards and Technology (NIST) explains in its 2022 account of cryptographic standards, public-key methods also made digital signatures possible. Public-key cryptography is not one algorithm, however. Different schemes support encryption, key agreement, signatures, or combinations of those functions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How do public and private keys work?

The role of each key depends on the cryptographic scheme and the task. In public-key encryption, someone encrypts a small piece of information with the recipient’s public key; the recipient uses the corresponding private key to recover it. In a digital-signature scheme, the signer uses a private key to create a signature, and other people use the associated public key to verify it.

Encryption and signatures answer different questions. Encryption is intended to keep information confidential. A valid signature helps establish that data was signed using the corresponding private key and that it has not changed since it was signed. A signature does not, by itself, keep the data secret.

Public keys also need context: a user or system must know whose key it is. Digital certificates and public-key infrastructure (PKI) help bind public keys to identities, so that a key received over a network is not simply trusted because it is labelled with a name. NIST’s Cyber History materials describe the development of PKI, X.509 certificates, and related standards that helped make public-key operations practical at Internet scale.

Who invented RSA, and what is its history?

RSA was developed by MIT researchers Rivest, Shamir, and Adleman. It followed the public introduction of public-key cryptography by Whitfield Diffie and Martin Hellman in 1976. The dates refer to different milestones: Diffie and Hellman’s work introduced the public-key concept and a key-exchange method; the RSA team later presented a public-key cryptosystem that also supported digital signatures.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Year Milestone
1976 Whitfield Diffie and Martin Hellman publish the foundational public-key concept and a key-exchange method.
1977–1978 Rivest, Shamir, and Adleman develop RSA. Their paper, “A Method for Obtaining Digital Signatures and Public-Key Cryptosystems,” is published in 1978.
1980s–1990s RSA becomes part of PKCS work and Internet security software. PKI, X.509 certificates, and IETF standards support wider use of public-key operations.
1991 NIST publishes Special Publication 800-2, an overview of public-key cryptography, including its theory, implementations, and security issues.
1995 NIST’s IR 5788 describes RSA as a complete example of a public-key system and discusses its roles in key distribution and digital signatures.
2016 The IETF publishes RFC 8017, PKCS #1 version 2.2, specifying RSA encryption and signature schemes, encodings, and parameters.

The history is therefore not a story of one person inventing every part of public-key cryptography. Diffie and Hellman established an important foundation; RSA provided a prominent system for encryption and signatures; later standards and certificate infrastructure helped make such systems interoperable.

How does RSA work?

RSA starts with two large prime numbers. The system multiplies them to form a composite number called the modulus. The public key includes that modulus and a public exponent; the private key includes secret information that enables the corresponding private-key operation. RSA uses modular exponentiation, which performs arithmetic within a fixed range defined by the modulus.

The security intuition is that, for appropriately chosen parameters, recovering the prime factors of the modulus is computationally difficult. That is not a complete security guarantee: security also depends on key generation, implementation, protocol design, and using standardized schemes correctly.

In particular, “raw” or textbook RSA is not a safe recipe for a real application. RSA implementations must use the specified encoding and padding for the intended operation. RFC 8017 is the IETF specification for PKCS #1 RSA encryption and signatures, including the relevant schemes and encodings.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What is RSA used for?

RSA can support encryption/key distribution and digital signatures. In practice, public-key cryptography is generally not the efficient way to encrypt a large file or a continuous stream of data. NIST IR 5788 notes that conventional (symmetric) encryption is generally faster for data encryption.

A common design is therefore hybrid: public-key operations help establish or protect a small secret, and symmetric cryptography uses that secret to encrypt the bulk data. Certificates and PKI help users and systems identify the public keys involved. RSA can also be used for signatures, where the goal is verification of origin and integrity rather than confidentiality.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Is RSA still secure?

RSA is not automatically insecure simply because it is old, but the name of the algorithm alone does not establish that a particular system is safe. Its security depends on suitable parameters, sound key generation, correct implementation, and standardized encodings and protocols. The 2016 IETF RFC 8017 documents standardized RSA encryption and signature schemes; deploying an implementation outside such specifications can undermine the protection the mathematics is meant to provide.

There is also a long-term limitation: RSA is not post-quantum cryptography. NIST states that “Today’s widely deployed public-key cryptography schemes, such as RSA and ECDSA, will not provide any security protection against quantum computers.” This is a warning about the capabilities of sufficiently powerful quantum computers, not a claim that ordinary computers have already made properly implemented RSA generally breakable. Organizations planning long-lived protection need to account for the quantum risk when choosing cryptography and migration plans.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How does RSA compare with other public-key systems?

RSA is one choice among several, and the right comparison depends on the task. A useful evaluation asks:

  • Purpose: Is the scheme for key establishment, encryption, signatures, or more than one of these?
  • Security assumption: Does it rely on factoring, a discrete-logarithm problem, an elliptic-curve problem, or a post-quantum construction?
  • Sizes and performance: What key, ciphertext, or signature sizes are required, and how does the scheme perform on the intended hardware?
  • Compatibility: Do the relevant standards, protocols, and deployed systems support it?
  • Quantum resistance: Is it designed to withstand attacks from quantum computers?

There is no single winner for every use. For example, key agreement and digital signatures are distinct functions, even when both are described broadly as public-key cryptography. Compatibility with the systems that must communicate and the security lifetime of the protected information can matter as much as the algorithm’s name.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.