How does encryption work? Keys and scrambled data

How does encryption work? It takes readable data, mixes it with a secret value called a key, and turns it into something that looks like random noise. Anyone who holds the right key can turn the noise back into the original. Anyone who does not hold it sees only scrambled bytes. This post explains the parts, the two main kinds of encryption, and a small example you can do with a pencil.

How does encryption work? The short answer

NIST, the US standards body, defines encryption in its glossary as "the process of changing plaintext into ciphertext using a cryptographic algorithm and key." Each of those words does a job.

  • Plaintext is the readable data: a message, a photo, a file.
  • Ciphertext is the scrambled result. NIST describes it as a form that "conceals the data's original meaning."
  • The algorithm is the recipe for scrambling. AES, a widely used one, is a published standard: anyone can read how it works.
  • The key is the secret that makes your scrambling different from everyone else's.

The reverse step is called decryption. NIST calls it "a transformation that restores encrypted data to its original state." So the whole system rests on one fact: the algorithm can be known to everyone, but the key must not be.

Plaintext, ciphertext and the key

Think of the algorithm as a lock design that anyone can buy, and the key as the one key cut for your door. Knowing how the lock works does not open your door. Holding the key does.

So the secret is the key, not the method. Wikipedia's Encryption article notes that a modern scheme usually uses a key made by a random generator, so it cannot be guessed from anything about you.

It is also worth knowing what encryption does not do. The same article says encryption "does not itself prevent interference but denies the intelligible content to a would-be interceptor." Someone can still copy, delete or block your encrypted data. They just cannot read it.

Symmetric and public key encryption

There are two main ways to handle the key.

Symmetric encryption uses one shared secret key. NIST's glossary describes a symmetric key algorithm as one that "uses the same secret key for an operation and its complement (e.g., encryption and decryption)." It is fast, but it has a puzzle built in: how do two people agree on the secret key without someone overhearing it?

Public key encryption solves that puzzle with a pair of keys. NIST's entry for public key cryptography describes "two separate keys," one to encrypt and one to decrypt. You publish the first key so anyone can lock a message for you. Only your private key opens it. Wikipedia says public key encryption was first described in a secret document in 1973, and before that every scheme was symmetric.

Wikipedia also names an answer to the shared-key puzzle: the Diffie and Hellman key exchange, "a method for establishing a shared secret over an insecure channel."

Diagram of symmetric encryption with one shared key turning MEET AT NOON into ciphertext and back, and public key encryption where anyone encrypts with a public key and only the owner decrypts with a private key

A worked example: encrypt a message by hand

The oldest textbook cipher is the Caesar cipher. Each letter moves a fixed number of places along the alphabet, and that number is the key. You can do it in a minute.

  1. Pick a key. Use 3. Each letter moves three places forward: A becomes D, E becomes H, M becomes P.
  2. Encrypt. Take the plaintext MEET AT NOON. Move each letter: M to P, E to H, T to W, A to D, N to Q, O to R. The ciphertext is PHHW DW QRRQ.
  3. Decrypt. Your friend knows the key is 3, so they move each letter three places back and read MEET AT NOON.
  4. Now attack it. Pretend you do not know the key. Wikipedia points out that English has only 25 possible shifts, so you can try every one. Shift back by 1, by 2, by 3. At 3, real words appear. The cipher is broken in minutes.

Notice two weaknesses. First, the key space is tiny: 25 choices. Second, the pattern leaks through. The double E in MEET became HH, and the double O in NOON became RR. A careful reader can spot repeats even before guessing the key. Wikipedia sums it up: the Caesar cipher "is easily broken and in modern practice offers essentially no communications security."

Modern algorithms fix both problems. AES, for example, scrambles each block of data over 10, 12 or 14 rounds, depending on the key size, so simple patterns like a doubled letter do not carry through, and the number of possible keys is enormous.

Why modern keys are so long

If an attacker can try every key, the only defence is to have too many keys to try. Key length is counted in bits, and every extra bit doubles the number of possible keys.

  • DES, one of the first widely used modern ciphers, had a 56-bit key. Wikipedia records that it was cracked in 1999 by a purpose-built machine in 22 hours and 15 minutes.
  • AES, its successor, uses keys of 128, 192 or 256 bits, according to Wikipedia's AES article.
  • AES-128 alone has 2 to the power of 128 possible keys. Wikipedia says that makes trying them all "computationally infeasible with current technology."

Going from 56 bits to 128 bits is not about twice as hard. It is 2 to the power of 72 times as many keys. That is why attackers usually look for weaker spots instead: a stolen password, a flaw in the software, or a key left lying around.

Where you already use encryption

Encryption protects data in two states, and you meet both every day.

  • Data in transit is data moving across a network, like a web page or a message on its way to a friend.
  • Data at rest is data stored somewhere. Wikipedia gives the example of files on computers and USB flash drives, and notes that encrypting stored files helps when a laptop or backup drive is lost or stolen.

Encryption can also be turned against you. Ransomware uses the very same idea: it encrypts your files and keeps the key. The algorithm is not broken. You simply do not hold the key. That is why a separate copy of your data matters as much as the lock on it.

And remember what encryption cannot do. It does not stop someone deleting your files, and it does not help if the attacker has your password. A second proof at login, like two-factor authentication, covers a different gap.

See the idea in the game: Encryption and the Encrypted zone

Tank City Reboot is a free tank game set inside a computer, and every power-up, enemy and wall is named for a real idea. Encryption shows up in two places.

On the battlefield of both games there is a terrain called the Encrypted zone. It hides any tank inside it. The card under the game explains the real idea: "Encrypted data looks like random noise to anyone without the key." The first game even has a stage named ENCRYPTION.

In Tank City Zero Day, the second game, Encryption is one of the upgrades you can pick after a wave. Your shots pass through one more enemy, and you can take it twice.

The Encryption upgrade card on the Tank City Zero Day page: shots pass through one more enemy, and the real idea, encryption scrambles data so only the key holder can read it

The game teaches one sentence per name. It is not a security course and it does not protect your computer. It is a way to meet the word, then come back here for the detail.

Frequently asked questions

How does encryption work in simple words?

It mixes your data with a secret key so it looks like random noise. Only someone with the right key can turn it back into the original.

What is the difference between symmetric and public key encryption?

Symmetric encryption uses one shared key to lock and unlock. Public key encryption uses a pair: a public key anyone can use to lock, and a private key only the owner uses to unlock.

Can encryption be broken?

Weak schemes can, like the Caesar cipher with only 25 keys, or DES, cracked in 1999. For AES-128, trying every key is computationally infeasible with current technology, so attackers usually go after passwords, flaws or stolen keys instead.

Does encryption stop ransomware?

No. Encryption keeps data unreadable to others, but ransomware encrypts your own files with its key. An offline backup is what lets you recover.

Get started

Play Tank City Reboot: it is free, plays in your browser on a computer or a phone, and needs no account. Find the Encrypted zone on the map, then try the Encryption upgrade in Zero Day.

0 likes

Comments

No comments yet.

Sign in or make an account to comment.