skip to content

Public-key encryption is usually taught as 'encrypt with the public key, decrypt with the private key'. Give the definition that explains what asymmetric encryption actually solves, and why calling it 'a stronger shared password' is the wrong frame.

level: juniorimportance: must knowfreq 72%

answer

  1. public encrypts, private decrypts
  2. solves distribution, not strength
  3. attacker owns the encryption key
  4. no sender authenticity, no freshness
  5. RSA encrypts / DH agrees / KEM encapsulates

basics

~20 s

A linked key pair: the public key only encrypts and may be published, the private key alone decrypts. It removes the need for a pre-shared secret, so it solves key distribution, not strength. A ciphertext still proves nothing about who produced it.

solid answer

~40 s

Symmetric encryption requires both sides to already share a secret, which requires a confidential channel you do not yet have. Asymmetric encryption breaks that circularity with a trapdoor one-way function: the public key can be published and still only enables encryption; only the private key reverses it. It is not a better password. Per bit it is weaker, and it is slow and size-limited, which is why it is used to establish a symmetric key rather than to carry data. It also buys less than people assume. Because anyone holds the encryption key, a ciphertext carries no evidence of sender, no freshness (an old ciphertext replays fine), and no protection if you encrypted to the wrong public key. Secrecy of distribution became authenticity of distribution: you still have to know the key is theirs.

go deeper

for a junior

Recall the pair, which half is published, and that it removes the pre-shared-secret requirement.

for a middle

Add why the primitive is slow and bounded, and that a ciphertext gives confidentiality only - no origin, no freshness.

for a senior

Frame it as converting a secrecy problem into an authenticity problem, and distinguish direct encryption from key agreement and encapsulation.

for a principal

Reason about where the residual trust decision lives in the system and what recorded ciphertext is worth to an attacker who later obtains the private key.

## The circular problem it breaks Symmetric encryption needs the same secret at both ends, so agreeing on it needs an already-confidential channel, which is what you were trying to build. It also scales as n(n-1)/2 pairwise keys. Asymmetric encryption removes the prerequisite: publish one half of a key pair and anyone can send you confidential data with no prior contact. ## The asymmetry itself The pair is generated together and linked by a hard mathematical problem (factoring, discrete logarithms). The direction that uses the public key is easy; reversing it without the private key is believed infeasible, and the private key is not derivable from the public key in practical time. That one-way structure is the whole mechanism. ## The threat-model consequence of 'public' The attacker owns the encryption key. Any attack that only requires encrypting is therefore free and offline: no interaction with you, no rate limit, no log entry. That single fact drives everything else, including why raw unpadded encryption is unsafe and why encrypting a low-entropy value is dangerous. ## What it does not provide - **Sender authenticity.** Anyone can encrypt to your public key, so 'it decrypted cleanly' means only that it was encrypted to you. - **Freshness.** Recording and replaying an old ciphertext works; nothing in the primitive binds a message to a moment. - **Forward secrecy** when a long-lived key pair is the only thing protecting recorded traffic. - **The trust decision.** Encrypting to an attacker's public key is flawless encryption to the wrong person, and it fails silently. ## Three families that diverge on what 'asymmetric encryption' even means RSA is a genuine trapdoor permutation: it encrypts a bounded message directly. Diffie-Hellman and its elliptic-curve form encrypt nothing at all; both sides derive a shared secret from each other's public values, so it is key agreement. Post-quantum designs such as ML-KEM are key-encapsulation mechanisms: they produce a random key plus a ciphertext that carries it. Only the first is literally 'encrypt a message with a public key'; the other two exist to hand you a symmetric key. So the sentence 'we encrypt with public-key crypto' almost always means 'we asymmetrically establish a symmetric key'. ## The invariant Anyone may hold the ability to encrypt; only the private-key holder may decrypt. Confidentiality is therefore a property of two things: who controls the private key, and whether you bound the right public key to the right identity.

  • If a message decrypts successfully with your private key, what have you actually learned?
    Only that someone encrypted it to your public key, which everybody can do. You have learned nothing about the sender's identity, nothing about when it was created, and nothing about whether it is the original message rather than a replay of an older one. Any claim of origin inside the plaintext is unauthenticated text.
  • Why is a key pair not simply 'two passwords'?
    A password is a shared secret: both sides hold the same value, so either can perform either operation, and disclosure to one party is disclosure to all. A key pair is deliberately unequal - one half is safe to publish because it only permits the easy direction. That inequality is what removes the need for a secure setup channel, and it is also why the two halves cannot be swapped when reasoning about risk.

saying these in an interview costs you the question

  • Saying asymmetric encryption is 'more secure' than symmetric rather than differently scoped; per bit it is weaker and far slower.
  • Claiming a successfully decrypted message proves who sent it.
  • Assuming the public key must be kept secret, or that publishing it weakens the pair.
  • Believing key distribution is now solved, when the residual problem is proving a public key belongs to the intended party.

context