skip to content

questions

5

Public-key encryption is usually taught as 'encrypt with the public key, decrypt with the private key'. Give the definition that explains what asymmetric encryption actually solves, and why calling it 'a stronger shared password' is the wrong frame.

level: juniorimportance: must knowfreq 72%

answer

  1. public encrypts, private decrypts
  2. solves distribution, not strength
  3. attacker owns the encryption key
  4. no sender authenticity, no freshness
  5. RSA encrypts / DH agrees / KEM encapsulates

basics

~20 s

A linked key pair: the public key only encrypts and may be published, the private key alone decrypts. It removes the need for a pre-shared secret, so it solves key distribution, not strength. A ciphertext still proves nothing about who produced it.

solid answer

~40 s

Symmetric encryption requires both sides to already share a secret, which requires a confidential channel you do not yet have. Asymmetric encryption breaks that circularity with a trapdoor one-way function: the public key can be published and still only enables encryption; only the private key reverses it. It is not a better password. Per bit it is weaker, and it is slow and size-limited, which is why it is used to establish a symmetric key rather than to carry data. It also buys less than people assume. Because anyone holds the encryption key, a ciphertext carries no evidence of sender, no freshness (an old ciphertext replays fine), and no protection if you encrypted to the wrong public key. Secrecy of distribution became authenticity of distribution: you still have to know the key is theirs.

go deeper

for a junior

Recall the pair, which half is published, and that it removes the pre-shared-secret requirement.

for a middle

Add why the primitive is slow and bounded, and that a ciphertext gives confidentiality only - no origin, no freshness.

for a senior

Frame it as converting a secrecy problem into an authenticity problem, and distinguish direct encryption from key agreement and encapsulation.

for a principal

Reason about where the residual trust decision lives in the system and what recorded ciphertext is worth to an attacker who later obtains the private key.

## The circular problem it breaks Symmetric encryption needs the same secret at both ends, so agreeing on it needs an already-confidential channel, which is what you were trying to build. It also scales as n(n-1)/2 pairwise keys. Asymmetric encryption removes the prerequisite: publish one half of a key pair and anyone can send you confidential data with no prior contact. ## The asymmetry itself The pair is generated together and linked by a hard mathematical problem (factoring, discrete logarithms). The direction that uses the public key is easy; reversing it without the private key is believed infeasible, and the private key is not derivable from the public key in practical time. That one-way structure is the whole mechanism. ## The threat-model consequence of 'public' The attacker owns the encryption key. Any attack that only requires encrypting is therefore free and offline: no interaction with you, no rate limit, no log entry. That single fact drives everything else, including why raw unpadded encryption is unsafe and why encrypting a low-entropy value is dangerous. ## What it does not provide - **Sender authenticity.** Anyone can encrypt to your public key, so 'it decrypted cleanly' means only that it was encrypted to you. - **Freshness.** Recording and replaying an old ciphertext works; nothing in the primitive binds a message to a moment. - **Forward secrecy** when a long-lived key pair is the only thing protecting recorded traffic. - **The trust decision.** Encrypting to an attacker's public key is flawless encryption to the wrong person, and it fails silently. ## Three families that diverge on what 'asymmetric encryption' even means RSA is a genuine trapdoor permutation: it encrypts a bounded message directly. Diffie-Hellman and its elliptic-curve form encrypt nothing at all; both sides derive a shared secret from each other's public values, so it is key agreement. Post-quantum designs such as ML-KEM are key-encapsulation mechanisms: they produce a random key plus a ciphertext that carries it. Only the first is literally 'encrypt a message with a public key'; the other two exist to hand you a symmetric key. So the sentence 'we encrypt with public-key crypto' almost always means 'we asymmetrically establish a symmetric key'. ## The invariant Anyone may hold the ability to encrypt; only the private-key holder may decrypt. Confidentiality is therefore a property of two things: who controls the private key, and whether you bound the right public key to the right identity.

  • If a message decrypts successfully with your private key, what have you actually learned?
    Only that someone encrypted it to your public key, which everybody can do. You have learned nothing about the sender's identity, nothing about when it was created, and nothing about whether it is the original message rather than a replay of an older one. Any claim of origin inside the plaintext is unauthenticated text.
  • Why is a key pair not simply 'two passwords'?
    A password is a shared secret: both sides hold the same value, so either can perform either operation, and disclosure to one party is disclosure to all. A key pair is deliberately unequal - one half is safe to publish because it only permits the easy direction. That inequality is what removes the need for a secure setup channel, and it is also why the two halves cannot be swapped when reasoning about risk.

saying these in an interview costs you the question

  • Saying asymmetric encryption is 'more secure' than symmetric rather than differently scoped; per bit it is weaker and far slower.
  • Claiming a successfully decrypted message proves who sent it.
  • Assuming the public key must be kept secret, or that publishing it weakens the pair.
  • Believing key distribution is now solved, when the residual problem is proving a public key belongs to the intended party.

context

open as a page

Why is a 4 MB file never encrypted directly under an RSA public key, and what does the standard hybrid (envelope) construction do instead? Derive the size limit rather than quoting a number.

level: middleimportance: must knowfreq 60%

basics

~20 s

RSA encrypts one integer smaller than the modulus, minus padding overhead - a couple of hundred bytes - and there is no chaining mode to extend it. So generate a random symmetric key, encrypt the bulk with it, and use the public key only to wrap that key.

open as a page

Asymmetric encryption is credited with solving key distribution. What problem does it leave behind, and for a system that must encrypt data to many recipients, how would you decide how public keys are trusted and how long a private key may live?

level: principalimportance: must knowfreq 40%

basics

~20 s

It converts secrecy of distribution into authenticity of distribution: you must prove a public key belongs to the intended party, and encrypting to the wrong one fails silently. Key lifetime is driven by blast radius - a static wrapping key leaked later exposes everything ever wrapped under it.

open as a page

A colleague argues that a 256-bit elliptic-curve key must be far weaker than a 2048-bit RSA key because 256 is much smaller than 2048. Explain what is wrong with comparing key lengths across algorithm families, and how you would reason about a key pair's security margin instead.

level: middleimportance: should knowfreq 45%

basics

~20 s

Compare work factor, not key length. Best-known attacks differ per family: exhaustive search for symmetric keys, sub-exponential sieving for RSA, square-root generic attacks for curves. Roughly, 128-bit security means AES-128, RSA-3072 or a 256-bit curve.

open as a page

Why is textbook RSA - treating the message as an integer and raising it to the public exponent modulo n with no padding - insecure even when nobody can factor the modulus? Name the property that randomized padding restores.

level: seniorimportance: should knowfreq 34%

basics

~20 s

Because the attacker holds the encryption key. Unpadded encryption is deterministic, so any low-entropy plaintext can be guessed and encrypted offline until the ciphertext matches. Randomized padding restores semantic security: the same message encrypts to unlinkable ciphertexts.

open as a page