AP® Cybersecurity review sheet from Aim for Five (aimforfive.com/cybersecurity/units/5/5-4)
Unit 5 · Topic 5.4
5.4 Asymmetric Cryptography
Asymmetric cryptography lets two people who have never met communicate secretly, using a public key anyone can have and a private key only its owner holds. This topic covers which key to use when, why longer keys are safer but slower, and how to generate keys and encrypt files with OpenSSL.
Key terms
- public key
- private key
- key pair
- key length
- RSA
- elliptic curve cryptography (ECC)
Public and private keys
With symmetric encryption, both sides must already share a secret key. Asymmetric encryption removes that step. Anyone who wants to receive encrypted data first generates a key pair: two matching keys of the same length, created together by one mathematical process. One is the public key, and the other is the private key.
The two keys are mathematical inverses: what one does, the other undoes. Either key can encrypt, but only the other key in the pair can decrypt.
The owner publishes the public key for anyone to use and guards the private key. The system's security depends entirely on the private key. If it's ever exposed, shared, stolen, corrupted or compromised, the owner must delete the pair and generate a new one.
Which key do you use?
To send someone a secret, encrypt it with the receiver's public key. Only the receiver's private key can decrypt it, so only the receiver can read it. Even you, the sender, can't decrypt what you just encrypted.
Asymmetric algorithms also power digital signatures and digital certificates. For a signature, the owner uses their private key, and anyone can check it with the matching public key. That proves who sent the data, not secrecy. The two most common asymmetric algorithms are RSA and elliptic curve cryptography (ECC). Tools like PGP use them to set up secure email and messages.
Key length
An n-bit key has a keyspace of 2ⁿ. An adversary guessing at random will, on average, find the right key after trying half of them: 2ⁿ ÷ 2 = 2ⁿ⁻¹ guesses. Each added bit doubles the work.
Longer keys are more secure but slower to encrypt and decrypt. And because computers keep getting faster, recommended key lengths for both symmetric and asymmetric algorithms rise over time. For example, an older U.S. standard, DES, used 56-bit keys and was retired once computers could search that keyspace.
You can only compare key lengths within the same algorithm. An AES 256-bit key beats an AES 128-bit key, and an RSA 4096-bit key beats an RSA 2048-bit key, but you can't compare an RSA key to an AES key by length. Different algorithms get different strength per bit. A 256-bit ECC key, for instance, is considered about as strong as a 3072-bit RSA key.
Asymmetric encryption with OpenSSL
As with symmetric encryption, you can use the command line, specialized open-source tools or web-based tools. With OpenSSL:
- Generate a 2048-bit RSA key pair into rsa.pem:
openssl genrsa -out rsa.pem 2048 - Copy the public key out into public.pem to share:
openssl rsa -pubout -in rsa.pem -out public.pem - Encrypt msg.txt with someone's public key:
openssl pkeyutl -encrypt -pubin -inkey public.pem -in msg.txt -out msg.enc - Decrypt it with the matching private key:
openssl pkeyutl -decrypt -inkey rsa.pem -in msg.enc -out msg.txt - Note: RSA can only encrypt a small amount of data directly. With a 2048-bit key and OpenSSL's default settings, the limit is 245 bytes, so a bigger file fails with an error. Real systems such as PGP encrypt the file with a fast symmetric cipher like AES, then use RSA to encrypt just that AES key.
Worked examples
Try each one yourself first, then open the solution.
- Example 1
Choosing the right key
Rosa wants to send Malik a secret file, and Malik will reply with a secret answer. Each has a key pair. (a) Which key does Rosa encrypt with? (b) Which key does Malik decrypt with? (c) Which key does Malik use to encrypt his reply? (d) An adversary copies Rosa's public key. What can they do with it?
Show the solutionHide the solution
- Step 1: (a) A secret for Malik is encrypted with the receiver's public key: Malik's public key.
- Step 2: (b) Only the matching private key can undo it: Malik's private key.
- Step 3: (c) Now Rosa is the receiver, so Malik uses Rosa's public key.
- Step 4: (d) Public keys are meant to be shared. With it, the adversary can only encrypt messages that Rosa alone can read. They can't decrypt anything sent to Rosa.
Answer: (a) Malik's public key. (b) Malik's private key. (c) Rosa's public key. (d) Only encrypt messages to Rosa; a public key can't decrypt.
- Example 2
Average guesses for a key
A key is 128 bits long. How many guesses does an adversary need on average, and roughly how long would that take at one trillion (10¹²) guesses per second?
Show the solutionHide the solution
- Step 1: Average guesses for an n-bit key: 2ⁿ⁻¹. With n = 128: 2¹²⁷ ≈ 1.70 × 10³⁸.
- Step 2: Time in seconds: 1.70 × 10³⁸ ÷ 10¹² = 1.70 × 10²⁶ seconds.
- Step 3: Convert to years: one year is about 3.16 × 10⁷ seconds, so 1.70 × 10²⁶ ÷ 3.16 × 10⁷ ≈ 5.4 × 10¹⁸ years.
- Step 4: That's hundreds of millions of times the age of the universe (about 1.4 × 10¹⁰ years), which is why 128-bit AES is considered safe from guessing.
Answer: About 2¹²⁷ ≈ 1.70 × 10³⁸ guesses, which at 10¹² per second takes roughly 5.4 × 10¹⁸ years.
Common mistakes
- Encrypting with your own public key, or with the receiver's private key. To send a secret, always use the receiver's public key.
- Thinking a stolen public key is a breach. Public keys are meant to be shared; a stolen private key is the emergency, and the pair must be replaced.
- Comparing an RSA key and an AES key by length. Key lengths only compare within the same algorithm.
- Using 2ⁿ as the average number of guesses. The average is half the keyspace, 2ⁿ⁻¹.
On the exam
- The most common question type: given a sender and a receiver, which key encrypts and which decrypts? Say whose key it is, not just public or private.
- For key-length questions, state that each added bit doubles the keyspace, that longer keys are slower, and that comparisons only work within one algorithm.
Connected topics
Videos
Check yourself: 5.4 Asymmetric Cryptography
4 questions on 5.4 Asymmetric Cryptography. Pick an answer to see if you got it, and why.
Maya wants to send Jordan a confidential file using asymmetric encryption. Jordan has already generated a key pair, published the public key and stored the private key securely.
Invented scenario
Which key should Maya use to encrypt the file?
Which key will Jordan use to decrypt the file?
Jordan's laptop is stolen, and the private key was stored on it. What should Jordan do?
An encryption key is 10 bits long. On average, how many random guesses would an adversary need to find the key?
0 of 4 answered