Learning Hub › Foundational Security › Cryptography Basics
Foundations 04 · Interactive guide
Cryptography Basics
Cryptography keeps data secret, proves it hasn't changed and proves who sent it. You don't need the maths to use it well, but you do need to know which tool does which job. Every demo on this page runs real cryptography in your browser (the Web Crypto API); nothing you type is sent anywhere.
What are you trying to protect?
Cryptography has three main tools: hashing, symmetric encryption (one shared key) and asymmetric cryptography (a public and a private key). Pick a goal to see which tool does the job.
Why key length matters: break a Caesar cipher
Julius Caesar shifted each letter by a secret number. With only 25 possible keys, anyone can try them all: a brute-force attack. Modern ciphers are safe because their key space is astronomically large.
Ciphertext
Press brute-force to try every key.
Hashing: a fingerprint for data
A hash function turns any input into a fixed-size fingerprint. It is one-way (you can't get the input back), deterministic (same input, same hash) and shows the avalanche effect: change one character and about half the output bits flip. Used for file integrity, digital signatures and (with extra care) passwords. A hash is not encryption: there is no key.
Bit difference
Each square is one output bit. Highlighted squares differ between A and B.
Symmetric encryption: AES-GCM
One secret key both locks and unlocks. AES (FIPS 197) is the global standard: fast, built into every CPU, and used for disk encryption, VPNs and the bulk data in every HTTPS connection. GCM mode also adds an authentication tag, so any tampering is detected. The hard part is not the algorithm, it's getting the key safely to the other side.
1 · Encrypt
Real AES-256-GCM- Key (256 bits, secret)
- IV / nonce (96 bits, unique per message, not secret)
- –
- Ciphertext + 128-bit tag
- –
2 · Send it, then decrypt
An attacker on the network can't read the ciphertext, but could try to change it. Flip one bit and see what GCM does.
Never reuse an IV with the same key in GCM: doing so can leak the plaintext and let attackers forge messages. Libraries generate a random IV for you.
Asymmetric cryptography: key exchange and signatures
Each party has a key pair: a public key to share freely and a private key that never leaves them. This solves symmetric crypto's key problem in two ways: two strangers can agree on a shared secret over an open network (key exchange), and anyone can check that a message came from the private-key owner (digital signature). It is slow, so in practice it only protects keys and signatures, while AES handles the data.
Key exchange (ECDH P-256)
Real ECDHAlice and Bob each generate a key pair and swap only public keys. Each combines their own private key with the other's public key, and they arrive at the same secret. An eavesdropper sees both public keys and still can't compute it.
Digital signature (ECDSA P-256)
Real ECDSAThe signer hashes the message and signs the hash with the private key. Anyone with the public key can verify it. Edit the message after signing and verification fails.
Encrypt with the public key
Only the private-key holder can decrypt. Gives confidentiality.
Sign with the private key
Anyone can verify. Gives integrity, authenticity and non-repudiation.
Certificates tie keys to names
A certificate authority signs "this public key belongs to bank.example". Your browser trusts a built-in list of CAs.
Putting it together: the TLS 1.3 handshake
Every HTTPS padlock uses all three tools in one round trip (RFC 8446): key exchange to agree a secret, a certificate and signature to prove the server is real, hashes to check nothing was altered, then AES-GCM or ChaCha20-Poly1305 for the data. Step through it.
Storing passwords: slow on purpose
Websites should never store your password, only a hash of it. But ordinary hashes like SHA-256 are built to be fast, and when a database leaks, attackers with graphics cards can try billions of guesses per second. Password hashing adds a unique random salt per user (so identical passwords look different) and a deliberate work factor that makes every guess expensive.
Feel the work factor: PBKDF2-HMAC-SHA256
Real PBKDF2 · timing estimateThe quantum threat and post-quantum crypto
A large enough quantum computer running Shor's algorithm would break RSA and elliptic-curve cryptography, the asymmetric half of almost everything. Symmetric crypto and hashes only lose some margin (Grover's algorithm), so AES-256 and SHA-384 stay safe. Attackers can record encrypted traffic today and decrypt it later ("harvest now, decrypt later"), so migration is already under way. Click an algorithm.
Migration timeline
Myth or fact?
Five common misunderstandings.
Sources & further reading
- NIST FIPS 197: Advanced Encryption Standard
The AES specification. GCM mode is SP 800-38D.
- NIST FIPS 180-4: Secure Hash Standard
SHA-1 and the SHA-2 family. The 2017 SHAttered collision broke SHA-1 in practice.
- RFC 8446: TLS 1.3
The handshake shown in section 05.
- OWASP Password Storage Cheat Sheet
Recommended Argon2id, scrypt, bcrypt and PBKDF2 settings. Argon2 is RFC 9106.
- NIST: first post-quantum standards, FIPS 203, 204 and 205 (Aug 2024)
ML-KEM, ML-DSA and SLH-DSA. HQC was selected as a backup KEM in March 2025.
- NIST IR 8547: Transition to Post-Quantum Cryptography Standards
The transition plan: quantum-vulnerable algorithms deprecated after 2030, disallowed after 2035.
- MDN: Web Crypto API
The browser API that powers the live demos on this page.
- CISA: Post-Quantum Cryptography Initiative
Guidance on building a cryptographic inventory and planning migration.
Next: see TLS in a real packet in Network Security 101, and how passkeys use signatures in IAM Fundamentals.