Asymmetric Encryption
In short: An encryption method with two different, mathematically linked keys — a public key for encrypting and a private key for decrypting.
In more detail: The public key can be distributed freely without endangering security — only the owner of the private key can read messages encrypted with it. This solves the key distribution problem of symmetric encryption, but is considerably more compute-intensive. In practice, a hybrid method is therefore often used: asymmetric encryption only for securely exchanging a symmetric session key, with the actual data then encrypted symmetrically. Well-known algorithms: RSA, elliptic curves (ECC).
In Depth
A historical breakthrough
Asymmetric cryptography solved a problem that was thousands of years old: until 1976, two parties who wanted to communicate in encrypted form had to exchange a shared secret key over a secure channel BEFORE the actual communication — practically impossible with millions of internet users who establish new connections to unknown servers every day. In 1976, Whitfield Diffie and Martin Hellman published the key exchange method named after them, which showed for the first time that two parties can agree on a shared secret over a completely public channel that can be eavesdropped on, without an eavesdropper being able to calculate it. RSA (named after Rivest, Shamir, Adleman) followed in 1977 as the first practicable asymmetric encryption AND signature method.
The mathematics behind RSA
Mathematically, asymmetric encryption is based on so-called trapdoor one-way functions: operations that are easy to compute in one direction but practically impossible in the other direction without additional knowledge. With RSA, this is the factorisation of large numbers — it’s easy to multiply two large prime numbers, but extremely laborious to reconstruct the two prime factors from the product. The public key contains the product, the private key the two prime factors.
public key: (n, e) n = p * q (product of two large primes)
private key: (n, d) d is calculated from p, q
Encrypt: c = m^e mod n
Decrypt: m = c^d mod n
Real RSA keys today use at least 2048 bits (recommended: 3072 or 4096 bits), which corresponds to prime numbers with hundreds of decimal digits — even with the combined computing power of all supercomputers existing today, factorising such a product would take longer than the age of the universe.
Elliptic curves as a leaner alternative
A second, equally widespread approach is elliptic curve cryptography (ECC): it’s based on the discrete logarithm problem on elliptic curves and achieves the same level of security as RSA with considerably shorter key lengths (a 256-bit ECC key is about as secure as a 3072-bit RSA key) — which is why ECC is increasingly preferred, e.g. for modern TLS certificates and SSH keys. Shorter keys mean smaller certificates, faster handshakes and less computing effort — particularly relevant for mobile devices and IoT hardware with limited computing power.
Signing instead of just encrypting
Besides encryption (only the owner of the private key can read), asymmetric cryptography can also be used the other way round for digital signatures: the sender “encrypts” with their PRIVATE key (or applies a mathematically related operation), and anyone with the matching public key can check the signature. This proves authenticity — only the owner of the private key could have created this signature, similar to a signature that nobody can forge without possessing the private key. GPG uses exactly this principle for signed emails and software packages.
Why hybrid methods dominate in practice
The high computing effort of asymmetric methods (typically 100 to 1000 times slower than symmetric encryption) is the reason why in practice it’s almost never used for encrypting whole amounts of data, but almost exclusively for securely exchanging a short symmetric key — see hybrid key methods. Practically every modern security protocol (TLS/HTTPS, SSH, GPG-encrypted emails) follows this pattern: asymmetric for the key exchange/authentication, symmetric for the actual bulk data.
The quantum computer threat
Both RSA and ECC are based on mathematical problems that are practically unsolvable on classical computers — a sufficiently powerful quantum computer, however, could break them in a manageable time using Shor’s algorithm. Because such computers don’t exist yet but may become reality in a few decades, the cryptography community is already working on “post-quantum” methods (e.g. lattice-based cryptography) that are meant to remain resistant even against quantum computers — the US NIST published the first such standards in 2024.
See also: Symmetric encryption, Public key, Private key