EMZETT.
Login

Symmetric Encryption

Symmetrische Verschlüsselung Image: Bananenfalter, CC0, Wikimedia Commons

In short: An encryption method where the same key is used for both encrypting and decrypting.

In more detail: Symmetric schemes (e.g. AES) are considerably faster than asymmetric encryption, but have a fundamental problem: both sides need the same key beforehand — and exchanging it securely is difficult without asymmetric methods. That’s why in practice a hybrid scheme is usually used: the symmetric key (session key) is exchanged asymmetrically, and the actual payload data is then encrypted symmetrically.

In Depth

The basic principle is a single shared key for both directions:

Plaintext + key   --[encrypt]-->  ciphertext
Ciphertext + the same key  --[decrypt]-->  plaintext

The current standard is AES (Advanced Encryption Standard) with typically 128 or 256 bits of key length — used practically everywhere, from Wi-Fi encryption (WPA2/WPA3) to encrypted hard drives to the actual payload data in a TLS connection. AES, when correctly implemented, is considered so secure that even with the largest known computing capacities, a brute-force attack on a 128-bit key would remain practically infeasible (longer than the age of the universe).

The core problem that gives symmetric schemes their name is key exchange: both sides have to know the same secret key, but simply sending it unencrypted would be pointless — anyone who intercepts it can immediately read along. With exactly two communication partners who can meet in person, this can still be solved (hand over the key on a USB stick); with a website with millions of unknown visitors worldwide, it’s impossible. This is exactly where combining it with asymmetric encryption comes in: the symmetric key is freshly and securely negotiated via an asymmetric scheme for every new connection (see Hybrid key schemes), so no one has to exchange keys in person beforehand.

Block ciphers vs. stream ciphers

Symmetric algorithms can be divided into two basic types: block ciphers (like AES) encrypt data in fixed blocks of a fixed size (128 bits per block for AES) — larger amounts of data are split into several blocks for this and linked together via a so-called mode of operation (e.g. GCM, CBC), so that identical plaintext blocks don’t produce identical ciphertext blocks (which would otherwise make patterns visible in the encrypted result). Stream ciphers (like ChaCha20), by contrast, encrypt bit by bit or byte by byte continuously, without fixed block boundaries — historically often faster in software, though modern block ciphers with hardware acceleration (the AES-NI instruction set in practically every current CPU) are now usually just as fast or faster.

Why key length matters

The key length in AES (128, 192 or 256 bits) directly determines how many possible keys an attacker would have to try in the worst case: at 128 bits there are 2^128 possible keys — a number with 39 digits, so large that even with all the computing power that exists in the world today, a complete brute-force search would remain practically impossible. AES-256 is nevertheless often preferred, among other reasons as a safety margin against future quantum computers: Grover’s algorithm could theoretically halve the effective security of a symmetric key, so that AES-128 would drop to a level comparable to “only” 64 bits under quantum attacks — AES-256 would still remain sufficiently secure with an effective 128 bits even then.

Predecessors of AES

Before AES, DES (Data Encryption Standard, 1977) was the prevailing symmetric standard, with a key length of only 56 bits — in 1998 a specially built machine (“Deep Crack”) showed that a DES key could be completely brute-forced within a few days, which finally disqualified DES for security-critical purposes. Triple DES (3DES) was used as a transitional solution, applying DES three times in a row with different keys to increase effective security — considerably slower than a modern algorithm, but compatible with existing hardware. The AES algorithm chosen by NIST in 2001 (originally developed under the name “Rijndael” by two Belgian cryptographers) replaced both and remains unbroken to this day.

See also: Asymmetric encryption, Hybrid key schemes, Session key