Public and Private Keys, Using a Mailbox

Public-key cryptography can seem complicated at first, but the basic idea is simple:

One key can be shared with everyone, while the other key must be kept secret.

These are called a public key and a private key.

The Mailbox Analogy

Imagine a mailbox outside your house.

Anyone can walk up to the mailbox and put a letter inside.

But only you have the key that opens the mailbox and lets you retrieve what is inside.

This is similar to how public-key encryption works.

Public key  → Can be shared with everyone
Private key → Must be kept secret

Someone can use your public key to encrypt information for you.

Only your private key can decrypt that information.

A Simple Example

Imagine Alice wants to send Bob a secret message.

Bob gives Alice his public key:

Bob's Public Key
       ↓
     Alice
       ↓
Encrypts the message
       ↓
Encrypted message
       ↓
     Bob
       ↓
Bob's Private Key
       ↓
Original message

Bob can safely share his public key with Alice because it is designed to be public.

His private key, however, should never be shared.

Why Have Two Keys?

With traditional symmetric encryption, the same secret key is used to encrypt and decrypt information.

That creates a problem:

How do you safely give the secret key to the other person in the first place?

Public-key cryptography helps solve this key distribution problem.

You can share your public key openly while keeping your private key secret.

Public Key vs Private Key

Public KeyPrivate Key
Can be sharedMust be kept secret
Used by others to encrypt data for youUsed to decrypt that data
Can be publishedShould never be published
Used in some digital-signature systemsUsed to create digital signatures

The exact use of each key depends on the cryptographic system and algorithm.

Public Keys Can Also Verify Signatures

Public and private keys aren’t only used for encryption.

They can also be used for digital signatures.

Imagine Bob signs a message using his private key.

Other people can use Bob’s public key to verify that the signature corresponds to Bob’s key.

Conceptually:

Bob's Private Key
        ↓
   Creates signature
        ↓
      Message
        ↓
Bob's Public Key
        ↓
 Verifies signature

This helps provide authentication and integrity.

Where Are Public and Private Keys Used?

Public-key cryptography is used in many areas of cybersecurity, including:

  • HTTPS/TLS for secure web communication
  • SSH for secure remote access
  • Digital signatures
  • Secure email
  • Software and certificate signing
  • Cryptocurrency systems

It is one of the fundamental ideas behind modern digital security.

One Important Detail

Public-key cryptography is usually not used to encrypt huge amounts of data directly because asymmetric operations are generally more computationally expensive than symmetric encryption.

Instead, modern systems often combine both approaches.

For example:

Public-key cryptography
        ↓
Securely establish/share a session key
        ↓
Symmetric encryption
        ↓
Encrypt the actual data

This combination provides both secure key exchange and efficient data encryption.

Key Takeaways

  • Public-key cryptography uses a key pair.
  • The public key can be shared openly.
  • The private key must remain secret.
  • A public key can be used to encrypt information intended for the private-key holder.
  • Private and public keys can also be used for digital signatures.
  • Public-key cryptography is an important part of technologies such as HTTPS and SSH.
  • Modern secure systems often combine asymmetric and symmetric cryptography.

Try It Yourself

You can see public-key cryptography in action by generating your own key pair in a Linux practice environment using SSH:

ssh-keygen -t ed25519

This creates a key pair consisting of:

Private key → Keep this secret
Public key  → Safe to share

For learning, use your own computer or virtual machine. Never share a private key that protects a real account or system.

Next Lesson

Next, learn How Authentication Works to understand how websites verify who you are and how sessions keep you logged in.

Similar Posts

  • Cross-Site Scripting, Explained With One Example

    Cross-Site Scripting (XSS) is a web security vulnerability that happens when a website places untrusted user input into a webpage without properly handling it. In simple terms: The website expects data, but the browser ends up treating that data as code or markup. A Simple Example Imagine a website has a comment box: A normal…

  • Linux File Permissions, Decoded

    Linux uses file permissions to control who can read, modify, or execute files. This is an important part of Linux security because it prevents users and programs from accessing files they should not be able to use. The Three Basic Permissions Linux commonly uses three basic permissions: Permission Symbol Meaning Read r View the contents…

  • Password strength checker

    The goal I wanted a small tool that tells you how weak or strong a password is, and explains why, not just gives a pass or fail. What you need Python 3, and about two hours if you’re new to it. How I built it The checker scores a password out of 5, based on…

  • Threat Modeling a Small Web App

    Threat modeling is a structured way of thinking about the security of an application before something goes wrong. Instead of asking: “How could someone attack this website?” we start by asking: “What are we building, what needs protection, and what could go wrong?” Threat modeling helps developers and security teams identify risks early and decide…

Leave a Reply

Your email address will not be published. Required fields are marked *