THE QUANTUM THREAT / BEGINNER

The Locks Of The Internet: What Public-Key Cryptography Does

Public-key cryptography lets strangers agree on secrets and prove who they are. Here is how it works, where you rely on it, and which parts a quantum computer would threaten.

Checked against primary sources and independently reviewed on . Sources are listed at the end.

Every time you open a banking app, connect to a work VPN or install a software update, your device runs a quick conversation with a computer it has never met. Within a fraction of a second the two sides agree on a secret key, and your device checks that the other side really is who it claims to be. Public-key cryptography is the tool that makes that possible.

This article explains what public-key cryptography does, the two mathematical problems it rests on, and where it sits inside everyday systems. That background matters because these are exactly the parts of today’s security that a large quantum computer would break, while other parts would survive.

Two Problems Public-Key Cryptography Solves

Ordinary encryption uses one shared secret key to encrypt and decrypt data. It is fast and strong, but it has an obvious gap: two parties who have never met need some safe way to agree on that key first. Public-key cryptography fills the gap by giving each party a pair of keys. One is public and can be shared with anyone. The other is private and never leaves its owner.

A helpful picture is a padlock. You can hand out open padlocks to the whole world, and anyone can snap one shut on a box addressed to you, but only you hold the key that opens it. That covers the first job, key establishment: agreeing on a fresh secret over an open network.

The second job is the digital signature. Think of a wax seal that only you can press but that anyone can inspect. A signature made with a private key can be checked by anyone who holds the matching public key, which proves who produced a message or a file and that nobody changed it afterwards. Linking a public key to a real organisation in the first place depends on a certificate from an authority your device already trusts.

The Maths Underneath

Public-key schemes depend on calculations that are easy to perform in one direction and extremely hard to reverse. Two families of problems carry almost all of today’s traffic.

  • Factoring. Multiplying two large prime numbers takes a computer no time at all. Recovering those primes from the product is believed to be infeasible for numbers of the size used in practice. RSA is built on this.
  • Discrete logarithms. Repeatedly combining a number with itself in a special mathematical group is easy, but working out how many times it was combined is hard. Diffie-Hellman key exchange relies on this, and so do the elliptic curve versions: elliptic curve Diffie-Hellman (ECDH) for key agreement and ECDSA and EdDSA for signatures.

In the mid-1990s the mathematician Peter Shor showed that a quantum computer could solve both problems efficiently, in what computer scientists call polynomial time.1 The next article explains what that means in practice.

Where You Rely On It

NIST, the US standards body, lists the public-key algorithms it plans to retire because of this threat. For signatures they are RSA, ECDSA and EdDSA. For key establishment they are finite field Diffie-Hellman, ECDH and RSA key transport.2 Those names turn up in almost every secure system.

NIST’s draft transition guidance walks through the places they appear: network protocols such as TLS (the padlock in your browser), Secure Shell (SSH) and IPsec virtual private networks, email signing and encryption with S/MIME, code and firmware signing, user and machine authentication, and the public key infrastructure (PKI) that issues and checks digital certificates.2 In a typical connection using TLS 1.3, the current version of the web’s main security protocol, the two sides agree keys with Diffie-Hellman over finite fields or elliptic curves, and the server proves its identity with an RSA, ECDSA or EdDSA signature backed by its certificate. TLS 1.3 then protects each message with an authenticated cipher such as AES-GCM, which both hides the data and detects tampering.3

Step Behind The ScenesWhat It DoesTypical AlgorithmQuantum Exposure
TLS key exchangeAgrees a fresh session key between your phone and the bankECDH or finite field Diffie-HellmanBroken by Shor’s algorithm
Server certificateProves the server really belongs to the bank, via a chain of signatures up to a trusted rootRSA or ECDSA signaturesBroken by Shor’s algorithm
App updateProves the app you installed came from the bank and was not alteredRSA or ECDSA code signatureBroken by Shor’s algorithm
Encrypting the session dataScrambles your balance and transactions in transitAES with the agreed session keyWeakened only slightly; stays safe at proper key sizes
Integrity checksDetects tampering with each messageBuilt into the session cipher (for example AES-GCM), with SHA-2 hashes used in the handshakeWeakened only slightly; stays safe at proper sizes
One everyday action, logging in to a banking app, depends on several cryptographic steps. The public-key steps are the ones a large quantum computer would break.

The pattern in the table is the key idea of this whole topic group. Public-key cryptography does the introductions and the identity checks. Symmetric cryptography, such as AES, does the bulk work of keeping data secret once the introductions are done. NIST states that its symmetric standards are far less exposed to known quantum attacks and that it does not expect to move away from them as part of this transition.2

How The Pieces Stack Up

It helps to see public-key cryptography as one layer in a stack. An application rarely calls RSA directly. It uses a protocol such as TLS, which uses a cryptographic library, which may in turn use a hardware security module to hold private keys. Certificates issued by a PKI tie it all to real identities.

  1. Applications And ServicesBanking apps, web portals, email, remote access, software updates.
  2. Security ProtocolsTLS, SSH, IPsec and S/MIME decide which algorithms to use and in what order.
  3. Certificates And PKICertificate authorities sign certificates that bind public keys to names.
  4. Cryptographic Libraries And HardwareSoftware libraries and hardware security modules carry out the operations and guard private keys.
  5. Public-Key AlgorithmsRSA, Diffie-Hellman, ECDH, ECDSA and EdDSA. This is the layer a quantum computer threatens.
Where public-key algorithms sit in a typical system. Changing the algorithm at the bottom means updating every layer above that depends on it.

NIST points out that every one of those layers needs work for the transition: protocols must support new algorithms, libraries and hardware modules must implement them, and PKI must be able to issue and sign certificates with them.2 That is why replacing a few algorithms turns into a multi-year programme, a theme the Preparing For Migration group covers in depth.

Why This Matters For The Rest Of The Series

Once you know which job each algorithm does, the quantum threat becomes easier to reason about. Key establishment protects secrecy, so it is exposed to attackers who record traffic today and break it later. Signatures protect identity and integrity, so the danger there is forgery once a capable quantum computer actually runs. The two risks have different timelines, and the harvest now, decrypt later article looks at the first in detail.

Footnotes

  1. P. W. Shor, “Polynomial-Time Algorithms for Prime Factorization and Discrete Logarithms on a Quantum Computer”, arXiv quant-ph/9508027, submitted 30 August 1995. arxiv.org ↩

  2. NIST, IR 8547 (initial public draft), “Transition to Post-Quantum Cryptography Standards”, November 2024. nvlpubs.nist.gov ↩ ↩2 ↩3 ↩4

  3. IETF, RFC 8446, “The Transport Layer Security (TLS) Protocol Version 1.3”, August 2018. rfc-editor.org ↩

  4. NIST, “NIST Releases First 3 Finalized Post-Quantum Encryption Standards”, 13 August 2024. nist.gov ↩

Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.