What is cryptography?
Cryptography means "secret writing". It keeps information safe from people who should not read or change it.
- Plaintext: the normal, readable message.
- Ciphertext: the scrambled message.
- Key: the secret value that controls the scrambling.
- Encryption: plaintext → ciphertext. Decryption: ciphertext → plaintext.
Cryptography helps with four goals: confidentiality (only the right people read it), integrity (nobody changed it), authentication (you know who sent it) and non-repudiation (the sender cannot deny sending it).
Classic ciphers: Caesar and substitution
In a Caesar cipher every letter moves forward a fixed number of places. With key 3: A→D, B→E, … X→A, Y→B, Z→C (it wraps round).
A substitution cipher swaps each letter for another letter using a table. A transposition cipher keeps the letters but changes their order.
These are easy to break. A Caesar cipher has only 25 useful keys, so a computer can try all of them (a brute-force attack). Letter counts also give it away: E is the most common letter in English, so the most common cipher letter is probably E (frequency analysis).
Symmetric and asymmetric (public-key) encryption
Symmetric
One shared secret key both encrypts and decrypts. It is fast, so it is used for large data (for example AES). Problem: how do you send the key safely?
Asymmetric (public-key)
Each person has a key pair: a public key that anyone may have and a private key kept secret. Data locked with the public key can be opened only with the matching private key (for example RSA). It solves the key-sharing problem but is slower.
Real systems such as https use both: public-key cryptography to agree on a secret key, then symmetric encryption for the data.
Hashing, digital signatures and authentication
A hash function turns any data into a short fixed-length value. The same input always gives the same hash, a tiny change gives a totally different hash, and you cannot get the input back. Websites store password hashes, not passwords.
A digital signature: the sender hashes the message and locks the hash with their private key. Anyone can check it with the sender's public key. This proves who sent it and that it was not changed.
Authentication means proving who you are: something you know (password), have (phone OTP) or are (fingerprint). Using two of these is two-factor authentication.
Key formulas and definitions
- Caesar encryption: C = (P + k) mod 26; decryption: P = (C − k) mod 26 (A = 0 … Z = 25)
- Symmetric: same key encrypts and decrypts
- Asymmetric: encrypt with public key, decrypt with private key
- Digital signature: sign with private key, verify with public key
- Hash: any length in → fixed length out, one-way
Worked examples
1. Encrypt CAT with a Caesar shift of 4.
C(2)+4=6 → G; A(0)+4=4 → E; T(19)+4=23 → X. Answer: GEX.
2. Decrypt the Caesar cipher BQQMF, key 1.
Move each letter 1 back: B→A, Q→P, Q→P, M→L, F→E. Answer: APPLE.
3. Encrypt ZOO with key 3 (watch the wrap).
Z(25)+3=28, 28 mod 26 = 2 → C; O(14)+3=17 → R; O → R. Answer: CRR.
4. Riya wants anyone to send her secret files, but only she should open them. Which keys are used?
Senders lock the file with Riya's public key. Only Riya's private key can unlock it. She never shares the private key.
5. Why is a Caesar cipher weak?
It has only 25 useful keys. A computer can try all 25 in a moment, and letter frequencies also reveal the shift.
Common mistakes
- Thinking hashing is the same as encryption. A hash cannot be decrypted; it is a one-way fingerprint.
- Mixing up the keys: in public-key encryption you lock with the receiver's PUBLIC key, not your own private key.
- Forgetting the wrap-around in Caesar: after Z comes A again (mod 26).
- Believing a longer password alone stops all attacks. You also need safe storage (hashing) and ideally two-factor authentication.