Cryptography
Cryptography literature has a recurring cast of three. Alice sends the message. Bob receives it. Eve listens in, hoping to read what she was never meant to see. This small drama, repeated across textbooks and protocols, captures the whole field in three names. Cryptography is the practice and study of techniques for secure communication when an adversary is actively trying to intercept, alter, or impersonate. It is what keeps Eve from reading Alice's words.
The earliest known cryptography is carved into stone in Egypt, dated to around 1900 BCE. The newest worries about machines that do not yet fully exist, capable of cracking today's strongest keys in seconds. Between those two points lies a story of tattooed scalps, a wheel cipher invented by Thomas Jefferson, a British graduate student who took the US government to court, and an encryption chip that civil liberties advocates fought to kill. How did a craft once synonymous with simply scrambling letters become a discipline sitting at the intersection of mathematics, computer science, and physics? And why have governments classified it as a weapon?
Suetonius reports that Julius Caesar shifted each letter three positions down the alphabet to write to his generals, a method now called the Caesar cipher. The Hebrew Atbash is another early example. These are substitution ciphers, systematically replacing letters with others. Their cousins are transposition ciphers, which rearrange letter order rather than swap symbols. The Spartans are said to have used a transposition aid called the scytale, a rod for winding and reading a strip of text.
Herodotus preserved one of the strangest early tricks, not encryption but concealment. A message was tattooed onto a slave's shaved head, then hidden under the regrown hair. This is steganography, hiding the very existence of a message. Its modern descendants include invisible ink, microdots, and digital watermarks, along with music ciphers that disguise a secret inside ordinary sheet music.
The 2000-year-old Kama Sutra of Vatsyayana describes two ciphers, Kautiliyam and Mulavediya, one built on phonetic relations and the other on paired letters. Sassanid Persia, according to Ibn al-Nadim, kept two secret scripts, the King's script for official correspondence and another for messages to foreign countries. David Kahn, in The Codebreakers, credits the Arabs as the first to systematically document cryptanalysis. Al-Khalil, who lived from 717 to 786, wrote the Book of Cryptographic Messages, the first work to use permutations and combinations to list possible Arabic words.
Al-Kindi, the Arab mathematician and polymath, wrote Risalah fi Istikhraj al-Mu'amma, describing the first known use of frequency analysis. The insight is deceptively simple. Ciphertext leaks statistical fingerprints of the plaintext, since some letters appear far more often than others. Once an attacker counts frequencies, nearly every classical cipher falls apart. Those broken ciphers survive today mainly as puzzles.
Leon Battista Alberti, around 1467, offered the strongest answer to frequency analysis with the polyalphabetic cipher, which switches between multiple substitution alphabets within a single message. He also built what was probably the first automatic cipher device, a wheel realizing part of his idea. The Vigenere cipher applies the same principle using a key word to govern substitutions. Charles Babbage showed in the mid-19th century that the Vigenere cipher was vulnerable to what is now called Kasiski examination, though Friedrich Kasiski published it about ten years later.
Auguste Kerckhoffs stated a lasting principle in 1883. The secrecy of a cipher's algorithm is no real safeguard. A sound scheme must stay secure even when the adversary fully understands how it works, with the key as the only secret. Claude Shannon restated it more bluntly as Shannon's Maxim, "the enemy knows the system." Physical aids kept pace with this thinking, from Alberti's cipher disk to Johannes Trithemius' tabula recta and Thomas Jefferson's wheel cypher, which was reinvented independently by Bazeries around 1900.
Rotor machines arrived early in the 20th century, the most famous being the Enigma used by the German government and military from the late 1920s and through World War II. These better machine designs made cryptanalysis far harder after the First World War. Breaking them by hand proved both difficult and laborious, which pushed codebreakers toward machines of their own.
Bletchley Park in the United Kingdom drove that effort during the war, automating the repetitive grind of decryption. The result was Colossus, described as the world's first fully electronic, digital, programmable computer. It helped decrypt messages from the German Army's Lorenz SZ40/42 machine.
Claude Shannon, working at Bell Labs, supplied the theory the machines lacked. His 1948 paper founded information theory, and his 1949 paper turned cryptography, as one assessment put it, from an art to a science. For that he is called the founding father of modern cryptography. Shannon also proved something rare and absolute, that the one-time pad is unbreakable when its key is truly random, never reused, kept secret, and at least as long as the message itself.
June 1976 marks a dividing line. Until then, every publicly known encryption method shared one key between sender and receiver, the symmetric model. That model carries a heavy burden. Each pair of parties ideally needs its own key, and the number of keys grows as the square of the network's size, which quickly becomes unmanageable.
Whitfield Diffie and Martin Hellman broke that constraint in a groundbreaking 1976 paper, proposing public-key cryptography. Two mathematically related keys do the work, a public key anyone may distribute and a private key that stays secret. Deriving the private key from the public one is computationally infeasible. David Kahn called this the most revolutionary new concept in the field since polyalphabetic substitution emerged in the Renaissance. Diffie and Hellman could not build a full encryption system, but they delivered the Diffie-Hellman key exchange, letting two parties secretly agree on a shared key.
The race for a practical system ended in 1978, won by Ronald Rivest, Adi Shamir, and Len Adleman, whose answer became the RSA algorithm. RSA had appeared a year earlier in Martin Gardner's Scientific American column. A document published in 1997 by GCHQ, the British intelligence organization, revealed the idea had been anticipated in secret. James H. Ellis conceived asymmetric cryptography around 1970, Clifford Cocks invented something close to RSA in 1973, and Malcolm J. Williamson is credited with the Diffie-Hellman exchange in 1974.
IBM personnel in the early 1970s designed the Data Encryption Standard, which became the first US federal cryptography standard. The Advanced Encryption Standard later replaced it, though triple-DES, a more secure variant, stayed popular across ATMs, e-mail privacy, and secure remote access. Symmetric ciphers come in two forms, block ciphers that process fixed-size blocks and stream ciphers that combine a long key stream with the plaintext bit by bit. RC4 is a widely used stream cipher.
Cryptographic hash functions form a third family, taking input of any length and returning a short, fixed-length output that cannot be reversed to recover the original. A good one makes it infeasible to find two messages with the same hash. MD4 is broken, and MD5, its strengthened variant, is broken in practice as well. The US National Security Agency built the Secure Hash Algorithm series. SHA-0 was flawed and withdrawn, SHA-1 is more secure than MD5 but has known attacks, and SHA-2 was vulnerable to clashes as of 2011.
A competition was launched to select a new national standard called SHA-3. It ended on the 2nd of October 2012, when NIST announced that Keccak had won. These functions guard everyday systems. Operating systems store hashes of passwords rather than the passwords themselves, so when you log in the system hashes your input and compares it, and neither it nor an attacker ever holds the plaintext password.
Encryption was once designated auxiliary military equipment in the United States and placed on the Munitions List, making it illegal after the Second World War to sell or distribute the technology overseas. That collided with the open internet. When the source code for Philip Zimmermann's Pretty Good Privacy reached the internet in June 1991, a complaint from RSA Security triggered a criminal investigation of Zimmermann by the US Customs Service and the FBI, though no charges were filed.
Daniel J. Bernstein, then a graduate student at UC Berkeley, sued the US government, arguing that source code was protected speech. The 1995 case Bernstein v. United States produced a 1999 ruling that printed cryptographic source code is free speech under the Constitution. In 1996, thirty-nine countries signed the Wassenaar Arrangement, an arms control treaty covering dual-use technologies, and a major US relaxation in 2000 lifted most key-size limits on mass-market software.
Governments also pushed from the other direction. The 1993 Clipper chip, built around the classified Skipjack algorithm, included an escrow key the government would hold for wiretapping, violating Kerckhoffs's Principle and drawing fierce criticism. In 1998 President Bill Clinton signed the Digital Millennium Copyright Act, which criminalized tools for circumventing digital rights management and chilled cryptanalytic research. Dmitry Sklyarov was arrested visiting the US and jailed for five months over work that was legal in Russia. The struggle continues into the quantum era, where a single sufficiently powerful machine could reduce the effort to break the strongest RSA or elliptic-curve keys from millennia to seconds, which is why researchers are racing to build post-quantum cryptography before such machines arrive.
Continue Browsing
Common questions
What is cryptography and what is it used for?
Cryptography is the practice and study of techniques for secure communication in the presence of adversarial behavior. Its practical applications include electronic commerce, chip-based payment cards, digital currencies, computer passwords, and military communications.
What is the difference between symmetric and public-key cryptography?
Symmetric cryptography uses the same secret key to encrypt and decrypt a message, and was the only publicly known kind until June 1976. Public-key cryptography uses two mathematically related keys, a public key that can be freely distributed and a private key that stays secret.
Who invented public-key cryptography and the RSA algorithm?
Whitfield Diffie and Martin Hellman proposed public-key cryptography in a groundbreaking 1976 paper, including the Diffie-Hellman key exchange. The RSA algorithm was developed in 1978 by Ronald Rivest, Adi Shamir, and Len Adleman, though GCHQ cryptographers including James H. Ellis and Clifford Cocks had anticipated these ideas in secret around 1970 to 1974.
What is the only cipher proven to be unbreakable?
The one-time pad is the only theoretically unbreakable cipher, proven so by Claude Shannon. It holds only when the key material is truly random, never reused, kept secret from all attackers, and of equal or greater length than the message.
What is frequency analysis in cryptography?
Frequency analysis is a cryptanalytic technique that breaks classical ciphers by using the statistical fingerprints that ciphertext reveals about plaintext. The Arab mathematician Al-Kindi described the first known use of it in his work Risalah fi Istikhraj al-Mu'amma.
Why is cryptography treated as a legal and national security issue?
Cryptography's potential as a tool for espionage and sedition has led many governments to classify it as a weapon and limit or prohibit its use and export. In the United States it was once placed on the Munitions List, and the 1999 Bernstein v. United States ruling held that printed cryptographic source code is protected free speech.
How does quantum computing threaten current cryptography?
Estimates suggest a quantum computer could reduce the effort to break today's strongest RSA or elliptic-curve keys from millennia to mere seconds, rendering protocols such as TLS that rely on those keys insecure. Researchers are developing post-quantum cryptography whose security rests on problems believed to remain hard for both classical and quantum computers.
All sources
90 references cited across the entry
- 1BookA Greek-English LexiconHenry George Liddell et al. — Oxford University Press — 1984
- 2BookHandbook of Theoretical Computer ScienceRonald L. Rivest — Elsevier — 1990
- 3BookIntroduction to Modern CryptographyMihir Bellare et al. — 21 September 2005
- 4Book2013 International Conference on Electrical Communication, Computer, Power, and Control Engineering (ICECCPCE)Sattar B. Sadkhan — Dec 2013
- 5BookHandbook of Applied CryptographyA.J. Menezes et al. — Taylor & Francis — 1997
- 6BookCodes: An introduction to Information Communication and CryptographyNorman Biggs — Springer — 2008
- 7The undercover war on your internet secrets: How online surveillance cracked our trust in the webSteve Ranger — TechRepublic — 24 March 2015
- 8JournalThe Code for Gold: Edgar Allan Poe and CryptographyTerence Whalen — University of California Press — 1994
- 9BookThe Cryptographic Imagination: Secret Writing from Edgar Poe to the InternetShawn Rosenheim — Johns Hopkins University Press — 1997
- 11Book2011 IEEE International Conference on Technologies for Homeland Security (HST)M.S. Sharbaf — 2011-11-01
- 13Cryptology (definition)Merriam-Webster
- 14What's a Cryptologic Linguist?Military.com — 2021-05-13
- 15BookLinguistics in a Systemic PerspectiveJohn Benjamins Publishing Company — January 1988
- 16JournalVt hkskdkxt: Early Medieval Cryptography, Textual Errors, and Scribal AgencyBenjamin A. Saltzman — 2018-10-01
- 17BookIntroduction to Modern CryptographyJonathan Katz et al. — Chapman and Hall — 2014
- 18BookCryptography: an introductionV.V. I︠A︡shchenko — AMS Bookstore — 2002
- 19BookThe CodebreakersDavid Kahn — 1967
- 20CODES – Encyclopaedia Iranicaelectricpulp.com
- 21BookThe Codebreakers: The Comprehensive History of Secret Communication from Ancient Times to the InternetDavid Kahn — Simon and Schuster — 1996
- 22JournalAn Account of Early Statistical Inference in Arab CryptologyLyle D. Broemeling — 1 November 2011
- 23BookCryptography Exam Study Essentials - A Comprehensive Guide to Cryptography Concepts for ExamsCybellium Ltd — 2024
- 24BookThe Code BookSimon Singh — Anchor Books — 2000
- 25JournalThe origins of cryptology: The Arab contributionsIbrahim A. Al-Kadi — April 1992
- 26JournalBreaking Short Vigenère CiphersTobias Schrödel — October 2008
- 27BookA History of US: War, Peace and all that JazzJoy Hakim — Oxford University Press — 1995
- 28BookStealing Secrets, Telling Lies: How Spies and Codebreakers Helped Shape the Twentieth CenturyJames Gannon — Brassey's — 2001
- 29The Legacy of DES – Schneier on Security6 October 2004
- 30BookThe Code Book: The Science of Secrecy From Ancient Egypt To Quantum CryptographySimon Singh — Anchor Books — 1999
- 31Minimal key lengths for symmetric ciphers to provide adequate commercial securityMatt Blaze et al. — Fortify — January 1996
- 32BookCryptography: A Very Short IntroductionF. C. Piper et al. — Oxford University Press — 2002
- 33BookAn Introduction to Mathematical CryptographyJeffrey Hoffstein et al. — Springer — 2014
- 34BookA Brief History of ComputingGerard O'Regan — Springer — 2008
- 35BookModern Cryptography Volume 1: A Classical Introduction to Informational and Mathematical PrincipleZhiyong Zheng — Springer Singapore — 2022
- 36BookCryptography, Information Theory, and Error-Correction: A Handbook for the 21st CenturyAiden A. Bruen et al. — Wiley-Interscience — 2005
- 37JournalNew directions in cryptographyW. Diffie et al. — 1 September 2006
- 38JournalPost-quantum cryptographyDaniel J. Bernstein et al. — September 14, 2017
- 39JournalNew Directions in CryptographyWhitfield Diffie et al. — November 1976
- 40FIPS PUB 197: The official Advanced Encryption StandardNational Institute of Standards and Technology
- 41NCUA letter to credit unionsJuly 2004
- 42SSHPawel Golen — 19 July 2002
- 43BookApplied CryptographyBruce Schneier — Wiley — 1996
- 44BookUnderstanding cryptography : a textbook for students and practitionersChristof Paar — Springer — 2009
- 46JournalNIST Selects Winner of Secure Hash Algorithm (SHA-3) CompetitionNational Institute of Standards and Technology — October 2, 2012
- 47BookProceedings of the June 7-10, 1976, national computer conference and exposition on - AFIPS '76Whitfield Diffie et al. — 8 June 1976
- 48JournalCryptology Goes PublicDavid Kahn — Fall 1979
- 50JournalA Method for Obtaining Digital Signatures and Public-Key CryptosystemsRonald L. Rivest et al. — 1978
- 51NewsBritish Document Outlines Early Encryption DiscoveryPeter Wayner — 24 December 1997
- 52JournalA Note on 'Non-Secret Encryption'Clifford Cocks — 20 November 1973
- 53BookThe Code BookSimon Singh — Doubleday — 1999
- 54JournalComparison Research on Digital Signature Algorithms in Mobile Web ServicesZuguang Xuan et al. — 2009
- 55BookThe Mathematical Theory of CommunicationClaude Shannon et al. — 1949
- 57BookSelected Areas in CryptographyPascal Junod — 2001
- 59BookAdvances in Cryptology – CRYPTO' 93S. Brands — 1994
- 60BookProceedings of the seventeenth annual ACM symposium on Theory of computing – STOC '85László Babai — 1985
- 61JournalThe Knowledge Complexity of Interactive Proof SystemsS. Goldwasser et al. — 1989
- 62Book1979 International Workshop on Managing Requirements Knowledge (MARK)G. Blakley — June 1979
- 63JournalHow to share a secretA. Shamir — 1979
- 64Book2020 16th International Conference on Network and Service Management (CNSM)Nilupulee A. Gunathilake et al. — IEEE — 2020-11-02
- 65JournalLightweight Cryptography Algorithms for Resource-Constrained IoT Devices: A Review, Comparison and Research OpportunitiesVishal A. Thakor et al. — 2021
- 662.4 – Applications of CryptographyFred Cohen — 1995
- 68Applications of Cryptography UCL Risky BusinessAustin Chamberlain — 12 March 2017
- 69Cryptography use cases: From secure communication to data security17 January 2024
- 70Prepping For Post-Quantum Cryptography16 April 2024
- 71Overview per countryFebruary 2013
- 726.5.1 What Are the Cryptographic Policies of Some Countries?RSA Laboratories
- 73NewsCryptography & SpeechJonathan Rosenoer — 1995
- 74Case Closed on Zimmermann PGP Investigation14 February 1996
- 75BookCrypto: How the Code Rebels Beat the Government – Saving Privacy in the Digital AgeSteven Levy — Penguin Books — 2001
- 76Bernstein v USDOJUnited States Court of Appeals for the Ninth Circuit — 6 May 1999
- 79The Data Encryption Standard (DES)Bruce Schneier — 15 June 2000
- 80JournalThe Data Encryption Standard (DES) and its strength against attacksD. Coppersmith — May 1994
- 81JournalDifferential cryptanalysis of DES-like cryptosystemsE. Biham et al. — 1991
- 83Censorship in action: why I don't publish my HDCP resultsNiels Ferguson — 15 August 2001
- 84Arrest of Computer Researcher Is Arrest of First Amendment RightsBruce Schneier — InternetWeek — 2001-08-06
- 85Digg users revolt over AACS keyCory Doctorow — 2 May 2007
- 86UK Data Encryption Disclosure Law Takes Effect1 October 2007
- 87Two convicted for refusal to decrypt dataChristopher Williams — 11 August 2009
- 88UK jails schizophrenic for refusal to decrypt filesChristopher Williams — 24 November 2009
- 89NewsPassword case reframes Fifth Amendment rights in context of digital worldJohn Ingold — January 4, 2012
- 90US court test for rights not to hand over crypto keysJohn Leyden — 13 July 2011
- 91Order Granting Application under the All Writs Act Requiring Defendant Fricosu to Assist in the Execution of Previously Issued Search WarrantsUnited States District Court for the District of Colorado