Encryption: Symmetric, Asymmetric, Certificates and PKI
Encryption shields data by converting plaintext to ciphertext using a key. Symmetric key cryptography uses one shared key (fast but sharing is hard); asymmetric cryptography uses public/private key pairs that scale and enable digital certificates via a certificate authority (CA) and public key infrastructure (PKI).
How this supports CIPP/US study
Use this lesson to identify the legal source, actor, data and activity before applying a rule to a scenario. Continue with the CIPP/US study guide.
Encryption converts plaintext to ciphertext and is reversed with a key. Shielding can be encryption in transit (against 'man in the middle' attacks), at rest (a stolen encrypted hard drive stays secure - and under most data breach laws encryption at rest creates an exception from the duty to report a breach), or in use.
| Approach | Keys | Trade-off |
|---|---|---|
| Symmetric key cryptography | One shared key to encrypt and decrypt | Fast and short, but Alice must securely share the key with Bob |
| Asymmetric cryptography | Public + private key pair per user | Scalable - encrypt with the recipient's public key; basis for digital certificates |
A certificate authority (CA) validates identity and issues a digitally signed certificate linking a person to a public key. Public key infrastructure (PKI) is the broader system of policies, standards, people, and systems supporting key distribution and identity validation.
Key terms - quick answers
What is “Encryption”?
What is “Plaintext”?
What is “Ciphertext”?
What is “Key”?
Sources and study method
This independent lesson uses active recall, spaced retrieval and scenario practice. Read the full study method.