Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Network Basics and Security
Cryptography, Encryption and Digital Signatures Explained
Updated 11 October 2026 · Fact-checked
Cryptography protects data using mathematics. Encryption hides data using a key. Symmetric encryption uses one shared key; asymmetric uses a public and private key pair. Hashing creates a fixed-length fingerprint that cannot be reversed. A digital signature is a hash encrypted with the sender's private key, giving authenticity, integrity and non-repudiation.
Understand Cryptography, Encryption and Digital Signatures
Cryptography is the science of keeping information secure when it travels or sits in storage. It aims at four things: confidentiality (only the right people read it), integrity (it is not altered), authentication (you know who sent it) and non-repudiation (the sender cannot deny sending it).
Encryption converts readable data (plaintext) into unreadable data (ciphertext) using an algorithm and a key. Decryption reverses it. Security rests on keeping the key secret, not the algorithm.
In symmetric encryption, the same key encrypts and decrypts. It is fast and suits large data. The weakness is key distribution: both parties must share the key safely. AES and DES are common examples. In asymmetric encryption, two linked keys are used: a public key, shared openly, and a private key, kept secret. Data encrypted with the public key can be decrypted only with the matching private key. It is slower, but solves key distribution. RSA is the standard example. In practice, systems such as HTTPS use asymmetric encryption to exchange a session key, then symmetric encryption for the bulk data.
Hashing is different. A hash function turns any input into a fixed-length output (the hash or digest). It is one-way: you cannot recover the input. A small change in the input gives a very different hash. Hashing checks integrity and stores passwords. It uses no key to reverse, so it is not encryption.
A digital signature works by hashing the message and encrypting that hash with the sender's private key. The receiver decrypts the signature with the sender's public key and compares it with a fresh hash of the message. A match proves the sender and that the message is unchanged. A digital certificate issued by a trusted Certifying Authority binds a public key to a named person or entity. PKI (Public Key Infrastructure) is the whole system of CAs, certificates, keys and policies that makes this trustworthy. In India, the Information Technology Act, 2000 gives legal recognition to digital signatures and provides for Certifying Authorities.
Key rules to remember
- Symmetric encryption
- Ciphertext = Encrypt(Plaintext, K); Plaintext = Decrypt(Ciphertext, K)
- Same key K at both ends. Fast. Key sharing is the problem.
- Asymmetric encryption for confidentiality
- Sender encrypts with receiver's public key; receiver decrypts with receiver's private key
- Only the receiver can read the message.
- Digital signature creation
- Signature = Encrypt(Hash(Message), Sender's private key)
- Gives authenticity, integrity and non-repudiation. It does not hide the message.
- Digital signature verification
- Decrypt(Signature, Sender's public key) = Hash(Message received) ⇒ valid
- Any mismatch means the message or signature was altered or the signer is different.
- Hashing vs encryption
- Hash: one-way, no key to reverse, fixed length. Encryption: two-way, key needed, output size varies with input
- Use this as your comparison line.
- Digital certificate contents
- Certificate = Holder's name + Public key + Validity period + CA's digital signature
- The CA's signature lets others trust the binding.
How to solve Cryptography, Encryption and Digital Signatures questions
Use this method for definition, comparison, process and scenario questions on cryptography.
- 1Identify the security goal in the question: confidentiality, integrity, authentication or non-repudiation.
- 2Name the tool that meets the goal: encryption, hashing, digital signature or certificate.
- 3Define the tool in one or two lines, with its key feature (one key, two keys, one-way).
- 4State how it works as a short sequence of steps, showing which key is used by whom.
- 5Compare with the nearest alternative if asked, using a point-wise difference.
- 6Apply to the facts given, for example a company sending a board resolution or filing online.
- 7Link to the legal position: digital signature recognition and Certifying Authorities under the Information Technology Act, 2000, only in terms you are sure of.
- 8Conclude by stating which goal is met and any limitation.
Quickest way: Goal-to-tool mapping
When to use it: When time is short and the question asks which technique to use or what a technique achieves.
- Secrecy needed: encryption (symmetric for bulk data, asymmetric for key exchange).
- Tamper check needed: hash.
- Proof of sender and no denial: digital signature.
- Proof that a public key belongs to a person: digital certificate from a CA.
- Whole trust system: PKI.
- Write one line on the key used by sender and receiver; this earns most of the marks.
Common mistakes in Cryptography, Encryption and Digital Signatures
Saying hashing is a type of encryption.
Both scramble data, so they look alike.
Fix: State that hashing is one-way and keyless in reversal terms; encryption can be reversed with the key.
Saying a digital signature encrypts the message for secrecy.
Students confuse signing with encrypting.
Fix: A signature uses the private key on the hash for authenticity. Confidentiality needs separate encryption with the receiver's public key.
Mixing up which key is used. Writing that the sender signs with the receiver's public key.
Two key pairs and two purposes get blended.
Fix: Signing: sender's private key. Verifying: sender's public key. Confidential sending: receiver's public key, receiver's private key to open.
Calling asymmetric encryption always better than symmetric.
It sounds more advanced.
Fix: Say asymmetric is slower but solves key distribution; symmetric is faster for bulk data. Real systems combine both.
Ignoring the role of the Certifying Authority.
Students stop at the key pair.
Fix: Explain that a certificate signed by a trusted CA ties a public key to an identity, which PKI manages.
Giving only definitions in a case-based question.
Students recall notes instead of analysing facts.
Fix: Follow provision, analysis, conclusion: name the tool, apply it to the facts, then conclude.
Worked examples
Example 1
Distinguish between symmetric and asymmetric encryption. Which would a company use to send a large confidential file to a vendor it has never dealt with before?
Show the solution
- Symmetric uses one shared secret key for encryption and decryption; asymmetric uses a public and private key pair.
- Symmetric is fast and suits large data, but key sharing is risky. Asymmetric is slower but needs no prior secret sharing.
- Facts: the file is large and the vendor is new, so no shared key exists.
- Asymmetric alone is slow for a large file; symmetric alone has no safe way to deliver the key.
- Best approach: generate a symmetric session key, encrypt the file with it, then encrypt that session key with the vendor's public key and send both.
- The vendor decrypts the session key with its private key and then opens the file.
Answer: The company should use a hybrid approach: symmetric encryption for the file and asymmetric encryption to deliver the session key to the vendor.
Example 2
Mehta Textiles Ltd's finance head emails a signed payment instruction to the bank. Explain how a digital signature lets the bank trust it, and what happens if a clerk changes the amount in transit.
Show the solution
- The finance head's software computes a hash of the instruction.
- The hash is encrypted with the finance head's private key; this is the digital signature, attached to the message.
- The bank decrypts the signature with the finance head's public key, obtaining the original hash. A certificate from a Certifying Authority confirms the public key belongs to the finance head.
- The bank computes a fresh hash of the received instruction and compares both hashes.
- If the amount was changed, the new hash differs from the decrypted one, so verification fails.
- If the hashes match, the bank knows who sent it (authenticity), that it is unaltered (integrity), and the sender cannot later deny it (non-repudiation).
Answer: The bank trusts the instruction because the hashes match. A changed amount makes verification fail, so the bank rejects the instruction.
Exam tips
- Write the key used at each step. Examiners look for sender's private key and sender's public key correctly placed.
- Use point-wise comparison for symmetric vs asymmetric and hashing vs encryption; four to five points are enough.
- Always mention the three assurances of a digital signature: authenticity, integrity, non-repudiation.
- In scenario questions, name the goal first, then the tool, then conclude. Do not stop at definitions.
- Mention the Certifying Authority and PKI whenever a question involves trust in a public key.
Practice questions from Network Basics and Security
- Mehta Textiles has offices in Surat, Chennai and Kolkata, linked through leased lines and the public internet so that all branches access a …
- Which statement best describes how a digital signature on an electronic document is created and verified under the usual asymmetric scheme r…
- A company wants a security control that sits between its internal network and the internet and permits or blocks traffic based on a predefin…
- A director receives a PDF of minutes bearing a valid digital signature from the Chairman. Later, one word in the PDF is altered by an unknow…
- In a client-server network of a Mumbai firm, a central machine stores the company's files, authenticates users and serves requests from empl…
Cryptography, Encryption and Digital Signatures: frequently asked questions
What is the difference between symmetric and asymmetric encryption?
Symmetric encryption uses one shared key for both encryption and decryption and is fast. Asymmetric encryption uses a public and private key pair and is slower but avoids sharing a secret key in advance.
How does a digital signature work?
The sender hashes the message and encrypts the hash with the private key. The receiver decrypts it with the sender's public key and compares it with a new hash of the message. A match proves origin and integrity.
What is PKI and a digital certificate?
A digital certificate links a public key to a person or entity and is signed by a Certifying Authority. PKI is the framework of CAs, certificates, keys and rules that manages this trust.
What is the difference between hashing and encryption?
Encryption is reversible with the right key and protects confidentiality. Hashing is one-way, gives a fixed-length output and is used to check integrity or store passwords.