October 1, 2026
Cryptography: How Encryption and Hashing Protect the Digital World
By Zahid Ali Cybersecurity Education

By Zahid (Cybersecurity Student)
8 min read
Every day, billions of messages, passwords, financial transactions, documents, and personal records move across digital networks.
When we log in to a website, use online banking, send a private message, connect to a remote server, or download a file, our information passes through different systems.
So, an important question is:
How do we stop attackers from reading, changing, or impersonating that information?
One of the fundamental answers is cryptography.
Cryptography uses mathematics, algorithms, and keys to protect information and establish trust in digital systems.
What Is Cryptography?
Cryptography is the practice of protecting information using mathematical techniques, algorithms, and cryptographic keys.
It helps provide important security properties such as:
Confidentiality
Confidentiality means that information should only be readable by authorized people or systems.
Encryption helps provide confidentiality by transforming readable data into protected ciphertext.
Integrity
Integrity means that information has not been changed without authorization.
Cryptographic hashes, MACs, and digital signatures can help detect unauthorized changes.
Authenticity
Authenticity helps verify that a person, device, server, or message is genuine.
Digital certificates and digital signatures are examples of cryptographic mechanisms used to establish authenticity.
In simple words:
Cryptography helps protect information, detect changes, and establish trust in digital communication.
Plaintext, Ciphertext, and Keys
Before understanding encryption, we need to know a few basic terms.
Plaintext
Plaintext is the original readable information.
For example:
HELLO WORLD
It could also be a password, document, image, database record, or financial transaction.
Ciphertext
Ciphertext is the protected output produced by encryption.
A simplified example might look like:
7#Q9-X2@P-4L
Without the required key, an attacker should not be able to practically recover the original plaintext.
Cryptographic Key
A cryptographic key is a value used by a cryptographic algorithm.
Depending on the system, keys can be:
- Shared secret keys
- Public keys
- Private keys
- Session keys
- Password-derived keys
A strong algorithm can still be insecure if its keys are generated poorly, exposed, or stored incorrectly.
Encryption and Decryption
Encryption transforms plaintext into ciphertext.
Encryption:
Plaintext + Algorithm + Key β Ciphertext
Decryption reverses the process:
Ciphertext + Correct Key β Plaintext
The goal of modern encryption is to make unauthorized recovery of the plaintext computationally impractical.
There are two major types of encryption:
- Symmetric encryption
- Asymmetric cryptography
Hashing is different from both and is mainly used for integrity and verification.
1. Symmetric Encryption
Symmetric encryption uses one shared secret key.
The same secret key is used to encrypt and decrypt the data.
Plaintext + Shared Key β Ciphertext
Ciphertext + Same Key β PlaintextPlaintext + Shared Key β Ciphertext
Ciphertext + Same Key β PlaintextA simple way to remember it is:
One key locks the information, and the same key unlocks it.
Why Is Symmetric Encryption Useful?
Symmetric encryption is generally fast and efficient, making it suitable for protecting large amounts of data.
It is commonly used for:
- Disk encryption
- Database encryption
- File encryption
- VPN traffic
- Network sessions
- Large data transfers
AES
AES (Advanced Encryption Standard) is one of the most widely used symmetric encryption algorithms.
AES supports:
- 128-bit keys
- 192-bit keys
- 256-bit keys
Older algorithms such as DES are no longer suitable for modern security, and 3DES has also been retired from modern cryptographic use.
The Key Distribution Problem
The main challenge with symmetric encryption is:
How can two parties securely obtain the same secret key?
If an attacker obtains the secret key, the attacker may be able to decrypt protected information.
This is one reason public-key cryptography is important.
2. Asymmetric Cryptography
Asymmetric cryptography uses a pair of mathematically related keys:
- Public key
- Private key
The public key can normally be shared openly.
The private key must be protected.
For confidentiality, a simplified example is:
Plaintext + Receiver's Public Key β Ciphertext
Ciphertext + Receiver's Private Key β Plaintext
The receiver does not need to send the private key to the sender.
Public-Key Cryptography Is More Than Encryption
Asymmetric cryptography is also important for:
- Digital signatures
- Authentication
- Key establishment
- Digital certificates
Common technologies include:
RSA
RSA is a well-known public-key cryptographic algorithm. Its security is based on mathematical problems involving large numbers, particularly integer factorization.
ECC
Elliptic Curve Cryptography (ECC) provides strong security with relatively small key sizes compared with traditional RSA configurations.
Diffie-Hellman
Diffie-Hellman is primarily a key-agreement method. It allows two parties to establish shared secret material over an untrusted network.
Why Modern Systems Combine Symmetric and Asymmetric Cryptography
You might wonder:
If asymmetric cryptography is useful, why not use it for everything?
Because asymmetric operations are generally more computationally expensive than symmetric encryption.
Modern protocols therefore often combine both approaches.
For example, in a simplified HTTPS/TLS connection:
- The browser connects to the website.
- The server provides a digital certificate.
- The browser validates the certificate.
- The TLS protocol authenticates the server and establishes shared secret material, commonly using ephemeral Diffie-Hellman methods.
- Symmetric session keys are derived.
- Symmetric authenticated encryption protects the application traffic.
This is a hybrid cryptographic approach.
In simple words:
Asymmetric cryptography helps establish trust and shared secrets, while symmetric cryptography efficiently protects the actual communication.
Digital Certificates
A public key by itself does not prove who owns it.
Imagine connecting to your bank's website and receiving a public key from an attacker pretending to be the bank.
How does your browser know which key belongs to the real website?
This is where digital certificates come in.
A certificate can contain information such as:
- Domain information
- Public-key information
- Validity period
- Certificate authority information
- Digital signatures
Browsers and operating systems use trusted Certificate Authorities (CAs) and certificate-validation rules to help determine whether a certificate can be trusted.
This is an important part of the trust model behind HTTPS.
3. Cryptographic Hashing
Hashing is different from encryption.
A cryptographic hash function takes input data and produces a fixed-length output called a hash or digest.
Input Data β Hash Function β Hash ValueInput Data β Hash Function β Hash ValueFor example:
File β SHA-256 β Hash Digest
Hashing Is Designed to Be One-Way
Encryption is designed to be reversible when the correct key is available.
Cryptographic hashing is designed so that recovering the original input from the hash is computationally infeasible for a secure hash function.
Important properties include:
- Deterministic: the same input produces the same hash.
- Fixed length: the output has a defined size.
- Avalanche effect: a small input change should cause a major output change.
- Preimage resistance: finding an input from a given hash should be computationally infeasible.
- Collision resistance: finding two different inputs with the same hash should be computationally infeasible.
Common cryptographic hash functions include:
- SHA-256
- SHA-3
Hashing in File Integrity
Suppose a software developer publishes the SHA-256 hash of a file.
You download the file and calculate its hash.
Published Hash: ABC123...
Downloaded Hash: ABC123...Published Hash: ABC123...
Downloaded Hash: ABC123...If the values match, the file is consistent with the published digest.
If they do not match, something may have changed.
The file could be:
- Corrupted
- Incomplete
- Modified
- Replaced
However, the hash itself must come from a trusted source. An attacker who can replace both the file and its published hash could defeat a simple hash comparison.
Password Hashing
Passwords should not be stored as plaintext.
A secure password-storage system uses a password-hashing function designed to make large-scale guessing expensive.
Common choices include:
- Argon2
- bcrypt
- scrypt
- PBKDF2
A password-hashing system should also use a unique salt for each password.
For example:
Password + Unique Salt
β
Password Hashing Function
β
Stored Password HashPassword + Unique Salt
β
Password Hashing Function
β
Stored Password HashUsing raw SHA-256 alone for password storage is not recommended because general-purpose hash functions are designed to be fast, while password-hashing algorithms are intentionally designed to make guessing more expensive.
This distinction is extremely important in cybersecurity.
Symmetric vs Asymmetric vs Hashing
MethodMain IdeaReversible?Common UseSymmetric EncryptionOne shared secret keyYesProtecting large amounts of dataAsymmetric CryptographyPublic + private keyDepends on operationAuthentication, signatures, key establishmentHashingFixed-length digestNoIntegrity, verification, password storage
These technologies are not replacements for one another.
A modern application may use all three.
For example:
Asymmetric cryptography β authentication/key establishment
Symmetric encryption β protects the communication
Hashing β integrity and verification
Digital Signatures
Digital signatures use asymmetric cryptography to provide authenticity and integrity.
A simplified process is:
- The sender calculates a hash of the message.
- The sender creates a digital signature using a private key.
- The receiver receives the message and signature.
- The receiver verifies the signature using the corresponding public key.
- The receiver checks the message integrity.
If verification succeeds, the receiver has cryptographic evidence that the signature corresponds to the message and the associated private key.
Digital signatures are widely used for:
- Software and code signing
- Digital certificates
- Electronic documents
- Secure communications
- Software updates
Common Cryptography Mistakes
Even strong algorithms can become insecure when implemented incorrectly.
Some common mistakes include:
1. Exposing Private Keys
A stolen private key can allow attackers to impersonate the key owner or compromise protected systems, depending on how the key is used.
2. Using Obsolete Algorithms
Old algorithms or insufficient key sizes may no longer provide adequate security.
3. Disabling Certificate Validation
Encryption without proper authentication can leave users vulnerable to impersonation attacks.
4. Generating Predictable Keys
Cryptographic keys require secure random-number generation.
5. Storing Plaintext Passwords
A database breach could immediately expose users' passwords.
6. Using Raw Hashes for Passwords
Fast general-purpose hashes make password guessing much easier than specialized password-hashing algorithms.
7. Creating Custom Cryptography
Designing your own cryptographic algorithm is risky. Established, publicly reviewed algorithms and well-tested libraries should normally be used instead.
8. Ignoring Endpoint Security
Even strong encryption cannot fully protect plaintext after legitimate decryption on a compromised device.
A Short History of Cryptography
Cryptography existed long before computers.
One famous example is the Caesar cipher, which shifts letters by a fixed number of positions.
With a shift of three:
A β D
B β E
C β FA β D
B β E
C β FTherefore:
HELLO β KHOORHELLO β KHOORThe Caesar cipher is useful for understanding basic encryption concepts, but it is not secure for modern communication because there are very few possible shifts.
Other historical cryptographic systems include the:
- Vigenère cipher
- Enigma machine
- One-time pad
- Mechanical rotor systems
Modern cryptography is much more advanced and relies heavily on mathematics and computer science.
The Mathematics Behind Cryptography
Cryptography uses many areas of mathematics.
Two simple concepts beginners may encounter are XOR and modular arithmetic.
XOR
XOR means exclusive OR.
0 XOR 0 = 0
0 XOR 1 = 1
1 XOR 0 = 1
1 XOR 1 = 00 XOR 0 = 0
0 XOR 1 = 1
1 XOR 0 = 1
1 XOR 1 = 0One useful property is:
A XOR A = 0A XOR A = 0XOR appears in many cryptographic and computer-security operations, although real encryption algorithms are far more complex than simply XORing plaintext with a key.
Modulo
Modulo gives the remainder after division.
25 mod 5 = 0
23 mod 6 = 5
23 mod 7 = 225 mod 5 = 0
23 mod 6 = 5
23 mod 7 = 2Modular arithmetic is an important part of many cryptographic algorithms and protocols.
The Future of Cryptography
Cryptography continues to evolve as technology changes.
One important area is post-quantum cryptography (PQC).
Large-scale quantum computers could threaten some public-key cryptographic systems currently in use. Researchers and standards organizations are therefore developing and deploying algorithms designed to resist quantum attacks.
Other important areas include:
- Hardware-backed key protection
- Confidential computing
- Zero-knowledge proofs
- Secure multi-party computation
- Privacy-preserving technologies
- Modern identity systems
- Automated certificate management
- Cryptographic agility
Cryptographic agility means designing systems so cryptographic algorithms and keys can be replaced when security requirements change.
Final Thoughts
Cryptography is one of the foundations of modern cybersecurity.
The key concepts to remember are:
Plaintext β Original readable information
Ciphertext β Protected encrypted information
Key β Value used by a cryptographic operation
Symmetric encryption β Uses a shared secret key
Asymmetric cryptography β Uses public and private keys
Hashing β Produces a one-way digest for integrity and verification
Modern systems combine these technologies rather than relying on only one.
When we browse an HTTPS website, connect to a server through SSH, use online banking, download software, or send protected information, cryptography is working behind the scenes.
We may not see it, but it is one of the technologies that makes the digital world possible.
About the Author
Zahid Ali is a cybersecurity learner interested in cryptography, ethical hacking, penetration testing, web security, and secure digital communication.
What cybersecurity topic should I explain next β AES, RSA, SHA-256, Digital Signatures, or HTTPS?
#Cryptography #Cybersecurity #Encryption #Hashing #AES #RSA #SHA256 #NetworkSecurity #InformationSecurity #EthicalHacking #CybersecurityEducation