Syllabus & Goals 3 min
Cambridge 2.3 · Symmetric and asymmetric encryption Paper 1 · Computer Systems
By the end of this lesson you can:
- Explain the purpose of encryption, using the terms plaintext and ciphertext.
- Describe symmetric encryption and its key-distribution weakness, and apply a shift key.
- Describe asymmetric encryption: who makes, shares and keeps the public and private keys.
Textbook: Chapter 2, §2.3.1–2.3.2 (pp. 63–67) — the purpose of encryption; symmetric and asymmetric encryption.
Recap / Warm-Up 5 min
Lessons 3 and 4 made sure data arrives correctly. This lesson makes sure only the right person can read it.
Quick starter
Does an error-detection method such as a checksum stop a hacker from reading the data? Why or why not?
Reveal the answer
No. A checksum only shows whether data changed. The data itself is still readable by anyone who intercepts it. Keeping it secret needs encryption.
Key Concept 14 min
1 · The purpose of encryption
Data sent over any public network, wired or wireless, can be intercepted. A hacker who does this is called an eavesdropper. Encryption turns data into a form that makes no sense to anyone it is not meant for.
2 · Symmetric encryption
Symmetric encryption uses one key. The same key encrypts and decrypts the message. A simple example is a shift key: each digit of the key says how many places to move a letter along the alphabet. To decrypt, shift back by the same amounts.
A 10-digit denary key gives 1010 possible keys. A modern computer could try them all in seconds. So real systems use 256-bit binary keys: 2256 ≈ 1.2 × 1077 possible keys. (Even this may not be enough once quantum computers arrive.)

3 · Asymmetric encryption
Asymmetric encryption was developed to solve the key problem. It uses two keys that form a matching pair:
Public key
Made available to everybody. Used by senders to encrypt messages to the key's owner.
Private key
Known only to its owner's computer. The only key that can decrypt what the matching public key encrypted.
The two keys are mathematically linked, but one cannot be worked out from the other. So sending the public key openly gives nothing useful away.
Alex can give her public key to any number of people. They can all send her encrypted documents, and only she can read them:
Worked Example 12 min
(a) Encrypt with a symmetric shift key
Question: encrypt MEET AT NOON with the key 2 7 1 8 2 8. Each key digit shifts one letter forward; the key repeats; spaces are left alone.
| Plaintext | M | E | E | T | A | T | N | O | O | N |
|---|---|---|---|---|---|---|---|---|---|---|
| Shift (key) | +2 | +7 | +1 | +8 | +2 | +8 | +2 | +7 | +1 | +8 |
| Ciphertext | O | L | F | B | C | B | P | V | P | V |
- Line the key up under the letters: M+2, E+7, E+1, T+8, A+2, T+8, then the key restarts: N+2, O+7, O+1, N+8.the key is shorter than the message, so it repeats from its first digit.
- Count forward along the alphabet: M → N, O, so M+2 = O. E+7 = L.
- Wrap past Z back to A: T+8 goes U, V, W, X, Y, Z, A, B.the alphabet is treated as a circle.
- Result: OLFB CB PVPV. Note that E became both L and F, and O became both V and P.a multi-digit key hides letter patterns better than a single shift.
- Alex decrypts with the same key, shifting back: O−2 = M, L−7 = E, and so on.one key for both jobs — that is what makes it symmetric.
(b) Set up two-way asymmetric messaging
Question: Sam and Alex want to send each other confidential files. Describe the keys each needs and how they are used.
- Alex generates a matching key pair: Alex-public and Alex-private. Sam does the same: Sam-public, Sam-private.each receiver needs their own private key.
- They swap public keys only. Each keeps their private key on their own computer.
- Sam → Alex: Sam encrypts with Alex-public; Alex decrypts with Alex-private.
- Alex → Sam: Alex encrypts with Sam-public; Sam decrypts with Sam-private.you always encrypt with the public key of the person who will read it.
- Scaling up: for 5 colleagues all talking securely, 5 key pairs are needed. Each person sends their public key to the other 4, so 5 × 4 = 20 public-key transfers — and not one private key moves.
How marks are earned: each person generates a public/private key pair (1) · public keys are exchanged (1) · the sender encrypts with the receiver's public key (1) · the receiver decrypts with their own private key (1).
Try It Yourself 12 min
Goal: encrypt CODE with the symmetric shift key 2. Then state which key is needed to decrypt it.
Goal: encrypt WAVE HELLO with the repeating key 4 1 3 (spaces left alone). Watch for the wrap past Z.
Goal: an eavesdropper has copied Alex's public key and the ciphertext Sam sent. Explain why the eavesdropper still cannot read the file — and explain what would go wrong if Sam and Alex were using symmetric encryption instead.
Hint
Which key decrypts, and has it ever left Alex's computer? In symmetric encryption, how many keys are there, and did that key have to travel?
📝 Exam Practice 10 min
Explain why data is encrypted when it is transmitted over a network.
Mark scheme
- Data can be intercepted (by an eavesdropper / hacker) (1).
- Encryption makes it meaningless / unreadable without the key — it does not stop interception (1).
Describe what is meant by symmetric encryption.
Mark scheme
- Plaintext is turned into ciphertext using an encryption key / algorithm (1).
- The same key is used to encrypt and to decrypt the data (1).
Describe how asymmetric encryption is used to send a confidential document from one person to another.
Mark scheme
- Uses a public key and a private key (a matching pair) (1).
- The receiver generates the key pair / keeps the private key secret (1).
- The receiver's public key is sent to / made available to the sender (1).
- The sender encrypts the document with the receiver's public key (1).
- The receiver decrypts it with their matching private key (1).
- The public key cannot decrypt the document (1).
Any four.
Explain why asymmetric encryption is more secure than symmetric encryption.
Mark scheme
- In symmetric encryption the single key must be sent to the receiver (1)…
- …and it can be intercepted, allowing all messages to be decrypted (1).
- In asymmetric encryption the private key is never sent / only the public key is shared (1).
- The public key cannot be used to decrypt the message (1).
Any three.
Recap & Key Terms 3 min
Encryption turns plaintext into ciphertext so intercepted data is useless. Symmetric encryption uses one shared key — which must somehow be sent safely. Asymmetric encryption encrypts with the receiver's public key and decrypts with their private key, which never leaves their computer.
- Encryption
- Making data meaningless using an encryption key; without the correct decryption key it cannot be decoded.
- Plaintext
- The original text / message before it is put through an encryption algorithm.
- Ciphertext
- The encrypted data produced by putting plaintext through an encryption algorithm.
- Eavesdropper
- A hacker who intercepts data being sent over a wired or wireless network.
- Symmetric encryption
- Encryption in which the same key is used both to encrypt and to decrypt a message.
- Asymmetric encryption
- Encryption that uses a matching pair of keys — a public key and a private key.
- Public key / private key
- A public key is known to all users; a private key is known only to the single computer / user that owns it.
Homework 1 min
Task (≤ 15 min): Kim can already receive encrypted documents from Sam. Describe what must happen so that Kim can also send encrypted documents back to Sam. [3]
Model answer
- Sam generates his own matching public and private key pair (1).
- Sam sends his public key to Kim (1).
- Kim encrypts documents with Sam's public key; Sam decrypts them with his own private key (1).