Start here

Introduction

Cryptography is the science of keeping secrets in the presence of adversaries. It began as a craft of priests, generals and diplomats, became a weapon in two world wars, and is now mathematics that runs, unnoticed, every time you open a web page, pay with a card or unlock a phone. This site follows that story from the first substitution ciphers to the post-quantum algorithms standardised in 2024.

What cryptography is for

Hiding a message is only one of its jobs. Modern cryptography protects four different things, and each chapter of this site builds the tools for one or more of them:

  • Confidentiality: only the intended reader can understand the message. This is what ciphers do, from Caesar's to AES.
  • Integrity: nobody can change the message without being noticed. Hash functions and message authentication codes do this, and so do the authenticated modes of block ciphers.
  • Authenticity: the message really comes from who it says. A shared secret key gives it; a digital signature gives it to anyone who holds the public key.
  • Non-repudiation: the author cannot later deny having signed. Only public-key signatures give this, because only one person holds the private key.

Two people who have never met agreeing on a secret over a channel that everybody can hear sounds impossible. Until 1976 everybody thought it was. The public-key revolution is the hinge of this story: before it, cryptography was about keeping keys secret; after it, it is also about keys that can be published.

A small vocabulary

Plaintext and ciphertext
The message before and after encryption. Encryption Ek and decryption Dk depend on a key k, and Dk(Ek(m))=m for every message m.
Cipher and code
A cipher transforms letters or bits by a rule; a code replaces whole words by code words from a book (“EAGLE” for “attack”). Codes need the book to be captured to be read; ciphers need to be broken.
Cryptanalysis
The art of breaking ciphers: recovering plaintext or keys without being given the key. Every chapter has its attacks, because every design is a reply to an attack.
Symmetric and asymmetric
In symmetric cryptography both sides share the same secret key; in asymmetric (public-key) cryptography there is a pair: a public key for encrypting or verifying, and a private key for decrypting or signing.
Encoding, encryption and hashing
Three different things that are often confused. Encoding (hexadecimal, Base64) only changes how bytes are written: no key, anyone can undo it. Encryption needs a key to undo. Hashing cannot be undone at all: it makes a fixed-size fingerprint of any input.

The enemy knows the system

In 1883 the Dutch linguist Auguste Kerckhoffs published six rules for military ciphers. The second one is the founding principle of modern cryptography:

The system must not require secrecy, and it must be able to fall into the hands of the enemy without inconvenience.Auguste Kerckhoffs, “La cryptographie militaire” (1883)

All the secrecy must live in the key, which is small and easy to change. The design of the cipher should be public, because designs leak (machines are captured, programs are disassembled, employees change jobs) and because only a design that has been attacked in public by many people deserves trust. Claude Shannon put it more bluntly in 1949: “the enemy knows the system”. Every modern standard (DES, AES, SHA-3, ML-KEM) was published in full and chosen after years of public attack; schemes that relied on a secret design, from the DVD's CSS to the GSM phone ciphers, were broken soon after their secret came out.

Bits, bytes and encodings

Classical ciphers work on letters. Modern ones work on bytes, groups of eight bits, so the first step is always to turn text into bytes. Today that is done with UTF-8: the letters of English take one byte each, an accented letter two, an emoji four. The ciphertext is bytes too, usually not printable, so to show it, copy it or put it in an e-mail we write it with a printable alphabet: hexadecimal uses two characters (0–9, a–f) per byte; Base64 regroups the bits in sixes and writes each six with one of 64 characters, so it is a third longer than the bytes instead of twice as long.

From characters to bytes and back to characters. Type anything: UTF-8 turns it into bytes; hexadecimal writes each byte as two digits; Base64 cuts the same bits into groups of six and adds “=” when the last group of three bytes is incomplete. None of this is encryption: there is no key.

The desktop app keeps these encodings in their own family, coloured grey, precisely to make the point: Base64 is not encryption. Plenty of real systems have been “protected” with it.

The journey

The chapters follow history, which here coincides with the logic of the subject: each new cipher answers the attack that broke the previous one.

  1. 01 Substitution c. 1900 BC – 1863 Hiding letters: from Caesar to Vigenère For two thousand years encryption meant replacing letters by other letters. The ciphers grew more clever, from Caesar's shift to Vigenère's keyword, and the breakers grew more patient, from al-Kindi counting letters in ninth-century Baghdad to Babbage and Kasiski measuring the distance between repetitions.
    • Key space of a substitution cipher: 26!≈288
    • Frequency analysis
    • Index of coincidence
    • Kasiski examination
  2. 02 Enigma 1918 – 1945 The machine that lost a war An electromechanical cipher with 159 quintillion settings, used by every branch of the German armed forces, broken first by three Polish mathematicians with permutation theory and then, on an industrial scale, at Bletchley Park. Its story shows that the weakest part of a cipher is often the way it is used.
    • Enigma is an involution with no fixed points
    • Conjugate permutations have the same cycle structure
    • Key space ≈1.59×1020
  3. 03 Shannon 1882 – 1949 Unbreakable, provably: the one-time pad There is a cipher that no amount of computing power can break, and Claude Shannon proved it in 1949. He also proved its price: a truly random key as long as everything you will ever send, used only once. Reuse it, as the Soviets did, and the message pours out.
    • The one-time pad is perfectly secret
    • Shannon's bound: |𝒦|≥|ℳ|
    • Unicity distance
    • Confusion and diffusion
  4. 04 DES & AES 1971 – 2001 Confusion and diffusion: from DES to AES A block cipher scrambles a fixed-size block of bits under a key, so thoroughly that without the key it looks like a random permutation. IBM's Lucifer became the US standard DES in 1977; twenty years later its 56-bit key fell to a machine built for $250,000, and an open competition chose its successor: Rijndael, now AES, the most used cipher in history.
    • A Feistel network is invertible for any round function
    • Luby–Rackoff
    • Meet-in-the-middle: double DES is not twice as strong
    • GF(28) is a field
  5. 05 Modes 1976 – 2018 One block is not enough: ECB, CBC, CTR, GCM AES encrypts sixteen bytes. Everything else (how to chain blocks, where the randomness goes, how to detect tampering) is the job of the mode of operation, and that is where most real-world breaks happen: patterns that show through, padding oracles, reused nonces, ciphertexts an attacker can edit.
    • Deterministic encryption leaks equality
    • Nonce reuse in CTR is a two-time pad
    • Encrypt-then-MAC is secure (Bellare–Namprempre)
    • GHASH is a polynomial over GF(2128)
  6. 06 Hashes 1979 – 2020 Fingerprints of data A hash function squeezes any input, a word or a whole disk, into a short fingerprint that changes completely if a single bit changes. Fingerprints protect downloads, passwords, signatures, Git and Bitcoin. Breaking them means finding two inputs with the same fingerprint, and the birthday paradox says that is far easier than it sounds.
    • Birthday bound: collisions after ≈2n/2 tries
    • Merkle–Damgård: a collision-resistant compression function gives a collision-resistant hash
    • Length extension
    • Sponge security ≈2c/2
  7. 07 Passwords 1976 – 2021 Slow on purpose: salts, bcrypt, scrypt and Argon2 Passwords are short, human and reused, and servers get breached. Storing them safely is the art of making every guess expensive: a salt so that each account must be attacked separately, and a hash that is deliberately slow and memory-hungry, so that a guess costs an attacker's GPU as much as it costs the server.
    • Password entropy H=Llog2⁡N
    • Salts defeat precomputation
    • Time–memory trade-off (Hellman)
    • Memory-hard functions
  8. 08 RSA & DH 1970 – 1998 Secrets in public: Diffie–Hellman and RSA For four thousand years, two people who wanted to communicate secretly had to share a key first. In 1976 Whitfield Diffie and Martin Hellman showed how to agree on one in public, and a year later Rivest, Shamir and Adleman built a cipher whose encryption key can be printed in a newspaper. Both rest on number theory that Fermat and Euler knew in the eighteenth century.
    • Fermat's little theorem
    • Euler's theorem
    • Correctness of RSA
    • Chinese remainder theorem
    • Square-and-multiply
  9. 09 ECC 1985 – 2013 The arithmetic of curves: ECDH, ECDSA, Ed25519 Points on a cubic curve can be added with a ruler: draw the line, find the third point, reflect it. Over a finite field this geometry becomes a group in which logarithms are even harder than in RSA's numbers, so a 256-bit key does the work of a 3,072-bit one. It is the cryptography inside every phone, passkey and TLS connection today.
    • The chord-and-tangent law makes E an abelian group
    • Hasse: |#E(𝔽p)−(p+1)|≤2p
    • Pollard's rho: ≈n steps
    • Reusing an ECDSA nonce reveals the private key
  10. 10 Post-quantum 1994 – 2026 After Shor: lattices, ML-KEM and ML-DSA A large quantum computer would break RSA, Diffie–Hellman and every elliptic curve in this site. It does not exist yet, but encrypted traffic recorded today could be read when it does. So in 2024, after an eight-year public competition, NIST standardised replacements built on lattices and hashes, and the migration of the whole Internet has begun.
    • Shor: factoring and discrete logarithms in polynomial time
    • Grover: N search, and no better
    • Learning with errors is as hard as worst-case lattice problems (Regev)
    • Correctness of Regev's encryption

How to read this site

In order, like a short book, or jump to the chapter you are curious about: each one stands on its own and links back where it needs to. Results are stated as theorems, with short proofs you can unfold, and every chapter has interactive figures that run the real algorithms in your browser: the AES of chapter 04 is the full AES-128, checked against the official test vectors, and the Enigma of chapter 02 has the same wiring as the machines at Bletchley Park. Nothing you type is sent anywhere.

The history page puts four thousand years of events on one line, and the app is cryptoKit itself: a free desktop toolkit (Java) with the 44 algorithms discussed here, for encrypting, decrypting, hashing and signing your own data, each one with a link back to the chapter that explains it.

A warning. Understanding how a cipher works is not the same as being able to build a secure system with it. The figures here are written to be read, not to resist side-channel attacks. For real data, use well-reviewed libraries and protocols, such as the ones the desktop app is built on.