Encryption helps protect information from unauthorized access when it is stored or transmitted. It is used throughout everyday technology, including websites, messaging apps, online banking, computers, smartphones, and cloud services.
So, what are the different types of encryption?
Modern encryption generally falls into two main categories: symmetric encryption and asymmetric encryption. Common encryption algorithms include AES and RSA, while older technologies such as DES and 3DES are no longer recommended for most applications.
Understanding these basic differences can help you better understand how your data is protected online.
What is data encryption?
Data encryption converts readable information, called plaintext, into an encoded form called ciphertext. A mathematical key is used as part of the encryption and decryption process.
Only someone or something with the appropriate key can decrypt the information and return it to a readable form.
For example, when you send sensitive information over a secure connection, encryption can help prevent someone who intercepts the data from simply reading it.
Encryption is used to protect many types of information, including:
- Passwords and account information
- Financial information
- Personal messages
- Business documents
- Files stored on computers and servers
- Data transmitted over networks
Encryption is one part of a broader security strategy. Strong passwords, multifactor authentication, software updates, and other security controls are also important for protecting your information.
What are the two main types of encryption?
The two primary categories of modern encryption are symmetric encryption and asymmetric encryption.
Symmetric encryption
Symmetric encryption uses the same secret key to encrypt and decrypt information.
The sender and recipient must both have access to the key. Because symmetric encryption is generally efficient, it is well suited for encrypting large amounts of data.
One of the most widely used symmetric encryption algorithms is Advanced Encryption Standard (AES).
Asymmetric encryption
Asymmetric encryption uses a pair of related keys: a public key and a private key.
The public key can be shared with others, while the private key is kept secret.
Depending on how it is used, asymmetric cryptography can help with secure communication, authentication, and digital signatures. It is generally slower than symmetric encryption, so it is not typically used to encrypt large amounts of data directly.
RSA is a well-known example of a public-key cryptographic algorithm.
What is AES encryption?
AES, or Advanced Encryption Standard, is a symmetric encryption algorithm widely used to protect electronic data.
AES uses a secret key for both encryption and decryption. It supports key sizes of:
- AES-128
- AES-192
- AES-256
The numbers refer to the size of the encryption key in bits. AES uses a fixed block size of 128 bits.
AES is widely used in applications and security technologies because it provides strong encryption while remaining efficient enough for many types of systems.
When is AES used?
AES can be used to protect many types of data, including:
- Files
- Databases
- Network traffic
- Stored data
- Communications
- Devices and applications
You may already use technology that relies on AES without interacting with the encryption directly.
What is RSA encryption?
RSA is a public-key cryptographic algorithm that uses a public key and a private key.
RSA can be used for purposes such as authentication, secure key exchange, and digital signatures.
For example, a public key can be shared openly while the corresponding private key remains protected. This allows systems to establish trust or verify that information came from the expected source.
RSA is not generally used to encrypt large files or large amounts of data because it is significantly less efficient than symmetric algorithms such as AES.
Instead, modern security systems can combine asymmetric and symmetric cryptography. For example, asymmetric cryptography can help establish or protect a session key, while a symmetric algorithm can then efficiently encrypt the actual data being transmitted.
What happened to DES and 3DES?
DES
Data Encryption Standard (DES) is an older symmetric encryption algorithm developed in the 1970s.
DES uses a 56-bit effective key and is no longer considered secure for modern applications because advances in computing made it vulnerable to brute-force attacks.
DES should not be used to protect sensitive information today.
3DES
Triple DES (3DES) was developed as a way to strengthen DES by applying the DES algorithm three times.
While 3DES was more secure than original DES, it is now considered an outdated technology. The National Institute of Standards and Technology (NIST) has deprecated the use of TDEA, the underlying algorithm used by 3DES, for applying cryptographic protection. (NIST)
For modern applications, stronger and more efficient encryption technologies such as AES are preferred.
What about Twofish, Blowfish, and other encryption algorithms?
There are many other cryptographic algorithms besides AES and RSA.
Examples include:
- Twofish
- Blowfish
- Threefish
- ChaCha20
Different algorithms were developed for different purposes, and some remain useful in specific applications.
Consumers generally do not need to choose an encryption algorithm themselves. Software, operating systems, websites, and security products typically determine which cryptographic technologies are appropriate for their specific use.
What is the difference between encryption and hashing?
Encryption and hashing are related security technologies, but they serve different purposes.
Encryption is reversible. Data can be decrypted when the appropriate key is available.
Hashing is designed to be one-way. A hashing algorithm converts data into a fixed-length value called a hash. The original information is not intended to be recovered from the hash.
For example, hashing is commonly used as part of password storage systems, while encryption can be used to protect files or communications.
Why does encryption matter?
Encryption helps protect information when it is stored or transmitted.
Without appropriate encryption, sensitive information could potentially be exposed if an unauthorized person gains access to the data or intercepts a communication.
Encryption is particularly important for:
- Online banking
- Shopping and payments
- Email and messaging
- Remote work
- Cloud storage
- Business communications
- Personal files
- Connected devices
However, encryption cannot protect against every security threat. If someone obtains your password, for example, encryption alone may not prevent them from accessing an account.
That's why encryption works best alongside other security practices.
How can I protect my data?
You don't need to understand the technical details of every encryption algorithm to improve your security.
Instead, focus on basic security practices:
- Use strong, unique passwords.
- Enable multifactor authentication when available.
- Keep your operating system and applications updated.
- Use trusted websites and applications.
- Be careful when opening unexpected links or attachments.
- Keep security software enabled.
- Back up important files.
- Use encrypted connections when transmitting sensitive information.
When choosing software or services, look for reputable providers that clearly explain how they protect customer data.
Frequently Asked Questions About Encryption
What is encryption in simple terms?
Encryption converts readable information into an encoded form that is difficult for unauthorized people to understand. A key is used to encrypt and, when appropriate, decrypt the information.
What are the two main types of encryption?
The two main types are symmetric encryption and asymmetric encryption. Symmetric encryption uses one shared secret key, while asymmetric encryption uses a related public and private key pair.
Is AES better than RSA?
AES and RSA are designed for different purposes, so they are not direct alternatives. AES is a symmetric encryption algorithm that is efficient for encrypting large amounts of data. RSA is a public-key cryptographic algorithm commonly used for authentication, digital signatures, and related functions.
Is DES still secure?
No. Original DES is considered obsolete and should not be used to protect sensitive information.
Is 3DES still secure?
3DES is an older encryption technology that has been deprecated for many modern uses. New systems should generally use modern cryptographic algorithms instead.
Do I need to choose an encryption type for my computer?
Usually not. Your operating system, applications, websites, and security products generally handle encryption automatically. You should focus on using reputable software, keeping your devices updated, and following good security practices.
The Bottom Line
Encryption protects data by converting readable information into an encoded form that can only be properly accessed with the appropriate key.
The two main categories are symmetric encryption, which uses a shared secret key, and asymmetric encryption, which uses a public and private key pair.
AES is a widely used modern symmetric encryption algorithm, while RSA is a well-known public-key cryptographic algorithm. Older technologies such as DES and 3DES are no longer recommended for modern security.
You don't need to be an encryption expert to protect your information. Using updated software, strong passwords, multifactor authentication, and reputable security products can help keep your data safer.