Encryption

Encrypting scrambles plain text into an unreadable form called ciphertext. To read the original text, a decryption key is needed.

Here is a great video explaining the basic concept of encryption.

Objectives

Students will be able to:

  • understand the difference between symmetric and asymmetric encryption
  • understand how public and private keys are used
  • understand the purpose of digital certificates
  • understand the importance of encryption key management

Intranets and Extranets

An intranet is really just a LAN. It is a network only available to the employees of a company, for example.

If a company has many offices, these can all be connected privately - so, bigger than a LAN... maybe a WAN... definitely an intranet!

Note: some companies allow parts of their intranet to be accessed securely by approved third parties eg customers or business partners.

This is when an intranet becomes an extranet!

Encryption

When your browser connects to a web server, there is every chance that you will be sharing sensitive data eg

  • usernames
  • passwords
  • bank details
  • PIN numbers

This is especially true when you are connecting to a bank website or sending an email to your mom.

In the modern internet, with so many malicious actors present, it is imperitive that the connection uses a eg https

This unit will introduce:

  • symmetric and asymmetric encryption and the difference between them (public and private keys)
  • the role of digital certificates in establishing secure network connections
  • the significance of encryption key management
 

Watch the video and complete this worksheet and let's find out more about encryption.

Note: you may have completed some of this in the VPN unit. Use this as a review opportunity.

Digital Certificates

So now we know that asymmetric encryption is more secure than symmetric encryption.

2 keys are used:

  • a public, shared key to encrypt
  • a private key, never shared, to decrypt

So what is the role of digital certificates if asymmetric encryption is so secure?

Asymmetric encryption protects data, but by itself it does not prove who you are communicating with.

What is a Digital Certificate?

A digital certificate is an electronic document that:

  1. identifies a server or organisation
  2. contains the server’s public key
  3. contains its expiry date
  4. is digitally signed by a trusted authority

When a browser connects to a secure website, the server sends its digital certificate.

The browser verifies:

  • the certificate is valid
  • it has not expired
  • it belongs to the correct website
  • it was issued by a trusted Certificate Authority (CA)

Once verified, the browser can safely trust that the public key genuinely belongs to that server.

This prevents attackers from simply sending their own fake public key.

Encryption Key Management

Large organisations may use:

  • thousands of servers
  • millions of encrypted connections
  • many different users and devices

Encryption Key Management Systems help automate:

  • certificate handling
  • key generation
  • deleting expired keys
  • updating/renewing keys
  • distributing keys safely

Without proper key management, even very strong encryption can become ineffective because attackers may gain access to the encryption keys needed to decrypt sensitive data.

Glossary

encryption

symmetric

asymmetric

keys

public

private

digital certificates