Contact

What is Encryption?

Definition

Encryption is the process of transforming readable data, using an algorithm and a key, into a form that only someone holding the correct key can turn back into the original. When the same secret key encrypts and decrypts, it is symmetric encryption; when a public and private key pair is used, it is asymmetric. On the web it underpins protecting data both in transit and at rest.

Also known as: data encryption, symmetric encryption, asymmetric encryption, public-key encryption

Flow of plaintext encrypted with a secret key into unreadable ciphertext that only the matching key can decrypt

Public algorithms, secret keys

The founding principle of modern cryptography is that security rests on keeping the key secret, not the algorithm. AES and ChaCha20 are public standards, and they are trusted precisely because they have been scrutinised for years. Someone who steals the ciphertext and knows the algorithm still learns nothing useful without the key. That is why real-world failures almost never come from the algorithm itself; they come from how and where keys are stored.

Symmetric and asymmetric encryption

SymmetricAsymmetric (public key)
KeysBoth sides share one secret keyA public key anyone may have; a private key only its owner holds
ExamplesAES, ChaCha20RSA, elliptic-curve (ECC) schemes
SpeedVery fast, suited to bulk dataSlow, suited to small values
Hard partGetting the key to the other side safelyProving whose public key it really is

Real systems combine the two. When you open a site over HTTPS, TLS uses asymmetric cryptography to authenticate the server and to let both sides agree on a shared session key; the page itself is then encrypted with that key using a fast symmetric cipher. The certificate is what ties the public key to the domain name, backed by a certificate authority's signature.

In transit versus at rest

Encryption in transit stops data being read or altered while it crosses a network: TLS between browser and server, TLS between the application and its database, STARTTLS between mail servers. Encryption at rest keeps data unreadable when a disk, database file, object store or backup is stolen or copied somewhere it should not be.

They defend against different threats and neither substitutes for the other. Full-disk encryption does nothing against an attacker who compromises the running application and queries the database, because at that point the data is already decrypted. For particularly sensitive fields such as national ID numbers or health data, teams therefore add field-level encryption in the application. Regulations push in the same direction: Article 32 of the GDPR names encryption explicitly among appropriate technical measures, and Turkey's KVKK requires data controllers to take technical measures that ensure an appropriate level of security.

What it looks like in code

Using AES-256-GCM with Node.js's built-in crypto module looks like this. GCM is an authenticated mode: besides encrypting, it produces a tag, and decryption fails if the data was tampered with.

import { randomBytes, createCipheriv } from "node:crypto";

const key = loadKeyFromKms();          // 32 bytes; never hard-coded
const iv = randomBytes(12);            // fresh and unique for every encryption
const cipher = createCipheriv("aes-256-gcm", key, iv);
const encrypted = Buffer.concat([cipher.update(iban, "utf8"), cipher.final()]);
const tag = cipher.getAuthTag();       // store iv and tag alongside the ciphertext

Do not invent your own algorithm or protocol; use the high-level APIs of widely used, maintained libraries. Small mistakes, such as reusing an IV with the same key, can quietly undo a perfectly sound cipher.

Keys, and the concepts people mix up

Storing encrypted data and its key in the same database is like taping the safe's key to the safe. Keys belong in a key management service (KMS) or at least a secrets management system separate from the application, with access logged and keys rotated on a schedule.

Two neighbours get confused with encryption. Encoding, such as Base64, changes the representation of data without any key, so anyone can reverse it and it provides no security. A hash is one-way: you cannot get the input back from the digest. Data you need to read again is encrypted; data you only need to verify, such as passwords, is hashed.

Related terms

← Back to the glossary