Part 2 · 1 chapters · ~8 min
Public-Key Cryptography
Key pairs and one-way functions, RSA and why its keys are large, elliptic curves (P-256, Curve25519) with smaller keys and faster operations measured here, hybrid encryption, key formats (PEM, JWK), and post-quantum cryptography with ML-KEM and ML-DSA.
5
Key pairs and the hard problems
code
openssl genpkey -algorithm ed25519 -out ed.pem # 32-byte private key
openssl pkey -in ed.pem -pubout -out ed.pub.pem # derive and publish the public key
openssl genpkey -algorithm RSA -pkeyopt rsa_keygen_bits:3072 -out rsa.pem
// JWK form, as published in a JWKS (Auth course part 2)
{ "kty": "OKP", "crv": "Ed25519", "x": "11qYAYKxCrfVS_7TyWQHOg7hcvPapiMlrwIaaPcHURo", "kid": "2026-10" }PUBLIC-KEY CRYPTOGRAPHY
a key pair: one key public, one private, and the hard problem that keeps them apart
swipe the figure sideways, or tap expand for full screen
1/5
a key pair
A private key and a mathematically linked public key. What one key does, only the other can undo or verify. Publishing the public key does not reveal the private one.
private kept, public publishedthe link is one-way in practice