MK ATLAS· Science Atlas

Concepts explained

Cryptography — Why the Lock Is Handed to Everyone

Can you exchange a secret with a stranger, in a room where everyone is listening, having agreed nothing beforehand? It sounds impossible, and we do it dozens of times a day. It works because some calculations are easy in one direction only.

Questions this piece threads together 24 min readUpdated 2026-09-09

Old ciphers meant sharing a key

As children we shifted each letter one along to pass notes. That is a real , the same one Rome used two thousand years ago.

It contains a method and a key: shifting is the method, how far to shift is the key.

And with it comes an old headache — how to get the key to the other person.

Hand out the lock, not the key

In the 1970s came the idea that broke the circle: make the locking key and the opening key different things.

Leave a heap of open padlocks at the post office for anyone to take. Anyone can snap one shut; the key stays in my pocket. Now a stranger can send me a secret with no prior meeting at all.

This is , and it happens every time you reach a bank's website: you are handed the bank's padlock, you close it, you send.

But how is such a lock built?

Here mathematics enters. What is needed is a calculation easy in one direction and hard in the other.

Ask anyone to multiply two and it is done at once. Hand over only the product and ask for the two numbers back, and if they are large enough every computer on Earth would take a very long time.

Multiplying is the locking, recovering is the opening. So calling cryptography mathematics is no metaphor: the lock is made not of steel but of difficulty.

A little further in

Hard does not mean impossible

An honest point belongs here. That factoring takes a long time is not a proven fact.

It means only that nobody has yet found a fast way. Somebody might tomorrow. The whole internet stands on that floor, and the floor is not proof but failure so far.

So people in this field do not say secure. They say that known attacks would take so many years. When computers get faster the numbers get longer; when a scheme wobbles it is replaced. Cryptography is not a finished object but clothing that keeps being changed.

Publish the method, keep only the key

Would hiding the method not be safer? For a long time that is exactly what was done.

So each country settles which ciphers it will standardise and keeps an institute to verify them. In Korea that work is done by the National Security Research Institute in Daejeon.

The key must be unguessable

However good the lock, a guessable key ruins it. Hence the importance of .

But a computer follows rules and cannot manufacture chance, and a number made by a rule is predictable to whoever knows the rule. A good share of real breaches came not from weak ciphers but from predictable key generation.

So unpredictable nature is borrowed: noise in a circuit, decay whose timing nothing fixes. Chance cannot be made, so it is borrowed.

When quantum computers arrive

Multiplying is easy and recovering is hard, and that hardness is the pillar of today's internet.

It has already been proved on paper that a quantum computer could do the recovering overwhelmingly faster. The machine does not exist yet. The proof does.

Yet what actually breaks is not the mathematics

Read this far and cryptography seems to be everything. In practice, failures happen elsewhere.

  1. People — a convincing email, and the password is handed over.
  2. Configuration — a fine lock on a door that was left open, believed shut.
  3. Age — software that needed patching years ago and never got it.
  4. Key storage — the strongest lock in the world, and the key under the flowerpot.

So security research is half mathematics and half people and housekeeping. Doing only one half does not keep anything safe.

Listening to the dial instead of breaking the safe

There is one more attack worth knowing. Rather than break the cipher, watch the machine doing the arithmetic.

How much electricity it draws varies very slightly with the numbers it handles, and so does the time it takes. Measure those differences long enough and the key emerges — listening to the dial instead of cutting the safe.

So security chips now mix in useless calculations on purpose, or flatten their power draw. At this point the field needs people who know electronics and measurement, not mathematics.

What you would study to do this

It is not a field for mathematicians alone.

  1. Someone who designs and scrutinises the ciphers — mathematics, number theory in particular.
  2. Someone who puts them into programs and chips — computing and electronics. Most mistakes happen here.
  3. Someone who measures power traces and timing to find leaks — instrumentation and circuits.
  4. Someone who attacks first — you cannot defend without knowing the attack.
  5. Someone who writes the rules and standards — law, policy, certification.
  6. Someone who teaches people — since people are the part that fails most often.

The third line will surprise you. There is a job where breaking a cipher is done with an oscilloscope, and it is open to anyone who has worked with circuits.

The fourth line requires authorisation. Probing someone else's system without permission is a crime; this work happens only inside contracts and procedures.

This work is done at the National Security Research Institute in Yuseong-gu, Daejeon, which grew out of the electronics and telecommunications institute.

The question that remainsIf secure only means that nobody has broken it yet — what is it that we are trusting when we hand over a secret?