{"id":20382,"date":"2020-01-29T16:14:57","date_gmt":"2020-01-29T16:14:57","guid":{"rendered":"https:\/\/www.arimetrics.com\/glosario-digital\/encryption"},"modified":"2026-09-24T08:31:22","modified_gmt":"2026-09-24T08:31:22","slug":"encryption","status":"publish","type":"encyclopedia","link":"https:\/\/www.arimetrics.com\/en\/digital-glossary\/encryption","title":{"rendered":"Encryption"},"content":{"rendered":"<p><img decoding=\"async\" class=\"boxpad alignright wp-image-23140 size-full\" src=\"https:\/\/www.arimetrics.com\/wp-content\/uploads\/2021\/11\/encryption.jpg\" alt=\"Encryption\" width=\"300\" height=\"300\" srcset=\"https:\/\/www.arimetrics.com\/wp-content\/uploads\/2021\/11\/encryption.jpg 300w, https:\/\/www.arimetrics.com\/wp-content\/uploads\/2021\/11\/encryption-150x150.jpg 150w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><strong>Definition:<\/strong><\/p>\n<p><strong>Encryption<\/strong> is the cryptographic process of transforming readable information into unintelligible data by means of an algorithm and a key. Only someone with the appropriate key, or an authorised mechanism for obtaining it, can recover the original content.<\/p>\n\n<p>Encryption does not prevent a third party from capturing or copying data: it prevents them from interpreting it without authorisation. Its main objective is confidentiality, although some schemes combine encryption with integrity and authenticity controls. The <a href=\"https:\/\/csrc.nist.gov\/glossary\/term\/encryption\" target=\"_blank\" rel=\"noopener\">NIST definition of encryption<\/a> similarly describes the transformation of plaintext into ciphertext using a cryptographic algorithm and key.<\/p>\n<h2>How encryption works<\/h2>\n<p>An encryption system receives a readable message, applies a mathematical operation and produces ciphertext. The process involves several distinct components:<\/p>\n<ul>\n<li><strong>Plaintext:<\/strong> the original data that a person or application can interpret.<\/li>\n<li><strong>Algorithm:<\/strong> the set of operations that transforms data according to a known cryptographic design.<\/li>\n<li><strong>Key:<\/strong> a secret or controlled value that determines the encryption result and enables authorised decryption.<\/li>\n<li><strong>Additional parameters:<\/strong> elements such as initialisation vectors, unique numbers or authentication tags that prevent repetition and allow changes to be detected when the system uses them.<\/li>\n<\/ul>\n<p>Security should not depend on hiding the algorithm. Modern algorithms are published and analysed; the key is what must be protected. A suitable algorithm can fail if keys are generated badly, reused insecurely, stored alongside the data or exposed in logs and backups.<\/p>\n<h2>Types of encryption<\/h2>\n<p>The main classification is based on the keys used:<\/p>\n<ul>\n<li><strong>Symmetric encryption:<\/strong> uses the same secret key to encrypt and decrypt. It is efficient for large volumes of data but requires the key to be distributed and stored securely.<\/li>\n<li><strong>Asymmetric encryption:<\/strong> uses a related pair of public and private keys. Data encrypted for the corresponding public key can only be recovered with the private key, depending on the scheme.<\/li>\n<li><strong>Hybrid encryption:<\/strong> uses asymmetric cryptography to agree or protect a session key and symmetric encryption for the data. This combination is common because it combines key exchange mechanisms with efficient processing.<\/li>\n<\/ul>\n<p>The choice does not depend only on which type appears stronger. The use case, algorithm, key size and lifecycle, mode of operation, implementation and regulatory requirements all need to be considered.<\/p>\n<h2>What encryption protects and does not protect<\/h2>\n<p>Encryption forms part of a security architecture but does not replace all its controls:<\/p>\n<ul>\n<li><strong>Confidentiality:<\/strong> makes content difficult for an unauthorised person to understand even if they access the file, device or traffic.<\/li>\n<li><strong>Integrity:<\/strong> encryption alone does not always detect changes. Authenticated encryption modes and other cryptographic mechanisms can add this check.<\/li>\n<li><strong>Authenticity:<\/strong> encrypting a message does not necessarily prove who created it. Certificates, authentication codes and digital signatures serve specific functions.<\/li>\n<li><strong>Availability:<\/strong> does not prevent deletion, loss or denial of access. <a href=\"https:\/\/www.arimetrics.com\/en\/digital-glossary\/ransomware\">Ransomware<\/a>, for example, can encrypt data maliciously to block legitimate access.<\/li>\n<li><strong>Metadata and endpoints:<\/strong> content may be encrypted while details such as participants, times or sizes remain visible. It also becomes readable again on authorised devices, which need protection.<\/li>\n<\/ul>\n<p>Encryption also does not prevent <a href=\"https:\/\/www.arimetrics.com\/en\/digital-glossary\/phishing\">phishing<\/a>, excessive permissions, a compromised password or configuration errors. It reduces particular risks but needs access controls, updates, backups, monitoring and response procedures.<\/p>\n<h2>Encryption in transit and at rest<\/h2>\n<p>Data can be protected at different stages of its lifecycle:<\/p>\n<ul>\n<li><strong>Web communications:<\/strong> <a href=\"https:\/\/www.arimetrics.com\/en\/digital-glossary\/https\">HTTPS<\/a> uses TLS to protect communication between the browser and server. The term <a href=\"https:\/\/www.arimetrics.com\/en\/digital-glossary\/ssl\">SSL<\/a> remains common, although modern protocols are TLS.<\/li>\n<li><strong>Private networks:<\/strong> a <a href=\"https:\/\/www.arimetrics.com\/en\/digital-glossary\/vpn\">VPN<\/a> can create an encrypted tunnel between devices or networks without by itself guaranteeing the security of the endpoints or final service.<\/li>\n<li><strong>Disks and devices:<\/strong> full-disk encryption protects stored data when the device is off or locked, provided that keys and credentials are not exposed.<\/li>\n<li><strong>Files, databases and backups:<\/strong> can be encrypted by volume, file, field or application according to who needs access and where keys are managed.<\/li>\n<li><strong>Remote services:<\/strong> <a href=\"https:\/\/www.arimetrics.com\/en\/digital-glossary\/cloud-storage\">cloud storage<\/a> can encrypt data during transfer and while stored; the architecture determines whether the provider, customer or both control the keys.<\/li>\n<\/ul>\n<p>End-to-end encryption restricts decryption to the authorised endpoints of a communication. It is not a synonym for every encrypted connection: a service may decrypt data on its servers for processing even when transport is protected.<\/p>\n<h2>Key management and good practices<\/h2>\n<p>Encryption quality depends on key management as much as on the algorithm. A sound process addresses:<\/p>\n<ul>\n<li><strong>Generation:<\/strong> creating keys with appropriate sources of randomness and lengths for the algorithm.<\/li>\n<li><strong>Distribution:<\/strong> delivering or agreeing keys without exposing them to third parties or embedding them directly in code.<\/li>\n<li><strong>Storage:<\/strong> using secret managers, security modules or other controls separated from the protected data.<\/li>\n<li><strong>Access:<\/strong> limiting which people and services can use each key, applying minimum permissions and auditability.<\/li>\n<li><strong>Rotation and recovery:<\/strong> defining when keys are replaced, how access is recovered and what happens to data encrypted with older keys.<\/li>\n<li><strong>Revocation and destruction:<\/strong> withdrawing compromised or obsolete keys and documenting the consequences for associated information.<\/li>\n<\/ul>\n<p>Teams should not design their own algorithms or select isolated primitives without cryptographic expertise. The <a href=\"https:\/\/cheatsheetseries.owasp.org\/cheatsheets\/Cryptographic_Storage_Cheat_Sheet.html\" target=\"_blank\" rel=\"noopener\">OWASP Cryptographic Storage Cheat Sheet<\/a> recommends starting from the threat model, minimising sensitive data and using maintained, reviewed solutions.<\/p>\n<h2>Differences between encryption and related concepts<\/h2>\n<p>Several processes transform data, but they have different objectives:<\/p>\n<ul>\n<li><strong>Hashing:<\/strong> generates a fixed-length digest and is designed as a one-way operation. It is used to check integrity or protect passwords with specific schemes, not to recover the original text.<\/li>\n<li><strong>Encoding:<\/strong> changes representation to support storage or transmission, as Base64 does. It is reversible without a secret key and does not provide confidentiality.<\/li>\n<li><strong>Digital signature:<\/strong> uses asymmetric cryptography to provide authenticity and integrity and, depending on the context, support non-repudiation. It does not necessarily hide content.<\/li>\n<li><strong>Obfuscation:<\/strong> makes code or data more difficult to understand but is not equivalent to a resistant cryptographic system.<\/li>\n<li><strong>Hashes and signatures in blockchain:<\/strong> many chains link blocks through hashes and authorise operations with signatures. This does not mean that all transactions are encrypted or private.<\/li>\n<\/ul>\n<p>Classification depends on the required property: hiding content, detecting changes, proving origin or converting a format. A system can combine several mechanisms, but their functions are not interchangeable.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Encryption transforms data using algorithms and keys. Learn how it works, its main types, uses, limits and differences from hashing and encoding.<\/p>\n","protected":false},"author":6,"featured_media":0,"template":"","encyclopedia-tag":[1263],"class_list":["post-20382","encyclopedia","type-encyclopedia","status-publish","hentry","encyclopedia-tag-web-encryption"],"_links":{"self":[{"href":"https:\/\/www.arimetrics.com\/en\/wp-json\/wp\/v2\/encyclopedia\/20382","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.arimetrics.com\/en\/wp-json\/wp\/v2\/encyclopedia"}],"about":[{"href":"https:\/\/www.arimetrics.com\/en\/wp-json\/wp\/v2\/types\/encyclopedia"}],"author":[{"embeddable":true,"href":"https:\/\/www.arimetrics.com\/en\/wp-json\/wp\/v2\/users\/6"}],"wp:attachment":[{"href":"https:\/\/www.arimetrics.com\/en\/wp-json\/wp\/v2\/media?parent=20382"}],"wp:term":[{"taxonomy":"encyclopedia-tag","embeddable":true,"href":"https:\/\/www.arimetrics.com\/en\/wp-json\/wp\/v2\/encyclopedia-tag?post=20382"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}