Skip to content

Locks and Keys

Public and private keys · RSA-OAEP · RSA-PSS

Make a real key pair, have a note encrypted to the half you hand out, open it with the half you keep — then use the same pair for its other job, signing.

Start here

How can somebody send you a private note without the two of you first agreeing on a password? You publish a public key anyone may encrypt to, and keep the matching private key secret. Four steps, no maths.

Real cryptography, running in your browser. Use example text, not real secrets.

Why RSA here, and what this demo is not

The padlock story is literally true for RSA, which is why this lab uses it: you encrypt straight to somebody's public key and there is nothing else on screen. Most of the web today uses a different shape — elliptic curves — where encrypting to someone needs a throwaway key pair and a key-derivation step first. That is better in practice and one idea too many for a first encounter. Iron Letter compares the two directly, and HPKE Envelope shows how it is actually packaged.

Nothing here is simulated — every operation is the browser's own RSA. It is still not production code. One deliberate difference: the private half is generated so that it can be exported, which real systems avoid, because Step 4 needs to re-import the same key material under a second algorithm name to show that one pair does both jobs.

The numbers underneath — how the pair is generated and why it works — are kept off this page on purpose. That is Educational RSA, which exists to show exactly the layer this one hides.

Step 1 Make a pair

You are Sam. Press the button; your browser generates two matching halves of one real key pair.

Step 2 Encrypt a note to you

Maya wants to send you something private. She has your public half — the one you hand out — and nothing else. Write what she is sending and encrypt it.

A key this size encrypts at most 190 bytes at a time, so this is a note and not a letter. A byte is a unit of stored data; plain letters take one each, an accented letter takes two and an emoji four, which is why the counter can run ahead of the characters you typed. Real systems get around the limit by encrypting a key rather than a message — that is what HPKE Envelope is about.

Step 3 Open it — and see what opening proves

Three experiments. Guess before each one; being wrong is the fastest way to remember it.

Open it with your private half

Now try the wrong key

Predict first — optional

This makes a second, completely unrelated pair and hands its private half the same encrypted bytes.

And now the part nobody expects

Predict first — optional

Your public half is public, so let somebody else use it. This hands a stranger nothing but your public bytes from Step 1 and lets them encrypt a note of their own choosing. Then you open it with your private half.

Step 4 The same pair, a different job

Step 3 ended with a problem: a note that opens tells you nothing about who sent it. A signature is the answer — and it needs no new keys. Now you are the sender: you sign, and Maya checks.

Predict first — optional

Check it with the public half

Maya checks with your public bytes and nothing else — the same block you could have printed in a newspaper. Then change the note she is checking and watch what happens: edit the box yourself, or let the button change one character for you.

Quick check — which half did which job?

What each job does, and does not, establish

Which key each operation uses and what it does not establish
JobKey usedWhat it does NOT establish
EncryptThe recipient’s public halfWho sent the note
DecryptThe recipient’s private halfWho sent the note
SignThe signer’s private halfSecrecy, or whether the note is true
VerifyThe signer’s public halfWhose key it is, unless you already know

Three questions

No score, and nothing is recorded. If one of these is awkward, the explanation is the point.

How this demo checks its own results

Everything above is this page agreeing with itself, which is not worth much alone: a build that got the maths wrong in both directions at once would look just as convincing. So the lab also runs a fixed set of cases published by somebody else, in your browser, on arrival.