How does public key cryptography actually work?
By using two mathematically related keys where one encrypts and only the other decrypts — which solves the problem that had blocked secure communication for centuries: how to agree a secret with someone you have never met, over a channel anyone can listen to.
The arrangement. Each party has a public key, published freely, and a private key, never shared. Anything encrypted with the public key can only be decrypted with the private one. The public key can be shouted across a room without weakening anything.
Why it is secure. The keys are generated from mathematical operations that are easy in one direction and impractical to reverse — multiplying two very large primes is trivial, factoring the result back is not; computing a point multiplication on an elliptic curve is fast, reversing it is not. Security rests on that asymmetry rather than on secrecy of the method.
The second use, which matters as much: signatures. Encrypt with your private key and anyone can decrypt with your public one. That is useless for secrecy and perfect for proof — only the holder of the private key could have produced it. This underpins software signing, certificates, secure updates and cryptocurrency transactions.
Why it is not used for everything. Public key operations are computationally expensive. In practice, systems use it to agree a shared symmetric key and then switch to fast symmetric encryption for the actual data — which is exactly what happens in the first moments of a secure web connection.
The genuinely hard part is trust. The maths is sound; the difficulty is knowing that a public key belongs to whom it claims. That is what certificate authorities solve for the web — a trusted third party signs a statement binding a key to a domain — and it is the weak point, since a compromised authority can vouch for anyone.
Forward secrecy means a fresh key is agreed per session, so a later compromise of the long-term key does not expose past traffic.
Quantum computing threatens this specifically, which is why post-quantum algorithms are being standardised and deployed now.