Written and maintained by CASRAI Editorial Board
Last updated
Cryptography is the study and practice of techniques that protect information and communication in the presence of an adversary. In everyday terms, it is the mathematics behind encrypted messages, password storage, software updates that can be trusted, and the padlock in a web browser. It is also an academic field with its own theory, conferences, professional society, and funding streams, and for research institutions it is a working tool: the means by which sensitive research data is kept confidential, shown to be unaltered, and shared with the right people only. This guide explains what cryptography is, how its main building blocks differ, what the field studies, and where it meets research administration, data protection, and export control. It is educational and defensive in intent: it describes how protection is organized, not how to break it.
What Cryptography Means
The word comes from Greek roots meaning “hidden writing,” and for most of history it meant secret codes. Modern cryptography is broader. It is concerned with a small set of security goals, and encryption (keeping content secret) is only one of them:
- Confidentiality — only authorized parties can read the information. Encryption provides this.
- Integrity — any unauthorized change to the information can be detected. Hash functions and message authentication codes provide this.
- Authentication — a party can prove who or what it is, and data can be tied to its origin.
- Non-repudiation — a signer cannot later convincingly deny having signed. Digital signatures provide this.
Two terms are worth separating. Cryptography usually refers to designing and using such techniques, while cryptanalysis is the study of how to defeat them. Together they are often called cryptology, and the main scholarly society uses that word in its name. Cryptography is also not the same as cybersecurity: it is one subfield, and often the most mathematical one, of the broader discipline described in What Is Cybersecurity? Many security failures in practice have nothing to do with broken mathematics; they come from poor implementation, mismanaged keys, or human error, which is why the field pays so much attention to how algorithms are used and not only to which algorithm is chosen.
The Core Building Blocks
Almost every real-world system combines a handful of primitives. Understanding what each one does, and what it does not do, resolves most of the confusion beginners have.
Symmetric (Secret-Key) Cryptography
In symmetric cryptography, the same secret key is used to encrypt and to decrypt. It is fast and efficient, which is why it protects the bulk of data in storage and in transit. The dominant standard is the Advanced Encryption Standard (AES), which NIST selected in 2001 after a public competition and published as FIPS 197. AES is a block cipher: it transforms fixed-size blocks of data under a key, and a separate mode of operation determines how it handles longer messages. Choosing a mode matters as much as choosing the cipher; a strong cipher used in a poor mode can still leak information. The central difficulty of symmetric cryptography is key distribution: both parties need the same secret, and getting it to them safely over an insecure channel is the problem that public-key methods were invented to solve.
Asymmetric (Public-Key) Cryptography
Asymmetric cryptography uses a pair of mathematically linked keys: a public key that can be shared openly and a private key that is kept secret. It was introduced in the open literature by Whitfield Diffie and Martin Hellman in 1976, and the RSA scheme followed in 1977 and 1978. Public-key methods serve two main purposes. Key establishment lets two parties who have never met agree on a shared secret over a public channel, which they then use for fast symmetric encryption. Digital signatures let the holder of a private key produce a value that anyone with the public key can verify. Public-key operations are slower than symmetric ones, so real protocols such as the ones behind secure web connections use both: asymmetric methods to set up, symmetric methods to carry the data. The security of widely deployed public-key schemes rests on the presumed difficulty of mathematical problems such as factoring large integers or computing discrete logarithms, including on elliptic curves. That reliance is exactly what makes quantum computing relevant, as discussed below.
Cryptographic Hash Functions
A hash function takes input of any size and produces a short, fixed-size fingerprint. A good cryptographic hash is one-way (you cannot recover the input from the output), and it is computationally infeasible to find two different inputs with the same output (collision resistance). Hashes do not encrypt anything and involve no key. They are used to verify that a file has not changed, to store passwords in a form that does not reveal them, and as a component inside digital signatures and many other protocols. NIST standardizes the SHA-2 family (FIPS 180-4) and the SHA-3 family (FIPS 202). Hash functions age: the older SHA-1 was publicly shown to have a practical collision in 2017, and standards bodies had by then been moving away from it. For research data, a published checksum is the simplest everyday application: it lets a recipient confirm that the dataset they downloaded is the one that was deposited.
Message Authentication and Digital Signatures
A message authentication code (MAC) uses a shared secret key to produce a tag that proves a message came from someone holding the key and was not modified. A digital signature does the same job with a key pair, so anyone can verify it and only the private-key holder could have created it, which gives non-repudiation as well. A digital signature is a cryptographic object and should not be confused with an electronic signature in the legal sense, such as a typed name or a click-to-sign form; the two overlap but are not the same thing. Signatures underpin software update verification, certificate systems that let browsers trust websites, and increasingly the provenance of datasets, code, and records.
Beyond the Basics
The research frontier includes primitives that go well beyond encrypting a message. Zero-knowledge proofs let one party prove a statement is true without revealing why. Secure multiparty computation lets several parties jointly compute a result over their combined data without any of them seeing the others’ inputs. Homomorphic encryption allows computation on data while it stays encrypted. These are of direct interest to research, because they offer ways to analyze sensitive data, such as patient records held at different hospitals, while limiting exposure. They are also costly in computing terms and are still being made practical, so treat them as active research areas rather than routine tools.
How the Field Works: Methods
Cryptography is unusual among engineering disciplines because it is built around proof under stated assumptions rather than testing alone. Passing every test an engineer can think of is not evidence of security against an intelligent attacker.
- Formal definitions and security proofs — researchers first state precisely what “secure” means, for example that an attacker cannot distinguish encryptions of two messages, and then prove that a construction meets that definition provided an underlying assumption holds. This is called provable security, and it often proceeds by reduction: showing that breaking the scheme would imply solving a problem believed to be hard.
- Public scrutiny — a long-standing principle, often credited to the nineteenth-century cryptographer Auguste Kerckhoffs, holds that a system should remain secure even if everything about it except the key is public. In practice, the strongest standards come out of open competitions, in which many teams analyze each candidate for years. The AES selection, the SHA-3 selection, and the post-quantum process described below all followed that pattern.
- Cryptanalysis — deliberate, published attempts to find weaknesses. Because a proof covers only the model it is stated in, attacks on implementations, such as timing or power-consumption side channels, form their own research area.
- Implementation and verification — writing correct, constant-time code, and using formal verification tools to check that implementations match specifications.
- Protocol analysis — examining the way primitives are combined, since many real breaks occur in the protocol rather than the cipher.
Major Subfields
- Symmetric-key cryptography — ciphers, hash functions, and authentication codes.
- Public-key cryptography — encryption, key exchange, and signatures built on number theory, curves, lattices, codes, and hash-based constructions.
- Theory of cryptography — the foundations: definitions, proofs, and the relationships between assumptions.
- Cryptographic protocols — secure communication, authentication, voting, and multiparty computation.
- Hardware and embedded cryptography — efficient and side-channel-resistant implementations on constrained devices.
- Applied and real-world cryptography — deployment, usability, and failure analysis of cryptography in production systems.
- Post-quantum cryptography — algorithms intended to withstand attacks by quantum computers.
- Privacy-oriented cryptography — zero-knowledge proofs, anonymous credentials, and private computation.
Post-Quantum Cryptography
In 1994 Peter Shor described a quantum algorithm that could efficiently factor large integers and compute discrete logarithms. If a sufficiently large, fault-tolerant quantum computer is built, it would break the public-key schemes in wide use today, including RSA and elliptic-curve systems. Such a machine does not exist at the scale required, and when or whether one will is uncertain, but the risk has a practical consequence now: information encrypted today could be recorded and decrypted later, sometimes called “harvest now, decrypt later.” That matters most for data that must stay confidential for decades, which includes much human-subjects and genomic research data. Symmetric cryptography and hash functions are affected less, and are generally handled by using larger key and output sizes. For background on the physics, see What Is Quantum Physics?
Post-quantum cryptography (PQC) refers to classical algorithms, running on ordinary computers, designed to resist both classical and quantum attacks. It should not be confused with quantum cryptography, such as quantum key distribution, which uses quantum physics itself. NIST began a public standardization process for post-quantum algorithms in 2016. On August 13, 2024, NIST published its first three finalized standards:
- FIPS 203 — ML-KEM, a module-lattice-based key-encapsulation mechanism for establishing shared keys, derived from CRYSTALS-Kyber.
- FIPS 204 — ML-DSA, a module-lattice-based digital signature algorithm, derived from CRYSTALS-Dilithium.
- FIPS 205 — SLH-DSA, a stateless hash-based digital signature algorithm, derived from SPHINCS+, whose security rests on different assumptions from the lattice-based schemes and so serves as a hedge.
In March 2025, NIST announced the selection of HQC, a code-based key-encapsulation algorithm, as an additional standardization candidate to back up ML-KEM, so that not all key-establishment schemes depend on lattice problems. Standards continue to evolve, so a research office or lab planning a migration should consult NIST’s current post-quantum cryptography pages rather than rely on any summary, including this one. For an institution, the practical task is called cryptographic agility: knowing where cryptography is used in its systems and being able to replace algorithms without rebuilding everything.
A Short History
Ciphers are ancient; substitution ciphers such as the one attributed to Julius Caesar are classroom staples. Through the two world wars, mechanical and electromechanical machines drove a race between code makers and code breakers. The shift to a scientific field is usually dated to Claude Shannon’s 1949 paper “Communication Theory of Secrecy Systems,” which put secrecy on a mathematical footing. In the 1970s two developments opened the field to civilian research: the adoption of the Data Encryption Standard (DES) as a U.S. federal standard in 1977, and the 1976 invention of public-key cryptography. For years afterward, strong cryptography was entangled with government secrecy and export restrictions, a period often called the “crypto wars.” The International Association for Cryptologic Research was organized in the early 1980s. The Advanced Encryption Standard replaced DES in 2001, SHA-3 was standardized in 2015, and the post-quantum standards arrived in 2024. A recurring lesson of this history is that standards are retired when attacks, or increases in computing power, outpace them.
Cryptography in Research Data Protection
For a research institution, cryptography is rarely a research topic and almost always a control. It shows up in at least four places:
- Encryption in transit and at rest — protecting data on networks, laptops, instruments, backups, and cloud storage, which is a baseline expectation in data management plans and many data use agreements.
- Key management — who holds the keys, how they are rotated, and what happens when a researcher leaves. Encryption without disciplined key management either fails to protect the data or locks the institution out of its own records.
- Integrity and provenance — checksums and signatures that show a dataset, code release, or instrument record has not changed since it was captured, which supports reproducibility and research integrity.
- Validated cryptographic modules — in the U.S., federal programs often expect cryptography to be implemented in modules validated under the NIST Cryptographic Module Validation Program. Some sponsor terms for sensitive data point to such expectations, so read the award clause rather than assuming. See CASRAI’s guide to NIST SP 800-171 and CUI in University Research and the dictionary entry for Controlled Unclassified Information.
Encryption is not a substitute for governance. It does not decide who should have access, does not satisfy consent or privacy law on its own, and does not remove the need for a data management plan. It is a control that supports those obligations. The wider obligations of a research institution are covered in NIST Cybersecurity Framework 2.0 for a Federally Funded Research Lab, and the policy layer in Research Security and NSPM-33 Research Security Program Requirements.
Cryptography and Export Control
Cryptography is one of the few areas of mathematics that governments regulate for export. In the United States, items that perform encryption are generally controlled under the Export Administration Regulations (EAR), administered by the Department of Commerce, in the “information security” category of the Commerce Control List, with a set of license exceptions and reporting arrangements that apply to many mass-market and standard products. Internationally, the Wassenaar Arrangement maintains shared control lists for dual-use goods and technologies that include information security, and the European Union implements its own dual-use regime. Rules distinguish among types of items and among published and unpublished material, and they have changed repeatedly since the 1990s, so classification should never be assumed from the topic alone.
For research, the points that matter are practical. Cryptographic software, hardware, and technical data can carry export-control implications when shared with foreign collaborators, shipped abroad, or made accessible to foreign nationals, depending on classification and on whether the material is published or arises from fundamental research. Researchers should not self-classify. They should involve the institution’s export control office early, particularly before international travel with encrypted devices, before building cryptographic hardware, and before sharing non-public code or technical data. CASRAI’s coverage of this area includes ITAR and EAR Compliance for University Research, Export Control Classification, What Are Dual-Use Items?, and Export Control and International Research Collaboration. This page is general education, not legal advice.
Training and Career Paths
Cryptography is studied inside computer science, mathematics, and electrical and computer engineering. Research careers typically run through a PhD, and the strongest preparation combines algebra, number theory, probability, complexity theory, and a working knowledge of systems and programming. Roles outside the academy include cryptographic engineering, protocol and standards work, security consulting, and evaluation roles at government agencies and laboratories. Interdisciplinary entry from mathematics and physics is common, and the field regularly overlaps with mathematics and computer science.
Funders, Venues, and Societies
- Funders — in the United States, the National Science Foundation funds cryptography research, notably through its Secure and Trustworthy Cyberspace (SaTC) program, whose topics of interest include cryptography. Defense and intelligence-community research agencies and industry are also significant funders. Funding structures vary by country, and programs change names and scope over time, so check the current solicitation. Proposal guidance is in How to Apply for an NSF Grant and the NSF grants overview.
- Society — the International Association for Cryptologic Research (IACR), a non-profit scientific organization, was organized at the initiative of David Chaum at the CRYPTO ’82 conference. Its flagship conferences are Crypto, Eurocrypt, and Asiacrypt, with specialist events including Fast Software Encryption, Public Key Cryptography, Cryptographic Hardware and Embedded Systems, the Theory of Cryptography Conference, and the Real World Crypto Symposium. It also publishes the Journal of Cryptology and operates the Cryptology ePrint Archive, where preprints appear before or alongside formal publication.
- Venues — beyond IACR events, cryptography appears at the major security conferences, including the IEEE Symposium on Security and Privacy and the ACM Conference on Computer and Communications Security. As in the rest of computer science, conference papers carry much of the weight that journal articles carry elsewhere, and preprint sharing is the norm, which affects how promotion and grant reviewers from other fields should read a cryptographer’s record.
- Standards bodies — NIST in the United States, and international standards organizations such as ISO/IEC, publish the algorithms and requirements most institutions actually implement.
Links to Research Administration
Research administrators rarely evaluate algorithms, but they meet cryptography constantly: in security clauses in awards, in data use agreements that require encryption, in export-control screening of collaborations and shipments, and in institutional policy on devices and travel. Their role is to read the terms, route questions to information security and export control staff, and make sure the obligations are accounted for in budgets and timelines. See What a Research Administrator Does for the role most directly responsible for that routing, and the overview of the branches of science for how cryptography’s parent disciplines relate.
Frequently Asked Questions
What is cryptography in simple terms?
It is the set of mathematical techniques used to keep information confidential, detect tampering, verify identity, and prove authorship, even when an adversary can see or interfere with the communication.
What is the difference between symmetric and asymmetric encryption?
Symmetric encryption uses one shared secret key for both encrypting and decrypting and is fast. Asymmetric encryption uses a public and private key pair, which solves the problem of agreeing on keys with strangers but is slower. Most real systems combine the two.
Is hashing the same as encryption?
No. Encryption is reversible by someone with the right key. A cryptographic hash is a one-way fingerprint with no key and no decryption. Hashes verify integrity; they do not keep content secret.
What is a digital signature, and is it the same as an electronic signature?
A digital signature is a cryptographic value that proves a message came from the holder of a private key and has not changed. An electronic signature is a legal concept covering many ways of indicating assent. A digital signature can be used to implement an electronic signature, but they are not synonyms.
What is post-quantum cryptography?
It is cryptography designed to resist attacks by future quantum computers while running on ordinary hardware. NIST published its first three post-quantum standards, FIPS 203, FIPS 204, and FIPS 205, on August 13, 2024, and in March 2025 selected HQC as a further key-establishment algorithm.
Do quantum computers already break encryption?
Not at a scale that threatens current standards. The concern is that data protected by today’s public-key methods could be harvested now and decrypted later, which is why long-lived sensitive data is the first priority.
What is the IACR?
The International Association for Cryptologic Research is the main scholarly society for cryptography. It runs the Crypto, Eurocrypt, and Asiacrypt conferences, publishes the Journal of Cryptology, and hosts the Cryptology ePrint Archive.
Who funds cryptography research?
In the U.S., chiefly the National Science Foundation, including through SaTC, plus defense-related agencies and industry. Elsewhere, national and regional research councils fill similar roles.
Is encryption software export controlled?
It can be. Many encryption items are regulated in the U.S. under the EAR, but the outcome depends on the specific item, its classification, and whether it is published. Consult your institution’s export control office before sharing or shipping cryptographic items or technical data.
Does encrypting research data satisfy data protection requirements?
Not by itself. Encryption protects confidentiality when keys are managed well, but consent, access control, retention, and sponsor-specific terms still apply.
Where Cryptography Fits
Cryptography sits at the intersection of mathematics and computer science and underlies most of modern information security. For the surrounding discipline, start with What Is Cybersecurity? and What Is Computer Science?








