What is Encryption?
Encryption transforms plaintext into ciphertext under a cryptographic key. Symmetric encryption uses a shared secret key. Asymmetric cryptography uses a related public and private key pair, but not every use encrypts data. Key establishment and digital signatures are also common. Encryption provides confidentiality. Authenticated encryption also detects unauthorized changes. Peer authentication requires an authenticated protocol and a validated peer credential.
Why it matters
Encryption limits who can read protected data when storage or a communication path is observed. Secure key management and authenticated protocols are necessary for reliable protection.
How it works
- The system selects an approved algorithm, protocol, key, and nonce or initialization value for the use case.
- It encrypts plaintext and, with authenticated encryption, creates an authentication tag for the ciphertext and associated data.
- The receiver verifies the protected data, decrypts it with the required key, and rejects any failed verification.
Example
A TLS 1.3 connection uses public-key operations to authenticate and establish shared keys. It then uses symmetric authenticated encryption to protect application records.
Pomerium boundary
Pomerium uses TLS on the client-to-Pomerium path and can use TLS on the Pomerium-to-upstream path. It can require a trusted client certificate on the downstream connection or present a configured client certificate on the upstream connection.
Limits and non-claims
- Data is normally plaintext at an authorized endpoint before encryption or after decryption.
- A stolen key or incorrect certificate validation can defeat the intended protection.
- Encryption alone does not authorize a user or operation, and unauthenticated encryption does not ensure integrity.
Evaluation checklist
- Which data needs confidentiality or integrity, and at which storage and transport boundaries?
- Who owns the keys, algorithms, nonces, rotation, recovery, and validation rules?
- Where does plaintext still exist, and which authorization decisions remain separate?
