Why can a code stay unbreakable even if everyone knows how it works?
A former NSA official said the standard assumption there was that serial number one of any new encryption device went straight to the Kremlin. Good cryptographers plan for exactly that.
▶ Start the storyGood cryptography doesn't rely on the enemy never figuring out how your code works. It assumes they already have. Kerckhoffs's principle, named for the 19th-century Dutch cryptographer Auguste Kerckhoffs, holds that a cryptosystem should stay secure even if everything about it, except the key, is public knowledge. A former official at the US National Security Agency told the researcher Steven Bellovin that the standard assumption there was that serial number one of any new encryption device was delivered straight to the Kremlin. Claude Shannon put it more plainly: design your systems assuming the enemy knows them in detail.
This idea sounds backwards until you see the alternative. A system that needs its whole design kept secret for the long term cannot achieve real security: it only replaces one hard problem with another. Secure cryptography is supposed to replace that enormous problem with a much smaller one: instead of keeping a whole complicated system secret forever, you only need to keep a relatively small key secret.
The extreme case of a key doing all the work is the one-time pad, a cipher that is mathematically proven unbreakable, not merely 'very hard to crack'. It works by pairing a message with a truly random key at least as long as the message itself; combine them correctly, and the result is unbreakable, but only if the key is used once, is genuinely random, and stays completely secret. To protect them, one-time pads were sometimes printed on sheets of highly flammable nitrocellulose, so they could easily be burned after use.
Step 1: Key as long as the message
Never shorter than the text it protects
Step 2: Truly random
No pattern an enemy could predict
Step 3: Never reused
Each key is used exactly once
Step 4: Kept completely secret
Sometimes printed on paper made to burn
This is also why modern systems split keys into two kinds. In symmetric cryptography, both sides share one secret key; in asymmetric cryptography, there's a public key anyone can see and a private key that must stay hidden. Either way, the lesson traces straight back to Kerckhoffs: the design can be public, and the entire security of the system rests on keeping the key secret.
Quiz me
0/3
Recap
A cryptosystem's algorithm can be completely public; as long as the key stays secret, random, and (for a one-time pad) used only once, the message stays unbreakable.
Surprising fact · The one-time pad is the only known encryption method mathematically proven unbreakable, provided its random key is used only once and kept secret, and agents sometimes printed these keys on paper designed to burn instantly.
Sources (3)
No source, no claim. Every fact in this lesson (14 claims) cites at least one of these.