What Is Public-Key Cryptography?

Public-key cryptography uses a mathematically linked pair of keys — one public, one private — so that what one key does, only the other can undo. Anyone can encrypt to your public key, but only your private key decrypts; and only your private key can sign, while anyone can verify with the public one. Introduced by Diffie and Hellman in 1976, it is the basis of signatures, passkeys and most agent identity.

Keys
A linked public/private pair
Origin
Diffie–Hellman, 1976
Underpins
Signatures, TLS, passkeys, DIDs

Why a pair changes everything

Before public-key cryptography, two parties had to share a secret in advance to communicate securely — a problem that does not scale to strangers. A key pair removes that: you publish one half and keep the other, so anyone can send you something only you can open, or verify something only you could have signed, with no prior contact.

For agents acting across organisations that never coordinated, this is the enabling primitive: identity and authority can be a key the actor holds, and verification is something anyone recomputes rather than a secret anyone must be trusted with.

Related standards

Diffie–Hellman, 1976 — New Directions in Cryptography

Questions

Is public-key cryptography the same as encryption?

It is a kind of it — asymmetric encryption — but it also enables signatures and key exchange, which are not encryption at all.

Why not just use it for everything?

It is slow for bulk data, so systems use it to exchange a fast symmetric key and encrypt the data with that.

Keep reading

related
What Is a Digital Signature?
related
Symmetric vs Asymmetric Encryption: What’s the Difference?
related
What Are WebAuthn and Passkeys?
related
Key Management for AI Agents
referenced by
What Is Mutual TLS (mTLS)?
Trust & the Record
Verify, Don’t Trust: Verification for AI Agents
Trust & the Record
Provenance for Autonomous Actions
Trust & the Record
How Is AI Agent Reputation Earned and Verified?
Trust & the Record
Zero-Trust Architecture for AI Agents
Trust & the Record
What Is Agent Attestation?
Trust & the Record
What Is a Trust Graph for Agents?
Trust & the Record
What Is a Zero-Knowledge Proof?
Trust & the Record
What Is a zk-Rollup?
Trust & the Record
What Is a Merkle Tree?
Trust & the Record
What Is a Blockchain Oracle?
Trust & the Record
What Is Confidential Computing?
Trust & the Record
zk-Rollup vs Optimistic Rollup: What’s the Difference?
Trust & the Record
TEEs vs Zero-Knowledge Proofs: Two Roads to Privacy
Trust & the Record
What Is a Cryptographic Hash Function?
Trust & the Record
What Is a Sybil Attack?
Trust & the Record
What Is Certificate Transparency?
Trust & the Record
Hashing vs Encryption: What’s the Difference?

By Michael Gord · published 2026-10-09 · part of the Agentic Encyclopedia. Dates are the day of publication; events are cited at their own dates.