← All subjects
Get this Mastery Pack — A$20 once

Digital resources for QCE Digital Solutions. No subscription. Review the free samples before you decide.

QCE Units 3 & 4

QCE Digital Solutions Mastery Pack

Master encryption, privacy, data exchange, pseudocode and SQL with desk-checked algorithms, original practice questions and Unit 4 exam preparation.

QCE exams start Mon 26 Oct — 16 days away

Explore the study materials

Sample revision note

Symmetric and asymmetric encryption: DES, Triple DES, AES, Blowfish, Twofish and RSA

1. Symmetric versus asymmetric: the one distinction every answer needs

Symmetric encryption uses one shared secret key: the same key that turns plaintext into ciphertext also turns the ciphertext back. Asymmetric encryption uses a mathematically linked key pair: a public key that anyone may hold and a private key that only the owner keeps. Data encrypted with the public key can only be decrypted with the matching private key, and a value signed with the private key can be checked by anyone holding the public key.

The trade-off is what the Unit 4 exam tests. Symmetric algorithms are fast and cheap to run on large volumes of data, but both parties must already share the key, and getting that key safely across a network is the key distribution problem. Asymmetric algorithms remove that problem because the public key can be sent openly, but they are far slower and are normally used only on small values such as a session key or a digital signature.

  • Symmetric family named in the syllabus: DES, Triple DES, AES, Blowfish, Twofish.
  • Asymmetric algorithm named in the syllabus: RSA.
  • You must recognise their features; you are not asked to perform their internal mathematics.

Model sentence for a 2-mark ‘distinguish’ item: “Symmetric encryption uses a single shared key for both encryption and decryption, so it is fast but requires a secure way to share the key; asymmetric encryption uses a public key to encrypt and a separate private key to decrypt, which removes the need to share a secret but is computationally slower.” Each half earns a mark only if it states both the key arrangement and a consequence.

2. DES and Triple DES: why the original standard was retired

The Data Encryption Standard (DES) was adopted as a US federal standard in 1977. It is a block cipher: it encrypts fixed 64-bit blocks of data using a 56-bit effective key (the key is stored as 64 bits, with 8 used for parity). Internally it runs 16 rounds of a Feistel structure, where each round splits the block in half, scrambles one half with a round key and swaps the halves.

The weakness is the key length. A 56-bit key gives 256 = 72,057,594,037,927,936 possible keys. That sounds large, but purpose-built hardware searched the whole space in days by the late 1990s, so DES is now considered broken by brute force, not by any clever flaw in its rounds.

Triple DES (3DES) was the stop-gap. It applies DES three times to each block, usually as encrypt–decrypt–encrypt (EDE) with two or three different keys. With three independent keys the nominal key length is 3 × 56 = 168 bits, although a meet-in-the-middle attack reduces its effective strength to about 112 bits. It keeps the small 64-bit block and is roughly three times slower than DES, so it has been phased out in favour of AES; standards bodies no longer approve it for new systems.

FeatureDESTriple DES
Block size64 bits64 bits
Key length56 bits effective112 or 168 bits nominal
SpeedFast for its eraAbout 3× slower
StatusBroken by brute forceLegacy, being retired

3. AES: the current symmetric default

The Advanced Encryption Standard (AES) is the Rijndael algorithm, selected after an open international competition and published as a standard in 2001. It replaced DES as the default symmetric cipher and is what protects most data you meet in Digital Solutions contexts: HTTPS sessions after the handshake, Wi-Fi (WPA2/WPA3), encrypted databases, full-disk encryption and VPN tunnels.

  • Block size: 128 bits (double DES).
  • Key lengths: 128, 192 or 256 bits, using 10, 12 or 14 rounds respectively.
  • Structure: a substitution–permutation network rather than a Feistel network; each round substitutes bytes, shifts rows, mixes columns and adds a round key.
  • Performance: very fast in software, and many processors include dedicated AES instructions in hardware.

The jump in key length matters more than any other feature. AES-128 has 2128 keys, which is 272 times as many as DES; no realistic brute-force search can cover that space. When an exam scenario involves storing or transmitting large volumes of personal data (health records, payment details, student results), AES is the defensible recommendation for data at rest and for the bulk of data in transit.

Exam technique: when asked to recommend an algorithm, name AES, give the key length (for example AES-256), and justify it against the scenario: “AES-256 is a symmetric block cipher with a 256-bit key that cannot practically be brute-forced and is fast enough to encrypt every record in the club’s database without slowing the booking app.”

4. Blowfish and Twofish: the free alternatives

Blowfish was designed by Bruce Schneier in 1993 as a free, unpatented replacement for DES. It is a 64-bit block cipher with a variable key length from 32 to 448 bits and 16 Feistel rounds. Its distinctive feature is key-dependent S-boxes: the substitution tables are generated from the key itself. That makes key setup deliberately slow, which is a disadvantage for systems that change keys often, but an advantage for password hashing; the bcrypt password-hashing function is built on Blowfish’s expensive key schedule.

Blowfish’s weakness is its 64-bit block. When very large amounts of data are encrypted under one key, repeated blocks become statistically likely, which leaks information. For that reason Schneier himself recommends Twofish for new work.

Twofish was one of the five finalists in the AES competition. It uses a 128-bit block, keys up to 256 bits, 16 Feistel rounds and key-dependent S-boxes. It lost the competition to Rijndael mainly on speed in some hardware, not on security, and it remains unpatented and free to use in open-source tools such as disk-encryption software.

BlowfishTwofish
Block64 bits128 bits
Key32–448 bits128, 192 or 256 bits
StructureFeistel, 16 roundsFeistel, 16 rounds
Best known usebcrypt, older VPN toolsOpen-source encryption tools

A distractor that appears in multiple-choice items: Blowfish and Twofish are symmetric, not asymmetric, despite being less familiar than AES.

5. RSA: public and private keys in practice

RSA (Rivest, Shamir and Adleman, 1977) is the asymmetric algorithm in the syllabus. Its security rests on a one-way problem: multiplying two very large prime numbers is easy, but factoring their product back into those primes is computationally infeasible for current computers when the key is long enough. Modern RSA keys are at least 2048 bits, far longer than symmetric keys, because factoring attacks are much more efficient than brute-forcing a symmetric key.

RSA is used in two directions, and exam questions often blur them deliberately:

  • Confidentiality: the sender encrypts with the receiver’s public key; only the receiver’s private key can decrypt.
  • Authenticity and integrity (digital signature): the sender signs a hash of the message with the sender’s private key; anyone can verify the signature with the sender’s public key, proving who sent it and that it was not altered.

Worked scenario. A school canteen app sends a supplier order. To keep the order secret, the app encrypts it with the supplier’s public key. To prove the order really came from the canteen, the app also signs it with the canteen’s private key. The supplier decrypts with its own private key and checks the signature with the canteen’s public key.

RSA is slow (hundreds to thousands of times slower than AES) and can only encrypt a message shorter than its key, so it is not used for bulk data. Saying “RSA encrypts the whole video stream” is a classic error that markers penalise.

6. Hybrid encryption and how to write the comparison answer

Real data exchanges combine both families so that each covers the other’s weakness. In an HTTPS (TLS) connection the browser and server use asymmetric techniques to authenticate the server and agree on a fresh random session key; from then on every request and response is encrypted with a fast symmetric cipher, normally AES, using that session key. The same pattern appears in secure email and many VPN set-ups.

Step sequence you can reproduce in an extended response:

  1. The client requests a secure connection and receives the server’s certificate containing its public key.
  2. The client verifies the certificate, then the two sides establish a random symmetric session key (historically by encrypting it with the server’s RSA public key).
  3. All application data (for example JSON returned by an API) is encrypted with AES under that session key.
  4. The session key is discarded at the end, so a later compromise of one session does not expose others.

When a question says compare, write in matched pairs, using a linking word in every sentence: “Whereas AES uses one 256-bit shared key, RSA uses a 2048-bit key pair; as a result AES suits encrypting the stored records, while RSA suits exchanging the AES key and signing messages.” A list of features for one algorithm followed by a separate list for the other does not demonstrate comparison and usually caps the response at half marks.

For evaluate or recommend items, finish with a judgement tied to the scenario’s constraint (speed on mobile devices, number of users, need to prove identity) rather than a general statement that one algorithm is “more secure”.

Sample exam question
A council app lets residents report damaged footpaths. The level 1 DFD contains: external entity Resident; external entity Works Crew; process 1 Validate report; process 2 Assign job; data store D1 Reports; data store D2 Crew roster. Flows: Resident → 1 (report details + photo); 1 → D1 (validated report); 1 → Resident (reference number); D1 → 2 (open reports); D2 → 2 (available crews); 2 → Works Crew (job sheet); 2 → D1 (job status). Explain the relationships between the external entity Resident and each process and data store in this DFD.
Show the worked answer

Answer: Worked solution

Resident and process 1 Validate report. Resident is the source of the data the system works on: it sends report details and a photo into process 1. Process 1 transforms that input (checking location, required fields and image format) and sends a reference number back to Resident, so the relationship is a two-way request/reply between an external entity and a process.

Resident and data store D1 Reports. Resident has no direct flow to D1. Under Gane–Sarson rules an entity cannot write to a store directly; data must be processed first. The resident's report reaches D1 only as the validated report output of process 1, which protects the integrity of stored data because unchecked input is never stored.

Resident and process 2 Assign job. Resident is indirectly related to process 2: process 2 reads the open reports that originated with residents from D1. Resident never communicates with process 2, which keeps crew scheduling inside the system.

Resident and data store D2 Crew roster. There is no relationship. D2 is read only by process 2; residents have no need to see crew rosters, so leaving them unlinked also limits exposure of staff information.

Marking focus: one mark for each correctly explained relationship (including the two indirect or absent ones) plus marks for using correct DFD terminology (entity, process, store, flow) and the rule that entities exchange data with stores only via processes.

What's inside Digital Solutions

20full-length model exams with mark-by-mark answer guides
20detailed note sets — ~200 pages across every topic
64exam-style practice questions with worked solutions
200flashcards for every key term & formula
16official past papers

Preview it all free. Unlock when you're ready.

Unlock the original practice exams, answer guides, worked questions and digital flashcards. Complete revision notes are also available free. From $20 once for one subject, with access while the platform operates.

Taking more subjects? Add two more for $30 — three subjects for $50 total, $16.67 each, all yours for life.

Compare 1, 3 or 5 subjects ▾
  • 1 subject — $20 once
    Digital Solutions only
    Unlock 1
  • 3 subjects — $50 once
    $16.67 a subject · pick the rest after you pay
    Unlock 3
  • 5 subjects — $60 once
    $12 a subject · pick the rest after you pay
    Unlock 5

Each selected subject includes its complete Mastery Pack. Choose how many subjects you need. Full pricing page →

No account needed · one-time payment in AUD · digital resources · by purchasing you agree to our Terms.

QCE exams start Mon 26 Oct — 16 days away

Our promise: see the real material before you pay — a worked exam question, the opening of a real revision note and the full contents list of all 20 revision notes and 20 practice exams are on this page, free. If you unlock it and it isn't what this page described, email hello@atarmaxxing.com.au and we'll refund it — no form, no argument. We won't promise you an ATAR; we promise the material is what we said it was.

Everything you unlock

All 20 practice exams

  1. Exam 1 — RSA versus AES for a payment gateway; Data flow diagram of a click-and-collect service; Desk check of a JSON averaging algorithm
  2. Exam 2 — Vigenère and Gronsfeld cipher evaluation; Australian Privacy Principles in a gym access system; SQL with GROUP BY and HAVING
  3. Exam 3 — One-time pad algorithm in pseudocode; Hashing and salting stored passwords; XML structure for an event ticket
  4. Exam 4 — Data flow diagram for a library reservation system; Constraints on a volunteer-built app; Correcting errors in a Caesar cipher algorithm
  5. Exam 5 — JSON processing for an esports ladder; Risks to data availability during a DDoS attack; Packet switching and error detection
  6. Exam 6 — Symbolising a secure login with hashing; SQL inner joins on a sports club database; Desk checking a nested loop
  7. Exam 7 — REST API design for a weather service; Data integrity: completeness and consistency; Caesar versus one-time pad security
  8. Exam 8 — Gronsfeld cipher in pseudocode; Data flow diagram for a pharmacy e-script; Biometric authentication ethics
  9. Exam 9 — Data dictionary for a citizen-science bird survey; Validation of user inputs in pseudocode; VPN and HTTPS for remote workers
  10. Exam 10 — Explaining DFD relationships for a parcel locker system; Hash functions and checksums in file downloads; SQL sub-selection
  11. Exam 11 — Pseudocode to merge two JSON data sources; Risks in a hospital patient wristband system; XML versus JSON payload size
  12. Exam 12 — Vigenère encryption desk check; Data flow diagram for a sports registration portal; Authentication with verification codes
  13. Exam 13 — Constraints and success criteria for a fundraising app; Integrity risks from manual data entry; SQL UPDATE and ALTER statements
  14. Exam 14 — One-time pad data flow diagram; Ethics of facial recognition in retail; Pseudocode to calculate percentages from JSON
  15. Exam 15 — Data dictionary for an energy-use data set; Caesar cipher pseudocode with modulus; Recommending security strategies at exchange points
  16. Exam 16 — Data flow diagram for an online voting system; Australian Privacy Principles and consent; SQL GROUP BY and ORDER BY on results
  17. Exam 17 — Desk check of an XOR-based encryption; Network protocols for a file-sharing service; Completeness and consistency in sensor logs
  18. Exam 18 — Payment data exchange vulnerabilities; Pseudocode for input validation and error messages; Data flow diagram for a food bank stock system
  19. Exam 19 — Symmetric versus asymmetric key exchange; JSON API responses for a bus tracker; SQL inner join and HAVING
  20. Exam 20 — Gronsfeld versus Vigenère key strength; Data flow diagram for a clinic referral system; Correcting a one-time pad algorithm

All 20 revision notes

  • Symmetric and asymmetric encryption: DES, Triple DES, AES, Blowfish, Twofish and RSA
  • Caesar, Vigenère, Gronsfeld and one-time pad: how they work and how to evaluate their security
  • Hashing, checksums, compression and encryption in the storage and transfer of data
  • Authentication: passwords, verification codes, biometrics and 2FA/MFA compared
  • The Australian Privacy Principles and ethics for personally identifiable and sensitive data
  • Network transmission principles, protocols and performance metrics: TCP/IP, HTTP, FTP, VPN, latency, jitter and QoS
  • REST, APIs, JSON and XML: how front-end and back-end sub-systems exchange data
  • Machine learning, deep learning, neural networks, NLP and reinforcement learning in data exchange
  • Analysing data exchange problems: scope, constraints, requirements, decomposition and success criteria
  • Risks to confidentiality, integrity, availability and privacy, and the strategies that reduce them
  • Data completeness, consistency and integrity: data dictionaries, data types and naming conventions
  • Data flow diagrams: symbolising and explaining external entities, processes, data stores and flows
  • Algorithm constructs, programming features, operators and variable scope in pseudocode
  • Desk checks, trace tables, debugging and correcting algorithms
  • Writing pseudocode for Caesar, Vigenère, Gronsfeld and one-time pad algorithms
  • Pseudocode that reads, processes and displays JSON and XML data using code libraries
  • SQL for data exchange solutions: CREATE, ALTER, INSERT, UPDATE, SELECT, GROUP BY, HAVING, sub-selections and inner joins
  • Evaluating solutions and impacts: success criteria, good programming practice and justified recommendations
  • Useability principles in exam responses: accessibility, effectiveness, safety, utility and learnability
  • Visual communication elements and principles, and annotated user-interface mock-ups

Common questions about QCE Digital Solutions

Does the external assessment examine Unit 3?

No. The syllabus says the examination consists of questions relating to Unit 4 (Digital impacts). Unit 3 is assessed internally, although its foundations such as useability principles, visual communication, DFDs, SQL and pseudocode reappear in Unit 4 subject matter.

How many marks is the Digital Solutions external assessment?

The syllabus fixes no total. Published papers were 72 (2021), 69 (2022), 69 (2023), 66 (2024) and 67 (2025) marks. Section 1 has always been 10 one-mark multiple choice questions. The practice papers here use 67 marks, the most recent real total.

How much perusal time is there, and can I use a calculator?

From 2026 perusal is 5 minutes (it was 15 minutes on the 2021-2025 papers) and working time is 120 minutes. A QCAA-approved non-programmable scientific calculator is permitted.

Which pseudocode style should I use?

Generic pseudocode suitable for any language: BEGIN/END, clear indentation, keywords such as IF/THEN/ELSE/ENDIF, FOR/ENDFOR and WHILE/ENDWHILE, meaningful variable names and comments. Marking guides reward unambiguous control structures and correct logic, not one language's syntax.

Which ciphers do I need to be able to work with?

Analyse, evaluate and write pseudocode for Caesar, Vigenère, Gronsfeld and one-time pad ciphers. For DES, Triple DES, AES, Blowfish, Twofish and RSA you need to recognise and describe features and differences, not implement them.

Are the 2021-2025 past papers still useful?

Yes for question style, command words and marking expectations, but they were set under the 2019 syllabus. The 2025 v1.4 syllabus adds APIs to methods of data exchange and revises some terminology, so practise API and REST questions as well.

How does Digital Solutions scale?

In QTAC's ATAR Report 2025, Digital Solutions had a median raw result of 78 and a median scaled result of 80.34 out of 100; at the 90th percentile a raw 94 corresponded to a scaled 92.86. That describes one cohort, not a formula for your own result.

Does QCE Digital Solutions scale up or down?

Digital Solutions scales up slightly at the middle of the cohort. In QTAC's 2025 ATAR report the median raw result of 78 scaled to 80.34 out of 100, while a 90th-percentile raw result of 94 scaled to 92.86. Scaling is recalculated every year, so this describes a past cohort rather than the year you are sitting.

What is included in the QCE Digital Solutions Mastery Pack?

Original practice exams with answer guides, worked questions, digital flashcards and revision notes for Digital Solutions. Complete revision notes are also available free. Official past papers are free external links, not material we sell. Preview the sample note, worked question and contents here. Paid resources unlock with a one-time purchase from $20, with access while the platform operates.

Where can I buy QCE Digital Solutions notes and practice exams?

You can buy the Digital Solutions Mastery Pack here as a one-time purchase: original practice exams with answer guides, revision notes, worked questions and flashcards. Printed study guides, trial-exam packs and student note marketplaces are other options, and official QCAA past papers are free — see the past-paper index for this subject.

Is the QCE Digital Solutions Mastery Pack a subscription?

No. It is a single payment per subject with no renewal, and access continues while the platform operates. You can preview a sample note, a worked question and the full contents before paying.

More detail: the syllabus explained · every official past paper by topic · how Digital Solutions scales · all 20 Digital Solutions revision notes · Digital Solutions practice exams with worked solutions

Explore more QCE subjects

Browse all QCE subjects →

Original study materials written to the public QCAA General senior syllabus. Indicative answer guides show the kind of points that earn marks. Not affiliated with the QCAA. See our Terms & Conditions.