QCE exams start Mon 26 Oct — 16 days away

ATARMAxxing · QCE Digital Solutions revision notes

Symmetric and asymmetric encryption: DES, Triple DES, AES, Blowfish, Twofish and RSA

Encryption algorithms
Topic 1 · Unit 4 Topic 1 — Digital methods for exchanging data

What this note covers

  1. Symmetric versus asymmetric: the one distinction every answer needs
  2. DES and Triple DES: why the original standard was retired
  3. AES: the current symmetric default
  4. Blowfish and Twofish: the free alternatives
  5. RSA: public and private keys in practice
  6. Hybrid encryption and how to write the comparison answer

6 sections · 10 key terms & formulas · 6 common mistakes

Free sample

1. Symmetric versus asymmetric: the one distinction every answer needs

Symmetric encryption uses one shared secret key: the same key that turns plaintext into ciphertext also turns the ciphertext back. Asymmetric encryption uses a mathematically linked key pair: a public key that anyone may hold and a private key that only the owner keeps. Data encrypted with the public key can only be decrypted with the matching private key, and a value signed with the private key can be checked by anyone holding the public key.

The trade-off is what the Unit 4 exam tests. Symmetric algorithms are fast and cheap to run on large volumes of data, but both parties must already share the key, and getting that key safely across a network is the key distribution problem. Asymmetric algorithms remove that problem because the public key can be sent openly, but they are far slower and are normally used only on small values such as a session key or a digital signature.

  • Symmetric family named in the syllabus: DES, Triple DES, AES, Blowfish, Twofish.
  • Asymmetric algorithm named in the syllabus: RSA.
  • You must recognise their features; you are not asked to perform their internal mathematics.

Model sentence for a 2-mark ‘distinguish’ item: “Symmetric encryption uses a single shared key for both encryption and decryption, so it is fast but requires a secure way to share the key; asymmetric encryption uses a public key to encrypt and a separate private key to decrypt, which removes the need to share a secret but is computationally slower.” Each half earns a mark only if it states both the key arrangement and a consequence.

2. DES and Triple DES: why the original standard was retired

The Data Encryption Standard (DES) was adopted as a US federal standard in 1977. It is a block cipher: it encrypts fixed 64-bit blocks of data using a 56-bit effective key (the key is stored as 64 bits, with 8 used for parity). Internally it runs 16 rounds of a Feistel structure, where each round splits the block in half, scrambles one half with a round key and swaps the halves.

The weakness is the key length. A 56-bit key gives 256 = 72,057,594,037,927,936 possible keys. That sounds large, but purpose-built hardware searched the whole space in days by the late 1990s, so DES is now considered broken by brute force, not by any clever flaw in its rounds.

Triple DES (3DES) was the stop-gap. It applies DES three times to each block, usually as encrypt–decrypt–encrypt (EDE) with two or three different keys. With three independent keys the nominal key length is 3 × 56 = 168 bits, although a meet-in-the-middle attack reduces its effective strength to about 112 bits. It keeps the small 64-bit block and is roughly three times slower than DES, so it has been phased out in favour of AES; standards bodies no longer approve it for new systems.

FeatureDESTriple DES
Block size64 bits64 bits
Key length56 bits effective112 or 168 bits nominal
SpeedFast for its eraAbout 3× slower
StatusBroken by brute forceLegacy, being retired

3. AES: the current symmetric default

The Advanced Encryption Standard (AES) is the Rijndael algorithm, selected after an open international competition and published as a standard in 2001. It replaced DES as the default symmetric cipher and is what protects most data you meet in Digital Solutions contexts: HTTPS sessions after the handshake, Wi-Fi (WPA2/WPA3), encrypted databases, full-disk encryption and VPN tunnels.

  • Block size: 128 bits (double DES).
  • Key lengths: 128, 192 or 256 bits, using 10, 12 or 14 rounds respectively.
  • Structure: a substitution–permutation network rather than a Feistel network; each round substitutes bytes, shifts rows, mixes columns and adds a round key.
  • Performance: very fast in software, and many processors include dedicated AES instructions in hardware.

The jump in key length matters more than any other feature. AES-128 has 2128 keys, which is 272 times as many as DES; no realistic brute-force search can cover that space. When an exam scenario involves storing or transmitting large volumes of personal data (health records, payment details, student results), AES is the defensible recommendation for data at rest and for the bulk of data in transit.

Exam technique: when asked to recommend an algorithm, name AES, give the key length (for example AES-256), and justify it against the scenario: “AES-256 is a symmetric block cipher with a 256-bit key that cannot practically be brute-forced and is fast enough to encrypt every record in the club’s database without slowing the booking app.”

4. Blowfish and Twofish: the free alternatives

Blowfish was designed by Bruce Schneier in 1993 as a free, unpatented replacement for DES. It is a 64-bit block cipher with a variable key length from 32 to 448 bits and 16 Feistel rounds. Its distinctive feature is key-dependent S-boxes: the substitution tables are generated from the key itself. That makes key setup deliberately slow, which is a disadvantage for systems that change keys often, but an advantage for password hashing; the bcrypt password-hashing function is built on Blowfish’s expensive key schedule.

Blowfish’s weakness is its 64-bit block. When very large amounts of data are encrypted under one key, repeated blocks become statistically likely, which leaks information. For that reason Schneier himself recommends Twofish for new work.

Twofish was one of the five finalists in the AES competition. It uses a 128-bit block, keys up to 256 bits, 16 Feistel rounds and key-dependent S-boxes. It lost the competition to Rijndael mainly on speed in some hardware, not on security, and it remains unpatented and free to use in open-source tools such as disk-encryption software.

BlowfishTwofish
Block64 bits128 bits
Key32–448 bits128, 192 or 256 bits
StructureFeistel, 16 roundsFeistel, 16 rounds
Best known usebcrypt, older VPN toolsOpen-source encryption tools

A distractor that appears in multiple-choice items: Blowfish and Twofish are symmetric, not asymmetric, despite being less familiar than AES.

5. RSA: public and private keys in practice

RSA (Rivest, Shamir and Adleman, 1977) is the asymmetric algorithm in the syllabus. Its security rests on a one-way problem: multiplying two very large prime numbers is easy, but factoring their product back into those primes is computationally infeasible for current computers when the key is long enough. Modern RSA keys are at least 2048 bits, far longer than symmetric keys, because factoring attacks are much more efficient than brute-forcing a symmetric key.

RSA is used in two directions, and exam questions often blur them deliberately:

  • Confidentiality: the sender encrypts with the receiver’s public key; only the receiver’s private key can decrypt.
  • Authenticity and integrity (digital signature): the sender signs a hash of the message with the sender’s private key; anyone can verify the signature with the sender’s public key, proving who sent it and that it was not altered.

Worked scenario. A school canteen app sends a supplier order. To keep the order secret, the app encrypts it with the supplier’s public key. To prove the order really came from the canteen, the app also signs it with the canteen’s private key. The supplier decrypts with its own private key and checks the signature with the canteen’s public key.

RSA is slow (hundreds to thousands of times slower than AES) and can only encrypt a message shorter than its key, so it is not used for bulk data. Saying “RSA encrypts the whole video stream” is a classic error that markers penalise.

6. Hybrid encryption and how to write the comparison answer

Real data exchanges combine both families so that each covers the other’s weakness. In an HTTPS (TLS) connection the browser and server use asymmetric techniques to authenticate the server and agree on a fresh random session key; from then on every request and response is encrypted with a fast symmetric cipher, normally AES, using that session key. The same pattern appears in secure email and many VPN set-ups.

Step sequence you can reproduce in an extended response:

  1. The client requests a secure connection and receives the server’s certificate containing its public key.
  2. The client verifies the certificate, then the two sides establish a random symmetric session key (historically by encrypting it with the server’s RSA public key).
  3. All application data (for example JSON returned by an API) is encrypted with AES under that session key.
  4. The session key is discarded at the end, so a later compromise of one session does not expose others.

When a question says compare, write in matched pairs, using a linking word in every sentence: “Whereas AES uses one 256-bit shared key, RSA uses a 2048-bit key pair; as a result AES suits encrypting the stored records, while RSA suits exchanging the AES key and signing messages.” A list of features for one algorithm followed by a separate list for the other does not demonstrate comparison and usually caps the response at half marks.

For evaluate or recommend items, finish with a judgement tied to the scenario’s constraint (speed on mobile devices, number of users, need to prove identity) rather than a general statement that one algorithm is “more secure”.

Included in the QCE Digital Solutions Mastery Pack

20 full-length practice exams with worked solutions, 20 revision notes, 64 practice questions and 200 flashcards.

Unlock Digital Solutions — $20

Preview a sample note and question free on the QCE Digital Solutions hub →

QCE Digital Solutions · revision note 1 of 20