A Cryptographic Algorithm is a precisely defined mathematical procedure that transforms data to achieve security properties—confidentiality, integrity, authentication, or non-repudiation—based on computational hardness assumptions. The class encompasses symmetric ciphers, asymmetric (public-key) schemes, hash functions, digital signature algorithms, and zero-knowledge proof systems, each providing different security guarantees and performance characteristics.

Content

  • Cryptographic algorithms have roots in classical substitution and transposition ciphers, but modern algorithmic cryptography began with Shannon’s 1949 paper establishing information-theoretic foundations of secrecy. The pivotal public-key revolution arrived with Diffie and Hellman’s 1976 “New Directions in Cryptography” paper and Rivest, Shamir, and Adleman’s RSA scheme (1977), which demonstrated that two parties could establish a shared secret over a public channel without prior key exchange—solving the key distribution problem that had constrained symmetric cryptography for centuries. National standardisation processes formalised AES (2001, Rijndael cipher selected from open competition) and SHA-2/3 families.
  • The technical taxonomy of cryptographic algorithms includes: (1) Symmetric-key ciphers—block ciphers (AES-128/256 in CBC, GCM, CCM modes; ChaCha20-Poly1305) and stream ciphers; (2) Asymmetric schemes—RSA (2048/4096-bit), Elliptic Curve Cryptography (P-256, Curve25519, secp256k1), and lattice-based post-quantum algorithms (CRYSTALS-Kyber for key encapsulation, CRYSTALS-Dilithium for signatures); (3) Hash functions—SHA-256, SHA-3 (Keccak), BLAKE3; (4) Message authentication codes—HMAC, CMAC, Poly1305; (5) Digital signatures—ECDSA, EdDSA (Ed25519); (6) Zero-knowledge systems—zk-SNARKs (Groth16), zk-STARKs, Bulletproofs. Security proofs reduce algorithm security to hardness of underlying mathematical problems.
  • Cryptographic algorithms are standardised through NIST (FIPS publications), IETF (RFC series), and ISO (18033 series). The OpenSSL and BoringSSL libraries implement the majority of production algorithms used in TLS 1.3, SSH, and IPsec. Hardware acceleration is ubiquitous: Intel AES-NI instructions accelerate AES at near-memory-bandwidth speeds, ARM Crypto Extensions accelerate AES and SHA on mobile processors, and dedicated hardware security modules (HSMs) from Thales and Entrust provide tamper-resistant key storage and algorithm execution for high-assurance applications.
  • In 2024–2025, the primary development is NIST’s post-quantum cryptography standardisation, finalised in 2024 with FIPS 203 (ML-KEM/Kyber), FIPS 204 (ML-DSA/Dilithium), and FIPS 205 (SLH-DSA/SPHINCS+) as the first approved post-quantum standards. Migration to PQC is now mandatory for US federal systems by 2035, driving large-scale cryptographic agility projects. TLS 1.3 hybrid key exchange (classical ECDH plus Kyber) is being deployed by Cloudflare, Google, and AWS to provide harvest-now-decrypt-later protection. Simultaneously, homomorphic encryption algorithms (BFV, CKKS, TFHE) are moving from research to production in privacy-preserving analytics and federated computation platforms.