Encryption and Decryption Explained
One key or two, reversible or one-way. Three distinctions cover most of what the exam asks about encryption.
Encryption turns readable data (plaintext) into scrambled data (ciphertext) using a key. Decryption reverses it, and only someone with the right key can do that. If a laptop with encrypted customer files is stolen from a branch, the thief has a disk full of noise.
For the exam, encryption sits in Unit 6 as a fraud protection control. You need three distinctions: symmetric versus asymmetric encryption, encryption versus hashing, and data at rest versus data in transit.
You save ₹300
- Full 120-question mocks
- Cyber law coverage
- Module-wise practice
One payment, no subscription · Valid for 2 months
Symmetric vs Asymmetric
Keys
Symmetric
One shared secret key encrypts and decrypts
Asymmetric (public key)
A key pair: a public key anyone can have and a private key only the owner holds
Speed
Symmetric
Fast, suits large volumes of data
Asymmetric (public key)
Slower, used for small pieces such as keys and signatures
Main problem
Symmetric
Getting the shared key safely to the other side
Asymmetric (public key)
Proving a public key really belongs to the person claimed
Common examples
Symmetric
AES
Asymmetric (public key)
RSA, elliptic curve
Banking use
Symmetric
Encrypting databases, disks and backups
Asymmetric (public key)
Exchanging keys at the start of a secure session; digital signatures
| Symmetric | Asymmetric (public key) | |
|---|---|---|
| Keys | One shared secret key encrypts and decrypts | A key pair: a public key anyone can have and a private key only the owner holds |
| Speed | Fast, suits large volumes of data | Slower, used for small pieces such as keys and signatures |
| Main problem | Getting the shared key safely to the other side | Proving a public key really belongs to the person claimed |
| Common examples | AES | RSA, elliptic curve |
| Banking use | Encrypting databases, disks and backups | Exchanging keys at the start of a secure session; digital signatures |
How They Work Together
When a customer opens net banking, the browser and the bank's server use asymmetric encryption to agree a fresh symmetric key, then switch to that symmetric key for the rest of the session. This is what TLS (the padlock in the address bar) does. Each method covers the other's weakness: asymmetric solves key exchange, symmetric does the heavy lifting.
In asymmetric encryption, the direction matters. To send something only the bank can read, encrypt it with the bank's public key; only the bank's private key opens it. To prove something came from the bank, the bank signs with its private key and anyone verifies with its public key. The second use is a digital signature.
Terms the Exam Uses
- Hashing
- A one-way function that turns any data into a short fixed-length value. The IT Act describes a hash function as one where the same record always gives the same hash, and it is computationally infeasible to rebuild the record from the hash or to find two records with the same hash. Hashing is not encryption: there is no key and no way back.
- Data at rest
- Stored data: databases, disks, backups, a laptop's hard drive.
- Data in transit
- Data moving across a network: a fund transfer request, an email, a card authorisation. Protected by TLS or a VPN.
- End-to-end encryption
- Only the sender and recipient can decrypt. Servers in between see only ciphertext.
- Key management
- Generating, storing, rotating and destroying keys. Strong encryption with a key stored next to the data protects nothing. Banks typically keep critical keys in hardware security modules (HSMs).
Quick practice on banking operations. No signup.
Rules That Apply
| Source | What it says |
|---|---|
| RBI Cybersecurity Directions, 2026 | Key lengths, algorithms, cipher suites and protocols must be strong, following internationally accepted published standards that are not deprecated or shown to be insecure |
| RBI Cybersecurity Directions, 2026 | Protect data at rest (for example by encryption where the device supports it) and in transit (for example by VPN or other secure protocols) |
| IT Act s.84A | The Central Government may prescribe modes or methods for encryption, for secure use of the electronic medium |
| IT Act s.69 | The Central or State Government may, for reasons recorded in writing and on specified grounds, direct an agency to intercept, monitor or decrypt information, and the person in charge of the computer resource must assist |
How the IIBF Exam Tests This
- check_circleWhich key does what: encrypting for confidentiality uses the recipient's public key; signing uses the sender's private key. The swap is the standard trap.
- check_circleHashing versus encryption: a question describing a fixed-length value that cannot be reversed is describing a hash.
- check_circleSymmetric means one key. If an option says 'two different keys', it is describing asymmetric.
- check_circleEncryption protects confidentiality. It does not stop a fraud where the genuine customer is tricked into authorising a payment.
FAQs
What is the difference between encryption and decryption?expand_more
Encryption converts readable data into ciphertext using a key; decryption converts ciphertext back into readable data using the right key. Without the key, the ciphertext is unusable.
What is the difference between symmetric and asymmetric encryption?expand_more
Symmetric encryption uses one shared key for both steps and is fast. Asymmetric encryption uses a public and private key pair and is slower, so it is used mainly for exchanging keys and for digital signatures.
Is hashing the same as encryption?expand_more
No. Encryption can be reversed with the key. Hashing is one-way: it produces a fixed-length value from which the original data cannot be rebuilt. It is used to check integrity, for example to show evidence has not changed.
Which section of the IT Act deals with encryption?expand_more
Section 84A lets the Central Government prescribe modes or methods for encryption. Section 69 lets authorised government agencies direct decryption of information on specified grounds, with a duty on the person in charge of the system to assist.
Next steps
Take a full IIBF Cyber Crimes mock test120 questions, 2 hours, scored instantly.
