An asymmetric-key algorithm uses a related pair of keys: a public key that can be shared and a private key that is kept secret. Depending on the algorithm and protocol, the keys can support encryption and decryption, digital signatures, or key agreement. These are distinct operations; not every asymmetric algorithm does all three.
What do the public and private keys do?
The keys are related but distinct. The public key may be distributed, while its corresponding private key is kept secret. Their roles depend on the operation being performed, as the NIST CSRC glossary entry for asymmetric-key cryptography explains.
How the three operations differ
| Operation | Typical key roles | Goal |
|---|---|---|
| Public-key encryption | Encrypt with the recipient’s public key; decrypt with the corresponding private key | Confidentiality for the protected material |
| Digital signature | Generate a signature with the private key; verify it with the corresponding public key | Authenticity and integrity, not confidentiality |
| Key agreement | Use related key material in an agreed protocol to compute a shared secret | Establish shared secret material |
This is a conceptual comparison, not a claim that every algorithm supports every operation. Which operations are available depends on the algorithm and protocol; NIST describes public-key uses that include encryption, signatures, and computing a shared secret in its public-key glossary entry.
What a digital signature does—and does not do
A signer uses the private key to generate a signature, and another party uses the corresponding public key to verify it. Verification supports confidence in the message’s authenticity and integrity. It does not conceal the message: NIST states that digital signatures provide authenticity, integrity, and non-repudiation protections, but not confidentiality, in Special Publication 800-63-3.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
A signature is therefore not simply “encrypting with the private key.” Signing and verification are signature operations, separate from encryption and decryption.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Why the term is broader than encryption
“Asymmetric” describes the use of separate, related keys for complementary operations; it does not name one universal operation. Some public-key systems are used for encryption, others for signatures or key agreement, and a protocol may combine operations for different purposes. The term “asymmetric-key algorithm” should not be taken to mean that an arbitrary public key can encrypt arbitrary data.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




