You’ve probably seen the little padlock in your browser and moved on without thinking about it. Fair enough. Behind that tiny icon, though, TLS uses public key cryptography to solve a surprisingly awkward problem: how can your browser trust a website and create a secure connection when they’ve never talked before?

Public Keys Start the Conversation

Public key cryptography gives each side a key pair. One key is public and can be shared openly. The other stays private. The useful part is that information involving one key can be handled in a way that depends on the matching key, without exposing the private key itself.

TLS uses this idea mainly during the handshake.

The Certificate Matters

• The public key is safe to share. That’s the whole point, so the website doesn’t need to hide it in some secret corner.

• A trusted certificate gives the browser something to verify, although the exact checks depend on the certificate and TLS setup.

Then TLS Creates a Shared Secret

Public key cryptography isn’t normally used to encrypt every piece of data you send. That would be inefficient. Instead, TLS uses public key cryptography during the handshake to establish shared secret material, then switches to symmetric encryption for the actual connection.

With modern TLS, this is commonly done through an ephemeral key exchange such as ECDHE. Your browser and the server each create temporary key information. They exchange public parts and independently calculate the same shared secret. An outsider can see the public information moving across the network but can’t calculate that secret from it.

So the public key gets the conversation started. Symmetric encryption handles the long conversation afterward. Honestly, that’s a much cleaner design.

Why Not Use Public Key Encryption for Everything?

Because speed matters. Symmetric encryption is far more efficient for handling large amounts of data, which is exactly what happens once you’re browsing a site, uploading a file, or watching something.

Public key cryptography has a different job. It helps with authentication and key establishment. Once TLS has done that work, symmetric encryption takes over and gets out of the way.

What This Looks Like in Real Life

• Certificate verification happens early, before the secure session settles into normal data transfer.

• The temporary keys are especially useful for modern TLS because each connection gets fresh key material, which is a design I much prefer to old-school schemes that relied on one long-lived secret.

• Encryption after the handshake feels almost invisible. Your browser just sends and receives data while TLS quietly does its job.

The Simple Way to Think About It

Think of public key cryptography as the introduction, not the entire conversation. The website proves its identity through its certificate, the two sides establish shared secrets, and symmetric encryption protects the data that follows.

SSL is the older name you’ll still see everywhere, but modern systems use TLS. And that distinction matters because SSL versions are obsolete and shouldn’t be used today.