Types of encryption: algorithms and where each is used

Symmetric, asymmetric, key exchange and hashes: a map of AES, ChaCha20, RSA, ECC and more, which algorithms to retire, and where each one protects a video lesson.

9 min read
On this page 10 sections
  1. The map at a glance
  2. Symmetric algorithms
  3. Asymmetric algorithms
  4. Key exchange
  5. Hashes and MACs: not encryption, but close
  6. Retired algorithms to avoid
  7. Other ways people classify encryption
  8. Which types protect a video lesson
  9. Key takeaways
  10. Frequently asked questions

There are two main types of encryption: symmetric encryption, where one shared key both encrypts and decrypts (AES, ChaCha20), and asymmetric encryption, where a public key and a private key work as a pair (RSA, elliptic-curve cryptography). Real systems add two close relatives: key-exchange methods such as Diffie-Hellman, which let two sides agree on a key in public, and hashes and MACs such as SHA-256 and HMAC, which check data rather than hide it. This guide maps the algorithms you will actually meet, what each one is for, which ones to retire, and where each shows up when a student watches a lecture.

The map at a glance

JobAlgorithms in use todayWhere you meet them
Encrypting bulk data (symmetric)AES in GCM, CBC, CTR or XTS mode; ChaCha20-Poly1305HTTPS traffic, phone and laptop storage, video segments, backups
Signatures and public-key encryption (asymmetric)RSA, ECDSA, Ed25519; ML-DSA for post-quantum signaturesWebsite certificates, app signing, signed links and tokens
Agreeing on a key (key exchange)ECDHE with X25519 or P-256; hybrids with ML-KEMThe start of almost every HTTPS connection
Checking integrity and originSHA-256, SHA-3, HMAC, Poly1305File checks, webhooks, and inside modern ciphers
Storing passwordsArgon2id, bcrypt, scrypt, PBKDF2Login systems

If encryption itself is new to you, start with what encryption is, and if the difference between the first two rows is new, read symmetric vs asymmetric encryption. This article focuses on the individual algorithms.

Symmetric algorithms

AlgorithmDesignKey sizesStatusWhere it is used
AESBlock cipher, 128-bit blocks128, 192 or 256 bitsThe global standard since 2001 (FIPS 197)HTTPS, disk and phone storage, HLS and DRM video
ChaCha20-Poly1305Stream cipher plus an authenticator256 bitsCurrent (RFC 8439)HTTPS, where TLS 1.3 lists it as a recommended cipher suite; preferred by devices without AES hardware
AdiantumWide-block mode built mainly on ChaCha256 bitsCurrent, specialisedStorage encryption on low-end Android phones without AES hardware
Triple DES (3DES)Block cipher, 64-bit blocks112 or 168 bitsRetired: NIST disallowed it for new encryption after 2023Only old systems
DESBlock cipher, 64-bit blocks56 bitsWithdrawn by NIST in 2005Nowhere, ideally
RC4Stream cipherVariableProhibited in TLS since 2015Nowhere, ideally
BlowfishBlock cipher, 64-bit blocksUp to 448 bitsLegacy; its key setup lives on inside bcryptOld software

Symmetric ciphers themselves come in two types. Block ciphers such as AES encrypt fixed-size chunks and need a mode of operation to handle longer data; stream ciphers such as ChaCha20 generate a keystream and combine it with the data. In practice AES almost always runs in a mode that makes it behave like a stream cipher, as our comparison of block vs stream ciphers explains. The mode matters as much as the cipher: AES-GCM adds tamper detection, AES-CBC does not, and AES-XTS is designed for disks.

Asymmetric algorithms

  • RSA rests on the difficulty of factoring a large number into its two primes. NIST's signature standard requires keys of at least 2,048 bits. Today RSA mostly signs things, such as website certificates and apps, rather than encrypting data; TLS 1.3 dropped RSA key transport altogether. Our guide to RSA encryption works through an example.

  • Elliptic-curve cryptography (ECC) rests on a different hard problem and reaches the same strength with far smaller keys: a 256-bit curve is rated about as strong as 3,072-bit RSA. ECDSA and Ed25519 sign, and ECDH agrees keys. See ECC vs RSA.

  • Post-quantum algorithms are designed to resist future quantum computers, which would break both RSA and ECC. NIST published the first standards in August 2024: ML-KEM for key establishment (FIPS 203), and ML-DSA and SLH-DSA for signatures.

Asymmetric algorithms are slow and handle only small inputs, so they almost never encrypt files or video directly. They sign, and they help two parties arrive at a symmetric key.

Key exchange

Key exchange lets two parties who have never met agree on a shared secret over a public network. Modern HTTPS uses elliptic-curve Diffie-Hellman with fresh (ephemeral) keys for every connection. TLS 1.3 removed the older static RSA and Diffie-Hellman options, so every public-key exchange it allows provides forward secrecy: stealing a server's long-term key later doesn't expose recorded traffic. The two curves you will see are X25519 and P-256, and since version 131 Chrome has combined X25519 with ML-KEM by default, so connections stay safe if either one holds. Our explainer on Diffie-Hellman key exchange shows the maths with small numbers.

Hashes and MACs: not encryption, but close

Hash functions such as SHA-256 and SHA-3 turn data into a fixed-length fingerprint and can't be reversed, so they aren't encryption. They still appear in almost every encryption system: to derive keys, inside signatures and in message authentication codes (MACs). A MAC such as HMAC, or the Poly1305 and GHASH components inside ChaCha20-Poly1305 and AES-GCM, uses a key to prove data hasn't been changed. Password hashes such as Argon2id and bcrypt are a separate, deliberately slow family built for storing passwords.

Retired algorithms to avoid

AvoidWhyUse instead
DESA 56-bit key is small enough to search exhaustively; NIST withdrew the standard in 2005AES
3DES and Blowfish64-bit blocks: the 2016 "Sweet32" attack recovered data from long 3DES sessions after about four billion blocks; NIST withdrew its 3DES recommendation on 1 January 2024 (NIST)AES
RC4Biases in its keystream let attackers recover repeatedly encrypted data; RFC 7465 bans it from TLSAES-GCM or ChaCha20-Poly1305
AES in ECB modeIdentical blocks encrypt identically, so patterns show throughAES-GCM
RSA below 2,048 bitsA public 896-bit RSA challenge number was factored in September 2026, and the researcher behind it says 1,024-bit keys are now within reach of many organisations with data-centre GPU fleetsRSA-3072 or ECC
RSA PKCS#1 v1.5 encryptionVulnerable to padding attacks; the RSA standard keeps it only for compatibilityRSA-OAEP, or better, ECDHE key agreement
MD5 and SHA-1 for integrity or signaturesPractical collisions have been demonstratedSHA-256 or SHA-3

Other ways people classify encryption

Search results for "types of encryption" often mix algorithm families with where encryption is applied. Both are useful, as long as you know which one you are talking about:

  • By the state of the data: in transit (TLS on the network), at rest (disks, databases, backups) and end to end (only the sender's and recipient's devices hold the keys). Our guide to encryption at rest vs in transit covers what each one protects.

  • By what it covers: full-disk encryption, file-based encryption (Android encrypts file contents with AES-256 in XTS mode), database or field-level encryption, and application-level encryption of particular items such as video files.

Every one of these uses the same small set of algorithms underneath, mostly AES for the data and ECC or RSA for keys and signatures.

Which types protect a video lesson

Follow one recorded lecture through a typical video platform, from a faculty member's laptop to a student's phone, and nearly every type of cryptography appears. Platforms differ in the details; this is a common pattern, not a description of any particular one:

StageWhat protects itType
The recording is uploadedTLS 1.3: an ECDHE key exchange, then AES-GCM or ChaCha20-Poly1305Key exchange, then symmetric
The master file sits in cloud storageEncryption at rest, typically AES-256, which cloud storage services provide as a standard featureSymmetric
The video is packaged for streamingSegments encrypted with AES-128: CBC mode for standard HLS, counter mode ("cenc") or a CBC pattern ("cbcs") for DRM formatsSymmetric
The student logs inPassword stored as an Argon2id or bcrypt hash; session token signed with an HMAC or a signaturePassword hash and MAC
The player asks for the keyDelivered over HTTPS, only after the server checks the student's session and enrolmentKey exchange, symmetric and access control
The player fetches segmentsSigned, expiring URLs, using HMAC or RSA/ECDSA depending on the CDNMAC or signature
The app is installed or updatedThe developer signs it with RSA or ECDSA, and the phone checks the signatureAsymmetric
The student saves it for offline viewingThe file is encrypted on the device, with the key in the platform keystoreSymmetric plus hardware key storage

Our guide to HLS encryption covers the packaging and key-delivery rows in detail. Notice what no row can cover: once the student's player decrypts a segment, the lecture is plain pixels on a screen, where it can be recorded, filmed with a second phone or watched through a shared login. No type of encryption helps at that point.

Key takeaways

  • The two main types are symmetric (AES, ChaCha20) and asymmetric (RSA, ECC); key exchange, hashes and MACs complete the toolkit.

  • AES and ChaCha20-Poly1305 encrypt the data; RSA and ECC mostly sign and set up keys.

  • Retire DES, 3DES, RC4, ECB mode, RSA below 2,048 bits, MD5 and SHA-1.

  • Post-quantum standards (ML-KEM, ML-DSA, SLH-DSA) are already appearing alongside today's algorithms.

  • Protecting a video takes several types together, and still leaves the screen to be covered by other means.

VidSafe protects coaching institutes' lectures with VidSafe proprietary encryption, screen- and camera-recording detection, account-sharing prevention, PDF watermarking, RASP, and visible and invisible watermarks that are extremely hard to remove, even after heavy re-encoding.

Frequently asked questions

What are the two types of encryption?

The two types are symmetric and asymmetric encryption. Symmetric encryption uses one shared secret key to encrypt and decrypt, and it is fast enough for files, network traffic and video; AES and ChaCha20 are the main examples. Asymmetric encryption uses a public key and a matching private key, and it is used mainly for signatures and for setting up symmetric keys; RSA and elliptic-curve cryptography are the main examples.

What are the three types of encryption?

There is no single official list of three. A frequent answer is symmetric encryption, asymmetric encryption and hashing, although hashing is strictly not encryption because it can't be reversed. Others mean where encryption is applied: in transit, at rest and end to end. Both lists are reasonable, so check which classification your syllabus, exam or security questionnaire expects before you answer.

What are the types of symmetric encryption?

Symmetric encryption divides into block ciphers and stream ciphers. Block ciphers such as AES encrypt fixed-size blocks and run in a mode of operation such as GCM, CBC, CTR or XTS. Stream ciphers such as ChaCha20 combine the data with a generated keystream. AES-GCM and ChaCha20-Poly1305 are today's standard choices; DES, 3DES, Blowfish and RC4 are older ciphers that should no longer be used.

Share this article

Looking for something else?

Talk to Us