About this interactive
Public key cryptography gives you a key pair: a private key the owner keeps and a public key anyone can have. If the public key unlocks something, you know it was locked with the matching private key. That is useful, and the lesson is careful about how far it goes: it shows the two keys belong together, and nothing more.
The reason is that anybody can generate a key pair, and anybody can create a digital certificate, the file that carries the public key along with details such as its expiration date. An attacker can put yourbank.com in a certificate they made five minutes ago, and their public key will unlock their data perfectly. A certificate on its own is not enough for authenticity.
Public key infrastructure adds what is missing: a trusted third party. A certificate authority that both you and the server trust validates the certificate, so you know the public key inside really belongs to who the certificate names. Your browser does this every time it shows the lock icon and "Certificate is valid", and the certificate's details name the CA that issued it.
One question sorts every card. Has anyone you trust vouched for the certificate? If not, all you know is that the keys match. If a certificate authority you and the server both trust has validated it, you know who is on the other end. Public key cryptography is a component of PKI, but PKI is the bigger thing because it includes that third party.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →