Skip to content
9618Paper 3 · Advanced Theory§17.1

17. Security

Asymmetric encryption, digital signatures and certificates, SSL/TLS, quantum cryptography.

Statometer33OccasionalNext Paper 372%
Marks a paper4.2 · 6%Rank#8 of 8 · #6 on P3Trend · last 12Oct/Nov 24 · 31: 0 marksOct/Nov 24 · 32: 0 marksOct/Nov 24 · 33: 0 marksMay/Jun 25 · 31: 4 marksMay/Jun 25 · 32: 4 marksMay/Jun 25 · 33: 4 marksOct/Nov 25 · 31: 5 marksOct/Nov 25 · 32: 5 marksOct/Nov 25 · 33: 4 marksMay/Jun 26 · 31: 6 marksMay/Jun 26 · 32: 7 marksMay/Jun 26 · 33: 6 marks
7 in 10 chance in the next paper

Everything for this topic — study hub

A2 Level · 9618 · Paper 3

Statometer — what 32 real papers say about this topic and each of its 2 syllabus bullets

Occasional · #8 of 8 in A2 Level · recomputed with every new session

33OCCASIONAL
Occasional#8 of 8 in A2 Level#6 on Paper 3 Steady

Rotated in now and then — learn it last, but never skip it: Cambridge sets everything eventually.

Next Paper 3
72%
7 in 10 chance it is set
Marks a paper
4.2 / 75
6% of Paper 3 · fair share 17%
Appeared in
22 / 32
Paper 3 sittings 20212026
Last set
May/Jun 2026
9618/33 · Q8 · 6 marks · 3-series streak
Marks in each of the last 12 Paper 3 sittingsOct/Nov 24May/Jun 26
Oct/Nov 24 · 31: 0 marksOct/Nov 24 · 32: 0 marksOct/Nov 24 · 33: 0 marksMay/Jun 25 · 31: 4 marksMay/Jun 25 · 32: 4 marksMay/Jun 25 · 33: 4 marksOct/Nov 25 · 31: 5 marksOct/Nov 25 · 32: 5 marksOct/Nov 25 · 33: 4 marksMay/Jun 26 · 31: 6 marksMay/Jun 26 · 32: 7 marksMay/Jun 26 · 33: 6 marks

What the papers say

  • Set in 22 of 32 Paper 3 sittings — about 7 papers in 10.
  • Worth about 4.2 marks a paper (6% of Paper 3, well under its fair share of 17%).
  • Last set May/Jun 2026 · 9618/33 · Q8 for 6 marks — in the most recent series.
  • Steady at around 4.3 marks a paper year on year.
  • Lives on “Explain” and “Describe” — 73% of its questions: full sentences with a reason, not one-word answers.
  • Its biggest question so far: 10 marks (May/Jun 2022 · 9618/32 · Q7).
  • Inside the topic, §17.1 Encryption carries the most marks (57%) and §17.1 Encryption protocols and digital certificates the least (43%).
  • It is examined almost entirely as AO1 (Knowledge & understanding, 100%) — definitions and descriptions in syllabus words score.
  • The examiner has commented on 13 of its questions — read “What the examiner said” before you practise.

Command words

Share of questions using the word (a question can use several). What each wants →

Question shapes

  • ≤ 6 mk16
  • 7–9 mk5
  • 10–12 mk1
  • 13–15 mk0
  • 16+ mk0

Average 6 marks a question · 0% with a figure or table · 0% with code · biggest 10 marks

Assessment objectives — how it is examined

Every part of every current-syllabus question filed under Cambridge's AO1 / AO2 / AO3 (from its command word and what it asks you to do), so you know whether this topic pays for definitions, for applying, or for judging and building.

  • AO1 Knowledge & understanding
  • AO2 Apply & analyse
  • AO3 Design, program & evaluate

Paper 3 as a whole

Paper 3SyllabusMeasured
AO1 Knowledge & understanding60%54%
AO2 Apply & analyse40%46%
AO3 Design, program & evaluate0%0%

Syllabus = Cambridge's grid; measured = the bank's current-syllabus papers.

Inside the topic — every syllabus bullet, measured

Each part of each question is filed under the bullet it examines; the numbers are per Paper 3 sitting, exactly like the topic's. Open a bullet for its own Statometer.

  • 17.1Encryption#10 of 14 on Paper 3Regular · 4052% next paper2.5 marks15/32 sittings May/Jun 2026

    Set most sessions for a few marks; know the definition and one example.Syllabus: plain text and cipher text; symmetric and asymmetric cryptography; public and private keys for private and for verified messages; quantum cryptography

    Next Paper 3
    52%
    5 in 10
    Marks a paper
    2.5
    3% of the paper · 57% of the topic
    Asked in
    15 / 32
    Paper 3 sittings · 15 questions
    Last asked
    May/Jun 2026
    9618/33 · Q8 · 6 marks · 3-series streak
    • Asked in 15 of 32 Paper 3 sittings — roughly one paper in 2.
    • About 2.5 marks a paper (3% of Paper 3; 57% of the topic's marks across its 2 bullets).
    • Last asked May/Jun 2026 · 9618/33 · Q8 (6 marks) — in the most recent series.
    • Rising: 2.2 → 2.8 marks a paper.
    • Usually “Describe” or “State”: full sentences with a reason, not one-word answers.
    • Biggest chunk of marks so far: 7 in May/Jun 2026 · 9618/32 · Q8.
    • It is examined almost entirely as AO1 (Knowledge & understanding, 100%) — definitions and descriptions in syllabus words score.
    Last 12 sittings Rising
    Oct/Nov 24 · 31: 0 marksOct/Nov 24 · 32: 0 marksOct/Nov 24 · 33: 0 marksMay/Jun 25 · 31: 0 marksMay/Jun 25 · 32: 2 marksMay/Jun 25 · 33: 0 marksOct/Nov 25 · 31: 0 marksOct/Nov 25 · 32: 5 marksOct/Nov 25 · 33: 2 marksMay/Jun 26 · 31: 6 marksMay/Jun 26 · 32: 7 marksMay/Jun 26 · 33: 6 marks

    Assessment objectives

    • AO1 Knowledge & understanding
    • AO2 Apply & analyse
    • AO3 Design, program & evaluate
    • Describe40%
    • State40%
    • Explain40%
    • Outline27%
  • 17.1Encryption protocols and digital certificates#13 of 14 on Paper 3Occasional · 2841% next paper1.6 marks13/32 sittings Oct/Nov 2025

    Rotated in occasionally — the bullet students skip and then meet.Syllabus: purpose and use of SSL/TLS in client-server communication; acquiring a digital certificate and using it to produce digital signatures

    Next Paper 3
    41%
    2 in 4
    Marks a paper
    1.6
    2% of the paper · 43% of the topic
    Asked in
    13 / 32
    Paper 3 sittings · 13 questions
    Last asked
    Oct/Nov 2025
    9618/33 · Q9 · 2 marks · 1 series ago
    • Asked in 13 of 32 Paper 3 sittings — roughly one paper in 2.
    • About 1.6 marks a paper (2% of Paper 3; 43% of the topic's marks across its 2 bullets).
    • Last asked Oct/Nov 2025 · 9618/33 · Q9 (2 marks), 1 series ago.
    • Usually “Explain” or “Describe”: full sentences with a reason, not one-word answers.
    • Biggest chunk of marks so far: 8 in May/Jun 2022 · 9618/32 · Q7.
    • It is examined almost entirely as AO1 (Knowledge & understanding, 100%) — definitions and descriptions in syllabus words score.
    Last 12 sittings Steady
    Oct/Nov 24 · 31: 0 marksOct/Nov 24 · 32: 0 marksOct/Nov 24 · 33: 0 marksMay/Jun 25 · 31: 4 marksMay/Jun 25 · 32: 2 marksMay/Jun 25 · 33: 4 marksOct/Nov 25 · 31: 5 marksOct/Nov 25 · 32: 0 marksOct/Nov 25 · 33: 2 marksMay/Jun 26 · 31: 0 marksMay/Jun 26 · 32: 0 marksMay/Jun 26 · 33: 0 marks

    Assessment objectives

    • AO1 Knowledge & understanding
    • AO2 Apply & analyse
    • AO3 Design, program & evaluate
    • Explain77%
    • Describe46%
    • State39%
    • Identify15%

3% of the topic's marks sit in question parts that belong to another topic (scenario questions cross sections) or that no bullet claims; they count for the topic, not for a bullet.

Marks a paper, year by year

212223242526

By exam series

  • May/Jun14/18 · 4.6 mk
  • Oct/Nov8/14 · 3.4 mk

What you need to know2syllabus §17.1

  1. 17.1Encryptionplain text and cipher text; symmetric and asymmetric cryptography; public and private keys for private and for verified messages; quantum cryptography
  2. 17.1Encryption protocols and digital certificatespurpose and use of SSL/TLS in client-server communication; acquiring a digital certificate and using it to produce digital signatures

Video lectures2ZAK's YouTube channel · play here

  • A220182.6K views

  • O LevelASA22018630 views

Infographics2draw these the way the examiner expects · download as PNG

Asymmetric encryption & digital signaturesA key pair: what the PUBLIC key locks only the PRIVATE key unlocks — and vice versa. Which key you usedecides what you achieve.Confidentiality — only the receiver can read itPlaintextEncryptreceiver's PUBLIC keyCiphertextDecryptreceiver's PRIVATE keyAnyone can encrypt with the public key; an eavesdropper who intercepts the ciphertext has no private key, so cannot read it.Authentication — a digital signature proves who sent it and that it was not alteredMessageHash→ digestEncrypt digestsender's PRIVATE keyMessage + signature sentReceiver: 1 decrypts the signature with the sender's PUBLIC key → the original digest. 2 hashes the received message itself.3 compares the two digests. Match → sent by the private-key owner (authentic) and unchanged in transit (integrity). Non-repudiation too.Hashing is one-way: you cannot get the message back from the digest, and a one-bit change gives a completely different digest.SymmetricAsymmetricKeysone shared secret keypublic + private pair per userSpeedfast — used for the bulk dataslow — used to exchange the session keyProblemhow to share the key safelysolved by the public keyCombine them: asymmetric to agree a session key, then symmetric for the traffic — exactly what TLS does.cswithzak.com

Asymmetric encryption & digital signatures

A2
Digital certificates & the SSL/TLS handshakeHow can you trust a public key? A certificate authority (CA) signs it. The handshake uses that to set upan encrypted session.Digital certificate• owner / domain name• owner's PUBLIC key• serial number, valid from/to• issuing CA's name• CA's digital signature of the above (hash encrypted with the CA's private key)Browsers ship with trusted CA public keys, so theycan check the CA’s signature and trust the certificate.ClientServer1 hello: TLS version, cipher suites, random2 hello back + the server's certificate3 client verifies the certificate with the CA's public key4 session key, encrypted with the server's PUBLIC key5 server decrypts it with its PRIVATE key; both confirm6 all further traffic: SYMMETRIC encryption with the session keyWhy it mattersHTTPS = HTTP over TLS: the padlock. Preventseavesdropping and tampering, and confirms you aretalking to the real server, not an impostor (pharming).Quantum cryptographyKeys sent as photon states (quantum key distribution). Measuring a photon disturbs it, so any eavesdropper is detected. Needsdedicated fibre, short range, expensive — but immune to the computing power that could break today’s public-key maths.cswithzak.com

Digital certificates & the TLS handshake

A2

Browse all infographics →

Key terms9use these exact words in the exam

asymmetric encryptionpublic keyprivate keydigital signaturedigital certificatehashingSSLTLSquantum cryptography

Dotted terms are defined in the glossary.

Code help1referenced to the Cambridge pseudocode guide

Simple hash + signature verification idea

pseudocode §5.5, §8.2 Run in Playground
FUNCTION Hash(S : STRING) RETURNS INTEGER
DECLARE i, H : INTEGER
H 7
FOR i 1 TO LENGTH(S)
H (H * 31 + ASC(MID(S, i, 1))) MOD 1000003
NEXT i
RETURN H
ENDFUNCTION
DECLARE Msg : STRING
DECLARE Digest : INTEGER
Msg "Pay Ali 100"
Digest Hash(Msg)
OUTPUT "Digest sent: ", Digest
// receiver recomputes and compares
OUTPUT "Tampered? ", Hash("Pay Ali 900") <> Digest

💡 Real signatures encrypt the digest with the sender's private key; the receiver decrypts with the public key and compares.

Playground examples1runnable program for this topic

  • Caesar cipher — encrypt & decrypt

    Shift letters with ASC and CHR, wrapping with MOD 26. Same key both ways = symmetric encryption.

    O LevelASA2PseudocodeString handling §5.5 · 2210 §5 / 9618 §6.2 security
    Run

Test yourself

Ready to check you know it?

Every round is a fresh random draw, weak cards come back until you get them right, and past-paper questions come with their mark schemes. Marks earn XP on your dashboard.

Enroll nowOnline classes