More correctly, this is how to send a message using commutative ciphers without ever exposing
any keys - public or private.
This is the problem with analogies such as these. They can sort of be nearly right, and sort of give the right idea, but at the same time actually be quite misleading in the detail.
Here's what's actually equivalent to the analogy. We openly agree a large prime N (this is equivalent to agreeing on a style of box to use). I select a random number A (the padlock) and compute its multiplicative inverse A' (mod N) (the key). You do the same to compute B and B'.
I want to send you a message M. I compute W=M^A (mod N) [I put the message in the box and lock it with the padlock] and send that to you. You compute X=W^B (mod N) [you put your padlock on it] and send it back.
Now I compute Y=X^A' (mod N) [unlock with the key] and send you that, and finally you unlock with B' by taking Z=Y^B' (mod N).
We compute Z=Y^B'=(X^A')^B'=((W^B)^A')^B'=(((M^A)^B)^A')^B' but that's equal to M^(A.A'.B.B') which turns out to equal M. On the way any evesdropper will know M^A, M^(A.B) and M^B, but it is computationally infeasible (if P!=NP) currently to compute M, A or B from these.
The obvious method of attack is to use M^A and M^(AB) to try to deduce B and hence compute B', but that's equivalent (probably) to the discrete log problem ( http://en.wikipedia.org/wiki/Discrete_logarithm ) which is thought to be pretty similar to factoring integers.
Both RSA and Diffie-Hellman-Merkle-Williamson key exchange need different analogies. RSA usually uses the analogy that I give people open padlocks, and they use them to send me locked boxes. I can open them because I have the key.
I don't know a good analogy for the DHMW key exchange. It works like this. We agree a large prime N and a suitable base b. I choose a random A, compute X=b^A and send X to you. You choose a random B, compute Y=b^B and send that to me. I compute Y^A, you compute X^B, and we both end up with K, a shared secret which we can use in a symmetric cipher.
I now await the really clever people to correct my errors.