MLchartDataset catalogue

Authentication Key

Term · Cybersecurity · MLC-T-CYB-000331

1. A private or symmetric key used by an authenticator to generate the authenticator output.

2. A public key that a DNSSEC-aware resolver has verified and can therefore use to authenticate data. A DNSSEC-aware resolver can obtain authentication keys in three ways. First, the resolver generally is configured to know about at least one public key; this configured data usually is either the public key itself or a hash of the public key as found in the DS RR (see “trust anchor”). Second, the resolver may use an authenticated public key to verify a DS RR and the DNSKEY RR to which the DS RR refers. Third, the resolver may be able to determine that a new public key has been signed by the private key corresponding to another public key that the resolver has verified. Note that the resolver must always be guided by local policy in deciding whether to authenticate a new public key, even if the local policy is simply to authenticate any new public key for which the resolver is able verify the signature.

Table 1. Record
IdentifierMLC-T-CYB-000331
FieldCybersecurity
ReferencesNIST SP 800-63-4; NIST SP 800-81-2 [Superseded]; NIST CSRC Glossary
See alsotrust anchor
Record as JSON
{
  "id": "MLC-T-CYB-000331",
  "term": "Authentication Key",
  "field": "Cybersecurity",
  "definition": "1. A private or symmetric key used by an authenticator to generate the authenticator output.\n\n2. A public key that a DNSSEC-aware resolver has verified and can therefore use to authenticate data. A DNSSEC-aware resolver can obtain authentication keys in three ways. First, the resolver generally is configured to know about at least one public key; this configured data usually is either the public key itself or a hash of the public key as found in the DS RR (see “trust anchor”). Second, the resolver may use an authenticated public key to verify a DS RR and the DNSKEY RR to which the DS RR refers. Third, the resolver may be able to determine that a new public key has been signed by the private key corresponding to another public key that the resolver has verified. Note that the resolver must always be guided by local policy in deciding whether to authenticate a new public key, even if the local policy is simply to authenticate any new public key for which the resolver is able verify the signature.",
  "see_also": [
    "trust anchor"
  ],
  "references": [
    "NIST SP 800-63-4",
    "NIST SP 800-81-2 [Superseded]",
    "NIST CSRC Glossary"
  ],
  "url": "https://mlchart.com/terminology/cybersecurity/authentication-key/"
}

Record 331 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.