cryptographic key
Term · Cybersecurity · MLC-T-CYB-001073
1. A parameter used in conjunction with a cryptographic algorithm that determines the specific operation of that algorithm.
2. A bit string used as a secret parameter by a cryptographic algorithm. In this Recommendation, a cryptographic key is either a random bit string of a length specified by the cryptographic algorithm or a pseudorandom bit string of the required length that is computationally indistinguishable from one selected uniformly at random from the set of all bit strings of that length.
3. A parameter used with a cryptographic algorithm that determines its operation.
4. The parameter of a block cipher that determines the selection of a permutation from the block cipher family.
5. A parameter used in conjunction with a cryptographic algorithm that determines its operation in such a way that an entity with knowledge of the key can reproduce or reverse the operation, while an entity without knowledge of the key cannot.
6. A parameter used in the block cipher algorithm that determines the forward cipher operation and the inverse cipher operation.
7. A value used to control cryptographic operations, such as decryption, encryption, signature generation, or signature verification. For the purposes of these guidelines, key requirements shall meet the minimum requirements stated in Table 2 of [SP 800-57 Part1].
8. A parameter used in conjunction with a cryptographic algorithm that determines its operation.
Examples applicable to this Standard include:
1. The computation of a digital signature from data, and
2. The verification of a digital signature.
9. A parameter used in conjunction with a cryptographic algorithm that determines its operation. Examples applicable to this Recommendation include: 1. The computation of a digital signature from data, and 2. The verification of a digital signature.
10. A parameter used with a cryptographic algorithm that determines its operation in such a way that an entity with knowledge of the key can reproduce or reverse the operation, while an entity without knowledge of the key cannot. Examples applicable to this Recommendation include:
1. The computation of a keyed-hash message authentication code.
2. The verification of a keyed-hash message authentication code.
3. The generation of a digital signature on a message.
4. The verification of a digital signature.
11. A binary string used as a secret parameter by a cryptographic algorithm. In this Recommendation, a cryptographic key shall be either a truly random binary string of a length specified by the cryptographic algorithm or a pseudorandom binary string of the specified length that is computationally indistinguishable from one selected uniformly at random from the set of all binary strings of that length.
12. A parameter used in conjunction with a cryptographic algorithm that determines its operation in such a way that an entity with knowledge of the key can reproduce or reverse the operation, while an entity without knowledge of the key cannot. Examples of cryptographic operations requiring the use of cryptographic keys include:
1. The transformation of plaintext data into ciphertext data,
2. The transformation of ciphertext data into plaintext data,
3. The computation of a digital signature from data,
4. The verification of a digital signature,
5. The computation of an authentication code from data,
6. The verification of an authentication code from data and a received authentication code,
7. The computation of a shared secret that is used to derive keying material.
8. The derivation of additional keying material from a key-derivation key (i.e., a pre-shared key).
13. A parameter used in conjunction with a cryptographic algorithm that determines the algorithm’s operation in such a way that an entity with knowledge of the key can reproduce or reverse the operation, while an entity without knowledge of the key cannot. Examples include:
1. The transformation of plaintext data into ciphertext data,
2. The transformation of ciphertext data into plaintext data,
3. The computation of a digital signature from data,
4. The verification of a digital signature,
5. The computation of an authentication code from data,
6. The verification of an authentication code from data and a received authentication code.
14. A parameter that determines the transformation from plaintext to ciphertext and vice versa. (A DEA key is a 64-bit parameter consisting of 56 independent bits and 8 parity bits). Multiple (1, 2 or 3) keys may be used in the Triple Data Encryption Algorithm.
15. The parameter of the block cipher that determines the selection of the forward cipher function from the family of permutations.
16. A parameter used in the block cipher algorithm that determines the forward cipher function.
17. A parameter used in conjunction with a cryptographic algorithm that determines its operation in such a way that an entity with knowledge of the key can reproduce or reverse the operation, while an entity without knowledge of the key cannot. Examples include:
• the transformation of plaintext data into ciphertext data,
• the transformation of ciphertext data into plaintext data,
• the computation of a digital signature from data,
• the verification of a digital signature,
• the computation of an authentication code from data,
• the computation of a shared secret that is used to derive keying material.
18. A value used to control cryptographic operations, such as decryption, encryption, signature generation, or signature verification. For the purposes of these guidelines, key requirements shall meet the minimum requirements stated in Table 2 of NIST SP 800-57 Part 1.
See also Asymmetric Keys, Symmetric Key.
19. A parameter that determines the transformation using DEA and TDEA forward and inverse operations.
20. A parameter used in conjunction with a cryptographic algorithm that determines its operation in such a way that an entity with knowledge of the key can reproduce the operation, while an entity without knowledge of the key cannot. Examples of the use of a key that are applicable to this Recommendation include: 1. The computation of a digital signature from data, and 2. The verification of a digital signature.
21. A parameter that determines the operation of a cryptographic function, such as:
1. The transformation from plaintext to ciphertext and vice versa,
2. The generation of keying material, or
3. A digital signature computation or verification.
22. A parameter used in conjunction with a cryptographic algorithm that determines its operation in such a way that an entity with knowledge of the key can reproduce or reverse the operation, while an entity without knowledge of the key cannot. Examples include: The transformation of plaintext data inot cipertext data, the transformation of ciphertext into plaintext data, The computation of a digital signautre from data, The verification of a digital signautre, The computation of an authentication code from data, The computation of a shared secret that is used to derive keying material.
23. See cryptographic key.
24. A parameter used in conjunction with a cryptographic algorithm that determines its operation in such a way that an entity with knowledge of the correct key can reproduce or reverse the operation, while an entity without knowledge of the key cannot. Examples of cryptographic operations requiring the use of cryptographic keys include: 1. The transformation of plaintext data into ciphertext data, 2. The transformation of ciphertext data into plaintext data, 3. The computation of a digital signature from data, 4. The verification of a digital signature, 5. The computation of an authentication code from data, 6. The verification of an authentication code from data and a received authentication code, 7. The computation of a shared secret that is used to derive keying material. 8. The derivation of additional keying material from a keyderivation key (i.e., a pre-shared key).
25. A parameter used in conjunction with a cryptographic algorithm that determines its operation in such a way that an entity with knowledge of the key can reproduce, reverse or verify the operation, while an entity without knowledge of the key cannot. Examples include:
1. The transformation of plaintext data into ciphertext data,
2. The transformation of ciphertext data into plaintext data,
3. The computation of a digital signature from data,
4. The verification of a digital signature on data,
5. The computation of an authentication code from data,
6. The verification of an authentication code from data and a received authentication code,
7. The computation of a shared secret that is used to derive keying material.
26. A parameter used in conjunction with a cryptographic algorithm that determines its operation in such a way that an entity with knowledge of the key can reproduce or reverse the operation while an entity without knowledge of the key cannot. Examples include 1. The transformation of plaintext data into ciphertext data, 2. The transformation of ciphertext data into plaintext data, 3. The computation of a digital signature from data, 4. The verification of a digital signature, 5. The computation of a message authentication code (MAC) from data, 6. The verification of a MAC received with data, 7. The computation of a shared secret that is used to derive keying material.
27. A parameter used in conjunction with a cryptographic algorithm that determines its operation in such a way that an entity with knowledge of the key can reproduce, reverse or verify the operation while an entity without knowledge of the key cannot. Examples include: 1. The transformation of plaintext data into ciphertext data, 2. The transformation of ciphertext data into plaintext data, 3. The computation of a digital signature from data, 4. The verification of a digital signature on data, 5. The computation of an authentication code from data, 6. The verification of an authentication code from data and a received or retrieved authentication code, and 7. The computation of a shared secret that is used to derive keying material.
28. A parameter used in conjunction with a cryptographic algorithm that determines its operation in such a way that an entity with knowledge of the correct key can reproduce or reverse the operation, while an entity without knowledge of the key cannot. Examples of cryptographic operations requiring the use of cryptographic keys include:
1. The transformation of plaintext data into ciphertext data,
2. The transformation of ciphertext data into plaintext data,
3. The computation of a digital signature from data,
4. The verification of a digital signature,
5. The computation of a message authentication code (MAC) from data,
6. The verification of a MAC from data and a received MAC,
7. The computation of a shared secret that is used to derive keying material, and
8. The derivation of additional keying material from a keyderivation key (e.g., a pre-shared key).
The specification of a cryptographic algorithm (as employed in a particular application) typically declares which of its parameters are keys.
29. A value used to control cryptographic operations, such as decryption, encryption, signature generation, or signature verification.
30. A cryptographic key. In this document, keys generally refer to public key cryptography key pairs used for authentication of users and/or machines (using digital signatures). Examples include identity key and authorized keys. The SSH protocol also uses host keys that are used for authenticating SSH servers to SSH clients connecting them.
31. See “Cryptographic Key”.
32. A parameter used in conjunction with a cryptographic algorithm that determines its operation in such a way that an entity with knowledge of the key can reproduce or reverse the operation, while an entity without knowledge of the key cannot. Examples include: 1. The transformation of plaintext data into ciphertext data, 2. The transformation of ciphertext data into plaintext data, 3. The computation of a digital signature from data, 4. The verification of a digital signature, 5. The computation of an authentication code from data, 6. The verification of an authentication code from data and a received authentication code, 7. The computation of a shared secret that is used to derive keying material.
33. A value used to control cryptographic operations, such as decryption, encryption, signature generation or signature verification. For the purposes of this document, key requirements shall meet the minimum requirements stated in Table 2 of NIST SP 800-57 Part 1.
See also Asymmetric keys, Symmetric key.
| Identifier | MLC-T-CYB-001073 |
|---|---|
| Field | Cybersecurity |
| Abbreviation | Key |
| References | FIPS 201-3; NIST SP 1800-12b; FIPS 201 [version unknown]; NIST SP 800-108r1 [August 2022 (Includes updates as of 02-02-2024)]; NIST SP 800-56C Rev. 2; NIST SP 800-56B Rev. 2; NIST SP 800-56B Rev. 1 [Superseded]; FIPS 197 [NIST FIPS 197-upd1]; NIST SP 800-175A; NIST IR 8459; NIST SP 800-38A; NIST SP 800-63-4; NIST SP 800-12 Rev. 1 from FIPS 186-4; FIPS 186-5; NIST SP 800-102; NIST SP 800-107 Rev. 1; NIST SP 800-108 [Superseded]; NIST SP 800-133 [Superseded]; NIST SP 800-135 Rev. 1; NIST SP 800-20; NIST SP 800-38D; NIST SP 800-38C; NIST SP 800-57 Part 2 [Superseded]; NIST SP 800-63-3 [Superseded]; NIST SP 800-67 Rev. 2; NIST SP 800-67 Rev. 1 [Superseded]; NIST SP 800-89; NIST SP 800-90A Rev. 1; NIST SP 800-57 Part 2 Rev.1; NIST SP 800-133 [Superseded]; NIST SP 800-133 Rev.1 [Superseded]; NIST SP 800-20; NIST SP 800-57 Part 1 Rev. 4 [Superseded]; NIST SP 800-67 Rev. 2; NIST SP 800-90A Rev. 1; NIST SP 800-175B Rev. 1; NIST SP 800-57 Part 1 Rev. 5; NIST SP 800-133 Rev. 2; NIST SP 800-57 Part 1 Rev. 3 [Superseded]; NIST SP 800-67 Rev. 1 [Superseded]; NIST SP 800-133 Rev.1 [Superseded]; NIST SP 800-57 Part 1 Rev. 4 [Superseded]; NIST SP 800-175B Rev. 1; NIST SP 800-57 Part 1 Rev. 5; NIST SP 800-133 Rev. 2; NIST SP 1800-21B from NIST SP 800-63-3; NISTIR 7966; FIPS 201 [version unknown]; NIST SP 800-57 Part 1 Rev. 3 [Superseded]; NIST SP 800-63-2 [Superseded]; NIST CSRC Glossary |
| See also | symmetric key |
Record as JSON
{
"id": "MLC-T-CYB-001073",
"term": "cryptographic key",
"field": "Cybersecurity",
"definition": "1. A parameter used in conjunction with a cryptographic algorithm that determines the specific operation of that algorithm.\n\n2. A bit string used as a secret parameter by a cryptographic algorithm. In this Recommendation, a cryptographic key is either a random bit string of a length specified by the cryptographic algorithm or a pseudorandom bit string of the required length that is computationally indistinguishable from one selected uniformly at random from the set of all bit strings of that length.\n\n3. A parameter used with a cryptographic algorithm that determines its operation.\n\n4. The parameter of a block cipher that determines the selection of a permutation from the block cipher family.\n\n5. A parameter used in conjunction with a cryptographic algorithm that determines its operation in such a way that an entity with knowledge of the key can reproduce or reverse the operation, while an entity without knowledge of the key cannot.\n\n6. A parameter used in the block cipher algorithm that determines the forward cipher operation and the inverse cipher operation.\n\n7. A value used to control cryptographic operations, such as decryption, encryption, signature generation, or signature verification. For the purposes of these guidelines, key requirements shall meet the minimum requirements stated in Table 2 of [SP 800-57 Part1].\n\n8. A parameter used in conjunction with a cryptographic algorithm that determines its operation.\nExamples applicable to this Standard include:\n1. The computation of a digital signature from data, and\n2. The verification of a digital signature.\n\n9. A parameter used in conjunction with a cryptographic algorithm that determines its operation. Examples applicable to this Recommendation include: 1. The computation of a digital signature from data, and 2. The verification of a digital signature.\n\n10. A parameter used with a cryptographic algorithm that determines its operation in such a way that an entity with knowledge of the key can reproduce or reverse the operation, while an entity without knowledge of the key cannot. Examples applicable to this Recommendation include:\n1. The computation of a keyed-hash message authentication code.\n2. The verification of a keyed-hash message authentication code.\n3. The generation of a digital signature on a message.\n4. The verification of a digital signature.\n\n11. A binary string used as a secret parameter by a cryptographic algorithm. In this Recommendation, a cryptographic key shall be either a truly random binary string of a length specified by the cryptographic algorithm or a pseudorandom binary string of the specified length that is computationally indistinguishable from one selected uniformly at random from the set of all binary strings of that length.\n\n12. A parameter used in conjunction with a cryptographic algorithm that determines its operation in such a way that an entity with knowledge of the key can reproduce or reverse the operation, while an entity without knowledge of the key cannot. Examples of cryptographic operations requiring the use of cryptographic keys include:\n1. The transformation of plaintext data into ciphertext data,\n2. The transformation of ciphertext data into plaintext data,\n3. The computation of a digital signature from data,\n4. The verification of a digital signature,\n5. The computation of an authentication code from data,\n6. The verification of an authentication code from data and a received authentication code,\n7. The computation of a shared secret that is used to derive keying material.\n8. The derivation of additional keying material from a key-derivation key (i.e., a pre-shared key).\n\n13. A parameter used in conjunction with a cryptographic algorithm that determines the algorithm’s operation in such a way that an entity with knowledge of the key can reproduce or reverse the operation, while an entity without knowledge of the key cannot. Examples include:\n1. The transformation of plaintext data into ciphertext data,\n2. The transformation of ciphertext data into plaintext data,\n3. The computation of a digital signature from data,\n4. The verification of a digital signature,\n5. The computation of an authentication code from data,\n6. The verification of an authentication code from data and a received authentication code.\n\n14. A parameter that determines the transformation from plaintext to ciphertext and vice versa. (A DEA key is a 64-bit parameter consisting of 56 independent bits and 8 parity bits). Multiple (1, 2 or 3) keys may be used in the Triple Data Encryption Algorithm.\n\n15. The parameter of the block cipher that determines the selection of the forward cipher function from the family of permutations.\n\n16. A parameter used in the block cipher algorithm that determines the forward cipher function.\n\n17. A parameter used in conjunction with a cryptographic algorithm that determines its operation in such a way that an entity with knowledge of the key can reproduce or reverse the operation, while an entity without knowledge of the key cannot. Examples include:\n• the transformation of plaintext data into ciphertext data,\n• the transformation of ciphertext data into plaintext data,\n• the computation of a digital signature from data,\n• the verification of a digital signature,\n• the computation of an authentication code from data,\n• the computation of a shared secret that is used to derive keying material.\n\n18. A value used to control cryptographic operations, such as decryption, encryption, signature generation, or signature verification. For the purposes of these guidelines, key requirements shall meet the minimum requirements stated in Table 2 of NIST SP 800-57 Part 1.\nSee also Asymmetric Keys, Symmetric Key.\n\n19. A parameter that determines the transformation using DEA and TDEA forward and inverse operations.\n\n20. A parameter used in conjunction with a cryptographic algorithm that determines its operation in such a way that an entity with knowledge of the key can reproduce the operation, while an entity without knowledge of the key cannot. Examples of the use of a key that are applicable to this Recommendation include: 1. The computation of a digital signature from data, and 2. The verification of a digital signature.\n\n21. A parameter that determines the operation of a cryptographic function, such as:\n1. The transformation from plaintext to ciphertext and vice versa,\n2. The generation of keying material, or\n3. A digital signature computation or verification.\n\n22. A parameter used in conjunction with a cryptographic algorithm that determines its operation in such a way that an entity with knowledge of the key can reproduce or reverse the operation, while an entity without knowledge of the key cannot. Examples include: The transformation of plaintext data inot cipertext data, the transformation of ciphertext into plaintext data, The computation of a digital signautre from data, The verification of a digital signautre, The computation of an authentication code from data, The computation of a shared secret that is used to derive keying material.\n\n23. See cryptographic key.\n\n24. A parameter used in conjunction with a cryptographic algorithm that determines its operation in such a way that an entity with knowledge of the correct key can reproduce or reverse the operation, while an entity without knowledge of the key cannot. Examples of cryptographic operations requiring the use of cryptographic keys include: 1. The transformation of plaintext data into ciphertext data, 2. The transformation of ciphertext data into plaintext data, 3. The computation of a digital signature from data, 4. The verification of a digital signature, 5. The computation of an authentication code from data, 6. The verification of an authentication code from data and a received authentication code, 7. The computation of a shared secret that is used to derive keying material. 8. The derivation of additional keying material from a keyderivation key (i.e., a pre-shared key).\n\n25. A parameter used in conjunction with a cryptographic algorithm that determines its operation in such a way that an entity with knowledge of the key can reproduce, reverse or verify the operation, while an entity without knowledge of the key cannot. Examples include:\n1. The transformation of plaintext data into ciphertext data,\n2. The transformation of ciphertext data into plaintext data,\n3. The computation of a digital signature from data,\n4. The verification of a digital signature on data,\n5. The computation of an authentication code from data,\n6. The verification of an authentication code from data and a received authentication code,\n7. The computation of a shared secret that is used to derive keying material.\n\n26. A parameter used in conjunction with a cryptographic algorithm that determines its operation in such a way that an entity with knowledge of the key can reproduce or reverse the operation while an entity without knowledge of the key cannot. Examples include 1. The transformation of plaintext data into ciphertext data, 2. The transformation of ciphertext data into plaintext data, 3. The computation of a digital signature from data, 4. The verification of a digital signature, 5. The computation of a message authentication code (MAC) from data, 6. The verification of a MAC received with data, 7. The computation of a shared secret that is used to derive keying material.\n\n27. A parameter used in conjunction with a cryptographic algorithm that determines its operation in such a way that an entity with knowledge of the key can reproduce, reverse or verify the operation while an entity without knowledge of the key cannot. Examples include: 1. The transformation of plaintext data into ciphertext data, 2. The transformation of ciphertext data into plaintext data, 3. The computation of a digital signature from data, 4. The verification of a digital signature on data, 5. The computation of an authentication code from data, 6. The verification of an authentication code from data and a received or retrieved authentication code, and 7. The computation of a shared secret that is used to derive keying material.\n\n28. A parameter used in conjunction with a cryptographic algorithm that determines its operation in such a way that an entity with knowledge of the correct key can reproduce or reverse the operation, while an entity without knowledge of the key cannot. Examples of cryptographic operations requiring the use of cryptographic keys include:\n1. The transformation of plaintext data into ciphertext data,\n2. The transformation of ciphertext data into plaintext data,\n3. The computation of a digital signature from data,\n4. The verification of a digital signature,\n5. The computation of a message authentication code (MAC) from data,\n6. The verification of a MAC from data and a received MAC,\n7. The computation of a shared secret that is used to derive keying material, and\n8. The derivation of additional keying material from a keyderivation key (e.g., a pre-shared key).\nThe specification of a cryptographic algorithm (as employed in a particular application) typically declares which of its parameters are keys.\n\n29. A value used to control cryptographic operations, such as decryption, encryption, signature generation, or signature verification.\n\n30. A cryptographic key. In this document, keys generally refer to public key cryptography key pairs used for authentication of users and/or machines (using digital signatures). Examples include identity key and authorized keys. The SSH protocol also uses host keys that are used for authenticating SSH servers to SSH clients connecting them.\n\n31. See “Cryptographic Key”.\n\n32. A parameter used in conjunction with a cryptographic algorithm that determines its operation in such a way that an entity with knowledge of the key can reproduce or reverse the operation, while an entity without knowledge of the key cannot. Examples include: 1. The transformation of plaintext data into ciphertext data, 2. The transformation of ciphertext data into plaintext data, 3. The computation of a digital signature from data, 4. The verification of a digital signature, 5. The computation of an authentication code from data, 6. The verification of an authentication code from data and a received authentication code, 7. The computation of a shared secret that is used to derive keying material.\n\n33. A value used to control cryptographic operations, such as decryption, encryption, signature generation or signature verification. For the purposes of this document, key requirements shall meet the minimum requirements stated in Table 2 of NIST SP 800-57 Part 1.\nSee also Asymmetric keys, Symmetric key.",
"abbreviation": "Key",
"see_also": [
"symmetric key"
],
"references": [
"FIPS 201-3; NIST SP 1800-12b; FIPS 201 [version unknown]",
"NIST SP 800-108r1 [August 2022 (Includes updates as of 02-02-2024)]",
"NIST SP 800-56C Rev. 2; NIST SP 800-56B Rev. 2; NIST SP 800-56B Rev. 1 [Superseded]",
"FIPS 197 [NIST FIPS 197-upd1]",
"NIST SP 800-175A",
"NIST IR 8459; NIST SP 800-38A",
"NIST SP 800-63-4",
"NIST SP 800-12 Rev. 1 from FIPS 186-4; FIPS 186-5",
"NIST SP 800-102",
"NIST SP 800-107 Rev. 1",
"NIST SP 800-108 [Superseded]",
"NIST SP 800-133 [Superseded]",
"NIST SP 800-135 Rev. 1",
"NIST SP 800-20",
"NIST SP 800-38D",
"NIST SP 800-38C",
"NIST SP 800-57 Part 2 [Superseded]",
"NIST SP 800-63-3 [Superseded]",
"NIST SP 800-67 Rev. 2; NIST SP 800-67 Rev. 1 [Superseded]",
"NIST SP 800-89",
"NIST SP 800-90A Rev. 1",
"NIST SP 800-57 Part 2 Rev.1",
"NIST SP 800-133 [Superseded]; NIST SP 800-133 Rev.1 [Superseded]; NIST SP 800-20; NIST SP 800-57 Part 1 Rev. 4 [Superseded]; NIST SP 800-67 Rev. 2; NIST SP 800-90A Rev. 1; NIST SP 800-175B Rev. 1; NIST SP 800-57 Part 1 Rev. 5; NIST SP 800-133 Rev. 2; NIST SP 800-57 Part 1 Rev. 3 [Superseded]; NIST SP 800-67 Rev. 1 [Superseded]",
"NIST SP 800-133 Rev.1 [Superseded]",
"NIST SP 800-57 Part 1 Rev. 4 [Superseded]",
"NIST SP 800-175B Rev. 1",
"NIST SP 800-57 Part 1 Rev. 5",
"NIST SP 800-133 Rev. 2",
"NIST SP 1800-21B from NIST SP 800-63-3",
"NISTIR 7966",
"FIPS 201 [version unknown]",
"NIST SP 800-57 Part 1 Rev. 3 [Superseded]",
"NIST SP 800-63-2 [Superseded]",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/cryptographic-key/"
}
Record 1,073 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.