Cybersecurity terminology · MLC-0102
Cybersecurity terms: K (133)
- K1The first subkey.
- K2The second subkey.
- k-anonymity1. A technique “to release person-specific data such that the ability to link to other information using the...
- KAS1-basicThe basic form of Key-Agreement Scheme 1.
- KAS1-Party_V-confirmationKey-Agreement Scheme 1 with confirmation by party V. Previously known as KAS1-responder-confirmation.
- KAS2-basicThe basic form of Key-Agreement Scheme 2.
- KAS2-bilateral-confirmationKey-Agreement Scheme 2 with bilateral confirmation.
- KAS2-Party_U-confirmationKey-Agreement Scheme 2 with confirmation by party U. Previously known as KAS2-initiator-confirmation.
- KAS2-Party_V-confirmationKey-Agreement Scheme 2 with confirmation by party V. Previously known as KAS2-responder-confirmation.
- KBA, see Knowledge-Based Authentication
- KBitsThe bit length of the secret keying material.
- KbpsLength in bits of the keying material.
- KCA procedure that provides assurance to one party (i.e., key-confirmation recipient) that another party (i.e...
- KDC, see key distribution center (KDC)
- KDFKey Derivation Function.
- KDK1. A key used as an input to a key-derivation function to derive additional keying material.
- KDMA method used to derive keying material from initial shared secrets and possibly other information.
- KEThe process of exchanging public keys in order to establish secure communications.
- KECCAKThe family of all sponge functions with a KECCAK-f permutation as the underlyinng function and multi-rate...
- KECCAK Message Authentication CodeKECCAK Message Authentication Code.
- KEK1. A cryptographic key that is used for the encryption or decryption of other keys to provide confidentiality...
- KEM1. A set of three cryptographic algorithms (KeyGen, Encaps, and Decaps) that can be used by two parties to...
- (KEM) ciphertextA bit string that is produced by encapsulation and used as an input to decapsulation.
- Kerberos1. An authentication system developed at the Massachusetts Institute of Technology (MIT). Kerberos is...
- key1. A parameter used in conjunction with a cryptographic algorithm that determines the specific operation of...
- key agreement1. A (pair-wise) key-establishment procedure in which the resultant secret keying material is a function of...
- Key agreement primitive1. A primitive algorithm used in a key-agreement scheme specified in [NIST SP 800-56A], or in [NIST SP...
- Key and metadata management functionsFunctions performed by a CKMS or FCKMS in order to manage keys and metadata.
- Key Bundle1. The three DEA cryptographic keys (Key1, Key2, Key3) that are used with a TDEA mode.
- Key centerA common central source of the keys or key components that are necessary to support cryptographically...
- Key certificationIn a Public Key Infrastructure (PKI), a process that permits keys or key components to be unambiguously...
- Key ChordsSpecific hardware keys pressed in a particular sequence on a mobile device.
- key combinerA function that takes multiple keys or shared secret values as input (possibly along with other information)...
- Key component1. See Cryptographic key component.
- Key custodianAn FCKMS role that is responsible for distributing keys or key splits and/or entering them into a...
- Key de-registration1. A function in the lifecycle of keying material; the marking of all keying material records and...
- Key derivation1. The process by which keying material is derived from 1) either a cryptographic key or a shared secret...
- Key destruction1. To remove all traces of keying material so that it cannot be recovered by either physical or electronic...
- Key Device Cybersecurity RequirementA device cybersecurity requirement that if lacking from an IoT device (in the case of a device cybersecurity...
- key distribution center (KDC)1. COMSEC facility generating and distributing key in electronic form.
- key encryption key (KEK)A key that encrypts other key [typically traffic encryption keys (TEKs)] for transmission or storage.
- key escrow1. A deposit of the private key of a subscriber and other pertinent information pursuant to an escrow...
- key establishment1. A procedure conducted by two or more participants, after which the resultant keying material is shared by...
- key exchange1. Process of exchanging public keys (and other information) in order to establish secure communications.
- Key Exchange Key, see KEK
- Key expansion1. The second step in the key-derivation procedure specified in this Recommendation in which a key-derivation...
- Key extractionSee Randomness extraction.
- Key formatThe data structure of a cryptographic key.
- Key generation1. The process of generating keys for cryptography.
- Key information1. Information about a key that includes the keying material and associated metadata relating to the key. See...
- Key inventoryInformation about each key that does not include the key itself (e.g., the key owner, key type, algorithm...
- Key length1. The length of a key in bits; used interchangeably with “Key size”.
- Key life cycleThe period of time between the creation of the key and its destruction.
- key logger1. A program designed to record which keys are pressed on a computer keyboard used to obtain passwords or...
- key management1. The activities involving the handling of cryptographic keys and other related security parameters (e.g...
- Key management componentsThe software module applications and hardware security modules (HSMs) that are used to generate, establish...
- Key management functionFunctions used 1) to establish cryptographic keys, certificates and the information associated with them; 2)...
- key management infrastructure (KMI)A unified, scalable, interoperable, and trusted infrastructure that provides net- centric key management...
- Key Management Plan1. Documents how key management for current and/or planned cryptographic products and services will be...
- Key management planning documentationThe Key Management Specification, CKMS Security Policy and CKMS Practice Statement
- Key Management Policy1. A high-level statement of organizational key management policies that identifies a high-level structure...
- Key management product1. A key management product is a cryptographic key (symmetric or asymmetric) or certificate used for...
- Key management protocolDocumented and coordinated rules for exchanging keys and metadata (e.g., X.509 certificates).
- Key Management Service1. A key management service is a function performed for or by an
- Key Management SystemA system for the management of cryptographic keys and their metadata (e.g., generation, distribution...
- Key (or key pair) ownerOne or more entities that are authorized to use a symmetric key or the private key of an asymmetric key pair.
- Key owner1. A person authorized by an FCKMS service provider or FCKMS service-using organization to use a specific key...
- key pair1. A set of two keys with the property that one key can be made public while the other key must be kept...
- Key Performance IndicatorA metric of progress toward intended results.
- key reference1. A 1-byte identifier that specifies a cryptographic key according to its PIV Key Type. The identifier is...
- Key registration1. A function in the lifecycle of keying material; the process of officially recording the keying material by...
- Key revocation1. A function in the lifecycle of keying material; a process whereby a notice is made available to affected...
- Key Risk IndicatorA metric used to measure risk.
- Key RotationChanging the key, i.e., replacing it by a new key. The places that use the key or keys derived from it (e.g...
- key sanitizationA technique for zeroization (e.g., overwriting with all zeros, all ones, or random data) of the target...
- Key scheduleThe sequence of round keys that are generated from the key by KEYEXPANSION().
- Key shareOne of n parameters (where n ≥ 2) such that among the n key shares, any k key shares (where k ≥ n) can be...
- Key size1. The length of a key in bits; used interchangeably with “Key length”.
- Key specification1. A key specification documents the data format, encryption algorithms, hashing algorithms, signature...
- Key splitting (k of n)Splitting a key into n key splits so that for some k (where k < n), any k key splits of the key can be used...
- Key states1. A categorization of the states that a key can assume during its lifetime. See [NIST SP 800-57 Part 1].
- Key Translation Center (KTC)A key center that receives keys from one entity wrapped using a symmetric key shared with that entity...
- key transport1. A (pair-wise) key-establishment procedure whereby one party (i.e., the sender) selects a value for the...
- Key transport (automated)A key-establishment procedure whereby one entity (the sender) selects a value for secret keying material and...
- Key typeOne of the twenty-one types of keys listed in [NIST SP 800-130].
- Key wrapping1. A method of encrypting and decrypting keys and (possibly) associated data using a symmetric key; both...
- Key wrapping algorithmA cryptographic algorithm approved for use in wrapping keys.
- Key1The first component of a TDEA key.
- Key2The second component of a TDEA key.
- Key3The third component of a TDEA key.
- Key-agreement transaction1. An execution of a key-agreement scheme.
- Key-center environmentAs used in this Recommendation, an environment in which the keys or key components needed to support...
- Key-confirmation provider1. The party that provides assurance to the other party (i.e., the recipient) that the two parties have...
- key-confirmation recipientThe party that receives assurance from the other party (i.e., the provider) that the two parties have indeed...
- KeyDataKeying material other than that which is used for the MacKey employed in key confirmation.
- Key-Dependent Message, see KDM
- Key-derivation function1. A function that, with the input of a cryptographic key and other data, generates a bit string called the...
- Key-derivation key1. A key used as an input to a key-derivation function to derive additional keying material.
- Key-derivation method1. As used in this Recommendation, a process that derives secret keying material from a shared secret. This...
- Key-derivation procedure1. A procedure consisting of multiple steps and using an approved algorithm (e.g., a MAC algorithm) by which...
- Keyed Hash Algorithm1. Algorithm that creates a hash based on both a message and a secret key; also known as a hash message...
- Keyed-Hash Message Authentication Code1. A message authentication code that uses a cryptographic key in conjunction with a hash function.
- Key-Encapsulation Mechanism1. A set of three cryptographic algorithms (KeyGen, Encaps, and Decaps) that can be used by two parties to...
- key-establishment key pair1. A public key and its corresponding private key; a key pair is used with a public key algorithm.
- key-establishment mechanism, see KEM
- Key-establishment transaction1. An execution of a key-establishment scheme. It can be either a key-agreement transaction or a...
- Key-generating moduleA cryptographic module in which a given key is generated.
- keying material1. A bit string such that non-overlapping segments of the string (with the required lengths) can be used as...
- Key/metadata recoveryThe process of retrieving or reconstructing a key or metadata from backup or archive storage.
- KEYnBlock of data representing KEY n
- Key-pair owner1. The entity that is authorized to use the private key associated with a public key, whether that entity...
- Key-recovery agent1. An FCKMS role that assists in the key-recovery/metadata-recovery process.
- Key-transport transaction1. An execution of a key-transport scheme.
- key-wrap algorithmA deterministic, symmetric-key authenticated-encryption algorithm that is intended for the protection of...
- Key-wrapping key1. In this Recommendation, a key-wrapping key is a symmetric key established through a key-agreement...
- KiB1. Kibi Byte, Measuring Unit 2^(10) Bytes = 1024 Bytes
- kibibyte1. Kibi Byte, Measuring Unit 2^(10) Bytes = 1024 Bytes
- Kill CommandA command that readers can send to tags that uses electronic disabling mechanisms to prevent tags from...
- Kilobits per second, see Kbps
- K_(IN)A key-derivation key used as input to a key-derivation function (along with other data) to derive the output...
- Klen1. The bit length of the block cipher key.
- KMACKECCAK Message Authentication Code.
- KMI, see key management infrastructure (KMI)
- KMI operating account (KOA)A key management infrastructure (KMI) business relationship that is established 1) to manage the set of user...
- KMI protected channel (KPC)A key management infrastructure (KMI) Communication Channel that provides 1) Information Integrity Service...
- KMI-aware deviceA user device that has a user identity for which the registration has significance across the entire key...
- KMNThe activities involving the handling of cryptographic keys and other related security parameters (e.g...
- KMP1. A high-level statement of organizational key management policies that identifies a high-level structure...
- KMPS1. A document or set of documents that describes, in detail, the organizational structure, responsible roles...
- KMS, see Key Management Service; Key Management System
- Knowledge1. A retrievable set of concepts within memory.
- Knowledge-Based AuthenticationAuthentication of an individual based on knowledge of information associated with his or her claimed identity...
- Known DataA category of information that may be present within an attribute of a CPE name. Known data represents any...
- Known Hosts FileA file associated with a specific account that contains one or more host keys. Each host key is associated...
- KOA, see KMI operating account (KOA)
- KOA agentA user identity that is designated by a key management infrastructure operating account (KOA) manager to...
- KOA manager (KOAM)An external operational management role that is responsible for the operation of a key management...
- KOA registration managerThe individual responsible for performing activities related to registering key management infrastructure...
- Kolmogorov-Smirnov TestA statistical test that may be used to determine if a set of data comes from a particular probability...
- K_(OUT)Output keying material that is derived from the key-derivation key K_(IN) and other data that were used as...
- KPC, see KMI protected channel (KPC)
- KPI, see Key Performance Indicator
- KRI, see Key Risk Indicator
- KTS-OAEP-basicThe basic form of the key-transport Scheme with Optimal Asymmetric Encryption Padding.
- KTS-OAEP-Party_V-confirmationKey-transport Scheme with Optimal Asymmetric Encryption Padding and key confirmation provided by party V...
133 of 4,693 terms in Cybersecurity terminology (MLC-0102). Request the full dataset.