nonce
Term · Cybersecurity · MLC-T-CYB-002853
1. A time-varying value that has - at most - a negligible chance of repeating; for example, a random value that is generated anew for each use, a timestamp, a sequence number, or some combination of these.
2. A varying value that has, at most, a negligible chance of repeating; for example, a random value that is generated anew for each use, a timestamp, a sequence number, or some combination of these.
3. A value that is only used once.
4. A value used in security protocols that is never repeated with the same key. For example, nonces used as challenges in challenge-response authentication protocols must not be repeated until authentication keys are changed. Otherwise, there is a possibility of a replay attack. Using a nonce as a challenge is a different requirement than a random challenge because a nonce is not necessarily unpredictable.
5. An input value to the authenticated encryption algorithm that is used only once for encryption performed under a given key.
6. A random or non-repeating value that is included in data exchanged by a protocol, usually for the purpose of guaranteeing the transmittal of live data rather than replayed data, thus detecting and protecting against replay attacks.
7. A time-varying value that has at most a negligible chance of repeating, for example, a random value that is generated anew for each use, a timestamp, a sequence number, or some combination of these.
8. A time-varying value that has at most a negligible chance of repeating - for example, a random value that is generated anew for each use, a timestamp, a sequence number, or some combination of these.
9. A time-varying value that has at most a negligible chance of repeating; for example, a random value that is generated anew for each use, a time-stamp, a sequence number, or some combination of these. It can be a secret or non-secret value.
10. A value that is used only once.
11. A value that is used only once within a specified context.
12. A randomly generated value used to defeat “playback” attacks in communication protocols. One party randomly generates a nonce and sends it to the other party. The receiver encrypts it using the agreed upon secret key and returns it to the sender. Because the sender randomly generated the nonce, this defeats playback attacks because the replayer cannot know in advance the nonce the sender will generate. The receiver denies connections that do not have the correctly encrypted nonce.
13. A time-varying value that has at most an acceptably small chance of repeating. For example, the nonce may be a random value that is generated anew for each use, a timestamp, a sequence number, or some combination of these.
14. A value used in security protocols that is never repeated with the same key. For example, nonces used as challenges in challenge-response authentication protocols SHALL not be repeated until authentication keys are changed. Otherwise, there is a possibility of a replay attack. Using a nonce as a challenge is a different requirement than a random challenge, because a nonce is not necessarily unpredictable.
15. A time-varying value that has at most a negligible chance of repeating, e.g., a random value that is generated anew for each use, a timestamp, a sequence number, or some combination of these.
16. A time-varying value that has an acceptably small chance of repeating. For example, a nonce is a random value that is generated anew for each use, a timestamp, a sequence number, or some combination of these.
17. A time-varying value that has (at most) an acceptably small chance of repeating. For example, the nonce may be a random value that is generated anew for each use, a timestamp, a sequence number, or some combination of these.
18. A value used in security protocols that is never repeated with the same key. For example, nonces used as challenges in challenge-response authentication protocols are not repeated until the authentication keys are changed. Otherwise, there is a possibility of a replay attack.
19. See Nonce
20. See Cryptographic Nonce
21. A time-varying value that has, at most, an acceptably small chance of repeating. For example, a nonce is a random value that is generated anew for each use, a timestamp, a sequence number, or some combination of these.
22. A value used in security protocols that is never repeated with the same key. For example, nonces used as challenges in challenge-response authentication protocols must not be repeated until authentication keys are changed. Otherwise, there is a possibility of a replay attack. Using a nonce as a challenge is a different requirement than a random challenge, because a nonce is not necessarily unpredictable.
| Identifier | MLC-T-CYB-002853 |
|---|---|
| Field | Cybersecurity |
| Abbreviation | NC |
| Synonyms | Cryptographic Nonce |
| References | NIST SP 800-108r1 [August 2022 (Includes updates as of 02-02-2024)]; NIST SP 800-56C Rev. 2; NIST IR 8459; NIST SP 800-63-4; NIST SP 800-232; CNSSI 4009-2015 from IETF RFC 4949 Ver 2; CNSSI 4009-2022 from IETF RFC 4949 Ver 2; NIST SP 800-102; NIST SP 800-108 [Superseded]; NIST SP 800-56C [Superseded]; NIST SP 800-135 Rev. 1; NIST SP 800-38A; NIST SP 800-38C; NIST SP 800-38D; NIST SP 800-44 Version 2; NIST SP 800-56A Rev. 2 [Superseded]; NIST SP 800-63-3 [Superseded]; NIST SP 800-90A Rev. 1; NIST SP 800-56B Rev. 2; NIST SP 800-133 Rev. 2; NIST SP 800-53 Rev. 5 from NIST SP 800-63-3; NISTIR 8202 from NISTIR 8202; NISTIR 8202; NIST SP 800-56B Rev. 1 [Superseded]; NIST SP 800-63-2 [Superseded]; NIST CSRC Glossary |
Record as JSON
{
"id": "MLC-T-CYB-002853",
"term": "nonce",
"field": "Cybersecurity",
"definition": "1. A time-varying value that has - at most - a negligible chance of repeating; for example, a random value that is generated anew for each use, a timestamp, a sequence number, or some combination of these.\n\n2. A varying value that has, at most, a negligible chance of repeating; for example, a random value that is generated anew for each use, a timestamp, a sequence number, or some combination of these.\n\n3. A value that is only used once.\n\n4. A value used in security protocols that is never repeated with the same key. For example, nonces used as challenges in challenge-response authentication protocols must not be repeated until authentication keys are changed. Otherwise, there is a possibility of a replay attack. Using a nonce as a challenge is a different requirement than a random challenge because a nonce is not necessarily unpredictable.\n\n5. An input value to the authenticated encryption algorithm that is used only once for encryption performed under a given key.\n\n6. A random or non-repeating value that is included in data exchanged by a protocol, usually for the purpose of guaranteeing the transmittal of live data rather than replayed data, thus detecting and protecting against replay attacks.\n\n7. A time-varying value that has at most a negligible chance of repeating, for example, a random value that is generated anew for each use, a timestamp, a sequence number, or some combination of these.\n\n8. A time-varying value that has at most a negligible chance of repeating - for example, a random value that is generated anew for each use, a timestamp, a sequence number, or some combination of these.\n\n9. A time-varying value that has at most a negligible chance of repeating; for example, a random value that is generated anew for each use, a time-stamp, a sequence number, or some combination of these. It can be a secret or non-secret value.\n\n10. A value that is used only once.\n\n11. A value that is used only once within a specified context.\n\n12. A randomly generated value used to defeat “playback” attacks in communication protocols. One party randomly generates a nonce and sends it to the other party. The receiver encrypts it using the agreed upon secret key and returns it to the sender. Because the sender randomly generated the nonce, this defeats playback attacks because the replayer cannot know in advance the nonce the sender will generate. The receiver denies connections that do not have the correctly encrypted nonce.\n\n13. A time-varying value that has at most an acceptably small chance of repeating. For example, the nonce may be a random value that is generated anew for each use, a timestamp, a sequence number, or some combination of these.\n\n14. A value used in security protocols that is never repeated with the same key. For example, nonces used as challenges in challenge-response authentication protocols SHALL not be repeated until authentication keys are changed. Otherwise, there is a possibility of a replay attack. Using a nonce as a challenge is a different requirement than a random challenge, because a nonce is not necessarily unpredictable.\n\n15. A time-varying value that has at most a negligible chance of repeating, e.g., a random value that is generated anew for each use, a timestamp, a sequence number, or some combination of these.\n\n16. A time-varying value that has an acceptably small chance of repeating. For example, a nonce is a random value that is generated anew for each use, a timestamp, a sequence number, or some combination of these.\n\n17. A time-varying value that has (at most) an acceptably small chance of repeating. For example, the nonce may be a random value that is generated anew for each use, a timestamp, a sequence number, or some combination of these.\n\n18. A value used in security protocols that is never repeated with the same key. For example, nonces used as challenges in challenge-response authentication protocols are not repeated until the authentication keys are changed. Otherwise, there is a possibility of a replay attack.\n\n19. See Nonce\n\n20. See Cryptographic Nonce\n\n21. A time-varying value that has, at most, an acceptably small chance of repeating. For example, a nonce is a random value that is generated anew for each use, a timestamp, a sequence number, or some combination of these.\n\n22. A value used in security protocols that is never repeated with the same key. For example, nonces used as challenges in challenge-response authentication protocols must not be repeated until authentication keys are changed. Otherwise, there is a possibility of a replay attack. Using a nonce as a challenge is a different requirement than a random challenge, because a nonce is not necessarily unpredictable.",
"abbreviation": "NC",
"synonyms": [
"Cryptographic Nonce"
],
"references": [
"NIST SP 800-108r1 [August 2022 (Includes updates as of 02-02-2024)]",
"NIST SP 800-56C Rev. 2",
"NIST IR 8459",
"NIST SP 800-63-4",
"NIST SP 800-232",
"CNSSI 4009-2015 from IETF RFC 4949 Ver 2; CNSSI 4009-2022 from IETF RFC 4949 Ver 2",
"NIST SP 800-102",
"NIST SP 800-108 [Superseded]; NIST SP 800-56C [Superseded]",
"NIST SP 800-135 Rev. 1",
"NIST SP 800-38A",
"NIST SP 800-38C; NIST SP 800-38D",
"NIST SP 800-44 Version 2",
"NIST SP 800-56A Rev. 2 [Superseded]",
"NIST SP 800-63-3 [Superseded]",
"NIST SP 800-90A Rev. 1",
"NIST SP 800-56B Rev. 2",
"NIST SP 800-133 Rev. 2",
"NIST SP 800-53 Rev. 5 from NIST SP 800-63-3",
"NISTIR 8202 from NISTIR 8202",
"NISTIR 8202",
"NIST SP 800-56B Rev. 1 [Superseded]",
"NIST SP 800-63-2 [Superseded]",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/nonce/"
}
Record 2,853 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.