Perfect Forward Secrecy (PFS)
Term · Cybersecurity · MLC-T-CYB-003076
1. An option available during quick mode that causes a new shared secret to be created through a Diffie-Hellman exchange for each IPsec SA.
2. An option that causes a new secret key to be created and shared through a new Diffie-Hellman key exchange for each IPsec SA. This provides protection against the use of compromised old keys that could be used to attack the newer derived keys still in use for integrity and confidentiality protection.
| Identifier | MLC-T-CYB-003076 |
|---|---|
| Field | Cybersecurity |
| Abbreviation | PFS |
| References | NIST SP 800-77 [Superseded]; NIST SP 800-77 Rev. 1; NIST CSRC Glossary |
Record as JSON
{
"id": "MLC-T-CYB-003076",
"term": "Perfect Forward Secrecy (PFS)",
"field": "Cybersecurity",
"definition": "1. An option available during quick mode that causes a new shared secret to be created through a Diffie-Hellman exchange for each IPsec SA.\n\n2. An option that causes a new secret key to be created and shared through a new Diffie-Hellman key exchange for each IPsec SA. This provides protection against the use of compromised old keys that could be used to attack the newer derived keys still in use for integrity and confidentiality protection.",
"abbreviation": "PFS",
"references": [
"NIST SP 800-77 [Superseded]",
"NIST SP 800-77 Rev. 1",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/perfect-forward-secrecy-pfs/"
}
Record 3,076 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.