trust anchor
Term · Cybersecurity · MLC-T-CYB-004414
1. A public or symmetric key that is trusted because it is built directly into hardware or software or securely provisioned via out-of-band means rather than because it is vouched for by another trusted entity (e.g., in a public-key certificate). A trust anchor may have name or policy constraints that limit its scope.
2. A CA with one or more trusted certificates containing public keys that exist at the base of a tree of trust or as the strongest link in a chain of trust and upon which a Public Key Infrastructure is constructed.
“Trust anchor” also refers to the certificate of this CA.
3. 1. An authoritative entity for which trust is assumed. In a PKI, a trust anchor is a certification authority, which is represented by a certificate that is used to verify the signature on a certificate issued by that trust-anchor. The security of the validation process depends upon the authenticity and integrity of the trust anchor's certificate. Trust anchor certificates are often distributed as self-signed certificates.
4. 2. The self-signed public key certificate of a trusted CA.
5. A public or symmetric key that is trusted because it is directly built into hardware or software, or securely provisioned via out-of-band means, rather than because it is vouched for by another trusted entity (e.g. in a public key certificate). A trust anchor may have name or policy constraints limiting its scope.
6. A configured DNSKEY RR or DS RR hash of a DNSKEY RR. A validating DNSSEC-aware resolver uses this public key or hash as a starting point for building the authentication chain to a signed DNS response. In general, a validating resolver will need to obtain the initial values of its trust anchors via some secure or trusted means outside the DNS protocol. The presence of a trust anchor also implies that the resolver should expect the zone to which the trust anchor points to be signed. This is sometimes referred to as a “secure entry point.”
7. An authoritative entity represented by a public key and associated data (see RFC 5914).
8. An established point of trust (usually based on the authority of some person, office, or organization) from which an entity begins the validation of an authorized process or authorized (signed) package. A "trust anchor" is sometimes defined as just a public key used for different purposes (e.g., validating a certification authority (CA), validating a signed software package or key, validating the process (or person) loading the signed software or key).
9. 1. An authoritative entity for which trust is assumed. In a PKI, a trust anchor is a certification authority, which is represented by a certificate that is used to verify the signature on a certificate issued by that trust-anchor. The security of the validation process depends upon the authenticity and integrity of the trust anchor’s certificate. Trust anchor certificates are often distributed as self-signed certificates. 2. The self-signed public key certificate of a trusted CA.
10. The key for a certificate authority who issues certificates or authorizes others to do so on its behalf
11. A public key and the name of a certification authority that is used to validate the first certificate in a sequence of certificates. The trust anchor’s public key is used to verify the signature on a certificate issued by a trust-anchor certification authority. The security of the validation process depends upon the authenticity and integrity of the trust anchor. Trust anchors are often distributed as self-signed certificates.
12. A public or symmetric key that is trusted because it is directly built into hardware or software, or securely provisioned via out-of-band means, rather than because it is vouched for by another trusted entity (e.g. in a public key certificate).
| Identifier | MLC-T-CYB-004414 |
|---|---|
| Field | Cybersecurity |
| Abbreviation | TA |
| References | NIST SP 800-63-4; NIST SP 800-63A-4; NIST SP 800-152; NIST SP 800-57 Part 1 Rev. 4 [Superseded]; NIST SP 800-63-3 [Superseded]; NIST SP 800-81-2 [Superseded]; NIST SP 800-57 Part 2 Rev.1; CNSSI 4009-2015; NIST SP 800-57 Part 1 Rev. 5; NISTIR 7682; NIST SP 800-57 Part 1 Rev. 3 [Superseded]; NIST SP 800-63-2 [Superseded]; NIST CSRC Glossary |
| See also | Authentication Key |
Record as JSON
{
"id": "MLC-T-CYB-004414",
"term": "trust anchor",
"field": "Cybersecurity",
"definition": "1. A public or symmetric key that is trusted because it is built directly into hardware or software or securely provisioned via out-of-band means rather than because it is vouched for by another trusted entity (e.g., in a public-key certificate). A trust anchor may have name or policy constraints that limit its scope.\n\n2. A CA with one or more trusted certificates containing public keys that exist at the base of a tree of trust or as the strongest link in a chain of trust and upon which a Public Key Infrastructure is constructed.\n“Trust anchor” also refers to the certificate of this CA.\n\n3. 1. An authoritative entity for which trust is assumed. In a PKI, a trust anchor is a certification authority, which is represented by a certificate that is used to verify the signature on a certificate issued by that trust-anchor. The security of the validation process depends upon the authenticity and integrity of the trust anchor's certificate. Trust anchor certificates are often distributed as self-signed certificates.\n\n4. 2. The self-signed public key certificate of a trusted CA.\n\n5. A public or symmetric key that is trusted because it is directly built into hardware or software, or securely provisioned via out-of-band means, rather than because it is vouched for by another trusted entity (e.g. in a public key certificate). A trust anchor may have name or policy constraints limiting its scope.\n\n6. A configured DNSKEY RR or DS RR hash of a DNSKEY RR. A validating DNSSEC-aware resolver uses this public key or hash as a starting point for building the authentication chain to a signed DNS response. In general, a validating resolver will need to obtain the initial values of its trust anchors via some secure or trusted means outside the DNS protocol. The presence of a trust anchor also implies that the resolver should expect the zone to which the trust anchor points to be signed. This is sometimes referred to as a “secure entry point.”\n\n7. An authoritative entity represented by a public key and associated data (see RFC 5914).\n\n8. An established point of trust (usually based on the authority of some person, office, or organization) from which an entity begins the validation of an authorized process or authorized (signed) package. A \"trust anchor\" is sometimes defined as just a public key used for different purposes (e.g., validating a certification authority (CA), validating a signed software package or key, validating the process (or person) loading the signed software or key).\n\n9. 1. An authoritative entity for which trust is assumed. In a PKI, a trust anchor is a certification authority, which is represented by a certificate that is used to verify the signature on a certificate issued by that trust-anchor. The security of the validation process depends upon the authenticity and integrity of the trust anchor’s certificate. Trust anchor certificates are often distributed as self-signed certificates. 2. The self-signed public key certificate of a trusted CA.\n\n10. The key for a certificate authority who issues certificates or authorizes others to do so on its behalf\n\n11. A public key and the name of a certification authority that is used to validate the first certificate in a sequence of certificates. The trust anchor’s public key is used to verify the signature on a certificate issued by a trust-anchor certification authority. The security of the validation process depends upon the authenticity and integrity of the trust anchor. Trust anchors are often distributed as self-signed certificates.\n\n12. A public or symmetric key that is trusted because it is directly built into hardware or software, or securely provisioned via out-of-band means, rather than because it is vouched for by another trusted entity (e.g. in a public key certificate).",
"abbreviation": "TA",
"see_also": [
"Authentication Key"
],
"references": [
"NIST SP 800-63-4; NIST SP 800-63A-4",
"NIST SP 800-152",
"NIST SP 800-57 Part 1 Rev. 4 [Superseded]",
"NIST SP 800-63-3 [Superseded]",
"NIST SP 800-81-2 [Superseded]",
"NIST SP 800-57 Part 2 Rev.1",
"CNSSI 4009-2015",
"NIST SP 800-57 Part 1 Rev. 5",
"NISTIR 7682",
"NIST SP 800-57 Part 1 Rev. 3 [Superseded]",
"NIST SP 800-63-2 [Superseded]",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/trust-anchor/"
}
Record 4,414 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.