1/95
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Public Key Infrastructure
Policies, procedures, hardware, and software used to create, distribute, manage, store, and revoke digital certificates.
PKI
Abbreviation for Public Key Infrastructure.
Symmetric Encryption
Encryption that uses the same secret key for both encryption and decryption.
Shared Secret
Another term for the key used in symmetric encryption because both parties use the same key.
Secret Key Algorithm
Another term associated with symmetric encryption.
Symmetric Encryption Advantage
It is fast and has relatively low processing overhead.
Symmetric Encryption Disadvantage
Securely distributing and managing shared keys becomes difficult as the number of users or devices grows.
Asymmetric Encryption
Encryption that uses two mathematically related keys: a public key and a private key.
Public Key
The key in an asymmetric pair that can be shared publicly.
Private Key
The key in an asymmetric pair that must remain secret.
Asymmetric Confidentiality Rule
Encrypt with the recipient's public key and decrypt with the recipient's private key.
Public-Private Key Pair
Two mathematically related keys created together for asymmetric cryptography.
Key Generation
The process of creating a mathematically related public and private key pair.
Key Escrow
Controlled storage of private keys so an organization can recover encrypted data when necessary.
Data at Rest
Data stored on a storage device such as an SSD or hard drive.
Full Disk Encryption
Encryption applied to an entire storage volume or disk.
BitLocker
Microsoft Windows technology used for full-disk or volume encryption.
FileVault
macOS technology used for full-disk encryption.
EFS
Encrypting File System; Windows file-level encryption built into NTFS.
Database Encryption
Using cryptography to protect some or all information stored in a database.
Transparent Encryption
Database encryption that uses a symmetric key to encrypt stored information.
Column-Level Encryption
Encrypting only selected database columns containing sensitive information.
Data in Transit
Data moving between systems across a network.
HTTPS
A protocol that encrypts browser and web server communication.
VPN
Virtual Private Network; creates an encrypted tunnel for network communication.
SSL/TLS VPN
A VPN technology commonly used for client-based remote access.
IPsec
A technology commonly used to provide encrypted site-to-site VPN connectivity.
Encryption Algorithm
The mathematical process used to encrypt and decrypt information.
DES
Data Encryption Standard; an encryption algorithm mentioned in the transcript.
AES
Advanced Encryption Standard; an encryption algorithm mentioned in the transcript.
Key Length
The size of a cryptographic key, which affects resistance to brute-force attacks.
Symmetric Key Length Example
128 bits or larger is described in the transcript as a common protected symmetric key size.
Asymmetric Key Length Example
3072 bits or larger is described in the transcript as a common asymmetric key size.
Brute-Force Attack
Trying every possible key or combination until the correct value is found.
Key Stretching
Repeating cryptographic operations multiple times to increase the work required for brute-force attacks.
Key Strengthening
Another term for key stretching.
Key Exchange
A process that allows systems to securely establish or share encryption keys.
Out-of-Band Key Exchange
Sharing a key through a different channel, such as in person, by courier, or by phone.
In-Band Key Exchange
Exchanging key-related information across the network.
Session Key
A temporary symmetric key used for a limited communication session.
Ephemeral Key
A temporary key that is discarded after use.
Asymmetric Protection of a Session Key
Encrypting a symmetric session key with a server's public key so the server can decrypt it with its private key.
Key Exchange Algorithm
A cryptographic process that allows both sides to derive the same symmetric key without directly sending that symmetric key across the network.
TPM
Trusted Platform Module; cryptographic hardware designed primarily for a single device.
TPM Functions
Generate random numbers, generate keys, securely store keys, and support technologies such as BitLocker.
HSM
Hardware Security Module; enterprise-scale hardware used for centralized secure key storage and cryptographic processing.
HSM Use Case
Securely managing cryptographic keys for hundreds or thousands of systems such as web servers.
Cryptographic Accelerator
Specialized hardware used to perform cryptographic operations quickly.
Centralized Key Management System
A system used to create, associate, rotate, log, report, and manage cryptographic keys from one location.
Key Rotation
Regularly replacing cryptographic keys over time.
Secure Enclave
A separate security processor dedicated to protecting data and performing cryptographic functions.
Secure Enclave Functions
May include secure boot monitoring, random-number generation, memory encryption, built-in cryptographic keys, and hardware AES encryption.
Obfuscation
Making information more difficult to understand while leaving it recoverable if the hiding method is known.
Steganography
Hiding information inside another medium such as an image, audio file, video, or network traffic.
Covertext
The object or document that contains hidden steganographic data.
Security Through Obscurity
Relying on secrecy of the hiding method rather than strong security controls.
Machine Identification Code
Tiny printer-generated markings that can help identify which printer produced a document.
Audio Steganography
Hiding information inside an audio file or track.
Video Steganography
Hiding information inside a video file.
Tokenization
Replacing sensitive data with a substitute token.
Payment Tokenization
Using temporary tokens instead of transmitting an actual credit card number during a transaction.
One-Time Token
A token designed to be valid for only one transaction or use.
Data Masking
Hiding part of sensitive information while showing only a limited portion.
Hash
A one-way cryptographic representation of data used as a digital fingerprint.
Hashing Is Not Encryption
A hash cannot normally be reversed to recreate the original data.
SHA-256
A hashing algorithm that produces a 256-bit hash represented as 64 hexadecimal characters.
Avalanche Effect
A small change in input results in a dramatically different hash output.
Hash Collision
When two different inputs produce the same hash value.
MD5
A hashing algorithm with known collision weaknesses and is not recommended for secure hashing.
File Integrity Check
Hashing a downloaded file and comparing the result with a trusted published hash.
Password Hashing
Storing a hash of a password instead of storing the password itself.
Salt
Random information added to a password before hashing to make resulting hashes different and harder to attack.
Salted Hash
A password hash created using an added random salt.
Rainbow Table
A precomputed collection of possible inputs and their corresponding hashes used to attack unsalted password hashes.
Digital Signature
A cryptographic signature created by hashing data and protecting the hash with the sender's private key.
Digital Signature Benefits
Integrity, authentication, and non-repudiation.
Blockchain
A distributed ledger in which participants maintain copies of transaction records.
Distributed Ledger
A shared record of transactions maintained by multiple participants.
Blockchain Block
A collection of transactions grouped together and protected with a hash.
Blockchain Integrity
Changing a transaction changes the block's hash, allowing tampering to be detected.
Digital Certificate
A file containing a public key, digital signature, and identity-related information used to establish trust.
X.509
The standardized format commonly used for digital certificates.
Certificate Authority
A trusted authority that validates identities and digitally signs certificates.
Web of Trust
A decentralized trust model in which individuals sign one another's certificates.
Root of Trust
A foundational component that is inherently trusted and is used to establish additional trust.
Certificate Signing Request
A request containing a public key and identifying information that is submitted to a CA for validation and signing.
CSR
Abbreviation for Certificate Signing Request.
Internal Certificate Authority
A CA operated by an organization to issue certificates for internal systems and users.
Wildcard Certificate
A certificate that can apply to multiple systems within a domain, often represented using an asterisk.
Subject Alternative Name
A certificate field used to identify additional domain or host names covered by the certificate.
Certificate Revocation
The process of making a previously trusted certificate invalid.
CRL
Certificate Revocation List; a list of certificates that have been revoked.
CRL Distribution Point
A location listed in a certificate where a browser or system can retrieve certificate revocation information.
Heartbleed
A 2014 OpenSSL vulnerability discussed in the transcript that demonstrated the need to revoke compromised certificates and issue new ones.
OCSP
Online Certificate Status Protocol; a protocol used to check whether a certificate is still valid.
OCSP Stapling
A process in which the server includes CA-signed certificate status information during the SSL/TLS handshake.