1.4 — Cryptographic Solutions

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/95

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 4:53 PM on 9/8/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

96 Terms

1
New cards

Public Key Infrastructure

Policies, procedures, hardware, and software used to create, distribute, manage, store, and revoke digital certificates.

2
New cards

PKI

Abbreviation for Public Key Infrastructure.

3
New cards

Symmetric Encryption

Encryption that uses the same secret key for both encryption and decryption.

4
New cards

Shared Secret

Another term for the key used in symmetric encryption because both parties use the same key.

5
New cards

Secret Key Algorithm

Another term associated with symmetric encryption.

6
New cards

Symmetric Encryption Advantage

It is fast and has relatively low processing overhead.

7
New cards

Symmetric Encryption Disadvantage

Securely distributing and managing shared keys becomes difficult as the number of users or devices grows.

8
New cards

Asymmetric Encryption

Encryption that uses two mathematically related keys: a public key and a private key.

9
New cards

Public Key

The key in an asymmetric pair that can be shared publicly.

10
New cards

Private Key

The key in an asymmetric pair that must remain secret.

11
New cards

Asymmetric Confidentiality Rule

Encrypt with the recipient's public key and decrypt with the recipient's private key.

12
New cards

Public-Private Key Pair

Two mathematically related keys created together for asymmetric cryptography.

13
New cards

Key Generation

The process of creating a mathematically related public and private key pair.

14
New cards

Key Escrow

Controlled storage of private keys so an organization can recover encrypted data when necessary.

15
New cards

Data at Rest

Data stored on a storage device such as an SSD or hard drive.

16
New cards

Full Disk Encryption

Encryption applied to an entire storage volume or disk.

17
New cards

BitLocker

Microsoft Windows technology used for full-disk or volume encryption.

18
New cards

FileVault

macOS technology used for full-disk encryption.

19
New cards

EFS

Encrypting File System; Windows file-level encryption built into NTFS.

20
New cards

Database Encryption

Using cryptography to protect some or all information stored in a database.

21
New cards

Transparent Encryption

Database encryption that uses a symmetric key to encrypt stored information.

22
New cards

Column-Level Encryption

Encrypting only selected database columns containing sensitive information.

23
New cards

Data in Transit

Data moving between systems across a network.

24
New cards

HTTPS

A protocol that encrypts browser and web server communication.

25
New cards

VPN

Virtual Private Network; creates an encrypted tunnel for network communication.

26
New cards

SSL/TLS VPN

A VPN technology commonly used for client-based remote access.

27
New cards

IPsec

A technology commonly used to provide encrypted site-to-site VPN connectivity.

28
New cards

Encryption Algorithm

The mathematical process used to encrypt and decrypt information.

29
New cards

DES

Data Encryption Standard; an encryption algorithm mentioned in the transcript.

30
New cards

AES

Advanced Encryption Standard; an encryption algorithm mentioned in the transcript.

31
New cards

Key Length

The size of a cryptographic key, which affects resistance to brute-force attacks.

32
New cards

Symmetric Key Length Example

128 bits or larger is described in the transcript as a common protected symmetric key size.

33
New cards

Asymmetric Key Length Example

3072 bits or larger is described in the transcript as a common asymmetric key size.

34
New cards

Brute-Force Attack

Trying every possible key or combination until the correct value is found.

35
New cards

Key Stretching

Repeating cryptographic operations multiple times to increase the work required for brute-force attacks.

36
New cards

Key Strengthening

Another term for key stretching.

37
New cards

Key Exchange

A process that allows systems to securely establish or share encryption keys.

38
New cards

Out-of-Band Key Exchange

Sharing a key through a different channel, such as in person, by courier, or by phone.

39
New cards

In-Band Key Exchange

Exchanging key-related information across the network.

40
New cards

Session Key

A temporary symmetric key used for a limited communication session.

41
New cards

Ephemeral Key

A temporary key that is discarded after use.

42
New cards

Asymmetric Protection of a Session Key

Encrypting a symmetric session key with a server's public key so the server can decrypt it with its private key.

43
New cards

Key Exchange Algorithm

A cryptographic process that allows both sides to derive the same symmetric key without directly sending that symmetric key across the network.

44
New cards

TPM

Trusted Platform Module; cryptographic hardware designed primarily for a single device.

45
New cards

TPM Functions

Generate random numbers, generate keys, securely store keys, and support technologies such as BitLocker.

46
New cards

HSM

Hardware Security Module; enterprise-scale hardware used for centralized secure key storage and cryptographic processing.

47
New cards

HSM Use Case

Securely managing cryptographic keys for hundreds or thousands of systems such as web servers.

48
New cards

Cryptographic Accelerator

Specialized hardware used to perform cryptographic operations quickly.

49
New cards

Centralized Key Management System

A system used to create, associate, rotate, log, report, and manage cryptographic keys from one location.

50
New cards

Key Rotation

Regularly replacing cryptographic keys over time.

51
New cards

Secure Enclave

A separate security processor dedicated to protecting data and performing cryptographic functions.

52
New cards

Secure Enclave Functions

May include secure boot monitoring, random-number generation, memory encryption, built-in cryptographic keys, and hardware AES encryption.

53
New cards

Obfuscation

Making information more difficult to understand while leaving it recoverable if the hiding method is known.

54
New cards

Steganography

Hiding information inside another medium such as an image, audio file, video, or network traffic.

55
New cards

Covertext

The object or document that contains hidden steganographic data.

56
New cards

Security Through Obscurity

Relying on secrecy of the hiding method rather than strong security controls.

57
New cards

Machine Identification Code

Tiny printer-generated markings that can help identify which printer produced a document.

58
New cards

Audio Steganography

Hiding information inside an audio file or track.

59
New cards

Video Steganography

Hiding information inside a video file.

60
New cards

Tokenization

Replacing sensitive data with a substitute token.

61
New cards

Payment Tokenization

Using temporary tokens instead of transmitting an actual credit card number during a transaction.

62
New cards

One-Time Token

A token designed to be valid for only one transaction or use.

63
New cards

Data Masking

Hiding part of sensitive information while showing only a limited portion.

64
New cards

Hash

A one-way cryptographic representation of data used as a digital fingerprint.

65
New cards

Hashing Is Not Encryption

A hash cannot normally be reversed to recreate the original data.

66
New cards

SHA-256

A hashing algorithm that produces a 256-bit hash represented as 64 hexadecimal characters.

67
New cards

Avalanche Effect

A small change in input results in a dramatically different hash output.

68
New cards

Hash Collision

When two different inputs produce the same hash value.

69
New cards

MD5

A hashing algorithm with known collision weaknesses and is not recommended for secure hashing.

70
New cards

File Integrity Check

Hashing a downloaded file and comparing the result with a trusted published hash.

71
New cards

Password Hashing

Storing a hash of a password instead of storing the password itself.

72
New cards

Salt

Random information added to a password before hashing to make resulting hashes different and harder to attack.

73
New cards

Salted Hash

A password hash created using an added random salt.

74
New cards

Rainbow Table

A precomputed collection of possible inputs and their corresponding hashes used to attack unsalted password hashes.

75
New cards

Digital Signature

A cryptographic signature created by hashing data and protecting the hash with the sender's private key.

76
New cards

Digital Signature Benefits

Integrity, authentication, and non-repudiation.

77
New cards

Blockchain

A distributed ledger in which participants maintain copies of transaction records.

78
New cards

Distributed Ledger

A shared record of transactions maintained by multiple participants.

79
New cards

Blockchain Block

A collection of transactions grouped together and protected with a hash.

80
New cards

Blockchain Integrity

Changing a transaction changes the block's hash, allowing tampering to be detected.

81
New cards

Digital Certificate

A file containing a public key, digital signature, and identity-related information used to establish trust.

82
New cards

X.509

The standardized format commonly used for digital certificates.

83
New cards

Certificate Authority

A trusted authority that validates identities and digitally signs certificates.

84
New cards

Web of Trust

A decentralized trust model in which individuals sign one another's certificates.

85
New cards

Root of Trust

A foundational component that is inherently trusted and is used to establish additional trust.

86
New cards

Certificate Signing Request

A request containing a public key and identifying information that is submitted to a CA for validation and signing.

87
New cards

CSR

Abbreviation for Certificate Signing Request.

88
New cards

Internal Certificate Authority

A CA operated by an organization to issue certificates for internal systems and users.

89
New cards

Wildcard Certificate

A certificate that can apply to multiple systems within a domain, often represented using an asterisk.

90
New cards

Subject Alternative Name

A certificate field used to identify additional domain or host names covered by the certificate.

91
New cards

Certificate Revocation

The process of making a previously trusted certificate invalid.

92
New cards

CRL

Certificate Revocation List; a list of certificates that have been revoked.

93
New cards

CRL Distribution Point

A location listed in a certificate where a browser or system can retrieve certificate revocation information.

94
New cards

Heartbleed

A 2014 OpenSSL vulnerability discussed in the transcript that demonstrated the need to revoke compromised certificates and issue new ones.

95
New cards

OCSP

Online Certificate Status Protocol; a protocol used to check whether a certificate is still valid.

96
New cards

OCSP Stapling

A process in which the server includes CA-signed certificate status information during the SSL/TLS handshake.