23.03.2013 Views

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

NIST IR <strong>7298</strong> <strong>Revision</strong> 1, <strong>Glossary</strong> <strong>of</strong> <strong>Key</strong> <strong>Information</strong> <strong>Security</strong> <strong>Terms</strong><br />

<strong>Key</strong> Distribution Center (KDC) – COMSEC facility generating and distributing key in electronic form.<br />

SOURCE: CNSSI-4009<br />

<strong>Key</strong> Escrow – A deposit <strong>of</strong> the private key <strong>of</strong> a subscriber and other pertinent<br />

information pursuant to an escrow agreement or similar contract<br />

binding upon the subscriber, the terms <strong>of</strong> which require one or more<br />

agents to hold the subscriber's private key for the benefit <strong>of</strong> the<br />

subscriber, an employer, or other party, upon provisions set forth in<br />

the agreement.<br />

SOURCE: SP 800-32<br />

<strong>Key</strong> Escrow – The processes <strong>of</strong> managing (e.g., generating, storing, transferring,<br />

auditing) the two components <strong>of</strong> a cryptographic key by two key<br />

component holders.<br />

SOURCE: FIPS 185<br />

1. The processes <strong>of</strong> managing (e.g., generating, storing, transferring,<br />

auditing) the two components <strong>of</strong> a cryptographic key by two key<br />

component holders.<br />

2. A key recovery technique for storing knowledge <strong>of</strong> a cryptographic<br />

key, or parts there<strong>of</strong>, in the custody <strong>of</strong> one or more third parties<br />

called "escrow agents," so that the key can be recovered and used in<br />

specified circumstances.<br />

SOURCE: CNSSI-4009<br />

<strong>Key</strong> Escrow System – A system that entrusts the two components comprising a<br />

cryptographic key (e.g., a device unique key) to two key component<br />

holders (also called "escrow agents").<br />

SOURCE: FIPS 185; CNSSI-4009<br />

<strong>Key</strong> Establishment – The process by which cryptographic keys are securely established<br />

among cryptographic modules using manual transport methods (e.g.,<br />

key loaders), automated methods (e.g., key transport and/or key<br />

agreement protocols), or a combination <strong>of</strong> automated and manual<br />

methods (consists <strong>of</strong> key transport plus key agreement).<br />

SOURCE: FIPS 140-2<br />

The process by which cryptographic keys are securely established<br />

among cryptographic modules using key transport and/or key<br />

agreement procedures. See key distribution.<br />

SOURCE: CNSSI-4009<br />

<strong>Key</strong> Exchange – The process <strong>of</strong> exchanging public keys in order to establish secure<br />

communications.<br />

SOURCE: SP 800-32<br />

Pg 106

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!