contains 210 terms · This page displays 30 terms, you can enter keywords to query the complete range
Cryptography哈希函数哈希函数是可用于将任意大小的数据映射到固定大小的值的任何函数,尽管有一些哈希函数支持可变长度输出。哈希函数返回的值称为哈希值、哈希码、(哈希/消息)摘要或简称为哈希。这些值通常用于索引称为哈希表的固定大小的表。使用哈希函数来索引哈希表称为哈希或分散存储寻址。哈希函数及其关联的哈希表用于数据存储和检索应用程序,以便在每次检索时以较小且几乎恒定的时间访问数据。它们所需的存储空间量仅略大于数据或记录本身所需的总空间。散列是一种快速有效地访问数据的方法。与列表或树不同,它提供近乎恒定的访问时间。
A hash function is any function that can be used to map data of arbitrary size to fixed-size values, though there are some hash functions that support variable-length output. The values returned by a hash function are called hash values, hash codes, (hash/message) digests, or simply hashes. The values are usually used to index a fixed-size table called a hash table. Use of a hash function to index a hash table is called hashing or scatter-storage addressing. Hash functions and their associated hash tables are used in data storage and retrieval applications to access data in a small and nearly constant time per retrieval. They require an amount of storage space only fractionally greater than the total space required for the data or records themselves. Hashing is a way to access data quickly and efficiently. Unlike lists or trees, it provides near-constant access time.
Sources, licensing and use
Wikipedia contributors · Retrieved2026-10-04 · CC BY-SA 4.0. Introductions were extracted as plain text and shortened. Language versions may emphasize different aspects.For concept reference; consult the original standards for authoritative requirements. The Chinese definition is a machine-assisted translation of the cited English introduction; check technical terminology against the original.
View content license ↗ CryptographySHA-2(专业术语)SHA-2(安全哈希算法 2)是由美国国家安全局 (NSA) 设计的一组加密哈希函数,于 2001 年首次发布。它们使用 Merkle–Damgård 结构构建,该结构是由单向压缩函数本身使用来自专用分组密码的 Davies–Meyer 结构构建的。 SHA-2 相对于其前身 SHA-1 进行了重大更改。 SHA-2 系列由六个摘要(哈希值)为 224、256、384 或 512 位的哈希函数组成:SHA-224、SHA-256、SHA-384、SHA-512、SHA-512/224、SHA-512/256。 SHA-256 和 SHA-512 是哈希函数,其摘要分别是八个 32 位和 64 位字。它们使用不同的移位量和加性常数,但它们的结构实际上是相同的,仅轮数不同。
SHA-2 (Secure Hash Algorithm 2) is a set of cryptographic hash functions designed by the United States National Security Agency (NSA) and first published in 2001. They are built using the Merkle–Damgård construction, from a one-way compression function itself built using the Davies–Meyer structure from a specialized block cipher. SHA-2 includes significant changes from its predecessor, SHA-1. The SHA-2 family consists of six hash functions with digests (hash values) that are 224, 256, 384 or 512 bits: SHA-224, SHA-256, SHA-384, SHA-512, SHA-512/224, SHA-512/256. SHA-256 and SHA-512 are hash functions whose digests are eight 32-bit and 64-bit words, respectively. They use different shift amounts and additive constants, but their structures are otherwise virtually identical, differing only in the number of rounds.
Sources, licensing and use
Wikipedia contributors · Retrieved2026-10-04 · CC BY-SA 4.0. Introductions were extracted as plain text and shortened. Language versions may emphasize different aspects.For concept reference; consult the original standards for authoritative requirements. The Chinese definition is a machine-assisted translation of the cited English introduction; check technical terminology against the original.
View content license ↗ Cryptography原像攻击在密码学中,对密码哈希函数的原像攻击试图找到具有特定哈希值的消息。加密哈希函数应该抵抗对其原像(一组可能的输入)的攻击。这些可以与碰撞阻力进行比较,在碰撞阻力中,找到任意两个不同的输入 x, x' 哈希到相同的输出在计算上是不可行的;即,h(x) = h(x′)。抗碰撞意味着抗第二原像,但不保证抗原像。然而,在散列函数范围的某些假设下,抗碰撞性确实意味着原像抗性(临时暗示)。相反,第二原像攻击意味着碰撞攻击(简单地说,因为除了 x' 之外,x 从一开始就已知)。
In cryptography, a preimage attack on cryptographic hash functions tries to find a message that has a specific hash value. A cryptographic hash function should resist attacks on its preimage (set of possible inputs). These can be compared with a collision resistance, in which it is computationally infeasible to find any two distinct inputs x, x′ that hash to the same output; i.e., such that h(x) = h(x′). Collision resistance implies second-preimage resistance, but does not guarantee preimage resistance. However, under certain assumptions of the range of the hash function, collision resistance does imply preimage resistance (by a provisional implication). Conversely, a second-preimage attack implies a collision attack (trivially, since, in addition to x′, x is already known right from the start).
Sources, licensing and use
Wikipedia contributors · Retrieved2026-10-04 · CC BY-SA 4.0. Introductions were extracted as plain text and shortened. Language versions may emphasize different aspects.For concept reference; consult the original standards for authoritative requirements. The Chinese definition is a machine-assisted translation of the cited English introduction; check technical terminology against the original.
View content license ↗ Cryptography香港发展基金会HKDF是基于HMAC消息认证码的多用途密钥派生函数(KDF)。 HKDF 遵循“提取然后扩展”范例,其中 KDF 在逻辑上由两个模块组成:第一阶段获取输入密钥材料并从中“提取”固定长度的伪随机密钥,然后第二阶段将此密钥“扩展”为几个附加的、独立的伪随机密钥作为 KDF 的输出。
HKDF is a multi-purpose key derivation function (KDF) based on the HMAC message authentication code. HKDF follows "extract-then-expand" paradigm, where the KDF logically consists of two modules: the first stage takes the input keying material and "extracts" from it a fixed-length pseudorandom key, and then the second stage "expands" this key into several additional, independent pseudorandom keys as the output of the KDF.
Sources, licensing and use
Wikipedia contributors · Retrieved2026-10-04 · CC BY-SA 4.0. Introductions were extracted as plain text and shortened. Language versions may emphasize different aspects.For concept reference; consult the original standards for authoritative requirements. The Chinese definition is a machine-assisted translation of the cited English introduction; check technical terminology against the original.
View content license ↗ Cryptography数字签名数字签名是一种用于验证数字消息或文档真实性的数学方案。邮件上的有效数字签名使任何收件人都确信该邮件来自收件人已知的发件人。相反,消息身份验证代码仅使特定收件人确信该消息来自已知的发件人。数字签名是一种公钥加密技术,通常用于软件分发、金融交易、合同管理软件以及其他需要检测伪造或篡改的情况。
A digital signature is a mathematical scheme for verifying the authenticity of digital messages or documents. A valid digital signature on a message gives any recipient confidence that the message came from a sender known to the recipient. In contrast, a message authentication code only gives confidence to a specific recipient that the message came from a known sender. Digital signatures are a type of public-key cryptography, and are commonly used for software distribution, financial transactions, contract management software, and in other cases where it is important to detect forgery or tampering.
Sources, licensing and use
Wikipedia contributors · Retrieved2026-10-04 · CC BY-SA 4.0. Introductions were extracted as plain text and shortened. Language versions may emphasize different aspects.For concept reference; consult the original standards for authoritative requirements. The Chinese definition is a machine-assisted translation of the cited English introduction; check technical terminology against the original.
View content license ↗ Cryptography椭圆曲线在数学中,椭圆曲线是平滑的投影代数曲线,其上有一个指定点 O。椭圆曲线在域 K 上定义,并描述 K 中的点(K 与其自身的笛卡尔积)。如果场的特性与2和3不同,则该曲线可以被描述为平面代数曲线,其由以下解(x,y)组成:对于K中的某些系数a和b。该曲线要求是非奇异的,这意味着该曲线没有尖点或自相交。 (这相当于条件 4a + 27b ≠ 0,即 x 中无平方。)通常理解,曲线嵌入在射影平面中,点 O 是无穷远处的唯一点。
In mathematics, an elliptic curve is a smooth, projective, algebraic curve of genus one, on which there is a specified point O. An elliptic curve is defined over a field K and describes points in K, the Cartesian product of K with itself. If the field's characteristic is different from 2 and 3, then the curve can be described as a plane algebraic curve which consists of solutions (x, y) for: for some coefficients a and b in K. The curve is required to be non-singular, which means that the curve has no cusps or self-intersections. (This is equivalent to the condition 4a + 27b ≠ 0, that is, being square-free in x.) It is usually understood that the curve is embedded in the projective plane, with the point O being the unique point at infinity.
Sources, licensing and use
Wikipedia contributors · Retrieved2026-10-04 · CC BY-SA 4.0. Introductions were extracted as plain text and shortened. Language versions may emphasize different aspects.For concept reference; consult the original standards for authoritative requirements. The Chinese definition is a machine-assisted translation of the cited English introduction; check technical terminology against the original.
View content license ↗ Cryptography离散对数在数学中,对于给定的实数 a {\displaystyle a} 和 b {\displaystyle b} ,对数 log b ( a ) {\displaystyle \log _{b}(a)} 是一个数 x {\displaystyle x} ,使得 b x = a {\displaystyle b^{x}=a} 。离散对数是群论中的一个类似概念。在任何群 G {\displaystyle G} 中,可以为所有整数 k {\displaystyle k} 定义幂 b k {\displaystyle b^{k}} ,并且离散对数 log b ( a ) {\displaystyle \log _{b}(a)} 是整数 k {\displaystyle k} ,使得 b k = a {\displaystyle b^{k}=a} 。在算术模整数 m {\displaystyle m} 的特殊情况下,更常用的术语是索引:当 b k ≡ a ( mod m ) {\displaystyle b^{k}\equiv 时,可以写 k = ind b a ( mod m ) {\displaystyle k=\operatorname {ind} _{b}a\!\!\!\!{\pmod {m}}} a\!\!\!\!{\pmod {m}}} 。
In mathematics, for given real numbers a {\displaystyle a} and b {\displaystyle b} , the logarithm log b ( a ) {\displaystyle \log _{b}(a)} is a number x {\displaystyle x} such that b x = a {\displaystyle b^{x}=a} . The discrete logarithm is an analogous concept in group theory. In any group G {\displaystyle G} , powers b k {\displaystyle b^{k}} can be defined for all integers k {\displaystyle k} , and the discrete logarithm log b ( a ) {\displaystyle \log _{b}(a)} is an integer k {\displaystyle k} such that b k = a {\displaystyle b^{k}=a} . In the special case of arithmetic modulo an integer m {\displaystyle m} , the more commonly used term is index: One can write k = ind b a ( mod m ) {\displaystyle k=\operatorname {ind} _{b}a\!\!\!\!{\pmod {m}}} when b k ≡ a ( mod m ) {\displaystyle b^{k}\equiv a\!\!\!\!{\pmod {m}}} .
Sources, licensing and use
Wikipedia contributors · Retrieved2026-10-04 · CC BY-SA 4.0. Introductions were extracted as plain text and shortened. Language versions may emphasize different aspects.For concept reference; consult the original standards for authoritative requirements. The Chinese definition is a machine-assisted translation of the cited English introduction; check technical terminology against the original.
View content license ↗ Cryptography有限域在数学中,有限域或伽罗瓦域(为纪念埃瓦里斯特·伽罗瓦而得名)是具有有限数量元素的域。与任何域一样,有限域是定义了乘法、加法、减法和除法运算并满足某些基本规则的集合。有限域最常见的例子是当 p {\displaystyle p} 是素数时的整数 mod p {\displaystyle p} 。有限域的阶是它的元素数量,元素要么是素数,要么是素数幂。对于每个素数 p {\displaystyle p} 和每个正整数 k {\displaystyle k} ,都有 p k {\displaystyle p^{k}} 阶的域。给定阶数的所有有限域都是同构的。
In mathematics, a finite field or Galois field (so-named in honor of Évariste Galois) is a field that has a finite number of elements. As with any field, a finite field is a set on which the operations of multiplication, addition, subtraction and division are defined and satisfy certain basic rules. The most common examples of finite fields are the integers mod p {\displaystyle p} when p {\displaystyle p} is a prime number. The order of a finite field is its number of elements, which is either a prime number or a prime power. For every prime number p {\displaystyle p} and every positive integer k {\displaystyle k} there are fields of order p k {\displaystyle p^{k}} . All finite fields of a given order are isomorphic.
Sources, licensing and use
Wikipedia contributors · Retrieved2026-10-04 · CC BY-SA 4.0. Introductions were extracted as plain text and shortened. Language versions may emphasize different aspects.For concept reference; consult the original standards for authoritative requirements. The Chinese definition is a machine-assisted translation of the cited English introduction; check technical terminology against the original.
View content license ↗ Cryptography领域(数学)在数学中,域是定义加法、减法、乘法和除法的集合,其行为与有理数的相应运算相同。域是基本的代数结构,广泛应用于代数、数论和许多其他数学领域。最著名的领域是有理数领域、实数领域和复数领域。许多其他领域,例如有理函数域、代数函数域、代数数域、有限域和 p 进数域,在数学中,特别是在数论和代数几何中,也被广泛使用和研究。场论是证明仅用圆规和直尺无法完成角度三等分和化圆为方的证明的关键要素。
In mathematics, a field is a set on which addition, subtraction, multiplication, and division are defined and behave as the corresponding operations on rational numbers do. Fields are fundamental algebraic structures that are widely used in algebra, number theory, and many other areas of mathematics. The best known fields are the field of rational numbers, the field of real numbers, and the field of complex numbers. Many other fields, such as fields of rational functions, algebraic function fields, algebraic number fields, finite fields, and p-adic fields are commonly used and studied in mathematics, particularly in number theory and algebraic geometry. The theory of fields is a crucial ingredient in the proofs that angle trisection and squaring the circle cannot be done with a compass and straightedge alone.
Sources, licensing and use
Wikipedia contributors · Retrieved2026-10-04 · CC BY-SA 4.0. Introductions were extracted as plain text and shortened. Language versions may emphasize different aspects.For concept reference; consult the original standards for authoritative requirements. The Chinese definition is a machine-assisted translation of the cited English introduction; check technical terminology against the original.
View content license ↗ Cryptography模运算在数学中,模算术是一种整数算术运算系统,与通常的算术运算不同,当达到或超过某个值(称为模)时,数字会“环绕”。使用模算术的现代数论方法由卡尔·弗里德里希·高斯 (Carl Friedrich Gauss) 在其 1801 年出版的《算术研究》一书中提出。模算术以 m 为模,系统地用除以 m 的余数替换加法、乘法和减法的结果。模运算的一个显着特性是,计算的结果并不取决于是否在每次运算后除以 m,而是只在计算结束时执行一次,或者在计算结束时和一些中间结果之后执行(通常是在中间结果变得太大时)。
In mathematics, modular arithmetic is a system of arithmetic operations for integers, differing from the usual ones in that numbers "wrap around" when reaching or exceeding a certain value, called the modulus. The modern approach to number theory using modular arithmetic was developed by Carl Friedrich Gauss in his book Disquisitiones Arithmeticae, published in 1801. Modular arithmetic modulo m consists of systematically replacing the results of additions, multiplications, and subtractions by the remainder of the division by m. A remarkable property of modular arithmetic is that the result of a computation does not depend on whether the division by m is performed after each operation, only once at the end of the computation, or at the end of the computation and after some intermediate results—typically when an intermediate result becomes too large.
Sources, licensing and use
Wikipedia contributors · Retrieved2026-10-04 · CC BY-SA 4.0. Introductions were extracted as plain text and shortened. Language versions may emphasize different aspects.For concept reference; consult the original standards for authoritative requirements. The Chinese definition is a machine-assisted translation of the cited English introduction; check technical terminology against the original.
View content license ↗ Cryptography模乘法逆元在数学中,特别是在算术领域中,整数 a 的模乘逆是整数 x,使得乘积 ax 对于模 m 等于 1。在模算术的标准表示法中,该同余被写为 m 除(均)量 ax − 1 的语句的简写方式,或者换句话说,ax 除以整数 m 后的余数为 1。如果 a 确实有模 m 的逆,则该同余有无限多个解,它们形成关于该模的同余类。此外,任何与 a 同余的整数(即,在 a 的同余类中)都具有 x 的同余类的任何元素作为模乘逆。
In mathematics, particularly in the area of arithmetic, a modular multiplicative inverse of an integer a is an integer x such that the product ax is congruent to 1 with respect to the modulus m. In the standard notation of modular arithmetic this congruence is written as which is the shorthand way of writing the statement that m divides (evenly) the quantity ax − 1, or, put another way, the remainder after dividing ax by the integer m is 1. If a does have an inverse modulo m, then there is an infinite number of solutions of this congruence, which form a congruence class with respect to this modulus. Furthermore, any integer that is congruent to a (i.e., in a's congruence class) has any element of x's congruence class as a modular multiplicative inverse.
Sources, licensing and use
Wikipedia contributors · Retrieved2026-10-04 · CC BY-SA 4.0. Introductions were extracted as plain text and shortened. Language versions may emphasize different aspects.For concept reference; consult the original standards for authoritative requirements. The Chinese definition is a machine-assisted translation of the cited English introduction; check technical terminology against the original.
View content license ↗ Cryptography扩展欧几里得算法在算术和计算机编程中,扩展欧几里得算法是欧几里得算法的扩展,除了计算整数 a 和 b 的最大公约数 (gcd) 之外,还计算 Bézout 恒等式的系数,它们是整数 x 和 y,使得 a x + b y = gcd ( a , b ) {\displaystyle ax+by=\gcd(a,b)} ;它通常表示为 xgcd ( a , b ) {\displaystyle \operatorname {xgcd} (a,b)} 。这是一个证明算法,因为 gcd 是唯一可以同时满足该方程并除以输入的数字。它还允许人们计算 a 和 b 除以其最大公约数的商,几乎不需要额外的成本。扩展欧几里得算法还指用于计算多项式最大公约数和两个单变量多项式的 Bézout 恒等式系数的非常相似的算法。
In arithmetic and computer programming, the extended Euclidean algorithm is an extension to the Euclidean algorithm, and computes, in addition to the greatest common divisor (gcd) of integers a and b, also the coefficients of Bézout's identity, which are integers x and y such that a x + b y = gcd ( a , b ) {\displaystyle ax+by=\gcd(a,b)} ; it is generally denoted as xgcd ( a , b ) {\displaystyle \operatorname {xgcd} (a,b)} . This is a certifying algorithm, because the gcd is the only number that can simultaneously satisfy this equation and divide the inputs. It allows one to compute also, with almost no extra cost, the quotients of a and b by their greatest common divisor. Extended Euclidean algorithm also refers to a very similar algorithm for computing the polynomial greatest common divisor and the coefficients of Bézout's identity of two univariate polynomials.
Sources, licensing and use
Wikipedia contributors · Retrieved2026-10-04 · CC BY-SA 4.0. Introductions were extracted as plain text and shortened. Language versions may emphasize different aspects.For concept reference; consult the original standards for authoritative requirements. The Chinese definition is a machine-assisted translation of the cited English introduction; check technical terminology against the original.
View content license ↗ Cryptography欧拉定理在数论中,欧拉定理(也称为费马-欧拉定理或欧拉 totient 定理)指出,如果 n 和 a 是互质正整数,则 a φ ( n ) {\displaystyle a^{\varphi (n)}} 与 1 {\displaystyle 1} modulo n 全等,其中 φ {\displaystyle \varphi } 表示欧拉 totient功能;即1736年,莱昂哈德·欧拉发表了费马小定理的证明(由费马无证明地陈述),即欧拉定理对n为素数的情况的限制。随后,欧拉提出了该定理的其他证明,并在 1763 年的论文中达到了顶峰,其中他证明了 n 不是素数情况的推广。欧拉定理的逆命题也成立:如果上述同余成立,则 a {\displaystyle a} 和 n {\displaystyle n} 必定互质。
In number theory, Euler's theorem (also known as the Fermat–Euler theorem or Euler's totient theorem) states that, if n and a are coprime positive integers, then a φ ( n ) {\displaystyle a^{\varphi (n)}} is congruent to 1 {\displaystyle 1} modulo n, where φ {\displaystyle \varphi } denotes Euler's totient function; that is In 1736, Leonhard Euler published a proof of Fermat's little theorem (stated by Fermat without proof), which is the restriction of Euler's theorem to the case where n is a prime number. Subsequently, Euler presented other proofs of the theorem, culminating with his paper of 1763, in which he proved a generalization to the case where n is not prime. The converse of Euler's theorem is also true: if the above congruence is true, then a {\displaystyle a} and n {\displaystyle n} must be coprime.
Sources, licensing and use
Wikipedia contributors · Retrieved2026-10-04 · CC BY-SA 4.0. Introductions were extracted as plain text and shortened. Language versions may emphasize different aspects.For concept reference; consult the original standards for authoritative requirements. The Chinese definition is a machine-assisted translation of the cited English introduction; check technical terminology against the original.
View content license ↗ Cryptography零知识证明在密码学中,零知识证明(也称为 ZK 证明或 ZKP)是一种协议,其中一方(证明者)可以说服另一方(验证者)某些给定的陈述是真实的,而无需向验证者传达除该陈述真实性之外的任何信息。零知识证明的非平凡性背后的直觉是,仅仅通过揭示相关信息来证明拥有相关信息是微不足道的;困难的部分是在不透露此信息(或其任何方面)的情况下证明这种所有权。
In cryptography, a zero-knowledge proof (also known as a ZK proof or ZKP) is a protocol in which one party (the prover) can convince another party (the verifier) that some given statement is true, without conveying to the verifier any information beyond the mere fact of that statement's truth. The intuition behind the nontriviality of zero-knowledge proofs is that it is trivial to prove possession of the relevant information simply by revealing it; the hard part is to prove this possession without revealing this information (or any aspect of it whatsoever).
Sources, licensing and use
Wikipedia contributors · Retrieved2026-10-04 · CC BY-SA 4.0. Introductions were extracted as plain text and shortened. Language versions may emphasize different aspects.For concept reference; consult the original standards for authoritative requirements. The Chinese definition is a machine-assisted translation of the cited English introduction; check technical terminology against the original.
View content license ↗ Cryptography随机预言机在密码学中,随机预言机是一种预言机(理论上的黑匣子),它使用从其输出域中统一选择的(真正)随机响应来响应每个唯一的查询。如果重复查询,则每次提交该查询时它都会以相同的方式响应。换句话说,随机预言是随机均匀选择的数学函数,即将每个可能的查询映射到来自其输出域的(固定)随机响应的函数。随机预言首先出现在复杂性理论的背景下,其中它们被用来论证复杂性类分离可能面临相对化障碍,最突出的例子是 P vs NP 问题,1981 年显示的两个类几乎肯定与随机预言不同。
In cryptography, a random oracle is an oracle (a theoretical black box) that responds to every unique query with a (truly) random response chosen uniformly from its output domain. If a query is repeated, it responds the same way every time that query is submitted. Stated differently, a random oracle is a mathematical function chosen uniformly at random, that is, a function mapping each possible query to a (fixed) random response from its output domain. Random oracles first appeared in the context of complexity theory, in which they were used to argue that complexity class separations may face relativization barriers, with the most prominent case being the P vs NP problem, two classes shown in 1981 to be distinct relative to a random oracle almost surely.
Sources, licensing and use
Wikipedia contributors · Retrieved2026-10-04 · CC BY-SA 4.0. Introductions were extracted as plain text and shortened. Language versions may emphasize different aspects.For concept reference; consult the original standards for authoritative requirements. The Chinese definition is a machine-assisted translation of the cited English introduction; check technical terminology against the original.
View content license ↗ Cryptography威胁模型威胁建模是一个过程,通过该过程可以识别和列举潜在威胁(例如结构漏洞或缺乏适当的保障措施),并优先考虑对策。威胁建模的目的是根据系统的性质、可能的攻击者的概况、最可能的攻击向量以及攻击者最想要的资产,为防御者提供需要包括哪些控制或防御的系统分析。威胁建模回答诸如“我在哪里最容易受到攻击?”、“最相关的威胁是什么?”以及“我需要做什么来防范这些威胁?”等问题。从概念上讲,大多数人在日常生活中融入了某种形式的威胁建模,但他们甚至没有意识到这一点。
Threat modeling is a process by which potential threats, such as structural vulnerabilities or the absence of appropriate safeguards, can be identified and enumerated, and countermeasures prioritized. The purpose of threat modeling is to provide defenders with a systematic analysis of what controls or defenses need to be included, given the nature of the system, the probable attacker's profile, the most likely attack vectors, and the assets most desired by an attacker. Threat modeling answers questions like "Where am I most vulnerable to attack?", "What are the most relevant threats?", and "What do I need to do to safeguard against these threats?". Conceptually, most people incorporate some form of threat modeling in their daily life and don't even realize it.
Sources, licensing and use
Wikipedia contributors · Retrieved2026-10-04 · CC BY-SA 4.0. Introductions were extracted as plain text and shortened. Language versions may emphasize different aspects.For concept reference; consult the original standards for authoritative requirements. The Chinese definition is a machine-assisted translation of the cited English introduction; check technical terminology against the original.
View content license ↗ Cryptography旁路攻击在计算机安全中,旁道攻击是一种安全漏洞,它利用系统无意中泄露的信息(例如定时、功耗、电磁或声发射)来获得对敏感信息的未经授权的访问。这些攻击不同于针对加密协议或算法设计中的缺陷的攻击(尽管密码分析可以识别与这两种类型的攻击相关的漏洞)。一些侧信道攻击需要系统内部操作的技术知识,而其他攻击(例如差分功率分析)则作为黑盒攻击是有效的。
In computer security, a side-channel attack is a type of security exploit that uses information inadvertently leaked by a system—such as timing, power consumption, or electromagnetic or acoustic emissions—to gain unauthorized access to sensitive information. These attacks differ from those targeting flaws in the design of cryptographic protocols or algorithms (notwithstanding the fact that cryptanalysis may identify vulnerabilities relevant to both types of attacks). Some side-channel attacks require technical knowledge of the internal operation of the system, others such as differential power analysis are effective as black-box attacks.
Sources, licensing and use
Wikipedia contributors · Retrieved2026-10-04 · CC BY-SA 4.0. Introductions were extracted as plain text and shortened. Language versions may emphasize different aspects.For concept reference; consult the original standards for authoritative requirements. The Chinese definition is a machine-assisted translation of the cited English introduction; check technical terminology against the original.
View content license ↗ Cryptography定时攻击在密码学中,定时攻击是一种旁道攻击,攻击者试图通过分析执行密码算法所需的时间来破坏密码系统。计算机中的每个逻辑运算都需要时间来执行,并且时间可能会根据输入而有所不同;通过精确测量每个操作的时间,攻击者也许能够逆向输入。通过测量响应某些查询所需的时间,信息可能会从系统中泄漏。这些信息对攻击者的帮助程度取决于许多变量,例如密码系统设计、运行系统的 CPU、使用的算法、各种实现细节、定时攻击对策以及定时测量的准确性。任何具有数据相关时序变化的算法都容易受到时序攻击。
In cryptography, a timing attack is a side-channel attack in which the attacker attempts to compromise a cryptosystem by analyzing the time taken to execute cryptographic algorithms. Every logical operation in a computer takes time to execute, and the time can differ based on the input; with precise measurements of the time for each operation, an attacker may be able to work backwards to the input. Information can leak from a system through measurement of the time it takes to respond to certain queries. How much this information can help an attacker depends on many variables such as cryptographic system design, the CPU running the system, the algorithms used, assorted implementation details, timing attack countermeasures, and accuracy of the timing measurements. Any algorithm that has data-dependent timing variation is vulnerable to timing attacks.
Sources, licensing and use
Wikipedia contributors · Retrieved2026-10-04 · CC BY-SA 4.0. Introductions were extracted as plain text and shortened. Language versions may emphasize different aspects.For concept reference; consult the original standards for authoritative requirements. The Chinese definition is a machine-assisted translation of the cited English introduction; check technical terminology against the original.
View content license ↗ Cryptography故障注入在计算机科学中,故障注入是一种测试技术,用于了解计算系统在受到异常压力时的行为方式。这可以使用基于物理或软件的手段或使用混合方法来实现。广泛研究的物理故障注入包括在电子元件(例如计算机内存和中央处理单元)上应用高电压、极端温度和电磁脉冲。通过将组件暴露在超出其预期操作限制的条件下,计算系统可能会被迫错误执行指令并损坏关键数据。在软件测试中,故障注入是一种通过向测试代码路径引入故障来提高测试覆盖率的技术;特别是错误处理代码路径,否则可能很少被遵循。
In computer science, fault injection is a testing technique for understanding how computing systems behave when stressed in unusual ways. This can be achieved using physical- or software-based means, or using a hybrid approach. Widely studied physical fault injections include the application of high voltages, extreme temperatures and electromagnetic pulses on electronic components, such as computer memory and central processing units. By exposing components to conditions beyond their intended operating limits, computing systems can be coerced into mis-executing instructions and corrupting critical data. In software testing, fault injection is a technique for improving the coverage of a test by introducing faults to test code paths; in particular error handling code paths, that might otherwise rarely be followed.
Sources, licensing and use
Wikipedia contributors · Retrieved2026-10-04 · CC BY-SA 4.0. Introductions were extracted as plain text and shortened. Language versions may emphasize different aspects.For concept reference; consult the original standards for authoritative requirements. The Chinese definition is a machine-assisted translation of the cited English introduction; check technical terminology against the original.
View content license ↗ Cryptography填充预言机攻击在密码学中,填充预言攻击是一种使用密码消息的填充验证来解密密文的攻击。在密码学中,通常必须填充(扩展)可变长度的明文消息才能与底层密码原语兼容。该攻击依赖于“填充预言机”,它可以自由响应有关消息是否正确填充的查询。这些信息可以直接提供,也可以通过旁道泄露。最早使用填充预言机的众所周知的攻击是 1998 年的 Bleichenbacher 攻击,该攻击使用 PKCS #1 v1.5 填充攻击 RSA。 2002 年,Serge Vaudenay 对对称分组密码中使用的 CBC 模式解密进行攻击后,术语“padding oracle”出现在文献中。这两种攻击的变体在最初发布十多年后继续取得成功。
In cryptography, a padding oracle attack is an attack which uses the padding validation of a cryptographic message to decrypt the ciphertext. In cryptography, variable-length plaintext messages often have to be padded (expanded) to be compatible with the underlying cryptographic primitive. The attack relies on having a "padding oracle" which freely responds to queries about whether a message is correctly padded or not. The information could be directly given, or leaked through a side-channel. The earliest well-known attack that uses a padding oracle is Bleichenbacher's attack of 1998, which attacks RSA with PKCS #1 v1.5 padding. The term "padding oracle" appeared in literature in 2002, after Serge Vaudenay's attack on the CBC mode decryption used within symmetric block ciphers. Variants of both attacks continue to find success more than one decade after their original publication.
Sources, licensing and use
Wikipedia contributors · Retrieved2026-10-04 · CC BY-SA 4.0. Introductions were extracted as plain text and shortened. Language versions may emphasize different aspects.For concept reference; consult the original standards for authoritative requirements. The Chinese definition is a machine-assisted translation of the cited English introduction; check technical terminology against the original.
View content license ↗ Cryptography重放攻击重放攻击(也称为重复攻击或回放攻击)是一种网络攻击形式,其中有效数据传输被恶意或欺诈性地重复或延迟。这是由发起者或拦截数据并重新传输数据的对手执行的,可能是通过 IP 数据包替换进行欺骗攻击的一部分。这是中间人攻击的低层版本之一。重放攻击本质上通常是被动的。描述此类攻击的另一种方式是:“对安全协议的攻击,使用从不同上下文到预期(或原始和预期)上下文的消息重播,从而欺骗诚实的参与者,让他们认为他们已经成功完成了协议运行。”假设爱丽丝想向鲍勃证明她的身份。
A replay attack (also known as a repeat attack or playback attack) is a form of network attack in which valid data transmission is maliciously or fraudulently repeated or delayed. This is carried out either by the originator or by an adversary who intercepts the data and re-transmits it, possibly as part of a spoofing attack by IP packet substitution. This is one of the lower-tier versions of a man-in-the-middle attack. Replay attacks are usually passive in nature. Another way of describing such an attack is: "an attack on a security protocol using a replay of messages from a different context into the intended (or original and expected) context, thereby fooling the honest participant(s) into thinking they have successfully completed the protocol run." Suppose Alice wants to prove her identity to Bob.
Sources, licensing and use
Wikipedia contributors · Retrieved2026-10-04 · CC BY-SA 4.0. Introductions were extracted as plain text and shortened. Language versions may emphasize different aspects.For concept reference; consult the original standards for authoritative requirements. The Chinese definition is a machine-assisted translation of the cited English introduction; check technical terminology against the original.
View content license ↗ Cryptography生日袭击生日攻击是一种暴力碰撞攻击,利用概率论中生日问题背后的数学原理。此攻击可用于滥用两方或多方之间的通信。攻击取决于随机攻击尝试和固定排列程度(鸽洞)之间发现的较高碰撞可能性。令 H {\textstyle H} 为哈希函数的可能值的数量,其中 H = 2 l {\textstyle H=2^{l}} 。通过生日攻击,可以在 2 l = 2 l / 2 , {\textstyle {\sqrt {2^{l}}}=2^{l/2},} 中找到哈希函数的冲突,概率为 50 % {\textstyle 50\%},其中 l {\textstyle l} 是哈希输出的位长度,而 2 l − 1 {\textstyle 2^{l-1}} 是经典的原像抵抗具有相同概率的安全性。
A birthday attack is a brute-force collision attack that exploits the mathematics behind the birthday problem in probability theory. This attack can be used to abuse communication between two or more parties. The attack depends on the higher likelihood of collisions found between random attack attempts and a fixed degree of permutations (pigeonholes). Let H {\textstyle H} be the number of possible values of a hash function, with H = 2 l {\textstyle H=2^{l}} . With a birthday attack, it is possible to find a collision of a hash function with 50 % {\textstyle 50\%} chance in 2 l = 2 l / 2 , {\textstyle {\sqrt {2^{l}}}=2^{l/2},} where l {\textstyle l} is the bit length of the hash output, and with 2 l − 1 {\textstyle 2^{l-1}} being the classical preimage resistance security with the same probability.
Sources, licensing and use
Wikipedia contributors · Retrieved2026-10-04 · CC BY-SA 4.0. Introductions were extracted as plain text and shortened. Language versions may emphasize different aspects.For concept reference; consult the original standards for authoritative requirements. The Chinese definition is a machine-assisted translation of the cited English introduction; check technical terminology against the original.
View content license ↗ Cryptography熵集体智慧 集体行动 自组织临界性 群体心态 相变 基于代理的建模 同步 蚁群优化 粒子群优化 群体行为 社交网络分析 小世界网络 中心性主题 图论 扩展 鲁棒性 系统生物学 动态网络 进化计算 遗传算法 遗传编程 人工生命 机器学习 进化发育生物学 人工智能 进化机器人
Collective intelligence Collective action Self-organized criticality Herd mentality Phase transition Agent-based modelling Synchronization Ant colony optimization Particle swarm optimization Swarm behaviour Social network analysis Small-world networks Centrality Motifs Graph theory Scaling Robustness Systems biology Dynamic networks Evolutionary computation Genetic algorithms Genetic programming Artificial life Machine learning Evolutionary developmental biology Artificial intelligence Evolutionary robotics
Sources, licensing and use
Wikipedia contributors · Retrieved2026-10-04 · CC BY-SA 4.0. Introductions were extracted as plain text and shortened. Language versions may emphasize different aspects.For concept reference; consult the original standards for authoritative requirements. The Chinese definition is a machine-assisted translation of the cited English introduction; check technical terminology against the original.
View content license ↗ Cryptography随机性在常见用法中,随机性是指信息中明显或实际缺乏明确的模式或可预测性。事件、符号或步骤的随机序列通常没有顺序,也不遵循可理解的模式或组合。根据定义,单个随机事件是不可预测的,但如果存在已知的概率分布,则重复事件(或“试验”)中不同结果的频率是可预测的。例如,当掷两个骰子时,任何特定骰子的结果都是不可预测的,但 7 的总和出现的频率往往是 4 的两倍。从这个角度来看,随机性并不是随意性;而是随机性。它是对结果不确定性的衡量。随机性适用于机会、概率和信息熵的概念。
In common usage, randomness is the apparent or actual lack of definite patterns or predictability in information. A random sequence of events, symbols or steps often has no order and does not follow an intelligible pattern or combination. Individual random events are, by definition, unpredictable, but if there is a known probability distribution, the frequency of different outcomes over repeated events (or "trials") is predictable. For example, when throwing two dice, the outcome of any particular roll is unpredictable, but a sum of 7 will tend to occur twice as often as 4. In this view, randomness is not haphazardness; it is a measure of uncertainty of an outcome. Randomness applies to concepts of chance, probability, and information entropy.
Sources, licensing and use
Wikipedia contributors · Retrieved2026-10-04 · CC BY-SA 4.0. Introductions were extracted as plain text and shortened. Language versions may emphasize different aspects.For concept reference; consult the original standards for authoritative requirements. The Chinese definition is a machine-assisted translation of the cited English introduction; check technical terminology against the original.
View content license ↗ Cryptography加密安全的伪随机数生成器加密安全伪随机数生成器 (CSPRNG) 或加密伪随机数生成器 (CPRNG) 是一种伪随机数生成器 (PRNG),其属性使其适合在密码学中使用。它也称为加密随机数生成器 (CRNG)。这些应用所需的随机性“质量”各不相同。例如,在某些协议中创建随机数只需要唯一性。另一方面,主密钥的生成需要更高的质量,例如更多的熵。在一次性密码本的情况下,只有当密钥材料来自具有高熵的真实随机源时,完全保密的信息论保证才成立,因此任何一种伪随机数生成器都是不够的。
A cryptographically secure pseudorandom number generator (CSPRNG) or cryptographic pseudorandom number generator (CPRNG) is a pseudorandom number generator (PRNG) with properties that make it suitable for use in cryptography. It is also referred to as a cryptographic random number generator (CRNG). The "quality" of the randomness required for these applications varies. For example, creating a nonce in some protocols needs only uniqueness. On the other hand, the generation of a master key requires a higher quality, such as more entropy. And in the case of one-time pads, the information-theoretic guarantee of perfect secrecy only holds if the key material comes from a true random source with high entropy, and thus just any kind of pseudorandom number generator is insufficient.
Sources, licensing and use
Wikipedia contributors · Retrieved2026-10-04 · CC BY-SA 4.0. Introductions were extracted as plain text and shortened. Language versions may emphasize different aspects.For concept reference; consult the original standards for authoritative requirements. The Chinese definition is a machine-assisted translation of the cited English introduction; check technical terminology against the original.
View content license ↗ Cryptography密钥导出函数在密码学中,密钥派生函数 (KDF) 是一种使用伪随机函数(通常使用加密哈希函数或分组密码)从秘密值(例如主密钥、密码或密码)派生一个或多个秘密密钥的算法。 KDF 可用于将密钥拉伸为更长的密钥或获取所需格式的密钥,例如将 Diffie-Hellman 密钥交换结果的组元素转换为用于 AES 的对称密钥。带密钥的加密哈希函数是用于密钥派生的伪随机函数的流行示例。 KDF 的最初用途是密钥派生,即从秘密密码或密码短语生成密钥。
In cryptography, a key derivation function (KDF) is an algorithm that derives one or more secret keys from a secret value, such as a master key, a password, or a passphrase using a pseudorandom function (which typically uses a cryptographic hash function or block cipher). KDFs can be used to stretch keys into longer keys or to obtain keys of a required format, such as converting a group element that is the result of a Diffie–Hellman key exchange into a symmetric key for use with AES. Keyed cryptographic hash functions are popular examples of pseudorandom functions used for key derivation. The original use for a KDF is key derivation, the generation of keys from secret passwords or passphrases.
Sources, licensing and use
Wikipedia contributors · Retrieved2026-10-04 · CC BY-SA 4.0. Introductions were extracted as plain text and shortened. Language versions may emphasize different aspects.For concept reference; consult the original standards for authoritative requirements. The Chinese definition is a machine-assisted translation of the cited English introduction; check technical terminology against the original.
View content license ↗ Cryptography氩气2Argon2 是一个密钥导出函数,被选为 2015 年密码哈希竞赛的获胜者。它是由卢森堡大学的 Alex Biryukov、Daniel Dinu 和 Dmitry Khovratovich 设计的。 Argon2 的参考实现是根据 Creative Commons CC0 许可证(即公共领域)或 Apache License 2.0 发布的。 Argon2 函数使用一个大的、固定大小的内存区域(在文档中通常称为“内存数组”),使得暴力攻击的计算成本很高。这三个变体在访问内存的方式上有所不同:虽然没有适用于 Argon2d 的公共密码分析,但有两个针对 Argon2i 函数的已发布攻击。第一种攻击仅适用于旧版本的Argon2i,而第二种攻击已扩展到最新版本(1.3)。
Argon2 is a key derivation function that was selected as the winner of the 2015 Password Hashing Competition. It was designed by Alex Biryukov, Daniel Dinu, and Dmitry Khovratovich from the University of Luxembourg. The reference implementation of Argon2 is released under a Creative Commons CC0 license (i.e. public domain) or the Apache License 2.0. The Argon2 function uses a large, fixed-size memory region (often called the 'memory array' in documentation) to make brute-force attacks computationally expensive. The three variants differ in how they access this memory: While there is no public cryptanalysis applicable to Argon2d, there are two published attacks on the Argon2i function. The first attack is applicable only to the old version of Argon2i, while the second has been extended to the latest version (1.3).
Sources, licensing and use
Wikipedia contributors · Retrieved2026-10-04 · CC BY-SA 4.0. Introductions were extracted as plain text and shortened. Language versions may emphasize different aspects.For concept reference; consult the original standards for authoritative requirements. The Chinese definition is a machine-assisted translation of the cited English introduction; check technical terminology against the original.
View content license ↗ CryptographyX.509(专业术语)在密码学中,X.509 是定义公钥证书格式的国际电信联盟 (ITU) 标准。 X.509 证书用于许多 Internet 协议,包括 TLS/SSL,它是 HTTPS(浏览网页的安全协议)的基础。它们还用于离线应用程序,例如电子签名。 X.509 证书使用数字签名将身份绑定到公钥。证书包含身份(主机名、组织或个人)和公钥(RSA、DSA、ECDSA、ed25519 等),并且由证书颁发机构 (CA) 签名或自签名。
In cryptography, X.509 is an International Telecommunication Union (ITU) standard defining the format of public key certificates. X.509 certificates are used in many Internet protocols, including TLS/SSL, which is the basis for HTTPS, the secure protocol for browsing the web. They are also used in offline applications, like electronic signatures. An X.509 certificate binds an identity to a public key using a digital signature. A certificate contains an identity (a hostname, or an organization, or an individual) and a public key (RSA, DSA, ECDSA, ed25519, etc.), and is either signed by a certificate authority (CA) or is self-signed.
Sources, licensing and use
Wikipedia contributors · Retrieved2026-10-04 · CC BY-SA 4.0. Introductions were extracted as plain text and shortened. Language versions may emphasize different aspects.For concept reference; consult the original standards for authoritative requirements. The Chinese definition is a machine-assisted translation of the cited English introduction; check technical terminology against the original.
View content license ↗ Cryptography前向保密在密码学中,前向保密 (FS) 也称为完美前向保密 (PFS),是特定密钥协商协议的一项功能,可保证即使会话密钥交换中使用的长期秘密被泄露,会话密钥也不会被泄露,从而限制损害。对于 TLS,长期秘密通常是服务器的私钥。前向保密可保护过去的会话免遭未来密钥或密码的泄露。通过为用户发起的每个会话生成唯一的会话密钥,单个会话密钥的泄露不会影响除受该特定密钥保护的特定会话中交换的数据之外的任何数据。这本身不足以实现前向保密,还要求长期的秘密妥协不会影响过去会话密钥的安全性。
In cryptography, forward secrecy (FS), also known as perfect forward secrecy (PFS), is a feature of specific key-agreement protocols that gives assurances that session keys will not be compromised even if long-term secrets used in the session key exchange are compromised, limiting damage. For TLS, the long-term secret is typically the private key of the server. Forward secrecy protects past sessions against future compromises of keys or passwords. By generating a unique session key for every session a user initiates, the compromise of a single session key will not affect any data other than that exchanged in the specific session protected by that particular key. This by itself is not sufficient for forward secrecy, which additionally requires that a long-term secret compromise does not affect the security of past session keys.
Sources, licensing and use
Wikipedia contributors · Retrieved2026-10-04 · CC BY-SA 4.0. Introductions were extracted as plain text and shortened. Language versions may emphasize different aspects.For concept reference; consult the original standards for authoritative requirements. The Chinese definition is a machine-assisted translation of the cited English introduction; check technical terminology against the original.
View content license ↗ Cryptography秘密分享秘密共享(也称为秘密分裂)是指在群体中分配秘密的方法,这样任何人都无法掌握有关秘密的任何可理解的信息,但是当足够数量的个人结合他们的“份额”时,秘密就可以被重建。不安全的秘密共享允许攻击者通过每次共享获得更多信息,而安全的秘密共享是“全部或全部”(其中“全部”表示必要的共享数量)。在一种类型的秘密共享方案中,有 1 个庄家和 n 个玩家。庄家将秘密的一部分交给玩家,但只有满足特定条件,玩家才能从他们的份额中重建秘密。
Secret sharing (also called secret splitting) refers to methods for distributing a secret among a group, in such a way that no individual holds any intelligible information about the secret, but when a sufficient number of individuals combine their 'shares', the secret may be reconstructed. Whereas insecure secret sharing allows an attacker to gain more information with each share, secure secret sharing is 'all or nothing' (where 'all' means the necessary number of shares). In one type of secret sharing scheme there is one dealer and n players. The dealer gives a share of the secret to the players, but only when specific conditions are fulfilled will the players be able to reconstruct the secret from their shares.
Sources, licensing and use
Wikipedia contributors · Retrieved2026-10-04 · CC BY-SA 4.0. Introductions were extracted as plain text and shortened. Language versions may emphasize different aspects.For concept reference; consult the original standards for authoritative requirements. The Chinese definition is a machine-assisted translation of the cited English introduction; check technical terminology against the original.
View content license ↗