contains 210 terms · This page displays 30 terms, you can enter keywords to query the complete range
Cryptography公钥基础设施PKI 通过证书、信任锚、发行和撤销流程把公钥与身份关联。验证证书链只是其中一步,还需校验名称、用途、时间和撤销状态。
PKI associates public keys with identities using certificates, trust anchors, issuance and revocation processes. Chain validation must be combined with name, purpose, time and status checks.
Sources, licensing and use
SciAtlas original bilingual definition · Edited2026-10-04 · CC BY-SA 4.0. Further-reading links provide context; the definition is original and does not assert that the linked page was retrieved or checked.For concept reference; consult the original standards for authoritative requirements.
View content license ↗ Cryptography公钥证书公钥证书是将身份或主体信息与公钥绑定的签名数据。信任取决于发行链和验证策略,而不是证书中自称的名称。
A public-key certificate is signed data binding a public key to subject information. Trust depends on the issuing chain and validation policy, not simply on a name asserted in the certificate.
Sources, licensing and use
SciAtlas original bilingual definition · Edited2026-10-04 · CC BY-SA 4.0. Further-reading links provide context; the definition is original and does not assert that the linked page was retrieved or checked.For concept reference; consult the original standards for authoritative requirements.
View content license ↗ Cryptography证书颁发机构证书颁发机构按照策略验证申请信息并签发证书。其可信度依赖操作控制、密钥保护和审计,签名本身不保证所有主体行为可靠。
A certificate authority validates requests under a policy and issues certificates. Its trust depends on operational controls, key protection and auditing; a signature does not guarantee all subject behavior.
Sources, licensing and use
SciAtlas original bilingual definition · Edited2026-10-04 · CC BY-SA 4.0. Further-reading links provide context; the definition is original and does not assert that the linked page was retrieved or checked.For concept reference; consult the original standards for authoritative requirements.
View content license ↗ Cryptography证书撤销列表CRL 是由发行者签名的已撤销证书序列号列表。验证时需检查发行者、签名和更新时间,过期列表不能可靠反映最新撤销情况。
A CRL is an issuer-signed list of revoked certificate serial numbers. Verification must check issuer, signature and update times, since a stale list may not reflect recent revocations.
Sources, licensing and use
SciAtlas original bilingual definition · Edited2026-10-04 · CC BY-SA 4.0. Further-reading links provide context; the definition is original and does not assert that the linked page was retrieved or checked.For concept reference; consult the original standards for authoritative requirements.
View content license ↗ Cryptography在线证书状态协议OCSP 允许查询证书状态并验证响应签名与有效期。服务可用性、隐私以及失败时的处理策略会影响实际系统的安全保证。
OCSP allows querying certificate status and verifying signed, time-bounded responses. Availability, privacy and failure policy influence the actual security guarantees of its deployment.
Sources, licensing and use
SciAtlas original bilingual definition · Edited2026-10-04 · CC BY-SA 4.0. Further-reading links provide context; the definition is original and does not assert that the linked page was retrieved or checked.For concept reference; consult the original standards for authoritative requirements.
View content license ↗ Cryptography传输层安全协议TLS 通过握手协商密钥和算法,并用记录层保护通信。协议版本、证书验证、密码套件和会话恢复都影响最终安全属性。
TLS negotiates keys and algorithms through a handshake and protects traffic with a record layer. Version selection, certificate validation, cipher suites and resumption affect the resulting security.
Sources, licensing and use
SciAtlas original bilingual definition · Edited2026-10-04 · CC BY-SA 4.0. Further-reading links provide context; the definition is original and does not assert that the linked page was retrieved or checked.For concept reference; consult the original standards for authoritative requirements.
View content license ↗ Cryptography硬件安全模块HSM 在受控硬件边界内执行密钥生成、保存和密码运算。其防护等级取决于具体设计及认证,不能代替应用层的权限控制。
An HSM generates, stores and uses keys within a controlled hardware boundary. Its protection level depends on design and certification, and it does not replace application-level authorization.
Sources, licensing and use
SciAtlas original bilingual definition · Edited2026-10-04 · CC BY-SA 4.0. Further-reading links provide context; the definition is original and does not assert that the linked page was retrieved or checked.For concept reference; consult the original standards for authoritative requirements.
View content license ↗ Cryptography可信平台模块TPM 是提供密钥保护、平台度量和相关证明操作的标准化安全组件。度量值的含义取决于启动链和验证策略,不能单独证明系统无漏洞。
A TPM is a standardized component for key protection, platform measurements and attestation operations. Measurement meaning depends on the boot chain and verification policy, not proof of a bug-free system.
Sources, licensing and use
SciAtlas original bilingual definition · Edited2026-10-04 · CC BY-SA 4.0. Further-reading links provide context; the definition is original and does not assert that the linked page was retrieved or checked.For concept reference; consult the original standards for authoritative requirements.
View content license ↗ Cryptography安全元件安全元件是用于隔离保存敏感凭据和执行安全操作的硬件部件。它通常受接口和访问策略限制,具体抗攻击能力依产品实现而异。
A secure element is hardware that isolates sensitive credentials and security operations behind controlled interfaces. Its resistance to physical and logical attacks depends on the particular implementation.
Sources, licensing and use
SciAtlas original bilingual definition · Edited2026-10-04 · CC BY-SA 4.0. Further-reading links provide context; the definition is original and does not assert that the linked page was retrieved or checked.For concept reference; consult the original standards for authoritative requirements.
View content license ↗ Cryptography恒定时间实现恒定时间密码实现避免执行路径或内存访问依赖秘密数据,以减少计时泄露;还需考虑编译器、缓存和处理器行为。
A constant-time cryptographic implementation avoids secret-dependent execution paths and memory access to reduce timing leakage. Compiler, cache and processor behavior must still be considered.
Sources, licensing and use
SciAtlas original bilingual definition · Edited2026-10-04 · CC BY-SA 4.0. Further-reading links provide context; the definition is original and does not assert that the linked page was retrieved or checked.For concept reference; consult the original standards for authoritative requirements.
View content license ↗ Cryptography密钥拉伸密钥拉伸通过有意昂贵的派生运算增加口令猜测成本。它不会增加原口令的真实熵,而是在一定资源预算下减慢攻击。
Key stretching deliberately makes derivation expensive to increase password-guessing cost. It does not increase the password's underlying entropy, but slows attacks under a resource budget.
Sources, licensing and use
SciAtlas original bilingual definition · Edited2026-10-04 · CC BY-SA 4.0. Further-reading links provide context; the definition is original and does not assert that the linked page was retrieved or checked.For concept reference; consult the original standards for authoritative requirements.
View content license ↗ Cryptography密钥封装机制KEM 使发送方产生共享秘密及封装密文,接收方用私钥恢复同一秘密。它常与对称认证加密组合构成混合加密系统。
A KEM lets a sender generate a shared secret and an encapsulation ciphertext, which a receiver decapsulates with a private key. It is commonly combined with symmetric authenticated encryption.
Sources, licensing and use
SciAtlas original bilingual definition · Edited2026-10-04 · CC BY-SA 4.0. Further-reading links provide context; the definition is original and does not assert that the linked page was retrieved or checked.For concept reference; consult the original standards for authoritative requirements.
View content license ↗ Cryptography密钥包裹密钥包裹使用另一个密钥对密钥材料进行保密和完整性保护,供存储或传输使用。算法和上下文需防止替换、重放与用途混淆。
Key wrapping protects key material under another key for storage or transport, generally providing confidentiality and integrity. Context must address substitution, replay and confusion between key purposes.
Sources, licensing and use
SciAtlas original bilingual definition · Edited2026-10-04 · CC BY-SA 4.0. Further-reading links provide context; the definition is original and does not assert that the linked page was retrieved or checked.For concept reference; consult the original standards for authoritative requirements.
View content license ↗ Cryptography密码学擦除密码学擦除通过销毁访问加密数据所需的密钥来使数据不可恢复。其有效性依赖没有残留密钥副本、备份或未加密数据。
Cryptographic erasure makes encrypted data inaccessible by destroying the necessary keys. Its effectiveness depends on the absence of surviving key copies, backups and unencrypted versions.
Sources, licensing and use
SciAtlas original bilingual definition · Edited2026-10-04 · CC BY-SA 4.0. Further-reading links provide context; the definition is original and does not assert that the linked page was retrieved or checked.For concept reference; consult the original standards for authoritative requirements.
View content license ↗ Cryptography密钥托管密钥托管安排第三方或特定机构保存可恢复密钥的材料,支持授权恢复;它同时引入新的信任主体和泄露、滥用风险。
Key escrow places recovery material with a third party or designated authority to support authorized recovery. It introduces additional trusted parties and potential disclosure or misuse paths.
Sources, licensing and use
SciAtlas original bilingual definition · Edited2026-10-04 · CC BY-SA 4.0. Further-reading links provide context; the definition is original and does not assert that the linked page was retrieved or checked.For concept reference; consult the original standards for authoritative requirements.
View content license ↗ Cryptography承诺方案承诺方案允许先固定一个值而暂不公开,之后再揭示并验证。安全定义通常要求隐藏性和绑定性,二者不能由普通摘要自动完全实现。
A commitment scheme fixes a value while initially hiding it, then allows verifiable opening. Security usually requires hiding and binding, which are not automatically supplied by an ordinary digest.
Sources, licensing and use
SciAtlas original bilingual definition · Edited2026-10-04 · CC BY-SA 4.0. Further-reading links provide context; the definition is original and does not assert that the linked page was retrieved or checked.For concept reference; consult the original standards for authoritative requirements.
View content license ↗ CryptographyPedersen 承诺Pedersen 承诺在离散对数群中用消息和随机盲因子构造承诺,具有加法同态关系;生成元之间的秘密关系不能被承诺者掌握。
Pedersen commitments combine a message with random blinding in a discrete-logarithm group and support additive homomorphism. The committing party must not know the secret relation between generators.
Sources, licensing and use
SciAtlas original bilingual definition · Edited2026-10-04 · CC BY-SA 4.0. Further-reading links provide context; the definition is original and does not assert that the linked page was retrieved or checked.For concept reference; consult the original standards for authoritative requirements.
View content license ↗ CryptographyFiat–Shamir 变换Fiat–Shamir 方法把交互证明中的挑战替换为公开记录的哈希值,用来构造非交互证明或签名;域分离和记录编码不可省略。
The Fiat–Shamir heuristic replaces an interactive challenge with a hash of the public transcript to build non-interactive proofs or signatures. Domain separation and unambiguous encoding are essential.
Sources, licensing and use
SciAtlas original bilingual definition · Edited2026-10-04 · CC BY-SA 4.0. Further-reading links provide context; the definition is original and does not assert that the linked page was retrieved or checked.For concept reference; consult the original standards for authoritative requirements.
View content license ↗ Cryptography混淆电路混淆电路用编码的导线标签和加密门表,使参与方在不知道另一方输入时共同计算函数。安全性还取决于输入传递和协议模型。
Garbled circuits use encoded wire labels and encrypted gate tables for jointly evaluating a function without disclosing another party's inputs. Input transfer and the adversary model remain essential.
Sources, licensing and use
SciAtlas original bilingual definition · Edited2026-10-04 · CC BY-SA 4.0. Further-reading links provide context; the definition is original and does not assert that the linked page was retrieved or checked.For concept reference; consult the original standards for authoritative requirements.
View content license ↗ Cryptography私有信息检索私有信息检索允许用户查询数据库记录而不向服务端暴露所选位置。它可依赖多个不串通服务器或计算假设,并非默认隐藏全部通信元数据。
Private information retrieval hides the selected database position from the server. It may rely on noncolluding servers or computational assumptions and does not automatically hide all traffic metadata.
Sources, licensing and use
SciAtlas original bilingual definition · Edited2026-10-04 · CC BY-SA 4.0. Further-reading links provide context; the definition is original and does not assert that the linked page was retrieved or checked.For concept reference; consult the original standards for authoritative requirements.
View content license ↗ Cryptography私有集合求交私有集合求交使参与方获得集合交集而尽量不暴露其他元素。交集大小、输出接收方和恶意参与者防护需要在协议中明确。
Private set intersection lets parties learn shared set elements while limiting disclosure of other elements. Intersection-size leakage, output recipients and malicious-party protection must be specified.
Sources, licensing and use
SciAtlas original bilingual definition · Edited2026-10-04 · CC BY-SA 4.0. Further-reading links provide context; the definition is original and does not assert that the linked page was retrieved or checked.For concept reference; consult the original standards for authoritative requirements.
View content license ↗ Cryptography环签名环签名证明签名来自某个公开密钥集合中的成员,同时隐藏具体成员。匿名性和可链接性取决于变体,不能把它等同于普通多重签名。
A ring signature shows that one member of a public-key set signed while concealing which member. Anonymity and linkability depend on the variant; it is distinct from an ordinary multisignature.
Sources, licensing and use
SciAtlas original bilingual definition · Edited2026-10-04 · CC BY-SA 4.0. Further-reading links provide context; the definition is original and does not assert that the linked page was retrieved or checked.For concept reference; consult the original standards for authoritative requirements.
View content license ↗ Cryptography盲签名盲签名允许签名者在看不到完整消息内容时生成可验证签名,常用于隐私凭证;协议仍需控制授权范围和重复兑换问题。
A blind signature lets a signer produce a verifiable signature without seeing the unblinded message. Privacy credentials use this idea, but authorization and double-spending controls remain separate needs.
Sources, licensing and use
SciAtlas original bilingual definition · Edited2026-10-04 · CC BY-SA 4.0. Further-reading links provide context; the definition is original and does not assert that the linked page was retrieved or checked.For concept reference; consult the original standards for authoritative requirements.
View content license ↗ Cryptography群签名群签名使注册群成员匿名代表群体签署消息,并可由指定管理角色按规则揭示身份。加入、撤销和揭示权限是其协议的重要部分。
A group signature lets enrolled members sign anonymously for a group, sometimes with designated opening authorities. Enrollment, revocation and opening permissions are important parts of the protocol.
Sources, licensing and use
SciAtlas original bilingual definition · Edited2026-10-04 · CC BY-SA 4.0. Further-reading links provide context; the definition is original and does not assert that the linked page was retrieved or checked.For concept reference; consult the original standards for authoritative requirements.
View content license ↗ Cryptography聚合签名聚合签名把多个消息及公钥对应的签名组合成较短对象供联合验证。防范恶意公钥和重复消息等问题需要方案规定的验证步骤。
Aggregate signatures combine signatures for multiple messages and public keys into a compact object. Scheme-specific checks are required to address rogue keys, repeated messages and related attacks.
Sources, licensing and use
SciAtlas original bilingual definition · Edited2026-10-04 · CC BY-SA 4.0. Further-reading links provide context; the definition is original and does not assert that the linked page was retrieved or checked.For concept reference; consult the original standards for authoritative requirements.
View content license ↗ Cryptography身份基加密身份基加密从身份字符串构造公开加密标识,由可信机构发行对应私钥。它减少证书需求,却增加对私钥发行机构的信任。
Identity-based encryption derives public encryption identifiers from identity strings while a trusted authority issues private keys. It reduces certificate needs but adds trust in the key-issuing authority.
Sources, licensing and use
SciAtlas original bilingual definition · Edited2026-10-04 · CC BY-SA 4.0. Further-reading links provide context; the definition is original and does not assert that the linked page was retrieved or checked.For concept reference; consult the original standards for authoritative requirements.
View content license ↗ Cryptography属性基加密属性基加密把解密权限与属性和访问策略关联,支持更细的权限表达。撤销、策略隐私及多方串通抵抗取决于具体方案。
Attribute-based encryption associates decryption rights with attributes and access policies. Revocation, policy privacy and resistance to colluding users depend on the particular construction.
Sources, licensing and use
SciAtlas original bilingual definition · Edited2026-10-04 · CC BY-SA 4.0. Further-reading links provide context; the definition is original and does not assert that the linked page was retrieved or checked.For concept reference; consult the original standards for authoritative requirements.
View content license ↗ Cryptography功能加密功能加密让特定密钥持有者仅获得明文的某个函数值,而非完整明文。可支持的函数类别与泄露范围由安全定义和构造限定。
Functional encryption lets a key holder learn a specified function of plaintext rather than the full plaintext. Supported function classes and permitted leakage are bounded by the construction and security definition.
Sources, licensing and use
SciAtlas original bilingual definition · Edited2026-10-04 · CC BY-SA 4.0. Further-reading links provide context; the definition is original and does not assert that the linked page was retrieved or checked.For concept reference; consult the original standards for authoritative requirements.
View content license ↗ Cryptography可搜索加密可搜索加密支持在受保护数据上执行限定查询。查询模式、访问模式和结果数量可能泄露信息,因此不能简单等同于完全隐藏数据库。
Searchable encryption supports restricted queries over protected data. Query patterns, access patterns and result counts may leak information, so it does not imply a completely hidden database.
Sources, licensing and use
SciAtlas original bilingual definition · Edited2026-10-04 · CC BY-SA 4.0. Further-reading links provide context; the definition is original and does not assert that the linked page was retrieved or checked.For concept reference; consult the original standards for authoritative requirements.
View content license ↗ Cryptography代理重加密代理重加密允许代理使用转换令牌改变密文的解密对象而不直接获取明文。授权方向、密钥串通和令牌撤销需由方案明确。
Proxy re-encryption lets a proxy transform ciphertext for another recipient using a re-encryption token without directly learning plaintext. Directionality, collusion and token revocation require explicit design.
Sources, licensing and use
SciAtlas original bilingual definition · Edited2026-10-04 · CC BY-SA 4.0. Further-reading links provide context; the definition is original and does not assert that the linked page was retrieved or checked.For concept reference; consult the original standards for authoritative requirements.
View content license ↗