Reference
Glossary
44 terms. Each points to the module where it is taught in depth.
- BDKBase Derivation KeyM10
- The root key of DUKPT, never loaded into a terminal. All transaction keys derive from it.
- CAVPCryptographic Algorithm Validation ProgramM5
- NIST's program that tests whether an implementation of an algorithm is mathematically correct. Passing CAVP means the algorithm is implemented correctly, not that the whole module is secure.
- CBOMCryptography Bill of MaterialsM12
- An inventory of every cryptographic asset a system uses: algorithms, certificates, protocols and keys. Produced as an extension of the CycloneDX standard.
- CMVPCryptographic Module Validation ProgramM5
- NIST's program that validates a whole cryptographic module (the full hardware or software boundary) against FIPS 140-3. Broader and slower than CAVP.
- CNSA 2.0Commercial National Security Algorithm Suite 2.0M6
- NSA's PQC transition schedule for national security systems. Hybrid is allowed in the interim but the end goal is pure PQC (2030 for software and firmware, 2033 for operating systems, web and cloud).
- CompositeM6
- Combining a classical and a PQC signature inside one X.509 certificate or signature object. The certificate-level counterpart of hybrid key exchange.
- CRLCertificate Revocation ListM7
- A list of all revoked certificates that clients download and check. Larger than OCSP responses but needs no live server query.
- CRQCCryptographically Relevant Quantum ComputerM1
- A quantum computer large enough to break today's asymmetric cryptography (RSA, ECC) in practice. Its arrival date is uncertain; the Global Risk Institute survey gives a probability range (28 to 49% within 10 years).
- Crypto-agilityM12
- The ability to change the algorithm a system uses quickly, without it being buried deep in code, if that algorithm is found insecure tomorrow. Achieved through provider models such as OpenSSL providers, JCE and PKCS#11.
- Digital signatureM4
- A family of algorithms that sign a message so that the sender can be verified and the message proven unchanged. ML-DSA, SLH-DSA and FN-DSA are the PQC signature standards this course covers.
- DORADigital Operational Resilience ActM11
- The EU regulation on ICT risk management for financial entities, in force since 17 January 2025. It covers cryptography under a risk-based 'remain abreast' principle and gives no PQC-specific date.
- DUKPTDerived Unique Key Per TransactionM10
- A key management scheme that derives a separate key for each transaction on payment terminals. The Base Derivation Key stays in a central HSM; only a derived key and KSN are loaded into the terminal.
- ECHEncrypted Client HelloM12
- The TLS 1.3 extension that encrypts the contents of the ClientHello, including SNI. It creates a blind spot for network-based crypto discovery.
- EO 14412M11
- The US executive order mandating the PQC transition in federal high value asset (HVA) systems: key establishment by 31 December 2030, signatures by 31 December 2031.
- Falcon / FN-DSAM4
- A compact signature scheme based on NTRU lattices. As of September 2026 it is not yet a FIPS standard (pre-IPD, DRAFT), so production decisions need care.
- Grover's algorithmM1
- A quantum speedup against symmetric cryptography such as AES. Its effect is moderate: it roughly halves effective key length (AES-128 drops to roughly 64-bit strength), which is why AES-256 is considered sufficient.
- HNDLHarvest Now, Decrypt LaterM1
- The threat of capturing encrypted data today and decrypting it later with a quantum computer. If data must stay secret for long (mortgage data, for example), the risk has already started.
- Hostile reviewgeneral
- This course's own process step: after each module, an adversarial review runs as a hostile bank architect and as a lost beginner, independently re-verifying primary sources.
- HQCHamming Quasi-CyclicM4
- A code-based backup KEM. Mathematically independent of ML-KEM's lattice family, it provides diversity against a break of that whole family.
- HSMHardware Security ModuleM9
- Dedicated hardware that keeps cryptographic keys inside a hardware boundary so they never leave in plaintext. Usually accessed through PKCS#11.
- Hybrid (key exchange)M6
- Using classical (e.g. X25519) and PQC (e.g. ML-KEM-768) key agreement together in one TLS key exchange, combining them into one secret. The classical side is a safety net if the PQC side turns out to be weak.
- initcwndM8
- TCP's initial congestion window, usually 10 segments. If a TLS handshake flight exceeds it, the server may have to wait an extra round trip. Large PQC messages cross this threshold more easily.
- KEMKey Encapsulation MechanismM3
- A key encapsulation mechanism. Unlike classical Diffie-Hellman, the sender encapsulates a secret with the recipient's public key and the recipient decapsulates it with their private key. ML-KEM is the PQC standard in this family.
- KSNKey Serial NumberM10
- In DUKPT, the serial number a terminal sends to identify which derived key was used. It does not contain the BDK, only the derivation path.
- KyberSlashM14
- A family of real timing vulnerabilities in the ML-KEM (Kyber) reference implementation: dividing a secret value by a public constant created CPU- and compiler-dependent timing differences. The math was right; the code was wrong.
- LatticeM2
- A set of points arranged at regular intervals in a many-dimensional space. ML-KEM and ML-DSA rely on the hardness of certain problems on this structure.
- LWELearning With ErrorsM2
- The core hardness problem of lattice-based cryptography: the assumption that recovering a secret vector from noisy linear equations is computationally hard. ML-KEM and ML-DSA rely on its Module-LWE variant.
- Mosca's inequalityM1
- If X + Y > Z, start worrying now: X is how long data must stay secret, Y is how long migration takes, Z is the time until a cryptographically relevant quantum computer exists.
- MTCMerkle Tree CertificatesM7
- A certificate format being developed in the IETF PLANTS working group to shrink certificate chains. A mitigation for the large size of PQC signatures.
- OCSPOnline Certificate Status ProtocolM7
- A protocol for checking in real time whether a certificate is still valid or has been revoked. The alternative to downloading a full CRL.
- ODAOffline Data AuthenticationM10
- The asymmetric EMV mechanism (SDA, DDA, CDA) that authenticates a card while card and terminal are offline. Exposed to Shor, and the uncounted eleventh exception to the M10 classification.
- PKCS#11M9
- The abstract, standard interface for talking to an HSM. It gives a common call pattern (for example C_EncapsulateKey and C_DecapsulateKey) regardless of vendor.
- Provenance tagsM0
- The five-value tag on every number in this course (MEASURED, SOURCED, DERIVED, ESTIMATED, UNSOURCED), showing whether a figure was measured, taken from a primary source, computed, or estimated.
- QKDQuantum Key DistributionM15
- Hardware that distributes keys using physical quantum properties. A completely different category from PQC. NSA, the UK NCSC and ANSSI each independently advise against it for general enterprise use.
- RACIM13
- A governance matrix showing who is Responsible, Accountable, Consulted and Informed for a task. Used to make vendor dependencies visible in a migration program.
- RainbowM14
- A multivariate signature candidate and Round 3 finalist. Broken in 2022 by Beullens's attack in about 53 hours on a standard laptop, and not selected.
- Reflection policyM11
- A planning heuristic invented by this course: the assumption that Turkey typically mirrors international regulatory dates with a lag of about 1 to 2 years. NOT an official BDDK or TCMB figure.
- SBOMSoftware Bill of MaterialsM12
- An inventory of every component (libraries, dependencies) a piece of software uses. A CBOM is its cryptography-specific extension.
- Shor's algorithmM1
- A devastating quantum algorithm against asymmetric cryptography (RSA, ECC). It solves factoring and discrete logarithms in polynomial time, so RSA and ECC are broken outright, not merely weakened.
- SIKEM14
- An isogeny-based KEM candidate. Broken in 2022 by Castryck and Decru with a classical (non-quantum) attack that ran in minutes on an ordinary computer, and removed from the NIST process.
- SLH-DSAM4
- A stateless hash-based signature standard (formerly SPHINCS+). Signatures are large but no state management is needed, so it is positioned as the conservative backup option.
- Status disciplineM5
- This course's seven-value status vocabulary (FINAL, DRAFT, SELECTED, CANDIDATE, VALIDATED, DEPLOYED, WITHDRAWN) for stating exactly where a standard or algorithm stands. 'Selected' and 'certified' are different claims.
- Supersedes chaingeneral
- The field in data/numbers.json showing that a value replaced an earlier (wrong or outdated) one. It keeps the correction history visible instead of hiding it.
- Vendor lock-in (PQC context)M13
- The possibility that a vendor profits from delaying its own PQC transition and keeping customers on legacy or proprietary integrations longer. The reason not to trust a vendor roadmap claim without independent verification.
No matching term.