← Back to catalogue
Research draft

key

vr.tr.key-q471771 · INF.MED

Let an agent reason about cryptographic keys by type, strength, lifecycle and custody, and never ask for, display or move a secret or private key.

Thing Registry Information and virtual systems

Research draft, second pass

A second pass drafted this model: the structure a model of this thing needs, and what is known about it in the world. The line under this one says how the second half was obtained - researched against sources, or recalled without web access, in which case nothing here was read anywhere and every claim is a lead to verify. Unreviewed either way.

written by Claude from model knowledge without web access - no source was read, every claim is a lead to verify

Researched by: Claude

Purpose and description

Let an agent reason about cryptographic keys by type, strength, lifecycle and custody, and never ask for, display or move a secret or private key.

In cryptography, a piece of information that determines the output of a cryptographic algorithm, such as a secret key for symmetric encryption or a public and private key pair.

What it is for: Encrypting and decrypting data, signing and verifying, and authenticating systems and people.

It can be generate it, with a secure random source; store and protect it, in hardware or key vaults; rotate and revoke it; publish the public half, while keeping the private half secret.

Distinguishing features

Secrecy of the private or secret key is the whole point

Public keys can be shared; private keys never

Strength depends on algorithm and length

A hashed password is not a key, though both protect access

What it looks like

A string of bits, usually shown as base64 or hex, or held inside a hardware security module or smart card where it cannot be seen.

Physical character

key length: 128-4096 bits - AES 128-256, RSA 2048-4096, Ed25519 256

How it is recognised

PEM blocks such as BEGIN PUBLIC KEY or BEGIN PRIVATE KEY

SSH public keys starting with ssh-ed25519 or ssh-rsa

Fingerprints identify keys without revealing them

Related models

is used by - the key parameterises the algorithm

cryptographic algorithm

is bound to - certificates bind public keys to identities

certificate

is confused with - a homonym

key for a lock

is confused with - passwords are human secrets; keys are machine secrets

password

In practice

Families and kinds

symmetric secret keys

asymmetric public and private key pairs

session keys

signing keys and encryption keys

weak keys to be avoided

Identifiers

key fingerprint hash of the public key identifies a key without exposing it

key ID system-specific names a key in a vault or keyring

Standards and regulation

NIST SP 800-57 key management

FIPS 140-3 cryptographic modules

RFC 8032 Ed25519 and other algorithm standards

Export control rules on cryptography

Failure modes and hazards

Leaked private keys, which compromise everything they protect

Keys committed to source code or logs

Weak or short keys

Lost keys making data unrecoverable

Also called

private keypublic keyhashed passwordsession keyweak keysecret keySSH public keyPGP public keybitcoin address

Where this came from

wikidata · CC0 1.0

Also registered as vr.tr.key-artifact

Drafted structure

Bundle to layer to finding to question, as the second pass will find it: 4 bundles · 8 layers · 8 findings · 16 questions.

Type and strength What kind of key.

Type and length decide security.

Type

Symmetric or asymmetric.

Key type

Algorithm and use.

  1. Which algorithm and use is this key for? definition
  2. Is it the public or the private half? boundary

Strength

Length and algorithm.

Strength

Length and current guidance.

  1. Is its length adequate under current guidance? measurement
  2. When should it be replaced? action
Custody Where it lives and who can use it.

Custody is where keys are won or lost.

Storage

HSM, vault, file.

Storage

Where the key is held.

  1. Where is the private key stored, and is it protected by hardware? definition
  2. Who has access to it? provenance

Handling rules

Never display or transmit secrets.

Handling rule

Rules for agents.

  1. Is key material present in this data, and should it be redacted? boundary
  2. What should an agent do instead of handling the key? action
Lifecycle From generation to destruction.

Keys must be rotated and retired.

Generation

Randomness and ceremony.

Generation

How the key was generated.

  1. How was the key generated, and with what randomness? provenance
  2. When was it created? provenance

Rotation and revocation

Replacing and revoking.

Rotation

Rotation schedule and revocation.

  1. When is it rotated, and how is it revoked if compromised? action
  2. How is revocation communicated? action
Trust Binding keys to identities.

A key is only as trustworthy as its binding.

Binding

Certificates and fingerprints.

Identity binding

How the key is bound to an identity.

  1. Which certificate or fingerprint binds this public key to its owner? provenance
  2. How was the fingerprint verified? provenance

Compromise

Suspected leaks.

Incident response

Steps after compromise.

  1. What must happen if this key is suspected compromised? action
  2. What data does it expose? boundary

What the second pass must settle

  • Should key types be separate entries?
  • How should key metadata be recorded without ever recording key material?
  • What must an agent do when it encounters a secret key in data?