key
Let an agent reason about cryptographic keys by type, strength, lifecycle and custody, and never ask for, display or move a secret or private key.
Research draft, second pass
A second pass drafted this model: the structure a model of this thing needs, and what is known about it in the world. The line under this one says how the second half was obtained - researched against sources, or recalled without web access, in which case nothing here was read anywhere and every claim is a lead to verify. Unreviewed either way.
written by Claude from model knowledge without web access - no source was read, every claim is a lead to verify
Researched by: Claude
Purpose and description
Let an agent reason about cryptographic keys by type, strength, lifecycle and custody, and never ask for, display or move a secret or private key.
In cryptography, a piece of information that determines the output of a cryptographic algorithm, such as a secret key for symmetric encryption or a public and private key pair.
What it is for: Encrypting and decrypting data, signing and verifying, and authenticating systems and people.
It can be generate it, with a secure random source; store and protect it, in hardware or key vaults; rotate and revoke it; publish the public half, while keeping the private half secret.
Distinguishing features
Secrecy of the private or secret key is the whole point
Public keys can be shared; private keys never
Strength depends on algorithm and length
A hashed password is not a key, though both protect access
What it looks like
A string of bits, usually shown as base64 or hex, or held inside a hardware security module or smart card where it cannot be seen.
Physical character
key length: 128-4096 bits - AES 128-256, RSA 2048-4096, Ed25519 256
How it is recognised
PEM blocks such as BEGIN PUBLIC KEY or BEGIN PRIVATE KEY
SSH public keys starting with ssh-ed25519 or ssh-rsa
Fingerprints identify keys without revealing them
Related models
is used by - the key parameterises the algorithm
is bound to - certificates bind public keys to identities
is confused with - a homonym
is confused with - passwords are human secrets; keys are machine secrets
In practice
Families and kinds
symmetric secret keys
asymmetric public and private key pairs
session keys
signing keys and encryption keys
weak keys to be avoided
Identifiers
key fingerprint hash of the public key identifies a key without exposing it
key ID system-specific names a key in a vault or keyring
Standards and regulation
NIST SP 800-57 key management
FIPS 140-3 cryptographic modules
RFC 8032 Ed25519 and other algorithm standards
Export control rules on cryptography
Failure modes and hazards
Leaked private keys, which compromise everything they protect
Keys committed to source code or logs
Weak or short keys
Lost keys making data unrecoverable
Also called
Where this came from
wikidata · CC0 1.0
Also registered as vr.tr.key-artifact
Drafted structure
Bundle to layer to finding to question, as the second pass will find it: 4 bundles · 8 layers · 8 findings · 16 questions.
Type and strength What kind of key.
Type and length decide security.
Type
Symmetric or asymmetric.
Key type
Algorithm and use.
- Which algorithm and use is this key for? definition
- Is it the public or the private half? boundary
Strength
Length and algorithm.
Strength
Length and current guidance.
- Is its length adequate under current guidance? measurement
- When should it be replaced? action
Custody Where it lives and who can use it.
Custody is where keys are won or lost.
Storage
HSM, vault, file.
Storage
Where the key is held.
- Where is the private key stored, and is it protected by hardware? definition
- Who has access to it? provenance
Handling rules
Never display or transmit secrets.
Handling rule
Rules for agents.
- Is key material present in this data, and should it be redacted? boundary
- What should an agent do instead of handling the key? action
Lifecycle From generation to destruction.
Keys must be rotated and retired.
Generation
Randomness and ceremony.
Generation
How the key was generated.
- How was the key generated, and with what randomness? provenance
- When was it created? provenance
Rotation and revocation
Replacing and revoking.
Rotation
Rotation schedule and revocation.
- When is it rotated, and how is it revoked if compromised? action
- How is revocation communicated? action
Trust Binding keys to identities.
A key is only as trustworthy as its binding.
Binding
Certificates and fingerprints.
Identity binding
How the key is bound to an identity.
- Which certificate or fingerprint binds this public key to its owner? provenance
- How was the fingerprint verified? provenance
Compromise
Suspected leaks.
Incident response
Steps after compromise.
- What must happen if this key is suspected compromised? action
- What data does it expose? boundary
What the second pass must settle
- Should key types be separate entries?
- How should key metadata be recorded without ever recording key material?
- What must an agent do when it encounters a secret key in data?