Skip to content

Glossary ​

Terms as this documentation uses them. Entries link to the page that explains them in context.

TermMeaning
AAD (associated data)Data that is authenticated but not encrypted. In an envelope it is stored in clear and bound to the ciphertext; the opener states the value it expects (expectedAad). Encryption
ACVPNIST's Automated Cryptographic Validation Protocol: known-answer test vectors. Passing them is evidence of correctness. Security
AEADAuthenticated encryption with associated data. Here: AES-256-GCM.
AKP"Algorithm Key Pair": the JWK key type (kty: "AKP") RFC 9964 uses for ML-DSA keys. JWT
Algorithm bindingEvery key, sealed message and signed message names its algorithm and version, and readers check both. Concepts
Anonymous encryptionEncryption to a public key that does not say who encrypted it. Envelopes and streams are anonymous; sign them if attribution matters.
Argon2idA memory-hard password hash. deriveMasterKey uses 19 MiB, 2 passes, 1 lane. Keys
CBOMCryptographic bill of materials: an inventory of the cryptography a system uses (CycloneDX 1.6). Audit
CBORConcise Binary Object Representation: the binary format of keys, sealed messages and signed messages.
CNSA 2.0NSA's Commercial National Security Algorithm Suite 2.0: ML-KEM-1024, ML-DSA-87, AES-256, SHA-384/512, LMS/XMSS. CNSA 2.0
Compare-and-setA write that succeeds only if the stored value is still what the writer last saw. Makes migration transitions safe across processes. Migration
ContextA label (at most 255 bytes) that ties a signature to one purpose. The verifier states the one it expects (expectedContext). Concepts
Decapsulation / encapsulationThe two KEM operations: the sender encapsulates to a public key and gets a ciphertext and a shared secret; the key holder decapsulates the ciphertext to the same secret. KEM
EnvelopeA self-describing, authenticated, public-key encrypted message (SealedMessage). v1 for hybrid keys, v2 for pure ML-KEM-1024. Encryption
FIPS 203 / 204 / 205The NIST standards for ML-KEM, ML-DSA and SLH-DSA.
Hedged signingSigning with fresh randomness mixed in, which blunts some fault attacks. In the default format a verifier must match the signer's mode. Concepts
HKDFHMAC-based key derivation (RFC 5869). SHA-256 for v1 envelopes and deriveKey, SHA-384 for v2 envelopes.
HybridA classical algorithm and a post-quantum one used together so that an attacker must break both. Concepts
Implicit rejectionML-KEM's design: decapsulating a modified ciphertext returns a pseudo-random secret instead of an error. KEM
JWK / JWKSJSON Web Key / a set of them. Public keys only are ever served. JWT
KEMKey encapsulation mechanism. KEM
LMS / HSS / XMSSStateful hash-based signature schemes (RFC 8554, SP 800-208). This library verifies LMS/HSS; it does not sign. Signatures
M2The bytes signed in the -v2 format: len(algo) ‖ algo ‖ len(ctx) ‖ ctx ‖ message. Signatures
MCPModel Context Protocol: how a coding agent calls tools. MCP server
Migration stateclassical_only → hybrid_transition → pqc_preferred → pqc_only: where a key is in its move to post-quantum. Migration
ML-KEM / ML-DSA / SLH-DSAThe NIST post-quantum KEM (lattice), signature (lattice) and hash-based signature.
NSSNational Security Systems (US).
Parity by fixtureProving two libraries agree by having each consume data produced by the real other one. Interop
PEMText armour for keys: -----BEGIN QUANTUM SAFE PUBLIC KEY-----.
Post-quantum (PQC)Cryptography believed to resist a large quantum computer.
SARIFStatic Analysis Results Interchange Format (2.1.0): how scanner results reach GitHub code scanning. Action
Shared secretThe secret both sides of a KEM end up with. Derive keys from it; never use it directly. SecretBytes / SharedSecret.
STREAMA construction for chunked authenticated encryption (counter and last-chunk flag in the nonce). Streaming
Typed errorAn error with a class, a stable code and a static hint. Errors
-v2The cleaner signature format: no prefix, native FIPS 204 context over a wrapped message M2, algorithm and context signed. Not a standard signature over your message. Signatures
WebAssembly (WASM)The portable binary format the Rust core is compiled to. Runtimes
X-WingA hybrid KEM (X25519 + ML-KEM-768) specified in draft-connolly-cfrg-xwing-kem, implemented by several libraries. KEM
X25519 / Ed25519 / P-256The classical key exchange, signature and NIST-curve algorithms used as the classical half of hybrids.

Apache-2.0.