KORTHEXDocumentation

Docs / FUNDAMENTALS

FUNDAMENTALS

Glossary

Written and maintained by Hendrik Schneider · Last reviewed · How we check this

Common terms used throughout the documentation. Cross-referenced from every section so you can jump back here whenever you hit a piece of jargon.

Cryptography Terms

TermDefinition
AEADAuthenticated Encryption with Associated Data. A scheme that encrypts and authenticates in one operation (AES-GCM, ChaCha20-Poly1305, AES-CCM).
AESAdvanced Encryption Standard. The dominant symmetric block cipher. Recommended at 256-bit keys; 128-bit acceptable.
Block cipher modeHow a block cipher is applied to larger data. ECB (bad - patterns leak), CBC (needs MAC), CTR (needs unique nonce), GCM (AEAD, recommended).
ChaCha20-Poly1305Modern AEAD stream cipher. Equivalent security to AES-GCM, faster in software, recommended.
HKDFHMAC-based Key Derivation Function. Standard way to derive multiple keys from one master secret.
HMACKeyed message-authentication code. Used for integrity. HMAC-SHA-256 is the typical choice.
IV / NonceInitialization Vector / Number-used-once. Random value paired with a key to make the same plaintext encrypt to different ciphertexts. Reuse breaks security.
KDFKey Derivation Function. Turns a secret (password, master key) into one or more usable cryptographic keys.
KEMKey Encapsulation Mechanism. The PQC-era way to do what RSA-OAEP did: encrypt a session key with a public key.
MACMessage Authentication Code. Proves a message wasn't altered (HMAC, GMAC, Poly1305).
Padding OracleAn attack class against CBC mode when padding errors are observable.
PBKDF2 / scrypt / Argon2 / bcryptPassword-hashing functions. Designed to be slow + memory-hard. Argon2id and bcrypt(>=12) are the current recommendation.
PKCS#1 v1.5 / OAEPTwo RSA padding schemes. v1.5 is vulnerable to Bleichenbacher attacks; OAEP is the safe modern choice.
RSAAsymmetric algorithm. Quantum-vulnerable. Min 2048 bits today; migrate to ML-KEM (encryption) or ML-DSA (signatures).
SaltRandom per-record value mixed into a hash to defeat rainbow-table attacks.
SHA-2 / SHA-3Cryptographic hash functions. SHA-256 / SHA-384 / SHA-512 (SHA-2) and SHA3-256 / SHA3-512 (SHA-3) are all recommended.
TLSTransport Layer Security. TLS 1.2+ recommended; 1.0 and 1.1 are deprecated; SSL of any version is disallowed.

Post-Quantum Cryptography

TermDefinition
PQCPost-Quantum Cryptography. Schemes designed to remain secure against attackers with large-scale quantum computers.
Harvest Now, Decrypt Later (HNDL)Threat model: an attacker captures encrypted traffic today and stores it until quantum capability arrives. Drives the urgency of migrating before 2030.
ML-KEM (Kyber)FIPS 203. Key encapsulation. The PQC replacement for RSA-OAEP and ECDH key exchange.
ML-DSA (Dilithium)FIPS 204. Digital signatures. The PQC replacement for RSA signatures and ECDSA.
SLH-DSA (SPHINCS+)FIPS 205. Stateless hash-based signatures. For long-lived signatures (firmware, root certs) where conservative assumptions matter.
Hybrid cryptographyCombining a classical primitive with a PQC primitive so the system is secure if either holds. Standard transition pattern.
Quantum-vulnerableSchemes whose security collapses against Shor's algorithm: RSA, DH, ECDH, ECDSA.
Quantum-resistant / Quantum-safeSchemes for which no known quantum advantage exists (AES-256, ChaCha20, SHA-256, ML-KEM, ML-DSA, SLH-DSA).
CNSA 2.0NSA's Commercial National Security Algorithm Suite 2.0. Specifies the PQC transition timeline for national-security systems.
NIST PQCThe NIST post-quantum standardization project that produced ML-KEM, ML-DSA, and SLH-DSA.

Korthex Concepts

TermDefinition
Baseline RegistryKorthex's central truth source for algorithm classification. Every severity, ELS score, and compliance verdict traces back to a lookup here.
Baseline statusRecommended / Acceptable / Deprecated / Disallowed / Not-crypto / Unknown.
CBOMCryptographic Bill of Materials. The CycloneDX-format SBOM extended with crypto-asset semantics.
SBOMSoftware Bill of Materials. Standard formats: CycloneDX, SPDX.
FindingA single instance of weak / interesting cryptography Korthex detected.
ClusterA group of related findings sharing the same algorithm + usage pattern across files.
TaintTracking how a cryptographic value (key, IV, salt) flows from its source through the program.
Severity ladderCRITICAL / HIGH / MEDIUM / LOW / INFO. Determined by Baseline Registry + Taint analysis.
ELSExploit Likelihood Score. 0-10 scale produced by the Exploit Engine. Combines algorithm-strength + key-length + mode + source + context.
VerdictPolicy Engine output: BLOCK / WARN / ALLOW / AUDIT.
ProfilePolicy preset: strict / balanced / legacy.
FingerprintStable per-finding hash that survives line-number drift from refactors. Used for cross-scan deduplication.
Air-gappedOperating mode where the Korthex installation has zero network connectivity. Enterprise feature.
KRX_PLATFORM_*Korthex's internal platform-detection macros: KRX_PLATFORM_WINDOWS / KRX_PLATFORM_LINUX / KRX_PLATFORM_MACOS.

File Formats

See File Format Reference for the full catalog. Quick orientation:

ExtensionQuick read
.krxThe headline report. Encrypted scan output. Also stores migration plans.
.kxiCryptographic inventory snapshot (CBOM source).
.kxgDataflow graph (with sub-variants .kxg.code / .kxg.binary / .kxg.runtime / .kxg.config / .kxg.tls / .kxg.git).
.kxnnNeural-network model archive.
.kxaExploit-engine attack-pattern database.
.kxsimMigration-simulation persistence.
.kxfhScan-history finding-ID sets.
.kxcb / .kxcsic / .kxcfh / .kxcf / .kxgdcThe scan cache family under <project>/.korthex_cache/: context bundle, semantic-IR cache, file-hash snapshot, per-file findings cache, and the git commit delta store.
.kxwWorkspace bundle (portable, passphrase-encrypted).
.krxrRuntime-agent encrypted report.
.cjsnFlowence JSON++ compressed columnar JSON (baseline tables, CVE caches).
.kxp / .korthex_policy.jsonOrganizational policy file. .kxp is the encrypted canonical form; the .json variant is its human-editable equivalent.
.korthexignoreUser-editable path-ignore list (gitignore syntax).