Docs / FUNDAMENTALS
FUNDAMENTALS
Glossary
Written and maintained by Hendrik Schneider · Last reviewed · How we check this
Common terms used throughout the documentation. Cross-referenced from every section so you can jump back here whenever you hit a piece of jargon.
Cryptography Terms
| Term | Definition |
|---|---|
| AEAD | Authenticated Encryption with Associated Data. A scheme that encrypts and authenticates in one operation (AES-GCM, ChaCha20-Poly1305, AES-CCM). |
| AES | Advanced Encryption Standard. The dominant symmetric block cipher. Recommended at 256-bit keys; 128-bit acceptable. |
| Block cipher mode | How a block cipher is applied to larger data. ECB (bad - patterns leak), CBC (needs MAC), CTR (needs unique nonce), GCM (AEAD, recommended). |
| ChaCha20-Poly1305 | Modern AEAD stream cipher. Equivalent security to AES-GCM, faster in software, recommended. |
| HKDF | HMAC-based Key Derivation Function. Standard way to derive multiple keys from one master secret. |
| HMAC | Keyed message-authentication code. Used for integrity. HMAC-SHA-256 is the typical choice. |
| IV / Nonce | Initialization Vector / Number-used-once. Random value paired with a key to make the same plaintext encrypt to different ciphertexts. Reuse breaks security. |
| KDF | Key Derivation Function. Turns a secret (password, master key) into one or more usable cryptographic keys. |
| KEM | Key Encapsulation Mechanism. The PQC-era way to do what RSA-OAEP did: encrypt a session key with a public key. |
| MAC | Message Authentication Code. Proves a message wasn't altered (HMAC, GMAC, Poly1305). |
| Padding Oracle | An attack class against CBC mode when padding errors are observable. |
| PBKDF2 / scrypt / Argon2 / bcrypt | Password-hashing functions. Designed to be slow + memory-hard. Argon2id and bcrypt(>=12) are the current recommendation. |
| PKCS#1 v1.5 / OAEP | Two RSA padding schemes. v1.5 is vulnerable to Bleichenbacher attacks; OAEP is the safe modern choice. |
| RSA | Asymmetric algorithm. Quantum-vulnerable. Min 2048 bits today; migrate to ML-KEM (encryption) or ML-DSA (signatures). |
| Salt | Random per-record value mixed into a hash to defeat rainbow-table attacks. |
| SHA-2 / SHA-3 | Cryptographic hash functions. SHA-256 / SHA-384 / SHA-512 (SHA-2) and SHA3-256 / SHA3-512 (SHA-3) are all recommended. |
| TLS | Transport Layer Security. TLS 1.2+ recommended; 1.0 and 1.1 are deprecated; SSL of any version is disallowed. |
Post-Quantum Cryptography
| Term | Definition |
|---|---|
| PQC | Post-Quantum Cryptography. Schemes designed to remain secure against attackers with large-scale quantum computers. |
| Harvest Now, Decrypt Later (HNDL) | Threat model: an attacker captures encrypted traffic today and stores it until quantum capability arrives. Drives the urgency of migrating before 2030. |
| ML-KEM (Kyber) | FIPS 203. Key encapsulation. The PQC replacement for RSA-OAEP and ECDH key exchange. |
| ML-DSA (Dilithium) | FIPS 204. Digital signatures. The PQC replacement for RSA signatures and ECDSA. |
| SLH-DSA (SPHINCS+) | FIPS 205. Stateless hash-based signatures. For long-lived signatures (firmware, root certs) where conservative assumptions matter. |
| Hybrid cryptography | Combining a classical primitive with a PQC primitive so the system is secure if either holds. Standard transition pattern. |
| Quantum-vulnerable | Schemes whose security collapses against Shor's algorithm: RSA, DH, ECDH, ECDSA. |
| Quantum-resistant / Quantum-safe | Schemes for which no known quantum advantage exists (AES-256, ChaCha20, SHA-256, ML-KEM, ML-DSA, SLH-DSA). |
| CNSA 2.0 | NSA's Commercial National Security Algorithm Suite 2.0. Specifies the PQC transition timeline for national-security systems. |
| NIST PQC | The NIST post-quantum standardization project that produced ML-KEM, ML-DSA, and SLH-DSA. |
Korthex Concepts
| Term | Definition |
|---|---|
| Baseline Registry | Korthex's central truth source for algorithm classification. Every severity, ELS score, and compliance verdict traces back to a lookup here. |
| Baseline status | Recommended / Acceptable / Deprecated / Disallowed / Not-crypto / Unknown. |
| CBOM | Cryptographic Bill of Materials. The CycloneDX-format SBOM extended with crypto-asset semantics. |
| SBOM | Software Bill of Materials. Standard formats: CycloneDX, SPDX. |
| Finding | A single instance of weak / interesting cryptography Korthex detected. |
| Cluster | A group of related findings sharing the same algorithm + usage pattern across files. |
| Taint | Tracking how a cryptographic value (key, IV, salt) flows from its source through the program. |
| Severity ladder | CRITICAL / HIGH / MEDIUM / LOW / INFO. Determined by Baseline Registry + Taint analysis. |
| ELS | Exploit Likelihood Score. 0-10 scale produced by the Exploit Engine. Combines algorithm-strength + key-length + mode + source + context. |
| Verdict | Policy Engine output: BLOCK / WARN / ALLOW / AUDIT. |
| Profile | Policy preset: strict / balanced / legacy. |
| Fingerprint | Stable per-finding hash that survives line-number drift from refactors. Used for cross-scan deduplication. |
| Air-gapped | Operating mode where the Korthex installation has zero network connectivity. Enterprise feature. |
| KRX_PLATFORM_* | Korthex's internal platform-detection macros: KRX_PLATFORM_WINDOWS / KRX_PLATFORM_LINUX / KRX_PLATFORM_MACOS. |
File Formats
See File Format Reference for the full catalog. Quick orientation:
| Extension | Quick read |
|---|---|
| .krx | The headline report. Encrypted scan output. Also stores migration plans. |
| .kxi | Cryptographic inventory snapshot (CBOM source). |
| .kxg | Dataflow graph (with sub-variants .kxg.code / .kxg.binary / .kxg.runtime / .kxg.config / .kxg.tls / .kxg.git). |
| .kxnn | Neural-network model archive. |
| .kxa | Exploit-engine attack-pattern database. |
| .kxsim | Migration-simulation persistence. |
| .kxfh | Scan-history finding-ID sets. |
| .kxcb / .kxcsic / .kxcfh / .kxcf / .kxgdc | The scan cache family under <project>/.korthex_cache/: context bundle, semantic-IR cache, file-hash snapshot, per-file findings cache, and the git commit delta store. |
| .kxw | Workspace bundle (portable, passphrase-encrypted). |
| .krxr | Runtime-agent encrypted report. |
| .cjsn | Flowence JSON++ compressed columnar JSON (baseline tables, CVE caches). |
| .kxp / .korthex_policy.json | Organizational policy file. .kxp is the encrypted canonical form; the .json variant is its human-editable equivalent. |
| .korthexignore | User-editable path-ignore list (gitignore syntax). |