Cryptographic Solutions Flashcards

(20 cards)

1
Q

What is Salting? (加盐是什么?)

A

• Add random data (“salt”) to the password before hashing.
• Even if two people have the same password, their hashes will be completely different.
• 🧂密码撒上一把独特的盐,让黑客的对照表失效!

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Why is Salting important? (加盐为什么重要?)

A

• Prevents Rainbow Table attacks! 🌈
• Makes each password hash unique and unpredictable.
• 加盐 = 密码穿上隐身斗篷,防止一眼被破解!🧙‍♂️

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is Key Stretching? (密钥拉伸是什么?)

A

• Make a simple password much harder to crack by repeatedly hashing it many times.
• 重复加工,让黑客的破解电脑跑到冒烟🔥!

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Why is Key Stretching important? (密钥拉伸为什么重要?)

A

• Slows down brute-force attacks. 🛡️
• Strengthens weak passwords by making guessing extremely slow.
• 小锁变金库!🔒➔🏦💪

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a Nonce? (Nonce是什么?)

A

• A “Number used once” – a random number that is used one time during authentication.
• 每次登录或通信,都生成一个一次性随机暗号,防止被重放!

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Why are Nonces important? (Nonce为什么重要?)

A

• Prevent replay attacks. 🔁
• Ensure every session is unique, safe, and fresh.
• Nonces = 每次出新暗号,神出鬼没!🕵️‍♂️🎭

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is Steganography? (隐写术是什么?)

A

Hiding secret information inside ordinary files like images, audio, or video.

在普通文件中偷偷藏信息,别人看不到也不会怀疑。🌊🎨

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Why is Steganography used? (隐写术有什么用?)

A

To hide communication so even the existence of the message is secret.

不让人知道你在传秘密,隐秘程度比加密还高!🕵️‍♂️📜

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is Tokenization? (代币化是什么?)

A

Replacing sensitive data with meaningless tokens.

把敏感数据换成无价值的代号,保护数据安全。🪙🏦

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Why is Tokenization important? (代币化为什么重要?)

A

Tokens have no value if stolen.

就算Token被偷了,黑客也拿不到真数据!🔐🛡️

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is Data Masking? (数据掩码是什么?)

A

Hiding or changing parts of sensitive data to protect it.

把重要数据打码或者伪装,防止泄露。🎭🔏

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Why is Data Masking important? (数据掩码为什么重要?)

A

Protects sensitive information in non-production environments like testing or training.

在测试、培训等场景保护真实数据,避免泄露风险!📚🛡️

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is PKI? (PKI是什么?)

A

Public Key Infrastructure, a system that issues and manages digital certificates.

公钥基础设施,一套负责发放、验证数字证书的体系。🪪🔒

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What does the Certificate Authority (CA) do? (CA做什么?)

A

Issues, signs, and manages digital certificates.

颁发、签署和管理数字证书,是信任链的源头。🏭

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What does the Registration Authority (RA) do? (RA做什么?)

A

Collects user identity information and sends certificate requests to CA.

收集用户信息,帮用户提交申请到CA。👮

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is a Digital Certificate? (数字证书是什么?)

A

A digital ID that proves your identity online using public key cryptography.

你的网络身份证,证明你的身份,保障通信安全。🪪

17
Q

What is a Certificate Signing Request (CSR)? (CSR是什么?)

A

An application including your public key, submitted to CA for a certificate.

包含你的公钥的申请表,用来申请数字证书。📄

18
Q

What is a Certificate Revocation List (CRL)? (CRL是什么?)

A

A list of revoked certificates no longer trusted.

被吊销证书的黑名单。📜

19
Q

What is OCSP? (OCSP是什么?)

A

Online Certificate Status Protocol, checks in real-time if a certificate is valid.

实时在线验证证书状态的协议。🔍

20
Q

What is the “Root of Trust”? (信任根是什么?)

A

The ultimate trusted CA that anchors the entire PKI system.

PKI体系最核心、最可信任的顶级证书机构。👑