Appendix E. Glossary

Definitions of OpenSSL terms follow the project's own glossary where one exists; those entries are marked (OpenSSL). Protocol terms follow RFC 8446.

AEAD
Authenticated Encryption with Associated Data. The only form of record protection in TLS 1.3. Provides confidentiality for the plaintext and integrity for both the plaintext and additional data that is transmitted in the clear.
Capability
A named set of declarations a provider makes to the core, answered by invoking a callback once per item with an OSSL_PARAM array. TLS-GROUP and TLS-SIGALG are the two the TLS layer consumes (§4.3).
Cipher suite
In TLS 1.3, a code point naming an AEAD algorithm and a handshake hash. Unlike TLS 1.2 suites, it does not encode key exchange or authentication.
Code point
A numeric identifier carried on the wire, drawn from an IANA registry. Groups, signature algorithms and cipher suites each have their own registry.
Dispatch table
An array of OSSL_DISPATCH entries pairing function identifiers with function pointers, terminated by a zero entry. The provider architecture's ABI (§3.2).
ENGINE
The pre-3.0 extension mechanism: a container for method structures indexed by NID. Deprecated in OpenSSL 3.0 and replaced by providers (claim 10, Appendix D).
Explicit fetching
(OpenSSL) Obtaining an algorithm object by an explicit call such as EVP_MD_fetch(). The returned object is owned by the caller.
Fetching
(OpenSSL) Resolving an algorithm name and property query to an implementation supplied by some activated provider.
Handshake hash
The hash function named by the cipher suite, used for the transcript hash and, through HMAC and HKDF, for the entire key schedule. Its output length parameterises the width of every secret (Chapter 15).
HKDF
HMAC-based key derivation function, structured as Extract and Expand. The basis of the TLS 1.3 key schedule.
Implicit fetching
(OpenSSL) Use of an algorithm object with no associated implementation, such as the return value of EVP_sha256(), with an implementation resolved automatically on first use using default criteria.
Invalid-curve attack
An attack in which a peer supplies a point that is not on the intended curve, causing operations with the victim's private key in a weaker group and leaking key material over successive handshakes. Prevented by the validation of §10.4.
Key schedule
The sequence of HKDF operations deriving every secret in a TLS 1.3 connection from the shared secret and the transcript.
Key share
The extension carrying a public key-exchange value, encoded as an opaque octet string whose interpretation is defined per group.
Library context
(OpenSSL) OSSL_LIB_CTX: a scope within which configuration applies and providers are activated. Represented by NULL for the default context.
OSSL_ALGORITHM
The structure by which a provider advertises one implementation: a colon-separated name list, a property definition, a dispatch table and a description (§3.3).
OSSL_PARAM
The key/typed-value structure by which data crosses the core/provider boundary (§3.4).
Property / property query
(OpenSSL) A key/value pair classifying an implementation, and a string of such assertions used to select among implementations. Required and preferred forms differ by one character and by a great deal of meaning (§14.1).
Provider
(OpenSSL) A component grouping together algorithm implementations, from OpenSSL itself or from a third party.
Small-subgroup attack
An attack supplying a point of small order, so that the resulting shared secret takes few possible values and reveals the private key modulo the subgroup order.
Transcript hash
A hash over all handshake messages so far, consumed at several points without being finalised — hence the requirement for context duplication (§9.2).

E.1 Abbreviations

AbbreviationExpansion
AADAdditional Authenticated Data
ABIApplication Binary Interface
AEADAuthenticated Encryption with Associated Data
CMVPCryptographic Module Validation Program
ECDHElliptic-Curve Diffie–Hellman
GCMGalois/Counter Mode
HKDFHMAC-based Key Derivation Function
HMACKeyed-Hash Message Authentication Code
IANAInternet Assigned Numbers Authority
KEMKey Encapsulation Mechanism
ML-DSAModule-Lattice-based Digital Signature Algorithm
NIDNumeric Identifier (OpenSSL's internal algorithm numbering)
OIDObject Identifier
TEETrusted Execution Environment
TLSTransport Layer Security