paint-brush
Glossary of Security Terms: Cipher Suiteby@mozilla
140 reads

Glossary of Security Terms: Cipher Suite

by Mozilla ContributorsAugust 17th, 2020
Read on Terminal Reader
Read this story w/o Javascript
tldt arrow

Too Long; Didn't Read

A cipher suite is a combination of a key exchange algorithm, authentication method, bulk encryption cipher, and message authentication code. In a cryptosystem like TLS, the client and server must agree on a cipher suite before they can begin communicating securely. A typical cipher suite looks like ECDHE_RSA_WITH_AES_128_GCM_SHA256 or ECDhe-RSA-AES128-GCM-SHA256, indicating:ECDHE (elliptic curve Diffie-Hellman ephemeral) for key exchange, RSA for authentication, AES-128 as the cipher, with Galois/Counter Mode (GCM) as the block cipher mode of operation.

Companies Mentioned

Mention Thumbnail
Mention Thumbnail
featured image - Glossary of Security Terms: Cipher Suite
Mozilla Contributors HackerNoon profile picture

A cipher suite is a combination of a key exchange algorithm, authentication method, bulk encryption cipher, and message authentication code.

In a cryptosystem like TLS, the client and server must agree on a cipher suite before they can begin communicating securely.  A typical cipher suite looks like ECDHE_RSA_WITH_AES_128_GCM_SHA256 or ECDHE-RSA-AES128-GCM-SHA256, indicating:

  • ECDHE (elliptic curve Diffie-Hellman ephemeral) for key exchange
  • RSA for authentication
  • AES-128 as the cipher, with Galois/Counter Mode (GCM) as the block cipher mode of operation
  • SHA-256 as the hash-based message authentication code (HMAC)

Learn more

View Previous Terms: