Security glossary

Clear language for the bridge between hardware and identity.

Definitions for the phrases and acronyms used throughout Xibernetix documentation and product pages.

Core concepts

Hardware, identity, and authorization.

Bluetooth

A short-range wireless protocol used to exchange context between compatible devices. In Xibernetix workflows, Bluetooth can help connect a physical event with a mobile device.

Key diversification

The practice of deriving a distinct key for an individual tag or device from protected base material and identity-specific inputs.

Legacy bridge

Hardware or software that connects an existing legacy interface to a modern authentication and synchronization workflow.

Passkey

A phishing-resistant credential based on public-key cryptography, typically unlocked through a device’s biometric or local security mechanism.

UID

Unique identifier. For an NFC tag, the UID is the hardware identity read from the tag and used as an input to tag-specific operations.

NFC

Near Field Communication. A short-range wireless technology that enables compatible devices and tags to exchange data when brought close together.

NTAG X DNA Connected NFC Tag

A connected NFC tag platform designed for secure identity, authentication, and protected data exchange. In Xibernetix workflows, its tag identity can participate in diversified-key and lifecycle operations.

NFC Forum Tag Types

A classification of interoperable NFC tag technologies. Type 1 and Type 2 use ISO/IEC 14443-style communication, Type 3 is based on JIS X 6319-4 (FeliCa), Type 4 uses ISO/IEC 14443 with ISO/IEC 7816-4 commands, and Type 5 is based on ISO/IEC 15693. The supported type determines memory, commands, and communication behavior.

Digital Product Passport (DPP)

A structured digital record associated with a physical product that can provide information such as identity, materials, provenance, maintenance, compliance, and end-of-life details. An NFC tag can provide a convenient, controlled way to access a product’s passport.

Cryptography

Terms you may see in implementation guides.

AES

Advanced Encryption Standard, a symmetric encryption standard used to protect data with the same secret key for encryption and decryption.

CMAC

A Message Authentication Code based on a block cipher such as AES. It helps verify that data came from a holder of the corresponding secret.

Lifecycle state

The current operational condition of a device or tag, such as active or disabled, used to control what actions are permitted.

Challenge-response

An authentication exchange in which one party proves knowledge of a secret by responding correctly to a fresh challenge.

EAL 6+

An Evaluation Assurance Level under the Common Criteria framework, with additional security requirements beyond the standard EAL 6 level. It indicates a highly structured, rigorously analyzed, and systematically tested evaluation process for a defined product and security target; it is not a general certification for an entire company.

PKI-based asymmetric cryptography and authentication

A security model that uses related public and private keys. A private key proves control of an identity by creating a signature, while the corresponding public key verifies it. Public Key Infrastructure (PKI) uses certificates and trusted certificate authorities to bind public keys to identities and support authenticated, encrypted communication.

Workspaces

Roles have different responsibilities.

Admin

The administrative workspace for platform governance, configuration, and oversight.

Maker

The workspace for building, registering, and managing devices and supported hardware workflows.

Operator

The workspace for people carrying out assigned device, tag, and operational actions.