[openpgp] Re: Ideas for alternative user interface terms for OpenPGP structures

Paul Schaub <[email protected]> Thu, 26 Feb 2026 18:40:04 +0100
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
Hey!

My 2 cents: I got used to refer to TPKs as either "OpenPGP Certificates" 
or "OpenPGP public keys" (I prefer OpenPGP Certificates though). For 
TSKs, I use the term "OpenPGP Key".

This follows the terminology from 
https://openpgp.dev/book/certificates.html which I also used for BCs new 
high level API and for PGPainless' 2.0 API.

Referring to a certificate as "pattern" feels wrong.

Happy Hacking
Paul

Am 26.02.26 um 11:37 schrieb Kai Engert:
> Hello,
>
> this message isn't about protocols, algorithms or packet structures. 
> It's just about user interface terms.
>
> I have been struggling with the use of the term "certificate" in the 
> context of OpenPGP. My pain points are:
> - it implies third party certification even when there is none,
>   which is often missing in OpenPGP transferable keys.
> - it overlaps with the established use of the term with S/MIME,
>   which is particularly relevant in applications that offer
>   both OpenPGP and S/MIME functionality to users.
>
> The alternative term "OpenPGP public key" also isn't perfect, because 
> the objects that users work with contain more than just the public key.
>
> Also overall, I think the terms "OpenPGP certificate" and "OpenPGP 
> public key" and "secret key" are difficult to understand for users. 
> (Especially when the word key is used for the public key, because in 
> human language, a key is used for unlocking something, so there is 
> risk of confusing secret and public keys. That's an argument for 
> avoiding the term key when talking about public keys to users.)
>
> I'd like to propose an alternative set of terms for OpenPGP objects to 
> be used in user interfaces, to make it easier for users to understand.
>
> I propose the term "Message Crypto Patterns" (or Mail Crypto Patterns) 
> (MCP) as a user understandable abstraction as a replacement for 
> "transferable public key" or "OpenPGP certificate.
>
> Based on the name, users can tell "this is the thing I need to make 
> cryptography work" and because cryptography is about transforming an 
> object, "this is the pattern that is used for the transformation".
>
> UI language could say Alice tries to find Bob's MCP. She can find 
> candidate MCPs. She could see that one of them is a certified MCP 
> (because it contains a certification signature). Alice can manually 
> verify an MCP.
>
> An MCP can contain multiple individual patterns. (That's why the 
> suggested expanded form of the acronym says patterns, not pattern.)
>
> The MCP can contain an encryption pattern (encryption subkey) and/or a 
> signature pattern (signing subkey).
>
> Alice uses the encryption pattern from Bob's MCP to encrypt a message 
> for Bob. To verify a signed message from Bob, Alice checks that the 
> signature matches Bob's signing pattern.
>
> Patterns can be old (expired/revoked), new patterns can get added. An 
> MCP can get updated to contain a new pattern.
>
> It would also work to say "Bob's MCP contains a Post-Quantum 
> encryption pattern". (The PQ pattern is a more advanced pattern to 
> transform messages in a stronger way.)
>
> The counterpart is the Message Crypto Secret (MCS), which contains the 
> private crypto material.
>
> What do you think? I'm looking forward to your feedback.
>
> Thanks,
> Kai
>
>
>
> _______________________________________________
> openpgp mailing list -- [email protected]
> To unsubscribe send an email to [email protected]

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]