Key that has not been encrypted in a system approved by NSA for key encryption or encrypted key in the presence of its associated key encryption key (KEK) or transfer key encryption key (TrKEK). Encrypted key in the same fill device as its associated KEK or TrKEK is considered unencrypted. (RED key is also known as unencrypted key). Such key is classified at the level of the data it is designed to protect. See BLACK data and encrypted key. Source: CNSSI No. 4005 (COMSEC)
What is red key?
The term Red Key refers to cryptographic keying material that is unencrypted or in plaintext-equivalent form and therefore requires strict protection against disclosure or unauthorized access. It gives election, security, legal, or technical readers a specific label for the concept rather than a broader everyday meaning.
How is red key used in cryptography or COMSEC?
In practice, Red Key is applied to the technical or security purpose captured by its definition: cryptographic keying material that is unencrypted or in plaintext-equivalent form and therefore requires strict protection against disclosure or unauthorized access. Organizations combine that function with documented procedures, authorized access, testing, monitoring, and controls appropriate to the system.
Why does red key need security controls?
Understanding Red Key matters because the concept can affect security, reliability, auditability, or trusted operation. In this glossary context, it refers to cryptographic keying material that is unencrypted or in plaintext-equivalent form and therefore requires strict protection against disclosure or unauthorized access.
Understand more election terms clearly
Get one important election term explained each week, with authoritative sources, practical context and related definitions.
Key that has not been encrypted in a system approved by NSA for key encryption or encrypted key in the presence of its associated key encryption key (KEK) or transfer key encryption key (TrKEK). Encrypted key in the same fill device as its associated KEK or TrKEK is considered unencrypted. (RED key is also known as unencrypted key). Such key is classified at the level of the data it is designed to protect. See BLACK data and encrypted key. Source: CNSSI No. 4005 (COMSEC)
Cite this term
Election Security Glossary. (2026). Red Key. In Election Security Glossary. Retrieved August 21, 2026, from https://electionsecurityglossary.com/glossary/red-key
Sources
01
Single-source
Get the weekly election term
Receive one cited, source-backed election explanation in your inbox each week.