IT lexicon Security Kerckhoffs's principle

Kerckhoffs's principle

Security På svenska → Updated: 2026-08-03

A cryptosystem must stay secure even when everything except the key is known to the enemy.

Stated by the Dutch linguist Auguste Kerckhoffs in two articles in Journal des sciences militaires in 1883. Of his six rules for military cryptography it is the second that survived: the system must not require secrecy, and it must be able to fall into enemy hands without causing trouble.

Claude Shannon later restated it as "the enemy knows the system". The principle is why serious ciphers are published and reviewed in the open rather than kept secret. Secret design has historically turned out to be weak design — and unlike a key, an algorithm cannot be swapped out once it has leaked.

← Back to the lexicon