Zeroization

Erasing cryptographic keys and other sensitive security parameters, commonly by overwriting them with zeros, to make them unrecoverable from a device or from memory.

Zeroization (zeroisation in UK spelling) is the erasure of sensitive values, above all cryptographic keys and other security parameters, by overwriting them, commonly with zeros, to make them unrecoverable. The term is most closely tied to cryptographic modules. FIPS 140-3, which adopts ISO/IEC 19790, expects a validated module to be able to zeroise its unprotected sensitive security parameters, and at higher security levels, tamper detection can trigger it automatically.

Zeroisation is narrower than media sanitisation. It targets specific values in memory or in a device, while sanitisation under NIST SP 800-88 addresses whole storage media. The two meet in cryptographic erase, where zeroising the key that protects a drive leaves the data encrypted under it unreadable; SP 800-88 Rev. 2 recommends ISO/IEC 19790 zeroisation as the way to sanitise that key. Zero-filling a whole disk is sometimes also called zeroisation, but it is overwriting, which NIST SP 800-88 treats as clearing. In software, compilers can optimise away a final write to memory that is never read again, so security libraries provide wipe functions. Prompt zeroisation also limits a cold boot attack, which recovers keys left in memory.

Exam relevance: a scenario is likely to describe a cryptographic device that is tampered with, or keys that must be destroyed at end of life. Candidates are expected to connect zeroisation with key destruction and cryptographic modules, and to tell it apart from sanitising an entire medium.