Approaches to cryptographic key management
Paul G. Comba · 1986
The first titIe of my talk, as it appeared in the tentative program, was "Encryption Work at IBM." Then the second title, as it appeared in the program, was "Data Encryption."The third title appeared in the final program and was "Cryptographic Key Management."The title of the talk I will give to you today is "Approaches to Cryptographic Key Management."When you speak later in the day, you always wonder if it is an advantage or whether people are tired and bored.In my case, I'm happy it's late because so many things have been alluded to and encryption was mentioned in several talks.So I don't have to explain what the DES is and what the NSA is up to.As someone mentioned, the NSA is trying to convince various users to use algorithms that are not fully known or evaluable by users, and there is some controversy on that point.I will not discuss this issue further.Instead, the environment I am addressing myself to is one where many modern crypto-techniques operate, where the algorithm is known but the key is kept secret.I'm going to deal with three approaches to key management.Personal Key Management, where the person decides what the key is.Centralized Key Management, where the ten tral organization decides and distributes the keys.And finally, what is most interesting in the field today, a system which incorporates private keys and __-______-__