Encryption key management strategy

Allen Endres, Efosa Osayamwen · 2004

Scope of study. The purpose of this study was to investigate a possible solution to encryption key management strategy, which involves generating, distributing, storing, and securing of encryption keys as well as recovery or destruction in the event of failure of the key management process. The process involves controlling encryption keys during the life of the keying material to prevent unauthorized disclosure, modification, or substitution. Encryption key management strategy was researched by exploring responses to the following questions: (1) What are the key problems associated with encryption key processes? (2) What is the range of solutions to the problems that exist with these processes? (3) What are the traits required to developing a server-based strategy to solve encryption key management problems? (4) Is there a common roadmap that organizations can use to implement a successful encryption key management strategy? Findings and conclusion. The analysis of the results indicated that there were several significant existing issues surrounding encryption management strategy, and question one in the research study identified problems associated with the encryption key processes. The first question helped to identify the problems associated with encryption key processes. The second question provided ranges of solutions to the problems associated with encryption processes. The third question sought an understanding of the most prevalent and satisfactory solutions used to develop a server-based strategy to solve encryption key management problems. Analyzing the responses to question number three also helped to identify what traits an organization would have to adopt to be able to develop encryption key management and the fourth question demonstrated percentages of organizations that had or had not yet implemented encryption key management strategy. From the research of key correlates of successful versus unsuccessful encryption key management processes, an encryption key management strategy roadmap was provided, and public key infrastructure was emphasized. This infrastructure relies on encryption policy rather than on an encryption software package. (Abstract shortened by UMI.)

Read the paper · More papers on PaperTik