Managing Encryption Keys - Best Practices for Any Organization

Table of Contents

Data encryption is a significant component of an organization’s response to emerging security threats and regulatory compliance mandates. Most organizations have already implemented controls by securely encrypting data but find managing the associated encryption keys throughout their lifecycle a challenging task. To take it one step further: It is impossible to manage individual keys at the enterprise scale, especially for regulated environments.
 

The Central Role of Encryption Key Management


Why can lack of key control turn into lack of data security?

Encrypting data –ideally by utilizing a Hardware Security Module (HSM)– is essential but does not fully protect your data from threats. If the encryption keys are not secured , your encrypted data aren’t either. 
Improper key management practices can create a new set of security vulnerabilities and risks. 


Some of the most common threat scenarios are: 

  • Lack of separation – If you store the encryption keys together with your data, encryption is useless and extremely vulnerable. It’s like putting the key to the front door under the welcome mat!
  • Lack of data access control – Either making important data inaccessible to authorized users who need it or even worse – making them accessible to unauthorized entities.
  • Losing data access through key loss – In case you lose an encryption key, you effectively lose access to your data.
  • Audit Failure – If you fail to control access to all your keys, you will fail your next audit.
  • Non-compliance – Especially when handling sensitive or restricted data, a lack of fulfillment of legal and regulatory obligations for handling your keys may lead to failing to achieve the required compliance levels. 


The Key Owner can become the risk

Attempting to increase the security of their key inventory, a lot of organizations have dedicated roles implemented, key custodians are responsible for key custody. 


Imagine a situation within your organization where the keys to important data are being managed by one single individual. As soon as this person is unavailable –maybe by being out sick, being on vacation, unexpectedly left the company or has an accident– you don’t’ have control over your data anymore.


A far worse situation with a single key owner is that one entity controls your keys, your data and your business – this could lead to key compromise! 


Centralized Key Management – Taking a deep dive

The solution is to use centralized KMS. This prevents leaving keys to the discretion of one individual while enabling central compliance and audit control. 


Key Management Systems as the game changer

A complete and unified strategy to protect sensitive data consisting of an HSM as root of trust for reliable data encryption alongside a centralized key management system (KMS) enables complete protection of your data wherever it is stored and utilized. 
A suitable KMS requires the following minimum capabilities:

  • Secure key generation
  • Secure key storage
  • Reliable key access
  • Centralized key management
  • Audit logs


By ticking all these boxes, a KMS helps to completely protect your data and provides peace of mind by meeting stringent legal and compliance standards. It also scales with constantly increasing requirements. 


Clustering technology enables highly available, centralized encryption and decryption for clients throughout the enterprise network for millions of key objects. All key management components and protocols of an entire organization can be easily deployed to these clients and integrated with the local encryption applications. 


Once integrated, encryption and decryption of the data is performed locally, minimizing the risk of a network or single point of failure avoiding a large impact on the overall data security posture. 


Key Management Best Practices 

There are specific requirements a KMS must cover to work as the enabler for complete security of digital infrastructures. 
These are the six main “ability factors” to consider when implementing a centralized KMS:


“Compliantability” 

Referring to the level of compliance to the most important standards defining the security for hardware and software encryption systems, such as FIPS, CC, PCI, or AES standards based on NIST’s recommendations.


“Availability”

This focuses on the uptime of the system, especially considering many KMS platforms are deployed to geographically dispersed data centers. Organizations tend to be more distributed than ever, with multiple data centers and even more applications and services that span them. Independent if set up in centralized and distributed clusters, KMS installations need to be able to provide high availability.


“Scalability”

With the trend to more compartmentalized and distributed digital infrastructures, the demand to issue and manage keys at wider scale without compromising security grows. 


To name a concrete example: Distributing data encryption keys to temporary data containers. In this case, a centralized KMS must scale as more and more containers are deployed to support the ever-growing needs of the enterprise.  It is desirable to sustain thousands of clients and millions of keys for a truly enterprise-class solution.


“Interoperability”

A well-designed central KMS typically requires support for vendor specific protocols for key exchange but is also expected to prevent vendor lock-in through support of industry standard protocols, e.g. OASIS KMIP and PKCS #11.


“Manageability”

To ensure complete manageability of your enterprise key inventory, user/system management practices play a crucial role. The most important ones are utilization of multiple credentials, Role Based Access Control (RBAC) and least privilege. Key rotation is another important aspect of KMS’s manageability to be compliant with regulatory bodies and to overcome disaster scenarios. Rotating keys should not require decrypting a set of encrypted data and then re-encrypting it when the keys expired or are changed. 


“Performanceability”

Another demand of today’s encryption ecosystems is to minimize operational or performance impacts. Up-to-date technologies are implementing encryption at the hardware layer being transparent to the applications and even to the underlying operating system making it platform agnostic. They also support in-place encryption ensuring strict separation of data from the key material, even in cloud environments. A KMS must scale to seamlessly support the rapid encryption & decryption requirements for AI workload volumes coming in the future!


“Cloudability” 

As every enterprise becomes an extension to a public, private or national cloud – it is vital for their enterprise key management to allow data sovereignty regardless of the cloud provider! Many customers already manage workloads in multiple clouds to ensure diversity and resiliency – a KMS must support them all the same as it does back on-prem behind the firewall!


Conclusion 

Encrypted data managed by organizations is growing by a tremendous rate and so are the complexities around managing keeping the encryption keys secure within distributed environments. Leveraging from the capabilities of a centralized KMS ensures reliable security and compliance fulfillment, granting you full control over your organizational data and keeping your auditors happy.


Discover Utimaco’s centralized KMS for your organization

Utimaco provides a whole portfolio of Key Management Systems  ensuring centralized and streamlined management of all cryptographic keys. Independent of their deployment option -whether on-premises as physical or virtual appliance or as a Service- they enable centralized and streamlined management of all cryptographic keys throughout their complete lifecycle.
 

 

About the Author

Silvia Clauss

Silvia Clauss

Head of Product Marketing, Utimaco

Prêt à assurer votre avenir numérique ?

Rejoignez plus de 500 entreprises mondiales et institutions gouvernementales qui font confiance à Utimaco pour leur infrastructure de sécurité critique.

Contacter le service des ventes

How can we help you?

Talk to one of our specialists and find out how Utimaco can support you today.
You have selected two different types of downloads, so you need to submit different forms which you can select via the two tabs.

Your download request(s):

    By submitting below form you will receive links for your selected downloads.
    Loading...

    Your download request(s):

      For this type of documents, your e-mail address needs to be verified. You will receive the links for your selected downloads via e-mail after submitting below form.
      Loading...

      About Utimaco's Downloads

      Visit our Downloads section and select from resources such as brochures, data sheets, white papers and much more. You can view and save almost all of them directly (by clicking the download button).

      For some documents, your e-mail address needs to be verified. The button contains an e-mail icon.

      Download via e-mail

       

      A click on such a button opens an online form which we kindly ask you to fill and submit. You can collect several downloads of this type and receive the links via e-mail by simply submitting one form for all of them. Your current collection is empty.