Technology Sectors

Market Sectors

Key management strategies in the Cloud

Jon Geater

There is a lot of discussion at the moment about key management in distributed on-demand computing environments (aka ‘the Cloud’), but much of this seems too deeply product- or technology-focused for my liking.

By taking the “solution-first” approach, I believe we’re addressing the problem in the wrong way. What I would like to see is a return to our roots; looking at why key management has become important and re-validating the use of cryptography to solve Cloud security issues -- both in government and the enterprise. We must re-examine the way we employ these tools in this new context and make sure that the technology is solving the problems, not defining them.

In any area of life people tend to focus on their area of expertise. To a man with a hammer, every problem is a nail. Those in cryptography and key management are no different. When Cloud computing became big news, everyone looked at their tool bag and applied existing policies, processes and products to the new environment.

Take a step back

Why do people need key management? Why has the field grown so much over the past few years? And why have best practices and standards of due care developed the way they have?

This much is obvious: More people are using more cryptographic keys than ever before, and cryptography is meaningless without strong key management. And why the rise in cryptography? Because in today’s information society, there is ever-more information in need of ever-more protection.

We don’t practice key management for its own sake. We do it to make cryptography useful. And we don’t use cryptography for its own sake either. We use it to support our businesses, to protect the information that is the lifeblood of the modern economy.

Each key, each use of cryptography means something. It’s a proxy to some promise made to underpin our electronic business and personal transactions. A signature means, “Alice really made this.” Encryption means, “only Bob can read this.”

Key management and solving the problem

And this is the way we need to think about key management in the Cloud. It’s all about information-centric protection, not the technology. We should be asking, “How do I use cryptography and key management to uphold my promises?”

By approaching the problem in this way, we can focus the discussion on the familiar concept of trust and start formulating a primary approach to Cloud key management and security, without worrying specifically about the technologies we will be using.

Potential approaches include:

 

Upcoming Events

Event Details Dates of Event
Mission Command Jun 10 - 12
Cyber Securty Brainstorm Jun 11 - 11
EDGE Summit 2013 Jun 11 - 11
IPv6 Summit 2013 Jun 14 - 16
SANSFIRE 2013 Jun 15 - 22
Oak Ridge National Laboratory's 2nd Biosurveillance Symposium Jun 17
Biodetection Technologies 2013 Jun 18 - 19
Southwest Microwave Seminar Jun 18 - 18
Cyber Defense and Network Security Summit Jun 24 - 26
Vanguard Security & Compliance 2013 Jun 24 - 27
SANS Canberra 2013 Jul 1 - 13
Border Management & Technologies Summit Jul 2 - 5
SANS Rocky Mountain 2013 Jul 15 - 20
SANS Mumbai 2013 Jul 22 - 27
Cyber Security Brainstorm Jul 24 - 24
SANS San Francisco 2013 Jul 29 - Aug 3
SANS Boston 2013 Aug 5 - 10
Cyber Security for Government Aug 12 - 14
SANS Thailand 2013 Aug 19 - 31
SANS Virginia Beach 2013 Aug 19 - 30
Maritime Security 2013 West Aug 19 - 21
930gov: Strategic Buying at Year-End Showcase Aug 21 - 21
SANS Melbourne 2013 Sep 2 - 7
SANS Capital City 2013 Sep 3 - 8
US/Canada Border Conference Sep 12 - 13
Network Security 2013 Sep 14 - 23
Cyber Intelligence Europe Sep 17 - 19
EnergySec 9th Annual Security Summit Sep 17 - 19
iFSO International Facility Security Officer Conference Sep 17 - 19
International Facility Security Officer Conference Sep 17 - 19
DefendUSA Sep 19 - 20
ASIS Foundation Golf Tournament Sep 23 - 23
NCT: CBRNe Asia, 24-27 September 2013, Kuala Lumpur Sep 24 - 27
ASIS Foundation Night at ASIS 2013 Sep 26 - 26
SANS Bangalore 2013 Oct 14 - 26
SOS SANS October Singapore 2013 Oct 21 - Nov 2