Key management

Decentralized encryption, but with key integration

Challenges

Each encrypted data element can only be used with one Encryption code must be decrypted. Managing key access and storage is therefore important, but can also be challenging.

Lost keys can mean valuable data loss. Thousands of items can be protected by different algorithms and keys. Stolen keys can lead to data breaches and misuse.

Solutions

Data masking and encryption product IRI FieldShield in the IRI Data Protection Suite and the IRI Voracity platform, which includes FieldShield, offers several ways to manage encryption keys. One method is to specify the keys directly within each field encryption or decryption specification. This aligns with Gary Palgon's advice:

Centralize key management with distributed execution. A solution that employs a hub-and-spoke architecture for distributed key management allows encryption and decryption nodes to exist anywhere within the enterprise network. Spoke key management components can be easily deployed onto these nodes and integrated with local encryption applications. Once the spoke components are active, all encryption and decryption of previously plaintext data is performed locally, minimizing the risk of network or single-component failure having a significant impact on overall data security.“ – Enterprise System Journal –

Other options include: specifying it in a hidden and/or secure key file, via an environment variable, or by using a public/private key pair system.

You can also work with IRI to integrate your key provisioning or storage appliance into these methods.

You can also work with IRI to integrate your key provisioning or storage appliance into these methods. The following example shows the use of FieldShield with encryption codes that are stored in the Azure Key Vault are stored. You can also find these keys in Alliance Key Manager managed by Townsend Security to utilize the HSM and other advanced features.