openskills.info
Course Preview

Cryptographic Key Management

Cryptographic key management controls encryption, signing, and authentication keys from generation through use, rotation, recovery, and destruction. It keeps key material separate from protected data while governing who and what may use each key.

itIdentity, access, and cryptography

Don't Panic - Cryptographic Key Management

Cryptographic key management is the system of policies, roles, components, and records that controls cryptographic keys and their metadata from generation to destruction. The algorithm transforms data; the key decides who can reverse, authenticate, or authorize that transformation. A strong cipher cannot fix an exposed or missing key. Key management therefore treats a key as a governed security object rather than a value placed beside ciphertext.

A cryptographic key management system, or CKMS, combines policy, procedures, software, hardware, and operators. Its control plane creates key identities, attaches policy, changes lifecycle state, records use, and handles recovery. Its data plane performs or authorizes cryptographic operations.

A common arrangement uses envelope encryption. A data-encryption key (DEK) encrypts application data. A key-encryption key (KEK) wraps the DEK. A key management service or HSM protects the KEK and enforces operations against it. Stored records usually keep ciphertext, the wrapped DEK, algorithm identifiers, and the CKMS key identity, plus any authenticated metadata the format requires. The application can encrypt large data locally while the CKMS handles a much smaller wrapped key.

Keys need identity, owner, allowed operations, rotation, destruction, and evidence. Availability is part of security: keys you cannot recover after an incident become an outage that invites unsafe workarounds. Centralizing keys improves policy and audit and also concentrates blast radius across every workload that depends on the same KEK.

Read the Intro for the control-plane model and envelope pattern. Use the Cheatsheet when you need lifecycle and role maps. Landscape and Timeline place CKMS designs among related crypto tooling; Updates tracks the NIST SP 800-57 publication line this course centers on.

Where this skill leads

Relevant careers

See how this topic contributes to broader role-level skill maps.

Sources