[Clips] Re: Commercial Key Escrow?

--- begin forwarded text Delivered-To: clips@philodox.com Date: Sat, 21 Jan 2006 09:12:05 -0500 To: "Philodox Clips List" <clips@philodox.com> From: "R. A. Hettinga" <rah@shipwright.com> Subject: [Clips] Re: Commercial Key Escrow? Reply-To: rah@philodox.com Sender: clips-bounces@philodox.com --- begin forwarded text Cc: "Philodox Clips List" <clips@philodox.com> From: Nicko van Someren <nicko@ncipher.com> Subject: Re: Commercial Key Escrow? Date: Sat, 21 Jan 2006 11:03:20 +0000 To: "R. A. Hettinga" <rah@shipwright.com> On 20 Jan 2006, at 22:58, R. A. Hettinga wrote:
No matter what sort of architecture one chooses for long term key protection it is inevitably going to fail once some threshold fraction of the system fails. With a simply multiple copies system you have to have 100% failure, but such a system has poorer security properties. K-of-N threshold schemes fail once you've lost N-(K+1) shares but generally have much better security. It is my understanding that Verisign have multiple HSMs for the root and they simply go out of their way to keep them very safe. At nCipher our critical keys (such as firmware signing keys) are distributed using a threshold scheme and we have procedures in place to periodically check the integrity of each share (though never checking more than one at a time). As far as I know there are no active commercial key escrow services around. One problem is that the half-life of Internet companies is short compared to the time people seem to want to keep their keys so it would be hard to trust such a company unless it was very carefully set up. Cheers, Nicko --- end forwarded text -- ----------------- R. A. Hettinga <mailto: rah@ibuc.com> The Internet Bearer Underwriting Corporation <http://www.ibuc.com/> 44 Farquhar Street, Boston, MA 02131 USA "... however it may deserve respect for its usefulness and antiquity, [predicting the end of the world] has not been found agreeable to experience." -- Edward Gibbon, 'Decline and Fall of the Roman Empire' _______________________________________________ Clips mailing list Clips@philodox.com http://www.philodox.com/mailman/listinfo/clips --- end forwarded text -- ----------------- R. A. Hettinga <mailto: rah@ibuc.com> The Internet Bearer Underwriting Corporation <http://www.ibuc.com/> 44 Farquhar Street, Boston, MA 02131 USA "... however it may deserve respect for its usefulness and antiquity, [predicting the end of the world] has not been found agreeable to experience." -- Edward Gibbon, 'Decline and Fall of the Roman Empire'
participants (1)
-
R. A. Hettinga