Advertisement
Promo

Security management Toolkit

Oasis group aims to simplify crypto-key management

Tom Espiner ZDNet.co.uk

Published: 07 May 2009 15:21 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Open-standards consortium Oasis has formed a group to devise a standard aimed at allowing encryption products to work easily with business applications and with each other.

Group members include IBM, Cisco, EMC, HP, PGP Corporation, Symantec and the US National Institute of Standards and Technology (NIST).

The Oasis group, called the Key Management Interoperability Protocol (KMIP) Technical Committee, will aim to define a single protocol for communication between encryption systems and enterprise applications, to cover such things as email, databases and storage devices. The companies participating in the new group submitted a key-management interoperability standard to Oasis in February.

Key-management interoperability is "vital" for businesses to be able to successfully implement encryption and protect data, according to Jamie Cowper, PGP's EMEA marketing manager.

"With the best will in the world, businesses are never going to be using a single encryption product, or a single company to provide that," Cowper told ZDNet UK on Thursday. "It's great to see key members of the security and encryption community working together and recognising the business need for key-management interoperability."

Key management is a problem for businesses, according to Cowper. As more documents are encrypted throughout an enterprise or shared with third parties, keys proliferate. Managing the administration of those keys until they are revoked is a problem that is exacerbated as companies grow, said Cowper.

"Encryption is really just a standard," said Cowper. "To strongly protect and decrypt in an automated way is the clever bit."

The Oasis KMIP group aims to provide a protocol that will enable interoperability of products throughout a key's lifecycle, which includes the generation, submission, retrieval and deletion of cryptographic keys. KMIP will support symmetric and asymmetric keys, digital certificates and other shared secrets.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
1 out of 1 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:











Video icon

Video

Sentry Posts Blog

Climate research centre compromised

One of the UK's leading climate change research centres has had a security breach. The Climate Research Unit at the University of East Anglia (UEA) suffered a compromise of information,... More

1 comment

Government web-monitoring plans on hol...

Government plans to compel ISPs to process and store details of all web communications have been put on hold until after the next election. The Home Office told ZDNet UK on Wednesday... More

1 comment

Watchdog reveals illegal sale of phone...

The Information Commissioner's Office is preparing a prosecution file against a mobile operator's employees who allegedly sold on thousands of customers' details to a competitor. The... More

1 comment

Featured Talkback

In association with Network Liberation Movement
It seems to me this is a burden being placed on the wrong shoulders. There is not an It system in the world that can stop an individual taking information in their heads and spewing out at the nearest undesirable third party.

By: RonaldWilkins

Read full story:
Deloitte: People are still weakest security link


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters