Unit content
Secret-key lifecycle and key rotation
Cryptographic security depends on how secret keys are generated, stored, used and retired, not only on the algorithm that consumes them.
A key lifecycle includes
- generation from appropriate cryptographic randomness;
- storage where unauthorized parties cannot read or replace the key;
- use only for the intended purpose and scope;
- rotation when policy, exposure or cryptographic lifetime requires replacement;
- revocation or retirement so old credentials stop authorizing new actions;
- destruction when retained copies are no longer required.
Reusing one key for unrelated purposes can couple systems that should fail independently. Separate keys or derived subkeys reduce this cross-protocol risk.
Rotation limits future exposure but does not automatically undo past compromise. If an attacker already copied encrypted data and the same long-term key can decrypt it later, simply replacing the key today does not protect that historical ciphertext.
Key management is therefore part of the security protocol, not an operational detail added after cryptography is chosen.