Securing a secret master key is a non-trivial task, we even argue it is impossible to fully secure it, hence we must make it as difficult as possible for any powerful adversary to steal or use the key. We introduce the reader to interesting cryptography which is starting to get more attention in terms of addressing the above problem, and we briefly overview some commercial and open-source products that can be used. Finally, we propose a set of solutions on how to secure master keys, more as guidelines rather than exact technical specifications, with aim to inspire and raise awareness of how to increase the security as much as possible.
翻译:确保秘密主钥匙是一项非三重任务,我们甚至认为不可能完全保证钥匙的安全,因此我们必须尽可能使任何强势对手难以窃取或使用钥匙。我们向读者介绍有趣的加密法,这种加密法开始在解决上述问题方面引起更多的注意,我们简要概述一些可以使用的商业和开放源产品。最后,我们就如何确保主钥匙的问题提出了一套解决办法,更多的是准则,而不是确切的技术规格,目的是激励和提高对如何尽可能加强安全的认识。