Cloud is a key-management pain: NIST
October 2, 2013Grazed from The Register. Author: Richard Chirgwin.
The ISA’s National Institute of Standards and Technology (NIST) – recently accused of collaborating with the NSA to weaken security standards – has put together a paper highlighting the key-management challenge posed by cloud computing platforms.
As readers will know, key multiplication (and therefore management) can be headache-making even in in-house IT environments. Just one service, SSH, was criticised by its creator earlier this year for spreading 1unwanted keys far and wide. The paper, Cryptographic Key Management Issues & Challenges in Cloud Services, would be available at http://www.nvlpubs.nist.gov/nistpubs/ir/2013/NIST.IR.7956.pdf if it were not for the fact NIST’s site has been DOSed by the US government shut down. The Reg has popped it into Dropbox here as a PDF. (See – we don’t need no lousy government, do we?)…
As the paper, authored by Ramaswamy Chandramouli, Michaela Iorga and Santosh Chokhani, states, crypto key management – already a challenge for anybody with a large IT infrastructure – starts to look a little nightmarish when you start spreading your systems far and wide into cloud environments you don’t control…
Read more from the source @ http://www.theregister.co.uk/2013/10/02/cloud_is_a_keymanagement_pain_nist/


