Secure Key Management
for Complete Control
Organization, Distribution, Control, Backup and Restore
Keys are at the heart of the STIKABA encryption system. STIKABA uses symmetric encryption, which means that the encrypting STIKABA and each authorized decrypting STIKABA must possess the same Keys.
STIKABA combines these Keys with Prime Numbers and a True Random Number Generator (TRNG) as part of the process used to generate the One-Time Pad (OTP). The resulting OTP is then used by STIKABA to perform encryption and decryption.
Because both sides of a symmetric encryption system require shared Keys, STIKABA provides an integrated method for generating, organizing, distributing, controlling, managing, backing up, and restoring those Keys.
Key Generation and Sharing
Keys are generated on an originating STIKABA and can then be securely transferred to one or more STIKABAs that require the same Keys for encryption and decryption.
STIKABA does not require the user to manually manage individual Keys. Instead, Keys are organized into a hierarchical structure consisting of Families and Groups.
Family > Group > Keys
A Family provides the highest organizational level, while Groups provide subdivisions within each Family. The number of Families and Groups that can be active on a STIKABA at any given time is determined by its Operation Level: Personal, Associate, Partner, Enterprise, or Director.
Organizing Keys
Around the Information
The Family/Group hierarchy allows Keys to be organized according to data type, department, project, customer, management level, security requirement, or other user-defined purpose.
Examples for an individual:
Examples for an organization:
Secure Key Export and Import
When Keys need to be transferred from an originating STIKABA to another STIKABA, the selected Family/Group Key information is encrypted and exported into a Key file using the Export command on the STIKABA Dashboard.
The Key file can then be transferred to the intended recipient. At the receiving end, the STIKABA Dashboard Import command is used to import the Key file into the receiving STIKABA.
Any STIKABA can receive and import a Key file; however, possession or import of the file does not necessarily authorize the STIKABA to use the Keys it contains.
Directed Delivery - Controlling Who Can Use the Keys
STIKABA's Directed Delivery feature allows the originator to specify exactly which STIKABA or STIKABAs are authorized to use the exported Keys. This separates possession of a Key file from authorization to use its cryptographic material.
Possession is Not Authorization
With Directed Delivery, a Key file that reaches an unintended STIKABA does not automatically give that device permission to use the Keys. This provides an "Eyes Only" capability at the Key-distribution level.
Time-Controlled Keys
STIKABA can also control when Keys are valid. A lifetime or validity period can be assigned to Keys, establishing the period during which those Keys are authorized for operation.
When the specified validity period expires, the Keys can no longer be used for further encryption or decryption. Key lifetime can therefore support projects, subscriptions, customer relationships, contracts, or other time-limited activities.
Key Backup and Restore
The STIKABA Dashboard provides Backup and Restore commands specifically designed to protect the Keys associated with a STIKABA.
Although performing a Backup is optional, SyferSafe considers maintaining a current Key backup essential. A new Backup should be created whenever Keys, Families, or Groups are defined, added, modified, or deleted.
A current Backup helps protect against accidental Key deletion, unintended configuration changes, failure or damage to a STIKABA, or physical loss of the device.
Why Key Backup is Critical
The Keys associated with a STIKABA are not simply configuration information. They are an essential part of maintaining access to data protected with those Keys.
If you lose the keys, you can lose access to your encrypted data.
Strong encryption is specifically designed so that the protected information cannot simply be recovered without the required cryptographic material. That same protection makes preservation of the authorized user's Keys critically important.
Backup
The Backup command on the STIKABA Dashboard creates a protected backup of the Key information associated with the STIKABA. Backups should be updated whenever the Key configuration changes so that the backup remains synchronized with the Keys, Families, and Groups in use.
Backups should be stored securely and separately from the STIKABA itself. Keeping the only backup with the STIKABA could defeat the purpose of the backup if both are lost, stolen, damaged, or destroyed at the same time.
Restore
The Restore command provides the complementary recovery function. When recovery is necessary, a valid STIKABA Backup can be used to restore the backed-up Key information according to STIKABA's recovery procedures.
A Simple Rule for Stikaba Users
Keys changed? Back up.
Whether a Family or Group has been added, changed, or deleted, or important new Keys have been established, creating a new Backup should become a routine part of using STIKABA.
A Managed Shared-Key Architecture
Together, these capabilities provide STIKABA with a scalable system for managing the shared Keys required by symmetric One-Time Pad encryption - from two STIKABAs exchanging protected information to organizations managing many users, departments, customers, and secure communications.
STIKABA - The right Keys. The right STIKABAs. The right time. Protected by Backup.