【24h】

Comparative Analysis of Cryptographic Key Management Systems

机译:加密密钥管理系统的比较分析

获取原文

摘要

Managing cryptographic keys can be a complex task for an enterprise and particularly difficult to scale when an increasing number of users and applications need to be managed. In order to address scalability issues, typical IT infrastructures employ key management systems that are able to handle a large number of encryption keys and associate them with the authorized requests. Given their necessity, recent years have witnessed a variety of key management systems. aligned with the features, quality, price and security needs of specific organisations. While the spectrum of such solutions is welcome and demonstrates the expanding nature of the market, it also makes it time consuming for IT managers to identify the appropriate system for their respective company needs. This paper provides a list of key management tools which include a minimum set of features, such as availability of secure database for managing keys, an authentication, authorization, and access control model for restricting and managing access to keys, effective logging of actions with keys, and the presence of an API for accessing functions directly from the application code. Five systems were comprehensively compared by evaluating the attributes related to complexity of the implementation, its popularity, linked vulnerabilities and technical performance in terms of response time and network usage. These were Pinterest Knox, Hashicorp Vault, Square Key-whiz, OpenStack Barbican, and Cyberark Conjur. Out of these five, Hachicorp Vault was determined to be the most suitable system for small businesses.
机译:管理加密密钥可以是企业的复杂任务,并且在需要管理越来越多的用户和应用程序时缩放的复杂任务。为了解决可扩展性问题,典型的IT基础架构采用能够处理大量加密密钥的密钥管理系统,并将它们与授权请求相关联。鉴于他们的必要性,近年来目睹了各种关键管理系统。与特定组织的特点,质量,价格和安全需求保持一致。虽然欢迎这种解决方案的频谱并展示了市场的扩大性质,但它也使IT管理人员耗时地耗时,以确定各自的公司需求的适当系统。本文提供了包含最小一组功能的密钥管理工具列表,例如用于管理密钥的安全数据库的可用性,用于限制和管理对键的访问,有效地记录具有键的操作的权限,身份验证,授权和访问控制模型,以及用于直接从应用程序代码访问函数的API的存在。通过评估与实施的复杂性有关的属性,其受欢迎程度,在响应时间和网络使用方面进行了全面评估了五种系统。这些是Pinterest Knox,Hashicorp拱顶,方形钥匙,Openstack Barbican和Cyber​​ Ark Congur。在这五个中,Hachicorp Vault被确定为最合适的小企业系统。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号