Enterprise Strategy Group | Getting to the bigger truth.TM

IBM: An Encryption Key Management Leader

While many folks were sunning themselves at the beach this past summer, IBM introduced some pretty important security technology: the Tivoli Key Lifecycle Manager (TKLS). Basically, the TKLS products are designed to create, manage, secure, and store encryption keys as a service.

What’s so special about this? First, key management is one of those IT security disciplines that will go from relatively esoteric to an enterprise requirement in the next year or so. Why? More and more data is being encrypted each day, so key management is becoming increasingly important. Stolen encryption keys could compromise the confidentiality of sensitive data while lost encryption keys could transform critical data into meaningless ones and zeros. Pretty soon, all large enterprises will have something resembling TKLS.

As far as IBM TKLS goes, it looks good to me because:

  1. It is one of the first products built with the KMIP standard. The Oasis Key Management Interoperability Protocol(s) is at the heart of TKLS. IBM has already tested TKLS interoperability with key management products from HP, RSA, and SafeNet. This gives distributed organizations the ability to create a federated key management architecture without mandating one vendor technology or another.
  2. IBM took an architectural approach. Yes, TKLS is mainly linked to storage encryption today, but the product is built with other encryption in mind (laptops, file systems, databases, applications, etc.). By offering TKLS support on System z, IBM will gain a beach head at large organizations that will then build a TKLS architecture from the data center to the distributed network.
  3. TKLS is a comprehensive solution. Many key management systems are built for symmetric key management alone. Alternatively, TKLS is designed for management of symmetric and asymmetric keys as well as digital certificates. Again, enterprises will appreciate this more complete solution.

In general, neither key management nor TKLS will get much visibility or industry recognition — key management is just a bit too geeky for most IT folks. Nevertheless, next-generation cloud computing will depend upon ubiquitous trust and data security. IBM gets this more than most. Think of TKLS as its part of its security plumbing for a smarter planet.

Related posts:

  1. CA Enters Encryption Key Management Market
  2. Symantec Moving to Define an Encryption Architecture
  3. Encryption consolidation
  4. The CIA and the Encrypted Enterprise
  5. Is Oracle Becoming an Identity Management Leader?

Tags: , , , , SafeNet, Smarter Planet, TKLS

All views and opinions expressed in ESG blog posts are intended to be those of the post's author and do not necessarily reflect the views of Enterprise Strategy Group, Inc., or its clients. ESG bloggers do not and will not engage in any form of paid-for blogging. Click to see our complete Disclosure Policy.

Add a comment

Search
© 2011 Enterprise Strategy Group, Milford, MA 01757 Main: Fax:

Switch to our mobile site