What happens if a private key is compromised ?

Answer Posted / ramkumar

Private keys must be stored securely, since forgery and
loss of privacy could result from compromise (see Question
4.1.3.7). The measures taken to protect a private key must
be at least equal to the required security of the messages
encrypted with that key. In general, a private key should
never be stored anywhere in plaintext form. The simplest
storage mechanism is to encrypt a private key under a
password and store the result on a disk. However, passwords
are sometimes very easily guessed; when this scheme is
followed, a password should be chosen very carefully since
the security is tied directly to the password.
Storing the encrypted key on a disk that is not accessible
through a computer network, such as a floppy disk or a
local hard disk, will make some attacks more difficult. It
might be best to store the key in a computer that is not
accessible to other users or on removable media the user
can remove and take with her when she has finished using a
particular computer. Private keys may also be stored on
portable hardware, such as a smart card. Users with
extremely high security needs, such as certifying
authorities, should use tamper-resistant devices to protect
their private keys (see Question 4.1.3.13).

Is This Answer Correct ?    0 Yes 1 No



Post New Answer       View All Answers


Please Help Members By Posting Answers For Below Questions

What are the ecb and cbc modes?

507


What is decryption?

505


Do digital signatures help detect altered documents and transmission errors?

601


whats cryptanalysis?

1712


What is an algorithm?

1879






Do encrypted files contain password in some form?

1699


why hash functions are not used for encryption but authentication ?

1376


Blowfish uses the longest key. Does this mean it is the strongest cipher?

1907


How can we use quantum properties in cryptography ?

1315


what is trapdoor and how does it works?

1520


What is multiple encryption?

487


What is public-key cryptography ?

1465


What is luc?

490


What are some other public key cryptosystems ?

1621


How to remove the Kryptel (Silver Key) icon from the desktop?

1593