Key Management
The Key Management section lets you configure key rotation and key lifecycle settings to maintain encryption security. These keys ensure that only authorised users and applications can open encrypted files. In any encryption system, attackers may eventually gain access to private keys. To reduce this risk, the private keys used for file encryption should be changed regularly. To maintain security, PROTECT supports scheduled key rotation, immediate key rotation, offline key lifespan control, and user key status changes.
Scheduled Key Rotation
This section lets you set scheduled key rotation intervals. Regular key rotation ensures that even if old keys are compromised, newer files remain secure.
How Scheduled Rotation Works
PROTECT automatically generates new private keys based on the selected interval.
New keys are distributed to all PROTECT Clients before the old keys expire.
Once the old key expires, PROTECT Clients automatically use the updated keys.
To schedule key rotation:
In Key Rotation Interval, select a duration and click Scheduled Key Rotation to activate the rotation cycle.
Immediate Key Rotation
Use immediate key rotation if a private key has been compromised, such as in cases like lost or stolen devices, compromised accounts, and suspected security breaches.
To rotate the key immediately:
Click Rotate Keys Now! to immediately generate and deploy new encryption keys across the system.
Default Offline Key Lifespan
Offline keys determine how long a user can access encrypted files without being connected to the PROTECT server.
If a user does not reconnect to PROTECT within the defined timeframe, their offline key expires. This prevents unauthorised access when a device is lost, stolen, or offline for too long.
To define the default offline key lifespan:
In Default Offline Key Lifespan, select a duration and click Set Lifespan.
Change User Key Status
This section allows you to enable or disable encryption key access for specific users within a selected security group. When a user’s key status is disabled, they will no longer be able to access any protected files.
To change user key status:
Select a Security Group from the dropdown.
Select the users whose status you want to change.
Click Enable Users or Disable Users based on your needs.
View History
Click View History at the top-right corner to view a complete log of previous key rotations, changes, and key-related events.

.
Last updated

