Key Rotation: How Often, and How Not to Break Everything
Key rotation replaces a cryptographic key with a new one. The reasons are straightforward; the reason it goes wrong is that a key is rarely in only one place, and rotating it without knowing where they all are causes an outage. Why rotate at all Limiting exposure. A key compromised at some unknown point protects everything it ever encrypted. Rotating bounds that window — material encrypted under a retired key is unaffected by compromise of the current one, and vice versa. Cryptoperiod limits. Every key has a usable lifetime based on how much data it protects and how much cryptanalysis it is exposed to. Some modes have hard limits on data volume under a single key. Personnel change. Where a human ever held or could have held the key material, rotation on departure is the only way to revoke that knowledge. Compliance. Several frameworks mandate defined cryptoperiods, and an auditor will ask for evidence of rotation rather than a policy stating it happens. Practice. The u...