Request for review: Offline Key Management Draft Report (Block 14)

@Tomofumi_Okubo @JBringer @Mitchell

Hello Cybersecurity WG Chairs and Experts,

Following our sessions at BGIN Block 14 in Tokyo, we have prepared the draft session report for: Offline Key Management.

Review Request: Please review the attached draft for technical accuracy and provide any feedback, corrections, or additions directly in this thread by March 27.

Security_Offline_Key_Management.docx (39.5 KB)

Thank you for your contributions to these governance standards.

Best regards,

Rola

Thanks @Rola .

Fixes:
-Engage with Begin’s partners → Engage with BGIN’s partners
-Not enough anonymized (“Chloe”?)

Additional info:

Among action items, for lifecycle framework:

  • importance to consider case where no HSM is possible, and how to deal with migration practices vs maintaining security of the keys, revocation challenges, governance provision for transfer of liability.
  • how to balance offline key management vs the regulatory requirement for x % of cold storage. For instance, is there a better way to secure assets than requiring 99% of cold storage?

Next step: start drafting a first document underlining the key aspects discussed during the session. And decide when / which remote calls to be scheduled to organized the drafting.

(We are sending this same request across other threads as well.)

@Tomofumi_Okubo @JBringer @Mitchell

Hello Cybersecurity WG Chairs and Experts,

Thank you for your response and ongoing support on the IKP session report.

I hope this is not too much to ask, but we are hoping to publish the document on the web page by next Monday. Would it be possible for you to upload the merged file with all revisions by this Friday?

We truly appreciate your time and effort, and we apologize for the short notice. Please let us know if the timeline is not feasible and we will do our best to accommodate.

Thank you so much for your understanding and continued support.

Best regards,

Sogo