Key Archival in Jellyfish 

The Jellyfish PKI (Public Key Infrastructure) suite provides comprehensive and flexible support for private key archival, giving organisations the tools they need to balance strong security practices with real-world operational demands. As digital ecosystems become increasingly complex and data protection regulations grow more stringent, the ability to securely manage cryptographic keys across their entire lifecycle is no longer optional—it is essential. Jellyfish addresses this challenge by delivering a robust, standards-based approach to key archival that integrates seamlessly into existing enterprise environments. 

In standard PKI deployments, private keys are generated and stored locally on the end user’s device. This model aligns with widely accepted security principles, particularly the concept of key sovereignty, where the owner maintains exclusive control over their private key. By ensuring that private keys are never transmitted or centrally stored, organisations can significantly reduce the attack surface and limit the risk of large-scale key compromise. This decentralised approach is especially effective for authentication use cases, where key recovery is typically not required. 

However, the realities of enterprise operations often introduce scenarios where exclusive end-user control over private keys can become a liability rather than a strength. In particular, encryption use cases present a unique challenge. When private keys are used to encrypt sensitive data, losing access to those keys can render the data permanently inaccessible. This creates a critical dependency on the continued availability and integrity of the end user’s device and credentials—conditions that cannot always be guaranteed. 

For example, organisations frequently encounter situations where employees leave the company, sometimes without proper handover procedures. In such cases, encrypted files, emails, or records tied to that individual’s private key may become inaccessible. Similarly, users may forget passwords, lose hardware tokens, or experience device failures that result in the loss of locally stored keys. In more severe cases, devices may be damaged, stolen, or compromised by malicious actors, further increasing the risk of data loss. 

We are also seeing, particularly with the advent of greater use of keys in operational technologies, the need to generate keys off card using better random number generators (RNGs) that are available in devices like Hardware Security Modules (HSMs). This presents another opportunity or requirement for Key Archival. 

To address these challenges, Jellyfish PKI offers an optional private key archival capability designed specifically for encryption scenarios. This certificate and private key focused archival is in addition to Jellyfish’s other key archival capability for other Symmetric and Asymmetric keys. The PKI Key Archival feature allows organisations to securely store encrypted copies of private keys within a controlled and protected environment, while maintaining a relationship to the entity that the key was intended for. By doing so, Jellyfish ensures that authorised administrators can recover keys when necessary, without undermining the overall security posture of the PKI system. 

The key archival process within Jellyfish is engineered with multiple layers of protection to ensure that archived keys remain confidential and tamper-resistant. Private keys are never stored in plaintext; instead, they are encrypted using strong cryptographic mechanisms before being archived. Access to these archived keys is tightly controlled through role-based permissions, audit logging, and policy enforcement, ensuring that only authorised personnel can initiate recovery operations. 

Importantly, Jellyfish maintains a clear separation between routine key usage and exceptional recovery scenarios. Under normal operations, end users continue to generate and manage their own private keys without interference. The archival system operates transparently in the background, activating only when recovery is explicitly required and properly authorised. This approach preserves the security benefits of decentralised key ownership while providing a safety net for critical data access. 

key archival architecture

Figure 1 - Key Archival Architecture 

From a compliance perspective, private key archival can play a crucial role in meeting regulatory and legal requirements. Many industries, including finance, healthcare, and government, are subject to data retention and accessibility mandates. Jellyfish enables organisations to demonstrate that encrypted data can be recovered under controlled conditions, supporting both internal governance policies and external audit requirements. Detailed audit trails further enhance accountability by recording every archival and recovery action. 

key archival

Figure 2 - Key Archival on the Template configuration page 

When key archival is enabled, private keys are securely stored in an encrypted form. These archived keys are protected using Key Encryption Keys (KEKs) that are backed by a Hardware Security Module (HSM). This ensures that the encryption keys themselves are generated, stored, and managed within a highly secure, tamper-resistant environment. As a result, even if the archival storage were accessed without authorisation, the private keys would remain protected and unusable. 

This layered security model ensures that key archival does not compromise the overall integrity of the PKI environment. Instead, it provides a controlled and auditable mechanism for key recovery, balancing strong security practices with practical operational needs. 

private key archival

Figure 3 - Enabling private key archival during certificate issuance 

The flexibility of Jellyfish PKI allows organisations to tailor key archival policies to their specific needs. Not all keys require archival, and Jellyfish supports selective implementation based on certificate templates, usage types, or organisational roles. This ensures that archival is applied only where it delivers clear value, avoiding unnecessary complexity or overhead. Administrators retain full control over how and when archival is enabled, aligning the solution with broader security strategies. 

Ultimately, Jellyfish’s private key archival capability represents a thoughtful balance between security, usability, and resilience. It acknowledges the importance of protecting private keys while recognising that absolute loss prevention is not always practical in dynamic business environments. By providing a secure and controlled recovery mechanism, Jellyfish empowers organisations to safeguard both their cryptographic assets and the data those assets protect. 

In an era where data is both highly valuable and highly vulnerable, having a dependable strategy for key management is critical. Jellyfish PKI not only delivers best-in-class security practices but also anticipates the operational realities organisations face every day. With its advanced private key archival support, Jellyfish ensures that organisations are not forced to choose between security and accessibility—they can confidently achieve both.