# Cryptographic Key Management
Cryptographic key management governs the generation, provisioning, storage, use, rotation, backup, recovery, revocation, and destruction of cryptographic keys.
## Security significance
Keys can authorize device identity, secure boot, encrypted storage, software signing, authentication, and protected communication. A technically strong algorithm cannot compensate for compromised provisioning, exposed backups, ambiguous ownership, failed revocation, or lost recovery authority.
## Continuity boundary
Availability and secrecy must be designed together. A key that cannot be recovered may destroy continuity; a recovery path that is too permissive may destroy authorization.
## Relationships
[[Secure Enclave]] · [[Hardware Root of Trust]] · [[Certificate and Device Identity Ledger]] · [[Identity Continuity]] · [[Recovery Topology]].