Glossary · Identity and trust

Key rotation

Replacing a cryptographic key with a new one on a schedule or after compromise, with an overlap so verifiers keep working through the switch.

Key rotation is the practice of replacing a cryptographic key with a new one, on a schedule or after a suspected compromise, while keeping everything that verifies with that key working through the change.

Why rotate. NIST SP 800-57 Part 1 calls the time span during which a key is authorized for use its cryptoperiod, and its key-management guidance sets out how to choose one. A bounded cryptoperiod limits how much data one key protects and how long a stolen key stays useful. The W3C DID specification makes the same point: frequent rotation reduces the value of any single compromised key to an attacker.

How it works with a JWK Set. A publisher that signs with keys listed in a JSON Web Key Set rotates in stages. Illustrative sequence:

Step Signing key Keys published
1. Announce Old Old and new, each with its own kid
2. Switch New Old and new, while verifiers refresh their caches
3. Retire New New only

Verifiers pick the right key by the kid in each signature’s header. RFC 7517 names choosing among the keys in a set during key rollover as a purpose of kid. The overlap matters because verifiers cache key sets and signed documents: a key should be published before anything is signed with it, and stay published while documents it signed are still in circulation.

In A2A. An Agent Card may carry several signatures, and the specification says this is to support key rotation. Clients must not verify with keys that are expired or revoked. The specification also says credentials should be rotated periodically, including the authentication tokens used for push-notification webhooks.

Rotation and revocation. Rotation retires a key on a timetable the owner chooses. Revocation withdraws a key early because it can no longer be trusted. After a compromise both happen at once: the owner publishes a new key and verifiers stop accepting the old one immediately. The DID specification notes that revoking right after rotating suits keys meant for short-lived uses such as authentication.

Neighbouring terms. JWKS is the usual container for keys in rotation. A signed Agent Card is the A2A document most affected by a signing-key change.

Sources

  1. NIST SP 800-57 Part 1 Rev. 5: Recommendation for Key Management, Part 1: General (May 2020) (accessed )
  2. RFC 7517: JSON Web Key (JWK), section 4.5: kid (Key ID) Parameter (accessed )
  3. W3C Decentralized Identifiers (DIDs) v1.0, section 9.7: Verification Method Rotation (accessed )
  4. A2A Protocol Specification, section 8.4.3: Signature Verification (accessed )
  5. A2A Protocol Specification, section 13: Security Considerations (accessed )