Reference is now made to
In some embodiments, the key management system 300 includes a trustee 330 (e.g., an independent legal entity such as a trusted attorney office), which is in agreement with the at least one first computing device 210 to instruct the recovery escrow service 230 under predefined conditions, for instance when the at least one first computing device 210 becomes unavailable. The trustee 330 may receive the recovery private key 205 from the recovery escrow service 230 and/or directly from the at least one first computing device 210. In some embodiments, in order to verify that the trustee 330 is to publish the recovery private key 205 when needed, the trustee 330 periodically publishes a general status report (e.g., a financial report of the company maintaining the servers of the system) related to the at least one first computing device 210 at the repository 240. The status report may then be retrieved by the at least one second computing device 220 in order to verify that the trustee is indeed in agreement with the at least one first computing device 210.