If the recovery escrow service 230 loses access to the recovery private key 205, the periodic report publication mechanism may detect that a problem occurred, and a new recovery key pair may be generated by the at least one first computing device 210 and refresh the encrypted portion on next rotation.
According to some embodiments, the trustee 330 publishes the recovery private key 205 in repository 240 and/or instruct the recovery escrow service 230 to publish the recovery private key 205, for instance when the at least one first computing device 210 becomes unavailable, such that the keys for the at least one second computing device 220 may be released to clients. Upon receipt of the at least one second computing device 220 receives the recovery private key 205, the decryption of the encrypted at least a portion of the cryptographic key 206 may be enabled.