Summary
- Anne-Marie Eklund Löwinder’s Cryptographic Officer key opened a safe-deposit box holding ceremony credentials; it was not the root Key Signing Key and could not authorize a root signature on its own.
- The durable achievement of the ceremony system is engineered incapacity: separate roles, multiple participants, public scripts, audit evidence and orderly succession make trust less dependent on any one celebrated custodian.
The safest fact about Anne-Marie Eklund Löwinder’s key was what it could not do. It could not sign the DNS root. It could not rewrite a domain name. It could not reconstruct the root’s cryptographic identity, and it certainly could not switch off the Internet. The metal key opened a safe-deposit box containing credentials needed for one part of a controlled process. Even inside that process, a Cryptographic Officer acted with other people, under a prepared procedure, before witnesses and cameras.
That is less cinematic than the recurring tale of a handful of people who each possess a “key to the Internet”. It is also more consequential. The root key ceremony is an attempt to make highly concentrated technical importance governable without concentrating operative discretion in a single person. Eklund Löwinder’s twelve years as Cryptographic Officer 2-East, recorded by IANA from 2010 to 2022, offer a particularly clear view of that design.
A pioneer placed inside a limit
Eklund Löwinder did not enter this setting as a ceremonial extra. The Internet Hall of Fame credits her DNSSEC work with helping .SE become the first top-level domain signed with DNSSEC in 2005. That history matters because DNSSEC is an answer to a specific weakness: the Domain Name System was designed to locate services, not to prove cryptographically that an answer had not been forged on its way to a user. A signed root supplies the top trust anchor in a chain that validating resolvers can inspect.
Experience could have been used as an argument for personal authority. The ceremony uses it differently. It recruits credible community representatives, then confines each of them to a narrow duty. IANA’s eligibility rules exclude direct affiliates of PTI, ICANN and Verisign and emphasize integrity, objectivity and diversity. The representative is valuable precisely because she brings standing from outside the operating organizations. That standing does not become unilateral control.
For a Cryptographic Officer, the bounded duty is concrete. The officer keeps a physical safe-deposit-box key between ceremonies, brings it when required, helps obtain the protected credentials and witnesses whether the documented procedure was followed. The officer attests to what happened and must report loss or suspected compromise. A final ceremony provides for the transfer of the role to a successor. Custody, observation and continuity are bundled together; the power to complete the operation alone is not.
Two custodians, two failure conditions
The distinction between a Cryptographic Officer and a Recovery Key Share Holder is easy to flatten in a headline. Operationally, it is decisive.
A CO participates in routine ceremonies. An RKSH is reserved for a catastrophe in which normal facilities and key material cannot be used. The RKSH’s smart card does not contain a whole recovery key. IANA describes it as carrying only a small fragment. Several holders and the prescribed recovery process would be needed to reconstruct what the system requires. RKSHs ordinarily do not attend the quarterly ceremony; instead, they provide periodic custody attestations and take part in functionality tests.
The two roles therefore answer different questions. Can the regular ceremony obtain the credentials it needs without placing them under one operator’s sole physical access? Can the system recover after an extreme failure without leaving a complete rescue secret in one person’s pocket? Conflating them turns a fault-tolerant design into folklore. Keeping them separate reveals a more mature security proposition: routine availability and disaster recovery should not share the same human choke point.
Trust made as a public record
The ceremony’s controls do not stop at splitting possessions. IANA publishes ceremony scripts in advance, opens the event to public observation and provides a live stream. If reality departs from the script, the exception is meant to be discussed, agreed, executed and captured in the audit materials. Attendance thresholds, standby representatives and emergency provisions determine what can proceed when a named participant is unavailable.
These details transform a room full of secure equipment into an accountable sequence of claims. The script states what should occur. The stream lets outsiders observe a performance in real time. Logs, attestations and audit materials preserve evidence after the room empties. None is perfect alone: a camera cannot see every internal state, a script cannot guarantee obedience, and an audit artifact still demands interpretation. Together, however, they increase the cost of an undisclosed deviation and give independent observers something specific to challenge.
The current DNSSEC Practice Statement makes the separation even more explicit. It describes task separation around key generation, use and destruction, multi-person access for KSK operations, and an audit role kept apart from the people exercising multi-person control. The document is current evidence, not proof that every clause remained identical throughout Eklund Löwinder’s tenure. The continuity is the governing idea: critical action should require distinct people performing distinct, reviewable functions.
What is actually being protected
The root KSK does not spend its days signing every DNS answer. In ordinary operations it authenticates the root Zone Signing Keys, which are used for the live root zone. The public portion of the KSK is distributed as a trust anchor. A typical ceremony prepares signatures for the coming operating period; other ceremonies may induct representatives, change secure hardware or handle a KSK lifecycle event.
That difference also corrects the myth of personal command. A box key is a prerequisite to reaching protected credentials in one facility. It is not the cryptographic private key. The private key is not the zone’s editorial authority. And the signed root is one layer in a distributed naming system operated through multiple institutions and technical roles. Every omitted distinction makes the story simpler and the security model less intelligible.
Eklund Löwinder’s importance is therefore not diminished by saying that her key could not sign. It is sharpened. A respected DNSSEC pioneer agreed to occupy a role designed so that reputation, possession and proximity could not collapse into command. She supplied independent human presence, continuity and an attestation that could enter the public record. In a global infrastructure, accepting a limit can be a more valuable contribution than acquiring a privilege.
Sources
- IANA — Root KSK ceremonies
- IANA — DNSSEC trust anchor files
- IANA — DNSSEC procedures
- IANA — DNSSEC Practice Statement, 14 April 2025
- IANA — Trusted Community Representatives
- IANA — Key ceremony schedule and participation
- IANA — Common questions from Trusted Community Representatives
- IANA — Criteria for Trusted Community Representatives
- IANA — Trusted Community Representative roles
- Internet Hall of Fame — Anne-Marie Eklund Löwinder
- Internet Hall of Fame — public portrait of Anne-Marie Eklund Löwinder
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
