A system and method for data recovery is described. In one embodiment, an
encrypting system encrypts a message or file using a secret key (KS) and
attaches a key recovery field (KRF), including an access rule index (ARI)
and KS, to the encrypted message or file. To access the encrypted message
or file, a decrypting system must satisfactorily respond to a challenge
issued by a key recovery center. The challenge is based on one or more
access rules that are identified by the ARI included within the KRF.