Methods, systems and computer program products are provided which provide
for controlling access to digital data in a file by encrypting the data with a
first key, encrypting the first key with a second personal key generated from a
password/passphrase associated with the file and further encrypting the encrypted
first key with a control key which is managed by the system. In certain embodiments,
user authentication may also be provided by issuing a ticket which is utilized
to create, access and administer the files in the system.