A physical encryption key system binds an encryption key to a physical key
and denies decryption of secured information if the physical key is not
present to a particular computing device. In one implementation, the
physical key comprises a convenient removable pen drive on which a .NET
isolated storage space is created to store the encryption key. The .NET
isolated storage space can only be accessed by concurrence of the same
user, domain, computing device, application, and physical key that
participated in creating the isolated storage space. The user enjoys the
security of knowing that protected information cannot be decrypted
without the physical key; cannot be decrypted without the user's
credentials even if the physical key is stolen; and cannot be decrypted
if the protected information is pirated to a different computing device.