How does a scheduled rollover help to prevent key compromise?

DNSSEC uses several mathematical formulas (cryptography) to “sign” a zone. They are subject to cryptanalysis. It is therefore possible for an attacker to learn the private key in a key pair even though that key has never been disclosed, either through “brute force” or other types of attacks. Every attack requires time to complete. Periodically changing the key decreases the length of time an attacker has to attempt the compromise.

