According to one embodiment, a key management device includes a storage and a server. The storage includes a first nonvolatile memory, and a first controller configured to encrypt, using a first media encryption key, data from a host, and store the encrypted data in the first nonvolatile memory. The server includes a second nonvolatile memory storing a first key, and a second controller configured to transmit the first key from the second nonvolatile memory to the storage without passing through the host. The first controller is configured to generate the first media encryption key using the first key.