Figure 37 Key Management Server Linkage - Fujitsu ETERNUS DX S5 Series Design Manual

Hybrid
Hide thumbs Also See for ETERNUS DX S5 Series:
Table of Contents

Advertisement

2. Basic Functions
Data Encryption
Function
Key backup
Target RAID groups
*1: The key becomes unavailable in the key server.
*2: After a pool is created or after the pool capacity is expanded, all the RAID groups that configure the pool must be added to the key
group. After a REC Disk Buffer is created, the RAID group that is registered as the REC Disk Buffer must be added to the key group.
An authentication key to access data of the RAID groups that are registered in a key group can be managed by
the key server.
RAID groups that use the same authentication key must be registered in the key group in advance.
Authentication for accessing the RAID groups that are registered in the key group is performed by acquiring the
key automatically from the key server when an ETERNUS DX is started.
As a key server for the key management server linkage, use a server that has the key management software
"ETERNUS SF KM" installed. IBM Security Key Lifecycle Manager can also be used as the key management
software.
Figure 37
Key Management Server Linkage
Business server
RAID group
RAID group
Global hot spare
SEDs (RAID group) that are not registered in a key server are encrypted by using the authentication key
(common key) that is stored in the ETERNUS DX.
A hot spare cannot be registered in a key group.
When a Global Hot Spare is configured as a replacement drive for a RAID group that belongs to a key group, an
authentication key is specified according to the setting of the key group.
When a Dedicated Hot Spare is registered, an authentication key is specified according to the setting of the key
group for the target RAID group.
SED authentication key
No
RAID groups (Standard, WSV, SDV, SDPV), REC Disk Buffers, TPPs, FTRPs, and FTSPs
(*2)
An ETERNUS DX uses the authentication key
that is stored in the key server in order to
unlock the encryption.
ETERNUS DX
RAID group
Key group
Common key
Key Management Server Linkage
Yes
Key server
Key group
Exclusive
authentication
key for a group
86
Design Guide

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents