Key Management Server Linkage; Figure 5.7 Data Encryption; Table 5.4 Functions For Sed Authentication Keys And Key Management Server Linkage - Fujitsu ETERNUS DX80 S2 Overview

Disk storage system
Hide thumbs Also See for ETERNUS DX80 S2:
Table of Contents

Advertisement

Chapter 5 Basic Functions
5.2 Security

Figure 5.7 Data encryption

Server
Server
Server
5.2.5

Key Management Server Linkage

Security for authentication keys that are used for authenticating encryption from Self Encrypting Drives (SEDs)
can be enhanced by managing the authentication key in the key server.
Key life cycle management
An authentication key is created and stored in the key server. A key can be obtained by accessing the key
server from the ETERNUS DX Disk storage system when required.
A key cannot be stored in the ETERNUS DX Disk storage system. Managing an authentication key in an area
that is different from where an SED is stored makes it possible to manage the key more securely.
Key management consolidation
When multiple ETERNUS DX Disk storage systems are used, a different authentication key for each
ETERNUS DX Disk storage system can be stored in the key server.
The key management cost can be reduced by consolidating key management.
Key renewal
An authentication key is automatically renewed before it expires by setting a key expiration date.
Security against information leakage can be enhanced by regularly changing the authentication key.
The authentication key is automatically changed after the specified period of time. Key operation costs can
be reduced by changing the key automatically. However, the key can be changed manually if required.
Table 5.4
Functions for SED authentication keys and key management server linkage
Function
Key creation
Key storage
Key renewal (auto/manual)
Key compromise (*1)
Key backup
*1:
The key becomes unavailable in the key server.
ETERNUS DX Disk
storage system
Setting and management of encryption
SED authentication key
In the storage system
In the storage system
No
No
No
58
ETERNUS DX80 S2/DX90 S2 Disk storage system Overview
Copyright 2013 FUJITSU LIMITED
???
???
???
Encrypted
???
???
???
123
123
123
Unencrypted
123
123
123
Prevention of information
Key management server linkage
Key server
Key server
Yes
Yes
Yes
???
leakage
P3AM-4812-11ENZ0

Advertisement

Table of Contents
loading

This manual is also suitable for:

Eternus dx90 s2

Table of Contents