IBM Midrange System DS4000 Series Hardware Manual page 277

Midrange system storage ds4000/ds5000 series
Hide thumbs Also See for Midrange System DS4000 Series:
Table of Contents

Advertisement

5
Disk Security with Full Disk
Chapter 5.
Encryption drives
Disk Security is a new feature introduced with the IBM System Storage DS5000 storage
subsystem that uses the newly available Full Disk Encryption (FDE) disk drives. It is
supported by the latest level of the DS5000 firmware (Version 7.60) and Storage Manager
V10.60. This chapter discusses how this new feature can add a greater level of security while
your data resides on disk, what it does, the various components of the feature, and how to
implement it.
The Disk Security premium feature requires security capable drives. A security capable drive
encrypts data during writes and decrypts data during reads. Each security capable drive has
a unique drive encryption key. When a security capable drive has the security enabled, the
drive requires the correct security key from the DS5000 for authentication before allowing
reading or writing the data. This is managed on each of the DS5000 controllers by the IBM
Disk Encryption Storage Manager. All of the drives in the DS5000 share the same security
key and the shared security key provides read and write access to the drives, and the drive
encryption key on each drive is used to encrypt the data.
259
© Copyright IBM Corp. 2010. All rights reserved.

Advertisement

Table of Contents
loading

Table of Contents