746 Implementing the IBM Storwize V5000 Gen2 with IBM Spectrum Virtualize V8.1
To enable encryption of both data copies, the Storwize V5000 Gen1 must be replaced by an
encryption capable IBM Spectrum Virtualize system, as shown in Figure 13-2. After such
replacement both copies of data are encrypted, but the Remote Copy communication
between both sites remains unencrypted.
Figure 13-2 Encryption on both sites
Figure 13-3 shows an example configuration that uses both software and hardware
encryption. Software encryption is used to encrypt an external virtualized storage system.
Hardware encryption is used for internal, SAS-attached disk drives.
Figure 13-3 Example of software encryption and hardware encryption
Placement of hardware encryption and software encryption in the Storwize code stack are
shown in Figure 13-4 on page 747. The functions that are implemented in software are shown
in blue. The external storage system is shown in yellow. The hardware encryption on the SAS
chip is marked in pink. Compression is performed before encryption. Therefore, it is possible
to realize benefits of compression for the encrypted data.
Hardware
Encryption
Remote Copy
Server
2145-DH8 2077-324
2145-24F
2145-24F
2077-24F
2077-24F
SAS
SAS
Server
Hardware
Encryption
Software
Encryption
SAS
FC
2145-SV1
2145-24F
2145-24F
2077-324