Chapter 10—Encryption and Key Management BlueScale Key Management
August 2017 User Guide—Spectra T50e Library
294
Standard Edition vs. Professional Edition
TodetermineaBlueScaleEncryptionkeymanagementstrategy
appropriateforyoursiteandyourdata,decideonthesecuritylevel
appropriateforyoursite,andtheamountandkindsofdatatoencrypt.See
BestPracticesonpage295forthingstoconsiderwhendeterminingyour
encryptionrequirementsandprocesses.Afteryoudecideonthe
appropriatesecuritylevelandwhetherdatasetsneedtobeisolated,you
candecidewhicheditionofBlueScaleEncryptionmeetsyourneeds.
BlueScale Encryption Standard Edition StandardEditionisincludedasa
standardfeatureonthelibrary.Itissuitableforsiteswithaprimarygoalof
securingdatawhileitistransportedtoaremotelocationandstoredthere
forlong‐termarchival.SeeLowSecuritySiteonpage300foranexampleof
settingupencryptionusingBlueScaleEncryptionStandardEdition.
BlueScale Encryption Professional Edition ProfessionalEditionprovides
additionalchoicesfordefiningthelevelofsecurityyouimplementinyour
datacenter.Itissuitableforsitesthatwanttheaddedsecurityofmulti‐
passwordaccesstotheencryptionconfigurationcontrolsandfor
importingandexportingencryptionkeys,andtheaddedflexibilityof
storingupto30encryptionkeysonthelibrary.SeeMediumSecuritySite
onpage301andHighSecuritySiteonpage302forexamplesofsettingup
encryptionusingBlueScaleEncryptionProfessionalEdition.
ThefollowingtableshowsthemajordifferencesbetweentheStandardand
ProfessionalEditions.
Feature Standard Edition Professional Edition
Availability Includedasastandardfeatureon
thelibrary.
Requiresapurchasedoptionkeyto
activate.
Encryption Login
Passwords
Singleencryptionpassword
accessesallencryptionfeatures.
Choiceofusingoneorthreepasswords
toaccessallencryptionfeatures.Using
thethree‐passwordoptionrequiresthe
following:
Threeuniqueencryptionpasswords
mustbeconfigured.
Anyoneofthethreepasswordsmust
beenteredtoenableencryptionwhen
thelibraryisinSecureInitialization
mode.
Anyoneofthethreepasswordsmust
beenteredtoaccessencryptionkey
managementandconfiguration
options,excludingkeyimportand
export.
Twoofthethreepasswordsmustbe
enteredtoimportandexportkeys.