Chapter 10—Encryption and Key Management BlueScale Key Management
August 2017 User Guide—Spectra T50e Library
296
Processes
Considerthefollowingwhenestablishingyourencryptionprocedures:
Startup Security
Developproceduresfortrackingusernamesandpasswords.Makesure
onlytheauthorizedusersknowtheencryptionpasswords,andthatthe
passwordsthemselvesaresecure.RefertoPasswordsandOther
Identifiersonpage298formoreinformationonsettinguppasswords.
Optionally,identifyaprimaryandsecondaryencryptionteam,sothat
youhaveredundancyinyourencryptionstrategy.Althoughthatmeans
theinformationrequiredtodecryptdataisspreadacrossmorepeople,
italsomeansthatrestorationofencrypteddatamaybemucheasier,
andyoumayultimatelyhavemoredataprotectiongiventheextralayer
ofcoverage;forexample,ifauserleaves,youarenotinapositionto
losedata.
Determinethelevelofsecuritytouseatstartup.Botheditionsof
BlueScaleEncryptionpermitastandardmodeandasecure
initializationmode.Instandardmode,dataisencryptedandrestored
assoonasthelibraryisstartedwithnofurtheractionrequired.In
secureinitializationmode,thepartitionsconfiguredtouseencryption
arenotaccessibleforbackuporrestoreoperationsuntilauserwith
superuserprivilegeslogsintothelibraryandenteredtheencryption
password.(SpectraSKLMdoesnotusethesecureinitializationmode.)
Data to Encrypt
Decidewhethertoencryptalldataorasubset.Ifallofthesite’sdatais
tobeencryptedonbackup,thenasinglepartitioncouldbesufficient.If,
however,youarebackingupsomedatawithoutencryption,createa
partitiondedicatedtoencrypteddata,andanotherfornon‐encrypted
data.
Determinewhethertheencrypteddatacanbegroupedtogetherorifit
mustbeisolatedintosets.Ifsetsofencrypteddataneedtobeisolated
fromeachother,createseveralencryptedstoragepartitions,eachusing
adifferentencryptionkey.Forexample,yoursitemaystorefinancial
dataasonesetandconsumeridentityinformationasaseparateset.
BlueScale Encryption Key Protection
BlueScaleEncryptionusesAES‐256encryption,whichisasymmetric,
privatekeyencryptionmethod.BlueScaleEncryptionidentifieseachkey
bythemoniker(nickname)usedtogeneratethekey;thekeyitselfisnever
displayed.Inaddition,keysareencryptedbeforetheyareexportedandthe
filecontainingthekeyispassword
‐protected.