EasyManua.ls Logo

Spectra T50e - Page 299

Default Icon
539 pages
Print Icon
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
Chapter 10—Encryption and Key Management BlueScale Key Management
August 2017 User GuideSpectra T50e Library
296
Processes
Considerthefollowingwhenestablishingyourencryptionprocedures:
Startup Security
Developproceduresfortrackingusernamesandpasswords.Makesure
onlytheauthorizedusersknowtheencryptionpasswords,andthatthe
passwordsthemselvesaresecure.RefertoPasswordsandOther
Identifiersonpage298formoreinformationonsettinguppasswords.
Optionally,identifyaprimaryandsecondaryencryptionteam,sothat
youhaveredundancyinyourencryptionstrategy.Althoughthatmeans
theinformationrequiredtodecryptdataisspreadacrossmorepeople,
italsomeansthatrestorationofencrypteddatamaybemucheasier,
andyoumayultimatelyhavemoredataprotectiongiventheextralayer
ofcoverage;forexample,ifauserleaves,youarenotinapositionto
losedata.
Determinethelevelofsecuritytouseatstartup.Botheditionsof
BlueScaleEncryptionpermitastandardmodeandasecure
initializationmode.Instandardmode,dataisencryptedandrestored
assoonasthelibraryisstartedwithnofurtheractionrequired.In
secureinitializationmode,thepartitionsconfiguredtouseencryption
arenotaccessibleforbackuporrestoreoperationsuntilauserwith
superuserprivilegeslogsintothelibraryandenteredtheencryption
password.(SpectraSKLMdoesnotusethesecureinitializationmode.)
Data to Encrypt
Decidewhethertoencryptalldataorasubset.Ifallofthesite’sdatais
tobeencryptedonbackup,thenasinglepartitioncouldbesufficient.If,
however,youarebackingupsomedatawithoutencryption,createa
partitiondedicatedtoencrypteddata,andanotherfornonencrypted
data.
Determinewhethertheencrypteddatacanbegroupedtogetherorifit
mustbeisolatedintosets.Ifsetsofencrypteddataneedtobeisolated
fromeachother,createseveralencryptedstoragepartitions,eachusing
adifferentencryptionkey.Forexample,yoursitemaystorefinancial
dataasonesetandconsumeridentityinformationasaseparateset.
BlueScale Encryption Key Protection
BlueScaleEncryptionusesAES256encryption,whichisasymmetric,
privatekeyencryptionmethod.BlueScaleEncryptionidentifieseachkey
bythemoniker(nickname)usedtogeneratethekey;thekeyitselfisnever
displayed.Inaddition,keysareencryptedbeforetheyareexportedandthe
filecontainingthekeyispassword
protected.

Table of Contents

Other manuals for Spectra T50e

Related product manuals