Chapter 10—Encryption and Key Management BlueScale Key Management
August 2017 User Guide—Spectra T50e Library
298
Createprocedurestohandleencrypteddatathatis,ormaybe,
compromised.Makesureyoucanidentifythedataassociatedwithany
compromisedkeyorkeys.Youmaywanttotakeallcompromiseddata
anddecryptitandthenre‐encryptitandstoreitinanalternatelocation
tominimizethepotentialforunauthorizedaccess.Youalsoneedto
investigatetheincidentinvolvingcompromiseddataandtake
appropriateactionsifidentity‐relateddatawasexposed.
Special Considerations When Using BlueScale Encryption
Professional Edition
Drive‐basedencryptiononlyallowsoneencryptionkeypercartridge,
regardlessofthenumberofkeysstoredonthelibrary.
Tosimplifydatarestorationincaseofdisasterrecoveryandtoachieve
businesscontinuitygoals,makesurethatcriticallyimportantdatais
storedonaseparate,well‐identifiedcartridgeandthatonlyonekeyis
usedforencryptingallthedataonthecartridge.
YoumaywanttotakeadvantageoftheM‐of‐Nsharesoption.This
optionletsyousplitanexportedencryptionkeyintomultiplefiles,or
shares,eachstoredonaseparateUSBdeviceoremailedtoseparate
mailrecipients.Somespecifiedsubsetofthesharesisrequiredto
importtheencryptionkeyintothelibrary.Splittinganexportedkey
intomultiplesharesfurtherprotectsdatafromunauthorizedaccess.
Forexample,ifyouchoosethe2‐of‐3sharesoption,theexported
encryptionkeyissplitintothreeshares(M).Inordertoimportthe
encryptionkeyintothelibrary,twooftheshares(N),eachonaseparate
USBdevice,mustbepresent.
Passwords and Other Identifiers
BlueScaleEncryptionrequiresyoutosupplypasswordsandmonikers(key
names)whenconfiguringandusingtheencryptionfeature.Yoursitemay
wanttoconsiderimplementingspecificrulesthatgovernhowtheseare
created.
Superuser Login/Encryption Passwords BlueScaleEncryptionrequiresa
separatepasswordfromtheoneusedtologintothelibraryinorderto
accessthelibrary’sencryptionfeatures.Thispasswordmustbeentered
afterauserwithsuperuserprivilegeslogsintothelibrary.
IfyouareusingProfessionalEdition,youhavetheoptiontosetthree
separateencryptionpasswords.Ifyouselecttousethisoption,twoofthe
threeencryptionpasswordsmustbeenteredinordertoimportBlueScale
encryptionkeysintothelibraryorexportthemfromthelibrary.