Chapter 10—Encryption and Key Management BlueScale Key Management
August 2017 User Guide—Spectra T50e Library
308
Key Protection Features of BlueScale Professional
IfyouareusingBlueScaleEncryptionStandardEdition,continuewith
ExportanEncryptionKeyonpage309.
Three Passwords to Access Export and import Key Functions Ifyou
enabledMul t i‐Usermodewhenyouconfiguredtheencryptionfeature,you
mustentertwoofthethreeencryptionpasswordsinordertoexportkeys
fromthelibrary.SeeConfiguretheUserMode(BlueScaleProfessional
Only)onpage285)andConfiguretheSecureInitializationMode
(BlueScaleOnly)onpage286forinformationaboutenablingMulti‐User
modeandconfiguringthelibrary tosupportmultipleencryptionpasswords.
Export as M-of-N Shares WiththeStandardEdition,anexportedkeyis
encryptedandsavedasapassword‐protectedfilethatiseithercopiedtoa
USBdeviceorsentasanemailattachmenttoapreconfiguredrecipient.
TheProfessionalEditionoffersanadditionsafeguardwhenexportingand
importingencryptionkeys.Ifdesired,youcanchoosetosplitanencryption
keyintomultiplefiles(M‐of‐Nshares)whenyouexportit.Duringthe
exportprocess,youselecttheatotalnumberofshares(N)tosplitthekey
intoandthesubsetofthoseshares(M)requiredtoimporttheencrypted
keyfileintothelibrary.Dependingonyoursite requirement,youcanselect
oneofthefollowingoptionsforyourM‐of‐Nshares:
2‐of‐3
2‐of‐4
3‐of‐4
2‐of‐5
3‐of‐5
4‐of‐5
EachofthesharesisthencopiedtoaseparateUSBdeviceorsenttoa
separatemailrecipient.SeeStep4onpage310foradditionalinformation
aboutusingtheM‐of‐Nsharesoptionwhenexportingakey.
Requirements for Exporting Keys as M-of-N Shares IfyouhaveBlueScale
ProfessionalEditionandyouwanttoexporttheencryptionkeyasM‐of‐N
shares,youmustmeetthefollowingrequirements.
IfyouselecttoexportthekeytoUSB,youneedaseparateUSBdevice
foreachshare.ThesharesarecopiedtotheUSBdevicesoneafterthe
other.
Ifyouchoosetoemailthekey,youmustselectdifferent,previously
configuredmailuserstoreceivetheshares.Eachrecipientreceivesone
shareasanemailattachment.
Althoughyoucanemailshareswhenexportingthekey,theonlywayto
importsharesofakeyistouseUSBdevices.
Forexample,ifyouchoosethe2‐of‐3option,thentheencryptedkey,which
isfurtherprotectedbyakey‐specificpassword,issplitintothreeshares.
EachshareisthencopiedtoaseparateUSBdevicesorsentasanemail
attachment.