Figure 38 Key Management Server Linkage; Table 23 Functional Comparison Between The Sed Authentication Key (Common Key) And Key Man- Agement Server Linkage - Fujitsu ETERNUS DX100 S4 Design Manual

Hybrid storage systems
Hide thumbs Also See for ETERNUS DX100 S4:
Table of Contents

Advertisement

2.
Basic Functions
Data Encryption
The following table shows functions for SED authentication keys and key management server link-
age.
Table 23 Functional Comparison between the SED Authentication Key (Common Key) and Key Man-
agement Server Linkage
Function
Key creation
Key storage
Key renewal (auto/manual)
Key compromise (*1)
Key backup
Target RAID groups
*1 : The key becomes unavailable in the key server.
*2: The SED key group must be enabled after a pool or REC Disk Buffer is created, or after a pool
capacity is expanded.
An authentication key to access data of the RAID groups that are registered in a key group can be
managed by the key server.
RAID groups that use the same authentication key must be registered in the key group in advance.
Authentication for accessing the RAID groups that are registered in the key group is performed by
acquiring the key automatically from the key server when an ETERNUS DX is started.
As a key server for the key management server linkage, use a server that has the key management
software installed. Only the following two key management software products can be used.
ETERNUS SF KM
IBM Security Key Lifecycle Manager

Figure 38 Key Management Server Linkage

Business server
RAID group
RAID group
Global hot spare
Fujitsu Storage ETERNUS DX100 S4/DX200 S4, ETERNUS DX100 S3/DX200 S3 Hybrid Storage Systems Design Guide (Basic)
SED authentication key
In the storage system
In the storage system
No
No
No
RAID groups (Standard, WSV, SDV), REC Disk Buffers, SDPs, TPPs,
FTRPs, and FTSPs (*2)
An ETERNUS DX uses the authentication
key that is stored in the key server
in order to unlock the encryption.
ETERNUS DX
RAID group
Key group
Common key
Copyright 2023 Fujitsu Limited
Key server
Key group
Exclusive
authentication
key for a group
68
Key Management Server Linkage
Key server
Key server
Yes
Yes
Yes
P3AM-7642-32ENZ0

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Eternus dx200 s4Eternus dx100 s3Eternus dx200 s3

Table of Contents