IBM System Storage Open Systems Tape Encryption Solutions
Total Page:16
File Type:pdf, Size:1020Kb
Front cover IBM System Storage Open Systems Tape Encryption Solutions Understanding tape encryption and Tivoli Key Lifecycle Manager Version 2 Planning for and installing hardware and software Configuring and managing the tape encryption solution Alex Osuna Luciano Cecchetti Edgar Vinson ibm.com/redbooks International Technical Support Organization IBM System Storage Open Systems Tape Encryption Solutions December 2010 SG24-7907-00 Note: Before using this information and the product it supports, read the information in “Notices” on page vii. First Edition (December 2010) This edition applies to Tivoli Key Lifecycle Manager (TKLM) Version 2. © Copyright International Business Machines Corporation 2010. All rights reserved. Note to U.S. Government Users Restricted Rights -- Use, duplication or disclosure restricted by GSA ADP Schedule Contract with IBM Corp. Contents Notices . vii Trademarks . viii Preface . ix The team who wrote this book . .x Become a published author . xi Comments welcome. xi Stay connected to IBM Redbooks . xii Chapter 1. Introduction to tape encryption. 1 1.1 IBM System Storage tape drives. 2 1.2 How tape data encryption works . 4 1.3 What to encrypt . 6 1.4 Why use tape data encryption. 7 1.4.1 Why encrypt data in the drive . 7 1.4.2 Fundamental to encryption: Policy and key management . 7 1.4.3 Summary. 8 1.5 Concepts of tape data encryption . 8 1.5.1 Symmetric key encryption. 9 1.5.2 Asymmetric key encryption . 11 1.5.3 Hybrid encryption . 14 1.5.4 Digital certificates . 15 1.6 Simplifying key management with TKLM . 20 1.6.1 Encryption as a critical business process . 20 1.6.2 Encryption and key management for compliance, availability, retention and security 21 1.6.3 Securing data automatically on self-encrypting drives . 21 1.6.4 Addressing objections to encryption of data at rest . 21 Chapter 2. IBM tape encryption methods . 23 2.1 Tivoli Key Lifecycle Manager . 24 2.1.1 What is new in version 2 . 24 2.1.2 Tivoli Lifecycle Key Manager components and resources . 25 2.1.3 Key exchange . 27 2.2 Methods of managing IBM tape encryption. 29 2.2.1 System-managed encryption . 29 2.2.2 Library-managed encryption . 30 2.2.3 Encrypting and decrypting with SME and LME. 32 2.2.4 Application-managed encryption. 34 2.2.5 Mixed mode example . 37 Chapter 3. IBM System Storage tape and tape automation for encryption . 39 3.1 IBM System Storage TS1130 and TS1120 Tape Drive . 40 3.1.1 Tape data encryption support . 40 3.1.2 IBM TotalStorage 3592 Model J70 Tape Controller . 41 3.2 IBM LTO Ultrium tape drives and libraries . 42 3.2.1 LTO overview . 42 3.2.2 LTO media . 43 3.2.3 IBM System Storage TS2240 Tape Drive Express Model . 46 © Copyright IBM Corp. 2010. All rights reserved. iii 3.2.4 IBM System Storage TS2250 Tape Drive Express model . 47 3.2.5 IBM System Storage TS2350 Tape Drive. 48 3.2.6 IBM System Storage TS2900 Tape Autoloader . 48 3.2.7 IBM System Storage TS3100 Tape Library . 50 3.2.8 IBM System Storage TS3200 Tape Library . 51 3.2.9 IBM System Storage TS3310 Tape Library . 53 3.3 IBM System Storage TS3400 Tape Library . 56 3.4 IBM System Storage TS3500 Tape Library . 57 3.4.1 Tape encryption overview . 58 3.4.2 Tape drives, libraries, and media relationship. 63 Chapter 4. Planning for software and hardware. 65 4.1 Encryption planning. 66 4.2 Planning assumptions . 66 4.3 Encryption planning quick-reference. 67 4.4 Choosing encryption methods. 70 4.4.1 Encryption method comparison. 70 4.4.2 Open systems encryption methods. 71 4.4.3 Decision time . 72 4.5 Solutions available by operating system . 72 4.5.1 AIX solution components . 72 4.5.2 Linux on System p, System x, and other Intel or AMD Opteron servers. 74 4.5.3 HP-UX, Sun, and Windows components . 76 4.5.4 IBM Tivoli Storage Manager . 79 4.6 Ordering information . 79 4.6.1 TS1120 tape drive prerequisites . 80 4.6.2 Tape controller prerequisites. 81 4.6.3 LTO4 or LTO5 tape drive prerequisites. 82 4.6.4 Tape library prerequisites . 83 4.6.5 Other library and rack open systems installations. 84 4.6.6 General software prerequisites for encryption . 85 4.6.7 TS1120 and TS1130 supported platforms . 85 4.6.8 IBM LTO4 and LTO5 tape drive supported platforms . 86 4.7 Other planning considerations for tape data encryption . 87 4.7.1 Performance considerations . 87 4.7.2 Encryption with other backup applications . 87 4.7.3 ALMS and encryption in the TS3500 library . ..