Solved

Tape Encryption

Posted on 2011-02-16
7
2,281 Views
Last Modified: 2012-05-11
Hi all, Just a gerneral question,

We have 3 tape libraries,
1 Dell ML6000
1 Quantum I500
1 IBM Ts3000 (I think)

We have  a project to look at encrypting the data we send off site, We would like to avoid software based encryption, but does anyone know of a product that is compatible with all 3 of the above libraries.

The independant solutions is the Dell DEKM, and for quantum QEKM and there is another one for IBM. But ideally we would be looking at one solution accross the board.

Does anyone know if this product exists? I know the encryption is getting better with the introduction of KMIP but Quantum are not adopting this on the I500.

Thanks

0
Comment
Question by:grangersi
  • 3
  • 3
7 Comments
 
LVL 25

Expert Comment

by:RobMobility
Comment Utility
Hi,

I believe LTO4 and LTO5 support native encryption which should be enabled via your backup software.

LTO3 does not support native encryption, from what I believe.

Regards,


RobMobility.
0
 

Author Comment

by:grangersi
Comment Utility
Hi, EMC Networker have decided not to include Key Management in their product at the moment.

All drives are LTO4 so we were looking at a possible other solution.

Thanks
0
 
LVL 25

Expert Comment

by:RobMobility
Comment Utility
Hi,

Looks like the TS3000 (TS3500 or TS3494?) supports hardware encryption depending on the drives installed.

The Quantum i500 looks as if it uses LTO5 and the Dell ML6000 can use LTO 4 or 5.

Therefore, they may already support hardware encryption and you just need to enable via your backup solution(s)?

Try and determine which drives are installed to determine whether they support hardware encryption.

Regards,


RobMobility.
0
Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

 
LVL 25

Expert Comment

by:RobMobility
Comment Utility
Hi,

How about CA - they have an encryption key management solution?

What platforms are you using?

Regards,


RobMobility.
0
 
LVL 20

Expert Comment

by:SelfGovern
Comment Utility
If you've got LTO-4 and LTO-5 drives, you *should* have support for hardware
encryption in the tape drives, although I have heard that some (non-Fibre Channel?)
IBM drives do not have HW encryption enabled.

If you have drives that support HW encryption, then you just need a backup application
that can give an encryption key to the drive.   If Networker doesn't do this and you're
stuck on Networker, then... you're out of luck.   Most other backup applications have
had support for the LTO encryption for quite a while now.   BTW -- this is NOT software
encryption; it's using the HW encryption of the tape drive.

The second choice, if your libraries are Fibre Channel attached, is to get a switch that
can encrypt the data in flight.  But this is not likely to be a cheap solution.

You're correct that key management and interoperability is a problem today.  I'm not
aware of any solution -- other than an encrypting FC switch -- that works today to
provide encryption to heterogenous libraries.

That said -- HP has a really elegant and inexpensive encryption solution for its MSL libraries
in the MSL Encryption Kit... but it won't work with other vendors' libraries.

0
 

Accepted Solution

by:
grangersi earned 0 total points
Comment Utility
From the comments/research, it does not look there is 1 solution, so it looks like I will have to go with 3 different solutions.
0
 

Author Closing Comment

by:grangersi
Comment Utility
No solution given
0

Featured Post

Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

Join & Write a Comment

As a financial services provider, your business is impacted by two of the strictest federal regulations on record: the Sarbanes-Oxley Act and the Gramm-Leach-Bliley Act. Correctly implementing faxing into your organization to provide secure, real-ti…
The article will include the best Data Recovery Tools along with their Features, Capabilities, and their Download Links. Hope you’ll enjoy it and will choose the one as required by you.
In this Micro Tutorial viewers will learn how they can get their files copied out from their unbootable system without need to use recovery services. As an example non-bootable Windows 2012R2 installation is used which has boot problems.
In this Micro Tutorial viewers will learn how to use Boot Corrector from Paragon Rescue Kit Free to identify and fix the boot problems of Windows 7/8/2012R2 etc. As an example is used Windows 2012R2 which lost its active partition flag (often happen…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now