Scalar i6000 Encryption

Overview

The library supports several encryption key management solutions. These solutions work in conjunction with the library to generate, protect, store, and manage encryption keys. The keys are used by tape drives to encrypt information being written to, and decrypt information being read from, media. The library communicates with the encryption key management server(s). The encryption keys pass through the library, so that encryption is transparent to the applications. Using the library in this way is known as library managed encryption.

Encryption Key Management (EKM)

The Encryption Key Management (EKM) feature enables support for Library-Managed Encryption (LME) with Scalar Key Manager configurations, or Key Management Interoperability Protocol (KMIP) connected encryption key servers, as well as IBM TKLM/SKLM/GSKLM encryption key management solutions via an IBM Proprietary Protocol (IPP) connection.

A tape library can only configure a single EKM solution for library manged encryption (LME). Encryption can be enabled or disabled per partition. By default, LME is disabled per partition. However, encryption-capable tape drives are configured for application managed encryption (AME) by default, so that an application is able to request drives to encrypt/decrypt data without the need for any specific library configuration.

Additional Information

WARNING: No changes to the encryption settings can be made while library partitions are configured to use Library-Managed Encryption (LME). LME must first be disabled on the partition before making changes to the encryption settings (see Encryption Key Management (EKM)).


Layout


Tasks

Configuration

Actions