Home > Ask the Storage Technology Experts > Questions & Answers > Choosing the best way to encrypt data
Ask The Storage Expert: Questions & Answers
EMAIL THIS

Choosing the best way to encrypt data

Vijay Ahuja EXPERT RESPONSE FROM: Vijay Ahuja

Pose a Question
Other Storage Categories
Meet all Storage Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 14 January 2001
Besides storing the media in a safe place, what security preparations would you recommend someone use who is planning to archive data for more than 10 years? Specifically, I would like to encrypt the data and I am wondering about the best choice of algorithm, key generation and length, and key management.

>

Before answering your question, I would suggest you analyze the "safe place" for the media storage. Is it just (only) physically secure or do you have intercepts such as firewall and intrusion detection protections?

Back to your question - for data archive, encryption is the first step. Here, the challenge is the storage of keys for long periods of time. One approach is to let the customer own and retain the keys - which can be done on some of the smart cards. However, key storage, both the number of keys and the duration of key storage, can pose a challenge. For encryption algorithms, 3-DES in CBC mode is commonly recommended for storage data (of course, it all depends on how secure you want your data to be). AES in CBC mode is another possibility. DES in CBC mode is now considered weak.

The next step after encryption is the support for ensuring data integrity using digital signature technologies. While encryption protects the confidentiality, it does not ensure integrity of the data.

There are also some aspects of the recent HIPAA regulations that specify certain levels of security for the healthcare records. You may want to consider that for your data archives.

Finally, you must develop and enforce sound security policies that meet the customer requirements.

Sorry, there are other considerations too, but this should give you the high level picture.

Editor's note: Do you agree with this expert's response? If you have more to share, post it in our Administrator Central discussion forum.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Search for Data Management Tools
TechTarget Storage Media
Storage Magazine View this month\\'s issue and subscribe today.
Storage Decisions Apply online for free conference admission.
SearchStorage.com
HomeNewsMagazineTopicsLearningMultimediaWhite PapersBlogsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts