Home > What you need to know about storage encryption products
Article:
EMAIL THIS

What you need to know about storage encryption products

19 Aug 2009 | Beth Pariseau, Senior News Writer

Storage technology learning materials
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

In an era of increasing regulation on corporate data, keeping sensitive information secure is moving up the priority list for data storage professionals. Encryption products are being deployed in new areas of IT, and key management is receiving more attention from the industry.

Two of the earliest methods of encryption to come to market are encryption appliances and encryption included in backup software. For a review of those two product categories, please see our Buying Guides entitled "Hardware-based encryption (appliance) product specifications" and "Purchasing backup software-based encryption".

More recently, customers have been moving away from managing encryption in backup software because hardware offers better performance and less complexity. "The market for 'bump in the wire' hardware appliances has remained pretty steady, but it hasn't taken off either," said Russ Fellows, managing partner at Greenwood Village, Colo.-based Evaluator Group Inc. "Encryption at the endpoint will probably continue to gain share."

The following products perform encryption at endpoints such as disk/tape drives and storage-area network (SAN)/network-based devices, and manage encryption keys.

ENDPOINT ENCRYPTION PRODUCTS

Disk Drives

Fujitsu Full Disk Encryption (FDE)
Fujitsu's Full-Disk Encryption (FDE) is performed in hardware at the disk drive level, without dependencies on operating systems for security of encryption keys and access credentials. Fujitsu claims FDE drives suffer no performance impact from performing encryption. The products are based on a partnership with Wave Systems Corp.

Seagate Technology Inc. Seagate Secure technology
Seagate Secure disk drives use a chip to encrypt data inside the drive enclosure. Seagate Secure can also be used to pair a drive with a workstation, and enables "invisible" secure partitions on drives. McAfee Inc.'s ePolicy Orchestrator security management software can manage the drives from a central corporate location, and offers authentication features for unlocking the encrypted drives, including support for biometrics and security tokens. Dell Inc. ships Seagate's Momentus line of desktop-class self-encrypting drives in its Latitude laptops, Precision Mobile Workstations and OptiPlex desktops.

Tape Drives

Proprietary tape formats: IBM TS1120, TS1130 tape drives; Sun Microsystems Inc. (soon to be Oracle Corp.) StorageTek T10000 tape drive
IBM and Sun are the two titans left standing in a declining mainframe / high-end proprietary tape market, and have been engaged in an arms race over the last few years with similar high-capacity, high-performance, self-encrypting tape drives.

IBM includes an encryption license with its drives, while Sun charges a separate fee. Hewlett-Packard (HP) Co. said last year it would ship DAT 320 drives with built-in encryption in 2009.

Various vendors, including Dell, HP, IBM, Overland Storage Inc., Quantum Corp., Spectra Logic Corp. and Tandberg Data: LTO-4 / Ultrium tape drives
Linear Tape-Open (LTO) has become the standard tape format in the enterprise storage market today, edging out earlier formats like DLT.

The fourth revision of the LTO spec contains AES-256 encryption in drive firmware, and the feature is made available by all vendors that offer LTO-4. While all the drives can perform encryption, they require the use of a separate key management application.

SAN/NETWORK-BASED ENCRYPTION PRODUCTS

Switch-based encryption

Brocade Communications Systems Inc. Encryption Switch
Brocade's Encryption Switch is a 32-port, 8 Gbps Fibre Channel switch. The FS8-18 Encryption Blade is a 16-port blade that plugs into Brocade's DCX Backbone switches. Brocade claims that both the switch and the blade can scale up to 96 Gbps of encryption processing power. The Brocade Encryption Switch is resold by NetApp Inc.

CipherMax Inc. CM100T tape appliance, CM180D/CM250/CM500 disk appliances
The company formerly known as Maxxan Systems Inc., an intelligent switch provider, re-emerged as storage security player CipherMax in 2007. Since then it's been marketing the CM100 series, 1U Fibre Channel switches that CipherMax claims can support up to four full-bandwidth disk array target ports and hundreds of encryption streams. All products feature the company's SANCruiser fabric management software, as well as KeyCruiser, which creates a central key repository for all devices in the environment and allows keys to be backed up and archived offsite.

Cisco Systems Inc./ RSA, the security division of EMC: MDS 9500, MDS 9200 blades and switch modules with RSA Key Manager
Cisco/RSA users can add encryption at the SAN director switch either as a blade for the MDS 9500 and MDS 9200 series chassis, or as a switch module for the MDS 9200. Because the MDS 9500 automatically load balances and clusters blades as they're added, adding encryption to the director requires no recabling or rewiring of the SAN. The switches can perform inline encryption for disk arrays and disk-based backup products like virtual tape libraries (VTLs). Hewlett-Packard resells its own version of the Cisco switch, dubbed the Cisco 9222i MultiService Fabric Switch.

Disk/Array-based encryption

SAN hardware vendors are increasingly looking to get a piece of the data security action, too. Below is a list of vendors that support disk-based encryption within enterprise arrays today.

Vendor Product Name
EMC Corp./RSA Symmetrix and Clariion disk arrays with PowerPath multipathing software
Fujitsu Eternus 4000 and 8000 series
Hitachi Data Systems Universal Storage Platform
IBM DS5000 and DS8000 series
LSI Corp. Engenio 7900 SAN

Network-based encryption

Exar Corp./Hifn Inc. Express DR 250/255 and 1600 cards
Prior to its acquisition by Exar earlier this year, Hifn developed a set of chip boards that will perform data deduplication, compression and encryption processing with the goal of eliminating some of the performance issues associated with software-based approaches. The first series, the Express DR 250 and 255, are slower than the 1600 series just introduced, which Hifn claims can perform at up to 1,800 MBps. Hifn is looking to sell the cards through storage hardware OEMs, but also offers its own primary storage deduplication software for Windows systems called BitWackr, which integrates with the DR cards.

KEY MANAGEMENT PRODUCTS

Encryption encodes data with long strings of characters that are decoded with matching encryption keys. Key management is the process of storing, protecting, backing up and keeping track of keys. Without keys, encrypted data becomes inaccessible and effectively destroyed. Key management can be a dauntingly complex process, according to the Evaluator Group's Fellows, and that complexity is part of the reason encryption has yet to see more widespread adoption in the storage market.

Currently, key management products can be split into two general categories: appliances and software-only. "Generally, I like appliances," Fellows said. "Software allows for a lot of configuration and tweaking, but it's not quite as simple to set up and get running as an appliance."

Software Key Managers
Vendor Product Name
EMC Corp./RSA Key Manager
IBM Tivoli Key Lifecycle Manager
Vormetric Key Security Expert
Appliance Key Managers
Vendor Product Name
EMC Corp./RSA Key Manager
HP StorageWorks Secure Key Manager
NetApp Inc. / Decru Lifetime Key Management
Quantum Corp. Scalar Key Manager Appliance
Sun Microsystems Inc. StorageTek Crypto Key Management Station
Thales Group Encryption Manager for Storage

Analysts agree that the biggest factor currently holding key management back is the lack of standards in the industry to make multiple key management products interoperable. For more insights on that issue, download our podcast on key management with Enterprise Strategy Group principal analyst Jon Oltsik.



BROWSE BY TAG
Secure data storage,   Data Protection,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Secure data storage
Throwing caution to the clouds
Storage encryption essentials
Vendors take steps to lock down cloud storage services
Encryption Special Report: Key management stumbling block to securing data
Isilon targets enterprise NAS with Backup Accelerator, N+2:1 parity
Storage Decisions Chicago 2009 Session Downloads
Storage Decisions Session Downloads: Disaster Recovery Track (Chicago 2009)
Storage Decisions Session Downloads: Data Retention & Retrieval Track (Chicago 2009)
Data on the brink
Sun jumbles key management picture

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
hard drive shredder  (SearchStorage.com)
Storage as a Service (SaaS)  (SearchStorage.com)
storage encryption  (SearchStorage.com)
storage security  (SearchStorage.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary




Find Data Reduction
TechTarget Storage Media
Storage Magazine View this month\\'s issue and subscribe today.
Storage Decisions Apply online for free conference admission.
SearchStorage.com
HomeNewsMagazineTopicsLearningMultimediaWhite PapersBlogsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts