HP Cisco MDS 9120 Cisco MDS 9000 Family Storage Media Encryption Configuration - Page 25

Cisco SME Terminology

Page 25 highlights

Chapter 1 Product Overview About Cisco Storage Media Encryption Send documentation comments to [email protected] • The affinity-based load balancing feature reduces the FC redirect interactions, which reduces the overhead in the existing operation. Cisco SME Terminology The following Cisco SME-related terms are used in this book: • Cisco SME interface-The security engine in the MSM-18/4 module or fixed slot of a Cisco MDS 9222i fabric switch. Each MSM-18/4 module and MDS 9222i switch has one security engine. • Cisco SME cluster-A network of MDS switches that are configured to provide the Cisco SME functionality; each switch includes one or more MSM-18/4 modules and each module includes a security engine. • Fabric-A physical fabric topology in the SAN as seen by Fabric Manager. There can be multiple VSANs (logical fabrics) within the physical fabric. • Tape group-A backup environment in the SAN. This consists of all the tape backup servers and the tape libraries that they access. • Tape device-A tape drive that is configured for encryption. • Tape volumes-A physical tape cartridge identified by a barcode for a given use. • Tape volume group-A logical set of tape volumes that are configured for a specific use, for example, a group of tape volumes used to backup a database. • Key Management Center-A component of the Fabric Manager that stores the encryption keys. • Master Key-An encryption key generated when an Cisco SME cluster is created. The master key encrypts the tape volume keys and tape keys and it is required to decrypt those keys in order to retrieve encrypted data. • Media Key-A key that is used for encrypting and authenticating the data on specific tapes. • SmartCard-A card (approximately the size of a credit card) with a built-in microprocessor and memory used for authentication. • Cisco SME Administrator-An administrator who configures Cisco SME. This role includes the Cisco Storage Administrator role where the administrator manages the storage media encryption operations and the Cisco SME KMC Administrator role where the administrator is responsible for the Cisco SME key management operations. • Cisco Storage Administrator -An administrator who manages the storage media encryption operations. • Cisco SME KMC Administrator-An administrator who is responsible for the Cisco SME key management operations. • Cisco SME Recovery Officer-A data security officer entrusted with smart cards and the associated PINs. Each smart card stores a share of the cluster master key. Recovery officers must present their cards and PINs to recover the key database of a deactivated cluster. A quorum of recovery officers are required to execute this operation. OL-18091-01, Cisco MDS NX-OS Release 4.x Cisco MDS 9000 Family Storage Media Encryption Configuration Guide 1-7

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280

Send documentation comments to [email protected]
1-7
Cisco MDS 9000 Family Storage Media Encryption Configuration Guide
OL-18091-01, Cisco MDS NX-OS Release 4.x
Chapter 1
Product Overview
About Cisco Storage Media Encryption
The affinity-based load balancing feature reduces the FC redirect interactions, which reduces the
overhead in the existing operation.
Cisco SME Terminology
The following Cisco SME-related terms are used in this book:
Cisco SME interface—The security engine in the MSM-18/4 module or fixed slot of a Cisco MDS
9222i fabric switch. Each MSM-18/4 module and MDS 9222i switch has one security engine.
Cisco SME cluster—A network of MDS switches that are configured to provide the Cisco SME
functionality; each switch includes one or more MSM-18/4 modules and each module includes a
security engine.
Fabric—A physical fabric topology in the SAN as seen by Fabric Manager. There can be multiple
VSANs (logical fabrics) within the physical fabric.
Tape group—A backup environment in the SAN. This consists of all the tape backup servers and the
tape libraries that they access.
Tape device—A tape drive that is configured for encryption.
Tape volumes—A physical tape cartridge identified by a barcode for a given use.
Tape volume group—A logical set of tape volumes that are configured for a specific use, for
example, a group of tape volumes used to backup a database.
Key Management Center—A component of the Fabric Manager that stores the encryption keys.
Master Key—An encryption key generated when an Cisco SME cluster is created. The master key
encrypts the tape volume keys and tape keys and it is required to decrypt those keys in order to
retrieve encrypted data.
Media Key—A key that is used for encrypting and authenticating the data on specific tapes.
SmartCard—A card (approximately the size of a credit card) with a built-in microprocessor and
memory used for authentication.
Cisco SME Administrator—An administrator who configures Cisco SME. This role includes the
Cisco Storage Administrator role where the administrator manages the storage media encryption
operations and the Cisco SME KMC Administrator role where the administrator is responsible for
the Cisco SME key management operations.
Cisco Storage Administrator —An administrator who manages the storage media encryption
operations.
Cisco SME KMC Administrator—An administrator who is responsible for the Cisco SME key
management operations.
Cisco SME Recovery Officer—A data security officer entrusted with smart cards and the associated
PINs. Each smart card stores a share of the cluster master key. Recovery officers must present their
cards and PINs to recover the key database of a deactivated cluster. A quorum of recovery officers
are required to execute this operation.