HP StorageWorks 4000/6000/8000 .HP StorageWorks SAN Design Reference Guide, Pa - Page 410

B-series Encryption Switch and Encryption FC Blade security, CHAP authentication, Features

Page 410 highlights

• Data confidentiality-Packets are encrypted by the sending device before transmitting them over the network. • Data integrity-Packets are authenticated by the receiving device to ensure that data has not been altered during transmission. • Data-origin authentication-The packet source can be authenticated by the receiving device. • Anti-replay protection-Replayed packets can be detected and rejected by the IPsec receiver. CHAP authentication C-series IP modules support CHAP, which uses a three-way handshake to ensure that validity of remote clients. C-series CHAP requires that you configure a password. which the switch presents to the iSCSI initiator. This password is used to calculate a CHAP response to a CHAP challenge sent to the IP port by the initiator. B-series Encryption Switch and Encryption FC Blade security This section describes the security features for the B-series Encryption Switch and Encryption FC Blade. For switch models and fabric rules, see "B-series switches and fabric rules" on page 93. The B-series Encryption Switch is a high-performance, 32-port autosensing 8 Gb/s Fibre Channel switch with data encryption/decryption and data compression capabilities. The switch is a network-based solution that secures data-at-rest for disk array LUNs using IEEE standard AES 256-bit algorithms. Encryption and decryption engines provide in-line encryption services with up to 96 Gb/s throughput for disk I/O (mix of ciphertext and cleartext traffic). For details on the B-series Encryption Switch, including deployment scenarios, see the Fabric OS Encryption Administrator's Guide available at http://h18006.www1.hp.com/storage/ saninfrastructure/switches/encrypt_sanswitch.html. NOTE: HP does not currently support the tape encryption features of the B-series Encryption Switch and Encryption FC Blade. Features • High-performance, scalable fabric-based encryption to enforce data confidentiality and privacy requirements • Unparalleled encryption processing at up to 96 Gb/s to support heterogeneous enterprise data centers • Integration with HP Secure Key Manager, providing secure and automated key sharing between multiple sites to ensure transparent access to encrypted data • Industry-standard AES 256-bit encryption algorithms for disk arrays on a single security platform for SAN environments • Frame Redirection technology that enables easy, nonintrusive deployment of fabric-based security services • Plug-in encryption services available to all heterogeneous servers, including virtual machines, in data center fabrics • Scalable performance with on-demand encryption processing power to meet regulatory mandates for protecting data 410 Storage security

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456

Data confidentiality
Packets are encrypted by the sending device before transmitting them over
the network.
Data integrity
Packets are authenticated by the receiving device to ensure that data has not been
altered during transmission.
Data-origin authentication
The packet source can be authenticated by the receiving device.
Anti-replay protection
Replayed packets can be detected and rejected by the IPsec receiver.
CHAP authentication
C-series IP modules support CHAP, which uses a three-way handshake to ensure that validity of remote
clients. C-series CHAP requires that you configure a password. which the switch presents to the iSCSI
initiator. This password is used to calculate a CHAP response to a CHAP challenge sent to the IP port
by the initiator.
B-series Encryption Switch and Encryption FC Blade security
This section describes the security features for the B-series Encryption Switch and Encryption FC Blade.
For switch models and fabric rules, see
B-series switches and fabric rules
on page 93.
The B-series Encryption Switch is a high-performance, 32-port autosensing 8 Gb/s Fibre Channel
switch with data encryption/decryption and data compression capabilities. The switch is a
network-based solution that secures data-at-rest for disk array LUNs using IEEE standard AES 256-bit
algorithms. Encryption and decryption engines provide in-line encryption services with up to 96 Gb/s
throughput for disk I/O (mix of ciphertext and cleartext traffic).
For details on the B-series Encryption Switch, including deployment scenarios, see the
Fabric OS
Encryption Administrator's Guide
available at
h
t
tp://h18
006
.w
w
w1.hp
.co
m/s
t
o
r
age/
s
aninf
r
a
s
tr
u
c
tur
e/s
w
it
c
he
s/e
nc
r
y
pt_s
ans
w
it
c
h
.h
tml
.
NOTE:
HP does not currently support the tape encryption features of the B-series Encryption Switch and
Encryption FC Blade.
Features
High-performance, scalable fabric-based encryption to enforce data confidentiality and privacy
requirements
Unparalleled encryption processing at up to 96 Gb/s to support heterogeneous enterprise data
centers
Integration with HP Secure Key Manager, providing secure and automated key sharing between
multiple sites to ensure transparent access to encrypted data
Industry-standard AES 256-bit encryption algorithms for disk arrays on a single security platform
for SAN environments
Frame Redirection technology that enables easy, nonintrusive deployment of fabric-based security
services
Plug-in encryption services available to all heterogeneous servers, including virtual machines, in
data center fabrics
Scalable performance with on-demand encryption processing power to meet regulatory mandates
for protecting data
Storage security
410