HP StoreOnce 4430 HP StoreOnce Backup System Concepts and Configuration Guidel - Page 12

Security Features, Types of licensing, Data at Rest Encryption, Secure erase

Page 12 highlights

Types of licensing There are two types of licensing: • Full license (not time limited) • Instant on (time limited to 90 days): This allows you to try out licensable functionality on StoreOnce hardware products before paying for a full license for features such as Replication Target, Catalyst, or the Security features of Data at Rest Encryption and Secure Erase. For more information on applying this type of license, see the HP StoreOnce backup system Installation and Configuration guide and the HP StoreOnce Backup system CLI Reference Guide. Security Features The HP StoreOnce backup system offers two security features that can be applied using a Security license: Data at Rest Encryption and Secure Erase. Data at Rest Encryption When enabled, the Data at Rest Encryption security feature protects data at rest on a stolen, discarded, or replaced disk from forensic attack. Data encryption is only available on Catalyst and VTL devices. When you create a new store or library (VTL or Catalyst), you have the option to enable encryption if the security features license has already been applied. Once enabled, encryption will automatically be performed on the data before it is written to disk. Encryption cannot be disabled once it has been set for a library or Catalyst store. When you create an encrypted store or library, the key store is updated with the encryption key. This keystore may be backed up and saved securely offsite in case the original key store is corrupted. However, be sure to keep only the latest version of the key store as a backup; the key store on the StoreOnce Backup system is updated each time you create a library or Catalyst store. The StoreOnce CLI command that backs up the key store also encrypts it, ensuring that it can only be decrypted by the HP StoreOnce backup system, should you need to restore it. Be very diligent about backing up your keystore if you are creating encrypted stores or libraries! See the HP StoreOnce Backup system CLI Reference Guide for more information about the StoreOnce CLI commands for backing up and restoring key stores. NOTE: Each library or Catalysts store configured will use a different key. The StoreOnce software automatically tracks which key is relevant to which device in the Key Store File. Keys are automatically re-applied to the right device if the key store file is restored. IMPORTANT: B6200 systems: Every time that you expand storage by adding a couplet, you will need to restore your keystore. Installing the additional couplet is an HP Support task, but you are responsible for ensuring that a Security license has been installed for the new couplet and saving the existing keystore. Secure erase Secure Erase can be enabled for all store types. When enabled, this feature allows you to securely erase data that has been backed up as part of a regular backup job. The Secure Erase feature can only be enabled after store or library creation (edit the store or library to enable Secure Erase). All data written to disk once secure erase is enabled will be securely erased upon data deletion. For example, you may have unintentionally backed up confidential data and need to be sure that it has been securely erased. You must work with your backup application to trigger the secure erase, for example by forcing a format of a cartridge. The backup application sends the request to delete the data and the deletion is carried out as part of the Housekeeping function. 12 Before you start

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122

Types of licensing
There are two types of licensing:
Full license (not time limited)
Instant on (time limited to 90 days): This allows you to try out licensable functionality on
StoreOnce hardware products before paying for a full license for features such as Replication
Target, Catalyst, or the Security features of Data at Rest Encryption and Secure Erase. For
more information on applying this type of license, see the
HP StoreOnce backup system
Installation and Configuration guide
and the
HP StoreOnce Backup system CLI Reference
Guide
.
Security Features
The HP StoreOnce backup system offers two security features that can be applied using a Security
license: Data at Rest Encryption and Secure Erase.
Data at Rest Encryption
When enabled, the Data at Rest Encryption security feature protects data at rest on a stolen,
discarded, or replaced disk from forensic attack. Data encryption is only available on Catalyst
and VTL devices.
When you create a new store or library (VTL or Catalyst), you have the option to enable encryption
if the security features license has already been applied. Once enabled, encryption will automatically
be performed on the data before it is written to disk. Encryption cannot be disabled once it has
been set for a library or Catalyst store.
When you create an encrypted store or library, the key store is updated with the encryption key.
This keystore may be backed up and saved securely offsite in case the original key store is corrupted.
However, be sure to keep only the latest version of the key store as a backup; the key store on the
StoreOnce Backup system is updated each time you create a library or Catalyst store. The StoreOnce
CLI command that backs up the key store also encrypts it, ensuring that it can only be decrypted
by the HP StoreOnce backup system, should you need to restore it. Be very diligent about backing
up your keystore if you are creating encrypted stores or libraries! See the
HP StoreOnce Backup
system CLI Reference Guide
for more information about the StoreOnce CLI commands for backing
up and restoring key stores.
NOTE:
Each library or Catalysts store configured will use a different key. The StoreOnce software
automatically tracks which key is relevant to which device in the Key Store File. Keys are
automatically re-applied to the right device if the key store file is restored.
IMPORTANT:
B6200 systems: Every time that you expand storage by adding a couplet, you will
need to restore your keystore. Installing the additional couplet is an HP Support task, but you are
responsible for ensuring that a Security license has been installed for the new couplet and saving
the existing keystore.
Secure erase
Secure Erase can be enabled for all store types. When enabled, this feature allows you to securely
erase data that has been backed up as part of a regular backup job. The Secure Erase feature
can only be enabled after store or library creation (edit the store or library to enable Secure Erase).
All data written to disk once secure erase is enabled will be securely erased upon data deletion.
For example, you may have unintentionally backed up confidential data and need to be sure that
it has been securely erased. You must work with your backup application to trigger the secure
erase, for example by forcing a format of a cartridge. The backup application sends the request
to delete the data and the deletion is carried out as part of the Housekeeping function.
12
Before you start