The IBM Tivoli Key Lifecycle Manager implements a key server application and
integrates with certain IBM storage products. It is software developed by IBM for
managing keys securely for encrypting hardware devices such as disk and tape.
The Tivoli Key Lifecycle Manager server is available as a DS8000 hardware feature
code 1760. This feature provides the Tivoli Key Lifecycle Manager server that is
required for use with the Tivoli Key Lifecycle Manager software. For more
information, see “IBM Tivoli Key Lifecycle Manager server” on page 73.
The Tivoli Key Lifecycle Manager can be installed on a set of servers to implement
a set of redundant key servers. Encryption capable storage devices that require key
services from the key server are configured to communicate with one or more key
servers and the key servers are configured to define the devices to which they are
allowed to communicate.
The Tivoli Key Lifecycle Manager supports two key serving methods. The method
that is used by the DS8000 is referred to as the wrapped key method. In the
wrapped key method, the configuration processes on the Tivoli Key Lifecycle
Manager and storage device define one or more key labels. A
key label
is a
user-specified text string that is associated with the asymmetric key pair that Tivoli
Key Lifecycle Manager generates when the key label is configured. In the wrapped
key method, there are basically two functions that an encryption capable storage
device can initiate to a Tivoli Key Lifecycle Manager key server:
Request a new data key
The storage device requests a new data key for one or two specified key
labels. The Tivoli Key Lifecycle Manager key server provides one or two
properly generated data keys to the storage device in two forms:
Externally Encrypted Data Key
Tivoli Key Lifecycle Manager maintains a public and private key
pair for each key label. Tivoli Key Lifecycle Manager keeps the
private key a secret. The data key is wrapped with the key label
public key and is stored in a structure that is referred to as the
externally encrypted data key (EEDK). This structure also contains
sufficient information to determine the key label associated with
the EEDK. One EEDK is sent for each key label.
Session Encrypted Data Key
The storage device generates a public and private key pair for
communicating with the Tivoli Key Lifecycle Manager and
provides the public key to the Tivoli Key Lifecycle Manager. The
storage device keeps the private key a secret. The data key is
wrapped with the public key of the storage device and is stored in
a structure called the session encrypted data key (SEDK).
Each EEDK is persistently stored by the storage device for future use. The
SEDK is decrypted by the storage device using the private key of the
storage device to obtain the data key. The data key is then used to
symmetrically encrypt and decrypt either data or the other subordinate
data keys that are required to encrypt, decrypt, or gain access to the data.
Unwrap an existing data key
The storage device requests that Tivoli Key Lifecycle Manager unwrap an
existing wrapped data key by sending the request to the Tivoli Key
Lifecycle Manager instance with all of the EEDKs and the public key of the
storage device. The Tivoli Key Lifecycle Manager key server receives each
EEDK, unwraps the data key with the private key for the key label to
72
Introduction and Planning Guide
Содержание DS8700
Страница 1: ...IBM System Storage DS8800 and DS8700 Version 6 Release 3 Introduction and Planning Guide GC27 2297 09...
Страница 2: ......
Страница 3: ...IBM System Storage DS8800 and DS8700 Version 6 Release 3 Introduction and Planning Guide GC27 2297 09...
Страница 8: ...vi Introduction and Planning Guide...
Страница 10: ...viii Introduction and Planning Guide...
Страница 20: ...xviii Introduction and Planning Guide...
Страница 22: ...xx Introduction and Planning Guide...
Страница 44: ...22 Introduction and Planning Guide...
Страница 142: ...120 Introduction and Planning Guide...
Страница 160: ...138 Introduction and Planning Guide...
Страница 212: ...190 Introduction and Planning Guide...
Страница 218: ...196 Introduction and Planning Guide...
Страница 224: ...202 Introduction and Planning Guide...
Страница 242: ...220 Introduction and Planning Guide...
Страница 254: ...232 Introduction and Planning Guide...
Страница 255: ......
Страница 256: ...Printed in USA GC27 2297 09...