538
IBM z13s Technical Guide
Figure H-7 Key serving topology
H.3.3 Error recovery scenarios
Possible error scenarios are described in this section.
Primary Support Element failure
When the primary SE fails, a switch is made to the alternate SE, which then becomes the new
primary. When the former primary is brought back up, it becomes the alternate SE. The KEK
and the Flash encryption key/authentication key from the primary SE were already sent to the
alternate SE for redundancy at initialization time.
Removal of a smart card
If a smart card is removed from the card reader, the card reader signals the event to the IKC
listening code. The IKC listener then calls the SE to take the appropriate action. The
appropriate action can involve deleting the flash encryption key or authentication key file.
If the smart card is removed while the SE is powered off, the system has no knowledge of the
event. However, when the SE is powered on, notification is sent to the system administrator.
Primary Support Element failure during IML serving of the flash key
If the primary SE fails during the serving of the key, the alternate SE takes over as the primary
and restarts the key serving operation.
Alternate Support Element failure during switchover from the primary
If the alternate SE fails during the switchover to become the primary SE, the key serving state
is lost. When the primary comes back up, the key serving operation can be restarted.
Support Element (SE)
SE
Hard Disk
Integrated
Key
Controller
Keys Generated in the Smart Card
RSA Public Key
AES Flash Encryption Key /
Authentication Key
RSA Public Key
AES Key-Encrypting Key
Firmware Public Key
AES Flash
Encryption Key /
Authentication Key
AES Flash
Encryption Key /
Authentication Key
Firmware Management of the
Flash Express Adapter
Private Key
Flash Encryption Key /
Authentication Key
Firmware RSA Key Pair
Public Key
Private Key
HSA
Flash Encryption Key /
Authentication Key
Flash
Содержание z13s
Страница 2: ......
Страница 3: ...International Technical Support Organization IBM z13s Technical Guide June 2016 SG24 8294 00 ...
Страница 24: ...THIS PAGE INTENTIONALLY LEFT BLANK ...
Страница 164: ...136 IBM z13s Technical Guide ...
Страница 226: ...198 IBM z13s Technical Guide ...
Страница 256: ...228 IBM z13s Technical Guide ...
Страница 414: ...386 IBM z13s Technical Guide ...
Страница 464: ...436 IBM z13s Technical Guide ...
Страница 476: ...448 IBM z13s Technical Guide ...
Страница 498: ...470 IBM z13s Technical Guide ...
Страница 502: ...474 IBM z13s Technical Guide ...
Страница 568: ...540 IBM z13s Technical Guide ...
Страница 578: ...550 IBM z13s Technical Guide ...
Страница 584: ...556 IBM z13s Technical Guide ...
Страница 585: ...ISBN 0738441678 SG24 8294 00 1 0 spine 0 875 1 498 460 788 pages IBM z13s Technical Guide ...
Страница 586: ......
Страница 587: ......
Страница 588: ...ibm com redbooks Printed in U S A Back cover ISBN 0738441678 SG24 8294 00 ...