IBM DS8000 Encryption for Data at Rest, Transparent Cloud Tiering, and Endpoint Security (DS8000 Release 10.0)

IBM DS8000 Encryption for Data at Rest, Transparent Cloud Tiering, and Endpoint Security (DS8000 Release 10.0)

Auteur : Bert Dufrasne, Gregg Arquero, Rinkesh Bansal, Tony Eriksson, Michael Frankenberg, Peter Kimmel, Aditi Prasad, Andreas Reinhardt, IBM Redbooks

Date de publication : 2025-11-30

Éditeur : IBM Redbooks

Nombre de pages : 262

Résumé du livre

The IBM DS8000® supports encryption-capable drives. They are used with key management services (local or external) to allow encryption for data-at-rest (DAR). The use of encryption technology involves several considerations that are critical for you to understand to maintain the security and accessibility of encrypted data.

This edition of this IBM Redpaper publication focuses on IBM Security® Guardium® Key Lifecycle Manager with the DS8000 Release 10.0 code or later and updated DS GUI for encryption functions.
The DS8000 Release 9.2 code introduced support for local key management for DAR encryption and is described in Chapter 7, “Local key management” on page 229.

Important: Failure to follow the requirements that are described in this publication can result in an encryption deadlock.

The DS8000 system supports Transparent Cloud Tiering (TCT) data object encryption. With TCT encryption, data is encrypted before it is transmitted to the cloud. The data remains encrypted in cloud storage and is decrypted after it is transmitted back to the IBM DS8000.

The DS8000 system also supports Fibre Channel Endpoint Security when communicating with IBM z15® and newer IBM Z® servers, which includes encryption of data that is in-flight, and link authentication.

Connexion / Inscription

Saisissez votre e-mail pour vous connecter ou créer un compte

Connexion

Inscription

Mot de passe oublié ?

Nous allons vous envoyer un message pour vous permettre de vous connecter.