Page 1
Dell PS Series Architecture: Self Encrypting Drive Management with PS Series Storage Arrays Dell Storage Engineering February 2017 A Dell EMC Technical White Paper
Page 2
Revisions Date Description May 2013 Initial release February 2017 Updated to reflect industry changes The information in this publication is provided “as is.” Dell Inc. makes no representations or war...
Page 3
Table of Contents 1 Introduction ................................................................................................................................................................... 4 2...
Page 4
Executive summary Data and intellectual property are the life blood for a company in the modern information driven economy. Although a considerable amount of money and effort has been spent towards pr...
Page 5
1 Introduction Whether it is sensitive customer information, intellectual property or proprietary data that helps a company reach its strategic objectives, company data is often its most valuable asse...
Page 6
The emergence of full disk encryption technology and SEDs is timely in mitigating the security vulnerabilities of data at rest. SEDs are also becoming a standardized technology across many top drive v...
Page 7
2 SED technology overview An SED is a self-encrypting hard drive with encryption and decryption functions built into the disk drive controller chip that encrypts all data written to the media and auto...
Page 8
Accessing data on a SED 1. Data is requested from the self-encrypting drive by the storage subsystem. The storage subsystem sends its access key (AK) to the drive electronics. 2. The drive electronics...
Page 9
2.2 Instant Secure Erase Another security method available with SEDs is Instant Secure Erase (ISE). Alternative methods, such as degaussing each drive or simply overwriting the data with zeros, are av...
Page 10
3 Securing data with SED technology on PS Series arrays As the leader in storage technologies, Dell EMC provides support and management capabilities that allow users to safely secure their data-at-res...
Page 11
Reuse of a drive from another array (The drive will be initially marked as a foreign drive ISE is invoked and the drive is converted to a spare after the administrator confirms that the drive should...
Page 12
Insider attack. Any person who possesses the administrator password can access any volume on the array, or change ACLs to allow others to do the same. Similarly, a compromised host can access volume...
Page 13
4 Summary As demonstrated, Auto SED technology and PS Series arrays provide a robust data-at-rest security solution. This solution further ensures that the provided enterprise level data security is e...
Page 14
A PS Series SED storage procedures A.1 Backing up the access key using the PS Series Group Manager GUI The Auto SED machinery is very robust and remains functional even when severe failures have taken...
Page 15
3. Copy the long string (130 hexadecimal characters) from the file and paste it onto the command line after the keyd command. The first 56 characters, the header, is the same for all three pieces. You...
Page 16
B Frequently Asked Questions Why are my key backups always different? Although the encryption key never changes, the backup will look different each time it is generated. The three backup units are cr...
Page 17
No. Every drive in the member has been securely erased. The data has been cryptographically destroyed. Recovery is impossible. What if the entire array is stolen? Security is compromised. The array wi...
Page 18
C Key terms and glossary Key terms Location and Term Definition and usage How it is generated management Media Required to encrypt and Resides on & managed Generated by the drive at Encryption Key...
Page 19
D Technical Support and resources Dell.com/support is focused on meeting customer needs with proven services and support. Dell Tech Center is an online technical community where IT professionals have ...