You are on page 1of 2

Datasheet

NetApp Storage
Encryption (NSE)
Full disk encryption that protects data
at rest with no operational impact

The Challenge Interoperability Protocol (KMIP). Only


KEY FEATURES
Encrypt your data without the storage system, drive, and key
Full Disk Encryption getting in the way manager have access to the key, and
• Self-encrypting drives (SED) You work for a government, financial, the drive cannot be unlocked if it is
prevent data access until or healthcare entity and are subject to moved outside of the security domain,
the drive’s encryption key is regulations surrounding data protection. thus preventing data leakage.
unlocked by an authorized The requirement to keep all of the
personally identifiable information, Completely Transparent
administrator NetApp fundamentals supported
personal healthcare information, and
Complete Transparency customer information protected within While higher level SAN and NAS fabric
• Supports storage efficiency: your storage infrastructure becomes encryption solutions provide more flex-
FAS deduplication and a challenge when repurposing drives, ibility, they can also present a challenge
storage compression returning defective drives, or upgrading to everyday operations. Data encrypted
• Supports integrated data to larger drives by selling them or trading before it is sent to the storage module
protection: backup/recovery, them in. Wouldn’t it be nice if there cannot be compressed, deduplicated,
SnapMirror ®, SnapProtect™, were a way for all of your data to or scanned for viruses, and it might
and SnapVault ® be encrypted all of the time without need to be decrypted before it can be
affecting everyday operations? replicated to a backup site or archived
Mandatory Data Encryption to tape.
• File system and network inde- The Solution
pendent: No action is required NetApp Storage Encryption (NSE) Contrast this with NSE, which transpar-
by the operator when aggre- NSE is configured to use self-encrypting ently supports these NetApp® storage
gates, volumes, shares, or drives to facilitate compliance and efficiency features. NSE can help
LUNs are created or deleted, spares return by enabling the protection you lower your overall storage costs,
and your data is always of data at rest, through transparent disk while preventing old data from being
protected encryption. The drives perform all of the accessed if a drive is repurposed.
data encryption operations internally, Set and forget
including encryption key generation. When new volumes, shares, or LUNs are
To prevent unauthorized access to created in storage using network or fabric
the data, the storage system must encryption, the storage administrator
authenticate itself with the drive using needs to determine that encryption is
an authentication key that is established enabled. Not so with NSE. Data encryp-
the first time the drive is used. The tion is always on and is completely
authentication key is backed up to an transparent to any data operations
external key manager using the industry- above the physical disk. Once NSE
standard OASIS Key Management is enabled, it does not matter how
KMIP Server NETAPP STORAGE ENCRYPTION
Encrypts data at rest •
Supports NetApp storage efficiency •
AUTH
Works with NAS encryption •
Works with SAN encryption •
Data ONTAP ® Spares return, repurpose drives without data disclosure •

Table 1) NSE protects disk-based data at rest whether on SAN or NAS, all at wire speed.
AU
TH

DISK

Decrypt

DISK

Figure 1) Schematic diagram


of NSE key wrapping.

your storage is provisioned. Even if If the answer to any of these questions strategy through every phase to
you move the drive from one shelf to is “yes,” then NSE can be combined maximize your return on investment
another or from primary to secondary with NAS or SAN encryption to augment as your business grows.
storage, the data you’ve placed on it your data protection.
is protected from disclosure. Supported Storage Modules
Combine encryption for defense • FAS2040
Industry standard means in depth
• FAS3200 series
no disk left behind If you need to segregate access to • FAS6200 series
Because NSE uses the new cross- data as well as make sure that data • DS4243 with 600GB NSE drives
platform industry-standard Key is protected all of the time, NSE can
Management Interoperability Protocol, be combined with network- or fabric-
you can use our solution with any level encryption. NSE can act like a About NetApp
compatible key manager now and backstop in case an administrator NetApp creates innovative storage
in the future. forgets to configure or misconfigures and data management solutions that
higher level encryption. deliver outstanding cost efficiency and
Do I Need More than NSE?
accelerate business breakthroughs.
Some questions to ask yourself Get Exceptional Enterprise Service
Discover our passion for helping
• Do you need to encrypt data on tape? and Support
companies around the world go
• Does data need to be encrypted Like all of our products, NSE comes further, faster at www.netapp.com.
on the SAN or NAS network? with NetApp’s world-class service and
• Do you need to segregate user support infrastructure and longtime Go further, faster ®

data at a granular level? industry expertise. We deliver global


• Do you need to encrypt data enterprise-class services, support, and
before storing it in the cloud? consulting to help you plan, evaluate,
• Are you a cloud vendor that needs to and implement your storage security
keep multi-tenant data segregated?

© 2011 NetApp, Inc. All rights reserved. No portions of this document may be reproduced without prior written consent of NetApp, Inc.
Specifications are subject to change without notice. NetApp, the NetApp logo, Go further, faster, Data ONTAP, SnapMirror, SnapProtect,
and SnapVault are trademarks or registered trademarks of NetApp, Inc. in the United States and/or other countries. All other brands or
products are trademarks or registered trademarks of their respective holders and should be treated as such. DS-3213-1211

www.netapp.com

You might also like