contents
 Overview      Standard Features      Product Highlights      Service and Support, HP Care Pack, and Warranty Information      Kit Contents      Related Options      Configuration Information      Technical Specifications line.gif (50 bytes)

Overview

HP StorageWorks Secure Key Manager

 

The HP StorageWorks Secure Key Manager reduces your risk of a costly data breach and reputation damage while improving regulatory compliance with a secure centralized encryption key management solution for HP LTO4 enterprise tape libraries. The Secure Key Manager automates key generation and management based on security policies for multiple libraries. This occurs transparent to ISV backup applications. The Secure Key Manager is a hardened server appliance delivering secure identity-based access, administration and logging with strong auditable security designed to meet the rigorous FIPS 140-2 security standards. Additionally, the Secure Key Manager provides reliable lifetime key archival with automatic multi-site key replication, high availability clustering and failover capabilities.

The HP StorageWorks Secure Key Manager provides centralized key management for HP StorageWorks Enterprise Storage Libraries (ESL) E-Series Tape Libraries and HP StorageWorks Enterprise Modular Library (EML) E-Series Tape Libraries. In addition to the clustering capability, the Secure Key Manager provides comprehensive backup and restore functionality for keys, as well as redundant device components and active alerts. The Secure Key Manager supports policy granularity ranging from a key per library partition to a key per tape cartridge while featuring an open extensible architecture for emerging standards and allowing additional client types in the future needing key management services. These clients may include other storage devices, switches, operating systems and applications. Keep your confidential data secure yet highly available with automated single point of management for your encryption keys using the HP Secure Key Manager, a member of the "HP Secure Advantage" portfolio.

 
HP StorageWorks Secure Key Manager node

Models
HP StorageWorks Secure Key Manager Models HP StorageWorks Secure Key Manager System
AJ086A
HP StorageWorks Secure Key Manager Expansion Module
AJ087A
NOTE: ETLA tape libraries are purchased separately (ESL and EML)
NOTE: To verify EML support timing on Secure Key Manager please check http://www.hp.com/go/ebs.
 
contents
 Overview      Standard Features      Product Highlights      Service and Support, HP Care Pack, and Warranty Information      Kit Contents      Related Options      Configuration Information      Technical Specifications line.gif (50 bytes)

Standard Features

Secure Key Manager Customer benefits
  • Enables effective privacy of data
  • Reduced complexity and effort to manage encrypted data
  • Verification for compliance and audit
  • High availability of archived keys for long term rapid access

Key Features
  • Centralized encryption key management for HP LTO4 enterprise tape libraries
    • Automatic policy-based key generation and management supporting key/cartridge granularity
    • ISV transparent key archival and retrieval for multiple libraries
    • Extensible to emerging open standards
  • Strong auditable security for encryption keys
    • Hardened server appliance
    • Secure identity-based access, administration and logging
    • Designed for FIPS 140-2 validation
  • Reliable lifetime key archival
    • Automatic multi-site clustering, key replication and failover
    • Comprehensive backup and restore functionality for keys
    • Redundant device components and active alerts
contents
 Overview      Standard Features      Product Highlights      Service and Support, HP Care Pack, and Warranty Information      Kit Contents      Related Options      Configuration Information      Technical Specifications line.gif (50 bytes)

Product Highlights

Mitigate data breach risk

Mitigate your risk of data exposure. Keep your tape encrypted data private and protect the company reputation with Secure Key Manager while improving regulatory compliance and avoiding financial consequences of a breach. Proactively avoid situations requiring disclosure of unauthorized access to unencrypted private information.


Centralized automated key management

The Secure Key Manager reduces the complexity of managing encryption keys across a distributed infrastructure with a single point of management. Independent of tape drive count, Secure Key Manager supports multiple ESL/EML LTO4 tape libraries per node further boosting investment protection. Secure Key Manager cluster nodes and key management clients may be deployed at different geographic sites; only network connectivity is required.


Extensible to emerging open standards

The Secure Key Manager architecture and plans support future encryption clients beyond HP ESL and EML tape libraries. It is the platform HP is using to build infrastructure-wide centralized key management for information protection across the enterprise.


Strong auditable security The Secure Key Manager features a closed Linux kernel, dual locking bezel with durable pick-resistant locks and tamper-evident enclosure seals to provide platform security substantially beyond a general- purpose server key repository.
The Secure Key Manager also provides a trusted infrastructure for enforcement of internal security policies/controls and a trusted audit trail of encryption and key management activities as evidence for compliance and audit verifications. This product is appropriate for stringent cryptographic installations and supports AES-256 key generation. FIPS 140-2 Level 2 security validation is pending. The Federal Information Processing Standard (FIPS) Publication 140-2 is a U.S. government standard used to validate cryptographic modules.

Reliable lifetime key archival High availability and reliability are paramount because keys must be retained for the life of the data which may be for decades. The Secure Key Manager delivers high availability of archived keys for same or multi-site coverage. Key replication and failover occurs automatically in a clustered configuration.
For improved overall hardware reliability, the Secure Key Manager has redundant dual fans, power supplies and disk drives with RAID 1 (mirroring). It also features active alerts and health checks to maximize uptime.

OS Support The Secure Key Manager is a dedicated, hardened server with a closed Linux kernel supporting the key management operations. The Secure Key Manager interfaces with its clients via secure Ethernet communications.

Backup Software Support and Compatibility

Minimize impact to existing backup and recovery processes. With Secure Key Manager, LTO-4 library key management and data encryption operations occur transparent to backup application. The data can be decrypted on any Secure Key Manager library client that has permission to access the key. Note that the LTO-4 drives require backup application ISV support. Check the EBS matrix and/or go-connect for support information for the LTO-4 drive.
http://www.hp.com/go/EBS
http://www.hp.com/go/connect

contents
 Overview      Standard Features      Product Highlights      Service and Support, HP Care Pack, and Warranty Information      Kit Contents      Related Options      Configuration Information      Technical Specifications line.gif (50 bytes)

Service and Support, HP Care Pack, and Warranty Information

Warranty

HP Care Pack Services offer upgraded service levels to extend and expand your standard product warranty with easy to buy, easy to use support packages that help you make the most of your hardware and software investments. They let you choose the support levels that meet your business requirements, from basic to mission-critical. They help you contain total cost of ownership.

HP Care Pack warranty extensions can be purchased along with HP products to cost-effectively upgrade or extend your warranty. For many products, post-warranty HP Care Pack Services are available when your original warranty has expired.

Why purchase an HP Care Pack service?

Your standard warranty protects against product defects. HP Care Pack Services help you guard against unplanned downtime, which can reduce your productivity and profitability. These convenient service packages:

  • Protect your investment in HP products
  • Provide consistent, predictable levels of support across your entire department or business
  • Ease budget planning with fixed-cost support that includes parts and labor
  • Give you direct access to proven technical and problem-solving expertise
  • Offer a choice of response-time and repair-time commitments
  • Deliver prompt, measurable results
  • Are available whenever and wherever you do business

HP Care Pack availability may vary by country and product.

Supporting your Adaptive Enterprise journey

HP Services helps you make the Adaptive Enterprise real for your organization. The breadth, depth, and quality of HP hardware and software support services can help you improve the performance of your IT support processes and resolve the complex software and hardware problems that tax user productivity. HP Care Pack services help you increase IT environment stability, efficiency, and agility from the desktop to the data center, and improve the productivity of your employees.


Warranty and Services Included with the Product Hewlett-Packard provides a 1-year, next-day, on-site, limited warranty for the HP StorageWorks Security Key Manager hardware, plus 9x5 phone support for the duration of the warranty.
For more information about HP's Global Limited Warranty and Technical Support, visit: http://h18006.www1.hp.com/products/storageworks/warranty.html

Recommended Services

In order to maximize ROI and product uptime, and minimize the cost of ownership, Hewlett Packard recommends:

3 years 24 x 7 Hardware Support

  • Guards against downtime, which reduces productivity and profitability
  • Eases budget planning with fixed-cost support that includes parts and labor
    Direct access to proven technical and problem-solving expertise

Installation Services via HP Direct    
Description
Band
Care Pack
HP StorageWorks Security Key Manager System (AJ086A)
HP Custom Storage deployment SVC (SOW)
None
HA546A1
HP StorageWorks Security Key Manager Expansion Module (AJ087A)
HP Custom Storage deployment SVC (SOW)
None
HA546A1
NOTE: If the additional system is to be configured at a different site the customer must purchase an additional instance of HA546A1
NOTE: New system node must include HP Custom Storage deployment SVC (SOW) (HA546A1)
NOTE: Tape library must be at the current supported level including the latest ETLA firmware, patches and software updates etc to support HP Secure Key Manager. Consult http://www.hp.com/go/EBS for the minimum revision numbers required

Description

Care Pack

HW, "3-year", "next-day", "13x5", "on-site"
HA101A3
HW, "3-year", "4-hour", "13x5", "on-site"
HA103A3
HW, "3-year", "4-hour", "24x7", "on-site"
HA104A3
HW, "3-year", "6hr CTR", "24x7", "on-site"*
HA105A3
HW Only, Support Plus, "3-year", "13x5"**
HA109A3
HW Only Support Plus 24, "3-year", "24x7"**
HA110A3
HW Only, Proactive 24, "3-year", "24x7"***
HA111A3
HW Only, Critical Service, "3-year", "24x7"***
HA112A3

* 6hr CTR 'standalone' service is not offered in Latin or North America.
** Support Plus covers 4hr Hardware response (Software support is not applicable).
*** Both Proactive 24 & Critical Service only relate to 'reactive elements', work is ongoing to offer the 'proactive elements' in the near future (Software support is not applicable).

The HP Care Pack information quoted above relates to 3 year offerings only, 1yr, 4yr and 5yr packs are available for each offering (replace A3 with A1, A4, A5 respectively).

In order to maximize ROI and product uptime, and minimize the cost of ownership, Hewlett Packard recommends the 3-year, 24x7 service options. These offerings will ensure that any product issue can be tackled when they occur (most back up issues will occur outside standard business hours) and that the service coverage regarding period, covers the minimum expected life of the host system.

To find HP Care Pack Services available via HP authorized commercial resellers, visit http://h30125.www3.hp.com/csn/salesmktg/elfpack/elf_nonlkup_ctrylang.asp?code=ELNL

contents
 Overview      Standard Features      Product Highlights      Service and Support, HP Care Pack, and Warranty Information      Kit Contents      Related Options      Configuration Information      Technical Specifications line.gif (50 bytes)

Kit Contents

Model Description
Part Number
HP StorageWorks Secure Key Manager System HP StorageWorks Secure Key Manager Two Node Cluster
AJ086A
Supplied with each Secure Key Manager Two Node Cluster  
  • Two HP StorageWorks Secure Key Manager nodes
  • Pick-resistant dual-locking bezel
  • Redundant power supplies per node
  • 10 total client licenses
  • HP Secure Key Manager Documentation CD

NOTE: This SKU is used to configure a 2 node cluster for high availability of the keys. The capacity is 100,000 keys.

 
HP StorageWorks Secure Key Manager Expansion Module HP StorageWorks Secure Key Manager Expansion Module
AJ087A
Supplied with each Secure Key Manager Expansion Module
 
  • One HP StorageWorks Secure Key Manager node
  • Pick-resistant dual-locking bezel
  • Redundant power supplies
  • 5 additional client licenses
  • HP Secure Key Manager Documentation CD

NOTE: This SKU is used to expand a cluster with 5 more licenses. The maximum key count will not increase with additional expansion modules because the cluster nodes share the keys. This SKU can be used to expand a single-site cluster into a multi-site cluster.

 
contents
 Overview      Standard Features      Product Highlights      Service and Support, HP Care Pack, and Warranty Information      Kit Contents      Related Options      Configuration Information      Technical Specifications line.gif (50 bytes)

Related Options

HP StorageWorks Enterprise Class Libraries ESL and EML tape libraries
For details please visit http://www.hp.com/go/tape

LTO-4 Encryption HP StorageWorks LTO-4 Ultrium 1840 tape drives
For details please visit http://h18006.www1.hp.com/products/storageworks/lto4Encryp/index.html

HP Compliance Log Warehouse (Optional) For additional compliance reporting capability consider the HP Compliance Log Warehouse (CLW) to transform security and compliance log event data into information.

By understanding the detailed event data that IT systems already produce, organizations can better manage, investigate, and protect these systems. HP CLW collects and analyzes data such as system and application log files, database event records, and operating system event logs. With powerful compliance reporting tools, it turns this data into actionable intelligence, providing rapid time-to-value at a fraction of the cost of traditional data warehousing and security solutions.

Visit http://www.hp.com/go/clw to verify log adaptor support options for HP Secure Key Manager


Power Cords
(for connection to standard wall outlets)

Power Cord, C13-Nema 5-15P
AF556A
NOTE: Each Secure Key Manager node ships with redundant power supplies and two (2) IEC-IEC power cords intended for rack mounting with Power Distribution Units (PDUs) and/or Uninterruptible Power Systems (UPS) for highest availability. Alternatively, each Secure Key Manager mode may be powered using two (2) optional power cords connecting to two separate wall receptacles provided on separate branch circuits and mains for highest availability. Two (2) such optional power cords must be ordered for each Secure Key Manager node.  
contents
 Overview      Standard Features      Product Highlights      Service and Support, HP Care Pack, and Warranty Information      Kit Contents      Related Options      Configuration Information      Technical Specifications line.gif (50 bytes)

Configuration Information

NOTE: Only rack-mount units are available
Step 1 – Select a Configuration
  HP StorageWorks Secure Key Manager System
AJ086A

Step 2 – Add additional cluster nodes to enable additional licenses (optional)
  HP StorageWorks Secure Key Manager Expansion Module
AJ087A

Step 3 - Select appropriate clients -- HP Enterprise Tape Library (optional)

NOTE: New or exiting tape library must be at the current supported level including the latest ETLA firmware, patches and software updates etc to support HP Secure Key Manager. Consult http://www.hp.com/go/ebs for the minimum revision numbers required
NOTE: Each ESL/EML E-Series Tape Library in the solution requires at least one LTO4 encrypting tape drive, LTO4 media and an ETLA Secure Manager License (343376-B21 or T3664A).


Step 4 - Select appropriate Services/Support
  • Choose required Installation and Startup service. This Statement of Work service requires a FAN override for removal. (More information on SOW in service section.)
  • Choose support uplift type. There are different service uplifts uplifting years of service, hours of availability and response time. HP recommends three year 24X7 support uplifts. (Details of specific part numbers in service section.)
  • Consider Consulting and Integration enterprise security services http://www.hp.com/hps/security

Application Overview

 
Using the HP StorageWorks Secure Key Manager

This section summarizes the usage and applications of the HP StorageWorks Secure Key Manager.

1. Installing and configuring the Secure Key Manager
  • Define your security policies and the roles for those who will administer the devices. For example, the security policies on the Secure Key Manager may be administered by a Security Officer. This role might direct security policy across all your storage products, not just tape. It is not necessary that this role overlap with existing roles, such as the Tape Library Administrator. The Secure Key Manager and the ETLA libraries that use it, both support the separation of roles, with each having separate logins and credentials.
  • Determine which tape libraries and drives will be used for encryption. You can configure keys to be shared among all libraries or restricted. Configure the key generation policies that best fit your business needs (key per cartridge or key per library/partition).
  • Setup the Secure Key Manager cluster. The cluster can span multiple sites if necessary.
  • Configure the ETLA tape libraries that will use the Secure Key Manager. The supported HP tape libraries are ESL and EML (confirm at http://www.hp.com/go/ebs). The configuration process is guided by a wizard in the tape library CommandView GUI. You can also use this wizard to modify the configuration later. NOTE: An Advanced Secure Manager license is required for each ETLA library that will use the Secure Key Manager.
2. Encrypting your data backups and decrypting your restored data
  • Each partition of each library may have a separate key generation policy. The library will automatically retrieve keys from the Secure Key Manager and transmit these keys to the HP LTO4 drives.
  • These operations are transparent to the backup software and therefore do not affect your existing backup / restore processes.
  • When a tape is written for the first time, the library obtains a key based on the key generation policy you established for it. The keys are assigned unique names, based on a media ID, the barcode value, and a timestamp.
  • When a tape is read, the library retrieves the key from the Secure Key Manager. If the tape is moved to a different library before it is read, the two libraries must be part of the same security group so the key can be shared. Security groups are easily configured at the Secure Key Manager GUI.
  • Keys are passed between the library and the Secure Key Manager via an SSL connection. This is more secure than using a backup application and the SAN where keys are passed in the clear.
  • Encrypted media may be re-used using a different key.
3. Backing up keys, logs, and configuration data
  • All the nodes of a Secure Key Manager cluster will continuously replicate, so all keys are stored on and available from each node. If a node fails, the other nodes continue to operate, and will serve keys to the tape libraries without interruption.
  • You can also periodically backup all the keys, logs and node configurations on each node. These backups are typically stored on a server in your network. These backup files are encrypted and can only be restored to a Secure Key Manager.
  • The Secure Key Manager will support multiple libraries. Each node in the cluster can support 5 HP ETLA tape libraries, so a 2-node cluster will support 10 ETLA libraries. The Secure Key Manager has capacity to support even the largest ETLA libraries (44 drives).
4. Auditing and Validation Features
  • The Secure Key Manager maintains an audit log of all key creation and usage. This can be used to support your auditing and security validation policies. This log is digitally signed, which provides non-repudiation.
5. Key Deletion
  • The Secure Key Manager supports manual key deletion, through the Secure Key Manager GUI. This operation can be used if a tape is lost or if the data on the tape is no longer needed. Key deletion is only possible as a manual process by an administrator with the proper authority. The tape library clients cannot delete keys.
contents
 Overview      Standard Features      Product Highlights      Service and Support, HP Care Pack, and Warranty Information      Kit Contents      Related Options      Configuration Information      Technical Specifications line.gif (50 bytes)

Technical Specifications

HP StorageWorks Secure Key Manager
Security
Key Generation
AES-256 (Advanced Encryption Standard with 256-bit keys)
Security Standards
FIPS 140-2 Level 2 (validation pending)
Operating System
Hardened Embedded Linux OS
Authentication/Quorum Control
2-factor client device authentication, multiple credentials administration
Configurable Security Policies
Customizable security settings for device and key generation
Physical Security
Dual locking bezel with high-security pick-resistant locks and tamper-evident enclosure seals
Secure Audit Logs Digitally signed logs
Scalability
Number of Clients Supported
5 EML/ESL tape library licenses included per node
Number of Keys Stored
100,000 (> 1 million pending)
Key Granularity
Key per cartridge or Key per library partition
Client IOP Extensible to emerging key management standards
Management
System Administration
Secure simple to use Web-GUI (HTTPS communications) and SSH/Serial CLI
Certificate Management
Local and external certificate authorities. Create and sign client and server certificates
Key Management
Centralized, automated key generation, archival and retrieval
Network Management SNMP, NTP, health checks, automatic log rotation, backups, upgrades and statistics
Redundancy and Failover
Hardware Redundancy
Dual fans, power supplies and disk drives ( RAID 1 mirroring)
Clustering and Failover Multi-node multi-site clustering, automatic key and policy synchronization, failover and recovery; > 20 nodes supported
Data Protection Secure encrypted and integrity checked backups of the keys, logs and all key manager configurations

Dimensions and Physical Characteristics
HP StorageWorks Secure Key Manager System
Form Factor
2U (total installed form factor - system unit)
Physical Dimensions (HxWXD):
NOTE: 2 nodes in each system configuration
Node
1.7 x 19.0 x 29.1 in (4.3 x 48.2 x 74.0 cm)
Shipping
41.0 x 28.5 x 38.0 x 41.0 in
(104.1 x 72.4 x 96.5 x 104.1 cm)
Out of Box Weight
Node (both)
74 lb (33.6 kg)
Shipping Weight
137 lb (62.3 kg)

HP StorageWorks Secure Key Manager Expansion Module
Form Factor
   
Physical Dimensions (HxWXD):
NOTE: 1 node in each expansion module configuration
Node
1.7 x 19.0 x 29.1 in (4.3 x 48.2 x 74.0 cm)
Shipping
11.5 x 23.8 x 36.0 in (29.2 x 60.3 x 91.4 cm)
Out of Box Weight
Node
37 lb (16.78 kg)
Shipping Weight
54 lb (24.5 kg)  

Environmental Operating temperature range
10°C to 35°C (50°F to 95°F)
Shipping temperature range
-40°C to 66°C (-40°F to 150°F)
Operating Humidity (non-condensing) 10 - 90 % RH

 

© Copyright 2007 Hewlett-Packard Development Company, L.P.

The information contained herein is subject to change without notice.

The only warranties for HP products and services are set forth in the express warranty statements accompanying such products and services. Nothing herein should be construed as constituting an additional warranty. HP shall not be liable for technical or editorial errors or omissions contained herein.


   DA-12814 1 - Version 1 - October 29, 2007