data center a high-performance encryption blade for the ...scale fabric-based data security...

4
HIGHLIGHTS • High-performance, scalable fabric-based encryption enforces data confidentiality and privacy requirements • Unparalleled encryption processing at up to 96 Gbps using industry-standard AES-256 encryption algorithms • Choice of industry-leading key management solutions that help reduce operational costs and simplify management • A single, centralized security platform for both disk and tape SAN environments supporting heterogeneous enterprise data centers • Frame Redirection technology enables easy, non-intrusive deployment of fabric-based security services • Plug-in encryption and compression services available to all host servers, including Virtual Machines (VMs), attached to data center fabrics • Scalable performance with on-demand encryption and compression processing power meets regulatory mandates for securing data A High-Performance Encryption Blade for the Brocade DCX Backbone Family Managing operational risk by protecting valuable digital assets has become increasingly critical in today’s enterprise IT environments. In addition to achieving compliance with regulatory mandates and meeting industry standards for data confidentiality, IT organizations must also protect against potential litigation and liability following a reported breach. In the context of data center fabric security, Brocade provides advanced fabric services for Storage Area Networks (SANs) with the Brocade ® FS8-18 Encryption Blade for use in Brocade DCX ® 8510 and Brocade DCX Backbones. The blade is a high-speed, highly reliable hardware device that delivers fabric-based encryption services to secure data assets either selectively or on a comprehensive basis. The Brocade FS8-18 scales non-disruptively, providing up to 96 Gbps of encryption processing power to meet the needs of the most demanding environments with flexible, on-demand performance. It also provides compression services at speeds up to 48 Gbps for tape storage systems. Moreover, it is tightly integrated with industry-leading, enterprise-class key management systems that can scale to support key lifecycle services across distributed environments. BROCADE FS8-18 ENCRYPTION BLADE DATA CENTER DATA SHEET FABRIC-BASED ENCRYPTION Most sensitive corporate data is stored in the data center, and the vast majority of data from critical applications resides in a SAN—enabling organizations to leverage the existing intelligence layer in the storage fabric. This layer provides a centralized framework in which to deploy, manage, and scale fabric-based data security solutions. The Brocade One strategy helps simplify networking infrastructures through innovative technologies and solutions. The Brocade FS8-18 Encryption Blade supports this strategy by allowing organizations to secure their data to meet regulatory and internal compliance requirements. www.brocade.com

Upload: others

Post on 16-Oct-2020

3 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: DATA CENTER A High-Performance Encryption Blade for the ...scale fabric-based data security solutions. The Brocade One strategy helps simplify networking infrastructures through innovative

HIGHLIGHTS•High-performance,scalablefabric-basedencryptionenforcesdataconfidentialityandprivacyrequirements

•Unparalleledencryptionprocessingatupto96Gbpsusingindustry-standardAES-256encryptionalgorithms

•Choiceofindustry-leadingkeymanagementsolutionsthathelpreduceoperationalcostsandsimplifymanagement

•Asingle,centralizedsecurityplatformforbothdiskandtapeSANenvironmentssupportingheterogeneousenterprisedatacenters

•FrameRedirectiontechnologyenableseasy,non-intrusivedeploymentoffabric-basedsecurityservices

•Plug-inencryptionandcompressionservicesavailabletoallhostservers,includingVirtualMachines(VMs),attachedtodatacenterfabrics

•Scalableperformancewithon-demandencryptionandcompressionprocessingpowermeetsregulatorymandatesforsecuringdata

A High-Performance Encryption Blade for the Brocade DCX Backbone FamilyManagingoperationalriskbyprotectingvaluabledigitalassetshasbecomeincreasinglycriticalintoday’senterpriseITenvironments.Inadditiontoachievingcompliancewithregulatorymandatesandmeetingindustrystandardsfordataconfidentiality,ITorganizationsmustalsoprotectagainstpotentiallitigationandliabilityfollowingareportedbreach.

Inthecontextofdatacenterfabricsecurity,BrocadeprovidesadvancedfabricservicesforStorageAreaNetworks(SANs)withtheBrocade®FS8-18EncryptionBladeforuseinBrocadeDCX®8510andBrocadeDCXBackbones.Thebladeisahigh-speed,highlyreliablehardwaredevicethatdeliversfabric-basedencryptionservicestosecuredataassetseitherselectivelyoronacomprehensivebasis.

TheBrocadeFS8-18scalesnon-disruptively,providingupto96Gbpsofencryptionprocessingpowertomeettheneedsofthemostdemandingenvironmentswithflexible,on-demandperformance.Italsoprovidescompressionservicesatspeedsupto48Gbpsfortapestoragesystems.Moreover,itistightlyintegratedwithindustry-leading,enterprise-classkeymanagementsystemsthatcanscaletosupportkeylifecycleservicesacrossdistributedenvironments.

BROCADEFS8-18ENCRYPTIONBLADE

DATA CENTER

DATASHEET

FABRIC-BASED ENCRYPTIONMostsensitivecorporatedataisstoredinthedatacenter,andthevastmajorityofdatafromcriticalapplicationsresidesinaSAN—enablingorganizationstoleveragetheexistingintelligencelayerinthestoragefabric.Thislayerprovidesacentralizedframeworkinwhichtodeploy,manage,andscalefabric-baseddatasecuritysolutions.

TheBrocadeOne™strategyhelpssimplifynetworkinginfrastructuresthroughinnovativetechnologiesandsolutions.TheBrocadeFS8-18EncryptionBladesupportsthisstrategybyallowingorganizationstosecuretheirdatatomeetregulatoryandinternalcompliancerequirements.

www.brocade.com

Page 2: DATA CENTER A High-Performance Encryption Blade for the ...scale fabric-based data security solutions. The Brocade One strategy helps simplify networking infrastructures through innovative

Figure 1. TheBrocadeFS8-18EncryptionBladeplays

avitalroleintheBrocadeOnestrategy.

pointofmanagementforbothdiskandtapestoragesecurityaswellaskeymanagement,andsupportsheterogeneousstorageenvironments.Deploymentissimpleandnon-disruptive:Organizationscanencryptdatafromanyswitchportwithoutreconfiguringthefabric.

Inaddition,organizationscanimplementprovisioningwithoutshuttingdownapplicationsorchangingtheLogicalUnitNumber(LUN)mappingandLUNmaskingconfigurationsonthetargetstoragearrays.TheBrocadeFS8-18ismanagedandconfiguredusingfamiliarBrocademanagementtools—includingBrocadeNetworkAdvisor,BrocadeDataCenterFabricManager(DCFM®),andCLImanagementtools—andiseasilyintegratedintoexistingnetworkinfrastructures.

KeyadvantagesoftheBrocadeFS8-18include:

•Theabilitytoencryptdataatwirespeed

•Centralmanagementofstorageandfabric-basedsecurityresources

•Concurrentsupportforbothdiskandtapeencryptionoperationsfromasingledevice

•Transparent,onlineencryptionof“cleartext”LUNsandrekeyingofencryptedLUNswithoutdisruption

•Datacompressionandintegrityauthenticationfortapebackupdata

•Simplified,non-disruptiveinstallationandconfiguration

HIGH-VALUE APPLICATIONS AND SOLUTION AREASTwoofthegreatestbusinessbenefitsoftheBrocadeFS8-18areincreasedproductivityandreducedriskofdataexposure.Otherkeybenefitsincludeimprovedbackupperformancewhiledeployingencryption/compressionandinvestmentprotectionforexistingresources.

TheBrocadeFS8-18isidealforapplicationssuchas:

•HighlysensitiveITapplicationswithsecuredata-at-restrequirements

•Securedatabackupsforoffsitetapestorageandlong-termarchiving

•Supportforheterogeneousdiskandtapestorageenvironmentsfromasingledevicewithcentralizedmanagement

•Decommissioningofdiskarraysthatrequirelegalvalidationoftheirrecoverabledestructionofdata(TheBrocadeFS8-18enablessecuredecommissioningofstoragedevicesbyencryptinganentireLUNandpermittingdeletionofdataencryptionkeys.)

•SecurereplicationofVirtualTapeLibrary(VTL)backupstoremotefacilities

•ScalingdatacenterencryptionservicesbyimplementinguptofourBrocadeFS8-18bladesinaBrocadeDCX8510orBrocadeDCXchassis

SAN

Client/Server

Emerging Protocols

(FCoE)

Brocade Data Center Fabric

Extended Data Center Fabric

Disaster Recovery Site

Continuous Remote

Replication

Key Management

Branch Office

Virtual and Standalone

Servers

Virtual and Standalone

Servers

Storage

Brocade FS8-18 Encryption Blade

Brocade DCX Backbone

Encryption

DirectorsSwitches

Thestoragefabricenablescentralizedmanagementtosupportnearlyeveryaspectofthedatacenter,fromserverenvironmentsandworkstationstoedgecomputingandbackupenvironments.Asaresult,itisanidealplacetostandardizeandconsolidateaholisticdata-at-restsecuritystrategy.Organizationscanalsoimplementthistypeofbest-practicemethodologyinotherpartsofthedatacenter,helpingtoprotectdatathroughouttheenterprise.

Mostcurrentindustrysolutionsincludeeitherhost-basedsoftwareencryption,device-embeddedencryption,oredgeencryption—allofwhichprovideisolatedservicestospecificapplicationsbuttypicallycannotscaleacrossextendedenterprisestorageenvironments.Incontrast,Brocadedeliversfabric-basedencryptionforbothdisk-andtape-basedstoragedevicesaspartoftheindustry-leadingBrocadeOnestrategyandinnovativeBrocadeAdaptiveNetworkingservices(seeFigure1).

Basedonindustrystandards,Brocadeencryptionfordata-at-restprovidescentralized,scalableencryptionandcompressionservicesthatseamlesslyintegrateintoexistingBrocadeFabricOS®(FOS)andBrocadeM-EnterpriseOS(M-EOS)environments1.

TheBrocadefabric-basedapproachtodataencryptionscalestomeetperformancerequirements,providesacentralized

1 Brocade M-EOS fabrics are McDATA switches and directors running McDATA Enterprise OS in McDATA Fabric mode or McDATA Open Fabric mode.

Page 3: DATA CENTER A High-Performance Encryption Blade for the ...scale fabric-based data security solutions. The Brocade One strategy helps simplify networking infrastructures through innovative

TheBrocadeFS8-18isdesignedforuseinthefollowingSANenvironments:

•Large-scaleencryptioninnewdatacenterdeployments

•Plug-instoragesecurityservicesforexistingSANfabrics

•Heterogeneousdiskandtapestorageenvironments

•StandalonedatacenterbackboneswithencryptionandcompressioninBrocadeFOSandBrocadeM-EOSfabrics

•Securefabric-basedenvironmentsthatintegratewithexistingenterprisekeymanagementsystems

•Expandingencryptionenvironmentsthatrequireprotectionforcurrentdatasecurityandkeymanagementinvestments

INVESTMENT PROTECTION AND EFFICIENCYTheBrocadeFS8-18istheindustry’smosteffectiveencryptionplatformintermsofpowerefficiencyandsystemperformance.Infact,itprovidesseveraltimestheencryptionandcompressionprocessingpowerofcompetitiveofferingswhiledeliveringasignificantadvantageinrackspaceutilization.

Tohelporganizationsprotecttheirtechnologyinvestments,theBrocadeFS8-18integratedintotheBrocadeDCXBackbonefamilychassisfeaturesforwardandbackwardcompatibilitywithBrocadeB-SeriesandM-Seriesfabrics.Byadoptinganevolutionarystrategyratherthana“rip-and-replace”approach,organizationscansavesignificanttime,money,andeffortwhileminimizingdisruptionandrisk.

Moreover,strategicrelationshipswithBrocadePartnersprovidethebroadestchoiceofintegrated,best-in-classkeymanagementandsecuritysolutions.Thisintegrationenablesorganizationstoleverageexistingkeymanagementinfrastructureinvestmentsandmaintaincurrentpolicies,procedures,andtrainingefficiencies.

BROCADE ENCRYPTION PROFESSIONAL SERVICESBrocadeProfessionalServiceshelpsorganizationsdeployandaddresstheirmanagement,encryption,andsecurityprocessesinaholisticapproachtomeetcomplianceandregulatoryrequirementsforencryptionofdata-at-rest.Auniqueend-to-endapproachconsidersthesolutiondesignfromanarchitectural,policy,andoperationalperspective.

Followingthedesignphase,Brocadeexpertswillinstallandconfigurethehardwareintoaneworexistingfabricinahighlyeffectiveandtimelymanneraccordingtobestpractices.Uponcompletionoftheengagement,organizationsreceivefulldocumentationofthesolution.ThistransferofinformationeducatesITstaffsotheycanbetterunderstandandassumeresponsibilityforthesolution.

BROCADE GLOBAL SERVICES BrocadeGlobalServiceshastheexpertisetohelporganizationsbuildscalable,efficientcloudinfrastructures.Leveraging15yearsofexpertiseinstorage,networking,andvirtualization,BrocadeGlobalServicesdeliversworld-classprofessionalservices,technicalsupport,networkmonitoringservices,andeducation,enablingorganizationstomaximizetheirBrocadeinvestments,acceleratenewtechnologydeployments,andoptimizetheperformanceofnetworkinginfrastructures.

MAXIMIZING INVESTMENTSTohelpoptimizetechnologyinvestments,Brocadeanditspartnersoffercompletesolutionsthatincludeprofessionalservices,technicalsupport,andeducation.Formoreinformation,contactaBrocadesalespartnerorvisitwww.brocade.com.

Systems ArchitectureFibreChannelports 16ports,universal(F/FL/E/EX/M)Ethernetports Tworedundant1000BaseTEthernetportsfor

clusteringandI/Osynchronizationduringrekeyingoperation

Smartcards Masterkeyrecovery,quorumauthorization,andsystemrecoveryoperations

Compressionfortape Hardware-baseddatacompressionpriortoencryption

Compatibility IEEE1619standard-basedmode(diskandtape)

DataFort-compatiblemode(diskandtape)Datarekeying Onlineorofflineconversionofdatafromcleartextto

ciphertext;manualorautomatedrekeyingsessionsCryptoscalability Upto256targetdevicesandinitiatorsper

encryptionengineCryptoengine Maximum96Gbpshardwareprocessingfordisk*

Maximum48Gbpshardwareprocessingfortapewithcompression*

FibreChannelperformance

1.063Gbpslinespeed,fullduplex;2.125Gbpslinespeed,fullduplex;4.25Gbpslinespeed,fullduplex;8.5Gbpslinespeed,fullduplex;auto-sensingof1,2,4,and8Gbpsportspeeds;optionallyprogrammabletofixedportspeed;speedmatchingbetween1,2,4,and8Gbpsports

Systemscalability UptofourBrocadeFS8-18bladesperBrocadeDCXBackbonefamilychassis

ISLTrunking Frame-basedtrunkingwithuptoeight8GbpsportsperISLtrunk;upto64GbpsthroughputperISLtrunk

Maximumframesize 2112-bytepayloadforFibreChannel

Classesofservice Class2(unencryptedtraffic),Class3(encryptedandunencrypted),andClassF(inter-switchframes)

Datatraffictypes Fabricswitchessupportingunicast,multicast(255groups),andbroadcast

BROCADE FS8-18 ENCRYPTION BLADE SPECIFICATIONS

Page 4: DATA CENTER A High-Performance Encryption Blade for the ...scale fabric-based data security solutions. The Brocade One strategy helps simplify networking infrastructures through innovative

DATASHEET

©2012BrocadeCommunicationsSystems,Inc.AllRightsReserved.03/12GA-DS-1222-05

Brocade,BrocadeAssurance,theB-wingsymbol,DCX,FabricOS,MLX,SANHealth,VCS,andVDXareregisteredtrademarks,andAnyIO,BrocadeOne,CloudPlex,EffortlessNetworking,ICX,NETHealth,OpenScript,andTheEffortlessNetworkaretrademarksofBrocadeCommunicationsSystems,Inc.,intheUnitedStatesand/orinothercountries.Otherbrands,products,orservicenamesmentionedmaybetrademarksoftheirrespectiveowners.

Notice:Thisdocumentisforinformationalpurposesonlyanddoesnotsetforthanywarranty,expressedorimplied,concerninganyequipment,equipmentfeature,orserviceofferedortobeofferedbyBrocade.Brocadereservestherighttomakechangestothisdocumentatanytime,withoutnotice,andassumesnoresponsibilityforitsuse.Thisinformationaldocumentdescribesfeaturesthatmaynotbecurrentlyavailable.ContactaBrocadesalesofficeforinformationonfeatureandproductavailability.ExportoftechnicaldatacontainedinthisdocumentmayrequireanexportlicensefromtheUnitedStatesgovernment.

Corporate Headquarters SanJose,CAUSAT:[email protected]

European Headquarters Geneva,SwitzerlandT:[email protected]

Asia Pacific Headquarters SingaporeT:[email protected]

Mediatypes 8Gbps:UtilizesBrocadehot-pluggableSFP+,LCconnector;Short-WavelengthLaser(SWL);distancedependsonfiber-opticcableandportspeed

Fabricservices SimpleNameServer(SNS),RegisteredStateChangeNotification(RSCN),NTPv3,ReliableCommitService(RCS),DynamicPathSelection(DPS),BrocadeAdvancedZoning(defaultzoning,port/WWNzoning,broadcastzoning),N_PortIDVirtualization(NPIV),FDMI,ManagementServer,FSPF,EnhancedGroupManagement,IPFC,FrameRedirection,PortFencing,BBcreditrecovery

Optionalfabricservices:BrocadeFabricWatch,ExtendedFabrics,ISLTrunking,AdvancedPerformanceMonitoring,AdaptiveNetworking(per-dataflowQoS,IngressRateLimiting,TrafficIsolation,FabricDynamicsProfiling,andIntegratedRouting)

FIPScertification FIPS140-2Level-3ValidatedCryptographicModule

ManagementAdministratorroles Administrator,fabricadministrator,security

administrator,recoveryofficerKeymanagement NetAppLifetimeKeyManager(LKM)4.0;SafeNet

KeySecurek460;RSAKeyManager(RKM)Appliance;HPSecureKeyManager(SKM)/EnterpriseSecureKeyManager(ESKM);ThalesEncryptionManagerforStorage(TEMS);IBMTivoliKeyLifecycleManager(TKLM)

MechanicalsSize Width:3.60cm(1.41in)

Height:41.11cm(16.19in)

Depth:27.98cm(11.02in)

OccupiesoneslotinaBrocadeDCXBackbonechassisSystemweight 5.5kg(12.0lb)withoutSFPs

EnvironmentalsTemperature Operating:0°Cto40°C(32°Fto104°F)

Non-operating:–25°Cto70°C(–13°Fto158°F)Altitude Operating:Upto3000meters(9842feet)

Storage:Upto12kilometers(39,370feet)Shock Operating:20g,6mshalf-sine

Non-operating:33g11mshalf-sine,3/egAxis

PowerACinputrange 40to50VACMaximumpower 235watts

ConfigurationsBasecryptomodel BrocadeFS8-18EncryptionBlade:16Fibre

Channelports,48Gbps*maximumencryptionprocessing

Cryptoengineperformanceupgrade

96Gbps*maximumdiskencryptionprocessingupgradeforallBrocadeFS8-18EncryptionBladesinaBrocadeDCXBackbonefamilychassis

BROCADE FS8-18 ENCRYPTION BLADE SPECIFICATIONS (CONTINUED)

ForinformationaboutsupportedSANstandards,visitwww.brocade.com/sanstandards.Forinformationaboutswitchanddeviceinteroperability,visitwww.brocade.com/interoperability.Forinformationabouthardwareregulatorycompliance,visitwww.brocade.com/regulatorycompliance.

* Actualencryptionperformancelevelsvarybaseduponuserconfigurationandenvironment.

www.brocade.com