Glossary of Terms: Storage Encryption
Computerworld - A glossary of common storage-encryption terms:
Sensitive data. Depending on the type of business, sensitive data can include Social Security numbers, credit card information, financial records, health data, intellectual property documents or information about sexual orientation. Most companies will find an average of 8 to 12 bits of data per record that need encryption. The difficulty is locating every place where that information is stored.
Encryption appliance. This hardware sits between servers and storage systems and encrypts data as it moves back and forth. Many of these appliances can run in SAN, NAS, iSCSI and tape infrastructures. They encrypt data at close to wire speed with very little latency. In comparison, encryption software on servers and in storage systems slows backups.
Library-based tape encryption. Security features embedded in tape drive and tape library hardware are often used when data is stored at an off-site facility. Encryption co-processors process the data stream at wire speed as it enters the library. Security functions are completely transparent to the software. No external software or operating system support is needed. But it also means that the tape vendor is entirely responsible for managing security.
Edge encryption. This includes encrypting data at the point of entry on laptops, handhelds and desktop PCs. Basic encryption that requires a username and password offers little protection, but it's better than nothing, say industry watchers. A global key-management system for Windows offers better protection. Some laptop manufacturers are incorporating encryption capabilities in new models.
Enterprise digital rights management. This is the next big thing in key-management technology. Still in its early stages, DRM offers the potential for persistent encryption and security as data travels from laptop to e-mail, database and storage tape by assigning access rights to the file. DRM becomes more important as companies distribute protected documents beyond the enterprise to partners and vendors.
Quorum-based recovery. This is one of three key-management approaches that companies should consider. Quorum-based recovery requires a group of three to five administrators to grant permission before encryption keys can be recovered. Encryption specialists also advise that tape libraries shouldn't have to maintain the mapping of keys to tape volumes. This method adds another point of management and complicates long-term key escrow. It's also important to automatically replicate keys to an escrow service or tape library at a disaster recovery site for fast data recovery in case the originals are lost.
Data compression. Appliances trump software-based encryption at the database level when it comes to compression. Software-encrypted data can't be compressed. Encryption hardware devices have a compression chip in them, so they compress before they encrypt, which is a tape-drive space savings of 1.5 to 1.
- New Wrinkles in Storage
- Storage Package Overview
- Backing Up the Virtual Machine
- Sidebar: How Many Licenses?
- Battle of the Bulge
- Sidebar: Provisioning Pretender
- Sidebar: Thin Provisioning Explained
- Cruising Over Copper
- DIY Recovery
- Sidebar: A Comeback for Managed Storage Services?
- Data Points: Storage
- Safe and Sound
- Sidebar: How Long Will It Be Safe?
- Sidebar: Have a Key-Recovery Plan
- Sidebar: Encryption Decrypted
- Storage-free Zone
- The Storage Specialty
- Sidebar: Resume Gold
- Sidebar: Big Cities, Big Bucks
- Virtual Tape
Read more about storage in Computerworld's Storage Knowledge Center.
glossary of common storage-encryption terms
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Tape Killed the IT Guy
Watch Now
Cache Tier Memory Efficiency with Gear6 Web Cache
Download this valuable white paper!
Customer Video: Cardinal Health
Download Now
Connecting to the Cloud with F5 and VMware VMotion
F5 and VMware partner to enable live application and storage migrations between datacenters and clouds, over short or long distances.
Virtualize Microsoft Applications on VMware
Register for this live webcast now!
F5 Virtualization Guide: Seven Key Challenges You Can't Ignore
Seven Key Challenges You Can't Ignore
Strategic ECM Webinar
Learn what new strategic business benefits can be realized through ECM!



