Sign up now for Deduplication Storage News and other free literature.
Data Domain Encryption Software
Secure Encryption of Deduplicated Backup and Archive Data
Data Domain Encryption software encrypts all incoming data to ensure it cannot be accessed on the existing system or in any other environment without first decrypting it. Encrypting data at rest satisfies some aspects of internal governance rules and compliance regulations and also protects user data against theft of a Data Domain system, loss of the physical storage media during transit or accidental exposure during the replacement of failed drives.
Key Features
- Secure Data Management: DD Encryption provides 128-bit or 256-bit Advanced Encryption Standard (AES) algorithms for encrypting and decrypting all data within the system. Depending on IT security policies, the block cipher modes for the AES algorithm can be set to provide confidentiality using Cipher Block Chaining (CBC) or both confidentiality and message authenticity using Galios/Counter Mode (GCM).
- Inline Encryption: DD Encryption seamlessly integrates with the high-speed, inline deduplication process used in Data Domain deduplication storage systems and encrypts data before it is written to disk. Similar to the advantages of inline deduplication, inline encryption requires minimal resources to provide fast, reliable, and secure backup and recovery.
- Key Management and Data Integrity: Basic key management functions combine simplicity with ease of use to provide data security at the appropriate level. The Data Domain system has one encryption key for all data on the system thereby making key management simpler. For reliability and security, the encryption key is also protected and stored encrypted.
- Easy Integration: DD Encryption supports leading enterprise backup and archive software and easily integrates into existing enterprise infrastructures. Additional deployment flexibility exists with support for multiple simultaneous data access methods including the use of EMC Data Domain Virtual Tape Library software over Fibre Channel, through NFS and CIFS file service protocols over Ethernet or as a diskbased target using application-specific interfaces such as Symantec NetBackup OpenStorage.




