Chapter 8: Encryption Key Management
Encryption Key Management Systems
288 Quantum Scalar i6000 User’s Guide
Encryption Key Management features described in this chapter. For
more information on licensing, see
Enabling Licenses on page 125 or
Step 1 — Installing the EKM License Key on page 293.
The Scalar i6000 supports four encryption key management systems:
Note: The library does not support using more than one encryption
key management system on a single library.
Encryption on the Scalar i6000 tape library is enabled by partition only.
The default setting for encryption-capable drives permits external
application-managed encryption support on all encryption-capable tape
drives and media within a partition.
You cannot select individual drives for encryption; you must select an
entire partition to be encrypted. If you encrypt a partition, all
encryption-capable tape drives are enabled for encryption, and all data
written to supported media is encrypted. Non encryption-capable tape
drives will not be enabled for encryption, and non-supported media will
not be encrypted.
Encryption System Supported Tape Drives Supported Media
Quantum Encryption Key Manager (Q-
EKM)
IBM LTO-4 Fibre Channel
IBM LTO-5 Fibre Channel
IBM LTO-6 Fibre Channel
IBM LTO-4, LTO-5, and
LTO-6
Scalar Key Manager (SKM) HP LTO-4 Fibre Channel
HP LTO-5 Fibre Channel
HP LTO-6 Fibre Channel
IBM LTO-5 Fibre Channel
IBM LTO-6 Fibre Channel
IBM LTO-7 Fibre Channel
HP LTO-4, LTO-5 and
LTO-6
IBM LTO-5, and LTO-6
LTO-7
KMIP-compliant key management (see
KMIP-compliant Encryption Key
Management on page 289).
HP LTO-4 Fibre Channel
HP LTO-5 Fibre Channel
HP LTO-6 Fibre Channel
IBM LTO-5 Fibre Channel
IBM LTO-6 Fibre Channel
IBM LTO-7 Fibre Channel
HP LTO-4, LTO-5, and
LTO-6
IBM LTO-5, LTO-6 and
LTO-7