Restoring encryption keys

When all of the LDEVs in an encrypted parity group are blocked, or if an existing data encryption key becomes unavailable or cannot be used (for example, due to a system failure), the encryption keys can be restored from the primary or secondary backup copy.

When key information is lost or deleted, restoration is performed in a batch for the backed-up encryption keys (including Free keys, DEKs, and CEKs):

  • VSP G100, VSP G200: 516 keys
  • VSP G400, G600, VSP F400, F600: 1,028 keys
  • VSP G800, VSP F800 models: 2,064 keys

The storage system automatically restores encryption keys from the primary backup. Users restore encryption keys from the secondary backup using Device Manager - Storage Navigator. If you need to restore an encryption key that is not the latest key from a secondary backup copy, you must have the Security Administrator (View & Modify) and Support Personnel (View & Modify) roles.

CautionWhen you restore the encryption key, always restore the latest key. If the backed up encryption key (secondary backup) is not the latest key, it cannot be restored.

To restore the encryption key, the volumes belonging to the parity group for which the key is set must be blocked. In addition, after the restoration of the key, the volumes belonging to the parity group for which encryption key is set must be restored.