Primary and secondary data encryption license keys
VSP G400 and VSP G600 use the Encryption License Key feature to set up the data encryption license keys to encrypt and decrypt data.
VSP G200 cannot use the Encryption License Key feature.
You can use the Encryption License Key feature to back up data encryption license keys. VSP G400 and VSP G600 automatically create a primary backup of the data encryption license key, and stores this backup in cache flash memory.
You can create a secondary backup data encryption license key. The secondary backup is required to restore the key if the primary backup is unavailable.
It is recommended that you back up each key or group of keys immediately after you create them. You are responsible for storing the secondary backup securely. Schedule regular backups for all keys at the same time one time every week to ensure data availability.
In addition, it is recommended that you back up each key after you perform any of the following operations:
Creating encryption license keys.
Increasing, decreasing, or replacing drives.
Increasing, decreasing, or replacing disk boards.
Updating CEK keys.
Updating KEK keys.
For more information about backing up secondary data encryption license keys, see Workflow for backing up secondary data encryption license keys.
You must add storing secondary backup encryption license keys securely as part of your corporate security policy.
If the primary backup key becomes unavailable and no secondary backup key exists, the system cannot decrypt encrypted data.