12.07.2015 Views

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>Brocade</strong> Encryption for Data-At-RestThe FIPS 140-2 Level compliance posed several challenges for theFS8-18. The typical <strong>Brocade</strong> enterprise-class platform blade has all ofits ASICs exposed on the card. To prevent tampering with the componentsof the blade involved in the cryptographic (crypto) process it wasnecessary to build a physical crypto security boundary protecting allthe memory, true random number generator, encryption, and Condor-2ASICs. This physical boundary was secured by placing a cover overthese components, which in turn posed a new challenge: cooling. Thecover cannot have vents for air circulation, since this could allowintruders to access the internal components with specialized tools.Instead, copper heat sinks were placed on the cover to dissipate theheat, as shown in Figure 44.As with the <strong>Brocade</strong> Encryption Switch, the FS8-18 Encryption Blade isalso available in an entry-level version for disk encryption. The entrylevelversion of the blade, though, applies to the entire DCX 8510/DCX/DCX-4S chassis. The <strong>Brocade</strong> DCX family chassis can supportfrom one to four FS8-18 blades per chassis. With the entry-level version,each blade is limited to 48 Gbps of encryption processingbandwidth per blade for disk, regardless of the number of bladesinstalled. The entry-level version affects only the disk encryption processingbandwidth; all 16 FC ports remain enabled and can be used toconnect hosts and storage devices. Later, if the 48 Gbps encryptionbandwidth is exceeded, either new FS8-18 blades can be added or allthe encryption blades in the chassis can be upgraded with a simplechassis-level license upgrade to the full 96 Gbps bandwidth.Copperheat sinksPhysical cryptographicsecurity boundaryFigure 4. Side view of the <strong>Brocade</strong> FS8-18Securing Fibre Channel Fabrics 177

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!