David Hill

Network Computing Blogger


Upcoming Events

Cloud Connect
Santa Clara
Feb 13-16, 2012

Cloud Connect brings together the entire cloud eco-system to better understand the transformation we're experiencing and promises to be the defining event of the cloud computing industry. Learn about the latest cloud technologies and platforms from thought leaders in Cloud Connect’s comprehensive conference.

Register Now!

More Events »

Subscribe to Newsletter

  • Keep up with all of the latest news and analysis on the fast-moving IT industry with Network Computing newsletters.
Sign Up

Wave Systems Rides The Wave Of Self-Encrypting Disk Drives

Protecting the confidentiality of data on mobile devices is an increasingly critical issue. For example, the loss or theft of laptop computers has led to numerous breaches of data privacy laws for exposing confidential information, such as Social Security and credit card numbers. Public admission of such a data breach is not only a matter of embarrassment and direct costs, such as notifying individuals of the thefts, but may also subject the company to fines and other sanctions.

That is the only the visible tip of the confidentiality iceberg. The vast majority of laptops probably don't contain that kind of information on them. However, they may include information that requires confidentiality from intellectual property to customer lists for sales representatives or other business planning documents. A bigger issue is public disclosure. Even when information lost is not overly sensitive, that is hard to prove and often requires the damaging public disclosure of a breach. For that reason, mobile devices used by businesses, as well as government and non-profit organizations, need to be protected, and the data encrypted.

Encryption seems to be the magic bullet most likely to successfully ensure data confidentiality. Two types of encryption are available for storage devices: software and hardware. Software has the advantage over hardware in that it can be retrofitted to existing pieces of storage media, such as hard drives or flash drives that do not have encryption or self-encryption built in. Conversely, hardware encryption is an option that must be chosen either when new mobile devices are purchased or through a painful migration of data and switchover to the self-encrypted drive. That is a costly use of personnel and product investment resources.

So then software encryption is best, right? The answer is an emphatic no. Why? Because software encryption suffers from performance degradation, imperfect security, and an IT management burden for both deployment and maintenance. The performance degradation comes about because software-based full disk encryption relies on a mobile device's memory and processing resources, often resulting in noticeably longer boot and response times. Imperfect security in software encryption often results from management and access issues, such as "cold boot" attacks (stealing information from memory at shut down time). The IT management burden of software encryption starts with the time required to encrypt a single device, which is reputedly between 3 1/2 to 24 hours for a 500 GB disk.

The hardware alternative consists of self-encrypting drives made by a number of manufacturers based on the Trusted Computing Group (TCG) "Opal" encryption specification. These drives contain a dedicated processor, dynamic RAM and boot environment that lead to higher security than software-based encryption solutions. For example, encryption keys reside in the disk controller and not system memory and are impervious to attack since external I/Os can never reach the disk controller itself. In addition, self-encrypting drives impose no performance penalty because dedicated processors in the disk provide the heavy lifting in a swift and transparent manner and without requiring any system memory or processing resources. Moreover, self-encrypting drives are always on, something that software-based encryption can not always claim, which is essential for ensuring you are truly in compliance with data breach laws.


Page:  1 | 2 |3 |Next Page »

Related Reading


More data-protection Insights



Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Network Computing encourages readers to engage in spirited, healthy debate, including taking us to task. However, Network Computing moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Network Computing further reserves the right to disable the profile of any commenter participating in said activities.

 
Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
 

DataProtection Reports

Research and Reports

Hypervisor Derby
August 2011

Network Computing: August 2011

TechWeb Careers