摘要:
Provided are a method, system, and article of manufacture, wherein a first write only register is maintained in an encryption engine of a cryptographic unit. A second write only register is maintained in a decryption engine of the cryptographic unit. A cryptographic key is written in the first write only register and the second write only register, wherein the cryptographic key is inaccessible for reading from any entity that is external to the cryptographic unit.
摘要:
Provided are a method, system and article of manufacture, wherein a cryptographic key generator generates a cryptographic key. The cryptographic key generator encrypts the cryptographic key with a session key that is available to both the cryptographic key generator and a cryptographic unit. The encrypted cryptographic key is transmitted across a link from the cryptographic key generator to the cryptographic unit.
摘要:
Provided are a method, system and article of manufacture, wherein a cryptographic key generator generates a cryptographic key. The cryptographic key generator encrypts the cryptographic key with a session key that is available to both the cryptographic key generator and a cryptographic unit. The encrypted cryptographic key is transmitted across a link from the cryptographic key generator to the cryptographic unit.
摘要:
Provided are a method, system, and article of manufacture, wherein a first write only register is maintained in an encryption engine of a cryptographic unit. A second write only register is maintained in a decryption engine of the cryptographic unit. A cryptographic key is written in the first write only register and the second write only register, wherein the cryptographic key is inaccessible for reading from any entity that is external to the cryptographic unit.
摘要:
Provided are a method, system, and article of manufacture that maintains, at a decryption unit, and expected key identifier and an expected initialization vector. A key identifier and an initialization vector are received at the decryption unit, wherein a plurality of encrypted data records are preceded by the key identifier and the initialization vector in a data stream, and wherein the plurality of encrypted data records have been encrypted with a cryptographic key that is recoverable by the decryption unit from the key identifier. An initiation is made of the reading of the plurality of encrypted data records of the data stream, in response to determining at the decryption unit that the received key identifier matches the expected key identifier. Certain embodiments are implemented in a storage library, comprising at least one storage drive, and at least one decryption unit included in the at least one storage drive, wherein in certain embodiments the storage library is a tape library. Certain additional embodiments are implemented in a storage drive, comprising a removable storage medium and at least one decryption unit coupled to the removable storage medium, wherein in certain embodiments the storage drive is a tape drive.
摘要:
Provided are a method, system, and article of manufacture that maintains, at a decryption unit, and expected key identifier and an expected initialization vector. A key identifier and an initialization vector are received at the decryption unit, wherein a plurality of encrypted data records are preceded by the key identifier and the initialization vector in a data stream, and wherein the plurality of encrypted data records have been encrypted with a cryptographic key that is recoverable by the decryption unit from the key identifier. An initiation is made of the reading of the plurality of encrypted data records of the data stream, in response to determining at the decryption unit that the received key identifier matches the expected key identifier. Certain embodiments are implemented in a storage library, comprising at least one storage drive, and at least one decryption unit included in the at least one storage drive, wherein in certain embodiments the storage library is a tape library. Certain additional embodiments are implemented in a storage drive, comprising a removable storage medium and at least one decryption unit coupled to the removable storage medium, wherein in certain embodiments the storage drive is a tape drive.
摘要:
An apparatus, system, and method are disclosed for testing data compression and data encryption circuitry. A pattern configuration module generates initial pattern parameters. Holding registers store the initial pattern parameters. A pattern generation module generates patterns for compression/encryption logic. A detection module detects a failure of the compression/encryption logic. The failure of the compression/encryption logic may be a cyclic redundancy check failure of a decompression module and/or a message authentication code failure of a decryption module.
摘要:
Provided is a data storage drive for encrypting data, comprising a microprocessor and circuitry coupled to the microprocessor and adapted to receive a session encrypted data key and to decrypt the session encrypted data key using a session key, wherein a result is a data key that is capable of being used to encrypt clear text and to decrypt cipher text written to a storage medium. Also provided is a system, comprising a microprocessor and circuitry coupled to the microprocessor and adapted to receive a session encrypted data key and to decrypt the session encrypted data key using a private key, wherein a result is a secret key that is capable of being used to encrypt clear text and to decrypt cipher text written to a storage medium.
摘要:
Provided is a data storage drive for encrypting data, comprising a microprocessor and circuitry coupled to the microprocessor and adapted to receive a session encrypted data key and to decrypt the session encrypted data key using a session key, wherein a result is a data key that is capable of being used to encrypt clear text and to decrypt cipher text written to a storage medium. Also provided is a system, comprising a microprocessor and circuitry coupled to the microprocessor and adapted to receive a session encrypted data key and to decrypt the session encrypted data key using a private key, wherein a result is a secret key that is capable of being used to encrypt clear text and to decrypt cipher text written to a storage medium.
摘要:
A method for equalizing the bandwidth of requesters using a shared memory system is disclosed. In one embodiment, such a method includes receiving multiple access requests to access a shared memory system. Each access request originates from a different requester coupled to the shared memory system. The method then determines which of the access requests has been waiting the longest to access the shared memory system. The access requests are then ordered so that the access request that has been waiting the longest is transmitted to the shared memory system after the other access requests. The requester associated with the longest-waiting access request may then transmit additional access requests to the shared memory system immediately after the longest-waiting access request has been transmitted. A corresponding apparatus and computer program product are also disclosed.