﻿<?xml version="1.0" encoding="utf-8"?><rss xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0"><channel><ttl>60</ttl><title>Self-Encrypting Storage</title><link>http://blog.willettworks.com</link><lastBuildDate>Mon, 28 May 2012 03:31:15 GMT</lastBuildDate><pubDate>Mon, 28 May 2012 03:31:15 GMT</pubDate><language>en</language><copyright /><itunes:subtitle> </itunes:subtitle><itunes:author /><itunes:summary /><description /><itunes:owner><itunes:name /><itunes:email>michaelwillett@willettworks.com</itunes:email></itunes:owner><itunes:explicit>no</itunes:explicit><itunes:category text="Arts" /><item><title>Self-Encrypting Drives tutorial at SNIA/SNW Fall 2009 in Phoenix</title><link>http://blog.willettworks.com/2009/10/19/selfencrypting-drives-tutorial-at-sniasnw-fall-2009-in-phoenix.aspx?ref=rss</link><dc:creator>Michael Willett</dc:creator><description>Michael Willett presented an invited tutorial on Self-Encrypting Drives at the SNIA/SNW Fall 2009 Conference in Phoenix on 12 Oct 2009. The charts are available at:&lt;BR&gt;&amp;nbsp;&amp;nbsp; 
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;A href="http://www.snia.org/education/tutorials/2009/fall/security/MichaelWillett-Self_Encrypting_Drives-FINAL.pdf"&gt;&lt;FONT size=3 face=Calibri&gt;http://www.snia.org/education/tutorials/2009/fall/security/MichaelWillett-Self_Encrypting_Drives-FINAL.pdf&lt;/FONT&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;&amp;nbsp;&amp;nbsp;</description><category>SED</category><comments>http://blog.willettworks.com/2009/10/19/selfencrypting-drives-tutorial-at-sniasnw-fall-2009-in-phoenix.aspx#Comments</comments><guid isPermaLink="false">c98a5910-5f9d-4f3a-ab77-e6ca514101c9</guid><pubDate>Tue, 20 Oct 2009 01:21:00 GMT</pubDate></item><item><title>Identity Management 2009</title><link>http://blog.willettworks.com/2009/09/08/identity-management-2009.aspx?ref=rss</link><dc:creator>Michael Willett</dc:creator><description>&lt;P class=MsoNormal&gt;Identity Management 2009:&amp;nbsp; "Transparent Government - Risks, Rewards, Repercussions"&lt;BR&gt;Date:&amp;nbsp; 29 &amp;amp; 30 September &lt;BR&gt;Location: NIST Gaithersburg, Maryland Facility&lt;BR&gt;Event website: &lt;A title=blocked::http://events.oasis-open.org/home/symposium/2008/ href="http://events.oasis-open.org/symposium/2008/"&gt;&lt;SPAN style="COLOR: black"&gt;&lt;SPAN style="COLOR: windowtext"&gt;http://events.oasis-open.org/home/forum/2009&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt; &lt;/P&gt;Produced by OASIS 
&lt;P class=MsoNormal&gt;&lt;STRONG&gt;OASIS is pleased to announce that&amp;nbsp;Dr. Michael Willett&lt;/STRONG&gt;&amp;nbsp;&lt;STRONG&gt;will be representing the ISTPA and WillettWorks&amp;nbsp;at our upcoming conference on 29-30 September 2009. The title of his talk will be "&lt;SPAN style="COLOR: #333333"&gt;&lt;STRONG&gt;Implementation of Privacy Management Throughout the Life Cycle of Personal Information&lt;/STRONG&gt;&lt;/SPAN&gt;".&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;An early-bird discount, as well as a substantial OASIS member discount is available. If you or any of your co-workers would like to take advantage of this savings, please register using the &lt;A href="http://events.oasis-open.org/home/forum/2009/registration"&gt;on-line registration form&lt;/A&gt;&amp;nbsp;(&lt;A href="http://events.oasis-open.org/home/forum/2009/registration"&gt;http://events.oasis-open.org/home/forum/2009/registration&lt;/A&gt;)&amp;nbsp;&lt;A title=blocked::http://events.oasis-open.org/home/symposium/2008/registration href="http://events.oasis-open.org/symposium/2008/registration"&gt;&lt;/A&gt;or contact OASIS directly &lt;A href="mailto:events@oasis-open.org"&gt;events@oasis-open.org&lt;/A&gt;. &lt;BR&gt;&lt;BR&gt;As national and international governments endeavor to provide open, transparent and trusted services, the challenges of managing citizens’ identities and access to information require careful planning, a strong policy focus, and attention to standards and interoperability. &lt;/P&gt;
&lt;P class=MsoNormal&gt;Identity Management 2009 will provide users who are evaluating or looking to deploy security infrastructures with an opportunity to explore the state-of-the-art in security services, standards and products. It will also offer users the opportunity to present and share their use cases, requirements and experiences with some of the leading experts in this field. &lt;/P&gt;
&lt;P&gt;For registration information, including registration discounts, special hotel rates, or to see a full conference program -- please visit the &lt;A href="http://events.oasis-open.org/home/forum/2009"&gt;conference website&lt;/A&gt;&amp;nbsp;(&lt;A href="http://events.oasis-open.org/home/forum/2009)&amp;nbsp;"&gt;http://events.oasis-open.org/home/forum/2009)&amp;nbsp;&lt;/A&gt;&amp;nbsp;or email us at &lt;A href="mailto:events@oasis-open.org"&gt;events@oasis-open.org&lt;/A&gt;. &lt;/P&gt;
&lt;P&gt;We look forward to seeing you this September in Gaithersburg! &lt;/P&gt;</description><category>privacy</category><comments>http://blog.willettworks.com/2009/09/08/identity-management-2009.aspx#Comments</comments><guid isPermaLink="false">65a99907-c90e-4ec5-8f36-4fe529ef2db1</guid><pubDate>Tue, 08 Sep 2009 19:20:00 GMT</pubDate></item><item><title>Superiority of Self-Encryption over software encryption</title><link>http://blog.willettworks.com/2009/08/27/superiority-of-selfencryption-over-software-encryption.aspx?ref=rss</link><dc:creator>Michael Willett</dc:creator><description>Indirect encryption solutions for stored data are used today because that is what&amp;nbsp;has been available historically. These indirect methods include host-based software, especially for laptops. All reads/writes to storage have to go indirectly through the software application. But, the storage industry is vigorously adopting the&amp;nbsp;direct, hardware-based, self-encryption&amp;nbsp;solution that has recently been specified by the TCG, with&amp;nbsp;contribution from all the major storage vendors.&lt;BR&gt;&lt;BR&gt;If only the storage industry had thought of this&amp;nbsp;approach sooner, the indirect methods&amp;nbsp;probably would not have&amp;nbsp;appeared. Now, the I.T. industry faces a methodical migration to self-encryption, as part of the normal component replacement cycle. The migration is worth the effort, due to the superior properties of self-encrypting drives&amp;nbsp;(SED) when compared to software solutions:&lt;BR&gt;&lt;BR&gt;&amp;nbsp;&amp;nbsp; - transparency: SEDs come from the factory with the encryption key already&amp;nbsp;generated on board. &lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; An SED is an encrypting drive&amp;nbsp;right out of the box.&lt;BR&gt;&lt;BR&gt;&amp;nbsp;&amp;nbsp; - ease of management: No encrypting key to manage.&lt;BR&gt;&lt;BR&gt;&amp;nbsp;&amp;nbsp; - life-cycle costs: The cost of an SED is&amp;nbsp;pro-rated into the initial drive cost. Conversely, &lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; software has a continuing life cycle cost,&amp;nbsp;due to&amp;nbsp;software licensing and upgrades, &lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; as well as day-to-day management costs.&lt;BR&gt;&lt;BR&gt;&amp;nbsp;&amp;nbsp; - disposal or re-purposing cost: With an SED, simply erase the on-board encryption key &lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; and the drive is "erased".&amp;nbsp;With the only copy of the key gone, no one can read the encrypted data.&lt;BR&gt;&lt;BR&gt;&amp;nbsp;&amp;nbsp; - re-encryption: With SED, there is no need to ever re-encrypt the data, since the encryption key &lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; is never changed throughout&amp;nbsp;the&amp;nbsp;active life cycle of the drive.&lt;BR&gt;&lt;BR&gt;&amp;nbsp;&amp;nbsp; - Performance: No degradation in SED performance; the encryption operates at channel speeds. &lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Can't say that about software!&lt;BR&gt;&lt;BR&gt;&amp;nbsp;&amp;nbsp; - Standardization: The whole drive industry is building to the TCG/SED Specs, providing for interoperability &lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; and competition, and thus driving down cost.&lt;BR&gt;&lt;BR&gt;&amp;nbsp;&amp;nbsp; - No interference with upstream processes like data compression and de-duplication: &lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; The encrypt/decrypt function is performed inside the drive. Software solutions on the host can interfere &lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; with such processes.&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR&gt;SEDs possess other&amp;nbsp;superior properties when compared to software solutions, which you can discover by seriously considering an evolution of your storage infrastructure to self-encryption.</description><category>SED</category><comments>http://blog.willettworks.com/2009/08/27/superiority-of-selfencryption-over-software-encryption.aspx#Comments</comments><guid isPermaLink="false">c8548451-1ec3-4482-b949-b6cd8def6181</guid><pubDate>Thu, 27 Aug 2009 21:39:42 GMT</pubDate></item><item><title>Rationale for Self-Encrypting Storage</title><link>http://blog.willettworks.com/2009/08/02/rationale-for-selfencrypting-storage.aspx?ref=rss</link><dc:creator>Michael Willett</dc:creator><description>&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Self-encrypting hard drives (SED) integrate the AES encryption hardware and strong access control directly into the drive electronics and thus avoid many of the vulnerabilities of software-based solutions. SED protects against computer loss or theft and facilitates computer re-purposing and end-of-life. By deleting the cryptographic key under strong administrative access control, the drive can be instantly “sanitized”. SED satisfies the encryption safe harbor exemption in breach notification laws. SED has been standardized across the storage industry, from the laptop to the data center, and products are now available from all the major storage vendors.&lt;/FONT&gt;&lt;/P&gt;</description><category>SED</category><comments>http://blog.willettworks.com/2009/08/02/rationale-for-selfencrypting-storage.aspx#Comments</comments><guid isPermaLink="false">09d0d44c-eca5-42b9-963d-9a5cf57bfaab</guid><pubDate>Sun, 02 Aug 2009 17:56:00 GMT</pubDate></item></channel></rss>
