fhs
Volume 6, Number 32 -- August 15, 2006

Help/Systems Delivers Encryption for Backups

Published: August 15, 2006

by Alex Woodie

Help/Systems last week delivered Robot/SAVE version 11, a new release of its backup and recovery software for OS/400 and i5/OS systems. With this release, the Eden Prairie, Minnesota, company has added new encryption capabilities that make a backup tape unreadable without the proper keys. With four levels of encryption, Help/Systems is banking that Robot/SAVE customers will be able to find the right balance of safety and performance.

Every week, it seems, we hear another report of the loss of massive amounts of sensitive data due to stolen laptops, PCs that disappear, and backup tapes that never arrive at their secure offsite location. Banks, brokerage houses, the Department of Justice, and many other large organizations have owned up to their mistakes, which have put millions of Americans at risk of identity theft. Several reports in the last week alone give credence to the claim that this is the summer of identity theft.

These are only the ones we hear about. There's currently no federal law requiring companies to notify customers when their personal data has been lost, although there are several bills making their way through various states' legislative bodies that are similar to California's identity theft regulation, SB 1386, currently the only such law. Encryption is also commonly used in HIPAA, Sarbanes-Oxley, and PCI remediation engagements.

As reports of lost backup tapes and stolen laptops pile up in the news and states and Congress inch closer to closing the legal gaps related to identity theft, corporations are increasingly looking for ways to reduce the risk of losing sensitive data, thereby incurring potential fees related to notifying customers of the data loss, or possibly even paying fines.

One of the ways companies can fight data loss is by encrypting backup tapes. Many tape encryption solutions apply encryption at the tape drive itself, which provides less flexibility than a software-based solution, because users must find their own way to manage the encryption keys that unlock the encrypted content. A hardware-based solution also doesn't manage backups or guide the handling of tapes.

These are the advantages of Robot/SAVE's new encryption capability in version 11, according to Help/Systems' vice president of technical services, Tom Huntington. Because key management is also built into the OS/400-based backup and recovery product, there's no need for a separate key management solution, he says. "This is all totally integrated, all panel driven. It's easy to do," Huntington says.

If the tape is being recovered and decrypted using the same iSeries server that did the initial backup and encryption, the recovery is done automatically. Of course, a disaster recovery solution wouldn't be much good if the only place a tape could be restored was on the original machine, which might be destroyed due to a disaster. In these situations, Help/Systems recommends that users have a copy of the product with them to perform the restore, as well as the passphrase that was used to encrypt the backups. "The easiest way would be to have Robot/SAVE with you and plan on it being part of your hot site," Huntington says.

Alternatively, customers can also use a separate runtime environment (referred to by Help/Systems as a "mini library") and a set of commands to restore data locked on an encrypted tape. In these situations, users--or even close partners of the user--could recover an encrypted tape, even if they didn't have the full Robot/SAVE product loaded on their system, although they would still need to have the passphrase. Without the passphrase, there's no way to restore the tape.

Robot/SAVE also gives users flexibility in what they encrypt. They can encrypt an entire library, or just a few individual objects in a library. Object lists, IFS objects, and Domino databases can also be encrypted as part of a standard Robot/SAVE backup.

Robot/SAVE provides four encryption levels, allowing users to match their required security level with the performance hit they can afford on their OS/400 server (encryption is a processor-intensive workload for every computer). The lowest setting uses an "internally defined" algorithm and consumes the least amount of CPW, according to Help/Systems, while the medium encryption uses Data Encryption Standard (DES). (Because the company uses an IBM API for the DES encryption, company sources weren't 100 percent sure whether it was the 56-bit or the 64-bit version of the algorithm).

Two Advanced Encryption Standard (AES) encryption levels are also offered, one with a 128-bit encryption key, and one with a 256-bit encryption key that provides the most security. Robot/SAVE also maintains a secure cross-reference file of the encryption keys used to encrypt data. OS/400 shops that require the highest degree of security would do well to choose one of the recently created AES algorithms. DES, which was originally designed by IBM more than 30 years ago, has shown itself to be vulnerable to brute-force attacks.

Huntington expects the new release of Robot/SAVE will meet the burgeoning demand for encryption solutions among OS/400 shops. "It's been something that's been hot for the last year and a half," he says.

Robot/SAVE version 11 is available now. Pricing is tier-based and ranges from $7,300 to $67,500. For more information, go to www.helpsystems.com.

RELATED STORIES

Robot/SAVE Picks Up Where Bad Backups Leave Off



Sponsored By
MAGIC SOFTWARE ENTERPRISES

Design IT. Control IT. Monitor IT.

A Powerful IBM System i5 (iSeries) "Integrated Services Environment" for Use by Business Analysts

Keeping the IBM System i5 at the center of your business

Whether you are pursuing service-oriented architecture (SOA) (or simply in need of a streamlined code-free approach to cross-platform integration, web enablement and application-to-application integration), Magic Software Enterprises' iBOLT for System i5 is a secure, scalable, standards-based framework for code-free end-to-end business processes innovation:

· Deploy Existing Business Logic as New Services in a Service-Oriented Architecture
   (SOA) Paradigm
· Quickly Integrate New Web Interfaces
· Extend Processes Based on 5250 Screens
· Service-Enable RPG, COBOL, ILE and Java Routines
· Connect to iSeries Databases and Files with High Speed Gateways
· Create New Composite Processes from Available Services
· Design, Test and Monitor Using a Code-Free Visual Process Design Interface
· Reduce Risks With "Out-of-the-Box" Native System i5/iSeries/AS400 Components
· Expose Existing Business Logic as New Services in a Service-Oriented Architecture
   (SOA) Paradigm

Download the iBOLT for System i5 trial version and gain access to these features:

iBOLT Features for iSeries

Database Access
      · Physical files.
      · SQL tables.
      · SQL interface for accessing physical files.
      · Data Mapper.
Accessing iSeries Programs and Commands
      · Invoke RPG/CL/COBOL programs.
      · Run CL commands.
      · Retrieve CPF error messages.
Accessing iSeries System Services
      · Retrieve object lists.
      · Retrieve system values.
      · Retrieve and access spooler file entries.
      · Retrieve and access IFS directory files.
Built-in Open Query File Function
      · Allows record sorting on an iSeries server.
      · Allows record selection on an iSeries server.
SQL Access to Physical Files
      · Ability to use Direct SQL statements.
      · Ability to access Views, Stored procedures, triggers, and functions.
Linux (Wintel/xSeries) and AIX (pSeries) Access to iSeries
      · Communication with iSeries.
      · DB2/400 Database access.
      · iSeries command access.
      · Native iSeries program (RPG/COBOL/CL) access.
Web Process
      · Native iBOLT Server on iSeries.
      · Native iBOLT Apache Internet Requester (CGI) for iSeries.
      · Native iBOLT Apache Internet Requester (CGI and Apache module) for Linux partition
         on iSeries.
Integration/Exposure of iSeries Elements
      · iBOLT Requester API allows invocation of external processes on any other platform from
         iSeries RPG/CL/COBOL programs.
      · EJB support.
      · Web Services support.
      · Email support.
      · XML format support.
      · PDF format support.

iBOLT Data Mapper Service

iBOLT's Data Mapper Service lets you create an association between records and fields in different formats and from different sources using a Visual Mapping device. It supports multiple Sources and multiple Destinations.

You can use the Data Mapper to graphically represent the relationship between source data elements and destination data elements. This creates a way of manipulating the data without having to write any lines of code.

You define the source and destination formats in the Data Mapper Service's Source/Destination Management dialog box. The Data Mapper can carry out any of the following actions:
· Create or update files in XML, HTML, or Flat File formats.
· Create, Update, and Delete a set of database records.
· Call a flow and pass arguments.
· Any Source can be mapped to any destination.

Get the Details You Need Today:
Find out why adidas Canada and hundreds of other System i5 customers choose Magic Software Enterprises. Click here to sign up for downloads and additional information or call (800) 345-6244 ext. 205.



Editor: Alex Woodie
Contributing Editors: Dan Burger, Joe Hertvik,
Shannon O'Donnell, Timothy Prickett Morgan
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

Vision Solutions:  The Industry Standard in eServer High Availability
Profound Logic Software:  Experience RPGsp - the #1 iSeries Web development tool
COMMON:  Join us at the Fall 2006 conference, September 17-21, in Miami Beach, Florida

 


 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2008 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement