Data-At-Rest Encryption | Teradata VantageCore with Dell ECS Object Storage - Data-At-Rest Encryption (D@RE) - Teradata VantageCore

Teradata® VantageCore with Dell ECS Object Storage - Architectural Reference Specification

Deployment
VantageCore
Edition
VMware
Product
Teradata VantageCore
Published
January 2025
ft:locale
en-US
ft:lastEdition
2025-01-22
dita:mapPath
wma1717779208646.ditamap
dita:ditavalPath
ayr1485454803741.ditaval
dita:id
wma1717779208646

Encryption of data-at-rest is recommended by Teradata, and can by achieved via server-side encryption (SSE) using Dell’s D@RE functionality.

ECS supports FIPS 140-2 only for the D@RE module and is Level 1 mode compliant using an AES 256-bit encryption algorithm.

SSE can be enabled to use D@RE at either the namespace level--such that all buckets within that namespace are encrypted by default--or it can be set at the bucket level if the namespace is not set to use SSE. When an S3 bucket is SSE enabled, the D@RE feature will ensure that all customer user data associated with objects written to it are encrypted.

Encryption using D@RE does incur some performance impacts, primarily on Reads, which can be up to 20% on 16MB object workloads.

Full details on D@RE functionality, capabilities, key management support, and best practices can be found in the Dell ECS Data at Rest Encryption (H18850.2) document, available on the Dell InfoHub. When configuring the functionality, Teradata recommends reviewing the Teradata on Dell ECS: Data Encryption at Rest Supplemental Guidance. This document is available for download from the attachment in the left sidebar.