Data inflight encryption, encrypts communication between mainframe hosts and the storage system.
It uses the Key Management Server (KMS) for key management in the same manner as data at rest encryption.
When Data inflight encryption is enabled:
- The storage system requests a shared key from the Key Management Server
- The shared key is used to encrypt Fibre Channel communication
If a Key Management Server is unavailable, the system automatically attempts to connect to the next server based on priority.
Certificate usage
The storage system uses the same key management server certificates for both data at rest encryption and data inflight encryption. Certificates that are registered with the key management server are shared across encryption functions.