Efficient Storage Device Header and CTE Private Region
The key sharing aspect of an ES GuardPoint requires a small amount of disk space in the storage device reserved for CTE private use. The reserved space is where CTE shares information with the storage array that is exporting the device to the protected host. The reserved space starts the beginning of the device.
The protected host writes the ES Header to the device when the device is guarded for the first time. The storage array recognizes the header written to the LUN and begins the key sharing process and encrypting/decrypting data streams transferred between the protected host and the storage array on the LUN.
CTE allocates a small amount of storage space on each device configured as CTE-Efficient Storage. This region is reserved for exclusive use by CTE and is referred to as the CTE Private Region. The CTE Private Region is 64 megabytes.
CTE stores the ES Header and other metadata information to allow CTE and the storage array to exchange information. The ES Header occupies the first sector on the device. The method that CTE uses to claim the CTE Private Region on a device depends on whether the device is new (holds no data) or has existing data that you want to preserve. CTE writes the ES Header when guarding the device for the first time. The storage array recognizes the header written to the device and begins the key sharing process for exchange of encrypted data streams between the protected host and the storage array on the device.