Nexsan is a leading provider of next generation energy efficient disk-based storage systems.Nexsan Assureon

Archive Storage System

Nexsan Assureon

Nexsan Product
Nexsan Assureon
Nexsan Assureon Appliance Call for Pricing: 800-663-5523 Request a Quote

Click here to jump to more pricing!

AssureonOverview:

  • Compliant-level privacy, integrity and longevity
  • Self-auditing, self-healing file management technology
  • Enterprise class manageability, scalability and energy efficiency
  • Affordable: enterprise class archive to meet your needs at a price to meet your budget

Assureon®, a member of the Flexible Storage Platform™, is an archive storage system that is ideal for storage optimization, regulatory and corporate compliance, and long-term archive.

Assureon® is Nexsan's next-generation archive storage system. It is ideal for any organization that needs to implement storage optimization, regulatory and corporate compliance, or the long-term archiving of unstructured data. Unlike other competitive archiving solutions, Assureon does not require that applications be customized to use proprietary APIs in order to store their data in the archive. Users do not need to learn anything new, change how they access data or learn any new processes. Assureon archive storage systems can house from 3TB to multiple PB of unstructured data.

Assureon archive storage systems are very popular in the financial and healthcare industries; federal, state and local government organizations; as well as call centers, video surveillance and organizations with multiple remote offices.

  • Storage Optimization – offload primary storage to free up space for active data and reduce the size, time and costs of monthly full backups
  • Regulatory & Corporate Compliance – comply with governmental regulatory requirements including HIPPA, SOX and SEC-17. Enforce company data retention, privacy and protection policies
  • Long-Term Archive – store managed data for days or decades with unsurpassed integrity and protection in an easy to administer system that resides on-premise, in the cloud, or both.

Storage Optimization

Up to 80% of data on primary storage is unstructured. Due to the nature of unstructured data, it either never changes or changes infrequently. This data can be easily and transparently offloaded by an IT generalist onto a cost-effective Assureon archive storage system without any disruption to ongoing operations. In addition to freeing up space on primary storage for active data, the data on Assureon is automatically protected from day one. Assureon-protected data does not need to be repeatedly backed up during weekly full or daily incremental backups, dramatically reducing the size, time and cost of the backup process. The data on Assureon is better protected and instantly available. The space on primary storage can be freed up immediately once data is protected by Assureon. Data can also be left on primary storage for periods of high access then replaced with a shortcut or deleted after a set period of time.

Regulatory And Corporate Compliance

Assureon is ideal for organizations that must comply with governmental regulatory requirements including HIPAA, GLBA, Sarbanes-Oxley, Federal Rules of Civil Procedure (FRCP), SEC 17A-4 and PCI DSS. Assureon exceeds even the strictest regulatory requirements for data integrity, protection, privacy, security, longevity and availability with full audit trails. Additionally, Assureon makes it easy and automatic for organizations to adhere to their internal guidelines for data retention, deletion, privacy, protection and risk mitigation.

Remote And Branch Offices

It can be particularly challenging to meet corporate compliance guidelines for data that resides in remote or branch offices, which often have little or no onsite IT personnel. The easiest solution to this challenge is to place Assureon at corporate headquarters with an Assureon Edge NAS in each remote office, providing NFS and CIFS shares. All data stored on the branch office Assureon Edge is securely transmitted to the Assureon archive storage system at corporate to be archived. Alternatively, the Assureon Client is installed on branch office Windows 2003 or 2008 servers where it archives selected directories and files by transmitting them to Assureon at corporate headquarters

Long-Term Archive

The Assureon archive storage system stores data for days or decades with unsurpassed integrity and protection in an easy to administer system that resides onpremise, in the cloud or both. High availability is built into each replicated Assureon system. High speed InfiniBand connectivity is available as an optional add-on for ultimate performance. Each file is fingerprinted and stored twice within Assureon on separate RAID disk sets, or, better yet, on separate Assureon archive storage systems that are geographically separated. Background data integrity auditing uses the fingerprints and duplicate copies to ensure authentic files for days or decades without the need for administrative intervention. Self-healing integrity checks and file availability audits along with digitally signed metadata files and third-party secure time stamps work together for the utmost protection of files within Assureon. Together, this applies a verifiable chain of custody to each data set throughout the retention period.

Cloud Storage

Assureon archive storage systems are designed with multi-tenancy in mind. Online archive storage providers utilize security features such as certificate-based authentication and separate AES-256 encryption for each cloud services customer. Additionally, each file is individually encrypted with its own AES-256 key to provide the strongest separation and security of data for each client. Standard reports keep track of storage usage for each cloud services customer and enables easy import into their billing systems.

Configurations

Assureon is offered in three different hardware platforms.

Assureon Appliance Appliance – The NXR and AXR Series of Assureon archive storage system is available in a 2U package that combines both the Processing Node and Storage in a single frame. Assureon NXR includes a NAS head and provides 2.7TB of usable archive space. The Assureon AXR provides 3.8TB usable capacity.
Assureon Low Capacity Appliance Low Capacity – Small SX/SXR Series Assureon ranges in size from 3TB to 16TB in a 4U package, including the Processing Node and Storage Node.
Assureon Enterprise Appliance Enterprise – Large SX/SXR Series Assureon system ranges in size from 7TB to 56TB in 5U. Assureon can scale to multiple Petabyte by adding additional Processing Nodes and Storage Nodes.

Dual Write – Assureon is offered in Dual Write configurations only.

Single Site Assureon (SX) – In this configuration, Assureon will maintain two copies of every file within the local Assureon system. Each copy resides on a separate RAID disk set.

Replicated Assureon (SXR) – In this configuration, Assureon will maintain two copies of every file or object. One copy in each of the two replicated Assureon systems are typically geographically separated for the greatest protection but may be optionally used across campus or at the same location.

Hosted Assureon (HXR) – In this configuration, a local Assureon will maintain a single copy of the data while a second copy of the data is replicated to a remote, multi-tenancy Assureon. Typically, the second Assureon resides at an Assureon-as-a- Service cloud provider or in a corporate cloud.

Advanced Features:


Automated Auditing ProcessesIntegrity

  • Fingerprints – Each time a file is saved, a unique fingerprint is generated using both an MD5 and SHA1 hash of its contents and metadata, so history and contents cannot be altered after the fact (WORM storage)
  • Serial Numbers – Each file is assigned a serial number which is used to ensure no files are missing or inappropriately added
  • Secure Time – Tampering with the system time clock is prevented by using a global, redundant, secure time source (Stratum Level I hardware time sources
  • Two Copies – Each file and its fingerprint are stored twice in the Assureon. The second copy is either stored in a separate RAID disk set in the same Assureon or on a remote Assureon
  • Data Verification – Files are continually verified against their fingerprints, repaired using their copies and safeguarded by RAID disk arrays for days or decades

Scalability and High Availability

  • Remote Replication – Two active Assureon systems can continuously replicate to each other to protect against a site failure
  • Failover/failback – Native active/active replication protects against site disasters with automatic read failover and manual write failover
  • Performance & Capacity – Scale capacity up to multiple petabytes and add performance by using multiple Assureon archive storage systems together
  • InfiniBand – Optional High Speed Assureon with InfiniBand connectivity provides blazingfast retrieval of data from the Assureon archive

Privacy

  • Separation of Data – Assureon provides complete separation of data between departments or projects using logical and physical separation as well as separation through the use of multiple AES-256 encryption keys
  • Encryption – Files can be AES-256 encrypted. Keys for a replicated Assureon are stored safely at 4 sites by the integrated key management system. A nominal annual key management subscription is required
  • Authentication – Users are authenticated with Active Directory or digital certificates
  • Audit Trails – Audit trails report on file access and denied access attempts

Regulatory and Corporate Compliance

  • Government Regulations – Meet regulatory mandates (e.g., Federal Rules of Civil Procedure (FRCP), SOX, SEC-17, HIPAA, GLBA and PCI DSS)
  • Data Retention – Easily create retention rules and associate them with unstructured data directories or file types
  • Legal Hold – A legal hold can be easily placed on any set of files, overriding their original retention periods until the hold is removed
  • One System – Data sets can be retained for a period of time that can be extended but not shortened. Other data sets can be assigned a flexible retention period that can be lengthened or shortened to accommodate both needs in the organization
  • Data Deletion – Industry-leading single-pointdeletion deletes all copies by destroying the encryption key for the file and deleting all copies of the file. Optional DoD wipe of the drive is also available on a per-object granularity

Easy to Manage

  • Automatic Archive – Assureon Windows Client moves files from Windows Servers to the Assureon and can leave the original file in place or optionally leave a shortcut behind
  • NAS (NFS/CIFS) – Assureon Edge presents a CIFS/NFS NAS interface to users and applications and stores all files on Assureon. Both replicated and Clustered NAS configurations are available
  • Fast, Easy Deployment – The Assureon Client can be installed on Windows Server 2003 or 2008 with no reboot required. Once the archiving policies are established, files and folders are archived, completely transparent to applications and users
  • Global Management – Single pane-of-glass management of all local and remote Assureon
  • Utmost Data Protection – Protecting data with Assureon has many advantages over traditional backups including WORM, single file deletion, greater reliability and availability, and near instantaneous restores to dramatically reduced RTO
  • Authentication – Assureon uses Microsoft Active Directory for authentication in the enterprise and can preserve folderlevel NTFS permissions; it can also use certificates for authentication in Linux or Unix environments, standalone Windows servers or when it is used for a multi-tenancy cloudbased online archive
  • Reports – Standard reports keep track of storage usage for bill back of cloud services customers or within an individual customer bill back for projects or departments
  • Four levels of monitoring – Automated monitoring via system state thresholds, node events, Assureon Client and self-healing file integrity and availability audits
  • Lights-out Management – Self-managing Assureon issues alerts when something needs attention

Easy to Use

  • Non-disruptive – Users and applications do not need to change to work with Assureon. An application running on a Windows 2003 or 2008 server can have its data securely archived, freeing up primary storage while the application is in production
  • Prior Versions – Prior versions of files are easily retrieved by administrators
  • Assureon Explorer – A web-based GUI makes it easy to search the entire archive with role-based restrictions for instant access. Metadata search is included with all Assureon systems. Optional file content indexing and searching is available as an Assureon Content Index Search node for typical files such as office, textual PDF files, text files, html files, xml files, etc.

Efficient

  • Free Primary Storage – Files moved to Assureon free up primary storage
  • Reduce Backups – Archived folders can be removed from the backup stream, significantly reducing the size of full backups. The result is a very fast return on investment based on savings of labor, hardware, media and time
  • Fast Restores – Hyper speed restores replace small shortcuts rather than the actual file contents to meet even the toughest Recovery Time Objectives (RTO)
  • Power Savings – AutoMAID energy saving technology reduces power consumption by up to 60% while maintaining fast response
  • Less Space Needed – Single-instance storage technology eliminates duplicate files, saving 20-60% on typical mid-sized organization's Assureon capacity requirements

Cloud-Ready

  • Multi-tenancy – Multi-tenancy features enable service providers to offer highly secure Archive-as-a-Service with logical, physical and encryption data separation
  • Online Archive – An on-premise Assureon can replicate to a cloud-based Assureon powered archive service. Assureon supports one-to-one and manyto- one replication

Features & Benefits:

Features Benefits
Assureon Client Copies or moves files from Windows onto the Assureon, leaving a small shortcut file behind.
Hyper speed Restores Because restores only require the shortcut files to be restored, time is significantly reduced.
CIFS/NFS NAS Interfaces via Assureon Edge Easy to use for all Windows and UNIX/Linux users and applications without changes being required. No development or use of special APIs are needed.
Fingerprinting When a file or object is archived, it is fingerprinted, so its history and contents cannot be altered after the fact (WORM).
Encryption Each file can be optionally encrypted with a unique AES-256 encryption key to ensure security. Three copies of the key exist: one onsite and two at separate remote managed locations.
File Integrity Checks Files are stored twice, and a background process continually scans files and repairs them, using their copies even if they are not being accessed, if necessary.
Active / Active Replication Replicated Assureons are active/active, meaning that as long as both are healthy, they can service different requests, providing increased utilization of resources over active/passive architectures.
Active / Active Ingestion Assureon allows for ingestion of data at two sites in a replicated configuration.
Cloud-based Archiving An Assureon can be configured as a Virtual Assureon. This allows for multiple secure applications, departments or even separate companies to operate with complete physical, logical and encryption separation. It is an ideal cloud platform to offer Archive-as-a-Service.
Active Directory Integration Assureon uses Active Directory integration to authenticate users
Certificate-based Authentication Certificate-based authentication can be used as an alternative to Active Directory authentication.
Powerful Search Assureon Explorer, a web-based GUI permits easy searches of the entire archive with role-based restrictions. The Assureon Explorer also allows end users to restore their own files, if allowed by access and disposition policy.
Management Console Single-pane-of-glass web-based management with role-based security.
Audit Trails Track all users that were permitted or denied file access.
Retention Policies Assureon makes it easy to define retention policies and to associate those policies to folders that are being archived for compliant and non-compliant environments.
Single-instance Storage Identical files are only stored once, saving disk space and increasing performance.
Legal Hold Assureon provides legal holds that can override retention policies.
File Versioning Assureon can support multiple versions of a file and is configuraable by the administrator.
AutoMAID AutoMAID is the industry's most sophisticated power management system. Drives containing infrequently accessed data can be powered down when not being for significant energy savings. For more on AutoMAID

AutoMAIDAutoMAID™ Energy Saving Technology:

Nexsan's evolutionary AutoMAID (Automatic Massive Array of Idle Disks) energy saving technology transparently places disk drives into an idle state to vastly reduce power and cooling costs. AutoMAID delivers the cost-effecdtive benefits of MAID 2.0 without the limitations of slow access times and special host software.

AutoMAID is granular to an individual drive or RAID set and offers multiple levels of energy savings. AutoMAID is user selectable enabling users to determine the right level of response time performance to energy savings. AutoMAID is the first MAID 2.0 architecture that supports VTL, full file format D2D and standard high performance RAID implementations.

Key Points

  • AutoMAID reduces power and cooling costs
  • Nexsan’s AutoMAID delivers the benefits of MAID without the limitations
  • Available on Nexsan Assureon, SATABoy, SATABeast, and SATABeast Xi

AutoMAID Defined

  • AutoMAID automatically reduces power consumption and heat generation on idle drives
  • Trade-off between response times and power savings are user configurable
  • AutoMAID behavior happens automatically and transparently to host – no software changes required
  • Typical configuration settings:
    • Level 1: Heads Unloaded
      • 15% to 20% savings
      • Sub-second recovery time
    • Level 2: Heads Unloaded, slows to 4000 RPM
      • 35% to 45% savings
      • 15 second recovery time
    • Level 3: Stops spinning (sleep mode; powered on)
      • 60% to 70% savings
      • 30 to 45 second recovery time

AutoMAID Safety Features

  • In maximum power saving mode, drive spin up is sequenced to reduce power surges
  • Drives automatically wake up for periodic surface scan to ensure data integrity (user configurable)
  • AutoMAID has no impact on performance if left on in data-intensive server applications
  • Only two simple configuration settings – "timeout" and "power savings desired"

SATABeast AutoMaid    SATABeast AutoMaid

Technical Specifications:

Assureon Front View
Front View
Assureon Rear View
Rear View

Power Requirements Specifications
Model Required Watts Peak Sustained Watts Heavy Load Watts
AS-SX6 893 443 660
AS-SX14 1343 723 910
AS-SX28 1543 1023 1260
AS-SXR3 (per each site) 463 148 286
AS-SXR6 (per each site) 893 443 660
AS-SXR14 (per each site) 943 533 690
AS-SXR28 (per each site) 1123 723 880
AS-SXRL42 (per each site) 1243 823 980
AS-SXRL56 (per each site) 1493 923 1080
Deployed Weigths Specifications
Model lbs Kgs
AS-SX6 133.76 60.80
AS-SX14 172.04 78.20
AS-SX28 207.90 94.50
AS-SXR3 (per each site) 78.10 35.50
AS-SXR6 (per each site) 133.76 60.80
AS-SXR14 (per each site) 141.68 64.40
AS-SXR28 (per each site) 168.08 76.40
AS-SXRL42 (per each site) 189.86 86.30
AS-SXRL56 (per each site) 207.90 94.50
Dimensions Specifications
Model inches mm
AS-SX6 4 EIA Units
Storage (133/520/430)
Server (1.69/30.39/18.98)
4 EIA Units
Storage (133/520/430)
Server (43/772/482)
AS-SX14 5 EIA Units
Storage (6.97/29.53/16.93)
Server (1.69/30.39/18.98)
5 EIA Units
Storage (177/750/430)
Server (43/772/482)
AS-SX28 5 EIA Units
Storage (6.97/29.53/16.93)
Server (1.69/30.39/18.98)
5 EIA Units
Storage (177/750/430)
Server (1.69/30.39/18.98)
AS-SXR3 (per each site) 2 EIA Units
Storage (N/A)
Server (3.39/26.81/17.44)
2 EIA Units
Storage (N/A)
Server (86/681/443)
AS-SXR6 (per each site) 4 EIA Units
Storage (133/520/430)
Server (1.69/30.39/18.98)
4 EIA Units
Storage (133/520/430)
Server (1.69/30.39/18.98)
AS-SXR14 (per each site) 5 EIA Units
Storage (6.97/29.53/16.93)
Server (1.69/30.39/18.98)
5 EIA Units
Storage (177/750/430)
Server (43/772/482)
AS-SXR28 (per each site) 5 EIA Units
Storage (6.97/29.53/16.93)
Server (1.69/30.39/18.98)
5 EIA Units
Storage (177/750/430)
Server (43/772/482)
AS-SXRL42 (per each site) 5 EIA Units
Storage (6.97/29.53/16.93)
Server (1.69/30.39/18.98)
5 EIA Units
Storage (177/750/430)
Server (43/772/482)
AS-SXRL56 (per each site) 5 EIA Units
Storage (6.97/29.53/16.93)
Server (1.69/30.39/18.98)
5 EIA Units
Storage (177/750/430)
Server (43/772/482)

Technology:

Assureon is based upon a combination of CAS (Content Addressable Storage) with advanced 256-bit AES encryption and other security and data protection technologies. CAS technology produces a unique file identifier or "fingerprint" for all objects, based on their content. Assureon's object storage model stores files, images, recordings, web pages, etc, as objects with a unique universal identifier. This approach differs from traditional file system models, where an application or user names the file and then places it in a hierarchical file system. Traditional file system models suffer from a lack of scalability and a high management cost.

In an object model, the archived physical object is completely separate from the logical location or application. Administrators can be relieved of performing typical storage housekeeping tasks, such as formatting file systems, creating volumes and binding LUNs (logical unit numbers).

Assureon's CAS technology provides:

Immutability - because each file fingerprint is based on the specific bit pattern of that file, if a bit is changed then the file fingerprint would be different. Assureon does not allow changes and will detect if any tampering has occurred.

Single-instance storage - one copy of each file is stored, regardless of how many users write that file to storage, giving significant storage-use efficiency.

Scalability - Additional storage can easily be added

Reduces Storage Management Cost - Storage housekeeping tasks, such as formatting file systems, creating volumes and binding LUNs are not necessary

Load Balancing - Enables a uniform distribution of files across available storage locations. Assureon's load balancing enhances performance and enables storage to scale into the petabytes

Assureon uses a dual cryptographic process (MD5 and SHA-1 hashing algorithms) to create its unique file identifier (UFID). The dual cryptographic process offers fail safe security against the occurrence of a collision.

Encryption with patent-pending secure encryption key management

Encryption a powerful tool to ensure privacy and protect against data theft. Assureon implements encryption on a file by file basis using the AES256 encryption standard. Each file has its own unique key, which is transparently and automatically handled by Assureon's secure "key manager."

Secure Key Management: The management of encryption keys is critical to data protection. Key management needs to be secure from attack and also from inadvertent corruption by insiders or physical theft of the hardware that contains the keys. Assureon's advanced, automated encryption key management system has a unique quadruple backup process safeguarding the keys against disaster. Assureon provides support for multiple offsite repositories of keys, which are themselves encrypted, as well as active deposits of file manifest information at secure locations or with a neutral third party.

Scalability - Assureon's performance and capacity scale independently

Assureon's architecture is not a "pizza box or brick" design whereby a certain number of server nodes need to be configured based upon the amount of storage and the two are locked together - if you want to scale capacity you must also scale performance. Assureon is flexible. Storage capacity can be vastly increased if needed and more server nodes can be added to the configuration for faster performance independent of each other. This allows the customer to purchase exactly what they need for their environment and, in the case of a large archive, reduces the cost per terabyte dramatically.

Media Independence

In addition to disk, Assureon supports offline media such as tape and optical. By combining CAS single instance store technology with secure encryption on removable media, Assureon reduces costs and prevents any unauthorized access to stored data including security breaches, attacks and lost or stolen media.

Security:

Compliance and Best Practices require Better Security

Information and storage security are very important topics - privacy and data theft are at the forefront of today's customer concerns. In addition, many regulations such as Sarbanes-Oxley, Privacy Acts, and HIPAA, spell out specific requirements for secure information access and data storage.  Assureon offers powerful answers to these important requirements through the integrated technologies it is built upon - security, file disposition, the individual destruction of offline files, WORM protection and file authentication.

Encryption

Assureon can encrypt any file, using the Advanced Encryption Standard (AES256). There have been no successful attacks against AES, and it has been approved by the National Security Agency (NSA) for top secret documents. Multiple Privacy Acts, HIPAA, California 's SB 1386 and the FDA's CFR part 11 recommend or require encryption of information for security purposes. When Assureon encryption is enabled, files cannot be viewed even if a hacker manages to compromise security.

Secure Accessibility

Assureon's Access Control has three components.

  1. Authentication verifies that a client is who they say they are
    • Assureon optionally uses security certificates (Smart Cards)
  2. Authorization determines that the client has the appropriate permissions to access the resources they are requesting. Authorization is given to an authenticated client by policies established within Assureon and then published into Active Directory.
  3. Audit logs that can be used to account for any and all access to managed information.

Assured Individual Key Destruction

At the end of an information asset's retention period, Assureon destroys the file's encryption key and all access to that file.  Assureon is unique in its key management capabilities in that it can identify and dispose of individual files  - not only on its integrated disk storage, but also on offline media such as tape or optical.

Authentication of Information

When a file is placed under Assureon management, it is processed by dual cryptographic hash functions (MD5 and SHA-1) to create a unique identifier sometimes called hash value, digital fingerprint, CAS (Content Addressable Storage) address or UFID. This unique identifier allows the system to verify that the file has not been altered or inadvertently corrupted.

When a file is authenticated, Assureon retrieves the file, creates a cryptographic hash value for the document, and then compares it to the original cryptographic hash value that was generated when the file was placed under management. If any changes were made to the document, even down to the bit level, the hash values will not be the same and the file is not authenticated; if the hash values are identical, the file is authenticated as an original. This process ensures the authenticity and integrity of all files stored by the Assureon system.

Management:

Management Made Easy

You can manage all local and remote Assureons from a single-pane-of-glass with Assureon's built-in web-based management GUI. Users and administrators are authenticated by Active Directory or via digital certificates to provide easy to use role-based administration.

Restores for servers that are being archived are lightening fast as only the shortcut files left behind need to be restored - not the entire file contents.

The system can be configured to constantly audit its files and repair them, if necessary, without the need for user intervention. Once Assureon is installed in a replicated configuration, they run continuously to automatically protect from data loss due to a disaster or malicious intent.

Support:

Hardware NBD On-Site Support
Next Business Day support provides Monday through Friday, 8:00AM – 5:00PM (your local time excluding Nexsan holidays) on-site service with "Next Business Day" response. Replacement parts are shipped via overnight service and if requested, a service representative will be onsite between 8:00AM – 5:00PM the following business day.

Software Business Day Support
Business day access to the Nexsan technical support is the standard level subscribed for Assureon

Hardware 7x24 On-Site Support
On-site 7x24support is available, providing a 4 hour response for customers within a certain distance of a repair center. Replacement parts are hand delivered with a service representative that will be onsite within 4 hours following diagnosis of hardware failure.

Software 7x24 Support
For your convenience 24 x7 access to the Nexsan technical support team is available.

Note: On-site service may not be available in all areas

Documentation:

PDF File
Nexsan Assureon Datasheet (.PDF)

Nexsan Product
Nexsan Assureon
Nexsan Assureon Appliance Call for Pricing: 800-663-5523 Request a Quote