Whenever you read data it will need to be decrypted and that may have impact on performance, but modern solution usually relay on fast HW based cards sitting between disk and software layer like application so impact is much less to be of any concern. If using software based encryption it might have some impact, but it shouldn't be that high nowadays. I guess, before you go live you will have proof of concept and test of this kind involving backup and restore should be performed and compared.
You didn't say how it will be encrypted in first place, but I assume same process which encrypts data during write will run decrypt during read and this should be automatic.
As it is - where? On disk from OS or application point of view, on disk array from its point of view? If you are transferring data from A to B, which is what you do with backup, then either this is done online where you must decrypt it or offline where you do not have necessary do that, but such backup would be offline (eg. snapshot of encrypted data on disk from OS/application point of view) and could only be restored by original client most likely (in presence with original crypt routine).
ble1
6 Operator
•
14354 Posts
•
56186 Points
3022
0
Posted July 29th, 2014 02:00
Data at rest on backup storage side or primary storage?