Encryption

Backups that reside in Amazon S3 buckets, Azure Blob storage and Google Cloud storage can be encrypted by Veeam Backup for AWS, Veeam Backup for Microsoft Azure and Veeam Backup for Google Cloud. Moreover, password for such encrypted backups may change on a daily basis. For example, there is a backup chain in Amazon S3 bucket that consists of 10 restore points, each of which was encrypted with different password. Therefore, there are 10 different passwords in total that have been used.

To be able to decrypt each restore point in such a backup chain without having to provide each previously used password separately, Veeam Backup & Replication implements the ability of backward hierarchical decryption.

Backward hierarchical decryption requires you to provide only the latest password so that all the previously created restore points can be decrypted as well. For example, there are three restore points: A, B, and C. The point A was encrypted with password 1, B with password 2, and C with password 3. Therefore, you will only need to know the password of the C point to decrypt points C, B, and A.

If you plan to perform data recovery operations with encrypted backups, you must provide a password for these backups in the External Repository wizard:

  • [For Veeam Backup for AWS] At the Encryption step of the wizard.
  • [For Veeam Backup for Microsoft Azure] At the Encryption step of the wizard.
  • [For Google Cloud Platform] At the Bucket step of the wizard.

Page updated 1/25/2024

Page content applies to build 12.1.1.56