![Cactus 910S Series Product Manual Download Page 28](http://html1.mh-extra.com/html/cactus/910s-series/910s-series_product-manual_3232568028.webp)
Cactus Technologies, Limited
Once the erase operation has started, it cannot be interrupted. If the device is powered off
while a quick erase operation is in progress, upon the next power up, the drive will resume
the erase operation from where it left off when power was lost.
The erase procedure used by default is DoD-5220. The time it takes to complete varies by
drive capacity but will generally between 20-30mins.
An optional quick erase procedure is supported, which will typically take around 30-60s to
complete. Customers who wish to use this erase procedure instead of the default DoD-5220
should contact the factory for details.
7.2. AES256 Hardware Encyrption
Cactus Technologies
®
-910S-P1 series SSDs support hardware AES256 encryption/decryption.
A unique feature of the implementation of encryption in the -910S-P1 series SSDs is that the
encryption key is not saved in non-volatile storage on the drive, thus there is no possibility of
the key being retrieved/hacked by 3
rd
party if the drive is stolen.
The features of the hardware encryption are as follows:
•
host sends over encryption key to the drive via a Vendor Specific command
•
the drive will generate a hash sum from the key and store this hash sum to reserved
area in the drive;
•
The encryption key is stored only in volatile DRAM and will be erased once the drive is
powered off
•
once the key has been accepted by the device, host will power cycle the drive which
will enable the encryption and drive locking features
•
once encryption is enabled, host must resend encryption key on power up; a hash
sum is generated from the key and verified against the hash sum stored in the
reserved area; decryption function is enabled only if the hash sums matches
•
if incorrect key is entered three times in a row, an automatic secure erase will be
triggered and all user data on the drive will be erased
•
once encryption is enabled, the only way to disable it is via a ATA Security Erase
operation, which will result in all user data being erased also
7.2.1.
Vendor Specific Command
To enable encryption function, host needs to issue the following Vendor Specific command to
the drive:
7
6
5
4
3
2
1
0
Features
N/A
Cactus Technologies Limited
Industrial Grade -910S/910S-P1 Series SSD Product Manual
v2.2
28