
Self-Encrypting Drive
Self-Encrypting Drive
The HPE MR Gen10 Plus Controller supports Self-Encrypting Drive (SED) that secures the drive data from unauthorized access or
modification of data. As the data on the drive is encrypted even if the SED drive is removed from its storage system, it cannot be
accessed without appropriate security authorization.
Passive Key Management
Passive Key Management
To use passive key management, enable the SED drive as JBOD and expose the drive to OS. This method allows you to manage SED
using third-party key management like SEDutil. SED monitoring is also available in MR Storage Administrator, Storage Command Line
Interface (StorCLI) tool, and configuration utility in UEFI System Utilities..
Local Key Management
Local Key Management
You can enable SED drive security for local key management using the MR Storage Administrator, StorCLI tool, and configuration utility
in UEFI System Utilities. You must provide a controller-wide security key identify and security key. While boot up, the security key
stored in the controller is used to unlock the drive. Whenever the drive is powered down, the security enabled drive data encryption key
is locked. This action protects the drives or systems against any theft.
Remote Key Management
Remote Key Management
Remote key management is also known as external key management.
NOTE:
NOTE:
You can enable SED drive security for remote key management using the configuration utility in UEFI System Utilities.
For more information, see Enabling Drive Security.
The configuration utility in UEFI System Utilities works with iLO key manager to create the security key identify and security key in the
remote key manager server. iLO key manager needs to be configured before enabling remote key management in the configuration
utility. Whenever the drive is powered down, the security enabled drive data encryption key is locked. While boot up, the security key is
retrieved from the remote key manager server to unlock the drive.
Self-Encrypting Drive
72
Summary of Contents for MR Gen10 Plus
Page 10: ...Features Features 10 ...
Page 19: ...RAID technologies RAID technologies 19 ...
Page 26: ...Striping Striping 26 ...
Page 28: ...Mirroring Mirroring 28 ...
Page 32: ...Parity Parity 32 ...
Page 45: ...Spare drives Spare drives 45 ...
Page 50: ...Transformation Transformation 50 ...
Page 51: ...Array transformations Array transformations 51 ...
Page 54: ...Logical drive transformations Logical drive transformations 54 ...
Page 58: ...Drive technology Drive technology 58 ...
Page 66: ...Security Security 66 ...
Page 68: ...Simple A Simple erase writes a pattern to the logical drive in a single pass Simple 68 ...
Page 73: ...Reliability Reliability 73 ...
Page 76: ...Performance Performance 76 ...
Page 80: ...Cache Cache 80 ...
Page 98: ...Configuration Configuration 98 ...
Page 106: ...Configuration management Configuration management 106 ...
Page 117: ...Controller management Controller management 117 ...
Page 119: ...Advanced controller management Advanced controller management 119 ...
Page 137: ...Logical drive management Logical drive management 137 ...
Page 143: ...Drive management Drive management 143 ...
Page 155: ...Maintenance Maintenance 155 ...
Page 156: ...System maintenance tools System maintenance tools 156 ...
Page 160: ...Models Models 160 ...
Page 172: ...Support and other resources Support and other resources 172 ...