SCSI Commands: 43BSECURITY PROTOCOL IN
Page
190
Field
Bytes
Bits
Description
ENCRYPTION
MODE
5
Value from the encryption mode in the saved data encryption
parameters currently associated with the I_T nexus on which
this command was received.
DECRYPTION
MODE
6
Value from the decryption mode in the saved data encryption
parameters currently associated with the I_T nexus on which
this command was received.
ALGORITHM
INDEX
7
00h = AES-256/GCM.
KEY
INSTANCE
COUNTER
8-11 Value of the key instance counter assigned to the key indicated by
the KEY SCOPE field value.
RDMD
(Raw
decryption
mode
disabled)
12 0
Set to one if the device server is configured to mark each
encrypted record as disabled for raw read operations based on the
RDMC_C value and the raw decryption mode disable parameter in
the saved data encryption parameters. See the Set Data
Encryption page of the SECURITY PROTOCOL OUT command.
CEEMS
(Check
external
encryption
mode status)
12 2-1
Contains the value from the check external encryption mode
parameter in the saved data encryption parameters. See the Set
Data Encryption page of the SECURITY PROTOCOL OUT
command.
Key-Associated Data Descriptors List
The Key-Associated Data Descriptors List shall contain the descriptors which were present in the Set
Data Encryption page sent by the I_T nexus requesting the Data Encryption Status page. These may
include any of the following descriptors:
Authenticated
Key-
Associated
Data
Descriptor
16
bytes
Contents of the authenticated key-associated data (A-KAD)
descriptor included (if any) when the key was established in the
device server.
Unauthenticat
ed Key-
Associated
Data
Descriptor
36
bytes
Contents of the unauthenticated key-associated data (U-KAD)
descriptor included (if any) when the key was established in the
device server.
Metadata Key-
Associated
Data
Descriptor
68
bytes
Contents of the metadata key-associated data (M-KAD) descriptor
included (if any) when the key was established in the device
server.
If the currently-loaded medium does not support encryption, then the fields of the
Data Encryption Status page shall have the following values:
Field Value
Page Length
0014h
Key Scope
0h
I_T Nexus Scope
0h
Encryption Mode
0h
Decryption Mode
0h
Algorithm Index
00h
Key Instance Counter
0h
Key-Associated Data Descriptors List
None returned
Summary of Contents for LTO 4
Page 1: ......