SCSI Commands: 44BSECURITY PROTOCOL OUT
Page
196
Field
Bytes
Bits
Description
SECURITY
PROTOCOL
SPECIFIC
2-3
0010h = Set Data Encryption page
INC_512 4 7
Always 0, indicating that the Allocation Length is expressed in
bytes.
TRANSFER
LENGTH
6-9
Length of data-out in bytes.
Reserved
All reserved bits must be 0.
Control
5
The control field must be 0.
3.32.2
Set Data Encryption page
The Set Data Encryption page is used to control the encryption and decryption
operation of the device server, including passing the key.
Byte
Bits
7 6 5 4 3 2 1 0
0
(MSB)
1
PAGE CODE (0010h)
(LSB)
2
(MSB)
3
PAGE LENGTH (n-3)
(LSB)
4
SCOPE Reserved
LOCK
5
CEEM RDMC
SDK
CKOD
CKORP
CKORL
6
ENCRYPTION MODE
7
DECRYPTION MODE
8
ALGORITHM INDEX
9
KEY FORMAT
10
17
Reserved
18
(MSB)
19
KEY LENGTH (0020h)
(LSB)
20
(MSB)
51
KEY
(LSB)
52
n
KEY-ASSOCIATED DATA DESCRIPTORS LIST
If the Encryption Mode is DISABLE or EXTERNAL and the Decryption Mode is
DISABLE or RAW, then no key is needed and the Key Length may be set to zero
and the key field not included. If it is included, then it will be ignored. However, if
Encryption Mode is ENCRYPT or Decryption Mode is either DECRYPT or MIXED,
then a key is required. If it is required but not present, then the device server shall
terminate the command with CHECK CONDITION status, with the sense key set to
ILLEGAL REQUEST, and the additional sense code set to INVALID FIELD IN
PARAMETER DATA.
If the Encryption Mode is DISABLE, then the Key-Associated Data Descriptors list
may be excluded. If any descriptors are included, then they are ignored.
If the Encryption Mode is EXTERNAL, then the Key-Associated Data Descriptors list
shall include a metadata key-associated data (M-KAD) descriptor. If any other
descriptors are included, then they are ignored.
Summary of Contents for LTO 4
Page 1: ......