background image

Seagate BarraCuda Product Manual, Rev. F

  27

 About (SED) Self-Encrypting

 

5.0

About (SED) Self-Encrypting Drives

Self-encrypting drives (SEDs) offer encryption and security services for the protection of stored data, commonly known as "protection of data at 
rest." These drives are compliant with the Trusted Computing Group (TCG) Opal Storage Specifications as detailed in the following:

Trusted Computing Group (TCG) Documents (apply to Self-Encrypting Drive models only)

TCG Storage Architecture Core Specification, Version 2.0
TCG Storage Security Subsystem Class Opal Specification, Version 2.0
(see 

www.trustedcomputinggroup.org

)

In case of conflict between this document and any referenced document, this document takes precedence.

The Trusted Computing Group ( TCG) is an organization sponsored and operated by companies in the computer, storage and digital 
communications industry. Seagate's SED models comply with the standards published by the TCG.

To use the security features in the drive, the host must be capable of constructing and issuing the following two SATA commands:

• Trusted  Send
• Trusted  Receive

These commands are used to convey the TCG protocol to and from the drive in their command payloads.

5.1

Data Encryption

Encrypting drives use one inline encryption engine for each drive employing AES-256 data encryption in Cipher Block Chaining (CBC) mode to

 

encrypt all data prior to being written on the media and to decrypt all data as it is read from the media. The encryption engine is always in operation

 

and cannot be disabled.

The 32-byte Data Encryption Key (DEK) is a random number which is generated by the drive, never leaves the drive, and is inaccessible to the host 
system. The DEK is itself encrypted when it is stored on the media and when it is in volatile temporary storage (DRAM) external to the encryption

 

engine. A unique data encryption key is used for each of the drive's possible16 data bands (see 

Section 5.5, Data Bands

).

5.2

Controlled Access

The drive has two security providers (SPs) called the "Admin SP" and the "Locking SP." These act as gatekeepers to the drive security services. 
Security-related commands will not be accepted unless they also supply the correct credentials to prove the requester is authorized to perform the

 

command.

5.2.1

Admin SP

The Admin SP allows the drive's owner to enable or disable firmware download operations (see 

Section 5.4, Drive Locking

). Access to the Admin

 

SP is available using the SID (Secure ID) password or the MSID (Manufacturers Secure ID) password.

5.2.2

Locking SP

The Locking SP controls read/write access to the media and the cryptographic erase feature. Access to the Locking SP is available using the Admin

 

or User passwords.

5.2.3

Default password

When the drive is shipped from the factory, all passwords are set to the value of MSID. This 32-byte random value can only be read by the host 
electronically over the interface. After receipt of the drive, it is the responsibility of the owner to use the default MSID password as the authority to

 

change all other passwords to unique owner-specified values.

5.2.4

ATA Enhanced Security

The drive can utilize the system's BIOS through the ATA Security API for cases that do not require password management and additional security

 

policies.

Furthermore, the drive's ATA Security Erase Unit command shall support both Normal and Enhanced Erase modes with the following modifications/
additions:

Normal Erase:

 Normal erase feature shall be performed by changing the Data Encryption Key (DEK) of the drive, followed by an overwrite

 

operation that repeatedly writes a single sector containing random data to the entire drive. This write operation bypasses the media encryption. On

 

reading back the overwritten sectors, the host will receive a decrypted version, using the new DEK of the random data sector (the returned data will 
not match what was written).

Enhanced Erase:

 Enhanced erase shall be performed by changing the Data Encryption Key of the drive.

Summary of Contents for ST1000LM038

Page 1: ...Standard models ST2000LM015 ST1000LM048 ST500LM030 SED FIPS 140 2 models ST2000LM010 ST1000LM038 ST500LM033 Self Encrypting Drive SED models ST500LM032 100807728 Rev F October 2017 SATA Product Manual...

Page 2: ...e Actual data rates may vary depending on operating environment and other factors The export or re export of hardware or software containing encryption may be regulated by the U S Department of Commer...

Page 3: ...16 2 9 Acoustics 16 2 9 1 Test for prominent discrete tones PDTs 16 2 10 Electromagnetic Immunity 17 2 10 1 DC Magnetic Field Immunity 17 2 11 Reliability 18 2 11 1 Data loss under power interruption...

Page 4: ...2 1 Admin SP 27 5 2 2 Locking SP 27 5 2 3 Default password 27 5 2 4 ATA Enhanced Security 27 5 3 Random Number Generator RNG 28 5 4 Drive Locking 28 5 5 Data Bands 28 5 6 Cryptographic Erase 28 5 7 Au...

Page 5: ...ure 2 Typical 2D 5V Startup and Operation Current Profile 13 Figure 3 Attaching SATA Cabling 22 Figure 4 Mounting Dimensions for 1 disk models 23 Figure 5 Mounting Dimensions for 1 disk models alterna...

Page 6: ...r information regarding Warranty Support visit http www seagate com support warranty and replacements For information regarding data recovery services visit http www seagate com services software reco...

Page 7: ...magnetic recording with perpendicular magnetic recording heads media State of the art cache and on the fly error correction algorithms Support for Read Multiple and Write Multiple commands Support fo...

Page 8: ...ing system views the two devices as if they were both masters on two separate ports This essentially means both drives behave as if they are Device 0 master devices The Serial ATA host adapter and dri...

Page 9: ...sical Recording density 2276 Kb in Track density 580 Ktracks in avg Areal density 1320 Gb in2 avg Spindle speed 5400 RPM Maximum sustained data rate OD read 140 MB s Interface SATA 6Gb s ATA data tran...

Page 10: ...www seagate com support warranty and replacements From this page click on the Is my Drive under Warranty link The following are required to be provided the drive serial number model number or part num...

Page 11: ...s Recording method Perpendicular Recording density 2276 Kb in Track density 580 ktracks in avg Areal density 1320 Gb in2 avg Spindle speed 5400 RPM Data transfer rate up to 140 MB s Height mm in 7 0 0...

Page 12: ...Write current is measured with the heads on track based on three 64 sector read or write operations every 100 ms The drive supports three idle modes Performance Idle mode Active Idle mode and Low Pow...

Page 13: ...uct Manual Rev F 12 Drive Specifications 2 7 1 1 Typical current profiles The typical 5V startup and operation current profile is shown in Figure 1 and Figure 2 Figure 1 Typical 1D 5V Startup and Oper...

Page 14: ...Seagate BarraCuda Product Manual Rev F 13 Drive Specifications Figure 2 Typical 2D 5V Startup and Operation Current Profile...

Page 15: ...s are parked and the spindle is at rest The drive accepts all commands and returns to Active mode when disk access is necessary n Sleep mode The drive enters Sleep mode after receiving a Sleep command...

Page 16: ...s 2 8 1 2 Non operating shock The non operating shock level that the drive can experience without incurring physical damage or degradation in performance when subsequently put into operation is 1000 G...

Page 17: ...s for steady state idle and active seeks modes of operation 2 9 1 Test for prominent discrete tones PDTs Seagate follows the ECMA 74 standards for measurement and identification of PDTs An exception t...

Page 18: ...4 5 95 Conducted RF immunity 150 kHz to 80 MHz 3 Vrms 80 AM with 1 kHz sine A EN 61000 4 6 97 Power Frequency H field immunity 1 A m 50Hz 60Hz 3 axes A EN 61000 4 8 97 Voltage dips interrupts 30 Redu...

Page 19: ...oltage Directive LVD 2014 35 EU Seagate drives are tested in representative end user systems Although CE marked Seagate drives comply with all relevant regulatory requirements and standards for the dr...

Page 20: ...on page 21 2 12 8 FCC verification These drives are intended to be contained solely within a personal computer or similar enclosure not attached as an external device As such each drive is considered...

Page 21: ...and materials Our supplier contracts require compliance with our chemical substance restrictions and our suppliers document their compliance with our requirements by providing full disclosure materia...

Page 22: ...sive chemicals as electronic drive component reliability can be affected by the installation environment The silver copper nickel and gold films used in Seagate products are especially sensitive to th...

Page 23: ...TA signal cable can be attached to the drive or host For direct backplane connection the drive connectors are inserted directly into the host receptacle The drive and the host receptacle incorporate f...

Page 24: ...080 in 2 032 mm minimum screw engagement recommended Avoid excessive drive distortion when mounting Refer to the following specifications for stiffness deflection information Figure 4 Mounting Dimensi...

Page 25: ...00 350 0 200 0 250 69 850 0 250 2 499 1 270 7 949 1 270 16 520 22 450 90 600 14 000 2X 3 000 7 000 0 200 2X M3 X 0 5 6H MOUNTING HOLES BOTH SIDES 4MM MIN SCREW DEPTH FROM M3 PADS NO THRU 3 5 075 3X90...

Page 26: ...20 0 25 69 850 0 250 22 450 16 520 7 949 1 270 2 499 1 270 90 600 14 000 2X 3 000 BOTH SIDES 7 000 0 200 BASE 13 430 3 500 2X M3 X 0 5 6H MOUNTING HOLES BOTH SIDES 4MM MIN SCREW DEPTH FROM M3 PADS NO...

Page 27: ...Policy document uploaded on the NIST website To reference the product certification visit http csrc nist gov groups STM cmvp documents 140 1 1401vend htm and search for Seagate Security Level 2 Securi...

Page 28: ...the drive s possible16 data bands see Section 5 5 Data Bands 5 2 Controlled Access The drive has two security providers SPs called the Admin SP and the Locking SP These act as gatekeepers to the drive...

Page 29: ...n key for a particular band Once changed the data is no longer recoverable since it was written with one key and will be read using a different key Since the drive overwrites the old key with the new...

Page 30: ...Notes below Notes 1 All pins are in a single row with a 1 27 mm 0 050 in pitch 2 The comments on the mating sequence apply to the case of backplane blindmate connector only In this case the mating seq...

Page 31: ...Cache E7h Flush Cache Extended EAh Identify Device ECh Initialize Device Parameters 91h Read Buffer E4h Read DMA C8h Read DMA Extended 25h Read DMA without Retries C9h Read Long with Retries 22h Read...

Page 32: ...rusted Receive 5Ch SED only Trusted Receive DMA 5Dh SED only Trusted Send 5Eh SED only Trusted Send DMA 5Fh SED only Write Buffer E8h Write DMA CAh Write DMA Extended 35h Write DMA without Retries CBh...

Page 33: ...l heads 16 4 Retired 0000H 5 Retired 0000H 6 Number of logical sectors per logical track 63 003FH 7 9 Retired 0000H 10 19 Serial number 20 ASCII characters 0000H none ASCII 20 Retired 0000H 21 Retired...

Page 34: ...IO cycle time with IORDY flow control 120 ns 0078H 69 Additional Supported bits Bit 4 means Device Encrypts All User Data on the device Bit 7 means IEEE1667 protocol is supported xx1xH or xx9xH 70 74...

Page 35: ...eagate reserved 0000H 108 111 The mandatory value of the world wide name WWN for the drive NOTE This field is valid if word 84 bit 8 is set to 1 indicating 64 bit WWN support Each drive will have a un...

Page 36: ...mode 0 is supported 1 Ultra DMA mode 1 is supported 2 Ultra DMA mode 2 is supported 3 Ultra DMA mode 3 is supported 4 Ultra DMA mode 4 is supported 5 Ultra DMA mode 5 is supported 6 Ultra DMA mode 6...

Page 37: ...er mode based on value in Sector Count register Sector Count register values 00H Set PIO mode to default PIO mode 2 01H Set PIO mode to default and disable IORDY PIO mode 2 08H PIO mode 0 09H PIO mode...

Page 38: ...es unnecessary drive returns The diagnostic software ships with all new drives and is also available at http www seagate com support downloads seatools This drive is shipped with S M A R T features di...

Page 39: ...ited States 408 658 1000 ASIA PACIFIC Seagate Singapore International Headquarters Pte Ltd 7000 Ang Mo Kio Avenue 5 Singapore 569877 65 6485 3888 EUROPE MIDDLE EAST AND AFRICA Seagate Technology SAS 1...

Reviews:

Related manuals for ST1000LM038