background image

Seagate BarraCuda Product Manual, Rev. D

26

www.seagate.com

About (SED) Self-Encrypting Drives

4.0 About (SED) Self-Encrypting Drives

Self-encrypting drives (SEDs) offer encryption and security services for the protection of stored data, commonly known as
"data at rest". These drives are compliant with the Trusted Computing Group (TCG) Opal Storage Specifications as detailed
in the following:

TCG Storage Architecture Core Specification, Version 2.0 (see 

www.trustedcomputinggroup.org

)

TCG Storage Security Subsystem Class Opal Specification, Version 2.0 (see 

www.trustedcomputinggroup.org

)

In case of conflict between this document and any referenced document, this document takes precedence.

The Trusted Computing Group (TCG) is a standards organization sponsored and operated by companies in the computer,
storage and digital communications industry. Seagate's SED models comply with the standards published by the TCG.

To use the security features in the drive, the host must be capable of constructing and issuing the following two SATA
commands:

Trusted Send

Trusted Receive

These commands are used to convey the TCG protocol to and from the drive in their command payloads. Seagate Secure SEDs also
support TCG Single User Mode, which can be disabled.

4.1

Data Encryption

Encrypting drives use one inline encryption engine within each drive employing AES-256 algorithms in Cipher Block Chaining (CBC)
mode to encrypt all data prior to being written on the media and to decrypt all data as it is read from the media. The encryption engine
is always in operation and cannot be disabled. The 32-byte Data Encryption Key (DEK) is a random number which is generated by the
drive, never leaves the drive, and is inaccessible to the host system. The DEK is itself encrypted when it is stored on the media and when
in volatile temporary storage (DRAM), which is external to the encryption engine. A unique data encryption key is used for each of the
drive's possible16 data bands (see 

 Section 4.5 Data Bands (TBD)

).

4.2

Controlled Access

The drive has two security providers (SPs) called the "Admin SP" and the "Locking SP." These act as gatekeepers to the drive security
services. Security-related commands will not be accepted unless the user provides the correct credentials to prove that they are
authorized to perform the command.

4.2.1 Admin SP

The Admin SP allows the drive's owner to enable or disable firmware download operations (see 

 Section 4.4 Drive Locking

). Access to

the Admin SP is available using the SID (Secure ID) password.

4.2.2 Locking SP

The Locking SP controls read/write access to the media and the cryptographic erase feature. Access to the Locking SP is available using
the Admin or User passwords.

4.2.3 Default password

When the drive is shipped from the factory, all passwords are set to the value of MSID. This 32-byte random value can only be read by the
host electronically over the interface. After receipt of the drive, it is the responsibility of the owner to use the default MSID password as
the authority to change all other passwords to unique owner-specified values.

4.2.4 ATA Enhanced Security

The drive can utilize the system's BIOS through the ATA Security API for cases that do not require password management and additional
security policies.

Furthermore, the drive's ATA Security Erase Unit command shall support both Normal and Enhanced Erase modes with the following
modifications/additions:

Normal Erase:

 Normal erase feature shall be performed by changing the Data Encryption Key (DEK) of the drive, followed by an

overwrite operation that repeatedly writes a single sector containing random data to the entire drive. This write operation bypasses the
media encryption. On reading back the overwritten sectors, the host will receive a decrypted version, using the new DEK of the random
data sector (the returned data will not match what was written).

Enhanced Erase:

 Enhanced erase shall be performed by changing the Data Encryption Key of the drive.

4.3

Random Number Generator (RNG)

The drive has a 32-byte hardware RNG that it is uses to derive encryption keys or, if requested to do so, to provide random numbers to
the host for system use, including using these numbers as Authentication Keys (passwords) for the drive's Admin and Locking SPs.

Summary of Contents for ST3000DM008

Page 1: ...Standard models ST3000DM008 ST2000DM006 ST1000DM010 ST500DM009 Self Encryption models ST3000DM009 ST2000DM007 100804187 Rev D June 2017 Product Manual...

Page 2: ...nd report a lower capacity In addition some of the listed capacity is used for formatting and other functions and thus will not be available for data storage Actual quantities will vary based on vario...

Page 3: ...4 2 8 4 Power management modes 14 2 9 Environmental specifications 15 2 9 1 Ambient temperature 15 2 9 2 Temperature gradient 15 2 9 3 Humidity 15 2 9 4 Altitude 15 2 9 5 Shock 16 2 9 6 Non operating...

Page 4: ...min SP 26 4 2 2 Locking SP 26 4 2 3 Default password 26 4 2 4 ATA Enhanced Security 26 4 3 Random Number Generator RNG 26 4 4 Drive Locking 27 4 5 Data Bands TBD 27 4 6 Cryptographic Erase 27 4 7 Auth...

Page 5: ...gures Figure 1 Attaching SATA cabling 21 Figure 2 Mounting dimensions 2 3 disk 2TB to 3TB models 22 Figure 3 Mounting dimensions configuration 1 23 Figure 4 Mounting dimensions configuration 2 24 Figu...

Page 6: ...ation regarding Warranty Support visit http www seagate com support warranty and replacements For information regarding data recovery services visit http www seagate com services software data recover...

Page 7: ...Seagate OptiCache technology boosts overall performance by as much as 45 over the previous generation Seagate SmartAlign technology provides a simple transparent migration to Advanced Format 4K secto...

Page 8: ...st operating system views the two devices as if they were both masters on two separate ports This essentially means both drives behave as if they are Device 0 master devices The SATA host adapter and...

Page 9: ...8 3 907 029 168 1 953 525 168 976 773 168 Heads 6 6 4 2 2 1 Disks 3 3 2 1 1 Bytes per sector 4K physical emulated at 512 byte sectors 4096 Default sectors per track 63 Default read write heads 16 Defa...

Page 10: ...Hz 3 0 Gs 22Hz to 350Hz 3 0 Gs 350Hz to 500Hz 3 0 Gs Drive acoustics sound power Idle 2 4 bels typical 2 6 bels max 2 2 bels typical 2 3 bels max Seek 2 6 bels typical 2 7 bels max 2 3 bels typical 2...

Page 11: ...fault logical geometry Cylinders 16 383 Read write heads 16 Sectors per track 63 LBA mode When addressing these drives in LBA mode all blocks sectors are consecutively numbered from 0 to n 1 where n i...

Page 12: ...1mm 1 028 in 1TB and 500GB 20 20mm 0 795 in Maximum width all models 101 6mm 4 0 in 0 010 in Maximum length all models 146 99mm 5 787 in Typical weight 3TB 626g 1 38 lb 2TB 626g 1 38 lb or 535g 1 18...

Page 13: ...nt Read write power is measured with the heads on track based on a 16 sector write followed by a 32 ms delay then a 16 sector read followed by a 32 ms delay Operating power and current Operating power...

Page 14: ...ected noise at up to 10MHz Using 5 volt power the drive is expected to operate with a maximum of 100 mV peak to peak square wave injected noise at up to 10MHz Table 2 DC power requirements 3 disk 3TB...

Page 15: ...ndby mode the drive buffer is enabled the heads are parked and the spindle is at rest The drive accepts all commands and returns to Active mode any time disk access is necessary Sleep mode The drive e...

Page 16: ...at sustained case temperatures above 60 C Operating at higher temperatures will reduce useful life of the product 2 9 2 Temperature gradient 2 9 3 Humidity 2 9 3 1 Relative humidity 2 9 3 2 Wet bulb t...

Page 17: ...models The non operating shock level that the drive can experience without incurring physical damage or degradation in performance when subsequently put into operation is 350 Gs based on a non repetit...

Page 18: ...ed in a representative host system the drive operates without errors or degradation in performance when subjected to the radio frequency RF environments defined in Table 5 Note For seek mode tests the...

Page 19: ...ied by the product standards for Information Technology Equipment ITE Emission levels are defined by EN 55022 Class B and the immunity levels are defined by EN 55024 Drives are tested in representativ...

Page 20: ...rates and uses radio frequency energy and if not installed and used in strict accordance with the manufacturer s instructions may cause interference to radio and television reception This equipment is...

Page 21: ...and corrosive chemicals as electronic drive component reliability can be affected by the installation environment The silver copper nickel and gold films used in Seagate products are especially sensi...

Page 22: ...to point with the SATA host adapter There is no master slave relationship because each drive is considered a master in a point to point relationship If two drives are attached on one SATA host adapter...

Page 23: ...ighten the mounting screws maximum torque 6 inch lb Figure 2 Mounting dimensions 2 3 disk 2TB to 3TB models Note Drawings are for mounting hole reference only PCBA show in pictorial only and can vary...

Page 24: ...can vary based on specific customer configurations 5 787 MAX 4 010 MAX 1 090 050 640 050 5 TOP OF LABEL 4 000 1 638 1 122 020 3X 250 010 BOTH SIDES 3X 6 32 UNC 2B 3 MINIMUM THREAD DEPTH 0 14 MAXIMUM...

Page 25: ...nfigurations 5 787 MAX 4 010 MAX 1 090 050 640 050 5 TOP OF LABEL 4 000 1 638 1 122 020 3X 250 010 BOTH SIDES 3X 6 32 UNC 2B 3 MINIMUM THREAD DEPTH 0 14 MAXIMUM FASTENER PENETRATION MOUNTING HOLES BOT...

Page 26: ...THREAD DEPTH 0 15 MAXIMUM FASTENER PENETRATION BOTH SIDES 4X 6 32 UNC 2B 3 MINIMUM THREAD DEPTH 0 15 MAXIMUM FASTENER PENETRATION 5 787 in max 146 99 mm 4 010 in max 101 85 mm 0 795 in or 20 20 mm ma...

Page 27: ...two security providers SPs called the Admin SP and the Locking SP These act as gatekeepers to the drive security services Security related commands will not be accepted unless the user provides the c...

Page 28: ...Since the drive overwrites the old key with the new one and keeps no history of key the older key the user data can never be recovered This is done in a matter of seconds and is very useful if the dri...

Page 29: ...apply to the case of backplane blindmate connector only In this case the mating sequences are the ground pins P4 and P12 the pre charge power pins and the other ground pins the signal pins and the res...

Page 30: ...fy B1H C2H Device Configuration Restore B1H C0H Device Configuration Set B1H C3H Device Reset 08H Download Microcode 92H Execute Device Diagnostics 90H Flush Cache E7H Flush Cache Extended EAH Format...

Page 31: ...H D2H S M A R T Enable Operations B0H D8H S M A R T Execute Offline B0H D4H S M A R T Read Attribute Thresholds B0H D1H S M A R T Read Data B0H D0H S M A R T Read Log Sector B0H D5H S M A R T Return S...

Page 32: ...umber of logical heads 16 4 Retired 0000H 5 Retired 0000H 6 Number of logical sectors per logical track 63 003FH 7 9 Retired 0000H 10 19 Serial number 20 ASCII characters 0000H none ASCII 20 Retired 0...

Page 33: ...d 120 nsec 0078H 67 Minimum PIO cycle time without IORDY flow control 240 nsec 0078H 68 Minimum PIO cycle time with IORDY flow control 120 nsec 0078H 69 74 ATA reserved 0000H 75 Queue depth 001FH 76 S...

Page 34: ...DM009 976 773 168 104 107 ATA reserved 0000H 108 111 The mandatory value of the world wide name WWN for the drive NOTE This field is valid if word 84 bit 8 is set to 1 indicating 64 bit WWN support Ea...

Page 35: ...A FUA EXT and WRITE MULTIPLE FUA EXT commands are supported 7 WRITE DMA QUEUED FUA EXT command is supported 8 64 bit World Wide Name is supported 9 10 Obsolete 11 12 Reserved for TLC 13 IDLE IMMEDIATE...

Page 36: ...03H Set transfer mode based on value in Sector Count register Sector Count register values 00H Set PIO mode to default PIO mode 2 01H Set PIO mode to default and disable IORDY PIO mode 2 08H PIO mode...

Page 37: ...that eliminates unnecessary drive returns The diagnostic software ships with all new drives and is also available at http seatools seagate com This drive is shipped with S M A R T features disabled U...

Page 38: ...nited States 408 658 1000 ASIA PACIFIC Seagate Singapore International Headquarters Pte Ltd 7000 Ang Mo Kio Avenue 5 Singapore 569877 65 6485 3888 EUROPE MIDDLE EAST AND AFRICA Seagate Technology SAS...

Reviews: