background image

Seagate Laptop Thin HDD Product Manual, Rev. H

  23

 About (SED) Self-Encrypting

 

5.0

About (SED) Self-Encrypting Drives

Self-encrypting drives (SEDs) offer encryption and security services for the protection of stored data, commonly known as "protection of data at 
rest" These drives are compliant with the Trusted Computing Group (TCG) Opal Storage Specifications as detailed in the following:

Trusted Computing Group (TCG) Documents (apply to Self-Encrypting Drive models only)

TCG Storage Architecture Core Specification, Version 2.0
TCG Storage Security Subsystem Class Opal Specification, Version 2.0
(see 

www.trustedcomputinggroup.org

)

In case of conflict between this document and any referenced document, this document takes precedence.

The Trusted Computing Group ( TCG) is an organization sponsored and operated by companies in the computer, storage and digital 
communications industry. Seagate's SED models comply with the standards published by the TCG.

To use the security features in the drive, the host must be capable of constructing and issuing the following two SATA commands:

Trusted Send

Trusted Receive

These commands are used to convey the TCG protocol to and from the drive in their command payloads.

5.1

Data Encryption

Encrypting drives use one inline encryption engine for each drive employing AES-256 data encryption in Cipher Block Chaining (CBC) mode to

 

encrypt all data prior to being written on the media and to decrypt all data as it is read from the media. The encryption engine is always in operation

 

and cannot be disabled.

The 32-byte Data Encryption Key (DEK) is a random number which is generated by the drive, never leaves the drive, and is inaccessible to the host 
system. The DEK is itself encrypted when it is stored on the media and when it is in volatile temporary storage (DRAM) external to the encryption

 

engine. A unique data encryption key is used for each of the drive's possible16 data bands (see 

Section 5.5, Data Bands

).

5.2

Controlled Access

The drive has two security providers (SPs) called the "Admin SP" and the "Locking SP." These act as gatekeepers to the drive security services. 
Security-related commands will not be accepted unless they also supply the correct credentials to prove the requester is authorized to perform the

 

command.

5.2.1

Admin SP

The Admin SP allows the drive's owner to enable or disable firmware download operations (see 

Section 5.4, Drive Locking

). Access to the Admin

 

SP is available using the SID (Secure ID) password or the MSID (Manufacturers Secure ID) password.

5.2.2

Locking SP

The Locking SP controls read/write access to the media and the cryptographic erase feature. Access to the Locking SP is available using the Admin

 

or User passwords.

5.2.3

Default password

When the drive is shipped from the factory, all passwords are set to the value of MSID. This 32-byte random value can only be read by the host 
electronically over the interface. After receipt of the drive, it is the responsibility of the owner to use the default MSID password as the authority to

 

change all other passwords to unique owner-specified values.

5.2.4

ATA Enhanced Security

The drive can utilize the system's BIOS through the ATA Security API for cases that do not require password management and additional security

 

policies.

Furthermore, the drive's ATA Security Erase Unit command shall support both Normal and Enhanced Erase modes with the following modifications/
additions:

Normal Erase:

 Normal erase feature shall be performed by changing the Data Encryption Key (DEK) of the drive, followed by an overwrite

 

operation that repeatedly writes a single sector containing random data to the entire drive. This write operation bypasses the media encryption. On

 

reading back the overwritten sectors, the host will receive a decrypted version, using the new DEK of the random data sector (the returned data will 
not match what was written).

Enhanced Erase:

 Enhanced erase shall be performed by changing the Data Encryption Key of the drive.

Summary of Contents for ST500LM021-RF

Page 1: ...100737930 Rev H Gen 3 0 September 2017 Standard models ST500LM021 ST320LM010 Self Encryption models ST500LM023 SED FIPS 140 2 models ST500LM024 Laptop Thin HDD 7200 RPM SATA Product Manual...

Page 2: ...is used for formatting and other functions and thus will not be available for data storage Actual quantities will vary based on various factors including file size file format features and applicatio...

Page 3: ...nmental Specifications 13 2 8 1 Shock 13 2 8 2 Vibration 14 2 9 Acoustics 14 2 9 1 Test for prominent discrete tones PDTs 14 2 10 Electromagnetic Immunity 15 2 11 Reliability 15 2 12 Agency and Safety...

Page 4: ...5 2 1 Admin SP 23 5 2 2 Locking SP 23 5 2 3 Default password 23 5 2 4 ATA Enhanced Security 23 5 3 Random Number Generator RNG 24 5 4 Drive Locking 24 5 5 Data Bands 24 5 6 Cryptographic Erase 24 5 7...

Page 5: ...duct Manual Rev H 4 Figures Figure 1 Typical 5V Startup and Operation Current Profile 11 Figure 2 Attaching SATA Cabling 20 Figure 3 Mounting Dimensions for standard models 21 Figure 4 Example of FIPS...

Page 6: ...For information regarding Warranty Support visit http www seagate com support warranty and replacements For information regarding data recovery services visit http www seagate com services software r...

Page 7: ...w users to install a Serial ATA host adapter and Serial ATA disk drive in the current system and expect all of the existing applications to work as normal The Serial ATA interface connects each disk d...

Page 8: ...racks in avg Areal density 670 Gb in2 avg Spindle speed 7200 RPM Sustained data transfer rate OD 135 MB s max I O data transfer rate 600 MB s max ATA data transfer modes supported PIO modes 0 4 Multiw...

Page 9: ...to access the following web page http www seagate com support warranty and replacements From this page click on the Is my Drive under Warranty link The following are required to be provided the drive...

Page 10: ...2 Physical organization 2 3 Recording and Interface Technology 2 4 Physical Characteristics Drive model Read write heads Number of discs ST500LM021 ST500LM023 ST500LM024 2 1 ST320LM010 Interface Seri...

Page 11: ...tor arm moves toward a specific position on the disk surface and does not execute a read or write operation Servo electronics are active Seek mode power is measured based on three random seek operatio...

Page 12: ...rements Power Dissipation 5V input average 25 C Spinup max 1 00A Seek average 1 80W Write average 1 90W Read average 1 70W Idle performance 1 1 During periods of drive idle some offline activity may o...

Page 13: ...rive buffer is enabled the heads are parked and the spindle is at rest The drive accepts all commands and returns to active mode any time disk access is necessary Sleep mode The drive enters sleep mod...

Page 14: ...nonoperating shock level that the drive can experience without incurring physical damage or degradation in performance when subsequently put into operation is 800 Gs based on a nonrepetitive half sin...

Page 15: ...as the total A weighted sound power levers for steady state idle and active seeks modes of operation 2 9 1 Test for prominent discrete tones PDTs Seagate follows the ECMA 74 standards for measurement...

Page 16: ...age dips interrupts 30 Reduction for 25 cycles 95 Reduction for 250 cycles 95 0 5 cycles C C B EN 61000 4 11 94 Nonrecoverable read errors 1 per 1014 bits read max Load Unload U UL 25 C 50 relative hu...

Page 17: ...regulatory requirements and standards applicable to the system level products The drive is designed for operation inside a properly designed system e g enclosure designed for the drive with properly s...

Page 18: ...ification or certification of the device is required Seagate has tested this device in enclosures as described above to ensure that the total assembly enclosure disk drive motherboard power supply etc...

Page 19: ...cles and materials Our supplier contracts require compliance with our chemical substance restrictions and our suppliers document their compliance with our requirements by providing full disclosure mat...

Page 20: ...emicals as electronic drive component reliability can be affected by the installation environment The silver copper nickel and gold films used in Seagate products are especially sensitive to the prese...

Page 21: ...to the drive or host For direct backplane connection the drive connectors are inserted directly into the host receptacle The drive and the host receptacle incorporate features that enable the direct c...

Page 22: ...Avoid excessive drive distortion when mounting Refer to the following specifications for stiffness deflection information Figure 3 Mounting Dimensions for standard models Top cover stiffness deflecti...

Page 23: ...oaded on the NIST website This product has achieved FIPS 140 2 certification To reference the product certificate 1826 please visit http csrc nist gov groups STM cmvp documents 140 1 1401val2012 htm 1...

Page 24: ...of the drive s possible16 data bands see Section 5 5 Data Bands 5 2 Controlled Access The drive has two security providers SPs called the Admin SP and the Locking SP These act as gatekeepers to the dr...

Page 25: ...tion key for a particular band Once changed the data is no longer recoverable since it was written with one key and will be read using a different key Since the drive overwrites the old key with the n...

Page 26: ...o the Notes below Notes 1 All pins are in a single row with a 1 27 mm 0 050 in pitch 2 The comments on the mating sequence apply to the case of backplane blindmate connector only In this case the mati...

Page 27: ...Diagnostics 90h Flush Cache E7h Flush Cache Extended EAh Identify Device ECh Initialize Device Parameters 91h Read Buffer E4h Read DMA C8h Read DMA Extended 25h Read DMA without Retries C9h Read Long...

Page 28: ...7h S M A R T Write Attribute Values B0h E1h S M A R T Write Log Sector B0h D6h Write Buffer E8h Write DMA CAh Write DMA Extended 35h Write DMA without Retries CBh Write Long with Retries 32h Write Lon...

Page 29: ...37H 3 Number of logical heads 16 4 Retired 0000H 5 Retired 0000H 6 Number of logical sectors per logical track 63 003FH 7 9 Retired 0000H 10 19 Serial number 20 ASCII characters 0000H none ASCII 20 Re...

Page 30: ...inimum PIO cycle time with IORDY flow control 120 ns 0078H 69 74 ATA reserved 0000H 75 Queue depth 001FH 76 Serial ATA capabilities 0D06H 77 ATA reserved 0000H 78 Serial ATA features supported 0048H 7...

Page 31: ...WWN for the drive NOTE This field is valid if word 84 bit 8 is set to 1 indicating 64 bit WWN support Each drive will have a unique value 112 118 ATA reserved 0000H 119 Free Fall Protection support b...

Page 32: ...DMA mode 0 is supported 1 Ultra DMA mode 1 is supported 2 Ultra DMA mode 2 is supported 3 Ultra DMA mode 3 is supported 4 Ultra DMA mode 4 is supported 5 Ultra DMA mode 5 is supported 6 Ultra DMA mode...

Page 33: ...nsfer mode based on value in Sector Count register Sector Count register values 00H Set PIO mode to default PIO mode 2 01H Set PIO mode to default and disable IORDY PIO mode 2 08H PIO mode 0 09H PIO m...

Page 34: ...nates unnecessary drive returns The diagnostic software ships with all new drives and is also available at http www seagate com support downloads seatools This drive is shipped with S M A R T features...

Page 35: ...ted States 408 658 1000 ASIA PACIFIC Seagate Singapore International Headquarters Pte Ltd 7000 Ang Mo Kio Avenue 5 Singapore 569877 65 6485 3888 EUROPE MIDDLE EAST AND AFRICA Seagate Technology SAS 16...

Reviews: