background image

Seagate Laptop Thin HDD Product Manual, Rev. H

  24

 About (SED) Self-Encrypting

 

5.3

Random Number Generator (RNG)

The drive has a 32-byte hardware RNG that it is uses to derive encryption keys or, if requested to do so, to provide random numbers to the host for 
system use, including using these numbers as Authentication Keys (passwords) for the drive's Admin and Locking SPs.

5.4

Drive Locking

In addition to changing the passwords, as described in 

Section 5.2.3, Default password

, the owner should also set the data access controls for the

 

individual bands.

The variable "LockOnReset" should be set to "PowerCycle" to ensure that the data bands will be locked if power is lost. In addition

 

"ReadLockEnabled" and "WriteLockEnabled" must be set to true in the locking table in order for the bands "LockOnReset" setting of "PowerCycle" to

 

actually lock access to the band when a "PowerCycle" event occurs. This scenario occurs if the drive is removed from its cabinet. The drive will not 
honor any data read or write requests until the bands have been unlocked. This prevents the user data from being accessed without the appropriate

 

credentials when the drive has been removed from its cabinet and installed in another system.

5.5

Data Bands

When shipped from the factory, the drive is configured with a single data band called Band 0 (also known as the Global Data Band) which comprises 
LBA 0 through LBA max. The host may allocate additional bands (Band1 to Band15) by specifying a start LBA and an LBA range. The real estate for 
this band is taken from the Global Band.

Data bands cannot overlap but they can be sequential with one band ending at LBA (x) and the next beginning at LBA (x+1).

Each data band has its own drive-generated encryption key. The host may change the Encryption Key (see 

Section 5.6, Cryptographic Erase

) or 

the password when required. The bands should be aligned to 4K LBA boundaries.

5.6

Cryptographic Erase

A significant feature of SEDs is the ability to perform a cryptographic erase. This involves the host telling the drive to change the data encryption key

 

for a particular band. Once changed, the data is no longer recoverable since it was written with one key and will be read using a different key. Since

 

the drive overwrites the old key with the new one, and keeps no history of key changes, the user data can never be recovered. This is tantamount to

 

an instantaneous data erase and is very useful if the drive is to be scrapped or redispositioned.

5.7

Authenticated Firmware Download

In addition to providing a locking mechanism to prevent unwanted firmware download attempts, the drive also only accepts download files which

 

have been cryptographically signed by the appropriate Seagate Design Center.

Three conditions must be met before the drive will allow the download operation:

1. The download must be an SED file. A standard (base) drive (non-SED) file will be rejected.

2. The download file must be signed and authenticated.

3. As with a non-SED drive, the download file must pass the acceptance criteria for the drive. For example it must be applicable to the correct drive

 

model, and have compatible revision and customer status.

5.8

Power Requirements

The standard drive models and the SED drive models have identical hardware, however the security and encryption portion of the drive controller 
ASIC is enabled and functional in the SED models. This represents a small additional drain on the 5V supply of about

30mA and a commensurate increase of about 150mW in power consumption. There is no additional drain on the 12V supply. See the tables in

 

Section 2.7, Power Specifications

 for power requirements on the standard (non-SED) drive models.

5.9

Supported Commands

The SED models support the following two commands in addition to the commands supported by the standard (non-SED) models as listed in 

Table

 

11

:

Trusted Send

Trusted Receive

5.10

RevertSP

SED models will support the RevertSP feature which erases all data in all bands on the device and returns the contents of all SPs (Security Providers) 
on the device to their original factory state. In order to execute the RevertSP method the unique PSID (Physical Secure ID) printed on the drive label 
must be provided. PSID is not electronically accessible and can only be manually read from the drive label or scanned in via the 2D barcode.

Summary of Contents for ST500LM021-RF

Page 1: ...100737930 Rev H Gen 3 0 September 2017 Standard models ST500LM021 ST320LM010 Self Encryption models ST500LM023 SED FIPS 140 2 models ST500LM024 Laptop Thin HDD 7200 RPM SATA Product Manual...

Page 2: ...is used for formatting and other functions and thus will not be available for data storage Actual quantities will vary based on various factors including file size file format features and applicatio...

Page 3: ...nmental Specifications 13 2 8 1 Shock 13 2 8 2 Vibration 14 2 9 Acoustics 14 2 9 1 Test for prominent discrete tones PDTs 14 2 10 Electromagnetic Immunity 15 2 11 Reliability 15 2 12 Agency and Safety...

Page 4: ...5 2 1 Admin SP 23 5 2 2 Locking SP 23 5 2 3 Default password 23 5 2 4 ATA Enhanced Security 23 5 3 Random Number Generator RNG 24 5 4 Drive Locking 24 5 5 Data Bands 24 5 6 Cryptographic Erase 24 5 7...

Page 5: ...duct Manual Rev H 4 Figures Figure 1 Typical 5V Startup and Operation Current Profile 11 Figure 2 Attaching SATA Cabling 20 Figure 3 Mounting Dimensions for standard models 21 Figure 4 Example of FIPS...

Page 6: ...For information regarding Warranty Support visit http www seagate com support warranty and replacements For information regarding data recovery services visit http www seagate com services software r...

Page 7: ...w users to install a Serial ATA host adapter and Serial ATA disk drive in the current system and expect all of the existing applications to work as normal The Serial ATA interface connects each disk d...

Page 8: ...racks in avg Areal density 670 Gb in2 avg Spindle speed 7200 RPM Sustained data transfer rate OD 135 MB s max I O data transfer rate 600 MB s max ATA data transfer modes supported PIO modes 0 4 Multiw...

Page 9: ...to access the following web page http www seagate com support warranty and replacements From this page click on the Is my Drive under Warranty link The following are required to be provided the drive...

Page 10: ...2 Physical organization 2 3 Recording and Interface Technology 2 4 Physical Characteristics Drive model Read write heads Number of discs ST500LM021 ST500LM023 ST500LM024 2 1 ST320LM010 Interface Seri...

Page 11: ...tor arm moves toward a specific position on the disk surface and does not execute a read or write operation Servo electronics are active Seek mode power is measured based on three random seek operatio...

Page 12: ...rements Power Dissipation 5V input average 25 C Spinup max 1 00A Seek average 1 80W Write average 1 90W Read average 1 70W Idle performance 1 1 During periods of drive idle some offline activity may o...

Page 13: ...rive buffer is enabled the heads are parked and the spindle is at rest The drive accepts all commands and returns to active mode any time disk access is necessary Sleep mode The drive enters sleep mod...

Page 14: ...nonoperating shock level that the drive can experience without incurring physical damage or degradation in performance when subsequently put into operation is 800 Gs based on a nonrepetitive half sin...

Page 15: ...as the total A weighted sound power levers for steady state idle and active seeks modes of operation 2 9 1 Test for prominent discrete tones PDTs Seagate follows the ECMA 74 standards for measurement...

Page 16: ...age dips interrupts 30 Reduction for 25 cycles 95 Reduction for 250 cycles 95 0 5 cycles C C B EN 61000 4 11 94 Nonrecoverable read errors 1 per 1014 bits read max Load Unload U UL 25 C 50 relative hu...

Page 17: ...regulatory requirements and standards applicable to the system level products The drive is designed for operation inside a properly designed system e g enclosure designed for the drive with properly s...

Page 18: ...ification or certification of the device is required Seagate has tested this device in enclosures as described above to ensure that the total assembly enclosure disk drive motherboard power supply etc...

Page 19: ...cles and materials Our supplier contracts require compliance with our chemical substance restrictions and our suppliers document their compliance with our requirements by providing full disclosure mat...

Page 20: ...emicals as electronic drive component reliability can be affected by the installation environment The silver copper nickel and gold films used in Seagate products are especially sensitive to the prese...

Page 21: ...to the drive or host For direct backplane connection the drive connectors are inserted directly into the host receptacle The drive and the host receptacle incorporate features that enable the direct c...

Page 22: ...Avoid excessive drive distortion when mounting Refer to the following specifications for stiffness deflection information Figure 3 Mounting Dimensions for standard models Top cover stiffness deflecti...

Page 23: ...oaded on the NIST website This product has achieved FIPS 140 2 certification To reference the product certificate 1826 please visit http csrc nist gov groups STM cmvp documents 140 1 1401val2012 htm 1...

Page 24: ...of the drive s possible16 data bands see Section 5 5 Data Bands 5 2 Controlled Access The drive has two security providers SPs called the Admin SP and the Locking SP These act as gatekeepers to the dr...

Page 25: ...tion key for a particular band Once changed the data is no longer recoverable since it was written with one key and will be read using a different key Since the drive overwrites the old key with the n...

Page 26: ...o the Notes below Notes 1 All pins are in a single row with a 1 27 mm 0 050 in pitch 2 The comments on the mating sequence apply to the case of backplane blindmate connector only In this case the mati...

Page 27: ...Diagnostics 90h Flush Cache E7h Flush Cache Extended EAh Identify Device ECh Initialize Device Parameters 91h Read Buffer E4h Read DMA C8h Read DMA Extended 25h Read DMA without Retries C9h Read Long...

Page 28: ...7h S M A R T Write Attribute Values B0h E1h S M A R T Write Log Sector B0h D6h Write Buffer E8h Write DMA CAh Write DMA Extended 35h Write DMA without Retries CBh Write Long with Retries 32h Write Lon...

Page 29: ...37H 3 Number of logical heads 16 4 Retired 0000H 5 Retired 0000H 6 Number of logical sectors per logical track 63 003FH 7 9 Retired 0000H 10 19 Serial number 20 ASCII characters 0000H none ASCII 20 Re...

Page 30: ...inimum PIO cycle time with IORDY flow control 120 ns 0078H 69 74 ATA reserved 0000H 75 Queue depth 001FH 76 Serial ATA capabilities 0D06H 77 ATA reserved 0000H 78 Serial ATA features supported 0048H 7...

Page 31: ...WWN for the drive NOTE This field is valid if word 84 bit 8 is set to 1 indicating 64 bit WWN support Each drive will have a unique value 112 118 ATA reserved 0000H 119 Free Fall Protection support b...

Page 32: ...DMA mode 0 is supported 1 Ultra DMA mode 1 is supported 2 Ultra DMA mode 2 is supported 3 Ultra DMA mode 3 is supported 4 Ultra DMA mode 4 is supported 5 Ultra DMA mode 5 is supported 6 Ultra DMA mode...

Page 33: ...nsfer mode based on value in Sector Count register Sector Count register values 00H Set PIO mode to default PIO mode 2 01H Set PIO mode to default and disable IORDY PIO mode 2 08H PIO mode 0 09H PIO m...

Page 34: ...nates unnecessary drive returns The diagnostic software ships with all new drives and is also available at http www seagate com support downloads seatools This drive is shipped with S M A R T features...

Page 35: ...ted States 408 658 1000 ASIA PACIFIC Seagate Singapore International Headquarters Pte Ltd 7000 Ang Mo Kio Avenue 5 Singapore 569877 65 6485 3888 EUROPE MIDDLE EAST AND AFRICA Seagate Technology SAS 16...

Reviews: