background image

S

EAGATE 

U

LTRA 

M

OBILE 

SSHD P

RODUCT 

M

ANUAL

, R

EV

. D

  18

 A

BOUT 

(SED) S

ELF

-E

NCRYPTING 

D

RIVES 

5.0

A

BOUT 

(SED) S

ELF

-E

NCRYPTING 

D

RIVES

Self-encrypting drives (SEDs) offer encryption and security services for the protection of stored data, commonly known as "protection of 

data at rest." These drives are compliant with the Trusted Computing Group (TCG) Opal Storage Specifications as detailed in the following:
Trusted Computing Group (TCG) Documents (apply to Self-Encrypting Drive models only)

TCG Storage Architecture Core Specification, Version 2.0

TCG Storage Security Subsystem Class Opal Specification, Version 2.0

(see 

www.trustedcomputinggroup.org

)

In case of conflict between this document and any referenced document, this document takes precedence.
The Trusted Computing Group (TCG) is an organization sponsored and operated by companies in the computer, storage and digital 

communications industry. Seagate's SED models comply with the standards published by the TCG.
To use the security features in the drive, the host must be capable of constructing and issuing the following two SATA commands:

Trusted Send

Trusted Receive

These commands are used to convey the TCG protocol to and from the drive in their command payloads.

5.1

D

ATA 

E

NCRYPTION

Encrypting drives use one inline encryption engine for each drive employing AES-256 data encryption in Cipher Block Chaining (CBC) 

mode to encrypt all data prior to being written on the media and to decrypt all data as it is read from the media. The encryption engine is 

always in operation and cannot be disabled.
The 32-byte Data Encryption Key (DEK) is a random number which is generated by the drive, never leaves the drive, and is inaccessible to 

the host system. The DEK is itself encrypted when it is stored on the media and when it is in volatile temporary storage (DRAM) external to 

the encryption engine. A unique data encryption key is used for each of the drive's possible16 data bands (see 

Section 5.5, Data Bands

).

5.2

C

ONTROLLED 

A

CCESS

The drive has two security providers (SPs) called the "Admin SP" and the "Locking SP." These act as gatekeepers to the drive security 

services. Security-related commands will not be accepted unless they also supply the correct credentials to prove the requester is 

authorized to perform the command.

5.2.1

Admin SP

The Admin SP allows the drive's owner to enable or disable firmware download operations (see 

Section 5.4, Drive Locking

). Access to the 

Admin SP is available using the SID (Secure ID) password or the MSID (Manufacturers Secure ID) password.

5.2.2

Locking SP

The Locking SP controls read/write access to the media and the cryptographic erase feature. Access to the Locking SP is available using 

the Admin or User passwords.

5.2.3

Default password

When the drive is shipped from the factory, all passwords are set to the value of MSID. This 32-byte random value can only be read by the 

host electronically over the interface. After receipt of the drive, it is the responsibility of the owner to use the default MSID password as the 

authority to change all other passwords to unique owner-specified values.

5.2.4

ATA Enhanced Security

The drive can utilize the system's BIOS through the ATA Security API for cases that do not require password management and additional 

security policies.
Furthermore, the drive's ATA Security Erase Unit command shall support both Normal and Enhanced Erase modes with the following 

modifications/additions:

Normal Erase:

 Normal erase feature shall be performed by changing the Data Encryption Key (DEK) of the drive, followed by an overwrite 

operation that repeatedly writes a single sector containing random data to the entire drive. This write operation bypasses the media 

encryption. On reading back the overwritten sectors, the host will receive a decrypted version, using the new DEK of the random data 

sector (the returned data will not match what was written).

Enhanced Erase:

 Enhanced erase shall be performed by changing the Data Encryption Key of the drive.

Summary of Contents for ST500LX009

Page 1: ...le SSHD Gen 1 0 100742811 Rev D May 2014 Standard models ST500LX009 ST500LX012 Standard models w ZGS ST500LX011 ST500LX014 Self Encryption Drive models ST500LX015 ST500LX016 SED FIPS 140 2 models Revi...

Page 2: ...e gigabyte or GB equals one billion bytes and one terabyte or TB equals one trillion bytes Your computer s operating system may use a different standard of measurement and report a lower capacity In a...

Page 3: ...MMUNITY 12 2 11 RELIABILITY 12 2 12 AGENCY CERTIFICATION 13 2 12 1 Safety certification 13 2 12 2 Electromagnetic Compatibility EMC 13 2 12 3 FCC verification 13 2 13 ENVIRONMENTAL PROTECTION 14 2 13...

Page 4: ...OWER REQUIREMENTS 19 5 9 SUPPORTED COMMANDS 19 5 10 REVERTSP 19 6 0 SERIAL ATA SATA INTERFACE 20 6 1 HOT PLUG COMPATIBILITY 20 6 2 SERIAL ATA DEVICE PLUG CONNECTOR PIN DEFINITIONS 21 6 3 SUPPORTED ATA...

Page 5: ...5V STARTUP AND OPERATION CURRENT PROFILE FOR 8GB MODELS 8 FIGURE 2 TYPICAL 5V STARTUP AND OPERATION CURRENT PROFILE FOR 16GB MODELS 8 FIGURE 3 ATTACHING SATA CABLING 15 FIGURE 4 MOUNTING DIMENSIONS F...

Page 6: ...usiness hours Authorized Service Centers For information regarding Warranty Support visit http www seagate com support warranty and replacements For information regarding data recovery services visit...

Page 7: ...and reporting Support for Read Multiple and Write Multiple commands Worldwide Name WWN capability uniquely identifies the drive Seagate Ultra Mobile SSHD Self Encrypting Drive models have the followin...

Page 8: ...erating system views the two devices as if they were both masters on two separate ports This essentially means both drives behave as if they are Device 0 master devices The Serial ATA host adapter and...

Page 9: ...isks 1 Bytes per sector 512 logical 4096 physical Recording density 1885 Kb in Track density 366 Ktracks in avg Areal density 690 Gb in2 avg Spindle speed 5400 RPM Sustained data transfer rate OD 100...

Page 10: ...recoverable read errors 1 per 1015 bits read Rated workload Average rate of 55TB year The MTBF specification for the drive assumes the I O workload does not exceed the average annualized workload rate...

Page 11: ...taken with nominal power at 25 C ambient temperature All times are measured using drive diagnostics The specifications in the table below are defined as follows Track to track seek time is an average...

Page 12: ...s not execute a read or write operation Servo electronics are active Seek mode power is measured based on three random seek operations every 100 ms This mode is not typical Read write power and curren...

Page 13: ...CATIONS 2 7 1 1 Typical current profiles The typical 5V startup and operation current profile is shown in Figure 1 Figure 1 Typical 5V Startup and Operation Current Profile for 8GB models Figure 2 Typ...

Page 14: ...able length of time The standby timer delay is established using a standby or idle command In standby mode the drive buffer is enabled the heads are parked and the spindle is at rest The drive accepts...

Page 15: ...ck The nonoperating shock level that the drive can experience without incurring physical damage or degradation in performance when subsequently put into operation is 800 Gs based on a nonrepetitive ha...

Page 16: ...d as the total A weighted sound power levers for steady state idle and active seeks modes of operation 2 9 1 Test for prominent discrete tones PDTs Seagate follows the ECMA 74 standards for measuremen...

Page 17: ...00 MHz 3 V m 80 AM with 1 kHz sine 900 MHz 3 V m 50 pulse modulation 200 Hz A EN 61000 4 3 96 ENV 50204 95 Electrical fast transient 1 kV on AC mains 0 5 kV on external I O B EN 61000 4 4 95 Surge imm...

Page 18: ...cant Seagate Technology LLC Certificate date 10 January 2014 Manufacturer nationality USA Singapore and China Australian C Tick N176 If these models have the C Tick marking they comply with the Austra...

Page 19: ...rol of Pollution Caused by Electronic Information Products Standard O indicates the hazardous and toxic substance content of the part at the homogeneous material level is lower than the threshold defi...

Page 20: ...host For direct backplane connection the drive connectors are inserted directly into the host receptacle The drive and the host receptacle incorporate features that enable the direct connection to be...

Page 21: ...um screw engagement recommended Avoid excessive drive distortion when mounting Refer to the following specifications for stiffness deflection information Figure 4 Mounting Dimensions for standard mode...

Page 22: ...Policy document uploaded on the NIST website To reference the product certification visit http csrc nist gov groups STM cmvp documents 140 1 1401vend htm and search for Seagate Security Level 2 Securi...

Page 23: ...ach of the drive s possible16 data bands see Section 5 5 Data Bands 5 2 CONTROLLED ACCESS The drive has two security providers SPs called the Admin SP and the Locking SP These act as gatekeepers to th...

Page 24: ...ncryption key for a particular band Once changed the data is no longer recoverable since it was written with one key and will be read using a different key Since the drive overwrites the old key with...

Page 25: ...IORDY signal to provide reliable high speed data transfers For detailed information about the Serial ATA interface refer to the Serial ATA High Speed Serialized AT Attachment specification 6 1 HOT PLU...

Page 26: ...from each voltage is used for pre charge when installed in a blind mate backplane configuration 4 All used voltage pins Vx must be terminated Table 8 Serial ATA Connector Pin Definitions SEGMENT PIN...

Page 27: ...Diagnostics 90h Flush Cache E7h Flush Cache Extended EAh Identify Device ECh Initialize Device Parameters 91h Read Buffer E4h Read DMA C8h Read DMA Extended 25h Read DMA without Retries C9h Read Long...

Page 28: ...D7h S M A R T Write Attribute Values B0h E1h S M A R T Write Log Sector B0h D6h Write Buffer E8h Write DMA CAh Write DMA Extended 35h Write DMA without Retries CBh Write Long with Retries 32h Write Lo...

Page 29: ...al heads 16 4 Retired 0000H 5 Retired 0000H 6 Number of logical sectors per logical track 63 003FH 7 9 Retired 0000H 10 19 Serial number 20 ASCII characters 0000H none ASCII 20 Retired 0000H 21 Retire...

Page 30: ...ithout IORDY flow control 240 ns 0078H 68 Minimum PIO cycle time with IORDY flow control 120 ns 0078H 69 74 ATA reserved 0000H 75 Queue depth 001FH 76 Serial ATA capabilities 0D06H 77 ATA reserved 000...

Page 31: ...rt Each drive will have a unique value 112 118 ATA reserved 0000H 119 Free Fall Protection support bit 5 1 Free Fall Protection supported 0 Free Fall Protection not supported 120 Free Fall Protection...

Page 32: ...is supported 6 Ultra DMA mode 6 is supported 8 Ultra DMA mode 0 is currently active 9 Ultra DMA mode 1 is currently active 10 Ultra DMA mode 2 is currently active 11 Ultra DMA mode 3 is currently act...

Page 33: ...ansfer mode based on value in Sector Count register Sector Count register values 00H Set PIO mode to default PIO mode 2 01H Set PIO mode to default and disable IORDY PIO mode 2 08H PIO mode 0 09H PIO...

Page 34: ...inates unnecessary drive returns The diagnostic software ships with all new drives and is also available at http www seagate com support downloads seatools This drive is shipped with S M A R T feature...

Page 35: ...ration Set 22 Diagnostics 22 dimensions 16 dissipation 7 Download Microcode 22 Drive Locking 19 E electrical fast transient 12 Electromagnetic Compatibility EMC 13 Electromagnetic Compatibility contro...

Page 36: ...Buffer 22 Read DMA 22 Read DMA Extended 22 Read DMA without Retries 22 read errors 12 Read Long with Retries 22 Read Long without Retries 22 Read Multiple 22 Read Multiple Extended 22 Read Native Max...

Page 37: ...bassembly 13 surge immunity 12 T temperature 6 timers Idle and Standby 9 track density 6 Track to track seek time 6 Transport major version number 26 Trusted Computing Group 18 U UL60950 1 13 V vibrat...

Page 38: ...United States 408 658 1000 ASIA PACIFIC Seagate Singapore International Headquarters Pte Ltd 7000 Ang Mo Kio Avenue 5 Singapore 569877 65 6485 3888 EUROPE MIDDLE EAST AND AFRICA Seagate Technology SAS...

Reviews: