K6610007
Rev.5
02.14.’03
- 72 -
6.3.2.9. Security Mode Feature
The Security Mode feature set is a password system that restricts access to user data stored on a device. The
system has two passwords, User and Master and two security levels, High and Maximum. The security system is
enabled by sending a user password to the device with the Security Set Password command. When the security
system is enabled, access to user data on the device is denied after a power cycle until the User password is sent
to the device with the Security Unlock command.
A Master password may be set in a addition to the User password. The purpose of the Master password is to
allow an administrator to establish a password that is kept secret from the user, and which may be used to unlock
the device if the User password is lost. Setting the Master password does not enable the password system.
The security level is set to High or Maximum with the Security Set Password command. The security level
determines device behavior when the Master password is used to unlock the device. When the security level is
set to High the device requires the Security Unlock command and the Master password to unlock. When the
security level is set to Maximum the device requires a Security Erase Prepare command and a Security Erase
Unit command with the master password to unlock.
The Security Freeze Lock command prevents changes to passwords until a following power cycle. The purpose of
the Security Freeze Lock command is to prevent password setting attacks on the security system.
The security mode features allow a host to implement a security password system to prevent unauthorized
access to the internal disk device.
The commands supported by this feature set are:
−
Security Set Password
−
Security
Unlock
−
Security Erase Prepare
−
Security Erase Unit
−
Security Freeze Lock
−
Security Disable Password
Support of the security mode feature set is indicated in Identify Device response Word 128.
6.3.2.9.1 Security Mode Default Setting
The device is shipped with the master password set to 20h value(ASCII space ) and the lock function
disabled. The system manufacturer/dealer may set a new master password using the Security Set Password
command, without enabling or disabling the lock function.