
2.5” SATA SSD 3TR6-P
36
V1.8 TPS, Aug., 2022
3.15.1 Encrypted Key Management
Innodisk 3TR6-P SSD includes two methods of key management to apply to different applications.
The first is a standard approach that allows the firmware to generate a random number and a
unique key when it leaves the factory. This method ensures that the user can easily apply the SSD
with the data encrypted key. Another approach is to meet unique customer requirements with an
encrypted key generated by an SSD from the SATA interface host. The SSD must keep the
encrypted key value when receiving the reset commands. This method works best for the SSD as
a removable device in different systems. Innodisk provides the test tool to execute the AES
hardware encryption. This user-friendly tool, developed by Innodisk Corporation, allows the
customer to use/test encryption functions.
3.15.2 Authorized Key Management
In order to complete the physical security layer of protection, encryption needs to be bundled with
an ATA user password provided by an ATA Security command. Unlike the AES key, the authorized
key must be set by the user via the BIOS configuration. Every time you power on the system with
SSD encryption, a password request prompt is sent to access the SSD. If the password is correct,
the SSD will run well; if not, you will not be able to access the SSD.
Command
Command Code
SECURITY SET PASSWORD
0XF1
SECURITY UNLOCK
0XF2
SECURITY ERASE PREPARE
0XF3
SECURITY ERASE UNIT
0XF4
SECURITY FREEZE LOCK
0XF5
SECURITY DISABLE PASSWORD
0XF6
3.15.3 TCG OPAL (In Dev.)
OPAL is a set of specifications for features of data storage devices that enhance security. These
specifications are published by the Trusted Computing Group’s Storage Work Group. Innodisk
3TR6-P is compliant with TCG OPAL 2.0
(*1)
. The capability of TCG OPAL Security mode allows multiple
users with independent access control to read/write/erase independent data areas (LBA ranges).
Each locking range adjusts by authenticated authority. Note that by default there is a single “Global
Range” that encompasses the whole user data area. In TCG Opal Security Mode, Revert, Revert SP
and GenKey command can erase all of data including global range and locking range; in the
meantime generate the new encrypted key.
*1. You need to install TCG OPAL software to implement OPAL function, which is supplied by TCG OPAL software developed company