7.
Managing SED
7.1
Overview
7.1.1
Introduction
A Self-Encrypting Drive (SED) encrypts data through disk-based encryption with a Media Encryption Key (MEK). The
MEK is known only to the SED and cannot be recovered through forensic analysis. Smart controllers enable the use
of SEDs as logical drives or physical drives.
The controller is responsible for managing and delivering the credentials required by the SED for enabling the
disk-based encryption. SAS, SATA, and NVME drives that are compliant to the Opal 2.0 and Enterprise 1.01 industry
standards are supported.
This section describes the functionality provided by the managed SED features.
This table lists the terms used in this section.
Table 7-1. Terminology
Term
Definition
Credential
A value (password, key, or PIN) that grants access privilege
Encrypted
A value that is obfuscated with an algorithm
PIN
A value (up to 32 bytes) used as a credential on a SED
Key
A value input to a hash function used to create a PIN
Locking range
An LBA range of a SED that may have unique credentials
Identifier
The "name" component of a name—values pair as in Key Identifier: Key
RAID set
A drive or group of drives that contain one or more RAID volumes
Secured
A SED managed by the smart controller. The SED PIN is required to
access user data.
Unsecured
A SED that is not managed by the smart controller
Password
This refers to the controller password. The controller password is not
related to the SED PIN or the adapter master key
OFS
Original Factory State. This is the state of a newly manufactured SED.
No security attributes or locking ranges are configured.
LKM
Local Key Management
RKM
Remote Key Management
7.2
Supported Features
The features described in the following sections are part of the managed SED feature set. Users can configure the
managed SED feature settings through the UEFI HII and ARCCONF or maxView OS-based tools.
7.2.1
Supported SED Types
Adapters support attaching SAS, SATA, and NVMe SED (depending on the controller used) that are compliant with
the following industry standards:
• TCG Storage Security Subsystem Class: Enterprise Standard version 1.01
• TCG Storage Security Subsystem Class: Opal standard version 2.01
Managing SED
©
2022 Microchip Technology Inc.
and its subsidiaries
User Guide
DS00004281C-page 40