SCSI Commands: 43BSECURITY PROTOCOL IN
Page
192
Field
Bytes
Bits
Description
ENCRYPTION
STATUS
12 0-3
0h = The device server is incapable of determining if the logical
object referenced by the LOGICAL OBJECT NUMBER field
has been encrypted.
1h = The device server is capable of determining if the logical
object referenced by the LOGICAL OBJECT NUMBER field
has been encrypted, but is not able to at this time. Possible
reasons are:
a) the next logical block has not yet been read into the buffer;
b) there was an error reading the next logical block; or
c) there are no more logical blocks (i.e., end-of-data).
2h = The device server has determined that the logical object
referenced by the LOGICAL OBJECT NUMBER field is not a
logical block, e.g., a filemark.
3h = The device server has determined that the logical object
referenced by the LOGICAL OBJECT NUMBER field is not
encrypted.
4h = The device server has determined that the logical object
referenced by the LOGICAL OBJECT NUMBER field is
encrypted by an algorithm that is not supported by this device
server. The values in the KEY-ASSOCIATED DATA
DESCRIPTORS field contain information pertaining to the
encrypted block.
5h = The device server has determined that the logical object
referenced by the LOGICAL OBJECT NUMBER field is
encrypted by an algorithm that is supported by this device
server. The values in the ALGORITHM INDEX and KEY-
ASSOCIATED DATA DESCRIPTORS fields contain
information pertaining to the encrypted block.
6h = The device server has determined that the logical object
referenced by the LOGICAL OBJECT NUMBER field is
encrypted by an algorithm that is supported by this device
server, but the device server is either not enabled to decrypt or
does not have the correct key value to decrypt the encrypted
block.
COMPRESSI
ON STATUS
12 4-7
0h = The device server is incapable of determining if the logical
object referenced by the LOGICAL OBJECT NUMBER field
has been compressed.
ALGORITHM
INDEX
13
00h = AES-256/GCM.
KEY-ASSOCIATED DATA DESCRIPTORS
The KEY-ASSOCIATED DATA DESCRIPTORS List may contain any of the following descriptors,
depending upon the current decryption mode and whether the currently-loaded volume supports
encryption.
Authenticated
Key-
Associated
Data
Descriptor
This descriptor is returned for any value of Decryption Mode and if
the currently-loaded volume supports encryption.
Contents of the authenticated key-associated data (A-KAD)
associated with the next logical block, if any. The length is up to
twelve bytes.
Unauthenticat
ed Key-
Associated
Data
Descriptor
This descriptor is returned for any value of Decryption Mode and if
the currently-loaded volume supports encryption.
Contents of the unauthenticated key-associated data (U-KAD)
associated with the next logical block, if any. The length is up to
32 bytes.
Metadata Key-
Associated
Data
Descriptor
68
bytes
This descriptor is returned if the Decryption Mode is RAW.
Contents of the metadata key-associated data (M-KAD)
associated with the next logical block.
Содержание LTO 4
Страница 1: ......