background image

Seagate Enterprise Capacity 3.5 HDD v6 Serial ATA Product Manual, Rev. B

  22

  

4.0

About self-encrypting drives

Self-encrypting drives (SEDs) offer encryption and security services for the protection of stored data, commonly known as 
“protection of data at rest.” These drives are compliant with the Trusted Computing Group (TCG) Enterprise Storage Specifications as 
detailed in Section 2.14.

The Trusted Computing Group (TCG) is an organization sponsored and operated by companies in the computer, storage and digital 
communications industry. Seagate’s SED models comply with the standards published by the TCG. 

To use the security features in the drive, the host must be capable of constructing and issuing the following two ATA commands:

• Trusted  Send

• Trusted  Receive

These commands are used to convey the TCG protocol to and from the drive in their command payloads.

4.1

Data encryption

Encrypting drives use one inline encryption engine for each port, employing AES-256 bit data encryption keys with AES-XTS mode to 
encrypt all data prior to being written on the media and to decrypt all data as it is read from the media. The encryption engines are 
always in operation and cannot be disabled.

The 32-byte Data Encryption Key (DEK) is a random number which is generated by the drive, never leaves the drive, and is 
inaccessible to the host system. The DEK is itself encrypted when it is stored on the media and when it is in volatile temporary 
storage (DRAM) external to the encryption engine. A unique data encryption key is used for each of the drive's possible16 data bands 
(see Section 4.5). 

4.2

Controlled access

The drive has two security providers (SPs) called the "Admin SP" and the "Locking SP." These act as gatekeepers to the drive security 
services. Security-related commands will not be accepted unless they also supply the correct credentials to prove the requester is 
authorized to perform the command.

4.2.1

Admin SP

The Admin SP allows the drive's owner to enable or disable firmware download operations (see Section 4.4). Access to the Admin SP 
is available using the SID (Secure ID) password or the MSID (Manufacturers Secure ID) password.

4.2.2

Locking SP

The Locking SP controls read/write access to the media and the cryptographic erase feature. Access to the Locking SP is available 
using the BandMasterX or EraseMaster passwords. Since the drive owner can define up to 16 data bands on the drive, each data band 
has its own password called BandMasterX where X is the number of the data band (0 through 15).

4.2.3

Default password

When the drive is shipped from the factory, all passwords are set to the value of MSID. This 32-byte random value can only be read by 
the host electronically over the interface. After receipt of the drive, it is the responsibility of the owner to use the default MSID 
password as the authority to change all other passwords to unique owner-specified values.

Содержание ST8000NM0006

Страница 1: ...KN models ST10000NM0006 ST8000NM0006 Self Encryption 4KN models ST10000NM0056 ST8000NM0056 Standard 512E models ST10000NM0016 ST8000NM0016 Self Encryption 512E models ST10000NM0046 ST8000NM0046 Enterp...

Страница 2: ...gabyte or GB equals one billion bytes and one terabyte or TB equals one trillion bytes Your computer s operating system may use a different standard of measurement and report a lower capacity In addit...

Страница 3: ...liability 16 2 10 1 Annualized Failure Rate AFR and Mean Time Between Failures MTBF 16 2 11 Agency certification 16 2 11 1 Safety certification 16 2 11 2 Electromagnetic compatibility 16 2 11 3 FCC ve...

Страница 4: ...nds 24 4 10 RevertSP 24 4 11 ATA Security Erase Unit Command on SED SATA drives 24 4 12 Sanitize Device CRYPTO SCRAMBLE EXT 24 5 0 Serial ATA SATA interface 25 5 1 Hot Plug compatibility 25 5 2 Serial...

Страница 5: ...For information regarding Warranty Support visit http www seagate com support warranty and replacements For information regarding data recovery services visit http www seagate com services software s...

Страница 6: ...and expect all of the existing applications to work as normal The Serial ATA interface connects each disk drive in a point to point configuration with the Serial ATA host adapter There is no master sl...

Страница 7: ...2 2 Heads 14 Discs 7 Bytes per logical sector 512 Bytes per physical sector 4096 Recording density KBPI Kb in max 2230 Track density KTPI ktracks in avg 386 Areal density Gb in2 avg 867 Spindle speed...

Страница 8: ...ualized Failure Rate AFR 0 35 based on 8760 POH Maximum Rated Workload Maximum rate of 550TB year Workloads exceeding the annualized rate may degrade the drive MTBF and impact product reliability The...

Страница 9: ...models Formatted capacity Guaranteed sectors Bytes per logical sector ST10000NM0006 ST10000NM0056 10TB 2 441 609 216 4096 ST8000NM0006 ST8000NM0056 8TB 1 953 506 646 ST10000NM0016 ST10000NM0046 10TB...

Страница 10: ...vels Table 2 DC power requirements 10TB and 8TB 6 0Gb mode Voltage 5V 12V Watts Regulation 5 Total Avg Idle Current 0 26 0 26 4 42 Advanced Idle Current Idle_A 0 25 0 26 4 36 Idle_B 0 16 0 18 2 98 Idl...

Страница 11: ...ad on the 12 V line or an equivalent 15 ohm resistive load on the 5V line Using 12V power the drive is expected to operate with a maximum of 120mV peak to peak square wave injected noise at up to 10MH...

Страница 12: ...the Extended Power Conditions EPC feature set using the standardized Set Features command interface Immediate host commanded power transitions may be initiated using an EPC Set Features Go to Power C...

Страница 13: ...anufacturer specified defaults or issuing the EPC Go to Power Condition subcommand at a rate exceeding the default timers may limit this products reliability and data integrity PowerChoice Supported E...

Страница 14: ...ze measure the case temperature of the drive See Figure 2 for HDA temperature checkpoint b Non operating 40 to 158 F 40 to 70 C package ambient with a maximum gradient of 36 F 20 C per hour This speci...

Страница 15: ...n subsequently put into operation is 250 Gs based on a nonrepetitive half sine shock pulse of 2ms duration 2 6 5 Vibration All vibration specifications assume that the drive is mounted securely with t...

Страница 16: ...immunity When properly installed in a representative host system the drive operates without errors or degradation in performance when subjected to the radio frequency RF environments defined in the f...

Страница 17: ...rements specified in the Electromagnetic Compatibility Directive 2004 108 EC as put into place 20 July 2007 Testing is performed to the levels specified by the product standards for Information Techno...

Страница 18: ...d this device in enclosures as described above to ensure that the total assembly enclosure disk drive motherboard power supply etc does comply with the limits for a Class B computing device pursuant t...

Страница 19: ...MCV Standard 2 13 Corrosive environment Seagate electronic drive components pass accelerated corrosion testing equivalent to 10 years exposure to light industrial environments containing sulfurous ga...

Страница 20: ...an also determine remaining warranty using the Seagate web site www seagate com The drive serial number is required to determine remaining warranty information Shipping When transporting or shipping a...

Страница 21: ...mateable For installations which require cables users can connect the drive as illustrated in Figure 3 Figure 3 Attaching SATA cabling Each cable is keyed to ensure correct orientation Enterprise Cap...

Страница 22: ...ns See Section 3 4 Drive mounting Figure 4 Mounting configuration dimensions 10TB and 8TB models Weight 10TB models 1 43 lb 650 g 8TB models Note These dimensions conform to the Small Form Factor Stan...

Страница 23: ...DEK is itself encrypted when it is stored on the media and when it is in volatile temporary storage DRAM external to the encryption engine A unique data encryption key is used for each of the drive s...

Страница 24: ...nal 32 Data Bands may be defined in a similar way Band2 through Band15 but before these bands can be allocated LBA space they must first be individually enabled using the EraseMaster password Data ban...

Страница 25: ...ia the 2D barcode 4 11 ATA Security Erase Unit Command on SED SATA drives The ATA SECURITY ERASE UNIT command shall support both the Normal and Enhanced erase modes with the following modifications ad...

Страница 26: ...er connectors Notes 1 All pins are in a single row with a 1 27mm 0 050 pitch 2 The comments on the mating sequence apply to the case of backplane blindmate connector only In this case the mating seque...

Страница 27: ...H Check Power Mode E5H Download Microcode 92H Execute Device Diagnostics 90H Flush Cache E7H Flush Cache Extended EAH Identify Device ECH Idle E3H Idle Immediate E1H NoP 00H Read Buffer E4H Read Buffe...

Страница 28: ...Return Status B0H DAH S M A R T Save Attribute Values B0H D3H S M A R T Write Log Sector B0H D6H Standby E2H Standby Immediate E0H Trusted Send 5EH SED drives only Trusted Send DMA 5FH SED drives only...

Страница 29: ...27 46 Drive model number 40 ASCII characters padded with blanks to end of string 47 Bits 7 0 Maximum sectors per interrupt on Read multiple and Write multiple 16 8010H 48 Trusted computing feature set...

Страница 30: ...ng this table xx7FH 89 Security erase time xxxxH 90 Enhanced security erase time xxxxH 92 Master password revision code FFFEH 93 Hardware reset value xxxxH 95 99 ATA reserved 0000H 100 103 Total numbe...

Страница 31: ...ART error logging is supported 1 SMART self test is supported 2 Media serial number is supported 3 Media Card Pass Through Command feature set is supported 4 Streaming feature set is supported 5 GPL f...

Страница 32: ...currently active Table 7 Set Features command values 02H Enable write cache default 03H Set transfer mode based on value in Sector Count register Sector Count register values 00H Set PIO mode to defau...

Страница 33: ...inates unnecessary drive returns The diagnostic software ships with all new drives and is also available at http www seagate com support downloads seatools This drive is shipped with S M A R T feature...

Страница 34: ...nited States 408 658 1000 ASIA PACIFIC Seagate Singapore International Headquarters Pte Ltd 7000 Ang Mo Kio Avenue 5 Singapore 569877 65 6485 3888 EUROPE MIDDLE EAST AND AFRICA Seagate Technology SAS...

Отзывы: