background image

Seagate Enterprise Capacity 3.5 HDD v5 Serial ATA Product Manual, Rev. G

  24

  

4.0

About self-encrypting drives

Self-encrypting drives (SEDs) offer encryption and security services for the protection of stored data, commonly known as 
“protection of data at rest.” These drives are compliant with the Trusted Computing Group (TCG) Enterprise Storage Specifications as 
detailed in Section 2.14.

The Trusted Computing Group (TCG) is an organization sponsored and operated by companies in the computer, storage and digital 
communications industry. Seagate’s SED models comply with the standards published by the TCG. 

To use the security features in the drive, the host must be capable of constructing and issuing the following two ATA commands:

• Trusted  Send

• Trusted  Receive

These commands are used to convey the TCG protocol to and from the drive in their command payloads.

4.1

Data encryption

Encrypting drives use one inline encryption engine for each port, employing AES-256 bit data encryption keys with AES-XTS mode to

 

encrypt all data prior to being written on the media and to decrypt all data as it is read from the media. The encryption engines are

 

always in operation and cannot be disabled.

The 32-byte Data Encryption Key (DEK) is a random number which is generated by the drive, never leaves the drive, and is 
inaccessible to the host system. The DEK is itself encrypted when it is stored on the media and when it is in volatile temporary

 

storage (DRAM) external to the encryption engine. A unique data encryption key is used for each of the drive's possible16 data bands 
(see Section 4.5). 

4.2

Controlled access

The drive has two security providers (SPs) called the "Admin SP" and the "Locking SP." These act as gatekeepers to the drive security

 

services. Security-related commands will not be accepted unless they also supply the correct credentials to prove the requester is 
authorized to perform the command.

4.2.1

Admin SP

The Admin SP allows the drive's owner to enable or disable firmware download operations (see Section 4.4). Access to the Admin SP

 

is available using the SID (Secure ID) password or the MSID (Manufacturers Secure ID) password.

4.2.2

Locking SP

The Locking SP controls read/write access to the media and the cryptographic erase feature. Access to the Locking SP is available

 

using the BandMasterX or EraseMaster passwords. Since the drive owner can define up to 16 data bands on the drive, each data band

 

has its own password called BandMasterX where X is the number of the data band (0 through 15).

4.2.3

Default password

When the drive is shipped from the factory, all passwords are set to the value of MSID. This 32-byte random value can only be read by

 

the host electronically over the interface. After receipt of the drive, it is the responsibility of the owner to use the default MSID

 

password as the authority to change all other passwords to unique owner-specified values.

Содержание ST8000NM0045

Страница 1: ...e 4KN models ST8000NM0165 Self Encryption 4KN models ST8000NM0115 ST6000NM0165 SED FIPS 4KN models ST8000NM0145 Standard 512E models ST8000NM0055 ST6000NM0065 Self Encryption 512E models ST8000NM0105...

Страница 2: ...pending on operating environment and other factors The export or re export of hardware or software containing encryption may be regulated by the U S Department of Commerce Bureau of Industry and Secur...

Страница 3: ...6 4 Shock 15 2 6 5 Vibration 15 2 7 Acoustics 16 2 8 Test for Prominent Discrete Tones PDTs 16 2 9 Electromagnetic immunity 16 2 10 Reliability 17 2 10 1 Annualized Failure Rate AFR and Mean Time Bet...

Страница 4: ...ocking SP 24 4 2 3 Default password 24 4 3 Random number generator RNG 25 4 4 Drive locking 25 4 5 Data bands 25 4 6 Cryptographic erase 25 4 7 Authenticated firmware download 25 4 8 Power requirement...

Страница 5: ...com contacts For information regarding Warranty Support visit http www seagate com support warranty and replacements For information regarding data recovery services visit http www seagate com servic...

Страница 6: ...electable power savings SeaTools diagnostic software performs a drive self test that eliminates unnecessary drive returns State of the art cache and on the fly error correction algorithms Support for...

Страница 7: ...r the host operating system views the two devices as if they were both masters on two separate ports This essentially means both drives behave as if they are Device 0 master devices The Serial ATA hos...

Страница 8: ...NM0155 Drive specification ST8000NM0045 ST8000NM0055 ST8000NM0105 ST8000NM0115 ST8000NM0145 ST8000NM0155 ST8000NM0165 ST6000NM0055 ST6000NM0065 ST6000NM0155 ST6000NM0165 Formatted 512 bytes sector 8TB...

Страница 9: ...4 9 Grms ref Drive acoustics sound power bels Idle 2 8 typical 3 0 max Performance seek 3 2 typical 3 4 max Nonrecoverable read errors 1 sector per 1015 bits read Annualized Failure Rate AFR 0 44 bas...

Страница 10: ...Recording and interface technology 2 4 Start stop times ST models Formatted capacity Guaranteed sectors Bytes per logical sector ST8000NM0045 ST8000NM0115 ST8000NM0145 8TB 1 953 506 646 4096 ST6000NM...

Страница 11: ...ls Table 2 DC power requirements 8TB and 6TB 6 0Gb mode Voltage 5V 12V Watts Regulation 5 Total Avg Idle Current 0 29 0 56 8 15 Advanced Idle Current Idle_A 0 19 0 55 7 57 Idle_B 0 12 0 48 6 42 Idle_C...

Страница 12: ...ity 3 5 HDD v5 Serial ATA Product Manual Rev G 11 2 5 1 1 Typical current profiles Figure 1 8TB and 6TB Typical 5V startup and operation current profile Figure 2 8TB and 6TB Typical 12V startup and op...

Страница 13: ...ved settings persist across power on resets The current settings do not persist across power on resets At the time of manufacture the default saved and current settings are in the Power Conditions log...

Страница 14: ...ting to set a timer values less than the specified minimum timer value threshold will result in an aborted EPC Set Power Condition Timer subcommand Setting power condition timer values less than the m...

Страница 15: ...ze measure the case temperature of the drive See Figure 3 for HDA temperature checkpoint b Non operating 40 to 158 F 40 to 70 C package ambient with a maximum gradient of 36 F 20 C per hour This speci...

Страница 16: ...n in performance when subsequently put into operation is 250 Gs based on a nonrepetitive half sine shock pulse of 2ms duration 2 6 5 Vibration All vibration specifications assume that the drive is mou...

Страница 17: ...immunity When properly installed in a representative host system the drive operates without errors or degradation in performance when subjected to the radio frequency RF environments defined in the f...

Страница 18: ...rce on 20 April 2016 Testing is performed to the levels specified by the product standards for Information Technology Equipment ITE Emission levels are defined by EN 55032 2012 Class B and the immunit...

Страница 19: ...ser system by a Korean recognized lab 2 11 6 Morocco Commodity Mark To satisfy our OEM customers Seagate has added the Moroccan Commodity Mark to the drives provided to the OEM for the sale of Custome...

Страница 20: ...technician for additional suggestions Users may find helpful the following booklet prepared by the Federal Communications Commission How to Identify and Resolve Radio Television Interference Problems...

Страница 21: ...ction 5 of CNS 15663 effective January 1 2018 This product is Taiwan RoHS compliant The following table meets the Section 5 Marking of presence requirements Table 5 China Hazardous Substances Part Nam...

Страница 22: ...t fails to function properly under normal use due to defect in materials or workmanship or due to nonconformance to the applicable specifications will be repaired or replaced at Seagate s option and a...

Страница 23: ...can connect the drive as illustrated in Figure 4 Figure 4 Attaching SATA cabling Each cable is keyed to ensure correct orientation Enterprise Capacity 3 5 HDD Serial ATA drives support latching SATA...

Страница 24: ...301 and SFF 8323 found at www sffcommittee org Note The image is for mechanical dimension reference only and may not represent the actual drive 3 750 010 2X 1 625 020 2X 3 000 010 127 010 4 000 010 1...

Страница 25: ...DEK is itself encrypted when it is stored on the media and when it is in volatile temporary storage DRAM external to the encryption engine A unique data encryption key is used for each of the drive s...

Страница 26: ...nal 14 Data Bands may be defined in a similar way Band2 through Band15 but before these bands can be allocated LBA space they must first be individually enabled using the EraseMaster password Data ban...

Страница 27: ...ia the 2D barcode 4 11 ATA Security Erase Unit Command on SED SATA drives The ATA SECURITY ERASE UNIT command shall support both the Normal and Enhanced erase modes with the following modifications ad...

Страница 28: ...order to operate in FIPS Approved Mode of Operation these SEDs require security initialization For more information refer to Security Rules section in the Security Policy document uploaded on the NIS...

Страница 29: ...ng sequences are the ground pins P4 and P12 the pre charge power pins and the other ground pins the signal pins and the rest of the power pins 3 There are three power pins for each voltage One pin fro...

Страница 30: ...ax Address Ext 78H 0002H Check Power Mode E5H Download Microcode 92H Execute Device Diagnostics 90H Flush Cache E7H Flush Cache Extended EAH Identify Device ECH Idle E3H Idle Immediate E1H NoP 00H Rea...

Страница 31: ...ctor B0H D5H S M A R T Return Status B0H DAH S M A R T Save Attribute Values B0H D3H S M A R T Write Log Sector B0H D6H Standby E2H Standby Immediate E0H Trusted Send 5EH SED drives only Trusted Send...

Страница 32: ...ion 8 ASCII character string padded with blanks to end of string x xx 27 46 Drive model number 40 ASCII characters padded with blanks to end of string 47 Bits 7 0 Maximum sectors per interrupt on Read...

Страница 33: ...rted 7561H 84 Command sets support extension see note following this table 6173H 85 Command sets enabled 3069H 86 Command sets enabled B441H 87 Command sets enable extension 6173H 88 Ultra DMA support...

Страница 34: ...e sets supported 41DEH 120 Commands and feature sets supported or enabled 409CH 121 127 ATA reserved 0000H 128 Security status 0021H 129 159 Seagate reserved xxxxH 160 205 ATA reserved 0000H 206 SCT C...

Страница 35: ...MA FUA EXT and WRITE MULTIPLE FUA EXT commands are supported 7 WRITE DMA QUEUED FUA EXT command is supported 8 64 bit World Wide Name is supported 9 10 Obsolete 11 12 Reserved for TLC 13 IDLE IMMEDIAT...

Страница 36: ...ult 03H Set transfer mode based on value in Sector Count register Sector Count register values 00H Set PIO mode to default PIO mode 2 01H Set PIO mode to default and disable IORDY PIO mode 2 08H PIO m...

Страница 37: ...nates unnecessary drive returns The diagnostic software ships with all new drives and is also available at http www seagate com support downloads seatools This drive is shipped with S M A R T features...

Страница 38: ...ted States 408 658 1000 ASIA PACIFIC Seagate Singapore International Headquarters Pte Ltd 7000 Ang Mo Kio Avenue 5 Singapore 569877 65 6485 3888 EUROPE MIDDLE EAST AND AFRICA Seagate Technology SAS 16...

Отзывы: