Seagate ST9146803SS About self-encrypting drives, Data encryption, Controlled access, Admin SP

Page 45

9.0About self-encrypting drives

Self-encrypting drives (SEDs) offer encryption and security services for the protection of stored data, com- monly known as “protection of data at rest.” These drives are compliant with the Trusted Computing Group (TCG) Enterprise Storage Specifications as detailed in Section 3.2.

The Trusted Computing Group (TCG) is an organization sponsored and operated by companies in the com- puter, storage and digital communications industry. Seagate’s SED models comply with the standards pub- lished by the TCG.

To use the security features in the drive, the host must be capable of constructing and issuing the following two SCSI commands:

Security Protocol Out

Security Protocol In

These commands are used to convey the TCG protocol to and from the drive in their command payloads.

9.1Data encryption

Encrypting drives use one inline encryption engine for each port, employing AES-128 data encryption in Cipher Block Chaining (CBC) mode to encrypt all data prior to being written on the media and to decrypt all data as it is read from the media. The encryption engines are always in operation, cannot be disabled, and do not detract in any way from the performance of the drive.

The 32-byte Data Encryption Key (DEK) is a random number which is generated by the drive, never leaves the drive, and is inaccessible to the host system. The DEK is itself encrypted when it is stored on the media and when it is in volatile temporary storage (DRAM) external to the encryption engine. A unique data encryption key is used for each of the drive's possible16 data bands (see Section 9.5).

9.2Controlled access

The drive has two security partitions (SPs) called the "Admin SP" and the "Locking SP." These act as gate- keepers to the drive security services. Security-related commands will not be accepted unless they also supply the correct credentials to prove the requester is authorized to perform the command.

9.2.1Admin SP

The Admin SP allows the drive's owner to enable or disable firmware download operations (see Section 9.4). Access to the Admin SP is available using the SID (Secure ID) password or the MSID (Makers Secure ID) password.

Savvio 10K.3 SAS Product Manual, Rev. G

37

Image 45
Contents ST9300403SS ST9146603SS ST9300603SSST9300503SS ST9146803SSST9146703SSStandard Models Self-Encrypting Drive Models SED Fips 140-2 ModelsPage Contents Installation Defect and error managementAbout Fips About self-encrypting drives Interface requirementsPage Savvio 10K.3 SAS Product Manual, Rev. G List of Figures Page Seagate Online Support and Services Seagate Technology support servicesScope Standards Applicable standards and reference documentationElectromagnetic compatibility Electromagnetic susceptibilityElectromagnetic compliance for the European Union Electromagnetic complianceAustralian C-Tick Korean MICEuropean Union Restriction of Hazardous Substances RoHS Reference documentsGeneral description Media description Standard featuresReliability PerformanceFormatted capacities Programmable drive capacityFactory-installed options Internal drive characteristics Performance characteristicsSeek performance characteristics Access timeStart/stop time General performance characteristicsPrefetch/multi-segmented cache control Cache operationCaching write data Prefetch operation Error rates Reliability specificationsRecoverable Errors Unrecoverable ErrorsSeek errors Reliability and serviceInterface errors Preventive maintenanceControlling S.M.A.R.T 4 S.M.A.R.TPerformance impact Reporting controlTemperature Log Page 0Dh Parameter Code Description Predictive failuresThermal monitor Drive Self Test DST State of the drive prior to testingDST failure definition ImplementationShort test Function Code 001b Short and extended testsExtended test Function Code 010b Log page entriesProduct warranty ShippingProduct repair and return information Physical/electrical specifications AC power requirementsDC power requirements Savvio 10K.3 SAS Product Manual, Rev. G Page General DC power requirement notes Power sequencingConducted noise immunity Current profiles for 300GB models Current profilesCurrent profiles for 146GB models GB models in 3 Gbit operation Power dissipation300GB models in 6 Gbit operation 146GB models in 3 Gbit operation Temperature a. Operating Environmental limits146GB models in 6 Gbit operation Relative humidity Effective altitude sea level a. OperatingShock and vibration Shock Recommended mounting Vibration a. Operating-normalAir cleanliness Corrosive environmentAcoustics Mounting configuration dimensions Mechanical specificationsAbout Fips PurposeLevel 2 security Admin SP Controlled accessAbout self-encrypting drives Data encryptionRandom number generator RNG Default passwordDrive locking Data bandsPower requirements Authenticated firmware downloadSupported commands Cryptographic eraseDefect and error management Drive internal defects/errorsDrive error recovery procedures SAS system errors Background Media Scan Media Pre-ScanDeferred Auto-Reallocation Idle Read After Write Drive orientation InstallationAir flow CoolingGrounding Drive mountingInterface requirements SAS featuresDual port support Supported commands Scsi commands supportedSupported commands Supported commands Supported commands Mode Sense data Inquiry dataSavvio inquiry data Page Mode Pages Mode Sense data for 300GB drivesMode Sense values for 146GB drives Miscellaneous operating features and conditions Miscellaneous featuresMiscellaneous status SAS physical interface Datum B Section C C Section a a Connector requirements Physical characteristicsElectrical description Pin descriptionsPower Signal characteristicsSAS transmitters and receivers Ready LED OutLED drive signal SAS-2 Specification complianceDifferential signals General interface characteristicsSavvio 10K.3 SAS Product Manual, Rev. G Numerics IndexKCC Msid Mtbf See also cooling Page Seagate Technology LLC

ST9146803SS, ST9300603SS, ST9300503SS, ST9146603SS, ST9146703SS specifications

Seagate has long been a key player in the storage technology industry, and its enterprise-class hard drives such as the ST9300503SS, ST9300403SS, ST9146603SS, ST9146803SS, and ST9146703SS stand out for their performance, reliability, and innovative features. Designed primarily for use in data centers and server environments, these drives offer a range of specifications suited for high-demand applications.

The Seagate ST9300503SS is a 300GB 2.5-inch SAS (Serial Attached SCSI) hard drive that operates at 10,000 RPM, which is essential for ensuring rapid data access. It provides a data transfer rate of 6 Gb/s and features Seagate's AgileArray technology, which enhances RAID performance and reliability by improving data integrity and optimizing power consumption. The drive is also designed to withstand the rigors of enterprise use, boasting a mean time between failures (MTBF) rating of 1.6 million hours.

In contrast, the ST9300403SS offers a similar 300GB capacity and speed, but with slight variations in features that make it better suited for specific applications. This drive also supports SAS 2.0 and includes features that enhance error recovery and data protection.

The ST9146603SS is another powerhouse, providing 146GB of storage. Operating at the same high spindle speed of 10,000 RPM, it is optimized for low-latency performance. This makes it highly suitable for transactional applications and environments where quick access to data is crucial. Like its counterparts, this drive is built with robust technologies that ensure reliable operation and enhanced data security.

The ST9146803SS bumps up the storage capacity to 300GB while maintaining the same impressive speed and performance features. Its incorporation of Seagate’s SeaTach technology allows for advanced communication protocols, which facilitate faster data transfers and lower latency.

Finally, the ST9146703SS also offers 146GB of storage and is known for its energy efficiency features that reduce operational costs in large-scale deployments. All these drives support a wide range of operating systems, making them versatile picks for businesses looking to upgrade their storage solutions.

Overall, the Seagate ST9300503SS, ST9300403SS, ST9146603SS, ST9146803SS, and ST9146703SS are essential components in any enterprise environment, delivering high performance, reliability, and advanced technology features that meet the critical demands of modern data storage.