4.2.1ATA Security policy exceptions

In the ATA Security Interface mode, the drive conforms to the ATA Security Policy, except the following desir- able exceptions to implement the desired Momentus 7200 FDE.1 SATA behavior:

Upon execution of the secure erase sequence, the drive will have the following behavior:

All secure erase modes will instantaneously delete the encryption key rendering all user data unintelligible.

A new encryption key will be generated inside the drive replacing the previous encryption key.

The new encryption/decryption key will be applied to the data for all subsequent writes/reads prior to the next secure erase sequence.

The user password will be cleared to a null value.

The master password will retain the current value per the ATA specification.

Note. On completion of this sequence, the user is assured that all sectors on the drive are unintelligible and the drive is returned to the default factory state. It is then immediately ready for disposal or repurpos- ing.

The ATA Security Erase Unit Command provides for normal and enhanced erase modes as follows:

Table 6:

ATA Security Erase Unit bits

 

 

 

 

 

 

 

Word

 

Content

 

 

 

 

 

 

 

0

 

Control word

 

 

 

 

 

 

 

 

 

Bit 0

 

Identifier

0 = Compare User password

 

 

 

 

 

 

 

 

 

 

 

1 = Compare Master password

 

 

 

 

 

 

 

 

Bit 1

 

Erase mode

0 = Normal Erase

 

 

 

 

 

 

 

 

 

 

 

1 = Enhanced Erase

 

 

 

 

 

 

 

 

Bit (15:2)

 

Reserved

 

 

 

 

 

 

 

1 - 16

 

Password (32 bytes)

 

 

 

 

 

 

 

17 - 255

 

Reserved

 

 

 

 

 

 

 

 

Choosing enhanced erase mode will simply perform the cryptographic erase described above, and return sta- tus almost immediately. This is the recommended option.

To maintain consistency with the ATA Security specification, Momentus 7200 FDE.1 SATA drives provide an option to perform the Normal Erase mode.

Choosing normal erase will result in the drive performing the cryptographic erase which is the same as choos- ing enhanced erase.

Momentus 7200 FDE.1 SATA Product Manual, Rev. A

29

Page 35
Image 35
Seagate ST9120414AS, ST980414ASG, ST9320424AS ATA Security policy exceptions, ATA Security Erase Unit bits, Word Content