Seagate Momentus FDE Self-Encrypting Drive

Transcription

Marketing BulletinSeagate Momentus FDESelf-Encrypting Drive Integrator Information and Self-Qualification KitInformation for System IntegratorsThis bulletin provides information necessary to ensure your systemcan support Seagate Momentus FDE Self-Encrypting Drives. Whilemost systems have the needed functionality, certain chipset/BIOScombinations may block certain commands that are needed to controlthe encrypting drives.This bulletin is providedfor informational purposesonly. Seagate provides nowarranty either expressedor implied regarding theaccuracy or validity of thisdocument and associatedinformation.The process for self-qualification is as follows:1. Procure a Momentus FDE Self-Encrypting Drive.2. Determine your needs as a client and choose the appropriate level ofSelf-Encrypting Drive management for your application.DO NOT COVERBREATHER HOLEMomentus Thin SEDXXXGBWWN: XXXXXXXXXXXXXXXXPSID: XXXXXXXX XXXXXXXX XXXXXXXX XXXXXXXX 5V 0.45 ADate: XXXXXSite: XXXProduct of Chinaexcessive shock; do not push onCAUTION: Avoidtop cover or remove any seal or label.Need support? Visit www.Seagate.com STX-MomentusThin (B)E190397N1763. If you do not require enterprise management of passwords and end-pointencryption, consider using the ATA Security API by setting the drive’spassword in BIOS.4. If you do require enterprise management of passwords and end-pointencryption, consider using the DriveTrust API and select a solution froman independent software vendor (ISV).a. Check the Self-Encrypting Drive compatibility information listed in thisdocument regarding your system and your chosen solution.b. If the information regarding compatibility is not listed in this document:i. Use our Compatibility tool to determine if your system provides thebasic capabilities required for Self-Encrypting Drive management.ii. Check with your chosen ISV to determine if your system iscompatible with their solution.D33027SN: XXXXXXXXSTXXXXXXXXXXXPN: XXXXXX-XXXFW: XXXXXXXXFigure 1. Location of part number on drive labelProcure a Seagate Momentus FDE Self-Encrypting DriveThe first step is to ensure that you have a Seagate Momentus FDESelf-Encrypting Drive, as identified in Table 1. It is important that the partnumber on the drive label (Figure 1) matches one of the part numbers listed.

Seagate Momentus FDESelf-Encrypting Drive Integrator Information and Self-Qualification KitTable 1. Momentus FDE Self-Encrypting Drive ModelsDescriptionMomentus 5400 FDE.2Momentus 5400 FDE.3Momentus 7200 FDEMomentus 7200 FDE ZGS1Momentus 5400 FDE.4Momentus 7200 FDE.2Momentus 7200 FDE.2 ZGS1Momentus 7200.2 FIPS 140-2 2Momentus ThinMomentus Thin FIPS-140-2 2Model NumberPart NumberCapacityST980816AS9CU132-52780 GBST9120827AS9CU133-527120 GBST9160824AS9CU134-527160 GBST9250322AS9GG133-500250 GBST9320322AS9GG134-500320 GBST9160414AS9GU142-500160 GBST9250424AS9GU143-500250 GBST9320424AS9GU144-500320 GBST9160414ASG9GUG42-500160 GBST9320424ASG9GUG44-500320 GBST9120317AS9PR131-500120 GBST9160317AS9PR13C-500160 GBST9250317AS9PR132-500250 GBST9320327AS9PR133-500320 GBST9500327AS9PR134-500500 GBST9160413AS9PT14C-500160 GBST9250411AS9PT142-500250 GBST9500421AS9PT144-500500 GBST9160418ASG9RXG4C-500160 GBST9250464ASG9RXG42-500250 GBST9500426ASG9RXG44-500500 20GB1 Zero G Sensor2 See FIPS 140-2 Level 2 Certificate at -1/1401vend.htm.Seagate continues to expand the Momentus FDESelf-Encrypting Drive family. For the most currentlist of drive models and part numbers, go to s/.Note: Additional part numbers may ship in OEMsystems. Contact the OEM to ensure the systemcontains the correct drives.Drive State Upon ShipmentUpon shipment, the Momentus FDE drive is fullyencrypting. However, authentication is not yet2established and therefore not required to accessthe drive. The drive may be installed in a systemand/or imaged the same as any non-encryptinghard drive. Following installation, the drive maybe configured to operate in either the DriveTrustSecurity API or the ATA Security API mode asshown below, depending on your needs.Determine Your NeedsAs mentioned above, there are currently twooptions for managing your Self-Encrypting Drive.For clients who only require the ability to set

Seagate Momentus FDESelf-Encrypting Drive Integrator Information and Self-Qualification Kita password on their drive and have a minimalnumber of users (and passwords) to manage, theATA Security API may be an ideal solution. Theutility provided by this API is minimal and thereare no administrative tools for managing users.However, this mode of operation requires nopurchase or installation of third-party softwareand setup is relatively straightforward.Operating SystemsFor clients that require more features (suchas single sign-on, password managementand recovery, or seamless external drivemanagement) or are deploying Self-EncryptingDrives in an environment with many users (morethan 20 users), the DriveTrust API enables ISVsto create tools that provide you with thesecapabilities. Windows 7 Hotfix KB976418Compatibility InformationDriveTrust Security API Using Third-PartySoftware ManagementThis API provides robust security managementtargeted for more feature-rich softwaremanagement of Momentus FDE drives. Thisrequires Seagate-certified software from a thirdparty software vendor.Pass-Through ConsiderationsThe Drive Trust Security API utilizes the ATATrusted Send and Trusted Receive commandsas defined in the ATA-8 specification. Sincethese are newer and optional commands inthe ATA command set, many chipsets, driversand operating systems do not natively supportthese commands. As a result, these commandsare delivered to the drive via the existing passthrough mechanisms.Seagate has done extensive developmentand testing and has identified the followingconfigurations that are available on all modernsystems to support pass-through:ATA Drivers Use the most current versions of atapi.sys,msahci.sys, or iastor.sys. Intel Turbo Memory must be disabled. RAID must be disabled.3 Windows XP SP1 or newer Windows Server 2003 Windows Vista RTM Hotfix KB950096 Windows Vista SP1 Hotfix KB943170 Windows Vista SP2 Hotfix KB977323 Windows Server 2008 Hotfix KB976323Seagate has tested a large population of systemswith these components and found 100 percent ofthe systems to be compatible with pass-through.Refer to Appendix B for the complete list ofsystems tested.If your system is not listed in Appendix B,Seagate provides a tool to verify your system’spass-through capability. This tool and instructionsfor its use are available at www.seagate.com/support/sedqual/.Note: This test may be performed before theinstallation of your FDE drive to avoid any return/warranty concerns with removing FDE drives fromthe shipment packaging.Third-Party Security Management SoftwareThe following companies have been certifiedby Seagate for support of Momentus FDESelf-Encrypting Drives via the DriveTrust SecurityAPI. They have developed security managementsoftware for single-user and enterprise-levelmanagement of the Momentus FDE SelfEncrypting Drives. Contact them directly forsoftware qualification assistance and to obtaina trial version of their software. CREDANT – anager.html Mobile Armor – DriveArmorwww.mobilearmor.com/drivearmor.php SECUDE International AG – FinallySecurewww.secude.com/html/index.php?id 1354 Wave Systems Corp. – Embassy RemoteAdministration Serverwww.wavesys.com/products/eras.asp WinMagic Data Security, Inc. – SecureDocwww.winmagic.com/seagate

Seagate Momentus FDESelf-Encrypting Drive Integrator Information and Self-Qualification KitNote: For the most up-to-date list of softwareproviders who support the Momentus FDE SelfEncrypting Drives, go to www.seagate.com/support/sedqual/.6. Enter the password. The hard drive is nowunlocked, and the system will boot.Seagate maintains a security softwarecompatibility lab to test the Momentus FDE SelfEncrypting Drives with each certified softwarevendor. This testing has demonstrated broadcompatibility across a large number of systemswhile using the identified third-party managementsoftware packages. Refer to Appendix A for acomplete list of systems and software tested.Seagate attempts to verify Momentus FDE drivecompatibility in as many systems as possible. Todate, 100 percent of systems with BIOS hard drivepassword capability that have been tested havepassed in ATA Security Mode.ATA Security API Using BIOS ManagementThis API allows the client to set the drive’spassword in BIOS instead of relying upon thirdparty software. This is a simple solution forsituations that do not require robust policies orpassword management.System ConsiderationsTo use the ATA Security API, the system integratorwill need to determine if the BIOS supports thesetting of hard drive passwords. A typical wayto verify this is to access the BIOS setup screenby pressing a particular Function key (Fn) duringpower-on, then navigate to the security or storagepages and find the drive password-settingfunction.For additional questions regarding systemcapability for BIOS setting of hard drivepasswords, see your BIOS or system provider.Further AssistanceFor further assistance and more information onSeagate Momentus FDE Self-Encrypting Drives,refer to the following: Seagate FDE Self-Encrypting Drives:www.seagate.com/securityFor system integration assistance follow theSecurity Partners and Integrators link. Seagate FDE Self-Encrypting DriveCompatibility Test:www.seagate.com/securityFollow the SED Qualification Test link. Ask the Expert: www.seagate.com/securityFollow the Ask the Expert link. Seagate Customer Service:Integration ProcedurePhone: 1-800-SEAGATE (1-800-732-4283)Upon verification of system BIOS capability, thesystem integrator just needs to set the hard drivepassword in the BIOS to complete the validation,as follows:Web: www.seagate.com/www/en-us/about/contact us1. Upon system power-on, access the BIOSsetting menu (typically a function key).2. Access the ATA Security Hard Drive passwordsetting menu (typical label is HDD password).3. Set the hard drive password according to themenus.4. Follow the instructions for saving andre-booting. (Your drive is now under passwordcontrol)5. On the subsequent power-up, the BIOSwill detect the locked drive and request thepassword prior to booting the system.47. On subsequent power-up events, repeat fromstep 5.For further assistance with third-party softwareintegration, see your software providers.Appendix A. DriveTrust Security APISystems TestedThe following systems have been tested in theDriveTrust Security API mode. Note that theabsence of a particular system only meansthat it has not been tested and implies neitherincompatibility nor compatibility. The broadcompatibility shown below suggests there willbe good compatibility on a large majority ofsystems across the notebook market. For allsystems, system integrators may look for thesystem in Appendix B for general compatibility.

Seagate Momentus FDESelf-Encrypting Drive Integrator Information and Self-Qualification KitIf the system is not listed in Appendix B, theymay use the Compatibility Test provided bySeagate to ensure correct operation. Once thesystem integrator has either found their systemlisted as passing in Appendix B, or successfullyrun our Compatibility Test on the target system,they should contact their intended ISV for furtherinformation.Note: Pass indicates a tested and passing case.Blank squares represent a test case that cannotoccur for the target system or a test case Seagatehas not included in the demonstration of broadcompatibility. We are constantly testing systemsfor compatibility. For the most recent informationgo to www.seagate.com/support/sedqual/.Summary Status of Credant thbridgeICH-8MICH-9MSystemModelBIOS ModeAHCI / ATAWin XP SP3AHCIATAWin Vista SP2AHCIATAPassPassASUS U6SgYes / YesDell Latitude D530Yes / YesPassPassPassPassDell Latitude D630Yes / YesPassPassPassPassDell Latitude D830Yes / YesPassPassPassPassDell Precision M4300Yes / YesPassPassDell Vostro 1400Yes / YesPassPassPassPassDell XPS M1330Yes / YesPassPassPassPassFujitsu Lifebook E8410Yes / YesPassPassPassPassLenovo Thinkpad T61Yes / YesPassPassPassPassLG R405sYes / YesNEC VERSA S5500Yes / YesPassPackard Bell EasyNote 12-in.Yes / NoPassToshiba Satellite M200Yes / NoPassAcer Aspire 4930GYes / YesPassAcer Travelmate 6293Yes / YesPassDell Latitude E4300Yes / YesDell Latitude E5400Yes / YesPassPassDell Latitude E5500Yes / YesPassPassDell Latitude E6400Yes / YesPassPassDell Latitude E6500Yes / YesDell Precision M2400Yes / YesDell Precision M4400Yes / YesDell Precision M6400Yes / YesPassDell Vostro 1088Yes / YesPassDell Vostro 1520Yes / YesPassHP 2530bYes / YesPassPassPassHP 6530bYes / YesPassPassPassHP 6930pYes / YesPassPassHP 8530pYes / YesPassPassPassHP ProBook 4411sYes / YesPassLenovo ThinkPad T400Yes / YesPassPassLenovo ThinkPad X200sYes / YesPassPassLenovo ThinkPad W700Yes / YesPassPassPanasonic CF-F8Yes / NoPassPanasonic CF-30Yes / NoPassPassPanasonic CF-19Yes / NoPassPassWin 7 PassPassPassPassPassPassPassPassPassPassPassPass

Seagate Momentus FDESelf-Encrypting Drive Integrator Information and Self-Qualification KitSummary Status of Credant v3.0.0.230 dgeICH-9MIntelICH-10DOAMD(ATI)SB700SystemModelWin XP SP3Win Vista SP2BIOS ModeAHCI / ATAAHCIPanasonic CF-W8Yes / NoPassSamsung R420Yes / YesPassToshiba Protégé A600Yes / YesDell OptiPlex 760Yes / YesDell OptiPlex 960HP 6535bATAAHCIWin 7 RTMATAAHCIATAPassPassPassPassPassPassYes / YesPassPassPassPassYes / YesPassPassSummary Status of Mobile Armor hbridgeICH-8MICH-9MSystemModelBIOS ModeAHCI / ATAWin XP SP3AHCIATAWin Vista SP2AHCIATAPassPassASUS U6SgYes / YesDell Latitude D530Yes / YesPassPassPassPassDell Latitude D630Yes / YesPassPassPassPassDell Latitude D830Yes / YesPassPassPassPassDell Precision M4300Yes /YesPassPassDell Vostro 1400Yes / YesPassPassPassPassDell XPS M1330Yes / YesPassPassPassPassFujitsu Lifebook E8410Yes / YesPassPassPassPassLenovo Thinkpad T61Yes / YesPassPassPassPassLG R405sYes / YesNEC VERSA S5500Yes / YesPassPackard Bell EasyNote 12-in.Yes / NoPassToshiba Satellite M200Yes / NoPassAcer Aspire 4930GYes / YesPassAcer Travelmate 6293Yes / YesPassDell Latitude E4300Yes / YesDell Latitude E5400Yes / YesPassPassDell Latitude E5500Yes / YesPassPassDell Latitude E6400Yes / YesPassPassDell Latitude E6500Yes / YesDell Precision M2400Yes / YesDell Precision M4400Yes / YesDell Precision M6400Yes / YesPassDell Vostro 1088Yes / YesPassDell Vostro 1520Yes / YesPassHP 2530bYes / YesPassPassPassHP 6530bYes / YesPassPassPassHP 6930pYes / YesPassPassHP 8530pYes / YesPassPassPassHP ProBook 4411sYes / YesPassLenovo ThinkPad T400Yes / YesPassPassLenovo ThinkPad X200sYes / YesPassPassLenovo ThinkPad W700Yes / YesPassPassWin 7 PassPassPassPassPassPassPassPassPassPassPassPass

Seagate Momentus FDESelf-Encrypting Drive Integrator Information and Self-Qualification KitSummary Status of Mobile Armor v3.0.0.80 dgeICH-9MIntelICH-10DOAMD(ATI)SB700SystemModelBIOS ModeAHCI / ATAWin XP SP3AHCIATAWin Vista SP2AHCIAHCIATAPassPassPassPassPanasonic CF-F8Yes / NoPassPanasonic CF-30Yes / NoPassPassPanasonic CF-19Yes / NoPassPassPanasonic CF-W8Yes / NoPassPassSamsung R420Yes / YesPassToshiba Protégé A600Yes / YesPassPassDell OptiPlex 760Yes / YesPassPassDell OptiPlex 960Yes / YesPassPassHP 6535bYes / YesPassSummary Status of Wave Systems outhbridgeICH-7MICH-8MSystemModelBIOS ModeAHCI / ATAWin 7 RTMATAWin XP SP3AHCIATAWin Vista SP1AHCIATAAcer Aspire 5680No / YesPassPassAsus A8JrNo / YesPassPassDell Latitude D520No / YesPassDell Latitude D620No / YesPassDell Latitude D820No / YesHP NC8430Yes / YesPassPassHP NX6320Yes / YesPassPassLenovo Thinkpad T60Yes /YesPassPassPassPassLenovo Thinkpad X60Yes / YesPassPassPassPassPanasonic CF-19Yes / NoPassAsus F9SYes / YesPassPassPassPassAsus G2SYes / YesPassPassPassPassAsus U65gYes / YesPassPassBenQ Joybook S32WYes / NoPassPassBenQ Joybook S41Yes / NoDell Latitude D530Yes / YesPassPassPassDell Latitude D630Yes / YesPassPassDell Latitude D830Yes / YesPassPassDell Vostro 1400Yes / YesDell Vostro 1500Yes / YesPassPassDell XPS M1330Yes / YesPassFujitsu Lifebook A6030Yes / YesFujitsu Lifebook assPassYes / YesPassPassPassPassHP Compaq 6910pYes / YesPassPassPassPassHP Compaq 8510pYes /YesPassPassPassPassLenovo Thinkpad T61Yes / YesPassPassLenovo Thinkpad T61Yes / YesLG R4O5sYes / YesPassPassNEC VERSA E6310Yes / YesPassPassNEC VERSA S5500Yes / YesPassPassPackard Bell EasyNote 12-in.Yes / NoPassPanasonic CF-Y7Yes / NoPassPanasonic Toughbook 74Yes / NoPassPassPassPass

Seagate Momentus FDESelf-Encrypting Drive Integrator Information and Self-Qualification KitSummary Status of Wave Systems v1.14.03.000 thbridgeICH-8MICH-9MSystemModelBIOS ModeAHCI / ATAToshiba Tecra M9Yes / NoPassPassToshiba Satellite U300Yes / NoPassPassToshiba Tecra MBYes / NoPassPassDell Latitude E5500Yes / YesPassPassDell Latitude E6500Yes / YesPassPassDell Latitude ES400Yes / YesPassPassDell Latitude E6400Yes / YesPassPassHP 6530bYes / YesLenovo ThinkPad T400Yes / YesDell Latitude D531No / YesNvidiaMCP67Acer Aspire 4520Yes / YesVIAVT8237R Win Vista SP1AHCIYes / NoSB600SB700ATAToshiba Satellite M200AMD(ATI)AMD(ATI)Win XP SP3AHCIPassPassPassPassHP 6535bHP Pavilion dv4zATAPassPassPassFounder R611No / YesPassHaier A60No / YesPassPassPassPassPassSummary Status of WinMagic etSouthbridgeICH-7MICH-8MSystemModelBIOS Mode AHCI / ATAWin XP SP3AHCIATAWin Vista SP1AHCIATAAcer Aspire 5610ZNo / YesPassPassAcer Aspire 5680No / YesPassPassAcer TravelMate 8210No / YesPassAsus A8FmNo / YesPassPassAsus A8JrNo / YesPassPassDell Latitude D520No / YesPassDell Latitude D620No / YesPassDell Latitude D820No / YesHP NX6320Yes / YesPassPassHP Pavilion DV6000TYes / YesPassPassLenovo Thinkpad T60Yes / YesPassPassPassPassLenovo Thinkpad X60Yes / YesPassPassPassPassPanasonic CF-19Yes / NoPassBenQ Joybook S32WYes / NoBenQ Joybook S41Yes / NoDell Latitude D530Yes / YesPassPassDell Latitude D630Yes / YesPassPassDell Latitude D830Yes / YesPassPassDell Vostro 1400Yes / YesDell Vostro 1500Yes / YesPassPassDell XPS M1330Yes / YesPassFujitsu Lifebook A6030Yes / YesFujitsu Lifebook assPassPassPassPassYes / YesPassPassPassPassHP Compaq 6910pYes / YesPassPassPassPassHP Compaq 8510pYes / YesPassPassPassPass

Seagate Momentus FDESelf-Encrypting Drive Integrator Information and Self-Qualification KitSummary Status of WinMagic v4.5.20080515.12 dgeICH-8MAMD(ATI)SB600NvidiaMCP67VIASISVT8237R VT8237ASIS968SystemModelBIOS Mode AHCI / ATAWin XP SP3AHCIATAWin Vista SP1AHCIATAPassPassLenovo Thinkpad T61Yes / YesLenovo Thinkpad T61Yes / YesLG P300uYes / YesPassNEC VERSA S5500Yes / YesPassPackard Bell EasyNote 12-in.Yes / NoPassPanasonic CF-Y7Yes / NoPassPanasonic Toughbook 74Yes / NoPassToshiba Satellite M200Yes / NoToshiba Tecra M9Yes / NoPassPassToshiba Satellite U300Yes / NoPassPassToshiba Tecra M8Yes / NoPassDell Latitude D531No / YesPassHP Compaq 6515pNo / YesPassAcer Aspire 4520Yes / YesFounder R611No / YesPassHaier A60No / YesPassTongFang K431No / YesPassBenQ Q41No / YesHaier A20Yes / YesPassPackard Bell EasyNote 15-in.No / YesPas

WinMagic Data Security, Inc. – SecureDoc . power-on, then navigate to the security or storage pages and find the drive password-setting function. Integration Procedure Upon verification of system BIOS capabilit