• Seagate


  •   
  • FileName: mb595_2_momentus_fde_sed_ii_sq_kit.pdf [read-online]
    • Abstract: Dell Latitude E6400. Yes / Yes. Pass. Pass. Pass. Dell Latitude E6500. Yes ... Dell Latitude E6400. Yes / Yes. Pass. Pass. Pass. Dell Latitude E6500. Yes ...

Download the ebook

Marketing Bulletin
Seagate Momentus FDE
® ®
Self-Encrypting Drive
Integrator Information and Self-Qualification Kit
Information for System Integrators
This bulletin provides information necessary to ensure your system
can support Seagate® Momentus® FDE Self-Encrypting Drives. While
This bulletin is provided
most systems have the needed functionality, certain chipset/BIOS
for informational purposes
only. Seagate provides no combinations may block certain commands that are needed to control
warranty either expressed the encrypting drives.
or implied regarding the
accuracy or validity of this
The process for self-qualification is as follows:
document and associated 1. Procure a Momentus FDE Self-Encrypting Drive.
information.
2. Determine your needs as a client and choose the appropriate level of
Self-Encrypting Drive management for your application.
3. If you do not require enterprise management of passwords and end-point
DO NOT COVER
encryption, consider using the ATA Security API by setting the drive’s
password in BIOS.
BREATHER HOLE
Momentus® Thin SED
XXXGB 4. If you do require enterprise management of passwords and end-point
WWN: XXXXXXXXXXXXXXXX
encryption, consider using the DriveTrust™ API and select a solution from
PSID: XXXXXXXX XXXXXXXX XXXXXXXX XXXXXXXX
+5V 0.45 A an independent software vendor (ISV).
Date: XXXXX
Site: XXX a. Check the Self-Encrypting Drive compatibility information listed in this
Product of China document regarding your system and your chosen solution.
CAUTION: Avoid excessive shock; do notorpush on
top cover or remove any seal label.
b. If the information regarding compatibility is not listed in this document:
Need support? Visit www.Seagate.com
® i. Use our Compatibility tool to determine if your system provides the
STX-MomentusThin (B)
E190397 N176 basic capabilities required for Self-Encrypting Drive management.
ii. Check with your chosen ISV to determine if your system is
compatible with their solution.
D33027
SN: XXXXXXXX
STXXXXXXXXXXX
PN: XXXXXX-XXX
FW: XXXXXXXX Procure a Seagate Momentus FDE Self-Encrypting Drive
The first step is to ensure that you have a Seagate Momentus FDE
Self-Encrypting Drive, as identified in Table 1. It is important that the part
Figure 1. Location of part number on drive label number on the drive label (Figure 1) matches one of the part numbers listed.
Seagate Momentus FDE
® ®
Self-Encrypting Drive
Integrator Information and Self-Qualification Kit
Table 1. Momentus FDE Self-Encrypting Drive Models
Description Model Number Part Number Capacity
ST980816AS 9CU132-527 80 GB
Momentus ® 5400 FDE.2 ST9120827AS 9CU133-527 120 GB
ST9160824AS 9CU134-527 160 GB
ST9250322AS 9GG133-500 250 GB
Momentus 5400 FDE.3
ST9320322AS 9GG134-500 320 GB
ST9160414AS 9GU142-500 160 GB
Momentus 7200 FDE ST9250424AS 9GU143-500 250 GB
ST9320424AS 9GU144-500 320 GB
1
ST9160414ASG 9GUG42-500 160 GB
Momentus 7200 FDE + ZGS
ST9320424ASG 9GUG44-500 320 GB
ST9120317AS 9PR131-500 120 GB
ST9160317AS 9PR13C-500 160 GB
Momentus 5400 FDE.4 ST9250317AS 9PR132-500 250 GB
ST9320327AS 9PR133-500 320 GB
ST9500327AS 9PR134-500 500 GB
ST9160413AS 9PT14C-500 160 GB
Momentus 7200 FDE.2 ST9250411AS 9PT142-500 250 GB
ST9500421AS 9PT144-500 500 GB
ST9160418ASG 9RXG4C-500 160 GB
Momentus 7200 FDE.2 + ZGS1 ST9250464ASG 9RXG42-500 250 GB
ST9500426ASG 9RXG44-500 500 GB
ST9250412AS 9PU142-500 250GB
Momentus 7200.2+FIPS 140-2 2
ST9500422AS 9PU144-500 500GB
ST250LT012 9YK14C-500 250GB
Momentus Thin
ST320LT012 9YK142-500 320GB
ST250LT009 9WC14C-500 250GB
Momentus Thin + FIPS-140-2 2
ST320LT009 9WC142-500 320GB
1 Zero G Sensor
2 See FIPS 140-2 Level 2 Certificate at http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/1401vend.htm.
Seagate continues to expand the Momentus FDE established and therefore not required to access
Self-Encrypting Drive family. For the most current the drive. The drive may be installed in a system
list of drive models and part numbers, go to www. and/or imaged the same as any non-encrypting
seagate.com/www/en-us/products/laptops/ hard drive. Following installation, the drive may
momentus/. be configured to operate in either the DriveTrust
Security API or the ATA Security API mode as
Note: Additional part numbers may ship in OEM
shown below, depending on your needs.
systems. Contact the OEM to ensure the system
contains the correct drives.
Determine Your Needs
Drive State Upon Shipment As mentioned above, there are currently two
options for managing your Self-Encrypting Drive.
Upon shipment, the Momentus FDE drive is fully
For clients who only require the ability to set
encrypting. However, authentication is not yet
2
Seagate Momentus FDE
® ®
Self-Encrypting Drive
Integrator Information and Self-Qualification Kit
a password on their drive and have a minimal Operating Systems
number of users (and passwords) to manage, the
• Windows XP SP1 or newer
ATA Security API may be an ideal solution. The
• Windows Server 2003
utility provided by this API is minimal and there
are no administrative tools for managing users. • Windows Vista RTM + Hotfix KB950096
However, this mode of operation requires no • Windows Vista SP1 + Hotfix KB943170
purchase or installation of third-party software • Windows Vista SP2 + Hotfix KB977323
and setup is relatively straightforward.
• Windows Server 2008 + Hotfix KB976323
For clients that require more features (such • Windows 7 + Hotfix KB976418
as single sign-on, password management
Seagate has tested a large population of systems
and recovery, or seamless external drive
with these components and found 100 percent of
management) or are deploying Self-Encrypting
the systems to be compatible with pass-through.
Drives in an environment with many users (more
Refer to Appendix B for the complete list of
than 20 users), the DriveTrust API enables ISVs
systems tested.
to create tools that provide you with these
capabilities. If your system is not listed in Appendix B,
Seagate provides a tool to verify your system’s
Compatibility Information pass-through capability. This tool and instructions
for its use are available at www.seagate.com/
DriveTrust Security API Using Third-Party support/sedqual/.
Software Management
Note: This test may be performed before the
This API provides robust security management installation of your FDE drive to avoid any return/
targeted for more feature-rich software warranty concerns with removing FDE drives from
management of Momentus FDE drives. This the shipment packaging.
requires Seagate-certified software from a third-
party software vendor. Third-Party Security Management Software
The following companies have been certified
Pass-Through Considerations
by Seagate for support of Momentus FDE
The Drive Trust Security API utilizes the ATA Self-Encrypting Drives via the DriveTrust Security
Trusted Send and Trusted Receive commands API. They have developed security management
as defined in the ATA-8 specification. Since software for single-user and enterprise-level
these are newer and optional commands in management of the Momentus FDE Self-
the ATA command set, many chipsets, drivers Encrypting Drives. Contact them directly for
and operating systems do not natively support software qualification assistance and to obtain
these commands. As a result, these commands a trial version of their software.
are delivered to the drive via the existing pass-
• CREDANT – DriveManager
through mechanisms.
www.credant.com/products/credant-
Seagate has done extensive development drivemanager.html
and testing and has identified the following
• Mobile Armor – DriveArmor
configurations that are available on all modern
www.mobilearmor.com/drivearmor.php
systems to support pass-through:
• SECUDE International AG – FinallySecure
ATA Drivers www.secude.com/html/index.php?id=1354
• Wave Systems Corp. – Embassy Remote
• Use the most current versions of atapi.sys,
Administration Server
msahci.sys, or iastor.sys.
www.wavesys.com/products/eras.asp
• Intel Turbo Memory must be disabled.
• WinMagic Data Security, Inc. – SecureDoc
• RAID must be disabled.
www.winmagic.com/seagate
3
Seagate Momentus FDE
® ®
Self-Encrypting Drive
Integrator Information and Self-Qualification Kit
Note: For the most up-to-date list of software 6. Enter the password. The hard drive is now
providers who support the Momentus FDE Self- unlocked, and the system will boot.
Encrypting Drives, go to www.seagate.com/ 7. On subsequent power-up events, repeat from
support/sedqual/. step 5.
Seagate maintains a security software Seagate attempts to verify Momentus FDE drive
compatibility lab to test the Momentus FDE Self- compatibility in as many systems as possible. To
Encrypting Drives with each certified software date, 100 percent of systems with BIOS hard drive
vendor. This testing has demonstrated broad password capability that have been tested have
compatibility across a large number of systems passed in ATA Security Mode.
while using the identified third-party management
For additional questions regarding system
software packages. Refer to Appendix A for a
capability for BIOS setting of hard drive
complete list of systems and software tested.
passwords, see your BIOS or system provider.
ATA Security API Using BIOS Management
Further Assistance
This API allows the client to set the drive’s
For further assistance and more information on
password in BIOS instead of relying upon third-
Seagate Momentus FDE Self-Encrypting Drives,
party software. This is a simple solution for
refer to the following:
situations that do not require robust policies or
password management. • Seagate FDE Self-Encrypting Drives:
www.seagate.com/security
System Considerations For system integration assistance follow the
To use the ATA Security API, the system integrator Security Partners and Integrators link.
will need to determine if the BIOS supports the • Seagate FDE Self-Encrypting Drive
setting of hard drive passwords. A typical way Compatibility Test:
to verify this is to access the BIOS setup screen www.seagate.com/security
by pressing a particular Function key (Fn) during Follow the SED Qualification Test link.
power-on, then navigate to the security or storage
• Ask the Expert: www.seagate.com/security
pages and find the drive password-setting
Follow the Ask the Expert link.
function.
• Seagate Customer Service:
Integration Procedure Phone: 1-800-SEAGATE (1-800-732-4283)
Upon verification of system BIOS capability, the Web: www.seagate.com/www/en-us/about/
system integrator just needs to set the hard drive contact_us
password in the BIOS to complete the validation, For further assistance with third-party software
as follows: integration, see your software providers.
1. Upon system power-on, access the BIOS-
Appendix A. DriveTrust™ Security API
setting menu (typically a function key).
Systems Tested
2. Access the ATA Security Hard Drive password-
setting menu (typical label is HDD password). The following systems have been tested in the
DriveTrust Security API mode. Note that the
3. Set the hard drive password according to the
absence of a particular system only means
menus.
that it has not been tested and implies neither
4. Follow the instructions for saving and
incompatibility nor compatibility. The broad
re-booting. (Your drive is now under password
compatibility shown below suggests there will
control)
be good compatibility on a large majority of
5. On the subsequent power-up, the BIOS systems across the notebook market. For all
will detect the locked drive and request the systems, system integrators may look for the
password prior to booting the system. system in Appendix B for general compatibility.
4
Seagate Momentus FDE
® ®
Self-Encrypting Drive
Integrator Information and Self-Qualification Kit
If the system is not listed in Appendix B, they Note: Pass indicates a tested and passing case.
may use the Compatibility Test provided by Blank squares represent a test case that cannot
Seagate to ensure correct operation. Once the occur for the target system or a test case Seagate
system integrator has either found their system has not included in the demonstration of broad
listed as passing in Appendix B, or successfully compatibility. We are constantly testing systems
run our Compatibility Test on the target system, for compatibility. For the most recent information
they should contact their intended ISV for further go to www.seagate.com/support/sedqual/.
information.
Summary Status of Credant v3.0.0.230
Chipset Chipset System BIOS Mode Win XP SP3 Win Vista SP2 Win 7 RTM
Manufacturer Southbridge Model AHCI / ATA AHCI ATA AHCI ATA AHCI ATA
ASUS U6Sg Yes / Yes Pass Pass
Dell Latitude D530 Yes / Yes Pass Pass Pass Pass Pass Pass
Dell Latitude D630 Yes / Yes Pass Pass Pass Pass
Dell Latitude D830 Yes / Yes Pass Pass Pass Pass Pass Pass
Dell Precision M4300 Yes / Yes Pass Pass
Dell Vostro 1400 Yes / Yes Pass Pass Pass Pass
Intel ICH-8M Dell XPS M1330 Yes / Yes Pass Pass Pass Pass Pass Pass
Fujitsu Lifebook E8410 Yes / Yes Pass Pass Pass Pass
Lenovo Thinkpad T61 Yes / Yes Pass Pass Pass Pass
LG R405s Yes / Yes Pass
NEC VERSA S5500 Yes / Yes Pass Pass
Packard Bell EasyNote 12-in. Yes / No Pass
Toshiba Satellite M200 Yes / No Pass
Acer Aspire 4930G Yes / Yes Pass
Acer Travelmate 6293 Yes / Yes Pass
Dell Latitude E4300 Yes / Yes Pass Pass
Dell Latitude E5400 Yes / Yes Pass Pass Pass
Dell Latitude E5500 Yes / Yes Pass Pass Pass Pass
Dell Latitude E6400 Yes / Yes Pass Pass Pass
Dell Latitude E6500 Yes / Yes Pass Pass
Dell Precision M2400 Yes / Yes Pass
Dell Precision M4400 Yes / Yes Pass Pass
Dell Precision M6400 Yes / Yes Pass
Dell Vostro 1088 Yes / Yes Pass Pass
Intel ICH-9M Dell Vostro 1520 Yes / Yes Pass
HP 2530b Yes / Yes Pass Pass Pass
HP 6530b Yes / Yes Pass Pass Pass
HP 6930p Yes / Yes Pass Pass
HP 8530p Yes / Yes Pass Pass Pass Pass
HP ProBook 4411s Yes / Yes Pass Pass
Lenovo ThinkPad T400 Yes / Yes Pass Pass
Lenovo ThinkPad X200s Yes / Yes Pass Pass
Lenovo ThinkPad W700 Yes / Yes Pass Pass
Panasonic CF-F8 Yes / No Pass
Panasonic CF-30 Yes / No Pass Pass
Panasonic CF-19 Yes / No Pass Pass
5
Seagate Momentus FDE
® ®
Self-Encrypting Drive
Integrator Information and Self-Qualification Kit
Summary Status of Credant v3.0.0.230 (continued)
Chipset Chipset System BIOS Mode Win XP SP3 Win Vista SP2 Win 7 RTM
Manufacturer Southbridge Model AHCI / ATA AHCI ATA AHCI ATA AHCI ATA
Panasonic CF-W8 Yes / No Pass Pass
Intel ICH-9M Samsung R420 Yes / Yes Pass
Toshiba Protégé A600 Yes / Yes Pass Pass Pass Pass
Dell OptiPlex 760 Yes / Yes Pass Pass
Intel ICH-10DO
Dell OptiPlex 960 Yes / Yes Pass Pass Pass Pass
AMD(ATI) SB700 HP 6535b Yes / Yes Pass
Summary Status of Mobile Armor v3.0.0.80
Chipset Chipset System BIOS Mode Win XP SP3 Win Vista SP2 Win 7 RTM
Manufacturer Southbridge Model AHCI / ATA AHCI ATA AHCI ATA AHCI ATA
ASUS U6Sg Yes / Yes Pass Pass
Dell Latitude D530 Yes / Yes Pass Pass Pass Pass Pass Pass
Dell Latitude D630 Yes / Yes Pass Pass Pass Pass
Dell Latitude D830 Yes / Yes Pass Pass Pass Pass Pass Pass
Dell Precision M4300 Yes /Yes Pass Pass
Dell Vostro 1400 Yes / Yes Pass Pass Pass Pass
Intel ICH-8M Dell XPS M1330 Yes / Yes Pass Pass Pass Pass Pass Pass
Fujitsu Lifebook E8410 Yes / Yes Pass Pass Pass Pass
Lenovo Thinkpad T61 Yes / Yes Pass Pass Pass Pass
LG R405s Yes / Yes Pass
NEC VERSA S5500 Yes / Yes Pass Pass
Packard Bell EasyNote 12-in. Yes / No Pass
Toshiba Satellite M200 Yes / No Pass
Acer Aspire 4930G Yes / Yes Pass
Acer Travelmate 6293 Yes / Yes Pass
Dell Latitude E4300 Yes / Yes Pass Pass
Dell Latitude E5400 Yes / Yes Pass Pass Pass
Dell Latitude E5500 Yes / Yes Pass Pass Pass Pass
Dell Latitude E6400 Yes / Yes Pass Pass Pass
Dell Latitude E6500 Yes / Yes Pass Pass
Dell Precision M2400 Yes / Yes Pass
Dell Precision M4400 Yes / Yes Pass Pass
Dell Precision M6400 Yes / Yes Pass
Intel ICH-9M
Dell Vostro 1088 Yes / Yes Pass Pass
Dell Vostro 1520 Yes / Yes Pass
HP 2530b Yes / Yes Pass Pass Pass
HP 6530b Yes / Yes Pass Pass Pass
HP 6930p Yes / Yes Pass Pass
HP 8530p Yes / Yes Pass Pass Pass Pass
HP ProBook 4411s Yes / Yes Pass Pass
Lenovo ThinkPad T400 Yes / Yes Pass Pass
Lenovo ThinkPad X200s Yes / Yes Pass Pass
Lenovo ThinkPad W700 Yes / Yes Pass Pass
6
Seagate Momentus FDE
® ®
Self-Encrypting Drive
Integrator Information and Self-Qualification Kit
Summary Status of Mobile Armor v3.0.0.80 (continued)
Chipset Chipset System BIOS Mode Win XP SP3 Win Vista SP2 Win 7 RTM
Manufacturer Southbridge Model AHCI / ATA AHCI ATA AHCI ATA AHCI ATA
Panasonic CF-F8 Yes / No Pass
Panasonic CF-30 Yes / No Pass Pass
Panasonic CF-19 Yes / No Pass Pass
Intel ICH-9M
Panasonic CF-W8 Yes / No Pass Pass
Samsung R420 Yes / Yes Pass
Toshiba Protégé A600 Yes / Yes Pass Pass Pass Pass
Dell OptiPlex 760 Yes / Yes Pass Pass
Intel ICH-10DO
Dell OptiPlex 960 Yes / Yes Pass Pass Pass Pass
AMD(ATI) SB700 HP 6535b Yes / Yes Pass
Summary Status of Wave Systems v1.14.03.000
Chipset Chipset System BIOS Mode Win XP SP3 Win Vista SP1
Manufacturer Southbridge Model AHCI / ATA AHCI ATA AHCI ATA
Acer Aspire 5680 No / Yes Pass Pass
Asus A8Jr No / Yes Pass Pass
Dell Latitude D520 No / Yes Pass
Dell Latitude D620 No / Yes Pass
Dell Latitude D820 No / Yes Pass
Intel ICH-7M
HP NC8430 Yes / Yes Pass Pass
HP NX6320 Yes / Yes Pass Pass
Lenovo Thinkpad T60 Yes /Yes Pass Pass Pass Pass
Lenovo Thinkpad X60 Yes / Yes Pass Pass Pass Pass
Panasonic CF-19 Yes / No Pass


Use: 0.0223