Chapter 15. Disk Security with Full Disk Encryption drives
471
Draft Document for Review March 28, 2011 12:24 pm
7914FDE.fm
The secure erase process is shown in Figure 15-23.
Figure 15-23 Secure erase process
Secure erase can only be performed on drives that are not allocated to an array. The process
is also referred to as re-provisioning, where:
The FDE drive becomes fully reusable.
The drive can be reused in secure or non-secure applications.
Previous data and keys are not accessible.
It executes in less than a second.
It returns the drive to the original factory state.
15.4.4 FDE drive status
The FDE drives have a status indicating whether the disk can be accessed. The statuses are:
Locked
– The drive is security capable.
– The drive has security enabled.
– The lock key has not been supplied to the drive.
– Data cannot be read or written from drive.
Unlocked
– The drive is security capable.
– The drive has security enabled.
– The lock key has been supplied to the drive.
– Data can be read or written from drive.
Warning: All data on the disk will be permanently and irrevocably erased when the secure
erase operation is completed for a security-enabled FDE drive. Do not perform this action
unless you are sure that you want to erase the data, as there is no recovery.
Data on Drive
The quick brown fox
jumps over the lazy dog
%$#@
βδελιφφυιλσκδ
%
$#@j&&6544IY899#@&$
%$#@
βδελιφφυιλσκδ
%
$#@j&&6544IY899#@&$
Data on Drive
Data Read from Drive
User Data
Data
Encryption
Key
New Data
Encryption
Key
Writing to the Drive
Encryption Process
Reading from the Drive
Decryption Process
±
!
Instant Secure
Erase
Change Data Encryption
Key
Summary of Contents for DS3500
Page 2: ......
Page 5: ...iii Draft Document for Review March 28 2011 12 24 pm 7914edno fm ...
Page 789: ......