User Manual

Enterprise Self-Encrypting Drive User’s Guide, Rev. B 16
2.8 Taking ownership of an SED
When the drive is shipped from the factory, all of the user configurable credentials are set to the value of MSID, and
the dive is unlocked ready for installation in the new host system. The drive will perform as a standard non-encrypting
drive at this time with unrestricted access
1
, so the first thing the new owner should do is to personalize the drive to
preclude the possibility of malicious access and possible Denial of Service (DoS).
To personalize the SID, follow the procedure
2
shown in Figure 9.
Figure 9. Changing the SID credential value
The host starts a session with the drive’s Admin SP and asks the drive to provide the value of MSID, which is the cur-
rent default value of SID. Now that SID is known, the host can access the Admin SP’s credential table and change the
value of SID as required. The value of SID is now a secret known only to the drive owner.
Figure 10. Setting up a data band
1 The download port (logical port) defaults to the locked state and the R/W Long and R/W Buffer commands are not available.
2 The protocol for the procedures shown in Figures 9 and 10 is covered in detail in the Self-Encrypting Drive Users Guide, Part 2.