The Opal Storage Specification is a set of specifications for features of data storage devices (such as hard disk drives and solid state drives) that enhance their security. For example, it defines a way of encrypting the stored data so that an unauthorized person who gains possession of the device cannot see the data. That is, it is a specification for self-encrypting drives (SED).
The specification is published by the Trusted Computing Group Storage Workgroup.
Overview
The Opal SSC (Security Subsystem Class) is an implementation profile for Storage Devices built to:
- Protect the confidentiality of stored user data against unauthorized access once it leaves the owner's control (involving a power cycle and subsequent deauthentication).
- Enable interoperability between multiple SD vendors.1
Functions
The Opal SSC encompasses these functions:
- Security provider support
- Interface communication protocol
- Cryptographic features
- Authentication
- Table management
- Access control and personalization
- Issuance
- SSC discovery
Features
- Security Protocol 1 support
- Security Protocol 2 support
- Communications
- Protocol stack reset commands
Security
Radboud University researchers indicated in November 2018 that some hardware-encrypted SSDs, including some Opal implementations, had security vulnerabilities.2
Implementers of SSC
Device companies
- Hitachi
- Intel Corporation3
- Kingston Technology4
- Lenovo5
- Micron Technology6
- Samsung7
- SanDisk8
- Seagate Technology910 as "Seagate Secure"
- Toshiba111213
Storage controller companies
Software companies
- Absolute Software17
- Check Point Software Technologies18
- Dell Data Protection19
- Cryptomill20
- McAfee21
- Secude 22
- Softex Incorporated23
- Sophos24
- Symantec25 (Symantec supports OPAL drives, but does not support hardware-based encryption.)26
- Trend Micro27
- WinMagic28
- OpalLock29(OpalLock support Self-Encrypt-Drive capable SSD and HDD. Develop by Fidelity Height LLC)
Computer OEMs
External links
References
TCG Storage Security Subsystem Class: Opal Specification Version 2.01 Revision 1.00. Trusted Computing Group, Incorporated. 05 August 2015. Retrieved 2019-11-22. https://trustedcomputinggroup.org/wp-content/uploads/TCG_Storage-Opal_SSC_v2.01_rev1.00.pdf#page=12 ↩
Meijer, Carlo; van Gastel, Bernard (19–23 May 2019). Self-Encrypting Deception: Weaknesses in the Encryption of Solid State Drives. 2019 IEEE Symposium on Security and Privacy (SP). San Francisco, CA, USA: IEEE. pp. 72–87. doi:10.1109/SP.2019.00088. hdl:2066/207837. ISBN 978-1-5386-6660-9. ISSN 2375-1207. 978-1-5386-6660-9 ↩
"Intel® SSD Pro 1500 Series (M.2): Specs". Intel.com. Retrieved 2017-05-03. http://www.intel.com/content/www/us/en/solid-state-drives/ssd-pro-1500-series-m2-specification.html ↩
"Solid State Hard Drives for Business". Kingston.com. 2017-03-05. Retrieved 2017-05-03. http://www.kingston.com/us/ssd/vplus/#skc300s3 ↩
Clain Anderson (2011-02-16). "Opal – More than a Semi-Precious Stone | Lenovo". Blog.lenovo.com. Retrieved 2017-05-03. http://blog.lenovo.com/en/blog/opal-more-than-a-semi-precious-stone ↩
"Micron Technology, Inc. - Full SSD Part Catalog". Micron.com. Retrieved 2017-05-03. http://micron.com/products/solid-state-storage/client-ssd ↩
"Samsung V-NAND SSD". Samsung.com. Retrieved 2017-05-03. http://www.samsung.com/global/business/semiconductor/minisite/SSD/global/html/about/whitepaper06.html ↩
"SanDisk's X300s Solid State Drive". Archived from the original on 2014-08-03. Retrieved 2014-08-02. https://web.archive.org/web/20140803081737/http://www.sandisk.com/products/ssd/sata/x300s ↩
"News". Seagate. Retrieved 2017-05-03. http://www.seagate.com/ww/v/index.jsp?locale=en-US&name=momentus-FDE-self-encrypting,FIPS-seagate-pr&vgnextoid=f0ea53279dc0b210VgnVCM1000001a48090aRCRD ↩
"Full Disk Encryption Software, Hard Drives, SSDs & Whole Disk". WinMagic. Retrieved 2017-05-03. http://www.winmagic.com/solutions/self-encrypting-hard-drives ↩
"Fujitsu Develops HDD Security Technology based on Opal SSC Standards - Fujitsu Global". Fujitsu.com. Retrieved 2017-05-03. http://www.fujitsu.com/global/news/pr/archives/month/2009/20090128-01.html ↩
"Specialty | TOSHIBA Storage & Electronic Devices Solutions Company | Americas". Storage.toshiba.com. Retrieved 2017-05-03. http://storage.toshiba.com/storagesolutions/specialty-products/mkxx61gsyg-series ↩
"Specialty | TOSHIBA Storage & Electronic Devices Solutions Company | Americas". Storage.toshiba.com. Retrieved 2017-05-03. http://storage.toshiba.com/storagesolutions/specialty-products/mkxx61gsyd-series ↩
"Marvell Technology Group Ltd". Marvell.com. Retrieved 2017-05-03. http://www.marvell.com ↩
"Marvell, Kingston Collaboration Proves Positive with Over Six Million SSD Units Shipped". Kingston Technology. Retrieved 30 December 2021. https://www.kingston.com/spain/es/company/press/article/49507 ↩
"SandForce Flash Storage Processor SSD Controllers". Archived from the original on 2013-08-08. Retrieved 2013-08-01. https://web.archive.org/web/20130808084202/http://www.lsi.com/products/storagecomponents/Pages/sandforce_flash_storage_processors.aspx ↩
"Self-Healing Endpoint Security". Absolute. Retrieved 2017-05-03. http://www.absolute.com ↩
"Industry-Leading Cyber Security Keeps Networks, Data Centers, Mobile Devices & Endpoints One Step Ahead | Check Point Software". Checkpoint.com. Retrieved 2017-05-03. http://www.checkpoint.com ↩
"Data Security | Dell United States". Dell.com. 2017-04-26. Retrieved 2017-05-03. http://www.dell.com/encryption ↩
"CryptoMill :: Products & services". Archived from the original on 2012-02-09. Retrieved 2012-01-14. https://web.archive.org/web/20120209044329/http://www.cryptomill.com/products/default.php ↩
"McAfee Corporate KB - KB75045". Kc.mcafee.com. Retrieved 2017-05-03. https://kc.mcafee.com/corporate/index?page=content&id=KB75045 ↩
"FinallySecure™ Enterprise - SECUDE AG". Archived from the original on 2012-01-26. Retrieved 2012-01-14. https://web.archive.org/web/20120126034405/http://www.secude.com/products/finallysecuretrade-enterprise/ ↩
"Comprehensive Data Encryption and Protection Solutions - SecureDrive". Softexinc.com. 2014-06-20. Retrieved 2017-05-03. http://www.softexinc.com/securedrive/overview ↩
"Full Disk Encryption | Always-On, Multi-Platform Enterprise Encryption Synchronizes Devices, Hard Drives, Removable Media, BitLocker, and Cloud Storage Protection in Real-Time". Sophos.com. Retrieved 2017-05-03. https://www.sophos.com/en-us/products/safeguard-encryption.aspx ↩
"Endpoint Encryption Powered by PGP Technology". Symantec.com. Retrieved 2017-05-03. https://www.broadcom.com/products/cybersecurity ↩
"Archived copy". Archived from the original on 2017-09-25. Retrieved 2016-02-03.{{cite web}}: CS1 maint: archived copy as title (link) https://web.archive.org/web/20170925230747/https://support.symantec.com/en_US/article.tech217784.html ↩
"Data Protection – Endpoint and Gateway Suites | Trend Micro". Us.trendmicro.com. Retrieved 2017-05-03. http://us.trendmicro.com/us/products/enterprise/endpoint-encryption/index.html ↩
"Full Disk Encryption Software, Hard Drives, SSDs & Whole Disk". WinMagic. Retrieved 2017-05-03. http://www.winmagic.com/products ↩
"Software management of TCG self-encrypting drives". Fidelity Height LLC. https://fidelityheight.com ↩
"Dell Official Site | Dell United States". Dell.com. 2017-04-26. Retrieved 2017-05-03. http://www.dell.com ↩
"Laptop Computers, Desktops, Printers and more | HP® Official Site". Hp.com. Retrieved 2017-05-03. http://www.hp.com ↩
[1] Archived 2008-08-28 at the Wayback Machine http://www.lenovo.com ↩
"Fujitsu News Updates - Fujitsu UK". Fujitsu.com. Retrieved 2017-05-03. http://www.fujitsu.com/emea/news/pr/fel-de_20090128.html ↩
"Panasonic Toughpad | Rugged Tablet | Toughpad". Panasonic.com. 2015-10-27. Retrieved 2017-05-03. http://www.Panasonic.com/toughbook ↩
"Rugged Notebooks, Tablets, Handhelds and Laptops from". Getac.com. Retrieved 2017-05-03. http://www.Getac.com/ ↩