SPECIAL REPORT: Interop   See more>>

Toshiba Launches Self-Encrypting Drives With Extra Security

The drives are the first that can also prevent access to the data they store after repeated failed log-ins or the device is removed.

Toshiba on Wednesday announced that it will release the first-ever self-encrypting hard disk drives that can also be crypto-erased.

The new drives aren't self-erasing, but rather can perform a crypto erase, which deletes the key that's used to encrypt and decrypt the drive. At that point, encrypted data on the drive would be irretrievable, except for access by an administrator who also had a copy of the drive's key.


More Security Insights

Webcasts

More >>

White Papers

More >>

Reports

More >>

According to Toshiba, the new hard drives perform a check when powered on to ensure that they're interfacing with the correct piece of hardware. If that check fails, the drive can be set to "invalidate" all encrypted data stored on the drive. Data can also be invalidated after a set number of failed log-in attempts--for example, failing to enter the correct pre-boot password. Those are new capabilities. Other included capabilities, such as invalidating encrypted data via a command-line interface or every time drive power is cycled, were previously available on some Toshiba drives.

"Digital systems vendors recognize the need to help their customers protect sensitive data from leakage or theft," said Scott Wright, product manager for Toshiba's storage device division, in a statement. "Toshiba's security technologies provide designers of copiers, printers, PCs, and other systems with new capabilities to help address these important security concerns."

The new serial-ATA drives from Toshiba, known as model type MKxx61GSYG, will run at 7,200 RPM and offer formatted storage capacities ranging from 160 GB to 640 GB. For encryption, Toshiba said the drives comply with the Opal specification from the Trusted Computing Group. Stored data is encrypted using the 256-bit Advanced Encryption Standard (AES 256). Toshiba said the drives should be available by the middle of 2011.

Self-encrypting drives are now available from Hitachi, Samsung, and Seagate. Toshiba also began selling self-encrypting drives via its acquisition of Fujitsu's HDD business in late 2009. In terms of computer sellers, Dell in particular has been offering self-encrypting drives in its products for several years.

Demand for self-encrypting drives continues to increase, according to numerous research reports. In February 2011, Seagate announced that it had shipped one million self-encrypting drives to date. "Companies and government organizations worldwide increasingly are securing confidential information on self-encrypting hard drives, recognizing that this commonsense yet powerful approach simplifies the deployment of security for data at rest," said Charles Kolodgy, research director of security products for market researcher IDC, in a statement at the time.

Indeed, one of the primary attractions of self-encrypting hard drives is that they remove encryption from the hands of users--meaning that they can't deactivate it--while ensuring that it always remains on. Drive makers also say that their hardware-based approach to partial or full-disk encryption is faster than using encryption software running at the operating system level. One criticism of self-encrypting drives, however, has been their relatively high cost and--at least for earlier models--performance that seemed to degrade after extensive use.

InformationWeek is conducting a survey on IT automation and the data center. Respond to the survey and be eligible to win an iPod Touch. Take the survey now. Survey ends April 22.

Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS

Resource Links