What is Opal Encryption?
Opal drives are like any other drives in which any individual can secure accumulate and incorporate their data. It is equally important that this incorporated data is secured for the same to be used for longer duration. This data which is accumulated in this Opal drives are secured by encrypting the same and hence the process is termed as Opal Encryption.
Why Opal Encryption?
A question by a large enterprise customer, “Why do I need to buy a self encrypting drive? I can just use any standard hard drive and enable the hard disk password security in BIOS.”
Since, it is equally essential that the drive should be secured, there are actually three possible ways to enable drive security:
- Just use a normal hard drive and enable the hard disk password in the BIOS.
- Use a self encrypting drive (SED) and enable the hard disk password in the BIOS
- Use a self encrypting drive (SED) along with a SED management software package.
The first option, hard disk (hdd encryption) is secured from access, but since the data is not encrypted on the drive, the data can easily be extracted using available data recovery methods.
The second option encrypts the data (hard disk encryption), but still uses the BIOS ATA password to secure the drive. This password is very difficult to manage in an enterprise environment (e.g. it is hard to reset the BIOS password if someone forgets it and also there are hacks available online that can remove the BIOS password from a drive.
The most secure method is the last one. By using a SED drive along with a SED software package to activate and manage the encryption, the data is completely encrypted and hidden until the user authenticates (either through a password, fingerprint, smart card or other multifactor authentication methods).
How SecureDrive supports Opal Encryption?
SecureDrive is an addition to Softex’s existing
security suite of products to take full advantage of the encryption and security features of Opal self-encrypting drives (SED’s). SecureDrive allows for easy set up and configuration of the encryption and access rights and allows for multiple authentication mechanisms such as fingerprint, smart card, RFID cards and TPM passphrase to unlock the Opal drive.
Opal self-encrypting drives (SEDs) are an easy and effective way to deliver a high level of security for digital information.
The key advantages of SEDs include:
- Quick and easy deployment: SEDs utilize their own Advanced Encryption Standard (AES) encryption, therefore SecureDrive can instantly activate them, and they do not require the hard drive to become initially encrypted in software, which requires several hours to convert into an encrypted drive.
- Zero performance degradation: SEDs use their own hardware for encryption, so computing systems do not suffer performance issues (no system processor usage or time delay overheads).
- Highest level of security: The data encryption key does not leave the drive, hence preventing cooled-RAM attacks and simplifying key management.
- Read-only PBA area: Supports single or multi-factor authentication by ISVs using the drive’s secure partition.
- Crypto erase: Enables instant secure disposal and repurposing of the self-encrypting drive, rendering all existing data unintelligible.
- Transparency and flexibility: The master boot record is not modified, therefore a kernel driver is unnecessary and no conflicts with other software occur.