Opal Storage Specification
{{Short description|Data storage device security specification}}
{{Multiple issues|
{{Primary sources|date=May 2017}}
{{missing information|Opalite and Pyrite, two subsets defined by the TCG (& the even simpler TCG Enterprise)|date=June 2023}}
}}
The Opal Storage Specification is a set of specifications for features of data storage devices (such as hard disk drives and solid state drives) that enhance their security. For example, it defines a way of encrypting the stored data so that an unauthorized person who gains possession of the device cannot see the data. That is, it is a specification for self-encrypting drives (SED).
The specification is published by the Trusted Computing Group Storage Workgroup.
Overview
{{unreferenced section|date=May 2017}}
The Opal SSC (Security Subsystem Class) is an implementation profile for Storage Devices (SD) built to:
- Protect the confidentiality of stored user data against unauthorized access once it leaves the owner's control (involving a power cycle and subsequent deauthentication).
- Enable interoperability between multiple SD vendors.
[https://trustedcomputinggroup.org/wp-content/uploads/TCG_Storage-Opal_SSC_v2.01_rev1.00.pdf#page=12 TCG Storage Security Subsystem Class: Opal Specification Version 2.01 Revision 1.00]. Trusted Computing Group, Incorporated. 05 August 2015. Retrieved 2019-11-22.
Functions
{{unreferenced section|date=May 2017}}
The Opal SSC encompasses these functions:
- Security provider support
- Interface communication protocol
- Cryptographic features
- Authentication
- Table management
- Access control and personalization
- Issuance
- SSC discovery
Features
{{unreferenced section|date=May 2017}}
- Security Protocol 1 support
- Security Protocol 2 support
- Communications
- Protocol stack reset commands
Security
Radboud University researchers indicated in November 2018 that some hardware-encrypted SSDs, including some Opal implementations, had security vulnerabilities.{{cite conference |last1=Meijer |first1=Carlo |last2=van Gastel |first2=Bernard |title=Self-Encrypting Deception: Weaknesses in the Encryption of Solid State Drives |date=19–23 May 2019 |conference=2019 IEEE Symposium on Security and Privacy (SP) |publisher=IEEE |location=San Francisco, CA, USA |pages=72–87 |isbn=978-1-5386-6660-9 |issn=2375-1207 |doi=10.1109/SP.2019.00088 |doi-access=free |hdl=2066/207837 |hdl-access=free }}
Implementers of SSC
= Device companies =
- Hitachi
- Intel Corporation{{cite web|url=http://www.intel.com/content/www/us/en/solid-state-drives/ssd-pro-1500-series-m2-specification.html |title=Intel® SSD Pro 1500 Series (M.2): Specs |website=Intel.com |date= |accessdate=2017-05-03}}
- Kingston Technology{{cite web|url=http://www.kingston.com/us/ssd/vplus/#skc300s3 |title=Solid State Hard Drives for Business |website=Kingston.com |date=2017-03-05 |accessdate=2017-05-03}}
- Lenovo{{cite web|author=Clain Anderson |url=http://blog.lenovo.com/en/blog/opal-more-than-a-semi-precious-stone |title=Opal – More than a Semi-Precious Stone | Lenovo |website=Blog.lenovo.com |date=2011-02-16 |accessdate=2017-05-03}}
- Micron Technology{{cite web|url=http://micron.com/products/solid-state-storage/client-ssd |title=Micron Technology, Inc. - Full SSD Part Catalog |website=Micron.com |date= |accessdate=2017-05-03}}
- Samsung{{cite web|url=http://www.samsung.com/global/business/semiconductor/minisite/SSD/global/html/about/whitepaper06.html |title=Samsung V-NAND SSD |website=Samsung.com |date= |accessdate=2017-05-03}}
- SanDisk{{cite web |url=http://www.sandisk.com/products/ssd/sata/x300s/ |title=SanDisk's X300s Solid State Drive |accessdate=2014-08-02 |url-status=dead |archiveurl=https://web.archive.org/web/20140803081737/http://www.sandisk.com/products/ssd/sata/x300s |archivedate=2014-08-03 }}
- Seagate Technology{{cite web|url=http://www.seagate.com/ww/v/index.jsp?locale=en-US&name=momentus-FDE-self-encrypting,FIPS-seagate-pr&vgnextoid=f0ea53279dc0b210VgnVCM1000001a48090aRCRD |title=News |publisher=Seagate |date= |accessdate=2017-05-03}}{{cite web|url=http://www.winmagic.com/solutions/self-encrypting-hard-drives |title=Full Disk Encryption Software, Hard Drives, SSDs & Whole Disk |publisher=WinMagic |date= |accessdate=2017-05-03}} as "Seagate Secure"
- Toshiba{{cite web|url=http://www.fujitsu.com/global/news/pr/archives/month/2009/20090128-01.html |title=Fujitsu Develops HDD Security Technology based on Opal SSC Standards - Fujitsu Global |website=Fujitsu.com |date= |accessdate=2017-05-03}}{{cite web|url=http://storage.toshiba.com/storagesolutions/specialty-products/mkxx61gsyg-series |title=Specialty | TOSHIBA Storage & Electronic Devices Solutions Company | Americas |website=Storage.toshiba.com |date= |accessdate=2017-05-03}}{{cite web|url=http://storage.toshiba.com/storagesolutions/specialty-products/mkxx61gsyd-series |title=Specialty | TOSHIBA Storage & Electronic Devices Solutions Company | Americas |website=Storage.toshiba.com |date= |accessdate=2017-05-03}}
= Storage controller companies =
- Marvell{{cite web|url=http://www.marvell.com |title=Marvell Technology Group Ltd |website=Marvell.com |date= |accessdate=2017-05-03}}{{cite web |title=Marvell, Kingston Collaboration Proves Positive with Over Six Million SSD Units Shipped |url=https://www.kingston.com/spain/es/company/press/article/49507 |website=Kingston Technology |access-date=30 December 2021}}
- Avago/LSI SandForce flash controllers{{cite web |url=http://www.lsi.com/products/storagecomponents/Pages/SandForce_Flash_Storage_Processors.aspx |title=SandForce Flash Storage Processor SSD Controllers |accessdate=2013-08-01 |url-status=dead |archiveurl=https://web.archive.org/web/20130808084202/http://www.lsi.com/products/storagecomponents/Pages/sandforce_flash_storage_processors.aspx |archivedate=2013-08-08 }}
=Software companies=
- Absolute Software{{cite web|url=http://www.absolute.com |title=Self-Healing Endpoint Security |publisher=Absolute |date= |accessdate=2017-05-03}}
- Check Point Software Technologies{{cite web|url=http://www.checkpoint.com |title=Industry-Leading Cyber Security Keeps Networks, Data Centers, Mobile Devices & Endpoints One Step Ahead | Check Point Software |website=Checkpoint.com |date= |accessdate=2017-05-03}}
- Dell Data Protection{{cite web|url=http://www.dell.com/encryption |title=Data Security | Dell United States |website=Dell.com |date=2017-04-26 |accessdate=2017-05-03}}
- Cryptomill{{cite web |url=http://cryptomill.com/products/default.php |title=CryptoMill :: Products & services |accessdate=2012-01-14 |url-status=dead |archiveurl=https://web.archive.org/web/20120209044329/http://www.cryptomill.com/products/default.php |archivedate=2012-02-09 }}
- McAfee{{cite web|url=https://kc.mcafee.com/corporate/index?page=content&id=KB75045 |title=McAfee Corporate KB - KB75045 |website=Kc.mcafee.com |date= |accessdate=2017-05-03}}
- Secude {{cite web |url=http://www.secude.com/products/finallysecuretrade-enterprise |title=FinallySecure™ Enterprise - SECUDE AG |accessdate=2012-01-14 |url-status=dead |archiveurl=https://web.archive.org/web/20120126034405/http://www.secude.com/products/finallysecuretrade-enterprise/ |archivedate=2012-01-26 }}
- Softex Incorporated{{cite web|url=http://www.softexinc.com/securedrive/overview |title=Comprehensive Data Encryption and Protection Solutions - SecureDrive |website=Softexinc.com |date=2014-06-20 |accessdate=2017-05-03}}
- Sophos{{cite web|url=http://www.sophos.com/en-us/products/safeguard-encryption.aspx |title=Full Disk Encryption | Always-On, Multi-Platform Enterprise Encryption Synchronizes Devices, Hard Drives, Removable Media, BitLocker, and Cloud Storage Protection in Real-Time |website=Sophos.com |date= |accessdate=2017-05-03}}
- Symantec{{cite web|url=https://www.broadcom.com/products/cybersecurity |title=Endpoint Encryption Powered by PGP Technology |website=Symantec.com |date= |access-date=2017-05-03}} (Symantec supports OPAL drives, but does not support hardware-based encryption.){{cite web |url=https://support.symantec.com/en_US/article.tech217784.html |title=Archived copy |accessdate=2016-02-03 |url-status=dead |archiveurl=https://web.archive.org/web/20170925230747/https://support.symantec.com/en_US/article.tech217784.html |archivedate=2017-09-25 }}
- Trend Micro{{cite web|url=http://us.trendmicro.com/us/products/enterprise/endpoint-encryption/index.html |title=Data Protection – Endpoint and Gateway Suites | Trend Micro |website=Us.trendmicro.com |date= |accessdate=2017-05-03}}
- WinMagic{{cite web|url=http://www.winmagic.com/products |title=Full Disk Encryption Software, Hard Drives, SSDs & Whole Disk |publisher=WinMagic |date= |accessdate=2017-05-03}}
- OpalLock{{cite web|url=https://fidelityheight.com |title=Software management of TCG self-encrypting drives. |publisher=Fidelity Height LLC}}(OpalLock support Self-Encrypt-Drive capable SSD and HDD. Develop by Fidelity Height LLC)
=Computer OEMs=
- Dell{{cite web|author= |url=http://www.dell.com |title=Dell Official Site | Dell United States |website=Dell.com |date=2017-04-26 |accessdate=2017-05-03}}
- HP{{cite web|author= |url=http://www.hp.com |title=Laptop Computers, Desktops, Printers and more | HP® Official Site |website=Hp.com |date= |accessdate=2017-05-03}}
- Lenovo[http://www.lenovo.com] {{webarchive|url=https://web.archive.org/web/20080828023252/http://lenovo.com/|date=2008-08-28}}
- Fujitsu{{cite web|url=http://www.fujitsu.com/emea/news/pr/fel-de_20090128.html |title=Fujitsu News Updates - Fujitsu UK |website=Fujitsu.com |date= |accessdate=2017-05-03}}
- Panasonic{{cite web|url=http://www.Panasonic.com/toughbook |title=Panasonic Toughpad | Rugged Tablet | Toughpad |website=Panasonic.com |date=2015-10-27 |accessdate=2017-05-03}}
- Getac{{cite web|url=http://www.Getac.com/ |title=Rugged Notebooks, Tablets, Handhelds and Laptops from |website=Getac.com |date= |accessdate=2017-05-03}}
References
{{Reflist|30em}}
External links
- [http://www.trustedcomputinggroup.org/resources/storage_work_group_storage_security_subsystem_class_opal Storage Work Group Storage Security Subsystem Class: Opal]