Self-encrypting drive (SED)

A drive whose own controller encrypts everything written to it in hardware, with the key held inside the drive, so the data can be sanitised quickly by cryptographic erase.

A self-encrypting drive encrypts every block written to it using a controller built into the drive, so encryption happens in hardware. The media encryption key stays inside the drive, protected by a key typically derived from the credential supplied at unlock. The Trusted Computing Group’s Opal and Enterprise specifications are the common standards.

Sanitisation is where an SED matters most. Because all stored data is ciphertext under keys held inside the drive, the drive can perform cryptographic erase: it sanitises and replaces the key, and the old data becomes unreadable almost at once. NIST SP 800-88 Rev. 2 treats cryptographic erase as a purge technique, subject to trust in the vendor’s implementation (US federal agencies are expected to use FIPS 140 validated modules), and it suits flash media, where overwriting is unreliable. The protection has a limit: while the drive is powered and unlocked it serves plaintext to the running system, so it defends a lost or powered-off device rather than a compromised host. A trusted platform module is a different thing: a separate chip that can hold keys for software encryption.

Exam relevance: a scenario is likely to involve repurposing many drives quickly and ask for the most efficient sanitisation method. Candidates are expected to link SEDs with cryptographic erase, and to remember that encryption at rest protects a drive that is off or locked, not data on a running, unlocked system.