Self-Encrypting Drives Explained: SED, OPAL and Crypto Erase
A self-encrypting drive performs encryption in hardware on the drive itself, using a controller built into the device. Every write is encrypted and every read decrypted, always, with no software involvement. How it works The drive holds a media encryption key generated on the device and never leaving it. All data on the platters or flash is encrypted with that key from the factory onwards — there is no "enable encryption" step that rewrites existing data. What changes when you enable security is that the media key is itself encrypted with an authentication key derived from a password or supplied by the platform. Without that, the drive will not release the media key and the stored data is unreadable. Two consequences follow, and both are exam points. Enabling encryption is instant. Nothing is re-encrypted; only the key wrapping changes. Compare this with software full-disk encryption, which must read and rewrite every block — hours on a large drive. There is no perfo...