Self-Encrypting Drives (SEDs)

A self-encrypting drive (SED) is a drive with encryption hardware built into the drive controller. An SED automatically encrypts all data as it is written to the drive and decrypts all data as it is read from the drive. Data stored on an SED is always fully encrypted by a data encryption key (DEK). The DEK can also be encrypted by a user-specified authentication key (AK) that allows the SED to be locked and unlocked. Both encryption keys are stored in the drive's hardware and cannot be accessed by the host operating system or unauthorized users.