Self-Encrypting Drive Management by WinMagic Inc. manages Self Encrypting Drives (SEDs), simplifying deployment and management. SEDs have encryption always on, the key remains on the drive, and authentication is independent of the operating system. SED stands for 'self-encrypting drive,' which includes HDDs or SSDs with built-in encryption circuits. It transparently encrypts all data written to the media and decrypts all data read from the media when unlocked. In an SED, encryption keys remain within the SED hardware, protecting them from OS level attacks. Software-based Encryption Key Management is needed to manage SEDs because encryption alone does not ensure confidentiality without proper authentication and management. A robust solution is essential for device authentication and data protection. WinMagic delivers a secure authentication and encryption experience that increases productivity. SecureDoc Enterprise Server (SES) allows organizations control over their data security environment, ensuring maximum protection and transparency. An SED works by utilizing a unique and random data encryption key (DEK) that transforms data to and from an unbreakable code. An encryption engine creates DEKs, and whenever you write data to the drive, it gets encrypted with the DEK. Whenever data is read from the drive (e.g., accessing a file on the SED), it’s decrypted with the same DEK. An SED encrypts data from the moment it is manufactured. The data on an SED is always encrypted, with encryption and decryption occurring within the drive, not in the computer’s memory or processor. If a computer is hacked, the criminal cannot access the DEK. Software-based Encryption Key Management is needed to manage SEDs. Self-encrypting drives (SEDs) offer benefits for securing confidential information. Organizations are increasingly using SEDs to simplify data-at-rest security deployment. As storage and security converge, SEDs provide strong, user-friendly security for data protection. SEDs drives are becoming the standard for enterprise customers seeking built-in security. They feature on-board technology to encrypt data, many supporting the Opal specification of the Trusted Computing Group. They offer authentication capability, central control and administration, and support for both hardware and software encryption. They extend protection to removable media encryption and provide audit trails and activity monitoring with high-performance hardware encryption. SecureDoc Enterprise Server (SES) collects encryption key information from self-encrypted drives and provides central control, escrow, and protection for software-encrypted drives. It supports hardware encryption with SecureDoc client installations on Windows, Mac, and Linux, as well as most Opal compliant SEDs. Enhanced functionality includes policy and user control, password recovery, multi-factor authentication, and removable media encryption. File/folder encryption. Enhanced key management. Full support in a multi-O/S environment. SecureDoc automatically recognizes supported SEDs and utilizes hardware encryption. It supports a heterogeneous environment, allowing a mix of encryption formats. You can use self-encrypting hard drives on some machines while using SecureDoc’s software encryption for legacy machines until hardware refresh is completed. SecureDoc enables immediate benefits from hardware encryption while ensuring compliance and protecting legacy machines, all within the same solution. WinMagic leads in full-disk encryption innovation. For organizations deploying Linux, SecureDoc takes an OS neutral approach using SEDs. SecureDoc OSA allows users to encrypt their hard drive without installing software in the OS. Using OPAL SEDs, installation is performed at pre-boot, eliminating the need for OS-specific installation packages. This is ideal for organizations wanting to run Linux while managing and auditing system security. The WinMagic TCG SED Compatibility Certification Program allows SED manufacturers to test, validate, and certify Opal specification implementations for compatibility with WinMagic software.