January 28, 2009 5:06 AM PST

Security-storage device specifications finalized

by Dong Ngo
  • Font size
  • Print
  • 1 comment

According to the Privacy Rights Clearinghouse, since January 2005 there have been more than 252 millions records containing sensitive personal information compromised because of security breaches in the U.S.

Most of these breaches were because of the loss of computer equipment, more specifically the hard drive. When a laptop is stolen, chances are the information contained on its hard drive is worth a lot more than the value of the computer itself. And thousands of laptops are stolen each year.

For this reason, the Trusted Computing Group released Tuesday its final versions of three storage specifications designed to enable stronger data protection, including:

The Opal specification outlines minimum requirements for storage devices used in the PC client and enterprise markets. It outlines for vendors the required and optional TCG capabilities and specifies how to activate and customize the trusted storage device.

The Enterprise Security Subsystem Class Specification focuses on storage devices used in data centers and high-volume applications, where high performance is required. The specification defines encryption of data on media and enables support for strong access control to support organizational security.

Finally, the Storage Interface Interactions Specification specifies how the TCG's existing Storage Core Specifications interact with other specifications and standards for storage interfaces and transports. In short, it enables interoperability of trusted drives with existing hardware.

This is especially important as currently storage hardware vendors have already been using proprietary self-encrypting methods on hard drives. For example, Seagate uses Full-Disc encryption while Hitachi uses Bulk Data Encryption.

According to TCG, so far, most major storage vendors have announced their support, either fully or in part, to the group's new set of specification. These vendors include: Hitachi, Seagate, Toshiba, and Fujitsu.

Dong Ngo is a CNET editor who covers networking and network storage, and writes about anything else he finds interesting. You can also listen to his podcast at insidecnetlabs.cnet.com. E-mail Dong.
Recent posts from Crave
Speculating on Chrome OS Netbook specs
MetroPCS adds Kyocera Laylo, Domino
Get freaky with samurai sword earbuds
The 404 Yuletide Mini-sode: Where The 404 is the Fifth Element
Running World of Warcraft in Ubuntu Linux
Last-minute deal: Buy an Olive 4 or 4 HD, get the Beatles Remastered free
Reports: Panasonic battery to power homes for one week
Will the Apple tablet be a full-fledged computer?
Add a Comment (Log in or register)
by Laptop-Security January 29, 2009 8:05 AM PST
This is a great step in the right direction. Standards are very helpful, especially as they enable interoperability. A hodge-podge of proprietary practices here only tends to slow down implementation by the vendors and adoption by the market. Meanwhile, much more data tends to be at risk, though thankfully good solutions already exist, such as MyLaptopGPS.com and TrueCrypt.org (though note again that hardware-level standardization is a great step forward).
Reply to this comment
advertisement

About Crave

The name says it all. Crave is our blog about gorgeous gadgets and other crushworthy stuff. If you would like to contact Crave with a tip or comment, please write to: crave@cnet.com

Add this feed to your online news reader

Crave topics

15 sites that went kaput in 2009

Web sites launch all the time, but they also shut their doors. We highlight 15 that bit the dust this year.

Top 10 news stories of the decade

Let the debate begin: Was the iPhone more important than iTunes? Was anything bigger than Google finding a great business model? CNET offers its list of the 10 most important stories of the '00s.