Opal Lock utilizes Opal SED technology to set up and manage built-in hardware-based encryption on compatible drives. Protecting your data is more important than ever before, and Opal Lock provides protection that cannot be cracked even in cases of physically losing your drive.
Drives that are compatible with Opal Lock have a unique Physical Security ID (PSID). The drive’s PSID is printed on the label of the drive.
Opal Lock is available for Windows 10/11, Windows Server 2019/2022. Opal Lock is compatible with SATA, NVMe, USB and other third party drivers like the SAS host adapter, including both hard disk drives (HDDs) and solid state drives (SSDs). An unused USB drive is also required for setup.
Opal Lock enables the drive’s built-in encryption. When the drive is locked, all data on the drive is encrypted using hardware-based encryption.
Unfortunately, Opal Lock does not support namespaces.
Understanding Block SID– Block SID (Security ID) is a security feature in self-encrypting drives (SEDs) that comply with Opal standards. It restricts certain operations when the drive is locked to enhance security.
Solution– Disable Block SID in the BIOS: To set up such drives using Opal Lock, you’ll need to disable the Block SID feature in the BIOS settings. This option is typically found under the Security or Advanced Settings section of the BIOS. Once Block SID is disabled, retry the operation with Opal Lock. With Block SID turned off, Opal Lock should be able to perform the desired operation on Drive without encountering compatibility issues.
Note- It’s important to note that the Block SID feature status will revert to its original value upon system reboot. This means that if you disable Block SID in the BIOS settings to perform the desired operation with Opal Lock, the feature will be re-enabled automatically when the system restarts.
Self-encrypting drives are a type of drive that have built-in hardware-based encryption. Opal SEDs conform to the Opal SSC specification made by TCG. Many drive manufacturers produce drives that are Opal SEDs.
Opal Lock is able to detect, set up, and manage all Opal drives that are mounted on the system, internally or externally.
Your data cannot be accessed without your password. An adversary would be unable to decrypt the data and would only be able to execute a cryptographic erase, which would erase all data on the drive without exposing it.
Opal Lock is coming soon for Mac but unfortunately currently not available for mobile devices.
This happens when Preboot Image is not written on the Shadow MBR of the system drive at the time of Setting up the System drive. In this case “Recovery USB” can be used to unlock the System drive.