FDE
Feature list
  • Automatically encrypts (and decrypts) all data on the drive
  • Operations are performed with no measurable performance loss
  • All user data is encrypted on write operations and decrypted on read operations
Benefits
  • Drive-level protection of data
  • Drives that are stolen, taken out of service, or re-purposed remain fully protected
  • Near instantaneous disposal and re-purposing of the drive (ensures that data from previous user is not accessible by the new drive owner)
  • Able to be deployed within a trusted computing environment

The drive encrypts every write operation and decrypts every read operation without user intervention. The encryption and decryption is done on the drive itself, so there is a near-zero performance impact when the drive writes and reads data. The performance-optimized encryption and decryption engine performs at the SATA interface speed. The purpose of full-disc encryption on the drive is to protect the data stored on the drive in the event that the host system is lost or stolen. This data at rest protection assures the system owner that if their system is lost or stolen, their data will not be accessible without the correct credentials.

Note: To ensure that the system reauthenticates the user, turn the laptop power off (shut down) rather than putting it in sleep mode. The system will authenticate the user at powerup. Having the encryption/decryption on the drive also provides the highest level of security for data because all data, including the boot sector bytes, operating system, temp and even the swap files are encrypted at the drive level.