WHITE PAPER
February 1998
Prepared By
Portable Software
Marketing
Compaq Computer
Corporation
CONTENTS
ATA-3
Specification
Background .................... 3
Compaq DriveLock
Implementation ............... 3
F10 Setup Passwords............ 3
DriveLock Setup................... 4
Password Prompts ................ 4
Standby & Hibernation........... 5
Important
Considerations...............5
Service & Support...........6
User Interface
Messages .......................6
Additional Tables............7
Frequently Asked
Questions ....................... 8
PowerPoint Slide
PresentationError! Bookmark not defined.
List of Tables ............... 10
.
.
.
DriveLock Hard Drive Protection for the
.
.
.
.
.
.
.
Armada 7800
.
.
.
.
.
.
.
DriveLock is a security feature that offers customers advanced protection against
.
.
.
unauthorized access to valuable data on their internal notebook hard drives. The feature
.
.
.
has been designed to meet expressed needs from customers who cannot afford to have
.
.
.
their sensitive hard drive data fall into the wrong hands.
.
.
.
.
.
The purpose of this document is to explain the Compaq DriveLock security
.
.
.
implementation. Particular focus will be given to the severe consequences that can arise
.
.
.
from misuse. The document will also suggest strategies that corporate MIS managers can
.
.
.
implement to make the most use of DriveLock and minimize the likelihood of adverse
.
.
.
consequences.
.
.
.
.
The document has been written for internal Compaq personnel with a need to understand
.
.
.
DriveLock and how to communicate its features, benefits and limitations to customers.
.
.
.
For a concise overview of essential messages that need to be communicated to customers,
.
.
.
refer to the section titled Key Customer Messages.
.
.
.
.
.
.
.
.
This document is intended external audiences with a need for information about
.
.
.
DriveLock on the Armada 7800.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
1
WHITE PAPER (cont.)
.
NOTICE
.
.
.
.
.
The information in this publication is subject to change without notice.
.
.
.
.
.
THE COMPETITIVE INFORMATION CONTAINED IN THIS PUBLICATION IS BASED ON
.
.
.
DATA AVAILABLE FROM PUBLIC SOURCES AT THE TIME OF PUBLICATION. COMPAQ
.
.
.
COMPUTER CORPORATION SHALL NOT BE RESPONSIBLE FOR ANY INACCURACIES,
.
.
.
ERRORS, OR OMISSIONS IN INFORMATION CONTAINED HEREIN, INCLUDING, BUT NOT
.
.
LIMITED TO, INFORMATION OBTAINED FROM THIRD PARTY SOURCES, SUCH AS
.
.
.
PUBLICATIONS OF OTHER COMPANIES, THE PRESS, OR COMPETITIVE DATA
.
.
.
ORGANIZATIONS.
.
.
.
.
.
THIS PUBLICATION IS MADE AVAILABLE ON AN “AS IS” BASIS AND COMPAQ
.
.
.
SPECIFICALLY DISCLAIMS ALL ASSOCIATED WARRANTIES, WHETHER EXPRESS OR
.
.
IMPLIED. IN NO EVENT WILL COMPAQ BE LIABLE FOR DIRECT, INDIRECT, SPECIAL,
.
.
.
INCIDENTAL, OR CONSEQUENTIAL DAMAGES IN CONNECTION WITH THE USE OF OR
.
.
.
RELIANCE ON THE MATERIAL CONTAINED IN THIS PUBLICATION, EVEN IF ADVISED OF
.
.
.
THE POSSIBILITY OF SUCH DAMAGES. COMPAQ RESERVES THE RIGHT TO MAKE
.
.
.
IMPROVEMENTS OR CHANGES TO THIS PUBLICATION AND THE PRODUCTS AND
.
.
SERVICES HEREIN DESCRIBED AT ANY TIME, WITHOUT NOTICE OR OBLIGATION.
.
.
.
.
.
This publication does not constitute an endorsement of the product or products that were tested.
.
.
.
The configuration or configurations tested or described may or may not be the only available
.
.
.
solution. This test is not a determination of product quality or correctness, nor does it ensure
.
.
.
compliance with any federal, state or local requirements. Compaq does not warrant products other
.
.
.
than its own and then, only as strictly stated in Compaq product warranties.
.
.
.
.
ARMADA, Compaq, LTE, Deskpro, Presario, ProLiant, and ProSignia are trademarks registered
.
.
.
in the United States Patent and Trademark Office.
.
.
.
.
.
LTE 5000, MultiBay, and Netelligent are trademarks of Compaq Computer Corporation.
.
.
.
.
Other product names mentioned herein may be trademarks and/or registered trademarks of their
.
.
.
respective companies.
.
.
.
.
.
Microsoft, Windows NT are trademarks and/or registered trademarks of Microsoft Corporation.
.
.
.
.
©1998 Compaq Computer Corporation.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
DriveLock Hard Drive Protection for the Armada 7800
.
.
.
.
.
.
First Edition (October 1997)
.
.
Second Edition (February 1998)
.
.
.
0298/B
.
.
.
.
.
.
.
.
.
.
2
WHITE PAPER (cont.)
.
.
.
.
.
ATA-3 SPECIFICATION BACKGROUND
.
.
.
.
DriveLock is based on the industry standard ATA-3 specification. The standard uses a dual
.
.
.
password structure featuring a master and user password. The master password has been designed
.
.
.
to give the MIS manager supervisory control over DriveLock features. It allows for unlocking of
.
.
.
protected hard drives as well as the ability to change the user password. The user password, as the
.
.
.
name suggests, has been designed to give the user access to protected hard drives as well as the
.
.
.
ability to change the user password.
.
.
.
.
.
ATA-3 also defines two security modes, high and max. Under high mode, the master password can
.
.
.
be used to unlock a protected hard drive and reset the user password. By contrast, in max mode the
.
.
.
master password can only be used to reformat the hard drive and reset security options for the
.
.
.
newly formatted drive. In the max mode, the master password cannot be used to change the user
.
.
.
password without first reformatting the hard drive. This protects against unauthorized access to
.
.
.
hard drive by the owner of the master password. In both security modes, if both passwords are lost,
.
.
.
the hard drive is rendered permanently unusable.
.
.
.
.
Compaq DriveLock is fully compatible with the ATA-3 specification, with the user model based
.
.
.
on the high security mode. The decision to only implement the high mode was made to eliminate
.
.
.
risk of data loss in the event only the user password is lost. The following table compares the key
.
.
.
ATA-3 security specifications with the Compaq DriveLock implementation.
.
.
.
.
.
.
ATA-3 SPECIFICATION
.
.
.
.
.
.
.
.
.
.
Defines a user password ü ü
.
.
.
.
.
Defines a master password ü ü
.
.
.
.
Defines a high security mode ü ü
.
.
.
.
.
Defines a max security mode ü ü
.
.
.
.
Under the high security model, the master
.
.
.
password unlocks a protected hard drive
.
.
.
.
Under the max security model, the master
.
.
.
password is only able to reformat a protected
.
.
.
hard drive
.
.
.
.
.
Table 1 - ATA-3 Hard Drive Security versus DriveLock
.
.
.
.
.
.
.
COMPAQ DRIVELOCK IMPLEMENTATION
.
.
.
.
.
.
.
F10 Setup Passwords
.
.
.
.
DriveLock has been implemented as an extension to the F10 setup utility. Access to the F10 setup
.
.
.
utility can be controlled by enabling an admin password1. If enabled, this password is required to
.
.
.
make any modifications to the F10 settings including DriveLock. From a DriveLock perspective,
.
.
.
the admin password is a key tool the MIS manager can use to maintain control over whether or not
.
.
.
users are allowed to use the DriveLock feature. Given that a hard drive can be rendered
.
.
.
permanently unusable, MIS managers may elect to restrict access to the feature to only those users
.
.
.
who absolutely require it.
.
.
.
.
.
1
.
The admin password is sometimes referred to as the setup password. This document consistently refers to the admin
.
.
password as the password required to enter into F10 Setup at power-on.
.
.
3
ATA-3 Specification Compaq Implementation
ü ü
ü û