Advice Request AES Hardware Acceleration - Some questions

Please provide comments and solutions that are helpful to the author of this topic.

Status
Not open for further replies.

HarborFront

Level 71
Thread author
Verified
Top Poster
Content Creator
Oct 9, 2016
6,033
Hi

Things here needed for a speedier disk encryption using hardware (3x - 10x better) over software AES encryption

1) Intel processors that support AES hardware acceleration

ARK | Processor Feature Filter

2) VeraCrypt which supports AES hardware acceleration

VeraCrypt - Documentation

3) Samsung consumer SSDs which support AES hardware acceleration

Quote

With the introduction of the SSD 840 and 840 Pro Series SSDs, Samsung has added AES hardware-based SED technology to its consumer SSD lineup

SSD White Paper | Samsung SSD

The Samsung SSD 950 & 960 supports AES-256 TCG/OPAL (is SED developed by TCG)

Samsung SSD 950 PRO Review

Samsung NVMe SSD 960 PRO Review


The question I want to ask is if I have all so should I disable VeraCrypt or the default Samsung's AES hardware acceleration feature? Which is better....VeraCrypt or Samsung?
 
Last edited:

XhenEd

Level 28
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Mar 1, 2014
1,708
I can't comment on this because I don't have Samsung SSD like those, and I don't use VeraCrypt's disk encryption.

What I can only say is that don't do disk encryption with both at the same time. I assume you know this. Just a reminder. :D
 

Zero Knowledge

Level 20
Verified
Top Poster
Content Creator
Dec 2, 2016
841
Samsung hardware disk encryption is not enabled by default on all SSD models.

You have to enable hardware encryption by using Samsung Magician software then use secure erase to wipe the disk then re-install your OS.
 
  • Like
Reactions: XhenEd

HarborFront

Level 71
Thread author
Verified
Top Poster
Content Creator
Oct 9, 2016
6,033
Samsung hardware disk encryption is not enabled by default on all SSD models.

You have to enable hardware encryption by using Samsung Magician software then use secure erase to wipe the disk then re-install your OS.

_CyberGhosT_ said:
@HarborFront Samsung in my opinion, have you read up and compared the pluses for each option ?

In the Magician software there are three options for encryption

1.Class 0
2.TCG Opal
3.Encrypted drive (eDrive)

and these are clearly explained here

Samsung SSD FAQs | Samsung SSD

They are pictured here in the Magicain software

My Review of Samsung 840 EVO SSD Full Drive Encryption. - Windows 7 Help Forums

It seems from the above link Secure Erase works with eDrive (encrypted drive) option only

Apparently, the writer of the article said that hardware encryption by Samsung is a lie. And he mentioned TrueCrypt which uses "hardware encryption".

Quote
Think of it this way. Truecrypt is software but it uses hardware (HDD, CPU, RAM, IO Channels) for encryption, decryption, locking, unlocking data and user interface. Truecypt then could just as accurately be called “hardware based” encryption as the “hardware encryption” of SED SSD's from manufacturers like Samsung based on the apparently malleable TCG-Opal “standard” which requires installed software to function even though they claim it doesn't.

Well....TrueCrypt is now replaced by VeraCrypt and, the latter, also supports hardware encryption

VeraCrypt - Documentation

There are many articles on the net to be read up on hardware accelerated encryption. Don't have the time to really read all of them. Be a judge yourself.

If I want to believe in what the writer said about Samsung's hardware encryption is a lie then I'll choose VeraCrypt instead. The other thing is I can also use VeraCrypt to encrypt my external SSD as well
 
Last edited:
  • Like
Reactions: XhenEd
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top