ST Engineering Electronics DigiSAFE DiskCrypt M10 User manual

DigiSAFE
DiskCrypt M10
USER MANUAL
Version 1.0.0

This page has been left blank intentionally

G
G-P6029-TM001
Issue A
DigiSAFE DiskCrypt M10 User Manual i
Disclaimer
Thank you for purchasing DigiSAFE DiskCrypt M10.
DiskCrypt M10 has been designed to be compliant with the M.2 SATA Solid State Drive
operating specifications as well as USB 3.1 operating specifications. DiskCrypt M10 is also
backward compatible with USB 3.0/2.0 machines.
ST Electronics (Info-Security) accepts no liability for any loss of data or the inability of
DiskCrypt M10 to work with equipment that are not compatible with the above operating
specifications. Nor can ST Electronics (Info-Security) accept any liability or responsibility
for software which is also non-compliant.

G
G-P6029-TM001
Issue A
DigiSAFE DiskCrypt M10 User Manual ii
Contents
1. About this Guide....................................................................1
2. Introduction ..........................................................................2
2.1. About DiskCrypt M10 .............................................................................. 2
2.2. Connection Ports .................................................................................... 3
2.3. Checklist ............................................................................................... 3
2.4. Specifications......................................................................................... 4
3. Using DiskCrypt M10 .............................................................5
3.1 Authentication........................................................................................ 5
3.2 Using the built-in keypad......................................................................... 7
4 Smart Card Security Features................................................8
4.1 PIN Change ........................................................................................... 8
4.2 Administrative Functions ......................................................................... 9
4.3 User Interface .......................................................................................13
5 Optional Accessories ........................................................... 14
5.1 DiskCrypt Key Management Software (DMS).............................................14
6 Helpful Information............................................................. 15
6.1 Partitioning and formatting your hard drive...............................................15
7 Care and Handling ............................................................... 16
8 Frequently Asked Questions ................................................ 17
9 Troubleshooting .................................................................. 20

G
G-P6029-TM001
Issue A
DigiSAFE DiskCrypt M10 User Manual 1
1. About this Guide
This guide is designed to provide step-by-step instructions for the installation of
DiskCrypt M10 and as a reference for its operation and usage.
PLEASE READ AND FOLLOW THE INSTRUCTIONS
PROVIDED IN THIS GUIDE CAREFULLY AND
THOROUGHLY.
FAILURE TO DO SO MAY RESULT IN DAMAGE TO
DISKCRYPT M10 AND ANY OR ALL OF THE
CONNECTED DEVICES.

G
G-P6029-TM001
Issue A
DigiSAFE DiskCrypt M10 User Manual 2
2. Introduction
2.1. About DiskCrypt M10
Congratulations on your purchase of DiskCrypt M10. DiskCrypt M10 represents the most
advanced secure Mobile storage solution today, utilizing smart card authentication
technology and AES 256-bits full disk encryption. With DiskCrypt M10, you can enjoy
Mobile storage with the speed and convenience of USB 3.1 in a compact form factor, and
be assured that your data is safe from prying eyes.
DiskCrypt M10 is a secure portable M.2 Solid State Drive (SSD) which consists of
hardware-based encryption module that performs full disk encryption, i.e. it encrypts
every byte and every sector of data that is written into the SSD. The device is designed
to fit standard 2242 form factor M.2 SSD and communicates with the computer via
standard USB 3.1/3.0/2.0 ports. DiskCrypt M10 is operating system independent and
does not require any software drivers. It encrypts every single byte and sector that
includes all temporary files, as well as areas that would normally be missed and left “in
the clear” by software encryption products. Encryption and decryption occurs
transparently without any loss in disk performance. Users simply use their computers as
usual with the assurance and complete peace of mind that their data is fully protected in
the unfortunate event that their hard drives are stolen or lost.
DiskCrypt M10 stores the hard drive encryption key securely in smart cards (two are
provided per unit). Smart card technology is well understood and represents the highest
level of security possible for secure data storage. It is vastly more secure than other
solutions that use hardware tokens, where the encryption key is stored in insecure
memory that can be easily read and duplicated. In contrast, smart cards store the
encryption key securely within, and can only be accessed upon presentation of a valid
PIN. The user will need both the smart card as well as knowledge of its PIN to be able to
access the data in the connected SSD. By doing so, DiskCrypt M10 enforces two-factor
authentication, which is a higher security protection by ensuring that the user possesses
both the physical Smart Card and the knowledge of its PIN.
The user is required to authenticate him or herself each time DiskCrypt M10 is plugged
into the computer. After authentication, the drive presents itself to the operating system
and the user is granted normal drive access.

G
G-P6029-TM001
Issue A
DigiSAFE DiskCrypt M10 User Manual 3
2.2. Connection Ports
2.3. Checklist
The following items are included with DiskCrypt M10. If you discover any missing items,
please contact your local reseller/distributor.
1 x DiskCrypt M10
1 x USB 3.1 cable
2 x Smartcards
1 x Quick start guide
USB 3.1 Type C receptacle

G
G-P6029-TM001
Issue A
DigiSAFE DiskCrypt M10 User Manual 4
2.4. Specifications
Bus Interface
USB 3.1
Physical
USB 3.1 Type C Receptacle
Smart card slot
M.2 connector (internal)
Solid State Drive
M.2 SSD (2242 form factor and max. height of 3.6mm)
MLC NAND flash type
Dimensions
91.2mm (L) x 59.2mm (W) x 8.9mm (H)
Power
5V, approximately 300mA
Authentication
Supports two-factor authentication via smart card and PIN
Smart Card
Supports FIPS 140-2 level 3 and Common Criteria EAL 5+
certified smart card
Encryption
AES hardware cipher engine
Supported key strengths: 256 bits
Encryption chip is FIPS 140-2 level 2 certified
Key Management
User-configurable smart card PIN
Admin password for administrative mode
Operating Systems
Operating system independent
Tested with Windows 10/8/7/XP, Linux, MAC OS

G
G-P6029-TM001
Issue A
DigiSAFE DiskCrypt M10 User Manual 5
3. Using DiskCrypt M10
3.1 Authentication
DiskCrypt M10 comes with the 2242 form factor M.2 SSD installed. You are ready to use
it with your computer anytime. If the SSD is not installed, simply approach your local
reseller/distributor.
DiskCrypt M10 requires users to authenticate themselves via two-factor authentication
before they are granted access to the installed drive. In order to do so, users must have
the included smart card (something you have) and its associated PIN (something you
know). The authentication process involves inserting the correct smart card into
DiskCrypt M10, followed by PIN entry. Upon completion of these two steps, the
connected drive will present itself to the operating system, and can be used like a
normal drive.
To connect DiskCrypt M10 to your computer via USB, follow these easy steps:
1. Insert the USB cable to your computer’s USB A port with the other type C end to
DiskCrypt M10. Ensure correct connector orientation to obtain a snug fit.
2. Insert the smart card with the contacts facing up.
You may insert the card before or after connecting DiskCrypt M10 to your computer.
Once a valid card is inserted, the keypad will then allow key entry.
If an invalid card is inserted, the Error LED will light up.
3. Enter your PIN.
Once DiskCrypt M10 recognizes that a valid card is inserted, you may proceed to
enter your 8-digit PIN. The default factory PIN is “12345678”. At the end of your
PIN entry, press the Enter button.
(For Enterprise deployment, the default PIN will be provided by the
Administrator.)
Insert the smart card into the smart card slot with the
contacts facing up.
Enter your 8-digit PIN, followed by the Enter button.
IMPORTANT:
Do NOT force the smart card into the unit. DiskCrypt M10 is
designed with the smart card half inserted with a purpose
to remind users to remove the smart card after use.

G
G-P6029-TM001
Issue A
DigiSAFE DiskCrypt M10 User Manual 6
Important Notes:
It is recommended that the default PIN is changed.
Users shall ensure that the host machine connected to DiskCrypt M10 has updated
Anti-virus software to ensure no malicious software/malware installed.
If an incorrect PIN is entered, the Error LED will blink continuously. Press the Esc
button to restart DiskCrypt M10. If you think you have mistyped your PIN, press the
Esc key at any time to restart the entire authentication process.
You will be locked out of your smart card after 8 incorrect PIN attempts. Please
ensure that you have the correct PIN to the smart card.
You shall approach their Administrator in the event that their smartcard is locked.
(Applicable to Enterprise Users)
DiskCrypt M10 is shipped with two smart cards. It is recommended that you use only
one card and keep the other in a secure place. In the event that one card is
stolen/lost, you may authenticate with the other card.
Users should always remove the smart card when: device is not in use or
device is unattended.
Users should perform preliminary visual inspection of device for tamper signs
before usage.
The continuous blinking of the ERROR LED upon device boot up indicates Power-On-
Self-Test failure. Users should contact their supplier/Administrator.

G
G-P6029-TM001
Issue A
DigiSAFE DiskCrypt M10 User Manual 7
3.2 Using the built-in keypad
The built-in keypad allows you to enter/change your PIN (refer Section 4.1 on changing
PIN) and perform other administrative functions. It works on the principle of capacitive
sensing to provide a better user experience and can detect the presence of a touch on
the button.
Note:
The keypad is only activated when the user inserts the smart card.
Status LED
indicators

G
G-P6029-TM001
Issue A
DigiSAFE DiskCrypt M10 User Manual 8
4 Smart Card Security Features
You can perform certain smart card related security functions with DiskCrypt M10. These
functions are only available before connecting to the disk. The following functions are
available.
CAUTION: Smart Card security and administrative functions must be
performed carefully as they cause changes in smart cards and associated
PINs. Please read the following instructions carefully and follow them when
performing administrative functions.
4.1 PIN Change
You can change your smart card PIN with DiskCrypt M10. It is recommended that you
change the default factory PIN to another one that only you know. Follow these steps to
change your PIN.
1. Insert smart card into DiskCrypt M10. The keypad should turn on to allow key entry.
2. Press the Change Pin button, followed by the ‘1’ button.
3. Press Enter. The Status LED will blink three times.
4. Enter the current 8-digit smart card PIN and press Enter. The Status LED blinks
twice to notify that you may press the new PIN.
5. Enter the new 8-digit smart card PIN and press Enter. The Status LED blinks
twice to notify that you may press the confirmed new PIN.
6. Enter the new confirmed 8-digit smart card PIN and press Enter.
Upon a successful PIN change, DiskCrypt M10 will proceed to connect the drive. If the
PIN change is not successful, the Error LED will blink continuously.
Note:
Smart card PINs are specific to the physical smart card. Please be aware that you
may have different PINs for each of the two included smart cards.
The user is responsible to remember his/her smart card PIN. The smart card will be
locked after 8 incorrect PIN attempts. There is NO WAY to unlock the smart card
PIN due to security reasons.
DiskCrypt M10 only accepts 8-digit PINs. If a shorter or longer PIN is entered, the
Error LED will blink continuously. Press the Esc button to restart the authentication
process again. You will need to restart the entire PIN Change process from step 2.
Pressing the Esc key restarts the entire authentication process.

G
G-P6029-TM001
Issue A
DigiSAFE DiskCrypt M10 User Manual 9
4.2 Administrative Functions
(Note that this section is not applicable to Enterprise Users. Enterprise Users
may approach their Administrators.)
DiskCrypt M10 provides the following administrative functions:
1) Initialize a smart card so as to use it with DiskCrypt M10
2) Enable/disable the smart card lockout mode.
3) Admin smart card initialization
4) Change the Admin PIN
Additional smart cards may be purchased from your local retailer. You will need a
supported smart card and knowledge of the Admin PIN to enter the mode. The default
factory Admin PIN is “87654321”. To exit Administrative Mode, remove and reconnect
the USB cable.
Note:
It is recommended that the default Admin PIN is changed.
You are responsible to remember the Admin PIN. The Administrative functions will be
locked after 8 consecutive incorrect PIN attempts.
It is NOT possible to connect to the hard disk via ANY of the above administrative
modes. To do so, remove and reconnect the USB cable to exit the Administrative
mode and proceed to enter the smart card PIN to authenticate to DiskCrypt M10.
4.2.1 Smart Card Initialization
This procedure allows a supported smart card to be used with the particular DiskCrypt
M10 unit. To initialize a smart card, follow these steps:
1. Insert the new smart card into DiskCrypt M10. The keypad will be activated to allow
key entry.
2. The Error LED will light up indicating an invalid card has been inserted. Ignore the
LED if it lights up.
3. Press the Admin button, followed by the ‘0’ button.
4. Press Enter. The Status LED will blink three times.
5. Enter the 8-digit Admin PIN and press Enter.
6. DiskCrypt M10 will proceed to initialize the smart card to be used with that particular
DiskCrypt M10 unit. While the initialization process is taking place, the Status LED
will continue to blink. At the end of the process, DiskCrypt M10 will provide three
‘beep’ sounds to indicate that this operation is successful.
7. Remove and reconnect the USB cable to exit the Administrative mode.
Note:
Once a new smart card is initialized, you will need to repartition/reformat any
existing drive, as the encryption key will be different. The existing data in the drive
will be unreadable with the new card.

G
G-P6029-TM001
Issue A
DigiSAFE DiskCrypt M10 User Manual 10
4.2.2 Smart Card Lockout mode
This mode controls the behavior of DiskCrypt M10 when the smart card is removed after
authentication. DiskCrypt M10 allows the user to choose between 2 Smart Card Lockout
modes. There are 2 supported modes:
1. Lockout (default) –DiskCrypt M10 is automatically disconnected from the host PC
upon smart card removal. The status LED is green in authenticated mode.
2. No lockout –DiskCrypt M10 remains connected to the host PC upon smart card
removal. The status LED is red in authenticated mode.
To toggle the smart card lockout mode, follow these steps:
1. Insert the smart card into DiskCrypt M10. The keypad will turn on to allow key entry.
Note:
When the smart card is inserted and ONLY the ERROR LED lights up, please proceed
to initialize the smart card as described in 4.2.1 first.
2. Press the Admin button, followed by the ‘1’ button.
3. Press Enter. The Status LED will blink three times.
4. Enter the 8-digit Admin PIN and press Enter. DiskCrypt M10 will proceed to
change the settings. While the change process is taking place, the Status LED will
continue to blink. At the end of the process, DiskCrypt M10 will provide three ‘beep’
sounds to indicate that this operation is successful.
5. Remove and reconnect the USB cable to exit the Administrative mode.
Note:
The default mode is the “Lockout” mode. This is the recommended (higher
security) mode of usage.
In Lockout mode, DiskCrypt M10 is automatically disconnected from the host PC
upon card removal. Do NOT remove the smart card while DiskCrypt M10 is being
accessed as this may cause unrecoverable data loss/corruption.

G
G-P6029-TM001
Issue A
DigiSAFE DiskCrypt M10 User Manual 11
4.2.3 Admin Smart Card Initialization
(Note that this section is applicable only to DiskCrypt M10 (Enterprise) version.
This function shall be invoke by Administrators during DiskCrypt M10 setup and
provisioning. Administrators may refer to the DiskCrypt Key Management Guide
on preparation of the Admin smart card)
This procedure allows a supported Admin smart card to be initialized with DiskCrypt M10
unit. This function injects a Disk Key into DiskCrypt M10. The Disk Key is used in
conjuncture with the User Key (stored in User smartcard) to deduce a Data Encryption
Key (DEK) used for cryptographic functions of DiskCrypt M10. To initialize the Admin
smart card, follow these steps:
1. Insert the Admin smart card into DiskCrypt M10. The keypad will be activated to
allow key entry.
2. The Error LED may light up indicating an untagged card has been inserted. Ignore
the LED if it lights up.
3. Press the Admin button, followed by the ‘5’ button.
4. Press Enter. The Status LED will blink three times.
5. Enter the 8-digit Admin PIN and press Enter. (you will observe that the status Led
will blink)
6. Enter the 8-digit Admin smart card PIN and press Enter
7. DiskCrypt M10 will proceed to initialize the Admin smart card with the DiskCrypt M10
unit. While the initialization process is taking place, the Status LED will continue to
blink. At the end of the process, DiskCrypt M10 will provide three ‘beep’ sounds to
indicate that this operation is successful.
8. Remove and reconnect the USB cable to exit the Administrative mode.
Note:
The Admin smart card shall be stored in a secure location as it contains the Disk Key.

G
G-P6029-TM001
Issue A
DigiSAFE DiskCrypt M10 User Manual 12
4.2.4 Change Admin PIN
The Admin PIN provides a layer of protection around your DiskCrypt M10 unit to deter
others from unauthorized access of the administrative functions. It is recommended that
you change the default factory Admin PIN to another one that only you know. To change
your Admin PIN, follow these steps:
1. Insert the smart card into DiskCrypt M10. The keypad will be activated to allow key
entry.
2. Press the Change Pin button, followed by the ‘0’ button.
3. Press Enter. The Status LED will blink three times.
4. Enter the current 8-digit Admin PIN and press Enter. The Status LED blinks twice
to notify that you may press the new Admin PIN.
5. Enter the new 8-digit Admin PIN and press Enter. The Status LED blinks twice to
notify that you may press the confirmed new Admin PIN.
6. Enter the new confirmed 8-digit Admin PIN and press Enter.
7. DiskCrypt M10 will proceed to change the Admin PIN of that particular DiskCrypt M10
unit. While the PIN change is taking place, the Status LED will continue to blink.
DiskCrypt M10 will provide three ‘beep’ sounds to indicate that this operation is
successful.
8. Remove and reconnect the USB cable to exit the Administrative mode.
If you have mistyped your PIN, press the Esc key at any time to restart the entire
authentication process.
4.2.5 Buzzer On/Off Function
For better user experience where device is to be used in quiet places like during meeting
and etc, the buzzer can be activated on or off with the following step:
1. Insert the smart card into DiskCrypt M10. The keypad will be activated to allow key
entry.
2. Press the Admin button, followed by the ‘6’ button.
3. Press Enter. The Status LED will blink three times and finally lighted on to indicate
that this operation is successful.
4. Remove and reconnect the USB cable to enter to buzzer on/off mode.
Note:
Like the smart card user PIN, DiskCrypt M10 only accepts 8-digit Admin PIN. If a
shorter or longer PIN is entered, the Error LED will blink continuously. Press the Esc
button to restart the authentication process again. You will need to restart the entire
PIN Change process from step 2.
Note:
If the device is in Buzzer on mode, this operation will turn off the buzzer. Likewise, if
the device is in Buzzer off mode, this operation will turn the buzzer back on.

G
G-P6029-TM001
Issue A
DigiSAFE DiskCrypt M10 User Manual 13
4.3 User Interface
Button
Colour
Status
Actions
Active
Green
Blinking
Transferring data
Solid
Authenticated / Unit is
Operational
Blue
Solid
Unit is ready for pin entry
Blinking
After each keypad entry when
Buzzer is muted
Status
Red
Blinking
Processing data in non-Lockout
mode
Solid
Functional in non-Lockout
mode
Yellow
Blinking
Processing data in Admin mode
Solid
Waiting for response in Admin
mode
Green
(default)
Blinking
Processing data in Lockout
mode
Solid
Functional in Lockout mode
Error
Red
Blinking
Wrong Password
Solid
Wrong matchID
Buzzer Beep
Notification
2 beep / Active (Blue)
Ready to enter PIN
3 beep
Entered PIN is correct

G
G-P6029-TM001
Issue A
DigiSAFE DiskCrypt M10 User Manual 14
5Optional Accessories
5.1 DiskCrypt Key Management Software (DMS)
DiskCrypt Key Management Software (DMS) provides a way for enterprises to manage
their own smart cards for usage with DiskCrypt M10. System administrators may also
use this software to back up the encryption keys that are pre-loaded in the two smart
cards, shipped with DiskCrypt M10.
DMS comes with the general features:
1) Generation and loading of encryption key into a smart card
2) Duplication of smart card with the same encryption key
3) Editing smart card record
4) Reading smart card and backup of encryption keys
5) Delete smart card record
Note:
Please contact your respective sales channels for any enquiries or purchase of the
software and/or additional smart cards.

G
G-P6029-TM001
Issue A
DigiSAFE DiskCrypt M10 User Manual 15
6Helpful Information
6.1 Partitioning and formatting your hard drive
Note that in most cases, it is not necessary to do this because the hard drive will be
shipped, completely formatted.
In any case, if you wish to partition and format the drive, simply follow these steps.
CAUTION: Performing partition and format operations will erase all data in the
drive.
Windows XP and above
1. Connect and authenticate into DiskCrypt
M10.
2. Right click on My Computer and Select
Manage.
3. From the Computer Management
window, select Disk Management.
4. Right click on the drive and choose
Initialize.
5. Right click on the drive and select New
Partition.
6. Follow the New Partition Wizard to create
as many partitions as desired.
7. Right click on each partition and select
Format to format the drive.
8. The drive is ready to be used once
formatting completes.
Note:
You must have Administrator privileges to use the Disk Management utility.
Mac
1. Connect and authenticate into DiskCrypt
M10.
2. Enter the Applications folder, followed by
the Utilities folder
3. Run Disk Utility.
4. Select DiskCrypt M10 on the left hand
column and click on the Partition tab.
5. Choose the number, size and names of
the desired partitions.
6. Mac OS will then format the drives
automatically.
7. The drive is ready to be used once
formatting completes.

G
G-P6029-TM001
Issue A
DigiSAFE DiskCrypt M10 User Manual 16
7Care and Handling
The following are some important information on the proper care and
handling of DiskCrypt M10. Please take a moment to review these
instructions.
Ensure that you follow the proper removal procedure to disconnect DiskCrypt M10.
Do not move or disconnect this device from your computer while it is reading or
writing data. This may cause damage to DiskCrypt M10 and it is possible that the
data that is read from or written to the device becomes corrupted.
Do not expose device to direct flame or heat (Recommended operating temperature:
0-45 degree celcius).
Do not place the device near to equipment generating strong electromagnetic fields.
Exposure to strong electromagnetic fields may cause the device to malfunction or
data to be corrupted.
Do not drop or cause shock to your DiskCrypt M10.
Do not expose DiskCrypt M10’s internals to water.
Do not attempt to disassemble and service DiskCrypt M10 yourself.
Other manuals for DigiSAFE DiskCrypt M10
1
Table of contents
Popular Security System manuals by other brands

Sierra Monitor Corporation
Sierra Monitor Corporation 2050 Specification sheet

SECOLink
SECOLink P16 Wiring Manual

DSC
DSC neo HS2032 installation guide

IntelliSense
IntelliSense FG-1015 installation instructions

Digital Watchdog
Digital Watchdog SiteWatch DW-DTLA500 quick start guide

Ideal Security
Ideal Security BK6311 instructions