How to enable disk encryption on Samsung EVO SSD hard drive

The Samsung range of SSD drives boast about their hardware level encryption – but what surprises me is that there is so little detail about this feature.

In fact, the more I looked into it I noticed that it’s not even enabled by default and there’s no clear instruction on how to enable it.

Here I hope to clear up some of that mystery and show how to enable the hardware level encryption.

What is the hardware level encryption?

Encryption is the processing of taking data from its standard state and processing it so it is no longer readable without a ‘key’ to unlock it.

Hardware level encryption is where the hardware manages the encryption/decryption process of all data on the drive – this has a significant performance advantages and reduces read/write cycles that ultimately shorten the life of the drive. Without hardware level encryption you can still encrypt the data but performance is typically reduced.

What’s important to note here is that the drive alone does not encrypt the data – it needs to be done along with a software level encryption tool like BitLocker or TrueCrypt.

How can I tell if hardware level encryption is enabled?

  1. Download and install the Samsung Magician software on the computer with the SSD drive.
  2. Open Samsung Magician and select ‘Data Security’ from the left hand menu
  3. Make sure the correct drive is selected under ‘Target Drive’
  4. Under ‘Encrypted Drive’ you will see ‘Disabled’ if it is not already enabled.

How to enable hardware level encryption?

Note: this process requires you to erase all existing content on the SSD drive – backup and be prepared to reinstall everything.

To enable hardware level encryption on your Samsung drive you will need to

  1. use the Samsung Magician software to enable it,
  2. create a bootable usb drive
  3. boot the drive with the SSD connected and follow the on screen prompts
  4. re-install Windows
  5. enable BitLocker (required the Professional edition of Windows) or TrueCrypt (or similar third party paid software)

Step 1: Enable encrypted drive

  1. Download and install the Samsung Magician software on the computer with the SSD drive.
  2. Open Samsung Magician and select ‘Data Security’ from the left hand menu
  3. Make sure the correct drive is selected under ‘Target Drive’
  4. Under ‘Encrypted Drive’ click ‘How to enable’
  5. In the pop-up click ‘Ready to enable’
  6. The state will change from ‘Disabled’ to ‘Ready to enable’

Step 2: Create bootable media

  1. Now in the left hand menu select ‘Secure Erase’ – you will now need to create a bootable drive, you can do this using a CD/DVD or USB (note that this will erase all existing content from the USB drive).
  2. Using the USB option, insert the USB drive into the computer.
  3. Click ‘Browse’ and select the drive from the list
  4. Click ‘Start’ to start the process
  5. When finished it will prompt you to restart the computer.
  6. Restart the computer and boot from the USB drive.

Step 3: SSD Secure Erase

When booted from the USB drive you’ll see the following screen

  1. Click ‘Y’ on the keyboard to continue
  2. The software will list the compatible SSD drive connected to the computer
  3. Click ‘Y’ on the keyboard to continue
  4. If you see a message which says “the selected drive is in a Frozen state” – you will need to follow the on instructions provided on screen (I’ve had this happen on desktop and laptop computers – it is much more awkward for laptop computers and should be done with extreme caution … you are after all prodding your hands inside a powered computer!)
  5. Once completed you will see “Secure Erase is Successful” – the software will exit to DOS – you can now turn off the computer and begin the Windows re-install process.

Step 4: Re-install Windows and enable BitLocker

I won’t detail how to re-install Windows, but once this is done this guide will help explain how to enable BitLocker on Windows 10 – Windows 10 – How to encrypt a drive using BitLocker

 

References:

Tagged in

2 comments on “How to enable disk encryption on Samsung EVO SSD hard drive

  1. hello,
    i just setup a new windows 10 laptop with a samsun evo,
    very completed process, took a lot of tries.

    when using hardware encryption, bitlocker does not encrypt/decrypt the data, the drive itself does that.
    bitlocker generate and manages the passwords and keys.

    i found bitlocker to be very flexible, i can use a password or key.
    i uses a tiny usb key to boot the laptop. once booted up, i remove the key.
    i have mutiple keys stored in differnet locations.
    without that key, i cannot boot, need to use a recovery key and/or password.

    one trick that i do, is that tiny usb key, can actually boot a tiny linux,
    the bitlocker key is stored in a password protected zip file.
    so i would need to boot my laptop with that key, unzip the file, reboot and windows will find the key.

  2. what good is the hardware encryption, if you stil have to use bitlocker? What is its advantage of just using bitlocker? I currently use bitlocker (it is a PAIN with TPM, but it is OK WITHOUT TPM, I can set up an alphanumeric password; TPM, if I enter a wrong bitlocker password, can’t be reset and I have to enter the bitlocker recovery key
    anyway, any feedback on this is appreciated

Leave a Comment

Your email address will not be published. Required fields are marked *