[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-86262-en":3,"doc-seo-86262-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},86262,687197207919,"Theodora","https://ap-avatar.wpscdn.com/avatar/a000253d6f5f7c60be?x-image-process=image/resize,m_fixed,w_180,h_180&k=1779446848396160552",8,"Research & Report","Linux Disk Encryption and Self-Encrypting Drives: A Case Study on Opal2 Drives Security","Opal2 self-encrypting drives provide hardware-based disk encryption as an added protection layer or an alternative to software-only solutions. The study documents a real-world Linux integration effort for Opal2 drives and evaluates the security of Opal2 firmware through black-box testing. Using a testbed of 38 commercial off-the-shelf Opal2 drives from multiple vendors, the authors identify firmware security issues and incompatibilities, disclose them responsibly, and enable improvements across major Linux disk encryption tools. A public open-source toolset is released for independent evaluation.","arXiv :2607 . 1 1563v 1 [ cs .CR] 13 Jul 2026  \nLinux disk encryption and self-encrypting drives  \nA case study on Opal2 drives security  \nMilan Brož 1 ,2 􀀀 , Tamara Čierniková 1 , Ondřej Kozina3 , and Vladimír Sedláček 1   \n1 Masaryk University, Brno, Czechia  \n{milan.broz,ciernikova,[vlada.sedlacek}@mail.muni.cz](vlada.sedlacek}@mail.muni.cz)  \n2 OpenSSL Corporation  \n3 Red Hat Czech  \n[okozina@redhat.com](okozina@redhat.com)  \nThis work is licensed under a “CC BY 4 .0” license.  \nAbstract. Opal2 self-encrypting drives provide hardware-based disk encryption serving as an additional layer of protection, or a replacement, for software-based solutions. This paper presents a case study of real-world Linux integration of Opal2 drives and the security of Opal2 firmware. The study was conducted on a testbed of 38 commercial off-the-shelf Opal2 drives from various vendors using a black-box approach. We identified several firmware security issues and incompatibilities, which we responsibly disclosed to respective vendors. Our findings led to improvements in Linux disk encryption tools used across all major Linux distributions.  \nTo enable independent evaluation for the public, we release our test scenarios for Opal2 drives as an open-source toolset.  \nKeywords: SED Opal2, LUKS2, self-encrypting drives, disk encryption  \n1 Introduction  \nDisk encryption is a common mechanism for protecting data at rest. It can be implemented in software, where the operating system handles encryption per disk sector, or in hardware through self-encrypting drives (SEDs) . The TCG Opal2 standard [37] defines a widely adopted specification for SEDs that offloads cryptographic operations to the drive controller itself.  \nOpal2 can be deployed alongside software encryption as an additional security layer, or as a standalone solution where data confidentiality relies entirely on the hardware. Both use cases expect the underlying hardware to behave correctly and as specified; an assumption we put to the test.  \nLinux disk encryption relies on the open-source Linux Unified Key Setup 2 (LUKS2) format [4] together with the cryptsetup [6] user-space configuration utility. The practical contribution of this work is the secure integration of Opal2 support into LUKS2, thereby enabling a user-friendly configuration of SEDs on Linux, which was not feasible with prior tooling.  \n2 M. Brož, T. Čierniková, O.Kozina and V. Sedláček  \nWe present a case study on the security of Opal2 drives. To this end, we assemble a testbed of 38 drives advertising Opal2 support and conduct a security analysis of intercepted firmware. Our testbed is a mix of second-hand units and new in-stock purchases, representing the diversity of Opal2 SEDs found in present Linux deployments. We employ a black-box analysis methodology: we rely exclusively on documented protocols, without any knowledge of the internal firmware implementation.  \nOur security evaluation focuses on non-adversarial operational use of SEDs, deliberately setting aside hardware-level or supply-chain attacks. The black-box approach has a key advantage: every test is fully reproducible on any drive that exposes the required Opal2 interface. Importantly, our findings are not Linuxspecific; they apply to any platform that supports Opal2 drives.  \nAnalysis uncovered firmware-level issues affecting the correctness of encryption, including a discrepancy between the encryption block size and the physical sector size, potential reuse of sector tweak values, and insufficient randomness in the exported random number generator interface. All issues were reported to affected vendors through a responsible disclosure process.  \nWe make following contributions:  \n– A black-box security analysis of 38 Opal2 drives, revealing firmware vulnerabilities, specification ambiguities, and implementation incompatibilities. The Opal2 tooling developed for this analysis is released as open source.  \n– Backed by this analysis, we achieve Opal2 integration","cbCaipTCl80UObz8","https://ap.wps.com/l/cbCaipTCl80UObz8","pdf",2139382,5,1,20,"English","en",105,"# Introduction\n# Sector-based (disk) encryption\n# Linux integration, standards, and security goals\n# Methodology, testbed, and black-box results\n# Practical impact\n# Appendices","[{\"question\":\"What problem does the paper address regarding Opal2 drives on Linux?\",\"answer\":\"The paper studies how Opal2 self-encrypting drives are integrated in real Linux environments and evaluates the security of Opal2 firmware, aiming to ensure correct and safe disk encryption behavior.\"},{\"question\":\"How was the Opal2 security evaluation conducted?\",\"answer\":\"The authors use a black-box approach on a testbed of 38 commercial off-the-shelf Opal2 drives, relying only on documented protocols without internal firmware knowledge to keep tests reproducible.\"},{\"question\":\"What kinds of firmware issues were discovered?\",\"answer\":\"The study found firmware-level problems affecting encryption correctness, including mismatches between encryption block size and physical sector size, potential reuse of sector tweak values, and insufficient randomness in the exported random number generator interface.\"}]",1784209897,50,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"linux-disk-encryption-and-self-encrypting-drives-a-case-study-on-opal2-drives-security","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/linux-disk-encryption-and-self-encrypting-drives-a-case-study-on-opal2-drives-security/86262/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-07-27","2026-07-16",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What problem does the paper address regarding Opal2 drives on Linux?","Question",{"text":76,"@type":77},"The paper studies how Opal2 self-encrypting drives are integrated in real Linux environments and evaluates the security of Opal2 firmware, aiming to ensure correct and safe disk encryption behavior.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"How was the Opal2 security evaluation conducted?",{"text":81,"@type":77},"The authors use a black-box approach on a testbed of 38 commercial off-the-shelf Opal2 drives, relying only on documented protocols without internal firmware knowledge to keep tests reproducible.",{"name":83,"@type":74,"acceptedAnswer":84},"What kinds of firmware issues were discovered?",{"text":85,"@type":77},"The study found firmware-level problems affecting encryption correctness, including mismatches between encryption block size and physical sector size, potential reuse of sector tweak values, and insufficient randomness in the exported random number generator interface.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":93},[94,98,102,106,110,114,119,122,126,129,133],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":29,"slug":113},6,"Technology","technology",{"id":115,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":22,"slug":125},9,"Religion & Spirituality","religion-spirituality",{"id":22,"doc_module":4,"doc_module_name":46,"category_name":127,"show_sort_weight":22,"slug":128},"World Cup","world-cup",{"id":130,"doc_module":4,"doc_module_name":46,"category_name":131,"show_sort_weight":130,"slug":132},10,"Lifestyle","lifestyle",{"id":134,"doc_module":4,"doc_module_name":46,"category_name":135,"show_sort_weight":20,"slug":136},19,"General","general"]