HP Secure Erase for Imaging and Printing

White Paper

Invent

January 2007

Document Version: 3

Imaging and Printing Group

Hewlett-Packard Company

Abstract

To meet the needs for higher levels of print and imaging security, HP has implemented a storage erase feature which meets the U.S. Department of Defense 5220-22.M requirements for clearing storage media when the administrator selects certain options and uses supported devices. This paper describes the capabilities of HP Secure Erase and related information.

Notice

©2007 Hewlett-Packard Company

Microsoft®, Windows®, and Windows NT® are trademarks of Microsoft Corporation in the U.S. and/or other countries. UNIX® is a trademark of The Open Group in the U.S. and/or other countries. Intel® and Itanium® are trademarks or registered trademarks of Intel Corporation or its subsidiaries in the U.S. and other countries. Oracle® is a registered U.S. trademark of Oracle Corporation, Redwood City, California. All other product names mentioned herein may be the trademarks of their respective companies.

Neither HP, nor any of its subsidiaries, shall be liable for technical or editorial errors or omissions contained herein. The information in this publication is provided "as is" without warranty of any kind and is subject to change without notice. The warranties for HP products are set forth in the express limited warranty statements accompanying such products. Nothing herein should be construed as constituting an additional warranty.

Contents

  1. Introduction
  2. Data Affected
  3. Default Setting
  4. Specifications
  5. Common Usage Environment
  6. User Interface
  7. Impact to Performance
  8. Availability
  9. Questions and Answers
  10. Acronyms

1 Introduction

To meet the needs for higher levels of print and imaging security, Hewlett-Packard created HP Secure Erase technology for Imaging and Printing. This capability allows the administrator to select how data is erased from storage devices, including print, scan, fax, and copy jobs.

Several levels of erase security are provided. The capability is provided as a standard feature on supported HP multifunction peripherals (MFPs), digital copiers, and printers when used with HP's Web Jetadmin (available separately).

HP Secure Erase technology provides a choice of three different modes of erase security, each of which can be configured by an administrator and may be protected from unauthorized changes with a password. The three erase security modes are:

HP Secure Erase technology is applied in two different ways to remove data from storage devices.

2 Data Affected

All data removed from the system by a delete operation is erased using the active erase mode (Secure Sanitizing Erase, Secure Fast Erase, or Non-secure Fast Erase) including temporary files created during the print, scan, fax, and copying processes. User initiated delete operations, including Stored Jobs and Proof and Hold Jobs deleted through the “Retrieve Job” menu, are also removed using the active Secure Erase mode.

In contrast, the Secure Storage Erase operation will erase stored files even though they have not been retrieved.

The HP Secure Erase features will not impact data stored on:

3 Default Setting

Prior to the introduction of Secure Erase technology, all HP MFPs used a method similar to the Non Secure Fast Erase method for file delete operations. With the introduction of HP Secure Erase technology, Non Secure Fast Erase becomes the default erase mode on supported devices.

Changing the erase mode (Secure Sanitizing Erase, Secure Fast Erase, or Non-secure Fast Erase), does not overwrite previously stored data on the disk, nor does it immediately perform a full Secure Storage Erase. Changing the erase mode dictates how the MFP erases data after the erase security mode has been changed.

4 Specifications

HP's Secure Sanitizing Erase mode, supported on all the devices described in Section 8, meets the U.S. Department of Defense 5220-22.M overwrite algorithms for overwriting disk files. Using a succession of multiple data overwrites, including the validation of the success of those overwrites, Secure Sanitizing Erase mode can prevent the subsequent physical analysis of the hard disk drive's media for recovery of data. Each byte of file data is overwritten with:

To ensure successful completion of the write operation, each overwritten byte is verified.

5 Common Usage Environment

The most common scenario under which administrators will use HP Secure Erase for Imaging and Printing is when devices are being used in a highly secure environment. If the administrator configures the MFP for Secure Sanitizing Erase mode or for Secure Fast Erase mode, then data is overwritten on an ongoing basis when a job is completed.

6 User Interface

Secure Storage Erase settings within HP Web Jetadmin 8.1 can be accessed for supported devices in one of two modes: single device or multiple devices. To configure the Secure Storage Erase settings for a single device, select Configuration from the device drop-down menu, then select Filesystem from the Configuration Categories menu (Figure 1).

Figure 1 - Secure Storage Erase settings within Filesystem settings page.

Device Configuration: HP LaserJet 4345 MFP-15.1.50.252

Configuration option

Filesystem option in Configuration Categories menu

File Systems Password field

Secure Storage Erase

Permissions

Capacity

Estimated Erase Time

Hard disk

19535005 KB

59 mins

Other Read-Write media

1008 KB

<1 min

Set File System Password

File System Password:

Confirm File System Password:

Select All

Configure

The Set File System Password fields allows for typing the file system password. A file system password must be present on the device in order to change Secure Storage Erase settings. If a password is not present on the device, a message stating "Error: password values must be specified," is displayed when changes are attempted.

Figure 2 – Secure Storage Erase Settings in HP Web Jetadmin

Device Configuration: HP LaserJet 4345 MFP-15.1.50.252

Storage Device to Erase

Secure File Erase Mode

Hard disk

19535008 KB

59 mins

Other Read-Write media

1008 KB

<1 min

HP Web Jetadmin Device Configuration

Configure Security Settings

Set File System Password

File System Password:

Confirm File System Password:

Set Secure File Erase Mode

Secure File Erase Mode:

Select All

Secure Sanitizing Erase

Configure

Configure the following additional settings:

To minimize the time it takes to perform configurations, HP Web Jetadmin also allows for setting Secure Storage Erase features on many devices simultaneously. Merely highlight the desired devices from the All Devices list or a group of devices, select Configuration from the drop-down menu, then select Filesystem from the Configuration Categories menu. Configure the settings as you would for a single device. (Figure 3).

Figure 3 – Selecting Multiple Devices and Using the Device Tools Menu

Multiple Device Configuration

Device Model

Subnet

All Device Models in List

Select All

Device Model

Hardware Address

Part

IP Address

PC Name

Displaying 2 of 2 Possible Devices

HP LaserJet 4345MFP

001195FCC10E

1

15.1.50.252

MPID9553F

HP LaserJet 9000 MFP

00016725866

1

15.5.546.54

MP1725856

Configure

Devices

Schedule Configuration

Save/Load Configuration

Store Credentials

HP Web Jetadmin Device Configuration

Configuration

Categories

Device

Fax

Digital Sending

Embedded Web Server

Filesystem

Network

Security

Secure Storage Erase

Hard disk

Other media

Select storage device to erase

Set File System Password

File System Password:

Confirm File System Password:

Select All

Configure

Secure File Erase and Secure Storage Erase settings can be accessed within an MFP's Embedded Web Server (EWS) for supported devices. To configure the Secure Storage Erase settings for a single device, select the Settings Tab, then select Security from the left menu (Figure 4).

Figure 4 - Secure Storage Erase settings within EWS Security page.

HP LaserJet M4345 MFP Series

Information

Settings

Digital Sending

Networking

Configure Device

E-mail Server

Alerts

Auto Send

Security

menu

Authentication Manager

LDAP Authentication

Kerberos Authentication

Device PIN Authentication

User PIN Authentication

Edit Other Links

Device Information

Language

Date & Time

Sleep Schedule

Tray Sizes/Types

Other Links

Shop for Supplies

Product Support

Security

HP Jetdirect Security Configuration Wizard

Click the HP Jetdirect Security Configuration Wizard button below, and configure the settings that appear. Be sure to come back to this page to configure the settings on the Configure Security Settings page (see the Configure Security Settings button below).

HP Jetdirect Security Configuration Wizard

Configure Security Settings

Once the Jetdirect Security Configuration is complete, click the Configure Security Settings button, below, and configure the settings that appear.

Configure Security Settings

Perform Secure Storage Erase

Click Perform Secure Storage Erase to delete data permanently on the selected items. Performing a Secure Storage Erase can take more than 2 hours, depending on the size of the media and the Secure File Erase Mode chosen. During this time the device will not be accessible.

Warning: Performing a Secure Storage Erase will cause the MFP to restart. All data and applications on the storage device(s) you selected will be completely destroyed. Click Help for more information

Hard Disk

Perform Secure Storage Erase

Status of Security Settings

Configure Security Settings menu

Secure Storage Erase

The Secure File Erase Mode and File System Password settings are accessed by selecting the Configure Security Settings menu button (Figure 4).

Figure 5 - Configure Security Settings menu

Information

Settings

Digital Sending

Networking

Configure Device

E-mail Server

Alerts

Auto Send

Security

Authentication Manager

LDAP Authentication

Kerberos Authentication

Device PIN Authentication

User PIN Authentication

Edit Other Links

Device Information

Language

Date & Time

Sleep Schedule

Tray Sizes/Types

Other Links

Shop for Supplies

Product Support

Configure Security Settings

Each section below contains a category of security settings for the MFP. The recommended settings are in the Help link, but you should configure settings according to the needs of your network. Click Help for detailed instructions and HP recommendations.

Be sure to click Apply at the bottom of the page to complete your configurations. None of the configurations will be complete until you click Apply.

File System Password

Configure the File System Password using 8 or fewer characters.

Old Password

New Password

Verify Password

Not Configured

File Erase Mode

Select the File Erase Mode option for the level of security at which you want files erased:

NOTE: The File Erase Mode setting is available only after the File System password is configured. The MFP will require the File System Password to make changes to the File Erase Mode setting.

Non-Secure Fast Erase

Secure Fast Erase

Secure Sanitize Erase

In the Configure Security Settings menu, the Set File System Password fields and File Erase Mode settings are accessible (Figure 5).

7 Impact to Performance

The HP Secure Erase feature does not affect printing and typical copying including simplex, duplex, enlargements, reductions, and n-up printing. Non-secure Fast Erase is the fastest mode and is the default setting. Secure Fast Erase is slower than Non-secure Fast Erase because the stored data is overwritten. Secure Sanitizing Erase is the most secure mode, but requires multiple overwrites of disk data and, therefore, results in the most impact to performance. Actual performance impacts will vary.

8 Availability

Devices that support Continuous, On Demand, and Scheduled Secure Erase include:

Devices that support only Continuous Secure Erase (not On Demand or Scheduled) include:

Firmware versions can be upgraded remotely using HP Web Jetadmin. The latest versions of the firmware files are available at the following locations:

9 Questions and Answers

  1. Question: Can HP Secure Erase be accessed through the Embedded Web Server or via the MFP control panel?
  2. Answer: Access to HP Secure Erase is controlled through HP Web JetAdmin 8.1 which is available separately (see Question 3 for more details).
  3. Question: Where can HP Web Jetadmin be downloaded?
  4. Answer: HP Web Jetadmin can be downloaded free from: www.hp.com/go/webjetadmin

10 Acronyms

PDF preview unavailable. Download the PDF instead.

hp-disk-erase-white-paper Acrobat PDFWriter 5.0 for Windows NT

Related Documents

Preview HP Secure Erase for SSDs & HDDs: Secure Data Sanitization
Learn how HP Secure Erase safely and effectively sanitizes sensitive data from solid state drives (SSDs) and hard disk drives (HDDs) to industry standards, ensuring data security before disposal or recycling.
Preview HP Essential Security Overview: Safeguarding Commercial PCs
Discover the HP Essential Security Overview, detailing the HP Security Stack for Commercial PCs. Learn about advanced hardware-enforced security features like HP Sure Start, HP BIOSphere, and HP Sure Click designed to protect business endpoints from evolving threats.
Preview HP Access Control Secure Authentication for Healthcare Security
Learn how HP Access Control Secure Authentication enhances security for healthcare organizations, protecting patient information at the point of care with robust authentication features and secure printing protocols.
Preview HP ProDesk 4 Mini G1i Desktop AI PC: Kompakt, Leistungsstark und KI-fähig
Entdecken Sie den HP ProDesk 4 Mini G1i Desktop AI PC mit Intel® Core™ Ultra Prozessor, 16GB RAM und 512GB SSD. Ideal für Unternehmen, bietet er professionelle Leistung, Sicherheit und ein kompaktes Design für optimale Bereitstellung.
Preview HP EliteBook 830 G8 Notebook PC QuickSpecs
Explore the technical specifications and features of the HP EliteBook 830 G8 Notebook PC, including its design, processors, displays, storage, memory, and networking capabilities.
Preview HP LaserJet Pro MFP 4101-4104dw/fdn/fdw Printer Series Data Sheet
Comprehensive data sheet for the HP LaserJet Pro MFP 4101-4104dw/fdn/fdw printer series, detailing features like fast printing, high-volume scanning, seamless management, and HP Wolf Pro Security.
Preview HP Access Control Printing Solutions: Secure and Controlled Print Environment
HP Access Control Printing Solutions offer enhanced security, cost reduction, and improved efficiency for networked printing environments. Features include secure pull printing, user authentication, job accounting, and mobile printing capabilities.
Preview HP DesignJet T1700 Printer Series Datasheet: Secure, Efficient, Accurate Large Format Printing
Detailed datasheet for the HP DesignJet T1700 Printer series, focusing on its secure, efficient, and accurate large-format printing capabilities for CAD/GIS workgroups. Includes technical specifications, ordering information, and eco-friendly features.