Lexmark MS818 Embedded Web Server Administrator s Guide - Page 59

Disk encryption, Checking disk encryption status, Erasing printer settings

Page 59 highlights

Securing printers 59 Disk encryption Enable hard disk encryption to prevent loss of sensitive data if the printer or its hard disk is stolen. When hard disk encryption is activated, the encryption key to be used (256-bit AES symmetric encryption) is pseudorandomly generated. This encryption key is stored in a proprietary way in the NV memory of the device. The hard disk is then reformatted with the encryption key. Any data on the disk is lost. The key, which is unique to the device, is not stored on the hard disk itself. So if the hard disk is removed from the device, then the contents of the hard disk are indecipherable. When an encrypted hard disk is moved to another supported device, the hard disk attempts to verify its encryption key with the device encryption key. Because the encryption key on the hard disk is different than the device encryption key, the verification fails. The device prompts to reformat the hard disk with a new encryption key, replacing the existing encrypted data on the hard disk. Note: Some printer models may not have a printer hard disk installed. 1 From the Embedded Web Server, click Settings > Security > Disk Encryption. Note: Disk Encryption appears in the Security menu only when a formatted, working hard disk is installed. 2 From the Disk Encryption menu, select Enable. Notes: • Disable is the factory default setting. • Changing this setting causes the printer to undergo a power‑on reset. Warning-Potential Damage: Changing the setting for disk encryption erases the contents of the hard disk. 3 Click Submit to proceed with disk encryption. Note: Encryption takes approximately two minutes to complete. A status bar appears on the control panel indicating the progress of the disk encryption task. Warning-Potential Damage: Do not turn off the printer during the encryption process. 4 Refresh the web page to return to the Embedded Web Server. Checking disk encryption status 1 From the Embedded Web Server, click Select Reports > Select Device Settings. 2 In the Other Settings section, check the value for Disk Encryption. Note: You can also check the disk encryption status using MarkvisionTM Enterprise. Markvision provides an advanced search feature to view the disk encryption status on a fleet of devices. Erasing printer settings Most devices use two forms of non-volatile memory-EEPROM and NAND. These components store the device settings, network information, embedded solution applications, various scanner settings, and bookmark settings. No user-related print, copy, or scan data is stored in non‑volatile memory.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98

Disk encryption
Enable hard disk encryption to prevent loss of sensitive data if the printer or its hard disk is stolen. When hard
disk encryption is activated, the encryption key to be used (256-bit AES symmetric encryption) is pseudo-
randomly generated. This encryption key is stored in a proprietary way in the NV memory of the device. The
hard disk is then reformatted with the encryption key. Any data on the disk is lost. The key, which is unique to
the device, is not stored on the hard disk itself. So if the hard disk is removed from the device, then the contents
of the hard disk are indecipherable.
When an encrypted hard disk is moved to another supported device, the hard disk attempts to verify its
encryption key with the device encryption key. Because the encryption key on the hard disk is different than
the device encryption key, the verification fails. The device prompts to reformat the hard disk with a new
encryption key, replacing the existing encrypted data on the hard disk.
Note:
Some printer models may not have a printer hard disk installed.
1
From the Embedded Web Server, click
Settings
>
Security
>
Disk Encryption
.
Note:
Disk Encryption appears in the Security menu only when a formatted, working hard disk is installed.
2
From the Disk Encryption menu, select
Enable
.
Notes:
Disable
is the factory default setting.
Changing this setting causes the printer to undergo a power
on reset.
Warning—Potential Damage:
Changing the setting for disk encryption erases the contents of the hard
disk.
3
Click
Submit
to proceed with disk encryption.
Note:
Encryption takes approximately two minutes to complete. A status bar appears on the control panel
indicating the progress of the disk encryption task.
Warning—Potential Damage:
Do not turn off the printer during the encryption process.
4
Refresh the web page to return to the Embedded Web Server.
Checking disk encryption status
1
From the Embedded Web Server, click
Select Reports
>
Select Device Settings
.
2
In the Other Settings section, check the value for Disk Encryption.
Note:
You can also check the disk encryption status using Markvision
TM
Enterprise. Markvision provides an
advanced search feature to view the disk encryption status on a fleet of devices.
Erasing printer settings
Most devices use two forms of non-volatile memory—EEPROM and NAND. These components store the device
settings, network information, embedded solution applications, various scanner settings, and bookmark
settings. No user-related print, copy, or scan data is stored in non
volatile memory.
Securing printers
59