The PC-Doctor Blog

Erasing an OPAL Drive Without the Key: What PSID Revert Does

Erasing an OPAL Drive Without the Key: What PSID Revert Does

Last technical review: September 29, 2026 by PC-Doctor Engineering

A PSID revert erases a TCG Opal self-encrypting drive without the owner’s credentials. The 32-character Physical Security ID printed on the drive’s label authorizes a Revert command that destroys the media encryption key and returns the drive to its manufacturing state. Every block becomes unreadable, the drive unlocks, and it can be reimaged and reused. The operator needs physical possession of the drive and nothing else.

That last clause is the whole security model, and it is worth understanding before relying on it.

The Situation

A system arrives at an ITAD depot or a refurbisher. The drive is a self-encrypting drive with Opal locking enabled. The previous owner set an authentication key, and nobody knows it. The drive will not unlock, will not mount, and cannot be erased through the normal path, because the normal path requires authentication.

This is common. Enterprise laptops are frequently deployed with Opal drives managed by a corporate encryption client, and the credentials stay with the corporate directory, not the hardware. When the laptop is decommissioned the drive comes along, locked, with no way to reach anyone who could open it.

Without PSID revert, the options are to destroy the drive or to warehouse it. With it, the drive is sanitized in seconds and goes back into inventory.

What Opal Is, in Two Sentences

TCG Opal is a specification from the Trusted Computing Group for self-encrypting drives.[1] An Opal drive encrypts everything written to it, always, using a media encryption key held inside the drive controller; Opal adds an authentication layer on top, so that the drive refuses to decrypt until a credential is presented.

Two consequences follow. First, the data on an Opal drive is already ciphertext, from the first byte written. Second, the credential the owner sets does not encrypt the data; it protects access to the key that does.

What the PSID Is

Every Opal drive ships with a Physical Security ID: a 32-character string, printed on the drive label and often encoded in a QR code beside it. The PSID is not stored anywhere the host can read it. It is not in firmware, not in the drive’s identify data, not retrievable over the interface. The only way to obtain it is to look at the drive.

That is the point. The PSID is an authority that can only be exercised by someone holding the physical drive. It cannot be exercised remotely, cannot be extracted by malware, and cannot be recovered from a stolen laptop image. An attacker who has the drive in hand could read it; an attacker who does not, cannot.

What Revert Does

The Opal specification defines a Revert operation that returns the drive to its original factory state.[1] When authorized with the PSID, Revert does three things.

It destroys the media encryption key and generates a new one. Every block on the drive was encrypted with the old key; without it, every block is unreadable. This is a cryptographic erase, and it completes in the time it takes the controller to regenerate a key, regardless of the drive’s capacity.

It clears all Opal configuration: locking ranges, authentication credentials, the owner’s settings. The drive is unlocked.

It returns the drive to its manufacturing state. What it does not do is preserve anything. There is no partial revert, no data recovery, no undo. Revert authorized by PSID is a factory reset with the data cryptographically destroyed on the way through.

What It Does Not Do

Revert is not a data-wiping operation in the overwrite sense. No blocks are rewritten. The ciphertext is still physically present in the flash until the controller reuses those cells. What has changed is that the ciphertext can no longer be decrypted, because the key is gone.

For sanitization purposes this is a distinction without a difference — provided two conditions hold. The drive has to have been encrypting all of its contents throughout its life, which an Opal drive does by design. And the key destruction has to be real and unrecoverable, which the specification requires and which is the property a third-party test of the drive would verify. Where both hold, a PSID revert meets the Purge threshold as a cryptographic erase under NIST SP 800-88 Revision 2, which treats cryptographic erase in a dedicated section and ties it to key-destruction requirements.[3]

There is a case where the second condition fails, and it is worth naming. TCG Pyrite is a sibling specification that provides the same locking and authentication interface as Opal without mandating encryption of the user data.[2] A Pyrite drive can present the same commands, accept a PSID, and complete a Revert — and the user data may still be present in plaintext, because it was never encrypted in the first place. On a Pyrite drive, a PSID revert unlocks the drive; it does not sanitize it. A sanitization process has to identify which specification the drive implements before treating a Revert as an erase, and a Pyrite drive still needs a firmware sanitize or destruction.

How It Is Recorded

A PSID revert on an Opal drive is a cryptographic erase, and the certificate should say so: technique, cryptographic erase; standard and level, as classified by the tool; verification, that the drive reports its post-revert state and that no prior data is readable. The PSID itself should not be recorded on the certificate. It is a permanent credential for the drive, and a drive that goes back into service should not have its PSID in a document that travels with its paperwork.

A revert on a drive that turns out to be Pyrite, or on an Opal drive that cannot complete the operation, is not an erase and should be recorded as such, with the drive routed to a firmware sanitize or to destruction.

The Practical Pattern

For a locked self-encrypting drive with unknown credentials: confirm the drive implements Opal and not Pyrite. Read the PSID from the label. Issue Revert with the PSID. Confirm the drive reports its factory state and unlocks. Record a cryptographic erase.

For a drive whose label is missing or unreadable, there is no PSID, and therefore no revert. The drive can still be reached by a firmware sanitize command if the drive accepts one while locked — some do not — or it can be destroyed. Which of those applies is a property of the drive, and a tool that has tried should record what it found.

The broader point is the same one that runs through every part of sanitization. The operation is fast and simple. What makes it an erase rather than an unlock is knowing what the drive was doing before you touched it, and being able to say so afterward.

Frequently Asked Questions

Is a PSID revert a Purge?

On a TCG Opal drive, yes: it is a cryptographic erase that destroys the media encryption key, which meets the Purge threshold under NIST SP 800-88 Revision 2 provided the drive encrypted all user data throughout its life and the key destruction is verifiable.[3] On a TCG Pyrite drive it is not, because Pyrite does not require user data to be encrypted.

Does PSID revert work on every self-encrypting drive?

It works on drives that implement TCG Opal or a compatible specification with PSID authority. Not every drive marketed as self-encrypting implements Opal, and Pyrite drives implement the interface without the encryption guarantee. The drive’s specification has to be confirmed before a revert is treated as an erase.

What if the PSID label is missing or unreadable?

There is no way to recover the PSID over the interface; it exists only on the label. A drive with no readable PSID cannot be reverted. If the drive accepts a firmware sanitize command while locked, that path may still be available; otherwise the drive is destroyed.

Can PSID revert recover the data?

No. Revert destroys the encryption key. The data is unrecoverable by anyone, including the original owner. It is a sanitization operation, not a password reset.

Should the PSID be recorded on the certificate of erasure?

No. The PSID is a permanent physical credential for the drive. Record that a PSID-authorized cryptographic erase was performed; do not record the credential.

References

  1. Trusted Computing Group. TCG Storage Security Subsystem Class: Opal, Version 2.30. January 2025. ↩
  2. Trusted Computing Group. TCG Storage Security Subsystem Class: Pyrite, Version 2.01. ↩
  3. National Institute of Standards and Technology. Guidelines for Media Sanitization, NIST Special Publication 800-88 Revision 2, cryptographic erase. September 2025. ↩

Authors

Colin Corr

Colin Corr

Senior Information Technology Manager