Lenovo ThinkShield P-Series Secure Wipe on Workstation User Guide

June 13, 2024
Lenovo

ThinkShield P-Series Secure Wipe on Workstation
User GuideLenovo ThinkShield P-Series Secure Wipe on
Workstation Lenovo ThinkShield Secure Wipe on Workstation
ThinkStation: PX-P7-P5-P3-P360-P358-P350
ThinkPad P-Series Workstations

Overview

The purpose of this document is to provide guidelines for users on how to securely erase SATA and M.2 drives in select Lenovo ThinkStations and ThinkPads using the built-in ThinkShield Secure Wipe feature. Secure Wipe is available for drives utilizing the onboard controller. Secure Wipe for drives utilizing external controllers is not currently supported.
Some last generation and legacy ThinkStation platforms utilize Secure Erase instead of Secure Wipe. For more information on that feature, please see the ThinkStation Secure Erase whitepaper.

Section 1 – Prepare Drive(s) for Secure Wipe

The following instructions will cover the steps required to use ThinkStation BIOS to securely erase SATA HDD/SSD and M.2 NVMe drives.
To avoid erasing incorrect drives, Lenovo recommends users remove any drives not targeted for erasure to ensure only the intended drive is erased. If the user does not wish to remove any drives from the system, it is highly recommended to externally back up data from non-targeted drives to avoid accidental loss of data.
The ThinkShield Secure Wipe feature works best when erasing single drives rather than an entire RAID array or its members sequentially. It is recommended to switch the system’s storage setting to AHCI and erase each drive individually.
Magnetic rotating drives will take significantly longer to erase compared to M.2 and SSD drives due to the nature of the older technology. Using legacy erasure methods may also increase the process duration for any drive type.
Large capacity HDDs may take hours to complete, and the system cannot be used while the process is occurring.

  1. With the target drive connected to the system, power on the system and press “F1” at the Lenovo splash screen to enter the BIOS setup. Navigate to the “Devices” tab and select the “Storage Setup”. This may appear as “ATA Drive Setup” on some systems. Press enter.Lenovo ThinkShield P-Series Secure Wipe on Workstation - setting 1
  2. Make sure the “Configure SATA as” option is set to “AHCI”.Lenovo ThinkShield P-Series Secure Wipe on Workstation - setting 1
  3. Some platforms’ RAID options may be listed under Advanced→”Intel® VROC SATA Controller” (for SATA RAID) or “Intel® Virtual RAID on CPU” (for M.2 NVMe VMD RAID). These titles may vary by platform. RAID arrays can be deconstructed in these menus.Lenovo ThinkShield P-Series Secure Wipe on Workstation - setting 3
  4. For all systems, to perform Secure Wipe, a password must be assigned to the drive. If a password is not assigned now, the user will be prompted later in the Secure Wipe process to assign one. To do this, navigate to Security→Hard Disk Password. Highlight “SATA Drive # Password” or “M.2 Drive # Password” and press enter. Lenovo ThinkShield P-Series Secure Wipe on Workstation - setting 4
  5. A “Setup Confirmation” box will appear. Select “User” or “Single Password” and press enter. The dual password option may also be selected, however only the single user password is required for the Secure Wipe feature.Lenovo ThinkShield P-Series Secure Wipe on Workstation - setting 5
  6. Choose a simple, temporary password and confirm it. Write down this password as it will be needed later. Select “Yes” to continue. This password will also be erased alongside all data on the drive. Lenovo ThinkShield P-Series Secure Wipe on Workstation - setting 6
  7. A “Setup Notice” box will be prompted, displaying that the changes have been saved. Press “Continue”.Lenovo ThinkShield P-Series Secure Wipe on Workstation - setting 7
  8. At this point, the system needs to be rebooted for the changes to take effect. Press “F10” function key to save and exit the BIOS setup.Lenovo ThinkShield P-Series Secure Wipe on Workstation - setting 8
  9. Once the system starts to reboot, press “F1” at Lenovo splash screen to enter the BIOS setup again. If the system prompts to enter the “Hard Disk Password”, enter the assigned password.Lenovo ThinkShield P-Series Secure Wipe on Workstation - setting 9

Section 2 – Secure Wipe on ThinkStation

This section covers performing the Secure Wipe function for ThinkStation. The tables below list methods found on most systems. Some methods may appear/disappear depending on system model, drive type, and RAID status.
Secure Wipe is available for drives utilizing the onboard controller. Secure Wipe for drives utilizing external controllers is not currently supported.

Erase Method Description
ATA Secure Erase This method resets all data on the drive in the standard

way.
ATA Cryptographic KeyReset| For Full Disk Encrypted drives only. This method resets the internal encryption key, making the drive data completely unreadable.

Legacy Methods – These methods are not guaranteed to fully erase a modern hard drive.
Legacy Erase Method
US DoD 5220.22-M
Single Pass Zeros
US Navy & Air Force
CSE Canada ITSG-06 (Unclassified)
British HMG Infosec Standard 5, Enhanced
German VSITR
Russian GOST P50739-95 Level 1
Russian GOST P50739-95 Level 4
RCMP TSSIT OPS-II

  1. Enter BIOS and navigate to “Secure Wipe” under the Security tab. Set to “Enabled”. Press F10 to save the setting and reboot the system.Lenovo ThinkShield P-Series Secure Wipe on Workstation - setting 10
  2. On the Lenovo splash screen, press F12 to enter the Boot Menu. Navigate to the App Menu and select “ThinkShield secure wipe”.Lenovo ThinkShield P-Series Secure Wipe on Workstation - setting 11
  3. ThinkShield will load and list available drives in the system that can be wiped. Click “NEXT” to proceed.Lenovo ThinkShield P-Series Secure Wipe on Workstation - setting 12
  4. Select the preferred erasure method. “ATA Secure Erase” will be used in this example. Click “NEXT”.Lenovo ThinkShield P-Series Secure Wipe on Workstation - setting 13
  5. This is the final warning to the user that all data will be erased. Once acknowledged, click “OK”.Lenovo ThinkShield P-Series Secure Wipe on Workstation - setting 14
  6. If the user forgot to assign a password on the drive, ThinkShield will prompt at this step to assign one to the drive.Lenovo ThinkShield P-Series Secure Wipe on Workstation - setting 15
  7. The wiping process will now start. Once concluded the system will need to be rebooted. The temporary password set on the drive is now erased. Once the reboot is concluded, the system can be powered down, and the drive can safely be removed from the system. Repeat the process for any additional drives that might need to be securely wiped.Lenovo ThinkShield P-Series Secure Wipe on Workstation - setting 16

Section 4 – Secure Wipe on ThinkPad

The following instructions will cover the steps required to use ThinkShield feature in ThinkPad BIOS to securely erase storage drives.

  1. Boot into BIOS by pressing function “F1” key at the Lenovo splash screen.Lenovo ThinkShield P-Series Secure Wipe on Workstation - setting 17

  2. Once inside the BIOS setup, navigate to the “Security” menu and select “ThinkShield secure wipe”.Lenovo ThinkShield P-Series Secure Wipe on Workstation - setting 18

  3. Confirm the “ThinkShield secure wipe in App Menu” is set to enabled.Lenovo ThinkShield P-Series Secure Wipe on Workstation - setting 19

  4. Save and exit the BIOS setup by pressing the “F10” function key.
    On reboot, load the “Boot Menu” by pressing the “F12” function key at the Lenovo splash screen. Tab over to the “App Menu” and select “ThinkShield secure wipe” option.Lenovo ThinkShield P-Series Secure Wipe on Workstation -
setting 20

  5. Select the storage device to be erased and press “Next”.Lenovo ThinkShield P-Series Secure Wipe on Workstation - setting 21

  6. Select an appropriate method from the dropdown menu to securely erase the chosen drive and press “Next”. “ATA Secure Erase” will be used in this example.Lenovo ThinkShield P-Series Secure Wipe on Workstation - setting 22

  7. A warning will appear to confirm if the user wants to continue with the secure erase process. Select “Yes” to proceed.Lenovo ThinkShield P-Series Secure Wipe on Workstation - setting 23

  8. A progress window will appear displaying the data wiping process. Do not power off until the process is complete.Lenovo ThinkShield P-Series Secure Wipe on Workstation - setting 24

  9. On completion of the process, a confirmation message will be displayed. At this time, drives are wiped successfully, and the system should be rebooted for the changes to take effect. Select “Reboot”.Lenovo ThinkShield P-Series Secure Wipe on Workstation - setting 25

  10. At this point, the erase procedure is complete. The temporary password on the drive is now erased. Repeat the process for any additional drives that might need to be securely erased.

Section 5 – Revision History

Version Date Author Updates
1 7/26/2023 Chris C. Initial Release

Read User Manual Online (PDF format)

Read User Manual Online (PDF format)  >>

Download This Manual (PDF format)

Download this manual  >>

Lenovo User Manuals

Related Manuals