- the drive can request the key on each boot - the drive stores the key in the firmware, but part of the de-provisioning process would be to reset this key