PXE-based data erasing method and system and medium
By integrating DHCP, TFTP, and NFS services through PXE network boot technology, large-scale parallel processing of SSD data erasure is achieved, solving the problems of low efficiency, poor compatibility, and high operation and maintenance costs in existing technologies, and improving data erasure efficiency and compliance audit capabilities.
Patent Information
- Application Number
- CN202511660990.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-13
- Publication Date
- 2026-02-10
AI Technical Summary
Existing SSD data erasure technologies are inefficient, cannot be managed at scale, have scattered reports, pose significant audit risks, have poor compatibility, and incur high maintenance costs.
It adopts PXE network boot technology and integrates DHCP, TFTP and NFS services on the server to enable parallel booting and data erasure of multiple clients. The clients do not need local hard drives or operating systems, and the parallel processing is managed in a unified manner.
It improves SSD data erasure efficiency, enables large-scale parallel processing, simplifies deployment processes, reduces operation and maintenance costs, strengthens compliance audit capabilities, is widely compatible with multi-source hardware, and ensures the stability and reliability of the operation process.
Smart Images

Figure CN121501356A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data security, and in particular to a PXE-based data erasing method and system and medium. BACKGROUND
[0002] At present, data leakage events occur frequently, and data destruction has become the last link of the lifeline of enterprise security. However, the existing SSD (Solid State Disk) data erasing technology is seriously lagging behind the actual needs of enterprise-level batch processing, and the following problems are widespread: first, low efficiency, unable to manage on a large scale: the traditional erasing method relies on single-machine local start or manual operation one by one, which is tedious and inefficient, and difficult to manage on a large scale; second, scattered reports, huge audit risks: the erasing results and logs of each device are stored separately, there is no unified and reliable audit traceability mechanism, and fatal defects are easily exposed in compliance review; third, poor compatibility, deployment and maintenance are complicated: the existing tools are difficult to adapt to multi-vendor, multi-protocol and multi-generation hardware environment, and require a lot of manual adaptation, which is high in operation and maintenance cost and difficult to guarantee reliability. SUMMARY
[0003] The present application provides a PXE-based data erasing method, device, computer equipment and medium to solve the technical problem of low efficiency of existing SSD data erasing.
[0004] In a first aspect, a PXE-based data erasing method is provided, applied to a PXE-based data erasing system including a server and multiple clients, the method comprising: The server configures and starts a DHCP service, a TFTP service and an NFS service, wherein the DHCP service is used to allocate a network address for the client and indicate the location of the TFTP service; the TFTP service is used to provide a PXE boot program, an operating system kernel and a start configuration file; the NFS service is used to share an operating system root file system; After the client is powered on, the PXE obtains the PXE boot program, the operating system kernel, the start configuration file and the operating system root file system from the server, and loads the operating system kernel according to the PXE boot program and the start configuration file, and after the operating system kernel starts successfully, mounts the operating system root file system and enters a diskless running environment; The client performs data erasing in the diskless running environment.
[0005] In a second aspect, a PXE-based data erasing system is provided, which comprises a server and a plurality of clients, wherein the server is configured with a starting unit, and the clients are configured with an obtaining and loading unit and an erasing unit, wherein: the starting unit is configured to configure and start a DHCP service, a TFTP service and an NFS service in the server, wherein the DHCP service is configured to allocate a network address for the clients and indicate the location of the TFTP service; the TFTP service is configured to provide a PXE boot program, an operating system kernel and a starting configuration file; and the NFS service is configured to share an operating system root file system; the obtaining and loading unit is configured to obtain the PXE boot program, the operating system kernel, the starting configuration file and the operating system root file system from the server through PXE after the clients are powered on, load the operating system kernel according to the PXE boot program and the starting configuration file, mount the operating system root file system after the operating system kernel is started successfully, and enter a diskless running environment; the erasing unit is configured to perform data erasing in the diskless running environment.
[0006] In a third aspect, a PXE-based data erasing system is provided, which comprises a server and a plurality of clients, and the server and the clients each comprise a memory, a processor and a computer program stored in the memory and executable on the processor, and the processor implements the steps of the PXE-based data erasing method when executing the computer program.
[0007] In a fourth aspect, a computer readable storage medium is provided, which stores a computer program, and the computer program implements the steps of the PXE-based data erasing method when executed by a processor.
[0008] The scheme realized by the PXE-based data erasing method, device, computer device and storage medium has the following advantages. The server is configured and started with a DHCP service, a TFTP service and an NFS service. The DHCP service is used to allocate a network address for a client and indicate the location of the TFTP service. The TFTP service is used to provide a PXE boot program, an operating system kernel and a start configuration file. The NFS service is used to share an operating system root file system. After the client is powered on, the PXE boot program, the operating system kernel, the start configuration file and the operating system root file system are obtained from the server through the PXE, and the operating system kernel is loaded according to the PXE boot program and the start configuration file. After the operating system kernel is successfully started, the operating system root file system is mounted, and a diskless running environment is entered. The client performs data erasing in the diskless running environment. In the present application, the DHCP service, the TFTP service and the NFS service are integrated on the server, and then the multi-client parallel starting and data erasing are realized through the PXE network boot. The client does not need a local hard disk or an operating system, the local starting of a single machine and the manual operation of each machine are avoided, and the SSD data erasing efficiency is effectively improved. BRIEF DESCRIPTION OF DRAWINGS
[0009] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the description of the embodiments of the present application. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can also be obtained by those skilled in the art without any creative labor based on these drawings.
[0010] Figure 1 is a flowchart of a PXE-based data erasing method in an embodiment of the present application; Figure 2 is a scene diagram of a PXE-based data erasing system in an embodiment of the present application; Figure 3 is Figure 1 is a flowchart of a specific embodiment of step S130 in Figure 4 is a flowchart of a PXE-based data erasing method in another embodiment of the present application; Figure 5 is a schematic block diagram of a PXE-based data erasing system in an embodiment of the present application; Figure 6 is a structural diagram of a computer device in an embodiment of the present application; Figure 7 is another structural diagram of a computer device in an embodiment of the present application. DETAILED DESCRIPTION
[0011] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of the present application.
[0012] The PXE-based data erasing method provided by the embodiments of the present application can be applied to a client or a server. The client can be, but is not limited to, various personal computers, notebook computers, smart phones, tablet computers and portable wearable devices. The server can be implemented by an independent server or a server cluster composed of multiple servers. At present, the existing SSD data erasing efficiency is low in the field of data security. In view of the above problem, the present application provides a PXE-based data erasing method. The method integrates the DHCP service, the TFTP service and the NFS service in the server first, and then realizes the parallel start and data erasing of multiple clients through PXE network boot. The client does not need a local hard disk or an operating system, which avoids the local start of a single machine and manual operation of each machine, and effectively improves the SSD data erasing efficiency. The present application will be described in detail through specific embodiments.
[0013] Please refer to Figure 1 as shown, Figure 1 A flowchart of the PXE-based data erasing method provided by the embodiments of the present application is shown, which includes the following steps: S110-S130.
[0014] S110, the server is configured and started DHCP service, TFTP service and NFS service, wherein the DHCP service is used to allocate network address for the client and indicate the location of the TFTP service; the TFTP service is used to provide PXE boot program, operating system kernel and start configuration file; the NFS service is used to share the operating system root file system.
[0015] Specifically, the PXE-based data erasing method in the present application is applied to a PXE-based data erasing system, which includes a server 10 and multiple clients 20. The DHCP service, the TFTP service and the NFS service are configured in the server 10, wherein the DHCP service is used to allocate network address for the client 20 and indicate the location of the TFTP service; the TFTP service is used to provide PXE boot program, operating system kernel and start configuration file; the NFS service is used to share the operating system root file system. As shown in Figure 2As shown, the PXE-based data erasing system further comprises a switch, the server 10 uniformly manages the erasing operation of the client 20 and collects and stores the erasing report; after the client 20 is powered on, the PXE boot program, the operating system kernel, the start configuration file and the operating system root file system are obtained from the TFTP service through the PXE, the operating system kernel is loaded according to the PXE boot program and the start configuration file, after the operating system kernel is started successfully, the operating system root file system shared by the NFS service is mounted, and a diskless running environment is entered. That is, the principle of the present application is that the PXE network boot technology is combined with the SSD safe erasing technology to construct a centralized and automated data erasing solution, and the core lies in that the client 20 does not need local storage, after being powered on, the operating system is booted and loaded to the memory running (diskless mode) from the server 10 through the PXE network, and then the local SSD is automatically called to execute safe erasing by using the preset tool; the server 10 uniformly schedules the task, monitors the state and collects the report, and realizes the full-process automatic management from starting to erasing.
[0016] It should be noted that in order to achieve efficient SSD data erasure, the server needs to deploy and configure three core services: DHCP, TFTP and NFS, to build a complete PXE network boot environment. The server hardware is the foundation, it is recommended to deploy high-performance servers, and use multi-network card binding technology to aggregate network bandwidth, improve network throughput, and ensure that it can respond to a large number of client requests simultaneously. At the same time, the storage layer should be configured with a RAID array (such as RAID 5 or RAID 10 that balances performance and reliability) to ensure the reliability of the storage root file system and the erasure report, and to prevent single point failure. The network switching environment is recommended to be Gigabit or even Gigabit Ethernet to avoid becoming a performance bottleneck. Software deployment starts with selecting a stable Linux distribution as the server operating system. The DHCP service (such as isc-dhcp-server) is responsible for automatically allocating IP addresses, subnet masks, gateways, and other network configurations for the client. In the / etc / dhcp / dhcpd.conf file, the IP address pool, subnet mask, gateway, next-server option, and filename option are defined, the next-server option is the IP address pointing to the TFTP server, and the filename option is the path to the network boot program (such as "pxelinux.0"). The TFTP service is used to store and provide a series of core files required for the PXE boot process. These files include the PXE boot program (pxelinux.0), the boot configuration file (usually located in pxelinux.cfg / default), the operating system kernel (vmlinuz), and the initial memory disk (initrd.img). These files need to be placed in the root directory of the TFTP service (such as / var / lib / tftpboot / ) and ensure that their permissions are correct so that the client can download them smoothly through the TFTP protocol. The NFS service is responsible for sharing a complete operating system root file system over the network. This root file system needs to be carefully built using debootstrap and other tools in advance, and it is a minimal Linux system that integrates all necessary hardware drivers (especially diverse network cards and NVMe drivers), dependent libraries (such as Python3), and a complete erasure tool chain (such as smartctl, nvme-cli, storcli64, etc.). The server shares this root file system directory (such as / srv / nfsroot / ) in read-only mode by configuring the / etc / exports file. When the client boots and selects PXE network boot, it first communicates with the DHCP server to obtain the IP and TFTP server address, and then downloads the boot program and kernel image from the TFTP server.After the operating system kernel starts, it mounts the root file system shared by the NFS service, thus entering a complete diskless operating environment that does not require a local disk, preparing for the subsequent automatic execution of the data erasure program.
[0017] S120. After the client is powered on, it obtains the PXE bootloader, the operating system kernel, the boot configuration file, and the operating system root file system from the server via PXE. It loads the operating system kernel according to the PXE bootloader and the boot configuration file. After the operating system kernel starts successfully, it mounts the operating system root file system and enters the diskless running environment.
[0018] Specifically, client booting and automated operation are the core of the entire process, ensuring that a large number of clients can efficiently and consistently perform the erasure task. More specifically: after a client device supporting PXE boot powers on, its network card's built-in PXE Client module sends a DHCP discovery broadcast to the current network, requesting network configuration information. The DHCP server deployed on the server responds to this request, assigning an IP address to the client and explicitly stating the address of the TFTP server and the location of the initial bootloader file (usually pxelinux.0 or core.efi) in its reply request. Subsequently, the client uses the TFTP protocol to connect to the TFTP server, downloading the bootloader and the corresponding configuration file (usually located in pxelinux.cfg / default). The kernel loads the downloaded bootloader (e.g., pxelinux.0) from the client. This bootloader, according to the settings in the configuration file (e.g., pxelinux.cfg / default), continues to load the operating system kernel (vmlinuz) and the initial memory disk (initrd.img) from the TFTP server. The initial memory disk is a temporary root filesystem containing the hardware drivers and tools necessary for the initial kernel boot process, preparing for the subsequent mounting of the actual root filesystem. When the operating system kernel boots, it specifies the source of the root file system using specific boot parameters (such as root= / dev / nfs) and configures network information to prepare for mounting the final root file system. After the diskless operating system kernel successfully boots, it mounts the root file system provided by the NFS service according to preset parameters. At this point, the client enters a complete diskless operating environment. In this environment, all client operations (including running data erasure programs and generating temporary logs) are performed in memory, and any write operations to the root file system are lost after the client restarts. This mechanism effectively ensures the purity and consistency of the operating environment at each boot, providing a stable and reliable foundation for automated, large-scale SSD data erasure tasks.
[0019] S130, The client performs data erasure in the diskless operating environment.
[0020] Specifically, such as Figure 3As shown, step S130 includes steps S131-S133: S131, the client identifies all its storage disks and obtains the serial number (SN), interface protocol, and health status of each storage disk; S132, for each identified storage disk, an erasure strategy is selected based on the corresponding interface protocol and health status; S133, according to the erasure strategy, parallel data erasure is performed on all storage disks using a multi-process or multi-threaded approach. It should be noted that when the client identifies all its storage disks, if it detects that the storage disk is in a RAID array, it automatically calls the RAID management tool to remove the storage disk from the RAID array and convert it to JBOD mode or pass-through mode. JBOD mode is a storage configuration mode. The health status of the storage disk is obtained by calling preset commands to read and analyze its attribute data. The erasure strategy includes block erasure and overwrite erasure. Users can customize the erasure strategy for the selected storage disks through preset configuration files or an interactive interface. More specifically, after the diskless operating environment successfully starts, the client automatically executes the Python erasure main program. First, it calls system commands such as `lspci` and `lsblk` to comprehensively enumerate all block devices, completing initial device discovery. For storage disks identified as being in a RAID array, it calls specific RAID management command-line tools (such as `storcli` for LSI / Avago controllers or `sas3ircu` for SAS3 controllers) to execute operations such as `delete raid`, stripping the storage disks from the logical array and converting them to JBOD or pass-through mode, thereby ensuring that subsequent erasure operations directly affect the storage disk level. Next, the SMART attribute data of each SSD is obtained using the command `smartctl -a / dev / sdX`, and its health status is analyzed accordingly. Disks with poor health are marked as "faulty" and skipped from the erasure process, with the result recorded in a report. This prevents interruptions or data loss due to hardware issues, ensuring process reliability. After device preprocessing, the erasure method for each qualified storage disk is determined based on a pre-defined configuration file (such as `config.ini`) or a user-defined strategy in the interactive interface. The erasure strategy is flexible and diverse, allowing users to choose between a single block erase or an overwrite erase based on disk type and security requirements. Block erase can also be combined with one or more overwrite erases, with a specified number of executions for each method. During the actual erasure execution phase, Python's `subprocess` module is used to concurrently issue erase commands to multiple disks using a multi-process or multi-threaded approach, achieving true parallel erasure of multiple storage disks.During the erasure process, the standard output and error stream of each erasure process are monitored in real time, and detailed progress percentage and status information are parsed and recorded, thereby ensuring that the entire parallel erasure process is controllable and visible, and effectively improving the overall efficiency of large-scale data destruction tasks.
[0021] Figure 4 A flowchart illustrating a PXE-based data erasure method according to another embodiment of the present invention is shown below. Figure 4 As shown, in this embodiment, the method includes steps S110-S170. That is, in this embodiment, after step S130 in the above embodiment, the method further includes steps S140-S170.
[0022] S140. After the data erasure is completed, the client generates an erasure report; S150. Randomly select or select all logical block addresses from the erased storage disk according to the selected verification strategy, and read their data content. S160. Verify whether the read data content meets the expected erasure result, obtain the verification result, record the verification result in the erasure report, and upload the erasure report after recording the verification result to the specified storage path of the server. S170. The server indexes and stores the received erase report based on the client's identifier, operation date, and the storage disk's serial number (SN).
[0023] Specifically, to ensure the thoroughness and auditability of data erasure, an automated verification and reporting management process is initiated after the erasure command is executed. This process does not rely solely on the return code of the erasure command, but rather ensures data unrecoverability through substantive data reading verification. According to a preset verification strategy, multiple logical block addresses are randomly or entirely selected from the erased storage disk, and the actual data content of these addresses is read using low-level commands such as `dd`. Subsequently, it is verified whether the read data content fully matches the expected erasure result. For example, after an overwrite operation, it is verified whether the data is all "0"s or specific randomly filled values, thereby confirming at the data level whether the overwrite is thorough and effectively preventing data residue. It should be noted that all results of the verification process, including whether the verification passed, the sampled LBA range, and the sampled read values, are captured and recorded. Subsequently, structured erase reports are dynamically generated using Python libraries such as openpyxl. These reports are presented in Excel format (.xlsx) and are detailed, including the client IP address, disk serial number (SN), disk model, erasure method used, start and end times of the erasure operation, total time taken, disk health status, verification results, and the final operation status (success / failure / skipped). After being generated locally on the client, the erase report is automatically uploaded to a centralized storage directory on the server using efficient synchronization tools such as Rsync. On the server, all erase reports are automatically archived and indexed according to the operation date, client identifier, and the serial number (SN) of the storage disk, forming a complete and tamper-proof audit chain, greatly facilitating subsequent compliance reviews and historical operation tracing.
[0024] It should also be noted that, to address the performance and reliability challenges in high-concurrency scenarios, this PXE-based data erasure process has implemented dual optimizations at both the server and client levels. On the server side, the number of NFS service threads is increased, a high-performance SSD root file system is used, and the network switch's traffic control strategy is adjusted to effectively handle the enormous IOPS and network bandwidth pressure generated by a large number of concurrent client startups. IOPS (Input / Output Operations Per Second) is a key indicator for measuring the performance of computer storage devices (such as HDDs, SSDs, or Storage Area Networks), representing the number of read and write operations that the storage device can handle per second. Simultaneously, a robust heartbeat detection and timeout mechanism has been established. The client erasure process periodically sends heartbeat signals to the server. If the server monitoring module does not receive a heartbeat from a client within a preset time, it automatically marks it as a "timeout anomaly" and triggers an alarm, notifying the administrator to intervene promptly, thereby ensuring the overall reliability of the batch erasure task.
[0025] This invention presents a PXE-based data erasure method that integrates DHCP, TFTP, and NFS services on the server side, and then uses PXE network booting to achieve parallel startup and data erasure of multiple clients. Clients do not require local hard drives or operating systems, avoiding single-machine local startup and manual operation on each device, effectively improving SSD data erasure efficiency. Specifically: 1. Achieves large-scale parallel processing, significantly improving operational efficiency: Utilizing the PXE network booting mechanism, multiple client devices can be simultaneously booted and executed for erasure tasks, transforming the traditional serial processing mode relying on manual operation on each device into an automated pipeline operation, greatly shortening the device decommissioning cycle; 2. Simplifies deployment process, significantly reducing maintenance costs: Adopting a unified diskless boot technology completely eliminates the manpower and material costs of preparing, installing, and recycling temporary system disks for each device. Maintenance personnel only need to ensure that the devices are powered on and connected to the network and set network boot priority to achieve zero-contact deployment of batch devices, greatly reducing operational complexity and the need for manual intervention; 3. Establishes a full-process monitoring system, strengthening compliance audit capabilities: Real-time monitoring of the erasure progress and status of all clients, each erasure... In addition to automatically generating standardized detailed reports for each operation and centrally archiving them to the server to form a complete and tamper-proof audit evidence chain; 4. Broadly compatible with multi-source hardware, reducing the workload of environment adaptation: It supports mainstream interface protocols and can automatically identify and process common RAID card configurations, converting storage disks to pass-through mode, thereby widely adapting to server hardware from various manufacturers and enterprises, significantly reducing the deployment and adaptation threshold in heterogeneous IT environments; 5. Optimized resource allocation, ensuring stable and reliable operation: The client adopts a networked, stateless operating mode, reducing dependence on local resources; The server intelligently allocates the number of concurrent tasks and combines heartbeat detection and timeout mechanisms to monitor the task status in real time, effectively avoiding network and storage resource overload and ensuring the highly reliable execution of large-scale erasure tasks.
[0026] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0027] The software tools or components not belonging to our company that appear in the embodiments of this application are merely examples and do not represent actual use.
[0028] Figure 5 This is a schematic block diagram of a PXE-based data erasure system 200 provided in an embodiment of the present invention. Figure 5 As shown, this corresponds to the PXE-based data erasure method applied to the server 10 and client 20 described above. The PXE-based data erasure system 200 includes a unit for executing the aforementioned PXE-based data erasure method. Specifically, please refer to... Figure 5The PXE-based data erasure system 200 includes a server 10 and multiple clients 20. The server 10 is configured with a startup unit 101, and each client 20 is configured with an acquisition and loading unit 201 and an erasure unit 202. The startup unit 101 is used to configure and start the DHCP service, TFTP service, and NFS service on the server side. The DHCP service is used to assign network addresses to clients and indicate the location of the TFTP service. The TFTP service is used to provide the PXE bootloader, operating system kernel, and startup configuration file. The NFS service is used to share the operating system root file system. The acquisition and loading unit 201 is used to acquire the PXE bootloader, the operating system kernel, the startup configuration file, and the operating system root file system from the server via PXE after the client is powered on, and load the operating system kernel according to the PXE bootloader and the startup configuration file. After the operating system kernel starts successfully, the operating system root file system is mounted to enter the diskless running environment. The erasure unit 202 is used by the client to perform data erasure in the diskless operating environment.
[0029] In one embodiment, the erasing unit 202 is specifically used for: The client identifies all of its own storage disks and obtains the serial number (SN), interface protocol, and health status of each storage disk. For each identified storage disk, an erasure strategy is selected based on the interface protocol and health status corresponding to the storage disk. According to the erasure strategy, all the storage disks are erased in parallel using a multi-process or multi-threaded approach.
[0030] In one embodiment, the erasing unit 202 is further configured to: When the client identifies all its storage disks, if it detects that the storage disk is in a RAID array, it automatically calls the RAID management tool to remove the storage disk from the RAID array and convert the storage disk to JBOD mode or pass-through mode.
[0031] In one embodiment, the erasing unit 202 is further configured to: The health status of the storage disk is obtained by calling a preset command to read and analyze its attribute data.
[0032] In one embodiment, the erasing unit 202 is further configured to: The erasure strategy includes block erasure and overwrite erasure. For the selected storage disk, the user can customize the erasure strategy through a preset configuration file or interactive interface.
[0033] In one embodiment, the PXE-based data erasure system 200 further includes a generation unit, a reading unit, and a record uploading unit configured on the client 20, and an index storage unit configured on the server: The generation unit is used by the client to generate an erasure report after the data erasure is completed; The reading unit is used to randomly select or select all of the logical block addresses from the erased storage disk according to the selected verification strategy, and read its data content. The record upload unit is used to verify whether the read data content meets the expected erasure result, obtain the verification result, record the verification result in the erasure report, and upload the erasure report after recording the verification result to the specified storage path of the server. The index storage unit is used by the server to index and store the received erase report based on the client's identifier, the operation date, and the serial number (SN) of the storage disk.
[0034] The PXE-based data erasure system of this invention first integrates DHCP, TFTP and NFS services on the server side, and then enables multiple clients to start up and erase data in parallel through PXE network boot. The client does not need a local hard drive or operating system, avoiding single-machine local boot and manual operation on each machine, and effectively improving the efficiency of SSD data erasure.
[0035] For specific limitations regarding the PXE-based data erasure system, please refer to the limitations of the PXE-based data erasure method mentioned above, which will not be repeated here. Each unit in the aforementioned PXE-based data erasure system can be implemented entirely or partially through software, hardware, or a combination thereof. These units can be embedded in or independent of the processor in the computer device in hardware form, or stored in the memory of the computer device in software form, so that the processor can call and execute the corresponding operations of each module.
[0036] In one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 6As shown, the computer device includes a processor, memory, network interface, and database connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile and / or volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and database. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage media. The network interface is used to communicate with external clients via a network connection. When executed by the processor, the computer program implements the functions or steps of a PXE-based data erasure method on the server side.
[0037] In one embodiment, a computer device is provided, which may be a client, and its internal structure diagram may be as follows: Figure 7 As shown, the computer device includes a processor, memory, network interface, display screen, and input devices connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage media. The network interface is used to communicate with an external server via a network connection. When executed by the processor, the computer program implements the client-side functions or steps of a PXE-based data erasure method.
[0038] In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the PXE-based data erasure method described above.
[0039] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored, which, when executed by a processor, implements the steps of the PXE-based data erasure method described above.
[0040] It should be noted that the functions or steps that can be implemented by the computer-readable storage medium or computer device described above can be referred to the relevant descriptions on the server side and client side in the foregoing method embodiments. To avoid repetition, they will not be described one by one here.
[0041] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments described above. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in a variety of forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.
[0042] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is used as an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.
[0043] The above-described embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.
Claims
1. A PXE-based data erasure method, applied to a PXE-based data erasure system, wherein the PXE-based data erasure system includes a server and multiple clients, characterized in that, The method includes: The server configures and starts DHCP, TFTP, and NFS services. The DHCP service is used to assign network addresses to clients and indicate the location of the TFTP service. The TFTP service is used to provide the PXE bootloader, operating system kernel, and boot configuration file. The NFS service is used to share the operating system root file system. After the client is powered on, it obtains the PXE bootloader, the operating system kernel, the boot configuration file, and the operating system root file system from the server via PXE. It then loads the operating system kernel according to the PXE bootloader and the boot configuration file. After the operating system kernel starts successfully, it mounts the operating system root file system and enters the diskless running environment. The client performs data erasure in the diskless operating environment.
2. The method according to claim 1, characterized in that, The client performs the data erasure steps in the diskless operating environment, including: The client identifies all of its own storage disks and obtains the serial number (SN), interface protocol, and health status of each storage disk. For each identified storage disk, an erasure strategy is selected based on the interface protocol and health status corresponding to the storage disk. According to the erasure strategy, all the storage disks are erased in parallel using a multi-process or multi-threaded approach.
3. The method according to claim 2, characterized in that, When the client identifies all its storage disks, if it detects that the storage disk is in a RAID array, it automatically calls the RAID management tool to remove the storage disk from the RAID array and convert the storage disk to JBOD mode or pass-through mode.
4. The method according to claim 2, characterized in that, The health status of the storage disk is obtained by calling a preset command to read and analyze its attribute data.
5. The method according to claim 2, characterized in that, The erasure strategy includes block erasure and overwrite erasure. For the selected storage disk, the user can customize the erasure strategy through a preset configuration file or interactive interface.
6. The method according to claim 2, characterized in that, After the client performs the data erasure step in the diskless operating environment, it also includes: The client generates an erasure report after the data erasure is completed; From the erased storage disk, randomly select or select all logical block addresses according to the selected verification strategy, and read their data content; Verify whether the read data content matches the expected erasure result to obtain the verification result, record the verification result in the erasure report, and upload the erasure report after recording the verification result to the designated storage path on the server.
7. The method according to claim 6, characterized in that, After the step of uploading the erase report, which records the verification result, to the designated storage path on the server, the method further includes: The server indexes and stores the received erase report based on the client's identifier, the operation date, and the serial number (SN) of the storage disk.
8. A PXE-based data erasure system, characterized in that, It includes a server and multiple clients, wherein the server is configured with a startup unit, and the clients are configured with an acquisition and loading unit and an erasure unit, wherein: The startup unit is used to configure and start the DHCP service, TFTP service, and NFS service on the server side. The DHCP service is used to assign network addresses to clients and indicate the location of the TFTP service. The TFTP service is used to provide the PXE bootloader, operating system kernel, and startup configuration file. The NFS service is used to share the operating system root file system. The acquisition and loading unit is used to acquire the PXE bootloader, the operating system kernel, the startup configuration file, and the operating system root file system from the server via PXE after the client is powered on, and load the operating system kernel according to the PXE bootloader and the startup configuration file. After the operating system kernel starts successfully, the operating system root file system is mounted to enter the diskless running environment. The erasure unit is used by the client to perform data erasure in the diskless operating environment.
9. A PXE-based data erasure system, comprising a server and multiple clients, wherein both the server and the clients include a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the PXE-based data erasure method as described in any one of claims 1 to 7.
10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the steps of the PXE-based data erasure method as described in any one of claims 1 to 7.