Network Device Wiping
The method and system provide a standardized data erasure solution for network devices by comparing device responses to expected outcomes, ensuring reliable data clearance and audit trails across various manufacturers.
Patent Information
- Application Number
- JP2023503032
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-07-16
- Filing Date
- 2021-07-15
- Publication Date
- 2025-08-21
- Estimated Expiration
- 2041-07-15
AI Technical Summary
There is a lack of universal methods for reliably erasing data from network devices due to varying manufacturers and lack of standardization, with existing protocols allowing for different interpretations and partial implementations, posing security risks from stored data access.
A method and system for erasing data from network devices involving a data wiping procedure, followed by a comparison of the device's response to an expected outcome, and recording the result for audit trails, using protocols like TR-069 CPE WAN Management Protocol and cloud storage for verification.
Ensures reliable data erasure by verifying successful memory clearance through response comparisons and audit trails, providing a standardized approach across diverse network devices.
Smart Images

Figure 0007727710000001 
Figure 0007727710000002 
Figure 0007727710000003
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to methods and systems for use in erasing data stored in memory of a network device, and particularly, but not exclusively, to methods and systems for use in erasing data stored in memory of at least one of a router, a switch, a modem, a gateway, a firewall, a media converter, and a repeater. [Background technology]
[0002] Information networks, such as the public Internet or local area networks (LANs), consist of computers connected to each other through network devices such as routers, switches, modems, gateways, firewalls, media converters, and repeaters. These network devices store data that may pose information security risks by providing access to the network itself and / or logging information about network traffic (e.g., visited websites).
[0003] In an IP network, data packets are transmitted from one network device to another. Specifically, the Internet Protocol (IP) enables delivery of packets from a source computing resource or host to a destination computing resource or host based on the IP address in the data packet's header. In interconnected networks, routers forward packets across network boundaries based on information stored in their internal routing tables.
[0004] Additionally, routers typically collect and log data about devices and traffic on the network. Such data may include, for example, the number of devices connected to the router, the IP addresses, MAC addresses, and serial numbers of the devices, and data about network traffic, such as websites visited. Such data can be used by Internet Service Providers (ISPs) for network optimization or targeted advertising. However, such data can also be used by hackers who seek to find and target vulnerable devices on the network and sensitive information related to the websites visited.
[0005] Access to local networks is typically protected by passwords stored in routers and firewalls. While these network devices are typically password protected themselves, the default username and password for network devices are typically very generic (e.g., "admin" / "1234") and may be stamped on the outside of the network device by the network device's original equipment manufacturer (OEM). If the default password is not changed, anyone with access to the physical network device would easily be able to view the network passwords, rules, and log data. Even without knowing the network password, it may be possible to access at least some of the data by bypassing the firmware layer using invasive methods that directly read the network device's memory.
[0006] In light of the above, there is a need to reliably erase the memory of network devices after they have been used in a network. However, there are challenges due to the lack of universal standards for data management on network devices, as well as the vast range of network devices and manufacturers. Currently, there is no universal method for erasing network devices.
[0007] Some OEMs may use their own set of commands / methods for triggering the internal erase function, in which case users must maintain documentation describing the interfaces and commands for erasing various devices. While there are several universal remote management protocols, these protocols may only include optional methods for data management and may allow for different interpretations or partial implementations. For example, support for the factory reset Remote Procedure Call (RPC) message is only an optional part of the TR-069 CPE WAN Management Protocol (Issue: 1 Revision 6). Summary of the Invention [Means for solving the problem]
[0008] According to one aspect of the present disclosure, there is provided a method for use in erasing data stored in a memory of a network device, the method comprising: performing a data wiping procedure to erase stored data from the memory of the network device; requesting data from the memory of the network device after the data erasure procedure is completed or accessing the memory of the network device after the data erasure procedure is completed; a comparison of a response received from the network device in response to the request for data with an expected response indicating successful erasure of the memory of the network device; or and determining a final result of the data erasure procedure based at least in part on a comparison of any contents of the network device's memory after completion of the data erasure procedure with expected contents of the network device's memory after completion of the data erasure procedure, the expected contents indicating that the network device's memory was successfully erased. Determining the final outcome of the data erasure procedure may, for example, allow for the provision of an audit trail to enable a third party to verify at a later date, if desired, that the erasure of the network device was successful.
[0009] The method may include recording or storing the received response, for example, recording or storing the received response in a cloud. Recording or storing the received response may, for example, enable the provision of an audit trail to enable a third party to verify that the erasure of the network device was successful at a later date, if desired.
[0010] The method may include recording or storing any contents of the memory of the network device after the data erasure procedure is completed, for example, recording or storing in a cloud any contents of the memory of the network device after the data erasure procedure is completed. Recording or storing any contents of the memory of the network device after the data erasure procedure may, for example, enable the provision of an audit trail to enable a third party to verify at a later date, if desired, that the erasure of the network device was successful.
[0011] The method may include recording or storing the determined final outcome of the data erasure procedure, for example, recording or storing the determined final outcome of the data erasure procedure in a cloud. Recording or storing the determined final outcome of the data erasure procedure may, for example, enable the provision of an audit trail to enable a third party to verify that the network device was successfully erased at a later date, if desired.
[0012] The expected response may include a default response.
[0013] The expected contents of the network device's memory may include default contents.
[0014] The method may include requesting the IP address data from the memory of the network device after completing the data erasure procedure. The method may include determining a successful final outcome based at least in part on verifying that the response received from the network device does not include the IP address data assigned to the network device.
[0015] The method may include accessing a predetermined portion of a memory of the network device used to store IP address data after completion of the data erasure procedure. The method may include determining a successful final outcome based at least in part on verifying that the predetermined portion of the memory of the network device used to store IP address data does not contain IP address data after completion of the data erasure procedure.
[0016] The method may include requesting the MAC address data from a memory of the network device after completing the data erasure procedure. The method may include determining a successful final outcome based at least in part on verifying that a response received from the network device does not include the MAC address data assigned to the network device.
[0017] The method may include accessing a predetermined portion of a memory of the network device used to store MAC address data after completion of the data erasure procedure. The method may include determining a successful final outcome based at least in part on verifying that the predetermined portion of the memory of the network device used to store MAC address data does not contain MAC address data after completion of the data erasure procedure.
[0018] The method may include requesting running configuration data from a memory of the network device after completion of the data erasure procedure. The method may include determining a successful final outcome based at least in part on verifying that a response received from the network device corresponds to an expected running configuration indicating that the memory erasure of the network device was successful.
[0019] The method may include accessing a predetermined portion of the memory of the network device used to store running configuration data after completion of the data erasure procedure. The method may include determining a successful final outcome based at least in part on verifying that the predetermined portion of the memory of the network device used to store running configuration data contains running configuration data corresponding to an expected running configuration indicating that the erasure of the memory of the network device was successful.
[0020] The method may include requesting a local area network (LAN) name and password from a memory of the network device after completing the data erasure procedure. The method may include determining a successful final outcome based at least in part on verifying that the received local area network name and password correspond to an expected username and expected password for the local area network, respectively.
[0021] The method may include accessing a predetermined portion of a memory of the network device used to store local area network (LAN) names and passwords after completion of the data erasure procedure. The method may include verifying that the local area network (LAN) name and password stored in the predetermined portion of the memory of the network device used to store local area network (LAN) names and passwords correspond to an expected name and expected password for the local area network (LAN), respectively, after completion of the data erasure procedure.
[0022] The method may include requesting network device information from the network device.
[0023] The method may include receiving network device information from the network device in response to the request for network device information.
[0024] The method may include selecting a data erasure procedure from a database of data erasure procedures based at least in part on the received network device information.
[0025] The method may include selecting, based at least in part on the received network device information, a predicted response from a database of predicted responses that indicates a successful erasure of the memory of the network device.
[0026] The method may include accessing network device information stored in a memory of the network device.
[0027] The method may include selecting a data erasure procedure from a database of data erasure procedures based at least in part on the accessed network device information.
[0028] The method may include selecting, based at least in part on the accessed network device information, from a database of predicted contents, predicted contents of the memory of the network device that indicate a successful erasure of the memory of the network device.
[0029] The network device information may include at least one of the following: the manufacturer of the network device, the model number, and / or operating system details of the network device, such as the type and / or version of the operating system of the network device.
[0030] At least one of the database of data purging procedures, the database of expected responses, and the database of expected content includes a profiler API.
[0031] The method may include requesting initial data from a memory of the network device before initiating the data erasure procedure.
[0032] The method may include receiving an initial response from the network device in response to the request for the initial data.
[0033] The method may include determining a final outcome of the data erasure procedure based at least in part on a comparison of an initial response received from the network device and a response received from the network device in response to the request for initial data.
[0034] The method may include accessing a memory of the network device before initiating the data erasure procedure, and determining a final outcome of the data erasure procedure based at least in part on a comparison of any initial contents of the memory of the network device before initiating the data erasure procedure and any contents of the memory of the network device after completion of the data erasure procedure.
[0035] The method may include determining a final outcome of the data erasure procedure that is successful based at least in part on verifying that all IP addresses and / or all MAC addresses have been cleared from the routing table of the network device.
[0036] The stored data may include one or more IP addresses.
[0037] The stored data may include one or more MAC addresses.
[0038] The stored data may include one or more usernames.
[0039] The stored data may include one or more passwords.
[0040] The stored data may include the name of a local area network (LAN).
[0041] The stored data may include a local area network (LAN) password.
[0042] The stored data may include configuration data such as IP configuration data and / or boot setting data.
[0043] The stored data may be stored in one or more data files and / or one or more configuration files in a file system in the memory of the network device.
[0044] The data wiping procedure is configured to erase all accessible data stored in the memory of the network device.
[0045] Performing a data wiping procedure may include clearing data stored in a memory of the network device.
[0046] Performing a data erasure procedure may include replacing data stored in the memory of the network device.
[0047] Performing a data erasure procedure may include changing the key used to encrypt data stored in the memory of the network device.
[0048] Performing a data erasure procedure may include clear-level sanitization as defined by NIST SP 800-88 (Revision 1).
[0049] Performing a data erasure procedure may include executing an internal, built-in, default, factory, and / or native data erasure procedure associated with or stored in the network device, for example, executing a reset procedure or erase function associated with or stored in the network device.
[0050] Performing a data wiping procedure may include manually clearing data stored in the memory of the network device, for example, via a computing resource and / or a user interface.
[0051] Data erasure procedures may include purge-level sanitization as defined by NIST SP 800-88 (Revision 1).
[0052] Performing a data erasure procedure may include updating and / or replacing software and / or firmware on the network device.
[0053] A network device may have memory and may comprise a device configured to interconnect or enable the interconnection of two or more computing resources.
[0054] The network device may comprise at least one of a router, a switch, a modem, a gateway, a firewall, a media converter, and a repeater.
[0055] The network device may include a router with a serial port.
[0056] The method may include logging into the router by sending a username and password to the router via a serial port.
[0057] The method may include sending a trigger command to the router via the serial port to cause the router to initiate an internal, built-in, default, factory, and / or native data wipe procedure associated with or stored in the router, for example, to cause the router to initiate a reset procedure or wipe function associated with or stored in the router.
[0058] The method may include providing an image file to the router. The method may include sending a trigger command to the router via a serial port to cause the router to use the image file to overwrite existing firmware on the router.
[0059] The method comprises: After the data wipe procedure is complete, you can log in to the router via the serial port and Requesting data from the router's memory via the serial port; receiving a response from the router via the serial port in response to the request for data.
[0060] After the data wipe procedure is complete, logging into the router via the serial port is Using the default username and password to log into the router, or This may include resetting usernames and passwords. The network device may have an Ethernet port for communication with a wide area network (WAN).
[0061] The method may include establishing a connection with the network device via an Ethernet port in accordance with a WAN management protocol. Establishing a connection with the network device via an Ethernet port in accordance with a WAN management protocol may be advantageous because it may avoid the requirement to log in to the network device, for example, by transmitting a username and password to the network device.
[0062] The WAN management protocol may include the TR-069 CPE WAN Management Protocol (CWMP).
[0063] The method may include sending a factory reset remote procedure call (RPC) message to the network device to reset the network device to a factory default state and erase memory of the network device.
[0064] The method may include sending a schedule download or download message to the network device to cause the network device to download a firmware update from a specified location and apply the firmware update to overwrite existing firmware on the network device.
[0065] According to one aspect of the present disclosure, there is provided a system for use in erasing data stored in a memory of a network device, the system being configured to perform any of the methods described above. The system may include a computing resource configured to communicate with the network device. The computing resource may be configured to trigger or initiate a data erasure procedure or perform a data erasure procedure on the memory of the network device. The computing resource may be configured to request the data from the memory of the network device after the data erasure procedure is completed.
[0066] The computing resource may be configured to receive a response from the network device in response to the request for data.
[0067] The computing resource may be configured to determine a final outcome of the data erasure procedure based at least in part on a comparison of a response received from the network device in response to the request for data to an expected response indicating successful erasure of the memory of the network device.
[0068] The computing resource may be configured to access the memory of the network device after the data erasure procedure is completed.
[0069] The computing resource may be configured to determine a final outcome of the data erasure procedure based at least in part on a comparison of any contents of the network device's memory after completion of the data erasure procedure with predicted contents of the network device's memory after completion of the data erasure procedure, which indicates that the network device's memory was successfully erased.
[0070] The computing resource may be configured to record or store the determined end result of the data erasure procedure in a memory of the computing resource. The computing resource may be configured to record or store the determined end result of the data erasure procedure remotely from the computing resource, for example in the cloud.
[0071] The computing resource may be configured to record or store the received response in a memory of the computing resource.
[0072] The computing resource may be configured to record or store the received response remotely from the computing resource, for example in the cloud.
[0073] The computing resource may be configured to record or store any contents of the memory of the network device after the data erasure procedure is complete.
[0074] The computing resource may be configured to record or store any contents of the memory of the network device in the cloud after the data erasure procedure is completed. The expected response may include a default response.
[0075] The expected contents of the network device's memory may include default contents.
[0076] The computing resource may be configured to request network device information from the network device.
[0077] The computing resource may be configured to receive network device information from the network device in response to a request for the network device information.
[0078] The computing resource may be configured to select a data erasure procedure from a database of data erasure procedures based at least in part on the received network device information.
[0079] The computing resource may be configured to select a predicted response from a database of predicted responses or a default response based at least in part on the received network device information. The computing resource may be configured to access network device information stored in a memory of the network device.
[0080] The computing resource may be configured to select a data erasure procedure from a database of data erasure procedures based at least in part on the accessed network device information.
[0081] The computing resource may be configured to select, based at least in part on the accessed network device information, from a database of predicted contents, predicted contents of the memory of the network device that indicate a successful erasure of the memory of the network device.
[0082] The computing resource may be configured to access network device information stored in a memory of the network device.
[0083] The computing resource may be configured to select a data erasure procedure from a database of data erasure procedures based at least in part on the accessed network device information.
[0084] The computing resource may be configured to select, based at least in part on the accessed network device information, from a database of predicted contents, predicted contents of the memory of the network device that indicate a successful erasure of the memory of the network device.
[0085] At least one of the database of data purging procedures, the database of expected responses, and the database of expected content may include a profiler API.
[0086] At least one of the database of data erasure procedures, the database of expected responses, and the database of expected content may be provided with the computing resource or may be located remotely from the computing resource.
[0087] The network device information may include at least one of the following: the manufacturer of the network device, the model number, and / or operating system details of the network device, such as the type and / or version of the operating system of the network device.
[0088] The computing resource may be configured to request initial data from the memory of the network device before initiating the data erasure procedure.
[0089] The computing resource may be configured to receive an initial response from the network device in response to the request for the initial data.
[0090] The computing resource may be configured to determine a final outcome of the data erasure procedure based at least in part on a comparison of an initial response received from the network device in response to the request for initial data with the response received from the network device.
[0091] The computing resource may be configured to access the memory of the network device before initiating the data erasure procedure.
[0092] The computing resource may be configured to determine a final outcome of the data erasure procedure based at least in part on a comparison of any initial contents of the network device's memory before initiating the data erasure procedure and any contents of the network device's memory after completion of the data erasure procedure.
[0093] The computing resource may be configured to determine a final outcome of the data erasure procedure that is successful based at least in part on verifying that all IP addresses and / or all MAC addresses have been cleared from the routing table of the network device.
[0094] The stored data may include one or more IP addresses.
[0095] The stored data may include one or more MAC addresses.
[0096] The stored data may include one or more usernames.
[0097] The stored data may include one or more passwords.
[0098] The stored data may include the name of a local area network (LAN).
[0099] The stored data may include a local area network (LAN) password.
[0100] The stored data may include configuration data such as IP configuration data and / or boot setting data.
[0101] The stored data may be stored in one or more data files and / or one or more configuration files in a file system in the memory of the network device.
[0102] The data wiping procedure may be configured to erase all accessible data stored in the memory of the network device.
[0103] The data wiping procedure may include clearing data stored in the memory of the network device.
[0104] The data erasure procedure may include replacing data stored in the memory of the network device.
[0105] The data erasure procedure may include changing the key used to encrypt data stored in the memory of the network device.
[0106] Data erasure procedures may include clear-level sanitization as defined by NIST SP 800-88 (Revision 1).
[0107] The data erasure procedure may include executing an internal, built-in, default, factory, and / or native data erasure procedure associated with or stored on the network device, for example, executing a reset procedure or erase function associated with or stored on the network device.
[0108] The data clearing procedure may involve manually clearing data stored in the memory of the network device, for example, via a computing resource and / or a user interface.
[0109] Data erasure procedures may include purge-level sanitization as defined by NIST SP 800-88 (Revision 1).
[0110] The data erasure procedure may include updating and / or replacing the software and / or firmware of the network device.
[0111] A network device may include a device having memory and configured to interconnect or enable the interconnection of two or more computing resources.
[0112] The network device may include at least one of a router, a switch, a modem, a gateway, a firewall, a media converter, and a repeater.
[0113] The network device may include a router with a serial port.
[0114] The computing resource may be configured to log into the router by sending a username and password to the router via the serial port.
[0115] The computing resource may be configured to send a trigger command to the router via the serial port to cause the router to initiate an internal, built-in, default, factory, and / or native data wipe procedure associated with or stored in the router, e.g., to cause the router to initiate a reset procedure or wipe function associated with or stored in the router.
[0116] The computing resource may be configured to provide the image file to the router, and to send a trigger command to the router via the serial port to cause the router to use the image file to overwrite existing firmware on the router.
[0117] Computing resources are After the data wipe procedure is complete, you can log in to the router via the serial port and Requesting data from the router's memory via the serial port; receiving a response from the router via the serial port in response to the request for data.
[0118] The computing resource must use the default username and password to log into the router after the data erasure procedure is complete, or It may be configured to log into the router via the serial port by resetting the username and password.
[0119] The network device may have an Ethernet port for communication with a wide area network (WAN).
[0120] The computing resource may be configured to establish a connection with the network device via the Ethernet port according to a WAN management protocol.
[0121] The WAN management protocol may include the TR-069 CPE WAN Management Protocol (CWMP).
[0122] The computing resource may be configured to send a factory reset remote procedure call (RPC) message to the network device to reset the network device to a factory default state and erase the memory of the network device.
[0123] The computing resource may be configured to send a schedule download or download message to the network device to cause the network device to download a firmware update from a specified location and apply the firmware update to overwrite the existing firmware of the network device.
[0124] According to one aspect of the present disclosure, there is provided a method for use in erasing data stored in a memory of a network device, the method including erasing all accessible data stored in the memory of the network device.
[0125] The stored accessible data may include one or more IP addresses.
[0126] The stored accessible data may include one or more MAC addresses.
[0127] The stored accessible data may include one or more usernames.
[0128] The stored accessible data may include one or more passwords.
[0129] The stored data may include the name of a local area network (LAN).
[0130] The stored data may include a local area network (LAN) password.
[0131] The stored accessible data may include IP configuration data and / or boot configuration data.
[0132] The stored accessible data may be stored in one or more data files and / or one or more configuration files within a file system in the memory of the network device.
[0133] Performing a data wiping procedure may include clearing all accessible data stored in the memory of the network device.
[0134] Performing a data erasure procedure may include replacing all accessible data stored in the memory of the network device.
[0135] Performing a data wiping procedure may include changing the key used to encrypt all accessible data stored in the memory of the network device.
[0136] Data erasure procedures may include clear-level sanitization as defined by NIST SP 800-88 (Revision 1).
[0137] Performing a data erasure procedure may include executing an internal, built-in, default, factory, and / or native data erasure procedure associated with or stored in the network device, for example, executing a reset procedure or erase function associated with or stored in the network device.
[0138] Performing a data wiping procedure may include manually clearing all accessible data stored in the memory of the network device.
[0139] Performing a data wiping procedure may include using computing resources and / or a user interface to clear all accessible data stored in the memory of the network device.
[0140] Data erasure procedures may include purge-level sanitization as defined by NIST SP 800-88 (Revision 1).
[0141] Performing a data erasure procedure may include updating and / or replacing software and / or firmware on the network device.
[0142] The method may include requesting the IP address data from the memory of the network device after the data wiping procedure is completed.
[0143] The method may include receiving a response from the network device in response to the request for data.
[0144] The method may include determining a final outcome of the data erasure procedure based at least in part on a comparison of a response received from the network device in response to the request for data to an expected response indicating successful erasure of the memory of the network device.
[0145] The method may include accessing the memory of the network device after the data erasure procedure is completed.
[0146] The method may include determining a final result of the data erasure procedure based at least in part on a comparison of any contents of the network device's memory after completion of the data erasure procedure to expected contents of the network device's memory after completion of the data erasure procedure, where the comparison indicates that the network device's memory was successfully erased.
[0147] The method may include recording or storing the received response, for example, recording or storing the received response in a cloud.
[0148] The method may include recording or storing any content of the memory of the network device after the data erasure procedure is completed, for example recording or storing any content of the memory of the network device after the data erasure procedure is completed in the cloud.
[0149] The method may include recording or storing the determined final outcome of the data erasure procedure, for example, recording or storing the determined final outcome of the data erasure procedure in a cloud.
[0150] The expected response may include a default response.
[0151] The expected contents of the network device's memory may include default contents.
[0152] The method may include requesting the IP address data from a memory of the network device after completing the data erasure procedure. The method may include determining a successful final outcome based at least in part on verifying that a response received from the network device does not include the IP address data assigned to the network device.
[0153] The method may include accessing a predetermined portion of a memory of the network device used to store IP address data after completion of the data erasure procedure. The method may include determining a successful final outcome based at least in part on verifying that the predetermined portion of the memory of the network device used to store IP address data does not contain IP address data after completion of the data erasure procedure.
[0154] The method may include requesting MAC address data from a memory of the network device after completing the data erasure procedure. The method may include determining a successful final outcome based at least in part on verifying that a response received from the network device does not include MAC address data assigned to the network device.
[0155] The method may include accessing a predetermined portion of a memory of the network device used to store MAC address data after completion of the data erasure procedure. The method may include determining a successful final outcome based at least in part on verifying that the predetermined portion of the memory of the network device used to store MAC address data does not contain MAC address data after completion of the data erasure procedure.
[0156] The method may include requesting running configuration data from a memory of the network device after the data erasure procedure is completed. The method may include determining a successful final outcome based at least in part on verifying that a response received from the network device corresponds to an expected or default running configuration, indicating that the memory erasure of the network device was successful.
[0157] The method may include accessing a predetermined portion of the memory of the network device used to store running configuration data after completion of the data erasure procedure. The method may include determining a successful final outcome based at least in part on verifying that the predetermined portion of the memory of the network device used to store running configuration data contains running configuration data corresponding to an expected running configuration indicating that the erasure of the memory of the network device was successful.
[0158] The method may include requesting a name and password of the local area network from a memory of the network device after completing the data erasure procedure. The method may include determining a successful final outcome based at least in part on verifying that the received name and password of the local area network correspond to an expected name and expected password for the local area network, respectively.
[0159] The method may include accessing a predetermined portion of a memory of the network device used to store a local area network (LAN) name and password after completion of the data erasure procedure. The method may include verifying that the local area network (LAN) name and password stored in the predetermined portion of the memory of the network device used to store the local area network (LAN) name and password correspond to an expected local area network (LAN) name and expected password, respectively, after completion of the data erasure procedure.
[0160] The method may include requesting network device information from the network device.
[0161] The method may include receiving network device information from the network device in response to the request for network device information.
[0162] The method may include selecting a data erasure procedure from a database of data erasure procedures based at least in part on the received network device information.
[0163] The method may include selecting, based at least in part on the received network device information, a predicted response from a database of predicted responses that indicates a successful erasure of the memory of the network device.
[0164] The method may include accessing network device information stored in a memory of the network device.
[0165] The method may include selecting a data erasure procedure from a database of data erasure procedures based at least in part on the accessed network device information.
[0166] The method may include selecting, based at least in part on the accessed network device information, from a database of predicted contents, predicted contents of the memory of the network device that indicate a successful erasure of the memory of the network device.
[0167] The network device information may include at least one of the following: the manufacturer of the network device, the model number, and / or operating system details of the network device, such as the type and / or version of the operating system of the network device.
[0168] At least one of the database of data purging procedures, the database of expected responses, and the database of expected content includes a profiler API.
[0169] The method may include requesting initial data from a memory of the network device before initiating the data erasure procedure.
[0170] The method may include receiving an initial response from the network device in response to the request for the initial data.
[0171] The method may include determining a final outcome of the data erasure procedure based at least in part on a comparison of an initial response received from the network device in response to the request for initial data and the response received from the network device.
[0172] The method may include accessing a memory of the network device before initiating the data erasure procedure.
[0173] The method may include determining a final result of the data erasure procedure based at least in part on a comparison of any initial contents of the network device's memory before the data erasure procedure is initiated and any contents of the network device's memory after the data erasure procedure is completed.
[0174] The method may include determining a final outcome of the data erasure procedure that is successful based at least in part on verifying that all IP addresses and / or all MAC addresses have been cleared from the routing table of the network device.
[0175] A network device may include a device having memory and configured to interconnect or enable the interconnection of two or more computing resources.
[0176] The network device may include at least one of a router, a switch, a modem, a gateway, a firewall, a media converter, and a repeater.
[0177] The network device may include a router with a serial port.
[0178] The network device may have an Ethernet port for communication with a wide area network (WAN).
[0179] The method may include establishing a connection with the network device via the Ethernet port according to a WAN management protocol.
[0180] The WAN management protocol may include the TR-069 CPE WAN management protocol.
[0181] It should be understood that any one or more of the features of any one of the above aspects of the present disclosure may be combined with any one or more of the features of any of the other above aspects of the present disclosure.
[0182] A system and method for use in erasing data stored in the memory of a network device will now be described, by way of non-limiting example only, with reference to the accompanying drawings, in which: [Brief explanation of the drawings]
[0183] [Figure 1] FIG. 1 is a schematic diagram of a general-purpose router and a general-purpose system used to erase data stored in the memory of the general-purpose router. [Figure 2A] FIG. 2A is a rear view of an industrial router with one or more Ethernet ports and an additional serial port. [Figure 2B] FIG. 2B is a front view of the industrial router of FIG. 2A. [Figure 3] Figure 3 shows a router that includes remote management support compliant with the TR-069 CPE WAN Management protocol. [Figure 4] FIG. 4 is a flowchart of a method used in erasing data stored in the memory of the industrial router of FIG. [Figure 5A] FIG. 5A shows a response to a request for routing table data from the industrial router of FIG. 2 after a data cleaning procedure has been successfully performed. [Figure 5B] FIG. 5B shows a response to a request for routing table data from the industrial router of FIG. 2 after the data cleaning procedure has failed. [Figure 6A] FIG. 6A shows a response to a request for configuration data from the industrial router of FIG. 2 after a data wiping procedure has been successfully performed. [Figure 6B] FIG. 6B shows a response to a request for configuration data from the industrial router of FIG. 2 after an unsuccessful execution of the data wiping procedure. [Figure 7A] FIG. 7A shows a response to a request for a list of user-created files stored in the memory of the industrial router of FIG. 2 after a data wiping procedure has been successfully performed. [Figure 7B] FIG. 7B shows a response to a request for a list of user-created files stored in the memory of the industrial router of FIG. 2 after a failed execution of a data wiping procedure. [Figure 8A] FIG. 8A shows the response to a request for a list of IP and MAC addresses stored in the memory of the router of FIG. 3, as seen in the router's native user interface, after the data wiping procedure has been successfully performed. [Figure 8B] FIG. 8B shows the response to a request for a list of IP and MAC addresses stored in the memory of the router of FIG. 3, as seen by the automatic configuration server (ACS) software, after the data wiping procedure has failed. [Figure 8C] FIG. 8C shows the response to a request for a list of IP and MAC addresses stored in the memory of the router of FIG. 3, as seen by the automatic configuration server (ACS) software, after the data wiping procedure has been successfully performed. DETAILED DESCRIPTION OF THE INVENTION
[0184] 1 , there is shown a network device in the form of a general-purpose router 2 and a general-purpose system, generally designated 10, for use in erasing data stored in the memory of the general-purpose router 2. The system 10 includes a computing resource in the form of a host computer 12 and a remote database 14. The host computer 12 includes a memory 16 and processing resources 20. The memory 16 stores a computer program 18. The host computer 12 is configured to communicate with the router 2, the database 14, and the cloud 30, as indicated by the arrows.
[0185] The remote database 14 stores a lookup table containing router information such as the manufacturer, model number, and / or operating system details of the router 2, such as the operating system type and / or version of the router 2. The lookup table also stores, in association with the router information, one or more appropriate data wiping procedures and one or more expected or default router responses indicating that the memory of the router 2 has been successfully wiped.
[0186] As described in more detail below, computer program 18, when executed by processing resource 20, causes host computer 12 to perform a generic method for erasing data stored in the memory of router 2, initiated when host computer 12 requests router information from router 2. In response to the request for router information, host computer 12 receives router information from router 2. Host computer 12 then selects, based at least in part on the received router information, an appropriate data erasure procedure for erasing the data stored in the memory of router 2 from a lookup table stored in remote database 14. Furthermore, host computer 12 uses the received router information to select, based at least in part on the received router information, an expected or default response from the lookup table stored in remote database 14 indicating successful erasure of the memory of router 2.
[0187] The host computer 12 then triggers, initiates, or executes the selected data erasure procedure to erase the stored data from the memory of the router 2. After completion of the data erasure procedure, the host computer 12 requests the data from the memory of the router 2 and receives a response from the router 2 in response to the data request. The host computer 12 determines a final outcome of the data erasure procedure based, at least in part, on a comparison of the received response from the router 2 with an expected or default response indicating successful erasure of the memory of the router 2. The host computer 12 then records or stores the determined final outcome of the data erasure procedure, for example, on the host computer 12 and / or the cloud 30. Additionally or alternatively, the host computer 12 records or stores the received response on the host computer 12 and / or the cloud 30. Storing the determined final outcome of the data erasure procedure and / or the received response may provide an audit trail, for example, to enable a third party to verify the successful erasure of the router 2 at a later date, if desired.
[0188] 2A and 2B, there is shown an industrial router generally designated 102 that includes one or more Ethernet ports and an additional serial port, such as a 9-pin or 25-pin serial port. The router 102 typically uses a vendor-specific serial protocol and command set. A method generally designated 150 for use in erasing data stored in the memory of the router 102 will now be described with reference to FIG. 4. Method 150 is based on the generic method used in erasing data stored in the memory of the generic router 2 described with reference to FIG. 1 and is performed using a system having a generic form similar to the generic system 10 of FIG. 1, except that the host computer 12 takes the form of a Windows® host and the database 14 takes the form of a Profiler API.
[0189] The method 150 begins in step 152 when one or more routers 102 are connected to a Windows host using one or more serial cables.
[0190] In step 154, the user logs into the router 102 via the Windows host and establishes a connection between the router 102 and the Windows host via the serial port.
[0191] In step 156, the processing resource 20 executes the software 18 to cause the Windows host to obtain router information from the router 102, including the manufacturer, model number, operating system type, operating system version, and serial number of the router 102.
[0192] In step 158, the Windows host uses the obtained router information to obtain the appropriate cleaning procedure from the profiler API. At the same time, the Windows host uses the obtained router information to obtain an expected or default response from the profiler API indicating successful cleaning of the router 102's memory.
[0193] In step 160, the retrieved erase procedure is initiated or executed to erase data from the memory of the router 102. For example, the Windows® host may send a trigger command to the router 102 via the serial port to cause the router 102 to initiate an internal, built-in, default, factory, and / or native data erase procedure associated with or stored in the router 102, e.g., to erase data, such as data files and configuration files, from the file system of the router 102, or to cause the router 102 to initiate a reset procedure or erase function associated with or stored in the router 102.
[0194] In step 162, the router 102 is rebooted and the user logs back into the router 102 using the router's 102 default username and password, or, if necessary, by resetting the router's 102 username and / or password.
[0195] In step 164, the Windows® host performs a verification procedure to determine whether the erasure procedure was successfully performed in step 160. Specifically, after the data erasure procedure is completed, the Windows® host requests data from the memory of the router 102. The Windows® host receives a response from the router 102 in response to the request for data, and then determines the final outcome of the data erasure procedure based at least in part on a comparison of the response received from the router 102 with a previously obtained, expected, or default response indicating that the erasure of the memory of the router 102 was successful.
[0196] For example, as described below with reference to FIGS. 5A and 5B, the Windows® host checks whether the network IP addresses have been cleared from the contents of the routing table of the router 102. In the case of a Cisco router, this may be done using a "Show ip arp" command. Specifically, the Windows® host sends the "Show ip arp" command to the router 102 via a serial port to request the routing table data from the memory of the router 102 via the serial port. If the data has been successfully cleared from the memory of the router 102 in step 160, the router 102 indicates that the data has been successfully cleared from the memory of the router 102 in step 160 by not returning an IP address to the Windows® host in response to the "Show ip arp" command shown in FIG. 5A, but by indicating that the routing table is empty or that there are no IP addresses assigned to the router 102. However, if erasing the data from the memory of the router 102 fails in step 160, the router 102 may, in response to the "Show ip arp" command, return to the Windows® host a list of one or more IP addresses that were stored in the memory of the router 102 before performing the erasing procedure. For example, as shown in FIG. 5B, in response to the "Show ip arp" command, the router 102 may return the IP address "10.1.169.12" to the Windows® host, indicating that erasing the data from the memory of the router 102 failed in step 160.
[0197] Additionally or alternatively, in step 164, the Windows® host verifies the erase result by checking the running configuration of the router 102, as described below with reference to Figures 6A and 6B. In the case of a Cisco router, this may be done using a "Show startup-config" command. Specifically, the Windows® host sends a "Show startup-config" command to the router 102 via the serial port, requesting configuration data from the router 102 via the serial port. If the data was successfully erased from the memory of the router 102 in step 160, the router 102 responds to the "Show startup-config" command by sending "9 bytes used out of 524284 bytes, decompressed size = 5 bytes, done" 6A to the Windows® host, indicating that the data was successfully erased from the memory of the router 102 in step 160. However, if the data was not successfully erased from the memory of the router 102 in step 160, the router 102 may return the startup configuration data of the router 102 to the Windows® host in response to the "Show startup-config" command, as shown in the example of FIG. 6B.
[0198] In step 164, additionally or alternatively, the Windows host verifies the erasure result by checking whether the file exists in the memory of the router 102. In the case of a Cisco router, this may be done using a "dir nvram" command. Specifically, the Windows host sends a "dir nvram" command to the router 102 via a serial port to request a list of files stored in the memory of the router 102 via the serial port. If the erasure of data from the memory of the router 102 is successful in step 160, the router 102 may indicate that the erasure of data from the memory of the router 102 was successful in step 160 by returning file information such as that shown in the example of FIG. 7A to the Windows host in response to the "dir nvram" command. However, if the erasure of data from the memory of the router 102 fails in step 160, the router 102 may return file information such as that shown in the example of FIG. 7B to the Windows host in response to the "dir nvram" command.
[0199] The method 150 used in erasing data stored in the memory of the router 102 concludes in step 166 with the Windows host storing and / or uploading a verification report to the cloud to provide an audit trail that allows, for example, a third party to verify at a later date, if desired, that the erasure of the router 102 was successful. The verification report may include the final results of the verification step 164. The verification report may include one or more of the responses returned from the router 102 to the Windows host in response to one or more of the following commands: "Show ip arp," "Show startup-config," and "dir nvram."
[0200] 4, in step 160, rather than sending a trigger command to the router 102 via the serial port to cause the router 102 to initiate an internal, built-in, default, factory, and / or native data wipe procedure associated with or stored in the router 10, the Windows® host may trigger a firmware update for the router 102. Specifically, the Windows® host may send a trigger command to the router 102 via the serial port to provide the router 102 with an image file and cause the router 102 to use the image file to overwrite the existing firmware of the router 102.
[0201] From the above description of steps 160 and 164 of method 150, one skilled in the art will understand that successful execution of the erase procedure will result in all accessible data being erased from router 102, including erasing all IP addresses stored in router 102's memory for any network devices connected to router 102, erasing all user-defined startup configuration data stored in router 102's memory, and erasing all user-defined file information stored in router 102's memory.
[0202] Referring now to FIG. 3, a router generally designated 202 is shown including at least one Ethernet port allocated for communication with a wide area network (WAN) in accordance with a WAN management protocol in the form of the TR-069 CPE WAN Management Protocol. A method used to erase data stored in the memory of router 202 will now be described. The method used to erase data stored in the memory of router 202 is based on the generic method used to erase data stored in the memory of generic router 2 described above with reference to FIG. 1 and is performed using a system having the same general form as generic system 10 of FIG. 1, but in this case it should be understood that host computer 12 establishes a connection with router 202 via the WAN port of router 202. Specifically, host computer 12 provides Dynamic Host Configuration Protocol (DHCP) and Autoconfiguration Server (ACS) services in accordance with the TR-069 CPE WAN Management Protocol, and router 202 sends DHCP discover messages to host computer 12. The DHCP service assigns an IP address to router 202. The router 202 initiates a connection with the ACS service, and the router 202 sends router information or details to the ACS service.
[0203] When the host computer 12 and the router 202 establish a connection, the host computer 12 executes a computer program 18 that causes the host computer 12 to perform a method used in erasing data stored in the memory of the router 202, which begins when the host computer accesses router information stored in the memory of the router 202. The host computer 12 then selects an appropriate data erasure procedure from a lookup table stored in the remote database 14 based at least in part on the accessed router information. Additionally, the host computer 12 uses the accessed router information to select, based at least in part on the accessed router information, from the lookup table stored in the remote database 14, predicted or default contents of the memory of the router 202 that indicate a successful erasure of the memory of the router 202.
[0204] In one example, the host computer 12 selects a factory reset remote procedure call (RPC) data erase procedure, and the ACS service sends a factory reset remote procedure call (RPC) message to the router 202, triggering the router 202 to perform a factory reset procedure, thereby resetting the router 202 to a factory default state and erasing data stored in the memory of the router 202.
[0205] After performing the factory reset procedure, the host computer 12 logs into the router 202 using the default username and password, for example, "admin" and "1234."
[0206] After a successful login or reconnection between the host computer 12 and the router 202 via the ACS, the host computer 12 performs a verification procedure to confirm whether the erasure procedure was successful. Specifically, the host computer 12 accesses the memory of the router 202 after the data erasure procedure is completed. The host computer 12 determines the final result of the data erasure procedure based at least in part on a comparison result between any contents of the memory of the router 202 and expected contents indicating successful erasure of data in the memory of the router 202. For example, the host computer 12 determines whether the data erasure procedure was successful based at least in part on whether the memory of the router 202 contains an IP address and / or a MAC address. If the memory of the router 202 does not contain an IP address and / or a MAC address, the host computer 12 determines that the data erasure procedure was successful; otherwise, the host computer 12 determines that the data erasure procedure failed.
[0207] Additionally or alternatively, the host computer 12 may access local area network (LAN) name and password data from the router 202 after the data erasure procedure is complete. The host computer 12 then determines the final result of the data erasure procedure based, at least in part, on a comparison of the accessed local area network (LAN) name and password with an expected local area network (LAN) name and password that indicates successful erasure of the router 202's memory. If the accessed local area network (LAN) name and password correspond to the expected or default local area network (LAN) name and password, the host computer 12 determines that the data erasure procedure was successful; otherwise, the host computer 12 determines that the data erasure procedure failed. For example, FIGS. 8A through 8C illustrate verification procedures that may be used to verify whether a factory reset procedure was successfully performed. The screenshot in FIG. 8A shows the router 202's administration panel (i.e., the router 202's native user interface) after a successful factory reset procedure. Specifically, FIG. 8A shows the "Wireless Networks" tab, which allows a user to enable or disable the 2.4 GHz and 5 GHz wireless networks and change their names (SSIDs). After performing the factory reset procedure, the names of the 2.4 GHz and 5 GHz wireless networks revert to the default name "FRITZ!Box 4040 TI," indicating that the factory reset procedure was successful and the memory of the router 202 was successfully erased. Similarly, on the "Security" tab (not shown), a user may change the passwords for the wireless networks. After performing the factory reset procedure, the passwords for the wireless networks revert to the default passwords, indicating that the factory reset procedure was successful and the memory of the router 202 was successfully erased.
[0208] Similarly, FIG. 8B shows the wireless network names (SSIDs) accessed by the automatic configuration server (ACS) before a factory reset procedure was performed. Here, the 2.4 GHz network and the 5 GHz network were renamed by the user to "ChangeMe_2.4GHz" and "ChangeMe_5GHz," respectively. FIG. 8C shows the 2.4 GHz wireless network name (SSID) after a factory reset procedure was performed by the ACS. Here, the network name has been reset back to the default name, indicating that the factory reset procedure was successfully performed and the memory of the router 202 was successfully erased. Similarly, the wireless network password (not shown) has been reset back to the default password, indicating that the factory reset procedure was successfully performed and the memory of the router 202 was successfully erased.
[0209] The method used to erase data stored in the memory of the router 202 concludes with the host computer 12 storing and / or uploading a verification report to the cloud 30 to provide an audit trail that allows, for example, a third party to verify at a later date, if desired, that the erasure of the router 202 was successful. The verification report may include the final results of the verification step. The verification report may include a list of any IP addresses and MAC addresses stored in the router 202. The verification report may also include the name and password of any local area network (LAN) that was accessed.
[0210] In a variation of the method used to erase data stored in the memory of router 202 described above, host computer 12 may trigger, initiate, or perform a firmware update for router 202. For example, the ACS service may send a "schedule download" or "download" message to cause router 202 to download a firmware update from a specified location and apply the firmware update to overwrite the existing firmware of router 202. It should be understood that the "schedule download" or "download" message is a baseline message that must be implemented in accordance with the TR-069 CPE WAN management protocol.
[0211] From the above description of the method used to erase data stored in the memory of router 202 with reference to Figures 8A-8C, one skilled in the art will understand that successful execution of the erasure procedure will erase all data accessible from router 202, including erasing all IP addresses and all MAC addresses stored in the memory of router 202, and erasing all local area network (LAN) names and passwords stored in the memory of router 202.
[0212] Those skilled in the art will appreciate that various variations are possible with respect to the methods used to erase data stored in the memory of a router described above with reference to Figures 1 through 8C. For example, although the methods are described in terms of routers 2, 102, and 202, the methods may be performed in connection with any network device having memory and configured to interconnect or enable the interconnection of two or more computing resources. For example, the methods may be performed in connection with at least one of a router, a switch, a modem, a gateway, a firewall, a media converter, and a repeater.
[0213] Any of the above methods requesting initial data from the memory of the network device before initiating the data erasure procedure; receiving an initial response from the network device in response to the request for initial data; and determining a final outcome of the data erasure procedure based at least in part on a comparison of the initial response received from the network device and the response received from the network device.
[0214] Any of the above methods accessing the memory of the network device before initiating the data erasure procedure; and determining a final result of the data erasure procedure based at least in part on a comparison of any initial contents of the network device's memory before the data erasure procedure is initiated and any contents of the network device's memory after the data erasure procedure is completed.
[0215] The data stored in the memory of the network device may include one or more IP addresses.
[0216] The data stored in the memory of the network device may include one or more MAC addresses.
[0217] The data stored in the memory of the network device may include one or more usernames and / or one or more passwords.
[0218] The data stored in the memory of the network device may include configuration data such as IP configuration data and / or boot setting data.
[0219] Data stored in the memory of the network device may be stored in one or more data files and / or one or more configuration files within a file system in the memory of the network device.
[0220] The data wiping procedure may be configured to erase all accessible data stored in the memory of the network device.
[0221] Performing a data wiping procedure may include clearing data stored in a memory of the network device.
[0222] Performing a data erasure procedure may include replacing data stored in the memory of the network device.
[0223] Performing a data erasure procedure may include changing the key used to encrypt data stored in the memory of the network device.
[0224] Performing a data erasure procedure may include clear-level sanitization as defined by NIST SP 800-88 (Revision 1).
[0225] Performing a data erasure procedure may include executing an internal, built-in, default, factory, and / or native data erasure procedure associated with or stored in the network device, for example, executing a reset procedure or erase function associated with or stored in the network device.
[0226] Performing a data wiping procedure may include manually clearing data stored in the memory of the network device.
[0227] Performing a data wiping procedure may include clearing data stored in memory of the network device using computing resources and / or a user interface.
[0228] Data erasure procedures may include purge-level sanitization as defined by NIST SP 800-88 (Revision 1).
[0229] Performing a data wiping procedure may include updating and / or replacing software and / or firmware on the network device.
[0230] Those skilled in the art will appreciate that one or more of the features of the systems or methods described above with reference to the drawings may produce effects or provide advantages when used separately from one or more of the features of the systems or methods described above, and that different combinations of features are possible other than the specific combinations of features of the systems or methods described above.
Claims
1. 1. A method for use in erasing data stored in a memory of a network device, the network device having a memory and configured to interconnect or enable the interconnection of two or more computing resources, the method comprising: a host computer communicatively coupled to the network device performing a data erasure procedure to erase stored data from the memory of the network device; the host computer requesting data from the memory of the network device after the data erasure procedure is completed, or the host computer accessing the memory of the network device after the data erasure procedure is completed; a comparison of a response received from the network device in response to the request for data with an expected response indicating successful erasure of the memory of the network device; or a comparison of any contents of the memory of the network device after completion of the data erasure procedure with the expected contents of the memory of the network device after completion of the data erasure procedure, the comparison indicating successful erasure of the memory of the network device; determining, by the host computer, an end result of the data erasure procedure based at least in part on the the host computer recording or storing in a cloud at least one of the received response, any contents of the memory of the network device, and the determined final result of the data erasure procedure; Including, Determining the final result of the data erasure procedure comprises determining the final result of the data erasure procedure as successful if the response received from the network device is the same as the expected response, or determining the final result of the data erasure procedure as unsuccessful if the response received from the network device is different from the expected response; or determining the final result of the data erasure procedure includes determining that the final result of the data erasure procedure is successful if the contents of the memory of the network device are the same as the predicted contents, and determining that the final result of the data erasure procedure is unsuccessful if the contents of the memory of the network device are different from the predicted contents.
2. 10. The method of claim 1, wherein the predicted response comprises a default response, or the predicted contents of the memory of the network device comprise default contents.
3. In the method according to claim 1 or 2, after completion of the data erasure procedure, the host computer requests IP address data and / or MAC address data from the memory of the network device, or after completion of the data erasure procedure, the host computer accesses a predetermined portion of the memory of the network device used to store IP address data and / or MAC address data; After completing the data erasure procedure, the host computer verifies that the response received from the network device does not include IP address data and / or MAC address data; or after completing the data erasure procedure, the host computer verifying that the predetermined portion of the memory of the network device used to store IP address data and / or MAC address data does not contain IP address data and / or MAC address data; and wherein the host computer determines a successful final result based at least in part on the
4. In the method according to any one of claims 1 to 3, after completion of the data erasure procedure, the host computer requests running configuration data from the memory of the network device, or after completion of the data erasure procedure, the host computer accesses a predetermined portion of the memory of the network device used to store running configuration data; the host computer verifying that a response received from the network device corresponds to an expected running configuration indicating that the memory of the network device was successfully erased; or verifying by the host computer that the predetermined portion of the memory of the network device used to store running configuration data contains running configuration data corresponding to an expected running configuration indicating that the erasure of the memory of the network device was successful; The method of claim 1, wherein the host computer determines a successful final result based at least in part on the
5. The method according to any one of claims 1 to 4, after completion of the data erasure procedure, the host computer requests a local area network (LAN) name and password from the memory of the network device, or after completion of the data erasure procedure, the host computer accesses a predetermined portion of the memory of the network device used to store a local area network (LAN) name and password; the host computer verifying that the received local area network (LAN) username and password correspond to an expected local area network (LAN) username and expected password, respectively; or and after completing the data erasure procedure, verifying by the host computer that the local area network (LAN) name and password stored in the predetermined portion of the memory of the network device used to store the local area network (LAN) name and password correspond to the expected local area network (LAN) name and expected password, respectively; The method of claim 1, wherein the host computer determines a successful final result based at least in part on the
6. The method according to any one of claims 1 to 5, the host computer requesting network device information from the network device or the host computer accessing network device information stored in the memory of the network device; the host computer selecting the data erasure procedure from a database of data erasure procedures based at least in part on network device information received from the network device in response to the request for network device information, or the host computer selecting the data erasure procedure from a database of data erasure procedures based at least in part on the accessed network device information; and based at least in part on the received network device information, the host computer selecting from a database of expected responses the predicted response indicating successful erasure of the memory of the network device, or based at least in part on the accessed network device information, the host computer selecting from a database of expected contents the predicted content of the memory of the network device indicating successful erasure of the memory of the network device.
7. 7. The method of claim 6, wherein the network device information includes at least one of the manufacturer, model number, and / or operating system type and / or version of the network device.
8. 8. The method of claim 6 or 7, wherein at least one of the database of data erasure procedures, the database of expected responses, and the database of expected contents includes a profiler API.
9. The method according to claim 1, wherein accessing the memory of the network device by the host computer before initiating the data erasure procedure; determining, by the host computer, a final result of the data erasure procedure based at least in part on a comparison of any initial contents of the memory of the network device before the data erasure procedure begins and any contents of the memory of the network device after the data erasure procedure is completed; Including, The method of determining the final result of the data erasure procedure includes determining that the final result of the data erasure procedure is successful if the contents of the memory of the network device after completion of the data erasure procedure are the same as the initial contents, and determining that the final result of the data erasure procedure is unsuccessful if the contents of the memory of the network device after completion of the data erasure procedure are different from the initial contents.
10. 10. The method of claim 9, including the host computer determining that the end result of the data erasure procedure is successful based at least in part on verifying that all IP addresses and / or all MAC addresses have been cleared from the routing table of the network device.
11. The method according to claim 1, wherein the stored data is: one or more IP addresses, one or more MAC addresses, one or more usernames, one or more passwords, The name of the local area network (LAN), Local Area Network (LAN) password, IP config data, and startup configuration data.
12. A method according to any one of claims 1 to 11, wherein the stored data is stored in one or more data files and / or one or more configuration files within a file system in the memory of the network device.
13. A method as claimed in any one of claims 1 to 12, wherein the data erasure procedure is configured to erase all accessible data stored in the memory of the network device.
14. The method according to any one of claims 1 to 13, The data erasure procedure is performed by: clearing data stored in the memory of the network device; replacing data stored in the memory of the network device; changing a key used to encrypt data stored in the memory of the network device; executing an internal, built-in, default, factory, and / or native data erasure procedure associated with or stored on said network device; clearing data stored in the memory of the network device using a computing resource and / or a user interface; updating and / or replacing software and / or firmware of said network device; The method includes at least one of the following:
15. The method of claim 1, wherein the data erasure procedure includes clear-level sanitization as defined by NIST SP 800-88 (Revision 1) or purge-level sanitization as defined by NIST SP 800-88 (Revision 1).
16. A method according to any one of claims 1 to 15, wherein the network device comprises at least one of a router, a switch, a modem, a gateway, a firewall, a media converter, and a repeater.
17. A method according to any one of claims 1 to 16, wherein the network device comprises a router having a serial port, and the method includes logging in to the router by sending a username and password to the router via the serial port.
18. The method of claim 17, further comprising the host computer sending a trigger command to the router via the serial port to cause the router to initiate an internal, built-in, default, factory-installed and / or native data erasure procedure associated with or stored in the router.
19. 19. The method of claim 17 or 18, after completing the data erasure procedure, the host computer logs into the router via the serial port; the host computer requesting the data from the memory of the router via the serial port; receiving, by the host computer, a response from the router via the serial port in response to the request for data; Logging into the router via the serial port after the data erasure procedure is completed includes: The host computer uses a default username and password to log in to the router; or the host computer resetting the username and the password.
20. 17. The method of any one of claims 1 to 16, wherein the network device has an Ethernet port for communication with a wide area network (WAN), the method including the host computer establishing a connection with the network device via the Ethernet port in accordance with a WAN management protocol.
21. 21. The method of claim 20, further comprising the host computer sending a factory reset remote procedure call (RPC) message to the network device to reset the network device to a factory default state and erase the memory of the network device, and / or the host computer sending a schedule download or download message to the network device to cause the network device to download a firmware update from a specified location and apply the firmware update to overwrite the existing firmware of the network device.
22. 1. A method for use in erasing data stored in a memory of a network device, comprising: erasing all accessible data stored in the memory of said network device; The method further comprises: a host computer communicatively coupled to the network device requesting data from the memory of the network device after the data erasure procedure is completed, or the host computer accessing the memory of the network device after the data erasure procedure is completed; a comparison of a response received from the network device in response to the request for data with an expected response indicating successful erasure of the memory of the network device; or a comparison of any contents of the memory of the network device after completion of the data erasure procedure with the expected contents of the memory of the network device after completion of the data erasure procedure, the comparison indicating successful erasure of the memory of the network device; determining, by the host computer, an end result of the data erasure procedure based at least in part on the the host computer recording or storing in a cloud at least one of the received response, any contents of the memory of the network device, and the determined final result of the data erasure procedure; Including, Determining the final result of the data erasure procedure comprises determining the final result of the data erasure procedure as successful if the response received from the network device is the same as the expected response, or determining the final result of the data erasure procedure as unsuccessful if the response received from the network device is different from the expected response; or determining the final result of the data erasure procedure includes determining that the final result of the data erasure procedure is successful if the contents of the memory of the network device are the same as the predicted contents, and determining that the final result of the data erasure procedure is unsuccessful if the contents of the memory of the network device are different from the predicted contents.
Citation Information
Patent Citations
Initialization system and initialization method
JP2007124429A
Data erasing method, data erasing program, computer with data erasing program and data erasing management server
JP2018139025A
Method and system for verifying data deletion processes
JP2020509467A
Data erasing device, data erasing method, program, and storage medium
WO2014167721A1