Information Processing Systems

The information processing system facilitates secure and efficient data erasure in electronic devices by using a client-server configuration to confirm erasure preparations, addressing the need for hardware changes and ensuring complete data deletion.

JP7762897B2Active Publication Date: 2025-10-31PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2024576130
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2023-02-06
Filing Date
2023-11-28
Publication Date
2025-10-31
Estimated Expiration
2043-11-28

AI Technical Summary

Technical Problem

Existing methods for erasing data from electronic devices in organizations require significant hardware and software changes and lack the ability to confirm data erasure preparations are complete before execution.

Method used

An information processing system comprising a client device and a server device connected via a communication line, where the client device includes a storage device for data and a control circuit that executes a firmware program to erase data upon receiving a command from the server, which acquires erasure permission information to ensure data is erased only when preparations are complete.

Benefits of technology

Enables reliable and easy data erasure without major design changes, allowing confirmation of erasure preparations and ensuring secure, cost-effective data deletion without physical transport of devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007762897000001
    Figure 0007762897000001
  • Figure 0007762897000002
    Figure 0007762897000002
  • Figure 0007762897000003
    Figure 0007762897000003
Patent Text Reader

Abstract

In the present invention, a storage device (13) of a client device (1) stores an OS, an application program, and data including user data. A storage device (15) stores a firmware program. A control circuit (14) of the client device (1) controls the storage device (13) and a communication device (16) by executing the firmware program. The control circuit (14) of the client device (1) erases data stored in the storage device (13) if an erase command is received from a server device (2) during the execution of the firmware program. A CPU (21) of the server device (2) acquires erase permission information indicating whether to permit the erasure of the data stored in the storage device (13), and transmits the erase command to the client device (1) if the erase permission information indicates that erasure is permitted.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to an information processing device, an information processing system, and an information processing method. [Background technology]

[0002] 2. Description of the Related Art When an organization such as a company disposes of an electronic device such as a personal computer, it is required to erase the data stored in the storage device in order to prevent confidential business information from being leaked.

[0003] Patent Document 1 discloses a method for erasing data from a recording medium, such as a hard disk attached to a personal computer. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Patent No. 6923311 Summary of the Invention [Problem to be solved by the invention]

[0005] When an organization manages a large number of electronic devices, it is required to erase data stored in the storage devices of the electronic devices without making any errors, and it is also required to easily achieve such data erasure without requiring major design changes to the hardware and / or software of the existing electronic devices.

[0006] The present disclosure provides an information processing device, an information processing system, and an information processing method that can reliably and easily erase data stored in a storage device of an electronic device. [Means for solving the problem]

[0007] An information processing device according to one aspect of the present disclosure includes: An information processing device connected to at least one electronic device via a communication line, The electronic device is a first storage device for storing data including an operating system, application programs, and user data; a second storage device that stores a firmware program; a first communication device connected to the information processing device via the communication line; a first control circuit that controls the first storage device and the first communication device by executing the firmware program, and that erases data stored in the first storage device when an erase command is received from the information processing device during execution of the firmware program; The information processing device includes: a second communication device connected to the electronic device via the communication line; and a second control circuit that acquires erasure permission information indicating whether erasure of data stored in the first storage device is permitted, and sends the erasure command to the electronic device if the erasure permission information indicates that erasure of the data is permitted. [Effects of the Invention]

[0008] According to an information processing device according to an aspect of the present disclosure, data stored in a storage device of an electronic device can be reliably and easily erased. [Brief explanation of the drawings]

[0009] [Figure 1] 1 is a schematic diagram showing a configuration of an information processing system 100 according to a first embodiment. [Figure 2] 2 is a block diagram showing the configuration of a client device 1 in FIG. 1. FIG. [Figure 3] 2 is a block diagram showing the configuration of a server device 2 in FIG. 1. FIG. [Figure 4] FIG. 2 is a block diagram showing the configuration of terminal devices 3 and 4 in FIG. [Figure 5] FIG. 10 is a sequence diagram showing an erasure process according to a comparative example. [Figure 6] FIG. 4 is a sequence diagram showing an erasure process according to the first embodiment. [Figure 7] FIG. 10 is a sequence diagram showing an erasure process according to a first modified example of the first embodiment. [Figure 8] FIG. 10 is a sequence diagram showing an erasure process according to a second modified example of the first embodiment. [Figure 9] FIG. 10 is a sequence diagram showing an erasure process according to the second embodiment. [Figure 10] FIG. 10 is a sequence diagram showing an erasure process according to a first modified example of the second embodiment. [Figure 11] FIG. 10 is a sequence diagram showing an erasure process according to a second modified example of the second embodiment. [Figure 12] FIG. 11 is a sequence diagram showing an erasure process according to the third embodiment. [Figure 13] FIG. 13 is a sequence diagram showing an erasure process according to a first modified example of the third embodiment. [Figure 14] FIG. 13 is a sequence diagram showing an erasure process according to a second modified example of the third embodiment. [Figure 15] FIG. 13 is a sequence diagram showing an erasure process according to the fourth embodiment. [Figure 16] FIG. 13 is a sequence diagram showing an erasure process according to a first modified example of the fourth embodiment. [Figure 17] FIG. 13 is a sequence diagram showing an erasure process according to a second modified example of the fourth embodiment. [Figure 18] FIG. 13 is a sequence diagram showing an erasure process according to a third modified example of the fourth embodiment. [Figure 19] 1 is a table comparing the first to fourth embodiments. DETAILED DESCRIPTION OF THE INVENTION

[0010] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. However, more detailed description than necessary may be omitted. For example, detailed description of well-known matters or redundant description of substantially identical configurations may be omitted. This is to avoid unnecessary redundancy in the following description and to facilitate understanding by those skilled in the art.

[0011] The inventor(s) provide the accompanying drawings and the following description to enable those skilled in the art to fully understand the present disclosure, and do not intend for them to limit the subject matter described in the claims.

[0012] [First embodiment] [Configuration of the first embodiment]

[0013] 1 is a schematic diagram showing the configuration of an information processing system 100 according to the first embodiment. The information processing system 100 in FIG. 1 includes a plurality of client devices 1-1 to 1-3, a server device 2, one or more terminal devices 3 and 4, and a communication line 5.

[0014] The client devices 1-1 to 1-3 are communicably connected to the server device 2 via a communication line 5. The client devices 1-1 to 1-3 are electronic devices equipped with a storage device (described later), such as a personal computer or a mobile phone. The client devices 1-1 to 1-3 are examples of electronic devices according to an embodiment.

[0015] In this specification, the client devices 1-1 to 1-3 are also collectively referred to as "client device 1."

[0016] The server device 2 manages the erasure of data stored in the storage device of each client device 1. The server device 2 is an example of an information processing device according to the embodiment.

[0017] The terminal devices 3 and 4 are communicatively connected to the server device 2 via a communication line 5. Administrators A and B of each client device 1 access the server device 2 using the terminal devices 3 and 4, respectively, and specify the storage device from which stored data should be erased. Administrators A and B may have the same or different authority regarding data erasure. For example, administrator B may have stronger authority than administrator A, such as administrator A's boss. The server device 2 distinguishes administrators A and B from each other using identification information previously assigned to administrators A and B, such as a login ID for the server device 2.

[0018] The communication line 5 is, for example, a local area network (LAN), the Internet, or a combination thereof.

[0019] For example, each client device 1 and terminal devices 3 and 4 may be owned by an organization such as a company, while the server device 2 may be operated by a third party different from this organization. In this case, the organization that owns each client device 1 and terminal devices 3 and 4 enters into a contract with the operator of the server device 2 to manage the erasure of data stored in the storage device of each client device 1, and becomes a customer of this operator.

[0020] In this specification, "erasing" means making all or most of the original data stored unreadable, for example, by overwriting it with other data such as "0", "1", or random values. Also, if the storage device 13 has a self-encryption function, "erasing" may mean changing the encryption key (cryptographic erasure).

[0021] FIG. 2 is a block diagram showing the configuration of the client device 1 in FIG. 1. The client device 1 includes a bus 10, a central processing unit (CPU) 11, a random access memory (RAM) 12, a storage device 13, a control circuit 14, a storage device 15, a communication device 16, an input device 17, and a display device 18. The CPU 11 controls the overall operation of the client device 1 by executing an operating system (OS) and multiple application programs (APPs) stored in the storage device 13. The CPU 11 is an example of a control circuit, processing circuit, or signal processor. The RAM 12 temporarily stores programs and data necessary for the operation of the client device 1. The storage device 13 stores data including the operating system (OS), multiple application programs (APPs), and user data. The storage device 13 is a non-volatile storage medium such as a hard disk drive (HDD) or a solid-state drive (SSD). The control circuit 14 executes a firmware program stored in the storage device 15 to directly control each hardware device of the client device 1 without going through the operating system. The storage device 15 stores a firmware program for the client device 1, such as a UEFI (Unified Extensible Firmware Interface) or BIOS (Basic Input / Output System) program. The storage device 15 is, for example, a non-volatile storage medium such as a flash memory. The communication device 16 is communicatively connected to the server device 2 via a communication line 5. The communication device 16 includes a communication circuit that transmits and receives signals via a communication port. The input device 17 receives user input that controls the operation of the client device 1. The input device 17 includes, for example, a keyboard and a pointing device. The display device 18 displays information related to the status of the client device 1. The CPU 11, RAM 12, storage device 13, storage device 15, communication device 16, input device 17, and display device 18 are connected to one another via a bus 10.

[0022] FIG. 3 is a block diagram showing the configuration of the server device 2 of FIG. 1. The server device 2 includes a bus 20, a CPU 21, a RAM 22, a storage device 23, a communication device 26, an input device 27, and a display device 28. The CPU 21 executes programs stored in the storage device 23 to control the overall operation of the server device 2 and manages the deletion of data stored in the storage device 13 of each client device 1. The CPU 21 is an example of a control circuit, processing circuit, or signal processor. The RAM 22 temporarily stores programs and data necessary for the operation of the server device 2. The storage device 23 is a non-volatile storage medium that stores programs and data necessary for the operation of the server device 2. The communication device 26 is communicatively connected to each client device 1 and the terminal devices 3 and 4 via a communication line 5. The communication device 26 includes a communication circuit that transmits and receives signals via a communication port. The input device 27 receives user inputs that control the operation of the server device 2. The input device 27 includes, for example, a keyboard and a pointing device. The display device 28 displays information related to the status of the server device 2. The CPU 21 , RAM 22 , storage device 23 , communication device 26 , input device 27 , and display device 28 are connected to one another via a bus 20 .

[0023] FIG. 4 is a block diagram showing the configuration of the terminal devices 3 and 4 in FIG. 1. The terminal devices 3 and 4 include a bus 30, a CPU 31, a RAM 32, a storage device 33, a communication device 36, an input device 37, and a display device 38. The CPU 31 controls the overall operation of the terminal devices 3 and 4 by executing a program stored in the storage device 33. The CPU 31 is an example of a control circuit, processing circuit, or signal processor. The RAM 32 temporarily stores programs and data necessary for the operation of the terminal devices 3 and 4. The storage device 33 is a non-volatile storage medium that stores programs and data necessary for the operation of the terminal devices 3 and 4. The communication device 36 is communicatively connected to the server device 2 via a communication line 5. The communication device 36 includes a communication circuit that transmits and receives signals via a communication port. The input device 37 receives user input to control the operation of the terminal devices 3 and 4. The input device 37 includes, for example, a keyboard and a pointing device. The display device 38 displays information related to the status of the terminal devices 3 and 4. The CPU 31 , RAM 32 , storage device 33 , communication device 36 , input device 37 , and display device 38 are connected to one another via a bus 30 .

[0024] The server device 2 provides an interface, for example, a web page-based interface, accessible by the terminal devices 3 and 4 to manage the erasure of data stored in the storage device of each client device 1. In this case, the server device 2 executes a web server application program, and the terminal devices 3 and 4 execute a web browser application program to access the web server of the server device 2.

[0025] [Operation of the first embodiment] As described above, in the client device 1, the storage device 13 stores the operating system and multiple application programs, and the storage device 15 stores the firmware program. The operating system and each application program are executed by the CPU 11, and the firmware program is executed by the control circuit 14. Generally, when the client device 1 starts up, the firmware program is executed first, and then the operating system is called from the firmware program. The application program is executed on the operating system. The application program accesses each hardware device of the client device 1 (the CPU 11, RAM 12, storage device 13, communication device 16, input device 17, and display device 18) via the operating system. On the other hand, the firmware program accesses each hardware device of the client device 1 directly without going through the operating system.

[0026] Some firmware programs allow remote access even when the operating system is unavailable or the device is powered off. For example, Intel® Advanced Management Technology (AMT) and the Intel AMT High Level Application Programming Interface (HLAPI) from Intel Corporation provide such functionality. Therefore, for example, by using the Remote Platform Erase (RPE) of the Intel AMT HLAPI, data stored in the storage device 13 can be erased without going through the operating system and regardless of whether the client device 1 is powered on or off.

[0027] Here, data erasure using the Intel AMT HLAPI will be described with reference to FIG.

[0028] FIG. 5 is a sequence diagram showing an erasure process according to a comparative example.

[0029] In the initial state, the power of the client device 1 may be either off or on. When the power of the client device 1 is off, the CPU 11 is inactive, but the control circuit 14 is executing a firmware program. On the other hand, when the power of the client device 1 is on, the CPU 11 is running an operating system, and the control circuit 14 is executing a firmware program.

[0030] In step S1, the CPU 21 of the server device 2 receives an instruction to erase data from the administrator. The CPU 21 sends a startup command to the client device 1. If the client device 1 is powered off, in step S2, the control circuit 14 of the client device 1 responds to the startup command by turning on the power of the client device 1, causing the CPU 11 to start the operating system, and sending a startup response indicating the completion of startup to the server device 2. When using Intel AMT HLAPI, the control circuit 14 can receive the startup command and start the operating system even if the client device 1 is powered off. On the other hand, if the client device 1 is powered on, the control circuit 14 responds to the startup command by directly sending a startup response to the server device 2.

[0031] After receiving the startup response, the CPU 21 of the server device 2 transmits an erase command to the client device 1. In step S3, in response to the erase command, the control circuit 14 of the client device 1 erases the data stored in the storage device 13. After the data erasure is completed, the control circuit 14 transmits an erase response indicating the completion of the data erasure to the server device 2.

[0032] After receiving the deletion response, the CPU 21 of the server device 2 transmits an end command to the client device 1. In step S4, the control circuit 14 of the client device 1 turns off the power supply of the client device 1 in response to the end command.

[0033] 5, when the client device 1 receives an erase command, the data stored in the storage device 13 is forcibly erased unconditionally without requesting confirmation from the user (end user) or administrator of the client device 1. Therefore, data may be erased regardless of whether preparations for data erasure, such as whether backups of necessary data have been completed or whether permission to erase has been obtained from a person with the necessary authority, are complete. Therefore, even when using an existing API that forcibly erases data unconditionally, it is necessary to confirm whether preparations for data erasure have been completed.

[0034] In each embodiment of the present disclosure, an information processing system and an information processing method are provided that can confirm whether preparations for data erasure are complete and reliably and easily erase data stored in a storage device 13, even when using an existing API that forcibly erases data unconditionally.

[0035] In the first embodiment, an erasure process involving only the client device 1 and the server device 2 among the client device 1, the server device 2, and the terminal devices 3 and 4 shown in FIG. 1 will be described.

[0036] FIG. 6 is a sequence diagram showing the erasure process according to the first embodiment.

[0037] In step S11, the client device 1 acquires from the user (end user) erasure permission information indicating whether erasure of data stored in the storage device 13 is permitted, and stores the information in the storage device 15. The erasure permission information may be stored in the storage device 15 as, for example, a one-bit flag. The client device 1 may display a prompt on the display device 18 for inputting the erasure permission information by executing an application program with the CPU 11 or by executing a firmware program with the control circuit 14.

[0038] After acquiring the erasure permission information and storing it in the storage device 15, the client device 1 may turn off the power.

[0039] In step S12, the CPU 21 of the server device 2 receives a data erasure instruction from the administrator. The administrator may instruct the server device 2 to erase data directly from the input device 27 of the server device 2, or may instruct the server device 2 to erase data via one of the terminal devices 3 and 4. The CPU 21 sends an erasure permission request to the client device 1, requesting the return of erasure permission information. In response to the erasure permission request, the control circuit 14 of the client device 1 reads the erasure permission information from the storage device 15 and sends an erasure permission response including the erasure permission information to the server device 2. When the Intel AMT HLAPI is used, the control circuit 14 can receive the erasure permission request, read the erasure permission information from the storage device 15, and send the erasure permission response to the server device 2 even when the client device 1 is powered off.

[0040] In step S13, the CPU 21 of the server device 2 confirms that the erasure permission information has been acquired from the erasure permission response. In step S14, the CPU 21 determines whether a predetermined erasure condition is met based on the erasure permission information, and if YES, sends a startup command to the client device 1, and if NO, ends the process. The erasure condition in step S14 is that the erasure permission information indicates permission to erase data.

[0041] After the start command in FIG. 6 is sent, the process is the same as that in FIG.

[0042] According to the process of Figure 6, when the user has completed preparations for data erasure, such as backing up necessary data, the user inputs erasure permission information into the client device 1. If the erasure permission information indicates that data erasure is permitted, an erasure command is issued and the data stored in the storage device 13 is erased. On the other hand, if the erasure permission information does not indicate that data erasure is permitted, an erasure command is not issued and the data stored in the storage device 13 is not erased. Therefore, according to the process of Figure 6, even when using an existing API that forcibly erases data unconditionally, it is possible to check whether data erasure preparations are complete and to reliably and easily erase data stored in the storage device 13.

[0043] FIG. 7 is a sequence diagram showing an erasure process according to a first modification of the first embodiment. After acquiring erasure permission information from a user (step S11), the client device 1 may transmit an erasure permission notice including the erasure permission information to the server device 2. In this case, in step S15, the CPU 21 of the server device 2 acquires the erasure permission information from the erasure permission notice and stores it in the storage device 23. Thereafter, when the server device 2 receives a data erasure instruction from an administrator (step S12), the CPU 21 confirms in step S13A that the erasure permission information is stored in the storage device 23, without sending and receiving an erasure permission request and an erasure permission response as in FIG. 6. The process from step S14 onward in FIG. 7 is the same as that in FIG. 5. According to the process in FIG. 7, by receiving and storing the erasure permission information from the client device 1 in advance, the process after the server device 2 receives a data erasure instruction from the administrator can be simplified compared to the case in FIG. 6.

[0044] FIG. 8 is a sequence diagram showing an erasure process according to a second modified example of the first embodiment. In FIG. 8, the process from step S11 to the transmission of the startup response is the same as the process in FIG. 5. After transmitting the startup response, the control circuit 14 of the client device 1 transmits a backup request to the server device 2, requesting the saving of data stored in the storage device 13, for example, files in a predetermined folder. In step S16, the CPU 21 of the server device 2 saves the data specified in the backup request to the storage device 23. After saving the data, the CPU 21 transmits a backup response to the client device 1 indicating that the data saving has been completed, and then transmits an erasure command to the client device 1. The process after transmitting the erasure command in FIG. 8 is the same as the process in FIG. 5. According to the process in FIG. 8, at least a portion of the data stored in the storage device 13 can be automatically backed up to an external storage device before erasing the data stored in the storage device 13.

[0045] The user may specify in advance, for example, in step S11, whether to back up data stored in the storage device 13 and which files or folders to back up, along with the erasure permission information. For example, the user may specify in step S11 whether backup is necessary and the backup target, along with the erasure permission information.

[0046] The data to be backed up may be stored in the storage device 33 of the terminal devices 3 and 4, or in another storage device, instead of in the storage device 23 of the server device 2.

[0047] [Advantages of the first embodiment] According to one embodiment of the present disclosure, an information processing system 100 includes a client device 1 and a server device 2 connected to each other via a communication line 5. The client device 1 includes a first storage device 13, a second storage device 15, a first communication device 16, and a control circuit 14. The first storage device 13 stores data including an operating system, application programs, and user data. The second storage device 15 stores a firmware program. The first communication device 16 is connected to the server device 2 via the communication line 5. The control circuit 14 controls the first storage device 13 and the first communication device 16 by executing the firmware program. When the control circuit 14 receives an erase command from the server device 2 while the firmware program is being executed, it erases data stored in the first storage device 13. The server device 2 includes a second communication device 26 and a CPU 21. The second communication device 26 is connected to the client device 1 via the communication line 5. The CPU 21 acquires erasure permission information indicating whether erasure of data stored in the first storage device 13 is permitted, and if the erasure permission information indicates that erasure of data is permitted, transmits an erasure command to the client device 1. The CPU 21 acquires, from the client device 1, first permission information indicating whether erasure of data stored in the first storage device 13 is permitted, as erasure permission information.

[0048] With this configuration, even when using an existing API for erasing data, it is possible to check whether preparation for data erasure is complete and to erase data stored in the storage device 13 reliably and easily.

[0049] According to one aspect of the present disclosure, the control circuit 14 may transmit the first permission information to the server device 2 in response to a request from the server device 2 while the firmware program is being executed.

[0050] This configuration allows data stored on the storage device 13 to be erased even when the operating system is not available.

[0051] According to an embodiment of the present disclosure, the server device 2 may further include an input device for receiving a user operation. In this case, the CPU 21 determines whether the erasure permission information indicates permission to erase data in response to the user operation, and sends an erase command to the client device 1 if the erasure permission information indicates permission to erase data.

[0052] With this configuration, the data deletion can be initiated from the server device 2.

[0053] According to one embodiment of the present disclosure, the information processing system may further include a third storage device connected to the client device 1 via the communication line 5. In this case, the control circuit 14 backs up the data stored in the first storage device 13 to the third storage device before erasing the data stored in the first storage device 13.

[0054] This configuration allows the data stored in the storage device 13 to be automatically backed up.

[0055] According to one aspect of the present disclosure, when the control circuit 14 receives an erase command from the server device 2 while the firmware program is being executed, the control circuit 14 may unconditionally erase the data stored in the first storage device 13.

[0056] With this configuration, even when using an existing API that forcibly erases data unconditionally, it is possible to check whether preparations for data erasure are complete and to reliably and easily erase data stored in the storage device 13.

[0057] According to one aspect of the present disclosure, there is provided an information processing method for an information processing system including a client device 1 and a server device 2 connected to each other via a communication line 5. The client device 1 includes a first storage device 13, a second storage device 15, a first communication device 16, and a control circuit 14. The first storage device 13 stores data including an operating system, application programs, and user data. The second storage device 15 stores a firmware program. The first communication device 16 is connected to the server device 2 via the communication line 5. The control circuit 14 controls the first storage device 13 and the first communication device 16 by executing the firmware program. The method includes, by the server device 2, acquiring erasure permission information indicating whether erasure of data stored in the first storage device 13 is permitted. The method also includes, if the erasure permission information indicates permission to erase the data, sending an erase command from the server device 2 to the client device 1. The method also includes, if the client device 1 receives the erase command from the server device 2 while the firmware program is being executed, erasing the data stored in the first storage device 13.

[0058] With this configuration, even when using an existing API for erasing data, it is possible to check whether preparation for data erasure is complete and to erase data stored in the storage device 13 reliably and easily.

[0059] For example, it is conceivable to outsource the erasure of data stored in the storage device 13 to a service provider. However, transporting a client device equipped with a storage device from which data is to be erased to the service provider's business premises poses security risks. Using a highly secure delivery method increases costs. Furthermore, a lot of work is required for the erasure and subsequent checks. Furthermore, erasing data takes a long time, for example, half a day. According to the first embodiment, data stored in the storage device 13 can be erased without moving the client device 1, enabling data to be erased easily, with high security, and at low cost.

[0060] [Second embodiment] [Configuration of the second embodiment] In the second embodiment, an erasure process involving the client device 1, the server device 2, and the terminal device 3 will be described, among the client device 1, the server device 2, and the terminal devices 3 and 4 shown in Fig. 1. The client device 1, the server device 2, and the terminal device 3 according to the second embodiment are configured in the same manner as the corresponding components according to the first embodiment.

[0061] [Operation of the second embodiment] FIG. 9 is a sequence diagram showing the erasure process according to the second embodiment.

[0062] In step S21, the CPU 21 of the server device 2 acquires erasure permission information input by a user (end user) from the client device 1, or acquires erasure permission information input by the administrator A from the terminal device 3. The CPU 21 may acquire the erasure permission information input by the user by receiving an erasure permission notification from the client device 1, similar to the processing in FIG. 7. Alternatively, the CPU 21 may acquire the erasure permission information input by the user by transmitting and receiving an erasure permission request and an erasure permission response, similar to the processing in FIG. 6, during execution of step S23, which will be described later. The CPU 21 also receives an erasure permission notification from the terminal device 3, including the erasure permission information input by the administrator A. The CPU 21 stores the erasure permission information acquired from the client device 1 or the terminal device 3 in the storage device 23.

[0063] In step S22, when the power supply of the client device 1 is on, the CPU 11 or the control circuit 14 of the client device 1 receives a data deletion instruction from the user and transmits a start command to the server device 2.

[0064] In step S23, the CPU 21 of the server device 2 responds to the start command and confirms that the erasure permission information input by the user or the erasure permission information input by the administrator A has been acquired. The CPU 21 may confirm the erasure permission information input by the user by sending and receiving an erasure permission request and an erasure permission response, similar to the process of FIG. 6. In step S24, the CPU 21 determines whether a predetermined erasure condition is met based on the erasure permission information. If YES, the CPU 21 sends an erasure command to the client device 1, and if NO, the process ends. The erasure condition in step S24 is that at least one of the erasure permission information input by the user and the erasure permission information input by the administrator A indicates permission to erase data.

[0065] After the deletion command in FIG. 9 is sent, the process is the same as that in FIG.

[0066] According to the processing of FIG. 9, the erasure condition is that at least one of the erasure permission information entered by the user and the erasure permission information entered by administrator A indicates permission to erase data, so that erasure permission can be obtained more flexibly than in the first embodiment.

[0067] FIG. 10 is a sequence diagram showing an erasure process according to a first modified example of the second embodiment.

[0068] Step S21 in FIG. 10 is the same as step S21 in FIG.

[0069] In step S23A, the CPU 21 of the server device 2 periodically checks whether the erasure permission information input by the user or the erasure permission information input by the administrator A has been acquired. In step S24, the CPU 21 determines whether or not a predetermined erasure condition is met based on the erasure permission information, and if YES, sends a startup command to the client device 1, and if NO, returns to step S21.

[0070] After the start command in FIG. 10 is sent, the process is the same as that in FIG.

[0071] According to the processing of FIG. 10, as with the processing of FIG. 9, the erasure condition is that at least one of the erasure permission information entered by the user and the erasure permission information entered by administrator A indicates permission to erase data, so that erasure permission can be obtained more flexibly than in the first embodiment.

[0072] 10, by periodically checking permission to erase, it is possible to automatically erase data when the user is not using the client device 1. For example, data erasure can start at night and be completed by morning.

[0073] FIG. 11 is a sequence diagram showing an erasure process according to a second modification of the second embodiment.

[0074] Step S21 in FIG. 11 is the same as step S21 in FIG.

[0075] In step S25, the terminal device 3 receives an instruction to erase data from the administrator A and transmits a start command to the server device 2.

[0076] In step S23, in response to the start command, the CPU 21 of the server device 2 confirms that the erasure permission information input by the user or the erasure permission information input by the administrator A has been acquired. In step S24, the CPU 21 determines whether or not a predetermined erasure condition is met based on the erasure permission information, and if YES, sends a start command to the client device 1, and if NO, ends the process.

[0077] After the start command in FIG. 11 is sent, the process is the same as that in FIG.

[0078] According to the processing of FIG. 11, as with the processing of FIG. 9, the erasure condition is that at least one of the erasure permission information entered by the user and the erasure permission information entered by administrator A indicates permission to erase data, so that erasure permission can be obtained more flexibly than in the first embodiment.

[0079] According to the processes of FIGS. 9 to 11, the data deletion can be started by any of the client device 1, the server device 2, and the terminal device 3.

[0080] 9 to 11, the CPU 21 of the server device 2 may acquire the erasure permission information input by the administrator B from the terminal device 4, instead of or in addition to acquiring the erasure permission information input by the administrator A from the terminal device 3. In this case, the erasure condition in step S24 is that at least one of the erasure permission information input by the user and the erasure permission information input by the administrator B indicates permission to erase data.

[0081] [Advantages of the second embodiment] According to one embodiment of the present disclosure, an information processing system 100 includes a client device 1 and a server device 2 connected to each other via a communication line 5. The client device 1 includes a first storage device 13, a second storage device 15, a first communication device 16, and a control circuit 14. The first storage device 13 stores data including an operating system, application programs, and user data. The second storage device 15 stores a firmware program. The first communication device 16 is connected to the server device 2 via the communication line 5. The control circuit 14 controls the first storage device 13 and the first communication device 16 by executing the firmware program. When the control circuit 14 receives an erase command from the server device 2 while the firmware program is being executed, it erases data stored in the first storage device 13. The server device 2 includes a second communication device 26 and a CPU 21. The second communication device 26 is connected to the client device 1 via the communication line 5. The CPU 21 acquires erasure permission information indicating whether erasure of data stored in the first storage device 13 is permitted, and transmits an erasure command to the client device 1 if the erasure permission information indicates that erasure of the data is permitted.

[0082] With this configuration, even when using an existing API for erasing data, it is possible to check whether preparation for data erasure is complete and to erase data stored in the storage device 13 reliably and easily.

[0083] According to one aspect of the present disclosure, the CPU 21 may acquire, from the client device 1, first permission information indicating whether erasure of data stored in the first storage device 13 is permitted, as erasure permission information.

[0084] With this configuration, the erasure permission information input by the user of the client device 1 can be obtained.

[0085] According to an embodiment of the present disclosure, the information processing system may further include a first terminal device 3 connected to the server device 2 via a communication line 5. In this case, the CPU 21 may acquire, as erasure permission information, second permission information from the first terminal device 3 indicating whether erasure of data stored in the first storage device 13 is permitted.

[0086] With this configuration, it is possible to obtain the erasure permission information input by the user of the first terminal device 3 (for example, the administrator of the client device 1).

[0087] According to one aspect of the present disclosure, in response to a first start signal received from the client device 1, the CPU 21 may determine whether the erasure permission information indicates permission to erase data, and if the erasure permission information indicates permission to erase data, send an erase command to the client device 1.

[0088] This configuration allows the client device 1 to initiate data erasure.

[0089] According to an embodiment of the present disclosure, the server device 2 may further include an input device for receiving a user operation. In this case, the CPU 21 may determine, in response to the user operation, whether the erasure permission information indicates permission to erase the data, and may transmit an erasure command to the client device 1 if the erasure permission information indicates permission to erase the data.

[0090] With this configuration, the data deletion can be initiated from the server device 2.

[0091] According to one aspect of the present disclosure, the CPU 21 may periodically determine whether the erasure permission information indicates permission to erase data, and if the erasure permission information indicates permission to erase data, send an erasure command to the client device 1.

[0092] With this configuration, the data deletion can be started automatically from the server device 2.

[0093] According to one aspect of the present disclosure, in response to a second start signal received from the first terminal device 3, the CPU 21 may determine whether the erasure permission information indicates permission to erase data, and if the erasure permission information indicates permission to erase data, send an erasure command to the client device 1.

[0094] With this configuration, data erasure can be initiated from the terminal device 3.

[0095] [Third embodiment] [Configuration of the third embodiment] In the third embodiment, the erasure process involving the client device 1, the server device 2, and the terminal device 3 will be described, among the client device 1, the server device 2, and the terminal devices 3 and 4 shown in Fig. 1. The client device 1, the server device 2, and the terminal device 3 according to the third embodiment are configured in the same manner as the corresponding components according to the first embodiment.

[0096] [Operation of the third embodiment] FIG. 12 is a sequence diagram showing the erasure process according to the third embodiment.

[0097] In step S31, the CPU 21 of the server device 2 acquires the erasure permission information input by the user (end user) from the client device 1, and also acquires the erasure permission information input by the administrator A from the terminal device 3. The CPU 21 may acquire the erasure permission information input by the user from the client device 1, as in step S21 of FIG. 9. Furthermore, the CPU 21 acquires the erasure permission information input by the administrator A from the terminal device 3, as in step S21 of FIG. 9. The CPU 21 stores the erasure permission information acquired from the client device 1 and the terminal device 3 in the storage device 23.

[0098] In step S32, when the power supply of the client device 1 is on, the CPU 11 or the control circuit 14 of the client device 1 receives a data deletion instruction from the user and transmits a start command to the server device 2.

[0099] In step S33, the CPU 21 of the server device 2 responds to the start command and confirms that the erasure permission information input by the user and the erasure permission information input by administrator A have been acquired. The CPU 21 may confirm the erasure permission information input by the user by sending and receiving an erasure permission request and an erasure permission response, similar to the process of FIG. 6. In step S34, the CPU 21 determines whether a predetermined erasure condition is met based on the erasure permission information. If YES, the CPU 21 sends an erasure command to the client device 1, and if NO, the process ends. The erasure condition in step S34 is that both the erasure permission information input by the user and the erasure permission information input by administrator A indicate permission to erase data.

[0100] After the deletion command in FIG. 12 is sent, the process is the same as that in FIG.

[0101] 12, if both the erasure permission information input by the user and the erasure permission information input by administrator A indicate that erasure of data is permitted, an erasure command is issued and the data stored in storage device 13 is erased. On the other hand, if at least one of the erasure permission information input by the user and the erasure permission information input by administrator A does not indicate that erasure of data is permitted, an erasure command is not issued and the data stored in storage device 13 is not erased. By determining whether the erasure conditions are met based on both pieces of erasure permission information, data stored in storage device 13 of client device 1 that is the target of erasure can be erased more reliably than in the first and second embodiments.

[0102] FIG. 13 is a sequence diagram showing an erasure process according to a first modified example of the third embodiment.

[0103] Step S31 in FIG. 13 is similar to step S31 in FIG.

[0104] In step S33A, the CPU 21 of the server device 2 periodically checks whether the erasure permission information input by the user and the erasure permission information input by the administrator A have been acquired. In step S34, the CPU 21 determines whether or not a predetermined erasure condition is met based on the erasure permission information, and if YES, sends a startup command to the client device 1, and if NO, returns to step S31.

[0105] After the start command in FIG. 13 is sent, the process is the same as that in FIG.

[0106] According to the processing of FIG. 13, as with the processing of FIG. 12, the erasure condition is that both the erasure permission information entered by the user and the erasure permission information entered by administrator A indicate permission to erase data, so that data stored in the memory device 13 of the client device 1 to be erased can be erased more reliably than in the first and second embodiments.

[0107] FIG. 14 is a sequence diagram showing an erasure process according to a second modified example of the third embodiment.

[0108] Step S31 in FIG. 14 is the same as step S31 in FIG.

[0109] In step S35, the terminal device 3 receives an instruction to erase data from the administrator A and transmits a start command to the server device 2.

[0110] In step S33, in response to the start command, the CPU 21 of the server device 2 confirms that the erasure permission information input by the user and the erasure permission information input by the administrator A have been acquired. In step S34, the CPU 21 determines whether or not a predetermined erasure condition is met based on the erasure permission information, and if YES, sends a start command to the client device 1, and if NO, ends the process.

[0111] After the start command in FIG. 14 is sent, the process is the same as that in FIG.

[0112] According to the processing of FIG. 14, as with the processing of FIG. 12, the erasure condition is that both the erasure permission information entered by the user and the erasure permission information entered by administrator A indicate permission to erase data, so that data stored in the memory device 13 of the client device 1 to be erased can be erased more reliably than in the first and second embodiments.

[0113] According to the processes of FIGS. 12 to 14, the data deletion can be started by any of the client device 1, the server device 2, and the terminal device 3.

[0114] 12 to 14, the CPU 21 of the server device 2 may acquire the erasure permission information input by the administrator B from the terminal device 4, instead of acquiring the erasure permission information input by the administrator A from the terminal device 3. In this case, the erasure condition in step S34 is that both the erasure permission information input by the user and the erasure permission information input by the administrator B indicate permission to erase data.

[0115] [Advantages of the third embodiment] According to one embodiment of the present disclosure, an information processing system 100 includes a client device 1 and a server device 2 connected to each other via a communication line 5. The client device 1 includes a first storage device 13, a second storage device 15, a first communication device 16, and a control circuit 14. The first storage device 13 stores data including an operating system, application programs, and user data. The second storage device 15 stores a firmware program. The first communication device 16 is connected to the server device 2 via the communication line 5. The control circuit 14 controls the first storage device 13 and the first communication device 16 by executing the firmware program. When the control circuit 14 receives an erase command from the server device 2 while the firmware program is being executed, it erases data stored in the first storage device 13. The server device 2 includes a second communication device 26 and a CPU 21. The second communication device 26 is connected to the client device 1 via the communication line 5. The CPU 21 acquires erasure permission information indicating whether erasure of data stored in the first storage device 13 is permitted, and if the erasure permission information indicates permission to erase the data, sends an erasure command to the client device 1. The CPU 21 acquires, from the client device 1, first permission information indicating whether erasure of data stored in the first storage device 13 is permitted, as erasure permission information. The information processing system further includes a first terminal device 3 connected to the server device 2 via a communication line 5. The CPU 21 acquires, from the first terminal device 3, second permission information indicating whether erasure of data stored in the first storage device 13 is permitted, as erasure permission information. If both the first permission information and the second permission information indicate permission to erase the data, the CPU 21 sends an erasure command to the client device 1.

[0116] With this configuration, even when using an existing API for erasing data, it is possible to check whether preparation for data erasure is complete and to reliably and easily erase data stored in the storage device 13. Furthermore, with this configuration, by determining whether the erasure conditions are met based on both the first permission information and the second permission information, it is possible to erase data stored in the storage device 13 of the client device 1 to be erased more reliably than in the first embodiment.

[0117] According to one aspect of the present disclosure, in response to a first start signal received from the client device 1, the CPU 21 may determine whether the erasure permission information indicates permission to erase data, and if the erasure permission information indicates permission to erase data, send an erase command to the client device 1.

[0118] This configuration allows the client device 1 to initiate data erasure.

[0119] According to an embodiment of the present disclosure, the server device 2 may further include an input device for receiving a user operation. In this case, the CPU 21 may determine, in response to the user operation, whether the erasure permission information indicates permission to erase the data, and may transmit an erasure command to the client device 1 if the erasure permission information indicates permission to erase the data.

[0120] With this configuration, the data deletion can be initiated from the server device 2.

[0121] According to one aspect of the present disclosure, the CPU 21 may periodically determine whether the erasure permission information indicates permission to erase data, and if the erasure permission information indicates permission to erase data, send an erasure command to the client device 1.

[0122] With this configuration, the data deletion can be started automatically from the server device 2.

[0123] According to one aspect of the present disclosure, in response to a second start signal received from the first terminal device 3, the CPU 21 may determine whether the erasure permission information indicates permission to erase data, and if the erasure permission information indicates permission to erase data, send an erasure command to the client device 1.

[0124] With this configuration, data erasure can be initiated from the terminal device 3.

[0125] [Fourth embodiment] [Configuration of the fourth embodiment] In the fourth embodiment, an erasure process involving all of the client device 1, server device 2, and terminal devices 3 and 4 shown in Fig. 1 will be described. The client device 1, server device 2, and terminal devices 3 and 4 according to the fourth embodiment are configured in the same manner as the corresponding components according to the first embodiment. However, administrator B, who operates terminal device 4, has stronger authority than administrator A, who operates terminal device 3.

[0126] [Operation of the fourth embodiment] FIG. 15 is a sequence diagram showing the erasure process according to the fourth embodiment.

[0127] In step S41, the CPU 21 of the server device 2 acquires erasure permission information input by a user (end user) from the client device 1, acquires erasure permission information input by administrator A from the terminal device 3, and acquires erasure permission information input by administrator B from the terminal device 4. The CPU 21 may acquire the erasure permission information input by the user from the client device 1, as in the case of step S21 in FIG. 9. The CPU 21 may also acquire the erasure permission information input by administrator A from the terminal device 3, and may acquire the erasure permission information input by administrator B from the terminal device 4, as in the case of step S21 in FIG. 9. The CPU 21 stores the erasure permission information acquired from the client device 1 and the terminal devices 3 and 4 in the storage device 23.

[0128] In step S42, when the power supply of the client device 1 is on, the CPU 11 or the control circuit 14 of the client device 1 receives a data deletion instruction from the user and transmits a start command to the server device 2.

[0129] In step S43, the CPU 21 of the server device 2 responds to the start command and confirms that the erasure permission information input by the user and the erasure permission information input by administrators A and B have been acquired. The CPU 21 may confirm the erasure permission information input by the user by sending and receiving an erasure permission request and an erasure permission response, similar to the process of FIG. 6. In step S44, the CPU 21 determines whether a predetermined erasure condition is met based on the erasure permission information. If YES, the CPU 21 sends an erasure command to the client device 1, and if NO, the process ends. The erasure condition in step S44 is that both the erasure permission information input by the user and the erasure permission information input by administrator A indicate permission for erasure of data, or that the erasure permission information input by administrator B indicates permission for erasure of data.

[0130] After the deletion command in FIG. 15 is sent, the process is the same as that in FIG.

[0131] 15, by determining whether the erasure conditions are met based on both the erasure permission information input by the user and the erasure permission information input by administrator A, data stored in the storage device 13 of the client device 1 to be erased can be reliably erased. Also, as described above, administrator B has stronger authority than administrator A. In this case, even if at least one of the erasure permission information input by the user and the erasure permission information input by administrator A does not indicate permission for data erasure, data stored in the storage device 13 can be erased based on the erasure permission information input by administrator B. For example, if it is not possible to wait until erasure permission information is input by both the user and administrator A, data stored in the storage device 13 can be quickly erased based on the erasure permission information input by administrator B.

[0132] FIG. 16 is a sequence diagram showing an erasure process according to a first modified example of the fourth embodiment.

[0133] Step S41 in FIG. 16 is the same as step S41 in FIG.

[0134] In step S43A, the CPU 21 of the server device 2 periodically checks whether the erasure permission information input by the user and the erasure permission information input by the administrators A and B has been acquired. In step S34, the CPU 21 determines whether or not a predetermined erasure condition is met based on the erasure permission information, and if YES, sends a startup command to the client device 1, and if NO, returns to step S41.

[0135] After the start command in FIG. 16 is sent, the process is the same as that in FIG.

[0136] 16, similarly to the process of Fig. 15, by determining whether the erasure conditions are met based on both the erasure permission information input by the user and the erasure permission information input by administrator A, it is possible to reliably erase data stored in the storage device 13 of the client device 1 to be erased. Furthermore, even if at least one of the erasure permission information input by the user and the erasure permission information input by administrator A does not indicate permission for erasure of data, it is possible to erase the data stored in the storage device 13 based on the erasure permission information input by administrator B.

[0137] FIG. 17 is a sequence diagram showing an erasure process according to a second modified example of the fourth embodiment.

[0138] Step S41 in FIG. 17 is the same as step S41 in FIG.

[0139] In step S45, the terminal device 3 receives an instruction to erase data from the administrator A and transmits a start command to the server device 2.

[0140] In step S43, in response to the start command, the CPU 21 of the server device 2 confirms that it has acquired the erasure permission information input by the user and the erasure permission information input by the administrators A and B. In step S44, the CPU 21 determines whether or not a predetermined erasure condition is met based on the erasure permission information, and if YES, it sends a start command to the client device 1, and if NO, it ends the process.

[0141] After the start command in FIG. 17 is sent, the process is the same as that in FIG.

[0142] 17, similarly to the process of Fig. 15, by determining whether the erasure conditions are met based on both the erasure permission information input by the user and the erasure permission information input by administrator A, it is possible to reliably erase data stored in the storage device 13 of the client device 1 to be erased. Furthermore, even if at least one of the erasure permission information input by the user and the erasure permission information input by administrator A does not indicate permission for erasure of data, it is possible to erase the data stored in the storage device 13 based on the erasure permission information input by administrator B.

[0143] 18 is a sequence diagram showing an erasure process according to a third modified example of the fourth embodiment. The start command may be sent from the terminal device 4 to the server device 2 instead of from the terminal device 3. In step S46, the terminal device 4 receives an instruction to erase data from the administrator B and sends the start command to the server device 2. Other processes in FIG. 18 are the same as those in FIG. 17.

[0144] According to the processes of FIGS. 15 to 18, the data deletion can be started by any of the client device 1, the server device 2, and the terminal devices 3 and 4.

[0145] Fig. 19 is a table comparing the first to fourth embodiments. According to the comparative example of Fig. 5, the erasure process is initiated by the administrator who operates the server device 2, and the erasure permission information is not used. According to the first embodiment, the erasure process is initiated by an administrator operating the server device 2, and erasure permission is issued by the user of the client device 1. According to the second embodiment, the erasure process is initiated by an administrator A operating the user of the client device 1, the server device 2, or the terminal device 3, and erasure permission is issued by the user of the client device 1 or the administrator A operating the terminal device 3. According to the third embodiment, the erasure process is initiated by an administrator A operating the user of the client device 1, the server device 2, or the terminal device 3, and erasure permission is issued by both the user of the client device 1 and the administrator A operating the terminal device 3. According to the fourth embodiment, the erasure process is initiated by an administrator A operating the client device 1, the server device 2, or the terminal device 3, and erasure permission is issued by both the user of the client device 1 and the administrator A operating the terminal device 3, or by the administrator B operating the terminal device 4.

[0146] [Effects of the fourth embodiment] According to one embodiment of the present disclosure, an information processing system 100 includes a client device 1 and a server device 2 connected to each other via a communication line 5. The client device 1 includes a first storage device 13, a second storage device 15, a first communication device 16, and a control circuit 14. The first storage device 13 stores data including an operating system, application programs, and user data. The second storage device 15 stores a firmware program. The first communication device 16 is connected to the server device 2 via the communication line 5. The control circuit 14 controls the first storage device 13 and the first communication device 16 by executing the firmware program. When the control circuit 14 receives an erase command from the server device 2 while the firmware program is being executed, it erases data stored in the first storage device 13. The server device 2 includes a second communication device 26 and a CPU 21. The second communication device 26 is connected to the client device 1 via the communication line 5. The CPU 21 acquires erasure permission information indicating whether erasure of data stored in the first storage device 13 is permitted, and if the erasure permission information indicates permission for data erasure, sends an erasure command to the client device 1. The CPU 21 acquires, from the client device 1, first permission information indicating whether erasure of data stored in the first storage device 13 is permitted, as erasure permission information. The information processing system further includes a first terminal device 3 connected to the server device 2 via the communication line 5. The CPU 21 acquires, from the first terminal device 3, second permission information indicating whether erasure of data stored in the first storage device 13 is permitted, as erasure permission information. If both the first permission information and the second permission information indicate permission for data erasure, the CPU 21 sends an erasure command to the client device 1. The information processing system further includes a second terminal device 4 connected to the server device 2 via the communication line 5. The CPU 21 acquires, from the second terminal device 4, third permission information indicating whether erasure of data stored in the first storage device 13 is permitted, as erasure permission information. If the third permission information indicates permission to erase the data, the CPU 21 transmits an erase command to the client device 1.

[0147] With this configuration, even when using an existing API for erasing data, it is possible to confirm whether preparation for data erasure is complete and to reliably and easily erase data stored in the storage device 13. Furthermore, with this configuration, it is possible to reliably erase data stored in the storage device 13 of the client device 1 to be erased by determining whether the erasure conditions are met based on both the first permission information and the second permission information. Furthermore, even if at least one of the erasure permission information input by the user and the erasure permission information input by the administrator A does not indicate permission for data erasure, it is possible to erase data stored in the storage device 13 based on the erasure permission information input by the administrator B.

[0148] According to one aspect of the present disclosure, in response to a first start signal received from the client device 1, the CPU 21 may determine whether the erasure permission information indicates permission to erase data, and if the erasure permission information indicates permission to erase data, send an erase command to the client device 1.

[0149] This configuration allows the client device 1 to initiate data erasure.

[0150] According to an embodiment of the present disclosure, the server device 2 may further include an input device for receiving a user operation. In this case, the CPU 21 may determine, in response to the user operation, whether the erasure permission information indicates permission to erase the data, and may transmit an erasure command to the client device 1 if the erasure permission information indicates permission to erase the data.

[0151] With this configuration, the data deletion can be initiated from the server device 2.

[0152] According to one aspect of the present disclosure, the CPU 21 may periodically determine whether the erasure permission information indicates permission to erase data, and if the erasure permission information indicates permission to erase data, send an erasure command to the client device 1.

[0153] With this configuration, the data deletion can be started automatically from the server device 2.

[0154] According to one aspect of the present disclosure, in response to a second start signal received from the first terminal device 3, the CPU 21 may determine whether the erasure permission information indicates permission to erase data, and if the erasure permission information indicates permission to erase data, send an erasure command to the client device 1.

[0155] With this configuration, data erasure can be initiated from the terminal device 3.

[0156] According to one aspect of the present disclosure, in response to a third start signal received from the second terminal device 4, the CPU 21 may determine whether the erasure permission information indicates permission to erase data, and if the erasure permission information indicates permission to erase data, send an erasure command to the client device 1.

[0157] With this configuration, data erasure can be initiated from the terminal device 4.

[0158] [Other embodiments] As described above, the embodiments have been described as examples of the technology disclosed in this application. However, the technology in this disclosure is not limited to these, and can be applied to embodiments in which modifications, substitutions, additions, omissions, etc. are made as appropriate. Furthermore, it is also possible to combine the components described in the above embodiments to create new embodiments. Therefore, other embodiments will be described below as examples.

[0159] In the first to fourth embodiments, if it is determined that the deletion conditions are not met, the server device 2 may output some kind of error code.

[0160] In the first to fourth embodiments, the transmission of the end command and step S4 may be omitted. In this case, after the data erasure is completed, the power of the client device 1 may not be turned off and the erasure result may be displayed on the display device 18 of the client device 1.

[0161] The data backup described with reference to FIG. 8 may be applied to the processes of FIGS.

[0162] 2, the client device 1 is described as having only one storage device 13 from which stored data is to be erased, but the client device 1 may also have multiple storage devices 13 from which stored data is to be erased. The multiple storage devices 13 may be configured as, for example, a RAID (Redundant Array of Inexpensive Disks) device. In this case, the multiple storage devices 13 are treated as an integrated device, and the data stored therein is erased as a unit. Alternatively, the multiple storage devices 13 may be treated individually, and the data stored therein may be erased individually.

[0163] Like each client device 1, the terminal device 3 of administrator A may also be configured to allow external remote access when the device is powered off, for example, using Intel AMT HLAPI. In this case, in the processes of FIGS. 9 to 18, the server device 2 may obtain the erasure permission information entered by administrator A immediately before determining whether the erasure conditions are met, instead of obtaining it in advance in steps S21, S31, and S41. For this purpose, the server device 2 sends a startup command to the terminal device 3. In response to the startup command, the terminal device 3 turns on the power of the terminal device 3, starts the operating system, and sends a startup response indicating the completion of startup to the server device 2. Thereafter, the server device 2 obtains the erasure permission information entered by administrator A by transmitting and receiving an erasure permission request and an erasure permission response to the terminal device 3. Similarly, the terminal device 4 of administrator B may also be configured to allow external remote access when the device is powered off.

[0164] In the first to fourth embodiments, the cases where the user, administrator A, and / or administrator B issues the erasure permission have been described. However, in addition to or instead of this, other parties may issue the erasure permission. In this case, the server device 2 may perform a logical operation based on the erasure permission information input by multiple parties to determine whether the erasure condition is met. For example, in the fourth embodiment, the server device 2 may also refer to the erasure permission information input by an administrator C different from administrators A and B, for example, an administrator C with weaker authority than administrator B. In this case, the erasure condition is that both the erasure permission information input by the user and the erasure permission information input by administrator A indicate permission for erasure of data, that the erasure permission information input by administrator B indicates permission for erasure of data, or that both the erasure permission information input by administrator A and the erasure permission information input by administrator C indicate permission for erasure of data. Even if neither the erasure permission information input by the user nor the erasure permission information input by administrator B indicates permission for erasure of data, data stored in the storage device 13 can be erased based on the erasure permission information input by administrators A and C. This allows the number of people to whom erasure authorization is issued to be increased as desired and allows the erasure conditions to be set as desired, thereby improving the convenience of erasure.

[0165] As described above, the embodiments have been described as examples of the technology in the present disclosure, and for that purpose, the accompanying drawings and detailed description have been provided.

[0166] Therefore, the components shown in the accompanying drawings and detailed description may include not only essential components for solving the problem, but also components that are not essential for solving the problem in order to illustrate the above technology. Therefore, the fact that these non-essential components are shown in the accompanying drawings or detailed description should not be interpreted as immediately indicating that these non-essential components are essential.

[0167] Furthermore, since the above-described embodiments are intended to illustrate the technology of the present disclosure, various modifications, substitutions, additions, omissions, etc. may be made within the scope of the claims or their equivalents.

[0168] [Summary of the embodiment] According to the information processing device according to the first aspect of the present disclosure, An information processing device connected to at least one electronic device via a communication line, The electronic device is a first storage device for storing data including an operating system, application programs, and user data; a second storage device that stores a firmware program; a first communication device connected to the information processing device via the communication line; a first control circuit that controls the first storage device and the first communication device by executing the firmware program, and that erases data stored in the first storage device when an erase command is received from the information processing device during execution of the firmware program; The information processing device includes: a second communication device connected to the electronic device via the communication line; and a second control circuit that acquires erasure permission information indicating whether erasure of data stored in the first storage device is permitted, and sends the erasure command to the electronic device if the erasure permission information indicates that erasure of the data is permitted.

[0169] According to the information processing device according to the second aspect of the present disclosure, in the information processing device according to the first aspect, The second control circuit acquires, as the erasure permission information, first permission information indicating whether erasure of data stored in the first storage device is permitted from the electronic device.

[0170] According to the information processing device according to the third aspect of the present disclosure, in the information processing device according to the second aspect, the second control circuit transmits an erase permission request to the electronic device, the erase permission request requesting the first permission information; The first control circuit transmits the first permission information to the information processing device in response to the erase permission request during execution of the firmware program.

[0171] According to the information processing device according to the fourth aspect of the present disclosure, in the information processing device according to the first aspect, the second communication device is further connected to a first terminal device via the communication line; The second control circuit acquires, as the erasure permission information, second permission information indicating whether erasure of data stored in the first storage device is permitted from the first terminal device.

[0172] According to the information processing device according to the fifth aspect of the present disclosure, in the information processing device according to the second aspect, the second communication device is further connected to a first terminal device via the communication line; The second control circuit includes: acquiring, from the first terminal device, second permission information indicating whether erasure of data stored in the first storage device is permitted, as the erasure permission information; If both the first permission information and the second permission information indicate permission to erase the data, the erase command is sent to the electronic device.

[0173] According to the information processing device according to the sixth aspect of the present disclosure, in the information processing device according to the fifth aspect, the second communication device is further connected to a second terminal device via the communication line; The second control circuit includes: acquiring, from the second terminal device, third permission information indicating whether erasure of the data stored in the first storage device is permitted, as the erasure permission information; If the third permission information indicates permission to erase the data, the erase command is sent to the electronic device.

[0174] According to the information processing device according to the seventh aspect of the present disclosure, in the information processing device according to one of the first to sixth aspects, The second control circuit determines whether the erasure permission information indicates permission to erase the data in response to a first start signal received from the electronic device, and sends the erase command to the electronic device if the erasure permission information indicates permission to erase the data.

[0175] According to an information processing device according to an eighth aspect of the present disclosure, in the information processing device according to one of the first to sixth aspects, the information processing device further includes an input device for receiving a user operation; In response to the user operation, the second control circuit determines whether the erasure permission information indicates permission to erase the data, and if the erasure permission information indicates permission to erase the data, sends the erasure command to the electronic device.

[0176] According to an information processing device according to a ninth aspect of the present disclosure, in the information processing device according to one of the first to sixth aspects, The second control circuit periodically determines whether the erasure permission information indicates permission to erase the data, and if the erasure permission information indicates permission to erase the data, sends the erasure command to the electronic device.

[0177] According to the information processing device according to the tenth aspect of the present disclosure, in the information processing device according to one of the fourth to sixth aspects, The second control circuit determines whether the erasure permission information indicates permission to erase the data in response to a second start signal received from the first terminal device, and sends the erasure command to the electronic device if the erasure permission information indicates permission to erase the data.

[0178] According to an information processing device according to an eleventh aspect of the present disclosure, in the information processing device according to the sixth aspect, The second control circuit determines whether the erasure permission information indicates permission to erase the data in response to a third start signal received from the second terminal device, and sends the erasure command to the electronic device if the erasure permission information indicates permission to erase the data.

[0179] According to the information processing device according to the twelfth aspect of the present disclosure, in the information processing device according to one of the first to eleventh aspects, When the first control circuit receives the erase command from the information processing device while the firmware program is being executed, the first control circuit unconditionally erases the data stored in the first storage device.

[0180] According to the information processing system according to the thirteenth aspect of the present disclosure, An information processing system including an electronic device and an information processing device connected to each other via a communication line, The electronic device is a first storage device for storing data including an operating system, application programs, and user data; a second storage device that stores a firmware program; a first communication device connected to the information processing device via the communication line; a first control circuit that controls the first storage device and the first communication device by executing the firmware program, and that erases data stored in the first storage device when an erase command is received from the information processing device during execution of the firmware program; The information processing device includes: a second communication device connected to the electronic device via the communication line; and a second control circuit that acquires erasure permission information indicating whether erasure of data stored in the first storage device is permitted, and sends the erasure command to the electronic device if the erasure permission information indicates that erasure of the data is permitted.

[0181] According to an information processing system according to a fourteenth aspect of the present disclosure, in the information processing system according to the thirteenth aspect, the information processing system further includes a third storage device connected to the electronic device via the communication line; The first control circuit backs up the data stored in the first storage device to the third storage device before erasing the data stored in the first storage device.

[0182] According to an information processing method according to a fifteenth aspect of the present disclosure, An information processing method for an information processing system including an electronic device and an information processing device connected to each other via a communication line, The electronic device is a first storage device for storing data including an operating system, application programs, and user data; a second storage device that stores a firmware program; a communication device connected to the information processing device via the communication line; a control circuit that controls the first storage device and the communication device by executing the firmware program; The information processing method includes: acquiring, by the information processing device, erasure permission information indicating whether erasure of data stored in the first storage device is permitted; transmitting an erase command from the information processing device to the electronic device when the erase permission information indicates that erasure of the data is permitted; When the electronic device receives an erase command from the information processing device while the firmware program is being executed, the electronic device erases the data stored in the first storage device. [Industrial Applicability]

[0183] An electronic device according to one aspect of the present disclosure is useful for erasing data stored in a storage device. [Explanation of symbols]

[0184] 1,1-1~1-3 Client device 2. Server device 3,4 Terminal Device 5. Communication lines 10 Bus 11 CPU 12 RAM 13 Storage device 14 Control circuit 15 Storage device 16. Communications equipment 17 Input Devices 18 Display device 20 Bus 21 CPU 22 RAM 23 Storage device 26 Communication equipment 27 Input Devices 28 Display device 30 Bus 31 CPU 32 RAM 33 Storage device 36 Communication equipment 37 Input Devices 38 Display device

Claims

1. An information processing device connected to at least one electronic device via a communication line, The electronic device is a first storage device for storing data including an operating system, application programs, and user data; a second storage device for storing a firmware program; a first communication device connected to the information processing device via the communication line; a first control circuit that controls the first storage device and the first communication device by executing the firmware program, and that erases data stored in the first storage device when an erase command is received from the information processing device during execution of the firmware program; The information processing device includes: a second communication device connected to the electronic device via the communication line; a second control circuit that acquires erasure permission information indicating whether erasure of data stored in the first storage device is permitted, and transmits the erasure command to the electronic device when the erasure permission information indicates that erasure of the data is permitted; the second communication device is further connected to a first terminal device and a second terminal device via the communication line; The second control circuit includes: acquiring, from the electronic device, first permission information indicating whether erasure of data stored in the first storage device is permitted, as the erasure permission information; acquire, from the first terminal device, second permission information indicating whether erasure of data stored in the first storage device is permitted, as the erasure permission information, and if both the first permission information and the second permission information indicate permission to erase the data, transmit the erasure command to the electronic device; acquiring, as the erasure permission information, third permission information indicating whether erasure of the data stored in the first storage device is permitted from the second terminal device, and transmitting the erasure command to the electronic device when the third permission information indicates that erasure of the data is permitted; Information processing device.

2. (delete)

3. the second control circuit transmits an erase permission request to the electronic device, the erase permission request requesting the first permission information; the first control circuit transmits the first permission information to the information processing device in response to the erasure permission request during execution of the firmware program; 2. The information processing device according to claim 1.

4. (delete)

5. (delete)

6. (delete)

7. the second control circuit, in response to a first start signal received from the electronic device, determines whether the erasure permission information indicates permission to erase the data, and sends the erasure command to the electronic device if the erasure permission information indicates permission to erase the data; 7. The information processing device according to claim 1.

8. the information processing device further includes an input device for receiving a user operation; the second control circuit determines whether the erasure permission information indicates permission to erase the data in response to the user operation, and sends the erasure command to the electronic device if the erasure permission information indicates permission to erase the data.

4. The information processing device according to claim 1.

9. the second control circuit periodically determines whether the erasure permission information indicates permission to erase the data, and if the erasure permission information indicates permission to erase the data, sends the erasure command to the electronic device.

4. The information processing device according to claim 1.

10. the second control circuit, in response to a second start signal received from the first terminal device, determines whether the erasure permission information indicates permission to erase the data, and sends the erasure command to the electronic device if the erasure permission information indicates permission to erase the data; 4. The information processing device according to claim 1.

11. the second control circuit, in response to a third start signal received from the second terminal device, determines whether the erasure permission information indicates permission to erase the data, and sends the erasure command to the electronic device if the erasure permission information indicates permission to erase the data; 4. The information processing device according to claim 1.

12. the first control circuit unconditionally erases the data stored in the first storage device when the erase command is received from the information processing device during execution of the firmware program; 2. The information processing device according to claim 1.

13. An information processing system including an electronic device and an information processing device connected to each other via a communication line, The electronic device is a first storage device for storing data including an operating system, application programs, and user data; a second storage device for storing a firmware program; a first communication device connected to the information processing device via the communication line; a first control circuit that controls the first storage device and the first communication device by executing the firmware program, and that erases data stored in the first storage device when an erase command is received from the information processing device during execution of the firmware program; The information processing device includes: a second communication device connected to the electronic device via the communication line; a second control circuit that acquires erasure permission information indicating whether erasure of data stored in the first storage device is permitted, and transmits the erasure command to the electronic device when the erasure permission information indicates that erasure of the data is permitted; the second communication device is further connected to a first terminal device and a second terminal device via the communication line; The second control circuit includes: acquiring, from the electronic device, first permission information indicating whether erasure of data stored in the first storage device is permitted, as the erasure permission information; acquire, from the first terminal device, second permission information indicating whether erasure of data stored in the first storage device is permitted, as the erasure permission information, and if both the first permission information and the second permission information indicate permission to erase the data, transmit the erasure command to the electronic device; acquiring, as the erasure permission information, third permission information indicating whether erasure of the data stored in the first storage device is permitted from the second terminal device, and transmitting the erasure command to the electronic device when the third permission information indicates that erasure of the data is permitted; Information processing system.

14. the information processing system further includes a third storage device connected to the electronic device via the communication line; the first control circuit backs up the data stored in the first storage device to the third storage device before erasing the data stored in the first storage device; 14. The information processing system according to claim 13.

15. An information processing method for an information processing system including an electronic device and an information processing device connected to each other via a communication line, The electronic device is a first storage device for storing data including an operating system, application programs, and user data; a second storage device for storing a firmware program; a communication device connected to the information processing device via the communication line; a control circuit that controls the first storage device and the communication device by executing the firmware program; The information processing method includes: acquiring, by the information processing device, erasure permission information indicating whether erasure of data stored in the first storage device is permitted; transmitting an erase command from the information processing device to the electronic device when the erase permission information indicates that erasure of the data is permitted; erasing the data stored in the first storage device when the electronic device receives an erasure command from the information processing device while the firmware program is being executed; the information processing device is further connected to a first terminal device and a second terminal device via the communication line; The information processing method includes: The information processing device acquires, from the electronic device, first permission information indicating whether erasure of data stored in the first storage device is permitted, as the erasure permission information; the information processing device acquires, from the first terminal device, second permission information indicating whether erasure of the data stored in the first storage device is permitted, as the erasure permission information, and when both the first permission information and the second permission information indicate permission to erase the data, transmits the erasure command from the information processing device to the electronic device; the information processing device acquires, from the second terminal device, third permission information indicating whether erasure of the data stored in the first storage device is permitted or not, as the erasure permission information, and when the third permission information indicates permission to erase the data, the information processing device transmits the erasure command to the electronic device. Information processing methods.

Citation Information

Patent Citations

  • Data erasing system, management server, data erasing method, and program

    JP2007293401A

  • Management method, management system, management server and management program of computer

    JP2020129159A

  • Data erasure method

    JP6923311B2

  • Information processing device and setting information management method

    WO2012105031A1

  • Electronic apparatus, system, and method for deleting data stored in storage device of electronic apparatus

    WO2022255396A1