Data erasure method, information processing system, and information processing device
The method employs a management server and secure sub-controller to verify and execute encrypted erasure commands, addressing incomplete data erasure in SSDs by ensuring secure and complete data deletion.
Patent Information
- Application Number
- JP2024225506
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2024-12-20
- Publication Date
- 2025-11-21
- Estimated Expiration
- 2044-12-20
AI Technical Summary
Conventional data erasure methods in information processing devices, such as SSDs, may fail to completely erase data due to tampering, necessitating a reliable method to ensure data integrity during disposal.
A data erasure method involving a management server transmitting encrypted erasure programs and commands to a secure device using a sub-device, which includes a secure area that is not directly accessible from the outside, and a sub-controller verifying the legitimacy of these commands and programs using cryptographic keys, ensuring secure execution and verification of the erasure process.
Ensures reliable and secure data erasure by verifying the legitimacy of erasure programs and commands using cryptographic keys, preventing unauthorized access and ensuring complete data deletion.
Smart Images

Figure 0007774700000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a data erasure method, an information processing system, and an information processing device. [Background technology]
[0002] In recent years, a technology for erasing data from information processing devices such as notebook personal computers (notebook PCs) has become known (see, for example, Patent Document 1). In the technology described in Patent Document 1, a memory drive device such as an SSD (Solid State Drive) has a function for completely and automatically erasing data, and this function is used by the information processing device to erase data. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Publication No. 2020-119361 Summary of the Invention [Problem to be solved by the invention]
[0004] However, with the above-mentioned conventional technology, there is a possibility that data may not be erased completely if the function for completely and automatically erasing data is tampered with, etc. For example, when a company disposes of an information processing device that it has used, it is required to guarantee that the data in the memory drive device built into the information processing device has been completely erased, and reliability is required to be guaranteed.
[0005] The present invention has been made to solve the above problems, and its purpose is to provide a data erasure method, an information processing system, and an information processing device that can reliably erase data and ensure reliability when erasing data from a memory drive device. [Means for solving the problem]
[0006] In order to solve the above problems, one aspect of the present invention is a data erasure method for an information processing device having a built-in memory drive device, the data erasure method including: a first transmission step in which a management server managing the information processing device transmits a data erasure program for the memory drive device to the information processing device using encryption processing with a first private key that is the secret key of the management server; an installation step in which the information processing device confirms the legitimacy of the data erasure program using a first public key that is the public key of the management server, and, if the legitimacy of the data erasure program is confirmed, installs the confirmed legitimacy data erasure program into the memory drive device; a second transmission step in which the management server transmits an erase command to the information processing device using encryption processing with the first private key, causing a processor of the memory drive device to execute the data erasure program; and a data erasure step in which the information processing device confirms the legitimacy of the erase command using the first public key, and, if the legitimacy of the erase command is confirmed, transmits the confirmed legitimacy erase command to the memory drive device, causing the memory drive device to execute the data erasure process using the data erasure program.
[0007] Furthermore, one aspect of the present invention may include, in the above-mentioned data erasure method, a third transmission step in which the information processing device transmits a data erasure result, which is a result of the data erasure process, to the management server using encryption processing with a second private key, which is a private key of the information processing device; and a result storage step in which the management server confirms the legitimacy of the data erasure result using a second public key, which is a public key of the information processing device, and, if the legitimacy of the data erasure result is confirmed, stores the data erasure result, whose legitimacy has been confirmed, in an erasure result storage unit.
[0008] Furthermore, one aspect of the present invention is that in the above-mentioned data erasure method, the information processing device is provided with a sub-controller that can operate independently of a main controller that executes processing based on an OS (Operating System) and a BIOS (Basic Input Output System), the sub-controller being a secure area that is not directly accessible from the outside and having a security area that stores at least the first public key and the second private key, and in the installation step and the data erasure step, the sub-controller may verify the legitimacy of the data erasure program and the erasure command, and send the data erasure program and the erasure command to the memory drive device via the sub-controller and the BIOS.
[0009] In addition, one aspect of the present invention is that in the above-mentioned data erasure method, in the third transmission step, the sub-control unit may transmit the data erasure result to the management server using encryption processing with the second private key.
[0010] Furthermore, according to one aspect of the present invention, in the above-described data erasure method, in the first transmission step and the second transmission step, the management server generates signature information for the transmission data using cryptographic processing with the first private key, attaches the signature information to the transmission data for which the signature information has been generated, and transmits the data to the information processing device; in the installation step and the data erasure step, the information processing device verifies the legitimacy of the data erasure program and the erasure command based on the signature information and the first public key; in the third transmission step, the information processing device generates signature information for the data erasure result using cryptographic processing with the second private key, attaches the signature information to the data erasure result, and transmits the data erasure result to the management server; and in the result storage step, the management server verifies the legitimacy of the data erasure result based on the signature information for the data erasure result and the second public key.
[0011] In addition, one aspect of the present invention may be such that in the data erasing method, the memory drive device is an SSD (Solid State Drive).
[0012] Another aspect of the present invention is an information processing system comprising an information processing device having a built-in memory drive device and a management server that manages the information processing device, wherein the management server executes a first transmission process to transmit a data erasure program for the memory drive device to the information processing device using cryptographic processing with a first private key that is a private key of the management server, and a second transmission process to transmit an erasure command to the information processing device, the erasure command causing a processor of the memory drive device to execute the data erasure program, using cryptographic processing with the first private key; and the information processing device executes an installation process to verify the legitimacy of the data erasure program using a first public key that is a public key of the management server, and, if the legitimacy of the data erasure program has been verified, install the verified data erasure program into the memory drive device, and a data erasure process to verify the legitimacy of the erasure command using the first public key, and, if the legitimacy of the erasure command has been verified, send the verified erase command to the memory drive device, causing the data erasure process to be executed by the data erasure program.
[0013] Another aspect of the present invention is an information processing device of an information processing system including an information processing device with a built-in memory drive device and an administrative server that manages the information processing device, the information processing device including: an installation processing unit that acquires a data erasure program for the memory drive device sent by the administrative server using cryptographic processing with a first private key that is the private key of the administrative server, verifies the legitimacy of the data erasure program using a first public key that is the public key of the administrative server, and, if the legitimacy of the data erasure program is confirmed, installs the confirmed legitimacy of the data erasure program into the memory drive device; and a data erasure processing unit that acquires an erase command sent by the administrative server using cryptographic processing with the first private key to cause a processor of the memory drive device to execute the data erasure program, verifies the legitimacy of the erase command using the first public key, and, if the legitimacy of the erase command is confirmed, sends the confirmed legitimacy of the erase command to the memory drive device, causing the memory drive device to execute a data erasure process using the data erasure program. [Effects of the Invention]
[0014] According to the above aspects of the present invention, when erasing data from a memory drive device, data can be erased reliably and reliability can be ensured. [Brief explanation of the drawings]
[0015] [Figure 1] 1 is a configuration diagram illustrating an example of an information processing system according to a first embodiment. [Figure 2] 1 is a block diagram showing an example of a main hardware configuration of a notebook PC according to a first embodiment. [Figure 3] 1 is a functional block diagram illustrating an example of a functional configuration of an information processing system according to a first embodiment. [Figure 4] FIG. 4 is a diagram illustrating an example of data stored in a device information storage unit according to the first embodiment. [Figure 5] FIG. 4 is a diagram illustrating an example of data in an erasure program storage unit in the first embodiment. [Figure 6] FIG. 4 is a diagram illustrating an example of data in an erasure result storage unit in the first embodiment. [Figure 7] FIG. 2 is a first diagram illustrating an example of the operation of the information processing system according to the first embodiment. [Figure 8] FIG. 2 is a second diagram illustrating an example of the operation of the information processing system according to the first embodiment. [Figure 9] FIG. 10 is a functional block diagram illustrating an example of a functional configuration of an information processing system according to a second embodiment. [Figure 10] FIG. 11 is a first diagram illustrating an example of the operation of the information processing system according to the second embodiment. [Figure 11] FIG. 10 is a second diagram illustrating an example of the operation of the information processing system according to the second embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0016] A data erasure method, an information processing system, and an information processing device according to an embodiment of the present invention will be described below with reference to the drawings.
[0017] [First embodiment] FIG. 1 is a configuration diagram showing an example of an information processing system 100 according to the first embodiment. As shown in FIG. 1, the information processing system 100 includes a notebook PC 1 and a management server 5.
[0018] The notebook PC 1 is an information processing device with a built-in memory drive device (for example, an SSD 40 described later) and executes processing based on an OS (Operating System). The notebook PC 1 is, for example, a personal computer used by a company, and is an information processing device in the information processing system 100 from which data stored in the memory drive device (for example, an SSD 40 described later) is to be completely erased. The notebook PC 1 can be connected to a management server 5 via a network NW1. The detailed configuration of the notebook PC 1 will be described later.
[0019] The management server 5 is, for example, a server device managed by the manufacturer (manufacturer) of the notebook PC 1, and is connectable to the notebook PC 1 via the network NW1. The management server 5 is used for erasing data from a memory drive device (for example, an SSD 40 described later) built into the notebook PC 1.
[0020] Next, the main hardware configuration of the notebook PC 1 will be described with reference to FIG. FIG. 2 is a diagram showing an example of the main hardware configuration of the notebook PC 1 according to this embodiment.
[0021] As shown in FIG. 2, the notebook PC 1 includes a CPU 11, a main memory 12, a video subsystem 13, a display unit 14, a chipset 21, a BIOS memory 22, a WLAN card 23, an embedded controller 31, an input unit 32, a power supply circuit 33, and an SSD 40.
[0022] In this embodiment, the CPU 11 and the chipset 21 correspond to the main control unit 10. The main control unit 10 is an example of a processor (main processor) that executes a program stored in a memory (main memory 12).
[0023] A CPU (Central Processing Unit) 11 executes various arithmetic processes under program control and controls the entire notebook PC 1.
[0024] The main memory 12 is a writable memory used as a read area for the execution program of the CPU 11 or as a work area for writing processing data for the execution program. The main memory 12 is composed of, for example, multiple DRAM (Dynamic Random Access Memory) chips. The execution program includes the BIOS, the OS, various drivers for operating peripheral devices, various service / utilities, application programs, etc.
[0025] The main memory 12 is an example of a system memory that stores programs and data, and is installed in the notebook PC 1 as a DIMM in which multiple DRAMs are mounted.
[0026] Video subsystem 13 is a subsystem for realizing functions related to image display, and includes a video controller. This video controller processes drawing commands from CPU 11, writes the processed drawing information to a video memory, and also reads the drawing information from the video memory and outputs it to display unit 14 as drawing data (display data).
[0027] The display unit 14 is, for example, a liquid crystal display, and displays a display screen based on the drawing data (display data) output from the video subsystem 13.
[0028] The chipset 21 includes controllers for USB, Serial ATA (AT Attachment), SPI (Serial Peripheral Interface) bus, PCI (Peripheral Component Interconnect) bus, PCI-Express bus, and LPC (Low Pin Count) bus, and multiple devices are connected to the chipset 21. In FIG. 2, an SSD 40, a BIOS memory 22, a WLAN card 23, and an embedded controller 31 are connected to the chipset 21 as examples of devices.
[0029] The BIOS memory 22 is configured by an electrically rewritable nonvolatile memory such as an EEPROM (Electrically Erasable Programmable Read Only Memory) or a flash ROM, etc. The BIOS memory 22 stores a BIOS program, a control program (firmware) for the embedded controller 31, etc.
[0030] The WLAN (Wireless Local Area Network) card 23 connects to the network NW1 via a wireless LAN to perform data communication. The WLAN card 23 can be connected to the management server 5 via the network NW1.
[0031] The embedded controller 31 (an example of a sub-controller) is a one-chip microcomputer that monitors and controls various devices (peripheral devices, sensors, etc.) regardless of the system state of the notebook PC 1. The embedded controller 31 also has a power management function that controls the power supply circuit 33. The embedded controller 31 is composed of a CPU, ROM, RAM, etc. (not shown), and also has A / D input terminals for multiple channels, D / A output terminals, a timer, and digital input / output terminals. The embedded controller 31 is connected to, for example, an input unit 32 and a power supply circuit 33 via these input / output terminals, and the embedded controller 31 controls the operations of these devices.
[0032] The input unit 32 is an input device such as a keyboard, a pointing device, or a touchpad.
[0033] The power supply circuit 33 includes, for example, a DC / DC converter, a charge / discharge unit, a battery unit, an AC / DC adapter, etc., and converts the DC voltage supplied from the AC / DC adapter or the battery unit into multiple voltages required to operate the notebook PC 1. The power supply circuit 33 also supplies power to each component of the notebook PC 1 under the control of the embedded controller 31.
[0034] The SSD 40 (an example of a memory drive device) stores an OS, various drivers, various services / utilities, application programs, and various data. The SSD 40 is connected to the chipset 21 via, for example, a serial ATA or a PCI-Express bus. The SSD 40 may also be connected to the CPU 11. In this embodiment, the SSD 40 is connected to the chipset 21 via an NVMe connection using a PCI-Express bus. The SSD 40 also includes a plurality of flash memories 41 and a memory controller 42 .
[0035] The flash memory 41 is, for example, a NAND flash memory, which is an example of a rewritable nonvolatile memory. Data can be erased from the flash memory 41 in page units or block units.
[0036] The memory controller 42 is a processor including, for example, a CPU, a ROM, a RAM, etc. (not shown), and performs overall control of the SSD 40. The memory controller 42 performs processes such as control processing of a host interface (host I / F) with the chipset 21, control processing of a memory interface (memory I / F) with the flash memory 41, and data management processing of the flash memory 41.
[0037] Next, the functional configuration of the information processing system 100 according to this embodiment will be described with reference to FIG. Fig. 3 is a functional block diagram showing an example of the functional configuration of the information processing system 100 according to this embodiment. Note that Fig. 3 shows only the configuration related to the present invention among the various functional configurations provided in the information processing system 100.
[0038] As shown in FIG. 3, the information processing system 100 includes a notebook PC 1 and a management server 5. The management server 5 includes a NW communication unit 51, a server storage unit 52, and a server control unit 53.
[0039] The NW (Network) communication unit 51 is, for example, a network adapter that can be connected to a network NW1 via a wired LAN or the like, and can be connected to the notebook PC 1 via the network NW1.
[0040] The server storage unit 52 is a storage unit realized by, for example, a RAM, an SSD, an HDD, etc., and stores various information used by the management server 5. The server storage unit 52 includes a device information storage unit 521, a key information storage unit 522, an erasure program storage unit 523, a command storage unit 524, and an erasure result storage unit 525.
[0041] The device information storage unit 521 stores device information of each notebook PC 1 manufactured and shipped by a manufacturer. The device information storage unit 521 stores, for example, the serial number of the notebook PC 1, the product model name, the public key of the notebook PC 1 (PC public key), etc. Here, the device information storage unit 521 will be described with reference to FIG. 4.
[0042] FIG. 4 is a diagram showing an example of data stored in the device information storage unit 521 in this embodiment. As shown in FIG. 4, the device information storage unit 521 stores a serial number, a product model name, an SSD model name, and a public key in association with each other.
[0043] Here, the manufacturing number is an example of identification information for identifying the notebook PC 1, and is a serial number assigned at the time of manufacturing the notebook PC 1. Furthermore, the product model name indicates the product model name or product name of the notebook PC 1, and the SSD model name indicates the model name or model name of the SSD 40 installed in the notebook PC 1. Furthermore, the public key here indicates the PC public key.
[0044] The PC public key is a public key of public key cryptography assigned to the notebook PC 1, and forms a key pair with a private key (PC private key) similarly assigned to the notebook PC 1. The key pair of the PC public key and PC private key is assigned when the notebook PC 1 is manufactured, and one key pair is assigned to one notebook PC PO1. Examples of public key cryptography include RSA cryptography and elliptic curve cryptography.
[0045] In the example shown in Figure 4, the notebook PC1 with the serial number "XXXXXXX" has a manufacturing model name of "XPCXYZ-XX" and an SSD model name of "SSDXXXXX". It also shows that the public key (PC public key) of the notebook PC1 is "PUBKEY1".
[0046] Returning to the explanation of FIG. 3, the key information storage unit 522 stores a key pair of the management server 5's private key (server private key) and public key (server public key). In this embodiment, the server private key and server public key are an example of a first private key and a first public key, and the PC private key and PC public key are an example of a second private key and a second public key.
[0047] The erasure program storage unit 523 stores a data erasure program to be installed in the SSD 40. The data erasure program is a program that can be executed by the SSD 40, and completely and automatically erases data stored in the SSD 40. Note that the erasure program storage unit 523 may change the data erasure program for each model name (model name) of the SSD 40, for example. Here, an example of data in the erasure program storage unit 523 will be described with reference to FIG. 5.
[0048] The data erasure program is, for example, the latest firmware for the SSD 40 provided by the vendor of the SSD 40, and may be firmware for the data erasure program or firmware for the entire SSD 40 including the data erasure program.
[0049] FIG. 5 is a diagram showing an example of data in the erasure program storage unit 523 in this embodiment. As shown in FIG. 5, the erasure program storage unit 523 stores the SSD model name and the data erasure program in association with each other. In the example shown in FIG. 5, the erasure program storage unit 523 stores "PRGA" as the data erasure program corresponding to the SSD model name "SSDXXXXX", and stores "PRGB" as the data erasure program corresponding to the SSD model name "SSDYYYYY".
[0050] 3, the command storage unit 524 stores an erasure command to be sent to the SSD 40 when erasing data in the SSD 40 using the data erasure program. The command storage unit 524 may store, for example, an SSD model name and command information indicating the erasure command in association with each other.
[0051] The erasure result storage unit 525 stores the data erasure result, which is the execution result when the above-mentioned data erasure program is executed in the SSD 40 of the notebook PC 1. Here, an example of data in the erasure result storage unit 525 will be described with reference to FIG.
[0052] FIG. 6 is a diagram showing an example of data stored in the erasure result storage unit 525 in this embodiment. As shown in FIG. 6, the erasure result storage unit 525 stores, for example, a serial number, an erasure date and time, and an erasure result in association with each other.
[0053] Here, the serial number is the serial number of the notebook PC 1, and the erasure date and time is the execution date and time of the data erasure program. Furthermore, the erasure result is information indicating the execution result of the data erasure program, and may include, for example, an error code if erasure has failed.
[0054] In the example shown in Figure 6, a data erasure program was executed on SSD 40 of notebook PC 1 with serial number "XXXXXXX" at "2024 / 09 / 15 10:00:00" (10:00 on September 15, 2024), and the erasure result is "erasure completed."
[0055] Furthermore, it indicates that a data erasure program was executed on SSD 40 of notebook PC 1 with serial number "YYYYYYY" at "2024 / 09 / 15 11:00:00" (11:00 on September 15, 2024), and the erasure result was "Erasure failed (error code: XXX)."
[0056] 3, the server control unit 53 is a functional unit that is realized, for example, by causing a CPU (not shown) to execute a program stored in the server storage unit 52. The server control unit 53 executes various processes for registering information stored in the device information storage unit 521, erasing data stored in the SSD 40 of the notebook PC 1, and the like. The server control unit 53 includes an erasure program transmission processing unit 531 , a command transmission processing unit 532 , and an erasure result storage processing unit 533 .
[0057] The erasure program transmission processing unit 531 executes a first transmission process for transmitting a data erasure program for the SSD 40 to the notebook PC 1 by using encryption processing with a server private key, which is the private key of the management server 5. The erasure program transmission processing unit 531 acquires a data erasure program corresponding to the notebook PC 1 (SSD 40) that is the target of data erasure from the erasure program storage unit 523. That is, the erasure program transmission processing unit 531 acquires a data erasure program corresponding to the serial number of the notebook PC 1 that is the target of data erasure from the erasure program storage unit 523.
[0058] The erasure program transmission processing unit 531 generates a digital signature for the data erasure program from the acquired data erasure program using the server private key stored in the key information storage unit 522. The erasure program transmission processing unit 531 generates a hash value for the data erasure program using, for example, a hash function, and encrypts the hash value using the server private key with public key encryption to generate a digital signature for the data erasure program.
[0059] The erasure program transmission processing unit 531 adds a digital signature to the data erasure program and transmits it to the notebook PC 1 via the NW communication unit 51.
[0060] The command transmission processing unit 532 executes a second transmission process using encryption processing with a server private key to transmit an erasure command that causes a processor (e.g., memory controller 42) of SSD 40 to execute a data erasure program to the notebook PC 1. The erasure program transmission processing unit 531 acquires, from the command storage unit 524, an erasure command that corresponds to the notebook PC 1 (SSD 40) that is the target of data erasure.
[0061] The command transmission processing unit 532 generates a digital signature for the acquired erase command using the server private key stored in the key information storage unit 522. The command transmission processing unit 532 generates a hash value for the erase command using, for example, a hash function, and encrypts the hash value using the server private key with public key encryption to generate a digital signature for the erase command.
[0062] The command transmission processing unit 532 adds a digital signature to the erase command and transmits it to the notebook PC 1 via the NW communication unit 51 .
[0063] The erasure result storage processing unit 533 confirms the legitimacy of the data erasure result using the PC public key (second public key), which is the public key of the notebook PC 1, and if the legitimacy of the data erasure result is confirmed, performs a result storage process to store the data erasure result whose legitimacy has been confirmed in the erasure result memory unit 525.
[0064] When the erasure result storage processing unit 533 receives the data erasure result and the digital signature from the laptop PC 1 via the NW communication unit 51, it generates a hash value of the data erasure result using, for example, a hash function. The erasure result storage processing unit 533 also executes a public key encryption decryption process using the PC public key to decrypt the received digital signature and generate a decrypted value (hash value) of the digital signature. The erasure result storage processing unit 533 also obtains the PC public key corresponding to the serial number of the laptop PC 1 to be erased from the device information storage unit 521.
[0065] The erasure result storage processing unit 533 determines the validity of the data erasure result based on whether the hash value of the generated data erasure result matches the decrypted value (hash value) of the electronic signature. If the hash value of the generated data erasure result matches the decrypted value (hash value) of the electronic signature, the erasure result storage processing unit 533 determines that the data erasure result is valid and stores the data erasure result in the erasure result storage unit 525. For example, as shown in FIG. 6, the erasure result storage processing unit 533 associates the serial number, erasure date and time, and erasure result and stores them in the erasure result storage unit 525.
[0066] Furthermore, if the hash value of the generated data erasure result does not match the decrypted value (hash value) of the digital signature, the erasure result storage processor 533 determines that the data erasure result is invalid and executes abnormal termination processing. For example, as abnormal termination processing, the erasure result storage processor 533 notifies the administrator of the notebook PC 1 (for example, by email) that an abnormality has occurred that causes the data erasure result to be invalid.
[0067] The notebook PC 1 includes a main control unit 10, an embedded controller 31, an SSD 40, and a NW communication unit 230. The NW communication unit 230 is a functional unit realized by, for example, the WLAN card 23, and can be connected to the management server 5 via the network NW1.
[0068] The main control unit 10 is a functional unit realized by causing the CPU 11 to execute programs stored in the SSD 40, the BIOS memory 22, the main memory 12, etc. The main control unit 10 executes processing based on the OS and BIOS. The main control unit 10 includes, for example, a BIOS processing unit 101 and an OS processing unit 102.
[0069] The BIOS processing unit 101 is a functional unit that is realized by causing the CPU 11 to execute a BIOS program stored in the BIOS memory 22, for example, and executes processing based on the BIOS.
[0070] The OS processing unit 102 is a functional unit that is realized by causing the CPU 11 to execute an OS program stored in the SSD 40, for example, and executes processing based on the OS.
[0071] When executing data erasure processing for the SSD 40, the embedded controller 31 communicates with the management server 5 and executes various processes for executing the data erasure processing for the SSD 40. The embedded controller 31 includes a key information storage unit 311, an installation processing unit 312, a data erasure processing unit 313, and an erasure result transmission processing unit 314.
[0072] The key information storage unit 311 is a storage unit realized by, for example, an internal storage unit of the embedded controller 31 or a firmware area of the embedded controller 31 in the BIOS memory 22, and stores key information such as the PC private key and the server public key. The key information storage unit 311 is a secure area that cannot be directly accessed from outside, such as the OS, and is realized by a security area that makes it impossible to illegally read the PC private key and the server public key from outside. The key information stored in the key information storage unit 311 is stored, for example, when the notebook PC 1 is manufactured.
[0073] The installation processing unit 312 confirms the legitimacy of the data erasure program using a server public key (first public key), which is the public key of the management server 5, and if the legitimacy of the data erasure program is confirmed, performs an installation process to install the data erasure program, whose legitimacy has been confirmed, into the SSD 40.
[0074] When the installation processing unit 312 receives the data erasure program and the digital signature from the management server 5 via the NW communication unit 230, it generates a hash value of the data erasure program by using, for example, a hash function. Furthermore, the installation processing unit 312 executes a public key encryption decryption process on the received digital signature using the server public key stored in the key information storage unit 311, and generates a decrypted value (hash value) of the digital signature.
[0075] The installation processing unit 312 determines the legitimacy of the data erasure program based on whether the hash value of the generated data erasure program matches the decrypted value (hash value) of the electronic signature. If the hash value of the generated data erasure program matches the decrypted value (hash value) of the electronic signature, the installation processing unit 312 determines that the data erasure program is legitimate and installs the data erasure program in the SSD 40.
[0076] The installation processing unit 312 transmits the data erasure program to the SSD 40 via the BIOS processing unit 101 (BIOS) and causes the SSD 40 to install the latest data erasure program.
[0077] Furthermore, if the hash value of the generated data erasure program does not match the decrypted value (hash value) of the digital signature, the installation processing unit 312 determines that the data erasure program is invalid and executes abnormal termination processing. As the abnormal termination processing, the installation processing unit 312, for example, stops the data erasure processing of the SSD 40 and notifies the management server 5 of the abnormal termination.
[0078] The data erasure processing unit 313 uses the server public key to confirm the validity of the erasure command, and if the validity of the erasure command is confirmed, it sends the confirmed validity erasure command to the SSD 40 and executes the data erasure process by executing the data erasure process using the data erasure program.
[0079] When the data erasure processing unit 313 receives an erasure command and a digital signature from the management server 5 via the NW communication unit 230, it generates a hash value of the erasure command using, for example, a hash function. Furthermore, the data erasure processing unit 313 executes a public key encryption decryption process on the received digital signature using the server public key stored in the key information storage unit 311, and generates a decrypted value (hash value) of the digital signature.
[0080] The data erasure processing unit 313 determines the validity of the erasure command based on whether the hash value of the generated erasure command matches the decrypted value (hash value) of the electronic signature. If the hash value of the generated erasure command matches the decrypted value (hash value) of the electronic signature, the installation processing unit 312 determines that the erasure command is valid and sends the erasure command to the SSD 40.
[0081] The data erasure processing unit 313 transmits an erasure command to the SSD 40 via the BIOS processing unit 101 (BIOS), and causes the SSD 40 to execute a data erasure process according to a data erasure program.
[0082] Furthermore, if the hash value of the generated erase command does not match the decrypted value (hash value) of the digital signature, the data erasure processing unit 313 determines that the erase command is invalid and executes abnormal termination processing. As the erase command abnormal termination processing, for example, the data erasure processing of the SSD 40 is stopped and the management server 5 is notified of the abnormal termination.
[0083] The erasure result transmission processing unit 314 executes a third transmission process to transmit the data erasure result, which is the result of the data erasure process, to the management server 5 using encryption processing with the PC private key (second private key), which is the private key of the notebook PC 1.
[0084] The erasure result transmission processing unit 314 acquires the data erasure result, which is the execution result of the erasure command, from the SSD 40 via the BIOS processing unit 101 (BIOS), and generates a hash value of the acquired data erasure result using, for example, a hash function. The erasure result transmission processing unit 314 encrypts the generated hash value using public key cryptography with the PC private key stored in the key information storage unit 311, and generates a digital signature of the data erasure result.
[0085] The erasure result transmission processing unit 314 adds a digital signature to the data erasure result and transmits it to the management server 5 via the NW communication unit 230.
[0086] The SSD 40 includes a memory controller 42 and a data storage unit 410 . The data storage unit 410 is a storage unit realized by the above-mentioned plurality of flash memories 41, and is a storage unit that is the target of the data erasure process.
[0087] The memory controller 42 includes a memory management unit 421 , a command processing unit 422 , and a command program storage unit 423 . The command program storage unit 423 is a storage unit realized by, for example, RAM and ROM (such as a flash memory) built into the memory controller 42, and the flash memory 41 of the SSD, and stores a command processing program installed from the outside. For example, when a data erasure program is installed in the SSD 40, the command program storage unit 423 stores the data erasure program.
[0088] The memory management unit 421 is a functional unit realized by a CPU (processor) (not shown) or the like of the memory controller 42, and manages the data storage unit 410.
[0089] The command processing unit 422 is a functional unit realized by a CPU (processor) (not shown) or the like of the memory controller 42, and executes various command processes for the SSD 40. For example, when the command processing unit 422 receives an erasure command from the data erasure processing unit 313 via the BIOS processing unit 101 (BIOS), the command processing unit 422 executes the data erasure process of the data storage unit 410 by executing a data erasure program stored in the command program storage unit 423.
[0090] Next, the operation of the information processing system 100 according to this embodiment will be described with reference to the drawings. 7 and 8 are diagrams showing an example of the operation of the information processing system 100 according to this embodiment.
[0091] 7 and 8, first, the management server 5 generates a digital signature for the data erasure program using the server private key (step S101). The erasure program transmission processing unit 531 of the management server 5 acquires the data erasure program corresponding to the notebook PC 1 (SSD 40) that is the target of data erasure from the erasure program storage unit 523. The erasure program transmission processing unit 531 generates a hash value of the data erasure program using, for example, a hash function, and performs public key encryption processing on the hash value using the server private key to generate a digital signature for the data erasure program.
[0092] The management server 5 may start the processing of step S101 in response to a request from the notebook PC 1 from which data is to be erased, or the management server 5 may start the processing of step S101 in response to a request from an administrator of the notebook PC 1, or when an execution condition (for example, a set date and time) is met. The data erasure program may also be the latest firmware for the SSD 40 provided by the SSD 40 vendor.
[0093] Next, the management server 5 transmits the data erasure program and the electronic signature to the embedded controller 31 of the notebook PC 1 (step S102). The erasure program transmission processing unit 531 transmits the data erasure program and the electronic signature to the notebook PC 1 (embedded controller 31) via the NW communication unit 51.
[0094] Next, the embedded controller 31 verifies the digital signature of the data erasure program using the server public key (step S103). When the installation processing unit 312 of the embedded controller 31 receives the data erasure program and the digital signature from the management server 5 via the NW communication unit 230, the installation processing unit 312 generates a hash value of the data erasure program using, for example, a hash function. The installation processing unit 312 also executes a public key encryption decryption process on the received digital signature using the server public key stored in the key information storage unit 311 to generate a decrypted value (hash value) of the digital signature. The installation processing unit 312 verifies the legitimacy of the data erasure program based on whether the generated hash value of the data erasure program matches the decrypted value (hash value) of the digital signature.
[0095] Next, the installer 312 determines whether the data erasure program is authentic (step S104). If the hash value of the generated data erasure program matches the decrypted value (hash value) of the digital signature, the installer 312 determines that the data erasure program is authentic (step S104: YES), and proceeds to step S105. If the installer 312 determines that the data erasure program is not authentic (step S104; NO), the installer 312 proceeds to step S108, and executes abnormal termination processing.
[0096] In step S105, the embedded controller 31 transmits the data erasure program to the BIOS processing unit 101 (BIOS), and the BIOS processing unit 101 (BIOS) transmits the data erasure program to the SSD 40 (step S106).
[0097] Next, the memory controller 42 of the SSD 40 installs the data erasure program (step S106). The memory controller 42 stores the data erasure program received from the installation processing unit 312 via the BIOS in the command program storage unit 423, installs the program, and makes the erasure command executable.
[0098] Next, the SSD 40 transmits an installation completion notification to the BIOS processing unit 101 (BIOS) (step S109), and the BIOS processing unit 101 (BIOS) transfers the installation completion notification to the embedded controller 31 (step S110). Next, the embedded controller 31 transmits a notification of completion of the installation to the management server 5 via the NW communication unit 230 (step S111).
[0099] Next, the management server 5 generates a digital signature for the erase command using the server private key (step S112). The command transmission processing unit 532 of the management server 5 acquires the erase command corresponding to the notebook PC 1 (SSD 40) that is the target of data erasure from the command storage unit 524. The command transmission processing unit 532 generates a hash value of the erase command using, for example, a hash function, and encrypts the hash value using public key encryption with the server private key to generate a digital signature for the erase command.
[0100] Next, the management server 5 transmits the erase command and the electronic signature to the embedded controller 31 of the notebook PC 1 (step S113). The command transmission processing unit 532 transmits the erase command and the electronic signature to the notebook PC 1 (embedded controller 31) via the NW communication unit 51.
[0101] Next, the embedded controller 31 verifies the digital signature of the erase command using the server public key (step S114). When the data erasure processing unit 313 of the embedded controller 31 receives the erase command and the digital signature from the management server 5 via the NW communication unit 230, it generates a hash value of the erase command using, for example, a hash function. The data erasure processing unit 313 also executes a public key encryption decryption process on the received digital signature using the server public key stored in the key information storage unit 311 to generate a decrypted value (hash value) of the digital signature. The data erasure processing unit 313 verifies the legitimacy of the erase command based on whether the generated hash value of the erase command matches the decrypted value (hash value) of the digital signature.
[0102] Next, the data erasure processing unit 313 determines whether the erasure command is valid (step S115). If the hash value of the generated erasure command matches the decrypted value (hash value) of the digital signature, the data erasure processing unit 313 determines that the erasure command is valid (step S115: YES), and proceeds to step S116. On the other hand, if the data erasure processing unit 313 determines that the erasure command is invalid (step S115; NO), it proceeds to step S119 and executes abnormal termination processing.
[0103] In step S116, the embedded controller 31 transmits the erase command to the BIOS processing unit 101 (BIOS), and the BIOS processing unit 101 (BIOS) transmits the erase command to the SSD 40 (step S117).
[0104] Next, the command processing unit 422 of the SSD 40 executes a data erasure process for the SSD 40 (step S118). In response to the received erasure command, the command processing unit 422 executes a data erasure program stored in the command program storage unit 423, and completely erases the data in the data storage unit 410.
[0105] Next, the command processing unit 422 transmits the data erasure result, which is the execution result of the erasure command, to the BIOS processing unit 101 (BIOS) (step S120), and the BIOS processing unit 101 (BIOS) transfers the data erasure result to the embedded controller 31 (step S121).
[0106] Next, the erasure result transmission processing unit 314 of the embedded controller 31 generates a digital signature of the data erasure result using the PC private key (step S122). The erasure result transmission processing unit 314 generates a hash value of the acquired data erasure result using, for example, a hash function, and encrypts the generated hash value using public key cryptography with the PC private key stored in the key information storage unit 311 to generate a digital signature of the data erasure result.
[0107] Next, the erasure result transmission processing unit 314 transmits the data erasure result and the digital signature to the management server 5 (step S123). The erasure result transmission processing unit 314 adds the digital signature to the data erasure result and transmits it to the management server 5 via the NW communication unit 230.
[0108] Next, the management server 5 verifies the digital signature of the data erasure result using the PC public key (step S124). The management server 5 generates a hash value of the data erasure result using, for example, a hash function. The erasure result storage processing unit 533 then executes a public key encryption decryption process using the PC public key to decrypt the received digital signature, generating a decrypted value (hash value) of the digital signature. The erasure result storage processing unit 533 verifies the validity of the data erasure result based on whether the generated hash value of the data erasure result matches the decrypted value (hash value) of the digital signature.
[0109] The erasure result storage processing unit 533 determines whether the data erasure result is valid (step S125). If the generated hash value of the data erasure result matches the decrypted value (hash value) of the digital signature, the erasure result storage processing unit 533 determines that the data erasure result is valid (step S125: YES) and proceeds to step S126. On the other hand, if the erasure result storage processing unit 533 determines that the data erasure result is invalid (step S125; NO), the erasure result storage processing unit 533 proceeds to step S127 and executes abnormal termination processing.
[0110] In step S126, the erasure result storage processing unit 533 stores the data erasure result in the erasure result storage unit 525. For example, as shown in FIG. 6, the erasure result storage processing unit 533 associates the serial number, erasure date and time, and erasure result, and stores them in the erasure result storage unit 525.
[0111] 7 and 8, the processes of steps S101 and S102 correspond to a first transmission step, the processes of steps S112 and S113 correspond to a second transmission step, and the processes of steps S122 and S123 correspond to a third transmission step.
[0112] The processes from step S103 to step S106 (or step S107) correspond to the installation step, the processes from step S114 to step S117 (or step S118) correspond to the data erasure step, and the processes from step S124 to step S126 correspond to the result storage step.
[0113] As described above, the data erasure method according to this embodiment is a data erasure method for a notebook PC 1 (information processing device) having a built-in SSD 40 (memory drive device), and includes a first transmission step, an installation step, a second transmission step, and a data erasure step. In the first transmission step, the management server 5 managing the notebook PC 1 transmits a data erasure program for the SSD 40 to the notebook PC 1 using encryption processing with a server private key (first private key), which is the private key of the management server 5. In the installation step, the notebook PC 1 confirms the authenticity of the data erasure program using a server public key (first public key), which is the public key of the management server 5, and if the authenticity of the data erasure program is confirmed, installs the confirmed data erasure program into the SSD 40. In the second transmission step, the management server 5 uses encryption processing with the server private key to transmit an erasure command to the notebook PC 1, causing a processor in the SSD 40 to execute the data erasure program. In the data erasure step, the notebook PC 1 uses the server public key to verify the validity of the erasure command, and if the validity of the erasure command is verified, the notebook PC 1 transmits the verified erase command to the SSD 40, causing the SSD 40 to execute the data erasure process using the data erasure program.
[0114] As a result, the data erasure method according to this embodiment uses the management server 5 to erase data from the SSD 40 using a data erasure program and an erasure command whose legitimacy is ensured by a server private key (first private key) and a server public key (first public key), so that data can be reliably erased and reliability can be guaranteed when erasing data from the SSD 40. For example, when a notebook PC 1 used by a company is disposed of, the data erasure method according to this embodiment can guarantee that the data in the SSD 40 built into the notebook PC 1 has been completely erased.
[0115] The data erasure method according to this embodiment also includes a third transmission step and a result storage step. In the third transmission step, the laptop PC 1 (erasure result transmission processor 314) transmits the data erasure result, which is the result of the data erasure process (erasure command), to the management server 5 using encryption processing with a PC private key (second private key), which is the private key of the laptop PC 1. In the result storage step, the management server 5 confirms the legitimacy of the data erasure result using a PC public key (second public key), which is the public key of the laptop PC 1, and if the legitimacy of the data erasure result is confirmed, stores the confirmed data erasure result in the erasure result storage unit 525.
[0116] As a result, the data erasure method according to this embodiment allows the management server 5 to store the data erasure results with guaranteed reliability, and this can be used as evidence to prove that the data on the SSD 40 of the notebook PC 1 has been completely erased, for example, when a company disposes of the notebook PC 1 that it has used.
[0117] In this embodiment, the notebook PC 1 is also provided with an embedded controller 31 (sub-controller) which is a sub-controller that can operate independently of the main control unit 10 that executes processes based on the OS and BIOS, is a secure area that is not directly accessible from the outside, and has a security area that stores at least a server public key and a PC private key. In the installation step and data erasure step, the embedded controller 31 verifies the legitimacy of the data erasure program and the erasure command, and the notebook PC 1 transmits the data erasure program and the erasure command to the SSD 40 via the embedded controller 31 and the BIOS.
[0118] As a result, the data erasure method according to this embodiment operates independently of the main control unit 10 and uses the embedded controller 31 (sub-control unit) having a security area to verify the legitimacy of the data erasure program and erasure command, thereby further reducing the possibility of data erasure being performed using an unauthorized data erasure program and erasure command, for example. Therefore, the data erasure method according to this embodiment can erase data more reliably and ensure even higher reliability when erasing data from the SSD 40.
[0119] In this embodiment, in the third transmission step, the embedded controller 31 transmits the data erasure result to the management server 5 using encryption processing with the PC private key.
[0120] As a result, the data erasure method according to this embodiment can further improve the reliability of the data erasure results by using the embedded controller 31.
[0121] In this embodiment, in the first transmission step and the second transmission step, the management server 5 generates signature information (e.g., a digital signature) for the transmission data using encryption processing with the server private key, attaches the signature information (e.g., the digital signature) to the transmission data for which the signature information has been generated, and transmits the data to the laptop PC 1. In the installation step and the data erasure step, the laptop PC 1 verifies the legitimacy of the data erasure program and the erasure command based on the signature information (e.g., the digital signature) and the server public key. In the third transmission step, the laptop PC 1 generates signature information (e.g., a digital signature) for the data erasure result using encryption processing with the PC private key, attaches the signature information to the data erasure result, and transmits the data erasure result to the management server 5. In the result storage step, the management server 5 verifies the legitimacy of the data erasure result based on the signature information (e.g., the digital signature) for the data erasure result and the PC public key.
[0122] As a result, the data erasure method according to this embodiment can verify the legitimacy of the data erasure program and erasure command, and the legitimacy of the data erasure results, without imposing a heavy processing load, by using signature information (e.g., an electronic signature).
[0123] In this embodiment, the memory drive device is an SSD 40. As a result, the data erasure method according to this embodiment can reliably erase data from the SSD 40, ensuring reliability.
[0124] The information processing system 100 according to this embodiment includes a notebook PC 1 incorporating an SSD 40 and a management server 5 that manages the notebook PC 1. The management server 5 executes a first transmission process and a second transmission process. In the first transmission process, the management server 5 transmits a data erasure program for the SSD 40 to the notebook PC 1 using encryption processing with a server private key, which is the private key of the management server 5. In the second transmission process, the management server 5 transmits an erasure command to the notebook PC 1 using encryption processing with the server private key, which causes the processor of the SSD 40 to execute the data erasure program. The notebook PC 1 also executes an installation process and a data erasure process. In the installation process, the notebook PC 1 confirms the authenticity of the data erasure program using a server public key, which is the public key of the management server 5. If the authenticity of the data erasure program is confirmed, the notebook PC 1 installs the confirmed authentic data erasure program into the SSD 40. In the data erasure process, the notebook PC 1 uses the server public key to verify the validity of the erasure command, and if the validity of the erasure command is verified, it sends the verified erase command to the SSD 40, causing the SSD 40 to execute the data erasure process using the data erasure program.
[0125] As a result, the information processing system 100 according to this embodiment has the same effect as the data erasure method described above, and when erasing data from the SSD 40, the data can be erased reliably and reliability can be ensured.
[0126] Furthermore, the notebook PC 1 (information processing device) according to this embodiment is a notebook PC 1 of an information processing system including the notebook PC 1 with a built-in SSD 40 and a management server 5 that manages the notebook PC 1, and includes an installation processing unit 312 and a data erasure processing unit 313. The installation processing unit 312 acquires a data erasure program for the SSD 40 transmitted by the management server 5 using encryption processing with a server private key, which is the secret key of the management server 5, verifies the legitimacy of the data erasure program using a server public key, which is the public key of the management server 5, and, if the legitimacy of the data erasure program is confirmed, installs the confirmed data erasure program into the SSD 40. The data erasure processing unit 313 acquires an erasure command transmitted by the management server 5 using encryption processing with the server private key to cause the processor of the SSD 40 to execute the data erasure program, verifies the legitimacy of the erasure command using the server public key, and, if the legitimacy of the erasure command is confirmed, transmits the confirmed erasure command to the SSD 40, causing the SSD 40 to execute the data erasure process using the data erasure program.
[0127] As a result, the notebook PC 1 (information processing device) according to this embodiment has the same effects as the data erasure method and information processing system 100 described above, and can reliably erase data from the SSD 40, ensuring reliability.
[0128] Next, an information processing system 100a according to a second embodiment will be described with reference to the drawings. In the second embodiment, a modified example will be described in which the processes of the installation processing unit 312, the data erasure processing unit 313, and the erasure result transmission processing unit 314 are executed by the BIOS processing unit 101a instead of the embedded controller 31.
[0129] [Second embodiment] Fig. 9 is a functional block diagram showing an example of the functional configuration of the information processing system 100a according to the first embodiment. Note that Fig. 9 shows only the configuration related to the present invention among the various functional configurations included in the information processing system 100a.
[0130] The configuration diagram of the information processing system 100a and the main hardware configuration of the notebook PC 1a of this embodiment are the same as those of the first embodiment shown in FIGS. 1 and 2, and therefore a description thereof will be omitted here. In addition, in FIG. 9, the same components as those in FIG. 3 described above are given the same reference numerals, and the description thereof will be omitted.
[0131] 9, the information processing system 100a includes a notebook PC 1a and a management server 5. The notebook PC 1a also includes a main control unit 10a, an embedded controller 31a, an SSD 40, and a NW communication unit 230.
[0132] The main control unit 10a is a functional unit realized by causing the CPU 11 to execute programs stored in the SSD 40, the BIOS memory 22, the main memory 12, etc. The main control unit 10a executes processing based on the OS and BIOS. The main control unit 10a includes, for example, a BIOS processing unit 101a and an OS processing unit 102.
[0133] The BIOS processing unit 101a is a functional unit that is realized, for example, by causing the CPU 11 to execute a BIOS program stored in the BIOS memory 22, and executes processing based on the BIOS. The BIOS processing unit 101a includes an installation processing unit 112, a data erasure processing unit 113, and an erasure result transmission processing unit 114.
[0134] The installation processing unit 112, data erasure processing unit 113, and erasure result transmission processing unit 114 perform the same processes as the installation processing unit 312, data erasure processing unit 313, and erasure result transmission processing unit 314 of the first embodiment.
[0135] When executing the data erasure process for the SSD 40, the embedded controller 31a communicates with the management server 5 and executes various processes for executing the data erasure process for the SSD 40. The embedded controller 31a includes a key information storage unit 311.
[0136] The embedded controller 31a is similar to the embedded controller 31 of the first embodiment, except that most of the functions of the installation processing unit 312, the data erasure processing unit 313, and the erasure result transmission processing unit 314 have been moved to the BIOS processing unit 101a.
[0137] Moreover, other functional configurations are the same as those in the first embodiment, and therefore descriptions thereof will be omitted here.
[0138] Next, the operation of the information processing system 100a according to this embodiment will be described with reference to the drawings. 10 and 11 are diagrams showing an example of the operation of the information processing system 100a according to this embodiment.
[0139] 10 and 11, the processes in steps S201 and S202 are the same as the processes in steps S101 and S102 shown in FIG. 7, and therefore, a description thereof will be omitted here.
[0140] Next, the embedded controller 31a transmits the received data erasure program and the digital signature to the BIOS processing unit 101a (step S203), whereby the installation processing unit 112 of the BIOS processing unit 101a receives the data erasure program and the digital signature.
[0141] Next, the BIOS processing unit 101a transmits a request to transmit the server public key information to the embedded controller 31a (step S204). The installation processing unit 112 requests the embedded controller 31a for the server public key information in order to verify the digital signature of the data erasure program.
[0142] Next, the embedded controller 31a transmits the server public key information to the BIOS processing unit 101a (step S205). The embedded controller 31a transmits the server public key stored in the key information storage unit 311 to the BIOS processing unit 101a as server public key information.
[0143] Next, the BIOS processing unit 101a verifies the digital signature of the data erasure program using the server public key (step S206). When the installation processing unit 112 receives the data erasure program and the digital signature, it generates a hash value of the data erasure program using, for example, a hash function. The installation processing unit 112 also executes a public key encryption decryption process using the server public key to decrypt the received digital signature, generating a decrypted value (hash value) of the digital signature. The installation processing unit 112 verifies the authenticity of the data erasure program based on whether the generated hash value of the data erasure program matches the decrypted value (hash value) of the digital signature.
[0144] Next, the installer 112 determines whether the data erasure program is authentic (step S207). If the hash value of the generated data erasure program matches the decrypted value (hash value) of the digital signature, the installer 112 determines that the data erasure program is authentic (step S207: YES), and proceeds to step S208. If the installer 112 determines that the data erasure program is not authentic (step S207; NO), the installer 112 proceeds to step S210 and executes abnormal termination processing, including discarding the server public key.
[0145] The subsequent processing from step S208 to step S215 is similar to the processing from step S106 to step S113 shown in FIG. 7, and therefore description thereof will be omitted here.
[0146] Next, in step S216, the embedded controller 31a transmits the erase command and the electronic signature to the BIOS processing unit 101a, whereby the data erasure processing unit 113 of the BIOS processing unit 101a receives the erase command and the electronic signature.
[0147] Next, the BIOS processing unit 101a transmits a request to transmit the server public key information to the embedded controller 31a (step S217). The data erasure processing unit 113 requests the embedded controller 31a for the server public key information in order to verify the digital signature of the data erasure program.
[0148] Next, the embedded controller 31a transmits the server public key information to the BIOS processing unit 101a (step S218). The embedded controller 31a transmits the server public key stored in the key information storage unit 311 to the BIOS processing unit 101a as server public key information.
[0149] Next, the BIOS processing unit 101a verifies the digital signature of the erase command using the server public key (step S219). When the data erasure processing unit 113 receives the erase command and the digital signature, it generates a hash value of the erase command using, for example, a hash function. The data erasure processing unit 113 also performs public key cryptography decryption processing on the received digital signature using the server public key to generate a decrypted value (hash value) of the digital signature. The data erasure processing unit 113 verifies the legitimacy of the erase command based on whether the generated hash value of the erase command matches the decrypted value (hash value) of the digital signature.
[0150] Next, the data erasure processing unit 113 determines whether the erasure command is valid (step S220). If the hash value of the generated erasure command matches the decrypted value (hash value) of the digital signature, the data erasure processing unit 113 determines that the erasure command is valid (step S220: YES), and proceeds to step S221. On the other hand, if the data erasure processing unit 113 determines that the erasure command is invalid (step S220; NO), it proceeds to step S223, and executes abnormal termination processing including discarding the server public key.
[0151] The subsequent processing from step S221 to step S225 is similar to the processing from step S117 to step S121 shown in FIG. 7, and therefore description thereof will be omitted here.
[0152] Next, in step S226, the embedded controller 31a generates a digital signature for the data erasure result using the PC private key. The embedded controller 31a generates a hash value for the acquired data erasure result using, for example, a hash function, and encrypts the generated hash value using public key cryptography with the PC private key stored in the key information storage unit 311 to generate a digital signature for the data erasure result.
[0153] Next, the embedded controller 31a transmits the electronic signature to the BIOS processing unit 101a (step S227).
[0154] Next, the erasure result transmission processing unit 114 of the BIOS processing unit 101a transmits the data erasure result and the digital signature to the embedded controller 31a (step S228), and the embedded controller 31a transmits the data erasure result and the digital signature to the management server 5 (step S229). The embedded controller 31a adds the digital signature to the data erasure result and transmits it to the management server 5 via the NW communication unit 230.
[0155] The subsequent processing from step S230 to step S233 is similar to the processing from step S124 to step S127 shown in FIG. 7, and therefore description thereof will be omitted here.
[0156] 10 and 11, the processes of steps S201 and S202 correspond to the first transmission step, the processes of steps S214 and S215 correspond to the second transmission step, and the processes of steps S226 to S229 correspond to the third transmission step.
[0157] The processes from step S204 to step S208 (or step S209) correspond to the installation step, the processes from step S217 to step S221 (or step S222) correspond to the data erasure step, and the processes from step S230 to step S232 correspond to the result storage step.
[0158] As described above, in the data erasure method and information processing system 100a according to this embodiment, instead of the embedded controller 31a, the BIOS processing unit 101a of the notebook PC 1a (information processing device) includes an installation processing unit 112, a data erasure processing unit 113, and an erasure result transmission processing unit 114.
[0159] As a result, the data erasure method and information processing system 100a according to this embodiment have the same effects as those of the first embodiment described above, and when erasing data from the SSD 40, data can be erased reliably and reliability can be ensured.
[0160] The present invention is not limited to the above-described embodiments, and can be modified within the scope of the present invention. For example, in each of the above embodiments, the information processing device is described as being a notebook personal computer (notebook PC 1 (1a)), but this is not limited to this and may be, for example, another information processing device such as a desktop personal computer or a tablet terminal device.
[0161] In addition, in each of the above embodiments, an example has been described in which the memory drive device is an SSD 40, but this is not limited to this and other memory drive devices such as a flash memory card may also be used. In addition, in the above embodiments, an example has been described in which the memory drive device is applied, but the present invention may also be applied to other drive devices such as an HDD (Hard Disk Drive).
[0162] In addition, in each of the above embodiments, examples have been described in which the legitimacy of the data erasure program, erasure command, and data erasure result is confirmed using a digital signature, but this is not limited to this, and the information processing system 100 (100a) may confirm the legitimacy using other authentication information, signature information, etc.
[0163] Alternatively, the information processing system 100 (100a) may use encryption and decryption processes to verify the authenticity of the data erasure program, erasure command, and data erasure result instead of using a digital signature. Alternatively, the information processing system 100 may exchange a common key between the management server 5 and the notebook PC 1 using, for example, a Diffie-Hellman key exchange method, and verify the authenticity of the data erasure program, erasure command, and data erasure result using common key encryption.
[0164] Each component of the information processing system 100 (100a) described above has an internal computer system. A program for implementing the functions of each component of the information processing system 100 (100a) described above may be recorded on a computer-readable recording medium, and the program recorded on the recording medium may be read into a computer system and executed to perform processing in each component of the information processing system 100 (100a) described above. Here, "reading a program recorded on a recording medium into a computer system and executing it" includes installing the program into a computer system. The term "computer system" used here includes hardware such as an OS and peripheral devices. Furthermore, a "computer system" may include multiple computer devices connected via a network, including communication lines such as the Internet, WAN, LAN, and dedicated lines. Furthermore, a "computer-readable recording medium" refers to portable media such as flexible disks, optical magnetic disks, ROMs, and CD-ROMs, as well as storage devices such as hard disks built into a computer system. Thus, the recording medium storing the program may be a non-transitory recording medium such as a CD-ROM.
[0165] The recording medium also includes internal or external recording media accessible from a distribution server for distributing the program. The program may be divided into multiple parts, downloaded at different times, and then combined by each component of the information processing system 100 (100a), or each divided program may be distributed by a different distribution server. Furthermore, the term "computer-readable recording medium" also includes a medium that stores a program for a certain period of time, such as volatile memory (RAM) within a computer system that serves as a server or client when a program is transmitted over a network. The program may also be a medium that realizes part of the above-described functions. Furthermore, the program may be a so-called differential file (differential program) that can realize the above-described functions in combination with a program already stored in the computer system.
[0166] Furthermore, some or all of the above-described functions may be realized as an integrated circuit such as an LSI (Large Scale Integration). Each of the above-described functions may be individually implemented as a processor, or some or all of the functions may be integrated into a processor. Furthermore, the integrated circuit implementation method is not limited to LSI, and may be implemented using a dedicated circuit or a general-purpose processor. Furthermore, if an integrated circuit implementation technology that can replace LSI emerges due to advances in semiconductor technology, an integrated circuit based on that technology may be used. [Explanation of symbols]
[0167] 1, 1a Notebook PC 5 Management Server 10, 10a Main control unit 11 CPU 12. Main memory 13 Video Subsystem 14 Display section 21 Chipset 22 BIOS memory 23 WLAN card 31, 31a Embedded Controller (EC) 32 Input section 33 Power circuit 40 SSD 41 Flash memory 42 Memory Controller 51, 230 Network Communications Department 52 Server storage unit 53 Server control unit 100, 100a Information Processing Systems 101, 101a BIOS processing unit 102 OS processing unit 311, 522 Key information storage unit 312, 112 Installation processing section 313, 113 Data erasure processing unit 314, 114 Erasure result transmission processing unit 410 Data storage unit 421 Memory Management Unit 422 command processing section 423 Command program memory unit 521 Device information storage unit 523 Erasing program memory unit 524 command memory section 525 Erasure result memory unit 531 Erase program transmission processing unit 532 Command transmission processing unit 533 Erasure result storage processing unit NW1 Network
Claims
1. A data erasure method for an information processing device having a built-in memory drive device, comprising: a first transmission step in which a management server that manages the information processing device transmits a data erasure program for the memory drive device to the information processing device using encryption processing with a first private key that is a private key of the management server; an installation step in which the information processing device confirms the authenticity of the data erasure program using a first public key that is a public key of the management server, and when the authenticity of the data erasure program is confirmed, installs the data erasure program whose authenticity has been confirmed into the memory drive device; a second transmission step in which the management server uses encryption processing with the first private key to transmit to the information processing device an erasure command that causes a processor of the memory drive device to execute the data erasure program; a data erasure step in which the information processing device uses the first public key to confirm the validity of the erase command, and when the validity of the erase command is confirmed, transmits the erase command whose validity has been confirmed to the memory drive device, and causes the memory drive device to execute a data erasure process by the data erasure program; Data erasure methods, including:
2. a third transmission step in which the information processing device transmits a data erasure result, which is a result of the data erasure process, to the management server using encryption processing with a second private key, which is a private key of the information processing device; a result storage step in which the management server confirms the validity of the data erasure result by using a second public key that is a public key of the information processing device, and when the validity of the data erasure result is confirmed, stores the data erasure result whose validity has been confirmed in an erasure result storage unit; The data erasure method according to claim 1 , comprising:
3. the information processing device includes a sub-controller that can operate independently of a main controller that executes processing based on an OS (Operating System) and a BIOS (Basic Input Output System), the sub-controller having a security area that is a safe area that cannot be directly accessed from outside and that stores at least the first public key and the second private key; In the installation step and the data erasure step, the sub-controller confirms the validity of the data erasure program and the erasure command, and transmits the data erasure program and the erasure command to the memory drive device via the sub-controller and the BIOS. The data erasure method according to claim 2 .
4. In the third transmission step, the sub-controller transmits the data erasure result to the management server using encryption processing with the second private key. The data erasure method according to claim 3.
5. In the first transmission step and the second transmission step, the management server generates signature information for the transmission data using encryption processing with the first private key, adds the signature information to the transmission data for which the signature information has been generated, and transmits the transmission data to the information processing device; In the installing step and the data erasing step, the information processing device confirms the legitimacy of the data erasure program and the erasure command based on the signature information and the first public key; In the third transmission step, the information processing device generates signature information for the data erasure result using encryption processing with the second private key, adds the signature information to the data erasure result, and transmits the data erasure result to the management server; In the result storage step, the management server verifies the validity of the data erasure result based on the signature information of the data erasure result and the second public key. The data erasure method according to any one of claims 2 to 4.
6. The memory drive device is an SSD (Solid State Drive). The data erasure method according to any one of claims 1 to 4.
7. An information processing device having a built-in memory drive device and a management server that manages the information processing device, The management server a first transmission process of transmitting a data erasure program for the memory drive device to the information processing device by using encryption processing with a first private key that is a private key of the management server; a second transmission process of transmitting, to the information processing device, an erasure command that causes a processor of the memory drive device to execute the data erasure program, using encryption processing with the first private key; Run The information processing device includes: an installation process for verifying the authenticity of the data erasure program using a first public key that is a public key of the management server, and, if the authenticity of the data erasure program is verified, installing the verified authentic data erasure program into the memory drive device; a data erasure process in which the authenticity of the erasure command is confirmed using the first public key, and when the authenticity of the erasure command is confirmed, the authenticity of the erasure command is transmitted to the memory drive device, and the data erasure process is executed by the data erasure program; Run Information processing system.
8. An information processing device of an information processing system including an information processing device having a built-in memory drive device and a management server that manages the information processing device, an installation processing unit that acquires the data erasure program for the memory drive device transmitted by the management server using encryption processing with a first private key that is a private key of the management server, confirms the legitimacy of the data erasure program using a first public key that is a public key of the management server, and, if the legitimacy of the data erasure program is confirmed, installs the data erasure program, whose legitimacy has been confirmed, into the memory drive device; a data erasure processing unit that uses encryption processing with the first private key to acquire an erasure command sent by the management server to cause a processor of the memory drive device to execute the data erasure program, uses the first public key to verify the legitimacy of the erasure command, and when the legitimacy of the erasure command is verified, sends the verified erasure command to the memory drive device to cause the memory drive device to execute data erasure processing with the data erasure program; An information processing device comprising:
Citation Information
Patent Citations
Data storage medium destruction system
CN118211279A
Data erasure system, management server, data erasure method and program
JP2003256283A
Platform type IC card and program for same
JP2009075913A
Data erasure program, data erasure method, computer having data erasure function and data erasure management server
JP2014115724A
Flash storage, computer, data erasure method for flash storage and flash storage control program
JP2020119361A