Electronic device, system, and method for erasing data stored in a storage device of an electronic device

The system uses a graphic code and pre-distributed keywords to reliably transmit erasure results from electronic devices to a server device, addressing communication and access variability issues and enhancing data security.

JP7777796B2Active Publication Date: 2025-12-01PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2022067100
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-04-14
Publication Date
2025-12-01
Estimated Expiration
2042-04-14

AI Technical Summary

Technical Problem

Existing systems fail to reliably notify a server device of the erasure results from storage devices in electronic devices due to communication line status and user access variability, leading to potential data leakage risks.

Method used

A system that includes an electronic device with a storage device, a server device, and a terminal device, utilizing a graphic code displayed on the electronic device to capture erasure completion information, which is then transmitted to the server device through a terminal device, ensuring reliable notification using pre-distributed keywords for verification.

Benefits of technology

Ensures reliable communication of erasure results to the server device, enhancing data security by preventing data leakage through guaranteed transmission of erasure completion information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007777796000001
    Figure 0007777796000001
  • Figure 0007777796000002
    Figure 0007777796000002
  • Figure 0007777796000003
    Figure 0007777796000003
Patent Text Reader

Abstract

To reliably notify server equipment of an erase result of a storage device.SOLUTION: A client device 1 erases data stored in a storage device 13 and displays a 2D barcode including erase completion information on a display device 16. A user terminal device 4 picks up an image of the 2D barcode, extracts the erase completion information from the 2D barcode, and transmits the erase completion information to a piece of server equipment 2. The server equipment 2 receives the erase completion information from the user terminal device 4, and reads a keyword from a storage device 23, and transmits the keyword to the user terminal device 4. The user terminal device 4 receives the keyword from the server equipment 2, and displays the keyword on a display device 46. The client device 1 acquires a keyword input via an input device 17, and when the keyword input via input device 17 matches the keyword stored in a storage device 14, shut down the client device 1.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to an electronic device, a system, and a method for erasing data stored on a storage device of an electronic device. [Background technology]

[0002] When an organization such as a company disposes of an electronic device such as a personal computer, it is required to erase the data stored in the storage device in order to prevent confidential business information from being leaked.

[0003] Patent Document 1 discloses a data erasure method in which a computer performs a data erasure process to erase data stored in a storage device of the computer, the data erasure process comprising a storage device, a display device, an arithmetic processing unit, and an input device. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Japanese Patent Application Publication No. 2018-136778 Summary of the Invention [Problem to be solved by the invention]

[0005] When an organization manages a large number of electronic devices, it may be required to report the results of erasure of the storage devices to an administrator (e.g., a server device accessible by the administrator) after data erasure is complete. However, due to factors such as the status of the communication line between the electronic device with the storage device to be erased and the server device, and the status of users who can access the electronic device with the storage device to be erased, it is not always possible to guarantee that the erasure results will be notified to the server device. Therefore, there is a need to more reliably notify the server device of the erasure results than before.

[0006] The present disclosure provides a system for erasing data stored in a storage device of an electronic device, which can more reliably notify a server device of the results of erasure from the storage device than in the past. The present disclosure also provides a method for operating such a system. The present disclosure also provides an electronic device that can more reliably notify a server device of the results of erasure from the storage device than in the past. [Means for solving the problem]

[0007] A system according to one aspect of the present disclosure is a system for erasing data stored in a storage device of at least one electronic device, the system including at least one electronic device, a server device, and a terminal device. The electronic device includes a first storage device that stores data to be erased, a second storage device that stores a first keyword, a first display device, and a first input device. The server device includes a third storage device that stores a second keyword. The terminal device includes a photographing device and a second display device. The electronic device erases the data stored in the first storage device and displays a graphic code including erasure completion information indicating that erasure of the data stored in the first storage device has been completed on the first display device. The terminal device photographs the graphic code using the photographing device, extracts the erasure completion information from the graphic code, and transmits the erasure completion information to the server device. The server device receives the erasure completion information from the terminal device, reads the second keyword from the third storage device, and transmits the second keyword to the terminal device. The terminal device receives the second keyword from the server device and displays the keyword on the second display device. The electronic device acquires a second keyword input via the first input device, and shuts down the electronic device if the second keyword input via the first input device matches the first keyword stored in the second storage device. [Effects of the Invention]

[0008] According to a system according to an aspect of the present disclosure, it is possible to notify a server device of the results of erasure of a storage device more reliably than in the past. [Brief explanation of the drawings]

[0009] [Figure 1] 1 is a schematic diagram showing the configuration of a system 100 according to a first embodiment. [Figure 2] 2 is a block diagram showing the configuration of a client device 1 in FIG. 1. FIG. [Figure 3] 2 is a block diagram showing the configuration of a server device 2 in FIG. 1. FIG. [Figure 4] FIG. 2 is a block diagram showing the configuration of an administrator device 3 in FIG. [Figure 5] FIG. 2 is a block diagram showing the configuration of a user terminal device 4 in FIG. [Figure 6] 3 is a schematic diagram showing the functional blocks of a firmware program 50 and an erase application program 70 executed by the processor 11 of FIG. 2. FIG. [Figure 7] FIG. 2 is a schematic diagram for explaining distribution of keywords in the system 100 of FIG. [Figure 8] 3 is a flowchart showing a registration process of the client device 1 by the erasure application program 70 executed by the processor 11 of FIG. 2. [Figure 9] 4 is a flowchart showing a registration process of the server device 2 by the erasure application program 92 executed by the processor 21 of FIG. 3. [Figure 10] 4 is a diagram showing exemplary contents of a management table stored in the memory 22 or the storage device 23 of FIG. 3. FIG. [Figure 11] 3 is a flowchart showing an erasure process of the client device 1 by an erasure application program 70 executed by the processor 11 of FIG. 2. [Figure 12] 3 is a flowchart showing erasure processing of the client device 1 by the firmware program 50 executed by the processor 11 of FIG. [Figure 13] 4 is a flowchart showing an erasure process of the server device 2 by an erasure application program 92 executed by the processor 21 of FIG. 3. [Figure 14]FIG. 13 is a diagram showing the content displayed on the display device 16 of the client device 1 in step S39 of FIG. [Figure 15] FIG. 14 is a diagram showing the content displayed on the display device 46 of the user terminal device 4 after a keyword is transmitted from the server device 2 to the user terminal device 4 in step S60 of FIG. [Figure 16] 1. FIG. 4 is a sequence diagram showing the operation of the system 100 in the case where the transmission of the erasure result information via the communication line 6 in the system 100 of FIG. 1 is successful. [Figure 17] 1. FIG. 4 is a sequence diagram showing the operation of the system 100 in the case where transmission of erasure result information via the communication line 6 in the system 100 of FIG. [Figure 18] FIG. 10 is a schematic diagram for explaining distribution of keywords in the system 100 according to the second embodiment. [Figure 19] 10 is a flowchart showing an erasure process of the client device 1 by an erasure application program 70 executed by the processor 11 of the client device 1 according to the second embodiment. [Figure 20] 10 is a flowchart showing erasure processing of the client device 1 by the firmware program 50 executed by the processor 11 of the client device 1 according to the second embodiment. [Figure 21] 10 is a flowchart showing an erasure process of the server device 2 according to the second embodiment, which is performed by an erasure application program 92 executed by the processor 21 of the server device 2. [Figure 22] FIG. 10 is a sequence diagram showing the operation of the system 100 according to the second embodiment when the transmission of erasure result information via the communication line 6 is successful. [Figure 23] FIG. 10 is a sequence diagram showing the operation of the system 100 according to the second embodiment when transmission of erasure result information via the communication line 6 fails. [Figure 24] FIG. 10 is a schematic diagram for explaining distribution of keywords in a system 100 according to a first modified example of the second embodiment. [Figure 25] FIG. 10 is a diagram showing the contents displayed on the display device 26 of the server device 2 according to a first modified example of the second embodiment. [Figure 26] 10 is a flowchart showing an erasure process of the server device 2 by an erasure application program 92 executed by the processor 21 of the server device 2 according to a second modification of the second embodiment. [Figure 27] FIG. 10 is a sequence diagram showing the operation of the system 100 according to the second modification of the second embodiment when the erasure result information is successfully transmitted via the communication line 6. [Figure 28] FIG. 10 is a sequence diagram showing the operation of the system 100 according to the second modification of the second embodiment when transmission of erasure result information via the communication line 6 fails. [Figure 29] FIG. 10 is a diagram showing exemplary contents of a keyword table stored in the memory 22 or storage device 23 of the server device 2 according to a second modified example of the second embodiment. [Figure 30] FIG. 10 is a diagram showing another exemplary content of the keyword table stored in the memory 22 or the storage device 23 of the server device 2 according to the second modified example of the second embodiment. [Figure 31] FIG. 10 is a schematic diagram for explaining distribution of keywords in the system 100 according to the third embodiment. [Figure 32] 10 is a flowchart showing erasure processing of the client device 1 by the erasure application program 70 executed by the processor 11 of the client device 1 according to the third embodiment. [Figure 33] 10 is a flowchart showing an erasure process of the server device 2 according to the third embodiment, which is performed by an erasure application program 92 executed by the processor 21 of the server device 2. [Figure 34] FIG. 10 is a sequence diagram showing the operation of the system 100 according to the third embodiment when the transmission of erasure result information via the communication line 6 is successful. [Figure 35]FIG. 10 is a sequence diagram showing the operation of the system 100 according to the third embodiment when transmission of erasure result information via the communication line 6 fails. [Figure 36] FIG. 10 is a diagram showing exemplary contents of a keyword table stored in the memory 22 or storage device 23 of the server device 2 of the third embodiment. [Figure 37] FIG. 10 is a schematic diagram for explaining distribution of keywords in the system 100 according to a first modified example of the third embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0010] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. However, more detailed description than necessary may be omitted. For example, detailed description of well-known matters or redundant description of substantially identical configurations may be omitted. This is to avoid unnecessary redundancy in the following description and to facilitate understanding by those skilled in the art.

[0011] The inventor(s) provide the accompanying drawings and the following description to enable those skilled in the art to fully understand the present disclosure, and do not intend for them to limit the subject matter described in the claims.

[0012] [First embodiment] [Configuration of the first embodiment]

[0013] 1 is a schematic diagram showing the configuration of a system 100 according to the first embodiment. The system 100 in FIG. 1 includes a plurality of client devices 1-1 to 1-3, a server device 2, an administrator device 3, a user terminal device 4, a base station device 5, and a communication line 6.

[0014] The client devices 1-1 to 1-3 are communicably connected to the server device 2 via a communication line 6. The client devices 1-1 to 1-3 are electronic devices equipped with a storage device (described later), such as a personal computer or a mobile phone. The client devices 1-1 to 1-3 are examples of electronic devices according to an embodiment.

[0015] In this specification, the client devices 1-1 to 1-3 are also collectively referred to as "client device 1."

[0016] The server device 2 manages the erasure of data stored in the storage device of each client device 1.

[0017] The administrator device 3 is communicably connected to the server device 2 via a communication line 6. The administrator of each client device 1 uses the administrator device 3 to access the server device 2 and specify the storage device from which stored data should be erased.

[0018] The user terminal device 4 is an electronic device, such as a mobile phone, that includes an image capturing device 48 and a communication device (described later). The user terminal device 4 is connected to the server device 2 via the base station device 5 so as to be able to communicate with the server device 2.

[0019] The communication line 6 is, for example, a local area network (LAN), the Internet, or a combination thereof.

[0020] For example, each client device 1 and administrator device 3 may be owned by an organization such as a company, while the server device 2 may be operated by a third party different from this organization. In this case, the organization that owns each client device 1 and administrator device 3 enters into a contract with the operator of server device 2 to manage the erasure of data stored in the storage device of each client device 1, and becomes a customer of this operator.

[0021] In this specification, "erasing" means overwriting the original stored data with other data, such as "0", "1", or random values, so that the original data cannot be read.

[0022] FIG. 2 is a block diagram showing the configuration of the client device 1 of FIG. 1. The client device 1 includes a bus 10, a processor 11, a memory 12, a storage device 13, a storage device 14, a communication device 15, a display device 16, and an input device 17. The processor 11 controls the overall operation of the client device 1 and, for example, erases data stored in the storage device 13. The memory 12 temporarily stores programs and data necessary for the operation of the client device 1. The storage device 13 stores data including an operating system (OS), multiple application programs (APPs), and user data. The storage device 13 is a non-volatile storage medium such as a hard disk drive (HDD) or a solid-state drive (SSD). The storage device 14 stores a firmware program for the client device 1, such as a UEFI (Unified Extensible Firmware Interface) or a BIOS (Basic Input / Output System) program. The storage device 14 is a non-volatile storage medium such as a flash memory. The communication device 15 is communicably connected to the server device 2 via a communication line 6. The display device 16 displays information related to the status of the client device 1, for example, graphical symbols including information related to erasure of data stored in the storage device 13. The input device 17 receives user input that controls the operation of the client device 1, for example, user input related to erasure of data stored in the storage device 13. The input device 17 includes, for example, a keyboard and a pointing device. The processor 11, the memory 12, the storage device 13, the storage device 14, the communication device 15, the display device 16, and the input device 17 are connected to each other via the bus 10.

[0023] FIG. 3 is a block diagram showing the configuration of the server device 2 of FIG. 1. The server device 2 includes a bus 20, a processor 21, a memory 22, a storage device 23, a communication device 25, a display device 26, and an input device 27. The processor 21 controls the overall operation of the server device 2 and manages the deletion of data stored in the storage device 13 of each client device 1. The memory 22 temporarily stores programs and data necessary for the operation of the server device 2. The storage device 23 is a non-volatile storage medium that stores programs necessary for the operation of the server device 2. The communication device 25 is communicably connected to each client device 1 and the administrator device 3 via a communication line 6. The display device 26 displays information related to the status of the server device 2. The input device 27 receives user input to control the operation of the server device 2. The input device 27 includes, for example, a keyboard and a pointing device. The processor 21, the memory 22, the storage device 23, the communication device 25, the display device 26, and the input device 27 are connected to one another via a bus 20.

[0024] FIG. 4 is a block diagram showing the configuration of the administrator device 3 in FIG. 1. The administrator device 3 includes a bus 30, a processor 31, a memory 32, a storage device 33, a communication device 35, a display device 36, and an input device 37. The processor 31 controls the overall operation of the administrator device 3. The memory 32 temporarily stores programs and data necessary for the operation of the administrator device 3. The storage device 33 is a non-volatile storage medium that stores programs necessary for the operation of the administrator device 3. The communication device 35 is communicably connected to the server device 2 via a communication line 6. The display device 36 displays information related to the status of the administrator device 3. The input device 37 receives user input to control the operation of the administrator device 3. The input device 37 includes, for example, a keyboard and a pointing device. The processor 31, the memory 32, the storage device 33, the communication device 35, the display device 36, and the input device 37 are connected to one another via a bus 30.

[0025] The server device 2 provides an interface, for example, a web page-based interface, accessible by the administrator device 3 to manage the erasure of data stored in the storage device of each client device 1. In this case, the server device 2 executes a web server application program, and the administrator device 3 executes a web browser application program to access the web server of the server device 2.

[0026] FIG. 5 is a block diagram showing the configuration of the user terminal device 4 of FIG. 1. The user terminal device 4 includes a bus 40, a processor 41, a memory 42, a storage device 43, a communication device 45, a display device 46, an input device 47, and a photographing device 48. The processor 41 controls the overall operation of the user terminal device 4. The memory 42 temporarily stores programs and data necessary for the operation of the user terminal device 4. The storage device 43 is a non-volatile storage medium that stores programs necessary for the operation of the user terminal device 4. The communication device 45 is communicably connected to the server device 2 via the base station device 5. The display device 46 displays information related to the status of the user terminal device 4 and also displays information related to the deletion of data stored in the storage device 13 of the client device 1. The input device 47 receives user inputs that control the operation of the user terminal device 4. The input device 47 includes, for example, a switch and a touch panel. The photographing device 48 photographs an image displayed on the display device 16 of the client device 1, for example. As will be described later, a graphic code (e.g., a two-dimensional barcode) containing information related to erasure of data stored in the storage device 13 of the client device 1 may be displayed on the display device 16 of the client device 1. In this case, the user terminal device 4 transmits the content of the photographed graphic code to the server device 2 via the base station device 5. The processor 41, memory 42, storage device 43, communication device 45, display device 46, input device 47, and photographing device 48 are connected to one another via a bus 40.

[0027] As described above, in the client device 1, the storage device 13 stores an operating system and multiple application programs, and the storage device 14 stores a firmware program. The operating system, each application program, and the firmware program are executed by the processor 11. Generally, when the client device 1 starts up, the firmware program is executed first, and then the operating system is called from the firmware program. The application program is executed on the operating system. The application program accesses each hardware device of the client device 1 (the storage device 13, the storage device 14, the communication device 15, the display device 16, and the input device 17) via the operating system. On the other hand, the firmware program accesses each hardware device of the client device 1 directly without going through the operating system. One of the application programs is an erasure application program for erasing data stored in the storage device 13. The client device 1 is configured to erase data stored in the storage device 13 by executing the erasure application program and the firmware program.

[0028] FIG. 6 is a schematic diagram showing the functional blocks of the firmware program 50 and the erase application program 70 executed by the processor 11 of FIG.

[0029] The firmware program 50 includes, as its functional blocks, a core control unit 51, an erasure control unit 52, a data encoding unit 53, and a two-dimensional barcode generation unit 54, for example. The core control unit 51 controls the other functional blocks of the firmware program 50, controls the input and output of data between the functional blocks, and controls the input and output of data to and from the firmware program 50. The erasure control unit 52 controls the erasure of data stored in the storage device 13. The data encoding unit 53 encodes erasure result information, which indicates whether or not all data stored in the storage device 13 has been successfully erased, using a predetermined encoding method. The two-dimensional barcode generation unit 54 generates a two-dimensional barcode including the erasure result information, which indicates whether or not all data stored in the storage device 13 has been successfully erased.

[0030] The operating system 60 provides an interface for each hardware device (storage device 13, storage device 14, communication device 15, display device 16, and input device 17) of the client device 1 to the erasure application program 70 and other application programs (not shown). The operating system 60 includes, as its functional blocks, a device information monitor 61 and a power management unit 62. The device information monitor 61 acquires information about the client device 1 from the client device 1 and also acquires information about various components of the client device 1 from the components. The example of FIG. 6 shows a case where the device information monitor 61 acquires information about the storage device 13. The information about the client device 1 includes, for example, the manufacturer, model, serial number, and UUID (Universally Unique Identifier) ​​of the client device 1. The information about the storage device 13 includes, for example, the manufacturer, model, serial number, UUID, and capacity of the storage device 13. The power management unit 62 controls the stopping, suspending, hibernation, and restarting of the client device 1.

[0031] The storage devices of each client device 1 under the management of a certain server device 2 can be identified from one another using at least some of the manufacturer of the client device 1, the model of the client device 1, the serial number of the client device 1, the UUID of the client device 1, the manufacturer of the storage device 13, the model of the storage device 13, the serial number of the storage device 13, the UUID of the storage device 13, and the capacity of the storage device 13. Therefore, at least some of the manufacturer of the client device 1, the model of the client device 1, the serial number of the client device 1, the UUID of the client device 1, the manufacturer of the storage device 13, the model of the storage device 13, the serial number of the storage device 13, the UUID of the storage device 13, and the capacity of the storage device 13 can be used as identification information that uniquely identifies the storage device 13.

[0032] The erasure application program 70 includes, as its functional blocks, for example, a core control unit 71. The core control unit 71 controls other functional blocks (not shown) of the erasure application program 70, controls input and output of data between the functional blocks, and controls input and output of data from and to the outside of the erasure application program 70.

[0033] The storage device 13 also executes a firmware program including the functional blocks shown in FIG. 6. The firmware program of the storage device 13 includes, as its functional blocks, for example, a core control unit 81, a reading unit 82, a writing unit 83, and an erasing unit 84. The core control unit 81 controls the other functional blocks of the storage device 13 and controls the input and output of data between the functional blocks. The reading unit 82 reads data from a storage medium (not shown) of the storage device 13. The writing unit 83 writes data to the storage medium of the storage device 13. The erasing unit 84 erases data from the storage medium of the storage device 13.

[0034] The operation of the client device 1 will be described below with reference to the functional blocks in FIG. 6, and the operation of the server device 2 will also be described.

[0035] [Operation of the first embodiment] In the system 100 of FIG. 1 , when erasing data stored in the storage device 13 of a client device 1, the administrator of each client device 1 first accesses the server device 2 via the administrator device 3 and registers the storage device 13 to be erased with the server device 2. Each client device 1 periodically accesses the server device 2 to check whether the storage device 13 of the client device 1 is registered as a data item to be erased. If the storage device 13 is registered as a data item to be erased, the client device 1 erases the data stored in the storage device 13. The client device 1 then transmits the results of the erasure of the data stored in the storage device 13 to the server device 2 via the communication line 6. If the client device 1 is unable to transmit the results of the erasure to the server device 2, for example, if the client device 1 is unable to receive an acknowledgment signal for the results of the erasure, the client device 1 generates a graphic code containing the results of the erasure, such as a two-dimensional barcode such as a QR code (registered trademark), and displays it on the display device 26. This allows a user or administrator with access to the client device 1 to photograph the two-dimensional barcode using the user terminal device 4 and transmit the results of the erasure contained in the two-dimensional barcode from the user terminal device 4 to the server device 2. The user or administrator uses the user terminal device 4 to transmit the deletion result to the server device 2, and then shuts down the client device 1.

[0036] However, in conventional systems using two-dimensional barcodes containing erasure results, it is not always guaranteed that the erasure results will be transmitted from the user terminal device to the server device before the client device is shut down. For example, once a two-dimensional barcode displayed on the client device is cleared by a user or administrator, it may never be displayed again. In this case, the server device cannot obtain the erasure results of the storage device 13 to be erased. Therefore, in systems using two-dimensional barcodes containing erasure results, it is necessary to transmit the erasure results to the server device more reliably than in conventional systems.

[0037] As will be described below, the system 100 according to each embodiment of the present disclosure reliably transmits the erasure result to the server device 2 using keywords that are distributed in advance to the client device 1 and the server device 2.

[0038] FIG. 7 is a schematic diagram illustrating distribution of keywords in the system 100 of FIG. 1. In the first embodiment, the same keywords are distributed in advance to the client device 1 and the server device 2. As described with reference to FIG. 6, the client device 1 executes the firmware program 50, the operating system 60, and the erasure application program 70 via the processor 11. The keywords are pre-stored in the storage device 14 of the client device 1. For example, the keywords may be written to the storage device 14 when the client device 1 is manufactured. Alternatively, the keywords may be pre-embedded in the firmware program 50 and installed in the storage device 14 together with the firmware program 50. Alternatively, the keywords may be pre-embedded in the erasure application program 70 and installed in the storage device 13 together with the erasure application program 70, and then written to the storage device 14 by executing the erasure application program 70. The server device 2 executes the operating system 91 and the erasure application program 92 via the processor 21. The keywords are pre-stored in the memory 22 or the storage device 23 of the server device 2. For example, the keywords may be pre-written in the storage device 23 and read from the storage device 23 to the memory 22 by executing the erasure application program 92. As a result, the same keyword is distributed to the client device 1 and the server device 2 in advance before the deletion process, which will be described later with reference to, for example, FIGS.

[0039] Fig. 8 is a flowchart showing the registration process of the client device 1 by the erasure application program 70 executed by the processor 11 of Fig. 2. Fig. 9 is a flowchart showing the registration process of the server device 2 by the erasure application program 92 executed by the processor 21 of Fig. 3.

[0040] If the organization that owns each client device 1 is not registered with the server device 2, before performing the registration process of Figure 8, an administrator or other person in charge of the organization that owns each client device 1 obtains the following information from the server device 2.

[0041] Server device 2 account information (customer ID and password) - URL (Uniform Resource Locator) of the erasure application program 70 Customer number (a serial number assigned to each customer and associated with their account information)

[0042] The customer number is generated for each customer, that is, for each contract that governs the erasure of data stored in the storage device of each client device 1, and is therefore not identification information for each client device 1 or storage device 13.

[0043] Each client device 1 accesses the URL of the erasure application program 70, downloads the erasure application program 70, and installs it. After installation, the erasure application program 70 is started automatically or manually. After the erasure application program 70 is started, the processor 11 executes the registration process of FIG. 8 to register the storage device 13 of the client device 1 with the server device 2.

[0044] 8, the core control unit 71 of the client device 1 displays on the display device 16 a dialog box prompting the user to enter a customer number assigned to the organization that owns the client device 1. The user of the client device 1 follows the dialog box to enter the customer number using the input device 17. The core control unit 71 acquires the customer number from the user via the input device 17.

[0045] In step S2, the core control unit 71 of the client device 1 acquires information about the client device 1 and information about the storage device 13 from the device information monitor 61 of the operating system 60.

[0046] In step S3, the core control unit 71 of the client device 1 uses the communication device 15 to transmit the customer number, the information of the client device 1, and the information of the storage device 13 to the server device 2.

[0047] 9, the server device 2 receives the customer number, information about the client device 1, and information about the storage device 13. The server device 2 stores in the memory 22 or the storage device 23 a management table for managing the erasure of data stored in the storage device 13 of each client device 1. In step S12, the server device 2 registers the client device 1 and its storage device 13 in the management table as new management targets. When the client device 1 and its storage device 13 have been registered, the server device 2 transmits an acknowledgement signal to the client device 1 in step S13.

[0048] In step S4 of FIG. 8, the core control unit 71 of the client device 1 determines whether or not an acknowledgment signal has been received from the server device 2, and if YES, ends the process, and if NO, returns to step S3.

[0049] 8 and 9, the storage device 13 of the client device 1 is registered in the management table of the server device 2 as a new management target. According to the registration process of Figures 8 and 9, the user of the client device 1 only needs to input the customer number using the input device 17, and information about the client device 1 and information about the storage device 13 are automatically transmitted from the client device 1 to the server device 2. According to the registration process of Figures 8 and 9, the user of the client device 1 does not need to be aware of the organization to which he or she belongs (or the organization that owns the client device 1), and the server device 2 automatically classifies the registered storage devices 13 by customer based on the customer number.

[0050] After the storage devices 13 of each client device 1 are registered with the server device 2, an administrator of the organization that owns each client device 1 registers with the server device 2, as necessary, that the data stored in the storage devices 13 should be erased. To do this, the administrator first uses the administrator device 3 to access the server device 2 and logs in to the server device 2 using account information. Next, while viewing the list of storage devices 13 registered in the management table of the server device 2, the administrator sets an erase flag for one or more storage devices 13 indicating that the stored data should be erased.

[0051] Fig. 10 is a diagram showing exemplary contents of a management table stored in the memory 22 or the storage device 23 of Fig. 3. The management table includes, for each client device 1 or storage device 13 to be managed, for example, a customer number, a group number, information about the client device 1, information about the storage device 13, an erasure flag, a processing number, an erasure start time, and an erasure end time.

[0052] As described above, a customer number is assigned to each customer. A group number is assigned to any sub-organization (group) that is part of the customer's organization. For example, if the customer is a company, a group may be a department or section of the company. As described above, the information about the client device 1 includes, for example, the manufacturer, model, serial number, and UUID of the client device 1. As described above, the information about the storage device 13 includes, for example, the manufacturer, model, serial number, UUID, and capacity of the storage device 13. As described above, the erasure flag indicates that data stored in the storage device 13 should be erased. A processing number is issued for each storage device 13 for which the erasure flag indicates that data stored in the storage device 13 should be erased. The erasure start time and erasure end time indicate the actual start and end times of erasure of data stored in the storage device 13.

[0053] The customer number is provided by the server device 2. The group number, information about the client device 1, and information about the storage device 13 are provided by the client device 1. The erasure flag is set by the administrator of the organization that owns each client device 1 using the administrator device 3. The processing number is provided by the server device when the erasure flag is set, indicating that the stored data should be erased. The erasure start time and erasure end time are obtained when the data stored in the storage device 13 is actually erased.

[0054] Based on the management table, the server device 2 may generate a status report indicating the status of each client device 1 and each storage device 13. The status report indicates, for example, which of the following states each storage device 13 is in:

[0055] -Flag for deletion set Erasing -Erasing completed -Erasure completed and erasure certificate issued ·Erase failed

[0056] The certificate of erasure will be described later.

[0057] The status report may also include the following information:

[0058] Date and time the deletion flag was set Approval of deletion Start date and time of erasure ·Erase completion date and time ·Elimination method The manufacturer, model, and serial number of the client device 1 The manufacturer, model, serial number, and capacity of the storage device 13

[0059] The administrator can view the status report by accessing the server device 2 using the administrator device 3.

[0060] Fig. 11 is a flowchart showing erasure processing of the client device 1 by the erasure application program 70 executed by the processor 11 of Fig. 2. Fig. 12 is a flowchart showing erasure processing of the client device 1 by the firmware program 50 executed by the processor 11 of Fig. 2. Fig. 13 is a flowchart showing erasure processing of the server device 2 by the erasure application program 92 executed by the processor 21 of Fig. 3.

[0061] 13, the server device 2 determines whether or not a storage device 13 to be erased has been designated by the administrator device 3. If the determination is YES, the server device 2 proceeds to step S52, and if the determination is NO, the server device 2 repeats step S51. In step S52, the server device 2 sets an erasure flag in the management table for the storage device 13 designated as the storage device to be erased, and updates the status report of this storage device 13.

[0062] After the client device 1 is started, the erasure application program 70 is started automatically or manually.

[0063] In step S21 of FIG. 11, the core control unit 71 of the client device 1 inquires of the server device 2 using the communication device 15 whether an erasure flag is registered in the management table of the server device 2 for the memory device 13 of the client device 1 that is executing the erasure process of FIG. 11.

[0064] 13, the server device 2 determines whether or not an inquiry about the deletion flag has been received from the client device 1, and if the answer is YES, the process proceeds to step S54, and if the answer is NO, the process returns to step S51. In step S54, the server device 2 replies to the client device 1 about the presence or absence of the deletion flag.

[0065] In step S22 of FIG. 11, the core control unit 71 of the client device 1 determines whether an erasure flag is registered in the management table of the server device 2 for the memory device 13 of the client device 1 that is executing the erasure process of FIG. 11, and if YES, proceeds to step S23, and if NO, returns to step S21.

[0066] In step S23, the core control unit 71 of the client device 1 uses the communication device 15 to transmit information about the client device 1 and information about the storage device 13 to the server device 2.

[0067] In step S55 of FIG. 13, the server device 2 determines whether or not it has received information about the client device 1 and the storage device 13 from the client device 1, and if YES, proceeds to step S56, and if NO, returns to step S51.

[0068] If the information about the client device 1 and the storage device 13 received by the server device 2 in step S55 matches the information about the client device 1 and the storage device 13 registered in the management table of the server device 2 by the registration process of FIG. 8, in step S56 the server device 2 generates a processing number for the storage device 13 of the client device 1 that is executing the erasure process of FIG. 11 and transmits it to the client device 1. If the server device 2 cannot identify the storage device 13 based on the received information about the client device 1 and the storage device 13, or if the erasure flag is not set, the server device 2 returns an error response. If the server device 2 can identify the storage device 13 based on the received information about the client device 1 and the storage device 13, but the erasure flag is not set or the identification information of the storage device 13 is different, the server device 2 may return a response indicating that the information is different. In this case, the server device 2 does not return a processing number, and therefore the client device 1 cannot erase the data stored in the storage device.

[0069] In step S24 of FIG. 11, the core control unit 71 of the client device 1 determines whether or not it has received a processing number for deletion from the server device 2 in response to the information sent in step S23, and if YES, proceeds to step S25, and if NO, returns to step S23.

[0070] In step S25, the core control unit 71 of the client device 1 displays a dialog box on the display device 16 to confirm whether or not to erase the data stored in the storage device 13. The user of the client device 1 uses the input device 17 in accordance with the dialog box to input whether or not to erase the data stored in the storage device 13. The core control unit 71 obtains, via the input device 17, whether or not to erase the data stored in the storage device 13.

[0071] In step S26, the core control unit 71 of the client device 1 determines whether the user has consented to the erasure of the data stored in the storage device 13, and if YES, proceeds to step S27, and if NO, ends the process.

[0072] In step S27, the core control unit 71 of the client device 1 sends the UUID of the storage device 13, the processing number, the address of the server device 2, and information on the erasure method to the firmware program 50. The information on the erasure method includes, for example, secure erase, overwrite and erase three times, overwrite and erase once, and failure.

[0073] The core control unit 51 of the firmware program 50 stores the UUID of the storage device 13, the processing number, the address of the server device 2, and the information on the erasure method acquired from the erasure application program 70 in the storage device 14 (see step S31 in FIG. 12). When the core control unit 51 has acquired and stored the UUID of the storage device 13, the processing number, the address of the server device 2, and the information on the erasure method, it sends an acknowledgement signal to the erasure application program 70 (see step S32 in FIG. 12).

[0074] In step S28, the core control unit 71 of the client device 1 determines whether or not an acknowledgment signal has been received from the firmware program 50, and if YES, proceeds to step S29, and if NO, returns to step S27.

[0075] In step S29, the core control unit 71 of the client device 1 sends a control signal to the power management unit 62 of the operating system 60 to restart the client device 1.

[0076] Steps S31 to S33 in FIG. 12 correspond to steps S27 to S29 in FIG.

[0077] In step S31 of FIG. 12, the core control unit 51 of the client device 1 stores the UUID of the storage device 13, the processing number, the address of the server device 2, and the information on the erasure method acquired from the erasure application program 70 in the storage device .

[0078] In step S32, the core control unit 51 of the client device 1 sends an acknowledgement signal to the erasure application program 70 when it has acquired and stored the UUID of the storage device 13, the processing number, the address of the server device 2, and the erasure method information.

[0079] In step S33, the erasure application program 70 restarts the client device 1.

[0080] After rebooting, the firmware program 50 continues the erasure process of FIG. 12 without calling the operating system 60.

[0081] In step S34, the core control unit 51 of the client device 1 uses the erasure control unit 52 to erase all data stored in the storage device 13 using the specified erasure method. The erasure control unit 52 may use the secure erase command of the storage device. After the erasure is completed, the core control unit 51 stores data indicating the erasure result, including the erasure start time, the erasure end time, and the erasure method, in the storage device 14.

[0082] In step S35, the core control unit 51 of the client device 1 reads the data indicating the deletion result from the storage device 14, and encodes the data indicating the deletion result using a predetermined encoding method using the data encoding unit 53. The core control unit 51 stores the encoded data in the storage device 14.

[0083] The encoding of the data indicating the encoded erasure result is performed, for example, in the following steps.

[0084] (1) The UUID, processing number, erasure start time, erasure end time, and erasure method are arranged serially. These parameters may be arranged in, for example, a CSV format. (2) The character string related to the parameter in step (1) is converted to a half-width character string such as BCD. Here, a character string may be added. (3) Calculate the hash value of the string from step (2). (4) The character string in step (2) and the hash value in step (3) are converted into a format that can be transmitted via the communication line 6. If necessary, URL encoding is performed, for example. (5) The data from step (4) is sent to the address of the server device 2 as the destination.

[0085] In step S36, the core control unit 51 of the client device 1 reads the coded data indicating the deletion result from the storage device 14, and transmits the coded data indicating the deletion result to the server device 2 using the communication device 15.

[0086] In step S57 of FIG. 13, the server device 2 determines whether or not it has received an erasure result from the client device 1, and if YES, the process proceeds to step S58, and if NO, the process proceeds to step S59.

[0087] In step S58, the server device 2 transmits to the client device 1 an acknowledgement signal for the result of erasure.

[0088] In step S37 of FIG. 12, the core control unit 51 of the client device 1 determines whether or not it has received an acknowledgment signal from the server device 2 within a predetermined period of time after transmitting the erasure result, and if YES, proceeds to step S43, and if NO, proceeds to step S38.

[0089] In step S38, the core control unit 51 of the client device 1 reads the data indicating the erasure result from the storage device 14, and generates a two-dimensional barcode from the data indicating the erasure result using the two-dimensional barcode generation unit 54. The core control unit 51 stores the generated two-dimensional barcode in the storage device 14.

[0090] In step S39, the core control unit 51 of the client device 1 reads the two-dimensional barcode from the storage device 14 and displays the two-dimensional barcode on the display device 16.

[0091] 14 is a diagram showing the content displayed on the display device 16 of the client device 1 in step S39 of FIG. 12. The display screen 200 displayed on the display device 16 includes, for example, a two-dimensional barcode 201 and an input field 202. The user photographs the two-dimensional barcode 201 using the photographing device 48 of the user terminal device 4. The user terminal device 4 decodes the two-dimensional barcode 201 to extract data indicating the deletion result, and transmits this data to the server device 2. The two-dimensional barcode 201 may include, for example, the URL of the server device 2. In this case, the user terminal device 4 may launch a web browser and access the server device 2 via HTTPS communication.

[0092] In step S59 of FIG. 13, the server device 2 determines whether or not it has received an erasure result from the user terminal device 4, and if YES, the process proceeds to step S60, and if NO, the process returns to step S57.

[0093] In step S60, the server device 2 reads out the keyword from the memory 22 or the storage device 23 and transmits it to the user terminal device 4.

[0094] The user terminal device 4 receives the keyword transmitted from the server device 2 in step S60 of FIG.

[0095] 15 is a diagram showing the content displayed on the display device 46 of the user terminal device 4 after the keyword is transmitted from the server device 2 to the user terminal device 4 in step S60 of FIG. 13. The user terminal device 4 displays the keyword 211 received from the server device 2 ("TWEraseEnd" in the example of FIG. 15) on the display device 46. When the user terminal device 4 that captured the image of the two-dimensional barcode launches a web browser, the keyword 211 may be displayed on the web browser. The user inputs the displayed keyword 211 into the input field 202 of the client device 1 using the input device 17 and presses the Enter key.

[0096] In step S40 of FIG. 12, the core control unit 51 of the client device 1 determines whether or not a keyword has been input from the input device 17, and if YES, proceeds to step S41, and if NO, repeats step S40.

[0097] In step S41, the core control unit 51 of the client device 1 determines whether the keyword input from the input device 17 matches a keyword pre-stored in the storage device 14, and if YES, proceeds to step S42, and if NO, returns to step S40.

[0098] 12 and 13, first, in step S36, the erasure result is transmitted from the client device 1 to the server device 2 via the communication line 6. If a failure or the like occurs on the communication line 6, that is, if an acknowledgment signal for the erasure result is not received in step S37, the erasure result is transmitted to the server device 2 via the user terminal device 4 by executing steps S38 to S42.

[0099] Referring to FIG. 13, after executing step S58 or S60, in step S61, the server device 2 stores the erase result in the management table and updates the status report.

[0100] In step S62, the server device 2 issues an erasure certificate based on the result of the erasure.

[0101] In step S43 of FIG. 12, the core control unit 51 of the client device 1 performs post-processing and shuts down the client device 1.

[0102] Fig. 16 is a sequence diagram showing the operation of the system 100 in Fig. 1 when the system 100 has succeeded in transmitting the erasure result information via the communication line 6. Fig. 17 is a sequence diagram showing the operation of the system 100 in Fig. 1 when the system 100 has failed in transmitting the erasure result information via the communication line 6.

[0103] In Fig. 16 and Fig. 17, for the sake of simplicity, only the main steps of the steps described with reference to Fig. 8 to Fig. 9 and Fig. 11 to Fig. 13 are shown, and the others are omitted. Fig. 16 also shows both the registration process of Fig. 8 to Fig. 9 and the deletion process of Fig. 11 to Fig. 13. Since the registration process is common to both Fig. 16 and Fig. 17, Fig. 17 omits the registration process and shows only the deletion process.

[0104] 16, the client device 1 acquires a customer number from the user in step S1. Then, the client device 1 transmits the customer number, information about the client device 1, and information about the storage device 13 to the server device 2.

[0105] In step S11, the server device 2 registers the storage device 13 of the client device 1 as a new management target based on the customer number, the information of the client device 1, and the information of the storage device 13.

[0106] In the first embodiment, as described above, the same keywords are distributed to the client device 1 and the server device 2 in advance before the erasure process is executed.

[0107] Thereafter, in step S101, the administrator device 3 transmits account information to the server device 2 and logs in to the server device 2. The administrator device 3 specifies the storage device 13 to be erased, that is, the storage device 13 from which the stored data should be erased.

[0108] In step S52, the server device 2 stores the erasure flag in the management table so as to correspond to the storage device 13 designated in step S101.

[0109] Thereafter, the client device 1 periodically inquires of the server device 2 as to whether or not an erasure flag has been set in the management table of the server device 2 corresponding to the storage device of the client device 1. When the client device 1 receives a response signal from the server device 2 in response to the erasure flag inquiry, indicating that an erasure flag has been set in the management table of the server device 2, the client device 1 transmits information about the client device 1 and information about the storage device 13 to the server device 2. When the information about the client device 1 and the storage device 13 received by the server device 2 matches the information about the client device 1 and the storage device 13 registered in the management table of the server device 2, the server device 2 generates a processing number for the storage device 13 of the client device 1 and transmits the processing number to the client device 1.

[0110] Thereafter, in step S25, the client device 1 displays a dialog box on the display device 16 to confirm whether or not to erase the data stored in the storage device 13. If the user agrees to erase the data stored in the storage device 13, the client device 1 restarts in step S29. Thereafter, in step S34, the client device 1 erases all data stored in the storage device 13.

[0111] After the erasure is completed, the client device 1 transmits erasure result information to the server device 2. If a response signal to the erasure result information is received from the server device 2 within a predetermined timeout period, the client device 1 shuts down in step S43.

[0112] In step S61, the server device 2 stores the erasure result included in the erasure result signal in a management table. In step S62, the server device 2 issues an erasure certificate based on the erasure result included in the erasure result signal.

[0113] On the other hand, as shown in FIG. 17, if the erasure result information sent by the client device 1 does not reach the server device 2, or if a response signal to the erasure result information is not received, the client device 1 displays a two-dimensional barcode on the display device 16 in step S39.

[0114] In step S111, the user of client device 1 uses user terminal device 4 to capture an image of the two-dimensional barcode displayed on display device 16 of client device 1. User terminal device 4 decodes the two-dimensional barcode to extract data indicating the deletion result, and transmits this data to server device 2.

[0115] When the server device 2 receives data indicating the deletion result from the user terminal device 4, the server device 2 reads out a keyword from the memory 22 or the storage device 23 and transmits the keyword to the user terminal device 4.

[0116] In step S112, the user terminal device 4 displays the keyword received from the server device 2 on the display device 46. The user inputs the keyword displayed on the display device 46 into the client device 1.

[0117] In step S40, the client device 1 acquires the input keyword. In step S41, the client device 1 determines whether the input keyword matches a keyword previously stored in the storage device 14. If the keyword matches, the client device 1 clears the display content of the display device 16 in step S42. Thereafter, the client device 1 shuts down in step S43.

[0118] [Certificate of erasure] For example, when data stored in a storage device is erased using erasure software or an erasure process certified by a third-party certification body such as the Association of Data Erase Certification Council (ADEC), a certificate can be issued to indicate that proper erasure of data has been performed. The certificate includes, for example, the following information:

[0119] (1) Information on client device 1 ·Manufacturer Model Serial number (2) Information on storage device 13 ·Manufacturer Model Serial number ·capacity (3) Information to be deleted - Information about the company to be deleted (company ID, company name, rating) - Erasure software information (vendor name, software name, certification number, erasure method) - Erase execution date and time (erasure start time, erasure end time) Erasing results

[0120] As described above, information about the client device 1 and information about the storage device 13 are sent from the client device 1 to the server device 2 by the erasure application program 70. Of the erasure information, the business ID, business name, vendor name, and software name must be applied for and certified in advance by a certification authority. Once the erasure software is certified, an authentication number is issued. The firmware program 50 also sends the erasure execution date and time and the erasure result from the client device 1 to the server device 2. In this way, the information required to issue an erasure certificate can be automatically sent from the client device 1 to the server device 2, making it easy to issue an erasure certificate.

[0121] [summary] The client device 1 cannot complete the erasure operation unless it receives an acknowledgment signal for the erasure result from the server device 2, or unless it transmits the erasure result from the user terminal device 4 to the server device 2 and inputs the keyword returned from the server device 2 to the user terminal device 4 into the client device 1. The client device 1 may be configured to display the display content of FIG. 14 on the display device 16 each time the power is turned on if the erasure operation is not completed successfully. This ensures that if the erasure result cannot be transmitted from the client device 1 to the server device 2, the user is prompted to transmit the erasure result to the server device 2 using the user terminal device 4. Therefore, the system according to the first embodiment uses keywords, i.e., distributes the keywords between the client device 1 and the server device 2 and transmits the keywords from the server device 2 to the user terminal device 4, thereby more reliably notifying the server device 2 of the erasure result of the storage device 13 than conventional systems.

[0122] If the client device 1 is shut down normally after erasing the data stored in the memory device 13 of the client device 1 (i.e., the screen of Figure 14 is not displayed even when the power of the client device 1 is turned on), it means that the data has been erased normally and the erasure results have been sent to the server device 2.

[0123] Even if a keyword displayed on the user terminal device 4 is accidentally deleted before the keyword is entered into the client device 1 (for example, if the web browser displaying the keyword is closed), the keyword can be redisplayed by photographing the two-dimensional barcode using the user terminal device 4.

[0124] The keyword may be commonly determined for each company, department, or contract. In this case, the firmware program 50 or erasure application program 70 with the keyword pre-embedded may be installed on multiple client devices 1 belonging to the same company, department, or contract.

[0125] The keywords may be entered into the client device 1 by an end user of the client device 1 or by an administrator who has access to the client device 1. The administrator who has access to the client device 1 may be the same as or different from the administrator who has access to the server device 2.

[0126] Furthermore, according to the system of the first embodiment, an administrator accesses the server device 2 and sets an erasure flag indicating that data stored in the storage device 13 of each client device 1 should be erased. The client device then inquires of the server device 2 about the presence or absence of the erasure flag, without transmitting an erasure command or the like from the server device 2 to the client device 1. This allows the storage device 13 to be erased to be identified without error and easily set. No signal is sent from the server device 2 to the client device 1 when erasure begins; the user of the client device 1 simply connects the client device 1 to the communication line 6 when erasure begins. Therefore, data can be erased at the user's convenience. This allows the data stored in the storage device 13 to be identified without error and easily erased.

[0127] Performing the erasure process not only by the erasure application program 70 but also by a combination of the erasure application program 70 and the firmware program 50 has the following advantages. The erasure application program 70, which runs on the operating system 60, resides in the storage device 13. Similarly, the UEFI application program, which runs on the firmware program 50, resides in the storage device 13. Therefore, when data stored in the storage device 13 is erased by the erasure application program 70 or the UEFI application program, the area of ​​the storage device 13 where the program resides cannot be deleted. Furthermore, the erasure application program 70 or the UEFI application program cannot communicate with the server device 2 via the communication line 6 after the data erasure is complete. Furthermore, since the erasure application program 70 or the UEFI application program cannot operate after the data erasure is complete, it cannot obtain information indicating the erasure result (e.g., the erasure start time, the erasure end time, and the erasure method). According to the system 100 of the first embodiment, by executing the firmware program 50, all data stored in the storage device 13 can be erased. After the data erasure is complete, communication with the server device 2 can be performed via the communication line 6, and after the data erasure is complete, information indicating the erasure result can be obtained.

[0128] For example, it is conceivable to outsource the erasure of data stored in the storage device 13 to a service provider. However, transporting a client device equipped with a storage device from which data is to be erased to the service provider's business premises poses security risks. Using a highly secure delivery method increases costs. Furthermore, a lot of work is required for the erasure and subsequent checks. Furthermore, erasing data takes a long time, for example, half a day. According to the system 100 of the first embodiment, data stored in the storage device 13 can be erased without moving the client device 1, enabling data to be erased easily, with high security, and at low cost.

[0129] [Advantages of the first embodiment] According to one aspect of the present disclosure, there is provided a system 100 for erasing data stored in a storage device of at least one client device 1. The system 100 includes at least one client device 1, a server device 2, and a user terminal device 4. The client device 1 includes a first storage device 13 for storing data to be erased, a second storage device 14 for storing a first keyword, a first display device 16, and a first input device 17. The server device 2 includes a memory 22 or a storage device 23 for storing a second keyword. The user terminal device 4 includes a photographing device 48 and a second display device 46. The client device 1 erases the data stored in the first storage device 13 and displays, on the first display device 16, a graphical symbol including erasure completion information indicating that erasure of the data stored in the first storage device 13 has been completed. The user terminal device 4 photographs the graphical symbol using the photographing device 48, extracts the erasure completion information from the graphical symbol, and transmits the erasure completion information to the server device 2. The server device 2 receives the erasure completion information from the user terminal device 4, reads the second keyword from the memory 22 or the storage device 23, and transmits the second keyword to the user terminal device 4. The user terminal device 4 receives the second keyword from the server device 2 and displays the keyword on the second display device 46. The client device 1 acquires the second keyword input via the first input device 17, and if the second keyword input via the first input device 17 matches the first keyword stored in the second storage device 14, shuts down the client device 1.

[0130] This makes it possible to notify the server device 2 of the results of erasure of the storage device 13 more reliably than before.

[0131] According to one aspect of the present disclosure, the first storage device 13 may store data including an operating system, application programs, and user data, and the second storage device 14 may further store a firmware program. In this case, the client device 1 erases all data stored in the first storage device 13 by executing the firmware program.

[0132] This allows all data stored on the storage device 13, including the operating system, to be erased.

[0133] According to one aspect of the present disclosure, the first keyword may be pre-embedded in the firmware program.

[0134] This allows the same keywords to be distributed to the client device 1 and the server device 2 in advance.

[0135] According to one aspect of the present disclosure, the graphic code may be a two-dimensional barcode.

[0136] This allows the result of erasing the storage device 13 to be transmitted from the user terminal device 4 to the server device 2.

[0137] According to one aspect of the present disclosure, the client device 1 may erase data stored in the first storage device 13 and then transmit erasure completion information to the server device 2. In this case, if an acknowledgment signal in response to the transmitted erasure completion information is received from the server device 2 within a predetermined period, the client device 1 shuts down without displaying the graphic code on the first display device 16. On the other hand, if an acknowledgment signal is not received from the server device 2 within the predetermined period, the graphic code is displayed on the first display device 16.

[0138] As a result, even if the client device 1 cannot communicate with the server device 2, the server device 2 can be notified of the result of erasure of the storage device 13 more reliably than before.

[0139] According to one aspect of the present disclosure, the server device 2 may obtain erasure completion information from the client device 1 and, based on the erasure completion information, issue an erasure certificate certifying that the erasure of data stored in the first storage device 13 has been completed.

[0140] This makes it possible to issue a certificate of erasure that proves that all data stored in the storage device has been completely erased.

[0141] According to one aspect of the present disclosure, an electronic device for processing information includes a first storage device 13 for storing data to be erased, a second storage device 14 for storing a first keyword, a first display device 16 for displaying information, a first input device 17 for receiving input from a user of the electronic device 1, and a processor 11 for controlling the electronic device 1. The processor 11 erases the data stored in the first storage device 13. The processor 11 displays, on the first display device 16, a graphic code including erasure completion information indicating that erasure of the data stored in the first storage device 13 has been completed. The processor 11 acquires, via the first input device 17, a second keyword obtained by the user transmitting the erasure completion information included in the graphic code to the server device 2. The processor 11 compares the second keyword with the first keyword stored in the second storage device 14, and if they match, shuts down the electronic device 1.

[0142] This makes it possible to notify the server device 2 of the results of erasure of the storage device 13 more reliably than before.

[0143] According to one aspect of the present disclosure, there is provided a method for operating a system 100 for erasing data stored in a storage device of at least one client device 1. The system 100 includes at least one client device 1, a server device 2, and a user terminal device 4. The client device 1 includes a first storage device 13 for storing data to be erased, a second storage device 14 for storing a first keyword, a first display device 16, and a first input device 17. The server device 2 includes a memory 22 or a storage device 23 for storing a second keyword. The user terminal device 4 includes a photographing device 48 and a second display device 46. The method includes the steps of: erasing, by the client device 1, the data stored in the first storage device 13; and displaying, on the first display device 16, a graphical symbol including erasure completion information indicating that erasure of the data stored in the first storage device 13 has been completed. The method includes the steps of: by the user terminal device 4, photographing the graphical symbol using the photographing device 48, extracting the erasure completion information from the graphical symbol, and transmitting the erasure completion information to the server device 2. The method includes the steps of: receiving, by the server device 2, erasure completion information from the user terminal device 4; reading a second keyword from the memory 22 or the storage device 23; and transmitting the second keyword to the user terminal device 4. The method includes the steps of: receiving, by the user terminal device 4, the second keyword from the server device 2; and displaying the keyword on the second display device 46. The method includes the steps of: obtaining, by the client device 1, the second keyword input via the first input device 17; and shutting down the client device 1 if the second keyword input via the first input device 17 matches the first keyword stored in the second storage device 14.

[0144] This makes it possible to notify the server device 2 of the results of erasure of the storage device 13 more reliably than before.

[0145] [Second embodiment] In the first embodiment, a case where a keyword is pre-allocated to the client device 1 and the server device 2 before the erasure process is executed is described. On the other hand, in the second embodiment, a case where the server device 2 sets a keyword and sends the keyword from the server device 2 to the client device 1 during the erasure process is described.

[0146] [Configuration of the second embodiment] The configuration of the system 100 according to the second embodiment is the same as the configuration of the system 100 according to the first embodiment described with reference to FIGS. 1 to 5 and the like.

[0147] [Operation of the second embodiment] FIG. 18 is a schematic diagram illustrating the distribution of keywords in the system 100 according to the second embodiment. In the second embodiment, as described above, the server device 2 sets keywords and transmits them to the client device 1 during the erasure process. The server device 2 sets the keywords, for example, by executing the erasure application program 92 to internally generate the keywords. In this case, the server device 2 may randomly generate the keywords. The set keywords are stored in the memory 22 or storage device 23 of the server device 2. The server device 2 also transmits the set keywords to the client device 1 having the storage device 13 to be erased. The client device 1 receives the keywords transmitted from the server device 2 using the erasure application program 70 and writes them to the storage device 14. The client device 1 may also receive the keywords transmitted from the server device 2 using the erasure application program 70, transmit them to the firmware program 50, and then write them to the storage device 14 using the firmware program 50. This distributes the same keywords to the client device 1 and the server device 2.

[0148] Fig. 19 is a flowchart showing erasure processing of the client device 1 by the erasure application program 70 executed by the processor 11 of the client device 1 according to the second embodiment. Fig. 20 is a flowchart showing erasure processing of the client device 1 by the firmware program 50 executed by the processor 11 of the client device 1 according to the second embodiment. Fig. 21 is a flowchart showing erasure processing of the server device 2 by the erasure application program 92 executed by the processor 21 of the server device 2 according to the second embodiment.

[0149] 21, after step S52 is executed, the process proceeds to step S121. In step S121, the server device 2 sets a keyword. As described above, the server device 2 sets a keyword, for example, by generating the keyword internally. After step S121 is executed, the process proceeds to step S53. Thereafter, when the server device 2 receives information about the client device 1 and the storage device 13 in step S55, the server device 2 executes step S56A instead of step S56. In step S56A, the server device 2 generates a processing number and transmits the processing number and the keyword to the client device 1.

[0150] 19, the client device 1 executes step S24A instead of step S24. In step S24A, the core control unit 71 of the erasure application program 70 determines whether or not a processing number and a keyword have been received from the server device 2 in response to the information transmitted in step S23. If the determination is YES, the process proceeds to step S25. If the determination is NO, the process returns to step S23. Thereafter, if the user agrees to the erasure of the data stored in the storage device 13 in step S26, the client device 1 executes step S27A instead of step S27. In step S27A, the core control unit 71 transmits information, including the UUID of the storage device 13, the processing number, the address of the server device 2, the erasure method, and the keyword, to the firmware program 50.

[0151] 20, the client device 1 executes step S31A instead of step S31. In step S31A, the core control unit 51 of the firmware program 50 stores the UUID of the storage device 13, the processing number, the address of the server device 2, the erasure method, and the keyword information acquired from the erasure application program 70 in the storage device 14.

[0152] Fig. 22 is a sequence diagram showing the operation of the system 100 according to the second embodiment when the transmission of erasure result information via the communication line 6 is successful. Fig. 23 is a sequence diagram showing the operation of the system 100 according to the second embodiment when the transmission of erasure result information via the communication line 6 is unsuccessful. After executing step S52, the server device 2 sets a keyword in step S121. Thereafter, the server device 2 transmits the keyword together with the processing number to the client device 1.

[0153] Thereafter, the client device 1 and the server device 2 execute the remaining steps of the erasure process in the same manner as in the first embodiment.

[0154] According to the system of the second embodiment, the server device 2 sets a keyword and sends it to the client device 1 during the erasure process, eliminating the need to pre-allocate the keyword to the client device 1 and the server device 2. This eliminates the need to pre-provide a special firmware program or application program with an embedded keyword for the client device 1 equipped with the storage device 13 to be erased.

[0155] In the second embodiment, the server device 2 may set a keyword for each client device 1 individually.

[0156] [First Modification of the Second Embodiment] 24 is a schematic diagram for explaining distribution of keywords in the system 100 according to the first modified example of the second embodiment. The server device 2 may set keywords by acquiring them from the outside, for example, from an administrator, instead of generating the keywords internally.

[0157] FIG. 25 is a diagram showing the contents displayed on the display device 26 of the server device 2 according to the first modified example of the second embodiment. In step S121 of FIG. 21, the server device 2 may display a window 220 of FIG. 25 on the display device 26 to prompt the administrator to input a keyword. The administrator uses the input device 27 of the server device 2 to input a keyword in the input field 221 and presses the Enter key or the Apply button on the screen. Furthermore, when the administrator accesses the server device 2 using the administrator device 3, the server device 2 may display the window 220 of FIG. 25 on the display device 36 of the administrator device 3. In this case, the administrator uses the input device 37 of the administrator device 3 to input a keyword.

[0158] Even when the server device 2 acquires a keyword from outside, the erasure process is executed in the same manner as in the cases of FIGS.

[0159] In this modification, the administrator may set a keyword for each client device 1 individually, or may set a common keyword for each company, department, or contract.

[0160] [Second Modification of the Second Embodiment] Keywords may need to be updated periodically for security purposes, etc. Therefore, the server device 2 may set multiple keywords associated with multiple erasure operations performed at different times. Note that data stored in the storage device 13 is not necessarily erased immediately after the server device 2 transmits a keyword to the client device 1; a new keyword may be set before the data erasure is complete. Furthermore, the erasure results are not necessarily transmitted to the server device 2 immediately after the data erasure is complete; a new keyword may be set before the server device receives the erasure results. The server device 2 manages a keyword history so that it can send an appropriate keyword to the user terminal device 4 when transmission of erasure result information via the communication line 6 fails.

[0161] For this purpose, the server device 2 stores a keyword table containing the set keywords in the memory 22 or the storage device 23. Each keyword has a different usage period, and is therefore associated with a plurality of erasure operations that are performed at different times.

[0162] FIG. 26 is a flowchart showing the erasure process of the server device 2 by the erasure application program 92 executed by the processor 21 of the server device 2 according to the second modification of the second embodiment.

[0163] After step S121 is executed, the process proceeds to step S122. In step S122, the server device 2 adds the keyword newly set in step S121 to the keyword table to update the keyword table. After step S122 is executed, the process proceeds to step S53.

[0164] In step S56A, as described above, the server device 2 generates a processing number and transmits the processing number and the keyword to the client device 1. Here, the server device 2 transmits the latest keyword included in the keyword table to the client device.

[0165] If an erasure result is received from the user terminal device 4 in step S59, the process proceeds to step S123. In step S123, the server device 2 compares the keywords included in the keyword table based on the erasure result and selects the keyword associated with the current erasure operation being performed by the client device 1, i.e., the same keyword as the keyword transmitted in step S56A. For example, the server device 2 selects the keyword that was used at the time the erasure operation of the data stored in the storage device 13 of the client device 1 started, based on the erasure start time included in the erasure result. After performing step S123, the process proceeds to step S60, where the server device 2 reads the selected keyword from the memory 22 or the storage device 23 and transmits it to the user terminal device 4.

[0166] In this modification, the client device 1 operates in the same manner as in the cases of FIGS.

[0167] Fig. 27 is a sequence diagram showing the operation of the system 100 according to the second modified example of the second embodiment when the system 100 has succeeded in transmitting the erasure result information via the communication line 6. Fig. 28 is a sequence diagram showing the operation of the system 100 according to the second modified example of the second embodiment when the system 100 has failed in transmitting the erasure result information via the communication line 6.

[0168] 27, after executing step S52, the server device 2 sets a keyword in step S121. Next, in step S122, the server device 2 adds the newly set keyword to the keyword table to update the keyword table. Thereafter, the server device 2 transmits the latest keyword together with the processing number to the client device 1. If the transmission of the erasure result information via the communication line 6 is successful, the client device 1 and server device 2 operate in the same manner as in the cases of FIGS. 16 and 22.

[0169] 28, in step S123, the server device 2 checks the keywords included in the keyword table based on the erasure result and selects a keyword associated with the current erasure operation being performed by the client device 1. Then, the server device 2 transmits the selected keyword to the user terminal device 4.

[0170] Thereafter, the client device 1 and the server device 2 execute the remaining steps of the erasure process in the same manner as in the first embodiment.

[0171] 29 is a diagram showing exemplary contents of a keyword table stored in the memory 22 or storage device 23 of the server device 2 according to the second modification of the second embodiment. The keyword table in FIG. 29 includes four keywords having different usage periods (i.e., combinations of usage start date and time and usage end date and time). As described above, the server device 2 can select the keyword that was in use at the time when the erasure operation of the data stored in the storage device 13 of the client device 1 was started, based on the erasure start time included in the erasure result.

[0172] 30 is a diagram showing another example of the contents of a keyword table stored in the memory 22 or storage device 23 of the server device 2 according to the second modification of the second embodiment. The keyword table in FIG. 30 includes the processing number transmitted together with the keyword in step S56A. In this case, the server device 2 can select the keyword that was in use at the time when the operation to erase data stored in the storage device 13 of the client device 1 was started, based on the processing number included in the erasure result.

[0173] In this modification, the multiple keywords may be generated inside the server device 2 or may be obtained from outside the server device 2. In the former case, the server device 2 may periodically generate new keywords by executing the erasure application program 92. In the latter case, the server device 2 may periodically display the window 220 of Fig. 25 on the display device 26 or 36 to prompt the administrator to input new keywords.

[0174] According to this modified example, even if keywords are updated periodically for security purposes or the like, an appropriate keyword associated with the current erasure operation being performed by the client device 1 can be sent to the user terminal device 4.

[0175] [Advantages of the second embodiment] According to one aspect of the present disclosure, the server device 2 may internally generate a keyword. In this case, the server device 2 transmits the generated keyword to the client device 1 as a first keyword and stores the generated keyword in the memory 22 or the storage device 23 as a second keyword.

[0176] This eliminates the need to distribute keywords to the client device 1 and the server device 2 in advance.

[0177] According to an embodiment of the present disclosure, the server device 2 may further include a second input device 27 or 37 that acquires a keyword from outside. In this case, the server device 2 transmits the acquired keyword to the client device 1 as a first keyword, and stores the acquired keyword in the memory 22 or the storage device 23 as a second keyword.

[0178] This eliminates the need to distribute keywords to the client device 1 and the server device 2 in advance.

[0179] According to one embodiment of the present disclosure, the memory 22 or the storage device 23 may store multiple second keywords associated with multiple erasure operations performed at different times. In this case, the erasure completion information includes an erasure start time. Based on the erasure start time included in the erasure completion information received from the user terminal device 4, the server device 2 reads out the second keyword associated with the current erasure operation from the memory 22 or the storage device 23 and transmits it to the user terminal device 4.

[0180] This makes it possible to transmit to the user terminal device 4 an appropriate keyword associated with the current erasing operation, even when the keyword is periodically updated for security purposes or the like.

[0181] According to one aspect of the present disclosure, the memory 22 or the storage device 23 may store multiple process numbers and multiple second keywords associated with multiple erasure operations performed at multiple different times. In this case, the erasure completion information includes the process number. Based on the process number included in the erasure completion information received from the user terminal device 4, the server device 2 reads out the second keyword associated with the current erasure operation from the memory 22 or the storage device 23 and transmits it to the user terminal device 4.

[0182] This makes it possible to transmit to the user terminal device 4 an appropriate keyword associated with the current erasing operation, even when the keyword is periodically updated for security purposes or the like.

[0183] [Third embodiment] In the second embodiment, a case has been described in which the server device 2 sets a keyword and sends the keyword from the server device 2 to the client device 1 during execution of the erasure process. On the other hand, in the third embodiment, a case has been described in which the client device 1 sets a keyword and sends the keyword from the client device 1 to the server device 2 during execution of the erasure process.

[0184] [Configuration of the third embodiment] The configuration of the system 100 according to the third embodiment is the same as the configuration of the system 100 according to the first embodiment described with reference to FIGS. 1 to 5 and the like.

[0185] [Operation of the third embodiment] FIG. 31 is a schematic diagram illustrating distribution of keywords in the system 100 according to the third embodiment. In the third embodiment, as described above, the client device 1 sets a keyword and transmits the keyword to the server device 2 during the erasure process. The client device 1 sets the keyword, for example, by executing the erasure application program 70 to generate the keyword internally. In this case, the client device 1 may generate the keyword randomly. The set keyword is stored in the storage device 14 of the client device 1. The client device 1 also transmits the set keyword to the server device 2. The server device 2 receives the keyword transmitted from the client device 1 using the erasure application program 92 and writes it to the memory 22 or the storage device 23. As a result, the same keyword is distributed to the server device 2 and the client device 1.

[0186] The server device 2 may receive keywords generated by each of the multiple client devices 1 from the multiple client devices 1. The server device 2 manages the multiple keywords received from each of the multiple client devices 1 in an identifiable manner, in order to send an appropriate keyword to the user terminal device 4 when transmission of erasure result information via the communication line 6 fails. For this purpose, the server device 2 stores a keyword table containing the multiple keywords received from each of the multiple client devices 1 in the memory 22 or the storage device 23. The keyword table includes, in association with the keyword generated by the client device 1 having the storage device 13 to be erased, for example, identification information of the storage device 13 to be erased, identification information of the client device 1 having the storage device 13 to be erased, or a process number associated with the erasure operation to be performed on the storage device 13 to be erased.

[0187] Fig. 32 is a flowchart showing erasure processing of the client device 1 by the erasure application program 70 executed by the processor 11 of the client device 1 according to the third embodiment. Fig. 33 is a flowchart showing erasure processing of the server device 2 by the erasure application program 92 executed by the processor 21 of the server device 2 according to the third embodiment.

[0188] 32, if it is determined in step S22 that an erasure flag has been registered, the client device 1 executes step S131. In step S131, the core control unit 71 of the erasure application program 70 sets a keyword. As described above, the core control unit 71 sets the keyword, for example, by generating the keyword inside the client device 1. After executing step S131, the client device 1 executes step S23A instead of step S23. In step S23A, the core control unit 71 uses the communication device 15 to transmit information about the client device 1, information about the storage device 13, and the keyword to the server device 2. After executing step S23A, the process proceeds to step S24.

[0189] 33, the server device 2 executes step S55A instead of step S55. In step S55A, the server device 2 determines whether or not it has received the information about the client device 1, the information about the storage device 13, and a keyword from the client device 1. If the determination is YES, the server device 2 proceeds to step S56, and if the determination is NO, the server device 2 returns to step S51.

[0190] In step S56, the server device 2 generates a processing number and transmits it to the client device 1. Next, in step S141, the server device 2 adds the keyword received in step S55A and the processing number generated in step S56 to the keyword table to update the keyword table. After executing step S141, the process proceeds to step S57.

[0191] Thereafter, if an erasure result is received from the user terminal device 4 in step S59, the process proceeds to step S142. In step S142, the server device 2 compares the keywords included in the keyword table based on the erasure result and selects the keyword associated with the current erasure operation being performed by the client device 1, i.e., the keyword received in step S55A. After executing step S142, the process proceeds to step S60, where the server device 2 reads the selected keyword from the memory 22 or the storage device 23 and transmits it to the user terminal device 4.

[0192] Fig. 34 is a sequence diagram showing the operation of the system 100 according to the third embodiment when the system 100 has succeeded in transmitting the erasure result information via the communication line 6. Fig. 35 is a sequence diagram showing the operation of the system 100 according to the third embodiment when the system 100 has failed in transmitting the erasure result information via the communication line 6.

[0193] 34, after receiving a response signal from the server device 2 in response to the inquiry about the erasure flag, the client device 1 sets a keyword in step S131. The client device 1 then transmits the keyword to the server device 2 along with information about the client device 1 and the storage device 13. If the information about the client device 1 and the storage device 13 received by the server device 2 matches the information about the client device 1 and the storage device 13 registered in the server device 2's management table, the server device 2 generates a processing number for the storage device 13 of the client device 1 and transmits it to the client device 1. Furthermore, the server device 2 adds the keyword and the processing number to the keyword table to update the keyword table. If the transmission of the erasure result information via the communication line 6 is successful, the client device 1 and the server device 2 operate in the same manner as in FIGS. 16, 22, and 27.

[0194] 35, in step S142, the server device 2 checks the keywords included in the keyword table based on the erasure result and selects a keyword associated with the current erasure operation being performed by the client device 1. Then, the server device 2 transmits the selected keyword to the user terminal device 4.

[0195] Thereafter, the client device 1 and the server device 2 execute the remaining steps of the erasure process in the same manner as in the first embodiment.

[0196] FIG. 36 illustrates exemplary contents of a keyword table stored in the memory 22 or the storage device 23 of the server device 2 according to the third embodiment. The keyword table in FIG. 36 includes a processing number associated with an erasure operation to be performed on the storage device 13 to be erased and a keyword generated by the client device 1 including the storage device 13 to be erased. In this case, the server device 2 can select a keyword generated by the client device 1 including the storage device 13 to be erased based on the processing number included in the erasure result. The keyword table may include identification information for the storage device 13 to be erased or identification information for the client device 1 including the storage device 13 to be erased, for example, information identical to at least part of the information about the client device 1 and the storage device included in the management table in FIG. 10. While FIG. 36 illustrates a case in which the keyword table includes the UUID of the client device 1, it may also include other information about the client device 1 or the storage device. This allows the server device 2 to transmit to the user terminal device 4 an appropriate keyword associated with the current erasure operation being performed by the client device 1, even when the server device 2 receives keywords from multiple client devices 1.

[0197] According to the system of the third embodiment, the client device 1 sets a keyword and sends it to the server device 2 during the erasure process, so similar to the system of the second embodiment, there is no need to distribute the keyword in advance to the client device 1 and the server device 2. Therefore, there is no need to provide in advance a special firmware program or application program with an embedded keyword for the client device 1 equipped with the storage device 13 to be erased.

[0198] [Modification of the third embodiment] FIG. 37 is a schematic diagram for explaining distribution of keywords in the system 100 according to the first modified example of the third embodiment. Instead of generating keywords internally, the client device 1 may set keywords by acquiring them externally, for example, from a user. In step S131 of FIG. 32, the client device 1 may display the window 220 of FIG. 25 on the display device 16 to prompt the user to input a keyword. The user inputs a keyword using the input device 17 of the client device 1. Even when the client device 1 acquires a keyword externally, the deletion process is executed in the same manner as in the cases of FIGS. 32 to 35.

[0199] [Advantages of the third embodiment] According to one embodiment of the present disclosure, the client device 1 may internally generate a keyword. In this case, the client device 1 stores the generated keyword in the second storage device 14 as a first keyword and transmits the generated keyword to the server device 2 as a second keyword.

[0200] This eliminates the need to distribute keywords to the client device 1 and the server device 2 in advance.

[0201] According to one embodiment of the present disclosure, the client device 1 may acquire a keyword from the outside using the first input device 17. In this case, the client device 1 stores the acquired keyword in the second storage device 14 as a first keyword, and transmits the acquired keyword to the server device 2 as a second keyword.

[0202] This eliminates the need to distribute keywords to the client device 1 and the server device 2 in advance.

[0203] [Other embodiments] As described above, the embodiments have been described as examples of the technology disclosed in this application. However, the technology in this disclosure is not limited to these, and can be applied to embodiments in which appropriate modifications, substitutions, additions, omissions, etc. are made. Furthermore, it is also possible to combine the components described in the above embodiments to create new embodiments.

[0204] Therefore, other embodiments will be exemplified below.

[0205] In the second embodiment, a case has been described in which the server device 2 sets a keyword before receiving an inquiry about the deletion flag from the client device 1. Alternatively, the server device 2 may randomly generate a keyword after receiving an inquiry about the deletion flag from the client device 1.

[0206] When the administrator accesses the server device 2 via the administrator device 3, the display device 26 and the input device 27 of the server device 2 may be omitted.

[0207] After erasing the data stored in the storage device 13, the client device 1 may verify that the data has been erased. The client device 1 transmits the verification result to the server device 2 via the communication line 6. However, if the verification result cannot be transmitted from the client device 1 to the server device 2, the client device 1 may generate a two-dimensional barcode containing the verification result and display it on the display device 26. This allows a user or administrator who has access to the client device 1 to photograph the two-dimensional barcode using the user terminal device 4 and transmit the verification result contained in the two-dimensional barcode from the user terminal device 4 to the server device 2. When generating a two-dimensional barcode containing the verification result, a keyword can be used to reliably transmit the verification result to the server device 2, just as in the case of generating a two-dimensional barcode containing erasure completion information.

[0208] When issuing an erasure permit, it may be possible to issue it by specifying the model. In addition to the model, user information may be entered in the notes so that if a user has a model other than the specified model, an erasure permit for the specified model may be issued. The specified models may be displayed in a list so that the administrator can issue an erasure permit. This has the effect of allowing the client device 1 to be managed in a way that reflects the user's intentions, such as discarding models that have predetermined features or discarding models that do not have predetermined features (for example, discarding models that do not have both the form of a notebook computer and a tablet computer (so-called "2-in-1")). This has the effect of allowing, for example, older models to be discarded first.

[0209] Furthermore, erasure authorization may be issued by specifying the manufacturer of the storage device 13. This has the effect of eliminating client devices 1 supplied by manufacturers that tend to cause malfunctions.

[0210] The management table of the server device 2 may also have a remarks column in which any character string can be entered. By entering user information in the remarks column, users who use multiple client devices 1 can be listed and erasure authorization can be issued. This has the effect of reducing the total number of client devices 1. Furthermore, by entering user information in the remarks column, it becomes easier to handle multiple client devices 1 in units such as departments or sections.

[0211] Furthermore, by transmitting SMART (Self-Monitoring Analysis and Reporting Technology) information of the client device 1 to the server device 2, a client device 1 in poor condition may be discovered and erasure permission may be issued based on that information. To evaluate the status of the storage device 13 based on the SMART information, for example, the number of sectors that have been replaced, the number of power-on times, the error rate caused by impact, the length of use time, the temperature, the increase in the above parameters as seen by the server device 2, or a combination thereof may be used. The client device 1 may calculate the status of the client device 1 based on the SMART information and transmit the status as remarks to the server device 2. Registered client devices 1 may periodically send SMART information to the server device 2 so that the server device 2 can grasp the status of all client devices 1. Registered client devices 1 may periodically calculate the status of the client device 1 based on the SMART information of the client device 1 and transmit the status as remarks to the server device 2 so that the server device 2 can grasp the status of all client devices 1. This has the effect of enabling client devices 1 in poor condition to be discarded first.

[0212] Furthermore, by sending the usage time of the client device 1 to the server device 2, a client device 1 in poor condition may be discovered and erasure permission may be issued based on that information. The usage time of the client device 1 may also be sent as remark information to the server device 2. This has the effect of enabling client devices 1 with long usage times to be discarded first.

[0213] Furthermore, stress information of the client device 1 may be sent to the server device 2 to discover client devices 1 in poor condition and issue deletion permission based on that information. The stress of the client device 1 may be sent as remark information to the server device 2. This has the effect of making it possible to discard client devices 1 that have been used in high-load environments.

[0214] 11, 13, 16, and 17, the client device 1 inquires about the deletion flag and transmits information about the client device 1 and the storage device 13 to the server device 2 separately, but these communications may be performed simultaneously. When the server device 2 receives the information about the client device 1 and the storage device 13 from the client device 1, the server device 2 may consider that it has received an inquiry about the deletion flag.

[0215] 11 to 13, 16, and 17, the case has been described where the client device 1 is restarted and transitions from erasure processing using a combination of the application program 70 and the firmware program 50 to erasure processing using only the firmware program 50. However, the client device 1 may be configured to transition from erasure processing using a combination of the application program 70 and the firmware program 50 to erasure processing using only the firmware program 50 without restarting.

[0216] 2, the client device 1 is described as having only one storage device 13 from which stored data is to be erased, but the client device 1 may also have multiple storage devices 13 from which stored data is to be erased. The multiple storage devices 13 may be configured as, for example, a RAID (Redundant Array of Inexpensive Disks) device. In this case, the multiple storage devices 13 are treated as an integrated device, and the data stored therein is erased as a unit. Alternatively, the multiple storage devices 13 may be treated individually, and the data stored therein may be erased individually.

[0217] When erasing data stored in the storage device 13, if secure erase is specified as the erasure method but fails, and triple overwrite erase is performed as an alternative and is successful, "triple overwrite erase" is recorded as the erasure result information. The firmware program 50 presets an alternative process to be performed in the event of an erase failure. For example, each time an erase fails, the erase method may be changed in the following order: secure erase → triple overwrite erase → single overwrite erase.

[0218] As described above, the embodiments have been described as examples of the technology in the present disclosure, and for that purpose, the accompanying drawings and detailed description have been provided.

[0219] Therefore, the components shown in the accompanying drawings and detailed description may include not only essential components for solving the problem, but also components that are not essential for solving the problem in order to illustrate the above technology. Therefore, the fact that these non-essential components are shown in the accompanying drawings or detailed description should not be interpreted as immediately indicating that these non-essential components are essential.

[0220] Furthermore, since the above-described embodiments are intended to illustrate the technology of the present disclosure, various modifications, substitutions, additions, omissions, etc. may be made within the scope of the claims or their equivalents. [Industrial Applicability]

[0221] An electronic device according to one aspect of the present disclosure is useful for erasing data stored in a storage device. [Explanation of symbols]

[0222] 1,1-1~1-3 Client device 2. Server device 3 Administrator device 4. User terminal equipment 5 Base station equipment 6. Communication lines 10 Bus 11 processors 12 Memory 13 Storage device 14 Storage device 15. Communications equipment 16 Display device 17 Input Devices 20 Bus 21 processors 22 Memory 23 Storage device 25 Communication equipment 26 Display device 27 Input Devices 30 Bus 31 processors 32 memory 33 Storage device 35 Communication equipment 36 Display device 37 Input Devices 40 Bus 41 processors 42 memory 43 Storage device 45 Communication equipment 46 Display device 47 Input Devices 48 Imaging Device 50 Firmware Program 51 Core control unit 52 Erase control section 53 Data Encoding Unit 54 Two-dimensional barcode generator 60 Operating Systems 61 Device Information Monitor 62 Power management section 70 Erasure Application Program 71 Core control unit 81 Core control unit 82 Readout section 83 Writing section 84 Eraser 91 Operating Systems 92 Erasure Application Program 100 systems 200 display screen 201 Two-dimensional barcode 202 Input field 211 Keywords 220 Window 221 Input field

Claims

1. 1. A system for erasing data stored on a storage device of at least one electronic device, comprising: the system includes the at least one electronic device, a server device, and a terminal device; the electronic device includes a first storage device that stores data to be erased, a second storage device that stores a first keyword, a first display device, and a first input device; the server device includes a third storage device that stores a second keyword; the terminal device includes an imaging device and a second display device; the electronic device erases the data stored in the first storage device, and displays on the first display device a graphic code including erasure completion information indicating that erasure of the data stored in the first storage device has been completed; the terminal device photographs the graphic code using the photographing device, extracts the erasure completion information from the graphic code, and transmits the erasure completion information to the server device; the server device receives the erasure completion information from the terminal device, reads the second keyword from the third storage device, and transmits the second keyword to the terminal device; the terminal device receives the second keyword from the server device and displays the keyword on the second display device; the electronic device acquires the second keyword input via the first input device, and shuts down the electronic device if the second keyword input via the first input device matches the first keyword stored in the second storage device; system.

2. the first storage device stores data including an operating system, application programs, and user data; the second storage device further stores a firmware program; the electronic device erases all data stored in the first storage device by executing the firmware program; The system of claim 1 .

3. The first keyword is embedded in the firmware program in advance. The system of claim 2.

4. the server device internally generates a keyword, transmits the generated keyword to the electronic device as the first keyword, and stores the generated keyword in the third storage device as the second keyword; The system of claim 1 .

5. the server device further includes a second input device (27 or 37) that acquires a keyword from the outside, transmits the acquired keyword to the electronic device as the first keyword, and stores the acquired keyword in the third storage device as the second keyword; The system of claim 1 .

6. the third storage device stores a plurality of second keywords respectively associated with a plurality of erasure operations executed at a plurality of different times; the erasure completion information includes an erasure start time, the server device reads a second keyword associated with the current erasure operation from the third storage device based on the erasure start time included in the erasure completion information received from the terminal device, and transmits the second keyword to the terminal device; 6. A system according to claim 4 or 5.

7. the third storage device stores a plurality of process numbers and a plurality of second keywords respectively associated with a plurality of erasure operations executed at a plurality of different times; the erasure completion information includes the processing number, the server device reads a second keyword associated with the current erasure operation from the third storage device based on a processing number included in the erasure completion information received from the terminal device, and transmits the second keyword to the terminal device; 6. A system according to claim 4 or 5.

8. the electronic device internally generates a keyword, stores the generated keyword in the second storage device as the first keyword, and transmits the generated keyword to the server device as the second keyword; The system of claim 1 .

9. the electronic device externally acquires a keyword using the first input device, stores the acquired keyword in the second storage device as the first keyword, and transmits the acquired keyword to the server device as the second keyword; The system of claim 1 .

10. The graphic code is a two-dimensional bar code. The system of claim 1 .

11. The electronic device is After erasing the data stored in the first storage device, transmitting the erasure completion information to the server device; If an acknowledgement signal for the transmitted erasure completion information is received from the server device within a predetermined period of time, the electronic device is shut down without displaying the graphic code on the first display device; if the acknowledgement signal is not received from the server device within the predetermined period of time, displaying the graphic symbol on the first display device. The system of claim 1 .

12. The server device obtaining the erasure completion information from the electronic device; issuing an erasure certificate that certifies that erasure of the data stored in the first storage device has been completed based on the erasure completion information; 11. The system of claim 1 or 10.

13. 1. An electronic device for processing information, comprising: a first storage device that stores data to be erased; a second storage device for storing the first keyword; a first display device for displaying information; a first input device for accepting input from a user of the electronic device; a processor for controlling the electronic device; The processor: erasing the data stored in the first storage device; displaying on the first display device a graphic code including erasure completion information indicating that erasure of the data stored in the first storage device has been completed; acquiring, via the first input device, a second keyword obtained by the user transmitting erasure completion information included in the graphic code to a server device; comparing the second keyword with the first keyword stored in the second storage device and shutting down the electronic device if a match is found; electronic equipment.

14. 1. A method of operating a system for erasing data stored on a storage device of at least one electronic device, comprising: the system includes the at least one electronic device, a server device, and a terminal device; the electronic device includes a first storage device that stores data to be erased, a second storage device that stores a first keyword, a first display device, and a first input device; the server device includes a third storage device that stores a second keyword; the terminal device includes an imaging device and a second display device; The operating method includes: erasing the data stored in the first storage device by the electronic device, and displaying on the first display device a graphic code including erasure completion information indicating that erasure of the data stored in the first storage device has been completed; a step of taking an image of the graphic code using the photographing device by the terminal device, extracting the erasure completion information from the graphic code, and transmitting the erasure completion information to the server device; receiving, by the server device, the erasure completion information from the terminal device, reading the second keyword from the third storage device, and transmitting the second keyword to the terminal device; receiving the second keyword from the server device by the terminal device and displaying the keyword on the second display device; acquiring, by the electronic device, the second keyword input via the first input device, and shutting down the electronic device if the second keyword input via the first input device matches the first keyword stored in the second storage device. How it works.

Citation Information

Patent Citations

  • OTP generating system and mobile communication terminal

    JP2015228098A

  • Data erasing method, data erasing program, and administrative server

    JP2018136778A

  • Image forming apparatus and image processing system

    JP2022076250A

  • Electronic device and remote control system

    US20180004423A1