Information processing device

The information processing device uses hash values to verify data erasure in self-encrypting storage, addressing the heavy load issue of conventional methods by comparing encrypted data, thus efficiently confirming data erasure without external support.

JP7777800B2Active Publication Date: 2025-12-01PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2024567238
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2023-06-20
Filing Date
2023-10-16
Publication Date
2025-12-01
Estimated Expiration
2043-10-16

AI Technical Summary

Technical Problem

Conventional methods for verifying data erasure in storage devices place a heavy load on information processing devices due to the need to compare large amounts of data, requiring external assistance.

Method used

An information processing device with a self-encrypting storage device and an erasure controller that uses hash values to verify data erasure by comparing encrypted data before and after a key change, reducing the load by using hash values instead of full data comparison.

Benefits of technology

The method allows for successful verification of data erasure with a smaller load on the processing device, eliminating the need for external assistance and reducing processing time.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007777800000001
    Figure 0007777800000001
  • Figure 0007777800000002
    Figure 0007777800000002
  • Figure 0007777800000003
    Figure 0007777800000003
Patent Text Reader

Abstract

In the present invention, a deletion controller (14) acquires a first hash value obtained by calculating on the basis of data to be stored or having been stored in a designated position in a storage region. The deletion controller (14) controls a storage device (13) to change a first encryption key stored in a nonvolatile memory (23) into a second encryption key. The deletion controller (14) calculates a second hash value on the basis of data read out from the designated position in the storage region. The deletion controller (14) outputs, when the second hash value is different from the first hash value, a verification result indicating that deletion of the data stored in the storage device (13) has succeeded. The deletion controller (14) outputs, when the second hash value coincides with the first hash value, a verification result indicating that the deletion of the data stored in the storage device (13) has failed.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to an information processing device, an information processing method, an information processing system, and a program. [Background technology]

[0002] When discarding an information processing device such as a personal computer, in order to prevent leakage of confidential data, it is required to erase the data stored in the storage device (or equivalently, make the data inaccessible) and verify that the data has been securely erased. For example, Patent Document 1 and Non-Patent Document 1 disclose methods for verifying data erasure. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Patent No. 7096829 [Non-patent literature]

[0004] [Non-Patent Document 1] Richard Kissel et al., "Guidelines for Media Sanitization," NIST Special Publication 800-88, Revision 1, National Institute of Standards and Technology, December 2014 [Retrieved December 1, 2022], Internet<URL:http: / / dx.doi.org / 10.6028 / NIST.SP.800-88r1> Summary of the Invention [Problem to be solved by the invention]

[0005] Conventionally, to verify whether data erasure was successful, the current data stored in the storage device after erasure (e.g., pattern data or random data overwritten on the original data) is compared with the original data stored in the storage device before erasure. In this case, a large amount of data is compared, which places a heavy load on the information processing device. Therefore, it is required to verify whether data erasure was successful with a smaller load than conventional methods.

[0006] The present disclosure provides an information processing device, an information processing method, an information processing system, and a program that can verify whether data stored in a storage device has been successfully erased with a smaller load than conventional methods. [Means for solving the problem]

[0007] An information processing device according to one aspect of the present disclosure includes: a storage device having a function of self-encrypting data to be stored; an erasure controller for controlling erasure of data stored in the storage device, The storage device a storage medium having a storage area; a non-volatile memory storing an encryption key; an input / output controller that writes input data to the storage area, outputs data read from the storage area, encrypts at least a portion of the data to be written to the storage area using the encryption key, and decrypts at least a portion of the data read from the storage area using the encryption key; The erasure controller If a first encryption key is stored in the nonvolatile memory, a first hash value calculated based on data to be stored at a specified location in the storage area or based on data stored at a specified location in the storage area is obtained; controlling the storage device to change the first encryption key stored in the nonvolatile memory to a second encryption key; If the second encryption key is stored in the nonvolatile memory, a second hash value is calculated based on the data read from the specified location in the storage area; If the second hash value is different from the first hash value, outputting a verification result indicating that the data stored in the storage device has been successfully erased; If the second hash value matches the first hash value, a verification result indicating that erasure of the data stored in the storage device has failed is output. [Effects of the Invention]

[0008] According to an information processing device according to an aspect of the present disclosure, it is possible to verify whether data stored in a storage device has been successfully erased with a smaller load than conventionally required. [Brief explanation of the drawings]

[0009] [Figure 1] 1 is a block diagram showing a configuration of an information processing device 1 according to a first embodiment. [Figure 2] FIG. 2 is a block diagram showing the configuration of a storage device 13 in FIG. [Figure 3] 3 is a schematic diagram showing logical blocks 31 of the flash memory 24 of FIG. 2, showing an example of the arrangement of logical blocks 31 that are compared to verify the erasure of data. FIG. [Figure 4] 10 is a flowchart showing an erasing process according to a first comparative example. [Figure 5] 10 is a flowchart showing an erasing process according to a second comparative example. [Figure 6] 10 is a flowchart showing an erasure process according to the first embodiment, which is executed by an erasure controller 14 of FIG. [Figure 7] 1 is a table comparing verification methods according to Comparative Example 1, Comparative Example 2, and Example 1. [Figure 8] 3 is a schematic diagram showing logical blocks 31 of the flash memory 24 of FIG. 2, illustrating a first variation of the arrangement of logical blocks 31 that are compared to verify the erasure of data. FIG. [Figure 9] 3 is a schematic diagram showing logical blocks 31 of the flash memory 24 of FIG. 2, illustrating a second variation of the arrangement of logical blocks 31 that are compared to verify the erasure of data. FIG. [Figure 10] 10 is a flowchart showing an erasure process according to a second embodiment, which is executed by an erasure controller 14 of FIG. [Figure 11] 10 is a flowchart showing an erasure process according to a third embodiment, which is executed by an erasure controller 14 of FIG. [Figure 12] 3 is a schematic diagram showing logical blocks 31 of flash memory 24 of FIG. 2, where all logical blocks 31 are compared to verify erasure of data. [Figure 13] FIG. 3 is a schematic diagram showing logical blocks 31 of the flash memory 24 of FIG. 2, illustrating a case where logical blocks 31 included in each of partial areas 24b-1 and 24b-2 are compared to verify data erasure. [Figure 14] FIG. 3 is a schematic diagram showing logical blocks 31 of the flash memory 24 of FIG. 2, illustrating a case where logical blocks 31 included in each of partial areas 24c-1 to 24c-4 are compared to verify data erasure. [Figure 15] FIG. 3 is a schematic diagram showing logical blocks 31 of the flash memory 24 of FIG. 2, illustrating a case where logical blocks 31 included in each of partial areas 24d-1 to 24d-8 are compared to verify data erasure. [Figure 16] FIG. 10 is a block diagram showing a configuration of an information processing device 1A according to a modified example of the first embodiment. [Figure 17] 10 is a flowchart showing an erasure process executed by the information processing device 1 according to the second embodiment. [Figure 18] 18 is a flowchart showing a subroutine of the pre-processing (step S101) in FIG. [Figure 19] 18 is a flowchart showing a subroutine of the key change process (step S102) of FIG. [Figure 20]18 is a flowchart showing a subroutine of the verification process (step S103) of FIG. 17. [Figure 21] 18 is a diagram showing an example of an image indicating the progress of data erasure, which is displayed on the display device 18 of FIG. 1 by executing the erasure process of FIG. 17. FIG. [Figure 22] 18 is a diagram showing another example of an image showing the progress of data erasure, which is displayed on the display device 18 of FIG. 1 by executing the erasure process of FIG. 17. FIG. [Figure 23] 18 is a flowchart showing a first modified example of the verification process of FIG. 17. [Figure 24] 18 is a flowchart showing a second modified example of the verification process of FIG. 17. [Figure 25] 18 is a flowchart showing a third modified example of the verification process of FIG. [Figure 26] FIG. 10 is a block diagram showing a configuration of an information processing system including an information processing device 1 and a server device according to a third embodiment. [Figure 27] FIG. 27 is a block diagram showing the configuration of the server device 2 in FIG. 26. [Figure 28] 27 is a flowchart showing the erasure process executed by the server device 2 of FIG. 26. [Figure 29] 27 is a flowchart showing an erasure process executed by the information processing device 1 of FIG. 26. [Figure 30] 27 is a flowchart showing a modified example of the erasure process executed by the server device 2 of FIG. 26. [Figure 31] 27 is a flowchart showing a modified example of the erasure process executed by the information processing device 1 of FIG. 26. [Figure 32] 32 is a flowchart showing a subroutine of the pre-processing (step S231) of FIG. 31. [Figure 33] 32 is a flowchart showing a subroutine of the key change process (step S232) of FIG. [Figure 34] 32 is a flowchart showing a subroutine of the verification process (step S233) of FIG. 31. DETAILED DESCRIPTION OF THE INVENTION

[0010] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. However, more detailed description than necessary may be omitted. For example, detailed description of well-known matters or redundant description of substantially identical configurations may be omitted. This is to avoid unnecessary redundancy in the following description and to facilitate understanding by those skilled in the art.

[0011] The inventor(s) provide the accompanying drawings and the following description to enable those skilled in the art to fully understand the present disclosure, and do not intend for them to limit the subject matter described in the claims.

[0012] [First embodiment] [Configuration of the first embodiment] 1 is a block diagram showing the configuration of an information processing device 1 according to the first embodiment. The information processing device 1 includes a bus 10, a central processing unit (CPU) 11, a random access memory (RAM) 12, a storage device 13, an erasure controller 14, a non-volatile memory 15, a communication device 16, an input device 17, and a display device 18.

[0013] The CPU 11 controls the overall operation of the information processing device 1 .

[0014] The RAM 12 temporarily stores programs and data necessary for the operation of the information processing device 1.

[0015] The storage device 13 stores data including an operating system, application programs, and user data. The storage device 13 is a self-encrypting drive (SED) that has a function of self-encrypting stored data, such as a solid-state drive (SSD) that has a function of self-encrypting.

[0016] The erasure controller 14 controls erasure of data stored in the storage device 13 by executing an erasure process described later with reference to Fig. 6 etc. In this disclosure, "erasure" means making at least some of the data stored in the storage device 13 inaccessible. The erasure controller 14 includes, for example, a microprocessor.

[0017] The nonvolatile memory 15 stores programs and data required to execute the erasure process. The nonvolatile memory 15 includes a nonvolatile storage medium such as a flash memory.

[0018] The program for the erasure process may be incorporated into a firmware program of the information processing device 1, such as a UEFI (Unified Extensible Firmware Interface) or BIOS (Basic Input / Output System) program. In this case, the program for the erasure process may be stored in the same storage medium as the UEFI or BIOS program, and may be executed by the same microprocessor as the UEFI or BIOS program.

[0019] The communication device 16 is connected to other external information processing devices via a communication line such as a local area network (LAN) so as to be able to communicate with them.

[0020] The input device 17 receives user inputs that control the operation of the information processing device 1. The input device 17 includes, for example, a keyboard and a pointing device.

[0021] The display device 18 displays information relating to the state of the information processing device 1, for example, information relating to the erasure of data stored in the storage device 13.

[0022] The CPU 11 , RAM 12 , storage device 13 , erasure controller 14 , non-volatile memory 15 , communication device 16 , input device 17 , and display device 18 are connected to one another via a bus 10 .

[0023] The information processing device 1 is, for example, a personal computer.

[0024] FIG. 2 is a block diagram showing the configuration of the storage device 13 in FIG. 1. The storage device 13 includes an input / output controller 21, a random access memory (RAM) 22, a nonvolatile memory 23, and a flash memory 24. The input / output controller 21 controls writing and reading of data to and from the storage device 13. The RAM 22 is a buffer memory that temporarily stores data to be written to and read from the storage device 13. The nonvolatile memory 23 stores a firmware program (FW) and an encryption key for the storage device 13. The flash memory 24 is a nonvolatile storage medium having a storage area. The input / output controller 21 controls the operation of the storage device 13 by executing the firmware program stored in the nonvolatile memory 23. The input / output controller 21 writes input data to the storage area of ​​the flash memory 24 and outputs data read from the storage area.

[0025] As described above, the storage device 13 has a self-encryption function. The storage device 13 may encrypt and decrypt data stored in the entire storage area of ​​the flash memory 24, or may encrypt and decrypt only data stored in a portion of the storage area. The input / output controller 21 encrypts at least a portion of the data to be written to the storage area of ​​the flash memory 24 using an encryption key stored in the non-volatile memory 23. The input / output controller 21 also decrypts at least a portion of the data read from the storage area of ​​the flash memory 24 using the encryption key. The input / output controller 21 may use hardware, software, or a combination thereof to encrypt and decrypt data.

[0026] By including such a storage device 13, the information processing device 1 can encrypt and decrypt data stored in the storage device 13 without relying on an operating system or an application program.

[0027] In a storage device 13 having a self-encrypting function, when the encryption key is changed, data encrypted with the previous encryption key and stored in a storage area of ​​the flash memory 24 can no longer be decrypted using the changed encryption key. Therefore, by changing the encryption key of the storage device 13, the original data stored in the storage device 13 becomes inaccessible, and the original data stored in the storage device 13 can be equivalently erased (cryptographically erased). The input / output controller 21 changes the encryption key stored in the non-volatile memory 23 under the control of the erasure controller 14. The encryption key may be changed, for example, by the input / output controller 21 executing a revert command included in the firmware of the storage device 13.

[0028] As described above, if only data stored in a portion of the storage area is encrypted and decrypted, the data that is not encrypted or decrypted will not become inaccessible even if the encryption key is changed, and therefore will not be erased. To verify whether the data has been successfully erased, the erasure controller 14 compares the current data stored in the storage device 13 after the encryption key has been changed with the original data that was stored in the storage device 13 before the encryption key was changed. If the current data differs from the original data, the erasure controller 14 determines that the data has been successfully erased. If the current data matches the original data, the erasure controller 14 determines that the data has not been erased.

[0029] FIG. 3 is a schematic diagram showing logical blocks 31 of the flash memory 24 of FIG. 2, illustrating an example of the arrangement of logical blocks 31 compared to verify data erasure. The storage area of ​​the flash memory 24 includes multiple logical blocks 31. Each logical block 31 is a partial area logically divided from the storage area. For example, a 1 TB storage area may be divided into 10,000 logical blocks 31, each having a size of 100 MB. To verify whether data erasure has been successful, the erasure controller 14 may compare data before and after the encryption key change for the entire storage area, or may compare only a portion of the storage area (e.g., 1,000 logical blocks 31 equivalent to 10% of the entire storage area). In the latter case, the logical blocks 31 to be compared may be specified according to a predetermined rule (e.g., the hatched logical blocks 31 in FIG. 3) or may be specified randomly.

[0030] Although the storage area of ​​the flash memory 24 is shown two-dimensionally in FIG. 3 and other figures, the storage area may be considered as a continuous series of memory spaces.

[0031] [Comparative Example] Here, verification of data erasure according to the conventional technology will be described with reference to Fig. 4 and Fig. 5. For the purpose of description, it is assumed that the information processing device 1 of Fig. 1 executes the erasure process shown in Fig. 4 and Fig. 5.

[0032] 4 is a flowchart showing the erasure process according to Comparative Example 1. FIG. 4 shows the method of verifying data erasure disclosed in Non-Patent Document 1.

[0033] The erasure process shown in FIG. 4 is started when an instruction to erase data stored in the storage device 13 is issued via a BIOS or UEFI program, for example.

[0034] In step S1, the erasure controller 14 reads original data from a specified logical block 31, as shown in FIG. 3 . Here, the “original data” refers to data read from a specified logical block 31 in a storage area when the pre-change encryption key is stored in the non-volatile memory 23. If the logical block 31 is to be encrypted and decrypted, the erasure controller 14 acquires data decrypted using the pre-change encryption key. On the other hand, if the logical block 31 is not to be encrypted or decrypted, the erasure controller 14 acquires the data read from the logical block 31 without decrypting it. Generally, for example, if the RAM 12 has a size of several GB to several tens of GB, the storage device 13 has a storage area of ​​1 TB, and 10% of the storage area, i.e., 100 GB of data, is read, it is not possible to store all of the data in the RAM 12. Therefore, in step S2, the erasure controller 14 transmits the original data to an external information processing device to temporarily save it.

[0035] In step S3, the erasure controller 14 changes the encryption key stored in the nonvolatile memory 23. In this specification, the encryption key before the change is also referred to as the "first encryption key," and the encryption key after the change is also referred to as the "second encryption key."

[0036] In step S4, the erasure controller 14 reads the current data of the specified logical block 31, the same as in step S1. Here, "current data" refers to data read from the specified logical block 31 of the storage area when the changed encryption key is stored in the non-volatile memory 23. If this logical block 31 is to be encrypted and decrypted, the erasure controller 14 obtains data decrypted using the changed encryption key. On the other hand, if this logical block 31 is not to be encrypted or decrypted, the erasure controller 14 obtains the data read from the logical block 31 without decrypting it.

[0037] In step S5, the erasure controller 14 receives the temporarily saved original data from the external information processing device.

[0038] In step S6, the erasure controller 14 determines whether the current data is different from the original data, and if YES, proceeds to step S7, and if NO, proceeds to step S8. Here, the current data and the original data are compared for each logical block 31, so this can be performed using a RAM 12 having a size of several GB to several tens of GB.

[0039] In step S7, the erasure controller 14 outputs a verification result indicating that the data erasure was successful to the display device 18. In addition, in step S8, the erasure controller 14 outputs a verification result indicating that the data erasure was unsuccessful to the display device 18.

[0040] 4 requires an external information processing device to temporarily save the data because it compares a large amount of data that cannot be stored in the RAM 12. Therefore, a method for verifying data erasure that can be executed by the information processing device 1 alone without requiring an external information processing device is required.

[0041] 5 is a flowchart showing an erasure process according to Comparative Example 2. FIG. 5 shows the method of verifying data erasure disclosed in Patent Document 1.

[0042] In step S11, the erasure controller 14 writes known pattern data to a specified logical block 31, for example, as shown in Fig. 3. The pattern data includes, for example, a bit string consisting of all 1s, a bit string consisting of all 0s, a random bit string, etc. The pattern data is pre-stored in the non-volatile memory 15. The pattern data is encrypted using the old encryption key and written to the specified logical block 31 in the storage area.

[0043] In step S12, the erasure controller 14 changes the encryption key stored in the nonvolatile memory 23.

[0044] In step S13, the erase controller 14 reads the current data in the same specified logical block 31 as in step S11.

[0045] In step S14, the erase controller 14 determines whether the current data is different from the pattern data, and if YES, proceeds to step S15, and if NO, proceeds to step S16.

[0046] In step S15, the erasure controller 14 outputs a verification result indicating that the data erasure was successful to the display device 18. In addition, in step S16, the erasure controller 14 outputs a verification result indicating that the data erasure was unsuccessful to the display device 18.

[0047] As described above, the pattern data is written to the specified logical block 31 of the storage area when the encryption key before the change is stored in the nonvolatile memory 23. Therefore, the pattern data substantially corresponds to the "original data" in the process of Fig. 4, that is, the data read from the specified logical block 31 of the storage area when the encryption key before the change is stored in the nonvolatile memory 23.

[0048] 5 uses known pattern data and can be executed by the information processing device 1 alone, without the need for an external information processing device. However, like the process in Figure 4, the process in Figure 5 places a heavy load on the information processing device 1 because it compares a large amount of data. Therefore, there is a demand for an erasure process that can verify whether data erasure has been successful with a smaller load.

[0049] Next, an erasure process according to an embodiment will be described, which can verify whether data has been successfully erased with a smaller load.

[0050] [Example 1] FIG. 6 is a flowchart illustrating an erasure process according to the first embodiment, which is executed by the erasure controller 14 of FIG.

[0051] In step S21, the erasure controller 14 writes known pattern data to a specified logical block 31, for example, as shown in FIG. 3. The nonvolatile memory 15 stores the pattern data and also stores in advance a hash value of the pattern data calculated using an arbitrary hash function. The hash function may be, for example, a SHA-2 function such as SHA-256. The SHA-256 function can store up to 2 (64-1) A 256-bit (32-byte) hash value is generated from data of any length up to 1280 bits.

[0052] In step S22, the erasure controller 14 changes the encryption key stored in the nonvolatile memory 23.

[0053] In step S23, the erasure controller 14 reads the current data in the same specified logical block 31 as in step S21. Then, in step S24, the erasure controller 14 calculates a hash value of the current data using the same hash function as that used to calculate the hash value of the pattern data.

[0054] In step S25, the erasure controller 14 reads the hash value of the pattern data from the nonvolatile memory 15.

[0055] In step S26, the erasure controller 14 determines whether the hash value of the current data is different from the hash value of the pattern data, and if YES, proceeds to step S27, and if NO, proceeds to step S28.

[0056] There is a possibility that the hash values ​​of different data may collide. However, it is considered extremely unlikely that the hash value of the pattern data and the hash value of the current data will collide in all of the compared logical blocks 31. Therefore, for example, when comparing hash values ​​in 1,000 logical blocks 31, the erasure controller 14 may determine that the data erasure has been successful even if the hash values ​​match in several logical blocks 31. Furthermore, if the hash values ​​differ in more than half of the logical blocks 31, the erasure controller 14 may determine that the data erasure has been successful.

[0057] Furthermore, if the hash values ​​of the pattern data and the current data match in several adjacent logical blocks 31, the erasure controller 14 may determine that the data erasure has failed. In this case, it is considered that the area including these logical blocks 31 is not subject to encryption or decryption.

[0058] In step S27, the erasure controller 14 outputs a verification result indicating that the data erasure was successful to the display device 18. In addition, in step S28, the erasure controller 14 outputs a verification result indicating that the data erasure was unsuccessful to the display device 18.

[0059] FIG. 7 is a table comparing the verification methods according to Comparative Example 1, Comparative Example 2, and Example 1. It is assumed that the storage device 13 has a storage area of ​​1 TB, and that this storage area is divided into 10,000 logical blocks 31, each having a size of 100 MB. It is also assumed that 10% of the storage area, i.e., a total of 100 GB of data from 1,000 logical blocks 31, is read and verified. According to Comparative Example 1, it is necessary to temporarily save 100 GB of data to an external information processing device. According to Comparative Examples 1 and 2, it is necessary to compare the 100 GB of data before and after the encryption key change. According to Example 1, when the SHA-256 function is used, the data in each logical block 31 is represented by a 32-byte hash value. Therefore, according to Example 1, it is not necessary to temporarily save the data to an external information processing device, and it is only necessary to compare a total of 32 KB of data before and after the encryption key change. Thus, according to Example 1, it is possible to verify whether data erasure was successful with a small load.

[0060] When reading and verifying data that accounts for 10% of the storage area, data from one logical block 31 out of every 10 blocks may be specified. When reading and verifying data that accounts for 5% of the storage area, data from one logical block 31 out of every 20 blocks may be specified. When a storage area is divided into 10,000 logical blocks 31 and 10% of the storage area, i.e., data from 1,000 logical blocks 31, is read and verified, the hash value of the data has a total size of 32 KB. When a storage area is divided into 1,000 logical blocks 31 and 10% of the storage area, i.e., data from 100 logical blocks 31, is read and verified, the hash value of the data has a total size of 3,200 bytes. When a storage area is divided into 10,000 logical blocks 31 and 5% of the storage area, i.e., data from 500 logical blocks 31, is read and verified, the hash value of the data has a total size of 16 KB. Furthermore, if the storage area is divided into 1000 logical blocks 31 and 5% of the storage area, i.e., data in 50 logical blocks 31, is read and verified, the hash value of the data will have a total size of 1600 bytes. In either case, the size of the data to be compared is much smaller than in Comparative Example 1 and Comparative Example 2.

[0061] When the logical blocks 31 to be compared are randomly specified, the addresses of the logical blocks 31 must also be stored. When the storage area is divided into 10,000 or 1,000 logical blocks 31, the address (0 to 9999 or 0 to 999) of each logical block 31 is represented by 2 bytes. Therefore, when reading and verifying data from 1,000, 500, 100, or 50 logical blocks 31, the total size of the addresses to be stored is 2,000 bytes, 1,000 bytes, 200 bytes, or 100 bytes. In either case, the size of the addresses to be stored is relatively small.

[0062] FIG. 8 is a schematic diagram showing logical blocks 31 of the flash memory 24 of FIG. 2, illustrating a first modified example of the arrangement of the logical blocks 31 compared to verify data erasure. The storage area may include a plurality of partial areas 24a-1 to 24a-2, each of which is a logical division of the storage area and includes a plurality of logically contiguous logical blocks 31. In the example of FIG. 8, the partial area 24a-1 has a logical address smaller than the logical address of the partial area 24a-2. The erasure controller 14 may specify a different proportion of the logical blocks 31 for each of the partial areas 24a-1 to 24a-2 among the plurality of logical blocks 31 included in the partial area (e.g., the hatched logical blocks 31 in FIG. 8). The hash value is calculated based on the data stored in the specified plurality of logical blocks 31. Important files of the information processing device 1 (e.g., confidential data such as a login password for the information processing device 1) are likely to be stored in logical blocks 31 with small logical addresses. Therefore, the erasure controller 14 may specify a larger proportion of logical blocks 31 in the partial area 24a-1 than in the partial area 24a-2. By specifying logical blocks 31 as shown in Fig. 8, it is possible to more reliably verify the erasure of data stored in an area that is thought to contain important files of the information processing device 1.

[0063] The storage area of ​​the storage device 13 is not limited to the two partial areas 24a-1 to 24a-2, but may be divided into three or more partial areas.

[0064] 9 is a schematic diagram showing logical blocks 31 of the flash memory 24 of FIG. 2, illustrating a second modified example of the arrangement of logical blocks 31 that are compared to verify data erasure. The erasure controller 14 may designate multiple logical blocks 31 that are logically adjacent to one another (e.g., the hatched logical blocks 31 in FIG. 9). A hash value is calculated based on data stored in the multiple logical blocks 31 that are logically adjacent to one another. The hash value may be calculated based on a logical AND, a logical OR, or an exclusive OR of data stored in two logically adjacent logical blocks 31. Designating logical blocks 31 as shown in FIG. 9 may prevent hash value collisions.

[0065] [Example 2] FIG. 10 is a flowchart illustrating an erasure process according to the second embodiment, which is executed by the erasure controller 14 of FIG.

[0066] In step S31, the erasure controller 14 reads original data from a specified logical block 31, for example, as shown in FIG. 3, FIG. 8, or FIG. 9. Next, in step S32, the erasure controller 14 calculates a hash value of the original data. One hash value may be calculated for each logical block 31, or one hash value may be calculated for a predetermined number of logical blocks 31. In the latter case, a buffer memory for storing the read data is provided in the RAM 12. The buffer memory has, for example, a size ten times that of the logical blocks 31. The erasure controller 14 writes the read data sequentially to the buffer memory, and calculates a hash value of the data when the buffer memory becomes full. Since the power supply of the information processing device 1 is not turned off during execution of the process of FIG. 10 (particularly before and after changing the encryption key), the calculated hash value may be stored in the RAM 12. The calculated hash value may also be stored in the non-volatile memory 15.

[0067] In step S33, the erasure controller 14 changes the encryption key stored in the nonvolatile memory 23.

[0068] In step S34, the erasure controller 14 reads the current data of the same specified logical block 31 as in step S31. Then, in step S35, the erasure controller 14 calculates a hash value of the current data using the same hash function as that used to calculate the hash value of the original data. As in the case of calculating the hash value of the original data, one hash value may be calculated for each logical block 31, or one hash value may be calculated for a predetermined number of logical blocks 31. As a result, for the same one or more logical blocks 31, the hash value of the original data is calculated (step S32), and the hash value of the current data is calculated (step S35).

[0069] In step S36, the erasure controller 14 determines whether the hash value of the current data is different from the hash value of the original data, and if YES, proceeds to step S37, and if NO, proceeds to step S38.

[0070] As mentioned above, there is a possibility that the hash values ​​of different data may collide. However, it is considered extremely unlikely that the hash values ​​of the original data and the current data will collide in all of the compared logical blocks 31. Therefore, for example, when comparing hash values ​​in 1,000 logical blocks 31, the erasure controller 14 may determine that the data erasure was successful even if the hash values ​​match in several logical blocks 31. Furthermore, if the hash values ​​differ in more than half of the logical blocks 31, the erasure controller 14 may determine that the data erasure was successful.

[0071] Furthermore, if the hash values ​​of the original data and the current data match in some adjacent logical blocks 31, the erasure controller 14 may determine that the data erasure has failed. In this case, it is considered that the area including these logical blocks 31 is not subject to encryption or decryption.

[0072] In step S37, the erasure controller 14 outputs a verification result indicating that the data erasure was successful to the display device 18. In addition, in step S38, the erasure controller 14 outputs a verification result indicating that the data erasure was unsuccessful to the display device 18.

[0073] According to the second embodiment, similar to the first embodiment, it is not necessary to temporarily save the data in an external information processing device, and it is only necessary to compare hash values ​​of the data before and after the encryption key is changed. In this way, according to the second embodiment, it is possible to verify whether the data has been successfully erased with a small load.

[0074] Generally, in a solid state drive, writing data takes longer than reading data. According to the process of Fig. 10, there is no need to write pattern data to the storage device 13, so the processing time can be reduced compared to the case of Fig. 6.

[0075] Furthermore, when one hash value is calculated for each of multiple logical blocks 31, the amount of calculation is reduced compared to when one hash value is calculated for each logical block 31, improving processing speed and reducing the memory capacity required to store the calculated hash values.

[0076] [Example 3] FIG. 11 is a flowchart showing an erasure process according to the third embodiment, which is executed by the erasure controller 14 of FIG.

[0077] In step S41, the erasure controller 14 reads original data for the entire storage area and for a portion of the storage area. The storage area includes a plurality of partial areas obtained by logically dividing the storage area into a plurality of partial areas of different sizes. The original data is read for the entire storage area and for each of the partial areas of different sizes. In step S42, the erasure controller 14 calculates a hash value of the original data stored in the entire storage area and for each of the partial areas of different sizes.

[0078] FIG. 12 is a schematic diagram showing the logical blocks 31 of the flash memory 24 of FIG. 2, illustrating a case where all logical blocks 31 are compared to verify data erasure. FIG. 13 is a schematic diagram showing the logical blocks 31 of the flash memory 24 of FIG. 2, illustrating a case where logical blocks 31 included in each of partial areas 24b-1 and 24b-2 are compared to verify data erasure. FIG. 14 is a schematic diagram showing the logical blocks 31 of the flash memory 24 of FIG. 2, illustrating a case where logical blocks 31 included in each of partial areas 24c-1 to 24c-4 are compared to verify data erasure. FIG. 15 is a schematic diagram showing the logical blocks 31 of the flash memory 24 of FIG. 2, illustrating a case where logical blocks 31 included in each of partial areas 24d-1 to 24d-8 are compared to verify data erasure. In the case of FIG. 12, one hash value is calculated for the entire storage area. In the case of FIG. 13, the entire storage area is divided into two partial areas 24b-1 and 24b-2, and one hash value is calculated for each of the partial areas 24b-1 and 24b-2. In the case of FIG. 14, the entire storage area is divided into four partial areas 24c-1 to 24c-4, and one hash value is calculated for each of the partial areas 24c-1 to 24c-4. In the case of FIG. 15, the entire storage area is divided into eight partial areas 24d-1 to 24d-8, and one hash value is calculated for each of the partial areas 24d-1 to 24d-8. As in FIGS. 12 to 15, a hash value may be calculated for each of the further divided partial areas.

[0079] In step S43 of FIG. 11, the erasure controller 14 changes the encryption key stored in the nonvolatile memory 23.

[0080] In step S44, the erasure controller 14 reads the current data in the storage area, and then in step S45, the erasure controller 14 calculates a hash value of the current data in the entire storage area.

[0081] In step S46, the erasure controller 14 determines whether the hash value of the current data is different from the hash value of the corresponding original data calculated in step S42, and if YES, proceeds to step S49, and if NO, proceeds to step S47.

[0082] In step S47, the erasure controller 14 determines whether or not all hash values ​​of the original data calculated in step S42 have been compared, and if YES, proceeds to step S50, and if NO, proceeds to step S48.

[0083] In step S48, the erasure controller 14 calculates a hash value of the current data for each partial area obtained by dividing the storage area. When step S48 is executed for the first time, the erasure controller 14 calculates a hash value of the current data for each of the partial areas 24b-1 and 24b-2 obtained by dividing the storage area into two. When step S48 is executed for the second time, the erasure controller 14 calculates a hash value of the current data for each of the partial areas 24c-1 to 24c-4 obtained by dividing the storage area into four. Thereafter, the erasure controller 14 similarly repeats step S48 and calculates a hash value of the current data for each partial area until the determination in step S46 or S47 is YES.

[0084] In step S49, the erasure controller 14 outputs a verification result indicating that the data erasure was successful to the display device 18. In addition, in step S50, the erasure controller 14 outputs a verification result indicating that the data erasure was unsuccessful to the display device 18.

[0085] According to the process of FIG. 11, even if the hash value of the original data and the hash value of the current data collide in a certain partial area, the collision of the hash values ​​can sometimes be avoided by comparing the hash values ​​of smaller partial areas.

[0086] [Modification of the first embodiment] Fig. 16 is a block diagram showing the configuration of an information processing device 1A according to a modified example of the first embodiment. In addition to the components of the information processing device 1 in Fig. 1, the information processing device 1A further includes a device interface (I / F) 19 for connecting to an external device. The device interface 19 is, for example, a USB. In the example of Fig. 16, the device interface 19 is connected to an external storage device 41 such as a USB memory, a solid state drive, or a hard disk drive.

[0087] The program for the erasure process described with reference to FIG. 6 and other figures may be stored in the external storage device 41 instead of being stored in the nonvolatile memory 15. In this case, the erasure controller 14 reads out and executes the program for the erasure process from the external storage device 41. The program for the erasure process may also be divided into multiple parts, one part stored in the nonvolatile memory 15, and the other part stored in the external storage device 41. In this case, by executing the program part stored in the external storage device 41, the program part stored in the nonvolatile memory 15 is called and executed.

[0088] For example, when the information processing device 1A executes the erasure process according to the second embodiment, the calculated hash value of the original data may be stored in the external storage device 41 instead of being stored in the RAM 12 or the nonvolatile memory 15. Since it is difficult to infer the original data from the hash value, even if the external storage device 41 is lost or stolen, there is a low possibility that the confidential data will be leaked.

[0089] The calculated hash value of the original data may be transmitted to and stored in an external information processing device connected via the communication device 16. The information processing device 1, 1A may further include a drive device for a storage medium such as a CD or DVD, in which case the calculated hash value of the original data may be stored on the CD, DVD, or the like.

[0090] [Advantages of the first embodiment] The information processing device 1 according to the first embodiment includes a storage device 13 having a self-encryption function for stored data and an erasure controller 14 that controls erasure of data stored in the storage device 13. The storage device 13 includes a storage medium having a storage area, a nonvolatile memory 23 storing an encryption key, and an input / output controller 21 that writes input data to the storage area, outputs data read from the storage area, encrypts at least a portion of the data written to the storage area using the encryption key, and decrypts at least a portion of the data read from the storage area using the encryption key. When a first encryption key is stored in the nonvolatile memory 23, the erasure controller 14 obtains a first hash value calculated based on data to be stored at a specified location in the storage area or based on data stored at a specified location in the storage area. The erasure controller 14 controls the storage device 13 to change the first encryption key stored in the nonvolatile memory 23 to a second encryption key. When a second encryption key is stored in the nonvolatile memory 23, the erasure controller 14 calculates a second hash value based on data read from a specified location in the storage area. If the second hash value is different from the first hash value, the erasure controller 14 outputs a verification result indicating that the erasure of the data stored in the storage device 13 was successful. If the second hash value matches the first hash value, the erasure controller 14 outputs a verification result indicating that the erasure of the data stored in the storage device 13 was unsuccessful.

[0091] This makes it possible to verify whether or not the data stored in the storage device 13 has been successfully erased with a smaller load than before.

[0092] According to the information processing device 1 of the first embodiment, the erasure controller 14 may control the storage device 13 to store predetermined pattern data at a specified location in the storage area. In this case, the first hash value is calculated based on the pattern data.

[0093] This makes it possible to verify data erasure without temporarily saving the data to an external information processing device.

[0094] According to the information processing device 1 of the first embodiment, the erasure controller 14 may calculate the first hash value based on the data read from a specified location in the storage area.

[0095] This makes it possible to verify data erasure without temporarily saving the data to an external information processing device.

[0096] According to the information processing device 1 of the first embodiment, the storage area may include a plurality of blocks. In this case, the first and second hash values ​​are calculated for each of a predetermined number of blocks based on the data stored in the blocks.

[0097] This reduces the amount of calculation compared to when one hash value is calculated for each logical block 31, improving processing speed and reducing the memory capacity required to store the calculated hash values.

[0098] According to the information processing device 1 of the first embodiment, the storage area may include a plurality of partial areas obtained by logically dividing the storage area, each of which includes a plurality of logically contiguous blocks. In this case, the erasure controller 14 designates, for each of the plurality of partial areas, a different proportion of logical blocks from the plurality of logical blocks included in the partial area. The first and second hash values ​​are calculated based on the data stored in the designated plurality of blocks.

[0099] This makes it possible to more reliably verify the erasure of data stored in an area of ​​the information processing device 1 that is thought to contain important files.

[0100] According to the information processing device 1 of the first embodiment, the storage area may include multiple blocks, in which case the first and second hash values ​​are calculated based on data stored in multiple blocks that are logically adjacent to each other.

[0101] This may prevent hash value collisions.

[0102] According to the information processing device 1 of the first embodiment, the storage area may include multiple partial areas obtained by logically dividing the storage area into multiple different sizes. In this case, a first hash value is calculated for each of the multiple partial areas having multiple sizes based on the data stored in the partial area. The erasure controller 14 calculates a second hash value for each of the multiple partial areas having a first size among the multiple sizes based on the data stored in the partial area. If the second hash value for the partial area having the first size is different from the first hash value, the erasure controller 14 outputs a verification result indicating successful erasure of data stored in the storage device 13. If the second hash value for the partial area having the first size matches the first hash value, the erasure controller 14 calculates a second hash value for each of the multiple partial areas having a second size smaller than the first size among the multiple sizes based on the data stored in the partial area. If the second hash value for the partial area having the second size is different from the first hash value, the erasure controller 14 outputs a verification result indicating successful erasure of data stored in the storage device 13.

[0103] As a result, even if the hash value of the original data and the hash value of the current data collide in a certain partial area, the collision of the hash values ​​can sometimes be avoided by comparing the hash values ​​of smaller partial areas.

[0104] The information processing device 1 according to the first embodiment may include a display device 18 that outputs the verification result.

[0105] This makes it possible to know whether the data stored in the storage device 13 has been successfully erased.

[0106] An information processing method according to a first embodiment controls erasure of data stored in a storage device 13 having a self-encrypting function. The storage device 13 includes a storage medium having a storage area, a nonvolatile memory 23 storing an encryption key, and an input / output controller 21 that writes input data to the storage area, outputs data read from the storage area, encrypts at least a portion of the data written to the storage area using the encryption key, and decrypts at least a portion of the data read from the storage area using the encryption key. The information processing method includes, when a first encryption key is stored in the nonvolatile memory 23, acquiring a first hash value calculated based on data to be stored at a specified location in the storage area or based on data stored at a specified location in the storage area. The information processing method includes controlling the storage device 13 to change the first encryption key stored in the nonvolatile memory 23 to a second encryption key. The information processing method also includes, when a second encryption key is stored in the nonvolatile memory 23, calculating a second hash value based on data read from a specified location in the storage area. The information processing method includes a step of outputting a verification result indicating that erasure of the data stored in the storage device 13 was successful if the second hash value is different from the first hash value. The information processing method includes a step of outputting a verification result indicating that erasure of the data stored in the storage device 13 was unsuccessful if the second hash value matches the first hash value.

[0107] This makes it possible to verify whether or not the data stored in the storage device 13 has been successfully erased with a smaller load than before.

[0108] The program according to the first embodiment includes instructions to be executed by a processor implemented in the information processing device 1. The information processing device 1 further includes a storage device 13 having a self-encryption function for stored data. The storage device 13 includes a storage medium having a storage area, a nonvolatile memory 23 storing an encryption key, and an input / output controller that writes input data to the storage area, outputs data read from the storage area, encrypts at least a portion of the data written to the storage area using the encryption key, and decrypts at least a portion of the data read from the storage area using the encryption key. The instructions include instructing the processor to obtain a first hash value calculated based on data to be stored at a specified location in the storage area or based on data stored at a specified location in the storage area if a first encryption key is stored in the nonvolatile memory 23. The instructions include instructing the processor to control the storage device 13 to change the first encryption key stored in the nonvolatile memory 23 to a second encryption key. The instructions include instructing the processor to calculate a second hash value based on data read from a specified location in the storage area if a second encryption key is stored in the nonvolatile memory 23. The instructions include causing the processor to output a verification result indicating successful erasure of the data stored in the storage device 13 if the second hash value is different from the first hash value. The instructions cause the processor to output a verification result indicating unsuccessful erasure of the data stored in the storage device 13 if the second hash value matches the first hash value.

[0109] This makes it possible to verify whether or not the data stored in the storage device 13 has been successfully erased with a smaller load than before.

[0110] [Second embodiment] In the second embodiment, a case will be described in which the progress of data erasure is displayed while the erasure process of the first embodiment (see FIG. 10) is being performed.

[0111] 17 is a flowchart showing the erasure process executed by the information processing device 1 according to the second embodiment. The information processing device 1 according to the second embodiment is configured similarly to the case of the first embodiment. The erasure process of FIG. 17 is executed by the erasure controller 14 of FIG. 1.

[0112] In step S101, the erasure controller 14 performs pre-processing and calculates a hash value of the original data of the specified logical block 31.

[0113] In step S102, the erasure controller 14 executes a key change process to change the encryption key stored in the nonvolatile memory 23.

[0114] In step S103, the erasure controller 14 executes a verification process to determine whether the hash value of the current data is different from the hash value of the original data, that is, whether the data has been successfully erased.

[0115] FIG. 18 is a flowchart showing a subroutine of the pre-processing (step S101) of FIG.

[0116] In step S111, the erasure controller 14 initializes a parameter i1 to 1. The parameter i1 indicates one of a plurality of logical blocks 31 designated, for example, as shown in Figure 3, Figure 8, or Figure 9. In the example of Figure 18, N1 logical blocks 31 are designated.

[0117] In step S112, the erasure controller 14 reads the original data from the i1-th logical block 31 among the specified logical blocks 31. Next, in step S113, the erasure controller 14 calculates a hash value of the original data. Steps S112 and S113 are similar to steps S31 and S32 in FIG. 10, except that they are performed for one of the specified logical blocks 31.

[0118] In step S114, the erasure controller 14 stores the hash value of the original data and the address of the i1th logical block 31 in the RAM 12 or the nonvolatile memory 15 (or the external storage device 41 in FIG. 16).

[0119] In step S115, the erasure controller 14 outputs the number of logical blocks 31 for which the processes of steps S112 to S114 have been executed to the display device 18 in a predetermined format.

[0120] In step S116, the erase controller 14 determines whether the parameter i1 has exceeded the threshold value N1, and if YES, the process proceeds to step S102 in FIG. 17, and if NO, the process proceeds to step S117.

[0121] In step S117, the erasure controller 14 increments the parameter i1 by 1, and repeats steps S112 to S116.

[0122] FIG. 19 is a flowchart showing a subroutine of the key change process (step S102) of FIG.

[0123] In step S121, the erasure controller 14 changes the encryption key stored in the nonvolatile memory 23. Step S121 is similar to step S33 in FIG.

[0124] In step S122, the erasure controller 14 outputs to the display device 18 in a predetermined format a message indicating that the encryption key has been changed.

[0125] FIG. 20 is a flowchart showing a subroutine of the verification process (step S103) of FIG.

[0126] In step S131, the erasure controller 14 initializes a parameter i2 to 1. The parameter i2 indicates one of the N1 logical blocks 31 specified in the preprocessing of FIG.

[0127] In step S132, the erasure controller 14 reads the hash value and address of the original data stored in the RAM 12 or the nonvolatile memory 15 (or the external storage device 41 in FIG. 16). Based on this address, the logical block 31 for which the hash value was calculated in the preprocessing is identified.

[0128] In step S133, the erasure controller 14 reads the current data of the i2-th logical block 31 among the logical blocks 31 identified by the address read in step S132. Next, in step S134, the erasure controller 14 calculates a hash value of the current data. Steps S133 and S134 are similar to steps S34 and S35 in FIG. 10, except that steps S133 and S134 are performed for one of the specified logical blocks 31.

[0129] In step S135, the erasure controller 14 determines whether the hash value of the current data is different from the hash value of the original data, and if YES, proceeds to step S136, and if NO, proceeds to step S140. Step S135 is the same as step S36 in Figure 10, except that it is performed on one of the specified logical blocks 31.

[0130] In step S136, the erasure controller 14 outputs the number of verified logical blocks 31, i.e., the number of logical blocks 31 for which it has been determined whether the hash value of the current data is different from the hash value of the original data, to the display device 18 in a predetermined format.

[0131] In step S137, the erasure controller 14 determines whether the parameter i2 has exceeded the threshold value N1, and if YES, the process proceeds to step S139, and if NO, the process proceeds to step S138.

[0132] In step S138, the erasure controller 14 increments the parameter i2 by 1, and repeats steps S132 to S137.

[0133] In step S139, the erasure controller 14 outputs a verification result indicating that the data erasure was successful to the display device 18. In step S140, the erasure controller 14 outputs a verification result indicating that the data erasure was unsuccessful to the display device 18.

[0134] FIG. 21 shows an example of an image indicating the progress of data erasure, which is displayed on the display device 18 of FIG. 1 by executing the erasure process of FIG. 17. FIG. 21(a) is an image indicating the progress of preprocessing. The progress of preprocessing is represented, for example, by a progress bar indicating the ratio of the number of processed logical blocks 31 to the number of specified logical blocks 31, i.e., i1 / N1. FIG. 21(b) is an image indicating the progress of key change processing. The progress of key change processing is represented, for example, by a progress bar indicating whether the encryption key change has been completed. FIG. 21(c) is an image indicating the progress of verification processing. The progress of verification processing is represented, for example, by a progress bar indicating the ratio of the number of verified logical blocks 31 to the number of specified logical blocks 31, i.e., i2 / N1.

[0135] Fig. 22 is a diagram showing another example of an image showing the progress of data erasure, which is displayed on the display device 18 of Fig. 1 by executing the erasure process of Fig. 17. The three progress bars shown in Fig. 21 may be displayed together as one.

[0136] The progress of data erasure may be displayed as text such as the following instead of being displayed as an image as in FIGS.

[0137] Pretreatment: a1 Key change process: a2 Verification process: a3

[0138] Here, a1 starts from the specified number of blocks N1 and decreases as the parameter i1 increases (a1=N1-i1), a2 is "1" before the encryption key is changed and becomes "0" after the encryption key is changed, and a3 starts from the specified number of blocks N1 and decreases as the parameter i2 increases (a3=N1-i2).

[0139] The progress of the data erasure may also be displayed as text such as:

[0140] Pretreatment: b1 / N1 Key change process: b2 Verification process: b3 / N1

[0141] Here, b1 = i1. b2 is "0" before the encryption key is changed and "1" after the encryption key is changed. Also, b3 = i2.

[0142] The progress of data erasure may also be displayed as "c", where c = a1 + a2 + a3, or as "d / N", where d = b1 + b2 + b3, and N = N1 x 2 + 1.

[0143] As described above, when one hash value is calculated for each of a plurality of logical blocks 31, the progress of data erasure may be displayed as an image or text based on the number or percentage of groups of logical blocks 31, with each group of logical blocks 31 corresponding to one hash value as a unit.

[0144] In the verification process of Fig. 20, if the hash value of the current data matches the hash value of the original data in one logical block 31, it is determined that the data erasure has failed. However, as described above, the erasure controller 14 may determine that the data erasure has been successful even if the hash values ​​match in some of the specified logical blocks 31. Next, a modified example of the verification process that allows such collisions of hash values ​​will be described with reference to Figs. 23 to 25.

[0145] Fig. 23 is a flowchart showing a first modified example of the verification process of Fig. 17. The process of Fig. 23 includes steps S141 to S143 in addition to the steps of Fig. 20.

[0146] In step S141, the erasure controller 14 initializes a parameter j1 to 0. Using the parameter j1, the number of logical blocks 31 in which the hash value of the current data matches the hash value of the original data is counted.

[0147] If it is determined in step S135 that the hash value of the current data matches the hash value of the original data, the process proceeds to step S142. In step S142, the erasure controller 14 increments the parameter j1 by one.

[0148] In step S143, the erasure controller 14 determines whether the parameter j1 exceeds the threshold value Th1, and if YES, the process proceeds to step S140, and if NO, the process proceeds to step S136.

[0149] According to the verification process of FIG. 23, even if hash value collisions occur in logical blocks 31 the number of which is equal to or less than threshold Th1, it is possible to determine that data erasure has been successful if the hash values ​​in other logical blocks 31 are different.

[0150] Fig. 24 is a flowchart showing a second modified example of the verification process of Fig. 17. The process of Fig. 24 includes steps S151 to S156 in addition to the steps of Fig. 20.

[0151] In step S151, the erasure controller 14 initializes a parameter j2 to 0. Using the parameter j2, the number of hash value collisions that occur consecutively in some of the designated logical blocks 31 that are close to each other is counted.

[0152] If it is determined in step S135 that the hash value of the current data is different from the hash value of the original data, the process proceeds to step S152; otherwise, the process proceeds to step S153. In step S152, the erasure controller 14 decrements the parameter j2 by 1. In step S153, the erasure controller 14 increments the parameter j2 by 1.

[0153] In step S154, the erasure controller 14 determines whether the parameter j2 is less than 0. If YES, the process proceeds to step S155, and if NO, the process proceeds to step S156. In step S155, the erasure controller 14 reinitializes the parameter j2 to 0.

[0154] In step S156, the erasure controller 14 determines whether the parameter j2 exceeds the threshold value Th2, and if YES, the process proceeds to step S140, and if NO, the process proceeds to step S136.

[0155] According to the verification process of Figure 24, the parameter j2 increases or decreases depending on whether the hash values ​​match or mismatch. Therefore, if hash value collisions occur consecutively in several logical blocks 31 that are close to each other among the specified logical blocks 31, the parameter j2 increases. In this case, it is considered that the storage area including these logical blocks 31 is not subject to encryption, and the data is stored in plaintext. On the other hand, if hash value matches and mismatches alternate almost alternately in several logical blocks 31 that are close to each other among the specified logical blocks 31, the parameter j2 does not increase. In this case, it is considered that the hash value collisions are accidental.

[0156] Fig. 25 is a flowchart showing a third modified example of the verification process of Fig. 17. The process of Fig. 25 includes steps S161 to S169 in addition to the steps of Fig. 20.

[0157] If it is determined in step S135 that the hash value of the current data matches the hash value of the original data, the process proceeds to step S161. In step S161, the erasure controller 14 stores the address of the logical block 31 where the hash value collision occurred in the RAM 12 or the nonvolatile memory 15 (or the external storage device 41 in FIG. 16).

[0158] If the parameter i2 exceeds the threshold value N1 in step S137, the process proceeds to step S162. In step S162, the erasure controller 14 initializes parameters i3 and i4 to 1, and initializes parameter j3 to 0. In the verification process of FIG. 25, the number of hash value collisions is counted in a group of a predetermined number of logical blocks 31 that are adjacent to each other among the specified logical blocks 31. The parameter i3 indicates the position of the group of logical blocks 31. The parameter i4 indicates one of the logical blocks 31 included in a certain group. In the example of FIG. 25, each group includes N4 logical blocks 31, and the position of the group is shifted in N3=N1-N4 ways among the specified logical blocks 31. The number of hash value collisions in a certain group is counted using the parameter j3.

[0159] In step S163, the erasure controller 14 determines whether the hash value of the current data in the i3+i4th logical block 31 matches the hash value of the original data based on the address stored in step S161, and if the result is YES, proceeds to step S164, and if the result is NO, proceeds to step S165. In step S164, the erasure controller 14 increments the parameter j3 by 1.

[0160] In step S165, the erasure controller 14 determines whether the parameter i4 has exceeded the threshold value N4, i.e., whether all logical blocks 31 included in the current group have been processed; if YES, the process proceeds to step S167; if NO, the process proceeds to step S166.

[0161] In step S166, the erasure controller 14 increments the parameter i4 by 1, and repeats steps S163 to S165.

[0162] In step S167, the erasure controller 14 determines whether the parameter j3 exceeds the threshold value Th3, and if YES, the process proceeds to step S140, and if NO, the process proceeds to step S168.

[0163] In step S168, the erasure controller 14 determines whether the parameter i3 exceeds the threshold value N3, i.e., whether the group of logical blocks 31 has been shifted to all positions; if YES, the process proceeds to step S139; if NO, the process proceeds to step S169.

[0164] In step S169, the erasure controller 14 increments the parameter i3 by 1, and repeats steps S163 to S168.

[0165] According to the processing of Figure 25, if hash value collisions occur repeatedly in a group of a predetermined number of logical blocks 31 that are close to each other, it is assumed that the storage area containing these logical blocks 31 is not subject to encryption and that the data is stored in plain text.

[0166] The threshold value Th3 in step S167 may be set to, for example, a value close to the number N3 of logical blocks 31 included in the group. Also, in step S168, the erasure controller 14 may calculate j3 / N3, in which case the threshold value Th3 may be set to, for example, a value close to 1.

[0167] [Advantages of the second embodiment] According to the information processing device 1 of the second embodiment, the erasure controller 14 may output to the display device 18 the progress of erasing the data stored in the storage device 13.

[0168] This allows the progress of data erasure to be ascertained.

[0169] [Third embodiment] Fig. 26 is a block diagram showing the configuration of an information processing system including an information processing device 1 and a server device according to a third embodiment. The information processing system of Fig. 26 includes a plurality of information processing devices 1-1 to 1-3, a server device 2, and a communication line 3. Each of the information processing devices 1-1 to 1-3 has the same configuration as the information processing device 1 of Fig. 1. The server device 2 is connected to each of the information processing devices 1-1 to 1-3 via the communication line 3.

[0170] In this specification, the information processing devices 1-1 to 1-3 are collectively referred to as "information processing device 1."

[0171] FIG. 27 is a block diagram showing the configuration of the server device 2 of FIG. 26. The server device 2 includes a bus 120, a CPU 121, a RAM 122, a storage device 123, a communication device 126, an input device 127, and a display device 128. The CPU 121 controls the overall operation of the server device 2 and manages the erasure of data stored in the storage device 13 of each information processing device 1. The RAM 122 temporarily stores programs and data necessary for the operation of the server device 2. The storage device 123 is a non-volatile storage medium that stores programs necessary for the operation of the server device 2. The communication device 126 is communicably connected to each information processing device 1 via a communication line 3. The input device 127 receives user input for controlling the operation of the server device 2. The input device 127 includes, for example, a keyboard and a pointing device. The display device 128 displays information related to the erasure of data stored in the storage device 13 of each information processing device 1. The CPU 121, the RAM 122, the storage device 123, the communication device 126, the input device 127, and the display device 128 are connected to one another via a bus 120.

[0172] Fig. 28 is a flowchart showing the erasure process executed by the server device 2 of Fig. 26. Fig. 29 is a flowchart showing the erasure process executed by the information processing device 1 of Fig. 26.

[0173] In step S201 of FIG. 28, the CPU 121 of the server device 2 transmits to the information processing device 1 a control signal instructing the deletion of data.

[0174] 29, the erasure controller 14 of the information processing device 1 receives a control signal from the server device 2 instructing the erasure of data. Next, the erasure controller 14 executes steps S212 to S219 in accordance with the control signal. Steps S212 to S217 are the same as steps S31 to S36 of FIG. 10. If it is determined in step S217 that the hash value of the current data is different from the hash value of the original data, the process proceeds to step S218; otherwise, the process proceeds to step S219. In step S218, the erasure controller 14 transmits a notification signal to the server device 2 including a verification result indicating that the data erasure was successful. In step S219, the erasure controller 14 transmits a notification signal to the server device 2 including a verification result indicating that the data erasure failed.

[0175] 28, the CPU 121 of the server device 2 receives a notification signal indicating the verification result from the information processing device 1. In step S203, the CPU 121 outputs the verification result to the display device 128.

[0176] According to the processing of Figures 28 and 29, the erasure of data stored in the storage devices 13 of multiple information processing devices 1 can be centrally controlled by the server device 2, and it is also possible to verify with a small load whether the data has been successfully erased.

[0177] Furthermore, as will be described with reference to FIGS. 30 to 34, the progress of the data erasure may be output to the display device 128 of the server device 2. FIG.

[0178] Fig. 30 is a flowchart showing a modified example of the erasure process executed by the server device 2 of Fig. 26. Fig. 31 is a flowchart showing a modified example of the erasure process executed by the information processing device 1 of Fig. 26. The process of Fig. 30 includes steps S221 to S223 instead of step S202 of Fig. 28. The process of Fig. 31 includes steps S231 to S233 instead of steps S212 to S219 of Fig. 29.

[0179] In step S201 of FIG. 30, the CPU 121 of the server device 2 transmits to the information processing device 1 a control signal instructing the deletion of data.

[0180] 31, the erasure controller 14 of the information processing device 1 receives a control signal instructing data erasure from the server device 2. Next, the erasure controller 14 executes steps S231 to S233 in accordance with the control signal. Steps S231 to S233 are similar to steps S101 to S103 of FIG. 17, except that the progress of data erasure and the verification result are transmitted to the server device 2 instead of being output to the display device 18 of the information processing device 1.

[0181] Fig. 32 is a flowchart showing a subroutine of the pre-processing (step S231) of Fig. 31. The processing of Fig. 32 includes step S115A instead of step S115 of Fig. 18. In step S115A, the erasure controller 14 transmits to the server device 2 a notification signal including the number of logical blocks 31 for which the processing of steps S112 to S114 has been executed, as the progress of data erasure.

[0182] Fig. 33 is a flowchart showing a subroutine of the key change process (step S232) of Fig. 31. The process of Fig. 33 includes step S122A instead of step S122 of Fig. 19. In step S122A, the erasure controller 14 transmits a notification signal to the server device 2 indicating that the encryption key change has been completed as the progress of data erasure.

[0183] Fig. 34 is a flowchart showing a subroutine of the verification process (step S233) of Fig. 31. The process of Fig. 34 includes steps S136A, S139A, and S140A instead of steps S136, S139, and S140 of Fig. 20. In step S136A, the erasure controller 14 transmits to the server device 2 a notification signal including the number of verified logical blocks 31 as the progress of data erasure. In step S139A, the erasure controller 14 transmits to the server device 2 a notification signal including a verification result indicating that the data erasure was successful. In step S140A, the erasure controller 14 transmits to the server device 2 a notification signal including a verification result indicating that the data erasure failed.

[0184] 30, CPU 121 of server device 2 receives a notification signal including the progress of data erasure from information processing device 1. In step S222, CPU 121 outputs the progress of data erasure to display device 128 in a predetermined format, similar to when outputting to display device 18 of information processing device 1. In step S223, CPU 121 determines whether data erasure has been completed, that is, whether a notification signal indicating the verification result has been received from information processing device 1. If YES, the process proceeds to step S203, and if NO, the process returns to step S221. In step S203, CPU 121 outputs the verification result to display device 128.

[0185] According to the processes of FIGS. 30 to 34, the progress of erasing data stored in the storage devices 13 of the plurality of information processing devices 1 can be grasped in the server device 2.

[0186] [Advantages of the third embodiment] An information processing system 100 according to the third embodiment includes the information processing device 1 according to the first embodiment and a server device 2 connected to the information processing device 1 via a communication line. An erasure controller 14 controls erasure of data stored in the storage device 13 in accordance with a control signal received from the server device 2.

[0187] This makes it possible to verify whether or not the data stored in the storage device 13 has been successfully erased with a smaller load than before.

[0188] In the information processing system 100 according to the third embodiment, the erasure controller 14 may transmit a first notification signal including the verification result to the server device 2. The server device 2 may include a display device 128 that outputs the verification result.

[0189] This makes it possible to know whether the data stored in the storage device 13 has been successfully erased.

[0190] In the information processing system 100 according to the third embodiment, the erasure controller 14 may transmit a second notification signal including the progress of erasure of data stored in the storage device 13 to the server device 2. In this case, the display device 128 displays the progress.

[0191] This allows the progress of data erasure to be ascertained.

[0192] [Other embodiments] As described above, the embodiments have been described as examples of the technology disclosed in this application. However, the technology in this disclosure is not limited to these, and can be applied to embodiments in which appropriate modifications, substitutions, additions, omissions, etc. are made. Furthermore, it is also possible to combine the components described in the above embodiments to create new embodiments.

[0193] Therefore, other embodiments will be exemplified below.

[0194] The storage device 13 is not limited to a solid state drive, but may be a nonvolatile storage medium such as a hard disk drive (HDD) with a self-encrypting function.

[0195] The verification result is not limited to being output to the display device 18, but may also be output to an external information processing device via the communication device 16.

[0196] Since important data is stored at the logical beginning of a storage area, the erasure controller 14 may always specify the first 32 bytes of the storage area.

[0197] The erasure controller 14 may add a salt (a predetermined keyword) to the data when calculating the hash value.

[0198] The erasure controller 14 may shrink the size of the logical block 31 to, for example, 1 / 10.

[0199] 17 to 25 and 30 to 34 have been described with reference to the case where the progress of data erasure is displayed while the erasure process (see FIG. 10) according to the second embodiment is being executed. Instead, the progress of data erasure may be similarly displayed while the erasure process (see FIG. 6) according to the first embodiment or the erasure process (see FIG. 11) according to the third embodiment is being executed.

[0200] As described above, the embodiments have been described as examples of the technology in the present disclosure, and for that purpose, the accompanying drawings and detailed description have been provided.

[0201] Therefore, the components shown in the accompanying drawings and detailed description may include not only essential components for solving the problem, but also components that are not essential for solving the problem in order to illustrate the above technology. Therefore, the fact that these non-essential components are shown in the accompanying drawings or detailed description should not be interpreted as immediately indicating that these non-essential components are essential.

[0202] Furthermore, since the above-described embodiments are intended to illustrate the technology of the present disclosure, various modifications, substitutions, additions, omissions, etc. may be made within the scope of the claims or their equivalents.

[0203] [Summary of the embodiment] An information processing device according to a first aspect of the present disclosure includes: a storage device having a function of self-encrypting data to be stored; an erasure controller for controlling erasure of data stored in the storage device, The storage device a storage medium having a storage area; a non-volatile memory storing an encryption key; an input / output controller that writes input data to the storage area, outputs data read from the storage area, encrypts at least a portion of the data to be written to the storage area using the encryption key, and decrypts at least a portion of the data read from the storage area using the encryption key; The erasure controller If a first encryption key is stored in the nonvolatile memory, a first hash value calculated based on data to be stored at a specified location in the storage area or based on data stored at a specified location in the storage area is obtained; controlling the storage device to change the first encryption key stored in the nonvolatile memory to a second encryption key; If the second encryption key is stored in the nonvolatile memory, a second hash value is calculated based on the data read from the specified location in the storage area; If the second hash value is different from the first hash value, outputting a verification result indicating that the data stored in the storage device has been successfully erased; If the second hash value matches the first hash value, a verification result indicating that erasure of the data stored in the storage device has failed is output.

[0204] An information processing device according to a second aspect of the present disclosure is the information processing device according to the first aspect, the erase controller controls the storage device to store predetermined pattern data at the specified location in the storage area; The first hash value is calculated based on the pattern data.

[0205] An information processing device according to a third aspect of the present disclosure is the information processing device according to the first aspect, The erasure controller calculates the first hash value based on data read from the specified location in the storage area.

[0206] An information processing device according to a fourth aspect of the present disclosure is the information processing device according to the third aspect, the storage area includes a plurality of blocks; The first and second hash values ​​are calculated for each of a predetermined number of blocks based on the data stored in the blocks.

[0207] An information processing device according to a fifth aspect of the present disclosure is the information processing device according to one of the first to fourth aspects, the storage area includes a plurality of partial areas obtained by logically dividing the storage area, each partial area including a plurality of logically contiguous blocks; the erasure controller designates, for each of the plurality of partial areas, a different proportion of blocks among a plurality of blocks included in the partial area; The first and second hash values ​​are calculated based on data stored in the specified plurality of blocks.

[0208] An information processing device according to a sixth aspect of the present disclosure is the information processing device according to one of the first to fourth aspects, the storage area includes a plurality of blocks; The first and second hash values ​​are calculated based on data stored in a plurality of blocks that are logically adjacent to each other.

[0209] An information processing device according to a seventh aspect of the present disclosure is the information processing device according to the first aspect, the storage area includes a plurality of partial areas obtained by logically dividing the storage area into a plurality of partial areas each having a different size; the first hash value is calculated for each of the plurality of partial areas having the plurality of sizes based on data stored in the partial area; The erasure controller calculating the second hash value for each of a plurality of partial areas having a first size among the plurality of sizes based on data stored in the partial area; If the second hash value is different from the first hash value for the partial area having the first size, output a verification result indicating that the data stored in the storage device has been successfully erased; If the second hash value matches the first hash value for the partial area having the first size, calculate the second hash value for each of a plurality of partial areas having a second size smaller than the first size among the plurality of sizes based on data stored in the partial area; If the second hash value for the partial area having the second size is different from the first hash value, a verification result indicating that the data stored in the storage device has been successfully erased is output.

[0210] According to an information processing device according to an eighth aspect of the present disclosure, in the information processing device according to one of the first to seventh aspects, A first display device is provided to output the verification result.

[0211] An information processing device according to a ninth aspect of the present disclosure is the information processing device according to the eighth aspect, The erasure controller outputs the progress of erasure of the data stored in the storage device to the first display device.

[0212] An information processing system according to a tenth aspect of the present disclosure includes: An information processing device according to one of the first to ninth aspects; a server device connected to the information processing device via a communication line, The erasure controller controls erasure of data stored in the storage device in accordance with a control signal received from the server device.

[0213] According to an information processing system according to an eleventh aspect of the present disclosure, in the information processing system according to the tenth aspect, the erasure controller transmits a first notification signal including the verification result to the server device; The server device includes a second display device that outputs the verification result.

[0214] According to an information processing system according to a twelfth aspect of the present disclosure, in the information processing system according to the eleventh aspect, the erasure controller transmits a second notification signal to the server device, the second notification signal including a progress of erasure of the data stored in the storage device; The second display device displays the progress.

[0215] An information processing method according to a thirteenth aspect of the present disclosure includes: 1. An information processing method for controlling erasure of data stored in a storage device having a self-encrypting function, comprising: The storage device includes: a storage medium having a storage area; a non-volatile memory storing an encryption key; an input / output controller that writes input data to the storage area, outputs data read from the storage area, encrypts at least a portion of the data to be written to the storage area using the encryption key, and decrypts at least a portion of the data read from the storage area using the encryption key; The information processing method includes: If a first encryption key is stored in the non-volatile memory, acquiring a first hash value calculated based on data to be stored at a specified location in the storage area or based on data stored at a specified location in the storage area; controlling the storage device to change the first encryption key stored in the non-volatile memory to a second encryption key; If the second encryption key is stored in the nonvolatile memory, calculating a second hash value based on data read from the specified location in the storage area; outputting a verification result indicating that the data stored in the storage device has been successfully erased if the second hash value is different from the first hash value; and outputting a verification result indicating that erasure of the data stored in the storage device has failed if the second hash value matches the first hash value.

[0216] A program according to a thirteenth aspect of the present disclosure includes: A program including instructions executed by a processor implemented in an information processing device, the information processing device further includes a storage device having a function of self-encrypting data to be stored therein; The storage device includes: a storage medium having a storage area; a non-volatile memory storing an encryption key; an input / output controller that writes input data to the storage area, outputs data read from the storage area, encrypts at least a portion of the data to be written to the storage area using the encryption key, and decrypts at least a portion of the data read from the storage area using the encryption key; The instructions cause the processor to: When a first encryption key is stored in the nonvolatile memory, acquiring a first hash value calculated based on data to be stored at a specified location in the storage area or based on data stored at a specified location in the storage area; controlling the storage device to change the first encryption key stored in the non-volatile memory to a second encryption key; If the second encryption key is stored in the nonvolatile memory, calculating a second hash value based on the data read from the specified location in the storage area; If the second hash value is different from the first hash value, outputting a verification result indicating that the data stored in the storage device has been successfully erased; If the second hash value matches the first hash value, a verification result indicating that erasure of the data stored in the storage device has failed is output. [Industrial Applicability]

[0217] An information processing device according to an aspect of the present disclosure is useful for verifying whether data stored in a storage device with a self-encrypting function has been successfully erased. [Explanation of symbols]

[0218] 1,1A Information processing equipment 10 Bus 11 Central Processing Unit (CPU) 12 Random Access Memory (RAM) 13 Storage device 14 Erasure Controller 15 Non-volatile memory 16. Communications equipment 17 Input Devices 18 Display device 19 Device Interface (I / F) 21 Input / Output Controller 22 Random Access Memory (RAM) 23 Non-volatile memory 24 Flash memory 31 logical blocks 41 External storage device 100 Information Processing Systems 120 Bus 121 Central Processing Unit (CPU) 122 Random Access Memory (RAM) 123 Storage device 126 Communication Equipment 127 Input Device 128 Display device

Claims

1. a storage device having a function of self-encrypting data to be stored; an erasure controller for controlling erasure of data stored in the storage device, The storage device a storage medium having a storage area; a non-volatile memory storing an encryption key; an input / output controller that writes input data to the storage area, outputs data read from the storage area, encrypts at least a portion of the data to be written to the storage area using the encryption key, and decrypts at least a portion of the data read from the storage area using the encryption key; The erasure controller If a first encryption key is stored in the nonvolatile memory, a first hash value calculated based on data to be stored at a specified location in the storage area or based on data stored at a specified location in the storage area is obtained; controlling the storage device to change the first encryption key stored in the nonvolatile memory to a second encryption key; If the second encryption key is stored in the nonvolatile memory, a second hash value is calculated based on the data read from the specified location in the storage area; If the second hash value is different from the first hash value, outputting a verification result indicating that the data stored in the storage device has been successfully erased; If the second hash value matches the first hash value, output a verification result indicating that erasure of the data stored in the storage device has failed. Information processing device.

2. the erase controller controls the storage device to store predetermined pattern data at the specified location in the storage area; The first hash value is calculated based on the pattern data.

2. The information processing device according to claim 1.

3. the erasure controller calculates the first hash value based on the data read from the specified location in the storage area; 2. The information processing device according to claim 1.

4. the storage area includes a plurality of blocks; the first and second hash values ​​are calculated for each of a predetermined number of blocks based on data stored in the blocks; 4. The information processing device according to claim 3.

5. the storage area includes a plurality of partial areas obtained by logically dividing the storage area, each partial area including a plurality of logically contiguous blocks; the erasure controller designates, for each of the plurality of partial areas, a different proportion of blocks among a plurality of blocks included in the partial area; the first and second hash values ​​are calculated based on data stored in the specified plurality of blocks; 5. The information processing device according to claim 1.

6. the storage area includes a plurality of blocks; the first and second hash values ​​are calculated based on data stored in a plurality of blocks that are logically adjacent to each other; 5. The information processing device according to claim 1.

7. the storage area includes a plurality of partial areas obtained by logically dividing the storage area into a plurality of partial areas each having a different size; the first hash value is calculated for each of the plurality of partial areas having the plurality of sizes based on data stored in the partial area; The erasure controller calculating the second hash value for each of a plurality of partial areas having a first size among the plurality of sizes based on data stored in the partial area; If the second hash value is different from the first hash value for the partial area having the first size, output a verification result indicating that the data stored in the storage device has been successfully erased; If the second hash value matches the first hash value for the partial area having the first size, calculate the second hash value for each of a plurality of partial areas having a second size smaller than the first size among the plurality of sizes based on data stored in the partial area; outputting a verification result indicating that the data stored in the storage device has been successfully erased if the second hash value for the partial area having the second size is different from the first hash value; 2. The information processing device according to claim 1.

8. a first display device that outputs the verification result; 2. The information processing device according to claim 1.

9. the erasure controller outputs a progress of erasure of the data stored in the storage device to the first display device; 9. The information processing device according to claim 8.

10. The information processing device according to claim 1; an information processing system including a server device connected to the information processing device via a communication line, the erasure controller controls erasure of data stored in the storage device in accordance with a control signal received from the server device; Information processing system.

11. the erasure controller transmits a first notification signal including the verification result to the server device; the server device includes a second display device that outputs the verification result; 11. The information processing system according to claim 10.

12. the erasure controller transmits a second notification signal to the server device, the second notification signal including a progress of erasure of the data stored in the storage device; the second display device displays the progress; 12. The information processing system according to claim 11.

13. 1. An information processing method for controlling erasure of data stored in a storage device having a self-encrypting function, comprising: The storage device includes: a storage medium having a storage area; a non-volatile memory storing an encryption key; an input / output controller that writes input data to the storage area, outputs data read from the storage area, encrypts at least a portion of the data to be written to the storage area using the encryption key, and decrypts at least a portion of the data read from the storage area using the encryption key; The information processing method includes: If a first encryption key is stored in the nonvolatile memory, acquiring a first hash value calculated based on data to be stored at a specified location in the storage area or based on data stored at a specified location in the storage area; controlling the storage device to change the first encryption key stored in the non-volatile memory to a second encryption key; If the second encryption key is stored in the nonvolatile memory, calculating a second hash value based on data read from the specified location in the storage area; outputting a verification result indicating that the data stored in the storage device has been successfully erased if the second hash value is different from the first hash value; and outputting a verification result indicating that erasure of the data stored in the storage device has failed if the second hash value matches the first hash value. Information processing methods.

14. A program including instructions executed by a processor implemented in an information processing device, the information processing device further includes a storage device having a function of self-encrypting data to be stored therein; The storage device a storage medium having a storage area; a non-volatile memory storing an encryption key; an input / output controller that writes input data to the storage area, outputs data read from the storage area, encrypts at least a portion of the data to be written to the storage area using the encryption key, and decrypts at least a portion of the data read from the storage area using the encryption key; The instructions cause the processor to: When a first encryption key is stored in the nonvolatile memory, acquiring a first hash value calculated based on data to be stored at a specified location in the storage area or based on data stored at a specified location in the storage area; controlling the storage device to change the first encryption key stored in the non-volatile memory to a second encryption key; If the second encryption key is stored in the nonvolatile memory, calculating a second hash value based on data read from the specified location in the storage area; If the second hash value is different from the first hash value, outputting a verification result indicating that the data stored in the storage device has been successfully erased; outputting a verification result indicating that erasure of data stored in the storage device has failed if the second hash value matches the first hash value; program.

Citation Information

Patent Citations

  • Method and system for verifying data deletion processes

    JP7096829B2

  • Method and apparatus for data protection

    US20080082836A1