Erase related lock state for electronic device

WO2026164615A1PCT designated stage Publication Date: 2026-08-06HEWLETT PACKARD DEVELOPMENT COMPANY LP
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
HEWLETT PACKARD DEVELOPMENT COMPANY LP
Filing Date
2025-01-31
Publication Date
2026-08-06

Smart Images

  • Figure US2025014005_06082026_PF_FP_ABST
    Figure US2025014005_06082026_PF_FP_ABST
Patent Text Reader

Abstract

Provided is an erase assurance method for an electronic device, comprising executing an erase process to erase data stored in the electronic device; and in response to completing the erase process, loading an operating system image into a non-volatile memory of the electronic device, and bringing the electronic device into a locked state, the locked state blocking access to the operating system image on the electronic device until the electronic device is unlocked.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] 86343662 / HPSEC . l l OWO

[0002] ERASE RELATED LOCK STATE FOR ELECTRONIC DEVICE

[0003] BACKGROUND

[0004]

[0001] Di scarded electronic devices contribute to a growing global environmental is sue of so-called electronic waste . Reusing and recycling of electronic devices may support establishing a circular and more sustainable economy in which electronic devices may be subj ect of internal (within a company or organization) or external trans fer . Even for internal transfers , unauthori zed data access such as for personally identif iable information should be avoided . While the ( final ) destination of the electronic device may therefore be different , it should be ensured that no ea sily re-constructable residual representation of data is stored in the storage media of the electronic device after it has left control of an organization or a user .

[0005]

[0002] In this connection , sanitization techniques may ( irreversibly) erase or remove data or otherwise render acce s s to data on the storage media infeasible and may be employed to ensure that sensitive data i s effectively protected . Saniti zing computing devices may be performed in accordance with the NI ST S P 800 -88 standard (National Institute of Standards and Technology Special Publication 800 -88 Revision 1 Natl . Inst . Stand . Technol . Spec . Publ .

[0006] 800 -88 Revis ion 1 , 64 pages ( December 2014 ) CODEN : NSPUE2 : http : / / dx . doi . org / 10 . 6028 / NIST . S P . 800-88 rl ) .

[0007]

[0003] Sanitization methods may include clearing data , e . g . by overwriting user-addres sable storage space on storage media with non-sensitive data , and purging data , e . g . by using media-specific overwrite , block erase , cryptographic era se ( sanitiz ing cryptographic keys used to encrypt the data ) . Clearing and / or purging data may beinitiated by a ( remote) instruction, such as a wipe instruction to, for example, factory reset the electronic device to a factory state, for example to reset the electronic device to its factory default state (erasing user specific data, settings , and applications) .

[0008] BRIEF DESCRIPTION OF THE DRAWINGS

[0009]

[0004] Figure 1 represents an example scenario of the underlying technical problem of the present disclosure .

[0010]

[0005] Figure 2A is a diagram of an example electronic device 100 of the present disclosure .

[0011]

[0006] Figure 2B illustrates an example erasure assurance method for the electronic device of the present disclosure .

[0012]

[0007] Figure 3 illustrates another example erasure assurance method for the electronic device of the present disclosure .

[0013]

[0008] Figure 4 illustrates an example erasure assurance method 400 for the electronic device 100 using a posterase screen for the electronic device of the present disclosure .

[0014]

[0009] Figure 5 illustrates an example process workflow for establishing a temporary locked state using a double lock mechanism for the electronic device of the present disclosure .

[0015]

[0010] Figure 6 illustrates another example erasure assurance method for the electronic or user device .

[0016]

[0011] Figure 7 is a diagram of an example system according to the present disclosure .DETAILED DESCRIPTION

[0017]

[0012] The present disclosure relates to factory erasing for an electronic device, such as a personal computer ( PC) , a desktop, or a laptop, to enable an administrator or user to execute an erase on the electronic device and to put the electronic device in a state ready for disposal or ready to be recycled or reused without the previous user worrying about the confidentiality of data previously stored on the electronic device . It also provides assurances to a user who is receiving a previously used electronic device that the electronic device has been factory-reset and has no malicious software on it and / or is managed or still controllable by another company.

[0018]

[0013] In practice, a factory erase may be used in different scenarios . For example, company A and B may have signed up to cloud-based service, such as a Device-as-a-Service (DaaS ) . A PC (or generally, an electronic device) being used by company A may be returned to the cloud-based service and will later be used by company B . In this context, company A wants to ensure that any data that was on the PC remains confidential and cannot be accessed by company B . In addition, company B wants to have assurances that a factory-reset electronic device is received; for example, in that company A has not loaded any malware onto the electronic device . Furthermore, the cloud-based service may wish to prove they are not leaking any of company A' s data to company B .

[0019]

[0014] Once the erase is complete, a 'destruction certificate' may be generated to demonstrate that the electronic device has indeed erased all necessary data . Such a certificate may provide evidence of the erase produced and may be compliant with the 'certificate of sanitization' as defined in the NIST SP 800-88 standard,Appendix G (National Institute of Standards and Technology Special Publication 800-88 Revision 1 Natl . Inst . Stand . Technol . Spec . Publ . 800-88 Revision 1 , 64 pages (December 2014 ) CODEN: NSPUE2 : http : / / dx . doi . org / 10. 6028 / NIST . SP . 800-88rl) . The skilled person understands that the destruction certificate may provide the user or administrator with assurances that an erase on a specific electronic device occurred and could also be used to demonstrate (to an auditor, for example) that necessary precautions were taken and data were erased prior to either recycling / disposing the electronic device or passing it on to another user .

[0020]

[0015] In the above first example , company A may execute a factory erase prior to returning the electronic device to the cloud-based service . The cloud-based service may subsequently read the generated certificate to verify that a factory erase has been performed for the electronic device . Optionally, also the cloud-based service may execute the factory reset, so that the cloud-based service has an assurance that the electronic device given to company B has been reset and has not been tampered with by company A immediately after the factory erase .

[0021]

[0016] According to another example, a company may own an electronic device, such as PC, and the electronic device is currently being used by a user A. User A may return the electronic device to the company' s IT group, and the electronic device will later be used by user B who also works for the same company . In such a scenario, both user A and the company want to ensure that any confidential information on the electronic device is not accessible by user B or anyone else with access to the electronic device, for example while being shipped and stored . In addition, user A may have to demonstrate to their employer (the company) that all user-related data and / or company related data were erased on the electronic device priorto returning it to IT (which may involve a potentially insecure delivery mechanism) . In addition, also user B wishes to have confidence that an electronic device was received that can be trusted . In this second example, it may be expected that user A executes an erase on the electronic device prior to returning the electronic device to IT, while user B and IT may read the generated certificate to verify that the erase was carried out on the electronic device .

[0022]

[0017] According to further examples , a third party may execute a factory erase on an electronic device on behalf of a company, for example prior to recycling the electronic device . The company wishes to gain assurances that all company data was removed from the electronic device before it was recycled. The third party, for example a service provider, may execute a factory erase and generate a certificate to provide assurances that the electronic device was appropriately brought into a factory erase state prior to recycling . The company may then read the certificate to verify that an erase has occurred . Alternatively, an individual consumer may want to resell or recycle their electronic device . The individual user wants to gain assurance that the electronic device has had all personal information and data removed and accounts are disconnected prior to being resold or recycled . On the other hand, any potential buyer also prefers to have assurances that the electronic device is clean and does not have personal or confidential data or any spyware installed . In this example , it may be the individual user who executes a factory reset prior to reselling or recycling the electronic device . The new customer may then verify the generated certificate .

[0023]

[0018] The above example scenarios share, however, the following technical problem: After the initial user / company performs an erase, the next user / companydoes not have any guarantees that nothing malicious occurred on the computer platform of the electronic device between the erase occurring and the next user / company receiving the device . The generated destruction certificate therefore does not maintain its value and provides fewer assurances about the state of the electronic device (or the electronic platform thereof) as time passes . For example, when user A performs a factory erase on the electronic device prior to the electronic device being sent to user B, while the destruction certificate may demonstrate that the erase has been carried out and was successful, there is a time delay until user B receives the electronic device and thus user B has no assurances that nothing has happened on the electronic device since the factory erase was performed .

[0024]

[0019] Figure 1 represents an example scenario of the underlying technical problem of the present disclosure . Under the conventional scenario, a user A may, after having onboarded the electronic device (for example, setting up the electronic device, including authenticating and connecting the device, software and application installation, data synchronization and implementing security measures , which may also include learning or acquiring cryptographic keys , e . g . company cryptographic public keys ) in step 1, execute a factory erase as described above in step 2 , and may retrieve, verify and save a destruction certificate in step 3, and the electronic device is subsequently sent to user B in step 4 , either directly or indirectly, for example via a DaaS cloud service . Then, user B may receive the electronic device and perform an onboarding process themselves in step 5 and may retrieve and verify the destruction certificate in step 6 to have assurances that a factory erase has occurred. In this conventional scenario, user A themselves may, however, install malicious code or otherwise unwanted code, for example tocapture passwords of user B, after the erase has been performed in step 2. In addition, also during the transit of the electronic device from user A to user B, the electronic device could be intercepted or temporarily in possession of an intermediary ( such as the cloud-based service) and may be compromised or maliciously modified by loading such unwanted software code .

[0025]

[0020] One solution to this technical problem could be that user B, after receiving the electronic device, executes their own factory erasure before or during onboarding the electronic device . This would ensure that the erase is fresh and that nothing has happened to compromise the electronic device after the last erase, or any malicious code implemented after the last erase is wiped . However, a fresh erase by user B and then reinstalling the operating system (OS ) can take a long time, potentially more than 20 minutes , and such a solution would thus not lead to good user experiences , for example regarding the onboarding process for user B .

[0026]

[0021] Against this background, the present disclosure provides a technical solution that provides the receiver of the electronic device with assurances about the state of the electronic device after the erase without requiring user B to initiate their own erase . This technical solution is based on providing a locking functionality of the electronic device in connection with the erase . Figure 2A is a diagram of an example electronic device 100 and Figure 2B illustrates an example erasure assurance method 200 for the electronic device 100.

[0027]

[0022] The electronic device 100 may have an interface ( I / F) module 110 providing means , e . g . a display with an integrated or external keyboard, for entering and outputting information . The electronic device 100 may also have a controller or processor 120 , e . g . a centralprocessing unit (CPU) , a graphics processing unit (GPU) , or the like, for controlling the electronic device 100 to perform the functions of the electronic device 100 , a memory device 130 , e . g . a hard disk drive, a flash memorybased storage device such as a solid state drive (SSD) and / or a random-access memory, and an instruction store 140 storing a computer program 145 having computer- readable instructions which, when executed by the controller or processor 120 , cause the processor 120 to perform the functions of the electronic device 100.

[0028]

[0023] The instruction store 140 may include a ROM, e . g . in the form of an electrically-erasable programmable readonly memory (EEPROM) or flash memory, which is pre-loaded with the computer-readable instructions . Alternatively, the instruction store 140 may include a RAM or similar type of memory, and the computer-readable instructions can be input thereto from a computer program product, such as a computer-readable storage medium 150 such as a CD-ROM, etc . or a computer-readable signal 160 carrying the computer-readable instructions .

[0029]

[0024] Storage devices may be (peripheral) hard disk drives, flash memory-based storage devices such as SSDs, embedded flash storage devices, RAM, and ROM-based storage devices .

[0030]

[0025] The electronic device 100 may be any computing entity to process information and having computer memory media (in any form) , for example, a personal computer (PC) , a notebook, a desktop, a laptop, a personal digital assistant (PDA) , a mobile phone, a smartphone, a printing device, a wearable, an Internet-of-Thing (loT) device or the like . The electronic device 100 may also be referred to as a user device .

[0026] According to the example erasure assurance method, in step S210 , an erase process is executed on the electronic device 100. The erase process may erase user- related data, user-related software or applications, related settings , and associated security information ( such as related cryptographic keys) . The erase process may delete or remove these data , for example by formatting related memory device ( s ) , wiping the data, clearing the data , resetting the memory device (s ) to its factory settings , scrubbing the data, shredding the data , or encrypting the data and erasing the key required for decryption . The erase process may be a factory erase to reset the electronic device to a factory state, for example to reset the electronic device to its factory default . More specifically, a factory reset may be considered as a process in which user data , applications, and user-related settings are wiped, restoring the electronic device to its original factory settings . This may include erasing all user data, installed apps , and settings , to restore the original operating system state as when the electronic device was new . The factory reset may not affect the operating system itself , j ust user- added content .

[0031]

[0027] The erase process may also include an option to not only erase user-related data but also to reinstall or reset the operating system to its initial version or to a specific version of f irmware / sof tware . This may include, for example, a recovery mode reset, that is using a recovery partition to reinstall the system software, which may include updates or patches that were not part of the original factory state . This may also include a firmware update, that is updating the electronic device to the latest firmware and can serve as a form of factory reset, especially if the update is significant enough to change system behavior or fix deep-seated issues . The erase process may also include a reset of network andsettings . To reset network settings may also include erasing network-related configurations such as Wi-Fi passwords , Bluetooth pairings, and mobile network settings without touching personal data or apps . The reset of settings may include resetting the electronic device settings back to default without erasing personal data or apps , focusing on configurations like display, sound, and accessibility settings .

[0032]

[0028] According to the example erasure assurance method, in step S230 , the electronic device is put or brought into a temporary locked state . The temporary locked state may be considered as a state that is recognizable by a user and where access to the electronic device is momentarily restricted but can be bypassed or resolved by various means . Unlike a more stringent lock, such a temporary restriction may be undone by various methods that satisfy an unlock condition which may include entering correct credentials , using a previously set recovery key, a physical token, but not simply waiting for a predetermined time to elapse . The temporary locked state may thus be readily cleared or unlocked if anything occurs to (the platform of ) the electronic device . If the electronic device is unlocked, this means that the assurances gained from the erase in step S210 can no longer be relied on . In other words , if the electronic device is (received) in the locked state, there is an additional security assurance that nothing has occurred on (the platform of ) the electronic device since the erase has occurred . On the other hand, if the electronic device is not (received) in the locked state it can be concluded that something has occurred to (the platform of ) the electronic device since the erase, and thus the erase should be executed (by user B) to get a full guarantee of an erase . This mechanism addresses the conventional technical problem as identified, for example, in Figure 1 above . The skilled person also understands that thetemporary locked state may be achieved by different techniques , as will be further elaborated below.

[0033]

[0029] This technical solution provides an erase function with consistent results and improved assurances to users that their data has been satisfactorily deleted from the electronic device . That is , a true factory erase over the relevant storage elements of the electronic device can be achieved and maintained in the locked state, such that no residual information remains (in the memory disc (s) ) of the electronic device, including fingerprint sensor data, TPM (Trusted Platform Module) data including information and cryptographic keys stored and managed by TPM, data in BIOS flash (resetting BIOS settings) , data protected by the ESC (Endpoint Security Controller) and UEFI (Unified Extensible Firmware Interface ) variables . The erase may also include public keys . Such public keys may be company managed public keys to verify commands for managing the electronic device and may be stored by the ESC . Such public keys may also be used by the electronic device to authenticate and act on commands to, for example , modify BIOS settings and the like . In other words , a factory erase state can be achieved as a state having a clean operating system (OS ) image (as if the electronic device was delivered from a factory) and no customer data are left . The skilled person understands that the erase may also impact the f irmware / sof tware foundation below the OS, for example, BIOS settings , public keys stored by the endpoint security controller for secure management for secure management, private keys in the TPM and the like . It is noted that deleting all the relevant data, and then performing a secure recovery for preparing the device with a new OS image ready for use takes some time, with the erase itself taking a few minutes , followed by a recovery process which could take about 20 minutes if done , for example , over a network .

[0030] Figure 3 illustrates another example erasure assurance method 300 for the electronic device 100. According to the example erasure assurance method, in step S310 , the controller 120 of the electronic device 100 executes an erase process to erase data stored in the electronic device . The data to be erased may include an operating system, user data , and / or user-related applications (APPs ) and associated settings , private and / or public keys , and related user credentials , which may be stored by a non-volatile memory, such as any solid- state drive (SSD) , hard disk drive (HDD) , or any other user-accessible memory 130. The erase process may also rest the electronic device below the OS or blocking access to the firmware below the OS , and may include a reset of BIOS settings, a wipe of public keys stored in the endpoint security controller, of private keys stored in the TPM, and the like . The skilled person understands that the erase process may not affect the ROM which typically stores firmware, BIOS / UEFI strings essential for basic operations of the electronic device . The erase process may be a factory erase in which user data, applications , and user-related settings are wiped, restoring the electronic device to its original factory state . The controller 120 of the electronic device 100 may thus bring the non-volatile memory into a factory reset state .

[0034]

[0031] As the erase process is completed, according to the example erasure assurance method, in step S320 , a 'destruction certificate' may be generated to demonstrate that an erase on the electronic device has occurred and may be used by a user or administrator to provide evidence (for example, to an auditor) that necessary precautions have been taken and data (confidential or otherwise user- related) were erased prior to recycling / disposing the electronic device or passing it on to another user . The certificate may be compliant with the 'certificate ofstandardization' as defined in the NIST SP 800-88 standard, Appendix G (National Institute of Standards and Technology Special Publication 800-88 Revision 1 Natl . Inst . Stand . Technol . Spec . Publ . 800-88 Revision 1 , 64 pages (December 2014 ) CODEN: NSPUE2 : http : / / d . doi , org / 10. 6028 / NIST . SP . 800-88rl) .

[0035]

[0032] In other words, in response to completing the erase process, a certificate may be generated indicating that an erase on the electronic device has occurred . Here, the certificate may include a (cryptographic) signature generated by a cryptographic entity of the electronic device . The skilled person understands that a cryptographic entity on a security processor may refer to a component of the electronic device responsible for performing cryptographic operations, such as key generation, encryption, decryption, and digital signing . The private key used for signing may be securely stored within the security processor and never leaves its protected environment . This ensures that the key cannot be accessed or stolen by unauthorized users or malicious software . When the certificate (or any other data) needs to be signed, the security processor may use the private key to generate a digital signature . This operation may be performed inside the secure boundary of the processor, ensuring that the key remains safe throughout the process . The certificate may also be signed by an external device or service . For example, the erase may occur in a secure environment, the unsigned destruction certificate may be retrieved from the electronic device and then signed by an external device or service . Alternatively, the erase may be performed and the certificate may be signed by the electronic device (as described above) , and then an external device or service may verify that signature, and additionally sign the destruction certificate with its own private signing key. The latter version may be useful as external entities verifying the erase would only needto store and manage one verification public key for all certificates , rather than the public key of each electronic device . Still alternatively, an erasure tool or APP, which contains a private key, may be loaded onto the electronic device . The tool itself may execute the erase and sign the certificate with its private key.

[0036]

[0033] After creation, the destruction certificate may be stored on the electronic device, so that anyone in possession of the electronic device could retrieve and verify the certificate . Additionally, the certificate may be extracted from the electronic device and stored elsewhere, so it can be retrieved and verified without access to the device . Verifying the certificate may include verifying the signature on the certificate as well as whether the information included in the certificate sufficiently demonstrates that an erase has been performed . In the case that the destruction certificate is signed, the receiver of the certificate will need to retrieve the public key that will be used to verify the signature in the destruction certificate . Hence, three workflows may be required : ( 1 ) an onboarding process where any public keys , universally unique identifiers (UUIDs ) or serial numbers are retrieved from the electronic device, (2 ) an erase execution and destruction certificate generation process , and (3) a destruction certificate retrieval and verification process .

[0037]

[0034] In general, the erase process may be initiated by an administrator or user in several ways . For example, the erase may be initiated remotely . A command may be constructed and sent to the electronic device through the OS . Alternatively, the erase may be an enhanced version of a (signed) protect and trace erase command, which may be sent either through the OS or directly to a (endpoint) security controller . Still alternatively, the erase maybe initiated by a local user, e . g . via a BIOS menu operation, through the F10 menu (with appropriate authentication or the like) . Once the command has been received and authenticated by the (endpoint) security controller, the erase process may be executed .

[0038]

[0035] According to the example erasure assurance method, in step S330 , in response to completing the erase process initiated locally or remoted in step S310 and thus to bring the electronic state into a (factory) reset state, the controller 120 may operate to load an operating system image into the non-volatile memory of the electronic device . In addition, according to the example erasure assurance method, in step S350 , the controller 120 may further bring the electronic device 100 into a locked state . The locked state of the electronic device blocks or restricts access to the operating system (image) and / or blocks or restricts any data and / or software configuration change or modifications on the electronic device, in particular the non-volatile memory thereof , until the electronic device is unlocked . By loading an operating system image, a generic (new) operating system may be installed on the electronic device 100 so that the electronic device may be readily used by another user, if required . Alternatively, by loading an operating system image, a custom operating system may be installed on the electronic device so that the electronic device may be readily used by another user in the same company or organization . As explained above, the locked state may be a state temporarily restricting access to the electronic device . An access to the electronic device in a mechanical and / or electronical manner during the locked state may dismiss unlock the electronic device .

[0039]

[0036] In other words , the erase process may be a full erase in the sense that user-related data, settings , and applications as well as the operating system are erasedon the electronic device and a generic operating system is loaded afterwards . Such an erase may be chosen if the electronic device is to be disposed of , recycled, or resold to a new user outside the company or organization .

[0040]

[0037] The erase process may, however, also be limiting in the sense that the electronic device restores a user data free state of the electronic device while data for establishing a secure operational environment, for example within a company or organization defining a security environment , for the electronic device is maintained . Such an erase process may also be referred to as a company erase in which the electronic device is brought into a state in which no previous user-related data (user-related data, settings, and applications ) remain, but it may not be a complete factory reset because management public keys and recovery settings (which may be stored, for example, in a security controller) may remain . Here, either a generic or custom operating system image may be loaded . Such an erase may be chosen if the electronic device is to be reused by a different user of the same company or organization, that is , the same company or organization maintains control over the electronic device even though the user has changed .

[0041]

[0038] The erase process may erase data except state information of a security processor of the electronic device to maintain data for establishing a secure operational environment for the electronic device . The skilled person understands that a security processor is a dedicated hardware module that may handle various security functions such as encryption and decryption, authentication, secure boot, key management, digital signature and integrity checks . A state of a security processor refers to its current configuration, data, and operational status , and may include current keys in use (for example, active cryptographic keys) , currentsecurity policies (for example, configurations for security operations ) , execution context (for example, tasks , processes , commands being executed) , and system status (for example, error conditions , ongoing transactions , locked states ) . The state may influence how the security processor responds to security tasks and external inputs .

[0042]

[0039] The erase process may also erase data except data for maintaining a management authority of the electronic device to maintain data for establishing a secure operational environment for the electronic device . The skilled person understands that a managing authority may refer to an entity, component or system (for example, a system' s BIOS or a trusted application such as a management software application) responsible for controlling, configuring and managing security functions and policies of a processor, in particular related to configuration management, access control, key management, security policy enforcement , firmware and software updates, monitoring and auditing . This may also maintain the relationship between a security processor and a management authority that may be characterized by a hierarchical and control-oriented interaction, where the management authority governs , configures , and monitors the security processor' s functions to establish a secure operational environment in which the security processor' s capabilities are effectively controlled and aligned with overall system security obj ectives .

[0043]

[0040] As indicated above , the temporary locked state may be implemented in different ways , for example by a posterase lock screen, an authorized user lock, or a cryptographic key lock .

[0044]

[0041] According to a preferred embodiment of the present disclosure, the temporary locked state may be achieved bygenerating a post-erase lock screen for the locked state . That is, after the erase has been initiated or has been completed, as generally indicated in step S210 of Figure 2B or S310 of Figure 3 , the electronic device 100 may be put into a locked state indicated by a screen displaying, on a graphical user interface thereof , information about the erase . This lock screen may be dismissed by anyone, and nothing can be done on or to the computer platform of the electronic device without the screen being dismissed . The post-erase screen may be actively dismissed, for example, by an individual user by indicating an acknowledgement (for example, entered to the computer platform via any of the I / O devices ) that an erase has occurred and that the screen should now be dismissed, and it should be proceeded to use the electronic device . Alternatively, the post-erase screen may be automatically dismissed in reaction to an (electronically and / or mechanically) interaction on or to the computer platform of the electronic device . As such, the electronic device may (continuously) monitor whether an electronical and / or mechanical (physical) interaction occurs with the computer platform of the electronic device . Such an interaction may, for example, be a USB or thunderbolt device being connected to the electronic device or a management command being received locally or remotely which may be executed by an (endpoint) security controller or the like . The lock screen may include a setting so that any such remotely received command would only be acted upon after the lock screen is dismissed .

[0045]

[0042] An interaction occurring to the electronic device may also be a detection or registration of a cover removal of the electronic device; in particular, this mechanism may detect whether a case of the electronic device is opened or a system (chassis ) cover of the electronic device is removed to obtain access to a system board, which potentially may be a physical attack related to aflash memory replacement, trusted platform module (TPM) probing attacks , direct memory attack, side channel attacks . Such a detection may be performed for different settings , such as while an Operating System of the electronic device is running, during a shutdown of the Operating System or during a hibernated or sleep state of the Operating System. The detection may be achieved using one or a plurality of removal sensors , such as a Hall effect sensor (tracking a proximity of a magnet ) , a mechanical switch, or the like, which may also operate when power sources are removed from the electronic device . A configuration of corresponding lock settings , such as for the cover removal sensor, may be done via a BIOS setting and may be managed locally or remotely. Based on this , if a cover removal is registered, the screen may be automatically dismissed . The skilled person understands that the electronic device may be shut down whilst the post-erase screen is present , but when it powers on again, the post-erase screen will continue to be displayed. The skilled person understands that the cover removals is a non-limiting example of a hardware change related to a mechanical / physical interaction .

[0046]

[0043] When user B receives the electronic device, user B can verify that the 'post-erase' screen is still present on the electronic device and has not been dismissed . If the post-erase display is (remains to be) present, user B has assurances that nothing has occurred on the computer platform of the electronic device since the erase, and so can proceed to dismiss the screen and safely use the electronic device . If , on the other hand, there is no post-erase display present, user B knows that something has occurred to the computer platform of the electronic device since the erase, and so necessary measures should be taken to recover from this by, for example, contacting the supplier or by user B completing an own erase .

[0044] The post-erase screen may include erase-related information such as : (i) a plaintext message indicating that the system is paused post an erase, and any activity or anything happening on or to the electronic device will un-pause (unlock) the system (dismiss the temporary locked state) ; (ii) information related to or identifying the electronic device, such as a UUID of the electronic device, a serial number of the electronic device, and / or a public key (or a certificate of the public key, or a hash of either of these values ) of, for example, a security controller' s cryptographic identity; and / or (iii ) information relating to the erase, including the destruction certificate and, if generated, a signature of the destruction certificate . This advantageously would enable user B to verify the erase prior to dismissing the post-erase screen . The information may be provided in different formats . For example, the information may be displayed in a user readable plaintext, but may all also be encoded in a QR code which the user could scan with an external device such as a smartphone . Such encoding simplifies the verification of the digital signature . Alternatively, rather than including this information directly, the post-erase screen may include a QR code, a website address or the like, which points the user to a location where all information is stored and can be retrieve .

[0047]

[0045] Figure 4 illustrates an example erasure assurance method 400 for the electronic device 100 using a posterase screen . Here, according to step S410, the electronic device 100 may execute an erase process , for example a factory erase process , initiated by user A, and may further generate a destruction certificate preferably together with a signature for the destruction certificate . In addition, according to step S420 , the electronic device 100 may generate and continuously display a post-erase screen, as described above, andmonitors the activity on the electronic device . As discussed, if any mechanical and / or electronical activity or any mechanical and / or electronical interaction with the electronic device is detected, the post-erase screen is dismissed . Then, for example in a state, in which user B has received the electronic device, it is checked in step S430 , whether the post-erase screen is active . If the post-erase screen is still active (Yes in step S430 ) , the electronic device may be used (e . g . for onboarding user B etc . ) in step S440 , preferably if also the destruction certificate is verified. On the other hand, if the post-erase screen is not active (No in step S330 ) , the electronic device may be readily used (e . g . for onboarding user B etc . ) because user B has not assurances that the erase is fresh and step S450 proceeds to perform a executing an erase themselves . As explained above, the post-erase screen may be actively dismissed by an individual user by, for example, indicating acknowledgement that an erase has occurred and that they would now like to dismiss the post-erase screen and proceed to use the electronic device . Alternatively, the post-erase screen may be automatically dismissed in a reaction to something happening on or to the computer platform of the electronic device, such as a system cover removal being detected, or a USB or thunderbolt device being connected, or a management command being received locally or remotely, and executed, for example, by an (endpoint) security controller of the electronic device .

[0048]

[0046] According to another preferred embodiment of the present disclosure, the temporary locked state may be achieved by employing a lock for an authorized user (an authorized user lock) . In other words , instead of showing a post-erase screen to 'pause' the electronic device which could be dismissed by anyone prior to use, the electronic device may alternatively be locked in such a way that only an authorized user can then unlock the electronicdevice to use it . Until the electronic device is unlocked, no user can make any changes or updates on the computer platform of the electronic device .

[0049]

[0047] A particular challenge with this lock for an authorized user solution may be, at the point of erasure and locking, identifying who an authorized user to unlock the electronic device later would be . For example, at the point user A performs a factory erase on the electronic device, it may not be known that user B is the specific user that will later be legitimately using the electronic device, and user A therefore may not have a way to establish credentials that could be used by user B to authenticate to the electronic device . The skilled person understands that the problem is not j ust that user A does not know who user B is, user B may not yet have been selected at the point in time of the factory erase and locking the electronic device .

[0050]

[0048] This specific problem can be overcome in specific use cases . For example : (i) in a first use case , where companies A and B are signed up to a common cloud (e . g . DaaS ) service, the electronic device may be locked by company A such that the common cloud service, which is known to company A (and at least subsequently also to company B) can unlock the electronic device . Later, the common cloud service may lock the device for an authorized unlocking only by company B .

[0051]

[0049] More specifically, in use case 1 , company A may lock the electronic device such that the common cloud (e . g . DaaS ) service may unlock the electronic device . User / Company B may subsequently receive the electronic device and use a public key-based authentication; for example, an (Sure Admin / On Demand Lock) unlock screen may be provided at the electronic device, preferably in addition to the post-erase screen described above . The(Sure Admin / On Demand Lock) unlock screen may initiate a challenge sequence, which also be referred to as an on- demand lock challenge, for example together with an electronic application (APP) on an additional electronic device (e . g . , a mobile phone) . The skilled person understands that the locked state may thus be implemented by a cryptographic key lock . The challenge may be generated on the device and encrypted using the locally stored public encryption key. As such, the (Sure Admin / On Demand Lock) unlock screen may display a ciphertext (the encrypted challenge) to the user via a QR code or the like . The user may scan the QR code using the additional electronic device to retrieve the ciphertext which may be decrypted using an accessible private key (or by requesting the company / organization to decrypt the ciphertext) . The user may then enter the plaintext challenge (or a representation of the challenge) to demonstrate, for example to the ESC, that the user has access to the private key corresponding to the public key stored on the electronic device, and thus is authenticated . Company B may thus use a (Sure Admin) APP that may also be provided with a new electronic device option . The ( Sure Admin) APP may interact with the common (DaaS ) cloud service (which may be a company owned service or alternatively a selected value-added reseller) which may manage the corresponding private key. The APP may also interact with the (DaaS ) cloud service to upload erase data from the QR code into the ( DaaS ) cloud service, but the private key (for authenticating the user) used to decrypt the plaintext is preferably owned by the company . Preferably, unlock audit information may be kept and logged for additional verification of the unlock process .

[0052]

[0050] This means that the controller of the electronic device may further facilitate or instruct sending information, for example related to the on-demand challenge ( such as QR codes , key-related information,PINs ) related to the factory-reset state and / or the locked state to an external device (e . g . the additional electronic device running the (Sure Admin) APP) or a cloud-based service entity (e . g . a server of the common (DaaS ) cloud service) .

[0053]

[0051] In this context, the skilled person understands that Sure Admin is , in general, a security feature that may be operated locally (in which a user is physically located with the electronic device) or remotely. Sure Admin, in the local version uses encryption with QR codes , as explained above, while the remote version may use digital signatures . Sure Admin allows for a secure management of BIOS settings using cryptographic controls instead of BIOS passwords . A digital signature mechanism may be used instead of passwords . Changes to the BIOS setting are authorized using cryptographic signatures . It may rely on a public key infrastructure in which a private key is used to sign BIOS configuration changes, and the corresponding public key should be securely stored (for example, in BIOS or the ESC) to verify the authenticity of the changes . BIOS settings may thus be securely managed remotely . Further, the on-demand (cryptographic) lock may be a lock that may be triggered remotely ensuring that the electronic device becomes inaccessible even if the user is not physically near the electronic device . This may immediately lock down the BIOS or the entire system of the electronic device . Based on the above, the skilled person understands that the on-demand lock can be unlocked (or dismissed) via the (local or remote) Sure Admin mechanism.

[0054]

[0052] For example : (ii) in a second use case in which the electronic device is staying within the company and only a user change occurs, user A may lock the electronic device such that only the IT department could unlock it .Subsequently, the IT department may lock the electronic device such that only user B could unlock the device .

[0055]

[0053] Also for the second use case a (Sure Admin / On Demand Lock) challenge may be provided as part of the unlock screen or in addition to the post-erase screen described above . The recipient (user B) user may use, for example, the APP running on another electronic device to scan the unlock QR code which may direct user B to the company' s key management server that would authenticate user B and audit the unlock command before providing an unlock pin .

[0056]

[0054] A lock for an authorized user may thus be implemented in different ways . For example, at the point of (factory) erasure, a public key may be specified such that, after the (factory) erasure is completed and the lock has happened, only someone demonstrating they own the private key corresponding to the specified public key can unlock the electronic device, for example, by participating in an authentication protocol with the electronic device, which may include providing, for example , a signature on a challenge presented by the electronic device or similar by providing correct decryption of an encrypted challenge ( such as in the case of using QR codes , as explained above) .

[0057]

[0055] In some cases , such as for the common cloud (e . g . DaaS ) service or a company' s IT department, public keys may already exist in the computer platform of the electronic device that may be leveraged to unlock the electronic device . For example, there may be a cloud (e . g . DaaS ) service public key and a tenant public key, plus multiple other keys such as the Secure Platform Management (SPM) key in a hierarchy of keys . In other cases , a key may be defined and transported in the erase command itself . Alternatively, existing lock mechanisms may be used, such as an On Demand lock feature or the like .

[0056] Here, if a Sure Admin / On Demand lock were to be used as the lock as described above , the QR code presented to the user at the electronic device may include the challenge information required to unlock the electronic device and may also include information regarding the erase, such as , for example, a link to the destruction certificate . The destruction certificate as described above may also be referred to as certificate of sanitization . The electronic device may also indicate two QR codes : a first QR regarding the corresponding unlock information, and a second QR code regarding the destruction certificate .

[0058]

[0057] According to a preferred embodiment of the present disclosure, the temporary locked state to provide erase assurance may also be achieved by a double lock mechanism. Figure 5 illustrates an example process workflow 500 establishing a temporary locked state may also be achieved by a double lock mechanism. According to step S510 , user / company A may instruct the electronic device to perform a factory erase on the electronic device and the controller may temporarily lock the electronic device using the common cloud (e . g . DaaS) service public key to establish a first temporary lock . User / company A may then send or transfer the (factory reset and locked with first lock) electronic device to the cloud service . According to step S520 , the cloud service receives the (factory reset and locked) electronic device from user / company A, allocates the electronic device to user / company B, and locks the electronic device using a public key of user / company B to establish a second temporary lock . Then, according to step S530 , the cloud service unlocks the electronic device regarding the first temporary lock using the cloud service' s corresponding private key, and the (factory reset and locked with second lock) electronic device is sent to user / company B . Subsequently, according to step S540 , user / company B receives the electronicdevice, and user / company B may verify the erase using the destruction certificate and may also verify the locked state . Then, user / company B finally unlocks the electronic device regarding the second temporary lock using user / company B' s corresponding private key.

[0059]

[0058] In other words , the computer platform of the electronic device may be locked to a second public key before being unlocked with the first private key to ensure that the electronic device is never in an unlocked state prior to reaching the next user . In still other words , the double lock mechanism is a mechanism in which at least temporary a first and second temporary lock is used, that is a state, in which the controller establishes a secondary locked state for the user device simultaneous with the primary locked state, the secondary locked state being established before the primary locked state is dismissed . This mechanism would also be useful in the above scenarios . For example : Company A executes an erase and locks the electronic device , for unlock by the common DaaS ; Company A returns the device to the common DaaS ; the DaaS allocates the device to company B and locks the device for unlock by company B, optionally, the DaaS may verify the destruction certificate before locking the device to company B; the DaaS removes the lock intended to DaaS ; the DaaS sends the device to company B; Company B verifies the device during intake . This may include verifying that the device is locked, capturing and verifying the destruction certificate, and verifying logs related to the locking and unlocking . Finally, Company B unlocks the electronic device . The skilled person understands that secure logs on the electronic device may capture the locking and unlocking seguence for later verification by party (user / company) B .

[0060]

[0059] As discussed above , when the electronic device is locked, the information displayed on the screen of theelectronic device may include the information as in the post-erase screen but may also include information relating to the lock . For example, the public key (or a hash of the public key) corresponding to the private key that must be used to unlock the device may be displayed, or logging information showing the lock / unlock history may be displayed.

[0061]

[0060] Figure 6 illustrates another example erasure assurance method 600 for the electronic or user device 100. This method provides a solution with an alternative order of the erase and locking processes . In other words , an instruction to execute an erase process may alternatively lead to an initial temporary locking of the electronic device which is then followed by the erase process .

[0062]

[0061] According to step S610 , the controller of the electronic or user device 100 may establish a (primary) locked state for the user device when an instruction is received to execute an erase process . The (primary) locked state may be a lock screen on a graphical user interface 110 of the user device 100. Other than in the abovedescribed post-erase lock screen, here the lock screen may receive a control signal to display information about the receipt of an erase instruction and the subsequent erase process when the lock screen is dismissed. This lock screen may be dismissed by anyone, and nothing can be done on or to the computer platform of the user device without the screen being dismissed . The lock screen may be actively dismissed, for example , by an individual user by indicating an acknowledgement (for example , entered to the computer platform via any of the I / O devices) that an erase should occur when the screen is dismissed.

[0063]

[0062] Then, according to step S630 , the controller may further be implemented or programmed to dismiss the(primary) locked state and to perform the erase process . For example, the lock screen of the locked state may initiate an on-demand lock-unlock challenge or mechanism to identify an authorized user and dismiss the (primary) locked state, as described above . An APP may have access to a local access private key to perform the cryptographic challenge . As such, the lock screen may additionally display a QR code (in which an encryption challenge may be included or a public key may be embedded) or the like which may be scanned using the additional electronic device . In particular, the cryptographic challenge may be generated and encrypted using a public key (accessible by the ESC) . A ciphertext may then be generated and displayed to the user via a QR code . Using the APP, the user may scan the QR code to retrieve the ciphertext and decrypt it, either by using an accessible private key or requesting an external entity to decrypt it . The plaintext challenge may then be entered . As such, by demonstrating access to the private key corresponding to the public key stored on the electronic device , the user can be authenticated . The (primary) locked state may thus be dismissed using a single cryptographic key pair .

[0064]

[0063] The locked state may also be implemented by using simultaneously a first and second temporary lock, as described above in conj unction with Figure 5. In other words , when the user device is given to another user or a cloud service, the controller may, using a second public-private key pair, establish a secondary locked state for the user device simultaneous with the primary locked state . The secondary locked state is established before the primary locked state is dismissed using a first public-private key pair . As such, even if the user device is transferred between multiple users or entities, a locked state is always maintained, so that an intermediate or final recipient of the user device is provided with improved assurances that there has not been a maliciousinterception or the device has not been compromised during the transfer . Then, as soon as the ( secondary) locked state is ended, the controller proceeds to perform the erase process to bring the user device into a state readily usable .

[0065]

[0064] A specific example of the alternative erasure assurance method may be as follows . An (endpoint ) security controller or other controller of the user / electronic device may receive and verify an erase instruction . The erase instruction may be an instruction to erase the user- related data , to perform a factory reset, or the like, as described above . The user / electronic device may then be temporarily brought into a locked state in which the erase may only be performed after the device has been brought into an unlocked state (in which the locked state is dismissed) . Subseguently, the user / electronic device may be transmitted to a third party such as a cloud service, to the IT department of a company or organization, or to another user . The third party may subsequently verify the locked state to gain an assurance that no software or data modification has occurred on the device after the instruction to perform an erase process . The third party may then unlock the user / electronic device, and the (endpoint) security controller may then execute the erase process and generate a destruction certificate as described above .

[0066]

[0065] As asset recovery and erase solutions are becoming more in demand due to concerns around supply chain security, the above-described solutions provide a complete and reliable erase of relevant user-related data on the electronic device . In particular, the abovedescribed solutions enable the erase function to be used in a range of use cases such that multiple parties may gain assurance from a single erase in a useable andefficient manner (in comparison to each party having to execute a (potentially slow) erase) .

[0067]

[0066] Figure 7 is a diagram of an example system 700 of an electronic or user device according to the present disclosure . The system may include a processor 710 and a non-transitory computer-readable storage medium 720 to store a computer program. Although the description may refer to a single processor and a single computer-readable storage medium, the description may also apply to a system with multiple processors and multiple computer-readable storage mediums . In such an example , the instructions may be distributed and stored across multiple computer- readable storage mediums and the instructions may be distributed and executed across multiple processors .

[0068]

[0067] Processor 710 may be a CPU, a GPU, a semiconductorbased microprocessor, and / or a hardware device suitable for retrieval and execution of instructions stored in the computer-readable storage medium 720. The processor 710 may fetch, decode, and execute instructions 722 , 724. The processor may be a part of a controller of a computing device as described above .

[0069]

[0068] Referring to Figure 7 , execute erase process instruction 722 , when executed by a processor of a controller, may comprise erase user-related data, user- related software or applications , related settings , and associated security information ( such as related cryptographic keys ) . As explained, the erase may be a factory erase to reset the electronic device to a factory state, for example to reset the electronic device to its factory default setting . In addition, bring electronic device into locked state instruction 724 , when executed by the processor of the controller, may bring the electronic device into a temporary locked state . The temporary locked state may be considered as a state thatis recognizable by a user and where access to the electronic device is momentarily restricted but can be bypassed or resolved by various mechanisms, as described above .

[0070]

[0069] In the foregoing detailed description of the present disclosure, reference is made to the accompanying drawings that form a part hereof , and in which is shown by way of illustration how examples of the disclosure may be practiced. These examples are described in sufficient detail to enable those of ordinary skill in the art to practice the examples of this disclosure, and it is to be understood that other examples may be utilized and that process, electrical, and / or structural changes may be made without departing from the scope of the present disclosure .

[0071]

[0070] The figures herein follow a numbering convention in which the first digit corresponds to the drawing figure number and the remaining digits identify an element or component in the drawing . Elements shown in the various figures herein can be added, exchanged, and / or eliminated to provide additional examples of the present disclosure . In addition, the proportion and the relative scale of the elements provided in the figures are intended to illustrate the examples of the present disclosure and should not be taken in a limiting sense .

Claims

CLAIMS1. An erase assurance method for an electronic device, comprising :executing an erase process to erase data stored in the electronic device; andin response to completing the erase processloading an operating system image into a nonvolatile memory of the electronic device, and bringing the electronic device into a locked state, the locked state blocking access to the operating system image on the electronic device until the electronic device is unlocked .2 . The erase assurance method of claim 1 , wherein the erase process restores a user data free state of the electronic device while maintaining data for establishing a secure operational environment for the electronic device .

3. The erase assurance method of claim 1 , further comprising generating a post-erase lock screen for the locked state .4 . The erase assurance method of claim 3 , wherein the posterase lock screen is dismissed in response to detecting a cover removal at the electronic device .

5. The erase assurance method of claim 3 , wherein the posterase lock screen is dismissed if an external device is connected with the electronic device or a remote management command is received and executed by a security controller of the electronic device .

6. The erase assurance method of claim 1 , further comprising, in response to completing the erase process :generating a certificate indicating that an erase on the electronic device has occurred, the certificate including a signature generated by a cryptographic entity of the electronic device .7 . An electronic device, comprising :a non-volatile memory to store an operating system;a controller to :- bring the non-volatile memory of the electronic device into a factory-reset state; andin response to establishing the factory-reset state,- bring the electronic device into a locked state;and- block modifications to the non-volatile memory while the electronic device is in the locked state .8 . The electronic device of claim 7 ,the controller further to dismiss the locked state in case of detecting an electronical and / or mechanical interaction on the electronic device .

9. The electronic device of claim 7 , wherein the locked state is implemented by a post-erase lock screen, an authorized user lock, a cryptographic key lock, or using simultaneously a first and second temporary lock .

10. The electronic device of claim 7 , wherein the locked state is dismissed using an on-demand lock challenge .

11. The electronic device of claim 7 ,the controller further to generate a certificate of sanitization indicating that the electronic device was brought into the factory-reset state, the certificate including a signature generated by a cryptographic entity related to the controller .12 . A user device, comprisinga non-volatile memory to store user-related data ;a controller to establish a primary locked state for the user device when an instruction is received to execute an erase process for the user-related data,the controller further to dismiss the primary locked state and to perform the erase process .

13. The user device of claim 12 ,the controller to generate, in the primary locked state, a lock screen on a graphical user interface of the user device .14 . The user device of claim 12 ,the controller further to use a cryptographic lock-unlock mechanism to dismiss the primary locked state .

15. The user device of claim 12 ,the controller to establish a secondary locked state for the user device simultaneous with the primary locked state, the secondary locked state being established before the primary locked state is dismissed .