Cloud Host Secure Erasure via Daemon Process

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In conventional cloud-computing environments, erasing a cloud host only labels the memory space as unoccupied, leading to resource wastage and potential information security risks due to unrecoverable sensitive data, with existing methods not adequately addressing the impact on other running instances sharing the same system.

Innovation Solution

A method and system that securely erase a cloud host by generating an erase instruction, sending it to a secure erasing server, which calls a secure erasing daemon process to erase the host, minimizing resource wastage and ensuring data unrecoverability through prioritization of erase tasks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If simple erasing function is used to label memory space as unoccupied, then operation simplicity is improved, but resource wastage increases and information security deteriorates

Engineering Contradiction:
Improveerasing operation simplicityVSAvoidsystem resource wastage
Core Design Contradiction:
Ease of operationVSLoss of energy

Solution Approach 1:

The patent introduces a secure erasing daemon process as an intermediary component that runs on the host machine. This daemon receives erase instructions from the virtualization management server and executes the actual secure erasure operations on cloud hosts, bridging the gap between simple user requests and complex secure erasure requirements without burdening the user with complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The secure erasing daemon process operates autonomously on the host machine, self-managing the secure erasure operations. It receives instructions, identifies target cloud hosts, executes secure erasure algorithms, and manages the entire secure deletion process without requiring continuous external intervention, thereby enabling comprehensive resource utilization while maintaining operational simplicity.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If simple erasing function is used to label memory space as unoccupied, then operation simplicity is improved, but information security deteriorates due to data recoverability

Engineering Contradiction:
Improveerasing operation simplicityVSAvoidinformation security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The secure erasing daemon acts as an intermediary that implements robust security measures while keeping the user interface simple. It executes secure erasure algorithms that ensure data unrecoverability, using cryptographic techniques and multiple-pass deletion methods without requiring users to understand or configure these complex security mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements secure erasure by treating data as disposable and irrecoverable after deletion. The secure erasing daemon executes comprehensive deletion algorithms that overwrite data multiple times or use cryptographic shredding methods, ensuring that sensitive information cannot be recovered even if storage media is later accessed or analyzed.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Reliability

If secure erasing is implemented to actually delete data, then information security is improved, but device complexity increases

Engineering Contradiction:
Improveinformation securityVSAvoidsystem structure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the secure erasure functionality into distinct modular components: a secure erasing daemon process running on the host machine, virtualization management server components, and cloud host entities. This segmentation allows each component to have specialized responsibilities, simplifying the overall system architecture while enabling comprehensive secure erasure capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure erasing daemon process autonomously manages the complex secure erasure operations, handling instruction parsing, target identification, algorithm execution, and result reporting without requiring complex external coordination. This self-service capability reduces the apparent system complexity from the user perspective while maintaining robust security functionality.

Inventive Principle:
Principle #25Self-service

4Productivity

If secure erasing daemon process is used to erase cloud hosts, then resource utilization is improved, but impact on other running instances increases

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidimpact on other instances
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The secure erasure process is applied locally and specifically to the target cloud host's data and resources only. The daemon process identifies and erases only the data belonging to the specific cloud host being decommissioned, leaving other running instances and their data completely unaffected. This localized approach ensures that secure erasure of one instance does not interfere with or impact other instances sharing the same physical infrastructure.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3279795B1Method and apparatus for deleting cloud host in cloud computing environment, server and storage medium
Publication Date: 2022.01.19 PING AN TECH (SHENZHEN) CO LTD
  • EP3279795B1 patent drawingFigure 1~2
  • EP3279795B1 patent drawingFigure 3~4
  • EP3279795B1 patent drawingFigure 5

AI summary

A method of erasing a cloud host in a cloud-computing environment includes: receiving a cloud host secure erasing request; generating an erase instruction according to the request; and sending the erase instruction to a secure erasing server, such that the secure erasing server calls a secure erasing daemon process on the corresponding host machine according to the erase instruction, and erases the cloud host to be erased on the host machine via the secure erasing daemon process.