Data Sanitization Attestation via Encryption Key Fingerprinting
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data sanitization methods may leave behind recoverable data traces, and there is a need for secure evidence of complete data erasure, especially for sensitive information stored on data storage devices.
Innovation Solution
An apparatus and method for data sanitization that securely erases data by overwriting storage encryption keys, generates fingerprints of these keys, and provides a signed attestation confirming successful sanitization, including details of the erasure process and device authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is securely erased by overwriting encryption keys, then data recovery is prevented, but verification of complete erasure becomes difficult
Solution Approach 1:
The patent applies preliminary action by capturing fingerprints of encryption keys before they are overwritten during sanitization. These fingerprints serve as pre-established evidence that proves the keys existed and were subsequently destroyed, providing verifiable proof of complete data erasure without requiring complex post-erasure analysis
Solution Approach 2:
The patent uses fingerprints as an intermediary representation of the encryption keys. Instead of directly verifying the destruction of complex encryption keys, the system verifies the destruction of their simpler fingerprint representations, which serve as unique identifiers. This intermediary approach simplifies the verification process while maintaining security
2Device complexity
If traditional data erasure methods are used, then device complexity is low, but data traces may remain recoverable
Solution Approach 1:
The patent replaces mechanical data erasure methods (overwriting individual data blocks) with a cryptographic approach. By overwriting the encryption key that protects the data, the system achieves secure erasure through cryptographic means rather than mechanical data destruction, maintaining simplicity while ensuring reliability
Solution Approach 2:
The patent changes the parameter being erased from the data itself to the encryption key. Instead of modifying data parameters (overwriting data blocks), the system changes the security parameter (encryption key) that controls access to the data, making the data unrecoverable without adding complex erasure procedures
3Reliability
If encryption keys are overwritten to sanitize data, then data security is improved, but proof of sanitization becomes harder to establish
Solution Approach 1:
The patent creates a copy of the essential identifying information (fingerprint) of the encryption key before destruction. This fingerprint copy serves as evidence that the key existed and was processed, providing verifiable proof of sanitization without retaining the actual sensitive key material
Solution Approach 2:
The system performs preliminary capture of the encryption key fingerprint before the key is overwritten. This pre-captured fingerprint becomes permanent evidence of the key's existence and subsequent destruction, ensuring that proof of sanitization is established before the actual erasure occurs
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Systems and methods are disclosed for performing data sanitization at a data storage device (DSD). In an embodiment, a controller may direct a memory device to sanitize data by securely erasing the data, generate an attestation confirming that the data was successfully sanitized, and sign the attestation using an authentication key to create a signed attestation. In another embodiment, a circuit may direct a memory device to sanitize data based on the data sanitization instruction, generate a sanitization confirmation indicating that the data was successfully sanitized, and provide the sanitization confirmation including a first thumbprint and a second thumbprint to another device. Generating the sanitization confirmation may include processing a first storage encryption key to produce the first thumbprint, directing the memory device to obliterate the first storage encryption key, and processing a second storage encryption key to produce the second thumbprint.