Discrete Secure Erase Hardware Logic for Encryption Key Destruction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing infrastructure resources face challenges in securely erasing sensitive information stored on electronic devices, particularly due to corrupted erase mechanisms that can lead to unauthorized access or increased operational costs from physically destroying hardware devices.

Innovation Solution

Implementing discrete secure erase hardware logic within a security chip that operates independently of the device processor, using a combination of hardware logic gates to securely erase encryption keys without involving the main processor, and providing a local indicator for confirmation of successful erase operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing erase mechanisms are used to delete sensitive information, then information can be erased from storage, but the erase mechanisms can be corrupted leading to unauthorized access or require physical destruction of hardware

Engineering Contradiction:
Improvesecure erasureVSAvoidunauthorized access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the erasure function into two separate components: a discrete secure erase hardware logic circuit and the main device processor. This segmentation allows the erasure operation to be performed by dedicated hardware logic that is isolated from the main processor, preventing malware or corruption of the main processor from compromising the erasure function. The hardware logic circuit operates independently to erase encryption keys, ensuring reliable secure erasure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary indicator circuit that provides visible confirmation of successful erasure operations. This intermediary component bridges the gap between the discrete hardware logic and the user, providing tangible evidence that erasure occurred without requiring trust in the main processor or software mechanisms. The indicator serves as a mediator that verifies the erasure function worked as intended.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If discrete secure erase hardware logic is implemented, then secure erasure without processor involvement is achieved, but device complexity increases

Engineering Contradiction:
Improveerase securityVSAvoidhardware logic
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the secure erasure function from the main device processor and implements it as a separate discrete hardware logic circuit. This extraction removes the security-critical erasure function from the potentially compromised main processor, creating an isolated trust zone. The discrete hardware logic contains only the essential functionality needed for secure key erasure, minimizing its complexity while maximizing its security value.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies local quality by making the indicator circuit visible only to users in close physical proximity to the device. This localized visibility ensures that confirmation of erasure cannot be remotely observed or tampered with, providing security while using a simple visual indicator rather than complex notification systems. The local quality constraint simplifies the indicator mechanism while maintaining security.

Inventive Principle:
Principle #3Local quality

3Reliability

If encryption keys are erased to secure information, then provider-tenant isolation is maintained, but hardware components cannot be reused

Engineering Contradiction:
Improveprovider-tenant isolationVSAvoidhardware reuse
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements a mechanism where encryption keys are selectively erased from the discrete hardware logic circuit while the physical hardware components remain intact and reusable. After a tenant's data is securely erased by destroying the encryption keys, the same hardware circuit can be reconfigured or reprogrammed for use with a different tenant or purpose. This allows the infrastructure provider to maintain provider-tenant isolation while recovering and reusing expensive hardware components, improving productivity.

Inventive Principle:
Principle #34Discarding and recovering

Data Source

PatentUS20240256679A1Information erase by a discrete secure erase hardware logic
Publication Date: 2024.08.01 HEWLETT PACKARD ENTERPRISE DEV LP
  • US20240256679A1 patent drawing
  • US20240256679A1 patent drawing
  • US20240256679A1 patent drawing

AI summary

In some examples, a security chip for an electronic device includes a nonvolatile memory to store a collection of encryption keys for encrypting information to produce encrypted information. The security chip includes a discrete secure erase hardware logic and is separate from a collection of device processors of the electronic device. The discrete secure erase hardware logic receives an erase indication indicating a request to erase the encrypted information. In response to the erase indication, the discrete secure erase hardware logic erases the collection of encryption keys in the nonvolatile memory, and activates an output indication to cause activation of an erase indicator at the electronic device.