Storage Drive Erasure Attestation Using Root-of-Trust Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data erasure processes in cloud storage lack reliability, accountability, and consistency, leading to untrustworthy data destruction methods that compromise customer data security and trust, with third-party services often failing to guarantee complete erasure due to lack of manufacturer-level control over storage drives.
Innovation Solution
Implementing a root-of-trust (RoT) in storage drives to collect and verify cryptographic measurements of erasure operations, ensuring accurate and complete data erasure through a secure attestable methodology, with manufacturer-defined criteria and third-party auditing, and recording erasure evidence in a confidential ledger accessible only to the data owner.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If third-party erasure services are used, then data erasure can be performed, but complete erasure cannot be guaranteed due to lack of manufacturer-level control over storage drives
Solution Approach 1:
The patent introduces a root-of-trust (RoT) as an intermediary component within the storage drive that enables secure erasure attestation. The RoT acts as a mediator between the erasure service and the storage medium, providing cryptographic verification of erasure completeness without requiring direct manufacturer-level control. This resolves the contradiction by enabling reliable erasure verification through a trusted intermediary rather than direct control.
Solution Approach 2:
The patent replaces mechanical/physical control mechanisms with cryptographic verification mechanisms. Instead of relying on physical access or manual verification of erasure, the system uses cryptographic hashes, digital signatures, and attestation certificates to verify erasure completeness. This substitution enables reliable verification without requiring complex control access or physical intervention.
2Reliability
If physical destruction of drives is implemented, then data security is improved, but cost recovery and environmental benefits are lost
Solution Approach 1:
The patent implements a feedback mechanism through cryptographic attestation that provides verifiable confirmation of erasure completion. The root-of-trust generates attestation certificates that can be verified by the data owner, providing feedback on erasure effectiveness. This enables confidence in data security without requiring physical destruction, allowing drives to be recycled or repurposed while maintaining security.
Solution Approach 2:
The patent changes the parameter of verification from physical inspection to cryptographic verification. Instead of relying on physical destruction to ensure security, the system uses cryptographic parameters (hashes, signatures, certificates) to verify erasure. This parameter change enables security verification without physical destruction, preserving resource value and environmental benefits.
3Ease of operation
If existing erasure processes mark blocks as free for garbage collection, then erasure can be implemented, but there is no real mechanism for guaranteeing actual erasure
Solution Approach 1:
The patent performs preliminary action by having the root-of-trust collect and verify cryptographic measurements of the storage drive state before and after erasure operations. The system pre-establishes verification criteria and measurement protocols, then executes them systematically to guarantee erasure. This preliminary preparation enables both ease of operation through automated verification and reliability through cryptographic guarantees.
Solution Approach 2:
The patent substitutes the unreliable mechanical garbage collection process with cryptographic verification. Instead of relying on the asynchronous and unverified garbage collection mechanism, the system uses cryptographic hashes and digital signatures to provide a deterministic and verifiable erasure guarantee. This substitution transforms the erasure process from operationally simple but unreliable to both easy and reliable.
4Productivity
If human technicians perform drive destruction, then physical erasure can be carried out, but irrefutable audibility is lacking and misuse by technicians is possible
Solution Approach 1:
The patent replaces the human technician process with an automated cryptographic verification system. Instead of relying on human operators whose actions cannot be verified, the system uses root-of-trust cryptographic attestation to provide irrefutable proof of erasure. The RoT generates and signs attestation certificates that cannot be forged, eliminating the audibility problem associated with human-based processes.
Solution Approach 2:
The root-of-trust acts as an intermediary that bridges the erasure execution and verification processes. It collects cryptographic measurements, generates attestation certificates, and provides verifiable proof of erasure. This intermediary mechanism enables automated, auditable verification without requiring human intervention in the verification process, thereby ensuring irrefutable audibility.
Data Source
AI summary
A method securely erasing data on a storage drive includes transmitting a communication that initiates an erasure operation on a storage drive and receiving a drive erasure attestation generated in association with erasure operation and by a root-of-trust of the storage drive. The drive erasure attestation includes a first claim that contains cryptographic evidence of a measured state of the storage drive following the erasure operation. The method further includes verifying the first claim and instructing a ledger service to record the drive erasure attestation in a ledger in response to the verification. Verification of the first claim depends upon confirmation of a match between first measurement values in the first claim and a first set of stored values previously-verified as corresponding to a correct implementation of the erasure operation.


