Information Processing Apparatus Hibernation Data Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information processing apparatuses with hibernation functions do not adequately differentiate between confidential and non-confidential data during the hibernation process, potentially compromising the security of sensitive information when stored on nonvolatile storage devices.
Innovation Solution
Incorporating a classification unit that distinguishes between confidential and non-confidential information by using a second secure nonvolatile storage device with encryption or password locking functions, while a first storage unit handles less sensitive data, ensuring secure storage and retrieval during hibernation and startup processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all information from memory is stored on a single nonvolatile storage device during hibernation, then the hibernation function operates simply and quickly, but confidential information may be accessed unauthorizedly if the storage device is removed
Solution Approach 1:
The nonvolatile storage device is divided into two distinct storage units: a first storage unit for confidential information and a second storage unit for other information. This segmentation allows confidential data to be isolated and protected with additional security measures while maintaining separate access paths, thereby improving data security without requiring a completely new storage architecture
Solution Approach 2:
The classification unit acts as an intermediary between the memory and the storage units, determining which information belongs in the first storage unit and which belongs in the second. This intermediary component enables automated classification and routing of data based on confidentiality criteria, resolving the complexity of manual classification while enhancing security
2Reliability
If confidential information is separated and stored on a secure storage device with encryption or password locking, then unauthorized access is prevented, but the storage system becomes more complex and requires additional security mechanisms
Solution Approach 1:
Different security qualities are applied to different storage units: the first storage unit implements encryption or password locking mechanisms specifically for confidential information, while the second storage unit stores other information with standard access controls. This localized application of security measures protects sensitive data without unnecessarily complicating the storage of non-sensitive information
Solution Approach 2:
The classification unit performs preliminary classification of information before storage, identifying confidential information and routing it to the secure first storage unit before the hibernation process completes. This preliminary action ensures that security measures are applied only where needed, reducing overall system complexity while maintaining protection
3Reliability
If a classification unit is introduced to distinguish between confidential and non-confidential information, then data security is improved, but the system complexity and processing time increase
Solution Approach 1:
The classification unit utilizes existing metadata or attributes already associated with files and data structures in the memory to automatically classify information as confidential or non-confidential. By leveraging existing data characteristics rather than requiring deep content analysis, the system achieves security classification with minimal additional processing time
Data Source
AI summary
An information processing apparatus includes a controller, a first storage unit, a second storage unit, and a classification unit. The controller stores pieces of information retained in a memory on a nonvolatile storage device and, upon startup, makes the information processing apparatus return to a state before power-down. The first storage unit is part of the nonvolatile storage device and stores some pieces of information among the pieces of information retained in the memory. The second storage unit is part of the nonvolatile storage device and stores pieces of information different from those stored on the first storage unit among the pieces of information retained in the memory. The classification unit classifies the pieces of information retained in the memory. The controller stores the pieces of information retained in the memory on the first storage unit or the second storage unit in accordance with classification performed by the classification unit.

