Nonvolatile Memory Drive Secure Erase Modes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional data storage devices face challenges in securely erasing data without overwriting it on the hard disk, leading to potential information leakage due to decoding difficulties of scrambled data.
Innovation Solution
An information processing apparatus with a nonvolatile semiconductor memory drive that employs a control module with three erase modes: pseudo-erase, normal erase, and expansive erase, utilizing an address management table to ensure secure data deletion and prevent information leakage by initializing logical block addresses and managing physical addresses to set memory areas as non-written states.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is scrambled for security, then decoding difficulty increases, but take-out of scrambled data becomes easier leading to potential information leakage
Solution Approach 1:
The patent applies preliminary action by erasing data before physical disposal or reuse of the storage device. The control unit executes erase commands that clear data from memory blocks prior to the device being taken out or repurposed, preventing any subsequent decoding or information leakage regardless of the scrambling mechanism's strength.
Solution Approach 2:
The patent changes the state parameter of data from stored to erased by implementing multiple erase modes (pseudo-erase, normal erase, expansive erase) that modify memory block states. These parameter changes ensure data is transformed into an unrecoverable state, addressing the security vulnerability of scrambled data that could potentially be decoded.
2Loss of time
If virtual erase is performed by changing initial values, then work time for re-use or discard is reduced, but data cannot be normally read out making secure deletion insufficient
Solution Approach 1:
The patent segments the erase operation into three distinct modes: pseudo-erase (fast, initializes address management table), normal erase (moderate speed, erases specific blocks), and expansive erase (comprehensive, erases all blocks including defective ones). This segmentation allows users to select the appropriate erase level based on security requirements, resolving the contradiction between speed and security by providing options rather than a single approach.
Solution Approach 2:
The patent implements dynamic erase operations where the control unit can selectively apply different erase modes based on the situation. The system dynamically adjusts the erasure thoroughness - using pseudo-erase for quick re-use scenarios and expansive erase for secure disposal scenarios, making the erasure process adaptive to different security needs while maintaining efficiency.
3Productivity
If normal erase is performed, then data is erased from non-defective blocks, but defective blocks remain unerased creating security vulnerabilities
Solution Approach 1:
The patent changes the erasure parameter from partial (normal erase affecting only non-defective blocks) to complete (expansive erase affecting all blocks including defective ones). The control unit is designed to handle defective blocks specifically during expansive erase operations, ensuring that no data remains in any block type, thereby eliminating security vulnerabilities while maintaining operational efficiency through mode selection.
Data Source
AI summary
According to one embodiment, a control module of a nonvolatile semiconductor memory drive has a first erase mode in which an address management table, which is indicative of a correspondency between logical block addresses and physical addresses of a nonvolatile semiconductor memory, is initialized to set the memory area of the nonvolatile semiconductor memory in a state in which no user data is written, a second erase mode in which the address management table is initialized to set the memory area in a state in which no user data is written, and the blocks, other than a defective block, which are included in the memory area, are erased, and a third erase mode in which the address management table is initialized to set the memory area in a state in which no user data is written, and the blocks, including the defective block, which are included in the memory area, are erased.


