Secure Erase Algorithms for Multi-Level File Chunks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure erase algorithms require significant computational resources for multiple overwrites, and there is a need for improved techniques to efficiently erase files with chunks associated with different security levels.

Innovation Solution

A method is implemented to select and apply different secure erase algorithms based on the security level of each chunk in a file, using computationally expensive algorithms for high-security chunks and less resource-intensive algorithms for lower-security chunks, optimizing the secure erase operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple secure erase overwrites are performed to meet government and industry standards, then data security and compliance are improved, but computational resources and processing time are significantly consumed

Engineering Contradiction:
Improvedata securityVSAvoidcomputational resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies different secure erase algorithms to different chunks of data based on their security classification. High-security chunks receive multiple overwrite passes with complex algorithms, while low-security chunks use simpler algorithms with fewer passes. This local differentiation ensures that computational resources are concentrated where security is most critical, rather than uniformly applying expensive algorithms to all data.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts the parameters of the secure erase operation based on the security level of each data chunk. For high-security data, it uses algorithms with more overwrite passes and more complex patterns. For low-security data, it reduces the number of passes and uses simpler patterns. This parameter adjustment resolves the contradiction by matching the security measure intensity to the actual security requirements of each data portion.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If a uniform high-security erase algorithm is applied to all file chunks, then maximum security is ensured, but processing efficiency and resource utilization deteriorate

Engineering Contradiction:
Improvesecurity levelVSAvoidprocessing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements local quality by classifying file chunks into different security categories and applying appropriate erase algorithms to each category. Critical data chunks receive the most rigorous treatment with multiple passes of complex algorithms, while non-critical chunks use faster, simpler algorithms. This approach maintains high security where needed while significantly improving overall processing efficiency.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system applies partial action by using high-security algorithms only for the portion of data that actually requires such protection. Instead of applying excessive security measures uniformly to all data, the patent tailors the security measure intensity to match the sensitivity of each data chunk, thereby improving productivity without compromising security where it matters.

Inventive Principle:
Principle #16Partial or excessive action

3Loss of information

If secure erase operations are performed on all chunks of a file, then complete data destruction is achieved, but the time and computational overhead increase significantly

Engineering Contradiction:
Improvedata destruction completenessVSAvoiderase operation time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent achieves local quality by analyzing the security classification of each file chunk and applying erase operations accordingly. Chunks marked as containing sensitive information undergo complete secure erasure with multiple passes, while chunks containing non-sensitive data receive faster erasure treatment. This ensures data destruction completeness for critical information while minimizing the time spent on less critical data.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes the erase operation parameters based on data sensitivity. For highly sensitive data, it uses multiple overwrite passes with different patterns to ensure complete destruction. For less sensitive data, it uses fewer passes and simpler patterns. This parameter adaptation resolves the contradiction between complete data destruction and acceptable erase time.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9111109B2Using different secure erase algorithms to erase chunks from a file associated with different security levels
Publication Date: 2015.08.18 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9111109B2 patent drawing
  • US9111109B2 patent drawing
  • US9111109B2 patent drawing

AI summary

Provided are a computer program product, system, and method for using different secure erase algorithms to erase chunks from a file associated with different security levels. A request is received to secure erase a file having a plurality of chunks stored in at least one storage device. A determination is made of a first secure erase algorithm to apply to a first chunk in the file in response to the request and of a second secure erase algorithm to apply to a second chunk in the file in response to the request. The first secure erase algorithm is applied to erase the first chunk and the second secure erase algorithm is applied to erase the second chunk. The first and second secure erase algorithms use different processes to erase the chunks to which they are applied.