Secure Erase Algorithms for Multi-Level File Chunks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing secure erase algorithms require significant computational resources for multiple overwrites, and there is a need for improved techniques to efficiently erase files with chunks associated with different security levels.
Innovation Solution
A method is implemented to select and apply different secure erase algorithms based on the security level of each chunk in a file, using computationally expensive algorithms for high-security chunks and less resource-intensive algorithms for lower-security chunks, optimizing the secure erase operation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple secure erase overwrites are performed to meet government and industry standards, then data security and compliance are improved, but computational resources and processing time are significantly consumed
Solution Approach 1:
The patent applies different secure erase algorithms to different chunks of data based on their security classification. High-security chunks receive multiple overwrite passes with complex algorithms, while low-security chunks use simpler algorithms with fewer passes. This local differentiation ensures that computational resources are concentrated where security is most critical, rather than uniformly applying expensive algorithms to all data.
Solution Approach 2:
The system dynamically adjusts the parameters of the secure erase operation based on the security level of each data chunk. For high-security data, it uses algorithms with more overwrite passes and more complex patterns. For low-security data, it reduces the number of passes and uses simpler patterns. This parameter adjustment resolves the contradiction by matching the security measure intensity to the actual security requirements of each data portion.
2Reliability
If a uniform high-security erase algorithm is applied to all file chunks, then maximum security is ensured, but processing efficiency and resource utilization deteriorate
Solution Approach 1:
The patent implements local quality by classifying file chunks into different security categories and applying appropriate erase algorithms to each category. Critical data chunks receive the most rigorous treatment with multiple passes of complex algorithms, while non-critical chunks use faster, simpler algorithms. This approach maintains high security where needed while significantly improving overall processing efficiency.
Solution Approach 2:
The system applies partial action by using high-security algorithms only for the portion of data that actually requires such protection. Instead of applying excessive security measures uniformly to all data, the patent tailors the security measure intensity to match the sensitivity of each data chunk, thereby improving productivity without compromising security where it matters.
3Loss of information
If secure erase operations are performed on all chunks of a file, then complete data destruction is achieved, but the time and computational overhead increase significantly
Solution Approach 1:
The patent achieves local quality by analyzing the security classification of each file chunk and applying erase operations accordingly. Chunks marked as containing sensitive information undergo complete secure erasure with multiple passes, while chunks containing non-sensitive data receive faster erasure treatment. This ensures data destruction completeness for critical information while minimizing the time spent on less critical data.
Solution Approach 2:
The system changes the erase operation parameters based on data sensitivity. For highly sensitive data, it uses multiple overwrite passes with different patterns to ensure complete destruction. For less sensitive data, it uses fewer passes and simpler patterns. This parameter adaptation resolves the contradiction between complete data destruction and acceptable erase time.
Data Source
AI summary
Provided are a computer program product, system, and method for using different secure erase algorithms to erase chunks from a file associated with different security levels. A request is received to secure erase a file having a plurality of chunks stored in at least one storage device. A determination is made of a first secure erase algorithm to apply to a first chunk in the file in response to the request and of a second secure erase algorithm to apply to a second chunk in the file in response to the request. The first secure erase algorithm is applied to erase the first chunk and the second secure erase algorithm is applied to erase the second chunk. The first and second secure erase algorithms use different processes to erase the chunks to which they are applied.


