Storage Device Data Invalidation via Segmented Erasure
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing storage devices face challenges in securely invalidating user data when accessed from unauthorized environments, with existing methods either being time-consuming or increasing processing complexity and power consumption, and may not comply with regulatory requirements across different nations.
Innovation Solution
A storage device configuration that includes a nonvolatile semiconductor memory, a drive control circuit with authentication modules, and a NAND memory structure, which executes parallel operations to quickly invalidate user data by modifying address translation information and employing incomplete erasure techniques to prevent data retrieval.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If complete erasure methods are used to invalidate user data, then data security is improved, but processing time and power consumption increase
Solution Approach 1:
The patent segments the data invalidation process into two distinct methods: complete erasure for high-security scenarios and incomplete erasure for routine operations. By dividing the invalidation approach based on security requirements, the system achieves both fast processing (incomplete erasure) and high security (complete erasure when needed) without always incurring the full time and power cost of complete erasure.
Solution Approach 2:
The patent applies partial action through incomplete erasure, where only sufficient portions of data are erased to prevent retrieval while leaving some data intact. This partial erasure method provides adequate security for many scenarios without the excessive time and power consumption of complete erasure, thus resolving the contradiction between security and processing efficiency.
2Reliability
If complete erasure methods are used to invalidate user data, then data security is improved, but power consumption increases
Solution Approach 1:
The patent segments the erasure strategy into complete and incomplete methods, allowing the system to select the appropriate level of erasure based on security requirements. This segmentation enables power-efficient incomplete erasure for routine operations while reserving complete erasure for high-security scenarios, thus reducing overall power consumption while maintaining adequate security.
Solution Approach 2:
The patent changes the erasure parameter from always complete to conditionally complete or incomplete. By adjusting the erasure completeness parameter based on security requirements, the system optimizes power consumption by using less intensive incomplete erasure when full security is not required, while still providing complete erasure capability when needed.
3Reliability
If authentication and data invalidation processes are enhanced, then data security is improved, but device complexity increases
Solution Approach 1:
The patent segments the security mechanism into authentication module and erasure control module that work independently but coordinate through simple interfaces. This modular segmentation reduces complexity by allowing each module to handle its specific function without requiring the entire system to become more complex, thus improving security through specialized components while managing overall system complexity.
Data Source
AI summary
According to one embodiment, a storage device that has a nonvolatile semiconductor memory includes an authentication information storage unit that previously stores first apparatus authentication information to authenticate an authorized host device and first user authentication information to authenticate an authorized user. The storage device executes apparatus authentication on the basis of second apparatus authentication information received from a newly connected host device and the first apparatus authentication information in the authentication information storage unit and executes an invalidation process of user data stored in the nonvolatile semiconductor memory, when the apparatus authentication is failed.


