Storage System Targeted Data Erasure with Concurrent I/O
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing data erasure techniques, such as the U.S. Department of Defense (DoD) method, are slow and significantly impair I/O performance, making them impractical for large-scale storage environments, as they require taking storage resources offline and are time-consuming.
Innovation Solution
A method and system that securely removes data from storage systems by mapping logical units to physical extents, allowing for concurrent I/O operations during the erasure process, using hardware and software to execute a secure data removal process that overwrites data on targeted extents while leaving other data intact, and includes modules for isolation and tracking to ensure data integrity and efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the DoD data erasure technique is used to securely erase data, then data security is improved, but I/O performance and processing speed deteriorate significantly
Solution Approach 1:
The storage system is divided into multiple storage resources, and the data erasure process is segmented to operate on specific portions rather than the entire storage system. This allows other portions to remain accessible, maintaining I/O performance while securing specific data regions.
Solution Approach 2:
Instead of applying the comprehensive DoD erasure technique to the entire storage system, the patent applies erasure operations to only the specific data portions that require secure deletion. This partial action approach maintains overall system productivity while achieving the security goal for targeted data.
2Reliability
If the DoD data erasure technique is used to securely erase data, then data security is improved, but the time required for erasure increases substantially
Solution Approach 1:
The erasure process is segmented into parallel operations across multiple storage resources and portions, reducing the total time required compared to sequential erasure of the entire system.
Solution Approach 2:
The system allows I/O operations to continue on non-erased portions during the erasure process, maintaining continuous useful action and reducing the overall impact on system productivity and time loss.
3Reliability
If the DoD data erasure technique is used to securely erase data, then data security is improved, but storage resources become inaccessible during the process
Solution Approach 1:
The storage system is segmented into erased and non-erased portions, allowing I/O operations to continue on the non-erased portions. This maintains ease of operation for accessible data while performing secure erasure on targeted segments.
Solution Approach 2:
Only specific storage resources or portions are taken offline for erasure operations, rather than the entire system. This partial action approach preserves accessibility for other storage resources, maintaining operational ease.
Data Source
AI summary
A method for securely removing data from a storage system is disclosed. In one embodiment, such a method includes receiving, by a storage system, instructions to erase logical units from the storage system. In response to receiving the instructions, the storage system maps the logical units to physical extents on the storage system. The storage system then initiates, using at least one of hardware and software embedded in the storage system, a secure data removal process that securely erases data from the physical extents by overwriting the data thereon, while leaving intact data stored on other physical extents of the storage system. The storage system is configured to process I/O to the other physical extents during execution of the secure data removal process. A corresponding system and computer program product are also disclosed.


