Information erase by a discrete secure erase hardware logic
View Patent ↗In some examples, a security chip for an electronic device includes a nonvolatile memory to store a collection of encryption keys for encrypting information to produce encrypted information. The security chip includes a discrete secure erase hardware logic and is separate from a collection of device processors of the electronic device. The discrete secure erase hardware logic receives an erase indication indicating a request to erase the encrypted information. In response to the erase indication, the discrete secure erase hardware logic erases the collection of encryption keys in the nonvolatile memory, and activates an output indication to cause activation of an erase indicator at the electronic device.
1 . An electronic device comprising:
a collection of device processors;
a physical erase actuator;
an erase indicator; and
a security chip comprising:
a nonvolatile memory to store a collection of encryption keys for encrypting information to produce encrypted information; and
a discrete secure erase hardware logic in the security chip and that is separate from the collection of device processors, the discrete secure erase hardware logic to, while the collection of device processors is disabled:
enable the discrete secure erase hardware logic to perform an erase of the collection of encryption keys based on an indication of a physical containment structure of the electronic device being unlocked;
receive, at the discrete secure erase hardware logic, an erase indication indicating a request to erase the encrypted information, the erase indication provided based on physical user interaction with the physical erase actuator,
in response to the erase indication and the discrete secure erase hardware logic being enabled based on the indication of the physical containment structure being unlocked, erase the collection of encryption keys in the nonvolatile memory, and
activate an output indication to cause activation of the erase indicator of the electronic device.
2 . The electronic device of claim 1 , wherein the physical erase actuator comprises a biometric reader to sense a biometric feature of a user, and the discrete secure erase hardware logic is to authorize the erasing of the collection of encryption keys based on the biometric feature sensed by the biometric reader.
3 . The electronic device of claim 1 , wherein the physical erase actuator comprises a receptacle to receive a peripheral device to plug into a physical port of the security chip, and wherein the erase indication is based on the peripheral device being plugged into the physical port of the security chip.
4 . The electronic device of claim 1 , further comprising:
one or more power supplies to:
inactivate a primary power voltage to the collection of device processors to disable the collection of device processors, and
activate an auxiliary power voltage to the security chip while the primary power voltage to the collection of device processors is inactivated.
5 . The electronic device of claim 1 , wherein the discrete secure erase hardware logic is to receive the erase indication, erase the collection of encryption keys, and activate the output indication without execution of any machine-readable instructions on the security chip.
6 . The electronic device of claim 1 , wherein the erasing of the collection of encryption keys renders the encrypted information in a persistent memory of the electronic device inaccessible.
7 . The electronic device of claim 1 , comprising:
an output pin to communicate the output indication to the erase indicator of the electronic device.
8 . The electronic device of claim 1 , wherein the erase indicator is selected from among a visual indicator, an audio indicator, or a tactile indicator.
9 . The electronic device of claim 1 , wherein the physical containment structure holds a plurality of electronic devices.
10 . A method comprising:
storing, in a nonvolatile memory of a security chip in an electronic device, a collection of encryption keys for encrypting information to produce encrypted information;
while a collection of device processors in the electronic device is disabled:
enabling, by the security chip, a discrete secure erase hardware logic in the security chip to perform an erase of the collection of encryption keys based on an indication of a physical containment structure of the electronic device being unlocked;
receiving, at the security chip, an erase indication indicating a request to erase the encrypted information, the erase indication provided based on physical user interaction with a physical erase actuator of the electronic device;
as a response to the erase indication and when the discrete secure erase hardware logic is enabled based on the indication of the physical containment structure being unlocked, erasing, by the discrete secure erase hardware logic in the security chip, the collection of encryption keys in the nonvolatile memory;
activating an output indication provided from the security chip; and
activating an erase indicator at the electronic device in response to the activating of the output indication.
11 . The method of claim 10 , wherein the erasing of the collection of encryption keys is performed prior to returning the electronic device from a tenant to a provider of the electronic device.
12 . The method of claim 10 , wherein the physical containment structure holds a plurality of electronic devices.
13 . The method of claim 10 , wherein the physical erase actuator comprises a biometric reader to sense a biometric feature of a user, and the method comprises:
authorizing, by the discrete secure erase hardware logic, the erasing of the collection of encryption keys based on the biometric feature sensed by the biometric reader.
14 . The method of claim 10 , wherein the erasing of the collection of encryption keys in the nonvolatile memory is performed while an auxiliary power voltage to the security chip is activated and a primary power supply to the collection of device processors is off.
15 . The method of claim 10 , wherein the physical erase actuator comprises a receptacle to receive a peripheral device to plug into a physical port of the security chip, and wherein the erase indication is based on the peripheral device being plugged into the physical port of the security chip.
16 . An electronic device comprising:
a physical erase actuator;
an erase indicator;
an auxiliary power supply;
a collection of device processors; and
a security chip separate from the collection of device processors and powered by the auxiliary power supply while a primary power voltage to the collection of device processors is off, the security chip comprising a discrete secure erase hardware logic to, while the collection of device processors is disabled by the primary power voltage being off:
enable the discrete secure erase hardware logic to perform an erase of the collection of encryption keys based on an indication of a physical containment structure of the electronic device being unlocked;
receive an erase indication activated by a user and indicating a request to erase encrypted information in a persistent memory, the encrypted information encrypted using a collection of encryption keys in a nonvolatile memory of the security chip, the erase indication provided based on physical user interaction with the physical erase actuator,
in response to the erase indication and the discrete secure erase hardware logic being enabled based on the indication of the physical containment structure being unlocked, erase the collection of encryption keys in the nonvolatile memory, and
activate an output indication provided from the security chip to cause activation of the erase indicator of the electronic device.
17 . The electronic device of claim 16 , wherein the erase indicator is selected from among a visual indicator, an audio indicator, or a tactile indicator that can be sensed by the user when in a proximity of the electronic device.
18 . The electronic device of claim 16 , wherein the erasing of the collection of encryption keys results in erasing of the encrypted information belonging to a tenant of an infrastructure provider that provides the electronic device.
19 . The electronic device of claim 16 , wherein the physical erase actuator comprises a biometric reader to sense a biometric feature of a user, and the discrete secure erase hardware logic is to authorize the erasing of the collection of encryption keys based on the biometric feature sensed by the biometric reader.
20 . The electronic device of claim 16 , wherein the physical erase actuator comprises a receptacle to receive a peripheral device to plug into a physical port of the security chip, and wherein the erase indication is based on the peripheral device being plugged into the physical port of the security chip.