Data Sanitization & the Circular Economy

Enabling the Circular Economy for a Storage Device - Remove barriers through the use of "Purge Media Sanitization".

Sanitization to unlock Circularity for Storage

Technology is driving globalization and the available data about customers, products, and services. With this increased amount of data comes great responsibility, and every organization is liable to protect proprietary and personally-identifying information of their customers, products, and services.

As a result, organizations go to great lengths to secure sensitive data, and fundamental to any cloud service provider's business is the customer's promise that their data is secure in the cloud. It is, therefore, common to physically destroy data-bearing devices (DBDs) such as hard disk drives and solid-state drives, despite the advanced encryption and security features built into the device.

By understanding what steps to take, a functioning drive can be made safe for internal or external reuse, and a non-functional drive still needs to be secured to make data unrecoverable. If you ask many people what they would do to sanitize their data, they may say, “just format the drive.” If the drive is broken, they may say “I'll just dispose of it”. In both cases they don't have enough knowledge to make an informed decision. There are different options for formatting a drive, many of which still leave data remaining physically on the drive. If the drive isn't working, there are various forensic methods that can be used to recover data from non-functional HDDs and SSDs. Data Destruction is intended to prevent unauthorized access to the storage media, but physical destruction alone in many cases is not fully secure. There are secure methods of making data recovery infeasible, including encryption and sanitization capabilities already built into the drives themselves.

Core Asset Solutions ITAD services equipment processing

Media Sanitization Standards

IEEE 2883 Standard for Sanitizing Storage is the latest international standard that defines sanitization methods and techniques, adopted by NIST SP800-88r2.

Sanitization Methods

Sanitization: A process or method to render access to target data on storage media infeasible for a given level of effort.

  • Clear: Uses logical techniques to remove data on all addressable storage, preventing simple non-invasive data recovry.
  • Purge: Uses logical or physical techniques to remove all data. Infeasible data recovery with state of the art techniques.
  • Destruct: Infeasible data recovery with state of the art techniques. Leaves devices in an unusable state. Disintegrate, incinerate, melt.

Purge Sanitization Techniques

Purge sanitize uses logical techniques or physical techniques that make the recovery of target data infeasible using state-of-the-art laboratory techniques, but that preserves the storage media and the storage device in a potentially reusable state.

  • Sanitize Purge Cryptographic erase (CE) will change the media encryption key on a device, typically today AES256, which is not only a secure way to sanitize a device but also happens in seconds
  • Sanitize Purge Overwrite securely overwrites the storage media with various patterns that can be verified later. Overwrite can be used with hard drives that don't support CE
  • Sanitize Purge Block Erase can zero out the erase blocks on NAND based SSDs, and can be used in conjunction with CE
Core Asset Solutions facility operations
Core Asset Solutions compliance standards

Reuse Storage with Purge Media Sanitization

Extending the first use is very important for minimizing the percentage of the LCA carbon and materials impact for the use phase vs everything else (manufacturing, distribution, etc.) HDDs and SSDs generally have a 5 year warranty but are swapped out every 3-5 years. Reuse has the largest carbon impact and value recovery for circularity. Purge sanitization is the best for reuse since it prevents data recovery and leaves the device in a usable state. There are multiple methods for purge, which depend on the drive model and firmware for support. Cryptographic erase, which some vendors call Instant Secure Erase (ISE), uses AES-256 data encryption to scramble the data in seconds cryptographically. AES-256 is considered to be quantum compute resistant by the NSA and other governmental agencies and standards groups. For highly sensitive data where a "steal now, de-encrypt decades later" is considered plausible, third-party verified sanitize overwrite technology is an option that takes approximately one hour per terabyte to complete on a modern HDD. Solutions exist for doing this inside a data center or facility in economically viable ways.

Recycling of Hard Drive Materials

If drives must be destroyed, it is best to disassemble and separate the materials prior to shredding the media in order to maximize the recyclability and avoid downcycling. Most recycling methods today shred the entire drive, which mixes all the materials together, and focus on recovering aluminum which is only a small fraction of the recycling potential in terms of value and environmental impact. The most critical resource to recover is the rare earth neodymium magnet. Value recovery of recycling components on hard drives has been well studied

Verified custody record stamp on metal plate
Core Asset Solutions data destroyed badge

GHG Accounting for Circular Business Models

The impact for extending the use can be in a reduction in a company's scope 3 emissions. The company can also reduce the impact of the EOL phase in an LCA if the device gets reused. Since a large percentage of the carbon in an SSD LCA comes from pre-use (manufacturing, specifically the NAND flash) extended use will offer a large reduction by amortizing that carbon over a larger period of time. A longer first use also means that companies will have to purchase less equipment, reducing the scope 3 emissions for purchased goods and services.

Emissions Impact Reuse vs Recycling

Reusing raw materials is a step towards circularity, but the value recovery and carbon impact from giving the drive a second and/or third has been proven to be vastly more impactful, up to 275 times compared to recycling. Safe media sanitization with a purge can ensure data does not get into the wrong hands while enabling the circular economy for storage.

When a company is done using its IT equipment, including the storage devices contained within, it is important to render the data inaccessible. At the end of first use, destroying the storage device is common practice to eliminate any perception of risk. Other sanitization methods are available that leave the device in a reusable state, while still eliminating risk of recovering any user data.

Verified custody record stamp on metal plate
Desktop motherboards in crate handled by worker

Encryption and Cloud Computing has been trusted for years

Privacy is not only a fundamental human right but essential to enterprise needs. With massive growth of cloud computing and storage, it is safe to say that there is already a considerable amount of trust in today's security and encryption technologies. So why does this suddenly break down when a device is leaving organizational control? When a device is at the end of its first use?

The shift to cloud computing has made companies' workloads and data more agile, scalable, and cost-effective. This required a tremendous amount of trust from the cloud service providers and did not happen overnight. These CSPs promise trust in the technology, operations, policies, and industry collaboration. Technology has delivered strong encryption protocols that protect user content by securing data at rest and in flight. Data at rest security uses encryption, e.g. self-encrypting drive or Microsoft BitLocker, to protect against the very unlikely scenario of someone obtaining physical access to a device. Data in-flight security is done to prevent unauthorized parties from eavesdropping with internet technologies like TLS.