A high-efficient and safe personal information multi-copy deletion method and system
By using a method that transfers information between information domains and verifies it based on signatures, the problem of information leakage caused by communication failures during the deletion of multiple copies of personal information is solved, achieving comprehensive information deletion and system simplification.
Patent Information
- Application Number
- CN202310330141.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-30
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2043-03-30
AI Technical Summary
Existing technologies for deleting multiple copies of personal information suffer from communication failures that cause some platforms to fail to delete copies in a timely manner, leading to information leakage and illegal use. Furthermore, existing solutions increase system complexity and implementation costs.
By circulating copies of personal information between information domains and signing and verifying them based on the personal information subject identifier, combined with storage, circulation, access, and deletion protocols, the timely deletion and irreversibility of all copies are ensured.
It enables comprehensive deletion of personal information, ensuring that the information cannot be recovered, reducing system complexity and dependence on third parties, and protecting the data subject's right to delete and intellectual property rights.
Smart Images

Figure CN116346364B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of cloud storage security technology, and in particular to an efficient and secure method and system for deleting multiple copies of personal information. Background Technology
[0002] To improve the user experience for data subjects, companies may share data subjects' personal information with other internet service platforms or other departments within the same company, resulting in associated copies of the personal information on these platforms or within these departments. When a data subject requests deletion, the company needs to delete these multiple copies to prevent leakage or illegal use of the deleted personal information, thus achieving the goal of protecting personal information after deletion. However, when a data subject requests the deletion of personal information and its corresponding copies on a platform or from the initial data uploader, unexpected situations such as communication quality issues or system lag may prevent a platform sharing the personal information from receiving the deletion request in a timely manner. Consequently, the platform may not delete the personal information copy as expected, but the data subject may not be aware of this failure, potentially leading to problems such as personal information leakage and illegal use.
[0003] Curtmola et al. first proposed a provably secure directory structure for recording multiple copies of information, but this work did not actually consider the problem of integrity deletion of multiple copies. Du et al. proposed an encryption scheme called ADM, which can reduce the key management overhead while realizing multiple copy deletion, and ensure the integrity and verifiability of multiple copies through key outsourcing technology.
[0004] Zhang et al. constructed a multi-copy association model and deletion feedback mechanism, ensuring that when the original file is deleted, its associated copies stored in the copy directory are also deleted, effectively solving the problem of multiple copies being unable to be associated for deletion during storage or sharing. Tian et al. and Xiong Jinbo et al. proposed a secure multi-copy deletion scheme to address the privacy leakage problem of multiple copies in shared cloud environments. Wang Weihua of Hubei University and Liu Xinzhong of the University of Electronic Science and Technology of China proposed a multi-copy association deletion scheme for cloud storage by mining the association rules of multiple copies. This scheme feeds back a list of files associated with the content of the file to be deleted to the personal information subject, allowing for file copy filtering based on needs, thereby assisting the personal information subject in achieving the goal of multi-copy deletion. Because most deletion schemes are designed based on cryptographic techniques, their goal is almost always to ensure that the encrypted personal information is unreadable and unrecoverable, rather than deleting the personal information itself; the encrypted information is still stored.
[0005] In summary, how to achieve the associated deletion of multiple copies of personal information and to perform full deletion of multiple copies of personal information according to the needs of the personal information subject are important issues we currently face. Therefore, we need to propose efficient methods to solve these problems.
[0006] In existing technologies, such as the secure association deletion method proposed in patent document CN111092847A, the data owner first encrypts the data and then encapsulates it into incomplete ciphertext copy association objects and ciphertext extraction and key objects. This is then shared with a cloud service provider via ICRAO, while CESKO uses ABE attribute-based encryption. The data is then distributed to the DHT network through key sharing, and the data owner maintains it during the data's validity period. Simultaneously, a copy association model is established to manage the copies generated during ICRAO migration and to achieve multi-copy association deletion. This existing technology uses cryptographic techniques for multi-copy deletion, such as increasing the number of keys to manage different copies. However, this method easily increases system complexity, and the integrity and verifiability of the copies cannot be guaranteed.
[0007] Existing technologies, such as the cloud data multi-copy integrity verification and associated deletion method and cloud storage system proposed in patent document CN108418796B, involve users randomly generating data keys to encrypt file copies, and simultaneously encrypting the data keys with a control key issued by a trusted third party. The keys and encrypted files are then outsourced to the cloud while ensuring security. A cloud file multi-copy association table is created, and a cloud data integrity verification and associated deletion strategy combining a Merkle hash verification tree and a user-pre-specified random deletion sequence is employed. This existing technology also uses cryptographic techniques for multi-copy deletion, increasing the number of keys to manage different copies, thus increasing system complexity. Furthermore, the integrity and verification of the deletion strategy require third-party participation. In addition to the information owner and user, extra resources are needed for data communication with the third party, and the introduction of the third party itself also consumes additional resources. Therefore, the implementation cost of this existing technology is significantly increased.
[0008] Furthermore, on the one hand, there are differences in understanding among those skilled in the art; on the other hand, the inventors studied a large number of documents and patents when making this invention, but due to space limitations, not all details and contents were listed in detail. However, this does not mean that the present invention does not possess the features of these prior art. On the contrary, the present invention already possesses all the features of the prior art, and the applicant reserves the right to add relevant prior art to the background art. Summary of the Invention
[0009] To address the shortcomings of existing technical solutions, this application proposes an efficient and secure method for deleting multiple copies of personal information. The method provides several information domains. The method includes signing personal information and a personal information subject identifier and uploading the signed information to each information domain, where the information domain stores the signed personal information as a copy. These copies circulate among the information domains, each copy recording its source and purpose. When an information domain receives a deletion command, it transmits the command to each information domain based on the personal information subject identifier and the purpose information in the copy, and performs the deletion operation. After completing the deletion, each information domain stores its own domain identifier and the received feedback information in a log, and then sends the log back to the next higher-level information domain.
[0010] Because the collection of personal information in the real-world network environment lacks a strict regulatory mechanism, there are a lot of secondary processing situations during the period when personal information is handed over to the platform for use. This means that even if the personal information subject applies to delete personal information, it cannot be guaranteed that all shared copies of the information and other personal information derived from it can be completely deleted, let alone that the deleted items will not be restored and reused by the cloud platform.
[0011] The solution proposed in this application allows individuals to request the deletion of relevant information from a data processor, ultimately achieving complete deletion of the personal information. This means that the deleted information should be irrecoverable by any other data subject or processor, and it should be impossible to deduce any historical information from the final deleted state. Furthermore, any other copies generated based on this information should also be deleted upon request. This is not only crucial for protecting the right to deletion of personal information but also for safeguarding the intellectual property rights of data subjects in most practical application scenarios.
[0012] In addition, each information domain records the source, purpose, and logs of personal information, enabling the traceability of the generation and dissemination of each copy, so as to accurately control the deletion of the corresponding copy and determine whether personal information remains after deletion.
[0013] Preferably, the method enables the sharing, deletion, and verification of multiple copies of personal information based on storage protocols, transfer protocols, access protocols, and deletion and evidence preservation protocols configured within the information domain.
[0014] According to a preferred embodiment, the storage protocol includes:
[0015] Signature: A digital signature is obtained by performing a hash calculation based on personal information and the personal information subject identifier, and then using the personal information subject's private key to perform a signature operation on the calculated hash value; among which, the personal information subject identifier serves as a globally unique identifier.
[0016] Preferably, the storage protocol further includes:
[0017] Upload: The personal information subject uploads the personal information subject identifier, personal information, and digital signature to the information source domain; wherein, the personal information copy backed up in the information source domain stores at least the personal information subject identifier, personal information, digital signature, source domain identifier, and destination domain identifier, and the source domain identifier and destination domain identifier are initialized to empty; wherein, the source domain identifier stores the identifier of the next higher level information domain from which the current information copy flows; the destination domain identifier stores the identifier of the next lower level information domain into which the current information copy flows.
[0018] According to a preferred embodiment, the transfer protocol includes:
[0019] Request: The current propagation domain requests a backup copy of the personal information from the superior domain based on the personal information subject identifier, and modifies the source domain identifier and destination domain identifier in the personal information copy backed up to the current propagation domain. Specifically, the source domain identifier is modified to the identifier of the superior domain, and the destination domain identifier is reset to empty.
[0020] Feedback: The current propagation domain sends the destination domain identifier and its own domain identifier from the modified copy of the personal information to the parent domain. The parent domain updates its copy of the personal information based on the feedback from the current propagation domain.
[0021] Preferably, the transfer protocol further includes:
[0022] Update: The process of updating the personal information copy based on the feedback content of the current propagation domain is as follows: the destination domain identifier is added with a domain identifier that exists in the feedback content but does not exist in the destination domain identifier;
[0023] Repeat the feedback and update steps until the information source domain is updated.
[0024] According to a preferred embodiment, the access protocol includes:
[0025] Download: The current propagation domain downloads the desired copy of the current information based on the personal information subject identifier;
[0026] Verification: The current propagation domain performs a preliminary parsing of the current information copy to obtain a digital signature, and selects the expected public key based on the personal information subject identifier to verify the digital signature;
[0027] Desig: If the verification is successful, the current propagation domain desigs the current copy of the information to obtain personal information.
[0028] According to a preferred embodiment, the deletion and evidence preservation protocol includes:
[0029] Deletion Request: The personal data subject sends a deletion command to the information source domain. The information source domain determines the copy of the personal data to be deleted based on the personal data subject's identifier, and then sends a deletion command to the directly associated information domain based on the destination domain identifier of the personal data copy.
[0030] Deletion: When the current propagation domain receives a deletion request, it determines the current information copy to be deleted based on the personal information subject identifier, and issues a deletion command to the directly associated information domain based on the destination domain identifier of the current information copy. After issuing the deletion command, the current information copy is deleted.
[0031] Preferably, the deletion and evidence preservation protocol also includes log evidence preservation, which is configured as follows: if the target domain identifier of the current propagation domain is empty, the current propagation domain stores the personal information subject identifier and its own domain identifier in the log; if the target domain identifier of the current propagation domain is not empty, the current propagation domain stores the personal information subject identifier, the domain identifier of the current propagation domain, and the domain identifier recorded in the evidence preservation log fed back to the current propagation domain by the lower-level domain in the log.
[0032] Preferably, after the current propagation domain completes the log storage, it uses the private key of the current propagation domain to sign the storage log and sends the signed storage log back to the upper-level domain; the upper-level domain uses the private key of the current propagation domain to design the storage log to obtain the domain identifier in the log sent back by the current propagation domain.
[0033] This application also proposes an efficient and secure system for deleting multiple copies of personal information, comprising several information domains configured to have at least the following protocols:
[0034] The storage protocol signs personal information and personal information subject identifiers, uploads them to the information domain, and stores them as a copy of the personal information in the information domain;
[0035] A transfer protocol is provided in which copies of the personal information are transferred between the information domains, and each copy of the personal information records its source and purpose.
[0036] An access protocol is used by the information domain to verify and access copies of personal information based on the personal information subject identifier;
[0037] The deletion and evidence preservation protocol stipulates that when an information domain receives a deletion command, it transmits the deletion command to each information domain based on the personal information subject identifier and the purpose information in the personal information copy, and performs the deletion operation; after completing the deletion, the information domain stores its own domain identifier and the received feedback information in the log, and feeds the log back to the next higher-level information domain. Attached Figure Description
[0038] Figure 1 This is a simplified structural diagram of the storage procedure of the present invention;
[0039] Figure 2 This is a simplified structural diagram of the associated copy transfer process according to a preferred embodiment of the present invention;
[0040] Figure 3 This is a simplified structural diagram of the associated copy access process according to a preferred embodiment of the present invention;
[0041] Figure 4 This is a simplified structural diagram of the associated copy deletion process according to a preferred embodiment of the present invention;
[0042] Figure 5 This is a simplified structural diagram of the associated copy transfer process of another preferred embodiment of the present invention;
[0043] Figure 6 This is a simplified structural diagram of the associated copy access process according to another preferred embodiment of the present invention;
[0044] Figure 7 This is a simplified structural diagram of the associated copy deletion process according to another preferred embodiment of the present invention. Detailed Implementation
[0045] The present invention will now be described in detail with reference to the accompanying drawings.
[0046] Example 1
[0047] This application proposes an efficient and secure method for deleting multiple copies of personal information. It provides several information domains, a storage protocol for signing personal information with a personal information subject identifier and uploading it to the information domains, a transfer protocol for transferring copies of personal information between information domains and recording the identifiers of the transferred information domains in the personal information copies, an access protocol for information domains to verify and access personal information copies based on the personal information subject identifier, and a deletion and evidence storage protocol for performing personal information copy deletion operations and storing the deletion operation records. Based on the storage protocol, transfer protocol, access protocol, and deletion and evidence storage protocol, it achieves multiple copy sharing, associated deletion of multiple copies, and associated deletion verification of personal information.
[0048] The method for deleting multiple copies of personal information in this application is designed to store a copy of personal information in each information domain during the sharing, backup, and transfer of multiple associated copies. This facilitates subsequent associated deletion of personal information copies stored in each information domain and verification of whether personal information copies have been deleted across all information domains. Preferably, according to Figure 1The simplified structural diagram of the multi-copy association deletion method based on this application is shown. For a specific personal information subject, the information field D that first receives the copy of personal information uploaded by the personal information subject is denoted as the information source field D0 of that personal information subject, and the other information fields D are denoted as the propagation fields D. i (i>0).
[0049] Preferably, for the personal information copy of the personal information subject, the personal information copy packaged by the personal information subject is called the personal information source copy. The personal information source copy that is uploaded to the information source domain and saved by the information source domain is called the initial personal information copy, denoted as File0. The personal information copy obtained by the propagation domain is marked according to the sequence number of the propagation domain itself. For example, the personal information copy stored in the propagation domain D9 is denoted as File9.
[0050] According to a preferred embodiment, the storage protocol includes at least a signature() function and an upload() function.
[0051] Preferably, the UserID, the personal information subject identifier, can be determined by the personal information subject based on their personal information, or it can be randomly selected by the information field of this application for the personal information subject.
[0052] Preferably, in this embodiment, the globally unique identifier is configured as the personal information subject identifier UserID. In this case, the signature Signature() is configured as follows:
[0053] Signature(Hash(UserID||Data), SK)→Sig: The personal information subject performs a hash operation on the personal information and the personal information subject identifier UserID based on a hash algorithm to obtain the hash value Hash(UserID||Data); the personal information subject uses its own private key SK to perform a signature operation on the calculated hash value Hash(UserID||Data) to obtain the digital signature Sig about the personal information and the personal information subject identifier UserID.
[0054] Specifically, encryption algorithms currently mainly include asymmetric encryption algorithms, hash algorithms, and symmetric encryption algorithms; among them, the SM3 hash algorithm is the main hash algorithm, while the signature algorithm used in the signature process is the asymmetric encryption algorithm SM2.
[0055] Preferably, the source domain identifier Sour is as follows: personal information will flow between different information domains, and the transmission domain will request a copy of the personal information from its associated upper-level information domain. For a specific propagation domain, the propagation domain is the current propagation domain, and its upper-level information domain is the source domain of the current propagation domain. The domain identifier of the source domain is denoted as the source domain identifier Sour.
[0056] Preferably, the destination domain identifier Des is as follows: personal information will flow between different information domains, and the transmission domain will request a copy of the personal information from its associated upper-level information domain. For a specific transmission domain, the transmission domain is the current transmission domain, and the transmission domain that requests a copy of the personal information from the current transmission domain is the destination domain of the current transmission domain. The domain identifier of the destination domain is denoted as the destination domain identifier Des.
[0057] Furthermore, the specific configuration for Upload() is as follows:
[0058] Upload(UserID, Data, Sig): The personal information subject transmits the personal information subject identifier UserID, personal information Data, and digital signature Sig to the information source domain D0. The information source domain D0 saves the above information as an initial copy of the personal information File0 based on the source domain identifier Sour and the destination domain identifier Des.
[0059] Preferably, the initial copy of personal information File0 includes: personal information subject identifier UserID, personal information Data, digital signature Sig, source domain identifier Sour, and destination domain identifier Des, wherein the source domain identifier Sour and the destination domain identifier Des are initialized to empty.
[0060] Preferably, under normal circumstances, for each current propagation domain, its source domain identifier Sour records only one domain identifier, while the destination domain identifier Des records the domain identifiers of all propagation domains subordinate to the current propagation domain.
[0061] Preferably, under normal circumstances, the source domain identifier Sour in the information source domain is denoted as NULL, and it possesses a source domain.
[0062] Preferably, under normal circumstances, the destination domain identifier Des in the current propagation domain that does not have a next-level current propagation domain is denoted as NULL.
[0063] According to a preferred embodiment, the transfer protocol includes at least the steps of request(), feedback(), and update().
[0064] Preferably, in this embodiment, based on the above, for a specific propagation domain, this propagation domain is denoted as the current propagation domain D.i , to the current propagation domain D i The source domain is denoted as D i-1 , to the current propagation domain D i Let D be a target domain at the next level. i+1 Therefore, as Figure 2 The diagram shown illustrates a preferred embodiment of the copy sharing process, where the Request() and Feedback() functions are specifically configured as follows:
[0065] Request(UserID): Current propagation domain D i Based on source domain D i-1 Copy and back up a copy of the personal information of the Personal Information Subject Identifier (UserID) File i-1 Save and update the relevant information and store it in the current propagation domain D. i In the node, it is stored as a File i Current propagation domain D i File of personal information i The Personal Information Subject Identifier (UserID), Personal Information (Data), and Digital Signature (Sig) in the document are related to the Source Domain (D). i-1 File of personal information i-1 Maintain consistency; the source domain identifier Sour is reset to D. i-1 The target domain identifier Des is reset to NULL;
[0066] Feedback(UserID, D) i ): Current propagation domain D i Complete the copy of personal information File i After storage, the current propagation domain D i Feedback its own domain identifier and destination domain identifier Des to the source domain D. i-1 The source domain D that received the feedback information i-1 Call the Modify() algorithm update function and perform related operations;
[0067] UpdateModify(UserID,DA i ,Des′): Source domain D i-1 File of his personal information i-1 Update the destination domain identifier Des in the table, Des = Des + Des", Des″ = (Des′∪DA) i )-Des, where Des is the source domain D i-1 The destination domain identifier is Des, and Des′ is the current propagation domain D. i The destination domain identifier Des′, DA iFor the current propagation domain D i The self-domain identifier, DeS″, exists in the set (Des′∪DA). i (and not the set of field identifiers that exist in the set Des.)
[0068] According to a preferred embodiment, the access protocol includes at least the steps of Download(), Verify(), and Decapsulate().
[0069] Preferably, when the propagation domain accesses a copy of the personal information of the personal information subject, it parses the copy to obtain a signature and uses the personal information subject's public key to verify the signature; if they match, the verification passes, otherwise it is invalid.
[0070] Preferably, in this embodiment, based on the foregoing content, such as Figure 3 The diagram shown illustrates the access flow under a preferred embodiment of this invention. The specific algorithm configuration in the access protocol is as follows:
[0071] Download (UserID): Current propagation domain D i Download the desired copy of personal information (File) based on the UserID (Personal Data Subject Identifier). i ;
[0072] Verify(File) i ): Current propagation domain D i File for personal information i When making an access, the current propagation domain D i File containing personal information i The digital signature Sig is obtained by parsing and then verified using the public key PK of the personal information subject.
[0073] Decapsulate(File) i Verify(File) i After the algorithm verification is passed, the current propagation domain D i File for personal information i The process of decryption ultimately yields personal information (Data).
[0074] According to a preferred embodiment, the deletion and evidence preservation protocol includes at least the following steps: deletion request DelReq(), deletion Del(), deletion evidence preservation DelRecord(), and evidence preservation feedback DelFeedback().
[0075] Preferably, in this embodiment, log storage is taken as an example, such as... Figure 4The diagram shown illustrates a preferred embodiment of the deletion and deletion evidence storage process, with the following specific configuration:
[0076] Deletion request DelReq(UserID, Des, File0): The personal information subject sends a deletion request. After receiving the deletion request, the information source domain D0 sends a deletion request to the propagation domain directly associated with the destination domain identifier Des based on the personal information subject identifier UserID and the destination domain identifier Des, and then deletes the personal information copy File0 in the information source domain D0.
[0077] Delete Del(D) i Des, File i ): The propagation domain D that received the deletion request i (i>0) will send a deletion request to the destination domain directly associated with the destination domain identifier Des, and then delete the personal information copy File. i Repeat the above steps until the current propagation domain D is reached. i The destination domain identifier Des is empty;
[0078] Delete the stored evidence DelRecord(UserID, DA) i Dlist): Current propagation domain D i (i>0) After deletion is complete, the personal information subject identifier UserID and the self-domain identifier DA will be deleted. i The domain identifier DList from the signature content received from the lower level is saved in the form of a log. If the current propagation domain D... i If the destination domain identifier Des = NULL, then the current propagation domain D i The log content is DA i ||UserID; if the current propagation domain D i The destination domain identifier is not empty, and the current propagation domain D is... i Will receive from destination domain D i+1 Log feedback, utilizing the target domain D i+1 If the public key is used to decrypt the signature and obtain the feedback log DList||UserID, then the current propagation domain D is... i The log content of the evidence storage is DA i ||DList||UserID. Next, DelFeedback() is called for further operations;
[0079] DelFeedback(): After the log evidence storage is completed, each domain signs the log content and sends it back to the parent domain; in particular, this operation is not required for the personal information source domain D0.
[0080] Preferably, after the deletion operation is completed, each domain will save the corresponding data structure information as an operation log to facilitate subsequent evaluation and auditing of the deletion operation. Each propagation domain will sign the log content and send it back to the associated parent domain. The parent domain will verify the signature upon receipt, thereby ensuring the reliability of the log source.
[0081] Example 2
[0082] This embodiment is an improvement and supplement to Embodiment 1. Repeated content will not be repeated. Specifically, in this embodiment, the globally unique identifier is configured as the digest value of the personal information Data, that is, the globally unique identifier is configured as the logical file name LFN of the personal information Data; the information domain identifier in this embodiment is configured as the address of the information domain, and the information stored in the source domain identifier is the source address PLSA, and the content stored in the destination domain identifier is the destination address DA, wherein the destination address is added to the destination address list AddList1; the deletion evidence method in this embodiment is configured as address list evidence storage, wherein, in the address list evidence storage process, the information domain address after deletion is added to the deletion address list AddList2, the specific content of which is as follows.
[0083] This embodiment describes an efficient and secure method for deleting multiple copies of personal information according to another preferred embodiment of this application. The method includes:
[0084] Provide a secure and reliable information domain D;
[0085] The data subject encapsulates the personal data (Data) and uploads the encapsulated personal data (File') to the data source domain (D0);
[0086] Different propagation domains D i By sharing a copy of personal information (File) i To access the personal information data of the data subject;
[0087] Each propagation domain D i All will record a copy of personal information File i The source address PLSA and destination address DA, each propagation domain D i Upon receiving a copy of personal information (File) i It will then go to the next higher source domain D. j Feedback of its own address, each source domain D j Received the next level of propagation domain D i When providing feedback, the destination address list AddList1 will be modified;
[0088] When a personal information subject initiates a file copy of personal information iDelete request, propagation domain D i According to the stored destination address list AddList1, propagation domain D in destination address list AddList1 is... i Send a delete request;
[0089] Each propagation domain D i File for personal information i After deletion, the address of itself and the next-level propagation domain D will be deleted. i The returned addresses are encapsulated into a deletion address list AddList2 and returned to the parent source domain D. j ;
[0090] After deletion is complete, the source domain D0 will compare the destination address list AddList1 with the deletion address list AddList2. If the comparison results are the same, it indicates that the personal information copy File... i Complete deletion.
[0091] This invention provides a function to protect the personal data subject's right to delete information. That is, when personal data is authorized by a third party, resulting in multiple copies of personal data being shared, the information copies shared with the third party can be completely deleted when the personal data subject requests deletion.
[0092] Preferably, for a specific personal information subject, the information field D that first receives a copy of the personal information uploaded by that personal information subject is denoted as the information source field D0 of that personal information subject, and the other information fields D are denoted as the propagation fields D0. i (i>0).
[0093] Preferably, for the personal information copy of the personal information subject, the personal information copy that is packaged by the personal information subject and uploaded to the information source domain and then saved by the information source domain is called the initial personal information copy, denoted as File0. The personal information copy obtained by the propagation domain is marked according to the sequence number of the propagation domain itself. For example, the personal information copy stored in the propagation domain D9 is denoted as File9.
[0094] Preferably, the secure and reliable information domain includes the information source domain D0 and the propagation domain D under the information source domain D0. i .
[0095] Preferably, the personal information subject, the information source domain D0, and the dissemination domain D i It is secure and trustworthy. The personal information subject is the creator of the source personal information Data, and is absolutely trustworthy; the information source domain D0 and the dissemination domain D... i They will not proactively disclose their private keys or personal information (Data) obtained during the transfer process. Propagation Domain D iBetween, between the information source domain D0 and the personal information subject, and between the information source domain D0 and the dissemination domain D i The communication between them is secure and reliable. They have a pre-defined secure communication protocol that can recognize the message commands communicated between them and execute corresponding operations.
[0096] According to a preferred embodiment, according to Figure 5 The diagram shown illustrates a simplified process for the storage and transfer of personal information in a preferred embodiment of this practice. The personal information subject encrypts and encapsulates their personal information (Data) into a source file (File′ = {Data, LFN, Sig, PK}), and uploads the encrypted source file (File′) to the information source domain D0. Subsequently, the information source domain D0 creates a backup copy or a transferred copy of File′ (i.e., a backup copy of the personal information, denoted as the personal information copy File). i Record the relevant information; Propagation domain D i Download Personal Information (File) i Then, a parsing operation is performed to verify the copy of the personal information (File). i Whether it is trustworthy ultimately determines whether personal information (Data) can be obtained.
[0097] Preferably, the personal information copy File' stores personal information Data, logical file name LFN, digital signature of the personal information subject, and public key of the personal information subject.
[0098] Preferably, the personal information data refers to the identity information data created by the personal information subject.
[0099] Preferably, the logical filename LFN is a digest value of the personal information data calculated by the personal information subject using a hash algorithm. This digest value is determined by the personal information data. For different personal information subjects, their personal information data is different, and therefore the logical filename LFN is different. In other words, for a personal information subject, the logical filename LFN is the same across all copies of personal information on the entire network. That is, the logical filename LFN serves as a globally unique identifier for all copies of personal information stored in different propagation domains. More precisely, the logical filename LFN = Hash(Data), where Hash(Data) is the hash value of the personal information data calculated using a hash algorithm. Optionally, the specific algorithm for calculating the hash value can be the SM3 algorithm.
[0100] Preferably, the digital signature of the personal information subject is obtained by the personal information subject digitally signing the hash value of the personal information data using the personal information subject's private key SK. Optionally, the personal information subject may use the SM2 algorithm to sign the hash value of the personal information data to obtain the personal information subject's digital signature.
[0101] Preferably, the public key PK is set by the personal information subject. The public and private keys are essentially paired; that is, during encryption / decryption or digital signature and designing processes, the personal information subject sets a public-private key pair (PK, SK). The private key is stored by the personal information subject, and the public key is shared with the information source domain D0 and various propagation domains D. i In this application, the public key is primarily used to design the hash value of the signed personal information Data to obtain a digest of the personal information Data.
[0102] According to a preferred embodiment, each personal information copy File i The system records relevant information about the original personal information file, File', including personal information Data, logical file name LFN, digital signature Sig, and public key PK. It also adds the source address PLSA of the previous level of the personal information copy and the destination address DA of the next level of the personal information copy.
[0103] Preferably, both the source address and the destination address are recorded as addresses of information domains. Specifically, for a given information domain (the current propagation domain), the next-level information domain from which a copy of personal information is obtained is called the source domain, and the source address records the address of that source domain. For the same information domain, the next-level information domain from which a copy of, backup of, or transmission of personal information is performed is called the propagation domain D. i The destination address records the propagation domain D. i The address.
[0104] Preferably, for copies of personal information with the same logical filename LFN, that is, for copies of personal information of the same personal information subject, typically, a certain information domain has only one source domain, but can have multiple propagation domains D. i In simple terms, each information domain typically obtains a copy of personal information from only one higher-level information domain, and each information domain can legally share copies of personal information with multiple lower-level information domains.
[0105] Preferably, under normal circumstances, after the personal information subject encapsulates the personal information Data into a personal information source copy, it uploads it to the information source domain D0. The information source domain D0 has an initial personal information copy File0. The personal information copy File0 of the information source domain D0 does not have a parent source domain. Therefore, the source address PLSA in the personal information copy File0 of the information source domain D0 is NULL.
[0106] Preferably, under normal circumstances, each information domain can legally propagate to its domain D. iSimilarly, while sharing copies of personal information is possible, there are also certain information domains that do not require sharing copies of personal information with the next level, i.e., there is no next-level propagation domain D. i At this point, the destination address DA in the personal information copy of this type of information domain is NULL.
[0107] According to a preferred embodiment, the destination address DA recorded in the personal information copy File0 in the information source domain D0 includes the addresses of all information domains that share the personal information copy, and the information source domain D0 encapsulates all addresses in the destination address DA and its own address into a destination address list AddList. a And send it to the individual's information subject.
[0108] Preferably, when an information domain shares a copy of personal information with a lower-level domain, the destination address of the personal information copy in that information domain is updated synchronously. When the destination address is updated, the information domain will send the updated destination address back to the source domain at the higher level. The information domain receives the information from the propagation domain D. i After receiving the destination address information, it will compare the received destination address information with its own destination address information, add any addresses not included in its own destination address information to its own destination address information, and report back to the next higher level until the destination address in the personal information copy in the information source domain D0 is updated.
[0109] According to a preferred embodiment, according to Figure 7 The diagram shown is a simplified flowchart of the deletion and deletion evidence process under the preferred embodiment of this example. When a personal information subject issues a request to delete a copy of personal information, the request will be synchronized to all information domains that have copies of the personal information subject. Whenever an information domain completes the deletion command, it adds its own address to the deletion address list AddList2 and feeds back the deletion address list AddList2 to the source domain at the next higher level.
[0110] Preferably, when a deletion request is received from a personal information subject, deletion is initiated from the information field where the destination address DA = NULL, and a deletion address list AddList2 is created from that information field.
[0111] Preferably, each information domain receives all propagation domains D i After the list of deleted addresses is provided, each propagation domain D will be included. iThe deleted address list AddList2 is merged into a new deleted address list AddList2. After the deletion operation is completed, the deleted address is added to the deleted address list AddList2 and reported back to the next higher-level source domain, until the deleted address is deleted and reported back to the information source domain D0. The information source domain D0 also merges the received deleted address list AddList2 and adds its own address to the merged deleted address list AddList2 after the deletion operation is completed. Finally, the information source domain D0 sends the final deleted address list AddList2 to the personal information subject.
[0112] According to a preferred embodiment, after receiving the deleted address list AddList2, the personal information subject compares the deleted address list AddList2 with the destination address list AddList1. If the destination address list AddList1 and the deleted address list AddList2 are the same, it indicates that all copies of personal information have been deleted. If the destination address list AddList1 and the deleted address list AddList2 are different, the personal information subject can specify the information field under the address where the destination address list AddList1 and the deleted address list AddList2 differ to delete the copies of personal information.
[0113] According to a preferred embodiment, each information domain verifies the acquired copy of personal information to ensure that the acquired personal information data has not been tampered with.
[0114] Preferably, the propagation domain D i Download copies of personal information shared from the source domain as needed, based on logical filenames with globally unique identifiers (LFNs).
[0115] Preferably, according to Figure 6 The diagram shown illustrates a simplified process for accessing and verifying a copy of personal information in a preferred embodiment of this invention, with propagation domain D. i When accessing a copy of a data subject's personal information, the process begins by parsing the copy to obtain a signature, which is then verified using the data subject's public key. Specifically, the verification process involves: first, parsing the copy to obtain the data subject's digital signature; then, using the data subject's public key to design the digital signature to obtain a digital digest of the personal information data (its hash value); next, performing the same hash calculation on the copy to obtain a new digital digest; finally, comparing the hash values of the two digests. If they match, the verification is successful; otherwise, it is invalid.
[0116] Example 3
[0117] This embodiment is an improvement and supplement to Embodiments 1 and 2, and repeated content will not be repeated.
[0118] This embodiment also proposes an efficient and secure personal information multiple copy deletion system, including several information domains, which are configured to have at least the following protocols:
[0119] The storage protocol signs personal information and personal information subject identifiers, uploads them to the information domain, and stores them as a copy of the personal information in the information domain;
[0120] A transfer protocol is provided in which copies of the personal information are transferred between the information domains, and each copy of the personal information records its source and purpose.
[0121] An access protocol is used by the information domain to verify and access copies of personal information based on the personal information subject identifier;
[0122] The deletion and evidence preservation protocol stipulates that when an information domain receives a deletion command, it transmits the deletion command to each information domain based on the personal information subject identifier and the purpose information in the personal information copy, and performs the deletion operation; after completing the deletion, the information domain stores its own domain identifier and the received feedback information in the log, and feeds the log back to the next higher-level information domain.
[0123] Preferably, the information domain of this system refers to the organization that autonomously decides the processing purpose and processing method in personal information processing activities (including the collection, storage, use, processing, transmission, provision, disclosure, and deletion of personal information). Specifically, the information domain can be understood as the server that collects, stores, uses, processes, transmits, provides, discloses, and deletes personal information.
[0124] Preferably, the information domains of this system are equipped with at least a personal information copy storage and management module with storage, transfer and access protocols, and a log retention module with deletion and evidence preservation protocols. The reception or transmission of signals between the information domains is achieved through wireless communication.
[0125] Preferably, this system can be specifically applied between Internet companies or within a company.
[0126] In real-world scenarios, when individual users, as the subjects of personal information, use social media software, they authorize the corresponding social media software to access their personal information. These users, in turn, use third-party software that collaborates with the social media software. In this case, the third-party software can obtain the individual user's personal information through the social media software. For example, Tencent's WeChat and QQ both have third-party information sharing lists. Any third-party platform on this list can unknowingly obtain the personal information subject's authorization, thus enabling multiple copies of the personal information subject's information to be shared.
[0127] Specifically, in the technical solution of this system, social software such as WeChat and QQ, which users log in to through passwords or other verification methods, constitute the information source domain within the information domain. The third-party platforms on the third-party information sharing list constitute the dissemination domain. Social software such as WeChat and QQ, as well as the third-party platforms shared by WeChat and QQ, are collectively referred to as the information domain of this system.
[0128] More specifically, social media platforms such as WeChat and QQ provide interfaces for third-party mini-programs to obtain personal information. With the consent of the data subject, these mini-programs can obtain a specified range of personal information from WeChat, QQ, and other social media platforms. Therefore, WeChat and QQ are the information source domain, and the third-party mini-programs are the dissemination domain.
[0129] For example, within an enterprise, there are usually several servers connected in a tree-like logical structure. When an individual uploads their personal information to the main server, other servers will request the individual's personal information from their superior server. Here, the main server is the information source domain, and the other servers are the propagation domains. The main server and the other servers are collectively referred to as the information domains of this system.
[0130] Based on the preferred embodiment of Example 1, the information domain of this system is configured as follows:
[0131] According to a preferred embodiment, the personal information copy storage and management module of the information domain is equipped with at least a storage protocol, and the storage protocol is configured with at least the following algorithms:
[0132] Signature(Hash(UserID||Data), SK)→Sig: The personal data subject uses a hash algorithm to calculate the hash value Hash(UserID||Data) of the personal data data and the personal data subject identifier UserID, and signs Hash(UserID||Data) using the private key SK to obtain the digital signature Sig. At the same time, the personal data subject identifier UserID is used as a globally unique identifier;
[0133] Upload(UserID, Data, Sig): Requests the upload of the personal data subject identifier UserID, personal data Data, and digital signature Sig to the personal data source domain D0. The personal data source domain D0 then saves these contents, along with the source domain identifier Sour and the destination domain identifier Des, into File0. That is, File0 includes: the personal data subject identifier UserID, personal data Data, signature Sig, source domain identifier Sour, and destination domain identifier Des. Sour and Des are initialized to empty.
[0134] According to a preferred embodiment, the personal information copy storage and management module of the information domain is equipped with at least a transfer protocol, and the transfer protocol is configured with at least the following algorithms:
[0135] Request(UserID): Personal Information Dissemination Domain D i Upward to the parent domain D i-1 Request to retain a copy of the personal information of the UserID (Personal Data Identifier) File i-i Then, save and update the relevant information in this node, storing it as a File. i Specifically, the personal information dissemination domain D i Copy File i-i In the UserID, Data, and Sig fields, update Sour and Des, changing Sour to D. i-1 Des should be changed to empty;
[0136] Feedback(UserID, D) i After the above storage operations are completed, the personal information dissemination domain D... i It feeds back its own domain identifier and destination domain identifier to the parent domain D. i-1 After receiving feedback, domain D i-1 Call Modify to perform the relevant operations. Repeat the above operations until feedback is returned to the source domain D0;
[0137] Modify(UserID, D) i ,DA′): Domain D i-1 For copy File i-1 The destination domain identifier Des′ is modified, that is, a new element existing in set D is added to the destination domain identifier. i VDes′, but not the part Des″ that exists in Des, i.e., Des″=(Des′VD i )-Des. This enables the association of multiple copies of personal information.
[0138] According to a preferred embodiment, the personal information copy storage and management module of the information domain is equipped with at least an access protocol, and the access protocol is configured with at least the following algorithms:
[0139] Download(UserID): Personal Information Domain D i Download a copy of personal information (File) based on the Personal Information Subject Identifier (UserID). i ;
[0140] Verify(File i ): When personal information domain D i File for personal information iWhen accessing the site, the copy is first parsed to obtain a signature, and then the signature is verified using the public key of the personal information subject.
[0141] Decapsulate(File i After the Verify algorithm verifies the information, it designs the copy of the personal information to obtain the personal information data.
[0142] According to a preferred embodiment, the log retention module of the information domain, the deletion and evidence preservation protocol of the information domain require the personal information copy storage and management module and the log retention module to be jointly implemented, and the deletion and evidence preservation protocol is configured with at least the following algorithms:
[0143] DelReq(): When a personal data subject sends a deletion request, the personal data source domain D0 receives the deletion request and, based on the personal data subject identifier UserID and the destination domain identifier, sends a deletion request to the personal data domain directly associated with the destination domain identifier, and then deletes the personal data copy File0.
[0144] Del(): The propagation domain D for each personal information that receives a deletion request. i (i>0) will send a deletion request to the personal information field directly associated with the destination field identifier, and then delete the personal information copy File. i Repeat the above steps until the destination field identifier is empty;
[0145] DelRecord(): Each propagation domain D i (i>0) After deletion is complete, the multi-copy deletion process also needs to be logged. The log content includes the personal information subject identifier UserID, the domain identifier D, etc. i And the domain identifier DList in the signature content received from the lower level. Specifically, the propagation domain D... i After deletion is complete, if the destination domain identifier is empty, then propagate to domain D. i The log content is D i ||UserID; If the destination domain identifier is not empty, the signature fed back from the lower level will be received. The signature is decrypted using the public key of the lower-level propagation domain to obtain DList||UserID. The log content for evidence storage is then Di||DList||UserID. Next, DelFeedback is called for subsequent operations.
[0146] DelFeedback(): After the log storage is completed, each domain signs the log content and sends it back to the parent domain; in particular, this operation is not required for the personal information source domain D0.
[0147] Based on the preferred embodiment of Example 2, the information domain of this system is configured as follows:
[0148] According to a preferred embodiment, during the personal information sharing and storage phase, the information domain has at least the following algorithm:
[0149] Digital signature algorithm: Signature(Hash(Data), SK);
[0150] The upload algorithm is Upload(Data, LFN, Sig, PK);
[0151] Destination address recording algorithm AddRecord(File) i-1 ,PLSA,DA);
[0152] Destination address list update algorithm AddFeedback(PLSA, DA).
[0153] Preferably, the execution process of the digital signature algorithm Signature(Hash(Data), SK)→Sig is as follows: the personal information subject uses the hash algorithm to calculate the hash value Hash(Data) of the personal information Data, and signs Hash(Data) with the private key SK to obtain the digital signature Sig; at the same time, the hash value Hash(Data) is used as its logical file name LFN to ensure that all identical copies of personal information stored in the information domain have a globally unique identifier.
[0154] Preferably, the execution process of the upload algorithm Upload(Data, LFN, Sig, PK) is as follows: the personal information subject uploads a copy of personal information File′ to the personal information source domain D0. File′ includes: personal information Data, logical file name LFN, signature Sig, and public key PK.
[0155] Preferably, the destination address recording algorithm AddRecord(File) i-1 The execution process of PLSA, DA is as follows: The information domain receives a copy of the personal information File. i-1 Afterwards, save and update the relevant information in this node, storing it as a copy of the personal information (File). i Specifically, save a copy (File). i-1 The system stores personal information (Data), logical filename (LFN), digital signature (Sig), and public key (PK), updating the source address (PLSA) and destination address (DA). After storage, it sends its own address back to the parent information domain. Upon receiving the feedback, the parent domain calls AddFeedback to perform relevant operations. (Personal information copy File) iThis includes: personal information (Data), logical file name (LFN), digital signature (Sig), public key (PK), source address (PLSA), and destination address (DA). Specifically, the personal information copy (File') does not contain the source address (PLSA) and destination address (DA), and the source address (PLSA) of the personal information copy (File0) in the source domain (D0) is NULL.
[0156] Preferably, the execution process of the destination address list update algorithm is as follows: the information domain modifies the destination address list, that is, it adds the newly added lower-level information domain address to the destination address list to realize the association of multiple copies of personal information.
[0157] According to a preferred embodiment, during the personal information access verification phase, the information domain has at least the following algorithm:
[0158] Download(LFN) algorithm for shared copy download;
[0159] Verification algorithm Verify(File) i );
[0160] Decapsulate(File) algorithm i );
[0161] Preferably, the execution process of the shared copy download algorithm Download (LFN) is as follows: [The text abruptly ends here, likely due to an incomplete sentence or a formatting error.] i Download a copy of your personal information based on the logical filename LFN. i .
[0162] Preferably, the verification algorithm Verify(File) i The execution process is as follows: when the information domain accesses a copy of the personal information of the personal information subject, it first parses the copy to obtain a signature, and then uses the personal information subject's public key to verify the signature.
[0163] Preferably, the decapsulation algorithm Decapsulate(File) i The execution process is as follows: After the Verify algorithm verifies the information, the copy of the personal information is designed to finally obtain the personal information Data.
[0164] according to Figure 3 The flowchart shown here illustrates the personal information access verification stage of this application, which specifically includes the following steps:
[0165] The execution unit calls the shared copy download algorithm Download(LFN) in the algorithm unit to download a copy of personal information;
[0166] The execution unit first performs a preliminary parsing of the downloaded personal information copy to obtain the encapsulated personal information, digital signature, and public key stored in the personal information copy;
[0167] The execution unit calls the verification algorithm Verify(File) in the algorithm unit. i The system uses the public key stored in the copy of the personal information to design the digital signature and obtain the digest value Hash1 of the personal information; it then uses the same hash algorithm to calculate the digest value Hash2 of the personal information; finally, it compares the digest values Hash1 and Hash2. If Hash1 = Hash2, the verification passes; otherwise, the verification fails.
[0168] If the verification passes, the execution unit calls the decapsulation algorithm Decapsulate(File) in the algorithm unit. i The personal information copy is designed to ultimately obtain the personal information Data.
[0169] According to a preferred embodiment, during the personal information deletion phase, the information field has at least the following algorithm:
[0170] The deletion algorithm is Delete().
[0171] The address indexing algorithm is Search(LFN, DA);
[0172] The algorithm for updating the deleted address list is DeleteFeedback(LFN, DA);
[0173] The address comparison algorithm is Compare(AddList1, AddList2);
[0174] Preferably, the execution process of the deletion algorithm Delete() is as follows: the personal information subject issues a deletion request, and the algorithm obtains the logical file name LFN of the copy of the personal information and the destination address list AddList1.
[0175] Preferably, the execution process of the address indexing algorithm Search(LFN, DA) is as follows: after receiving a deletion request, the information field sends a deletion request to the associated information field in the destination address list according to the logical file name LFN of the personal information copy and the destination address list.
[0176] Preferably, the execution process of the delete address list update algorithm DeleteFeedback(LFN, DA) is as follows: after receiving the deletion request, the information domain deletes the copy of the personal information and encapsulates its own address and the received feedback address into an address list AddList2 and sends it back to the superior information domain; specifically, for the personal information source domain, it needs to send the address list AddList2 back to the personal information subject.
[0177] Preferably, the execution process of the address comparison algorithm Compare(AddList1, AddList2) is as follows: the personal information subject compares the address lists AddList1 and AddList2; if they are the same, it indicates that the deletion was successful.
[0178] The choice of public key encryption algorithm and hash algorithm stored in the algorithm unit in this embodiment has no substantial impact on the implementation of this method. Even if other algorithms are selected, the same implementation effect can be achieved.
[0179] It should be noted that the specific embodiments described above are exemplary, and those skilled in the art can devise various solutions inspired by the disclosure of this invention. These solutions all fall within the scope of this invention and its protection. Those skilled in the art should understand that this specification and its accompanying drawings are illustrative and not intended to limit the scope of the claims. The scope of protection of this invention is defined by the claims and their equivalents.
Claims
1. A highly efficient and secure method for deleting multiple copies of personal information, providing several information fields, characterized in that, The method includes: The personal information and the personal information subject identifier are signed and uploaded to the information domain, and the information domain stores the personal information as a copy. The copies of the personal information are circulated between the information domains, and each copy of the personal information records its source and purpose; When an information field receives a deletion command, it transmits the deletion command to each information field based on the personal information subject identifier and the destination information in the personal information copy, and performs the deletion operation. After the information domain is deleted, it stores its own domain identifier and the received feedback information in the log, and then feeds the log back to the next higher level information domain. Configure the stored procedure as follows: A hash calculation is performed based on personal information and the personal information subject identifier, and the hash value is signed using the personal information subject's private key to obtain a digital signature. Among them, the personal information subject identifier serves as a globally unique identifier; The personal information subject uploads the personal information subject identifier, personal information, and digital signature to the information source domain; The backup copy of personal information in the information source domain stores at least the personal information subject identifier, personal information, digital signature, source domain identifier, and destination domain identifier, with the source domain identifier and destination domain identifier initialized to empty; The source domain identifier stores the identifier of the parent domain from which the current information copy flows out; the destination domain identifier stores the identifier of the child domain from which the current information copy flows in.
2. The method for deleting multiple copies of personal information according to claim 1, characterized in that, The following configuration is performed during the workflow: The current propagation domain requests a backup copy of the personal information from the superior domain based on the personal information subject identifier, and modifies the source domain identifier and destination domain identifier in the personal information copy backed up to the current propagation domain. Specifically, the source domain identifier is modified to the identifier of the superior domain, and the destination domain identifier is reset to empty. The current propagation domain sends the destination domain identifier and its own domain identifier from the modified copy of the personal information back to the parent domain. The parent domain then updates its copy of the personal information based on the feedback from the current propagation domain.
3. The method for deleting multiple copies of personal information according to claim 2, characterized in that, The following configuration is also performed during the transfer process: The process by which the parent domain updates the copy of personal information based on the feedback content of the current propagation domain is as follows: the destination domain identifier is added with a domain identifier that exists in the feedback content but does not exist in the destination domain identifier; Repeat the feedback and update steps until the information source domain is updated.
4. The method for deleting multiple copies of personal information according to claim 3, characterized in that, The deletion and evidence preservation process is configured as follows: The personal data subject sends a deletion command to the information source domain. The information source domain determines the copy of the personal data to be deleted based on the personal data subject's identifier, and then sends a deletion command to the directly associated information domain based on the destination domain identifier of the personal data copy. When the current propagation domain receives a deletion request, it determines the current information copy to be deleted based on the personal information subject identifier, issues a deletion command to the directly associated information domain based on the destination domain identifier of the current information copy, and deletes the current information copy after issuing the deletion command.
5. The method for deleting multiple copies of personal information according to claim 4, characterized in that, The deletion and evidence preservation process also includes the following configuration: If the target domain identifier of the current propagation domain is empty, the current propagation domain will store the personal information subject identifier and its own domain identifier in the log. If the destination domain identifier of the current propagation domain is not empty, the current propagation domain will store the personal information subject identifier, the domain identifier of the current propagation domain, and the domain identifier recorded in the evidence storage log of the lower-level domain in the current propagation domain's log.
6. The method for deleting multiple copies of personal information according to claim 5, characterized in that, The deletion and evidence preservation process also includes the following configuration: After the current propagation domain completes the log storage, it uses the private key of the current propagation domain to sign the stored log and sends the signed stored log back to the superior domain. The parent domain uses the private key of the current propagation domain to design the evidence log to obtain the domain identifier in the log returned by the current propagation domain.
7. The method for deleting multiple copies of personal information according to claim 6, characterized in that, The following configuration is performed when accessing a copy of personal information in the information domain: The current propagation domain downloads the desired copy of the current information based on the personal data subject identifier; The current propagation domain performs a preliminary parsing of the current information copy to obtain a digital signature, and selects the desired public key based on the personal information subject identifier to verify the digital signature; If the verification is successful, the current propagation domain will design the current copy of the information to obtain personal information.
8. A highly efficient and secure system for deleting multiple copies of personal information, comprising several information fields, characterized in that, The information domain is configured to have at least the following protocols: The storage protocol signs personal information and personal information subject identifiers, uploads them to the information domain, and stores them as a copy of the personal information in the information domain; A transfer protocol is provided in which copies of the personal information are transferred between the information domains, and each copy of the personal information records its source and purpose. An access protocol is used by the information domain to verify and access copies of personal information based on the personal information subject identifier; The deletion and evidence preservation protocol stipulates that when an information domain receives a deletion command, it transmits the deletion command to each information domain based on the personal information subject identifier and the purpose information in the personal information copy, and performs the deletion operation; after completing the deletion, the information domain stores its own domain identifier and the received feedback information in the log, and feeds the log back to the next higher level information domain. The system is configured in the stored procedure as follows: A hash calculation is performed based on personal information and the personal information subject identifier, and the hash value is signed using the personal information subject's private key to obtain a digital signature. Among them, the personal information subject identifier serves as a globally unique identifier; The personal information subject uploads the personal information subject identifier, personal information, and digital signature to the information source domain; The backup copy of personal information in the information source domain stores at least the personal information subject identifier, personal information, digital signature, source domain identifier, and destination domain identifier, with the source domain identifier and destination domain identifier initialized to empty; The source domain identifier stores the identifier of the parent domain from which the current information copy flows out; the destination domain identifier stores the identifier of the child domain from which the current information copy flows in.
Citation Information
Patent Citations
Methods for verifying the integrity of multiple cloud data replicas and associated deletion, cloud storage systems
CN108418796B
Secure cloud data multi-copy association deletion method
CN111092847A
Cloud heterogeneous storage system and data copy management method thereof
CN104317669A