A trusted third party auditing method and system for personal information deletion

By parsing and correlating log data from personal information source domains and associated domains, third-party audit logs are generated, solving the problem of the inability to effectively monitor the deletion of personal information in existing technologies. This enables automated, secure compliance auditing and rapid detection of abnormal behavior.

CN116346592BActive Publication Date: 2026-05-05HUAZHONG UNIV OF SCI & TECH
View PDF 6 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
HUAZHONG UNIV OF SCI & TECH
Filing Date
2023-03-29
Publication Date
2026-05-05

AI Technical Summary

Technical Problem

Existing technologies cannot effectively monitor and ensure the secure deletion of personal information, lack credible third-party auditing methods, make it difficult to identify abnormalities and internal violations by the deleting entity, and fail to meet compliance and internal control requirements.

Method used

By acquiring log data from the source and associated domains of personal information within the network, parsing, normalizing, and performing correlation analysis, third-party audit logs for personal information deletion are generated, enabling automated monitoring and compliance auditing of personal information deletion activities.

Benefits of technology

It automates, secures, and makes the personal information deletion process easy, ensuring the compliance and integrity of information deletion, supporting the rapid detection of abnormal behavior and providing detailed evidence.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116346592B_ABST
    Figure CN116346592B_ABST
Patent Text Reader

Abstract

This invention relates to a trusted third-party auditing method and system for personal information deletion. The method includes: acquiring several log data points from any personal information source domain deletion entity and its associated domain deletion entities within a network; normalizing the log data using preset parsing rules to generate normalized log data; and performing notification consistency and operational compliance analysis on the normalized log data through correlation analysis. This application, based on log file audit analysis, determines whether the information deletion process meets multi-dimensional or multi-level audit judgment conditions and promptly obtains evidence of abnormal personal information deletion behavior, thereby ensuring that personal information deletion meets compliance internal control requirements, industry standards, and policies and regulations.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of information technology, computer technology, network technology, and Internet technology, and particularly to the fields of auditing methods and information protection technology, specifically a trusted third-party auditing method and system for the deletion of personal information. Background Technology

[0002] With the widespread circulation of personal information and the requirements of relevant laws and regulations, personal information deletion is becoming increasingly common. Various data breach cases have also made users increasingly aware of the importance of deleting and protecting their personal information. Although existing internet companies typically promise users that personal information will be completely deleted after the user no longer needs it, current data deletion technologies vary in implementation and effectiveness, leaving users unable to guarantee the secure deletion of their personal information.

[0003] To better monitor and safeguard the operation of entities deleting personal information, promptly identify operational anomalies and internal violations, and provide necessary information for post-incident analysis and investigation, trusted third-party auditing of personal information deletion activities is required. National policies, regulations, and industry standards all explicitly require log auditing, making it an essential function for enterprises to meet compliance and internal control requirements. Existing personal information deletion auditing methods primarily include manual and automated auditing. Manual auditing generally requires professional personnel, is cumbersome, time-consuming, and costly, and struggles to audit the deletion process across related personal information domains. Automated auditing typically only checks whether deletion notifications were sent, making it difficult to ensure consistency in notifications and compliance of the operation.

[0004] Existing technologies also propose technical solutions to improve audit efficiency and quality. For example, patent CN106095575B discloses a log auditing device, system, and method. This log auditing device is connected to at least two peripheral devices. Each collection process in the collection unit receives log files sent by at least two peripheral devices when idle. Each normalization process in the normalization unit determines normalization rules. When idle, it parses log file attributes and determines the log file's association attributes based on the normalization rules and the log file attributes. Each association process in the log association unit determines association rules and alarm rules. When an association attribute is received, log association is performed according to the association rules. When the log association meets the alarm rules, an alarm unit is triggered. The alarm unit then issues log audit alarms. This patent's technical solution optimizes the log auditing process through collection, normalization, association, and alarm determination to improve audit efficiency. However, this technical solution does not involve the review of the specific content of the logs or the determination of log compliance.

[0005] Patent CN107818150B discloses a log auditing method and apparatus. By parsing, standardizing and mapping fields, and classifying log operation types and details from raw logs collected from components of major big data platforms, the method can standardize the initial logs of various components in big data platforms with different sources and formats. Then, based on the auditing requirements of big data security management, the method adopts corresponding auditing rules and analysis strategies to automatically audit and analyze the standardized logs of various components in the big data platform to determine whether the management and data access operations of the big data platform and its components comply with security technical specifications and management requirements.

[0006] Patent CN115408229A discloses an operation log auditing method, apparatus, electronic device, and storage medium. The method includes: acquiring the operation logs of an account to be audited; inputting the operation logs of the account to be audited into a log auditing model to obtain the audit results of the account to be audited output by the log auditing model; wherein the log auditing model is trained based on the basic operation characteristics and abnormal operation characteristics of sample accounts in various sample account categories, as well as the audit tags of each sample account; the sample account categories are determined based on the basic operation characteristics of multiple sample accounts, and the audit tags of the sample accounts are determined based on preset tags of sample accounts within the sample accounts. The technical solution of the above patent uses standardization as a pre-audit step, and then performs a log review process based on preset audit rules, analysis strategies, and a trained auditing model.

[0007] Based on the above, existing technical solutions for auditing system operation status and behavior information based on log files or data from various data platforms do not provide reliable third-party auditing for the analysis and judgment of deletion operation records and deletion results of personal information deletion entities. In other words, existing technical solutions cannot effectively monitor the personal information deletion behavior of various data platforms or systems and provide effective analytical means and evidence support for situations such as abnormal operation of deletion entities and internal violations, ensuring that each data platform can completely delete personal information in an unauthorized retention state. Therefore, it is not possible to conduct information use supervision and privacy protection review based on the third-party auditing process of deletion-related logs of various data platforms or systems.

[0008] Furthermore, on the one hand, there are differences in understanding among those skilled in the art; on the other hand, the inventors studied a large number of documents and patents when making this invention, but due to space limitations, not all details and contents were listed in detail. However, this does not mean that the present invention does not possess the features of these prior art. On the contrary, the present invention already possesses all the features of the prior art, and the applicant reserves the right to add relevant prior art to the background art. Summary of the Invention

[0009] To address at least some of the shortcomings of existing technologies, this application provides a trusted third-party auditing method for personal information deletion. The method includes: acquiring several log data from any personal information source domain deletion entity and its associated domain deletion entities within the network; normalizing the log data and generating normalized log data through preset parsing rules; and performing notification consistency analysis and operational compliance analysis on the normalized log data through correlation analysis.

[0010] In this application, the content data of the log data refers to the main content of the log data, including information content, information status, etc., such as deletion notification log, deletion notification confirmation log, deletion operation log, and deletion effect self-evaluation log; while the tag data of the log data refers to the security verification data of the log data, such as signature, key, identification code, etc. For example, the tag data of the log data is the log data signature, so that the log collection module receives the content data of the log data after the log data signature verification is successful.

[0011] This application provides a trusted third-party auditing method and system for personal information deletion, which can fill the gap in the existing technology regarding trusted third-party auditing of personal information deletion or overcome the defects of the existing technology. The method and system of this application obtain a third-party audit log for personal information deletion, representing the audit results, by acquiring, normalizing, and performing correlation analysis on log data of the personal information source domain deletion subject and its associated domain deletion subjects. Based on correlation analysis, the third-party audit log for personal information deletion can identify abnormal personal information deletion behaviors and trace back to obtain evidence from the original log data and files. Based on the review process of log files carrying personal information deletion information, it can accurately and comprehensively determine whether the collection, use, and deletion of information comply with relevant regulations on information security and privacy protection, and promptly correct abnormal states or internal violations. This ensures that the management and data access operations of the data platform and system comply with security technical specifications and management requirements, and meet compliance internal control requirements, industry standards, and policies and regulations.

[0012] Especially in terms of information security and privacy protection, log files can record the status and destination information of information during the stages of collection, use, and deletion. Based on the method and system of this application, logs can be automatically acquired, correlated, and analyzed, and log audit results can be output. Normalization based on parsing rules can significantly improve the efficiency of analysis and processing and obtain targeted data information. The correlation analysis process can perform correlation analysis on the content data and tag data of log files respectively to obtain multi-dimensional and multi-level correlation analysis results. Based on the multi-dimensional and multi-level correlation analysis results, massive log files can be processed efficiently and corresponding abnormal deletion of personal information can be quickly found. Through retrospective evidence collection, an efficient audit method and detailed evidence support can be provided for the analysis and correction of abnormal deletion of personal information and internal violations.

[0013] Therefore, this application can be applied to organizations such as governments, internet companies, and auditing firms. Governments and auditing firms can use the technical solution of this application to audit the personal information deletion operations performed by personal information processors, thereby confirming whether the personal information processors have performed personal information deletion operations in accordance with relevant laws and regulations. Internet companies can use the technical solution of this application to check whether multiple copies of the data have been completely deleted across their various business systems and whether the personal information deletion operations comply with relevant laws and regulations. In other words, this application provides an efficient and secure method for auditing personal information deletion, which can automatically audit personal information deletion and effectively ensure the complete deletion of data and the compliance of deletion operations. The specific advantages of the technical solution of this application compared with the prior art include: Automation: The method of this application can automatically audit personal information deletion, reducing the cost and negligence of manual operations; Security: The method of this application can ensure the integrity of personal information deletion logs and authenticate the sender's identity; Ease of use: The method of this application can also be easily integrated into existing data management systems without additional human and resource investment.

[0014] Preferably, obtaining log data of any personal information source domain deletion subject and its associated domain deletion subject within the network includes: the log data includes content data and tag data, and the content data is received after the tag data is verified. The content data includes deletion notification logs, deletion notification confirmation logs, deletion operation logs, and deletion effect self-evaluation logs.

[0015] Preferably, obtaining log data of any personal information source domain deletion entity and its associated domain deletion entity within the network includes: proactively sending a log data collection request to the personal information source domain deletion entity within the network and receiving a request confirmation message and / or receiving log data periodically pushed by the personal information source domain deletion entity within the network and returning a push confirmation message; finding the corresponding associated domain based on the log data of the personal information source domain deletion entity and sending a log data collection request to the corresponding associated domain deletion entity and receiving a request confirmation message.

[0016] Preferably, the content data received after the tag data verification is successful includes: tag data generated by the personal information source domain deletion entity and its associated domain deletion entities; and the audit entity receiving and verifying the tag data sent from the personal information source domain deletion entity and its associated domain deletion entities. For example, when the tag data is a log data signature, the personal information source domain deletion entity and its associated domain deletion entities sign the log data, and the audit entity receiving and verifying the log data signature sent from the personal information source domain deletion entity and its associated domain deletion entities.

[0017] Preferably, the generation of tag data by the personal information source domain deletion entity and its associated domain deletion entities includes: the personal information source domain deletion entity and its associated domain deletion entities combine the content data of the log data with a timestamp to form a log data message, and use the corresponding private key to calculate the tag data of the log data message. The audit entity receiving and verifying the tag data sent from the personal information source domain deletion entity and its associated domain deletion entities includes: verifying the communication time of the log data message to select log data messages that do not exceed a set time value, and continuing to perform public key verification calculation on the tag data.

[0018] Preferably, normalizing log data and generating normalized log data by means of preset parsing rules includes: merging log information by filtering out useless fields in the logs, extracting key field information from the log data and reorganizing it into the corresponding normalized log using the corresponding normalization format.

[0019] Preferably, the notification consistency analysis of normalized log data by means of correlation analysis includes: analyzing each entry in the normalized log of deletion notifications of the deletion subject in the personal information source domain and defining the current analysis entry as the first entry; finding the corresponding second entry in the normalized log of the deletion notification confirmation of the deletion subject in the associated domain based on the key fields in the first entry; and obtaining the notification consistency audit analysis result based on the existence correspondence result and content correspondence result of the first entry and the second entry.

[0020] Preferably, the existence of a corresponding result refers to whether the corresponding second entry in the normalized log of the deletion notification confirmation of the subject of deletion in the associated domain can be found based on the key fields in the first entry; the content corresponding result refers to whether the target, granularity and method of personal information deletion in the first entry are consistent with the second entry.

[0021] Preferably, the operation compliance analysis of normalized log data through correlation analysis includes: analyzing each entry in the normalized log of deletion operations of the deletion subject in the personal information source domain and its associated domain deletion subjects, and defining the current analysis entry as the first entry; finding the corresponding second entry in the normalized log of deletion effect self-evaluation in the same domain based on the key fields in the first entry; and obtaining the operation compliance audit analysis results based on the existence of the first entry and the second entry, the corresponding results, and the content compliance results.

[0022] Preferably, the existence of a corresponding result refers to whether the corresponding second entry in the normalized log of the deletion effect self-evaluation within the same domain can be found based on the key fields in the first entry; the content compliance result refers to whether the deletion request consistency assessment result, deletion operation consistency assessment result, deletion operation effectiveness assessment result, and deletion irreversibility assessment result in the second entry comply with regulatory requirements.

[0023] Preferably, the method further includes: after completing the correlation analysis of the normalized log data, generating a third-party audit log for personal information deletion; and based on the third-party audit log for personal information deletion, obtaining log data of personal information deletion anomalies and collecting evidence of the original log data.

[0024] Preferably, the process of obtaining log data backtracking and evidence collection of abnormal personal information deletion based on third-party audit logs includes: obtaining audit analysis results on the consistency of personal information deletion notifications and the compliance of operations, locating relevant log data entries, and providing evidence collection analysis results.

[0025] This application also provides a trusted third-party auditing system for personal information deletion, the system including at least: a log collection module, which is configured to acquire several log data of any personal information source domain deletion subject and its associated domain deletion subject within the network; and a log analysis module, which is configured to normalize the log data and generate normalized log data through preset parsing rules, and perform notification consistency and operation compliance analysis on the normalized log data through correlation analysis. Attached Figure Description

[0026] Figure 1 This is a schematic diagram of the system structure according to an embodiment of the present invention;

[0027] Figure 2 This is a flowchart illustrating the method and system log collection process according to an embodiment of the present invention;

[0028] Figure 3 This is a flowchart illustrating the method and system log analysis of an embodiment of the present invention.

[0029] List of reference numerals

[0030] 1: Log collection module; 2: Log analysis module; 3: Log management module. Detailed Implementation

[0031] The present invention will now be described in detail with reference to the accompanying drawings.

[0032] In this application, personal information refers to various information recorded electronically or otherwise that can, alone or in combination with other information, identify a specific natural person or reflect the activities of a specific natural person, including name, ID number, contact information, address, account password, financial status, and whereabouts. Auditing refers to an independent economic oversight activity conducted by a specialized agency in accordance with law, reviewing the major projects and financial revenues and expenditures of governments at all levels, financial institutions, and enterprises before and after the fact. Third-party auditing refers to the process of an audit commissioned by a specialized agency. Log data consists of a large amount of log information generated during the operation of general computer hardware and software such as network devices, servers, and application services, as well as various specific business systems. Log information can reflect the operating status of computer hardware and software and business systems, and auditing logs is one of the important means of understanding the operating status. Currently, for the auditing of operation logs of big data platforms, enterprise security management personnel typically periodically view the original log information from the nodes of service components, or view partial logs through certain big data management platforms, manually checking and auditing to determine whether the management and data access operations of the platform and components comply with security technical specifications and management requirements, thereby meeting compliance internal control requirements, industry standards, and policies and regulations.

[0033] Especially regarding information security and privacy protection, log files can record the status and destination information of information during the stages of collection, use, and deletion. Therefore, the review process based on log files can accurately and comprehensively determine whether the collection, use, and deletion of information comply with relevant regulations on information security and privacy protection, and promptly correct any abnormal states or internal violations. However, existing systems lack trusted third-party auditing for the deletion of personal information. To ensure the secure deletion of personal information and to monitor the deletion process, this invention provides an auditing method and system, particularly a log auditing method and system, and more specifically, a trusted third-party auditing method and system for the deletion of personal information, hereinafter referred to as the method and system.

[0034] like Figure 1As shown, the system of this application includes at least a log acquisition module 1, a log analysis module 2, and a log management module 3. The system also includes an audit filter for storing parsing rules and an audit subject for performing audit processing. The log acquisition module 1 can use a network adapter to connect to the network and communicate with personal information domains via network protocols to acquire various log data. The log analysis module 2 can use a CPU to process the log data; if massive amounts of log data are involved or high analysis speed is required, a GPU, FPGA, or dedicated integrated circuit can be used for processing. The log management module 3 can use a USB flash drive to store data. Therefore, the system of this application can be composed of hardware such as a network adapter, CPU, and USB flash drive. The front-end data source hardware of the system can be a network adapter, or it can connect to the device through different interfaces to transmit data. The back-end data destination of the system can be the storage hardware built into the device, or various storage hardware on a cloud storage platform or remote host.

[0035] Specifically, the log collection module 1 is used to acquire deletion notification logs, deletion notification confirmation logs, deletion operation logs, deletion effect self-evaluation logs, and log data signatures of the personal information source domain deletion entity and its associated domain deletion entities. Log data is received after signature verification. The personal information source domain deletion entity is the main data platform or system for personal information management, and the associated domain deletion entity is other data platforms or systems that have relationships with the personal information source domain deletion entity regarding personal information collection, use, sharing, backup, etc. Deletion notifications can be generated by the personal information source domain deletion entity and sent to the associated domain deletion entities, forming a deletion notification log. The associated domain deletion entity receives the deletion notification, sends a confirmation of the deletion notification to the personal information source domain deletion entity, forming a deletion notification confirmation log. The personal information source domain deletion entity and / or the associated domain deletion entity execute deletion operations, forming a deletion operation log. The personal information source domain deletion entity and / or the associated domain deletion entity independently evaluate the deletion effect, forming a deletion effect self-evaluation log. Log analysis module 2 is used to parse, correlate, and analyze logs, generating third-party audit logs for personal information deletion. Log parsing involves normalizing log files, unifying the log files of various deletion entities into a standardized, simplified format based on procedural operation steps. Log correlation and analysis includes establishing relationships between several log files based on log content and log tags, and generating third-party audit logs for personal information deletion based on the correlation and analysis results. Log management module 3 can be used for log sampling audits and evidence analysis, as well as setting alarms for various risks and managing various types of logs.

[0036] like Figures 2 to 3As shown, the method in this application audits the information deletion entities of various data platforms or systems based on third-party audits. This includes monitoring and verifying the operational data and status of the deletion entity's operations. Based on the operational data and status of the deletion entity's results, a third-party audit log for personal information deletion is generated, and a corresponding digital signature is calculated and stored. This enables comprehensive auditing of the consistency of notifications and the compliance of operations related to personal information deletion, and also allows for the storage and management of abnormal personal information deletion logs. The method also supports log sampling auditing, generating audit results quickly and efficiently; supports log forensic analysis to quickly locate the cause of problems and trace the source based on various abnormal log data; and supports real-time alerts for various risks and events, promptly notifying users of alerts via email, SMS, and sound.

[0037] The audit targets of this method are any personal information source domain deletion entity and its associated domain deletion entities within the network. The deletion entity can be a device, software, or person. For example, the personal information source domain deletion entity is a smart terminal, and the personal information associated domain deletion entities include various authorized network platforms or apps. This creates a relationship of collection, use, sharing, and backup of personal information between the personal information source domain deletion entity and its associated domain deletion entities. Thus, the personal information source domain and its associated domains can form a closed system containing all existing personal information. Personal information flows and operates within this closed system under control. The system can control its scope by including or deleting other personal information associated domain deletion entities, thereby adjusting the scope of personal information use and allocating usage permissions.

[0038] To ensure effective supervision of the collection, use, and deletion of personal information, the method in this application achieves auditing by analyzing and processing log files from various data platforms. This includes: acquiring several log data points from any personal information source domain deletion entity and its associated domain deletion entities within the network; the log data includes content data and tag data; receiving content data after tag data verification; normalizing the log data using preset parsing rules to generate normalized log data; and performing notification consistency analysis and operational compliance analysis on the normalized log data through correlation analysis. For personal information deletion behaviors with abnormal audit results, all relevant original logs are stored; the results are summarized to generate a third-party audit log for personal information deletion, and the corresponding digital signature is calculated and stored. Based on the third-party audit log for personal information deletion, log data with abnormal personal information deletion is obtained for backtracking and evidence collection of the original log data. Content data is the main content of the log data, including information content and information status; while tag data is the security verification data of the log data, such as signatures, keys, and identification codes. For example, the tag data of the log data is the log data signature, enabling the log collection module 1 to receive the content data of the log data after the log data signature verification is successful.

[0039] Preferably, such as Figure 2 As shown, obtaining certain log data of any personal information source domain deletion subject and its associated domain deletion subject within the network includes: obtaining deletion notification logs, deletion notification confirmation logs, deletion operation logs, deletion effect self-evaluation logs, and log data signatures of any personal information source domain deletion subject and its associated domain deletion subject within the network; and receiving log data after the signature verification is successful.

[0040] Preferably, obtaining deletion notification logs, deletion notification confirmation logs, deletion operation logs, deletion effect self-evaluation logs, and log data signatures of any personal information source domain deletion entity and its associated domain deletion entities within the network includes: proactively sending collection requests for deletion notification logs, deletion notification confirmation logs, deletion operation logs, deletion effect self-evaluation logs, and log data signatures to the personal information source domain deletion entities within the network and obtaining request confirmation information; and / or receiving deletion notification logs, deletion notification confirmation logs, deletion operation logs, deletion effect self-evaluation logs, and log data signatures periodically pushed by the personal information source domain deletion entities within the network and returning push confirmation information; then finding the corresponding associated domains based on the deletion notification logs of the personal information source domain deletion entities, and sending collection requests for deletion notification logs, deletion notification confirmation logs, deletion operation logs, deletion effect self-evaluation logs, and log data signatures to the corresponding associated domain deletion entities and obtaining request confirmation information.

[0041] Preferably, the log data signature is generated by the source domain deletion entity and its associated domain deletion entities, and the log data signature is verified by the audit entity. That is, the source domain deletion entity and its associated domain deletion entities sign the log data, and the audit entity receives the log data signature sent by the source domain deletion entity and its associated domain deletion entities and verifies it.

[0042] Preferably, the digital signature module of the personal information source domain deletion subject and its associated domain deletion subject signs the log data, including: the personal information source domain deletion subject and its associated domain deletion subject combine the deletion notification log, deletion notification confirmation log, deletion operation log, and deletion effect self-evaluation log with timestamps into a message, and calculate the signature of this message using the corresponding private key. The specific process is as follows: the deletion subject first logs the deletion notification log... n Delete notification confirmation log c Delete operation log o Deletion effect self-evaluation log s and timestamp T i Combined into a message m i =(Log n ||Log c ||Log o ||Logs ||T i ), where || represents message concatenation. Then, for message m i Perform a hash operation to obtain a message digest, and then use the corresponding private key sk i The signature value σ is calculated. i .

[0043] Preferably, the specific process by which the auditing entity receives and verifies the log data signature sent by the personal information source domain deletion entity and its associated domain deletion entity is as follows: Upon receiving the log data message m from the personal information source domain deletion entity... i and signature σ i Then, first use the current time T to calculate the equation TT. i If the value of the equation is not greater than the maximum tolerable communication time τ, the message can be considered a fresh message and the signature verification can continue; otherwise, the message expires and is discarded. When verifying the signature, the corresponding public key PK is used. i For the signature value σ i Perform verification. If the verification is successful, output 1 and accept the signature; otherwise, output 0 and reject the signature.

[0044] like Figure 3 As shown, normalizing log data and generating normalized log data through preset parsing rules includes: merging log information by filtering out useless fields in the logs, extracting key field information from the log data, and reorganizing it into the corresponding normalized logs using the appropriate normalization format. After signature verification is passed, the specified unified parsing rules are immediately used to parse deletion notification logs, deletion notification confirmation logs, deletion operation logs, and deletion effect self-evaluation logs of any format; normalizing various types of logs through the parsing rules in the audit filter includes: filtering out useless fields in the logs, merging log information; extracting key field information from the deletion notification logs, deletion notification confirmation logs, deletion operation logs, and deletion effect self-evaluation logs, and reorganizing them into the corresponding normalized logs using the appropriate normalization format. Useless fields can serve an auxiliary purpose and help understand the log statement content, while key field information is used to record user operations, track the execution process, and collect runtime environment data.

[0045] Preferably, the fields of the normalized deletion notification log (i.e., the deletion notification normalized log) include at least: deletion notification identifier, personal information source domain deletion subject identifier, deletion notification associated domain deletion subject identifier, deletion target data identifier, deletion granularity, deletion method, deletion notification date, and deletion notification time; the fields of the normalized deletion notification confirmation log (i.e., the deletion notification confirmation normalized log) include at least: deletion notification confirmation identifier, personal information associated domain deletion subject identifier, deletion notification source domain deletion subject identifier, received deletion notification identifier, deletion target data identifier, deletion granularity, deletion method, deletion notification confirmation date, and deletion notification confirmation time; deletion operation After log normalization, the fields of the deletion operation normalized log should include at least: deletion operation identifier, personal information field deletion subject identifier, deletion notification confirmation identifier, deletion target data identifier, deletion granularity, deletion method, deletion operation date, and deletion operation time. After deletion effect self-evaluation log normalization, the fields of the deletion effect self-evaluation normalized log should include at least: deletion effect self-evaluation identifier, personal information field deletion subject identifier, deletion operation identifier, deletion request consistency evaluation result, deletion operation consistency evaluation result, deletion operation effectiveness evaluation result, deletion irrecoverability evaluation result, deletion effect self-evaluation date, and deletion effect self-evaluation time.

[0046] like Figure 3 As shown, the notification consistency analysis and operation compliance analysis of normalized log data through correlation analysis includes: after parsing the original logs into normalized logs, immediately correlate the deletion notification normalized logs, deletion notification confirmation normalized logs, deletion operation normalized logs, and deletion effect self-evaluation normalized logs, and perform notification consistency and operation compliance audit analysis on the corresponding fields to obtain the corresponding audit analysis results.

[0047] Preferably, the notification consistency analysis of normalized log data through correlation analysis includes: analyzing each entry in the normalized log of deletion notifications for the source domain deletion subject and defining the current analysis entry as the first entry; finding the corresponding second entry in the normalized log of deletion notification confirmation for the associated domain deletion subject based on the key fields in the first entry; and obtaining the notification consistency audit analysis result based on the existence correspondence result and content correspondence result of the first and second entries. The existence correspondence result refers to whether the corresponding second entry in the normalized log of deletion notification confirmation for the associated domain deletion subject can be found based on the key fields in the first entry; the content correspondence result refers to whether the target, granularity, and method of personal information deletion in the first entry are consistent with those in the second entry. Specifically, each entry in the normalized log of deletion notifications for the source domain deletion subject is audited; when auditing any entry, the corresponding second entry in the deletion notification confirmation log of the associated domain is found based on the key fields in the first entry. Specifically, the deletion notification confirmation log of the corresponding associated domain is found based on the content of the deletion notification associated domain deletion subject identifier field in the first entry, and the second entry with the same deletion notification identifier field content is found based on the content of the deletion notification identifier field in the first entry. If no second entry corresponding to the first entry is found in the deletion notification confirmation log of the associated domain, the notification consistency audit analysis is abnormal, and an exception message is returned. The analysis checks whether the target, granularity, and method of personal information deletion in the first entry are consistent with the content in the second entry. If they are consistent, the first entry has notification consistency for personal information deletion; otherwise, it indicates that the notification consistency audit analysis of the first entry is abnormal, and an exception message is returned.

[0048] Preferably, the operational compliance analysis of normalized log data through correlation analysis includes: analyzing each entry in the normalized log of deletion operations of the personal information source domain deletion subject and its associated domain deletion subjects, and defining the current analysis entry as the first entry; finding the corresponding second entry in the normalized log of deletion effect self-evaluation within the same domain based on the key fields in the first entry; and obtaining the operational compliance audit analysis result based on the existence correspondence result of the first entry and the second entry and the content compliance result. The existence correspondence result refers to whether the corresponding second entry in the normalized log of deletion effect self-evaluation within the same domain can be found based on the key fields in the first entry; the content compliance result refers to whether the deletion request consistency assessment result, deletion operation consistency assessment result, deletion operation effectiveness assessment result, and deletion irreversibility assessment result in the second entry comply with regulatory requirements. Specifically, each entry in the deletion operation log of the personal information source domain and its associated domain deletion subjects is audited and analyzed item by item; when auditing and analyzing any entry, the corresponding second entry in the self-evaluation log of deletion effect within the same domain is found based on the key fields in the first entry. Specifically, the second entry with the same second deletion operation identifier field content is found based on the first entry's first deletion operation identifier field content. If no second entry corresponding to the first entry is found in the self-evaluation log of the deletion effect within the same domain, the operation compliance audit analysis is abnormal and an error message is returned. Analyze whether the deletion request consistency assessment result, deletion operation consistency assessment result, deletion operation effectiveness assessment result, and deletion irreversibility assessment result in the second entry meet the relevant standards or regulatory requirements. If they meet the requirements, the first entry has the operation compliance of deleting personal information; otherwise, it indicates that the operation compliance audit analysis of the first entry is abnormal and an error message is returned.

[0049] Preferably, after completing the correlation analysis of the normalized log data, the results are summarized to generate a third-party audit log for personal information deletion, and the corresponding digital signature is calculated and stored. For personal information deletion behaviors with abnormal audit results, all relevant original logs are stored. Preferably, the personal information deletion third-party audit log is calculated. a The digital signature process is as follows: Combine the third-party audit log generation time T to generate the message m = (Log... a ||T)∈{0,1} *The message m is hashed to obtain a message digest, and the signature σ is calculated using the audit subject's private key sk. Specifically, when any subject verifies message m, it first calculates the equation Tt using the last third-party audit time t in the message. If the equation value is not greater than the maximum tolerable signature time τ, the message is considered fresh; otherwise, the signature expires. Given the audit subject's public key PK, the signature is verified. If it is valid, 1 is output and the signature is accepted; otherwise, 0 is output and the signature is rejected.

[0050] Preferably, the key fields of the generated personal information deletion third-party audit log include at least: third-party audit identifier, personal information domain deletion subject identifier, deletion notification identifier, notification consistency audit analysis result, deletion operation identifier, operation compliance audit analysis result, third-party audit date, and third-party audit time.

[0051] Specifically, based on third-party audit logs of personal information deletion, log data of abnormal personal information deletion is obtained through backtracking and evidence collection of original log data. The consistency of personal information deletion notifications and the compliance of operational actions are then assessed through audit analysis. Relevant log data entries are located, and evidence analysis results are provided. For example... Figure 2 and Figure 3 As shown, when conducting log forensic analysis, for audit anomalies in personal information deletion behavior, all relevant original logs are located, the cause of the problem is determined through certain rules, and the relevant log entries are accurately located. For example, if an audit anomaly is found in the normalized log of the deletion notification from the source domain's deletion entity, the audit entity extracts this first entry and finds the corresponding second entry in the deletion notification confirmation log of the associated domain. The audit then analyzes whether the target, granularity, and method of personal information deletion in the first entry are consistent with the content of all second entries, and provides a detailed reason for the anomaly.

[0052] Preferably, this method can also notify and alert on the risk categories and risk events of personal information deletion behavior according to preset rules based on the forensic analysis results of abnormal audit results. The preset rules can be frequency thresholds, probability thresholds, or other types of custom judgment conditions. When issuing real-time alerts for various risks and events, for each type of risk and event, notifications and alerts will be issued in a corresponding manner after a certain number of occurrences according to the system's preset rules. Specifically, for example, when an audit abnormality appears in the deletion notification log of the personal information source domain deletion subject, an email will be sent to the corresponding email address; when five abnormal entries appear, an SMS will be sent to the mobile phone; when ten abnormal entries appear, an audible alarm will be issued.

[0053] Preferably, to improve log auditing efficiency and quality, the method of this application can perform sampling audits on logs and conduct forensic analysis on target logs to obtain evidence indicating the compliance status of the use of personal or customer information. The method includes: randomly selecting log data or a certain proportion of entries from the personal information source domain deletion entity and its associated domain deletion entities to conduct notification consistency and operational compliance audit analysis of personal information deletion and obtain audit analysis results. When the audit analysis results meet frequency thresholds, probability thresholds, or other types of custom judgment conditions, it is determined that the personal information source domain deletion entity and its associated domain deletion entities have notification consistency and operational compliance.

[0054] For example, when conducting log sampling audits, a certain percentage of entries in the deletion notification logs of the personal information source domain deletion entity are randomly selected, and notification consistency audit analysis is performed on these entries. If all these entries are consistent with notifications, there is a certain probability that the personal information source domain deletion entity is consistent with notifications. Similarly, a certain percentage of entries in the deletion operation logs of the personal information source domain and its associated domain deletion entities are randomly selected, and operation compliance audit analysis is performed on these entries. If all these entries are compliant with operation procedures, there is a certain probability that the personal information domain deletion entity is compliant with operation procedures. Specifically, for example, if the target log has r entries, x entries are sampled for auditing, where r, x ∈ Z. * And x ≤ r. Randomly select x distinct random numbers j1, j2…j x , where 1≤j i ≤r and 1≤i≤x, random numbers j1,j2…j x This refers to the location from which the entries are to be extracted.

[0055] Specifically, for example, if there is an audit anomaly in the normalized log of the deletion notification of the subject deleting personal information from the source domain, the auditing subject will extract this first entry and find the corresponding second entry in the deletion notification confirmation log of the associated domain. The auditing subject will analyze whether the target, granularity, and method of personal information deletion in the first entry are consistent with the content in all the second entries and provide a detailed reason for the anomaly.

[0056] Preferably, when issuing real-time alerts for various risks and events, the system will notify and alert the relevant parties in a corresponding manner after a certain number of occurrences of each risk and event, according to the system's preset rules.

[0057] It should be noted that the specific embodiments described above are exemplary, and those skilled in the art can devise various solutions inspired by the disclosure of this invention. These solutions all fall within the scope of this invention and its protection. Those skilled in the art should understand that this specification and its accompanying drawings are illustrative and not intended to limit the scope of the claims. The scope of protection of this invention is defined by the claims and their equivalents.

Claims

1. A trusted third-party auditing method for personal information deletion, characterized in that, The method includes: Obtain log data of any personal information source domain deletion entity and its associated domain deletion entity within the network. The personal information source domain deletion entity is the main data platform or system for personal information management, and the associated domain deletion entity is other data platforms or systems that have personal information collection, use, sharing, or backup relationships with the personal information source domain deletion entity. The log data is normalized using preset parsing rules to generate normalized log data; The normalized log data is analyzed for notification consistency and operational compliance using correlation analysis. Each entry in the normalized log of deletion notifications from the source domain deletion subject is analyzed, and the current analysis entry is defined as the first entry. Based on the key fields in the first entry, the corresponding second entry in the normalized log of deletion notification confirmations from the associated domain deletion subject is found. The notification consistency audit analysis results are obtained based on the existence and content correspondence results of the first and second entries. The existence and content correspondence results refer to the ability to find the corresponding second entry in the normalized log of deletion notification confirmations from the associated domain deletion subject based on the key fields in the first entry. The content correspondence results refer to whether the target, granularity, and method of personal information deletion in the first entry are consistent with those in the second entry. Each entry in the normalized log of deletion operations of the deletion subject in the personal information source domain and its associated domain deletion subjects is analyzed one by one, and the current analysis entry is defined as the first entry. Based on the key fields in the first entry, the corresponding second entry in the normalized log of deletion effect self-evaluation within the same domain is found. The operation compliance audit analysis results are obtained based on the existence correspondence results of the first and second entries and the content compliance results. The existence correspondence results refer to the ability to find the corresponding second entry in the normalized log of deletion effect self-evaluation within the same domain based on the key fields in the first entry. The content compliance results refer to whether the deletion request consistency assessment results, deletion operation consistency assessment results, deletion operation effectiveness assessment results, and deletion irreversibility assessment results in the second entry comply with regulatory requirements.

2. The method according to claim 1, characterized in that, Obtaining log data for any personal information source domain deletion subject and its associated domain deletion subjects within the network includes: The log data includes content data and tag data. The content data is received after the tag data is verified. The content data includes deletion notification logs, deletion notification confirmation logs, deletion operation logs, and deletion effect self-evaluation logs.

3. The method according to claim 2, characterized in that, Normalizing the log data and generating normalized log data by using preset parsing rules includes: Log information is merged by filtering out useless fields in the logs, and key field information in the log data is extracted and reorganized into the corresponding normalized log using the appropriate normalization format.

4. The method according to claim 1, characterized in that, The method further includes: After completing the correlation analysis of the normalized log data, a third-party audit log for personal information deletion is generated; Based on the third-party audit logs of personal information deletion, log data of abnormal personal information deletion can be obtained for backtracking and evidence collection of original log data.

5. The method according to claim 4, characterized in that, Based on the third-party audit logs of personal information deletion, log data of abnormal personal information deletion was obtained for backtracking and evidence collection. The original log data includes: Obtain the audit analysis results on the consistency of notifications and compliance of operations related to the deletion of personal information, locate relevant log data entries, and provide evidence analysis results.

6. A trusted third-party auditing system for personal information deletion, the system being used to execute the trusted third-party auditing method for personal information deletion as described in any one of claims 1 to 5, characterized in that, The system includes at least: The log collection module (1) is configured to acquire several log data of any personal information source domain deletion subject and its associated domain deletion subject within the network; The log analysis module (2) is configured to normalize the log data and generate normalized log data through preset parsing rules, and to perform notification consistency and operation compliance analysis on the normalized log data through correlation analysis.

Citation Information

Patent Citations

  • An apparatus, system, and method for log auditing

    CN106095575B

  • A log auditing method and apparatus

    CN107818150B

  • Operation log auditing method and device, electronic equipment and storage medium

    CN115408229A

  • Server audit management method, device and system

    CN111800295A

  • Privacy computing security auditing method and system

    CN115098890A