Traceable data self-destruction method

By combining server-side and client-side data self-destruction methods, the problems of incomplete data destruction and inflexible strategies are solved, enabling refined management and full-process traceability of the data lifecycle, and improving the compliance and security of data governance.

CN121901162APending Publication Date: 2026-04-21FUZHOU BIDA NETWORK TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
FUZHOU BIDA NETWORK TECH CO LTD
Filing Date
2026-02-12
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

Existing data destruction methods suffer from incomplete destruction, inflexible strategies, and a lack of operational log recording and traceability capabilities, making it difficult to meet compliance requirements.

Method used

The system employs a server-side and client-side architecture, utilizing a policy-driven automated data destruction mechanism and a full-process traceability mechanism to achieve closed-loop management of the data lifecycle. The server is responsible for policy formulation, distribution, and auditing, while the client is responsible for data synchronization, policy execution, and feedback, ensuring the reliability and traceability of data destruction.

Benefits of technology

It achieves refined control, irreversibility, full-chain traceability, and efficient management of data destruction, thereby improving the compliance and security of data governance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure FT_1
    Figure FT_1
  • Figure FT_2
    Figure FT_2
Patent Text Reader

Abstract

The invention discloses a traceable data self-destruction method, and relates to the field of data security and life cycle management. The method is composed of a server side and a client side, the server side transmits a data self-destruction strategy to the client side through a strategy issuing channel, and the client side reports a data state and a destruction execution result to the server side through a state reporting channel. The server comprises a user system, a log record, a file server, an auditing tool and a self-destruction strategy pool; the client comprises a data synchronizer, a self-destruction strategy execution unit and a self-destruction tool. According to the method, through combination of strategy driving and whole-process log recording, safe, reliable and automatic destruction and whole-process auditing and tracing of data are realized, and the compliance and safety of data management are effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data security and lifecycle management, specifically to a traceable data self-destruction method. Background Technology

[0002] In today's digital age, data has become one of the most critical assets, making its security and lifecycle management paramount. Especially for data involving sensitive information or time-sensitive data, ensuring its secure and thorough destruction after it has fulfilled its purpose, and preventing data leakage or misuse, presents a significant challenge in the field of information security. Traditional data destruction methods such as file deletion or disk formatting often fail to achieve true physical erasure, and the processes lack transparency and auditability, failing to meet increasingly stringent compliance requirements and addressing the risks associated with data retention on distributed terminal devices.

[0003] To address the aforementioned need for secure data destruction, existing technologies have proposed several solutions. For example, some solutions employ a policy-based data security management method, which distributes security policies to clients via a central server. Clients then encrypt or control access to local files according to these policies. While this approach provides some protection, its core focus is on controlling access rather than destroying data, and it lacks complete recording and traceability of destruction actions, making it impossible to verify whether data has been effectively deleted. Other solutions utilize a timed destruction mechanism, setting a lifespan for files and automatically triggering deletion upon expiration. However, this type of method typically only performs system-level logical deletion, leaving the data potentially recoverable. Furthermore, its single destruction strategy cannot adapt to the varying requirements of destruction trigger conditions and intensity across different scenarios. Additionally, the entire destruction process is like a black box, lacking crucial operational logs for post-event auditing.

[0004] In summary, existing data destruction methods generally suffer from incomplete destruction and inflexible strategies. This invention aims to provide a traceable data self-destruction method that combines a policy-driven automated destruction mechanism with complete operation log recording to achieve closed-loop secure management of the data lifecycle. This invention ensures that sensitive data is reliably and irreversibly destroyed after specified conditions are met, while providing end-to-end traceability credentials. This significantly improves the compliance and security of data governance, and has significant social benefits for protecting personal privacy, corporate trade secrets, and important national data assets. Summary of the Invention

[0005] To address these issues, this invention provides a traceable data self-destruction method.

[0006] The present invention is achieved through the following technical solution: a traceable data self-destruction method, consisting of two core parts, a server (1) and a client (2), to realize policy-based controllable data destruction and full-process traceability, characterized in that: the server (1) is connected to the client (2) through a policy distribution channel (3) to transmit the data self-destruction policy to the client; the client (2) is connected to the server (1) through a status reporting channel (4) to report the data status and destruction execution result to the server.

[0007] The server (1) as described in claim 1 is responsible for managing users, policies, files and audit logs, characterized in that: it includes a user system unit (5), a log recording unit (6), a file server unit (7), an audit tool unit (8) and a self-destruction policy pool unit (9); the user system unit (5) is connected to the self-destruction policy pool unit (9) and is used to associate policies based on user identity; the self-destruction policy pool unit (9) is connected to the client (2) through the policy distribution channel (3); the log recording unit (6) and the audit tool unit (8) are respectively connected to the user system unit (5), the file server unit (7) and the self-destruction policy pool unit (9).

[0008] The client (2) as described in claim 1 is responsible for performing data synchronization, policy implementation and data destruction, characterized in that: it includes a data synchronizer (10), a self-destruction policy execution unit (11) and a self-destruction tool (12); the data synchronizer (10) is connected to the self-destruction policy execution unit (11); the self-destruction policy execution unit (11) is connected to the self-destruction tool (12); the data synchronizer (10) is connected to the server (1) through the status reporting channel (4); the self-destruction policy execution unit (11) is connected to the server (1) through the policy distribution channel (3).

[0009] The user system unit (5) as described in claim 2 is responsible for managing user identity information and its associated policies. It is characterized in that it is directly connected to the self-destruction policy pool unit (9) and is used to determine and issue the corresponding self-destruction policy based on the login user identity of the client (2).

[0010] The self-destruction policy pool unit (9) as described in claim 2 is responsible for storing and managing data self-destruction policies. It is characterized in that: it is connected to the self-destruction policy execution unit (11) of the client (2) through the policy distribution channel (3) and is used to distribute policies to the client.

[0011] The log recording unit (6) as described in claim 2 is responsible for recording system operation and policy execution logs. It is characterized in that it is connected to the user system unit (5), the file server unit (7) and the self-destruction policy pool unit (9) and is used to record user operations, file changes and policy issuance events.

[0012] The audit tool unit (8) as described in claim 2 is responsible for auditing and analyzing logs to provide traceability capabilities, characterized in that it is directly connected to the log recording unit (6) and is used to analyze log records and generate traceable audit reports.

[0013] The data synchronizer (10) as described in claim 3 is responsible for continuously synchronizing newly added files and logs on the client side, characterized in that: it is connected to the server (1) through the status reporting channel (4) and is used to synchronize newly added files and operation logs on the client side to the server side.

[0014] The self-destruction policy execution unit (11) as described in claim 3 is responsible for receiving and executing the self-destruction policy issued by the server. Its feature is that it receives the policy instruction from the server (1) through the policy issuance channel (3) and triggers the self-destruction tool (12) when the policy conditions are met.

[0015] The self-destruct tool (12) as described in claim 3 is responsible for performing specific data destruction operations. Its features are: it is directly connected to the self-destruct strategy execution unit (11) and is used to perform irreversible destruction processing on the specified data according to the strategy instructions.

[0016] Compared with traditional data destruction methods, the traceable self-destruction method proposed in this invention has the following advantages: 1. Achieve centralized and refined management of data destruction strategies. Traditional data destruction often relies on end-user self-management or simple scripts, resulting in fragmented strategies, inconsistent execution standards, and difficulty in meeting unified compliance requirements. This invention centrally manages a self-destruction strategy pool on the server side, and can issue differentiated destruction instructions to various clients based on data security level, business scenario, compliance period, and other dimensions. These instructions include triggering conditions, destruction targets, and destruction intensity, achieving standardized and refined governance of end-of-life data disposal.

[0017] 2. Ensure the reliability and irreversibility of the data destruction process. Traditional deletion operations often remain at the file system logic level, making data easily recoverable through technical means and posing a risk of leakage. This invention's client has a built-in professional self-destruction tool that can execute data erasure operations that comply with security standards according to policies, ensuring that data is physically destroyed and unrecoverable. Simultaneously, the server ensures the legitimacy of the identity used to issue policies through the user system, guaranteeing the reliability of destruction commands from the source.

[0018] 3. Build a fully auditable data destruction traceability capability. Traditional data destruction activities often lack effective records, making it difficult to trace and assign responsibility after an incident. This invention uses a server-side logging system and auditing tools to fully record key events such as policy issuance, client reception, and execution feedback. Combined with logs reported by the client's data synchronizer, a complete chain of evidence is formed from policy formulation to data destruction, meeting the traceability requirements of internal audits and external compliance checks for data destruction activities.

[0019] 4. Improve the efficiency of automated management of distributed terminal data. In scenarios with a large number of widely distributed terminal devices, manual monitoring and destruction of data is costly and prone to omissions. This invention starts a data synchronizer upon client startup, continuously monitoring and reporting new files, enabling the server to dynamically perceive data distribution. Through policy-driven mechanisms, specific data on designated terminals can be automatically and accurately located and destroyed, greatly improving the automation level and response speed of massive terminal data management.

[0020] 5. Enhanced system architecture compatibility and deployment flexibility. This invention employs a loosely coupled server-side and client-side design, communicating through standardized interfaces. Server-side components can be deployed and expanded independently, while the client is compatible with mainstream operating system environments. This design enables the system to flexibly adapt to the existing IT architectures of different organizations, supporting a smooth evolution from local pilot projects to large-scale deployments, and reducing deployment and integration costs. Attached Figure Description

[0021] Figure 1 Process description for specific implementation on the server side Figure 2 Detailed process description for client-side implementation Detailed Implementation

[0022] The specific embodiments of the present invention will now be described clearly and in detail with reference to the accompanying drawings. The described embodiments are merely a part of the embodiments of the present invention.

[0023] The technical solution of this invention to solve the above-mentioned technical problems is: a traceable data self-destruction method. This invention includes two main parts: a server and a client. The server consists of a user system, a log system, a file server, an auditing tool, and a self-destruction policy pool; the client includes a data synchronizer, a self-destruction policy, and a self-destruction tool.

[0024] 1) Server The server is the central management unit for the entire method, responsible for strategy formulation, instruction issuance, status monitoring, and post-event auditing. User system management: The server maintains a unified user system, performing identity authentication and permission verification on requesting clients. Only authorized users' clients can successfully log in and receive self-destruction policies matching their permissions. This ensures the legitimacy and security of the policy distribution source, forming the basis for tracing the responsible party. Self-destruction policy pool management: The self-destruction policy pool is the core component for storing and managing all data destruction policies. Administrators configure policies through auditing tools. A policy must include at least the following elements: applicable objects, target data characteristics, destruction trigger conditions, destruction strength requirements, and feedback requirements after execution. Policy issuance and command transmission: Based on the client's logged-in user identity, the server matches and issues the corresponding self-destructing policy from the policy pool to the client. The issuance process is conducted through a secure encrypted channel to ensure the confidentiality and integrity of command transmission. The file server can be used to store and distribute necessary resources or reference files related to policy execution; The server-side logging system comprehensively records all critical events, including but not limited to: client login / logout events, policy distribution records for each client, and received client execution feedback. All logs are tamper-proofed and indexed for efficient querying. Auditing Tools: The auditing tools provide an interactive interface for administrators to configure policies, maintain policy pools, and view client online status and policy execution overviews in real time. More importantly, the auditing tools can correlate and query server logs with client-reported logs, enabling full-process tracing and audit analysis of any data destruction operation and generating audit reports.

[0025] II) Client The client is the specific execution terminal of the data self-destruction policy, responsible for monitoring local data, policy execution, and status feedback. The specific implementation method is as follows: Data Synchronizer: The data synchronizer automatically starts after the client boots up. This component continuously monitors newly added and modified files and logs in a specified local directory or the entire disk on the client, and synchronizes and reports their metadata to the server. This allows the server to have near real-time knowledge of the data asset status of each terminal, providing a basis for accurately formulating and issuing destruction strategies; Self-destruction policy reception and parsing: The client receives the self-destruction policy from the server and stores and parses it securely locally. The parsing process converts the abstract conditions in the policy into specific indicators that can be monitored and judged locally; Policy condition monitoring and triggering: The client runs a monitoring process in the background to continuously detect whether the local environment meets the destruction triggering conditions defined in the loaded policy; Self-destruct tool execution: Once the triggering conditions of a certain policy are detected, the client immediately invokes the built-in self-destruct tool. This tool performs secure destruction operations on the target data specified in the policy, based on the destruction strength defined in the policy. The destruction operation goes beyond simple file deletion; it employs a data erasure algorithm that conforms to information security standards to write to the corresponding sectors of the storage medium, ensuring that the data is physically and irreversibly destroyed. Execution Feedback and Log Reporting: After the self-destruction tool completes its execution, regardless of success or failure, the client generates detailed local execution logs. The logs include the triggered policy ID, the time of the destruction operation, the list of target files, the destruction method used, and the execution result status code. The client then reports this execution log to the server-side logging system, forming a closed loop with the server-side command records, thus creating a complete chain of evidence for traceability.

Claims

1. A traceable data self-destruction method, consisting of two core parts: a server (1) and a client (2), realizes policy-based controllable data destruction and full-process traceability, characterized in that: The server (1) connects to the client (2) through the policy distribution channel (3) and transmits the data self-destruction policy to the client; The client (2) connects to the server (1) through the status reporting channel (4) and reports the data status and destruction execution result to the server.

2. The server (1) as described in claim 1, responsible for managing users, policies, files, and audit logs, characterized in that: It includes a user system unit (5), a log recording unit (6), a file server unit (7), an auditing tool unit (8), and a self-destruction policy pool unit (9); The user system unit (5) is connected to the self-destruction policy pool unit (9) and is used to associate policies based on user identity. The self-destruction policy pool unit (9) is connected to the client (2) through the policy distribution channel (3); The log recording unit (6) and the audit tool unit (8) are respectively connected to the user system unit (5), the file server unit (7) and the self-destruction policy pool unit (9).

3. The client (2) as described in claim 1, responsible for performing data synchronization, policy implementation, and data destruction, characterized in that: It includes a data synchronizer (10), a self-destruction policy execution unit (11), and a self-destruction tool (12). The data synchronizer (10) is connected to the self-destruction policy execution unit (11); The self-destruction strategy execution unit (11) is connected to the self-destruction tool (12); The data synchronizer (10) is connected to the server (1) through the status reporting channel (4); The self-destruction policy execution unit (11) is connected to the server (1) through the policy distribution channel (3).

4. The user system unit (5) as described in claim 2, responsible for managing user identity information and its associated strategies, characterized in that: It is directly connected to the self-destruction policy pool unit (9) and is used to determine and issue the corresponding self-destruction policy based on the login user identity of the client (2).

5. The self-destruction policy pool unit (9) as described in claim 2, responsible for storing and managing data self-destruction policies, characterized in that: The policy is connected to the self-destructing policy execution unit (11) of the client (2) through the policy distribution channel (3) and is used to distribute policies to the client.

6. The log recording unit (6) as described in claim 2, responsible for recording system operation and policy execution logs, characterized in that: It is connected to the user system unit (5), the file server unit (7) and the self-destruction policy pool unit (9) to record user operations, file changes and policy issuance events.

7. The audit tool unit (8) as described in claim 2, responsible for auditing and analyzing logs to provide traceability capabilities, characterized in that: It is directly connected to the log recording unit (6) and is used to analyze log records and generate traceable audit reports.

8. The data synchronizer (10) as described in claim 3, responsible for continuously synchronizing newly added files and logs on the client, characterized in that: The status reporting channel (4) is connected to the server (1) to synchronize the new files and operation logs added by the client to the server.

9. The self-destruction policy execution unit (11) as described in claim 3, responsible for receiving and executing the self-destruction policy issued by the server, characterized in that: The policy instruction from the server (1) is received through the policy distribution channel (3), and the self-destruct tool (12) is triggered when the policy conditions are met.

10. The self-destruct tool (12) as described in claim 3, responsible for performing specific data destruction operations, characterized in that: It is directly connected to the self-destruction policy execution unit (11) and is used to perform irreversible destruction processing on the specified data according to the policy instructions.