IP Library Granted Patent US 12,499,270
Granted Patent B2
US 12,499,270 · App. 18/603,202 · Granted Dec 16, 2025

Method and system for deleting multi copy personal data efficiently and securely

Inventors: Peng Xu (Wuhan, CN); Runze Xu (Wuhan, CN); Wei Wang (Wuhan, CN); Yinjia Pi (Wuhan, CN); Tianyang Chen (Wuhan, CN); Hai Jin (Wuhan, CN)
Assignee: HUAZHONG UNIVERSITY OF SCIENCE AND TECHNOLOGY
G06F21/6245H04L9/088H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,499,270
App. No.
18/603,202
Granted
Dec 16, 2025
Kind
B2
Abstract

A method and system for deleting multi-copy personal data efficiently and securely is provided, wherein the personal data and its subject identifier are signed and uploaded to data domains and stored as personal data copies; the personal data copies along with its source and destination data are circulated among the data domains; the data domain receiving a deletion instruction transmits the deletion instruction to every relevant data domains based on the identifier of the personal data subject and the destination data and then performs deletion; and after completing the deletion, the data domain deposit its domain identifier and feedback data it receives into a log, and feed the log back to its superior data domain. And the system of the present disclosure includes a plurality of data domains that can perform the above operations, thereby realizing association-based storage, association-based deletion and verification of association-based deletion of multi-copy personal data.

Claims (32)

1 . A method for deleting multi-copy personal data efficiently and securely, being executed among data domains, the method comprising:

signing and uploading personal data and an identifier of a personal data subject to the data domains, so that the data domains store the personal data along with the subject identifier as personal data copies;

having the personal data copies, with its source and destination recorded therein, circulated among the data domains;

when any of the data domains receives a deletion instruction, having the data domain transmit the deletion instruction to all relevant data domains based on the identifier of the personal data subject and destination data in the personal data copy and perform deletion; and

after the data domain completes the deletion, having the data domain deposit a domain identifier of itself and feedback data it receives into a log, and feed the log back to its superior data domain;

wherein during the storing step the method further comprises:

performing a Hash operation based on the personal data and the identifier of the personal data subject, and using a private key of the personal data subject to perform a signature operation on a Hash value obtained through the Hash operation, thereby obtaining a digital signature;

wherein the identifier of the personal data subject acts as a globally unique identifier, and

having the personal data subject upload the identifier of the personal data subject, the personal data, and digital signature to a data source domain that is the data domain acting as the source of the personal data;

wherein the personal data copy stored in the data source domain as backup at least stores the identifier of the personal data subject, the personal data, the digital signature, a source domain identifier, and a destination domain identifier, wherein the source domain identifier and the destination domain identifier are initialized as empty;

wherein the source domain identifier stores the identifier of the superior data domain from which the current data copy is circulated, and the destination domain identifier stores the identifier of the inferior data domain to which the current data copy is circulated.

2 . The method of claim 1 , wherein during the circulating step the method further comprises:

having the current propagation domain make a request to the superior domain for backup of the personal data copy based on the identifier of the personal data subject, and alter the source domain identifier and the destination domain identifier in the personal data copy backuped to the current propagation domain, wherein the source domain identifier is altered into the identifier of the superior domain, and the destination domain identifier is reset into empty; and

having the current propagation domain feed the destination domain identifier in the altered personal data copy and the domain identifier of itself back to the superior domain as feedback, so that the superior domain updates the personal data copy of the superior domain based on the feedback of the current propagation domain.

3 . The method of claim 2 , wherein during the circulating step the method further comprises:

the superior domain updates the personal data copy based on the feedback of the current propagation domain through: adding any domain identifier that exists in the feedback but does not exist in the destination domain identifier to the destination domain identifier; and

repeating the step of feeding back and updating, until the data source domain completes updating.

4 . The method of claim 3 , wherein during the deleting and depositing steps the method further comprises:

having the personal data subject send the deletion instruction to the data source domain, so that the data source domain determines the personal data copy to delete based on the identifier of the personal data subject, and sends the deletion instruction to the directly associated data domain based on the destination domain identifier related to the personal data copy; and

having the current propagation domain receiving the deletion request identify the current data copy to delete based on the identifier of the personal data subject, send the deletion instruction to the directly associated data domain based on the destination domain identifier of the current data copy, and then delete the current data copy.

5 . The method of claim 4 , wherein during the deleting and depositing steps the method further comprises:

if the destination domain identifier of the current propagation domain is empty, having the current propagation domain store the identifier of the personal data subject and the domain identifier of itself into the log; or

if the destination domain identifier of the current propagation domain is not empty, having the current propagation domain store the identifier of the personal data subject, the domain identifier of the current propagation domain, and the domain identifier recorded in a deposited log that is fed back by the inferior domain to the current propagation domain, into the log.

6 . The method of claim 5 , wherein during the deleting and depositing steps the method further comprises:

after the current propagation domain deposit the log, having it sign the deposited log using the private key of the current propagation domain, and feed back the signed deposited log to the superior domain; and

having the superior domain unsign the deposited log using the private key of the current propagation domain so as to acquire the domain identifier in the log fed back by the current propagation domain.

7 . The method of claim 6 , wherein while the data domain accesses the personal data copy the method further comprises:

having the current propagation domain download the desired current data copy based on the identifier of the personal data subject;

having the current propagation domain preliminarily analyze the current data copy so as to acquire the digital signature, and select the expected public key based on the identifier of the personal data subject to verify the digital signature; and

if verification succeeds, having the current propagation domain unsign the current data copy so as to acquire the personal data.

8 . The method of claim 7 , wherein every data domain verifies the acquired personal data copy to ensure the acquired personal data Data are not tampered;

the propagation domain D i downloads the personal data copy shared by the source domain according to needs and based on the logic file name LFN having the globally unique identifier.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 1, 2024
From: SU, PENG; XU, RUNZE; WANG, WEI; PI, YINJIA; CHEN, TIANYANG; JIN, HAI
To: HUAZHONG UNIVERSITY OF SCIENCE AND TECHNOLOGY
Reel/Frame 068753/0311 →
Continuity (1)
Related Publication 20240330506A1 · Oct 3, 2024
References Cited (16)
US 11714918B1 · Kondal · 2023 [cited by examiner]
US 12147564B1 · Ma · 2024 [cited by examiner]
US 12260107B1 · Wang · 2025 [cited by examiner]
US 20120324529A1 · Rangachari · 2012 [cited by examiner]
US 20210182240A1 · Dongieux · 2021 [cited by examiner]
US 20220029822A1 · Ubbens · 2022 [cited by examiner]
US 20240421974A1 · Ma · 2024 [cited by examiner]
CN 108418796 · 2018 [cited by applicant]
CN 111092847 · 2020 [cited by applicant]
Ateniese, Giuseppe, et al. “Provable data possession at untrusted stores.” Proceedings of the 14th ACM conference on Computer and communications security. 2007. [cited by applicant]
Du Lln, et al. “Research on Associated Deletion Technology for Multi copy in Cloud and its Application” Xidian University, Jun. 2019. [cited by applicant]
Zhang Cui-ping, Guo Zhen-zhou and Gong Chang-qing. Study on Strategy of Replica Selection in Cloud Storage Environment[J].Computer Science, 2015, 42(Z11): 408-412. [cited by applicant]
Dong Ji-guang Chen Wei-wei Tian Lang-jun Wu Hai-jia. Replica placement study in large-scale cloud storage system[J]. Journal of Computer Applications, 2012, 32(03): 620-624. [cited by applicant]
Xiong, et al. “Security sharing and associated deleting scheme for multi-replica in cloud” vol. 36 No. Z1 Nov. 2015. [cited by applicant]
Liu, et al. “Research on Timed Access of Sensitive Data Based on Dual Encryption” Journal of University of Electronic Science and Technology of China, vol. 46 No. May 3, 2017. [cited by applicant]
Wang-Wei-hua, et al. Journal of HuBei Adult Education Institute, vol. 13, No. Jun. 4, 2007. [cited by applicant]