DelRightGuard: A secure yet lightweight data deletion notification distribution protocol for safeguarding right to deletion

Qipeng Song, Ruiyun Wang, Yue Li, Yiheng Yan, Xingyue Zhu, Hui Li
{"title":"DelRightGuard: A secure yet lightweight data deletion notification distribution protocol for safeguarding right to deletion","authors":"Qipeng Song,&nbsp;Ruiyun Wang,&nbsp;Yue Li,&nbsp;Yiheng Yan,&nbsp;Xingyue Zhu,&nbsp;Hui Li","doi":"10.1016/j.jiixd.2024.11.001","DOIUrl":null,"url":null,"abstract":"<div><div>In recent years, the right to deletion of individual has been recognized by many privacy protection laws and regulations. It stipulates that the data controller receiving individual data deletion request shall not only erase the required data, but also take reasonable steps to inform other data controllers to delete the same data. Prior to irrecoverable data erasure, it is of paramount importance to design a distribution and acknowledgement process of deletion notifications across involved data controllers. The design of such a mechanism is faced with the following challenges: 1) completeness: Ensuring that all relevant data controllers, who possess the data slated for erasure, are duly informed; 2) robustness: Immune from malicious attacks when deletion notifications traverse through untrusted networks; 3) lightweight: Reduce the right to deletion compliance cost and accommodate more deletion requests for data controllers. To this end, this article proposes DelRightGuard, which is the first attempt to tackle with the aforementioned challenges. DelRightGuard is built on a cross-plane cooperation architecture between regulatory and service planes. Within regulatory plane, DelRightGuard proposes a cuckoo filters based on data circulation recording algorithm to efficiently ensure the completeness of deletion notifications. Within service plane, DelRightGuard devises a secure yet lightweight deletion notification distribution protocol that runs on a network function hosted by each data controller. This protocol employs HMAC based hop-by-hop forward traversal verification, recursive backward acknowledgement and probabilistic sampling verification, so that it ensure the robustness and lightweight of deletion notification distribution process. We implement a prototype for DelRightGuard. The experimental result confirms that it is practical with acceptable performance.</div></div>","PeriodicalId":100790,"journal":{"name":"Journal of Information and Intelligence","volume":"3 4","pages":"Pages 303-325"},"PeriodicalIF":0.0000,"publicationDate":"2025-07-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of Information and Intelligence","FirstCategoryId":"1085","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S2949715925000083","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

In recent years, the right to deletion of individual has been recognized by many privacy protection laws and regulations. It stipulates that the data controller receiving individual data deletion request shall not only erase the required data, but also take reasonable steps to inform other data controllers to delete the same data. Prior to irrecoverable data erasure, it is of paramount importance to design a distribution and acknowledgement process of deletion notifications across involved data controllers. The design of such a mechanism is faced with the following challenges: 1) completeness: Ensuring that all relevant data controllers, who possess the data slated for erasure, are duly informed; 2) robustness: Immune from malicious attacks when deletion notifications traverse through untrusted networks; 3) lightweight: Reduce the right to deletion compliance cost and accommodate more deletion requests for data controllers. To this end, this article proposes DelRightGuard, which is the first attempt to tackle with the aforementioned challenges. DelRightGuard is built on a cross-plane cooperation architecture between regulatory and service planes. Within regulatory plane, DelRightGuard proposes a cuckoo filters based on data circulation recording algorithm to efficiently ensure the completeness of deletion notifications. Within service plane, DelRightGuard devises a secure yet lightweight deletion notification distribution protocol that runs on a network function hosted by each data controller. This protocol employs HMAC based hop-by-hop forward traversal verification, recursive backward acknowledgement and probabilistic sampling verification, so that it ensure the robustness and lightweight of deletion notification distribution process. We implement a prototype for DelRightGuard. The experimental result confirms that it is practical with acceptable performance.
DelRightGuard:一个安全但轻量级的数据删除通知分发协议,用于保护删除权
近年来,个人删除权得到了许多隐私保护法律法规的认可。它规定,收到个人数据删除请求的数据控制者不仅要删除所需的数据,还要采取合理的步骤通知其他数据控制者删除相同的数据。在不可恢复的数据擦除之前,设计一个跨相关数据控制器的删除通知的分发和确认过程是至关重要的。这种机制的设计面临以下挑战:1)完整性:确保所有拥有预定擦除数据的相关数据控制器都得到适当通知;2)健壮性:当删除通知通过不受信任的网络时,免受恶意攻击;3)轻量化:降低删除权合规成本,容纳数据控制器更多的删除请求。为此,本文提出了DelRightGuard,这是解决上述挑战的第一次尝试。DelRightGuard基于监管平面和业务平面的跨平面协作架构。在监管平面内,DelRightGuard提出了一种基于数据循环记录算法的布谷鸟过滤器,有效保证删除通知的完整性。在业务平面内,DelRightGuard设计了一个安全而轻量级的删除通知分发协议,该协议运行在每个数据控制器托管的网络功能上。该协议采用基于HMAC的逐跳前向遍历验证、递归后向确认和概率抽样验证,保证了删除通知分发过程的鲁棒性和轻量化。我们实现了DelRightGuard的原型。实验结果证实了该方法的实用性和可接受的性能。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信