中图分类号:TP309文献标志码:ADOI:10.19358/j.issn.2097-1788.2026.07.010 中文引用格式:吴超辉,高建彬,宋蒴鑫,等.面向个人数据流通的三方授权条款建模与可验证自动交付机制[J].网络安全与数据治理,2026,45(7):71-79. 英文引用格式:Wu Chaohui, Gao Jianbin,Song Shuoxin, et al. Three-party authorization clause modeling and verifiable automatic delivery mechanism for personal data circulation[J].Cyber Security and Data Governance,2026,45(7):71-79.
Three-party authorization clause modeling and verifiable automatic delivery mechanism for personal data circulation
1. Unit 66015; 2. University of Electronic Science and Technology of China; 3. State Information Center; 4. Sichuan Provincial Big Data Center
Abstract: To address the problems of unclear tripartite authorization boundaries, difficulty in verifying the delivery process, and challenges in tracing dispute liability in personal data circulation, this paper proposes a tripartite authorization clause modeling and verifiable automatic delivery mechanism. The proposed mechanism constructs an authorization clause model consisting of the subject domain, data domain, constraint domain, and responsibility domain. By integrating decentralized identity, digital signatures, and smart contracts, it enables clause registration, state evolution, one-time delivery token issuance, and delivery receipt anchoring. Under a collaborative architecture combining on-chain rule notarization and off-chain controlled delivery, the mechanism establishes a complete closed loop of "authorization activation -condition verification -automatic delivery -result verification -audit and accountability". Experimental results show that the proposed mechanism can support clause-driven automatic delivery while keeping on-chain overhead controllable, and outperforms comparative schemes in terms of abnormal delivery identification rate and accountability.
Key words : personal data circulation; tripartite authorization;authorization clause modeling; smart contract; automatic delivery