中圖分類號:TP311文獻標志碼:ADOI:10.19358/j.issn.2097-1788.2026.07.011 中文引用格式:夏虎,吳志剛,劉濟銘,等.面向個人數(shù)據(jù)要素化的可信授權(quán)系統(tǒng)設(shè)計[J].網(wǎng)絡(luò)安全與數(shù)據(jù)治理,2026,45(7):80-86. 英文引用格式:Xia Hu, Wu Zhigang, Liu Jiming. Design of a trusted authorization system for personal data factorization[J].Cyber Security and Data Governance,2026,45(7):80-86.
Design of a trusted authorization system for personal data factorization
1. School of Computer Science and Engineering, University of Electronic Science and Technology of China; 2. China Electronics Information Industry Development Research Institute;3. Unit 66015
Abstract: To address three core challenges in the process of personal data factorization—insufficient protection of data subjects′ rights and interests, unclear technical implementation paths, and the absence of a universal framework—this paper proposes and constructs an endtoend trusted authorization framework for personal data factorization. The framework integrates existing technologies including decentralized identifiers, verifiable credentials, zeroknowledge proofs, and smart contracts, forming a closedloop mechanism that covers the entire lifecycle of authorization, usage, metering, revenue distribution, and audit. Guided by the four design goals of ownership attribution, autonomous management, privacy preservation, and revenue attribution, the framework achieves identity autonomy and context isolation through a layered DID architecture, enables finegrained permission control via intentbased verifiable credentials and fieldlevel authorization policies, realizes automatic revenue attribution through onchain metering and smart contractbased batch distribution, and ensures data usability without plaintext exposure by leveraging zeroknowledge proofs and homomorphic encryption. A prototype system built on opensource tools has been functionally validated in typical data usage scenarios. The results demonstrate that the framework supports layered identity management, finegrained authorization, privacypreserving data delivery, onchain metering, and automated batch distribution, with all critical operations recorded onchain and independently verifiable. The cost evaluation demonstrates that the gas consumption for a single complete data access and revenuesplitting process is estimated to 1.58 million gas, indicating that the economic cost is manageable.
Key words : data factorization; personal data; decentralized identity; verifiable credential