摘要
P3P为Web站点公布它们的在使用用户数据时的隐私策略提供了一种标准的方式,用户能够根据其制定的隐私策略来决定自己的响应方式。但这种机制不能监督当Web站点获得用户的数据后对其所采取的非法处理。基于此,本文提出了一种新的安全访问机制,称为在线个人数据许可证(OPDL)机制,在此机制下,用户有权访问和修改其提供给Web站点的数据,同时,站点对用户数据的使用必须通过许可证的方式获得用户的授权。这种机制能保证用户数据不被非法滥用。
P3P provides a standard means for Web sites to disclose their privacy policies when they need users' personal data for processing. A user can then decide whether or not to provide personal data to the sites based on the disclosed policies. However, this mechanism cannot guarantee that Web sites do act according to their policies once they have obtained user's personal data. In light of this, we proposed a new technical and legal approach called Online Personal Data Licensing(OPDL). The idea is that the person has the right to access and modify those data provided to sites, and the use of a person's data must be authorized by the person through the issue of data licenses. Licenses can then be checked to prevent personal data from being misused.
出处
《现代计算机》
2005年第12期37-39,共3页
Modern Computer