Usage Control in the International Data Spaces
- 1. Fraunhofer IESE
- 2. Fraunhofer IAIS
- 3. Fraunhofer IOSB
- 4. Fraunhofer AISEC
- 5. Fraunhofer ISST
- 6. Fraunhofer IML
Description
In this report, we focus on data usage control and data provenance that are conceptual and technological solutions to cope with data sovereignty challenges. We introduce a common scenario for the Industry 4.0 age, in which a supplier and an original equipment manufacturer (OEM) are exchanging data to mitigate risks in the supply chain management. We describe the difference between access control and usage control, the usage control concepts and related concepts such as digital rights management or user managed access. We present the implementation of data usage control in the IDS. In doing so, we present possible integration layers and its integration with the IDS Reference Architecture Model. In addition, we also present the IDS Usage Control Object as a way to transfer usage control metadata between connectors. We explain the topic of policy specification in the IDS by presenting the information model and policy language, the IDS policy classes and the IDS policy editor, which supports data owners to expressing usage restrictions. Furthermore, we show how we handle policy transformation to machine-readable policies as well as policy handshake and negotiation in the IDS. As there are different ways to implement data usage control, we present three approaches researched and developed within Fraunhofer: The MYDATA Control Technologies, the Logic-based Usage Control and Degree. Every technology is presented in detail including its integration concepts. Finally, we compare these technologies and discuss them. We address data provenance as additional concept to data usage control to cope with transparency and accountability. We conclude the document by elaborating on the current state and presenting future work, like the role of usage control in the App Store and automated IDS contract negotiation.