Cryptography-Enhanced Data Spaces: Secure Cross-Domain Data Sharing via IDS Connectors
: Data spaces enable controlled data sharing across organizations while preserving data sovereignty through policy-based governance mechanisms. Frameworks such as the International Data Spaces (IDS) provide standardized infrastructures for secure data exchange; however, they lack native mechanisms for performing computations on confidential data and for securely combining datasets across domains. In current implementations, datasets typically need to be decrypted before analysis, which limits the applicability of data spaces in privacy-sensitive environments and restricts the potential for cross-domain data fusion. To address this limitation, this paper presents an architecture implemented within the TRUSTEE platform that enables privacy-preserving computation on encrypted datasets hosted by IDS connectors. The proposed approach integrates homomorphic encryption (HE) workflows with standard data space connector infrastructures, allowing analytical operations to be performed directly on encrypted data while preserving existing governance and policy enforcement mechanisms. As a result, raw datasets remain protected within the provider environment throughout the computation lifecycle, and only the final computation results are shared with authorized participants. The proposed architecture is validated through a proof-of-concept demonstrating encrypted data fusion across multiple domains using TRUSTEE and IDS-based infrastructures. The evaluation confirms the feasibility, interoperability, and practical applicability of the approach for enabling secure secondary use of data and privacy-preserving cross-domain analytics in federated data space environments.