A blockchain-governed SSI trust architecture for EDC-based federated data spaces
The usage of blockchain technologies incorporates a trust layer due to its immutability and transparency for all participants. The implementation of this technology in order to validate and authenticate the identity of different entities in a Data Spaces ecosystem, allows to all the contributors to validate which of them have certain sets of traits suitable for their data sharing, interests, and moreover, role managing. This way, connectors can automatically identify with who they are interacting and choose which data to share with them based on these characteristics. Some useful examples are the detection of certain issued verifiable credentials that prove their belonging to a specific sector, accreditations … that automatically provide them with access to specific datasets. In order to achieve this, the presented Trust Layer uses a governance infrastructure with blockchain, an identity layer to store private keys and connect the blockchain address to a decentralized identifier, and a credential manager to issue and verify the Verifiable Credentials. Added to this, an integration layer is designed and implemented, which connects these components to the Data Space Connector. For this specific technical implementation, the design has been built to be operable with Eclipse Dataspace Components (EDC), given its Verifiable Credentials interoperability and its wide adoption among Data Spaces as their preferred connector. A qualitative discussion of the architecture’s strengths and challenges is provided, covering aspects such as decentralization, regulatory alignment, and adoption barriers, together with a comparison against alternative identity and trust models for federated data spaces.