Authentication and authorization in Data Spaces: A relationship-based access control approach for policy specification based on ODRL

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Plaza-Ortiz, Irene, Munoz-Arcentales, Andres, Salvachúa, Joaquín, Aparicio, Carlos, Huecas, Gabriel, Barra, Enrique
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915313823514624
author Plaza-Ortiz, Irene
Munoz-Arcentales, Andres
Salvachúa, Joaquín
Aparicio, Carlos
Huecas, Gabriel
Barra, Enrique
author_facet Plaza-Ortiz, Irene
Munoz-Arcentales, Andres
Salvachúa, Joaquín
Aparicio, Carlos
Huecas, Gabriel
Barra, Enrique
contents Data has become a crucial resource in the digital economy, fostering initiatives for secure and sovereign data sharing frameworks such as Data Spaces. However, these distributed environments require fine-grained access control mechanisms that balance openness with sovereignty and security. This paper proposes an extension of the Open Digital Rights Language (ODRL) standard, the ODRL Data Spaces (ODS) profile, aimed at supporting authorization and complementing existing authentication mechanisms throughout the data lifecycle. Additionally, a policy execution engine is introduced to translate ODRL policies into executable formats, enabling effective enforcement. The approach is validated through a use case involving OpenFGA, demonstrating its applicability to relationship-based access control scenarios.
format Preprint
id arxiv_https___arxiv_org_abs_2505_24742
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Authentication and authorization in Data Spaces: A relationship-based access control approach for policy specification based on ODRL
Plaza-Ortiz, Irene
Munoz-Arcentales, Andres
Salvachúa, Joaquín
Aparicio, Carlos
Huecas, Gabriel
Barra, Enrique
Cryptography and Security
Emerging Technologies
Data has become a crucial resource in the digital economy, fostering initiatives for secure and sovereign data sharing frameworks such as Data Spaces. However, these distributed environments require fine-grained access control mechanisms that balance openness with sovereignty and security. This paper proposes an extension of the Open Digital Rights Language (ODRL) standard, the ODRL Data Spaces (ODS) profile, aimed at supporting authorization and complementing existing authentication mechanisms throughout the data lifecycle. Additionally, a policy execution engine is introduced to translate ODRL policies into executable formats, enabling effective enforcement. The approach is validated through a use case involving OpenFGA, demonstrating its applicability to relationship-based access control scenarios.
title Authentication and authorization in Data Spaces: A relationship-based access control approach for policy specification based on ODRL
topic Cryptography and Security
Emerging Technologies
url https://arxiv.org/abs/2505.24742