eclipse-tractusx / sig-release

https://eclipse-tractusx.github.io/sig-release
Apache License 2.0
8 stars 10 forks source link

[R25.03] [Architecture] Propose a B2C tech solution to enable public access of cx-data maintaining Data Sovereignty #924

Open matbmoser opened 3 days ago

matbmoser commented 3 days ago

Overview

As we got to know by the VDA Verband der Automobilindustrie e. V. one of the requirements from the regulations is that a part of the "Battery Passports", "Digital Product Passports" and other products' data MUST be accessed not in B2B by any public consumer. It was noted during a meeting with the Digital Product Pass Expert group and the stutainability domain that Catena-X has currenltly no plan or solution to tackle that.

I have something in mind already, but I would like to propose it formally and discuss it with the architecture committee first

Architecture-Solution mnew drawio

Motivation

Explain the topic in 2 sentences

There MUST be a solution that allows end users to view data from OEMs. Currently, Catena-X supports only, B2B and not B2C because the EDC requires companies to be onboarded in Catena-X.

I want to propose and analyze the impact of enabling a tech solution for B2C interaction while still maintaining the Data Sovereighty, increasing the interoperability with other non-edc dataspaces.

What's the benefit?

Enables any users to use Catena-X Standards and Values (Data Sov, Decentrality, Interoperability, Secure) to retrieve data from B2C. Increasing also the interoperability with multiple networks which do not use the EDC connector.

What are the Risks/Dependencies ?

Detailed explanation

I have drafted a proposal on how can Catena-X maintain their data sovereighty concept, and still be able to handover data throught the EDC to other non-edc dataspaces. Also providing a "public interface" for Customers to retrieve a limited set of data which lies behind the EDC in a Data Source.

This is mandated by regulation, so many organizations are implementing central solutions to enable this kind of behavior. So the idea here is to decentralize the public data provision and enable data sovereignty concepts using SSI.

In this way that the "complete" set of data would be shared via the "EDC" and the regulatory public data using another interface which needs to be proposed and discussed in this feature.

Diagram1-NetworkInteroperabilityOptimization

Current implementation

  1. Eclipse Data Space Connectors (EDC) supports only B2B connections by design.
  2. Catena-X is using just the EDC to retrieve and provide data for companies.
  3. The EU regulations mandate that economic operator companies provide public data to customers.
  4. Currently, Authorities and Customers are not allowed to retrieve data

Proposed improvements

  1. Catena-X propose a standard for providing public data (B2C) with data sovereighty. Provides simple reference implementation.
  2. Authorities and Consumers can retrieve a set of partial data using catena-x B2C interface and visualize the data.
  3. Catena-X will help companies comply with the regulations and it will have success in the market
  4. Companies that require more than just "public" data can use the "Connector" and the policies to retrieve the complete set of data.

Feature Team

Committer

User Stories

Acceptance Criteria

Test Cases

None

Expected Result

Examples

Architectural Relevance

It will enable Catena-X to do B2C data exchanges, maintaining data sovereignty and increasing interoperability.

The following items are ensured (answer: yes) after this issue is implemented:

Justification: This feature will be proposed in the Architecture Management committee

Additional information

Possible Solutions

matbmoser commented 3 days ago

@lgblaumeiser now that I am not inside yet of the Architecture Committee can you let them aware that there is this problem, I have found it yesterday in a meeting with @stanfaldin and the VDA.

I want to take this topic and discuss with them together once I join Catena-X.

matbmoser commented 3 days ago

I would like to create a "sig-architecture" so we can centralize and publish this topics. @stephanbcbauer what do you think about that?

matbmoser commented 16 hours ago

Maybe place the dpp in Cofinity-X? And all then Cofinity-X would enable a public interface, retrieving data from the edcs from companies.

Maybe we could add a new operator company type, which are certified or allowed to provide public data from Catena-X.

Maybe like this:

EDC Public Data Operators drawio