You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: docs/src/docs/arc42/runtime-view/data-sovereignty/policy-management.adoc
+69-30Lines changed: 69 additions & 30 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -10,6 +10,17 @@ However, to be sure that data is shared only with companies that match one's req
10
10
The policies used for sending and receiving notifications and parts have an identical data format, so they can be used for each process interchangeably.
11
11
The processes itself are different and will be explained here:
12
12
13
+
== Policy Types
14
+
The EDC Connector MUST provide a possibility to restrict the access of a Data Asset to specific business partners by attribute(s), e.g., represented as a VC.
15
+
The Connector MUST restrict the data usage to partners and purposes for a specific use case.
16
+
17
+
There are two policy types used.
18
+
* Access
19
+
* Usage
20
+
21
+
As specified by the https://github.com/International-Data-Spaces-Association/ids-specification[Dataspace Protocol], one Data Asset MUST refer to at least one Usage Policy, expressed in ODRL.
22
+
For additional information refer to https://eclipse-tractusx.github.io/docs-kits/kits/Connector%20Kit/Adoption%20View/connector_kit_adoption_view[Connector KIT]
|Policies can be created by administrators at any time in the administration section of Trace-X.
32
+
|1
33
+
|Policies can be created by User with role 'Admin' at any time in the administration section of Trace-X. The policy is created to later used for publishing assets in the current company context.
34
+
35
+
|2
36
+
|Policies are stored in the PolicyStore which is a shared component used by Trace-X [A] app and IRS for storing usage and access policies.
23
37
24
38
|3
25
-
|Parts can be imported at any time in the parts section of Trace-X. They will be stored locally at first.
39
+
|Policy is created in the policy store.
26
40
27
41
|4
28
-
|Before connected BPNs can access the imported parts, the parts must be published to the EDC and to the Digital Twin Registry (DTR).
42
+
|User with role 'Admin' receives feedback that creation of policy was successful.
29
43
30
-
|5
31
-
|The user must choose the policy that is used for contract negotiation of the selected parts.
32
-
33
-
|6
34
-
|The policy is created in the EDC.
44
+
|5, 6
45
+
|User with role 'Admin' imports assets in Admin section of Trace-X [A]. Parts can be imported at any time in the parts section of Trace-X. They will be stored locally at first. https://github.com/eclipse-tractusx/traceability-foss/tree/main/tx-backend/testdata[Testdata for asset import]
35
46
36
47
|7
37
-
|Each part is created as a shell in the DTR. This holds all the data of the part.
48
+
|User with role 'Admin' selects assets in transient state in application.
38
49
39
50
|8
40
-
|The created part is linked to the policy from the EDC. This is the last step of data provisioning. Trace-X A has done everything to ensure that companies that have a matching policy can access its published parts.
51
+
|User with role 'Admin' is requested to define a policy for assets publishing.
41
52
42
53
|9
43
-
|Trace-X B wants to synchronize parts and retrieve available ones from connected BPNs. In this case Trace-X A and Trace-X B have an established connection.
54
+
|User with role 'Admin' selects policy under which assets are published. The user must choose the policy that is used for contract negotiation of the selected parts.
44
55
45
-
|10
46
-
|For part synchronization the Item Relationship Service (IRS) is requested.
56
+
|10, 11
57
+
|Assets are created in the EDC. (POST /v3/assets)
47
58
48
-
|11
49
-
|First the IRS must know the policies that are used by Trace-X B, so it requests them directly.
59
+
|12,13
60
+
|Trace-X [A] BE checks if PolicyDefinition for selected policy already exists.
50
61
51
-
|12
52
-
|Trace-X B returns a list of the configured policies depending on the configuration done by the administrator in step 2.
62
+
|14,15
63
+
|In case PolicyDefinition does not exist. New PolicyDefinition is created in EDC [A]. The PolicyDefinition is created in the EDC.
53
64
54
-
|13
55
-
|The IRS requests the catalog from Trace-X A. In the catalog, all policies of Trace-X A are stored.
65
+
|16,17
66
+
|The created part is linked in the PolicyDefinition from the EDC. This is the last step of data provisioning. Trace-X [A] has done everything to ensure that companies that have a matching policy can access its published parts.
56
67
57
-
|14
58
-
|The EDC of Trace-X A provides the catalog.
68
+
|18,19
69
+
|Each part is created as a shell in the DTR. This holds all the data of the part. Before connected BPNs can access the imported parts, the parts must be published to the EDC and to the Digital Twin Registry (DTR).
59
70
60
-
|15
61
-
|The IRS checks the catalog for the required policies and extracts them.
71
+
|20,21
72
+
|User with role 'Admin' in Trace-X [B] creates policy for consuming assets of Trace-X [A].
62
73
63
-
|16
74
+
|22
75
+
|Trace-X [B] wants to synchronize parts and retrieve available ones from connected BPNs. In this case Trace-X [A] and Trace-X [B] have an established connection.
76
+
77
+
|23,24
78
+
|Trace-X [B] requests for globalAssetIds (unique identifier of digital twins (Asset Administration Shell)) in decentral Digital Twin registry.
79
+
80
+
|25
81
+
|For part synchronization a synchronization job is started in the Item Relationship Service (IRS) .
82
+
83
+
|26,27
84
+
|IRS requests for CatalogOffer for globalAssetsIds passed by Trace-X [A]
85
+
86
+
|28
87
+
|IRS extracts policies from CatalogOffer
88
+
89
+
|29,30
90
+
|IRS requests for policies defined for BPNL of Trace-X [A] in PolicyStore of Trace-X [B]
91
+
92
+
|31
64
93
|Now that the IRS has all the relevant policies of both companies, it can start comparing the linked policy of each part to the policy list of Trace-X B. This works by comparing the included constraints logically. If no policy matches for a part, it will not be imported.
65
94
66
-
|17, 18
67
-
|If the policy of the part matches with any policy of Trace-X A, a contract agreement is created for both Trace-X A and Trace-X B. It can be viewed in the administration section of Trace-X and documents the data exchange.
95
+
|32,33,34
96
+
|If the policy of the part matches with any policy of Trace-X A, a contract agreement is created for both Trace-X A and Trace-X B. It can be viewed in the administration section of Trace-X and documents the data exchange. Since the contractAgreementId will be mapped to an submodel of IRS. The contracts can be seen after IRS responded to Trace-X initial sync call with the submodels including the contractAgreementId.
68
97
69
-
|19
98
+
|35
70
99
|Now that the contract negotiation was successful, the data consumption process can take place for that part.
100
+
101
+
|36
102
+
|In case policy does not match IRS created tombstone.
103
+
104
+
|37
105
+
|IRS callbacks Trace-X [B] Instance after completing job processing. ContractAgreementId for asset is available in Trace-X passed in IRS JobResponse.
71
106
|===
72
107
73
108
It's possible to publish parts with different policies. For this, the user must only publish a limited selection of parts for which he can select a policy. For the parts that must be published with different policies, the user can repeat the process.
74
109
110
+
111
+
**Note**:
112
+
For more detailed information concerning the functionality of IRS please refer to https://eclipse-tractusx.github.io/item-relationship-service/docs/[IRS documentation]
113
+
75
114
**[Work-in-progress]** The user may also choose parts that have already been published - they can be republished with a different policy. The process for this is identical to the regular publishing process.
76
115
77
116
== Policies for sending and receiving notifications
Policies always have an expiration time. When a notification is sent and there are policies configured for the selected BPN with an expiration time in the past, Trace-X will throw an error. In that case, an administrator must either update the policy. Then the policy can be resent.
172
+
Policies always have an expiration time defined by the 'validUntil' timestamp. When a notification is sent and there are policies configured for the selected BPN with an expiration time in the past, Trace-X will throw an error. In that case, an administrator must either update the policy. Then the policy can be resent.
134
173
135
174
=== Testing policies
136
175
In order to test the functionality of policies, an administrator can create a policy with test constraints for connected BPNs. When sending notifications to that BPN, the process should be blocked.
Copy file name to clipboardExpand all lines: docs/src/uml-diagrams/arc42/runtime-view/data-provisioning/trace-x-data-import-interface-modul1-sequence.puml
0 commit comments