In the modern digital economy, data is a collaborative asset. Companies, healthcare institutions, and research groups increasingly need to share valuable data across organizational boundaries to co-create AI models and advanced services. However, this necessity creates a fundamental tension: how do you share data without losing control over it?
During Talk 06 of ENSURE-6G Event #6, Dr. Marcela Tuler from TU Delft addressed this critical challenge, presenting her research on building Trustworthy Data Systems Across Organizational Boundaries. The presentation delved into advanced cryptographic techniques, attribute-based access control, and the role of decentralized smart contracts in ensuring data sovereignty.
The Pillars of Organizational Trust
For organizations to confidently share data, they require trustworthiness based on three core pillars:
- Ability/Confidentiality: Can the data controller guarantee that sensitive information is kept confidential?
- Integrity: Can the organization ensure that the data has not been compromised, poisoned, or altered?
- Benevolence/Availability: Can the organization guarantee that the data won’t be used for malevolent purposes, while ensuring it remains available when needed?
Fear of violating these pillars has created a data silo effect. Companies are so afraid of losing control—or losing the ability to enforce the conditions of data processing—that they simply refuse to share it.
Achieving Data Sovereignty: Ex-Ante vs. Ex-Post Policies
To break down these silos, data providers must retain self-determination over their data even after sharing it. This is achieved through strict policy enforcement at two stages:
- Ex-Ante Policies: Rules defined and enforced before data usage (e.g., Who gets access? Under what context?).
- Ex-Post Policies: Rules evaluated during and after usage (e.g., Was the data used correctly downstream? Was it deleted after the agreed time?).
While Ex-Post auditing remains a complex open challenge in the industry, Dr. Tuler’s research presented significant breakthroughs in enforcing Ex-Ante policies using hybrid cryptography and blockchain technology.
Hybrid Cryptography: Combining Efficiency with Granular Control
To guarantee confidentiality without relying entirely on potentially “curious” central cloud providers, the research leverages a hybrid cryptographic approach:
- Symmetric Encryption (The Locker): Because large datasets (like healthcare images or heavy sensor logs) require efficient encryption, the actual data is secured using a highly efficient symmetric key.
- Attribute-Based Encryption (The Lock): The symmetric key itself is then encrypted using Ciphertext-Policy Attribute-Based Encryption (CP-ABE).
Instead of generating keys based solely on identity, CP-ABE generates keys based on policies and attributes. For example, a policy might dictate that the key can only be decrypted by someone who simultaneously holds the attributes of “Neurologist” AND “Emergency Team Member.”
Decentralizing Access Control via Smart Contracts
To make this system work across multiple untrusting organizations, the access control mechanism itself must be decentralized.
Traditionally, Attribute-Based Access Control (ABAC) relies on a centralized decision point (PDP) to evaluate policies. Dr. Tuler’s team successfully migrated this logic into a permissioned blockchain using smart contracts (deployed on Hyperledger Besu as part of the Horizon Europe ExtremeXP project).
- How it works: When a user requests data, the request is intercepted and sent to a smart contract on the blockchain. The smart contract, which acts as persistent, immutable code, evaluates the user’s attributes (e.g., their role, geolocation, or working hours) against the predefined policies.
- The Result: The decision to grant or deny access is recorded immutably on the ledger, providing a fully transparent, auditable trail of who accessed what data and why—without requiring a centralized trust authority.
Despite the added complexity of consensus mechanisms, the system maintained highly stable, predictable response times with minimal latency overhead, proving it feasible for real-world enterprise deployment.
Future Directions: Enforcing the “Aftermath”
With robust Ex-Ante controls now feasible via smart contracts, the research team is turning its attention to the Ex-Post challenge. Future work will focus on integrating Self-Sovereign Identities and developing trigger-based mechanisms to enforce downstream obligations. The ultimate goal? Ensuring that once data is shared, rules like “do not reshare,” “delete after 30 days,” or “purpose limitation” are not just legally binding, but technologically guaranteed.
Watch the Full Talk: