🤖 AI Summary
To address challenges in data spaces—including difficult integration of metadata catalogs with connectors, weak cross-domain interoperability, and compromised data sovereignty due to tight coupling between policies and metadata—this paper proposes a hybrid federated architecture that decouples metadata management from access policy enforcement. We build an extensible federated metadata catalog atop DataHub, supporting multi-source data ingestion and end-to-end lineage governance. Additionally, we design and implement Rainbow Catalog, a custom ODRL-compliant policy engine enabling fine-grained access control policy modeling, publication, and dynamic enforcement, tightly integrated with metadata querying. The architecture strictly adheres to the International Data Spaces (IDS) reference architecture and protocol specifications. Evaluation demonstrates significant improvements in cross-domain data sharing security, automation, and standardized interoperability—while rigorously preserving data sovereignty.
📝 Abstract
In the digital era, data spaces are emerging as key ecosystems for the secure and controlled exchange of information among participants. To achieve this, components such as metadata catalogs and data space connectors are essential. This document proposes an implementation and integration solution for both elements, considering standardization guidelines for data formats, metadata, and protocols, which ensures interoperability. A hybrid solution is presented: DataHub is used as a federated catalog for robust metadata management, leveraging its advanced ingestion, governance, and lineage capabilities. On the other hand, a custom implementation, Rainbow Catalog, manages ODRL policies for access and usage. This integration makes it possible to query datasets from DataHub and associate them with ODRL policies, facilitating negotiation and transfer flows defined by the Dataspace Protocol. The result is a system that combines the power of DataHub for large-scale cataloging with the policy management of the connector crucial for sovereignty and trust in data spaces.