TDS
Decoding the Technical Architecture of Trusted Data Spaces
01
Trusted Data Spaces: Enabling Secure Data "Flow"
The Essence of Trusted Data Spaces (TDS)
A Trusted Data Space (TDS) fundamentally addresses the core challenges of trust, security, and efficiency in data circulation through technological solutions. To draw an analogy: if data circulation is the "highway" of modern society, then the TDS serves as its traffic lights, surveillance systems, and toll stations—not only ensuring secure data passage but also safeguarding the rights and interests of all participants. This chapter will explore the technical pain points to reveal the core value of TDS.
What is a Trusted Data Space?
A TDS is a technical framework that enables multi-party data sharing and collaboration while maintaining clear data sovereignty and controlled privacy. At its core, it functions as a "data secure enclave"—allowing participants to conduct joint modeling, analysis, and other operations without surrendering raw data.
Practical Example:
In the healthcare sector, multiple hospitals can use a TDS to share patient feature data for training AI diagnostic models, while keeping the original medical records stored locally.

Three Key Pain Points Driving the Development of Trusted Data Spaces
Trust Barriers: Data holders fear misuse (e.g., leakage of corporate trade secrets or patient privacy exposure).
Technical Fragmentation: Significant disparities in cross-industry data formats (e.g., industrial equipment data vs. medical imaging standards are incompatible).
Compliance Risks: Cross-border data flows face conflicting regulations (e.g., GDPR vs. China's Data Security Law).
Case Study: Supply Chain Finance
In traditional models, verifying data among logistics providers, banks, and manufacturers requires multiple offline verifications—time-consuming and prone to tampering. By contrast, Trusted Data Spaces enable real-time trusted verification through blockchain notarization and federated learning, slashing financing cycles from 15 days to just 72 hours.
02
Technical Module Breakdown: The Four Pillars of Building a Trusted Data Space
The Four Technical Pillars of Trusted Data Spaces
Trusted Data Spaces rely on four core technical modules that form the foundational infrastructure for secure operations:
Identity & Access Management (IAM)
The "gatekeeper" system that determines "who can access what data under which conditions."
Privacy-Enhancing Computation (PEC)
Like one-way mirror glass—enabling data usability while maintaining strict visibility control.
Data Provenance & Notarization
Functions as continuous surveillance recording, ensuring full traceability and accountability for data usage.**
Cross-Platform Interoperability
Similar to international power adapters—bridging disparate system interfaces for seamless data exchange.
Next, we'll analyze the implementation logic of each technical module in detail.
2.1 Identity & Access Management
Trusted Data Spaces achieve fine-grained permission control through:
Decentralized Identifiers (DID): Assigns unique identifiers to data objects, ensuring traceable data sovereignty
Attribute-Based Encryption (ABE): Enables dynamic access allocation via attribute keys (e.g., restricting access to users with specific credentials)
Case Study: Germany's Industrial Data Space (IDSA) employs DID technology to assign unique codes for industrial equipment data, supporting cross-border identity verification and access control during supply chain data transfers.
2.2 Privacy-Enhancing Computation Engine
Core technologies include:
Federated Learning (FL)
Enables collaborative modeling across institutions while keeping raw data localized—only model parameters are exchanged.
Trusted Execution Environments (TEE)
Hardware-isolated encrypted computing (e.g., Intel SGX chips) secures edge-side data processing.
2.3 Data Provenance & Notarization Network
Key implementations:
Optimized Blockchain Notarization
Uses chameleon hash algorithms to enable compliant data amendments (e.g., EU "right to be forgotten") while maintaining blockchain integrity.
Smart Contract Governance
Automated execution of data usage policies (e.g., triggering quality claims for anomalous data).
Innovation: Nanjing University of Science and Technology's decentralized ledger solution allows historical data erasure while preserving audit trails, achieving 30% block compression.
2.4 Cross-Platform Interoperability Protocols
Current focus:
Harmonizing technical standards, architectures, and protocols across platforms
Solution: Developing metadata federation architectures with industry-standard data dictionaries (e.g., unifying definitions for industrial equipment status, energy consumption metrics) to establish standardized labeling systems and circulation protocols within Trusted Data Spaces.

03
Key Technological Breakthroughs: Navigating the Uncharted Territories
Current Technical Bottlenecks in Trusted Data Spaces
The existing technical framework for Trusted Data Spaces faces three critical "chokepoint" challenges:
Dynamic Trust Assessment
How to evaluate the reliability of data users in real-time within decentralized environments?
Data Value Quantification
How to establish fair and efficient pricing mechanisms for data?
Edge Computing Collaboration
How to enable secure computation for massive IoT devices under low-power constraints?
Innovative Solutions to Address These Challenges
1. Dynamic Trust Assessment Models
Traditional certificate-based or rule-fixed trust evaluation methods exhibit two key flaws in multi-party collaborations:
Lagging Response: Inability to reflect real-time behavioral changes (e.g., dynamically increasing data misuse risks)
Narrow Scope: Single-dimensional metrics (e.g., corporate qualifications) fail to address complex trust scenarios
Technical Breakthrough: Multimodal Evidence Fusion
Combine cryptographic behavioral logs (e.g., data usage frequency, compliance records) with machine learning models to build dynamic trust scores.
Example: Applying Dempster-Shafer evidence theory to synthesize:
Historical behavior (e.g., past data breach incidents)
Environmental attributes (e.g., cross-border compliance levels)
Third-party audit results
→ Generates real-time quantifiable trust metrics
2. Decentralized Data Pricing Mechanisms
Current manual negotiation or cost-based pricing struggles with:
Heterogeneous data quality among participants
Real-time fluctuations in data value
Solution: Game Theory-Driven Dynamic Pricing
Shapley Value Algorithm: Allocates revenue based on each participant’s marginal contribution to joint modeling.
Example: In vertical federated learning, secret sharing techniques quantify feature contributions to model accuracy.
zk-SNARKs Integration: Verifies pricing calculations without exposing raw data distributions.
Example: In carbon emission trading, verifiers confirm contribution calculations via zero-knowledge proofs while withholding enterprise energy details.
3. Edge Computing & Privacy Protection Balance
IoT devices face inherent constraints:
Computational Limits: Struggle with traditional protocols (e.g., fully homomorphic encryption)
Dual Conflicts:
Encryption Strength vs. Efficiency: Strong algorithms cause excessive edge latency
Data Utility vs. Privacy: Excessive cleansing may disrupt business logic
Technical Approach: Layered Encryption Architecture
Critical Data: Protected by hardware-level TEE (e.g., patient genome sequences)
Non-Critical Data: Encrypted via lightweight algorithms (e.g., ChaCha20 stream cipher for device status) → Achieves dynamic compute-security tradeoffs
Protocol Optimization:
Federated Learning Enhancements:
Deploys model pruning/quantization at the edge, compressing model parameters by 60–80%
Integrates differential privacy noise to prevent gradient leakage
Example: Dynamic privacy budget allocation adjusts noise intensity based on data sensitivity.
04
Open Discussion: Technology Ethics and Ecosystem Co-creation
Navigating the Future of Trusted Data Spaces: Trends and Challenges
As the global push for Trusted Data Spaces accelerates, stakeholders are actively exploring implementation pathways and solutions. However, technical considerations—such as algorithmic fairness, cross-border data governance, and role definition to prevent technology monopolies—remain critical to unlocking their full potential.
The International Institute of Advanced Data Management (IIADMS) observes that Trusted Data Spaces are undergoing a pivotal transition: from "technology validation" to "ecosystem construction." We highlight three key trends shaping the future:
1. Hardware-Software Integration
Synergistic innovation between hardware (e.g., Trusted Execution Environment (TEE) chips, quantum encryption) and algorithms is driving progress.
Example: Guodun Quantum has launched a specialized encryption card for Trusted Data Spaces, exemplifying this convergence.
2. Standardization Ecosystem
The establishment of a unified standards framework is imperative.
Recent Development: China’s National Data Administration is coordinating multi-sectoral standardization efforts across industries. All stakeholders are urged to participate in co-creating these benchmarks.
3. Diversified Governance
A tripartite governance alliance (government, enterprises, and the public) is essential to foster inclusive collaboration.
Goal: Ensure all participants in Trusted Data Spaces have a voice in co-building equitable and transparent ecosystems.
About Us
The International Institute for Advanced Data Management Study Limited —— abbreviated as IIADMS, is a non-profit, supplier-independent institution initiated by Mr. Hu Benli, the current chairman of DAMA China Limited, and others. IIADMS is committed to advancing research in data and data management-related fields and continuously exploring new knowledge and best practices related to data. It strives to become a world-class platform for the exchange of knowledge on data management theory and practice. IIADMS is willing to cooperate with famous forums at home and abroad in various forms to discuss traditional and frontier topics related to data management, sharing the research results of IIADMS with these forums.
Contact Us
WeChat Official Account: IIADMS
Website: http://www.iiadms.com/
Email: study@iiadms.com