Although the development of centralized web-based platforms have brought about economic and societal benefits, such platforms have also resulted in the concentration of power in a small number of web stakeholders. Decentralization initiatives, such as Solid, Digi.me, and ActivityPub, aim to give data owners more control over their data and to level the playing field by enabling small companies and individuals to gain access to data thus stimulating innovation. However, these initiatives typically employ access control mechanisms that cannot verify compliance with usage conditions after access has been granted to others. Thus, in this paper, we extend the state of the art by proposing a resource governance conceptual framework, entitled ReGov, that facilitates usage control in decentralized web environments. We subsequently demonstrate how our framework can be instantiated by combining blockchain and trusted execution environments. Additionally, we evaluate its effectiveness through a detailed analysis of requirements derived from a data market motivating scenario, as well as an assessment of the security, privacy, and affordability aspects of our proposal.
翻译:尽管中央网络平台的发展带来了经济和社会效益,但这类平台也导致权力集中在少数网络利益攸关方,例如Solid、Digi.me和ActionPub等权力下放倡议旨在使数据拥有者对其数据有更大的控制权,并通过使小公司和个人能够获取数据从而刺激创新,使竞争环境更加公平;然而,这些举措通常采用出入控制机制,在允许他人进入后无法核查使用条件的遵守情况;因此,在本文件中,我们提出了题为ReGov的资源治理概念框架,为分散化网络环境中的使用控制提供了便利,从而扩展了最新水平;我们随后展示了如何通过将块链和可信赖的执行环境结合起来,使我们的框架能够即时化;此外,我们通过详细分析数据市场激励情景所产生的要求,评估我们提案的安全、隐私和可负担性,评估其有效性。