Advances in emerging technologies have accelerated digital transformation with the pervasive digitalization of the economy and society, driving innovations such as smart cities, industry 4.0 and FinTech. Unlike digitization, digitalization is a transformation to improve processes by leveraging digital technologies and digitized data. The cyberspace has evolved from a hardware internetworking infrastructure to the notion of a virtual environment, transforming how people, business and government interact and operate. Through this transformation, lots of personal data are captured which individuals have no ownership or control over, threatening their privacy. It is therefore necessary for the data owners to have control over the ownership, custody and utilization of their data and to protect one's digital assets and identity through proper data governance, cybersecurity control and privacy protection. This results in the notions of data sovereignty and digital sovereignty - two conceptually related terms, but different focuses. This paper first explains these two concepts in terms of their guiding principles, laws and regulations requirements, and analyse and discuss the technical challenges of implementing these requirements. Next, to understand the emerging trend shift in digital sovereignty towards individuals to take complete control of the security and privacy of their own digital assets, this paper conducts a systematic study and analysis of Self-Sovereign Identity, and discuss existing solutions and point out that an efficient key management system, scalability and interoperability of the solutions and well established standards are some of its challenges and open problems to wide deployments.
翻译:与数字化不同,数字化是一种通过利用数字技术和数字化数据改进流程的转变。网络空间已经从硬件互联网工作基础设施演变为虚拟环境的概念,转变了人们、企业和政府的互动和运作方式。通过这一转变,收集了大量个人数据,而个人对这些数据没有所有权或控制权,从而威胁到他们的隐私。因此,数据所有者必须控制其数据的所有权、保管和使用,并通过适当的数据治理、网络安全控制和隐私保护来保护个人的数字资产和身份。这导致数据主权和数字主权概念----两个概念相关术语,但重点不同。本文首先从指导原则、法律和规章要求的角度解释了这两个概念,分析和讨论执行这些要求的技术挑战。接下来,为了了解数字主权方面新出现的向个人转变趋势,以便完全控制自身数字资产的安全和隐私,通过适当的数据治理、网络控制和隐私保护,保护个人的数字资产和身份。这导致数据主权和数字主权概念的概念----两个概念相关术语,但重点不同。本文件首先从指导原则、法律和规章要求的角度解释了这两个概念,分析和讨论实施这些要求的技术挑战。然后,分析和讨论数字主权向个人的全面控制其安全和隐私趋势的转变。本文件对自身数字资产的安全性和隐私进行系统进行系统进行系统的系统进行系统的系统系统的系统系统的系统化研究和分析,并找出各种解决办法。