← Theses

Federated Governance in a Digital Trust Coalition

MA Andy Aidoo · Master's thesis, University of Zurich · February 2024

Advisors: Bruno Rodrigues, Katharine O. E. Mueller, Burkhard Stiller

Figure from the thesis: Federated Governance in a Digital Trust Coalition

Abstract

The importance of information and secure communication thereof is well known. A recent paradigm shift in data engineering towards the so called data mesh takes a domain-driven approach similar to the well established microservice architecture in software engineering. Rather than separating operational from analytical data and consequently relying on a plethora of data pipelines to aggregate analytical from operational data, business domains who are closest to the data are responsible for developing and maintaining the data products their domain offers. To manage the life cycle of such a data product, federation of identity management alongside its governance become crucial aspects, highlighting areas for further research; establishing trust between domains, especially remains challenging to this day. This Master’s Thesis presents a proof of concept for federated governance and identity management in a data mesh architecture aiming to provide means for secure information exchange between domains of various companies. A standardized onboarding process allows new domains to join through one of the two joiner-processes; they can start an application to attain membership-status of the Trust Coalition by filling out the sign up form. Provided that a two-thirds majority of the pre-established coalition participants vote in favor of the admission, a domain’s application is accepted and authorization servers of the Trust Coalition members can now authenticate users of the newly added domain. To verify the identity of users, we employ a two-factor authentication mechanism using possession-based factors in form of AnonCreds verifiable credentials; access to the credentials is secured through a mobile client that has to be unlocked utilizing either a knowledge-based or biometric authentication factor. An accelerated onboarding process is offered for reputable domains; within the framework of this Master’s Thesis, a domain is deemed reputable if it possess an extended validation or organisation validated TLS certificate. To verify the owner ship of the domain, the cryptographic key material is extracted from its certificate and used to encrypt a freshly generated mnemonic phrase; given the cipher text can be submitted as plain text, the application is accepted.

This line of work led to the paper Towards Federated Governance and Decentralized Identities for Participatory Sensing Data Mesh (IEEE ICBC 2025).