EP4732178A1 - Systems and methods for controlling access to digital twins of products - Google Patents
Systems and methods for controlling access to digital twins of productsInfo
- Publication number
- EP4732178A1 EP4732178A1 EP24733227.3A EP24733227A EP4732178A1 EP 4732178 A1 EP4732178 A1 EP 4732178A1 EP 24733227 A EP24733227 A EP 24733227A EP 4732178 A1 EP4732178 A1 EP 4732178A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- data
- decentral
- access
- digital twin
- participant
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/62—Protecting access to data via a platform, e.g. using keys or access control rules
- G06F21/6218—Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q10/00—Administration; Management
- G06Q10/06—Resources, workflows, human or project management; Enterprise or organisation planning; Enterprise or organisation modelling
- G06Q10/063—Operations research, analysis or management
- G06Q10/0631—Resource planning, allocation, distributing or scheduling for enterprises or organisations
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q10/00—Administration; Management
- G06Q10/08—Logistics, e.g. warehousing, loading or distribution; Inventory or stock management
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q10/00—Administration; Management
- G06Q10/30—Administration of product recycling or disposal
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q50/00—Information and communication technology [ICT] specially adapted for implementation of business processes of specific business sectors, e.g. utilities or tourism
- G06Q50/04—Manufacturing
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
- H04L63/101—Access control lists [ACL]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0816—Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
- H04L9/0819—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
- H04L9/083—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) involving central third party, e.g. key distribution center [KDC] or trusted third party [TTP]
- H04L9/0833—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) involving central third party, e.g. key distribution center [KDC] or trusted third party [TTP] involving conference or group key
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0891—Revocation or update of secret information, e.g. encryption key update or rekeying
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/50—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using hash chains, e.g. blockchains or hash trees
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F16/00—Information retrieval; Database structures therefor; File system structures therefor
- G06F16/20—Information retrieval; Database structures therefor; File system structures therefor of structured data, e.g. relational data
- G06F16/22—Indexing; Data structures therefor; Storage structures
- G06F16/2228—Indexing structures
- G06F16/2246—Trees, e.g. B+trees
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/21—Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/2141—Access rights, e.g. capability lists, access control lists, access tables, access matrices
Landscapes
- Engineering & Computer Science (AREA)
- Business, Economics & Management (AREA)
- Human Resources & Organizations (AREA)
- Economics (AREA)
- Theoretical Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Computer Security & Cryptography (AREA)
- Strategic Management (AREA)
- Physics & Mathematics (AREA)
- Entrepreneurship & Innovation (AREA)
- Signal Processing (AREA)
- Marketing (AREA)
- Tourism & Hospitality (AREA)
- General Business, Economics & Management (AREA)
- Computer Networks & Wireless Communication (AREA)
- Operations Research (AREA)
- Quality & Reliability (AREA)
- Computer Hardware Design (AREA)
- Development Economics (AREA)
- Health & Medical Sciences (AREA)
- General Health & Medical Sciences (AREA)
- General Engineering & Computer Science (AREA)
- Primary Health Care (AREA)
- Game Theory and Decision Science (AREA)
- Educational Administration (AREA)
- Computing Systems (AREA)
- Manufacturing & Machinery (AREA)
- Life Sciences & Earth Sciences (AREA)
- Sustainable Development (AREA)
- Databases & Information Systems (AREA)
- Bioethics (AREA)
- Software Systems (AREA)
- Storage Device Security (AREA)
Abstract
The present disclosure relates to an apparatus, a system and a computer-implemented method for generating access policy data for controlling access to a digital twin of a physical entity of a product and a respective computer-program element, a computer-implemented method and apparatus for controlling access to a digital twin of a physical entity of a product by a decentral data consuming network node associated with a participant of a decentral network and a respective computer-program element, a computer-implemented method for processing a digital twin or a part thereof of a physical entity of a product and a respective computer-program element and a computer-implemented method for controlling access to a digital twin or a part thereof of a physical entity of a product by a decentral data consuming network node associated with a participant of a decentral network using a digital access element associated with the product and a respective computer-program element.
Description
SYSTEMS AND METHODS FOR CONTROLLING ACCESS TO DIGITAL TWINS OF PRODUCTS
TECHNICAL FIELD
The present disclosure relates to an apparatus, a system and a computer-implemented method for generating access policy data for controlling access to a digital twin of a physical entity of a product and a respective computer-program element, a computer-implemented method and apparatus for controlling access to a digital twin of a physical entity of a product by a decentral data consuming network node associated with a participant of a decentral network and a respective computer-program element, a computer-implemented method for processing a digital twin or a part thereof of a physical entity of a product and a respective computer-program element and a computer-implemented method for controlling access to a digital twin or a part thereof of a physical entity of a product by a decentral data consuming network node associated with a participant of a decentral network using a digital access element associated with the product and a respective computer-program element.
TECHNICAL BACKGROUND
In the supply of products multiple regulatory requirements need to be met, which differ depending on the product. For instance, in automotive supply chains chemical companies provide standardized information using the International Chemical Product Data System (IMDS). Such system allows to collect data along the entire automotive supply chain. Participants in the automotive supply chain register with the IMDS service and maintain product entries in the central database as provided and hosted by a third-party provider.
Systems like IMDS are static regarding data, prone to error and cumbersome in handling or maintenance. Owing to the highly specific and centralized setup of such systems, exchange and sharing of chemicals data is laborious. Hence, there is a need to simplify and/or customize sharing or exchange of product data between participants of product ecosystems while allowing the data owner of the product data to control the access to said data by said further product ecosystem participants.
SUMMARY OF THE INVENTION
In an aspect, the disclosure relates to an apparatus for generating access policy data for controlling access to a digital twin of a physical entity of a product produced from one or more input materials, wherein the access to the digital twin by one or more decentral data consuming network node(s) of a decentral network is controlled by a decentral data providing network node associated with the digital twin, wherein the digital twin includes a digital twin data structure comprising a tree structure which comprises a plurality of nodes including a root node and optionally one or more leaf nodes and wherein the digital twin data structure includes a decentral digital twin identifier and at least one measured physical and/or chemical property of the product and/or at least one physical and/or chemical property
determined from collected data associated with a production and/or a use of the product, the apparatus comprising:
• at least one group access data generator configured to generate group access data associated with the digital twin data structure, the group access data identifying access control groups including decentral participant identifier(s) associated with decentral network participants permitted to access at the digital twin data structure,
• at least one participant access data generator configured to generate participant access data associated with one or more node(s) present within the digital twin data structure based on the generated group access data, the participant access data identifying the decentral network participant(s) permitted to access the one or more node(s) and one or more actions allowed to be performed on the one or more node(s) by decentral network participant(s) associated with the decentral participant identifier(s),
• at least one access policy data generator configured to generate access policy data associated with the digital twin based on the generated group access data and the generated participant access data, the access policy data identifying the group access data and the associated participant access data.
In a further aspect, the disclosure relates to an apparatus for generating access policy data for controlling access to a digital twin of a physical entity of a product produced from one or more input materials, wherein the access to the digital twin by one or more decentral data consuming network node(s) of a decentral network is controlled by a decentral data providing network node associated with the digital twin, wherein the digital twin includes a digital twin data structure comprising a tree structure which comprises a plurality of nodes including a root node and optionally one or more leaf nodes and wherein the digital twin data structure includes a decentral digital twin identifier and at least one measured physical and/or chemical property of the product and/or at least one physical and/or chemical property determined from collected data associated with a production and/or a use of the product, the apparatus comprising:
• at least one group access data generator configured to generate group access data associated with the digital twin data structure, the group access data identifying access control groups including decentral participant identifier(s) associated with decentral network participants permitted to access at the digital twin data structure,
• at least one participant access data generator configured to generate participant access data associated with one or more node(s) present within the digital twin data structure based on the generated group access data, the participant access data identifying the decentral network participant(s) permitted to access the one or more node(s) and one or more actions allowed to be performed on the one or more node(s) by decentral network participant(s) associated with the decentral participant identifier(s),
• at least one access policy data generator configured to generate access policy data based on the generated group access data and the generated participant access data, the access policy data identifying the group access data and the associated participant access data
• at least one linking unit configured to link the generated access policy data to the digital twin.
In a further aspect, the disclosure relates to a system for generating access policy data for controlling access to a digital twin of a physical entity of a product produced from one or more input materials, wherein the access to the digital twin by one or more decentral data consuming network node(s) of a decentral network is controlled by a decentral data providing network node associated with the digital twin and wherein the digital twin includes a digital twin data structure comprising a tree structure which comprises a plurality of nodes including a root node and optionally one or more leaf nodes and wherein the digital twin data structure includes a decentral digital twin identifier and at least one measured physical and/or chemical property of the product and/or at least one physical and/or chemical property determined from collected data associated with a production and/or a use of the product, the system comprising:
• optionally a digital twin provider layer configured to provide the digital twin of the physical entity of the product,
• an access policy data provider layer configured to o generate group access data associated with the digital twin data structure, the group access data identifying access control groups including decentral participant identifier(s) associated with decentral network participants permitted to access at the digital twin data structure, o generate participant access data associated with one or more nodes(s) present within the digital twin data structure based on the generated group access data, the participant access data identifying the decentral network participant(s) permitted to access the one or more node(s) and one or more actions allowed to be performed on the one or more nodes(s) by decentral network participant(s) associated with the decentral participant identifier(s), o generate access policy data associated with the digital twin based on the generated group access data and the generated participant access data, the access policy data identifying the group access data and the associated participant access data.
In a further aspect, the disclosure relates to a system for generating access policy data for controlling access to a digital twin of a physical entity of a product produced from one or more input materials, wherein the access to the digital twin by one or more decentral data consuming network node(s) of a decentral network is controlled by a decentral data providing network node associated with the digital twin and wherein the digital twin includes a digital twin data structure comprising a tree structure which comprises a plurality of nodes including a root node and optionally one or more leaf nodes and wherein the digital twin data structure includes a decentral digital twin identifier and at least one measured physical and/or chemical property of the product and/or at least one physical and/or chemical property
determined from collected data associated with a production and/or a use of the product, the system comprising:
• optionally a digital twin provider layer configured to provide the digital twin of the physical entity of the product,
• an access policy data provider layer configured to o generate group access data associated with the digital twin data structure, the group access data identifying access control groups including decentral participant identifier(s) associated with decentral network participants permitted to access at the digital twin data structure, o generate participant access data associated with one or more nodes(s) present within the digital twin data structure based on the generated group access data, the participant access data identifying the decentral network participant(s) permitted to access the one or more node(s) and one or more actions allowed to be performed on the one or more nodes(s) by decentral network participant(s) associated with the decentral participant identifier(s), o generate access policy data based on the generated group access data and the generated participant access data, the access policy data identifying the group access data and the associated participant access data, o link the generated access policy data to the digital twin.
In a further aspect, the disclosure relates to a computer-implemented method for generating access policy data for controlling access to a digital twin of a physical entity of a product produced from one or more input materials, wherein the access to the digital twin by one or more decentral data consuming network node(s) of a decentral network is controlled by a decentral data providing network node associated with the digital twin and wherein the digital twin includes a digital twin data structure comprising a tree structure which comprises a plurality of nodes including a root node and optionally one or more leaf nodes and wherein the digital twin data structure includes a decentral digital twin identifier and at least one measured physical and/or chemical property of the product and/or at least one physical and/or chemical property determined from collected data associated with a production and/or a use of the product, the method comprising the steps of:
• generating group access data associated with the digital twin data structure, the group access data identifying access control groups including decentral participant identifier(s) associated with decentral network participants permitted to access at the digital twin data structure,
• generating participant access data associated with one or more nodes(s) present within the digital twin data structure based on the generated group access data, the participant access data identifying the decentral network participant(s) permitted to access the one or more node(s) and one or more actions allowed to be performed on the one or more nodes(s) by decentral network participant(s) associated with the decentral participant identifier(s),
• generating access policy data associated with the digital twin based on the generated group access data and the generated participant access data, the access policy data identifying the group access data and the associated participant access data.
In a further aspect, the disclosure relates to a computer-implemented method for generating access policy data for controlling access to a digital twin of a physical entity of a product produced from one or more input materials, wherein the access to the digital twin by one or more decentral data consuming network node(s) of a decentral network is controlled by a decentral data providing network node associated with the digital twin and wherein the digital twin includes a digital twin data structure comprising a tree structure which comprises a plurality of nodes including a root node and optionally one or more leaf nodes and wherein the digital twin data structure includes a decentral digital twin identifier and at least one measured physical and/or chemical property of the product and/or at least one physical and/or chemical property determined from collected data associated with a production and/or a use of the product, the method comprising the steps of:
• generating group access data associated with the digital twin data structure, the group access data identifying access control groups including decentral participant identifier(s) associated with decentral network participants permitted to access at the digital twin data structure,
• generating participant access data associated with one or more nodes(s) present within the digital twin data structure based on the generated group access data, the participant access data identifying the decentral network participant(s) permitted to access the one or more node(s) and one or more actions allowed to be performed on the one or more nodes(s) by decentral network participant(s) associated with the decentral participant identifier(s),
• generating access policy data based on the generated group access data and the generated participant access data, the access policy data identifying the group access data and the associated participant access data,
• linking the generated access policy data to the digital twin.
In a further aspect, the disclosure relates to a computer-implemented method for controlling access to a digital twin of a physical entity of a product by a decentral data consuming network node associated with a participant of a decentral network, wherein the digital twin includes a digital twin data structure comprising a tree structure which comprises a plurality of nodes including a root node and optionally one or more leaf nodes and wherein the digital twin data structure includes a decentral digital twin identifier and at least one measured physical and/or chemical property of the product and/or at least one physical and/or chemical property determined from collected data associated with a production and/or a use of the product, the method comprising:
• receiving at the decentral data providing network node a request to access the digital twin or a part thereof from a decentral data consuming network node, the request including the decentral digital
twin identifier and a decentral participant identifier of a decentral network participant associated with the decentral data consuming network node,
• determining - based on the decentral digital twin identifier included in the received request - access policy data as generated by the apparatus, the system or according to the computer-implemented method as disclosed herein,
• determining, based on the decentral participant identifier included in the received request and the access policy data, that the decentral network participant is a member of at least one access control group that is permitted to access the digital twin data structure and that the participant is permitted to interact with the digital twin data structure upon accessing the digital twin data structure, and in response,
• permitting the decentral data consuming network node access to the digital twin data structure according to the access policy data.
In a further aspect, the present disclosure relates to an apparatus for controlling access to a digital twin of a physical entity of a product by a decentral data consuming network node associated with a participant of a decentral network, wherein the digital twin includes a digital twin data structure comprising a tree structure which comprises a plurality of nodes including a root node and optionally one or more leaf nodes and wherein the digital twin data structure includes a decentral digital twin identifier and at least one measured physical and/or chemical property of the product and/or at least one physical and/or chemical property determined from collected data associated with a production and/or a use of the product, the apparatus comprising one or more computing nodes and one or more computer-readable media having thereon computer-executable instructions that are structured such that, when executed by the one or more computing nodes, cause the apparatus to perform the following steps:
• receive a request to access the digital twin or a part thereof from a decentral data consuming network node, the request including the decentral digital twin identifier and a decentral participant identifier associated with the decentral data consuming network node related,
• determine - based on the decentral digital twin identifier included in the received request - access policy data as generated by the apparatus, the system or according to the computer-implemented method as disclosed herein,
• determine, based on the decentral participant identifier included in the received request and the access policy data, that the participant is a member of at least one access control group that is permitted to access the digital twin data structure and that the participant is permitted to interact with the digital twin data structure upon accessing the digital twin data structure, and in response,
• permitting the decentral data consuming network node access to the digital twin data structure according to the access policy data.
In a further aspect, the present disclosure relates to a computer-implemented method for controlling access to a digital twin of a physical entity of a product by a decentral data consuming network node
associated with a participant of a decentral network, wherein the digital twin includes a digital twin data structure comprising a tree structure which comprises a plurality of nodes including a root node and optionally one or more leaf nodes and wherein the digital twin data structure includes a decentral digital twin identifier and at least one measured physical and/or chemical property of the product and/or at least one physical and/or chemical property determined from collected data associated with a production and/or a use of the product, the method comprising:
• receiving at a decentral data providing network node a request to access the digital twin or a part thereof from the decentral data consuming network node, the request including the decentral digital twin identifier and a decentral participant identifier of a decentral network participant associated with the decentral data consuming node,
• accessing access policy data associated with the digital twin based on the decentral digital twin identifier, the access policy data identifying one or more access control group(s) associated with the digital twin data structure, membership in an access control group indicating that the decentral network participant is permitted to access the digital twin data structure, and membership in the access control group being independent from participant access data associated with one or more node(s) present within the digital twin data structure and indicative of how the decentral network participant may interact with the digital twin data structure upon accessing the digital twin data structure,
• determining, based on the decentral participant identifier included in the received request and the access policy data, that the decentral network participant is a member of at least one access control group that is permitted to access the digital twin data structure, and in response
• permitting the decentral data consuming network node access to the digital twin data structure according to the access policy data.
In a further aspect, the present disclosure relates to an apparatus for controlling access to a digital twin of a physical entity of a product by a decentral data consuming network node associated with a participant of a decentral network, wherein the digital twin includes a structure comprising a tree structure which comprises a plurality of nodes including a root node and optionally one or more leaf nodes and wherein the digital twin data structure includes a decentral digital twin identifier and at least one measured physical and/or chemical property of the product and/or at least one physical and/or chemical property determined from collected data associated with a production and/or a use of the product, the apparatus comprising one or more computing nodes and one or more computer-readable media having thereon computer-executable instructions that are structured such that, when executed by the one or more computing nodes, cause the apparatus to perform the following steps:
• receive at a decentral data providing network node a request to access the digital twin or a part thereof from the decentral data consuming network node, the request including the decentral digital twin identifier and a decentral participant identifier of a decentral network participant associated with the decentral data consuming node,
• access policy data associated with the digital twin based on the decentral digital twin identifier, the access policy data identifying one or more access control group(s) associated with the digital twin data structure, membership in an access control group indicating that the decentral network participant is permitted to access the digital twin data structure, and membership in the access control group being independent from participant access data associated with one or more node(s) being present within the digital twin data structure and indicative of how the decentral network participant may interact with the digital twin data structure upon accessing the digital twin data structure,
• determine, based on the decentral participant identifier included in the received request and the access policy data, that the decentral network participant is a member of at least one access control group that is permitted to access the digital twin data structure, and in response
• permit the decentral data consuming network node access to the digital twin according to the access policy data.
In a further aspect, the present disclosure relates to a computer-implemented method for processing a digital twin or a part thereof of a physical entity of a product, wherein the digital twin includes a digital twin data structure comprising a tree structure which comprises a plurality of nodes including a root node and optionally one or more leaf nodes and wherein the digital twin data structure includes a decentral digital twin identifier and at least one measured physical and/or chemical property of the product and/or at least one physical and/or chemical property determined from collected data associated with a production and/or the use of a product, the method comprising:
• gathering by a decentral data consuming network node the digital twin or a part thereof from the apparatus for controlling access or via the computer-implemented method for controlling access as disclosed herein,
• processing the gathered digital twin, and
• providing an output based on the processing.
In a further aspect, the present disclosure relates to a computer-implemented method for controlling access to a digital twin or a part thereof of a physical entity of a product by a decentral data consuming network node associated with a participant of a decentral network using a digital access element associated with the product, wherein the digital twin includes a digital twin data structure comprising a tree structure which comprises a plurality of nodes including a root node and optionally one or more leaf nodes and wherein the digital twin data structure includes a decentral digital twin identifier and at least one measured physical and/or chemical property of the product and/or at least one physical and/or chemical property determined from collected data associated with a production and/or a use of the product, the method comprising : providing the digital access element including a decentral passport identifier and digital twin location data, wherein the decentral passport identifier is or is associated with the decentral digital twin identifier,
• providing - based on the provided digital access element, the decentral digital twin identifier and a decentral participant identifier associated with a decentral data consuming network node requesting access to the digital twin or a part thereof - access to the digital twin or the part thereof as controlled by the apparatus disclosed herein or via the computer-implemented method disclosed herein.
In a further aspect, the present disclosure relates to a computer element, such as a computer readable storage medium, a computer program or a computer program product, comprising instructions, which when executed by a computing node or a computing system, direct the computing node or computing system to carry out the steps of the computer-implemented methods disclosed herein.
In a further aspect, the present disclosure relates to a computer element, such as a computer readable storage medium, a computer program or a computer program product, comprising instructions, which when executed by the apparatuses or systems disclosed herein, direct the apparatuses or systems to carry out steps the apparatuses or systems disclosed herein are configured to execute.
Any disclosure, embodiments and examples described herein relate to the methods, the systems, apparatuses, digital twins, products and computer elements lined out above and below. Advantageously, the benefits provided by any of the embodiments and examples equally apply to all other embodiments and examples.
Embodiments
The methods, apparatuses, digital twins, products, and computer elements disclosed herein provide an efficient, secure and robust way robust way for sharing or exchanging data associated with products across different decentral network nodes associated with different participants of a product ecosystem including the chemical products under control of a decentral data providing network node associated with the data owner of the digital twin data structure. The party controlling the decentral data providing network node, such as the data owner of the digital twin data structure, may hence control access to the digital twin data structure via said decentral data providing network node using the decentral participant identifier associated with the decentral data consuming network node requesting access to the digital twin data structure and the decentral digital twin identifier associated with the digital twin to be accessed.
By filtering decentral data consuming network node(s) requesting access to the digital twin data structure based on a group-based policy for accessing the digital twin, the digital twin data structure can be securely exchanged and shared under the sovereignty of the data owner of the digital twin data structure and unauthorized access to the digital twin data structure by decentral network participants via associated decentral data consuming network nodes can be avoided. This allows for controlled access to the digital twin or parts thereof by further upstream participants of the product ecosystem. Moreover, access to the digital twin or a part thereof by multiple decentral data consuming network nodes associated with different consumers of different products produced by different participants of the product ecosystem can be
controlled via the decentral data providing service using the group-based policy and the decentral digital twin identifier.
The group-based access policy may be defined by the data owner of the digital twin data and may include one or more groups of decentral network participants that are permitted to access the digital twin data structure. Decentral network participants that are associated with such group may then be able to access the digital twin data structure while all other decentral network participants may be denied access to the digital twin data structure. Hence, access to the digital twin data structure may be granted and/or denied to a defined group of decentral network participants. This group-based access control technique allows to quickly and efficiently grant or revoke access to the digital twin data structure to defined decentral network participants. By combining the group-based access control with fine-grained access controls associated with one or more node(s) contained in the digital twin data structure, actions of the decentral network participants permitted to access the digital twin data structure under the group-based access control may be controlled at a fine-grain once the decentral network participants have been granted access to the digital twin data structure. This allows to manage who has access to the digital twin data structure without compromising the ability to control what actions those decentral network participants having access to the digital twin data structure may perform once these decentral network participants access the digital twin data structure. Thus, access to the digital twin data structure can be easily managed via the group-based access control without having to adjust the actions decentral network participants are allowed to perform on the digital twin data structure.
Use of a group-based access in combination with fine-grained access controls on node level allows to avoid the generation of multiple copies of digital twin data structures customized to the access rights associated with each decentral network participant permitted to access the digital twin data structure. Hence, the amount of data associated with the digital twin may be reduced since access may be controlled on node level of the digital twin data structure, making generation of multiple copies of the digital twin data structure redundant.
By linking the access policy data to the digital twin of the product, generation of different digital twins for different participants of the decentral network based on participant access data can be avoided while ensuring that access to the data contained in the digital twin is controlled in a reliable and secure manner. This way, generation of numerous digital twins for a single product can be avoided, hence reducing the amount of resources required to generate, manage and update the digital twin.
In the following, embodiments of the present disclosure will be outlined by ways of examples. It is to be understood that the present disclosure is not limited to said embodiments and/or examples.
The digital twin of the product may be a digital representation of a physical entity of the product with a defined semantic description of said physical entity of the product. The digital twin of the physical entity
of the product is hence a digital version of said physical entity. Once created, the digital twin may be used to represent the physical entity of the product in a digital representation of a real-world system. The digital twin may be uniquely linked to the physical product via at least the decentral digital twin identifier. The digital twin may be created such that it is identical in form and behavior of the corresponding product. Additionally, the digital twin may mirror the properties of the product during its lifetime. For example, sensors may capture real-time (or near real-time) data, such as transport data or use data, from the physical product to relay it back to a remote digital twin. The digital twin may then be updated to maintain its correspondence to the physical entity of the product. Hence, the digital twin may at any time represent the current state of the physical entity of the product. The digital twin may contain a decentral digital twin identifier. The decentral digital twin identifier may be associated with a physical entity of the product the digital twin is associated with. The decentral digital twin identifier may be associated with the physical entity of the product the digital twin is generated for. The decentral digital twin identifier may be associated with decentral identifiers of chemical materials used to produce the product. The decentral identifier may be associated with products, components, component assemblies and/or end products produced using the product. This allows to track the product within the value chain. The decentral digital twin identifier may or may be assigned to a physical identifier connected to the product. The physical identifier may be any identifier for the produced product, such as a batch number or a part number. The physical identifier may comprise a passive or active element, e.g. bar code, QR-code, RFID-tag, but is not limited thereto. The physical identifier may include markers embedded in materials or similar physical arrangement that allows to digitally identify the product. The digital twin may further contain a product identifier.
The digital twin may be generated by a decentral participant node. The decentral participant node may be in communication with the decentral data providing network node. The decentral participant node may be associated with the decentral data providing network node. The digital twin may be generated by the data owner of the digital twin data structure. The data owner of the digital twin data may be the production producing the product. The data owner of the digital twin data structure may be the legal entity operating the production producing the product. The data owner of the digital twin data structure may be the natural person operating the production producing the product. The digital twin may be generated on behalf of the data owner of the digital twin data structure. For instance, the digital twin may be generated by a third party based on a service provided by the third party to the data owner.
The digital twin may include a digital twin data structure comprising a tree structure. The tree structure may include a root node and optionally one or more leaf nodes. The tree structure may comprise a plurality of nodes including a root node and one or more leaf nodes. The tree structure may further include one or more intermediate nodes. The root node may be a parent of a respective set of one or more children in the tree structure and may not be a child node (e.g. may not be associated with a parent node). The leaf node(s) may be a child node but not a parent node. The intermediate node(s) may be a child node of the root node or of another intermediate node but may not be a leaf node. Hence, children
of a root node may either be leaf node(s) or intermediate node(s). Intermediate node(s) in turn may have children, such as leaf node(s) or other intermediate node(s). A collection of intermediate nodes and/or child node(s) may be regarded as a sub data structure of the digital twin data structure. The tree structure of the digital twin data structure or a sub data structure may be inherited from the data model(s) used to generate the digital twin data structure. For instance, a single data model comprising a tree structure may be used to generate the digital twin data structure (e.g. by applying said data model to product data associated with the product). In another instance, at least two different data models may be used to generate the digital twin data structure comprising at least two sub data structures (e.g. each sub data structure is resulting from applying the respective data model to the product data). At least one of said data models may comprise a tree structure. The digital twin data structure may in this case be regarded as a tree structure containing at least two sub data structures resulting from the at least two different data models used to generate the digital twin data structure. A node may comprise one or more data set(s). Such data set(s) may include one or more key value pair(s). Key value pair(s) may include physical and/or chemical properties of the respective product (e.g. where the key represents the respective property and the value represents the value of the respective property).
The digital twin data structure may further include other decentral product identifier(s) according to a physical relation of the product entity with other physical entities e.g. those produced using the product or those produced from the product. This way decentral participant node(s) of the decentral network may be able to interpret the relation of the decentral digital twin identifier corresponding to the physical relation of the physical chemical entity to other physical entities.
Physical entity may relate to the physical embodiment of the product. The physical entity may be any product in the product ecosystem. The physical entity of the product may be a raw material or basic substance, a chemical product, a chemical material, a chemical formulation, a chemical mixture, a component, a component assembly, an end-product or a combination thereof. The product ecosystem may include a plurality of participants, such as product raw chemical product supplier(s), chemical product manufacturer(s), part manufacturer(s), component manufacturer(s), component assembly manufacturer(s), end-product manufacturer(s), end-product user(s) and/or partici pant(s) of the recycling chain associated with the end-product, such as end-of-life product collector(s) and/or recycler(s).
The decentral data providing network node may comprise computer-executable instructions for providing and/or processing data within a decentral network, such as the digital twin (e.g. the digital twin data structure) of the product, by a decentral data consuming network node. The decentral data providing network node may be associated with or connected to one or more dedicated data storage(s) storing the digital twin data structure. The decentral data providing network node may be directly or indirectly connected to the data storage(s) storing the digital twin data structure. Hence, the decentral data providing network node may be associated with the digital twin data structure. The dedicated data
storage(s) may be under control of the data owner of the digital twin data structure. The data owner may have access to the dedicated data storage(s). The data owner may control access to the dedicated data storage(s), for example via he decentral data providing network node. The dedicated storage(s) may store digital twin(s) of product(s) for access by consumers of the product (e.g. product consumers). The product consumer(s) may be associated with decentral data consuming network node(s).
The decentral data consuming network node may comprise computer-executable instructions for accessing and/or processing data within a decentral network, such as digital twin data structure, provided by a decentral data providing network node. The decentral data consuming network node may be controlled or owned by or associated with a consumer of the product. The consumer may be any entity processing the product. The consumer may be any entity operating a production configured to process the product. Processing may include using the product to produce further chemical products, parts, component, assemblies, or end products. Processing may include performing one or more recycling step(s) on the end-product. The consumer may be an upstream participant of the product ecosystem the produced product is associated with, e.g. the product is used in. For instance, the consumer may be a discrete product processor, such as a discrete product producer or a participant of the recycling process of the discrete product. Discrete products may be finished products that are distinct items capable of being easily identifiable, for example by counting. Examples of discrete products include automobiles, airplanes, shoes, etc. A discrete product may be broken down at the end of its lifecycle so that its components can be recycled. The consumer may receive the product from the entity producing the product, such as a product producer. Via the decentral data consuming network node, the consumer of the product may access the digital twin or a part thereof associated with supplied products, thus allowing to improve production or recycling by using the accessed digital twin data structure. For instance, the accessed data may be used to enhance the properties of the resulting further product, component or discrete product or the overall production efficiency. In another instance, the accessed digital twin data structure associated with the supplied product and may be used control the production involving the supplied product. In yet another instance, the accessed digital twin data structure may be used to reliably determine the composition of the components or end-products to be recycled, thus improving recycling efficiency by determining the correct recycling process, recycling parameters, recycling plant, etc.
The decentral network may be a decentral peer-to-peer communication network. The decentral network may include participant network nodes associated with participants of the product ecosystem and may be configured to perform data transactions. The decentral participant node may comprise a network node of the decentral network. The network nodes associated with participants of the product ecosystem may be associated with raw chemical product supplier(s), chemical product manufacturer(s), part manufacturer(s), component manufacturer(s), component assembly manufacturer(s), end product manufacturer(s), end product user(s), end-of-life product collector(s) and/or recycler(s). The data transactions may be based on a transaction protocol including authentication and/or authorization
mechanism(s). Based on the authentication and/or authorization mechanism(s) a peer-to-peer communication between decentral network nodes associated with participants of the product ecosystem may be established. The one or more authentication mechanism(s) may be associated with or linked to the decentral digital twin identifier and/or the decentral passport identifier. The one or more authentication mechanism(s) associated with the decentral digital twin identifier and/or the decentral passport identifier may be accessible by the decentral data providing network node and/or the decentral data consuming network node. The decentral configuration allows for more efficient use of computing resources and strengthens control by the data owners of the decentral network.
The decentral data providing network node and the one or more decentral data consuming network node(s) may be part of the decentral network. The decentral data consuming network node and the decentral data providing network node may be regarded as decentral participant node(s) of the decentral network.
The decentral digital twin identifier and/or the decentral passport identifier may comprise any unique identifier uniquely associated with the digital twin data structure and optionally a data owner of the digital twin data structure. The decentral digital twin identifier and/or the decentral passport identifier may connect the physical entity of the product to the digital twin data structure. The decentral digital twin identifier and/or the decentral passport identifier may include one or more Universally Unique Identifier(s) (UUID(s)) and/or one or more Decentralized Identifier(s) (DID(s)). The one or more DID(s) and/or UUID(s) may be associated with the digital twin and/or the digital twin data structure. The one or more DID(s) and/or UUID(s) may further be associated with the product. For instance, the decentral digital twin identifier and/or the decentral passport identifier may include a digital twin identifier associated with the digital twin and one or digital twin data identifier(s) associated with sub data structure(s) present within the digital twin data structure. The sub data structure(s) may include one or more intermediate node(s) and/or one or more leaf node(s). The node(s) of the sub data structure(s) may be regarded as child node(s) of the root node of the digital twin data structure. The decentral digital twin identifier and/or the decentral passport identifier may further include a product identifier associated with the product. Any combination of UUID(s) and DID(s) may be possible. For instance, the decentral digital twin identifier and/or the decentral passport identifier may be a DID while the digital twin data identifier(s) may be UUID(s). In another instance, the decentral digital twin identifier and/or the decentral passport identifier, and the digital twin data identifier(s) may be UUlDs. The decentral digital twin identifier and/or the decentral passport identifier may be associated with any participant of the product ecosystem including raw chemical product supplier(s), chemical product manufacturer(s), part manufacturer(s), component manufacturer(s), component assembly manufacturer(s), end product manufacturer(s) end-of-life product collector(s) and/or recycler(s). The decentral digital twin identifier and/or the decentral passport identifier may be associated with a machine, a system, or a device used for producing the raw material, the basic substance, the product, the part, the component, the component assembly, the end product or
a recycled material, or a collection of such machine(s), device(s) and/or system(s). The decentral digital twin identifier and/or the decentral passport identifier may be issued by a central or decentral identity issuer. The decentral digital twin identifier and/or the decentral passport identifier may be generated by the data owner or on behalf of the data owner of the digital twin data structure. The decentral digital twin identifier and/or the decentral passport identifier may include authentication information. Via the decentral digital twin identifier and/or the decentral passport identifier and its unique association with the digital twin data structure of the digital twin associated with the product and optionally the data owner of the digital twin data structure, access to the digital twin data structure may be controlled by the data owner of the digital twin data structure. This contrasts with central authority schemes, where identifiers are provided by such central authority and access to data is controlled by such central authority. Decentral in this context refers to the usage of the decentral digital twin identifier and/or the decentral passport identifier in implementations as controlled by the data owner of the data associated with the decentral digital twin identifier and/or decentral passport identifier. The decentral digital twin identifier and/or the decentral passport identifier may be digital or virtual identifier(s), e.g. may not correspond to physical identifier(s) physically attached to the product.
The decentral participant identifier may comprise any identifier uniquely associated with a participant of a decentral network and/or with a production site of a participant of the decentral network. The participant of the decentral network may be a consumer of the product, e.g. may consume the product received from or supplied by the product producer. The production site of a participant of the decentral network may use the received/supplied product to produce further products, such as further chemical products, parts, components, component assemblies and/or end products. The production site of a participant of the decentral network may use the received/supplied product to perform one or more recycling steps on the product. The decentral participant identifier may include letters and/or numbers. The decentral participant identifier may include one or more Universally Unique Identifier(s) (UUID(s)) and/or one or more Decentralized Identifier(s) (DID(s)). The decentral participant identifier may be associated with or may include a verifiable claim or credential. The verifiable claim may be issued by a central or decentral identity issuer making one or more claims about a subject, such as a consumer entity being a trustworthy participant of the decentral network. For instance, the issuer may make a claim about a consumer (e.g. the customer entity) the DID as decentral participant identifier is associated with. The verifiable claim may include those claim(s) as well as proof instructions to prove that claim(s) have not been tampered with and were indeed issued by the claims issuer. The verifiable claim may also include duration information metadata that defines a period of time that the verifiable claim is valid for use or that defines a specific number of times that the verifiable claim is authorized for use. The verifiable claim may also include a DID of the claims issuer and/or the subject, such as a consumer entity. The verifiable claim may be signed by the claims issuer. The claims issuer may provide the verifiable claim to a claims holder, such as the consumer entity, for presentation to any relying party that relies upon the veracity of those claims, such as a decentral data provider. The signature of the verifiable claim may be validated with a
public key associated with the claims issuer to determine that the customer entity is a trusted entity within the decentral network. The verifiable credential may be presented by the decentral data consuming network node and may be used by the decentral data providing network node to verify that the decentral participant associated with the decentral data consuming network node is a trusted entity within the decentral network prior to providing access to the digital twin data structure, hence ensuring that the digital twin data structure can be exchanged in a secure and controlled manner within the decentral network. The decentral participant identifier may be different from the data related to the product produced from the one or more input materials. In contrast to the data related to the product which may not be unique within the decentral network, the decentral participant identifier is unique within the decentral network. Hence, the decentral participant identifier allows to uniquely identify a participant and/or a site of the participant of the decentral network. The decentral participant identifier may be generated by a central or decentral node of the decentral network. The decentral participant identifier may be provided to all participants of the decentral network. The decentral participant identifier may be associated with the name of the participant of the decentral network. The decentral participant identifier may be associated with the name of the site, such as a production site, of the participant of the decentral network. Decentral in this context refers to the usage of the decentral participant identifier in implementations as controlled by the decentral data consuming network node associated with a decentral participant.
The chemical property may be a property of the product that becomes evident during, or after, a chemical reaction. Hence, the chemical property may be any quality that can be established only by changing the chemical identity of the product. Examples of chemical properties include heat of combustion, enthalpy of formation, toxicity, chemical stability in a given environment, flammability, oxidation state(s), ability to corrode, combustibility, acidity and basicity, chemical product composition, recyclate content used for producing or manufacturing the product, bio-based content used for producing or manufacturing the product, renewable content used for producing or manufacturing the product and/or pH value.
The physical property may be any property that is measurable. Hence, the value of a physical property describes a state of the product. Examples of physical properties include absorption, brittleness, boiling point, capacitance, color, concentration, density, ductility, distribution, efficacy, elasticity, electric charge, electrical conductivity, electrical impedance, electric potential, flow rate, fluidity, hardness, heat capacity, inductance, intrinsic impedance, luminance, luminescence, luster, mass, melting point, opacity, permeability, permittivity, plasticity, pressure, radiance, resistivity, reflectivity, refractive index, solubility, specific heat, strength, stiffness, temperature, tension, thermal conductivity, thermal resistance, viscosity, volume and/or wave impedance.
In an embodiment, the measured at least one physical and/or chemical property is obtained by sensors configured to measure the physical and/or chemical property. The sensor may be included in a measuring
device. The sensor may correspond to the measuring device. For example, the physical and/or chemical property may include a property provided by sensors of a mobile device such as a camera, or measurement devices configured to measure at least one physical and/or chemical property.
In an embodiment, the data associated with the production of the product is collected before, during and/or after production of the product. The collected product data may be used to determine at least one physical and/or chemical property of the produced product. For instance, emission data of the product may be determined based on product data collected during production of the product. Data associated with the production of the product may include production data from the production of the product. Data associated with the production of the product may include monitoring and/or control data associated with the production of the product.
In an embodiment, data associated with the use of the product is collected via at least one identifier associated with the product. The data may be collected during and/or after use of the product. Collected data may include at least one measured physical and/or chemical property of the used product. The measured physical and/or chemical property may include the chemical and/or physical properties described previously. The data may be collected with a suitable sensor configured to measure the chemical and/or physical property. The sensor data may be interrelated with the identifier associated with the product. The chemical and/or physical property determined from the sensor data may be interrelated with the identifier associated with the product. The identifier may be the product identifier. The identifier may be the decentral digital twin identifier. The decentral digital twin identifier may be linked to other decentral product identifier(s) according to a physical relation of the chemical product entity with other physical entities e.g. those produced using the chemical product or those produced from the chemical product. The linking of the decentral digital twin identifier with other decentral product identifier(s) allows to determine the decentral participant node(s) storing the collected data associated with the use of the product or the determined physical and/or chemical property. The collected data and/or the determined chemical and/or physical property may be provided by said decentral participant node(s) and may be stored within the digital twin. For instance, a new sub data structure may be generated by applying a data model associated with the use of the product to the collected data and/or the determined property and said new sub data structure t may be used to update the digital twin data structure, e.g. may be appended to the root node of the digital twin data structure as child node(s) of said root node.
In an embodiment, the product is a chemical product. The chemical product may be obtained from at least one chemical reaction using one or more chemical input materials. Chemical reactions may include any chemical reaction commonly known in the state of the art in which the reactants are converted to one or more different chemical products. Chemical reactions may involve the use of catalysts, enzymes, bacteria, etc. to achieve the chemical reaction between the reactants. The chemical product may include natural chemical products. Natural chemical products may include any chemical product that is produced
by nature without human interaction or intervention, i.e. any unprocessed chemical substance that is found in nature, such as chemicals from plants, micro-organisms, animals, the earth and the sea or any chemical substance that is found in nature and extracted using a process that does not change its chemical composition. Natural chemical products may include biologicals like enzymes as well naturally occurring inorganic or organic chemical products. Natural chemical products may be isolated and purified prior to their use or they can be used in unisolated and/or unpurified form. Chemical products may be synthetic chemical products. Synthetic chemical products may include chemical products produced with human interaction or intervention. Synthetic chemical products may be produced with the same chemical reactions occurring in nature or with different chemical reactions. The chemical product may include a raw material. The chemical product may include a chemical material produced by reacting at least two raw materials. The chemical product may be a chemical intermediate product. The chemical product may include a component. The chemical product may include a component assembly. The chemical product may include an end product.
The chemical product may be produced by a chemical production from one or more chemical input materials. The chemical input materials may include raw materials, intermediate chemical products or chemical products received from a supplier. The chemical production may be a chemical production network including multiple interlinked processing steps. The chemical production network may be an integrated chemical production network with interrelated production chains. The chemical production network may include multiple different production chains that have at least one intermediate product in common. The chemical production network may include multiple stages of the chemical value chain. The chemical production network may include multiple production chains that produce from one or more inbound material(s) as input chemical products as output. The chemical production network may include multiple tiers of a chemical value chain. The chemical production network may include a physically interconnected arrangement of production sites. The production sites may be at the same location or at different locations. In the latter case, the production sites may be interconnected by means of dedicated transportation systems such as pipelines, supply chain vehicles, like trucks, supply chain ships or other cargo transportation means. The chemical production may be controlled by an operating system. The operating system may be configured to perform the methods disclosed herein. The operating system may comprise the apparatuses and systems disclosed herein. The chemical product may comprise a physical identifier. The physical identifier may be present on the packaging of the produced chemical product. The physical identifier may be a code, such as a QR code or an embossed code, an NFT tag or the like. The physical identifier may be assigned to the decentral identifier of the digital twin to uniquely link the digital twin and hence the digital twin data with the physical entity of the chemical product.
In an embodiment, the digital twin data structure further includes a product name, product declaration data, product safety data, certificate of analysis data associated with the product, certificates associated with the product or a combination thereof. The digital twin data structure may include different sub data
structures as previously described). At least one sub data structure may include data required by regulation or regulatory data for chemicals. Such sub data structure may include chemical product declaration data, chemical product safety data and certificate of analysis data. At least one sub data structure may include emission data, recyclate content data bio-based content data and/or at least one physical and/or chemical property determined from collected data associated with the production of the product. Each sub data structure may include one or more node(s) (e.g. intermediate nodes and/or leaf node(s)). At least part of the node(s) may be leaf node(s). The sub data structure(s) may be linked to the root node and may hence represent child node(s) of the root node. At least part of the node(s) may be associated with the participant access data. The participant access data associated with at least part of the sub data structure(s) may differ from each other. This allows to define access to the digital twin data structure on a more granular level, hence increasing the security and avoiding undesired access to a sub data structure containing more sensitive information, like the composition of the product, by unauthorized decentral data consuming services.
Emission data may comprise any data related to environmental footprint. The environmental footprint may refer to an entity and its associated environmental footprint. The environmental footprint may be entity specific. For instance, the environmental footprint may relate to a product, a company, a process such as a manufacturing process, a raw material or basic substance, a chemical product or material, a component, a component assembly, an end product, a recycled material, combinations thereof or additional entity-specific relations. Emission data may include data relating to the carbon footprint of the chemical product or a Product Carbon Footprint (PCF). Emission data may include data relating to greenhouse gas emissions e.g. released in production of the chemical product. Emission data may include data related to greenhouse gas emissions. Greenhouse gas emissions may include emissions such as carbon dioxide (CO2) emission, methane (CH4) emission, nitrous oxide (N2O) emission, hydrofluorocarbons (HFCs) emission, perfluorocarbons (PFCs) emission, sulphurhexafluoride (SFe) emission, nitrogen trifluoride (NF3) emission, combinations thereof and additional emissions. Emission data may include data related to greenhouse gas emissions of an entities or companies own operations (production, power plants and waste incineration). Scope 2 may comprise emissions from energy production which is sourced externally. Scope 3 may comprise all other emissions along the value chain. Specifically, this may include the greenhouse gas emissions of raw materials obtained from suppliers. Product Carbon Footprint (PCF) may sum up greenhouse gas emissions and removals from the consecutive and interlinked process steps related to a particular product. Cradle-to-gate PCF may sum up greenhouse gas emissions based on selected process steps: e.g. from the extraction of resources up to the factory gate where the product leaves the company. Such PCFs may be called partial PCFs. In order to achieve such summation, each company providing any products may provide the scope 1 and scope 2 contributions to the PCF for each of its products.
Recyclate content data, bio-based content data and renewable content data may comprise any data related to the recyclate content or the bio-based content or the renewable content used for producing or manufacturing a physical entity of the product.
In an embodiment, the digital twin data structure may include at least two different measured and/or determined physical and/or chemical properties being present in different subsets. Data points and/or data sets within different sub data structures may overlap. The sub data structures may correspond to a data structure obtained upon applying an aspect model to gathered data associated with the physical entity of the product as described previously. The sub data structures may include values and/or value ranges defined in data models used to generate the respective sub data structures. The data models used to generate the sub data structures may contain a tree structure which may be inherited to the respective sub data structures upon generation of the sub data structures. This ensures that each sub data structure has a defined structure and contains defined data set(s) and/or data point(s), thus allowing to simplify data exchange and processing of the exchanged data on products.
In an embodiment, the decentral data providing network node is associated with a data owner of the digital twin and/or the digital twin data structure. The data owner may include an entity generating the digital twin. The data owner may include any entity generating the digital twin data structure. The data generating node may be coupled to the entity producing or owning the physical entity of the products from or for which the digital twin data structure is generated. The digital twin data structure may be generated by a third-party entity on behalf of the entity producing or owning the physical entity of the products from or for which the digital twin data structure is generated. The data owner may be the product producer. The data owner may hence directly or indirectly own the digital twin and digital twin data structure. The digital twin and digital twin data structure may be stored in a database of or associated with the data owner. The digital twin and digital twin data structure may be stored in a database of or under control by the data owner. The digital twin and digital twin data structure may be stored in a database accessible by the data owner. The data owner may control access to the digital twin and digital twin data structure, for instance via the decentral data providing network node associated with the data owner. The digital twin and digital twin data structure may be associated with the data owner. In this sense, the data owner is to be construed broadly as the entity having access to the digital twin and digital twin data structure and controlling access via the decentral data providing network node to the digital twin or a part thereof by data consuming services of the decentral network.
In an embodiment, the group access data is generated based on the digital twin identifier and associated attribute data related to decentral network participant(s). The decentral network participant may include a participants of the product ecosystem. Decentral network participants may be associated with respective decentral participant node(s) allowing peer-to-peer communications within the decentral network. The attribute data may be associated with or includes the role of the decentral network
participant(s) . Roles may include a raw material supplier role, a chemical product producer role, a chemical product consumer role, an OEM role, an end-product user role, a dismantler role, a recycler role, etc.. Roles may be associated with the operation performed by the decentral network participant within the product ecosystem. The group access data may be generated by
• gathering data on decentral network participants,
• generating at least one access control group,
• assigning at least part of the decentral participant identifiers included in the gathered data to at least one generated access control group,
• providing the decentral digital twin identifier included in the digital twin,
• generating the access group data including the provided decentral digital twin identifier and at least one group access policy defining generated access control group(s) for which access to the digital twin data structure is permitted.
Use of the decentral digital twin identifier during generation of the group access data allows to link the generated group access data to the digital twin and hence the digital twin data structure said group access data is applied to upon receiving a request to access said digital twin data structure from a decentral participant node(s).
In an embodiment, the group access data includes a gathering of one or more decentral participant identifier(s) associated with the decentral network participant(s) permitted to access the digital twin data structure. The gathering may correspond to a decentral participant identifier package. The group access policy may include data being indicative of the access control group(s) and associated data being indicative that access to the digital twin data structure associated with the decentral digital twin identifier is permitted. Data being indicative of the access control group(s) may include the package of decentral participant identifiers. Data being indicative of the access control group may include an identifier and/or a name of the access control group. Data being indicative that access is permitted may include a classifier, such as “permitted” or “not permitted”.
In an embodiment, membership in one of the access control groups is indicating that decentral network participant(s) associated with the decentral participant identifier(s) is/are permitted to access the digital twin data structure associated with said access control group. By using the group access data, decentral data consuming network node(s) having access the digital twin data structure may be filtered. For instance, decentral data consuming network node(s) associated with decentral network participants and hence participant identifier(s) included in one or more access control groups permitted to access the digital twin data structure may be permitted access to said digital twin data structure while decentral data consuming network node(s) associated with decentral network participants and hence decentral participant identifier(s) not included in access control groups permitted to access the digital twin data structure may not be permitted access to the digital twin data structure. Access to the digital twin data
structure may hence be controlled by the access control groups irrespective of the rights of a decentral network participant to interact with the digital twin data structure upon accessing said data structure. This allows to manage access rights efficiently, securely and reliably to the digital twin data structure, hence avoiding unauthorized access to said digital twin data structure and improving security.
In an embodiment, membership in one of the access control groups is independent from the participant access data associated with the decentral network participant(s) via the associated decentral participant identifier contained in the participant access data. Hence, access to the digital twin data structure may be managed independently of the participant access data controlling permitted interactions with one or more node(s) included in the digital twin data structure. The group access data allows the data owner to ensure data security by avoiding stale permissions permitting decentral network participants to access and/or manipulate the digital twin data structure when the participant(s) should no longer be able to do so since access control to the digital twin data structure is defined by the access control groups. This allows to manage access to the digital twin data structure easily and reliably without having to check access rights for one or more node(s) present within the digital twin data structure to ensure that no unauthorized decentral network participants have access to node(s) of the digital twin data structure.
In an embodiment, generating the participant access data includes generating access control list data including at least one access control list entry, the at least one access control list entry including the decentral participant identifier(s) associated with the decentral network partici pant(s) permitted to access one or more node(s) present within the digital twin data structure, the respective node(s) to which access is permitted for said decentral network participant(s), and the one or more action(s) allowed to be performed on the node(s) for which access is permitted. Action(s) allowed to be performed on the node(s) may include actions allowed to be performed on data set(s) contained within the node(s), such as key value pair(s) contained within the node(s). The access control entry may further include one or more action(s) allowed to be performed on data point(s) present within the node(s). An access control list entry may be generated for at least part of the data points present within the digital twin data.
Generating access control list data may include gathering data related to the product, wherein the data related to the product includes a gathering of consumer identifier(s) associated with consumers of the product. The gathered data related to the product may be mapped to respective decentral participants identifier(s) contained in the access control groups based on a relationship representation according to which the data related to the product is associated with the decentral participant identifier(s). The relationship representation may specify consumer(s) associated with the product and/or the product associated with consumer(s). The relationship representation may specify the consumer(s) based on consumer identifier(s), such as the consumer identifier(s) contained in the data related to the product, and associated decentral network identifier(s), such as decentral network identifier(s) contained in the
access control groups. The relationship representation may correspond to a data structure containing the relationship between the product, the consumer identifier(s) and the decentral participant identifier(s).
In an embodiment, generating participant access data includes selecting, for one or more node(s), at least one decentral participant identifier permitted to access and interact with the one or more node(s) from decentral participant identifier(s) included in the generated group access data. Interacting may include performing one or more action(s) on the respective node(s).
In an embodiment, the one or more node(s) include(s) emission data, recyclate content data, bio-based content data, provenance data, labour conditions data, data on the composition of the product, material safety data, certificate of analysis data, data associated with the production of the product, certificates data associated with the product, regulatory information data associated with the product, data associated with the transport of the product, data associated with the use of the product, measured and/or determined chemical and/or physical properties of the product, or combinations thereof.
In an embodiment, the one or more actions include read operations, modify operations, update operations, delete operations, create operations, operations involving further processing of the data included in the node(s) by a data processing system associated with the participant of the decentral network or a combination thereof.
In an embodiment, the one or more actions are associated with a particular location, wherein the location is associated with a jurisdiction and the one or more actions are associated with legal requirements related to the supply of products, in particular chemical products. The location may be the location of the decentral data consuming network node. The location may be the location of the decentral data providing network node. The location may be the location of the decentral network participant associated with the decentral data consuming network node. The location may be the location of the decentral network participant associated with the decentral data providing network node. The location may be the location of the entity operated by the decentral network participant. The location may be determined based on the decentral participant identifier.
In an embodiment, the one or more actions are associated with at least one regulatory requirement for the supply of products.
In an embodiment, the one or more action(s) are associated with obligations of decentral data consuming network node(s) associated with respective decentral participant identifier(s) and/or obligations of decentral network node(s) using the digital twin data structure accessed by data consuming network node(s) associated with respective decentral participant identifier(s). Such obligations may include data transaction logging, usage policies for processing or use of the accessed digital twin data structure, mapping to access prescriptions or the like. Usage policies for processing or use of the accessed digital
twin data structure may include conditions for a time restriction of the usage of the accessed digital twin data structure. For instance, the usage policies may contain duration data being indicative of a duration the digital twin data structure may be accessed by decentral data consuming network node(s). After the duration has elapsed, the digital twin data structure may no longer be accessed by said decentral data consuming network node(s). Usage policies for processing or use may include one or more prescribed processing rules relating to the processing of emission data, production data, recyclate content data, bio-based content data, provenance data, labour conditions data or combinations thereof by a decentral data consuming network node associated with a decentral participant identifier. Usage policies including one or more prescribed processing rules may be enforced by applications using the accessed digital twin data structure. Usage policies for processing or use may include obligations associated with a purpose the accessed digital twin data structure is allowed to be processed for or used for. For instance, such usage policies may define that the accessed digital twin data structure is only used in the context of emission data calculations. Usage policies associated with a purpose may be enforced by applications using the accessed digital twin data structure. Usage policies may be attached to digital twin data structure provided from the decentral data providing network node to the decentral data consuming network node.
By using the participant access data, actions permitted to be performed on particular node(s) present within the digital twin data structure by decentral network participant upon to access the digital twin data structure may be defined, hence ensuring that only decentral network participants associated with decentral participant identifier(s) defined in the participant access data are permitted to perform defined action(s) on said particular node(s). This avoids generation of multiple copies of the digital twin data structure containing different node(s) to ensure that different decentral network participants may only access and interact with data digital twin data structure they are authorized to access and to interact with.
In an embodiment, the access policy data includes computer-executable instructions to allow access to the digital twin data structure, deny access to the digital twin data structure, to modify access to the digital twin data structure or to perform one or more action(s) on the digital twin data structure.
In an embodiment, the access policy data includes the decentral digital twin identifier, the decentral participant identifier(s) included in the access group data, the decentral participant identifier(s) permitted to access one or more node(s) present within the respective digital twin data structure and one or more actions allowed to be performed on one or more node(s) by the decentral participant node(s) associated with the decentral participant identifier(s) included in the participant access data.
In an embodiment, the access policy generator is further configured to link the access policy data to the digital twin. Linking may include including the decentral digital twin identifier associated with the digital twin in the access policy data. Linking may include associating an identifier included in the access policy data, such as an access policy data identifier, with the decentral digital twin identifier associated with the
digital twin. Linking of the access policy data to the digital twin avoids generation of different digital twins for a chemical product for different participants of the decentral network associated with different participant access data.
In an embodiment, the access policy data generator is further configured to provide at least part of the generated access policy data to the decentral data providing network node. The provided access data may be stored in a database of or associated with the decentral data providing network node. Providing the access policy data to the decentral data providing network node allows to store the digital twin data structure separately from the decentral data providing network node, thus ensuring a higher level of security since appropriate authentication and authorization schemes can be implemented for communications between the downstream database(s) storing the digital twin data structure and the decentral data providing network node. Moreover, only minimum amount of data is stored in the database associated with the decentral data providing network node, hence reducing the risk of unwanted data leakage of digital twin data structure(s) associated with produced products in case the contents of the database of the decentral data providing network node are accessed unauthorized.
At least part of the access policy data may include group access data. The decentral data providing network node may be configured to use the group access data to filter decentral data consuming network nodes authorized to access the digital twin data structure. The decentral data providing network node may be configured to control access to the digital twin data structure based on the provided access policy data. The decentral data providing network node may be associated with the data owner of the digital twin or parts thereof, such as sub data structure(s). The data owner may be the product producer. The data owner may be a data owner a previously described. The decentral data providing network node may be directly or indirectly connected to one or more dedicated data storage(s) storing the digital twin data structure. The dedicated data storage(s) may be under control of the data owner of the digital twin and/or the digital twin data structure. The data owner may have access to the dedicated data storage(s). The data owner may hence control access to the digital twin data structure via the decentral data providing network node based on the decentral digital twin identifier and associated access policy data. This allows to retain full control of the digital twin data structure by the data owner but at the same time enabling sharing of the digital twin data structure under controlled conditions by using access policy data associated with said digital twin.
By combining group access data with participant access data, access to the digital twin data structure may be controlled on separate levels, ensuring that only authorized decentral network participants can access and interact with node(s) present within the digital twin data structure while avoiding generation of multiple digital twin data structure copies to ensure that the each respective copy of the digital twin data structure only includes node(s) that decentral participant nodes being members of the associated access control group is permitted to access and interact with. Hence, a decentral participant node(s)
being a member of the same access control group may be permitted to interact with different node(s) present within the digital twin data structure without having to generate multiple copies of digital twin data structure containing different node(s). This enables to control access to digital twin data structure by the decentral data providing network node based on the decentral digital twin identifier and requested action(s) by filtering decentral data consuming network node(s) requesting access to the digital twin data structure based on the decentral participant identifier(s)..The database storing the digital win data structure may be configured to control interaction(s) with the one or more node(s) based on the participant access data.
In an embodiment of the computer-implemented method for controlling access to a digital twin of a physical entity of a product by a decentral data consuming network node associated with a participant of a decentral network, the request may be received based on a digital access element containing a decentral passport identifier associated with the product and digital twin location data. The decentral passport identifier may correspond to the decentral digital twin identifier contained in the digital twin or may be associated with the decentral digital twin identifier. The digital twin location data may include a digital representation pointing to the decentral data providing network node associated with the digital twin. The digital twin location data may include a representation for accessing the digital twin or a part thereof. The decentral digital twin identifier may be associated with the representation for accessing the digital twin or the part thereof. The digital access element may correspond to a DID document associated with the decentral digital twin identifier or decentral passport identifier, said DID document including the decentral digital twin identifier or decentral passport identifier in the form of a decentralized identifier (DID). The digital access element may be retrieved from a central or decentral repository. The digital access element may be retrieved based on the decentral digital twin identifier associated with a physical identifier of the product. For instance, the decentral identifier may be embedded in the physical identifier. In another instance, the product identifier may be embedded in the physical identifier and the product identifier may be used to retrieve the associated decentral digital twin identifier and - based on said decentral digital twin identifier, the digital access element.
In an embodiment of the computer-implemented method for controlling access to a digital twin of a physical entity of a product by a decentral data consuming network node associated with a participant of a decentral network, the method includes a step of authenticating a decentral network node for access to the digital twin or a part thereof associated with the product. Authenticating may include receiving a request to authenticate the decentral network node. The request may include a decentral network node identifier associated with the decentral network node. The request may include the decentral participant identifier associated with the decentral data consuming network node. The request may include the decentral participant identifier associated with the decentral data providing network node. Authentication may further include providing one or more authentication mechanisms associated with the decentral network node identifier. The authentication mechanisms may be associated with a private-public key
infrastructure. The authentication mechanisms may be provided from at least one authentication data registry. The authentication data registry may be a central registry node such as a central file system, a centrally managed distributed database, and/or a centrally managed peer-to-peer network. The central configuration allows for more control and standardization via a central node. The authentication data registry may be a decentral registry such as a distributed ledger, a decentralized file system, a distributed database, and/or a peer-to-peer network. The decentral configuration allows for more efficient use of computing resources and strengthens control by the data owner. In addition, the decentral configuration is independent from centrally managed nodes and increases reliability and flexibility of the system. The authentication mechanisms may be provided in response to a request from the decentral network node to the authentication registry. Based on the authentication mechanism, a request to generate authentication data may be provided. The authentication data received in response to the request may be verified and access to the digital twin data structure may be authorized if the authentication is verified, or access may be denied, if the authentication is not verified. The access may be authorized by the apparatus or computer-implemented method for authorizing access.
The decentral network node to be authenticated may provide a dynamic token from at least one authentication data registry and/or an identity token to be presented in the authentication request to the decentral network node performing the verification. For instance, the decentral data consuming network node may provide a dynamic token from at least one authentication data registry and/or an identity token to be presented in the authentication request to the decentral data providing network node. In another instance, the decentral data providing network node provides a dynamic token from at least one authentication data registry and/or an identity token to be presented in the authentication request to the decentral data consuming network node. The dynamic token may be generated based on a certificate scheme. The dynamic token may be associated with a public private key infrastructure. The verifying decentral network node may grant access to another decentral network node to be authenticated based on verification of the dynamic token and/or the identity token by the verifying decentral network node. The decentral network node to be authenticated may grant access to the verifying decentral network node based on verification of the dynamic token and/or the identity token by the decentral network node to be authenticated. For instance, the decentral data consuming network node is granted access to the decentral data providing network node based on verification of the dynamic token and/or the identity token by the decentral data providing network node. In another instance, the decentral data providing network node may grant access to the decentral data consuming network node based on verification of the dynamic token and/or the identity token by the decentral data providing network node. The authentication process may be implemented as part of the decentral data providing network node or the decentral data consuming network node. The authentication process may be provided by a separate authentication service accessible for the decentral data providing network node and/or the decentral data consuming network node. In the authentication process, one decentral network node may act as verifying service and the other decentral network node may act as service to be authenticated.
At least one authentication mechanism may be based on a private-public-key infrastructure, a digital certificate issued by a certificate issuer, a biometric authentication service or combinations thereof. The public key may be included in the digital access element. The digital access element may include the decentral passport identifier, access data and the public key. The digital access element may be recorded on at least one authentication registry. In response to an authentication request by a decentral data service, authentication data including a cryptographic signature encrypted by the private key of the requesting decentral data service may be provided. The provided authentication data may be validated based on the at least one authentication mechanism. Validation may include retrieving the public key from the authentication data registry, decrypting the cryptographic signature using the retrieved public key and in response to a valid decryption result, determine if the authentication request is valid. Access to digital twin data may be granted, if the authentication request is valid, or access to digital twin data may be denied, if the authentication request is not valid.
In an embodiment of the computer-implemented method for controlling access to a digital twin of a physical entity of a chemical product by a decentral data consuming network node associated with a participant of a decentral network, the method further comprises
• obtaining access control list data associated with one or more nodes(s) present within the digital twin data structure,
• identifying one or more actions to be performed on the one or more node(s) present within the digital twin data structure based on data contained in the received request,
• determining whether the decentral network participant is permitted to perform the one or more actions requested to be performed on the one or more node(s) by comparing access control list entries present within the access control list data with the data included in the received request, and, in response,
• performing the one or more actions requested to be performed on the one or more node(s) or providing the digital twin data structure according to the one or more requested actions to the decentral data consuming network node.
Providing the digital twin data structure may include providing the digital twin data structure associated with computer-executable instructions configured to control access to said provided digital twin data structure. The computer-executable instructions may comprise obligations concerning the use and/or processing of the provided digital twin data structure.
BRIEF DESCRIPTION OF THE SEVERAL VIEWS OF THE DRAWINGS
In the following, the present disclosure is further described with reference to the enclosed figures. The same reference numbers in the drawings and this disclosure are intended to refer to the same or like elements, components, and/or parts.
FIG. 1 illustrates an example embodiment of a decentral network environment including decentral participant network nodes associated with participants of a product ecosystem involving chemical products.
FIG. 2 illustrates an example of a chemical production controlled by an operating system including a digital twin management system.
FIG. 3 illustrates an example of a production system providing a chemical product associated with a one or more digital twin(s).
FIG. 4A illustrates an example apparatus for generating access policy data to control access to a digital twin of a physical entity of a product produced from one or more input materials in accordance with an embodiment of the present disclosure.
FIG. 4B illustrates an example system for generating access policy data to control access to a digital twin of a physical entity of a product produced from one or more input materials in accordance with an embodiment of the present disclosure.
FIG. 5 illustrates an example digital twin data structure including a tree structure.
FIG. 6A illustrates an example of controlling access to digital twin data structure based on different access control groups.
FIG. 6B illustrates an example of controlling access to digital twin data structure based on access control group(s) in combination with fine grained access control on node level in accordance with an embodiment of the present disclosure.
FIG. 7A illustrates a first example of controlling access to the digital twin data structure based on access policy data including group access data and participant access data associated with one or more node(s) present within the digital twin data structure in accordance with an embodiment of the present disclosure.
FIG. 7B illustrates another example of controlling access to the digital twin data structure based on access policy data including group access data and participant access data associated with one or more node(s) present within the digital twin data structure in accordance with an embodiment of the present disclosure.
FIG. 8A illustrates a first example of a linkage between a digital twin data structure of a product and a digital access element via the decentral digital twin identifier.
FIG. 8B illustrates a second example of a linkage between a digital twin data structure of a product and digital access elements via the decentral digital twin identifier.
FIG. 9A illustrates an example of a system and associated methods for controlling access to a digital twin of a product produced from one or more input materials by a production in accordance with an embodiment of the present disclosure.
FIG. 9B illustrates an example of an apparatus and associated methods for controlling access to a digital twin of a product produced from one or more input materials by a production using a digital access element in accordance with an embodiment of the present disclosure.
FIG. 10 illustrates a flow chart of a computer-implemented method for generating a digital twin of a physical entity of a product in accordance with an example embodiment of the present disclosure.
FIG. 11 illustrates a flow chart of a computer-implemented method for generating access policy data for controlling access to a digital twin of a physical entity of a product produced from one or more input materials in accordance with an example embodiment of the present disclosure.
FIG. 12 illustrates a flow chart of a computer-implemented method for generating group access data as described in block 1002 of FIG. 1 1 in accordance with an example embodiment of the present disclosure.
FIGs. 13A, 13B illustrate examples of relationship representations which may be used to generate participant access data as described in the context of FIG. 11 .
FIG. 14 illustrates a flow chart of a computer-implemented method for controlling access to a digital twin of a physical entity of a product by a decentral data consuming network node associated with a participant of a decentral network in accordance with an example embodiment of the present disclosure.
FIG. 15A illustrates a diagram showing a first example of processing a request from a decentral data consuming network node to access digital twin data structure.
FIG. 15B illustrates a diagram showing a further example of processing a request from a decentral data consuming network node to access digital twin data structure.
FIG. 16 shows a schematic illustration for controlling access by a decentral data providing network node to digital twin data structure of a digital twin associated with a product using a digital
access element to access the digital twin data structure in accordance with an example embodiment of the present disclosure.
FIG. 17 illustrates a flow chart a computer-implemented method for processing digital twin data structure of a digital twin of a physical entity of a product in accordance with an example embodiment of the present disclosure.
FIG. 18 illustrates a computer-implemented method for controlling access to digital twin data structure of a digital twin of a physical entity of a chemical product by a decentral data consuming network node using a digital access element associated with the product in accordance with an example embodiment of the present disclosure
FIG. 19 illustrates an example of a digital access element including DID owner data, DID document data and decentral identity infrastructure.
DETAILED DESCRIPTION
The following embodiments are mere examples for implementing the method, the system or application device disclosed herein and shall not be considered limiting.
FIG. 1 illustrates an example embodiment of a decentral network environment. The decentral network environment may include a decentral participant network 130. The decentral participant network 130 may include one or more decentral network participants 102 to 1 12. The decentral network participants may be part of a product ecosystem including chemical products. The product ecosystem may include production chains to produce an end-product. The product ecosystem may include recycling chains to recycle at least part of an end-of-life product. The product ecosystem may include a chemical product producer 102,, a chemical product consumer 104, an OEM 106, an end-product user 108, an EOL product collector 110 and a recycler 112. The product ecosystem may include further participants, such as raw material suppliers 134. The decentral participant network 130 may be a chemical supply chain. The product ecosystem may allow to use materials resulting from recycling of end-of-life products to produce new products, such as chemical products. The product ecosystem may be associated with the production and/or recycling of physical products. The product may be a chemical product, an intermediate chemical product, a component, a component assembly, an end product, an end-of-life product or a recycled product.
The participant(s) of the decentral participant network 130 may be associated with the production the product and/or recycling of the product. The decentral network participant 102 to 112 may refer to a manufacturer of physical products, such as chemical product producer 102, chemical product consumer 104, OEM 106, end-product user 108, EOL product collector 110 and recycler 1 12. The decentral network
participant may be associated with a decentral participant identifier. The decentral participant identifier may uniquely identify the decentral network participant within the decentral participant network 130.
The participant(s) of the decentral participant network 130 may be connected via material flow 132. The material flow 132 may correspond to the flow of product from an upstream participant of the decentral participant network 130 to the downstream participant of the decentral participant network 130. The material flow 132 may refer to a continuous or a discontinuous flow of product. The flow of product may include any means of transportation suitable to transport the product from a participant to the downstream participant. The means of transportation may include pipes, containers, barrels, packages. The material flow 132 may be associated with raw materials used to produce the chemical product, such as virgin raw materials. The raw materials may be provided to the chemical product manufacturer for producing chemical product(s) and/or intermediate chemical product(s) (not shown).
The data flow 128 between decentral network participant nodes may be directly or indirectly associated with the material flow 132 between the decentral network participants. For instance, data flow 128 may be directly associated with material flow 132 if data associated with a chemical product provided from the chemical product producer 102 to the chemical product consumer 104 is accessed by a decentral data consuming network node associated with said chemical product consumer 104. For instance, data flow 128 may be indirectly associated with material flow 132 if data associated with a chemical product produced by chemical product producer 102 is accessed by a decentral data consuming network node associated with recycler 112.
At least part of the participants of the decentral participant network 130 may be associated with decentral participant network nodes 116, 1 18, 120, 122, 124. The decentral participant nodes 1 16 to 124 may be under control of the respective decentral participant associated with the respective decentral participant node. The decentral participant nodes 116 to 124 may form decentral network 126. The decentral network 126 may be a peer-to-peer communication network. The decentral network 126 may be configured to perform data transactions 128. The data transactions 128 may be based on a transaction protocol including authentication and/or authorization mechanism(s). Based on the authentication and/or authorization mechanism(s) a peer-to-peer communication between decentral network nodes 116 to 124 associated with decentral network participants 102 to 112 may be established. The one or more authentication mechanism(s) may be associated with or linked to a decentral digital twin identifier and/or a decentral passport identifier as described in the context of FIG. 15. The one or more authentication mechanism(s) associated with the decentral digital twin identifier and/or the decentral passport identifier may be accessible by a decentral data providing network node and/or a decentral data consuming network node as described in the context of FIG. 15. The decentral configuration allows for more efficient use of computing resources and strengthens control by the data owners of the decentral network.
Data transactions between decentral network participant nodes may be based on a decentral identifier associated with respective product data to be accessed, for example as described in the context of FIG. 9A, FIG. 9B and FIG. 16. The decentral identifier may be uniquely associated with the physical entity of the product and associated product data. The decentral identifier may uniquely identify the respective product within the decentral network. The decentral identifier may be associated with further decentral identifier(s), such as decentral identifier(s) of product(s) used to produce the product. This may allow to track the product(s) used to produce a product, such as an end-product. The decentral identifier may be included in a digital access element associated with the product, for example as described in the context of FIG. 16 and FIG. 19.
The decentral participant nodes 116 to 124 may be decentral computing nodes. The decentral computing node may be any device or system that includes at least one physical and tangible processor, and a physical and tangible memory capable of having thereon computer-executable instructions that are executed by a processor. The memory may take any form and depends on the nature and form of the computing node.
At least part ofthe decentral participant nodes 1 16 to 124 may be decentral data providing network nodes. At least part of the participant nodes 1 16 to 124 may be decentral data consuming network nodes. A participant of the decentral participant network 130 may be associated with a decentral data providing network node and/or a decentral data consuming network node depending on whether data is provided to downstream participants and/or consumed from upstream participants. For instance, chemical product producer 102 may be associated with a decentral data providing network node configured to provide chemical product data to a downstream participant (e.g. chemical product consumer 104) for example as described in the context of FIG. 15. In addition to or alternatively, chemical product producer 102 may be associated with a decentral data consuming network node configured to access data associated with the recycled product produced by an upstream participant (e.g. recycler 1 12).
The decentral network 126 may include further decentral network nodes. The further decentral network nodes may be decentral infrastructure service nodes (not shown in FIG. 1). The decentral infrastructure service nodes may not be associated with a participant of the product ecosystem. The decentral infrastructure service nodes may provide services for decentral participant nodes 116 to 124, such as verifying the identity of the decentral network participant nodes 116 to 124 prior to performing a data exchange. The decentral network participant nodes 1 16 to 124 may be associated with or include certificate(s), such as X.509 certificate(s). The certificate(s) may be associated with decentral infrastructure service node(s) including e.g. a certificate issuing service and/or a dynamic provisioning service providing dynamic attribute tokens (e.g. OAuth Access Tokens). This way the decentral network participant nodes 1 16 to 124 possess a unique identifier embedded in a X.509 certificate that identifies the respective decentral network participant node 116 to 124. The information required to verify the
certificate may be provided via an authentication registry associated with the certificate issuing service and/or a dynamic provisioning service. For instance, in the IDSA Reference Architecture Model, Version 3.0 of April 2019, a decentral data providing network node associated with a data owner, a Certification Authority (CA), a Dynamic Attribute Provisioning Service (DAPS) and a decentral data consuming network node associated with a data consumer are used to verify the identity prior to performing a data exchange (not shown) .
FIG. 2 illustrates an example of a chemical production 204 producing one or more chemical products(s) from one or more inbound material(s) 202 in connection with an operating system 208 including a digital twin management system. The chemical production 204 may be associated with a decentral network participant, such as the chemical product producer 102 described in the context of FIG. 1 . The operating system 208 may be used to operate the chemical production 204, for example by managing different production chains present within the chemical production. For producing one or more chemical product(s) 206, different chemical materials 202 (also called inbound material 202 hereinafter) may be provided as physical inputs from material providers or suppliers. The physical inputs to the chemical production 204 may include chemical materials, such raw materials, intermediate materials or a combination thereof. Raw materials may be virgin or recycled raw materials. The inbound material 202 may be fed into the chemical production 204 at any entry point. The inbound material 202 may be fed into the chemical production 204 at the start of the chemical production 204. The inbound materials may be considered input for the chemical production 204.
The chemical production 204 may be a chemical production network including multiple interlinked processing steps. The chemical production network may be an integrated chemical production network with interrelated production chains. The chemical production network may include multiple different production chains that have at least one intermediate product in common. The chemical production network may include multiple stages of the chemical value chain. The chemical production network may include multiple production chains that produce from one or more inbound material(s) as input chemical products as output. The chemical production network may include multiple tiers of a chemical value chain. The chemical production network may include a physically interconnected arrangement of production sites. The production sites may be at the same location or at different locations. In the latter case, the production sites may be interconnected by means of dedicated transportation systems such as pipelines, supply chain vehicles, like trucks, supply chain ships or other cargo transportation means.
The chemical production 204 may include multiple production steps. The production steps included in the chemical production 204 may be defined by the system boundary of the chemical production 204. The system boundary may be defined by location or control over production processes. The system boundary may be defined by the site of the chemical production 204. The system boundary may be defined by production processes controlled by one entity or multiple entities jointly. The system boundary may be
defined by value chain with staggered production processes to an end product, which may be controlled by multiple entities separately.
The chemical production 204 may convert inbound material 202 to one or more chemical products 206 that exit the chemical production 204. The conversion may be performed via intermediate chemical products. The conversion may be a chemical reaction or any other processing step, such as physical processing. The chemical reaction may result in a mixture of different chemical product(s) since the yield of the chemical reaction may be less than 100%. Hence, a chemical reaction of one or more starting materials, such as inbound material(s) 202, may result in a mixture of different chemical product(s). Chemical reactions may therefore be characterized by a one-to-many or many-to-many relationship between starting materials and resulting reaction productions. This contrasts with discrete manufacturing, where a many-to-one relationship between parts/components and assemblies is existing, e.g. the result of a discrete manufacturing step is a concrete and predictable assembly. Since the yield of a chemical reaction is not 100%, the amount of desired chemical product 206 (e.g. chemical product(s) to be supplied to upstream participants of the chemical ecosystem) is less than the theoretical amount of said chemical product calculated from the amount of starting materials. Such mixtures typically require separation of the different chemical products contained in said mixture. This allows to avoid a negative influence of impurities and unreacted inbound material(s) 202 on the further processing of the chemical product 206. Separation may include distillation, washing, extraction, crystallization and recrystallization. The resulting mixture may contain unreacted starting material, such as unreacted inbound material 202. Unreacted starting material may be reintroduced into the chemical reaction to reduce the amount of required starting material. The resulting mixture may contain desired chemical product(s) 206 to be supplied to upstream participants of the chemical ecosystem, such as chemical product consumers or chemical product processors. The resulting mixture may contain intermediate chemical product(s) used as input material in further chemical reactions performed within the chemical production 204. This allows to reduce the amount of waste associated with the disposal of said intermediate chemical products and/or the amount of energy associated with transportation of these intermediate products to another chemical production. The resulting mixture may contain waste chemical product(s), e.g. chemical product(s) which cannot be used any further and which need to be disposed, for example by burning. Waste chemical products may be produced from undesired chemical side reactions.
The chemical production 204 may comprise a plurality of sensors 210a, 210b. The sensors 210a, 210b may measure at least one chemical and/or physical property of the chemical product(s) 206 produced by the chemical production 204. The sensors 210a, 210b may measure at least one chemical and/or physical property of the inbound material(s) 202 provided to the chemical production 204. The sensors 210a, 210b may include sensors 2010b configured to determine the amount of inbound material(s) 202 and/or produced chemical product(s). Examples of such sensors may include scales or flow meters. The sensors 210a, 210b may include sensors 210a configured to measure at least one chemical and/or physical
property of the inbound material(s) 202. Measurement of chemical and/or physical properties of the inbound material(s) 202 allows to control production processes based on the measured data. The sensors 210a, 210b may include sensors 210a configured to determine chemical and/or physical properties of the produced chemical product 206. Sensors 210a configured to measure chemical properties may measure data associated with or corresponding to the heat of combustion, enthalpy of formation, toxicity, chemical stability in a given environment, flammability, oxidation state(s), ability to corrode, combustibility, acidity and basicity and/or pH value. Sensors 210a configured to measure physical properties may measure data associated with or corresponding to absorption, brittleness, boiling point, capacitance, color, concentration, density, ductility, distribution, efficacy, elasticity, electric charge, electrical conductivity, electrical impedance, electric potential, flow rate, fluidity, hardness, heat capacity, inductance, intrinsic impedance, luminance, luminescence, luster, mass, melting point, opacity, permeability, permittivity, plasticity, pressure, radiance, resistivity, reflectivity, refractive index, solubility, specific heat, strength, stiffness, temperature, tension, thermal conductivity, thermal resistance, viscosity, volume and/or wave impedance. Data measured by sensors 210a, 210b may be stored in one or more databases, for example databases contained in data source layer 422 of FIG. 4B. The one or more databases may be distributed databases. The stored data may be interrelated with input material identifier(s) and/or chemical product identifier(s), respectively.
The operating system 208 of the chemical production may monitor and/or control the chemical production 204 based on operating parameters associated with the different processes performed by the chemical production 204. One process step monitored and/or controlled may be the feed of inbound materials 202 or the release of produced chemical product(s) 206. Another process step monitored and/or controlled may be the separation of chemical product(s) contained in mixtures resulting from chemical reactions performed within the chemical production 204. Another process step monitored and/or controlled may be the determination of chemical and/or physical properties of produced chemical product(s) 206 from data collected associated with the production of the chemical product, such as data measured by sensors 210a, 210b before, during and/or after production of the chemical product(s) 206. Another process step monitored and/or controlled may the generation of digital twins. The digital twins may be generated by an apparatus for generating DTs 424 as described in the context of FIG. 9A and FIG. 9B. The digital twins may be generated using the method described in FIG. 10. Yet another process step monitored and/or controlled may be the generation of access policy data to control access to generated digital twins by one or more decentral data consuming network nodes, for example as described in the context of FIG. 4A, FIG. 4B, FIG. 11 and FIG. 12. Yet another process step monitored and/or controlled may be the control of access to the generated digital twins based on the generated access policy data, for example as described in the context of FIG. 7A. FIG. 7B, Fig, FIG. 15A and FIG. 15B. Yet another process step monitored and/or controlled may be the generation of digital access elements associated with digital twins of produced chemical products, for example as described in the context of FIG. 9B and FIG. 18. Yet
another process step monitored and/or controlled may be the control of access to the generated digital twin based on generated digital access elements, for example as described in the context of FIG. 16.
The operating system 208 may be configured to determine physical and/or chemical properties of the chemical product from collected data associated with the production of the chemical product. The operating system 208 may be configured to generate a digital twin of a chemical product, for example as described in the context of FIG. 3, FIG. 9A and FIG. 10. The operating system may be configured to generate access policy data to control access to the digital twin, for example as described in the context of FIG. 4A, FIG. 4B, FIG. 11 and FIG. 12. The operating system 208 may be configured to generate a digital access element associated with the digital twin, for example as described in the context of FIG. 9B. The operating system may be configured to control access to the digital twin based on generated access policy data, for example as described in the context of FIG. 7A, FIG. 7B and FIG. 14. The operating system may be configured to control access to the digital twin based on the generated access element, for example as described in the context of FIG. 16.
FIG. 3 illustrates an example for generating digital twins for different chemical products used within the product ecosystem. The chemical products may be generated by a decentral network participant, such as chemical product producer 102 described in the context of FIG. 1 . The chemical product, such as chemical product 206, may be produced by a chemical production 204 comprising an operating system 208, for example as described in the context of FIG. 2. FIG. 3 specifically illustrates an example for generating a digital twin for a precursor material (e.g. intermediate chemical product) and for generating a digital twin for a chemical product produced at least in part from said precursor material.
The production of a chemical product may comprise a two-step process: 1) production of intermediate chemical product(s) from one or more inbound material(s), and 2) production of the chemical product at least in part from the intermediate chemical product(s). To produce the intermediate chemical product(s), inbound materials may be used as physical inputs. The inbound materials may be provided from raw material provider(s). The inbound materials may include virgin or recycled materials. The inbound materials may be provided to an intermediate chemical product production as inbound material 202. The intermediate chemical product production may be a chemical production 204 as described in the context of FIG. 2. The inbound materials may comprise a physical identifier. The physical identifier may be or may be associated with a decentral inbound material identifier. The decentral inbound material identifier may be associated with a digital twin of the inbound material. The operating system, such as the operating system 208 described in the context of FIG. 2, of the intermediate chemical product production may comprise or be in communication with an ID reader configured to read the physical identifier and to determine the decentral inbound material identifier associated with said physical identifier. The digital twin of the inbound materials may be generated as described in the context of FIG. 9 below. The digital twin may include a measured physical and/or chemical property and/or a physical and/or chemical
property determined from collected data associated with the production and/or the use of the inbound material. The physical and/or chemical property may be measured with sensors as described in the context of FIG. 2. The physical and/or chemical property may be determined from collected data as described in the context of FIG. 2. The digital twin may further include the inbound material name, inbound material producer, inbound material declaration data, inbound material safety data, emission data such as CO2 footprint and/or PCF data, recyclate content data, biobased content data, certificate of analysis data associated with the inbound material, certificates associated with the inbound material or a combination thereof.
The operating system may be configured to access the digital twin or a part thereof of inbound material(s) provided to the intermediate chemical product production based on the determined decentral inbound material identifier(s) e.g. from decentral data providing network node(s) associated with the inbound material provider(s) (see for example FIG. 15). Such data may be used to operate the chemical production producing the intermediate chemical product(s). For instance, if the inbound material(s) are recycled material(s), production steps purifying the recycled material(s) may be performed. For instance, if the inbound material(s) are virgin materials, purification steps may be omitted. The intermediate chemical product(s) may be formed by chemically reacting the inbound material(s) and/or by physically processing the inbound material(s). Chemical reactions may include polymerization, precipitation and other chemical reactions commonly known. Physical processing may include mixing, grinding, extruding, etc.. The intermediate chemical product production may include sensors, such as sensors 210a, 210b, measuring physical and/or chemical properties of the intermediate chemical product(s) produced by the intermediate chemical product production as described in the context of FIG. 2. The operating system may be configured to determine physical and/or chemical properties from collected data associated with the production of the intermediate chemical product(s), for example as described in the context of FIG. 2.
The operating system may be configured to generate digital twin(s) for the produced intermediate chemical product(s) as described in the context of FIG. 10 below. Each digital twin may include a decentral intermediate chemical product identifier and at least one chemical and/or physical property of the respective intermediate chemical product measured by sensors 210a, 210b and/or at least one physical and/or chemical property of the respective intermediate chemical product determined from collected data. The digital twin may further include decentral inbound material identifier(s) of inbound material(s) used to produce the respective intermediate chemical product. This allows to track the inbound materials used to produce the respective intermediate chemical product. The digital twin may further include data previously described in relation with the digital twin of the inbound material(s). Intermediate chemical product digital access element(s) may be generated, for example as described in the context of FIG. 9B. The produced intermediate chemical product(s) may be packaged, and the packaging may include a physical identifier, such as a QR code, an embossed code or an optical holographic code, such as zero-order diffractive microstructure. The physical identifier may be assigned
to the respective decentral intermediate chemical product identifier of the digital twin and/orthe respective decentral passport identifier of the intermediate chemical product digital access element. The assignment of the physical identifier and the decentral intermediate chemical product identifier may be executed through an ID assignor running locally, in a decentral system and/or in a distributed system. For instance, the packaging line may comprise a labelling device detecting the packaging of the produced intermediate chemical product(s). Based on such recognition, a requestor may generate a request to generate the digital twin and the respective decentral intermediate chemical product identifier included in the generated digital twin may be assigned, for example by the ID assignor, to the respective physical identifier (see also FIG. 9A, FIG. 9B below). Assigning may include encoding the respective decentral intermediate chemical product identifier in a physical identifier and providing the physical identifier, such as a code, to the labelling device configured to attach the physical identifier to the respective intermediate chemical product, such as the packaging of the respective intermediate chemical product. The ID assignor may be part of the labelling device or may be a separate device.
In a second step, the intermediate chemical product(s) produced in step 1) may be provided to a chemical production 204 as inbound material 202 to produce the chemical product 206. The chemical production 204 may be the chemical production 204 described in the context of FIG. 2. The chemical production may be associated with a decentral network participant, such as chemical product producer 102 described in the context of FIG. 1 . The chemical production 204 may be the chemical production producing the intermediate chemical product(s). The chemical production 204 may be different from the chemical production producing the intermediate chemical product(s). Apart from the intermediate chemical product(s) produced in step 1), further inbound material(s) may be provided to the chemical production and may be used to produce the chemical product 206. The intermediate chemical product(s) may comprise recycled intermediate chemical product(s) and/or intermediate chemical product(s) produced by a different intermediate chemical product production than the intermediate chemical product production described in the context of step 1). Such intermediate chemical product(s) may be associated with a physical identifier. The physical identifier may be associated with a decentral intermediate chemical product identifier via which the digital twin or a part thereof of the respective intermediate chemical product may be accessible as previously described. An ID reader may be used to read the physical identifier associated with the respective decentral intermediate chemical product identifier as described above. The digital twin or a part thereof may be access via a decentral data consuming network node, for example via a decentral data consuming network node associated with the chemical product producer 102 as described in the context of FIG. 1 , using the decentral intermediate chemical product identifier as described above.
Production data from the intermediate chemical product production of the intermediate chemical product may be used by the operating system, such as operating system 208 described in the context of FIG. 2, of the chemical production to produce the chemical product 206 as described above. The chemical
production may include sensors, such as sensors 210a, 210b, measuring physical and/or chemical properties of the chemical product produced by the chemical production as described in the context of FIG. 2. The operating system may be configured to determine physical and/or chemical properties from collected data associated with the production of the chemical product, for example as described in the context of FIG. 2.
The operating system may be configured to generate a digital twin for the produced or packaged chemical product as described above. The digital twin may include a decentral chemical product identifier and at least one measured and/or determined physical and/or chemical property as outlined above. The digital twin may include decentral intermediate chemical product identifier(s). This allows to track the intermediate chemical product(s) used to produce the chemical product and also indirectly the inbound material(s) used to produce the intermediate chemical product(s). The digital twin may include further data as outlined above, such as the producer name, producer brand, producer identifier, chemical product name, chemical product brand and chemical product identifier.
A digital access element associated with the chemical product may be generated, for example as described in the context of FIG. 9A. The decentral chemical product identifier and/or the digital access element may be associated with the chemical product via a physical identifier as described above. The digital access element may include a decentral passport identifier and access data. Access data may include a digital representation pointing to the digital twin or parts thereof. The decentral passport identifier may correspond to or be associated with the decentral chemical product identifier. The digital access element may be used by the chemical product consumer 104 (see FIG. 1) to access chemical product data. The chemical product data may be accessed via a decentral data consuming network node associated with the chemical product consumer 104. Access to the chemical product data may be controlled by a decentral data providing network node associated with the chemical product producer 102 based on access policy data, for example as described in the context of FIG. 15A and FIG. 15B.
FIG. 4A illustrates an example apparatus 402 for generating access policy data to control access to a digital twin of a physical entity of a chemical product produced from one or more chemical input materials. The digital twin may be accessed by decentral data consuming network node(s) (not shown). The decentral data consuming network node(s) may be associated with downstream participants of the chemical product producer 102, such as chemical product consumers 104 (see for example FIG. 1). Access to the digital twin may be controlled based on the generated access policy data, for example as described in the context of FIG. 7A, FIG. 7B, FIG. 15A and FIG. 15B.
Apparatus 402 may be included in operating system 208 of chemical production 204 producing chemical products from one or more inbound materials (see for example FIG. 2). The chemical products may be intermediate chemical products. The chemical products may be chemical end-products. Apparatus 402 may be communicatively coupled to operating system 208 of chemical production 204 producing chemical
products. Apparatus 402 may be configured to generate access policy data to control access to a digital twin of a chemical product. Apparatus 402 may be configured to provide at least part of the generated access policy data to decentral data providing network node 416. Apparatus 402 may be configured to generate access policy data, for example using the method described in the context of FIG. 1 1 and FIG. 12.
Apparatus 402 may be coupled to a digital twin (DT) storage 414. DT storage 414 may store digital twin data of chemical products. Each digital twin stored in DT storage 414 may include a decentral digital twin identifier and digital twin data comprising at least one measured and/or determined chemical and/or physical property as previously described. Each digital twin may include further data, such as described in the context of FIG. 3 above. The digital twins stored in DT storage 414 may be generated by an apparatus for generating DTs 424 (not shown, see for example FIG. 9A, FIG. 9B) using the method described in FIG. 10 below. The digital twins may be stored in DT storage 414 for access by a consumer of the chemical product, such as described in the context of FIG. 6A and FIG. 6B.
Apparatus 402 may comprise group access data generator 404 configured to generate access group data associated with digital twin data. The access group data may identify access control groups including decentral participant identifier(s) associated with decentral participant node(s) permitted to access at the digital twin data, for example as described in the context of FIG. 7A and FIG. 7B. The access control group may hence represent a gathering of decentral participant identifier(s) permitted to access the digital twin data. The decentral participant identifier may comprise any identifier uniquely associated with a participant of the decentral network 126 and/or with a production site of a participant of the decentral network 126. The decentral participant identifier may include letters and/or numbers. The decentral participant identifier may include one or more Universally Unique Identifier(s) (UUID(s)) and/or one or more Decentralized Identifier(s) (DID(s)). The decentral participant identifier may be associated with or may include a verifiable claim or credential. The decentral participant identifier may be generated by a central or decentral node of the decentral network. The decentral participant identifier may be provided to all participants of the decentral network. The decentral participant identifier may be associated with the name of the participant of the decentral network 126. The decentral participant identifier may be associated with the name of the site, such as a production site, of the participant of the decentral network 126.
The access control group may be associated with an access group policy permitting access for said access control group to the digital twin data. The access group data may be associated with a decentral digital twin identifier associated with the respective digital twin data. The decentral digital twin identifier may be provided from decentral ID provider 410. Decentral ID provider 410 may provide the decentral digital twin identifier in response to a received request received at said unit 404. The request may contain the decentral digital twin identifier associated with the digital twin data for with access policy data is to
be generated for. The request may contain a chemical product identifier associated with the chemical product and the decentral digital twin identifier providing unit may be configured to provide the decentral digital twin identifier based on the received chemical product identifier. For instance, the decentral digital twin identifier providing unit may retrieve the decentral digital twin identifier from DT storage 414 storing the digital twin based on the chemical product identifier. The request may be generated by the apparatus for generating digital twins 424 after the respective digital twin has been generated. The request may be received from an input/output device (not shown) connected to decentral ID provider 410. For instance, a user may trigger generation of access policy data via said input/output device, for example by providing the decentral digital twin identifier or the chemical product identifier associated with the respective chemical product.
Group access data generator 404 may be configured to generate group access data for one or more decentral digital twin identifier(s) provided by decentral ID provider 410. Group access data generator 404 may be connected to identifier DB 406 storing decentral participant identifier(s) associated with decentral network participants (see for example FIG. 1). Group access data generator 404 may be configured to generate the group access data as described in the context of FIG. 12. The generated group access data may be used for group-based access to the digital twin data as described in the context of FIG. 7A, FIG. 7B, FIG. 15A and FIG. 15B. Group access data generator 404 may be configured to provide the generated group access data to participant access data generator 408. Group access data generator 404 may be configured to provide the generated group access data to access policy data generator 412.
Apparatus 402 may comprise participant access data generator 408 configured to generate participant access data associated with the digital twin data based on the access control data generated by group access data generator 404. The access control data generated by participant access data generator 408 may identify decentral network participant(s) permitted to access one or more data point(s) present within the digital twin data and one or more actions allowed to be performed on the one or more data point(s) upon access to the digital twin data. The decentral participant identifier(s) identified by participant access data may at least in part correspond to decentral participant identifier(s) included in access control group(s) identified by the group access data. The participant access data may be generated as described in the context of FIG. 11 . Participant access data generator 408 may be configured to provide the generated participant access data to access policy data generator 412.
Apparatus 402 may comprise access policy data generator 412 configured to generate access policy data associated with the digital twin based on the group access data generated by group access data generator 404 and access control data generated by participant access data generator 408. The access policy data may identify the group access data and associated participant access data for the digital twin data. Access policy data generator 412 may be configured to link the access policy data to the digital
twin. Linking may include including the decentral digital twin identifier associated with the digital twin in the access policy data. Linking may include associating an identifier included in the access policy data, such as an access policy data identifier, with the decentral digital twin identifier associated with the digital twin. Access policy data generator 412 may be configured to provide at least part of the generated access policy data to decentral data providing network node 416. Access policy data generator 412 may be configured to provide group access data provided by group access data generator 404 and the decentral digital twin identifier associated with the access control group(s) to decentral data providing network node 416. Decentral data providing network node 416 may be configured to store the access policy data provided from access policy data generator 412 in DB 418. For instance, decentral data providing network node 416 may be configured to store at least one access control policy and associated decentral digital twin identifier(s) provided from access policy data generator 412 in DB 418.
FIG. 4B illustrates an example system for generating access policy data to control access to a digital twin of a physical entity of a chemical product produced from one or more chemical input materials. The access to the digital twin by one or more decentral data consuming network nodes (not shown, see for example FIGs. 8A, 8B) may be controlled by decentral data providing network node 416 associated with the digital twin based on access policy data generated by access control layer 430. The decentral data providing network node 416 may be associated with or connected to data storage(s) storing the digital twin data (not shown, see for example FIG. 4A, FIG. 4B).
The system 400b may be included in the operating system 208 of a chemical production 204 producing chemical products from one or more inbound materials (see for example FIG. 2). The chemical products may be intermediate chemical products. The chemical products may be chemical end-products. The system 400b may be communicatively coupled to the operating system 208 of a chemical production 204 producing chemical products. The system 400b may be configured to control access to a digital twin of a chemical product, for example using the method described in the context of FIG. 15A and FIG. 15B.
System 400b may comprise a data source layer 420. Data source layer 420 may comprise one or more distributed data sources. The one or more distributed data sources may be distributed databases. The distributed data source may be a data lake comprising data associated with chemical products from a plurality of distributed data sources. The one or more distributed data sources may contain at least one measured and/or determined chemical and/or physical property of chemical products, such as chemical products 206 produced by chemical production 204 from one or more inbound materials 202 as described in the context of FIG. 2 and FIG. 3. The at least one physical and/or chemical property may be measured using sensors, such as sensors 210a, 210b, and the measured chemical and/or physical property/properties may be stored in the distributed data sources. The at least one physical and/or chemical property may be determined from data acquired from sensors, such as sensors 210a, 210b, before, during and/or after production and the determined chemical and/or physical property/properties
may be stored in the distributed data sources. The one or more distributed data sources may further contain chemical product names, chemical product producer, chemical product declaration data, chemical product safety data, emission data, recyclate content data, biobased content data, certificate of analysis data associated with the chemical products, certificates associated with the chemical products or a combination thereof.
Data source layer 420 may be owned or controlled by the data owner of the data associated with chemical product data. The data source layer 420 may be associated with the data owner of the chemical product data. Data source layer 420 may be connected, for example via a communication interface such as a network or an API, to digital twin provider layer 428. Data source layer 420 may be connected to service layer 422 being present in between data source layer 420 and digital twin provider layer 428. Hence, service layer 422 may be optional in some implementations of the system illustrated in FIG. 4B.
Service layer 422 may be configured to gather data according to predefined selection criteria. Service layer 422 may be configured to apply one or more semantic models on the gathered data to generate a uniform data collection. Service layer 422 may be configured to provide the uniform data collection to a data streaming platform included in service layer 422. The streaming platform may include a platform that is deployed across a number of hosts, clusters, data centers, and/or other collections of computing resources. The streaming platform may include one or more client processes that generate records of activity and publish the records to one or more event streams. For instance, when a certain type of activity occurs in data source layer 420, for example provision of a new uniform data collection, production of a new batch of chemical product, measurement or determination of chemical and/or physical property/properties of the produced chemical product, etc., the one or more client processes may generate a record of the activity and publish said record to one or more event streams. The data streaming platform may then propagate the record to one or more components subscribing to the same event streams(s). The data propagated to one or more components may be stored in a database present within service layer 422 or digital twin provider layer 428. The data streaming platform thus allows activity occurring in multiple distributed data sources of data source layer 420 to be captured and transmitted in a unified, scalable manner.
Digital twin provider layer 428 may be configured to provide digital twins of chemical products. Each digital twin may include a decentral digital twin identifier and digital twin data comprising at least one measured and/or determined physical and/or chemical property. The digital twins may be linked to the chemical products via decentral digital twin identifiers. Digital twin provider layer 428 may comprise a digital twin storage for storing digital twins, such as DT storage 414. DT storage 414 may be included in the apparatus for generating DTs 424. Digital twin provider layer 428 may be configured to generate digital twins of chemical products based on data gathered from data source layer 420, such as measured and/or determined physical and/or chemical property/properties stored in data source layer 420. The
digital twins may be generated by an apparatus for generating DTs 424 (see also FIG. 9A and FIG. 9B). The digital twins may be generated by apparatus 424 using the method described in the context of FIG. 10.
Digital twin provider layer 428 may further comprise an apparatus for generating digital access elements 426, this apparatus being generally optional. Apparatus 426 may generate digital access elements associated with digital twins generated by apparatus 424. Each digital access element may comprise a decentral passport identifier and digital twin location data. The decentral passport identifier may correspond to or be associated with the decentral digital twin identifier of the respective digital twin the digital access element is associated with. The digital access elements generated by apparatus 426 may be provided to the decentral data providing network node 416 (see also FIG. 9B). The digital access elements may be used by decentral data consuming network nodes to access the digital twin associated with the digital access element via the decentral passport identifier, for example as described in the context of FIG. 16.
System 400b may further comprise access control layer 430 configured to generate access policy data to control access to digital twins of chemical products produced from one or more inbound materials. Access control layer 430 may comprise apparatus for generating access policy data 402 for controlling access to digital twin data, such as apparatus 402 described in the context of FIG. 4A. Access control layer 430 may be configured to control access based on the generated access policy data, for example as described in the context of FIG. 7B and FIG. 15B. Access control layer 430 may be configured to provide the generated access policy data to decentral data providing network node 416 and decentral data providing network node 416 may be configured to control access to the digital twin data, for example as described in the context of FIG. 7A and FIG. 15A. Access control layer 430 may be configured to control access to digital twin data based on digital access elements, for example as described in the context of FIG. 16.
System 400b allows to achieve availability, integrity and confidentiality of the digital twin or a part thereof. For instance, separation of the digital twin generation and the access to the digital twin allows to achieve a high and stabile availability of the digital twin within the decentral network. The access control layer allows to configure and ensure technically that only defined decentral network participants can access digital twin data. The access policy data generated by access control layer 430 may comprise access control groups defining decentral participant identifier(s) associated with decentral network participants permitted to access the digital twin data and access control data defining access for one or more data points within the digital twin data for said decentral network participant(s). By filtering decentral data consuming network node(s) requesting access to the digital twin on a group-based policy for accessing the digital twin, the digital twin data can be securely exchanged and shared under the sovereignty of the data owner of the digital twin data and undesired access to the digital twin data by decentral network
participants via associated decentral data consuming network nodes can be avoided. Moreover, this allows to manage who has access to the digital twin data without compromising the ability to control what actions those decentral network participants having access to the digital twin data may perform once these decentral network participants access the digital twin data. By defining actions permitted by decentral network participants on data point level of the digital twin data, generation of several copies of the digital twin data containing different data points customized to access rights of individual decentral network participants may be avoided.
FIG. 5 illustrates an example digital twin data structure 500 including a tree structure. The digital twin data structure may be generated by applying a data model comprising the tree structure to product data, for example as described in the context of Fig. 10. The digital twin data structure may be generated by applying two data models, one data model including the tree structure shown on the left-hand side (e.g. node 1 to node 7) and one data model including the tree structure shown on the right-hand side (e.g. node 8 to node 1 1).
The tree structure may include a root node 5O2.The root node may include data. The data may include one or more data point(s) and/or data set(s). The data may include the decentral digital twin identifier. The root node 502 may be connected to one or more sub data structures, such as sub data structures 526, 528. The sub data structures may be regarded as child nodes of root node 502. The root node may include more or less sub data structures than illustrated in FIG. 5. The sub data structure may include one or more node(s), such as one or more intermediate node(s) and/or one or more leaf node(s). The sub data structure may include a parent node and one or more child node(s). The parent node may be an intermediate node. The child node(s) may be further intermediate node(s) or leaf node(s).
The tree structure may further include intermediate nodes 504, 506, 510, 516, 518 and 524. The intermediate nodes 504 and 516 may be child nodes of root node 502. The intermediate nodes 504 and 516 may in turn be parent nodes to further intermediate nodes 506, 510, 518 and 524. The intermediate nodes 506, 510, 518 and 524 may in turn be parent nodes for leaf nodes 508, 512, 514, 520 and 522. The intermediate node(s) and/or the leaf node(s) may include data. The data may include one or more data point(s) and/or data set(s). The data set(s) may include key value pair(s). The data set(s) may include emission data, recyclate content data, bio-based content data, provenance data, labour conditions data, data on the composition of the product, material safety data, certificate of analysis data, data associated with the production of the product, certificates data associated with the product, regulatory information data associated with the product, data associated with the transport of the product, data associated with the use of the products, measured and/or determined chemical and/or physical properties of the product, or combinations thereof.
FIG. 6A illustrates a non-inventive example of controlling access to digital twin data structure based on different access control groups. Decentral data providing network node 416 and apparatus for generating
access policy data 402 may interact with DT storage 414 storing digital twin data. Decentral participant nodes 1 16A to 1 16E associated with chemical product consumers 602 to 612 may interact with decentral data providing network node 416 (see also FIG. 1). Decentral data providing network node 416 may be configured to access the digital twin data stored in DT storage 414 via a network connection. The network connection may be over one or more public and/or private networks. In some implementations, decentral data providing network node 416 may access DT storage 414 via the Internet.
In the example shown in FIG. 6A, two access control groups of decentral network participants have been defined for digital twin data. In this example, the digital twin data may include a DT data set 616 comprising two sub data sets 618, 620. Each sub data set may include one or more data points 622, 624, 626. The first access control group 606 may include decentral participant nodes 1 16A and 116B associated with chemical product consumer 1 602, chemical product consumer 2 604 respectively. The second access control group 614 may include decentral participant nodes 116D and 116E associated with chemical product consumer 4 610, chemical product consumer 5 612 respectively. Decentral participant node 1 16C may not be associated with any access control group in this example.
Decentral data providing network node 416 may be configured to receive requests to access digital twin data from one or more decentral participant node(s) (e.g. decentral data consuming network node(s)). Decentral data providing network node 416 may be configured to provide access to the digital twin data based on the group access policy/policies provided from apparatus 628. Decentral data providing network node 416 may be configured to gather digital twin data from DT storage 414 and to provide gathered digital twin data to the decentral participant node(s) requesting access to said digital twin data. While the example implementation illustrated in FIG. 6A includes five decentral participant nodes 116A to 1 16E, other implementations may include a different number of decentral participant nodes. Apparatus for generating group access data 628 may be used to generate group access policies for access control groups associated with the digital twin data, to add, modify and/or delete group access policies.
Apparatus for generating group access data 628 may generate group access data. The group access data include one or both access control groups 606, 614. The group access data may include access control groups 606, 614 and at least one group access policy that indicates that decentral participant identifiers associated with chemical product consumers 602 and 604 of the first access control group 606 and decentral participant identifiers associated with chemical product consumers 610 and 612 of the second access control group 614. Chemical product consumer 3 608 is not associated with either of these groups and may hence not be able to access the digital twin data structure 630, 632. Apparatus 628 may send a set group access policy message to decentral data providing network node 416, and decentral data providing network node 416 may send a set policy response message to apparatus 628 in response to receiving the set group access policy message. The set group access policy message may specify one or more access control groups for which access to the digital twin data structure 630, 632 is to be granted
or revoked. For instance, apparatus 402 may submit a group access message containing a new group access policy for the digital twin data structure 630, 632 that revokes access of the second access control group 614 to the digital twin data structure 630, 632. Hence, chemical product consumer 4 510 and chemical product consumer 5 612 would no longer be able to access the digital twin data via decentral participant nodes 1 16D and 116E, while chemical product consumer 1 602 and chemical product consumer 2 604 would still be able to access the digital twin data structure 630, 632. The set policy response message sent by decentral data providing network node 416 may provide an indication whether the request was completed or failed.
Since access to the digital twin data structure 630, 632 is based on group access data, a defined digital twin data structure 630, 632 has to be generated for each access control group if access to different digital twin data structures is to be provided to different access control groups. Hence, as illustrated in FIG. 6A, a copy of the digital twin data structure 630 has to be generated for access control group 2 614 and said copy has to be modified with respect to included nodes, such that the copy only contains nodes that are permitted to be accessed by decentral network participants included in said access control group 2 614. In this example, access control group 1 606 is permitted to access digital twin data structure 630 including root node 616, intermediate nodes 618, 620 and leaf nodes 622, 624, 626. In contrast, access control group 2 614 is only permitted to access digital twin data structure 632 including root node 616, intermediate node 616 and leaf nodes 622, 624. Hence, digital twin data structure 630 must be copied and node 2 620 and all child node(s) must be removed, as illustrated in FIG. 6A.
While the use of group-based policies allows to control access to digital twin data structure in an efficient and easy to use manner by controlling the access on a group level, the digital twin data structure needs to be adjusted to the respective access group, hence resulting in creating of several copies of the digital twin data structure. This results in large amounts of digital twin data structures which have to be generated and stored, hence requiring large amounts of data storage volume.
FIG. 6B illustrates an example of controlling access to digital twin data structure based on access control group(s) in combination with fine grained access control on node level in accordance with an embodiment of the present disclosure. In contrast to the example illustrated in FIG. 6A, access to the digital twin data structure 630 is not only controlled based on access control groups. Instead, access to the digital twin data structure 630 is controlled based on a combination of group-based access control and access and interaction control on node level of the digital twin data structure 630. This allows to benefit from the advantages of group-based access control described in the context of FIG. 6A while avoiding generation of several copies of digital twin data structures to control interaction with node(s) present within the digital twin data structure for each decentral network participant being a member of an access control group permitted to access the digital twin data structure 630.
Decentral data providing network node 416 and apparatus for generating access policy data 402 may interact with DT storage 414 storing digital twin data. Decentral participant nodes 1 16A to 1 16E associated with chemical product consumers 602 to 612 may interact with decentral data providing network node 416 (see also FIG. 1) as described in the context of FIG. 6A. Apparatus for generating access policy data 402 and decentral data providing network node 416 may be configured to access the digital twin data stored in DT storage 414 via a network connection. The network connection may be over one or more public and/or private networks. In some implementations, apparatus for generating access policy data 402 and decentral data providing network node 416 may access DT storage 414 via the Internet.
Decentral data providing network node 416 may be configured to receive requests to access digital twin data structure 630 from one or more decentral participant node(s) (e.g. decentral data consuming network node(s)) as described in the context of FIG. 6A. Decentral data providing network node 416 may be configured to provide access to the digital twin data structure based on access policy data provided from apparatus 402. The access policy data may include group access data and associated participant access data associated with one or more node(s) present within the digital twin data structure 630. Decentral data providing network node 416 may be configured to gather digital twin data structure from DT storage 414 and to provide gathered digital twin data structure to the decentral participant node(s) requesting access to said digital twin data structure as described in the context of FIG. 6A. While the example implementation illustrated in FIG. 6B includes five decentral participant nodes 116A to 1 16E, other implementations may include a different number of decentral participant nodes. Apparatus for generating access policy data 402 may be used to generate access policy data for the digital twin data structure, to add, modify and/or delete participant access data and/or to configure participant access data for decentral network participants accessing the digital twin data structure.
Apparatus for generating access policy data 402 may generate an access control policy for one or both access control groups 606, 614, for example as described in the context of FIG. 6A. Apparatus for generating access policy data 402 may generate access policy data for the digital twin data structure 630. Access policy data may include access control data for one or both access control groups and associated participant access data controlling access of decentral network participants (via respective decentral participant nodes) to one or more node(s) of the digital twin data structure and interaction with said one or more node(s). For instance, access control data may indicate that members of the access control group 1 606 are permitted to access and interact with the root node 616, the intermediate nodes 618, 620 and the leaf nodes 622, 624, 626 while members of access control group 2 614 are only permitted to access and interact with root node 616, intermediate node 620 and leaf nodes 626. Thus, node 618 and associated child nodes 622, 624 are not accessible for members of access control group 614 such that these members cannot access and interact with said nodes and the data contained therein. Hence, use of participant access data allows to inherit permissions of parent node(s) to all child node(s),
thus avoiding definition of permissions for each node present within the digital twin data structure. Use of participant access data allows to avoid generation of different copies of digital twin data structure 630 to reflect different permissions for members of different access control groups with respect to access and interaction with node(s) present within the digital twin data structure. By using access policy data including group access data for access control group(s) and associated participant access data associated with one or more node(s) present within the digital twin data structure, access to and interaction with the digital twin data structure may be controlled in an efficient and easy to use manner while avoiding generation of multiple copies of the digital twin data structure to reflect different permission associated with different access control groups with respect to access and interaction with node(s) of the digital twin data structure.
FIG. 7A illustrates a first example of controlling access to a digital twin data structure, such as illustrated in Fig. 5, based on access policy data including at least one group access policy and participant access data associated with one or more node(s) present within the digital twin data structure in accordance with an embodiment of the present disclosure. In this embodiment of FIG. 7A, decentral data providing network node 416 may implement the access policy data for controlling access to the digital twin data structure.
The example shown in FIG. 7A includes a single decentral data consuming network node 602 and a single apparatus for generating access policy data 402. However, decentral data providing network node 416 may interact with multiple decentral data consuming network nodes and/or apparatuses 402, which may be similar to those described the context of FIG. 6B. Decentral data providing network node 416 may control access to the digital twin data stored in DT storage 414.
Decentral data providing network node 416 may include a policy configuration unit 704. Policy configuration unit 704 may be configured to provide a means for apparatus 402 to generate, modify and/or delete group access data associated with the digital twin data structure and/or the participant access data associated with node(s) present within the digital twin data structure. Apparatus 402 may send a set group access policy message to decentral data providing network node 416 to create a new access control group and associated group access policy, to create a new group access policy or to modify an existing group access policy associated with the digital twin data. Policy configuration unit 704 may receive the set group access policy message and update the group access policy datastore 708. Apparatus 402 may also send a participant access data message to decentral data providing network node 416 in which the participant access data for one or more decentral network participants may be added, updated, or modified. The participant access data for a decentral network participant may be configured to provide fine-grain control over the action(s) that a decentral network participant may perform on one or more node(s) present within the digital twin data structure. The participant access data may include or correspond to access control list data including at least one access control list entry. The at least one access control list entry may include the decentral participant identifier(s) associated with
the decentral network participant(s) permitted to access one or more node(s) present within the digital twin data structure, the respective node(s) to which access is permitted for said decentral network participant(s), and the one or more action(s) allowed to be performed on the node(s) for which access is permitted. Policy configuration unit 704 may update the participant access data datastore 710 with the information received in the message.
Policy configuration unit 704 may be configured to authenticate a user of apparatus 402 to ensure that the user is authorized to modify the contents of the group access policy datastore 708 and the access control data datastore 710. In some implementations, apparatus 402 may provide a security token to policy configuration unit 704 that includes information that identifies the user of apparatus 402 to decentral data providing network node 416 and may be used by policy configuration unit 704 to confirm that the user has been authenticated. The security token may be implemented as a JavaScript Object Notation (JSON) web token in some implementations. Once policy configuration unit 704 has determined that the user of apparatus 402 is authenticated, policy configuration unit 704 may determine which action(s) the user is authorized to perform. In some implementations, the data owner of the digital twin data structure may be permitted to modify the contents of the group access policy datastore 708 and/or the access control data datastore 710.
Decentral data providing network node 416 may include policy engine 706. Policy engine 706 may be configured to: (1) determine whether a decentral network participant associated with decentral data consuming network node 702 is authorized to access the digital twin data structure, and (2) determine whether the decentral network participant has the rights required to perform a requested action or actions on the digital twin data structure if the user has access to the to the digital twin data structure, for example as described in the context of FIG. 15A. The decentral data consuming network node 702 may correspond to any one of decentral participant nodes 1 16 to 124 described in the context of FIG. 1 and FIG. 6B. The decentral data consuming network node 702 may send a request to access the digital twin data structure including the decentral digital twin identifier associated with the digital twin data structure to be accessed, a decentral participant identifier of the decentral network participant associated with decentral data consuming network node 702 and one or more actions to be performed on the digital twin data structure, for example as described in the context of FIG. 16. The policy engine 706 may analyze the request to determine whether decentral data consuming network node 702 should be permitted to access the digital twin data structure and whether the decentral network participant has the required level of access to perform the requested action on the digital twin data structure (e.g. on one or more node(s) present within the digital twin data structure) using data stored in group access policy datastore 708 and access control data datastore 710, for example as described in the context of FIG. 15A.
FIG. 7B illustrates another example of controlling access to a digital twin data structure, such as illustrated in Fig. 5, based on access policy data including access control groups and participant access data
associated with one or more node(s) present within the digital twin data structure in accordance with an embodiment of the present disclosure. In contrast to the example illustrated in FIG. 7A, only the group- based access is controlled by decentral data providing network node 416 while the access controller 712 is used to determine whether the decentral network participant has the rights required to perform one or more requested actions on one or more node(s) present within the digital twin data structure.
The example shown in FIG. 7B includes a single decentral data consuming network node 702 and a single apparatus for generating access policy data 402. However, decentral data providing network node 416 may interact with multiple decentral data consuming network nodes and/or apparatuses 402 as described in the context of FIG. 7A. Decentral data providing network node 416 in combination with access controller 712 may control access to the digital twin data stored in DT storage 414.
Decentral data providing network node 416 may include a policy configuration unit 704. Policy configuration unit 704 may be configured to provide a means for apparatus 402 to configure the group access policies for groups associated with digital twin data structure as described in the context of FIG. 7A. Policy configuration unit 704 may be configured to authenticate a user of apparatus 402 as described in the context of FIG. 7A.
Decentral data providing network node 416 may include policy engine 706. Policy engine 706 may be configured to determine whether a decentral network participant associated with decentral data consuming network node 702 is authorized to access the digital twin data structure, for example as described in the context of FIG. 15B. The decentral data consuming network node 702 may send a request to access the digital twin data structure as described in the context of FIG. 7A. The policy engine 706 may analyze the request to determine whether decentral data consuming network node 702 should be permitted to access the digital twin data structure using data stored in group access data datastore 708, for example as described in the context of FIG. 15B.
Access controller 712 may be communicatively coupled to decentral data providing network node 416. Access controller 712 may include a policy configuration unit 704. Policy configuration unit 704 may be configured to provide a means for apparatus 402 to configure the access control data for one or more node(s) present within the digital twin data structure as described in the context of FIG. 7A. Policy configuration unit 704 may be configured to authenticate a user of apparatus 402 as described in the context of FIG. 7A.
Access controller 712 may include policy engine 2 714. Policy engine 2 714 may be in communication with policy engine 706 of decentral data providing network node 416. In response to a message from policy engine 706 that the decentral network participant associated with decentral data consuming network node 702 is permitted access to the digital twin data structure, policy engine 2 714 may be configured to determine whether the decentral network participant has the rights required to perform a
requested action or actions on the digital twin data structure (e.g. to perform requested action(s) on one or more node(s) present within the digital twin data structure), for example as described in the context of FIG. 15B. Decentral data providing network node 416 may provide data contained in the request received from decentral data consuming network node 702 to policy engine 2 714. The policy engine 2 712 may analyze the provided data to determine whether the decentral network participant has the required level of access to perform the requested action on the digital twin data structure using data stored in participant access data 710, for example as described in the context of FIG. 15B.
FIG. 8A illustrates a first example of a linkage between a digital twin data structure and a digital access element via a decentral digital twin identifier. The digital twin data structure may include a root node, intermediate node(s) and/or leaf node(s) (see for example FIG. 5). The digital twin data structure 500 may be generated as described in the context of FIG. 9A and FIG. 10. The digital twin data structure 500 may be stored in DT storage 414. Digital access element 804 associated with the physical entity of the product may be generated as described in FIG. 9B. The digital twin data structure may include different sub data structures connected to the root node 502 of the digital twin data structure 500 (see for example FIG. 5). The root node 502 may include the decentral digital twin identifier 802. The root node may be connected to one or more sub data structures which may be regarded as child nodes of the root node 502. Each sub data structure may include one or more node(s). The sub data structures 526, 528 connected to root node 502 of the digital twin data structure 500 may include to the decentral digital twin identifier 802. Use of said decentral digital twin identifier 802 hence allows to identify all existing sub data structures contained in digital twin data structure 500. The decentral digital twin identifier 802 may include further identifiers, such as identifiers of sub data structures 526, 528. This allows to uniquely identify the sub data structures contained in the digital twin data structure using the decentral digital twin identifier 802 and the respective identifiers of the sub data structures.
Digital access element 804 may contain a decentral passport identifier 806. The decentral passport identifier 806 may be a decentral identifier linked to the decentral digital twin identifier 802 included in digital twin data structure 500. The decentral passport identifier 806 may correspond to the decentral digital twin identifier 802 included in digital twin data structure 500. The latter avoids generation of a new decentral identifier and linking of the newly generated decentral identifier to the decentral digital twin identifier included in the digital twin data structure.
The digital access element may contain digital twin location data 808. The digital twin location data 808 may include digital representation(s) pointing directly or indirectly to the storage structure storing the digital twin data structure 500, such as DT storage 414 (not shown, see for example FIG. 4A). The digital twin location data 808 may include a digital representation pointing to decentral data providing network node 416 associated with DT storage 414 (not shown, see for example FIG. 4A).
Digital access element 804 may be linked via the decentral passport identifier 806 to digital twin data structure 500, thus allowing to access the digital twin data structure using the decentral passport identifier 806 and digital twin location data 808 included in digital access element 804 as described in the context of FIG. 16.
FIG. 8B illustrates a second example of a linkage between a digital twin data structure 500 and digital access elements 810, 816 via decentral digital twin identifier 802 and decentral passport identifiers 814, 820. The digital twin data structure may include a root node, intermediate node(s) and/or leaf node(s) (see for example FIG. 5). The digital twin data structure 500 may be generated as described in in the context of FIG. 9A and FIG. 10. The digital twin data structure 500 may include different sub data structures connected to the root node 502 of the digital twin data structure 500 (see for example FIG. 5). The root node 502 may include the decentral digital twin identifier 802. The root node may be connected to one or more sub data structures which may be regarded as child nodes of the root node 502.. Each sub data structure may include one or more node(s). The sub data structures 526, 528 connected to root node 502 of digital twin data structure 500 may include the decentral digital twin identifier 802. Use of said decentral digital twin identifier 802 thus allows to identify all existing sub data structures connected to root node 502 of digital twin data structure 500. The digital access elements 810, 816 associated with the physical entity of the product may be generated as described in FIG. 9B.
In this example, a digital access element 810 may be generated for sub data structure 1 526 and a digital access element 816 may be generated for sub data structure 2 528. Digital access elements may be generated for each sub data structure or for at least part of the sub data structures connected to root node 502 of the digital twin data structure 500. Each digital access element may be linked by the decentral passport identifier 814, 820 via the decentral digital twin identifier 802 to the respective sub data structure. Each digital access element 810, 816 may contain digital twin location data 812, 818. Said digital twin location data 812, 818 may include a digital representation as described in the context of FIG. 8A.
FIG. 8A and FIG. 8B only show two example embodiments and any number of digital access elements and any number of sub data structures within the digital twin data structure may be possible. For instance, a first digital access element may be generated for a first group of sub data structures while a second digital access element may be generated for a second group of sub data structures. The group of sub data structures may include one or more sub data structures.
FIG. 9A illustrates an example of a system and associated methods for controlling access to a digital twin of a product produced from one or more input materials by a production in accordance with an embodiment of the present disclosure. The system may comprise a digital twin management system 902. Digital twin management system 902 may comprise an apparatus for generating digital twins, for example apparatus 424 described below. Digital twin management system 902 may comprise an apparatus for generating access policy data for controlling access to digital twin data structure(s), for example
apparatus 402 described in the context of FIG. 4A. Digital twin management system 902 may comprise system 400b described in the context of FIG. 4B. Digital twin management system 902 may comprise means for controlling access to digital twins, for example decentral data providing network node 416 as described in the context of FIG. 7A or decentral data providing network node 416 in combination with access controller 712 as described in the context of FIG. 7B. Digital twin management system 902 may be included in an operating system of a production (see for example FIG. 2). The digital twin management system 902 may be communicatively coupled to the operating system of a chemical production (not shown).
The production may be a chemical production, such as chemical production 204 described in relation to FIG. 2. The production 204 may produce at least one product 206 from one or more inbound material(s) 202. The inbound materials may be provided to the production 204, for example as described in the context of FIG. 2. The inbound materials may enter the system boundary 904 of the production 204 at the entry point, such as a production plant or a material storage associated with the production 204. The amount of inbound material entering the system boundary 904 of the production 204 may be measured, for example using sensor 210b described in the context of FIG. 2. Chemical and/or physical properties of the inbound material may be measured, for example using sensor 210a described in the context of FIG. 2, upon passing system boundary 904 of the production 204. The measured data may be used to determine at least one chemical and/or physical property of the inbound material.
The inbound materials may be used in the production to produce one or more product(s), such as chemical products, from the inbound materials, for example as described in the context of FIG. 2. The operating system 208 of the production 204 may monitor and/or control the production 204 based on operating parameters of the different processes. The operating system 208 may receive production demand data associated with the production planning for the production 204. The production demand data may be produced from target production capacities for one or more chemical product(s) produced by the production 204. The production demand data may be produced from pre-defined production capacities or data-driven models that relate production capacities to market demand data or quantities consumed at the consumption location. The production demand data may include target capacities for products produced by the production 204. The operating system 208 may further receive a bill of materials associated with products to be produced. The bill of materials may include material data associated with the materials used to produce the product, process data associated with the production chain for producing the product and/or product data associated with the product, such as a product specification data or data on the amount of product to be produced.
Based on the received production demand data and the bill of materials, material demand data may be determined. The material demand data may include data on the amount of material required to produce the target capacities of product. The material demand data may include material identifiers associated
with materials required to produce the product and data on amounts of material for respective materials. The material demand data may include one or more material specifier(s) per material identifier signifying the material specification. The material demand data may include data on the material amount per material identifier signifying the amount of material to be supplied. The material demand data may specify the production chain(s) of the production 204. The material demand data may include a bill of materials for one or more production chain(s) of the production 204. The material demand data may include one or more recipe(s) specifying one or more material(s) for production process(es) of the production 204. The determined material demand data may be provided for access by a supplier system associated with a supplier outside the physical system boundary of the production 204. Material supply may be triggered by the supplier system accessing the material demand data.
The amount of product(s) resulting from processes performed within production 204, such as chemical reactions and/or physical processing, may be measured using a sensor, such as sensor 210b described in the context of FIG. 2. Since chemical reactions may result in more than one reaction product, e.g. a chemical reaction is associated with a many-to-many relationship between starting materials and resulting reaction products (see also FIG. 2), measuring the amount of chemical product(s) resulting from each chemical reaction performed within chemical production 204 allows to track material flows within the chemical production 204. The measured data may be stored in one or more databases associated with operating system 208. Moreover, processes may be monitored using sensors, such as sensors 210b, and the generated monitoring data may be stored in one or more databases associated with operating system 208. The measured amounts of produced products as well as the monitoring data may be used to generate a digital twin data structure of each production process performed within production 204. The measured amounts of produced products as well as the monitoring data may be used to generate a digital twin data structure of the production 204. This digital twin data structure allows to reliably track and account for flows of inbound material, intermediate chemical products and chemical products despite the many-to-many relationships between starting materials and reaction products associated with chemical reactions. Physical and/or chemical properties of produced products may be measured by sensors, such as sensors 210a, and/or determined as described in the context of FIG. 2. The measured and/or determined chemical and/or physical properties of the produced products 206 may be stored in one or more databases associated with operating system 208.
The produced products 206 may be provided at one or more exit points of the production 204. The product 206 may exit the system boundary 904 of the chemical production 204. Upon producing the product 206 or upon exiting of the product 206 of the production 204, a digital twin data structure associated with the product may be generated. The digital twin data structure may be generated by apparatus 424. Apparatus 424 may be configured to generate the digital twin data structure as described in the context of FIG. 10. A requestor 906 may be configured to generate the request to generate the digital twin data structure of the produced product 206. The requestor 906 may be included in a labelling device, for example as
described in the context of FIG. 3. The request may contain data related to the product, such as a batch number and/or a LOT number. The request may further contain data associated with aspect model(s) (e.g. data models) related to products, such as aspect model identifier(s). The request to generate the digital twin data structure may be provided to apparatus 424. In response to the request, digital twin generator 908 of apparatus 424 may be configured to generate the digital twin data structure, for example using the method described in FIG. 10.
Digital twin generator 908 may be configured to gather data associated with the product, for example from a data layer such as data source layer 420 (not shown, see for example FIG. 4B), based on the data contained in the received request. Digital twin generator 908 may contain a data gathering unit configured to gather the product data, for example from the data source layer 420. The gathered data may contain at least one measured and/or determined physical and/or chemical property of the product. Digital twin generator 908 may be configured to determine whether a digital twin data structure associated with the produced product 206 is already existing, for example is already stored in a data storage of apparatus 424, such as DT storage 414 (see FIG. 4A). This avoids generation of already existing digital twin data structures and hence results in a more efficient generation of digital twin data structures.
Digital twin generator 908 may be configured to request a decentral identifier associated with the gathered data and optionally a data owner from decentral ID generator 910. Said request may include at least one authentication mechanism or may include selecting at least one of multiple authentication mechanisms. The request may include an owner identifier and/or a chemical product identifier and/or digital twin location data.
Decentral ID generator 910 may be configured to generate and provide a decentral identifier associated with the gathered data and optionally a data owner, such a data owner of the data associated with the chemical product. For instance, decentral ID generator 910 may be configured to generate a decentral digital twin identifier, such as a DID or a UUID. Decentral ID generator 910 may be configured to generate a decentral identifier including or being associated with further identifier, such as sub data structure identifier(s). Decentral ID generator 910 may be configured to generate sub data structure identifier(s), such as DID(s) and/or UUID(s). Decentral ID generator 910 may comprise a component configured to generate Decentralized Identifier(s) (DID(s)). Decentral ID generator 910 may comprise a component configured to generated Universally Unique Identifiers (UUID(s)). Decentral ID generator 910 may be part of apparatus 424. Decentral ID generator 910 may be communicatively coupled to apparatus 424, e.g. apparatus 424 may not comprise said decentral ID generator 910 (not shown). The decentral identifier generated by decentral ID generator 910 may be one or more DID(s) and/or UUID(s). The one or more DID(s) and/or UUID(s) may be associated with the digital twin data structure. The one or more DID(s) and/or UUID(s) may further be associated with the product. For instance, the decentral identifier may include a decentral digital twin identifier associated with the digital twin data structure and one or more
sub data structure identifier(s) associated with sub data structure(s) linked to the root node of the digital twin data structure. The decentral identifier may further include a product identifier associated with the product. Decentral ID generator 910 may be a central or decentral node configured to generate a decentral ID, such as a DID or UUIDv4 as described in relation to FIGs. 16 and 17. Decentral ID generator 910 may be computing node that acts as a DID owner’s management module, user agent, ID hub and/or certification issuer. Decentral ID generator 71910 0 may be configured to receive a request to provide a decentral identifier associated with the data associated with the data gathered by digital twin generator 908 and optionally a data owner. Said request may include at least one authentication mechanism or may include selecting at least one of multiple authentication mechanisms. The request may include an owner identifier and/or a chemical product identifier and/or access data as previously described. Decentral ID generator 910 may be configured to generate the decentral identifier as well as data related to the authentication mechanism.
Decentral ID provider 914 may be configured to provide the received decentral identifier to the requestor 906 configured to associate the received decentral identifier with the product. For this purpose, the requestor 906 may include an ID assignor (see for example FIG. 3). Decentral ID provider 914 may be configured to provide the received decentral identifier to an ID assignor configured to associate the received decentral identifier with the product (not shown). Such association may include encoding the decentral identifier into a code, such as a bar code, a QR code, an embossed code, an optical holographic identifier, and providing the generated code for labelling of the product. This way a physical identifier may be provided that relates the physical entity of the product with the decentral identifier of the digital twin data structure and hence linking the digital twin data structure with the physical entity of the product. Decentral ID provider 914 may be configured to provide the received decentral identifier to digital twin generator 908. Decentral ID generator 910 and decentral ID provider 914 may be separate devices as illustrated in FIG. 9A. Decentral ID generator 910 and decentral ID provider 914 may be contained within one device configured to generate the decentral identifier and to provide the generated decentral identifier (not shown).
In response to receiving the decentral identifier from decentral ID provider 914, digital twin generator 908 may be configured to retrieve at least one aspect model (e.g. data model) from an aspect model DB (not shown) and to generate the digital twin data structure by applying each retrieved aspect model to the gathered data, for example as described in the context of FIG. 10. Applying each aspect model to the gathered data may result in respective sub data structures. The generated sub data structures may be linked to a root node to generate the digital twin data structure.
Digital twin generator 908 may be configured to generate the digital twin data structure, for example as described in the context of FIG. 10. The digital twin data structure may include a tree structure including a root node and one or more leaf node(s). The tree structure may further include one or more intermediate
node(s). An exemplary tree structure of a digital twin data structure is illustrated in FIG. 5. The tree structure may include the decentral identifier sub data structures. The decentral identifier may include one or more DID(s) and/or UUID(s), for example as described above. Digital twin generator 908 may further be configured to generate digital twin location data, for example as described in the context of FIG. 10. Digital twin generator 908 may be configured to store the generated digital twin in DT storage 414.
Apparatus for generating access policy data 402 may be configured to generate access policy data, for example as described in the context of FIG. 4A and FIG. 11 . The access policy data may include group access data and associated participant access data, as described in the context of FIG. 7A, FIG. 7B and FIG. 11 . The access policy data may include the decentral digital twin identifier associated with the digital twin data structure. Apparatus 402 may generate access policy data as described in FIG. 11 . At least part of the access policy data may be provided to decentral data providing network node 416, for example as described in the context of FIG. 4A, FIG. 7A and FIG. 7B.
Decentral data providing network node 416 may be associated with the production 204 producing the product 206. Decentral data providing network node 416 may be associated with the data owner of the digital twin data structure, such as the product producer. Decentral data providing network node 416 may be configured to control access to the digital twin data structure, such as digital twin data stored in DT storage 414, based on the access policy data provided by apparatus 402, for example as described in the context of FIG. 7A, and FIG. 15A. Decentral data providing network node 416 may be configured in combination with access controller 712 to control access to the digital twin data structure such as described in the context of FIG. 7B and FIG. 15B. Decentral data providing network node 416 may be configured to provide access to the digital twin data structure upon request of a decentral data consuming network node 702, for example as described in the context of FIG. 7A, FIG. 7B, FIG. 15A and FIG. 15B. Decentral data providing network node 416 and decentral data consuming network node 702 may be part of decentral network 126, for example as described in the context of FIG. 1 .
Use of the group access data contained within the access policy data allows to filter decentral data consuming network nodes based on the decentral participant identifier of decentral network participants associated with said decentral data consuming network nodes, hence ensuring that only decentral data consuming network nodes associated with authorized decentral participants can access the digital twin data structure. Use of participant access data contained within the access policy data allows to control access and interaction with the digital twin data structure of decentral network participants on a node level of the digital twin data structure, hence avoiding the generation of multiple copies of digital twin data structure containing different nodes.
FIG. 9B illustrates an example of an apparatus and associated methods for controlling access to a digital twin of a product produced from one or more input materials by a production using a digital access
element in accordance with an embodiment of the present disclosure. The system may comprise a digital twin management system 902. Digital twin management system 902 may comprise an apparatus for generating digital twin data structure(s), for example apparatus 424 described in the context of FIG. 9A. Digital twin management system 902 may comprise an apparatus for generating access policy data for controlling access to digital twin data structure(s), for example apparatus 402 described in the context of FIG. 4A. Digital twin management system 902 may comprise system 400b described in the context of FIG. 4B. Digital twin management system 902 may comprise means for controlling access to digital twin data structure(s), for example decentral data providing network node 416 as described in the context of FIG. 7A or decentral data providing network node 416 in combination with access controller 712 as described in the context of FIG. 7B. Digital twin management system 902 may comprise an apparatus for generating digital access elements, such as apparatus 426. Digital twin management system 902 may be included in an operating system of a production (see for example FIG. 2). The digital twin management system 902 may be communicatively coupled to the operating system of a production (not shown).
The production may be a chemical production, such as chemical production 204 described in relation to FIGs. 2 and FIG. 9A. The production 204 may produce at least one product 206 from one or more inbound material(s) 202, for example as described in the context of FIG. 9A. The produced products 206 may be provided at one or more exit points of the production 204. The product 206 may exit the system boundary 904 of the production 204. Upon producing the product 206 or upon exiting of the product 206 of the production 204, the digital twin data structure may be generated, for example as described in FIGs. 8A and 9. A requestor 906 may be configured to generate the request to generate the digital twin data structure of the produced product 206, for example as described in the context of FIG. 9A. The generated digital twin data structure may be stored in DT storage 414. The digital twin data structure may contain a tree structure including a root node and one or more leaf node(s). The tree structure may further include one or more intermediate node(s). An exemplary tree structure of a digital twin data structure is illustrated in FIG. 5. The tree structure may include a decentral identifier. The decentral identifier may be assigned to product 206 by an ID assignor 906, for example as described in the context of FIG. 3 and FIG. 9A.
Apparatus for generating DTs 424 may be configured to generate digital twin data structures of produced products 206 as described in the context of FIG. 9A. Apparatus for generating DTs 424 may be configured to store the generated digital twin data structures in DT storage 414 as described in the context of FIG. 9A.
Apparatus for generating access policy data 402 may be configured to generate access policy data, for example as described in the context of FIG. 4A and FIG. 11 . The access policy data may include group access data and associated participant access data, as described in the context of FIG. 7A, FIG. 7B and FIG. 11 . The access policy data may include the decentral digital twin identifier associated with the digital twin data structure. Apparatus 402 may generate access policy data as described in FIG. 11. At least
part of the access policy data may be provided to decentral data providing network node 416, for example as described in the context of FIG. 4A, FIG. 7A and FIG. 7B.
Decentral data providing network node 416 may be associated with the production 204 producing the product 206. Decentral data providing network node 416 may be associated with the data owner of the digital twin data structure, such as the product producer. Decentral data providing network node 416 may be configured to control access to the digital twin data structure as described in the context of FIG. 9A. Decentral data providing network node 416 may be configured in combination with access controller 712 to control access to the digital twin data structure as described in the context of FIG. 9A. Decentral data providing network node 416 may be configured to provide access to the digital twin data structure upon request of a decentral data consuming network node 602, for example as described in the context of FIG. 7A, FIG. 7B, FIG. 15A and FIG. 15B. Decentral data providing network node 416 and decentral data consuming network node 702 may be part of decentral network 126, for example as described in the context of FIG. 1 .
Apparatus for generating digital access elements 426 may be configured to generate a digital access element associated with the product. The digital access element allows for an indirect access to the digital twin data structure, i.e. an access to the digital twin data structure via the digital access element. Access to the digital access element itself can remain unrestricted while still allowing for controlled access to the digital twin data structure. The digital access element may include a decentral passport identifier and digital twin location data. The decentral passport identifier is or is associated with the decentral digital twin identifier of the digital twin associated with the product. The decentral identifier may further be associated with a data owner. The data owner may be the data owner of the digital twin data structure contained in the digital twin as described in the context of FIG. 9A. The data owner may be the product producer as described in the context of FIG. 9A. The decentral identifier may include one or more UUID(s) and/or one or more DID(s), for example as described in the context of FIG. 9A. The one or more DID(s) and/or UUID(s) may be associated with the digital twin and/or the digital twin data structure contained in the digital twin. The one or more DID(s) and/or UUID(s) may further be associated with the product.
The digital access element may correspond to a DID document including the decentral digital twin identifier as DID. Such DID document may further contain sub data structure identifiers associated with sub data structures connected to the root node of the digital twin data structure and digital twin location data. Digital twin location data may include digital representations pointing to the digital twin data structure or sub data structure(s), for example as described in the context of FIG. 9A. The digital access element may correspond to a DID document containing a decentral passport identifier associated with the digital twin identifier. Such DID document may further contain sub data structure identifiers associated with sub data structures connected to the root node of the digital twin data structure and digital twin location data. The digital access element may correspond to a data structure comprising the decentral
passport identifier and digital twin location data. An example of a digital access element is illustrated in FIG. 19.
The digital access element may be generated in response to generating the digital twin data structure. Hence, generation of the digital access element by apparatus 426 may be triggered by apparatus 424, e.g. when apparatus 424 has generated the respective digital twin data structure. The request to generate the digital access element may contain an owner identifier and/or a product identifier as described in the context of FIG. 9A.
The digital access element may be generated by providing the decentral passport identifier and digital twin location data as described in the context of FIG. 18. A physical identifier associated with the product may be assigned to the decentral passport identifier included in the generated digital access element. Apparatus 426 may be configured to provide the decentral passport identifier to the requestor 906 configured to associate the received decentral passport identifier with the product. For this purpose, the requestor 906 may include an ID assignor as described in the context of FIG. 3 and FIG. 9A. This allows to link the decentral passport identifier and hence the digital twin data structure associated with the decentral passport identifier with the physical entity of the product. The physical identifier may correspond to a code, such as a bar code, a QR code, an embossed code, an optical holographic code, such as zeroorder diffractive microstructures, or a tag, such as an RFID tag. The physical identifier may be produced by a labelling machine, for example as described in the context of FIG. 9A.
Apparatus 426 may be configured to provide the generated digital access element to a decentral registry 914 accessible by decentral data consuming network node 702. Decentral data consuming network node 702 may use the data contained in the digital access element, such as the decentral passport identifier and the digital twin location data, to access the digital twin data structure associated with the decentral passport identifier from decentral data providing network node 416, for example as described in the context of FIG. 16. The decentral data providing network node 416 may authorize access to the digital twin data structure based on the decentral digital twin identifier associated with the digital access element, the decentral participant identifier associated with the decentral data consuming network node requesting access to said digital twin and the access policy data provided by apparatus 402 (see for example FIG. 6A and FIG. 15A). The decentral data providing network node 416 may authorize in combination with access controller 712 access to the digital twin data structure based on the decentral digital twin identifier associated with the digital access element, the decentral participant identifier associated with the decentral data consuming network node requesting access to said digital twin and the access policy data provided by apparatus 402 (see for example FIG. 6B and FIG. 15A).
FIG. 10 illustrates a flow chart of a computer-implemented method for generating a digital twin of a physical entity of a product in accordance with an example embodiment of the present disclosure. The digital twin may include a digital twin data structure. The digital twin data structure may include a tree
structure comprising a root node and one or more leaf nodes. AN example of a digital twin data structure is illustrated in FIG. 5. The digital twin may be generated for a product 206 produced by a production 204 from one or more inbound materials 202. The production may be a chemical production 204 as described in relation to FIG. 2 and FIG. 3. The digital twin may be generated by operating system 208 of the production 204. The operating system may comprise an apparatus for generating digital twin(s) 424 as described in the context of FIG. 9A. The request to generate the digital twin may be triggered manually by a user via a user interface. The request to generate the digital twin may be triggered automatically, for example upon detection of a packaging of the produced chemical product as described in the context of FIG. 3 and FIG. 9A.
In block 1002, a request to generate a digital twin of a product may be received. The request may contain data related to the product. The request may further contain data related to at least one aspect model associated with products. The request may be generated manually or automatically, as previously described. Data related to the product may include a product identifier, such as a batch number, a LOT number, a product name and/or a product ID. Data related to at least one aspect model may include aspect model identifier(s).
In decision block 1004, it may be determined whether a digital twin data structure for the product is already existing. Hence, it may be determined whether the digital twin data structure has already been generated and stored, for example in DT storage 414. This determination may be based on the data related to the product contained in the received request, such as the product identifier. For instance, the product identifier may be used to determine whether a digital twin data structure associated with or including said product identifier is already existing, e.g. already stored in DT storage 414. If a digital twin data structure of the product is already existing, the method may proceed to decision block 1006. Otherwise, the method may proceed to block 1010 as described later on.
In decision block 1006, it may be determined whether the existing digital twin data structure is to be updated. The determination may be made based on data contained in the received request. For instance, the request may contain data being indicative of updating the digital twin data structure. If a digital twin data structure is to be updated, the method may proceed to block 1008. Otherwise, the method may end or may proceed to block 1002.
In block 1008, the digital twin data structure may be updated. Updating may include performing block 1010 to block 1016 described later on, e.g. generating further sub data structures. Updating may include modifying digital twin data structure contained in the existing digital twin.
In block 1010, data containing the at least one measured and/or determined physical and/or chemical property of the chemical product may be gathered based on the data related to the product contained in the request received in block 1002. The data may be gathered as described in the context of FIG. 9A
from one or more data sources, for example distributed data sources of data source layer 420 (see FIG. 4B). The data may be gathered directly from the one or more distributed data sources of data source layer 420. The data may be consumed from service layer 422, for example as described in the context to FIG. 4B. Apparatus 424 may determine whether the request contains product identifier(s). If this is the case, said product identifier(s) may be used to gather the data from the distributed data source(s). Otherwise, apparatus 424 may determine the product identifier(s) from the data contained in the received request. For instance, the product identifier(s) may be retrieved from a database based on the data contained in the received request.
In block 1012, a decentral digital twin identifier associated with the gathered data and optionally a data owner may be provided. The decentral digital twin identifier may be provided in response to a request generated, for example, by digital twin generator 908 of apparatus 424 (see FIG. 8A). The request may contain a data owner identifier and/or a product identifier. The data owner may be the data owner of the gathered data and/or the data contained in the distributed data sources. The data owner may be the product producer. The data owner may be a data owner as previously described. The decentral digital twin identifier may be requested from a central or decentral node, for example as described in the context of FIG. 9A. The decentral identifier may be one or more DID(s) and/or UUID(s), for example as described in the context of FIG. 9A. Block 1012 may also be performed after any one of blocks block 1014 and block 1016.
In block 1014, aspect model(s) associated with products may be gathered. At least part of the aspect model(s) may be associated with environmental attributes associated with products. The aspect model(s) may be gathered based on aspect model identifier(s) contained in the received request or based on data contained in the received request. The aspect model(s) may be gathered from a data storage.
In block 1016, sub data structures may be generated for each aspect model retrieved in block 1008. AT least part of the generated sub data structures may include a tree structure. The sub data structure may be generated by applying each aspect model retrieved in block 1014 to the data gathered in block 1010. For instance, the gathered data may be mapped to the structure and/or properties of the respective aspect model. Each gathered aspect model may include the structure of at least a portion of the sub data structure, and/or properties of the sub data structure. The data storage may contain aspect model(s) related to environmental attributes associated with the products. The environmental attributes may relate to emission data, such as CO2 footprint data, recyclate content, bio-based content, renewable content, certificates, or a combination thereof. Use of different aspect models allows to more granularly structure the sub data structure that is contained in the digital twin data structure, thus allowing to retrieve only specific parts of the digital twin data structure and avoiding unnecessary data transfer within the decentral network. Sub data structure generated by applying an aspect model to the gathered data and associated with the decentral identifier of the digital twin data structure may be regarded as an asset or aspect of
the digital twin. Each asset or aspect may be uniquely identified by the sub data structure identifier. Hence, the combination of decentral identifier and sub data structure identifier may allow to uniquely identify sub data structure associated with a product. Moreover, said combination also allows to specifically retrieve such sub data structure, for example via a decentral data consuming network node using the decentral identifier and digital twin location data as described in the context of FIG. 16.
In block 1018, the digital twin may be generated. Generating the digital twin may include generating a digital twin data structure including a tree structure comprising a root node and one or more leaf nodes. Generating the digital twin data structure may include generating a root node and linking the root node to at least part of the generated sub data structures. The provided decentral identifier may be included in the root node. The digital twin may include the digital twin data structure including a tree structure comprising the root node and one or more leaf nodes. The digital twin data structure may include the root node and one or more sub data structures generated in block 1016. The decentral identifier may include one or more DID(s) and/or UUID(s), for example as described in the context of FIG. 9A. The one or more DID(s) and/or UUID(s) may be associated with at least part of the sub data structures. The one or more DID(s) and/or UUID(s) may further be associated with the product. The digital twin may further include a product identifier associated with the product. The product identifier may be the product identifier contained in the received request.
Generating the digital twin may further include generate digital twin location data. Digital twin location data may include digital representation(s) pointing to the digital twin data structure or parts thereof. For instance, a DID document including the provided decentral identifier and the generated digital twin location data may be generated (see for example FIG. 19). The DID document may be propagated to a distributed ledger, such as a blockchain or a decentralized file storage system as described in the context of FIG. 19 and may be used by chemical product consumer 104 to access the digital twin data structure, for example as described in the context of FIG. 15.
In block 1020, the generated digital twin may be stored in a DT storage 414 as described in the context of FIG. 9A, this block being generally optional. Storage of the digital twin in DT storage 414 may improve security with respect to the access to the digital twin, since appropriate authentication and authorization schemes may be implemented between DT storage 414 and the decentral data providing network node providing the digital twin data to authorized decentral data consuming network nodes, for example as described in the context of FIG. 15A and Fig, FIG. 15B.
In block 1022, a physical identifier may be assigned to the decentral digital twin identifier included in the digital twin, this block being generally optional. This block may be performed, for example, if the decentral identifier contained in the digital twin is used to generate the digital access element (see for example FIG. 8B). This allows to link the decentral identifier and thus the digital twin to the physical entity of the product. Assigning the decentral identifier to the physical identifier may include generating a physical
identifier having embedded the decentral identifier. The physical identifier may be generated by an ID assignor, for example as described in the context of FIG. 9A, and may be attached to the product, for example using a labelling device.
FIG. 1 1 illustrates a flow chart of a computer-implemented method for generating access policy data for controlling access to a digital twin of a physical entity of a product produced from one or more input materials in accordance with an example embodiment of the present disclosure. The method may be implemented by the apparatus for generating access policy data 402 described in the context of FIG. 4A. The method may be implemented by system 400b described in the context of FIG. 4B. The method may be implemented by digital twin management system 902 described in the context of FIG. 9A and FIG. 9B. The generated access policy data may be used to control access to digital twin data structure by decentral data consuming network nodes (see for example FIG. 14A and FIG. 14B). The access to the digital twin data structure may be controlled by decentral data providing network node 416 based on the access policy data, for example as described in the context of FIG. 15A. The access to the digital twin data structure may be controlled by decentral data providing network node 416 in combination with access controller 712, for example as described in the context of FIG. 15B.
In block 1 102, group access data associated with the digital twin data structure may be generated. The group access data may be generated based on the decentral digital twin identifier and associated attribute data related to participant(s) associated with the decentral network. Group access data may be generated as described in the context of FIG. 12. Group access data may include one or more access control groups. The access control group may include one or more decentral participant identifier(s) associated with decentral network participant(s). The decentral network participant(s) may be associated with decentral participant node(s), hence the decentral participant identifier(s) may also be associated with decentral participant node(s). Group access data may include group access policy data. The group access policy data may define access control group(s) permitted access to the digital twin data structure. The group access policy data may include access control group(s) and/or access control group identifier(s) and an indication of whether decentral participant identifier(s) included in said access control group are permitted or are not permitted to access the digital twin data structure. Hence, group access data may identify access control group(s) including decentral participant identifier(s) associated with decentral network participant(s) permitted to access to the digital twin data structure. By using the group access data, decentral data consuming network node(s) having access the digital twin data structure may be filtered. For instance, decentral data consuming network node(s) associated with decentral participant identifier(s) included in one or more access control groups permitted to access the digital twin data structure may be permitted access to said digital twin data structure while decentral data consuming network node(s) associated with decentral participant identifier(s) not included in access control groups permitted to access the digital twin data structure may not be permitted access to the digital twin data structure. However, membership in an access control group permitted to access the digital twin data structure may
be independent from participant access data associated with the respective participant of the decentral network via the associated decentral participant identifier contained in the participant access data. Hence, access to the digital twin data structure may be managed independently of the participant access data controlling access and interaction of decentral network participants to specific nodes(s) present within the digital twin data structure. The group access data allows the data owner to ensure data security by avoiding stale permissions permitting decentral network participants to access and/or manipulate the digital twin data structure when the participant(s) should no longer be able to do so since said participant(s) would no longer be able to access the digital twin data structure because they would no longer be associated with an access control group that is permitted to access the digital twin data structure. Access to the digital twin data structure may hence be controlled by the access control groups irrespective of the rights of a decentral network participant to interact with the digital twin data structure upon accessing said data structure. This allows to manage access rights efficiently, securely and reliably to the digital twin data structure, hence avoiding unauthorized access to said digital twin data structure and improving security.
In block 1 104, participant access data associated with the digital twin data structure may be generated based on the generated group access data. Generating participant access data may include selecting, for at least part of the node(s), at least one decentral participant identifier permitted to access one or more of said node(s) from decentral participant identifier(s) included in the generated group access data. Generating participant access data may include generating access control list data including at least one access control list entry. The at least one access control list entry may include the decentral participant identifier associated with the respective participant of the decentral network permitted to access one or more node(s) present within the digital twin data structure, the respective node(s) to which access is permitted for said participant, and the one or more action(s) allowed to be performed on the node(s) for which access is permitted. Action(s) allowed to be performed on the node(s) may include actions allowed to be performed on data set(s) contained within the node(s), such as key value pair(s) contained within the node(s). The access control entry may further include one or more action(s) allowed to be performed on data point(s) present within the node(s). The access control list entry may be generated for at least part of the node(s) present with the digital twin data structure.
Generating access control list data may include gathering data related to the product, wherein the data related to the product includes a gathering of consumer identifier(s) associated with consumers of the product. The gathered data related to the product may be mapped to respective decentral participants identifier(s) contained in the access control groups based on a relationship representation according to which the data related to the product is associated with the decentral participant identifier(s). The relationship representation may specify consumer(s) associated with the product and/or the product associated with consumer(s). The relationship representation may specify the consumer(s) based on consumer identifier(s), such as the consumer identifier(s) contained in the data related to the product,
and associated decentral network identifier(s), such as decentral network identifier(s) contained in the access control groups. The relationship representation may correspond to a data structure containing the relationship between the product, the consumer identifier(s) and the decentral participant identifier(s). The data structure may include further information associated with the consumer identifier(s) and/or the decentral participant identifier(s), such as the name(s) and/or the addresses associated with said identifier(s). The relationship representation may be generated by determining the data related to the decentral participant(s) which is associated with the data related to the product. For instance, the relationship representation may be generated by matching the name(s) and/or addresses contained in the data related to the product with the names and/or addresses contained in the data related to the decentral participant node(s) and - based on said matching - interrelating the data related to the product with the decentral participant identifier(s). An example of relationship representations is illustrated in FIG. 13A and FIG. 13B.
The one or more node(s) may include emission data, recyclate content data, bio-based content data, provenance data, labour conditions data, data on the composition of the chemical product, material safety data, certificate of analysis data, data associated with the production of the product, certificates data associated with the product, regulatory information data associated with the product, data associated with the transport of the product, data associated with the use of the products, measured and/or determined chemical and/or physical properties of the product, or combinations thereof. The one or more actions may include read operations, modify operations, update operations, delete operations, create operations, operations involving further processing of the data included in the node(s) by a data processing system associated with the participant of the decentral network or a combination thereof. The one or more actions may be associated with a particular location, wherein the location is associated with a jurisdiction and the one or more actions are associated with legal requirements related to the supply of products. The one or more actions may be associated with at least one regulatory requirement for the supply of products. The one or more action(s) may be associated with obligations of decentral data consuming network node(s) associated with respective decentral participant identifier(s) and/or obligations of decentral network node(s) using the digital twin data structure accessed by data consuming network node(s) associated with respective decentral participant identifier(s).
The participant access data may define, for one or more node(s) of the digital twin data structure, decentral participant identifier(s) permitted to access said node(s) and one or more actions allowed to be performed on said node(s). By using the participant access data, decentral participant permitted to access and interact with particular node(s) present within the digital twin data structure may be defined, hence ensuring that only decentral participants associated with decentral participant identifier(s) defined in the participant access data owner are permitted to perform defined action(s) on said particular node(s). This avoids generation of multiple copies of the digital twin data structure containing different nodes to ensure that different access control groups are only allowed to access the appropriate nodes.
In block 1106, access policy data may be generated based on group access data and the participant access data. The access policy data generated in block 1106 may be associated with the digital twin. The access policy data generated in block 1 106 may include the decentral digital twin identifier associated with the digital twin. The access policy data may include computer-executable instructions to allow access to the digital twin data structure, deny access to the digital twin data structure, to modify access to the digital twin data structure or to perform one or more action(s) on the digital twin data structure. The access policy data may include the decentral digital twin identifier, the decentral participant identifier(s) included in the access group data, the decentral participant identifier(s) permitted to access one or more node(s) present within the respective digital twin data structure and one or more actions allowed to be performed on one or more node(s) by the decentral participant node(s) associated with the decentral participant identifier(s) included in the participant access data.
The generated access policy data may be linked to the digital twin, this block being generally optional. Linking the generated access policy data to the digital twin may include associating or linking the access policy data to the decentral digital twin identifier associated with the digital twin. Linking the generated access policy data to the digital twin may include including the decentral digital twin identifier in the access policy data. Linking the generated access policy data to the digital twin may include linking an access policy data identifier to the decentral digital twin identifier.
In block 1 1 10, at least part of the generated access policy data is provided to a decentral data providing network node. For instance, the group access data may be provided to the decentral data providing network node. The decentral data providing network node may be configured to grant or deny access to the digital twin data structure based on the provided group access data, for example as described in the context of FIG. 7B and FIG. 15B. In another instance, the group access data and associated participant access data may be provided to the decentral data providing network node. The decentral data providing network node may be configured to grant or deny access to the digital twin data structure based on the provided group access data, for example as described in the context of FIG. 7A and FIG. 15A.
The decentral data providing network node may be associated with the digital twin data structure. The decentral data providing network node may be decentral data providing network node 416, for example as described in the context of FIG. 15A and FIG. 15B.
By combining group access data with participant access data, access to the digital twin data structure may be controlled on separate levels, ensuring that only authorized decentral network participants can access node(s) within the digital twin data structure while avoiding generation of multiple digital twin copies to ensure that only permitted node(s) can be accessed by decentral participant nodes being members of different access control groups. Hence, a decentral participant node(s) being a member of the same access control group may have access to and interact with different node(s) present within the
digital twin structure without having to generate multiple copies of digital twin data structure containing different node(s).
FIG. 12 illustrates a flow chart of a computer-implemented method for generating group access data as described in block 1 102 of FIG. 1 1 in accordance with an example embodiment of the present disclosure. The access group data may be generated based on the decentral digital twin identifier and associated attribute data related to participant(s) associated with the decentral network. Attribute data may be associated with or may include the role of the participant(s) associated with the decentral network. Roles may include a raw material supplier role, a chemical product producer role, an OEM role, an end-product user role, a dismantler role, a recycler role, etc.. Roles may be associated with the operation performed by the decentral network participant within the product ecosystem. For instance, a decentral network participant producing chemical products may be assigned to the role chemical product producer.
In block 1202, data on decentral network participants may be gathered. Data on decentral network participants may include data being indicative of the decentral network participants, such as participant names, decentral participant identifier(s) and associated attribute data. The attribute data may include attribute type(s), such as existing role(s) of participant(s) of the product ecosystem, such as described above. The decentral participant identifier(s) may be gathered from such decentral data storage of the decentral network 126 storing said data.
In block 1204 at least one access control group may be generated and at least part of the decentral participant identifiers included in the gathered data may be assigned to at least one generated access control group. The decentral participant identifier(s) may be assigned to the at least one access control group based on attribute data. For instance, decentral participant identifier(s) associated with a specific attribute type, such as a specific participant role, may be assigned to an access control group being indicative of such attribute type. Hence, an access control group may include a gathering of decentral participant identifier(s). The gathering may be regarded as a decentral participant identifier package. The access control group may include metadata. The metadata may indicate an identifier of the access control group, a name of the access control group, its creation data, its update data, or a combination thereof.
In block 1206, the decentral digital twin identifier included in the digital twin of the product may be provided. The decentral digital twin identifier may be provided by a decentral digital twin identifier providing unit, such decentral ID provider 410 of FIG. 4A. The decentral digital twin identifier may be provided as described in the context of FIG. 4A.
In block 1208, group access data may be generated. The group access data may identify generated access control groups including decentral participant identifier(s) associated with decentral participant node(s) permitted to access at the digital twin data structure. The group access data may include the provided decentral digital twin identifier and at least one group access policy defining generated access
control group(s) for which access to the digital twin data structure is permitted. The group access policy may include data being indicative of the access control group(s) and associated data being indicative that access to the digital twin data structure associated with the decentral digital twin identifier is permitted. Data being indicative of the access control group(s) may include the package of decentral participant identifiers. Data being indicative of the access control group may include an identifier and/or a name of the access control group. Data being indicative that access is permitted may include a classifier, such as “permitted” or “not permitted”. Use of the decentral digital twin identifier during generation of the group access data allows to link the generated group access data to the digital twin and hence the digital twin data structure said group access data is applied to upon receiving a request to access said digital twin data structure from a decentral participant node(s), such as decentral data consuming network node 602.
After the end of block 1208, the method may proceed with block 1104 of FIG. 11 .
FIG. 13A illustrates a first example of a relationship representation which may be used to generate participant access data as described in the context of FIG. 1 1. The relationship representation may be used by participant access data generator 408 of apparatus 402 to generate participant access data, for example as described in the context of FIG. 4A and FIG. 11. The relationship representation may relate a chemical product 1302 to one or more chemical product consumers 602, 604, 610. The one or more chemical product consumers may be chemical product consumers 104 and may be part of a decentral participant network 130 as described in the context of FIG. 1 . While a chemical product is used to illustrate the concept in FIG. 13A and FIG. 13B, this concept likewise applies to further products, such as discrete products, parts, part assemblies and end-products.
The chemical product 1302 may be a chemical product produced by a chemical production, such as chemical production 204 described in the context of FIG. 2, FIG. 9A and FIG. 9B. The chemical product 1302 may be a chemical product producible by a chemical production, such as chemical production 204 described in the context of FIG. 2, FIG. 9A and FIG. 9B. The chemical product 1302 may be associated with a digital twin. The digital twin may include a digital twin data structure, for example as described in the context of FIG. 5 and FIG. 9A. The chemical product 1302 may be associated with each batch of produced chemical product. The chemical product 1302 may represent a produced batch of chemical product.
The one or more chemical product consumers 602, 604, 610 may process the chemical product to produce further chemical or discrete products. The one or more chemical product consumers 602, 604, 610 may be associated with decentral participant network nodes 116A, 116B, 116D, such as described in the context of FIG. 6B. The respective decentral participant network nodes may be operated by the respective chemical product consumer. The decentral network participant nodes may correspond to decentral data consuming network nodes, such as decentral data consuming network node 702 described
in the context of FIG. 6A and FIG. 6B. Said decentral data consuming network node(s) may be configured to request access to the digital twin of the chemical product at a decentral data providing network node associated with said digital twin, for example as described in the context of FIG. 16. The relationship representation illustrated in FIG. 13A hence allows to identify consumers of chemical products produced by a chemical product producer 102 and associated decentral participant network node(s).
The relationship representation may be a data structure defining the relationship between a chemical product 1302, chemical product consumers 104 and decentral network node(s) associated with said chemical product consumers 104.
FIG. 13B illustrates a further example of a relationship representation which may be used to generate participant access data as described in the context of FIG. 11. The relationship representation may be used by participant access data generator 408 of apparatus 402 to generate participant access data, for example as described in the context of FIG. 4A and FIG. 11. The relationship representation may relate a chemical product 1302 to data related to the chemical product and decentral participant identifier(s).
The chemical product 1302 may be a chemical product produced by a chemical production, such as chemical production 204 described in the context of FIG. 13A. The chemical product 1302 may be a chemical product producible by a chemical production, such as chemical production 204 described in the context of FIG. 13A. The chemical product 1302 may be associated with a digital twin as described in the context of FIG. 13A. The chemical product 1302 may be associated with each batch of produced chemical product. The chemical product 1302 may represent a produced batch of chemical product.
The data related to the chemical product may contain consumer identifier(s) associated with chemical product consumers 104, such as consumer identifier 1 1306, consumer identifier 2 1308 and consumer identifier 3 1314. The consumer identifier(s) may be unique identifiers used within the chemical production producing the chemical product, such as chemical production 204 described in the context of FIG. 2, FIG. 9A and FIG. 9B. The consumer identifier(s) may not be unique within the decentral network 126. The consumer identifier(s) may not be known to other decentral network participant(s). The data related to the chemical product may contain a chemical product identifier associated with the chemical product. This allows to relate the data related to the chemical product to chemical product 1302 to provide a relationship to the chemical product 1302.
A consumer identifier may be related to a decentral participant identifier associated with a chemical product consumer 104. The respective decentral participant identifier may comprise any identifier uniquely associated with a participant of a decentral network and/or with a production site of a participant of the decentral network, for example as described in the context of FIG. 4A. The decentral participant identifier may be associated with a decentral participant node of a chemical product consumer 104 the consumer identifier is associated with. This allows to relate the consumer identifier(s) used within the
chemical production to respective decentral participant identifier(s) associated with participant network nodes of chemical product consumers 104.
The relationship representation may be a data structure defining the relationship between a chemical product 1302, chemical product consumers 104 and decentral network node(s) associated with said chemical product consumers 104. The data structure may contain chemical product identifier(s) interrelated with customer identifier(s) and associated decentral participant identifier(s).
FIG. 14 illustrates a flow chart of a computer-implemented method for controlling access to a digital twin of a physical entity of a product by a decentral data consuming network node associated with a participant of a decentral network in accordance with an example embodiment of the present disclosure. The digital twin may be generated as described in the context of FIG. 9A and FIG. 10. The digital twin may include a digital twin data structure. The digital twin data structure may include a tree structure which comprises a plurality of nodes including a root node and one or more leaf nodes. An example of such a tree structure is illustrated in FIG. 5. The digital twin data structure may include the decentral digital twin identifier and at least one measured physical and/or chemical property of the product and/or at least one physical and/or chemical property determined from collected data associated with the production and/or the use of the product.
The product may be produced by a production from one or more input materials, for example as described in the context of FIG. 2, FIG. 9A and FIG. 9B. The product may be a chemical product. Access to the digital twin data structure by a decentral data consuming network node, such as decentral data consuming network node 702, associated with a chemical product consumer 104 may be controlled based on access policy data associated with the digital twin data structure. The access policy data may be generated as described in the context of FIG. 4A, FIG. 4B, FIG. 11 and FIG. 12. Access to the digital twin data structure may be controlled by digital twin management system 902 as described in the context of FIG. 9A and FIG. 9B. The digital twin management system may be part of an operating system of a production, such as operating system 208 of production 204 (see for example FIG. 2, FIG. 9A, FIG. 9B). The digital twin management system may be communicatively coupled to the operating system (not shown).
For accessing the digital twin data structure, a request to access the digital twin data structure may be received by decentral data providing network node 416 in block 1402. Decentral data providing network node 416 may be associated with DT storage 414 storing the digital twin data structure. Decentral data providing network node 416 may be identified using a digital access element associated with the digital twin, for example as described in the context of FIG. 16. The digital access element may be generated as described in the context of FIG. 9B. The request may be generated by decentral data consuming network node 702 and may be provided to decentral data providing network node 416. Decentral data consuming network node 702 may be associated with a decentral network participant, such as a chemical product consumer 104 (see for example FIG. 1 and FIG. 16). The request may contain the decentral
digital twin identifier associated with the requested digital twin data structure and a decentral participant identifier associated with the decentral network participant requesting access to the digital twin data structure. The request may further contain data being indicative of one or more operation(s) to be performed on the requested digital twin data structure. One or more actions may include read, update, modify, process, or a combination thereof. The request may be transmitted through a peer-to-peer communication channel between decentral data providing network node 416 and decentral data consuming network node 702 (see FIG. 1 , dotted line between node 114 and 1 16). The decentral digital twin identifier may be encoded in the physical identifier of the product (see for example FIG. 16). The decentral digital twin identifier may be retrieved from a database based on the physical identifier associated with the product (see for example FIG. 16).
Authentication may be performed in block 1404, this block being generally optional. In particular, decentral data consuming network node 702 requesting to access the digital twin data and/or the decentral data providing network node 416 providing access to the digital twin data structure may be authenticating, e.g. may perform authentication. Such authentication may be based on data related to an authentication mechanism. The authentication mechanism may be based on certificate(s) associated with the respective decentral participant nodes.
In decision block 1406, decentral data providing network node 416 and/or decentral data consuming network node 702 may determine whether the authentication is valid, this block being generally optional. If authentication is not valid, e.g. failed, decentral data providing network node 416 may deny the requested access to the digital twin data structure and the method may end. Decision block 1406 may further include signature of an electronic contract as described in the context of FIG. 16. Use of the electronic contract ensures that decentral data consuming network node 702 and further systems handling the digital twin data structure are complying to participant access data associated with the digital twin data structure. If no electronic contract is signed, decentral data providing network node 416 may deny the requested access to the digital twin data structure.
If authentication is valid, access policy data may be determined in block 1408 based on the received decentral digital twin identifier. The access policy data may include the decentral digital twin identifier, group access data and associated participant access data as described in the context of FIG. 1 1. The access policy data may be retrieved from a database of the decentral data providing network node, such as database 418 (see FIG. 4A). The group access data may identify access control groups including decentral participant identifier(s) associated with decentral participant node(s) permitted to access at the digital twin data structure as described in the context of FIG. 1 1 and FIG. 12. The participant access data may identify decentral participant identifier(s) permitted to access one or more node(s) present within the digital twin data structure and one or more actions allowed to be performed on the one or more node(s) by decentral participant node(s) associated with the decentral participant identifier(s). The decentral
participant identifier(s) identified by participant access data may be included in one or more access control groups identified by the group access data. Hence, the participant access data may define access and actions for decentral participant identifier(s) included in the access control groups identified by the group access data on node level. This allows to filter decentral data consuming network nodes requesting access to the digital twin data structure by applying a group-based access control as well as a data nodebased access control. Since membership in an access control group permitted to access the digital twin data structure is independent from participant access data, access to the digital twin data structure may be managed independently of the participant access data controlling access of decentral network participants to specific node(s) and interaction with said node(s) present within the digital twin data structure. Combination of the group-based a group access control with the node-based access control allows the data owner to easily manage access to the digital twin data structure and ensuring high data security of the digital twin data structure by avoiding stale permissions resulting in unauthorized access to said digital twin data structure while at the same time allowing the data owner to define permitted actions for decentral participants permitted to access the digital twin data structure on node level, hence avoiding generation of multiple copies of the digital twin data structure. This allows to control access to the digital twin data structure in a controlled and secure manner, hence ensuring that the digital twin data structure can be shared within a decentral network under the control of the data owner of the digital twin data.
Based on the determined access policy data, it may be determined in decision block 1412 whether the decentral network participant associated with decentral data consuming network node 702 is a member of one or more access control group(s) permitted to access the digital twin data structure, for example as described in the context of FIG. 15A and FIG. 15B. This determination may include comparing the decentral participant identifier associated with the decentral network participant and included in the received request to the group access data included in the determined access policy data, e.g. to decentral participant identifier(s) included in access control group(s) associated with a group access policy permitted to access the digital twin dat structure a. For instance, the received decentral participant identifier may be compared to decentral participant identifiers included in access control groups having permission to the digital twin data structure. If the decentral network participant is a member of an access control group permitted to access the digital twin data structure (e.g. if the received decentral participant identifier matches a decentral participant identifier included in one or more access control groups permitted to access the digital twin data structure), the method may proceed to decision block 1416. Otherwise, decentral data providing network node 416 may deny requested access to the digital twin data structure and the method may end.
In decision block 1416, it may be determined whether the decentral network participant having access to the digital twin data structure may be permitted to perform requested action(s) on the digital twin data structure, for example as described in the context of FIG. 15A and FIG. 15B. The received decentral
participant identifier may be compared to participant access data included in the determined access policy data. The received decentral participant identifier may be compared to decentral participant identifier(s) permitted to access one or node (s). If said decentral participant identifier matches a decentral participant identifier permitted to access one or more node(s), received data being indicative of one or more actions requested to be performed may be compared to one or more actions allowed to be performed on the one or more nodes(s) by the decentral participant node associated with the received decentral participant identifier. If the decentral network participant is permitted to perform the requested action(s) on the one or more node(s), the method may proceed to block 1420. Otherwise, decentral data providing network node 416 may deny the requested access to the digital twin data structure and the method may end.
In block 1420, decentral data consuming network node 702 may be permitted access to the digital twin data structure according to the determined access policy data. Permitting access may include applying participant access data contained in the determined access policy data to digital twin data structure associated with the received decentral digital twin identifier and the resulting digital twin data structure may be provided to decentral data consuming network node 702. Applying participant access data may include traversing through the tree structure of the digital twin data structure and determining, for each node, whether the decentral participant is permitted to access said node and to perform one or more action(s) on said node (e.g. on data contained in said node). Node(s) which may not be accessed by the participant may be filtered, e.g. removed, from the digital twin data structure and the remaining data structure, e.g. the data structure containing only node(s) that the decentral participant is allowed to access and interact with, may be provided to the decentral data consuming network node requesting access to the digital twin data structure. Applying determined participant access data may include gathering the digital twin data structure based on the decentral digital twin identifier contained in the received request and applying the determined participant access data to the gathered digital twin data structure as previously described. The digital twin data structure may further be gathered based on digital twin location data contained in the determined access policy data. The digital twin data structure may be gathered from a data storage, such as DT storage 414 (see for example FIG. 4A, FIG. 7A, FIG. 7B, FIG. 15A, FIG. 15B). Decentral data providing network node 416 may gather digital twin data structure, apply determined participant access data and provide resulting digital twin data structure to decentral data consuming network node 702, for example as described in the context of FIG. 7A. The data storage may be connected to decentral data providing network node 416 via a further authentication network node. This improves security because it ensures that only properly authenticated decentral data providing network nodes 416 can access the database storing the digital twin data structure and hence avoids unauthorized access to said digital twin data structure.
Access controller 712 may gather digital twin data structure and may apply the determined participant access data, for example as described in the context of FIG. 15A and FIG. 15B. The resulting digital twin data structure may be provided to decentral data providing network node 416 and decentral data providing
network node 416 may provide the resulting digital twin data structure to decentral data consuming network node 702.
The decentral data consuming network node 702 may hence retrieve or receive the resulting digital twin data structure from decentral data providing network node 416.
FIG. 15A illustrates a diagram showing a first example of processing a request from a decentral data consuming network node to access digital twin data structure of a digital twin of a product. The decentral data consuming network node may be associated with a decentral network participant as illustrated in FIG. 1. The decentral network participant may desire access to digital twin data structure of a product. The decentral network participant may be a chemical product consumer 104 receiving chemical products from chemical product producer 102. The digital twin data structure may be generated as described in the context of FIG. 9A and FIG. 10. The request may be processed by decentral data providing network node 416 associated with the digital twin data (see for example FIG. 7A).
Decentral data consuming network node 702 may submit request to access the digital twin data structure to decentral data providing network node 416 (see step [1] in FIG. 15A). Upon receipt, the request may be processed by policy engine 706 to (1) determine whether the decentral network participant associated with decentral data consuming network node 702 submitting the request is authorized to access the digital twin data structure, and (2) determine whether the decentral network participant has the rights required to perform a requested action or actions on one or more node(s) present within the digital twin data structure if the decentral network participant has access to the digital twin data structure. The request may contain the decentral digital twin identifier associated with the digital twin data structure to be accessed and a decentral participant identifier associated with the decentral network participant. The request may indicate one or more operations requested to be performed on the digital twin data structure on behalf of the decentral network participant associated with decentral data consuming network node 702.
Policy engine 706 may be configured to obtain group access data for a requested digital twin data structure identified in the request received from decentral data consuming network node 702 (see operation 1502). Policy engine 706 may formulate a request for group access data (see step [2] of FIG. 15A) to obtain the group access data from the group access data datastore 708. Group access data associated with the requested digital twin data structure may be provided to the policy engine 706 (see step [3] of FIG. 15A). Group access data may include one or more access control groups. Group access data may include group access policy data. The group access policy data may include access control group(s) and/or identifier(s) of access control group(s) and an indication of whether decentral participant identifier(s) of the group are permitted or are not permitted to access the digital twin data.
Policy engine 706 may be configured to obtain the decentral participant identifier from the received request (see operation 1512).
Policy engine 706 may be configured to determine whether the decentral network participant is a member of at least one access control group (e.g. whether the decentral participant identifier associated with the decentral network participant is contained in at least one access control group) that has been granted access to the digital twin data structure and the access has not been revoked (see operation 1504). Policy engine 706 may make this determination by comparing the decentral participant identifier obtained from the received request with the decentral participant identifier(s) included in the group access data (e.g. included in one or more of the access control group(s) obtained from the group access data datastore 708). If the decentral network participant is not a member of any access control groups or is not a member of an access control group that has been granted access to the digital twin data structure, the policy engine 706 may proceed to operation 1510. In operation 1510, policy engine 706 may deny the request to access the digital twin data structure received from decentral data consuming network node 702, before generating a message indicating that the request has been denied. The message may include an indication that the decentral network participant does not have access to the digital twin data structure.
Policy engine 706 may proceed to operation 1506 responsive to the decentral network participant being authorized to access the digital twin data structure. In operation 1506, policy engine 706 may determine participant access data for the decentral network participant requesting access to the digital twin data structure (e.g. rights of the decentral network participant to perform one or more defined actions on node(s) present within the digital twin data structure). The participant access data may be determined using participant access data obtained from participant access data datastore 710. Participant access data stored in datastore 710 may be access control list data (see FIG. 11). Access control list data may include at least one access control list entry. The at least one access control list entry may include the decentral participant identifier associated with the respective participant of the decentral network permitted to access at least part of the nodes present within the digital twin data structure, the respective node(s) to which access is permitted for said participant, and the one or more action(s) allowed to be performed on the node(s) for which access is permitted (see FIG. 11). The node(s) present within the digital twin data structure may be assigned to different security protections that define the decentral network participant rights to access these node(s) and to perform specific actions on these node(s). These rights may be expressed as access control list data associated with the node(s) present within the digital twin data. Policy engine 706 may formulate and send a request for participant access data to obtain the participant access data from the participant access data datastore 710.
Policy engine 706 may query the participant access data datastore 710 to obtain the participant access data for the digital twin data structure associated with the request. Policy engine 706 may compare each of the actions requested by the decentral network participant with the rights afforded to the decentral
network participant according to the participant access data. Policy engine 706 may determine rights for the decentral network participant based on the results of this comparison. The determined rights may represent the union of the rights from the participant access data that have corresponding claims (e.g. corresponding decentral participant identifier and action(s)) contained in the received request.
Policy engine 706 may be configured to determine whether the decentral network participant has the rights required to perform the request on the digital twin data structure (see operation 1508). Policy engine 706 may compare the participant rights obtained from operation 1506 with the data contained in the received request to determine whether the decentral network participant has the rights required for the request to be performed on the digital twin data structure. If the decentral network participant does not have the required rights for the request to be performed, policy engine 706 may proceed to the operation 1510 discussed above to notify the decentral data consuming network node 702 that the request may not be performed. Otherwise, if the decentral network participant has the rights required for the request to be performed on the digital twin data structure, the policy engine 706 may provide the request to decentral data providing network node 416 for execution. Decentral data providing network node 416 may be configured to gather digital twin data from DT storage 414 in response to receiving the request from policy engine 706 (see operation 1516). The gathered digital twin data structure may be provided to policy engine 706 and policy engine 606 may apply determined participant rights (see operation 1414) to the gathered digital twin data structure, for example as described in the context of FIG. 14. Policy engine 706 may provide a request response to decentral data consuming network node 702. The request response may include digital twin data structure resulting from operation 1514.
FIG. 15B illustrates a diagram showing a further example of processing a request from a decentral data consuming network node to access a digital twin data structure. The decentral data consuming network node may be associated with a decentral network participant as illustrated in FIG. 1 . The decentral network participant may desire access to digital twin data structure associated with a product. The decentral network participant may be a chemical product consumer 104 receiving chemical products from chemical product producer 102. The digital twin data structure may be generated as described in the context of FIG. 9A and FIG. 10. The request may be processed by decentral data providing network node 416 associated with the digital twin data structure in combination with an access controller 712 (see for example FIG. 7B).
In contrast to the example illustrated in FIG. 15A, only the group-based access is controlled by decentral data providing network node 416 while an access controller 712 is used to determine whether the decentral network participant has the rights required to perform one or more requested actions on one or more node(s) present within the digital twin data structure. Hence, group-based access control and nodebased access control are performed by separate policy engines present within separate units.
Decentral data consuming network node 702 may submit a request to access the digital twin data structure to decentral data providing network node 416 as described in the context of FIG. 15A (see step [1] in FIG. 15B). Upon receipt, the request may be processed by policy engine 706 of decentral data providing network node 416 to determine whether the decentral network participant associated with decentral data consuming network node 702 submitting the request is authorized to access the digital twin data structure. The request may contain the data mentioned with respect to FIG. 15A.
Policy engine 706 may be configured to obtain group access data for a requested digital twin data structure identified in the request received from decentral data consuming network node 702 as described in the context of FIG. 15A (see operation 1502, steps [2] and [3] of FIG. 15B).
Policy engine 706 may be configured to obtain the decentral participant identifier from the received request (see operation 1512).
Policy engine 706 may be configured to determine whether the decentral network participant is a member of at least one access control group that has been granted access to the digital twin data structure and the access has not been revoked as described in the context of FIG. 15A (see operation 1504). If the decentral network participant is not a member of any access control groups or is not a member of an access control group that has been granted access to the digital twin data structure, the policy engine 706 may proceed to operation 1510. In operation 1510, policy engine 706 may deny the request to access the digital twin data structure received from decentral data consuming network node 702, before generating a message indicating that the request has been denied as described in the context of FIG. 15 A.
Policy engine 706 may provide a deny request to access DT 1510 determine participant access data for the decentral network participant requesting access to the digital twin data structure to policy engine 2 714 of access controller 712 responsive to the decentral network participant being authorized to access the digital twin data structure. The request may contain the decentral participant identifier and data on one or more actions requested to be performed on the digital twin data structure. The request may further contain an indication of the access control group the participant belongs to. The request may further contain an indication that the participant is authorized to access the digital twin data structure.
In response to the request, policy engine 2 714 may determine participant access data for the decentral network participant requesting access to the digital twin data structure in operation 1506 as described in the context of FIG. 15A.
Policy engine 2 714 may be configured to determine whether the decentral network participant has the rights required to perform the request on the digital twin data structure in operation 1508 as described in the context of FIG. 15A. If the decentral network participant does not have the required rights for the
request to be performed, policy engine 2 714 may proceed to the operation 1510 discussed above to notify the decentral data consuming network node 702 that the request may not be performed. Otherwise, if the decentral network participant has the rights required for the request to be performed on the digital twin data structure, policy engine 2 714 may provide the request to access controller 712 for execution. Access controller 712 may be configured to gather the digital twin data structure from DT storage 414 in response to receiving the request from policy engine 2 714 (see operation 1516). The gathered digital twin data structure may be provided to policy engine 2 714 and policy engine 2 714 may apply determined participant rights (see operation 1514) to the gathered digital twin data, for example as described in the context of FIG. 14. Policy engine 2 714 may provide a request response to decentral data consuming network node 702. The request response may include digital twin data structure resulting from operation 1514.
FIG. 16 shows a schematic illustration for controlling access by a decentral data providing network node to a digital twin data structure of a digital twin associated with a product using a digital access element associated with the product to access the digital twin data structure in accordance with an example embodiment of the present disclosure. Access to digital twin data structure may be requested by a decentral data consuming service associated with a participant of the decentral network 126 (see FIG. 1). The participant may be a chemical product consumer 104 receiving chemical products from a chemical product producer 102 (see FIG. 1). The product 206 may be produced by a production, such as chemical production 204 described in the context of FIG. 2, FIG. 9A and FIG. 9B. The product 206 may be associated with a digital twin. The digital twin including the digital twin data structure may be generated as described in the context of FIG. 9A and FIG. 10. The digital twin may include a digital twin data structure. The digital twin data structure may include a tree structure which comprises a plurality of nodes including a root node and one or more leaf nodes. An example of such a tree structure is illustrated in FIG. 5. The digital twin data structure may include a decentral digital twin identifier and at least one measured physical and/or chemical property of the product and/or at least one physical and/or chemical property determined from collected data associated with the production and/or the use of the product. The digital twin may be stored in a data storage associated with the data owner of the digital twin, such as DT storage 414. The data owner may be the product producer, such as chemical product producer 102. Access to the digital twins stored in the data storage, such as DT storage 414, may be controlled by the data owner of the digital twins, for example via decentral data providing network node 1 14.
The digital access element may be generated upon or after production of the product, for example as described in the context of FIG. 9B. The digital access element may be associated with the digital twin or a part thereof (e.g. the digital twin data structure or a sub data structure included in the digital twin data structure). The digital access element may contain a decentral passport identifier and digital twin location data. The digital access element may contain a decentral passport identifier and a representation for accessing the digital twin or parts thereof. The representation may include an endpoint for accessing
the digital twin or parts thereof. The representation may be associated with the decentral digital twin identifier. The decentral passport identifier may correspond to or be associated with the decentral digital twin identifier included the digital twin data structure. The digital twin location data may include digital representation(s) pointing to the digital twin or parts thereof. Examples of digital access elements are illustrated in FIG. 19. The digital access element may further include or relate to authentication and/or authorization information linked to the decentral passport identifier. The authentication and/or authorization information may be provided for authentication and/or authorization of the decentral data providing network node 416 and/or the decentral data consuming network node 602. The digital access element may be provided to a decentral registry 914, for example as described in the context of FIG. 9B. Decentral registry 914 may store decentral passport identifier(s) and associated digital twin location data.
The product 206 as produced by the production 204 may be provided by a product producer, such as chemical product producer 102, in association with the digital access element to a product consumer, such as chemical product consumer 104. The product consumer may process the product to produce further chemical and/or discrete products. The product 206 may be connected to a code, such as a bar code or QR-code, having encoded the decentral passport identifier. The product consumer of the product 206 may read the code through a code reader 1602. The code reader 1602 may be a smartphone running a code reading application, such as a QR code reader app. The data obtained by the code reading application may be used to determine the decentral passport identifier. The data obtained by the code reading application may be used to determine the decentral digital twin identifier. The data obtained by the code reading application may be used to determine the product identifier. The data obtained by the code reading application may be used to determine the digital twin location data. The decentral passport identifier, decentral digital twin identifier, product identifier and digital twin location data may be determined by code reader 1602. For instance, the decentral passport identifier determined by the code reader 1602 may be a DID and the code reader 1602 may be configured to retrieve the associated DID document containing the decentral digital twin identifier and the digital twin location data, for example using a DID resolver (see also FIG. 19). In another instance, the chemical product identifier is determined by code reader 1602 and used to retrieve the decentral passport identifier and associated digital twin location data, for example from a database, such as decentral registry 914. Hence, code reader 1602 may be configured to retrieve the digital access element containing the decentral passport identifier and digital twin location data from decentral registry 914. Code reader 1602 may be configured to provide the decentral passport identifier and/or the decentral digital twin identifier to a database 1606 associated with the consumer of the product. Code reader 1602 may be configured to provide the determined decentral passport identifier, decentral digital twin identifier and digital twin location data to decentral data consuming network node 702.
Code reader 1602 may be configured to display determined/retrieved data on a user interface as illustrated by reference sign 1604. The user interface may display the determined decentral passport
identifier (PP identifier), the determined decentral digital twin identifier (DT identifier) and the determined digital twin location data (DT location). In this embodiment, the decentral passport identifier and the decentral digital twin identifier differ from each other. In another embodiment, the decentral passport identifier is equal to the decentral digital twin identifier. The user interface may further display the determined product identifier (CP identifier). The user interface may also allow to initiate retrieval of the digital twin data structure or a part thereof based on the decentral passport identifier and the digital twin location data as described in the following. This process may be initiated by the button denoted “Access DT”. Upon pressing said button, code reader 1602 may send a request to access the digital twin data structure or a part thereof to decentral data consuming network node 702.
Decentral data consuming network node 1 16 may generate a request to access the data structure or a part thereof. Decentral data consuming network node 116 node may generate the request based on the data received from code reader 1602. For instance, decentral data consuming network node 1 16 may generate the request based on the decentral digital twin identifier received from code reader 1602. Decentral data consuming network node 116 may generate the request based on the decentral passport identifier and/or decentral digital twin identifier provided to database 1606. For example, decentral data consuming network node 116 may be configured to retrieve the decentral digital twin identifier and digital twin location data from decentral registry 914 based on the decentral passport identifier stored in database 1606. The request generated by decentral data consuming network node 1 16 may include the decentral digital twin identifier and the decentral participant identifier of the product consumer associated with decentral data consuming network node 1 16. The request may include one or more actions to be performed on the digital twin data structure. Decentral data consuming network node 116 may be configured to determine the decentral data providing network node 114 associated with the digital twin data structure based on the digital twin location data provided by code reader 1602 or retrieved from decentral registry 914.
Decentral data consuming network node 116 may sent the request to access the digital twin data structure to the determined decentral data providing network node 114 as signified by arrow 1608. The decentral data providing network node 114 may be associated with the product producer producing product 206. The decentral data providing network node 114 may be associated with the production producing the product. The decentral data providing network node 114 may be associated with the data owner of the digital twin data structure. In addition to the request, authentication and/or authorization information may be provided by decentral data consuming network node 1 16, for example as described in the context of FIG. 14.
The request may be authenticated, for example as described in the context of FIG. 14. Access to the digital twin data structure may be authorized based on access policy data as described in the context of FIG. 14, FIG. 15A and FIG. 15B. This allows to filter decentral data consuming network nodes requesting
access based on the decentral participant identifier(s) associated with said network nodes and requested actions to be performed on the accessed digital twin data structure. If the request is not authorized, e.g. if decentral data consuming network node 1 16 is not authorized to access the digital twin data structure, the peer-to-peer communication channel will be terminated by decentral data providing network node 1 14 and no digital twin data structure or a part thereof will be provided.
If the request is authorized, decentral data providing network node 1 14 may initiate contract negotiations with decentral data consuming network node 1 16 prior to providing the digital twin data structure or a part thereof. Decentral data providing network node 1 14 may provide an electronic contract to decentral data consuming network node 116. The electronic contract may include one or more authorization rule(s) associated with the decentral digital twin identifier. This allows the data consumer to determine access and usage conditions associated with the desired data. Decentral data providing network node 114 and decentral data consuming network node 116 may be configured to negotiate an electronic contract and to sign the negotiated electronic contract. Use of the electronic contract ensures that the decentral data consuming network node and further systems handling the digital twin data structure or par thereof are complying to at least one policy associated with the digital twin data structure. Upon signature of the electronic contract, the digital twin data structure may be gathered, participant rights may be applied to the gathered data as signified by arrows 1610 and 1614 (see also FIG. 14, FIG. 15A and FIG. 15B). The resulting digital twin data structure resulting from applying participant rights to the gathered digital twin data structure may be provided by decentral data providing network node 1 14 to decentral data consuming network node 116 as signified by arrow 1612.
The digital twin provided by decentral data providing network node 1 14 may be stored in database 1606 associated with the decentral data consuming network node 116 according to the access policy data as signified by arrow 1616.
Through the decentral digital twin identifier, the digital twin data structure can be uniquely associated with the product. Through the decentral network, the digital twin data structure or a part thereof may be transferred between a product producer and a product consumer in a standardized and secure way, allowing the product producer to control access to the digital twin data structure by multiple decentral data consuming network nodes existing within the decentral network. This way, the digital twin data structure can be shared with unique association to the product and without central intermediary directly between the participants of the product ecosystem. This allows for transparency of digital twins within the product ecosystem.
FIG. 17 illustrates a flow chart a computer-implemented method for processing digital twin data of a digital twin of a physical entity of a product in accordance with an example embodiment of the present disclosure. The product may be produced by a production, such as chemical production 204, described in the context of FIG. 2, FIG. 9A and FIG. 9B. The digital twin may be generated as described in the
context of FIG. 9A and FIG. 10. The digital twin may include a digital twin data structure. The digital twin data structure may include a tree structure which comprises a plurality of nodes including a root node and one or more leaf nodes. An example of such a tree structure is illustrated in FIG. 5. The digital twin data structure may include a decentral digital twin identifier and at least one measured physical and/or chemical property of the product and/or at least one physical and/or chemical property determined from collected data associated with the production and/or the use of the product.
In block 1702, access to the digital twin data structure is requested. The access may be requested by a decentral data consuming network node, such as a node associated with chemical product consumer 104 (see also FIG. 1 , FIG. 16). The access may be requested at a decentral data providing network node being associated with the digital twin data structure (see for example FIG. 16). The request may contain the decentral digital twin identifier associated with digital twin and a decentral participant identifier associated with the decentral data consuming network node. The request may include one or more actions requested to be performed on the digital twin data structure.
In response to the request, access to the digital twin data structure may be authorized by the decentral data providing network node, for example as described in the context of FIG. 14, FIG. 15A and FIG. 15B. In case access to the digital twin data structure is authorized, the digital twin data structure or a part thereof may be provided to the decentral data consuming network node in block 1704 (see also FIG. 14 to FIG. 16). Providing may include pushing the digital twin structure or a part thereof to the database associated with the decentral data consuming network node. Providing may include receiving the digital twin structure or a part thereof from the decentral data providing network node.
The digital twin data structure or a part thereof may be processed in block 1706. Processing may include determining further data using the provided digital twin data structure or a part thereof. Processing may include aggregation of provided digital twin data structure or a part thereof. Processing may include use of the provided digital twin data structure or a part thereof to generate control data to control the production of further chemical and/or discrete products from the received product.
The output resulting from the processing may be provided in block 1708. Providing may include providing said data via a communication interface.
FIG. 18 illustrates a computer-implemented method for controlling access to a digital twin data structure of a digital twin of a physical entity of a product by a decentral data consuming network node using a digital access element associated with the product in accordance with an example embodiment of the present disclosure. The product may be produced by a production, such as a chemical production, described in the context of FIG. 2, FIG. 9A and FIG. 9B. The digital twin may be generated as described in the context of FIG. 9A and FIG. 10. The digital twin may include a digital twin data structure. The digital twin data structure may include a tree structure which comprises a plurality of nodes including a root
node and one or more leaf nodes. An example of such a tree structure is illustrated in FIG. 5. The digital twin data structure may include a decentral digital twin identifier and at least one measured physical and/or chemical property of the product and/or at least one physical and/or chemical property determined from collected data associated with the production and/or the use of the product.
In block 1802, a digital access element may be generated. The digital access element may be generated as described in the context of FIG. 9B. The digital access element may include a decentral passport identifier and digital twin location data. The decentral passport identifier may correspond to or be associated with the decentral digital twin identifier, for example as described in the context of FIG. 9B and FIG. 16. The digital access element may correspond to a DID document associated with the decentral passport identifier being a DID.
The generated digital access element may be provided in block 1804. This may include providing the digital access element to a decentral registry, such as decentral registry 914 (see for example FIG. 9B and FIG. 16). This may include encoding the digital access element in a physical identifier attached to the product.
Access to the digital twin data structure may be controlled based on the provided digital access element, the decentral digital twin identifier and a decentral participant identifier of a decentral network participant associated with a decentral data consuming network node requesting access to the digital twin data structure in block 1806. Control of access to the digital twin data structure may be performed as described in the context of FIG. 14 to FIG. 15B.
FIG. 19 illustrates an example of a digital access element including DID owner data, DID document data and decentral identity infrastructure.
The decentral identifier may include a Decentralized Identifier (DID). The decentral identifier-based digital access element may in this case be a DID document 1904 associated with the DID. Besides the DID document 1904 serving as digital access element, FIG. 19 shows a DID owner data element 1802 including decentral identifier-based owner data. Generally, the decentral identifier-based owner data may include the decentral identifier associated with a subject such as chemical product data set(s) and may include one or more authentication mechanism(s). The decentral identifier-based owner data 1802 may include owner data that is electronically owned and controlled by the DID owner. In this context electronically owned may refer to data that is stored in an owner repository or wallet. Such data may be securely stored and/or managed on an organizational server or client device. The decentral identifierbased owner data 1902 may include a DID, a private key and a public key. The DID owner may own and control the DID that represents an identity associated with the DID subject, a private key and public key pair that are associated with the DID. DID may be understood as an identifier and authentication information associated with or uniquely linked to the identifier.
The DID subject may be a raw material, a basic substance, a chemical product, or an end product. The DID subject may be a machine, a system, or a device used for producing the raw material, the basic substance, the chemical product, the intermediate product, or the end product, or a collection of such machine(s), device(s) and/or system(s). The DID owner may be a supply chain participant or a manufacturer such as a chemical manufacturer producing chemicals. The DID owner may be an upstream participant of chemical product producer 102 such as a supplier that supplies raw chemical products or precursors to produce the chemical product. The DID owner may be a downstream participant of the chemical product producer 102 such as a customer that consumes chemical products to produce an intermediate product, the component, the component assembly or the end product. The DID owner may be any participant of the product ecosystem including raw chemical product supplier, intermediate chemical products manufacturer, intermediate part manufacturer, component manufacturer, component assembly manufacturer, end product manufacturer, end product user, EOL collector or recycler.
The DID may be any identifier that is associated with the DID subject and/or the DID owner. Preferably, the identifier is unique to the DID subject and/or DID owner. The identifier may be unique at least within the scope in which the DID is anticipated to be in use. The identifier may be a locally or globally unique identifier for the raw material, the precursor, the basic substance, the chemical product, the intermediate product, the component, the component assembly, the end product, the recycled material or a collection thereof; the machine, the system, or the device used for producing the raw material, the basic substance, the chemical product, the intermediate product, the component, the component assembly, the end product, the recycled material, or the collection of such machine(s), device(s) and/or system(s); the chemical manufacturer producing chemicals, the upstream participant of the chemical manufacturer, the downstream participant of the chemical manufacturer or a collection thereof; any participant of the product ecosystem including raw chemical product supplier, intermediate chemical products manufacturer, intermediate part manufacturer, component manufacturer, component assembly manufacturer, end product manufacturer, end product user, EOL collector, recycler or a collection thereof.
The DID may be any identifier that is associated with the DID subject and the DID owner. Preferably, the DID is unique to the DID subject and/or DID owner. The DID may be unique at least within the scope in which the DID is anticipated to be in use. The DID may be a locally or globally unique identifier for any of the above mentioned possible DID subjects. The DID may also be a Uniform Resource Identifier (URI) such as a Uniform Resource Locator (URL). Moreover, the DID may be an Internationalized Resource Identifier (IRI). The DID may be a Uniform Resource Identifier (URI) such as a Uniform Resource Locator (URL). The DID may be an Internationalized Resource Identifier (IRI). The DID may be a random string of numbers and letters for increased security. In one embodiment, the DID may be a string of 128 letters and numbers e.g. according to the scheme did:method name: method specific-did such as did:example:ebfeb1f712ebc6f1 c276e12ec21 . The DID may be decentralized ID independent of a centralized, third party management system and under the control of the DID owner.
The digital access element as DID document data 1904 may be associated with the DID, i.e. the DID included in the decentral identifier-based owner data 1902. Accordingly, the digital access element may include a reference to the DID, which is associated with the DID subject that is described by the DID document 1904. The DID document 1904 may also include an authentication information such as the public key. The public key may be used by third-party entities that are given permission by the DID owner/subject to access information and data owned by the DID owner/subject. The public key may also be used for verifying that the DID owner, in fact, owns or controls the DID. The DID document may include authentication information, authorization information e.g. to authorize third party entities to read the DID document or some part of the DID document e.g. without giving the third party the right to prove ownership of the DID.
The digital access element 1904 may include one or more representations that digitally link to digital twin data structure included in the digital twin the digital access element is associated with, e.g. by way of service endpoints. A service endpoint may include a network address at which a service operates on behalf of the DID owner. In particular, the service endpoints may refer to services, such as data providing services, of the DID owner that give access to digital twin data. Such services may include services to read or analyze data contained in the digital twin data. Data contained in the digital twin data may include chemical product declaration data, chemical product safety data, certificate of analysis data, emission data, product carbon footprint data, product environmental footprint data, chemical product specification data, product information, technical application data, production data, chemical composition data or combinations thereof.
The digital access element 1904 may include further identifiers, such as digital twin data identifier(s) and a chemical product identifier.
The digital access element 1904 may include various other information such metadata specifying when the digital access element was created, when it was last modified and/or when it expires.
The DID and digital access element 1904 may be associated with a data registry node such as a centralized data service system or a decentralized data service system 1906, e.g. a distributed ledger or blockchain or a decentralized file system. The distributed ledger or blockchain may be used to store a representation of the DID that points to the digital access element 1904. A representation of the DID may be stored on distributed computing nodes of the distributed ledger or blockchain 1906. For example, DID hash may be stored on multiple computing nodes of the distributed ledger and point to the location of the digital access element 1904. In some embodiments, the digital access element 1904 may be stored on the distributed ledger 1906. Each of the computing nodes may store a copy of the distributed ledger 1906. In this way, each DID hash can be stored redundantly, thereby allowing for an increased data safety. DIDs associated with a plurality of different digital access element 1904 may be included in the distributed ledger 1906.
In some embodiments, the digital access element 1904 may be stored on the distributed ledger 1906, i.e. either additionally or alternatively to the associated DID representation being stored on the distributed ledger 1906. In other embodiments, the digital access element 1904 may be stored in a data storage (not illustrated) that is associated with the distributed ledger or blockchain or decentralized file system.
The distributed ledger or blockchain 1906 may be any decentralized, distributed network that includes various computing nodes that are in communication with each other. For example, the distributed ledger 1806may include a first distributed computing node, a second distributed computing node, a third distributed computing node, and any number of additional distributed computing nodes (not shown). The distributed ledger or blockchain 1806 may include known technology stacks like Bitcoin (see e.g. Bitcoin documentation of November 11 , 2022 published https://en.bitcoin.it/wiki/Protocol_documentation), Ethereum (see e.g. Ethereum documentation of August 15, 2022 published on https://ethereum.org/en/developers/docs/), Solana (see e.g. Solana documentation of November 11 , 2022 published on https://spl.solana.com/), Polygon (see e.g. Polygon documentation of November 11 , 2022 published on https://wiki.polygon.technology/) or other implementations with varying degree of data transactions performed on the distributed ledger. The description of the example framework is only for illustrative purposes and shall not be considered limiting.
The present disclosure has been described in conjunction with preferred embodiments and examples as well. However, other variations can be understood and effected by those persons skilled in the art and practicing the claimed invention, from the studies of the drawings, this disclosure and the claims.
Any steps presented herein can be performed in any order. The methods disclosed herein are not limited to a specific order of these steps. It is also not required that the different steps are performed at a certain place or in a certain computing node of a distributed system, i.e. each of the steps may be performed at different computing nodes using different equipment/data processing.
As used herein ..determining" also includes ..initiating or causing to determine", “generating" also includes ..initiating and/or causing to generate" and “providing” also includes “initiating or causing to determine, generate, select, send and/or receive”. "Initiating or causing to perform an action” includes any processing signal that triggers a computing node or device to perform the respective action.
In the claims as well as in the description the word “comprising” does not exclude other elements or steps and the indefinite article “a” or “an” does not exclude a plurality. A single element or other unit may fulfill the functions of several entities or items recited in the claims. The mere fact that certain measures are recited in the mutual different dependent claims does not indicate that a combination of these measures cannot be used in an advantageous implementation. In the claims as well as in the description the word “comprising” or “including” or similar wording does not exclude other elements or steps and shall not be construed limiting to the elements or steps lined out. The indefinite article “a” or “an” does not exclude a
plurality. A single element or other unit may fulfill the functions of several entities or items recited in the claims. The mere fact that certain measures are recited in the mutual different dependent claims does not indicate that a combination of these measures cannot be used in an advantageous implementation or further elements may be included. Providing in the scope of this disclosure may include any interface configured to provide data. This may include an application programming interface, a human-machine interface such as a display and/or a software module interface. Providing may include communication of data or submission of data to the interface, in particular display to a user or use of the data by the receiving entity.
Claims
1. An apparatus for generating access policy data for controlling access to a digital twin of a physical entity of a product produced from one or more input materials, wherein the access to the digital twin by one or more decentral data consuming network node(s) of a decentral network is controlled by a decentral data providing network node associated with the digital twin and wherein the digital twin includes a digital twin data structure comprising a tree structure which comprises a plurality of nodes including a root node and optionally one or more leaf nodes and wherein the digital twin data structure includes a decentral digital twin identifier and at least one measured physical and/or chemical property of the product and/or at least one physical and/or chemical property determined from collected data associated with a production and/or a use of the product, the apparatus comprising: at least one group access data generator configured to generate group access data associated with the digital twin data structure, the group access data identifying access control groups including decentral participant identifier(s) associated with decentral network participants permitted to access at the digital twin data structure, at least one participant access data generator configured to generate participant access data associated with one or more nodes(s) present within the digital twin data structure based on the generated group access data, the participant access data identifying the decentral network participant(s) permitted to access the one or more node(s) and one or more actions allowed to be performed on the one or more node(s) by decentral network participant(s) associated with the decentral participant identifier(s), at least one access policy data generator configured to generate access policy data associated with the digital twin based on the generated group access data and the generated participant access data, the access policy data identifying the group access data and the associated participant access data.
2. The apparatus of claim 1 , wherein the group access data includes a gathering of one or more decentral participant identifier(s) associated with the decentral participant node(s) permitted to access the digital twin data structure.
3. The apparatus of claim 1 or 2, wherein membership in one of the access control groups is indicating that decentral network participant(s) associated with the decentral participant identifier(s) is/are permitted to access the digital twin data structure associated with said access control group.
4. The apparatus of any one of claims 1 to 3, wherein membership in one of the access control groups is independent from the participant access data associated with decentral network partici pant(s) via the associated decentral participant identifier contained in the participant access data.
5. The apparatus method of any one of claims 1 to 4, wherein generating the participant access data includes generating access control list data including at least one access control list entry, the at least one access control list entry including the decentral participant identifier(s) associated with the decentral network partici pant(s) permitted to access at least part of the data points present within the digital twin data structure, the respective node(s) to which access is permitted for said decentral network participant(s), and the one or more action(s) allowed to be performed on the node(s) for which access is permitted.
6. The apparatus of claim 5, wherein an access control list entry is generated for at least part of the nodes present within the digital twin data structure.
7. The apparatus of any one of claims 1 to 6, wherein generating participant access data includes selecting, for one or more node(s), at least one decentral participant identifier permitted to access and interact with one or more of said node(s) from decentral participant identifier(s) included in the generated group access data.
8. The apparatus of any one of claims 1 to 7, wherein the one or more node(s) include emission data, recyclate content data, bio-based content data, provenance data, labour conditions data, data associated with the composition of the chemical product, material safety data, certificate of analysis data, data associated with the production of the product, certificates data associated with the product, regulatory information data associated with the product, data associated with a transport of the product, data associated with the use of the product, measured and/or determined chemical and/or physical properties of the product, or combinations thereof.
9. The apparatus of any one of claims 1 to 8, wherein the one or more actions include read operations, modify operations, update operations, delete operations, create operations, operations involving further processing of the data included in the node(s) by a data processing system associated with the participant of the decentral network or a combination thereof.
10. The apparatus of any one of claims 1 to 9, wherein the one or more actions are associated with a particular location, wherein the location is associated with a jurisdiction and the one or more actions are associated with legal requirements related to a supply of products.
11. The apparatus of any one of claims 1 to 10, wherein the one or more action(s) are associated with obligations of decentral data consuming network node(s) associated with respective decentral participant identifier(s) and/or obligations of decentral network node(s) using the digital twin data structure accessed by data consuming network node(s) associated with respective decentral participant identifier(s).
12. A computer-implemented method for generating access policy data for controlling access to a digital twin of a physical entity of a product produced from one or more input materials, wherein the access to the digital twin by one or more decentral data consuming network node(s) of a decentral network is controlled by a decentral data providing network node associated with the digital twin and wherein the digital twin includes a digital twin data structure comprising a tree structure which comprises a plurality of nodes including a root node and optionally one or more leaf nodes and wherein the digital twin data structure includes a decentral digital twin identifier and at least one measured physical and/or chemical property of the product and/or at least one physical and/or chemical property determined from collected data associated with a production and/or a use of the product, the method comprising the steps of: generating group access data associated with the digital twin data structure, the group access data identifying access control groups including decentral participant identifier(s) associated with decentral network participants permitted to access at the digital twin data structure, generating participant access data associated with one or more node(s) present within the digital twin data structure based on the generated group access data, the participant access data identifying the decentral network participant(s) permitted to access the one or more node(s) and one or more actions allowed to be performed on the one or more node(s) by decentral network participant(s) associated with the decentral participant identifier(s), generating access policy data associated with the digital twin based on the generated group access data and the generated participant access data, the access policy data identifying the group access data and the associated participant access data.
13. A computer-implemented method for controlling access to a digital twin of a physical entity of a product by a decentral data consuming network node associated with a participant of a decentral network, wherein the digital twin includes a digital twin data structure comprising a tree structure which comprises a plurality of nodes including a root node and optionally one or more leaf nodes and wherein the digital twin data structure includes a decentral digital twin identifier and at least one measured physical and/or chemical property of the chemical product and/or at least one physical and/or chemical property determined from collected data associated with a production and/or a use of the product, the method comprising: receiving a request to access the digital twin or a part thereof from a decentral data consuming network node, the request including the decentral digital twin identifier and a decentral participant identifier of a decentral network participant associated with the decentral data consuming network node, determining - based on the decentral digital twin identifier included in the received request - access policy data as generated by the apparatus according to any one of claims 1 to 11 or according to the computer-implemented method according to claim 12,
determining, based on the decentral participant identifier included in the received request and the access policy data, that the decentral network participant is a member of at least one access control group that is permitted to access the digital twin data structure and that the participant is permitted to interact with the digital twin data structure upon accessing the digital twin data structure, and in response, permitting the decentral data consuming network node access to the digital twin data structure according to the access policy data.
14. A computer-implemented method for controlling access to a digital twin of a physical entity of a product by a decentral data consuming network node associated with a participant of a decentral network, wherein the digital twin includes a digital twin data structure comprising a tree structure which comprises a plurality of nodes including a root node and optionally one or more leaf nodes and wherein the digital twin data structure includes a decentral digital twin identifier and at least one measured physical and/or chemical property of the product and/or at least one physical and/or chemical property determined from collected data associated with the production and/or the use of the product, the method comprising: receiving a request to access the digital twin data structure from the decentral data consuming network node, the request including the decentral digital twin identifier and a decentral participant identifier associated with the decentral data consuming node, accessing access policy data for participants of the decentral network associated with the digital twin, the access policy data identifying one or more access control group(s) associated with the digital twin data structure, membership in an access control group indicating that the decentral participant is permitted to access the digital twin data structure, and membership in the access control group being independent from access control data associated with the participant and indicative of how the participant may interact with the digital twin data structure upon accessing the digital twin data structure, determining, based on the decentral participant identifier included in the received request and the access policy data, that the participant is a member of at least one access control group that is permitted to access the digital twin data structure, and in response permitting the decentral data consuming network node access to the digital twin data structure according to the access policy data.
15. A computer element, such as a computer readable storage medium, a computer program or a computer program product, on which are stored instructions that, when executed, cause a processor of a programmable device to perform operations as claimed in any one of claims 12 to 14.
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP23180351 | 2023-06-20 | ||
| PCT/EP2024/067199 WO2024261111A1 (en) | 2023-06-20 | 2024-06-20 | Systems and methods for controlling access to digital twins of products |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP4732178A1 true EP4732178A1 (en) | 2026-04-29 |
Family
ID=86942753
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP24733227.3A Pending EP4732178A1 (en) | 2023-06-20 | 2024-06-20 | Systems and methods for controlling access to digital twins of products |
Country Status (3)
| Country | Link |
|---|---|
| EP (1) | EP4732178A1 (en) |
| CN (1) | CN121399605A (en) |
| WO (1) | WO2024261111A1 (en) |
Family Cites Families (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US11488176B2 (en) * | 2019-01-31 | 2022-11-01 | Salesforce.Com, Inc. | Systems, methods, and apparatuses for implementing certificates of authenticity of digital twins transacted onto a blockchain using distributed ledger technology (DLT) |
| US20210133670A1 (en) * | 2019-11-05 | 2021-05-06 | Strong Force Vcn Portfolio 2019, Llc | Control tower and enterprise management platform with a machine learning/artificial intelligence managing sensor and the camera feeds into digital twin |
| US11921872B2 (en) * | 2020-12-16 | 2024-03-05 | International Business Machines Corporation | Access control for a data object including data with different access requirements |
-
2024
- 2024-06-20 CN CN202480041157.0A patent/CN121399605A/en active Pending
- 2024-06-20 EP EP24733227.3A patent/EP4732178A1/en active Pending
- 2024-06-20 WO PCT/EP2024/067199 patent/WO2024261111A1/en not_active Ceased
Also Published As
| Publication number | Publication date |
|---|---|
| CN121399605A (en) | 2026-01-23 |
| WO2024261111A1 (en) | 2024-12-26 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP4203378A1 (en) | Apparatus for generating a digital access element associated with a polystyrene composition | |
| US20250240176A1 (en) | Method for verifying a transfer of a material between a material owner and a material recipient in a decentral network | |
| TW201923639A (en) | Systems and methods for managing relationships among digital identities | |
| CN111919417A (en) | System, method and apparatus for implementing super communities and community sidechains for distributed ledger technology with consensus management in a cloud-based computing environment | |
| KR20210090519A (en) | SLA-Based Sharing Economy Service with Smart Contract for Resource Integrity in the Internet of Things | |
| Kiruthika et al. | Fusion of IoT, blockchain and artificial intelligence for developing smart cities | |
| CN118503220A (en) | Block chain-based multi-domain data sharing method and system for Internet of things | |
| Abdulrahman et al. | A Distributed Blockchain-based Access Control for the Internet of Things | |
| WO2025125448A1 (en) | Balancing of environmental attributes in product ecosystems | |
| WO2024213403A1 (en) | Digital twin generation using streaming of chemical product data | |
| WO2024261111A1 (en) | Systems and methods for controlling access to digital twins of products | |
| WO2024213404A1 (en) | Systems and methods for controlling access to a digital twin of a chemical product | |
| JP2026514068A (en) | System and method for controlling access to digital twins of chemical products | |
| EP4695744A1 (en) | Digital twins of chemical products | |
| EP4720947A1 (en) | Configurable digital twins of chemical products | |
| WO2025103999A1 (en) | Generation and processing of data associated with chemical materials in decentral systems | |
| WO2026046787A1 (en) | Methods and systems enabling product data search within decentral networks | |
| Abreu et al. | Decentralized IoT permission management using NFTs: Implementation and evaluation on low-cost blockchains | |
| JP2026514083A (en) | Digital twins of chemical products | |
| US20250045361A1 (en) | Protection of digital assets within the blockchain by approval revocations | |
| WO2025149397A1 (en) | Methods for monitoring production chains | |
| CN121839058A (en) | A blockchain-based secure medical data sharing platform | |
| WO2025068291A1 (en) | Methods and systems enabling secure data lookup in decentral systems | |
| WO2025104007A1 (en) | Generation and processing of data associated with chemical materials in decentral systems | |
| CN113569203A (en) | A data rights protection method and system |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20260120 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC ME MK MT NL NO PL PT RO RS SE SI SK SM TR |