From Access Control to Usage Control with User-Managed Access
Wout Slabbinck, Wouter Termont, Ruben Dedecker, Beatriz Esteves

TL;DR
This paper presents a new architecture that enhances data governance by integrating usage control policies using W3C ODRL with UMA authorization, enabling flexible, interoperable, and legally compliant data management in decentralized ecosystems.
Contribution
It introduces an UMA-based architecture replacing Solid's native access control with ODRL-enabled policies, bridging gaps between authorization standards and legal, usage-aware data governance.
Findings
Decoupling authorization from storage improves flexibility and interoperability.
Prototype demonstrates compatibility with existing Solid infrastructure.
Operationalizes usage control using Web standards for policy enforcement.
Abstract
Recent data protection and data governance regulations have intensified the demand for interoperable, decentralized data ecosystems that can support not only access control but also legally-aligned governance over data use. Existing Web-based data storage platforms increasingly struggle to meet these regulatory and practical requirements, as their authorization mechanisms rely on tightly coupled, document-centric access control models that lack expressiveness for legal constraints and fail to separate data management from authorization concerns. In parallel, widely adopted authorization standards remain poorly aligned with decentralized, semantically rich usage-control scenarios. To bridge this gap, this work introduces an architecture that replaces Solid's native access control mechanisms with a UMA authorization flow, enabling the enforcement of usage control policies expressed with…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAccess Control and Trust · Distributed systems and fault tolerance · Cloud Data Security Solutions
