IDM: Building Trustworthy Identity for Inter-Dataspace Collaboration
- Laura Gavrilut
- Jun 12
- 2 min read

In modern dataspaces, trust does not start when data is exchanged. It starts much earlier, with the ability to know who is participating, which organisations are recognised members, and whether a company can prove its identity and role in a secure and verifiable way. As dataspaces become more interconnected, identity management becomes a foundation for collaboration, access control and trustworthy data sharing. This is where the DS2 Identity Manager, or IDM, comes in.
What is IDM?
IDM is a DS2 foundation module that provides a practical framework for creating, managing and validating participant and module identities for inter-dataspace activities. It uses Verifiable Credentials, or VCs, and integrates with technologies such as EDC IdentityHub to support secure and trustworthy identity management across the DS2 ecosystem.
The goal of IDM is to reuse existing identities from different companies while providing robust mechanisms to verify their membership and participation in different dataspaces. Through this approach, organisations can prove who they are, what dataspace they belong to, and which agreements or memberships support their participation.
IDM gives users and organisations the ability to:
Register dataspaces within the DS2 ecosystem
Search for other registered dataspaces
Request and manage collaboration agreements between dataspaces
Register companies as DS2 members
Issue, host and visualise Verifiable Credentials
Verify company membership within specific dataspaces
Support secure inter-dataspace communication through authenticated and authorised participants
Why IDM?
In inter-dataspace environments, data exchange depends on more than technical connectivity. Participants need to know that the organisations they interact with are legitimate, that their membership can be verified, and that digital credentials can be trusted.
Without a shared identity framework, collaboration between dataspaces can become fragmented. Companies may need to repeat registration processes, agreements may be difficult to verify, and trust decisions may rely on manual or inconsistent checks.
IDM addresses this gap by enabling secure identity and credential management across DS2. It supports Verifiable Credential management, a DS2-native credential issuer, wallet visualisation, EDC IdentityHub integration, and a portal for managing dataspaces, agreements and company registrations.are exceeded and clear analytics to support trust, governance and operational decisions.
By doing so, IDM helps establish the trust layer needed for organisations to collaborate across dataspaces with greater confidence, transparency and control.
DS2 Architecture Overview
At the heart of IDM is the IDM Portal, which provides both backend services and user-facing interfaces for managing identities, dataspaces and agreements. The backend manages the business logic for dataspace registration, agreement workflows, company registration, and interactions with the credential issuer and wallet functionalities.
The IDM architecture includes several key components:
IDM Portal, providing interfaces for dataspace registration, collaboration requests, agreement management, policy visualisation and company registration
DS2 Credentials Issuer, which generates cryptographically signed Verifiable Credentials based on dataspace agreements and DS2 membership
Local Credential Hub, allowing companies to view and manage issued credentials
EDC IdentityHub Integration Layer, supporting the storage and retrieval of Verifiable Credentials
Core Identity Logic, which verifies membership and manages the lifecycle of identities and credentials in the DS2 ecosystem
Through these components, IDM provides the identity foundation required for trustworthy collaboration between dataspaces. Once companies are approved and relevant dataspace agreements are in place, the DS2 Credentials Issuer can generate credentials that companies can use to prove their identity and membership in inter-dataspace interactions.



Comments