Designation of a trusted entity in a data space
Patent Information
- Application Number
- EP2023786581
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-10-14
- Filing Date
- 2023-10-11
- Publication Date
- 2025-08-20
AI Technical Summary
Current data sharing technologies lack transparency and interoperability, failing to ensure a trusted environment for data exchange, which is essential for the European Union's GAIA-X initiative aimed at creating a trusted data space ecosystem.
A method for designating a certification entity within a data space by evaluating candidate entities based on self-description data to verify conformity with predefined criteria, allowing for the registration and cataloging of trusted certification entities for specific services and resources.
This approach ensures the integrity of services within a data space by identifying and designating trusted certification entities, limiting the number of entities required and ensuring compliance with specific criteria, thereby establishing a trusted environment for data sharing.
Smart Images

Figure 1.1
Abstract
Description
DESIGNATION OF A TRUSTED ENTITY IN A DATA SPACE
[0001] This disclosure relates to the field of data spaces. More particularly, this disclosure relates to methods for designating a certification entity of a data space and the associated management entities, data spaces and communications networks.
[0002] It is well known that data is shared within data exchange spaces. However, current data sharing technologies are non-transparent and non-interoperable, thus failing to guarantee a trusted environment.
[0003] In response to this, the European Union has launched an initiative, called "GAIA-X," to design and then create a new generation of target data infrastructures for Europe, its businesses, and its citizens. The target infrastructure, also known as a data space, aims to be the cradle of an ecosystem where data and services based on this data are available, collected, and shared in a trusted environment where digital sovereignty is exercised. In particular, the target infrastructure is supported by a federation of computer networks, also known as clouds, operated by different operators.Certification entities, or "trust anchors" in English, are responsible for verifying compliance, with respect to a predefined compliance scheme, of the deployment of a service by ensuring that the resources of the participants who will support the service are indeed compliant with the pre-established rules and standards and can therefore be certified and registered as such.
[0004] However, not every certification entity is necessarily able to validate a particular resource. Therefore, there is a need, knowing the particular resource, to identify a certification entity able to validate the particular resource of an infrastructure. Summary
[0005] There is thus proposed a method for designating a certification entity of a data space for at least one target criterion associated with a predetermined service on a zone, the method being implemented by a management entity of the data space capable of managing the certification entity of the data space and comprising:receiving self-description data from a candidate for the status of certification entity of the data space for the at least one target criterion associated with the predetermined service on the zone, the candidate being capable of certifying at least one criterion of a service implemented in the zone of the data space;verifying, from the self-description data, whether the candidate is also capable of verifying the conformity of the at least one target criterion associated with the predetermined service on the zone;if suitable, register in a data space-specific registry said candidate as a data space certification entity for the at least one target criterion associated with the service in the area.;
[0006] Advantageously, with this method, a mechanism for searching for, then designating, a certification entity for at least one target criterion can be obtained.
[0007] Knowing that distinct certification entities can be used to certify characteristics of a resource for a given service, it is possible that for the deployment of a service, a plurality of certification entities are required for the different resources contributing to the service. The method makes it possible to limit the number of certification entities to a zone, such as a legal zone of a data space (territory, country, geographical zone) and to determine the certification entities capable of certifying a characteristic (location, network technology, security, etc.) of a resource for a given service. The designation method makes it possible to ensure that the services implemented in a data space, on the basis of resources, are integral thanks to the designation of trusted certification entities in accordance with the designation method.
[0008] The features set out in the following paragraphs may, optionally, be implemented, independently of each other or in combination with each other:
[0009] According to one or more embodiments, the method further comprises: sending a certification entity certificate to the certification entity of the data space for the at least one target criterion associated with the predetermined service on the zone; indexing the certification entity of the data space for the target criterion associated with the predetermined service on the zone in a service catalog of the data space.
[0010] According to one or more embodiments, the candidate for certification entity status is capable of certifying at least one resource, and the self-description data is chosen from a group comprising one element among: a certification of the resource by an authority of the data space, a use of the resource, a location of the resource, or a combination of the elements of the group.
[0011] According to one or more embodiments, the method further comprises: determining the existence or non-existence of at least one data space authority certification entity in a service catalog of the data space for the predetermined service on the area; and when the non-existence of at least one data space authority certification entity is determined for the predetermined service on the area of the data space, the method further comprises: registering in the data space-specific registry the data space certification entity for the at least one target criterion associated with the predetermined service on the area as a data space authority certification entity for the predetermined service on the area, adding the data space authority certification entity in the service catalog of the data space for the predetermined service on the area.
[0012] According to one or more embodiments, when the existence of at least one data space authority certification entity is determined for the predetermined service on the data space area, the method further comprises: sending the information regarding the certification entity candidate to the data space authority certification entity; wherein the determination of the certification entity candidate's compliance is performed by the data space authority certification entity.
[0013] According to one or more embodiments, a certification entity status of the certification entity of the data space for the predetermined service target criterion on the area is stored with a network data analysis function and / or the management entity.
[0014] According to another aspect, a management entity of a data space is proposed, the management entity being able to manage a certification entity of the data space for at least one target criterion associated with a predetermined service on a zone and being configured to:receive self-description data from a candidate for the status of certification entity of the data space for the at least one target criterion associated with the predetermined service on the zone, the candidate being able to certify at least one criterion of a service implemented in the zone of the data space;check, from the self-description data, whether the candidate is also able to check the conformity of the at least one target criterion associated with the predetermined service on the zone;if suitable, record in a register specific to the data space said candidate as a certification entity of the data space for the at least one target criterion associated with the service on the zone.
[0015] According to another aspect, there is provided a data space of a communications network, the data space comprising a data space management entity according to the present disclosure and a service catalog for the service on the area, wherein the management entity is configured to:send a certification entity certificate to the data space certification entity for the at least one target criterion associated with the service on the area;index the data space certification entity for the target criterion associated with the predetermined service on the area in the data space service catalog.
[0016] According to one or more embodiments, the data space comprises a management entity according to the present disclosure and a service catalog for the predetermined service on the area, wherein the management entity is configured to:determine the existence or non-existence of at least one authority certification entity of the data space in the service catalog;wherein when the non-existence of at least one data space authority certification entity is determined for the predetermined service on the data space area, the management entity is further configured to:register in the data space-specific registry the data space certification entity for the at least one target criterion associated with the predetermined service on the area as a data space authority certification entity for the predetermined service on the area,add the data space authority certification entity to the service catalog.;
[0017] According to one or more embodiments, the data space comprises a management entity according to the present disclosure. The management entity assigns an authority certification entity status to certain candidate third-party entities. The authority certification entity status (of the data space for the at least one target criterion associated with the predetermined service on the area) is then stored with a network data analysis function and / or the management entity.
[0018] According to another aspect, there is provided a communications network comprising a data space according to the present disclosure, wherein when the existence of at least one data space authority certification entity is determined for service on the data space area, the management entity is further configured to:send the information regarding the certification entity candidate to the data space authority certification entity;and the determination of the candidate's compliance with the certification entity status is performed by the data space authority certification entity.
[0019] According to another aspect, there is provided a computer program comprising instructions for implementing all or part of a method as defined herein when this program is executed by a processor. According to another aspect, there is provided a non-transitory, computer-readable recording medium on which such a program is recorded.
[0020] Other features, details and advantages will become apparent upon reading the detailed description below, and upon analyzing the attached drawings, in which: Fig. 1
[0021] shows an example architecture of network functions designated as certification entities according to one embodiment. Fig. 2
[0022] shows an example method of designating a certification entity according to one embodiment. Fig. 3
[0023] shows an example of verifying the ability of a candidate to verify compliance with at least one target criterion associated with a predetermined service over an area according to one embodiment. Fig. 4
[0024] shows an example of deploying a service to an area of the data space according to one embodiment.
[0025] In the various figures, the same references designate identical or similar elements.
[0026] Lamontre shows an example of network function architecture, referenced TA, designated as certification entities of the data space referenced DS Y.
[0027] According to one or more embodiments, the DS Y data space is associated with a field of activity. The field of activity is, according to certain non-limiting examples, relating to telecommunications, finance, health, agriculture services.
[0028] The governance, referenced DS Y GOV, of the DS Y data space is addressed to the authority in charge of the field of activity in order to obtain a list of reference certifiers. According to one or more embodiments, the authorities differ according to the characteristics of the DS Y data space. For example, the authorities differ according to the field of activity of the DS Y data space and / or according to its geographical footprint. According to a non-limiting example, the National Agency for the Security of Information Systems (ANSSI) can be chosen as the authority in charge of the telecommunications field of activity for the geographical area corresponding to France.
[0029] In a step S10, the governance DS Y GOV of the data space DS Y defines parameters necessary for the certification of resources, referenced R, R1, R2, R3, of one or more participants, referenced P, to the data space DS Y. The participants P are providers of the resources R, R1, R2, R3. The resources R, R1, R2, R3 can for example be data, network links, software, or "software" in English, clouds, or "cloud" in English. The resources can also correspond to management functions of a network or a service.
[0030] The parameters necessary for the certification of resources R, R1, R2, R3 are compiled in a certified catalog function, referenced DS Y SERV CAT.
[0031] In order to guarantee the compliance of the resources R, R1, R2, R3, with the compliance schemes of the DS data space Y, the DS data space Y relies on certification entities TA. The certification entities TA can be provided by the participants P during a step S11. The certification entities TA are for example control equipment, for example located at the periphery, or "edge" in English, of the DS data space Y. The control equipment are for example orchestrators.
[0032] The TA certification entities are able to verify at least one criterion of a service implemented in the DS Y data space. In particular, the TA certification entities can act as certifiers to verify compliance and then sign parameters of a parameterization scheme, or "self-signed description, SSD" in English, of the resources R, R1, R2, R3. In addition, the TA certification entities can act as certifiers to verify and sign an identity and / or resources R, R1, R2, R3.
[0033] In a step S12, one or more participants P, or even each of the participants P, receives one or more addresses of certification entities TA capable of certifying at least one criterion of a service implemented in the data space DS Y.
[0034] The resources, R1, R2, R3 submit their parameters of the parameterization scheme to one or more, or even each, of the TA certification entities whose addresses were received in step S12. Each TA certification entity can verify and then certify only some or all of the parameters of the parameterization scheme. Thus, depending on the parameters and the TA certification entities, a single TA certification entity or several complementary TA certification entities may be necessary for the certification of a resource. Indeed, a TA certification entity may be specialized and certify one or more parameters of the parameterization scheme. For example, a TA certification entity may verify parameters relating to the identification of a resource, or parameters relating to compatibility with a telecommunications standard, or parameters related to a value-added service.
[0035] When a resource is certified by a certification entity TA, for example the resource R2 on the, the parameters of the parameterization schema are presented during a step S13 to the conformity service, referenced DS Y CONF SERV, of the data space Y. Furthermore, in a step S14, the certified resource is registered in the service registry, referenced DS Y REG, of the data space DS Y. The certified resource R2 can then be used by the participants P to support the services of the data space DS Y.
[0036] Lamontre an example of a method for designating a TA certification entity of the DS Y data space for at least one target criterion associated with a predetermined service, referenced service_i on the, on a zone.
[0037] The zone can be defined as a geographical territory over which DS Y GOV governance has legal authority and / or a recognized reputation. It can be a particular geographical area of the data space, such as a country or an area spanning several countries. It can also be an area delimited according to legal responsibility when the data space spans several jurisdictions. It can also be an area delimited by a technology, for example in the context of a multi-technology or multi-domain data space, for example in the case of a multi-AS (Autonomous Systems) data space. For example, the zone corresponds to the DS Y data space. A zone can correspond to a cooperation agreement and / or a recognized reputation, can be subject to a set of rules of a domain or a legal authority.For example, a consortium of partners – for example, health sector players and / or industrial players – who wish to exchange data agree on the conditions for exchanging this data while respecting the business law applicable to their sector, for example, via a cooperation contract specific to the area, and technically implement the DS Y data space to do so. In some cases, a label is implemented to depend only on the legal influence in force in the area, for example, European legislation, and not on extraterritorial influence, for example, American legislation specific to another area of the data space.
[0038] In a first step, referenced CANDIDATE_DATA_RECEIVE S20, self-description data of a candidate (or candidate certification entity) for the status of certification entity of the DS Y data space for the at least one target criterion associated with the predetermined service service_i on the area are received. The candidate is able to certify at least one criterion of any service implemented in the area of the DS Y data space.
[0039] In a second step, referenced CANDIDATE_CONFORM_CHECK S21, it is checked, from the self-description data, whether the candidate is also able to verify the conformity of at least one target criterion associated with the predetermined service service_i in the area.
[0040] In a third step, referenced CANDIDATE_AS_TA S22, when the candidate is deemed suitable in step S21, the candidate is registered in the DS Y REG register as a certification entity of the DS Y data space for the at least one target criterion associated with the service service_i on the area.
[0041] Shows an example of verification of the candidate's ability to verify compliance with at least one target criterion associated with the predetermined service service_i in the area.
[0042] The verification of the candidate's ability to verify the conformity of at least one target criterion associated with the predetermined service service_i on the zone can be implemented by a management entity, referenced DS Y GEST ENTITY on the.
[0043] The management entity may, for example, be an operation support system, or "Operation Support System (OSS) in English, an activity support system, or "Business Support System (BSS) in English, or even an authority certification entity, referenced TA_ROOT on the, of the data space.
[0044] In a step S30, one or more authority certification entities of the data space TA_ROOT can be identified from the service catalog DS Y CAT SERV of the data space DS Y for the predetermined service service_i on the zone. Additionally, the participants P of the domain can be identified from the service catalog DS Y CAT SERV.
[0045] In a step S31, the existence or non-existence of at least one authority certification entity of the TA_ROOT data space can be determined from the identification of step S30. An authority certification entity is an entity for example designated by a control entity of the data space, this entity being able to certify at least one parameter of a service_i and being further able to delegate the certification of a resource to a certification entity designated for one or more parameters. In particular, when no authority certification entity of the TA_ROOT data space is identified in step S30, the non-existence of at least one authority certification entity of the TA_ROOT data space can be confirmed.Conversely, when at least one authority certification entity of the TA_ROOT data space is identified in step S30, the existence of at least one authority certification entity of the TA_ROOT data space can be confirmed.
[0046] When the non-existence of at least one authority certification entity of the TA_ROOT data space is determined in step S31 (arrow "NOK" at the output of step S31), a certification of the candidate can be evaluated in a step S321. The evaluated certification can be a certification by an authority of the DS Y data space.
[0047] When the candidate is not certified by the authority (arrow "NOK" at the output of step S321), the candidate is judged as non-compliant with the DS Y data space in a step S34. In this case, the candidate is then not designated as the TA certification entity of the DS Y data space for the target criterion associated with the predetermined service service_i on the zone.
[0048] When the candidate is certified by the authority (“OK” arrow at the output of step S321), self-description data of the candidate is sent to the DS Y GOV governance of the DS Y data space.
[0049] Alternatively, when the existence of at least one authority certification entity of the TA_ROOT data space is identified in step S31 (arrow “OK” at the output of step S31), self-description data of the candidate are sent to the at least one authority certification entity of the TA_ROOT data space of the DS Y data space. In addition, the self-description data of the candidate can be sent to the participants P identified during step S30 on the zone.
[0050] The applicant's self-description data may include one or more elements selected from a group including one of: a certification of the resource by a data space authority, a use of the resource, a location of the resource, or a combination of the elements in the group.
[0051] The implementation of steps S33, S330, S331, S332 aims to verify, from the self-description data, whether the candidate is indeed capable of verifying the conformity of the at least one target criterion associated with the predetermined service service_i in the area. Step S33 can be implemented individually or in combination with one or more of steps S330, S331, S332.
[0052] Step S33 aims to verify whether the candidate's parameters are compliant with the DS Y data space. According to one or more embodiments, the candidate is judged to be compliant with the DS Y data space only if each of the parameters is compliant (“OK” arrow at the output of step S33).
[0053] According to one or more embodiments, during step S330, the conformity of the candidate's use may be evaluated. The candidate's use may, for example, correspond to the candidate's intended use for public or private use. According to a non-limiting example, the candidate's use may correspond to use by a company.
[0054] According to one or more embodiments, during step S331, the location of the candidate may be evaluated. According to one or more embodiments, the evaluation of the location of the candidate may depend on the use. According to a non-limiting example, the location of the candidate may be deemed compliant if the candidate is located within the European Union.
[0055] According to one or more embodiments, in step S332, a certification of the network and / or the security of the candidate by a data space authority may be evaluated. The evaluation of the certification of the network and / or the security of the candidate may comprise one or more elements in a group comprising one of: an ANSSI certification, a standard of the European Telecommunications Standards Institute, or "European Telecommunication Standards Institute" (ETSI) in English, a standard of the International Organization for Standardization, or "International Organization for Standardization" (ISO), or a combination of the elements of the group.
[0056] When the candidate's parameters are not deemed compliant in step S33 (arrow "NOK" at the output of step S33), the candidate is deemed non-compliant with the DS Y data space in a step S34. In this case, the candidate is then not designated as a TA certification entity of the DS Y data space for the target criterion associated with the predetermined service service_i on the zone.
[0057] Alternatively, when the candidate's parameters are deemed compliant in step S33 (arrow "OK" at the output of step S33), the candidate is then designated as TA certification entity of the DS Y data space for the target criterion associated with the predetermined service service_i on the zone in a step S35. The candidate, now designated as TA certification entity of the DS Y data space for the target criterion associated with the predetermined service service_i on the zone, receives a certification entity certificate. In addition, the TA certification entity designated for the target criterion associated with the predetermined service service_i on the zone is indexed in the DS Y SERV CAT service catalog of the DS Y data space. Additionally, the newly designated TA certification entity for the target criterion associated with the predetermined service service_i on the zone is added to the DS Y REG service registry of the DS Y data space.
[0058] In a step S36, the presence of other TA certification entities (other than the newly designated one) on the domain can be evaluated. When the TA certification entity designated for the target criterion associated with the predetermined service service_i on the zone is the only TA certification entity on the domain (arrow "OK" at the output of step S36), the TA certification entity designated for the target criterion associated with the predetermined service service_i on the zone can be updated in the service register DS Y REG of the data space DS Y as the authority certification entity TA_ROOT of the data space for the predetermined service service_i on the zone (step S37).
[0059] Shows an example of deploying the predetermined service service_i on the DS Y data space area.
[0060] In a step S40, the provider of service_i requests support for service_i by the DS Y data space with criteria on the area. The criteria are for example criteria of the type fault, configuration, accounting, performance, security, or "Fault, Configuration, Accounting, Performane, Security, FCAPS" in English.
[0061] In a step S41, the management entity DS Y GEST ENTITY asks the service catalog function DS Y SERV CAT whether there are candidates capable of certifying at least one criterion of a service implemented in the area of the data space DS Y. The candidates may comprise one or more network functions, referenced NF. The network functions NF may validate different criteria, such as for example identity and location.
[0062] In addition, the management entity DS Y GEST ENTITY asks the participants P if they have resources, referenced R_j, to support the service_i.
[0063] In a step S42, the catalog service function DS Y SERV CAT responds to the management entity DS Y GEST ENTITY.
[0064] According to one or more embodiments, the response of the DS Y GEST ENTITY management entity includes an identity of a manager of a candidate. In some cases, the manager is a participant P of the DS Y data space. According to one or more embodiments, the response of the DS Y GEST ENTITY management entity may include a certificate and an address of a network function NF of a candidate.
[0065] In a step S43, the management entity DS Y GEST ENTITY evaluates the ability of the network function NF to verify the conformity of at least one target criterion associated with the predetermined service service_i on the zone. This evaluation can in particular be done as described with reference to the.
[0066] If the candidate's network function NF is suitable in step S43, the candidate is designated as the TA certification entity of the DS Y data space for the at least one target criterion associated with the predetermined service service_i in the area. All or part of the steps described below can then be implemented.
[0067] In a step S44, the designated certification entity TA receives a certification entity certificate.
[0068] In a step S45, the management entity DS Y GEST ENTITY indexes the designated certification entity TA in the service catalog DS Y SERV CAT of the data space DS Y.
[0069] In a step S46, the management entity DS Y GEST ENTITY registers the designated TA certification entity in the DS Y REG register specific to the DS Y data space as a TA certification entity of the DS Y data space for the at least one target criterion associated with the service service_i on the zone.
[0070] In a step S47, the certification entity certificate is announced to the data space DS Y. According to one or more embodiments, the certification entity certificate is announced to the data space DS Y by a protocol called “Border Gateway Protocol, BGP”. The certification entity certificate may in particular be announced via trusted network links. In particular, according to a non-limiting example, the trusted network links may be of the secure communication protocol type in an industrial data space, or “Industrial Data space communication Secure Protocol, IDSP” in English, within the framework of a data space as defined in GAIA-X.
[0071] Furthermore, according to one or more embodiments, a certification entity status of the certification entity TA of the DS Y data space for the at least one target criterion associated with the predetermined service service_i on the area is stored with a network data analysis function or "Network Data Analytics Function" (NWDAF) and / or the DS Y GEST ENTITY management entity. By "stored with" is meant here that the information is stored in a manner accessible to said entities.
[0072] The network data analysis function makes it possible in particular to collect data relating to a user, to the NF network function, or to a maintenance and management function. According to one or more embodiments, the data is transmitted between the 2 actors, the participant, for example operating the 5G functions (NF, NWDAF), and the DS Y operator (OSS / BSS), via a network exposure function, "Network Exposition Function" (NEF) in English.
[0073] In a step S48, the resource or a manager of the resource R_j of the participant P requests the service catalog function DS Y SERV CAT to validate the resource R_j. The resource R_j is for example a connector (link, equipment, network function, etc.).
[0074] In a step S49, the service catalog function DS Y SERV CAT provides the address(es) of the designated TA certification entity(ies) in order to validate the resource R_j in the zone Z for the data space DS Y. Each designated TA certification entity comprises one or more network functions NF which can validate different but complementary criteria required for a service_i, such as the identity, location, use, certifications of the resource. In particular, the data space DS Y provides the addresses of the designated TA certification entities for the service service_i.
[0075] In a step S50, the resource R_j presents its parameterization scheme to the network function NF for validation request by the certification entity TA. In the example of the, the certification entity TA is for example an orchestrator, possibly located at the edge of the data space.
[0076] In a step S51, the parameterization scheme is signed with the certification entity certificate of the network function NF and its private key. Optionally, the parameterization scheme is hashed and / or timestamped.
[0077] In a step S52, the signed parameterization scheme is presented to the DS Y CONF SERV conformity service of the DS Y SERV CAT service catalog.
[0078] In a step S53, the parameterization schema is signed by the conformity service DS Y CONF SERV and is registered for the data space DS Y in the service catalog DS Y SERV CAT.
[0079] In a step S54, the resource R_j is recorded by the data space DS Y.
[0080] In a step S55, the management entity DS Y GEST ENTITY transmits the response to the service provider service_i: service_i is supported by the data space DS Y on the zone Z.
[0081] Thus, the methods described above make it possible to efficiently identify a TA certification entity of the DS Y data space for at least one target criterion associated with the predetermined service service_i on the area. Furthermore, for the same target criterion associated with another service, the TA certification entity can be preselected as a candidate to further increase the efficiency of identifying TA certification entities in the DS Y data space.
Claims
Method for designating a certification entity of a data space (DS Y) for at least one target criterion associated with a predetermined service (service_i) on a zone, the method being implemented by a management entity of the data space (DS Y) capable of managing the certification entity of the data space (DS Y) and comprising:receiving self-description data from a candidate for the status of certification entity of the data space (DS Y) for the at least one target criterion associated with the predetermined service (service_i) on the zone, the candidate being capable of certifying at least one criterion of a service implemented in the zone of the data space (DS Y);verifying, from the self-description data, whether the candidate is also capable of verifying the conformity of the at least one target criterion associated with the predetermined service (service_i) on the zone;in case of suitability, register in a data space-specific registry (DS Y) said candidate as a data space certification entity (DS Y) for the at least one target criterion associated with the service (service_i) on the area.; The method of claim 1 further comprising:sending a certification entity certificate to the data space certification entity (DS Y) for the at least one target criterion associated with the predetermined service (service_i) on the zone;indexing the data space certification entity (DS Y) for the target criterion associated with the predetermined service (service_i) on the zone in a data space service catalog (DS Y). Method according to one of claims 1 and 2, in which the candidate for certification entity status is capable of certifying at least one resource, and in which the self-description data is chosen from a group comprising one element from: a certification of the resource by an authority of the data space, a use of the resource, a location of the resource, or a combination of the elements of the group. Method according to one of claims 1 to 3, the method further comprising:determining the existence or non-existence of at least one data space authority certification entity (TA_ROOT) in a data space service catalog (DS Y) for the predetermined service (service_i) on the zone;wherein, when the non-existence of at least one data space authority certification entity (TA_ROOT) is determined for the predetermined service (service_i) on the data space area (DS Y), the method further comprises:recording in the data space specific registry (DS Y) the data space certification entity (DS Y) for the at least one target criterion associated with the predetermined service (service_i) on the area as a data space authority certification entity (TA_ROOT) for the predetermined service (service_i) on the area,adding the data space authority certification entity (TA_ROOT) in the data space service catalog (DS Y) for the predetermined service (service_i) on the area.; The method of claim 4, wherein when the existence of at least one data space authority certification entity (TA root) is determined for the predetermined service (service_i) on the data space area (DS Y), the method further comprises: sending the information regarding the certification entity candidate to the data space authority certification entity (TA_ROOT); wherein the determination of the certification entity candidate's compliance is performed by the data space authority certification entity (TA_ROOT). Method according to one of claims 1 to 5, wherein a certification entity status of the data space certification entity (DS Y) for the at least one target criterion associated with the predetermined service (service_i) on the area is stored with a network data analysis function and / or the management entity. Data space management entity (DS Y), the management entity being able to manage a data space certification entity (DS Y) for at least one target criterion associated with a predetermined service (service_i) on a zone and being configured to:receive self-description data from a candidate for the status of data space certification entity (DS Y) for the at least one target criterion associated with the predetermined service (service_i) on the zone, the candidate being able to certify at least one criterion of a service implemented in the zone of the data space (DS Y);check, from the self-description data, whether the candidate is also able to check the conformity of the at least one target criterion associated with the predetermined service (service_i) on the zone;in case of suitability, register in a data space-specific registry (DS Y) said candidate as a data space certification entity (DS Y) for the at least one target criterion associated with the service (service_i) on the area.; Data space (DS Y) of a communications network, the data space (DS Y) comprising a data space management entity (DS Y) according to claim 7 and a service catalog for the service (service_i) on the area, wherein the management entity is configured to:send a certification entity certificate to the data space certification entity (DS Y) for the at least one target criterion associated with the service (service_i) on the area;index the data space certification entity (DS Y) for the target criterion associated with the predetermined service (service_i) on the area in the data space service catalog (DS Y). A data space (DS Y) of a communications network, the data space (DS Y) comprising a management entity according to claim 7 and a service catalog for the predetermined service (service_i) on the area, wherein the management entity is configured to:determine the existence or non-existence of at least one data space authority certification entity (TA root) in the service catalog;wherein when the non-existence of at least one data space authority certification entity (TA root) is determined for the predetermined service (service_i) on the data space zone (DS Y), the management entity is further configured to:register in the data space specific registry (DS Y) the data space certification entity (DS Y) for the at least one target criterion associated with the predetermined service (service_i) on the zone as a data space authority certification entity (TA root) for the predetermined service (service_i) on the zone,add the data space authority certification entity (TA root) in the service catalog.; Data space (DS Y) of a communications network, the data space (DS Y) comprising a management entity according to claim 7, wherein a certification entity status of the certification entity of the data space (DS Y) for the at least one target criterion associated with the predetermined service (service_i) on the area is stored with a network data analysis function and / or the management entity. A communications network comprising a data space (DS Y) according to claim 9, wherein when the existence of at least one data space authority certification entity (TA_ROOT) is determined for the service (service_i) on the data space area (DS Y), the management entity is further configured to:send the information regarding the certification entity candidate to the data space authority certification entity (TA_ROOT);wherein the determination of the candidate's compliance with the certification entity status is performed by the data space authority certification entity (TA_ROOT). Computer program comprising instructions for implementing the method according to one of claims 1 to 6 when this program is executed by a processor. Non-transitory recording medium readable by a computer on which is recorded a program for implementing the method according to one of claims 1 to 6 when this program is executed by a processor.