Chemical Product Passport
Patent Information
- Application Number
- JP2024537549
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-12-05
- Filing Date
- 2022-12-19
- Publication Date
- 2025-12-26
AI Technical Summary
Existing chemical product data management systems, such as the International Chemical Data System (IMDS), are static and centralized, leading to difficulties in data sharing and replacement, which are cumbersome and prone to errors.
A system and method for generating a chemical product passport using non-centralized identifiers to collect and manage recycling and biobase content data, allowing for decentralized data management and secure, customizable data sharing and replacement.
Enables efficient, reliable, and flexible data sharing and replacement across the chemical supply chain, maintaining data ownership and security while simplifying data handling and compliance with regulatory requirements.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical field]
[0001] Technical Field The present disclosure relates to an apparatus for generating a chemical product passport, a computer-implemented method for generating a product passport, respective computer program elements, methods for using a chemical product passport, chemical products associated with such a chemical product passport, a chemical product passport including one or more decentralized identifiers and data related to chemical data, and a method for producing a chemical product associated with such a chemical product passport. [Background technology]
[0002] Technology background The supply of chemical products has to meet many regulatory requirements that vary depending on the chemical product. For example, in the automotive supply chain, chemical companies provide standardized information using the International Chemical Product Data System (IMDS). Such a system makes it possible to collect data along the entire automotive supply chain. Parties in the automotive supply chain register with the IMDS service and maintain product entries in a centralized database provided and hosted by a third-party provider. Summary of the Invention [Problem to be solved by the invention]
[0003] Systems like IMDS are static in terms of data, prone to errors, and cumbersome to handle or maintain. Due to the highly specific and centralized setup of such systems, exchanging and sharing chemical data is a daunting task. Hence, there is a need to simplify the exchange and sharing of chemical data. [Means for solving the problem]
[0004] Summary of the Invention In one aspect, an apparatus for generating a chemical product associated with a chemical product passport is disclosed, the apparatus comprising: a collector configured to collect recyclate content data and / or biobased content data associated with a chemical product, the chemical product comprising a physical identifier; an assigner configured to assign physical identifiers to decentralized identifiers to generate chemical product passports associated with the produced chemical products; a chemical product passport generator configured to generate a chemical product passport by receiving a request to provide at least a decentralized identifier associated with at least the recyclable content data and / or the biobased content data of the chemical product, and in response to the request, generating a chemical product passport including the decentralized identifier and data related to the recyclable content data and / or the biobased content data of the chemical product; Equipped with.
[0005] In another aspect, an apparatus for generating a chemical product passport is disclosed, the apparatus comprising one or more computing nodes, the apparatus being configured to, when executed by the one or more computing nodes, perform the following steps: receiving a request to provide a decentralized identifier associated with the recyclate content data and / or the biobased content data; generating, in response to the request, a chemical product passport including the decentralized identifier and data related to the recyclate content data and / or the biobased content data; one or more computer-readable media having computer-executable instructions configured to cause Equipped with.
[0006] In another aspect, a computer implemented method for generating a chemical product passport is disclosed, the method comprising: receiving a request to provide recyclate content data and / or biobased content data and preferably a decentralized identifier associated with the data owner; generating, in response to the request, a chemical product passport that includes a decentralized identifier and data related to the recyclate content data and / or the biobased content data; providing a chemical product passport for access by a data consuming service, preferably under the control of a data providing service associated with the data owner; Includes.
[0007] In a further aspect of the present disclosure, an apparatus for generating a chemical product passport is disclosed, the apparatus comprising: at least one receiving unit configured to receive a request to provide a decentralized identifier associated with recyclable content data and / or biobased content data of a chemical product; at least one generating unit configured to generate, in response to a request, a chemical product passport comprising a decentralized identifier and data related to recyclable content data and / or biobased content data of the chemical product; Equipped with.
[0008] A further aspect of the present disclosure relates to a method of producing or providing a chemical product associated with a chemical product passport, the method comprising: Producing a chemical product that is linked to or includes a physical identifier; assigning physical identifiers to decentralized identifiers to generate chemical product passports associated with the produced chemical products; generating a chemical product passport according to a computer-implemented method for generating a chemical product passport or by a system or device for generating a chemical product passport; Includes.
[0009] A further aspect of the present disclosure relates to a system for producing or providing a chemical product associated with a chemical product passport, the system comprising: a production line configured to produce a chemical product that is associated with or includes a physical identifier; an assigner configured to assign physical identifiers to decentralized identifiers to generate chemical product passports associated with the produced chemical products; a chemical product passport generator configured to generate a chemical product passport by receiving a request to provide a decentralized identifier associated with the recyclate content data and / or the biobased content data, and in response to the request, generating a chemical product passport that includes the decentralized identifier and data related to the chemical product; Equipped with.
[0010] A further aspect of the present disclosure relates to a computer implemented method of producing or providing a chemical product associated with a chemical product passport, the method comprising: Requiring provision of a decentralized identifier based on a physical identifier of the chemical product; and assigning the decentralized identifier to the physical identifier. Including, In response to the request, a chemical product passport is generated according to a computer-implemented method for generating chemical product passports or by a system or device for generating chemical product passports, the chemical product passport including the decentralized identifier and data related to the chemical product produced.
[0011] A further aspect of the present disclosure relates to an apparatus for producing or providing a chemical product associated with a chemical product passport, the apparatus comprising: and one or more computing nodes, and when executed by the one or more computing nodes, the apparatus includes the steps of: requesting a decentralized identifier based on a physical identifier of the chemical product; and assigning the decentralized identifier to the physical identifier; generating, in response to the request, a chemical product passport including a decentralized identifier and data related to the produced chemical product, the chemical product passport being generated by: receiving a request to provide a decentralized identifier associated with recyclable content data and / or biobased content data of the chemical product; and generating, in response to the request, a chemical product passport including the decentralized identifier and data related to the recyclable content data and / or biobased content data. one or more computer-readable media having computer-executable instructions configured to cause Equipped with.
[0012] A further aspect of the present disclosure relates to an apparatus for producing or providing a chemical product associated with a chemical product passport, the apparatus comprising: a requester configured to request provision of a decentralized identifier based on a physical identifier of the chemical product; an assigner configured to assign a decentralized identifier to a physical identifier; a chemical product passport generator configured to generate, in response to a request, a chemical product passport including a decentralized identifier and data related to the produced chemical product, the chemical product passport being generated by: receiving a request to provide a decentralized identifier associated with recyclable content data and / or biobased content data of the chemical product; and, in response to the request, generating a chemical product passport including the decentralized identifier and data related to the recyclable content data and / or biobased content data of the chemical product; Equipped with.
[0013] In a further aspect, an apparatus for producing or providing a chemical product associated with a chemical product passport is disclosed, the apparatus comprising: a collector configured to collect recyclate content data and / or biobased content data associated with a chemical product or a production of the chemical product, the chemical product being linked to or comprising a physical identifier; an assigner configured to assign physical identifiers to decentralized identifiers to generate chemical product passports associated with the produced chemical products; a chemical product passport generator configured to generate a chemical product passport by receiving a request to provide a decentralized identifier associated with the recyclable content data and / or biobased content data of the chemical product, and in response to the request, generating a chemical product passport that includes the decentralized identifier and data related to the recyclable content data and / or biobased content data of the chemical product; Equipped with.
[0014] In a further aspect, a computer implemented method for producing or providing a chemical product associated with a chemical product passport is disclosed, the method comprising: collecting recyclable content data and / or biobased content data associated with a chemical product or associated with the production of the chemical product, the chemical product being linked to or comprising a physical identifier; assigning physical identifiers to decentralized identifiers to generate chemical product passports associated with the produced chemical products; generating a chemical product passport, the chemical product passport comprising: receiving a request to provide a decentralized identifier associated with the recyclable content data and / or biobased content data of the chemical product; and in response to the request, generating a chemical product passport comprising the decentralized identifier and data related to the recyclable content data and / or biobased content data of the chemical product; Includes.
[0015] In a further aspect, a system for producing or providing a chemical product associated with a chemical product passport is disclosed, the system comprising: a production line configured to produce a chemical product that is associated with or includes a physical identifier; a collector configured to collect recyclate content data and / or biobased content data associated with production of a chemical product, the chemical product being linked to or comprising a physical identifier; an assigner configured to assign physical identifiers to decentralized identifiers to generate chemical product passports associated with the produced chemical products; a chemical product passport generator configured to generate a chemical product passport by receiving a request to provide a decentralized identifier associated with the recyclable content data and / or biobased content data of the chemical product, and in response to the request, generating a chemical product passport that includes the decentralized identifier and data related to the recyclable content data and / or biobased content data of the chemical product; Equipped with.
[0016] In yet another aspect, a computer implemented method is disclosed which preferably uses a chemical product passport for further processing of a chemical product associated with the chemical product passport, the method comprising the steps of: receiving a request to access recyclate content data and / or biobased content data associated with a decentralized identifier of a chemical product passport generated according to the methods disclosed herein or by the apparatus disclosed herein; Optionally, authenticating and / or authorizing requests to access the recyclate content data and / or the biobased content data; - optionally based on authentication and / or authorization, providing access to the recyclate content data and / or biobased content data associated with the decentralized identifier of the chemical passport; Includes.
[0017] In a further aspect, a system for producing or providing a chemical product associated with a chemical product passport is disclosed, the system comprising: a production line configured to produce a chemical product that is associated with or includes a physical identifier; a collector configured to collect recyclate content data and / or biobased content data associated with a chemical product or a production of the chemical product, the chemical product being linked to or comprising a physical identifier; an assigner configured to assign physical identifiers to decentralized identifiers to generate chemical product passports associated with the produced chemical products; a chemical product passport generator configured to generate a chemical product passport by receiving a request to provide a decentralized identifier associated with the recyclable content data and / or biobased content data of the chemical product, and in response to the request, generating a chemical product passport that includes the decentralized identifier and data related to the recyclable content data and / or biobased content data of the chemical product; Equipped with.
[0018] In a further aspect, a method of producing or providing a chemical product associated with a chemical product passport is disclosed, the method comprising: Producing a chemical product that is linked to or includes a physical identifier; collecting recyclable content data and / or biobased content data associated with a chemical product or associated with the production of the chemical product, the chemical product being linked to or comprising a physical identifier; assigning physical identifiers to decentralized identifiers to generate a chemical product passport associated with the produced chemical product, where generating the chemical product passport includes receiving a request to provide the decentralized identifier associated with at least the recyclable content data and / or the biobased content data of the chemical product, and in response to the request, generating a chemical product passport including the decentralized identifier and data related to the recyclable content data and / or the biobased content data of the chemical product; Includes.
[0019] A further aspect of the present disclosure relates to the use of a chemical product passport generated according to a computer-implemented method for generating a chemical product passport or by a system or apparatus for generating a chemical product passport, for further processing of a chemical product and / or a chemical product associated with the chemical product passport.
[0020] A further aspect of the present disclosure relates to the use of a chemical product passport generated according to a computer-implemented method of producing or providing a chemical product associated with the chemical product passport, or by a system or apparatus of producing or providing a chemical product associated with the chemical product passport, for further processing of chemical products and / or chemical products associated with the chemical product passport.
[0021] A further aspect of the present disclosure relates to a chemical product and / or a chemical product associated with a chemical product passport, wherein the chemical product passport includes one or more decentralized identifiers and data related to recyclate content data and / or biobased content data, and is generated according to a computer-implemented method for generating a chemical product passport or by a system or device for generating a chemical product passport.
[0022] A further aspect of the present disclosure relates to a chemical product and / or a chemical product associated with a chemical product passport, wherein the chemical product passport including one or more decentralized identifiers and data related to recycle content data and / or biobased content data is generated according to a computer-implemented method of producing or providing the chemical product associated with the chemical product passport or by a system or device that produces or provides the chemical product associated with the chemical product passport.
[0023] A further aspect of the present disclosure relates to a chemical product passport comprising one or more decentralized identifiers and data relating to recycle content data and / or biobased content data, wherein the chemical product passport is generated according to a computer-implemented method for generating a chemical product passport or by a system or device for generating a chemical product passport.
[0024] A further aspect of the present disclosure relates to a chemical product passport that includes one or more decentralized identifiers and data related to recycle content data and / or biobased content data, where the chemical product passport is generated according to a computer-implemented method of producing or providing the chemical product associated with the chemical product passport or by a system or device that produces or provides the chemical product associated with the chemical product passport.
[0025] A further aspect of the present disclosure relates to a computer program element including instructions configured, when executed by one or more computing nodes, to perform steps of a computer-implemented method for generating a chemical product passport or for producing or providing a chemical product associated with a chemical product passport.
[0026] All disclosures and embodiments described herein relate to the methods, apparatus, and computer elements outlined above and below, and vice versa. Advantages provided by any of the embodiments and examples apply equally to all other embodiments and examples, and vice versa.
[0027] As used herein, "determining" also includes "initiating or causing a determination," "generating" also includes "initiating and / or causing a generation," and "providing" also includes "initiating or causing a determination, generation, selection, transmission, and / or reception." "Initiating or causing the performance of an action" includes any processing signal that triggers a computing node or device to perform the respective action.
[0028] The methods, devices, and computer elements disclosed herein provide an efficient, secure, and robust way of sharing or exchanging data across different participant nodes in the chemical value chain. In particular, by attaching a decentralized identifier and associated recycle content data and / or biobased content data, a simplified and customizable sharing or exchange of data from the chemical industry to the participants in the chemical supply chain can be performed. In this way, more reliable and efficient further processing of chemical products supplied by upstream participants in the chemical supply chain can be achieved while the data remains within the ownership of the chemical supplier supplying the upstream participant. By directly combining data related to chemical substances with a decentralized identifier and optionally one or more authentication mechanisms, more reliable and secure data sharing and exchange can be provided. By further including one or more authorization mechanisms, data sharing or exchange can be performed more flexibly with multiple data consuming services from different participants in the chemical supply chain having access to the recycle content data and / or biobased content data.
[0029] It is an object of the present invention to provide simplified and customizable data sharing or exchange from the chemical industry to participants in the chemical supply chain.
[0030] These and other objects which will become apparent on reading the following description are solved by the subject matter of the independent claims. The dependent claims refer to preferred embodiments of the invention.
[0031] The term "decentralized identifier" should be understood broadly in this case and includes any unique identifier that is uniquely associated with a data owner and chemical data, in particular recyclate content data and / or biobased content data. A decentralized identifier may include a universally unique identifier (UUID) or a digital identifier (DID). A decentralized identifier may be issued by a centralized or decentralized identity information issuer. A decentralized identifier may include authentication information. Through the decentralized identifier and its unique association with the data owner and chemical data, access to the chemical data, in particular recyclate content data and / or biobased content data, may be controlled by the data owner. This is in contrast to a central authority scheme, where the identifier is provided by such a central authority and access to the data is controlled by such a central authority. In this context, decentralized refers to the use of identifiers in embodiments controlled by the data owner.
[0032] The term "chemical product passport" is to be understood broadly in the present case and includes a digital representation of chemical product data, in particular recyclable content data and / or biobased content data. The digital representation may include a representation for accessing the chemical product data, in particular the recyclable content data and / or biobased content data, or a part thereof. The digital representation may include a representation of the chemical product data, in particular the recyclable content data and / or biobased content data, or a part thereof. The chemical product passport may include data related to the chemical product data, in particular the recyclable content data and / or biobased content data, a public key, and a decentralized identifier. The data related to the chemical product data, in particular the recyclable content data and / or biobased content data, may include a digital representation of the chemical product data, in particular the recyclable content data and / or biobased content data.
[0033] The term "chemical product" should be understood broadly in this case and includes not only chemical products obtained from chemical reactions, but also natural chemical products. Natural chemical products encompass any naturally occurring chemical, i.e., any unprocessed chemical found in nature, such as chemicals from plants, microorganisms, animals, soil, and the sea, or any chemical found in nature and extracted using a process that does not change any chemical composition. Natural chemical products may include biological products such as enzymes and naturally occurring inorganic or organic chemical products. Natural chemical products may be separated and purified prior to use or may be used in unseparated and / or unpurified form. Chemical products obtained from chemical reactions may be any inorganic or organic chemical products obtained by reaction of inorganic and / or organic chemical reactants. The inorganic and organic chemical reactants may be naturally occurring chemical products or may be chemical products obtained from chemical reactions. Chemical reactions may include any chemical reaction generally known in the art in which reactants are converted into one or more different chemical products. Chemical reactions may include the use of catalysts, enzymes, bacteria, etc. to achieve a chemical reaction between reactants.
[0034] The term "chemical product data" should be understood broadly in this case and includes data related to the properties of a chemical product and / or data related to the use of a chemical product. Such properties can be static properties or dynamic properties. Static properties can be properties that remain constant over time, e.g. melting point, boiling point, density, hardness, flammability, etc. Dynamic properties can be properties that change over time, e.g. shelf life, pH value, color, reactivity. Chemical product properties can include chemical properties such as performance properties, flammability, toxicity, acidity, reactivity, heat of combustion, etc., and / or physical properties such as density, color, hardness, melting point, and boiling point, electrical conductivity, etc. Data related to the use of a chemical product can include data related to the further processing of a chemical product, e.g. by using the chemical product as a reactant in a further chemical reaction, and / or data related to the use of a chemical product, e.g. data related to the use of a chemical product in a treatment process and / or in a manufacturing process. Chemical product data can include chemical substance data, emission data, recyclate content, biobased content, and / or production data.
[0035] The term "physical entity" should be understood broadly in this case and relates to the physical embodiment of a product. The physical entity can be any product in the chemical supply chain. The physical entity of a product can be a raw material or base substance, a chemical product, a chemical material, a chemical composition, a chemical mixture, a component, a component assembly, a final product, or a combination thereof.
[0036] The term “recycled content data and / or biobased content data” is to be understood broadly in this context and includes any data related to the recycle content or biobased content used to provide or manufacture a physical entity at any stage in the chemical supply chain, such as a raw material or base substance, a chemical product or chemical material, a component, a component assembly, or a final product.
[0037] The term "emissions data" should be understood broadly in this case and includes any data related to an environmental footprint. An environmental footprint may refer to an entity and its associated environmental footprint. An environmental footprint may be entity-specific. For example, an environmental footprint may relate to a product, a company, a process such as a manufacturing process, a raw material or base substance, a chemical product or material, a component, a component assembly, a final product, a combination thereof, or additional entity-specific relationships. Emissions data may include data related to a carbon footprint of a chemical product. Emissions data may include data related to greenhouse gas emissions, for example, emitted in the production of a chemical product. Emissions data may include data related to greenhouse gas emissions. Greenhouse gas emissions may include emissions such as carbon dioxide (CO2) emissions, methane (CH4) emissions, nitrous oxide (N2O) emissions, hydrofluorocarbon (HFC) emissions, perfluorocarbon (PFC) emissions, sulfur hexafluoride (SF6) emissions, nitrogen trifluoride (NF3) emissions, combinations thereof, and additional emissions.
[0038] Emissions data may include data related to the greenhouse gas emissions of the entity's or company's own activities (production, powering factories, and waste incineration). Scope 2 includes emissions from externally supplied energy production. Scope 3 includes all other emissions along the value chain. Specifically, this includes the greenhouse gas emissions of raw materials obtained from suppliers. The Product Carbon Footprint (PCF) sums up the greenhouse gas emissions and removals from successive interlinked process steps related to a particular product. A cradle-to-gate PCF may sum up the greenhouse gas emissions based on selected process steps, from the extraction of the resource to the factory gate where the product leaves the company. Such a PCF is called a partial PCF. To achieve such summation, each company offering any product must be able to provide, as accurately as possible, for each of its products, the scope 1 and scope 2 contributions to the PCF, and to obtain reliable and consistent data on the PCFs of purchased energy (scope 2) and its raw materials (scope 3).
[0039] The term "production data" should be understood broadly in this context and includes any data related to the production of a product at any stage in the chemical supply chain. Preferably, the production data includes chemical production data from the production of a chemical product. The production data may include monitoring and / or control data related to the production of a product such as a raw material or base substance, a chemical material or product, a component, a component assembly, a final product, or a combination thereof. The production data may include measurement data related to product quality, preferably the quality of a chemical product, at any stage in the chemical supply chain.
[0040] The term "data owner" should be understood broadly in this context and includes any entity that generates data. A generating node may be coupled to an entity that owns the physical product from which the data is generated. Data may be generated by a third party entity on behalf of the entity that owns the physical product from which the data is generated.
[0041] The term "data consumption service" should be understood broadly in this context and includes computer-executable instructions for accessing and / or processing data, such as chemical product data, in particular recyclable content data and / or biobased content data, associated with a data owner.
[0042] The term “data providing service” in this context should be understood broadly and includes computer-executable instructions that provide and / or process chemical product data, i.e., recyclate content data and / or biobased content data, associated with a data owner for access and / or processing by a data consuming service.
[0043] The term "digital representation of product data or a portion thereof" should be understood broadly in this case and includes at least one interface to a data providing service. It may further include at least one interface to a data consuming service. The digital representation of product data or a portion thereof may include data exchange or sharing endpoints (resource endpoints) or service interaction endpoints (service endpoints) that are uniquely identified via a communication protocol. Thus, the digital representation of product data or a portion thereof may be uniquely associated with a decentralized identifier.
[0044] In one embodiment, the request includes data related to the chemical data, particularly the recyclate content data and / or the biobased content data, and an owner identifier associated with the owner of the chemical data. The owner identifier may be a string identifier associated with the data owner's name. The owner identifier or product identifier may be provided by a physical identifier provider, such as a barcode or tag, such as an RFID tag, via a barcode or QR code. Such communication may be completed via ad-hoc WIFI, BLE beacon, and / or NFC. Communication between the wallet apps 1010B and 1020B may be performed via any available communication, including, but not limited to, a web server, ad-hoc WIFI, BLE beacon signal, NFC, barcode, or QR code scanning, etc.
[0045] Through the owner identifier, the generated chemical passport can be associated with the owner of the chemical data by including the owner identifier. The owner identifier can be used for data transactions such as sharing or exchanging chemical data, particularly recyclate content data and / or biobased content data. The owner identifier can be provided to a transaction manager. Providing the decentralized identifier and the owner identifier of the data owner to a transaction manager or data consumption service can simplify tracking of data transactions. Any transaction in the data ecosystem can be associated with, for example, the unambiguous name of the data owner.
[0046] In one embodiment, the decentralized identifier is provided by one central node or one or more decentralized nodes. The decentralized identifier generated by one central node or one or more decentralized nodes may be provided to the node generating the chemical passport and to at least one authenticated data registry node, preferably accessible by the data providing service and / or the data consuming service. This allows customized data sharing or exchange regarding the chemical products and the chemical supply chain to which the chemical products are supplied. In particular, the data providing service and / or the data consuming service may customize a data sharing or exchange protocol based on associating the decentralized identifier with the chemical product data, in particular the recyclate content data and / or the biobased content data.
[0047] The authenticated data registry node may be a centralized registry node, such as a centralized file system, a centrally managed distributed database, and / or a centrally managed peer-to-peer network. A centralized configuration allows for more control and standardization via a central node. The authenticated data registry node may be a decentralized registry, such as a distributed ledger, a decentralized file system, a distributed database, and / or a peer-to-peer network. A decentralized configuration allows for more efficient use of computational resources and allows for greater control by data owners. In addition, a decentralized configuration is independent of a central management node, thus increasing the reliability and flexibility of the system.
[0048] In one embodiment, the generation of the chemical product passport includes providing a decentralized identifier associated with a physical entity of the chemical product. In this context, the physical entity may relate to a physical product associated with the decentralized identifier. The physical entity may be any entity in the chemical supply chain. The physical entity may relate to a raw material such as crude oil, a chemical product such as polyols and diisocyanates or polyurethane intermediates produced from polyols and diisocyanates, a component such as a foam part or bead, a component assembly such as a car seat or a shoe sole, and / or a final product such as a car.
[0049] The decentralized identifier may be associated with a physical entity with which the chemical product data, particularly the recyclable content data and / or the biobased content data, is associated. The decentralized identifier may be associated with a chemical product with which the chemical product data, particularly the recyclable content data and / or the biobased content data, is associated. For example, the decentralized identifier may be associated with a physical entity such as a base substance, a raw material, a chemical material, a chemical mixture, a chemical composition, etc. The decentralized identifier may be associated with a physical entity with which the chemical product is sourced and with which the chemical product data, particularly the recyclable content data and / or the biobased content data, is associated. For example, the decentralized identifier may be associated with a physical entity such as a component, a component assembly, a final product, etc. The decentralized identifier may be associated with two or more physical entities with which the chemical product is sourced and with which the chemical product data, particularly the recyclable content data and / or the biobased content data, is associated. For example, the decentralized identifier may be associated with a physical entity such as a component, a component assembly, and a final product. By associating decentralized identifiers with different physical entity stages in the chemical supply chain, it becomes possible to virtually trace chemical products as they are delivered through the supply chain. In this way, chemical products associated with chemical product data, particularly recyclable content data and / or biobased content data, can be tracked, for example, to the end of the life of the final product.
[0050] In one embodiment, the decentralized identifier is a physical identifier that is linked to the chemical product or is assigned to a physical identifier. The linking of the physical identifier to the chemical product may be provided by a physical link to a physical product or a physical entity. For example, the physical identifier may be linked to a physical entity of the chemical product. The physical entity may be a raw material or an intermediate product. The physical identifier may have a one-to-one correspondence to a virtual identity or a physical identity by a physical link to a physical entity. In one embodiment, the physical identifier is physically attached to the chemical product via an identifier element.
[0051] A "physical identifier" or "physical identifier element" may refer to any virtual or physical configuration that associates a decentralized identifier with a chemical product. A physical identifier may be any identifier of a produced chemical product, such as a batch number or part number. A physical identifier element may include passive or active elements, such as, but not limited to, a QR code, an RFID tag. A physical identifier element may be a physical identifier that is physically tied to a chemical product. An identifier element may include a marker embedded in a material, a tag such as a barcode, a QR code, an RFID tag, or a similar physical configuration that allows a chemical product to be digitally identified.
[0052] In one embodiment, an identifier element including a physical identifier is physically attached to the chemical product. The physical identifier may be provided from a sensor that reads the physical identifier element, and the physical identifier element is physically tied to the chemical product. The identifier element may be physically tied to the chemical product to uniquely identify the chemical product. The identifier element may be physically tied to any component of the chemical product, such as the packaging of the chemical product, to uniquely identify the chemical product.
[0053] In one embodiment, the chemical passport includes a decentralized identifier and one or more authentication mechanisms associated with chemical data, particularly data related to recyclate content data and / or biobased content data. The authentication mechanisms may include tokens such as private key and public key infrastructure, certificate mechanisms, or biometric mechanisms such as fingerprint, face recognition, or voice recognition. One common public key certificate is, for example, an X.509 certificate. Through the authentication mechanisms, data access by data consuming services can be securely controlled and the integrity of data providing services can be ensured. This allows for more reliable, controlled, and secure data exchange or sharing.
[0054] One or more authentication mechanisms associated with the decentralized identifiers generated by one central node or one or more non-centralized nodes may be provided to at least one decentralized authenticated data registry accessible to the nodes generating the chemical product passports and preferably by the data providing service and / or the data consuming service. The authenticated data registry may be a centralized registry such as a centralized file system, a centrally managed distributed database, and / or a centrally managed peer-to-peer network. The centralized configuration allows for a higher degree of control and standardization via the central node. The authenticated data registry may be a decentralized registry such as a distributed ledger, a decentralized file system, a distributed database, and / or a peer-to-peer network. The decentralized configuration allows for a more efficient use of computational resources and enhances control by the data owners.
[0055] In one embodiment, the chemical passport is associated with or includes a decentralized identifier and one or more authorization mechanisms associated with the chemical data, particularly data related to recyclate content data and / or biobased content data. The authorization mechanisms may include authorization rules including data transaction instructions or protocols such as data usage policies, smart data contracts, or more complex data processing instructions associated with the data providing service and / or data consuming service. Through the authorization mechanisms, data access and data usage by the data consuming service may be securely controlled.
[0056] One or more authorization mechanisms associated with the decentralized identifiers generated by one central node or one or more non-central nodes may be provided to nodes generating or processing chemical passports or nodes accessing chemical data, in particular data related to recyclate content data and / or biobased content data. Additionally or alternatively, one or more authorization mechanisms may be provided in at least one centralized or decentralized authorized data registry, preferably accessible by the data providing service and / or the data consuming service. In an embodiment, one or more authorization mechanisms associated with the decentralized identifiers generated by one or more non-central nodes may be provided to nodes generating or processing chemical passports and in at least one of a centralized file system, a centrally managed distributed database, a centrally managed peer-to-peer network, a distributed ledger, a decentralized file system, a distributed database, and / or a peer-to-peer network, preferably accessible by the data providing service and / or the data consuming service.
[0057] In one embodiment, the data relating to the chemical data, in particular the recyclate content data and / or the biobased content data, comprises the chemical data, in particular the chemical data, in particular the recyclate content data and / or the biobased content data, or a portion thereof. In one embodiment, the data relating to the chemical data, in particular the recyclate content data and / or the biobased content data, comprises one or more digital representations pointing to the chemical data, in particular the recyclate content data and / or the biobased content data, or a portion thereof. In this context, pointing to means any network representation or address suitable for accessing the chemical data, in particular the recyclate content data and / or the biobased content data. The data relating to the chemical data, in particular the recyclate content data and / or the biobased content data, may comprise multiple digital representations pointing to separate portions of the chemical data, in particular the recyclate content data and / or the biobased content data. Data relating to chemical data, particularly recyclate content data and / or biobased content data, may include multiple digital representations pointing to different portions of the chemical data, particularly recyclate content data and / or biobased content data. Such different portions may overlap at some data points. The representations may include access points to the chemical data, particularly recyclate content data and / or biobased content data, links for accessing the chemical data, particularly recyclate content data and / or biobased content data, endpoints for accessing the chemical data, particularly recyclate content data and / or biobased content data, or service endpoints for accessing the chemical data, particularly recyclate content data and / or biobased content data. In this way, the chemical data, particularly recyclate content data and / or biobased content data, may be maintained and controlled by the data owner. Because there is no need to check and control access to multiple distributed data points, access may be provided via the representation of the access points, simplifying data validation, integrity checks, or quality checks and access control.
[0058] In one embodiment, the chemical passport comprises data relating to different classes of chemical data, in particular recyclable content data and / or biobased content data, for example the data relating to the chemical data comprises a plurality of digital representations referring to different classes of chemical data, in particular recyclable content data and / or biobased content data.
[0059] In one embodiment, at least one class of chemical product data includes chemical substance data, e.g., regulatory required data or chemical substance regulatory data. The chemical substance data may include chemical product declaration data associated with a physical entity of a product, such as a raw material, a chemical product, a component, a component assembly, or an end product, and / or combinations thereof. The chemical product declaration data may be associated with two or more raw materials or chemical products, such as those used to manufacture a component. The chemical product declaration data may be associated with two or more raw materials or chemical products, such as those used to manufacture multiple components to assemble a component assembly or end product.
[0060] In one embodiment, the chemical data includes chemical safety data associated with a hazard of a substance or mixture of a physical entity of a product, such as a raw material, a chemical product, a component, a component assembly, or an end product, and / or combinations thereof. The chemical safety data may be associated with two or more raw materials or chemical products, such as those used to manufacture a component. The chemical safety data may be associated with two or more raw materials or chemical products, such as those used to manufacture multiple components to assemble a component assembly or end product.
[0061] In one embodiment, the chemical data includes certificates of analytical data related to laboratory measurement data obtained from samples of raw materials, chemical products, components, component assemblies, or final products, and / or combinations thereof. The certificates of analytical data may be associated with two or more raw materials or chemical products, such as those used to manufacture a component. The certificates of analytical data may be associated with two or more raw materials or chemical products, such as those used to manufacture multiple components to assemble a component assembly or final product.
[0062] In one embodiment, at least one class of chemical product data includes emissions data, recyclable content data, biobased content data, and / or production data associated with a physical entity of a product, such as a raw material, a chemical product, a component, a component assembly, a final product, and / or combinations thereof. The emissions data, recyclable content data, biobased content data, and / or production data may be associated with two or more raw materials or chemical products, such as those used to manufacture a component. The emissions data, recyclable content data, biobased content data, and / or production data may be associated with two or more raw materials or chemical products, such as those used to manufacture multiple components to assemble a component assembly or a final product.
[0063] In one embodiment, at least one class of chemical data, particularly recyclable content data and / or biobased content data, includes restricted access chemical data, particularly recyclable content data and / or biobased content data, associated with a physical entity of a product, such as a raw material, a chemical product, a component, a component assembly, a final product, and / or a combination thereof. For example, the discharge data, the recyclable content data, the biobased content data, the production data, or a combination thereof, may be restricted access. Such access restrictions may be provided by an authorization mechanism. For example, the authorization mechanism may include rules that specify which data consuming services may access under which conditions.
[0064] In one embodiment, at least one class of chemical data includes unrestricted access chemical data associated with a product physical entity, such as a raw material, a chemical, a component, a component assembly, a final product, and / or combinations thereof. For example, chemical declaration data, chemical safety data, and / or certificate of analysis data associated with a product physical entity, such as a raw material, a chemical, a component, a component assembly, or a final product, and / or combinations thereof, may be unrestricted access. Such access may be provided by an authorization mechanism. For example, the authorization mechanism may include rules that specify that certain regulatory data of chemical substances are accessible.
[0065] BRIEF DESCRIPTION OF THE DRAWINGS The present disclosure will now be described in detail with reference to the accompanying drawings. [Brief description of the drawings]
[0066] [Figure 1a] 1 illustrates an exemplary embodiment of a centralized and decentralized computing environment having computing nodes. [Figure 1b]1 illustrates an exemplary embodiment of a centralized and decentralized computing environment having computing nodes. [Figure 1c] 1 illustrates an exemplary embodiment of a distributed computing environment. [Diagram 2] An example of a chemical product passport containing DID owner data, DID document data, and a decentralized identity infrastructure is shown. [Diagram 3] An example of a chemical product passport including ID-based data, passport data, and a decentralized identity infrastructure is shown. [Figure 4] 1 illustrates an exemplary method for generating a chemical product passport. [Diagram 5] 1 illustrates an exemplary method of using a chemical product passport for further processing of a chemical product associated with the chemical product passport. [Figure 6a] 1 shows an example of an authentication protocol. [Figure 6b] 1 shows an example of an authentication protocol. [Figure 7a] Illustrate the principles of cryptographic signatures. [Figure 7b] Illustrate the principles of cryptographic signatures. [Figure 8] 1 illustrates an exemplary method for authorizing access to chemical data. [Figure 9] 1 shows a schematic diagram of providing access to a product passport of a data providing service within an International Data Space (IDS) architecture to a data consuming service. [Figure 10] 1 shows a schematic diagram of the authentication process between two IDS connectors. [Figure 11] 1 shows a schematic diagram of usage-controlled data flow within an IDS architecture. [Figure 12] 3 shows different exemplary configurations of a digital identifier based product passport; [Figure 13] 3 shows different exemplary configurations of a digital identifier based product passport; [Figure 14] 3 shows different exemplary configurations of a digital identifier based product passport; [Figure 15] 1 illustrates an example of a production facility that produces a chemical product associated with a chemical product passport. [Figure 16] 1 illustrates another example of a production facility that produces a chemical product associated with a chemical product passport. [Figure 17] 1 illustrates an example of a production system that produces chemical products associated with one or more chemical product passports. [Figure 18] An example of providing access to data via one or more chemical product passports is given. [Figure 19] An example of providing access to data via one or more chemical product passports is given. [Figure 20] An example of providing access to data via one or more chemical product passports is given. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0067] 1a-1c show different computing environments: centralized, decentralized and distributed. The disclosed method, apparatus and computer elements can be implemented in a decentralized or at least partially decentralized computing environment. In particular, different problems exist in data sharing or exchange in a multi-player ecosystem. Data sovereignty can be seen as a core issue. Data sovereignty can be defined as the ability of a natural person or business entity to be totally self-determined with respect to data. To enable this particular ability, related aspects can be implemented across the chemical value chain, including the requirement to exchange data securely and reliably in a business ecosystem. In particular, the chemical industry needs tailor-made solutions to deliver chemical products more sustainably by using digital ecosystems. The provision, determination or processing of data can be realized by different computing nodes that can be implemented in a centralized, decentralized or distributed computing environment.
[0068] FIG. 1a illustrates an exemplary embodiment of a centralized computing system 100 including a central computing node 101 (solid circle at the center) and several peripheral computing nodes 101.1-101.n (shown as solid circles around the periphery). As used herein, the term "computing system" is broadly defined to include one or more computing nodes, a system of nodes, or a combination thereof. As used herein, the term "computing node" is broadly defined and may refer to any device or system that includes at least one physical, tangible processor and a physical, tangible memory capable of having computer-executable instructions executed by the processor. Computing nodes are now increasingly taking a variety of forms. Computing nodes may be, for example, handheld devices, production facilities, sensors, monitoring systems, control systems, home appliances, laptop computers, desktop computers, mainframes, data centers, or even devices that have not traditionally been considered computing nodes, such as wearables (e.g., glasses, watches, etc.). Memory may take any form, depending on the nature and form of the computing node.
[0069] In this example, the peripheral computing nodes 101.1-101.n may be connected to one central computing system (or server). In another example, the peripheral computing nodes 101.1-101.n may be attached to the central computing node, for example via a terminal server (not shown). Most of the functionality may be performed by or obtained from the central computing node (also referred to as a remote centralized management location). One peripheral computing node 101.n is expanded to provide an overview of the components present in the peripheral computing node. The central computing node 101 may comprise the same components as described in relation to the peripheral computing node 101.n.
[0070] Each computing node 101, 101.1-101.n may comprise at least one hardware processor 102 and memory 104. The term "processor" may refer to any logic circuitry configured to perform basic operations of a computer or system and / or generally to a device configured to perform calculations or logical operations. In particular, a processor or computer processor may be configured to process basic instructions that run a computer or system. The processor may be a semiconductor-based processor, a quantum processor, or any other type of processor configured to process instructions. By way of example, the processor may include at least one arithmetic logic unit ("ALU"), at least one floating point unit ("FPU"), such as a numeric coprocessor or numeric coprocessor, a number of registers, particularly registers configured to supply operands to the ALU and store results of operations, and memory, such as L1 and L2 cache memories. In particular, the processor may be a multi-core processor. In particular, the processor may be or comprise a central processing unit ("CPU"). The processor may be a graphics processing unit ("GPU"), a tensor processing unit ("TPU"), a complex instruction set computing ("CISC") microprocessor, a reduced instruction set computing ("RISC") microprocessor, a very long instruction word ("VLIW") microprocessor, a processor implementing other instruction sets, or a processor implementing a combination of instruction sets. The processing means may also be one or more special-purpose processing devices, such as an application specific integrated circuit ("ASIC"), a field programmable gate array ("FPGA"), a complex programmable logic device ("CPLD"), a digital signal processor ("DSP"), a network processor, or the like. The methods, systems, and devices described herein may be implemented as software in a DSP, a microcontroller, or any other side processor, or as hardware circuitry in an ASIC, CPLD, or FPGA.It should be understood that the term processor may also refer to one or more processing devices, such as a distributed system of processing devices located across multiple computer systems (e.g., cloud computing), and is not limited to a single device unless otherwise specified.
[0071] Memory 104 may refer to physical system memory, which may be volatile, non-volatile, or a combination thereof. Memory may include non-volatile mass storage devices such as physical storage media. Memory may be computer readable storage media such as RAM, ROM, EEPROM, CD-ROM, or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other physical, tangible storage medium that can be used to store desired program code means in the form of computer executable instructions or data structures and that can be accessed by a computing system. Furthermore, memory may be a computer readable medium (also called a transmission medium) having computer executable instructions. Furthermore, program code means in the form of computer executable instructions or data structures may be automatically transferred from a transmission medium to a storage medium (or vice versa) when reaching various computing system components. For example, computer executable instructions or data structures received over a network or data link may be buffered in a RAM in a network interface module (e.g., a "NIC") and then eventually transferred to the computing system's RAM and / or to a less volatile storage medium in the computing system. Thus, it should be understood that storage media may be included in computing components that also (or even primarily) utilize transmission media.
[0072] Computing nodes 101, 101.1,..., 101.n may include a number of structures 106, often referred to as "executable components or computer-executable instructions." For example, memory 104 of computing nodes 101, 101.1,..., 101.n may be depicted as including executable components 106. The term "executable components" may refer to structures that may be software, hardware, or a combination thereof, or that are well understood by those skilled in the computing arts as being structures that may be implemented in software, hardware, or a combination thereof. For example, when implemented in software, those skilled in the art will understand that the structure of executable components includes software objects, routines, methods, etc. that are executable on computing nodes 101, 101.1,..., 101.n, regardless of whether such executable components reside on multiple computing nodes 101, 101.1,..., 101.n, or whether the executable components reside on computer-readable storage media. In such cases, one skilled in the art will recognize that the structure of the executable components resides on a computer-readable medium such that, when interpreted by one or more processors (e.g., by processor threads) of the computing nodes 101, 101.1, ..., 101.n, the computing nodes 101, 101.1, ..., 101.n perform the functions. Such structures may be directly computer readable by the processors (as if the executable components were binary). Alternatively, the structures may be structured to be interpretable and / or compiled (whether in one step or multiple steps) to generate binary that is directly interpretable by the processor. Such an understanding of an exemplary structure of an executable component is well within the understanding of one skilled in the computing arts when using the term "executable component."Examples of hardware implemented executable components include hard-coded or hard-wired logic gates that are implemented exclusively or almost exclusively in hardware, such as in a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), or any other dedicated circuit. In this description, the terms "component," "agent," "manager," "service," "engine," "module," "virtual machine," and the like are used synonymously with the term "executable component."
[0073] The processor 102 of each computing node 101, 101.1, ..., 101.n may direct the operation of each computing node 101, 101.1, ..., 101.n in response to executing computer-executable instructions that constitute executable components. For example, such computer-executable instructions may be embodied in one or more computer-readable media forming a computer program product. The computer-executable instructions may be stored in the memory 104 of each computing node 101, 101.1, ..., 101.n. The computer-executable instructions include, for example, instructions and data that, when executed by the processor 101, cause a general-purpose computing node 101, 101.1, ..., 101.n, a special-purpose computing node 101, 101.1, ..., 101.n, or a special-purpose processing device to perform a particular function or group of functions. Alternatively or additionally, computer-executable instructions may configure the computing nodes 101, 101.1, ..., 101.n to perform a particular function or group of functions. The computer-executable instructions may be, for example, binaries or even instructions that undergo some translation (e.g., compilation) before being executed directly by a processor, such as intermediate format instructions such as assembly language or even source code.
[0074] Each computing node 101, 101.1,..., 101.n may include a communication channel 108, e.g., a network (shown in FIG. 1a as a solid line between the peripheral computing nodes and the central computing node), that allows each computing node 101.1,..., 101.n to communicate with the central computing node 101. A "network" may be defined as one or more data links that enable the transmission of electronic data between the computing nodes 101, 101.1,..., 101.n, modules, and / or other electronic devices. When information is transferred or provided to the computing nodes 101, 101.1,..., 101.n via a network or another communication connection (either wired, wireless, or a combination of wired and wireless), the computing nodes 101, 101.1,..., 101.n properly consider the connection to be a transmission medium. A transmission medium may be used to carry desired program code means in the form of computer-executable instructions or data structures and may include a network and / or data links accessible by general-purpose or special-purpose computing nodes 101, 101.1, ..., 101.n. Combinations of the above may also be included within the scope of computer-readable media.
[0075] Computing nodes 101, 101.1-101.n may further comprise a user interface system 110 used to interface with a user. User interface system 110 may include an output mechanism 110A and an input mechanism 110B. The principles described herein are not limited to the precise output mechanism 110A or input mechanism 110B as such will depend on the nature of the device. However, output mechanism 110A may include, for example, a display, a speaker, a display, a haptic output, a hologram, etc. Examples of input mechanism 110B include, for example, a microphone, a touch screen, a hologram, a camera, a keyboard, a mouse or other pointer input, any type of sensor, etc.
[0076] FIG. 1b illustrates an exemplary embodiment of a decentralized computing environment 100′ with several computing nodes 101.1′-101.n′ depicted as solid circles. In contrast to the centralized computing environment 100 illustrated in FIG. 1a, the computing nodes 101.1′-101.n′ of the decentralized computing environment are not connected to the central computing node 101 and are therefore not under the control of the central computing node. Instead, both hardware and software resources can be allocated to each individual computing node 101.1′, . . . , 101.n′ (local or remote computing system) and data can be distributed among the various computing nodes 101.1′, . . . , 101.n′ for task execution. Thus, in a decentralized system environment, program modules can be located in both local and remote memory storage devices. One computing node 101′ is enlarged to provide an overview of the components present in the computing node 101′. In this example, the computing node 101′ comprises the same components as those described in relation to FIG. 1a.
[0077] FIG. 1c illustrates an exemplary embodiment of a distributed computing environment 103. In this description, "distributed computing" may refer to any computing that utilizes multiple computing resources. Such use may be realized through virtualization of physical computing resources. One example of distributed computing is cloud computing. "Cloud computing" may refer to a model that enables on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services). When distributed, a cloud computing environment may be distributed internally within an organization and / or across multiple organizations. In this example, the distributed cloud computing environment 103 may include the following computing resources: mobile devices 114, applications 116, databases 118, data storage 120, and servers 122. The cloud computing environment 103 may be deployed as a public cloud 124, a private cloud 126, or a hybrid cloud 128. The private cloud 124 may be owned by the organization, and only members of the organization with appropriate access may use the private cloud 126, keeping the data in the private cloud at least confidential. In contrast, data stored in the public cloud 126 may be open to anyone via the Internet. A hybrid cloud 128 may be a combination of a private cloud 124 and a public cloud 126, allowing some data to be kept private while other data may be public.
[0078] FIG. 2 shows an example of ID-based owner data, ID-based passport data, and a decentralized identity manager.
[0079] The identity may be a decentralized identity (DID). The identity-based passport data may be a DID document associated with the DID. The identity-based owner data may include an identity associated with a subject, such as product data, chemical product data, etc., and may include an authentication mechanism. The identity-based owner data may include owner data that is electronically owned and controlled by the DID owner. In this context, electronically owned may refer to data stored in an owner repository or wallet. Such data may be securely stored and / or managed on an organized server or client device. The identity-based owner data may include a DID, a private key, and a public key. The identity-based owner may own and control the DID, which represents the identity associated with the DID subject, the private key and the public key associated with the DID. A DID may be understood as an identifier and authentication information associated or uniquely linked to the identifier.
[0080] A DID subject may be a raw material, base material, chemical product, intermediate product, component, component assembly, or final product. A DID subject may be a machine, system, or device or a collection of such machines, devices, and / or systems used in the production of a raw material, base material, chemical product, intermediate product, component, component assembly, or final product. A DID owner may be a supply chain actor or a manufacturer, such as a chemical manufacturer that produces a chemical. A DID owner may be an upstream actor in the supply chain of a chemical manufacturer, such as a supplier that supplies a feedstock chemical or precursor to produce a chemical. A DID owner may be a downstream actor in the supply chain of a chemical manufacturer, such as a customer that consumes a chemical to produce an intermediate product, component, component assembly, or final product. A DID owner may be any actor in the supply chain, including a feedstock chemical supplier, an intermediate chemical manufacturer, an intermediate component manufacturer, a component manufacturer, a component assembly manufacturer, or a final product manufacturer.
[0081] A DID can be any identifier associated with a DID subject and / or DID owner. Preferably, the identifier is unique to the DID subject and / or DID owner. The identifier can be unique at least to the extent that the DID is expected to be in use. The identifier can be a locally or globally unique identification of any actor in the supply chain, including a raw material, a base substance, a chemical product, an intermediate product, a component, a component assembly, a final product, or a collection thereof, a machine, a system, or a device used in the production of a raw material, a base substance, a chemical product, an intermediate product, a component, a component assembly, or a final product, or a collection of such machines, devices, and / or systems, a chemical manufacturer producing a chemical, an upstream actor in the supply chain of a chemical manufacturer, a downstream actor in the supply chain of a chemical manufacturer, or a collection thereof, a feedstock chemical supplier, an intermediate chemical manufacturer, an intermediate component manufacturer, a component manufacturer, a component assembly manufacturer, or a final product manufacturer, or a collection thereof.
[0082] A DID may be a Uniform Resource Identifier (URI), such as a Uniform Resource Locator (URL). A DID may be an Internationalized Resource Identifier (IRI). A DID may be a random string of numbers and letters for increased security. In one embodiment, a DID may be a string of 128 letters and numbers following the scheme did:method name:method specific did, such as did:example:ebfeb1f712ebc6f1c276e12ec21. A DID may be decentralized and under the control of the DID owner, independent of any centralized third-party management system.
[0083] A chemical passport as a DID document may be associated with a DID. Thus, a chemical passport may contain a reference to a DID associated with a DID subject described by the DID document. A DID document may also contain authentication information, such as a public key. The public key may be used by a third party entity authorized by the DID owner / subject to access information and data owned by the DID owner / subject. The public key may also be used to verify that the DID owner actually owns or controls the DID. A DID document may contain authentication information, authorization information, for example to authorize the reading of the DID document or certain parts of the DID document by a third party entity, for example without giving the third party the right to prove ownership of the DID.
[0084] A chemical passport may include one or more representations that are digitally linked to product or chemical data, for example by a service endpoint. A service endpoint may include a network address at which a service operates on behalf of a DID owner. In particular, a service endpoint may refer to a service of a DID owner that provides access to product or chemical data. Such services may include services that read or analyze product or chemical data. Chemical data may include chemical product declaration data, chemical product safety data, certificate of analysis data, emissions data, product carbon footprint data, product environmental footprint data, chemical product specification data, product information, technical application data, production data, or a combination thereof.
[0085] A chemical passport may include various other information, such as metadata specifying when the chemical passport was created, when it was last modified, and / or when it expires.
[0086] The DID and the chemical product passport may be associated with a data registry node of a centralized or decentralized data service system, such as a distributed ledger or blockchain. Possible blockchain systems include Quorum, Hyperledger, Fabric. The distributed ledger or blockchain may be used to store a representation of the DID that points to the chemical product passport. The representation of the DID may be stored on distributed computing nodes of the distributed ledger or blockchain. For example, a DID hash may be stored on multiple computing nodes of the distributed ledger and point to the location of the chemical product passport. In some embodiments, the chemical product passport may be stored on the distributed ledger.
[0087] A distributed ledger or blockchain may be any decentralized, distributed network that includes various computing nodes that communicate with each other. For example, a distributed ledger may include a first distributed computing node, a second distributed computing node, a third distributed computing node, and any number of additional distributed computing nodes. A distributed ledger or blockchain may operate according to any known distributed ledger standard or method. Examples of conventional distributed ledgers that correspond to a distributed ledger or blockchain include, but are not limited to, Bitcoin [BTC], Ethereum, and Litecoin.
[0088] FIG. 3 shows an example of ID-based certificate data, ID-based passport data, and an identity manager.
[0089] In contrast to the example of FIG. 2, the example of FIG. 3 is certificate-based. Identity-based certificate data may include authentication data of the certificate owner and the certificate issuer. For example, a cryptographic signature from the issuer may bind the data owner's public key to an identity. The identity may be a unique ID (such as a UID) as described in connection with the DID of FIG. 2. The certificate may be an X.509 certificate, such as X509v3. Identity-based passport data may be associated with a data source of the data owner. Identity-based passport data may include identity, authentication data, and endpoints associated with product data or chemical data. Such endpoints may include any digital representation that is bound to a data source. The data source may provide product data and / or chemical data.
[0090] In this certificate-based example, the identity-based passport data includes one or more certificates associated with the data owner. The certificates may be associated with an identity manager, for example, including a certificate issuing service and / or a dynamic provisioning service that provides dynamic attribute tokens (e.g., OAuth access tokens). The information required for the validation of the certificates is provided via an authentication registry associated with the certificate issuing service and / or the dynamic provisioning service. For example, in the IDSA Reference Architecture Model, version 3.0 of April 2019, connectors associated with the data owner, a certificate authority (CA), a dynamic attribute provisioning service (DAPS), and connectors associated with the data consumer service are used to validate the identity prior to the execution of the data exchange (not shown). For this purpose, such connectors include one or more certificates, such as an X.509 certificate. Thus, the connector possesses a unique identifier embedded in the X.509 certificate that identifies the connector instance.
[0091] FIG. 4 illustrates an exemplary method for generating a chemical product passport. In chemical passport generation, a request may be provided to provide a decentralized identifier associated with the data owner and chemical product data. A computing node (acting as a management module, user agent, ID hub, and / or certificate issuer for the DID owner) may receive instructions to generate the decentralized identifier. The instructions may include providing at least one authentication mechanism or selecting at least one of a plurality of authentication mechanisms.
[0092] In response to the request, a chemical passport may be generated that includes a decentralized identifier and data associated with the chemical data. An authentication mechanism may be selected or provided. A decentralized identifier and data associated with the authentication mechanism may be generated or provided. A digital representation linked to the chemical data may be provided. A chemical passport may be generated based on the decentralized identifier, the data associated with the authentication mechanism, and the digital representation linked to the chemical data.
[0093] The chemical passport may be provided for access by a data consuming service controlled by a data providing service associated with the data owner. The chemical passport may include at least (1) data associated with a decentralized identifier and (2) data associated with at least one selected authentication mechanism. At least a portion of the data included in the chemical passport may then be communicated to an authentication data registry, such as a distributed ledger. The chemical passport may further include data associated with the chemical data.
[0094] FIG. 5 illustrates an exemplary method of using a chemical product passport for further processing of a chemical product associated with the chemical product passport.
[0095] To use the chemical passport, instructions may be received to access chemical data associated with a decentralized identifier in the chemical passport. The chemical passport may be structured as described in Figures 2 and 3. The chemical passport may be generated as described in Figure 5.
[0096] Before access to the chemical product data can be provided, the request may be authenticated. In particular, a data consuming service requesting access to the chemical process data and / or a data provider service providing access to the chemical process data may be authenticated.
[0097] Such authentication may be based on data related to a decentralized identity and authentication mechanism. Authentication may be performed through different communication patterns detailed in Figures 6 and 10.
[0098] If the authentication fails, access to the chemical data may be denied. If the authentication is valid, an authorization step may follow. Such authorization may be based on data related to decentralized identity and authorization rules. Authorization may be performed through different communication patterns detailed in Figures 7 and 11.
[0099] If authorization fails, access to the chemical data may be denied or the access may be adapted. In particular, the requested authorization may be adapted to comply with the applicable authorization rules. If authorization is valid, access to the chemical data may be granted in accordance with the requested authorization rules. Such access to the chemical data associated with the decentralized identifier may be provided using a representation embodied in a chemical passport.
[0100] FIG. 6 illustrates an exemplary method for authenticating access to chemical data. In the process of authentication, various communication patterns may be implemented to verify identity. Figure 6a shows one exemplary communication pattern that may take place between a data providing service and a data consuming service. In this case, the data providing service may act as a verifying entity and a separate service may not be used for authentication.
[0101] The data consuming service may request a service from the data providing service. The request may include a decentralized identifier of the data consuming service, such as a DID.
[0102] In response to the request, the data providing service may access a registry, such as a centralized or decentralized authentication registry, to retrieve data related to the authentication mechanism associated with the identity. For example, a centralized authentication registry may provide data related to the authentication mechanism via an authentication service that issues an access token. For further example, a decentralized authentication registry may provide data related to the authentication mechanism by generating a request token. The data related to the authentication mechanism may include the public key of the data consuming service.
[0103] Based on the retrieved data related to the authentication mechanism, the data providing service may generate an authentication request (e.g., corresponding to an authentication request token or dynamic attribute token). The authentication request may be generated based on the data consuming service's public key and / or the data provider service's private key. The generated authentication request may be sent to the data consuming service.
[0104] Based on the received authentication request, the data consumption service may generate authentication data in response to the authentication request, and the generated authentication data may be transmitted to the data providing service.
[0105] Upon receiving a response from the data consuming service that includes the authentication information, the data providing service may then verify the validity of the authentication data, and in response to verifying the validity, the data providing service may allow or deny the service request of the data consuming service.
[0106] FIG. 6b illustrates yet another communication pattern between a data provider service, an authentication service, and a data consumer service.
[0107] First, a data consumer service may request a service or initiate communication with a data provider service. The request may include a decentralized identifier, such as the DID, of the data consumer service.
[0108] Upon receiving the request, the data provider service may access the distributed ledger to retrieve one or more authentication mechanisms associated with the identity. Based on the retrieved authentication mechanisms, the service provider may generate an authentication request.
[0109] Here, at least one of the authentication mechanisms retrieved via the authentication service may be provided. Thus, in some embodiments, the generated authentication request may be sent directly to the authentication service. Upon receiving the authentication request from the data provider service, the authentication service may generate authentication data.
[0110] The authentication data generated by the authentication service may be transmitted to a data consumer service. The data consuming service may then pass the authentication data to the data provider service. Upon receiving the authentication data, the data provider service may then verify the validity of the authentication data. In response to verifying the validity, the data providing service may allow or deny the service request of the data consuming service.
[0111] Alternatively, in some embodiments, after the data provider service can generate the authentication request, the data provider service can send the authentication request to the data consumer service, which can pass the authentication request to the authentication service.
[0112] Furthermore, after the authentication service is able to generate the authentication data, in some embodiments the authentication service simply contacts the data consumer service to acknowledge receipt of the authentication request and obtain consent. Once the data consumer service receives the acknowledgement, the data consumer service consents and sends the consent to the authentication service. Upon receiving consent, the authentication service then sends the authentication data directly to the data provider service.
[0113] Finally, in many transactions, authentication may be performed mutually by both parties. In such mutual authentication situations, each party involved is both the subject entity and the verifying entity. The data consumer service and the data provider service control their respective identities. Initially, the services exchange their respective identities. Then, each of the services accesses the distributed ledger to obtain each other's authentication mechanisms. Each service then generates its own authentication request based on the authentication method of the other's identity. The generated authentication data is then sent to the other service. Upon receiving each other's authentication data, each service verifies the validity of the received authentication data. Based on the result of the validation, the services may then perform additional communications, for example, one service may allow or deny the other service's service request.
[0114] 6a and 6b merely illustrate an example of an authentication protocol, and although the communication arrows are discussed in a particular order or shown in a sequence of communications, unless specifically noted, no particular order is required or may be required because a communication is dependent on another communication being completed before that communication can be sent.
[0115] 7a and 7b show the principle of cryptographic signatures as they can be used for example for authentication mechanisms based on private and public key pairs. Such processes include cryptographic mechanisms using key pairs and / or hash functions.
[0116] Figure 7a shows an example of a cryptographic process. In a first step, subject data such as a JWT request token may be provided. Such data may include the recipient's public key. Additionally, the sender's private key may be provided.
[0117] In a second step, the data or a part of the data may be transformed through a hash function. A hash function may map multiple inputs to exactly one output. Known hash functions are, for example, SHA256, MD5, Bcyrpt, or RIPEMD.
[0118] In a third step, the hashed data or hash may be encrypted using the sender's private key. Such encryption of the data or hashed data ensures that the data is provided by the sender as the legitimate owner and not an unauthorized third party. This encryption process with the sender's private key is sometimes called signing. The additional use of a hash function can reduce the size of the data package sent over the network.
[0119] In a fourth step, the data and the encrypted hash are encrypted using the recipient's public key, and in a fifth step, the encrypted data package containing the data and the signature is provided for transmission to the sender.
[0120] Figure 7b shows an example of a decryption process for the encrypted data package of figure 7a. In a first step, the encrypted data package may be provided. Furthermore, the sender's public key and the receiver's private key may be provided.
[0121] In a second step, the data package can be decrypted using the recipient's private key, thus ensuring the confidentiality of the data transmission.
[0122] In a third step, the hash of the decrypted data package can be decrypted using the sender's public key, thus resolving the sender's signature and verifying the authenticity of the sender.
[0123] In a fourth step, the decrypted data may be hashed from the decrypted data. In a fifth step, the decrypted hash and the hash from the decrypted data may be compared. If the hashes match, the data was transmitted in confidence and has not been corrupted. If the hashes do not match, the data has been corrupted.
[0124] 7a and 7b merely illustrate the principle of the authentication mechanism based on cryptographic signature. Several different authentication mechanisms exist and several variations can be implemented. Further examples of authentication mechanisms include biometric authentication such as Touch ID or Face ID, FIDO security keys, push authentication, biometric and device binding mechanisms, magic links, any combination thereof, or any other passwordless authentication mechanism known to those skilled in the art.
[0125] FIG. 8 illustrates an exemplary method for authorizing access to chemical data. In a first step, a set of authorization rules for the first decentralized identifier and the chemical product data associated with the first decentralized identifier is provided. The set of authorization rules may include usage instructions that specify a usage policy for an entity accessing the chemical product data associated with the decentralized identifier. The set of rules may include one or more local rules that are specific to a particular location. The one or more local rules may be based on the location where the decentralized identifier was generated, the location where the data providing service was implemented, the location where the data consuming service was implemented, or a combination thereof.
[0126] The one or more sets of local rules may be based on a location or a data providing service provided by a data providing service. The location may refer to a jurisdiction and the local rules may relate to legal requirements related to the supply of chemicals or chemical materials. For example, access to chemical data may be provided via authorization rules, which may include jurisdiction rules or local rules. The chemical data may include attestations of analytical data related to laboratory measurement data obtained from samples of raw materials, chemical products, components, component assemblies, or end products, and / or combinations thereof. The attestations of analytical data may be associated with two or more raw materials or chemical products, such as those used to manufacture a component. The attestations of analytical data may be associated with two or more raw materials or chemical products, such as those used to manufacture a plurality of components to assemble a component assembly or end product. The chemical data includes chemical product safety data related to hazards of mixtures of physical entities of a substance or product, such as raw materials, chemical products, components, component assemblies, or end products, and / or combinations thereof. The chemical product safety data may be associated with two or more raw materials or chemical products, such as those used to manufacture a component. The chemical product safety data may be associated with two or more raw materials or chemical products, such as those used to manufacture a plurality of components to assemble a component assembly or end product. The chemical data may include chemical product declaration data related to a physical entity of a product, such as a raw material, a chemical product, a component, a component assembly, or an end product, and / or combinations thereof. The chemical product declaration data may be associated with two or more raw materials or chemical products, such as those used to manufacture a component. The chemical product declaration data may be associated with two or more raw materials or chemical products, such as those used to manufacture multiple components to assemble a component assembly or end product.
[0127] In a second step, data associated with the second decentralized identifier or the second decentralized identifier of the accessing entity is provided. Based on the data of the second decentralized identifier or the second decentralized identifier of the accessing entity, an authorization rule for the chemical product data associated with the first decentralized identifier is selected. The authorization rule may include computer executable instructions for permitting, denying, or modifying the chemical product data. The authorization rule may be associated with each data point of the chemical product data or a set or class of chemical product data. The selected authorization rule may be stored for application to the chemical product data. Such authorization rules may be applied before or at the time of a data transaction. The selected authorization rule may be bound to the chemical product data, individual data points or classes of chemical product data for application to the chemical product data. The product data may include data related to different classes of product data, such as chemical product data. For example, the data chemical product data may itself include different classes of chemical product data. In one embodiment, at least one class of chemical product data includes chemical product data, such as data required by regulation or regulatory data of chemical products.
[0128] The selected authorization rule may be applied to the chemical data associated with the first decentralized identifier. The selected authorization rule may be applied prior to accessing the chemical data. The selected authorization rule may be applied at runtime when accessing the chemical data.
[0129] The chemical data associated with the first decentralized identifier is provided according to the selected authorization rules. The authorization rules may include, for example, local rules specific to a particular location, the location being related to a jurisdiction, and the local rules of the location being related to legal requirements related to supplying chemicals. The set of authorization rules may include at least one regulatory instruction configured to provide access to the chemical data related to regulatory requirements for supplying chemicals. The set of authorization rules provided may be associated with the decentralized identifier of the accessing entity, and the authorization rules may include computer-executable instructions to allow access to the chemical data associated with the first decentralized identifier, deny access to the chemical data associated with the first decentralized identifier, modify access to the chemical data associated with the first decentralized identifier, or modify the chemical data associated with the first decentralized identifier. The authorization rules may be associated with each data point of the chemical data or a class of chemical data, and the selected authorization rule is bound to the chemical data, a class of chemical data, an individual data point, or a combination thereof. The set of authorization rules may include one or more prescribed rules related to obligations of the data consumption service associated with the second decentralized identifier. The set of authorization rules may include one or more prescribed rules related to discharge data, production data, recycle content data, biobased content data, origin data, working condition data, or combinations thereof. The set of authorization rules may include one or more processing rules related to processing of the discharge data, production data, recycle content data, biobased content data, origin data, working condition data, or combinations thereof by the data consumption service associated with the accessing entity's decentralized identifier. The set of authorization rules may include one or more aggregation rules related to an invoice for material data provided by a supplier data provision service or an invoice for raw material data provided by a supplier data provision service.
[0130] FIG. 9 shows a schematic diagram of providing chemical product passports from a data provisioning service via an IDS architecture.
[0131] The data providing service may provide chemical product data to the data consuming service. The following IDS components may be executable components in the "IDS infrastructure" shown in FIG. 8: data connector, app store, identity provider, vocabulary provider, broker, and clearinghouse. Data may be exchanged between the data owner interface and the data user interface via the data providing service and the data consuming service. The data providing service and the data consuming service are each connected to a data connector to enable secure and reliable data exchange. The data provided by the data owner interface may be associated with an authorization mechanism, such as a usage policy that specifies authorization rules, such as data usage rules. The exchange or sharing of data may be performed according to the prescribed authorization mechanism, as described in relation to FIG. 7. The data provided by the data owner interface via the data providing service may be accessed by the data user interface according to the usage policy associated with the data provided by the data owner interface.
[0132] A participant acting as a data owner may take on the role of a data provider. However, there may be cases where the data provider does not coincide with the data owner (e.g., when the data is technically controlled by an entity other than the data owner, such as when an enterprise uses external services to provide the data, or when data management activities are handed over to a data fiduciary). If the data owner does not simultaneously act as a data provider, the only activity of the data owner is to authorize the data provider to make the data available for use by the data consumer interface.
[0133] The data provider interface makes data available for sharing or exchange between data owners and data consumers. To facilitate data requests from the data consumer interface, the data provider interface may provide metadata to a broker service provider (described below) describing the dataset, e.g., syntax, serialization, and / or semantics of the data source, provider description, consumer description, etc. The broker service provider is not required for the data consumer interface and data provider interface to establish a connection.
[0134] Exchanging or sharing data with a data consumer interface is not necessarily the only activity of a data provider. A data provider interface may record details of successful (or unsuccessful) completion of a transaction in a clearinghouse (see below). A data provider interface may facilitate billing or dispute resolution. Additionally, a data provider interface may use data apps to check, enrich, or transform data.
[0135] The data consumer interface may receive data from the data provider interface. The data consumer interface may be a mirror entity of the data provider interface. The executable components of the data provider interface may be mirrored by the data consumer interface. Before a connection to the data provider interface can be established, the data consumer may explore existing data sets by querying a broker service provider. The broker service provider may provide the metadata required by the data consumer interface to connect to the data provider. Such metadata may include the identity and / or authentication mechanism of the data provider interface. Alternatively or additionally, the data consumer interface may establish a connection to the data provider interface (i.e., with or without the involvement of a broker service provider). If the information to connect with the data provider interface is already known to the data consumer interface, the data consumer interface may request data (and corresponding metadata) directly from the data provider interface. Like the data provider interface, the data consumer interface may also log details of the success (or failure) of the data exchange transaction in a clearinghouse, use data apps to check, enrich, transform, etc. the data received, or use service provider interfaces to connect to the international data space (if it has not deployed the technology infrastructure to do so itself).
[0136] Just as a data owner is a legal entity that has legal control over its data, a data user is a legal entity that has the legal right to use the data owner's data as specified by a usage policy. In most cases, a data user is the same as a data consumer. However, there can be scenarios where these roles are assumed by different participants.
[0137] The Identity Provider may act as an agent. The Identity Provider may include services named Certification Authority (managing digital certificates of participants in the international data space), Dynamic Attribute Provisioning Service (DAPS, managing dynamic attributes of participants), Dynamic Trust Monitoring (DTM, continuous monitoring of network security and behavior). The Identity Provider may be responsible for issuing technical identities to parties approved to become participants in the international data space. The Identity Provider may be instructed to issue identities based on approved roles (mentioned above). The Identity Provider may also manage the PKI deployment. There are two separate PKI hierarchies, one for software signing (Software Signing Root CA) and one for IDS Connectors (Service Root CA). Entities are assigned either final certificates or sub / root CA certificates. The Identity Provider may act as an authentication and / or authorization service by incorporating DAPS.
[0138] Each IDS Connector may run different services and communicate with other IDS Connectors. Using PKI, the IDS Connector secures persistent storage of services and communication with other IDS Connectors. To verify PKI signatures (e.g., for authentication, authorization, or downloaded data apps), the IDS Connector stores trusted root certificates (Service Root CA and Software Signing Root CA) so that their integrity is preserved.
[0139] An app store may provide data apps that can run inside an isolated container of an IDS connector. These are applications that can be deployed in an IDS connector to perform tasks such as data transformation, aggregation, or analysis. App stores can be provided by IDS members and must be separately certified under the IDS standard. App stores have a service sub-CA. The International Data Spaces Consortium signs a Certificate Signing Request (CSR) to authorize an app or app store. The CSR identifies the app store and allows it to sign a service CSR from an IDS connector requesting an app. The IDS connector creates a key pair for every app it downloads. The private key protects the app's persistent data. When an app is downloaded from an app store, the IDS connector uses the public key to create a CSR. The app store signs the CSR and issues a certificate. The IDS connector uses this certificate to verify that the app is running and valid.
[0140] A vocabulary provider may manage and provide "vocabularies" (including ontologies, reference data models, metadata elements) that can be used to annotate and describe datasets. Vocabulary providers provide these (domain-specific) vocabularies and their references to the IDS information model, which is the basis for describing data sources.
[0141] Brokers may be used as intermediaries that store and manage information about data sources available in the international data space. The role of a broker is centralized but non-exclusive, so that multiple brokers may exist around at the same time (e.g. for different application domains). An organization that provides broker services in the international data space may simultaneously play other intermediary roles (e.g. clearinghouse or identity provider, see below). Broker activities may include receiving and providing metadata. Brokers must provide an interface to data provider interfaces to send metadata. The metadata may be stored in a structured manner in an internal repository that is queried by data consumers. The core of the metadata model may be specified by the international data space, but brokers may extend the metadata model to manage additional metadata elements. After a broker provides metadata for a particular data provider interface to a data consumer interface, its job is completed (i.e. it is not involved in the subsequent data exchange process).
[0142] A clearinghouse may be an intermediary that provides settlement and settlement services for financial and data sharing or exchange transactions. In the international data space, settlement activities are separated from broker services because these activities are technically different from maintaining metadata repositories. As already mentioned above, it may still be possible for the two roles of "clearinghouse" and "broker" to be played by the same organization, since both roles of clearinghouse and broker are required to act as a trusted intermediary between data provider interfaces and data consumer interfaces. Clearinghouses and brokers may include distributed ledgers to record metadata from data services. Clearinghouses record activities performed in the course of data exchange. After the data exchange or part of it is completed, both data provider interfaces and data consumer interfaces confirm the data transfer by recording transaction details in the clearinghouse. Based on this recorded information, transactions may be checked or charged. Recorded information may also be used for conflict resolution (e.g., to clarify whether a data package was received by a data consumer or not). Clearinghouses may provide reports on performed (recorded) transactions, such as charges, conflict resolution, etc.
[0143] FIG. 9 shows a schematic diagram of the authentication process between an IDS connector 1 residing in an IDS data provider domain and an IDS connector 2 residing in an IDS data consumer domain.
[0144] In a typical scenario, Connector 2 is associated with a third party seeking to access chemical data associated with a chemical data owner's Connector 1. To provide data from IDS Connector 1 in an IDS data provider domain to IDS Connector 2 residing in an IDS data consumer domain, the following authentication protocol may be applied.
[0145] A connector is associated with a certificate issued by a device CA. This certificate may act as a root of identity. A connector may include multiple authentication mechanisms or identity tokens, for example, a device certificate (X.509v3), a TLS connection certificate (X.509v3), and a "dynamic attribute token" (OAuth access token).
[0146] If the IDS Connector 2 has access to data in the data service of the IDS Connector 1, an access token may be presented by the IDS Connector 2. For this purpose, the IDS Connector 2 may present an X.509 device certificate to a DAPS (Dynamic Attribute Provisioning Service) in the IDS infrastructure in order to receive a Dynamic Attribute Token (DAT). The "Dynamic Attribute Token" may comprise an OAuth access token signed by the Dynamic Attribute Provisioning Service (DAPS). The DAT may be implemented as a JSON Web Token (JWT) containing a cryptographic signature of the DAPS and / or an indication of the verified or unverified identity attributes of the Connector 2. In this context, dynamic refers to a short-lived token containing attributes held by the IDS Connector 2. Such a short-lived token may be valid only for a limited number of transactions, e.g. one transaction. The DAPS may validate the device certificate with the Device Sub-CA prior to issuing the DAT.
[0147] The following steps may be performed by Connector 2 to receive the DAT. A: Call the token endpoint DAPS using a client certificate (X.509 certificate). B: Issue JWT-1{attribute_list,client_id,aud:idsAS:*}.
[0148] After receiving the DAT, a TLS tunnel can be established by using the same X.509 device certificate to request a TLS connection certificate, which can be requested automatically by IDS Connector 2 by interacting with an ACME server, which can be integrated into a TLS sub-CA present in the IDS infrastructure (not shown).
[0149] In one example, an identity token may be requested by Connector 2 using the authorization service of Connector 1. This step may be optional. An identity token may be requested, for example, if some access token (At) is used. To request an identity token, Connector 2 submits a DAT at the authorization service of Connector 1 and requests an identity token. The authorization service in IDS Connector 1 uses a database or a rules engine to determine whether an identity token should be provided to Connector 2.
[0150] The following steps may be performed by Connector 2: Submit JWT-1 to the Connector 1 authentication service. Request JWT-2{scope:C1 / PS}. Use the rules engine for access decisions and issue JWT-2{aud:C1} at Connector 1. Provide JWT-2 to Connector 2.
[0151] Connector 1 may provide an identity token to Connector 2. Connector 2 submits the identity token and optionally a DAT via IDSCP (IDS communications protocol) to request access to data in the data service of IDS Connector 1. If no identity token needs to be requested, Connector 2 submits the DAT to Connector 1 to request access to data in the data service of Connector 1 via IDSCP (IDS communications protocol).
[0152] Connector 1 may validate the DAT and provide access to the data. 10 shows an exemplary implementation of an authorization mechanism using usage control data flow. Such an example may be implemented in the International Data Space (IDS) framework described in FIG.
[0153] After access to the IDS connector associated with the data providing service is granted according to the procedure described in relation to Fig. 9, authorization may follow based on authorization rules. For authentication purposes, the decentralized identifier of the accessing entity or data associated with the decentralized identifier is made available to the connector IDS connector.
[0154] Usage control data flow is one way of enforcing authorization rules or usage policies on data exchange or sharing. Usage control can be achieved by binding usage policies to the data being exchanged, subsequently controlling how the data is processed, aggregated, or forwarded to other endpoints.
[0155] To enforce usage policies, data flows may be monitored and potentially intercepted by control points. Intercepted data flows may be passed to a decision engine to request permission, denial, or modification of the data flow. Decisions may be based on evaluation of usage policies by the decision engine. Data usage transactions may trigger interception and evaluation.
[0156] The usage policies may be provided to the decision engine by a policy manager to provide a set of authorization rules for the chemical data associated with the decentralized identifiers of the IDS connector. The usage policies may be stored independently of the data. The policy manager may reside in the IDS connector and / or in the clearinghouse to enforce the usage policies.
[0157] Based on the decentralized identifier of the accessing entity or the data associated with the decentralized identifier, authorization rules for chemical product data associated with the decentralized identifier can be selected for enforcement. Enforcement mechanisms can work differently (e.g., affect different system actions) for different systems or technologies. Abstract policies can have different instantiations. Usage policies can be instantiated in target systems. In another example (not shown), usage policies can be attached to data (also called sticky policies). Sticky policies are one way of dealing with the distribution of usage restrictions. In this approach, machine-readable usage policies can be attached to data when the data is exchanged. Different realization possibilities also exist. For example, data can be encrypted and can only be decrypted if adherence to usage restrictions is guaranteed.
[0158] The usage policy may include additional information provided, for example, by a policy information registry, such as information regarding previous data usage or the geographic location of the entity, pre- or post-conditions that must be maintained before (e.g., integrity checks) and after (e.g., data item is deleted after usage) decision making, and situational information such as on-conditions that must be maintained during usage (e.g., only during business hours).
[0159] If the decision depends on additional information, the decision engine or control point may request the additional information from the policy information registry. The policy information registry information may provide the requested additional information. In addition, the policy information registry may be used to obtain context information for or about the intercepted system action (e.g., data flow information, geolocation of the requesting device). For example, the policy information registry may be used to resolve a supplier's ID to a postal address and a postal address to GPS coordinates.
[0160] The policy enforcer may be used to perform additional actions based on policy rules, such as sending notifications via email when data is used or writing to a system log. Actions may be triggered, for example, by sending instructions related to the desired additional action from the control point to the policy enforcer after the control point receives the additional information from the policy information system. The policy enforcer may perform the indicated action and confirm to the decision engine that the action was successful.
[0161] After the decision engine receives confirmation from the policy enforcer, it may forward the decision to the requesting control point. The decision may include allowing the data flow, denying the data flow, or modifying the data flow. The decision may be implemented by the control point. The selected authorization rule may be applied to the chemical product data associated with the decentralized identifier. The chemical product data associated with the decentralized identifier may be provided according to the selected authorization rule.
[0162] Usage control enforcement may be implemented in the IDS connector. At runtime, usage control enforcement prevents the IDS connector from handling data in an undesirable manner, for example, by forwarding personal data to a public endpoint. The application of usage policies related to usage enforcement control in a data provider connector or a data consumer connector may depend on the usage policy. In a data provider connector, the usage policy may specify how often and when (e.g., only during business hours) the data may be accessed, or that the data must be filtered or masked (e.g., anonymized) before leaving the enterprise. The usage policy in a data provider connector may include obligations to the data consumer. The technical enforcement may be handled by the control point or the policy enforcer depending on the usage restrictions. For example, limiting data flow to a specific target system to ensure correct usage purposes may be handled by the control point, while deleting data in a storage infrastructure external to the connector may be handled by the policy enforcer.
[0163] Usage control enforcement may be implemented in the storage infrastructure. The storage infrastructure may be any kind of storage for persistent data, such as a file system or a database. The storage infrastructure may be used without modification, but any use of the data may be handled by the IDS connector. In certain cases, this may lead to a bottleneck. Usage control may be implemented by encrypting the data in an IDS connector connected to the storage infrastructure before transferring the data to the storage infrastructure. Use of the data is only possible by decrypting the data using the IDS connector. Thus, any use is controlled by the IDS connector. In such cases, usage restrictions such as lifetime or time constraints on the data may be implemented by deleting cryptographic keying material. Additionally or alternatively, the storage infrastructure may include a usage control enforcement component that monitors and / or controls the use of the data.
[0164] Usage control enforcement may also be implemented in applications such that data flow within the application may be controlled to adhere to usage policies. Similar to the storage infrastructure, control points may be integrated into the application to control data flow.
[0165] By implementing the above-mentioned usage control in the IDS, the following security requirements can be achieved, which cannot be achieved using conventional access control: - Confidentiality: Sensitive data must not be transferred to nodes that do not have the respective clearance. - Integrity: Critical data should not be modified by untrusted nodes, because otherwise the integrity of the critical data cannot be guaranteed. - Lifetime: A prerequisite for persistent data is that it must be deleted from storage after a given period of time. -Anonymization by Aggregation: Personal data must be made available to non-trusted parties only in the aggregate. A sufficient number of separate records must be aggregated to avoid personal identification of each individual record. -Anonymization by substitution: Data that allows the identification of an individual (e.g. faces in camera images) must be replaced with appropriate substitutes (e.g. blurred) to ensure that an individual cannot be identified from the data. -Separation of duties: Two data sets from competing companies (e.g., two chemical industries) should never be aggregated or processed by the same service. - Scope of use: Data may only serve as input for data pipes within the connector, but should never leave the connector towards an external endpoint.
[0166] 12 to 14 show different exemplary configurations of a product passport based on a digital identifier, including different parent, child, grandchild, and other relationships of the product passports generated up to the final product in the chemical value chain.
[0167] FIG. 12 shows the individual configurations of different product passports generated in the chemical value chain. Individual product passports can be generated for multiple product stages in the chemical value chain. The generation of the product passport can include providing a decentralized identifier and authentication mechanism for each of the multiple product stages. The product passports of the multiple product stages can be based on cryptographic signatures. For example, the product passports of the multiple product stages can be linked through hash values based on different data sets. As shown in FIG. 12, hash 1 can be based on data in the raw material passport, hash 2 can be based on data in the chemical product passport, and hash 3 can be based on data in the raw material passport + data in the chemical product passport. Further linking can be done for other combinations of product passports up to hash n, resulting in linking of product passports up to the final product passport. Linking through hashes of cryptographic signatures is just one example of linking. Other examples include aggregation permissions on different ranges of data that can be embedded in child passports, public key aggregation with different cryptographic signatures, or service endpoint aggregation with different links.
[0168] FIG. 13 shows the composition of the different product passport actors generated in the chemical value chain. For the final product, a final product passport is generated. For multiple further product stages in the chemical value chain, individual product passports may be generated and embedded or linked to the final product passport. The generation of the product passport may include providing a decentralized identifier and authentication mechanism for each of the multiple product stages. The product passports of the multiple product stages may be based on cryptographic signatures. For example, the product passports of the multiple further product stages may be linked through hash values based on different data sets. As shown in FIG. 13, hash 1 may be based on data in the raw material passport, hash 2 may be based on data in the chemical product passport, and hash 3 may be based on data in the raw material passport + data in the chemical product passport. Further linking can be done for other combinations of product passports up to hash n, resulting in linking of the product passports up to the final product passport. Linking through hashes of cryptographic signatures is just one example of linking. Other examples include aggregation permissions on different ranges of data that may be embedded in child passports, public key aggregation with different cryptographic signatures, or service endpoint aggregation with different links.
[0169] FIG. 14 shows a fully embedded configuration of different product passports generated in the chemical value chain. Individual product passports can be generated for multiple product stages in the chemical value chain. The generation of the product passport can include providing a decentralized identifier and authentication mechanism for each of the multiple product stages. The product passports of multiple product stages can be based on cryptographic signatures. For example, the product passports of multiple product stages can be linked through hash values based on different data sets. As shown in FIG. 14, hash 1 can be based on data in the raw material passport. Hash 2 can be based on data in the raw material passport and the chemical product passport. Further linking can be done for other combinations of product passports up to hash n, resulting in linking of product passports up to the final product passport. Linking through hashes of cryptographic signatures is just one example of linking. Other examples include aggregation permissions on different ranges of data that can be embedded in child passports, public key aggregation with different cryptographic signatures, or service endpoint aggregation with different links.
[0170] 12 to 14 show different exemplary configurations of a product passport based on a digital identifier, including different parent, child, grandchild, and other relationships of the product passports generated up to the final product in the chemical value chain.
[0171] FIG. 12 shows the individual configurations of different product passports generated in the chemical value chain. Individual product passports can be generated for multiple product stages in the chemical value chain. The generation of the product passport can include providing a decentralized identifier and authentication mechanism for each of the multiple product stages. The product passports of the multiple product stages can be based on cryptographic signatures. For example, the product passports of the multiple product stages can be linked through hash values based on different data sets. As shown in FIG. 12, hash 1 can be based on data in the raw material passport, hash 2 can be based on data in the chemical product passport, and hash 3 can be based on data in the raw material passport + data in the chemical product passport. Further linking can be done for other combinations of product passports up to hash n, resulting in linking of product passports up to the final product passport. Linking through hashes of cryptographic signatures is just one example of linking. Other examples include aggregation permissions on different ranges of data that can be embedded in child passports, public key aggregation with different cryptographic signatures, or service endpoint aggregation with different links.
[0172] FIG. 13 shows another configuration of different product passports generated in the chemical value chain. For a final product, a final product passport is generated. For multiple further product stages in the chemical value chain, individual product passports may be generated and embedded or linked to the final product passport. The generation of the product passport may include providing a decentralized identifier and authentication mechanism for each of the multiple product stages. The product passports of multiple product stages may be based on cryptographic signatures. For example, the product passports of multiple further product stages may be linked through hash values based on different data sets. As shown in FIG. 13, hash 1 may be based on data in the raw material passport, hash 2 may be based on data in the chemical product passport, and hash 3 may be based on data in the raw material passport + data in the chemical product passport. Further linking can be done for other combinations of product passports up to hash n, resulting in linking of product passports up to the final product passport. Linking through hashes of cryptographic signatures is just one example of linking. Other examples include aggregation permissions on different ranges of data that may be embedded in child passports, public key aggregation with different cryptographic signatures, or service endpoint aggregation with different links.
[0173] FIG. 14 shows a fully embedded configuration of different product passports generated in the chemical value chain. Individual product passports can be generated for multiple product stages in the chemical value chain. The generation of the product passport can include providing a decentralized identifier and authentication mechanism for each of the multiple product stages. The product passports of multiple product stages can be based on cryptographic signatures. For example, the product passports of multiple product stages can be linked through hash values based on different data sets. As shown in FIG. 14, hash 1 can be based on data in the raw material passport. Hash 2 can be based on data in the raw material passport and the chemical product passport. Further linking can be done for other combinations of product passports up to hash n, resulting in linking of product passports up to the final product passport. Linking through hashes of cryptographic signatures is just one example of linking. Other examples include aggregation permissions on different ranges of data that can be embedded in child passports, public key aggregation with different cryptographic signatures, or service endpoint aggregation with different links.
[0174] The configurations shown in Figures 12 to 14 relate to product passports generated in the chemical value chain up to the final product. Similarly, product passports generated in the recycling chain from the final product to the recycler can also be linked. Furthermore, product passports generated in the chemical value chain up to the final product and in the recycling chain from the final product to the recycler can also be linked. In this way, the circularity of products, especially materials, can be virtually represented and tracked.
[0175] FIG. 15 illustrates an example of a production facility that produces a chemical product associated with a chemical product passport.
[0176] The production facility shown in FIG. 15 may produce chemical products. The production facility may produce organic chemical products, for example, obtained by reacting organic chemical reactants. The production facility may include one or more production plants. For example, a production facility for producing chemical products may include at least one precursor / intermediate production plant.
[0177] The physical inputs to a production facility may include materials such as raw materials, intermediate materials, or components to be assembled. The raw materials may be unprocessed raw materials or recycled raw materials.
[0178] The physical input may be associated with a decentralized identifier as described above. The physical input may be registered with the production facility. Registering may include providing a decentralized identifier associated with the physical input. Providing the decentralized identifier may include reading a physical identifier element physically tied to the physical input as described above. Providing the decentralized identifier may include accessing a database with decentralized identifiers and fetching the decentralized identifier associated with the physical input.
[0179] Based on the decentralized identifier provided, chemical product data associated with such decentralized identifier may be accessed. Access may be granted through authentication and authorization based on authentication and authorization information associated with the decentralized identifier. Based on the decentralized identifier, chemical product data such as chemical product declaration data, chemical product safety data, certificate of analysis data, emission data, product carbon footprint data, product environmental footprint data, chemical product specification data, product information, technical application data, production data, performance data, quality data, material composition data, recyclate content data, or combinations thereof may be accessed. The chemical product data may be accessed through a data service associated with each decentralized identifier and requesting access to the chemical product data controlled by a physical input data owner. The data owner may be the producer of the physical input. The data service may include computer executable instructions operating at least in part in the decentralized computing environment. Such computer executable instructions may be based on authentication information, authorization information, and / or a Json Web Token (JWT) including a digital representation pointing to the chemical product data or a portion thereof. The digital representation may include endpoints for data exchange or sharing (resource endpoints) or endpoints for service interaction (service endpoints) that are uniquely identified via a communication protocol. The digital representation may be uniquely associated with a decentralized identifier that points to the chemical data or a portion thereof. The chemical data may be used in the manufacturing process of the production facility.
[0180] The production facility may produce a physical output based on one or more physical inputs. The physical output of the production facility may be associated with a physical identifier. The physical output of the production facility may be physically bound to the physical identifier element as described above. The physical identifier may be assigned to identifier information associated with the decentralized identifier. For such assignment, the physical identifier element may be read or a database with the physical identifier may be accessed. A request to provide the decentralized identifier may be triggered to assign the physical identifier to the decentralized identifier. In this manner, the decentralized identifier may be assigned to the physical output. Providing the decentralized identifier may include accessing a database with the decentralized identifier and associated information, such as authentication information. Providing the decentralized identifier may include accessing a decentralized service that provides the decentralized identifier and associated information, such as authentication information. In response to the request, a chemical passport may be generated that includes the decentralized identifier and data related to chemical product data of the chemical product. The data related to the chemical product data may include a representation, such as a pointer or link, to the chemical product data. The decentralized identifiers can be associated with data related to the chemical data of the physical output. The decentralized identifiers can further be associated, assigned or linked to the decentralized identifiers of the physical inputs. The chemical passports can be provided to the decentralized network for access by other participants or producers of the network. In this way, the chain of materials from input to output can be traceable and usable in further manufacturing steps without exposing the chemical data in an uncontrolled manner.
[0181] The above process steps may be performed via an operating system of the production facility. In this embodiment, the operating system includes a collector configured to collect chemical data and / or physical identifiers as described above. The collector may be configured to collect chemical data related to a chemical product or chemical data related to the production of a chemical product, the chemical product being linked to or provided with a physical identifier. The operating system may include, among other things, an ID reader configured to provide a physical identity of a physical input or a physical output as described above. The system may further include an assigner configured to assign a decentralized identifier and related information to the physical output as described above. Additionally, the operating system may include an ID provider configured to provide a decentralized identifier and related information as described above.
[0182] FIG. 16 illustrates another example of a production facility that produces a chemical product associated with a chemical product passport.
[0183] The process steps described in connection with FIG. 15 may be performed via an operating system of the production facility interacting with the assigner, collector, or reader, or ID provider. In this embodiment, the operating system may be communicatively connected to the production facility and the assigner, collector, ID reader, or ID provider. The operating system may be configured to provide chemical product data from the production facility. The operating system may include a collector configured to provide chemical product data from the production facility. The operating system may include an ID reader configured to read a physical identifier element physically bound to a physical input or a physical output. The assigner may be configured to assign a decentralized identifier and associated information to a physical identifier of the physical output, as described above in connection with FIG. 15. The ID provider may be configured to provide a decentralized identifier and associated information, as described above in connection with FIG. 15. The ID reader may be configured to provide a physical identifier of the physical input or physical output, as described above in connection with FIG. 15. The assigner, collector, ID reader, and / or ID provider may be configured as a decentralized service or application running over a decentralized network.
[0184] Figures 15 and 16 show just two example embodiments, and any combination of the system components shown in Figures 15 and 16 may be possible. For example, the ID reader may be configured as part of the operating system, while the ID provider and assigner may not be configured as part of the operating system.
[0185] Figure 17 shows an example of tracking materials from raw materials to final products in the production of chemical products. Figure 17 specifically shows an example of tracking materials in the production of chemical products.
[0186] To produce a chemical product, a raw material may be provided as a physical input. The raw material may include a precursor material. The raw material may include a raw material or a recycled material. The raw material may be associated with a decentralized identifier. The decentralized identifier may be associated with a digital twin of the raw material. The decentralized identifier may be associated with raw material data, such as tags for raw material or recycled material, material properties related to environmental impact, or material properties related to origin.
[0187] Chemical production may include a two-step process: 1) production of precursor material; 2) production of chemical product. To produce the precursor material, raw materials may be used as physical inputs. The precursor production operating system may access data related to the raw materials based on a decentralized identifier, e.g., a decentralized identifier from a raw material provider. Such data may be used to operate the production. For example, if the raw materials are recycled materials, a production step of purifying the recycle may be included. For example, if the raw materials are raw materials, the purification step may be omitted. The precursor material may be formed by co-precipitating the raw materials. Production data from precursor manufacturing may be stored and / or associated with the decentralized identifier.
[0188] In a second stage, precursor materials may be provided for producing chemical products. The precursor materials may include precursors produced by precursor production. The precursor materials may include recycled precursor materials or precursor materials produced by different entities. Such precursor materials may be associated with a decentralized identifier, via which data related to the precursor materials may be accessible.
[0189] The produced and packaged chemical products may be assigned a decentralized identifier and associated information as outlined above. Packaged electrode active materials may include a physical identifier element, such as a QR code, physically attached to the packaging. Such a physical identifier element may be assigned a decentralized identifier. The assignment of physical identifier elements and decentralized identifiers may be performed through an ID generator / assigner running locally in the decentralized and / or distributed system.
[0190] For example, the packaging line may include a detector that detects the physical identifier of each package. Based on such recognition, the chemical production operating system may request to provide a decentralized identifier, which may be assigned to the physical identifier. In response to the request, a chemical passport may be generated that includes the decentralized identifier as well as data related to the chemical product. In such generation, data related to the chemical product that was recorded before and / or during production of the chemical product may be collected or accessed. Such data may be provided by the chemical production operating system or a storage environment connected to the chemical production operating system. This may include data collected and stored during precursor material production.
[0191] The data related to the chemical product may include an identifier of a raw material used to produce the chemical product. The data related to the chemical product may include data related to a raw material accessible, for example, via a decentralized identifier of the raw material. The data related to the chemical product may include data related to a material makeup of the chemical product. The material makeup data may be related to a chemical composition of the chemical product. The material makeup data may specify at least one constituent of the chemical composition of the chemical product.
[0192] The data related to the chemical product may include data related to characteristics related to environmental burden, such as CO2 footprint or recycled content. For example, the data related to the chemical product may specify the recycled content of a component or raw material. Such recycled content may be directly associated with the decentralized identifier of the chemical product or may be indirectly associated with the decentralized identifier of the chemical product, for example, via a decentralized identifier of a raw material or precursor material. The data related to the chemical product may include data related to production conditions provided by the operating system of the chemical product production. The data related to the chemical product may include data related to the operating conditions provided by the operating system of the chemical product production. The data related to the chemical product may include data related to the producer, such as producer name, producer brand, or producer identifier. The data related to the chemical product may include data related to the product, such as product name, product brand, or product identifier.
[0193] 15-17 show examples of providing access to data via one or more chemical product passports.
[0194] Through such a decentralized setup, various supply chain actors or producers to the end consumer may access data from supply chain actors or producers. Such access to data may include forwarding the data to the requester, or processing the data and forwarding the processing results to the requester. The example in FIG. 18 shows data that may be accessed based on a decentralized identifier of an end product (e.g., an automobile). Material data may be provided from various material providers who supplied materials for the production of the automobile. Environmental impact data may be aggregated and provided from various material providers involved in the production of the automobile. Lifetime data may be collected during the use of the end product and provided.
[0195] The example in FIG. 19 shows chemical product data provided by a chemical producer, precursor A data provided by a precursor A producer / provider, and precursor B data provided by a precursor B producer / provider.
[0196] The example in FIG. 20 shows environmental data such as total emissions data compiled from data provided by automotive component producers, production emissions data provided by automotive component producers, and recyclate content data provided by automotive component producers.
[0197] The disclosure has been described by way of example in conjunction with the preferred embodiment. However, other variations can be understood and implemented by those skilled in the art, by studying the drawings, the disclosure, and the claims, and by practicing the claimed invention. In particular, any steps specifically presented may be performed in any order, i.e., the invention is not limited to a particular order of these steps. Moreover, it is not required that different steps are performed at a particular location or at one node of a distributed system, i.e., each of the steps may be performed at different nodes using different equipment / data processing units.
[0198] In the claims and in this specification, the word "comprising" does not exclude other elements or steps, and the indefinite articles "a" or "an" do not exclude a plurality. "Can" or "may" refer to optional features. A single element or other unit may fulfill the functions of several entities or items recited in the claims. The mere fact that certain measures are recited in mutually different dependent claims does not indicate that a combination of these measures cannot be used in an advantageous embodiment.
Claims
1. 1. An apparatus for producing a chemical product associated with a chemical product passport, said apparatus comprising: a collector configured to collect recycle content data and / or biobased content data associated with the chemical product, the chemical product comprising a physical identifier; an assigner configured to assign the physical identifier to a decentralized identifier to generate the chemical product passport associated with the produced chemical product; a chemical passport generator configured to generate the chemical passport by receiving a request to provide at least the decentralized identifier associated with at least the recycle content data and / or biobased content data of the chemical product, and in response to the request, generating the chemical passport including the decentralized identifier and data related to the recycle content data and / or biobased content data of the chemical product; An apparatus comprising:
2. 1. An apparatus for generating a chemical product passport, said apparatus comprising: one or more computing nodes; and a method, when executed by the one or more computing nodes, for causing the apparatus to: receiving a request to provide a decentralized identifier associated with the recyclate content data and / or the biobased content data; generating, in response to the request, the chemical product passport including the decentralized identifier and data related to recycle content data and / or biobased content data; one or more computer-readable media having computer-executable instructions configured to cause An apparatus comprising:
3. The apparatus of claim 1 or 2, wherein the generation of the chemical product passport comprises providing the decentralized identifier associated with a physical entity of a chemical product.
4. The apparatus of claim 1 , wherein the decentralized identifier is a physical identifier associated with the chemical product or is assigned to the physical identifier.
5. The apparatus of claim 1 , wherein an identifier element comprising the physical identifier is physically attached to the chemical product.
6. 10. The apparatus of claim 1, wherein the data related to the recycle content data and / or biobased content data includes one or more digital representations that refer to the recycle content data and / or biobased content data or portions thereof.
7. The apparatus of claim 1 , wherein the chemical passport includes data associated with different classes of chemical data.
8. The apparatus of claim 1 , wherein the chemical product passport comprises at least one class of chemical product data including chemical product declaration data, chemical product safety data, and / or certificate of analysis data associated with a physical entity of the product.
9. 10. The apparatus of claim 1, wherein the chemical product passport includes at least one class of recyclable content data and / or bio-based content data including access-restricted recyclable content data and / or bio-based content data associated with a physical entity of the product.
10. 1. A computer-implemented method for producing chemical products associated with a chemical product passport, the method comprising: collecting recycle content data and / or biobased content data associated with the chemical product, the chemical product comprising a physical identifier; assigning the physical identifier to a decentralized identifier to generate the chemical product passport associated with the produced chemical product; generating the chemical product passport by receiving a request to provide a decentralized identifier associated with the limited recyclate content data and / or biobased content data of the chemical product, and in response to the request, generating the chemical product passport including the decentralized identifier and data related to the limited recyclate content data and / or biobased content data of the chemical product; A method comprising:
11. 1. A computer-implemented method for generating a chemical product passport, said method comprising: receiving a request to provide a decentralized identifier associated with the recyclate content data and / or the biobased content data; generating, in response to the request, the chemical product passport including the decentralized identifier and data related to recycle content data and / or biobased content data; A method comprising:
12. Use of a chemical product passport generated according to the method of claim 10 or 11 or by the device of claim 1 for further processing of a chemical product associated with said chemical product passport.
13. A chemical product associated with a chemical product passport, the chemical product passport comprising a decentralized identifier and data related to recycle content data and / or biobased content data generated according to the method of claim 10 or 11 or by the device of claim 1.
14. 12. A chemical product passport comprising a decentralized identifier and data relating to recycle content data and / or biobased content data, said chemical product passport being generated according to the method of claim 10 or 11 or by the device of claim 1.
15. A computer program comprising instructions arranged to perform the steps of the method according to claim 10 or 11 or to perform the steps of the apparatus according to claim 1 when executed on one or more computing nodes.