<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>If You Can't Enforce It, Contract It: Enforceability in Policy-Driven (Linked) Data Markets</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Simon Steyskal</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Sabrina Kirrane</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Vienna University of Economics and Business</institution>
          ,
          <addr-line>Vienna</addr-line>
          ,
          <country country="AT">Austria</country>
        </aff>
      </contrib-group>
      <fpage>63</fpage>
      <lpage>66</lpage>
      <abstract>
        <p>The Web of Data refers to a network of data, which is published from various data sources, distributed across di erent machines, and possibly interconnected as Linked (Open) Data. We assume that in the near future these machines will not only publish and consume data, but will also perform transactions in digital data markets without human intervention. For these digital data markets to succeed, it is crucial that published data is accessed and used in a manner, which is compliant with restrictions or regulations that have been de ned by data publishers. While it is fairly simple to express access policies using one of the numerous vocabularies available, the actual enforcement of those policies is rather di cult especially when taking dependencies among policies into account. In this paper, we demonstrate how ODRL can be used not only to represent access policies but also to specify access requests, o ers and agreements, and propose an approach to generate on-the- y contracts that govern all explicit and implicit non-enforceable policies.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>
        Simon Steyskal has been partially funded by the Vienna
Science and Technology Fund (WWTF) through project
ICT12-015 and by the Austrian Research Promotion Agency
(FFG) grant 845638 (SHAPE).
for the buying and selling of raw data, but also o ers
valueadded services derived from this data (e.g. data cleansing,
integration, analytics and visualisation). According to a
recent survey conducted by the European Research Center for
Information Systems (ERCIS) [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ], last year there was a slight
decrease in the number of service providers o ering access
to raw data and an increase in the provision of high quality
processed data. Here high quality processed data refers to
data that is represented in a manner which supports data
integration and analytics (i.e. accurate data represented in
manner which is interoperable, exible and extensible).
Additionally the survey highlighted that the number of service
providers that publish data using the Resource Description
Framework (RDF) is signi cantly less than the number that
publish data using the Extensible Markup Language (XML)
or Comma-Separated Values (CSV) / Excel Spreadsheets
(XLS). Given that interoperability, exibility, and
extensibility are cornerstones of the RDF data model and the fact
that the number of Linked Open Data publishers is
growing year-on-year, it begs the question what are the current
challenges for Linked Data Markets?. Although there are
a number of challenges with respect to data quality, data
lifecycle management and quality of service, in this paper
we focus speci cally on the challenges that relate to access
control and licensing.
      </p>
      <p>
        Moller and Dodds [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ], De Virgilio et al. [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ] and Kim et al. [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]
all propose systems that can potentially be used to realise
the LDM vision, however very little consideration if any is
given either to access control or machine readable licensing.
A number of authors have looked into using the Open
Digital Rights language (ODRL) to specify access constraints
and licensing [
        <xref ref-type="bibr" rid="ref1 ref8">1, 10, 8, 11</xref>
        ], however they do not focus on the
question of enforceability nor do they apply their work to
LDMs. In order to ll this gap in this paper, we present our
vision of a Policy-Driven (Linked) Data Market and discuss
how our framework can be used to cater for both
enforceable and non-enforceable ODRL policies. Our main
contributions can be summarized as follows, we: (i) propose
a work ow for PDLDM transactions and demonstrate how
ODRL can be used not only to represent access policies but
also to specify access requests, data o ers and agreements;
and (ii) present a framework which can be used to both
enforce access restrictions (in the case of enforceable policies)
and automatically generate license agreements (in the case
of non-enforceable policies). The remainder of the paper is
structured as follows:
We demonstrate how the ODRL can be used to express a
variety of policies in Section 2. Our strategy for dealing
with non-enforceable policies is presented in Section 3. We
discuss related work in Section 4. Finally, we conclude and
outline directions for future work in Section 5.
      </p>
    </sec>
    <sec id="sec-2">
      <title>2. EXPRESSING (LINKED) DATA MARKET</title>
    </sec>
    <sec id="sec-3">
      <title>POLICIES IN ODRL</title>
      <p>
        A Data Market is a platform where data and potentially
value-added services derived from the data are bought and
sold. Although data markets are not a new concept, with an
ever increasing amount of data available (social data,
sensor data, open data) and advances in information technology
we are seeing more and more online marketplaces appear [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ].
Data consumers can bene t from the high quality data, that
is aggregated and presented in a consistent format, making
it easier for then to nd and use the data they require. On
the other hand, data produces can outsource the cleansing,
hosting and discoverability of their data. While, both parties
can take advantage of value added services such as
integration and analytics.
      </p>
      <p>
        A Linked Data Market is a speci c type of marketplace,
which is built on top of the Linked Data Web (LDW) and
adheres to the Linked Data principles. In this paper, we
propose a Policy-Driven (Linked) Data Market (PDLDM)
where data requests, data o ers, access policies and
agreements are encoded in machine readable policies. The
various transactions required for contract negotiation are
represented using the work ow illustrated in Figure 1, which
consists of four major steps:
1. Make a request. A data transaction is initiated when a
data consumer issues a request to the data market, which
is subsequently forwarded to one or more data providers
who can potentially service the request.
2. Check applicable policies. On receipt of the request
the data provider retrieves the relevant access policies
(relevance is determined based on the data requested and
the credentials supplied by the data consumer).
3. Compose and o er contract. The data provider
generates a machine readable contract (known as an o er),
based on the explicit and implicit non-enforceable actions
that are associated with the request. The auto-generated
contract is subsequently o ered to the data consumer.
4. Accept contract. If the data consumer agrees to the
terms of the contract, an agreement between the data
consumer and the data publisher is generated and
persisted for accountability and compliance purposes.
The Open Digital Rights Language (ODRL) [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ] is a
comprehensive policy expression language that is suitable for
expressing ne-grained access restrictions, access policies,
as well as licensing information for Linked Data as shown
in [
        <xref ref-type="bibr" rid="ref1">1, 10</xref>
        ].
      </p>
      <p>An ODRL Policy is composed of a set of ODRL Rules and
an ODRL Con ict Resolution Strategy, which is used by
the enforcement mechanism to ensure that when con icts
among rules occur the system either grants access, denies
access or generates an error. In the sample policies that
follow we use an odrl pre x for &lt;http://w3.org/ns/odrl/2/&gt;
and an ex pre x for &lt;http://www.example.com/&gt;. Listing 1
demonstrates how ODRL can be used to specify two
policies, one that prohibits ex:provider1 to aggregate data from
ex:dataset1 and another that permits ex:provider1 to read
data from ex:dataset1.</p>
      <p>Listing 1: Policy governing access to ex:dataset1
ex:storedPolicy1 a odrl:Set ;
odrl:prohibition [ a odrl:Prohibition ;
odrl:assigner ex:provider1 ;
odrl:target ex:dataset1 ;
odrl:action odrl:aggregate ] ;
ex:storedPolicy2 a odrl:Set ;
odrl:permission [ a odrl:Permission ;
odrl:assigner ex:provider1 ;
odrl:target ex:dataset1 ;
odrl:action odrl:read ] .</p>
    </sec>
    <sec id="sec-4">
      <title>2.1 Selected ODRL Policy Types</title>
      <p>In this paper, we go beyond simple access control policies
and licenses and demonstrate how ODRL can be used to
represent access requests, data o ers and agreements.
Although all types of policies share the same general structure
(i.e. they all consist of a set of rules and a con ict resolution
strategy) they di er in terms of their scope.</p>
      <p>ODRL Request Policies contain rules that represent the
terms of usage sought by a data consumer. The policy
dened in Listing 2 can be used to specify that ex:consumer1
requests read access to ex:dataset1.</p>
      <p>Listing 2: Request read access to ex:dataset1
ex:request a odrl:Request ;
odrl:permission [ a odrl:Permission ;
odrl:assignee ex:consumer1 ;
odrl:target ex:dataset1 ;
odrl:action odrl:read ] .</p>
      <p>ODRL O er Policies contain rules that propose terms of
usage to data consumers. The policy de ned in Listing 3
o ers ex:consumer1 read access to ex:dataset1 if they agree
to a contract that prohibits them from aggregating the data.</p>
      <p>Listing 3: O er a contract for ex:dataset1
ex:offer a odrl:Offer ;
odrl:prohibition [ a odrl:Prohibition ;
odrl:assigner ex:provider1 ;
odrl:assignee ex:consumer1 ;
odrl:target ex:dataset1 ;
odrl:action odrl:aggregate ] .</p>
      <p>ODRL Agreement Policies represent contracts between
data producers and consumers that stipulate all terms of
usage. The policy de ned in Listing 4 states that ex:consumer1
has agreed to a contract that prohibits them from
aggregating the data from ex:dataset1.</p>
      <p>Listing 4: Construct an agreement for ex:dataset1
ex:agreement a odrl:Agreement ;
odrl:prohibition [ a odrl:Prohibition ;
odrl:assigner ex:provider1 ;
odrl:assignee ex:consumer1 ;
odrl:target ex:dataset1 ;
odrl:action odrl:aggregrate ] ;
odrl:permission [ a odrl:Permission ;
odrl:assigner ex:provider1 ;
odrl:assignee ex:consumer1 ;
odrl:target ex:dataset1 ;
odrl:action odrl:read ] .</p>
    </sec>
    <sec id="sec-5">
      <title>3. ENFORCING ODRL POLICIES</title>
      <p>Not only in PDLDMs but also in other domains, policies
and especially licenses are widely used to stipulate terms of
usage for assets. From a data producer perspective,
governance and ensuring compliance with non-enforceable
policies is di cult and can result in litigation, which can be a
lengthy and expensive processes. As such when it comes to
PDLDMs, it is necessary to make the distinction between
enforceable and non-enforceable policies and to propose a
framework that is capable of handling both. Another con- 5
sideration is the fact that data consumers might be less eager 6
to conduct business with data providers that o er complex 7
and verbose contracts (even if they able to comply with the 8
verbose policies), as opposed to data providers that keep 9
their contracts as concise as possible. As such, we propose 10
an access control strategy, which on receipt of a request ver- 11 end
i es that the requested access is allowed and auto-generates
contracts for non-enforceable policies that are as concise as
possible (i.e. minimal contracts).</p>
    </sec>
    <sec id="sec-6">
      <title>3.1 Enforceability of ODRL Policies</title>
      <p>A policy is enforceable if restrictions on actions de ned in
the policy can actually be controlled by a system. In the
context of ODRL we de ne an ODRL Action to be
controllable if its execution is permitted, or in the case where its
execution is prohibited compliance with the prohibition can
be controlled by the party who assigned the policy. Thus, a
policy is de ned to be enforceable, if all actions it aims to
prohibit are not part of the set of uncontrollable actions.</p>
    </sec>
    <sec id="sec-7">
      <title>3.2 Composition of Minimal Contracts</title>
      <p>We propose an algorithm which auto-generates contracts for
non-enforceable policies based on the work ow presented in
Section 2. A data request which is submitted by a data
consumer (Step 1) is matched against a set of stored
policies based on the credentials of the requesting party and the
actions relating to assets that they request (Step 2). This
matching process does not only consider actions explicitly
stated in the request but also those which are implicitly
related to them and the relevant con ict resolution strategy.
A contract which is composed and o ered (Step 3) is
represented as an ODRL O er Policy and incorporates a set of
requested permissions together with the terms of usage that
are retrieved from the data provider's stored policies.
Algorithm 1: Minimal Contract Composition Algorithm
Input: A set of applicable ODRL Policies P according to
a certain ODRL Request Policy R.</p>
      <p>Output: A minimal ODRL O er Policy O.
1 forall the policies in P do
2 forall the permission rules in do
3 add to the set of permission rules in O;
4 add all new uncontrollable actions to the set of
uncontrollable actions;
end
forall the prohibition rules in do
if prohibited action is uncontrollable then</p>
      <p>add to the set of prohibition rules in O;
end
end
Algorithm 1 (minimal contract composition) denotes the
composition procedure that is used to generate minimal ODRL
O er Policies. The algorithm takes an ODRL Request
Policy R and a respective set of applicable ODRL Policies P
retrieved from the policy store as input and iterates over all
policies in P .</p>
      <p>For each of the permission rules, the algorithm adds
all actions that become uncontrollable once the
permission has been granted to the overall set of
uncontrollable actions of the policy, and adds the permission
rule to the set of permission rules in O (line 1-5).
For each of the prohibition rules, the algorithm checks
whether the rule prohibits an action that is de ned
to be uncontrollable (line 6-7). If that is the case, the
respective prohibition rule is added to the ODRL O er
Policy O (line 8).</p>
      <p>The nal ODRL O er Policy O now consists of all
requested permissions a data provider is able to grant as well
as all non-enforceable prohibitions that are consequences of
these permissions. The ODRL O er Policy is subsequently
o ered to the data consumer that initiated the transaction
(Step 4). If the data consumer agrees to the terms of the
contract (i.e. accepts), an ODRL Agreement Policy is
generated from the ODRL O er Policy and persisted for
accountability and compliance purposes (Step 5).</p>
    </sec>
    <sec id="sec-8">
      <title>4. RELATED WORK</title>
      <p>
        Moller and Dodds [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ], De Virgilio et al. [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ] and Kim et al. [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]
all propose systems that can potentially be used to realise
the LDM vision. Moller and Dodds [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ] describe the Kasabi
information marketplace which is built on Linked Data
principles. Although data publishers are required to supply
licensing metadata, the authors do not detail how access to
data is restricted or how licenses are enforced. De Virgilio
et al. [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ] present Nyaya, a system which can be used to
manage di erent Semantic Web datasets. The authors
discuss how their system can support user de ned constraints,
however no speci c consideration is given either to access
policies or licenses. Kim et al. [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ] present an architecture
that can be used to support Linked Open Data as a
Service (LODaaS) however, they do not mention either access
control or licensing.
      </p>
      <p>
        When it comes to access control for RDF, broadly
speaking researchers have focused on representing existing
access control models and standards using semantic
technology; proposing new access control models suitable for open,
heterogeneous and distributed environments; and devising
languages and frameworks that can be used to facilitate
access control speci cation and maintenance. Kirrane et al.
[
        <xref ref-type="bibr" rid="ref6">6</xref>
        ] provide a comprehensive survey of existing access
control proposals for RDF. To date no speci c consideration
has been given to enforceable versus non-enforceable
policies. There has however been a number of digital rights
management proposals that use ODRL to model their
access control and licensing policies. Guth et al. [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]
demonstrate how ODRL can be used to exchange access control
information and present a framework, which can be used to
enforce access control policies. Cabrio et al. [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] discuss how
ODRL can be used to model licenses as opposed to access
rights. Rodriguez-Doncel et al. [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ] present a legal framework
for publishing and consuming Linked Data and provide an
overview of the existing vocabularies for rights and licensing
represented using RDF. Villata and Gandon [11] present a
framework which associates licensing terms with data and
auto-generates an aggregated license.
      </p>
      <p>In this paper, we go beyond existing proposals by
demonstrating how ODRL can be used to represent not only access
policies and licenses, but can also support contract
negotiation in the form of data requests, data o ers and data
agreements. We subsequent present a framework, which is
capable of dealing with both enforceable and non-enforceable
policies.</p>
    </sec>
    <sec id="sec-9">
      <title>5. CONCLUSIONS AND FUTURE WORK</title>
      <p>A digital data market is an online marketplace where data
and potentially value-added services such as data cleansing,
integration, analytics and visualisation are bought and sold.</p>
      <p>A LDM is a speci c type of marketplace, which is built on
top of the LDW and adheres to the Linked Data principles.
If LDMs are to succeed, it is crucial that data published is
accessed and used in a manner, which is compliant with access
restrictions and licenses. In this paper, we demonstrated
how ODRL can be used to specify auto-generated contracts.
We subsequently proposed a framework which can be used
to both enforce access restrictions and automatically
generate contractual agreements for non-enforceable policies. In
future work, we will investigate the various mechanisms that
can be used to ensure policy compliance and accountability.
We also plan to extend the existing framework to support
advanced contract composition and privacy protecting,
using a combination of negotiation and reasoning techniques.
[11] Serena Villata and Fabien Gandon. Licenses
compatibility and composition in the web of data. In The 2nd
International Workshop on Consuming Linked Data.
2012.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>Elena</given-names>
            <surname>Cabrio</surname>
          </string-name>
          , Alessio Palmero Aprosio, and
          <string-name>
            <given-names>Serena</given-names>
            <surname>Villata</surname>
          </string-name>
          .
          <article-title>These are your rights</article-title>
          .
          <source>In Proceedings of the 11th Extended Semantic Web Conference (ESWC)</source>
          ,
          <year>2014</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>Roberto</given-names>
            <surname>De Virgilio</surname>
          </string-name>
          , Giorgio Orsi, Letizia Tanca, and
          <string-name>
            <given-names>Riccardo</given-names>
            <surname>Torlone</surname>
          </string-name>
          .
          <article-title>Semantic Data Markets: a Flexible Environment for Knowledge Management</article-title>
          .
          <source>In Proceedings of the 20th ACM international conference on Information and knowledge management</source>
          ,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>Susanne</given-names>
            <surname>Guth</surname>
          </string-name>
          , Gustaf Neumann, and
          <string-name>
            <given-names>Mark</given-names>
            <surname>Strembeck</surname>
          </string-name>
          .
          <article-title>Experiences with the Enforcement of Access Rights Extracted from ODRL-based Digital Contracts</article-title>
          .
          <source>In Proceedings of the 3rd ACM Workshop on Digital Rights Management, DRM '03</source>
          ,
          <year>2003</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>Renato</given-names>
            <surname>Iannella</surname>
          </string-name>
          , Susanne Guth, Daniel Pahler, and Andreas Kasten. Odrl:
          <article-title>Open digital rights language 2.1</article-title>
          . W3C ODRL Community Group,
          <year>2012</year>
          . http: //www.w3.org/community/odrl/.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>Seonho</given-names>
            <surname>Kim</surname>
          </string-name>
          , Ivan Berlocher, and
          <string-name>
            <given-names>Tony</given-names>
            <surname>Lee</surname>
          </string-name>
          .
          <article-title>RDF based Linked Open Data Management as a DaaS Platform</article-title>
          .
          <year>2015</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>Sabrina</given-names>
            <surname>Kirrane</surname>
          </string-name>
          , Alessandra Mileo, and
          <string-name>
            <given-names>Stefan</given-names>
            <surname>Decker</surname>
          </string-name>
          .
          <article-title>Access control and the resource description framework: A survey</article-title>
          .
          <source>Technical Report</source>
          ,
          <year>2015</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>Knud</given-names>
            <surname>Mo</surname>
          </string-name>
          <article-title>ller and Leigh Dodds. The Kasabi Information Marketplace</article-title>
          .
          <source>In 21nd World Wide Web Conference</source>
          , Lyon, France,
          <year>2012</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>Victor</given-names>
            <surname>Rodriguez-Doncel</surname>
          </string-name>
          ,
          <article-title>Asuncion Gomez-Perez, and Nandana Mihindukulasooriya. Rights declaration in linked data</article-title>
          .
          <source>In The 3rd International Workshop on Consuming Linked Data</source>
          .
          <year>2013</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>Florian</given-names>
            <surname>Stahl</surname>
          </string-name>
          , Fabian Schomm, and
          <string-name>
            <given-names>Gottfried</given-names>
            <surname>Vossen</surname>
          </string-name>
          .
          <article-title>The Data Marketplace Survey Revisited</article-title>
          .
          <source>Technical report, Working Papers, ERCIS-European Research Center for Information Systems</source>
          ,
          <year>2014</year>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>