Original journal article · Extended web analysis
European Business Wallet and Market Role Credentials for DPP Access Control: The energy data-X Reference Case
How verifiable company identities, governed market roles and machine-readable policies enable secure access to Digital Product Passports, Battery Passports and European data spaces
Browse this paper
In brief
What does this research establish?
European Business Wallets and market-role credentials address different questions in restricted Digital Product Passport access. Legal-person authentication establishes which organisation is requesting access. A governed market-role credential establishes the capacity in which that organisation acts, who issued the evidence and whether it remains valid. A policy engine then evaluates those verified attributes, credential status, purpose, product scope and machine-readable access rules before a connector or DPP application permits an operation. This distinction matters when information is not public and access depends on statutory authority, a Person with a Legitimate Interest, contractual authority, consent or ecosystem governance. The energy data-X prototype provides a practical reference: authentic sources and authorised issuers supply verifiable evidence to a business wallet, while connector-side policy enforcement turns that evidence into an auditable access decision.
Key takeaways
- Authentication proves the organisation; a governed role credential proves the capacity in which it acts; policy determines what that role may do with a specific asset.
- energy data-X implements a federated trust chain from authentic sources and authorised issuers through European Business Wallet concepts to connector-side verification and policy enforcement.
- The project demonstrates role-based energy-data exchange and the Imbalance Settlement Quality use case; transfer to DPP, DBP and authority-access models is an architectural application, not proof that every future legal requirement is already satisfied.
- Regulation (EU) 2023/1542 separates public, authority-restricted and legitimate-interest battery-passport data, making current status, governed roles and purpose-limited policy central design concerns.
- The European Business Wallet remains a legislative proposal as of the research cut-off; its identity, credential, delegation and secure-exchange functions are nevertheless directly relevant to cross-border DPP access architecture.
- Existing sector trust such as the German Smart Metering PKI can coexist with wallet-based legal-person and role credentials rather than being displaced.
This web page is an extended, source-linked analysis. The attached journal PDF remains the primary source for the implemented energy data-X architecture and the authors' published claims.
Original publication and academic attribution
Published citation. Gößling, Jan-Niklas; Hoffmann, René; Kießling, Axel; Rohrbach, Daniel; and Stöcker, Carsten (2026). “The energy data-X data ecosystem: Cross-sector and BESS data exchange enabled by the European Business Wallet and market role credentials.” ENERGIEWIRTSCHAFTLICHE TAGESFRAGEN, Vol. 76, Issue 7-8, pp. 19–22.
The paper is a five-author industry and academic publication. It is not presented as a single-author Spherity paper. Its primary contribution is an implemented trust architecture for federated energy-data exchange, including legal-person identity, Market Partner IDs, governed market roles, connector-side policy checks and compatibility with existing technical trust infrastructures.
Why governed roles matter more than a login
The difficult part of restricted DPP access is not merely authenticating a user. It is establishing and continuously verifying the governed role and authority under which an organisation acts, then evaluating that evidence against machine-readable access policy.
| Control | Question answered | Typical evidence or component |
|---|---|---|
| Legal-person authentication | Which organisation is this? | Register-backed company credential, European Unique Identifier or comparable organisational evidence |
| Role verification | In which governed capacity is it acting? | Market Partner ID, market-role or professional-role credential |
| Authorisation | What may that role do with this asset? | Attribute-based or policy-based decision using role, purpose, scope and status |
| Policy enforcement | Is this operation allowed now? | Connector, DPP API or policy enforcement point |
| Provenance | Which trusted source supports the identity, role or data? | Authentic source, authorised issuer and auditable credential chain |
energy data-X: a working reference architecture for trusted sector data exchange
energy data-X is a German cross-sector energy-data ecosystem project. It builds on the German Energy Agency's Reference System for Data Exchange in the Energy Sector (Re4DE). The paper reports a federated model: data remains in participants' systems and is exchanged through connectors under common identity, trust, catalogue, contract and policy mechanisms. It is not a central data pool.
The project's official Identity & Trust material identifies Spherity as the lead for that federated service. In the reported implementation, Bundesanzeiger Verlag supplies register-backed company information as verifiable credentials. The paper describes how company identity, European Unique Identifier (EUID), EU Company Certificate (EUCC), Market Partner ID and market-role evidence can be combined and checked by a connector-side policy engine.
- Authentic sourceRegister or governed primary role source
- Authorised issuerCompany authentication and credential issuance
- European Business WalletLegal-person identity, roles and attestations
- Verifiable credentialIssuer-bound, status-checkable evidence
- ConnectorCredential request and presentation
- Policy engineContextual verification and decision
- Data or serviceAllow, constrain or deny the operation
The paper's “Imbalance settlement quality” case links metering data, a supplier or Balance Responsible Party (BRP), forecasting and flexibility provision. Test data passes through connectors, while verifiable identity and role evidence supports fine-grained authorisation. The reported result is evidence that regulated energy processes can be linked through a federated data ecosystem; it is not a claim that all production, legal or cross-border scenarios have been completed.
Existing technical trust can coexist with wallet trust
The German Smart Metering Public Key Infrastructure (SM-PKI) remains applicable to mandated sector processes. energy data-X combines that technical trust level with business-wallet credentials. The transferable pattern is:
sector or device technical trust + legal-person trust + governed role trust + policy enforcement
This layered model is relevant to industrial systems, BESS, Internet of Things deployments and future machine-to-machine transactions because it avoids forcing one credential system to replace every established sector control.
Market-role credentials are governed authorisation evidence
A role credential creates trustworthy authorisation only when governance exists behind it. The BDEW Codes system provides the German electricity-market reference: role-specific Market Partner IDs identify participants in governed market communication. energy data-X is important because it demonstrates how an established sector role model can be exposed as verifiable evidence and evaluated automatically.
- Authoritative source: a register or sector body maintains the underlying identity or role.
- Eligibility: documented criteria determine who may hold the role.
- Assignment and issuance: an authorised issuer binds the role to the identified legal person.
- Validity and runtime verification: relying systems verify issuer trust, attributes, dates and credential status.
- Monitoring and change: the authoritative role may change, be suspended or end.
- Status, renewal and audit: credential status or revocation mechanisms reflect those changes and preserve decision evidence.
Management of the underlying Market Partner ID or role and revocation of a corresponding verifiable credential are related but distinct processes. This page does not assert a specific BDEW credential-revocation procedure beyond what the authoritative source documents.
From energy-market roles to DPP and battery-passport access
Regulation (EU) 2023/1542, Articles 77 and 78 and Annex XIII, separates public battery-passport information from information reserved for notified bodies, Market Surveillance Authorities and the Commission, and information reserved for Persons with a Legitimate Interest (PLI). It also requires restricted access rights, data authentication, reliability, integrity, security and privacy.
| Actor | Typical reason | Legal or access category | Possible evidence | Example data or action |
|---|---|---|---|---|
| Market Surveillance Authority | Compliance investigation | Express statutory authority access | Authority identity, jurisdiction and mandate credential | Compliance test reports and regulated model data |
| Notified body | Conformity assessment | Express statutory access | Notified-body identity and scope credential | Test reports for the assessed product scope |
| European Commission | Regulatory oversight | Express statutory access | Institution and delegated-officer or system mandate | Authority and PLI information under Annex XIII |
| Customs authority | Border and import controls | ESPR/DPP Registry and customs-law context; exact data access depends on applicable law and implementation | Authority, jurisdiction and customs mandate | Registry status, identifiers and conformity evidence |
| Professional repairer or workshop | Safe repair and spare-part selection | Potential PLI aligned with repair purpose; final eligibility depends on Article 77(9) | Professional role, qualification and service mandate | Parts, dismantling, safety and relevant state information |
| Dismantler, recycler or remanufacturer | Preparation for reuse, remanufacturing or recycling | Purpose expressly reflected in Article 77(9) criteria; actor status still requires implementing detail | Facility/operator role and product-handling scope | Composition, disassembly, safety and lifecycle status |
| Second-life operator or marketplace | Residual-value and suitability assessment | Potential PLI; may also require contract or consent | Second-life role plus transaction mandate | State of health, use history and lifecycle status |
| BESS operator or maintenance provider | Safe operation and maintenance | Contractual/operational access unless a legal entitlement applies | Operator or service role, asset scope and delegation | Maintenance, safety, condition and service history |
| Independent aggregator or energy-market participant | Flexibility and market operation | Energy-market and contractual governance; not automatically a PLI | Market Partner ID, market role and asset mandate | Permitted operational data, not unrestricted passport content |
| Safety auditor | Risk and control assurance | Legal, contractual or ecosystem authority | Auditor qualification and engagement scope | Safety evidence and bounded audit records |
| Leasing, finance or insurance provider | Valuation, underwriting or claims | Contract, consent or another legal basis; not automatically a PLI | Service role, customer consent and product scope | Purpose-limited condition or event evidence |
Battery and BESS boundaries
From 18 February 2027, the battery-passport obligation applies to electric-vehicle batteries, light-means-of-transport batteries and industrial batteries above the statutory threshold. It can cover batteries used within commercial, industrial and grid-scale storage. The regulated passport object is the battery, however, not automatically the entire BESS or Grid Booster installation. A system-level BESS evidence model may also include inverters, controls, software, interfaces, operators and service history.
Role-controlled access is particularly important for detailed composition, dismantling and safety information, state of health, negative events, maintenance, second-life assessment, repair, repurposing, remanufacturing and recycling. Product scope, purpose and the current lifecycle status must be evaluated alongside the requester's role.
European Business Wallet + DPP: an emerging European trust architecture
The European Commission's COM(2025) 838 final proposes European Business Wallets under procedure 2025/0358(COD). As of 11 August 2026, the procedure remains ongoing. The Council adopted its negotiating position on 9 June 2026; the proposal is not enacted law.
The proposal's relevant primitives are European legal-person identification, trusted documents and attestations, delegation, electronic signatures and seals, and secure cross-border exchange. Those capabilities provide a strong policy bridge to DPP access, but they do not by themselves define a complete DPP-role taxonomy or access-control profile. Sector governance and product legislation still determine who may act and what may be accessed.
This produces a two-plane relationship:
- Business-wallet plane: who the organisation is, who represents it, which governed roles and mandates it can prove, and whether the evidence remains valid.
- DPP/DBP plane: which product or battery data exists, which access tier applies, and which read, write, update or reuse operation policy permits.
Credentials establish facts; policies determine access
A verifiable credential can prove attributes such as legal-person identity, market role, professional qualification or delegated authority. The W3C ODRL Information Model 2.2 is a W3C Recommendation for expressing permissions, prohibitions, duties and constraints concerning an asset. A policy engine evaluates the credential evidence, context and policy. A connector, DPP API or Policy Enforcement Point applies the decision.
Access = verified legal entity AND valid role credential AND authorised issuer AND acceptable status AND permitted purpose AND matching product policy
ODRL does not authenticate an organisation. Identity and role evidence, policy semantics, decision logic and enforcement remain separate controls. Attribute-Based Access Control (ABAC), Policy-Based Access Control (PBAC) and Zero Trust principles can be combined so that every request is evaluated using current evidence rather than a one-time account assignment.
- Role registerAuthentic source for legal or professional capacity
- Credential issuerGoverned binding of role to legal person
- Business walletControlled presentation of identity and authority
- DPP requestProduct, action, purpose and jurisdiction context
- Policy engineCredential, status and policy evaluation
- Access decisionPLI, authority, professional or contractual path
- DPP/DBP dataPurpose-limited read, write, update or reuse
Mitigating DPP authentication and authorisation risks identified by CIRPASS-2
CIRPASS-2 D4.1 and its Risks and Mitigations companion identify risks that can reduce DPP system value or harm stakeholders. energy data-X does not solve the complete DPP threat model. Its trust pattern can, however, address important authentication and authorisation classes.
| Risk class | Relevant control chain | Residual requirement |
|---|---|---|
| Impersonation or weak authentication | Register-backed legal-person credential, trusted issuer and wallet presentation | Identity proofing, key protection, phishing resistance and incident response |
| Incorrect or unauthorised access | Governed role credential, product context, least-privilege policy and enforcement | Correct policy design, testing and exception handling |
| Overly broad permissions | Purpose, action, product, jurisdiction and time constraints | Data minimisation and periodic entitlement review |
| Stale, suspended or invalid roles | Credential status, expiry, authoritative-source monitoring and runtime verification | Timely propagation and resilient status services |
| Compromised credentials | Revocation or suspension, wallet security and auditable re-issuance | Key compromise detection and recovery |
| Insufficient provenance | Authentic source, authorised issuer and decision evidence | Product-data provenance and transformation evidence |
| Weak auditability | Issuer, credential, policy version, context and decision receipt | Retention, privacy, evidence integrity and accountable review |
Portable trust across European data spaces
energy data-X and the Common European Energy Data Space
energy data-X is not the Common European Energy Data Space (CEEDS). It is a national and sector reference implementation. The Commission's current digitalisation-of-energy work emphasises interoperable and open digital solutions, data sovereignty and a pan-European energy data space. At European scale, participants need to prove not only organisational identity but also the regulated or governed capacity in which they act.
The reusable infrastructure is market-role governance, trusted issuers, credential status and policy-based verification. It can support distributed flexibility, smart and bidirectional charging, BESS, grid operation and sector coupling while allowing sector-specific rules to remain authoritative.
Why this matters for Catena-X
Catena-X EcoPass provides a sovereign automotive data-space foundation for Digital Product Passports and is advancing validation, verification, onboarding and governance. Portable, externally governed professional-role credentials can complement participant identity where DPP access depends on a recycler, repairer, remanufacturer, authority or other lifecycle role. This page does not claim that Catena-X currently uses the energy data-X role-credential implementation.
Why the same trust layer matters for Manufacturing-X
Manufacturing-X is a cross-industry initiative for sovereign, federated industrial data ecosystems. Cross-sector DPP access needs portable identity and role semantics so authority is not trapped in a single sector IAM silo. energy data-X shows how one regulated sector's role governance can become verifiable input to cross-company data exchange.
A practical trust architecture for authorities
A scalable European DPP system needs more than a separate “authority login.” It must determine which authority is requesting access, its jurisdiction and competence, whether an officer or system may act for it, the information category and purpose, and whether that mandate remains valid. Under the Ecodesign for Sustainable Products Regulation, the DPP Registry supports market-surveillance and customs functions. Credential-based authority access is an architecture proposal where legislation does not prescribe the exact implementation.
Implementation guide for DPP and data-space operators
- Define the legal and product object. Separate the regulated battery passport from the wider BESS, site or service architecture.
- Map access tiers. Distinguish public, statutory authority, legitimate-interest, contractual, consent-based and ecosystem-governed access.
- Name authentic sources. Identify who authoritatively maintains each legal-person, authority, professional or market role.
- Govern issuers and status. Specify eligibility, issuance, expiry, suspension, revocation, renewal and audit responsibilities.
- Separate identity, role and policy. Avoid encoding every entitlement in application-local user groups.
- Evaluate at runtime. Check issuer trust, credential integrity, status, purpose, product scope, jurisdiction and policy version for each sensitive operation.
- Enforce and record. Apply the decision at the connector or DPP API and retain proportionate, privacy-aware decision evidence.
- Test failure paths. Include stale roles, unavailable status services, compromised credentials, conflicting policies and revoked mandates.
Benefits include less bilateral role administration, reusable organisation onboarding, portable role evidence, dynamic status, policy changes without rebuilding every application, consistent access across DPP providers, stronger auditability, cross-sector interoperability and reduced dependence on proprietary IAM silos.
Forward path: delegated machines and AI agents
The paper recognises delegation to employees, machines, services and AI agents, but does not claim that autonomous agent delegation was implemented in the reported energy data-X use case. The logical extension is:
Legal Person → Enterprise or Business Wallet → Delegated Mandate → Machine or Agent Identity → Policy → Authorised Action
This becomes relevant when BESS optimisers, flexibility agents or industrial AI services request protected data or execute market actions. Each action then needs a verifiable principal, bounded mandate, applicable market role, policy context and decision evidence.
Evidence boundaries
- Implemented and reported: federated connectors, credential-based company and market-role evidence, policy-engine checks, compatibility with Smart Metering PKI, and the Imbalance Settlement Quality test case.
- Regulatory fact: the Batteries Regulation defines differentiated access tiers and requires an Article 77(9) implementing act; the European Business Wallet remains a proposal under the ordinary legislative procedure at the cut-off date.
- Architecture transfer: using governed role credentials and policy engines for DPP, DBP, PLI, authority and professional access.
- Future research: cross-border role governance, production-scale DPP authority access, BESS system passports, and delegated machine or AI-agent actions.
Primary sources
[1] Gößling, J.-N.; Hoffmann, R.; Kießling, A.; Rohrbach, D.; Stöcker, C. (2026). “The energy data-X data ecosystem: Cross-sector and BESS data exchange enabled by the European Business Wallet and market role credentials.” ENERGIEWIRTSCHAFTLICHE TAGESFRAGEN 76, Issue 7-8, pp. 19–22. Original PDF.
[2] energy data-X. Official project website and Identity & Trust federated-service brief.
[3] German Energy Agency. Reference System for Data Exchange in the Energy Sector (Re4DE).
[4] European Parliament and Council. Regulation (EU) 2023/1542 concerning batteries and waste batteries, especially Articles 77–78 and Annex XIII.
[5] European Parliament and Council. Regulation (EU) 2024/1781 establishing the ESPR framework.
[6] European Commission. COM(2025) 838 final: proposal on European Business Wallets; procedure 2025/0358(COD).
[7] Council of the European Union. European business wallets: Council adopts negotiating position, 9 June 2026.
[8] W3C. ODRL Information Model 2.2, W3C Recommendation.
[9] CIRPASS-2. D4.1 Reference Architecture and Risks and Mitigations companion, 10 June 2026.
[10] Catena-X. Digital Product Passport / EcoPass.
[11] Plattform Industrie 4.0. Manufacturing-X architecture and technological base.
[12] European Commission. Digitalising the EU energy system.
The original web analysis on this page is licensed by its named authors under the Creative Commons Attribution 4.0 International License (CC BY 4.0), except for the third-party material identified below. Reuse must credit every named author, link to this canonical version and the license, and indicate whether changes were made.
Third-party rights: The journal PDF, journal layout, credited source figures, photograph and other third-party material retain their respective rights and are not relicensed by this webpage.
How to cite this work
Jan-Niklas Gößling; René Hoffmann; Axel Kießling; Daniel Rohrbach; Carsten Stöcker (2026-08-11). “European Business Wallet and Market Role Credentials for DPP Access Control: The energy data-X Reference Case: How verifiable company identities, governed market roles and machine-readable policies enable secure access to Digital Product Passports, Battery Passports and European data spaces.” Amprion GmbH; Westnetz GmbH; TenneT TSO GmbH; Fraunhofer IOSB-AST; Spherity GmbH. https://spherity.github.io/spherity-research/energy-data-x-ebw-market-role-credentials-dpp-access-control.html. Licensed CC BY 4.0.
Direct answers
Questions this research answers
What is energy data-X?
energy data-X is a German cross-sector energy-data ecosystem project. It uses a federated model rather than a central data pool: data remains with participants and is exchanged through connectors under shared identity, trust, catalogue, contract and policy mechanisms. The published case study reports implementation of fine-grained authorisation with European Business Wallet concepts and verifiable credentials.
What is a market-role credential?
A market-role credential is verifiable evidence that an identified organisation holds a governed role, such as supplier, grid operator or metering point operator. Its value depends on an authoritative role source, eligibility rules, an authorised issuer, validity and status controls, and runtime verification. It is not merely a self-declared profile field or copied master-data value.
Why is authentication alone insufficient for a Digital Product Passport?
Authentication answers who is requesting access. Restricted DPP access also requires evidence of the capacity in which the organisation acts, the purpose and product scope, the current validity of that authority, and the operation allowed by policy. A verified login therefore cannot by itself establish entitlement to commercially sensitive, authority-only or legitimate-interest information.
What is a Person with a Legitimate Interest in a battery passport?
Regulation (EU) 2023/1542 reserves specified model-level and individual-battery information for Persons with a Legitimate Interest. Article 77(9) requires an implementing act to define the eligible persons and their rights. At the 11 August 2026 research cut-off, the statutory deadline of 18 August 2026 had not yet passed, so this page does not treat every repair, finance, insurance or lifecycle actor as automatically qualifying.
Can a European Business Wallet control DPP access?
A European Business Wallet can present legal-person, representation, delegation and role evidence used in an access decision. It does not itself determine every DPP permission. A policy engine must evaluate the credentials, trusted issuer, status, purpose, jurisdiction, product context and applicable DPP policy, while the connector or DPP API enforces the result.
What is the role of W3C ODRL in DPP access control?
W3C Open Digital Rights Language (ODRL) 2.2 expresses permissions, prohibitions, duties and constraints concerning an asset. It can make DPP usage rules machine readable, but it does not authenticate an organisation or prove a market role. Verifiable identity and role evidence supply facts; ODRL-style policy semantics describe how those facts affect permitted use.
How does energy data-X relate to the Common European Energy Data Space?
energy data-X is not the Common European Energy Data Space. It is a national and sector reference implementation whose federated connectors, organisational trust, governed roles and machine-readable policies can inform European convergence. The reusable lesson is that cross-border participants must prove both who they are and the regulated or governed capacity in which they act.
How can this architecture mitigate DPP cybersecurity risks?
The architecture can mitigate impersonation, unauthorised access, overly broad permissions, stale roles and weak provenance by combining verified legal-person identity, governed role credentials, trusted issuers, status checks, least-privilege policy, connector enforcement and auditable decisions. It does not address every CIRPASS-2 risk; product-data integrity, availability, recovery and lifecycle governance require additional controls.