Skip to content

Add signing references to API spec#50

Open
aorzelskiGH wants to merge 7 commits intoadmin-shell-io:IDTA-01004-3-1_Workingfrom
aorzelskiGH:aorzelski/issue42
Open

Add signing references to API spec#50
aorzelskiGH wants to merge 7 commits intoadmin-shell-io:IDTA-01004-3-1_Workingfrom
aorzelskiGH:aorzelski/issue42

Conversation

@aorzelskiGH
Copy link
Contributor

No description provided.


This document specifies the security for the Asset Administration Shell and its submodels, i.e. how to use Access Tokens and how to define Access Rules for Authorization.
The signing of submodel data will be specified in a next version of this document.
Identifiables (i.e. Asset Adminstration Shells, Submodels and Concept descriptions) can also be signed by the additional endpoint /$sign, as described in the REST API specification.

Check warning

Code scanning / QDJVMC

Typo Warning documentation

Typo: In word 'Identifiables'

This document specifies the security for the Asset Administration Shell and its submodels, i.e. how to use Access Tokens and how to define Access Rules for Authorization.
The signing of submodel data will be specified in a next version of this document.
Identifiables (i.e. Asset Adminstration Shells, Submodels and Concept descriptions) can also be signed by the additional endpoint /$sign, as described in the REST API specification.

Check warning

Code scanning / QDJVMC

Typo Warning documentation

Typo: In word 'Adminstration'
A next version of this document shall define signatures (and possibly encryption) of AAS data.
So far this is only possible together with AASX packages, but signatures are also needed when using APIs to exchange data.
Some business partners like to copy AAS data to their servers, so that the signature of the originator of the AAS data must be able to be proven by a final receiver.
Signing of Identifiables is defined in the REST API specification. This may be extended to SubmodelElements or other parts of Identifiables. Currently plain JWS (JSON Web Signature) is used for signing, which may be extended to additional formats e.g. JAdES (JSON Advanced Digital Signature).

Check warning

Code scanning / QDJVMC

Typo Warning documentation

Typo: In word 'Identifiables'
@Martin187187 Martin187187 added the ready for review “Ready for review by the Task Force label Feb 23, 2026
@Martin187187
Copy link
Collaborator

closes #42

@Martin187187 Martin187187 requested a review from BirgitBoss March 6, 2026 16:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ready for review “Ready for review by the Task Force

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants