
a DG framework. It is indicated that these aspects
cover the most important organizational requirements
to restrict and ensure the access to data and its use
through AAS. For this reason, these requirements
were integrated into the data management principles
of the concept and must be accepted by users before
accessing the data. The answer to Q2 shows that the
current AAS metamodel does not yet consider DG as-
pects. However, it offers specifications, definitions,
and elements suitable for integrating potential DG as-
pects. The existing metamodel includes classes, SC,
attributes, data elements, and relationships, allowing
the addition of new elements that incorporate poten-
tial DG aspects. In answering Q3, possible aspects of
a DG were initially specified for integration into the
AAS metamodel. Regarding conceptualization, the
necessity for a binary classification of the data was
first demonstrated. This classification was required
because the authorization in our concept was imple-
mented using RBAC. To enable the RBAC to sensi-
bly restrict access and granularity to the SM, the data
was classified into business-critical and non-business-
critical data. In the course of this, it was shown that
different roles and rights for data access can be as-
signed depending on the type of data. The concept
also includes the introduction of SC, such as UserIn-
formation and Authorizable, as well as the creation of
the class AccessControl. The AccessControl class was
the foundation for ensuring that a user first authen-
ticates himself with an X.509 certificate and accepts
the organization’s most important data management
principles before accessing the AAS. To do this, the
AccessControl class received the attributes of the user
by inheriting them from the UserInformation class. If
these two aspects of access control were fulfilled, the
authorization of the user could continue. This was en-
sured by means of the Authorizable class, which also
inherits the attributes from the UserInformation class.
This concept will be tested and validated in future
work. The remaining unanswered questions revolve
around handling sensitive user data in the AAS, since
our concept is based on the consumption and persis-
tence of this user data in the AAS. One idea would
be to integrate encryption concepts into user informa-
tion to ensure data security and prevent it from being
readable by any type of user.
ACKNOWLEDGEMENTS
The authors gratefully acknowledge the support from
The German Federal Ministry for Economic Affairs
and Climate Action through the VWS4LS project
(Grant No.13IK005A).
REFERENCES
Adolphs, P., Auer, S., Bedenbender, H., and Billmann, M.
(2016). Structure of the asset administration shell: fur-
ther development of the reference model for the in-
dustry 4.0 component. Federal Ministry for Economic
Affairs and Climate Action.
Adolphs, P., Bedenbender, H., Dirzus, D., ..., and
Wollschlaeger, M. (2015). Referenzarchitekturmodell
industrie 4.0. Association of German Engineers VDI.
Alonso,
´
A., Fern
´
andez, F., Marco, L., and Salvach
´
ua, J.
(2017). Iot application-scoped access control as a ser-
vice. Future Internet.
Angeli, C., Boss, B., Braunmandl, A., Brost, G., and ...,
Schmitt, M. (2019). Access control for industrie 4.0
components for application by manufacturers, opera-
tors and integrators. Federal Ministry for Economic
Affairs and Climate Action.
Bader, S., Barnstedt, E., and Bedenbender, H. (2019). De-
tails of the asset administration shell. Plattform Indus-
trie 4.0.
Bedner, M. and Ackermann, T. (2010). Schutzziele der it-
sicherheit. Datenschutz und Datensicherheit - DuD.
Belyaev, A., Diedrich, C., and Espen, D. (2021). Aas refer-
ence modelling: Exemplary modelling of a manufac-
turing plant with aasx package explorer based on the
aas metamodel. Plattform Industrie 4.0.
Boss, B., Bader, S., Orzelski, A., and Hoffmeister, M.
(2019). Verwaltungsschale. Handbuch Industrie 4.0.
Br
¨
oring, A., Belyaev, A., Trsek, H., Wisniewski, L., and
Diedrich, C. (2021). Secure asset administration shell
exchange with distributed ledger technology. Plat-
tform Industrie 4.0.
Broring, A., Ehrlich, M., Wisniewski, L., Trsek, H., and
Heiss, S. (2022). Towards an asset administration
shell integrity verification scheme. In 2022 IEEE 27th
International Conference on Emerging Technologies
and Factory Automation (ETFA). IEEE.
Claes, W. (2014). Guidelines for snowballing in systematic
literature studies and a replication in software engi-
neering. Blekinge Institute of Technology.
Czuchra, W. (2010). UML in logistischen Prozessen:
Graphische Sprache zur Modellierung der Systeme.
Studium. Vieweg + Teubner Verlag, 1st edition.
DIN EN IEC (2022). DIN EN IEC 63278-1: Verwaltungss-
chale fuer industrielle Anwendungen. DIN EN Inter-
national Electrotechnical Commission[IEC].
Ding, K., Fan, L., and Liu, C. (2021). Manufacturing sys-
tem under i4.0 workshop based on blockchain: Re-
search on architecture, operation mechanism and key
technologies. Computers & Industrial Engineering.
Dogan, A., Fay, A., Rijo, G., Diedrich, C., Block, C., and
Bondza, A. (2021). Distributed ledger-basierte infras-
truktur f
¨
ur verwaltungsschalen. VDI Congress Au-
tomation.
Dogan, A., Schnakenbeck, A., and Fay, A. (2022). Dis-
tributed ledger-based authentication and authorization
for industrie 4.0 components. In IEEE 20th Interna-
tional Conference on Industrial Informatics (INDIN).
IEEE.
Advancing Industry 4.0: Integrating Data Governance into Asset Administration Shell for Enhanced Interoperability
139