Skip links
Home » Blog Articles » Domain Extensions for Data Spaces: Leveraging the Gaia-X Trust Framework and Trust Protocol for Scalable, Interoperable Data Spaces

Domain Extensions for Data Spaces: Leveraging the Gaia-X Trust Framework and Trust Protocol for Scalable, Interoperable Data Spaces

Roland Fadrany, Chief Operations Officer & Christoph Strnadl, Chief Technology Officer at Gaia-X

White Papre published in the June edition of the Gaia-X Magazine

Executive Summary

The Gaia-X Trust Framework now supports Domain and Geographical Extensions, enabling vertical industries and regional ecosystems to build sovereign, interoperable data spaces under a common trust architecture. Building on it, the Gaia-X Trust Protocol operationalises the establishment of trust between different ecosystems and jurisdictions in a fully interoperable manner.

This white paper outlines the strategic rationale and a concrete implementation proposal for adopting Gaia-X Domain Extensions across vertical and regional data space ecosystems, irrespective of sector or geography.

Key Takeaway

Any established ecosystem is well positioned to act as a domain custodian, retaining full governance over its own credentials and trust anchors while gaining global interoperability with other Gaia-X-technically compliant ecosystems.

Background & Motivation

As data space deployments scale across industries and geographies, a recurring set of challenges has emerged:

  • Multiple ecosystems and regions resist reliance on a single, centralised data space operator.
  • Regions require their own Participant IDs and Trust Anchors under local sovereign control.
  • Cross-data space and cross-ecosystem interoperability is an urgent requirement, particularly along complex value chains and adjacent domains.
  • Credentials must be universally verifiable across regions and ecosystems.
  • Data spaces need to establish trust with other data spaces and their participants in a rapid and scalable way.
  • Onboarding mechanisms must be highly scalable and automated to support rapid growth.

Gaia-X addresses these challenges through a layered extension model that accommodates several coexisting scenarios. Domain Extensions allow individual ecosystems to appoint a custodian — typically an industry or regional governance body — that defines domain-specific rules, certifications, trust anchors, and labels, while maintaining mandatory use of the Gaia-X Participant ID and optional use of Gaia-X Label Levels 1–3.

Building on this, the Gaia-X Trust Protocol provides a universal discovery and automation framework allowing ecosystems to establish unidirectional or mutual trust in a standardised, interoperable way.

The Case for Domain Extensions

Many mature ecosystems are already structurally aligned with the Domain Extension model. Their existing governance bodies effectively function as the domain custodian envisioned by Gaia-X:

  • A significant portion of an industry’s participants may designate a single body as their custodian and governance authority.
  • Such an ecosystem has typically already defined its rules, criteria, certifications, and trust anchors.
  • Under Gaia-X 3.0 (“Danube”), a domain custodian does not require Gaia-X Label Levels 1–3, simplifying adoption significantly.
  • Domain Extensions can be processed through any Gaia-X Digital Clearing House (GXDCH). Using one or more dedicated, ecosystem-operated GXDCHs that remain fully interoperable with the broader GXDCH network is also possible.

Strategic Benefits of Domain Extensions

Adopting Domain Extensions delivers measurable advantages for ecosystem participants and the broader landscape:

  • Universal recognition: ecosystem participants become accepted across all cooperating Gaia-X ecosystems.
  • Simplified global expansion: Geographical Extensions and distributed GXDCHs enable multi-region verification without architectural complexity.
  • Ecosystem growth: operators can accelerate the onboarding of adjacent industries such as manufacturing, logistics, energy, healthcare, and finance.
  • Clean architectural separation: a clear boundary between a common Trust Framework and specific functions such as the data space connector, which today solely executes access and usage control policies.

The Case for the Gaia-X Trust Protocol

An ecosystem acting as a data space governance authority may rely on a single, nationally based clearing house for issuing participant and other credentials as the basis for its trust framework.

Such a configuration will meet resistance when interacting with other ecosystems, as they will, in all likelihood, not accept a single foreign clearing house as a trust service provider for their own particular credentials. It may also be the case that non-local clearing houses cannot access and verify foreign identity certificates because of national restrictions — for example, where only national IP addresses or registered national companies are permitted to query company numbers at a national company registry.

The Gaia-X Trust Protocol allows any ecosystem to accredit entities as trust service providers for arbitrary trust scopes, not limited to identity or services, nor to any single nationality. Examples include IoT devices, AI agents, data space connectors, machine standards (such as OPC UA), digital product passports, and any identifiable entity. By exposing an ecosystem’s list of trust service providers and their respective trust scopes and credentials in so-called ecosystem trust profiles within the Gaia-X Meta-Registry, it enables one ecosystem (the trustor) to establish selective trust relationships with other ecosystems (the trustee).

Strategic Benefits of the Trust Protocol

Adopting the Gaia-X Trust Protocol enables:

  • an ecosystem to keep or extend its current trust profile;
  • other ecosystems to establish and keep their own trust profiles;
  • an ecosystem to establish unidirectional trust for selected trust scopes with other ecosystems complying with the Gaia-X Trust Protocol;
  • other ecosystems to establish unidirectional trust for selected trust scopes in return;
  • the establishment of mutual trust between two ecosystems for selected trust scopes; and
  • seamless interoperation with other ecosystems at the trust plane.

Proposal & Implementation Path

Gaia-X proposes the following co-creation initiative targeting readiness for the Gaia-X Summit in November:

  1. Co-Create a Domain Extension. Fully formalise an ecosystem’s current credential set within the Gaia-X Domain Extension framework, covering representative credential types such as:
  • Membership Credential
  • Participant Identification Credential
  • Framework Agreement Credential
  1. Deploy a Domain Extension Engine on Danube. Implement a dedicated extension engine on the Gaia-X 3.0 “Danube” platform, enabling GXDCHs to simultaneously issue and verify both Gaia-X and domain-specific credentials within a single, unified workflow.
  2. Decouple Verification from Access Management. Separate credential verification (handled by a dedicated clearing house) from access and rights management (handled by the connector). This architectural decoupling improves modularity and cross-ecosystem interoperability, and significantly simplifies the onboarding of new participants through automation.
  3. Demonstrate Cross-Ecosystem Trust using the Gaia-X Trust Protocol. Use the Danube platform to illustrate how the Gaia-X Meta-Registry and its Ecosystem Trust Profiles enable cross-ecosystem trust — building on proven precedents such as the IMXC use case, the Myrtus data space, available regional company-number extensions, and the generic company-number AI-agent.
Gaia-X Commitment

Gaia-X AISBL is committed to supporting this approach and will provide active technical and governance assistance to ensure readiness in time for the Gaia-X Summit.

Conclusion

The integration of Domain Extensions and the Gaia-X Trust Protocol into any vertical or regional ecosystem represents a natural and strategically sound evolution. By formally adopting the Gaia-X Domain Extension model, ecosystem participants gain global interoperability without surrendering existing governance structures or credential frameworks.

The proposed Domain Extension Engine on Danube provides a technically sound, standards-compliant implementation path that positions any data space for scalable, trusted, cross-industry and cross-region collaboration.