I-D Action: draft-das-digital-sovereignty-finality-00.txt

[email protected]
Newsgroups gmane.ietf.announce
Message-ID <178807608486.212399.3030588802820143589@dt-datatracker-6669c7b496-s9mrn>
Internet-Draft draft-das-digital-sovereignty-finality-00.txt is now available.

   Title:   When Data Leaves Its Originating Jurisdiction, Who Controls It? Digital Sovereignty Without Data Localisation by Separating the Compute Plane from the Authority Plane
   Author:  Sangam Das
   Name:    draft-das-digital-sovereignty-finality-00.txt
   Pages:   25
   Dates:   2026-08-30

Abstract:

   Consider a simple case: data concerning U.S. citizens is processed in
   infrastructure located outside the United States.  The foreign
   jurisdiction may have its own lawful-access, surveillance,
   disclosure, retention, or national-security rules.  Even where
   contractual commitments, privacy policies, regional settings, or
   enterprise agreements specify how that data should be handled, the
   infrastructure executing the workload may ultimately operate under
   legal and technical authority outside the originating jurisdiction.

   The same problem applies in reverse to European, Indian, Japanese,
   Canadian, Australian, or other data processed through globally
   distributed infrastructure.

   This creates a deeper architectural problem than ordinary data
   localisation.

   If control over data automatically follows the physical location of
   compute, then moving computation across borders can also move
   practical authority over the resulting data, operations, and
   disclosures.  Privacy may be the first concern, but the same
   architectural dependency can later affect economic security, critical
   infrastructure, sensitive enterprise information, government
   workloads, and national security.

   This is where policy alone begins to reach its limit.

   Contracts, privacy policies, adequacy mechanisms, access-control
   rules, cloud-region settings, and audit requirements remain
   important.  However, they primarily describe what an actor is
   permitted or expected to do.  They do not necessarily create a
   technical condition that prevents a prohibited external effect from
   occurring in the first place.

   The architecture described here addresses this problem through a
   different model of digital sovereignty: separate the Compute Plane
   from the Authority Plane.

   The Compute Plane may remain globally distributed.  Data may be
   stored, transformed, analysed, routed, or processed using
   infrastructure located in another jurisdiction.  The architecture
   therefore does not require that all data remain physically local, nor
   does it assume that sovereign computing requires complete national
   isolation from global cloud, telecom, AI, or platform infrastructure.

   Instead, the Authority Plane remains independently governed.  A
   remote compute environment may perform computation, but computation
   alone does not grant authority to produce a protected external
   consequence.

   A proposed cross-jurisdiction operation is represented as a Candidate
   Act and remains in a Non-Effective State until the required policy,
   identity, purpose, destination, jurisdiction, runtime, revocation,
   and other applicable predicates have been validated.

   Protected validation may produce a LAVR or equivalent validation
   commitment and a scoped Finality Authority bound to the particular
   Candidate Act.  At the relevant Finality Sink — the first point at
   which the protected operation would become externally effective — the
   authority is independently verified.  Only after successful
   verification and appropriate consumption or reservation of that
   authority may the external effect occur.

   The resulting model is therefore: Compute Anywhere -> Authority
   Remains Independently Governed -> Candidate Act -> Protected
   Validation -> Scoped Finality Authority -> Finality-Sink Verification
   -> External Effect.

   If the required authority is missing, stale, revoked, mismatched,
   replayed, or inconsistent with the governing jurisdictional policy:
   No Valid Authority -> No Protected External Effect.

   This permits a form of digital sovereignty without mandatory data
   localisation.  A jurisdiction, enterprise, regulated institution, or
   other authorised policy owner does not necessarily need to operate
   every processor, cloud region, network, or AI system that performs
   the computation.  Instead, it can retain technical control over the
   conditions under which specified externally effective acts are
   permitted.

   The architecture therefore separates two questions that are commonly
   treated as one: Where is the computation performed?  Who has
   authority over the resulting external effect?  Those questions need
   not have the same answer.

   A U.S. workload could execute outside the United States while
   specified sensitive external effects remain subject to U.S.-
   controlled or enterprise-controlled authorization conditions.  An EU
   workload could similarly use infrastructure outside a particular
   Member State while retaining independently governed finality
   requirements.

   The same mechanism could apply to India, Japan, Singapore, Australia,
   Canada, multinational enterprises, sovereign clouds, regulated
   industries, or private data spaces.  The architecture does not
   prescribe which country's policy should prevail and does not attempt
   to resolve conflicts of law.

   Its contribution is narrower and technical: cross-border computation
   does not have to imply cross-border surrender of execution authority.

   This turns digital sovereignty from a primarily location-centred
   concept into an authority-centred execution model.  The objective is
   not to fragment the Internet or exclude global technology providers.

   On the contrary, separating the Compute Plane from the Authority
   Plane could allow hyperscale cloud providers, AI platforms, telecom
   operators, CDNs, satellite networks, and other global infrastructure
   providers to continue supplying efficient distributed computation
   while supporting stronger jurisdiction-specific, enterprise-specific,
   or regulated execution guarantees.

   In this model, sovereignty does not require saying that the data must
   never leave.  It can instead mean: the computation may occur
   elsewhere, but this protected external effect cannot occur without
   the required authority.

   That is the central architectural proposition of this document.

The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-das-digital-sovereignty-finality/

There is also an HTML version available at:
https://www.ietf.org/archive/id/draft-das-digital-sovereignty-finality-00.html

Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts


_______________________________________________
I-D-Announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.