Task-Bound Authorization and Compliance Auditing with Quantum-Safe Task Passports for Privacy-Preserving Computation in Trusted Data Spaces
Abstract
Trusted data spaces support privacy-preserving computation, but existing credentials leave an execution-time gap when task parameters or cumulative resources change. We present a task-bound lifecycle and state model instantiated by a quantum-safe task passport (QTP). Its signed schema binds purpose, scope, computation type, participants, validity, evidence-key metadata, and an initial governed-resource profile. At admission, QTP matches an independently reconstructed request, queries authoritative state, and atomically reserves units before mediated execution; Commit/Result evidence is bound to the admitted version. ML-DSA protects the credential, and ML-KEM establishes an off-chain evidence key. ML-DSA-44 signing and verification averaged 0.295 and 0.079 ms; a complete QTP occupied 4150 B. Fifteen field-correctness cases and ten additive-resource checks passed. In a four-node FISCO BCOS deployment co-located with one sequential client in a single virtual machine, state queries averaged 0.737 ms for 100 synthetic tasks, and all 71 negative transactions were rejected without state changes. The experiments do not characterize concurrent contention or an operational FL, PSI, or MPC runtime. Merkle-path measurements assume a supplied authenticated root; checkpoint authentication and finality verification remain deployment requirements. The quantum-safe claim covers credential and evidence-key layers; the ledger remains conventionally authenticated.