Skip to content
Deze documentatie wordt actief uitgebreid — kom regelmatig terug.

BDI Reference Architecture – BDI Connector

The BDI Connector is defined as the standard integration point for secure communication, signing and event handeling: interface between internal IT landscape and BDI network, implemented by every participant.

The BDI Connector is a set of functions that can be implemented building upon existing infrastructure such as reverse proxies, proxies and messaging platforms/brokers, or implemented as a container with all functions.

The BDI (Basic Data Infrastructure) Reference Architecture is designed to minimize complexity for participants by standardizing the core components and confining complexity of authentication, signing certficates handling and event handling to the set of core components.

The main standardised components in the 2026 scope are:

  • ASR (Association Register) — Registration of onboarding information, authentication enrolment, local Certificate Authority that issues a BDI Signing Certificate to a Connector, issuer of signed Assurance (VAD) tokens, maintenance of synced trust lists, event notification to participants/users.
  • BDI Connector — Standard integration point for secure communication, signing and event handling: interface between the internal IT landscape and the BDI network, implemented by every participant.

The implementation of an ASR will typically use a BDI Connector as its standard integration point. Additional components (Orchestration Register, Local Policy Engine as a separate PDP service) are part of later phases — see the Roadmap.

{This section needs to be expanded by Jomco and others]

Forward proxy, with TLS.

Proxy

API Gateway

Webhook or messaging platform for event notification

  • subcribing entities to specific topics
  • sending notifications
  • receiving notifications from others

OAuth client credentials flow handling: enrollment ASR, access token requests

JWT validation (JWKS endpoint of signing authorithy, content, expiration etc.)

PKI handling

  • generation of key pair
  • storage of private key
  • ACME protocol initial verification with ASR, CSR requests
  • ACME key rotation with ASR
  • signing of tokens or data

Trust list handling (domain, public keys

Data requests: receiving, sending. Sending data.

In samenwerking met

Connected Trade NetworkConclusionData in LogisticsContargoInland Terminals GroupVan Berkel