Overview
ISO/TR 6277:2025 is a technical report developed by ISO that provides comprehensive models describing data flows within blockchain and distributed ledger technology (DLT) systems, between DLT and related systems, and among different DLT nodes. The standard aims to guide system designers, developers, and business stakeholders in understanding and analyzing the characteristics of DLT data flows. By leveraging descriptive, system-level data flow models in alignment with ISO 23257 (DLT Reference Architecture) and the use case analysis in ISO/TR 3242, this document serves as a foundation for designing robust, secure, and interoperable DLT solutions.
Understanding data flows is vital to the performance, security, and usability of blockchain and DLT-based applications. This technical report not only outlines general models but also demonstrates these models through real-world use cases, aiding stakeholders in maximizing business value while managing risk.
Key Topics
-
DLT Data Flow Categories:
The report identifies and organizes essential data flow types, such as:
- Data within and between DLT nodes
- Data between distinct DLT systems (interoperability)
- Data exchange between DLT systems and non-DLT systems
- Data flow associated with user and administrator interactions
-
Data Categories:
ISO/TR 6277 classifies DLT-related data from different perspectives:
- Storage Perspective: On-ledger (stored within the DLT) vs. off-ledger data (external storage with ledger references)
- Source Perspective: Includes transaction records, account data, smart contract data, operational data, access/authentication data, derived data, and end user identifiable information (EUII)
- Identifier Data: Such as decentralized identifiers (DIDs), subject, and object identifiers
-
Roles and Stakeholders:
The document details how data flows are generated by different roles:
- DLT users (data entry, retrieval)
- DLT administrators (data governance, security, interoperability management)
- DLT providers (system, node, and application operation)
-
Data Security and Privacy:
Focuses on ensuring confidentiality, integrity, and availability across DLT environments, emphasizing the importance of privacy impact assessments and compliance with evolving data protection requirements.
-
Interoperability and Governance:
Discusses the governance models for DLT data and the need for interoperability between internal and external systems, supporting secure, seamless business operations.
Applications
ISO/TR 6277:2025 serves practical purposes across various blockchain and DLT use cases, supporting:
-
DLT System Design:
Provides architects and developers with a structured framework for mapping and analyzing data flows, optimizing application architecture for transparency, scalability, and compliance.
-
Business Process Analysis:
Enables business analysts to understand the movement of data in distributed environments, ensuring that business objectives align with technical capabilities.
-
Security and Privacy Assessment:
Supports compliance officers and security professionals in identifying data touchpoints, aiding in risk assessment, privacy protection, and implementing robust security strategies.
-
Interoperable Solutions:
Facilitates the creation of DLT systems that interact reliably with other DLT and non-DLT platforms, key for ecosystems such as supply chain, finance, and digital identity.
-
Use Case Development:
The standard includes detailed templates and visualizations for applying data flow models to diverse scenarios such as insurance for fish farming, international trade platforms, and peer-to-peer metaverse travel networks.
Related Standards
ISO/TR 6277:2025 references and complements several key international standards in the blockchain and distributed ledger technology ecosystem, including:
- ISO 23257: Blockchain and distributed ledger technologies - Reference architecture
- ISO/TR 3242: Blockchain and distributed ledger technologies - Use cases
- ISO 22739: Blockchain and distributed ledger technologies - Vocabulary
- ISO/TR 23244: Privacy and personally identifiable information protection considerations
- ISO/IEC 38505-1: Governance of data
- ISO/TR 6039: Identifier data guidelines
Applying ISO/TR 6277:2025 in combination with these related standards supports the creation of structured, interoperable, and trustworthy DLT systems for a broad array of industries and applications.