
A method and open-source implementation for expressing and enforcing access to sensitive FAIR Digital Objects, combining ODRL policies and access grants published as signed nanopublications, Decentralized Identifiers (DIDs) for requester identity, AES-256-GCM authenticated encryption with ECDH/HKDF per-recipient key wrapping, and RO-Crate metadata deposited as a citable Research Object.The metadata layer is openly findable while the data itself remains encrypted, so that possession of a URL is not equivalent to possession of access. Developed in the FAIR2Adapt project for the Hamburg building-level pluvial flood-risk case study (CS3), whose outputs resolve to individual buildings and cannot be released openly.Archived to accompany the Open Research Europe method article describing the approach.
