Trust Registry Task Force

This page is the charter of the TSWG Trust Registry Task Force (TRTF). See the Meeting Page for links to the meeting agenda and notes for each meeting.

Background

The ToIP Technology Stack WG originally created the TRTF in June 2021 in response to the market gap identified during the work on the Good Health Pass Interoperability Blueprint. The first-generation TRTF worked quickly to create a first-generation ToIP Trust Registry Protocol specification, which it published in September 2021 for community review. At that point, the attention of the TSWG moved to the Technology Architecture Task Force (TATF) to develop the ToIP Technology Architecture V1.0 Specification (TAS). With the publication of the first public review draft of the TAS in December 2022, and with market demand increasing for decentralized trust registries (aka trust lists), the TSWG started up the second generation of the TRTF in December 2022 to produce a complete, production-ready ToIP Trust Registry Query Protocol Specification that can then be submitted to a formal SDO such as ISO. Furthermore, as related work has is now underway at the Decentralized Identity Foundation, the second-generation TRTF will be working in collaboration with the DIF Claims and Credentials Working Group work on Trust Establishment.

Objectives

The primary objective of this Task Force is to develop the ToIP Trust Registry Query Protocol (TRQP) as a ToIP Specification. The purpose of this deliverable to enable interoperability between ToIP-compliant trust registries.

Context

One of the primary uses of decentralized digital trust infrastructure is digital wallets and digital credentials. The primary roles involved in a digital trust ecosystem focused on the exchange of digital credentials are shown in the diagram below (see further details in the ToIP white paper):

As this diagram illustrates, the heart of this ecosystem is a trust registry: a network service that enables a governing body—typically the publisher of an ecosystem governance framework (EGF)—to specify what governed parties are authorized to perform what actions under the EGF. In most case this means answering one of two main questions:

  • Does Entity X have Authorization Y under Governance Framework Z?
    • This question allows a system to ask about what rights (authorizations) a particular entity has, according to an authority (governed by a governance framework). For example, "Is hospital X authorized to issue vaccination credential Y under governance framework Z?"
  • Does this trust registry recognize another trust registry X? 
    • This question establishes peer relationships between trust registries (often called a "registry of registries" or "metaregistry" capability).

As with all layers of the ToIP stack, the purpose of a ToIP specification is to enable the technical interoperability necessary to support transitive trust across different trust communities implementing the ToIP stack. In this case, the desired interoperability outcome is a common protocol that works between any number of decentralized trust registries operated by independent governing bodies representing multiple legal and business jurisdictions.

Leadership

The leads of the second-generation TRTF are:

  1. Darrell O'Donnell
  2. Antti Kettunen 
  3. Andor 

Membership and Joining

Prior to participating in the meetings, please ensure that you are a member of the Trust Over IP Foundation (Contributor Membership is free to both organizations and individuals). More details can be found at this link.

To join this TF, add your name to this list:

Deliverables

  1. ToIP Trust Registry Query Protocol Specification. This is a formal specification of a protocol for interactions with a ToIP-compliant trust registry service.
  2. OpenAPI 3.0 API (managed in GitHub). 
  3. X.509 DID Interop guidance.

GitHub Repository

Intellectual Property Rights (Copyright, Patent, Source Code)

As a Task Force (TF) of the Technology Stack WG (TSWG), the TRTF inherits the IPR terms from the TSWG JDF Charter.

  • This Task Force is not currently expected to produce source code.

Milestones

Key milestones will include, but are not limited to:

  1. Publication of the first Draft Deliverable via a GitHub repo.
  2. Publication of the final Draft Deliverable.
  3. Approval of the Draft Deliverable as a Working Group Approved Deliverable.

The work of this Task Force will be complete when the Working Group Approved Deliverable is approved by the TSWG.

Dependencies

Meeting Schedule and Notes

The TRTF holds two meetings — one on NA/EU time zones and one for APAC time zones — every Thursday. Please see the ToIP Calendar for the exact meeting times and Zoom links.

See the Meeting Page for links to the meeting agenda and notes for each meeting (including the Zoom links for joining a meeting and for listening to a recording of the meeting).

Mailing List and Communications

This task force uses the following for communications

FAQ

  1. Q: Why can't we simply use VCs instead of a TR? A: At some point you MUST step out of a VC to say “and who says you are the authority”