2023-07-17 CTWG Meeting Notes

2023-07-17 CTWG Meeting Notes

Meeting Date

  • Jul 17, 2023 The CTWG meets bi-weekly on Mondays at 10:00-11:00 PT / 17:00-18:00 UTC. See the ToIP Calendar for the full schedule.

Zoom Meeting Recording

Attendees

  • @Drummond Reed

  • @Rieks Joosten

  • @Charles Lanahan

  • @Neil Thomson 

  • @Judith Fleenor (Deactivated) 

  • @Brian Richter 

Agenda Items and Notes (including all relevant links)

Time

Agenda Item

Lead

Notes

3 min

  • Start recording

  • Welcome & antitrust notice

  • Introduction of new members

  • Agenda review

Chairs

  • Antitrust Policy Notice: Attendees are reminded to adhere to the meeting agenda and not participate in activities prohibited under antitrust and competition laws. Only members of ToIP who have signed the necessary agreements are permitted to participate in this activity beyond an observer role.

  • New Members:

    • Charles Lanahan has been a data scientist at Trust Science until recently and a new ToIP member.

5 min

General announcements

All

News and updates of general interest to CTWG members:

@Neil Thomson shared a GSWG conversation about how issuers and trust registries are related.

  • A trust registry is a qualified object list

  • The qualifying authority for a trust registry is a registrar

  • Neil's point is that the jobs of qualifying authorities, from a governance standpoint, are similar for an issuer and a trust registry.

  • @Rieks Joosten agreed. He said it reminds him of a data exchange project in the EU, where similar decisions need to be made about registries of semantic data, such as schemas, and also product offerings, identity services, and other related services. All of these services share three things:

    1. First, a provider of the service needs to provision and operate the service at runtime.

    2. Secondly, there is a management layer that applies the governance policies under which the service operates.

    3. Thirdly, there is the governance layer that establishes the policies.

  • Rieks felt this was a good model that could be defined by the Governance Stack. He made the analogy to how CAs (certificate authorities) operate in conventional PKI. It is a good scaffolding for registries of all kinds.

  • Neil agreed that governance and operations are different roles, and whether the same party performs them or not is a matter of choice.

  • Rieks said that trust communities can get up and running by choosing the initial set of services they will offer.

 

2 min

Review of previous action items

Chairs

ACTION: @Drummond Reed to follow up with @Judith Fleenor (Deactivated) with regard to Henk's draft document to see how we can address these GitHub issues much more efficiently and effectively, including who/where we might be able to request budget.
ACTION: @Drummond Reed to move the ToIP Glossary Workspace Google doc to another location so it can be more widely shared.
ACTION: @Drummond Reed to review Riek's comments on the ToIP Glossary Workspace and make recommendations about next steps.
ACTION: @Drummond Reed to request @Michelle Janata to cancel the July 3 CTWG meeting.

10 min

Update on TEv2 progress

@Brian Richter @Rieks Joosten 

  • TNO is looking to develop tools for the TEv2 toolbox in TypeScript. The TRRT had some setbacks, but we expect it te be fully working at the end of this month. Progress can be followed in the TRRT-repo.

  • TNO is planning on a template repo that other tool developers can use to make other tools (in TypeScript), and that can be documented using the TEv2 tools (when they're up and running).

  • TNO is gathering the tools in the tno-terminology-design github organization. That's where the specs and methods have moved to from eSSIF-Lab.

    • These will include terminology design methodologies.

    • Some experiments are under way, including with the W3C Verifiable Credentials Working Group terminology.

    • Rieks hopes this will help terms communities justify doing terminology work earlier and more productively in their project.

  • @Brian Richter hasn't been doing a lot — too busy. The ingress tools have been progressing, the rest is still tbd. It might be a good idea to create HRGT-tools in the TNO repo, using the templates, and reusing parts of the TRRT code.

  • The MRGT (in Java) is giving some operational problems. It seems appropriate to leave it as it is, as TNO expects a TypeScript version to become a available in Q4 of this year.

10 min

Update on the ACDC and Web of Trust (WoT) Glossary

@Henk van Cann 

On 2023-07-11 in the ToIP Slack, Henk posted this update:

In the KERI meeting today we voted for the move of our “source of terms truth” known as the ACDC-wiki: it’s going to be WOT-terms wiki: https://github.com/WebOfTrust/WOT-terms/wiki from today. We will still be able to sync between the glossaries at
ToIP user acdc repo and WebofTrust WOT-terms repo.

The reason for the move is a practical one: more control over our own data and functionality while maintaining the symbiotic properties between ToIP and WoT. More info and acknowledgements in KERISSE section how we did.

The most recent update of the glossary in ToIP format can now be found here but will most probably also be hosted from ToIP github space (here) soon.

10 min

Update on the new TNO Party-Driven Actor model

@Rieks Joosten 

See the notes from the last meeting. Rieks didn't have any new updates yet.

@Neil Thomson noted that the work on the Trust Spanning Protocol TF on climbing a "spiral staircase" of higher levels of trust, each of which corresponds to a different protocol.

@Rieks Joosten said he didn't see a web server treating a customer differently depending on how many visits you have made, unless there are rules that make it explicit. The rules may change for the provisioning and management, but the web service will remain quite stable. 

Neil gave the example of opening a bank account and the KYC data that must be shared by a consumer. Once the account is established, it is easier to move to a higher level of trust faster.

Rieks: the bank's web server will follow a decision tree that has a set of rules that can result in clear outcomes for the consumer. Those rules will be in machine-readable policies. Some of them may call for human intervention / review. These decision trees could be shared within a trust community.

@Drummond Reed pointed out that any leaf in the decision tree can kick out to a human-mediated process to review as necessary.

10 min

Update on the ToIP Glossary Workspace progress

@Drummond Reed 

Drummond will share his progress on the ToIP Glossary Workspace and proposed next steps for the rest of this month:

  1. Finish remaining TODOs (four are left).

  2. Review existing approved or draft ToIP specifications for terms not yet included.

  3. Draft those terms.

  4. Begin an ToIP WG-by-WG review.

ACTION: @Drummond Reed to finish the remaining TODO entries in the ToIP Glossary Workspace before our next meeting and, if possible, review existing approved or draft ToIP specifications for any other terms not yet included.

ACTION: @Drummond Reed to schedule an agenda item for our next meeting to discuss the best way to develop mental models for the terms in the ToIP Glossary Workspace.

5 mins

  • Review decisions/action items

  • Planning for next meeting 

Chairs

Our next meeting will be at our regular time in 2 weeks, on July 31.

Decisions

  • None

Action Items

ACTION: @Drummond Reed to follow up with @Judith Fleenor (Deactivated) with regard to Henk's draft document to see how we can address these GitHub issues much more efficiently and effectively, including who/where we might be able to request budget.
ACTION: @Drummond Reed to move the ToIP Glossary Workspace Google doc to another location so it can be more widely shared.
ACTION: @Drummond Reed to finish the remaining TODO entries in the ToIP Glossary Workspace before our next meeting and, if possible, review existing approved or draft ToIP specifications for any other terms not yet included.
ACTION: @Drummond Reed to schedule an agenda item for our next meeting to discuss the best way to develop mental models for the terms in the ToIP Glossary Workspace.