2025-09-03 TSPTF Meeting Notes

2025-09-03 TSPTF Meeting Notes

Meeting Date & Time

Sep 3, 2025 This Task Force meets every other Wednesday. There is a single meeting for the NA/EU. (Updates for the APAC time zone will be at the monthly TSWG APAC meeting the first Tuesday of every month.)

  • NA/EU meeting: 08:00-09:00 PT / 15:00-16:00 UTC

See the Calendar of ToIP Meetings for exact meeting dates, times and Zoom links.

Zoom Meeting Links / Recordings

To see the recording of the meeting, click on the calendar entry for the meeting in the ToIP Calendar. The link to the Zoom recording should appear there approximately one hour after the meeting ends.

Attendees

@Sam Smith

@Wenjing Chu

@Steven Milstein

@Drummond Reed

@Steve McCown

Agenda Items and Notes (including all relevant links)

Time

Agenda Item

Lead

Notes

3 min

  • Start recording

  • Welcome & antitrust notice

  • New member introductions

  • Agenda review

Chairs

  • Antitrust Policy Notice: Attendees are reminded to adhere to the meeting agenda and not participate in activities prohibited under antitrust and competition laws. Only members of ToIP who have signed the necessary agreements are permitted to participate in this activity beyond an observer role.

  • NOTICE: In addition to the licensing terms of this Working Group’s JDF charter, this Working Group operates under the official policy that any Working Group Participant who makes a contribution to a Draft Deliverable shall have a maximum of 45 days from the date of that contribution to exclude any Essential Claims pertaining to that contribution.

  • New Members:

2 min

Review of previous action items

Chairs

ALL: Review the current TSP spec.

35 mins

Catch-Up and Issue #57

Chairs

See the issues list.

@Wenjing Chu said that we closed most of the issues related to CESR codes. But there are two new ones.

The first one is issue #57 to the version of the CESR codes.

@Sam Smith pointed out that every time there is a new cryptographic primitive, it will update the CESR code table. But it would be a much lighter lift to update the CESR code table than to version the protocol itself.

@Wenjing Chu said the other alternative is to let the CESR code table updates accumulate, then upgrade the protocol. The other option is to treat CESR as a separate specification that has its own versioning.

Wenjing also said that adding a new code does not necessarily mean the protocol will fail as long as the parties using the protocol do not use the new code. Sam said that this is how CESR 1.0 works. But with CESR 2.0, the code table has a minor version that will change as soon as a new code is added. This also allows the sender to choose the CESR code version number on a per-message basis, so if the sender is only using older primitives in their messages, they can signal that by using earlier CESR code version numbers.

Wenjing suggests we use issue #57 to discuss the pros and cons.

Sam also suggests that we could “steal” 3 characters from the protocol version number and use them for the CESR version number. That matters because the version number goes in every message.

 

Issue #56

Chairs

@Wenjing Chu explained that the other issue is the HPKE spec removing the authentication option.

Sam gave some backstory that HPKE thought that they could do powerful things with “authcrypt”, but then they realized that HPKE didn’t solve the key compromise impersonation attack. So authcrypt is just weak.

Wenjing pointed out that with TSP we send the signature anyway.

Wenjing said the proposal is to officially remove the HPKE authentication option to save space.

 

Other issues

Chairs

Most other issues are older and none are urgent.

Wenjing is thinking that most issues should be resolved by October and implementations should be upgraded.

@Drummond Reed asked if there was any reason to push for a 1.0 release, for example by the ToIP Symposium on November 19-20.

Wenjing asked if there should be some interop testing between at least the two implementations (KERI and OWF). Sam said that he might be able to make it fit in that time frame. He said that different KERI libraries are now using ESSR instead of TLS.

ACTION: ALL TSPTF MEMBERS to weigh in on issues #56 and #57 on GitHub.

5 min

AI & Human Trust WG (AIHTWG)

@Wenjing Chu

The AI & Human Trust TF is now the AI & Human Trust Working Group. This will soon be joined by a new Decentralized Identity Foundation WG called the Trusted Agent WG.

5 min

Decentralized Trust Graph Working Group (DTGWG)

@Drummond Reed

This new WG, approved by the ToIP Steering Committee in May, is planning its kickoff meetings for Wednesday, Sept 24, at 8-9AM PT / 15:00-16:00 UTC and also 6-7PM PT / 10:00-02:00 UTC. This is the charter:

The scope of the Decentralized Trust Graph Working Group (DTGWG) is to define the socio-technical standards for a decentralized trust graph where there is no centralized database and all parties control their own subgraph of trust relationships. This work includes specifying requirements for key management and recovery, verifiable identifiers, verifiable credentials, verifiable relationship credentials, social vouching, relationship cards (r-cards), privacy-preserving zero-knowledge proofs, trust task protocols, trust registries, out-of-band introductions, UI/UX affordances, decentralized naming and discovery mechanisms, and governance considerations. This work will be based on the Design Principles for the ToIP Stack, the ToIP Technology Architecture Specification, other ToIP technical specifications, and complementary open standards for decentralized digital trust infrastructure.

5 mins

ToIP Symposium Planning



The new dates of Symposium are November 19-20. What: a) talks, and b) workshops would the TSPTF like to do?

Wenjing said he would like to do two talks: one on TSP and one on using agent protocols (MCP and A2A) over TSP.

He also said that he could do a TSP workshop the second day.

 

Trust Tasks over TSP

@Wenjing Chu

Wenjing brought up several examples of trust tasks being run over TSP. Credential exchange is already being implemented. Also running agent-to-agent protocols like MCP and A2A.

But the newest one is using Matrix over TSP. That is being prototyped by the OWF TSP implementation.

 

DIDComm Update

@Steve McCown

Steve gave an update that binary encoding in CBOR is being added to DIDComm. The first byte of the CBOR will assert what encoding is being used. A PR is being drafted now.

Steve expects it to be a minor release.

Sam asked if the CBOR will be a stream, because a CBOR field map already reserves the first byte.

Sam explained that is what CESR does: the first byte can be sniffed to determine the encoding that follows.

Steve offered to share the PR here with the TSPTF once the PR is ready.

ACTION: @Drummond Reed to add to the next meeting an update from DIF DIDComm WG co-chair @Steve McCown on the addition of binary encoding to DIDComm.

5 mins

  • Review decisions/action items

  • Planning for next meeting 

Chairs

@Drummond Reed said he might have a conflict with the next meeting on Sept 17, so he will leave it to Wenjing and Sam to decide about that meeting.

Decisions

  • None

Action Items

ACTION: ALL TSPTF MEMBERS to weigh in on issues #56 and #57 on GitHub.
ACTION: @Drummond Reed to add to the next meeting an update from DIF DIDComm WG co-chair @Steve McCown on the addition of binary encoding to DIDComm.