Trustchain -- Trustworthy Decentralised Public Key Infrastructure for Digital Credentials
Abstract
The sharing of public key information is central to the digital credential security model, but the existing Web PKI with its opaque Certification Authorities and synthetic attestations serves a very different purpose. We propose a new approach to decentralised public key infrastructure, designed for digital identity, in which connections between legal entities that are represented digitally correspond to genuine, pre-existing relationships between recognisable institutions. In this scenario, users can judge for themselves the level of trust they are willing to place in a given chain of attestations. Our proposal includes a novel mechanism for establishing a root of trust in a decentralised setting via independently-verifiable timestamping. We also present a reference implementation built on open networks, protocols and standards. The system has minimal setup costs and is freely available for any community to adopt as a digital public good.
Cite
@article{arxiv.2305.08533,
title = {Trustchain -- Trustworthy Decentralised Public Key Infrastructure for Digital Credentials},
author = {Tim Hobson and Lydia France and Sam Greenbury and Luke Hare and Pamela Wochner},
journal= {arXiv preprint arXiv:2305.08533},
year = {2024}
}
Comments
10 pages, 4 figures, presented at the International Conference on AI and the Digital Economy (CADE 2023), Venice, Italy. Replaces the preprint version, with minor changes & additions based on reviewers' comments