Edge Rewrite
// HTMLRewriter · presentation

This page was redesigned at the edge.

Cloudflare fetched the original article and streamed it through HTMLRewriter to apply an entirely new visual system without rebuilding the source page.

// request.cf · coarse context

A page that knows where it met you.

Only coarse request metadata is shown. This demo does not display or persist visitor IP addresses.

Country
US
Cloudflare location
CMH
Connection
HTTP/2
Language
Not provided

Ray ID: a42f301b4cc96102

Jump to content

Draft:Trust Registry

From Wikipedia, the free encyclopedia
  • Comment: Thank you for making an effort to write a relatively neutral and factual article. The majority of the citations in this draft are to primary sources (WP:PRIMARY), which are not sufficient to show notability (WP:SIRS).
    Also, can you please disclose whether you used a generative AI tool to help write this article (see WP:NOLLM)? And do you have any relevant conflicts of interest (WP:COI)? Thank you. Dreamyshade (talk) 14:39, 25 July 2026 (UTC)

A trust registry (also called a trust list) is a repository that serves as an authoritative source of statements about a trust community, in particular which entities are authorized to perform which actions within a governed digital ecosystem, such as issuing or verifying a given type of digital credential.[1] Trust registries are a core building block of decentralized identity architectures based on verifiable credentials, where they allow a relying party to determine not merely who issued a credential, but whether that issuer is recognized as authoritative for that kind of credential under the rules of an ecosystem.[2]

In the model of the Trust Over IP Foundation (ToIP), a trust registry is the network service through which the governing authority of an ecosystem governance framework specifies what governed parties are authorized to perform what actions. A trust registry does not itself create authority: the authority of a registry is an outcome of governance, and the registry is simply the queryable expression of it.[2]

Background

[edit]

Verifiable credential systems are commonly described as a "trust triangle" between an issuer, a holder, and a verifier. Cryptographic verification lets a verifier confirm that a credential has not been tampered with and that it was signed by a particular issuer, but cryptography alone cannot answer the question that follows: is this issuer actually entitled to make this claim? A diploma signed by an unknown key proves nothing about whether the signer is a recognized university. This "issuer trust" gap is the problem trust registries address: they bind cryptographic identifiers (such as X.509 certificates or decentralized identifiers) to accreditations granted under a published governance framework, so that verifiers can check an issuer's status at verification time.[1][3]

The same mechanism can operate in the other direction: registries can also list accredited verifiers, allowing a credential holder (or their wallet) to check whether a party requesting a credential presentation is authorized to ask for it. The mechanism can further extend to other ecosystem roles, such as accreditation bodies that grant issuing or verifying rights to others.[3]

History

[edit]

Trust lists before decentralized identity

[edit]

Authoritative lists of trusted parties long predate verifiable credentials. Web browsers and operating systems ship root-certificate programs that determine which certification authorities are trusted, and document software vendors maintain equivalent lists for electronic signatures.[4] The most formalized example is the European Union's trusted lists: Article 22 of the eIDAS Regulation (No 910/2014) obliges each member state to establish, maintain, and publish a trusted list of the qualified trust service providers under its supervision, in a standardized XML format (ETSI TS 119 612); the European Commission aggregates these into a "List of Trusted Lists" (LOTL). A trust service provider is legally qualified only if it appears on a trusted list.[5] Under the eIDAS 2.0 framework and the European Digital Identity (EUDI) Wallet's Architecture and Reference Framework, trusted lists are extended to hold the trust anchors for wallet providers and credential issuers.[5][6]

Trust registries in decentralized identity

[edit]

As self-sovereign identity architectures matured, the need for a standardized, machine-queryable registry layer became explicit. The Trust Over IP Foundation, a Linux Foundation project launched in 2020, placed the trust registry role in the governance layer of its four-layer stack,[2] and its Trust Registry Task Force published a first Trust Registry Protocol specification (v1) in 2022.[7] The topic was also explored in community research, including the Rebooting the Web of Trust workshop paper "Verifiable Issuers and Verifiers" (2022), which catalogued approaches for communicating lists of trusted issuers and verifiers.[3]

The task force's work led to the Trust Registry Query Protocol (TRQP), a substantially redesigned second version. ToIP announced its implementers draft in April 2024,[8] and TRQP v2.0 was subsequently ratified as a ToIP Approved Deliverable.[1]

Trust Registry Query Protocol

[edit]

TRQP is a lightweight, read-only protocol for querying authoritative data from trust registries, described by ToIP as being "to trust registries what DNS is to name servers."[1] It deliberately standardizes only the query interface, not how a registry is governed, stored, or replicated, so that heterogeneous registries (government trusted lists, blockchain-based registries, federation servers) can answer the same questions in an interoperable way. The protocol defines two core query types:[1]

  • Authorization: asks "Has Authority A authorized Entity B to take Action X on Resource Y?" It is used, for example, to ask whether a DID is an accredited issuer or accredited verifier for a particular credential schema of a given ecosystem.
  • Recognition: asks "Does Authority X recognize Authority B as authoritative for Action X on Resource Y?" It is used between authorities, allowing one ecosystem or registry to acknowledge another, which enables federation and "registry of registries" topologies.

TRQP is registry-agnostic and transport-agnostic (an HTTPS binding is defined, with others possible), and its design anticipates bridges to adjacent trust frameworks such as OpenID Federation, X.509 chains, and TRAIN.[1]

[edit]

Several systems implement the trust-registry function with differing architectures, and interoperability between them is an active area of work:[9]

  • EU trusted lists (eIDAS): the supervisory model described above, with national, government-operated lists aggregated by the European Commission, carrying legal effect within the EU.[5]
  • EBSI Trusted Issuers Registry: the European Blockchain Services Infrastructure maintains a decentralized registry recording trusted issuers, their public data, and accreditations for cross-border public services.[10]
  • OpenID Federation: an extension of the OpenID family of standards that expresses trust through chains of signed "entity statements" resolved between federation participants, rather than through a central list.[9]
  • TRAIN: a trust-management infrastructure developed by Fraunhofer, anchoring discoverable trust lists in the DNS.[9]
  • Verifiable Public Registry (VPR): a public, blockchain-based "registry of registries" in which each ecosystem entry plays the trust-registry role, recording credential schemas and the participants authorized to issue or verify against them; it is queried during the trust-resolution process of the Verifiable Trust model and exposes a profile of TRQP v2.[11]

A 2024 Fraunhofer analysis compared four of these approaches (TRQP, the EBSI trust model, OpenID Federation, and TRAIN), identifying gaps in interoperability, governance, and validation, and proposing a "universal resolver" across trust registries.[9]

See also

[edit]

References

[edit]
  1. 1 2 3 4 5 6 "ToIP Trust Registry Query Protocol (TRQP) v2.0". Trust Over IP Foundation. Retrieved 20 July 2026.
  2. 1 2 3 "Trust over IP (ToIP) Technology Architecture Specification". Trust Over IP Foundation. Retrieved 20 July 2026.
  3. 1 2 3 "Verifiable Issuers and Verifiers". Rebooting the Web of Trust XI. 2022. Retrieved 20 July 2026.
  4. ↑ "European Union Trusted Lists". Adobe. Retrieved 20 July 2026.
  5. 1 2 3 "EU Trusted Lists". Shaping Europe's digital future. European Commission. Retrieved 20 July 2026.
  6. ↑ "Architecture and Reference Framework for the EU Digital Identity Wallet". European Commission. Retrieved 20 July 2026.
  7. ↑ "ToIP Trust Registry V1 Specification". Trust Over IP Foundation. 2022. Retrieved 20 July 2026.
  8. ↑ "ToIP Announces the Implementers Draft of the Trust Registry Query Protocol Specification V2.0". Trust Over IP Foundation. 3 April 2024. Retrieved 20 July 2026.
  9. 1 2 3 4 "Universal Resolver for Trust Registries in Decentralized Identity Ecosystems". Fraunhofer Publica. Retrieved 20 July 2026.
  10. ↑ "Trusted Issuers Registry API". EBSI hub. European Commission. Retrieved 20 July 2026.
  11. ↑ "Verifiable Public Registry (VPR) Specification". Verana Foundation. Retrieved 20 July 2026.