Decentralized Trust Graph Working Group Weekly Meeting - AM/EU Time Zone - 2026/08/19
Watch on YouTubeVideo summary
The August 19th meeting of the Decentralized Trust Graph Working Group, a collaborative effort between Trust Over IP and the Decentralized Identity Foundation, focused on advancing global digital identity standards through several key initiatives. The group welcomed new contributions, including an invitation to help plan San Francisco Democracy Week and the availability of Linux Foundation tickets for upcoming events in Prague and Geneva. Significant technical progress was reported by the Credentials Task Force, which accelerated preparations for the Global Digital Citizenship conference by aligning credential and trust test specifications using semantic versioning and establishing a dedicated repository. Meanwhile, the ZKPs Task Force highlighted a probabilistic trust prototype capable of verifying thousands of credentials in six seconds and successfully completed an external verification registry test, while also emphasizing the importance of using plain language to explain complex concepts to a broader audience.
A major portion of the discussion centered on the Human Trust Experience methodology and the evolution of delegation within an AI-driven world. Daniel presented insights from his recent trip to New Zealand, where he introduced the "sovereign stack" concept at the Digital Identity New Zealand conference, integrating tree keys, verifiable identifiers, and credentials into a framework for digital wallets and trust agents. This approach garnered significant interest among Māori leaders seeking peer governance models based on the Treaty of Waitangi. Concurrently, Glenn proposed a new Verifiable Delegation Credential to clearly distinguish between acting on behalf of another and granting access rights, addressing limitations in current systems that often require Zero-Knowledge Proofs for privacy protection in scenarios like parent-child relationships or maintainer transitions. The group also explored strategies to ensure their flexible, globally applicable architecture could complement existing EU initiatives like eIDAS 2, which tend to focus on per-device locked keys.
Looking toward future collaboration and documentation, the meeting addressed the need to formally document the group's unified trust infrastructure for the internet of humans and agents, acknowledging that such a comprehensive map currently does not exist in international literature. Participants volunteered to collaborate on producing this essential document soon, alongside requests for specific outlines on how their agents fit into the current landscape to share with partners from Singapore and Korea. The group also strategized further during pre-meetings for the Linux Plumbers Conference on August 31st, which will feature a deep technical rehearsal of the VTI setup designed to test user experience and scale across various operating systems. Attendees are encouraged to actively participate in these rehearsals by using persona DIDs to stress-test the system and identify potential vulnerabilities before the conference begins.
The session concluded with logistical updates regarding the upcoming week, which is scheduled to be meeting-free to allow focus on the Linux Plumbers Conference unless specific task forces request otherwise. Attendees were asked to confirm their availability for any necessary meetings during that period so the calendar could be adjusted accordingly. As the group moves forward, they remain committed to driving global adoption of robust digital identity standards while maintaining a philosophy that supports necessary delegation without compromising privacy or security. The collective effort continues to bridge gaps between different technological approaches, ensuring that the evolving landscape of digital trust remains interoperable, secure, and accessible to diverse communities worldwide.
Read the full video transcript
All righty, folks. Sorry, the uh
the Zoom gods are being a little slow
this morning.
Morning, Daniel. I see you there.
Hi, I'll pre-
I will prepare our
very full agenda page.
Get ready to share this here.
And we'll give it 1 more minute for
folks to roll in.
And let's see. Share here.
And does that.
Arrange windows.
Chat in there. Okay.
All right. Actually, I'll get a little
bit more room on that window if I go
like that.
All right. Can you see my screen okay?
Oops.
>> Yeah.
>> Good. Okay, it's 4 minutes after, so
let's go ahead and get going cuz we have
a very full agenda today.
And I don't believe I'm just looking at
We have Martina, but um
uh Nikki is out on her annual um,
August sabbatical that uh,
I
swear starting next August I'm going to
do the same thing.
So, welcome everyone to our August 19th
decentralized trust graph working group
meeting. We are a joint working group of
Trust Over IP and the Decentralized
Identity Foundation.
And this is our antitrust policy notice
that hopefully everyone knows well now.
Um, next thing [clears throat] we always
check to see do we have any new members
that would like to make an introduction?
I'm looking up and down the list and
they all look like very familiar names.
Uh, so
but always checking.
Um,
>> [clears throat]
>> you also can uh,
add something to our bio page.
Uh, D D D
bio and have a
link to that up in the chat.
And
uh,
you can you can also put something in in
the chat. Um, if there's anyone new. All
right.
So, um,
quick review. We have actually awful lot
of announcements uh, coming across but
that's uh, we'll we'll do that quickly.
Um, we have several task force reports
um,
including incredible set of notes that
Brendan just put together this morning.
Um,
and uh, from four four task force
reports here today and then
thr- actually m- m- three but we just
expanded to 1/4 uh, special topic
uh, that uh, Kaliya um, suggested to add
this morning. So, we got a lot to cover
and so let's dive right into it.
Um,
so starting with the uh, announcements
I'm quickly going to I will actually
what I'm going to do is I'm going to put
before I start editing this page all the
links to everything we're going to be
discussing are on the
uh meeting notes page. So, that's a link
that you can click into um
as we're editing the page, you will be
looking at the previous version and as
soon as we add any more links or
anything, we will um
refresh it and [clears throat] and to
refresh it yourself.
So, anyway, I'll I'll quickly cover
uh we have been invited
uh to help find there should be an help
there right there. Help plan uh San
Francisco Democracy Week uh
which is week of October 5th. There's a
bunch of us are going to be at the
um LF um
Plumbers Conference uh and the Open
Source um uh
Summit LF Open Source Summit in Prague
that week. So, um
number of us will not be able to go, but
if you're going to be in San Francisco
or going to SF Tech Week and you want to
be part of that, they have a planning
call this coming
Thursday and I'll put a link that link
into the chat.
You're welcome to join that. Um
Daniel, do you want to quickly say
something about your uh submission for
the uh GDC 26 fight of use case
promotion?
>> Sure, we'd love to, yeah.
Uh good to have your attention for this
case because I need some votes to get
visibility for this case.
Uh this is a case that this submitted to
the
uh uh GDC via Vitis.
They're going to celebrate kind of a
digital trust award and we built a very
nice case. It's actually built in
pre-production, so it's tested, it's
live. Um and it's about AI fairness and
responsible AI. So, the problem with
responsible AI is that the machine
itself cannot be held responsible and
it's not really responsible, but we can
use AI responsibly and we can do that by
using also our verifiable credential
concept and what we do is we
evaluate systems
on commission or you can do it yourself
on a platform and the engine identifies
the right mechanisms, the right meshes
and the right jurisdiction. So, it's
quite complex thing, but you can then
seal your readiness and your verdict
into a verified credentials. And we
don't stop there. We also provide a
customer receipt for the one person
where the decision has been made for and
this person can then see
together with some explainable AI
capabilities what made the decision,
what could have flipped the decision if
the owner of the seal wants that. So,
that's optional, but it gives the user,
the people actually some agency back in
the world where more and more systems
are making the decisions. So, we'll be
great to get your vote just to have some
visibility and I will uh
also paste link directly in the
comments. Thank you.
>> Yeah, I think I already did that. So,
you got you have it twice.
>> Fantastic.
>> [laughter]
>> Excellent. Thank you uh Daniel. I
already voted by the way. So,
>> Cool. Thank
>> All good.
Um all right. Um
>> [clears throat]
>> we will have a a special topic covering
prep for global digital cooperation, but
I just wanted to uh note that there are
still tickets available if you're
interested um in in coming or thinking
last minute.
Um so, um
the
Linux Foundation Decentralized Trust
still has tickets available. Uh you can
uh contact me or any any of the LFDT
staff to ask about that. Um and just
quick note, um First Person Project and
our partners including Infinity will be
hosting a first-person meet up in Geneva
that afternoon before of Monday before
um
TV uh the
>> [clears throat]
>> GDC.
And uh we we welcome anyone who wants to
come to that. We have We're still
figuring out the the venue. I'll have
more details next week.
And lastly, we now have a a special
topic on this uh but I'm going to copy
this
link out here that Kalea um brought to
my attention like last night.
A new paper from
Singapore AI Safety Hub called Designing
Agent IDs. And they have a task force on
that they put out this paper. And Kalea
will talk more about it on our uh
uh and our potential response to that uh
in the
uh agenda item our special topic number
four.
So, I'm going to stop and say, are there
any other announcements anyone wants to
make or we can dive into the rest of the
agenda?
I mean,
just checking.
We have a really full house today here.
Ah, okay. Let's dive into it. So, we
don't did not have any action items from
the last meeting. I missed the last two
meetings, but I checked the uh very
excellent notes by the way and um
um so, um and Nikki's uh uh
on her sabbatical this week, so no
activity uh risk and sexual harm
prevention except I think Saikrishna has
been doing some work there. Saikrishna,
is there anything uh you want to report
on that?
Do we have Saikrishna today?
>> Not specifically, Doman.
>> Okay.
>> The only The only The only thing I'll
highlight is that the task force
is now doing things asynchronously using
GitHub and Discord.
>> Ah, that's that's a good point. Uh
so, anyone who who is interested in
that, I know Saikrishna, you're doing um
uh I like it.
That uh
work
asynchronous
in
in the GitHub.
Um thank you, Drummond. If you happen to
have a link, um
I can stick in there. I would be happy
to do that in the notes if you stick
that in the uh
in the chat. Okay, uh Brandon, I'm going
to turn it over to you uh to give the
credentials task force report. And I'm
going to get your notes, as many as I
can, up here on the on screen.
>> Sure.
>> [clears throat]
>> Uh thanks, Drummond. So,
um yeah, just put a bunch of links in
here. So, there's been some activity
recently. The main thing to know is that
there is now a weekly
uh call um about the credential spec. Um
you know, what the pace has ramped up a
little bit as we're moving towards GDC
and then the Linux Plumbers conference.
Um
So, um yes, uh that's on the the Trust
over IP calendar. You can find it there.
And that's an open meeting.
Um if you want to join us. Um so, the
the notes, I'll just go through them.
They're also just listed here in the
document already, but uh we had a
conversation about, you know, keeping
track of the credential spec versus the
Trust Test spec. And they are, um you
know, needing to be aligned in various
ways. So, we're going to use semantic
versioning, semver,
uh with like a major, minor, um and a
patch
uh version. And so, just decided to do
that. Um
each uh spec will have free-floating
versions. So, they're not going to be
locked together. So, you know, the
credential might be on 0.4 and the Trust
Test might be on 0.9. But each one will
reference the minimum,
um
you know, version of the other that is
compatible. So, that's um how we're
coordinating that. Just a reminder, um
these are the links to the specs right
now.
Uh one other thing that was decided is
that it's time to create a trust task. I
I'm I might be scooping later later
notes from the trust task
task force, but they're they're going to
be making a spec repo as well. So, this
will help us all to
to keep things aligned and clear.
Uh one of the things that we're doing in
Keyring, you know, our project, this is
not
you know,
the official references of
of the task force or anything like that,
but we are as we're working to integrate
the spec and to prove things out, we're
making little references
that you can see to show how things work
and to confirm that they do work. For
example, we've recently added one that
is implementing our witnessing
flow, our witness flow witnessing
relationship credential formation using
trust tasks. So,
that you can find there and others. And
so, that's just a resource that will be
working as we're extending Keyring and
making it more interoperable with the
rest of the Open VTC DTG world.
Um just linking now some things from the
repos that are helpful if you want to
dive into details. Um there's an issue
about what you might call trust
ceremonies. So, trust tasks are a little
more atomic. You know, it's like one
specific trust task, but what if you
have a orchestration of multiple trust
tasks and credentials that need to be
linked together.
You know, the simplest example is if you
need to know that a trust task completed
successfully to be able to interpret a
credential. So, the credentials have a
task context field in them.
And
we are also looking at having a digest
that links to the digest of the trust
task that is is referenced.
So, there's a conversation about this
this issue 173.
We have a poll
that Alberto spearheaded into the
credential repo, which is aligning with
what's already in place on the trust
task spec
that Glenn's put in there that allows
this coordination to work, you know,
this kind of multi-part um
trust task flows. And so, it seems to be
working pretty well. But again, more
eyes on it, more folks reviewing it,
more folks implementing it in their own
flows
is going to be very helpful. So,
that's one of the highlights.
You know, one of the recent bigger
bodies of work is making sure that we
can orchestrate these these multi-trust
task flows and that if a credential
comes out of it that you can verify that
the trust task, you know, completed
successfully or has the state you would
expect it to have. So, I think we've
made some good progress there, but your
comments are very welcome.
This next one here, verifiable
delegation credential, that's the
special topic one of the special topic
Drummonds mentioned
that we'll talk about in more detail
below.
Just wanted to put a quick note that
it's important to distinguish delegation
from authorization and there's some good
notes about that on that pull request
and then we might hear more about that
today.
And just also a final housekeeping
thing. So, the
credential task force repo, which is
different than the spec repo, had an
outdated version of the spec and was not
pointing to the official spec repo. So,
that's been cleared up. So, now
hopefully all issues related to the spec
are put onto to spec repo and we still
have the task force repo for more
general conversations.
But so just wanted to you know, let
folks know where to find things. So I
think that's a good high-level overview.
Drummond, do you want to say anything
more should we take any more questions
about this?
>> I was going to say any any questions
Riza put something in the chat talking
about contributing trust task lib P2P.
>> Yeah.
>> Go ahead and Riza.
>> Yeah, so we've been tracking what you've
been doing. Thanks so much Brendan
and uh
being mulling over whether to fork the
code. We really don't want to do that.
Instead, what we want to do is
contribute a rust crate
that to to your code base and then we
would basically integrate just at the
crate level. So that means
so let me explain what it is we want to
contribute. We want to contribute
trust tasks for lib P2P. So P2P
peer-to-peer
infrastructure like the one that Quai is
building
does not assume that any node has a
public connection. So we want to
establish the trust tasks between
peers and
that seems to be a use case that is a
gap in the current code base and we
would like to contribute that but then
make that part of your project and we
would basically just
integrate at a crate level.
So we would basically get that bundle
that that library.
Um
>> [clears throat]
>> And Riza, have you looked at the trust
spanning protocol at all yet?
>> Um, I've not yet.
I think there's a there's there's a
massive overlap between what you're
doing Steve and so you're you're
creating the theory of it. Yeah, I've
>> Well, that's actually when James worked
with uh Sam over at uh Kerry, so it's
it's what we're building on,
but it's is not in fact my work.
>> Okay. So,
if if it So, so I've got a document that
I can
I'll be able to share shortly with with
you all and and maybe we're reinventing
a wheel that already exists, but I've
looked through the existing
documentation at least under the the DT
the distributed trust graph working
group,
and I couldn't find
the the sort of functionality that we
needed.
>> Yeah, uh
Yeah, I think that sounds really great
and yeah, I I personally, just speaking
only for myself, I like the idea of
rather than forking, you know,
contributing back when there's shared
shared elements and I think
I think we all agree that this is not
transport specific what we're doing, you
know, these these
trust tasks and credentials should work
over any transport and so libp2p,
you know, is certainly one of important
one of those. So, all of that that makes
sense to me
and
we are another thing that's on my mind
is
kind of conformance tests. I think we're
moving to that world where we're we're
going to need some suite, you know, that
can test that folks even with different
implementations,
you know, are producing the, you know,
compatible results, but this sounds
great to me, Reza, so.
>> Thanks.
I'll follow up with you and
see Glenn's got questions here
separately. I'll follow up with Glenn as
well
on the specifics.
>> Yeah, perfect. And
again, I wasn't here
um
last week, but I did listen to, uh, to
the meeting where, uh, Eric and and
Shannon were presenting their work on
the P2P Trust Act that is based on
P2P.
Uh, so I think you have nice, uh,
potential synergy there to, uh, Reza.
Um, and, uh, hey, that's what we're here
to do. It's It's bring all this, uh, the
code and the standards together. So,
um, why it's feeling like an only an
hour a week for these meetings. Well,
we now have The one thing I want to
reinforce is we now have, uh, Tuesday
morning is now three contiguous,
uh, time slots for, uh, for task force,
uh, meetings. Um, and and all those, by
the way, are on the Trust Over IP
calendar. So, the editors meeting, uh,
the credential editors meeting is open
to anyone who wants to attend. We had
several other, uh, folks attend
yesterday. Um, and then we have the ZKP
meeting followed by the HTX meeting. Um,
so, Tuesday mornings are, uh, deep dives
on all those topics. Everyone is, uh, is
invited.
Um, okay.
>> Can I say one last thing? Just real
quick, uh, Drummond.
>> One more thing.
>> Okay. Real quick, um, just wanted to
flag to the ZKP group, um, there are
some overlapping issues that we'll want
to discuss with you when we talk about
doing digests over credentials.
Um,
and, you know, are we supporting
selective disclosure? Are we not? So,
uh, we're not we don't have anything for
you to look at specifically, but just
letting you know that that's coming up
and we'll probably have to cross over
there. So, anyway, thank you.
>> Fantastic. Excellent.
All right. I knew there was a lot to
report there. Okay, next up, Trust Task
Protocols.
Uh, you've already mentioned that
they're going to have a separate spec,
but I'm going to turn that over to, uh,
Glenn and Jeff. Anything they want to
report?
>> No, I think, uh,
all that was covered in Brendan's
update.
>> Cool. All right, I will put the link to
the
the new repo that thank you Jeff for he
oversaw
getting that set up already. So that
pattern by the way will apply to all the
specs.
Any any task force that says we need to
do a spec
because the way spec up T works is a as
utilities easiest to create a dedicated
repo for that and all the spec up T
machinery that goes with it. So so for
every every every spec we have we'll
have a dedicated repo and we will keep a
an index of all of them on our on our
main page in the wiki and also on the on
the DTD general um
GitHub page so you can use either one as
a
as a
front door to all of what we're doing.
Okay,
on the VDS task force formerly
our cards no activity this week but I
will
talk a little bit in my uh
summary of the New Zealand trip. There's
a lot of interest in that function once
people understand that BTAs can do
peer-to-peer
data sharing it's a
they just start seeing lots of uses for
that.
I don't have anything to report on agent
names this week
if if I don't know Marcus as I don't see
Marcus here so I don't think we have
anything to report there. So over to our
last two task force reports first ZKPs
Scott Mitchell.
>> Thank you. I will use my auctioneer
voice in the interest of time.
We had a
good call yesterday. We welcomed David
Condry from Writers Logic as a a new
member to this group and fascinating to
learn about what Writers Logic is doing.
We are graduating our requirements doc
to an official V0.4 that Sankarshan
produced and I'm coordinating with him
live to get a pull request together.
Our verification registry got its full
uh uh first full external run from Glenn
Gore. So, thank you for that, Glenn. He
ran all three circuits himself. They all
passed and filed a ratified position.
Um, great independent validation. We'd
love to get more folks uh digging into
it as well as we keep going.
Uh Dennis demoed a probabilistic trust
prototype, which was really cool to see
proving credential connections and issue
of verification in about 6 seconds on
device across thousands of credentials.
Um
the the cross task force streams we're
tracking. We had one from Jeff Turk
about identity linkage. Um, and then the
one we just heard from Brendan. We're
here for it. We're excited for these
cross task force syncs whenever the time
is right so we can stay aligned.
Uh looks like we're getting closer to
getting the Berkeley team involved.
Drummond is going to give us a direct
intro um myself and Mitchell to Dr.
Sanjam and and uh Garg and Hart. Um
Yeah, and we are being very intentional.
Drummond raised a great point yesterday.
This task force is dealing in very
esoteric subject matter. So, we're
taking it very seriously to
uh lean into plain language explainers
and an AI first approach.
Um and we'll keep ourselves honest on
that. So, if anyone says what you're
doing is really confusing, I don't get
it, we'll try to make it better.
>> Absolutely. Thank you for uh for
mentioning that. It it I attended that
call yesterday and
boy, it's it's it's like
you know, suddenly waiting into a uh uh
uh
you know, an ocean beach and realizing,
"Whoa, this gets really steep really
fast."
>> [laughter]
>> But, it's it's absolutely necessary and
I really really uh am glad that that uh
task force is up and going. And I I do
have the action item uh Scott to make
that introduction. Um
I looked at it at midnight last night
and said, "Oh, I'm going to do that in
the morning." So, I'll get that done
shortly after this call.
>> Thank you.
>> All right. And lastly,
uh
HTX.
Um and I know Margie's on vacation this
week and next before she goes to the
GDC. So, that's over to you, Daniel.
>> Thank you again. Uh can you uh give me
the right to share?
>> Yes, indeed.
>> quickly there. Oh, hell.
>> Sharing it now. Go for it.
>> you. Try that.
>> [gasps]
>> Um um um um um um.
So, I hope you can see my screen. Yes, I
guess you can.
>> Yes, indeed.
>> So, just want to give you a a quick
insight in in what we do and how we do
it. And this is also
the company's this Margie's work. So, I
don't want to take a kudos
from her. So,
I would rather go into the methodology
quickly very quickly. So, what we do
here now is actually apply a a standard
human-centered experience analysis
approach. We derived a human trust
experience design framework for that
from that. And
it's basically a structured approach how
we look at at what's happening and how
we derive our deliverables from that.
And I guess this picture I'm showing
currently shows everything on one card.
So, it's it's a process that applies
different lens
uh lenses to the same topic. So, we we
choose a scenario and then we we look
from a persona perspective on it. We
look We look the into the scenario in
detail. We look at journey mapping,
empathy mapping, and so on. So, there
are different lenses
uh that there is the person human, the
journey, or the interaction itself,
which is uh the topic of the analysis
mainly. And in the end, that's the main
goal we derived in our design
requirements from that. And that's also
where our trust experience best
practices
uh collection could help them to map
these moments of truth you identify
uh to to best practice in this area to
find the better solution. So, this is
basically what we do and just to give
you without going into the content, we
don't have that time, but but how this
looks like. So, it's really an iterative
very heuristic approach and the benefit
is that we identify the important and
and maybe the the interesting moments
while playing through the this whole uh
scenarios and um it it starts with uh
the number one step here so with the
persona itself so that we can be more
empathic and and go through this entire
step until uh step nine, not step 10
yet. And when we have
uh a little bit issues to understand how
it really works, then we have to dig
deeper and uh play around and just uh
uh play through the entire action
sequence and that's also where we get or
where we can validate our assumptions
because we cannot yet observe things,
but we can do some interviews and talk
with you about that and you're also
happy of course to reread all the time
this Excalidraw
drawing is available uh via link from
our page or in the comments. I going to
paste that as well. So, uh you can
always leave a note in here. It's open.
So, that's it from my side. Thank you.
>> Excellent. Uh and thank you for the
link.
Um
that uh um that HTX call yesterday was
just fabulous. There is going to be so
much goodness coming out of that.
Uh which I will emphasize when we get to
our next Oh, I guess we're there.
Um all right, I'm going to share my
screen again and we'll go back to um
our reports. Uh let's see. Here we go.
All right.
And oh,
Zoom has learned to actually uh
replace things in the right place.
Oh, this great. Okay, so um perfect
timing. We're uh halfway through. We
have uh again four special topics to try
and cover in the next uh half an hour.
So, I will keep in mind as uh as as
um concise as I can, although I could go
on for hours about the uh the learnings
of my trip to uh
New Zealand um and and actually the very
last day to uh
uh I spent 36 hours in Melbourne um
and had a fantastic conversation with
two long-time Trust over IP contributors
there, John Phillips and Joe Spencer um
and we recorded a podcast there that um
actually I'll I'll find a link to and
put uh
uh put in there, but it you know, it's
sort of summarized all of the work we're
doing and uh and the things I learned on
my trip to New Zealand. The number one
thing I learned was there is tremendous
interest in
uh verifiable trust infrastructure that
we are creating here with the
decentralized trust graph. Um
I will share the uh the
the link in there, too.
The uh presentation I gave that for
specific reasons because they wanted me
to talk about uh they invited me uh uh
in the in the keynote of the their
annual conference for Digital Identity
New Zealand to talk about sovereign AI.
Um that's Oh,
uh Sai Krishna, fantastic. Thank you.
You've already got the link to the uh
that podcast. Anyway, they wanted me to
talk about sovereign AI, so I uh I I I
shared uh
uh
I I ended up calling the version of the
Trust over IP stack that we're creating
here with uh decentralized trust graph
the sovereign stack and I'm realizing
that
um there was I wanted to show one
specific
um I just have to get it up in another
window here.
And
let me close this for a second. I want
to show it to you.
And so I will actually stop sharing and
switch over to show this.
Um mm
okay, here we go.
Start here and I'm going to go into
slideshow mode because this is a build.
Uh
okay, are you seeing this now?
>> Yes.
>> Okay, good.
So um again, I I tried to capture this
in one screen and here's the quick
narrative that I gave to it. So the
sovereign stack
the heart of it is of course tree uh
keys um
um you know, public private keys and
algorithms that can be strong enough to
course
be quantum resistant even though that
does
affect the storage size and everything
else. Uh
in any case, the next next key uh uh
component verifiable identifiers from
the term that we use here at TrustOver
IP and in the TSP spec because it
it covers both DIDs and um autonomic
AIDs which is uh the the term that Keri
uses.
Um and of course the next thing after
that is verifiable credentials. And uh
what what explained because I you know,
one of the reasons they invited me down
there was because I'm known for um the
uh
uh the book that I did on on these
components uh being self-sovereign
identity um and really establishing the
the the the the essential tool necessary
for for wielding uh these things as
digital wallet.
And my key message uh
you know, you know, everyone there were
actually a couple people that had the
book uh
uh down there and it was like, oh yeah,
this is great and
the group I I first addressed was
um, uh, called the, uh, trusted
credential adoption working group of
Digital Identity New Zealand. And
they're bringing six credentials to
market. They've been working on it for,
um, like 9 months now after they passed,
uh,
a, uh, a governance framework for New
Zealand. Um, that authorizes, you know,
all of this stuff. One of them is a
digital driver's license. One is an age
over 18 credential. One is a government
access credential.
Um, and there there are a couple other
more more specialized licensing
credentials, but they're coming from
different issuers. They've got a very
healthy ecosystem.
Um, and so they they really get this
paradigm. And they were really
interested in uh what I'm what was I
bringing? I was saying, hey, we can
use all that, leverage all that, but
when you add, uh, when you wrap those
wallets in a verifiable trust agent, and
then you enable those to form verifiable
trust communities,
and those to form verifiable trust
networks,
well, then you have verifiable trust
infrastructure. Uh,
uh, thank you, Glenn, for for for, uh,
you know, um,
arriving at that at title. And now you
actually
got infrastructure that can deal with
digital agents of all kinds, of course,
including AI agents.
I was stunned at how they were just
like, whoa, this is really, you know,
they just
it didn't take much to, you know,
explain the advantages of doing this.
Uh, I followed it with our typical
explanation of how the, uh, DTG works.
And they were very interested, uh, in
establishing,
um, not just VTCs, but but potentially
separate VTNs in New Zealand. Um, and in
particular, I don't have time to go into
detail.
Um, there's a
it it
New Zealand is home of um the the Maori
people uh um that
is uh one of the most um
uh
There's a good quote for it. Anyway,
they're just one of the most influential
and and and well-recognized indigenous
peoples in the world. Uh they tend to
lead out uh
on on on issues involving indigenous
rights
all the way back to their uh Treaty of
Waitangi, um which is the basis for New
Zealand government.
>> [clears throat]
>> That's
still, I guess, very controversial, more
so than the US Constitution in in in the
United States.
Um, but a key facet of that from the
Maori standpoint is
uh governance of peers that are all
sovereign. And so, they saw here the
potential to have multiple VTNs in in
New Zealand,
which are peers that do not depend on
each other, but are totally
interoperable by virtue of the standards
we're working on.
Um, so
uh I'm not making that up. There were
Maori leaders that were part of all
these conversations. I talked to you
directly, and they were just
uh just way more interested than I had
any reason to expect. Um and uh so, we
are we're following up with them. I have
another call with them this afternoon.
Um, it was it was really exciting.
Um I then
uh in Melbourne uh uh uh
uh with was there and and was explaining
this again to uh John and Joe at um
Sezoo is the name of their uh um
uh digital consultancy. It's part of
something called 460 Degrees, where we
had an afternoon uh
um
event, and
they were saying, "Well, that's
fantastic. What about Australia? What
about the provinces in Australia? What
about Wellington as a city? Um, isn't a
city uh doesn't have so many VTCs that
it that it that every any any large city
could be a VTN?
And I was like, well, yeah. So, I have a
follow-up call with them later this week
as well. So, that's my my main message
is there is enormous interest in
our infrastructure
and uh
some folks are already following up at
GDC coming up later this week. So, I
think that's all I'm happy to take any
questions or have follow-on calls with
anyone who's interested in this. So, I
will stop sharing that
and uh
just get back to uh our main
our main screen. So, uh
And well, yeah, I I want to keep my
under 10 minutes to get it over to the
next thing. So, is there any uh
Oh, uh anyone from New Zealand going to
GDC? Uh Andy Higgs, who is the executive
director of Digital Identity New
Zealand, really wanted to go, but I
don't think he's got the uh
the budget uh to be able to do that.
He was going to investigate to see if
anyone else
from their group. I have a call with him
uh later today, so I will get the answer
to that.
Um
Uh
I I I really hope that would be the
case. But in any case, he he asked me to
represent what they were doing um there
at uh
uh at GDC.
Uh
how can I move that window?
Sorry, I'm going to share uh my screen
again, but I don't want to Oh, I see
what I'm doing.
Uh
Yeah, okay, sorry. I had to
get back to this.
Um okay, here we are.
Um
All right, I got I have to open the chat
to see are there any other questions
about that or should we jump on to the
next?
Uh
hello.
I can't get the chat up. There's my Zoom
is stuck for some reason not wanting to
let me see the chat. How's that?
I'm going to stop sharing for a second
so I can re-share and see if I can get
it to work.
Oh, fascinating.
It's just not letting me see the chat.
All right. Well, um
Glenn, over to you. Maybe I don't know
if you want to share then I could use
the chat again.
>> Uh, I'll just put the link in.
>> I can also uh click over to show the uh
um
your pull request if you want me to do
that.
>> Yeah, that might be easier on your
screen than
mine. So,
I know last week we talked a little bit
into for the last couple of weeks, I
think delegation has come up uh a few
different times in different strategies
of
uh what to do with it, but on the
implementation side we've run into
limitations of what we can express via
the existing uh decentralized trust
graph credentials
uh around delegation. So, we're
proposing
that there is a new DTG credential type,
which is a verifiable delegation
credential.
Uh I will say that there is likely to be
closely linked with another credential,
which
uh just for ease will name a verifiable
authorization credential, and the two
kind of go together uh as you go through
this, but
um
the difference is when you delegate,
you're giving permission to the
delegated authority to act on your
behalf. Um whereas when you give
authority, you have permission to uh
access is kind of how you think about
it. So, um having authority to access my
email uh doesn't mean you have the
authority the delegation to send an
email on my behalf as you go through
this. This is important for parent-child
relationships, you know, um elderly
individuals, those that for whatever
reason can't give informed consent. They
may be illiterate, semi-literate,
um
they may be
uh in a coma, lots of different reasons
in daily life while each of us might not
be able to give fully informed consent
and may want to give delegation at a
very specific level as we go through
this. Um so, it's
quite a complex
topic when you kind of think about it.
Uh and there's some notes in here
already around you does it need to
relate to a relationship credential you
kind of make sense in a way that if
you're delegating authority, there's
probably a relationship there, but
should it be expressly called out? Um
we're proposing a new credential type
instead of overusing one. We did try
actually to use the endorsement
credential type to
uh carry delegation, but we ran straight
into the issue of you endorsement saying
I don't know uh Scott is awesome at ZKP
is not the same as giving Scott
delegation rights to uh a GitHub repo on
ZKP, for example.
Um and so that's where it was coming up
in the Linux Foundation work was as we
start thinking about maintainers versus
contributors, if a maintainer is away,
they may actually delegate their
maintainer authority to somebody as a
trial
uh of them progressing from being a
contributor to a maintainer, for
example,
uh as we go through this. So, there's a
lot of detail in here. I'm not going to
go through it all.
Um but, you know, kind of open questions
are
is it the right word, uh
delegation?
Uh
are there
do we need to define the authority
credential at the same time? Um
how do you define scope of delegation
within this? Uh
we do believe that the delegation
credential in particular has a very
strong requirement for ZKP constructions
because you may not want to disclose to
everyone what exact delegation you're
giving uh between you and the recipient
uh where there may be others that are
witnessing that uh along the way
as well. So,
this will be part of, you know, a lot of
conversations on the DTG working group
uh as well as kind of trust tasks as
well cuz they do believe together. Um
but, if you want to know more, either
book time or feel free to
respond to the PR or talk to myself or
Brendan. Um happy to answer any
questions on this one.
>> This is a good, big, deep, ripe topic.
Um when it came up on the editor's call
uh yesterday,
I actually said, "Ah, I'm going to note
this as a milestone that we finally
uh are going to go down the delegation
rabbit hole."
Um
which, frankly, I don't think we ever
could have avoided. I'm surprised it's
has taken this long.
Any uh any questions uh for for uh Glenn
just a high-level about this PR? Um
go ahead, Erica.
>> have what I put in chat. Um
>> Oh, Steve. Okay, go ahead, Steve, and
then Erica.
>> I in uh
my proposal, I I uh had the idea for a
a multi-hop delegation record.
And so
basically, I would think that these
individual credentials would live inside
this sort of multi-hop record, which
would then be digested as a whole. So,
you would have a verifiable provenance.
Have you considered about multi-hop?
>> Uh
I probably need to understand what
exactly what you mean by a multi-hop,
but
>> whoever you delegated something to
delegates to somebody else, and they
delegate
>> Ah, okay.
So, there is there is uh we do have a
concept of that, and there's actually a
uh
like a max depth of how how far away can
you delegate from the original person as
you go through this. But again, I think
if you've got thoughts on that, Steve,
happy to dive into it cuz I think that's
one of the areas that's uh
ripe hazard for sure.
>> [laughter]
>> It was uh uh Sankaran wrote this piece
on it, which was, you know, informed my
design. So, anyway, okay, back to you in
in just book something then. All right,
thanks.
>> Thank you. Excellent. Next in the queue
is Erica.
>> Yeah, thanks. I put a a comment in
there, and I I think it kind of touches
on what Steve was just talking about.
I've been
also trying to deal with delegation in
our stack, and thinking of it as a uh
verifiable data structure, and not a
credential. Um but yeah, I guess
I I really thought about making it a new
credential. Um but I also I'm not ready
to give up on it potentially being a
just a data structure.
Um
>> [clears throat]
>> is there is there a space for a
conversation about comparing those two
approaches?
>> Uh yeah, I mean, would love to
understand you kind of have
VDS versus VDC.
Um
>> Yeah, yeah. I I I mean, I know VDS is
Yeah, they're not really graph claims,
and that's the thing. Um but yeah, okay.
I just want to throw that out there that
that we're taking a
kind of a different path. We may end up
at the same place.
>> [laughter]
>> Yeah, I mean, it could be that the VDS
goes into the VDC, and the VDC is just a
representation on the graph.
For example.
>> Yeah, yeah, exactly. Yeah.
>> Cool. I'd love to join that because I do
think the two things are are closely
uh uh related. Um
Uh
anyway, over to Grace.
>> Yeah, just really quickly, our um we
have a task force under the trusted
agentic AI uh working group, and they
they're actually in um
close to draft uh 1.0 of a review of the
different types of technologies and how
they think about delegation and
delegated trust, and you guys were just
talking about uh the difference between
delegation and and
Anyway, it's a really good piece of
work. I don't have the link on me cuz
I'm not I'm not in the office right now,
but um if you look at the trusted
agentic AI working group and under the
delegated trust task force, it's almost
a book. We We're still in the point
where we would love anybody to review
it, and there are a couple of missing
chapters, but basically, we've gone over
a lot of the technologies that do this
and the confused deputy problem, which
is uh what you guys were just referring
to. So, that's just something to look
at, and uh it's a good reference
material.
>> Grace, can you uh can you shoot me a
link to that when you find it? Cuz
>> Um yes, I can shoot you a link to that.
>> Yeah, uh just cuz it'd
be good to just
see if we can link to that.
>> Got it. And I And when when that
eventually surfaces, let me know, and I
will add it to the uh to the notes here
on this page because uh I yeah, I've
been aware
um you know, there's there's a
that's a very active working group at
DIF and uh that we were going to overlap
at at some point uh
Andrew Castleman who helped start that
um
felt the same way. So, that's
good stuff. Thanks, Grace, for pointing
that out.
Uh
I'll just add note here.
When we get to it, okay.
Um
any other We have We have 10 minutes
left or 9 minutes and two more things to
go over here.
Um
So, yeah, let's let's uh
keep going here. We've got
uh GDC coming up uh in 2 weeks.
Um what I've what you see on your screen
is um since they they published the
schedule of talks,
um there are four directly um you know,
that we are directly part of giving that
are that are that are tied, you know, um
to
uh to our work. Um those are the first
four listed here. And then we're also
included speakers in three more um that
are more of general, you know,
discussions uh that cover our space and
they want us to be a you know, a
panelist on those.
Um
uh I think the the main question Glenn
has raised and it's a it's a really good
one, which is um a lot a lot of the
focus there will be um on the uh it's
it's a global conference. So, not the
whole thing will be even though it's
hosted by Switzerland in Geneva,
uh it won't be just about uh eIDAS 2 and
the European digital identity wallets uh
uh work. Um it really does, you know,
have as much focus on on the you know,
initiatives uh and and approaches around
the world.
Um it's one of the reasons Linux
Foundation uh as a group is is is so
involved. Um uh so, anyway, Glenn, you
you brought up with me a really good
issue, which is alignment between
verifiable trust infrastructure and the
ideas.
Um, and uh I I do you have any specific
ideas for how um we we want to
uh you know, follow up on that
discussion or particular um um
folks or parties that we should uh be
trying to open that discussion with?
>> Uh ideally
trying to find people who either
directly involved in the standards of
that or can influence or open doors cuz
while I does is good
VTI
while it's aligned and can plug into it
it feels like EU has missed
some important uh steps in this that the
VTI is actually solving and so it'd be
good to say, "Hey, you've got something
that's almost 80% there, but
architecturally
you you've kind of skipped over and it's
a bit hand-wavy. This could fill in some
of the blanks for the EU digital
identity uh experience. So, I'm just
talking this, you know, a little more
bluntly and directly, but we need to
frame that a bit better.
Um,
but for example
they have a philosophy of it's per
device
completely locked down, never get your
keys. So, if you ever need to move
across devices or you have multiple
devices, it's effectively a
you know, each one is a walled garden
and that does not work in the kind of
world that we're thinking of with VTI.
Um, definitely doesn't work in a world
with AI.
Um that, you know, kind of having
delegated access to things on your
behalf as you go through it. So,
it'd be good just to kind of ask them
how are they thinking about this? Do
they see, you know, I would explain VTI
to them
uh Drummond the exact slide that you
showed before of the the onion layers
and then basically
are they philosophically opposed to this
or do they
see that this could work and actually
help drive adoption of the EU standards
globally into different communities that
are going to come up?
>> 100% agree and be very happy to you know
do everything we can there. Um, I think
we'll we we can strategize further on
that.
in our pre-meetings
uh and but I'm already already trying to
plant seeds with a few other people that
I know are going
uh and we can do more of that in in our
uh pre-meet on the afternoon of Monday
the 31st for anyone who's going to be
there then. Some people are arriving you
know that evening or or the or the next
morning.
um
um Glenn you also um just just for
anyone who who wants to come to that um
the you and Jeff have mentioned doing a
uh
uh a a
deep technical rehearsal of uh of the
VTI um setup that you you plan
you know to be showing at the Linux
Plumbers Conference.
Um,
is that still something that uh uh you
the two of you think you want to tackle
that that afternoon?
>> Uh yes for
probably half of the plumbers I would
want to
one do a user experience test, two would
like to do some scale testing. So, the
more people we can get and uh the faster
you can create persona DIDs at the
click of a key on your keyboard and just
basically try and break it. Um,
we would want to just do some bug
smashing cuz
uh only 2 weeks after GDC we're going to
be in a room full of highly technical
people who are we're to do everything
they can to throw things at it. So, uh
it's an important milestone just to get
as many hands, as many different
keyboards, operating systems,
uh usability in there and just see what
the experience is actually like.
It's going to be horrendous. I'm looking
forward to it.
>> [laughter]
>> All right. Um I will, too. So, again,
we'll get more details out that we'll
get the space uh uh reserved to get more
details out. Uh we'll probably uh I'll
I'll share it as soon as we have it. You
don't have to wait till next week, but
we'll certainly have it by next week.
>> [laughter]
>> All right.
Uh unless there are any questions about
that,
we will have in the final 4 minutes uh
Kalia, do you want to talk about this?
Uh I could I could
pop open this PDF if it would help. Uh
but do you want to talk about this paper
and and what you're thinking would be
ideal for us to produce?
>> Sure. Um
I [clears throat] was contacted by the
folks who wrote this paper last week.
Um I calmly sat down and read it
yesterday and was very impressed with
its breadth and the questions it was
asking.
Um
they,
you know, sort of asked who has a
compre- like, is there anybody else
doing a comprehensive map of all the
options out there? And I said the answer
is no. And then I replied to them and
mentioned the agent
names working group.
>> [clears throat]
>> Which is sort of what I had gleaned is
happening in in coming out of this
cluster a few months [laughter] working
on all this stuff. And Drummond was
like, "Oh, no, no, there's a whole idea
we have about how agents
uh and people connect." And
I said, "What can I point them at?"
Because these folks are clearly with,
you know, two
you know, reasonably together
governments, Singapore and Korea trying
to make sense of all this stuff. It
would be good to point them in what
we're doing, and they
And German said, "We don't have a
paper." And I said, "Oh, well, how
How can I tell them about what you're
doing if there isn't a thing to point to
that sort of paints the picture about
how agents fit in?" So,
you know, it's it was
you know, is there a short
It doesn't have to be a long paper, but
something that the folks who wrote this
paper could receive and understand what
you all are doing relative to agents and
humans and
how it fits into this landscape that
they're doing a reasonable job mapping.
>> Yeah,
and I want to reinforce the
as Kulia pointed me at it, I I quickly
read the paper last night.
And uh it's not very long. This This one
you put the link in the chat. Uh and
this is a table it has, which is pretty
I've been, you know, keeping track, not
not my own list, but
um by my I I think there are a few
additional protocol um proposals I've
seen that don't have the visibility to
have made this list.
Um but
but the solution we effectively are
proposing, uh again, the the title of
the talk we have a GDC, the the one uh
the first one we submitted is
decentralized trust graph uh a unified
trust infrastructure for the internet of
humans and internet of agents.
And so, we we do have, uh as I I saw the
thumbs up from Glenn, a pretty
comprehensive answer, um but we haven't
documented it in a in a paper that would
be, you know, something this group or
anyone else would say, "Oh, we
understand what you're proposing and how
it would compare to some of these
others."
Um and and and her point is a good one.
Um I knew my initial reaction was, "Ah,
I'm
struggling with all the other the I'm
trying to get written right now." And I
thought, wait a minute, there's a whole
bunch of us here and and some people
here that have some very powerful agents
working with them.
Uh
so, who is there
the one this call with a simple is there
anyone
you know, now well, Glenn's already um
um
volunteering. So, is there anyone else
who would like to join
uh Glenn's effort to produce such a
paper
um you know, in the relatively near
future?
>> I mean, I I I don't understand really
the scope of what they're asking for
because uh I'm doing more high-level
stuff over in the agents group uh which
meets uh tomorrow um
but yeah, the
uh
so, I I I don't know yet, but I'll look
into it.
>> Cool. All right. Um
>> I'll put my hand up for that one as
well.
Okay.
>> Excellent.
>> That's some agent major energy into the
paper.
>> There you go.
>> They're they're they're basically just
asking, what's what are pragmatic
solutions that exist to solve this
problem? That's the short of they're
asking for.
>> I was going to I know we're at time, but
but I was going to ask Glenn because
this is coming from uh Singapore, were
you aware of this uh
>> Yes. Yeah, yes, we are.
Yeah. Yeah.
>> All right. So, so this isn't isn't news
to you.
All right. That would be fantastic.
Thank you, Kalia, for uh bringing this
up. Um she has the broadest scope of
everything happening in the space. Um
so, really appreciate that.
Uh and with that, I think we're done. Um
amazingly, I actually got through it
all. Um just heads up, we'll have a
normal meeting next week, but the
following week is GDC and I'm proposing
that we have a meeting-free week that
week because a lot of us will be tied up
there.
Um so, obviously any task force that
decides it still wants to meet that week
can do that, but otherwise, if you're
notify us if you're planning to do that,
otherwise, we're going to uh tell uh
um the LFTT folks to uh clear the
calendar for that week. Yeah, as as
Sankara is is suggesting. So, I'm going
to ask you right now, any task force who
is still planning to meet that week, let
me know, otherwise I'm going to say just
uh wipe the meetings for that week so no
one's confused.
And uh
we will see you all next week or at the
next next task force meeting on Tuesday
next Tuesday morning, my time.
Thank you all.
>> Mhm.