Trust Registry TF Monthly Meeting- AMERICAS+EMEA Time Zone - 2026/08/20
Watch on YouTubeVideo summary
The Trust Registry Task Force meeting highlighted a pivotal shift in digital identity management as major technology companies recognized their inability to monopolize issuance, prompting sovereign entities and governments to actively seek inclusion in registries such as Apple Wallet. This evolution has moved the industry focus toward robust governance models, metadata standards, and defined assurance levels, acknowledging that while protocols like TRQP v2 are gaining commercial traction with organizations like IATA, significant challenges remain in preventing self-certification without independent laboratory testing. Participants emphasized that true decentralization often arises from inappropriate centralization, necessitating appropriate governance structures rather than pure decentralization to avoid duplication and fraud, a sentiment reinforced by examples like the AMVA's consolidation of US state registries and the UN's Global Trust Registry project, which faces limitations due to geopolitical concerns.
Central to the discussion was the hypothesis that higher assurance data holds greater value, requiring accurate identification of entities including companies and persons with aliases, while maintaining the registries' orthogonal independence from judging identifier quality themselves. Registries retain the freedom to select specific identifier types or DID methods they support, much like how IRA defines its scope by excluding non-DID URIs such as HTTPS URLs, yet the industry must navigate complex alignment issues between diverse groups such as the recording industry and photojournalists. To address these fragmentation challenges, significant efforts are underway to help various stakeholders define authoritative action-resource pairs using formats like C2BA credentialing, aiming to create a comprehensive guidebook for the Trust over IP task force that facilitates broader adoption across sectors like journalism and publishing.
As business models transition toward tiered access governed by service level agreements, market forces are expected to determine the value of different assurance levels, shifting the conversation from purely technical solutions to practical realities involving liability management and fraud prevention. The meeting concluded with a strong consensus that trust is fundamentally rooted in governance, reputation, and responsibility rather than technology alone, requiring registries to establish legitimacy without relying solely on blockchain infrastructure. Ultimately, the task force committed to sharing results regardless of whether their initiatives evolve into formal products, underscoring the need to align technical protocols with business realities to ensure a secure and interoperable digital identity ecosystem that serves diverse sovereign systems effectively.
Read the full video transcript
Good morning, Daniel. How are you?
>> Hello.
Good morning indeed.
Hello.
>> Hey, Zankan. How are you, sir?
>> I am good. We have Daniel with us on the
call today.
>> Daniel Bockenheimimer.
>> Hey. Hey. How's it going?
>> Great. How about you?
>> All right. Hanging in there.
>> Good morning, good afternoon, good
evening, Jeff. Not sure where you are on
the planet.
>> I'm at Lake Tahoe.
>> Nice.
Yeah.
>> Was early morning for early morning for
you? 7 or 8?
>> Uh 7 is it's 7, but uh just about
lunchtime given given the uh
international schedule.
>> Good. Good.
>> Yeah.
>> Hey, Dan, are you going to be at GDC in
Geneva?
>> Uh no. Marie Marie is going to be there.
Uh and and I guess maybe a couple
others, but uh I I will not.
>> Cool.
Yeah, the trust registries are becoming
pretty hot there.
>> Yeah. Yeah.
>> Yeah. More and more people adopt
verifiable credentials. I guess they're
saying, hm, how do we trust these
things? Right. [laughter]
>> Yeah. Yeah. It's a it's an
inevitability, right? You're like, wait,
hang on. How do I Oh,
>> right.
>> Oh, you you mean that famous anecdote of
Daryl printing credentials in his garage
doesn't hold anymore?
>> Exactly. Yeah. I try to try to sell
driver's licenses but yeah no it's been
interesting because because I'm chairing
the uh
the well I don't know basically all the
non- tech architecture stuff governance
on boarding policy tech
>> it's a mouthful of things that you're
sharing isn't it the last time you read
it off some document
>> yeah it's um
yeah [clears throat]
I didn't create the titling of it and
they they initially the GDC group
because because there's really two
things the GDC. Now, there's the event
itself and then there's the ongoing work
that happens now. So, they've kind of
got a uh you know a task force on trust
registries. They have one on age
assurance which I don't get involved but
yeah they merged a couple tracks. I'm
like policy onboarding governance
taxonomy and there's a fifth word I
can't remember what it was. So
[clears throat] we're but yeah we're so
it's interesting because it's uh it's
really you know real business questions
now because Apple it seems to me my my
summary of it is this is that the big
tech players were looking at MDL mobile
driver's license digital passports
digital travel credentials as a thing
that they could control and they've
realized it's out of control they they
they they're having countries and and
other you know subcountry you know
provinces whatever states
approach them saying we want to be in
the Apple wallet. They're like who are
you? We we don't even what are you
doing? Oh, they're doing MDL. Oh, we're
doing verif W3C. Oh, it's SD job. So,
they realized it's out of their control
now. So, that's good.
>> The fifth word was probably ontology.
[laughter]
>> Yeah. No, it didn't it didn't get into
ontology. It was uh it was specifically
taxonomy, which we turned into more of a
vocabulary. Anyways,
>> um Yeah. Yeah. I just I just I just say
that because you know lowercase O
ontology is being bandied about as the
next thing for AI and knowledge graphs
and all that. Um yeah my line with trust
registries has always been who's going
to bodyguard the bodyguards.
>> Yeah. Exactly. Yeah. And actually the
the the interesting thing we're working
on right now or have worked on it's
already done largely speaking. It
follows the trust of IP uh governance
template
is specifically handling the sovereigns
that we want listed because you know
they say maybe it was onboarding
included application or something like
application to be in a trust registry
which Dan as you would know you don't
ask a country doesn't want to apply to
be in a registry they're they're sort of
a they're more like no you will just
list us because we are are the sovereign
like you don't then then you get into
assurance level saying well what does
that mean you know that's where you
start to say okay there's some rigidity
to it which AMVA has done on the mobile
driver's license side they do have two
levels of assurance um but they're still
they're still just talking about the
levels of assurance now so
>> yeah EU is trying to do that with
qualified and not qualified electronic
signatures and things like that
>> yeah it's like so what does not
qualified mean [laughter]
it's like yeah I'll sign it but it's not
qualif Boulevard. Um
>> well, it just means that you didn't go
through that that whole uh process, the
official process. It's just like, you
know, within PHTO, well, I
selfcertified. I self- tested it. You
have to believe me that, you know, my
false accept and false reject rates are,
as I stated, we didn't have an
independent, you know, certified lab um
certify us, right? Self-certified.
>> Yeah.
>> Yeah. And that's some of the things that
we're looking at for next stage is is
what do you expose in the governance
side which gets into our discussion here
at trust the trusty task force which is
what does the metadata look like so that
we can have some kind of a standard way
of saying hey in order to be in this
registry let's assume it's not the
sovereigns because they're not going to
apply to an ISO certified lab for
testing though they may that's their
choice but many of the higher assurance
industry things will need to have to see
you know were you tested by a certified
lab.
>> So to me the the most uh yeah the the
best longest global example of that is
IO and member states do um apply to be
and pay for um the right to be in IO's
public key directory. Uh which the US
does, but we don't use the public key
directory because it's in Southeast
Asia. It's hosted in two sites there and
we say screw that we'll have our own
you know list
>> but and a KO was created in a in a very
different time right
>> geopolitics wise the UN was the was the
thing now it's like the UN's what not
the UN's going to tell me what to do
yeah that's that's not geopolitically
take
>> and it really breaks down um in terms of
what you're saying about levels of
assurance you know so IO has trip the
traveler um registration uh identity
process, right? And we're supposed to
create passports in this case where um
the photo in that uh as introduced in
1995 is used to bind the presenter the
natural person presenting these
credentials to the actual
cryptographically signed credentials.
But because we don't have levels of
assurance uh that are audited, US allows
you know morphed faces poor quality
faces in the passport so that when we
use them in an e-gate three of us could
use the same passport to get through an
e- gate
>> because there's no levels of assurance.
>> Yeah.
>> Yep. Yeah. And that's the
to me that's a consequence of trying to
do too much in one spot. But at least
they've tried it. They've exposed it
going this is not working. Like we at
the IRA for example, we we've really um
simplified things to be focused on only
two things and it's really one trust
registries that registry of registry
connection. That's fundamentally what
the IRA trust network is about. The
other that we have a bunch of members
asking about is person binding is
because that's a everybody needs it and
it's not being there there's some
technical standards but then you get
into the business process of what does
it mean when I tie that in that's a
whole different thing that's not a
technical process anymore.
>> So it's sort of how can we create
business guidance we're not sure if
that's going to turn into a problem that
IRA is going to help solve but certainly
the trust or agencies is our is our
game. Yeah, and we're working on that um
onholder device binding within ISO
18013-5 series. It's actually in the
23220 series that the MDL, you know, and
other STA ISO standards refer to and
there's definitely levels of assurance
and and it does talk about both
biometric and pinbase and we try to
expose, hey, if you're Europe and you're
poo pooing biometrics, you're you're
never going to get non-repudiation.
Yeah, you could request or demand
assurance level high, but if it's pin
based and I have Daryl's advice,
>> right? Yeah. [clears throat]
>> Yeah. Well, and that's actually and
that's actually I was surprised to
learn, but I guess it's just, you know,
my world. I was surprised to learn that
the credit unions, that's one of the
biggest things is family fraud, which is
I know your PIN.
>> Yeah. And I'm going to and I'm going to
drain your account.
>> Um Yeah. Yeah.
So just uh for for today's task force
meeting I mean I didn't have a
particular agenda Drummond ping he says
are we doing like everything else and
cancelling August and it's a little
little late I'm in bed like I was asleep
when he asked so I'm like I'll be there
to make sure people but what do you guys
So one of the things that Sankers and I
and I have been working on and this
might be new for you both both you
Daniel and and Jeff is kind of the
what's next. So,
I'll see if I can lower while I'm
yammering on pull up a diagram that we
created some time ago.
Um, that covers off um that really what
we're looking at is the protocol itself.
So, trust res task force is bigger than
just TRQP. It's about trust in general,
how do they work and how they interact
with the world. TRQPs is sort of a core
protocol. Um, yeah, I found it here. I
found the diagram here. Just to share
this and so I have something to speak to
at least.
Uh
yeah, I've been on the road a little bit
here.
So if we look at the big picture, you
know, TRQP version 2 is approved. We're
we're getting more and more um
commercial members by the certainly in
the IRA space
um building. This is built into their
product and being used in production
now. So that's going to be a good signal
we can share at trust over IP in here is
where is it in use but once we have that
available what becomes possible
so and put in the a whole set of tickets
on a bunch of different things but they
range from life cycle meaning what does
your trust registry do in the visa v um
life cycle I see a chat message
what's next there we go
>> that's just a link to the thing the the
The big the big question. Perfect. Yeah.
Perfect.
>> So this question that that Sankeran
created was was really a beautiful way
to structure
>> what do we need to work on next? And
this is not necessarily
one of the things that um Scott Perry,
you know, he's very forceful. He's like,
you need to work on X. I'm like, we're a
bunch of volunteers. You don't tell us
what to do. We build consensus and do
what's necessary. Now, our clients may
push us to do that. That's too that's
true, too. But it's important for us to
know what's possible as the next thing.
So this is a great thing to look at the
detail of it. This kind of diagram here
sort of speaks to some of it. So life
cycle speaks to the hey what does it
mean in your world if I say if I'm
managing a list of professional
engineers? That's a very different thing
than I'm managing a list of education
institutions that are that are issuing
education or workforce credentials.
when I revoke something, what does it
mean? If it's suspended, what does it
mean in the outside world? Because
really, the TRQP is a true and false. It
simply says, "No, that did not check
out." It may provide more information,
and that's really different different
worlds.
There's also a discovery need, you know,
how do I find um who's in the ecosystem?
This is something we do at IRA right
now. We talked about many, many months
ago is this was part of it. you know, I
could find the it's not very it's not
zoomed in, but oh, there we go. Um, you
know, list the entities in the in the
registry, list the ecosystems, the
lookups and metadata. This is something
that was in the original TRP before it
was called the query protocol. Um, but
we removed that to simplify on the
protocol of simply being authorization
check and and recognition check. That's
something we are working with actively
with our members which ties into a
registry of registries use and it works
by extension. It doesn't change the
protocol. It just adds more to it um to
allow us to do that. But then we get
into transport. We know for right now
that in production now there are both
didcom and tsp implementations. So the
spec itself is HTTP based but now we
have TS transport trust spanning
protocol and didcom implementations that
that someone can bring to hey here's our
implementation.
We also get into credential ecosystem
interop. So how does a credential
ecosystem work with another one? um on
at at GDC on day two. So 9:00 a.m. I'm
opening up the trust registry track
keynoting that and then we have
following that immediately is a very
detailed examination of AMVA which is US
Canada and OSROS which is Australia New
Zealand. They are trying to get into
alignment on recognition of driver's
licenses. So um they're getting into the
details of you know one their assurance
model is not just
it's not just a mapping of assurance
levels they're orthogonal they're
they're different assurance levels when
you take NIST as your as your model yet
you have another one is based on
business risk they're not the same thing
so they're trying to map those how do
they say this is functionally equivalent
to this
um other non-functional requirements you
know performance Scott Whoops Sorry,
Scott's pointed out that we really start
we really need and this is part of what
one of the things I'm doing at least and
and anywhere you think we can do this,
please let me know if you want me to
jump in or if you want to jump in get
the message out on the promotional
material. How do we share with folks
what it means? I've been helping COG
creator researching working group
understand what trust registries are
where they fit and what's interesting is
COG a lot of the members of COG are
groups like the international press and
telecommunication
cooperative I don't know what the C is
for um recording industry artists
uh there's one that does
what do they do they call them career
talent identifiers this is for sports
entertainment writer songwriters,
um, including fictional characters. So,
you could have Robert Downey in there as
an actor, as a producer, but also Iron
Man as a character. Who's licensing what
um, and getting the guidance pieces in,
we call traction. These these three
pieces kind of come together. And then
we get into the uh, uh, governance
metadata. Now, I've zoomed in on things
and I don't know how. There we go.
governance metadata which is where a lot
of the uh right now certainly certainly
Apple and France who are leading the
task force that um that we've kind of
taken over in some ways um we're
certainly providing the the what we've
recognized is those of us on doing the
trust task for task force work here at
trust over IP we just have been down the
path further that's all we just know
more about what's on the path so we've
been able to add a lot of value there so
that governance metadata becomes key I
have a feeling that's going to get
shaken out somewhere else. I hope um
we're not going to invent a metadata
standard. We'll find one that gets
adopted Z3950 or whatever Dublin core
whatever the metadata standards are and
we'll just you know point to those
recognition and security profiles. So I
can't say but and and Seran has done a
ton of work on on all of these and
specifically
where would I click through um um
Sankeran for the
>> if you scroll down a little bit you'll
see the list of linkable stuff. Yeah,
there you go.
>> And which one has the time discussion
that's on right now?
>> That's the life cycle method that I can
see. So this is one that's got some some
heat meaning it's got some active
activity where we talk about has done a
bunch of work on you know in the
protocol itself we say hey there's a
context time
parameter
and it is simply I want to know the
answer as of time x
that's it
this gets into well what does the time
mean what else can I learn about it when
did you if I want more information
returned which is their option not a
requirement necessarily. If I want to
say hey this is valid from here until
great I can do that or I can tell you it
was revoked at or suspended at whatever
whatever that data the metadata are that
I can provide with the information on a
particular entity. This gets into the
details of that. What's really cool is
it's also generated if I mean one
there's a lot of detail here. Um but it
also my my word has it gotten detailed.
Well, these are these are some
responses, right? Sashan. Yes. So, we've
had some outside folks.
>> Yeah. You please do this.
>> And I just I just wanted to add a bit of
context. So the the UN sefac folks are
doing the the grid or the GTR project
and the UNP teams are doing the DIA DIA
digital identity anchor I believe it's
called and they have been going back and
forth about how to view the concept of
time uh in the registry but more in
terms of what is the liability or the
responsibility of a registry in terms of
the data that is going to show and
there's a fascinating discussion that
kind of I got John Phillips uh who's
also I think uh a very regular trust
over IP contributor to chime in on some
of the work that he has done and then I
blended all the stuff into a version of
what it might look like. So there's a
second draft now that that's added which
is why Daryl do you see it the issue has
become longer than it was previously
>> right and we also have the um the the
some other folks have been chiming in on
on ideas and how you do these stuff
which is great because it's getting more
interest in what the work that we're
doing here. Um, one one point on that.
Um, during on day one for sorry, day two
for the GDC, um, Steve Capel, who works
with John on the UN ECE,
uh, the UN TP stuff. Um, he's
presenting. They've renamed, by the way,
GTR. It is now called Grid
Global.
>> Yeah, I should I should have said that
given I turn up at every single meeting
and work with them. Well, it's funny
because the the the GTR, global trust
registry, it's actually terms registry
of I keep on forgetting what it is. I
I'll give it to you in a bit.
>> Yeah. Global registry. Global Yeah.
something directory or something like
that.
>> Yeah.
>> But uh what the term global trust
registry all three
>> global registry information directory.
Sorry about that.
>> Information directory. Yeah. The term
global trust registry. All three words
caused conions in various different
places. If I'm a registar, don't you
dare use the term registry. If if if
it's global, don't tell me what to do.
Trust, how do you define trust?
[laughter]
They're like, wow. So, it blew up.
Interestingly, but now they've got, you
know, the feedback they've received
because of that has been really, really
helpful. And their idea is this. Um so
if you take the example of we need to
know where all of the the
sovereign issued just governmentisssued
identity documents that's a term that
we're using at uh GDC they don't like
the term digital identity because UK
Canada US all freak out when they hear
the term but you have all these
documents so driver's license ID cards
and passports call them that
where do you go to get the list of
countries you're going to multiple
places to go. Dan, you've already seen
this in IKEO versus the the US regist
registry and I'm sure other countries
are doing similar. So, you're going to
need a place and the UN is a very valid
place to put that. It's not the only
place. So, some folks at the UN think
that the UN is the source. Therefore,
thou shalt use it. That's not going to
work in our geopolitical climate, but it
is a great place to put it if you don't
want to have to run a registry because a
lot of people are realizing running a
registry is not trivial.
But it's neat all these discussions are
happening. The coolest thing I'm finding
right now is last year at GDC, were you
there last year, Dan or Jeff?
>> No. Last year GDC, much to my chagrin,
the most common question I got was
what's a trust registry?
>> Yeah.
>> This year it's where are they running?
It's like oh. And some folks are saying
and what do they need to support because
I need them. It's like oh good. So now
the business questions has have
fundamentally changed. So this is the
kind of work that that that we you know
we get to decide what are we
individually groupwise wanting to work
on next. This one clearly the life cycle
metadata has clearly got uh a few folks
um very very interested but I'd
recommend any everyone look through
those those those uh especially um
Asan's um original
question which gets into the you know
where are the areas that we may want to
that's not the one
that
it's not it
there we go where the these get sort of
the big picture of where it is you're
seeing activity. Dan, I know that you've
got some areas where you're seeing
registry of registries activity where
you have different groups. You have
different groups who no one wants to be
in char that guy to be in charge, but
they need the information.
>> Yeah. I mean, you mentioned AMA before
and and each state um or province is
sovereign as you uh intonated. Um but
what AMA's doing uh they're not calling
it a global trust registry but they have
their um uh you their trust service um
you know that their their DTS um you
know to amalgamate all those independent
sovereign registries so it's one-stop
shopping but each um entity is still
sovereign it's just yeah under one
umbrella you know
>> and I do think it will be um as this
develops, matures, still, you know,
driven by the industry. You know, IATA's
going to be there. I'm still
contributing to IATA and they're having
a a premeating meeting, you know, in
Geneva. But, you know, there, you know,
so I mean, IATA already, you know, has
like Tmatic for um as a service to our
airlines for determining what
documentation you need and they're
trusted to do that. right now. Will for
the air industry, will IATA emerge as
maintaining that trust registry as more
and more airports and airlines use these
digital credentials for contactless
experience and stuff that you could
share your credentials ahead of time to
make that process. And I'm sure we're
going to see the same thing. We're
seeing it in education with educational
searchs with like credly you know we're
seeing it in health you know
>> um so you're right there's but I think
it's going to you know emerge as um in
the private sector as industry based in
the public sector you already said it's
going to be the you know um u expanding
the registries that are in place today
>> um y
>> you know like um uh yeah national IDs in
countries that have that um and you know
as we see a lot they're creating more
and more digital identities leveraging
those uh national IDs like in Bhutan um
things like that
>> um and in ISO world I'll just end it you
know leveraging on the MDL or MDOT
standard um we have a proposed birth
certificate digital birth certificate
We've already seen the vehicle
registration
standardization. Now, birth certificates
are probably going to be the next um
standardized um uh in in terms of the
schemas, but it's still going to be
sovereign um registries that you know,
birth and death registries that
countries are going to own.
>> Yeah. Yeah. That'll be interesting
because you're now crossing domains as
well because when you're going from
driver's license to vehicle
registrations, that's the DMV. At least
in a North American context, it's it's a
similar group of people driving and
vehicles. But then you end up touching
the CRVS world or CV RS.
>> Yes. CRVS. Yeah.
>> CRVS. What? Something blah blah vital
statistics. It's
>> right.
>> Critical records and vital statistics,
which is birth, deaths, marriages, that
type of stuff.
>> Yeah. Um, another thing I was talking to
Sashan about this. This is one that I
learned recently. So, speaking of
operational trust registries,
um, friend of mine, he's a former
business partner of mine. Um, he's the
treasurer for Eclipse Foundation. So,
he's he was the number two there. He's
now stepping back and just doing the the
required officer work as he retires.
But, Open VSX is a standard that's been
around for some time. this. If anyone's
using uh Visual Studio and they're
adding extensions, that's what it is.
It's the where do you get the list of
extensions and how do you download them,
how do you update them, all that type of
stuff
that was running. There was one server
that was running and everyone was using
it was like literally not quite but damn
close to just sitting on the side of
someone's desk like sitting on someone's
desk as a just a computer, not a server,
no service level agreement. With the
advent of Agentic AI, the number of
people using this has gone up by orders
of magnitude and it fell over. It
collapsed. So they realized they had to
stand up an operational registry um have
done so. So they have the big players,
Anthropic,
um Open AI, data bricks, all these types
of players um paying relatively huge
fees to keep those services running with
service level agreements, you know. So
you have free access, but then if you're
an enterprise, you have a tiered access
type of thing with service level
agreements, which is interesting because
it's also shaking out the business model
behind trust registries. We're hearing
at the at IRA more and more members are
now getting inbound queries about
establishing
what do they do for trust registries and
how are you going to help me run one. So
the countries for example like AMA
states will go to look to AMA as one of
their providers, right? They look to
Ambas saying, "Hey, I'm going to be part
of your digital trust service because I
don't want to do it myself with my IT
department." Other states be like, "No,
no, it's fine. Our IT department do it."
Great. Perfect. That's awesome. Um, but
those are real businesses that are being
established now that are effectively
trust registries. So, it's nice to see
the shift over the past year. It's been
it's been quite the sea change.
Jeff, what are you hearing?
Um [clears throat]
well I think this kind of has some
parallels to other issues with other
identifiers. Um I was on the board of
the uh global lei foundation for seven
years. help was on the help started and
there is a a juncture um you know the
verifiable lei has been the means by
which the gly had had hoped to expand
its reach from 2 million to 20 million
uh and and in e-commerce and there's a
lot of headwind because right now it's
only mandated and supported in the
financial sector uh at institutional
level and so
>> the the challenges to um
just have that one identifier be used
more um has you know and open corporates
is doing a very nice thing with this
thing called the proto or the PLI which
uh is basically leveraging you know
Chris Tagger's open corporates scraping
of all the commercial registers of
businesses
>> y
>> and and using the um you know ISO17442
format for the LEI to create you know a
a a temporary uh identifier called the
PLI Yeah, a a placeholder type of thing.
>> Well, a placeholder and but but the
discussion also revolves around the fact
that unless the actual you know in
theory the the verifiable LEI credential
is dependent upon the chain of trust
from the gly down to the QVI down to the
entity down to you know the uh issuance
of of the LEI and so so the PLI cannot
issue a VI. Um
and but the problem is that the adoption
of the LEI in order to support having a
VLAI under it is challenged and and
um the this whole thing about and the
other parallel that comes to mind is the
is the
uh is the plethora uh of different forms
of blockchains that are having digitized
tokens on them that need some type of uh
interoperability mechanism like chain
link to try to transfer things between
blockchains. And so the more that you
have um tremendous numbers of different
organizations saying, you know, they
have a solution to some problem and now
you need to have have figure out how to
interoperate or, you know, uh trust each
other. I see I see a big issue here with
regard to trust registries because, you
know, if I can open up a trust registry
at my corner deli, um it's almost like
how do I
>> y
the whole thing about how do you know
that you're not doing duplication of
identifiers or that you're not have you
don't have overlap or how do you there's
this whole issue
>> or or yeah perhaps the question is what
do you do when you know you have
duplication
>> yeah but just the opportunity for it if
there is no in fact you know the the the
decentralized approach to the world is
is came on because nobody liked the
centralized imposition of of things and
yet at the same time when you get down
to ultimately decentralized
uh it's it's basically the wild the wild
west and you've got you know local
county board doing so I I think there's
a real big all the technology and all
the thoughts about how these things can
co can interoperate with a protocol is
nice but I see it really as a governance
and uh it's it's like an accreditation
or certification problem of who are the
resources that can in fact ascertain or
uh basically
um a credit the that these are
legitimate registries.
>> Yep.
>> And they and they don't contain they're
they're basically not made up. They're
not artificial in the in the AI sense or
they're not criminal.
>> Um and they're not they're not
deceiving. They're not gaming the entire
system. So I I see a real issue here
with disregards at the high level view
of how does this plethora and um
incredible growth of all these
opportunities everybody's setting up a
registry defeat the purpose.
>> Yeah, there's a few things I would not
by no means push back. I I agree with
much of it. One is one point I would
clarify though is I believe the
decentralization of something is driven
by the inappropriate centralization of
that thing. Mhm.
>> Without decentralization of what we're
talking about,
>> it's a meaningless term.
>> We we internally it's like when people
say we need decentralization, no we
don't. We need appropriate
centralization or appropriate
decentralization.
That helps us answer a few things of you
know what are we actually this is an IRA
perspective. What what what are we
caring about? The other is this is that
liability comes in there a lot, right?
The liability of me saying you should
use that registry is hard, right? It's
like that's what I consider official.
It's okay. Well, then what does that
mean? Can I sue you if you're wrong?
That's why the recognition again the
only thing the protocol does is it'll
answer an authorization which really
gets into the detail of a particular
business domain. You know, are you doing
driver's license? That's very different
than if I'm doing creative artists who
were doing something. That's very
different worlds. But they know their
worlds really well.
>> And by the way, they're already the
authority today,
>> right?
>> Yeah.
>> So if I have the recording industry, I'm
and they put up a registry. Guess what?
They carry their authority with them.
>> If you want to stand up your own,
perfect. Great. Compete with them.
That's okay.
>> Well, this this has simil not to
interrupt that. This has similarities to
what CNRI did with the um the rights
databases for for the entertainment
industry for movies in terms of who who
gets credit, you know, on the roster of
credits for movies. And that's that's an
entirely and and so the handle system
and allocating out authority to a topic
like like uh you know, fishing fishing
uh sports fishing, you know, as as a
handle system repository of information
by object type.
is is you know that kind of is a and
people can stand up their own um servers
saying I I have information about I have
documents about this topic
>> but documents about a topic documents
about a topic is well that's you know
SSRI network that's everybody can write
documents and and make articles but
verifying identities and having
credentials
>> is is a much more highly constrained
reliance and reputation and
responsibility topic that is is the
heart of all trust of other things and
so that is why it becomes much more
challenging topic I believe I have one
question
there are all of these registries are
essentially saying that
here are people that have registered
with me here are identifiers and what is
is there actually a common standard for
the type of digital identifier that's
being used because there again there
again you've got the oh I have this
blockchain protocol all that does this
type of token and I've got this other
one that has this other type of token.
How do I
>> standard? Yeah. The only standard we
impose in in in the in the protocol at
least is is a URI.
>> That's it.
>> Okay.
>> Which comes with its own baggage, right?
>> Yeah. Well, welcome to the medic.
>> But you can choose your U. Yeah. But you
can choose your URI
which could which house helps you if you
do a you know an HTTP web, you know,
just what we would call a did web but
just use an HTTP address. Yeah,
>> you can do that.
>> If you want the other things like I want
an Ethereum anchor did or a Salana
anchor did, great. I can use that, too.
>> Yeah,
>> because there's no standard identifier.
That's one thing we've learned.
>> Yeah. So, how that's that's good. I
mean, you know, that's back to the uh
you know, semantic web of the 90s. I
mean, you know, just look up the
definition of currency code with 128
character URI,
>> which is which is one of the reasons it
didn't work. But
>> y
>> then how do you how do you prevent sock
puppets and you know Mickey Mousees and
all that kind of stuff.
>> Y
>> well that's just it. So so so that's why
you want to know let's go to just a
government registry. So if we have a a
registry in Canada, and this is
something that's actively being
discussed,
>> a registry of registries in Canada that
is focused specifically on
identification issuers, education
issuers, and I think they're talking
about healthcare issuers. That's a real
business thing. At least it's it's
identification, government ID, and uh
education
um including driver's licenses
specifically. And Japan does the same
thing. And then you notice a signal that
Canada recognizes Japan, Japan
recognizes Canada. What does that tell
you? It tells you, huh, two countries
are talking and actively willing to say,
I recognize them. Nothing more. I
actively recognize them.
>> Yeah.
>> Which is how the
web of trust forms. That's a signal.
That's not your only signal by any
means.
>> But then you get into things as Dan
alluded to, which is when you start
getting into assurance levels. So, so
this open VSSX thing for example is a
good working example of here it is in
free form use it with no no warranty
total indemnity
or no I want I want a service level
agreement which means I'm willing to pay
to understand what's behind the thing
and the market then discovers what's
worthwhile if I'm getting a corporate
identifier and it's $10 a year is it
fundamentally different than $1,000 a
year when it comes to to the fact that I
can't join a registry unless I'm a
higher assurance level. Therefore, need
the $1,000 a year thing. Who knows?
That's for the market to figure out over
time.
>> But isn't isn't most of the um let's say
membership in maintaining services
oriented around the cost of the service
as opposed to the validity of the
service. Well, part of yeah,
>> I realize I realize I realize the
objective is that you want to actually
have eyes into uh the validation of the
services, but in fact, if you're just
supporting the the running of the
service, then
>> anybody any system admin inside the
service can do things.
>> Yeah. Well, certainly you have controls
and stuff that have to be in place that
that if you want to go there, you have
to go there. But
>> well, let's let's look the you know the
outsourcing ISO 9,000 all the things
that say if you're outsourcing to work
to people how do you know that they're
not that they're not you know using your
data.
>> So let me ask you this and here's where
the the technical world collides with
the business world often. One of the I
watched an interesting discussion with
someone says you can't do it until you
have this. It's like I'm moving billions
of dollars of business today with paper.
>> So don't tell me I can't do it.
>> It may be more efficient. It may be more
cost-effective. It might be more more
secure,
>> right,
>> than the clunky paper personal
relationship way I'm doing it.
>> That's your point. I may have a personal
relation with someone and I trust them
and their organization implicitly,
>> but they've got a bad actor inside the
house and they're just, you know, I
didn't I didn't know that until I knew
that and now I'm in trouble. Those are
separate problems and when we I think
when we conflate them, we create so many
problems overlapping
>> that there's no answer.
>> Yeah. Yes.
>> Well, the the um the benefits of being
able to establish trusted peer-to-peer
connections with people you do trust is
certainly an advantage of of a
decentralized identifier. However,
>> it does not solve the other issue of
um trust of an organization per se or uh
I mean it's just a it's we're not this
is this is not this is human nature and
the way people do things in order to uh
make money or and avoid you know laws. I
mean, human nature is going to find ways
of doing things that are always going to
deceive others. And so the there is no
100% insurance on this by any means.
>> Y totally agreed and that's where the
way I look at is this is again I I don't
look at like people point out you know a
registry of registries a network of
registries is by nature decentralized
but many of the players are highly
centralized and that's okay.
>> The recording industry exists because it
helps the recording industry. multiple
groups have tried to compete with it and
they should be able to and this actually
likely would open up more for
competition because it's easy to
recognize seven of them versus only the
one.
>> Um,
>> yeah. Well, I got a different take on
that because I have a small indie label
and I'm not making any money in music
because, you know, the the big this is
the big tech consolidation problem of
the fact that there are
>> only so many companies that really are
controlling information.
>> Yep. and they're largely a team of
lawyers.
>> Yeah. Um interesting you mentioned
Japan. Japan of course has has a very
rigorous system of keeping track of
people's names and addresses as part of
their identity.
I mean you when you're born you register
yourself with a post office and saying I
live at this address and this is my and
this is my house and that's part of your
estate. I mean it's it goes it's this is
it's old school you know uh
type you know type of things that
>> um
so different countries have different
completely different
>> and so it's really it's very interesting
and so I'm
>> I mean I'm I'm a big supporter of of of
the whole
digital uh efficiency aspect of doing
things but at the same time you look at
you look at the types of protocol that's
under the hood of of things like the VI
which doesn't require a blockchain and
you need you know you need to have you
need to have a hood on top of that
engine because you can't open the hood
and look at it you know things
>> yeah I mean there's lots of identifiers
that don't require blockchain it's a
>> is blockchain's a good feature great
>> yeah anyway I just um
>> I'm I'm sort of a you know I'm I'm a
gadfly in this particular uh I I drop in
occasionally when I have the time to do
it and if the meetings still exist on my
calendar and it's still there. But I I
think this is really interesting
>> a very fundamental topic in terms of if
you're going to use this type of these
types of identifiers, what are they and
how do you trust them and how and the
registries are
so I'm I I I think I applaud the work
you guys are doing in this and I'm I'
I'd like to follow it. Uh I'm not very
informed on it except for the fact that
I know what's going on.
>> Yeah, I think as Dan captured it really
really well. I think what's happened now
is that now that credentials are being
used in the wild,
people are recognizing you have to ask
the question who issued that
>> who says they're authoritative
>> and what's nice in business, we do have
authorities.
>> We have many of them. That's an
unfortunate aspect like you said,
>> you know, Elliot Gly, member of IRA by
the way. Um,
>> yeah,
>> they have a mandate. Open corporates,
business focused B I think I think
they're a BC Corp, but they're not an
official sanctioned group. You have done
and Bradreets always been around, right?
D&B numbers if you're operating I
haven't seen that as much lately.
They're all adding value in different
ways. How do we support them? How do we
use them? That's really the protocol
is indifferent to many of the aspects.
Mhm.
>> But the Trojan horse that I would say
that we've got in there is the is the um
it's it's it's codified in there is is
is level of assurance.
>> That's in in the in the IR it's not in
the authorization and
it's part of an optional context object.
level of assurance to me is the Trojan
horse that gets the trust building
because if I can prove a level of
assurance,
>> it's level ofsurance,
>> say I'm at this level.
>> Yeah. Does is level of assurance um a a
measure of how you have accurately
identified some entity or person or is
it simply is it does
>> Yeah. See, yeah. The IRA approach for
level assurance is we make room for it.
Your governance tells us what it means
in your world.
Interesting. So,
>> so GLife is very very clear on what
level their what their approach is and
they would be you know very high level
of assurance in a broad business
registry
>> meaning meaning that the reference data
that was used to assign the identifier
is correct. Is that the level of
assurance you're talking about or
>> well the operational processes behind
it.
>> Yeah. Yeah.
>> But but the key met the key objective
being accurate identification based upon
information.
>> Yeah. Here's the thing. Here's the
here's the theory. The hypothesis is
this.
>> Higher assurance data is more valuable.
If that proves to be wrong, levels of
assurance are not helpful.
>> Well, you know, one of the early debates
in Glyfe was whether or not they should
issue LEIS for criminal organizations
is, well, we don't want to do that
because they're criminal. Well, the
other person said, well, then we can
track them.
So I mean, you know, identifying
identifying
>> identifying an organization is not the
same thing as um
>> passing judgment on them or, you know,
suing them or whatever it might be. And
so I just think the the accuracy of
identifier is it really boils down to
are you actually correctly identifying
what you think you're identifying? be
that a company that might emerged or is
no longer a business or has changed its
name or it headquarters or it's a person
that has different aliases. I think it
the identification problem is how
accurate is the identifier itself to the
current state of what's being identified
to me. That just seems that seems to be
a fundamental
u requirement of anything that says I am
an identifier.
I resolved
>> and that's that's yeah and that's where
trust registries look to use identifiers
but not have an opinion on just how good
that identifier is because we can't
solve all problems right now.
>> That's part of the hard part.
>> So if I have an identifier in a trust
registry, I still need to resolve that
identifier to what it what it resolves
to and that's a separate process and
what's in the trust registry.
>> Yeah. Well,
>> exactly. And if I don't know how to do
that, then the trust is probably not
overly useful for me.
>> Yeah. Okay. So at least there's that
level of orthogonal independence and it
doesn't put that onus on the registry
itself. It puts the onus on the issue or
the identifier.
>> Yeah.
>> Yes. Additionally and we have for
example not codified this but we have
discussed as an IRA as a community when
we get to the point where there are
multiple levels of assurance we may say
there are different identifiers you
cannot use at a high level of assurance.
>> Yeah. So did web for example, no way.
Just you can't. It's it's just not
controllable. Um and there would be a
short list of at the high assurance
level of the DID methods you'd be
allowed to use.
>> So what a what a registry um I I presume
a trust registry would have in its list
of identifiers, a variety of different
types of identifiers. It's not
constrained to just one type or or you
could say this registry only will all
this this registry is only for this type
of identifier. So it's a is that just
basically whatever the registry wants.
>> It's a choice. It's a choice of the
registry. What in the IRA world what we
say is what's the list of DIDID methods
you support? We have an opinion for the
register for the identifier. You must be
a DID and you need to list the DID
methods that you support.
>> Yeah. Okay. That's our that's the IRA
opinion which extends by by by by by by
refinement by whatever by snipping off
the that we don't take did we don't take
an HTTPS URL as a URI that we'll accept
it's a did and it and here are the DID
methods we will use.
Okay. Well, this has been interesting.
I'm glad I joined for to get this
update. Um
uh I do have another call coming up but
I but I
>> Yeah. Yeah. Me too. Me too.
[clears throat]
>> I like I do like following this. I mean
the whole thing you know the trust
banning protocol all the things that are
going on when you know trust IP folded
into LFDT and but I'll be at the U IW
again in November whatever.
>> Cool. Cool.
Yeah, D, I had a question. When you
first displayed that um that that chart
with the um uh with the COG example in
the lower right um and uh I'm thinking
of the content authenticity, you know,
would that fit in that category? Like
where you know, where do you see the U
content authenticity initiative and
those guys fitting in?
>> Yeah. So this is where one of the things
that Scott pointed out is is we need to
work on traction. Where is ATRQP being
adopted? How are we helping it get
adopted? How are we sharing information
about where it's adopted? So
specifically the COG work. This is what
Scott indicated. You know, we need a
proof of concept with COG and someone
needs to write a paper. Now the idea was
COG is real and doing this. But I'll
tell you this. So COG is working right
now on their
uh I guess it's their governance
framework and they are specifying thou
shalt use TRQP
and each what what what they're trying
to do and it's it's not working because
it's not a thing. It's not a real
approach. They're like well we need to
come up with the master list of what are
the actions and resources when we look
at our authorizations action resource
pair that we all need to use. is like,
"No, no, that's not how it works."
Because when you have recording industry
talking about one thing, you have um
journalists and photojournalists over
here and then writers over here. You
have a fundamentally different world.
The difference is how do you talk to the
recording industry association and say,
"What are you authoritative for?" And
let's go set your action resource pairs
that you should use. Talk to the IPCC,
which does its international press and
telecommunication. I don't know what the
C is. I don't know why it says
telecommunication but they do press
credentiing um photojournalist that type
of thing as well as publishing agencies
like uh BBC AP writers. So we're working
with them and helping them just in
broader discussion on how they can use
TRQP
as part of their you're probably
familiar with the C2BA credentiing
format. So as part of the identity
assertion so if I go and publish an
article with a photo in it I can have
any number of of assertions you know I
took this picture I wrote this article
and I took this picture and I'm
submitting it under the go opices that
I'm a member of IPTC
and I to I'm doing the article because
I'm a member of the BBC which is also a
member of IPTC.
So it's how do I walk that back and it
all comes down to trust registries. So
it's actively actively discussing um
they're a very what's really nice about
dealing with them is they're very
business operations and governance
focused as a group. They're not techies.
So they don't they look at a protocol
and it's kind of confusing for them. was
like no let's go give you the list of
things you are authoritative for and
let's just start with can I sign a thing
that's of photojournal photo photo
journalist you know photography
photograph journalist or whatever the
hell that the the name spacing is that
they use so we're helping them with that
but that's on a pro bono working with
them um to help basis does that help Dan
Ron, I guess that's why it's in that
corner of operational guidance then
based based on what you just said. Yeah.
>> Yes. Yep. And and the goal is how do we
go through three or four or five of
those then have sign of a kind of a
guide book for those who want to look at
the trust over IP trust resurre task
force. Um and again Scott was pushing
for this because and he's right we do
need traction. Um, it's a hard thing to
tell a bunch of volunteers to do that
though, right? To go create a guide book
and stuff. But what I've committed on
the IRA basis is that we are doing this.
We are doing this actively and we will
share the results. And if it turns into
a trust over IP product and we hand it
over, great, fine. If not, because I
don't not sure this is part of me that
I'm one of the founders, one of the
original forer behind the trust over IP
idea. Just
who's here? Oh jeez. I need to get
going. I need to get going to drop uh to
take my my stepfather to a uh to a car.
But um
yeah, it is part of the work we need to
get this get this more broadly adopted.
>> Yeah. Well, thanks Darl. And speaking of
music, Tahoe Records, little indie
label.
>> Awesome. [laughter] Awesome. Thanks,
guys. I gota You can find me. All right.
See you guys. Cheers. Bye. Bye. Thanks a
lot.