TamgaNetwork
All posts
Technical·6 min

X.509, not DID: how we identify institutions

Institutions are identified with X.509 certificates anchored to national root authorities — regulator-readable by design. Citizens get no global identifier at all.

Early on we identified institutions with a custom decentralized identifier. We changed course. Today, institutions — universities, ministries, hospitals, banks — are identified with X.509 certificates, the very standard the regulated world already uses (eIDAS qualified certificates, QWAC/QSeal).

Why X.509 for institutions

The counterparty in most institutional flows is already certified. “Verified by a qualified certificate” is a sentence that has a legal meaning; “verified by a DID” is not. When money and audits are involved, this regulator-readability is decisive. Each member state runs its own national Root CA, and Tamga anchors the root’s fingerprint on-chain.

trust chain
National Root CA   (fingerprint anchored on-chain, stateCode = "TR")
   +-- (optional Intermediate CA)
         +-- Institution certificate  (leaf, e.g. a university)

issuerId  = keccak256( stateCode || SHA-256(DER(cert)) )
on-chain  : Root CA anchors + issuer registry (public key, category, status)
off-chain : the credential itself — never on the chain

Citizens: no global identifier

A citizen gets no such certificate and no global identifier at all. Personal relationships use pairwise pseudonyms — a different, unlinkable pseudonym per relationship. A person’s education, health, logistics and payment traces cannot be strung onto a single thread. Chain accounts, meanwhile, are ordinary EVM addresses, kept separate from identity. The set of anchored roots and registered issuers is our Trusted List — the analogue of the EU’s List of Trusted Lists. More in Identifiers and credentials.