X.509, not DID: how we identify institutions
Institutions are identified with X.509 certificates anchored to national root authorities — regulator-readable by design. Citizens get no global identifier at all.
Early on we identified institutions with a custom decentralized identifier. We changed course. Today, institutions — universities, ministries, hospitals, banks — are identified with X.509 certificates, the very standard the regulated world already uses (eIDAS qualified certificates, QWAC/QSeal).
Why X.509 for institutions
The counterparty in most institutional flows is already certified. “Verified by a qualified certificate” is a sentence that has a legal meaning; “verified by a DID” is not. When money and audits are involved, this regulator-readability is decisive. Each member state runs its own national Root CA, and Tamga anchors the root’s fingerprint on-chain.
National Root CA (fingerprint anchored on-chain, stateCode = "TR")
+-- (optional Intermediate CA)
+-- Institution certificate (leaf, e.g. a university)
issuerId = keccak256( stateCode || SHA-256(DER(cert)) )
on-chain : Root CA anchors + issuer registry (public key, category, status)
off-chain : the credential itself — never on the chainCitizens: no global identifier
A citizen gets no such certificate and no global identifier at all. Personal relationships use pairwise pseudonyms — a different, unlinkable pseudonym per relationship. A person’s education, health, logistics and payment traces cannot be strung onto a single thread. Chain accounts, meanwhile, are ordinary EVM addresses, kept separate from identity. The set of anchored roots and registered issuers is our Trusted List — the analogue of the EU’s List of Trusted Lists. More in Identifiers and credentials.