Concepts
Cryptography basics
The magic of verifiable credentials rests on three simple cryptographic ideas: hash, key pair and digital signature. Let’s explain them with no formulas.
1. Hash — a digital fingerprint
A hash function takes any data (a word, a file, a book) and produces a fixed-length “fingerprint” from it. The same data always gives the same fingerprint; but if you change even a single letter of the data, the fingerprint changes completely.
hash("Hello") → 185f8db32271fe25...
hash("hello") → 2cf24dba5fb0a30e... (one letter → totally different)A hash is also one-way: you cannot go back from the fingerprint to the original data. That’s why a hash is perfect for answering “has this document changed?”
2. Public and private key pair
In cryptography every identity has two keys that are mathematically bound to each other:
- Private key — stays only with you, shared with no one. Think of it as a seal stamp.
- Public key — is open to everyone. It serves to recognize the pattern the stamp leaves.
The magic: something “sealed” with the private key can be verified only with the corresponding public key. And finding the private key from the public key is practically impossible.
3. Digital signature
This is exactly where the tamga (seal) becomes digital. When an institution issues a document, it:
- Takes the hash of the document (fingerprint).
- Seals this fingerprint with its own private key → digital signature.
- Attaches the signature to the document.
The party verifying the document then:
- Recomputes the document’s hash.
- Checks the signature with the institution’s public key.
- If the two fingerprints match: the document really came from that institution and has not been altered at all.
The digital counterpart of the ancient seal
PKI — where does trust come from?
But how do you know a public key really belongs to “Example University”? The system that solves this is called PKI (Public Key Infrastructure). PKI is a chain of trust that records which key belongs to which institution and what that institution is authorized to do.
In Tamga the signed trust lists do exactly this job today (a permissioned ledger may take it over later): they keep institutions’ public keys and authorities as a public, tamper-evident trust registry. Not the document itself — only the information “is this institution trusted, is its key still valid.”