How Tamga works

Tamga and the EUDI architecture

Tamga keeps the EU’s technical layer as it is and writes its own governance layer for the Turkic world. This page shows, row by row, where Tamga is the same, where it builds a bridge, what is planned — and what it does differently on purpose.

The same layers

The EU framework has five layers. Tamga mirrors each one with its own document set.

LayerEUTamga
Law and governanceeIDAS 2.0 + implementing actsTamga Trust Framework
Architecture and rolesARFTamga ARF
Participant rulesARF high-level requirementsTamga Rulebook
Document-type rulesAttestation rulebooksEducation rulebook, more to follow
Technical standardsETSI · IETF · OpenID · ISOthe same, with Tamga profiles

Roles: who does what, today and later

Every role of the EU architecture exists in Tamga. Where a state has not joined yet, Tamga holds the role provisionally — on the record, on behalf of the state.

Role (ARF)TodayWhen the state joins
Trusted List OperatorTamga — provisional, on behalf of the national authoritythe national authority
RegistrarTamga (on behalf)the state registrar
National Root CA“TR National Root CA (provisional operator: Tamga)” — its identifier does not change on handoverthe state’s own root
PID Providerempty slot; an identity credential from Tamga’s identity service (document + liveness check) insteadthe state
Attestation Provideruniversities, ticket sellers+ public bodies
Wallet ProviderTamga (wallet attestation)+ certified third parties
Relying Partyemployers, websites, gates — registered with a scopethe same
Validator Operatornone — no ledger in this phase≥ 2 independent operators → ledger

Standards

The technical layer is the same. Where the first release still takes a shortcut, the row says so.

● same · ◐ bridge (same model, interim form) · ○ planned
ComponentEUTamgaFit
Trust listsETSI TS 119 612same model, signed JSON (JWS); ETSI XML projection plannedbridge
Institution identityX.509X.509, national rootsame
Credential formatSD-JWT VCSD-JWT VC (dc+sd-jwt), ES256same
Mobile documentISO/IEC 18013-5 mdocidentity credential also issued as mdocsame
IssuanceOpenID4VCI 1.0OpenID4VCI: pre-authorized code + PIN, or wallet-initiatedsame
PresentationOpenID4VP 1.0, DCQLOpenID4VP, DCQL, signed request, encrypted answersame
RevocationIETF Token Status Listsame, published at a fixed intervalsame
Identity proofingETSI TS 119 461document + liveness check, mapped to assurance levelssame
Wallet attestationWallet Unit AttestationWUA required by issuers; until Tamga Wallet is on the App Store and Google Play, the phone’s own claim of secure hardware is not accepted (every wallet counts as software-level); with the store release App Attest / Play Integrity become mandatorybridge
Key storagesecure element (WSCD)first release: software keys; pilot: the phone’s secure enclavebridge
Close rangeISO 18013-5 over NFC/BLEQR pass for gates today; NFC/BLE nextbridge
BrowserW3C Digital Credentials APIplannedplanned
Qualified e-signatureQES from the walletplannedplanned

Where Tamga differs on purpose

DifferenceWhat it means
by designSovereignty-first governanceEach state is the only writer of its own registry; network membership by a 2/3 vote; cross-border recognition decided by each state unilaterally.
by designProvisional operator, built for handoverNo structure assumes Tamga as the only operator. Every member state has a slot; handover changes only the operator field.
by designOptional ledgerThe EU relies on lists alone. Tamga adds a permissioned ledger only when at least two independent operators join; lists and ledger give the same answers.
by designPublic anchor logEvery revocation-list publication and schema change is a signed line in an append-only log, at least hourly — a rolled-back list is detectable.
by designThree outcomes, always“Could not check” (INDETERMINATE) is never reported as “rejected”.
by designNo national ID in shared documentsThe national ID number appears only in the identity credential; diplomas, tickets and cards never carry it.

Known limits, stated openly

These limits are also listed in the pilot’s limitations notice.

  • In this phase the trust anchor rests on one operator’s signature; the public log, transparency report and audits deter misuse but cannot make it impossible.
  • A revocation takes effect within about 90 minutes at most.
  • The same issuer could link a person across verifiers if they collude; closing this needs zero-knowledge credentials.
  • First release only: keys in software and the issuer key held by Tamga — both close before the pilot.

Details: trust lists · architecture · eIDAS, EUDI and EBSI.