TamgaNetwork

Reference

Glossary

The core terms used across the Tamga Network ecosystem. When you get stuck on a concept, you can quickly look here. For the EU roles and their Tamga counterparts, see Roles and terms.

Core concepts

Tamga Network
A Digital Trust Infrastructure that unites digital identity, verifiable credentials, authorization and immutable records under a single architecture. It is not a blockchain network: today trust is anchored in signed trust lists; a permissioned ledger may be added later.
Digital Trust Infrastructure
The layer that provides trust in the digital world as a shared infrastructure service. Instead of each application solving the trust problem separately, it provides a common trust layer.
Tamga Wallet
Tamga’s wallet app and the infrastructure’s first end-user product. It keeps a person’s credentials on their phone and shares only the fields they approve. Tamga Wallet is not Tamga Network itself.
Trust Mesh
Not a central authority, but a mesh of interoperable, independent trust networks. Each country keeps its own network while connecting through shared standards.

Tamga today

Trust list
A signed, versioned, hash-chained public register of institutions, their certificates, what they may issue and their status. The EU model (ETSI TS 119 612).
Anchor log
A public, append-only log where every revocation-list publication and schema change is written as a signed line, at least hourly.
SD-JWT VC
The IETF credential format Tamga uses by default: each field hidden behind a salted hash, revealed only with the holder’s approval.
mdoc (ISO 18013-5)
The mobile-document format of the mobile driving licence. Tamga issues the identity credential also as an mdoc, e.g. for age checks.
OpenID4VCI / OpenID4VP
The OpenID standards for issuing credentials into a wallet and presenting them to a verifier — the EUDI profiles.
Wallet Unit Attestation (WUA)
A short-lived statement from the wallet provider that the app is a genuine wallet; issuers require it.
Per-verifier copy
The wallet holds several copies of each credential, each bound to a different device key, and gives each verifier a different one — so verifiers cannot link the holder.
ACCEPTED / REJECTED / INDETERMINATE
The three verification outcomes. INDETERMINATE means “could not be checked right now” and is never shown as a rejection.
Passkey
A WebAuthn key on your device for one website. After signing up with the wallet, daily sign-in uses a passkey and shares no fields.

Identity and trust

Digital Identity
The verifiable representation of an entity on the network (individual, institution, object). The starting point of the ecosystem.
VC — Verifiable Credential
A verifiable document. A digital document with an embedded digital signature that can be verified without going to the source (diploma, licence, etc.).
SSI
Self-Sovereign Identity. The approach where control of identity belongs not to a central institution but to the user themselves.
Issuer – Holder – Verifier
The trust triangle. The Issuer issues and signs the credential; the Holder carries and presents it in their wallet; the Verifier checks the signature without going to the source.

Cryptography and records

Hash
A fixed-length, one-way digital fingerprint produced from data. Used to prove that the data has not changed.
Digital signature
Sealing the hash of data with a private key. Verified with the public key; proves the source and integrity of a document.
PKI
Public Key Infrastructure. A chain of trust that records which key belongs to which institution and what it is authorized to do.
SD-JWT
Selective Disclosure JWT. A format that lets only the necessary fields be revealed without breaking a document’s integrity.
ZKP
Zero-Knowledge Proof. A technique for proving something without revealing its value at all.
On-chain / Off-chain
On-chain: non-personal trust data kept on the blockchain. Off-chain: operational data and documents kept in the wallet/institution. Today Tamga has no chain; public trust data lives in signed trust lists.

Network and standards

Permissioned network
A blockchain network where the validators are specific and trusted. The ledger Tamga plans is one.
Consensus
The mechanism by which the network’s nodes agree on the content of the next block. Tamga uses QBFT (the Byzantine Fault Tolerance family).
Hyperledger Besu
The open-source, EVM-compatible client Tamga chose for its future ledger (once at least two independent operators join).
eIDAS 2.0
The EU’s electronic identity and trust services framework; it makes a digital identity wallet mandatory for every member state.
EUDI Wallet
European Digital Identity Wallet — the EU citizen’s digital identity wallet (the application layer).

Advanced architecture

Root Identity
The unique identity record issued by the state that holds the link to the real person. Only the issuer + a guardian threshold can access it.
Pseudonym
A separate, mutually unlinkable identity derived from the root identity for each application. Prevents cross-application profiling.
Unlinkability
The property that the same person’s identities in different applications cannot be mathematically correlated.
HD derivation (BIP32/SLIP-0010)
Hierarchical deterministic key derivation. A method of producing unlimited, unlinkable child keys from a single seed along fixed paths.
BIP39 mnemonic
A 24-word recovery phrase; converted to a seed (PBKDF2-HMAC-SHA512). The source of all the user’s keys.
Escrow
A record holding the link between pseudonyms and the root identity, protected by threshold encryption. Opened only with authority.
Threshold encryption
A model where the decryption authority is split into shares and can only be used when enough (K-of-N) shares come together.
Distributed Key Generation (DKG)
A protocol where guardians jointly generate a shared key so that no single party ever holds it; the key is never reconstructed — only a specific ciphertext is opened by a quorum (threshold ElGamal).
Guardian
One of an institutional set of five per state (judiciary, data-protection authority, civil-registry authority, ombudsman, a parliament-appointed member), each holding one threshold share. A 3-of-5 quorum with at least one non-executive approval is required to open.
Envelope encryption
Encrypting data with a DEK and wrapping the DEK with a KEK; since the server never sees the KEK, it cannot read the content.
DEK / KEK
Data Encryption Key / Key Encryption Key. The two-layer keys in envelope encryption that encrypt the data and wrap that key.
Token Status List
The IETF revocation list Tamga uses: two bits per credential copy (valid, revoked, suspended) at a random position, signed and published at a fixed interval.
Challenge-response (FIDO2/WebAuthn)
Authentication where, without sending a password, a random value from the server is signed with the private key and verified with the public key.
Secure Enclave / StrongBox
The secure area on iOS and Android where keys/PINs are stored in hardware isolation.
ICAO 9303
The e-passport/e-ID NFC chip verification standard. Used together with face matching in second-tier recovery.