Tamga Network

Chapter 2 · 8/8

Revocation and freshness

Can a credential be withdrawn, and how does a verifier find out without asking the institution?

4 min

Credentials are not valid forever. A membership ends, a licence is suspended, a diploma issued by mistake is withdrawn. The verifier needs to know, but without asking the institution each time; otherwise the institution would learn about every check, that is, everywhere the person used the credential.

STATUS LIST · ONE POSITION PER CREDENTIAL0010000100000010Your credential's position: 71 = revoked, 0 = validVerifierdownloads the list; never asks who you are
The issuer sets a revoked credential's position to 1, then signs and publishes the list.

How does a status list work?

The institution keeps a large A signed list showing, with one position per credential, whether an issuer's credentials are valid or revoked (IETF Token Status List). for the credentials it issues. Each credential gets a position: 0 means valid, 1 means revoked. When the credential is issued, its position and the list's address are written into it. When the institution revokes a credential, it sets that position to 1, signs the list and republishes it.

The verifier downloads the list and looks at the position. Because the list carries thousands of positions together, the institution cannot tell which credential the verifier looked at. The list is compressed; even for thousands of credentials it is a small file and can be fetched in advance and cached.

Freshness: "I cannot tell right now" is an answer too

What if the list cannot be downloaded or is too old? Tamga's rule is clear: in that case the verifier does not say "valid"; it says "cannot be verified right now". The result has three values:

  • Valid: signature, registration and status are all fine.
  • Invalid: revoked, expired or the signature does not match.
  • Indeterminate: the lists are stale or unreachable; try again later.

Copies and refresh

The wallet carries several single-use copies of each credential. When they run low or approach expiry, the wallet fetches fresh copies from the institution on its own, without asking you to do anything. The institution does not issue fresh copies of a credential it has revoked.

Summary

  • The issuer sets a revoked credential's position to 1 in a signed, public status list.
  • The verifier downloads the list; the issuer never learns which credential was checked.
  • An unconfirmed case is 'indeterminate', never 'valid'; the wallet refreshes copies on its own.

Go deeper

Technical details and binding rules: