Chapter 1 · 4/4
The trust triangle
Issuer, person and verifier: who trusts whom, and why.
4 min
Every transaction in the wallet model happens between three parties. They form the trust triangle. All of Tamga Network's rules describe how these three can trust each other.
Three parties
- The institution that prepares, signs and issues the credential: a university, a professional chamber, a ticket seller, a public body.. The institution responsible for the truth of a piece of information. The university issues the diploma, the organiser the ticket, the chamber the licence.
- The person the credential is about, who carries it in their wallet.. The person who carries the credential in their wallet and decides when, and to whom, to show it.
- The party that requests a credential and checks its signature and validity: an employer, a site, a gate, a bank.. The party that needs the information: a hiring company, a concert gate, a bank, a website.
Who trusts whom?
Here is the interesting part: the verifier does not have to trust the holder. The holder shows a piece of information, the verifier looks at the signature and asks, "Does this signature really belong to the issuer?" So the real trust is between the verifier and the issuer. The holder, in turn, wants two assurances: that the credential goes only to whom they approved, and that the other side really is who it claims to be.
The fourth corner: the trust list
A verifier cannot know every university in the world. How would it know that a signature really belongs to Example University? The answer is a signed list anyone can read: a A signed, public list of which institutions in a country may issue credentials and which verifiers and wallets are registered. that says which institutions may issue credentials, which verifiers are registered and which wallets follow the rules. In Tamga Network each state publishes its own list; today Tamga operates the Türkiye list provisionally, on behalf of the state.
In this chapter we covered what identity is, today's problems, the models and the trust triangle. The next chapter opens up the technology inside the triangle: signatures, certificates and the credential itself.
Summary
- The trust triangle: issuer, holder and verifier.
- The real trust is between verifier and issuer; the signature carries it.
- The trust list is the fourth corner: everyone reads who may issue from the same list; no question goes to the issuer.
Go deeper
Technical details and binding rules: