Tamga Network

Chapter 3 · 4/5

Unlinkability

Single-use copies and a pseudonym per site: traces in different places cannot be joined up.

5 min

A pseudonym per siteOne person, three sites, three different identifiers; the sites cannot link them.Youticket sitek7f2…9alibraryp91a…3cexam portalz3c8…e1sites cannot match each other

Say that thanks to selective disclosure and zero-knowledge proofs you show only what is needed everywhere. A risk remains: can the traces you leave in different places be joined up? Could a website, a hotel and a health app compare their records and say "these three belong to the same person"?

Preventing that is called unlinkabilityThe property that a person's presentations in different places cannot be linked to each other.. Tamga achieves it with two tools: single-use credential copies and a pseudonym per site.

The problem: same signature, same trace

A signed credential carries the same signature and hashes wherever it is shown. That signature behaves like a fingerprint. Even if you show only "over 18", two verifiers who see the same signature can tell they saw the same credential, and so the same person.

Solution 1: several copies

The issuer issues several copies of the same credential, each signed separately with different hashes. The wallet uses them carefully:

  • A given verifier always gets the same copy. If it already knows you it learns nothing new, and copies are not used up for nothing.
  • Different verifiers get different copies. Even if two of them compare signatures, they find no match.
  • When copies run low, the wallet requests new ones from the issuer automatically, after a random delay so the request cannot be matched to the moment a copy was used.

Solution 2: a pseudonym per site

When you register on a site with Sign in with Tamga, the site knows you by an account identifier. If that identifier were the same everywhere, two sites could easily match you. Instead the wallet creates a separate but stable pseudonymAn identifier that only one site knows you by; it cannot be linked to your identifier on other sites. for each site:

  • Every time you return to the same site, the same pseudonym is sent; the site recognises you and your account is safe.
  • Another site gets a completely different pseudonym; the two cannot connect you.
  • Pseudonyms are derived from your identity. If you change phones and verify your identity again, the same pseudonyms come back: you don't lose your accounts, and you can't end up with two accounts on one site.

What is protected, and what is not

Unlinkability stops the credential itself from leaving a trace. But if you type your name into a site yourself, the site knows your name; no technical tool can stop that. So the last link in privacy is the person: seeing what they share, and agreeing or refusing. The final page of this chapter covers that.

Summary

  • If the same copy is shown in two places, both carry the same signature and can be linked.
  • The wallet holds several copies of a credential; each verifier always gets the same one, others get different ones.
  • With Sign in with Tamga every site knows the person by its own pseudonym; two sites cannot match them.

Go deeper

Technical details and binding rules: