Skip to content

Public Review - verifiable closure over material trust dependencies (Manu Fontaine)

From Manu Fontaine 2026-08-16 15:29 AEST - Original received via email to the project groups.io account: https://groups.io/g/UNCEFACTGlobalTrustRegistry/topic/gtr_public_review_feedback/120772788

The email message format has been replicated below to match the original, including the highlighting of text using bold.


Dear GRID Public Review Team,

Thank you for the opportunity to comment on the GRID Public Review.

I strongly support GRID's stated objective of establishing globally interoperable digital trust infrastructure. My concern is that the proposed reliance on Verifiable Credentials as a foundational mechanism is architecturally incompatible with that objective.

I have attached a longer technical note developing the argument and recommendations in detail.

Page/Section being reviewed:

Primary: Annex A, Technical Reference for GRID & DIA, Digital Identity Anchor, particularly "Why a credential model" and "Standards and formats," including the statement:

"The key requirement is: issuer authenticity + tamper evidence + machine checkability + revocation."

Related: Implementation Guidelines, Section 1.6, Technological Neutrality Principle; and UNTP Transparency Graphs, particularly "Verifying the Graph" and "Trust chains."

Issue:

The stated requirement defines credential verification, not global trust.

Verifiable Credentials cryptographically establish a narrow proposition: that a particular key signed a particular assertion and that the assertion has not subsequently been altered. The material dependencies required for a relying party to determine whether that assertion should actually be trusted remain outside the VC verification boundary.

Those dependencies include, among others, the issuer's identity and authority, scope of authority, key custody and control, issuance processes, source-information provenance and completeness, software integrity, execution integrity, verification procedures, identifier resolution, status infrastructure, governance, policy, delegation, and temporal state.

Each of those dependencies may itself depend on further people, organizations, information, software, infrastructure, keys, processes, or assertions.

This creates a fundamental architectural problem.

Every additional VC can close one narrow cryptographic question while introducing another set of material trust dependencies that cannot be verified through the same mechanism. Chaining VCs therefore does not produce closure over trust. It expands a graph of cryptographically attributable assertions while simultaneously expanding the unresolved assurance graph beneath those assertions.

The more extensively VCs are composed, the more external trust dependencies can accumulate.

A graph of cryptographically valid VCs is therefore not a graph of cryptographically verified trust.

This is particularly problematic because VCs look like a solution to the trust problem. Their signatures, standardized formats, issuer identifiers, revocation mechanisms, and machine-verifiable proofs create the appearance of an end-to-end assurance architecture. In fact, the material dependencies that determine whether the assertions should be trusted remain outside that architecture.

Selecting VCs as the foundational trust mechanism therefore risks foreclosing the more fundamental architectural question that GRID should be solving.

Proposed Solution:

UNECE should remove Verifiable Credentials as the foundational recommendation for achieving global digital trust and instead define the required assurance property first.

That property should be verifiable closure over material trust dependencies.

For any assertion used in a relying-party decision, every material dependency required to establish its provenance, authority, integrity, context, scope, temporal validity, relevant completeness, and production or verification process should either:

(a) be recursively represented and verifiable through the assurance architecture; or

(b) remain explicitly visible as an unresolved assumption or trust anchor intentionally selected by the relying party.

The architecture should preserve the ability to follow the question "why should I trust this?" recursively across the dependencies of the assertion rather than terminating that inquiry at the validity of a signed credential.

This does not require UNECE to prescribe a single national technology stack. It requires UNECE to define the functional assurance property that any implementation must be capable of satisfying if it is to participate in a genuine global trust infrastructure.

Participating jurisdictions can remain free to choose their technologies, architectures, governance mechanisms, and maturity paths. What should not vary is whether material trust dependencies are visible and verifiable enough for relying parties to make their own trust decisions.

Rationale:

GRID's stated ambition is much larger than credential interoperability.

It seeks to support global digital trust infrastructure, cross-border verification, legal identity, transparent governance, resilient institutions, supply-chain transparency, and the objectives of the UN Global Digital Compact and 2030 Agenda.

Those objectives require the infrastructure to support an optimal trust decision by the relying party, not merely successful verification of signatures on portable assertions.

If a relying party can verify that a credential was signed by a key associated with a recognized issuer, but must still separately determine whether the issuer acted within scope, whether the source information was correct and sufficiently complete, whether the key was properly controlled, whether the software and execution environment were trustworthy, whether the verification procedure actually occurred, and whether those facts held at the relevant time, then the underlying trust problem remains unresolved.

The credential has become portable. The trust decision has not.

This also directly affects the economic case for GRID. The major economic opportunity is not simply cheaper credential checking. It is the ability to perform assurance work once and reuse it across many downstream trust decisions because the provenance and material dependencies of that assurance remain independently verifiable.

Without that property, relying parties must continue performing additional diligence outside the credential graph. The infrastructure may reduce the cost of document authentication while leaving much of the actual cost and friction of trust intact.

National sovereignty does not alter this architectural requirement.

There is an important distinction between prescribing how a country implements its domestic infrastructure and defining what properties the global infrastructure must have in order to achieve its stated purpose.

GRID's own Technological Neutrality Principle recognizes this distinction by allowing common requirements where necessary to support interoperability, integrity, authenticity, or trust.

Verifiable closure over material trust dependencies is such a requirement.

UNECE therefore does not need to mandate one implementation across participating countries. It does, however, need to decide what architecture is capable of achieving the global objective it has set.

If the recommendation is constrained to mechanisms that participating countries already use or are presently comfortable adopting, the result risks becoming a least-common-denominator interoperability framework rather than a genuine global trust infrastructure.

The decision to recommend VCs is especially consequential because it can make the architecture appear further along than it is. VCs provide visible cryptographic proofs, interoperable formats, and readily demonstrable verification flows. But the unresolved trust dependencies remain outside those proofs.

The result is a system that can become increasingly effective at proving who signed assertions while never acquiring the architectural property required to determine why those assertions should be trusted.

For GRID's stated objectives, that distinction is foundational.

I therefore recommend that UNECE reconsider the VC-centric architectural starting point and first establish verifiable closure over material trust dependencies as the governing requirement against which candidate technologies and national implementations are evaluated.

The attached technical comment develops this argument in detail.GRID_Public_Review_Verifiable_Closure.pdf