US / Microsoft / Technical Specifications
Technical Specifications
Comment and rationale:
The specification assumes the use of digital signatures for credential authenticity, but it would be helpful to distinguish signature-based authenticity (verifying who issued a credential) from verifiable auditability (proving that all issued credentials are visible and have not been omitted). Some implementations may register issued credentials in a transparency mechanism that produces verifiable inclusion proofs. This would allow relying parties to validate not only the signature, but also the completeness and history of published data, thereby strengthening trust in credential ecosystems.
Proposed changes:
Clarify the distinction between signature-based authenticity and verifiable auditability and optionally describe transparency mechanisms or inclusion proofs as an implementation pattern. Suggested text for addition: "Digital signatures provide assurance of credential integrity and issuer authenticity. Some implementations may additionally use transparency mechanisms that provide verifiable inclusion proofs or append-only audit logs. These mechanisms enable relying parties to validate not only credential authenticity but also the completeness and history of published data. Such mechanisms are implementation-specific and are not required for UNTP conformance."
Page URL: https://untp.unece.org/docs/specification/
Name: Anish Karmarkar
Organisation: Microsoft
Country: United States