← Back to list

Issuer Registries — Layering Trust for Verifiable Credential Ecosystems

When issued as Verifiable Credentials (VCs) and aligned standards like Open Badges 3.0 (OBv3), Learning and Employment Records (LERs) are…

Gillian Walsh in Digital Credentials Commons · 2024-08-19 13:41 · 51 claps · 3.0 min read
#digital-credentials #trust-registries #verifiable-credentials #open-badges #workforce-development
Open on Medium ↗
Wiki topics: EDU · Education & Learning

Issuer Registries — Layering Trust for Verifiable Credential Ecosystems

When issued as Verifiable Credentials (VCs) and aligned standards like Open Badges 3.0 (OBv3), Learning and Employment Records (LERs) are equipped with a critical layer of verifiability and privacy. Inherent to VCs is the premise that the credentials are verifiable without contacting the issuer. Verifiers can check that (1) the credentials were digitally signed by the issuer identity found in the credentials and (2) the data hasn’t changed since it was signed, ensuring that what the verifier receives is the data that was originally signed by the issuer. This means that the earners of the credentials can share with parties they trust without the issuer knowing who those parties are.

This is a departure from how we are accustomed to learners sharing their official academic credentials like degrees and transcripts. Typically a graduate, alum or former student contacts their institution or a data clearinghouse to request that the sealed documents be sent to another party. In this process, the learner is typically required to provide information about that party — and sometimes pay a fee for the release of their own data. Older versions of Open Badges are hosted on web servers which allow issuers to track clicks and the associated IP addresses. In both of these instances, the verifier of the credentials ascertains trust of the issuer identity through the sender of the credentials or the web host of the digital credentials.

When LERs are issued as VCs, the issuer identity can be proven true through its inclusion in an issuer registry, a secure digital list monitored by a governing body. Examples of use cases for issuer registries could include a consortium of accredited higher education institutions, state authorized agencies like DMVs, or licensure divisions for healthcare facilities. To be included on such a list, an issuing entity must meet the criteria laid out by the governing body. Therefore, the existence of an issuer on a registry provides an endorsement of its identity.

A verifier — which could include an employer confirming a job applicant’s training credential, a law enforcement officer checking a driver’s license, or a citizen looking for information about a healthcare facility — is able to look up the identity of the credential issuer on registries to ensure that a trusted party has confirmed the issuer’s identity at the time credential was issued. A degree, for example, issued as a VC by an university included on an issuer registry is digitally signed and tamper evident with an additional layer of trust provided by the confirmation of the university’s identity.

The advantages of issuer registries have been acknowledged by the Global Legal Identifier Foundation (GLEIF) and the Trust Over IP Foundation, who are currently using trust registries to promote confidentiality and interoperability across the web. However, the benefits for LERs have yet to be defined. To address this gap, the DCC and Credential Engine are engaged in a project to explore the function of issuer registries in the LER Ecosystem.

With the support of Walmart, the Issuer Registry Project will address a number of key questions:

  • What current standards for issuer registries exist and which are applicable for the LER Ecosystem?
  • What does the process of implementing an issuer registry look like and what are some approaches to governance?
  • What considerations should be made for ensuring long term sustainability of issuer registries?

Throughout this year-long project, the DCC and Credential Engine will leverage open standards in the development of an issuer registry prototype. The project team will solicit input from subject matter experts through the recently formed Issuer Registry Advisory Group, which will inform decision making and design implementations. Findings from the project will be shared through a research paper describing existing and emerging issuer registry standards and specifications and approaches to governance. Additionally, the team will work with select collaborators on piloting the issuer registry prototype to test functionality, security, impact and replicability.

We welcome you to join this effort! Some ways you can get involved are by

  • Joining the Issuer Registry Advisory Group: Participate in discussions, contribute to deliverables, and help to build shared understanding. You can learn more about this opportunity here.
  • Participating in the pilot: Participants will engage in testing a functional issuer registry and provide feedback and insights to refine the model for broader implementation. Invitations will be sent out later.
  • Staying informed: We will continue to provide updates on this project! Subscribe to Credential Engine’s newsletter and DCC’s newsletter to stay current.

메타데이터
post_id
1199a9bef7c9
slug
issuer-registries-layering-trust-for-verifiable-credential-ecosystems-1199a9bef7c9
url
https://blog.dccommons.org/issuer-registries-layering-trust-for-verifiable-credential-ecosystems-1199a9bef7c9
canonical_url
https://blog.dccommons.org/issuer-registries-layering-trust-for-verifiable-credential-ecosystems-1199a9bef7c9
author_url
https://medium.com/@gwalsh_26541
status
ok
fetched_at
2026-08-22 03:58:28