23F/ Good Health Pass Ecosystem Trust Architecture: DIDs and X.509 Trust Registries with Ecosystem Governance Frameworks
Good Health Pass Ecosystem Trust Architecture: DIDs and X.509 Trust Registries with Ecosystem Governance Frameworks
Thursday 23F
Convener: Drummond Reed, Darrell O-Donnell and Scott Perry
Notes-taker(s): Scott Perry
Tags for the session - technology discussed/ideas considered:
Governance, Trust Registry, Ecosystem, Transitive Trust, Architecture
Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:
Presentation Deck: GHP Ecosystem Trust Architecture PDF
Proposed Trust Interoperability (Global) for the Good Health Pass (GHP) Ecosystem
Kaliya Young & Rebecca Distler - Working Group Co-Leads
Trust in the system - focus for today’s discussion.
Principles - https://www.goodhealthpass.org/wp-content/uploads/2021/02/Good-Health-Pass-Collaborative-Principles-Paper.pdf
Blueprint Outline - https://www.goodhealthpass.org/wp-content/uploads/2021/03/GHPC-Interoperability-Blueprint-Outline-v2.pdf
Global Problems inhibiting world travel. Many emerging instances of GHP related ecosystems. GHP establishing an umbrella for all GHP-compliant ecosystems.
Relying on the ToIP Trust stack as an architectural blueprint
Ecosystem Governance Framework is at the top of a governance and technical stack.
Some specific Ecosystems need to accommodate x.509 certificate and VC constructs.
ToIP Stack diagram is undergoing new changes - some new terminology being discussed at IIW.
Governance and Trust Framework terms are being used as synonyms but we conveyed that Governance Frameworks are over arching of subject Trust Frameworks.
GHP wll be a General Ecosystem Governance Framework. Overseeing Specific EGFs..
[[File:./media/image1.png|377x194px]]
It is likely to have a GHP compliance but only on the lightweight tenets of interoperability.
We are introducing a trust registry infrastructure that works with all GHP-compliant ecosystems.
Issuers within an ecosystem will be included in a trust registry.
Each Ecosystem must publish its governance framework and make its trust registry available
All issuers need to be recognized by a governance framework and included in a trust registry
The second principle is that each specific EGF will identify its trust registry with a DID and specify its trust registry service endpoint(s) in its associated DID document
The third principle is that each VC issued under a specific EGF will identify its issuer with either:
a DID
a URI (for X.509 certificates)
The final principle is that each VC issued under a specific EGF will identify its type with a type URI. That field will be using common semantics.
With this architecture, all we need is a simple trust registry protocol to answer the question:
Is this issuer
authorized to issue this VC type
under this specific EGF?
GOOD - is a pass
BETTER - may be purpose-limited (“trivial” example -
Chat Notes:
• Bart Suichies to Everyone : It's slightly different, no? It's modeling governance frameworks rather than adding hierarchy? specific EGF (typeOf) general EGF
• Darrell O'Donnell to Everyone : @Bart - correct. Not hierarchical - additive.
• Dan Bachenheimer to Everyone : I think the GHPC EGF is a template - Guidance only
• Darrell O'Donnell to Everyone : @Dan - but can a Specific EGF be a “Good Health Pass” if it violates fundamental tenets of the GHPC EGF?
• Darrell O'Donnell to Everyone : it’s inheritance
• Bart Suichies to Everyone : maybe add a little text to the lines
• Tom Jones to Everyone : Taxonomies are hierarchical - can we talk about something else?
• Jacob Dilles to Everyone : It took ICAO 10 years to get 2/3 of countries to talk to each other. Most are still not strongly verifying signatures.
• Kaliya Identity Woman to Everyone : what the hell is a “trust level”?
• Bart Suichies to Everyone : Sovereigns are funny beasts ;)
• Bart Suichies to Everyone : I think US is one of the countries still not strongly verifying?
• Dan Bachenheimer to Everyone : @Darrel - interesting question; GHPC is offering guidance (e.g., what does good look like) - I don't think there will be any certifications (e.g., pass / fail, compliant / non-compliant)
• Jacob Dilles to Everyone : @Bart (correct)
• Bart Suichies to Everyone : What would even be certified? the country implementing a hp? the provider of such a hp?
• Bart Suichies to Everyone : +1 to show what good looks like
• Bart Suichies to Everyone : I think certification would be overreach given the time and market-dynamics
• Todd Gehrke1 to Everyone : @Bart that is exactly the discussion that is being had
• Darrell O'Donnell to Everyone : @bart - 100% in the short/medium term, but may be required longer-term
• Bart Suichies to Everyone : true - but by then most governments will be locked in
• Darrell O'Donnell to Everyone : they can license the “(not so)Good Health Pass” mark then! (totally kidding)
• Bart Suichies to Everyone : We have to be honest as well - GHP is also one of more initiatives trying to do this
• Darrell O'Donnell to Everyone : agreed Bart
• Drummond Reed to Everyone : This is true - and we know that GHP needs to interop with WHO, EU Green Certificate, and VCI
• From Bart Suichies to Everyone : do verifiers need to be in a trust-registry as well?
• Darrell O'Donnell to Everyone : @Bart - depends on the governance framework - in some places I suppose so
• Bart Suichies to Everyone : @darrel - is that explicitly optional in the trust framework? I think it would be good practice to limit verification of medical data
• Bart Suichies to Everyone : countries allowing it for anyone should be the exception rather than the best practice
• Bart Suichies to Everyone : @drummond - so this would be the PKI from WHO for instance?
• Darrell O'Donnell to Everyone : @bart - agreed that health records need limits. but if you’re travelling with data-minimized pass already (i.e. no direct medical/health data beyond “ok to travel by rules 1,27, and 43”), perhaps not.
• Darrell O'Donnell to Everyone : @bart - totally - WHO SVC is one registry - and countries may continue that - or do their own thing.
• Bart Suichies to Everyone : strongly disagree on that one: what if employers start asking for it. Purpose limitation is something that needs to be promoted
• Bart Suichies to Everyone : purpose binding is something that should be in there by design
• Bart Suichies to Everyone : it's a nuance - which is why I'd be in favor of adding a trust-registry for verifiers (it could contain a GRANT ALL statement)
• Darrell O'Donnell to Everyone : privacy-centric areas (let’s use EU/Switzerland as example) may consider that forbidden. More market-driven/less-privacy (US for example) may totally allow it. The in-betweeners (Canada for example) may allow wide use in some cases, very tight in others. Nuance.
• Bart Suichies to Everyone : we're implementing it in our interoperable aries bridge, in combination with a link to eidas
• Bart Suichies to Everyone : the eidas demo is here: https://essif.adaptivespace.io/
• Darrell O'Donnell to Everyone : @Bart or @David Chadwick - YAML would be massively appreciated.
• Bart Suichies to Everyone : https://gitlab.grnet.gr/essif-lab/infrastructure/fraunhofer/deliverables not sure if this an open repo
• Bart Suichies to Everyone : https://gitlab.grnet.gr/essif-lab/infrastructure/fraunhofer/deliverables/-/blob/master/api_documentation/train-atv-1.0.0-swagger.yaml
• Darrell O'Donnell to Everyone : closed repos - I have reached out to Victor though
• Bart Suichies to Everyone : perfect! we've been thinking about doing a nice cross-border test-case with some of our Canadian friends...
• Bart Suichies to Everyone : eIDAS to PCTF
• Bart Suichies to Everyone : Observation: in GHP the aspect of human readability is quite underappreciated
• Kyle Den Hartog to Everyone : Sorry just joined, what’s an EGF? Is that an electronic governance framework?
• Darrell O'Donnell to Everyone : Ecosystem Governace Framework @kyle
• Dominic Wörner to Everyone : I’m quite late to this session. A bit of a technical question How do you encode the x.509 as the issuer? Just a HTTPS website oder a URI that’s pointing the x.509 in some format? Is there a link I can read up on that?
• Jacob Dilles to Everyone : @Dominic there isn't a standard way, HTTPS is one way, .well-known/jwks.json is commonly used in OAUTH/OIDC; technically there is an LDAP URI format but I haven't seen that in use
• Bart Suichies to Everyone : Isn't that what ACDC is working on?
• Bart Suichies to Everyone : @drummond - returning to my earlier question - shouldn't #1 also contain the verifier. If we're talking about a 'trust registry protocol'
• Kyle Den Hartog to Everyone : Does anyone have a link to the TRAIN work?
• Bart Suichies to Everyone : @kyle: https://gitlab.grnet.gr/essif-lab/infrastructure/fraunhofer/train_project_summary
• Todd Gehrke1 to Everyone : @Kyle the TRAIN documentation is part of the eSSIF lab project. Bart and David Chadwick are going to help us get the info.
• Drummond Reed to Everyone : I think this is critical for anti-coercion
• Drummond Reed to Everyone : See the anti-coercion section of the original ToIP RFC: https://github.com/hyperledger/aries-rfcs/blob/master/concepts/0289-toip-stack/README.md
• Dan Bachenheimer to Everyone : it sounds like we need rules to respond to a Proof Request
• Sterre den Breeijen to Everyone : https://blockchain.tno.nl/blog/verify-the-verifier-anti-coercion-by-design/ Blog on anti-coercion by my colleague Oskar van Deventer
• Dan Bachenheimer to Everyone : if the request is OK / NOK versus raw health data
• Mahesh Balan - pocketcred.com to Everyone : There is the “Terms of Use” in the VC per the data model
• Riley Hughes to Everyone : This trust registry for verifiers is already party of the Trinsic Ecosystems product we announced Monday - happy to talk more about that
• Mahesh Balan - pocketcred.com to Everyone : As well as in the Verifiable Presentation
• Drummond Reed to Everyone : This is an our opportunity for Privacy by Design at scale
• Drummond Reed to Everyone : +1 for verifiers to publish their policies. The cool thing is that we can make it MUCH simpler for them by having them join a digital trust ecosystem!
• Bart Suichies to Everyone : there needs to be more attention to HUMAN READABILITY on GHPs on all levels.. #changeMyMind
• Judith Fleenor to Everyone : What is the TRAIN project?
• Bart Suichies to Everyone : @judith: https://gitlab.grnet.gr/essif-lab/infrastructure/fraunhofer/train_project_summary
• Darrell O'Donnell to Everyone : TRAIN - https://essif-lab.eu/essif-train-by-fraunhofer-gesellschaft/
• Kyle Den Hartog to Everyone : What considerations have you put on limitations to what verifiers need to publish so that to balance their privacy with their necessity to request information?
• Drummond Reed to Everyone : Bart, I am totally on board with the human-readable element for GHP. Happy to chat more with you about that. There is a lot of focus on that in the Consistent User Experience drafting group
• Kyle Den Hartog to Everyone : Also, looking at these things I’d highly suggest looking to the VC Data model and triangle to see if you can build upon it to enable these capabilities at the machine readable layer
• Kyle Den Hartog to Everyone : I can see ways to leverage VCs that are public to enable these in an open world model
• Darrell O'Donnell to Everyone : @kyle a “you have a GHP-I-Can-Request-A-Pass credential?” process may help.
• Bart Suichies to Everyone : @drummond - make sure the consistent UX WG links towards the paperbased WG
• Kyle Den Hartog to Everyone : The two actually can play together well
• Bart Suichies to Everyone : Have to drop to watch the magic of ledger agnostic AcaPY - thx for the great discussion all!
• David Chadwick to Everyone : The policy registry publishes its requirements for VCs. It is similar to a shop putting visa and mastercard stickers on its window
• Kyle Den Hartog to Everyone : Doing a demo we’ve worked on for paper based credentials if anyone’s interested in attending next session