Overview
ISO/TR 23644:2023 - Blockchain and distributed ledger technologies (DLTs) - Overview of trust anchors for DLT‑based identity management - is a technical report that explains concepts and considerations for using trust anchors in identity systems that leverage blockchain and other DLTs. The document maps the different forms of trust anchors (legal, data, cryptographic, cybersecurity and social), outlines levels of assurance, and describes how trust anchors interact in decentralized identity architectures such as PKI, self‑sovereign identity (SSI), DIDs and zero‑knowledge proof (ZKP) solutions.
Key technical topics and considerations
This report does not prescribe a single implementation; rather it highlights technical topics and practical requirements to address when designing DLT‑based identity systems:
- Types of trust anchors: legal, data, cryptographic, cybersecurity and social - their roles, risks and interdependencies.
- Levels of assurance (LoA): a four‑level spectrum (low to very high) for identity, authentication and data quality that guides risk mitigation.
- Cryptographic anchors: roots of trust for authentication, signing, revocation and key management (PKI, federated PKI, DKMS, KERI, MPC, TPM).
- Data trust anchors: authoritative data sources and the need for high data quality, provenance and governance.
- Governance and chains of trust: modelling shared and distributed governance, policy decision/enforcement points (PDP/PEP), and legal baselines.
- Architectures covered: public PKI, federated PKI, DID/SSI approaches, ZKP‑based partial SSI solutions, and practical interactions with DLTs.
- Security and operational controls: assurance, testing, incident detection/response and certification regimes (blue/red teaming).
- Risk representation: vectors of trust, multi‑dimensional risk, and how to combine anchors to achieve required assurance.
Practical applications and who uses this standard
ISO/TR 23644:2023 is valuable for practitioners and decision‑makers involved in digital identity and DLT projects:
- Identity architects and system designers building blockchain‑backed identity infrastructures (SSI, DID, PKI).
- Relying parties and service providers (RPs, IDPs) assessing trust and assurance of credentials and identifiers.
- Governments and regulators designing trust frameworks and eID policies (e.g., eIDAS interactions).
- Security and compliance teams defining anchors for certification, incident response and risk management.
- Standards bodies and implementers seeking conceptual alignment between legal, technical and data governance aspects.
Keywords: ISO TR 23644:2023, trust anchors, DLT‑based identity management, blockchain identity, decentralized identity, PKI, SSI, DIDs, verifiable credentials, level of assurance.
Related standards and references
ISO/TR 23644:2023 is an overview and guidance resource to help design and govern trustworthy DLT‑based identity ecosystems.