Technology
Digital signatures
Each credential is digitally signed using cryptographic mechanisms designed to establish a verifiable association between the credential and the issuer's signing key. The signing process generates a cryptographic signature linked to the credential's information, providing a means of establishing its origin and protecting the integrity of the signed data. This signature forms the foundation for subsequent verification by authorised systems and independent third parties.
Cryptographic verification
Verit employs cryptographic verification mechanisms to validate digital signatures associated with issued credentials. During verification, the signed credential information is evaluated against the corresponding public verification key to determine whether the signature is mathematically valid. This process enables independent verification without requiring access to the issuer's private signing key or relying on a centrally stored copy of the original document.
Issuer-Controlled Keys
Issuers retain control over their private cryptographic signing keys, which are used to digitally sign credentials and associated documents. The signing process is designed to maintain a clear separation between the issuer's signing authority and Verit's verification functionality. This approach supports issuer autonomy by ensuring that the authority to generate valid credential signatures remains under the control of the respective issuer throughout the credential issuance process.
Tamper Detection
Cryptographically signed credential information is subject to integrity verification, enabling the detection of modifications made to the signed data following issuance. Any alteration to information covered by the original digital signature causes the signature verification process to fail, provided that the signature and verification mechanisms remain secure. This capability supports the identification of unauthorised changes and provides a reliable means of assessing whether credential information remains consistent with its originally signed state.
Privacy-Preserving Records
Credential issuance and revocation events are recorded through cryptographic hashing mechanisms, establishing a tamper-evident record of significant activities throughout the credential lifecycle. This architecture supports the traceability of credential-related events while minimising the retention and exposure of sensitive information. By recording cryptographic hashes rather than personally identifiable information or complete credential data within the event ledger, Verit supports lifecycle event tracking without requiring the centralised storage of underlying credential information.