Structured normative architecture that defines the policies, technical standards, legal rules, certification requirements, and governance mechanisms enabling organisations and individuals to establish, assert, verify, and maintain digital trust relationships across participating entities in an ec…
Semantic Classification
Content
Compositional Relationships (Components)
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:hasPart ig:TrustAnchor))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:hasPart ig:TrustList))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:hasPart ig:AssuranceLevel))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:hasPart ig:IdentityProofingProcess))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:hasPart ig:AuthenticationMechanism))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:hasPart ig:FederationProtocol))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:hasPart ig:AccreditationBody))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:hasPart ig:ConformityAssessmentBody))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:hasPart ig:RevocationMechanism))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:hasPart ig:TrustMark))
## Dependency Relationships
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:requires ig:IdentityVerification))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:requires ig:DigitalCredentials))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:requires ig:CryptographicProof))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:requires ig:ConformityAssessment))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:requires ig:AuditTrail))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:dependsOn ig:PublicKeyInfrastructure))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:dependsOn ig:Cryptography))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:dependsOn ig:DecentralisedIdentifiers))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:dependsOn ig:DataProtectionLaw))
## Capability Relationships
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:enables ig:DigitalIdentity))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:enables ig:CrossBorderAuthentication))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:enables ig:CredentialPortability))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:enables ig:TrustTransitivity))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:enables ig:RiskBasedAuthentication))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:enables ig:SelectiveDisclosure))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:supports ig:AMLKYCCompliance))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:supports ig:AccessControlSystem))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:supports ig:ZeroTrustArchitecture))
## Implementation Relationships
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:implements ig:NISTSP80063))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:implements ig:eIDAS2))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:implements ig:OpenIDFederation))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:implements ig:VerifiableCredentials))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:implements ig:OpenIDConnect))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:implements ig:TrustOverIP))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:uses ig:JSONWebToken))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:uses ig:X509Certificate))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:uses ig:SDJWT))
## Reduction Relationships
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:reduces ig:IdentityFraud))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:reduces ig:OnboardingFriction))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:reduces ig:ComplianceCost))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:reduces ig:TrustEstablishmentLatency))
SubClassOf(ig:TrustFramework
ObjectSomeValuesFrom(ig:reduces ig:DataDuplication))
## Data Properties
DataPropertyAssertion(ig:hasIdentifier ig:TrustFramework "IF-0031"^^xsd:string)
DataPropertyAssertion(ig:authorityScore ig:TrustFramework "0.87"^^xsd:decimal)
DataPropertyAssertion(ig:globalFrameworkCount ig:TrustFramework "8"^^xsd:integer)
DataPropertyAssertion(ig:policyAreasCount ig:TrustFramework "15"^^xsd:integer)
DataPropertyAssertion(ig:policyCharacteristicsCount ig:TrustFramework "75"^^xsd:integer)
## Annotations
AnnotationAssertion(rdfs:label ig:TrustFramework "Trust Framework"@en)
AnnotationAssertion(rdfs:comment ig:TrustFramework "Normative architecture defining policies, technical standards, legal rules, certification requirements, and governance mechanisms for establishing digital trust across ecosystem participants; encompasses UK DIATF/DVS v1.0, EU eIDAS 2 Regulation 2024/1183, NIST SP 800-63-4, Pan-Canadian Trust Framework PCTF, and Trust over IP governance metamodel; implemented via OpenID Federation trust chains, ETSI TS 119 612 trusted lists, W3C Verifiable Credentials 2.0, and ISO/IEC 17065 conformity assessment."@en)
AnnotationAssertion(dcterms:identifier ig:TrustFramework "IF-0031"^^xsd:string)
AnnotationAssertion(dcterms:subject ig:TrustFramework "Digital Identity, Trust, Certification, Accreditation, Identity Assurance, eIDAS, NIST"@en)
About Trust Frameworks
- Trust frameworks are the foundational normative architecture of the digital trust economy. They specify, at multiple abstraction levels — policy, legal, technical, and operational — the rules under which organisations can participate in an ecosystem as identity providers, relying parties, attribute providers, or credential issuers, and the rules under which individuals can have confidence that services claiming conformance with the framework genuinely protect their privacy, security, and rights. The core problem trust frameworks solve is transitive trust: two organisations that have never interacted can nonetheless trust assertions made by each other because they both independently satisfy the requirements of a mutually recognised framework, examined and certified by an accredited third party.
- The architecture of a trust framework typically comprises four interacting layers. The governance layer establishes who controls the framework, how rules are changed, what legal instruments bind participants (terms of service, codes of conduct, statutory obligations), and how disputes are resolved. The policy layer defines risk taxonomy, assurance levels, permitted use cases, and the mapping between transaction risk and required assurance. The technical layer specifies interoperable protocols (OpenID Connect, OpenID Federation, W3C Verifiable Credentials), data formats (SD-JWT, JSON-LD, ISO 18013-5 mDL), and cryptographic requirements. The certification layer defines how conformity to policy and technical requirements is assessed — by whom (conformity assessment bodies, CABs), against what standard (ISO/IEC 17065, ISO/IEC 27001), and with what oversight (national accreditation body, e.g. UKAS in the UK, DAkkS in Germany).
Identity Assurance Architecture
- The dominant conceptual vocabulary for identity assurance derives from NIST SP 800-63, which disaggregates the identity lifecycle into three independently scalable assurance dimensions. Identity Assurance Level (IAL) governs identity proofing — the binding of a claimed digital identity to a real-world person or entity. IAL1 requires no proofing (self-asserted attributes); IAL2 requires remote or in-person verification of reliable identity evidence with photographic and biographical matching; IAL3 requires supervised physical presence with biometric binding and trained personnel, suitable for high-security government and financial use cases. Authenticator Assurance Level (AAL) governs the security of the authentication mechanism after identity proofing. AAL1 permits single-factor methods; AAL2 mandates multi-factor authentication and under SP 800-63-4 must offer at least one phishing-resistant MFA option; AAL3 requires hardware-bound cryptographic authenticators (FIDO2 security keys, smart cards) proven phishing-resistant. Federation Assurance Level (FAL) governs the security of assertion passing between Identity Provider and Relying Party; FAL1 permits standard bearer assertions (SAML, OIDC ID tokens); FAL2 requires holder-binding preventing assertion replay; FAL3 requires cryptographic presentation proof tying assertion to the holder’s key material.
- NIST SP 800-63-4 (final draft August 2024, with adoption guidance targeting 2025) introduced explicit recognition of mobile driver’s licences (mDLs, ISO 18013-5) and W3C Verifiable Credentials as valid identity evidence at IAL2 and above, bridging the gap between the traditional assurance framework and the emerging decentralised credential ecosystem.
UK DIATF and DVS Framework
- The UK Digital Identity and Attributes Trust Framework (DIATF) evolved through alpha, beta, gamma, and in 2026 version 1.0 stages, underpinned by the Data (Use and Access) Act 2025 which received Royal Assent on 19 June 2025 and brought Part 2 (Digital Verification Services) into force on 1 December 2025. The Act establishes the Office for Digital Identities and Attributes (OfDIA) — a new executive body within DSIT — with statutory duties to: publish and maintain the DVS trust framework; operate a public register of certified providers (the DVS Register); oversee the certification scheme; and enforce provider obligations. The official register at digital-identity-services-register.service.gov.uk lists providers certified as Digital Verification Services (DVS).
- The gamma 0.4 framework (final publication June 2025, in force July 2025) represented the last pre-statutory version; the DVS Trust Framework 1.0 (published March 2026) constitutes the first statutory version. Version 1.0 introduced the UK CertifID trust mark — a government-branded signal that a provider has been independently certified and is on the DVS Register — modelled in part on analogous schemes in other markets. Under the Data (Use and Access) Act 2025, only registered DVS providers may display the UK CertifID trust mark; displaying it without registration is a regulatory offence.
- The certification path requires providers to be audited by a Conformity Assessment Body (CAB) approved by OfDIA and then UKAS-accredited under ISO/IEC 17065. Kantara Initiative achieved the historic milestone of becoming the first UKAS-accredited CAB for the UK DIATF in November 2025, alongside BSI Assurance UK working towards accreditation. UKAS, headquartered in Feltham, Middlesex, is the sole national accreditation body for the UK under Regulation (EC) 765/2008 as retained in UK law; its Digital Sector Accreditation programme manages the CAB recognition pipeline for identity frameworks. Certified providers span Right-to-Work verification, Right-to-Rent verification, DBS criminal record checking, and financial services onboarding against Money Laundering Regulations (MLR) — with DSIT/HM Treasury joint guidance (2025) explicitly confirming DIATF-certified services satisfy MLR identity verification requirements.
EU eIDAS 2 and the EUDI Wallet
- Regulation (EU) 2024/1183 (eIDAS 2, in force 20 May 2024) amends the original eIDAS Regulation 910/2014 and establishes the legal basis for the European Digital Identity (EUDI) Wallet — a standardised digital identity wallet that every EU Member State must offer to citizens by May 2026. Each EUDI Wallet instance is issued by or on behalf of a Member State, interoperates with wallets from all other Member States, and supports selective disclosure of attributes from government-issued credentials (driving licence, professional qualification, age attestation, social security number).
- The technical blueprint is the Architecture and Reference Framework (ARF), maintained by the European Commission’s Digital Building Blocks team on GitHub (eu-digital-identity-wallet/eudi-doc-architecture-and-reference-framework); ARF version 2.0 specifies the common architecture, exchange protocols (OpenID4VP, OpenID4VCI, SD-JWT VC), and data formats ensuring wallets issued by one Member State function across all others. The ARF mandates support for selective disclosure (users share only minimum necessary attributes), holder binding (preventing credential forwarding without the holder’s key), and wallet attestation (the wallet itself carries a signed statement of its security properties from the issuing Member State or a certified manufacturer).
- Trust in the EUDI ecosystem flows through a Trust List architecture: each Member State publishes a nationally-supervised trusted list conformant with ETSI TS 119 612 listing authorised trust service providers (TSPs) offering qualified electronic signatures, qualified timestamps, qualified certificates, and wallet providers. The European Commission maintains the List of Trusted Lists (LOTL) aggregating all Member State lists; relying parties can traverse LOTL to validate assertions from any wallet in any Member State without bilateral agreements. Version 2.4.1 of ETSI TS 119 612 (August 2025) aligns the specification with eIDAS 2 service type extensions.
OpenID Federation and Trust Chains
- OpenID Federation 1.0 (final specification published by the OpenID Foundation) provides the cryptographic machinery for expressing, discovering, and evaluating trust relationships in large-scale identity federation. Unlike traditional PKI or bilateral federation (where each pair of organisations must establish direct trust), OpenID Federation supports trust chains — cryptographically verifiable paths connecting a leaf entity (identity provider or relying party) through zero or more intermediate authorities to a trust anchor, enabling automated trust establishment at internet scale. Entity Statements are signed JSON Web Tokens (JWTs); the trust chain is validated by following issuer claims from leaf to trust anchor, with each intermediate applying policy constraints that narrow the acceptable metadata of downstream entities.
- The trust anchor plays the role of root CA in PKI: it is the party whose public key is distributed out-of-band and whose signatures bootstrap chain validation. Intermediate authorities enable delegation — a large national federation can designate sector-specific intermediates (healthcare, finance, education) that manage their own sub-federations under the top-level trust anchor’s policy. OpenID Federation 1.1 (draft 01) separates protocol-independent federation machinery (entity statements, trust chains, metadata policies, trust marks, federation endpoints) from the OpenID Connect-specific bindings, enabling reuse in OAuth 2.0 and other protocol contexts. OpenID Federation Wallet Architectures 1.0 (draft 04) applies the federation model to EUDI Wallet trust, directly linking it with eIDAS 2 governance.
Trust over IP (ToIP) Governance Metamodel
- The Trust over IP Foundation (ToIP, founded May 2020, 200+ member organisations) defines a four-layer architecture for internet-scale digital trust combining cryptographic assurance at the machine layers (Layer 1: DID/VDR registries; Layer 2: DIDComm/Trust Spanning Protocol peer-to-peer; Layer 3: Verifiable Credential exchange) with human accountability at the governance layer (Layer 4: Ecosystem governance frameworks). The Governance Metamodel Specification V1.0 (approved December 2021) provides a master template for ToIP-compliant governance frameworks, specifying required, recommended, and optional components of a governance document set: primary document (governed ecosystem description, controlled document registry), controlled documents (credential governance, trust registry, certification governance), and human governance (membership, roles, dispute resolution, accountability).
- The Trust Spanning Protocol (TSP) Task Force published its first Implementers Draft in April 2024, specifying a Layer 2 protocol serving as the keystone of the ToIP stack — a transport-agnostic secure messaging layer enabling any two principals that have each other’s DID to exchange authenticated, confidential, and optionally anonymised messages without dependence on any centralised intermediary. In 2025, the Coalition for Content Provenance and Authenticity (C2PA) adopted the ToIP governance metamodel for its conformance programme, demonstrating the framework’s applicability beyond digital identity to content authenticity use cases including AI-generated media governance.
Pan-Canadian Trust Framework (PCTF)
- The Pan-Canadian Trust Framework (PCTF), developed by the Digital ID & Authentication Council of Canada (DIACC), provides a modular certification framework for Canadian public and private sector digital identity services. PCTF is structured around discrete components (Verified Person, Verified Organization, Authentication, Consent, Credentials, Notices and Receipts) each of which has separately published Conformance Criteria and reaches maturity through a staged peer-review process: Discussion Draft → Recommended Draft → Final Recommendation. The Authentication Final Recommendation V1.2 (July 2024) and Verified Organization Final Recommendation V1.0 (October 2024) represent the most recent completions, with the Authentication component’s readiness signalling eligibility for inclusion in DIACC’s certification programme. PCTF deliberately aligns with international frameworks — NIST SP 800-63, eIDAS levels of assurance, and ISO/IEC 29115 — to support mutual recognition and cross-border interoperability with UK, EU, and US frameworks.
- In July 2024, OIX (then still operating) and DIACC committed to a joint interoperability workstream, culminating in OIX’s Digital ID DNA paper identifying 15 general policy areas, 75 policy characteristics, and 289 possible values across eight frameworks (UK DIATF, EU eIDAS 2, US NIST, Canada PCTF, Sweden BankID, Thailand ETDA, Singapore Singpass, and MOSIP) — the most comprehensive comparative analysis of trust framework interoperability published to 2024.
Trust Anchors, Trust Lists, and Trust Registries
- Trust anchors are the root cryptographic authorities whose public keys are distributed out-of-band as trusted starting points for chain-of-trust validation. In X.509/PKI, the trust anchor is the root CA certificate embedded in operating system or browser trust stores. In OpenID Federation, the trust anchor’s JWKS is the known-good starting point for trust chain evaluation. In ToIP, each governance framework designates a trust anchor whose DID and public key anchor the ecosystem. In ETSI TSL/eIDAS, the national trust list operator is the trust anchor for that Member State’s qualified trust services, with the European Commission’s LOTL serving as the meta-anchor for cross-border reliance.
- Trust lists (Trusted Service Provider Lists, TSLs) are structured, machine-readable registries of entities whose trustworthiness has been established under a specific governance regime. ETSI TS 119 612 defines the XML schema and publication requirements for EU Member State TSLs; ETSI TS 119 615 specifies procedures for using TSLs for certificate validation. Analogous trust registries appear in OpenID Federation (trust anchor’s self-signed entity configuration listing subordinate entities), ToIP (trust registries listing credential schemas and issuer DIDs), and the UK DVS Register (statutory list of certified DVS providers). Trust registry discovery — the ability for a relying party to automatically discover whether a given issuer is authorised under a given governance framework — is a key technical challenge addressed differently across frameworks: OpenID Federation uses cryptographic entity statements; ToIP uses DIDDoc-referenced trust registry endpoints; DVS uses a GOV.UK API endpoint over the public internet.
W3C Verifiable Credentials 2.0 and Selective Disclosure
- The W3C Verifiable Credentials Data Model 2.0 (published as a W3C Recommendation 15 May 2025) provides the semantic data model for machine-verifiable cryptographic credentials: a credential is a set of claims made by an issuer about a subject, packaged with metadata enabling any verifier to confirm issuer identity, credential integrity, and validity status without contacting the issuer at verification time. VC 2.0 introduces mandatory support for Data Integrity Proofs and clarifies the relationship between the abstract data model and concrete serialisations (JSON-LD with Data Integrity, SD-JWT VC).
- SD-JWT VC (Selective Disclosure JSON Web Token Verifiable Credentials) has emerged as the dominant format for eIDAS 2/EUDI Wallet credentials, combining JWT compactness with cryptographic selective disclosure — the holder can reveal any subset of credential claims by including only the corresponding disclosure values in a presentation, leaving undisclosed claims unlinkable. SD-JWT VC is specified in IETF draft-ietf-oauth-sd-jwt-vc and referenced by both the ARF and OpenID4VP. This enables privacy-preserving presentations — e.g. proving age ≥ 18 without revealing exact date of birth — that are simultaneously compact, verifiable, and unlinkable across presentations when combined with unlinkability techniques.
Components / Architecture
- A complete trust framework implementation requires the following functional layers working together:
- Governance and Legal Layer: The legal instrument (statute, contract, code of conduct) that binds participants; defines liability allocation, dispute resolution, and framework evolution governance. Examples: Data (Use and Access) Act 2025 for DVS; eIDAS 2 Regulation 2024/1183 for EUDI Wallet; PCTF DIACC governance charter for Pan-Canadian framework.
- Policy and Assurance Layer: Risk taxonomy mapping transaction categories to required assurance levels; IAL/AAL/FAL matrices (NIST model) or LoA 1–4 scales (ISO/IEC 29115 model) or equivalent. Includes permitted credential types, acceptable identity evidence, age verification policies, and accessibility requirements.
- Technical Standards Layer: Interoperable protocols (OpenID Connect for authentication; OpenID Federation for entity-to-entity trust; OpenID4VCI for credential issuance; OpenID4VP for credential presentation; DIDComm for peer-to-peer messaging); credential formats (SD-JWT VC, ISO 18013-5 mDL, W3C VC JSON-LD); cryptographic algorithms (ECDSA P-256, EdDSA Ed25519, RSA 2048 minimum; FIPS 140-3 for AAL3 authenticators).
- Certification and Accreditation Layer: CABs auditing providers against framework requirements; national accreditation body (UKAS in UK, DAkkS in Germany, RvA in Netherlands) granting ISO/IEC 17065 accreditation to CABs; scheme owner (OfDIA in UK, European Commission for eIDAS) approving CABs before UKAS accreditation. Assessment scope covers identity proofing processes, IT security controls (ISO/IEC 27001), biometric data handling (GDPR special category data), liveness detection (ISO 30107-3), and document verification against known-forgery libraries.
- Trust Registry / Register Layer: The machine-readable, queryable source of truth about which entities are authorised under the framework. UK: DVS Register (GOV.UK). EU: LOTL + Member State TSLs (ETSI TS 119 612). OpenID Federation: trust anchor entity configuration + subordinate statement cache. ToIP: DIDDoc-referenced trust registry endpoints per governance framework. NIST: no central registry specified — each relying party policy determines accepted CSPs.
Use Cases / Major Families
- Right-to-Work and Right-to-Rent verification (UK): Employers and landlords may use DIATF-certified DVS providers to discharge statutory document verification obligations; DSIT/Home Office guidance confirms certified services constitute a valid alternative to physical document inspection. Leading certified providers (per DVS Register 2026): Yoti, Onfido (Entrust), OneID, Experian Identity, TrueLayer, iProov.
- Financial services onboarding (UK/EU): Know Your Customer (KYC) and Anti-Money Laundering (AML) compliance; DSIT/HM Treasury joint guidance (2025) explicitly confirms DIATF-certified services satisfy MLR 2017 identity verification requirements, enabling fully digital customer onboarding with certified assurance. Under eIDAS 2, EUDI Wallet presentations at LoA High satisfy the identity verification requirements of the 4th/5th AML Directives.
- Cross-border government services (EU): eIDAS 2 mandates mutual recognition of notified national eID schemes and EUDI Wallets across Member States for public sector services (e-government, university enrolment, healthcare records access, benefits claim). The ARF specifies 23 PID (Person Identification Data) attributes exchangeable across all Member States.
- Education credential portability: ToIP-governed verifiable credential ecosystems for academic degrees; Europass Digital Credentials Infrastructure (EDCI) uses W3C VC data model underpinned by eIDAS qualified signatures for cross-border recognition of diplomas within EU.
- Healthcare identity and consent (UK): NHS Login implements IAL2/AAL2-equivalent assurance for patient-facing digital services; NHS Digital Identity programme aligns with DIATF requirements. CareIdentity Service (CIS2) provides Smartcard-based AAL3-equivalent authentication for clinical staff under NHS England.
- Content provenance and AI governance: C2PA adopted ToIP governance metamodel (2025) for its conformance programme, establishing a trust framework over AI-generated and AI-labelled media content — issuers of content provenance assertions are enumerated in a trust list, relying parties validate assertions against certified issuer DIDs.
Academic Context
- Trust framework theory draws on multiple research traditions. Federated identity research (Winsborough & Li, RBAC federation; Blaze, Feigenbaum & Lacy, PolicyMaker/KeyNote trust management, 1996–1998; Abadi’s calculus of principals) established formal foundations for delegating authority across administrative boundaries. Sociotechnical systems research at Edinburgh (Sasse, Inglesant; usability of authentication), UCL (Anderson; security economics), Cambridge (Murdoch, Bohm; transaction authentication, chip-and-PIN failures), and Imperial (Sadeghi, Schneider; trusted computing) directly informs the design of certification schemes balancing security with usability.
- Identity assurance level theory formalised by Burr et al. (NIST SP 800-63, 2006 original; revised Grassi et al. 2017) introduced the IAL/AAL/FAL disaggregation; subsequent academic critique (Grassi, Fenton, Lefkovitz, 2017 revision authors; Chadwick et al. UCL identity federation work) drove the move away from fixed LoA to risk-adaptive assurance selection in 800-63-4. The trust transitivity problem — whether trust in A and trust in B transitively implies trust in the composition of A and B — remains an open question with negative results from role-based trust management literature (Li & Mitchell 2003, IBM Research) driving the conditional trust assertions model in OpenID Federation’s policy constraint propagation.
Current Landscape (2026)
- The 2024–2026 period marks the transition from pilot to statutory operation for the two largest trust framework programmes globally. In the UK, the DVS Trust Framework 1.0 came into force March 2026, the UK CertifID trust mark launched, and the DVS Register transitioned from a DSIT-managed spreadsheet to a live statutory register under OfDIA. Kantara Initiative (first UKAS-accredited CAB, November 2025) and BSI Assurance UK (in accreditation process 2026) constitute the CAB ecosystem; approximately 50+ providers were certified under gamma prior to the 1.0 transition. The framework explicitly supports Age Verification use cases following the Online Safety Act 2023 commencement.
- In the EU, eIDAS 2 pilot programmes across Member States (the “Large Scale Pilots” — POTENTIAL, NOBID, EUDIW Consortium, DC4EU) tested EUDI Wallet interoperability across 150+ use cases from 2022–2025. Member States must issue production EUDI Wallets by May 2026. The ARF v2.0 stabilised the core technical specifications; OpenID4VP and SD-JWT VC have converged on IETF standards track. The European Digital Identity Wallet Consortium (EWC) coordinates reference implementation work.
- Globally, NIST SP 800-63-4 adoption progresses across US federal agencies under OMB guidance; mDL (ISO 18013-5) deployments in US state DMVs (Arizona, Colorado, Georgia, Maryland, Utah) have created real-world IAL2 credential evidence accepted by NIST-aligned verifiers. The International Trust Framework Interoperability work (OIX DNA analysis, ITU-T SG17 studies, ISO/IEC JTC1 SC27 WG5) aims to establish mutual recognition agreements enabling a UK DIATF-certified individual to be recognised by an eIDAS-relying party and vice versa — the Global Digital Trust Framework interoperability layer envisaged by multiple standards bodies.
UK Context
- The UK’s trust framework ecosystem is centred on OfDIA within DSIT, responsible for the DVS trust framework, DVS Register, and UK CertifID scheme. UKAS (United Kingdom Accreditation Service), headquartered at 2 Pine Trees, Chertsey Lane, Staines-upon-Thames (with operational offices in Feltham), is the national accreditation body (NAB) designated under the Accreditation Regulations 2009; it accredits CABs under ISO/IEC 17065 for the digital identity sector. Kantara Initiative (the international digital identity assurance certification body) achieved UKAS accreditation in November 2025 as the first CAB for UK DIATF, auditing providers against the full technical and policy requirements of the DVS Trust Framework. BSI Assurance UK (British Standards Institution certification arm) is the second CAB in the accreditation pipeline.
- Open Identity Exchange (OIX) — the UK-rooted digital identity cross-sector forum whose UK chapter launched in 2016 and played a formative role in shaping the DIATF through consultations and pilots — ceased operations in August 2024 following its major 2023 “Digital ID DNA” cross-framework interoperability analysis. The identity industry representation function has been partially absorbed into techUK’s Identity and Access Management group and the government’s DIATF industry working groups. Yoti (UK company, London) and OneID (UK company) are UK-headquartered certified DVS providers, alongside iProov (London, biometric liveness detection for DIATF IAL2), which holds both UK DIATF and EU certifications.
- Northern England’s industrial relevance includes HMRC Digital in Washington (Tyne and Wear) and Newcastle processing personal tax identity at scale using Government Gateway credentials aligned with IAL2-equivalent government standards; NHS Business Services Authority in Newcastle managing NHS Login identity services for 20M+ users at IAL2; Lloyds Banking Group Leeds technology centre deploying DIATF-certified KYC pipelines for retail banking onboarding; Co-operative Bank Manchester implementing DIATF-compliant digital onboarding following the 2025 MLR guidance. Sheffield Hallam University and University of Leeds run active research programmes in digital identity usability and trust framework governance as part of the UKRI Digital Security by Design initiative.
Future Directions (2026–2030)
- EUDI Wallet global reach: By 2028 the EU aims to extend mutual recognition of EUDI Wallets to third countries under Article 46 eIDAS 2 equivalency decisions; the UK-EU Digital Partnerships track (under the Windsor Framework and subsequent bilateral technology agreements) may establish EUDI Wallet ↔ UK CertifID mutual recognition, creating a de facto transatlantic trust framework.
- AI agent identity: As Agents proliferate (agentic AI systems acting on behalf of individuals in financial, healthcare, and legal contexts), trust frameworks must address non-human identity: agent credentials issued to AI systems, constrained delegation limiting agent authority within specific scopes, and audit trails satisfying accountability obligations. NIST SP 800-63-4’s IAL/AAL/FAL model is not directly applicable to AI agents; NIST IR 8062 and emerging work from the Cloud Security Alliance explore agent identity governance.
- Continuous adaptive authentication: Moving beyond point-in-time identity verification to continuous risk assessment integrating behavioural biometrics, device posture, and network signals within a trust framework’s AAL policy — enabling session-level assurance adjustment without friction-imposing re-authentication.
- Quantum-safe cryptographic transitions: PKI and JWT-based trust frameworks depend on RSA/ECDSA cryptography vulnerable to large-scale quantum computers. NIST post-quantum cryptography standards (FIPS 203 ML-KEM, FIPS 204 ML-DSA, August 2024) will require trust framework cryptographic agility provisions; eIDAS 2 and DVS 1.0 both include provisions for cryptographic algorithm updates without full framework revision.
- Reusable identity portability: The ITU-T X.1278 standard and emerging “identity wallet portability” requirements would allow individuals to migrate their verified identity credentials between wallet providers without re-proofing — extending the portability principle of the UK DVS scheme to the wallet layer.
Research & Literature
- The foundational trust management literature (Blaze, Feigenbaum & Lacy, “Decentralized trust management”, IEEE S&P 1996; Rivest & Lampson, SDSI/SPKI 1996; Ellison et al., SPKI Certificate Theory, RFC 2693, 1999) established the conceptual vocabulary. NIST SP 800-63-4 (Grassi et al., NIST 2024 final draft) is the canonical US government digital identity assurance guideline; its predecessor SP 800-63-3 (2017) remains the most widely cited identity assurance standard globally. Cameron’s “Laws of Identity” (2005, Microsoft) introduced the “minimal disclosure” principle now instantiated in SD-JWT VC selective disclosure. The eIDAS 2 ARF (European Commission, v2.0, 2025) is the definitive technical specification for the EUDI Wallet ecosystem. Chadwick et al., “My Private Cloud” (Int. J. Information Security, 2014) provides UK academic treatment of federated identity policy across cloud boundaries. Murdoch & Drimer, “Chip and PIN is Broken” (IEEE S&P 2010, Cambridge Computer Laboratory) demonstrated the failure modes of authentication assurance schemes that lack end-to-end protocol binding — a lesson directly incorporated into FAL3 requirements. Josang’s subjective logic (2016, Springer) provides the formal probabilistic trust calculus underpinning Bayesian trust frameworks. The OIX “Digital ID DNA” analysis (OIX, 2023) provides the most comprehensive cross-framework policy comparison.
Metadata
- Domain correction:
infrastructure→identity-governance. The original frontmatter incorrectly classified this concept underinfrastructure. Trust frameworks are fundamentally instruments of identity governance — covering certification, accreditation, policy, legal instruments, and assurance level architecture — not generic infrastructure components. IRI, URI, same-as, and owl-class corrected accordingly. - Legacy term ID assigned:
IF-0031(Identity Frameworks ontology series) - Enrichment worker:
claude-sonnet-4-6 - Enrichment phase: 6 / bulk run
- Completed: 2026-05-17T10:00:00Z
Provenance
-
- NIST SP 800-63-4, “Digital Identity Guidelines”, NIST (final draft August 2024), https://pages.nist.gov/800-63-4/sp800-63.html
-
- European Commission, “Architecture and Reference Framework (ARF) v2.0”, EU Digital Identity Wallet programme (2025), https://eu-digital-identity-wallet.github.io/eudi-doc-architecture-and-reference-framework/2.4.0/architecture-and-reference-framework-main/
-
- Regulation (EU) 2024/1183 of the European Parliament and of the Council (eIDAS 2), OJ L 1183, 20 May 2024
-
- UK Data (Use and Access) Act 2025, Part 2 (Digital Verification Services), UK Parliament, Royal Assent 19 June 2025, https://www.legislation.gov.uk/ukpga/2025/18/part/2
-
- DSIT/OfDIA, “UK Digital Verification Services Trust Framework 1.0” (March 2026), https://www.gov.uk/government/publications/uk-digital-verification-services-trust-framework-1-0/uk-digital-verification-services-trust-framework-1-0-pre-release
-
- DSIT/OfDIA, “Final Gamma (0.4) Trust Framework and Updated Supplementary Codes” (June 2025), https://enablingdigitalidentity.blog.gov.uk/2025/06/26/sharing-the-final-gamma-0-4-trust-framework-and-updated-supplementary-codes/
-
- UKAS, “UK Digital Identity and Attributes Trust Framework — Digital Sector Accreditation”, https://www.ukas.com/accreditation/sectors/digital/
-
- Kantara Initiative, “Kantara Achieves Historic First: Accredited to Certify Against the UK DIATF” (November 2025), https://kantarainitiative.org/kantara-achieves-historic-first-accredited-to-certify/
-
- GOV.UK, “Certification Scheme for the UK Digital Identity and Attributes Trust Framework”, https://www.gov.uk/guidance/certification-scheme-for-the-uk-digital-identity-and-attributes-trust-framework
-
- GOV.UK, “Digital Identity Services Register”, https://www.digital-identity-services-register.service.gov.uk/
-
- ETSI TS 119 612 V2.4.1 (August 2025), “Electronic Signatures and Infrastructures (ESI); Trusted Lists”, https://www.etsi.org/deliver/etsi_ts/119600_119699/119612/02.04.01_60/ts_119612v020401p.pdf
-
- OpenID Foundation, “OpenID Federation 1.0”, https://openid.net/specs/openid-federation-1_0.html
-
- OpenID Foundation, “OpenID Federation 1.1 — draft 01”, https://openid.net/specs/openid-federation-1_1-01.html
-
- OpenID Foundation, “OpenID Federation Wallet Architectures 1.0 — draft 04”, https://openid.github.io/federation-wallet/main.html
-
- Trust over IP Foundation, “ToIP Technology Architecture Specification”, https://trustoverip.github.io/TechArch/
-
- Trust over IP Foundation, “Governance Metamodel Specification Companion Guide V1.0” (December 2021), https://trustoverip.org/wp-content/uploads/ToIP-Governance-Metamodel-Specification-Companion-Guide-V1.0-2021-12-21.pdf
-
- Trust over IP Foundation, “Trust Spanning Protocol — First Implementers Draft” (April 2024), https://trustoverip.org/our-work/deliverables/
-
- DIACC, “Pan-Canadian Trust Framework — Authentication Final Recommendation V1.2” (July 2024), https://diacc.ca/wp-content/uploads/2024/10/PCTF-Authentication_Final-Rec-V1.2_Compressed_ENG.pdf
-
- DIACC, “Pan-Canadian Trust Framework — Verified Organization Final Recommendation V1.0” (October 2024), https://diacc.ca/wp-content/uploads/2024/10/PCTF-Verified-Organization_Final-Rec-V1.0_Comrpessed_ENG.pdf
-
- OIX, “Digital ID DNA — Interoperability Across Trust Frameworks” (October 2023), https://openidentityexchange.org/networks/87/item.html?id=708
-
- W3C Verifiable Credentials Working Group, “Verifiable Credentials Data Model v2.0” (W3C Recommendation, 15 May 2025), https://www.w3.org/TR/vc-data-model-2.0/
-
- Grassi P.A. et al., “NIST SP 800-63-3: Digital Identity Guidelines” (2017), National Institute of Standards and Technology
-
- Blaze M., Feigenbaum J., Lacy J., “Decentralized Trust Management”, IEEE Symposium on Security and Privacy (1996)
-
- Cameron K., “The Laws of Identity”, Microsoft (2005)
-
- Murdoch S.J., Drimer S. et al., “Chip and PIN is Broken”, IEEE Symposium on Security and Privacy (2010), University of Cambridge Computer Laboratory
-
- Jøsang A., “Subjective Logic: A Formalism for Reasoning Under Uncertainty”, Springer (2016)
-
- DSIT/HM Treasury, Joint Guidance on DIATF Certification and Money Laundering Regulations (2025), https://www.techuk.org/resource/digital-id-boost-for-aml-checks-dsit-and-hmt-issue-guidance-for-mlr-compliance.html
- domain-correction: infrastructure → identity-governance