Skip to content

Tensions in Practice: Issuance reach in tension with a narrow trust set

Signed artifacts · accepted issuer keys

A verifier can check a signed artifact without acquiring the power to create one. But it must still decide whose signatures count. Trusting only issuer A keeps the accepted minting authority narrow. Accepting A or B gives another issuer a route to provide usable artifacts, while making either issuer’s compromise relevant. More trusted issuers are not more votes on the same artifact.

Keep issuance usable

Allow the intended organizations to supply artifacts without routing every issuance through one party.

Limit accepted minting authority

Keep the set of parties able to create accepted artifacts small enough to govern.

Why these aims pull against each other

The issue/verify split can remain intact for each key while the total set of accepted issuing authorities grows.

Compare the arrangements

Trust one issuer

Accept signatures under A’s key and exclude B from this trust set.

What it protects
The accepted authority boundary is small and easy to identify.
What it costs
Issuance depends on A, and compromise of A still permits forged-but-valid-looking artifacts.
When it fits
Fits a scope with one legitimate issuing organization and a workable plan for its continuity and key management.

Illustration note: Dependence on one issuer is a structural inference from the single accepted path; no availability rate is supplied.

Trust either issuer

Accept a valid signature from A or B, with the same required artifact checks.

What it protects
Either intended issuer can supply an accepted artifact; one need not perform every issuance.
What it costs
Either trusted issuer can also create an accepted artifact improperly if its issuing capability is compromised.
When it fits
Fits genuinely plural issuance needs when each added issuer is explicitly authorized, governed and removable from trust.

Illustration note: This is OR acceptance, not multiple signatures, consensus or a claim that adding issuers improves verification strength.

What this illustration does—and does not—establish

Capability Separation: Asymmetry Invariant versus Issuance Breadth (Scalar) supplies issuance breadth; Capability Separation: Restricted Issuance versus Single Point of Failure (Coupling) prevents the one-issuer option from appearing risk-free. The alternative-path drawing is an editorial instantiation.

  • Signature validity establishes a relationship to a key under the assumed mechanism; it does not establish that the artifact’s content or use is appropriate.
  • The graphs omit expiry, key rotation and revocation; stale trust configuration can matter.
  • Two issuers are an illustrative finite set, not a recommended count.

Source entries

Capability Separation

Prime · Source of the tension

Capability Separation: Asymmetry Invariant versus Issuance Breadth (Scalar) supplies the conflict examined here.

Asymmetry Invariant versus Issuance Breadth (Scalar)

The invariant — verifying never enables issuing — holds per-issuer, but widening the *set* of issuers quietly dissolves the asymmetry into shared authority.

Read the source section

Restricted Issuance versus Single Point of Failure (Coupling)

Concentrating issuance in one privileged party is the source of the asymmetry's cleanliness — and its concentrated risk. Compromise the single issuer (steal the private key, capture the central bank's plates, subvert the CA) and the adversary can mint unlimited valid artifacts the open population trusts completely.

Read the source section