Tensions in Practice: Issuance reach in tension with a narrow trust set¶
Signed artifacts · accepted issuer keys
A verifier can check a signed artifact without acquiring the power to create one. But it must still decide whose signatures count. Trusting only issuer A keeps the accepted minting authority narrow. Accepting A or B gives another issuer a route to provide usable artifacts, while making either issuer’s compromise relevant. More trusted issuers are not more votes on the same artifact.
Keep issuance usable
Allow the intended organizations to supply artifacts without routing every issuance through one party.
Limit accepted minting authority
Keep the set of parties able to create accepted artifacts small enough to govern.
Why these aims pull against each other
The issue/verify split can remain intact for each key while the total set of accepted issuing authorities grows.
Choose an arrangement to see what changes and what remains difficult.
Qualitative paths and conditions, not measured costs, timings or performance guarantees.
What this choice protects
What it costs
When it fits
Compare the arrangements
Trust one issuer
Accept signatures under A’s key and exclude B from this trust set.
- What it protects
- The accepted authority boundary is small and easy to identify.
- What it costs
- Issuance depends on A, and compromise of A still permits forged-but-valid-looking artifacts.
- When it fits
- Fits a scope with one legitimate issuing organization and a workable plan for its continuity and key management.
Illustration note: Dependence on one issuer is a structural inference from the single accepted path; no availability rate is supplied.
Trust either issuer
Accept a valid signature from A or B, with the same required artifact checks.
- What it protects
- Either intended issuer can supply an accepted artifact; one need not perform every issuance.
- What it costs
- Either trusted issuer can also create an accepted artifact improperly if its issuing capability is compromised.
- When it fits
- Fits genuinely plural issuance needs when each added issuer is explicitly authorized, governed and removable from trust.
Illustration note: This is OR acceptance, not multiple signatures, consensus or a claim that adding issuers improves verification strength.
What this illustration does—and does not—establish
Capability Separation: Asymmetry Invariant versus Issuance Breadth (Scalar) supplies issuance breadth; Capability Separation: Restricted Issuance versus Single Point of Failure (Coupling) prevents the one-issuer option from appearing risk-free. The alternative-path drawing is an editorial instantiation.
- Signature validity establishes a relationship to a key under the assumed mechanism; it does not establish that the artifact’s content or use is appropriate.
- The graphs omit expiry, key rotation and revocation; stale trust configuration can matter.
- Two issuers are an illustrative finite set, not a recommended count.
Source entries
Capability Separation
Capability Separation: Asymmetry Invariant versus Issuance Breadth (Scalar) supplies the conflict examined here.
Asymmetry Invariant versus Issuance Breadth (Scalar)
The invariant — verifying never enables issuing — holds per-issuer, but widening the *set* of issuers quietly dissolves the asymmetry into shared authority.
Restricted Issuance versus Single Point of Failure (Coupling)
Concentrating issuance in one privileged party is the source of the asymmetry's cleanliness — and its concentrated risk. Compromise the single issuer (steal the private key, capture the central bank's plates, subvert the CA) and the adversary can mint unlimited valid artifacts the open population trusts completely.