Zusammenfassung
Digital identity stays rigid while it is bound to provider accounts, mutable handles and local wallet schemes. An accountable hash-anchor tier sits above them: an inert root anchor, unlinkable profile anchors for distinct contexts, and gate-specific assurance evaluated at a point in time.
Introduction
Digital identity becomes rigid when it is bound to a provider account, a mutable contact handle, a single social context, and one legal scheme. Natural persons move between family, professional, civic, and pseudonymous contexts, and they may also hold several jurisdictional identities. Platform accounts collapse these audiences into one presentation surface, a dynamic studied as context collapse and as audience management in social interaction.(Marwick and boyd 2011; Goffman 1959) The privacy problem is contextual as well: a datum may be appropriate in one relationship and inappropriate in another, even when it is true and lawfully held.(Nissenbaum 2010)
Four rigidities follow from that account-level design. Anchor rigidity appears when identity is welded to a phone number, email address, platform account, or wallet instance instead of a portable root. Context rigidity appears when one identifier must serve family, work, public, and pseudonymous interaction at once. Portability rigidity appears when an identity check performed by one institution cannot be reused by another without repeated collection. Jurisdiction rigidity appears when one scheme carries one legal frame while the actor’s life and transactions cross borders. The common cause is architectural: flexible use requires an identity object above wallets, providers, and local schemes.
Regulatory pressure points converge on the same architectural need. Data-protection law grants erasure and minimisation rights, while anti-money-laundering law requires customer due diligence and retention of identity records.(European Union 2016, 2024b) Electronic-identity law supports selective disclosure and pseudonym use, while regulated activity still requires lawful identifiability and recourse.(European Union 2024a) These duties can be stated in separate legal instruments, but a system that mediates legally relevant digital acts must implement them together. The missing architecture is an accountable middle layer: ordinary interaction remains pseudonymous and minimal, while defined conditions preserve resolution, audit, and responsibility.
The companion paper supplies the legal identity-assurance substrate for that layer.(Kurz 2026b) It defines natural, juridical, and machine entities; distinguishes entities from actors; represents assurance through Entity Actor Identity (EAID) coordinates over assertion rows and source classes; records confirmation and reliance as events; and states capability gates as predicates over that assurance state. It also fixes the machine-actor caveat used here: a machine may act technically, but legal responsibility is imputed through a natural or juridical actor under present law. This paper starts above that substrate and defines the hash-anchor tier that binds, separates, presents, and aggregates the legal assurance state.
From a systems-theory perspective, the hash anchor is an observation point for operations rather than a digital person. The system registers credential issuance, confirmation, presentation, consent, resolution, revocation, reliance, and dispute as events around an inert anchor, while legal identity remains reachable only through governed linkage.(Luhmann 1995) The design question is cybernetic: how much independent, fresh, and legally reachable evidence gives a relying party enough variety to let a pseudonymous counterparty act with credible recourse.(Ashby 1956)
This paper contributes five linked elements. First, it defines an above-wallet hash-anchor tier that binds to Paper 14’s event-backed assurance state and bridges credential schemes inside and outside the European Union. Second, it defines root and profile anchors so that context separation and accountable pseudonymity can coexist. Third, it defines gate-specific triangulated assurance-at-time over independent confirmation-event clusters, with freshness, revocation, source independence, binding strength, and jurisdiction evaluated at reliance time. Fourth, it models disclosure, lawful resolution, governed erasure, and retention as constraints that can be jointly satisfied under stated assumptions. Fifth, it models assurance-mediated trust as a reliance event in which verifiable gate satisfaction and credible recourse let pseudonymous parties transact.
Contribution
The building blocks are standards, privacy-preserving credential primitives, and the legal assurance substrate supplied by Paper 14. Paper 15 contributes the anchor tier that makes that substrate presentable, separable across contexts, and usable for trust decisions.
First, the paper defines an above-wallet hash-anchor tier. A root hash anchor commits to the off-chain EAID assurance state, while profile anchors let the same entity act in distinct contexts without disclosing the root anchor during ordinary interaction. The tier consumes credentials and wallet presentations as evidence packages and treats Paper 14 confirmation events as the units of assurance.
Second, the paper states the identifier and capability separation invariant for the anchor tier. The hash anchor names and commits; private keys authenticate; explicit consent and gate satisfaction authorize. This separation explains why the anchor can be public, why credentials and capabilities remain off-chain, and why erasure can target linkage and profile-binding state rather than the ledger commitment itself.
Third, the paper defines gate-specific triangulated assurance-at-time. The model evaluates independent confirmation-event clusters against a concrete gate predicate at reliance time. The function discounts shared issuers, ceremonies, status authorities, and proof failure modes, while accounting for binding strength, freshness, revocation, and jurisdictional fit.
Fourth, the paper combines accountable pseudonymity, lawful resolution, and governed erasure as constraints in one architecture. Profile anchors support ordinary pseudonymous interaction; threshold-governed resolution preserves recourse under valid legal process; the two-layer erasure model preserves required records while removing personal linkage when retention no longer applies.
Fifth, the paper models assurance-mediated trust over reliance events. A relying party can transact with a profile anchor when the presentation satisfies the gate and a dispute can reach the legally relevant imputation point. This connects identity assurance to practical cooperation between parties that start without direct knowledge of each other.
System Model and Formal Framework
Inputs from legal identity assurance
This paper builds on the legal identity-assurance substrate developed in the companion paper.(Kurz 2026b) That substrate distinguishes entities from actors: an entity exists, while an actor is an entity in the act being evaluated. It defines natural entities (N), juridical entities (J), and machine entities (M). A machine entity can act technically, but, under the present legal framing, it is not the terminal bearer of legal responsibility. Legally relevant machine action is presented through an admissible constellation, such as N+M, restricted J+M, or J+N+M, where a natural or juridical entity supplies the imputation point. A standalone M presentation is inadmissible for legally consequential gates unless future law supplies an independent legal identity for that machine entity; until then, J+M and J+N+M presentations also require role, mandate, or control evidence that connects the machine-mediated act to the accountable natural or juridical record.
The same substrate defines the Entity Actor Identity (EAID) coordinate grammar. An EAID coordinate, such as EAID-N6-S7, names one assertion row and one source-of-information rung: what identity-relevant item is disclosed, and who or what stands behind that item. Filled cells are supported by confirmation events. A confirmation event records the checked cells, source class, binding evidence, valid time, record time, revocation or status pointer, policy version, and proof package. A reliance event records the consuming-side act: who relied, for which capability, under which gate, law, actor constellation, time, and liability boundary. Paper 15 takes that legal grammar as input. It defines the hash-anchor layer that binds to it, presents it, and aggregates independent confirmation-event clusters for a concrete relying-party gate.
The Paper 15 root anchor is a self-issued, public, inert hash that commits to an off-chain EAID assurance state and confers no capability. It is registered on a distributed ledger as a tamper-evident, timestamped commitment. A profile anchor is a public, inert pseudonymous commitment for a defined context. Its public commitment is context-specific; its relation to is held in the encrypted binding registry of Definition [def:hierarchy] and is shown to a relying party only through a gate-specific predicate proof or through lawful resolution. In this paper, hash anchor names this ledger fixed point. It is distinct from the jurisdictional anchor of the companion paper, which is a time-indexed legal relation used to evaluate an act under a governing law.
For a hash anchor , let denote the set of confirmation events bound to the corresponding root EAID state. Each event may be carried by a verifiable credential, presentation, status entry, ledger proof, or other signed evidence package, but the unit of assurance is the confirmation event rather than the credential container.(World Wide Web Consortium 2025; Terbu et al. 2025)
Anchors and separation
An identifier names; it never authorises. All capability derives solely from possession of private keys (authentication) together with an explicit, fresh, consented grant (authorisation). Formally, knowledge of alone yields no admissible action.
Definition [def:sep] separates three functions that legacy identifiers conflate: the anchor names, keys prove, and consent permits. Two consequences follow. The anchor is safe to publish and to anchor on a public ledger, because it is inert. The sensitive material is the off-chain linkage between the accountable legal record and the anchor, together with the private keys.
An entity holds one root hash anchor within a governance domain and may hold profile anchors . The binding registry between root and profile anchors is held off-chain and encrypted, like the linkage between the accountable legal record and root anchor. The registry is never published. From and alone, an observer should not be able to determine whether both profile anchors bind to the same root, provided the implementation also partitions capabilities and correlation channels across profiles.
The hierarchy resolves context rigidity. Familial, professional, and pseudonymous relationships each address a distinct profile anchor, while reusable legal identity assurance binds to the root. A presentation through a profile anchor proves that the root EAID state satisfies a gate predicate without revealing the root or any sibling profile. The construction uses the anonymous-credential and unlinkable-proof family discussed in the related work, while the complete root/profile predicate primitive remains an assumption of this paper. Lawful resolution applies uniformly: under the constraint of Equation Eq. 3, a profile anchor resolves first to its root through and then to the legal linkage , so context separation preserves accountability.
Unlinkability is a property of the whole capability surface, not of identifiers alone. Any capability shared across profile anchors, such as a common payment instrument, a common recovery handle, or correlated transport metadata, constitutes a linkage channel that collapses the separation. The threat model treats cross-profile capability sharing as an attack surface, and a conforming implementation partitions capabilities per profile.
Triangulated assurance and disclosure
A relying party declares a gate for a concrete capability. Its demand predicate imports Paper 14’s gate grammar: required EAID cells, source floors, freshness windows, jurisdictional anchors, revocation conditions, and admissible actor constellations. For a disclosure response through a profile anchor, let be the confirmation events that are disclosed, or predicate-proven, as supporting at time . The verifier-facing assurance calculation is limited to events presented through . Events are equivalent, written , when they share a confirmer, ceremony, custody path, status authority, or proof failure mode relevant to . Only equivalence classes count as independent corroboration.
Let be the independence weight of an event class, its binding and source-strength term, and its gate-specific validity, freshness, revocation, and jurisdiction term. Where several events collapse into one equivalence class, the gate policy specifies the class summary rule, with the conservative default taking the weakest applicable binding, status, and freshness term. The verifier-facing triangulated assurance-at-time of response for gate is
Equation Eq. 1 is a gate-specific attribution-resilience form. It composes the independent confirmation-event clusters presented in , discounts shared failure modes, and reads status and freshness at reliance time. General reputation scoring remains outside the model. The value is evaluated after the mandatory gate predicates have been addressed; by itself it grants no permission. Several official identities, addresses, payment-control events, and jurisdictional anchors can raise assurance for a gate when they supply source-diverse corroboration. Repeated evidence resting on the same issuer or ceremony is collapsed into its event class, and the loss or revocation of one event leaves only the remaining independent event classes available. The product form is a simple independence-adjusted fusion rule for this architecture, while broader trust and evidence-fusion formalisms remain comparators rather than prerequisites.(Jøsang 2016)
A disclosure response to a relying party is admissible only if it carries explicit holder consent, discloses no more than requested, presents only holder-bound evidence packages, and presents only fresh, non-revoked evidence packages. With each factor in ,
and is released to if and only if . The final factor means that the disclosed package satisfies the declared gate predicate, including the required EAID cells, source floors, freshness windows, jurisdictional anchor, and constellation family. Where a gate also declares an assurance threshold , the factor includes . The threshold filters otherwise admissible presentations; it never replaces required cell, status, binding, or constellation predicates. Credential and presentation standards supply the carrying format; the gate semantics come from the legal identity-assurance model.(World Wide Web Consortium 2025; Fett et al. 2025; Terbu et al. 2025; Kurz 2026b)
Resolution, erasure, and trust
Lawful resolution of the linkage between the anchor and the accountable legal record is governed rather than unilateral. It requires a valid legal order and a quorum of at least of escrow key-holders,
Equation Eq. 3 describes authorised resolution as a legal-state predicate. Threshold secret sharing can ensure that fewer than key-holders cannot reconstruct the escrowed secret.(Shamir 1979) Collusion by key-holders without a valid order is a governance and audit breach rather than a cryptographic impossibility. The architecture addresses it by separating operator access from key custody and by notarising every resolution event for later attribution.
Immutable on-ledger artifacts are commitments and proofs, and they are retained. While the linkage exists, they constitute pseudonymised personal data and are processed under a retention basis (European Union 2016; European Data Protection Board 2025). The linkage and the binding registry are held off-chain and encrypted. On an erasure request at time , deletable linkage and profile-binding entries are removed unless a retention obligation holds for the affected profile, gate, reliance event , dispute window, or regulated record class. Deletion is deferred only for the obligated entries and performed when the obligation lapses. After deletion, the design claim is limited to removal of operator-side attribution means under the stated threat model; prior relying parties and institutions that lawfully retain disclosed preimages remain governed by their own retention duties.
Definition [def:erasure] reconciles the right to erasure with retention duties at the architecture level: the chain is preserved, the personal linkage is removed subject to law, and anonymisation is pursued by erasing linkage rather than records. The architecture defends a sequenced claim, pseudonymous while linkage exists and anonymous only when the remaining data and reasonably available auxiliary information no longer permit attribution under a context-specific legal assessment. Together, Equations Eq. 2 and Eq. 3 with Definition [def:erasure] state sufficient architectural conditions under which pseudonymity, lawful access, erasure, and retention can coexist.
Consider a verifier deciding whether to transact with a pseudonymous counterparty in a reliance event for gate at time . The verifier sees an admissible presentation through a profile anchor, plus the gate-specific assurance value . If defects, it gains , but defection triggers recourse with probability , where denotes the legal reachability of the submitted actor constellation and resolution path. Recourse imposes a penalty .
Cooperation is ’s best response whenever . If recourse is sufficiently credible and punitive that , and if is increasing in gate-specific assurance for the submitted constellation, there exists a threshold such that for cooperation dominates defection. A gate policy that uses assurance as a transaction screen should set for the relevant act. If , assurance for that gate falls short of deterring defection, and the rational verifier declines or collateralises the transaction.
Proposition [prop:trust] formalises the central claim: trust between strangers comes from a verifiable, gate-scoped assurance presentation coupled with credible recourse. The relying party need not learn the civil identity during ordinary interaction. It needs to know that the profile anchor is backed by a root EAID state that satisfies the gate, and that a dispute can reach the legally relevant imputation point through the governed resolution path.
Six threats and their mitigations follow from the model. A borrowed or replayed presentation is defeated by the holder-binding factor in Equation Eq. 2. The compromise or coercion of a single confirmer is bounded by the event-cluster form of Equation Eq. 1, since gate-specific assurance does not rest on any one issuer, ceremony, or status authority. Assurance inflation by corroboration farming is bounded by the equivalence relation and by the independence weights , whose governance Section 7 leaves open. Tampering with evidence is detected by ledger notarisation of proofs, consents, and dispute records. Unauthorised resolution of identity is constrained operationally by threshold custody, legal approval, separation of duties, and notarised resolution events; collusion by a valid quorum remains a governance breach with forensic evidence rather than an impossible act. Cross-profile linkage through shared capabilities is excluded only if an implementation partitions payment, recovery, and transport capabilities per profile anchor (Definition [def:hierarchy]). Two residual risks remain: registry-level scraping of inert anchors, which grants no capability under Definition [def:sep], and coercion of the holder, which no holder-bound scheme eliminates.
Discussion
The assurance presentation is evaluated over an actor constellation rather than over an isolated identifier alone. A relying party needs to know which constellation presented the anchor, which confirmation-event clusters support the requested gate, and which recourse path exists if the operation later becomes disputed. The hash-anchor layer carries or resolves to enough structured state for the relying party to distinguish a natural actor acting alone, a juridical actor acting through an accountable natural actor, a juridical actor acting through a natural anchor and a machine actor, a restricted juridical-machine constellation with legally sufficient delegation evidence, and a natural actor acting with a machine actor. Standalone machine presentations are treated as technical action without terminal legal imputation in the present legal frame. The reliance question is whether this constellation is credible for the requested operation and whether recourse can reach the appropriate imputation point.
The construction shows conditions under which requirements usually treated as competing can be jointly satisfied. Selective disclosure and pseudonymity coexist with lawful identifiability through accountable pseudonymity and threshold-governed resolution; the right to erasure coexists with retention through the two-layer model. Because authorised resolution requires both a legal order and a key quorum, accountability is preserved while the operator lacks unilateral resolution power.
Applications across the Agnostyca core
The tier serves natural, juridical, and machine-mediated actor constellations across several application domains. A family-safety application uses accountable pseudonymity and contact gating directly. Platform attestations already instantiate part of the pattern in production: the declared age range of a mobile operating system (Apple Inc. 2026) is an attested claim, verification-backed in some jurisdictions, that a relying party could consume as one confirmation event for an age-related gate without disclosure of the underlying data. A higher-education application uses credential binding and gate-specific assurance for enrolment and for signed, ledger-timestamped academic work. An enterprise artificial-intelligence application binds agent identity, attestations, and accountable action to the same anchor tier, so that one agent can evaluate whether another presents the required constellation and recourse path for a requested operation. The companion agent-orchestration framework (Kurz 2026a) governs how actors coordinate; the present tier governs which assurance and imputation state they present, and the two share a ledger substrate.
Complementarity with national wallets
The tier can consume and present national credentials as high-quality confirmation sources when their issuance and presentation satisfy the relevant gate. A relying party that accepts the EU Digital Identity Wallet (European Union 2024a; European Commission 2025) receives a routed presentation; a relying party with a scheme-specific legal requirement receives the specific credential, while a relying party that accepts event-backed corroboration receives the gate-specific assurance result of Equation Eq. 1. A natural person who holds, for example, an Austrian credential, a Swiss credential (Swiss Confederation 2024), and a non-European credential can bind all three to one root assurance state while presenting only the profile and evidence package required for the act. By accepting credentials already held by the user, the tier gives new deployments an initial evidence base across schemes and jurisdictions.
Conclusion
Digital identity is rigid when provider accounts, wallet instances, context, and jurisdiction are fused into one operational identity. This paper has argued that the missing layer sits above wallets: an accountable hash-anchor tier that binds to Paper 14’s legal assurance state, separates root and profile anchors, and lets relying parties evaluate gate-specific assurance-at-time over disclosed independent confirmation-event clusters. The hash anchor is deliberately inert. It names and commits, while keys authenticate, consent permits, gate predicates authorise, and governed resolution preserves recourse.
The model makes that architecture inspectable. The root/profile hierarchy separates contexts while preserving a lawful route to the accountable record. The assurance equation evaluates disclosed confirmation-event clusters at reliance time, discounting shared issuers, ceremonies, status authorities, and proof failure modes. The disclosure predicate fixes consent, minimisation, holder binding, freshness, status, and gate satisfaction as release conditions. The resolution, erasure, and reliance constructions then state how pseudonymity, lawful access, erasure, retention, and rational trust can hold together under the paper’s assumptions.
For the paper series, P15 supplies the anchor and assurance-at-time layer between progressive legal identity assurance and accountable ledger operation. P14 defines the actor grammar, confirmation events, reliance events, jurisdictional anchors, and capability gates. P15 turns that state into root and profile anchors that can be presented, separated, resolved, erased, and relied on. The following ledger layer can then bind validator identities, observer records, and evidentiary commitments to anchors whose assurance state is already gate-scoped, replayable, and legally attributable.
Limitations and Future Research
Several constraints bound the present work. Registry-level invisibility is a soft property with residual access risk, even when the separation invariant prevents the anchor from carrying capability. Holder binding assumes secure key storage and a workable cross-device recovery model, which is the most operationally demanding component. Confirmation-event governance, including which events enter Equation Eq. 1, which shared failure modes define , which summary rule applies within each event class, and which weights apply to event classes, requires an institutional process that this paper specifies only in outline. The model also treats event-class weights as scalar terms, while real evidence sources may have pairwise or higher-order correlations, for example two credentials drawing on the same civil registry. Modelling that correlation structure is future work. Presentations from profile anchors assume a predicate-proof primitive that proves gate satisfaction without revealing the root anchor, sibling profiles, or a stable cross-relying-party correlator. Anonymous credentials, AnonCreds, U-Prove, and BBS-style derived proofs supply important parts of that primitive; a complete construction binding those proofs to the root/profile hierarchy and the legal assurance state remains future work.(Camenisch and Lysyanskaya 2001; Paquin and Zaverucha 2013; World Wide Web Consortium 2026; Hyperledger AnonCreds Project 2026) Threshold custody also requires a legal and operational design for key-holders, collusion controls, and the orders that trigger authorised resolution. The erasure claim remains context-specific: deleting linkage and profile-binding state removes operator-side attribution means, while prior relying parties, AML records, dispute files, and other lawful preimage holders remain governed by their own legal bases. The model is analytical; empirical validation through a reference implementation and a cross-jurisdiction pilot is future work, as is formal verification of the joint-satisfiability claim under adversarial confirmation-event behaviour.