Skip to main content
Version: Work in Progress
UNTP Public Review
Public review has now closed. The UNTP team is working through the review comments and expects to release UNTP version 1.0.

Privacy-Preserving Verification

info

Please note that this specification is suitable for pre-production pilot implementations.

Overview​

A buyer, a regulator or a customs authority needs confidence in a claim made further up the supply chain. The evidence behind that claim sits with the company that made it, and that company usually cannot publish it. Supplier relationships are commercially sensitive, production volumes tell competitors what a facility is capable of, and in some countries the underlying data may not lawfully leave the country at all.

Withholding the evidence does not have to mean withholding the confidence. Three patterns let a claim be verified without its evidence being published, and they differ in what the verifier gets instead:

PatternWhat the verifier getsWho sees the evidence
Evidence seen only by an auditorAn independent auditor's signed conclusionThe company and its auditor
Sensitive values maskedThe structure of the data, with sensitive parts replaced by fingerprintsNobody, unless the holder chooses to reveal a value
Evidence shared only with named partiesThe evidence itself, if they qualifyWhoever the issuer has named

There is always a simpler option as well: publish it. Where data is not sensitive, the cheapest pattern is no pattern.

The patterns combine. They are not alternatives to pick between once and for all. A single supply chain commonly has an auditor attesting at a refinery, direct trading partners sharing evidence with each other, masked supplier identities in a published facility record, and ordinary public credentials wherever nothing is sensitive. One company may use all four in the same week, for different parts of the same product.

UNTP specifies the first pattern and the third. The second is described here rather than specified: implementations are beginning to appear and the shape is still under discussion, so no UNTP credential property carries a masked value yet.

Evidence seen only by an auditor​

An independent auditor examines the evidence. Everyone else receives the auditor's signed conclusion.

The auditor looks at production records, supplier contracts, meter readings, or whatever else the claim rests on, and issues a Digital Conformity Credential stating what it found. The evidence stays with the company and its auditor. This is the trusted auditor option in Disclosing the Data.

It is also the pattern that answers data residency rules. The audit happens inside the country holding the data, and the only thing that crosses the border is a signed statement of the result.

In a refining facility the split falls out like this. The auditor receives stock positions, production runs, and inbound and outbound shipping events, together with the passports for every input material. The customer receives the output passport, the facility record and the auditor's conformity credentials; the production data behind them stays with the facility and its auditor.

An independent auditor receives a refiner's internal stock and flow data as traceability events, audits the material accounting, and issues product-level and facility-level conformity credentials. The customer receives those credentials, the output product passport and the facility record, and none of the underlying production data.

Chain of Custody and Mass Balance follows the same flow step by step.

Making the auditor accountable​

The conclusion is worth no more than the auditor behind it, so a reader needs to be able to check the auditor rather than simply trust it. Two things make that possible.

Anyone can check what the auditor is accredited for. The auditor's Digital Identity Anchor states which body accredited it and for which schemes. A verifier can confirm that the auditor was accredited for the scheme it is attesting against rather than for something unrelated, and the AssessorAccreditedForScope rule expresses that check in a form software can run automatically.

The auditor is pinned to the evidence it actually used. Each piece of evidence listed in an assessment can carry a digestMultibase: a short fingerprint of the file, from which the file itself cannot be reconstructed. Including it commits the auditor, at the moment it signs, to the exact evidence it relied on.

"evidence": [
{
"linkURL": "https://evidence.sample-cab.example.com/bundles/smelter-002-2025-Q1",
"linkName": "Production records and supplier declarations, Q1 2025",
"linkType": "https://test.uncefact.org/vocabulary/link-type/evidence",
"digestMultibase": "zQmSampleDigestOfTheEvidenceBundle"
}
]

An ordinary reader cannot open that bundle. An accreditation body, a regulator or a court can later demand it, and the fingerprint shows whether the auditor is producing the same evidence it originally signed over or something assembled afterwards.

PPV-01. Where an assessment's conclusion is relied upon in place of its evidence, the assessment SHOULD carry a digestMultibase for each evidence link.

PPV-02. An assessor that issues a committed assessment SHOULD retain the evidence bundle, unaltered, for at least the period the assessment is relied upon.

PPV-02 is what makes PPV-01 worth anything. A fingerprint of a file that no longer exists proves only that something was once hashed. Durable Storage covers how to keep evidence retrievable for the long term, and Decentralised Access Control carries a related requirement about credentials remaining available after their issuer stops trading.

How much the auditor needs to see​

Continuous access to everything is not required. In increasing order of access:

  • Sampling. The company groups each period's evidence into a bundle and publishes only the bundle's fingerprint. The auditor asks for bundles at random and checks each against its published fingerprint.
  • Continuous. The company sends its traceability events to the auditor as they happen, and the auditor attests on a standing basis.
  • One up, one down. The company shares with its direct customer only, who does not pass it on. Strictly this is the third pattern rather than this one, but it is often the practical first step.

The evidence and the credentials are the same in each. Only how much the auditor sees differs.

Sampling only works if the company commits first. Asking for bundles at random proves nothing if the company can decide what a bundle contains after it learns which one was picked. A fingerprint shows that a bundle has not been altered since it was published; it does not show that the company was working from that bundle rather than from a second, equally tidy set of books kept for a different audience. Random audit works in tax collection because the taxpayer files before the auditor selects, and the same ordering is needed here.

Publishing the fingerprints somewhere the company cannot quietly swap them later closes that gap. An append-only log does the job: entries can be added but never altered or removed, and independent witnesses countersign the log so that the company cannot show one history to its auditor and a different one to a customer without somebody noticing. A witness signs only a short summary of the log and sees none of its contents, so witnessing is not itself a disclosure, and a witness can sit in a different country from the data.

PPV-03. Where an assessment relies on random selection from a holder's evidence bundles, those digests SHOULD be published in an append-only log whose head is attested by parties independent of both the holder and the assessor, and the assessment SHOULD carry the inclusion proof for each bundle it relied upon.

For implementers, this is a profile of existing work rather than anything new. RFC 9162 defines the log structure and its proofs, and the IETF Supply Chain Integrity, Transparency and Trust group defines a receipt that travels with the credential, so that a verifier can check it without contacting the log.

Sensitive values masked​

The verifier learns that something exists, and what shape it has, without learning what it is.

In place of a confidential value the holder publishes a fingerprint of it: a hash, with a random salt mixed in so that the value cannot be recovered by trying likely candidates. Nobody can work backwards from the fingerprint to the value, and a counterparty who already knows the value can confirm that it matches.

The case driving this is supplier identity. An intermediate company will not publish its supplier list, but masking the names while still publishing the relationships lets a reader downstream see the shape of the chain, including how many tiers it has and which countries it passes through, without learning who any of the counterparties are.

What masking can and cannot do​

Masking buys the shape of the chain. It does not buy the ability to walk up it, and that limit is structural rather than a design problem waiting to be solved.

Each company salts its own records independently, so the same supplier appearing in two different companies' records produces two fingerprints that cannot be matched against each other. A reader following the chain cannot tell that two different routes have arrived at the same place. Restoring that ability means giving some single party the power to recognise every company across the whole chain, whether an auditor holding every salt or a service that every participant must use. That party would have to accumulate supplier relationships across borders, which data export rules in several countries prevent, and every supplier at every tier would have to trust it, including the many who have no relationship with the scheme asking for the data.

An auditor can reasonably hold the salts for the facilities it already assesses, so a reader can still be told when a path has reached a known and assessed facility. It is the chain in between that cannot be reconstructed.

The direction that does work is the other one. Where a claim travels downward with the material, carried by the transaction that moves it, there is nothing to walk up and no party needs that recognition power. That is why UNTP credentials are designed to be handed on with the goods rather than discovered by searching upstream, as described in Chain of Custody and Mass Balance.

One caveat on fingerprints. A fingerprint commits its publisher to a value, but nothing stops a publisher showing one fingerprint to one counterparty and a different fingerprint, over a different value, to another. For a masked identity that is self-defeating, because a counterparty who knows the real value will simply fail to match it. It matters where a fingerprint stands in for evidence that nobody else holds a copy of, which is why evidence bundles need the append-only log described above.

UNTP does not yet specify this pattern. Publishing a fingerprint is straightforward; the shape of a masked entry is under discussion in issue #848.

Evidence shared only with named parties​

The verifier receives the evidence itself, and the issuer decides who qualifies. Two mechanisms, both specified.

Encryption. The credential is encrypted and the key released only to those who may read it. Release can be conditioned on the requester proving who they are, for example by showing a Digital Identity Anchor matching a party to the transaction in question. Specified in Decentralised Access Control.

Variants. Instead of one credential with parts hidden, the issuer publishes several complete signed credentials, one per audience: a public version without supplier identities, a customer version with them, a regulator version with more again. The Identity Resolver returns whichever matches the requester. Specified in Variant-based disclosure.

An access role in a web link is a filter, not a lock. Anyone can type any role into a query string. Anything genuinely confidential is protected by encrypting it or by issuing a different signed variant, never by the role parameter on its own.

Choosing​

Start from what the verifier actually needs, rather than from what is technically possible.

If the verifier needs……and the holder can share…Use
A conclusion they can act onnothingAn auditor's attestation
To know a relationship existsits shape, but not the namesMasked values
The evidence itselfwith named parties onlyNamed-party sharing
The evidence itselffreelyPublish it

Three limits apply whichever is chosen.

A reader can follow a chain only as far as it has been disclosed. Someone assembling a transparency graph stops at the first participant they cannot read. How far upstream a chain can be read depends on how many companies have published and to whom, not on any single credential.

None of this proves that nothing was left out. Every pattern here shows that what was published is genuine and attributable to whoever published it. None of them detects a company quietly leaving a supplier out of its own records. That is inherent in voluntary disclosure and worth stating plainly: these patterns make dishonesty expensive and traceable, not impossible.

Completeness can still be bounded across a whole market. Totals recorded under a scheme, by commodity and period, can be compared against independently produced figures such as national production and trade statistics. More material recorded than a country produced is detectable without auditing any single participant, which catches widespread small over-claiming that no single-chain check can see. Described under aggregate reconciliation.