Perspectives

Как работи разпределеното доверие в регулирани сектори

Как работи разпределеното доверие в регулирани сектори

Regulated industries share a structural problem: the organisations that need to trust each other do not share infrastructure. A hospital and a pharmacy. A bank and a regulator. A manufacturer and a customs authority. Each operates within its own security perimeter, with its own identity systems, its own compliance requirements, and its own chain of command.

Distributed trust is the architecture that resolves this problem without requiring a central intermediary that all parties must depend on.

Why Centralised Trust Fails at Institutional Scale

Centralised trust models — where a single authority vouches for all participants — work within an organisation. Active Directory authenticates employees. OAuth tokens grant access to internal services. Certificate authorities vouch for server identities.

But when trust must span organisations, centralisation creates structural weaknesses. A single certificate authority becomes a single point of failure. A central identity provider becomes a dependency that all participants must trust — and a target that, if compromised, undermines every relationship in the system.

The Distributed Alternative

Distributed trust replaces the single authority with a mesh of bilateral trust relationships. Each organisation manages its own cryptographic identity. Trust is established peer-to-peer: Organisation A and Organisation B establish a trust relationship directly, based on verifiable credentials that each presents to the other.

This is the model behind Stargate, now deployed across Swiss healthcare. Each participating organisation runs its own Stargate node. Trust relationships are established bilaterally, anchored in DKMS (Decentralised Key Management System) and KERI (Key Event Receipt Infrastructure).

What Makes It Work in Practice

Three properties make distributed trust practical for regulated environments:

Auditability: Every trust relationship, every credential issuance, and every verification event is recorded in tamper-evident key event logs. Regulators can audit the complete history of any trust relationship without depending on a single party’s records.

Resilience: No single node’s failure brings down the network. If one organisation’s gateway goes offline, all other bilateral trust relationships continue to function. The network degrades gracefully rather than catastrophically.

Sovereignty: Each organisation retains control over its own identity and its own trust relationships. No external party can unilaterally revoke an organisation’s identity or alter its trust relationships.

The Healthcare Proof Point

The HIN deployment of Stargate across Swiss healthcare is the largest production proof of distributed trust in a regulated sector. Over 800,000 verified messages per month flow through a mesh of trust nodes connecting hospitals, GP offices, pharmacies, and laboratories.

What this proves is not theoretical. It proves that distributed trust can operate at the scale, reliability, and compliance standards that a national health system requires — without a central intermediary.

Beyond Healthcare

The trust architecture that makes this possible is not healthcare-specific. Any regulated sector that requires cross-institutional trust — finance, legal, government, supply chain — faces the same structural problem. The pattern is consistent: centralised infrastructure for what happens within an organisation, distributed trust for what happens between organisations.

Healthcare has now proven, at national scale, that this architecture works. The question for other regulated sectors is not whether distributed trust is viable — that question has been answered. The question is when they will adopt it.

Продължете да четете

Една година SEAL в продуктивна среда
Здравеопазване

Една година SEAL в продуктивна среда

В технологиите лансирането на продукт получава прессъобщение. Продукт, който работи тихо цяла година, получава нещо по-ценно: тишина. Нито един доклад за инцидент. Нито един спешен patch. Нито един пост „наясно сме с проблема“. Просто система, която прави това, за което е създадена, всеки ден, в мащаб, който непрекъснато расте. Преди една година HIN внедри SEAL […]

Прочетете повече →
Защо здравеопазването се нуждае от нов слой на доверие
Perspectives

Защо здравеопазването се нуждае от нов слой на доверие

Във философията има мисловен експеримент, наречен Корабът на Тезей. Ако замените всяка дъска на дървен кораб, една по една, той все още ли е същият кораб? Здравното IT прави свой собствен вариант на този експеримент от три десетилетия — заменя аналоговите компоненти с дигитални, парче по парче, приемайки, че основният модел на доверие ще издържи. […]

Прочетете повече →
Reverse Google: От имейл към децентрализация — FOSDEM 2026
Events
· ggreve

Reverse Google: От имейл към децентрализация — FOSDEM 2026

Резюме на презентацията: На 1 февруари 2026 г. Георг Грев представи „Reverse Google: From Email to Decentralisation” на FOSDEM в Брюксел (Track: Decentralised Communication, Room AW1.126). Презентацията аргументира, че имейлът — технологията, с която Google завладя глобалната идентичност през 2008 г. — е днес портата, през която обръщаме това завладяване и изграждаме доверие на edge-а. […]

Прочетете повече →

Верифицирана комуникация — изградена и внедрена, не само описана.

Инфраструктурата за доверие на Vereign работи в цялото швейцарско здравеопазване. Резервирайте 30-минутен архитектурен преглед, за да определите какво означава суверенна комуникация за вашата организация.

Швейцарска защита на данните GDPR съвместимост Open Source AGPLv3+ Швейцарски хостинг