ToIP Trust Spanning Protocol (TSP) transport binding for the Trust Tasks framework.
Wraps affinidi-tsp so a Trust Task
document can ride as the authenticated, encrypted payload of a TSP message —
sealed with HPKE authenticated encryption and signed from the producer's
Verifiable Identifier (VID) to the recipient's VID. On unwrap, the
authenticated sender VID becomes the framework's transport-authenticated
sender for SPEC §4.8.1 precedence.
Binding URI
https://trusttasks.org/binding/tsp/0.1
Wire shape
The TSP message payload (the plaintext TSP seals) is the JSON serialisation of the binding envelope object:
Unlike the DIDComm binding — which normalises a sender_kid to its bare DID —
a TSP VID is the framework VID, so no transformation is applied: the
authenticated VID_sndr is surfaced verbatim as the transport-authenticated
issuer. TSP has no anonymous/unauthenticated sender mode, so every envelope
this binding accepts carries a verified sender.
The producer can ship a plain Direct message ([pack_trust_task], sealed
straight to the consumer) or, for metadata privacy, wrap that Direct message in
an outer Nested envelope sealed to an intermediary
([pack_trust_task_nested], SPEC binding §5). Routed/Nested relaying — where
the messaging mediator unwraps its outer layer and forwards the sealed inner —
is the mediator's job on the wire; the consumer always opens the innermost
Direct message, which [unpack_trust_task] handles regardless of how it was
carried.
Sketch
use PrivateVid;
use ;
// alice (producer) seals a document for bob:
let wire = pack_trust_task?;
// bob (consumer) opens it (alice's VID resolved for verification):
let = ?;