Draft proposal · No agreement in place · Nothing has been awarded
wsu.life · Node three · A proposal to the Utah Board of Higher Education
Two-thirds of Weber State's associate-degree earners come back within a year for another credential and every one of them pays a cost in time to prove something already true.
Weber State is also the third node, built from the published specification alone
the only real test of whether any of this is reusable.
Weber State University brings the problem and the test. Two-thirds of its associate-degree earners return within a year for another credential and pay a cost in time to prove what is already true. Weber State comes online third, built from the published specification alone with no hands-on help — the only real test of whether any of this is reusable. It issues from its own keys and cannot read what any other institution issued.
Proposed subaward: $330,000. No agreement exists and nothing has been awarded.
Start here. The rest of this page is how it works and who controls it which matters, but this is what it is for.
A landlord who needs to know you are enrolled receives enrolled: yes. Not your transcript, not your address history. The rest never leaves your phone.
Tuition, lunch, a parking pass, a campus paycheck. Today a $3,000 tuition payment by card costs around $88 in fees. Here it costs nothing.
A professor's recommendation, held by you signed, verifiable, reusable. It does not expire when they change jobs.
Projects finished, hours served, skills demonstrated — all portable, all yours. No rating, no rank, no leaderboard.
Enrollment forms, housing leases, work agreements. Proof of who signed and exactly what they signed, held by both parties.
Certificates, degrees, competencies verified in seconds without anyone phoning a registrar.
Campus messaging, groups, and mail on open protocols, on infrastructure your own university operates. Nobody is mining it.
No standing access to anything. When it needs authority it asks for exactly one thing, for one purpose, expiring, revocable with one tap.
Everything you use today works the same way. Some company or some office holds your record, and lets you look at it. Your grades, your money, your signature, your messages. You are the subject of the file, not the owner of it.
That arrangement is not a law of nature. It is a design choice, made when there was no cheap way to prove something was true without a trusted middle. There is now.
A key is the thing only you have, that proves something came from you. A node is the place an institution keeps its own keys, so no single school and no single company sits in the middle of everyone else. That is the entire mechanism.
Not decentralized instead of centralized. Decentralized authority, pointed at a centralized model. The model becomes a tool you aim — it stops being a party you are exposed to.
Weber State does two things no other partner can. It supplies the problem this project is trying to solve, stated in its own data. And it is the independent test of whether any of this is reusable. Every one of those returning students pays a friction cost to prove what they have already earned — that cost is measurable, and reducing it is the project's clearest dollar-denominated outcome.
Credentials awarded by Weber State in 2024–2025
Of them certificates
Associate-degree earners return within a year
Tested reference implementations at population scale today
Everything on this page rests on one small piece of machinery: the keys that prove a record is yours. Four questions every person actually asks - where keys come from, what happens when one is stolen, what happens when a phone is lost, and how an assistant can use any of this without learning who you are.
One secret on your device quietly produces a separate key for every place you use it. Nobody can connect them.
Retire a key and name its successor without changing who you are on the network.
A lost phone is an inconvenience not the loss of your degree, your money, or your history.
Your own directed intelligence uses a large model without ever handing it who you are.
Shown to the registrar
Shown to campus merchants
Shown to a counterparty
Shown to the comms server
Derivation runs one direction. A key can be produced from the root, but the root cannot be worked backward out of a key. Because each party is handed a different key, two of them comparing notes learn nothing: the registrar and the campus store hold values that look unrelated. This is what an automated system cannot follow. A platform, or a model, that sees your key at one place and your key at another has no mathematical way to know they belong to the same person. There is nothing to stitch. You do not memorize any of this and you never type a key.
Each entry in your record does two jobs. It signs with the key in force at that moment, and it seals a fingerprint of the key that will come next. The successor is committed before it is ever used, so a thief who takes today's key still cannot name tomorrow's. Rotating is a normal event in the log, not a new account.
A verifier replays this log from the beginning. It accepts a signature only if the key was in force at the sequence number where the signature was made.
Not one of these nodes can read your record. They hold a signed log and confirm what order it happened in. No node can issue a key. Only your root can.
Public, or private and non public
This is the difference between directed digital intelligence and artificial intelligence in one picture. Yours runs on your device, reads your record locally, and decides how little to ask. Theirs is very good at language and reasoning, and it gets exactly one scoped grant, under a key that was made for this request and will never be used again. When the grant expires the model holds nothing it could use to find you, and the next request arrives under a different key it has never seen. Public model or private one, the boundary is the same. You direct yours. Theirs hires theirs.
Rotation retires the old key in the same record that names the new one. The theft becomes a dated line in your history instead of the end of it.
The log says which key was in force when, so a transcript signed two years ago still verifies after four rotations. No re- issuance, no fees.
Your university can issue a credential and witness your log. It cannot rotate your keys or sign in your place and neither can the company that built this.
Every request rides a key made for that request and never used again. Two requests share nothing a model could use to connect them.
The institutions are peers not branches of a platform. Each can revoke only what it issued, and none can read the others.
Everything is engineered and hosted from the Canopy campus in Lindon - the reference node, the witnesses, the hosting, the engineering. The keys are not. The standard in the middle is public and belongs to nobody; the keys stay with each university. Take the base away and the standard still exists and the keys still work.
Its own keys in its own hardware, its own issuance policy, its own revocation registry. It can revoke what it issued and nothing else. No node can issue on another node's authority or read another node's records.
In a wallet on their device. They choose what to present and to whom, one attribute at a time. Custodial recovery exists and is opt-in and separable - not a back door held by anyone by default.
KERI and ACDC for keys and authentic chained data, W3C Verifiable Credentials for format, OpenID4VP for presentation. The conformance suite is published open source so the state can check any vendor's claim - including ours.
There is no central database of who holds what, and nobody can list who verified what. A wallet that is a view onto someone else's server is not a wallet.
Students pay no fee, no surcharge, and no basis point, and nothing may be passed through to them. The institution pays nothing per transaction either. There is no revenue share anywhere in this model. Earlier drafts of the campus proposal carried a one percent fee on rewards and stored value split between the provider and the university; it has been removed.
Two things make zero credible rather than a slogan. This institution can run its own node, because the specification and conformance suite are published open source – hosting is a convenience, not a lock. And the keys stay here whether it self-hosts or subscribes, so buying hosting never means handing over authority.
Every one is a real transaction with a real current cost - which is what makes the measurement meaningful.
Funded inside the awards where the application says so, gated by counsel where noted.
Not in either application - listed so the roadmap is visible and the scope is honest.
Credential issuance, verification, portability, a conformance suite, trust framework, and adversarial security research.
A pro-human AI agent bound to student-held credentials, with scoped delegation, a consent ledger, and measurement of human agency.
The proposal states that both applications include a cost crosswalk so no person, equipment item, or cost line is charged twice.
An additional $3.5 million in cost share is offered; its schedule is incomplete.