Public key infrastructure (PKI)
PKI is the system of asymmetric cryptography, certificates and certificate authorities (CAs) that makes digital trust scale. Everyone has a key pair: the private key signs or decrypts, the public key verifies or encrypts. A CA binds a public key to an identity by issuing a certificate; relying parties trust the CA (chain) rather than each individual key.
All eIDAS trust services are built on PKI: certificates, signatures, seals, timestamps and revocation checking (CRL/OCSP). A QTSP is, at its core, a strictly supervised CA with certified processes and HSMs.