A CA with one or more trusted certificates containing public keys that exist at the base of a tree of trust or as the strongest link in a chain of trust and upon which a Public Key Infrastructure is constructed.
“Trust anchor” also refers to the certificate of this CA.
Sources:
NIST SP 800-152
under Trust anchor
An authoritative entity represented by a public key and associated data (see RFC 5914).
Sources:
NIST SP 800-57 Part 2 Rev.1
under Trust anchor
1. An authoritative entity for which trust is assumed. In a PKI, a trust anchor is a certification authority, which is represented by a certificate that is used to verify the signature on a certificate issued by that trust-anchor. The security of the validation process depends upon the authenticity and integrity of the trust anchor’s certificate. Trust anchor certificates are often distributed as self-signed certificates. 2. The self-signed public key certificate of a trusted CA.
Sources:
NIST SP 800-57 Part 1 Rev. 5
under Trust anchor
A public or symmetric key that is trusted because it is built directly into hardware or software or securely provisioned via out-of-band means rather than because it is vouched for by another trusted entity (e.g., in a public-key certificate). A trust anchor may have name or policy constraints that limit its scope.
Sources:
NIST SP 800-63-4
[
NIST SP 800-63A-4
[
The key for a certificate authority who issues certificates or authorizes others to do so on its behalf
Sources:
NISTIR 7682
under Trust anchor