This design eliminates dependence on centralized registries for identifiers as well as centralized certificate authorities for key management—the standard pattern in hierarchical PKI (public key infrastructure). Because DIDs reside on a distributed ledger, each entity may serve as its own root authority—an architecture referred to as DPKI (decentralized PKI).
"Because DIDs reside on a distributed ledger" What is a DID? If a DID is a character string identifier, then it doesn't live on the the ledger, the DID Document lives on the ledger. See the following diagram...
In https://w3c-ccg.github.io/did-spec/#overview, it states....
Hyperledger Indy/Sovrin Comprehensive Architecture Reference Model (INDY ARM) - latest version - bullets (12) thru (16) in both the diagram, Narration, and principles.
Reword/clarify (here and throughout the draft specification).