Well, in Estonia, they have a different approach. 1. If you are a citizen or a resident, you get an ID card to use for every public service. It's just a smart card with a government PKI. 2. The public services provide an email account that can only be used within the e-government services. The card is used for accessing those services. 3. The email service accepts either identity number or registry number of the reci…
> If you are a citizen or a resident, you get an ID card to use for every public service. It's just a smart card with a government PKI. This is the biggest flaw in the design. Tying the ID card to a single identity. If you're using it with a bank, it needs to be tied to your bank account. If you're using it for physical access control at your company's building, it needs to be tied to your employee account. These are…
No, it's solid design. It's a very simple safe primitive. You can build endless infrastructure on top of it. Similar to subkeys.
For example a lot of businesses use Smart-ID on top of that. You need to tie the smartid stuff to your PKI identity. But after that you can just use that as identity.