It would be nice if there were identity providers that could vend attribute certificates with no PII besides the desired attributes, such as:
- is_human
- is_over_18
- is_over_21
- is_over_65
- sex/gender?
- marital status?
- ...?
- device_number (e.g., you
might be allowed N<4 user
attribute certs, one per-
device)
and naturally the issuer would be the provider.The issuer would have to keep track of how many extant certificates any given customer has and revoke old ones when the customer wants new ones due to device loss or whatever.
Any company that has widespread physical presence could provide these. UPS, FedEx, grocery stores, USPS, etc.
European eID solutions can do some of those (e.g. is over 18). Let's see if usage becomes more wide-spread.