Protocol
Who issues an identity in a network nobody owns
Authenticating, activating and signing are three different acts. The harder question is who is allowed to issue an identity, and what happens when the issuer
An identity in a network nobody owns rests on whoever is allowed to issue it. Three acts get confused: authenticating proves you hold an identity, activating turns it on once, signing produces something a third party accepts as yours. Portugal separates all three in the Chave Móvel Digital, a state-issued credential used to authenticate, activate and sign.
Authenticating, activating, signing: three acts, not one
Authenticating answers a single question: are you the holder of this identity, right now? The answer is a proof, valid for the moment it is given, and it says nothing about what the identity is for. Activating is a different operation. It happens once, it binds the identity to a place where its holder can be reached, and it is the step that turns a record into something usable. Signing is a third act again: it produces an artefact that survives the session, travels without its author, and is meant to be checked later by someone who was not there.
Confusing them produces predictable failures. A system that treats a successful authentication as a signature will accept a proof of presence where a durable commitment was required. A system that treats activation as authentication will let a one-time enrolment stand in for an ongoing claim. In XMPP the same separation holds. A client authenticates to a server, a resource is bound once per session, and a message stanza carries the author's address, not a signature. The protocol never pretends the three are the same thing.
Which body is entitled to issue an identity?
This is the question underneath the other three, and it is not technical. An issuer is a body that a community has agreed to accept, and that agreement is what gives the credential its weight. A domain name registrar, a certificate authority, a national agency: each is an issuer because others have decided to check its output. Nothing in the mathematics of a key pair says who may generate one on your behalf.
Delegation is the mechanism that keeps this manageable. An issuer rarely acts alone; it acts under a mandate, granted by a law, a contract or a technical policy, and the mandate defines the scope. When the mandate is withdrawn or transferred, the credential does not become false. It becomes unverifiable, which is worse, because it still looks valid to anyone who has not heard the news.
What is the Chave Móvel Digital and what is it used for?
The Chave Móvel Digital is a Portuguese credential that lets its holder authenticate to public services, activate access to them, and sign documents in a way a third party can verify. The three acts are distinct in its design, and a public body stands behind each one. It is worth reading as a worked example of a state acting as an identity issuer: the credential is only as solid as the body that issues it, in the same way a JID is only as solid as the domain that owns it. If the domain lapses, the address keeps its shape and loses its meaning. If the issuer changes, the credential keeps its shape and loses its guarantor.
Which agencies and public policies built the digital state?
The Portuguese digital state was assembled in layers, and the layers have dates. The Unidade de Missão Inovação e Conhecimento was succeeded in 2005 by the UMIC, an agency charged with coordinating information society policy, which operated until 2012. On 1 March 2012 the FCT took over that coordination, and the UMIC archive was integrated into the Arquivo de Ciência e Tecnologia. Earlier still, the Unidade Acesso was created in 1999, and the Rede Solidária, created in April 2001, counted 240 organisations by the end of 2004.
Connectivity came through separate programmes: RCTS from 1997, e-U Campus Virtual with 57 institutions in 2005 and more than 5 000 access points, broadband in every public school by January 2006, and the Plano Tecnológico da Educação in 2007. Accessibility has its own paper trail, including the Portuguese translation of WCAG 2.0 published on 25 February 2009. None of these layers was designed as a single system. They accumulated, and each one left an issuer behind.
How is the internet governed?
The layer above the technical one is where the rules that everyone else implements are argued out. No single body owns the network, so governance happens in forums: the Internet Governance Forum, the Commission on Science and Technology for Development at the United Nations, and the process that ran from the World Summit on the Information Society in 2005. What is settled there is not how a packet is routed but who may decide, who is consulted, and how a decision is reviewed.
This is also where the identity question returns in institutional form. If a state issues credentials, if a registry issues names, if a forum issues policy, each is an issuer operating under a mandate that someone else granted. The argument over who grants those mandates has been running since 2005, and it has not converged. The technical specifications are stable by comparison.
What happens when the issuer changes
An issuer can be extinguished, merged or replaced, and the credential it issued does not disappear with it. It remains in circulation, held by people who activated it, presented to systems that were built to accept it. The practical question is continuity: who inherits the mandate, who can still verify what was issued, and who tells the holders that the answer has changed.
History offers the pattern. An agency coordinates a policy for seven years, the mandate moves to another body, and the archive moves with it. The documents survive; the authority does not. For anyone holding a credential, that is the part worth understanding before the first authentication, because the strength of an identity is never in the identity itself. It is in the issuer, and in the agreement that keeps the issuer recognised.