Institutions issue identity
MID and MCID derive authority from accredited issuers. The terminal never crosses that line.
MSD trusted terminal branch
Mandate→Identity→Terminal→Evidence
A trusted terminal for carrying institution-issued MID and MCID into daily civic action: present identity, approve access, sign records, and recover control when a device is lost.
Care, Kids and One are role-specific access terminals: elder support, supervised credentials, and adult civic access. Three devices, one bounded trust architecture.
Once, the answer was a clay seal, a letter of introduction, a passport stamped in steel. Today the same question has moved into a digital world — and it needs to be answered there too. Meridian Special District — an institutional framework for identity and civic services in the digital age — gives the institutional answer; Meridian Phone is what takes that answer out of the archive and into a person's day. It does not invent identity. It only lets MID and MCID be used by an ordinary person, from morning to evening.
Public systems first recognise who a person is, before turning them into an account.
Trust comes from issuance, verification and audit, not from screenshots or platform promises.
Identity has to move from archive and backend into counters, schools, households and daily services.
The terminal carries the relationship; it does not own it. It presents qualification, not an entire life.
The harder edge of this question lies on the other side: every system of identity leaves someone out. People without a home, elders who cannot read, migrant workers, people with disabilities, the stateless — those who most need to be recognised are the ones a form, a QR code or a login screen most easily turns away. A digital identity worth trusting has to begin by acknowledging who is being left out; a device that hopes to hold it has to keep a door open for them from the start.
This is also why — in an age where almost everything has become software, and almost nothing is held in the hand — there still has to be an object you can hold. When relationships dissolve entirely into code, they become easy to copy, easy to revoke, easy to forget. An object held in the hand is itself a kind of restraint: it reminds everyone that an identity is not a line of data, but a living person, present.
For a decade, digital identity has lived inside databases, not inside lives. To use their own identity, a person has had to log into someone else's product.
When identity can be carried properly on a personal device, it stops being just an account — it becomes a form of recognised membership. A person no longer logs into someone else's product to be themselves; they walk into a place already carrying who they are.
A phone never issues identity. It is only the trusted container — what lets an already-issued identity be carried, presented and, when needed, set down again.
Verifiers trust credentials, not screens. Holders present a single qualification — they do not hand over a whole file. Each use leaves a trace of being trusted, not a trace of being exposed.
This boundary is where Meridian Phone becomes willing to be examined, by a government, with care. It is written into the hardware and into the institution. Three lines of commitment, three lines of restraint — a device worth being entrusted with has to say both, clearly.
The terminal receives and presents credentials; it never becomes the issuer.
Carry, verify and recover are bounded device functions, not a new identity regime.
No source-data exposure, no medical claim, no uncontrolled expansion beyond mandate.
A family is more than one relationship. A person grows old; a child grows up; an adult, in between, holds up both ends. We have made three devices, so that the three generations of a household can be held by the same institution of trust — gently. Elders are looked after. Children are accompanied. Adults are entrusted with the day. They share one identity system underneath, and each one focuses on doing only one thing properly.
Care is not a large-font phone. It is an access terminal for elders: family authorization, emergency support, assisted service entry and a simpler civic console, all bounded so help can arrive without taking dignity away.
Kids is not a smaller adult phone. It carries parent-derived sub-credentials for school, transit and learning, while institutional issuance stays separate and family use remains supervised.
One carries MID and MCID for adult civic life: identity proof, verified acceptance, business services and recovery on one trusted terminal.
Three procurement tiers, not a consumer price ladder. They correspond to three positions inside a household: a child's entry, an adult's anchor, an elder's relationship of care. A family can walk all the way up that ladder — three generations, one same set of trusted relations.
Identity is not something that happens once. It has a life of its own — applied for, verified, issued, used through the years, sometimes lost and recovered, finally set down when it is no longer needed. Six stages, four kinds of participant. Meridian Phone is deliberately not an issuance authority on this path; it does only four things — carry, assist, record, protect. That restraint is itself the reason a government can examine it with care.
Conventional phrase-based recovery has shown the weakness: when a remembered string becomes the only way back, a simple loss can become a permanent lockout. Meridian Phone uses an MPC threshold scheme that splits signing authority across the device, a custodian and a guardian: no one party can act alone, and no single loss is fatal. Identity access is no longer held inside a cold line of text; it is entrusted to a small, human-shaped network of people who know the holder.
And more importantly: access capability is not the identity. It is only a capability MID can open, at a later, regulated stage — identity first, settlement second; relationship first, sums of money afterward.
For governments and institutions, trust should not rest on vendor promises. It should rest on reviewable boundaries, verifiable device state, recoverable access processes and service traces that do not overreach.
The source, authorization chain and revocation authority of MID / MCID remain with the issuer; the terminal records carrying state only.
TEE, SE, device posture and controlled application versions form terminal evidence that can be verified.
New-device pairing, guardian participation and re-verification steps leave a traceable audit path.
Each acceptance event keeps necessary proof, timestamp and signature only; source identity material is not made public.
Behind every civic or commercial acceptance moment — breakfast in a quiet town, a prescription at a clinic, a contract signed in an office — there is already a relationship: who is present, who is authorized, who vouches for whom. For a decade we have compressed that relationship behind a QR code. Meridian Phone wants to put it back. When MID and MCID are both present, a service moment no longer has to begin from "who you are, who I am" — trust returns to the counter between people.
The service party's MCID and the citizen's MID present proof at the same time: who is present, which desk is acting, who carries authority — every link signed.
The holder presents only the qualification the service moment requires — "of legal age," "licensed to sell" — without handing over any of the surrounding personal data.
Phase 1 does not open a public external transfer path. Settlement runs through regulated rails. A settlement proof is recorded to the Meridian evidence layer.
Event hashes, timestamps and signed records are anchored to the memory layer — independently verifiable during compliance review.
A chip. A process. An audit. Trust, on a phone, has never come from a slogan — it has to come from those three places. Meridian Phone writes the trustworthy parts into hardware, the reviewable parts into procedure, and keeps what does not belong on a personal phone inside controlled environments. Only when all three stand up does a device deserve the word entrusted.
Critical operations run inside a Trusted Execution Environment; credential keys live in a Secure Element — untouchable by regular apps and unreachable across OS boundaries.
No raw fingerprint or face image is stored — only a revocable, regenerable protected representation. A lost phone is not a leaked biometric.
Cloning, replay, downgrade and supply-chain implantation each map to specific hardware, protocol or institutional controls — documented in the threat model.
Where identity data lives, where keys live, where biometric representations live, and what may enter the evidence layer all need clear answers. Meridian Phone separates those answers into four boundaries so privacy, institutional responsibility and audit evidence remain in their proper place.
Keys and credentials are bound to the TEE + SE device structure. Regular apps may request a result; they cannot read the root material.
Biometrics do not leave as raw images. They remain as protected, revocable and regenerable representations generated locally.
Recovery, migration and revocation do not depend on one administrator. Sensitive actions require multiple authorisations.
The evidence layer records status, signatures and audit trails without moving private personal data into public records or third-party systems.
BOM, security baseline and threat model are signed off before manufacturing — and made available to independent third-party review from the design stage.
Secure elements are pre-provisioned on a controlled line; every device can be traced back to its origin — supply-chain tampering has an answer.
Every update is signed; the path from a vulnerability being discovered to being patched is on a public timeline, not in silence.
When a device retires, credentials are securely destroyed and the hardware is recycled — no debris, and no forgotten keys.
The operator and the institution each carry their own share of responsibility. If anything goes wrong, somebody has signed for it.
For a phone to be trusted by verifiers anywhere, it has to speak the international language of identity and authentication. That language is not set by any one company. It has been slowly agreed — by W3C, FIDO, ISO, by many nations and many researchers, working alongside each other — and it belongs to this age, and to everyone who lives in it. Meridian Phone aligns with the standards below, so that credentials, authentication and interoperability are never locked to a single vendor.
Meridian Phone separates identity identifiers, credential models, device authentication and assurance levels into four rails. Each rail points to existing international specifications, preventing public identity infrastructure from being locked inside one vendor or one jurisdictional technology island.
W3C DID / VC define who issues, who receives, what is proven and how selective disclosure works.
FIDO2 / WebAuthn bind critical access to hardware and local presence, rather than passwords or SMS codes.
ISO 18013-5 and related mobile credential standards support counter, offline and regulatory verification.
NIST IAL / AAL / FAL and EUDI alignment help different services map to different verification strengths.
The identifier and resolution model shared by subjects and issuers.
Signed, structured credentials supporting selective disclosure.
Device-bound strong authentication; biometrics never leave the device.
Identity and VC transport protocols for third-party services.
Mobile driver's license and similar credentials, including offline use.
Protected, revocable biometric representations — no raw templates.
The EU's official framework — a long-term alignment path.
IAL / AAL / FAL tiers — services map to required verification strength.
Pilot-stage device tiers are not a retail catalogue. Inside any specific jurisdiction, the framework is localised, subsidised, and reduced — whether an identity institution has reached those most easily left out is not finally a matter of language, but of a procurement schedule and a reductions table. Here is what that framework usually becomes, in practice.
In each partner jurisdiction, final pricing is determined together with the accredited issuer — not imposed as a global flat rate. A device made to be used in a particular place should be made affordable in that particular place.
For people without a home, elders who cannot read, migrant workers, people with disabilities and the stateless, a tiered reductions schedule and accessibility configurations are kept open — whether an identity system can be trusted depends, first, on whether it leaves a door open for these people.
Bulk procurement channels for civic, education, health and social-security systems are aligned with each jurisdiction's budgets and intergenerational programmes. Care, in partner jurisdictions, can be folded into elder-care programmes — shared across government, family and philanthropy.
The tier labels are not retail prices. They are the starting point of a procurement conversation. In each partner jurisdiction, the subsidy model, procurement framework and reductions schedule are decided together with the issuer and the government — and written into a contract both sides can refer back to.
If an identity terminal only serves people who are already easy to serve, it is not public infrastructure. Meridian Phone's localisation framework puts procurement, reductions, accessibility and public-service entry points onto the same institutional table, so every jurisdiction can state who is covered first, who receives reductions, who provides service and who retains final governance authority.
Reviewable terms shaped by local budget, currency, service scope and issuer responsibility.
Reserved pathways for people without a fixed address, elders, disabled people, stateless people and low-income groups.
Voice, magnification, high contrast, one-handed use and assisted counter flows become deployment requirements.
Education, health, social security, care institutions and civic counters define the first acceptance scenarios.
Meridian Phone should not, either. We prefer to begin inside a single, well-defined pilot jurisdiction — in that one city, make identity, verified acceptance, the civic console and the recovery mechanism actually work; let an institution take root, slowly, inside a real set of relationships. Only when it is steady, talk about the next city. A thing made with care deserves to be allowed to be slow. The first city is never a test market; it is a partner — and the patience of a jurisdiction willing to be first is where this whole thing earns its right to be trusted.
Identify the issuer, signing process, Path A boundary and pilot review packet. Hardware BOM, security baseline and threat model are signed off before manufacturing.
The standard citizen variant first. MID carry, verified acceptance, civic console and baseline audit run end-to-end — validating the underlying design.
Extend to elder and child editions on the same system. Family authorization, guardian recovery and derived sub-credentials open in sequence.
Inter-recognition with other jurisdictions on the same standards. Settlement and additional services become regulated extensions, not preconditions.
Every phase corresponds to a set of controls already in place — boundary before feature, audit before scale, trust before expansion. It is a slowness, and it is also the patience required to make something worthy of being trusted.
Before deployment, each partner jurisdiction should complete four reviews: institutional authority, device evidence, service acceptance and public protection. That makes the pilot a public institution started responsibly, not a market experiment.
Define the issuer, signing authority, revocation power, operating boundary and the sovereign position retained by government.
Complete the hardware BOM, security baseline, supply-chain traceability and independent review materials.
Select the first civic and service scenarios, and define how counters, businesses, schools or care institutions verify credentials.
Set appeal, revocation, recovery, reductions, accessibility and vulnerable-group access before expanding functionality.
A real pilot review should let every mandate, evidence record, acceptance scenario and public safeguard be traced on the same table. Meridian Phone therefore enters society only where the institution can see it, question it, pause it and govern it.
Issuer, signing authority, revocation power, operating boundary and powers retained by government.
Hardware list, security baseline, key boundary, production batch and independent review.
Verification and audit flows for the first civic, counter, school, health or care scenarios.
Appeal, recovery, revocation, reductions, accessibility and vulnerable-group access.
This section is written for government reviewers and procurement partners. The easier misreadings are addressed first — so the harder discussions can be about substance. An institution that welcomes being questioned first, and discussed afterward, has begun to deserve the trust it asks for.
No. The phone does not issue MID or MCID. Issuance authority remains with accredited bodies. The device carries, assists, records and protects.
No. Care offers companionship and advisory prompts (fall alerts, medication reminders) — no diagnosis, treatment or prescription. Medical compliance belongs on dedicated devices.
From a parent-derived sub-credential under explicit parental authorization — not issued directly by a school. This stays within Path A.
No. With MPC threshold signing, no single share of the key can act alone. Through guardian and re-verification flows, access is restored on a new device.
No. Only verifiable proofs — hashes, status and timestamps — are anchored to the evidence layer. Source identity material stays inside controlled environments and can be deleted when required.
Jurisdictions with clear digital identity legislation, an accredited issuer and a willingness to adopt open standards (W3C, FIDO, ISO).
Because identity is not only a sign-in step; it needs a trusted hardware root. An app can be uninstalled, replaced, screenshotted; a device made with care can hold the boundary at the hardware level (TEE + SE), so that "carrying an identity" is no longer just a software promise — it becomes a fact of physical structure.
Complementary, not exclusive. Apple's credential container is a commercial ticket and credential surface; EUDI is the EU's official digital identity framework; Meridian Phone is a device aligned with W3C, FIDO and ISO standards, and is designed to interoperate with relevant frameworks in jurisdictions where it operates — not locking out, not replacing, and not pretending to solve what they were never meant to solve.
Meridian Phone's maturity is not only a matter of interface or hardware form. It rests on putting product boundaries, technical basis, pilot conditions and retained government authority on the same review surface.
Authority over MID / MCID stays with issuers. The terminal only holds, presents, approves and recovers access.
TEE + SE, W3C DID/VC, FIDO2, ISO 18013-5 and MPC threshold recovery form the review basis.
Legal authority, device evidence, service acceptance and public protection gates precede scale.
The adopting jurisdiction keeps final governance authority; operator, supplier and issuer duties are written into agreement.
Whether a digital age is worth looking forward to has less to do with how fast it runs than with whether it can gently carry an ordinary person — whether it can keep an elder from facing a new age alone; whether the first piece of identity a child ever holds can be one looked after with care; whether an adult can put the few most important things of a day onto a single device worth trusting. Meridian Phone does not try to replace institutions, and it does not try to replace trust. It only wants to be the thing of this age — a place where a relationship that has already been recognised can be carried, gracefully and safely and across generations, into a single person's hand.