10 UK digital identity entry points · 8 identity priorities · 6 DEFONEOS MCPs · GOV.UK One Login / UK DIATF / GDPR backbone
UK digital identity infrastructure is undergoing its largest transformation since the introduction of passports. The GOV.UK One Login programme is consolidating 200+ separate departmental login systems into a single citizen identity layer serving 65M+ UK residents. The UK Digital Identity & Attributes Trust Framework (UK DIATF) — now statutory under the 2026 Digital Identity & Attributes Act — establishes the legal equivalence of digital and physical identity for the first time. GOV.UK Verify's successor, the Home Office Identity Document Validation Technology (IDVT) framework, and the OIX (Open Identity Exchange) trust scheme operate alongside eIDAS 2.0 cross-border identity requirements.
DEFONEOS delivers the UK's first open-source Sovereign Public Services OS purpose-built for digital identity and trust services: GOV.UK One Login integration, UK DIATF certified provider readiness, eIDAS 2.0 cross-border Qualified Trust Service compliance, GDPR Article 25 data protection by design, and BFT-governed identity attestation — all on a 33-agent Ed25519-signed sovereign substrate.
All entries are BFT-signed (Ed25519 / RFC 8032 / 2026-Q3 rotation) and curl-verifiable. Per-entry contacts sourced from GDS GOV.UK One Login programme (2026-Q1) + DSIT Digital Identity Strategy 2026 + Home Office IDVT framework 2026.
| # | Entry point | Location | Identity function | DEFONEOS fit |
|---|---|---|---|---|
| I1 | GDS — GOV.UK One Login Programme | London | National citizen identity · 200+ service consolidation | DEFONEOS MCPs: sovereign-keystore · bft-council-probe — Ed25519 citizen attestation + BFT identity governance |
| I2 | DSIT — Digital Identity Policy | London (Whitehall) | UK DIATF statutory framework · strategy | DEFONEOS MCPs: bft-council-probe · sovereign-keystore — DIATF certified provider + BFT trust framework |
| I3 | Home Office — IDVT Framework | London (Croydon) | Right-to-work · right-to-rent · DBS digital ID | DEFONEOS MCPs: sovereign-keystore · bft-council-probe — IDVT certified identity verification + BFT audit |
| I4 | HMRC — Identity Assurance | Tyneside / London | Tax identity · Government Gateway successor | DEFONEOS MCPs: sovereign-keystore · bft-council-probe — HMRC identity attestation + BFT tax governance |
| I5 | NHS — NHS Login / NHS App | Leeds | Patient identity · 33M+ users · health records | DEFONEOS MCPs: sovereign-keystore · bft-council-probe — NHS patient identity + BFT health record governance |
| I6 | Passport Office — Digital Passport | London / Belfast / Glasgow | UK passport · biometric passport · ePassport gates | DEFONEOS MCPs: sovereign-keystore · bft-council-probe — biometric passport attestation + BFT border trust |
| I7 | DVLA — Driving Licence Digital | Swansea | UK driving licence · digital counterpart · identity proof | DEFONEOS MCPs: sovereign-keystore · bft-council-probe — DVLA licence attestation + BFT identity verification |
| I8 | OIX (Open Identity Exchange) | London | Industry trust scheme · cross-sector identity | DEFONEOS MCPs: bft-council-probe · mcp-dynamic-sbom — OIX trust scheme + BFT interoperability audit |
| I9 | ICO — Identity & Biometrics | Wilmslow | Biometric data regulation · Special Category Data | DEFONEOS MCPs: mcp-dynamic-sbom · bft-council-probe — biometric DPIA + BFT biometric governance |
| I10 | Cabinet Office — Trust Services | London (Whitehall) | eIDAS 2.0 · Qualified Trust Services · e-signatures | DEFONEOS MCPs: sovereign-keystore · bft-council-probe — eIDAS Qualified Trust Service + BFT signature governance |
| # | Identity priority | Owning body | DEFONEOS MCP coverage | Alignment cross-walk |
|---|---|---|---|---|
| ID1 | GOV.UK One Login integration | GDS | sovereign-keystore · bft-council-probe | GOV.UK One Login design system · GDS Service Standard · 200+ service migration |
| ID2 | UK DIATF certified provider | DSIT | sovereign-keystore · bft-council-probe | UK DIATF · Digital Identity Act 2026 · DSIT certification |
| ID3 | IDVT right-to-work / right-to-rent | Home Office | sovereign-keystore · bft-council-probe | Home Office IDVT framework · DBS digital identity · Right to Work 2026 |
| ID4 | eIDAS 2.0 cross-border identity | Cabinet Office | sovereign-keystore · bft-council-probe | eIDAS 2.0 · EUDI Wallet · UK-EU adequacy · Qualified Trust Services |
| ID5 | GDPR biometric data protection | ICO | mcp-dynamic-sbom · bft-council-probe | UK GDPR Art 9 · Special Category Data · Biometric DPIA |
| ID6 | Decentralised identity (DID / VCs) | OIX / W3C | sovereign-keystore · bft-council-probe | W3C DID · Verifiable Credentials · OIX trust scheme |
| ID7 | Zero-trust identity architecture | NCSC / GDS | sovereign-keystore · mcp-cspm | NCSC Zero Trust Principles · GDS Service Standard v2 |
| ID8 | Identity fraud prevention | Home Office / Action Fraud | sovereign-keystore · bft-council-probe | Action Fraud · Home Office fraud strategy · Document fraud detection |
| # | MCP | Category | Identity deployment | Key capability |
|---|---|---|---|---|
| M1 | sovereign-keystore | Identity | All 10 identity entry points | Ed25519 key management · citizen attestation · BFT-governed identity signing |
| M2 | bft-council-probe | Core | All identity governance decisions | 33-agent BFT defence council · quorum-gated identity decisions · Ed25519 audit trail |
| M3 | mcp-dynamic-sbom | Supply Chain | Identity software supply chain | Dynamic SBOM generation · biometric system provenance · ICO DPIA-ready |
| M4 | mcp-cspm | Security | Identity infrastructure · cloud posture | Cloud security posture · zero-trust identity audit · NCSC principles |
| M5 | companies-house-mcp | Data | Corporate identity verification | Companies House director verification · PSC checks · KYC integration |
| M6 | data-gov-uk-mcp | Data | Public sector identity registers | Electoral register · GP register · HMRC records · cross-government identity |
| Identity Component | Role | DEFONEOS integration | MCP coverage |
|---|---|---|---|
| GOV.UK One Login | National citizen identity · 200+ services | Ed25519 citizen attestation + BFT identity governance | sovereign-keystore · bft-council-probe |
| UK DIATF Trust Framework | Certified identity providers · legal equivalence | DIATF certified provider + BFT trust framework audit | sovereign-keystore · bft-council-probe |
| Home Office IDVT | Right-to-work / rent / DBS digital | IDVT certified verification + BFT audit trail | sovereign-keystore · bft-council-probe |
| ICO Biometric DPIA | Special Category Data protection | Biometric DPIA + BFT biometric governance | mcp-dynamic-sbom · bft-council-probe |
| eIDAS 2.0 QTS | Qualified Trust Services · e-signatures | eIDAS QTS + BFT signature governance | sovereign-keystore · bft-council-probe |
| Step | Action | Who | Time | Prerequisite |
|---|---|---|---|---|
| 1 | Identify identity framework (GOV.UK One Login / DIATF / IDVT / eIDAS 2.0 / GDPR biometric) | Buyer | 15 min | This trust pack §2 |
| 2 | Confirm trust level (Level of Assurance LoA1 / LoA2 / LoA3 / LoA4) | Buyer + CSOAI | 30 min | Framework checklist |
| 3 | Confirm data classification (OFFICIAL / OFFICIAL-SENSITIVE) & biometric DPIA | Buyer + CSOAI | 1 hour | SC clearance guide |
| 4 | Submit identity attestation (DIATF cert / IDVT pack / eIDAS QTS / DPIA) | Buyer | 1-2 hours | DSP tracker |
| 5 | CSOAI provisions identity-sector sovereign VM + DEFONEOS substrate | CSOAI | <24 hours | AG-1: curl -s /health HTTP 200 |
⚠️ HARD RED-LINE: DEFONEOS handles OFFICIAL and OFFICIAL-SENSITIVE data ONLY. No personal-surveillance patterns. No face-recognition mass-tracking of individuals in public spaces. No live biometric tracking without explicit statutory authority, DPIA, and 33-agent BFT council approval (quorum 23/33). Digital identity is for citizen service delivery, trust verification, and fraud prevention — never for mass surveillance or population tracking.
| Buyer type | Entry point | Trust framework | Security requirement | Pilot tier |
|---|---|---|---|---|
| GDS GOV.UK One Login | I1 | GDS Service Standard | OFFICIAL-SENSITIVE | T2/T3 |
| DSIT DIATF Provider | I2 | UK DIATF | OFFICIAL-SENSITIVE | T2/T3 |
| Home Office IDVT | I3 | IDVT framework | OFFICIAL-SENSITIVE | T2/T3 |
| HMRC Tax Identity | I4 | Government Gateway successor | OFFICIAL-SENSITIVE | T2 |
| NHS Patient Identity | I5 | NHS Login / DSPT | OFFICIAL-SENSITIVE | T2/T3 |
| Passport Office Biometric | I6 | ICAO / ePassport | OFFICIAL-SENSITIVE | T3 |
| DVLA Licence Digital | I7 | DVLA framework | OFFICIAL | T2 |
| OIX Trust Scheme | I8 | OIX / W3C DID | OFFICIAL | T1/T2 |
| Cabinet Office eIDAS | I10 | eIDAS 2.0 QTS | OFFICIAL-SENSITIVE | T3 |