mashbean 黃豆泥
mashbean.eth
豆泥的以太坊地址:mashbean.eth
狀態:未簽名
0xf9bdb99d771e4a752584346a9baead395f934fa64b0a7a037312dd76d45b400f
已簽名表示這篇文章已建立獨特的身分證字號(內容雜湊,contentHash)並且由豆泥簽署認證,簽署是採用以太坊區塊鏈的豆泥專用地址(signer.mashbean.eth)。只要內容一經修改,就會需要重新驗證換發新的身分證字號。但豆泥不是每天都在公所上班,所以偶爾會慢一點認證。

這是一篇開發心得與個人思路,文章由 Agent 撰寫。
我在自己的 AI 部落格「難題」開了一個新專區「有備而來」,記錄我打造、魔改、開發理想版數位皮夾的過程。
由於沒有上線壓力,也沒有官方包袱,所以我會使用無所不用其極的方式進行開發——因此有很大的機率成為縫合怪——並且撰寫心得筆記,目標是進行數位公共服務的倡議。
而且,這些文章背後的有備而來 App 原始碼與研究文章原始碼都有同步開源,所以我可以很有底氣地說明哪些做得到,哪些做不到。
今天是第一篇,題目是〈如果用自然人憑證接收電子公文?〉。
背景是這樣的:一般人目前沒有一個跨機關通用的電子公文收件途徑,還是得收實體信件;政府機關、公司行號與民間組織團體卻已經可以參與公文電子交換。讓自然人也能接收電子公文,可以說是電子化政府的最後一哩路。
國外有許多案例可以說明,這是一項必要、而且確實做得到的數位公共建設;完整文章裡也整理了各國做法。
我在 2024 年擔任行政院青年諮詢委員時,建穎委員其實就提出過相關構想。詳見提案 10:「建置一般民眾以自然人憑證收取電子公文之平臺」。我們可以從前後幾次機關回覆中,看到一如往常的權責來回狀態。
不過結果是好的。檔案管理局把「G2C 民眾公文電子交換服務」納入數發部的「智慧政府數位領航發展計畫(115–119 年)」,並表示預計民國 117 年,也就是 2028 年,完成上線服務。
從我自己的視角來看,既有的數位公共建設其實已經相當完備。最缺的交換機制與治理制度,我現在也碰不到,更不用說跨機關合作的權利義務歸屬問題。所以我可以做的,就是先開發一隻「縫合怪」來驗證可行性。
我把「數位皮夾」與「行動自然人憑證」縫在一起,也接上了實體自然人憑證的 Driver,讓數位皮夾產生接收公文並簽收的可能。
自然人憑證當然沒辦法自己收公文,因為它是身分識別與簽章工具,不是收件容器。數位皮夾自己也不行:單靠一組分散式識別符地址(did:key),並不會自動取得電子簽章法下足以證明本人意思表示的法律效果。
不過,Pen-Pineapple-Apple-Pen,碰在一起,就解決啦!
所以我實現了行動自然人憑證與實體自然人憑證簽署,再跳轉回第三方數位皮夾「有備而來」,並接收自行產生的合成電子公文。
這組測試資料借用了官方規範中 EN(信封檔)、DI(文書本文檔)與 ESW(加密交換表單檔)的元件名稱與分工,但不是檔案管理局提供的官方測試套件,也尚未通過官方 DTD/Schema、簽章、加密或 G2C 介接驗證。目前找不到可公開取得的官方沙盒測試資料,因此 App 與文章都明確把它標示為自製合成資料、沒有法律效果。
最後,畢竟已經具備甲方的內建尿性,所以我也根據數位公共建設的一些原則,試寫了標規與驗收項目。有緣的話,歡迎來參考一下,哈哈。
至於圖片裡的其他服務,例如 MyData 資料保險箱、實現零知識證明的數位國民身分證、第三方皮夾超商取貨等等,接下來會在其他文章分享,敬請期待!
This is a development write-up and a record of my own thinking. The article was drafted by an Agent.
On my AI blog “Wicked Problems”, I’ve opened a new section called “Ready in Advance” to document my process of building, hacking on, and developing my ideal version of a digital wallet.
Since there’s no pressure to ship and no official baggage, I get to develop by whatever means necessary—which means there’s a very high chance the result becomes a Frankenstein’s monster—while writing up my notes along the way. The goal is to make the case for better digital public services.
And because the source code for the “Ready in Advance” app and the source code for the research articles behind these posts are both open-sourced in sync, I can speak with full confidence about what works and what doesn’t.
Today is the first post, titled “What if you could receive electronic official mail with a Natural Person Certificate?”.
Here’s the background: ordinary people currently have no cross-agency, universal channel for receiving electronic official mail—we still have to receive physical letters. Government agencies, companies, and civic organizations, on the other hand, can already take part in electronic official-document exchange. Letting natural persons receive electronic official mail too could be called the last mile of e-government.
There are plenty of overseas cases to show this is a necessary—and genuinely achievable—piece of digital public infrastructure; the full article also gathers together how various countries do it.
Back in 2024, when I served on the Executive Yuan’s Youth Advisory Committee, committee member Chien-ying actually raised a related idea. See Proposal 10: “Building a platform for ordinary citizens to receive electronic official mail using the Natural Person Certificate”. From the several rounds of agency replies before and after, you can see the same old back-and-forth over who’s responsible for what.
But the outcome was good. The National Archives Administration folded the “G2C Citizen Official-Document Electronic Exchange Service” into the Ministry of Digital Affairs’ “Smart Government Digital Navigation Development Plan (2026–2030),” and stated that the service is expected to go live by ROC year 117—that is, 2028.
From my own vantage point, the existing digital public infrastructure is actually already quite complete. The pieces that are most missing—the exchange mechanism and the governance framework—are things I can’t touch right now, let alone the question of how rights and obligations get assigned in cross-agency cooperation. So what I can do is first develop a “Frankenstein’s monster” to prove out feasibility.
I stitched the “digital wallet” together with the “mobile Natural Person Certificate,” and also hooked up the driver for the physical Natural Person Certificate, giving the digital wallet the ability to receive an official document and sign for it.
The Natural Person Certificate obviously can’t receive official mail on its own, because it’s an identity and signing tool, not a receiving container. The digital wallet can’t do it alone either: a single decentralized identifier address (did:key) doesn’t automatically acquire the legal effect—under the Electronic Signatures Act—of proving that the person expressed their own intent.
But, Pen-Pineapple-Apple-Pen—bring them together, and problem solved!
So I made it possible to sign with both the mobile and the physical Natural Person Certificate, then jump back into the third-party digital wallet “Ready in Advance” and receive a self-generated synthetic electronic official document.
This set of test data borrows the component names and division of labor from the official spec—EN (the envelope file), DI (the document body file), and ESW (the encrypted exchange form file)—but it is not the official test suite provided by the National Archives Administration, and it has not passed official DTD/Schema, signature, encryption, or G2C integration validation. There’s currently no publicly available official sandbox test data to be found, so both the app and the article clearly label it as self-made synthetic data with no legal effect.
Finally, since I already come with the built-in temperament of a client-side commissioning party, I also took a stab at drafting the standards and acceptance items based on some digital-public-infrastructure principles. If the stars align, feel free to take a look, ha.
As for the other services in the images—MyData data vault, a digital national ID card that implements zero-knowledge proofs, third-party-wallet convenience-store pickup, and so on—I’ll share those in future articles, so stay tuned!