I'm thinking aloud here..

A p2p protocol, where each identity have at least 5 authenticating signatures, so that adding a new device/node to be used by an identity would just be replacing a signature, instead of adding one.

This would be for the purpose of masking how many nodes / devices are active for any given identity.

Hm. This probably needs more thought. There might also be something valuable in having two levels of auth, like DNSSec.

The half-idea for multi-layer signatures is that one or more always- or often-on nodes could be primary authenticators, and sign more or less temporary authenticators for other devices / nodes.

