Funnily enough that is roughly the implementation the EU seems to be working on.
https://digital-strategy.ec.europa.eu/en/policies/eu-age-verification
On a side-note. I do not consider the government to be a trusted party. Whatever solution gets implemented needs to not provide the government any information that they can use for mass surveillance.
The two main requirements in my view are:
- The website that needs your age shouldn't get to know your identity. They only get to verify your age.
- The government age verification shouldn't get to know what service you are requesting access for. They only provide age verification.
Edit: You mention the certificate being short-lived, but one of the concerns mentioned in the proposed implementation for the EU age verification states that if that window is too short it can be used to determine identity.