I'd be curious to know why it chooses to have a register step, why not just use the key of the authenticator/the relying ID as a proof of identity?
You would normally use a scheme like this so that websites cannot connect multiple identities together, but it seems pointless here because the pubkey will be signed with the user identity and the server will have logged your real pubkey