I thought a solution to this would be to use a physical smartcard to store the certificate(perhaps on your government ID).
if the protocol is a challenge/response and the private key never leaves the card it would make proxying without the physical card more difficult.