Dear Prem,
Thank you for the detail in your inquiry and apologies for the delay in response. We appreciate the context you've provided and welcome the opportunity to support progress toward certification.
Based on your description, your implementation appears to fall within the User Authentication Certification Program. We would like to invite you to meet with FIDO Certification to review your certification effort and help identify the appropriate next steps.
Please use this
booking link to schedule a time that is convenient for you.
To help us prepare, we ask that you provide a brief overview of your implementation in advance. This will also allow us to review the certification resources available to implementers, including applicable conformance test suites, certification guides, and
reference documentation.
As your questions span both implementation guidance and certification, we will focus on the applicable certification requirements and navigating the certification process. While implementation design and technology decisions are left to the implementer, we
are happy to discuss how your implementation aligns with the FIDO User Authentication Certification Program.
Thank you again and see you soon!
Regards,
Elizabeth Komarnicki
| Certification Secretariat | FIDO Alliance
T: +1 630-965-9062
eliz...@fidoalliance.org |
www.fidoalliance.org
***NOTICE:
Please be aware that all certificates are being transitioned to CyberPass, FIDO’s new certification management and database system. If you have FIDO Certified Products, you will be notified once they’re available in the database and will be prompted
to create new user accounts to manage both historical and future certifications. Please stand by for additional information. Preview CyberPass at:
https://www.cyberpass.com.***
Dear FIDO Alliance Team,
I hope you are doing well.
My name is Prem Prashant Jha, and I am currently working on an Android Passkey Provider implementation based on FIDO2/WebAuthn, Android Credential Manager, Android Keystore/StrongBox, and biometric user verification.
While implementing and analyzing cross-device authentication flows, I have been studying the hybrid passkey architecture involving QR codes, BLE proximity verification, and relay-based communication. I would appreciate your guidance on a few topics:
- Best practices for implementing a custom Android passkey provider.
- Recommended resources for understanding Hybrid Transport and Cross-Device Authentication.
- Whether a BLE-only transport architecture is considered practical for production-grade WebAuthn cross-device authentication.
- Key architectural considerations when comparing BLE-only transport with caBLE / hybrid transport.
- Any public implementation guides, reference architectures, technical papers, or working group resources that may help developers better understand Android passkey ecosystem integration.
I would also appreciate guidance regarding FIDO certification:
- Can an Android passkey provider application be submitted for FIDO certification?
- Which certification programs would apply to such a product?
- What are the certification requirements for a software authenticator implemented using Android Credential Manager and Android Keystore?
- Are there any conformance test suites, certification guides, or reference documents available for implementers?
- What would be the recommended certification path for a team developing a standards-compliant passkey authenticator?
My goal is to ensure compliance with FIDO2/WebAuthn standards while understanding both the technical and certification requirements for a production-ready implementation.
If there are any relevant documents, mailing lists, working groups, or technical contacts that you would recommend, I would be grateful for your guidance.
Thank you for your time and support.
Kind regards,
Prem Prashant Jha
------------------------------------------------------------------------------------------------------------
[ C-DAC is on Social-Media too. Kindly follow us at:
Facebook:
https://www.facebook.com/CDACINDIA & Twitter: @cdacindia ]
This e-mail is for the sole use of the intended recipient(s) and may
contain confidential and privileged information. If you are not the
intended recipient, please contact the sender by reply e-mail and destroy
all copies and the original message. Any unauthorized review, use,
disclosure, dissemination, forwarding, printing or copying of this email
is strictly prohibited and appropriate legal action will be taken.
------------------------------------------------------------------------------------------------------------