Hi There,
Also, can you please share the updated specification as mentioned in the workshop?
Thank you
Regards,
Kirubakaran Selvaraj
Manager – Product Development
Tech Rizes Transdomain Pvt. Ltd.

![]()
+91 9986483320
kirubakara...@techrizes.net![]()
Tel: +91 80 4261 1430
Fax: +91 80 4261 1445
www.tech-rizes.com![]()
702 7th Floor, World Trade Centre,
Brigade Gateway 26/1, Dr Rajkumar Rd,
Rajajinagar Ext (Malleshwaram West),
Bangalore, 560 055, India![]()
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/06280fa0-a39e-4000-9a0c-304f236ddb5e%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
Dear UIDAI Team,
Due to the short notice, we can not participate the workshop. We are very appreciated if you can share the presentation (slides) on the July 17th workshop for L1 compliance and any new specification.
Thank you very much.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/a1b3aa48-d8e2-44c4-bc6a-20c2877993da%40googlegroups.com.
Dear UIDAI Team,
Due to the short notice, we can not participate the workshop. We are very appreciated if you can share the presentation (slides) on the July 17th workshop for L1 compliance and any new specification.
Thank you very much.
On 7/18/2017 12:59 AM, Jyjesh Thayyil wrote:
Dear All,--
Pl use this thread to provide your suggestions and queries on Level 1 compliance.
Regards,Team UIDAI.
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+unsubscribe@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/a1b3aa48-d8e2-44c4-bc6a-20c2877993da%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+unsubscribe@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/4c8add91-a6c5-918a-889c-8ebebdd20808%40iritech.com.
Regards
Ketan Upadhyay
The TEE here is ARM 9 processor with Hardware random no generation, CMOS scanner interface, volatile key storage with secure RAM module. This uses FIPS certified encryption algorithm. The Processor supports secure boot
The Private key is stored on external FLASH (25Qxxxx) in encrypted value and encryption key is device specific, unique for every IC. This simulates hardware key-store.
The channel between Censor module and Main board is protected with encryption and board replacement is not possible.
Dear Team,
Architecture suggested by Mr. Ketan is not valid as per L1 guidelines.
1. Keystore Memory should be the part of Controller/Processor and should be secured Write Only memory.
2. If its outside the controller/processor, then anybody can remove the memory/Change the memory and access the keystore.
3. Keystore memory should be write only memory.
4. It’s necessary that Host should not access the memory directly and its accessed only by the TEE execution.
5. Even if the data in external flash is encrypted then also it can be read through multiple read and decrypt attack.
6. External Flash cannot be protected since its outside TEE environment.
If keystore is on external flash then there will be no difference between L0 and L1 device as one of the major objective behind the L1 device is to protect keystore.
If keystore memory is external then it can’t be L1 device.
I suggest other L1 device vendors to put in their views.
Regards
Hiren
From: aadha...@googlegroups.com [mailto:aadha...@googlegroups.com] On Behalf Of ketan
Sent: Thursday, October 05, 2017 21:49
To: Aadhaar Registered Devices Discussion Group
Subject: [aadhaar_rd] Re: Suggestions and Queries on L1 compliance
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/665d709a-96ac-4ec9-bbb3-395d831ef8e4%40googlegroups.com.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+unsubscribe@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/665d709a-96ac-4ec9-bbb3-395d831ef8e4%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+unsubscribe@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/000601d33eb9%24f90e4450%24eb2accf0%24%40mantratec.com.
Can we use flash to store firmware or part of firmware in signed and encrypted manner and use on-board processor memory for Keystore? Does this meet L1 requirement?
Thanks,
With much gratitude and respect,
For Biomatiques Identification Solutions (P) Ltd.
| Pratik Patel | VP – Global System Integration ‘Rishi House’, Nr. Kargil Chowk, Piplod, Surat – 395 007, (Guj.), INDIA Mobile: +91 990 980 4321 Phone: +91 261 2225767 Email: pra...@biomatiques.com |
Pl suggest on below L1 architecture, This is having secure boot and Hardware keystore
The TEE here is ARM 9 processor with Hardware random no generation, CMOS scanner interface, volatile key storage with secure RAM module. This uses FIPS certified encryption algorithm. The Processor supports secure boot
The Private key is stored on external FLASH (25Qxxxx) in encrypted value and encryption key is device specific, unique for every IC. This simulates hardware key-store.
The channel between Censor module and Main board is protected with encryption and board replacement is not possible.
Regards
On Monday, July 17, 2017 at 11:29:37 PM UTC+5:30, Jyjesh Thayyil wrote:Dear All,
Pl use this thread to provide your suggestions and queries on Level 1 compliance.
Regards,
Team UIDAI.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/665d709a-96ac-4ec9-bbb3-395d831ef8e4%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/000601d33eb9%24f90e4450%24eb2accf0%24%40mantratec.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/CAOt%2BV9MaLv6mOyhJyef6mvdyZn3BcGJj0baFA8hHX1wS5a-9WA%40mail.gmail.com.
Dear Pratik,
1. I think You may use Encrypted Nor Flash to store Firmware.
2. MCU/Processor internal secured write only memory should have private key to decrypt firmware on the fly.
3. MCU/Processor On the fly decryption method should support AES 128 or AES256 or any other standard decryption method.
4. This process will make sure that only MCU can decrypt the firmware.
5. Key is always protected by TEE inside MCU.
Hiren
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/001601d33f2f%2483d65170%248b82f450%24%40biomatiques.com.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+unsubscribe@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/665d709a-96ac-4ec9-bbb3-395d831ef8e4%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+unsubscribe@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/000601d33eb9%24f90e4450%24eb2accf0%24%40mantratec.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+unsubscribe@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/CAOt%2BV9MaLv6mOyhJyef6mvdyZn3BcGJj0baFA8hHX1wS5a-9WA%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+unsubscribe@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/001601d33f2f%2483d65170%248b82f450%24%40biomatiques.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+unsubscribe@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/008901d33f36%24daa24d90%248fe6e8b0%24%40mantratec.com.
Dear All,
1. Keystore cannot be used on external Flash or any other memory. Memory chip can be replaced and can be compromised.
2. Keystore should be on secured processor/Controller with secure access model.
3. As I mentioned earlier, external flash or keystore can be accessed by Flash Programmer/Reader.
4. Key retrieved from Flash Programmer/reader can be decrypted by multiple decryption attacks.
5. I believe External key storage cannot be a secured model.
Regards
Hiren
From: aadha...@googlegroups.com [mailto:aadha...@googlegroups.com] On Behalf Of Netaji Rao
Sent: Saturday, October 07, 2017 13:01
To: aadha...@googlegroups.com
Subject: RE: [aadhaar_rd] Re: Suggestions and Queries on L1 compliance
Dear Pratik,
Firmware storage is not an issue as it is supposed to be signed and verified as part of secureboot process.
On-board processor (unless it is secure processor) may not be used for keystore. privatekey is not protected.
------------------------
Device Private Key must be stored in secure Hardware Keystore
- May be a Secure Processor or a Secure Access Model
- Must contain TRNG and ability to Sign the biometric
- Signature must happen in the Hardware Keystore
Thanks,
Netaji Rao D
On 07-Oct-2017 12:09 PM, "Hiren Bhandari" <hi...@mantratec.com> wrote:
Dear Pratik,
1. I think You may use Encrypted Nor Flash to store Firmware.
2. MCU/Processor internal secured write only memory should have private key to decrypt firmware on the fly.
3. MCU/Processor On the fly decryption method should support AES 128 or AES256 or any other standard decryption method.
4. This process will make sure that only MCU can decrypt the firmware.
5. Key is always protected by TEE inside MCU.
Hiren
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/665d709a-96ac-4ec9-bbb3-395d831ef8e4%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/000601d33eb9%24f90e4450%24eb2accf0%24%40mantratec.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/CAOt%2BV9MaLv6mOyhJyef6mvdyZn3BcGJj0baFA8hHX1wS5a-9WA%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/001601d33f2f%2483d65170%248b82f450%24%40biomatiques.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/008901d33f36%24daa24d90%248fe6e8b0%24%40mantratec.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/CAOt%2BV9OfSw1J3vkJmxpv0Y%2BXqc7LxYWfJJKNxm3ijV8xxCC3bg%40mail.gmail.com.
I had requested UIDAI to define hardware key-store and required certification (if any) during last meeting at UIDAI tech center and also by subsequent mails.
But there is no fix definition and hence I had suggested the most cost effective architecture in group for review and inputs.
As we all are getting inquiry from market for L1 devices, we need to be ready with option and in absence of clarity of Secure boot working and Hardware key-store we are on three diff options L1(-), L1 and L1(+), depending on security of key store.
In case of L1(-) and L1, secure boot is required, for L1(-) to protect key access and for L1 (single chip solution) due to access to security module is only for signed execution code.
Do we require secure boot for single chip module HSM? As this is certified and widely used across all platforms throughout the world without any security problem since long ( we all are using HSM dongle to sign).
Above all is technical details but when we consider market requirements, there is only L1 and most cost effective solution (in absence of clear mention of no storage of Key on unsecure memory) is L1(-).
L1(+) provides tamper protection (as it is mandatory for HSM used everywhere), but this is optional in specs.
We are open with all three options, let’s get final verdict from UIDAI team.
I will also request all others to provide tech inputs with positive and negative details.
Best Regards
Ketan Upadhyay
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+unsubscribe@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/426d9d16-fa50-49d2-a0bb-fc126d8f8de8%40googlegroups.com.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+unsubscribe@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/1d8a7896-26cc-4c6d-af25-610ec337a435%40googlegroups.com.
Dear All
What I mean by HSM module :- Single chip security module having Processor, secure memory for key storage, secure memory for processing, True Random no generator, Able to generate various bit length RSA key pair, Able to encrypt , create checksum or sign. This module supports multiple encryption and signing and checksum algorithms and multiple key length. This module normally has execution program in temper proof ROM and handshake is done using crypto. Algorithms are FIPS 140-2 certified and many chip are also certified for TPM. These are widely used everywhere for HSM dongle and other secure commercial application. The program in ROM is secure boot as in cannot be altered or tampered at the same time it is also proof against future updates as it supports multiple algorithms currently being used. We are not depending on chip manufacturer words for this on security as these modules are third party certified by reputed labs.
This is to clarify about HSM module and security offered in HSM module is being used for secure commercial use with much higher impact and to-date this is safe. Secondly these are standards and verifiable.
Now continuing in the main line of discussion
The response to points of Netaji
This discussion I had started to jointly analyze the architecture of various possible options. The secure boot or equivalent is good for first two but does not provide any additional sec with HSM. Same way Key security is also at diff level, L1(-) key in encrypted data can be broken so as security module of IC (as this has happened in past). The key security is not backed by standards and Lab tests in case of L1(-) and L1 (for few single chip solutions).
Requesting other members to provide inputs, there is no word from IC mfgs.
Lets see what UIDAI and STQC team decides on specs and be ready with multiple options.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+unsubscribe@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/9643bba5-0bb3-4144-8190-6c0a76dd8d80%40googlegroups.com.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/9643bba5-0bb3-4144-8190-6c0a76dd8d80%40googlegroups.com.
(//Biometric module does not require to be secure as it is any way available in open and anybody can use image extractor. The criteria in L0 and L1 is signing. Even if bio module is secure but the private key is compromised, what is the use. The importance is to keep key secure and sign only valid data.// àThis understanding is not correct. If the biometric module is not loaded through secureboot, that itself can generate and inject biometrics. Secure channels won't help.)
(//But TEE does not mean secure boot, If someone loads wrong FW and it cannot call my HSM IC, what it will do? It cannot make PID da//
Please do not assume that none can call HSM (can you pl share any case where HSM call is compromised anywhere in world ? it is being used since many years and on multiple platform and format. Till now it is most trusted and used everywhere). Wrong FW doesn't mean a competitor's firmware. You own unsigned firmware is also a wrong firmware from trust perspective. An untrusted device is as good as an unsecured device.)
The definition required in case of dual processor architecture, which processor should be secure boot and what is secure boot (there is no standard and it name differs for diff manufacturer with same logic). Same way just hardware key-store without any standards are not clear. The encrypted key on flash is hardware key-store as this are hardware and cannot be denied. Again about TEE it is just description and not standard.
On other specific question by Netaji (Privatekey in an encrypted flash doesn't qualify for Hardware-keystore. Where will decryption of these keys taken place? Where are the decryption keys stored?):- Regarding details on decryption of encrypted private keys and key used for decryption, these are protected by secure boot, and are part of FW and HW of IC.
Let’s discuss technical points and advantage and drawbacks. The decision should not be from us but from UIDAI and STQC team.
During working with multiple architecture and prototypes, our team has discovered few missing details in specs and in this absence we can put our all three diff versions as discussed till now and can pass all required test criteria. If saying L1(-) or L0(+) does not make any diff if it gets test passed and certified. This can also be most cost effective solution. For the users who want highest security it could be more secure second model.
Best Regards
Ketan Upadhyay
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+unsubscribe@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/c13442ed-1143-447e-bbff-2b66b6c91d4b%40googlegroups.com.
Hi all,
It has been a very engaging discussion regarding L1 compliance. The views by Ketanji, Netaji, Hirenji, Pratikji and others have been very informative. Thanks a lot for the information shared.
Brief introduction – I head the technical support activities in the space of cryptography and security implementation for Microchip Technologies in the ASEAN region (India, Indonesia, Thailand, etc.).
I am working on Aadhaar L1 solutions with a few customers but this post is not about our solution or part numbers.
I would like to restrict my inputs regarding the current discussion and a call-to-action as technology providers to the government.
· As rightly pointed out by esteemed members mentioned above, secure boot and TEE are completely different and most importantly – independent aspects of a security design
·
Secure Boot requires a so-called immutable root
à The first level bootloader should be unchangeable – the most common way to implement this is thru
ROM codes like a lot of semiconductor vendors do. But that is just one of the requirements.
Another very important requirement is the fact that the application image (in case of a monolithic firmware) or image components (in case of a rich OS like *nix-based OS) should be signed and (optionally) encrypted using separate keys. This key (or these keys)
should either be housed in an user-unreadable location inside the ROM (the most common implementation) or inside an HSM – the host-HSM interface should mandatorily be
session-based else you run the risk of key leakage thru a probe attack. The first level bootloader is responsible for verifying the signed image (and decrypting the encrypted image if applicable).
I believe UIDAI has mandated secure boot hence any topology that violates the any of the above basic requirements may need to be re-looked at. Semiconductor vendors also generally provide other “secure boot” provisions like a key-verifying key (KVK) – but the
above basic reqs should be met at the minimum to qualify a “secure boot” capability.
·
TEE or Trusted Execution Environment is a completely
different ball-game. TEE refers to a hardware-isolated “environment” that runs in parallel to the non-trusted part of the application. The “environment” I refer to is a combination of hardware and software.
In its most common implementation, hardware isolation is achieved inside the processor core by implementing privileged instructions which are issued by a dedicated software OS or an RTOS. By erecting a strong security perimeter between the two worlds,
hardware logic present in the CPU bus fabric prevents “Normal World” components from accessing “Secure World” resources. To paint an example picture for Aadhaar L1, a TEE can be a combination of a rich OS/RTOS and a secure OS/RTOS – the rich OS/RTOS runs the
USB stack, the XML stack, etc. which are generally open-source codes prone to known or yet to be discovered bugs and the secure OS/RTOS runs the secure code responsible for fetching data from the camera sensor, the extraction algorithm, the crypto accelerators
and most importantly the DSA and the AES encryption. What this does is even though a vulnerability is discovered and acted upon in the rich OS, the secure OS will still not be impacted and continues to not only preserve the secret keys and codes, but also
has the capability to signal to the CPU that something has gone wrong with the rich world.
Organizations like Global Platform have laid out the guidelines for inter-operable communication between the rich OS and secure OS as well as for implementation of secure key-stores.
There are proven hardware technologies in the market today (and soon to come!) like the ARM TrustZone-A, Intel’s Trusted Execution Technology, ARM TrustZone-M (for microcontrollers), etc. that help implement a true TEE. There are also secure OSes prevalent
today like the OpTEE (open source TEE ported to lot of different platforms), CoreTEE (proprietary ready-to-use secure OS), Samsung KNOX (people who are aware of the immense security involved in tech like Samsung Pay will know this).
·
There was a discussion on use of an external storage being prone to repeat decrypt attacks. With a TEE implementation detailed above, this should
not be a concern as areas inside the flash/external memory are dedicated for access by the secure OS and exist in an encrypted form all the time – the key itself is inside a memory zone ear-marked for the TEE. This makes it practically impossible for someone
to retrieve the secure OS or the keystore as is. This is the reason such technologies have found their applications primarily in systems with external memories.
·
As far as reverse-engineering a firmware design goes or guessing secrets go, hackers are far ahead of all of us as of today. For instance consider
this company that takes pride in reverse-engineering MCUs and memory. It is not surprising to see that the list they have put up consists of products from a lot of vendors. At the same time, it is important to understand
that these are products designed for cost efficiency – not for security (I speak on behalf of all vendors you see there!!).
Some of us may also have heard about Defcon hack conference where the sole goal is to reverse engineer hardware. From missile systems to access systems to voting machines, these guys have been inside (figuratively!) a lot
of applications!
The sole goal of mentioning these links is to motivate all of us to provide the best possible design. For all of us, the very first thought is always to reduce the cost of build, but esteemed members – I firmly believe we should also give security its due importance.
Only then, I believe we can together quell any doubts that people have about the immense potential of Aadhaar and together realize the government’s dream to make India world’s first
inclusive cash-less society – inclusive being the operating word J.
Thank for you the discussions on the group and hope you find the above info useful. I would be glad to participate in discussions one-on-one or on the group.
Look forward and Jai Hind!
Regards,
Shashank
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to
aadha...@googlegroups.com.
Visit this group at
https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/c13442ed-1143-447e-bbff-2b66b6c91d4b%40googlegroups.com.
For more options, visit
https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to
aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/CAOt%2BV9OSon9P3XiZxu_auT0_yrZVQ%3D_vXX3EWr3VSj%2B0QsphCg%40mail.gmail.com.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+unsubscribe@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/c13442ed-1143-447e-bbff-2b66b6c91d4b%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+unsubscribe@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/CAOt%2BV9OSon9P3XiZxu_auT0_yrZVQ%3D_vXX3EWr3VSj%2B0QsphCg%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+unsubscribe@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/904BE92D59CF0F4193C53CBEAE6E5DDA437261%40CHN-SV-EXMX03.mchp-main.com.
Thanks for the brief below. Do you think detailed list of test cases from UIDAI will help us identify the exact requirement and improve our design capability to incorporate the required security?
UIDAI can test 1 design aspect (such as secure boot) by multiple test cases (1. Bootloader location, 2. key extract/fake etc)!
Thanks,
With much gratitude and respect,
For Biomatiques Identification Solutions (P) Ltd.
| Pratik Patel | VP – Global System Integration ‘Rishi House’, Nr. Kargil Chowk, Piplod, Surat – 395 007, (Guj.), INDIA Mobile: +91 990 980 4321 Phone: +91 261 2225767 Email: pra...@biomatiques.com |
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/c13442ed-1143-447e-bbff-2b66b6c91d4b%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/CAOt%2BV9OSon9P3XiZxu_auT0_yrZVQ%3D_vXX3EWr3VSj%2B0QsphCg%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/904BE92D59CF0F4193C53CBEAE6E5DDA437261%40CHN-SV-EXMX03.mchp-main.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/CAOt%2BV9O7jmN27fn8-0Z7bX1%2Br%3D7dOheV9xgFcoLwqqCi4ukLUQ%40mail.gmail.com.
Hi Netaji,
As I mentioned the secure OS runs in parallel to the rich OS. Both software run in a time-sliced manner. The difference is in the fashion on instruction calls at the CPU level. This implementation differs from CPU to CPU.
For instance, ARM TrustZone makes use of an implementation called the Secure Monitor that is responsible for switching between the secure and the non-secure world. But just the secure monitor is not enough – you need a trusted kernel (not necessarily *nix – can be simpler) which is the crux of the “secure” world. This trusted kernel is the one that is responsible for the memory space allocation for the secure OS, performing secure calls to peripherals and the CPU (using special instruction extensions specific to the CPU and the CPU bus – ARM has these extensions built into the AXI bus fabric). The Secure OS should implement drivers to access the hardware peripherals that are to be only-secure accessible like the AES, the SHA, etc. On top of this would sit the crypto engine that implements the DSA, the Global Platform key storage implementation, etc.
For a microcontroller, the equivalent is the TrustZone-M which has done away with Secure Monitor and implemented the switch logic in hardware. This will make it easier to meet the real-time requirements for which MCUs are used most commonly. TrustZone-M is a new technology and you will soon see vendors coming out with this built-in.
Without this kind of hardware isolation at the core level, your application code has the same level of accesses to system resources like your BSP code or you low-level drivers which makes it that much easy for vulnerabilities to (negatively) affect the system.
PS: I talked about ARM TrustZone only because I am comfortable with their implementation and thought it would be good to explain with an example. J
· Can we assume it's a complete secure-world with no action on normal world? àI am not really sure what action is being referred to here but I would put it this way – tomorrow if someone is able to get access to your system making use of any vulnerability in software, their access will be restricted to the non-secure components only (be it the kernel access, memory space access, etc.). The secure OS would run unaffected as the privilege for this software is not restricted by user being normal user or root user but by the type of CPU accesses i.e. transactions at the bus level!
Regards,
Shashank
From: aadha...@googlegroups.com [mailto:aadha...@googlegroups.com] On Behalf Of Netaji Rao
Sent: 09 October 2017 11:31
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to
aadha...@googlegroups.com.
Visit this group at
https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/c13442ed-1143-447e-bbff-2b66b6c91d4b%40googlegroups.com.
For more options, visit
https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to
aadha...@googlegroups.com.
Visit this group at
https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/CAOt%2BV9OSon9P3XiZxu_auT0_yrZVQ%3D_vXX3EWr3VSj%2B0QsphCg%40mail.gmail.com.
For more options, visit
https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to
aadha...@googlegroups.com.
Visit this group at
https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/904BE92D59CF0F4193C53CBEAE6E5DDA437261%40CHN-SV-EXMX03.mchp-main.com.
For more options, visit
https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to
aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/CAOt%2BV9O7jmN27fn8-0Z7bX1%2Br%3D7dOheV9xgFcoLwqqCi4ukLUQ%40mail.gmail.com.
Thanks everybody for this detail technical discussion and special thanks to Ketan for bringing an Architectural question.
I think we still didn’t get the concrete answer to Ketan’s question. And probably it will not be easy to give an answer if the Arch clearly does not describe the sections mentioned in the STQC Solution arch document.
I would like to bring attention to 2 Excellent UIDAI and STQC documents.
AADHAAR REGISTERED DEVICES , TECHNICAL SPECIFICATION - VERSION 2.0 (REVISION 2), July 2017
Page 7:
UIDAI does not mandate any specific hardware design and device providers are expected to innovate appropriate form factors for market use. Key design mandate is that registered devices MUST securely sign the biometric data, form the encrypted PID block within the RD Service and give it back to application for use within Aadhaar authentication.
Registered devices MUST ensure the following;
1. There should be no mechanism for any external program to provide stored biometrics and get it signed and encrypted.
2. There should be no mechanism for external program/probe to obtain device private key used for signing the biometrics.
It is important to note that it is in device provider’s interest to ensure the above two items are implemented securely since any compromise on these will result in fraudulent activities signed using the device provider key. As per IT Act it is essential for the key owners (device provider) to protect the signature key and take responsibility for any compromise.
So any Arch proposal has to be viewed in this spirit of innovation.
In reference to what Shashank has shared, I think we should follow what STQC guidelines says about TEE. In UIDAI/STQC spec there is definition of TEE:
Guidance to applicant for Registered Devices for UID Application, Page 23 defines TEE.
TEE Definition:
For the purposes of the registered device specification the Trusted Execution Environment (TEE) is implied in the generic sense (and not restricted to Global Platform TEE). The capabilities of the TEE
1. Support for Secure boot
2. Secure storage for keys (separate isolated hardware)
3. Support for PKI encryption and signing using RSA 2048
4. Support for symmetric encryption using AES 256 GCM
5. Support for Hashing using SHA-256
6. Support at the hardware level to isolate the key operations and biometric signing
Only trusted software components from the device provider can be deployed on the TEE. It is expected that PKI (or equivalent) infrastructure will be used to deploy the trusted software.
Suggested certifications for the Trusted Execution Environment include:
1. Common Criteria certification of Global Platform TEE PP
2. Common Criteria certification of Global Platform TPM 2.0 PP
3. Common criteria certification of SE PP
4. FIPS 140-2 certification of Global Platform TEE, Global Platform TPM 2.0, SE
5. EAL 3 or more is a good sign so if anyone has EAL 3 or more we can simply take their certificate and accept.
6. https://en.wikipedia.org/wiki/Trusted_execution_environment#Implementations - Also compliance to the open implementations
Alternatively test reports from the semiconductor vendor showing compliance to the capabilities of TEE may be furnished.
So when we say something as TEE, we must look into this definition.
Further I would like to highlight notes from STQC spec:
Page 24:
In most cases, considering the rule of thumb that states every device can be broken, a device should not try and defend against lab attack directly, but should take measures which limit the damage when a device is broken and therefore make the lab attack uneconomical.
Intent
The intent of the registered device specification is to protect against scalable hack and shack attacks and limit damage due to lab attacks.
So System Arch design should consider these aspects, while designing.
And also when we give answer to feasibility of specific arch, we must keep these aspects in mind.
A Reference from ARM TrustZone spec:
Limitations of security solutions
All security solutions are designed to defend against only a subset of the possible attacks that they may experience. Defending against all possible attacks is an impossible task; there is always someone willing to spend a significant amount of time and money to break any security scheme using very complex attacks. A design must therefore decide which assets it wants to protect, and which of the possible attacks it wants to protect the assets against. This is perhaps the most critical part of the design process; a design that protects the wrong assets against an incorrect or incomplete list of attacks can be easily broken.
The UIDAI/STQC specs are excellent in this Model.
So I think our Goal should be to design L1 devices that can withstand scalable hack and shack attacks and limit damage due to lab attacks
I have two questions to Ketan.
What are the limitations in your ARM9 Chip (you mentioned as
TEE) that you need an External Flash to store Keys?
And how adding External Flash going to close those limitations?
May be these two answers can further help us to better understand the Arch.
Thanks,
Anup
Thanks all for participating in detail discussion. During this discussion we also get some diff point of view.
While working in detail on multiple possible options this got noticed.
The main problem from point of designer is there is no mandate or requirement of specific certification or testing process.
For L0 devices we have detailed testing process, including native code requirement and memory dump test etc.
I suppose we have clear understanding on at-least one point is, if OTA updates are required, The CPU must support Secure-boot. However OTA update is not mandated by UIDAI (till now) and in this case the guidelines also can be achieved by ROM and OTP-ROM as it does not have any chance of tempering. This does not match TEE definition point of secure boot, but the code is tamper proof. What is the view of UIDAI on this specific point?
The earlier architecture case we have discussed, still can be passed as per input of Mr. Shashank , if the encryption are strong enough. The point here could be how testing agency will simulate attacks on this encrypted storage, which is accessible for data reading, but the encryption key and even mechanism is unknown.
Here I am presenting second option diagram, (This will enable many more CPU to pass L1 requirements) (attached)
Here CPU has security module and secure boot, the key-storage is also external (same like earlier) additionally even RAM is also external. The interested case here is by design of manufacture there is no provision to extract or insert templates (biometrics data for Iris), but as the RAM is external and in standard package, it can be manipulated or tampered with and can be used to extract FMR or Insert FMR (need to monitor memory for FMR data only). Most of the compiled program on CPU has fixed memory location for shared variable and once located can be manipulated. Interesting point here is how this will be tested or evaluated by UIIDAI/STQC, as to make test rig for these type of design specific attacks are difficult.
Above design fulfills all the point of TEE definition given in documents.
Many chips has very good security futures, but the detailed working of same is not shared with manufacturer (to protect security, they have this policy). Does UIDAI planning to take undertakings instead of testing and evaluation? If, so the mfgs are signing undertakings without full detailed information. If manufacturer works on architecture shown above or earlier (which was even better secure than this) and provides undertakings, will it get L1 certification?
Why not UIDAI add some guidelines like, restriction on external storage and RAM without TPM. Device manufacture to submit details on security module supported by any good standards (or Chip manufacture share details with UIDAI, if they do not want to share with mfg, as it could be used against competitor or due to security policy of chip mfg) and prove beyond doubt about secure storage of key and biometric data protection
Additional testing procedure and guidelines for submitting testing rig by manufacture is also required. As if asked to prove, manufacture will provide only positive test rigs and not full capacity attack test rigs.
Greetings from Biomatiques and wishing all a Happy New Year J
As per your email below regarding TEE Definition and its applicable compliance (highlighted in Green below), point 2 mentioned (as highlighted in yellow below), separate hardware can be used for secure key storage.
Can I expect UIDAI team to comment on this??? This also means we can use external memory compliant to FIPS or other equivalent standards in our designs as suggested by Ketan and other colleagues!
Thanks,
With much gratitude and respect,
For Biomatiques Identification Solutions (P) Ltd.
| Pratik Patel | VP – Global System Integration ‘Rishi House’, Nr. Kargil Chowk, Piplod, Surat – 395 007, (Guj.), INDIA Mobile: +91 990 980 4321 Phone: +91 261 2225767 Email: pra...@biomatiques.com |
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/881e8773-bdcc-4f93-8ebc-a84e120c97a3%40googlegroups.com.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+unsubscribe@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/881e8773-bdcc-4f93-8ebc-a84e120c97a3%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+unsubscribe@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/009001d34d81%24b9ca7710%242d5f6530%24%40biomatiques.com.
Srinivas
Natekar
Project Manager -
Authentication
UNIQUE IDENTIFICATION AUTHORITY OF INDIA
L- 080-23099243, M-9620919782.
E-Mail- Srinivas...@uidai.net.in
Dear All,
Please be informed that L1 workshop on Registered Devices is planned on 20th March,2018 at UIDAI Tech Centre, Bangalore.
Workshop is ONLY for those Device Vendors who are interested in L1 Registered devices certification. Only Technical person should be nominated for the workshop and Each company can nominate only 2 persons.
Pls send Participant details for Gate pass latest by 18th EOD to Srinivas...@uidai.net.in with below subject line.
Subject:- L1 Workshop <Company Name>- Gate pass
Pls Note:- Request will not be accepted beyond stated date.
Venue:-
UIDAI Tech Centre,
NTI Layout, Tata Nagar, Kodigehalli,
Bangalore -560092.
Srinivas
Natekar
Project Manager -
Authentication
UNIQUE IDENTIFICATION AUTHORITY OF INDIA
L- 080-23099243, M-9620919782.
E-Mail- Srinivas...@uidai.net.in
Dear All.Whoever is completed with L1- Solution Architect Document Pls share on below Id's.
Srinivas Natekar
Project Manager - AuthenticationUNIQUE IDENTIFICATION AUTHORITY OF INDIA
L- 080-23099243, M-9620919782.
E-Mail- Srinivas.natekar@uidai.net.in
Srinivas Natekar
Project Manager - Authentication
UNIQUE IDENTIFICATION AUTHORITY OF INDIA
L- 080-23099243, M-9620919782.
E-Mail- Srinivas.natekar@uidai.net.in
Dear All,
Please be informed that L1 workshop on Registered Devices is planned on 20th March,2018 at UIDAI Tech Centre, Bangalore.
Workshop is ONLY for those Device Vendors who are interested in L1 Registered devices certification. Only Technical person should be nominated for the workshop and Each company can nominate only 2 persons.
Pls send Participant details for Gate pass latest by 18th EOD to Srinivas...@uidai.net.in with below subject line.
Subject:- L1 Workshop <Company Name>- Gate pass
Pls Note:- Request will not be accepted beyond stated date.
Venue:-
UIDAI Tech Centre,
NTI Layout, Tata Nagar, Kodigehalli,
Bangalore -560092.
Srinivas Natekar
Project Manager - AuthenticationUNIQUE IDENTIFICATION AUTHORITY OF INDIA
L- 080-23099243, M-9620919782.
E-Mail- Srinivas.natekar@uidai.net.in
Dear All,
Thanks for nominating yourself in Workshop, Entry pass are made available kindly be in present in 2nd floor Board room by 9.20 am.
Srinivas Natekar
Project Manager - Authentication
UNIQUE IDENTIFICATION AUTHORITY OF INDIA
L- 080-23099243, M-9620919782.
E-Mail- Srinivas...@uidai.net.in
Dear All,
Thanks for nominating yourself in Workshop, Entry pass are made available kindly be in present in 2nd floor Board room by 9.20 am.
Regards,
Srinivas Natekar
Project Manager - AuthenticationUNIQUE IDENTIFICATION AUTHORITY OF INDIA
L- 080-23099243, M-9620919782.
E-Mail- Srinivas.natekar@uidai.net.in
--
You received this message because you are subscribed to a topic in the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/aadhaar_rd/xsYNUbO50II/unsubscribe.
To unsubscribe from this group and all its topics, send an email to aadhaar_rd+unsubscribe@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/24b4591f-2e96-4934-bd14-ddb472547dae%40googlegroups.com.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+unsubscribe@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/CALmhGqXQ4iSwgNumZ_oAzhPy7HJH8kv14C%2BpHTaX8y1FKe%3Di%3DA%40mail.gmail.com.
Please help us understand if the new L1 specification will also call for integration of FaceAuth SDK as there is a report saying UIDAI will start Face Auth in “fusion mode” from 1st July 2018.
Warm Regards,
Ameya
E-Mail- Srinivas...@uidai.net.in
On Wednesday, 14 March 2018 22:53:32 UTC+5:30, natekar srinivas wrote:
Dear All,
workshop Time:- 9.30 to 12.00
Regards,
Srinivas Natekar
Project Manager - AuthenticationUNIQUE IDENTIFICATION AUTHORITY OF INDIA
L- 080-23099243, M-9620919782.
E-Mail- Srinivas...@uidai.net.in
On Wednesday, 14 March 2018 22:16:35 UTC+5:30, natekar srinivas wrote:
Dear All,
Please be informed that L1 workshop on Registered Devices is planned on 20th March,2018 at UIDAI Tech Centre, Bangalore.
Workshop is ONLY for those Device Vendors who are interested in L1 Registered devices certification. Only Technical person should be nominated for the workshop and Each company can nominate only 2 persons.
Pls send Participant details for Gate pass latest by 18th EOD to Srinivas...@uidai.net.in with below subject line.
Subject:- L1 Workshop <Company Name>- Gate pass
Pls Note:- Request will not be accepted beyond stated date.
Venue:-
UIDAI Tech Centre,
NTI Layout, Tata Nagar, Kodigehalli,
Bangalore -560092.
Regards,
Srinivas Natekar
Project Manager - AuthenticationUNIQUE IDENTIFICATION AUTHORITY OF INDIA
L- 080-23099243, M-9620919782.
E-Mail- Srinivas...@uidai.net.in
On Wednesday, 22 November 2017 12:21:56 UTC+5:30, natekar srinivas wrote:
Dear All.
Whoever is completed with L1- Solution Architect Document Pls share on below Id's.
Srinivas Natekar
Project Manager - AuthenticationUNIQUE IDENTIFICATION AUTHORITY OF INDIA
L- 080-23099243, M-9620919782.
E-Mail- Srinivas...@uidai.net.in
On Monday, 17 July 2017 23:29:37 UTC+5:30, Jyjesh Thayyil wrote:Dear All,
Pl use this thread to provide your suggestions and queries on Level 1 compliance.
Regards,
Team UIDAI.
--
You received this message because you are subscribed to a topic in the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/aadhaar_rd/xsYNUbO50II/unsubscribe.
To unsubscribe from this group and all its topics, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/24b4591f-2e96-4934-bd14-ddb472547dae%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/CALmhGqXQ4iSwgNumZ_oAzhPy7HJH8kv14C%2BpHTaX8y1FKe%3Di%3DA%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to
aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/CACEk3ioM%3DdA%2BsZYBv1eWhZYOMOsVz1%3DMCtNkJzh5qyQKSvDTvQ%40mail.gmail.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/SN1PR13MB01734CB8D83AF67D635D8DD490AD0%40SN1PR13MB0173.namprd13.prod.outlook.com.
E-Mail- Srinivas.natekar@uidai.net.in
On Wednesday, 14 March 2018 22:53:32 UTC+5:30, natekar srinivas wrote:
Dear All,
workshop Time:- 9.30 to 12.00
Regards,
Srinivas Natekar
Project Manager - AuthenticationUNIQUE IDENTIFICATION AUTHORITY OF INDIA
L- 080-23099243, M-9620919782.
E-Mail- Srinivas.natekar@uidai.net.in
On Wednesday, 14 March 2018 22:16:35 UTC+5:30, natekar srinivas wrote:
Dear All,
Please be informed that L1 workshop on Registered Devices is planned on 20th March,2018 at UIDAI Tech Centre, Bangalore.
Workshop is ONLY for those Device Vendors who are interested in L1 Registered devices certification. Only Technical person should be nominated for the workshop and Each company can nominate only 2 persons.
Pls send Participant details for Gate pass latest by 18th EOD to Srinivas...@uidai.net.in with below subject line.
Subject:- L1 Workshop <Company Name>- Gate pass
Pls Note:- Request will not be accepted beyond stated date.
Venue:-
UIDAI Tech Centre,
NTI Layout, Tata Nagar, Kodigehalli,
Bangalore -560092.
Regards,
Srinivas Natekar
Project Manager - AuthenticationUNIQUE IDENTIFICATION AUTHORITY OF INDIA
L- 080-23099243, M-9620919782.
E-Mail- Srinivas.natekar@uidai.net.in
On Wednesday, 22 November 2017 12:21:56 UTC+5:30, natekar srinivas wrote:
Dear All.
Whoever is completed with L1- Solution Architect Document Pls share on below Id's.
Srinivas Natekar
Project Manager - AuthenticationUNIQUE IDENTIFICATION AUTHORITY OF INDIA
L- 080-23099243, M-9620919782.
E-Mail- Srinivas.natekar@uidai.net.in
On Monday, 17 July 2017 23:29:37 UTC+5:30, Jyjesh Thayyil wrote:Dear All,
Pl use this thread to provide your suggestions and queries on Level 1 compliance.
Regards,
Team UIDAI.
--
You received this message because you are subscribed to a topic in the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/aadhaar_rd/xsYNUbO50II/unsubscribe.
To unsubscribe from this group and all its topics, send an email to aadhaar_rd+unsubscribe@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/24b4591f-2e96-4934-bd14-ddb472547dae%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+unsubscribe@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/CALmhGqXQ4iSwgNumZ_oAzhPy7HJH8kv14C%2BpHTaX8y1FKe%3Di%3DA%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+unsubscribe@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/CACEk3ioM%3DdA%2BsZYBv1eWhZYOMOsVz1%3DMCtNkJzh5qyQKSvDTvQ%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+unsubscribe@googlegroups.com.
E-Mail- Srinivas...@uidai.net.in
On Wednesday, 14 March 2018 22:53:32 UTC+5:30, natekar srinivas wrote:
Dear All,
workshop Time:- 9.30 to 12.00
Regards,
Srinivas Natekar
Project Manager - AuthenticationUNIQUE IDENTIFICATION AUTHORITY OF INDIA
L- 080-23099243, M-9620919782.
E-Mail- Srinivas...@uidai.net.in
On Wednesday, 14 March 2018 22:16:35 UTC+5:30, natekar srinivas wrote:
Dear All,
Please be informed that L1 workshop on Registered Devices is planned on 20th March,2018 at UIDAI Tech Centre, Bangalore.
Workshop is ONLY for those Device Vendors who are interested in L1 Registered devices certification. Only Technical person should be nominated for the workshop and Each company can nominate only 2 persons.
Pls send Participant details for Gate pass latest by 18th EOD to Srinivas...@uidai.net.in with below subject line.
Subject:- L1 Workshop <Company Name>- Gate pass
Pls Note:- Request will not be accepted beyond stated date.
Venue:-
UIDAI Tech Centre,
NTI Layout, Tata Nagar, Kodigehalli,
Bangalore -560092.
Regards,
Srinivas Natekar
Project Manager - AuthenticationUNIQUE IDENTIFICATION AUTHORITY OF INDIA
L- 080-23099243, M-9620919782.
E-Mail- Srinivas...@uidai.net.in
On Wednesday, 22 November 2017 12:21:56 UTC+5:30, natekar srinivas wrote:
Dear All.
Whoever is completed with L1- Solution Architect Document Pls share on below Id's.
Srinivas Natekar
Project Manager - AuthenticationUNIQUE IDENTIFICATION AUTHORITY OF INDIA
L- 080-23099243, M-9620919782.
E-Mail- Srinivas...@uidai.net.in
On Monday, 17 July 2017 23:29:37 UTC+5:30, Jyjesh Thayyil wrote:Dear All,
Pl use this thread to provide your suggestions and queries on Level 1 compliance.
Regards,
Team UIDAI.
--
You received this message because you are subscribed to a topic in the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/aadhaar_rd/xsYNUbO50II/unsubscribe.
To unsubscribe from this group and all its topics, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/24b4591f-2e96-4934-bd14-ddb472547dae%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/CALmhGqXQ4iSwgNumZ_oAzhPy7HJH8kv14C%2BpHTaX8y1FKe%3Di%3DA%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/CACEk3ioM%3DdA%2BsZYBv1eWhZYOMOsVz1%3DMCtNkJzh5qyQKSvDTvQ%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/SN1PR13MB01734CB8D83AF67D635D8DD490AD0%40SN1PR13MB0173.namprd13.prod.outlook.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/af7a283c-68b7-4ddc-8e47-117b25b85c22%40googlegroups.com.
Hi There,
Please find the below doubts from this draft document
Section 6. Secure Boot and Secure Upgrade
How STQC will validate whether our device actually does secured boot and secured software upgrade ?
Whether Device Provider's self certification will be enough or whether STQC have some test cases for secured boot and secured s/w upgrade which will be executed as part of certification test?
Whether is it allowed to upgrade TEE secured Software for the in-field devices or not ?
Section 10. Reference design
There are two diagrams in this section. And, both explains about 2 chip solution.
If possible, can you please share the reference design for a single chip solution?
Section 11
1. what is the purpose of Sign1 ? (this section in draft explains about it. But it’s not used)
2. How management server can validate IDHash since the CI(k) is part of the device?
Thanks,
Kiruba
E-Mail- Srinivas...@uidai.net.in
On Wednesday, 14 March 2018 22:53:32 UTC+5:30, natekar srinivas wrote:
Dear All,
workshop Time:- 9.30 to 12.00
Regards,
Srinivas Natekar
Project Manager - AuthenticationUNIQUE IDENTIFICATION AUTHORITY OF INDIA
L- 080-23099243, M-9620919782.
E-Mail- Srinivas...@uidai.net.in
On Wednesday, 14 March 2018 22:16:35 UTC+5:30, natekar srinivas wrote:
Dear All,
Please be informed that L1 workshop on Registered Devices is planned on 20th March,2018 at UIDAI Tech Centre, Bangalore.
Workshop is ONLY for those Device Vendors who are interested in L1 Registered devices certification. Only Technical person should be nominated for the workshop and Each company can nominate only 2 persons.
Pls send Participant details for Gate pass latest by 18th EOD to Srinivas...@uidai.net.in with below subject line.
Subject:- L1 Workshop <Company Name>- Gate pass
Pls Note:- Request will not be accepted beyond stated date.
Venue:-
UIDAI Tech Centre,
NTI Layout, Tata Nagar, Kodigehalli,
Bangalore -560092.
Regards,
Srinivas Natekar
Project Manager - AuthenticationUNIQUE IDENTIFICATION AUTHORITY OF INDIA
L- 080-23099243, M-9620919782.
E-Mail- Srinivas...@uidai.net.in
On Wednesday, 22 November 2017 12:21:56 UTC+5:30, natekar srinivas wrote:
Dear All.
Whoever is completed with L1- Solution Architect Document Pls share on below Id's.
Srinivas Natekar
Project Manager - AuthenticationUNIQUE IDENTIFICATION AUTHORITY OF INDIA
L- 080-23099243, M-9620919782.
E-Mail- Srinivas...@uidai.net.in
On Monday, 17 July 2017 23:29:37 UTC+5:30, Jyjesh Thayyil wrote:Dear All,
Pl use this thread to provide your suggestions and queries on Level 1 compliance.
Regards,
Team UIDAI.
--
You received this message because you are subscribed to a topic in the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/aadhaar_rd/xsYNUbO50II/unsubscribe.
To unsubscribe from this group and all its topics, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/24b4591f-2e96-4934-bd14-ddb472547dae%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/CALmhGqXQ4iSwgNumZ_oAzhPy7HJH8kv14C%2BpHTaX8y1FKe%3Di%3DA%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/CACEk3ioM%3DdA%2BsZYBv1eWhZYOMOsVz1%3DMCtNkJzh5qyQKSvDTvQ%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/SN1PR13MB01734CB8D83AF67D635D8DD490AD0%40SN1PR13MB0173.namprd13.prod.outlook.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/af7a283c-68b7-4ddc-8e47-117b25b85c22%40googlegroups.com.
------------------------------------------------------------------From:kirubakaran <kirubakara...@techrizes.net>Time:2018 May 8 (Tue) 17:49To:aadhaar_rd <aadha...@googlegroups.com>Subject:RE: [aadhaar_rd] Re: Suggestions and Queries on L1 compliance - Draft L1 specs
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/0a8401d3e6c6%24b582aef0%2420880cd0%24%40techrizes.net.
------------------------------------------------------------------From:kirubakaran <kirubakaran.selvaraj@techrizes.net>
Time:2018 May 8 (Tue) 17:49To:aadhaar_rd <aadha...@googlegroups.com>Subject:RE: [aadhaar_rd] Re: Suggestions and Queries on L1 compliance - Draft L1 specs
Hi There,
Please find the below doubts from this draft document
Section 6. Secure Boot and Secure Upgrade
How STQC will validate whether our device actually does secured boot and secured software upgrade ?
Whether Device Provider's self certification will be enough or whether STQC have some test cases for secured boot and secured s/w upgrade which will be executed as part of certification test?
Whether is it allowed to upgrade TEE secured Software for the in-field devices or not ?
Section 10. Reference design
There are two diagrams in this section. And, both explains about 2 chip solution.
If possible, can you please share the reference design for a single chip solution?
Section 11
1. what is the purpose of Sign1 ? (this section in draft explains about it. But it’s not used)
2. How management server can validate IDHash since the CI(k) is part of the device?
Thanks,
Kiruba
E-Mail- Srinivas.natekar@uidai.net.in
On Wednesday, 14 March 2018 22:53:32 UTC+5:30, natekar srinivas wrote:
Dear All,
workshop Time:- 9.30 to 12.00
Regards,
Srinivas Natekar
Project Manager - AuthenticationUNIQUE IDENTIFICATION AUTHORITY OF INDIA
L- 080-23099243, M-9620919782.
E-Mail- Srinivas.natekar@uidai.net.in
On Wednesday, 14 March 2018 22:16:35 UTC+5:30, natekar srinivas wrote:Dear All,
Please be informed that L1 workshop on Registered Devices is planned on 20th March,2018 at UIDAI Tech Centre, Bangalore.
Workshop is ONLY for those Device Vendors who are interested in L1 Registered devices certification. Only Technical person should be nominated for the workshop and Each company can nominate only 2 persons.
Pls send Participant details for Gate pass latest by 18th EOD to Srinivas...@uidai.net.in with below subject line.
Subject:- L1 Workshop <Company Name>- Gate pass
Pls Note:- Request will not be accepted beyond stated date.
Venue:-
UIDAI Tech Centre,
NTI Layout, Tata Nagar, Kodigehalli,
Bangalore -560092.
Regards,
Srinivas Natekar
Project Manager - AuthenticationUNIQUE IDENTIFICATION AUTHORITY OF INDIA
L- 080-23099243, M-9620919782.
E-Mail- Srinivas.natekar@uidai.net.in
On Wednesday, 22 November 2017 12:21:56 UTC+5:30, natekar srinivas wrote:
Dear All.
Whoever is completed with L1- Solution Architect Document Pls share on below Id's.
Srinivas Natekar
Project Manager - AuthenticationUNIQUE IDENTIFICATION AUTHORITY OF INDIA
L- 080-23099243, M-9620919782.
E-Mail- Srinivas.natekar@uidai.net.in
On Monday, 17 July 2017 23:29:37 UTC+5:30, Jyjesh Thayyil wrote:Dear All,
Pl use this thread to provide your suggestions and queries on Level 1 compliance.
Regards,
Team UIDAI.
--
You received this message because you are subscribed to a topic in the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/aadhaar_rd/xsYNUbO50II/unsubscribe.
To unsubscribe from this group and all its topics, send an email to aadhaar_rd+unsubscribe@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/24b4591f-2e96-4934-bd14-ddb472547dae%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+unsubscribe@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/CALmhGqXQ4iSwgNumZ_oAzhPy7HJH8kv14C%2BpHTaX8y1FKe%3Di%3DA%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+unsubscribe@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/CACEk3ioM%3DdA%2BsZYBv1eWhZYOMOsVz1%3DMCtNkJzh5qyQKSvDTvQ%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.
------------------------------------------------------------------From:kirubakaran <kirubakara...@techrizes.net>
Time:2018 May 8 (Tue) 17:49To:aadhaar_rd <aadha...@googlegroups.com>Subject:RE: [aadhaar_rd] Re: Suggestions and Queries on L1 compliance - Draft L1 specs
Hi There,
Please find the below doubts from this draft document
Section 6. Secure Boot and Secure Upgrade
How STQC will validate whether our device actually does secured boot and secured software upgrade ?
Whether Device Provider's self certification will be enough or whether STQC have some test cases for secured boot and secured s/w upgrade which will be executed as part of certification test?
Whether is it allowed to upgrade TEE secured Software for the in-field devices or not ?
Section 10. Reference design
There are two diagrams in this section. And, both explains about 2 chip solution.
If possible, can you please share the reference design for a single chip solution?
Section 11
1. what is the purpose of Sign1 ? (this section in draft explains about it. But it’s not used)
2. How management server can validate IDHash since the CI(k) is part of the device?
Thanks,
Kiruba
E-Mail- Srinivas...@uidai.net.in
On Wednesday, 14 March 2018 22:53:32 UTC+5:30, natekar srinivas wrote:
Dear All,
workshop Time:- 9.30 to 12.00
Regards,
Srinivas Natekar
Project Manager - AuthenticationUNIQUE IDENTIFICATION AUTHORITY OF INDIA
L- 080-23099243, M-9620919782.
E-Mail- Srinivas...@uidai.net.in
On Wednesday, 14 March 2018 22:16:35 UTC+5:30, natekar srinivas wrote:Dear All,
Please be informed that L1 workshop on Registered Devices is planned on 20th March,2018 at UIDAI Tech Centre, Bangalore.
Workshop is ONLY for those Device Vendors who are interested in L1 Registered devices certification. Only Technical person should be nominated for the workshop and Each company can nominate only 2 persons.
Pls send Participant details for Gate pass latest by 18th EOD to Srinivas...@uidai.net.in with below subject line.
Subject:- L1 Workshop <Company Name>- Gate pass
Pls Note:- Request will not be accepted beyond stated date.
Venue:-
UIDAI Tech Centre,
NTI Layout, Tata Nagar, Kodigehalli,
Bangalore -560092.
Regards,
Srinivas Natekar
Project Manager - AuthenticationUNIQUE IDENTIFICATION AUTHORITY OF INDIA
L- 080-23099243, M-9620919782.
E-Mail- Srinivas...@uidai.net.in
On Wednesday, 22 November 2017 12:21:56 UTC+5:30, natekar srinivas wrote:
Dear All.
Whoever is completed with L1- Solution Architect Document Pls share on below Id's.
Srinivas Natekar
Project Manager - AuthenticationUNIQUE IDENTIFICATION AUTHORITY OF INDIA
L- 080-23099243, M-9620919782.
E-Mail- Srinivas...@uidai.net.in
On Monday, 17 July 2017 23:29:37 UTC+5:30, Jyjesh Thayyil wrote:Dear All,
Pl use this thread to provide your suggestions and queries on Level 1 compliance.
Regards,
Team UIDAI.
--
You received this message because you are subscribed to a topic in the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/aadhaar_rd/xsYNUbO50II/unsubscribe.
To unsubscribe from this group and all its topics, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/24b4591f-2e96-4934-bd14-ddb472547dae%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/CALmhGqXQ4iSwgNumZ_oAzhPy7HJH8kv14C%2BpHTaX8y1FKe%3Di%3DA%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/CACEk3ioM%3DdA%2BsZYBv1eWhZYOMOsVz1%3DMCtNkJzh5qyQKSvDTvQ%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to
--
You received this message because you are subscribed to the Google Groups "Aadhaar Registered Devices Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aadhaar_rd+...@googlegroups.com.
To post to this group, send email to aadha...@googlegroups.com.
Visit this group at https://groups.google.com/group/aadhaar_rd.
To view this discussion on the web visit https://groups.google.com/d/msgid/aadhaar_rd/77277c03-ce79-4cb5-b5c9-a6c979e8bd7e%40googlegroups.com.