Mobile-ID / Certificates & scope
RAR/C06 · eID / SSO / ShareInfoISO/IEC 24745:2022
Phase 7 publication editionPOL-DEVICE-TRUST

Device trust

Manage devices from model selection through activation, maintenance, replacement and revocation.

Full public textOrganization/contract scoped

This is the full text published in the Phase 7 package. Effective dates, responsible contacts and contract-specific parameters are maintained in the corresponding release and deployment records.

01

Device record and intake

Each device record identifies model, supplier, serial, firmware/SDK versions, capture capabilities and compatibility scope. RGB/IR, PAD, edge processing, secure boot or secure elements are marked supported only where model evidence establishes them. The organization and Mobile-ID agree installation, power, network, environment and purpose before activation.

02

Registration and activation

Activation binds the device to the approved organization, location and configuration. Verify software provenance and operator authority; issue an identity/certificate if the architecture uses one. Unchecked, revoked or incompatible devices do not proceed through normal operations. Retain approval and version evidence.

03

Session-bound capture

Capture requests are bound to a fresh session, purpose and device. Apply configured quality/PAD checks; a device certificate alone does not prove liveness or identity. Transfer outputs under the approved protocol, limit buffers and exclude biometrics from ordinary diagnostic logs. Old capture cannot be reused as fresh presence.

04

Configuration and updates

Firmware, SDK, algorithm and threshold changes need compatibility/data assessment, testing and approval. Verify update integrity and provenance under device capabilities; offline updates still require controlled handover. Retain prior versions, rollback conditions and logs; do not introduce unverified packages into production.

05

Health monitoring and exceptions

Monitor connectivity, capture errors, configuration, certificate expiry and maintenance indicators where supported. Health records exclude unnecessary images or references. If assurance conditions fail, use assistance or another verification method rather than silently bypassing PAD or lowering thresholds to increase success rates.

06

Maintenance and supplier access

Maintenance cases identify faults, technicians, access permissions and residual data. Suppliers have no automatic right to vaults or identity records; access needs customer authorization and appropriate oversight. Address device-resident data before repair shipment and record custody. Warranty/RMA terms come from agreements, not proposed cooperation diagrams.

07

Replacement, revocation and retirement

Replacement creates a new device record and disconnects the old device's authority under the architecture. Revoking certificates/access does not prove all data copies are deleted; execute and verify separate data-disposition tasks. Prevent retired devices reconnecting with old configuration. End-of-lease/loan/supply records account for assets, data and access.

08

Lifecycle accountability and evidence

The responsibility matrix distinguishes hardware/firmware supply, Mobile-ID integration/administration and customer on-site operations under agreement. Records cover intake, configuration, access issuance, updates, maintenance and revocation. Missing model, PAD or compatibility evidence is disclosed before deployment; a configuration button does not establish support.

Responsibility & deployment annex

Detailed responsibilities are determined by activity and deployment records; this public document does not replace customer-specific contractual annexes.

  • The relying organization defines business purposes, populations and operational authority within the deployment.
  • Mobile-ID supplies and operates components within the agreed scope, including integration, control configuration and related evidence.
  • Device suppliers support models, firmware, SDKs and maintenance within authorization; data access is never implicit.
  • Legal, security and service ownership assignments are maintained in each organization’s operating records.

Execution and evidence cycle

  1. Record purpose, organization, data/device scope and the business reference.
  2. Verify authority, applicable conditions, configuration and relevant obligations.
  3. Execute with data minimization, authorization and necessary evidence.
  4. Close with confirmations from relevant systems, response handling and remaining exceptions.

Legal and reference sources

Detailed obligations, periods and exceptions apply according to law, contract and the actual service configuration.

Contact about applicability

Send contact details and a general question only; sensitive records require a confirmed channel.

info@mobile-id.vn

Search Trusted Palm ID

Selected interface