IDMETRIX
Secure Identity
Device Management

IDmetrix® Device Management Platform (DMP)

One command centre for every enrolment station, kiosk, verification terminal and gate in the programme — wherever in the country they are deployed.

In a national identity programme every device is a critical asset. They are geographically dispersed, they run different operating systems, and each one is a place where data can be compromised or a service can quietly stop. The Device Management Platform puts the whole fleet under one authority: a web command centre inside the government’s own data centre, a hardened agent on every device, and a mutually authenticated channel between them.

Zero-trust, mutually authenticated TLS 1.3+

99.9%

Availability target

TLS 1.3+

Mutual authentication

3 OS families

Windows, Android, Linux

On-premise

Or private sovereign cloud

Capabilities

What the platform does

Real-time operations map

Every device on a national map with a colour-coded status — active, maintaining, locked — drilled down from the country to the region, the city and the individual unit.

Executive KPIs and metrics

System-wide uptime and device health scores, enrolment throughput and success rates, and the security and compliance posture of the fleet.

Role-based operational views

A country-wide strategic overview for national administrators, jurisdiction performance for regional directors, and device-level technical detail for IT support — with menu-level permissions behind each role.

Unified alert management

One consolidated view of every critical incident, with priority-based routing and escalation, and integration into email, SMS and SIEM systems.

Device and component registry

Each unit is tracked from loaded to active, maintaining, locked and retired — down to its main board, face and fingerprint modules and card reader, with installation, removal, maintenance and warranty history against every part.

Intelligent geofencing

A device that leaves its authorized zone locks itself, and the violation is reported in real time with its location.

Port and tamper protection

USB ports are blocked, made read-only or whitelisted; Bluetooth and wireless interfaces are managed; hardware tamper switches and control-box door sensors are monitored and every unauthorized access attempt is logged.

Secure over-the-air updates

Digitally signed firmware and software, delivered encrypted to certificate-authenticated devices, rolled out in stages with automatic rollback, delta transfers and scheduled maintenance windows.

Integration with national systems

A RESTful integration fabric carries device and operational data to the ABIS, the civil registry, SSO, SIEM and ITSM systems already in place.

Scheme of work

Four layers, one chain of trust

The platform is sovereign by design: it runs in the state’s own data centre, and nothing between the command centre and a device is unauthenticated.

  1. 1Web Command CenterGovernance, inventory, tasks, logs
  2. 2Secure GatewayMutual TLS 1.3+
  3. 3Secure Device AgentOn every managed unit
  4. 4Managed fleetStations, kiosks, terminals, gates
The central nervous system of the identity ecosystem
Visualized and centralized

The central nervous system of the identity ecosystem

Enrolment devices, self-service kiosks, travel document identification terminals and automated border control gates all report into the same command centre, and the data centre behind it is the state’s own — on-premise or private cloud.

From data to decisive action
Centralized dashboard

From data to decisive action

Production and personalization throughput, document stock and dispensing, device ranking and equipment groups — each role sees the operational picture it is accountable for, on a wall display or at a desk.

Deployment

Primary and backup, inside your own perimeter

A microservices architecture runs as a primary node — management system, task, API, document and database services — shadowed by a backup node on a real-time replicated database, for a 99.9% availability target. Administrators reach it through the command centre in the browser; devices reach it through the secure gateway, and answer with their status, their tasks and their errors.

AdministratorsNational, regional, IT supportBrowser, role-based accessWeb command centreGovernance, inventory, tasks, logs
Management and policies

Sovereign data centre

On-premise or private cloud
Primary node
  • Management systemCommand centre back end
  • Task serviceJobs, updates, commands
  • API serviceRESTful integration fabric
  • Document storeDistributed file service
  • DatabaseDevices, components, logs
Real-time replication
Backup node
  • System managementTakes over on failover
  • Task serviceStandby worker
  • Document storeMirrored file service
  • DatabaseReal-time replica
Service discoveryDevices find the node that is serving
Secure gatewayMutually authenticated TLS 1.3+
Status, tasks, warnings, errors

Managed device fleet

Secure agent on every unit
  • Enrolment stationsPlatform agent
  • Self-service kiosksPlatform agent
  • Verification terminalsPlatform agent
  • Border control gatesPlatform agent
Specification

Platform specification

Platform

Deployment
On-premise or private cloud, for full data sovereignty
Architecture
Microservices-based, for scalability and resilience
High availability
  • Primary–backup servers with real-time database replication
  • 99.9% uptime target
Security model
Zero-trust, mutual TLS 1.3+ authentication between agent and gateway
Administration
  • Role-based access control with menu-level permissions
  • Full system and operator log monitoring
Integration
RESTful APIs to ABIS, civil registry, SSO, SIEM and ITSM systems

Managed operating systems

Windows
  • Active Directory group policy integration
  • Compliance with Intune security frameworks
  • Automated security baseline enforcement
  • Centralized credential and access management
  • BitLocker encryption enforcement
Android
  • Device Owner (DO) mode
  • Single-purpose kiosk lockdown
  • Controlled application whitelisting
  • System-level permission enforcement
  • Factory reset protection
Linux
  • Read-only root filesystem for critical devices
  • Secure boot
  • Minimal attack surface configuration
  • Custom security module integration

Over-the-air updates

Delivery
  • Digitally signed firmware and software packages
  • End-to-end encryption of every update transmission
  • Certificate-based device authentication
Rollout
  • Staged, progressive deployment
  • Automatic rollback on failure detection
  • Bandwidth-optimized delta updates
  • Maintenance window scheduling
Assurance
  • Pre-update device health checks
  • Update compliance verification
  • Success and failure reporting and analytics
  • Emergency update path
Field conditions
  • Resilient to intermittent connectivity
  • Interrupted downloads resume
  • Battery-aware update timing
  • Regional update staging

Interested in this system?

Tell us about your issuance program and we will advise on the right configuration.

Get in Touch