In re Pagaria Infotech Ventures LLP (CAAR Mumbai)
M/s. Pagaria Infotech Ventures LLP (hereinafter referred to as ‘the applicant’, in short) filed an application for advance ruling before the Customs Authority for Advance Rulings, Mumbai (CAAR, in short). The said application was received in the secretariat of the CAAR, Mumbai on 26.12.2022, along with its enclosures in terms of Section 28H (1) of the Customs Act, 1962 (hereinafter referred to as the ‘Act’). The applicant is seeking advance ruling on the classification of ‘Cryptogenic Device/Token’ (ProxKey and ProxKey PRO) (hereinafter referred to as ‘subject goods’), proposed to be imported and applicability of Sr. No. 2 of Notification No. 24/2005-Customs, dated 01.03.2005 , as amended.
2. The applicant is a registered LLP (Limited Liability Partnership) company involved in the business of trading. The applicant is intending to import ‘Cryptogenic Device/Token’ (ProxKey and ProxKey PRO) (herein after referred as ‘subject goods’). In their submissions the applicant has stated the following:
2.1 Both ProxKey & ProxKey PRO represent the same product with same functions, technical specification with different brand name on hardware and its associated middleware/drivers & physical appearance in terms of color.
2.2 Products Overview, Features & Appearance-:
a. Cryptographic Device/Token is very portable, easy-to-use and cost-effective solution for strong authentication, secure access and online transactions. It features a plug-and-play capability that brings convenience to end users and is designed to meet the demand for secure, fast and reliable external tokens with built-in secure mechanisms and designed to function with computer systems and automated data processing machined with varied configurations and operating systems.
b. They are among the securest and lightest cryptographic USB tokens in the world, complying with the most stringent international standards, like ISO 7816 4, 8, 9, FIPS140-2 certified and possesses the most reliable encrypting capabilities like DES, 3DES and RSA. The chip embedded in the device is a highly secure data container as the private key stored on the chip and can never be exported. With this device, users can access web-based applications, corporate networks and carry out online transactions easily, conveniently for consumers; the convenience of a robust yet simple “plug and-play” solution is unbeatable
c. The products also embodie an internal SPI Flash simulating CD-ROM for Auto Run Plug & Play feature, which provides the software package of mini-driver and allows the user to have a convenient experience.
2.3 Products Usage & Functioning
a. The products closely resemble to USB Flash Drives/ Pen drive as covered under heading 8523 in physical appearance only but its functions, specifications & usage cannot even be remotely linked to USB Flash Drives/ Pen drive.
b. The products used to generate the private key of digital signature which in turn is securely retained in the device and is used to authenticate an electronic record function, using the process of asymmetric cryptography and hash. The Information Technology Act, 2000 (ITA) defines a “digital signature” to mean authentication of any electronic record by a subscriber by means of an electronic method or procedure in accordance with the provisions of Section 3 of the ITA.
c. Rule 3 of the Information Technology (Certifying Authorities) Rules, 2000 (extracted below for ready reference) specifies the manner in which information is to be authenticated by means of a digital signature viz., hash function. It would be observed there from that the digital signature shall be created and verified by the process of hash function using asymmetric cryptography. “Asymmetric crypto system” is defined in Section2(1) (f) of the ITA to mean a system of a secure key pair consisting of a private key for creating a digital signature and a public key to verify the digital signature.
d. The manner in which information be authenticated by means of Digital Signature. – A Digital Signature shall: –
(a) Be created and verified by cryptography that concerns itself with transforming Electronic record into seemingly unintelligible forms and back again;
(b) Use what is known as “Public Key Cryptography”, which employs an algorithm using two different but mathematical related “keys” — one for creating a Digital Signature or transforming data into a seemingly unintelligible form, and another key for verifying a Digital Signature or returning the electronic record to original form, the process termed as hash function shall be used in both creating and verifying a Digital Signature.
e. Further the Information Technology Act 2000, mandates that the key pair of the user must be mandatorily generated on the FIPS -140-2 Level 2 validated cryptographic Module / Hardware. The Federal Information Processing Standard [FIPS] 140-2 is a U.S. government computer security standard used to approve cryptographic modules. The National Institute of Standards and Technology (NIST) issued the FIPS 140 Publication Series to coordinate the requirements and standards for cryptography modules that include both hardware and software components. Protection of a cryptographic module within a security system is necessary to maintain the confidentiality and integrity of the information protected by the module. This standard specifies the security requirements that will be satisfied by a cryptographic module.
f. The products barely have only 1 critical component which determines the functioning of the product i.e. AS518 in the form of Crypto processor IC mounted on the PCB version no K023314A having an USB Interface. AS518 series is a high-performance 32-bit micro-processor based on ARM Cortex-M. The IC has its own RAM, Memory, CPU and various interfaces like USB, SPI, and UART. The IC has built-in hardware algorithm coprocessor provides excellent performance DES/3DES, AES, SHA, RSA, ECC and other security algorithm module for signing, encryption and authentication. In common parlance these IC’s together with all its embedded components, firmware and algorithms are also referred to as Crypto Modules, Crypto Processors, Co Processors, Crypto CPU. This Crypto IC along with its PCB version, Firmware and physical body are validated for FIPS 140-2 Cryptographic Module Validation Program. The various algorithms like DES, AES, RSA, ECDSA, HMAC, SHA, DRBG which the crypto processor support are approved by FIPS – Cryptographic Algorithm Validation Program [CAVP]. The, Crypto processor, PCB, USB Interface, Led Indicator, Plastic enclosure along with its firmware, driver and middleware together form the final product under discussion i.e. Cryptographic Device / Token
g. Sec 3 of IT Act 2000 provides for “Authentication of Online record by affixing a Digital Signature”. The Gazette Notification 735(E) dated 24th October 2004 which contains the Rules to be read in conjunction with section 16 of the IT Act 2000 defines the Secure Electronic Record to be one that has been authenticated by means of a Secure Digital Signature. To create a Secure Digital Signature a hardware token with cryptographic module has be used to create the key pair. The content to be signed /encrypted should go from the host system to the cryptographic device and the signed /encrypted content to be returned to the host system. The products are one such hardware token device with cryptographic processor to be used for the purpose and mentioned aforesaid. Further it is also submitted that user’s private and public key pairs can be generated and retained only on the memory of the Crypto Processor / Module. The Crypto Processor / Module has very limited memory of 256 KB out of which only 64KB can be used to store the user’s private and public key pairs. The user’s key pairs reside in the memory of the Crypto Processor / Module and the private keys can never be exported.
h. The products are used for digital signature authentication/identification purposes using a system of a secure key pair consisting of a private key for creating a digital signature and a public key to verify the digital signature using the cryptographic modules / Crypto Processor / Crypto CPU and validated algorithms.

i. The products cannot be operated on a standalone basis and it should be operated along with a computer system for its authentication and identification. The products when connected with the computer or ADP read the data embedded in the device and send the information to the network / server to get the authentication for the transaction. Thus it means that mere token/device alone is not sufficient and it has to get connected to the computer system to access the network / server to send the details for its authentication / identification. Cryptographic Device cannot work without an ADPS.
j. Rule 2 of the Information Technology (Security Procedure) Rules, 2004 defines “hardware token” to mean a token which can be connected to any computer system using Universal Serial Bus (USB) port.” Thus the IT law itself recognizes the Cryptographic Device as a device, which is connected to the computer system by using USB port
k. The products have an auto run plug and play feature which when connected to the ADPS automatically install the drivers / middleware of the product which are preloaded in the memory of the product. The memory is 2MB in size and contains only the drivers / middleware of the product which is loaded from the factory during production. This memory is out of the scope of the crypto processor and in no manner impact, enhances, reduce the function and performance of the device core functionality. The driver and middleware preloaded in the product pertains to the product only and cannot be used for any other purpose or as general purpose software. The user of the product in no manner can add, erase or modify any content in this memory.
2.4 The applicant wished to classify goods under heading 8471 80 00 – Other units of automatic data processing machines or 8473 30 99- Others – Parts and accessories of the machines heading 8471 (ADPS) and also eligible to avail benefit under Sr. 2 of Notification No 24/2005- Customs
1. The applicant hereby submitted of following statements with respect to Interpretation of Law for classification of product ‘Cryptographic Device/Token’-:
3.1 To determine the CTH of the goods reference is hereby made to the Rule 1 of ‘general rules for the interpretation of the harmonized system’ (GIR) which states as under:
“The titles of Sections, Chapters and sub-Chapters are provided for ease of reference only; for legal purposes, classification shall be determined according to the terms of the headings and any relative Section or Chapter Notes and, provided such headings or Notes do not otherwise require, according to the following provisions”
It is further submitted that the as per Rule 1 of ‘General rules for the interpretation of the harmonized system’ the headings, relative section or chapter notes should be applied first to determine the classification of goods. Also subsequent rules should be referred only when the classification cannot be done in accordance with Rule 1. Thus is clear that as principles laid down in GIR, for legal purposes, classification of goods shall be determined according to the terms of the headings and any relative Section or Chapter Notes. The goods under consideration are classified with reference to the headings and any relative Section or Chapter Notes.
3.2 For ease of reference, the relevant portions of CTH 8471 are reproduced as under:






