Air-Gapped & On-Prem
Physical Media Transfer Protocols That Pass Audit
· 10 minute read
If the only record of how the weights entered the SDC is a WhatsApp to the vendor engineer, you do not have an air gap. You have a USB stick with anecdotes.
Every honest air gap eventually becomes a logistics problem. Weights, container images, OS patches, licence files and, more rarely, outbound exports for a court or a CERT-In request have to cross a physical or one-way boundary. The boundary is only as defensible as the docket that travelled with the disk.
Auditors in Indian public institutions are good at dockets. They are less used to model artefacts. They will still ask the same questions they ask of a treasury tape: who wrote it, who carried it, who checked the seal, who verified the hash, who loaded it, who watched, where the disk is now, and what was destroyed. If you cannot answer, the air gap is a story.
This guide is a protocol you can attach to an SDC SOP or a district NIC room order. It is not a classified-network accreditation. Defence and certain intelligence environments will have stricter rules you must not dilute. For a typical state data centre, university DC or collectorate rack, this is the minimum that survives a later file inspection.
Two rooms, not one pendrive
Create a dirty room and a clean room, even if both are only cages or labelled benches. The dirty room receives vendor media, internet-connected laptops used to download from a vendor portal, and anything that has been outside. The clean room only receives media that has already been scanned, hashed and resealed. The processing VLAN only mounts media that left the clean room.
Never let the vendor engineer plug their own stick into a clean host to save time. That sentence is how most air gaps die. If they must be present, they watch. They do not insert. Prefer write-once or tamper-evident media for inbound artefacts. Reusable USB sticks are convenient and therefore dangerous. If you must reuse, wipe with a recorded method and treat the wipe as a step, not a habit.
| Step | Who | What the file keeps |
|---|---|---|
| Build artefact on vendor or staging side | Vendor + department technical owner | Manifest: files, versions, SHA-256, build id, signed by vendor |
| Write media, seal, number | Two people, dirty room | Bag number, time, names, photograph of seal |
| Courier or hand carry | Named carrier or government bag | Despatch number, expected arrival, tamper note |
| Receive, check seal, re-hash | Two people, dirty room | Match to manifest. Mismatch stops the load. |
| Malware / content scan on isolated scanner | SDC security | Scanner version, signatures date, result |
| Copy to clean media, reseal | Two people | New bag number. Dirty media quarantined or destroyed. |
| Load on clean system | Admin + watcher | Change ticket, before/after checksum on the store |
| Return or destroy media | Named officer | Destruction certificate or return docket |
Hashes are the sentence that makes the rest true
A manifest without hashes is a packing list. A hash without a second person reading it aloud is a suggestion. Compute SHA-256 or the algorithm your SDC already standardises on the writing side and the receiving side. Read them out. File both printouts. If they differ, the media did not transfer. It mutated or it was swapped. Do not try the load anyway.
Sign the manifest. A vendor PDF with a logo is not a signature. Use the same class of signature you would accept on an invoice — DSC, or a wet ink name with ID that your finance already recognises — and keep the public key or the ID copy in the vendor file. For container images, hash the tar or the digest list, not only the USB volume label. For model weights, hash each shard. The load should fail if a digest is missing from the internal registry.
Outbound media is rarer and more dangerous
Inbound weights are uncomfortable. Outbound logs or sample tickets are worse, because they can carry personal data out of the perimeter you just spent a crore protecting. Default deny outbound media. When a court, a CERT-In request, or a genuine debug need requires a copy, treat it as a transfer decision.
Redact first. Prefer aggregated metrics and stack traces without prompt text. If prompt text is required, take the minimum, key it, put it on clean media, dual-control the bag, and set a return-or-destroy date. The DPO signs. The CISO signs. A vendor engineer does not decide this at 11pm. CERT-In's 180-day log duty is a reason to keep logs inside Indian jurisdiction, not a reason to hand a raw SIEM export to whoever asks.
- No unofficial I'll take a copy home to debug.
- No personal USB, no phone USB, no vendor laptop as media.
- No outbound bag without a DPO or CISO signature.
- No reusable stick that also holds family photographs.
- No WhatsApp of checksums as the only record — print or ticket as well.
Objections you will hear — and what to do with them
These are the lines that stall the file. Answer them in the room, then put the answer in the note. A spoken answer without paper will be forgotten by the next officer.
This will slow every patch.
Yes. That is the trade. If you need weekly patches, you need a staffed dirty room and a standing courier pattern, not a skipped hash. Speed without a docket is how you will explain a bad binary later.
Our diode / one-way transfer box replaces all of this.
A diode is a good pump. It is not a manifest, a scan, a dual control or a destruction certificate. Keep the protocol. Let the diode be one transport.
Classification rules already cover this.
If you are on a classified network, follow those rules and ignore any lighter sentence in this article. Most collectorate and university racks are not classified, and therefore have no protocol at all. That gap is what this is for.
Stand up a media desk in fifteen working days
- Days 1–3: name the dirty bench, the clean bench, the scanner host that never joins the processing VLAN, and two officers who must both be present for a seal.
- Days 4–7: publish the manifest template (files, versions, hashes, signatures) and refuse any vendor artefact that does not use it.
- Days 8–11: run a dry transfer of a dummy file end to end. File the dummy docket as the training piece.
- Days 12–15: write the outbound-media ban, the exception signature block, and the destruction method. Brief the night staff. Put the SOP number in the RFP annexure.
How this shows up in the file
Keep a register, paper or ticket, with one line per bag: number, direction, hashes, names, times, ticket, destruction. The register is the air gap's memory. A folder of informal emails is not.
When the auditor asks how did this model get here, you should be able to hand them one numbered page. If you cannot, the protocol does not exist yet.
What an auditor will actually ask
They will pick one production model file and walk backwards. Who signed the manifest. Which bag number. Which courier docket. Which two names appear on the receive line. Which scanner version. Which clean-bag number. Which change ticket loaded it. Which hash now sits on the store. Which bag was destroyed. If any answer is the vendor engineer would know, you have a finding.
They will also ask about outbound. Show the register's empty-or-rare outbound lines. Show the DPO signature on the one exception. Show the destroy-by date and the certificate. An outbound bag with no return is a transfer with a handle.
Couriers, district bags and monsoon reality
A state with thirty sites cannot pretend every bag is hand-carried by a joint director. Use a government bag service or a named courier with tamper-evident seals, expected arrival, and a rule that a late or wet bag is not loaded — it is re-hashed and, if doubtful, re-issued. Monsoon is a design input. Print two manifests. Keep one at HQ. Put a hash on the ticket system before the bag leaves.
Destruction is a step, not a drawer
Dirty media piles up in a drawer labelled old. That drawer is an unindexed store of model weights and, if anyone cheated, of sample tickets. Schedule a monthly destruction with two people, a method, and a line in the register. If you cannot destroy, you cannot claim a chain. You can only claim a pile. Vendors who want their SSD back may have it back after wipe and a note. They may not have it back as is because they are flying the next morning.
This article is informational field guidance for Indian public institutions, not legal, procurement, security-accreditation or engineering advice. Confirm against the current Gazette, CERT-In direction, GFR, GeM term, SDC policy and your counsel before you file it.
Questions this usually raises
- Is a hashed email download on an SDC laptop an acceptable inbound path?
- Only as a dirty-room step, on a host that never joins the processing VLAN, followed by scan, re-hash and clean media. Downloading straight onto a GPU node is not a protocol.
- What hash should we use?
- Use whatever your SDC already standardises; SHA-256 is the usual floor. The algorithm matters less than computing it on both sides and filing both values.
- Can we send sample tickets out on media so the vendor can improve quality?
- Not by default, and not with unique personal data. Prefer synthetic tickets. If a lawful debug requires samples, the DPO and CISO sign a minimum set with a destroy-by date.
- Do CERT-In log rules require us to export logs to the vendor?
- No. They require you to maintain logs for 180 days in Indian jurisdiction and to produce them when lawfully required. Exporting raw logs to a vendor is a separate, usually bad, decision.