Ambimat GroupAmbimatAmbiSecureV2XeSIM & eUICCAmbiAutomationEngineering BlogAhmedabad · India · Est. 1982
Engineering blog

AmbiSecure Engineering Blog

Practical, code-first writing on hardware-rooted security. Current engineering content from the AmbiSecure team — FIDO, WebAuthn, JavaCard, DESFire, SAM-backed transit, passwordless rollouts, smart-card lifecycles. Each piece is written by someone who has shipped the thing they are writing about.

Latest engineering

2026-06-02

EU Cyber Resilience Act: What It Means for Connected Hardware and IoT Manufacturers

The EU Cyber Resilience Act (CRA) turns “ship it and patch later” into a regulated discipline for anything with a plug, a radio, or a…

Read article →
2026-06-02

CRA Vulnerability Handling and Product Lifecycle Security: What Manufacturers Need to Prepare

The Cyber Resilience Act's secure-by-design expectations get the headlines, but the part that reshapes day-to-day product operations is vulnerability…

Read article →
2026-06-02

Secure by Design Under the CRA: Why Hardware-Backed Trust Matters

“Secure by design” is the phrase in the Cyber Resilience Act that engineers can actually act on. It is not a paperwork requirement…

Read article →
2026-06-02

Mapping AmbiSecure Products to CRA Readiness: AmbiSEC, ONE Pass, BioKey and Secure Identity

The Cyber Resilience Act is a process and documentation obligation, not a product you can buy. But several CRA-aligned security needs &mdash…

Read article →
2026-05-28

Lava Lamps and Cryptographic Entropy: Inside the Wall of Entropy

A wall of lava lamps in a corporate lobby is the most photographed piece of cryptography infrastructure in the world. It is also one of the least…

Read article →
2026-05-26

Why Software-Only Device Trust Fails

The case for hardware-rooted identity in field-deployed devices is not "hardware is more secure than software". The case is sharper. The threat model…

Read article →
2026-05-26

Secure Elements in Connected Vehicles

The connected-vehicle threat model is not the laboratory threat model. The device sits in a chassis any owner, mechanic, or attacker can open. The…

Read article →
2026-05-26

Pseudonymous Certificates and Privacy in V2X

A vehicle that broadcasts position, speed, and heading ten times a second is broadcasting a movement profile. If those broadcasts are signed under a…

Read article →
2026-05-26

How V2X PKI Works: EA, AA, Pseudonymous Certificates, Lifecycle

V2X PKI looks superficially like web PKI: a root, intermediates, end-entity certificates, signatures over messages. Open it up and the resemblance…

Read article →
2026-05-26

Device Identity at Manufacturing Scale

A deployment of one device with one credential is an engineering exercise. A deployment of a million devices, each with a hardware-bound identity…

Read article →
2026-05-11

Why Transit Validators Need Offline Trust Architecture

Transit gates do not stop when the backend has a bad afternoon. Closed-loop ticketing depends on a trust model where the validator and the card…

Read article →
2026-05-11

How to Choose Between Smart Cards, FIDO Tokens and Passkeys

Three credential classes that look adjacent on a slide and behave very differently in production. This is the comparison the procurement spreadsheet…

Read article →
2026-05-11

Embedded Secure-Element FIDO2 Authenticators for Enterprise Identity.

An enterprise FIDO2 credential that lives inside a CC EAL6+ secure element packaged as a removable nano-card (4FF) or a solderable MFF2 module…

Read article →
2026-05-11

Building Secure IoT Identity with Security Applets.

Hardware-backed IoT identity isn’t one applet, it’s five. Provisioning, attestation, mTLS, signed firmware, key rotation — on a…

Read article →
2026-05-11

Secure Element vs TPM vs HSM — Where Each Fits

All three are "hardware that stores keys". They are not interchangeable. Picking the wrong one is the difference between a credential that works in…

Read article →
2026-05-11

PKI Credential Issuance for Workforce and Government Identity

Issuing X.509 credentials is the lowest-glamour part of building a hardware-identity programme and the part most likely to get the system into…

Read article →
2026-05-11

PIV Smart Cards vs USB Tokens vs Embedded Secure Elements.

The decision matrix isn’t about which is most secure — all three are. It’s about lifecycle, convergence, and what happens at…

Read article →
2026-05-11

JavaCard Applet Development for Enterprise Identity

Smart-card programmes hit a wall the moment the off-the-shelf applets don’t do quite what the enterprise needs. JavaCard is the answer. This is…

Read article →
2026-05-11

How FIDO Authentication Works

An explanation of how FIDO2 / WebAuthn actually works — what happens on your device, what happens on the server, and why the design is…

Read article →
2026-05-11

Where Your AmbiSecure FIDO Key Works

A practical, vendor-neutral overview of the platforms and services that accept FIDO2 / WebAuthn today. The list is large enough that "what works with…

Read article →
2026-05-11

Engineering ePassport Issuance and Identity Platforms.

An ePassport is a small system on a contactless chip and a much larger system in the issuing authority’s data centre. Both halves matter; this…

Read article →
2026-05-11

Designing Secure Email and Document Signing Platforms.

Server-side TLS protects the wire. Once the message lands, only a signature gives you cryptographic integrity that survives the transport, the…

Read article →
2026-05-11

Cyber Security Threats — What Actually Matters in 2026

A clear-eyed overview of the threats that drive identity and hardware-credential decisions today — written so a security lead can take it into…

Read article →
2026-05-11

Designing Secure Credential Lifecycle Management

Credential systems are usually designed around issuance. They fail in production around everything else — rotation, recovery, revocation…

Read article →
2026-05-09

Why SAMs matter in closed-loop transit systems.

A Secure Access Module is the unglamorous chip inside a transit validator that does the actual cryptography. The reader CPU never sees the issuer…

Read article →
2026-05-09

Why Hardware-Backed Identity Matters.

Software-only credentials look fine until you stack the threat surfaces. Hardware shifts the cost-per-extraction by orders of magnitude — and that is…

Read article →
2026-05-09

Understanding WebAuthn Attestation Objects.

A relying party that decodes attestation but never verifies it has a decorative pipeline. This is the engineer's walkthrough: what the structure…

Read article →
2026-05-09

Platform vs Roaming Authenticators.

Platform-bound and roaming authenticators are both first-class WebAuthn citizens. The deployment choice is operational: which form factor matches…

Read article →
2026-05-09

Passkeys vs Traditional MFA.

"MFA" was a strategy, not a primitive. Passkeys are the primitive. Origin binding, hardware boundary, no replayable secret. Here is what changes for…

Read article →
2026-05-09

Designing low-latency secure transit validators.

Tap-to-decision under 300 milliseconds. Mutual authentication. Transaction MAC. Audit write. Gate actuation. The same gate makes that decision tens…

Read article →
2026-05-09

Designing Enterprise Passwordless Systems.

WebAuthn is well-specified and library-supported. Anyone can stand up a demo in a weekend. What separates a demo from a production deployment is the…

Read article →
2026-05-09

DESFire EV1 vs EV2 vs EV3 — an architectural evolution.

Three generations of the same platform spaced over twelve years. Each refines the same trust model, but the operational consequences for what you…

Read article →
2026-05-09

APDU from First Principles: CLA, INS, P1/P2, Le, Lc, and SW1/SW2

If you have ever poked at a smart card with PC/SC, gpshell, or OpenSC, you have seen a stream of hex bytes labelled APDUs. This is what those bytes…

Read article →
2025-01-20

Implementing FIDO2 Authentication: A Complete Developer Guide

Passwords are one of the biggest security risks for modern systems. FIDO2 is what comes next — phishing-resistant, hardware-bound credentials…

Read article →
2023-05-15

Using ethical hackers to protect firm data

Cybersecurity assaults are becoming more numerous and complicated by the day, making it increasingly difficult for enterprises to protect themselves.

Read article → Cybersecurity
2023-05-15

The risks of hybrid employment for security

While the world continues to react to the pandemic, hybrid employment, which allows individuals to work both remotely and in the office, has gained…

Read article → Cybersecurity

Where are the older posts?

Continue to page 2 and page 3 for the rest of the 84 posts, or browse everything by subject under categories.

Page 2 (older) → Browse by topic

Frequently asked questions

What does the AmbiSecure engineering blog cover?

Practical, code-first writing on hardware-rooted security — FIDO, WebAuthn, JavaCard, DESFire, SAM-backed transit, passwordless rollouts, and smart-card lifecycle topics.

How far back does the blog go?

The blog holds 84 posts published between 2020 and 2026. Earlier pieces keep their original publication date and, where the field has moved on, carry a note pointing at current coverage.

How is the blog organised?

Posts are listed newest-first across three pages and grouped by subject under blog categories.

How often is the engineering blog updated?

New posts land in batches as engineering work concludes, and existing posts carry a last-reviewed date so you can tell current guidance from material that has not been revisited.

Can I reference these posts in internal documentation?

Yes. They are written to be citable engineering references, with standards named explicitly so a claim can be traced back to its source specification.