Ambimat GroupAmbimatAmbiSecureSIMAuthAmbiAutomationEngineering BlogAhmedabad · India · Est. 1982
Resource · Deck

The AmbiSecure deck

A concise 20-slide overview of AmbiSecure’s hardware-rooted trust platform — authenticators, secure-element engineering, Java Card services, PKI, IoT identity, and the engagement model.

Slide 1 of 20 — AmbiSecure title slide: embedded security, identity and hardware-rooted trust. FIDO authenticators, JavaCard applets, secure elements, PKI and IoT trust, engineered by the Ambimat Electronics team on an EAL6+ secure element, shipping since 1982.

Slide 1 of 20

Slide-by-slide

What does the deck cover?

Read the 20 slides as text

  1. AmbiSecure. Embedded security, identity and hardware-rooted trust. FIDO authenticators, JavaCard applets, secure elements, PKI and IoT trust, engineered by the Ambimat Electronics team on an EAL6+ secure element — shipping hardware since 1982.
  2. AmbiSecure within the Ambimat Group. The security and trusted-identity business unit of Ambimat Electronics, an embedded-engineering team that has shipped hardware since 1982 and identity systems since 2017, sitting alongside AmbiPay, AmbiSpace, AmbiSense, AmbiPower, AmbiLogistics, AmbiCon and AmbiAutomation as the Group’s security and identity layer.
  3. The AmbiSecure security stack. A layered platform: EAL6+ secure-element silicon (root), the AmbiSEC nano-card / MFF2 module (package), JavaCard applets for FIDO, PIV, OpenPGP and IoT, and OnePass device identity and authenticators — consumed by enterprise, telecom and IoT systems. One trust chain, one team, many surfaces.
  4. A chain that begins below the OS. Trust is anchored in an EAL6+ secure element and carried up through verified transitions rather than inherited from software that can be cloned or spoofed: root of trust in the secure element, a verified boot ROM and signed bootloader, measured signed anti-rollback firmware, an attested isolated OS/runtime, and applications that consume FIDO, PKI and identity.
  5. Product & service portfolio. Authenticators: OnePass Card, OnePass Bio Card, OnePass USB Key, BioKey and Tappable. Platforms & applets: AmbiSEC module, Java Card applet services, IoT Security Co-Processor and the multi-tenant FIDO Validation Server. Trust & identity: embedded PKI & signature, ePassport platform, DESFire / transit, and eSIM / SIM-Auth.
  6. One identity card, phishing-resistant. The OnePass Card replaces badges and separate security keys with a single FIDO2 smart card on one EAL6+ secure element: FIDO2 / U2F passwordless login, PIV and OpenPGP roles, door access and NDEF, and issuer keys with brand artwork — built for enterprise, government and secure access.
  7. OnePass USB Key & BioKey. FIDO2 USB security keys: the OnePass USB Key (FIDO2 / U2F, no battery, no network, compact and durable) and BioKey, the biometric variant adding on-device fingerprint verification on an EAL6+ secure element for the highest-assurance tier.
  8. FIDO2 & modern authentication. Public-key cryptography replaces shared-secret passwords, making authentication phishing-resistant by construction. The ceremony spans the authenticator, the relying party and a validation server (attestation, MDS), and the private key never leaves the device — passwordless MFA, WebAuthn / CTAP2 and passkeys, secure-element-backed credentials.
  9. AmbiSEC module & Java Card engineering. We architect, build, personalise and validate applets in-house, shipped on the same EAL6+ secure element as a nano-card or solderable MFF2 module: silicon selection, applet development (FIDO / PIV / OpenPGP / IoT), personalisation via SCP03 and key derivation, form-factor choice, and validation on the FIDO Validation Server.
  10. FIDO — login that can’t be phished. Passwords get reused, phished and spilled in breaches; with FIDO, login becomes a hardware tap and the private key never leaves the chip. Business use cases: passwordless workforce, stopping account takeover, passkeys for customers, and locking down privileged VPN, SSO and admin access.
  11. PIV — one card for everything an employee needs. One standards-based card handles building access, computer login, signing and encryption end to end (slots 9A / 9C / 9D / 9E): meets FIPS 201 credentialing, kills the password with smart-card logon to Windows, VPN and business apps, produces legally-signed documents, and gives one credential with one audit trail.
  12. OpenPGP — protect the keys your teams rely on. Signing and encryption keys live inside tamper-resistant hardware and never touch disk: sign to prove authorship, encrypt to keep files and messages private, and authenticate to servers over SSH — enabling a trusted software supply chain, confidential communication, phish-proof server access, and protection of crown-jewel keys.
  13. Java Card applet development services. Custom secure-element applets for authentication, identity, PKI, secure messaging and IoT trust, engineered on EAL6+ silicon: discover (use case, threat model, APDU surface), architect, develop, personalize (keys, GlobalPlatform, host interface), validate and deploy (nano-card, MFF2, AmbiSEC, product), delivered with GlobalPlatform / SCP03 and testing under real secure-element constraints.
  14. IoT device identity & lifecycle. Hardware-rooted device identity across three phases. Factory: manufacture with an EAL6+ secure element / AmbiSEC module and provision keys, certificates, applets and identity material. Field: deploy, authenticate cryptographically, operate encrypted and attested, and update signed firmware and secure lifecycle policy. End of life: key revocation and secure decommissioning.
  15. Embedded PKI, attestation & key custody. A certificate chain anchored in hardware: a root CA / trust anchor, an issuing CA, and device or credential certificates whose keys are generated inside the EAL6+ secure element and never exported. AAGUID and attestation certificates are injected at personalisation, with PKCS#11 / eIDAS audit-grade issuance, renewal and revocation validated by the relying party.
  16. eSIM / SIM-Auth — the same trust, in telecom. Because the eUICC is itself a secure element, the same EAL6+ secure-element and key-custody expertise extends to telecom-grade embedded identity: SGP.22 / SGP.32 eUICC remote provisioning, OpenID Connect applets with automotive and M2M variants, and hardening SMS OTP with SIM-rooted authentication — on the dedicated SIMAuth platform.
  17. Services & engagement model. What we deliver: architecture and product security design review, secure-element feasibility and silicon selection, Java Card applet development from define to deploy, and personalisation, certification and deployment support. Engagements are scoped as an architecture review, pilot, prototype / sandbox, integration, secure manufacturing or rollout — most start as “we need something like X, but with Y,” and one accountable team takes it from there.
  18. Target sectors & use cases. Government & defence (PIV, eID and ePassport identity programmes), enterprise IT & CISOs (passwordless workforce and device trust), banking & fintech (strong auth and transaction integrity), connected mobility & IoT OEMs (V2X PKI and device identity in silicon), transit & smart cities (SAM-backed offline fare and access trust), and telecom operators (eUICC and SIM-rooted authentication).
  19. An embedded team, not a security boutique. AmbiSecure combines embedded engineering, secure elements, applet development, and hardware-rooted identity and authentication products — not just software security. A generic IoT or software-security vendor ships apps, dashboards and agents where trust stops at the software layer and integrates someone else’s secure element across three vendor handoffs; AmbiSecure owns trust from silicon to validation server, does JavaCard, FIDO and personalisation in-house, ships hardware products, and is one accountable team with 40+ years embedded.
  20. A security problem that lives in hardware? Talk to engineers, not BDRs: tell AmbiSecure what you are building and get a path that is realistic, standards-aware and shipped before. Links to the AmbiSecure security platform (ambisecure.ambimat.com), the SIMAuth eSIM platform (esim.ambimat.com) and the Ambimat Group (ambimat.com). Ambimat Electronics, Ahmedabad, India.