Secure Personalization of Java Card Applets Using Issuer Security Domain and SCP02
The tutorial demonstrates an elegant approach to secure Java Card applet personalization by relying on the built-in security features of the Issuer Security Domain instead of custom asymmetric cryptography implementations.
Background and Problem Statement
Previous examples using ECDH for session key derivation required significant testing resources and failed to provide authentication, allowing any party knowing the elliptic curve parameters to extract secrets. The new method avoids these issues by delegating security to the GlobalPlatform card manager.
The use case involves an access control system where employee data (name, department, position, validity period) must be written or updated only by authorized parties over a protected channel. Any reader can retrieve the data, but it is returned encrypted with AES-128. The applet must securely receive and periodically update the 16-byte key throughout the card lifecycle.
Applet Implementation Details
The constructor simply allocates a 255-byte buffer for personal information. Heavy cryptographic objects such as AESKey and Cipher are instantiated after installation to avoid 6F00 errors on NXP cards during the INSTALL for install command.
The install method follows GlobalPlatform guidelines by passing the instance AID to register(). The process method handles three proprietary instructions for setting the secret key, writing personal data, and reading personal data, while unknown instructions are routed to mutual authentication.
A helper method determines whether an instruction carries command data, ensuring setIncomingAndReceive is called only when needed. Comprehensive try-catch blocks convert CryptoException reasons into informative status words instead of generic 6F00 errors.
Secure Channel Usage
The applet obtains a SecureChannel instance in select() via GPSystem.getSecureChannel and resets it in deselect(). Unknown APDUs invoke scp02.processSecurity, which handles INITIALIZE UPDATE and EXTERNAL AUTHENTICATE commands according to the negotiated security level.
The update_secret_key method calls unwrap with an adjusted length to account for the CLA offset, then verifies that the security level includes C_DECRYPTION before installing the AES key. The set_person_info method applies a lower requirement of C_MAC only.
Reading personal information simply initializes the AES cipher in encryption mode and returns the ciphertext. All operations are tested using the FunGP Python library, which supports multiple SCP02 security levels configurable at mutual authentication time.
Related articles
IT Jobs at Major Tech Firms Turn Into Dating Red Flags for Some Women
Working in IT used to be seen as a strong advantage in dating due to high salaries and prestigious employers. However, employees at companies like Palantir and Tesla now report that their jobs trigger uncomfortable conversations about ethics and politics instead of romantic interest. A Palantir engineer named Gary has started hiding his employer after facing sharp reactions from women and even requests from friends to avoid mentioning the company at social events. Tesla employee James encounters questions about his political views simply because of his association with Elon Musk's company. Dating specialist Amy Laurent notes that tech giants face backlash over issues like surveillance, inequality, and AI displacing workers, forcing professionals to present their careers with caveats. The article from Wired highlights how an employer's reputation now overshadows individual values during initial meetings. While IT roles remain attractive in many ways, the automatic boost from big tech brands appears to be fading in personal contexts.
Neuromorphic Chips: Event-Driven Architectures Aim to Cut Energy Use in Always-On AI and Sensor Systems
Modern processors and GPUs excel at massive parallel math yet remain inefficient for continuous sensor streams where little changes most of the time. Neuromorphic chips borrow principles such as local memory, sparse spiking communication and threshold-based activation from biological nervous systems to reduce data movement and idle computation. The approach replaces constant matrix multiplications with asynchronous spikes that propagate only when meaningful events occur, lowering both power and latency for edge devices. Spiking neural networks encode information in the timing and frequency of pulses rather than dense numeric tensors, making them suitable for vibration monitoring, robotic vision and wearable health sensors. Hybrid systems are expected to pair conventional CPUs and NPUs for heavy training workloads with neuromorphic accelerators that stay dormant until events arrive. The architecture does not replace existing accelerators but targets the niche of always-on, battery-constrained perception tasks where conventional von Neumann designs hit the memory wall.
Russia Boosts Digitalization Budget by 58% Using Telecom Operators' Universal Service Fund
The Russian government has significantly increased allocations for digital projects from the universal service reserve funded by telecom operators. In the 2027 draft budget, 16.3 billion rubles are earmarked for digital solutions, up 58% from the previously planned 10.3 billion rubles. The funds will support the national project Data Economy and the state program Information Society, covering state information systems, digital platforms, cloud infrastructure, AI projects, and quantum technologies. The operator contribution rate remains unchanged at 2% of revenue, with no new levies under consideration. Funding for connecting small settlements to the internet stays at 19.3 billion rubles, while allocations from traffic fines for digitalization are being reduced.
GigaChat Creates New Continuation of Gogol's Dead Souls Under Expert Supervision
Sber's GigaChat generative AI model has produced a new version of the second volume of Nikolai Gogol's Dead Souls, which the author himself destroyed in 1852. The project involved training the model on Gogol's writings, letters, drafts, works by his contemporaries, and philosophical and religious texts that may have influenced the writer. Historians, literary scholars, linguists, and engineers guided the process to ensure the creation of original images and meanings rather than recycled phrases. Experts reviewed every fragment of the generated text for authenticity and quality. Illustrations were also produced by an AI model based on the style of Alexander Agin, who illustrated the first volume during Gogol's lifetime. Sber states the goals are to demonstrate AI as a creative and analytical tool in the hands of specialists and to attract younger readers to Russian classics. Vladislav Kreynin noted that the work does not resolve debates about the lost original manuscript.