FSB Russia Certifies Rutoken Chip 3127 with Five-Year Cryptographic Key Validity
Aktiv has obtained an FSB Russia certificate for its embedded microcontroller Rutoken Chip 3127 under security classes KS1 and KS2. Following additional research, the validity period of the device's private cryptographic keys has been extended to five years.
The chip forms part of the Rutoken ECP 3.0 3127 product line and is designed for equipment that requires long-term cryptographic protection. Target platforms include servers, ATMs, workstations, tablets, biometric systems, industrial equipment, and IoT devices that must independently verify trust relationships while human operators focus on other tasks.
Rutoken Chip 3127 stores cryptographic keys in non-extractable form, authenticates users and devices, checks the integrity of system components, and enables trusted boot. At every stage it can validate executable code to prevent unauthorized modifications. The microcontroller also supports data encryption, derivation of session and derived keys, secure software updates, and protected TLS and VPN connections.
For data exchange over open channels the chip implements the CRISP protocol that complies with GOST R 71252-2024. Hardware-level protections include continuous monitoring of supply voltage and the integrity of the protective layer covering the die. Any detected physical tampering attempt triggers immediate blocking of operations. A dummy branch execution mechanism performs false commands to mask power consumption and timing information against side-channel attacks.
The company reports that Rutoken Chip 3127 has already completed pilot deployments. One project integrated the microcontroller into the OVISION biometric access control systems. Completion of the certification process is expected to enable serial production use in devices deployed within critical information infrastructure.
Related articles
Durov's Addition to Terrorist List Triggers Russian Account Blocks but Does Not Automatically Ban Telegram or Classify Transfers as Terrorism Financing
Russian financial institutions must suspend operations on Pavel Durov's domestic accounts following his inclusion in the Rosfinmonitoring terrorist and extremist list on July 30. The restrictions primarily target his personal finances and property inside Russia, as confirmed by attorney Dmitry Roshchin. Telegram itself remains unaffected as a platform because the messenger and its founder are legally distinct entities. Transfers to Durov do not automatically constitute terrorism financing; criminal liability requires proof that the funds were specifically intended for terrorist activities. The FSB has accused Durov of aiding terrorism by failing to remove channels allegedly used by Ukrainian services for sabotage planning, yet he has not been convicted by a court. Media outlets RIA Novosti and Izvestia reported these clarifications on compliance with Russian anti-terrorism legislation.
Russian Ministry Proposes Mandatory Phone-Number Authentication for Foreign Websites and Apps
The Russian Ministry of Digital Development has drafted new rules requiring foreign websites and applications to authenticate users in Russia exclusively through phone numbers. The measure forms part of the third anti-fraud package known as Antifraud 3.0 and would eliminate email, social-media logins and other traditional methods. Foreign service operators would also be obliged to retain registration, login and account-deletion records for three years and to hand them over to Russian law-enforcement agencies upon request. Amendments are planned for Article 8 of the law On Information, with submission to the State Duma scheduled for autumn 2026. Experts warn that many international companies may refuse to build separate authentication flows for the Russian market, potentially leading some services to exit Russia entirely. The proposal also raises enforcement questions for already-blocked platforms such as Facebook and Instagram owned by Meta.
Google's Android Developer Verification Rollout: Implications for Russian Devices and MDM-Managed Phones
Google is introducing mandatory Android Developer Verification on certified devices starting in select countries in September 2026, requiring developers to register and sign apps with verified identities. The policy aims to curb fraudulent and malicious applications by linking package names to registered developer signatures checked via the new Android Developer Verifier system component. Devices without Google services, including many Russian and Chinese firmware builds as well as AOSP variants, remain completely unaffected since the verification mechanism relies on Google Play services. Russia is explicitly excluded from the initial rollout and subsequent waves due to sanctions, allowing continued distribution of in-house and third-party applications. Corporate MDM deployments are also exempt because administrators are considered to have already vetted the apps for safety. Google plans to offer both full registration requiring D-U-N-S numbers for organizations and a limited option for hobbyists capped at 20 devices. The company has already registered SafeMobile as a verified developer, ensuring seamless installation of its client on supported devices.
Building Information Security Culture: How Welcome Training Turned Rules into Engaging Dialogue
A large software development company transformed its approach to information security awareness by replacing formal policy sign-offs and portal documents with an interactive Welcome Training program. The 45-minute in-person sessions target developers, analysts, testers, product managers, and designers, focusing on real-world context, attack mechanics, and personal relevance rather than prohibitions. Training covers global and local threat landscapes, password policies, corporate email usage, sensitive data storage with VeraCrypt, secure credential sharing via pbin, file verification with VirusTotal, and social engineering defense. It also highlights existing corporate tools including Kaspersky Endpoint Security, Kaspersky Secure Mail Gateway, and SIEM systems to emphasize layered protection. The format has increased engagement, improved retention of guidelines, fostered conscious compliance, and noticeably reduced incidents stemming from human error. The company stresses that technology alone fails without employee understanding of why rules matter.