AntiMalware•July 31, 2026•🇷🇺Translated from Russian

FSB Russia Certifies Rutoken Chip 3127 with Five-Year Cryptographic Key Validity

Aktiv has obtained an FSB Russia certificate for its embedded microcontroller Rutoken Chip 3127 under security classes KS1 and KS2. Following additional research, the validity period of the device's private cryptographic keys has been extended to five years.

The chip forms part of the Rutoken ECP 3.0 3127 product line and is designed for equipment that requires long-term cryptographic protection. Target platforms include servers, ATMs, workstations, tablets, biometric systems, industrial equipment, and IoT devices that must independently verify trust relationships while human operators focus on other tasks.

Rutoken Chip 3127 stores cryptographic keys in non-extractable form, authenticates users and devices, checks the integrity of system components, and enables trusted boot. At every stage it can validate executable code to prevent unauthorized modifications. The microcontroller also supports data encryption, derivation of session and derived keys, secure software updates, and protected TLS and VPN connections.

For data exchange over open channels the chip implements the CRISP protocol that complies with GOST R 71252-2024. Hardware-level protections include continuous monitoring of supply voltage and the integrity of the protective layer covering the die. Any detected physical tampering attempt triggers immediate blocking of operations. A dummy branch execution mechanism performs false commands to mask power consumption and timing information against side-channel attacks.

The company reports that Rutoken Chip 3127 has already completed pilot deployments. One project integrated the microcontroller into the OVISION biometric access control systems. Completion of the certification process is expected to enable serial production use in devices deployed within critical information infrastructure.

Related articles

Habr•Policy & Regulation

RWB Deploys Enterprise-Wide Database Access Control with Trino and Open Policy Agent

RWB has replaced fragmented manual database access processes with a centralized architecture built on Trino as the single entry point and Open Policy Agent for policy enforcement. The system enforces least-privilege access, mandatory auditing, and automated revocation tied to HR records while eliminating anonymous and password-based logins. Access requests now complete in 3–10 minutes instead of an average of four days, with 92 percent handled automatically. Key components include Keycloak for OIDC authentication, Vault for secrets, Kafka for security event streaming to SOC, and Kubernetes orchestration. Responsibility is split across AI & Data Security, Core DevOps, Access Management, SOC, and Trust & Safety teams. More than 1,250 PostgreSQL clusters and 90 projects are now connected, with real-time dashboards tracking adoption and policy health.

AntiMalware•Policy & Regulation

Russia Moves to Allow Biometric Data Processing for Suspects and Convicts Without Consent

Russian law enforcement agencies may soon gain the legal right to process biometric data of suspects, accused individuals, and convicted persons without requiring their personal consent. A corresponding draft bill has already been submitted to the government and is scheduled for review at the next cabinet meeting, according to TASS. The measure covers fingerprints, facial images, voice recordings, and other physiological or behavioral characteristics used for identification. If approved, prior permission from the individual will no longer be needed when biometrics are used in criminal proceedings. The change applies not only to those already convicted but also to suspects and accused persons whose guilt has not yet been established by a court. For ordinary citizens, enrollment in the Unified Biometric System remains voluntary and is used for remote identity verification when accessing financial and government services.

AntiMalware•Policy & Regulation

FAS Clears Russian Operators on 'Unlimited' Internet Claims Despite Speed Throttling to 128 Kbit/s

The Federal Antimonopoly Service has declined to investigate complaints regarding promises of unlimited internet and unrestricted roaming access made by major Russian mobile operators. The Association of Professional Users of Social Networks and Messengers argued that operators including Vimpelcom, MegaFon, MTS, and T2 Mobile mislead customers by advertising unlimited plans while throttling speeds to 128-512 Kbit/s after data caps are reached. FAS determined that information on official company websites does not qualify as advertising under Russian law. Operators maintain that the term unlimited remains accurate because no total data volume limit exists, only speed reductions detailed in service descriptions. The complainants and legal experts contend that FAS reviewed only technical parameter pages and ignored banners, promotional news, search ads, SMS, and push notifications that may meet legal criteria for advertising. The decision leaves consumers facing slow connections unsuitable for video or file downloads after initial allowances are exhausted.

Habr•Policy & Regulation

Merkle Tree Certificates Proposed to Enable Lightweight Post-Quantum HTTPS in Chrome

Google Chrome developers, together with industry partners and the IETF PLANTS working group, are introducing Merkle Tree Certificates (MTC) as the first HTTPS change designed to address performance challenges of post-quantum cryptography. The new format replaces parts of traditional X.509 certificate chains with compact inclusion proofs inside a Merkle tree whose root is signed by a certificate authority. This approach significantly reduces the size of authentication data exchanged during TLS handshakes while preserving strong post-quantum security properties. MTC also enforces Certificate Transparency by design, making it impossible to issue a public certificate without recording it in a publicly verifiable log. Performance evaluations are currently underway with Cloudflare, and initial public MTC logs operated by experienced CT log providers are planned for early 2027. A dedicated post-quantum Chrome Root Store supporting only MTC is scheduled for the third quarter of 2027 and will run in parallel with the existing root store.