// Field_Implementations

The token is the easy part.
A token can replace a sensitive value. The difficult work is defining what the replacement means, who may reverse it and how the system behaves over time.

The SIM as a cryptographic computer.
Long before the secure element became a general platform, SIM and UICC applets provided a small governed environment for keys, authentication and digital signatures.

Designing a fare token for intermittent connectivity.
When balance and fare rules remain in a central account, a QR code is not the ticket. It is a compact claim whose meaning depends on connectivity, trust and replay control.

A card migration is a state machine.
Moving a live fare system from MIFARE Classic to MIFARE Plus is not a card replacement exercise. It is a controlled transition across credentials, readers, keys and operational states.

Putting the trust boundary beside the reader.
A SAM can keep master keys out of reader firmware and perform card protocols locally. The security result still depends on permissions, host integration and lifecycle.

Keys without a secure boundary.
When cryptographic operations must run without an HSM, software can reduce the exposure of key material—but it cannot make a hostile host trustworthy.
