Identity Card

  • Visual authentication:
    Photograph, wet signature, guilloche, rainbow print, MLI, micro text, raster print, charm, relief print, optical variable ink, ultraviolet ink and OVD/DOVID
  • Electronic authentication:
    Electronic certificate, digital photo, PIN
  • Biometric verification:
    Fingerprint, finger vein print, hand palm print
  • Ability to upload Qualified Electronic Certificate (QC) and private key
  • ISO/IEC 7816-3 compliant contact communication
  • Command set compliant with ISO/IEC 7816-4, 8, and 9
  • AES-256 Secure Messaging
  • Get hashes (SHA-1, SHA-256, SHA-384, SHA-512)1
  • Random Number Generator (RNG) 2
  • Card Verifiable Certificate (CVC) support3
  • Role-based access mechanism
  • RSA digital signing and decryption operations3
  • Generating an RSA key pair4
  • ECDSA signing (ECC 128 – 640 bit range)5
  • Generating an ECC key pair (ECC 128–640-bit range)5
  • Cryptographic integrity checks (DES3 MAC/CMAC/RetailMAC, AES MAC/CMAC)5
  • Symmetric encryption/decryption (DES3, AES: CBC, ECB, GCM)6
  • Wrap/Unwrap Key7
  • ECDH Key Derivation7
  • Session-based symmetric key generation7
  • Session-based ECC key pair generation7
  • Common Criteria (CC) EAL 4+ security level
  • Multi-chip support8
    • UKTUM-H v7.01
    • Infineon SLE78CFX2400P
    • NXP P71D320P, P71D352P
  • PKCS#119 driver assistance
  • CSP and Minidriver driver support10

1Only SHA-1 and SHA-256 are supported for AKiS v2.2.
2AKiS v2.2 supports true random number generation, while AKiS v2.5 and v2.6 support only hybrid deterministic random number generation.
3RSA 1024 for AKiS v2.5 – 2816-bit range and RSA 1024 – 2688-bit range for AKiS v2.6 are supported, while only RSA 1024-bit and 2048-bit are supported for AKiS v2.2.
4 RSA key lengths ranging from 1024 to 2816 bits are supported for AKiS v2.5, and RSA key lengths ranging from 1024 to 2688 bits are supported for AKiS v2.6; only 2048-bit RSA keys are supported for AKiS v2.2.
5Supported in AKiS v2.5 and v2.6.
6Supported in AKiS v2.5 and v2.6 (GCM block mode is supported only in v2.6).
7Only supported in AKiS v2.6.
8The chips have at least a CC EAL 5+ security evaluation certificate.
9 It supports the MS Windows, Linux, and macOS operating systems.
10 It supports the MS Windows operating system.

  • Standards compliance
    • ICAO Doc 9303
    • ISO/IEC 14443-3, 4
    • ISO/IEC 7816-4, 8, 9
    • ICAO Technical Report: Supplemental Access Control for MRTDs
    • BSI TR-03110
    • BSI TR-03111
  • ICAO LDS 1.71 compatible with the data structure
  • Basic Access Control (BAC)
  • Active Authentication (AA)
    • RSA (up to 2560 bits)2: SHA-1, SHA-256, SHA-384, SHA-512 2
    • ECC (up to 521 bit): SHA-1, SHA-224, SHA-256, SHA-384, SHA-512
  • Supplemental Access Control (SAC)
    • PACE v2
    • MRZ, CAN and PIN3 support
    • Generic Mapping and Integrated Mapping support
    • ECDH (Brainpool curves up to 512 bits)
    • DH (1024 bits, 2048 bits)
  • Extended Access Control (EAC)
    • EAC v14
    • RSA (up to 3072 bit): SHA-1, SHA-256, SHA-512
    • ECC (up to 521 bit): SHA-1, SHA-224, SHA-256, SHA-384, SHA-512
  • Contactless Communication
    • ISO/IEC 14443-3, 4 Type A
    • 424/848 kbps communication speed
  • Secure Communication
    • DES3
    • AES-128, AES-192, AES-256
  • Common Criteria (CC) security level
    • CC EAL 4+ for BAC (ALC_DVS.2)
    • CC EAL 5+ for SAC & EAC (ALC_DVS.2, AVA_VAN.5)
  • Multi-chip support5
    • Infineon6 SLE78CLFX3000P, SLE78CLFX308AP, SL78CLFX4000P, SLE78CLFX408AP
    • NXP P71D320P6, P71D352P7
  • Standards compliance
    • ICAO Doc 9303
    • ISO/IEC 14443-3, 4
    • ISO/IEC 7816-4, 8, 9
    • ICAO Technical Report: Supplemental Access Control for MRTDs
    • BSI TR-03110
    • BSI TR-03111

1In AKiS GEZGİN v2.0, you can define more data groups.
2The maximum supported RSA bit length for AKiS GEZGiN v1.x is 2048 bits.
3PIN support is available only in AKiS GEZGiN v2.0.
4In AKiS GEZGiN v2.0, you can use up to 32 roles.
5The chips have a CC EAL 6+ security evaluation certificate.
6Compatible only with AKiS GEZGiN v1.x.
7Compatible only with AKiS GEZGiN v2.0.

AKIS PKI

Developed in accordance with ISO/IEC 7816 standards, the AKiS PKI smart card family—comprising AKiS v2.2, v2.5, and v2.6—provides a secure, interoperable, and reliable foundation for digital identity and electronic signature solutions.

AKiS PKI products provide strong authentication, digital signing, and secure access across a wide range of public and private sector applications. The advanced Public Key Infrastructure (PKI) architecture supports a wide variety of cryptographic algorithms and ensures a high level of security and data integrity.

With their proven performance in e-Government, corporate, and financial systems, AKiS PKI smart cards help institutions establish trusted digital identities, safeguard transactions, and build a resilient digital ecosystem aligned with global standards.

  • ISO/IEC 7816-3 compliant contact communication
  • Command set compliant with ISO/IEC 7816-4, 8, and 9
  • AES-256 Secure Messaging
  • Get hashes (SHA-1, SHA-256, SHA-384, SHA-512)1
  • Random Number Generator (RNG)2
  • Card Verifiable Certificate (CVC) support3
  • Role-based access mechanism
  • RSA digital signing and decryption operations3
  • Generating an RSA key pair4
  • ECDSA signing (ECC 128 – 640 bit range)5
  • Generating an ECC key pair (ECC 128–640-bit range)5
  • Cryptographic integrity checks (DES3 MAC/CMAC/RetailMAC, AES MAC/CMAC)5
  • Symmetric encryption/decryption (DES3, AES: CBC, ECB, GCM)6
  • Wrap/Unwrap Key7
  • ECDH Key Derivation7
  • Session-based symmetric key generation7
  • Session-based ECC key pair generation7
  • Common Criteria (CC) EAL 4+ security level
  • Multi-chip support8
    • UKTUM-H v7.01
    • Infineon SLE78CFX2400P
    • NXP P71D320P, P71D352P
  • PKCS#119 driver assistance
  • CSP and Minidriver driver support10

1 Only SHA-1 and SHA-256 are supported for AKiS v2.2.
2 AKiS v2.2 supports true random number generation, while AKiS v2.5 and v2.6 support only hybrid deterministic random number generation.
3 RSA 1024 for AKiS v2.5 – 2816-bit range, and for AKiS v2.6, the RSA 1024 – 2688-bit range is supported; for AKiS v2.2, only RSA 1024-bit and 2048-bit are supported.
4 RSA key lengths ranging from 1024 to 2816 bits are supported for AKiS v2.5, and RSA key lengths ranging from 1024 to 2688 bits are supported for AKiS v2.6; only 2048-bit RSA keys are supported for AKiS v2.2.
5 Supported in AKiS v2.5 and v2.6.
6 Supported in AKiS v2.5 and v2.6 (GCM block mode is supported only in v2.6).
7 Only supported in AKiS v2.6.
8 The chips have at least a CC EAL 5+ security evaluation certificate.
9 It supports the MS Windows, Linux, and macOS operating systems.
10 It supports the MS Windows operating system.

AKİS GEZGİN E-Passport

(with e-ID and e-Signature Applications)

AKiS GEZGiN e-Passport application is compatible with ICAO Doc 9303 standards. The information stored on contactless chip can only be accessed via secure communication protocols such as Basic Access Control (BAC) and Supplemental Access Control (SAC). Active Authentication (AA) and Chip Authentication (EAC - CA) prevent cloning of the e-Passport. In addition, biometric data on the chip is protected by Extended Access Control (EAC) and CVC certificates. Therefore, only those countries that are allowed by the issuing country can access the biometric data.

AKiS GEZGiN extends the ICAO Doc 9303 standards by increasing the number of supported roles to 32 and also supports e-Signature applications. Consequently, it can be customized for e-ID and/or e-Signature applications as well.

  • ICAO LDS 1.71
  • Basic Access Control (BAC)
  • Active Authentication (AA)
    • RSA (up to 2560 bits)2: SHA-1, SHA-256, SHA-384, SHA-512
    • ECC (up to 521 bit): SHA-1, SHA-224, SHA-256, SHA-384, SHA-512
  • Supplemental Access Control (SAC)
    • PACE v2
    • MRZ, CAN and PIN3 support
    • Generic Mapping and Integrated Mapping support
    • ECDH (Brainpool curves up to 512 bits)
    • DH (1024 bits, 2048 bits)
  • Extended Access Control (EAC)
    • EAC v14
    • RSA (up to 3072 bit): SHA-1, SHA-256, SHA-512
    • ECC (up to 521 bit): SHA-1, SHA-224, SHA-256, SHA-384, SHA-512
  • Contactless Communication
    • ISO/IEC 14443-3, 4 Type A
    • 424/848 kbps communication speed
  • Secure Communication
    • DES3
    • AES-128, AES-192, AES-256
  • Common Criteria (CC) security level
    • CC EAL 4+ for BAC (ALC_DVS.2)
    • CC EAL 5+ for SAC & EAC (ALC_DVS.2, AVA_VAN.5)
  • Multi-chip support5
    • Infineon6 SLE78CLFX3000P, SLE78CLFX308AP, SL78CLFX4000P, SLE78CLFX408AP
    • NXP P71D320P6, P71D352P7
  • Standards compliance
    • ICAO Doc 9303
    • ISO/IEC 14443-3, 4
    • ISO/IEC 7816-4, 8, 9
    • ICAO Technical Report: Supplemental Access Control for MRTDs
    • BSI TR-03110
    • BSI TR-03111

BASIC ACCESS CONTROL (BAC)
It is a mechanism that enables an authorized terminal to access the data stored on the contactless chip and ensures that communication between the terminal and the contactless chip takes place securely. It enables the generation and verification of session keys, as well as the initiation of secure communication, through the optical reading of the Machine Readable Zone (MRZ) or Card Access Number (CAN) information printed on the e-passport.

SUPPLEMENTAL ACCESS CONTROL (SAC)
It is a mechanism that enables the generation of session keys that are more secure and robust than those generated by BAC, thanks to the Diffie-Hellman key exchange protocols (DH/ECDH). When a passport holder presents their passport, they are deemed to have consented to the reading of the information stored on the chip; in such cases, the SAC protocol can be implemented using the MRZ and CAN fields. However, for other use cases—such as e-ID and e-Signature—where authentication is expected before accessing the cryptographic services provided by the card or the data stored on the chip, the SAC with a PIN can be used.

EXTENDED ACCESS CONTROL (EAC)
EAC is a mechanism that enables the verification of the authenticity of both e-passports and terminals: Chip Authentication (EAC – CA) ensures that secure session keys are updated with stronger keys, and Terminal Authentication (EAC–TA) ensures that optional biometric data groups (DG3 and DG4) within the chip can be read only by authorized terminals using role-based CVC certificates. AKiS GEZGiN increases the number of supported roles for e-ID usage to 32; consequently, a greater number of files (EF) than expected by EAC can be protected through role authentication.

ACTIVE AUTHENTICATION
It prevents the creation of an exact copy of the e-passport chip.

1 In AKiS GEZGİN v2.0, more data groups than those defined by ICAO standards can be defined.
2 The maximum supported RSA bit length for AKiS GEZGiN v1.x is 2048 bits.
3 PIN support is available only in AKiS GEZGiN v2.0.
4 In AKiS GEZGiN v2.0, you can use up to 32 roles.
5 The chips have a CC EAL 6+ security evaluation certificate.
6 Compatible only with AKiS GEZGiN v1.x.
7 Compatible only with AKiS GEZGiN v2.0.

AKİS GEZGİN e-Driver License

(with e-ID and e-Signature Applications)

AKiS GEZGiN e-Driving Licence (ISO-compliant Driving Licence - IDL) application is compatible with ISO/IEC 18013 standards. The information stored on the contactless chip can only be accessed via secure communication protocols such as Basic Access Protection (BAP) and Supplemental Access Control (SAC). Active Authentication (AA) and Chip Authentication (EAC – CA) prevent cloning of the e-Driving Licence. In addition, biometric data on the chip is protected by Extended Access Control (EAC) and CVC certificates. Therefore, only those countries that are allowed by the issuing country can access the biometric data.

AKiS GEZGiN extends the ISO/IEC 18013 standards by increasing the number of supported roles to 32 and additionally supports e-Signature applications. Consequently, it can also be customized for e-ID and/or e-Signature applications.

  • ISO/IEC 18013-2 LDS1
  • Basic Access Protection (BAP)
  • Active Authentication (AA)
    • RSA (up to 2560 bits)2 : SHA-1, SHA-256, SHA-384, SHA-512
    • ECC (up to 521 bit): SHA-1, SHA-224, SHA-256, SHA-384, SHA-512
  • Supplemental Access Control (SAC)
    • PACE v2
    • SAI and PIN3 support
    • Generic Mapping support
    • ECDH (Brainpool curves up to 512 bits)
  • Extended Access Control (EAC)
    • EAC v14
    • ECC (up to 521 bit): SHA-1, SHA-224, SHA-256, SHA-384, SHA-512
  • Contactless Communication
    • ISO/IEC 14443-3, 4 Type A
    • 424/848 kbps communication speed
  • Secure Communication
    • DES3
    • AES-128, AES-192, AES-256
  • Common Criteria (CC) security level5
    • CC EAL 4+ (ALC_DVS.2) for BAP
    • CC EAL 5+ for SAC & EAC (ALC_DVS.2, AVA_VAN.5)
  • Multi-chip support6
    • Infineon7 SLE78CLFX3000P, SLE78CLFX308AP, SL78CLFX4000P, SLE78CLFX408AP
    • NXP P71D320P7, P71D352P8
  • Standards compliance
    • ICAO Doc 9303
    • ISO/IEC 14443-3, 4
    • ISO/IEC 7816-4, 8, 9
    • ICAO Technical Report: Supplemental Access Control for MRTDs
    • BSI TR-03110
    • BSI TR-03111

BASIC ACCESS PROTECTION (BAP)
It is a mechanism that enables an authorized terminal to access the data stored on the contactless chip and ensures that communication between the terminal and the contactless chip takes place securely. It enables the generation and verification of session keys, as well as the initiation of secure communication, through the optical reading of the SAI (Scanning Area Identifier) information printed on the e-Driver’s License or its manual entry by the operator.

SUPPLEMENTAL ACCESS CONTROL (SAC)
It is a mechanism that enables the generation of more secure and robust session keys than those generated by the BAP, thanks to the Diffie–Hellman key exchange protocol (ECDH). When a driver’s license holder presents their document, they are presumed to have authorized the reading of the information stored on the chip; in such cases, the SAC protocol can be implemented using the SAI field. However, for other use cases—such as e-ID and e-Signature—where identity verification is required before accessing the cryptographic services provided by the card or the data stored on the chip, a PIN-based SAC can be used.

EXTENDED ACCESS CONTROL (EAC)
EAC is a mechanism that enables the verification of the authenticity of both e-Driver’s Licenses and terminals: Chip Authentication (EAC – CA) ensures that secure session keys are updated with stronger keys, and Terminal Authentication (EAC–TA) ensures that optional biometric data groups (DG7 and DG8) within the chip can be read only by authorized terminals using role-based CVC certificates. AKiS GEZGiN increases the number of supported roles for e-ID usage to 32; consequently, a greater number of files (EF) than expected by EAC can be protected through role authentication.

ACTIVE AUTHENTICATION
It prevents the creation of an exact copy of the e-Driver's License chip.

1 In AKiS GEZGİN v2.0, additional data groups beyond those defined in the ISO/IEC 18013 standards can be defined.
2 The maximum supported RSA bit length for AKiS GEZGiN v1.x is 2048 bits.
3 PIN support is available only in AKiS GEZGiN v2.0.
4 A maximum of 32 roles can be used in AKiS GEZGiN v2.0.
5 The Common Criteria (CC) security evaluation certificate is valid only for AKiS GEZGiN v2.0.
6 The chips have a CC EAL 6+ security evaluation certificate.
7 Applies to AKiS GEZGiN v1.x.
8 Valid for AKiS GEZGiN v2.0.

DTC

Digital Turkey Wallet

Digital Türkiye Wallet (DTC) is a next-generation digital identity ecosystem that enables individuals and organizations to use identity information securely in the digital world, while maintaining control and ensuring privacy protection. 

Developed by TÜBİTAK BİLGEM, DTC brings together, within a single ecosystem, the technologies needed to securely create, store, share, and verify identity information.

In developing DTC, we focus not only on today’s identity verification needs but also on the future applications of digital identity. With an approach centered on user control, privacy, security, and interoperability, we aim to enable various services, organizations, and systems to interact through a secure digital identity infrastructure.

We tailor our work to meet national requirements as well as international standards and the European Digital Identity Wallet (EUDI Wallet) ecosystem. Our goal is for the Digital Türkiye Wallet to provide an infrastructure that is interoperable with different systems, supports cross-border use cases, and is ready for the digital identity ecosystems of the future.

User Management: Users decide what information they want to share (e.g., age, driver’s license, diploma). Through selective disclosure, only the required information is provided.

Privacy and Security: Data is stored locally on the device (e.g., an eSIM-based wallet), thereby preventing tracking or profiling.

Portability: Identity documents can be used for a variety of services within the Republic of Türkiye. For example, a Turkish citizen may open a bank account in Germany using a DTC.

Accessibility: Digital documents, including identification cards, diplomas, medical records, and tickets, can be stored and shared.

Passwordless Authentication: Access is granted via a PIN or biometric security measures, such as fingerprint recognition, thereby reducing the risk of phishing.

Public Administration and Governance
Reconceptualize Bureaucracy

Finance and Commerce
Transact Securely

Health and Education
Protect Personal Information, Shape the Future

Technology and Lifestyle
A Connected and Free World

Simple, secure and intuitive

1. Download the App
Download the DTC Wallet app on your device from the App Store or Google Play.

2. Define Your Identity
Scan your chip ID using NFC or verify your account through e-Government verification.

3. Manage Your Information
You decide what information to share with each institution. Selective disclosure ensures that only essential information is shared.

4. Finalize Your Transaction
Transactions with your bank, university, municipality, or international transactions are processed securely within seconds.

Reconceptualize Bureaucracy

Legislation & Electoral Processes
Identity verification in notarial transactions (e.g., power of attorney); proof of “Turkish citizenship and being at least 18 years old” for voter registration.

Municipal Services
ZKP-based authentication for water bill payments or access to municipal services.

Taxation and Social Services
Proof of “taxpayer” status for tax returns; verification of “eligibility” for social assistance applications.

Transact Securely

Banking & Credit

  • Proof of “eligible income” or “sufficient credit score.”.
  • Verification of “Turkish citizenship” when opening a bank account.

Insurance

  • Proof of “no accident history”
  • Health Insurance
  • Data transfer between insurers

E-Commerce and Customer Loyalty

  • Payment Authorization for Online Purchases
  • Transfer of Loyalty Points
  • “Confirmation of ”Over 18” Age Status

Telecom

  • Proof of Citizenship
  • Secure identity sharing
  • Identity Verification

Protect Personal Information, Shape the Future

Education & Professional Development

  • Verification of Diploma Authenticity
  • Certificate Distribution
  • Blockchain-based management of educational resources in initiatives such as BLUEDU.

Health Insurance

  • Verification of “Insured” status using ZKP (Zero-Knowledge Proof).

Healthcare Services

  • Proof of vaccination
  • Patient ID Provisioning with ZKP
  • Disclosure of blood type or allergy information in emergencies
  • Identity Verification in Medical Services

A Connected and Free World

  • Transportation and Automotive Industries
  • Tourism and Travel
  • Intelligent Devices and the Internet of Things
  • Corporate and Supply Chain Management
  • Recreation and Entertainment
  • Energy and Agriculture

Designed in Accordance with EUDI Wallet Standards

  • eIDAS 2.0 – Regulation (EU) 2024/1183
  • EUDI Wallet Architecture and Reference Framework (ARF)
  • EU Implementing Regulations 2024/2977, 2024/2979, 2024/2981, and 2024/2982
  • ISO/IEC 18013-5 and ISO/IEC 18013-7
  • OpenID for Verifiable Credential Issuance (OpenID4VCI)
  • OpenID for Verifiable Presentations (OpenID4VP)
  • SD-JWT-Based Verifiable Credentials (SD-JWT VC)
  • W3C Verifiable Credentials Data Model 2.0
  • Relevant ETSI standards for electronic attestations, trust services, and EUDI Wallet certificates

AKİS BİLET

e-Ticket, Access Control and Loyalty Card

Developed by TÜBİTAK BİLGEM, AKiS BiLET is a contactless smart card solution based on OSPT CIPURSE1 open standards. Featuring an advanced security architecture and a cost-effective design, AKiS BiLET is engineered specifically for use as an electronic payment medium in Automated Fare Collection (AFC) systems. In addition, it is the first smart card product developed in Türkiye that provides reliable contactless functionality for a range of applications, including access control and parking systems.

KEY FEATURES

  • Contactless communication speed: 848 kbps
  • 13.56MHz operating frequency
  • ISO/IEC 14443A-L4 protocol layer support
  • ISO/IEC 7816-compliant file system
  • APDU command set compliant with ISO/IEC 7816-4 and ISO/IEC 7816-92
  • 8 app support2
  • Support for 32 files per application2
  • Binary and record-oriented files
  • CTM (Consistent Transaction Mechanism)3
  • Support for multiple applications

SAFETY FEATURES

  • Hardware platform with a CC EAL 6+ security level
  • True Random Number Generator (TRNG)
  • AES-1284 encryption mechanism
  • 8 AES-128 security keys for each application
  • Flexible key management structure
  • Built-in protection mechanism against Differential Power Analysis (DPA) attacks
  • Built-in protection mechanism against Differential Fault Analysis (DFA) attacks
  • ISO/IEC 9798-2-Based Mutual Authentication (AES-128)
  • ISO/IEC 7816-4-based Secure Messaging modes (Plain, AES MACed, AES ENCed)
  • Data Integrity Protection
  • File-based access authorization and secure messaging

SCOPE OF APPLICATION

  • e-Ticket Apps
  • Personnel attendance control systems
  • Access authorization control systems
  • Parking systems
  • Libraries
  • Health, social assistance, and loyalty card programs

CIPURSE OPEN STANDARDS

CIPURSE open standards provide a proven technology infrastructure based on the ISO/IEC 7816 and ISO/IEC 14443 standards and AES-128 to deliver secure, flexible, and standardized electronic toll collection solutions.

INDEPENDENT TECHNOLOGY

Platform independent: CIPURSE technology can be implemented on any smart card chip that meets all specifications, as well as on NFC SIM cards or JavaCards as an applet.

Supplier independent: CIPURSE technology was developed not as a proprietary solution for a specific manufacturer, but as a standardized and open technology that anyone interested can implement. Today, many companies—including TÜBİTAK BİLGEM—are developing CIPURSE products, and the number of these companies is steadily increasing.

Card reader standalone: No modifications are required to existing card readers to communicate with CIPURSE cards. CIPURSE technology can be used with all smart card readers that support the ISO/IEC 14443A-L4 standards.

1 The CIPURSE open specifications are published by the OSPT Alliance. TÜBİTAK BİLGEM is a full member of the OSPT Alliance.
2 Applies to CIPURSE T Profile only.
3 CTM is a mechanism used to ensure that the data stored on the card is consistently updated during a transaction.
4AES (Advanced Encryption Standard), ISO/IEC 18033-3, FIPS 197.

KYS - ID Document Lifecycle Management Platform

Modern identity management is no longer just a document production process—it is an experience that combines trust, speed, and integrity.

Our Identity Document Lifecycle Management Application enables you to manage the lifecycle of all identity documents—from passports to driver’s licenses, and from electronic signatures to special ID cards—through a single platform.

  • Modular Design: A flexible architecture with customized solutions tailored to your needs, powered by a web-based microservices architecture.
  • High Security: Full compliance with international standards (ICAO, BSI, EAC).
  • Full Integration: AFIS/ABIS, PKI, HSM, LDAP, OpenID, BI, and more.
  • Real-Time Traceability: Full control over procurement, inventory, and distribution processes.

Supported Documents

  • e-Passport
  • e-ID Card
  • e-Driving License
  • Residence Permit
  • Firearm License
  • Electronic Signature Card
  • Access Card
  • Custom ID Card for the Customer

Appointment Management Module

  • Centralized scheduling and management of registration appointments.
  • Real-time coordination between registration offices and personalization centers.

Application Management Module

  • Securely receiving applications via web or mobile platforms in compliance with ICAO standards.
  • Accurate capture of biometric data through AFIS/ABIS integration.
  • An enhanced user experience with real-time application status tracking.

Personalization Module

  • Package-based production suitable for industrial manufacturing.
  • ICAO-compliant data encoding and visual customization.
  • Automated quality control and chip verification processes.
  • PIN/PUK Management.
  • Full integration with desktop and industrial printers / document personalization machines.
  • Surface designs that can be customized to meet customer needs.
  • Detailed audit logs for all personalization operations.

Secure Inventory Management Module

  • Tracking documents with and without serial numbers.
  • Inventory management based on electronic signatures (e-Signature).
  • Role-based access control and approval workflows.
  • Fire monitoring and secure delivery process management.
  • Maintenance of inventory transaction records.

Reporting Module

  • Data visualization and interpretation
  • Dynamic, customizable, and filterable reporting
  • Reporting in various formats, such as PDF, Excel, and Word
  • Integration with Business Intelligence (BI) tools
  • Real-time operational and performance monitoring

Enveloping Module (Optional)

  • Integration with packaging and shipping systems
  • Customer-Focused Delivery Management and Shipment Tracking

User and Access Management Module

  • Centralized management of users and roles
  • Role-Based Access Control and Transaction-Based Authorization
  • Compatibility with LDAP and OpenID
  • Transaction-Based User Tracking

PKI and Cryptographic Security

  • CVCA, CSCA, DS, and DV profiles compliant with BSI TR-03110 and ICAO 9303 standards
  • HSM-based key generation, secure key storage, and key usage.
  • Terminal access authorized through the Terminal Authentication (TA) and Extended Access Control (EAC) mechanisms.
  • High-security digital signing and authentication processes using the RSA and ECDSA algorithms.

Our Reference Projects

  • Republic of Turkey Electronic ID Card Project
  • TRNC ID Card Project
  • Republic of Turkey Passport Project
  • Republic of Turkey Driver's License Project
  • Secure Door Access Systems
  • Resident Card, Firearm License, and Private Security Cards

EKDS - Electronic Authentication System

While performing the service, it confirms whether the people who participate in the service and want to benefit from the service are really the people they claim.

ELECTRONIC AUTHENTICATION SYSTEM COMPONENTS

ELECTRONIC ID CARD

It is a smart identity card used for personal identity verification in order to benefit from the services offered by public service institutions.

CARD ACCESS DEVICE

The Card Access Device (KEC) is one of the terminal devices of EKDS and is used to verify that the ID card is issued by the authorized institution for applications that serve in the electronic environment and that the card really belongs to the holder.

AUTHENTICATION SERVER

It is the server where the authenticity of the authentication notifications created by KEC is checked.

AUTHENTICATION POLICY SERVER

The authentication process is carried out in accordance with the policies determined by each institution depending on the services it offers. While some institutions find only the card password (PIN) sufficient, some institutions may request verification with both the card password and biometrics. Institutions' authentication policies are defined on this server.

INTERFACE APPLICATION SOFTWARE

The integration of the software used by the institutions into EKDS is carried out through interface application software. Interface applications can be a desktop application [Automation Software Interface (OYA/WIA)] or an application running on a server [Security Services Platform (GSP)].

AUTHENTICATION FACTORS

  • Physical verification
  • Secure messaging
  • Electronic certificate
  • Password (PIN code)
  • Biometrics
  • Digital photography

Note: The Electronic Identity Verification System (EKDS) standard was developed by TÜBİTAK BİLGEM and published by the Turkish Standards Institute (TSE). The EKDS to be used in the Republic of Turkey must comply with TSE standards.

6-yze card logo

(IZE) Artificial Intelligence Institute

Artificial Intelligence Institute is the first institute established within the scope of TUBITAK centers and institutes, which cuts the sectors and research fields horizontally and focuses directly on the emerging technology field. For this reason, it constitutes an innovative model in terms of both the open innovation and co-development approach of the institute and its focus on emerging technology.

Artificial Intelligence Institute aims to develop core technologies in the field of artificial intelligence and bring these innovations from the forefront of science to the use of the industry as soon as possible. Focusing on the transformative potential of artificial intelligence, it will continue to play its part in pioneering efforts to create and sustain artificial intelligence-based innovation, growth and productivity in Turkey. Working with industry and public institutions in Turkey, together with other organizations within the artificial intelligence ecosystem, spreading the use of artificial intelligence and increasing the workforce specialized in this field are among its primary goals.

sge

(SGE) Cyber Security Institute

The Cyber Security Institute, which was established to carry out studies to increase the national cyber security capacity, carries out research and development activities in the field of cyber security; carries out solutions-oriented projects for military institutions, public institutions and organizations and the private sector.

The main fields of activity of our institute, which has made a significant contribution to the creation of cyber security knowledge and tactical infrastructure in our country with many successful projects to date, are secure software development, penetration tests and vulnerability analysis.

Discover institutes laboratories technologies products projects of BİLGEM.

Researcher

By joining TÜBİTAK BİLGEM as a Researcher, you can contribute to developments in the fields of information technology, information security, and advanced electronics. You'll have the opportunity to make your mark on innovations, closely follow advancements, enhance your skills, and shape your future by advancing in your career.

You can apply to our currently open positions through the TÜBİTAK Job Application System .

Application Conditions

Conditions for Job Application:

  • Foreign language proficiency: Attaining appropriate scores in the exam types specified in the announcement or studying in a program that is 100% in English for undergraduate education.
  • Fulfilling specific requirements stated in the announcement (such as undergraduate department, years of experience, expertise, etc.).
  • Satisfying the formula score:

For Candidates with Less than 3 Years of Experience:

Weighted Graduation Average + (10,000 / University Placement Exam Ranking) + Additional Score* >= 3.20

 

For Candidates with 3 Years and More of Experience:

Weighted Graduation Average + (10,000 / University Placement Exam Ranking) + 5*[1 / (1 + e^(5 - years of experience) ) ] + Additional Score* >= 3.20


*Candidates who have achieved rankings and awards in national and international competitions will receive an additional score of 0.3.

researcher-img-1

Candidate Researcher

Students in the 3rd and 4th years of relevant engineering departments at universities can apply to our Part-Time Candidate Researcher positions through our Job Application System at kariyer.tubitak.gov.tr. By doing so, they can gain work experience at TÜBİTAK BİLGEM during their university years.

This program does not have an end date. Candidate Researcher personnel working part-time during their university period can seamlessly transition to full-time employment as Researcher personnel at TÜBİTAK BİLGEM without interrupting their career journey after graduating from the undergraduate program.

Application Conditions

Conditions for the Candidate Researcher Program:

  • Being a 3rd or 4th-year student in the relevant departments specified in the announcements at universities.
  • Foreign language proficiency: Achieving appropriate scores in the exam types specified in the announcement or studying in a program that is 100% in English for undergraduate education.
  • Satisfying the formula score:

Weighted Graduation Average + (10,000/University Placement Exam Ranking) + Additional Score* >= 3.20

*Candidates who have achieved rankings and awards in national and international competitions will receive an additional score of 0.3.

candidate-researcher-img-1

Scholar

Scholar assignments are made for research and development activities for undergraduate, master's, doctoral students, and post-doctoral researchers. In our center, scholars are appointed for practical purposes in externally funded, TARAL, or European Union projects.

You can contact us via the email address bilgem.yetenekkazanimi@tubitak.gov.tr to apply to be a scholar.
Application Conditions

(1) The conditions for undergraduate scholars in externally funded projects conducted by the institution are specified below:

  •  Being a student continuing undergraduate education at higher education institutions established in Turkey (excluding foreign language preparatory students).
  • Having a weighted cumulative GPA for previous years, excluding preparatory years, based on the university's grading system, which satisfies the formula score and foreign language requirements in the recruitment criteria.
  • Completing at least the first semester of the first year of undergraduate education.
  • Having a GPA of "+3.00" and a University Placement Exam Ranking of "10,000 ≥" for undergraduate general average.
  • For foreign students placed in Turkish universities without taking the ÖSYM exam or for those who completed undergraduate education through exams such as Vertical Transfer Exam, the lowest university placement ranking of the department from the year the candidate started the undergraduate program is considered in the ranking formula.

(2) The conditions for master's degree scholars in externally funded projects conducted by the institution are specified below:

  • Being a student continuing master's degree education at higher education institutions established in Turkey (excluding special students and foreign language preparatory students).
  • Currently pursuing a master's degree in the project's field of responsibility.

(3) The conditions for doctoral students in externally funded projects conducted by the institution are specified below:

  • Being a student continuing doctoral education at higher education institutions established in Turkey (excluding special students and foreign language preparatory students).
  • Currently pursuing a doctorate in the project's field of responsibility or conducting a doctorate in areas determined within the framework of the YÖK-TÜBİTAK Doctoral Program Project Collaboration Protocol. (Students in medical specialization and artistic proficiency are accepted as doctoral students.)
scholarship-img-1

Intern

TÜBİTAK BİLGEM builds its basic strategy for the future on qualified knowledge and qualified people focused on national targets in the research, technology development and innovation ecosystem.

Starting from the understanding that "the most important resource of a country is generally people, specifically scientists," TÜBİTAK encourages and supports our youth from an early age. In this context, providing young minds with early exposure to technology production is crucial for the success of our National Technology Move. Accordingly, TÜBİTAK BİLGEM offers internship opportunities to undergraduate students from universities every year.

You can follow internship announcements and submit your applications through the Career Gateway at https://kariyerkapisi.cbiko.gov.tr.

You can access frequently asked questions about internships at TÜBİTAK BİLGEM from here. 

Application Conditions
  • Students enrolled in undergraduate (2nd year and above) and associate degree programs in departments offering education in universities and conducting insurance procedures through the higher education institution to which they are affiliated can benefit from the internship opportunity.
  • For undergraduate and associate degree students, a minimum Weighted Grade Point Average (GPA) of 2.50 out of 4 is required. The GPA of candidates with a 100-point system is converted to a 4-point system based on the "Conversion Table of Grades from the 4-Point System to the 100-Point System" published by the Higher Education Council.
  • There is no requirement for a foreign language certificate during the internship application process.
  • Students enrolled in departments such as Forensic Computing Engineering, Computer Sciences, Computer Science and Engineering, Computer Engineering, Computer and Informatics, Computer and Software Engineering, Information Systems Engineering, Electrical and Electronics Engineering, Control Engineering, Control and Computer Engineering, Control and Automation Engineering, Mechanical Engineering, Mechatronics Engineering, Telecommunication Engineering, or Software Engineering in universities can apply for internships.

Internship applications are accepted between December and January, and the internship period covers June, July, and August.

intern-img-1

Discover institutes laboratories technologies products projects of BİLGEM.

MILSEC 4 - Secure IP Terminal

SAFE IP TERMINAL

While the MİLSEC-4 terminal offers an up-to-date solution for next-generation secure communication (voice, data and video) in IP networks, it provides an uninterrupted communication service by maintaining the compatibility of secure voice communication in PSTN networks with PSTN secure phones in use.
provides.

Configuration, surveillance and software update processes of MILSEC-4 terminals are carried out securely remotely using the Security Management Center (GYM). MİLSEC-4 terminal is capable of IP Network Key Loading (IPAAY) through secure communication with GYM without the need for an additional device.

MİLSEC-4 terminals are interoperable with MİLSEC-1A and MİLSEC-2 phones and offer the opportunity to replace MİLSEC-1A and MİLSEC-2 phones without interruption in the gradual transformation of PSTN networks to next generation IP networks.

FEATURES

  • End-to-end secure voice communication in PSTN networks
  • End-to-end secure voice, image and data transmission in IP networks
  • NATO SCIP compliance on IP networks
  • Compatibility with commercial SIP products
  • Interoperability with MILSEC1A and MILSEC2 secure phones
  • National and AES crypto algorithms
  • Remote software update
  • Easy operation with touch screen

It is subject to the sales license to be given by the Ministry of National Defense.