AKİS
AKİS Solutions
National Identity Card / TR - TRNC Identity Card

Electronic ID Card Application
- Visual authentication:
Photograph, wet signature, guilloche, rainbow print, MLI, micro text, raster print, charm, relief print, optical variable ink, ultraviolet ink and OVD/DOVID - Electronic authentication:
Electronic certificate, digital photo, PIN - Biometric authentication:
Fingerprint, finger vein print, hand palm print - Ability to upload a Qualified Electronic Certificate (QC) and private key
- ISO/IEC 7816-3 contact-based communication
- ISO/IEC 7816-4, 8, 9 compliant APDU command set
- Secure messaging with AES-256
- Hash computation (SHA-1, SHA-256, SHA-384, SHA-512)1
- Random Number Generator (RNG) 2
- Card Verifiable Certificates3
- Role-based access control mechanism
- RSA Digital Signature Generation and Decryption3
- RSA key pair generation4
- ECDSA digital signature generation (ECC 128–640 bits)5
- ECC key pair generation (ECC 128 - 640 bit range)5
- Cryptographic checksum computation (DES3 MAC/CMAC/RetailMAC, AES MAC/CMAC)5
- Symmetric encryption/decryption (DES3, AES: CBC, ECB, GCM)6
- Wrap/Unwrap Key7
- ECDH Key Derivation7
- Session-based symmetric key generation7
- Session-based ECC key pair generation7
- Common Criteria (CC) EAL 4+ security evaluation
- Support for multiple chip platforms8
- UKTUM-H v7.01
- Infineon SLE78CFX2400P
- NXP P71D320P, P71D352P
- PKCS#119 driver support
- Support for CSP and Minidriver10
1AKiS v2.2 supports SHA-1 and SHA-256 only.
2AKiS v2.2 supports true random number generation, whereas AKiS v2.5 and v2.6 support Hybrid Deterministic random number generation.
3AKiS v2.5 supports RSA 1024–2816 bits, AKiS v2.6 supports RSA 1024–2688 bits, whereas AKiS v2.2 supports RSA 1024 bits and 2048 bits only.
4 AKiS v2.5 supports RSA 1024–2816 bits, AKiS v2.6 supports RSA 1024–2688 bits, whereas AKiS v2.2 supports RSA 2048 bits only.
5AKiS v2.5 and v2.6 only.
6AKiS v2.5 and v2.6 only (block type GCM supported by AKiS v2.6 only).
7AKiS v2.6 only.
8Hardware platforms are certified for CC EAL 5+ or above.
9 MS Windows, Linux and MacOS operating systems.
10 MS Windows operating system only.
Electronic Travel Document Application
- Compliance with standards
- ICAO Doc 9303
- ISO/IEC 14443-3, 4
- ISO/IEC 7816-4, 8, 9
- ICAO Technical Report: Supplemental Access Control for MRTDs
- BSI TR-03110
- BSI TR-03111
- ICAO LDS 1.71 compatible with data structure
- Basic Access Control (BAC)
- Active Authentication (AA)
- RSA (up to 2560 bits)2: SHA-1, SHA-256, SHA-384, SHA-512 2
- ECC (up to 521 bits): SHA-1, SHA-224, SHA-256, SHA-384, SHA-512
- Supplemental Access Control (SAC)
- PACE v2
- MRZ, CAN, and PIN3support
- Support for Generic Mapping and Integrated Mapping
- ECDH (Brainpool curves up to 512 bits)
- DH (1024 bit, 2048 bit)
- Extended Access Control (EAC)
- EAC v14
- RSA (up to 3072 bits): SHA-1, SHA-256, SHA-512
- ECC (up to 521 bits): SHA-1, SHA-224, SHA-256, SHA-384, SHA-512
- Contactless Communication
- ISO/IEC 14443-3, 4 Type A
- Baud rate: 424/848 kbps
- Secure Messaging
- DES3
- AES-128, AES-192, AES-256
- Common Criteria (CC) Security Evaluation
- CC EAL 4+ for BAC (ALC_DVS.2)
- CC EAL 5+ for SAC & EAC (ALC_DVS.2, AVA_VAN.5)
- Support for multiple chip platforms5
- Infineon6SLE78CLFX3000P, SLE78CLFX308AP, SL78CLFX4000P, SLE78CLFX408AP
- NXP P71D320P6, P71D352P7
- Compliance with standards
- ICAO Doc 9303
- ISO/IEC 14443-3, 4
- ISO/IEC 7816-4, 8, 9
- ICAO Technical Report: Supplemental Access Control for MRTDs
- BSI TR-03110
- BSI TR-03111
1In AKiS GEZGİN v2.0 supports more data groups than defined by ICAO.
2Maximum supported RSA bit length for AKiS GEZGiN v1.x is 2048 bits.
3Support for PINs is available only for AKiS GEZGiN v2.0.
4AKiS GEZGiN v2.0 supports a maximum of 32 roles.
5Hardware platforms are certified for CC EAL 6+.
6AKiS GEZGiN v1.x only.
7KiS GEZGiN v2.0 only.




