{"id":4996,"date":"2018-06-18T11:58:37","date_gmt":"2018-06-18T08:58:37","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=4996"},"modified":"2019-11-15T14:40:40","modified_gmt":"2019-11-15T11:40:40","slug":"secure-element","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/secure-element\/4996\/","title":{"rendered":"G\u00fcvenli \u00d6\u011fe: ak\u0131ll\u0131 telefonlarda temass\u0131z \u00f6demeleri g\u00fcvenceye alma"},"content":{"rendered":"<p>Modern ak\u0131ll\u0131 telefonlar y\u0131llard\u0131r telefon, kamera, m\u00fczik \u00e7alar, toplu ta\u015f\u0131ma kart\u0131 ve hatta c\u00fczdan i\u015flevlerini ba\u015far\u0131yla bir araya getirmi\u015ftir. Do\u011fal olarak bu da saklad\u0131klar\u0131 verinin g\u00fcvenli\u011fini merak etmenize neden olur. Hadi ak\u0131ll\u0131 telefonlar\u0131n, kullan\u0131c\u0131lar\u0131n en de\u011ferli bilgilerini nas\u0131l korudu\u011funu ve temel g\u00fcvenlik mekanizmas\u0131 olan G\u00fcvenli \u00d6\u011fe isimli k\u00fc\u00e7\u00fck bir yongan\u0131n nas\u0131l \u00e7al\u0131\u015ft\u0131\u011f\u0131na bakal\u0131m.<\/p>\n<h2>G\u00fcvenli \u00d6\u011fe ile Tan\u0131\u015f\u0131n<\/h2>\n<p>G\u00fcvenli \u00f6deme bilgilerini saklayacak \u00f6zel bir yonga, temass\u0131z kredi kartlar\u0131ndan ak\u0131ll\u0131 telefonlara ta\u015f\u0131nd\u0131. G\u00fcn\u00fcm\u00fczde en g\u00fcvenilir standart olan EMV (Europay, MasterCard, Visa) standard\u0131n\u0131 duymu\u015f olabilirsiniz. Bununla birlikte \u00f6deme bilgileriniz, k\u0131rman\u0131n neredeyse imkans\u0131z oldu\u011fu korumal\u0131 bir mikro\u00e7ip \u00fczerinde saklan\u0131r. Bu y\u00fczden EMV standard\u0131n\u0131 kullanan kartlara basit\u00e7e \u201cyongal\u0131 kart\u201d denir.<\/p>\n<p>Telefonunuzdaki G\u00fcvenli \u00d6\u011fe, asl\u0131nda kredi kartlar\u0131nda kullan\u0131lanla ayn\u0131 yongad\u0131r. Ayr\u0131 bir i\u015fletim sistemi vard\u0131r (evet, kredi kartlar\u0131nda programlar\u0131n\u0131 \u00e7al\u0131\u015ft\u0131racak kendi i\u015fletim sistemleri bulunuyor). T\u00fcm bilgileriniz bu yonga \u00fczerinde saklan\u0131r, telefon veya tablete y\u00fcklenen uygulamalar \u015f\u00f6yle dursun, bu cihazlar\u0131n i\u015fletim sistemi taraf\u0131ndan bile okunamaz veya kopyalanamaz. G\u00fcvenli \u00d6\u011fe, se\u00e7kin sanal c\u00fczdanlar gibi yaln\u0131zca \u00f6zel ve g\u00fcvenilir uygulamalarla \u00e7al\u0131\u015f\u0131r.<\/p>\n<p>Yonga, \u00f6deme terminalleriyle do\u011frudan ileti\u015fime ge\u00e7er, b\u00f6ylece ak\u0131ll\u0131 telefon k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mdan etkilenmi\u015f olsa bile korsanlar bu bilgiyi tutamaz. \u00c7\u00fcnk\u00fc veriler, ana i\u015fletim sistemine aktar\u0131lmaz, G\u00fcvenli \u00d6\u011fe\u2019nin \u00f6zel sisteminde hi\u00e7bir yere gitmeden kal\u0131r.<\/p>\n<h2>Telefon c\u00fczdan\u0131: Nas\u0131l ba\u015flad\u0131?<\/h2>\n<p>Telefonun kredi kart\u0131yla birle\u015ftirilmesi fikri asl\u0131nda d\u00fc\u015f\u00fcnd\u00fc\u011f\u00fcn\u00fczden daha da eskilere uzan\u0131yor. G\u00fcvenli \u00d6\u011fe y\u00fckl\u00fc ilk modeller <a href=\"https:\/\/www.nfcworld.com\/nfc-devices\/nokia-6131-nfc\/\" target=\"_blank\" rel=\"noopener nofollow\">\u00f6zellikli telefonlard\u0131<\/a>, yine de hi\u00e7 pop\u00fcler olmad\u0131lar. Hatta bir \u015firket bir ara\u00e7la <a href=\"https:\/\/www.looppay.com\/about-us\/\" target=\"_blank\" rel=\"noopener nofollow\">manyetik \u015ferit taklidi yapma y\u00f6ntemi<\/a> bile icat etti. Ama telefonlar ancak yak\u0131n zamanda, 2014\u2019te, Apple Pay\u2019in lansman\u0131ndan sonra plastik kartlar i\u00e7in ger\u00e7ek bir rakibe d\u00f6n\u00fc\u015ft\u00fc.<\/p>\n<p>Apple Pay\u2019in ba\u015far\u0131s\u0131 rakiplerinin ilgisini \u00e7ekti ve 2015\u2019te Samsung benzeri bir hizmet sunmaya ba\u015flad\u0131. \u0130ki sistem de G\u00fcvenli \u00d6\u011fe gerektiriyor (bu y\u00fczden eski iPhone\u2019lar ve ucuz Samsung modelleri temass\u0131z \u00f6demeyi desteklemiyor).<\/p>\n<p>Hatta, bu Kore \u015firketi cihazlar\u0131n\u0131n i\u015flevselli\u011fini geli\u015ftirme amac\u0131yla manyetik \u015ferit taklidi teknolojisini geli\u015ftiren \u015firketi, LoopPay\u2019i, <a href=\"https:\/\/www.kaspersky.com\/blog\/samsung-pay-security\/7932\/\" target=\"_blank\" rel=\"noopener nofollow\">sat\u0131n ald\u0131<\/a>. Birka\u00e7 ay sonra Google, Android Pay\u2019i tan\u0131tt\u0131 (2018 ba\u015flar\u0131nda ad\u0131 Google Pay olarak de\u011fi\u015ftirildi).<\/p>\n<h2>G\u00fcvenli \u00d6\u011fe: yerle\u015fik, harici veya bulut tabanl\u0131<\/h2>\n<p>Asl\u0131nda G\u00fcvenli \u00d6\u011fe\u2019nin ak\u0131ll\u0131 telefona yerle\u015ftirilmesi gerekmiyor. \u00c7\u0131kar\u0131labilir bir \u00f6zelli\u011fe sahip: \u00f6rne\u011fin, haf\u0131za kart\u0131 bi\u00e7iminde. Baz\u0131 mobil operat\u00f6rler kredi kart\u0131 ve toplu ta\u015f\u0131ma kart\u0131 bilgilerinizi saklayabilen SIM kartlar bile \u00fcretiyor. Yine de bu se\u00e7enekler hi\u00e7 pop\u00fcler olmad\u0131.<\/p>\n<p>Apple veya Samsung\u2019un aksine Google; temel olarak bu cihazlar\u0131 de\u011fil, bu cihazlarda yer alacak yaz\u0131l\u0131mlar\u0131 \u00fcretiyor. Bu y\u00fczden de \u00f6deme sistemi ba\u015flang\u0131\u00e7ta \u00e7ok fazla zorlukla kar\u015f\u0131la\u015ft\u0131. \u00d6ncelikle, \u00e7o\u011fu Android telefonda G\u00fcvenli \u00d6\u011fe yongas\u0131 bulunmuyordu. \u015eirket, ba\u011f\u0131ms\u0131z \u00fcreticileri g\u00fcvenli yonga y\u00fcklemeye veya kullan\u0131c\u0131lar\u0131 yeni bir kart almaya zorlayamazd\u0131. G\u00fcvenli \u00d6\u011fe olmadan temass\u0131z \u00f6deme de ger\u00e7ekle\u015ftiremezdi.<\/p>\n<p>\u00d6nce, Google bu durumdan kurtulmak i\u00e7in bir yol bulmaya \u00e7al\u0131\u015farak c\u00fczdan uygulamas\u0131n\u0131 G\u00fcvenli \u00d6\u011fe ile SIM kartlara y\u00fcklemeyi <a href=\"http:\/\/pocketnow.com\/2012\/03\/21\/google-wallet-gets-in-bed-with-carriers-editorial\" target=\"_blank\" rel=\"noopener nofollow\">denedi<\/a>. Ancak Amerika\u2019n\u0131n \u00f6nde gelen cep telefonu operat\u00f6rleri, Verizon, AT&amp;T, ve T-Mobile, \u015firketle i\u015f birli\u011fi yapmay\u0131 reddederek bunun yerine kendi uygulamalar\u0131n\u0131 \u00f6ne s\u00fcrd\u00fcler, uygulama ba\u015fta Isis Wallet olarak adland\u0131r\u0131lm\u0131\u015ft\u0131 ama sonra politik kayg\u0131larla Softcard olarak de\u011fi\u015ftirildi. Dikkatleri \u00e7eken \u015fey ise; b\u00fct\u00fcn bunlar\u0131n sonucunun, Google\u2019\u0131n patentler i\u00e7in sistemi sat\u0131n almas\u0131 oldu.<\/p>\n<p>Yine de bunun \u00f6ncesinde \u015firket, soruna \u00e7ok daha zarif bir \u00e7\u00f6z\u00fcmle geldi. Android telefonlarda fiziksel g\u00fcvenlik yongas\u0131 y\u00fckl\u00fc olmamas\u0131na ra\u011fmen bulut ortam\u0131nda sanal g\u00fcvenlik yongalar\u0131 olu\u015fturuldu. Bu teknolojiye Host Card Emulation (Ana Kart Em\u00fclasyonu, HCE) ad\u0131 verildi.<\/p>\n<p>Bu bulut tabanl\u0131 sistem, yerle\u015fik G\u00fcvenli \u00d6\u011fe yongal\u0131 c\u00fczdanlarla \u00f6nemli bir a\u00e7\u0131dan farkl\u0131l\u0131k g\u00f6steriyordu. HCE, \u00f6deme terminalinin cihaz i\u015fletim sistemi ile ileti\u015fim kurmas\u0131n\u0131 gerektiriyor. Bu i\u015fletim sistemi, \u00f6deme bilgilerinin sakland\u0131\u011f\u0131 bulut tabanl\u0131 bir G\u00fcvenli \u00d6\u011fesi\u2019nin yan\u0131 s\u0131ra g\u00fcvenilir bir uygulama ile de ileti\u015fim kurmak durumunda.<\/p>\n<p>Uzmanlar HCE kullanman\u0131n teknik olarak ger\u00e7ek bir G\u00fcvenli \u00d6\u011fe kullanmak kadar <a href=\"https:\/\/www.tomshardware.com\/news\/host-card-emulation-secure-element,28804.html\" target=\"_blank\" rel=\"noopener nofollow\">g\u00fcvenli olmad\u0131\u011f\u0131n\u0131<\/a> belirtiyor: Veriler internetten ne kadar \u00e7ok ge\u00e7erse, m\u00fcdahale etmesi de o kadar kolay olacakt\u0131r. Yine de HCE, bu g\u00fcvenlik a\u00e7\u0131\u011f\u0131n\u0131 olu\u015fturan ek koruma mekanizmalar\u0131n\u0131 da i\u00e7eriyor: \u00f6rne\u011fin, kal\u0131c\u0131 \u00f6deme anahtarlar\u0131n\u0131 de\u011fil, yaln\u0131zca tek kullan\u0131ml\u0131k ge\u00e7ici anahtarlar\u0131 kullan\u0131yor.<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"android-malware\">\n<h2>Devam\u0131 gelecek<\/h2>\n<p>Art\u0131k \u00f6deme verilerini telefonunuzda saklamak i\u00e7in kullan\u0131lan \u201ckara kutu\u201d nedir, biliyorsunuz. Sonraki makalede Android ve iOS cihazlar\u0131n G\u00fcvenli \u00d6\u011fe\u2019ye dayal\u0131 temass\u0131z \u00f6deme sistemlerini nas\u0131l kulland\u0131\u011f\u0131na bakaca\u011f\u0131z. Ayr\u0131ca birinin Apple Pay, Google Pay veya Samsung Pay\u2019i kar\u0131\u015ft\u0131rmadan bir banka kart\u0131n\u0131 ak\u0131ll\u0131 telefonunda neden saklayamayaca\u011f\u0131ndan da bahsedece\u011fiz.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Modern ak\u0131ll\u0131 telefonlar y\u0131llard\u0131r telefon, kamera, m\u00fczik \u00e7alar, toplu ta\u015f\u0131ma kart\u0131 ve hatta c\u00fczdan i\u015flevlerini ba\u015far\u0131yla bir araya getirmi\u015ftir. Do\u011fal olarak bu da saklad\u0131klar\u0131 verinin g\u00fcvenli\u011fini merak etmenize neden olur. Hadi ak\u0131ll\u0131 telefonlar\u0131n, kullan\u0131c\u0131lar\u0131n en de\u011ferli bilgilerini nas\u0131l korudu\u011funu ve temel g\u00fcvenlik mekanizmas\u0131 olan G\u00fcvenli \u00d6\u011fe isimli k\u00fc\u00e7\u00fck bir yongan\u0131n nas\u0131l \u00e7al\u0131\u015ft\u0131\u011f\u0131na bakal\u0131m.<\/p>\n","protected":false},"author":2484,"featured_media":4997,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[995],"tags":[580,105,1634,1635,1637,1639,750,1638,878,1636],"class_list":{"0":"post-4996","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-technology","8":"tag-akilli-telefon","9":"tag-android","10":"tag-android-pay","11":"tag-apple-pay","12":"tag-google-pay","13":"tag-guvenli-element","14":"tag-ios","15":"tag-samsung-pay","16":"tag-teknoloji","17":"tag-temassiz-odeme"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/secure-element\/4996\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/secure-element\/13354\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/secure-element\/11136\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/secure-element\/15411\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/secure-element\/13687\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/secure-element\/13003\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/secure-element\/16189\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/secure-element\/15752\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/secure-element\/20556\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/secure-element\/22408\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/secure-element\/10596\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/secure-element\/10424\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/secure-element\/9224\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/secure-element\/16797\/"},{"hreflang":"zh","url":"https:\/\/www.kaspersky.com.cn\/blog\/secure-element\/9670\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/secure-element\/20379\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/secure-element\/20298\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/secure-element\/20295\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/akilli-telefon\/","name":"ak\u0131ll\u0131 telefon"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/4996","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/2484"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=4996"}],"version-history":[{"count":2,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/4996\/revisions"}],"predecessor-version":[{"id":6927,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/4996\/revisions\/6927"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/4997"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=4996"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=4996"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=4996"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}