Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
This document addresses the proper use of iDynamo 5 Gen III secure card readers (SCR), in a secure manner. This includes information about key-management responsibilities, administrative responsibilities, device functionality, identification, and environmental requirements.
The use of this secure card reader in any method not described in this security policy will invalidate the PCI PTS POI v6.2 approval of the device.
Throughout this document:
iDynamo 5 Gen III refers to all products in the iDynamo 5 Gen III product family.
Document Number: D998200619-108
REGISTERED TO ISO 9001:2015
MagTek® is a registered trademark of MagTek, Inc.
MagnePrint® is a registered trademark of MagTek, Inc.
MagneSafe® is a registered trademark of MagTek, Inc.
Magensa™ is a trademark of MagTek, Inc. iDynamo™ is a trademark of MagTek, Inc.
ANSI®, the ANSI logo, and numerous other identifiers containing "ANSI" are registered trademarks, service marks, and accreditation marks of the American National Standards Institute (ANSI).
ISO® is a registered trademark of the International Organization for Standardization.
UL™ and the UL logo are trademarks of UL LLC.
PCI Security Standards Council® is a registered trademark of the PCI Security Standards Council, LLC.
Apple Pay®, Apple Wallet®, iPhone®, iPod®, Mac®, and OS X® are registered trademarks of Apple Inc., registered in the U.S. and other countries. iPad™ is a trademark of Apple. Inc. App StoreSM is a service mark of Apple Inc., registered in the U.S. and other countries. Apple and MFi are registered trademarks of Apple Inc. IOS is a trademark or registered trademark of Cisco in the U.S. and other countries and is used by Apple Inc. under license.
Google Play™ store, Google Wallet™ payment service, and Android™ platform are trademarks of Google LLC.
Microsoft®, Windows®, and .NET® are registered trademarks of Microsoft Corporation.
All other system names and product names are the property of their respective owners
Table 0-1
The following documents may be used to provide additional details about the device and this security policy:
MagTek iDynamo 5 Gen III Installation and Operation Manual PN: D998200614
MagTek iDynamo 5 Gen III SRED, Device Inspection Manual PN: D998200620
NIST SP 800-57-1 Recommendation for Key Management
ANS X9.24 Part 3:2017, Retail Financial Services Symmetric Key Management, Part 3: Derived Unique Key Per Transaction Using Symmetric Techniques
X9 TR-31:2010, Interoperable Secure Key Exchange Key Block Specification for Symmetric Algorithms
X9.143 (TR-31) Symmetric Key
Rev Number
Date
Notes
108
December 18, 2024
Initial Release

After receiving the device, the customer should visually inspect the product as follows:
Inspect the label found on the back of the device (see section 2.3.1 Hardware Identification) and make sure the label is not missing, obscured, or modified.
Check the PCI Hardware Identifier on the device label and make sure it matches the Hardware # listed for the device on the PCI website for Approved Devices. Go to the PCI compliance web page and search for MagTek, and find the product name, iDynamo 5 Gen III. Compare the Hardware ID and Firmware ID: https://www.pcisecuritystandards.org/assessors_and_solutions/pin_transaction_devices
Note: Firmware ID is accessible by connecting iDynamo 5 Gen III to a host device via USB-C, using the latest software provided by MagTek (see Firmware Identification).
Check the Device serial number (SN) and make sure it matches with labels on shipping materials and documentation.
Visually inspect the device, per [2], which is included in the package with each device. See section 4.1 Periodic Inspection for more information regarding visual inspection of the device.
Follow the steps in Firmware Identification to view the PCI firmware versions installed on the device. Make sure this matches one of the Firmware # values listed on the PCI web site for iDynamo 5 Gen III.
Connect the device to a host via USB-C for control and power. iDynamo 5 Gen III products are designed to provide flexible mounting options such as:
External clip
Embedded lanyard
See the device installation and operation manual for more information on how to handle and operate the device, [1].
The specified environmental conditions to operate and store the device are:
Operating temperature range: 32°F to 95°F (0°C to 35°C) 5-90% RH with no condensation.
Storage temperature range: -4°F to 113°F (-20°C to 45°C) 10-90% RH with no condensation.
Power Supply: DC 5.0 V/1.0A
Any temperature or operating voltage outside the values listed above will trigger environmental security protections, resulting in a tamper condition. The device will need to be returned to the factory for inspection before this condition can be cleared.
iDynamo 5 Gen III products support a USB-C interface using the USB-HID protocol. Transactions, configuration, firmware updates, and key injection can all be performed using this interface type. Use of any method not listed in this security policy will invalidate the device’s PCI PTS approval.
iDynamo 5 Gen III products ship from the factory fully secure. The devices have no configuration settings that require modification by the user to meet PCI security requirements.
The merchant or acquirer should inspect the appearance of secure card reader on a daily basis:
Inspect the appearance of secure card reader to make sure it is the right product.
Inspect whether the Swipe Path has an additional card reader or other inserted bugs, See Figure 4-1, below.
Inspect whether the product appearance has been changed.
Check if the firmware version is correct.
After connecting the device to a USB-C power supply, it will power on, the LED indicator should illuminate green and remain powered on to indicate the device is in an idle state, ready for a transaction. Powering on the secure card reader will test hardware security and authenticity, and the integrity of the installed firmware.
MSR Swipe Path: The swipe path is smooth. The only moving part is the spring-mounted read head that depresses into the device as the card’s magnetic stripe makes contact with the read head.
Figure 4-1 - Card Swipe Path Example
MagTek strongly recommends performing security inspections on a regular schedule. Additional information can be found in [2]. If any problems are detected, stop using the device, set it aside in a secure location, and contact the manufacturer or your acquirer for further advice.
iDynamo 5 Gen III performs self-tests at power-up and after reset. The device automatically resets and performs self-tests every 24 hours at the configured time of day. No manual intervention by the operator is required. Self-tests include:
Checking the integrity and authenticity of the firmware and cryptographic keys.
Checking security mechanisms for signs of tampering.
The secure card reader has no functionality that gives access to security-sensitive services based on roles. Such services are managed through dedicated tools, using cryptographic authentication.
iDynamo 5 Gen III products ship from the factory fully secure. The devices have no security related default values (e.g., passwords/authentication codes/certificates) that require modification by the user to meet PCI security requirements.
If the device senses a physical or environmental attack, it erases all sensitive keys and will have limited functionality. While powered on, the SCR indicates it is in a tampered state by illuminating its only LED solid red, as seen in Figure 4-2 Tamper Response. If this occurs:
Remove the device from service immediately.
Store it securely for a possible forensics investigation.
Contact the manufacturer for assistance. The device will likely need to be returned to the manufacturer for diagnosis and servicing.
Figure 4-2 Tamper Response
iDynamo 5 Gen III products support file-based updates of the device’s core firmware (main firmware) and authorized commands for updating sensitive configuration. For optimal device security, MagTek recommends the latest versions of firmware should always be installed.
Firmware updates are provided as files that have been signed by MagTek. The firmware files can be loaded locally through the USB-C interface by using update tools available from the MagTek web site. The device verifies each update is newer than the installed version, and cryptographically authenticates the file with RSA-2048 and SHA-256. If version checking or authentication fails, the device erases the update file and reports an error to the host.
Before iDynamo 5 Gen III products are permanently removed from service, all the keys and sensitive data must be erased. One way to accomplish this is by temporarily removing the back cover, which forces a tamper response.
If removal from service is only temporary, no action is required. All sensitive data will continue to be protected by the device’s physical and logical protection mechanisms.
The device always encrypts account data from the MSR using 112-bit TDEA, 128-bit AES, or 256-bit AES algorithms with X9.24 DUKPT key management. This device does not support any mechanisms such as whitelists or SRED disable that would allow the data to be sent out unencrypted. The programmers need to follow the guidance provided in [3]. Use of the device with key-management systems not described in this policy will invalidate the PCI PTS POI v6.2 approval of the device.
The device includes the following cryptographic algorithms:
AES-128/256
TDEA-128



Sensor
Low Threshold Value
High Threshold Value
Internal Voltage
2.2V ± 0.1V
4.2V ± 0.2V
Temperature
-48°C to -27°C
Note that in PCI listings, lowercase “x” is a wildcard meaning ‘any single character.’
95°C to 105°C
Contactless
DES
Data Encryption Standard
DUKPT
Derived Unique Key Per Transaction
ECC
Elliptic-Curve Cryptography
FSK
Firmware Signing Key
ICCR
Integrated Circuit Card Reader
MAC
In cryptography: Message Authentication Code In networking: Media Access Control [address]
MSR
Magnetic Stripe Reader
NFC
Near Field Communication
POI
Point Of Interaction
S/N
Serial Number
SCRA
Secure Card Reader Authenticator
SHA
Secure Hash Algorithm
SRED
Secure Reading and Exchange of Data
TDEA
Triple Data Encryption Algorithm
USB
Universal Serial Bus
USB HID
USB Human Interface Device
Acronym
Definition
AES
Advanced Encryption Standard
BCR
Barcode Reader
CTLS
ECDSA (P256 and P521)
RSA2048
SHA-256
The device implements the original AES/TDEA DUKPT as its only key management method. Use of any other method will invalidate PCI approval. DUKPT derives a new unique key for every transaction. For more details, see [5] and [6].
Key Name
Size
Algorithm
Purpose
Transport Keys:
· Master Transport Key
· Device Transport Key
· Financial Transport Key
· Production Transport Key
· Manufacturing Transport Key
· MagTek KIF Financial Transport Key
32 bytes
AES X9.143 KBPKs
Key Injection
The device does not support manual or plaintext cryptographic key entry. Only specialized tools, compliant with key management requirements and cryptographic methods, specifically [6] and [7]. On the production line, the ANSI X9.143 format can be used for key loading by an HSM after mutual authentication. Use of any other methods will invalidate PCI approval.
Keys should be replaced with new keys whenever the original key is known or suspected to have been compromised, and whenever the time deemed feasible to determine the key by exhaustive attack has elapsed, as defined in [4].
Account Data Key
· DKPTM7-FK
16 bytes for TDEA and AES- 128
32 bytes for AES-256
AES and TDEA DUKPT (ANS X9.24-3)
Encrypt and MAC Account Data
Firmware Protection Key
· Firmware Signing Key (FSK)
256 bytes
RSA2048 and SHA-256
Checks integrity and authenticity of firmware
The front view of iDynamo 5 Gen III, is shown in Figure 2-1 below. The back view of iDynamo 5 Gen III is shown in Figure 2-2. The side views of iDynamo 5 Gen III can be seen in Figure 2-3 and Figure 2-4. The Top View displaying the pushbutton and LED indicator can be seen in Figure 2-5, and the Bottom View displaying the USB-C receptacle can be seen in Figure 2-6.
Figure 2-1 - Front View
Figure 2-2 - Back View
Figure 2-3 - Left Side View
Figure 2-4 - Right Side view
Figure 2-5 - Top View
Figure 2-6 - Bottom View
iDynamo 5 Gen III devices include a USB-C interface for Power and Communications, and a magnetic stripe reader (MSR). It is designed for attended and unattended environments.
iDynamo 5 Gen III can be used as a desktop or handheld device. It is approved as a secure card reader (SCR) under PCI PTS POI v6.2 requirements.
Usage in any other environment will invalidate PCI approval.
To find important product identification information, look for the printed product label on the back face of the device as shown in Figure 2-7 below.
Figure 2-7 – iDynamo 5 Gen III Device Label Location
The product label includes the following elements of device identification information, shown by the numbered callouts in Figure 2-8.
Product Name
PCI Hardware Identifier (“HW”)
Figure 2-8 -iDynamo 5 Gen III Device Label
The label also contains other supporting information about the device.
The hardware version of the device is 10PCI50U0xAx . All iDynamo 5 Gen III hardware configurations are listed in Table 2-1 below. The device utilizes one interface type, USB-C. Use of any interface otherthan USB-C will invalidate PCI approval.
The most recent firmware versions for iDynamo 5 Gen III products are 1000009547-AAx-PCI for the secure bootloader, and 1000009535-AAx-PCI for the main firmware. The lowercase x in firmware versions indicates minor non-security related changes, see Table 2-3 and Table 2-4.
All device identification information, including firmware versions and PCI Hardware ID, is accessible by connecting iDynamo 5 Gen III to a host device via USB-C using the latest software provided by MagTek, as seen in Figure 2-9 - Device Information Screen.
The host user can retrieve device information at any time using Command 0x0000 Get Property as described in [3].
Figure 2-9 - Device Information Screen
10
11
12
1
0
P
C
I
U
x
A
6
Device Options 5 = Standard
7
Option RFU (Reserved for Future Use) RFU 0 = as Certified
8
Interface Options U = USB
9
Option RFU (Reserved for Future Use) RFU 0 = as Certified
11
10
Cover Color: B = Black
11
Version A = as Certified
11
12
minor fixes not adding functionality or related to security (e.g., change component value for antenna matching): 0 = as certified
10
11
12
13
14
15
16
17
18
1
0
0
0
0
5
5
-
12-13
AA = Certified Version
14
Minor Revisions, Bug Fixes
15
Delimiter (-)
16-18
PCI = PCI Version of Firmware
10
11
12
13
14
15
16
17
18
1
0
0
0
0
5
5
-
12-13
AA = Certified Version
14
Minor Revisions, Bug Fixes
15
Delimiter (-)
16-18
PCI = PCI Version of Firmware
PCI ID Tag
Configuration Description
10PCI50U0BA0
iDynamo 5 Gen III, PCI, BLACK
PCI Hardware ID Number
1
2
3
4
5
8
Fixed Position
Variable "X" Position
Description of Fixed or Variable “X” in the Selection Position
1-2
10 = iDynamo 5 Gen III
3-5
Firmware Number
1
2
3
4
5
8
Fixed Position
Variable “x” Position
Description of Fixed or Variable “x” in the Selected Position
1-10
1000009535 = iDynamo 5 Gen III Main Firmware Part Number
11
Firmware Number
1
2
3
4
5
8
Fixed Position
Variable “x” Position
Description of Fixed or Variable “x” in the Selected Position
1-10
1000009547 = iDynamo 5 Gen III Boot Firmware Part Number
11










PCI = PCI Hardware
Delimiter (-)
Delimiter (-)
x
A
A
x
-
P
C
I
A
A
x
-
P
C
I