All pages
Powered by GitBook
1 of 8

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Purpose

This document addresses the proper use of iDynamo 5 Gen III secure card readers (SCR), in a secure manner. This includes information about key-management responsibilities, administrative responsibilities, device functionality, identification, and environmental requirements.

The use of this secure card reader in any method not described in this security policy will invalidate the PCI PTS POI v6.2 approval of the device.

Throughout this document:

  • iDynamo 5 Gen III refers to all products in the iDynamo 5 Gen III product family.

Secure Card Reader Security Policy

Document Number: D998200619-108

REGISTERED TO ISO 9001:2015

MagTek® is a registered trademark of MagTek, Inc.

MagnePrint® is a registered trademark of MagTek, Inc.

MagneSafe® is a registered trademark of MagTek, Inc.

Magensa™ is a trademark of MagTek, Inc. iDynamo™ is a trademark of MagTek, Inc.

ANSI®, the ANSI logo, and numerous other identifiers containing "ANSI" are registered trademarks, service marks, and accreditation marks of the American National Standards Institute (ANSI).

ISO® is a registered trademark of the International Organization for Standardization.

UL™ and the UL logo are trademarks of UL LLC.

PCI Security Standards Council® is a registered trademark of the PCI Security Standards Council, LLC.

Apple Pay®, Apple Wallet®, iPhone®, iPod®, Mac®, and OS X® are registered trademarks of Apple Inc., registered in the U.S. and other countries. iPad™ is a trademark of Apple. Inc. App StoreSM is a service mark of Apple Inc., registered in the U.S. and other countries. Apple and MFi are registered trademarks of Apple Inc. IOS is a trademark or registered trademark of Cisco in the U.S. and other countries and is used by Apple Inc. under license.

Google Play™ store, Google Wallet™ payment service, and Android™ platform are trademarks of Google LLC.

Microsoft®, Windows®, and .NET® are registered trademarks of Microsoft Corporation.

All other system names and product names are the property of their respective owners

Table 0-1

Appendix A References

The following documents may be used to provide additional details about the device and this security policy:

  • MagTek iDynamo 5 Gen III Installation and Operation Manual PN: D998200614

  • MagTek iDynamo 5 Gen III SRED, Device Inspection Manual PN: D998200620

MagTek iDynamo 5 Gen III Programmer’s Manual COMMANDS PN: D998200587
  • NIST SP 800-57-1 Recommendation for Key Management

  • ANS X9.24 Part 3:2017, Retail Financial Services Symmetric Key Management, Part 3: Derived Unique Key Per Transaction Using Symmetric Techniques

  • X9 TR-31:2010, Interoperable Secure Key Exchange Key Block Specification for Symmetric Algorithms

  • X9.143 (TR-31) Symmetric Key

  • Rev Number

    Date

    Notes

    108

    December 18, 2024

    Initial Release

    Installation and User Guidance

    Initial Inspection

    After receiving the device, the customer should visually inspect the product as follows:

    • Inspect the label found on the back of the device (see section 2.3.1 Hardware Identification) and make sure the label is not missing, obscured, or modified.

    • Check the PCI Hardware Identifier on the device label and make sure it matches the Hardware # listed for the device on the PCI website for Approved Devices. Go to the PCI compliance web page and search for MagTek, and find the product name, iDynamo 5 Gen III. Compare the Hardware ID and Firmware ID: https://www.pcisecuritystandards.org/assessors_and_solutions/pin_transaction_devices

    Note: Firmware ID is accessible by connecting iDynamo 5 Gen III to a host device via USB-C, using the latest software provided by MagTek (see Firmware Identification).

    • Check the Device serial number (SN) and make sure it matches with labels on shipping materials and documentation.

    • Visually inspect the device, per [2], which is included in the package with each device. See section 4.1 Periodic Inspection for more information regarding visual inspection of the device.

    • Follow the steps in Firmware Identification to view the PCI firmware versions installed on the device. Make sure this matches one of the Firmware # values listed on the PCI web site for iDynamo 5 Gen III.

    Connect the device to a host via USB-C for control and power. iDynamo 5 Gen III products are designed to provide flexible mounting options such as:

    • External clip

    • Embedded lanyard

    See the device installation and operation manual for more information on how to handle and operate the device, [1].

    The specified environmental conditions to operate and store the device are:

    • Operating temperature range: 32°F to 95°F (0°C to 35°C) 5-90% RH with no condensation.

    • Storage temperature range: -4°F to 113°F (-20°C to 45°C) 10-90% RH with no condensation.

    • Power Supply: DC 5.0 V/1.0A

    Any temperature or operating voltage outside the values listed above will trigger environmental security protections, resulting in a tamper condition. The device will need to be returned to the factory for inspection before this condition can be cleared.

    iDynamo 5 Gen III products support a USB-C interface using the USB-HID protocol. Transactions, configuration, firmware updates, and key injection can all be performed using this interface type. Use of any method not listed in this security policy will invalidate the device’s PCI PTS approval.

    iDynamo 5 Gen III products ship from the factory fully secure. The devices have no configuration settings that require modification by the user to meet PCI security requirements.

    Operation and Maintenance

    Periodic Inspection

    The merchant or acquirer should inspect the appearance of secure card reader on a daily basis:

    • Inspect the appearance of secure card reader to make sure it is the right product.

    • Inspect whether the Swipe Path has an additional card reader or other inserted bugs, See Figure 4-1, below.

    • Inspect whether the product appearance has been changed.

    • Check if the firmware version is correct.

    • After connecting the device to a USB-C power supply, it will power on, the LED indicator should illuminate green and remain powered on to indicate the device is in an idle state, ready for a transaction. Powering on the secure card reader will test hardware security and authenticity, and the integrity of the installed firmware.

    MSR Swipe Path: The swipe path is smooth. The only moving part is the spring-mounted read head that depresses into the device as the card’s magnetic stripe makes contact with the read head.

    Figure 4-1 - Card Swipe Path Example

    MagTek strongly recommends performing security inspections on a regular schedule. Additional information can be found in [2]. If any problems are detected, stop using the device, set it aside in a secure location, and contact the manufacturer or your acquirer for further advice.

    iDynamo 5 Gen III performs self-tests at power-up and after reset. The device automatically resets and performs self-tests every 24 hours at the configured time of day. No manual intervention by the operator is required. Self-tests include:

    • Checking the integrity and authenticity of the firmware and cryptographic keys.

    • Checking security mechanisms for signs of tampering.

    The secure card reader has no functionality that gives access to security-sensitive services based on roles. Such services are managed through dedicated tools, using cryptographic authentication.

    iDynamo 5 Gen III products ship from the factory fully secure. The devices have no security related default values (e.g., passwords/authentication codes/certificates) that require modification by the user to meet PCI security requirements.

    If the device senses a physical or environmental attack, it erases all sensitive keys and will have limited functionality. While powered on, the SCR indicates it is in a tampered state by illuminating its only LED solid red, as seen in Figure 4-2 Tamper Response. If this occurs:

    • Remove the device from service immediately.

    • Store it securely for a possible forensics investigation.

    • Contact the manufacturer for assistance. The device will likely need to be returned to the manufacturer for diagnosis and servicing.

    Figure 4-2 Tamper Response

    iDynamo 5 Gen III products support file-based updates of the device’s core firmware (main firmware) and authorized commands for updating sensitive configuration. For optimal device security, MagTek recommends the latest versions of firmware should always be installed.

    Firmware updates are provided as files that have been signed by MagTek. The firmware files can be loaded locally through the USB-C interface by using update tools available from the MagTek web site. The device verifies each update is newer than the installed version, and cryptographically authenticates the file with RSA-2048 and SHA-256. If version checking or authentication fails, the device erases the update file and reports an error to the host.

    Before iDynamo 5 Gen III products are permanently removed from service, all the keys and sensitive data must be erased. One way to accomplish this is by temporarily removing the back cover, which forces a tamper response.

    If removal from service is only temporary, no action is required. All sensitive data will continue to be protected by the device’s physical and logical protection mechanisms.

    Acronyms

    Security

    The device always encrypts account data from the MSR using 112-bit TDEA, 128-bit AES, or 256-bit AES algorithms with X9.24 DUKPT key management. This device does not support any mechanisms such as whitelists or SRED disable that would allow the data to be sent out unencrypted. The programmers need to follow the guidance provided in [3]. Use of the device with key-management systems not described in this policy will invalidate the PCI PTS POI v6.2 approval of the device.

    The device includes the following cryptographic algorithms:

    • AES-128/256

    • TDEA-128

    Self-Test

    Roles and Responsibilities

    Passwords and Certificates

    Tamper Response

    Patching and Updating

    Decommissioning

    Sensor

    Low Threshold Value

    High Threshold Value

    Internal Voltage

    2.2V ± 0.1V

    4.2V ± 0.2V

    Temperature

    -48°C to -27°C

    Note that in PCI listings, lowercase “x” is a wildcard meaning ‘any single character.’

    Installation

    Environmental Conditions

    Communications and Security Protocols

    Configuration Settings

    95°C to 105°C

    Contactless

    DES

    Data Encryption Standard

    DUKPT

    Derived Unique Key Per Transaction

    ECC

    Elliptic-Curve Cryptography

    FSK

    Firmware Signing Key

    ICCR

    Integrated Circuit Card Reader

    MAC

    In cryptography: Message Authentication Code In networking: Media Access Control [address]

    MSR

    Magnetic Stripe Reader

    NFC

    Near Field Communication

    POI

    Point Of Interaction

    S/N

    Serial Number

    SCRA

    Secure Card Reader Authenticator

    SHA

    Secure Hash Algorithm

    SRED

    Secure Reading and Exchange of Data

    TDEA

    Triple Data Encryption Algorithm

    USB

    Universal Serial Bus

    USB HID

    USB Human Interface Device

    Acronym

    Definition

    AES

    Advanced Encryption Standard

    BCR

    Barcode Reader

    CTLS

    ECDSA (P256 and P521)

  • RSA2048

  • SHA-256

  • The device implements the original AES/TDEA DUKPT as its only key management method. Use of any other method will invalidate PCI approval. DUKPT derives a new unique key for every transaction. For more details, see [5] and [6].

    Key Name

    Size

    Algorithm

    Purpose

    Transport Keys:

    · Master Transport Key

    · Device Transport Key

    · Financial Transport Key

    · Production Transport Key

    · Manufacturing Transport Key

    · MagTek KIF Financial Transport Key

    32 bytes

    AES X9.143 KBPKs

    Key Injection

    The device does not support manual or plaintext cryptographic key entry. Only specialized tools, compliant with key management requirements and cryptographic methods, specifically [6] and [7]. On the production line, the ANSI X9.143 format can be used for key loading by an HSM after mutual authentication. Use of any other methods will invalidate PCI approval.

    Keys should be replaced with new keys whenever the original key is known or suspected to have been compromised, and whenever the time deemed feasible to determine the key by exhaustive attack has elapsed, as defined in [4].

    Account Data Protection

    Algorithms Supported

    Key Management

    Table 5-1 - iDynamo 5 Gen III Product Keys

    Key Loading

    Key Replacement

    Account Data Key

    · DKPTM7-FK

    16 bytes for TDEA and AES- 128

    32 bytes for AES-256

    AES and TDEA DUKPT (ANS X9.24-3)

    Encrypt and MAC Account Data

    Firmware Protection Key

    · Firmware Signing Key (FSK)

    256 bytes

    RSA2048 and SHA-256

    Checks integrity and authenticity of firmware

    General Description

    Product Name and Appearance

    The front view of iDynamo 5 Gen III, is shown in Figure 2-1 below. The back view of iDynamo 5 Gen III is shown in Figure 2-2. The side views of iDynamo 5 Gen III can be seen in Figure 2-3 and Figure 2-4. The Top View displaying the pushbutton and LED indicator can be seen in Figure 2-5, and the Bottom View displaying the USB-C receptacle can be seen in Figure 2-6.

    Figure 2-1 - Front View

    Figure 2-2 - Back View

    Figure 2-3 - Left Side View

    Figure 2-4 - Right Side view

    Figure 2-5 - Top View

    Figure 2-6 - Bottom View

    iDynamo 5 Gen III devices include a USB-C interface for Power and Communications, and a magnetic stripe reader (MSR). It is designed for attended and unattended environments.

    iDynamo 5 Gen III can be used as a desktop or handheld device. It is approved as a secure card reader (SCR) under PCI PTS POI v6.2 requirements.

    Usage in any other environment will invalidate PCI approval.

    To find important product identification information, look for the printed product label on the back face of the device as shown in Figure 2-7 below.

    Figure 2-7 – iDynamo 5 Gen III Device Label Location

    The product label includes the following elements of device identification information, shown by the numbered callouts in Figure 2-8.

    • Product Name

    • PCI Hardware Identifier (“HW”)

    Figure 2-8 -iDynamo 5 Gen III Device Label

    The label also contains other supporting information about the device.

    The hardware version of the device is 10PCI50U0xAx . All iDynamo 5 Gen III hardware configurations are listed in Table 2-1 below. The device utilizes one interface type, USB-C. Use of any interface otherthan USB-C will invalidate PCI approval.

    The most recent firmware versions for iDynamo 5 Gen III products are 1000009547-AAx-PCI for the secure bootloader, and 1000009535-AAx-PCI for the main firmware. The lowercase x in firmware versions indicates minor non-security related changes, see Table 2-3 and Table 2-4.

    All device identification information, including firmware versions and PCI Hardware ID, is accessible by connecting iDynamo 5 Gen III to a host device via USB-C using the latest software provided by MagTek, as seen in Figure 2-9 - Device Information Screen.

    The host user can retrieve device information at any time using Command 0x0000 Get Property as described in [3].

    Figure 2-9 - Device Information Screen

    10

    11

    12

    1

    0

    P

    C

    I

    5
    0

    U

    0

    x

    A

    6

    Device Options 5 = Standard

    7

    Option RFU (Reserved for Future Use) RFU 0 = as Certified

    8

    Interface Options U = USB

    9

    Option RFU (Reserved for Future Use) RFU 0 = as Certified

    11

    10

    Cover Color: B = Black

    11

    Version A = as Certified

    11

    12

    minor fixes not adding functionality or related to security (e.g., change component value for antenna matching): 0 = as certified

    10

    11

    12

    13

    14

    15

    16

    17

    18

    1

    0

    0

    0

    0

    0
    9

    5

    3

    5

    -

    12-13

    AA = Certified Version

    14

    Minor Revisions, Bug Fixes

    15

    Delimiter (-)

    16-18

    PCI = PCI Version of Firmware

    10

    11

    12

    13

    14

    15

    16

    17

    18

    1

    0

    0

    0

    0

    0
    9

    5

    3

    5

    -

    12-13

    AA = Certified Version

    14

    Minor Revisions, Bug Fixes

    15

    Delimiter (-)

    16-18

    PCI = PCI Version of Firmware

    PCI ID Tag

    Configuration Description

    10PCI50U0BA0

    iDynamo 5 Gen III, PCI, BLACK

    PCI Hardware ID Number

    1

    2

    3

    4

    5

    6
    7

    8

    Fixed Position

    Variable "X" Position

    Description of Fixed or Variable “X” in the Selection Position

    1-2

    10 = iDynamo 5 Gen III

    3-5

    Firmware Number

    1

    2

    3

    4

    5

    6
    7

    8

    Fixed Position

    Variable “x” Position

    Description of Fixed or Variable “x” in the Selected Position

    1-10

    1000009535 = iDynamo 5 Gen III Main Firmware Part Number

    11

    Firmware Number

    1

    2

    3

    4

    5

    6
    7

    8

    Fixed Position

    Variable “x” Position

    Description of Fixed or Variable “x” in the Selected Position

    1-10

    1000009547 = iDynamo 5 Gen III Boot Firmware Part Number

    11

    Product Type

    Identification

    Hardware Identification

    Table 2-1 - PCI Hardware Identifier

    Table 2-2 – Hardware Versions with Description of Associated Variables

    Firmware Identification

    Table - Main Firmware Version and Associated Variables

    Table - Boot Firmware Version and Associated Variables

    9

    PCI = PCI Hardware

    9

    Delimiter (-)

    9

    Delimiter (-)

    x

    A

    A

    x

    -

    P

    C

    I

    A

    A

    x

    -

    P

    C

    I