Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
This document addresses the proper use of iDynamo 5 Gen III secure card readers (SCR), in a secure manner. This includes information about key-management responsibilities, administrative responsibilities, device functionality, identification, and environmental requirements.
The use of this secure card reader in any method not described in this security policy will invalidate the PCI PTS POI v6.2 approval of the device.
Throughout this document:
iDynamo 5 Gen III refers to all products in the iDynamo 5 Gen III product family.
Document Number: D998200619-108
REGISTERED TO ISO 9001:2015
MagTek® is a registered trademark of MagTek, Inc.
MagnePrint® is a registered trademark of MagTek, Inc.
MagneSafe® is a registered trademark of MagTek, Inc.
Magensa™ is a trademark of MagTek, Inc. iDynamo™ is a trademark of MagTek, Inc.
ANSI®, the ANSI logo, and numerous other identifiers containing "ANSI" are registered trademarks, service marks, and accreditation marks of the American National Standards Institute (ANSI).
ISO® is a registered trademark of the International Organization for Standardization.
UL™ and the UL logo are trademarks of UL LLC.
PCI Security Standards Council® is a registered trademark of the PCI Security Standards Council, LLC.
Apple Pay®, Apple Wallet®, iPhone®, iPod®, Mac®, and OS X® are registered trademarks of Apple Inc., registered in the U.S. and other countries. iPad™ is a trademark of Apple. Inc. App StoreSM is a service mark of Apple Inc., registered in the U.S. and other countries. Apple and MFi are registered trademarks of Apple Inc. IOS is a trademark or registered trademark of Cisco in the U.S. and other countries and is used by Apple Inc. under license.
Google Play™ store, Google Wallet™ payment service, and Android™ platform are trademarks of Google LLC.
Microsoft®, Windows®, and .NET® are registered trademarks of Microsoft Corporation.
All other system names and product names are the property of their respective owners
Table 0-1
iDynamo 5 (Gen III) is a compact secure card reader authenticator (SCRA) that reads magnetic stripe cards that conform to ISO standards. iDynamo models are made for iOS, Android, and Windows devices equipped with a USB-C or Lightning interface. When a cardholder swipes a card, the device encrypts card data before they leave the encapsulated magnetic stripe reader head using the Triple Data Encryption Algorithm (TDEA, also known as Triple DES) and DUKPT key management.
The exterior of the device is a a rubberrized plastic. Visually inspect the device for signs of tampering. There should be no evidence of loose wires or screws, misplaced labels, cracked casing, holes, or tool marks.
Front Face: Inspect the overall form factor for signs of tampering. The front face has an embossed MagTek lock.
The following documents may be used to provide additional details about the device and this security policy:
MagTek iDynamo 5 Gen III Installation and Operation Manual PN: D998200614
MagTek iDynamo 5 Gen III SRED, Device Inspection Manual PN: D998200620
After receiving the device, the customer should visually inspect the product as follows:
Inspect the label found on the back of the device (see section 2.3.1 Hardware Identification) and make sure the label is not missing, obscured, or modified.
Check the PCI Hardware Identifier on the device label and make sure it matches the Hardware # listed for the device on the PCI website for Approved Devices. Go to the PCI compliance web page and search for MagTek, and find the product name, iDynamo 5 Gen III. Compare the Hardware ID and Firmware ID:
NIST SP 800-57-1 Recommendation for Key Management
ANS X9.24 Part 3:2017, Retail Financial Services Symmetric Key Management, Part 3: Derived Unique Key Per Transaction Using Symmetric Techniques
X9 TR-31:2010, Interoperable Secure Key Exchange Key Block Specification for Symmetric Algorithms
X9.143 (TR-31) Symmetric Key
Rev Number
Date
Notes
108
December 18, 2024
Initial Release

General Status LED: Power on the device and make sure that there is no indication that potential tampering was detected. After the device goes through the boot-up process, the LED should be solid green.
Bottom: A single USB-C receptacle is on the bottom of the device with certification and compliance logos as shown in the image.
Reader Left: There are 2 adapter sleeve retainer holes. There are no other components.
Reader Right: There are 2 adapter sleeve retainer holes. There are no other components.
Reader Back: The MagTek logo is debossed into the plastic and the product label in located on the bottom right.
Magnetic Swipe Path: Check the card insert slot. The reader has a smooth, unobstructed path. Insert an embossed card into the device to check for any signs of obstructions inside the card insertion slot. Other than the magnetic head that reads magnetic stripes there are no electronics, objects, or wires in the path.
Product Label: The product label is located on the back of the device. Check PN, SN and HW number. Serial Number matches serial number on boot-up. Check the product label on the device is complete, fully attached, with no signs of modification.Check the information (part #, model name, and serial number) on the label and ensure it matches the information found on the package and in any documents such as invoices.
Check shipping documents and tracking information to ensure that the shipment origin and sender information are correct. Check for evidence of tampering with the package containing this device. Before shipment, the box is sealed with tamper evident tape that will show VOID and OPENED if removed. The box and seal should be intact when initially received.
Check all views of the device and compare to photos.
It is helpful to do the following for your device inspection audit.
Have a list of the devices and details listed on the asset tag.
Take photos of the front, back, and sides of each device.
Check device Part numbers, serial numbers and IDs and check physical connections. Report any suspected signs of tampering immediately.
PCI Web Site: https://www.pcisecuritystandards. org/assessors_and_solutions/pin_transaction_devices.
Search for MagTek and find the product name, oiDynamo 5 (Gen III), on the web page. Compare the Hardware # and Firmware #.
Periodically inspect the following items while in use:
Card swipe path
Power Button
Form factor
LED
Label
USB-C receptacle
Need Help?
For additional support, please contact MagTek Support:
Technical Support:
📧 Email:
Check the Device serial number (SN) and make sure it matches with labels on shipping materials and documentation.
Visually inspect the device, per [2], which is included in the package with each device. See section 4.1 Periodic Inspection for more information regarding visual inspection of the device.
Follow the steps in Firmware Identification to view the PCI firmware versions installed on the device. Make sure this matches one of the Firmware # values listed on the PCI web site for iDynamo 5 Gen III.
Connect the device to a host via USB-C for control and power. iDynamo 5 Gen III products are designed to provide flexible mounting options such as:
External clip
Embedded lanyard
See the device installation and operation manual for more information on how to handle and operate the device, [1].
The specified environmental conditions to operate and store the device are:
Operating temperature range: 32°F to 95°F (0°C to 35°C) 5-90% RH with no condensation.
Storage temperature range: -4°F to 113°F (-20°C to 45°C) 10-90% RH with no condensation.
Power Supply: DC 5.0 V/1.0A
Any temperature or operating voltage outside the values listed above will trigger environmental security protections, resulting in a tamper condition. The device will need to be returned to the factory for inspection before this condition can be cleared.
Sensor
Low Threshold Value
High Threshold Value
Internal Voltage
2.2V ± 0.1V
4.2V ± 0.2V
Temperature
-48°C to -27°C
iDynamo 5 Gen III products support a USB-C interface using the USB-HID protocol. Transactions, configuration, firmware updates, and key injection can all be performed using this interface type. Use of any method not listed in this security policy will invalidate the device’s PCI PTS approval.
iDynamo 5 Gen III products ship from the factory fully secure. The devices have no configuration settings that require modification by the user to meet PCI security requirements.
Note: Firmware ID is accessible by connecting iDynamo 5 Gen III to a host device via USB-C, using the latest software provided by MagTek (see Firmware Identification).
Note that in PCI listings, lowercase “x” is a wildcard meaning ‘any single character.’
Acronym
Definition
AES
Advanced Encryption Standard
BCR
Barcode Reader
iDynamo 5 (Gen III) is a compact secure card reader authenticator (SCRA) that reads magnetic stripe cards that conform to ISO standards. iDynamo models are made for iOS, Android, and Windows devices equipped with a USB-C interface. When a cardholder swipes a card, the device encrypts card data before they leave the encapsulated magnetic stripe reader head using the Triple Data Encryption Algorithm (TDEA, also known as Triple DES) and DUKPT key management.
The basic form factor of the package is a folded white cardboard box with a cardboard insert where the device is nestled into the box. There are no rips or added materials on the package other than product and Lot labels. The package only has one color ink printed on the package: black. The box is made with corrugated white cardboard.
Back of Package
Industry certification logos showing compliance are printed on the back of the package as shown.
Manufacturer
Manufacturer address is shown.
Top of Package
The top of the package is printed as shown, with MFi logo, QR Code for Package inspection document and Quick Installation Guide, URL Links and product name and description.
Left Side of Package
On the left side of the package is printed with the contents and the product label is adhered.
Right Side of Package
The right side of the package lists the storage guidelines and CAUTION content regarding temperature and humidity.
Front of Package
The front of the package lists the product name, product category, and is secured with Security Tape.
Security Tape
Security tape wraps onto the bottom of the package from the front flap of the package.
Adhered
Here security tape is applied and secured. Wrapping front to bottom of package.
Tape - Removed Tape
Tape is removed VOID and OPENED appear on tape.
Package - Removed Tape
Tape is removed VOID and OPENED show as the inverse ink on the package.
Bottom
Security Tape
The Security Tape wraps from the front flap to the bottom of the package.
Make certain there are no signs of tampering.
Lot Label
The Lot label is adhered on the bottom of the box. Make certain there are no false labels added or signs of tampering.
Inside
Dynamo 5 (Gen III) products are nestled inside the package for transit. The package includes the device, cable(s), device inspection document, and quick installation guide.
To check for PCI Validation check the Hardware and Firmware ID. Hardware ID is printed on the label. The Firmware ID is accessible via the device.
Go to the PCI compliance web page and search for MagTek, and find the product name. Compare the Hardware ID and Firmware ID:
As part of your inspection, include the following for your inspection audit:
Be certain to have a list of the devices and include the details listed on the product label.
It may be helpful to take photos of the front, back, and sides of each device.
Be certain to check device part numbers, serial numbers, and IDs and check physical connections. Use the chart below as a checklist to inspect the device for signs of tampering.
The device always encrypts account data from the MSR using 112-bit TDEA, 128-bit AES, or 256-bit AES algorithms with X9.24 DUKPT key management. This device does not support any mechanisms such as whitelists or SRED disable that would allow the data to be sent out unencrypted. The programmers need to follow the guidance provided in [3]. Use of the device with key-management systems not described in this policy will invalidate the PCI PTS POI v6.2 approval of the device.
The device includes the following cryptographic algorithms:
AES-128/256
TDEA-128
ECDSA (P256 and P521)
RSA2048
SHA-256
The device implements the original AES/TDEA DUKPT as its only key management method. Use of any other method will invalidate PCI approval. DUKPT derives a new unique key for every transaction. For more details, see [5] and [6].
The device does not support manual or plaintext cryptographic key entry. Only specialized tools, compliant with key management requirements and cryptographic methods, specifically [6] and [7]. On the production line, the ANSI X9.143 format can be used for key loading by an HSM after mutual authentication. Use of any other methods will invalidate PCI approval.
Keys should be replaced with new keys whenever the original key is known or suspected to have been compromised, and whenever the time deemed feasible to determine the key by exhaustive attack has elapsed, as defined in [4].
The merchant or acquirer should inspect the appearance of secure card reader on a daily basis:
Inspect the appearance of secure card reader to make sure it is the right product.
Inspect whether the Swipe Path has an additional card reader or other inserted bugs, See Figure 4-1, below.
Inspect whether the product appearance has been changed.
Check if the firmware version is correct.
After connecting the device to a USB-C power supply, it will power on, the LED indicator should illuminate green and remain powered on to indicate the device is in an idle state, ready for a transaction. Powering on the secure card reader will test hardware security and authenticity, and the integrity of the installed firmware.
MSR Swipe Path: The swipe path is smooth. The only moving part is the spring-mounted read head that depresses into the device as the card’s magnetic stripe makes contact with the read head.
Figure 4-1 - Card Swipe Path Example
MagTek strongly recommends performing security inspections on a regular schedule. Additional information can be found in [2]. If any problems are detected, stop using the device, set it aside in a secure location, and contact the manufacturer or your acquirer for further advice.
iDynamo 5 Gen III performs self-tests at power-up and after reset. The device automatically resets and performs self-tests every 24 hours at the configured time of day. No manual intervention by the operator is required. Self-tests include:
Checking the integrity and authenticity of the firmware and cryptographic keys.
Checking security mechanisms for signs of tampering.
The secure card reader has no functionality that gives access to security-sensitive services based on roles. Such services are managed through dedicated tools, using cryptographic authentication.
iDynamo 5 Gen III products ship from the factory fully secure. The devices have no security related default values (e.g., passwords/authentication codes/certificates) that require modification by the user to meet PCI security requirements.
If the device senses a physical or environmental attack, it erases all sensitive keys and will have limited functionality. While powered on, the SCR indicates it is in a tampered state by illuminating its only LED solid red, as seen in Figure 4-2 Tamper Response. If this occurs:
Remove the device from service immediately.
Store it securely for a possible forensics investigation.
Contact the manufacturer for assistance. The device will likely need to be returned to the manufacturer for diagnosis and servicing.
Figure 4-2 Tamper Response
iDynamo 5 Gen III products support file-based updates of the device’s core firmware (main firmware) and authorized commands for updating sensitive configuration. For optimal device security, MagTek recommends the latest versions of firmware should always be installed.
Firmware updates are provided as files that have been signed by MagTek. The firmware files can be loaded locally through the USB-C interface by using update tools available from the MagTek web site. The device verifies each update is newer than the installed version, and cryptographically authenticates the file with RSA-2048 and SHA-256. If version checking or authentication fails, the device erases the update file and reports an error to the host.
Before iDynamo 5 Gen III products are permanently removed from service, all the keys and sensitive data must be erased. One way to accomplish this is by temporarily removing the back cover, which forces a tamper response.
If removal from service is only temporary, no action is required. All sensitive data will continue to be protected by the device’s physical and logical protection mechanisms.
95°C to 105°C
CTLS
Contactless
DES
Data Encryption Standard
DUKPT
Derived Unique Key Per Transaction
ECC
Elliptic-Curve Cryptography
FSK
Firmware Signing Key
ICCR
Integrated Circuit Card Reader
MAC
In cryptography: Message Authentication Code In networking: Media Access Control [address]
MSR
Magnetic Stripe Reader
NFC
Near Field Communication
POI
Point Of Interaction
S/N
Serial Number
SCRA
Secure Card Reader Authenticator
SHA
Secure Hash Algorithm
SRED
Secure Reading and Exchange of Data
TDEA
Triple Data Encryption Algorithm
USB
Universal Serial Bus
USB HID
USB Human Interface Device



📞 Phone: 1-562-546-6800 (US)
🕐 Hours: Monday-Friday, 5:30 AM - 5:00 PM PST
Online Resources:
🌐 Support Portal: developer.magtek.com
Documentation Feedback:
Help us improve this documentation! feedback@magtek.com

16 bytes for TDEA and AES- 128
32 bytes for AES-256
AES and TDEA DUKPT (ANS X9.24-3)
Encrypt and MAC Account Data
Firmware Protection Key
· Firmware Signing Key (FSK)
256 bytes
RSA2048 and SHA-256
Checks integrity and authenticity of firmware
Key Name
Size
Algorithm
Purpose
Transport Keys:
· Master Transport Key
· Device Transport Key
· Financial Transport Key
· Production Transport Key
· Manufacturing Transport Key
· MagTek KIF Financial Transport Key
32 bytes
AES X9.143 KBPKs
Key Injection
Account Data Key
· DKPTM7-FK
Front
Check form factor
Look for signs of tamper
Check printing and no added labels
Left, Right, and Back Sides
Check form factor
Look for signs of tamper
Check printing and no added labels
Check product label
Front Flap
Check Security Tape
Look for signs of tamper
Check printing and no added labels
Check form factor
Bottom
Check Security Tape
Look for signs of tamper
Check printing
Check form factor
Check lot Label
Are there signs of tampering?
YES
NO
Package Inspection
Form Factor - check overall form factor
NOTICE: Follow RMA procedures. User should report all signs of tampering as per standard protocol.
Need Help?
For additional support, please contact MagTek Support:
Technical Support:
📧 Email: support@magtek.com
📞 Phone: 1-562-546-6800 (US)
🕐 Hours: Monday-Friday, 5:30 AM - 5:00 PM PST
Online Resources:
🌐 Support Portal: developer.magtek.com
Documentation Feedback:
Help us improve this documentation!










The front view of iDynamo 5 Gen III, is shown in Figure 2-1 below. The back view of iDynamo 5 Gen III is shown in Figure 2-2. The side views of iDynamo 5 Gen III can be seen in Figure 2-3 and Figure 2-4. The Top View displaying the pushbutton and LED indicator can be seen in Figure 2-5, and the Bottom View displaying the USB-C receptacle can be seen in Figure 2-6.
Figure 2-1 - Front View
Figure 2-2 - Back View
Figure 2-3 - Left Side View
Figure 2-4 - Right Side view
Figure 2-5 - Top View
Figure 2-6 - Bottom View
iDynamo 5 Gen III devices include a USB-C interface for Power and Communications, and a magnetic stripe reader (MSR). It is designed for attended and unattended environments.
iDynamo 5 Gen III can be used as a desktop or handheld device. It is approved as a secure card reader (SCR) under PCI PTS POI v6.2 requirements.
Usage in any other environment will invalidate PCI approval.
To find important product identification information, look for the printed product label on the back face of the device as shown in Figure 2-7 below.
Figure 2-7 – iDynamo 5 Gen III Device Label Location
The product label includes the following elements of device identification information, shown by the numbered callouts in Figure 2-8.
Product Name
PCI Hardware Identifier (“HW”)
Figure 2-8 -iDynamo 5 Gen III Device Label
The label also contains other supporting information about the device.
The hardware version of the device is 10PCI50U0xAx . All iDynamo 5 Gen III hardware configurations are listed in Table 2-1 below. The device utilizes one interface type, USB-C. Use of any interface otherthan USB-C will invalidate PCI approval.
The most recent firmware versions for iDynamo 5 Gen III products are 1000009547-AAx-PCI for the secure bootloader, and 1000009535-AAx-PCI for the main firmware. The lowercase x in firmware versions indicates minor non-security related changes, see Table 2-3 and Table 2-4.
All device identification information, including firmware versions and PCI Hardware ID, is accessible by connecting iDynamo 5 Gen III to a host device via USB-C using the latest software provided by MagTek, as seen in Figure 2-9 - Device Information Screen.
The host user can retrieve device information at any time using Command 0x0000 Get Property as described in [3].
Figure 2-9 - Device Information Screen
10
11
12
1
0
P
C
I
U
x
A
6
Device Options 5 = Standard
7
Option RFU (Reserved for Future Use) RFU 0 = as Certified
8
Interface Options U = USB
9
Option RFU (Reserved for Future Use) RFU 0 = as Certified
11
10
Cover Color: B = Black
11
Version A = as Certified
11
12
minor fixes not adding functionality or related to security (e.g., change component value for antenna matching): 0 = as certified
10
11
12
13
14
15
16
17
18
1
0
0
0
0
5
5
-
12-13
AA = Certified Version
14
Minor Revisions, Bug Fixes
15
Delimiter (-)
16-18
PCI = PCI Version of Firmware
10
11
12
13
14
15
16
17
18
1
0
0
0
0
5
5
-
12-13
AA = Certified Version
14
Minor Revisions, Bug Fixes
15
Delimiter (-)
16-18
PCI = PCI Version of Firmware
PCI ID Tag
Configuration Description
10PCI50U0BA0
iDynamo 5 Gen III, PCI, BLACK
PCI Hardware ID Number
1
2
3
4
5
8
Fixed Position
Variable "X" Position
Description of Fixed or Variable “X” in the Selection Position
1-2
10 = iDynamo 5 Gen III
3-5
Firmware Number
1
2
3
4
5
8
Fixed Position
Variable “x” Position
Description of Fixed or Variable “x” in the Selected Position
1-10
1000009535 = iDynamo 5 Gen III Main Firmware Part Number
11
Firmware Number
1
2
3
4
5
8
Fixed Position
Variable “x” Position
Description of Fixed or Variable “x” in the Selected Position
1-10
1000009547 = iDynamo 5 Gen III Boot Firmware Part Number
11










PCI = PCI Hardware
Delimiter (-)
Delimiter (-)
x
A
A
x
-
P
C
I
A
A
x
-
P
C
I
This compliance documentation page provides the essential security and inspection guides required to maintain PCI PTS approval and ensure the physical integrity of iDynamo 5 Gen III secure card readers before and after deployment.
Applies to: iDynamo 5 Gen III
Reference Section
Information Available
A manual that outlines the step-by-step procedures for visually inspecting the iDynamo 5 Gen III's hardware label, physical appearance, and tamper indicators to verify its authenticity and security before use.
A guide that details how to examine the device's secure packaging for signs of tampering during storage or transit, helping to ensure the reader has not been compromised before deployment.
This document addresses the proper use of theiDynamo 5 Gen III secure card readers (SCR) in a secure manner.
Need Help?
For additional support, please contact MagTek Support:
Technical Support:
📧 Email: support@magtek.com
📞 Phone: 1-800-788-6835 (US) | +1-562-546-6616 (International)
🕐 Hours: Monday-Friday, 6:00 AM - 5:00 PM PST
Online Resources:
🌐 Official Site:
💬 Developer Forum:
Documentation Feedback:
Help us improve this documentation!