All pages
Powered by GitBook
1 of 11

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Purpose

This document addresses the proper use of iDynamo 5 Gen III secure card readers (SCR), in a secure manner. This includes information about key-management responsibilities, administrative responsibilities, device functionality, identification, and environmental requirements.

The use of this secure card reader in any method not described in this security policy will invalidate the PCI PTS POI v6.2 approval of the device.

Throughout this document:

  • iDynamo 5 Gen III refers to all products in the iDynamo 5 Gen III product family.

Secure Card Reader Security Policy

Document Number: D998200619-108

REGISTERED TO ISO 9001:2015

MagTek® is a registered trademark of MagTek, Inc.

MagnePrint® is a registered trademark of MagTek, Inc.

MagneSafe® is a registered trademark of MagTek, Inc.

Magensa™ is a trademark of MagTek, Inc. iDynamo™ is a trademark of MagTek, Inc.

ANSI®, the ANSI logo, and numerous other identifiers containing "ANSI" are registered trademarks, service marks, and accreditation marks of the American National Standards Institute (ANSI).

ISO® is a registered trademark of the International Organization for Standardization.

UL™ and the UL logo are trademarks of UL LLC.

PCI Security Standards Council® is a registered trademark of the PCI Security Standards Council, LLC.

Apple Pay®, Apple Wallet®, iPhone®, iPod®, Mac®, and OS X® are registered trademarks of Apple Inc., registered in the U.S. and other countries. iPad™ is a trademark of Apple. Inc. App StoreSM is a service mark of Apple Inc., registered in the U.S. and other countries. Apple and MFi are registered trademarks of Apple Inc. IOS is a trademark or registered trademark of Cisco in the U.S. and other countries and is used by Apple Inc. under license.

Google Play™ store, Google Wallet™ payment service, and Android™ platform are trademarks of Google LLC.

Microsoft®, Windows®, and .NET® are registered trademarks of Microsoft Corporation.

All other system names and product names are the property of their respective owners

Table 0-1

Device Inspection Document

iDynamo 5 (Gen III) is a compact secure card reader authenticator (SCRA) that reads magnetic stripe cards that conform to ISO standards. iDynamo models are made for iOS, Android, and Windows devices equipped with a USB-C or Lightning interface. When a cardholder swipes a card, the device encrypts card data before they leave the encapsulated magnetic stripe reader head using the Triple Data Encryption Algorithm (TDEA, also known as Triple DES) and DUKPT key management.

The exterior of the device is a a rubberrized plastic. Visually inspect the device for signs of tampering. There should be no evidence of loose wires or screws, misplaced labels, cracked casing, holes, or tool marks.

  • Front Face: Inspect the overall form factor for signs of tampering. The front face has an embossed MagTek lock.

Appendix A References

The following documents may be used to provide additional details about the device and this security policy:

  • MagTek iDynamo 5 Gen III Installation and Operation Manual PN: D998200614

  • MagTek iDynamo 5 Gen III SRED, Device Inspection Manual PN: D998200620

Installation and User Guidance

After receiving the device, the customer should visually inspect the product as follows:

  • Inspect the label found on the back of the device (see section 2.3.1 Hardware Identification) and make sure the label is not missing, obscured, or modified.

  • Check the PCI Hardware Identifier on the device label and make sure it matches the Hardware # listed for the device on the PCI website for Approved Devices. Go to the PCI compliance web page and search for MagTek, and find the product name, iDynamo 5 Gen III. Compare the Hardware ID and Firmware ID:

MagTek iDynamo 5 Gen III Programmer’s Manual COMMANDS PN: D998200587
  • NIST SP 800-57-1 Recommendation for Key Management

  • ANS X9.24 Part 3:2017, Retail Financial Services Symmetric Key Management, Part 3: Derived Unique Key Per Transaction Using Symmetric Techniques

  • X9 TR-31:2010, Interoperable Secure Key Exchange Key Block Specification for Symmetric Algorithms

  • X9.143 (TR-31) Symmetric Key

  • Rev Number

    Date

    Notes

    108

    December 18, 2024

    Initial Release

    TOP: The top of the device has a single LED and power button.
  • General Status LED: Power on the device and make sure that there is no indication that potential tampering was detected. After the device goes through the boot-up process, the LED should be solid green.

  • Bottom: A single USB-C receptacle is on the bottom of the device with certification and compliance logos as shown in the image.

  • Reader Left: There are 2 adapter sleeve retainer holes. There are no other components.

  • Reader Right: There are 2 adapter sleeve retainer holes. There are no other components.

  • Reader Back: The MagTek logo is debossed into the plastic and the product label in located on the bottom right.

  • Magnetic Swipe Path: Check the card insert slot. The reader has a smooth, unobstructed path. Insert an embossed card into the device to check for any signs of obstructions inside the card insertion slot. Other than the magnetic head that reads magnetic stripes there are no electronics, objects, or wires in the path.

  • Product Label: The product label is located on the back of the device. Check PN, SN and HW number. Serial Number matches serial number on boot-up. Check the product label on the device is complete, fully attached, with no signs of modification.Check the information (part #, model name, and serial number) on the label and ensure it matches the information found on the package and in any documents such as invoices.

  • Check shipping documents and tracking information to ensure that the shipment origin and sender information are correct. Check for evidence of tampering with the package containing this device. Before shipment, the box is sealed with tamper evident tape that will show VOID and OPENED if removed. The box and seal should be intact when initially received.

    Check all views of the device and compare to photos.

    It is helpful to do the following for your device inspection audit.

    • Have a list of the devices and details listed on the asset tag.

    • Take photos of the front, back, and sides of each device.

    Check device Part numbers, serial numbers and IDs and check physical connections. Report any suspected signs of tampering immediately.

    PCI Web Site: https://www.pcisecuritystandards. org/assessors_and_solutions/pin_transaction_devices.

    Search for MagTek and find the product name, oiDynamo 5 (Gen III), on the web page. Compare the Hardware # and Firmware #.

    Periodically inspect the following items while in use:

    • Card swipe path

    • Power Button

    • Form factor

    • LED

    • Label

    • USB-C receptacle

    IMPORTANT: Be certain to inspect this device before deployment and during its life-cycle.

    Overview

    Form Factor

    Shipment

    Checklist Summary

    Device Audit

    PCI compliance web page.

    Need Help?

    For additional support, please contact MagTek Support:

    Technical Support:

    • 📧 Email:

    Check the Device serial number (SN) and make sure it matches with labels on shipping materials and documentation.

  • Visually inspect the device, per [2], which is included in the package with each device. See section 4.1 Periodic Inspection for more information regarding visual inspection of the device.

  • Follow the steps in Firmware Identification to view the PCI firmware versions installed on the device. Make sure this matches one of the Firmware # values listed on the PCI web site for iDynamo 5 Gen III.

  • Connect the device to a host via USB-C for control and power. iDynamo 5 Gen III products are designed to provide flexible mounting options such as:

    • External clip

    • Embedded lanyard

    See the device installation and operation manual for more information on how to handle and operate the device, [1].

    The specified environmental conditions to operate and store the device are:

    • Operating temperature range: 32°F to 95°F (0°C to 35°C) 5-90% RH with no condensation.

    • Storage temperature range: -4°F to 113°F (-20°C to 45°C) 10-90% RH with no condensation.

    • Power Supply: DC 5.0 V/1.0A

    Any temperature or operating voltage outside the values listed above will trigger environmental security protections, resulting in a tamper condition. The device will need to be returned to the factory for inspection before this condition can be cleared.

    Sensor

    Low Threshold Value

    High Threshold Value

    Internal Voltage

    2.2V ± 0.1V

    4.2V ± 0.2V

    Temperature

    -48°C to -27°C

    iDynamo 5 Gen III products support a USB-C interface using the USB-HID protocol. Transactions, configuration, firmware updates, and key injection can all be performed using this interface type. Use of any method not listed in this security policy will invalidate the device’s PCI PTS approval.

    iDynamo 5 Gen III products ship from the factory fully secure. The devices have no configuration settings that require modification by the user to meet PCI security requirements.

    Initial Inspection

    Note: Firmware ID is accessible by connecting iDynamo 5 Gen III to a host device via USB-C, using the latest software provided by MagTek (see Firmware Identification).

    https://www.pcisecuritystandards.org/assessors_and_solutions/pin_transaction_devices

    Note that in PCI listings, lowercase “x” is a wildcard meaning ‘any single character.’

    Installation

    Environmental Conditions

    Communications and Security Protocols

    Configuration Settings

    Acronyms

    Acronym

    Definition

    AES

    Advanced Encryption Standard

    BCR

    Barcode Reader

    Package Inspection Documentation

    iDynamo 5 (Gen III) is a compact secure card reader authenticator (SCRA) that reads magnetic stripe cards that conform to ISO standards. iDynamo models are made for iOS, Android, and Windows devices equipped with a USB-C interface. When a cardholder swipes a card, the device encrypts card data before they leave the encapsulated magnetic stripe reader head using the Triple Data Encryption Algorithm (TDEA, also known as Triple DES) and DUKPT key management.

    Overall Form Factor

    The basic form factor of the package is a folded white cardboard box with a cardboard insert where the device is nestled into the box. There are no rips or added materials on the package other than product and Lot labels. The package only has one color ink printed on the package: black. The box is made with corrugated white cardboard.

    Back of Package

    Industry certification logos showing compliance are printed on the back of the package as shown.

    Manufacturer

    Manufacturer address is shown.

    Top of Package

    The top of the package is printed as shown, with MFi logo, QR Code for Package inspection document and Quick Installation Guide, URL Links and product name and description.

    Left Side of Package

    On the left side of the package is printed with the contents and the product label is adhered.

    Right Side of Package

    The right side of the package lists the storage guidelines and CAUTION content regarding temperature and humidity.

    Front of Package

    The front of the package lists the product name, product category, and is secured with Security Tape.

    Security Tape

    Security tape wraps onto the bottom of the package from the front flap of the package.

    Adhered

    Here security tape is applied and secured. Wrapping front to bottom of package.

    Tape - Removed Tape

    Tape is removed VOID and OPENED appear on tape.

    Package - Removed Tape

    Tape is removed VOID and OPENED show as the inverse ink on the package.

    Bottom

    Security Tape

    The Security Tape wraps from the front flap to the bottom of the package.

    Make certain there are no signs of tampering.

    Lot Label

    The Lot label is adhered on the bottom of the box. Make certain there are no false labels added or signs of tampering.

    Inside

    Dynamo 5 (Gen III) products are nestled inside the package for transit. The package includes the device, cable(s), device inspection document, and quick installation guide.

    To check for PCI Validation check the Hardware and Firmware ID. Hardware ID is printed on the label. The Firmware ID is accessible via the device.

    Go to the PCI compliance web page and search for MagTek, and find the product name. Compare the Hardware ID and Firmware ID:

    As part of your inspection, include the following for your inspection audit:

    • Be certain to have a list of the devices and include the details listed on the product label.

    • It may be helpful to take photos of the front, back, and sides of each device.

    Be certain to check device part numbers, serial numbers, and IDs and check physical connections. Use the chart below as a checklist to inspect the device for signs of tampering.

    Security

    Account Data Protection

    The device always encrypts account data from the MSR using 112-bit TDEA, 128-bit AES, or 256-bit AES algorithms with X9.24 DUKPT key management. This device does not support any mechanisms such as whitelists or SRED disable that would allow the data to be sent out unencrypted. The programmers need to follow the guidance provided in [3]. Use of the device with key-management systems not described in this policy will invalidate the PCI PTS POI v6.2 approval of the device.

    Algorithms Supported

    The device includes the following cryptographic algorithms:

    • AES-128/256

    • TDEA-128

    • ECDSA (P256 and P521)

    • RSA2048

    • SHA-256

    The device implements the original AES/TDEA DUKPT as its only key management method. Use of any other method will invalidate PCI approval. DUKPT derives a new unique key for every transaction. For more details, see [5] and [6].

    The device does not support manual or plaintext cryptographic key entry. Only specialized tools, compliant with key management requirements and cryptographic methods, specifically [6] and [7]. On the production line, the ANSI X9.143 format can be used for key loading by an HSM after mutual authentication. Use of any other methods will invalidate PCI approval.

    Keys should be replaced with new keys whenever the original key is known or suspected to have been compromised, and whenever the time deemed feasible to determine the key by exhaustive attack has elapsed, as defined in [4].

    Operation and Maintenance

    Periodic Inspection

    The merchant or acquirer should inspect the appearance of secure card reader on a daily basis:

    • Inspect the appearance of secure card reader to make sure it is the right product.

    • Inspect whether the Swipe Path has an additional card reader or other inserted bugs, See Figure 4-1, below.

    • Inspect whether the product appearance has been changed.

    • Check if the firmware version is correct.

    • After connecting the device to a USB-C power supply, it will power on, the LED indicator should illuminate green and remain powered on to indicate the device is in an idle state, ready for a transaction. Powering on the secure card reader will test hardware security and authenticity, and the integrity of the installed firmware.

    MSR Swipe Path: The swipe path is smooth. The only moving part is the spring-mounted read head that depresses into the device as the card’s magnetic stripe makes contact with the read head.

    Figure 4-1 - Card Swipe Path Example

    MagTek strongly recommends performing security inspections on a regular schedule. Additional information can be found in [2]. If any problems are detected, stop using the device, set it aside in a secure location, and contact the manufacturer or your acquirer for further advice.

    iDynamo 5 Gen III performs self-tests at power-up and after reset. The device automatically resets and performs self-tests every 24 hours at the configured time of day. No manual intervention by the operator is required. Self-tests include:

    • Checking the integrity and authenticity of the firmware and cryptographic keys.

    • Checking security mechanisms for signs of tampering.

    The secure card reader has no functionality that gives access to security-sensitive services based on roles. Such services are managed through dedicated tools, using cryptographic authentication.

    iDynamo 5 Gen III products ship from the factory fully secure. The devices have no security related default values (e.g., passwords/authentication codes/certificates) that require modification by the user to meet PCI security requirements.

    If the device senses a physical or environmental attack, it erases all sensitive keys and will have limited functionality. While powered on, the SCR indicates it is in a tampered state by illuminating its only LED solid red, as seen in Figure 4-2 Tamper Response. If this occurs:

    • Remove the device from service immediately.

    • Store it securely for a possible forensics investigation.

    • Contact the manufacturer for assistance. The device will likely need to be returned to the manufacturer for diagnosis and servicing.

    Figure 4-2 Tamper Response

    iDynamo 5 Gen III products support file-based updates of the device’s core firmware (main firmware) and authorized commands for updating sensitive configuration. For optimal device security, MagTek recommends the latest versions of firmware should always be installed.

    Firmware updates are provided as files that have been signed by MagTek. The firmware files can be loaded locally through the USB-C interface by using update tools available from the MagTek web site. The device verifies each update is newer than the installed version, and cryptographically authenticates the file with RSA-2048 and SHA-256. If version checking or authentication fails, the device erases the update file and reports an error to the host.

    Before iDynamo 5 Gen III products are permanently removed from service, all the keys and sensitive data must be erased. One way to accomplish this is by temporarily removing the back cover, which forces a tamper response.

    If removal from service is only temporary, no action is required. All sensitive data will continue to be protected by the device’s physical and logical protection mechanisms.

    95°C to 105°C

    CTLS

    Contactless

    DES

    Data Encryption Standard

    DUKPT

    Derived Unique Key Per Transaction

    ECC

    Elliptic-Curve Cryptography

    FSK

    Firmware Signing Key

    ICCR

    Integrated Circuit Card Reader

    MAC

    In cryptography: Message Authentication Code In networking: Media Access Control [address]

    MSR

    Magnetic Stripe Reader

    NFC

    Near Field Communication

    POI

    Point Of Interaction

    S/N

    Serial Number

    SCRA

    Secure Card Reader Authenticator

    SHA

    Secure Hash Algorithm

    SRED

    Secure Reading and Exchange of Data

    TDEA

    Triple Data Encryption Algorithm

    USB

    Universal Serial Bus

    USB HID

    USB Human Interface Device

    Self-Test

    Roles and Responsibilities

    Passwords and Certificates

    Tamper Response

    Patching and Updating

    Decommissioning

    📞 Phone: 1-562-546-6800 (US)

  • 🕐 Hours: Monday-Friday, 5:30 AM - 5:00 PM PST

  • Online Resources:

    • 🌐 Support Portal: developer.magtek.com

    Documentation Feedback:

    Help us improve this documentation! feedback@magtek.com

    support@magtek.com

    16 bytes for TDEA and AES- 128

    32 bytes for AES-256

    AES and TDEA DUKPT (ANS X9.24-3)

    Encrypt and MAC Account Data

    Firmware Protection Key

    · Firmware Signing Key (FSK)

    256 bytes

    RSA2048 and SHA-256

    Checks integrity and authenticity of firmware

    Key Name

    Size

    Algorithm

    Purpose

    Transport Keys:

    · Master Transport Key

    · Device Transport Key

    · Financial Transport Key

    · Production Transport Key

    · Manufacturing Transport Key

    · MagTek KIF Financial Transport Key

    32 bytes

    AES X9.143 KBPKs

    Key Injection

    Key Management

    Table 5-1 - iDynamo 5 Gen III Product Keys

    Key Loading

    Key Replacement

    Account Data Key

    · DKPTM7-FK

    Front

    Check form factor

    Look for signs of tamper

    Check printing and no added labels

    Left, Right, and Back Sides

    Check form factor

    Look for signs of tamper

    Check printing and no added labels

    Check product label

    Front Flap

    Check Security Tape

    Look for signs of tamper

    Check printing and no added labels

    Check form factor

    Bottom

    Check Security Tape

    Look for signs of tamper

    Check printing

    Check form factor

    Check lot Label

    Are there signs of tampering?

    YES

    NO

    Package Inspection

    Form Factor - check overall form factor

    NOTICE: Follow RMA procedures. User should report all signs of tampering as per standard protocol.

    Need Help?

    For additional support, please contact MagTek Support:

    Technical Support:

    • 📧 Email: support@magtek.com

    • 📞 Phone: 1-562-546-6800 (US)

    • 🕐 Hours: Monday-Friday, 5:30 AM - 5:00 PM PST

    Online Resources:

    • 🌐 Support Portal: developer.magtek.com

    Documentation Feedback:

    Help us improve this documentation!

    https://www.pcisecuritystandards.org/assessors_and_solutions/pin_transaction_devices

    feedback@magtek.com

    General Description

    Product Name and Appearance

    The front view of iDynamo 5 Gen III, is shown in Figure 2-1 below. The back view of iDynamo 5 Gen III is shown in Figure 2-2. The side views of iDynamo 5 Gen III can be seen in Figure 2-3 and Figure 2-4. The Top View displaying the pushbutton and LED indicator can be seen in Figure 2-5, and the Bottom View displaying the USB-C receptacle can be seen in Figure 2-6.

    Figure 2-1 - Front View

    Figure 2-2 - Back View

    Figure 2-3 - Left Side View

    Figure 2-4 - Right Side view

    Figure 2-5 - Top View

    Figure 2-6 - Bottom View

    iDynamo 5 Gen III devices include a USB-C interface for Power and Communications, and a magnetic stripe reader (MSR). It is designed for attended and unattended environments.

    iDynamo 5 Gen III can be used as a desktop or handheld device. It is approved as a secure card reader (SCR) under PCI PTS POI v6.2 requirements.

    Usage in any other environment will invalidate PCI approval.

    To find important product identification information, look for the printed product label on the back face of the device as shown in Figure 2-7 below.

    Figure 2-7 – iDynamo 5 Gen III Device Label Location

    The product label includes the following elements of device identification information, shown by the numbered callouts in Figure 2-8.

    • Product Name

    • PCI Hardware Identifier (“HW”)

    Figure 2-8 -iDynamo 5 Gen III Device Label

    The label also contains other supporting information about the device.

    The hardware version of the device is 10PCI50U0xAx . All iDynamo 5 Gen III hardware configurations are listed in Table 2-1 below. The device utilizes one interface type, USB-C. Use of any interface otherthan USB-C will invalidate PCI approval.

    The most recent firmware versions for iDynamo 5 Gen III products are 1000009547-AAx-PCI for the secure bootloader, and 1000009535-AAx-PCI for the main firmware. The lowercase x in firmware versions indicates minor non-security related changes, see Table 2-3 and Table 2-4.

    All device identification information, including firmware versions and PCI Hardware ID, is accessible by connecting iDynamo 5 Gen III to a host device via USB-C using the latest software provided by MagTek, as seen in Figure 2-9 - Device Information Screen.

    The host user can retrieve device information at any time using Command 0x0000 Get Property as described in [3].

    Figure 2-9 - Device Information Screen

    10

    11

    12

    1

    0

    P

    C

    I

    5
    0

    U

    0

    x

    A

    6

    Device Options 5 = Standard

    7

    Option RFU (Reserved for Future Use) RFU 0 = as Certified

    8

    Interface Options U = USB

    9

    Option RFU (Reserved for Future Use) RFU 0 = as Certified

    11

    10

    Cover Color: B = Black

    11

    Version A = as Certified

    11

    12

    minor fixes not adding functionality or related to security (e.g., change component value for antenna matching): 0 = as certified

    10

    11

    12

    13

    14

    15

    16

    17

    18

    1

    0

    0

    0

    0

    0
    9

    5

    3

    5

    -

    12-13

    AA = Certified Version

    14

    Minor Revisions, Bug Fixes

    15

    Delimiter (-)

    16-18

    PCI = PCI Version of Firmware

    10

    11

    12

    13

    14

    15

    16

    17

    18

    1

    0

    0

    0

    0

    0
    9

    5

    3

    5

    -

    12-13

    AA = Certified Version

    14

    Minor Revisions, Bug Fixes

    15

    Delimiter (-)

    16-18

    PCI = PCI Version of Firmware

    PCI ID Tag

    Configuration Description

    10PCI50U0BA0

    iDynamo 5 Gen III, PCI, BLACK

    PCI Hardware ID Number

    1

    2

    3

    4

    5

    6
    7

    8

    Fixed Position

    Variable "X" Position

    Description of Fixed or Variable “X” in the Selection Position

    1-2

    10 = iDynamo 5 Gen III

    3-5

    Firmware Number

    1

    2

    3

    4

    5

    6
    7

    8

    Fixed Position

    Variable “x” Position

    Description of Fixed or Variable “x” in the Selected Position

    1-10

    1000009535 = iDynamo 5 Gen III Main Firmware Part Number

    11

    Firmware Number

    1

    2

    3

    4

    5

    6
    7

    8

    Fixed Position

    Variable “x” Position

    Description of Fixed or Variable “x” in the Selected Position

    1-10

    1000009547 = iDynamo 5 Gen III Boot Firmware Part Number

    11

    Product Type

    Identification

    Hardware Identification

    Table 2-1 - PCI Hardware Identifier

    Table 2-2 – Hardware Versions with Description of Associated Variables

    Firmware Identification

    Table - Main Firmware Version and Associated Variables

    Table - Boot Firmware Version and Associated Variables

    9

    PCI = PCI Hardware

    9

    Delimiter (-)

    9

    Delimiter (-)

    x

    A

    A

    x

    -

    P

    C

    I

    A

    A

    x

    -

    P

    C

    I

    iDynamo 5 Gen III

    This compliance documentation page provides the essential security and inspection guides required to maintain PCI PTS approval and ensure the physical integrity of iDynamo 5 Gen III secure card readers before and after deployment.

    Applies to: iDynamo 5 Gen III

    Documents

    Reference Section

    Information Available

    A manual that outlines the step-by-step procedures for visually inspecting the iDynamo 5 Gen III's hardware label, physical appearance, and tamper indicators to verify its authenticity and security before use.

    A guide that details how to examine the device's secure packaging for signs of tampering during storage or transit, helping to ensure the reader has not been compromised before deployment.

    PCI PTS POI Security Policy

    This document addresses the proper use of theiDynamo 5 Gen III secure card readers (SCR) in a secure manner.

    For more help

    Need Help?

    For additional support, please contact MagTek Support:

    Technical Support:

    • 📧 Email: support@magtek.com

    • 📞 Phone: 1-800-788-6835 (US) | +1-562-546-6616 (International)

    • 🕐 Hours: Monday-Friday, 6:00 AM - 5:00 PM PST

    Online Resources:

    • 🌐 Official Site:

    • 💬 Developer Forum:

    Documentation Feedback:

    Help us improve this documentation!

    Device Inspection Document
    Package Inspection Document, Without Stand
    https://www.magtek.com
    https://forum.magtek.com
    Submit feedback