Security & Key Management
This section covers how DynaFamily readers protect cardholder data and manage keys: encrypting data at the point of read, the keys and key-serial numbers behind DUKPT, verifying message integrity with MACs, loading keys with TR-31, and the PCI requirements deployers must meet. These pages are the concepts and procedures; the security commands and data objects that implement them live in the API & Command Reference.
Applies to: DynaFamily (DynaFlex II PED, Go, SCR, DynaProx). The core concepts — DUKPT, KSN, MAC, TR-31 — apply to MagTek MMS SCRAs generally.
In This Section
Reference Section
Information Available
DUKPT: 3DES/TDEA --> AES Migration
How DUKPT derives a unique key per transaction, and the path (and reasons) for moving from legacy 3DES/TDEA DUKPT to AES DUKPT on your devices and host.
Key Serial Numbers (KSN)
What a KSN is, how it's structured, and how it identifies the unique key used to encrypt a given transaction under DUKPT.
Message Authentication Codes (MAC)
How a MAC lets the host and device confirm a message hasn't been altered in transit, and when one is required.
Encryption & Decryption
How the reader encrypts data at the point of read (SRED), how to determine which key was used, and how to decrypt the output on your host.
TR-31 Key Blocks
The ANSI TR-31 key-block format used to transport and load keys securely into the device.
PCI requirements (24-hour Reset, device lock)
The operational requirements the device enforces for PCI compliance: the 24-hour automatic reset and the device lock feature.
Where to Find Security Information
The Guides section (where you are now) contains articles on implementation. actual commands and objects live in the API & Command Reference section:
Key Security Commands
Reference Section
Information Available
Get Challenge
Requests a random challenge from the device, used to build a secured command.
Send Secured Command to Device
Transmits another command to the device securely.
Load Key using TR-31
Loads a key into one of the device's secure key slots.
Challenge Device lock State/Passcode
Change the device's lock state or its lock passcode.
Get Key Info
Retrieves information about a key slot and the key stored in it.
PCI requirements (24-hour Reset, device lock)
The operational requirements the device enforces for PCI compliance: the 24-hour automatic reset and the device lock feature.
Security Data Objects
Individual Security Data Objects can be found in the Data Types & Shared TLV Objects section.
Reference Section
Information Available
Security Operation
This non-TLV data structure consists of four or five bytes that describes a security operation, including the algorithms and methods to be used in that operation.
Security Parameters
This structure contains an Encrypted Signature Capture FileType specifying the operation to be performed.
Key Information
Identifies the key being used for operation.
TR-31 Key Block
The data object, its tags, and structure (in the command reference).
For More Help
Need Help?
For additional support, please contact MagTek Support:
Technical Support:
📧 Email: support@magtek.com
📞 Phone: 1-800-788-6835 (US) | +1-562-546-6616 (International)
🕐 Hours: Monday-Friday, 6:00 AM - 5:00 PM PST
Online Resources:
🌐 Official Site: https://www.magtek.com
💬 Developer Forum: https://forum.magtek.com
Documentation Feedback:
Help us improve this documentation! Submit feedback
Last updated

