All pages
Powered by GitBook
1 of 4

Loading...

Loading...

Loading...

Loading...

Other Documents

This page provides essential supporting documentation for the oDynamo, including industry magnetic stripe card standards, a white paper on cryptographic algorithm transitions, and a technical bulletin on proper device maintenance and debris removal.

Key Documents

Reference Section

Information Available

Common technical details for magnetic stripe cards.

A white paper that addresses NIST Special Publication 800-131A regarding the transition away from Two-Key TDEA encryption, outlining MagTek's approach to cryptographic algorithm migration.

How to Use the MagTek Debris Clearing Tool

A technical bulletin that provides illustrated step-by-step instructions for correctly using the MagTek debris clearing tool to remove accumulated debris from the oDynamo's card insertion slot, helping to maintain device functionality and prevent mechanical damage.

Need More Help

Need Help?

For additional support, please contact MagTek Support:

Technical Support:

  • 📧 Email: support@magtek.com

  • 📞 Phone: 1-562-546-6800 (US)

  • 🕐 Hours: Monday-Friday, 5:30 AM - 5:00 PM PST

Online Resources:

  • 🌐 Support Portal: developer.magtek.com

Documentation Feedback:

Help us improve this documentation!

Magnetic Stripe Standards
MagTek Response to NIST SP 800-131A re: Two-Key TDEA Encryption
feedback@magtek.com

How to Use the MagTek Debris Clearing Tool

Introduction

This document provides instructions for using MagTek’s debris clearing tool to perform regular maintenance cleaning of the oDynamo card insertion slot. For additional support, contact MagTek Support Services.

1000007173 CLEANING KIT, CARD SLOT DEBRIS CLEARING TOOL, ODYNAMO contains the debris clearing tool and these instructions. For more intensive cleaning, consider 1000007139 CLEANING KIT, CARD SLOT, ODYNAMO, which includes additional tools and materials.

Instructions

To clean the oDynamo card insertion slot using the MagTek debris clearing tool, follow these steps. MagTek recommends performing this preventive maintenance regularly, depending on usage of the devices you are cleaning. Ideally maintenance would be performed before debris accumulates and renders the device non-functional:

  • Gather one of the debris cleaning tools from the kit. Turn the tool so its hook corner is on the right side, pointing toward the card insertion slot.

  • Push the tool straight into the card insertion slot all the way until you feel it touch the back wall.

  • Push the butt end of the tool to the left. This pivots the tool inside the device and pushes the hook against the back right corner of the card insertion slot.

  • Continue pushing the tool to the left so it stays engaged with the right wall of the slot, and slowly pull the tool out, scraping the right wall of the card insertion slot clean as you pull.

  • Repeat the scraping motion 2-3 times.

  • Turn the tool over so the hook points to the left, and repeat the same steps 2-3 times.

MagTek Response to NIST SP 800-131A re: Two-Key TDEA Encryption

April 8, 2019

Dear MagTek Customers,

In March 2019, NIST (National Institute of Standards and Technology) released a document entitled: “NIST Special Publication 800-131A Revision 2 – Transitioning the Use of Cryptographic Algorithms and Key Lengths1”. In that document, it states that the use of “Two-Key TDEA Encryption” has been listed as a “Disallowed” operational mode. This NIST document has raised concerns with our customers regarding the use of Two-Key TDEA Encryption within our products.

As a security leader, it is our intent to provide relevant information and guidance on this subject to our customers, and we can advise as follows:

At present time, “Two-Key TDEA Encryption” is currently the most widely used encryption method in the electronic payments and financial services sectors. It is used to protect both PIN and PAN payment data, and is used by most of the leading secure payment devices and payment networks deployed today.

As of this date there have been no successful attacks upon Two-Key TDEA Encryption that have resulted in the compromise of payment data encrypted under this mode. As such, Two-Key TDEA Encryption remains fully approved for use by both the ANSI X9 (American National Standards X9 - Financial Services) standards group and the PCI Security Standards Council.

MagTek customers who are currently using our products in the “Two-Key TDEA Encryption” mode can rest assured that the recent NIST announcements have no impact on security requirements within the Financial Services or Electronic Payments business sectors. As such, there is no need to make any changes to your MagTek products or encryption modes at this time.

It should be noted that the NIST recommendations only apply to Federal Agencies and their Information Systems. Commercial sector financial services are exempt from the NIST directives and are best served by following the ANSI X9 and PCI security standards organizations for recommendations on encryption requirements for payment data.

In regard to Two-Key TDEA Encryption for Transport Layer Security (TLS), PCI advised on this matter during a November 2017 blog entitled: “2”.

In that discussion, PCI acknowledges that the strength of Two-Key TDEA Encryption is under review and is no longer considered as “strong cryptography” by NIST. Further, PCI mentions that when NIST formally declares

MagTek, Inc. | 1710 Apollo Court | Seal Beach, CA 90740 | p. 562-546-6400 | f. 562-546-6301 |

Registered to ISO 9001:2015 © Copyright 2019 MagTek, Inc. PN D998200305 rev 10 4/19

Two-Key TDEA Encryption as “fully disallowed” it will no longer be considered “strong cryptography” by PCI SSC. Now that NIST has formally declared such (as of March 2019), the payment industry will need to await PCI’s further guidance on this subject.

In the interim, PCI has recommended that organizations begin planning their transition towards AES-128, yet acknowledges that due to legacy considerations this transition may take place over a long period of time.

Additionally, PCI recommends the use of several mitigation techniques to reduce risk. One of those measures is to “Change TDEA keys regularly…every 256 transactions or daily, whichever is more frequent”. In regard to this recommendation, MagTek can advise that our products utilize DUKPT (Derived Unique Key Per Transaction), a far more rigorous key management method. DUKPT ensures that a different key is generated for each and every transaction, taking PCI’s recommendation for frequent key changes to the maximum level.

Looking ahead, both the ANSI X9 and PCI Security Standards Council are establishing standards and transition paths towards the adoption of AES-128 as the successor to TDEA for encryption of payment data.

However, due to the proven security of TDEA, legacy concerns, and logistical considerations, it is anticipated that this transition will take place over the next 4-10 years. The earliest transition milestone will be the end of PCI support for TDEA PIN encryption using fixed-key management by Jan 1, 2023.

It is important to note that this milestone does not apply to the use of TDEA PIN encryption using DUKPT (Derived Unique Key Per Transaction) key management. As such, it is very likely that there will be a long transition period where both Two-Key TDEA DUKPT and AES128 DUKPT encryption methods will be used concurrently for the foreseeable future. (See table below for upcoming security milestones.)

As a security leader in the electronic payments industry, MagTek is moving forward with implementation of AES-128 DUKPT into our products and security services. In the meantime, we will continue to support Two-Key TDEA DUKPT encryption in our products for however long the payments industry requests it, and/or the relevant security standards support it.

As always, MagTek will continue to keep our customers informed on these matters and provide clear guidance as new security trends and requirements emerge.

If you have any further questions, please contact your MagTek Sales Representative or me and we will be happy to answer any questions you may have.

Sincerely,

Larry Meyers

Vice President, Qwantum Secure Media MagTek, Inc

1710 Apollo Court Seal Beach, CA 90740 562-546-6400

About MagTek

Founded in 1972, MagTek is a leading manufacturer of electronic systems for the reliable issuance, reading, transmission and security of cards, checks, PINs and identification documents. Leading with innovation and engineering excellence, MagTek is known for quality and dependability. Its products include secure card reader/authenticators, token generators, EMV contact, contactless and NFC reading devices, encrypting check scanners, PIN pads and distributed credential personalization systems for secure magstripe and EMV enabled cards. These products are used worldwide by financial institutions, retailers, and processors to provide secure and efficient payment and identification transactions.

Today, MagTek continues to innovate. Its MagneSafe™ Security Architecture leverages strong encryption, secure tokenization, dynamic card authentication, and device/host validation enabling users to assess the trustworthiness of credentials and terminals used for online identification, payment processing, and high- value electronic transactions.

MagTek is headquartered in Seal Beach, CA. For more information, please visit

Citations

1. Barker, Elaine and Roginsky, Allen; March 21, 2019; NIST Special Publication (SP) 800-131A Revision 2; “Transitioning the Use of Cryptographic Algorithms and Key Lengths”

2 and and “PCI SSC Cryptography Expert on Triple DEA”; link:

Magnetic Stripe Card Standards

PCI PIN

All hosts must support ISO PIN Block Format 4 (AES)

DECRYPTION

Jan 1, 2023

PCI PIN

All hosts must support ISO PIN Block Format 4 (AES)

DECRYPTION & ENCRYPTION

Jan 1, 2025

Security

Entity

Requirement

Effective Date

VISA PCI PIN

Sunset data for SINGLE DES PIN encryption

(applies to fuel dispenser environments POS only)

Oct 1, 2020

PCI PIN

FIXED Key for TDEA PIN encryption in POI devices and

Host-to-Host connections is disallowed

PCI SSC Cryptography Expert on Triple DEA
www.magtek.com
larry.meyers@magtek.com
www.magtek.com.
. Poore, Ralph Spencer; Nov 9, 2019; PCI Security Standards; TLS/SSL
Encryption
Approved Scanning Vendors;
https://blog.pcisecuritystandards.org/pci-ssc-cryptography-expert-on-triple-dea

Jan 1, 2023

7811-3

Location of embossed characters

7811-4

Location of tracks 1 & 2

7811-5

Location of track 3

7811-6

Magnetic stripe - high coercivity

7813

Financial transaction cards

Measurement - 0.223"

Track

Recording Density (bits per inch)

Character Configuration (including parity bit)

Information Content (including control characters)

0.110"

1 IATA

210

7 bits per character

76 alphanumeric data characters between Format Code and Discretionary Data.

SS

FC

PAN

FS

Name

FS

Additional data

Discretionary Data

ES

  • SS: Start Sentinel - %

  • FC: Format Code - ^

  • PAN: Primary Account Number (19 digits max.)

  • FS: Field Separator

  • NAME: Name (26 alphanumeric characters max.)

  • ADDITIONAL DATA: Number of characters:

    • Expiration Date (YYMM) - 4

    • Service Code - 3

  • DISCRETIONARY DATA: Number of characters:

    • PVKI - PIN Verification Key Number

    • PVV or Offset - PIN Verification Value

  • ES: End Sentinel - ?

  • LRC: Logitudinal Redundancy Check character

37 data characters between PAN and Discretionary Data.

SS

PAN

FS

Additional data

Discretionary Data

ES

LRC

  • SS: Start Sentinel - Hex B - ;

  • PAN: Primary Account Number (19 digits max.)

  • FS: Field Separator - Hex D - =

  • ADDITIONAL DATA: Number of characters:

    • Expiration Date (YYMM) - 4

    • Service Code - 3

  • DISCRETIONARY DATA: Number of characters:

    • PVKI - PIN Verification Key Number

    • PVV or Offset - PIN Verification Value

  • ES: End Sentinel - Hex F - ?

  • LRC: Logitudinal Redundancy Check character

104 numeric data characters between Format Code and Additional Data.

SS

FC

PAN

FS

USE AND SECURITY DATA

Additional data

ES

LRC

  • SS: Start Sentinel - Hex B - ;

  • PAN: Primary Account Number (19 digits max.)

  • FS: Field Separator - Hex D - =

  • USE AND SECURITY DATA - Number of characters

    • Country Code (optional) - 3

    • Currency Code - 3

    • Currency Exponent - 1

    • Amount Authorized per Cycle - 4

  • ADDITIONAL DATA: Number of characters:

    • First subsidiary account number (optional)

    • Second subsidiary account number (optional)

  • ES: End Sentinel - Hex F - ?

  • LRC: Logitudinal Redundancy Check character

  • FC: Format Code - (2 digits) (in place of optional field)

7810

Physical characteristics of credit card size document

7811-1

Embossing

7811-2

Magnetic stripe - low coercivity

Dimensions - Financial Transaction Cards

ISO

For copies of specifications contact: American National Standards Institute 11 W. 42nd Street, New York, NY 10036 212-642-4900

Magnetic Stripe Encoding

Magnetic Stripe Encoding

Track 1

Encoding Key

Track 2

Encoding Key

Some or all of the above Discretionary Data fields may be found with the discretionary data

Track 3 (ISO 4909)

Encoding Key

A Field Separator (FS) must be used if an optional field is not used

The track formats used in this document are based on ISO Standards, however, other formats may be used. Contact your card issuer for your exact requirements

CVV or CVC - Card Verification Value, Card Vakudation Code
CVV or CVC - Card Verification Value, Card Vakudation Code
  • Amount Remaining this Cycle - 4

  • Cycle Begin (Validity Date) - 4

  • Cycle Length - 2

  • Retry Count - 1

  • PIN Control Parameters (optional) - 6

  • Interchange Controls - 1

  • PAN Service Restriction - 2

  • SAN-1 Service Restriction - 2

  • SAN-2 Service Restriction - 2

  • Expiration Date (optional) - 4

  • Card Sequence Number - 1

  • Card Security Number (optional) - 9

  • Relay marker - 1
  • Cryptographic check digits (optional) - 6

  • Discretionary Data

  • 79 alphanumeric characters

    0.110"

    ABA

    75

    5 bits per character

    40 numeric characters

    0.110"

    THRIFT

    210

    5 bits per character

    107 numeric characters

    LRC

    Orange characters identify control characters

    Orange characters identify control characters