APG8201 – Technical Specifications
info@acs.com.hk
Version 2.03
www.acs.com.hk
Page 3 of 8
1.0. Introduction
As technology becomes more sophisticated, fraud-related incidents in
banking sector becomes more prevalent. These occurrences generate
billions of dollars worth of losses and bring distress among credit and
debit cardholders. Certain security measures and systems are created
specifically to protect cardholders from frauds, which makes the
APG8201 PINhandy 1 a reliable tool to fight these occurrences.
1.1. What is APG8201 PINhandy 1?
APG8201 PINhandy 1 is a portable, low-cost, and hand-held smart card device which supports PC-
linked and standalone modes to perform various authentication applications. It is capable of managing
One-Time Passwords (OTP), Challenge-Response Authentication Codes, and Transaction Data
Signing (Public Key Infrastructure digital signatures) based on the security keys stored in the EMV™
(Europay, MasterCard®, and Visa®) cards.
1.2. How does APG8201 PINhandy 1 work?
The APG8201 PINhandy 1 uses a two-level authentication process which requires the cardholder to
insert the EMV card into the device and enter a Personal Identification Number (PIN) using the built-in
PIN-pad. APG8201 PINhandy 1 then generates a dynamic one-time password on the display screen
which can be used to log-in before performing several transactions like online transactions, banking
logons and telephone orders.
1.3. How is APG8201 PINhandy 1 secure?
APG8201 PINhandy is compliant with major banking, computing and safety standards such as
MasterCard® Chip Authentication Program (CAP), MasterCard® Advanced Authentication for Chip
(AA4C/PLA), VISA® Dynamic Passcode Authentication (DPA) and EMV™ Level 1 (Contact). It is
specially designed to safeguard users from the emerging fraud attacks like Card-not-Present (CNP)
fraud and emerging Man-in-the-Middle (MitM) attacks. It also provides proof that a card is present
during an OTP process.
Likewise, APG8201 PINhandy 1 supports Secure PIN Entry (SPE), to assure safe PIN entry and PIN
change while in PC-linked mode. The PIN is securely entered on the device rather than the vulnerable
personal computer or workstation, hence eliminating the possibility of a virus (Trojan) getting hold of
the PIN.
1.4. How can APG8201 PINhandy 1 help save money?
Banks can now distribute APG8201 PINhandy 1 most efficiently in bulk/volume to individual
customers without the concern of handling sensitive data. More importantly, complicated device
issuance or re-issuance strategy is no longer needed, hence the overall implementation cost is
lowered. And since the APG8201 PINhandy 1 also works as a standalone device, no specialized
programming is required.