background image

Inspection of Point of Sale Application 

The Square POS application provides its own internal integrity verification processes.  Ensure you are using the 
latest version of the app by checking your native application store. The SPoC-enabled application will show 
“SPoC version 1.0” under Support -> About -> Application. 
 
Automatic Tamper Response 
The Reader may identify certain events as attempts to tamper with its operations to alter its inner workings. If the

 

 

 

 

 

   

   

 

   

   

   

 

   

 

Reader identifies a tamper event it will erase the encryption key material it contains and become inoperable. 
 
The Reader is rated for normal operation and any of the below scenarios may tamper the device and cause it to

 

   

 

 

 

 

 

   

 

 

 

 

 

 

 

 

     

become inoperable: 

Temperatures outside of the range of 0 and 40 degrees Celsius 

Voltage greater or less than 5V input for charging the device via USB 

Any attempt to open/disassemble/take apart the Reader or access parts inside 

 
The Reader is intended to be fully charged once a year. If the Reader’s primary battery is fully discharged and

 

   

     

 

 

   

   

 

 

 

   

 

 

 

left for more than a year without a recharge it may become inoperable.  
 
The Seller can detect if a tamper event has occurred by connecting the Reader to an approved mobile device

 

 

 

     

 

 

 

   

 

 

     

 

 

 

with the Point of Sale application installed. Opening the Point of Sale application will notify the Seller if the

 

 

   

 

 

 

 

 

   

 

 

 

 

 

   

 

device has experienced a tamper event. 
 
If the Reader experiences one of the above tamper events, Square will reach out to the Seller and communicate

 

 

 

 

   

 

 

 

 

 

 

 

   

 

 

 

 

as appropriate how to return the Reader to Square for secure disposal and replacement. 
 

Software Development Guidance

 

The Reader is designed for use with Square products and applications, and does not work with other

 

   

 

 

 

 

 

 

 

 

 

 

 

 

 

 

applications. All code is developed, written, and managed by Square. Square developers must refer to the

 

 

   

 

 

 

 

 

 

 

 

 

   

 

Software Engineering and Vulnerability Management Procedures when developing new software for Readers. 
 

Encryption and key management

 

The Reader is only intended for use with other Square applications and services. Square performs all key

 

   

 

 

 

 

 

 

 

 

 

 

 

   

 

management, key loading, and acquiring. Attempts to operate the Reader with any other key loading, acquirer,

 

 

 

 

 

   

 

 

 

 

 

 

 

 

 

or key management will render the device inoperable. In addition, use of the Reader with different key

 

 

 

 

 

 

 

   

 

   

 

 

 

 

 

management systems will invalidate the PCI approval of this device. 
 
All of the cryptographic keys used by the Reader to protect the confidentiality and integrity of sensitive data are

   

 

 

 

   

 

   

 

 

 

 

   

 

 

 

injected at the time of manufacture using a Square-proprietary protocol. The keys are stored within the Reader’s

   

 

   

 

   

 

 

 

 

 

 

 

 

 

secure boundary, and are protected from both disclosure and modification; such protection is achieved with a

 

 

 

 

 

 

 

 

 

 

 

   

 

   

key-encrypting key that meets the PCI PTS key strength requirements. Sensitive data is encrypted by a unique

 

 

 

 

 

 

 

 

 

 

 

   

     

 

 

Summary of Contents for S089

Page 1: ...Square Mobile PIN Security Policy and Procedures PCI Software PIN on COTS ...

Page 2: ...ion and Use Square POS Application Use Reader Security Appendix A Magstripe Readers Version Control Version Effective Date Author s Version Description 1 0 6 23 19 Square Inc Document Creation and Publication 1 1 9 18 19 Square Inc Addition of Appendix A 1 2 4 14 20 Square Inc Addition of SPF1 01 ...

Page 3: ...ftware based PIN Entry on COTS standard version 1 0 The purpose of this document is to inform Square sellers of how to use the Reader and Point of Sale POS application in a secure fashion including information on key management responsibilities administrative responsibilities device functionality identification and environmental requirements The security policy defines the roles supported by the R...

Page 4: ...on The Solution only works with a compatible mobile device There is no configuration of the Reader required other than to verify that the Reader is fully powered and connected via a USB port to the Square Stand or via bluetooth to your mobile device Initial Inspection Upon receipt of the Reader the Seller should inspect that the hardware version and serial number are visible on the underside of th...

Page 5: ...Top view Front view Back view Installation ...

Page 6: ...ing it off It ll automatically go into sleep mode after 2 hours of inactivity To wake it up from sleep mode firmly press the button on the side of the reader 2 Charge Your Square Reader Connect one end of the accompanying USB cable to your reader and the other end to a USB port like a cell phone charger computer or car charger It will take around 2 hours for a reader with low battery to charge com...

Page 7: ...e top of the Square Point of Sale app 4 Tap Settings Card Readers Connect a Reader On an iOS device tap Contactless Chip Reader 5 Put your reader into pairing mode by pressing the reader s button for 3 10 seconds 6 Remove your finger as soon as you see orange flashing lights If you see red flashing lights you ve held the button too long and you ll need to try again When connected the reader will b...

Page 8: ...following PCI PTS approval class Secure Card Reader PIN The Reader is intended for use in countertop and or handheld environments with attended and semi attended payments it is not intended for use as an unattended payment terminal UPT Use of the device in an unapproved method invalidates the PCI PTS approval of this device How to store a Reader To store the Reader simply remove it from the Square...

Page 9: ...rancisco CA 942103 USA How to review the hardware and firmware version A Square Seller can confirm the hardware version by physical inspection as described above In addition the Seller can confirm the hardware and firmware version via an the Settings Card Readers screen of the Square Point of Sale application The PCI approved firmware version is displayed as SCRP 1 x xx xx The firmware version of ...

Page 10: ...he Customer has no security configuration permissions Secure Use Upon starting the application and pairing the Reader the Square Mobile PIN solution will perform multiple security checks on the mobile device to ensure that it is suitable for PIN entry If these checks fail there is an incompatibility with the mobile device and the Point of Sale app will not accept PIN entry The Seller should be abl...

Page 11: ...attery The primary battery is used for operation of the Reader The backup battery is used to maintain the tamper detection features of the Reader If the primary battery is entirely discharged the backup battery will maintain tamper detection of the device for one year If the Reader is not fully charged annually it may enter into a tampered state and become inoperable Common use and recharging of t...

Page 12: ... application will notify the Seller if the device has experienced a tamper event If the Reader experiences one of the above tamper events Square will reach out to the Seller and communicate as appropriate how to return the Reader to Square for secure disposal and replacement Software Development Guidance The Reader is designed for use with Square products and applications and does not work with ot...

Page 13: ...coming Readers Readers entering the key provisioning stage authenticate the key bundles received as having originated from Square s factory key provisioning module The Reader does not accept keys from any entity other than the factory provisioning module Using the Square proprietary protocol the cryptographic keys are injected into new devices in encrypted form The Square keys are injected and mai...

Page 14: ...Square Mobile PIN solution can be used in conjunction with a Magstripe Swipe reader These transactions do not support the use of PIN Availability of Swipe based transactions varies by geographical market Approved Swipe Readers S4 SPM1 01 ...

Page 15: ...S089 ...

Page 16: ...SPF1 01 ...

Reviews: