background image

key per transaction using AES CCM, which is an authenticated encryption mode for AES that provides both

 

 

 

 

 

 

     

 

 

 

 

 

 

 

 

confidentiality and authentication. 
 
The Reader only supports injection of keys during the manufacturing process; no remote key injection is

 

 

 

 

   

 

 

 

 

 

 

 

 

   

required as the Reader communicates directly with Square servers. During the manufacturing process, Square's

   

 

 

 

 

 

 

 

 

 

 

 

 

key provisioning equipment authenticates incoming Readers. Readers entering the key provisioning stage

 

 

 

 

 

 

 

 

 

 

 

 

authenticate the key-bundles received as having originated from Square's factory key provisioning module. The

 

 

 

   

 

 

 

 

 

 

 

 

 

Reader does not accept keys from any entity other than the factory provisioning module. Using the

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Square-proprietary protocol, the cryptographic keys are injected into new devices in encrypted form. The

 

 

 

 

 

 

 

 

 

   

 

 

 

Square keys are injected and maintained under Square control and the details are transparent to the merchant. 
 
The Reader does not provide or allow any user-configurable encryption key management functions. 
Thank you for reading! 
 

 

 

 

Summary of Contents for S089

Page 1: ...Square Mobile PIN Security Policy and Procedures PCI Software PIN on COTS ...

Page 2: ...ion and Use Square POS Application Use Reader Security Appendix A Magstripe Readers Version Control Version Effective Date Author s Version Description 1 0 6 23 19 Square Inc Document Creation and Publication 1 1 9 18 19 Square Inc Addition of Appendix A 1 2 4 14 20 Square Inc Addition of SPF1 01 ...

Page 3: ...ftware based PIN Entry on COTS standard version 1 0 The purpose of this document is to inform Square sellers of how to use the Reader and Point of Sale POS application in a secure fashion including information on key management responsibilities administrative responsibilities device functionality identification and environmental requirements The security policy defines the roles supported by the R...

Page 4: ...on The Solution only works with a compatible mobile device There is no configuration of the Reader required other than to verify that the Reader is fully powered and connected via a USB port to the Square Stand or via bluetooth to your mobile device Initial Inspection Upon receipt of the Reader the Seller should inspect that the hardware version and serial number are visible on the underside of th...

Page 5: ...Top view Front view Back view Installation ...

Page 6: ...ing it off It ll automatically go into sleep mode after 2 hours of inactivity To wake it up from sleep mode firmly press the button on the side of the reader 2 Charge Your Square Reader Connect one end of the accompanying USB cable to your reader and the other end to a USB port like a cell phone charger computer or car charger It will take around 2 hours for a reader with low battery to charge com...

Page 7: ...e top of the Square Point of Sale app 4 Tap Settings Card Readers Connect a Reader On an iOS device tap Contactless Chip Reader 5 Put your reader into pairing mode by pressing the reader s button for 3 10 seconds 6 Remove your finger as soon as you see orange flashing lights If you see red flashing lights you ve held the button too long and you ll need to try again When connected the reader will b...

Page 8: ...following PCI PTS approval class Secure Card Reader PIN The Reader is intended for use in countertop and or handheld environments with attended and semi attended payments it is not intended for use as an unattended payment terminal UPT Use of the device in an unapproved method invalidates the PCI PTS approval of this device How to store a Reader To store the Reader simply remove it from the Square...

Page 9: ...rancisco CA 942103 USA How to review the hardware and firmware version A Square Seller can confirm the hardware version by physical inspection as described above In addition the Seller can confirm the hardware and firmware version via an the Settings Card Readers screen of the Square Point of Sale application The PCI approved firmware version is displayed as SCRP 1 x xx xx The firmware version of ...

Page 10: ...he Customer has no security configuration permissions Secure Use Upon starting the application and pairing the Reader the Square Mobile PIN solution will perform multiple security checks on the mobile device to ensure that it is suitable for PIN entry If these checks fail there is an incompatibility with the mobile device and the Point of Sale app will not accept PIN entry The Seller should be abl...

Page 11: ...attery The primary battery is used for operation of the Reader The backup battery is used to maintain the tamper detection features of the Reader If the primary battery is entirely discharged the backup battery will maintain tamper detection of the device for one year If the Reader is not fully charged annually it may enter into a tampered state and become inoperable Common use and recharging of t...

Page 12: ... application will notify the Seller if the device has experienced a tamper event If the Reader experiences one of the above tamper events Square will reach out to the Seller and communicate as appropriate how to return the Reader to Square for secure disposal and replacement Software Development Guidance The Reader is designed for use with Square products and applications and does not work with ot...

Page 13: ...coming Readers Readers entering the key provisioning stage authenticate the key bundles received as having originated from Square s factory key provisioning module The Reader does not accept keys from any entity other than the factory provisioning module Using the Square proprietary protocol the cryptographic keys are injected into new devices in encrypted form The Square keys are injected and mai...

Page 14: ...Square Mobile PIN solution can be used in conjunction with a Magstripe Swipe reader These transactions do not support the use of PIN Availability of Swipe based transactions varies by geographical market Approved Swipe Readers S4 SPM1 01 ...

Page 15: ...S089 ...

Page 16: ...SPF1 01 ...

Reviews: