ID TECH SecureHead SPI with TMIV User Manual
Page | 26
4.16.
Security Management
This reader is intended to be a secure reader. Security features include:
•
Can include Device Serial Number
•
Can encrypt Track1 and Track2 data for all bank cards
•
Provides clear text confirmation data including card holder’s name and a portion
of the PAN as part of the Masked Track Data
•
Optional display of expiration data
•
Security Level is settable
The reader features configurable security settings. Before encryption can be enabled, Key Serial
Number (KSN) and Base Derivation Key (BDK) must be loaded; then encrypted transactions can take
place. The keys must be injected by certified key injection facility (such as ID TECH). Contact ID TECH
for more information about key injection services.
Four security levels are available when using DUKPT key management:
4.16.1.
Level 0
Security Level 0 is a special case where all DUKPT keys have been used and is set automatically when
it runs out of DUKPT keys. The supply of DUKPT keys is effectively 1 million, meaning that a new key
can be generated, per swipe, for up to a million card swipes. After this limit has been reached, key
injection will need to occur again before any more transactions can be done.
4.16.2.
Level 1
By default, readers from the factory are configured to have this security level. There is no encryption
process, no key serial number transmitted with decoded data. The reader functions as a non-
encrypting reader and the decoded track data is sent out in default mode.
4.16.3.
Level 2
Key Serial Number and Base Derivation Key have been injected but the encryption process is not yet
activated. The reader will send out decoded track data in default format. Setting the encryption type
to TDES and AES will change the reader to security level 3.
4.16.4.
Level 3
Both Key Serial Number and Base Derivation Keys are injected and encryption mode is turned on. For
payment cards, both encrypted data and masked cleartext data are sent out. (Users can select the
data masking of the PAN area; the encrypted data format cannot be modified.) You can choose
whether to send hashed data and whether to reveal the card expiration date. When encryption is
turned on, Level 3 is the default security level.