SCH2 Technical Manual TSP016.doc Issue 3.0 – January 2005
Money Controls 2005. All rights reserved.
Page 20 of 61
11.1 PIN Number Mechanism
A PIN number is provided on SCH2 as an
optional
security feature. By default, units are
shipped without the PIN number mechanism enabled. If this feature is not required or its use
is too restrictive then it can simply be ignored.
By programming a PIN number into the device, if the hopper device is subsequently powered
down or removed to another location then unless the PIN number is known, no coins can be
dispensed. This is another layer of defence against the determined hacker who wishes to
experiment with the encryption mechanism. However it does require the host machine
keeping track of the PIN numbers of any hoppers used in that cabinet.
Various possibilities include…
1. Don’t use a PIN number
Nice and easy that one.
2. Fix the PIN number to the same value always
This can be done but is not very secure. Once the PIN number is known then there is
effectively no PIN number protection on any of the hoppers. It is simple to manage though
and the ‘master’ PIN number is unlikely to be forgotten.
3. Scramble the PIN number and store in the user memory
This is quite a clever idea because it means you can randomise the PIN number on each
hopper and as long as you know how you scrambled it, it can be recovered, unscrambled
and sent to the hopper during the initialisation routine. Security relies on keeping this
scrambling algorithm secret.
4. Log the PIN number versus serial number
As each hopper has a unique serial number then this gives a convenient method of storing
the serial number against a random PIN number in a central database which all the
machines have access too on a network. This is the most secure method because unless
the PIN number transaction is captured on the bus at just the right moment in time, and for
that particular hopper, the only way to obtain the PIN would be by exhaustive searching.
With 4.3 billion combinations at 245ms per guess would take on average 16.7 years.
If you are unfortunate enough to have a hopper for which you have forgotten the PIN number
then contact Money Controls for details of any possible recovery mechanism that we may
have in place at the time.
Continued…..
Summary of Contents for SCH2
Page 8: ......