background image

Square Reader Security

Visible or tactile changes to the cable connections or card slot

Please contact Square Support at

https://squareup.com/square-support

if you discover any

evidence of external tampering.

Automatic Tamper Response

The Square Reader may identify certain events as attempts to tamper with its operation and
alter its inner workings. If the Square Reader identifies a tamper event it will erase the
encryption key material it contains and become inoperable.

The Square Reader is rated for normal operation and any of the below scenarios may tamper
the device and cause it to become inoperable:

Temperatures outside of the range of 0 and 40 degrees Celsius

Voltage outside of the range of 1.6 and 3.9 volts

Any attempt to open/disassemble/take apart the Square Reader or access parts inside

The Square Reader is intended to be fully charged once a year. If the Square Reader’s primary
battery is fully discharged and left for more a year without a recharge it may become
inoperable.

The Seller can detect if a tamper event has occurred by connecting the Square Reader to an
approved mobile device with the Register application installed. Opening the Register
application will notify the Seller if the device has reached a tamper event.

If the Square Reader experiences one of the above tamper events, Square will reach out to the
Seller and communicate as appropriate how to return the Square Reader to Square for secure
disposal and replacement.

Software development guidance

The Square Reader is designed for use with Square products and applications, and does not
work with other applications. All code is developed, written, and managed by Square.

Square developers must refer to the Software Engineering and Vulnerability Management
Procedures when developing new software for Square Readers.

Encryption and key management

The Square Reader is only intended for use with other Square applications and services.
Square performs all key management, key loading, and acquiring. Operating the device with
any other key loading, acquirer, or key management will render the device inoperable. In
addition, the use of the device with different key management systems will invalidate the PCI
approval of this device.

All of the cryptographic keys used by the Square Reader to protect the confidentiality and

© 2016 Square Inc. All Rights Reserved.

Version 1.00

8

Содержание Contactless and Chip Reader

Страница 1: ...Contactless and Chip Reader PCI Compliance Policy and Procedures Version 1 00 ...

Страница 2: ...Table of Contents 01 Introduction 05 Square Reader Authentication and Use 07 Square Reader Security 10 Version History ...

Страница 3: ...r use by merchants in many industries for accepting card present payment transactions The Reader only works with the Square Register application and a compatible mobile device1 running in a Square Stand https squareup com stand There is no configuration required other than to verify that the Reader is fully powered and connected via a USB port to the Square Stand Installation and inspection Sellers...

Страница 4: ...Introduction Isometric top down view Front view 2016 Square Inc All Rights Reserved Version 1 00 2 ...

Страница 5: ...Introduction Side view Back view 2016 Square Inc All Rights Reserved Version 1 00 3 ...

Страница 6: ...Introduction 2016 Square Inc All Rights Reserved Version 1 00 4 ...

Страница 7: ... classes Secure Card Reader SCR Secure Read and Exchange of Data SRED Integrated Chip Card Reader ICCR The Square Reader is intended for use in environments with attended payments it is not intended for use as an unattended payment terminal UPT How to store a Square Reader To store the Square Reader simply remove it from the Square Stand USB port and store for next use In the event the Seller will...

Страница 8: ...for decommissioning Square Inc Reader Decommissioning 1455 Market St Suite 600 San Francisco CA 942103 USA How to review the hardware and firmware version A Square Seller can confirm the hardware version by physical inspection as described above In addition the Seller can confirm the hardware and firmware version via the Support Readers screen of the Square Register application The PCI approved firmwar...

Страница 9: ... the Square Reader If the primary battery is entirely discharged the backup battery will maintain tamper detection of the device for one year If the Square Reader is not fully charged annually it will enter into a tampered state and become inoperable Common use and recharging of the primary battery will prevent the Square Reader from entering a tampered state For infrequent or seasonal users of th...

Страница 10: ...ader to an approved mobile device with the Register application installed Opening the Register application will notify the Seller if the device has reached a tamper event If the Square Reader experiences one of the above tamper events Square will reach out to the Seller and communicate as appropriate how to return the Square Reader to Square for secure disposal and replacement Software development...

Страница 11: ...re s key provisioning equipment authenticates incoming readers Square Readers entering the key provisioning stage authenticate the key bundles received as having originated from Square s factory key provisioning module The Square Reader does not accept keys from any entity other than the factory provisioning module Using the Square proprietary protocol the cryptographic keys are injected into new ...

Страница 12: ...Version History Version Change description 1 00 Initial release 2016 Square Inc All Rights Reserved Version 1 00 10 ...

Отзывы: