background image

Reader Security

 

 

 

Firmware and software update

 

Square will update the firmware associated with the Reader and POS application automatically as needed. For

 

 

 

 

 

 

 

 

 

 

 

 

   

 

 

the Reader, this will occur automatically with limited Seller interaction required. For the Square POS app, the

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

user will be prompted through standard OS messaging in addition to messaging within the app, once started.

 

 

 

 

 

 

 

   

   

 

 

 

 

 

 

These updates may address various issues, including security updates. In the event of a critical update, the

 

 

 

 

 

 

 

 

   

 

     

 

 

 

Square Point of Sale app will notify the Seller of the critical nature of the update and advise a course of action

 

   

 

 

 

 

 

   

 

 

   

 

 

 

   

   

 

for applying the update. Based on the criticality of the update, Square may disable transaction processing until

 

 

 

 

   

 

   

 

 

 

 

 

 

 

 

the update is successfully applied. For the Point of Sale (POS) application, the Seller will see updated

 

   

 

 

 

 

   

 

 

 

 

 

 

 

 

applications released every two (2) weeks. Based on the criticality of the updates that have been made to the

 

 

 

   

 

   

 

   

 

 

 

 

 

   

 

application, and the age of the currently installed app, Square may disable transaction processing until an

 

 

 

   

 

 

 

 

 

 

 

 

 

 

 

updated application is successfully installed. 
 

Infrequent or seasonal use 

The Reader has a primary battery and backup battery. The primary battery is used for operation of the Reader.

 

 

   

 

 

 

 

 

 

 

   

 

 

   

 

 

The backup battery is used to maintain the tamper-detection features of the Reader. If the primary battery is

 

 

   

   

 

 

 

   

 

   

 

 

   

entirely discharged the backup battery will maintain tamper-detection of the device for one year. If the Reader is

 

 

 

 

 

 

 

   

 

   

 

   

 

   

not fully charged annually it may enter into a tampered state and become inoperable. 
 
Common use and recharging of the primary battery will prevent the Reader from entering a tampered state. For

 

 

 

   

 

 

 

 

 

 

 

 

   

 

 

 

infrequent or seasonal users of the Reader we recommend charging the Reader fully at least once each year. 
 

Tamper detection and response

 

 
External Inspection of Reader 
Under normal operation, the Reader employs internal active tamper-response mechanisms as described below.

 

 

 

 

 

 

 

 

 

   

 

 

These mechanisms are enforced automatically and do not require any initial configuration by the user.  
 
Prior to accepting payments with the Reader, the Seller must inspect the Reader for evidence of external

   

 

 

 

 

 

 

 

 

 

 

 

 

   

 

tampering. Procedures should include, at minimum, examination to identify: 

Evidence of inserts, wires, overlays or any unknown component connected to the

   

 

 

   

 

 

 

   

 

Reader or inside the card slot 

Evidence of modification or disassembly of the Reader 

Visible or tactile changes to the cable connections or card slot 

 
Please contact 

Square Support

 if you discover any evidence of external tampering.   

 

Содержание S089

Страница 1: ...Square Mobile PIN Security Policy and Procedures PCI Software PIN on COTS ...

Страница 2: ...ion and Use Square POS Application Use Reader Security Appendix A Magstripe Readers Version Control Version Effective Date Author s Version Description 1 0 6 23 19 Square Inc Document Creation and Publication 1 1 9 18 19 Square Inc Addition of Appendix A 1 2 4 14 20 Square Inc Addition of SPF1 01 ...

Страница 3: ...ftware based PIN Entry on COTS standard version 1 0 The purpose of this document is to inform Square sellers of how to use the Reader and Point of Sale POS application in a secure fashion including information on key management responsibilities administrative responsibilities device functionality identification and environmental requirements The security policy defines the roles supported by the R...

Страница 4: ...on The Solution only works with a compatible mobile device There is no configuration of the Reader required other than to verify that the Reader is fully powered and connected via a USB port to the Square Stand or via bluetooth to your mobile device Initial Inspection Upon receipt of the Reader the Seller should inspect that the hardware version and serial number are visible on the underside of th...

Страница 5: ...Top view Front view Back view Installation ...

Страница 6: ...ing it off It ll automatically go into sleep mode after 2 hours of inactivity To wake it up from sleep mode firmly press the button on the side of the reader 2 Charge Your Square Reader Connect one end of the accompanying USB cable to your reader and the other end to a USB port like a cell phone charger computer or car charger It will take around 2 hours for a reader with low battery to charge com...

Страница 7: ...e top of the Square Point of Sale app 4 Tap Settings Card Readers Connect a Reader On an iOS device tap Contactless Chip Reader 5 Put your reader into pairing mode by pressing the reader s button for 3 10 seconds 6 Remove your finger as soon as you see orange flashing lights If you see red flashing lights you ve held the button too long and you ll need to try again When connected the reader will b...

Страница 8: ...following PCI PTS approval class Secure Card Reader PIN The Reader is intended for use in countertop and or handheld environments with attended and semi attended payments it is not intended for use as an unattended payment terminal UPT Use of the device in an unapproved method invalidates the PCI PTS approval of this device How to store a Reader To store the Reader simply remove it from the Square...

Страница 9: ...rancisco CA 942103 USA How to review the hardware and firmware version A Square Seller can confirm the hardware version by physical inspection as described above In addition the Seller can confirm the hardware and firmware version via an the Settings Card Readers screen of the Square Point of Sale application The PCI approved firmware version is displayed as SCRP 1 x xx xx The firmware version of ...

Страница 10: ...he Customer has no security configuration permissions Secure Use Upon starting the application and pairing the Reader the Square Mobile PIN solution will perform multiple security checks on the mobile device to ensure that it is suitable for PIN entry If these checks fail there is an incompatibility with the mobile device and the Point of Sale app will not accept PIN entry The Seller should be abl...

Страница 11: ...attery The primary battery is used for operation of the Reader The backup battery is used to maintain the tamper detection features of the Reader If the primary battery is entirely discharged the backup battery will maintain tamper detection of the device for one year If the Reader is not fully charged annually it may enter into a tampered state and become inoperable Common use and recharging of t...

Страница 12: ... application will notify the Seller if the device has experienced a tamper event If the Reader experiences one of the above tamper events Square will reach out to the Seller and communicate as appropriate how to return the Reader to Square for secure disposal and replacement Software Development Guidance The Reader is designed for use with Square products and applications and does not work with ot...

Страница 13: ...coming Readers Readers entering the key provisioning stage authenticate the key bundles received as having originated from Square s factory key provisioning module The Reader does not accept keys from any entity other than the factory provisioning module Using the Square proprietary protocol the cryptographic keys are injected into new devices in encrypted form The Square keys are injected and mai...

Страница 14: ...Square Mobile PIN solution can be used in conjunction with a Magstripe Swipe reader These transactions do not support the use of PIN Availability of Swipe based transactions varies by geographical market Approved Swipe Readers S4 SPM1 01 ...

Страница 15: ...S089 ...

Страница 16: ...SPF1 01 ...

Отзывы: