background image

In addition to continual tamper detection and response, the Reader authenticates the firmware and terminal

 

   

 

 

 

 

 

 

 

 

 

 

 

 

configurations using RSA 3072/SHA-256 every time it is powered on. The Reader also implements a forced

 

 

 

 

 

     

 

 

 

 

 

   

 

reboot every 23.5 hours which initiates the same self-tests as when the device is powered on. 
 
How to decommission a Reader 
To decommission the Reader please ship the device to the following address for decommissioning: 
 

Square, Inc. 
℅: Reader Decommissioning 
1455 Market St, Suite 600 
San Francisco, CA 942103  
USA 

 
How to review the hardware and firmware version 
A Square Seller can confirm the hardware version by physical inspection as described above. In addition, the

 

 

 

 

 

 

 

   

 

   

 

   

 

 

Seller can confirm the hardware and firmware version via an the Settings > Card Readers screen of the Square

 

 

 

 

 

 

 

 

   

 

   

 

 

   

 

 

Point of Sale application.  
 
The PCI approved firmware version is displayed as “SCRP.1.x.xx.xx”.   
 
The firmware version of valid S4, SPM1-01, and SPF1-01 magnetic stripe readers is “M1”. Only MSRs with “S4”,

 

 

   

 

 

 

 

 

 

 

   

 

 

 

 

 

“SPM1-01”, or “SPF1-01” etched on the device casing contain this valid “M1” firmware. The firmware version of

   

 

 

 

 

 

 

 

 

 

 

 

 

 

   

valid S089 magnetic stripe readers is “S089”. Only MSRs with “S089” etched on the device casing contain this

 

 

 

 

   

 

 

 

 

 

   

 

 

 

 

 

firmware. 
 
 
 

 

 

 

Содержание S089

Страница 1: ...Square Mobile PIN Security Policy and Procedures PCI Software PIN on COTS ...

Страница 2: ...ion and Use Square POS Application Use Reader Security Appendix A Magstripe Readers Version Control Version Effective Date Author s Version Description 1 0 6 23 19 Square Inc Document Creation and Publication 1 1 9 18 19 Square Inc Addition of Appendix A 1 2 4 14 20 Square Inc Addition of SPF1 01 ...

Страница 3: ...ftware based PIN Entry on COTS standard version 1 0 The purpose of this document is to inform Square sellers of how to use the Reader and Point of Sale POS application in a secure fashion including information on key management responsibilities administrative responsibilities device functionality identification and environmental requirements The security policy defines the roles supported by the R...

Страница 4: ...on The Solution only works with a compatible mobile device There is no configuration of the Reader required other than to verify that the Reader is fully powered and connected via a USB port to the Square Stand or via bluetooth to your mobile device Initial Inspection Upon receipt of the Reader the Seller should inspect that the hardware version and serial number are visible on the underside of th...

Страница 5: ...Top view Front view Back view Installation ...

Страница 6: ...ing it off It ll automatically go into sleep mode after 2 hours of inactivity To wake it up from sleep mode firmly press the button on the side of the reader 2 Charge Your Square Reader Connect one end of the accompanying USB cable to your reader and the other end to a USB port like a cell phone charger computer or car charger It will take around 2 hours for a reader with low battery to charge com...

Страница 7: ...e top of the Square Point of Sale app 4 Tap Settings Card Readers Connect a Reader On an iOS device tap Contactless Chip Reader 5 Put your reader into pairing mode by pressing the reader s button for 3 10 seconds 6 Remove your finger as soon as you see orange flashing lights If you see red flashing lights you ve held the button too long and you ll need to try again When connected the reader will b...

Страница 8: ...following PCI PTS approval class Secure Card Reader PIN The Reader is intended for use in countertop and or handheld environments with attended and semi attended payments it is not intended for use as an unattended payment terminal UPT Use of the device in an unapproved method invalidates the PCI PTS approval of this device How to store a Reader To store the Reader simply remove it from the Square...

Страница 9: ...rancisco CA 942103 USA How to review the hardware and firmware version A Square Seller can confirm the hardware version by physical inspection as described above In addition the Seller can confirm the hardware and firmware version via an the Settings Card Readers screen of the Square Point of Sale application The PCI approved firmware version is displayed as SCRP 1 x xx xx The firmware version of ...

Страница 10: ...he Customer has no security configuration permissions Secure Use Upon starting the application and pairing the Reader the Square Mobile PIN solution will perform multiple security checks on the mobile device to ensure that it is suitable for PIN entry If these checks fail there is an incompatibility with the mobile device and the Point of Sale app will not accept PIN entry The Seller should be abl...

Страница 11: ...attery The primary battery is used for operation of the Reader The backup battery is used to maintain the tamper detection features of the Reader If the primary battery is entirely discharged the backup battery will maintain tamper detection of the device for one year If the Reader is not fully charged annually it may enter into a tampered state and become inoperable Common use and recharging of t...

Страница 12: ... application will notify the Seller if the device has experienced a tamper event If the Reader experiences one of the above tamper events Square will reach out to the Seller and communicate as appropriate how to return the Reader to Square for secure disposal and replacement Software Development Guidance The Reader is designed for use with Square products and applications and does not work with ot...

Страница 13: ...coming Readers Readers entering the key provisioning stage authenticate the key bundles received as having originated from Square s factory key provisioning module The Reader does not accept keys from any entity other than the factory provisioning module Using the Square proprietary protocol the cryptographic keys are injected into new devices in encrypted form The Square keys are injected and mai...

Страница 14: ...Square Mobile PIN solution can be used in conjunction with a Magstripe Swipe reader These transactions do not support the use of PIN Availability of Swipe based transactions varies by geographical market Approved Swipe Readers S4 SPM1 01 ...

Страница 15: ...S089 ...

Страница 16: ...SPF1 01 ...

Отзывы: