ICO-OPE-04848-EN-V11 Public Move/3500 PCI PTS Security Policy 1_3 References ANS X9.24 Part 2: 2016, Retail Financial Services Symmetric Key Management Part 2: Using Asymmetric Techniques for the Distribution of Symmetric Keys ANS X9.24 - 1: 2017, Retail Financial Services Symmetric Key Management Part 1: Using Symmetric Techniques ANS X9.24 - 3: 2017, Retail Financial Services Symmetric Key Management Part 1: Unique...
3_1 Product Overview 3_1_1 Product type The Move/3500 PED is a Point of Sale (POS) payment handheld device, to process credit and PIN- based debit card transactions in an attended environment. The device can also be used as a desk mounted device, when following the guidance as stated in the installation guide.
The label at the back of the device shall not be teared off, covered or altered. Hardware version number Figure 2: Move/3500 product hardware identification The full list of approved Hardware Version Number is available on the PCI PTS website.
ICO-OPE-04848-EN-V11 Public Move/3500 PCI PTS Security Policy 3_2_3 Product software versions The software versions can be retrieved using the software menu. To get this information on the device, select the following menu: “Control Panel”, then “Terminal information”. • Select “Firmware PCI PTS” from the following configuration menu: •...
ICO-OPE-04848-EN-V11 Public Move/3500 PCI PTS Security Policy 4_Guidance 4_1 Initial Security Inspection The merchant or acquirer must visually inspect the terminal for sign of tampering when received via shipping, as it is described in the Installation Guide [8]. It is strongly advised that these checks are also performed on a regular basis after receipt and installation.
ICO-OPE-04848-EN-V11 Public Move/3500 PCI PTS Security Policy 4_4 Periodic Inspection and Maintenance Information about periodic inspection is specified in the installation guide [8]. The merchant or acquirer should daily check that the keypad is firmly in place. Such checks would provide warning of any unauthorized modification to the terminal, or suspicious behavior of the terminal.
ICO-OPE-04848-EN-V11 Public Move/3500 PCI PTS Security Policy 5_Product Hardware Security 5_1 Tamper Response Event The device contains tamper mechanisms that will trigger when a physical penetration attempt of the device is detected. A merchant or acquirer can easily detect a tampered terminal: −...
ICO-OPE-04848-EN-V11 Public Move/3500 PCI PTS Security Policy 6_Product Software Security 6_1 Software Development Guidance When developing IP enabled applications, the developer must abide by the coding rules and best practices described in the document [9], [10]. The following protocols and services are available on the device: TLS /SSL , IP, DNS, SMTP, POP3, DHCP, HTTP, HTTPS, SNTP, SOCKS, FTP, SFTP, WS/WSS, TCP/UDP, PPP.
ICO-OPE-04848-EN-V11 Public Move/3500 PCI PTS Security Policy 6_5 Self-Tests Self-tests are performed upon start up/reset and also periodically (i.e. at least once a day during the normal use of the device). These tests are not initiated by an operator. Self-tests include: Check of integrity and authenticity of the software •...
ICO-OPE-04848-EN-V11 Public Move/3500 PCI PTS Security Policy 7_System Administration 7_1 Configuration Settings The device is functional when received by the merchant or acquirer. No security sensitive configuration settings are necessary to be tuned by the end user to meet security requirements.
ICO-OPE-04848-EN-V11 Public Move/3500 PCI PTS Security Policy 8_3 Key Table Form Number Size factor Key Name Purpose / Usage Algorithm Storage (Bits) loaded to available device In Key Slots CA public keys for Secure K_Root_CA ECDSA certificate verification unit CA public keys for...
Page 16
ICO-OPE-04848-EN-V11 Public Move/3500 PCI PTS Security Policy Form Number Size factor Key Name Purpose / Usage Algorithm Storage (Bits) loaded to available device In Key Slots Derived MAC calculation / Secure DUKPT2009 – MAC Key TDES originally verification unit from IPEK...
ICO-OPE-04848-EN-V11 Public Move/3500 PCI PTS Security Policy Form Number Size factor Key Name Purpose / Usage Algorithm Storage (Bits) loaded to available device In Key Slots MAC Generation and Randoml verification of Secure MC_MAC Key TDES MC_ECC_Payment_Sy unit generate stem PK...
ICO-OPE-04848-EN-V11 Public Move/3500 PCI PTS Security Policy 8_5 Key Loading Policy The device has no functionality that gives access to security sensitive services, based on roles. Such services are managed through dedicated tools, using cryptographic authentication. 9_Roles and Services The device has no functionality that gives access to security sensitive services, based on roles. Such services are managed through dedicated tools, using cryptographic authentication.
Need help?
Do you have a question about the Move/3500 and is the answer not in the manual?
Questions and answers
What the OS of move 3500
The operating system of the Ingenico Move/3500 is TELIUM Tetra OS.
This answer is automatically generated