Download Print this page

Square SPF1-01 Manual

Square mobile pin security policy and procedures pci software pin on cots

Advertisement

 
 
 
Square Mobile PIN 
Security Policy and Procedures 
PCI Software PIN on COTS 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Advertisement

loading
Need help?

Need help?

Do you have a question about the SPF1-01 and is the answer not in the manual?

Questions and answers

Summarization of Contents

Installation and User Guidance
Initial Inspection
Inspect the reader for hardware version and serial number visibility on the underside.
Check the Battery of Your Square Reader
Check battery status by pressing the reader button; charge if red light appears.
Charge Your Square Reader
Charge the reader using a USB cable; charging takes approximately 2 hours.
Wirelessly Connect Your Square Reader
Connect wirelessly via Bluetooth LE; ensure the latest Square POS app version is used.
Connecting
Connect reader via Bluetooth settings and Square POS app, following pairing steps.
Reader Authentication and Use
Authentication of the Reader
Reader is authenticated cryptographically to POS app and servers; unauthorized readers are flagged.
How to obtain a Reader
Obtain reader via Square website or approved retail location; verify country of operation.
Attributes of a Reader
Reader has PCI PTS approval class; intended for attended payments, not unattended terminals.
How to store a Reader
Store reader by removing from USB port; charge annually to prevent inoperability.
Procedures for using a Reader
Inspect reader daily for tampering; check chip card slot for foreign objects.
Security Self-Tests
Reader performs self-tests upon power-on and via forced reboots.
How to decommission a Reader
Ship the reader to Square for decommissioning at the provided address.
How to review the hardware and firmware version
Confirm hardware/firmware version via physical inspection or POS app settings.
Square POS Application Use
User Roles and Permissions
Defines two roles: Seller (operates device, no config) and Customer (uses payment card/PIN).
Secure Use
POS app performs security checks; incompatibility may prevent PIN entry.
Privacy Shielding
PINs are entered on the mobile device; customers should shield device during entry.
Reader Security
Firmware and software update
Firmware/app updates occur automatically; critical updates may temporarily disable processing.
Infrequent or seasonal use
Charge reader annually to maintain tamper-detection and prevent inoperability.
Tamper detection and response
Reader has internal tamper mechanisms; external inspection is required before use.
External Inspection of Reader
Inspect for inserts, wires, modifications, or tactile changes to card slot/connections.
Inspection of Point of Sale Application
Verify POS app integrity via native store; SPoC-enabled app shows version 1.0.
Automatic Tamper Response
Tamper events erase encryption keys, rendering the reader inoperable.
Software Development Guidance
Reader is for Square apps only; developers must follow Square's procedures.
Encryption and key management
Keys are injected during manufacturing, stored securely, and protected.
Appendix A: Magstripe Reader Use
Approved Swipe Readers
Lists approved Magstripe readers (S4, SPM1-01) used with the solution.