july 2006 sc 5000 smart programmable pinpad. the changing payment environment compliance with...

Download July 2006 SC 5000 Smart Programmable PINpad. The Changing Payment Environment  Compliance with global EMV standards will be mandated by card associations

If you can't read please download the document

Upload: charles-simon

Post on 17-Jan-2018

217 views

Category:

Documents


0 download

DESCRIPTION

The Competitive Advantage of Next-Generation Payment Solutions  Fast, flexible, full-featured solutions improve customer service Choice – consumers have a variety of electronic payment choices Speed – process even the most complex transactions in seconds Simplicity – friendly, intuitive interface Design – compact and ergonomic

TRANSCRIPT

July 2006 SC 5000 Smart Programmable PINpad The Changing Payment Environment Compliance with global EMV standards will be mandated by card associations Banks, acquirers and merchants must manage the cost & timing of upgrading their payment infrastructure Smart cards will increase security for payment transactions Value-added applications create an opportunity to improve customer service and generate new sources of revenue The emergence of a global smart card standard presents challenges & opportunities The Competitive Advantage of Next-Generation Payment Solutions Fast, flexible, full-featured solutions improve customer service Choice consumers have a variety of electronic payment choices Speed process even the most complex transactions in seconds Simplicity friendly, intuitive interface Design compact and ergonomic Smart Move: SC 5000 Unsurpassed performance in a programmable PINpad EMV compatibility Outstanding flexibility Ergonomically designed Comprehensive security protections Integrates with older-generation POS terminals and electronic cash registers The smart solution for the smart card generation SC 5000: Unsurpassed Performance 32-bit processing power delivers unbeatable performance on smart card transactions Quickly handles complex cryptography Development environment designed for maximum performance Performance assured for older-generation terminals and ECRs without replacing existing installed base The Smart EMV Solution The SC 5000 family provides all the elements required for EMV compatibility without compromising the ability to customize the solution EMV Level 1 Type Approval for hardware EMV Level 2 Type Approval for optional application resident on device Flexible development environment supports creation of EMV-compliant solutions or custom smart card applications Smart and Versatile Capabilities SC 5000 a card reader for every occasion Primary smart card reader Choice of 0, 2, or 4 SAMs Optional, bi-directional, dual or triple track magnetic stripe reader Optional backlit display Robust Software Developers Toolkit (SDTK) for streamlined applications development Designed for merchants and their customers Bold, ergonomic design is sleek and stylish Small footprint reduces countertop clutter Ergonomic design is easy for clerks and consumers to handle for PIN or other data entry Large keys minimize errors Highly readable LED-display with backlit option for low-light environments Multiple language support, including support or graphics-based character sets SC 5000 Product Details User Interface telephone-style numeric keypad 3 programmable function keys 3 screen addressable keys 122 x 32 pixel Graphics Display Supports simultaneous display of graphics & text Supports text display of 4 lines by 15 characters Support for Multiple Languages Both graphics-based & roman character fonts Application controls presentation of multiple languages 1, 2, or 4 MB RAM Supports multiple applications SC 5000 Product Details Programmable C Based Programming Environment can leverage Verix application development MULTI Software Development Environment from Green Hills Software Inc. (GHS) Magnetic stripe reader Data can be read simultaneously on all tracks and in both directions of card swipe 0, 2, 4 Security Access Module (SAM) option EMV 4.0 Type Approved Level 1 (Hardware), Level 2 (Application) SC 5000 Modular Repair Benefits Cost Effective Module swap-outs are simple and do not require technical experts Labor rates are lower and repair time is quicker Training is not complicated, further lowering costs associated with high staff turnover Extensive Training Tools to Simplify Training for Secure Products CD, pictures & video contain all the information needed to deliver 'Modular Repairs" training Technicians can train themselves at their own pace SC 5000 Configuration Options, Accessories & Connectivity Options Product Configuration Options Mag-stripe reader options No MSR Track 1/2 Track 1/2/3 Secure Access Modules (SAM) 0, 2, 4 Backlight Display option Product Accessories Privacy Shield Snap-In Mounting Adapter SC 5000 Connectivity Terminal Direct Connect Terminal with external power ECR Connectivity Cabling Configurations: Terminal Direct Connect Cabling Configurations: Terminal with External Power Cabling Configurations: ECR Connectivity SC 5000 Application Environment SC 5000 Application Development Environment Software Development Toolkit (SDTK) Compiler/Debugger/Loader (from GHS) Smart Card Library Documentation & APIs Development Unit Development units could be purchased separately M SD SC 5000 Applications VeriFone architecture and approach is intended to Provide a simple but highly effective internal and external interface Maximize reusability of common components Provide a mechanism for non-VeriFone applications to leverage from a common architecture and interface methodology Minimize development costs and time to market It is the approach selected by VeriFone, it is not the only way to use SC 5000 VeriFone-Developed SC 5000 Applications SC 5000 Application Menu Manager SC 5000 PINPad 1000/2000 Emulation Application SC 5000 Generic EMV Application SC 5000 Common / Reusable Application Modules Provide specific categories of functionality Handle command specific errors General Command Library (GCL) EMV Command Library (ECL) ICC Command Library (ICL) Database Command Library (DCL) Application Command Parser Library (ACPL) User Defined Command Library (DCL) Remote Device SC 5000 AMM PPxxxx App PPEMVG App ???? App Application i/f RS232 i/f SC 5000 AMM PPxxxx App PPEMVG App SC 5000 Applications SC 5000 Application Menu Mgr Application selection menu Remote application selection command interface SC 5000 PP1000/2000 Emulation PINPad 1000/2000 remote command interface SC 5000 Generic EMV Application Remote command interface for EMV functionality EMV 4.0 Level 2 Type Approved SC 5000 Security Features: VeriShield Security Architecture SC 5000 Security Features Third Generation VeriShield Implementation Visa PED Spec Compliant VeriShield File Authentication VeriShield Hardware Security VeriShield Security Scripts VeriShield Hardware Security Tamper Detection Security fence to prevent access to sensitive components Multiple tamper/case-open detectors Voltage detector to monitor power supply Keypad with conductive carbon pills between keys In case of attack, firmware, application and keys are erased 3DES Encryption Standard 3DES Status No standard today for 3DES Session Key management VeriFone leading consortium to create specification SC DES Support Full 3DES support 3DES Master/Session 3DES DUKPT Other 3DES key management schemes VeriShield File Authentication Prevents unauthorized applications from being executed Ensures security and integrity O/S, application, data Secures all O/S upgrades for local or remote downloads Uses a hierarchy of public key certificates to protect all files loaded into SC 5000 Certificate Hierarchy Trusted Root Certificate O/S Root Cert. Sponsor Certificate Signer Certificate O/S Update File Customer Application (Credit/Debit/Loyalty) Default Certificate Embedded During Manufacturing DEFAULT DIGITAL CERTIFICATE Application Development is Simple, Uses Default Certificate DEFAULT DIGITAL CERTIFICATE Default Certificate Does Not Guard Against Rogue Applications From Being Downloaded Application downloads are still password protected DEFAULT DIGITAL CERTIFICATE SPONSORS SIGNER CERTIFICATE CAN NOT BE EXECUTED Assigning Sponsor Certificate Will Protect Against Execution of Rogue Files Additional Certificates Allow Downloading Privileges to Third Party ADDITIONAL SIGNER CERTIFICATE SPONSORS SIGNER CERTIFICATE VeriShield Security Scripts Unique, flexible security language Supports virtually any key management scheme Scripts may be written by trained application programmers Supports DES, 3DES, AES, RSA, SHA-1