Security
In order to make sure sensitive cardholder data is protected in a secure way, the payment terminal partners need to adhere to the following specifications.
Cardholder Data
The cardholder data needs to be protected at all times. The payment terminal will perform the encryption of the cardholder data using a Derived unique key per transaction (DUKPT). Personalization of the payment terminals and loading the security keys MUST be done under secure conditions as prescribed by PCI standards.
PIN BLOCK
When a cardholder enters the PIN on any PIN entry device [POS, ATM, etc.] the PIN will be encrypted and stored in the PIN BLOCK 5FE311 tag of the Authorization request. The payment terminal must use ISO format-0 to create the encrypted PIN block.
Client-to-Host Communication
The client-to-host communication is encrypted using an up-to-date version of TLS. Trust is provided both ways so a client and server x.509 certificate is used.
Extra details about the usage of keys and certificates will be provided during onboarding.