eKrypto Web-Enabled Secure PIN Pad
eKrypto Technology for:
- Secure
v PIN Code Entry
v PIN/ Chip Verification
v Password Entry
v Access Control
v Communications
- Banking, eCommerce and Healthcare Applications
- Windows RS232 and USB Serial Plug and Play Compliant (for easy installation)
•The eKrypto Web-Enabled Secure PIN Pad is the optimum PIN entry device where security is of paramount importance. Whether for financial applications or access control this security device ensures integrity of communication between device and host. The user identity is verified by secret PIN rather than traditional signature. The PIN as with all other secret data transmitted from the device can be encrypted by the eKrypto Engine in the device controller. Therefore the data travels through the host PC/ Workstation encrypted.
•All communication between the secure PIN Pad and Host is managed within the eKrypto Controller as per the instructions of the download secure applets.
•
For each secure transaction to be performed with the PIN Pad a signed applet is downloaded to the Secure PIN Pad via the connected Host. Once the signature on the applet has been validated by the eKrypto Controller a secure or unsecured session is initiated depending on the applet. In secure mode all data from device to host travels encrypted, the security level determined by the applet. The eKrypto Controller contains three encryption engines, 3DES, SHA-1 and PKI
•
The eKrypto Web-Enabled Secure PIN Pad is intended for use as a Secure PIN Pad for applications requiring Secret PIN Code Entry. The PIN Pad with optional Smart Card Reader is EMV2000 Level 1 Approved (Approval no. 11680 1003 400 20 CET)
•
The eKrypto Web-Enabled Secure PIN Pad has a 2 x 16 character LCD and an integrated privacy shield. The LCD will serve to prompt the user to enter a PIN or perform other actions. J/XFS and XFS Middleware drivers and EMV2000 Level 2 Kernel available on request.
Technology Benefits
Security
v 3 x Crypto Engines
v PKI Enabled
v 3DES Enabled
v Secure Remote Key Loading
v Tamper Resistant Housing
v Privacy Shield
Features
v RS232 or USB Serial Host Interface
v PIN Pad Application for secure PIN Entry as per ANSI X9.24
v MACing ( Message Authentication Code) as per ANSI X9.19
v Web Enabled
v 16 Key PIN Pad
v Size: 174 (L) x 88 (W) x 54 (H) mm
v 16 x 2 LCD Display with Backlight
v Single Color Charcoal Black Housing
Option
v Secure Desk Mounting Bracket (**)
v Magnetic Swipe Reader (MSR) available in single or dual track version (*)
v Smart Card Reader Application Modules for EMV ? PC/SC (**)
v 5 volt DC external power supply if PC power is not available on serial host connector (**)
v Smart Card Reader Hardware Platform (5000,000 reader inserts) (*)
v Colored Housing (*)
v Client Logo Printing (*)
v Alternative Keypad legend layout and colors (*)
v Alternative Keypad technology can be discussed if additional vandal proofing is a requirement (*)
* Factory Installed Option
** Client Enabled Option
eKrypto Secure Cryptographic Keyboard
eKrypto Secure
v Chip and PIN Verification
v PIN Code Entry
v Password Entry
v Access Control
v Communications
v Biometric Verification (Optional)
eKrypto Security Benefits
v PED Compliant Device
v Tamper Evident Secure Housing
v EMV2000 Level 1 + 2 Approved Smart Card Reader
v Magnetic Card Reader
v Secure PKI + 3DES Key storage
v Web Enabled
v Remotely Programmable
v 3 Encryption Accelerators
v USB 2.0 Compliant
v
Option
v Biometric Fingerprint Reader
v USB Downstream Port
v Second Secure PC/SC EMV Smart Card Reader for Secure Logon/Transactions
v J/XFS and XFS Middle Drivers Available on Request
•
The eKrypto Secure PED Compliant Cryptographic Keyboard is an Intelligent Cryptographic Keyboard for applications requiring the combination of Online/ Offline PIN verification, Secure Logon and Digital Signing. The eKrypto Secure Cryptographic Keyboard (SCKB) is designed to meet the VISA PED Standard for Offline and Online PIN verification, Secure PIN Entry, processing and tamper evidence security device ensures integrity of communication between device and host. The user identity is verified by Secret PIN (or Finger optional) rather than traditional signature, requiring the user to be in possession of a physical card and knowledge of the secret PIN number. The PIN as with all other secret data transmitted from the device is encrypted by the eKrypto Engine in the device controller ensuring data leaves the Keyboard encrypted.
•
For each secure transaction to be performed with the keyboard a signed applet is downloaded to the Keyboard via the connected host. Once the signature on the applet is validated by the eKrypto Controller a secure session is initiated depending on the applet instruction.
•
In secure mode all data from device to host travels encrypted, the security level determined by the applet. The eKrypto Controller contains three encryption engines, 3DES, SHA-1, and PKI.
•
The Secure Applet approach allows the e Krypto SCKB to support up to 18 applications as it is not limited to available SAM slots. It also leads to significant maintenance savings as application changes only require an applet revision. The Keyboard is also remotely programmable and supports secure remote key loading for greater security plus maintenance convenience and savings.
Product Applications
•
The eKrypto Web-Enabled Secure Cryptographic Keyboard intended for use as:
•
A PED Keyboard for secure Chip and Transactions. The Keyboard can perform both Secure Offline and Online PIN Verification. Integrated Smart Card Reader Accompanied by Magnetic Card Reader for ease of migration.
•
An Intelligent Cryptographic Keyboard for applications requiring the combination of client ID with Smart Card Reader and PIN Code where access and usage require knowledge and the possession of both PIN/ Password and Smart Card. Fingerprint Swipe reader option available for enhance Biometric Security.
•
The e Krypto Web-Enabled Secure Cryptographic Keyboard has an integrated ISO 7816 and EMV2000 (4.0) Approved Smart Card Reader, Magnetic Card Reader and a 2 x 16 character LCD. The LCD will serve to prompt the user to enter PIN or perform other actions. Options include Biometric Fingerprint Swipe Reader, 2nd PC/SC EMV Smart Card Reader and external USB 2.0 Full Speed Downstream Port for connecting additional USB device such as PIN Pad, Receipt Printer or mouse. XFS and J/XFS Middleware drivers and EMV2000 Level 2 Kernel available on request.
Technology Benefits
Security
v 3 x Crypto Accelerators
v 2048, 1024, 512 bits
v <55ms for a 1024 bits verify
v PKI and 3DES Enabled
v Tamper Evident Housing
v
Features
v USB 2.0 Bus powered high speed end-point smart card keyboard
v Downwards compatible with standard USB PC keyboard.
v OIN Entry / Offline PIN Verification with inserted Smart Card
v Web-Enabled
v PSCS compliant Smart Card Reader (400,000 reader inserts)
v Smart Card Reader application Modules for PC/SC EMV
v Magnetic Card Reader (2Track)
v Full Win XP and Office XP keyboard
v 16 x 2 LCD Display with Backlight
v Keystroke life 10 million cycles
v Programmable Hot Keys
v Windows 2000 / XP OS supported.
Optional Features
v Windows Logon Software + User Cards
v Keyboard preloaded operator ?PKI Key + Certificate
v Fingerprint Swipe Reader for Biometric Verification
v Second Smart Card Reader
v Downstream USB 2.0 Full Speed Port for connecting additional USB device.
eKrypto Web-Enabled Smart Card PIN Pad
eKrypto Technology for:
- EMV Transaction
- Web-Enabled Devises
- Secure
v Chip and PIN Verification
v PIN Code Entry
v Password Entry
v Access Control
v Communications
- Banking, eCommerse and Healthcare Applications
- Windows RS232 and USB Serial Plug and Play Compliant ( for easy installation)
•
The eKrypto Web-Enabled Smart Card PIN Pad is the optimum EMV PIN entry device for both Offline and Online Chip and PIN Transactions. Whether for financial application or access control this security device ensures integrity of communication between device and host. The user identity is verified by Secret Pin rather than traditional signature, requiring the user to be in the possession of a physical card and knowledge of a secret PIN number. The PIN as with all other secret data transmitted from the device can be encrypted by the eKrypto Engine in the device Controller. Therefore the data travels through the Host PC/Workstation encrypted. The eKrypto Engine also negates the requirement for costly cryptographic smart cards as all encryption is performed in the engine.
•
For each secure transaction to be performed with the PIN Pad a signed applet is downloaded to the Smart Card PIN Pad via the connected Host. Once the signature on the applet has been validated by the eKrypto Controller a secure session is initiated depending on the applet instruction and the resultant security status will be indicated by the LED. In secure mode all data from device to host travels encrypted, the security level determined by the applet.
•
The eKrypto Controller contains three encryption engines, 3DES, SHA-1 and PKI and supports secure remote key loading.
•
The eKrypto Web-Enabled Smart Card PIN Pad is intended for use as:
v An EMV Smart Card PIN Pad for Secure Chip and PIN Transactions. The PIN Pad can perform secure Offline and Online PIN Verification.
v An Intelligent Cryptographic PIN Pad for applications requiring the combination of client ID with Smart Card Reader (SCR) b/ PIN Code where access and usage require knowledge and the possession of both password and smart card.
•
The eKrypto Web-Enabled Smart Card PIN Pad has an integrated ISO 7816 and EMV2000 Level 1 Approved (Approval No. 11680 1003 400 20 CET) Smart Card Reader (SCR) , a 2 x 16 character LCD, a privacy shield and a LED to indicate secure mode. The LCD will serve to prompt the user to enter PIN or perform other actions. J/XFS and XFS middleware drivers and EMV2000 Level 2 Kernel Available on request.
Technology Benefits
Security
v 3 x Crypto Engines
v PKI Enabled
v 3DES Enabled
v Secure Remote Key Loading
v Tamper Evident Housing
v Secure Mode Indicator
v Privacy Shield
v EMV2000 Level 1 approved
Features
v RS232 or USB Serial Host Interface
v PIN Entry / PIN Verification with inserted Smart Card
v Web enabled
v Smart Card Reader (500,000 reader inserts)
v Smart Card Reader application modules for EMV- PC/Sc
v 16 Key PIN Pad
v Size: 174 (L) x 88 (W) x 54 (H) mm
v 16 x 2 LCD Display with Backlight
v Single Color Charcoal Black Housing
Options
v Secure Desk Mounting Bracket (**)
v MSR available in single or dual track version (*)
v 5 volt DC external supply if PC power is not available on serial host connector(**)
v Colored Housing (*)
v Client Logo Printing (*)
v Alternative Keypad Technology can be discussed where vandal proofing is a requirement (*)
(*) Factory Installed Option
(**) Client Enabled Option
eKrypto Secure Device Communication (SDC)
Software Suite
•
The eKrypto Secure Device Communication (SDC) is a complete software suite providing all of the elements necessary for managing secure networked I/O device communication.
eKrypto SDC Control
v Software Drivers
v Secure Key Management
v Smartlets
v Remote Maintenance and Programmability
v J/XFS and XFS Middleware Device Services
v EMV Level 2 Kernel
v Communications Port management
v SDC VIRCOM ? Migration of Legacy Systems
eKrypto SDC Software Drivers
•
The eKrypto SDC contains the software drivers and smartlets required for eKrypto Chip functionality along with the functionality of all I/O devices RS232m Serial or USB that may be controlled by the eKrypto Chip. Such devices may for example include integrated Smart Card Reader/s, Magnetic Card Reader, Scanner, LCd Display, Fingerprint Swipe Reader, Signature Pad, Receipt Printer or Bar Code Scanner. All the devices firmware to ensure ease of maintenance, optimum security and future proofing.
eKrypto SDC Secure Key Management
•
Each eKrypto Chip is loaded with a factory PKI certificate, allowing secure remote initial 3DES key load and secure distribution of firmware upgrades. Extension of these services can be provided for customers if required. The eKrypto Chip contain three encryption engines, 3DES, SHA-1 and PKI plus a True Random Number Generator.
eKrypto SDC Smartlets
•
eKrypto device controllers are loaded with a assigned smartlet that dictates the device functionality. A secure transaction is only initiated on receipt and verification of a signed, trusted smartlet by the eKrypto device via the connected Host. An individual eKrypto device can support in excess of 18 applications as it is not limited to available SAM slots.
eKrypto SDC Remote Maintenance and Programmability
•
Application and firmware changes only a require smartlet revision plus each device is remotely programmable and supports secure remote key loading for greater security, maintenance, convenience and cost savings. The upgrade process steps are (1) revision of smartlet (2) replacing the old smartlet file with the revised version on host server (3) automatic download of the new smartlet during next boot operation. A secure operation is only initiated on receipt and verification of a signed, trusted smartlet by the eKrypto device via the connected Host negating the threat of rogue updates.
eKrypto SDC J/XFS and XFS Middleware Device Services
•
The eKrypto SDC can include J/XFS or XFS Middleware Device Services where a JAVA or Windows middleware platform is being deployed. Device Services for non eKrypto devices can be created for clients on request.
eKrypto SDC EMV2000 (4.0) Level 2 Kernel
•
The eKrypto SDC can include the optional EMV200 (4.0) Level 2 Approved Kernel When required by customers seeking a fully EMV compliant solution with EMV2000 (4.0) Level 2 Approved Keyboards and/or PIN Pads. An EMV L2 approved development application can also be provided to assist customer development of EMV compliant applications.
eKrypto SDC Communications Port Management
•
Coupled with the eKrypto Chip the eKrypto Secure Device Communication Software Suite can provide the engine for both USB and RS232 Serial Port connectivity through providing and managing the USB ports necessary for integrating peripherals such as PIN Pads and Receipt Printers. Where necessary the SDC can create virtual RS232 Serial and USB ports for multiple integrated and connected device deployment where limited physical ports are available. The eKrypto SDC VIRCOM Solution (see below for more detail) enabled organizations with non USB legacy applications but USB workstations to deploy eKrypto USB devises via the USB port but communicating in RS232 Serial form. When the organization eventually migrates the legacy application to USb, these devises can switch to full speed plug and play USB communication by simply issuing a revised signed smartlet instruction remotely from the Host server.
eKrypto SDC VIRCOM ? Migation of Legacy Systems
•
The SDC VIRCOM software enables the eKrypto keyboard and/or PIN Pad to work with legacy serial applications over its USB Infrastructure, therefore in the future when an organization migrates its application to USB the device will continue to work seamlessly, only requiring a remote instruction to turn off the VIRCOM function in the SDC software. This technology combined with the best of breed components and full remote programmability contributes to a product life expectancy of 12 to 15 years.
•
Using the USB based host interface architecture; the SDC VIRCOM driver includes a true virtual communications port for each RS232 serial device. The banking application contentious to use the COM ports architecture in the driver for the individual RS232 serial devises interface (maintain actual device interface protocol). There is no application change required for this interface. Only the communications port name changes from the physical port (e.g. comm2) to the Virtual communications port (e.g. comm4).
eKrypto SDC VIRCOM Benefits:
v Huge Savings on Migration Cost and Time.
v Devices can be migrated at Clients Convenience.
v Software Update Switches Device to Pure USB Mode.
v No need for immediate revision of reliable legacy no USB platform.
eKrypto Web-Enabled PCI PIN Pad
Ekrypto Technology for:
- Secure
v PCI Chip and PIN Verification
v PIN Code Entry
v Access Control
v Tamper Responsive
v Biometric Responsive
- Web-Enabled Devices
- Banking and eCommerce Applications
- Windows RS232 and USB Serial Plug and Play compliant (for easy installation)
- Optional Fingerprint Swipe Reader
•
The eKrypto Web-Enabled PCI PIN Pad with hybrid 3 Track MCR/SCR reader is designed to meet the very latest VISA/ Mastercard/ JCB PCI POS PED Standard for both Offline and Online PIN verification, Secure PIN Entry, privacy shield and tamper responsive requirements. Whether for financial applications or access control security device ensures integrity of communication between host and device. The user identity is verified by Secret PIN (or fingerprint optional) rather traditional signature, requiring the user to be in possession of a physical card and knowledge of the secret PIN number. The PIN as with all other secret data transmitted from the device is encrypted by the eKrypto Engine in the device controller ensuring data leaves the PIN Pad encrypted.
•
For each secure transaction to be performed with the PIN Pad a signed smartlet is downloaded to the eKrypto PIN Pad via the connected Host. Once the signature on the smartlet has been validated by the eKrypto Controller a secure session is initiated depending on the smartlet instruction and the resultant security status will be indicated by the LED. In secure mode all data from the device to host travels encrypted, the security level determined by the smartlet. The eKrypto Controller contains three encryption engines, 3DES, SHA-1, and PKI.
•
The Secure Smartlet approach allows the eKrypto PIN Pad to support more than 18 applications as it is not limited to available Sam slots. It also leads to significant maintenance savings as application changes only require a smartlet revision. The PCI PIN Pad is also remotely programmable and supports secure remote key loading for greater security plus maintenance convenience and savings.
The eKrypto Web-Enabled PCI PIN Pad is intended for use as:
v The PCI POS PED PIN Pad for Secure Chip and PIN Transactions. The PIN Pad can perform secure Offline and Online PIN Verification. Integrated Smart and Magnetic Card Readers for ease of migration.
v An intelligent Cryptographic PIN Pad for applications requiring the combination of Client ID with Smart Card Reader (SCR) / PIN Code where access and usage require knowledge and the possession of both password and Smart Card.
•
The eKrypto Web-Enabled PCI PIN Pad has an integrated combined hybrid ISO 7816 and EMV2000 approved Smart Card Reader (SCR) and 3 Track Magnetic Card Reader (MCR), a 4 x 16 Character Graphic Backlit LCD, a Privacy Shield and a LED to indicated Smart Card entered. The LCD will serve to prompt the user to enter PIN or perform other actions. Fingerprint Swipe Reader for biometric identification and RS232 Serial Upstream Port for connecting receipt printer or equivalent device are optional extras. J/XFS and XFS Middleware drivers and EMV2000 Level 2 Kernel available on request.
Technology Benefits
Security
v 3 x Crypto Engines
v PKI Enabled
v Secure Key Loading
v Tamper Responsive Housing
v Secure Mode Indicator
v Privacy Shield
v PCI POS PED Compliant
v Biometric Fingerprint Option
Features
v RS232 or USB Serial Host Interface
v Chip and PIN Verification with inserted Smart Card
v Smart Card Reader (500,000 reader inserts)
v Smart Card Reader Application Modules for PC/ SC EMV and ISO
v Magnetic Card Reader 3 Track
v 16 Key PIN Pad
v Size: 210 (L) x 103 (W) x 83 (H) mm
v 4 x 16 Graphic LCD Display with Backlight
v Single Colour Charcoal Black Housing
Options
v Secure Desk Mounting Bracket (**)
v 5 volt DC external power supply if PC power is not available on serial host connector (**)
v Colored Housing (*)
v Client Logo Printing (*)
v RS232 Serial Upstream Port (*)
v Fingerprint Swipe Reader for Biometric Identification (*)
* Factory Installed Option
** Client Enabled Option