Remote Key Injection Datasheet

Remote Key Injection
Inject Keys Anytime, Anywhere
The Equinox Remote Key Injection (RKI) platform was the first
system of its kind in the industry and continues to be the
benchmark for standards-based remote key transactions. RKI
eliminates completely the need for a secure room or special
security procedures by utilizing a proprietary public key
infrastructure (PKI) that allows symmetric debit PIN and data
encryption keys to be safely and securely distributed anywhere a
POS terminal is located—whether in-lane or in a terminal staging
area. In addition, Equinox RKI gives customers the added
convenience of being able to inject multiple keys in a single
session and increased flexibility when rotating or adding
processor and encryption keys.
+
The Equinox Remote Key Injection platform allows for the deployment of keys at anytime and from
anywhere. As the following examples show, an Ethernet or Dial connection from the Equinox
terminal is all that is required for a safe and secure key injection from outside a secure facility.
+
The Equinox Remote Key Injection platform offers multiple configuration options that can
accommodate even the most robust POS environments. Whether integrated directly into the POS
platform or not, RKI creates a completely safe and secure way for retailers to load or update keys.
What’s more, our customers enjoy the added convenience of
being able to set up and manage key injection from anywhere
and at anytime via the Equinox RKI web portal.
Cost-Effective and Secure
Since its introduction, Equinox—an accredited Encryption
Services Organization (ESO)—has successfully delivered over
one million remote key injections to Equinox payment terminals
in live retail environments. From the outset, Equinox RKI has
provided retailers and distributors alike with a safe and secure
means to deploy and update keys—all while reaping these
significant cost-saving benefits:
• RKI eliminates the costs and time needed to set up and
maintain secure injection facilities. For distributors, this means
they can save money, reduce risk and create revenue streams—
all without having to incur a substantial financial investment.
• RKI eliminates the need to ship terminals to third-party
secure facilities for key injections.
• RKI eliminates the administrative costs and overhead
associated with the key management process.
• RKI eliminates the costs of physically rotating deployed
terminals to update or rotate keys.
[email protected] | EQUINOXPAYMENTS.COM
© Copyright 2013-2014 Equinox Payments. All Rights Reserved.
Remote Key Injection
Hardware | Software FAQ
What Equinox terminals will work with the Remote Key
Injection platform?
Remote Key Injection platform will work on any of the
following terminals:
+ Legacy Equinox T4205, T4210, T4220, T4230,
M4220 and M4230 terminals (all require key loading
application)
+ Legacy Equinox L4150
+ Equinox L5200 and L5300 terminals
+ Equinox Apollo CFD and AiO
Operational FAQ
What terminal connection types can be used with the
Remote Key Injection platform?
For legacy T4200/M4200 family products:
+ Ethernet, Dial or GPRS (M4230)
For Equinox L5200 and L5300 terminals:
+ Directly via Ethernet
+ Indirectly via an RS232 or USB connection through
an ECR or PC
For the Equinox Apollo platform:
+ Via Ethernet or Dial
If I already have a debit key in my terminal, can I use
the Remote Key Injection platform to add new or
additional keys (e.g., debit keys, EBT, or E2E keys)?
Yes, any type of symmetric key can be injected.
How do I send keys to Equinox to be injected via the
Remote Key Injection platform?
Contact your processor and let them know you would
like Equinox to host your key for remote key injection.
Equinox key management team can be contacted by
sending an email to:
[email protected].
Is it necessary to provide Equinox with the serial
numbers for my terminals prior to beginning the
injection process?
Yes. Customers can upload terminal serial numbers at
anytime through the Equinox Remote Key System web
portal at https://rks.equinoxpayments.com.
Can I inject multiple keys into a terminal during the
same remote key injection session?
Absolutely.
Security FAQ
Is Remote Key Injection as safe as traditional
symmetric key injection?
The Equinox Remote Key Injection platform is actually
safer than traditional methods of symmetric key
injection because RKI encrypts the key from our secure
facilities to your terminal, never allowing key data to be
“in the clear.”
Is the Equinox Remote Key Injection platform
compliant with any security standards?
Equinox is an Encryption Service Organization (ESO)
and our RKI service is compliant with the following
security standards:
+ X509 for PKI
+ PCI PIN Security Requirements Version 1.0,
Normative Annex A
+ PCI DSS for system security
+ X9.24 Part 1 for storing/transmitting symmetric keys
+ X9.24 Part 2 for transmitting keys and establishing
secure communications
+ TR-39/TG-3 guidelines for audit controls, user
authentication and key entry/management
processes
+ FIPS 140-2 Lever 3 for HSM physical security
9045 E PIMA CENTER PKWAY, SUITE 3, SCOTTSDALE, AZ 85258. P| 877 497 3726 F| 480 551 7811
[email protected] | EQUINOXPAYMENTS.COM
Sales | Service FAQ
How long does it take to set up an account to use the
Equinox RKI platform?
When Equinox receives possession of your keys, your
account can be set up in 2-3 business days (during
normal business hours). Once your account is set up,
the Equinox Remote Key System web portal is available
24/7 for your convenience.
Who do I contact in the unlikely event that I incur a
problem during the remote key injection process?
Contact your Equinox representative via the Equinox
Remote Key System web portal at:
https://rks.equinoxpayments.com.
If I choose to purchase this service, will I pay per
injection?
Yes.
Is there fee to set-up my keys?
No.
© Copyright 2013-2014 Equinox Payments. All Rights Reserved. Equinox Payments and the Equinox Payments logo are registered
trademarks of Equinox Payments. All other products or services or mentioned in this document are trademarks, service marks, registered
trademarks or registered service marks of their respective owners. Product specifications subject to change without notice.