EMV 3-D Secure (3DS) - Payment Authentication Protocol
Authentication flow requirements (chapter 3: app-based, out-of-band, browser-based) – EMV 3-D Secure (3DS) - Payment Authentication Protocol

EMV 3-D Secure (3DS) - Payment Authentication Protocol 3.1.S10-11: 3.1.S10-11 App: SDK completes the secure channel and sends the first CReq (Steps 10 and 11)

The 3DS Requestor App passes the ARes data to the SDK and invokes the doChallenge method; the SDK checks the received data elements against Table A.1, completes the ACS-to-SDK secure channel (verifying the JWS-signed ephemeral key and ACS URL, ending with an error report to the app if it cannot), establishes the TLS link to the ACS at the verified URL, formats the CReq per Table B.3 protected as JWE and sends it.

Maintained by Gerard BlokdykControl text last updated

Other controls in Authentication flow requirements (chapter 3: app-based, out-of-band, browser-based) – EMV 3-D Secure (3DS) - Payment Authentication Protocol

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.