EMV 3-D Secure (3DS) - Payment Authentication Protocol
Authentication flow requirements (chapter 3: app-based, out-of-band, browser-based) – EMV 3-D Secure (3DS) - Payment Authentication Protocol

EMV 3-D Secure (3DS) - Payment Authentication Protocol 3.1.S4: 3.1.S4 App: Requestor App and SDK gather AReq data (Steps 1 to 4)

The 3DS Requestor App identifies the Directory Server from the cardholder account number and invokes the 3DS SDK, over a server-authenticated TLS session with the 3DS Requestor or 3DS Server (Req 3.1), reporting to the cardholder without further processing if the 3DS Server cannot receive the data in reasonable time; the SDK obtains the device information together with the SDK reference number and the SDK app ID, generates the SDK Transaction ID that identifies the transaction in every message, sets the device rendering options supported, encrypts the device information with the DS public key and prepares the SDK-to-ACS secure channel (Req 3.2 to 3.6); the 3DS Requestor Environment assembles cardholder account, merchant risk, requestor authentication, payment or non-payment and cardholder information for the 3DS Server.

Maintained by Gerard BlokdykControl text last updated

Other controls in Authentication flow requirements (chapter 3: app-based, out-of-band, browser-based) – EMV 3-D Secure (3DS) - Payment Authentication Protocol

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.