The DS validates the AReq, generates the DS Transaction ID, moves the decrypted SDK device data into the AReq's device information for the ACS, rejects unsupported message versions (status U, IReq 06), rejects non-participating 3DS Servers, SDKs, acquirer BINs, merchant IDs not related to the BIN (IReq 50) and invalid merchant category codes (IReq 59), determines whether the account number is in a participating range and which ACS serves it, stores the 3DS Server URL for the results leg, establishes the mutually authenticated link with the ACS and forwards the AReq, answering with the DS's own status or IReq 98 on failure.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.