EMV 3-D Secure (3DS) - Payment Authentication Protocol
Message handling requirements (chapter 5) – EMV 3-D Secure (3DS) - Payment Authentication Protocol

EMV 3-D Secure (3DS) - Payment Authentication Protocol 5.8.2: 5.8.2 Browser challenge window (Req 5.81 to 5.86)

The 3DS Requestor selects the iframe size from the Challenge Window Size values (Req 5.81), uses a server-authenticated TLS session to the ACS (Req 5.82), creates the challenge window by building the CReq, creating the iframe and posting through it to the ACS URL from the ARes (Req 5.83), with the chosen window size in the CReq (Req 5.84); the ACS answers the CReq with the code that renders the challenge in the iframe, possibly over several interactions (Req 5.85), and after the RReq/RRes exchange posts the final CRes to the notification URL; the 3DS Requestor then closes the challenge window by reloading the parent page and taking out the iframe (Req 5.86).

Maintained by Gerard BlokdykControl text last updated

Other controls in Message handling requirements (chapter 5) – EMV 3-D Secure (3DS) - Payment Authentication Protocol

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.