EMV 3-D Secure (3DS) - Payment Authentication Protocol
Security requirements: links and functions (chapter 6) – EMV 3-D Secure (3DS) - Payment Authentication Protocol

EMV 3-D Secure (3DS) - Payment Authentication Protocol 6.1.4: 6.1.4 Link d: SDK or browser to ACS for the challenge

The direct link to the ACS is established only when a challenge is required: in the app channel the SDK connects to the ACS URL from the ARes over TLS with server authentication of the ACS under a commercial CA certificate, and the challenge and response data are encrypted and MACed with the session keys established between ACS and SDK; in the browser channel the browser connects from the iframe to the ACS URL over TLS with server authentication under a commercial CA certificate.

Maintained by Gerard BlokdykControl text last updated

Other controls in Security requirements: links and functions (chapter 6) – EMV 3-D Secure (3DS) - Payment Authentication Protocol

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.