EMV 3-D Secure (3DS) - Payment Authentication Protocol
Security requirements: links and functions (chapter 6) – EMV 3-D Secure (3DS) - Payment Authentication Protocol

EMV 3-D Secure (3DS) - Payment Authentication Protocol 6.2.3-4: 6.2.3-4 Functions J and K: SDK to ACS secure channel and protected challenge messages

For an app challenge the SDK prepares an ephemeral ECC key pair (Annex C), the ACS generates its own ephemeral key and returns it with the ACS URL in signed content (JWS) that the SDK verifies with the DS public key, both derive session keys from the ephemeral pair, and every CReq and CRes is a JWE object encrypted and integrity-protected with those keys, the SDK and ACS each encrypting what they send and decrypting and verifying what they receive.

Maintained by Gerard BlokdykControl text last updated

Other controls in Security requirements: links and functions (chapter 6) – EMV 3-D Secure (3DS) - Payment Authentication Protocol

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.