For an app challenge the SDK prepares an ephemeral ECC key pair (Annex C), the ACS generates its own ephemeral key and returns it with the ACS URL in signed content (JWS) that the SDK verifies with the DS public key, both derive session keys from the ephemeral pair, and every CReq and CRes is a JWE object encrypted and integrity-protected with those keys, the SDK and ACS each encrypting what they send and decrypting and verifying what they receive.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.