The SDK builds a JSON device information object and encrypts it for the DS under a DS public key chosen from the requestor's configuration: with an RSA key as JWE (RSA-OAEP-256, key ID, A128CBC-HS256 or A128GCM), with an EC key by ECDH-ES on P-256 with a Concat KDF bound to the DS identifier and a fresh ephemeral key pair it then deletes; if no key can be identified processing stops with an error. The 3DS Server forwards it as SDK Encrypted Data; the DS decrypts it and places it, Base64url encoded (up to 64,000 characters), in Device Information for the ACS only. The ACS returns the Device Information Recognised Version, the newest data version it supports (values in Bulletin 255). In the browser channel the requestor and 3DS Server find the 3DS Method URL in the cached card range data, invoke the method before the AReq in a hidden iframe with the attributes Tables A.23 and A.24 set, posting the 3DS Server Transaction ID and notification URL; the ACS stores what it gathers under that ID and posts back; the 3DS Server sets the completion indicator to Y, to N after 5 seconds, or to U when there is no URL. A method run for the same card, device and browser in the last 10 minutes may be reused by sending its ID. The AReq also carries the browser elements (accept header, IP, Java and JavaScript flags, language, colour depth, screen size, time zone, user agent, and browser device and user identifiers).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.