EMV 3-D Secure (3DS) - Payment Authentication Protocol
Versions 2.2 and 2.3.1: features added after v2.0.0 – EMV 3-D Secure (3DS) - Payment Authentication Protocol

EMV 3-D Secure (3DS) - Payment Authentication Protocol V.17: V.17 Split-SDK and SDK type

The AReq's SDK Type says whether a default SDK (01) or a Split-SDK (02) is used. A default SDK describes itself in the Default SDK Type (variant 01 native, and a wrapped flag when it is embedded as a wrapped component); a Split-SDK in the Split-SDK Type (variant 01 native client, 02 browser, 03 shell, and a limited flag when the client has limited capabilities). With a limited Split-SDK the authentication methods 01 static password and 06 knowledge-based are invalid, a browser Split-SDK sets the OOB App URL Indicator to 02, and an ACS rejects with Error Code 310 any Split-SDK CReq not protected with A128GCM. The Split-SDK Server holds a key pair whose X.509 certificate is signed by a DS certificate authority and signs, as a JWS (PS256 or ES256, certificate chain in the header without the DS CA's own certificate), four values: the Split-SDK Server ID the DS assigned (up to 32 characters), the SDK Transaction ID, the SDK reference number and the time of signing; the result travels in the AReq as SDK Server Signed Content. The DS validates it with the DS CA public key and stops with an error if it fails; a signature timestamp more than 30 minutes off UTC draws Error Code 203.

Maintained by Gerard BlokdykControl text last updated

Other controls in Versions 2.2 and 2.3.1: features added after v2.0.0 – EMV 3-D Secure (3DS) - Payment Authentication Protocol

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.