EMV 3-D Secure (3DS) - Payment Authentication Protocol
Versions 2.2 and 2.3.1: features added after v2.0.0 – EMV 3-D Secure (3DS) - Payment Authentication Protocol

EMV 3-D Secure (3DS) - Payment Authentication Protocol V.19: V.19 Operation messages (OReq and ORes)

Version 2.3 adds Operation messages through which a DS sends operational information to a 3DS Server or ACS, on its own or tied to a transaction: for example response time and performance reports, flags on fraudulent ecosystem participants, key and certificate rotation notices and compromised device information. A DS using them sends the OReq, or a numbered series of OReqs in order, over a secure link to the recipient; after a failed TCP/IP connection or TLS handshake it retries at once, and after a second failure it ends the attempt and retries every 60 seconds for up to 24 hours. The recipient validates every OReq (Error Code 203 for an invalid element, 201 for a missing one, with component S or A) and answers once, after the whole series, with an ORes carrying the operation status (01 received, 02 series interrupted, 03 requested action not supported or not taken); the DS validates the ORes the same way. Operation messages are not part of the authentication flow.

Maintained by Gerard BlokdykControl text last updated

Other controls in Versions 2.2 and 2.3.1: features added after v2.0.0 – EMV 3-D Secure (3DS) - Payment Authentication Protocol

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.