Device binding ties the cardholder's device to the card account, the cardholder, or both. An ACS that supports it signals ACS Information Indicator 05; the requestor may ask for a binding prompt if a challenge occurs (Challenge Indicator 12). In the app channel the ACS may show Device Binding Information Text (up to 64 characters) whose control starts off, and the SDK returns the cardholder's consent (Y or N) in the Device Binding Data Entry. Device Binding Status travels in the AReq, ARes and RReq with its source (3DS Server, DS or ACS): 01 not bound, 02 not eligible, 03 awaiting confirmation, 04 rejected, 05 unknown, and for bound devices the kind of binding: 11 hardware or SIM inside the device (for example keys in a secure element), 12 hardware outside it (for example an external FIDO authenticator), 13 data including dynamically generated data, 14 static device data, 15 another method. A 3RI request with indicator 13 checks the status.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.