EMV 3-D Secure (3DS) - Payment Authentication Protocol
Versions 2.2 and 2.3.1: features added after v2.0.0 – EMV 3-D Secure (3DS) - Payment Authentication Protocol

EMV 3-D Secure (3DS) - Payment Authentication Protocol V.7: V.7 3DS Requestor authentication information and delegated authentication data

The requestor may tell the ACS how the cardholder authenticated to it, as a list of objects: the method (01 guest checkout, 02 the requestor's own credentials, 03 federated ID, 04 issuer credentials, 05 third-party authentication, 06 FIDO authenticator, 07 FIDO authenticator with signed assertion or attestation, 08 SRC assurance data, 09 SPC, 10 electronic ID), its UTC timestamp and supporting data of up to 50,000 characters (for 06 and 07 the FIDO assertion or attestation, formatted as EMVCo's white paper on FIDO data in 3DS messages describes; for 08 the SRC assurance data; for 09 the object the SPC API returns). Where the DS verifies the signature on such data it records the outcome in the DS Authentication Information Verification Indicator (01 when the signature checked out, 02 when it did not, 03 when no check was made) before passing the message to the ACS. The ACS weighs this with the other risk data; the requestor risk elements (cardholder account, merchant risk indicator, prior authentication, multi-transaction and seller information) are optional but make risk-based authentication more accurate, and the Address Match Indicator states whether shipping and billing addresses match.

Maintained by Gerard BlokdykControl text last updated

Other controls in Versions 2.2 and 2.3.1: features added after v2.0.0 – EMV 3-D Secure (3DS) - Payment Authentication Protocol

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.