EMV® 3-D Secure Approval – Test Requirements for DS as System Under Test
EMV® 3-D Secure Approval Test Requirements for DS as System Under Test Version 2.14 11 Oct 2024
countries.
EMV® 3-D Secure Approval Test Requirements for DS as System Under Test v2.14
Legal Notice
This document summarizes EMVCo’s present plans for evaluation services and related policies and is subject to change by EMVCo at any time. This document does not create any binding obligations upon EMVCo or any third party regarding the subject matter of this document, which obligations will exist, if at all, only to the extent set forth in separate written agreements executed by EMVCo or such third parties. In the absence of such a written agreement, no product provider, test laboratory or any other third party should rely on this document, and EMVCo shall not be liable for any such reliance. No product provider, test laboratory or other third party may refer to a product, service or facility as EMVCo approved, in form or in substance, nor otherwise state or imply that EMVCo (or any agent of EMVCo) has in whole or part approved a product provider, test laboratory or other third party or its products, services, or facilities, except to the extent and subject to the terms, conditions and restrictions expressly set forth in a written agreement with EMVCo, or in an approval letter, compliance certificate or similar document issued by EMVCo. All other references to EMVCo approval are strictly prohibited by EMVCo. Under no circumstances should EMVCo approvals, when granted, be construed to imply any endorsement or warranty regarding the security, functionality, quality, or performance of any particular product or service, and no party shall state or imply anything to the contrary. EMVCo specifically disclaims any and all representations and warranties with respect to products that have received evaluations or approvals, and to the evaluation process generally, including, without limitation, any implied warranties of merchantability, fitness for purpose or noninfringement. All warranties, rights and remedies relating to products and services that have undergone evaluation by EMVCo are provided solely by the parties selling or otherwise providing such products or services, and not by EMVCo, and EMVCo will have no liability whatsoever in connection with such products and services. This document is provided "AS IS" without warranties of any kind, and EMVCo neither assumes nor accepts any liability for any errors or omissions contained in this document. EMVCO DISCLAIMS ALL REPRESENTATIONS AND WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NONINFRINGEMENT, AS TO THIS DOCUMENT. EMVCo makes no representations or warranties with respect to intellectual property rights of any third parties in or in relation to this document. EMVCo undertakes no responsibility to determine whether any implementation of this document may violate, infringe, or otherwise exercise the patent, copyright, trademark, trade secret, know-how, or other intellectual property rights of third parties, and thus any person who implements any part of this document should consult an intellectual property attorney before any such implementation. Without limiting the foregoing, this document may provide for the use of public key encryption and other technology, which may be the subject matter of patents in several countries. Any party seeking to implement this document is solely responsible for determining whether its activities require a license to any such technology, including for patents on public key encryption technology. EMVCo shall not be liable under any theory for any party's infringement of any intellectual property rights in connection with this document.
countries.
EMV® 3-D Secure Approval Test Requirements for DS as System Under Test v2.14
Version 1.0 1.1 1.2 1.3 1.4 1.5 2.0 2.1 2.2 2.3 2.4 2.5 2.6 Date 05 Mar 2020 20 Mar 2020 24 Apr 2020 17 Jun 2020 27 Jul 2020 11 Dec 2020 29 Jan 2021 14 May 2021 11 Feb 2022 14 Mar 2022 22 Jul 2022 23 Sep 2022 28 Oct 2022 Revision Log
Description
Initial version Clarification about endpoint connections. Editorial changes. Change about Operator ID management. Clarification about DS Public keys and certificates New section added: 3.1.5. 3DS Requestor Name and ID New section added: 3.1.6. Disable the “sent message limit exceeded” check P3DS_TP-127: New requirement about 3DS Requestor ID see section 3.1.7 [TEST_REQ_ALL_SUT] version have been upgraded to 2.0 P3DS_MP-11: Clarification in section “3.1.2 Configurable fields” Updated section 3.1.1, a new timeout is precised. P3DS_MP-37: CLONE of P3DS_TP-159: Clarification in section 3.1.2 about configurable values “authenticationValue” P3DS_IM-18: DS Configuration Improvement and Enhancement:
- the presence of the field 'broadInfo' is now configurable for 2.1/2.2 (not for 2.3 and later). See details in section “3.1.2. Configurable fields” DS Configuration: the following new fields in 2.3 shall be configurable for DS according to latest [3DS_Core_2.3.1]:
- taxId
- cardSecurityCode
- avValidityTime (in Multi-Transaction)
- avNumberUse (in Multi-Transaction) See details in section “3.1.2. Configurable fields” New section added:
3.1.8 Card Range Data File URL Update version for [TEST_REQ_ALL_SUT] referenced document DS Configuration: the following new fields shall be configurable for DS according to latest [3DS_Core_2.3.1]:
- cardSecurityCodeStatus (see detail in section 3.1.2. Configurable fields” countries. EMV® 3-D Secure Approval Test Requirements for DS as System Under Test v2.14 Page v Version 2.7 2.8 2.9 2.10 2.11 2.12 2.13 2.14 Date 25 Nov 2022 14 Dec 2022 30 Jun 2023 21 Jul 2023 27 Oct 2023 05 Apr 2024 25 Apr 2024 11 Oct 2024 Description [TEST_REQ_ALL_SUT]: Updated version of referred document. [TEST_REQ_ALL_SUT]: Updated version of referred document. [TEST_REQ_ALL_SUT]: Updated version of referred document. [TEST_REQ_ALL_SUT]: Updated version of referred document. Update relative to product 2.2 which are supporting Bridging Message Extension
- Updated section “3.1.2. Configurable fields” which are applicable also for those products (cardSecurityCode and cardSecurityCodeStatus)
- Updated section “3.1.8 Card Range Data File URL” also applicable for those products [TEST_REQ_ALL_SUT]: Updated version of referred document. P3DS_MP-92: Resolution of Pass* K3DS-67
- In section 3.1.4, instead of a fixed value (000), the invalid Merchant Category Code (mcc) is now to be specified by the PP. Updated version of the referred documents
- [TEST_REQ_ALL_SUT]
- [Bridging_Mess_Ext] Update from EMV® Specification Bulletin No. 255 v4 July 2024: 3DS 2.1.0 is sunsetted
- All references to 3DS 2.1.0 are removed
- The condition of configurable fields are updated accordingly (Cf 3.1.2) Updated version of referred documents:
- [TEST_REQ_ALL_SUT] countries. EMV® 3-D Secure Approval Test Requirements for DS as System Under Test v2.14 3. 3.1.1 3.1.2 3.1.3 3.1.4 3.1.5 3.1.6 3.1.7 3.1. 3. 3. 3.3. 3. countries. EMV® 3-D Secure Approval Test Requirements for DS as System Under Test v2.14 / 13 1
References
Short name [TEST_REQ_ALL_SUT] [3DS_Core_2.2.0] [3DS_Core_2.3.1] [Bridging_Mess_Ext] Reference Document Test Requirements for all Systems Under Test EMV® 3-D Secure Protocol and Core Functions Specification EMVCo EMV® 3-D Secure Protocol and Core Functions Specification EMVCo EMV® 3-D Secure – Bridging Message Extension Version / Date v2.14 / 11 Oct 2024 v2.2.0 / nov-2018 v2.3.1.1 / May2023 v2.0 / Nov-2023
countries.
EMV® 3-D Secure Approval Test Requirements for DS as System Under Test v2.14
/ 13 2
Introduction
This document describes the test requirements for DS as system under test.
countries.
EMV® 3-D Secure Approval Test Requirements for DS as System Under Test v2.14 3 Test requirements for DS as SUT
/ 13 3.1 DS default data or message definition 3.1.1 Timeout values The DS shall set a 3-second timeout value from the time the TLS handshake has completed and the full RReq message is sent for processing to the 3DS Server URL. This timeout duration is fixed in Requirement 244 [3DS_Core_2.2.0], but is flexible from [3DS_Core_2.3.1]. According to Requirement 234 [3DS_Core_2.x.0], the DS shall set the ARes timeout value. The timeout value of 7 seconds is expected to be implemented.
3.1.2 Configurable fields The DS configuration is determined for the fields which are indicated as “DS Specific” or “based on DS rules” in [3DS_Core_2.x.0] for the presence and/or for the value. Such a DS Configuration will be dynamically used during XML MRF Tests execution, in order to:
- not provide a field in a message if it is expected absent by DS product
- provide a field in a message, with eventually the configured value, like it is expected by DS product Fields which are configurable for presence / absence only (not the value) Field name threeDSServerOperatorID acsOperatorID authenticationValue broadInfo Presence or Absence configurable in DS Yes Yes Yes Yes Condition if Condition not satisfied field not configurable in DS Always Always DS 2.2 or DS 2.3 or later Message Category = 02-NPA or Message Category = 01-PA AND Transaction Status = C, D, N, U, R or I (not Y/A) DS 2.2 countries. EMV® 3-D Secure Approval Test Requirements for DS as System Under Test v2.14 / 13 Field name cardExpiryDate transType taxId cardSecurityCode cardSecurityCodeStatus avValidityTime (in Multi-Transaction) avNumberUse (in Multi-Transaction) Presence or Absence configurable in DS Yes Yes Yes Yes Yes Yes Yes Condition if Condition not satisfied field not configurable in DS Always DS 2.3 or later Not configurable Always Always DS 2.3 or later Always DS 2.3 or later or DS 2.2 supporting [Bridging_Mess_Ext] Always DS 2.3 or later or DS 2.2 supporting [Bridging_Mess_Ext] If cardSecurityCode is configured as present DS 2.3 or later Always DS 2.3 or later Always Fields which are configurable for presence + value / absence Field name Presence & Value or Absence configurable in DS Condition if Condition not satisfied field not configurable in DS eci Yes Always transStatusReason Yes DS 2.2 or DS 2.3 or later Message Category = 02-NPA /! This DS configuration is to be transmitted to TPP for them to integrate it in Adaptation Layer Implementation (for the specific functions “apply_DS_message_configuration_for_presence_only” and “apply_DS_message_configuration_for_presence_and_value”) countries. EMV® 3-D Secure Approval Test Requirements for DS as System Under Test v2.14 / 13 3.1.3 Operator ID Values The DS must also recognize two operator ID values which will be utilized by certain test cases. The fields threeDSServerOperatorID and acsOperatorID are DS assigned values that may be assigned to a 3DS Server and ACS, respectively – as per the EMVCo Specifications [3DS_Core_2.x.0]. The values to be used for the Operators ID are:
- Operator ID = “threeDSServerOperatorID” / Value = “threeDSServerOperator_”
- Operator ID = “acsOperatorID” / Value = “acsOperator_< TPP_ID >” Where is provided by Test Platform Provider to DS Product Provider.
3.1.4 Merchant Category Code To test the Error Code 306, the DS Product Provider must provide the TPP an invalid Merchant Category Code (mcc) value. As per the Error Description, this value must be “not valid for Payment System” but is otherwise expected to be valid against other checks (e.g. length, format). The TPP then integrates this value in the Adaptation Layer implementation Specific function “get_mcc_not_valid_defined_by_PP”. 3.1.5 3DS Requestor Name and ID DS Product Provider shall allocate 3DS Requestor Name and ID to the Test Platform Provider.
3.1.6 Disable the “sent message limit exceeded” check To avoid that test case execution exceeds the maximum number of PReq messages sent to the DS (resulting in Error Code '103'), the System Under Test should temporarily disable the 'Sent messages limit exceeded' check. 3.1.7 3DS Requestor ID The DS must define and provide to TPP a specific fixed threeDSRequestorID value to be used by the TPP in AReq messages.
3.1.8 Card Range Data File URL If the DS supports the Card Range Data File download then it shall use it each time the received PReq message indicates Card Range Data Download Indicator = Y (In PReq message for 2.3 products, and, in the relative field in messageExtension for 2.2 product which is supporting [Bridging_Mess_Ext])
countries.
EMV® 3-D Secure Approval Test Requirements for DS as System Under Test v2.14
/ 13 3.2 DS behavior regarding data profile The document [TEST_REQ_ALL_SUT] describe all the configuration data Profiles and how the DS shall behave depending on card range.
3.3 DS Network configuration 3.3.1 DS connection with Test environment DS is connected with the following elements in Test Environment:
- 3DS Server
- ACS 3.4 DS Public keys and certificates DS Product Provider shall provide dedicated DS Public Keys and Certificates to Test Platform Providers. Such DS Public keys and certificates shall be dedicated for test and certification purpose only. countries. EMV® 3-D Secure Approval Test Requirements for DS as System Under Test v2.14 *** END OF DOCUMENT *** / 13 countries.