EMV® 3-D Secure Approval – Test Requirements for 3DS Server as System Under Test

v2.16 Test Cases & Test Environments
3-D Secure

EMV® 3-D Secure Approval Test Requirements for 3DS Server as System Under Test Version 2.16 11 Oct 2024

countries.

EMV® 3-D Secure Approval Test Requirements for 3DS Server as System Under Test v2.16

Legal Notice

This document summarizes EMVCo’s present plans for evaluation services and related policies and is subject to change by EMVCo at any time. This document does not create any binding obligations upon EMVCo or any third party regarding the subject matter of this document, which obligations will exist, if at all, only to the extent set forth in separate written agreements executed by EMVCo or such third parties. In the absence of such a written agreement, no product provider, test laboratory or any other third party should rely on this document, and EMVCo shall not be liable for any such reliance. No product provider, test laboratory or other third party may refer to a product, service or facility as EMVCo approved, in form or in substance, nor otherwise state or imply that EMVCo (or any agent of EMVCo) has in whole or part approved a product provider, test laboratory or other third party or its products, services, or facilities, except to the extent and subject to the terms, conditions and restrictions expressly set forth in a written agreement with EMVCo, or in an approval letter, compliance certificate or similar document issued by EMVCo. All other references to EMVCo approval are strictly prohibited by EMVCo. Under no circumstances should EMVCo approvals, when granted, be construed to imply any endorsement or warranty regarding the security, functionality, quality, or performance of any particular product or service, and no party shall state or imply anything to the contrary. EMVCo specifically disclaims any and all representations and warranties with respect to products that have received evaluations or approvals, and to the evaluation process generally, including, without limitation, any implied warranties of merchantability, fitness for purpose or non-infringement. All warranties, rights and remedies relating to products and services that have undergone evaluation by EMVCo are provided solely by the parties selling or otherwise providing such products or services, and not by EMVCo, and EMVCo will have no liability whatsoever in connection with such products and services. This document is provided "AS IS" without warranties of any kind, and EMVCo neither assumes nor accepts any liability for any errors or omissions contained in this document. EMVCO DISCLAIMS ALL REPRESENTATIONS AND WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NONINFRINGEMENT, AS TO THIS DOCUMENT. EMVCo makes no representations or warranties with respect to intellectual property rights of any third parties in or in relation to this document. EMVCo undertakes no responsibility to determine whether any implementation of this document may violate, infringe, or otherwise exercise the patent, copyright, trademark, trade secret, know-how, or other intellectual property rights of third parties, and thus any person who implements any part of this document should consult an intellectual property attorney before any such implementation. Without limiting the foregoing, this document may provide for the use of public key encryption and other technology, which may be the subject matter of patents in several countries. Any party seeking to implement this document is solely responsible for determining whether its activities require a license to any such technology, including for patents on public key encryption technology. EMVCo shall not be liable under any theory for any party's infringement of any intellectual property rights in connection with this document.

countries.

EMV® 3-D Secure Approval Test Requirements for 3DS Server as System Under Test v2.16 Revision Log

Version 1.0 1.1 1.2 1.3 1.4 1.5 2.0 2.1 2.2 2.3 2.4 2.5 2.6 2.7 Date 05 Mar 2020 20 Mar 2020 24 Apr 2020 27 Jul 2020 08 Sept 2020 11 Dec 2020 18 Dec 2020 29 Jan 2021 30 Mar 2021 14 May 2021 28 Jan 2022 11 Feb 2022 14 Mar 2022 22 Jul 2022

Description

Initial version Clarification about endpoint connections Editorial changes New section “Secure Security Requirement for proprietary messages” Corrections for pArq/pArs/pPrq/pPrs Clarification about DS Public keys and certificates Adjust version of reference document in section 1. Add the field “p_isSerialNumPresent” in the message pPrq, see in section 0 Updated reference for [TEST_REQ_ALL_SUT] Updated sections “3.3.2 pArq definition” and “3.3.3 pArs definition” to consider the new or removed fields in 3DS 2.3 [P3DS_TP-132] New sections 3.3.6, 3.3.7 to describe proprietary pGcq and pGcs messages, used to get the CReq produced by 3DSS in browser flow Removal of the field ‘p_messageVersion’ in pGcq and pGcs. Upgraded version of [TEST_REQ_ALL_SUT] to version 2.1 To consider the new or removed fields according to latest [3DS_Core_2.3.0]:

  • Updated section “3.3.2 pArq definition” (field numbers from 85 to 109).
  • Updated section “3.3.3 pArs definition” (field numbers from 29 to 40). P3DS_TP-277: A clarification note is threeDSServerURL in section “3.3.2. Authentication Request (pArq)” added for Proprietary Correction and clarification about pGcs content of htmlCreq encoded in base64url (without padding) instead of base64. See details in section “3.3.7 Proprietary Get Challenge Response (pGcs)” Upgraded version of [TEST_REQ_ALL_SUT] to version 2.4 To consider the new or removed fields according to latest [3DS_Core_2.3.1]: countries. EMV® 3-D Secure Approval Test Requirements for 3DS Server as System Under Test v2.16 Page v Version 2.8 2.9 2.10 2.11 2.12 2.13 2.14 Date 23 Sept 2022 28 Oct 2022 25 Nov 2022 14 Dec 2022 30 Jun 2023 21 Jul 2023 27 Oct 2023 Description
  • Updated section “3.3.2 pArq definition” (new field numbers from 110 to 114).
  • Updated section “3.3.3 pArs definition” (new field number 41).
  • Updated section “0 pPrq definition” (new field number 9). Upgraded version of [TEST_REQ_ALL_SUT]. referenced document Updated section “3.3.2 pArq definition”: letter case changed for fields 113 “deviceId" and 114 “userId” P3DS_TP-417 Clarification, the 3DSS shall be able to send pArs without any pArq (see updated section “3.3.3 pArs definition”) [TEST_REQ_ALL_SUT]: Updated version of referred document. P3DS_TP-446 the 3DS Server will pass the RRes data to the 3DS requestor. Then the merchant will initiate the sub-sequent 3RI transaction. This means that the test platform shall always send to the 3DS Server a pArq to initiate an AReq in 3RI. (Revert of previous comment added in version 2.9 section “3.3.3 pArs definition”) [TEST_REQ_ALL_SUT]: Updated version of referred document. [TEST_REQ_ALL_SUT]: Updated version of referred document. Update related to latest published [3DS_Core_2.3.1], see impact in section “3.3.2 Proprietary Authentication Request (pArq)”:
  • 80 - threeDSReqAuthMethodInd is only for 2.0 because removed from 2.3.1.1 [TEST_REQ_ALL_SUT]: Updated version of referred document. Update relative to product 2.2 which are supporting Bridging Message Extension or to any other extension.
  • New note for “messageExtension” field in pArq (See section 3.3.2)
  • New note for “messageExtension” field in pArs (See section 3.3.3) [TEST_REQ_ALL_SUT]: Updated version of referred document countries. EMV® 3-D Secure Approval Test Requirements for 3DS Server as System Under Test v2.16 Version 2.15 2.16 Date 26 Apr 2024 11 Oct 2024 Description Updated version of referred documents:
  • [Bridging_Mess_Ext]
  • [TEST_REQ_ALL_SUT] Update from EMV® Specification Bulletin No. 255 v4 July 2024: 3DS 2.1.0 is sunsetted
  • All references to 3DS 2.1.0 are removed Updated version of referred documents:
  • [TEST_REQ_ALL_SUT] countries. EMV® 3-D Secure Approval Test Requirements for 3DS Server as System Under Test v2.16 Contents 1. 2. 3. 3.1. 3.1.1. 3.1.2. 3.1.3. 3.2. 3.3. 3.3.1. 3.3.2. 3.3.3. 3.3.4. 3.3.5. 3.3.6. 3.3.7. 3.4. 3.4.1. 3.5. countries. EMV® 3-D Secure Approval Test Requirements for 3DS Server as System Under Test v2.16 / 20 1.

References

Short name [TEST_REQ_ALL_SUT] [3DS_Core_2.2.0] [3DS_SDK_Spec_2.2.0] [3DS_Core_2.3.1] [3DS_SDK_Spec_2.3.1] [3DS_Split_SDK_Spec_2.3.1] [Bridging_Mess_Ext] Reference Document Test Requirements for all Systems Under Test EMV® 3-D Secure Protocol and Core Functions Specification EMVCo EMV® 3-D Secure – SDK Specification EMVCo EMV® 3-D Secure Protocol and Core Functions Specification EMVCo EMV® 3-D Secure – SDK Specification EMVCo EMV® 3-D Secure – Split-SDK Specification EMVCo EMV® 3-D Secure – Bridging Message Extension Version / Date v2.14 / 11 oct 2024 v2.2.0 / nov-2018 v2.2.0 / nov-018 v2.3.1.1 / May-2023 v2.3.1.1 / May-2023 v2.3.1.1 / May-2023 v2.0 / Nov-2023

countries.

EMV® 3-D Secure Approval Test Requirements for 3DS Server as System Under Test v2.16

/ 20 2.

Introduction

This document describes test requirements for 3DS Server as System Under Test.

countries.

EMV® 3-D Secure Approval Test Requirements for 3DS Server as System Under Test v2.16

/ 20 3. Test requirements for 3DS Server as SUT 3.1. 3DS SERVER default data or message definition 3.1.1. Timeout values According to Requirement 228 [3DS_Core_2.x.0], the 3DS Server shall set appropriate AReq message timeout values, after exceeding the connection is closed. To test the corresponding SUT behavior, a timeout value of 10 seconds is expected to be implemented for the 3DS Server. 3.1.2. Proprietary messages content type The proprietary messages (See details in §3.3 “3DS SERVER Proprietary messages with Test environment”) shall use the same Content-Type header as defined in Requirement 190 [3DS_Core_2.x.0] with the value: Content-Type: application/json;charset=UTF-8 3.1.3. Specific behavior regarding error messages Error messages shall be sent to the 3DS REQUESTOR by the 3DS Server for all scenarios described in the EMV 3-D Secure Core specification [3DS_Core_2.x.0]. Including, but not limited to, section 5.9.4, 5.9.9 and requirements 229 and 271 of the specification. Error messages sent from the 3DS Server to 3DS REQUESTOR will be handled as follows:

  • As a response to the pArq or pPrq message over the connection that was set up for the pArq/pArs or pPrq/pPrs message exchange (instead of the pArs/pPrs message). For example, if an ARes or PRes is received from the DS that contains an error (incorrect value etc.) or if an Erro message is received from the DS. The error messages shall be formatted according to sections A.5.5, B.10 and table A.4 of the EMV 3-D Secure Core specification [3DS_Core_2.x.0]. 3.2. Active protocol versions A 3DS Server shall use the same Message Version Number in the AReq message sent to the DS as received in the pArq message received from the 3DS Requestor Environment (See details in §3.3 “3DS SERVER Proprietary messages with Test environment”). In this way, the test case can drive the 3-D Secure Protocol Version Number used within the test case. countries. EMV® 3-D Secure Approval Test Requirements for 3DS Server as System Under Test v2.16 / 20 3.3. 3DS SERVER Proprietary messages with Test environment For testing purpose, four proprietary messages are specified to emulate the communication between 3DS REQUESTOR and 3DS Server, because this communication is out of scope of 3-D Secure specification [3DS_Core_2.x.0]: 1. Test environment to provide information to 3DS Server to build the AReq message sent to DS:  3DS REQUESTOR  3DS Server: Proprietary Authentication Request (pArq) (details are provided in sub-sections below) 2. To forward to Test environment the received ARes message from DS to 3DS Server  3DS Server  3DS REQUESTOR: Proprietary Authentication Response (pArs) (details are provided in sub-sections below) 3. Test environment to provide information to 3DS Server to send PReq message sent to DS:  3DS REQUESTOR  3DS Server: Proprietary Preparation Request (pPrq) (details are provided in sub-sections below) 4. To forward to Test environment the received PRes message from DS to 3DS Server:  3DS Server  3DS REQUESTOR: Proprietary Preparation Response (pPrs) (details are provided in sub-sections below) 5. Test environment to ask to 3DS Server to send the CReq message computed by 3DS Server to browser (cf [3DS_Core_2.x.0] Req 117):  3DS REQUESTOR  3DS Server: Proprietary Get Challenge Request (pGcq) (details are provided in sub-sections below) 6. To forward to Test environment the computed CReq message from 3DS Server to browser (cf [3DS_Core_2.x.0] Req 117):  3DS Server  3DS REQUESTOR: Proprietary Get Challenge Response (pGcs) (details are provided in sub-sections below) 3.3.1. Secure Security Requirement for proprietary messages The 3DS Requestor to 3DS Server link shall following the same security requirement as for AReq (See [3DS_Core_2.x.x] §6.1.2.1) 3.3.2. Proprietary Authentication Request (pArq) [Test environment behavior] The test environment, as 3DS REQUESTOR, shall send a proprietary Authentication Request (pArq) to 3DS Server as specified below. The 3DS Server shall extract the appropriate information to build and complete the AReq message to be sent to DS. N° Field Presence Type/Format Accepted Value 1 acctNumber 2 cardExpiryDate R According to EMVCo 3DS According to EMVCo 3DS Spec Spec R According to EMVCo 3DS According to EMVCo 3DS Spec Spec countries. EMV® 3-D Secure Approval Test Requirements for 3DS Server as System Under Test v2.16 / 20 3 deviceChannel R 4 messageCategory R 5 messageType R 6 messageVersion R 7 p_messageVersion R 8 threeDSRequestorID R 9 threeDSRequestorName R 10 threeDSRequestorURL R 11 acquirerBIN C 12 acquirerMerchantID C 13 addrMatch C 14 billAddrCity C 15 billAddrCountry C 16 billAddrLine1 C 17 billAddrLine2 C 18 billAddrLine3 C 19 billAddrPostCode C 20 billAddrState C 21 browserAcceptHeader C 22 browserColorDepth C 23 browserIP C 24 browserJavaEnabled C 25 browserLanguage C 26 browserScreenHeight C 27 browserScreenWidth C 28 browserTZ C 29 browserUserAgent C 30 cardholderName C 31 deviceRenderOptions C 32 email C 33 homePhone C 34 mcc C 35 merchantCountryCode C 36 merchantName C 37 mobilePhone C 38 purchaseAmount C 39 purchaseCurrency C 40 purchaseDate C 41 purchaseExponent C 42 recurringExpiry C According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec 1.1.0 According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec pArq According to EMVCo 3DS Spec Starting value:

1.0.0 According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec

countries.

EMV® 3-D Secure Approval Test Requirements for 3DS Server as System Under Test v2.16 43 recurringFrequency C 44 sdkAppID C 45 sdkEncData R 46 sdkEphemPubKey C 47 sdkReferenceNumber C 48 sdkTransID C 49 shipAddrCity C 50 shipAddrCountry C 51 shipAddrLine1 C 52 shipAddrLine2 C 53 shipAddrLine3 C 54 shipAddrPostCode C 55 shipAddrState C 56 transType C 57 workPhone C 58 acctID O 59 acctInfo O 60 acctType O 61 merchantRiskIndicator O 62 messageExtension (See Note2 below) O 63 payTokenInd O 64 purchaseInstalData O 65 threeDSRequestorAuthenticationInfo O 66 threeDSRequestorChallengeInd O 67 threeDSRequestorAuthenticationInd R 68 threeRIInd R 69 threeDSRequestorPriorAuthenticationInfo O 70 threeDSServerRefNumber R 71 threeDSServerOperatorID O 72 threeDSServerTransID R 73 threeDSServerTransID R 74 threeDSServerURL (see Note1 below) R 75 broadInfo C 76 notificationURL R 77 threeDSCompInd R 78 sdkMaxTimeout R 79 acsURL C 80 threeDSReqAuthMethodInd C (for v2.2.0 only) 81 threeDSRequestorDecMaxTime C (for v2.2.0 and later) According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec

/ 20 According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec. According to EMVCo 3DS Spec.

countries.

EMV® 3-D Secure Approval Test Requirements for 3DS Server as System Under Test v2.16

/ 20 82 threeDSRequestorDecReqInd O (for v2.2.0 and later) According to EMVCo 3DS Spec 83 browserJavaScriptEnabled R (for v2.2.0 and later) According to EMVCo 3DS Spec 84 payTokenSource C (for v2.2.0 and later) According to EMVCo 3DS Spec 85 whiteListStatus O (only for v2.2.0) According to EMVCo 3DS Spec 86 whiteListStatusSource C (only for v2.2.0) According to EMVCo 3DS Spec 85 trustlistStatus O (for v2.3.0 and later) According to EMVCo 3DS Spec 86 trustlistStatusSource C (for v2.3.0 and later) According to EMVCo 3DS Spec 87 sdkType R (for v2.3.0 and later) According to EMVCo 3DS Spec 88 sdkServerSignedContent C (for v2.3.0 and later) According to EMVCo 3DS Spec 89 acceptLanguage R (for v2.3.0 and later) According to EMVCo 3DS Spec 90 acquirerCountryCode R (for v2.3.0 and later) According to EMVCo 3DS Spec 91 acquirerCountryCodeSource R (for v2.3.0 and later) According to EMVCo 3DS Spec 92 appIp C (for v2.3.0 and later) According to EMVCo 3DS Spec 93 cardSecurityCode C (for v2.3.0 and later) According to EMVCo 3DS Spec 94 cardSecurityCodeStatus C (for v2.3.0 and later) According to EMVCo 3DS Spec 95 cardSecurityCodeStatusSource C (for v2.3.0 and later) According to EMVCo 3DS Spec 96 deviceBindingStatus O (for v2.3.0 and later) According to EMVCo 3DS Spec 97 deviceBindingStatusSource C (for v2.3.0 and later) According to EMVCo 3DS Spec 98 payTokenInfo O (for v2.3.0 and later) According to EMVCo 3DS Spec 99 multiTransaction O (for v2.3.0 and later) According to EMVCo 3DS Spec 100 recurringAmount C (for v2.3.0 and later) According to EMVCo 3DS Spec 101 recurringCurrency C (for v2.3.0 and later) According to EMVCo 3DS Spec 102 recurringExponent C (for v2.3.0 and later) According to EMVCo 3DS Spec 103 recurringDate C (for v2.3.0 and later) According to EMVCo 3DS Spec 104 recurringInd C (for v2.3.0 and later) According to EMVCo 3DS Spec 105 sellerInfo O (for v2.3.0 and later) According to EMVCo 3DS Spec 106 spcIncompInd C (for v2.3.0 and later) According to EMVCo 3DS Spec 107 taxId C (for v2.3.0 and later) According to EMVCo 3DS Spec 108 threeDSMethodId C (for v2.3.0 and later) According to EMVCo 3DS Spec 109 threeDSRequestorSpcSupport C (for v2.3.0 and later) According to EMVCo 3DS Spec 110 defaultSdkType C (for v2.3.1 and later) According to EMVCo 3DS Spec 111 payeeOrigin C (for v2.3.1 and later) According to EMVCo 3DS Spec 112 splitSdkType C (for v2.3.1 and later) According to EMVCo 3DS Spec 113 deviceId O (for v2.3.1 and later) According to EMVCo 3DS Spec 114 userId O (for v2.3.1 and later) According to EMVCo 3DS Spec Note: Since market or region restriction may vary, any conditional data or region restriction should be treated as optional for testing purposes. According Spec. According Spec. According Spec. According Spec. According Spec. According Spec. According Spec. According Spec According Spec According Spec According Spec According Spec According Spec According Spec According Spec According Spec According Spec According Spec According Spec According Spec According Spec According Spec According Spec According Spec According Spec According Spec According Spec According Spec According Spec According Spec According Spec According Spec According Spec According Spec According Spec element to EMVCo 3DS to EMVCo 3DS to EMVCo 3DS to EMVCo 3DS to EMVCo 3DS to EMVCo 3DS to EMVCo 3DS to EMVCo 3DS to EMVCo 3DS to EMVCo 3DS to EMVCo 3DS to EMVCo 3DS to EMVCo 3DS to EMVCo 3DS to EMVCo 3DS to EMVCo 3DS to EMVCo 3DS to EMVCo 3DS to EMVCo 3DS to EMVCo 3DS to EMVCo 3DS to EMVCo 3DS to EMVCo 3DS to EMVCo 3DS to EMVCo 3DS to EMVCo 3DS to EMVCo 3DS to EMVCo 3DS to EMVCo 3DS to EMVCo 3DS to EMVCo 3DS to EMVCo 3DS to EMVCo 3DS to EMVCo 3DS to EMVCo 3DS with a market Note1: the threeDSServerURL shall be provided to TPP by 3DSS Product Provider according to its own configuration.

countries.

EMV® 3-D Secure Approval Test Requirements for 3DS Server as System Under Test v2.16

/ 20 Note2: the 3DSS product may receive messageExtension filled in pArq, it has to forward the same message extension in the outgoing AReq 3.3.3. Proprietary Authentication Response (pArs) [3DS Server behavior] the 3DS Server shall forward the message ARes received from DS and send it, as proprietary Authentication Response pArs to 3DS REQUESTOR (Test environment). The content of pArs message is specified with: № Field 1. threeDSServerTransID Presence R 2. p_messageVersion 3. 4. messageType R R 5. messageVersion R 6. transStatus R 7. dsReferenceNumber R 8. acsReferenceNumber R 9. acsTransID R 10. dsTransID R 11. authenticationValue C 12. 13. acsRenderingType C 14. acsOperatorID O 15. acsSignedContent C 16. acsURL C 17. authenticationType 18. acsChallengeMandated C (only for v2.1.0 and v2.2.0) C 19. eci C 20. messageExtension C (See Note1 below) 21. 22. sdkTransID R 23. transStatusReason C 24. cardholderInfo 25. broadInfo O (only for v2.1.0) C (for v2.2.0 and later) C 26 acsDecConInd C (for v2.2.0 and later) 27 whiteListStatus O (only for v2.2.0) 28 whiteListStatusSource C (only for v2.2.0) 29 trustlistStatus O (for v2.3.0 and later) 30 trustlistStatusSource C (for v2.3.0 and later) 31 authenticationMethod C (for v2.3.0 and later) 32 cardSecurityCodeStatusSource C (for v2.3.0 and later) 33 cardSecurityCodeStatus C (for v2.3.0 and later) Type/Format According to EMVCo 3DS Spec 1.1.0 According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec Accepted Value According to EMVCo 3DS Spec Starting value: 1.0.0 pArs According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec. According to EMVCo 3DS Spec. According to EMVCo 3DS Spec. According to EMVCo 3DS Spec. According to EMVCo 3DS Spec. According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec

countries.

EMV® 3-D Secure Approval Test Requirements for 3DS Server as System Under Test v2.16

/ 20 34 deviceBindingStatus 35 deviceBindingStatusSource 36 deviceInfoRecognisedVersion 37 spcTransData 38 transChallengeExemption 39 transStatusReasonInfo 40 webAuthnCredList 41 threeDSRequestorAppURLInd O (for v2.3.0 and later) C (for v2.3.0 and later) R (for v2.3.0 and later) C (for v2.3.0 and later) O (for v2.3.0 and later) C (for v2.3.0 and later) O (for v2.3.0 and later) R (for v2.3.1 and later) According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec Note1: the 3DSS product may receive messageExtension filled in ARes, it has to forward the same message extension in the outgoing pArs 3.3.4. Proprietary Preparation Request (pPrq) [Test environment behavior] The test environment, as 3DS REQUESTOR, shall send a proprietary Preparation Request (pPrq) to 3DS Server as specified below. The 3DS Server shall extract the appropriate information to build and complete the PReq message to be sent to DS. № Field 1. messageType 2. p_messageVersion 3. messageVersion 4. threeDSRequestorID 5. threeDSServerTransID 6. threeDSRequestorURL 7. messageExtension 8. p_isSerialNumPresent Presence R R R R R R O R Type/Format According to EMVCo 3DS Spec 1.0.6 According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec Indicate if the 3DS Server shall include the serial number in outgoing PReq from latest PRes received. Accepted Value pPrq Starting value:

1.0.0 According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec According to EMVCo 3DS Spec Boolean true / false If True, the 3DS Server shall consider the PReq as subsequent PReq since the first one (outgoing PReq includes the serial number from latest PRes received) 9. cardRangeDataDownloadInd C (for v2.3.1 and later) If False, the 3DS Server shall consider the PReq as the first one. Adjust the related database routine to take into account cardrange from related PRes (erase previous cardrange data from former PRes). The outgoing PReq shall not contain the field serialNum. According to EMVCo 3DS Spec According to EMVCo 3DS Spec

countries.

EMV® 3-D Secure Approval Test Requirements for 3DS Server as System Under Test v2.16

/ 20 3.3.5. Proprietary Preparation Response (pPrs) [3DS Server behavior] the 3DS Server shall forward the message PRes received from DS and send it, as proprietary Preparation Response pPrs to 3DS REQUESTOR (Test environment), as specified: № Field Presence Type/Format Accepted Value 1. messageType R Length: 4 character JSON Data Type: String pPrs 2. messageVersion R According to EMVCo 3DS Spec According to EMVCo 3DS Spec 3. p_messageVersion R 1.0.5 Starting value: 1.0.0 4. p_completed R JSON Data Type: Boolean True 5 messageExtension O According to EMVCo 3DS Spec According to EMVCo 3DS Spec 3.3.6. Proprietary Get Challenge Request (pGcq) [Test environment behavior] The test environment, as 3DS REQUESTOR, shall send a proprietary Get Challenge Request (pGcq) to 3DS Server as indicated in the test sequence and as specified below: № Field 1. messageType Presence Type/Format Accepted Value R According to EMVCo 3DS Spec pGcq 2. messageVersion R According to EMVCo 3DS Spec According to EMVCo 3DS Spec 3. threeDSServerTransID R According to EMVCo 3DS Spec According to EMVCo 3DS Spec 4. acsTransID R According to EMVCo 3DS Spec According to EMVCo 3DS Spec 5. threeDSSessionData O According to EMVCo 3DS Spec According to EMVCo 3DS Spec 6. challengeWindowSize R According to EMVCo 3DS Spec According to EMVCo 3DS Spec 3.3.7. Proprietary Get Challenge Response (pGcs) [3DS Server behavior] the 3DS Server shall forward the CReq (previously computed and sent to browser) in the response message: pGcs № Field 1. messageType Presence R Type/Format According to EMVCo 3DS Spec Accepted Value pGcs 2. messageVersion R According to EMVCo 3DS Spec According to EMVCo 3DS Spec 3. htmlCreq R The complete HTML generated by 3DSS and posted through the Browser (Important note: in “creq” html property: Base64url encoded Creq, without any padding: no ‘=’ character) According to EMVCo 3DS Spec According to EMVCo 3DS Spec Example: { "messageType": "pGcs", "messageVersion": "2.2.0", "htmlCreq": " " }

countries.

EMV® 3-D Secure Approval Test Requirements for 3DS Server as System Under Test v2.16 3.4. 3DS SERVER Network configuration 3.4.1. 3DS SERVER connection with Test environment SERVER is connected with the following elements in Test Environment:

  • DS
  • 3DS REQUESTOR o for App-based flow o for Browser-based flow o for 3RI-based flow / 20 3.5. DS Public keys and certificates The DS public keys and Certificates are provided by the Test Platform Provider. Test Platform Provider also indicates the associated RIDs for the DS public Keys depending on the algorithm (RSA, EC). countries. EMV® 3-D Secure Approval Test Requirements for 3DS Server as System Under Test v2.16 *** END OF DOCUMENT *** / 20 countries.