EMV® 3-D Secure Approval – Test Requirements for all Systems Under Test

v2.14 Test Cases & Test Environments
3-D Secure

EMV® 3-D Secure Approval Test Requirements for all Systems Under Test Version 2.14 11 Oct 2024

EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14

Legal Notice

This document summarizes EMVCo’s present plans for evaluation services and related policies and is subject to change by EMVCo at any time. This document does not create any binding obligations upon EMVCo or any third party regarding the subject matter of this document, which obligations will exist, if at all, only to the extent set forth in separate written agreements executed by EMVCo or such third parties. In the absence of such a written agreement, no product provider, test laboratory or any other third party should rely on this document, and EMVCo shall not be liable for any such reliance. No product provider, test laboratory or other third party may refer to a product, service or facility as EMVCo approved, in form or in substance, nor otherwise state or imply that EMVCo (or any agent of EMVCo) has in whole or part approved a product provider, test laboratory or other third party or its products, services, or facilities, except to the extent and subject to the terms, conditions and restrictions expressly set forth in a written agreement with EMVCo, or in an approval letter, compliance certificate or similar document issued by EMVCo. All other references to EMVCo approval are strictly prohibited by EMVCo. Under no circumstances should EMVCo approvals, when granted, be construed to imply any endorsement or warranty regarding the security, functionality, quality, or performance of any particular product or service, and no party shall state or imply anything to the contrary. EMVCo specifically disclaims any and all representations and warranties with respect to products that have received evaluations or approvals, and to the evaluation process generally, including, without limitation, any implied warranties of merchantability, fitness for purpose or non-infringement. All warranties, rights and remedies relating to products and services that have undergone evaluation by EMVCo are provided solely by the parties selling or otherwise providing such products or services, and not by EMVCo, and EMVCo will have no liability whatsoever in connection with such products and services. This document is provided "AS IS" without warranties of any kind, and EMVCo neither assumes nor accepts any liability for any errors or omissions contained in this document. EMVCO DISCLAIMS ALL REPRESENTATIONS AND WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NONINFRINGEMENT, AS TO THIS DOCUMENT. EMVCo makes no representations or warranties with respect to intellectual property rights of any third parties in or in relation to this document. EMVCo undertakes no responsibility to determine whether any implementation of this document may violate, infringe, or otherwise exercise the patent, copyright, trademark, trade secret, know-how, or other intellectual property rights of third parties, and thus any person who implements any part of this document should consult an intellectual property attorney before any such implementation. Without limiting the foregoing, this document may provide for the use of public key encryption and other technology, which may be the subject matter of patents in several countries. Any party seeking to implement this document is solely responsible for determining whether its activities require a license to any such technology, including for patents on public key encryption technology. EMVCo shall not be liable under any theory for any party's infringement of any intellectual property rights in connection with this document.

EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14

Version 1.0 1.1 1.2 1.3 2.0 2.1 Date 05 Mar 2020 24 Apr 2020 17 Jun 2020 11 Dec 2020 29 Jan 2021 14 May 2021 Revision Log

Description

Initial version Editorial changes Clarification on DS public keys and certificates Change in Reference Numbers management Editorial changes: in §3.2.2, column descriptions for: - CardholderFrictionlessNotContaining3DSMethodURL - CardholderFrictionlessNotContainingDSProtocolVersion Clarification for ACS behavior for a specific account range in section 3.2.2: CardholderDecoupledMaxTimeExpired Updated some existing account ranges for any version: 12. CardholderChallengeAcsRenderingType0104 renamed in CardholderChallengeAcsRenderingType0104_no_OOB_automa tic_switch + Updated description 30. CardholderForInformation: updated description New account ranges for 3DS Specification 2.3.0 from number 33 to 51, dealing with the following features

  • Device Binding feature.
  • Challenge Data Entry feature.
  • Toggle Position Indicator.
  • OOB Automatic Switching feature.
  • Information ACS UI type (07). Removed restriction on using acsRenderingType ["01", "01"] in account ranges 33 to 46. New account ranges for 3DS Specification 2.3.0 from number 52 to 67, dealing with the following features
  • Device User Interface Mode (in ACS Rendering Type)
  • Cardholder Information Text
  • DS response on ACS behalf
  • Challenge Additional Label
  • Challenge Information Text Indicator EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 Page v Version 2.2 2.3 Date 10 Dec 2021 21 Jan 2022 Description Updated account ranges for 3DS Specification 2.3.0
  • Ranges 33 to 37 to refer to the new deviceBindingStatus values.
  • Ranges 38 to 43 to refer to the challengeEntryBox object.
  • Range 56 to the new cardholderInfo structure. New account ranges for 3DS Specification 2.3.0 from number 68 to 76, dealing with the following features:
  • Challenge Entry Box 2
  • Challenge Text Box Settings
  • SPC
  • Transaction Challenge Exemption
  • 3DS Method ID Updated account ranges for 3DS Specification 2.3.0
  • Range 72 to include new requirements targeted at the 3DSS. New account ranges for 3DS Specification 2.3.0 from number 77 to 78, dealing with the following features:
  • SPC EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 Version 2.4 2.5 Date 14 Mar 2022 22 Jul 2022 Description P3DS_TP-283: Add clarifications regarding SPC behavior for ACS, see descriptions in ranges:
  • See description range 72. CardholderSPC_initiatedBy3DSRequestor
  • See description range 73. CardholderSPC_initiatedByACS Add clarifications regarding SPC behavior for 3DSS, see descriptions in ranges:
  • 72. CardholderSPC_initiatedBy3DSRequestor
  • 77. CardholderSPC_initiatedBy3DSRequestor_spcIncompIn d_01
  • 78. CardholderSPC_initiatedBy3DSRequestor_spcIncompIn d_02 P3DS_TP-293: Correction of end value of the range 27. CardholderChallenge in section “3.2. Configuration Data Profiles”. New account ranges for 3DS Specification 2.3.0 from number 79 to 82 (see details in section “3.2. Configuration Data Profiles”) dealing with the following features:
  • OReq/ORes P3DS_TP-354: Align expected acsInfoInd in test case and account number range definition in Test Requirements for All SUT
  • Specified the expected acsInfoInd value for account ranges 33, 34, 35, 36, 37, 72, 73, 77 and 78. P3DS_TP-341: for 3DSS, SPC transaction identification of 2nd pArq is made through the usage of ‘threeDSServerTransID’ transmitted in pArq
  • Updated description for account ranges 72, 77 and 78. P3DS_TP-346: for DS, OReq is triggered after ARes, instead of after AReq
  • Updated description for account ranges: 79, 80, 81 and 82 EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 Version 2.6 2.7 2.8 2.9 2.10 2.11 2.12 2.13 Date 23 Sept 2022 28 Oct 2022 25 Nov 2022 14 Dec 2022 30 June 2023 21 July 2023 27 Oct 2023 26 Apr 2024 Description New account ranges for 3DS Specification 2.3.1, dealing with the following feature:
  • Index 83 for Challenge Additional Label / OOB
  • Index 84 to 90 for Decoupled Authentication Fallback Added a precision on account ranges 29. CardholderDecoupledAuthentication and 31. CardholderDecoupledMaxTimeExpired regarding Decoupled Authentication Fallback. Updated 72. CardholderSPC_initiatedBy3DSRequestor: threeDSReqAuthData set to a JSON Object instead of a String. No content change. Only reformatting to latest EMVCo Template document P3DS_TP-434: Add information in pArq for SPC account ranged about threeDSRequestorSpcSupport and spcIncompInd
  • Updated description for account ranges 72, 77 and 78. P3DS_MP-73: complementary specifications for the list of used ACS Reference Numbers shall include the list of used DS Reference Numbers (See section “3.1.3. Reference numbers”). P3DS_TP-562: Question about requirement of Stand-In authentication
  • Updated description for account range 57. Update relative to product 2.2 which are supporting Bridging Message Extension
  • Updated general comment in section 3.2.2 to determine the additional applicable account numbers for this kind of products.
  • Updated description for account range 38
  • Updated description for account range 40
  • Updated description for account range 47
  • Updated description for account range 74
  • Updated description for account range 75 P3DS_MP-103: LOA definition depending on SDK Type Allow a specific prefix for sdkReferenceNumber for Split-SDK: Updated section 3.1.3: three new values using the new function Updated version of referred document: [Bridging_Mess_Ext] EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 Version 2.14 Date 11 Oct 2024 Description Update from EMV® Specification Bulletin No. 255 v4 July 2024: 3DS 2.1.0 is sunsetted P3DSMP-129: protocol version 2.1.0 sunset impacts:
  • All references to 3DS 2.1.0 are removed
  • Update of starting protocol version (Cf 3.1.1)
  • Update of Configuration Data Profiles (Cf 3.2) EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 Contents 1. 2. 3. 3.1. 3.1.1. 3.1.2. 3.1.3. 3.1.4. 3.1.5. 3.2. 3.2.1. 3.2.2. EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 1.

References

Short name [3DS_Core_2.2.0] [3DS_SDK_Spec_2.2.0] [3DS_Core_2.3.1] [3DS_SDK_Spec_2.3.1] [3DS_Split_SDK_Spec_2.3.1] Reference Document EMV® 3-D Secure Protocol and Core Functions Specification EMVCo EMV® 3-D Secure – SDK Specification EMVCo EMV® 3-D Secure Protocol and Core Functions Specification EMVCo EMV® 3-D Secure – SDK Specification EMVCo EMV® 3-D Secure – Split-SDK Specification EMVCo [Bridging_Mess_Ext] EMV® 3-D Secure – Bridging Message Extension Version / Date v2.2.0 / nov-2018 v2.2.0 / nov-2018 v2.3.1.1 / May-2023 v2.3.1.1 / May-2023 v2.3.1.1 / May-2023 v2.0 / Nov-2023

EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14

2.

Introduction

This document describes the test requirements for all systems under test (SUT) of 3DS Specification: ACS, DS, 3DS Server and 3DS SDK.

EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 3. Test Requirements for all SUT

3.1. All SUT default data or message behavior 3.1.1. Active protocol versions The Test Requirements document applies to both active 3-D Secure Protocol Version Numbers 2.2.0 and 2.3.1 with the following remarks:

  • Systems Under Test only supporting a specific 3-D Secure Protocol Version Number should not include the data elements marked as applicable for later 3DS Protocol Version Number only in proprietary messages defined in the dedicated Test Requirements for each SUT.
  • Systems Under Test (more specifically Directory Servers) should list version 2.2.0 as Start Protocol Version Number and 2.3.1 as End Protocol Version Number in the relevant data elements included in PRes messages in case they support 3-D Secure Protocol Version Number 2.3.1. In case a DS only supports 3-D Secure Protocol Version Number 2.2.0 or 2.2.0, only that Protocol Version Number should be mentioned in the PRes messages. 3.1.2. DS Public keys The way to manage the DS public keys is dependent on the System Under Test. Please refer to the dedicated document: Test Requirements for each System Under Test. 3.1.3. Reference numbers To integrate with the Test Environment and Test Plan, Systems Under Test must configure a reference number from this list for each component. A system must also recognize these reference numbers as participating reference numbers. Any other reference numbers (including EMVCo-assigned reference numbers) will be rejected.
  • sdkReferenceNumber: o 3 values are used into the Test Plan for the Default SDK  _00007  _00011  _00015  Where is a prefix value provided by TPP o 3 values are used into the Test Plan for the Split-SDK  _00007  _00011  _00015  Where is a prefix value provided by TPP
  • threeDSServerRefNumber
  • The list of used threeDSServerRefNumbers will be provided by TPP EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14
  • acsReferenceNumber
  • The list of used acsReferenceNumbers will be provided by TPP
  • According to [Req 421] for [3DS_Core_2.3.1], according to FAQ for [3DS_Core_2.2.0], when the DS creates the ARes message on the ACS’s behalf then the DS sets the ACS Reference Number equal to the DS Reference Number and the ACS Transaction ID equal to the DS Transaction ID.  Then the list of used acsReferenceNumbers shall include also the list of use dsReferenceNumbers
  • dsReferenceNumber
  • The list of used dsReferenceNumbers will be provided by TPP 3.1.4. Defaults values Field Scenarios acquirerBIN Default Acquirer profile for happy flow Acquirer profile with a nonparticipating Acquirer BIN Invalid format (more than 11 characters) acquirerMerchantID Default Acquirer Merchant ID for happy flow Acquirer Merchant ID that does not relate to the Acquirer BIN 999999999999 9 Electronic Happy flow Commerce Indicator value (ECI) Authentication value Happy flow value Default Value 000000999 000000000 01234567890987 9876543210001 ‘00’ or ‘99’ ‘AABBCCDDEEFF AABBCCDDEEFF AAA=’ or ‘QXV0aGVudGljY XRpb24gdmFsdW U=’ Conditional Inclusion
  • Required for transStatus == 'Y' and transStatus == 'A' in case the ACS is the System Under Test.
  • Included in the ARes message generated by the test platform for all values of transStatus in case the 3DS Server, 3DS SDK, or the DS is the System Under Test Message Category = 01 and Required if transStatus = ‘Y’ or transStatus = ‘A’. EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 3.1.5. Message Extensions As per EMVCo’s decision, testing of critical message extensions is not in scope of the platform. Any message extension received by the System Under Test with the criticalityIndicator set to ’true’ will be regarded as a non-recognized critical message extension. The test cases expect an error message to be returned in such a scenario. Non-critical message extensions need to be handled by the Systems Under Test. EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 3.2. Configuration Data Profiles The interfaces for testing different components are specified by the EMVCo 3DS specifications [3DS_Core_2.x.0]. Before testing can start, the Data Profiles as described below shall be configured. These profiles contain a specific ID and description, linking to predefined card ranges. Applicability of data profiles depending on 3D Secure Protocol Version Number:
  • Systems Under Test supporting 3-D Secure Protocol Version Number 2.2.0 shall support Account Number Ranges from 1 to 32
  • Systems Under Test supporting 3-D Secure Protocol Version Number 2.2.0 which are supporting [Bridging_Mess_Ext] shall also support also the specific Account Number between 1 to 90: only the ones which have a mark “Applicable for 3DS Secure Protocol 2.2 supporting [Bridging_Mess_Ext] ” in the description.
  • Systems Under Test supporting 3-D Secure Protocol Version Number 2.3.1 shall support Account Number Ranges from 1 to 90 All the data profiles, except ‘FrictionlessConfigurationDataNotContaining3DSMethodURL’, should contain the 3DSMethodURL value for the Browser based flow. 3.2.1. Format More specifically, regarding the Account Range number, the following syntax was used: Account Range: NNNNNNCCXXXXXXXXXY, in which:
  • N – BIN (6 digits)
  • C – number of the configuration data profiles (2 digits)
  • X – identify the account (4 to 9 digits)
  • Y – Check Digit based on the mod10 (Luhn) algorithm. Each card range will use account numbers with a fixed length ranging between 13 and 19 digits, as is allowed by the EMV 3-D Secure specifications [3DS_Core_2.x.0]. Note: The account numbers used by the test platform will not pass the mod10 algorithm (also known as the Luhn Algorithm) to avoid the usage of production grade account numbers for testing purposes. EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 3.2.2. Details on configuration data profiles EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 N° ID Account range - Start 1. UnsupportedDeviceConfigurationData 6543200100000 2. AuthenticationUnsupportedConfiguration 65432102000000 Data 3. 4. FrictionlessConfigurationData 7654310400000000 5. CardholderNotAuth 7654320500000000 6. CardholderCouldNotAuth 7654340600000000 7. CardholderAttemptedAuth 7654350700000000 8. CardholderRejected 7654360800000000 9. CardholderChallengeAcsRenderingType 7654370900000000 0101 10 CardholderChallengeAcsRenderingType 7654381000000000. 0102 11 CardholderChallengeAcsRenderingType 7654391100000000. 0103 12 CardholderChallengeAcsRenderingType 8765411200000000. 0104_no_OOB_automatic_switch Account range End 6543200199999 65432102999999 7654310499999999 7654320599999999 7654340699999999 7654350799999999 7654360899999999 7654370999999999 7654381099999999 7654391199999999 8765411299999999 Description Process as if the device is unsupported Process as if the authentication is not available due to the Configuration Data not representing a valid 3DS Account Perform Frictionless transStatus = Y authentication flow, Process such that transaction is not authenticated, transStatus = N Process as if authentication could not be performed, transStatus = U Process as if authentication could not be performed, transStatus = A Process as if authentication was available and rejected, transStatus = R Perform Challenge flow using acsRenderingType ["01", "01"] Perform Challenge flow using acsRenderingType ["01", "02"] Perform Challenge flow using acsRenderingType ["01", "03"] Perform Challenge flow using acsRenderingType ["01", "04"] The ACS does not include the oobAppURL field in the CRes messages. EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 13. 14 CardholderChallengeAcsRenderingType. 0201 15 CardholderChallengeAcsRenderingType. 0202 16 CardholderChallengeAcsRenderingType. 0203 17 CardholderChallengeAcsRenderingType. 0204 18 CardholderChallengeAcsRenderingType. 0205 19 CardholderOutOfRange. 20 CardholderOutOfRangeACS. 21. 22. 23. 24 CardholderAuthNotAvailable. 8765431400000000 8765441500000000 8765451600000000 8765461700000000 8765471800000000 8765481900000000 8765492000000000 8765431499999999 8765441599999999 8765451699999999 8765461799999999 8765471899999999 8765481999999999 8765492099999999 1876542400000000000 1876542499999999 999 Perform Challenge flow using acsRenderingType ["02", "01"] Perform Challenge flow using acsRenderingType ["02", "02"] Perform Challenge flow using acsRenderingType ["02", "03"] Perform Challenge flow using acsRenderingType ["02", "04"] Perform Challenge flow using acsRenderingType ["02", "05"] Process as if Cardholder Account Number is not in a participating account range, transStatus = U DS should process as if Cardholder Account Number is not in an account range that has an ACS capable of processing 3-D Secure messages, transStatus = U Process as if the Authentication is not available or cannot be completed for the cardholder. EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 25 CardholderFrictionlessNotContaining3D. SMethodURL 8765422500000000 26 CardholderFrictionlessNotContainingDS. ProtocolVersion 9876512600000000 27 CardholderChallenge. 28 CardholderChallengeHTML. 765430270000000 9876522800000000 8765422599999999 9876512699999999 765430279999999 9876522899999999 Perform Frictionless authentication flow, transStatus = Y, but the 3DS Method URL is not available in the PRes (only used by the 3DS Test Platform to construct the PRes message). Perform Frictionless authentication flow, transStatus = Y, but the dsEndProtocolVerison and dsStartProtocolVersion are not available in the entry for this account range in the Card Range Data returned in the PRes message (only used by the 3DS Test Platform to construct the PRes message). Perform Challenge flow. In the 01-APP device channel, the choice of acsRenderingType is up to the discretion of the System Under Test within the following restrictions: acsRenderingType indicates that a Native UI is being used, i.e. “acsInterface” equals to “01”. Perform Challenge flow. In the 01-APP device channel, the choice of acsRenderingType is up to the discretion of the System Under Test within the following restrictions: acsRenderingType indicates that an HTML UI is being used, i.e. “acsInterface” equals to “02”. ACS Information Indicator is set to [ “01”, “02”, “04” ] in the Card Range Data (for 3-D Secure Protocol Version Number 2.2.0 and later versions). EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 29 CardholderDecoupledAuthentication. 9876532900000000 30 CardholderForInformation. 9876543000000000 31 CardholderDecoupledMaxTimeExpired. 9876553100000000 32 CardholderDecoupledAuthAndWhiteListi 9876563200000000. ngNotSupported 9876532999999999 9876543099999999 9876553199999999 9876563299999999 Perform decoupled authentication, transStatus = D (in ARes message) (for 3-D Secure Protocol Version Number 2.2.0 and later versions). ACS Information Indicator is set to [ “01”, “02”, “03”, “04” ] in the Card Range Data. Note: threeDSRequestorDecReqInd may be set to either Y or B in the AReq message. Process for informational purpose, transStatus = I (in ARes message) (for 3-D Secure Protocol Version Number 2.2.0 and later version). ACS Information Indicator is set to ["01", "02", "03", "04", "05"] for Protocol Version "2.3.1" in the Card Range Data. Perform Decoupled Authentication (transStatus = D (in ARes message) in which the cardholder does not authenticate within the 3DS Requestor Decoupled Max Time. In that case the ACS does not send a request to Test OOB Server (no pOrq). The ACS sends the RReq message within the 30 second grace period maintained by the 3DS Server (only for 3-D Secure Protocol Version Number 2.2.0). ACS Information Indicator is set to [ “01”, “02”, “03”, “04” ] in the Card Range Data. Note: threeDSRequestorDecReqInd may be set to either Y or B in the AReq message. The ACS does not support Decoupled Authentication and Whitelisting for this account range (only for 3-D Secure Protocol Version Number 2.2.0). Return transStatus = C if challenge is required. ACS Information Indicator is set to [ “01”, “02” ] in the Card Range Data. EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 33 CardholderDeviceBinding_03Pending_1. 5BoundOther 9876573000100000 34 CardholderDeviceBinding_03Pending_0. 1NotBound 9876573000200000 9876573000199999 9876573000299999 Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow. In the 01-APP device channel, the choice of acsRenderingType is up to the discretion of the System Under Test. The ACS supports Device Binding with the following behavior when building messages:
  • ARes: deviceBindingStatus = 03
  • RReq: deviceBindingStatus = 15
  • CRes: in the 01-APP device channel, set deviceBindingInfoText = "Would you like to be remembered on this device?" ACS Information Indicator is set to ["01", "02", "03", "04", "05"] for Protocol Version "2.3.1" in the Card Range Data. Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow. In the 01-APP device channel, the choice of acsRenderingType is up to the discretion of the System Under Test. The ACS supports Device Binding with the following behavior when building messages:
  • ARes: deviceBindingStatus = 03
  • RReq: deviceBindingStatus = 01
  • CRes: in the 01-APP device channel, set deviceBindingInfoText = "Would you like to be remembered on this device?" ACS Information Indicator is set to ["01", "02", "03", "04", "05"] for Protocol Version "2.3.1" in the Card Range Data. EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 35 CardholderDeviceBinding_03Pending_0. 2NotEligible 9876573000300000 36 CardholderDeviceBinding_03Pending_0. 4Rejected 9876573000400000 9876573000399999 9876573000499999 Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow. In the 01-APP device channel, the choice of acsRenderingType is up to the discretion of the System Under Test. The ACS supports Device Binding with the following behavior when building messages:
  • ARes: deviceBindingStatus = 03
  • RReq: deviceBindingStatus = 02
  • CRes: in the 01-APP device channel, set deviceBindingInfoText = "Would you like to be remembered on this device?" ACS Information Indicator is set to ["01", "02", "03", "04", "05"] for Protocol Version "2.3.1" in the Card Range Data. Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow. In the 01-APP device channel, the choice of acsRenderingType is up to the discretion of the System Under Test. The ACS supports Device Binding with the following behavior when building messages:
  • ARes: deviceBindingStatus = 03
  • RReq: deviceBindingStatus = 04
  • CRes: in the 01-APP device channel, set deviceBindingInfoText = "Would you like to be remembered on this device?" ACS Information Indicator is set to ["01", "02", "03", "04", "05"] for Protocol Version "2.3.1" in the Card Range Data. EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 37 CardholderDeviceBinding_03Pending_0. 5Unknown 9876573000500000 9876573000599999 Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow. In the 01-APP device channel, the choice of acsRenderingType is up to the discretion of the System Under Test. The ACS supports Device Binding with the following behavior when building messages:
  • ARes: deviceBindingStatus = 03
  • RReq: deviceBindingStatus = 05
  • CRes: in the 01-APP device channel, set deviceBindingInfoText = "Would you like to be remembered on this device?" ACS Information Indicator is set to ["01", "02", "03", "04", "05"] for Protocol Version "2.3.1" in the Card Range Data. EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 38 CardholderChallengeDataEntry_MaskN. 9876574000100000 9876574000199999 Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow. In the 01-APP device channel, the choice of acsRenderingType is up to the discretion of the System Under Test. In the 01-APP device channel, the ACS sets the following field in the CRes messages:
  • challengeEntryBox = { "challengeDataEntryLabel": "Provide the required data for the test case.", "challengeDataEntryMasking": "N" } Applicable for 3DS Secure Protocol 2.2 supporting [Bridging_Mess_Ext] Perform Challenge flow. In the 01-APP device channel, the choice of acsRenderingType is up to the discretion of the System Under Test. In the 01-APP device channel, the ACS sets the following field in the CRes messages:
  • "challengeInfoLabel": "Provide the required data for the test case."
  • In the field specified in [Bridging_Mess_Ext] "challengeDataEntryMasking": “N” EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 39 CardholderChallengeDataEntry_MaskY_ 9876574000200000. ToggleY 9876574000299999 Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow. In the 01-APP device channel, the choice of acsRenderingType is up to the discretion of the System Under Test. In the 01-APP device channel, the ACS sets the following field in the CRes messages:
  • challengeEntryBox = { "challengeDataEntryLabel": "Provide the required data for the test case.", "challengeDataEntryMasking": "Y", "challengeDataEntryToggle": "Y" } EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 40 CardholderChallengeDataEntry_MaskY_ 9876574000300000. ToggleN 9876574000399999 Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow. In the 01-APP device channel, the choice of acsRenderingType is up to the discretion of the System Under Test. In the 01-APP device channel, the ACS sets the following field in the CRes messages:
  • challengeEntryBox = { "challengeDataEntryLabel": "Provide the required data for the test case.", "challengeDataEntryMasking": "Y", "challengeDataEntryToggle": "N" } Applicable for 3DS Secure Protocol 2.2 supporting [Bridging_Mess_Ext] Perform Challenge flow. In the 01-APP device channel, the choice of acsRenderingType is up to the discretion of the System Under Test. In the 01-APP device channel, the ACS sets the following field in the CRes messages:
  • "challengeInfoLabel": "Provide the required data for the test case."
  • In the field specified in [Bridging_Mess_Ext] "challengeDataEntryMasking": "Y" EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 41 CardholderChallengeDataEntry_Length. Max 9876574000400000 42 CardholderChallengeDataEntry_Keyboar 9876574000500000. d01 9876574000499999 9876574000599999 Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow. In the 01-APP device channel, the choice of acsRenderingType is up to the discretion of the System Under Test. In the 01-APP device channel, the ACS sets the following field in the CRes messages:
  • challengeEntryBox = { "challengeDataEntryLabel": "Provide the required data for the test case.", "challengeDataEntryLengthMax": "45" } Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow. In the 01-APP device channel, the choice of acsRenderingType is up to the discretion of the System Under Test. In the 01-APP device channel, the ACS sets the following field in the CRes messages:
  • challengeEntryBox = { "challengeDataEntryLabel": "Provide the required data for the test case.", "challengeDataEntryKeyboardType": "01" } EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 43 CardholderChallengeDataEntry_Keyboar 9876574000600000. d02 44 CardholderTogglePositionInd01_TrustLis 9876575000100000. t 9876574000699999 9876575000199999 Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow. In the 01-APP device channel, the choice of acsRenderingType is up to the discretion of the System Under Test. In the 01-APP device channel, the ACS sets the following field in the CRes messages:
  • challengeEntryBox = { "challengeDataEntryLabel": "Provide the required data for the test case.", "challengeDataEntryKeyboardType": "02" } Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow. In the 01-APP device channel, the choice of acsRenderingType is up to the discretion of the System Under Test. In the 01-APP device channel, the ACS sets the following fields in the CRes messages:
  • togglePositionInd = 01
  • trustListInfoText = "Would you like to add this Merchant to your Trust List?"
  • deviceBindingInfoText is not present. ACS Information Indicator is set to ["01", "02", "03", "04", "05"] for Protocol Version "2.3.1" in the Card Range Data. EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 45 CardholderTogglePositionInd01_Device. Binding 9876575000200000 46 CardholderTogglePositionInd01_TrustLis 9876575000300000. tAndDeviceBinding 9876575000299999 9876575000399999 Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow. In the 01-APP device channel, the choice of acsRenderingType is up to the discretion of the System Under Test. In the 01-APP device channel, the ACS sets the following fields in the CRes messages:
  • togglePositionInd = 01
  • trustListInfoText is not present.
  • deviceBindingInfoText = "Would you like to be remembered on this device?" ACS Information Indicator is set to ["01", "02", "03", "04", "05"] for Protocol Version "2.3.1" in the Card Range Data. Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow. In the 01-APP device channel, the choice of acsRenderingType is up to the discretion of the System Under Test. In the 01-APP device channel, the ACS sets the following fields in the CRes messages:
  • togglePositionInd = 01
  • trustListInfoText = "Would you like to add this Merchant to your Trust List?"
  • deviceBindingInfoText = "Would you like to be remembered on this device?" ACS Information Indicator is set to ["01", "02", "03", "04", "05"] for Protocol Version "2.3.1" in the Card Range Data. EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 47 CardholderChallengeAcsRenderingType 9876576000100000. 0104_with_OOB_automatic_switch 48 CardholderChallengeAcsRenderingType 9876576000200000. 0206_no_OOB_automatic_switch 49 CardholderChallengeAcsRenderingType 9876576000300000. 0206_with_OOB_automatic_switch 50 CardholderChallengeAcsRenderingType 9876577000100000. 0107 51 CardholderChallengeAcsRenderingType 9876577000200000. 0207 9876576000199999 9876576000299999 9876576000399999 9876577000199999 9876577000299999 Applicable for 3DS Secure Protocol 2.3.1 and later. Applicable for 3DS Secure Protocol 2.2 supporting [Bridging_Mess_Ext] Perform Challenge flow using acsRenderingType ["01", "04"] In the 01-APP device channel, the ACS sets the following field in the CRes messages (for 2.2 products, set also the field in messageExtension as specified in [Bridging_Mess_Ext])
  • oobAppURL Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow using acsRenderingType ["02", "06"] The ACS does not include the oobAppURL field in the CRes messages. Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow using acsRenderingType ["02", "06"] In the 01-APP device channel, the ACS sets the following field in the CRes messages:
  • oobAppURL Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow using acsRenderingType ["01", "07"] Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow using acsRenderingType ["02", "07"] EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 52 CardholderChallengeDeviceUserInterfac 9876578000100000. eMode01 53 CardholderChallengeDeviceUserInterfac 9876578000200000. eMode02 54 CardholderChallengeDeviceUserInterfac 9876578000300000. eMode03 55 CardholderChallengeDeviceUserInterfac 9876578000400000. eMode04 9876578000199999 9876578000299999 9876578000399999 9876578000499999 Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow. In the 01-APP device channel, the choice of acsRenderingType is up to the discretion of the System Under Test within the following restriction: "deviceInterfaceMode" equals to "01". Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow. In the 01-APP device channel, the choice of acsRenderingType is up to the discretion of the System Under Test within the following restriction: "deviceInterfaceMode" equals to "02". Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow. In the 01-APP device channel, the choice of acsRenderingType is up to the discretion of the System Under Test within the following restriction: "deviceInterfaceMode" equals to "03". Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow. In the 01-APP device channel, the choice of acsRenderingType is up to the discretion of the System Under Test within the following restriction: "deviceInterfaceMode" equals to "04". EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 56 CardholderInformationText. 9876579000100000 57 CardholderDsOnAcsBehalf. 9876579000200000 58 CardholderChallengeAdditionalLabel. 9876579000300000 9876579000199999 9876579000299999 9876579000399999 Applicable for 3DS Secure Protocol 2.3.1 and later. Perform decoupled authentication, transStatus = D (in ARes message). ACS Information Indicator is set to [ “01”, “02”, “03”, “04” ] in the Card Range Data. The ACS sets the following field in the ARes and RReq messages:
  • cardholderInfo = { "text": "Additional authentication is needed for this transaction, please contact (Issuer Name) at xxx-xxx-xxxx." } Applicable for 3DS Secure Protocol 2.3.1 and later. Applicable if feature "DS creates the ARes message on the ACS’s behalf " is supported. The DS creates the ARes messages on the ACS' behalf and returns transStatus = A. Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow. In the 01-APP device channel, the choice of acsRenderingType is up to the discretion of the System Under Test. In the 01-APP device channel, the ACS sets the following field in the CRes messages:
  • challengeAddLabel = "Additional choice button" EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 59 CardholderChallengeInformationTextIndi 9876579000400000. cator_Y 60 CardholderChallengeInformationTextIndi 9876579000500000. cator_N 61 CardholderChallengeAcsRenderingType 9876579000600000. 0107_challengeAddLabelNotPresent 62 CardholderChallengeAcsRenderingType 9876579000710000. 0101_with_challengeAddLabel 9876579000499999 9876579000599999 9876579000699999 9876579000719999 Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow. In the 01-APP device channel, the choice of acsRenderingType is up to the discretion of the System Under Test. In the 01-APP device channel, the ACS sets the following field in the CRes messages:
  • challengeInfoTextIndicator = "Y" Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow. In the 01-APP device channel, the choice of acsRenderingType is up to the discretion of the System Under Test. In the 01-APP device channel, the ACS sets the following field in the CRes messages:
  • challengeInfoTextIndicator = "N" Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow using acsRenderingType ["01", "07"] In the 01-APP device channel, the ACS does not include the challengeAddLabel field in the CRes messages. Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow using acsRenderingType ["01", "01"] In the 01-APP device channel, the ACS sets the following field in the CRes messages:
  • challengeAddLabel = "Additional choice button" EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 63 CardholderChallengeAcsRenderingType 9876579000720000. 0102_with_challengeAddLabel 64 CardholderChallengeAcsRenderingType 9876579000730000. 0103_with_challengeAddLabel 65 CardholderChallengeAcsRenderingType 9876579000740000. 0201_with_challengeAddLabel 9876579000729999 9876579000739999 9876579000749999 Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow using acsRenderingType ["01", "02"] In the 01-APP device channel, the ACS sets the following field in the CRes messages:
  • challengeAddLabel = "Additional choice button" Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow using acsRenderingType ["01", "03"] In the 01-APP device channel, the ACS sets the following field in the CRes messages:
  • challengeAddLabel = "Additional choice button" Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow using acsRenderingType ["02", "01"] In the 01-APP device channel, the ACS sets the following field in the CRes messages:
  • challengeAddLabel = "Additional choice button" EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 66 CardholderChallengeAcsRenderingType 9876579000750000. 0202_with_challengeAddLabel 67 CardholderChallengeAcsRenderingType 9876579000760000. 0203_with_challengeAddLabel 68 CardholderChallengeEntryBoxTwo. 9876579000810000 9876579000759999 9876579000769999 9876579000819999 Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow using acsRenderingType ["02", "02"] In the 01-APP device channel, the ACS sets the following field in the CRes messages:
  • challengeAddLabel = "Additional choice button" Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow using acsRenderingType ["02", "03"] In the 01-APP device channel, the ACS sets the following field in the CRes messages:
  • challengeAddLabel = "Additional choice button" Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow using acsRenderingType ["01", "01"] In the 01-APP device channel, the ACS provides a valid value for the following field in the CRes messages:
  • challengeEntryBoxTwo EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 69 CardholderChallengeDataEntryAutofill_B 9876579000821000. ox1 70 CardholderChallengeDataEntryAutofill_B 9876579000822000. ox2 9876579000821999 9876579000822999 Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow using acsRenderingType ["01", "01"] In the 01-APP device channel, the ACS provides a valid value for the following fields in the CRes messages:
  • challengeEntryBox o challengeDataEntryAutofill = Y
  • challengeEntryBoxTwo o challengeDataEntryAutofill is not present. Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow using acsRenderingType ["01", "01"] In the 01-APP device channel, the ACS provides a valid value for the following fields in the CRes messages:
  • challengeEntryBox o challengeDataEntryAutofill is not present.
  • challengeEntryBoxTwo o challengeDataEntryAutofill = Y EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 71 CardholderChallengeDataEntryAutofill_B 9876579000823000. ox1_Box2 9876579000823999 Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow using acsRenderingType ["01", "01"] In the 01-APP device channel, the ACS provides a valid value for the following fields in the CRes messages:
  • challengeEntryBox o challengeDataEntryAutofill = Y
  • challengeEntryBoxTwo o challengeDataEntryAutofill = Y EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 72 CardholderSPC_initiatedBy3DSRequest 9876579000910000. or 9876579000919999 Applicable for 3DS Secure Protocol 2.3.1 and later. In the 02-BRW device channel, perform an authentication flow with SPC initiated by the 3DS Requestor (transStatus = S). The ACS recognizes the threeDSReqAuthData Object values: following
  • { "value": "valid assertion data" }: the ACS returns transStatus = Y in the ARes message.
  • { "value": "invalid assertion data" }: the ACS returns transStatus = C in the ARes message and performs Challenge flow. The ACS shall emulate the interaction with FIDO (including enrollment of FIDO authenticator) and will return in ARes with any syntactically valid webAuthnCredList. If the spcIncompInd field is present in next AReq, perform Challenge flow (transStatus = C). The 3DSS behaves as following:
  • For the 1st AReq message (triggered with a pArq without 'threeDSServerTransID’ and threeDSRequestorSpcSupport = Y) 3DSS set threeDSRequestorSpcSupport = Y.
  • Receive the ARes message with transStatus = S, and consider the Object { "value": "valid assertion data" } as the threeDSReqAuthData. EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 73 CardholderSPC_initiatedByACS. 9876579000920000
  • For the 2nd AReq message (triggered with a pArq with ‘threeDSServerTransID’ equal to the value in outgoing 1st AReq sent by 3DSS and threeDSRequestorSpcSupport = Y), 3DSS computes and set threeDSRequestorAuthenticationInfo and threeDSRequestorPriorAuthenticationInfo according with the SPC flow (any timestamps are valid) 9876579000929999 ACS Information Indicator is set to ["01", "02", "03", "04", "05", "06", "07", "08", "09", "10", "11"] for Protocol Version "2.3.1" in the Card Range Data. Applicable for 3DS Secure Protocol 2.3.1 and later. In the 02-BRW device channel, perform an authentication flow with SPC initiated by the ACS (transStatus = C). The ACS recognises a pre-registered FIDO authenticator on the device for this Cardholder and uses the Authentication Method = 14 (SPC), in combination with Transaction Status = C to indicate to the 3DS Server that the ACS intends to perform SPC authentication as the challenge method ACS Information Indicator is set to ["01", "02", "03", "04", "05", "06", "07", "08", "09", "10", "11"] for Protocol Version "2.3.1" in the Card Range Data. EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 74 CardholderFrictionless_transChallengeE 9876579000931000. xemption_applied 75 CardholderFrictionless_transChallengeE 9876579000932000. xemption_79NoExemption 9876579000931999 9876579000932999 Applicable for 3DS Secure Protocol 2.3.1 and later. Applicable for 3DS Secure Protocol 2.2 supporting [Bridging_Mess_Ext] Perform Frictionless transStatus = Y authentication flow, In the ARes message, the ACS sets the transChallengeExemption field (for 2.2 products, the field is in the message extension [Bridging_Mess_Ext]) to the same value as the previously received threeDSRequestorChallengeInd in the corresponding AReq message. threeDSRequestorChallengeInd will contain one value, among 05, 08, 10, 11. Example: If threeDSRequestorChallengeInd is ["05"], the ACS will set transChallengeExemption = "05". Applicable for 3DS Secure Protocol 2.3.1 and later. Applicable for 3DS Secure Protocol 2.2 supporting [Bridging_Mess_Ext] Perform Frictionless transStatus = Y authentication flow, The ACS sets the following field in the ARes message: (for 2.2 products, the field is in the message extension [Bridging_Mess_Ext])
  • transChallengeExemption = 79 EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 76 CardholderFrictionless_threeDSMethodI 9876579000940000. d 77 CardholderSPC_initiatedBy3DSRequest 9876579000950100. or_spcIncompInd_01 9876579000940999 9876579000950199 Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Frictionless transStatus = Y authentication flow, In the AReq messages, if threeDSMethodId is absent, the ACS considers that the 3DS Method is used and successful. Applicable for 3DS Secure Protocol 2.3.1 and later. In the 02-BRW device channel, perform an authentication flow with SPC initiated by the 3DS Requestor (transStatus = S). The 3DSS behaves as following:
  • For the 1st AReq message (triggered with a pArq without 'threeDSServerTransID’ and threeDSRequestorSpcSupport = Y), 3DSS set threeDSRequestorSpcSupport = Y.
  • Receive the ARes message with transStatus = S
  • For the 2nd AReq message (triggered with a pArq with ‘threeDSServerTransID’ equal to the value in outgoing 1st AReq sent by 3DSS and threeDSRequestorSpcSupport = Y and spcIncompInd = 01), 3DSS sets spcIncompInd to 01 ACS Information Indicator is set to ["01", "02", "03", "04", "05", "06", "07", "08", "09", "10", "11"] for Protocol Version "2.3.1" in the Card Range Data. EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 78 CardholderSPC_initiatedBy3DSRequest 9876579000950200. or_spcIncompInd_02 79 CardholderOperation_toACS_seqTotal_. 01 9876579000960100 9876579000950299 9876579000960199 Applicable for 3DS Secure Protocol 2.3.1 and later. In the 02-BRW device channel, perform an authentication flow with SPC initiated by the 3DS Requestor (transStatus = S). The 3DSS behaves as following:
  • For the 1st AReq message (triggered with a pArq without 'threeDSServerTransID’ and threeDSRequestorSpcSupport = Y), 3DSS set threeDSRequestorSpcSupport = Y.
  • Receive the ARes message with transStatus = S
  • For the 2nd AReq message (triggered with a pArq with ‘threeDSServerTransID’ equal to the value in outgoing 1st AReq sent by 3DSS and threeDSRequestorSpcSupport = Y and spcIncompInd = 02), 3DSS sets spcIncompInd to 02 ACS Information Indicator is set to ["01", "02", "03", "04", "05", "06", "07", "08", "09", "10", "11"] for Protocol Version "2.3.1" in the Card Range Data. Applicable for 3DS Secure Protocol 2.3.1 and later. The DS behaves as following at the ARes message:
  • In addition to the normal flow, send an OReq message to the ACS where:
  • OReq with seqNum = 01 and seqTotal = 01
  • OReq message is syntactically valid. EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 80 CardholderOperation_toACS_seqTotal_. 02 9876579000960200 81 CardholderOperation_to3DSS_seqTotal. _01 9876579000960300 9876579000960299 9876579000960399 Applicable for 3DS Secure Protocol 2.3.1 and later. The DS behaves as following at the ARes message:
  • In addition to the normal flow, send two OReq messages to the ACS where: o 1st OReq with seqNum = 01 and seqTotal = 02 o 2nd OReq with seqNum = 02 and seqTotal = 02
  • All OReq messages are syntactically valid. Applicable for 3DS Secure Protocol 2.3.1 and later. The DS behaves as following at the ARes message:
  • In addition to the normal flow, send an OReq message to the 3DSS where:
  • OReq with seqNum = 01 and seqTotal = 01
  • OReq message is syntactically valid. EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 82 CardholderOperation_to3DSS_seqTotal. _02 9876579000960400 83 CardholderChallengeAcsRenderingType 9876579000770000. 0104_with_challengeAddLabel 9876579000960499 9876579000779999 Applicable for 3DS Secure Protocol 2.3.1 and later. The DS behaves as following at the ARes message:
  • In addition to the normal flow, send two OReq messages to the 3DSS where: o 1st OReq with seqNum = 01 and seqTotal = 02 o 2nd OReq with seqNum = 02 and seqTotal = 02
  • All OReq messages are syntactically valid. Applicable for 3DS Secure Protocol 2.3.1 and later. Perform Challenge flow using acsRenderingType ["01", "04"] In the 01-APP device channel, the ACS sets the following field in the CRes messages:
  • challengeAddLabel = "Additional choice button" EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 84 CardholderDecoupledAuthenticationFall. back 9876579000970000 85 CardholderDecoupledAuthenticationFall. back_0101 9876579000981000 86 CardholderDecoupledAuthenticationFall. back_0102 9876579000982000 9876579000979999 9876579000981999 9876579000982999 Applicable for 3DS Secure Protocol 2.3.1 and later. ACS Information Indicator is set to [ “01”, “02”, “03”, “04” ] in the Card Range Data. First, perform Challenge flow. In the 01-APP device channel, the choice of acsRenderingType is up to the discretion of the System Under Test. The ACS determines that Decoupled Authentication Fallback is necessary (authentication have been attempted but can be either not completed or completed). In the Final CRes, the ACS sets transStatus = Y or N whether the authentication was completed or not completed, respectively. During the subsequent 3RI Decoupled Authentication, the ACS behaves as for the CardholderDecoupledAuthentication card range. Applicable for 3DS Secure Protocol 2.3.1 and later. Same as CardholderDecoupledAuthenticationFallback, except that for Challenge flow in the 01-APP device channel, acsRenderingType is set to ["01", "01"]. Applicable for 3DS Secure Protocol 2.3.1 and later. Same as CardholderDecoupledAuthenticationFallback, except that for Challenge flow in the 01-APP device channel, acsRenderingType is set to ["01", "02"]. EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 87 CardholderDecoupledAuthenticationFall. back_0103 9876579000983000 88 CardholderDecoupledAuthenticationFall. back_0104 9876579000984000 89 CardholderDecoupledAuthenticationFall. back_0205 9876579000985000 90 CardholderDecoupledAuthenticationFall. back_0206 9876579000986000 9876579000983999 9876579000984999 9876579000985999 9876579000986999 Applicable for 3DS Secure Protocol 2.3.1 and later. Same as CardholderDecoupledAuthenticationFallback, except that for Challenge flow in the 01-APP device channel, acsRenderingType is set to ["01", "03"]. Applicable for 3DS Secure Protocol 2.3.1 and later. Same as CardholderDecoupledAuthenticationFallback, except that for Challenge flow in the 01-APP device channel, acsRenderingType is set to ["01", "04"]. Applicable for 3DS Secure Protocol 2.3.1 and later. Same as CardholderDecoupledAuthenticationFallback, except that for Challenge flow in the 01-APP device channel, acsRenderingType is set to ["02", "05"]. Applicable for 3DS Secure Protocol 2.3.1 and later. Same as CardholderDecoupledAuthenticationFallback, except that for Challenge flow in the 01-APP device channel, acsRenderingType is set to ["02", "06"]. Notes: In case the card ranges are included in the ‘cardRangeData’ data element in the PRes message: 1. All the Card Ranges should include threeDSMethodURL except from CardholderFrictionlessNotContaining3DSMethodURL (No.25) in which the threeDSMethodURL should be absent EMV® 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 2. All the Card Ranges should include the relevant Protocol Version elements except from CardholderFrictionlessNotContainingDSProtocolVersion (No.26), in which the dsEndProtocolVerison and dsStartProtocolVersion should be absent. The values should be in line with the version of EMV® 3D Secure Protocol and Core Functions specification supported by the System Under Test. 3. As account numbers from card ranges number 19 and 20 are to be treated as ‘not participating’, a DS as System Under Test most likely does not want to list these two ranges in the ‘cardRangeData’ data element in the PRes messages. Absence or presence of these two ranges will not affect the outcome of the DS specific test cases available in the platform. 4. Unless otherwise mentioned in the table above, the optional ACS Information Indicator shall be either absent or at least set to [ “01”, “02”, “04” ] in the relevant entries of the ‘cardRangeData’ data element. Furthermore, receiving systems should consider any account numbers that are not part of the card ranges listed in this section as not belonging to the Issuer (hence resulting in Error Code ‘305’). EMV 3-D Secure Approval Test Requirements for all Systems Under Test v2.14 / 49 *** END OF DOCUMENT *** © 2020-2024 EMVCo, LLC. All rights reserved. Reproduction, distribution and other use of this document is permitted only pursuant to the applicable agreement between the user and EMVCo found at www.emvco.com. EMV® is a registered trademark or trademark of EMVCo, LLC in the United States and other countries.