SB n° 279 EMV® 3-D Secure Protocol and Core Functions Specification v2.2.0–2.3.1.1
EMV® Specification Bulletin No. 279 Second Edition August 2025 EMV® 3-D Secure Protocol and Core Functions Specification version 2.3.1.1 This Specification Bulletin No. 279 provides the updates, clarifications and errata incorporated into the EMV® 3-D Secure Protocol and Core Functions Specification since version 2.2.0 (as amended by Specification Bulletin No. 214v3). The purpose of this Specification Bulletin is to document all the differences between version 2.2.0 (as amended by Specification Bulletin No. 214v3) and version 2.3.1.1 of the EMV® 3-D Secure Protocol and Core Functions Specification for ease of reference.
Applicability
This Specification Bulletin applies to:
- EMV® 3-D Secure Protocol and Core Functions Specification, Version 2.3.1.1 Updates are provided in the order in which they appear in the specification. Deleted text is identified using strikethrough, and red font is used to identify changed text. Green double underline is used to indicate moved text. Unedited text is provided only for context.
Related Documents
- EMV® 3-D Secure Protocol and Core Functions Specifications Version 2.2.0 (as amended by Specification Bulletin No. 214v3)
- EMV® 3-D Secure Protocol and Core Functions Specifications Version2.3.1.1
Effective Date
- August 2025 countries. Contents EMV® 3-D Secure Protocol and Core Functions Specification version 2.3.1.1. Table 1. 1. Table 1. 1. Table 1. 1. Table 1. 1. 1. 1. 1. 2. 2.1. 2.1. 2. 2.2. 2.2. 2. 2.4. 2.4. 2.4. 2.4. 2.4. 2.4. 2. 2.6. 2. 3. countries. countries. 3. 3.2. 3.2. 3. countries. 3. 3. 4. 4. countries. Figure 4. Figure 4. Figure 4. 4.2. 4.2. Figure 4.124. Figure 4.134. Figure 4. Figure 4. Figure 4.144. Figure 4.154. Figure 4.164. Figure 4.194. Figure 4.204. Figure 4. Figure 4. Figure 4.214. Figure 4.224. Figure 4.234. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. countries. Figure 4. Figure 4. 4.2. 4.2. 4.2. Figure 4. Figure 4. Figure 4. Figure 4.44: Sample OOB HTML UI Template with OOB App URL button—PA—Landscape... 45 Figure 4. Figure 4. 4.2. 4. 4.3. 4.3. 4.3. Figure 4. Figure 4. countries. 5. 5.1. 5.1. 5.1. 5.1. 5.1. 5.1. 5. 5. 5.5. countries. 5.5. 5. 5. 5.7. 5. 5.8. 5. 5.9. 5.9. countries. 5.9. 5.9. 5.9. 5. 5. 6. 6.1. 6.1. 6. 6.2. 6.2. 6.2. 6.2. A. Table A. A. A.5.1A. A.5.2A. A.5.3A. Table A. A.5.4A. Table A. A.5.5A. countries. Table A. A.5.6A. A.5.7A. Table A. Table A. A.11. Table A. A.6A. A.6.1A.12. A.6.2A.12. A.6.3A.12. A.7A. A.7.1A.13. Table A.8A. A.7.2A.13. Table A.9A. A.7.3A.13. Table A.10A. A.7.4A.13. Table A. A.13. Table A. A.13. Table A.13A. A.13. Table A.14A. A.7.8A.13. Table A.15A. A.13. A.13. A.8A. Table A.18A. A.14. countries. Table A.16A. A.13.10A.14. Table A.17A. A. A. A. A. A. A. A. A. B. Table B. B. Table B. B. Table B. B. Table B. B. Table B. B. Table B. B. Table B. B. B. countries. Throughout Specification
- To facilitate enhanced version number management, a fourth digit was added to the 3-D Secure Protocol and Core Functions Specification version number: 2.3.1.x.
- Data element name/terminology updates:
- ACS Start Protocol Version/ACS End Protocol Version data elements were updated to a single element: ACS Protocol Version
- DS Start Protocol Version/DS End Protocol Version were updated to a single element: DS Protocol Version
- BIN range was changed to card range.
- All instances of White List, whitelisted, whitelisting were updated to Trust List. Figure 4.26 and Figure 4.27 were updated to include this data element update.
- All instances of challenge window were changed to challenge iframe.
- Annex A Section and Table references may be updated throughout the specification to reflect changes made in Annex A for version 2.3.1.0.
- Instances of SDK were replaced with 3DS SDK.
- In Section 5.9, references to Section 5.1.6 were replaced with references to Section 5.1.7.
- Revisions added to improve grammar, consistency, clarity and readability without any effect on the meaning or interpretation of the specification are not included in this bulletin.
- Updates made to defined abbreviations, such as EC(C) and DH (Diffie–Hellman), have no substantive effect on the use of the underlying specification and are not reflected in this bulletin. countries. Chapter 1
Introduction
The 3-D Secure authentication protocol can be initiated through three Device Channels:
- Browser-based—Authentication during a transaction on a Consumer Device that originates from a website utilising a browser Browser as defined in Table 1.3.
1.3 Normative
References
Table 1.1 Normative References Reference Publication Name Bookmark IETF BCP 47 Tags for Identifying Languages https://tools.ietf.org/html/bc p47 RFC 2397 The "data" URL scheme https://datatracker.ietf.org/ doc/html/rfc2397 RFC 3986 Uniform Resource Identifier (URI): Generic Syntax https://tools.ietf.org/html/rfc 3986 RFC 791 INTERNET PROTOCOL https://tools.ietf.org/html/rfc 791 RFC 4291 IP Version 6 Addressing Architecture https://tools.ietf.org/html/rfc 4291 RFC 7233 Hypertext Transfer Protocol (HTTP/1.1): Range Requests https://datatracker.ietf.org/ doc/html/rfc7233 1.4 Acknowledgements The following ISO Standards are referenced in this specification. The latest version including all published amendments shall apply unless a publication date is explicitly stated.
countries.
Table 1.2 ISO Standards Reference Publication Name Bookmark ISO/IEC 7812-1:2015 ISO/IEC 7812-1:2015 Identification cards—Identification of issuers—Part 1: Numbering system ISO/IEC 7813:2016 ISO/IEC 7813:2016 Information technology— Identification cards—Financial transaction cards ISO/IEC 7816-5:2004 ISO/IEC 7816-5:2004 Identification cards—Integrated circuit cards—Part 5: Registration of application providers ISO 8583-1 ISO 8583-1 Financial transaction card originated messages — Interchange message specifications — Part 1: Messages, data elements and code values https://www.iso. org/standard/31 628.html 1.5
Definitions
Table 1.3 Definitions Term Definition 3DS SDK 3-D Secure Software Development Kit (SDK). A component that is incorporated intointeracts with the 3DS Requestor App. The 3DS SDK performs functions related to 3-D Secure on behalf of the 3DS Server. Access Control The ACS UI is generated during a Cardholder challenge and is rendered Server User Interface by the ACS within a Browser challenge windowiframe. (ACS UI) App Screen Orientation The orientation of the app screen display on the device, which may differ from the device orientation (for example, if the app supports Portrait-only or Landscape-only display, or if the device is in multi-window or splitscreen mode). The orientation is considered Landscape if the display is wider than it is tall, and Portrait otherwise. Bank Identification Number (BIN) The first six or eight digits of a payment card account number that uniquely identifies the issuing financial institution. Base64url Encoding applied to the 3DS Method Data, Device Information, WebAuthn Credential List and the CReq/CRes messages as defined in RFC 7515. Card Range Data File The file containing the JSON Card Range Data object. The Card Range Data provides to the 3DS Server the 3DS protocol versions supported by the card ranges hosted by the ACS, and other optional information (e.g. 3DS Method, Message Extension).
countries.
Term Definition Decoupled Authentication Fallback An additional challenge option for an ACS during the Challenge process. By returning Transaction Status = D in the RReq message, the ACS requests that the 3DS Server initiate a subsequent 3DS authentication using Decoupled Authentication. Device Binding In this specification, the process to link the Consumer Device used for a transaction to the Cardholder Account and/or Cardholder. Ends processing In the 3-D Secure processing flow, this indicates that an error has been found by a specific 3-D Secure component, which reports the error via the appropriate Error Message as defined in Section A.5.5A.9 or RReq message as defined in Table B.8. Fully Qualified URL A Fully Qualified URL contains all the information necessary to locate a web resource using the following format: scheme://server/path/resource, and is defined as an ‘Absolute-URL string’ with scheme ‘https’, encoded in 'UTF-8' using 'url-code-points' from https://whatwg.org/. Refer to https://url.spec.whatwg.org/#absolute-url-string and to https://url.spec.whatwg.org/#url-code-points A Fully Qualified URL does not contain credentials (https://url.spec.whatwg.org/#include-credentials). Example: https://server.domainname.com/acs/auth.htmlhttps://server.domainname.c om/acs/auth(*ret iframe An iframe (short for inline frame) is a frame within a frame. It is used to embed a piece of HTML content from other sources in an HTML document. Refer to: w3c: https://www.w3.org/html/wg/spec/the-iframe-element.html#theiframe-element OR whatwg: https://html.spec.whatwg.org/#the-iframe-element OOB Authentication App App on a Consumer Device that is used by the ACS to authenticate the Cardholder as part of the 3-D Secure flow, for example, a mobile banking app. See Section 3.2 for details of the OOB flow. Operation Request (OReq) Message The OReq message sequence is created to communicate operational information serving as an alert, a reminder, report, or call to action. This message is not part of the 3-D Secure authentication message flow. Operation Response (ORes) Message The ORes message acknowledges receipt of the OReq message sequence. The message is created by the recipient of the OReq message and sent to the source of the OReq message. Platform Provider An entity that provides a digital ecosystem consisting of an operating system and/or hardware components, capable of uniquely identifying the consumer and their device through a user ID and a hardware-derived device ID, and sharing these IDs for the purposes of risk assessment and fraud prevention.
countries.
Term Definition Preparation Response (PRes) Message Response to the PReq message that contains the DS Card Ranges, active Protocol Versions for the ACS and DS and 3DS Method URL, or a Card Range Data File URL to download this information, so that updates can be made to the 3DS Server’s internal storage. Protocol Version Refers to the version of the EMV 3-D Secure specification that the component supports. The protocol version for this specification is 2.1.0. Defines the message interoperability between the EMV 3-D Secure components. Responsive Design Responsive design is an approach to make the web page content adjust to the dimensions of the device's screen for a better user experience. The approach is based on the use of three web techniques when designing the web pages:
- Flexible grid to create the web page layout that dynamically adapt to the screen width.
- Media queries to allow the page to adopt different CSS styles depending on the Browser and device screen.
- Flexible media to make images scalable to the size of the viewport. Secure Payment Confirmation FIDO-based authentication to securely confirm payments initiated via the Payment Request API on a Browser (refer to w3.org for additional information). Token Service Provider A role within the Payment Tokenisation ecosystem that is authorised by a Token Programme to provide Payment Tokens to registered Token Requestors. Refer to the EMV® Payment Tokenisation Specification Technical Framework. Trust List Whitelisting In this specification, the process of an ACS enabling the Cardholder to place the 3DS Requestor on their trusted beneficiaries list. WebAuthn Defines an API enabling the creation and use of strong, attested, scoped, public key-based credentials by web applications, for the purpose of strongly authenticating users. Refer to https://www.w3.org/TR/webauthn-2/ 1.6 Abbreviations Table 1.4 Abbreviations Abbreviation
Description
AOC Attestation of Compliance CA DS Certificate Authority Directory Server CEK Content Encryption Key DH Diffie–Hellman
countries.
Abbreviation Description DS CA Directory Server Certificate Authority ECC Elliptic Curve Cryptography LOA Letter of Approval OReq Operation Request Message ORes Operation Response Message SPC Secure Payment Confirmation 1.7 3-D Secure Protocol Version Number The following table provides the Protocol Version Number status for the EMV 3-D Secure Protocol and Core Functions Specification. Refer to EMV® Specification Bulletin 255 for the list of active Protocol Version Numbers. Table 1.5 Protocol Version Numbers was removed from the specification.
1.8 Supporting Documentation
- EMV® 3-D Secure—Split-SDK Specification
- EMV® 3-D Secure Message Extensions
- EMV® 3-D Secure Bridging Message Extension
- EMV® 3-D Secure Device Acknowledgement Message Extension
- EMV® 3-D Secure Payment Token Message Extension
- EMV® 3-D Secure Travel Industry Message Extension
- EMV® Specification Bulletin 255—3-D Secure Protocol Version Numbers 1.9 Terminology and Conventions 3DS SDK When this specification refers to the 3DS SDK, EMVCo has defined two options for a 3DS SDK implementation. The options are as follows: 1. Default SDK—Software component designed as an SDK that is integrated into a 3DS Requestor App. This SDK option is defined in the EMV 3-D Secure—SDK Specification, in which it is referred to as the 3DS SDK. In earlier versions of this Core Specification, this is referred to as the 3DS SDK. 2. Split-SDK—Client-server implementation of the 3DS SDK. Some functions of the SplitSDK entity can be performed by either a Split-SDK Client or a Split-SDK Server or, in some situations, both. The Split-SDK has multiple variants depending on the Consumer Device and the 3DS Requestor Environment. These variants include the SplitSDK/Native, Split-SDK/Shell and Split-SDK/Browser, and each is defined in the EMV 3-D Secure—Split-SDK Specification. Unless explicitly noted otherwise, the term 3DS SDK applies as identified above. countries. Refer to the applicable 3DS SDK specification for detailed information regarding the SDK options. Activate(s) the 3DS SDK Detailed information about the 3DS SDK activation can be obtained in the applicable 3DS SDK specification. Perform(s) the Challenge Detailed information about the 3DS SDK performing the challenge can be obtained in the applicable 3DS SDK specification.
1.10 Constraints The Core Specification or any implementation of the Core Specification is not intended to replace or interfere with any international, regional, national or local laws and regulations; those governing requirements supersede any industry standards.
countries.
Chapter 2 EMV 3-D Secure Overview 2.1 Acquirer Domain 2.1.1 3DS Requestor Environment 2.1.1.1 3DS Requestor To process 3-D Secure transactions:
- App-based—3DS Requestor App integrates with the 3DS SDK as defined in the applicable EMV 3-D Secure 3DS SDK Specificationspecification. The 3DS SDK displays the User Interface (UI) to Cardholders. 2.1.2 3DS Integrator (3DS Server and 3DS Client) The 3DS Integrator provides the approved 3DS SDK component or the 3DS Method functionality to 3DS Requestors for integration into with their 3DS Requestor App and/or website.
2.2 Interop
Only this document's contents pages are available. Read the original for the body text.