EMV® 3-D Secure Protocol and Core Functions Specification

v2.3.0.0 Specifications
3-D Secure

EMV® 3 -D Secure Protocol and Core Functions Specification Version 2.3.0.0 September 2021 EMV 3-D Secure Protocol and Core Functions Specification v2.3.0.0 Legal Notice

/ xvii

countries.

Legal Notice

The EMV® Specifications are provided "AS IS" without warranties of any kind, and EMVCo neither assumes nor accepts any liability for any errors or omissions contained in these Sp ecifications. EMVCO DISCLAIMS ALL REPRESENTATIONS AND WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NON - INFRINGEMENT, AS TO THESE SPECIFICATIONS. EMVCo makes no representations or warranties with respect to intellectual property rights of any third parties in or in relation to the Specifications. EMVCo undertakes no responsibility to determine whether any implementation of the EMV® Specifications may viol ate, infringe, or otherwise exercise the patent, copyright, trademark, trade secret, know -how, or other intellectual property rights of third parties, and thus any person who implements any part of the EMV® Specifications should consult an intellectual pro perty attorney before any such implementation. Without limiting the foregoing, the Specifications may provide for the use of public key encryption and other technology, which may be the subject matter of patents in several countries. Any party seeking to implement these Specifications is solely responsible for determining whether its activities require a license to any such technology, including for patents on public key encryption technology. EMVCo shall not be liable under any theory for any party’s inf ringement of any intellectual property rights in connection with the EMV® Specifications. EMV 3-D Secure Protocol and Core Functions Specification v2.3.0.0 Revision Log

/ xvii

countries. Revision Log The following table lists the version history for the EMV 3 -D Secure Protocol and Core Functions Specification. EMVCo Specification Bulletins provide the detailed updates made with each specification release. Version Release Date Associated Specification Bulletins 2.0.0 October 2016

  • SB 190: 3-D Secure

Requirement

Numbering Scheme and Error Processing

  • SB 196: 3 -D Secure Updates, Clarifications & Errata 2.1.0 October 2017
  • SB 204v4: 3 -D Secure Updates, Clarifications & Errata
  • SB 214v1 EMV® 3-D Secure Updates, Clarifications & Errata 2.2.0 December 2018
  • SB 207: 3-D Secure Updates, Clarifications & Errata 2.3.0.0 September 2021
  • SB 227 v1 EMV<sup>®</sup> 3 -D Secure Key Features v2.3.0.0 EMV 3-D Secure Protocol and Core Functions Specification v2.3.0.0 Contents / xvii countries 1 1 1 1 1 1 1 1 1 1 2 2.1 2.1.1 2.1.1 2.1.1 2.1 2.1 2 2.2 2.2 2.2 2 2.3.. 39 2.3 2.3 2.3 2 EMV 3-D Secure Protocol and Core Functions Specification v2.3.0.0 Contents Page v / xvii countries. 2.4 2.4 2.4 2.4 2.4 2.4 2.4 2.4 2.4 2.4 2.4 2 2.5 2.5 2.5 2 2.6 2.6 2.6 2 3 EMV 3-D Secure Protocol and Core Functions Specification v2.3.0.0 Contents / xvii countries 3 3.2 3.2 3.2.2 3.2.2 3... 79 EMV 3-D Secure Protocol and Core Functions Specification v2.3.0.0 Contents / xvii countries 3 3 3.5 3.5 4 4.2 4.2.1 4.2 4.2.2 4.2 4.2 EMV 3-D Secure Protocol and Core Functions Specification v2.3.0.0 Contents / xvii countries. 4.2.4 4.2.4 4.2.4 4.2 4.2.5 4.2 4.2.6... 133 4.2 4.2.7 4.2.7 4.2.7 4 4.3 4.3.1 4.3.1 4.3 4.3.2 4.3 4 5 5.1 5.1.. 145 5.1 5.1 5.1 5.1 5.1 5 5 5 5 5.5 5.5 5.5.2 5.5.2 5 EMV 3-D Secure Protocol and Core Functions Specification v2.3.0.0 Contents / xvii countries. 5 5.7 5 5.8 5.8.1 5.8.1 5.8 5 5.9 5.9 5.9 5.9.3 5.9.3 5.9 5.9 5.9.5 5.9 5.9 5.9 5.9.8 5.9 5.9 5.9 5.9 5.9 5 5.. 172 6 6.1 6.1 6.1.2 6.1.2 6.1 6.1.3 6.1.3 6.1 6.1.4. 175 EMV 3-D Secure Protocol and Core Functions Specification v2.3.0.0 Contents Page x / xvii countries. 6.1.4 6.1. 6.1. 6.1. 6.1 6 6.2 6.2 6.2.2 6.2.2 6.2.2. 179 6.2.2. 6.2. 6.2.3 6.2.3 6.2.3 6.2 6.2.4 6.2.4 6.2.4 6.2.4 A A.. 187 A A A A... 292 A A A A A A.11 EMV 3-D Secure Protocol and Core Functions Specification v2.3.0.0 Contents / xvii countries A A.12.. 313 A.12 A.12... 314 A A.13 A.13 A.13 A.13. A.13 A.13 A.13 A.13. 333 A.13 A.13 A. 344 A.14 A.14 A A A A A A A B B B B B... 375 B B EMV 3-D Secure Protocol and Core Functions Specification v2.3.0.0 Contents / xvii countries. B B B B B C C C.2 D.1 Cipher Suites for TLS 1.2 D.1 D.1 D EMV 3-D Secure Protocol and Core Functions Specification v2.3.0.0 Figures / xvii countries. Figures Figure 2 Figure 2 Figure 2. Figure 2 Figure 2... 46 Figure 2. 47 Figure 3 Figure 3 Figure 3 Figure 3 Figure 3 Figure 4 Figure 4 Figure 4 Figure 4 Figure 4. Figure 4 Figu re 4 Figure 4 Figure 4. Figure 4 Figure 4. Figure 4. Figure 4.13: Sample Decoupled Authentication Template — App -based Processing Flow 103 Figure 4... 106 Figure 4. Figure 4 Figure 4 Figure 4 Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4.24: Sample OOB Native UI Template with Complete button — PA — Landscape. 114 Figure 4 EMV 3-D Secure Protocol and Core Functions Specification v2.3.0.0 Figures / xvii countries. Figure 4 Figure 4 Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4 Figure 4 Figure 4 Figure 4 Figure 4... 126 Figure 4. Figure 4 Figure 4. Figure 4.42: Sample OOB HTML UI Template with Complete button — PA — Landscape. 129 Figure 4.43: Sample OOB HTML UI Template with OOB App URL button — PA — Portrait 130 Figure 4 Figure 4 Figure 4... 133 Figure 4 Figure 4 Figure 4 Figure 4. Figure 4. Figure 4 Figure 4 Figure 6 Figure 6 Figure 6 Figure A. Figure A. EMV 3-D Secure Protocol and Core Functions Specification v2.3.0.0 Tables / xvii countries. Tables Table 1 Table 1... 20 Table 1 Table 1 Table A Table A Tabl e A Table A Table A Table A Table A Table A Table A Table A Table A Table A Table A. Table A Table A Table A Table A Table A Table A Table A Table A.. 348 Table A Table A Table A Table A Table A Table A 8 Table A Table B Table B Table B Table B Table B Table B Table B Table B Table B EMV 3-D Secure Protocol and Core Functions Specification v2.3.0.0 Tables / xvii countries. Table B Table B Table B EMV 3-D Secure Protocol and Core Functions Specification v2.3.0.0 Introduction / 397 countries. 1

Introduction

The 3-D Secure authentication protocol is based on a three -domain model where the Acquirer Domain and Issuer Domain are connected by the Interoperability Domain for the purpose of authenticating a Cardholder during an electronic commerce (e -commerce) transacti on or to provide identity verifica tion and account confirmation. The 3 -D Secure authentication protocol supports two Message Categories:

  • Payment Authentication — Cardholder authenticati on during an e -commerce transaction.
  • Non -Payment Authentication — Identity verification and account confirmat ion. The 3 -D Secure authentication protocol can be initiated through three Device Channels:
  • App -based — Authentication during a transaction on a Consumer Device that originates from an App provided by a 3DS Requestor (merchant, digital wallet, et al). For e xample, an e -commerce transaction originating during a check -out process within a merchant’s app.
  • Browser -based — Authentication during a transaction on a Consumer Device that originates from a web site utilising a browser as defined in Table 1.3. For example, an e-commerce transaction originat ing during a check -out process within a web site on a Consumer Device.
  • 3DS Requestor Initiated — Confirmation of account information and Cardholder authentication with no direct Cardholder present. For example, a subscription -based e-commerce merchant confirm ing that an account is still valid or Cardholder authentication when the 3DS Requester and the ACS utili ses Decoupled Authentication. 1.1

Purpose

The purpose of this EMV 3 -D Secure Protocol and Core Functions Specification is to describe the EMV 3-D Secure infrastructure and components, and to specify the requirements for each component within the infrastructure and their interaction. For purposes of this document, when the phrase 3 -D Secure, and/or 3DS is utilis ed, the intent is EMV 3 -D Secure.

1.2 Audience This document is intended for stakeholde rs develop ing EMV 3-D Secure products and support ing 3-D Secure implementations. EMV 3-D Secure Protocol and Core Functions Specification v2.3.0.0 Introduction

/ 397

countries.

1.3 Normative

References

The following standards contain provisions that are referenced in this specification. The latest version including all published amendments shall apply unless a publication date is explicitly stated. Table 1.1: Normative References Reference Publication Name Bookmark IETF BCP 47 Tags for Identifying Languages https://tools.ietf.org/ht ml/bcp47 ITU; ITU -T. E.164 The International Public Telecommunication Numbering Plan https://www.itu.int/rec /T-REC -E.164/en RFC 2045 Multipurpose Internet Mail Extensions (MIME) Part One: Format of Internet Message Bodies https://tools.ietf.org/ht ml/rfc2045 RFC 2397 The "data" URL scheme https://datatracker.ietf.org/doc/html/rfc2397 RFC 2616 Hypertext Transfer Protocol -- HTTP/1.1 https://tools.ietf.org/ht ml/rfc2616 RFC 3447 PKCS #1: RSA Cryptography Specifications https://www.ietf.org/rf c/rfc3447.t xt RFC 3986 Uniform Resource Identifier (URI): Generic Syntax https://tools.ietf.org/ht ml/rfc3986 RFC 4122 A Universally Unique IDentifier (UUID) URN Namespace https://tools.ietf.org/ht ml/rfc4122 RFC 4158 Internet X.509 Public Key Infrastructure: certification Path Building https://tools.ietf.org/ht ml/rfc4158 RFC 5246 The Transport Layer Security (TLS) Protocol Version 1.2 https://tools.ietf.org/ht ml/rfc5246 RFC 5322 Internet Message Format https://tools.ietf.org/ht ml/rfc5322 RFC 7159 The JavaScript Object Notation (JSON) Data Interchange Format https://tools.ietf.org/ht ml/rfc7159 RFC 7231 Hypertext Transfer Protocol (HTTP/1.1): Semantics and Content https://tools.ietf.org/ht ml/rfc7231 RFC 7515 JSON Web Signatures (JWS) https://tools.ietf.org/ht ml/rfc7515 RFC 7516 JSON Web Encryption (JWE) https://tools.ietf.org/ht ml/rfc7516 EMV 3-D Secure Protocol and Core Functions Specification v2.3.0.0 Introduction

/ 397

countries. Reference Publication Name Bookmark RFC 7517 JSON Web Key (JWK) https://tools.ietf.org/ht ml/rfc7517 RFC 7518 JSON Web Algorithms (JWA) https://tools.ietf.org/ht ml/rfc7518 RFC 8446 The Transport Layer Security (TLS) Protocol Version 1.3 https://tools.ietf.org/ht ml/rfc8446 RFC 791 INTERNET PROTOCOL https://tools.ietf.org/ht ml/rfc791 RFC 4291 IP Version 6 Addressing Architecture https://tools.ietf.org/ht ml/rfc4291 EMV 3-D Secure Protocol and Core Functions Specification v2.3.0.0 Introduction

/ 397

countries.

1.4 Acknowledgment The following ISO Standards are referenced in this specification. The latest version including all published amendments shall apply unless a publication date is explicitly stated. Table 1.2: ISO Standards Reference Publication Name Bookmark ISO 3166 Country Codes — ISO 3166 http://www.iso.org/iso /country_codes ISO 4217 Currency Codes — ISO 4217 http://www.iso.org/iso /home/standards/curr ency_codes.htm ISO/IEC 7812 -1 ISO/IEC 7812 -1 Identification cards — Identification of issuers — Part 1: Numbering system http://www.iso.org/iso /home/store/catalogu e_tc/catalogue_detail.htm?csnumber=660 11 ISO/IEC 7813 ISO/IEC 7813 Information technology — Identification cards — Financial transaction cards http://www.iso.org/iso /home/store/catalogu e_tc/catalogue_de tail.htm?csnumber=433 17 ISO/IEC 7816 -5 ISO/IEC 7816 -5 Identification cards — Integrated circuit cards — Part 5: Registration of application providers https://www.iso.org/st andard/34259.html ISO/IEC 15946 1 ISO/IEC 15946 1 Information technology — Security techniques —Cryptographic techniques based on elliptic curves — Part 1: General http://www.iso.org/iso /home/store/catalogu e_tc/catalogue_detail.htm?csnumber=654 80 EMV 3-D Secure Protocol and Core Functions Specification v2.3.0.0 Introduction

/ 397

countries. 1.5

Definitions

The following terms are used in this specification: Table 1.3: Definitions Term Definition 3DS Client The consumer -facing component allowing consumer interaction with the 3DS Requestor for initiation of the EMV 3 -D Secure protocol. 3DS Integrator An EMV 3 -D Secure participant that facilitates and integrates the 3DS Requestor Environment, and optionally facilitates integration between the Merchant and the Acquirer. 3DS Method A scripting call provided by the 3DS Integrator that is p laced on the 3DS Requestor website. Optionally used to obtain additional browser information to facilitate risk -based decisioning. 3DS Requestor The initiator of the EMV 3 -D Secure Authentication Request. For example, this may be a merchant or a digital w allet requesting authentication within a purchase flow. 3DS Requestor App An App on a Consumer Device that can process a 3 -D Secure transaction through the use of a 3DS SDK. The 3DS Requestor App is enabled through integration with the 3DS SDK. 3DS Requestor Environment The 3DS Requestor -controlled components (3DS Requestor App, 3DS SDK, and 3DS Server) are typically facilitated by the 3DS Integrator. Implementation of the 3DS Requestor Environment will vary as defined by the 3DS Integrator. 3DS Req uestor Initiated (3RI) 3-D Secure transaction initiated by the 3DS Requestor for the purpose s of confirming that an account is still valid or for Cardholder authentication. The first main use case being recurrent transactions (TV subscriptions, utility bi ll payments, etc.) where the merchant wants to perform a payment transaction to receive authentication data for each bill or a non -payment transaction to verify that a subscription user still has a valid form of payment. The second main use case is when th e 3DS Requestor requests Decoupled Authentication as a method to authenticate the Cardholder. 3DS Requestor Website Component that provides the website that requests Cardholder credentials (whether on file or entered by Cardholder). 3DS SDK A component that interacts with the 3DS Requestor App. The 3DS SDK performs functions related to 3 -D Secure on behalf of the 3DS Server. 3DS Server Refers to the 3DS Integrator's server or systems that handle online transactions and facilitates communication between the 3DS Requestor and the DS. 3-D Secure (3DS) An e -commerce authentication protocol that enables the secure processing of payment, non -payment and account confirmation card transactions. EMV 3-D Secure Protocol and Core Functions Specification v2.3.0.0 Introduction

/ 397

countries. Term Definition Abandon The act of a Cardholder leaving a transaction by use of the Cancel action while in the process of a challenge. For example, using the Cancel button in the App challenge UI. Absent Used in this specification to indicate that an element is absent when the name/value pair does not occur in the message. For example, element "firstName" is absent in the following JSON instance: { "lastName ":"Smith " } Access Control Server (ACS) A component that operates in the Issuer Domain, that verifies whether authentication is available for a card number and device type and authenticates specific Cardholders. Access Control Server User Interface (ACS UI) The ACS UI is generated during a Card holder challenge and is rendered by the ACS within a Browser challenge iframe. Acquirer A financial institution that establishes a contractual service relationship with a Merchant for the purpose of accepting payment cards. In the context of 3 -D Secure, in addition to the traditional role of receiving and sending authorisation and settlement messages (enters transaction into interchange), the Acquirer also determines whether a Merchant is eligible to support the Merchant’s participation in 3 -D Sec ure. Acquirer Domain Contains the systems and functions of the 3DS Requestor Environment and, optionally the Acquirer. App Screen Orientation The orientation of the app screen display on the device, which may differ from the device orientation (for examp le, if the app supports Portrait -only or Landscape -only display, or if the device is in multi -window or split - screen mode). The orientation is considered Landscape if the display is wider than it is tall, and Portrait otherwise. Attempts In this specification, used to indicate the process by which proof of an authentication attempt is generated when payment authentication is not available. Support for Attempts is determined by each DS. Authentication In the context of 3 -D Secure, the process of c onfirming that the person making an e -commerce transaction is entitled to use the payment card. Authentication Request (AReq) Message An EMV 3 -D Secure message sent by the 3DS Server via the DS to the ACS to initiate the authentication process. Authentic ation Response (ARes) Message An EMV 3 -D Secure message returned by the ACS via the DS in response to an Authentication Request message. EMV 3-D Secure Protocol and Core Functions Specification v2.3.0.0 Introduction

/ 397

countries. Term Definition Authentication Value (AV) A cryptographic value generated by the ACS to provide a way, during authorisation processing, for the authorisation system to validate the integrity of the authentication result. The AV algorithm is defined by each Payment System. Authorisation A process by which an Issuer, or a processor on the Issuer's behalf, approves a transaction for payment. Authorisation System The systems and services through which a Payment System delivers online financial processing, authorisation, clearing, and settlement services to Issuers and Acquirers. Bank Identification Number (BIN) The first six or eight digits of a payment card account number that uniquely identifies the issuing financial institution. Also referred to as Issuer Identification Number (IIN) in ISO 7812. Base64 Encoding applied to the Authentication Value data element as defined in RFC 204 5. Base64 url Encoding applied to the 3DS Method Data, Device Information, WebAuthn Credential List and the CReq /CRes messages as defined in RFC 7515. Browser A Browser is a dedicated software application for accessing information on the World Wide Web, for example Chrome, Safari, Edge, Firefox. When a user requests a web page from a particular website, the Browser retrieves the necessary content from a web server and then displays the page on the consumer’s screen. In the context of 3 -D Secure, the Browser is a conduit to transport messages between the Acquirer Domain and the Issuer Domain. A Browser is distinguished from a UI component for example, a WebView, or Custom Tabs, which can be used to display content within an App on a mobile device. The Browser flow is invoked by a Browser whereas the EMVCo specification does not support a UI component within an app invoking the Browser flow. Card In this specification, synonymous to the account of a payment card. Cardholder An individual to whom a card is issued or who is authorised to use that card. Certificate An electronic document that contains the public key of the certificate holder and which is attested to by a Certificate Authority (CA) and rendered not forgeable by cryptographic technology (si gning with the private key of the CA). Certificate Authority (CA) A trusted party that issues and revokes certificates. Refer also to DS Certificate Authority. Challenge The process where the ACS is in communication with the 3DS Client to obtain additional information through Cardholder interaction. Challenge Flow A 3 -D Secure flow that involves Cardholder interaction as defined in Section 2.5.2. EMV 3-D Secure Protocol and Core Functions Specification v2.3.0.0 Introduction

/ 397

countries. Term Definition Challenge Request (CReq) Message An EMV 3 -D Secure message sent by the 3DS SDK or 3DS Server where additional information is sent from the Cardholder to the ACS to support the authentication process. Challenge Response (CRes) The ACS response to the CReq message. It can indicate the result of the Cardholder authentication or, in the case of an App -based model, also signal that further Cardholder interaction is required to complete the authentication. Consumer Device Device used by a Cardholder such a s a smartphone, laptop, or tablet that the Cardholder uses to conduct payment activities including authentication and purchase. Decoupled Authentication Decoupled Authentication is an authentication method whereby authentication can occur independent from the cardholder’s experience with the 3DS Requestor. The authentication method used for Decoupled Authentication is outside the scope of this specification, however one method could be a push notification to a banking app that completes aut hentication and then sends the results to the ACS. Decoupled Authentication is applicable to all Device Channels. Device Binding In this specification, the process to link the Consumer Device used for a transaction to the Cardholder Account and/or Cardhol der. Device Channel Indicates the channel from which the transaction originated. Either:

  • App -based (01 -APP)
  • Browser -based (02 -BRW)
  • 3DS Requestor Initiated (03 -3RI) Device Information Data provided by the Consumer Device that is used in the authentication process. Digital signature An asymmetric cryptographic method whereby the recipient of the data can prove the origin and integrity of data, thereby protecting the sender of the data and the recipient against modification or forgery by third parties and the sender against forgery by the recipient. Digital wallet A software component that allows a user to make an electronic payment with a financial instrument (such as a credit card) while hiding the low -level details of executing the payment protocol, including such tasks as entering an account number and providing shipping information and Cardholder identifying information. Directory Server (DS) A server component operated in the Interoperability Domain; it performs a number of

Shown in part. Read the original for the full text.