EMV® 3-D Secure with Payment Token Use Cases

v1.0 Use Cases
3-D Secure

EMV<sup>®</sup> 3-D Secure Whitepaper 3-D Secure with Payment Token Use Cases Version 1.0 June 2021 EMV<sup>®</sup> 3-D Secure Whitepaper—3-D Secure with Payment Token Use Cases Legal Notice

/ 12

Legal Notice

This document is subject to change by EMVCo at any time. This document does not create any binding obligations upon EMVCo or any third party regarding the subject matter of this document, which obligations will exist, if at all, only to the extent set forth in separate written agreements executed by EMVCo or such third parties. In the absence of such a written agreement, no product provider, test laboratory or any other third party should rely on this document, and EMVCo shall not be liable for any such reliance. No product provider, test laboratory or other third party may refer to a product, service or facility as EMVCo approved, in form or in substance, nor otherwise state or imply that EMVCo (or any agent of EMVCo) has in whole or part approved a product provider, test laboratory or other third party or its products, services, or facilities, except to the extent and subject to the terms, conditions and restrictions expressly set forth in a written agreement with EMVCo, or in an approval letter, compliance certificate or similar document issued by EMVCo. All other references to EMVCo approval are strictly prohibited by EMVCo. Under no circumstances should EMVCo approvals, when granted, be construed to imply any endorsement or warranty regarding the security, functionality, quality, or performance of any particular product or service, and no party shall state or imply anything to the contrary. EMVCo specifically disclaims any and all representations and warranties with respect to products that have received evaluations or approvals, and to the evaluation process generally, including, without limitation, any implied warranties of merchantability, fitness for purpose or non-infringement. All warranties, rights and remedies relating to products and services that have undergone evaluation by EMVCo are provided solely by the parties selling or otherwise providing such products or services, and not by EMVCo, and EMVCo will have no liability whatsoever in connection with such products and services. This document is provided "AS IS" without warranties of any kind, and EMVCo neither assumes nor accepts any liability for any errors or omissions contained in this document. EMVCO DISCLAIMS ALL REPRESENTATIONS AND WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NONINFRINGEMENT, AS TO THIS DOCUMENT. EMVCo makes no representations or warranties with respect to intellectual property rights of any third parties in or in relation to this document. EMVCo undertakes no responsibility to determine whether any implementation of this document may violate, infringe, or otherwise exercise the patent, copyright, trademark, trade secret, know-how, or other intellectual property rights of third parties, and thus any person who implements any part of this document should consult an intellectual property attorney before any such implementation. Without limiting the foregoing, this document may provide for the use of public key encryption and other technology, which may be the subject matter of patents in several countries. Any party seeking to implement this document is solely responsible for determining whether its activities require a license to any such technology, including for patents on public key encryption technology. EMVCo shall not be liable under any theory for any party's infringement of any intellectual property rights in connection with this document.

countries. EMV<sup>®</sup> 3-D Secure Whitepaper—3-D Secure with Payment Token Use Cases Contents

/ 12 Contents Overview 4 Supporting Documentation 4 Enhanced Data for Risk-based Authentication 5 3-D Secure Sample Use Cases incorporating EMV Payment Token Data 6 Use Case 1: Card-add and Token ID&V (3DS Non-Payment Authentication) 7 Use Case 2A: Payment Authentication (with challenge) 8 Use Case 2B: Subsequent Payment Authentication (Frictionless—RBA) 9 Use Case 3: Payment Authentication (frictionless - RBA) 10 Use Case 4: Payment Authentication (Frictionless—RBA) with Detokenisation at DS 11 Use Case 5: Payment Authentication (Frictionless—RBA) with De-tokenisation at ACS 12

countries. EMV 3-D Secure Whitepaper—3-D Secure with Payment Token Use Cases Overview

of 12 Overview EMVCo® is working to improve the quality and security of transactions by utilising EMV Payment Tokenisation to remove PANs from the ecosystem for use cases such as Card-onFile e-commerce, Proximity at Point of Sale and In-app when using a Consumer Device. An ACS can leverage additional Payment Token data to assist the decision process at the time of authentication for e-commerce transactions using Payment Tokens. This document provides details to understand how EMV 3-D Secure components can provide and utilise additional Payment Token data to enhance the risk assessment during authentication. Sample use-cases where the Payment Token data has the potential to influence the outcome of the transaction are provided. The benefits of using this additional data include:

  • Increased Data Visibility
  • Better Consumer Experience
  • Increase EMV 3-D Secure Value Note: The use-cases in this document are not intended to be exhaustive or representative of all possible payment industry implementations and their possible interactions with EMV 3DS components. Supporting Documentation Implementers of this extension should reference:
  • EMV<sup>®</sup> 3-D Secure Payment Token Message Extension
  • EMV<sup>®</sup> 3-D Secure—Protocol and Core Functions Specification
  • EMV<sup>®</sup> Payment Tokenisation Specification—Technical Framework countries. EMV<sup>®</sup> 3-D Secure Whitepaper—3-D Secure with Payment Token Use Cases Overview / 12 Enhanced Data for Risk-based Authentication Providing enhanced data visibility leads to better informed decisions when determining the need for a 3-D Secure challenge. Additional data for transactions initiated with a Payment Token have the potential to promote a frictionless transaction resulting in an improved consumer experience. Table 1 shows examples of the transaction disposition and resulting consumer experience depending on the type of data received. Table 1: Enhanced Data for Risk-based Authentication TAM 12—Card Issuer Interactive Cardholder Authentication - 2 Factor TRID 00012345678 Transaction Context Assumption Card-on-file token 10—Card Issuer Account Verification 99898765432 Payment Token used in EMV Secure Remote Commerce transaction Token Cryptogram MTIzNDU2Nzg5MD A5ODc2NTQzMjE= Token Cryptogram Validity Indicator 3DS Challenge Outcome 01—Verified No challenge required MTIzNDU2Nzg5MD A5ODc2NTQzMjE= 01—Verified No challenge required Rationale ID&V was performed involving the cardholder and Card Issuer; Payment Token issued to a Merchant/TR supporting Care-on-File Use Case; Token Cryptogram is verified; ACS decides no challenge required. ID&V was performed involving the Card Issuer; Token Requestor identified as SRC System; Token Cryptogram is verified; ACS decides no challenge required. countries.. EMV<sup>®</sup> 3-D Secure Whitepaper—3-D Secure with Payment Token Use Cases 3-D Secure Sample Use Cases incorporating EMV Payment Token Data TAM 00—ID&V Not Performed TRID 99956565656 Transaction Context Assumption Card-on-file token Token Cryptogram MTIzNDU2Nzg5MD A5ODc2NTQzMjE= Token Cryptogram Validity Indicator 3DS Challenge Outcome 03—Not performed Challenge Consumer / 12 Rationale When no ID&V was performed and Token Requestor identified as Card-on-File merchant with an unverified Token Cryptogram; ACS may decide challenge is required. 3-D Secure Sample Use Cases incorporating EMV Payment Token Data The use cases below are examples to enable understanding of how the new Payment Token Message Extension may be utilised. The EMV 3DS Token Message Extension defines the data elements and the respective EMV 3DS component that can provide this data. countries.. EMV<sup>®</sup> 3-D Secure Whitepaper—3-D Secure with Payment Token Use Cases 3-D Secure Sample Use Cases incorporating EMV Payment Token Data / 12 Use Case 1: Card-add and Token ID&V (3DS Non-Payment Authentication) Token has already been issued to Token Requestor (or Token User) environment (card on file merchant) as identified by the TRID where no prior ID&V has been performed on Payment Token. countries.. EMV<sup>®</sup> 3-D Secure Whitepaper—3-D Secure with Payment Token Use Cases 3-D Secure Sample Use Cases incorporating EMV Payment Token Data Use Case 2A: Payment Authentication (with challenge) For a card on file merchant that uses a Token Requestor Aggregator to manage Payment Tokens. / 12 countries.. EMV<sup>®</sup> 3-D Secure Whitepaper—3-D Secure with Payment Token Use Cases 3-D Secure Sample Use Cases incorporating EMV Payment Token Data / 12 Use Case 2B: Subsequent Payment Authentication (Frictionless—RBA) For a card on file merchant that uses a Token Requestor Aggregator to manage Payment Tokens. The Payment Token’s TAM value now indicates the ID&V performed based on prior challenge. countries.. EMV<sup>®</sup> 3-D Secure Whitepaper—3-D Secure with Payment Token Use Cases 3-D Secure Sample Use Cases incorporating EMV Payment Token Data / 12 Use Case 3: Payment Authentication (frictionless - RBA) Checkout with EMV Secure Remote Commerce (Click To Pay) that has a Payment Token in the Payload and SRC is the Token Requestor. Can also be applied to use case where Token Requestor is the Market place and transaction is performed by cardholder with an underlying Merchant (Token User). countries.. EMV<sup>®</sup> 3-D Secure Whitepaper—3-D Secure with Payment Token Use Cases 3-D Secure Sample Use Cases incorporating EMV Payment Token Data / 12 Use Case 4: Payment Authentication (Frictionless—RBA) with Detokenisation at DS For a card on file merchant where the Token Cryptogram verification results indicates associated risks with the Payment Token (Token) for a specific transaction. The DS detokenises and provides the Token Cryptogram validation results by calling the TSP. The DS can optionally send the Token Cryptogram to the ACS. The Token Cryptogram is assumed to be included with this use case flow example. countries.. EMV<sup>®</sup> 3-D Secure Whitepaper—3-D Secure with Payment Token Use Cases 3-D Secure Sample Use Cases incorporating EMV Payment Token Data / 12 Use Case 5: Payment Authentication (Frictionless—RBA) with De-tokenisation at ACS For a card on file merchant where the Token Cryptogram validation results indicates associated risks with the Payment Token for a specific transaction. The ACS de-tokenises and validates the cryptogram by calling the TSP. Token Cryptogram is optional but is assumed to be included with this use case flow example. countries..