EMV® 3-D Secure Bridging Message Extension

v1.0 Specifications
3-D Secure

EMV® 3-D Secure Bridging Message Extension Version 1.0 August 2022

EMV 3-D Secure Bridging Message Extension Legal Notice

of 31

Legal Notice

The EMV® Specifications are provided “AS IS” without warranties of any kind, and EMVCo neither assumes nor accepts any liability for any errors or omissions contained in these Specifications. EMVCO DISCLAIMS ALL REPRESENTATIONS AND WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NONINFRINGEMENT, AS TO THESE SPECIFICATIONS. EMVCo makes no representations or warranties with respect to intellectual property rights of any third parties in or in relation to the Specifications. EMVCo undertakes no responsibility to determine whether any implementation of the EMV® Specifications may violate, infringe, or otherwise exercise the patent, copyright, trademark, trade secret, know-how, or other intellectual property rights of third parties, and thus any person who implements any part of the EMV® Specifications should consult an intellectual property attorney before any such implementation. Without limiting the foregoing, the Specifications may provide for the use of public key encryption and other technology, which may be the subject matter of patents in several countries. Any party seeking to implement these Specifications is solely responsible for determining whether its activities require a license to any such technology, including for patents on public key encryption technology. EMVCo shall not be liable under any theory for any party’s infringement of any intellectual property rights in connection with the EMV® Specifications.

Extension Contents

Extension Introduction

of 31

Introduction

This document describes how existing EMV® 3-D Secure (3DS) v2.1 and v2.2 components can provide or consume additional data related to the EMV® 3-D Secure Protocol and Core Functions Specification v2.3.1.0, and is designed to evolve to include additional v2.3 features. The EMV® 3-D Secure Protocol and Core Functions Specification v2.1.0, v2.2.0 and v2.3.1.0 is hereinafter referred to as the Core Specification v2.1, v2.2 and v2.3, respectively. This version of the Bridging Message Extension carries the Recurring Transaction data, Additional data and File URL data that are not present or contain new values in the AReq/ARes or RReq messages for v2.1 and 2.2. The Challenge Data is only provided in CReq/CRes messages when the Message Version Number is 2.2.0 (not 2.1.0). The EMV® 3-D Secure Bridging Message Extension should be used in conjunction with the Core Specification v2.3 and the EMV® 3-D Secure Specifications Frequently Asked Questions, available on the EMVCo website.

Extension Bridging Message Extension Support and Implementation Bridging Message Extension Support and Implementation

of 31 The 3DS v2.3 data elements present in the message extension may duplicate existing data elements from the 3DS v2.1 and v2.2 messages, but contain new or different values. According to the Core Specification v2.3, the data element values are set in the message extension, while, according to the Core Specification v2.1 and v2.2, they are set in the core part of the 3DS messages. In such cases, the data element value in the message extension overrides the data element value in the core part of the 3DS message. In addition, the 3DS Server builds the v2.1 or v2.2 AReq message assuming that the ACS does not support the Bridging Message Extension. Then it provides the additional information in the Bridging Message Extension. If the Bridging Message Extension is supported, then the 3DS component shall fully support at least one of the data objects (Recuring data, Challenge data, Additional data or File URL data) of the message extension and implement the related requirements of the Core Specification v2.3, as shown below in Table 1. Table 1: Bridging Message Extension Data Objects Supported or Processed Per 3DS Component DATA Recurring data Challenge data Additional data File URL data 3DS SDK x 3DS Server DS x x x x x x ACS x x x Some data objects have Optional or Conditional presence in the Bridging Message Extension messages. The data elements inside these objects may also have presence conditions (Required/Optional/Conditional). The presence condition of the data elements in an object applies only when the object is present in the message.

Extension Bridging Message Extension Support and Implementation

of 31 Challenge Flow with OOB Authentication Requirements These requirements refer to Section 3.2 of the Core Specification v2.3. The message extension support of OOB challenge-related data is limited to ACS UI Type = 04 (OOB). ACS UI Type = 06 (HTML OOB) is NOT supported in the 3DS Bridging Message Extension. For the ACS and 3DS SDK that support the OOB App URL:

  • the ACS shall implement Req 401, limited to ACS UI Type = 04
  • the 3DS SDK shall implement Req 399, Req 400, Req 403, Req 404, Req 406, Req 407, Req 408 and Req 409 limited to ACS UI Type = 04, and the Challenge Data Entry Masking (Figure 44 and 45, Table A.26). Challenge Cancelation Indicator Requirements The ACS shall implement Req 45 and the updates to Section 5.9.5 (ACS CReq Message Error Handling—01-APP) of the Core Specification. Extension Bridging Message Extension Data Elements Bridging Message Extension Data Elements Table 2: Bridging Message Extension Data Elements Data Element/Field Name

Description

Assigned Extension Group Identifier Field Name: id A unique identifier for the extension. Source 3DS Server ACS 3DS SDK Length/Format/Values Length: 14 characters JSON Data Type: String Value accepted:

  • A000000802-004 Criticality Indicator Field Name: criticalityIndicator A Boolean value indicating whether the recipient must understand the contents of the extension to interpret the entire message. 3DS Server ACS 3DS SDK JSON Data Type: Boolean Value accepted:
  • false of 31 Message Inclusion AReq = R ARes = R RReq = R CReq = R CRes = R PReq = R PRes = R AReq = R ARes = R RReq = R CReq = R CRes = R PReq = R PRes = R Extension Bridging Message Extension Data Elements Data Element/Field Name Data Field Name: data Description The data carried in the extension. Source 3DS Server ACS 3DS SDK Length/Format/Values Length: Variable, maximum 8059 characters JSON Data Type: Object Values accepted:
  • Refer to Table 3 for data elements Extension Name Field Name: name The name of the extension data set as defined by the extension owner. 3DS Server ACS 3DS SDK Length: 15 characters JSON Data Type: String Value accepted:
  • Bridging of 31 Message Inclusion AReq = R ARes = R RReq = R CReq = R CRes = R PReq = R PRes = R AReq = R ARes = R RReq = R CReq =R CRes = R PReq = R PRes = R Extension Bridging Message Extension Data Elements Data Table 3: Data Data Element/Field Name Additional Data Field Name: addData Challenge Data Field Name: challengeData Extension Version Number Field Name: version Description Specific data from the Core Specification v2.3. The data specific to the Challenge. Present if Message Version Number = 2.2.0; absent if Message Version Number = 2.1.0. Source 3DS Server ACS ACS 3DS SDK Length/Format/Values Length: Variable JSON Data Type: Object Values accepted:
  • Refer to Table 6 for data elements Length: Variable JSON Data Type: Object Values accepted:
  • Refer to Table 5 for data elements Version number of the message extension. 3DS Server ACS 3DS SDK Length: 3 characters JSON Data Type: String Value accepted:
  • 1.0 of 31 Message Inclusion AReq = O ARes = O RReq = O CReq = O CRes = O AND Message Version Number = 2.2.0 AReq = R ARes = R RReq = R CReq = R CRes = R PReq = R PRes = R Extension Bridging Message Extension Data Elements Data Element/Field Name File URL Data Field Name: fileURLData Recurring Data Field Name: recurringData Description Card range data provided in a file. Source 3DS Server DS The data specific to a recurring 3DS Server transaction. Length/Format/Values Length: Variable JSON Data Type: Object Values accepted:
  • Refer to Table 7 for data elements Length: Variable JSON Data Type: Object Values accepted:
  • Refer to Table 4 for data elements of 31 Message Inclusion PReq = O PRes = O AReq = O Extension Bridging Message Extension Data Elements of 31 Recurring Data Table 4: Recurring Data Data Element/ Field Name Recurring Amount Field Name: recurringAmount Description Recurring amount in minor units of currency with all punctuation removed. Recurring Currency Field Name: recurringCurrency Currency in which the Recurring Amount is expressed. Source 3DS Server 3DS Server Length/Format/Values Length: Variable, maximum 48 characters JSON Data Type: String Example: Purchase amount is USD 123.45 Example values accepted:
  • 12345
  • 012345
  • 0012345 Length: 3 characters; numeric JSON Data Type: String Values accepted:
  • ISO 4217 three-digit currency codes, other than those listed in Table A.5 in the Core Specification. Message Inclusion AReq = C Required if:
  • [ 3DS Requestor Authentication Indicator = 02 or 03; OR 3RI Indicator = 01 or 02 ] AND
  • Recurring Indicator/ Amount Indicator = 01 AReq = C Required if the Recurring Amount is present Extension Bridging Message Extension Data Elements of 31 Data Element/ Field Name Description Source Recurring Currency Exponent Field Name: recurringExponent Minor units of currency as specified in the ISO 4217 currency exponent. Examples:
  • USD = 2
  • JPY = 0 3DS Server Recurring Date Field Name: recurringDate Effective date of the new authorised amount following the first/promotional payment in a recurring or instalment transaction. 3DS Server Recurring Frequency Field Name: recurringFrequency Indicates the minimum number of days between authorisations for a recurring or instalment transaction. 3DS Server Length/Format/Values Length: 1 character; numeric JSON Data Type: String Length: 8 characters JSON Data Type: String Date format accepted:
  • YYYYMMDD Length: Variable, maximum 4 characters JSON Data Type: String Values accepted:
  • Numeric values between 1 and 9999 Example values accepted:
  • 31
  • 031
  • 0031 Message Inclusion AReq = C Required if the Recurring Amount is present. AReq = C Required if Recurring Indicator/ Frequency Indicator = 01 AReq = C Required if Recurring Indicator/ Frequency Indicator = 01 Extension Bridging Message Extension Data Elements of 31 Data Element/ Field Name Recurring Indicator Field Name: recurringInd Description Source Indicates whether the recurring or instalment payment has a fixed or variable amount and frequency. The Recurring Indicator object contains:
  • the Amount Indicator
  • the Frequency Indicator Example: {"recurringInd":{ "amountInd":"01", "frequencyInd":"02"}} 3DS Server Length/Format/Values JSON Data Type: Object Amount Indicator Field Name: amountInd Values accepted:
  • 01 = Fixed Purchase Amount
  • 02 = Variable Purchase Amount
  • 03–79 = Reserved for EMVCo future use (values invalid until defined by EMVCo)
  • 80–99 = Reserved for DS use Frequency Indicator Field Name: frequencyInd Values accepted:
  • 01 = Fixed Frequency
  • 02 = Variable or Unknown Frequency
  • 03–79 = Reserved for EMVCo future use (values invalid until defined by EMVCo)
  • 80–99 = Reserved for DS use Message Inclusion AReq = C Required if:
  • 3DS Requestor Authentication Indicator = 02 or 03; OR
  • 3RI Indicator = 01 or 02 Extension Bridging Message Extension Data Elements of 31 Challenge Data Table 5: Challenge Data Note: Challenge Data is only provided if the Message Version Number of the CReq/CRes message is 2.2.0. Data Element/ Field Name Description Source Length/Format/Values Message Inclusion Challenge Data Entry Masking Field Name: challengeDataEntryMasking Indicates that the 3DS SDK shall ACS mask the data entered by the Cardholder. OOB App Label Field Name: oobAppLabel Label to be displayed for the link to the OOB App URL. Example: "oobAppLabel":"Open Your Bank App" ACS Length: 1 character JSON Data Type: String Values accepted:
  • Y = Mask the data entered by the Cardholder
  • N = Do not mask the data entered by the Cardholder. CRes = C Required if ACS UI Type = 01 Length: Variable, maximum 45 characters JSON Data Type: String CRes = C Required if:
  • the OOB App URL is available and ACS UI Type = 04; AND
  • OOB App URL Indicator = 01 in the CReq message Extension Bridging Message Extension Data Elements Data Element/ Field Name OOB App Status Field Name: oobAppStatus Description Source Status code indicating the problem type encountered when using the OOB App URL. 3DS SDK OOB App URL Field Name: oobAppURL Universal App Link to an authentication app used in the OOB authentication. The OOB App URL will open the appropriate location within the OOB Authentication App. Refer to Table 1.3 in the Core Specification v2.3 for the Universal App Link definition. ACS of 31 Length/Format/Values Length: Variable, maximum 2 characters JSON Data Type: String Values accepted:
  • 01 = Open OOB App URL failed
  • 02–99 = Reserved for future EMVCo use (values invalid until defined by EMVCo) Length: Variable, maximum 2048 characters JSON Data Type: String Value accepted:
  • Universal App Link Message Inclusion CReq = C Required if the Cardholder encountered an error when selecting the OOB App URL for ACS UI Type = 04 CRes = C Required for ACS UI Type = 04 if:
  • OOB App URL Indicator = 01 in the CReq message; AND
  • the ACS utilises the OOB Authentication App automatic switching feature Extension Bridging Message Extension Data Elements Data Element/ Field Name OOB App URL Indicator Field Name: oobAppURLInd Description Indicates if the 3DS SDK supports the OOB App URL. Source 3DS SDK OOB Continuation Indicator Field Name: oobContinue Indicator notifying the ACS that the Cardholder has selected the OOB Continuation button in an OOB authentication method, or that the 3DS SDK automatically completes without any Cardholder interaction. 3DS SDK of 31 Length/Format/Values Message Inclusion Length: Variable, maximum 48 characters JSON Data Type: String Values accepted:
  • 01 = Supported
  • 02 = Not supported by the device
  • 03 = Not supported by the 3DS Requestor
  • 04–79 = Reserved for EMVCo future use (values invalid until defined by EMVCo)
  • 80–99 = Reserved for DS use CReq = R Length: 2 characters JSON Data Type: String Values accepted:
  • 01 = Cardholder clicks the button
  • 02 = Automatic complete
  • 03–99 = Reserved for EMVCo future use (values invalid until defined by EMVCo) CReq = C Required if:
  • ACS UI Type = 04; OR
  • the 3DS SDK sends a CReq message unless Challenge Additional Code = Y. Extension Bridging Message Extension Data Elements of 31 Additional Data Table 6: Additional Data Data Element/ Field Name 3DS Requestor App URL Indicator Field Name: threeDSRequestorAppURLInd Description Indicates whether the OOB Authentication App used by the ACS during a challenge supports the 3DS Requestor App URL. Source ACS 3DS Requestor Authentication Indicator Field Name: threeDSRequestorAuthentica tionInd Indicates the type of Authentication Request. This data element provides additional information to the ACS to determine the best approach for handling an Authentication Request. 3DS Server Length/Format/Values Length: 1 character JSON Data Type: String Values accepted:
  • Y = 3DS Requestor App URL is supported by the OOB Authentication App
  • N = 3DS Requestor App URL is NOT supported by the OOB Authentication App Length: 2 characters JSON Data Type: String Values accepted:
  • 01 = Payment transaction
  • 02 = Recurring transaction
  • 03 = Instalment transaction
  • 04 = Add card
  • 05 = Maintain card
  • 06 = Cardholder verification as part of EMV token ID&V
  • 07 = Billing Agreement
  • 08 = Split shipment
  • 09 = Delayed shipment
  • 10 = Split payment Message Inclusion ARes = R AND Message Version Number = 2.2.0 AReq = C Required if 3DS Requestor Authentication Indicator = 08 or 09 Extension Bridging Message Extension Data Elements Data Element/ Field Name Description 3RI Indicator Field Name: threeRIInd Indicates the type of 3RI request. This data element provides additional information to the ACS to determine the best approach for handling a 3RI request. of 31 Source 3DS Server Length/Format/Values
  • 11–79 = Reserved for EMVCo future use (values invalid until defined by EMVCo)
  • 80–99 = Reserved for DS use Length: 2 characters JSON Data Type: String Values accepted:
  • 01 = Recurring transaction
  • 02 = Instalment transaction
  • 03 = Add card
  • 04 = Maintain card information
  • 05 = Account verification
  • 06 = Split shipment
  • 07 = Top-up
  • 08 = Mail Order
  • 09 = Telephone Order
  • 10 = Trust List status check
  • 11 = Other payment
  • 12 = Billing Agreement
  • 13 = Device Binding status check
  • 14 = Card Security Code status check
  • 15 = Delayed shipment
  • 16 = Split payment Message Inclusion ARes = R AND Message Version Number = 2.2.0 Extension Bridging Message Extension Data Elements of 31 Data Element/ Field Name Description Source Acquirer Country Code Field Name: acquirerCountryCode Acquirer Country Code Source Field Name: acquirerCountryCodeSource The code of the country where the acquiring institution is located (in accordance with ISO 3166-1). The DS may edit the value provided by the 3DS Server. 3DS Server DS This data element is populated by the system setting the Acquirer Country Code. The DS may edit the value provided by the 3DS Server. 3DS Server DS Length/Format/Values
  • 17–79 = Reserved for EMVCo future use (values invalid until defined by EMVCo)
  • 80–99 = Reserved for DS use Length: 3 characters JSON Data Type: String Values accepted:
  • ISO 3166-1 numeric three-digit country codes Length: 2 characters JSON Data Type: String Values accepted:
  • 01 = 3DS Server
  • 02 = DS
  • 03–79 = Reserved for EMVCo future use (values invalid until defined by EMVCo)
  • 80–99 = Reserved for DS use Message Inclusion AReq = R AReq = R Extension Bridging Message Extension Data Elements Data Element/ Field Name Authentication Method Field Name: authenticationMethod Description Source Indicates the list of authentication types the Issuer will use to challenge the Cardholder, when in the ARes message, or what was used by the ACS, when in the RReq message. Note: For 03-3RI, only present for Decoupled Authentication. ACS of 31 Length/Format/Values Message Inclusion Size: Variable, 1–99 elements JSON Data Type: Array of String String: 2 characters Values accepted:
  • 01 = Static Passcode
  • 02 = SMS OTP
  • 03 = Key fob or EMV card reader OTP
  • 04 = App OTP
  • 05 = OTP Other
  • 06 = KBA
  • 07 = OOB Biometrics
  • 08 = OOB Login
  • 09 = OOB Other
  • 10 = Other
  • 11 = Push Confirmation
  • 12 = Decoupled
  • 13 = WebAuthn
  • 14 = SPC
  • 15 = Behavioural biometrics
  • 16–79 = Reserved for future EMVCo use (values invalid until defined by EMVCo)
  • 80–99 = Reserved for DS use ARes = C RReq = C
  • Required in the ARes message if Transaction Status = C or D
  • Required in the RReq message if Transaction Status = Y or N Extension Bridging Message Extension Data Elements of 31 Data Element/ Field Name Description Source Browser Screen Color Depth Field Name: browserColorDepth Value representing the bit depth of the colour palette for displaying images, in bits per pixel. Obtained from the Cardholder browser using the screen.colorDepth property. Refer to Section A.6 in the Core Specification v2.3 for more details. 3DS Server Card Security Code Field Name: cardSecurityCode Three- or four-digit security code 3DS Server printed on the card. Card Security Code Status Field Name: cardSecurityCodeStatus Enables the communication of Card Security Code Status between the ACS, the DS and the 3DS Requestor. ACS DS Length/Format/Values Message Inclusion Length: 1–2 characters; numeric JSON Data Type: String Values accepted:
  • 1–99 For a list of possible values, refer to https://www.w3schools.com/jsref/pro p_screen_colordepth.asp Note: If an ACS does not support the value provided, then the ACS can use the closest supported value. For example, if the value provided = 30 and the ACS does not support that value, then the ACS could use the value = 24. AReq = C Required when Browser JavaScript Enabled = true; otherwise, Optional Length: Variable, 3-4 characters, numeric. Action defined by Payment System rules. JSON Data Type: String AReq = C Conditional based on DS rules Length: 1 character AReq = C JSON Data Type: String ARes = C Values accepted:
  • Y = Validated Conditional based on DS rules
  • N = Failed validation
  • U = Status unknown, unavailable, or does not apply Extension Bridging Message Extension Data Elements Data Element/ Field Name Description Source Card Security Code Status Source Field Name: cardSecurityCodeStatusSour ce This data element will be populated by the system setting the Card Security Code Status. ACS DS Challenge Cancelation Indicator Field Name: challengeCancel Indicator informing the ACS and the DS that the authentication has been cancelled. 3DS SDK ACS of 31 Length/Format/Values Message Inclusion Length: 2 characters JSON Data Type: String Values accepted:
  • 01 = DS
  • 02 = ACS
  • 03–79 = Reserved for EMVCo future use (values invalid until defined by EMVCo)
  • 80–99 = Reserved for DS use AReq = C ARes = C Required if the Card Security Code Status is present Length: 2 characters JSON Data Type: String Values accepted:
  • 01 = Cardholder selected “Cancel”
  • 02 = Reserved for future EMVCo use (values invalid until defined by EMVCo).
  • 03 = Transaction Timed Out— Decoupled Authentication
  • 04 = Transaction Timed Out at ACS—other timeouts
  • 05 = Transaction Timed Out at ACS—First CReq not received by ACS
  • 06 = Transaction Error
  • 07 = Unknown
  • 08 = Transaction Timed Out at 3DS SDK CReq = C RReq = C
  • Required in CReq for 01APP if the authentication transaction was cancelled by user interaction with the cancellation button in the UI or for other reasons as indicated Extension Bridging Message Extension Data Elements Data Element/ Field Name Description Source Challenge Error Reporting Field Name: challengeErrorReporting Copy of the Erro Message sent or received by the ACS in case of error in the CReq/CRes messages. ACS Device Information Recognised Version Field Name: deviceInfoRecognisedVersio n Indicates the highest Data Version of the Device Information supported by the ACS. ACS of 31 Length/Format/Values
  • 09 = Error message in response to the CRes message sent by the ACS
  • 10 = Error message in response to the CReq message received by the ACS
  • 11–79 = Reserved for future EMVCo use (values invalid until defined by EMVCo)
  • 80–99 = Reserved for future DS use Message Inclusion
  • Required in RReq if the ACS identifies that the authentication transaction was cancelled for reasons as indicated Value of 04 or 05 is required when Transaction Status Reason = 14 Length: Variable JSON Data Type: Object Values accepted:
  • Refer to Table B.12 in the Core Specification v2.3 for data elements RReq = C Required when Challenge Cancelation Indicator = 09 or 10 Length: Variable, minimum 3 characters JSON Data Type: String Values accepted:
  • Any active Device Information Data Version is considered a valid value. Refer to EMV® Specification Bulletin 255 for values ARes = R Extension Bridging Message Extension Data Elements Data Element/ Field Name Transaction Challenge Exemption Field Name: transChallengeExemption Description Exemption applied by the ACS to authenticate the transaction without requesting a challenge. Note: The accepted values match the values of the 3DS Requestor Challenge Indicator. Source ACS of 31 Length/Format/Values Message Inclusion Length: 2 characters JSON Data Type: String Values accepted:
  • 05 = Transaction Risk Analysis exemption
  • 08 = Trust List exemption
  • 10 = Low Value exemption
  • 11 = Secure Corporate Payments exemption
  • 79 = No exemption applied
  • 01–04, 06, 07, 09 and 12–78 = Reserved for EMVCo future use (values invalid until defined by EMVCo)
  • 80–99 = Reserved for DS use ARes = O Extension Bridging Message Extension Data Elements of 31 File URL Data Table 7: File URL Data Data Element/ Field Name Card Range Data Download Indicator Field Name: cardRangeDataDownloadInd Card Range Data File URL Field Name: cardRangeDataFileURL Description Source Indicates if the 3DS Server supports Card Range Data from a file. Note: If present, this field contains the value Y. 3DS Server Fully Qualified URL of the DS DS File containing the Card Range Data for download. Note: When the Card Range Data File URL is present, the file contains the entire Card Range Data, and the 3DS Server ignores any Card Range Data and Serial Number present in the PRes message. Length/Format/Values Message Inclusion Length: 1 character JSON Data Type: String Value accepted:
  • Y = Download supported PReq = C Present if the 3DS Server supports the Card Range Data File download Length: Variable, maximum 2048 characters JSON Data Type: String Value accepted:
  • Fully Qualified URL Example:
  • https://server.dsdomainname.co m/cardfile.json PRes = C Present if Card Range Data Download Indicator = Y in the PReq message and the DS supports the Card Range Data File download Extension Message Format of 31 Message Format Table 8: Message Extension Data Elements Data Element Assigned Extension Group Identifier Criticality Indicator Extension Name Extension Version Number Data Recurring Data Recurring Amount Recurring Currency Recurring Currency Exponent Recurring Date Recurring Frequency Recurring Indicator Challenge Data Challenge Data Entry Masking OOB App Label OOB App Status OOB App URL OOB App URL Indicator OOB Continuation Indicator Additional Data 3DS Requestor App URL Indicator Field Name id criticalityIndicator name version data recurringData recurringAmount recurringCurrency recurringExponent recurringDate recurringFrequency recurringInd challengeData challengeDataEntryMasking oobAppLabel oobAppStatus oobAppURL oobAppURLInd oobContinue addData threeDSRequestorAppURLInd Extension Message Format of 31 Data Element Field Name 3DS Requestor Authentication Indicator threeDSRequestorAuthenticationInd Acquirer Country Code acquirerCountryCode Acquirer Country Code Source acquirerCountryCodeSource Authentication Method authenticationMethod Browser Screen Color Depth browserColorDepth Card Security Code cardSecurityCode Card Security Code Status cardSecurityCodeStatus Card Security Code Status Source cardSecurityCodeStatusSource Challenge Cancelation Indicator challengeCancel Challenge Error Reporting challengeErrorReporting Device Information Recognised Version deviceInfoRecognisedVersion Transaction Challenge Exemption transChallengeExemption File URL Data fileURLData Card Range Data Download Indicator cardRangeDataDownloadInd Card Range Data File URL cardRangeDataFileURL Extension Bridging Message Extension Samples of 31 Bridging Message Extension Samples The following are samples of the Bridging Message Extension that may be included in the AReq, ARes, RReq, CReq, CRes, PReq or PRes messages by the 3DS Server, 3DS SDK or ACS. Sample AReq Bridging Message Extension "messageExtension":[{ "name":"Bridging", "id":"A000000802-004", "criticalityIndicator":false, "version": "1.0", "data": { "recurringData": { "recurringAmount":"1234", "recurringCurrency":"826", "recurringExponent":"2", "recurringDate":"20220405", "recurringInd":{"amountInd":"01","frequencyInd":"01"} }, "addData": { "acquirerCountryCode":"250", "acquirerCountryCodeSource":"01", "browserColorDepth":"24", "cardSecurityCode":"123", "cardSecurityCodeStatus":"Y", "cardSecurityCodeStatusSource":"01", "threeDSRequestorAuthenticationInd":"08" } } }] Extension Bridging Message Extension Samples Sample ARes Bridging Message Extension "messageExtension":[{ "name":"Bridging", "id":"A000000802-004", "criticalityIndicator":false, "version": "1.0", "data": { "addData": { "authenticationMethod":["07","08"], "cardSecurityCodeStatus":"Y", "cardSecurityCodeStatusSource":"02", "deviceInfoRecognisedVersion":"1.5", "transChallengeExemption":"08", "threeDSRequestorAppURLInd":"Y" } } }] of 31 Sample RReq Bridging Message Extension "messageExtension":[{ "name":"Bridging", "id":"A000000802-004", "criticalityIndicator":false, "version": "1.0", "data": { "addData": { "authenticationMethod":["07","08"], "challengeCancel":"09", "challengeErrorReporting":{ "threeDSServerTransID": "8a880dc0-d2d2-4067-bcb1-b08d1690b26e", "errorCode":"203", … } } } }] Extension Bridging Message Extension Samples Sample CReq Bridging Message Extension "messageExtension":[{ "name":"Bridging", "id":"A000000802-004", "criticalityIndicator":false, "version": "1.0", "data": { "challengeData": { "oobAppStatus":"01", "oobAppURLInd":"01", "oobContinue":"02" }, "addData": { "challengeCancel":"09" } } }] Sample CRes Bridging Message Extension "messageExtension":[{ "name":"Bridging", "id":"A000000802-004", "criticalityIndicator":false, "version": "1.0", "data": { "challengeData": { "oobAppLabel":"OOB APP", "oobAppURL":https://oobapp.com/here, "challengeDataEntryMasking":"N" } } }] of 31 Extension Bridging Message Extension Samples Sample PReq Bridging Message Extension "messageExtension":[{ "name":"Bridging", "id":"A000000802-004", "criticalityIndicator":false, "version": "1.0", "data": { "fileURLData": { "cardRangeDataDownloadInd":"Y" } } }] of 31 Sample PRes Bridging Message Extension "messageExtension":[{ "name": "Bridging", "id": "A000000802-004", "criticalityIndicator": false, "version": "1.0", "data": { “fileURLData”: { "cardRangeDataFileURL": "https://server.dsdomainname.com/cardfile.json" } } }] © 2022 EMVCo, LLC. All rights reserved. Reproduction, distribution and other use of this document is permitted only pursuant to the applicable agreement between the user and EMVCo found at www.emvco.com. EMV® is a registered trademark or trademark of EMVCo, LLC in the United States and other countries.