EMV® 3-D Secure Protocol and Core Functions Specification

v2.3.1.1 Specifications
3-D Secure

EMV® 3-D Secure Protocol and Core Functions Specification Version 2.3.1.1 May 2023 EMV® 3-D Secure Protocol and Core Functions Specification v2.3.1.1 Legal Notice

/ xvii

countries.

Legal Notice

The EMV® Specifications are provided “AS IS” without warranties of any kind, and EMVCo neither assumes nor accepts any liability for any errors or omissions contained in these Specifications. EMVCO DISCLAIMS ALL REPRESENTATIONS AND WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NON - INFRINGEMENT, AS TO THESE SPECIFICATIONS. EMVCo makes no representations or warranties with respect to intellectual property rights of any third parties in or in relation to the Specifications. EMVCo undertakes no responsibility to determine whether any implementation of the EMV® Specifications may violate, infringe, or otherwise exercise the patent, copyright, trademark, trade secret, know-how, or other intellectual property rights of third parties, and thus any person who implements any part of the EMV® Specifications should consult an intellectual property attorney before any such implementation. Without limiting the foregoing, the Specifications may provide for the use of public key encryption and other technology, which may be the subject matter of patents in several countries. Any party seeking to implement these Specifications is solely responsible for determining whether its activities require a license to any such technology, including for patents on public key encryption technology. EMVCo shall not be liable under any theory for any party’s infringement of any intellectual property rights in connection with the EMV® Specifications. EMV® 3-D Secure Protocol and Core Functions Specification v2.3.1.1 Revision Log

/ xvii

countries. Revision Log The following table lists the version history for the EMV® 3-D Secure Protocol and Core Functions Specification. EMV® Specification Bulletins provide the detailed updates made with each specification release. Version Release Date Associated Specification Bulletins 2.0.0 October 2016

  • SB 190: 3-D S ecure

Requirement

Numbering Scheme and Error Processing

  • SB 196: 3-D S ecure Updates, Clarifications & Errata 2.1.0 October 2017
  • SB 204v4: 3-D Secure Updates, Clarifications & Errata
  • SB 214v1: EMV® 3-D Secure Updates, Clarifications & Errata 2.2.0 December 2018
  • SB 207: EMV® 3-D Secure Updates, Clarifications & Errata 2.3.0.0 September 2021
  • SB 227v1: EMV® 3-D Secure Key Features v2.3.0.0 2.3.1.0 August 2022
  • SB 256: EMV® 3-D Secure Protocol and Core Functions Specification v2.3.1.0 2.3.1.1 May 2023
  • SB 294: EMV® 3-D Secure Protocol and Core Functions Specification v2.3.1.1 EMV® 3-D Secure Protocol and Core Functions Specification v2.3.1.1 Contents / xvii countries. 1. 1. 1. 1. 1. 1. 1. 1. 1. 1. 2. 2.1. 2.1.1. 2.1.1. 2.1.1. 2.1. 2.1. 2. 2.2. 2.2. 2.2. 2. 2.3. 2.3. 2.3. 2.3. 2. EMV® 3-D Secure Protocol and Core Functions Specification v2.3.1.1 Contents Page v / xvii countries. 2.4. 2.4. 2.4. 2.4. 2.4. 2.4. 2.4. 2.4. 2.4. 2.4. 2.4. 2. 2.5. 2.5. 2.5. 2. 2.6. 2.6. 2.6. 2. 3. EMV® 3-D Secure Protocol and Core Functions Specification v2.3.1.1 Contents / xvii countries. 3. 3.2. 3.2. 3.2.2. 3.2.2. 3. EMV® 3-D Secure Protocol and Core Functions Specification v2.3.1.1 Contents / xvii countries. 3. 3. 3.5. 3.5. 4. 4. 4.2. 4.2.1. EMV® 3-D Secure Protocol and Core Functions Specification v2.3.1.1 Contents / xvii countries. 4.2. 4.2.2. 4.2. 4.2. 4.2.4. 4.2.4. 4.2.4. 4.2. 4.2.5. 4.2. 4.2.6. 4.2. 4.2.7. 4.2.7. 4.2.7. 4. 4.3. 4.3.1. 4.3.1. 4.3. 4.3.2. 4.3. 4. 5. 5.1. 5.1. 5.1. 5.1. 5.1. 5.1. 5.1. 5. 5. 5. 5. 5.5. 5.5. EMV® 3-D Secure Protocol and Core Functions Specification v2.3.1.1 Contents / xvii countries. 5.5.2. 5.5.2. 5. 5. 5.7. 5. 5.8. 5.8.1. 5.8.1. 5.8. 5. 5.9. 5.9. 5.9. 5.9.3. 5.9.3. 5.9. 5.9. 5.9.5. 5.9. 5.9. 5.9. 5.9.8. 5.9. 5.9. 5.9. 5.9. 5.9. 5. 5. 6. 6.1. 6.1. 6.1.2. 6.1.2. 6.1. 6.1.3. EMV® 3-D Secure Protocol and Core Functions Specification v2.3.1.1 Contents Page x / xvii countries. 6.1.3. 6.1. 6.1.4. 6.1.4. 6.1. 6.1. 6.1. 6.1. 6. 6.2. 6.2. 6.2.2. 6.2.2. 6.2.2. 6.2.2. 6.2. 6.2.3. 6.2.3. 6.2.3. 6.2. 6.2.4. 6.2.4. 6.2.4. 6.2.4. A. A. A. A. A. A. A. A. A. EMV® 3-D Secure Protocol and Core Functions Specification v2.3.1.1 Contents / xvii countries. A. A. A.11. A. A.12. A.12. A.12. A. A.13. A.13. A.13. A.13. A.13. A.13. A.13. A.13. A.13. A.13. A. A.14. A.14. A. A. A. A. A. A. A. A. B. EMV® 3-D Secure Protocol and Core Functions Specification v2.3.1.1 Contents / xvii countries. B. B. B. B. B. B. B. B. B. B. B. C. C. C.2. D.1 Cipher Suites for TLS 1.2 D.1. D.1. D. EMV® 3-D Secure Protocol and Core Functions Specification v2.3.1.1 Figures / xvii countries. Figures Figure 2. Figure 2. Figure 2. Figure 2. Figure 2. Figure 2. Figure 3. Figure 3. Figure 3. Figure 3. Figure 3. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4.24: Sample OOB Native UI Template with Complete button—PA —Landscape. 114 EMV® 3-D Secure Protocol and Core Functions Specification v2.3.1.1 Figures / xvii countries. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4.42: Sample OOB HTML UI Template with Complete button—PA —Landscape. 129 Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 4. Figure 6. Figure 6. Figure 6. Figure A. Figure A. EMV® 3-D Secure Protocol and Core Functions Specification v2.3.1.1 Tables / xvii countries. Tables Table 1. Table 1. Table 1. Table 1. Table A. Table A. Table A. Table A. Table A. Table A. Table A. Table A. Table A. Table A. Table A. Table A. Table A. Table A. Table A. Table A. Table A. Table A. Table A. Table A. Table A. Table A. Table A. Table A. Table A. Table A. Table A. Table A. Table A. Table B. Table B. Table B. Table B. Table B. Table B. Table B. Table B. EMV® 3-D Secure Protocol and Core Functions Specification v2.3.1.1 Tables / xvii countries. Table B. Table B. Table B. Table B. EMV® 3-D Secure Protocol and Core Functions Specification v2.3.1.1 Introduction / 410 countries. 1

Introduction

The 3-D Secure authentication protocol is based on a three-domain model where the Acquirer Domain and Issuer Domain are connected by the Interoperability Domain for the purpose of authenticating a Cardholder during an electronic commerce (e- commerce) transaction or to provide identity verification and account confirmation. The 3- D Secure authentication protocol supports two Message Categories:

  • Payment Authentication—Cardholder authentication during an e- commerce transaction.
  • Non-Payment Authentication— Identity verification and account confirmation. The 3- D Secure authentication protocol can be initiated through three Device Channels:
  • App-based—Authentication during a transaction on a Consumer Device that originates from an App provided by a 3DS Requestor (Merchant, digital wallet, et al.). For example, an e-commerce transaction originating during a checkout process within a M erchant’s app.
  • Browser-based—A uthentication during a transaction on a Consumer Device that originates from a website using a Browser as defined in Table 1.3. For example, an e-commerce transaction originating during a checkout process within a website on a Consumer Device.
  • 3DS Requestor Initiated—Confirmation of account information and Cardholder authentication with no direct Cardholder present. For example, a subscription- based e-commerce Merchant confirming that an account is still valid or Cardholder authentication when the 3DS Requestor and the ACS use Decoupled Authentication. 1.1

Purpose

The purpose of this EMV® 3-D Secure Protocol and Core Functions Specification (hereinafter referred to as the Core Specification) is to describe the EMV 3-D Secure infrastructure and components, and to specify the requirements for each component within the infrastructure and their interaction. For purposes of this document, when the phrase 3- D Secure and/or 3DS is used, the intent is EMV 3-D Secure.

1.2 Audience This document is intended for stakeholders developing EMV 3-D Secure products and supporting 3-D Secure implementations. EMV® 3-D Secure Protocol and Core Functions Specification v2.3.1.1 Introduction

/ 410

countries.

1.3 Normative

References

The following standards contain provisions that are referenced in this specification. The latest version including all published amendments shall apply unless a publication date is explicitly stated. Table 1.1: Normative References Reference Publication Name Bookmark IETF BCP 47 Tags for Identifying Languages https://tools.ietf.org/ht ml/bcp47 ITU; ITU-T. E.164 The International Public Telecommunication Numbering Plan https://www.itu.int/rec /T-REC-E.164/en RFC 2045 Multipurpose Internet Mail Extensions (MIME) Part One: Format of Internet Message Bodies https://tools.ietf.org/ht ml/rfc2045 RFC 2397 The "data" URL scheme https://datatracker.ietf.org/doc/html/rfc2397 RFC 2616 Hypertext Transfer Protocol -- HTTP/1.1 https://tools.ietf.org/ht ml/rfc2616 RFC 3447 PKCS #1: RSA Cryptography Specifications https://www.ietf.org/rf c/rfc3447.txt RFC 3986 Uniform Resource Identifier (URI): Generic Syntax https://tools.ietf.org/ht ml/rfc3986 RFC 4122 A Universally Unique IDentifier (UUID) URN Namespace https://tools.ietf.org/ht ml/rfc4122 RFC 4158 Internet X.509 Public Key Infrastructure: certification Path Building https://tools.ietf.org/ht ml/rfc4158 RFC 5246 The Transport Layer Security (TLS) Protocol Version 1.2 https://tools.ietf.org/ht ml/rfc5246 RFC 5322 Internet Message Format https://tools.ietf.org/ht ml/rfc5322 RFC 7159 The JavaScript Object Notation (JSON) Data Interchange Format https://tools.ietf.org/ht ml/rfc7159 RFC 7231 Hypertext Transfer Protocol (HTTP/1.1): Semantics and Content https://tools.ietf.org/ht ml/rfc7231 RFC 7233 Hypertext Transfer Protocol (HTTP/1.1): Range Requests https://datatracker.ietf.org/doc/html/rfc7233 RFC 7515 JSON Web Signatures (JWS) https://tools.ietf.org/ht ml/rfc7515 EMV® 3-D Secure Protocol and Core Functions Specification v2.3.1.1 Introduction

/ 410

countries. Reference Publication Name Bookmark RFC 7516 JSON Web Encryption (JWE) https://tools.ietf.org/ht ml/rfc7516 RFC 7517 JSON Web Key (JWK) https://tools.ietf.org/ht ml/rfc7517 RFC 7518 JSON Web Algorithms (JWA) https://tools.ietf.org/ht ml/rfc7518 RFC 8446 The Transport Layer Security (TLS) Protocol Version 1.3 https://tools.ietf.org/ht ml/rfc8446 RFC 791 INTERNET PROTOCOL https://tools.ietf.org/ht ml/rfc791 RFC 4291 IP Version 6 Addressing Architecture https://tools.ietf.org/ht ml/rfc4291 EMV® 3-D Secure Protocol and Core Functions Specification v2.3.1.1 Introduction

/ 410

countries.

1.4 Acknowledgements The following ISO Standards are referenced in this specification. The latest version including all published amendments shall apply unless a publication date is explicitly stated. Table 1.2: ISO Standards Reference Publication Name Bookmark ISO 3166 Country Codes—ISO 3166 http://www.iso.org/iso /country_codes ISO 4217 Currency Codes—ISO 4217 http://www.iso.org/iso /home/standards/curr ency_codes.htm ISO/IEC 7812-1 ISO/IEC 7812-1 Identification cards—Identification of issuers—Part 1: Numbering system http://www.iso.org/iso /home/store/catalogu e_tc/catalogue_detail.htm?csnumber=660 11 ISO/IEC 7813 ISO/IEC 7813 Information technology—Identification cards— Financial transaction cards http://www.iso.org/iso /home/store/catalogu e_tc/catalogue_detail.htm?csnumber=433 17 ISO/IEC 7816-5 ISO/IEC 7816-5 Identification cards—Integrated circuit cards—Part 5: Registration of application providers https://www.iso.org/st andard/34259.html ISO 8583-1 ISO 8583- 1 Financial transaction card originated messages — Interchange message specifications — Part 1: Messages, data elements and code values https://www.iso.org/st andard/31628.html ISO/IEC 15946-1 ISO/IEC 15946-1 Information technology—Security techniques—Cryptographic techniques based on elliptic curves—Part 1: General http://www.iso.org/iso /home/store/catalogu e_tc/catalogue_detail.htm?csnumber=654 80 EMV® 3-D Secure Protocol and Core Functions Specification v2.3.1.1 Introduction

/ 410

countries. 1.5

Definitions

The following terms are used in this specification: Table 1.3: Definitions Term Definition 3DS Client The consumer-facing component allowing consumer interaction with the 3DS Requestor for initiation of the EMV 3- D Secure protocol. 3DS Integrator An EMV 3-D Secure participant that facilitates and integrates the 3DS Requestor Environment, and optionally facilitates integration between the Merchant and the Acquirer. 3DS Method A scripting call provided by the 3DS Integrator that is placed on the 3DS Requestor W ebsite. Optionally used to obtain additional Browser information to facilitate risk-based decisioning. 3DS Requestor The initiator of the EMV 3- D Secure Authentication Request. For example, this may be a M erchant or a digital wallet requesting authentication within a purchase flow. 3DS Requestor App An App on a Consumer Device that can process a 3- D Secure transaction through the use of a 3DS SDK. The 3DS Requestor App is enabled through integration with the 3DS SDK. 3DS Requestor Environment The 3DS Requestor-controlled components (3DS Requestor App, 3DS SDK, and 3DS Server) are typically facilitated by the 3DS Integrator. Implementation of the 3DS Requestor Environment will vary as defined by the 3DS Integrator. 3DS Requestor Initiated (3RI) 3-D Secure transaction initiated by the 3DS Requestor for the purposes of confirming that an account is still valid or for Cardholder authentication. The first main use case being recurr ing transactions (TV subscriptions, utility bill payments, etc.) where the M erchant wants to perform a payment transaction to receive authentication data for each bill or a non-payment transaction to verify that a subscription user still has a valid form of payment. The second main use case is when the 3DS Requestor requests Decoupled Authentication as a method to authenticate the Cardholder. 3DS Requestor Website Component that provides the website that requests Cardholder credentials (whether on file or entered by Cardholder). 3DS SDK A component that interacts with the 3DS Requestor App. The 3DS SDK performs functions related to 3- D Secure on behalf of the 3DS Server. 3DS Server Refers to the 3DS Integrator’s server or systems that handle online transactions and facilitates communication between the 3DS Requestor and the DS. 3-D Secure (3DS) An e-commerce authentication protocol that enables the secure processing of payment, non-payment and account confirmation card transactions. EMV® 3-D Secure Protocol and Core Functions Specification v2.3.1.1 Introduction

/ 410

countries. Term Definition Abandon The act of a Cardholder leaving a transaction by use of the Cancel action while in the process of a challenge. For example, using the Cancel button in the App challenge UI. Absent Used in this specification to indicate that an element is absent when the name/value pair does not occur in the message. For example, element "firstName" is absent in the following JSON instance: { "lastName":"Smith" } Access Control Server (ACS) A component that operates in the Issuer Domain, that verifies whether authentication is available for a card number and device type and authenticates specific Cardholders. Access Control Server User Interface (ACS UI) The ACS UI is generated during a Cardholder challenge and is rendered by the ACS within a Browser challenge iframe. Acquirer A financial institution that establishes a contractual service relationship with a Merchant for the purpose of accepting payment cards. In the context of 3- D Secure, in addition to the traditional role of receiving and sending authorisation and settlement messages (enters transaction into interchange), the Acquirer also determines whether a Merchant is eligible to support the Merchant’s participation in 3- D Secure. Acquirer Domain Contains the systems and functions of the 3DS Requestor Environment and, optionally the Acquirer. App Screen Orientation The orientation of the app screen display on the device, which may differ from the device orientation (for example, if the app supports Portrait-only or Landscape- only display, or if the device is in multi-window or split- screen mode). The orientation is considered Landscape if the display is wider than it is tall, and Portrait otherwise. Attempts In this specification, used to indicate the process by which proof of an authentication attempt is generated when payment authentication is not available. Support for Attempts is determined by each DS. Authentication In the context of 3- D Secure, the process of confirming that the person making an e- commerce transaction is entitled to use the payment card. Authentication Request (AReq) Message An EMV 3-D Secure message sent by the 3DS Server via the DS to the ACS to initiate the authentication process. Authentication Response (ARes) Message An EMV 3-D Secure message returned by the ACS via the DS in response to an Authentication Request message. EMV® 3-D Secure Protocol and Core Functions Specification v2.3.1.1 Introduction

/ 410

countries. Term Definition Authentication Value (AV) A cryptographic value generated by the ACS to provide a way, during authorisation processing, for the Authorisation S ystem to validate the integrity of the authentication result. The AV algorithm is defined by each Payment System. Authorisation A process by which an Issuer, or a processor on the Issuer’s behalf, approves a transaction for payment. Authorisation System The systems and services through which a Payment System delivers online financial processing, authorisation, clearing, and settlement services to Issuers and Acquirers. Bank Identification Number (BIN) The first six or eight digits of a payment card account number that uniquely identifies the issuing financial institution. Also referred to as Issuer Identification Number (IIN) in ISO 7812. Base64 Encoding applied to the Authentication Value data element as defined in RFC 2045. Base64url Encoding applied to the 3DS Method Data, Device Information, WebAuthn Credential List and the CReq/ CRes messages as defined in RFC 7515. Browser A Browser is a dedicated software application for accessing information on the World Wide Web, for example Chrome, Safari, Edge, Firefox. When a user requests a web page from a particular website, the Browser retrieves the necessary content from a web server and then displays the page on the consumer’s screen. In the context of 3- D Secure, the Browser is a conduit to transport messages between the Acquirer Domain and the Issuer Domain. A Browser is distinguished from a UI component for example, a WebView, or Custom Tabs, which can be used to display content within an App on a mobile device. The Browser flow is invoked by a Browser whereas the EMVCo specification does not support a UI component within an app invoking the Browser flow. Card In this specification, synonymous to the account of a payment card. Card Range Data File The file containing the JSON Card Range Data object. The Card Range Data provides to the 3DS Server the 3DS Protocol Versions supported by the card ranges hosted by the ACS, and other optional information (e.g. 3DS Method, Message Extension). Cardholder An individual to whom a card is issued or who is authorised to use that card. Certificate An electronic document that contains the public key of the certificate holder and which is attested to by a Certificate Authority (CA) and rendered not forgeable by cryptographic technology (signing with the private key of the CA). Certificate Authority (CA) A trusted party that issues and revokes certificates. Refer also to DS Certificate Authority. Challenge The process where the ACS is in communication with the 3DS Client to obtain additional information through Cardholder interaction. EMV® 3-D Secure Protocol and Core Functions Specification v2.3.1.1 Introduction

/ 410

countries. Term Definition Challenge Flow A 3-D Secure flow that involves Cardholder interaction as defined in Section 2.5.2. Challenge Request (CReq) Message An EMV 3-D Secure message sent by the 3DS SDK or 3DS Server where additional information is sent from the Cardholder to the ACS to support the authentication process. Challenge Response (CRes) The ACS response to the CReq message. It can indicate the result of the Cardholder authentication or, in the case of an App- based model, also signal that further Cardholder interaction is required to complete the authentication. Consumer Device Device used by a Cardholder such as a smartphone, laptop, or tablet that the Cardholder uses to conduct payment activities including authentication and purchase. Decoupled Authentication Decoupled Authentication is an authentication method whereby authentication can occur independent from the C ardholder’s experience with the 3DS Requestor. The authentication method used for Decoupled Authentication is outside the scope of this specification. H owever, one method could be a push notification to a banking app that completes authentication and then sends the results to the ACS. Decoupled A uthentication is applicable to all Device Channels. Decoupled Authentication Fallback An additional challenge option for an ACS during the C hallenge process. By returning Transaction Status = D in the RReq message, the ACS requests that the 3DS Server initiate a subsequent 3DS authentication using Decoupled Authentication. Device Binding In this specification, the process to link the Consumer Device used for a transaction to the Cardholder Account and/or Cardholder. Device Channel Indicates the channel from which the transaction originated. Either:

  • App-based (01 -APP)
  • Browser-based (02-BRW)
  • 3DS Requestor Initiated (03- 3RI) Device Information Data provided by the Consumer Device that is used in the authentication process. Digital signature An asymmetric cryptographic method whereby the recipient of the data can prove the origin and integrity of data, thereby protecting the sender of the data and the recip

Shown in part. Read the original for the full text.