EMV® 3-D Secure Bridging Message Extension

v2.0 Specifications
3-D Secure

EMV® 3-D Secure Bridging Message Extension Version 2.0 November 2023

EMV® 3-D Secure Bridging Message Extension v2.0 Legal Notice

of 36

Legal Notice

The EMV® Specifications are provided “AS IS” without warranties of any kind, and EMVCo neither assumes nor accepts any liability for any errors or omissions contained in these Specifications. EMVCO DISCLAIMS ALL REPRESENTATIONS AND WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NON-INFRINGEMENT, AS TO THESE SPECIFICATIONS. EMVCo makes no representations or warranties with respect to intellectual property rights of any third parties in or in relation to the Specifications. EMVCo undertakes no responsibility to determine whether any implementation of the EMV® Specifications may violate, infringe, or otherwise exercise the patent, copyright, trademark, trade secret, know-how, or other intellectual property rights of third parties, and thus any person who implements any part of the EMV® Specifications should consult an intellectual property attorney before any such implementation. Without limiting the foregoing, the Specifications may provide for the use of public key encryption and other technology, which may be the subject matter of patents in several countries. Any party seeking to implement these Specifications is solely responsible for determining whether its activities require a license to any such technology, including for patents on public key encryption technology. EMVCo shall not be liable under any theory for any party’s infringement of any intellectual property rights in connection with the EMV® Specifications.

v2.0 Contents

v2.0 Tables

v2.0 Introduction

of 36

Introduction

This document describes the Bridging Message Extension and how existing EMV® 3-D Secure (3DS) v2.1.0 and v2.2.0 components can provide or consume additional data related to the EMV® 3-D Secure Protocol and Core Functions Specification (hereinafter referred to as the Core Specification) v2.3.1.1. The Bridging Message Extension enhances the existing v2.1.0 and v2.2.0 specifications by enabling the implementation of features that are incorporated in the v2.3.1.1 specification. In addition, during the migration to v2.3.1.1, support of the Bridging Message Extension will increase consistency of the key 3DS features provided in v2.1.0, v2.2.0 and v2.3.1.1. The first version of the Bridging Message Extension (v1.0) defined the Recurring Data, Additional Data, Challenge Data, and File URL Data, which is used to enable automation of the switching between the 3DS SDK and an out-of-band (OOB) authentication application, better support the processing of recurring transactions, and incorporate selected elements, values and requirements that were introduced in v2.3.1.0. The second version of the Bridging Message Extension (v2.0) continues support for the v1.0 capabilities and provides additional elements/values that were defined in the Core Specification v2.3.1.1. In the future, as new capabilities are added to the new 3DS specification versions, EMVCo will consider incorporating them, as appropriate, into a new version of the Bridging Message Extension. The Bridging Message Extension defines four sets of data:

  • Recurring Data;
  • Additional Data;
  • Challenge Data; and
  • File URL Data. Recurring Data, Additional Data and File URL Data contain new data or new values for existing data in the AReq/ARes, PReq/PRes or RReq messages for v2.1.0 and v2.2.0. Challenge Data is only provided in CReq/CRes messages for the App-based flow when the Message Version Number is 2.2.0 (not 2.1.0). The EMV® 3-D Secure Bridging Message Extension should be used in conjunction with the Core Specification v2.3.1.1 and the EMV® 3-D Secure Specifications—Frequently Asked Questions, available on the EMVCo website. For differences between v1.0 and v2.0 of the EMV® 3-D Secure Bridging Message Extension, please refer to EMV® Specification Bulletin No. 295, available on the EMVCo website. v2.0 Bridging Message Extension Support and Implementation Bridging Message Extension Support and Implementation of 36 The 3DS sending component builds the 3DS v2.1.0 or v2.2.0 message with the assumption that the 3DS receiving component does not support the Bridging Message Extension, so the 3DS transaction can complete without the Bridging Message Extension. Then the 3DS sending component provides the additional information in the Bridging Message Extension. The 3DS v2.3.1.1 data elements present in the message extension may duplicate existing data elements from the 3DS v2.1.0 and v2.2.0 messages but contain new or different values. The data element values are set in the message extension according to the Core Specification v2.3.1.1, while the core part of the 3DS messages is set according to the Core Specification v2.1.0 and v2.2.0. In such cases, the data element value in the message extension overrides the data element value in the core part of the 3DS message. If the Bridging Message Extension is supported, then the 3DS component shall fully support at least one of the data objects (Recurring Data, Challenge Data, Additional Data or File URL Data) of the message extension and implement the related requirements of the Core Specification v2.3.1.1, as shown below in Table 1. Table 1: Bridging Message Extension Data Objects Supported or Processed Per 3DS Component Data Recurring Data Challenge Data Additional Data File URL Data 3DS SDK x 3DS Server x DS x x x x x ACS x x x These four data objects are Optional in the Bridging Message Extension messages, but at least one data object should be present to use the Bridging Message Extension. The data elements inside these data objects may have presence conditions (Required/Optional/Conditional) related to:
  • the other data elements in the same data object; or
  • the data element in the 3DS message (AReq, ARes,…), but not related to the other data objects in the Bridging Message Extension. v2.0 Bridging Message Extension Support and Implementation of 36 For example, in the Recurring Data object, the Recurring Date presence depends on the value of the Recurring Indicator. Another example is the Authentication Method presence that depends on the Transaction Status in the ARes or RReq message. Bridging Message Extension Version The Extension Version Number should be kept the same across all message exchanges in a 3DS transaction. When responding, the recipient of the Bridging Message Extension shall use the same Extension Version Number for the message pair (AReq/ARes, CReq/CRes, PReq/PRes) as the one received. If the recipient does not support that Extension Version Number, it shall not include the Bridging Message Extension in its response. Recurring Data With the Recurring Data object, the 3DS Requestor and the 3DS Server can provide additional information to the ACS regarding recurring transactions, such as frequency, end date, etc. If the Recurring Data object (see Table 4 for data elements) is present in the Bridging Message Extension, the ACS shall ignore the recurring transaction-related data (Recurring Expiry, Recurring Frequency) that may be present in the AReq message. Challenge Data With the Challenge Data object, the ACS and the 3DS SDK may automate the switching between the 3DS SDK and an OOB Authentication App during an OOB challenge. The 3DS SDK indicates that it supports automatic switching in the OOB App URL Indicator. If supported, the ACS provides to the 3DS SDK the OOB App URL and OOB App Label in the Challenge Data object. The 3DS SDK displays a button that invokes the switching to the OOB Authentication App. The ACS may also use the Challenge Data object to request that the 3DS SDK mask the data entered by the Cardholder during a challenge. The Challenge Data object shall only be provided if the Message Version Number of the CReq/CRes message is 2.2.0. Challenge Flow with OOB Authentication Requirements These requirements refer to Section 3.2 of the Core Specification v2.3.1.1. v2.0 Bridging Message Extension Support and Implementation of 36 The message extension support of OOB challenge-related data is limited to ACS UI Type = 04 (OOB). ACS UI Type = 06 (HTML OOB) is NOT supported in the 3DS Bridging Message Extension. For the ACS and 3DS SDK that support the OOB App URL:
  • the ACS shall implement Req 401, limited to ACS UI Type = 04,
  • the 3DS SDK shall implement Req 399, Req 400, Req 403, Req 404, Req 406, Req 407, Req 408 and Req 409, limited to ACS UI Type = 04. Challenge Flow with Data Entry Masking Requirements The ACS requests the Challenge Data Entry to be masked by setting Challenge Data Entry Masking to Y (limited to ACS UI Type = 01). The 3DS SDK shall implement Challenge Data Entry Masking (Figures 44 and 45, Table A.26). Additional Data With the Additional Data object, the 3DS Server, the ACS and the DS can share additional information from 3DS v2.3.1.1 during the 3DS Authentication, for example:
  • whether the OOB Authentication App used by the ACS supports the 3DS Requestor App URL;
  • the Acquirer Country Code;
  • the Authentication Method used by the ACS;
  • the Card Security Code;
  • the Device Information Version supported by the ACS;
  • the Transaction Challenge Exemption applied by the ACS;
  • the Challenge Error Reporting: detailed information in case of error in the CReq/CRes messages; or
  • the reason for cancelling the Challenge. Challenge Cancelation Indicator Requirements In order to provide the Challenge Cancelation Indicator, the ACS shall implement the updates to Section 5.9.5 (ACS CReq Message Error Handling—01-APP) in the Core Specification. v2.0 Bridging Message Extension Support and Implementation of 36 File URL Data By using the File URL Data object, the 3DS Server may retrieve the Card Range Data in a file downloaded from the DS rather than from the PRes messages. To use the file download, both the 3DS Server and the DS shall implement all the requirements from Section 5.6 (PReq/PRes Message Handling Requirements) in the Core Specification v2.3.1.1. The Card Range Data in the file is provided in the format defined in the 3DS specification and corresponding to the protocol version of the PReq message. v2.0 Bridging Message Extension Data Elements of 36 Bridging Message Extension Data Elements Table 2: Bridging Message Extension Data Elements Data Element/Field Name

Description

Assigned Extension Group Identifier Field Name: id A unique identifier for the extension. Source 3DS SDK 3DS Server ACS DS Criticality Indicator Field Name: criticalityIndicator A Boolean value indicating whether the recipient must understand the contents of the extension to interpret the entire message. 3DS SDK 3DS Server ACS DS Length/Format/Values Device Channel Length: 14 characters JSON Data Type: String Value accepted:

  • A000000802-004 01-APP 02-BRW 03-3RI JSON Data Type: Boolean Value accepted:
  • false 01-APP 02-BRW 03-3RI Message Message Category Inclusion 01-PA 02-NPA AReq = R ARes = R RReq = R CReq = R CRes = R PReq = R PRes = R 01-PA 02-NPA AReq = R ARes = R RReq = R CReq = R CRes = R PReq = R PRes = R v2.0 Bridging Message Extension Data Elements of 36 Data Element/Field Name Data Field Name: data Extension Name Field Name: name Description The data carried in the extension. Source 3DS SDK 3DS Server ACS DS The name of the extension data set as defined by the extension owner. 3DS SDK 3DS Server ACS DS Length/Format/Values Device Channel Length: Variable, maximum 8059 characters JSON Data Type: Object Values accepted:
  • Refer to Table 3 for data elements 01-APP 02-BRW 03-3RI Length: 8 characters JSON Data Type: String Value accepted:
  • Bridging 01-APP 02-BRW 03-3RI Message Message Category Inclusion 01-PA 02-NPA AReq = R ARes = R RReq = R CReq = R CRes = R PReq = R PRes = R 01-PA 02-NPA AReq = R ARes = R RReq = R CReq =R CRes = R PReq = R PRes = R v2.0 Bridging Message Extension Data Elements of 36 Data Table 3: Data Data Element/Field Name Additional Data Field Name: addData Description Specific data from the Core Specification v2.3.1.1. Source 3DS Server ACS Challenge Data Field Name: challengeData The data specific to the Challenge. Present if Message Version Number = 2.2.0; Absent if Message Version Number = 2.1.0. 3DS SDK ACS Extension Version Number Version number of the Field Name: version message extension. 3DS SDK 3DS Server ACS DS Length/Format/Values Length: Variable JSON Data Type: Object Values accepted:
  • Refer to Table 6 for data elements Length: Variable JSON Data Type: Object Values accepted:
  • Refer to Table 5 for data elements Length: 3 characters JSON Data Type: String Value accepted:
  • 2.0 Device Channel 01-APP 02-BRW 03-3RI 01-APP 01-APP 02-BRW 03-3RI Message Message Category Inclusion 01-PA 02-NPA AReq = O ARes = O RReq = O 01-PA 02-NPA 01-PA 02-NPA CReq = O CRes = O AND Message Version Number = 2.2.0 AReq = R ARes = R RReq = R CReq = R CRes = R PReq = R PRes = R v2.0 Bridging Message Extension Data Elements of 36 Data Element/Field Name File URL Data Field Name: fileURLData Recurring Data Field Name: recurringData Description Source Card range data provided in a file. 3DS Server DS The data specific to a recurring transaction. 3DS Server Length/Format/Values Length: Variable JSON Data Type: Object Values accepted:
  • Refer to Table 7 for data elements Length: Variable JSON Data Type: Object Values accepted:
  • Refer to Table 4 for data elements Device Channel N/A 01-APP 02-BRW 03-3RI Message Message Category Inclusion N/A PReq = O PRes = O 01-PA 02-NPA AReq = O v2.0 Bridging Message Extension Data Elements of 36 Recurring Data Table 4: Recurring Data Data Element/ Field Name Recurring Amount Field Name: recurringAmount Recurring Currency Field Name: recurringCurrency Description Source Recurring amount in minor units of currency with all punctuation removed. 3DS Server Currency in which the Recurring Amount is expressed. 3DS Server Length/Format/Values Device Message Message Channel Category Inclusion Length: Variable, maximum 48 characters JSON Data Type: String Example: Purchase amount is USD 123.45 Example values accepted:
  • 12345
  • 012345
  • 0012345 01-APP 02-BRW 03-3RI 01-PA 02-NPA AReq = C Required if Recurring Indicator/Amount Indicator = 01 in the Recurring Data object Length: 3 characters; numeric JSON Data Type: String Values accepted:
  • ISO 4217 three-digit currency codes, other than those listed in Table A.5 in the Core Specification. 01-APP 02-BRW 03-3RI 01-PA 02-NPA AReq = C Required if the Recurring Amount is present in the Recurring Data object v2.0 Bridging Message Extension Data Elements of 36 Data Element/ Field Name Recurring Currency Exponent Field Name: recurringExponent Recurring Date Field Name: recurringDate Recurring Expiry Field Name: recurringExpiry Recurring Frequency Field Name: recurringFrequency Description Source Minor units of currency as specified in the ISO 4217 currency exponent. Examples:
  • USD = 2
  • JPY = 0 3DS Server Effective date of the new authorised amount following the first/promotional payment in a recurring or instalment transaction. 3DS Server Date after which no further authorisations are performed. 3DS Server Indicates the minimum number of days between authorisations for a recurring or instalment transaction. 3DS Server Length/Format/Values Length: 1 character; numeric JSON Data Type: String Device Channel 01-APP 02-BRW 03-3RI Message Message Category Inclusion 01-PA 02-NPA AReq = C Required if the Recurring Amount is present in the Recurring Data object Length: 8 characters JSON Data Type: String Date format accepted:
  • YYYYMMDD 01-APP 02-BRW 03-3RI 01-PA 02-NPA Length: 8 characters JSON Data Type: String Date format accepted:
  • YYYYMMDD Length: Variable, maximum 4 characters JSON Data Type: String Values accepted:
  • Numeric values between 1 and 9999 Example values accepted:
  • 31
  • 031
  • 0031 01-APP 02-BRW 03-3RI 01-APP 02-BRW 03-3RI 01-PA 02-NPA 01-PA 02-NPA AReq = C Required if Recurring Indicator/ Frequency Indicator = 01 in the Recurring Data object Required if there is an end date AReq = C Required if Recurring Indicator/ Frequency Indicator = 01 in the Recurring Data object v2.0 Bridging Message Extension Data Elements of 36 Data Element/ Field Name Recurring Indicator Field Name: recurringInd Description Source Indicates whether the recurring or instalment payment has a fixed or variable amount and frequency. 3DS Server The Recurring Indicator object contains:
  • the Amount Indicator
  • the Frequency Indicator Example: {"recurringInd":{ "amountInd":"01", "frequencyInd":"02"} } Length/Format/Values Device Channel JSON Data Type: Object Amount Indicator Field Name: amountInd 01-APP 02-BRW 03-3RI Values accepted:
  • 01 = Fixed Purchase Amount
  • 02 = Variable Purchase Amount
  • 03–79 = Reserved for EMVCo future use (values invalid until defined by EMVCo)
  • 80–99 = Reserved for DS use Frequency Indicator Field Name: frequencyInd Values accepted:
  • 01 = Fixed Frequency
  • 02 = Variable or Unknown Frequency
  • 03–79 = Reserved for EMVCo future use (values invalid until defined by EMVCo)
  • 80–99 = Reserved for DS use Message Message Category Inclusion 01-PA 02-NPA AReq = R if the Recurring Data object is present v2.0 Bridging Message Extension Data Elements Challenge Data Table 5: Challenge Data of 36 Data Element/ Field Name Description Source Challenge Data Entry Masking Field Name: challengeDataEntryMa sking Indicates that the 3DS SDK shall mask the data entered by the Cardholder. ACS OOB App Label Field Name: oobAppLabel Label to be displayed for the link to the OOB App URL. Example: "oobAppLabel":"Open Your Bank App" ACS Length/Format/Values Device Message Message Channel Category Inclusion Length: 1 character JSON Data Type: String Values accepted:
  • Y = Mask the data entered by the Cardholder
  • N = Do not mask the data entered by the Cardholder 01-APP 01-PA 02-NPA CRes = C Required if ACS UI Type = 01 Length: Variable, maximum 45 characters JSON Data Type: String 01-APP 01-PA 02-NPA CRes = C Required for ACS UI Type = 04 if:
  • OOB App URL Indicator = 01 in the Challenge Data object AND v2.0 Bridging Message Extension Data Elements of 36 Data Element/ Field Name OOB App Status Field Name: oobAppStatus Description Source Length/Format/Values Device Channel Message Category Message Inclusion
  • the ACS uses the OOB Authentication App automatic switching feature for this transaction Status code indicating the type of problem encountered when using the OOB App URL. 3DS SDK Length: Variable, maximum 2 characters JSON Data Type: String Values accepted:
  • 01 = Open OOB App URL failed
  • 02–99 = Reserved for EMVCo future use (values invalid until defined by EMVCo) 01-APP 01-PA 02-NPA CReq = C Required if the Cardholder encountered an error when selecting the OOB App URL for ACS UI Type = 04 v2.0 Bridging Message Extension Data Elements of 36 Data Element/ Field Name OOB App URL Field Name: oobAppURL Description Source Universal App Link to an authentication app used in the OOB authentication. The OOB App URL will open the appropriate location within the OOB Authentication App. Refer to Table 1.3 in the Core Specification v2.3.1.1 for the Universal App Link definition. ACS Length/Format/Values Device Channel Length: Variable, maximum 2048 characters JSON Data Type: String Value accepted:
  • Universal App Link 01-APP Message Message Category Inclusion 01-PA 02-NPA CRes = C Required for ACS UI Type = 04 if the OOB App Label is present AND if:
  • OOB App URL Indicator = 01 in the Challenge Data object; AND
  • the ACS uses the OOB Authentication App automatic switching feature for this transaction v2.0 Bridging Message Extension Data Elements of 36 Data Element/ Field Name OOB App URL Indicator Field Name: oobAppURLInd OOB Continuation Indicator Field Name: oobContinue Description Source Indicates if the 3DS SDK supports the OOB App URL. 3DS SDK Indicator notifying the ACS that the Cardholder has selected the OOB Continuation button in an OOB authentication method, or that the 3DS SDK automatically completes without any Cardholder interaction. 3DS SDK Length/Format/Values Length: 2 characters JSON Data Type: String Values accepted:
  • 01 = Supported
  • 02 = Not supported by the device
  • 03 = Not supported by the 3DS Requestor
  • 04–79 = Reserved for EMVCo future use (values invalid until defined by EMVCo)
  • 80–99 = Reserved for DS use Length: 2 characters JSON Data Type: String Values accepted:
  • 01 = Cardholder clicks the button
  • 02 = Automatic complete
  • 03–99 = Reserved for EMVCo future use (values invalid until defined by EMVCo) Device Channel 01-APP 01-APP Message Message Category Inclusion 01-PA 02-NPA CReq = R if the Challenge Data object is present 01-PA 02-NPA CReq = C Required if ACS UI Type = 04 in the CRes message v2.0 Bridging Message Extension Data Elements of 36 Additional Data Table 6: Additional Data Data Element/ Field Name Description Source 3DS Requestor App URL Indicator Field Name: threeDSRequestorAppU RLInd Indicates whether the OOB Authentication App used by the ACS during a challenge supports the 3DS Requestor App URL. ACS 3DS Requestor Authentication Indicator Field Name: threeDSRequestorAuth enticationInd Indicates the type of Authentication Request. This data element provides additional information to the ACS to determine the best approach for handling an Authentication Request. 3DS Server Length/Format/Values Length: 1 character JSON Data Type: String Values accepted:
  • Y = 3DS Requestor App URL is supported by the OOB Authentication App
  • N = 3DS Requestor App URL is NOT supported by the OOB Authentication App Length: 2 characters JSON Data Type: String Values accepted:
  • 01 = Payment transaction
  • 02 = Recurring transaction
  • 03 = Instalment transaction
  • 04 = Add card
  • 05 = Maintain card Device Channel 01-APP 01-APP 02-BRW Message Message Category Inclusion 01-PA 02-NPA ARes = C Required if Message Version Number = 2.2.0 01-PA 02-NPA AReq = C Required if 3DS Requestor Authentication Indicator = 08 or 09 or 10 Otherwise, Optional v2.0 Bridging Message Extension Data Elements of 36 Data Element/ Field Name Description Source 3RI Indicator Field Name: threeRIInd Indicates the type of 3RI request. This data element provides additional information to the ACS to determine the best approach for handling a 3RI request. 3DS Server Length/Format/Values
  • 06 = Cardholder verification as part of EMV token ID&V
  • 07 = Billing Agreement
  • 08 = Split shipment
  • 09 = Delayed shipment
  • 10 = Split payment
  • 11–79 = Reserved for EMVCo future use (values invalid until defined by EMVCo)
  • 80–99 = Reserved for DS use Length: 2 characters JSON Data Type: String Values accepted:
  • 01 = Recurring transaction
  • 02 = Instalment transaction
  • 03 = Add card
  • 04 = Maintain card information
  • 05 = Account verification
  • 06 = Split shipment
  • 07 = Top-up
  • 08 = Mail Order
  • 09 = Telephone Order Device Channel 03-3RI Message Message Category Inclusion 01-PA 02-NPA AReq = C Required if:
  • Message Version Number = 2.2.0 AND
  • 3RI Indicator = 14, 15, 16, 17 or 18 Otherwise, Optional v2.0 Bridging Message Extension Data Elements of 36 Data Element/ Field Name Description Source Acquirer Country Code Field Name: acquirerCountryCode The code of the country where the acquiring institution is located (in accordance with ISO 3166-1). The DS may edit the value provided by the 3DS Server. 3DS Server DS Length/Format/Values
  • 10 = Trust List status check
  • 11 = Other payment
  • 12 = Billing Agreement
  • 13 = Device Binding Status check
  • 14 = Card Security Code Status check
  • 15 = Delayed shipment
  • 16 = Split payment
  • 17 = FIDO credential deletion
  • 18 = FIDO credential registration
  • 19 = Decoupled Authentication Fallback
  • 20–79 = Reserved for EMVCo future use (values invalid until defined by EMVCo)
  • 80–99 = Reserved for DS use Length: 3 characters JSON Data Type: String Values accepted:
  • ISO 3166-1 numeric three-digit country codes, other than exceptions listed in Device Channel 01-APP 02-BRW 03-3RI Message Message Category Inclusion 01-PA 02-NPA AReq = R if the Additional Data object is present v2.0 Bridging Message Extension Data Elements of 36 Data Element/ Field Name Description Source Acquirer Country Code Source Field Name: acquirerCountryCodeS ource This data element is populated by the system setting the Acquirer Country Code. The DS may edit the value provided by the 3DS Server. 3DS Server DS Authentication Method Field Name: authenticationMethod Indicates the list of authentication types the Issuer will use to challenge the Cardholder, when in the ARes message, or what was used by the ACS, when in the RReq message. Note: For 03-3RI, only present for Decoupled Authentication. ACS Length/Format/Values Table A.5. of the Core Specification v2.3.1.1. Length: 2 characters JSON Data Type: String Values accepted:
  • 01 = 3DS Server
  • 02 = DS
  • 03–79 = Reserved for EMVCo future use (values invalid until defined by EMVCo)
  • 80–99 = Reserved for DS use Size: Variable, 1–99 elements JSON Data Type: Array of string String: 2 characters Values accepted:
  • 01 = Static Passcode
  • 02 = SMS OTP
  • 03 = Key fob or EMV card reader OTP
  • 04 = App OTP
  • 05 = OTP Other
  • 06 = KBA
  • 07 = OOB Biometrics Device Channel 01-APP 02-BRW 03-3RI 01-APP 02-BRW 03-3RI Message Message Category Inclusion 01-PA 02-NPA AReq = R if the Additional Data object is present 01-PA 02-NPA ARes = C RReq = C
  • Required in the ARes message if Transaction Status = C or D
  • Required in the RReq message if Transaction Status = Y or N v2.0 Bridging Message Extension Data Elements of 36 Data Element/ Field Name Browser Screen Color Depth Field Name: browserColorDepth Description Source Value representing the bit depth of the colour palette for displaying images, in bits per pixel. Obtained from the Cardholder browser using the screen.colorDepth property. Refer to Section A.6 in the Core Specification v2.3.1.1 for more details. 3DS Server Length/Format/Values
  • 08 = OOB Login
  • 09 = OOB Other
  • 10 = Other
  • 11 = Push Confirmation
  • 12 = Decoupled
  • 13 = WebAuthn
  • 14 = SPC
  • 15 = Behavioural biometrics
  • 16 = Electronic ID
  • 17–79 = Reserved for EMVCo future use (values invalid until defined by EMVCo)
  • 80–99 = Reserved for DS use Device Channel Length: 1–2 characters; numeric 02-BRW JSON Data Type: String Values accepted:
  • 1–99 Note: If an ACS does not support the value provided, then the ACS can use the closest supported value. For example, if the value provided = 30 and the ACS does not support that Message Message Category Inclusion 01-PA 02-NPA AReq = C Required if Browser JavaScript Enabled = true Otherwise, Optional v2.0 Bridging Message Extension Data Elements of 36 Data Element/ Field Name Description Source Card Security Code Field Name: cardSecurityCode Three- or four-digit security 3DS code printed on the card. Server Card Security Code Status Field Name: cardSecurityCodeStat us Enables the communication of Card Security Code Status between the ACS, the DS and the 3DS Requestor. ACS DS Card Security Code Status Source Field Name: cardSecurityCodeStat usSource This data element will be populated by the system setting the Card Security Code Status. ACS DS Length/Format/Values value, then the ACS could use the value = 24. Device Channel Message Message Category Inclusion Length: Variable, 3-4 characters, numeric Action defined by Payment System rules. JSON Data Type: String 01-APP 02-BRW 03-3RI 01-PA 02-NPA AReq = C Conditional based on DS rules Length: 1 character JSON Data Type: String Values accepted:
  • Y = Validated
  • N = Failed validation
  • U = Status unknown, unavailable, or does not apply 01-APP 02-BRW 03-3RI 01-PA 02-NPA AReq = C ARes = C Conditional based on DS rules Length: 2 characters JSON Data Type: String Values accepted:
  • 01 = DS
  • 02 = ACS
  • 03–79 = Reserved for EMVCo future use (values invalid until defined by EMVCo)
  • 80–99 = Reserved for DS use 01-APP 02-BRW 03-3RI 01-PA 02-NPA AReq = C ARes = C Required if the Card Security Code Status is present in the Additional Data object v2.0 Bridging Message Extension Data Elements of 36 Data Element/ Field Name Challenge Cancelation Indicator Field Name: challengeCancel Description Source Indicator informing the ACS and the DS that the authentication has been cancelled. Note: The Additional Data object is not valid for the CReq/CRes messages. Therefore, the Challenge Cancelation Indicator may only be present in the RReq message. ACS Length/Format/Values Device Channel Length: 2 characters JSON Data Type: String Values accepted:
  • 01 = Cardholder selected “Cancel”
  • 02 = Reserved for EMVCo future use (values invalid until defined by EMVCo)
  • 03 = Transaction Timed Out—Decoupled Authentication
  • 04 = Transaction Timed Out at ACS—other timeouts
  • 05 = Transaction Timed Out at ACS—First CReq not received by ACS
  • 06 = Transaction Error
  • 07 = Unknown
  • 08 = Transaction Timed Out at 3DS SDK
  • 09 = Error message in response to the CRes message sent by the ACS
  • 10 = Error message in response to the CReq message received by the ACS 01-APP 02-BRW 03-3RI Message Message Category Inclusion 01-PA 02-NPA RReq = C Required if the ACS identifies that the authentication transaction was cancelled for reasons as indicated Value of 04 or 05 is required if Transaction Status Reason = 14 v2.0 Bridging Message Extension Data Elements of 36 Data Element/ Field Name Description Source Challenge Error Reporting Field Name: challengeErrorReport ing Copy of the Erro Message sent or received by the ACS in case of error in the CReq/CRes messages. ACS Device Information Recognised Version Field Name: deviceInfoRecognised Version Indicates the highest Data Version of the Device Information supported by the ACS. ACS Transaction Challenge Exemption Field Name: transChallengeExempt ion Exemption applied by the ACS to authenticate the transaction without requesting a challenge. ACS Length/Format/Values
  • 11–79 = Reserved for EMVCo future use (values invalid until defined by EMVCo)
  • 80–99 = Reserved for future DS use Length: Variable JSON Data Type: Object Values accepted:
  • Refer to Table B.12 in the Core Specification v2.3.1.1 for data elements. Device Channel 01-APP 02-BRW Message Message Category Inclusion 01-PA 02-NPA RReq = C Required if Challenge Cancelation Indicator = 09 or 10 Length: Variable, minimum 3 characters JSON Data Type: String Values accepted:
  • Active Device Information Data Version Refer to EMV® Specification Bulletin 255 for values 01-APP 01-PA 02-NPA ARes = R if the Additional Data object is present Length: 2 characters JSON Data Type: String Values accepted: 01-APP 02-BRW 03-3RI 01-PA 02-NPA ARes = O v2.0 Bridging Message Extension Data Elements of 36 Data Element/ Field Name Description Source Note: The accepted values match the values of the 3DS Requestor Challenge Indicator. Transaction Characteristics Field Name: transChar Indicates to the ACS specific transactions identified by the Merchant. Refer to Merchant Risk Indicator in the Core Specification v2.3.1.1 3DS Server Length/Format/Values
  • 05 = Transaction Risk Analysis exemption
  • 08 = Trust List exemption
  • 10 = Low Value exemption
  • 11 = Secure Corporate Payments exemption
  • 79 = No exemption applied
  • 01–04, 06, 07, 09 and 12–78 = Reserved for EMVCo future use (values invalid until defined by EMVCo)
  • 80–99 = Reserved for DS use Size: Variable, 1–2 elements JSON Data Type: Array of string String: 2 characters Value accepted:
  • 01 = Cryptocurrency transaction
  • 02 = NFT transaction Device Channel 01-APP 02-BRW 03-3RI Message Message Category Inclusion 01-PA 02-NPA AReq = O v2.0 Bridging Message Extension Data Elements of 36 File URL Data Table 7: File URL Data Data Element/ Field Name Description Source Card Range Data Download Indicator Field Name: cardRangeDataDownloa dInd Indicates if the 3DS Server supports Card Range Data from a file. Note: If present, this field contains the value Y. 3DS Server Card Range Data File URL Fully Qualified URL of the DS Field Name: DS File containing the Card Range Data for cardRangeDataFileURL download. Note: When the Card Range Data File URL is present, the file contains the entire Card Range Data, and the 3DS Server ignores any Card Range Data and Serial Number present in the PRes message. Length/Format/Values Device Message Message Channel Category Inclusion Length: 1 character N/A JSON Data Type: String Value accepted:
  • Y = Download supported 01-PA 02-NPA PReq = C Present only if the 3DS Server supports the Card Range Data File download Length: Variable, N/A maximum 2048 characters JSON Data Type: String Value accepted:
  • Fully Qualified URL Example:
  • https://server.dsdomain name.com/cardfile.json 01-PA 02-NPA PRes = C Present if Card Range Data Download Indicator = Y in the File URL Data object and the DS supports the Card Range Data File download v2.0 Message Format of 36 Message Format Table 8: Message Extension Data Elements Data Element Assigned Extension Group Identifier Criticality Indicator Extension Name Data Extension Version Number Recurring Data Recurring Amount Recurring Currency Recurring Currency Exponent Recurring Date Recurring Expiry Recurring Frequency Recurring Indicator Challenge Data Challenge Data Entry Masking OOB App Label OOB App Status OOB App URL OOB App URL Indicator OOB Continuation Indicator Additional Data Field Name id criticalityIndicator name data version recurringData recurringAmount recurringCurrency recurringExponent recurringDate recurringExpiry recurringFrequency recurringInd challengeData challengeDataEntryMasking oobAppLabel oobAppStatus oobAppURL oobAppURLInd oobContinue addData v2.0 Message Format of 36 Data Element 3DS Requestor App URL Indicator 3DS Requestor Authentication Indicator 3RI Indicator Acquirer Country Code Acquirer Country Code Source Authentication Method Browser Screen Color Depth Card Security Code Card Security Code Status Card Security Code Status Source Challenge Cancelation Indicator Challenge Error Reporting Device Information Recognised Version Transaction Challenge Exemption Transaction Characteristics File URL Data Card Range Data Download Indicator Card Range Data File URL Field Name threeDSRequestorAppURLInd threeDSRequestorAuthenticationInd threeRIInd acquirerCountryCode acquirerCountryCodeSource authenticationMethod browserColorDepth cardSecurityCode cardSecurityCodeStatus cardSecurityCodeStatusSource challengeCancel challengeErrorReporting deviceInfoRecognisedVersion transChallengeExemption transChar fileURLData cardRangeDataDownloadInd cardRangeDataFileURL v2.0 Bridging Message Extension Samples of 36 Bridging Message Extension Samples The following are samples of the Bridging Message Extension that may be included in the AReq, ARes, RReq, CReq, CRes, PReq or PRes messages by the 3DS Server, 3DS SDK or ACS. Sample AReq Bridging Message Extension "messageExtension":[{ "name":"Bridging", "id":"A000000802-004", "criticalityIndicator":false, "data": { "version": "2.0", "recurringData": { "recurringAmount":"1234", "recurringCurrency":"826", "recurringExponent":"2", "recurringExpiry":"20240405", "recurringFrequency":"30", "recurringDate":"20220405", "recurringInd":{"amountInd":"01","frequencyInd":"01"} }, "addData": { "acquirerCountryCode":"250", "acquirerCountryCodeSource":"01", "browserColorDepth":"24", "cardSecurityCode":"123", "cardSecurityCodeStatus":"Y", "cardSecurityCodeStatusSource":"01", "threeDSRequestorAuthenticationInd":"08", "transChar":["01"] } } }] v2.0 Bridging Message Extension Samples Sample ARes Bridging Message Extension "messageExtension":[{ "name":"Bridging", "id":"A000000802-004", "criticalityIndicator":false, "data": { "version": "2.0", "addData": { "authenticationMethod":["07","08"], "cardSecurityCodeStatus":"Y", "cardSecurityCodeStatusSource":"02", "deviceInfoRecognisedVersion":"1.5", "transChallengeExemption":"08", "threeDSRequestorAppURLInd":"Y" } } }] of 36 Sample RReq Bridging Message Extension "messageExtension":[{ "name":"Bridging", "id":"A000000802-004", "criticalityIndicator":false, "data": { "version": "2.0", "addData": { "authenticationMethod":["07","08"], "challengeCancel":"09", "challengeErrorReporting":{ "threeDSServerTransID": "8a880dc0-d2d2-4067-bcb1-b08d1690b26e", "errorCode":"203", … } } } }] v2.0 Bridging Message Extension Samples Sample CReq Bridging Message Extension "messageExtension":[{ "name":"Bridging", "id":"A000000802-004", "criticalityIndicator":false, "data": { "version": "2.0", "challengeData": { "oobAppStatus":"01", "oobAppURLInd":"01", "oobContinue":"02" } } }] of 36 Sample CRes Bridging Message Extension "messageExtension":[{ "name":"Bridging", "id":"A000000802-004", "criticalityIndicator":false, "data": { "version": "2.0", "challengeData": { "oobAppLabel":"OOB APP", "oobAppURL":"https://oobapp.com/here", "challengeDataEntryMasking":"N" } } }] v2.0 Bridging Message Extension Samples Sample PReq Bridging Message Extension "messageExtension":[{ "name":"Bridging", "id":"A000000802-004", "criticalityIndicator":false, "data": { "version": "2.0", "fileURLData": { "cardRangeDataDownloadInd":"Y" } } }] of 36 Sample PRes Bridging Message Extension "messageExtension":[{ "name": "Bridging", "id": "A000000802-004", "criticalityIndicator": false, "data": { "version": "2.0", "fileURLData": { "cardRangeDataFileURL": "https://server.dsdomainname.com/cardfile.json" } } }] © 2022–2023 EMVCo, LLC. All rights reserved. Reproduction, distribution and other use of this document is permitted only pursuant to the applicable agreement between the user and EMVCo found at www.emvco.com. EMV® is a registered trademark or trademark of EMVCo, LLC in the United States and other countries.