Highlights from the EMVCo Phoenix Technical Meeting

Knowledge Hub

EMVCo Associates gathered in Phoenix earlier this year to provide technical input into EMV® Specification advancements. While a number of key initiatives were discussed at the event – including Electric Vehicle Open Payments (EVOP), Terminal and Card Testing and Biometric on Card – EMV 3-D Secure (EMV 3DS) was a standout topic, with a number of guest speakers in this session. In this EMV Insights post, Arman Aygen, Director of Technology at EMVCo, highlights four key learnings from the EMV 3DS session. 1. Can passkeys be used as a password replacement to authorise high-value transactions? Passkeys can be used to strengthen the security of e-commerce transactions. They are a phishing-resistant FIDO credential which act as a password replacement for fast, easy and trusted authentication. Issuers can leverage passkeys to authorise higher-risk transactions in EMV 3DS authentication flows. Rita Mounir, Co-founder and COO at Allthenticate explored the importance of passkeys for security, and the different types of passkeys: device-bound versus synced. As their name suggests, device-bound passkeys cannot be exchanged across different devices and are designed to streamline user management. On the other hand, synced passkeys can offer convenience and flexibility across multiple devices, enabling seamless access to accounts. The session explored the benefits of each of these types of passkeys for different use cases. 2. Decoupled authentication brings value to several purchasing use cases. James Rendell, CTO of the Broadcom Payment Security Division, provided insight on the EMV 3DS Decoupled Authentication flow, which allows cardholder authentication to occur even if the cardholder is offline. James explained the difference between this and the normal EMV 3DS challenge flow, and the benefits of decoupled authentication for different use cases. Such examples include when a merchant requests for the issuer to verify the cardholder for Mail Order/Telephone Order (MOTO) transactions, or prior to providing a high-value refund. Attendees also learned about other circumstances where delegated authentication may be valuable, such as to prevent social engineering or resolve device dependency issues. 3. There are plans to update the EMV 3DS user experience (UX). In 2021, EMVCo published the EMV 3DS UI/UX (user interface/user experience) Design Guidelines to help payment stakeholders implement a consistent, familiar and efficient approach to EMV 3DS UI/UX design that instils consumer trust in the authentication process and optimises the checkout experience. EMVCo has acknowledged the industry’s need for further enhanced UI/UX performance with respect to cardholder interactions during EMV 3DS transactions. At the meeting, it explained that a survey of EMVCo Associates was conducted in Q2 2023 to understand the real-life experience and attitudes towards EMV 3DS, in particular, how to improve the authentication success rate. This has been followed by a third-party expert UI/UX study to explore the field issues and feature clarifications. The results will be used to update the EMV 3DS UI/UX Design Guidelines later this year. 4. EMVCo is committed to aligning with industry partners to ensure EMV 3DS meets all users’ needs. Discussions also explored EMVCo’s work to align with key industry partners, including FIDO Alliance and W3C. Collaboration with these organisations supports the development of specifications, such as EMV 3DS, that improve security and payment experiences around the world. EMVCo explained how issuers and merchants can use FIDO-based WebAuthn and Secure Payment Confirmation (SPC) within the EMV 3DS flow to better determine the legitimacy of a transaction to help reduce the risk of fraud. This approach can make the authentication process three times faster than a standard EMV 3DS challenge. There was also a joint discussion with FIDO Alliance and W3C on Fime’s presentation at the Web Pay

Excerpt only.