EMV3DS-01 | Three-domain model | 0 |
EMV3DS-02 | 3DS Requestor and 3DS Client | 0 |
EMV3DS-03 | 3DS Server (Acquirer Domain) | 0 |
EMV3DS-04 | Directory Server (Interoperability Domain) | 0 |
EMV3DS-05 | Access Control Server (Issuer Domain) | 2 |
EMV3DS-06 | 3DS SDK | 0 |
EMV3DS-07 | Authentication Request and Response (AReq/ARes) | 0 |
EMV3DS-08 | Challenge Request and Response (CReq/CRes) | 0 |
EMV3DS-09 | Results Request and Response (RReq/RRes) | 0 |
EMV3DS-10 | Message integrity and protocol versioning | 0 |
EMV3DS-11 | Frictionless flow | 1 |
EMV3DS-12 | Challenge flow | 2 |
EMV3DS-13 | Decoupled authentication | 0 |
EMV3DS-14 | Challenge authentication methods | 1 |
EMV3DS-15 | Browser-based channel | 0 |
EMV3DS-16 | App-based channel and device information | 1 |
EMV3DS-17 | 3DS Requestor-Initiated and non-payment authentication | 0 |
EMV3DS-18 | Risk-based authentication | 1 |
EMV3DS-19 | Strong Customer Authentication support and exemptions | 1 |
EMV3DS-20 | Message security and key management | 1 |
EMV3DS-21 | Cardholder data protection and minimisation | 1 |
EMV3DS-22 | EMVCo approval and conformance | 0 |
3.1.S10-11 | 3.1.S10-11 App: SDK completes the secure channel and sends the first CReq (Steps 10 and 11) | 0 |
3.1.S12-14 | 3.1.S12-14 App: ACS builds the challenge and the SDK renders it (Steps 12 to 14) | 0 |
3.1.S15-17 | 3.1.S15-17 App: cardholder response, verification, retries and abandonment (Steps 15 to 17) | 0 |
3.1.S18-22 | 3.1.S18-22 App: results messaging RReq and RRes (Steps 18 to 22) | 0 |
3.1.S23-25 | 3.1.S23-25 App: final CRes and completion (Steps 23 to 25) | 0 |
3.1.S4 | 3.1.S4 App: Requestor App and SDK gather AReq data (Steps 1 to 4) | 0 |
3.1.S5 | 3.1.S5 App: 3DS Server verifies the SDK, routes and sends the AReq (Step 5) | 0 |
3.1.S6 | 3.1.S6 App: DS validates, checks participation and forwards the AReq (Step 6) | 0 |
3.1.S7 | 3.1.S7 App: ACS decides the transaction status and prepares any challenge (Step 7) | 0 |
3.1.S8-9 | 3.1.S8-9 App: DS relays the ARes and the 3DS Server acts on the status (Steps 8 and 9) | 0 |
3.2 | 3.2 Out-of-band challenge flow exceptions | 0 |
3.3 | 3.3 Browser-based flow requirements | 0 |
3DS | EMV 3-D Secure: the protocol, its three domains, messages and versions | 0 |
4.2.1 | 4.2.1 App processing screen | 0 |
4.2.2-3 | 4.2.2-3 App native UI templates and message exchange | 0 |
4.2.4-5 | 4.2.4-5 App HTML UI templates and exchange | 0 |
4.3 | 4.3 Browser UI: processing screen and challenge window | 0 |
5.1 | 5.1 General message handling: POST, content type, Base64, versions, parsing and validation | 0 |
5.2-4 | 5.2-4 Outages, availability and error codes | 0 |
5.5.1 | 5.5.1 Transaction timeouts | 0 |
5.5.2 | 5.5.2 Read timeouts per message pair | 0 |
5.6 | 5.6 PReq/PRes card range cache | 0 |
5.7 | 5.7 App-based message handling and CReq/CRes protection | 0 |
5.8.1 | 5.8.1 3DS Method handling | 0 |
5.8.2 | 5.8.2 Browser challenge window | 0 |
5.9 | 5.9 Message error handling per component | 0 |
6.1.1 | 6.1.1 Link a: consumer device to 3DS Requestor | 0 |
6.1.2-3 | 6.1.2-3 Links b and c: 3DS Server to DS and DS to ACS | 0 |
6.1.4 | 6.1.4 Link d: SDK or browser to ACS for the challenge | 0 |
6.1.8 | 6.1.8 Link h: browser to ACS for the 3DS Method | 0 |
6.2.1-2 | 6.2.1-2 Functions H and I: SDK authenticity and SDK encryption to the DS | 0 |
6.2.3-4 | 6.2.3-4 Functions J and K: SDK to ACS secure channel and protected challenge messages | 0 |
A.1-6 | A.1-6 Data elements: required, conditional and optional fields, edit criteria, extensions | 0 |
A.7 | A.7 3DS Requestor risk information: cardholder account, merchant risk indicator and requestor authentication | 0 |
D | Data elements, extensions and risk information (Annex A) | 0 |
F | Authentication flow requirements (chapter 3: app-based, out-of-band, browser-based) | 0 |
M | Message handling requirements (chapter 5) | 0 |
S | Security requirements: links and functions (chapter 6) | 0 |
U | User interface requirements (chapter 4) | 0 |