3-D Secure 2 Authentication

Device data, AReq/ARes risk scoring, challenge, and the cryptogram carried into authorization

3-D Secure 2 Authentication Device data, AReq/ARes risk scoring, challenge, and the cryptogram carried into authorization device data AReq AReq ARes (Y/C) CReq challenge OTP / biometric RReq result ECI + CAVV approved Authenticate Challenge Authorize Browser · cardholder · Sequence participant Browser cardholder 3DS Server · requestor · Sequence participant 3DS Server requestor Directory · scheme DS · Sequence participant Directory scheme DS Issuer ACS · authenticator · Sequence participant Issuer ACS authenticator Authorization · acquirer · Sequence participant Authorization acquirer Legend request return security async trace

Frictionless first

  • • Device data collected before Pay
  • • Most transactions stop at ARes (Y)
  • • Challenge is a bounded detour, not the norm

Trust the RReq

  • • Browser CRes is attacker-reachable
  • • Authoritative result arrives out of band
  • • Persist threeDSServerTransID to resume

Carry the proof

  • • ECI + CAVV + dsTransID into the auth
  • • Issuer revalidates the cryptogram
  • • A dropped CAVV silently loses liability shift