NCP Authentication 3DS
What is 3-D Secure Authentication?
3-D Secure is a security protocol designed to provide an additional layer of protection for online credit and debit card transactions. The term "3-D" refers to the three domains that interact using this protocol: the merchant/acquirer domain, the issuer domain, and the interoperability domain.
The protocol was initially developed by Celo Communications AB for Visa Inc. in 1999 and later updated by Gemplus between 2000-2001. It was introduced to enhance the security of internet payments and is offered under various brand names such as Verified by Visa (now Visa Secure), Mastercard SecureCode (now Identity Check), Discover ProtectBuy, JCB International J/Secure, and American Express SafeKey.
How 3-D Secure Works
The core idea of 3-D Secure is to link the financial authorization process with online authentication. This is achieved through a three-domain model:
- Acquirer Domain: This includes the bank and the merchant receiving the payment.
- Issuer Domain: This involves the card issuer.
- Interoperability Domain: This includes the infrastructure provided by the card scheme to support the 3-D Secure protocol, such as the internet, merchant plug-in, access control server, and other software providers.
The protocol uses XML messages sent over SSL connections with client authentication to ensure the authenticity of both the server and the client. During a transaction, the user is redirected to the card issuer's website to authorize the transaction. The authentication method can vary but typically involves entering a password tied to the card.
Benefits and Drawbacks
Benefits:
- Enhanced Security: By requiring an additional password or one-time code, 3-D Secure helps prevent unauthorized transactions even if card details are compromised.
- Reduced Chargebacks: Merchants benefit from a reduction in "unauthorized transaction" chargebacks.
Drawbacks:
- User Experience: The additional authentication step can be seen as a nuisance, leading to increased transaction abandonment and lost revenue for merchants.
- Phishing Risks: The use of pop-up windows or inline frames for authentication can make it difficult for users to verify the legitimacy of the authentication page, increasing the risk of phishing attacks.
3-D Secure 2.0
In October 2016, EMVCo published the specification for 3-D Secure 2.0, which aims to be less intrusive and more user-friendly. It allows more contextual data to be sent to the card issuer to assess the risk of the transaction, reducing the need for user intervention. The new version also supports out-of-band authentication via mobile apps and biometric authentication.
3-D Secure 2.0 is compliant with the EU's "strong customer authentication" mandates, making it a robust solution for secure online transactions.
Powered by: Joxall Marketing Group - www.jxlmkt.com
