Home / Companies / Evervault / Blog / February 2025

February 2025 Summaries

2 posts from Evervault

Filter
Month: Year:
Post Summaries Back to Blog
EMV 3D-Secure (3DS) is an advanced version of the original 3D-Secure protocol developed by VISA to combat payment fraud in online transactions while maintaining a streamlined user experience. By leveraging risk-based analysis and advanced authentication methods, such as biometrics and one-time passcodes, EMV 3DS aims to reduce fraud without causing excessive disruptions to the payment process. The protocol involves three main components—Directory Server, Access Control Server, and 3DS Server—that facilitate either a frictionless flow for low-risk transactions or a challenge flow for those requiring additional verification. Mandated in Europe under the Strong Customer Authentication component of the Revised Payment Service Directive, EMV 3DS shifts liability for chargebacks from merchants to card issuers, offering merchants protection against fraud costs. The evolution of the protocol, backed by EMVCo, has improved user experience by supporting mobile-first designs and digital wallet payments, and future developments may further integrate AI and IoT support to enhance security and convenience.
Feb 25, 2025 973 words in the original blog post.
The webinar on implementing and optimizing 3D-Secure addressed various questions about the technology, focusing on its application for payment and authentication processes. It clarified that each card network, like Visa and Mastercard, operates its directory server, which communicates with the issuing bank's Access Control Server during the 3DS flow. The discussion highlighted that Non-payment Authentications allow card additions without payments, while 3DS is necessary for payment authorizations to benefit from liability shifts. Recurring payments can use Merchant-Initiated Transactions for backend authentication, and the system can fallback to direct authorization if 3DS servers fail. In terms of infrastructure, businesses typically rely on 3DS Server vendors, and Evervault supports both backend and frontend integration for Customer-Initiated Transactions, requiring frontend for browser details collection. The 3DS process often involves merchants initiating authentication, particularly in 3DS-Requestor Initiated scenarios, with fingerprinting skipped for non-present cardholders. Technical limitations may affect acquirers' acceptance of external authentications, but payment service providers like Stitch can facilitate this. Evervault's standalone 3D-Secure Server offers a flexible solution for merchants to authenticate payments, shift liability, and meet regulatory requirements.
Feb 05, 2025 782 words in the original blog post.