PCI 3-D Secure
Three-Domain Secure (3DS) is a messaging protocol developed by EMVCo to enable consumers to authenticate themselves with their card issuer when making card-not-present (CNP) e-commerce purchases. EMV 3-D Secure is a new payment secure feature that supports app-based authentication and integration with digital wallets, as well as traditional browser-based e-commerce transactions. New cardholder authentication methods are introduced in the new 3-D Secure standards, including face recognition and fingerprint.
Overview
The PCI Security Standards Council (PCI SSC) have announced two new security standards to support implementation EMV 3D Secure (3DS) protocol of EMVCo. EMV® 3DS helps prevent unauthorized card-not-present (CNP) transactions. It protects merchants from exposure to CNP fraud by enabling consumers to authenticate themselves with their card issuers when making online purchases through web browsers or via mobile applications. EMVCo and PCI SSC work together to ensure the EMV 3DS function, and the related data and environment security, are all in good order for the successful and complete implementation of the entire 3DS ecosystem.
EMV® 3DS solutions make it increasingly difficult for criminals to obtain cardholder data (CHD) in online payment channels. "As CNP fraud continues to be a challenge globally, PCI SSC is pleased to be able to provide support for the secure implementation of these solutions."
"Dynamic authentication is becoming increasingly important to securing payments in an omni-channel world," added PCI SSC Chief Technology Officer Troy Leach. "A new and improved EMV® 3DS protocol supported by PCI Security Standards will enhance the security of 3DS infrastructures and transactions and improve dynamic authentication for e-commerce and m-commerce environments."
More About PCI SSC3DS Standard
The PCI Security Requirements and Assessment Procedures for EMV® 3-D Secure Core Components: ACS, DS, and 3DS Server (referred to as PCI 3DS Core Security Standard) and the PCI Security Requirements and Assessment Procedures for EMV® 3-D Secure SDK (referred to as PCI 3DS SDK Security Standard) focus on securing the EMV® 3DS infrastructure that supports 3DS transactions:
EMV which represents Europay, MasterCard and Visa are the first three companies to set the standard. Currently, the standard is managed by EMVCo. EMVCo was first established by the three organizations of EMV in February 1999. Currently, it is jointly held by AE, Discover, JCB, MasterCard, Union Pay and Visa. The main task is to develop product specifications, standards and certification for 3DS, and supervise and ensure global security interoperability. ACS, DS, and 3DSS products are required by the EMV 3DS 2.0 standard including the 3DS SDK standard for mobile devices. All 3DS products need to be certified by EMVCo before entering the market of 3DS service.
Participating 3DS card brands consist of AE, Discover, JCB, MasterCard, Union Pay and Visa. Card brands prescribe the Implementation Guidance of service institutions and operation specifications of the 3DS standard connecting with the original payment system. Card brands also prescribe the CNP Liability Transfer deadlines for payment institutions — issuers, merchants and service providers — using 3DS 2.0. According to Implementation Guidance and test standards, card brands verify 3DS products; after verification, card brands authorize agents to provide 3DS trading services with a Letter of Approval. Payment institutions are required to secure the card data environment and data security by card brands; to meet the requirement, payment institutions need compliance from a QSA company approved by PCI SSC.
PCI SSC is composed of AE, Discover, JCB, MasterCard, and Visa, mainly setting and maintaining the security standards related to the payment card industry including the PCI DSS, PCI 3DS, and PCI 3DS SDK Security Requirements. PCI SSC is responsible for selecting, training and verifying QSA companies (Qualified Security Assessor) which execute standards and compliance assessment. Secure Vectors is the first certificated QSA company in PCI 3DS.
Payment institutions, issuer banks (Issuer) and ACS (Access Control Server) are assessed by EMV product inspection, the card brands operation test, and the issuer bank operating environment. In order to get the ROC and AOC compliance reports, the issuer is required to validate data security with a QSA company based on PCI 3DS security standard requirements, and begins to provide 3DS services after delivering the report to card brands. The 3DSS system used by the service provider or merchant also needs to pass the same compliance and meet the implementation specifications of the card brands.
How to do
EMVCo® 3-D Secure – Protocol and Core Functions provides Specification v2.0 (EMV 3DS 2.0) for 3DS products (ACS, DS, 3DSS, 3DS SDK) features and specifications testing. To ensure interoperability between products, EMVCo will award the product a Letter of Approval and publish that on EMVCo's website.
The PCI 3DS standard contains two parts. Part 1: 3DS Baseline Security Requirements include the safety requirements of the 3DS operating environment. Part 2: 3DS Security Requirements are the system security and data security requirements of the 3DS system. The payment institutions or service provider shall conduct all technical and management requirements for the environment, personnel, system and data security in accordance with the corresponding systems and their PCI 3DS standards. If the operating environment of the 3DS system has already passed PCI DSS compliance, and the PCI DSS compliance audit scope is the same as the PCI 3DS operation requirements, then only Part 2 of PCI 3DS needs to be assessed.
In order to ensure that the handling process of 3DS transaction data complies with PCI 3DS standards requirements, payment institutions or service providers shall ensure their existing or planned processes for cardholder data flow and storage are based on the PCI 3DS Data Matrix for data storage, security and protection. These include protection and preservation requirements for Authentication data, Key data and Cryptographic Keys (for ACS, DS). Certain types of information shall also not be stored on the system. Please consult our consultants for more details.
PCI 3DS provides a set of common standards for payment institutions and service providers to establish management policies and procedures to ensure the security management of 3DS services in accordance with PCI 3DS specifications, such as access control policies and software development procedures. PCI 3DS also dictates strict records keeping requirements such as risk assessment results, relevant records of software and hardware, network architecture diagrams, data flow diagrams and all the testing and implementation records.
PCI 3DS requires the following technical tests:
- Software Security Tests
- Quarterly Internal and External Vulnerability Scans
- Annual Penetration Tests
Relevant tests may be conducted by a professional technology testing company or by an in-house specialist. The external vulnerability scan requires the use of a PCI SSC approved ASV.
PCI 3DS assessment can only be performed by a PCI SSC approved PCI 3DS QSA company, a list of which can be found on the PCI SSC website. Secure Vectors Information Technologies Inc. is currently among a small group of PCI SSC approved QSA companies to do PCI 3DS review services in the Asia-Pacific region. PCI 3DS assessment work can vary based on the size and environment of the client organization. The first step is a scoping of the work. The assessment phase which includes on-site reviews ranges from 3 to 5 days of on-site work. Upon completion of the assessment, the Report On Compliance (ROC) is signed by the QSA company and then the Attestation of Compliance (AOC) is signed by the client organization. The assessed entity shall submit the annual assessment AOC or ROC according to the requirements of the card brands or the acquiring bank. The PCI 3DS certification is done annually.