Eps 3: What is 3DS

isaballe

Host image: StyleGAN neural net
Content creation: GPT-3.5,

Host

Lucas Porter

Lucas Porter

Podcast Content
From 14 September 2019, all payment portals will now require additional security steps in relation to SCA for customer purchases within the European Union. Strict Customer Authentication is a European regulation introduced to reduce fraud and make it easier for customers to purchase by adding an additional security step for purchases and subscriptions.
For example, if there is not enough credit in the account, the transaction will be rejected. If the customer cannot authenticate for a transaction within the grace period allotted to him, this will also be marked as a failed transaction. All e-commerce retailers will have to adapt their solutions by May 2019, according to the brand's statement.
Although the SCA is not required for all purchases, there are some of the factors mentioned above that suggest that it may not be necessary. For high-chargeback and fraud traders, the solution should be even more useful, as the shift of liability is passed on to the bank as a problem. This is possible as long as a fixed threshold for the fraud rate is not exceeded.
Ultimately, it depends on the bank and the payment method used to make the purchase, and the business will include a trusted recipient maintained by the customer's bank or payment service provider. Once payment authentication is complete, customers may have the option of putting a company they trust on a whitelist to avoid having to authenticate themselves on future purchases.
The advantage of using data is simply that it enriches the databases of the issuing banks and MasterCard, which will receive more information about the holder and trader. Authentication is done silently without the airline calling the authentication into question, and once the transaction is authenticated, liability in the event of fraud is embedded in each issuer. Because issuers do not have their own 3DS 2.0 solution, they will not be able to report this protection, even though they have greater confidence in transaction authentication.
Once authentication is complete and the authentication data is sent, an authorization procedure is filed. If you implement this authentication process in addition to Cielo External Authentication, you can skip the authorization step completely.
This data is only an optional field that can only be used for MasterCard. If no authentication is required, a 3DS 2.0 field is also mapped and sent to the Mastercard issuing banks.
This applies if a customer makes a series of recurring payments of the same amount to the same company. When a subscription or invoice is invoiced, the corresponding transaction is put on a suspense state until the customer authenticates with the invoices. A fixed amount of money for a single payment or a fixed amount over a period of time. The total amount for the total number of payments and the amount fixed for each individual.
The bank must apply for authentication before using the exemption if the sum of previously exempted payments exceeds 100 euros. The cardholder and the bank must track the number of times this exemption has been used and decide whether authentication is required.
If the issuer is not yet able to respond to an authentication request using EMC 3DS 2.0, we have an independent model. The issuer identifies the holder as a potential risk, returns the authentication URL and then requests a challenge. Customers must follow instructions from their bank to authenticate the 3D purchase themselves. When a transaction is sent with an authentication request for 3DDS-2.1 or 2D3D-0, it is critical that the "issuer flag" in the Cielo solution is ready.
The 3DS 2.0 solution returns the authentication result to the vendor via a script and returns the authentication results to the vendor. Using the 3DDS - 2.1 and 2D3D-0 authentication protocols, we need to parameterize the bpmpi _ auth field, which describes the level of security of the transaction and the issuance of an authorization rating for the silent authentication issuer. When we consider where the market will grow when it integrates with the new 2 - 0 authentication protocol, we try to improve the ratings of "silent authentication" and "issuer approvals." The solution consists of three components: the Cielo solution, the EMC-3Ds-1 solution and a third-party solution for the issuer.
The new version also analyzes several variables used as criteria for determining the authenticity of the cardholder, in order to allow fewer interactions and challenges in authenticating the cardholder in the event of a risky shift of the merchant's liability.
In addition, as of May 2019, Mastercard will levy an additional fee for unauthenticated transactions by a purchaser, which could affect the price negotiated between Cielo and the merchant. It is worth mentioning that in this model the risk of backloading and fraud remains with the traders if there is no authentication on the part of the issuer. EMV 3DS, also known as 3DDS 2.0, is a new authentication technology developed by the payment industry to reduce the risk of fraud without affecting conversion rates. Transactions below 30 euros are considered to be low value transactions and may be exempted from SCA.