The EMV® 3-D Secure Authentication Domain of the A360 Payment Suite provides a comprehensive authentication framework that enables secure cardholder verification for e-commerce and digital payment transactions. Fully compliant with the latest EMV® 3-D Secure specifications, the platform delivers strong customer authentication while minimizing fraud and providing a seamless user experience across web, mobile and digital commerce channels.
The solution supports the complete EMV 3DS ecosystem through four integrated components: 3DS Split SDK, 3DS Server, Directory Server (DS) and Access Control Server (ACS). Together, these components establish a secure authentication bridge between merchants, payment service providers, acquiring institutions, card schemes and card issuers, ensuring end-to-end protection throughout the online payment authorization process.
The 3DS Split SDK provides the client-side authentication framework for mobile applications and digital commerce environments. It performs device fingerprinting, collects device intelligence, supports challenge user interfaces and securely communicates with the 3DS Server. The SDK enables merchants, payment gateways and payment service providers to integrate EMV 3DS authentication into native mobile applications while maintaining an optimized customer experience.
The 3DS Server serves as the central orchestration engine within the acquiring environment. It manages the complete authentication workflow by generating Authentication Requests (AReq), processing Authentication Responses (ARes), orchestrating challenge flows, managing merchant information and transmitting risk-related data to the issuer. The server provides seamless connectivity with the Split SDK, Directory Server and Access Control Server, ensuring interoperability across the entire authentication ecosystem.
The Directory Server (DS) acts as the central routing and directory infrastructure within the EMV 3DS architecture. Designed for deployment by local, regional or international card schemes, it identifies the appropriate Access Control Server for each transaction, validates card enrollment and securely routes authentication messages between acquiring and issuing domains. This functionality enables standardized interoperability across multiple issuers, acquirers and payment networks while supporting scalable authentication services.
The Access Control Server (ACS) is the primary issuer-side authentication component responsible for verifying the identity of the cardholder before an online payment is authorized. It supports multiple authentication methods, including one-time passwords (OTP), push notifications, biometric authentication and Risk-Based Authentication (RBA). By dynamically evaluating transaction risk, the ACS enables frictionless authentication for low-risk transactions while initiating challenge flows only when additional cardholder verification is required, thereby balancing security with customer convenience.
Built on a modular and highly scalable architecture, the EMV® 3-D Secure Authentication Domain integrates seamlessly with card management systems, fraud detection platforms, payment gateways, digital banking channels and international payment schemes. Its open interfaces and standards-based design enable rapid deployment in both issuer and acquirer environments while supporting cloud, on-premises and managed service operating models.
The solution delivers significant business and operational benefits, including stronger cardholder authentication, reduced e-commerce fraud, improved authorization approval rates, lower chargeback volumes and enhanced customer experience through intelligent, risk-based authentication. Fully aligned with EMVCo standards and international payment network requirements, the platform provides financial institutions, payment processors and payment service providers with a secure, interoperable and future-ready authentication infrastructure for modern digital payments.