- Combining the Authentication and the Authorization Services
- Implementing SDK Payer Authentication
- Authentication Examples Using Primary Account Numbers
- Authentication Examples Using Digital Payment (Google Pay)
- Authentication Examples Using TMS Tokens
- Authentication Examples Using Flex Microform Tokens
- Authentication Examples Using Tokenized Cards
- Authentication Examples of Merchant-Initiated Transactions
- Testing Payer Authentication
Mobile Device Data Collected
One of the key components to authenticating a cardholder during an online transaction is
to compare information about the mobile device that the buyer is using to the
information about mobile devices that the buyer used in past transactions. This
information is maintained in the access control server (ACS) at the issuing bank.
In mobile device transactions, information collected about the buyer device can
include:
- Device ID
- Device model
- Operating system version
- System language
- Country
- Time zone
- Screen dimensions
A successful device data collection process that includes the eleven browser fields listed
in the check enrollment step, increases the chances of a frictionless authentication.
The decision to escalate a transaction to a level of risk high enough to require
challenging the buyer to authenticate their identity is managed by business rules that
are configured in the issuer's risk analysis software that evaluates each
transaction.