Global eCommerce payment fraud is estimated to reach $48 billion this year. That's a 14% rise from last year.

As eCommerce continues to grow, so too will the number of thieves targeting its payments infrastructure and card details through tactics such as phishing scams.

It's an ongoing battle, but the financial authorization process has adapted to support internet payments.

Perhaps the simplest and most effective example of this is 3D Secure. Let's take a look at what it is and how it works.

What is 3D Secure?

3D Secure (3DS) is an additional security authentication measure used in online card transactions.

It is used to add an additional layer of security for both the cardholder and the online merchants.

'3D' stands for 'three domains'. The three-domain model consists of:

  1. The card issuer (the financial institution that issues a debit or credit card to the customer)
  2. The merchant that receives the payment
  3. The 3DS infrastructure that acts as a secure layer between customers (via card issuers) and merchants

3D Secure is designed to provide protection against fraudulent transactions.

Strong Customer Authentication (SCA) regulation requires the use of 3D Secure for European card payments. 3D Secure is optional in other regions across the globe, but still strongly recommended.

How does the 3D Secure process work?

When a customer makes an online purchase via credit or debit card, 3D Secure decides whether an extra security protocol needs to be implemented for each card payment. This protocol helps make sure that the customer is the rightful cardholder.

Step 1: Redirect to 3DS page & single-use pin generation

If 3D Secure is used, the customer will be directed to a 3DS page. This is where the authentication process begins. The cardholder will be asked to enter a PIN or password after they have completed the online checkout process.

Simultaneously, the cardholder's bank will generate a single-use PIN, sending push notifications to the customer's phone via an SMS code.

Step 2: Single-use PIN entry

Obviously, if the card transaction is not genuine, then attempted fraudulent activity should be blocked at this stage.

For a genuine transaction, this PIN will need to be entered into the 3DS page to verify any online payments.

Step 3: Card issuer approval or decline

Next, all information is forwarded to the card issuer, who either approves or declines the transaction.

Once the data is received by the issuer, it is run through an automated fraud detection system, which checks if the transaction is low or high-risk.

Low-risk transactions are typically approved automatically, with the customer only experiencing a 1-5 second delay whilst the payment is being processed.

High-risk transactions, on the other hand, may require more. This could mean a customer being sent a one-time password or using biometric authentication (such as fingerprint authentication) on their online banking app as an additional verification step.

Advantages and disadvantages of 3D Secure

Advantages of 3D Secure

1. Increased security

The main benefit of 3D Secure is the increased layer of security it brings.

In particular, because it verifies the cardholder's identity, it stops many attempts at fake profiles being set up to make payments.

Protection against chargebacks

3D secure is particularly good at providing increased protection against fraudulent chargebacks.

Visa Secure and Verified by Visa both ensure that merchants will not receive a chargeback on their account.

This can help prevent 'friendly fraud'. This is when a cardholder makes an online purchase and then purposely attempts to file a fraudulent chargeback.

Recent studies have found that merchants who use 3D secure can reduce chargebacks by as much as 70%.

2. Interchange benefits

与威士卡或万事达卡一起使用时,3D Secure 可以提供交换费和更长支付期限等交换优势。

持卡人和发卡机构都能从中受益:

  • 加强客户保护,提高供应商销售额
  • 更好的国际客户交易
  • SSL 加密保护服务器
  • 提高客户满意度

3.客户信心

如果客户确信他们的购物体验是安全的,他们就更有可能信任您的公司。

使用 3D Secure 可以让使用您网站的客户放心,与您共享他们的个人和财务信息是安全的。

4.责任转移

3D Secure 可确保商家不对欺诈性退款负责。

相反,责任从企业转移到了对欺诈性退单负责的发卡银行或发卡机构。虽然理想的情况是提出更少的扣款,但将责任转嫁给发卡行是供应商实施 3DS 的有力理由。

所有争议都将由发行商在幕后管理,而不是出现在供应商仪表板上。

3D 安全技术的缺点

3D Secure 有一些缺点。

1.摩擦

3DS 可能会给客户的购物体验带来摩擦。需要输入一次性密码可能会导致顾客放弃购物篮。

Ravelin 的研究发现,3DS 平均需要 37 秒,22% 需要 3DS 的付款会丢失

2.实施成本

建立或使用 3D Secure 可能会产生额外费用。这就给初创企业或预算较低的企业带来了困难。

当然,这取决于实施的方式和选择协助实施的支付处理商。

3.消费者缺乏了解

在未强制使用 3D 安全技术的市场,持卡人可能并不完全熟悉它。

如果他们不了解这是什么或如何完成需要它的付款,可能会阻止他们完成交易,导致他们放弃购物车。

什么是 3D 安全 PIN 码?

3D Secure PIN 或 3DS PIN 是一种六位数字代码,由银行卡用户使用,用于验证采用 3D Secure 协议的在线交易

该代码用于在网上购物时向发卡银行确认卡主身份。

与实体 POS 终端或自动取款机使用的传统 PIN 码类似,3D 安全 PIN 码能提高银行卡交易的安全性。它们可以保护金融资产,增强消费者对发起交易的信心。

什么是 3D secure 2.0?

3D Secure 2.0是一种用于在线交易的安全协议,可提供比标准 3D Secure 更高级别的身份验证信息。

Visa 的一项研究发现,它可以减少多达 40% 的欺诈行为。它允许商家与持卡人的银行进行沟通,反之亦然。

EMVCo 于 2016 年发布了 3D secure 2.0。其设计初衷是纠正原版本的一些局限性。

3D Secure 的第二个版本简化了验证过程。它确保在线结账体验尽可能无摩擦,同时又不牺牲额外的安全层。

3D Secure 的原始版本和 2.0 版本的主要区别在于:

  • 3D Secure 2.0 支持移动设备
  • 3D Secure 2.0 解决了 1.0 中存在的安全性和可用性问题。这包括 用一次性密码取代静态密码,以及生物识别身份验证

向 3D Secure 2.0 的转变与消费者转向移动和在线购物的趋势一致。商户们正在策略性地利用这一趋势,将 2.0 纳入其战略中。

与努维合作进行支付和欺诈风险管理

与合适的支付服务提供商合作,可以大大提高支付的安全性。

我们的欺诈和风险管理平台可完全集成到您的支付解决方案中。

它提供实时欺诈检测和评分引擎,可以及早阻止交易欺诈。它可以帮助您减少风险、扣款和客户注册时间,简化 PCI DSS 合规性并管理 3D Secure 的复杂性。

什么是 3d Secure 支付网关?

3D Secure 支付网关采用 3D Secure 或 3D Secure 2.0 协议授权在线交易。当买家与没有实体卡的商家交易时,该系统可提高安全性。在通过 3D 安全网关进行在线支付的过程中,持卡人需要通过输入固定密码、临时 PIN 码、一次性代码或使用生物识别验证来确认身份。

结论

3D Secure 是在线支付过程中防止欺诈的有力工具。在欧洲,这是一项法律要求,也是客户身份验证的一个范例,但在其他地方则是可选的。

它验证客户、发卡机构和 3DS 基础设施三方之间的数据点。

有了这个额外的验证步骤,就可以防止各种欺诈活动,如虚假资料和友好欺诈。它还能带来交换优势,增强客户信心,并将责任从商户转移到发卡银行。

它可能会带来一些不利因素,如客户摩擦和实施成本。

3D Secure 2.0 是一个重要的更新,使其成为功能更强大的工具版本。它支持移动支付,并可使用一次性密码和生物识别身份验证。

更多见解

准备好在各地拓展业务了吗?

立即开始使用 Nuvei——适用于任何支付场景、覆盖全球的增长基础设施。一个智能系统,专为扩展而设计。