Mastercard Identity Check Explained: A Guide to Modern Online Payment Authentication
vdelitz

vdelitz @vdelitz

About: Co-founder @ Corbado

Location:
Munich, Germany
Joined:
Mar 8, 2023

Mastercard Identity Check Explained: A Guide to Modern Online Payment Authentication

Publish Date: Jun 18
0 0

Read the full article here


Understanding Mastercard Identity Check for Secure Digital Payments

Mastercard Identity Check is the cornerstone of Mastercard’s online payment authentication, addressing the dual challenge of increasing security and delivering frictionless checkout experiences. Based on the EMV 3-D Secure (EMV 3DS) protocol, this program aims to ensure secure and smooth e-commerce transactions, helping issuers and merchants lower fraud rates, boost approval rates and improve overall customer satisfaction.


From SecureCode to Identity Check: Enhancing the Online Checkout

Earlier, Mastercard SecureCode (3DS 1.0) offered some protection against fraud but often caused friction and a suboptimal user experience, especially on mobile. Mastercard Identity Check advances this by supporting native mobile authentication, rich data exchange and more flexible, low-friction flows, ensuring that security measures don’t negatively impact user experience.


Core Technology: EMV 3-D Secure Protocol

EMV 3DS is an industry-standard for online payment authentication adopted globally. It facilitates secure data exchange between merchants, issuers, and cardholders, supporting over 150 data points for detailed risk assessment. The protocol allows risk-based authentication and native app support, introducing advanced authentication methods such as biometrics, OTPs, and device intelligence.


Key Features of Mastercard Identity Check

Mastercard Identity Check integrates several security technologies and proprietary enhancements for robust fraud detection:

  • NuData Behavioural Biometrics: Passively analyzes user behavior like typing, mouse movements and device handling to detect anomalies.
  • Device Intelligence: Gathers device-specific information (OS, browser, fingerprint) to recognize trusted devices and assess risk.
  • Risk-Based Authentication (RBA): Evaluates transaction risk in real-time using transaction history, device profile and behavioral analytics, deciding whether the flow should be frictionless or require additional verification.

Frictionless Payment Flows and SCA Exemptions

A primary goal of Mastercard Identity Check is maximizing frictionless flows, approving low-risk transactions transparently for the user. In markets with Strong Customer Authentication (SCA) requirements, such as the EU, the solution supports exemptions for scenarios like low-value payments or recurring transactions. Proper use of exemptions helps reduce cart abandonment and false declines, giving merchants better conversion rates.


Issuer Integration: Access Control Servers and BIN Enablement

To use Mastercard Identity Check, issuers must enable their card portfolios (Bank Identification Numbers) with an Access Control Server (ACS). This involves compliance checks, configuration and ongoing monitoring. Issuers can choose between building an in-house ACS or using certified third-party solutions, balancing control and compliance with operational costs.


Merchant and PSP Benefits: Approval Rates and User Experience

By adopting Mastercard Identity Check, merchants and payment service providers (PSPs) see higher approval rates and reduced fraud thanks to advanced data analysis and machine learning. This also means fewer authentication challenges for customers, improving the online payment experience and resulting in higher conversion rates.


Performance and KPI Monitoring

Mastercard guides issuers, merchants, and PSPs to optimize their authentication flows by tracking KPIs like challenge rates, authentication success, frictionless rate, fraud rate, approval rate and system performance. Regular reporting and the Data Integrity Monitoring Program (DIMP) ensure consistent and reliable performance across the network.


The Future: Passkey Authentication and Secure Payment Confirmation

Mastercard continues to improve online payment authentication with updates like EMV 3DS v2.3+, which introduces Secure Payment Confirmation (SPC) and direct support for passkey authentication using FIDO/WebAuthn standards. These innovations are paving the way for a passwordless, numberless future for digital payments, relying more on biometrics and strong cryptographic security methods.


Conclusion: Advancing Digital Payment Security

Mastercard Identity Check is a robust solution for modern online payment authentication, combining advanced fraud detection with a frictionless user experience. Its use of behavioral biometrics, device intelligence and risk-based authentication enables issuers and merchants to balance security with seamless digital commerce. To learn about implementation best practices, real-world adoption strategies and future developments in passkey authentication, find out more on www.corbado.com/blog/mastercard-identity-check.

Comments 0 total

    Add comment