3D認證(3-Domain Secure, 3DS)為制定信用卡組織(EMVco.)針對線上無卡交易訂定的標準。其中,3DS 2.2版本為確保身分準確性導入了快速身分驗證機制(Fast Online Identity, FIDO),並由商家擔任FIDO身分驗證角色。然而這樣的做法導致發卡銀行可能收到不真實的驗證結果,反而增加了身分冒用的風險。因此,本研究提出3DS-FIDO架構來提升整體的註冊及交易流程。在此架構中,使用者的FIDO驗證器須先透過EMV卡片認證協定,完成實體卡綁定。並且,後續的每筆交易由發卡銀行驗證使用者的FIDO身分。這樣確保銀行進行3DS及FIDO雙重驗證,對使用者來說也免除需分別向各商家綁定FIDO的麻煩手續,更可降低身分冒用的風險。最後,我們針對3DS-FIDO進行安全分析,並證明我們所提之架構可全面抵抗各式攻擊。本研究能有效提升3DS中身分驗證的安全性,並透過實體卡與驗證器綁定步驟,使得驗證器可作為合法實體卡的存在。相比原3DS流程更具安全性,更能有效防範線上無卡交易盜刷的發生。
3D Secure (3DS), a standard developed by EMVCo. for online card-not-present transactions, aims to enhance security in such scenarios. In its 3DS 2.2 version, the Fast Online Identity (FIDO) authentication mechanism was introduced to ensure identity accuracy, with merchants acting as FIDO authentication entities. However, this approach may lead to issuing banks receiving potentially inaccurate authentication results, thereby increasing the risk of identity fraud. This study proposes the 3DS-FIDO framework to enhance the overall registration and transaction processes. In this framework, the user's FIDO authenticator must first complete physical card binding through the EMV card authentication protocol. Subsequently, for each transaction, the issuing bank verifies the user's FIDO identity. This ensures dual verification via 3DS and FIDO by the bank, eliminating the inconvenience for users of binding FIDO credentials with individual merchants. It also reduces the risk of identity fraud. Finally, we conduct a security analysis of 3DS-FIDO and demonstrate that the proposed framework effectively resists various attacks. This study significantly enhances identity verification security within 3DS. Through the binding of physical cards with authenticators, the authenticator is effectively validated as a representation of the legitimate physical card. Compared to the original 3DS process, this framework offers superior security and effectively mitigates the occurrence of online card-not-present fraud.