Device Binding with SMS OTP
Device Binding is a separate from digitization flow intended to increase assurance level of card-on-file and other type of e-commerce tokens for the specific device and merchants while processing card-not-present authorizations. This process was introduced by Visa as part of Cloud Token Framework.
Device Binding is initiated by merchant or involved in Card-Not-Present authorizations Token Requestor. Token to device binding is performed for the tokens that was already succesfully provisioned and activated.
|Token Service Provider
|Visa Token Service
|Yellow path as REQUIRE_ADDITIONAL_AUTHENTICATION
|Check Eligibility (Visa specific)
|Not applicable in this flow
Sequence steps description
|Merchant propose consumer to proceed with token to device binding process
|Consumer opt into token to device binding process
|Merchant initiate token to device binding process
|4.1. Visa Token Service send device binding request to the MTP I-TSP.
4.2. MTP I-TSP passthrough device binding request as Authorize Binding request to the issuer.
|Issuer response to the device binding with the REQUIRE_ADDITIONAL_AUTHENTICATION to request additional verification and identification(ID&V) of consumer.
|Visa Token Service receive the issuer device binding decision to proceed with additional ID&V of consumer.
|7.1. Visa Token Service request available for consumer ID&V options
7.2. MTP I-TSP passthrough ID&V options request as Request Activation Methods to the issuer
|Issuer generate list of consumer available ID&V option
|Visa Token Service receive the list of available for consumer ID&V options
|10.1. Visa Token Service provide available ID&V options to the merchant
10.2. Merchant display available ID&V options to the consumer
|Consumer select SMS OTP as ID&V option
|Merchant passthrough consumer selected option and request activation code(OTP as One-Time Password) to be delivered to the consumer.
|Visa Token Service generate activation code
|Visa Token Service deliver activation code to the issuer through the MTP I-TSP
|Issuer deliver activation code in SMS text message to the consumer
|Consumer enter activation code received in SMS to the merchant screen
|Merchant pass activation code to the Visa Token Service for validation
|Visa Token Service succesfuly validated activation code
|Visa Token Service approve device binding request
|Visa Token Service notify merchant about succesful device binding