• DeutschEnglish

SCA - 2FA - MFA

Description

SCA stands for Strong Customer Authentication and became mandatory with 3-D Secure 2.0.

SCA stands for Strong Customer Authentication and is technically done with 2FA (two factor authentication) or MFA (multiple factor authentication).

The authentication checks the credentials provided by a person.

The authentication is performed in two steps:

  1. a person provides information and claims to be "Mr. Miller" (DE: Authentisierung)

  2. this information is checked and either confirmed or rejected (DE: Authentifizierung)

Please note: In the German language, there is a difference between "Authentisierung" (somebody claims to be somebody) and "Authentifizierung" (verification of provided credentials). In the English language, there is no such difference; both are referred to as "authentication".

Basically, there are three different types (factors) of authentication:

  • something you know, e.g. username/password

  • something you have or own, e.g. smartphone, token generator (hardware or software)

  • some unique biological feature of your body (biometrics), e.g. fingerprint, face proportion, iris, or vein structure

SCA defines that for "strong customer authentication" at least two types of the latter must be used to authenticate a payment before initiating (authorizing) a payment – meaning that username and password are not sufficient.

2FA / MFA is also used to protect other accounts like Google, Amazon, Facebook, eBay, PayPal, ...

You can find a list of websites supporting 2FA / MFA here: https://2fa.directory

Paygate

Documentation (EN)

Dokumentation (DE)

Paygate Status