What is payment authentication?¶
Payment authentication checks whether the attempted user or endpoint can satisfy required security factors. Success proves completion of those factors, not necessarily the person's identity or informed consent.
Factors test knowledge, possession or characteristics¶
Passwords and PINs test something known; cards, phones and tokens test possession; biometrics test a characteristic through the enrolled system. Payments can combine factors through chip-and-PIN, one-time codes or application approval.
Credentials can be shared or stolen, codes intercepted and endpoints remotely controlled. A deceived victim may personally complete the process. Recurring or low-value transactions may use different rules or no fresh challenge.
Interpret the recorded security event¶
Preserve method, result, time, device and session IDs, IP-related data, code delivery and provider risk decisions. Report that the specified method succeeded rather than naming a human authenticator without corroboration.
Authorisation is the separate decision to permit the payment. Establish who completed authentication and under what circumstances from endpoint, account and contextual evidence.
The point to remember
Use authentication records to show which security requirements were satisfied, then prove the human actor and circumstances separately.