Authentication
How individual end users authenticate to authorize actions, per src-functional-requirements §1.3.
Two paths
- On the Eurosystem digital euro app: seamless authentication (public-key crypto +
biometrics/PIN), letting the consumer stay in the merchant app for m-commerce without a
visible redirect (
FUR.16–FUR.17). Default is still redirection; seamless auth is offered for selected use cases. E-commerce uses decoupled authentication (biometrics/PIN via a digital euro app notification) (FUR.18). - On a pilot PSP’s own proprietary app: PSP chooses its own strong customer
authentication method (including EDIW support for online payments), subject to
applicable regulatory/security requirements and the minimum UX requirements in
src-user-journeys-ux-requirements (
FUR.19–FUR.20).
Offline
Relies on the device’s local authentication mechanism (digital euro app or proprietary
app) — no server round-trip for the payment itself. Online connectivity is only needed for
(de)funding or device-related operations (FUR.21).
Related
online-and-offline-payments · pilot-psp · src-functional-requirements