> For the complete documentation index, see [llms.txt](https://docs.payments.thalescloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.payments.thalescloud.io/tokenization/ja/implement-tokenization/post-tokenization-requests/update-the-digital-card-assurance-method-e-commerce-only/device-binding-flow.md).

# トークンバインディング

通常、マーチャントなどのトークンリクエスタは、エンドユーザーがトークンで支払う準備ができたときにトークンバインディング要求を開始します。トークンバインディングはトークンの使用を制限し、その正当性への信頼性を高めます。

D1 は要求を受け取り、登録済みデータを使用してワークフローをオーケストレーションします。イシュアバックエンドには新しい API は不要です。イシュアバックエンドの関与レベルは、イシュアが選択した統合モデルによって異なります。

トークンバインディングにはデバイスが関与するため、イシュアは D1 オンボーディング中に信頼しないデバイスタイプを定義できます。D1 は、このデータを使用して、TSP が必要なデバイス情報を提供した場合にバインディング要求を拒否します。

次の表には、イシュアが信頼しないデバイスを定義するために使用できる情報を示します:

| ルール名               | 説明                                                     |
| ------------------ | ------------------------------------------------------ |
| 信頼しないデバイスタイプ       | イシュアは、信頼しないデバイスタイプを選択できます。たとえば、次のタイプのデバイスなどです `WATCH`. |
| デバイス製造元            | イシュアは、信頼しないデバイス製造元を一覧表示できます。                           |
| デバイス製造元 - OS バージョン | 既知の場合、イシュアは信頼しない OS バージョンを指定できます。                      |
| デバイス製造元 - FW バージョン | 既知の場合、イシュアは信頼しないファームウェア バージョンを指定できます。                  |

信頼しないデバイスに関するルールがない場合、D1 は常に **ステップアップ認証** を各バインディング要求に対して必要とします。

### シーケンス図

次のシーケンス図は、D1 がオーケストレーションする全体のフローと、イシュアバックエンドの関与レベルを示しています。

<figure><img src="/files/9e73cf608231b12f8c7c66748332bbdee82ac1a3" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/1e5827b1895fcf88a5375f51c35c9cde002dff97" alt=""><figcaption></figcaption></figure>

信頼しないデバイスが定義されていない場合、または定義されたルールに一致するデバイスがない場合、D1 は常に **ステップアップ認証** および利用可能な ID\&V 方法の一覧を提供します。

ID\&V の前提条件については、 [ID\&V 方法の前提条件](/tokenization/ja/implement-tokenization/post-tokenization-requests/update-the-digital-card-assurance-method-e-commerce-only.md#prerequisites-for-id-and-v-methods).

#### SMS またはメールによる OTP 検証

次のシーケンス図は、エンドユーザーが検証方法として SMS またはメールによる OTP を選択したときのフローを示しています:

<figure><img src="/files/350aec4c0e00c2dcb0f2ae940134e57b85b238ce" alt=""><figcaption></figcaption></figure>

この `ステップアップ方法を配信` ステップでは `08` は依然として [OTP を配信](/tokenization/ja/integrate-the-d1-api/d1-api-reference/outbound-api-from-d1/consumer-api.md#post-banking-d1-v1-issuers-issuerid-consumers-consumerid-otp) API に対応します。この API は、選択された ID\&V 方法、この場合は OTP を配信します。

イシュアバックエンドが OTP 配信を管理する場合、 [OTP を配信](/tokenization/ja/integrate-the-d1-api/d1-api-reference/outbound-api-from-d1/consumer-api.md#post-banking-d1-v1-issuers-issuerid-consumers-consumerid-otp) API を実装し、 `otp.reason` フィールドを使用して、この要求とトークン化リクエストを区別する必要があります。これには `deliveryChannel` を使用してメッセージの種類を判別できます:

* `otp.reason` = `DEVICE-BINDING`
* `deliveryChannel` = `SMS` または `EMAIL`

#### イシュアアプリケーションによる検証

次のシーケンス図は、エンドユーザーが検証方法としてイシュアアプリケーションを選択したときのフローを示しています:<br>

<figure><img src="/files/64a318c593180a7a6a7b43cb932765a2418c9d2b" alt=""><figcaption></figcaption></figure>

で説明したとおり、 [高レベルフロー](/tokenization/ja/implement-tokenization/post-tokenization-requests/update-the-digital-card-assurance-method-e-commerce-only.md#high-level-flow) セクションでは、イシュアバックエンドはステップで必要な統合を処理する必要があります `[02]`。共有データは TSP に依存します。トークン化フローと比較して、次のマッピングを使用して `StepupAuthenticationResult` を正しく設定します:

<table><thead><tr><th width="228.45458984375">D1</th><th width="261.727294921875">Mastercard</th><th>Visa</th></tr></thead><tbody><tr><td><code>authenticationId</code></td><td><code>authenticationCorrelationId</code></td><td><code>lifeCycleTraceID</code></td></tr></tbody></table>

#### イシュア管理のトリガーを使用したイシュアアプリケーションによる検証

イシュアは、PUSH メッセージを使用してイシュアアプリケーションでの検証をサポートできます。これにより、マーチャントアプリケーションがイシュアアプリケーションを起動することに依存せずに済みます。

{% hint style="warning" %}
このオプションは、次の条件下でのみサポートされます:

* イシュアは Mastercard カードをサポートしています。この種の ID\&V オプションをマーチャントに伝播できるのは Mastercard のみです。
* イシュアは、エンドユーザーにメッセージを送信するために D1 OBO サービスに依存していません。その場合、Thales はイシュアに代わって PUSH メッセージを送信できません。
  {% endhint %}

次の図は、このフローを示しています:

<figure><img src="/files/a2c718814bc7b8cb4d6091c871acb2823c9d821c" alt=""><figcaption></figcaption></figure>

この `ステップアップ方法を配信` ステップでは `04` は依然として [OTP を配信](/tokenization/ja/integrate-the-d1-api/d1-api-reference/outbound-api-from-d1/consumer-api.md#post-banking-d1-v1-issuers-issuerid-consumers-consumerid-otp) API に対応します。この API は、選択された ID\&V 方法、この場合は PUSH メッセージを配信します。このケースを特定するには、イシュアは次のフィールドを確認する必要があります:

* `otp.reason` = `DEVICE-BINDING`
* `deliveryChannel` = `PUSH`
* `deviceInformation.deviceReference`
* `digitalCardId`

結果を報告するには `StepupAuthenticationResult`、イシュアは次の値を `digitalCardId`:

* `authenticationId` = `deviceInformation.deviceReference`

{% hint style="warning" %}
この場合、 `otp.value` は提供されません。

イシュアは PUSH メッセージの内容と形式を自由に管理できます。
{% endhint %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.payments.thalescloud.io/tokenization/ja/implement-tokenization/post-tokenization-requests/update-the-digital-card-assurance-method-e-commerce-only/device-binding-flow.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
