The flow goes: Merchant -> Merchant Plug-In (MPI) -> Directory Server -> Access Control Server (ACS) -> Banks. The first two are under the merchant's responsibility domain (or payment processors). The Directory Server is under the payment network's responsibility domain. The last two are under the bank's responsibility domain. Thus, a "3-Domains Secure" name.
Despite the word "secure" in its name, the primary purpose of 3-D Secure is to protect the merchant. Transactions authenticated with 3-D Secure will be "liability shifted," making merchants less liable for chargebacks (e.g., banks are more likely to reject your chargeback claims).