KOREAN / ENGLISH
SSenStone
  • About Us
  • Technology
    • OTAC
    • FIDO
  • Solutions
    • OTAC Solutions
      • OT Auth
        • - PLC OTAC
        • - OTAC Trusted Access Gateway
        • - OTAC auth - MFA for PLCnext
      • Fin Auth
        • - TAP OTAC
        • - OTAC Holderless Card
        • - OTAC Dynamic Token
      • IoT Auth
        • - IoT Auth Platform OTAC
        • - Smart Building OTAC
        • - HomeNet OTAC
        • - Connected Car OTAC
        • - Drone OTAC
      • Access Auth
        • - Identity&Access Management OTAC
    • FIDO & mOTP Solutions
      • swIDch Auth
        • - swIDch Auth Package
        • - swIDch Auth SDK
  • Case Studies
    • Case Studies
      • Toss Bank
      • Kakao
      • A-Card Bank
      • E-Stamp : Indonesia
      • Milipass
  • News
    • News & Information
    • Blog
    • Video
  • Contact
  • About Us
  • Technology
    • - OTAC
    • - FIDO
  • Solutions
    • OTAC solutions
      • swIDch: Finance
        • - TAP-OTAC
        • - OTAC Holderless Card
        • - OTAC Dynamic Token
      • swIDch: OT
        • - PLC-OTAC
        • - MFA for PLCnext
      • swIDch: IoT
        • - IoT Auth Platform OTAC
        • - Smart Building OTAC
        • - HomeNet OTAC
        • - Connected Car OTAC
        • - DroneOTAC
      • swIDch: Access
        • - Identity & Access Management
    • FIDO & mOTP Solutions
      • swIDch Auth
        • - swIDch Auth Package
        • - swIDch Auth SDK
  • Case Studies
    • Case Studies
      • - Toss Bank
      • - Kakao Bank
      • - A-Card Bank
      • - E-Stamp : Indonesia
      • - Milipass
  • News
    • - News & Information
    • - Blog
    • - Video
  • Contact

OTAC Solutions

OTAC Dynamic Token

SSenStone generates non-duplicate dynamic codes through our patented OTAC(One-Time Authentication Code) without the need of extra infrastructure or networks, a world-first.

Pain points

As the mobile financial environment has become more common and non-face-to-face financial transactions have increased, use of financial service apps is also rising. However, financial damages cases are also rapidly growing as they have become targets of various forms of hacking. Financial service companies introduce numerous security and authentication methods to protect consumers, but various issues arise in the process of using them. In fact, network-based payment tokens are difficult to use in an environment where communication is unstable, and user convenience can be compromised when a financial service app has a step-by-step user authentication process.

Solutions

SSenStone generates non-duplicate dynamic codes through our patented OTAC (One-Time Authentication Code) algorithm even in off-the-network environments without extra infrastructure. See the case of Doku e-wallet infrastructure . The generated verification code replaces the ID/PW and card number based on a fixed value.

 

  • A dynamic code that is safe from hacking and leaks is generated.
  • Dynamic codes are continuously changed even in an environment without a communication network
  • The dynamic code alone identifies the owner (combining identification and authentication steps).
  • Dynamic codes have a 0% chance of being duplicated.
  • All functions can be implemented without changing the existing infrastructure.

 

OTAC Dynamic PAN

SSenStone’s OTAC Dynamic PAN generates a dynamic card number that changes each time instead of fixed card information to prevent financial accidents caused by card number leakage. The dynamic card number generated based on the OTAC algorithm, the original technology of SSenStone, can be issued and registered in the same way as the existing payment process. You can use it as a payment token even if communication with the server is restricted.

 

dynamic token_1(eng)-1
dynamic token_2(eng)-1

Expected Effects with OTAC Dynamic PAN

-Reduction of operating costs by shortening verification time

Recently, hackers who attack IoT devices often manipulate the device firmware to download illegal firmware or plant malware on the device. SSenStone uses hashes of firmware files as a seed when generating OTAC to verify and execute only OTA commands sent from valid IoT servers. Therefore, since the download command from the unauthorized system itself is not approved by the device, it can naturally block the occurrence of illegal software downloads. OTAC Dynamic PAN provides a dynamic payment token generated from the user's mobile device during offline payment. Consumers can use the token to pay using the existing payment infrastructure of the shop or store to the financial service server. It not only reduces the operating cost by shortening the verification time compared to the token server that always requires communication networks, but also supports an environment where users can make payments with zero inconvenience even when offline. In addition, a shop that does not introduce 3D Secure authentication can also prevent payment incidents caused by the leakage of a user's card number, thereby you can reduce the cost of compensation for payment incidents.

-Convenience and security enhancement using dynamic codes

OTAC Dynamic PAN is generated by the user's device and undergoes authentication processes such as fingerprint, iris, and PIN in their device. As it can be used in the same way as the existing card payment method without additional authentication process, it is much simpler. Also, an online shop without 3D Secure authentication allows consumers to pay only with the dynamic payment token provided in the form of a card number, preventing theft and misuse of the card number and enhancing security.

OTAC Device Authentication Token

SSenStone’s OTAC Device Authentication Token generates a new OTAC on the user's device every time, even in an off-the-network environment, and provides it as a dynamic code that can act as 'ID + password + OTP' used for payment authentication. Consumers can also securely store unique values in their devices. In addition, by periodically sending a dynamic code valid only at the present time from the user's device to the server of the financial company, it is possible to check whether the user's device is accessing it from a normal customer's device by a one-way (uni-directional) verification of the received dynamic code.

dynamic token_3(eng)-1
  • Embedment of OTAC generation module in the user's app

To generate a unique OTAC, the unique value is safely stored in the user's mobile device, and a valid OTAC is generated and transmitted at every point in time

  • Embedment of OTAC verification module in financial company server

It verifies the periodically transmitted OTAC and assigns a unique value to each user.

Expected Effects with OTAC Device Authentication Token

-Support for abnormal transaction detection through device authentication

Since a significant number of financial-related hacking cases involve hackers impersonating users from other devices, many financial companies use fraud detection system (FDS) to defend against hackers targeting electronic financial transactions. However, the FDS method which collects and analyses various information from the payer, requires not only device information but also a large amount of transaction information. It means device authentication for each transaction on FDS is essential. OTAC Device Authentication Token can be used together with FDS to enhance security or replace the functions of FDS.

-Provides convenience through simplified user authentication

Because of the importance of security, financial service apps go through at least two factor authentication (2FA) when making payments or money transfers in addition to logging in. This process not only makes users uncomfortable, but also slows down the speed of the app due to the increase in resources required for authentication. OTAC Device Authentication Token eliminates the inconvenience of frequent logout or re-login when using the platform by reducing unnecessary user authentication steps through device authentication using dynamic codes and extending the session between financial service apps and servers through OTAC verification.

Read our 'DOKU e-wallet' case study

case_5_doku

Why OTAC

OTAC, developed by SSenStone, is the original technology that provides all of the following features at the same time.

Main Large

    OTAC is a dynamic code, which means the code keeps changing. As a result, you don’t need to worry about any leak of your personal information, such as your card details, because the codes must have already been changed when others try to use them.

    The network connection is NOT necessary at all for generating OTAC.

    Reducing an authentication stage that requires the network connection directly means there are fewer gateways for the hackers to access our personal information.

    Moreover, this feature enables users to authenticate even when they are in networkless environments, such as on the plane, underground, rural or foreign areas.

    swIDch can guarantee that the code never duplicates with anyone at any given moment.

    There is NO chance of someone else having the same code.

    The users or their devices can be identified with the code alone.

    Once OTAC has been generated, providing OTAC alone is already fully sufficient to identify the user as the code is unique.

    It means, you can forget about the bundles of static information including IDs and passwords.

OTAC Algorithm Analysis and Academic Verification

report_otac_surrey univ

The University of Surrey, one of the leading global cyber security companies in the UK, conducted OTAC algorithm analysis and academic verification of SSenStone. For the full text of the thesis, please visit the University of Surrey website and download the report.

 

Univ. of Surrey Website
Download the Report

New Excellent Technology (NET) Certification Acquired

NET신기술인증-removebg-preview

SSenStone has received the NET Certification from the Ministry of Trade, Industry, and Energy for its "Individual IoT Device Authentication and Transmission Data Security Technology through Unidirectional Dynamic Authentication (OTAC)."

 

NET Website
Press Release

International Common Criteria (CC) Certification Achieved

국제CC인증_엠블럼 (png)

OTACTokenV1.0, the authentication solution based on the world’s first unidirectional dynamic authentication technology, OTAC, has earned the international Common Criteria (CC) certification. For more information, please refer to the press release.

 

ITSCC Website
Press Release

OTAC for Phygital Wins IR52 Jang Yeong-sil Award

IR52 logo

SSenStone's OTAC for Phygital has been awarded the 40th-week IR52 Jang Yeong-sil Award for 2024, hosted by the Ministry of Science and ICT. For more details, please visit the official IR52 Jang Yeong-sil Award homepage or the press release.

 

IR52 Website
Press Release

Insights

  • The Future of Financial Security in the Face of Phishing Attacks

    In recent years, financial security incidents, especially phishing attacks, have become a serious...

    Read more

  • How is ChatGPT addressing financial fraud?

    Last year, after giving birth, I hired a postpartum doula to help me. After trying out a few...

    Read more

  • Solving Voice Phishing and Smishing Security Issues: SSenStone's Personal Information Authentication Technology

    Today, I'd like to discuss a crucial financial security issue that affects us all, and explore the...

    Read more

  • A-Card (De-identified Bank)

    'A-Card' bank (name redacted to protect identity), one of the largest credit card companies in...

    Read more

Contact Us

Improve your authentication environment and
make your service reliable with SSenStone!

Inquire now.

5F, 329, Cheonho-daero Dongdaemun-gu, Seoul, Republic of Korea

Contact below if you have an urgent inquiry.

Korea Office (SSenStone)

5F, 329, Cheonho-daero Dongdaemun-gu, Seoul, Republic of Korea (02622)

Tel : 02-569-9668  |  Fax : 02-6455-9668

im@ssenstone.com

UK Office (swIDch)

Floor 1, 3 More London SE1 2RE, United Kingdom

Tel : 020-3283-4563

info@swidch.com

SSenStone Inc.

5F, 329 Cheonho-daero Dongdaemun-gu, Seoul, Republic of Korea (02622)

T. 02-569-9668

F. 02-6455-9668

E. im@ssenstone.com

Sitemap

Copyright© SSenStone Inc. All rights reserved.