KOREAN / ENGLISH
SSenStone
  • About Us
  • Technology
    • OTAC
    • FIDO
  • Solutions
    • OTAC Solutions
      • OT Auth
        • - PLC OTAC
        • - OTAC Trusted Access Gateway
        • - OTAC auth - MFA for PLCnext
      • Fin Auth
        • - TAP OTAC
        • - OTAC Holderless Card
        • - OTAC Dynamic Token
      • IoT Auth
        • - IoT Auth Platform OTAC
        • - Smart Building OTAC
        • - HomeNet OTAC
        • - Connected Car OTAC
        • - Drone OTAC
      • Access Auth
        • - Identity&Access Management OTAC
    • FIDO & mOTP Solutions
      • swIDch Auth
        • - swIDch Auth Package
        • - swIDch Auth SDK
  • Case Studies
    • Case Studies
      • Toss Bank
      • Kakao
      • A-Card Bank
      • E-Stamp : Indonesia
      • Milipass
  • News
    • News & Information
    • Blog
    • Video
  • Contact
  • About Us
  • Technology
    • - OTAC
    • - FIDO
  • Solutions
    • OTAC solutions
      • swIDch: Finance
        • - TAP-OTAC
        • - OTAC Holderless Card
        • - OTAC Dynamic Token
      • swIDch: OT
        • - PLC-OTAC
        • - MFA for PLCnext
      • swIDch: IoT
        • - IoT Auth Platform OTAC
        • - Smart Building OTAC
        • - HomeNet OTAC
        • - Connected Car OTAC
        • - DroneOTAC
      • swIDch: Access
        • - Identity & Access Management
    • FIDO & mOTP Solutions
      • swIDch Auth
        • - swIDch Auth Package
        • - swIDch Auth SDK
  • Case Studies
    • Case Studies
      • - Toss Bank
      • - Kakao Bank
      • - A-Card Bank
      • - E-Stamp : Indonesia
      • - Milipass
  • News
    • - News & Information
    • - Blog
    • - Video
  • Contact

OTAC Solutions

TAP OTAC

SSenStone's TAP OTAC provides a proactive solution against financial fraud, such as phishing, through a straightforward card-tapping authentication process.

Pain points

The rise of digital financial services, including non-face-to-face transactions and open banking, has increased user convenience. However, it has also led to the evolution of financial fraud, such as phishing (smishing and voice phishing), card misuse, bank account theft, and personal information theft. The instances of significant financial losses due to ID leaks and lost smartphones have surged both domestically and internationally. Despite the implementation of multi-factor authentication (MFA) services like mobile OTP, mobile phone identity authentication, and biometric authentication by many financial service firms, preventing sophisticated financial fraud crimes in advance remains challenging.

 

 

- Extensive financial damage from the escalating phishing scams

Numerous cases involve accounts being hijacked for illegal financial transactions, unauthorised payments, or mobile payments. Criminals install remote control apps to steal account numbers and passwords, exposing fixed passwords in mobile financial environments to hacking and phishing risks. According to the Financial Supervisory Service, voice phishing victims over the past five years (2018 to the first half of 2023) reached 148,760, with damages totaling 237,859, amounting to KRW 1.7499 trillion. These incidents incur substantial response costs for financial institutions. In the U.S., 75% of all fraud losses are attributed to consumer phishing, with associated expenses for response activities, investigations, and recovery reaching $4.23 for every $1 lost.

 

- Growing consumer dissatisfaction with the inconvenience MFA

Enhanced security measures, such as additional authentication procedures (separate OTP authentication, ARS, and terminal designation service) for substantial transactions or logins from multiple devices, necessitate direct entry of authentication codes. Delays or non-receipt of authentication codes require users to go through cumbersome processes like contacting customer service, particularly when authentication services like SMS and ARS are inaccessible in off-network environments. 

 

- Challenges in responding to damage recovery post-financial fraud

Recovering from financial fraud involves varying responses across industries, including finance, telecommunications, and e-commerce. Each case requires investigation and legal interpretation of the cause, scale of damage, liability for compensation, etc. Responding solely to damage recovery limitations hinders receiving full compensation for the incurred losses. Despite national and industrial-level policy preparations, completely preventing increasingly sophisticated financial fraud remains elusive.

 

Solutions

SSenStone's TAP OTAC proactively prevents financial fraud, such as phishing, by isolating media from cyber attacks. The OTAC module, generating a financial payment authentication code, is embedded into the payment card's IC chip and financial app as an applet and software development kit (SDK). Authentication is effortlessly performed by lightly tapping the payment card on the back of a smartphone with a financial app installed. Utilising a dynamic code newly generated each time ensures a robust yet simple authentication process, significantly enhancing user convenience. Additionally, it is compatible with any mobile device's operating system (OS) and facilitates authentication without a separate cellular network.

Mitigating the source of sniffing risk

The card, embedding the OTAC applet, generates the initial OTAC via smartphone near field communication (NFC). As the primary code from the card produces a secondary OTAC through linkage with the app, there is no risk of hacking by stealing the seed value in memory or any potential sniffing risks within the NFC section.

 

Card tapping mOTP_2_eng-2

 

Proactive prevention of user theft

SSenStone's TAP OTAC authenticates users by tapping a card embedded with the OTAC applet to a mobile device. This thwarts hackers who have stolen personal information from issuing new mobile OTPs or using financial services like large-sum transfers. Crucially, flawless user identification and authentication are possible without any chance of code duplication with other users.

User-friendly User Experience (UX)

TAP OTAC, linked to a payment card for cash withdrawal and payment, enables secure and easy use of financial services requiring two-factor authentication (2FA) by simply tapping the card on the back of a smartphone. Users benefit from the convenience of not needing a separate device solely for 2FA.

 

Card tapping mOTP_(3)_eng

 

View 'Toss Bank' Case

Benefits

SSenStone's TAP OTAC provides payment cards with a robust user authentication function using a unique identification key. This not only increases cardholder usage frequency but also reduces the cost of issuing physical OTPs. It can utilise the NFC function to evolve into an all-in-one card encompassing payment card, access control, and identification functions.

Card tapping mOTP_(5)_eng

 

Enhancing customer loyalty to banks and financial services

Globally, 2.8 billion credit cards are in use as of 2021. Americans average four credit cards, while EU residents possess between 0.8 to 3.9 mobile cards. In Korea, the average number of credit cards per person is 1.79. By adding the OTP function to the payment car', SSenStone increases card usage frequency. Given that most consumers mainly use one or two cards, this naturally leads to heightened customer loyalty.

Proactive financial fraud prevention with a zero-trust approach

As the landscape of non-face-to-face digital finance expands, there is a concurrent increase in various forms of financial fraud, including voice phishing and SIM swapping. Recent data from the National Police Agency reveals that domestic phishing damage has exceeded KRW 3 trillion over the past six years, with a mere 0.3% reimbursement rate. Similarly, in the United States, a study indicates that 75% of financial fraud losses reported by lenders stem from consumer phishing, notably Authorised Push Payment (APP) scams. In a more proactive approach, the UK's top 14 banking groups have refunded up to 91% of APP losses. SSenStone's TAP-OTAC is positioned as a preventive measure against financial phishing incidents. Its distinctive feature, requiring a card tapping process for additional financial services, proves advantageous even in situations where user information is compromised or the smartphone is lost.

Expansion of various additional functions such as access control

OTAC-embedded cards can serve as a means of diverse authentication beyond payment. Logging into critical sites, such as internet banking, can involve generating a one-time QR code with a simple tap on the back of a smartphone. The same card can grant access to the office or restricted areas via tapping on digital door locks. Businesses can leverage this innovative card by integrating corporate payment cards, access control devices, and employee IDs into one card. The associated manufacturing costs related to contactless payment functions can naturally alleviate through additional applications beyond payment.

 

Card tapping mOTP_(4)_eng

 

Why OTAC

OTAC, developed by SSenStone, is the original technology that provides all of the following features at the same time.

Main Large

    OTAC is a dynamic code, which means the code keeps changing. As a result, you don’t need to worry about any leak of your personal information, such as your card details, because the codes must have already been changed when others try to use them.

    The network connection is NOT necessary at all for generating OTAC.

    Reducing an authentication stage that requires the network connection directly means there are fewer gateways for the hackers to access our personal information.

    Moreover, this feature enables users to authenticate even when they are in networkless environments, such as on the plane, underground, rural or foreign areas.

    swIDch can guarantee that the code never duplicates with anyone at any given moment.

    There is NO chance of someone else having the same code.

    The users or their devices can be identified with the code alone.

    Once OTAC has been generated, providing OTAC alone is already fully sufficient to identify the user as the code is unique.

    It means, you can forget about the bundles of static information including IDs and passwords.

OTAC Algorithm Analysis and Academic Verification

report_otac_surrey univ

The University of Surrey, one of the leading global cyber security companies in the UK, conducted OTAC algorithm analysis and academic verification of SSenStone. For the full text of the thesis, please visit the University of Surrey website and download the report.

 

Univ. of Surrey Website
Download the Report

New Excellent Technology (NET) Certification Acquired

NET신기술인증-removebg-preview

SSenStone has received the NET Certification from the Ministry of Trade, Industry, and Energy for its "Individual IoT Device Authentication and Transmission Data Security Technology through Unidirectional Dynamic Authentication (OTAC)."

 

NET Website
Press Release

International Common Criteria (CC) Certification Achieved

국제CC인증_엠블럼 (png)

OTACTokenV1.0, the authentication solution based on the world’s first unidirectional dynamic authentication technology, OTAC, has earned the international Common Criteria (CC) certification. For more information, please refer to the press release.

 

ITSCC Website
Press Release

OTAC for Phygital Wins IR52 Jang Yeong-sil Award

IR52 logo

SSenStone's OTAC for Phygital has been awarded the 40th-week IR52 Jang Yeong-sil Award for 2024, hosted by the Ministry of Science and ICT. For more details, please visit the official IR52 Jang Yeong-sil Award homepage or the press release.

 

IR52 Website
Press Release

Insights

  • The Future of Financial Security in the Face of Phishing Attacks

    In recent years, financial security incidents, especially phishing attacks, have become a serious...

    Read more

  • How is ChatGPT addressing financial fraud?

    Last year, after giving birth, I hired a postpartum doula to help me. After trying out a few...

    Read more

  • Solving Voice Phishing and Smishing Security Issues: SSenStone's Personal Information Authentication Technology

    Today, I'd like to discuss a crucial financial security issue that affects us all, and explore the...

    Read more

  • A-Card (De-identified Bank)

    'A-Card' bank (name redacted to protect identity), one of the largest credit card companies in...

    Read more

Contact Us

Improve your authentication environment and
make your service reliable with SSenStone!

Inquire now.

5F, 329, Cheonho-daero Dongdaemun-gu, Seoul, Republic of Korea

Contact below if you have an urgent inquiry.

Korea Office (SSenStone)

5F, 329, Cheonho-daero Dongdaemun-gu, Seoul, Republic of Korea (02622)

Tel : 02-569-9668  |  Fax : 02-6455-9668

im@ssenstone.com

UK Office (swIDch)

Floor 1, 3 More London SE1 2RE, United Kingdom

Tel : 020-3283-4563

info@swidch.com

SSenStone Inc.

5F, 329 Cheonho-daero Dongdaemun-gu, Seoul, Republic of Korea (02622)

T. 02-569-9668

F. 02-6455-9668

E. im@ssenstone.com

Sitemap

Copyright© SSenStone Inc. All rights reserved.