An online banking user registers their cell-phone number with their bank and the bank then sends them a text message. Once the customer has downloaded this message, they click on a link in it to download an application. |
The cell phone has now become an authentication device. There is no need for banks to issue their customers with online authentication tokens or smart cards. |
The user types the challenge code into the mobile phone, which validates that the challenge code is genuine. After the user has entered their PIN into the phone, it generates a response code. The user types the response code into the Web bank screen, and the transaction is confirmed. |