What Is a One-Time Password Or OTP?

Synopsis:

  • An OTP is a four to six-digit code sent to your mobile or email for validating online transactions.
  • OTPs provide an extra layer of security for online banking and transactions.
  • Typically valid for 2 to 10 minutes and used for a single transaction or login session.

Overview

OTP, or One Time Password, is that four to six-digit code that pops up on your screen every time you use your debit or credit card for an online or NetBanking transaction. Have you ever wondered what exactly these numbers are and why they play an integral role in securing your bank account? 

Through this article, we take you through what OTP is and all you need to know about it. 

What is the OTP Number? 

​​​​​​​OTP is unsystematically generated and sent to your registered mobile number to validate the transaction. It offers an enhanced layer of security for the card and online transactions. It is sent to your mobile number within a couple of seconds of you inputting your transaction details and stays on your phone only for 2 minutes. OTP is automatically generated with a numeric or alphanumeric string of characters that authenticates the user for a single transaction done by Credit Card, Debit Card or login session. This OTP is a secret token that must not be shared with anyone.

Understanding OTP Through an Example

An example of an OTP  is when a system administrator, for instance, HDFC Bank, sends you an OTP to complete your online purchase. This alphanumeric code, used to authenticate access to the system, changes every 30-60 seconds depending on how the back-end system is generated. Most banks allow an OTP to be valid for 2 to 10 minutes. However, for instance, mobile device apps such as Google Authenticator bank on the token device and PIN to generate the OTP and offer two-step verification. Unlike static passwords that expire only after every 30 to 60 days, the OTP is used per transaction or login session only. 

How does the OTP work? 

Through the OTP-based authentication mode, the user’s OTP and the authentication server rely on shared secrets. The numeric or alphanumeric values for the OTP  are generated using the Hashed Message Authentication Code-HMAC algorithm, such as time-based information or an event counter. Each OTP will have a timestamp for additional security. The OTP once generated, is delivered to a user through numerous channels such as text message via SMS, registered email address or other dedicated applications chosen by the bank.

OTP vs Static Password: How They Differ?

  • ​​Static Password: 

A static password is a password set up by the user and can be used multiple times. Although the authentication method is suitable, it is not secure. It is susceptible to online identity theft, phishing, keyboard logging, man-in-the-middle attacks, and ATM and POS skimming. All these theft practices are on the rise. A static password provides you with a single layer of security. 

  • OTP: 

An OTP is an extra security layer beyond your regular password. Modern authentication systems use OTPs to overcome the weaknesses of static passwords, adding an extra security measure. OTPs help safeguard network access and the digital identities of users.

  • Tip:

Though each of these passwords offers their specific type of security, they work best together. With OTP providing added protection, it becomes a challenge for unauthorised individuals to access information over networks and through online accounts. 

Step Guide to Generating an OTP

Here’s a brief guide on generating an OTP for banking transactions:

  • Step 1: Open your bank’s website or mobile application on your device. Make sure you are connected to a secure network.
  • Step 2: Share your user ID and password to log in. If you’re using a public device, don’t save these details.
  • Step 3: Navigate to the section where you want to perform the transaction. This could be a fund transfer, bill payment, or any other banking service.
  • Step 4: Enter the details mandatory for the transaction. This usually includes the recipient’s account number, bank, and transfer amount.
  • Step 5: Once you’ve entered the details, proceed to the next step. The bank will usually prompt you to request an OTP at this stage.
  • Step 6: Click on ‘Generate OTP’. The bank will send an OTP to your registered mobile number or email address.
  • Step 7: Enter the received OTP in the designated field on the website or app. Make sure to enter it correctly.
  • Step 8: After entering the OTP, confirm the transaction. The bank will then process it.

Benefits of OTP

  • The OTP outweighs all the security hiccups the administrator or the security managers at the back-end team of the bank must face.
  • With the OTP auto-generated algorithm, bad or weak passwords, sharing credentials, password composition rules, or reuse of the same password on multiple accounts and systems are all redundant. 
  • The OTP is valid only for a few minutes; thus, the security breach is extremely minimal. 
  • As it is a One-Time Password, it prevents attackers from obtaining and reusing the secret codes. 

Conclusion

This article has explained in detail what OTP means, how it is generated and the difference between a static password and an OTP. So, the next time you carry out any transaction online, you will know what those six digits mean on your SMS that reads as OTP. To learn more about HDFC Bank Debit and Credit Cards, click here.  If you want to open a bank account online with HDFC Bank, click here to get started! Read more about Digital Banking here.

*Terms and conditions apply. The information provided in this article is generic in nature and for informational purposes only. It is not a substitute for specific advice in your own circumstances.