# Breaking down the compliance limitations of SMS One-Time Passwords
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2021-03-10
Category: TECHNOLOGY
Category URL: https://financedigest.com/category/technology
Meta Title: Are SMS OTPs compliant with PSD2 requirements?
Meta Description: Learn about the compliance of SMS OTP with PSD2 for online payment account login and dynamic linking, as well as the security vulnerabilities associated with
URL: https://financedigest.com/breaking-down-the-compliance-limitations-of-sms-one-time-passwordshtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/otp-pass-1736838534825-compressed.jpg)

_By **Frederik Mennes,** Director Product Security at [OneSpan](http://www.onespan.com)_

Banks and payment service providers have several methods of authenticating someone attempting to log onto an online payment account. One of these is SMS. An SMS message with a one-time password (OTP) is sent to the user’s mobile phone, who then enters this OTP into the payment application. This method can also be used to confirm a payment, in which case the SMS will contain [key information](https://www.financedigest.com/golf-apparel-market-key-players-and-production-information-analysis-with-forecast-2031.html "Golf Apparel Market: Key Players and Production Information Analysis with Forecast 2031") such as the amount and beneficiary.

To provide an additional layer of security, the OTP often works alongside a static password that the user must also enter into the [payment application as part of a two-factor authentication system](https://www.financedigest.com/covid-19-putting-a-spotlight-on-mea-payment-systems.html "COVID-19: Putting a spotlight on MEA payment systems"). The SMS OTP represents a possession factor (“something only the user has”), while the static password represents a knowledge factor (“something only the user knows”).

The compliance of authentication systems based on SMS has caused plenty of discussion in recent times, particularly since the introduction of the revised Payment Services Directive (PSD2) and the Regulatory Technical Standards (RTS) on [Strong Customer Authentication](https://www.financedigest.com/strong-customer-authentication-must-be-adopted-to-make-open-banking-a-success.html "Strong Customer Authentication must be adopted to make open banking a Success") (SCA) and Common and Secure Communication (CSC). One common question is whether SMS OTP can meet the Dynamic Linking requirements of PSD2, which stipulate how to [authenticate payments](https://www.financedigest.com/why-latin-america-chose-biometric-authentication-for-payment-cards.html "Why Latin America Chose Biometric Authentication for Payment Cards").

As remote authentication is a key consideration in today’s [digital world](https://www.financedigest.com/six-reasons-why-digital-world-classtm-finance-organizations-outperform-peers.html "Six Reasons Why Digital World ClassTM Finance Organizations Outperform Peers"), let’s take a closer look at SMS OTP compliance in relation to two key use cases: account login and dynamic linking.

**Authenticating account login**

The question of whether SMS OTP complies with the SCA requirements for payment account login was addressed by the European Banking Authority (EBA) in an [Opinion](https://www.eba.europa.eu/eba-publishes-an-opinion-on-the-elements-of-strong-customer-authentication-under-psd2) published in 2019, and also via the [EBA’s Single Rulebook Q&A tool](https://www.eba.europa.eu/single-rule-book-qa/-/qna/view/publicId/2018_4039).

The Opinion clarifies that SMS – more specifically the SIM-card in the mobile device that receives the SMS – can be considered a valid possession element. This implies that one-time passwords (OTPs) delivered via SMS can be used to [construct a strong authentication mechanism when combined with a second factor](https://www.financedigest.com/construction-machinery-sector-is-primary-growth-factor-for-industrial-hydraulic-filters-market-unveils-fact-mr.html "Construction Machinery Sector Is Primary Growth Factor For Industrial Hydraulic Filters Market, Unveils Fact.MR") (e.g. a password or PIN). In other words, SMS OTP does indeed comply with the SCA requirements of PSD2.

![Frederik Mennes](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/frederik-mennes-450x675-1736838534668-compressed.jpg)

Frederik Mennes

However, this does not automatically mean that using SMS OTP is the best [option for account](https://www.financedigest.com/what-options-do-i-have-for-retirement-accounts.html "What Options Do I Have for Retirement Accounts?") login, as SMS is subject to a plethora of security vulnerabilities. For example, SMS messages can be intercepted/altered by exploiting vulnerabilities of the underlying SS7 protocol, and by malware residing on mobile devices. In addition, SIM swap attacks allow hackers to take over a victim’s mobile phone number and receive SMS messages intended for the victim. [Europol recently announced](https://www.europol.europa.eu/newsroom/news/ten-hackers-arrested-for-string-of-sim-swapping-attacks-against-celebrities) a string of arrests across Europe after a group of hackers used this method to steal more than $100 million.

Attacks against the authentication mechanisms of online banking systems exploiting these vulnerabilities are well-known and have been around for many years, which [banks must](https://www.financedigest.com/lost-in-translation-why-banks-must-learn-the-language-of-their-customers.html "Lost in Translation: Why Banks Must Learn the Language of their Customers") keep in mind when deciding whether to adopt SMS OTPs.

This is all fairly clear. But one thing the EBA’s Opinion does not discuss is SMS OTP in the context of dynamic linking. This raises the all-important question: does SMS OTP meet PSD2’s dynamic linking requirements?

**Addressing dynamic linking**

The dynamic linking [requirement stipulates that payment information needs to be protected](https://www.financedigest.com/fraud-protection-why-customer-onboarding-requires-digital-identity-processing.html "Fraud Protection: Why Customer Onboarding Requires Digital Identity Processing"). Since the content of SMS messages is not protected, one would expect that [SMS does not meet the dynamic linking requirements](https://www.onespan.com/blog/psd2-end-sms-based-authentication) of PSD2. However, until recently the EBA had not offered a clear opinion on the subject.

Now, for the first [time since](https://www.financedigest.com/sterling-slides-below-1-15-for-first-time-since-2020.html "Sterling slides below .15 for first time since 2020") PSD2 came into force, the EBA has officially made a statement about the compliance of SMS OTP in relation to dynamic linking. In its statement, the EBA [explains that an SMS does not have to be protected if it does not contain](https://www.financedigest.com/explainer-caps-and-corridors-how-can-europe-contain-gas-prices.html "Explainer-Caps and corridors: how can Europe contain gas prices?") payment information or an authentication code. This is logical, as there is no sensitive [data in the SMS at risk](https://www.financedigest.com/how-the-global-insurance-market-will-keep-pace-with-evolving-risks-through-data-analytics-and-technology.html "How the global insurance market will keep pace with evolving risks, through data, analytics and technology"). In this instance, _“the issuer would not be required under Article 5(2) of the Delegated Regulation to ensure the confidentiality, authenticity and integrity of the information transmitted via the SMS.”_

On the other hand, if payment information – i.e. the payee or the amount of the transaction – is present in the SMS, then that [information needs to be protected](https://www.financedigest.com/protecting-your-financial-information-and-identity.html "Protecting your Financial Information and Identity"). The EBA says, “the issuer should take all necessary security measures to ensure the confidentiality, authenticity and [integrity of the authentication code and/or the payment](https://www.financedigest.com/the-collective-power-of-partnerships-integrating-payment-solutions-to-drive-business-success.html "The collective power of partnerships: integrating payment solutions to drive business success") information transmitted via the SMS.”

As SMS itself does not provide sufficient security, this [effectively means that simply sending an SMS containing sensitive data](https://www.financedigest.com/can-banks-compete-in-the-digitisation-race-without-effective-data-integrity.html "Can banks compete in the digitisation race without effective data integrity?") does not meet the dynamic linking requirements. One option would be to encrypt the content of the SMS, but this introduces another issue – namely how the content can be decrypted on the user’s device. In most cases this will require a separate [mobile app](https://www.financedigest.com/the-growth-of-mobile-fintech-and-the-impact-for-mobile-app-marketers.html "The growth of mobile fintech and the impact for mobile app marketers"), which misses the point of using SMS in the first place.

This all presents a conundrum for banks and payment [service providers](https://www.financedigest.com/high-energy-shockwave-therapy-units-market-end-user-demand-by-types-regions-top-players-service-provides-regional-outlook-and-forecast-to-2028-2.html "High Energy Shockwave Therapy Units Market End-User Demand by Types, Regions, Top Players, Service Provides, Regional Outlook and Forecast to 2028") to navigate. SMS OTP for dynamic linking does not comply with PSD2, unless the content of the SMS is protected – which is not straightforward. [It’s therefore important](https://www.financedigest.com/paternity-leave-and-why-its-important.html "Paternity Leave and Why It’s Important.") that banks are aware of the alternative options available, such as mobile PUSH notifications which are protected by application shielding technology. Ultimately, this marks another compliance and security challenge facing [banks in today’s digital world](https://www.financedigest.com/bridging-the-gap-between-banking-and-digital-accessibility-in-todays-digital-by-default-world.html "Bridging the Gap Between Banking and Digital Accessibility in Today’s ‘Digital by Default’ World").


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

