Authentication

ekShield

Banks across the GCC, India, and Southeast Asia are under a regulatory order to replace SMS OTP with device-bound, phishing-resistant authentication. This page explains the problem, what the regulation requires, and how ekShield — Ektar’s MFA and passkeys platform — solves it.
 

SMS OTP is the weakest link in banking security

93% of organisations globally still rely on SMS OTP as their primary authentication method. SIM swap attacks have grown 1,055% year-on-year — eSIM reduces a full SIM swap to under five minutes. OTP interception through phishing is now industrialised at scale. And regulators across five major markets have now banned or restricted SMS OTP for high-risk banking transactions. Every bank still relying on it is non-compliant — or soon will be.

0

Major regulators have banned SMS OTP

UAE, India, Saudi Arabia, Philippines, Singapore. More are following.

0

Fraud victims in UAE (2023)

Driven primarily by SMS OTP exploitation. The numbers behind the CBUAE ban.

+ 0 %

SIM swap attacks (YoY)

eSIM makes a SIM swap trivially fast. Every SMS OTP is now at risk.

Use Cases Addressed

What Banks Need

Most banks aren’t shopping for an authentication vendor — they’re closing a specific list of compliance gaps against a deadline that has already passed. ekShield is scoped around five things banks are actually asking for right now, not a generic feature list.

Replace SMS OTP

with phishing-resistant, device-bound credentials that cannot be intercepted or stolen via SIM swap.

FIDO2 / Passkeys compliance
meet CBUAE, SAMA, and RBI mandates requiring FIDO-certified authentication.
Omnichannel coverage
authentication across mobile, web, call centre, ATM, and 3DS card payments, from a single platform.
Step-up authentication
contextual risk-triggered challenges for high-value transactions, new device registration, and limit changes.
White-label deployment
 the authentication experience carries the bank’s brand, not a third-party vendor’s.

What ekShield Delivers

Real-Time Malware Session Suspension
CBUAE mandates that banking sessions be suspended when malware or screen-sharing is detected. ekShield integrates natively with RASP SDK to enforce this — automatically, in real time, without requiring manual intervention.
Soft Tokens & Biometrics
App-based TOTP and biometric authentication — fingerprint and face — tightly bound to the customer’s enrolled device. Eliminates OTP interception at source. Supports step-down gracefully for devices that don’t support biometrics.
Omnichannel Coverage
Most MFA platforms cover mobile and web only. ekShield also covers call centre (IVR/USSD), ATM, and 3DS card payments — from the same platform, with the same underlying credential. A single platform that closes all channel gaps.
Contextual Step-Up Authentication
isk-triggered challenges for high-value transactions, new device registration, account limit changes, and beneficiary additions. Challenge the customer only when the risk warrants it — not on every login.
Passkeys (FIDO2)

Phishing-resistant, device-bound credentials that cannot be intercepted, shared, or stolen via SIM swap. The mandated successor to SMS OTP across CBUAE, RBI, SAMA, and BSP frameworks. ekShield is FIDO-certified.

White-Label Ready
Fully brandable. The authentication experience carries the bank’s name and identity — not Ektar’s. UAE’s 3rd largest bank deployed ekShield and branded it as their own product end-to-end.
ekShield happens over REST API.

Integration

ekShield integrates via REST API. Supports iOS and Android mobile SDK. IVR/USSD integration for call centre. 3DS integration for card payment authentication. Typical deployment timeline: 6–10 weeks to first go-live. No change required to the bank’s core banking system.

Proven in Production

Live Deployments

UAE's 3rd largest bank

deployed ekShield and white-labelled it as their own branded authentication product, independently extending it to corporate banking cards and transactions. A bank putting their name on a vendor’s product is the strongest possible signal of institutional confidence. RASP SDK is also live at the same institution.

3rd largest bank in the Sultanate of Oman

contracted for ekShield MFA. Ektar’s first major Oman deployment and a regional reference for GCC expansion.

Get Started Today

Talk to us about Authentication

This page explains the problem, what the regulation requires, and how Ektar solves it.