This document summarizes a research paper that proposes a two-factor authentication system for online transactions using mobile phones. The system generates one-time passwords (OTPs) using a secret key shared between the server and mobile phone. When users log in, the server sends an OTP as an SMS to their mobile phone. They must enter both their password and the OTP to authenticate. This adds an extra layer of security beyond a single static password by requiring possession of the mobile phone in addition to password knowledge. The system aims to reduce fraud while being easy for users without extra hardware.