This document discusses using one-time password (OTP) grid cards for strong authentication in online applications in Mongolia. It proposes a system where OTPs are generated from grid cards containing numbers and letters. When logging in, a user must provide their password and the contents of a randomly selected cell from their unique grid card. Adding salt passwords and generating challenges from least-used cells increases security by preventing prediction of responses. The system aims to improve online banking security in Mongolia by providing multi-factor authentication without specialized hardware tokens.