India operates one of the most sophisticated and expansive digital-payment ecosystems in the world. This incredible achievement has historically relied on a simple foundation: the mobile number, verified through robust KYC protocols.
However, as artificial intelligence reaches maturity, the trust model we have leaned on for a decade is facing an unprecedented architectural mismatch.
Our latest concept paper, “Moving Trust Down the Stack,” addresses why smartphone-based, hardware-bound authentication is the most secure, inclusive, and durable foundation for the next decade of Indian banking.
The Architectural Mismatch: Proofing is Not Authentication
There is a fundamental difference between establishing who a user is once, and verifying they are still that person every single day.
- Identity Proofing is a singular event that occurs at onboarding, where a SIM serves as a credible proxy for a government-validated identity.
- Authentication is a continuous, runtime requirement to verify the current user is indeed the same individual.
Today, the ecosystem heavily relies on the SIM and SMS-based OTPs to handle both jobs. This expansion has merged two separate functions, creating a critical vulnerability. While a network verification can confirm a SIM is active, it cannot prove that the original, verified human remains in possession of it —especially in a market where dormant numbers are legally recycled and reassigned to new subscribers.
The Evolving Risk: AI Lives at the Software Layer
The reason this distinction matters right now is the changing nature of attackers. Software-based authentication—whether it’s an SMS OTP, a knowledge factor like a PIN, or standard face-matching—lives at the software layer. This is precisely the terrain where AI is strongest.
AI can now fluently operate at this layer to execute:
- Advanced phishing and credential harvesting.
- AI-driven voice cloning and deepfake injection attacks.
- SIM-swap-as-a-service and probabilistic device spoofing.
Adding more software controls only fights AI on its own turf. As AI moves up the technology stack, the root of trust must move down it—into the hardware layer.
The Core Principle: The defender must rely on physics, which AI cannot reproduce, rather than on software, which it can.
Turning the Smartphone Camera into a Cryptographic Key
To secure India’s scale, the hardware anchor must be a device every citizen already holds: the smartphone.
This is where ToothPic comes in. Every single smartphone camera sensor carries a unique, immutable pattern of microscopic manufacturing imperfections known as Photo-Response Non-Uniformity (PRNU).
ToothPic converts this physical fingerprint into a cryptographic key that is:
- Never stored at rest: It is re-derived from the sensor at each use and immediately destroyed.
- Phish-proof: There is no secret to extract, clone, or intercept.
- SIM-independent: It is completely immune to SIM-swaps, number porting, and network changes.
Aligned with the RBI’s Vision
This hardware-bound framework isn’t just a security upgrade; it directly aligns with the Reserve Bank of India’s (RBI) 2025 Directions (effective April 1, 2026). The RBI’s mandate requires at least one dynamic, possession-based factor per transaction and actively encourages robust, device-bound alternatives.
By utilizing the smartphone’s built-in sensors, Indian banks can achieve compliance with effectively zero marginal hardware costs, ensuring financial inclusion remains uncompromised across both rural and urban segments.
Download the Full Concept Paper
We view this paper not as a rigid mandate, but as a principal framework for shared industry discussion. Read our full breakdown, including a side-by-side technical comparison between SMS Binding, Silent Network Authentication (SNA), and Hardware-Anchored security.



