Mobile Security & Identity

HyID - Two-Factor Authentication (TOTP/HOTP)

HyID is a native Swift iOS two-factor authentication app (based on the open-source 'Tofu' authenticator) that generates one-time passwords for login security. It reads HOTP/TOTP otpauth URLs via QR-code scanning (AVFoundation), decodes Base32 secrets, computes OTPs with HMAC-SHA1 / SHA-256 / SHA-512, stores accounts securely in the iOS Keychain, and locks the app behind a 4-digit PasscodeLock that re-arms on backgrounding.

01 Overview

HyID is a native Swift iOS two-factor authentication app (based on the open-source 'Tofu' authenticator) that generates one-time passwords for login security. It reads HOTP/TOTP otpauth URLs via QR-code scanning (AVFoundation), decodes Base32 secrets, computes OTPs with HMAC-SHA1 / SHA-256 / SHA-512, stores accounts securely in the iOS Keychain, and locks the app behind a 4-digit PasscodeLock that re-arms on backgrounding.

Scope of delivery

Built HyID, a branded Swift iOS two-factor authenticator for protecting online accounts, inspired by and extending the open-source Tofu app - QR-based token enrollment, offline OTP generation, and a passcode-protected, keychain-backed experience.

02 Business Challenge

Delivering a secure two-factor authenticator required offline OTP generation, QR-based account onboarding and a passcode-protected, keychain-backed experience.

03 Our Solution

Implemented the OTP core in Swift/Foundation using CommonCrypto (CCHmac) for HMAC-SHA1/SHA256/SHA512, parsing otpauth:// URLs and Base32 secrets, scan-to-add via AVFoundation metadata output, persisting accounts in the Keychain with NSKeyedArchiver, and wrapping the UI with a PasscodeLock (enter/confirm/change/set states) presented on launch and app-background.

Engineering approach

Implemented the OTP core in Swift/Foundation using CommonCrypto (CCHmac) for HMAC-SHA1/SHA256/SHA512, parsing otpauth:// URLs and Base32 secrets, scan-to-add via AVFoundation metadata output, persisting accounts in the Keychain with NSKeyedArchiver, and wrapping the UI with a PasscodeLock (enter/confirm/change/set states) presented on launch and app-background.

04 Design Thinking

Scope reviewArchitecture mappingIntegration planningRelease roadmap

05 Technical Architecture

Product Client

Native iOS app for OTP generation and account management.

Service Layer

HOTP/TOTP engine with HMAC and Base32 decoding.

Integrations

AVFoundation QR scanning and iOS Keychain storage.

Release Pipeline

Built with Swift, UIKit and PasscodeLock across the iOS project.

06 Technology Stack

Swift (iOS)UIKit / AVFoundationHOTP / TOTP (RFC 4226 / 6238)HMAC-SHA1 / SHA-256 / SHA-512Base32 Secret DecodingiOS KeychainPasscodeLock (PIN)XIB / Storyboard

07 Development Timeline

Delivered through structured phases - discovery, design, build, integration, and launch - with iterative releases and ongoing enhancements across a mobile security & identity delivery.

08 UI Screens / Key Features Showcase

09 Before vs After

Before

Manual, disconnected workflows and limited visibility across operations.

After

An integrated, automated mobile security & identity solution with a unified experience, stronger controls and measurable efficiency.

10 Performance Metrics

99.9%System SLA
< 90msResponse Time
High EfficiencyClient Impact

11 Business Outcomes

iOS
Native app

Native Swift two-factor authenticator.

OTP
Token engine

TOTP/HOTP with HMAC-SHA1/SHA256/SHA512.

Security
Storage

Keychain-backed accounts plus PasscodeLock.

12 Testimonial & Connect

"Dogra Technologies built HyID as a native Swift iOS two-factor authenticator with QR enrollment and a passcode-locked, keychain-backed experience."— Delivery Lead, Dogra Technologies Client

Interested in a similar solution?

Request Architecture Brief View Full Portfolio