When a user accesses a website which has SecuSURF installed, the user authenticates to the website and is presented with a dialog that asks for the One-Time Password.
SecuSURF generates an One-Time Password for the user and sends it via SMS to the user's registered mobile number.
The user enters the One-Time Password on the website.
If SecuSURF successfully verifies the One-Time Password, the user gains access to the website.