KOREAN / ENGLISH
SSenStone
  • 회사소개
  • 기술소개
    • OTAC
    • FIDO
  • 솔루션
    • OTAC Solutions
      • swIDch: OT Auth
        • - PLC OTAC
        • - OTAC Trusted Access Gateway
        • - OTAC auth - MFA for PLCnext
      • swIDch: Fin Auth
        • - TAP OTAC
        • - OTAC Holderless Card
        • - OTAC Dynamic Token
      • swIDch: IoT Auth
        • - IoT Auth Platform OTAC
        • - Smart Building OTAC
        • - HomeNet OTAC
        • - Connected Car OTAC
        • - Drone OTAC
      • swIDch: Access Auth
        • - Identity & Access Management OTAC
    • FIDO & mOTP Solutions
      • swIDch Auth
        • - swIDch Auth Package
        • - swIDch Auth SDK
  • 적용사례
    • Case Studies
      • Toss bank
      • Kakao bank
      • A-card bank
      • E-Stamp : Indonesia
      • Milipass
  • 회사소식
    • News & Information
    • Blog
    • Video
  • 문의하기
  • 회사소개
  • 기술소개
    • - OTAC
    • - FIDO
  • 솔루션
    • OTAC solutions
      • swIDch: Fin Auth
        • - TAP OTAC
        • - OTAC Holderless Card
        • - OTAC Dynamic Token
      • swIDch: OT Auth
        • - PLC OTAC
        • - MFA for PLCnext
      • swIDch: IoT Auth
        • - IoT Auth Platform OTAC
        • - Smart Building OTAC
        • - HomeNet OTAC
        • - PLC OTAC
        • - Connected Car
        • - Drone
      • swIDch: Access Auth
        • - Identity & Access Management
    • FIDO & mOTP Solutions
      • - swIDch Auth Package
      • - swIDch Auth SDK
  • 적용사례
    • Case Studies
      • - Toss Bank
      • - Kakao Bank
      • - A-Card Bank
      • - E-Stamp : Indonesia
      • - Milipass
  • 회사소식
    • - News & Information
    • - Blog
    • - Video
  • 문의하기

OTAC Solutions

OTAC Trusted Access Gateway

The OTAC Trusted Access Gateway (TAG) is an advanced authentication solution that strengthens PLC user authentication through centralised management—without requiring any modifications to existing PLCs.

Download OT Auth Solutions brochure

Challenges


Cyber threats against operational technology (OT) systems in critical sectors like energy, water, and transportation are escalating at an alarming rate. In 2024, the number of reported Common Vulnerabilities and Exposures (CVEs) reached an all-time high, highlighting the growing attack surface that cybercriminals exploit. These threats pose severe risks, including operational downtime, financial losses, and potential harm to human safety.

 

A major contributing factor to these security gaps is the weak authentication methods used in programmable logic controllers (PLCs), which serve as the backbone of OT networks. Studies indicate that 80% of vulnerabilities exist deep within the industrial control system (ICS) network, meaning attackers must first gain access to OT environments to exploit them. Many PLC devices still depend on factory-set or easily guessable passwords, making them highly susceptible to unauthorised access. Alarmingly, 81% of OT security incidents are linked to weak passwords or stolen credentials. In some cases, access is granted automatically or passwords are shared among users, exposing a severe lack of security enforcement.

 

While some OT organisations are making efforts to improve PLC security, progress is slow. As OT environments continue to evolve with more connected devices and advanced functionalities, implementing robust authentication becomes increasingly challenging—especially without direct collaboration from PLC manufacturers. As a result, many organisations remain dependent on vendor-released security patches to mitigate risks.

 

Moreover, user management in most OT infrastructures remains inadequate. Many PLC devices either lack individual user authentication or operate without any password protection, making it difficult to track and manage access.

 

[Standard OT Authentication Flow]

 

OTAC Trusted Access Gateway_01

Solutions


The OTAC Trusted Access Gateway eliminates the vulnerabilities of static password authentication by leveraging one-time authentication code (OTAC) technology—an innovative, one-way dynamic authentication method developed by swIDch. Instead of relying on fixed credentials, OTAC generates unique, non-reusable authentication codes via smartphones, smart cards, or authorised laptops, preventing credential theft and unauthorised access.

 

Designed to enhance PLC security without requiring modifications to existing devices, the OTAC Trusted Access Gateway acts as an intermediary between PLCs and users, ensuring that only authenticated personnel can gain access. This solution effectively blocks unauthorised entry and protects critical OT infrastructure from cyber threats.

 

Additionally, the OTAC Trusted Access Gateway simplifies identity management by recording both user and device activity, making access monitoring straightforward. Unlike public key infrastructure (PKI), which requires complex certificate management, or biometric authentication, which relies on bidirectional communication, OTAC operates as a one-way authentication solution that functions even in offline environments.

[OT Authentication Flow with The OTAC Trusted Access Gateway Deployed]

 

[센스톤] OTAC TAG_02_ENG

1. Deployment: The OTAC Trusted Access Gateway is positioned between the user device generating OTAC and the OT system requiring authentication.
2. Authentication Request: When an engineer launches a PLC, HMI, RTU, or DCS engineering application, the OTAC Trusted Access Gateway prompts the registered user device to complete the multi-factor authentication (MFA) process.
3. OTAC Generation: The user generates an OTAC on their registered device (e.g., smartphone or smart card) and enters it into the system.
4. Validation: The OTAC Trusted Access Gateway verifies the code and grants access if the user is authorised.

 

 

 

 

Benefits

The OTAC Trusted Access Gateway enhances OT authentication security without requiring extensive system modifications.

• No Modifications to Existing PLCs: The solution integrates seamlessly with current PLC infrastructure without requiring changes.
• Centralised User Management: Authentication is centrally managed for better access control.
• One-Time Dynamic Authentication Codes: Static passwords are replaced with unique, session-based codes to enhance security.
• Comprehensive Access Logs: Unlike traditional PLC access logs that lack user tracking, the OTAC Trusted Access Gateway provides detailed records, offering clear visibility into authentication events.

 

 

 

 

Why OTAC

OTAC, developed by SSenStone, is the original technology that provides all of the following features at the same time.

Main Large

    OTAC is a dynamic code, which means the code keeps changing. As a result, you don’t need to worry about any leak of your personal information, such as your card details, because the codes must have already been changed when others try to use them.

    The network connection is NOT necessary at all for generating OTAC.

    Reducing an authentication stage that requires the network connection directly means there are fewer gateways for the hackers to access our personal information.

    Moreover, this feature enables users to authenticate even when they are in networkless environments, such as on the plane, underground, rural or foreign areas.

    swIDch can guarantee that the code never duplicates with anyone at any given moment.

    There is NO chance of someone else having the same code.

    The users or their devices can be identified with the code alone.

    Once OTAC has been generated, providing OTAC alone is already fully sufficient to identify the user as the code is unique.

    It means, you can forget about the bundles of static information including IDs and passwords.

OTAC Algorithm Analysis and Academic Verification

report_otac_surrey univ

The University of Surrey, one of the leading global cyber security companies in the UK, conducted OTAC algorithm analysis and academic verification of SSenStone. For the full text of the thesis, please visit the University of Surrey website and download the report.

 

Univ. of Surrey Website
Download the Report

New Excellent Technology (NET) Certification Acquired

NET신기술인증-removebg-preview

SSenStone has received the NET Certification from the Ministry of Trade, Industry, and Energy for its "Individual IoT Device Authentication and Transmission Data Security Technology through Unidirectional Dynamic Authentication (OTAC)."

 

NET Website
Press Release

International Common Criteria (CC) Certification Achieved

국제CC인증_엠블럼 (png)

OTACTokenV1.0, the authentication solution based on the world’s first unidirectional dynamic authentication technology, OTAC, has earned the international Common Criteria (CC) certification. For more information, please refer to the press release.

 

ITSCC Website
Press Release

OTAC for Phygital Wins IR52 Jang Yeong-sil Award

IR52 logo

SSenStone's OTAC for Phygital has been awarded the 40th-week IR52 Jang Yeong-sil Award for 2024, hosted by the Ministry of Science and ICT. For more details, please visit the official IR52 Jang Yeong-sil Award homepage or the press release.

 

IR52 Website
Press Release

Insights

  • The Future of Financial Security in the Face of Phishing Attacks

    In recent years, financial security incidents, especially phishing attacks, have become a serious...

    Read more

  • How is ChatGPT addressing financial fraud?

    Last year, after giving birth, I hired a postpartum doula to help me. After trying out a few...

    Read more

  • Solving Voice Phishing and Smishing Security Issues: SSenStone's Personal Information Authentication Technology

    Today, I'd like to discuss a crucial financial security issue that affects us all, and explore the...

    Read more

  • Securing the Seas through Advanced Authentication Revolutionising Safer and Cleaner Shipping

    The maritime industry is undergoing a significant transformation, driven by the dual imperatives of...

    Read more

Contact Us

Improve your authentication environment and
make your service reliable with SSenStone!

Inquire now.

5F, 329, Cheonho-daero Dongdaemun-gu, Seoul, Republic of Korea (02622)

Contact below if you have an urgent inquiry.

Korea Office (SSenStone)

5F, 329, Cheonho-daero Dongdaemun-gu, Seoul, Republic of Korea (02622)

Tel : 02-569-9668  |  Fax : 02-6455-9668

im@ssenstone.com

UK Office (swIDch)

Floor 1, 3 More London SE1 2RE, United Kingdom

Tel : 020-3283-4563

info@swidch.com

SSenStone Inc.

서울특별시 동대문구 천호대로 329 (도이치모터스빌딩) 5층

T. 02-569-9668

F. 02-6455-9668

E. im@ssenstone.com

Sitemap  Privacy

Copyright© SSenStone Inc. All rights reserved.