OTAC Solutions
OTAC Trusted Access Gateway
The OTAC Trusted Access Gateway (TAG) is an advanced authentication solution that strengthens PLC user authentication through centralised management—without requiring any modifications to existing PLCs.
Challenges
Cyber threats against operational technology (OT) systems in critical sectors like energy, water, and transportation are escalating at an alarming rate. In 2024, the number of reported Common Vulnerabilities and Exposures (CVEs) reached an all-time high, highlighting the growing attack surface that cybercriminals exploit. These threats pose severe risks, including operational downtime, financial losses, and potential harm to human safety.
A major contributing factor to these security gaps is the weak authentication methods used in programmable logic controllers (PLCs), which serve as the backbone of OT networks. Studies indicate that 80% of vulnerabilities exist deep within the industrial control system (ICS) network, meaning attackers must first gain access to OT environments to exploit them. Many PLC devices still depend on factory-set or easily guessable passwords, making them highly susceptible to unauthorised access. Alarmingly, 81% of OT security incidents are linked to weak passwords or stolen credentials. In some cases, access is granted automatically or passwords are shared among users, exposing a severe lack of security enforcement.
While some OT organisations are making efforts to improve PLC security, progress is slow. As OT environments continue to evolve with more connected devices and advanced functionalities, implementing robust authentication becomes increasingly challenging—especially without direct collaboration from PLC manufacturers. As a result, many organisations remain dependent on vendor-released security patches to mitigate risks.
Moreover, user management in most OT infrastructures remains inadequate. Many PLC devices either lack individual user authentication or operate without any password protection, making it difficult to track and manage access.
[Standard OT Authentication Flow]

Solutions
The OTAC Trusted Access Gateway eliminates the vulnerabilities of static password authentication by leveraging one-time authentication code (OTAC) technology—an innovative, one-way dynamic authentication method developed by swIDch. Instead of relying on fixed credentials, OTAC generates unique, non-reusable authentication codes via smartphones, smart cards, or authorised laptops, preventing credential theft and unauthorised access.
Designed to enhance PLC security without requiring modifications to existing devices, the OTAC Trusted Access Gateway acts as an intermediary between PLCs and users, ensuring that only authenticated personnel can gain access. This solution effectively blocks unauthorised entry and protects critical OT infrastructure from cyber threats.
Additionally, the OTAC Trusted Access Gateway simplifies identity management by recording both user and device activity, making access monitoring straightforward. Unlike public key infrastructure (PKI), which requires complex certificate management, or biometric authentication, which relies on bidirectional communication, OTAC operates as a one-way authentication solution that functions even in offline environments.
[OT Authentication Flow with The OTAC Trusted Access Gateway Deployed]

1. Deployment: The OTAC Trusted Access Gateway is positioned between the user device generating OTAC and the OT system requiring authentication.
2. Authentication Request: When an engineer launches a PLC, HMI, RTU, or DCS engineering application, the OTAC Trusted Access Gateway prompts the registered user device to complete the multi-factor authentication (MFA) process.
3. OTAC Generation: The user generates an OTAC on their registered device (e.g., smartphone or smart card) and enters it into the system.
4. Validation: The OTAC Trusted Access Gateway verifies the code and grants access if the user is authorised.
Benefits
The OTAC Trusted Access Gateway enhances OT authentication security without requiring extensive system modifications.
• No Modifications to Existing PLCs: The solution integrates seamlessly with current PLC infrastructure without requiring changes.
• Centralised User Management: Authentication is centrally managed for better access control.
• One-Time Dynamic Authentication Codes: Static passwords are replaced with unique, session-based codes to enhance security.
• Comprehensive Access Logs: Unlike traditional PLC access logs that lack user tracking, the OTAC Trusted Access Gateway provides detailed records, offering clear visibility into authentication events.
Why OTAC
OTAC, developed by SSenStone, is the original technology that provides all of the following features at the same time.
-
OTAC is a dynamic code, which means the code keeps changing. As a result, you don’t need to worry about any leak of your personal information, such as your card details, because the codes must have already been changed when others try to use them.
-
The network connection is NOT necessary at all for generating OTAC.
Reducing an authentication stage that requires the network connection directly means there are fewer gateways for the hackers to access our personal information.
Moreover, this feature enables users to authenticate even when they are in networkless environments, such as on the plane, underground, rural or foreign areas. -
swIDch can guarantee that the code never duplicates with anyone at any given moment.
There is NO chance of someone else having the same code. -
The users or their devices can be identified with the code alone.
Once OTAC has been generated, providing OTAC alone is already fully sufficient to identify the user as the code is unique.
It means, you can forget about the bundles of static information including IDs and passwords.
OTAC Algorithm Analysis and Academic Verification

New Excellent Technology (NET) Certification Acquired

SSenStone has received the NET Certification from the Ministry of Trade, Industry, and Energy for its "Individual IoT Device Authentication and Transmission Data Security Technology through Unidirectional Dynamic Authentication (OTAC)."
International Common Criteria (CC) Certification Achieved
.png?width=150&height=150&name=%EA%B5%AD%EC%A0%9CCC%EC%9D%B8%EC%A6%9D_%EC%97%A0%EB%B8%94%EB%9F%BC%20(png).png)
OTACTokenV1.0, the authentication solution based on the world’s first unidirectional dynamic authentication technology, OTAC, has earned the international Common Criteria (CC) certification. For more information, please refer to the press release.
OTAC for Phygital Wins IR52 Jang Yeong-sil Award

SSenStone's OTAC for Phygital has been awarded the 40th-week IR52 Jang Yeong-sil Award for 2024, hosted by the Ministry of Science and ICT. For more details, please visit the official IR52 Jang Yeong-sil Award homepage or the press release.
Insights
Contact Us
make your service reliable with SSenStone!
Inquire now.
5F, 329, Cheonho-daero Dongdaemun-gu, Seoul, Republic of Korea (02622)
Contact below if you have an urgent inquiry.
Korea Office (SSenStone)
5F, 329, Cheonho-daero Dongdaemun-gu, Seoul, Republic of Korea (02622)
Tel : 02-569-9668 | Fax : 02-6455-9668
im@ssenstone.com
UK Office (swIDch)
Floor 1, 3 More London SE1 2RE, United Kingdom
Tel : 020-3283-4563
info@swidch.com