Technology
OTAC (One-Time Authentication Code)
A new paradigm for user authentication and device authentication
Based on the world’s first one-way dynamic authentication technology, the One-Time Authentication Code(OTAC) originally invented by SSenStone, provides more secure authentication by the only uni-directional dynamic token to overcome bi-directional limitations such as high dependency on push&pull system of network connectivity between clients and servers. By reinventing authentication, SSenStone sets a new standard for authentication in cybersecurity beyond the limitation of existing authentication methods.
What we face
A cyber-attack takes place somewhere around the world once every 39 seconds. As a result, there were 8 billion pieces of sensitive personal information being leaked to the market in 2019. These all cost the global economy a staggering $2.9M every minute in 2020. But WHY does this happen?
Risk of static
information
Card numbers, ID, password, and PINs which we use every day are great examples of static information used as authentication credentials. Knowledge-based authentication – whether with PINs, passwords, or passphrases – not only causes a major headache for users, but is also costly to maintain. As the world gets more connected, using static information for authentication carries with it a huge vulnerability allowing cyber crimes such as identity theft, card-not-present fraud, and hijacking to take place.
ID / PW
- Static information
- Easily lost and stolen
Complex
authentication process
OTP, which is widely used for secure identity authentication, cannot perform user authentication alone, so an initial authentication step (usually ID and password) is required. Since you must go through more than one authentication step, the complexity feels even greater for users.
OTP
- On its own, it is not enough to identify a user
- It always requires initial self-authentication
between a user and a server
Network connection
distress
In locations with a poor network, it is a big headache to force the use of a communication network for authentication. The token method is used in numerous authentication environments and has become one of the most common ways of performing secure authentication by obtaining access rights through a specific point-in-time comparison of the authentication key generated by a token service operator (TSP). This is limited due to the reliance on connectivity between a user, a server, and a TSP. It also only operates in an environment controlled by a central server.
Token
- Requires network connection
- Bi-Directional
What we offer
SSenStone’s OTAC technology combines the advantages of the three most common authentication systems – user ID/passwords, RSA hardware/software for generating authentication codes, and tokenisation. This provides a solution that is more efficient and more effective than any of these elements individually.
It generates a single dynamic code that both identifies and authenticates the user at the same time and can do so without a network connection. And because it’s a single-use, time-based code that’s unique to the user, it can’t be used by someone else or used again.
Strong
Security
OTAC completes stronger security by generating dynamic authentication codes even in an off-the-network environment.
Seamless
Integration
Use of API/SDK to bring simple and frictionless integration for IT admins.
Unlimited scalability
&flexibility
The lightness of OTAC enables applications in multiple industries and not limited to devices.
Unbelievable
cost saving
No need to build heavy token infrastructure. Save costs associated with network traffic, maintenance, and fraud compensation.
Existing Authentication Methods
-
High risk of information breach with static information
-
Difficult to identify/authentication the user with OTP alone
-
High dependency on push&pull system of network connectivity between clients and servers
OTAC
-
Duplication-free dynamic code authentication prevents from various breach risks
-
Identify and authenticate the user with dynamic codes alone
-
Dynamic code generates without network connectivity
How it works
To access a system using OTAC, authorised users can use their mobile devices. Also, other devices can be added for an extra layer of security such as an employee ID or bank card enabled with OTAC. By launching the SSenStone app or the client’s own app integrated with OTAC, and then tapping the ID or bank card on the mobile device, users can generate a one-time alphanumeric or QR code.
In effect, the user’s device acts like a token server, generating a one-time code for access without the need to connect to networks. Identification and authorisation are then both enabled when users insert or scan their code into the system they want to access.
Where to use
swIDch: Fin Auth
SSenStone provides authentication solutions that allow anyone to conduct financial transactions easily and conveniently, as well as fundamentally block external threats in the identity and transaction authentication process.
swIDch: OT Auth
SSenStone's PLC-OTAC surpasses the vulnerability of password-based authentication methods, offering a secure and advanced user authentication process using one-way dynamic codes, eliminating the risk of duplication.
swIDch: IoT Auth
SSenStone’s proven authentication solution provides a reliable foundation to manage all connected assets more safely and efficiently through secure access and control of all Internet of Things connected to the network.
Read more
swIDch: Access Auth
SSenStone’s OTAC provides control to users in mobile and remote work environments or grants a certain level of authority to access corporate resources and networks.
Read more
Insights
Contact Us
make your service reliable with SSenStone!
Inquire now.
5F, 329, Cheonho-daero Dongdaemun-gu, Seoul, Republic of Korea
Contact below if you have an urgent inquiry.
Korea Office (SSenStone)
5F, 329, Cheonho-daero Dongdaemun-gu, Seoul, Republic of Korea (02622)
Tel : 02-569-9668 | Fax : 02-6455-9668
im@ssenstone.com
UK Office (swIDch)
Office 158, 1st Floor, 3 More London Riverside, London, England, SE1 2RE
Tel : 020-3283-4081
info@swidch.com