technology cover
Technology

OTAC

A new paradigm for user authentication and device authentication
Based on the world’s first one-way dynamic authentication technology, OTAC technology, originally invented by swIDch, provides more secure authentication for all digital identities even in the off-the-network environment. By reinventing authentication, swIDch sets a new standard for authentication in cybersecurity beyond the limitations of existing authentication methods.
What we face

What we face

A cyber-attack takes place somewhere around the world once every 39 seconds. As a result, there were 8 billion pieces of sensitive personal information being leaked to the market in 2019.These all cost the global economy a staggering $2.9M every minute in 2020. But WHY does this happen?
Risk of static
information
Card numbers, ID, password, and PINs which we use every day are great examples of static information used as authentication credentials. Knowledge-based authentication – whether with PINs, passwords, passphrases – not only causes a major headache for users, but is also costly to maintain. As the world gets more connected, using static information for authentication carries with it a huge vulnerability allowing cyber crimes such as identity theft, card-not-present fraud, and hijacking to take place.
ID/PW
- Static information
- Easily lost and stolen
Complex
authentication process
OTP, which is widely used for secure identity authentication, cannot perform user authentication alone, so an initial authentication step (usually ID and password) is required. Since you must go through more than one authentication step, the complexity feels even greater for users.
OTP
- On its own, it is not enough to identify a user.
- It always requires initial self-authentication between a user and a server.
Network
connection distress
In locations with poor network,
it is a big headache to force the use of a communication network for authentication. The token method is used in numerous authentication environments and has become one of the most common ways of performing secure authentication by obtaining access rights through a specific point-in-time comparison of the authentication key generated by a token service operator (TSP). This is limited due to the reliance of connectivity between a user, a server and a TSP. It is also only operates in an environment controlled by a central server.
Token
- Requires network connection
- Bi-Directional

What we offer

swIDch’s OTAC technology combines advantages of the three most common authentication systems – user ID/passwords, RSA hardware/software for generating authentication codes, and tokenisation.This provides a solution that is more efficient and more effective than any of these elements individually.
It generates a single dynamic code that both identifies and authenticates the user at the same time andcan do so without a network connection. And because it’s a single-use, time-based code that’s unique to the user, it can’t be used by someone else or used again.
Strong security
Passwordless Multi-factor
Authentication.
No identity theft and CNP (Card-not-present) frauds by completely eliminating the attack surface.
Seamless Integration
Use of API/SDK to bring simple and frictionless integration for IT admins.
Unlimited scalability
& flexibility
The lightness of OTAC enables applications in multiple industries and not limited to devices
Unbelievable
cost saving
No need to build heavy token infrastructure. Save costs associated with network traffic, maintenance, and fraud compensation.
cover
User authentication is impossible With OTP only
Vulnerable to leakage/exposure by Static value
Communication required between User and server
(Pull & Push)
cover
No need to communicate with Server
Real-Time changes every time for Secure
authentication
Non-reusable One-Time Authentication
No duplication or overlap

How it works

To access a system using OTAC, authorised users can use their mobile device and – for an extra layer of security – something like an employee ID or bank card enabled with swIDch’s technology.
By launching the swIDch app, or the client’s own app integrated with swIDch technology, and then touching the ID or bank card to the mobile device, users can generate a one-time alphanumeric or QR code.
In effect, the user’s device acts like a token server, generating a one-time code for access without the need to connect to a network. Identification and authorisation are then both enabled when userstype or scan their code into the system they want to access.
Welcome to
Remote Access
This service provides secure access to internal resources when you are working outside of the office.
Username
Password
Pin+Token
Login
Traditional company intranet access
Welcome to
Remote Access
This service provides secure access to internal resources when you are working outside of the office.
OTAC
Login
Company intranet using swIDch

Where to use

cover
OTAC technology can generate dynamic virtual card details without a networkconnection, thereby adding an extra layer of security to the payment process. This patented technology is a CNP (card not present) security solution that replaces static card information with dynamic details, which gives users full control over their security and finance.
cover
Current digital key solutions require network connectivity when it comes to car sharing to receive and activate the key. There can be an issue when the vehicle is located in a basement or rural area where network connectivity is weak.
OTAC allows drivers to access a vehicle in a networkless environment. No matter where the driver or car is located, there are no obstacles for drivers activating the digital key and sharing it with an authorized person.
cover
OTAC is unidirectional authentication technology that allows devices to simply authenticate your user/object with the dynamic code. Enable your users to locally generate OTAC and deliver it over various channels such as voice, keypad, Bluetooth, etc. Algorithm size under 4KB fits into any device chips for enhanced security.
cover
Enterprises are moving towards microservice environments implemented with end-to-end trust. However, authentication flows can be cumbersome and involve many round-trips, with an irreducible time cost for each; authorisation services can become overwhelmed as each microservice relies on them for access control. OTAC allows secure authentication of a user in a single ended flow, greatly reducing the number of round trips.
cover
Forget passwords and OTPs. Users can securely access services and networks with OTAC code alone. OTAC guarantees hassle free log-in that works even in an off-the-network environment. With OTAC, access your company applications anywhere and anytime. Remote working is no longer a problem.
cover
In the middle of a battle in a war, it is very difficult to identify your friendlies or targets. Current solution to the problem is to identify friendlies from their devices using static information, which can be hacked and used by the enemy. OTAC can completely eliminate this risk by generating dynamic codes locally without a network. Wherever a soldier is located, their device will send a dynamic code which hackers cannot steal so that their own force can identify securely.

Patents
50 Registered,
140 Pending

covercovercovercovercovercovercover

List of Awards