The OTAC Trusted Access Gateway (TAG) is a secure bridge deployed at the network edge to manage access between users and Operational Technology (OT) networks. It acts as an intermediary, protecting assets such as PLCs, HMIs, and DCSs by verifying both remote and local user identity with One-Time Authentication Codes (OTAC). The gateway enables the implementation of Multi-Factor Authentication (MFA) at the network level, securing the connection at the device interface without requiring modifications to existing system architecture or legacy equipment firmware.
The gateway utilizes one-way dynamic authentication, which functions without stored credentials, public key infrastructure (PKI), or bidirectional communication, enabling its use in isolated or air-gapped environments. It supports both inline and bypass modes to allow deployment without causing operational downtime. The system also provides centralized user management and comprehensive access logging to facilitate device-level access control, auditability, and the enforcement of zero-trust security principles.