shutterstock_OTAC technology
shutterstock_OTAC technology


A new paradigm for user authentication and device authentication
A dynamic, randomized, one-time authentication code...
generated on-demand, locally by the user...
without needing any network...
...that enables identification and authentication simultaneously in a single step.


Based on the world’s first one-way dynamic authentication technology, one-time authentication code (OTAC) originally invented by swIDch provides more secure authentication by uni-directional dynamic token ONLY to overcome bi-directional limitations including high dependency on the push & pull system of network connectivity between clients and servers. By reinventing authentication, swIDch sets a new standard for authentication in cybersecurity beyond the limitations of existing authentication methods.

shutterstock_username and password EDITED

What we face

A cyber-attack takes place somewhere around the world
once every 39 seconds. As a result, there were 8 billion pieces
of sensitive personal information being leaked to the market in 2019.
These all cost the global economy a staggering $2.9M
every minute in 2020. But WHY does this happen?
shutterstock_username and password EDITED
Risk of static
Card numbers, ID, password, and PINs which we use every day are great examples of static information used as authentication credentials. Knowledge-based authentication – whether with PINs, passwords, passphrases – is not only a headache for users, it is also costly to maintain. As the world becomes more connected, using static information for authentication carries with it a huge vulnerability allowing cyber crimes such as identity theft, card-not-present fraud, and hijacking to take place.
- Static information
- Easily lost and stolen
authentication process
OTP, which is widely used for secure identity authentication, cannot perform user authentication alone, so an initial authentication step (usually ID and password) is required. Since you must go through more than one authentication step, the complexity feels even greater for users.
- On its own, it is not enough to identify a user.
- It always requires initial self-authentication between a user and a server.
connection distress
In locations with poor network,
it is difficult to force the use of a communication network for authentication. The token method is used in numerous authentication environments and has become one of the most common ways of performing secure authentication by obtaining access rights through a specific point-in-time comparison of the authentication key generated by a token service operator (TSP). This is limited due to the reliance of connectivity between a user, a server and a TSP. It is also only operates in an environment controlled by a central server.
- Requires network connection
- Bi-Directional

What we offer

swIDch’s OTAC technology combines advantages of the three most common authentication systems – user ID/passwords, RSA hardware/software for generating authentication codes, and tokenisation. This provides a solution that is more efficient and more effective than any of these elements individually. It generates a single dynamic code that both identifies and authenticates the user at the same time and can do so without a network connection. And because it’s a single-use, time-based code that’s unique to the user, it can’t be used by someone else or used again.
Strong security
OTAC substantially increases security by generating dynamic authentication codes even in an off-the-network environment.
Seamless Integration
Use of API/SDK to bring simple and frictionless integration for IT admins.
Unlimited scalability
& flexibility
The lightness of OTAC enables applications in multiple industries and not limited to devices
cost saving
No need to build heavy token infrastructure. Save costs associated with network traffic, maintenance, and fraud compensation.
High risk of information breach with static information
Difficult to identify/authenticate the user with OTP alone
High dependency on push & pull system of network connectivity between clients and servers
Duplication-free dynamic code authentication prevents from various breach risks
Identify and authenticate the user with dynamic codes alone
Dynamic code generation without network connectivity
[JPG] OTAC technology table v2

How it works

Build customisable, flexible solutions depending on your industry and use case. The generation of the code can happen locally on the device or even on the IC chip across a range of cards and applications. The format is then configurable to each clients needs, along with the transfer and verification. This flexibility combined with configurable time intervals provides a highly flexible and super secure authentication solution across a wide range of industries, and unique to every clients needs and requirements.


International CC Certification for OTAC
Our OTAC technology has obtained the global CC standard for its strong security, stability and reliability. 

144 Registered,
310 Pending

Cover cover Cover Cover Cover Cover Cover

List of Awards

Cybersecurity Breakthrough Award 2022_swIDch
"Transaction Security Solutions of the Year" 2022 CyberSecurity Breakthrough Award
See More
Best IoT/IIoT Security Solution 2022 SC Awards
See More
2022 Gold Winner at 14th Annual 2022 Golden Bridge Business and Innovation Awards
See More
2022 Gold Winner at 17th Annual 2022 Information Technology World Awards IT World Awards
See More
2022 Gold GLOBEE Winner "Startup of the Year" in Security Services
See More
CyberSecurity Breakthrough Award 2021 4MP
"Overall Fraud Prevention Solution Provider of the Year" CyberSecurity Breakthrough Awards 2021
See More
2021 Cybertech 100
2021 Cybertech 100
See More
2020 Cybertech category winner of EUROPAS 2020 Award
2020 Cybertech category winner of EUROPAS 2020 Award
See More
CyberSecurity Breakthrough Award 2020 (1)
“Authentication Solution of the Year” CyberSecurity Breakthrough Award 2020
See More
2020 Cybertech 100
See More
2021 Cybertech 100
See More