Identity provider
Establishes the user or workload identity and authentication assurance. It does not prove device posture.
TECHNICAL ARCHITECTURE
Oten Access connects a service-level policy authority with endpoint-local control and distributed enforcement. The architecture keeps application traffic in the data plane while policy and coordination use separate paths.
System role: System architecture
Establishes the user or workload identity and authentication assurance. It does not prove device posture.
Establishes device context, qualifies endpoint evidence, requests resource access, and enforces decisions at the source.
Acts as the service-level Policy Decision Point and desired-state manager. It does not carry application payload.
ogc-core persists local intent, reconciles desired and last-known-good state, and coordinates endpoint-owned enforcement services.
Coordinates authenticated presence and path candidates; it does not proxy the application payload.
Forwards end-to-end encrypted packets when a direct path is not feasible; it is not a resource Gateway.
Applies route, session, application, and infrastructure policy near protected resources.
Identity, inventory, policy, configuration, enrollment, and audit. The Oten Access Control Plane distributes versioned decisions and desired state outside the payload path.
Signal exchanges presence, control, and path-setup state. It does not carry application payload.
Direct or relayed encrypted traffic between authorized nodes and resource-side enforcement points. Failure affects specific traffic and sessions.
Decision evidence, enforcement acknowledgements, health, and security signals. Backpressure and delay must remain visible and bounded.
POLICY FLOW
A user or workload requests an application, service, host, route, role, or operation.
Oten validates subject identity, device identity, posture evidence, freshness, resource sensitivity, and current session state.
The Policy Decision Point evaluates an immutable policy version and assignment path.
The result includes action, reasons, resource and protocol scope, TTL, re-evaluation triggers, and required enforcement points.
Oten Endpoint and Oten Gateway apply the supported source- and destination-side controls.
Each enforcement point returns the applied generation, timestamp, outcome, evidence digest, or failure reason.
The system records one decision and enforcement trail with a correlation ID.
CONTINUOUS TRUST LOOP
Oten Access turns qualified identity and endpoint evidence into short-lived, resource-specific authority. It enforces the decision at the device and the resource, confirms the outcome, and re-evaluates whenever meaningful conditions change.
ObserveDecideEnforceProveRepeat
Diagram state: Healthy
Establish user and device identity, then qualify authorized posture, integrity, connectivity, and security signals.
A living decision adapts to meaningful evidence. Recovery is earned with new evidence, not assumed after time passes.
Independently establish user or workload identity and device identity.
Collect policy-authorized posture, integrity, connectivity, and security signals.
Verify source, freshness, generation, binding, and evidence integrity.
Evaluate current session context against resource-specific policy.
Define action, scope, lifetime, triggers, and required enforcement points.
Apply supported controls at Endpoint, Gateway, or another required PEP.
Record applied, partial, failed, rolled-back, or unreachable status.
Meaningful changes trigger a new decision; recovery requires fresh evidence.
01
Trust state, resource availability, remediation, approvals, and failure transparency.
02
Authenticated, least-privilege local control between UI, Core, and privileged services.
03
ogc-core maintains durable local intent, desired and last-known-good state, reconciliation, update, and telemetry contracts.
04
Connectivity, Device Trust, Endpoint Defense, Data Protection, and PAM.
05
Native operating-system primitives provide the required sensor and enforcement boundary.
Profile A is assigned to separate Singapore and Dubai Data Plane Groups. Node 01 and Node 02 receive the same signed configuration version.
Only the explicitly selected, compatible Singapore and Dubai nodes are eligible to take over for each other.
Profile B is assigned to the Vietnam Data Plane Group. Vietnam Node 03 remains outside the Singapore and Dubai failover boundary.
Oten-operated control services with customer-deployed Endpoint and Gateway components. Publish only with confirmed operational, residency, and support commitments.
Customer-operated identity integration, policy, Signal, Relay, state, keys, observability, backup, upgrade, and disaster recovery under a responsibility matrix.
Centralized control with Data Plane Groups near resources, scoped configuration, and explicit failure-domain and failover boundaries.
New and existing session behavior depends on token lifetime, session state, step-up requirements, and a separately controlled break-glass path.
Existing authority may continue only within signed policy, evidence, and lease limits. New authority cannot be invented locally.
Existing direct paths may remain; new or relayed connectivity depends on the affected service and network condition.
Takeover is limited to eligible compatible nodes in the configured Failover Set; active-session behavior is mode-specific.
Rollout stops or restores a valid last-known-good version; Saved, Staged, Active, Partial, and Rolled Back remain distinct states.
Unknown or stale never becomes pass. The UI shows last observation, policy outcome, buffering, backpressure, and remediation.
Next in Oten Access
Continue with identity and credential inventory, signed desired state, failure behavior, privacy, and evidence quality.