Oten Access

TECHNICAL ARCHITECTURE

Separate policy decisions from the encrypted access path.

Oten Access connects a service-level policy authority with endpoint-local control and distributed enforcement. The architecture keeps application traffic in the data plane while policy and coordination use separate paths.

System role: System architecture

Policy and desired stateCoordinationApplication trafficOptional encrypted fallback
The Oten Access Control Plane evaluates and distributes policy. Signal coordinates setup. Endpoint and Gateway enforce access while application payload remains in the data plane.

Every component has a defined trust and traffic boundary.

Identity provider

Establishes the user or workload identity and authentication assurance. It does not prove device posture.

Oten Endpoint

Establishes device context, qualifies endpoint evidence, requests resource access, and enforces decisions at the source.

Oten Access Control Plane

Acts as the service-level Policy Decision Point and desired-state manager. It does not carry application payload.

Oten Endpoint Local Control Plane

ogc-core persists local intent, reconciles desired and last-known-good state, and coordinates endpoint-owned enforcement services.

Signal Service

Coordinates authenticated presence and path candidates; it does not proxy the application payload.

Relay Service

Forwards end-to-end encrypted packets when a direct path is not feasible; it is not a resource Gateway.

Oten Gateway

Applies route, session, application, and infrastructure policy near protected resources.

Control, coordination, and traffic scale and fail independently.

Policy and desired stateCoordinationApplication trafficOptional encrypted fallback
The Oten Access Control Plane evaluates and distributes policy. Signal coordinates setup. Endpoint and Gateway enforce access while application payload remains in the data plane.

Control plane

Identity, inventory, policy, configuration, enrollment, and audit. The Oten Access Control Plane distributes versioned decisions and desired state outside the payload path.

Coordination plane

Signal exchanges presence, control, and path-setup state. It does not carry application payload.

Data Plane

Direct or relayed encrypted traffic between authorized nodes and resource-side enforcement points. Failure affects specific traffic and sessions.

Audit and telemetry

Decision evidence, enforcement acknowledgements, health, and security signals. Backpressure and delay must remain visible and bounded.

POLICY FLOW

Identity + Device + Resource + Conditions → Decision → Enforcement

  1. Request

    A user or workload requests an application, service, host, route, role, or operation.

  2. Qualify context

    Oten validates subject identity, device identity, posture evidence, freshness, resource sensitivity, and current session state.

  3. Evaluate

    The Policy Decision Point evaluates an immutable policy version and assignment path.

  4. Issue bounded authority

    The result includes action, reasons, resource and protocol scope, TTL, re-evaluation triggers, and required enforcement points.

  5. Enforce

    Oten Endpoint and Oten Gateway apply the supported source- and destination-side controls.

  6. Confirm

    Each enforcement point returns the applied generation, timestamp, outcome, evidence digest, or failure reason.

  7. Correlate

    The system records one decision and enforcement trail with a correlation ID.

CONTINUOUS TRUST LOOP

Access changes when risk changes.

Oten Access turns qualified identity and endpoint evidence into short-lived, resource-specific authority. It enforces the decision at the device and the resource, confirms the outcome, and re-evaluates whenever meaningful conditions change.

ObserveDecideEnforceProveRepeat

Oten Endpoint supplies qualified identity and device evidence. The Access Control Plane observes, decides, enforces at Oten Endpoint and Oten Gateway, and proves the outcome. Confirmation returns to the next evaluation.Oten Endpoint supplies qualified identity and device evidence. The Access Control Plane evaluates resource-specific policy and sends a bounded decision to Oten Endpoint and Oten Gateway. Required enforcement points report the actual outcome, which becomes input to the next evaluation.

Diagram state: Healthy

Source: User + Oten Endpoint. Destination: Oten Gateway + Private Resource. The decision reaches both sides and the confirmation returns to the loop.
OBSERVE

Establish user and device identity, then qualify authorized posture, integrity, connectivity, and security signals.

  • Establish identity
  • Observe evidence
  • Qualify trust

What happens when risk changes mid-session?

A living decision adapts to meaningful evidence. Recovery is earned with new evidence, not assumed after time passes.

View the complete eight-stage architecture
01

Establish identity

Independently establish user or workload identity and device identity.

02

Observe evidence

Collect policy-authorized posture, integrity, connectivity, and security signals.

03

Qualify trust

Verify source, freshness, generation, binding, and evidence integrity.

04

Decide access

Evaluate current session context against resource-specific policy.

05

Issue bounded authority

Define action, scope, lifetime, triggers, and required enforcement points.

06

Enforce at both ends

Apply supported controls at Endpoint, Gateway, or another required PEP.

07

Confirm outcome

Record applied, partial, failed, rolled-back, or unreachable status.

08

Re-evaluate and recover

Meaningful changes trigger a new decision; recovery requires fresh evidence.

Oten Endpoint keeps durable local authority inside the device boundary.

01

User experience

Trust state, resource availability, remediation, approvals, and failure transparency.

02

Secure IPC

Authenticated, least-privilege local control between UI, Core, and privileged services.

03

Oten Endpoint Local Control Plane

ogc-core maintains durable local intent, desired and last-known-good state, reconciliation, update, and telemetry contracts.

04

Capability modules

Connectivity, Device Trust, Endpoint Defense, Data Protection, and PAM.

05

Platform adapters

Native operating-system primitives provide the required sensor and enforcement boundary.

Gateway topology separates assignment from takeover.

Control Plane manages one Gateway Deployment. Profile A is assigned to separate Singapore and Dubai Data Plane Groups, whose compatible nodes form one explicit Failover Set. Profile B is assigned to the Vietnam Data Plane Group and remains outside that set.

Profile A: Singapore and Dubai

Profile A is assigned to separate Singapore and Dubai Data Plane Groups. Node 01 and Node 02 receive the same signed configuration version.

Singapore and Dubai Failover Set

Only the explicitly selected, compatible Singapore and Dubai nodes are eligible to take over for each other.

Profile B: Vietnam

Profile B is assigned to the Vietnam Data Plane Group. Vietnam Node 03 remains outside the Singapore and Dubai failover boundary.

Deployment ownership must be explicit.

Managed Control Plane

Oten-operated control services with customer-deployed Endpoint and Gateway components. Publish only with confirmed operational, residency, and support commitments.

Self-hosted Control Plane

Customer-operated identity integration, policy, Signal, Relay, state, keys, observability, backup, upgrade, and disaster recovery under a responsibility matrix.

Distributed data plane

Centralized control with Data Plane Groups near resources, scoped configuration, and explicit failure-domain and failover boundaries.

Partial failure is part of the access model.

Identity provider unavailable

New and existing session behavior depends on token lifetime, session state, step-up requirements, and a separately controlled break-glass path.

Control Plane unavailable

Existing authority may continue only within signed policy, evidence, and lease limits. New authority cannot be invented locally.

Signal or Relay unavailable

Existing direct paths may remain; new or relayed connectivity depends on the affected service and network condition.

Gateway node failed

Takeover is limited to eligible compatible nodes in the configured Failover Set; active-session behavior is mode-specific.

Configuration rollout failed

Rollout stops or restores a valid last-known-good version; Saved, Staged, Active, Partial, and Rolled Back remain distinct states.

Posture or audit evidence stale

Unknown or stale never becomes pass. The UI shows last observation, policy outcome, buffering, backpressure, and remediation.

Evaluate trust boundaries before individual features.

Continue with identity and credential inventory, signed desired state, failure behavior, privacy, and evidence quality.