For security & IT professionals
A control‑plane approach to Wi‑Fi access.
Tagnect is not another inline appliance. It orchestrates the network controller you already run — via its native API — while the data path stays untouched. Less attack surface, no choke point, no lock‑in.
Control plane vs. data plane
Orchestration, not interception
Tagnect's server never carries user traffic and is never an inline bottleneck. It makes access decisions and drives your controller (UniFi, Omada, Meraki, SmartZone, and others) through native APIs.
- Zero lock‑inSwap network hardware and keep all your Tagnect access intelligence.
- No inline choke pointTraffic never routes through Tagnect, so there's no single box to overload or own.
- Hardened administrationOperator access uses JWT + MFA/TOTP + IP allow‑list, with an append‑only audit ledger.
Identity from the network, not the app
Device identity without trusting the app
The local connector derives the device identity from the network itself: it resolves IP→MAC through the controller and signs the result with an HMAC‑SHA256 identity ticket. The client app never self‑declares its MAC address, so identity can't be spoofed by a tampered client.
- Network‑derived identityIP→MAC is resolved by the controller the venue already trusts — not asserted by the phone.
- Signed, outbound‑onlyThe connector opens only outbound connections and signs each identity proof; no inbound port is exposed at the venue.
Patent pending — Application BR 10 2026 017581‑1
The inventive core
Temporal credential table on a passive tag
Time‑block passwords are stored on the NFC tag and selected offline by the client — in explicit, aperiodic or periodic modes for maximum memory compaction.
Server‑side cross‑validation of tag, generation and time context
The server validates the registered UID, generation nonce, group/block context and server‑side time window, together with the signed device identity proof. On supported managed controllers, association with the current credential can initially place the device in a restricted state until this validation completes.
In‑segment state promotion
On supported managed controllers, the device can connect in a restricted state; after IP→MAC cross‑validation via the controller API, it's promoted in bandwidth/session while keeping the same IP link — no VLAN swap, no IP drop.
Delegated pair‑device provisioning
A device without NFC (laptop/desktop) receives a single‑use activation key from an already‑validated phone, creating a distinct virtual identity — without polluting the tag UID's security limits.
On Tagnect Ready / OpenWRT deployments, the current implementation relies primarily on credential rotation, expiration and deauthentication; fine‑grained per‑device traffic promotion and profile enforcement depend on a managed controller and are part of the roadmap.
Architecture comparison
Tagnect vs. traditional captive portals / MPSK
A factual, architecture‑level comparison — not a benchmark of any specific product.
| Layer / capability | Traditional captive portal / MPSK | Tagnect |
|---|---|---|
| Onboarding vector | HTTP / captive portal — exposed to phishing & cloning | NFC Direct binary tap — no web portal |
| Traffic architecture | Inline / appliance in the data plane | Out‑of‑band, vendor‑agnostic control plane |
| Password rotation | Manual, or static per‑user MPSK | Dynamic by time block, selected offline on the client |
| Credential leak impact | Exposed and reusable | Time‑scoped: expires after its block; on managed controllers, opens only a restricted state until validated |
| Hardware coupling | Tied to the vendor's appliance | Works across controllers — no lock‑in |
Threat mitigation — a real case
Hospitality Wi‑Fi & DNS poisoning
Threat research has documented compromised hotel and conference‑center Wi‑Fi gateways — likely accessed through exposed management interfaces — being used for DNS poisoning, forged captive portals and credential or token theft. The tradecraft was assessed as similar to earlier APT28‑linked router campaigns, including FrostArmada, but the hospitality activity was not directly attributed to APT28.
Where Tagnect closes the door
- Kills the captive portalNo web login page for the user to type into — the credential‑phishing vector disappears.
- Removes weak admin panelsManagement runs under JWT, MFA/TOTP and IP allow‑list — not an exposed gateway login.
- Devalues stolen credentialsRotating, time‑scoped passwords; on managed controllers they alone grant only a restricted state until validated.
Honest scope: Tagnect does not route user traffic, so it does not replace endpoint/transport defenses (VPN, DNS‑over‑HTTPS, certificate validation, disabling device‑code auth) against a gateway that is already fully compromised. It is complementary — it removes the onboarding, credential and admin surfaces the attack relies on.
Want the technical deep‑dive?
We're happy to walk your team through the validation flow (IP→MAC via API, with no data traffic on the Tagnect server).