Centralized Authentication Service for Multi-Site Password Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face difficulties in managing multiple usernames and passwords, leading to security vulnerabilities and high abandonment rates due to the complexity of remembering strong, unique passwords across various web sites.

Innovation Solution

A system that automatically generates unique, strong passwords for each network site, separates users from password management, and provides secure storage and retrieval through a centralized authentication management service, using knowledge-based questions and master passwords for access protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users manage multiple usernames and passwords manually, then they can access multiple network sites, but the complexity of remembering strong unique passwords increases and security vulnerabilities arise

Engineering Contradiction:
ImprovesecurityVSAvoidease of password management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an account management server as an intermediary between users and multiple network sites. This server stores credentials centrally and handles authentication automatically, eliminating the need for users to manually manage multiple passwords while maintaining security through centralized control and automatic credential distribution.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service authentication where the account management server automatically generates, stores, and distributes credentials to users and network sites without manual intervention. The server autonomously manages the credential lifecycle including generation, storage, distribution, and rotation, reducing user burden while maintaining security.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If users use the same username and password for multiple web sites, then ease of operation improves, but security vulnerabilities increase due to excessive abandonment rates

Engineering Contradiction:
Improveease of account managementVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the credential management system into distinct components: the account management server that generates and stores credentials, the users who consume credentials, and the network sites that verify them. This segmentation allows each component to perform its function optimally while maintaining security through centralized control at the server level.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The account management server provides universal authentication services across multiple network sites through a common protocol. It can serve multiple users and multiple network sites simultaneously, enabling single sign-on capability while maintaining unique credentials for each site through its multi-functional design.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If a centralized authentication management service is implemented, then security is enhanced and user experience is simplified, but device complexity increases

Engineering Contradiction:
Improveuser experienceVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts the complex credential management functionality from individual user devices and network sites, concentrating it in a dedicated account management server. This extraction simplifies the client devices and network sites while centralizing complexity in the server, which is designed to handle it.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP2810226B1Account management for multiple network sites
Publication Date: 2018.08.29 AMAZON TECH INC
  • EP2810226B1 patent drawingFigure 1
  • EP2810226B1 patent drawingFigure 2A
  • EP2810226B1 patent drawingFigure 2B

AI summary

Disclosed are various embodiments for account management for multiple network sites. Multiple accounts of a user are maintained for multiple network sites in a computing device. A secured resource of a network site is to be accessed by the computing device. A new account is created, or an existing account is upgraded, in response to determining that the accounts are not capable of accessing the secured resource. A set of information about the user is provided to the network site to create, or upgrade, the account.