Centralized Authentication Service for Multi-Site Password Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face difficulties in managing multiple usernames and passwords, leading to security vulnerabilities and high abandonment rates due to the complexity of remembering strong, unique passwords across various web sites.
Innovation Solution
A system that automatically generates unique, strong passwords for each network site, separates users from password management, and provides secure storage and retrieval through a centralized authentication management service, using knowledge-based questions and master passwords for access protection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users manage multiple usernames and passwords manually, then they can access multiple network sites, but the complexity of remembering strong unique passwords increases and security vulnerabilities arise
Solution Approach 1:
The patent introduces an account management server as an intermediary between users and multiple network sites. This server stores credentials centrally and handles authentication automatically, eliminating the need for users to manually manage multiple passwords while maintaining security through centralized control and automatic credential distribution.
Solution Approach 2:
The system enables self-service authentication where the account management server automatically generates, stores, and distributes credentials to users and network sites without manual intervention. The server autonomously manages the credential lifecycle including generation, storage, distribution, and rotation, reducing user burden while maintaining security.
2Ease of operation
If users use the same username and password for multiple web sites, then ease of operation improves, but security vulnerabilities increase due to excessive abandonment rates
Solution Approach 1:
The patent segments the credential management system into distinct components: the account management server that generates and stores credentials, the users who consume credentials, and the network sites that verify them. This segmentation allows each component to perform its function optimally while maintaining security through centralized control at the server level.
Solution Approach 2:
The account management server provides universal authentication services across multiple network sites through a common protocol. It can serve multiple users and multiple network sites simultaneously, enabling single sign-on capability while maintaining unique credentials for each site through its multi-functional design.
3Ease of operation
If a centralized authentication management service is implemented, then security is enhanced and user experience is simplified, but device complexity increases
Solution Approach 1:
The patent extracts the complex credential management functionality from individual user devices and network sites, concentrating it in a dedicated account management server. This extraction simplifies the client devices and network sites while centralizing complexity in the server, which is designed to handle it.
Data Source
Figure 1
Figure 2A
Figure 2B
AI summary
Disclosed are various embodiments for account management for multiple network sites. Multiple accounts of a user are maintained for multiple network sites in a computing device. A secured resource of a network site is to be accessed by the computing device. A new account is created, or an existing account is upgraded, in response to determining that the accounts are not capable of accessing the secured resource. A set of information about the user is provided to the network site to create, or upgrade, the account.