Passwordless Multi-Service Access Through a Trusted Web Portal
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The cumbersome experience of logging into multiple web services with different credentials and the security risks associated with traditional username-password combinations and single sign-on systems are not adequately addressed by existing technologies.
Innovation Solution
A single trusted portal application on a user's device, authenticated with biometric or knowledge factors, generates and manages one-time codes for secure resource access, eliminating the need for dedicated passwords by integrating with a central identity provider and using QR codes or Bluetooth for authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional username and password authentication is used for each web service, then security is maintained for each individual service, but the login burden and complexity increase significantly
Solution Approach 1:
The patent introduces a trusted portal application as an intermediary between users and multiple web services. This portal generates time-limited access codes that mediate authentication, eliminating the need for users to directly manage multiple passwords while maintaining security through the portal's controlled access mechanism
Solution Approach 2:
The patent replaces the mechanical password-entry system with an automated code-generation system. Instead of manually entering passwords, the trusted portal application automatically generates and provides access codes through QR codes or other interfaces, substituting manual authentication mechanics with automated cryptographic processes
2Ease of operation
If single sign-on with one username and password is implemented, then login convenience is improved, but security risk increases as hackers can gain broad access by compromising one credential
Solution Approach 1:
The patent implements disposable, time-limited access codes generated by the trusted portal. Each code is valid only for a specific duration and purpose, replacing permanent passwords with short-lived credentials that lose value after use or expiration, thereby limiting the impact of credential compromise
Solution Approach 2:
The patent transitions from static passwords to dynamic, time-varying access codes. The credentials change over time and are tied to specific sessions or resources, making the authentication system adaptive rather than fixed, which prevents long-term compromise even if one code is intercepted
3Reliability
If multiple passwords are required for different web services, then security is maintained for each account, but the number of credentials to manage increases
Solution Approach 1:
The trusted portal application serves multiple functions: it authenticates users to numerous different web services, generates various types of access codes, and manages multiple accounts simultaneously. This single multi-functional tool replaces the need for users to manage multiple separate passwords across different services
Data Source
AI summary
Exemplary methods and systems described herein include using a single portal application for accessing a plurality of secure resources. The system and methods may use a second authentication application for selecting a desired secure resource and authenticating a user. The systems and methods may authenticate a user using different credentials for different secure resource without requiring the user to enter a unique credential for a given secure resource.


