Centralized Web Password Management via Master Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional password management systems burden users with multiple usernames and passwords, are insecure due to local storage in weak encryption, and are vulnerable to phishing attacks, limiting access across different browsers and devices.

Innovation Solution

A system that stores usernames and passwords in a central database, accessible via a web browser or widget, requiring only a master password for access to multiple accounts, with additional security measures like fingerprint identification and SSL protocol to enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users store passwords locally in browser, then password management becomes convenient on that device, but security is compromised due to weak encryption and phishing vulnerabilities

Engineering Contradiction:
Improvepassword management convenienceVSAvoidpassword security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a server as an intermediary between the user and the websites. Instead of storing passwords locally in the browser, the system stores encrypted password data on a secure server. The server acts as a mediator that provides authentication services without exposing the actual passwords to the user's local device or the websites, thereby resolving the contradiction between convenience and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If users manage multiple usernames and passwords locally, then access to multiple websites is enabled, but the complexity of managing multiple credentials increases

Engineering Contradiction:
Improveaccess to multiple websitesVSAvoidcredential management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges multiple username-password credential pairs into a single centralized authentication system. Instead of managing separate credentials for each website, the system combines all authentication data into one secure storage location on the server. The user interacts with a single interface to access multiple websites, eliminating the need to manually manage multiple credentials and reducing complexity.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If users enable browser password protection with master password, then local password security is improved, but usability is reduced due to additional authentication steps

Engineering Contradiction:
Improvelocal password securityVSAvoidlogin convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary authentication by storing encrypted password data on the server in advance. When the user needs to access a website, the authentication has already been prepared and stored securely. The user only needs to provide a single master password to the system, which then automatically retrieves and uses the pre-prepared authentication credentials, eliminating the need for repeated authentication steps while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10341334B2Web based system that allows users to log into websites without entering username and password information
Publication Date: 2019.07.02 GOOGLE LLC
  • US10341334B2 patent drawing
  • US10341334B2 patent drawing
  • US10341334B2 patent drawing

AI summary

Internet user passwords are securely managed. A formation component can enable a user to create a master account on a web server, the master account comprising a master username and password. An access component can enable the user to access a plurality of password protected websites from a web browser or non-browser software application resident on the user's computing device when the user logs into the master account by entering the valid master username and password. A selection component can log the user into a website of the plurality of password protected websites when the user selects a hyperlink associated with the website, selects a linked image associated with the website, or selects the website from a pulldown list contained in a toolbar of a web browser. A display component can open a web browser or tab associated with the website.