One engine,
three products

On top of BSA — an authentication engine that stores no password — sit desktop sign-in and unified credential management. They run on the infrastructure you already have.

See how the login works

The fourth generation of authentication

A structure that establishes trust with no password, no central server and no master key — a pipeline that leaves nothing behind, from material to ledger.

See how the login works

For environments that demand strong security

For the core systems of finance, government and enterprise — meeting regulatory duty and user experience at the same time.

Talk to us
Authentication technology adopted as an ITU-T standard

There is no password
to steal

Every login generates a fresh one-time key of 300+ characters and destroys it the moment authentication ends.
With no secret in storage, the attack surface for theft and credential stuffing is simply not there.

Hybrid DLT · randomised distributed verification

Trust is never
kept in one place

Multiple randomly selected nodes verify at the same time, and the result is recorded across the Public and Private Chains.
Nothing rests on a single point, so there is no centre for an attacker to seize.

ITU-T X.1284 · X.1286 · Common Criteria EAL2

The world recognised it first
as an international standard

The ITU, the United Nations agency for telecommunications, adopted the BSA technology as an international standard.
Patents in 8 countries and a presence in 57 carry that competitiveness into world markets.

01 / 03
SCROLL
BSA · VERIFIED BY
ITU-T X.1284UN-body international standardITU-T X.1286UN-body international standardTTAK.KO-12.0411Established as a national standardCommon Criteria EAL2ISO/IEC 15408OIC-CERT 2021Global cybersecurity grand prizePatents in 8 countriesKorea, USA, UK, China, Japan and more57 countriesGlobal reach
The Problem

The safer it gets,
the more inconvenient it gets

Every extra layer of security is one more step for the user.
And most authentication still comes down to guarding a single stored secret.

01

Second and third factors, over and over

One login means an SMS, an app approval, a security card. More layers, but the same point still gives way.

02

Long, complicated passwords

Sixteen characters of upper case, lower case, digits and symbols. Nobody remembers it, so it ends up written down somewhere.

03

Scheduled password resets

A change-every-90-days policy satisfies the rulebook. It does not remove what has already leaked.

04

More and more ways to authenticate

Certificates, OTPs, security tokens — devices to carry and certificates that expire. The cost of managing all of it lands on the organisation.

No more awkward authentication.
Simpler and safer, without a password.

SIG ONE does not block attacks one at a time. It structurally removes the two premises every attack depends on — the fixed credential and the single verification point.

Live Walkthrough

So — how does the login actually work?

If no password is used, what actually proves who the user is? It is the question we hear most.
Here is that average 2.4-second authentication, laid out in 8 steps.
Played back slower than real time so it can be followed.

The BSA authentication pipeline — MIRC · OTAK · MDV · Hybrid DLT
Request → Verify → Consensus → GrantWhile the user touches the fingerprint sensor once, the four-layer chain of trust (MIRC · OTAK · MDV · Hybrid DLT) runs in sequence in the background. The 8 steps below complete in an average of 2.4 seconds.MIRCOTAKMDVHYBRID DLT
09:41
Sign in

Just your ID is enough.

There is no password field

With no stored secret, there is nothing to ask for
Sign in without a password
Secured by SIGONE · BSA
Processing the request
Public Chain received
Verify your identity
The data never leaves the device
Fingerprint · Face · PIN
Authenticated
Authenticated without typing a password
Avg 2.4s · error rate 0.02%
OTAK discarded right after use
0.0s
01
Enter only your IDINPUT0.0s

A login screen running SIGONE has no password field. There is no stored password to ask for in the first place.

02
The Public Chain receives the authentication requestREQUEST0.2s

The Public Chain receives the authentication request and hands it to the Private Chain. No password and no fixed secret travels through this step.

03
Authentication factors are recombined for every requestMIRC0.6s

A new combination is composed for every request out of separate authentication factors — registered handset, device, location, knowledge and biometrics. Even the same user never repeats a fixed combination.

No storageNo fixed combination
04
A one-time key of 300+ characters is generatedOTAK1.1s

From the newly composed factors a one-time key of 300+ characters is generated. The key exists only for that one request and is discarded when authentication ends.

Discarded right after authenticationCannot be reused
05
One authentication. That is allBIOMETRIC1.6s

This is where the user's part ends. The data itself is never transmitted off the device; only the verification result needed for authentication moves on to the next step.

Biometric never leaves the device
06
Random nodes verify simultaneouslyMDV2.0s

The nodes that take part are selected at random for every request. The selected nodes verify the authentication data in parallel and confirm the result under the consensus rules. Verification authority never concentrates in one single node.

No single verification point
07
The result is recorded on a distributed ledgerHYBRID DLT2.3s

The result is written to a distributed ledger, so any forgery or tampering can be verified afterwards. It gives you the basis to trace and audit the authentication history.

Distributed recordAuditable afterwards
08
Access granted, and the key disappearsGRANTED2.4s

Once the access grant reaches the service, authentication is complete. The OTAK that was used is discarded at once, and the next authentication generates a new combination and a new key. An authentication key that has been used cannot be used again.

Used key discarded at onceCannot be reused
Why SIGONE

The fourth generation of authentication:
blockchain-based passwordless

We resolve the structural limits of existing authentication.
Authentication is safer and faster with no password, no central server and no master key.

Multi-factor passwordless authentication — face, fingerprint, device, behaviour, context
What proves who you areNot one password but several authentication factors — possession, device, location, biometrics —
are combined afresh for every request, so nothing rests on a single fixed credential.
FACEFINGERPRINTDEVICEBEHAVIORCONTEXT

Fully passwordless

Passwords are not hidden or replaced —
no fixed password is stored at all.
Each authentication uses a new value.

Distributed verification

Verification authority is never concentrated in one place.
Several randomly selected nodes verify in parallel,
lowering reliance on any single point of verification.

2.4-second authentication

The user authenticates only once.
The process finishes in 2.4 seconds on average,
raising security and convenience together.

Standards & verification

Adopted as an ITU-T international standard,
Common Criteria EAL2,
and an OIC-CERT Global Award —
a record of international recognition.

Mechanism

A four-layer chain of trust
that leaves nothing behind

Material → key → verification → record. Each stage uses only what it needs and leaves behind no reusable credential.
It is a one-way structure: no secret from one stage is handed to the next.

LAYER 01MIRCFactors · random combination
LAYER 02OTAKOne-time key · built then destroyed
LAYER 03MDVDistributed verification · multi-node consensus
LAYER 04Hybrid DLTAuthentication result · distributed record
The SIGONE cube — public, hybrid and private DLT with the four-layer chain of trust
Factors → one-time key → distributed verification → recordThe public chain receives the request; the private chain generates the key and runs verification.
The two chains divide the roles and complete each other across the whole process.
PUBLIC DLTHYBRID DLTPRIVATE DLT
LAYER 01 · FactorsMIRC

Combine multiple authentication factors at random
to build a new combination for every request

For each request a subset is selected and combined from distinct factor sets — possession, device, location, knowledge and biometrics.
Even for the same user the combination differs request to request, so nothing depends on a fixed credential.

No storage

No fixed credential is kept

LAYER 02 · One-time keyOTAK

Generate a one-time key for every request
and destroy it the moment authentication ends

A one-time key of more than 300 characters is generated and used for that request alone.
Once authentication completes it is destroyed at once and is never reused by a later request.

One-time key

Destroyed right after authentication

LAYER 03 · Distributed verificationMDV

Several randomly selected nodes
verify at the same time and reach consensus

Verification authority is not concentrated in one place; several nodes are drawn at random for every request.
The selected nodes verify in parallel and settle the result by the consensus rule.

Distributed verification

No single point of verification

LAYER 04 · Distributed recordHybrid DLT

Public and private chains divide the roles
The result is recorded on a distributed ledger

The public chain and private chain share the work and record the process and its outcome.
The distributed record keeps the authentication history traceable and checkable after the fact.

Distributed record

Traceable history · checkable afterwards

0sAverage authentication time
0%Authentication error rate
0Patents held
0Global reach
International Standards

Proven by international standards
and independent verification

You cannot see for yourself how trustworthy a security technology is.
SIGONE proves its technology through international standards and third-party verification, not its own claims.

VERIFIED ITU-T · UN international standard

Adopted as an ITU-T standard

The International Telecommunication Union (ITU) is the UN agency for information and communication technology. The core of BSA was adopted as an ITU-T international standard and is formally part of the global standards framework.

Read X.1284 ↗ Read X.1286 ↗ Approved Apr 2025 · Jun 2026
VERIFIED TTA · National standard

Korean national standard
TTAK.KO-12.0411

It was established as a national standard by the Telecommunications Technology Association (TTA), so alongside the international standards it is formally part of Korea's ICT standards framework.

Read the standard ↗ Established Dec 2024
VERIFIED OIC-CERT · 2021

OIC-CERT Global Award

The technology was recognised at the 2021 Global Cybersecurity Award run by OIC-CERT, the international cybersecurity cooperation body.

OIC-CERT Award 2021
VERIFIED Common Criteria · EAL2

International security evaluation
ISO/IEC 15408

Common Criteria is the international information-security evaluation scheme based on ISO/IEC 15408. SIGONE achieved an EAL2 evaluation under it.

Evaluation Assurance Level 2
VERIFIED Patents · 8 Countries

Patents in 8 countries

Patents on the core technology are registered in eight countries including Korea, the United States, the United Kingdom, China and Japan, securing a global basis for rights protection.

Korea · USA · UK · China · Japan and 3 more

Technology confirmed by standards and verification.
Now see the evidence for yourself.

Full records of the standards, certifications,
awards and patents — with the source documents.

A single phone becomes a verification node and joins the distributed network
It runs on the infrastructure you already haveLeave core banking and your legacy systems as they are, and connect through the REST API and SDKs.REST APIiOS · Android SDKSSO
Enterprise

Authentication for environments
that demand strong security

Bring SIGONE to the core systems of a bank, a public body or an enterprise. Keep the infrastructure you already run and extend authentication through the API and SDKs.

  • About two to three months from requirements to launch
  • Your side of the team · 1-2 developers plus 1 planning lead
  • A parallel integration, kept separate from the core system

Finance · payment authentication

From sign-in to payment authentication and transfer approval, with no password anywhere.

  • Live references at first-tier banks
  • Authentication rooted in device integrity
  • Works across mobile environments

Government · public services

Citizen authentication and access to public services, safely and without a password.

  • Common Criteria EAL2
  • On-premise deployment in air-gapped networks
  • Integrates with public authentication infrastructure

Zero trust · VPN

Every request for VPN or internal system access is verified, tightening enterprise access control.

  • Continuous verification on every request
  • SSO and directory integration
  • Access rights withdrawn from lost devices

Electronic signature · document security

Electronic signatures, and the access history of sensitive documents, kept in a form you can verify.

  • Authentication records on the Hybrid DLT
  • Access history can be checked afterwards
  • No biometric original, no fixed password stored
Zero Trust

Trust is never granted once.
Every point of access is verified.

Trusting one login for the rest of the day is useless against an account that has already been taken.
SIGONE verifies again at every access point — user, device, behaviour, data, cloud —
and settles the outcome by consensus among distributed nodes.

  • USER
  • DEVICE
  • BEHAVIOR
  • DATA
  • CLOUD
Video

Passwordless authentication,
understood in a minute

Why authentication without a password matters — the essentials, in short films.

Deployment

Two ways to adopt it

A cloud subscription to start quickly, and a self-hosted build for air-gapped or large-scale environments.
Two ways to adopt it, whichever fits how you operate.

CLOUD

Subscription

Per user · monthly subscription

Passwordless authentication delivered as SaaS, live quickly. Nothing to build and no infrastructure to stand up.

  • Three-stage BSA authentication (device · distributed verification · biometric)
  • Passwordless sign-in · MFA
  • Admin dashboard and user management
  • iOS and Android SDKs included
  • Email technical support
Ask about Cloud
Recommended ON-PREMISE

Self-hosted

Site licence · unlimited apps

A self-hosted build for air-gapped networks, regulated industries and large organisations, shaped around your security policy and the way you operate.

  • On-premise installation, unlimited apps
  • SSO and directory integration
  • Electronic signature and VPN access control
  • Dedicated SLA · 24/7 support · named account manager
  • Custom integration and compliance consulting
Ask about On-Premise

Every plan is quoted individually after we understand your environment.

Contact Us

Eliminate passwords, today

Contact us and our specialists will design an authentication architecture tailored to your environment.

  • Reply within 1–2 business days
  • Tailored authentication design
  • NDA available on request
or
Message us on Instagram