One engine,
three products

On top of BSA — an authentication engine that stores no password — sit desktop sign-in and unified credential management. They run on the infrastructure you already have.

See how the login works

The fourth generation of authentication

A structure that establishes trust with no password, no central server and no master key — a pipeline that leaves nothing behind, from material to ledger.

See how the login works

For environments that demand strong security

For the core systems of finance, government and enterprise — meeting regulatory duty and user experience at the same time.

Talk to us
Technical Whitepaper

How trust holds
without a password

How SIGONE's BSA — Blockchain Secure Authentication — establishes trust without any stored secret such as a password, an OTP or a token, and how the four-layer chain of trust works.

Summary

In brief

BSA does not rely on a stored secret. Trust is established through one-time material and keys — created fresh for every authentication and destroyed immediately — plus distributed verification by multiple randomly selected nodes. The one-way chain of trust runs material (MIRC) → key (OTAK) → verification (MDV) → ledger (Hybrid DLT): each stage consumes what the previous one produced and leaves nothing behind. There is no asset to steal and no single point to seize.

LAYER 01MIRCFactors
LAYER 02OTAKOne-time key
LAYER 03MDVDistributed verification
LAYER 04Hybrid DLTDistributed record
Background and the problem

Every attack on authentication starts
from two structural premises

Rather than blocking each attack technique in turn, BSA sets out to remove from the structure the premises they all rely on.

Weak point 01

A fixed credential exists

So long as a fixed asset exists that can be stored, reused or stolen — a password, a key — the attacks below keep working.

Attacks this enables · Phishing · credential stuffing · password database theft · man-in-the-middle replay

Weak point 02

A single verification point exists

When verification concentrates at one point, seizing that single point is enough to control every authentication result.

Attacks this enables · Verification server compromise · insider tampering · single point of failure

Design principles

Create nothing worth stealing
Never place trust in one point

Principle 01 · Create nothing worth stealing

No fixed asset is left behind to store, reuse or steal. Material is combined at random for every request (MIRC), and the key is generated per request and destroyed at once (OTAK).

Principle 02 · Never place trust in one point

Verification and recording are distributed so that seizing one point cannot decide the whole outcome. Multiple random nodes rule by consensus (MDV), and the record is split across public and private chains (Hybrid DLT).

Mechanism

Four-layer chain of trust

Factors → one-time key → distributed verification → record. Each stage uses only what it needs, and no secret is handed from one stage to the next — a one-way structure.

LAYER 01 · FactorsMIRC

Combine multiple authentication factors at random
to build a new combination for every request

For each request a subset is selected and combined from distinct factor sets — possession, device, location, knowledge and biometrics. Even for the same user the combination differs request to request, so nothing depends on a fixed credential.

No storage

No fixed credential is kept

LAYER 02 · One-time keyOTAK

Generate a one-time key for every request
and destroy it the moment authentication ends

A one-time key of more than 300 characters is generated and used for that request alone. Once authentication completes it is destroyed at once and is never reused by a later request.

One-time key

Destroyed right after authentication

LAYER 03 · Distributed verificationMDV

Several randomly selected nodes
verify at the same time and reach consensus

Verification authority is not concentrated in one place; several nodes are drawn at random for every request. The selected nodes verify in parallel and settle the result by the consensus rule.

Distributed verification

No single point of verification

LAYER 04 · Distributed recordHybrid DLT

Public and private chains divide the roles
The result is recorded on a distributed ledger

The public chain and private chain share the work and record the process and its outcome. The distributed record keeps the authentication history traceable and checkable after the fact.

Distributed record

Traceable history · checkable afterwards

Proof that the security holds

Against four threats:
structural defence

BSA's defence rests on structure, not probability. For an attack to work it would need an asset or a point that does not exist.

Against forgery

Forging the material would mean matching possession, device, location and knowledge or biometric conditions all at once — plus the random combination drawn at that exact request. Securing one factor is worthless without the rest and that moment's combination.

Against replay

The key lives only for the span of one request. By the time an attacker has it, it is already destroyed and the next request uses a different one. There is nothing to reuse.

Against tampered verification

Verification is distributed across multiple randomly chosen nodes. No node can be named in advance or decide the result alone, and partial control is nullified by consensus.

Non-repudiation

The result is preserved as an immutable, transparent Hybrid DLT record, so the fact of authentication can be checked and proven later. Neither the biometric original nor a fixed password is ever stored.

Ready to start
a technical review?

Detailed specifications — consensus thresholds, key length, cryptographic algorithms, entropy sources — are supplied separately as a technical specification on request for security review.