A trust authorization layer (TAL) system and method thereof
Patent Information
- Application Number
- TW114145881
- Authority / Receiving Office
- TW · TW
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2025-11-25
- Publication Date
- 2026-09-01
- Estimated Expiration
- 2045-11-24
Smart Images

Figure TWG2TB001909112_001 
Figure TWG2TB001909112_002 
Figure TWG2TB001909112_003
Abstract
Claims
1. A trust authorization layer system that does not require adding a new server or database, but is deployed on an existing authorization server using a zero-exposure software development kit (SDK) layer. The SDK layer listens for authorization events on the authorization server and generates an event hash based on the event, with the original event data remaining within the security domain of the existing authorization server. The system comprises: a zero-exposure key isolation layer (ZEKI) coupled to a hardware security module (HSM) for generating a temporary key for the authorization event and destroying the temporary key upon receiving a revocation command; and a dynamic time consensus layer (DTC) for requesting timestamps from multiple independent time sources. The system is characterized by signing and aggregating to generate a time anchor; and a Merkle Playback Index (MRI) layer for attaching an authorization packet containing the event hash, the time anchor, and a status code to an append-only log protected by a Merkle tree; the system includes a quality gate module that performs self-checks according to predefined security rules, and triggers a preset shutdown mechanism when it detects that the aggregation delay of the dynamic time consensus layer exceeds a first time threshold or the response time of the hardware security module exceeds a second time threshold, so as to set the status of the authorization packet to a terminated state and anchor an exception event record containing an exception event code to the append-only log.
2. The system as described in Request 1, wherein the time anchor contains metric data sufficient to enable a third party to reconstruct and verify the aggregation operation in an offline environment.
3. The system as described in claim 1, wherein the authorization packet is digitally signed using a post-quantum cryptographic signature algorithm.
4. The system as described in claim 1, wherein after the zero-exposure key isolation layer destroys the temporary key, it generates an epitaph record and anchors the record to the append-only log for an offline playback verification program to audit the revocation status of the key, wherein the epitaph record includes at least: a packet identifier, an empty key check value or an invalidation flag, a timestamp and a revocation reason code.
5. The system as described in claim 4, wherein anchoring the epitaph record includes incorporating a hash value of the epitaph record into the hash calculation of a subsequent node in the append-only log.
6. The system as described in Request 1, wherein the Merkel replay index layer supports an offline replay verification procedure that verifies the integrity of the append-only logs without connecting to the authorized server, and the procedure includes sequentially calculating chain node hashes and comparing them with expected values to detect any deletions or replays.
7. The system as described in claim 6, wherein the offline playback verification procedure further includes, for each node in the append-only log, verifying a digital signature of the authorization packet, verifying the validity of the time anchor using the indicator data, and verifying the existence and validity of a corresponding epitaph record if the status code indicates that it has been revoked.
8. The system as described in claim 1 further includes a regulatory compliance verification layer for automatically generating a structured file that maps technical control measures to corresponding financial regulatory provisions.
9. A trust authorization layer method that, without requiring the addition of a new server or database, is executed on an existing authorization server as a software development kit (SDK) module, the method comprising the steps of: (a) listening to authorization events and calculating event hashes to ensure that the original event data is hashed without leaving the server's security domain; (b) instructing a hardware security module to generate a temporary key; (c) requesting timestamps from multiple independent time sources and aggregating the timestamp tokens using a verifiable hash aggregation function to generate a time anchor that can be verified offline; (d) constructing a structure containing event hashes and... (e) Authorize the time anchor and sign it using a cryptographic algorithm; (f) Attach the signed packet to an append-only log protected by a Merkle tree; (g) Perform a quality gate self-test procedure, which includes comparing whether the time anchor aggregation delay exceeds a first time threshold and whether the hardware security module response time exceeds a second time threshold; and (g) Based on the self-test result, if the thresholds are not exceeded, continue authorization, or if either of the thresholds is exceeded, trigger a preset shutdown mechanism and anchor an exception event record containing an exception event code to the append-only log.
10. The method as described in claim 9, wherein the time anchor contains metrics data sufficient to enable a third party to reconstruct and verify the aggregation operation in an offline environment.
11. The method as described in claim 9 further includes, upon receiving a revocation instruction, instructing the hardware security module to destroy the temporary key and recording a destruction certificate (epitaph record) in the append-only log for offline auditing of the revocation status of the key, wherein the epitaph record includes at least: a packet identification code, a blank key check value or an invalidation flag, a timestamp and a revocation reason code.
12. The method as described in claim 11, wherein the step of recording the epitaph record includes incorporating a hash value of the epitaph record into the hash calculation of a subsequent node in the append-only log.
13. The method as described in claim 9, wherein the authorization packet can be replayed and verified in an offline environment without relying on a network connection, and the verification includes sequentially calculating chain node hashes and comparing them with expected values to detect any deletions or replays.
14. The method as described in claim 13, wherein the verification step further comprises, for each node in the append-only log, verifying a digital signature of the authorization packet, verifying the validity of the time anchor using the indicator data, and verifying the existence and validity of a corresponding epitaph record if the status code indicates that it has been revoked.
15. A nontransitory computer-readable storage medium having stored thereon computer program instructions that, when executed by a processor, can perform the method as described in any one of claims 9 to 14.
16. The system as described in Request 1, wherein the authorization packet is generated according to a predetermined fixed field order, and if any field is missing or out of order, the quality gate module triggers the preset shutdown mechanism and outputs a downgrade scepter containing reason_code, timestamp_src and nonce, and records it in the append-only log.
17. The system as described in Request 1, wherein the authorization packet contains an ai_defense_status field, and when the field indicates dual_sign_required=true, the system requires a second independent signature; if the second independent signature is not satisfied, the quality gate module triggers the preset closing mechanism and records an r_check_mask in the proof.meta.
18. The system as described in Request 1, wherein the trust authorization layer must complete an offline reconstructable verification association check of access evidence, decision evidence and system consistency indicators before authorization; when any association is not established or the time anchor aggregation does not meet the minimum requirements, authorization is terminated and a replayable downgrade scepter is generated.
19. The system as described in Request 1, wherein the encapsulation of access evidence adopts fixed fields and a fixed order, the decision evidence includes a verifiable model and feature summary, the system consistency index is represented by version and state hashes, and the hash binding of the three constitutes a necessary condition for authorization decision.
Citation Information
Patent Citations
Single-packet multi-level authentication method based on zero trust
CN115776408A
A method and apparatus for implementing a zero-trust security gateway based on a blockchain structure
CN115987696B
Internet of Things data security communication method and system, and computer readable storage medium
CN116346505A
System and method for monitoring and suspending smart contracts
US20250182102A1