One-Time Signature Generation for HSM-Based Data Provenance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional hardware security modules (HSMs) are inefficient, vulnerable, and unable to scale with emerging technologies like distributed ledger technology (DLT), lacking industry-standard certifications and secure key management, leading to compromised security and operational inefficiencies.
Innovation Solution
A system and method for generating one-time signatures using a secure environment that coordinates multiple HSMs, deriving keys from seeds mapped to accounts, and providing one-time signatures through API calls, ensuring secure and scalable key management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If keys are imported into HSM, then security is improved, but device complexity and operational inefficiency increase due to partitioning requirements
Solution Approach 1:
The system segments key management by organizing HSMs into hierarchical groups (first-level groups, second-level groups) where each group manages specific key types or organizational units. This segmentation allows parallel operation of multiple HSMs without requiring complex partitioning within each device, resolving the contradiction between security and complexity.
Solution Approach 2:
The HSM system is designed with universal interfaces and standardized key management protocols that allow the same HSM architecture to serve multiple purposes (different key types, different organizations, different cryptographic operations) without requiring custom partitioning configurations, thereby reducing device complexity while maintaining security.
2Ease of operation
If keys are stored on local devices, then ease of operation is improved, but security vulnerability increases
Solution Approach 1:
The system introduces local key agents as intermediaries between end devices and the centralized HSM infrastructure. These agents enable convenient local key operations (signing, encryption) while maintaining security by keeping private keys protected in the HSM and only sharing derived public keys or signatures locally, thus resolving the contradiction between ease of operation and security vulnerability.
3Adaptability or versatility
If conventional HSMs are used for DLT, then operational security is compromised, but scalability is improved
Solution Approach 1:
The system changes the operational parameters of HSMs by implementing standardized key derivation functions, hierarchical group structures, and configurable key policies that are specifically optimized for DLT operations. These parameter changes enable DLT compatibility while maintaining security through controlled key generation and management processes, resolving the contradiction between adaptability and operational security.
4Productivity
If HSMs are made reusable and scalable, then productivity is improved, but device complexity increases
Solution Approach 1:
The system segments the HSM infrastructure into independent, reusable modules organized in hierarchical groups. Each HSM can be independently configured, deployed, and reused across multiple applications and organizations through standardized interfaces. This segmentation enables scalability and reusability without increasing individual device complexity, as each HSM operates autonomously within its defined scope.
Data Source
AI summary
Presented herein are system and methods for establishing data provenance by generating one-time signatures. A system may include one or more processors that receive, via an application programming interface (API) request, a request for a one-time signature and data associated with the request, provide a seed identifier and the data associated with the request to an HSM in a set of HSMs, and receive a response message from the HSM, the response message including a one-time signature. In examples, the response message and the one-time signature are provided to the device that transmitted the request for the one-time signature and the data associated with the request. Methods and non-transitory computer-readable mediums are also presented.


