One-Time Signature Generation for HSM-Based Data Provenance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional hardware security modules (HSMs) are inefficient, vulnerable, and unable to scale with emerging technologies like distributed ledger technology (DLT), lacking industry-standard certifications and secure key management, leading to compromised security and operational inefficiencies.

Innovation Solution

A system and method for generating one-time signatures using a secure environment that coordinates multiple HSMs, deriving keys from seeds mapped to accounts, and providing one-time signatures through API calls, ensuring secure and scalable key management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If keys are imported into HSM, then security is improved, but device complexity and operational inefficiency increase due to partitioning requirements

Engineering Contradiction:
ImprovesecurityVSAvoidHSM partitioning complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments key management by organizing HSMs into hierarchical groups (first-level groups, second-level groups) where each group manages specific key types or organizational units. This segmentation allows parallel operation of multiple HSMs without requiring complex partitioning within each device, resolving the contradiction between security and complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The HSM system is designed with universal interfaces and standardized key management protocols that allow the same HSM architecture to serve multiple purposes (different key types, different organizations, different cryptographic operations) without requiring custom partitioning configurations, thereby reducing device complexity while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If keys are stored on local devices, then ease of operation is improved, but security vulnerability increases

Engineering Contradiction:
Improvekey accessibilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system introduces local key agents as intermediaries between end devices and the centralized HSM infrastructure. These agents enable convenient local key operations (signing, encryption) while maintaining security by keeping private keys protected in the HSM and only sharing derived public keys or signatures locally, thus resolving the contradiction between ease of operation and security vulnerability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If conventional HSMs are used for DLT, then operational security is compromised, but scalability is improved

Engineering Contradiction:
ImproveDLT compatibilityVSAvoidoperational security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system changes the operational parameters of HSMs by implementing standardized key derivation functions, hierarchical group structures, and configurable key policies that are specifically optimized for DLT operations. These parameter changes enable DLT compatibility while maintaining security through controlled key generation and management processes, resolving the contradiction between adaptability and operational security.

Inventive Principle:
Principle #35Parameter changes

4Productivity

If HSMs are made reusable and scalable, then productivity is improved, but device complexity increases

Engineering Contradiction:
Improvekey management efficiencyVSAvoidHSM architecture complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system segments the HSM infrastructure into independent, reusable modules organized in hierarchical groups. Each HSM can be independently configured, deployed, and reused across multiple applications and organizations through standardized interfaces. This segmentation enables scalability and reusability without increasing individual device complexity, as each HSM operates autonomously within its defined scope.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250293891A1Systems and methods for establishing data provenance by generating one-time signatures
Publication Date: 2025.09.18 CITIGROUP TECHNOLOGY INC
  • US20250293891A1 patent drawing
  • US20250293891A1 patent drawing
  • US20250293891A1 patent drawing

AI summary

Presented herein are system and methods for establishing data provenance by generating one-time signatures. A system may include one or more processors that receive, via an application programming interface (API) request, a request for a one-time signature and data associated with the request, provide a seed identifier and the data associated with the request to an HSM in a set of HSMs, and receive a response message from the HSM, the response message including a one-time signature. In examples, the response message and the one-time signature are provided to the device that transmitted the request for the one-time signature and the data associated with the request. Methods and non-transitory computer-readable mediums are also presented.