Trust, Risk & Security Capability · TRS-MS

KeyMESH

KeyMESH is the sovereign cryptographic nervous system of the Trust, Risk & Security Management System (TRS-MS). Operating on a "Fortress and Field" hub-and-spoke trust architecture, it decouples high-level commercial intent from low-level mathematical implementation. By governing Remote Key Injection (RKI), TR-31/TR-34 key encapsulation, and Distributed Fragment Cryptography (DFC), KeyMESH enables policy-driven crypto-agility and eliminates static master secrets across shared physical appliances.

Target Architecture (Q4 2026 Roadmap) Target Latency: < 100 µs SIMD Adjudication · Zero Persistent Edge Master Secrets
KeyMESH Architecture Illustration
Introduction

Policy-Driven Cryptographic Agility & The Sovereign Trust Fabric

The KeyMESH serves as the modular, policy-driven cryptographic routing nervous system of the onePOI.online ecosystem. Traditional computing models hardcode cryptographic libraries directly into client applications, resulting in costly, months-long code refactoring cycles whenever algorithms must be upgraded. KeyMESH inverts this paradigm by completely abstracting mathematical execution from application logic.

To solve the Digital Public Infrastructure (DPI) Trilemma – balancing uncompromising security, hyperscale distribution, and hardware unit economics – KeyMESH deploys a "Fortress and Field" model. Centralised Master Root Keys reside exclusively in high-assurance Tier 1 Cloud HSMs ("The Fortress"), whilst edge POI terminals ("The Field") operate as completely empty vessels regarding static credentials. Ephemeral session keys are injected Just-in-Time (JIT) into hardware enclaves and shredded immediately upon transaction finality.

The Dual Commercial Promise

Engineered for Institutional Margins. Adopted for Human Sovereignty.

Every capability across the Salient Innovation Set delivers an immediate, symmetrical return: radical margin recovery for the enterprise tenant, paired with frictionless dignity and absolute cryptographic safety for the citizen.

Enterprise Economics · RevOps TENANT VALUE

How the Tenant Expands Margins

Transforming operating models from defensive cost centres into agile, shared revenue engines through multi-tenant pooling and mathematical compliance.

  • CapEx Pooling

    CapEx Pooling & No Single-Tenant Hardware

    POI Appliances run white-label on co-funded premises. Reach 50 commercial catchments without funding 50 proprietary branch builds.

  • Flat-Fee Clearing

    Zero Interchange & Flat-Fee Clearing

    Instant Account-to-Account rails (SEPA Instant / PayShap) bypass 1.5–3.5% card scheme tolls with predictable, flat sub-cent clearing fees.

  • Compliance by Construction

    Compliance by Construction

    Agreement DAGs enforce statutory mandates at wire speed; non-compliant states cannot execute, eliminating retrospective audit penalties.

  • Accelerated Onboarding

    Accelerated Partner Onboarding

    Pre-verified BIAN and ArchiMate capability components compress multi-firm integration cycles from quarters to days.

TARGET OPEX REDUCTION: 40–60% Q4 2026 ROADMAP
Customer Experience · RegOps CITIZEN TRUST

Why the Customer Loves Using It

Delivering sovereign dignity and verifiable security where users never surrender control over their identity, consent, or funds.

  • Nothing Stored to Steal

    Nothing Stored to Steal

    Credentials remain in the user's oneWallet. A breach of a merchant's server reveals zero identity records, protecting citizens completely.

  • One Pattern Everywhere

    One Pattern, Everywhere

    The same intuitive tap-and-confirm interaction works seamlessly at a high-street kiosk, transit hub, EV charger, or smartphone.

  • Delegated Authority

    Delegated Authority, Never Escalated

    Autonomous AI agents carry single-use, bounded warrants; an agent checking information cannot escalate its authority to transfer money.

  • Payments That Never Fail

    Payments That Do Not Fail

    When a payment network degrades, the transaction reroutes with authentication preserved – zero declines, zero repeated entries.

CITIZEN DATA EXPOSURE: ZERO EU eIDAS 2.0 / GDPR NATIVE
KeyMESH Runtime Manifest Icon

KeyMESH Runtime Manifest

Multi-Tenant Cryptographic Orchestrator

LAYER: TRS-MS // SYMPHONY
TARGET LATENCY: < 100 µs (Target State)
KEY ENCAPSULATION: ANSI X9.143 (TR-31)
RUNTIME DESCRIPTION: Distributed Fragment Cryptography (DFC) router managing Remote Key Injection (RKI), TR-34 asymmetric tunnels, and JIT enclave key release.

Commercial Sovereignty & Shared Phygital Infrastructure

In shared commercial environments – such as municipal kiosks, automated teller cash recyclers, and smart retail lockers – physical theft or endpoint tampering presents catastrophic liability. If static master keys reside on-disk, compromising one appliance compromises the entire tenant institution. KeyMESH eradicates this risk by ensuring edge hardware contains zero persistent cryptographic credentials.

As the cryptographic backbone of the Salient FinTech Innovation Set, KeyMESH natively integrates with BIAN v14 bare-metal service domains (Payment Execution, Party Authentication, Cryptographic Services) and real-time payment rails (SEPA Instant, FedNow, RTP, Discover/Pulse). Competing financial and civic institutions share unified physical appliances whilst maintaining absolute, mathematically enforced sovereign isolation.

Zero Edge Key Theft

Zero Edge Key Theft

If an appliance is stolen or drilled, the attacker captures empty silicon with no static credentials.

Zero-Truck-Roll Key Injection

Zero-Truck-Roll Key Injection

Automates Remote Key Injection (RKI) via TR-34 tunnels without requiring manual field technicians.

Multi-Tenant Key Curtaining

Multi-Tenant Key Curtaining

TR-31 usage tags cryptographically prevent Tenant A's software from misusing Tenant B's keys.

Post-Quantum Agility

Post-Quantum Agility

Hot-swaps classical ECC/RSA for NIST FIPS 203/204 PQC algorithms via simple Agreement DAG updates.

Architecture

The 4-Stage Industrial Cryptographic Supply Chain

KeyMESH governs the entire lifecycle of cryptographic secrets across edge and cloud infrastructure. From physical entropy harvesting to hardware-bound usage encapsulation, every stage adheres to rigorous international standards.

Stage 01 · Genesis
Entropy Mesh & EaaS

Entropy Mesh & EaaS

Eliminates edge "entropy starvation" at boot. Centralised Quantum Random Number Generator (QRNG) beacons supply cryptographically certified entropy seeds (NIST SP 800-90B) to initialise appliance cryptographic pools.

Standard: NIST SP 800-90B / QRNG Beacons
Stage 02 · Governance
Policy Hash Gating

Policy Hash Gating

Applications issue abstract intents (e.g. SIGN_CREDENTIAL). KeyMESH evaluates the active Agreement DAG and Policy Hash (PH), dynamically selecting mathematical algorithms based on jurisdiction and threat posture.

Mechanism: Intent-Based Abstraction Layer
Stage 03 · Transport
XFS4IoT & TR-34 Tunnels

XFS4IoT & TR-34 Tunnels

CEN XFS4IoT WebSockets provide OS-agnostic communication with peripherals. Remote Key Loading (TR-34) establishes blind, asymmetric encrypted tunnels from Cloud HSMs directly into peripheral Secure Elements (EPPs).

Protocols: CEN XFS4IoT · ASC X9 TR-34 RKL
Stage 04 · Packaging
TR-31 Smart Containers

TR-31 Smart Containers

Keys are encapsulated inside TR-31 (ANSI X9.143) key blocks where usage permissions (OPPs) are cryptographically bound to the ciphertext. Any unauthorised alteration corrupts the MAC and causes immediate hardware rejection.

Standard: ANSI X9.143 / TR-31 Key Block
  Corpus Deep Dive · The Authoritative Trinity & DCPU Loop

Structural Separation of Powers: State, Evidence, Flow & Execution

A sovereign digital economy requires more than isolated execution boundaries; it requires an authoritative control plane that substantiatedly proves the Present State (Registrar), the Past Evidence (Notary), and the Cryptographic Flow (KeyMESH), physically enforced within the oneVault MESH execution fabric.

1. State vs. Secrets

Registrar & KeyMESH Attestation

The Registrar performs recursive attestation of node xBOMs against the active Policy Hash (PH). KeyMESH only routes Distributed Fragment Cryptography (DFC) ciphertext payloads after verifying this Attestable Trust Envelope. Atomic Map Update syscalls push revocation state instantly to kernel eBPF filters.

Control: Delegation DAGs · Multi-Agent OBO Tokens
2. Secrets vs. Execution

KeyMESH & oneVault MESH Assembly

KeyMESH routes encrypted fragments across isolated network tiers. Full keys are never held on any single server; they are re-assembled strictly inside the hardware TEE "Silicon Apartment" (AMD SEV-SNP / Intel TDX) on the DRAGON DCPU at the exact moment of execution.

Isolation: Zero-Knowledge In-Enclave Assembly
3. Execution vs. Evidence

oneVault MESH & Notary VACs

As execution concludes, oneVault generates a Verifiable Adjudication Commitment (VAC). The Notary acts as an asynchronous observer, committing the VAC and Wipe Attestation Signature (WAS) to the Bi-Temporal Ledger without adding synchronous latency to line-rate financial flows.

Non-Repudiation: Bitemporal Hypergraph ($V_t \times T_t$)
Five-Part DCPU-Powered Tandem Execution Loop
  [ 1. Orchestration: inConcert iPaaS ] ──► Triggers Actuator DAG for multi-tenant financial transaction
                                                        │
                                                        ▼
  [ 2. Attestation: Registrar SoR ]      ──► Verifies xBOM integrity & loads Legal State Reachability Graph (LSRG)
                                                        │
                                                        ▼
  [ 3. Authorisation: KeyMESH Fabric ]   ──► Evaluates OBO Token & releases TR-31 wrapped DFC ciphertext fragments
                                                        │
                                                        ▼
  [ 4. Enforcement: DRAGON DCPU / oneVault ] ──► Assembles keys in TEE enclave, signs transaction, executes atomic zeroisation (\mathbb{Z}_{SRAM})
                                                        │
                                                        ▼
  [ 5. Certification: Notary Ledger ]    ──► Asynchronously seals Verifiable Adjudication Commitment (VAC) & WAS into Bi-Temporal Ledger

Ecosystem Authoritative Trinity Links

KeyMESH operates in continuous synchronisation with the Registrar for active policy hashing, the Notary for non-repudiation audit trails, and oneVault Mesh for confidential enclave execution.

Deep Technical: Remote Key Loading (TR-34) & Blind Enclave Tunnels

Deep Technical: Remote Key Loading (TR-34) & Blind Enclave Tunnels

Traditional Remote Key Injection (RKI) methods are vulnerable if the host operating system of an edge kiosk is compromised by malware or rootkits. Under the KeyMESH architecture, the host Linux operating system acts merely as an untrusted transport bridge.

Using the ASC X9 TR-34 standard, a dual-asymmetric public key handshake is established between the central Cloud HSM and the physical Secure Element (SE) / Encrypting PIN Pad (EPP). The ephemeral session keys are encrypted with the EPP's factory-fused public key inside the Cloud HSM. When the payload traverses the local appliance bus, the host OS cannot inspect or copy the key material. The key is decrypted exclusively inside the hardware-isolated cryptographic boundary of the peripheral.

Deep Technical: Post-Quantum Hybrid Migration (Kyber & Dilithium)

Deep Technical: Post-Quantum Hybrid Migration (Kyber & Dilithium)

KeyMESH is architected for quantum resilience from first principles. Rather than mandating immediate, brittle "forklift upgrades" of legacy hardware, KeyMESH supports hybrid cryptographic states as codified by NIST FIPS 203 (ML-KEM / Kyber), FIPS 204 (ML-DSA / Dilithium), and FIPS 205 (SLH-DSA / SPHINCS+).

In hybrid mode, transactions generate composite signatures combining classical elliptic-curve signatures (ECDSA-P256 or Ed25519) with lattice-based post-quantum signatures. As quantum cryptanalysis advances, the System of Agreement updates the Policy Hash (PH) globally, directing KeyMESH to deprecate classical primitives and transition to pure PQC without requiring a single line of application code to be rewritten.

Next-Gen Cryptography: Post-Quantum Security & Sovereign Keys
NIST PQC Standards

Native ML-KEM (Kyber) and ML-DSA (Dilithium) support safeguarding high-value transaction rails against store-now-decrypt-later adversaries.

Hardware Enclave Isolation

Keys never exist in plaintext memory; operations execute inside AMD SEV-SNP enclaves with zero OS-level interception risk.

Bi-Temporal Merkle Proofs

Every key rotation and signing assertion generates an immutable, non-repudiable audit event on the underlying ledger.

Deep Science: Multi-Party Computation & Threshold Mathematics

Deep Science: Multi-Party Computation & Threshold Mathematics

In a \((t, n)\) threshold secret-sharing scheme, a secret \(S \in \mathbb{F}_p\) is split among \(n\) participating nodes such that any subset of \(t\) nodes can reconstruct \(S\), whilst any group of \(t - 1\) or fewer nodes gains zero information regarding \(S\). KeyMESH constructs a random polynomial \(f(x)\) of degree \(t-1\) over the Galois Field \(\mathbb{F}_p\):

\(f(x) = a_0 + \sum_{j=1}^{t-1} a_j x^j \pmod p \quad \text{where } a_0 = S\)

Each shard \(S_i = (i, f(i))\) is distributed to an isolated node. Given any subset of \(t\) shards \(\mathcal{S} \subset \{1, \dots, n\}\), the secret \(S = f(0)\) is recovered via Lagrange polynomial interpolation:

\(S = \sum_{i \in \mathcal{S}} S_i \cdot \ell_i(0) \pmod p \quad \text{with} \quad \ell_i(0) = \prod_{j \in \mathcal{S}, j \ne i} \frac{-j}{i - j} \pmod p\)

In threshold signing (e.g. threshold ECDSA/Schnorr), KeyMESH utilises homomorphic properties to generate valid cryptographic signatures across nodes without ever reconstructing the private key \(S\) on a single physical host, guaranteeing that no central honeypot exists in the execution pipeline.