Policy-Driven Cryptographic Agility & The Sovereign Trust Fabric
The KeyMESH serves as the modular, policy-driven cryptographic routing nervous system of the onePOI.online ecosystem. Traditional computing models hardcode cryptographic libraries directly into client applications, resulting in costly, months-long code refactoring cycles whenever algorithms must be upgraded. KeyMESH inverts this paradigm by completely abstracting mathematical execution from application logic.
To solve the Digital Public Infrastructure (DPI) Trilemma – balancing uncompromising security, hyperscale distribution, and hardware unit economics – KeyMESH deploys a "Fortress and Field" model. Centralised Master Root Keys reside exclusively in high-assurance Tier 1 Cloud HSMs ("The Fortress"), whilst edge POI terminals ("The Field") operate as completely empty vessels regarding static credentials. Ephemeral session keys are injected Just-in-Time (JIT) into hardware enclaves and shredded immediately upon transaction finality.
Engineered for Institutional Margins.
Adopted for Human Sovereignty.
Every capability across the Salient Innovation Set delivers an immediate, symmetrical return: radical margin recovery for the enterprise tenant, paired with frictionless dignity and absolute cryptographic safety for the citizen.
How the Tenant Expands Margins
Transforming operating models from defensive cost centres into agile, shared revenue engines through multi-tenant pooling and mathematical compliance.
-
CapEx Pooling & No Single-Tenant Hardware
POI Appliances run white-label on co-funded premises. Reach 50 commercial catchments without funding 50 proprietary branch builds.
-
Zero Interchange & Flat-Fee Clearing
Instant Account-to-Account rails (SEPA Instant / PayShap) bypass 1.5–3.5% card scheme tolls with predictable, flat sub-cent clearing fees.
-
Compliance by Construction
Agreement DAGs enforce statutory mandates at wire speed; non-compliant states cannot execute, eliminating retrospective audit penalties.
-
Accelerated Partner Onboarding
Pre-verified BIAN and ArchiMate capability components compress multi-firm integration cycles from quarters to days.
Why the Customer Loves Using It
Delivering sovereign dignity and verifiable security where users never surrender control over their identity, consent, or funds.
-
Nothing Stored to Steal
Credentials remain in the user's oneWallet. A breach of a merchant's server reveals zero identity records, protecting citizens completely.
-
One Pattern, Everywhere
The same intuitive tap-and-confirm interaction works seamlessly at a high-street kiosk, transit hub, EV charger, or smartphone.
-
Delegated Authority, Never Escalated
Autonomous AI agents carry single-use, bounded warrants; an agent checking information cannot escalate its authority to transfer money.
-
Payments That Do Not Fail
When a payment network degrades, the transaction reroutes with authentication preserved – zero declines, zero repeated entries.
KeyMESH Runtime Manifest
Multi-Tenant Cryptographic Orchestrator
Commercial Sovereignty & Shared Phygital Infrastructure
In shared commercial environments – such as municipal kiosks, automated teller cash recyclers, and smart retail lockers – physical theft or endpoint tampering presents catastrophic liability. If static master keys reside on-disk, compromising one appliance compromises the entire tenant institution. KeyMESH eradicates this risk by ensuring edge hardware contains zero persistent cryptographic credentials.
As the cryptographic backbone of the Salient FinTech Innovation Set, KeyMESH natively integrates with BIAN v14 bare-metal service domains (Payment Execution, Party Authentication, Cryptographic Services) and real-time payment rails (SEPA Instant, FedNow, RTP, Discover/Pulse). Competing financial and civic institutions share unified physical appliances whilst maintaining absolute, mathematically enforced sovereign isolation.
Zero Edge Key Theft
If an appliance is stolen or drilled, the attacker captures empty silicon with no static credentials.
Zero-Truck-Roll Key Injection
Automates Remote Key Injection (RKI) via TR-34 tunnels without requiring manual field technicians.
Multi-Tenant Key Curtaining
TR-31 usage tags cryptographically prevent Tenant A's software from misusing Tenant B's keys.
Post-Quantum Agility
Hot-swaps classical ECC/RSA for NIST FIPS 203/204 PQC algorithms via simple Agreement DAG updates.
The 4-Stage Industrial Cryptographic Supply Chain
KeyMESH governs the entire lifecycle of cryptographic secrets across edge and cloud infrastructure. From physical entropy harvesting to hardware-bound usage encapsulation, every stage adheres to rigorous international standards.
Entropy Mesh & EaaS
Eliminates edge "entropy starvation" at boot. Centralised Quantum Random Number Generator (QRNG) beacons supply cryptographically certified entropy seeds (NIST SP 800-90B) to initialise appliance cryptographic pools.
Policy Hash Gating
Applications issue abstract intents (e.g. SIGN_CREDENTIAL). KeyMESH evaluates the active Agreement DAG and Policy Hash (PH), dynamically selecting mathematical algorithms based on jurisdiction and threat posture.
XFS4IoT & TR-34 Tunnels
CEN XFS4IoT WebSockets provide OS-agnostic communication with peripherals. Remote Key Loading (TR-34) establishes blind, asymmetric encrypted tunnels from Cloud HSMs directly into peripheral Secure Elements (EPPs).
TR-31 Smart Containers
Keys are encapsulated inside TR-31 (ANSI X9.143) key blocks where usage permissions (OPPs) are cryptographically bound to the ciphertext. Any unauthorised alteration corrupts the MAC and causes immediate hardware rejection.
Structural Separation of Powers: State, Evidence, Flow & Execution
A sovereign digital economy requires more than isolated execution boundaries; it requires an authoritative control plane that substantiatedly proves the Present State (Registrar), the Past Evidence (Notary), and the Cryptographic Flow (KeyMESH), physically enforced within the oneVault MESH execution fabric.
Registrar & KeyMESH Attestation
The Registrar performs recursive attestation of node xBOMs against the active Policy Hash (PH). KeyMESH only routes Distributed Fragment Cryptography (DFC) ciphertext payloads after verifying this Attestable Trust Envelope. Atomic Map Update syscalls push revocation state instantly to kernel eBPF filters.
KeyMESH & oneVault MESH Assembly
KeyMESH routes encrypted fragments across isolated network tiers. Full keys are never held on any single server; they are re-assembled strictly inside the hardware TEE "Silicon Apartment" (AMD SEV-SNP / Intel TDX) on the DRAGON DCPU at the exact moment of execution.
oneVault MESH & Notary VACs
As execution concludes, oneVault generates a Verifiable Adjudication Commitment (VAC). The Notary acts as an asynchronous observer, committing the VAC and Wipe Attestation Signature (WAS) to the Bi-Temporal Ledger without adding synchronous latency to line-rate financial flows.
[ 1. Orchestration: inConcert iPaaS ] ──► Triggers Actuator DAG for multi-tenant financial transaction
│
▼
[ 2. Attestation: Registrar SoR ] ──► Verifies xBOM integrity & loads Legal State Reachability Graph (LSRG)
│
▼
[ 3. Authorisation: KeyMESH Fabric ] ──► Evaluates OBO Token & releases TR-31 wrapped DFC ciphertext fragments
│
▼
[ 4. Enforcement: DRAGON DCPU / oneVault ] ──► Assembles keys in TEE enclave, signs transaction, executes atomic zeroisation (\mathbb{Z}_{SRAM})
│
▼
[ 5. Certification: Notary Ledger ] ──► Asynchronously seals Verifiable Adjudication Commitment (VAC) & WAS into Bi-Temporal Ledger
Ecosystem Authoritative Trinity Links
KeyMESH operates in continuous synchronisation with the Registrar for active policy hashing, the Notary for non-repudiation audit trails, and oneVault Mesh for confidential enclave execution.
Deep Technical: Remote Key Loading (TR-34) & Blind Enclave Tunnels
Deep Technical: Remote Key Loading (TR-34) & Blind Enclave Tunnels
Traditional Remote Key Injection (RKI) methods are vulnerable if the host operating system of an edge kiosk is compromised by malware or rootkits. Under the KeyMESH architecture, the host Linux operating system acts merely as an untrusted transport bridge.
Using the ASC X9 TR-34 standard, a dual-asymmetric public key handshake is established between the central Cloud HSM and the physical Secure Element (SE) / Encrypting PIN Pad (EPP). The ephemeral session keys are encrypted with the EPP's factory-fused public key inside the Cloud HSM. When the payload traverses the local appliance bus, the host OS cannot inspect or copy the key material. The key is decrypted exclusively inside the hardware-isolated cryptographic boundary of the peripheral.
Deep Technical: Post-Quantum Hybrid Migration (Kyber & Dilithium)
Deep Technical: Post-Quantum Hybrid Migration (Kyber & Dilithium)
KeyMESH is architected for quantum resilience from first principles. Rather than mandating immediate, brittle "forklift upgrades" of legacy hardware, KeyMESH supports hybrid cryptographic states as codified by NIST FIPS 203 (ML-KEM / Kyber), FIPS 204 (ML-DSA / Dilithium), and FIPS 205 (SLH-DSA / SPHINCS+).
In hybrid mode, transactions generate composite signatures combining classical elliptic-curve signatures (ECDSA-P256 or Ed25519) with lattice-based post-quantum signatures. As quantum cryptanalysis advances, the System of Agreement updates the Policy Hash (PH) globally, directing KeyMESH to deprecate classical primitives and transition to pure PQC without requiring a single line of application code to be rewritten.
Native ML-KEM (Kyber) and ML-DSA (Dilithium) support safeguarding high-value transaction rails against store-now-decrypt-later adversaries.
Keys never exist in plaintext memory; operations execute inside AMD SEV-SNP enclaves with zero OS-level interception risk.
Every key rotation and signing assertion generates an immutable, non-repudiable audit event on the underlying ledger.
Deep Science: Multi-Party Computation & Threshold Mathematics
Deep Science: Multi-Party Computation & Threshold Mathematics
In a \((t, n)\) threshold secret-sharing scheme, a secret \(S \in \mathbb{F}_p\) is split among \(n\) participating nodes such that any subset of \(t\) nodes can reconstruct \(S\), whilst any group of \(t - 1\) or fewer nodes gains zero information regarding \(S\). KeyMESH constructs a random polynomial \(f(x)\) of degree \(t-1\) over the Galois Field \(\mathbb{F}_p\):
Each shard \(S_i = (i, f(i))\) is distributed to an isolated node. Given any subset of \(t\) shards \(\mathcal{S} \subset \{1, \dots, n\}\), the secret \(S = f(0)\) is recovered via Lagrange polynomial interpolation:
In threshold signing (e.g. threshold ECDSA/Schnorr), KeyMESH utilises homomorphic properties to generate valid cryptographic signatures across nodes without ever reconstructing the private key \(S\) on a single physical host, guaranteeing that no central honeypot exists in the execution pipeline.