IP Library › Granted Patent US 12,712,740
Granted Patent B2
US 12,712,740 · App. 19/022,285 · Granted Aug 18, 2026

Systems and methods for establishing data provenance by generating one-time signatures

Inventors: Alex McMahon (North Dock, IE); Paul Carey (North Dock, IE); Sudha Iyer (North Dock, IE)
Assignee: Citigroup Technology, Inc.
H04L9/3247H04L9/0869H04L9/0825H04L9/0866H04L9/3249H04L9/3252H04L9/3255H04L9/3257
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,712,740
App. No.
19/022,285
Granted
Aug 18, 2026
Kind
B2
Abstract

Presented herein are system and methods for establishing data provenance by generating one-time signatures. A system may include one or more processors that receive, via an application programming interface (API) request, a request for a one-time signature and data associated with the request, provide a seed identifier and the data associated with the request to an HSM in a set of HSMs, and receive a response message from the HSM, the response message including a one-time signature. In examples, the response message and the one-time signature are provided to the device that transmitted the request for the one-time signature and the data associated with the request. Methods and non-transitory computer-readable mediums are also presented.

Claims (33)

1 . A computer-implemented method, comprising:

generating, by at least one processor, a request for a one-time signature comprises including a public certificate in the request for the one-time signature that is mapped to one or more accounts indicating an identity of a client, the request based on data to be stored on a server;

providing, by the at least one processor and via an application programming interface (API) associated with a signing environment, the request and the data to be stored on the server to the signing environment to generate the one-time signature;

receiving, by the at least one processor and via the API, a response message comprising the one-time signature in response to generation of the one-time signature by a hardware security module (HSM) for the data to be stored on the server, the HSM configured to generate the one-time signature based on a mapping between a seed and an account of a plurality of accounts;

generating, by the at least one processor, an entry for a distributed ledger associated with the server based on the one-time signature, the entry indicating an association between the data to be stored on the server and the one-time signature; and

transmitting, by the at least one processor, to the server at least a portion of the entry for inclusion in the distributed ledger associated with the server.

2 . The computer-implemented method of claim 1 , further comprising: encrypting, by the at least one processor, the request based on a predetermined encryption scheme, wherein providing the request to the signing environment comprises: providing the request to the signing environment in response to encrypting the request.

3 . The computer-implemented method of claim 1 , wherein receiving the response message comprises: receiving, by the at least one processor, the response message in response to execution of one or more operations by the HSM involving a seed value corresponding to the seed.

4 . The computer-implemented method of claim 1 , wherein generating the entry comprises: updating the data to be stored on the server by hashing at least a portion of the data; and generating the entry in response to updating the data to be stored on the server.

5 . The computer-implemented method of claim 4 , wherein the server comprises a first server, the computer-implemented method further comprising:

providing the one-time signature to a second server to establish provenance of the data stored on the first server.

6 . A system, comprising:

at least one hardware processor programmed to:

generate a request for a one-time signature, the request based on data to be stored on a server, wherein the request includes a public certificate for the one-time signature that is mapped to one or more accounts indicating an identity of a client;

provide, via an application programming interface (API) associated with a signing environment, the request and the data to be stored on the server to the signing environment to generate the one-time signature;

receive, via the API, a response message comprising the one-time signature in response to generation of the one-time signature by a hardware security module (HSM) for the data to be stored on the server, the HSM configured to generate the one-time signature based on a mapping between a seed and an account of a plurality of accounts;

generate an entry for a distributed ledger associated with the server based on the one-time signature, the entry indicating an association between the data to be stored on the server and the one-time signature; and

transmit to the server at least a portion of the entry for inclusion in the distributed ledger associated with the server.

7 . The system of claim 6 , wherein the at least one hardware processor is further programmed to: encrypt the request based on a predetermined encryption scheme, wherein the at least one hardware processor programmed to provide the request to the signing environment is programmed to: provide the request to the signing environment in response to encrypting the request.

8 . The system of claim 6 , wherein the at least one hardware processor programmed to receive the response message is programmed to: receive the response message in response to execution of one or more operations by the HSM involving a seed value corresponding to the seed.

9 . The system of claim 6 , wherein the at least one hardware processor programmed to generating the entry is programmed to: update the data to be stored on the server by hashing at least a portion of the data; and generate the entry in response to updating the data to be stored on the server.

10 . The system of claim 9 , wherein the server comprises a first server, and wherein the at least one hardware processor is further programmed to: provide the one-time signature to a second server to establish provenance of the data to be stored on the first server.

11 . A non-transitory computer-readable medium storing instructions thereon that, when executed by at least one processor, cause the at least one processor to:

generate a request for a one-time signature, the request based on data to be stored on a server;

include a public certificate in the request for the one-time signature that is mapped to one or more accounts indicating an identity of a client;

provide, via an application programming interface (API) associated with a signing environment, the request and the data to be stored on the server to the signing environment to generate the one-time signature;

receive, via the API, a response message comprising the one-time signature in response to generation of the one-time signature by a hardware security module (HSM) for the data to be stored on the server, the HSM configured to generate the one-time signature based on a mapping between a seed and an account of a plurality of accounts;

generate an entry for a distributed ledger associated with the server based on the one-time signature, the entry indicating an association between the data to be stored on the server and the one-time signature; and

transmit to the server at least a portion of the entry for inclusion in the distributed ledger associated with the server.

12 . The non-transitory computer-readable medium of claim 11 , wherein the instructions further cause the at least one processor to: encrypt the request based on a predetermined encryption scheme; and wherein the instructions that cause the at least one processor to provide the request to the signing environment cause the at least one processor to: provide the request to the signing environment in response to encrypting the request.

13 . The non-transitory computer-readable medium of claim 11 , wherein the instructions that cause the at least one processor to receive the response message cause the at least one processor to: receive the response message in response to execution of one or more operations by the HSM involving a seed value corresponding to the seed.

14 . The non-transitory computer-readable medium of claim 11 , wherein the instructions that cause the at least one processor to generate the entry cause the at least one processor to: update the data to be stored on the server by hashing at least a portion of the data; and generate the entry in response to updating the data to be stored on the server.

15 . The non-transitory computer-readable medium of claim 11 , wherein the server comprises a first server, and wherein the instructions further cause the at least one processor to: provide the one-time signature to a second server to establish provenance of the data to be stored on the first server.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 15, 2025
From: MCMAHON, ALEX; CAREY, PAUL; IYER, SUDHA
To: CITIGROUP TECHNOLOGY, INC.
Reel/Frame 069882/0033 →
Continuity (2)
Continuation 18602523 · Mar 12, 2024
Related Publication 20250293891A1 · Sep 18, 2025
References Cited (46)
US 11184157B1 · Gueron et al. · 2021 [cited by applicant]
US 11310060B1 · Poelstra · 2022 [cited by examiner]
US 11334883B1 · Auerbach · 2022 [cited by applicant]
US 11516186B1 · Ambaliya et al. · 2022 [cited by applicant]
US 11516253B1 · Van Deman et al. · 2022 [cited by applicant]
US 11539532B2 · Zeh et al. · 2022 [cited by applicant]
US 20090217041A1 · Ramzan et al. · 2009 [cited by applicant]
US 20140359288A1 · Jensen et al. · 2014 [cited by applicant]
US 20150358161A1 · Kancharla et al. · 2015 [cited by applicant]
US 20170329958A1 · Hitchcock et al. · 2017 [cited by applicant]
US 20170357496A1 · Smith et al. · 2017 [cited by applicant]
US 20180183602A1 · Campagna et al. · 2018 [cited by applicant]
US 20180183771A1 · Campagna et al. · 2018 [cited by applicant]
US 20180183774A1 · Campagna et al. · 2018 [cited by applicant]
US 20190158481A1 · Ronda · 2019 [cited by examiner]
US 20190172047A1 · Tan et al. · 2019 [cited by applicant]
US 20190173672A1 · Le Saint et al. · 2019 [cited by applicant]
US 20190238333A1 · Grubin et al. · 2019 [cited by applicant]
US 20190319798A1 · Chalkias · 2019 [cited by applicant]
US 20190319804A1 · Mathew et al. · 2019 [cited by applicant]
US 20190342079A1 · Rudzitis et al. · 2019 [cited by applicant]
US 20200084050A1 · Mensch et al. · 2020 [cited by applicant]
US 20200228338A1 · Bowness · 2020 [cited by applicant]
US 20200236113A1 · Monica et al. · 2020 [cited by applicant]
US 20200328902A1 · Wang · 2020 [cited by examiner]
US 20210326442A1 · Campagna et al. · 2021 [cited by applicant]
US 20220086009A1 · Vacek et al. · 2022 [cited by applicant]
US 20220385484A1 · Behnia et al. · 2022 [cited by applicant]
US 20230020193A1 · Williams · 2023 [cited by examiner]
US 20230033630A1 · Liu · 2023 [cited by applicant]
US 20230038949A1 · Kido · 2023 [cited by applicant]
US 20230058273A1 · Sundar et al. · 2023 [cited by applicant]
US 20230299972A1 · Villatel et al. · 2023 [cited by applicant]
US 20230318808A1 · Osborn · 2023 [cited by examiner]
US 20240097913A1 · Laing et al. · 2024 [cited by applicant]
US 20240097914A1 · Laing et al. · 2024 [cited by applicant]
US 20250060312A1 · McManus · 2025 [cited by examiner]
CN 103997405B · 2014 [cited by applicant]
CN 119966606A · 2025 [cited by examiner]
EP 4068685A1 · 2022 [cited by applicant]
JP 2003069560A · 2003 [cited by applicant]
WO WO2022136527A1 · 2022 [cited by applicant]
WO WO2022211899A1 · 2022 [cited by applicant]
WO WO2024220433A1 · 2024 [cited by examiner]
T. Visegrady, S. Dragone, and M. Osborne (Stateless cryptography for virtual environments); pp. 10 IBM J. Res. & Dev. vol. 58 No. 1 Paper 5 Jan./Feb. 2014. [cited by applicant]
PCT International Search Report and Written Opinion for Application No. PCT/US2025/018445 mailing date Jul. 8, 2025, 13 pages. [cited by applicant]