Interbank mTLS and Message Signing

Handshake, replay check, signature verification, and a signed acknowledgement

Interbank mTLS and Message Signing Handshake, replay check, signature verification, and a signed acknowledgement mTLS: client cert validate pin party enrolled signed request + nonce/ts check nonce fresh, stored verify JWS signature signature valid signed ack mTLS handshake Verify request Signed ack Bank A · sending bank · Sequence participant Bank A sending bank Bank B · receiving bank · Sequence participant Bank B receiving bank Trust Store · pins + signing keys · Sequence participant Trust Store pins + signing keys Nonce Cache · freshness window · Sequence participant Nonce Cache freshness window Legend request return security async trace

Two layers

  • • mTLS authenticates the connection endpoint
  • • The detached signature authenticates the payload
  • • Transport identity stays separate from signing identity

Cheap-to-expensive order

  • • Pin the client certificate before parsing
  • • Freshness check runs before signature verification
  • • A replay costs a cache lookup, not a crypto op

Non-repudiation

  • • Nonce plus timestamp bound the replay window
  • • The signed ack proves what Bank B committed to
  • • Both directions are signed, or it is theatre