plus, if the biller isnt exposed to anyone, and the only things that can interface with it are zones, theres essentially no risk, as a compromised zone doesnt have enough information to crack anything and what im envisioning is a pure distributed system where any zone could be attached to any biller, and your suggestion directly translates into any number of key servers attached to every biller and then you get the problem of potentially malicious rogue key servers