What BIS Project Leap - Quantum-Proofing the Financial System (Central Bank Post-Quantum VPN Experiment) requires
Project Leap: Quantum-proofing the financial system was published in June 2023 as a joint experiment by the BIS Innovation Hub Eurosystem Centre, the Bank of France and Deutsche Bundesbank. Unlike the national roadmaps that describe what should be done, this report records what was actually built and measured: a post-quantum virtual private network tunnel carrying a standard Pacs.008 payment message between two central banks, with timing and stability results. The stated threat is that quantum computers represent a serious threat for the financial system, that quantum algorithms created in the mid-1990s could in theory and given a sufficiently powerful quantum computer break today's widely used public key cryptographic schemes, and that this would instantly obsolete many current cryptographic techniques. Because malicious actors can already intercept and store confidential, classically encrypted data with the intention of decrypting it later, data stored or transmitted today are exposed to harvest now, decrypt later attacks, and the long-term sensitivity of financial data means the potential future existence of a quantum computer effectively renders today's systems insecure. The empirical findings are the value of the report. On cryptographic agility, a significant number of information systems suffer from a lack of it because they are not designed with easy replacement in mind, and systems with a high degree of cryptographic agility will be better equipped to handle the coming transition; central banks should identify where inflexible systems are used and plan their substitution, which the report says will most likely be the case for certain types of hardware such as hardware security modules, firewalls and smart cards. The key exchange mechanism could easily accept any post-quantum algorithm, whereas the digital signature standard configuration is not pre-configured to detect the algorithm. On performance, there was no impact at the performance level when sending data through the tunnel whatever the size of the data, because once the post-quantum tunnel is set up information is encrypted with traditional cryptography using AES-256; performance was impacted only when initially setting up the tunnel, which in real-world applications would happen only once or twice during a business day. Rekey testing repeated 100 times showed stable results with the impact confined to the key exchange and asynchronous for the client. On security, hybrid mode mitigates two risks: if legacy asymmetric cryptosystems are broken a post-quantum layer protects data transfer and prevents any regression, and hybridisation makes it easier to replace traditional schemes as they become outdated. There is always a trade-off between performance and security, so security must be configured according to application requirements. CRYSTALS-Kyber showed only a minuscule difference in speed between level 3 and level 5 and appears better suited than FrodoKEM where performance constraints are high; Falcon demonstrated better performance than CRYSTALS-Dilithium; and SPHINCS+ registered slower performance, though as a hash-based algorithm it does not have to be implemented in a hybrid mode because the reliability of that algorithm family is well known. The report's conclusion is that applying post-quantum protocols is already feasible, that migration planning should follow Mosca's model comparing the time needed to migrate plus the time data needs to remain protected against the time for a quantum computer to be ready, and that central banks need to allow for a transition phase in their cyber security roadmaps.
Pillar: Banking & Global Finance · Authority: Bank for International Settlements (BIS) Innovation Hub Eurosystem Centre, with the Bank of France and Deutsche Bundesbank · Version: 1.0.0 · Last updated:
Primary source: https://www.bis.org/publ/othp67.htm
SHA-256 integrity: 25c8d5f78231259cd958eee35dba582a3ce089fb958cc4d297ef7b86de10bc28
Primary Citations — 10 traced to source
+ 8 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/bis-project-leap-quantum-proofing-payments.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/bis-project-leap-quantum-proofing-payments.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/bis-project-leap-quantum-proofing-payments
- Back to registry: Browse all 10,099 compliance nodes