...
Skip to content

BIS and central banks test post-quantum cryptography in payments

Project Leap Phase 2, a collaboration between the BIS Innovation Hub Eurosystem Centre, the Bank of Italy, the Bank of France, Deutsche Bundesbank, Nexi-Colt, and Swift, tested post-quantum cryptography in an operational payment system.

Protecting financial systems from the potential threat posed by quantum computers requires a proactive and coordinated approach, says the BIS, noting that challenges go beyond technical aspects and include awareness, resource allocation, competence development, inventory, pilots, governance and more.

The experiment replaced traditional digital signatures with post-quantum cryptography when sending liquidity transfers in the Eurosystem’s Target2 system. It involved modifying numerous system components to ensure compatibility with updated cryptographic libraries.

All test scenarios were successfully executed, demonstrating the feasibility of migrating payment systems to post-quantum cryptography. The tests also revealed significant performance differences between traditional and post-quantum algorithms, pointing at the need for further testing and preparation before transitioning the financial system.

The project report describes functional findings when applying post-quantum cryptographic protocols considering deployment challenges at an organisational and technical level. It also describes learnings related to performance, interoperability, and cryptographic agility. For example, test results reveal significant performance differences between traditional and post-quantum algorithms, pointing at the need for further testing and preparation before transitioning the financial system.

“Migrating payment systems to quantum-safe solutions is a complex and high-stakes process that affects the entire financial ecosystem,” states the BIS. “Project Leap Phase 2 highlighted the importance of timely preparations and collaboration across institutions to ensure the financial system is resilient against emerging threats.”