国际清算银行-金融体系的量子准备_路线图(英)-2025.7_31页_2mb
报告摘要
Summary: Quantum-readiness for the Financial System – A Roadmap
Core Content
This paper discusses the quantum threat to the financial system and outlines a strategic roadmap for transitioning to quantum-safe cryptographic infrastructures. It highlights the urgency of preparing for this shift, emphasizing that quantum computers may break current encryption methods in the near future, which could compromise the security and resilience of financial systems.
Main Points
1. Quantum Threat to Cryptography
- Quantum computers may break today’s public key cryptography (e.g., RSA, ECC) using Shor's algorithm, which can factor large numbers and solve discrete logarithms in polynomial time.
- Grover's algorithm can speed up symmetric key searches, but this risk can be mitigated by using larger key sizes (e.g., 256-bit AES).
- Harvest now, decrypt later (HNDL) attacks pose a real threat, as data collected today could be decrypted in the future once quantum computers become powerful enough.
- The timeline for a cryptographically relevant quantum computer (CRQC) is estimated to be within 10–15 years, based on expert assessments.
2. Cryptographic Foundations
- Cryptography ensures confidentiality, integrity, authentication, access control, and non-repudiation in financial systems.
- Symmetric cryptography (e.g., AES) is efficient for data encryption, while asymmetric cryptography (e.g., RSA, ECC) is used for key exchange and digital signatures.
- Key management is critical to the effectiveness of cryptographic systems, including generation, distribution, storage, and revocation.
3. Quantum-safe Solutions
Three main categories of quantum-safe solutions are discussed:
a. Post-quantum cryptography (PQC)
-
Advantages:
- Established initial standards.
- Compatible with existing infrastructures.
- Scalable.
- Diverse algorithm options.
- Supports identity authentication.
-
Disadvantages:
- Requires extensive testing.
- Potential vulnerability to quantum attacks.
- Performance considerations.
- Larger key sizes and computational overhead.
b. Quantum key distribution (QKD)
-
Advantages:
- Security based on quantum mechanics.
- Resistant to cryptoanalysis.
- Long-term security assurance.
- Applicability in pre-shared key (PSK) use cases.
-
Disadvantages:
- Still in developmental stage.
- High cost implications.
- Distance constraints.
- Integration challenges.
- Lack of identity authentication.
c. Other quantum-safe methods
- Quantum homomorphic encryption (QHE) and blind quantum computing (BQC) are promising but still in the research phase.
- QHE allows computation on encrypted data without decryption, preserving confidentiality.
- BQC enables secure cloud-based quantum computing by hiding data and computation from the server.
- Both are not yet ready for widespread deployment.
4. Best Practices and Recommendations
- Cryptographic agility is essential, allowing organisations to adapt and reconfigure cryptographic defences quickly in response to new threats or vulnerabilities.
- Defence in depth is a key strategy, combining multiple layers of security (e.g., PQC, PSK, two-factor authentication) to reduce the risk of data breaches.
- Phased migration is recommended, as transitioning to quantum-safe systems is complex and requires careful planning.
- Hybrid models may be used in the transition, combining classical and quantum-safe algorithms to ensure compatibility and security.
5. Challenges and Considerations
- Implementation challenges include performance trade-offs and system integration issues.
- Legacy systems using outdated protocols like TLS 1.2 are vulnerable to quantum threats and must be upgraded to TLS 1.3 or newer versions.
- Pre-shared keys (PSK) are a practical option for short-term security, but they face scalability and distribution challenges.
- Centralised symmetric key management systems are used to support PSKs and ensure secure key access.
Key Information
- Quantum computing presents both opportunities and risks for the financial sector.
- Cryptography is the foundation of financial security, and its viability is under threat from quantum advancements.
- Post-quantum cryptography is the most mature and implementable solution today, with NIST leading the standardisation process.
- Quantum key distribution and other quantum-safe methods offer long-term security but are not yet practical for widespread use.
- Cryptographic agility and defence in depth are strategic approaches to enhance security and resilience in the face of quantum threats.
- Migration planning must be initiated now to avoid future disruptions and ensure continued financial stability.
Conclusion
The financial system must transition to quantum-safe cryptographic infrastructures as soon as possible. This includes raising awareness, implementing governance structures, and maintaining comprehensive cryptographic inventories. The paper advocates for a coordinated, multi-layered approach to ensure security and resilience against future quantum threats, with a focus on practical implementation and ongoing research and development.
试读结束,高清完整版pdf/doc/ppt,请点下载