SIX Builds Quantum Security for DLT-Based Exchange
The Swiss Exchange is future-proofing SDX with post-quantum encryption, ahead of its full-service launch.
SIX Digital Exchange (SDX), an end-to-end platform for trading digital assets based on distributed-ledger technology (DLT), is developing its architecture to be quantum-safe.
As part of its wider security strategy for the digital exchange and central securities depository, SIX is building post-quantum encryption into its technology to future-proof against organized cybercriminals with access to quantum technologies.
While they do contain vulnerabilities, DLT networks like blockchain are secured with advanced cryptography and are considered generally secure against present-day technologies or traditional computing. However, researchers at the National Institute of Standards and Technology (NIST) warn that a quantum computer could be powerful enough to crack even blockchain encryption.
Information infrastructure like the internet and distributed ledgers are underpinned by mathematical problems, such as encryption algorithms like RSA and elliptic curve cryptography, which are deemed too complex for conventional computers to crack. In theory, however, a quantum computer could decrypt these complex ciphers.
Many experts believe that commercial uses of quantum computing are years away, as these computers not only cost millions of dollars to buy, but are also extremely expensive to run due to the vast amounts of electricity required to maintain the conditions for quantum mechanics to work, which in some cases require the temperature to in the range of -400 degrees Fahrenheit.
Jochen Duerr, chief risk officer at SIX Group, does not view the risk of quantum computing capabilities falling into the wrong hands as such a distant problem. He says that there is an arms race when it comes to securing DLT networks, and that state-organized criminals are well-resourced and shouldn’t be underestimated.
“There are threat actors that get more and more access [to advanced technologies]…and if you talk about state actors, they have access to a substantial amount of funding,” says Duerr, though he declined to get into specifics as to just how they will create a quantum-safe architecture.
Further to SIX’s security strategy, the company will develop round-the-clock surveillance and security alerts on SDX. “Security doesn’t have a nine-to-five working day, so you need to make sure that that you provide 24/7 security protection and detection opportunity,” Duerr says.
SIX is building post-quantum resiliency into SDX’s architecture as one of the key security deliverables for the project, ahead of its full launch. SDX was originally scheduled to go live in late 2019, but SIX pushed the deadline back to this year. Now, the exchange expects that the first services of the SDX end-to-end platform will be rolled out all through 2020 on a use-case-by-use-case basis.
“We will go ahead in a use-case, staggered approach with our customers and with our shareholder banks,” Duerr says. “Therefore, it will also depend on their readiness and ability to go live with us. So, in other words, it will be a piloted approach, step-by-step, over the course of this year.”
SIX would not specify which of its digital services will be available this year.
Further reading
Only users who have a paid subscription or are part of a corporate subscription are able to print or copy content.
To access these options, along with all other subscription benefits, please contact info@waterstechnology.com or view our subscription options here: http://subscriptions.waterstechnology.com/subscribe
You are currently unable to print this content. Please contact info@waterstechnology.com to find out more.
You are currently unable to copy this content. Please contact info@waterstechnology.com to find out more.
Copyright Infopro Digital Limited. All rights reserved.
As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (point 2.4), printing is limited to a single copy.
If you would like to purchase additional rights please email info@waterstechnology.com
Copyright Infopro Digital Limited. All rights reserved.
You may share this content using our article tools. As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (clause 2.4), an Authorised User may only make one copy of the materials for their own personal use. You must also comply with the restrictions in clause 2.5.
If you would like to purchase additional rights please email info@waterstechnology.com
More on Regulation
Off-channel messaging (and regulators) still a massive headache for banks
Waters Wrap: Anthony wonders why US regulators are waging a war using fines, while European regulators have chosen a less draconian path.
Banks fret over vendor contracts as Dora deadline looms
Thousands of vendor contracts will need repapering to comply with EU’s new digital resilience rules
Chevron’s absence leaves questions for elusive AI regulation in US
The US Supreme Court’s decision to overturn the Chevron deference presents unique considerations for potential AI rules.
Aussie asset managers struggle to meet ‘bank-like’ collateral, margin obligations
New margin and collateral requirements imposed by UMR and its regulator, Apra, are forcing buy-side firms to find tools to help.
The costly sanctions risks hiding in your supply chain
In an age of geopolitical instability and rising fines, financial firms need to dig deep into the securities they invest in and the issuing company’s network of suppliers and associates.
Industry associations say ECB cloud guidelines clash with EU’s Dora
Responses from industry participants on the European Central Bank’s guidelines are expected in the coming weeks.
Regulators recommend Figi over Cusip, Isin for reporting in FDTA proposal
Another contentious battle in the world of identifiers pits the Figi against Cusip and the Isin, with regulators including the Fed, the SEC, and the CFTC so far backing the Figi.
US Supreme Court clips SEC’s wings with recent rulings
The Supreme Court made a host of decisions at the start of July that spell trouble for regulators—including the SEC.