Securing the Future of Finance: the PiQASO Architecture for Post-Quantum Online Banking

The global financial sector operates on a foundation of absolute trust, confidentiality, and data integrity. In the modern digital economy, this trust is sustained almost entirely by public-key cryptography. Trillions of dollars flow daily through networks secured by mathematical algorithms that, until recently, were considered unbreakable. However, the imminent arrival of cryptographically relevant quantum computers threatens to unravel these mathematical safeguards. The PiQASO project—standing for *Post-Quantum Cryptography As-a-Service for Common Transmission Systems and Infrastructures*—has taken on the crucial task of quantum-hardening modern service graph chains, including high-throughput financial infrastructures.

Transitioning quantum vulnerable e-banking ecosystems to a post-quantum paradigm requires a comprehensive architectural shift. The goal is to proactively secure online banking operations without disrupting the incredibly fast, high-volume transactions that modern financial institutions and their customers expect.

The Vulnerability of Current Financial Architectures

Before diving into the solution, it is essential to understand the current threat landscape. In standard online banking platforms, there is a mixed cryptographic posture. At the symmetric encryption layer, security remains highly robust, typically employing modern protocols like TLS 1.3 coupled with strong AES-256-GCM or ChaCha20-Poly1305 cipher suites. These symmetric algorithms are generally considered resistant to quantum attacks, provided key lengths are sufficient.

However, the critical vulnerability lies in the asymmetric layer. The entire architecture heavily depends on classical public-key cryptography—specifically RSA-2048—for essential tasks such as key distribution, digital signatures, and session authentication. This dependence marks the principal quantum-exposed element. A sufficiently powerful quantum computer running Shor’s algorithm could easily break RSA-2048. This renders the initial handshake and authentication phases completely insecure, leaving platforms vulnerable to “harvest now, decrypt later” attacks, where adversaries store encrypted financial traffic today with the intent to decrypt it tomorrow.

The Target Architecture: PQC Secured Online Banking

To mitigate these risks, CaixaBank will use PiQASO as a comprehensive framework focused specifically on PQC communications to secure online banking operations. Recognizing that financial infrastructures are complex, mixed-criticality environments, the transition must be seamless, scalable, and highly performant. This future-proof architecture is driven by three distinct integration pathways, ensuring every endpoint and node can be quantum-hardened:

1. Edge Integration for External Communications

The first strategic approach involves securing external communications directly at the network edge. This method integrates post-quantum cryptographic primitives natively into end-user devices and direct bank endpoints, completely replacing classical RSA-based processes with NIST-standardized PQC algorithms. By leveraging the PiQASO SDK, financial institutions can upgrade their traditional TLS implementations to PQ-TLS. This employs advanced algorithms like ML-KEM for secure key encapsulation and ML-DSA for robust, tamper-proof digital signatures.

2. PQCaaS (SaaS Model) for Constrained Devices

Not all devices or legacy banking systems possess the computational resources or memory required to execute computationally heavy post-quantum algorithms natively. To resolve this without leaving legacy systems vulnerable, PiQASO introduces the PQC-as-a-Service (PQCaaS) model. In this Software-as-a-Service approach, resource-constrained nodes can safely offload complex PQC computations to a dedicated, high-performance PQC Data Encryption Server (PQ-DES). The PQCaaS acts as a secure cryptographic intermediary, negotiating quantum-resistant sessions on behalf of the client and ensuring end-to-end security without requiring massive hardware overhauls at the edge.

3. FPGA-Accelerated PQC Operations

One of the primary challenges of implementing PQC in high-throughput financial environments (like core banking switches and central payment gateways) is the computational overhead. Post-quantum algorithms require mathematically intensive operations, which can introduce unacceptable latency if executed purely in software. To counter this, PiQASO emphasizes the use of hardware-based acceleration. By offloading bottleneck operations—such as the Number Theoretic Transform (NTT) for lattice-based cryptography and Karatsuba polynomial multiplications—onto specialized FPGA (Field-Programmable Gate Array) or HSM (Hardware Security Module) environments, the architecture achieves a highly efficient hardware/software co-design. This significantly speeds up cryptographic execution, ensuring PQC adoption does not degrade the user experience or limit transaction volume.

Ensuring Crypto-Agility

Crucially, the architecture avoids rigid, single-algorithm dependencies by prioritizing crypto-agility. The framework mandates the implementation of multiple mitigation strategies for PQ-TLS. This includes Hybrid Key Exchange mechanisms that pair established classical algorithms (like ECDH) with new post-quantum ones (like ML-KEM). This hybrid approach ensures that the system remains secure even if unexpected vulnerabilities are discovered in one of the new PQC primitives. Furthermore, dynamic fallback capabilities are implemented to gracefully revert to classical algorithms if PQC negotiations fail, guaranteeing uninterrupted banking services while the global internet completes its post-quantum transition.

The project funded under Grant Agreement No. ​101190366​ is supported by the European Cybersecurity Competence CentreFunded by the European Union.
Views and opinions expressed are however those of the author(s) only and do not necessarily reflect those of the European Union or European Cybersecurity Competence Centre.
Neither the European Union nor the granting authority can be held responsible for them.