Why Australia may need to upgrade one million payment terminals
Around 970,000 payment terminals and 25,000 ATMs may need upgrading as Australia replaces its ageing TDES encryption with the stronger AES standard. Here's what the technology actually does — and why quantum computing raises the stakes.
Nearly one million Australian payment terminals may need to be upgraded as the banking industry replaces a decades-old encryption system.
The issue sounds highly technical, but the basic problem is simple: when your card details travel through the payments system, they need to be turned into information that criminals cannot read.
Today, much of Australia's card-payment infrastructure relies on Triple Data Encryption Standard, or TDES. The Reserve Bank says TDES remains fit for purpose in the short term, but advances in conventional computing — and eventually quantum computing — mean it is unlikely to remain sufficiently secure over the longer term.
What does encryption actually do?
Imagine sending a message saying:
CARD NUMBER: 1234…
Encryption converts that readable information — known as plaintext — into apparently meaningless data called ciphertext. Only someone holding the correct cryptographic key can turn it back into readable information.
TDES dates from the 1990s. It effectively applies the older Data Encryption Standard three times, using three 56-bit keys and providing around 112 bits of effective security.
The proposed replacement is AES — the Advanced Encryption Standard.
AES is a modern symmetric encryption algorithm standardised by the US National Institute of Standards and Technology. “Symmetric” simply means the same secret key is used to encrypt and decrypt the data.
AES works with 128, 192 or 256-bit keys and processes data in 128-bit blocks. Longer keys create enormously more possible combinations for an attacker to test. AES is also faster and more computationally efficient than TDES.
Does this replace chip cards and PINs?
No.
AES is one layer of payment security.
Chip cards, PINs, tokenisation, dynamic security codes, fraud monitoring and authentication all perform different jobs. AES principally strengthens the cryptographic protection of sensitive information as it is stored and transmitted through the payment chain.
Think of payment security as a house with several locks. Moving from TDES to AES replaces one particularly important lock with a much stronger one.
Why does nearly everything need upgrading?
Because encryption is not performed in one central computer.
A card payment can move through:
terminal → merchant processor → acquiring bank → card network → issuing bank.
Every participant that encrypts, decrypts or passes protected payment information must be able to use compatible standards.
Australia's system includes roughly 970,000 point-of-sale terminals and 25,000 ATMs, plus processors, gateways and banking infrastructure. Some devices can be updated through software or during normal replacement cycles; others may require hardware replacement.
That makes migration a coordination problem as much as a technology problem. If one important link cannot support AES, the stronger protection elsewhere may not deliver its full benefit.
What does quantum computing have to do with it?
Quantum computers could eventually perform some cryptographic attacks much faster than conventional machines.
AES — particularly with longer keys — is considerably more resistant than TDES to known attack techniques. But AES migration is not the entire quantum-security solution. Payments systems also use other types of cryptography, including technologies for authentication and key exchange, which will require separate post-quantum upgrades.
That is why the RBA is now examining cryptography across the entire payments system rather than treating AES as a once-and-done fix.
Most industry submissions do not want the RBA to dictate a specific technical solution. Their fear is that moving too early could force firms to replace equipment twice as technology and international standards evolve.
The challenge is therefore one of timing: upgrade too slowly and security deteriorates; mandate technology too quickly and Australia could spend billions installing systems that soon become obsolete.
|
||||||||||||||||||||||||||||||||||