Why Australia may need to upgrade one million payment terminals

Around 970,000 payment terminals and 25,000 ATMs may need upgrading as Australia replaces its ageing TDES encryption with the stronger AES standard. Here's what the technology actually does — and why quantum computing raises the stakes.

Nearly one million Australian payment terminals may need to be upgraded as the banking industry replaces a decades-old encryption system.

The issue sounds highly technical, but the basic problem is simple: when your card details travel through the payments system, they need to be turned into information that criminals cannot read.

Today, much of Australia's card-payment infrastructure relies on Triple Data Encryption Standard, or TDES. The Reserve Bank says TDES remains fit for purpose in the short term, but advances in conventional computing — and eventually quantum computing — mean it is unlikely to remain sufficiently secure over the longer term.

What does encryption actually do?

Imagine sending a message saying:

CARD NUMBER: 1234…

Encryption converts that readable information — known as plaintext — into apparently meaningless data called ciphertext. Only someone holding the correct cryptographic key can turn it back into readable information.

TDES dates from the 1990s. It effectively applies the older Data Encryption Standard three times, using three 56-bit keys and providing around 112 bits of effective security.

The proposed replacement is AES — the Advanced Encryption Standard.

AES is a modern symmetric encryption algorithm standardised by the US National Institute of Standards and Technology. “Symmetric” simply means the same secret key is used to encrypt and decrypt the data.

AES works with 128, 192 or 256-bit keys and processes data in 128-bit blocks. Longer keys create enormously more possible combinations for an attacker to test. AES is also faster and more computationally efficient than TDES.

Does this replace chip cards and PINs?

No.

AES is one layer of payment security.

Chip cards, PINs, tokenisation, dynamic security codes, fraud monitoring and authentication all perform different jobs. AES principally strengthens the cryptographic protection of sensitive information as it is stored and transmitted through the payment chain.

Think of payment security as a house with several locks. Moving from TDES to AES replaces one particularly important lock with a much stronger one.

Why does nearly everything need upgrading?

Because encryption is not performed in one central computer.

A card payment can move through:

terminal → merchant processor → acquiring bank → card network → issuing bank.

Every participant that encrypts, decrypts or passes protected payment information must be able to use compatible standards.

Australia's system includes roughly 970,000 point-of-sale terminals and 25,000 ATMs, plus processors, gateways and banking infrastructure. Some devices can be updated through software or during normal replacement cycles; others may require hardware replacement.

That makes migration a coordination problem as much as a technology problem. If one important link cannot support AES, the stronger protection elsewhere may not deliver its full benefit.

What does quantum computing have to do with it?

Quantum computers could eventually perform some cryptographic attacks much faster than conventional machines.

AES — particularly with longer keys — is considerably more resistant than TDES to known attack techniques. But AES migration is not the entire quantum-security solution. Payments systems also use other types of cryptography, including technologies for authentication and key exchange, which will require separate post-quantum upgrades.

That is why the RBA is now examining cryptography across the entire payments system rather than treating AES as a once-and-done fix.

Most industry submissions do not want the RBA to dictate a specific technical solution. Their fear is that moving too early could force firms to replace equipment twice as technology and international standards evolve.

The challenge is therefore one of timing: upgrade too slowly and security deteriorates; mandate technology too quickly and Australia could spend billions installing systems that soon become obsolete.

BENCHMARK ANALYTICS | PAYMENTS SECURITY
Australia's million-device encryption upgrade
Card payments are moving from an encryption standard widely used since the 1990s to the stronger Advanced Encryption Standard.
~995,000
payment devices may require replacement or upgrade
970,000
payment terminals
25,000
ATMs
The cryptographic upgrade
CURRENT
TDES
Triple Data Encryption Standard
→
NEW
AES
Advanced Encryption Standard
FEATURE TDES AES
Effective key strength ~112 bit 128 / 192 / 256 bit
Design era Legacy Modern
Processing efficiency Lower Higher
Long-term security Declining Stronger
WHAT DOES ENCRYPTION DO?
Readable payment data → Encryption + secret key → Unreadable ciphertext
The authorised recipient uses the correct key to decrypt the information. Someone intercepting the encrypted data should see only meaningless ciphertext.
Why migration is difficult
Terminal  →  Processor  →  Acquirer  →  Card network  →  Bank
Every important link needs compatible cryptography. A weak or delayed participant can reduce the effectiveness of the upgrade elsewhere.
AND THEN COMES QUANTUM
AES strengthens today's card-payment encryption, but it is not the whole post-quantum solution. Other cryptographic technologies used for authentication, signatures and key exchange will also need to evolve.
The policy challenge: move too slowly and Australia risks relying on weakening cryptography. Move too quickly and businesses could be forced to replace equipment before new international standards have settled.
Sources: Reserve Bank of Australia; Australian Payments Network; ACCC; US National Institute of Standards and Technology. Device estimates refer to equipment that may require replacement or upgrade; not every device will necessarily require immediate physical replacement.

Never miss new Benchmark analysis

New economic and financial-services analysis delivered directly by email.
jamie@example.com
Subscribe