CRYPTOGRAPHY BILL OF MATERIALS · CYCLONEDX 1.6

SWIFT / ISO 20022 Payments
Crypto-Dependency Map + CBOM

Where quantum-vulnerable cryptography lives across the wire-payment lifecycle — and what to migrate first. A machine-readable inventory built with payments-domain context, not a generic scan.

P1 · P2 · P3 · P4 migration-priority ramp

One machine-readable inventory

Built with payments context

31
cryptographic assets across 7 stages + Lynx & RTR rails
23
quantum-vulnerable (74% of the estate)
26/5
documented / inferred — every asset evidence-labelled

Generic discovery tells you that you run RSA-2048. It can't tell you it's the signature on a pacs.009 liquidity transfer BIS Project Leap just stress-tested, or that the real harvest-now-decrypt-later exposure is the RSA key-wrap on a 10-year payment archive.

The flagship view

The wire-payment crypto-dependency map

S1
Initiation
pain.001
S2
Orchestration
pacs.008
S3
Screening
AML
S4
SWIFT msg
MT103 / pacs.008
S5
HSM signing
FIPS 140-2 L3
S6
RTGS
pacs.009
S7
Archive
7–10 yr

Each stage is linked in the CBOM's dependency graph to the crypto assets beneath it — so you can trace, for any point in the flow, exactly which quantum-vulnerable assets it relies on.

Home-market depth · Payments Canada

Two domestic rails, two evidence pictures

LYNX · CAD HIGH-VALUE RTGS — mostly documented

Runs over SWIFTNet — inherits SWIFT PKI

  • Live 2021 (Payments Canada, replaced LVTS); ISO 20022 over SWIFTNet InterAct.
  • RSA-2048 signing in FIPS 140-2 L3 SWIFT HSMs; RSA-4096 SWIFTNet CA root; IPsec (ECDH/RSA + AES-256).
  • PQC fate coupled to SWIFT's SwiftNet 8.0 (2027) rollout.
RTR · REAL-TIME RAIL — partly inferred

Modern JSON/REST + IPsec + OAuth — not SWIFTNet

  • Payments Canada; Interac (exchange) + Mastercard/Vocalink (clearing); launch 2026.
  • Guide confirms payloads "encrypted, digitally signed and validated" + IPsec + MFA — but the signing algorithm, TLS version & HSM custody are not public, so they're modelled INFERRED.
  • Greenfield for 2026 → the natural place to build hybrid-PQC from inception.

Every asset in the CBOM carries a DOCUMENTED / INFERRED confidence label with a note on exactly what is known vs assumed. Cyber Centre ITSM.40.001 (2031/2035) applies to Payments Canada and Interac by best-practice analogy and oversight expectations, not direct federal mandate.

The prioritisation backbone

‘Quantum-vulnerable’ is two problems, not one

CONFIDENTIALITY · P1 CRITICAL

Key transport & agreement

  • Attack is retroactive — harvest-now-decrypt-later.
  • Anything encrypted today whose secrecy must outlive Q-day is already exposed.
  • Target: ML-KEM-768 (hybrid X25519+ML-KEM).
AUTHENTICITY · P2 HIGH

Signatures & certificates

  • Not retroactive — you can't forge a wire that already settled.
  • Risk crystallises at Q-day, driven by deprecation deadlines.
  • Target: ML-DSA-65 (FIPS 204).
BIS Project Leap Phase 2 (SWIFT + three central banks, 11 Dec 2025) proved migration is feasible on the live euro T2/TARGET2 system — but a Dilithium signature of 3,293 bytes replacing a 256-byte RSA-2048 one (~12.9×) overflowed message buffers. The deliverable is crypto-agility, not a one-time cipher swap.

Explore the repo

What's inside

cbom/payment-estate-cbom.jsonThe CycloneDX 1.6 CBOM — 31 assets, 23 quantum-vulnerable (26 documented / 5 inferred).
data/crypto-inventory.yamlHuman-editable source of truth.
scripts/generate_cbom.pyYAML → CBOM generator (single-source-of-truth design).
docs/migration-priorities.mdWhat breaks / can be hybridised + Project Leap analysis.

Reference model, not a real institution. Every key, certificate, and endpoint is illustrative. Third-party figures should be verified against the cited primary sources.